publish: the public projection begins here
This is a projection, not a development branch. The tree above was constructed from the internal source named below under a manifest that decides which paths may leave, then scanned as a whole tree rather than as a series of patches, and only then published. Public history starts here because the history before it was not admissible, and neither was the tree. What used to stand in this repository included a rescue copy of another machine, a directory of phone handoffs, deployment wired to one house, and a submodule pointing at a forge no stranger can reach. None of that was ever the product. It stays in the private forge, which is allowed to hold the whole working organism, and this is what was deliberately sent out instead. Three mechanisms produced this tree, in decreasing order of trust. A top-level path the manifest does not name never arrives at all, which is the one that catches directories nobody has thought of yet. Named internal files inside admitted roots are dropped. A short, reviewed table replaces deployment defaults that a public build must not carry -- an endpoint aimed at one LAN, a VPN profile belonging to one phone, packaging built from one checkout path. Everything after this commit is an ordinary publication with the same three trailers, so a force push stops being routine and starts meaning that something deliberate happened. The trailers bind the projection to its source without pretending the public SHA is the private one: same lineage, different tree, and the record says so. Source-Sha: 8f27b1e76a8fef560a336aba18e6990713ff1047 Policy-Sha: 6b261d2f3e6e1fb19874846ba4bb1dfe15565d25b8618c1c1afba0419c101d27 Tree-Digest: 18ec3563c5e5ef9a414993a9f6734b251ff9ed3cd56eebdd6cac01e45c6e3067
This commit is contained in:
commit
8f42fc953d
1476 changed files with 238455 additions and 0 deletions
17
scripts/aarch64-linker
Executable file
17
scripts/aarch64-linker
Executable file
|
|
@ -0,0 +1,17 @@
|
|||
#!/usr/bin/env bash
|
||||
# aarch64-linker — Cargo linker wrapper for the SouveraineOS ARM sysroot.
|
||||
#
|
||||
# GCC's default aarch64 linker scripts contain absolute library paths. Cargo
|
||||
# supplies -lm before its late rustflags, so --sysroot alone is insufficient:
|
||||
# ld can select the host's x86 library. build-cross.sh supplies an overlay
|
||||
# containing sysroot-relative copies of those scripts; put it first.
|
||||
set -euo pipefail
|
||||
|
||||
SYSROOT="${SOUVERAINE_AARCH64_SYSROOT:-/usr/aarch64-linux-gnu}"
|
||||
SCRIPTS="${SOUVERAINE_AARCH64_LINKER_SCRIPTS:?run scripts/build-cross.sh, not this wrapper directly}"
|
||||
|
||||
exec aarch64-linux-gnu-gcc \
|
||||
--sysroot="$SYSROOT" \
|
||||
-L"$SCRIPTS" \
|
||||
-L"$SYSROOT/usr/lib" \
|
||||
"$@"
|
||||
68
scripts/build-cross.sh
Executable file
68
scripts/build-cross.sh
Executable file
|
|
@ -0,0 +1,68 @@
|
|||
#!/usr/bin/env bash
|
||||
# build-cross.sh — cross-compile souveraine for aarch64 (Pixel 3 / Arch ARM).
|
||||
#
|
||||
# The sysroot is /usr/aarch64-linux-gnu on the laptop and
|
||||
# ~/aarch64-sysroot on a build host. Set SOUVERAINE_AARCH64_SYSROOT for the latter.
|
||||
# PKG_CONFIG_* is exported here, not in .cargo/config.toml — cargo's [env]
|
||||
# block doesn't reliably reach build-script probes. The aarch64 linker scripts
|
||||
# need a small unprivileged overlay so absolute /usr/lib paths stay inside the
|
||||
# target sysroot rather than resolving to the x86 host.
|
||||
set -euo pipefail
|
||||
|
||||
cd "$(dirname "$0")/.."
|
||||
|
||||
SYSROOT="${SOUVERAINE_AARCH64_SYSROOT:-/usr/aarch64-linux-gnu}"
|
||||
TARGET_DIR="${CARGO_TARGET_DIR:-$PWD/target}"
|
||||
LINKER_SCRIPTS="$TARGET_DIR/aarch64-linker-scripts"
|
||||
|
||||
[[ -d "$SYSROOT/usr/lib" ]] || {
|
||||
echo "aarch64 sysroot is missing: $SYSROOT" >&2
|
||||
exit 1
|
||||
}
|
||||
|
||||
mkdir -p "$LINKER_SCRIPTS"
|
||||
# The artifact runner does not guarantee /dev/fd, so keep this stream on the
|
||||
# pipeline instead of feeding the loop through process substitution.
|
||||
find "$SYSROOT/usr/lib" -maxdepth 1 -type f -name '*.so' \
|
||||
-exec grep -lE '(^|[ (])/(usr/)?lib/' {} + |
|
||||
while IFS= read -r script; do
|
||||
name="${script##*/}"
|
||||
tmp="$LINKER_SCRIPTS/.${name}.$$"
