package: ask the distribution before publishing
This commit is contained in:
parent
216faea032
commit
f8c9df352b
4 changed files with 98 additions and 32 deletions
|
|
@ -1,10 +1,9 @@
|
|||
name: ci
|
||||
# CI for souveraine-lens — Rust crate. Tests + clippy, then the gates, then
|
||||
# the package: on primary, an archdev job builds the release binary, assembles
|
||||
# a signed pacman package and publishes it into the shared edge archive
|
||||
# (Fimeg/souveraine), where a machine with the souveraine-x86_64 repo
|
||||
# configured installs it by name. Green on primary means built, gated and
|
||||
# packaged.
|
||||
# the package: on primary, two archdev jobs build the x86_64 and AArch64
|
||||
# release binaries, assemble signed pacman packages and publish them into the
|
||||
# shared edge archive (Fimeg/souveraine). Green on primary means both declared
|
||||
# package paths built, passed their ownership gates and published.
|
||||
on:
|
||||
push:
|
||||
branches: [primary]
|
||||
|
|
@ -144,6 +143,30 @@ jobs:
|
|||
gpg --batch --yes --local-user "$ARCHIVE_KEY" \
|
||||
--detach-sign "$REPO/$(basename "$PKG")"
|
||||
|
||||
- name: Validate package ownership
|
||||
env:
|
||||
LOCAL_GITEA_TOKEN: ${{ secrets.LOCAL_GITEA_TOKEN }}
|
||||
run: |
|
||||
set -euo pipefail
|
||||
test -n "$LOCAL_GITEA_TOKEN" \
|
||||
|| { echo "LOCAL_GITEA_TOKEN is required for the distribution contract" >&2; exit 1; }
|
||||
CONTRACT="$GITHUB_WORKSPACE/SouveraineOS"
|
||||
rm -rf "$CONTRACT"
|
||||
git -c http.extraheader="Authorization: token $LOCAL_GITEA_TOKEN" \
|
||||
clone --depth 1 --branch public \
|
||||
"${GITHUB_SERVER_URL}/Fimeg/SouveraineOS.git" "$CONTRACT"
|
||||
PKG=$(find "$GITHUB_WORKSPACE/pacman-repo/x86_64" -maxdepth 1 \
|
||||
-name 'souveraine-lens-*.pkg.tar.zst' -print -quit)
|
||||
test -n "$PKG"
|
||||
NAME=$(bsdtar -xOf "$PKG" .PKGINFO | awk '$1 == "pkgname" { print $3; exit }')
|
||||
ARCH=$(bsdtar -xOf "$PKG" .PKGINFO | awk '$1 == "arch" { print $3; exit }')
|
||||
test "$NAME" = souveraine-lens
|
||||
test "$ARCH" = x86_64
|
||||
python3 "$CONTRACT/tools/validate-distribution.py" \
|
||||
"$CONTRACT/distribution/manifest.toml" \
|
||||
--producer souveraine-lens \
|
||||
--artifact "$NAME:$ARCH"
|
||||
|
||||
- name: Publish into the edge archive
|
||||
env:
|
||||
# A PAT rather than the job's own GITHUB_TOKEN, so the identical
|
||||
|
|
@ -165,10 +188,9 @@ jobs:
|
|||
souveraine-lens "$GITHUB_WORKSPACE/pacman-repo"
|
||||
|
||||
package-aarch64:
