Skip to content

Pin Mac recipes with the right pkgver and git checksum - #27

Merged
maralcbr merged 4 commits into
mainfrom
mac-release-version-pin
Oct 10, 2026
Merged

maralcbr merged 4 commits into
mainfrom
mac-release-version-pin

Conversation

@maralcbr

Copy link
Copy Markdown
Collaborator

Summary

mac-release's pin produced recipes that could not build: it only bumped pkgrel, and it left the git source's sha256sums at the old commit's value.

 plan_pins (per omarchy-mac, omarchy-mac-boot)
-  pin_recipe dir commit                       # pkgrel+1, sha only for *.tar.gz
+  if _commit == commit
+    check_pinned: pkgver and git sha must match the commit, else blocked
+  source_pkgver                               # CONTRIBUTING.md "Releases"
+    omarchy-mac       -> omarchy-mac/version at commit
+    omarchy-mac-boot  -> TZ=UTC0 commit date (%Y%m%d)
+  pin_recipe dir commit "" pkgver $v          # pkgrel=1 when pkgver moves
+    git+...#commit= source -> git_source_sha256

git_source_sha256 (lib/omacom.sh) does what makepkg 7.1's source/git.sh does: no global or system git config, * -export-subst -export-ignore in the clone's info/attributes, then sha256 of git -c core.abbrev=no archive --format tar <commit>. If any other source of the commit has a non-SKIP checksum the pin can't compute, it stops instead of leaving a stale checksum. The dry-run plan now prints the new sha256sums[0].

Evidence

  • Before: --package omarchy-mac b2c3985 proposed 0.1.0-12 -> 0.1.0-13 and kept the old sha, so prepare() and the checksum would both fail.
    After: pinning a 0.1.0-12 @ 2a3ed89 recipe to b2c3985 gives 0.1.1-1, sha 40bf12c3….
  • Checksums match makepkg:
    • 5b2c815 -> d44aadb3… (omarchy-pkgs #927)
    • 162f359 -> 31be04e5… (current boot recipe)
    • b2c3985 -> 40bf12c3…, 2a3ed89 -> ab951984… (makepkg -g)
    • an export-ignore/export-subst fixture -> c472510a… (makepkg -g, Arch ARM)
  • Both pinned recipes pass makepkg -o (sha256 "Passed" + prepare()) in the Arch ARM builder container.
  • Real dry runs at 5b2c815:
    • omarchy-mac: pin: nothing to move (and the pkgver and sha check passes)
    • omarchy-mac-boot: 20261008-1 -> 20261010-1 (_commit -> 5b2c815f007d, sha256sums[0] -> d44aadb3e396…)

Test plan

  • tools/release/test/omacom-lane (new: same version bumps pkgrel; version bump sets pkgver and pkgrel=1; boot pkgver is the UTC date, not the local one; makepkg fixture under a hostile tar.umask/autocrlf config; known real pairs, skipped on a shallow checkout; stale or uncomputable checksums refused; unusable version file blocks; already-pinned stale recipe blocks)
  • tools/release/test/candidate-set
  • omacom-lane in the Arch ARM container (Linux git 2.55)
  • fork-parity fails the same way on main (fork asahi-release scenario); not touched

Merge Danger

Door: two-way

Tooling only. Nothing runs until an operator runs mac-release without --dry-run, and even then its output is a PR the owner merges.

Blast Radius: release-tooling

Pin PRs on omacom/omarchy-pkgs now also change pkgver and sha256sums, which the recipes need in order to build. Advance and x86_64 handling are unchanged.

The Mac recipes source omarchy-mac-pkgs as git+...#commit=${_commit} with a
real sha256, but the pin only rewrote checksums of .tar.gz archives, so a
pin kept the old commit's checksum and makepkg refused the build.

makepkg's calc_checksum_git hashes `git -c core.abbrev=no archive --format
tar <commit>` from a mirror whose info/attributes disable export-ignore and
export-subst, with no global or system git configuration. The pin now does
the same from the source clone, and refuses any other source of the commit
whose checksum it cannot compute instead of leaving it stale.
A pin only bumped pkgrel, so pinning omarchy-mac across a version bump
proposed 0.1.0-13 for a tree whose omarchy-mac/version is 0.1.1, which the
recipe's prepare() rejects; omarchy-mac-boot's pkgver, the UTC date of the
pinned commit, never moved either.

The pin now takes pkgver as CONTRIBUTING.md "Releases" defines it,
omarchy-mac/version at the commit for omarchy-mac and the commit's UTC date
for omarchy-mac-boot, and resets pkgrel to 1 when it changes. A value that
cannot be a pkgver, or a source package without a rule, blocks the pin.
A recipe that pinned the commit before the pin set pkgver and git
checksums read as nothing to move, though its build fails in prepare() or
on the checksum, and every later run waited for a publication that could
not come. Such a recipe now blocks the pin with what to fix. A version file
that cannot be read now says why instead of reading as missing.
@maralcbr
maralcbr requested a review from scottjones as a code owner October 10, 2026 08:37
@maralcbr
maralcbr merged commit 85643f1 into main Oct 10, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant