Compare commits

..
Author SHA1 Message Date
github-actions[bot] b14cd21d70 sharpemu-bin: update to 0.0.2_beta.5-1 [skip ci] 2026-07-23 01:08:19 +00:00
Felitendo 8b3302d335 sharpemu-bin: add package (0.0.2_beta.4-1) 2026-07-22 06:53:10 +02:00
Felitendo db74a6b65a Prune superseded GitHub releases after publishing 2026-07-21 13:36:03 +02:00
Felitendo 0d9fea0a51 Queue workflow runs instead of racing on AUR pushes 2026-07-21 13:32:03 +02:00
Felitendo f215a99c11 chromium-widevine-helper-bin: add package (1.0.8-1) 2026-07-21 13:22:18 +02:00
github-actions[bot] abe8b73474 timetable-bin: update to 4.2.1-1 [skip ci] 2026-07-21 01:06:19 +00:00
github-actions[bot] 18a2e308b8 timetable-bin: update to 4.1-1 [skip ci] 2026-07-18 18:57:34 +00:00
Felitendo 1a83bd9eb9 timetable-bin: add missing runtime deps (4.0-2)
Upstream 4.0 replaced python-webuntis with pyotp for authentication and
unconditionally imports libsecret (credential storage) and WebKitGTK 6.0
at startup. Add python-pyotp, libsecret and webkitgtk-6.0 to depends.

Stop bundling the webuntis wheel from the next artifact build on; the
existing 4.0 artifact is reused as-is (its bundled copy is unused and
inert).
2026-07-18 15:10:59 +02:00
github-actions[bot] be1973ee39 timetable-bin: update to 4.0-1 [skip ci] 2026-07-18 01:05:31 +00:00
Felitendo 6a29785de6 Move AUR commit email to a secret 2026-07-17 12:53:07 +02:00
Felitendo 04d0a09896 Add fluxer-bin; support packages with upstream-hosted binaries 2026-07-17 10:58:06 +02:00
Felitendo bd4ed84ab3 Pass AUR SSH key via GIT_SSH_COMMAND instead of ~/.ssh 2026-07-17 10:25:52 +02:00
Felitendo 7baaa60cf2 Fix dubious-ownership git error in CI container 2026-07-17 09:46:28 +02:00
17 changed files with 492 additions and 79 deletions

No files matched your search

+10 -4
View File
@@ -8,11 +8,17 @@ on:
push: push:
branches: [main] branches: [main]
paths: paths:
- '*/PKGBUILD' # any package file (PKGBUILD, pkg.sh, .desktop, ...) and the shared script
- '*/pkg.sh' - '*/*'
- 'scripts/**'
- '.github/workflows/update.yml' - '.github/workflows/update.yml'
# Never run twice at once: concurrent runs race on pushing to this repository
# and to the AUR (e.g. a push-triggered run and a manual dispatch both creating
# a new AUR repo). Queue instead of cancelling so every trigger still lands.
concurrency:
group: aur-update
cancel-in-progress: false
permissions: permissions:
contents: write contents: write
@@ -51,5 +57,5 @@ jobs:
env: env:
AUR_SSH_PRIVATE_KEY: ${{ secrets.AUR_SSH_PRIVATE_KEY }} AUR_SSH_PRIVATE_KEY: ${{ secrets.AUR_SSH_PRIVATE_KEY }}
AUR_GIT_NAME: ${{ vars.AUR_GIT_NAME }} AUR_GIT_NAME: ${{ vars.AUR_GIT_NAME }}
AUR_GIT_EMAIL: ${{ vars.AUR_GIT_EMAIL }} AUR_GIT_EMAIL: ${{ secrets.AUR_GIT_EMAIL }}
run: bash scripts/update-package.sh "${{ matrix.package }}" run: bash scripts/update-package.sh "${{ matrix.package }}"
+1
View File
@@ -1,5 +1,6 @@
# makepkg build leftovers and downloaded/built artifacts # makepkg build leftovers and downloaded/built artifacts
*.tar.zst *.tar.zst
*.tar.gz
*.pkg.tar.* *.pkg.tar.*
*/src/ */src/
*/pkg/ */pkg/
+24 -11
View File
@@ -11,8 +11,9 @@ package's upstream for a new release. When one is found it:
release of **this** repository (tag `<pkgname>-<version>`), release of **this** repository (tag `<pkgname>-<version>`),
3. updates the `PKGBUILD` (pkgver/pkgrel/sha256sums), test-builds it with 3. updates the `PKGBUILD` (pkgver/pkgrel/sha256sums), test-builds it with
`makepkg` and regenerates `.SRCINFO`, `makepkg` and regenerates `.SRCINFO`,
4. commits the changes back to this repository, and 4. commits the changes back to this repository,
5. pushes `PKGBUILD` + `.SRCINFO` to the AUR. 5. pushes `PKGBUILD` + `.SRCINFO` to the AUR, and
6. deletes the package's superseded releases (older versions, tag included).
The AUR packages themselves only download the prebuilt asset from step 2, so The AUR packages themselves only download the prebuilt asset from step 2, so
users don't need any build dependencies. users don't need any build dependencies.
