Watch
1
0
Fork
You've already forked souveraine-updater
0

package the pacman transfer shim and stamp the packager

The XferCommand every repo transfers through lived unowned under
/usr/local, so no update could reach it. Its hardcoded host is gone —
curl already scopes a netrc to the machines it names. Unset PACKAGER
is why the archive signs packages reading "Unknown Packager".
This commit is contained in:
Fimeg 2026-08-26 14:41:30 -04:00
commit 1231cbb827
3 changed files with 46 additions and 3 deletions

View file

@ -110,6 +110,10 @@ jobs:
- name: Package and sign
env:
ARCHIVE_KEY: 3CD9E99E222C2A174986FC9AFF4949AA20C8E911
# makepkg stamps this into .PKGINFO and leaves "Unknown Packager"
# when it is unset — which is what the archive shipped until now, on
# packages the same job signs. Matches the archive key's own uid.
PACKAGER: "Souveraine Package Archive <packages@souveraine.local>"
run: |
set -euo pipefail
cd "$GITHUB_WORKSPACE/souveraine-updater"
@ -125,6 +129,7 @@ jobs:
cp "souveraine-updater-$ARCH" "$PKG_WORK/souveraine-updater-binary"
cp updater-ui/net.souveraine.Updater.svg "$PKG_WORK/"
cp packaging/net.souveraine.Updater.desktop "$PKG_WORK/"
cp packaging/souveraine-pacman-fetch "$PKG_WORK/"
cp LICENSE "$PKG_WORK/"
cp packaging/PKGBUILD.prebuilt "$PKG_WORK/PKGBUILD"
(
@ -137,6 +142,13 @@ jobs:
test -n "$PKG"
bsdtar -tf "$PKG" | grep -qx 'usr/bin/souveraine-updater'
bsdtar -tf "$PKG" | grep -qx 'usr/share/applications/net.souveraine.Updater.desktop'
bsdtar -tf "$PKG" | grep -qx 'usr/lib/souveraine-updater/pacman-fetch'
# A makepkg.conf on the runner outranks the environment, so assert
# the stamp landed rather than trusting the export above.
bsdtar -xOf "$PKG" .PKGINFO | grep -q '^packager = Souveraine Package Archive' || {
echo "::error::PACKAGER did not reach .PKGINFO — check makepkg.conf on the runner"
exit 1
}
cp "$PKG" "$ARCH_REPO/"
gpg --batch --yes --local-user "$ARCHIVE_KEY" \
--detach-sign "$ARCH_REPO/$(basename "$PKG")"

View file

@ -13,8 +13,9 @@ url="https://forge.caseytunturi.com/Fimeg/souveraine-updater"
license=('GPL-2.0-only')
# qt6-svg supplies the image-format plugin that renders the app icon; without
# it the sidebar logo silently fails to load. polkit provides pkexec, which is
# how every privileged pacman call escalates.
depends=('gcc-libs' 'qt6-base' 'qt6-declarative' 'qt6-svg' 'pacman' 'polkit')
# how every privileged pacman call escalates. curl is the transfer program in
# pacman-fetch — pacman itself links libcurl and does not pull the binary in.
depends=('gcc-libs' 'qt6-base' 'qt6-declarative' 'qt6-svg' 'pacman' 'polkit' 'curl')
optdepends=('pacman-contrib: paccache cleaning'
'reflector: mirror rating')
# The old Python implementation. Two package managers on one phone is how you
@ -27,11 +28,17 @@ options=('!strip' '!debug')
source=('souveraine-updater-binary'
'net.souveraine.Updater.svg'
'net.souveraine.Updater.desktop'
'souveraine-pacman-fetch'
'LICENSE')
sha256sums=('SKIP' 'SKIP' 'SKIP' 'SKIP')
sha256sums=('SKIP' 'SKIP' 'SKIP' 'SKIP' 'SKIP')
package() {
install -Dm755 "$srcdir/souveraine-updater-binary" "$pkgdir/usr/bin/souveraine-updater"
# The XferCommand every repo on the device transfers through. It was a
# hand-placed file under /usr/local for a month — load-bearing on the trust
# path and owned by no package, so no update ever reached it.
install -Dm755 "$srcdir/souveraine-pacman-fetch" \
"$pkgdir/usr/lib/souveraine-updater/pacman-fetch"
install -Dm644 "$srcdir/net.souveraine.Updater.svg" \
"$pkgdir/usr/share/icons/hicolor/scalable/apps/net.souveraine.Updater.svg"
install -Dm644 "$srcdir/net.souveraine.Updater.desktop" \

View file

@ -0,0 +1,24 @@
#!/bin/sh
#
# pacman XferCommand for SouveraineOS. Set it in pacman.conf:
#
# XferCommand = /usr/lib/souveraine-updater/pacman-fetch %o %u
#
# Two jobs. Authenticate to the archive, which is a private forge release
# endpoint rather than an anonymous mirror — curl applies the netrc only to
# hosts it names, so public mirrors are fetched anonymously and the host list
# lives in the credentials file instead of in this script.
#
# And stay quiet: the progress meter redraws with \r and no newline, so a
# frontend reading this pipe line-by-line receives the whole animation instead
# of the transfer. pacman prints its own progress; this one is noise.
set -eu
netrc=/etc/pacman.d/souveraine-gitea.netrc
if [ -r "$netrc" ]; then
exec /usr/bin/curl -L -C - -f --no-progress-meter \
--netrc-file "$netrc" -o "$1" "$2"
fi
exec /usr/bin/curl -L -C - -f --no-progress-meter -o "$1" "$2"