Watch
1
0
Fork
You've already forked souveraine-lens
0

package: ask the distribution before publishing

This commit is contained in:
Fimeg 2026-08-24 23:08:42 -04:00
commit f8c9df352b
4 changed files with 98 additions and 32 deletions

View file

@ -1,10 +1,9 @@
name: ci
# CI for souveraine-lens — Rust crate. Tests + clippy, then the gates, then
# the package: on primary, an archdev job builds the release binary, assembles
# a signed pacman package and publishes it into the shared edge archive
# (Fimeg/souveraine), where a machine with the souveraine-x86_64 repo
# configured installs it by name. Green on primary means built, gated and
# packaged.
# the package: on primary, two archdev jobs build the x86_64 and AArch64
# release binaries, assemble signed pacman packages and publish them into the
# shared edge archive (Fimeg/souveraine). Green on primary means both declared
# package paths built, passed their ownership gates and published.
on:
push:
branches: [primary]
@ -144,6 +143,30 @@ jobs:
gpg --batch --yes --local-user "$ARCHIVE_KEY" \
--detach-sign "$REPO/$(basename "$PKG")"
- name: Validate package ownership
env:
LOCAL_GITEA_TOKEN: ${{ secrets.LOCAL_GITEA_TOKEN }}
run: |
set -euo pipefail
test -n "$LOCAL_GITEA_TOKEN" \
|| { echo "LOCAL_GITEA_TOKEN is required for the distribution contract" >&2; exit 1; }
CONTRACT="$GITHUB_WORKSPACE/SouveraineOS"
rm -rf "$CONTRACT"
git -c http.extraheader="Authorization: token $LOCAL_GITEA_TOKEN" \
clone --depth 1 --branch public \
"${GITHUB_SERVER_URL}/Fimeg/SouveraineOS.git" "$CONTRACT"
PKG=$(find "$GITHUB_WORKSPACE/pacman-repo/x86_64" -maxdepth 1 \
-name 'souveraine-lens-*.pkg.tar.zst' -print -quit)
test -n "$PKG"
NAME=$(bsdtar -xOf "$PKG" .PKGINFO | awk '$1 == "pkgname" { print $3; exit }')
ARCH=$(bsdtar -xOf "$PKG" .PKGINFO | awk '$1 == "arch" { print $3; exit }')
test "$NAME" = souveraine-lens
test "$ARCH" = x86_64
python3 "$CONTRACT/tools/validate-distribution.py" \
"$CONTRACT/distribution/manifest.toml" \
--producer souveraine-lens \
--artifact "$NAME:$ARCH"
- name: Publish into the edge archive
env:
# A PAT rather than the job's own GITHUB_TOKEN, so the identical
@ -165,10 +188,9 @@ jobs:
souveraine-lens "$GITHUB_WORKSPACE/pacman-repo"
package-aarch64:
# Same gates and archive, for the phone. The phone is a full substrate
# device already: pacman reads souveraine-aarch64, the netrc exists, and
# webkit2gtk-4.1 + gtk3 are installed — only the lens never shipped there.
# Cross-compiles against the runner sysroot, the usb-signaller shape.
# Same gates and archive, with an AArch64 cross-build against the runner
# sysroot. A green job proves its package path; install and runtime on a
# device remain separate evidence.
runs-on: archdev
needs: [rust-test, no-ai-attribution, action-pins]
if: github.event_name == 'push' && github.ref == 'refs/heads/primary'
@ -247,6 +269,30 @@ jobs:
gpg --batch --yes --local-user "$ARCHIVE_KEY" \
--detach-sign "$REPO/$(basename "$PKG")"
- name: Validate package ownership
env:
LOCAL_GITEA_TOKEN: ${{ secrets.LOCAL_GITEA_TOKEN }}
run: |
set -euo pipefail
test -n "$LOCAL_GITEA_TOKEN" \
|| { echo "LOCAL_GITEA_TOKEN is required for the distribution contract" >&2; exit 1; }
CONTRACT="$GITHUB_WORKSPACE/SouveraineOS"
rm -rf "$CONTRACT"
git -c http.extraheader="Authorization: token $LOCAL_GITEA_TOKEN" \
clone --depth 1 --branch public \
"${GITHUB_SERVER_URL}/Fimeg/SouveraineOS.git" "$CONTRACT"
PKG=$(find "$GITHUB_WORKSPACE/pacman-repo/aarch64" -maxdepth 1 \
-name 'souveraine-lens-*.pkg.tar.zst' -print -quit)
test -n "$PKG"
NAME=$(bsdtar -xOf "$PKG" .PKGINFO | awk '$1 == "pkgname" { print $3; exit }')
ARCH=$(bsdtar -xOf "$PKG" .PKGINFO | awk '$1 == "arch" { print $3; exit }')
test "$NAME" = souveraine-lens
test "$ARCH" = aarch64
python3 "$CONTRACT/tools/validate-distribution.py" \
"$CONTRACT/distribution/manifest.toml" \
--producer souveraine-lens \
--artifact "$NAME:$ARCH"
- name: Publish into the edge archive
env:
EDGE_TOKEN: ${{ secrets.LOCAL_GITEA_TOKEN }}
@ -260,4 +306,4 @@ jobs:
git -C "$GITHUB_WORKSPACE/publisher" checkout "$PUBLISHER_SHA"
export PRODUCER_VERSION="0.1.r$(git -C "$GITHUB_WORKSPACE/src/lens" rev-list --count HEAD).g${GITHUB_SHA:0:12}"
"$GITHUB_WORKSPACE/publisher/packaging/arch/publish-edge.sh" \
souveraine-lens "$GITHUB_WORKSPACE/pacman-repo"
souveraine-lens "$GITHUB_WORKSPACE/pacman-repo"