@@ -22,6 +23,9 @@ users don't need any build dependencies.
| Package | Upstream | AUR | | Package | Upstream | AUR |
|---|---|---| |---|---|---|
| `timetable-bin` | [ostfriese4/untis](https://codeberg.org/ostfriese4/untis) — "Timetable", a GTK4 + LibAdwaita client for WebUntis | [timetable-bin](https://aur.archlinux.org/packages/timetable-bin) | | `timetable-bin` | [ostfriese4/untis](https://codeberg.org/ostfriese4/untis) — "Timetable", a GTK4 + LibAdwaita client for WebUntis | [timetable-bin](https://aur.archlinux.org/packages/timetable-bin) |
| `fluxer-bin` | [fluxer.app](https://fluxer.app) — Fluxer desktop client (Electron) | [fluxer-bin](https://aur.archlinux.org/packages/fluxer-bin) |
| `chromium-widevine-helper-bin` | [GloriousEggroll/chromium-widevine-helper](https://github.com/GloriousEggroll/chromium-widevine-helper) — extension + native helper installing Google's Widevine CDM into Chromium-based browser profiles | [chromium-widevine-helper-bin](https://aur.archlinux.org/packages/chromium-widevine-helper-bin) |
| `sharpemu-bin` | [sharpemu/sharpemu](https://github.com/sharpemu/sharpemu) — experimental PlayStation 5 emulator | [sharpemu-bin](https://aur.archlinux.org/packages/sharpemu-bin) |
## Setup (one-time) ## Setup (one-time)
@@ -30,9 +34,9 @@ users don't need any build dependencies.
2. Add the matching **private** key as a repository secret named 2. Add the matching **private** key as a repository secret named
`AUR_SSH_PRIVATE_KEY` `AUR_SSH_PRIVATE_KEY`
(Settings → Secrets and variables → Actions → New repository secret). (Settings → Secrets and variables → Actions → New repository secret).
3. Optionally set the repository **variables** `AUR_GIT_NAME` and 3. Optionally set the repository variable `AUR_GIT_NAME` and the repository
`AUR_GIT_EMAIL` to control the commit identity used on the AUR **secret** `AUR_GIT_EMAIL` to control the commit identity used on the AUR
(defaults: `Felitendo` / `95575686+Felitendo@users.noreply.github.com`). (defaults: `Felitendo` / the maintainer's GitHub noreply address).
The first push to `ssh://aur@aur.archlinux.org/<pkgname>.git` creates the AUR The first push to `ssh://aur@aur.archlinux.org/<pkgname>.git` creates the AUR
package automatically. package automatically.
@@ -44,12 +48,21 @@ Create a new directory named after the AUR package containing:
- **`PKGBUILD`** — sources the prebuilt asset from - **`PKGBUILD`** — sources the prebuilt asset from
`https://github.com/Felitendo/PKGBUILDS/releases/download/<pkgname>-<pkgver>/<pkgname>-<pkgver>.tar.zst`. `https://github.com/Felitendo/PKGBUILDS/releases/download/<pkgname>-<pkgver>/<pkgname>-<pkgver>.tar.zst`.
`pkgver`, `pkgrel` and `sha256sums` are maintained by CI. `pkgver`, `pkgrel` and `sha256sums` are maintained by CI.
- **`pkg.sh`** — bash sourced by [scripts/update-package.sh](scripts/update-package.sh), - **`pkg.sh`** — bash sourced by [scripts/update-package.sh](scripts/update-package.sh).
providing: Always provides `latest_version` (prints the latest upstream version, no
- `BUILD_DEPS` — array of Arch packages installed before building, `v` prefix), plus one of two modes:
- `latest_version` — prints the latest upstream version (no `v` prefix), - *upstream has no binaries* (e.g. `timetable-bin`): define
- `build_artifact <version> <output-file>` — downloads/builds upstream and `build_artifact <version> <output-file>` (build upstream and write the
writes the install tree (a tarball containing `usr/`) to `<output-file>`. install tree as a tarball containing `usr/`) and `BUILD_DEPS` (array of
Arch packages needed to build). CI hosts the result as a GitHub release
asset which the PKGBUILD downloads.
- *upstream hosts binaries* (e.g. `fluxer-bin`): define
`refresh_checksums <version> <pkgbuild-path>` which updates the
`sha256sums*` lines for the new version. The PKGBUILD sources upstream
URLs directly and nothing is hosted here.
Other local source files in the directory (`.desktop` files, etc.) are
pushed to the AUR alongside `PKGBUILD` and `.SRCINFO`.