|
||||
# Same gates and archive, for the phone. The phone is a full substrate
|
||||
# device already: pacman reads souveraine-aarch64, the netrc exists, and
|
||||
# webkit2gtk-4.1 + gtk3 are installed — only the lens never shipped there.
|
||||
# Cross-compiles against the runner sysroot, the usb-signaller shape.
|
||||
# Same gates and archive, with an AArch64 cross-build against the runner
|
||||
# sysroot. A green job proves its package path; install and runtime on a
|
||||
# device remain separate evidence.
|
||||
runs-on: archdev
|
||||
needs: [rust-test, no-ai-attribution, action-pins]
|
||||
if: github.event_name == 'push' && github.ref == 'refs/heads/primary'
|
||||
|
|
@ -247,6 +269,30 @@ jobs:
|
|||
gpg --batch --yes --local-user "$ARCHIVE_KEY" \
|
||||
--detach-sign "$REPO/$(basename "$PKG")"
|
||||
|
||||
- name: Validate package ownership
|
||||
env:
|
||||
LOCAL_GITEA_TOKEN: ${{ secrets.LOCAL_GITEA_TOKEN }}
|
||||
run: |
|
||||
set -euo pipefail
|
||||
test -n "$LOCAL_GITEA_TOKEN" \
|
||||
|| { echo "LOCAL_GITEA_TOKEN is required for the distribution contract" >&2; exit 1; }
|
||||
CONTRACT="$GITHUB_WORKSPACE/SouveraineOS"
|
||||
rm -rf "$CONTRACT"
|
||||
git -c http.extraheader="Authorization: token $LOCAL_GITEA_TOKEN" \
|
||||
clone --depth 1 --branch public \
|
||||
"${GITHUB_SERVER_URL}/Fimeg/SouveraineOS.git" "$CONTRACT"
|
||||
PKG=$(find "$GITHUB_WORKSPACE/pacman-repo/aarch64" -maxdepth 1 \
|
||||
-name 'souveraine-lens-*.pkg.tar.zst' -print -quit)
|
||||
test -n "$PKG"
|
||||
NAME=$(bsdtar -xOf "$PKG" .PKGINFO | awk '$1 == "pkgname" { print $3; exit }')
|
||||
ARCH=$(bsdtar -xOf "$PKG" .PKGINFO | awk '$1 == "arch" { print $3; exit }')
|
||||
test "$NAME" = souveraine-lens
|
||||
test "$ARCH" = aarch64
|
||||
python3 "$CONTRACT/tools/validate-distribution.py" \
|
||||
"$CONTRACT/distribution/manifest.toml" \
|
||||
--producer souveraine-lens \
|
||||
--artifact "$NAME:$ARCH"
|
||||
|
||||
- name: Publish into the edge archive
|
||||
env:
|
||||
EDGE_TOKEN: ${{ secrets.LOCAL_GITEA_TOKEN }}
|
||||
|
|
@ -260,4 +306,4 @@ jobs:
|
|||
git -C "$GITHUB_WORKSPACE/publisher" checkout "$PUBLISHER_SHA"
|
||||
export PRODUCER_VERSION="0.1.r$(git -C "$GITHUB_WORKSPACE/src/lens" rev-list --count HEAD).g${GITHUB_SHA:0:12}"
|
||||
"$GITHUB_WORKSPACE/publisher/packaging/arch/publish-edge.sh" \
|
||||
souveraine-lens "$GITHUB_WORKSPACE/pacman-repo"
|
||||
souveraine-lens "$GITHUB_WORKSPACE/pacman-repo"
|
||||
|
|
|
|||
|
|
@ -3,6 +3,7 @@ name = "souveraine-lens"
|
|||
version = "0.1.0"
|
||||
edition = "2021"
|
||||
description = "A wry mind-graph lens over a git-backed markdown vault"
|
||||
license = "AGPL-3.0-or-later"
|
||||
|
||||
[dependencies]
|
||||
anyhow = "1"
|
||||
|
|
@ -14,4 +15,4 @@ wry = "0.56"
|
|||
|
||||
[profile.release]
|
||||
lto = true
|
||||
strip = true
|
||||
strip = true
|
||||
|
|
|
|||
46
DESIGN.md
46
DESIGN.md
|
|
@ -225,28 +225,42 @@ The vault stays the one thing with no other readers.
|
|||
|
||||
## Delivery
|
||||
|
||||
Nothing ships until it has been loved on hardware — but the lens has been
|
||||
built on a laptop and driven over a socket; the missing step is that it be a
|
||||
*package*. The shape:
|
||||
A recipe establishes a path. Delivery crosses source, package, archive,
|
||||
install, then exercised behavior — each proved separately.
|
||||
As observed on 2026-08-24, r18 is a signed package in the internal x86_64 edge
|
||||
repository and owns the installed laptop binary. The current source head is
|
||||
r19 (`216faea`), which has not replaced that package.
|
||||
|
||||
- **Source of truth**: the `primary` branch; green CI (test + clippy + the
|
||||
attribution and action-pin gates) is the bar, on the same Gitea the
|
||||
substrate uses. No local builds anywhere; CI is the only compiler gate.
|
||||
substrate uses. Gitea Actions is the compiler and package gate; the laptop is
|
||||
an install and runtime target, not an alternate release builder.
|
||||
- **Composition authority**: SouveraineOS's `distribution/manifest.toml` names
|
||||
Lens as one producer of the x86_64 and AArch64 packages. Each package job
|
||||
reads the package's own metadata and must pass the canonical manifest
|
||||
validator before its publisher runs. Lens has no device-profile membership
|
||||
yet.
