Heavy packages build faster on a local machine, but there was no way to get
the artifacts to the server: bin/upload-prebuilt publishes to the rclone
remote from whatever tree it runs in, so the local -> host hop was manual.
bin/repo push rsyncs build-output artifacts to the host, verifies checksums,
and runs upload-prebuilt over ssh. Signing stays on the host, which is the
only machine with the key and the only one holding a complete repository.
Publishing from a local checkout was worse than merely unsupported. sync ran
rclone sync --delete-after against a tree that pkgs.omarchy.org/ gitignores,
so on any machine that had not run a full release it would have deleted the
production repository -- guarded only by a y/N prompt that --skip-prod-check
turns off. Package uploads are now additive, deletion moves behind --prune,
and sync refuses to publish a database built from a tree holding fewer
packages than the remote already lists.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
One-command releases for the omarchy + omarchy-settings pair:
bin/omarchy-pkgs release v4.0.0 | latest | rc [--commit sha] [--base X.Y.Z]
Rewrites both PKGBUILDs in lockstep (same _tag/_commit/pkgver/sha256sums,
pkgrel reset to 1), normalizes upstream tag forms to the vercmp-safe
attached rcN convention, refuses downgrades against the published edge DB,
regenerates and verifies checksums from a cached mirror clone, commits and
pushes to master, and triggers the build host when OMARCHY_BUILD_HOST is
configured. RCs stay on edge; finals are promoted with bin/repo migrate.
Includes a self-test covering tag normalization and pacman ordering, and a
README runbook.
A transient network failure cloning retroarch-joypad-autoconfig-git took
the whole sync workflow red. Clones now retry up to 3 times, and the
failure message includes git's actual error instead of guessing "may not
exist in AUR" — which was never the cause anyway: AUR serves an empty
repo for unknown package names, so that case is now detected explicitly
by the missing PKGBUILD.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
The dev packages are versioned off the quattro tip, so rebuilding the
same upstream commit yields the same filename. Promotion treated any
pre-existing filename as fatal, which wedged the release loop whenever a
run promoted but died before update-repo rebuilt the database: the stale
database kept advertising the older hash, so every later run rebuilt the
identical package and failed here again, retaining the state file each
time.
Compare the bytes instead. Identical packages are skipped and the run
continues, so the following update-repo step fixes the database and the
loop unsticks itself. Differing content under a published filename still
aborts. Signatures are judged by the package they sign, since gpg stamps
a timestamp into every signature and a re-signed package never matches.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>