The workflow discovers package directories automatically. Trigger a run The workflow discovers package directories automatically. Trigger a run
manually via *Actions → Update AUR packages → Run workflow* to publish it manually via *Actions → Update AUR packages → Run workflow* to publish it
+27
View File
@@ -0,0 +1,27 @@
pkgbase = chromium-widevine-helper-bin
pkgdesc = Extension + native helper that installs Google's Widevine CDM into Chromium-based browser profiles (prebuilt)
pkgver = 1.0.8
pkgrel = 1
url = https://github.com/GloriousEggroll/chromium-widevine-helper
arch = any
license = GPL-3.0-only
depends = python
depends = procps-ng
depends = ca-certificates
provides = chromium-widevine-helper
conflicts = chromium-widevine-helper
backup = etc/helium/native-messaging-hosts/org.chromium.widevine.json
backup = etc/net.imput.helium/native-messaging-hosts/org.chromium.widevine.json
backup = etc/chromium/native-messaging-hosts/org.chromium.widevine.json
backup = etc/chromium-browser/native-messaging-hosts/org.chromium.widevine.json
backup = etc/opt/chrome/native-messaging-hosts/org.chromium.widevine.json
backup = etc/opt/edge/native-messaging-hosts/org.chromium.widevine.json
backup = etc/brave/native-messaging-hosts/org.chromium.widevine.json
backup = etc/vivaldi/native-messaging-hosts/org.chromium.widevine.json
backup = etc/opera/native-messaging-hosts/org.chromium.widevine.json
backup = etc/thorium/native-messaging-hosts/org.chromium.widevine.json
backup = etc/iridium/native-messaging-hosts/org.chromium.widevine.json
source = https://github.com/Felitendo/PKGBUILDS/releases/download/chromium-widevine-helper-bin-1.0.8/chromium-widevine-helper-bin-1.0.8.tar.zst
sha256sums = efb70f082652176710b403a2629333220c1b8b96e3f27f398ba7efb496982829
pkgname = chromium-widevine-helper-bin
+31
View File
@@ -0,0 +1,31 @@
# Maintainer: Felitendo
# This PKGBUILD is updated automatically:
# https://github.com/Felitendo/PKGBUILDS
pkgname=chromium-widevine-helper-bin
pkgver=1.0.8
pkgrel=1
pkgdesc="Extension + native helper that installs Google's Widevine CDM into Chromium-based browser profiles (prebuilt)"
arch=('any')
url="https://github.com/GloriousEggroll/chromium-widevine-helper"
license=('GPL-3.0-only')
depends=('python' 'procps-ng' 'ca-certificates')
provides=('chromium-widevine-helper')
conflicts=('chromium-widevine-helper')
backup=('etc/helium/native-messaging-hosts/org.chromium.widevine.json'
'etc/net.imput.helium/native-messaging-hosts/org.chromium.widevine.json'
'etc/chromium/native-messaging-hosts/org.chromium.widevine.json'
'etc/chromium-browser/native-messaging-hosts/org.chromium.widevine.json'
'etc/opt/chrome/native-messaging-hosts/org.chromium.widevine.json'
'etc/opt/edge/native-messaging-hosts/org.chromium.widevine.json'
'etc/brave/native-messaging-hosts/org.chromium.widevine.json'
'etc/vivaldi/native-messaging-hosts/org.chromium.widevine.json'
'etc/opera/native-messaging-hosts/org.chromium.widevine.json'
'etc/thorium/native-messaging-hosts/org.chromium.widevine.json'
'etc/iridium/native-messaging-hosts/org.chromium.widevine.json')
source=("https://github.com/Felitendo/PKGBUILDS/releases/download/${pkgname}-${pkgver}/${pkgname}-${pkgver}.tar.zst")
sha256sums=('efb70f082652176710b403a2629333220c1b8b96e3f27f398ba7efb496982829')
package() {
cp -a "$srcdir/usr" "$srcdir/etc" "$pkgdir/"
}
+77
View File
@@ -0,0 +1,77 @@
# chromium-widevine-helper-bin - prebuilt package of
# https://github.com/GloriousEggroll/chromium-widevine-helper
# (Chromium extension + native messaging helper that installs Google's
# Widevine CDM into Chromium-based browser profiles).
#
# Upstream publishes neither releases nor tags; the canonical version lives in
# the Fedora RPM spec on the main branch. build_artifact() snapshots main,
# verifies the snapshot still carries the requested version and assembles the
# install tree following upstream's spec - with Fedora's /usr/libexec
# relocated to /usr/lib, which Arch uses instead.
UPSTREAM_REPO="GloriousEggroll/chromium-widevine-helper"
SPEC_PATH="Packaging/rpm/chromium-widevine-helper.spec"
# Pure noarch install tree (Python script + JSON + extension assets).
BUILD_DEPS=()
spec_version() {
grep -Po '^%global helper_version \K[0-9.]+'
}
latest_version() {
curl -sf "https://raw.githubusercontent.com/$UPSTREAM_REPO/main/$SPEC_PATH" \
| spec_version
}
# build_artifact <version> <output-file>
build_artifact() {
local ver="$1" outfile="$2"
local workdir destdir
workdir="$(mktemp -d)"
destdir="$(mktemp -d)"
curl -sfL "https://github.com/$UPSTREAM_REPO/archive/refs/heads/main.tar.gz" \
| tar -xz -C "$workdir" --strip-components=1
# main may have moved between the version check and this download.
local specver
specver="$(spec_version < "$workdir/$SPEC_PATH")"
if [[ "$specver" != "$ver" ]]; then
echo "snapshot of main is $specver, not the requested $ver - try again" >&2
return 1
fi
install -Dm755 "$workdir/helper/chromium-widevine" \
"$destdir/usr/lib/chromium-widevine/chromium-widevine"
install -d "$destdir/usr/bin"
ln -s /usr/lib/chromium-widevine/chromium-widevine "$destdir/usr/bin/chromium-widevine"
# The extension is shipped so it can be loaded unpacked from
# chrome://extensions (chromium-widevine --install-native-hosts then
# registers whatever ID the browser assigned it).
mkdir -p "$destdir/usr/share/chromium-widevine"
cp -a "$workdir/extension" "$destdir/usr/share/chromium-widevine/extension"
find "$destdir/usr/share/chromium-widevine" -type d -exec chmod 755 {} +
find "$destdir/usr/share/chromium-widevine" -type f -exec chmod 644 {} +
install -Dm644 "$workdir/README.md" \
"$destdir/usr/share/doc/chromium-widevine-helper-bin/README.md"
# System-wide native messaging host manifests for the same browser lookup
# roots upstream's RPM covers.
local hostdir
for hostdir in helium net.imput.helium chromium chromium-browser \
opt/chrome opt/edge brave vivaldi opera thorium iridium; do
install -Dm644 "$workdir/helper/chromium-widevine-native-host.json" \
"$destdir/etc/$hostdir/native-messaging-hosts/org.chromium.widevine.json"
done
# The upstream manifest hardcodes Fedora's /usr/libexec helper path.
find "$destdir/etc" -name 'org.chromium.widevine.json' -exec \
sed -i 's|/usr/libexec/chromium-widevine/|/usr/lib/chromium-widevine/|' {} +
tar --zstd --sort=name --owner=0 --group=0 --numeric-owner --mtime='@0' \
-cf "$outfile" -C "$destdir" usr etc
rm -rf "$workdir" "$destdir"
}
+20
View File
@@ -0,0 +1,20 @@
pkgbase = fluxer-bin
pkgdesc = Fluxer Desktop Application
pkgver = 0.0.8
pkgrel = 1
url = https://fluxer.app
arch = x86_64
arch = aarch64
license = AGPL-3.0-only
depends = gtk3
depends = nss
depends = alsa-lib
options = !strip
source = fluxer.desktop
sha256sums = 981daa8015b823fef254bb8e79fe6b28f77dda02cdc374796443bd64f5041de1
source_x86_64 = fluxer-0.0.8-x64.tar.gz::https://api.fluxer.app/dl/desktop/stable/linux/x64/0.0.8/tar_gz
sha256sums_x86_64 = acf6398fa6810720fed85b06c011b324e7db4fec6bf2fc7ad93c2446c3600f2d
source_aarch64 = fluxer-0.0.8-arm64.tar.gz::https://api.fluxer.app/dl/desktop/stable/linux/arm64/0.0.8/tar_gz
sha256sums_aarch64 = 77b874a98caf48de5bc4ccf03119f45262fe26fd7be085b57d7b40b1505d0ec8
pkgname = fluxer-bin
+54
View File
@@ -0,0 +1,54 @@
# Maintainer: Felitendo
# Contributor: Cosmo <cptncosmo@gmail.com>
# This PKGBUILD is updated automatically:
# https://github.com/Felitendo/PKGBUILDS
pkgname=fluxer-bin
pkgver=0.0.8
pkgrel=1
pkgdesc="Fluxer Desktop Application"
arch=('x86_64' 'aarch64')
url="https://fluxer.app"
license=('AGPL-3.0-only')
depends=('gtk3' 'nss' 'alsa-lib')
options=('!strip')
source=("fluxer.desktop")
sha256sums=('981daa8015b823fef254bb8e79fe6b28f77dda02cdc374796443bd64f5041de1')
source_x86_64=("fluxer-${pkgver}-x64.tar.gz::https://api.fluxer.app/dl/desktop/stable/linux/x64/${pkgver}/tar_gz")
sha256sums_x86_64=('acf6398fa6810720fed85b06c011b324e7db4fec6bf2fc7ad93c2446c3600f2d')
source_aarch64=("fluxer-${pkgver}-arm64.tar.gz::https://api.fluxer.app/dl/desktop/stable/linux/arm64/${pkgver}/tar_gz")
sha256sums_aarch64=('77b874a98caf48de5bc4ccf03119f45262fe26fd7be085b57d7b40b1505d0ec8')
package() {
local _dir
case "$CARCH" in
x86_64) _dir="fluxer-stable-${pkgver}-x64" ;;
aarch64) _dir="fluxer-stable-${pkgver}-arm64" ;;
esac
# upstream has changed the archive layout before - fall back to a glob
if [ ! -d "$srcdir/$_dir" ]; then
_dir=$(cd "$srcdir" && ls -d [Ff]luxer*"${pkgver}"*/ 2>/dev/null | head -n1)
_dir="${_dir%/}"
fi
if [ -z "$_dir" ] || [ ! -d "$srcdir/$_dir" ]; then
echo "Error: could not find extracted directory for $CARCH" >&2
ls -la "$srcdir" >&2
return 1
fi
install -d "$pkgdir/opt/$pkgname"
cp -a "$srcdir/$_dir/." "$pkgdir/opt/$pkgname/"
install -d "$pkgdir/usr/bin"
ln -s "/opt/$pkgname/fluxer" "$pkgdir/usr/bin/fluxer"
install -Dm644 "$srcdir/fluxer.desktop" "$pkgdir/usr/share/applications/fluxer.desktop"
if [ -f "$pkgdir/opt/$pkgname/resources/512x512.png" ]; then
install -Dm644 "$pkgdir/opt/$pkgname/resources/512x512.png" \
"$pkgdir/usr/share/icons/hicolor/512x512/apps/fluxer.png"
fi
}
+8
View File
@@ -0,0 +1,8 @@
[Desktop Entry]
Name=Fluxer
Comment=Fluxer Desktop App
Exec=/usr/bin/fluxer
Icon=fluxer
Terminal=false
Type=Application
Categories=Network;
