Watch
1
0
Fork
You've already forked souveraine-viewtop
0

public: cut the internal half out of the projection

Build and test stay; packaging, signing and archive publication do not, and
neither does the operator harness. Four references to the build host become
generic, package URLs point at the public forge, checkout is SHA-pinned.
This commit is contained in:
Fimeg 2026-08-23 11:38:28 -04:00
commit 4adf8c0bbb
7 changed files with 11 additions and 108 deletions

View file

@ -1,6 +1,6 @@
# Cross-compilation for the phone. Nothing is ever built on the device: the
# Pixel 3 is Casey's daily driver and a build there costs him his live system.
# archdev cross-compiles everything (SouveraineOS STATE.md).
# the cross-compilation host cross-compiles everything (SouveraineOS STATE.md).
[target.aarch64-unknown-linux-gnu]
linker = "aarch64-linux-gnu-gcc"

View file

@ -2,35 +2,22 @@ name: ci
on:
push:
branches: [main]
branches: [main, public]
pull_request:
workflow_dispatch:
# Build and test only. Packaging, signing, and archive publication run in
# the internal workflow, which this branch does not carry.
jobs:
check:
runs-on: archdev
runs-on: builder
steps:
- uses: actions/checkout@v4
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
with:
# pkgver is r<commit-count>.g<sha>. A shallow checkout stamps every
# package r1 and makes upgrades sort by hexadecimal accident.
fetch-depth: 0
- name: validate distribution contract
env:
LOCAL_GITEA_TOKEN: ${{ secrets.LOCAL_GITEA_TOKEN }}
run: |
set -euo pipefail
CONTRACT="$GITHUB_WORKSPACE/SouveraineOS"
git clone --depth 1 \
"http://oauth2:${LOCAL_GITEA_TOKEN}@10.10.20.120:4455/Fimeg/SouveraineOS.git" \
"$CONTRACT"
python3 "$CONTRACT/tools/validate-distribution.py" \
"$CONTRACT/distribution/manifest.toml" \
--producer souveraine-viewtop \
--complete \
--artifact souveraine-viewtop:x86_64 \
--artifact souveraine-viewtop:aarch64
- name: fmt
run: cargo fmt --all -- --check
@ -70,87 +57,3 @@ jobs:
# bare `--target` makes pkg-config answer with the host's copies.
- name: cross-build the phone backend (kms)
run: ./scripts/build-cross.sh --release
- name: package and sign x86_64
if: gitea.ref == 'refs/heads/main' && gitea.event_name == 'push'
env:
ARCHIVE_KEY: 3CD9E99E222C2A174986FC9AFF4949AA20C8E911
run: |
set -euo pipefail
PKGVER="0.1.0.r$(git rev-list --count HEAD).g${GITHUB_SHA:0:12}"
WORK="$GITHUB_WORKSPACE/pacman-package/x86_64"
REPO="$GITHUB_WORKSPACE/pacman-repo/x86_64"
rm -rf "$GITHUB_WORKSPACE/pacman-package" "$GITHUB_WORKSPACE/pacman-repo"
mkdir -p "$WORK" "$REPO"
cp target/release/viewtop "$WORK/viewtop"
cp packaging/arch/souveraine-session-viewtop \
packaging/arch/souveraine-shell.service \
packaging/arch/souveraine-session-pre.target \
packaging/arch/souveraine-session.target "$WORK/"
cp LICENSE "$WORK/LICENSE"
cp packaging/arch/PKGBUILD.prebuilt "$WORK/PKGBUILD"
(
cd "$WORK"
export SOUVERAINE_PKGVER="$PKGVER"
CARCH=x86_64 makepkg --nodeps --noconfirm --cleanbuild
)
PKG=$(find "$WORK" -maxdepth 1 -name 'souveraine-viewtop-*.pkg.tar.zst' -print -quit)
test -n "$PKG"
bsdtar -tf "$PKG" | grep -qx 'usr/bin/viewtop'
bsdtar -tf "$PKG" | grep -qx 'usr/bin/souveraine-session-viewtop'
bsdtar -tf "$PKG" | grep -qx 'usr/lib/systemd/user/souveraine-shell.service'
bsdtar -tf "$PKG" | grep -qx 'usr/lib/systemd/user/souveraine-session-pre.target'
bsdtar -tf "$PKG" | grep -qx 'usr/lib/systemd/user/souveraine-session.target'
cp "$PKG" "$REPO/"
gpg --batch --yes --local-user "$ARCHIVE_KEY" \
--detach-sign "$REPO/$(basename "$PKG")"
- name: package and sign aarch64
if: gitea.ref == 'refs/heads/main' && gitea.event_name == 'push'
env:
ARCHIVE_KEY: 3CD9E99E222C2A174986FC9AFF4949AA20C8E911
run: |
set -euo pipefail
PKGVER="0.1.0.r$(git rev-list --count HEAD).g${GITHUB_SHA:0:12}"
WORK="$GITHUB_WORKSPACE/pacman-package/aarch64"
REPO="$GITHUB_WORKSPACE/pacman-repo/aarch64"
mkdir -p "$WORK" "$REPO"
cp target/aarch64-unknown-linux-gnu/release/viewtop "$WORK/viewtop"
cp packaging/arch/souveraine-session-viewtop \
packaging/arch/souveraine-shell.service \
packaging/arch/souveraine-session-pre.target \
packaging/arch/souveraine-session.target "$WORK/"
cp LICENSE "$WORK/LICENSE"
cp packaging/arch/PKGBUILD.prebuilt.aarch64 "$WORK/PKGBUILD"
(
cd "$WORK"
export SOUVERAINE_PKGVER="$PKGVER"
CARCH=aarch64 makepkg --nodeps --noconfirm --cleanbuild
)
PKG=$(find "$WORK" -maxdepth 1 -name 'souveraine-viewtop-*.pkg.tar.zst' -print -quit)
test -n "$PKG"
bsdtar -tf "$PKG" | grep -qx 'usr/bin/viewtop'
bsdtar -tf "$PKG" | grep -qx 'usr/bin/souveraine-session-viewtop'
bsdtar -tf "$PKG" | grep -qx 'usr/lib/systemd/user/souveraine-shell.service'
bsdtar -tf "$PKG" | grep -qx 'usr/lib/systemd/user/souveraine-session-pre.target'
bsdtar -tf "$PKG" | grep -qx 'usr/lib/systemd/user/souveraine-session.target'
bsdtar -xOf "$PKG" usr/bin/viewtop | file - | grep -q 'ARM aarch64'
cp "$PKG" "$REPO/"
gpg --batch --yes --local-user "$ARCHIVE_KEY" \
--detach-sign "$REPO/$(basename "$PKG")"
- name: publish x86_64 and aarch64 into the edge archive
if: gitea.ref == 'refs/heads/main' && gitea.event_name == 'push'
env:
EDGE_TOKEN: ${{ secrets.LOCAL_GITEA_TOKEN }}
ARCHIVE_KEY: 3CD9E99E222C2A174986FC9AFF4949AA20C8E911
run: |
set -euo pipefail
PUBLISHER_SHA=6eb87a5
rm -rf "$GITHUB_WORKSPACE/publisher"
git -c http.extraheader="Authorization: token ${{ secrets.LOCAL_GITEA_TOKEN }}" \
clone "${GITHUB_SERVER_URL}/Fimeg/souveraine.git" "$GITHUB_WORKSPACE/publisher"
git -C "$GITHUB_WORKSPACE/publisher" checkout "$PUBLISHER_SHA"
export PRODUCER_VERSION="0.1.0.r$(git rev-list --count HEAD).g${GITHUB_SHA:0:12}"
"$GITHUB_WORKSPACE/publisher/packaging/arch/publish-edge.sh" \
souveraine-viewtop "$GITHUB_WORKSPACE/pacman-repo"

