Since publishing moved to CI on merge, a package whose PKGBUILD never
changes while its source moves was never rebuilt: omarchy-dev and
omarchy-settings-dev followed quattro through "#branch=" and a pkgver()
function, and nothing in this repository changed when quattro did. The
host timers that used to notice are off, so edge fell days behind.
The rule now: no git source without a commit or tag pin
(tests/pinned-sources.sh, run in CI). A package that has to follow a
branch declares a git_branch upstream watch, and the pin moves through
the same PR/build/publish path as every other version bump.
Watch (helpers/upstream-watch.py)
git_branch gains tag_pattern: the newest release tag in the pinned
commit's own history, exposed as {tag}/{version}/{distance}, so a
branch build is versioned <tag>.r<n>.g<sha>, above the release it
follows and below the next one. One blobless clone per branch per
run, shared by every package on it. min_release_age selects the
newest commit older than the window, so a push burst builds once.
Lane (helpers/package-metadata.sh, bin/sync-upstream --lane)
"auto_merge": true moves a package from the reviewed 6-hourly sync
PR to the unattended lane. Packages pinned from the same branch move
together: a failure on one restores the others and fails the group,
so the dev pair can never ship from two quattro commits.
Tracker (.github/workflows/track-branches.yml)
Every two hours: pin, open one PR with a GitHub App token, enable
auto-merge. Branch protection still gates the merge on result,
self-tests and build-isolation. A tip that fails to build stays an
open red PR until the next tick supersedes it. The App is required:
a PR opened with GITHUB_TOKEN has its checks held for approval and
its auto-merge would not fire publish.yml.
The reviewed workflows (sync-upstream, sync-rebuilds) open their PRs
with the same App so their builds start without a maintainer clicking
"Approve workflows to run"; without the App they fall back to
GITHUB_TOKEN and behave as before.
Recipes
The dev pair pins _commit and a real sha256sum, keeps the OMARCHY_SRC
override, and drops pkgver(). Its r-number stays the branch's total
commit count because the published history used it and pacman must
never see the version go down. omasnap-git is new: omacom/omasnap
main, versioned <tag>.r<distance>.g<sha>, provides/conflicts omasnap.
119 lines
4.6 KiB
YAML
119 lines
4.6 KiB
YAML
name: Sync Rebuild Triggers
|
|
|
|
on:
|
|
schedule:
|
|
# Every 6 hours, off the hour to dodge the scheduling backlog at :00
|
|
- cron: '40 */6 * * *'
|
|
workflow_dispatch:
|
|
inputs:
|
|
packages:
|
|
description: 'Specific packages to update (space-separated, leave empty for all)'
|
|
required: false
|
|
default: ''
|
|
|
|
jobs:
|
|
sync:
|
|
runs-on: ubuntu-latest
|
|
permissions:
|
|
contents: write
|
|
pull-requests: write
|
|
|
|
steps:
|
|
- name: Checkout repository
|
|
uses: actions/checkout@v4
|
|
with:
