Watch
1
0
Fork
You've already forked souveraine-updater
0
souveraine-updater/README.md
Fimeg 14481d936a describe the updater and point its urls at the public forge
The repository had no README, which policy requires, and both Cargo.toml and
the package recipe named the internal forge -- a current-tree finding the
candidate scan cannot forgive.
2026-08-23 19:39:35 -04:00

1.8 KiB

souveraine-updater

The pacman frontend SouveraineOS ships. A Rust workspace: updater-core holds the package model and the privileged-operation path, updater-ui is a Qt6 Quick application with the QML embedded in the binary as a qrc module.

What it does

pacman answers four different questions with four different listings. updater-core::catalog folds them into one row per package, on a worker thread, never on the GUI thread. The package list may come off a cache; update counts never do — pacman -Qu is cheap, and a stale update count is the one thing an updater must not show.

Authority

Every system mutation leaves as an argv to pkexec, never a shell string with a package name pasted into it. The shell's polkit agent owns the prompt and enforces the capability tier. This crate refuses outright when the session is locked, and reports honestly when there is no agent to prompt with rather than appearing to succeed.

That is the same rule the rest of Souveraine runs on: holding the ability to call pacman is not authority to change the system.

Place in the system

Named in the SouveraineOS distribution contract as a producer, and present in every device profile — blueline, generic-aarch64, x86-laptop, d10 and m1. It is how a device receives anything at all, so it ships before the things it would otherwise have to install.

Building

cargo build --workspace

Needs Qt6 (qt6-base, qt6-declarative, qt6-svg) and a Rust toolchain. scripts/build-cross.sh cross-compiles for aarch64; it expects the linker and qmake shims in scripts/.

Runtime dependencies, from the package recipe: gcc-libs qt6-base qt6-declarative qt6-svg pacman polkit. qt6-svg supplies the image-format plugin that renders the app icon — without it the sidebar logo fails silently.

License

GPL-2.0-only. See LICENSE.