Commit Graph
92 Commits
Author SHA1 Message Date
David Heinemeier HanssonandClaude Opus 5 f92de9c440 Make the upstream rewrite verify its own result
A second review pass found the PKGBUILD rewriting could still go wrong in ways
the pattern matching did not anticipate: an array element carrying a ")" in a
comment left the tail of the old array behind, and jq's "$" also matches before
a trailing newline, so a pkgver of "1.0\n" passed validation and then broke sed
after the checksum arrays had already been written.

Rather than chase each shape, prove the result. Every edit now lands on a
scratch copy that is parsed with bash -n and read back to confirm it holds the
version and checksums we meant to write, and only then replaces the PKGBUILD in
a single rename. Corruption that slips past the matching fails loudly with the
original untouched instead of landing in a pull request.

The validation anchors are \A and \z accordingly, empty checksum lists are
rejected rather than written as '', and the hook picks the newest stanza with
vercmp so it agrees with the comparator the updater uses.

Also stop the launcher probing /.config when HOME and XDG_CONFIG_HOME are both
unset, and require a regular file, so a directory at that path is skipped
instead of crashing the app on startup.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-15 08:34:42 -07:00
David Heinemeier HanssonandClaude Opus 5 01a566f01a Add bin/sync-upstream for packages that track a vendor release feed
Some vendors publish a release feed of their own that is faster and more
precise than anyone's packaging of it. A package opts in with an
.omarchy/upstream.sh hook that reports the newest release as JSON, and the
driver rewrites pkgver, the checksum arrays the hook names, and pkgrel.

Writes are guarded on both ends: every assignment the update will touch is
verified to exist before anything is written, so a hook naming an array the
PKGBUILD lacks fails with the file untouched rather than half rewritten; and
pkgver is held to pacman's character set, because it lands in a file makepkg
sources as shell.

Ordering is vercmp's, not sort -V's -- they disagree about whether 1.0a
precedes 1.0, and pacman is what decides if a published package is an upgrade.
That is also why the workflow runs in an Arch container rather than straight on
the runner.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-15 08:18:54 -07:00
Ryan Hughes d3298050bb Remove tag requirement 2026-08-14 11:08:39 -04:00
David Heinemeier HanssonandClaude Opus 5 daf98026bc Make bin/setup work on Ubuntu, which is what the host runs
The first version checked for pacman and refused anything else, so it would
have declined to run on the actual repository host. Nothing about that host
needs to be Arch: makepkg, repo-add and signing all happen inside containers.

Setup now detects apt or pacman and installs the right names for each --
bsdtar is libarchive-tools on Debian and libarchive on Arch. The requirement
list drops gnupg and the Arch build tools, which the host never runs directly,
leaving Docker, rclone, bsdtar, jq, git and rsync.

Docker is checked before being installed. A host may be running a version from
Docker's own repository, and replacing that underneath a working builder would
be a poor trade for consistency; setup starts it if stopped and otherwise
leaves it alone.

Verified both paths: apt installs the five dependencies and docker.io on a
bare Ubuntu 24.04 container, and an Arch host with Docker already running is
left untouched. A missing systemctl now reports that a container cannot be a
repository host instead of failing on an unknown command.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-12 05:43:23 -07:00
David Heinemeier HanssonandClaude Opus 5 f8c1cbb072 Add bin/setup to prepare a repository host
The sync guard could not read the repository database because bsdtar was not
installed on the host, and the first fix was to parse around its absence. The
better answer is for the host to have what the tooling needs: libarchive ships
the library pacman links against without necessarily installing the binary, so
bsdtar being present was an assumption, not a fact.

bin/setup installs the dependencies, enables Docker, creates the state
directory, and installs and enables the release timers -- the steps the README
previously listed by hand. It is idempotent and takes --check to report without
changing anything. Signing credentials and the rclone remote hold secrets, so
it reports on those rather than creating them.

sync-repo goes back to reading the database with bsdtar alone, and says to run
bin/setup when it is missing.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-12 05:04:06 -07:00
David Heinemeier HanssonandClaude Opus 5 dbe1db4b03 Read the remote database without depending on bsdtar
The partial-tree guard parsed omarchy.db with bsdtar, which is not installed on
the repository host. Every sync there aborted with "the remote database exists
but could not be read" -- a guard meant to catch a partial tree instead blocked
a complete one, stopping a publish after sign, promote and update had already
succeeded.

