bin/repo advance --from/--to moves packages forward through the pipeline (edge → rc → stable), driven by the source channel's database rather than the raw directory, copying packages AND their detached signatures (fixing the old migrate bug that left promoted packages unverifiable), refusing to rewrite any published filename, and requiring a .sig for everything it moves. stable → rc is allowed only as --fast-ring parity replication or the one-time --bootstrap seed (bin/repo bootstrap-rc). 'migrate' stays as a deprecated alias for the transition. helpers/lock-helpers.sh adds a host-wide flock shared by bin/release, advance-channel, and upload-prebuilt (reentrant via OMARCHY_RELEASE_LOCK_HELD) so timers and operators serialize instead of interleaving partial publishes. bin/release gains a stable-only step 7: replicate fast-ring artifacts to rc so rc and stable stay in parity between release trains (skipped until rc is bootstrapped).
188 lines
5.3 KiB
Bash
Executable File
188 lines
5.3 KiB
Bash
Executable File
#!/bin/bash
|
|
# Run the complete release workflow: build, sign, promote, clean, sync
|
|
|
|
set -e
|
|
|
|
BUILD_ROOT=$(realpath "${BASH_SOURCE[0]%/*}/..")
|
|
source "$BUILD_ROOT/helpers/message-helpers.sh"
|
|
source "$BUILD_ROOT/helpers/paths.sh"
|
|
source "$BUILD_ROOT/helpers/lock-helpers.sh"
|
|
source "$BUILD_ROOT/helpers/basecamp-notifier.sh"
|
|
|
|
SYNC_REMOTE=""
|
|
SKIP_PROD_CHECK=false
|
|
DRY_RUN=false
|
|
|
|
print_header "Complete Release Workflow"
|
|
|
|
echo ""
|
|
print_info "This will run the complete release workflow:"
|
|
echo " 1. Build packages"
|
|
echo " 2. Sign packages"
|
|
echo " 3. Promote to production"
|
|
echo " 4. Clean old versions"
|
|
echo " 5. Update repository database"
|
|
echo " 6. Sync to remote"
|
|
echo ""
|
|
|
|
# Parse arguments
|
|
BUILD_ARGS=()
|
|
while [[ $# -gt 0 ]]; do
|
|
case $1 in
|
|
--arch)
|
|
ARCH="$2"
|
|
BUILD_ARGS+=("--arch" "$2")
|
|
update_arch_paths
|
|
shift 2
|
|
;;
|
|
--mirror)
|
|
MIRROR="$2"
|
|
BUILD_ARGS+=("--mirror" "$2")
|
|
update_arch_paths
|
|
shift 2
|
|
;;
|
|
--package)
|
|
BUILD_ARGS+=("--package" "$2")
|
|
shift 2
|
|
;;
|
|
--sync-remote)
|
|
SYNC_REMOTE="$2"
|
|
shift 2
|
|
;;
|
|
--skip-prod-check)
|
|
SKIP_PROD_CHECK=true
|
|
shift
|
|
;;
|
|
--dry-run)
|
|
DRY_RUN=true
|
|
BUILD_ARGS+=("--dry-run")
|
|
shift
|
|
;;
|
|
-h | --help)
|
|
echo "Usage: $0 [OPTIONS]"
|
|
echo ""
|
|
echo "Options:"
|
|
echo " --arch <arch> Target architecture (x86_64 or aarch64, default: x86_64)"
|
|
echo " --mirror <mirror> Mirror to use (edge, rc, or stable, default: edge)"
|
|
echo " --package <name> Build only the specified package"
|
|
echo " --sync-remote <path> Rclone remote for sync (default: pkgs.omarchy.org:omarchy-pkgs)"
|
|
echo " --skip-prod-check Skip production environment check during sync
|
|
--dry-run Show build plan only; do not sign/promote/clean/update/sync"
|
|
echo " -h, --help Show this help message"
|
|
echo ""
|
|
echo "This script runs the complete workflow:"
|
|
echo " build → sign → promote → clean → sync"
|
|
exit 0
|
|
;;
|
|
*)
|
|
print_error "Unknown option: $1"
|
|
exit 1
|
|
;;
|
|
esac
|
|
done
|
|
|
|
echo ""
|
|
print_info "Target architecture: $ARCH"
|
|
print_info "Mirror: $MIRROR"
|
|
print_info "Build workspace: $BUILD_OUTPUT_DIR"
|
|
|
|
# One channel mutation at a time: a timer firing mid-run or a second operator
|
|
# waits here instead of interleaving a partial publish.
|
|
if [[ "$DRY_RUN" != true ]]; then
|
|
acquire_release_lock || exit 1
|
|
fi
|
|
|
|
# Step 1: Build
|
|
echo ""
|
|
if [[ "$DRY_RUN" == true ]]; then
|
|
print_info "Step 1/6: Planning build..."