|
|
persist-credentials: false
|
|
|
|
# Runs in an Arch container against the mirror the x86_64 builder itself
|
|
# uses, because the question being asked is what that builder will link
|
|
# against and a different mirror can be hours ahead of it. Recording a
|
|
# version the build never saw is the one failure this command must not
|
|
# have: nothing re-fires once the record matches.
|
|
- name: Bump pkgrel for packages whose dependencies moved
|
|
run: |
|
|
docker run --rm \
|
|
-e PACKAGES="$PACKAGES" \
|
|
-e HOST_UID="$(id -u)" \
|
|
-e HOST_GID="$(id -g)" \
|
|
-v "$PWD/bin:/workspace/bin:ro" \
|
|
-v "$PWD/helpers:/workspace/helpers:ro" \
|
|
-v "$PWD/pkgbuilds:/workspace/pkgbuilds" \
|
|
-w /workspace \
|
|
archlinux:base-devel bash -lc '
|
|
set -euo pipefail
|
|
|
|
printf "Server = https://mirror.omarchy.org/\$repo/os/\$arch\n" > /etc/pacman.d/mirrorlist
|
|
pacman -Syu --noconfirm jq
|
|
|
|
groupadd -g "$HOST_GID" runner
|
|
useradd -m -u "$HOST_UID" -g "$HOST_GID" runner
|
|
chown -R runner:runner /workspace/pkgbuilds
|
|
|
|
if [[ -n "${PACKAGES:-}" ]]; then
|
|
read -r -a package_args <<< "$PACKAGES"
|
|
runuser -u runner -- ./bin/sync-rebuilds "${package_args[@]}"
|
|
else
|
|
runuser -u runner -- ./bin/sync-rebuilds
|
|
fi
|
|
'
|
|
env:
|
|
PACKAGES: ${{ github.event.inputs.packages }}
|
|
|
|
- name: Check for changes
|
|
id: changes
|
|
run: |
|
|
if [ -z "$(git status --porcelain)" ]; then
|
|
echo "has_changes=false" >> "$GITHUB_OUTPUT"
|
|
else
|
|
echo "has_changes=true" >> "$GITHUB_OUTPUT"
|
|
fi
|
|
|
|
# App token rather than GITHUB_TOKEN so the PR's build and test runs
|
|
# start without a maintainer approving them (see sync-upstream.yml).
|
|
- name: Mint the bot token
|
|
if: steps.changes.outputs.has_changes == 'true'
|
|
id: app
|
|
env:
|
|
PKGS_BOT_APP_ID: ${{ secrets.PKGS_BOT_APP_ID }}
|
|
# Without the App configured this falls back to GITHUB_TOKEN below,
|
|
# which still opens the PR; a maintainer then has to approve its
|
|
# workflow runs by hand, as before.
|
|
uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1 # v3.2.0
|
|
with:
|
|
app-id: ${{ secrets.PKGS_BOT_APP_ID }}
|
|
private-key: ${{ secrets.PKGS_BOT_PRIVATE_KEY }}
|
|
continue-on-error: true
|
|
|
|
- name: Create Pull Request
|
|
if: steps.changes.outputs.has_changes == 'true'
|
|
uses: peter-evans/create-pull-request@5f6978faf089d4d20b00c7766989d076bb2fc7f1 # v8.1.1
|
|
with:
|
|
token: ${{ steps.app.outputs.token || secrets.GITHUB_TOKEN }}
|
|
commit-message: 'chore: rebuild against updated dependencies'
|
|
title: 'chore: rebuild against updated dependencies'
|
|
body: |
|
|
Automated pkgrel bump for packages that link against a dependency
|
|
which has moved in the official repositories.
|
|
|
|
Each package names those dependencies in `rebuild_on` and carries the
|
|
versions its current pkgrel was bumped for in `rebuilt_against`. The
|
|
bump is what makes the rebuilt package an upgrade pacman will offer;
|
|
without it the build produces the version already published and no
|
|
one receives it.
|
|
branch: auto/sync-rebuilds
|
|
delete-branch: true
|
|
labels: automated
|
|
reviewers: ryanrhughes
|
|
|
|
- name: Notify Basecamp on failure
|
|
if: failure() && env.BASECAMP_CHATBOT_URL != ''
|
|
env:
|
|
BASECAMP_CHATBOT_URL: ${{ secrets.BASECAMP_CHATBOT_URL }}
|
|
run: |
|
|
curl -s -o /dev/null \
|
|
-H "Content-Type: application/json" \
|
|
-d "$(jq -n --arg content \
|
|
"🔴 <strong>Rebuild trigger sync failed</strong><br><a href=\"${{ github.server_url }}/${{ github.repository }}/actions/runs/${{ github.run_id }}\">View run</a>" \
|
|
'{content: $content}')" \
|
|
"$BASECAMP_CHATBOT_URL"
|