Commit Graph
20 Commits
Author SHA1 Message Date
Ryan Hughes 5fae475743 Address Momus branch-review findings: harden ship, advance, and locking
- ship: no interactive override of the untested-commit guard; the tag targets
  the pinned commit the artifacts were built from (never the branch head); a
  tagged-but-incomplete train is found and resumed instead of vanishing from
  open-train detection; a fully shipped train reports as such
- start: a failed edge→rc advance fails the command loudly (both start and
  the advance are idempotent) instead of opening a train against stale rc
- rc trigger: bootstraps the server's rc worktree on first use, so a host set
  up before the rc branch existed can run its first RC build
- advance-channel: fast-ring packages are excluded from edge→rc (the stable
  build replicated by parity is authoritative for rc — same filename, other
  bytes); differing destination bytes abort instead of warn; a package whose
  signature copy was interrupted gets its .sig restored on resume
- the release lock now also covers direct promote/update/clean/remove/sync
  invocations, not just release/advance/upload-prebuilt
2026-08-27 01:10:33 -04:00
Ryan Hughes e73b843bd2 Add rc as a first-class channel: validation, shared repo root, rc build mirror
- helpers/paths.sh: validate_mirror/require_valid_mirror for the edge|rc|stable
  set, and REPO_ROOT (OMARCHY_REPO_ROOT override) so a secondary checkout like
  the rc branch worktree publishes into the same channel tree as the primary
- validate --mirror everywhere it previously accepted any string (sync-repo,
  promote-build, update-repo, clean-repo, remove-package) and widen the
  edge|stable checks in build, deploy, push-build, auto-release
- build/Dockerfile: rc builds compile against rc-mirror.omarchy.org
2026-08-27 01:10:33 -04:00
David Heinemeier HanssonandClaude Opus 5 f8c1cbb072 Add bin/setup to prepare a repository host
The sync guard could not read the repository database because bsdtar was not
installed on the host, and the first fix was to parse around its absence. The
better answer is for the host to have what the tooling needs: libarchive ships
the library pacman links against without necessarily installing the binary, so
bsdtar being present was an assumption, not a fact.

bin/setup installs the dependencies, enables Docker, creates the state
directory, and installs and enables the release timers -- the steps the README
previously listed by hand. It is idempotent and takes --check to report without
changing anything. Signing credentials and the rclone remote hold secrets, so
it reports on those rather than creating them.

sync-repo goes back to reading the database with bsdtar alone, and says to run
bin/setup when it is missing.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-12 05:04:06 -07:00
David Heinemeier HanssonandClaude Opus 5 dbe1db4b03 Read the remote database without depending on bsdtar
The partial-tree guard parsed omarchy.db with bsdtar, which is not installed on
the repository host. Every sync there aborted with "the remote database exists
but could not be read" -- a guard meant to catch a partial tree instead blocked
a complete one, stopping a publish after sign, promote and update had already
succeeded.

GNU tar reads the database fine when it is a seekable file; the pipe was what
defeated it originally, and that is already downloaded to a temp file. tar now
leads, with bsdtar as a fallback for a tar too old to detect zstd.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-12 04:59:22 -07:00
David Heinemeier HanssonandClaude Opus 5 fd9c078bf2 Fix nine defects in the push/sync path found in review
The worst was fatal: push passed --skip-prod-check to upload-prebuilt, which
forwards every argument to sign, promote and update as well, and sign rejects
unknown options. Every non-dry-run push and deploy would have uploaded and
verified its artifacts and then failed before signing. upload-prebuilt now
routes publishing flags to sync alone.

The partial-tree guard was weaker than it looked:

  - it counted archive files locally against package names in the remote
    database, and this tree keeps two versions per package, so a checkout with
    a spare version of half the repository could pass while still hiding
    hundreds of packages. It now compares package-name sets and lists what
    would be hidden.
  - it treated any unreadable remote as an empty one, so an auth failure or a
    corrupt database disabled it. Only rclone's "directory not found" now
    counts as a fresh mirror; every other failure aborts.

Also:

  - sync had no set -e, so a failed package upload fell through to publishing
    the database, advertising packages that were never uploaded. Each transfer
    is now checked before the next step.
  - --package with no names silently meant "every package", which under --yes
    could publish everything from one unset variable in a script.
  - push now refuses to run when the host has packages staged from an earlier
    failure, since publishing would sign and promote those too.
  - epoch versions contain a colon, which rsync reads as host:path, so no
    package with an epoch could be transferred. Sources are ./-prefixed.
  - remote paths are quoted for the remote shell.
  - sync spun forever on a missing option value.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-12 03:39:55 -07:00
David Heinemeier HanssonandClaude Opus 5 bf53101bbf Add bin/repo push and stop sync from deleting production
Heavy packages build faster on a local machine, but there was no way to get
the artifacts to the server: bin/upload-prebuilt publishes to the rclone
remote from whatever tree it runs in, so the local -> host hop was manual.

bin/repo push rsyncs build-output artifacts to the host, verifies checksums,
and runs upload-prebuilt over ssh. Signing stays on the host, which is the
only machine with the key and the only one holding a complete repository.

Publishing from a local checkout was worse than merely unsupported. sync ran
rclone sync --delete-after against a tree that pkgs.omarchy.org/ gitignores,
so on any machine that had not run a full release it would have deleted the
production repository -- guarded only by a y/N prompt that --skip-prod-check
turns off. Package uploads are now additive, deletion moves behind --prune,
and sync refuses to publish a database built from a tree holding fewer
packages than the remote already lists.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-12 03:13:06 -07:00
Ryan Hughes dd98747e2c Avoid R2 HEAD checks during repo sync 2026-06-05 19:11:16 -04:00
Ryan Hughes aca2584c8b Update sync and release to use mirror / arch 2025-11-21 13:20:06 -05:00
David Heinemeier Hansson 44ce28a0d8 Account for multiple subdirectories for syncing 2025-11-21 15:01:59 +01:00
Ryan Hughes 4b5342ba66 Add stable / edge 2025-11-10 11:03:39 -05:00
Ryan Hughes 51a3318b10 Consolidate more helpers 2025-10-27 00:28:46 -04:00
Ryan Hughes 95d1a77659 Overhaul the whole build process 2025-10-26 23:33:22 -04:00
Ryan Hughes de3f952825 Ignore existing 2025-10-26 17:58:27 -04:00
Ryan Hughes ff7dcb352c Don't show progress 2025-10-23 00:57:35 -04:00
Ryan Hughes 9202b56a88 Updates 2025-09-12 21:52:49 -04:00
Ryan Hughes 6df79d32d9 Change sync order 2025-09-07 23:06:43 +02:00
Ryan Hughes c57c9620de Lots of cleanup 2025-08-28 19:44:01 +03:00
Ryan Hughes c5f7c41b3b Bin cleanup 2025-08-28 19:14:28 +03:00
Ryan Hughes 0735958154 Clean up syncing 2025-08-28 19:13:04 +03:00
Ryan Hughes e00a529ba9 Probably should have committed a long time ago... 2025-08-25 05:45:19 +02:00