Repository navigation
Pin Mac recipes with the right pkgver and git checksum - #27
Merged
Merged
Conversation
The Mac recipes source omarchy-mac-pkgs as git+...#commit=${_commit} with a
real sha256, but the pin only rewrote checksums of .tar.gz archives, so a
pin kept the old commit's checksum and makepkg refused the build.
makepkg's calc_checksum_git hashes `git -c core.abbrev=no archive --format
tar <commit>` from a mirror whose info/attributes disable export-ignore and
export-subst, with no global or system git configuration. The pin now does
the same from the source clone, and refuses any other source of the commit
whose checksum it cannot compute instead of leaving it stale.
A pin only bumped pkgrel, so pinning omarchy-mac across a version bump proposed 0.1.0-13 for a tree whose omarchy-mac/version is 0.1.1, which the recipe's prepare() rejects; omarchy-mac-boot's pkgver, the UTC date of the pinned commit, never moved either. The pin now takes pkgver as CONTRIBUTING.md "Releases" defines it, omarchy-mac/version at the commit for omarchy-mac and the commit's UTC date for omarchy-mac-boot, and resets pkgrel to 1 when it changes. A value that cannot be a pkgver, or a source package without a rule, blocks the pin.
A recipe that pinned the commit before the pin set pkgver and git checksums read as nothing to move, though its build fails in prepare() or on the checksum, and every later run waited for a publication that could not come. Such a recipe now blocks the pin with what to fix. A version file that cannot be read now says why instead of reading as missing.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
mac-release's pin produced recipes that could not build: it only bumpedpkgrel, and it left the git source'ssha256sumsat the old commit's value.git_source_sha256(lib/omacom.sh) does what makepkg 7.1'ssource/git.shdoes: no global or system git config,* -export-subst -export-ignorein the clone'sinfo/attributes, then sha256 ofgit -c core.abbrev=no archive --format tar <commit>. If any other source of the commit has a non-SKIP checksum the pin can't compute, it stops instead of leaving a stale checksum. The dry-run plan now prints the newsha256sums[0].Evidence
--package omarchy-mac b2c3985proposed0.1.0-12 -> 0.1.0-13and kept the old sha, so prepare() and the checksum would both fail.After: pinning a
0.1.0-12 @ 2a3ed89recipe to b2c3985 gives0.1.1-1, sha40bf12c3….d44aadb3…(omarchy-pkgs #927)31be04e5…(current boot recipe)40bf12c3…, 2a3ed89 ->ab951984…(makepkg -g)c472510a…(makepkg -g, Arch ARM)makepkg -o(sha256 "Passed" + prepare()) in the Arch ARM builder container.omarchy-mac:pin: nothing to move(and the pkgver and sha check passes)omarchy-mac-boot:20261008-1 -> 20261010-1 (_commit -> 5b2c815f007d, sha256sums[0] -> d44aadb3e396…)Test plan
tools/release/test/omacom-lane(new: same version bumps pkgrel; version bump sets pkgver and pkgrel=1; boot pkgver is the UTC date, not the local one; makepkg fixture under a hostiletar.umask/autocrlfconfig; known real pairs, skipped on a shallow checkout; stale or uncomputable checksums refused; unusable version file blocks; already-pinned stale recipe blocks)tools/release/test/candidate-setfork-parityfails the same way on main (fork asahi-release scenario); not touchedMerge Danger
Door: two-way
Tooling only. Nothing runs until an operator runs
mac-releasewithout--dry-run, and even then its output is a PR the owner merges.Blast Radius: release-tooling
Pin PRs on omacom/omarchy-pkgs now also change
pkgverandsha256sums, which the recipes need in order to build. Advance and x86_64 handling are unchanged.