View file

@ -3,6 +3,7 @@ name = "souveraine-lens"
version = "0.1.0"
edition = "2021"
description = "A wry mind-graph lens over a git-backed markdown vault"
license = "AGPL-3.0-or-later"
[dependencies]
anyhow = "1"
@ -14,4 +15,4 @@ wry = "0.56"
[profile.release]
lto = true
strip = true
strip = true

View file

@ -225,28 +225,42 @@ The vault stays the one thing with no other readers.
## Delivery
Nothing ships until it has been loved on hardware — but the lens has been
built on a laptop and driven over a socket; the missing step is that it be a
*package*. The shape:
A recipe establishes a path. Delivery crosses source, package, archive,
install, then exercised behavior — each proved separately.
As observed on 2026-08-24, r18 is a signed package in the internal x86_64 edge
repository and owns the installed laptop binary. The current source head is
r19 (`216faea`), which has not replaced that package.
- **Source of truth**: the `primary` branch; green CI (test + clippy + the
attribution and action-pin gates) is the bar, on the same Gitea the
substrate uses. No local builds anywhere; CI is the only compiler gate.
substrate uses. Gitea Actions is the compiler and package gate; the laptop is
an install and runtime target, not an alternate release builder.
- **Composition authority**: SouveraineOS's `distribution/manifest.toml` names
Lens as one producer of the x86_64 and AArch64 packages. Each package job
reads the package's own metadata and must pass the canonical manifest
validator before its publisher runs. Lens has no device-profile membership
yet.
- **Package**: a `packaging/arch/PKGBUILD` in the house's prebuilt style —
CI assembles the release binary, checks it is a real x86-64 ELF, and
CI assembles a release binary, checks its target architecture, and
declares the `LENS_PKGVER` version `0.1.r<commits>.g<sha12>`. The package
owns `/usr/bin/souveraine-lens`, the desktop entry and the icon; the
binary is the durable result, never a home-directory symlink.
- **The runner**: the archdev label, self-provisioning its deps
(webkit2gtk, gtk3) — it cannot be assumed preinstalled, and it is not
reachable from here to check.
- **Delivery**: the package and its signature land in the shared edge archive
(`Fimeg/souveraine`) through the canonical `publish-edge.sh` — a read-
modify-write of the live `souveraine-x86_64` database under a single flock,
signed with the house archive key, one producer's packages never touching
another's. The laptop installs by name: `pacman -S souveraine-lens`.
- **The build machine is Gitea, never the laptop**: the laptop has 93% disk
and is not an alternate release builder. It installs, launches and reads.
- **x86_64 proof**: r18 (`0.1.r18.g1eb2840df769-1`) is present by name in
`souveraine-x86_64`, has a validated signature, and is package-owned on the
laptop. That proves r18 packaging and installation; it says nothing about
the unshipped r19 changes.
- **AArch64 boundary**: the second job cross-compiles against an AArch64
sysroot and assembles the same package name for `souveraine-aarch64`. Until a
run, archive artifact, package-owned install and device exercise are checked,
that is a source path rather than AArch64 build, install or runtime proof.
- **Delivery**: the canonical `publish-edge.sh` performs a read-modify-write of
the architecture's live database under one flock, signed with the house
archive key, so one producer's packages do not replace another's.
- **License and source URL**: the repo and package carry AGPL-3.0-or-later and
install the license text. Cargo names the same SPDX license. Repository
metadata and the PKGBUILD URL remain on the internal source authority until
an anonymous `souveraine-lens` Forge projection exists; a future public URL
must resolve before either points at it.
## Future
@ -256,4 +270,4 @@ built on a laptop and driven over a socket; the missing step is that it be a
- The shared-task lane, when TASK-68's authority shape lands: the agent
assigns human tasks through the vault; the lens surfaces them as notes.
- Typed links, if the grammar is worth changing — see above.
- A LICENSE for this repo, matching the substrate's AGPL-3.0.
- Public Forge projection and anonymous source URLs.

View file

@ -55,10 +55,10 @@ The vault stays the one thing with no other readers.
## Package
On a push to `primary`, CI builds the release binary on the archdev runner,
assembles a signed `souveraine-lens` pacman package and publishes it into the
shared edge archive (`Fimeg/souveraine`) — the same archive the substrate and
the viewtop publish into. A machine with the `souveraine-x86_64` repo
On a push to `primary`, CI has separate x86_64 and AArch64 package jobs. Each
assembles a signed `souveraine-lens` pacman package, checks the emitted package
against SouveraineOS's distribution manifest, then publishes into the shared
edge archive (`Fimeg/souveraine`). A machine with the matching repository
configured and the house key trusted installs it by name:
```sh
@ -67,4 +67,9 @@ sudo pacman -Syu souveraine-lens
The package owns `/usr/bin/souveraine-lens`, the desktop entry and the icon;
the vault remains a home-directory git tree pacman never touches. The design
argument lives in `DESIGN.md`.
argument lives in `DESIGN.md`.
Current proof, 2026-08-24: x86_64 r18 is signed, indexed and installed as
`0.1.r18.g1eb2840df769-1`. Source `primary` is r19 (`216faea`) and has not yet
replaced that package. The AArch64 workflow is a build path, not evidence of a
published, installed or running AArch64 Lens.