From c47aa209bee01a9a6fc6a5b98111b635bb369754 Mon Sep 17 00:00:00 2001 From: William Mantly Date: Thu, 16 Jul 2026 14:01:41 -0400 Subject: [PATCH] setup.sh: pin submodules to their latest release tag, not master's tip Both proxy and sso-manager-node now publish real vX.Y.Z tags (see their own release history). Track those instead of following the branch tip with `git submodule update --remote`, so a rebuild always lands on a tagged, versioned release rather than whatever commit happened to be most recently merged upstream. Bumps the submodule pins to their current latest tags as a result: proxy -> v1.1.1, sso-manager-node -> v1.1.1. --- README.md | 9 ++++---- proxy | 2 +- setup.sh | 57 ++++++++++++++++++++++++++++++------------------ sso-manager-node | 2 +- 4 files changed, 43 insertions(+), 27 deletions(-) diff --git a/README.md b/README.md index 4ff880f..f9de4d1 100644 --- a/README.md +++ b/README.md @@ -471,7 +471,8 @@ theta-env/ gitignored `./config/` (`sso-secrets.js` + `proxy-secrets.js`) and snapshots to the gitignored `./backups/` before each rebuild. -`./setup.sh` updates both submodules to the latest of their tracked remote -branch before building, so each run builds current upstream — no manual -`git submodule update --remote` needed. To lock to the pinned commits (offline -rebuild, or a deliberate pin), run `SKIP_SUBMODULE_UPDATE=1 ./setup.sh`. \ No newline at end of file +`./setup.sh` updates both submodules to their latest `vX.Y.Z` release tag +before building — not the tip of `master` — so each run builds the newest +tagged release of each app, not whatever's most recently merged upstream. To +lock to the pinned commits (offline rebuild, or a deliberate pin), run +`SKIP_SUBMODULE_UPDATE=1 ./setup.sh`. \ No newline at end of file diff --git a/proxy b/proxy index 8deecdb..5a685e9 160000 --- a/proxy +++ b/proxy @@ -1 +1 @@ -Subproject commit 8deecdba73ddadc1b3b65ba85cd6a2e7c91f7d8c +Subproject commit 5a685e9dd71d8c5d0dd518266d8664379e8e3a95 diff --git a/setup.sh b/setup.sh index aca61a3..1b7651a 100755 --- a/setup.sh +++ b/setup.sh @@ -146,32 +146,47 @@ then fi fi -# ── 1. Update submodules to latest, verify build contexts ───────────────────── +# ── 1. Update submodules to their latest release tag, verify build contexts ─── +# Submodules track release tags (vX.Y.Z), not the tip of master -- so +# "update" means "move to the newest tag", not "move to the newest commit". +# `git submodule update --init --recursive` (no --remote) only clones a +# missing submodule at its currently-pinned commit; it never advances it on +# its own, so the per-submodule tag resolution below is what actually moves +# proxy/sso-manager-node forward. if [[ "${SKIP_SUBMODULE_UPDATE:-0}" != "1" ]]; then if ! command -v git >/dev/null 2>&1; then die "git not found. Install git, or set SKIP_SUBMODULE_UPDATE=1 to build the pinned submodule commits." fi - info "Updating submodules to latest (sso-manager-node, proxy)..." - # Record each submodule's pinned commit before pulling so we can tell the - # operator exactly what moved (or didn't) -- `git submodule update` itself - # is quiet about this, and it's the only real "did anything change" signal - # available to a script that isn't watching GitHub releases. - declare -A SUBMODULE_BEFORE_REV=() - for sm in sso-manager-node proxy; do - [[ -d "$sm" ]] && SUBMODULE_BEFORE_REV["$sm"]="$(git -C "$sm" rev-parse HEAD 2>/dev/null || true)" - done - if ! git submodule update --init --remote --recursive 2>&1; then - warn "git submodule update failed (offline?) — continuing with the currently checked-out code." - else - for sm in sso-manager-node proxy; do - [[ -d "$sm" ]] || continue - after_rev="$(git -C "$sm" rev-parse HEAD 2>/dev/null || true)" - before_rev="${SUBMODULE_BEFORE_REV[$sm]:-}" - if [[ -n "$before_rev" && -n "$after_rev" && "$before_rev" != "$after_rev" ]]; then - info " ${sm}: updated ${before_rev:0:12} -> ${after_rev:0:12}" - fi - done + if ! git submodule update --init --recursive 2>&1; then + die "git submodule update --init failed. Run manually: git submodule update --init --recursive" fi + + info "Updating submodules to their latest release tag (sso-manager-node, proxy)..." + for sm in sso-manager-node proxy; do + [[ -d "$sm" ]] || continue + before_rev="$(git -C "$sm" rev-parse HEAD 2>/dev/null || true)" + + if ! git -C "$sm" fetch --tags -q 2>&1; then + warn " ${sm}: could not fetch tags (offline?) — staying on the current pin." + continue + fi + + latest_tag="$(git -C "$sm" tag --list 'v*' --sort=-v:refname | head -n1)" + if [[ -z "$latest_tag" ]]; then + warn " ${sm}: no vX.Y.Z release tags found — staying on the current pin." + continue + fi + + if ! git -C "$sm" checkout -q "$latest_tag" 2>&1; then + warn " ${sm}: could not check out ${latest_tag} — staying on the current pin." + continue + fi + + after_rev="$(git -C "$sm" rev-parse HEAD 2>/dev/null || true)" + if [[ "$before_rev" != "$after_rev" ]]; then + info " ${sm}: updated to ${latest_tag} (${before_rev:0:12} -> ${after_rev:0:12})" + fi + done else info "Skipping submodule update (SKIP_SUBMODULE_UPDATE=1)." fi diff --git a/sso-manager-node b/sso-manager-node index c3e086f..65e43a5 160000 --- a/sso-manager-node +++ b/sso-manager-node @@ -1 +1 @@ -Subproject commit c3e086fc7b00957c903eeafc0e9f1c38223db85d +Subproject commit 65e43a5677f7161d18b84767457deacd18cc4996