+30
View File
@@ -0,0 +1,30 @@
# fluxer-bin - Fluxer Desktop (https://fluxer.app), an Electron app.
#
# Upstream hosts versioned prebuilt binaries itself, so there is no
# build_artifact() here: on a new version only pkgver and the checksums
# are refreshed and the result is pushed to the AUR.
DL_BASE="https://api.fluxer.app/dl/desktop/stable/linux"
latest_version() {
# the download API exposes the current version in the attachment filename,
# e.g. content-disposition: attachment; filename="fluxer-stable-0.0.8-x64.tar.gz"
curl -sfI "$DL_BASE/x64/latest/tar_gz" \
| grep -oiP 'filename="fluxer-(stable-)?\K[0-9][^"]*(?=-x64\.tar\.gz)'
}
# refresh_checksums <version> <pkgbuild-path>
refresh_checksums() {
local ver="$1" pkgbuild="$2"
local sha_desktop sha_x64 sha_arm64
sha_desktop="$(sha256sum "$(dirname "$pkgbuild")/fluxer.desktop" | cut -d' ' -f1)"
sha_x64="$(curl -sfL "$DL_BASE/x64/$ver/tar_gz" | sha256sum | cut -d' ' -f1)"
sha_arm64="$(curl -sfL "$DL_BASE/arm64/$ver/tar_gz" | sha256sum | cut -d' ' -f1)"
sed -i \
-e "s|^sha256sums=.*|sha256sums=('$sha_desktop')|" \
-e "s|^sha256sums_x86_64=.*|sha256sums_x86_64=('$sha_x64')|" \
-e "s|^sha256sums_aarch64=.*|sha256sums_aarch64=('$sha_arm64')|" \
"$pkgbuild"
}
+103 -50
View File
@@ -1,12 +1,15 @@
#!/usr/bin/env bash #!/usr/bin/env bash
# Update one package directory: # Update one package directory:
# 1. determine the latest upstream version (pkg.sh: latest_version) # 1. determine the latest upstream version (pkg.sh: latest_version)
# 2. build the binary artifact if the matching GitHub release asset is # 2. bring the PKGBUILD up to date:
# missing (pkg.sh: build_artifact), otherwise reuse the published one # - packages we build ourselves (pkg.sh defines build_artifact): make
# 3. refresh PKGBUILD (pkgver/pkgrel/sha256sums), test-build it with # sure the GitHub release asset for that version exists - building and
# makepkg and regenerate .SRCINFO # uploading it if necessary - and sync pkgver/sha256sums with it
# 4. commit changes back to this repository # - packages prebuilt by upstream (no build_artifact): on a new version,
# 5. push PKGBUILD + .SRCINFO to the AUR # set pkgver and let pkg.sh's refresh_checksums update the sums
# 3. if the PKGBUILD changed: set pkgrel and run a makepkg test build
# 4. regenerate .SRCINFO and commit changes back to this repository
# 5. push the package files to the AUR if it differs
# #
# Requires: GH_TOKEN (GitHub release + repo push), AUR_SSH_PRIVATE_KEY. # Requires: GH_TOKEN (GitHub release + repo push), AUR_SSH_PRIVATE_KEY.
# Optional: AUR_GIT_NAME / AUR_GIT_EMAIL for the AUR commit identity. # Optional: AUR_GIT_NAME / AUR_GIT_EMAIL for the AUR commit identity.
@@ -17,6 +20,13 @@ repo_root="$(cd "$(dirname "$0")/.." && pwd)"
cd "$repo_root" cd "$repo_root"
pkg="${pkg%/}" pkg="${pkg%/}"
# In the CI container the checkout is owned by a different uid than root;
# git (also invoked internally by gh) refuses to touch it without this.
if [[ "${CI:-}" == "true" ]]; then
git config --global --add safe.directory "$repo_root"
fi
BUILD_DEPS=()
source "$pkg/pkg.sh" source "$pkg/pkg.sh"
ver="$(latest_version || true)" ver="$(latest_version || true)"
@@ -28,17 +38,18 @@ echo "$pkg: latest upstream version is $ver"
oldver="$(grep -Po '^pkgver=\K.*' "$pkg/PKGBUILD")" oldver="$(grep -Po '^pkgver=\K.*' "$pkg/PKGBUILD")"
oldrel="$(grep -Po '^pkgrel=\K.*' "$pkg/PKGBUILD")" oldrel="$(grep -Po '^pkgrel=\K.*' "$pkg/PKGBUILD")"
oldsha="$(grep -Po "^sha256sums=\('\K[0-9a-f]{64}" "$pkg/PKGBUILD" || true)"
tag="$pkg-$ver" ### 2: bring the PKGBUILD up to date ########################################
asset="$pkg-$ver.tar.zst"
### 1+2: make sure the release asset exists, get a local copy of it ######### if declare -f build_artifact >/dev/null; then
