Since publishing moved to CI on merge, a package whose PKGBUILD never
changes while its source moves was never rebuilt: omarchy-dev and
omarchy-settings-dev followed quattro through "#branch=" and a pkgver()
function, and nothing in this repository changed when quattro did. The
host timers that used to notice are off, so edge fell days behind.
The rule now: no git source without a commit or tag pin
(tests/pinned-sources.sh, run in CI). A package that has to follow a
branch declares a git_branch upstream watch, and the pin moves through
the same PR/build/publish path as every other version bump.
Watch (helpers/upstream-watch.py)
git_branch gains tag_pattern: the newest release tag in the pinned
commit's own history, exposed as {tag}/{version}/{distance}, so a
branch build is versioned <tag>.r<n>.g<sha>, above the release it
follows and below the next one. One blobless clone per branch per
run, shared by every package on it. min_release_age selects the
newest commit older than the window, so a push burst builds once.
Lane (helpers/package-metadata.sh, bin/sync-upstream --lane)
"auto_merge": true moves a package from the reviewed 6-hourly sync
PR to the unattended lane. Packages pinned from the same branch move
together: a failure on one restores the others and fails the group,
so the dev pair can never ship from two quattro commits.
Tracker (.github/workflows/track-branches.yml)
Every two hours: pin, open one PR with a GitHub App token, enable
auto-merge. Branch protection still gates the merge on result,
self-tests and build-isolation. A tip that fails to build stays an
open red PR until the next tick supersedes it. The App is required:
a PR opened with GITHUB_TOKEN has its checks held for approval and
its auto-merge would not fire publish.yml.
The reviewed workflows (sync-upstream, sync-rebuilds) open their PRs
with the same App so their builds start without a maintainer clicking
"Approve workflows to run"; without the App they fall back to
GITHUB_TOKEN and behave as before.
Recipes
The dev pair pins _commit and a real sha256sum, keeps the OMARCHY_SRC
override, and drops pkgver(). Its r-number stays the branch's total
commit count because the published history used it and pacman must
never see the version go down. omasnap-git is new: omacom/omasnap
main, versioned <tag>.r<distance>.g<sha>, provides/conflicts omasnap.
68 lines
2.3 KiB
YAML
68 lines
2.3 KiB
YAML
name: Tests
|
|
|
|
# PR-only. Publishing on push has its own workflow and is what verifies the
|
|
# merged tree: it resolves every package against the live channel and refuses
|
|
# a filename that already exists with different bytes, so two PRs cannot land
|
|
# the same version twice. A post-merge test run would only repeat the PR's.
|
|
on:
|
|
pull_request:
|
|
workflow_dispatch:
|
|
|
|
jobs:
|
|
build-isolation:
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
with:
|
|
persist-credentials: false
|
|
- name: Prepare fixture builder
|
|
run: docker build -t omarchy-build-isolation-test -f tests/build-isolation.Dockerfile tests
|
|
- name: Verify isolated builds with real pacman transactions
|
|
env:
|
|
CONTAINER_ENGINE: docker
|
|
TEST_BUILDER_IMAGE: omarchy-build-isolation-test
|
|
run: tests/build-isolation.sh
|
|
|
|
self-tests:
|
|
runs-on: ubuntu-latest
|
|
|
|
steps:
|
|
- name: Checkout repository
|
|
uses: actions/checkout@v4
|
|
with:
|
|
persist-credentials: false
|
|
|
|
- name: Test PR workflow approval
|
|
run: node --test tests/pr-workflow-approval.cjs
|
|
|
|
- name: Test builder images
|
|
run: node --test tests/builder-image.cjs
|
|
|
|
# An Arch container for vercmp: version ordering has to be decided by
|
|
# the same comparator pacman uses on users' machines.
|
|
- name: Run self-tests
|
|
run: |
|
|
docker run --rm \
|
|
-v "$PWD:/workspace:ro" \
|
|
-w /workspace \
|
|
archlinux:base-devel bash -lc '
|
|
set -euo pipefail
|
|
pacman -Syu --noconfirm git jq python libarchive neovim tmux
|
|
python tests/oma-service-removal.py
|
|
python tests/upstream-watch.py
|
|
./bin/sync-upstream self-test
|
|
./bin/sync-rebuilds --self-test
|
|
./bin/omarchy-pkgs self-test
|
|
./bin/omarchy-release self-test
|
|
./tests/neovim-remote-clipboard.sh
|
|
python tests/neovim-clipboard-tmux.py
|
|
./tests/partial-release.sh
|
|
./tests/published-build-plan.sh
|
|
./tests/pinned-sources.sh
|
|
./tests/controller.sh
|
|
./tests/artifact-helpers.sh
|
|
./tests/limine-mkinitcpio-hook.sh
|
|
pacman -S --noconfirm --quiet rclone >/dev/null
|
|
./tests/publish-artifact.sh
|
|
'
|