|
|
else
|
|
print_info "Step 1/6: Building packages..."
|
|
fi
|
|
"$BUILD_ROOT/bin/build" "${BUILD_ARGS[@]}" || {
|
|
print_error "Build failed"
|
|
notify_error "Release failed: Build step failed" "Mirror: $MIRROR | Arch: $ARCH"
|
|
exit 1
|
|
}
|
|
|
|
if [[ "$DRY_RUN" == true ]]; then
|
|
echo ""
|
|
print_success "Release dry run complete (build plan only)."
|
|
exit 0
|
|
fi
|
|
|
|
# Step 2: Sign
|
|
echo ""
|
|
print_info "Step 2/6: Signing packages..."
|
|
"$BUILD_ROOT/bin/sign" --arch "$ARCH" --mirror "$MIRROR" || {
|
|
print_error "Signing failed"
|
|
notify_error "Release failed: Signing step failed" "Mirror: $MIRROR | Arch: $ARCH"
|
|
exit 1
|
|
}
|
|
|
|
# Step 3: Promote
|
|
echo ""
|
|
print_info "Step 3/6: Promoting to production..."
|
|
"$BUILD_ROOT/bin/promote-build" --arch "$ARCH" --mirror "$MIRROR" || {
|
|
print_error "Promotion failed"
|
|
notify_error "Release failed: Promotion step failed" "Mirror: $MIRROR | Arch: $ARCH"
|
|
exit 1
|
|
}
|
|
|
|
# Step 4: Clean
|
|
echo ""
|
|
print_info "Step 4/6: Cleaning old versions..."
|
|
"$BUILD_ROOT/bin/clean-repo" --arch "$ARCH" --mirror "$MIRROR" || {
|
|
print_error "Cleaning failed"
|
|
notify_error "Release failed: Clean step failed" "Mirror: $MIRROR | Arch: $ARCH"
|
|
exit 1
|
|
}
|
|
|
|
# Step 5: Update DB
|
|
echo ""
|
|
print_info "Step 5/6: Updating repository database..."
|
|
"$BUILD_ROOT/bin/update-repo" --arch "$ARCH" --mirror "$MIRROR" || {
|
|
print_error "Database update failed"
|
|
notify_error "Release failed: Database update step failed" "Mirror: $MIRROR | Arch: $ARCH"
|
|
exit 1
|
|
}
|
|
|
|
# Step 6: Sync
|
|
echo ""
|
|
print_info "Step 6/6: Syncing to remote..."
|
|
SYNC_ARGS=("--mirror" "$MIRROR" "--arch" "$ARCH")
|
|
if [[ -n "$SYNC_REMOTE" ]]; then
|
|
SYNC_ARGS+=("--remote" "$SYNC_REMOTE")
|
|
fi
|
|
if [[ "$SKIP_PROD_CHECK" == true ]]; then
|
|
SYNC_ARGS+=("--skip-prod-check")
|
|
fi
|
|
"$BUILD_ROOT/bin/sync-repo" "${SYNC_ARGS[@]}" || {
|
|
print_error "Sync failed"
|
|
notify_error "Release failed: Sync step failed" "Mirror: $MIRROR | Arch: $ARCH"
|
|
exit 1
|
|
}
|
|
|
|
# Step 7 (stable only): fast-ring packages publish to rc and stable together,
|
|
# so rc never falls behind what stable users actually run. Skipped until the
|
|
# rc channel has been bootstrapped.
|
|
if [[ "$MIRROR" == "stable" ]]; then
|
|
echo ""
|
|
if [[ -f "$REPO_ROOT/rc/$ARCH/omarchy.db.tar.zst" ]]; then
|
|
print_info "Step 7: Replicating fast-ring packages to rc (parity)..."
|
|
REPLICATE_ARGS=(--from stable --to rc --fast-ring --arch "$ARCH")
|
|
[[ -n "$SYNC_REMOTE" ]] && REPLICATE_ARGS+=(--sync-remote "$SYNC_REMOTE")
|
|
[[ "$SKIP_PROD_CHECK" == true ]] && REPLICATE_ARGS+=(--skip-prod-check)
|
|
"$BUILD_ROOT/bin/advance-channel" "${REPLICATE_ARGS[@]}" || {
|
|
print_error "Fast-ring replication to rc failed"
|
|
notify_error "Release failed: rc parity replication failed" "Mirror: $MIRROR | Arch: $ARCH"
|
|
exit 1
|
|
}
|
|
else
|
|
print_info "rc channel not bootstrapped; skipping fast-ring replication"
|
|
fi
|
|
fi
|
|
|
|
echo ""
|
|
print_success "Release workflow completed successfully!"
|