Since publishing moved to CI on merge, a package whose PKGBUILD never
changes while its source moves was never rebuilt: omarchy-dev and
omarchy-settings-dev followed quattro through "#branch=" and a pkgver()
function, and nothing in this repository changed when quattro did. The
host timers that used to notice are off, so edge fell days behind.
The rule now: no git source without a commit or tag pin
(tests/pinned-sources.sh, run in CI). A package that has to follow a
branch declares a git_branch upstream watch, and the pin moves through
the same PR/build/publish path as every other version bump.
Watch (helpers/upstream-watch.py)
git_branch gains tag_pattern: the newest release tag in the pinned
commit's own history, exposed as {tag}/{version}/{distance}, so a
branch build is versioned <tag>.r<n>.g<sha>, above the release it
follows and below the next one. One blobless clone per branch per
run, shared by every package on it. min_release_age selects the
newest commit older than the window, so a push burst builds once.
Lane (helpers/package-metadata.sh, bin/sync-upstream --lane)
"auto_merge": true moves a package from the reviewed 6-hourly sync
PR to the unattended lane. Packages pinned from the same branch move
together: a failure on one restores the others and fails the group,
so the dev pair can never ship from two quattro commits.
Tracker (.github/workflows/track-branches.yml)
Every two hours: pin, open one PR with a GitHub App token, enable
auto-merge. Branch protection still gates the merge on result,
self-tests and build-isolation. A tip that fails to build stays an
open red PR until the next tick supersedes it. The App is required:
a PR opened with GITHUB_TOKEN has its checks held for approval and
its auto-merge would not fire publish.yml.
The reviewed workflows (sync-upstream, sync-rebuilds) open their PRs
with the same App so their builds start without a maintainer clicking
"Approve workflows to run"; without the App they fall back to
GITHUB_TOKEN and behave as before.
Recipes
The dev pair pins _commit and a real sha256sum, keeps the OMARCHY_SRC
override, and drops pkgver(). Its r-number stays the branch's total
commit count because the published history used it and pacman must
never see the version go down. omasnap-git is new: omacom/omasnap
main, versioned <tag>.r<distance>.g<sha>, provides/conflicts omasnap.
50 lines
1.9 KiB
Bash
Executable File
50 lines
1.9 KiB
Bash
Executable File
#!/bin/bash
|
|
# Every git source in the repository names an immutable commit or a tag.
|
|
#
|
|
# A source that follows a branch ("#branch=quattro", or no fragment at all)
|
|
# produces a package whose contents depend on when it was built, and nothing
|
|
# in this repository changes when that branch moves, so the CI publish path,
|
|
# which builds what a merge touched, never rebuilds it. Packages that need to
|
|
# follow a branch declare a git_branch upstream watch instead, and the tracker
|
|
# turns each new tip into a commit pin here (docs/upstream-sources.md).
|
|
set -euo pipefail
|
|
BUILD_ROOT=$(realpath "${BASH_SOURCE[0]%/*}/..")
|
|
PKGBUILDS_DIR=${PKGBUILDS_DIR:-$BUILD_ROOT/pkgbuilds}
|
|
|
|
failures=0
|
|
checked=0
|
|
for pkgdir in "$PKGBUILDS_DIR"/*/; do
|
|
[[ -f "$pkgdir/PKGBUILD" ]] || continue
|
|
package=$(basename "$pkgdir")
|
|
for arch in x86_64 aarch64; do
|
|
# Sourced the way the build tooling reads recipes: CARCH set, the local
|
|
# source override unset, so conditional and arch-suffixed arrays count.
|
|
sources=$(cd "$pkgdir" && env -u OMARCHY_SRC CARCH="$arch" bash -c '
|
|
source PKGBUILD >/dev/null 2>&1
|
|
printf "%s\n" "${source[@]}" "${source_x86_64[@]}" "${source_aarch64[@]}"' 2>/dev/null) || {
|
|
echo "FAIL: $package: PKGBUILD could not be sourced for $arch"
|
|
failures=$((failures + 1))
|
|
continue
|
|
}
|
|
while IFS= read -r entry; do
|
|
[[ -n "$entry" ]] || continue
|
|
url="${entry#*::}"
|
|
[[ "$url" == git+* ]] || continue
|
|
checked=$((checked + 1))
|
|
case "$url" in
|
|
*'#commit='*|*'#tag='*) ;;
|
|
*)
|
|
echo "FAIL: $package ($arch): git source is not pinned to a commit or tag: $url"
|
|
failures=$((failures + 1))
|
|
;;
|
|
esac
|
|
done <<<"$sources"
|
|
done
|
|
done
|
|
|
|
if ((failures)); then
|
|
echo "$failures unpinned git source(s). Pin with #commit= (and a git_branch upstream watch to move the pin), or #tag= with a checksum."
|
|
exit 1
|
|
fi
|
|
echo "PASS: $checked git source(s) across pkgbuilds/ are pinned to a commit or tag"
|