package the pacman transfer shim and stamp the packager
The XferCommand every repo transfers through lived unowned under /usr/local, so no update could reach it. Its hardcoded host is gone — curl already scopes a netrc to the machines it names. Unset PACKAGER is why the archive signs packages reading "Unknown Packager".
This commit is contained in:
parent
8a06f816e8
commit
1231cbb827
3 changed files with 46 additions and 3 deletions
|
|
@ -110,6 +110,10 @@ jobs:
|
|||
- name: Package and sign
|
||||
env:
|
||||
ARCHIVE_KEY: 3CD9E99E222C2A174986FC9AFF4949AA20C8E911
|
||||
# makepkg stamps this into .PKGINFO and leaves "Unknown Packager"
|
||||
# when it is unset — which is what the archive shipped until now, on
|
||||
# packages the same job signs. Matches the archive key's own uid.
|
||||
PACKAGER: "Souveraine Package Archive <packages@souveraine.local>"
|
||||
run: |
|
||||
set -euo pipefail
|
||||
cd "$GITHUB_WORKSPACE/souveraine-updater"
|
||||
|
|
@ -125,6 +129,7 @@ jobs:
|
|||
cp "souveraine-updater-$ARCH" "$PKG_WORK/souveraine-updater-binary"
|
||||
cp updater-ui/net.souveraine.Updater.svg "$PKG_WORK/"
|
||||
cp packaging/net.souveraine.Updater.desktop "$PKG_WORK/"
|
||||
cp packaging/souveraine-pacman-fetch "$PKG_WORK/"
|
||||
cp LICENSE "$PKG_WORK/"
|
||||
cp packaging/PKGBUILD.prebuilt "$PKG_WORK/PKGBUILD"
|
||||
(
|
||||
|
|
@ -137,6 +142,13 @@ jobs:
|
|||
test -n "$PKG"
|
||||
bsdtar -tf "$PKG" | grep -qx 'usr/bin/souveraine-updater'
|
||||
bsdtar -tf "$PKG" | grep -qx 'usr/share/applications/net.souveraine.Updater.desktop'
|
||||
bsdtar -tf "$PKG" | grep -qx 'usr/lib/souveraine-updater/pacman-fetch'
|
||||
# A makepkg.conf on the runner outranks the environment, so assert
|
||||
# the stamp landed rather than trusting the export above.
|
||||
bsdtar -xOf "$PKG" .PKGINFO | grep -q '^packager = Souveraine Package Archive' || {
|
||||
echo "::error::PACKAGER did not reach .PKGINFO — check makepkg.conf on the runner"
|
||||
exit 1
|
||||
}
|
||||
cp "$PKG" "$ARCH_REPO/"
|
||||
gpg --batch --yes --local-user "$ARCHIVE_KEY" \
|
||||
--detach-sign "$ARCH_REPO/$(basename "$PKG")"
|
||||
|
|
|
|||
|
|
@ -13,8 +13,9 @@ url="https://forge.caseytunturi.com/Fimeg/souveraine-updater"
|
|||
license=('GPL-2.0-only')
|
||||
# qt6-svg supplies the image-format plugin that renders the app icon; without
|
||||
# it the sidebar logo silently fails to load. polkit provides pkexec, which is
|
||||
# how every privileged pacman call escalates.
|
||||
depends=('gcc-libs' 'qt6-base' 'qt6-declarative' 'qt6-svg' 'pacman' 'polkit')
|
||||
# how every privileged pacman call escalates. curl is the transfer program in
|
||||
# pacman-fetch — pacman itself links libcurl and does not pull the binary in.
|
||||
depends=('gcc-libs' 'qt6-base' 'qt6-declarative' 'qt6-svg' 'pacman' 'polkit' 'curl')
|
||||
optdepends=('pacman-contrib: paccache cleaning'
|
||||
'reflector: mirror rating')
|
||||
# The old Python implementation. Two package managers on one phone is how you
|
||||
|
|
@ -27,11 +28,17 @@ options=('!strip' '!debug')
|
|||
source=('souveraine-updater-binary'
|
||||
'net.souveraine.Updater.svg'
|
||||
'net.souveraine.Updater.desktop'
|
||||
'souveraine-pacman-fetch'
|
||||
'LICENSE')
|
||||
sha256sums=('SKIP' 'SKIP' 'SKIP' 'SKIP')
|
||||
sha256sums=('SKIP' 'SKIP' 'SKIP' 'SKIP' 'SKIP')
|
||||
|
||||
package() {
|
||||
install -Dm755 "$srcdir/souveraine-updater-binary" "$pkgdir/usr/bin/souveraine-updater"
|
||||
# The XferCommand every repo on the device transfers through. It was a
|
||||
# hand-placed file under /usr/local for a month — load-bearing on the trust
|
||||
# path and owned by no package, so no update ever reached it.
|
||||
install -Dm755 "$srcdir/souveraine-pacman-fetch" \
|
||||
"$pkgdir/usr/lib/souveraine-updater/pacman-fetch"
|
||||
install -Dm644 "$srcdir/net.souveraine.Updater.svg" \
|
||||
"$pkgdir/usr/share/icons/hicolor/scalable/apps/net.souveraine.Updater.svg"
|
||||
install -Dm644 "$srcdir/net.souveraine.Updater.desktop" \
|
||||
|
|
|
|||
24
packaging/souveraine-pacman-fetch
Normal file
24
packaging/souveraine-pacman-fetch
Normal file
|
|
@ -0,0 +1,24 @@
|
|||
#!/bin/sh
|
||||
#
|
||||
# pacman XferCommand for SouveraineOS. Set it in pacman.conf:
|
||||
#
|
||||
# XferCommand = /usr/lib/souveraine-updater/pacman-fetch %o %u
|
||||
#
|
||||
# Two jobs. Authenticate to the archive, which is a private forge release
|
||||
# endpoint rather than an anonymous mirror — curl applies the netrc only to
|
||||
# hosts it names, so public mirrors are fetched anonymously and the host list
|
||||
# lives in the credentials file instead of in this script.
|
||||
#
|
||||
# And stay quiet: the progress meter redraws with \r and no newline, so a
|
||||
# frontend reading this pipe line-by-line receives the whole animation instead
|
||||
# of the transfer. pacman prints its own progress; this one is noise.
|
||||
set -eu
|
||||
|
||||
netrc=/etc/pacman.d/souveraine-gitea.netrc
|
||||
|
||||
if [ -r "$netrc" ]; then
|
||||
exec /usr/bin/curl -L -C - -f --no-progress-meter \
|
||||
--netrc-file "$netrc" -o "$1" "$2"
|
||||
fi
|
||||
|
||||
exec /usr/bin/curl -L -C - -f --no-progress-meter -o "$1" "$2"
|
||||
Loading…
Reference in a new issue