View file

@ -63,7 +63,7 @@ unconditional refusal in the codebase is that unlock is never an agent verb
## Building
**Never build on the phone.** The Pixel 3 is the daily driver; a build there
costs a live system. `archdev` cross-compiles everything.
costs a live system. a cross-compilation host builds everything.
```sh
cargo test --workspace

View file

@ -4085,7 +4085,7 @@ impl Viewtop {
// This used to call `toggle_float` directly, which made the
// compositor both the recogniser and the binder — the eighth blind
// actor DEVICE-STATE-MACHINE §12 forbids by name, and what
// `wiuf-vpn-gate` cost. sessiond has a `gesture` verb now: it holds
// `that host` cost. sessiond has a `gesture` verb now: it holds
// the binding table, it is where the trail is, and it is the one
// place a binding can be re-pointed without a rebuild.
//

View file

@ -108,7 +108,7 @@ path. That divergence is how the KMS backend went unbuilt for its whole life.
## Verified, and not
Green on archdev and in CI at `458a354`: 150 tests, clippy `-D warnings` on
Green on the cross-compilation host and in CI at `458a354`: 150 tests, clippy `-D warnings` on
default / `kms` / `nested`, fmt, cross-build aarch64, nested host build, and
`scripts/build-cross.sh` producing an aarch64 ELF with libinput linked.

View file

@ -5,7 +5,7 @@ pkgver="${SOUVERAINE_PKGVER:-0.1.0}"
pkgrel=1
pkgdesc='Souveraine Wayland compositor and its session launcher'
arch=(x86_64)
url='https://gitea.wiuf.net/Fimeg/souveraine-viewtop'
url='https://forge.caseytunturi.com/Fimeg/souveraine-viewtop'
license=(AGPL-3.0-or-later)
depends=(
dbus

View file

@ -8,7 +8,7 @@ pkgver="${SOUVERAINE_PKGVER:?CI must set SOUVERAINE_PKGVER}"
pkgrel=1
pkgdesc='Souveraine Wayland compositor and its session launcher'
arch=(aarch64)
url='https://gitea.wiuf.net/Fimeg/souveraine-viewtop'
url='https://forge.caseytunturi.com/Fimeg/souveraine-viewtop'
license=(AGPL-3.0-or-later)
depends=(
dbus