GNU tar reads the database fine when it is a seekable file; the pipe was what
defeated it originally, and that is already downloaded to a temp file. tar now
leads, with bsdtar as a fallback for a tar too old to detect zstd.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-12 04:59:22 -07:00
David Heinemeier HanssonandClaude Opus 5 ca90a19d73 Push every output of a selected pkgbase
--package meant a pkgbase to bin/build and a literal package name to
bin/push-build, so deploy --package nvidia-580xx-utils built three packages and
published one, leaving nvidia-580xx-dkms and opencl-nvidia-580xx behind with no
indication anything was missing. Hit while deploying exactly that package.

Selection now matches on the pkgbase recorded in .PKGINFO as well as on the
package name, so a pkgbase ships all of its outputs and an individual name
still selects just that one.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-12 04:24:38 -07:00
David Heinemeier HanssonandClaude Opus 5 51004999e7 Stop an unscoped deploy from rebuilding the whole repository
bin/build asks the local repository database which packages are already built.
A build machine has no such database, so every package looks out of date: an
unscoped 'bin/repo deploy' on this laptop would have built all 108 packages and
published them. Verified with a dry run.

deploy now refuses to run unscoped when that database is absent, and push
refuses the same combination under --yes, where nobody would see the list it
prints before publishing. Both are allowed on the repository host, which has
the database that makes the comparison meaningful.

Also states the split in the README: build, push and deploy are the three
commands that may run off the repository host; everything else works on the
published tree directly.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-12 04:03:31 -07:00
David Heinemeier HanssonandClaude Opus 5 34326295e9 Name the server OMARCHY_REPO_HOST, not OMARCHY_BUILD_HOST
Builds now happen wherever the operator likes, so naming the destination after
building described the old arrangement rather than the current one. What the
push and deploy commands reach is the machine that serves pkgs.omarchy.org and
holds the signing key: the repository host. It also runs the scheduled builds,
which is why the trigger in omarchy-pkgs release points at the same place.

Resolution moves into helpers/host-helpers.sh, which all three commands now
share instead of repeating: --host, then OMARCHY_REPO_HOST, then .repo-host.
OMARCHY_BUILD_HOST and .build-host keep working as fallbacks, so existing
environments and checkouts are unaffected.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-12 03:46:58 -07:00
David Heinemeier HanssonandClaude Opus 5 fd9c078bf2 Fix nine defects in the push/sync path found in review
The worst was fatal: push passed --skip-prod-check to upload-prebuilt, which
forwards every argument to sign, promote and update as well, and sign rejects
unknown options. Every non-dry-run push and deploy would have uploaded and
verified its artifacts and then failed before signing. upload-prebuilt now
routes publishing flags to sync alone.

The partial-tree guard was weaker than it looked:

  - it counted archive files locally against package names in the remote
    database, and this tree keeps two versions per package, so a checkout with
    a spare version of half the repository could pass while still hiding
    hundreds of packages. It now compares package-name sets and lists what
    would be hidden.
  - it treated any unreadable remote as an empty one, so an auth failure or a
    corrupt database disabled it. Only rclone's "directory not found" now
    counts as a fresh mirror; every other failure aborts.