# We build the binary artifact and host it as a GitHub release asset.
tag="$pkg-$ver"
asset="$pkg-$ver.tar.zst"
if gh release view "$tag" --json assets -q '.assets[].name' 2>/dev/null | grep -qxF "$asset"; then if gh release view "$tag" --json assets -q '.assets[].name' 2>/dev/null | grep -qxF "$asset"; then
echo "$pkg: release $tag already contains $asset - reusing it" echo "$pkg: release $tag already contains $asset - reusing it"
gh release download "$tag" --pattern "$asset" --dir "$pkg" --clobber gh release download "$tag" --pattern "$asset" --dir "$pkg" --clobber
else else
echo "$pkg: building $asset" echo "$pkg: building $asset"
if [[ "${CI:-}" == "true" && "${#BUILD_DEPS[@]}" -gt 0 ]]; then if [[ "${CI:-}" == "true" && "${#BUILD_DEPS[@]}" -gt 0 ]]; then
pacman -S --noconfirm --needed "${BUILD_DEPS[@]}" pacman -S --noconfirm --needed "${BUILD_DEPS[@]}"
@@ -48,45 +59,64 @@ else
gh release create "$tag" --title "$tag" \ gh release create "$tag" --title "$tag" \
--notes "Automated build of $pkg $ver (upstream: ${UPSTREAM_REPO:-unknown})." --notes "Automated build of $pkg $ver (upstream: ${UPSTREAM_REPO:-unknown})."
gh release upload "$tag" "$pkg/$asset" --clobber gh release upload "$tag" "$pkg/$asset" --clobber
fi fi
sha="$(sha256sum "$pkg/$asset" | cut -d' ' -f1)" sha="$(sha256sum "$pkg/$asset" | cut -d' ' -f1)"
sed -i \
### 3: refresh PKGBUILD, test-build, regenerate .SRCINFO ####################
if [[ "$ver" != "$oldver" ]]; then
rel=1
elif [[ "$sha" != "$oldsha" ]]; then
rel=$((oldrel + 1))
else
rel="$oldrel"
fi
sed -i \
-e "s|^pkgver=.*|pkgver=$ver|" \ -e "s|^pkgver=.*|pkgver=$ver|" \
-e "s|^pkgrel=.*|pkgrel=$rel|" \
-e "s|^sha256sums=.*|sha256sums=('$sha')|" \ -e "s|^sha256sums=.*|sha256sums=('$sha')|" \
"$pkg/PKGBUILD" "$pkg/PKGBUILD"
else
# Upstream publishes the binaries itself; only refresh version + checksums.
if [[ "$ver" != "$oldver" ]]; then
sed -i "s|^pkgver=.*|pkgver=$ver|" "$pkg/PKGBUILD"
refresh_checksums "$ver" "$pkg/PKGBUILD"
else
echo "$pkg: $ver is current"
fi
fi
# makepkg refuses to run as root (the CI container), so hand the build to an ### 3: pkgrel + test build if the PKGBUILD changed ##########################
# unprivileged user there. -d: the runner only needs to package, not run.
if [[ "$EUID" -eq 0 ]]; then # makepkg refuses to run as root (the CI container), so hand it to an
# unprivileged user there.
run_makepkg() {
if [[ "$EUID" -eq 0 ]]; then
useradd -m builder 2>/dev/null || true useradd -m builder 2>/dev/null || true
chown -R builder "$pkg" chown -R builder "$pkg"
(cd "$pkg" && runuser -u builder -- makepkg -fdc) (cd "$pkg" && runuser -u builder -- makepkg "$@")
(cd "$pkg" && runuser -u builder -- makepkg --printsrcinfo > .SRCINFO) else
chown -R 0:0 "$pkg" (cd "$pkg" && makepkg "$@")
fi
}
if git diff --quiet -- "$pkg/PKGBUILD"; then
rel="$oldrel"
else else
(cd "$pkg" && makepkg -fdc) if [[ "$ver" != "$oldver" ]]; then
(cd "$pkg" && makepkg --printsrcinfo > .SRCINFO) rel=1
else
rel=$((oldrel + 1))
fi
sed -i "s|^pkgrel=.*|pkgrel=$rel|" "$pkg/PKGBUILD"
# -d: the runner only needs to package, not run the result
run_makepkg -fdc
echo "$pkg: makepkg test build succeeded"
fi fi
echo "$pkg: makepkg test build succeeded"
rm -f "$pkg/$asset" "$pkg"/*.pkg.tar.* # .SRCINFO regeneration is cheap - do it every run so it can never go stale
run_makepkg --printsrcinfo > "$pkg/.SRCINFO.new"
mv "$pkg/.SRCINFO.new" "$pkg/.SRCINFO"
[[ "$EUID" -eq 0 ]] && chown -R 0:0 "$pkg"
# drop downloaded sources and build leftovers (all gitignored, never tracked)
rm -rf "$pkg/src" "$pkg/pkg"
rm -f "$pkg"/*.pkg.tar.* "$pkg"/*.tar.zst "$pkg"/*.tar.gz
### 4: commit back to this repository ######################################## ### 4: commit back to this repository ########################################
if [[ "${CI:-}" == "true" ]]; then if [[ "${CI:-}" == "true" ]]; then
git config --global --add safe.directory "$repo_root"
git config user.name "github-actions[bot]" git config user.name "github-actions[bot]"
git config user.email "41898282+github-actions[bot]@users.noreply.github.com" git config user.email "41898282+github-actions[bot]@users.noreply.github.com"
@@ -108,27 +138,31 @@ if [[ -z "${AUR_SSH_PRIVATE_KEY:-}" ]]; then
exit 1 exit 1
fi fi
mkdir -p ~/.ssh && chmod 700 ~/.ssh # Pass the key and known_hosts explicitly instead of via ~/.ssh: in the CI
printf '%s\n' "$AUR_SSH_PRIVATE_KEY" > ~/.ssh/aur_key # container $HOME and the passwd home directory disagree, and ssh resolves
chmod 600 ~/.ssh/aur_key # "~" through the latter, silently ignoring anything written to $HOME/.ssh.
