Watch
1
0
Fork
You've already forked souveraine-updater
0
No description
  • Rust 42.2%
  • QML 32.9%
  • Python 22%
  • Shell 2.9%
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Fimeg ccc79fefed resolve what a mutation changes before elevating
pkexec pacman -Syu authorises everything pacman would do. Operations carry
the resolved set now, hashed on RedFlag's own byte contract so a token
minted there verifies here, and re-derived before elevation: a repository
that moves while you read the prompt refuses instead of installing.
2026-08-26 15:14:53 -04:00
.cargo ci: build, package and publish into edge 2026-07-25 18:30:31 -04:00
.gitea/workflows package the pacman transfer shim and stamp the packager 2026-08-26 14:41:30 -04:00
.publication review the commit that installs the gate 2026-08-23 20:15:08 -04:00
docs/tasks resolve what a mutation changes before elevating 2026-08-26 15:14:53 -04:00
packaging package the pacman transfer shim and stamp the packager 2026-08-26 14:41:30 -04:00
scripts ci: build, package and publish into edge 2026-07-25 18:30:31 -04:00
updater-core resolve what a mutation changes before elevating 2026-08-26 15:14:53 -04:00
updater-ui resolve what a mutation changes before elevating 2026-08-26 15:14:53 -04:00
.gitignore souveraine-updater: rename from pachub fork, wire cxx-qt module 2026-07-25 17:18:58 -04:00
.publication-history-allowlist.txt review the commit that installs the gate 2026-08-23 20:15:08 -04:00
.publication-mechanism.json carry the publication gate on the candidate ref 2026-08-23 20:14:45 -04:00
Cargo.toml describe the updater and point its urls at the public forge 2026-08-23 19:39:35 -04:00
LICENSE souveraine-updater: rename from pachub fork, wire cxx-qt module 2026-07-25 17:18:58 -04:00
README.md describe the updater and point its urls at the public forge 2026-08-23 19:39:35 -04:00

souveraine-updater

The pacman frontend SouveraineOS ships. A Rust workspace: updater-core holds the package model and the privileged-operation path, updater-ui is a Qt6 Quick application with the QML embedded in the binary as a qrc module.

What it does

pacman answers four different questions with four different listings. updater-core::catalog folds them into one row per package, on a worker thread, never on the GUI thread. The package list may come off a cache; update counts never do — pacman -Qu is cheap, and a stale update count is the one thing an updater must not show.

Authority

Every system mutation leaves as an argv to pkexec, never a shell string with a package name pasted into it. The shell's polkit agent owns the prompt and enforces the capability tier. This crate refuses outright when the session is locked, and reports honestly when there is no agent to prompt with rather than appearing to succeed.

That is the same rule the rest of Souveraine runs on: holding the ability to call pacman is not authority to change the system.

Place in the system

Named in the SouveraineOS distribution contract as a producer, and present in every device profile — blueline, generic-aarch64, x86-laptop, d10 and m1. It is how a device receives anything at all, so it ships before the things it would otherwise have to install.

Building

cargo build --workspace

Needs Qt6 (qt6-base, qt6-declarative, qt6-svg) and a Rust toolchain. scripts/build-cross.sh cross-compiles for aarch64; it expects the linker and qmake shims in scripts/.

Runtime dependencies, from the package recipe: gcc-libs qt6-base qt6-declarative qt6-svg pacman polkit. qt6-svg supplies the image-format plugin that renders the app icon — without it the sidebar logo fails silently.

License

GPL-2.0-only. See LICENSE.