Also:

  - sync had no set -e, so a failed package upload fell through to publishing
    the database, advertising packages that were never uploaded. Each transfer
    is now checked before the next step.
  - --package with no names silently meant "every package", which under --yes
    could publish everything from one unset variable in a script.
  - push now refuses to run when the host has packages staged from an earlier
    failure, since publishing would sign and promote those too.
  - epoch versions contain a colon, which rsync reads as host:path, so no
    package with an epoch could be transferred. Sources are ./-prefixed.
  - remote paths are quoted for the remote shell.
  - sync spun forever on a missing option value.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-12 03:39:55 -07:00
David Heinemeier HanssonandClaude Opus 5 c5f5f1c12c Add bin/repo deploy and --host on every server-facing command
deploy runs build then push, which is the whole workflow on a local build
machine. It resolves the build host before building so a missing --host fails
in a second rather than after a long compile.

--host now overrides $OMARCHY_BUILD_HOST and .build-host on deploy, push, and
the build trigger in omarchy-pkgs release, so a server can be named per
invocation without arming the release auto-trigger.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-12 03:23:30 -07:00
David Heinemeier HanssonandClaude Opus 5 bf53101bbf Add bin/repo push and stop sync from deleting production
Heavy packages build faster on a local machine, but there was no way to get
the artifacts to the server: bin/upload-prebuilt publishes to the rclone
remote from whatever tree it runs in, so the local -> host hop was manual.

bin/repo push rsyncs build-output artifacts to the host, verifies checksums,
and runs upload-prebuilt over ssh. Signing stays on the host, which is the
only machine with the key and the only one holding a complete repository.

Publishing from a local checkout was worse than merely unsupported. sync ran
rclone sync --delete-after against a tree that pkgs.omarchy.org/ gitignores,
so on any machine that had not run a full release it would have deleted the
production repository -- guarded only by a y/N prompt that --skip-prod-check
turns off. Package uploads are now additive, deletion moves behind --prune,
and sync refuses to publish a database built from a tree holding fewer
packages than the remote already lists.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-12 03:13:06 -07:00
Ryan Hughes 2d8f35f43f Update 2026-08-12 00:14:02 -04:00
Ryan Hughes 155ff25666 Add a rebuild option 2026-08-11 23:58:45 -04:00
Ryan Hughes f6c8d3d33b Handle prerelease 2026-08-11 23:42:39 -04:00
Ryan Hughes f609e6a31e Add omarchy-pkgs 2026-08-11 23:36:37 -04:00
Ryan Hughes abec5dd439 Add bin/omarchy-pkgs release command
One-command releases for the omarchy + omarchy-settings pair:
  bin/omarchy-pkgs release v4.0.0 | latest | rc [--commit sha] [--base X.Y.Z]

Rewrites both PKGBUILDs in lockstep (same _tag/_commit/pkgver/sha256sums,
pkgrel reset to 1), normalizes upstream tag forms to the vercmp-safe
attached rcN convention, refuses downgrades against the published edge DB,
regenerates and verifies checksums from a cached mirror clone, commits and
pushes to master, and triggers the build host when OMARCHY_BUILD_HOST is
configured. RCs stay on edge; finals are promoted with bin/repo migrate.
Includes a self-test covering tag normalization and pacman ordering, and a
README runbook.
2026-08-11 22:21:23 -04:00
David Heinemeier HanssonandClaude Fable 5 98628968a3 Fix unbound variable expansion in add-package jq filters
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Ls3ump7hcv4oNnjWW5AXmn
2026-08-05 22:54:04 +02:00
David Heinemeier HanssonandClaude Fable 5 f95d544fdb Retry AUR clones and report the real error on failure
A transient network failure cloning retroarch-joypad-autoconfig-git took
the whole sync workflow red. Clones now retry up to 3 times, and the
failure message includes git's actual error instead of guessing "may not
exist in AUR" — which was never the cause anyway: AUR serves an empty
repo for unknown package names, so that case is now detected explicitly
by the missing PKGBUILD.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-31 22:04:01 -05:00
David Heinemeier HanssonandClaude Opus 5 0a80091fe6 Promote packages already in production idempotently
The dev packages are versioned off the quattro tip, so rebuilding the
same upstream commit yields the same filename. Promotion treated any
pre-existing filename as fatal, which wedged the release loop whenever a
run promoted but died before update-repo rebuilt the database: the stale
database kept advertising the older hash, so every later run rebuilt the
identical package and failed here again, retaining the state file each
time.