|
||||
# '=' tells GNU ld to resolve this path below --sysroot. Only linker
|
||||
# scripts (plain-text *.so files) are copied; actual shared objects stay
|
||||
# in the sysroot.
|
||||
sed -E 's#([ (])/(usr/)?lib/#\1=/\2lib/#g' "$script" > "$tmp"
|
||||
mv "$tmp" "$LINKER_SCRIPTS/$name"
|
||||
done
|
||||
|
||||
export PKG_CONFIG_ALLOW_CROSS=1
|
||||
export PKG_CONFIG_LIBDIR="$SYSROOT/usr/lib/pkgconfig"
|
||||
export PKG_CONFIG_SYSROOT_DIR="$SYSROOT"
|
||||
export PKG_CONFIG="$PWD/.cargo/aarch64-pkg-config"
|
||||
export SOUVERAINE_AARCH64_SYSROOT="$SYSROOT"
|
||||
export SOUVERAINE_AARCH64_LINKER_SCRIPTS="$LINKER_SCRIPTS"
|
||||
export CARGO_TARGET_AARCH64_UNKNOWN_LINUX_GNU_LINKER="$PWD/scripts/aarch64-linker"
|
||||
|
||||
BIN_NAME=souveraine
|
||||
EXPECT_BIN_NAME=false
|
||||
for arg in "$@"; do
|
||||
if $EXPECT_BIN_NAME; then
|
||||
BIN_NAME="$arg"
|
||||
EXPECT_BIN_NAME=false
|
||||
continue
|
||||
fi
|
||||
case "$arg" in
|
||||
--bin) EXPECT_BIN_NAME=true ;;
|
||||
--bin=*) BIN_NAME="${arg#--bin=}" ;;
|
||||
esac
|
||||
done
|
||||
|
||||
cargo build --release --target aarch64-unknown-linux-gnu "$@"
|
||||
|
||||
BIN="$TARGET_DIR/aarch64-unknown-linux-gnu/release/$BIN_NAME"
|
||||
[[ -x "$BIN" ]] || {
|
||||
echo "requested build produced no executable: $BIN" >&2
|
||||
exit 1
|
||||
}
|
||||
echo "== built: $BIN =="
|
||||
file "$BIN"
|
||||
70
scripts/install-quickshell-surface.sh
Executable file
70
scripts/install-quickshell-surface.sh
Executable file
|
|
@ -0,0 +1,70 @@
|
|||
#!/usr/bin/env bash
|
||||
# Safely adopt the Souveraine QuickShell surface into an existing ii setup.
|
||||
#
|
||||
# This is deliberately separate from pacman installation: packages place
|
||||
# assets on disk, while a person chooses whether their live shell may change.
|
||||
set -euo pipefail
|
||||
|
||||
usage() {
|
||||
cat <<'EOF'
|
||||
Usage: install-quickshell-surface.sh [--dry-run]
|
||||
|
||||
--dry-run Show every file in the current development overlay (default).
|
||||
|
||||
The present development overlay mixes phone and laptop assumptions. It is not
|
||||
safe to adopt wholesale on either device. Profile-specific manifests must land
|
||||
before an apply/adopt mode is enabled. Pacman should install assets only.
|
||||
EOF
|
||||
}
|
||||
|
||||
mode=dry-run
|
||||
while (($#)); do
|
||||
case "$1" in
|
||||
--dry-run) mode=dry-run ;;
|
||||
--apply|--adopt)
|
||||
echo "Surface adoption is disabled until laptop and phone manifests are split." >&2
|
||||
exit 2
|
||||
;;
|
||||
-h|--help) usage; exit 0 ;;
|
||||
*) echo "unknown option: $1" >&2; usage >&2; exit 2 ;;
|
||||
esac
|
||||
shift
|
||||
done
|
||||
|
||||
ROOT="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)"
|
||||
DEPLOY="$ROOT/surfaces/quickshell/deploy.sh"
|
||||
QS="${XDG_CONFIG_HOME:-$HOME/.config}/quickshell"
|
||||
II="$QS/ii"
|
||||
|
||||
[[ -x "$DEPLOY" ]] || { echo "surface deployer not found: $DEPLOY" >&2; exit 1; }
|
||||
[[ -d "$II" ]] || {
|
||||
echo "No ii QuickShell configuration at $II." >&2
|
||||
echo "Install and initialise QuickShell/illogical-impulse first; no files changed." >&2
|
||||
exit 1
|
||||
}
|
||||
|
||||
conflicts=()
|
||||
new_count=0
|
||||
managed_count=0
|
||||
|
||||
while read -r rel target; do
|
||||
src="$ROOT/surfaces/quickshell/$rel"
|
||||
dst="$QS/$target"
|
||||
[[ -f "$src" ]] || { echo "surface source missing: $src" >&2; exit 1; }
|
||||
|
||||
if [[ -L "$dst" && "$(readlink -f "$dst")" == "$src" ]]; then
|
||||
printf 'managed %s\n' "$target"
|
||||
((managed_count += 1))
|
||||
elif [[ -e "$dst" || -L "$dst" ]]; then
|
||||
printf 'replace %s\n' "$target"
|
||||
conflicts+=("$target")
|
||||
else
|
||||
printf 'new %s\n' "$target"
|
||||
((new_count += 1))
|
||||
fi
|
||||
done < <("$DEPLOY" --manifest)
|
||||
|
||||
printf '\n%d managed, %d new, %d replacement(s).\n' \
|
||||
"$managed_count" "$new_count" "${#conflicts[@]}"
|
||||
|
||||
echo "Dry run only. Profile-specific laptop/phone manifests are required before adoption can be enabled."
|
||||
Loading…
Reference in a new issue