cat >> ~/.ssh/config <<'EOF' sshdir="$(mktemp -d)"
Host aur.archlinux.org printf '%s\n' "$AUR_SSH_PRIVATE_KEY" > "$sshdir/key"
User aur chmod 600 "$sshdir/key"
IdentityFile ~/.ssh/aur_key
IdentitiesOnly yes
EOF
# Pinned host key, see https://aur.archlinux.org # Pinned host key, see https://aur.archlinux.org
echo 'aur.archlinux.org ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIEuBKrPzbawxA/k2g6NcyV5jmqwJ2s+zpgZGZ7tpLIcN' \ echo 'aur.archlinux.org ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIEuBKrPzbawxA/k2g6NcyV5jmqwJ2s+zpgZGZ7tpLIcN' \
>> ~/.ssh/known_hosts > "$sshdir/known_hosts"
export GIT_SSH_COMMAND="ssh -i $sshdir/key -o UserKnownHostsFile=$sshdir/known_hosts -o IdentitiesOnly=yes"
aurdir="$(mktemp -d)" aurdir="$(mktemp -d)"
git clone "ssh://aur@aur.archlinux.org/$pkg.git" "$aurdir" git clone "ssh://aur@aur.archlinux.org/$pkg.git" "$aurdir"
cp "$pkg/PKGBUILD" "$pkg/.SRCINFO" "$aurdir/"
# every tracked file of the package except our automation glue belongs on
# the AUR (PKGBUILD, .SRCINFO, .desktop files, .install files, ...)
while IFS= read -r f; do
[[ "$(basename "$f")" == "pkg.sh" ]] && continue
cp "$f" "$aurdir/"
done < <(git ls-files "$pkg")
cd "$aurdir" cd "$aurdir"
git config user.name "${AUR_GIT_NAME:-Felitendo}" git config user.name "${AUR_GIT_NAME:-Felitendo}"
git config user.email "${AUR_GIT_EMAIL:-95575686+Felitendo@users.noreply.github.com}" git config user.email "${AUR_GIT_EMAIL:-95575686+Felitendo@users.noreply.github.com}"
git add PKGBUILD .SRCINFO git add -A
if git diff --cached --quiet && [[ -n "$(git ls-remote origin)" ]]; then if git diff --cached --quiet && [[ -n "$(git ls-remote origin)" ]]; then
echo "$pkg: AUR package is already up to date" echo "$pkg: AUR package is already up to date"
else else
@@ -136,3 +170,22 @@ else
git push origin HEAD:master git push origin HEAD:master
echo "$pkg: pushed $ver-$rel to the AUR" echo "$pkg: pushed $ver-$rel to the AUR"
fi fi
### 6: prune superseded GitHub releases ######################################
# Build-mode packages get one release per version; once a newer version is
# fully published (asset built, PKGBUILD updated, AUR pushed - i.e. we got
# this far) the older releases are no longer referenced by anything, so drop
# them together with their tags. Runs every time to also catch leftovers.
cd "$repo_root"
if declare -f build_artifact >/dev/null; then
while IFS= read -r tag; do
[[ "$tag" == "$pkg-$ver" ]] && continue
rest="${tag#"$pkg-"}"
# only this package's tags: "<pkg>-<version>" (a pkgver never contains
# "-", which also keeps prefix-sharing package names apart)
[[ "$tag" == "$pkg-"* && "$rest" != *-* ]] || continue
echo "$pkg: deleting superseded release $tag"
gh release delete "$tag" --cleanup-tag --yes
done < <(gh release list --limit 100 --json tagName -q '.[].tagName')
fi
+27
View File
@@ -0,0 +1,27 @@
pkgbase = sharpemu-bin
pkgdesc = Experimental PlayStation 5 emulator (prebuilt)
pkgver = 0.0.2_beta.5
pkgrel = 1
url = https://github.com/sharpemu/sharpemu
arch = x86_64
license = GPL-2.0-or-later
depends = glibc
depends = gcc-libs
depends = icu
depends = openssl
depends = vulkan-icd-loader
depends = libx11
depends = libxcursor
depends = libxi
depends = libxinerama
depends = libxrandr
depends = libxkbcommon
depends = wayland
provides = sharpemu
conflicts = sharpemu
noextract = sharpemu-0.0.2-beta.5-linux-x64.tar.gz
options = !strip
source_x86_64 = https://github.com/sharpemu/sharpemu/releases/download/v0.0.2-beta.5/sharpemu-0.0.2-beta.5-linux-x64.tar.gz
sha256sums_x86_64 = 5e75173da220832e8ca56d4b88fd7effc77772da9b785bfb721ff138d5664cc4
pkgname = sharpemu-bin
+39
View File
@@ -0,0 +1,39 @@
# Maintainer: Felitendo
# This PKGBUILD is updated automatically:
# https://github.com/Felitendo/PKGBUILDS
pkgname=sharpemu-bin
pkgver=0.0.2_beta.5
pkgrel=1
pkgdesc="Experimental PlayStation 5 emulator (prebuilt)"
arch=('x86_64')
url="https://github.com/sharpemu/sharpemu"
license=('GPL-2.0-or-later')