Compare the bytes instead. Identical packages are skipped and the run
continues, so the following update-repo step fixes the database and the
loop unsticks itself. Differing content under a published filename still
aborts. Signatures are judged by the package they sign, since gpg stamps
a timestamp into every signature and a re-signed package never matches.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-07-27 16:37:01 -07:00
David Heinemeier HanssonandClaude Fable 5 d6b146bdc9 Add --package filter to repo migrate for single-package stable promotion
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-19 21:53:25 -07:00
Ryan Hughes 515b566cb9 Add skip_build 2026-07-13 19:55:23 -04:00
Ryan Hughes dd98747e2c Avoid R2 HEAD checks during repo sync 2026-06-05 19:11:16 -04:00
Ryan Hughes 7410dd87af Include log tail in release failure notifications 2026-06-04 19:36:05 -04:00
Ryan Hughes c1aed0d8f1 Squash merge omarchy-4 into master 2026-06-02 22:25:07 -04:00
Ryan Hughes 2ffe4f811c Refactor 2026-05-08 01:04:52 -04:00
Ryan Hughes f89e13e856 Prompt to sync at the end 2026-05-04 11:47:09 -04:00
David Heinemeier Hansson 6d217e1e87 Add prebuilt uploader 2026-04-23 13:59:21 +02:00
Ryan Hughes c42e988afe Add notifications for failures 2026-03-07 17:32:21 -05:00
Ryan Hughes ad61f12c11 Remove stable pkgbuilds 2026-03-07 16:25:40 -05:00
Ryan Hughes 2bcb57d4d1 Add stable migration command for edge packages 2026-02-26 12:37:43 -05:00
Ryan Hughes fdcce9465c Better logs and resolution 2026-02-17 11:12:52 -05:00
Ryan Hughes 8c5222fe01 Add pkgrel.override 2026-02-11 17:44:14 -05:00
Ryan Hughes fb5b71d209 Add docker cleaner 2026-01-10 20:36:21 -05:00
Ryan Hughes 45a356eb70 Create shared / fast track for certain packages 2026-01-10 20:18:35 -05:00
Ryan Hughes 0b13252528 Fix branch 2025-12-13 19:19:32 -05:00
Ryan Hughes 42401fa8a1 Add auto-release 2025-12-13 19:15:34 -05:00
Ryan Hughes 78d09cd2a1 Fix patching to prevent doubling up 2025-12-12 20:06:06 -05:00
Ryan Hughes 58562007c8 Remove update from the clean process 2025-11-21 22:20:56 -05:00
Ryan Hughes aca2584c8b Update sync and release to use mirror / arch 2025-11-21 13:20:06 -05:00
Ryan Hughes daa0e31db8 Update to display after parsing args 2025-11-21 13:15:30 -05:00
David Heinemeier Hansson 558af82690 Ensure the arch paths are updated too so we know where we are building 2025-11-21 15:39:14 +01:00
David Heinemeier Hansson c478b18a04 Set the mirror that was designated 2025-11-21 15:31:08 +01:00
David Heinemeier Hansson 274a4cb16d Show arch + mirror + build workspace before running 2025-11-21 15:28:01 +01:00
David Heinemeier Hansson 44ce28a0d8 Account for multiple subdirectories for syncing 2025-11-21 15:01:59 +01:00
Ryan Hughes ed25b693a1 Update paths 2025-11-10 12:27:13 -05:00
Ryan Hughes 02abd5fb51 Ensure repo dirs exist 2025-11-10 12:25:16 -05:00
Ryan Hughes 4ea26d5a30 Add promotion checking 2025-11-10 11:27:17 -05:00
Ryan Hughes 4b5342ba66 Add stable / edge 2025-11-10 11:03:39 -05:00
David Heinemeier Hansson bfd739f539 Revert "Pull gpg credentials directly from 1pw"
This reverts commit 93dd0fb78d.
2025-11-10 15:13:14 +01:00