|
||||
- **Package**: a `packaging/arch/PKGBUILD` in the house's prebuilt style —
|
||||
CI assembles the release binary, checks it is a real x86-64 ELF, and
|
||||
CI assembles a release binary, checks its target architecture, and
|
||||
declares the `LENS_PKGVER` version `0.1.r<commits>.g<sha12>`. The package
|
||||
owns `/usr/bin/souveraine-lens`, the desktop entry and the icon; the
|
||||
binary is the durable result, never a home-directory symlink.
|
||||
- **The runner**: the archdev label, self-provisioning its deps
|
||||
(webkit2gtk, gtk3) — it cannot be assumed preinstalled, and it is not
|
||||
reachable from here to check.
|
||||
- **Delivery**: the package and its signature land in the shared edge archive
|
||||
(`Fimeg/souveraine`) through the canonical `publish-edge.sh` — a read-
|
||||
modify-write of the live `souveraine-x86_64` database under a single flock,
|
||||
signed with the house archive key, one producer's packages never touching
|
||||
another's. The laptop installs by name: `pacman -S souveraine-lens`.
|
||||
- **The build machine is Gitea, never the laptop**: the laptop has 93% disk
|
||||
and is not an alternate release builder. It installs, launches and reads.
|
||||
- **x86_64 proof**: r18 (`0.1.r18.g1eb2840df769-1`) is present by name in
|
||||
`souveraine-x86_64`, has a validated signature, and is package-owned on the
|
||||
laptop. That proves r18 packaging and installation; it says nothing about
|
||||
the unshipped r19 changes.
|
||||
- **AArch64 boundary**: the second job cross-compiles against an AArch64
|
||||
sysroot and assembles the same package name for `souveraine-aarch64`. Until a
|
||||
run, archive artifact, package-owned install and device exercise are checked,
|
||||
that is a source path rather than AArch64 build, install or runtime proof.
|
||||
- **Delivery**: the canonical `publish-edge.sh` performs a read-modify-write of
|
||||
the architecture's live database under one flock, signed with the house
|
||||
archive key, so one producer's packages do not replace another's.
|
||||
- **License and source URL**: the repo and package carry AGPL-3.0-or-later and
|
||||
install the license text. Cargo names the same SPDX license. Repository
|
||||
metadata and the PKGBUILD URL remain on the internal source authority until
|
||||
an anonymous `souveraine-lens` Forge projection exists; a future public URL
|
||||
must resolve before either points at it.
|
||||
|
||||
## Future
|
||||
|
||||
|
|
@ -256,4 +270,4 @@ built on a laptop and driven over a socket; the missing step is that it be a
|
|||
- The shared-task lane, when TASK-68's authority shape lands: the agent
|
||||
assigns human tasks through the vault; the lens surfaces them as notes.
|
||||
- Typed links, if the grammar is worth changing — see above.
|
||||
- A LICENSE for this repo, matching the substrate's AGPL-3.0.
|
||||
- Public Forge projection and anonymous source URLs.
|
||||
|
|
|
|||
15
README.md
15
README.md
|
|
@ -55,10 +55,10 @@ The vault stays the one thing with no other readers.
|
|||
|
||||
## Package
|
||||
|
||||
On a push to `primary`, CI builds the release binary on the archdev runner,
|
||||
assembles a signed `souveraine-lens` pacman package and publishes it into the
|
||||
shared edge archive (`Fimeg/souveraine`) — the same archive the substrate and
|
||||
the viewtop publish into. A machine with the `souveraine-x86_64` repo
|
||||
On a push to `primary`, CI has separate x86_64 and AArch64 package jobs. Each
|
||||
assembles a signed `souveraine-lens` pacman package, checks the emitted package
|
||||
against SouveraineOS's distribution manifest, then publishes into the shared
|
||||
edge archive (`Fimeg/souveraine`). A machine with the matching repository
|
||||
configured and the house key trusted installs it by name:
|
||||
|
||||
```sh
|
||||
|
|
@ -67,4 +67,9 @@ sudo pacman -Syu souveraine-lens
|
|||
|
||||
The package owns `/usr/bin/souveraine-lens`, the desktop entry and the icon;
|
||||
the vault remains a home-directory git tree pacman never touches. The design
|
||||
argument lives in `DESIGN.md`.
|
||||
argument lives in `DESIGN.md`.
|
||||
|
||||
Current proof, 2026-08-24: x86_64 r18 is signed, indexed and installed as
|
||||
`0.1.r18.g1eb2840df769-1`. Source `primary` is r19 (`216faea`) and has not yet
|
||||
replaced that package. The AArch64 workflow is a build path, not evidence of a
|
||||
published, installed or running AArch64 Lens.
|
||||
|
|
|
|||
Loading…
Reference in a new issue