# The self-contained .NET binary bundles its own libglfw.so.3, which in turn
# dlopens the X11/Wayland client libraries at runtime.
depends=('glibc' 'gcc-libs' 'icu' 'openssl' 'vulkan-icd-loader'
'libx11' 'libxcursor' 'libxi' 'libxinerama' 'libxrandr'
'libxkbcommon' 'wayland')
provides=('sharpemu')
conflicts=('sharpemu')
options=('!strip')
# upstream tags use hyphens (v0.0.2-beta.4), which pkgver must not contain
_upver="${pkgver//_/-}"
noextract=("sharpemu-${_upver}-linux-x64.tar.gz")
source_x86_64=("https://github.com/sharpemu/sharpemu/releases/download/v${_upver}/sharpemu-${_upver}-linux-x64.tar.gz")
sha256sums_x86_64=('5e75173da220832e8ca56d4b88fd7effc77772da9b785bfb721ff138d5664cc4')
package() {
# extracted straight into pkgdir so new files in future upstream archives
# are picked up automatically
install -d "$pkgdir/opt/$pkgname"
tar -xzf "$srcdir/sharpemu-${_upver}-linux-x64.tar.gz" -C "$pkgdir/opt/$pkgname"
chmod 755 "$pkgdir/opt/$pkgname/SharpEmu"
install -d "$pkgdir/usr/bin"
ln -s "/opt/$pkgname/SharpEmu" "$pkgdir/usr/bin/sharpemu"
install -Dm644 "$pkgdir/opt/$pkgname/LICENSE.txt" \
"$pkgdir/usr/share/licenses/$pkgname/LICENSE.txt"
}
+28
View File
@@ -0,0 +1,28 @@
# sharpemu-bin - SharpEmu (https://github.com/sharpemu/sharpemu), an
# experimental PlayStation 5 emulator written in C#.
#
# Upstream publishes prebuilt linux-x64 release assets itself, so there is no
# build_artifact() here: on a new version only pkgver and the checksums are
# refreshed and the result is pushed to the AUR.
#
# Upstream versions contain hyphens (v0.0.2-beta.4), which an Arch pkgver
# must not; latest_version therefore reports the underscored form
# (0.0.2_beta.4) and the PKGBUILD derives the upstream form back via _upver.
UPSTREAM_REPO="sharpemu/sharpemu"
latest_version() {
# gh instead of plain curl: authenticated API calls, so shared-IP rate
# limits on the CI runners can't bite.
gh api "repos/$UPSTREAM_REPO/releases/latest" --jq '.tag_name' \
| sed -e 's/^v//' -e 's/-/_/g'
}
# refresh_checksums <version> <pkgbuild-path>
refresh_checksums() {
local ver="$1" pkgbuild="$2"
local upver="${ver//_/-}" sha
sha="$(curl -sfL "https://github.com/$UPSTREAM_REPO/releases/download/v$upver/sharpemu-$upver-linux-x64.tar.gz" \
| sha256sum | cut -d' ' -f1)"
sed -i "s|^sha256sums_x86_64=.*|sha256sums_x86_64=('$sha')|" "$pkgbuild"
}
+7 -4
View File
@@ -1,22 +1,25 @@
pkgbase = timetable-bin pkgbase = timetable-bin
pkgdesc = GTK4 + LibAdwaita client for WebUntis (prebuilt, bundles python-webuntis) pkgdesc = GTK4 + LibAdwaita client for WebUntis (prebuilt)
pkgver = 3.1 pkgver = 4.2.1
pkgrel = 1 pkgrel = 1
url = https://codeberg.org/ostfriese4/untis url = https://codeberg.org/ostfriese4/untis
arch = any arch = any
license = GPL-3.0-or-later license = GPL-3.0-or-later
depends = gtk4 depends = gtk4
depends = libadwaita depends = libadwaita
depends = webkitgtk-6.0
depends = libsecret
depends = python depends = python
depends = python-gobject depends = python-gobject
depends = python-requests depends = python-requests
depends = python-pyotp
depends = glib2 depends = glib2
depends = hicolor-icon-theme depends = hicolor-icon-theme
provides = untis provides = untis
provides = timetable provides = timetable
conflicts = untis conflicts = untis
conflicts = timetable conflicts = timetable
source = https://github.com/Felitendo/PKGBUILDS/releases/download/timetable-bin-3.1/timetable-bin-3.1.tar.zst source = https://github.com/Felitendo/PKGBUILDS/releases/download/timetable-bin-4.2.1/timetable-bin-4.2.1.tar.zst
sha256sums = ffd735d1a08204fe18e563815813b3a62f7625bce5bd5d4c086f1456422e0590 sha256sums = c68179716fdb5eb6268203168207a1ea7d03a75456c00de38d152dc6098bd0dc
pkgname = timetable-bin pkgname = timetable-bin
+5 -4
View File
@@ -3,17 +3,18 @@
# https://github.com/Felitendo/PKGBUILDS # https://github.com/Felitendo/PKGBUILDS
pkgname=timetable-bin pkgname=timetable-bin
pkgver=3.1 pkgver=4.2.1
pkgrel=1 pkgrel=1
pkgdesc="GTK4 + LibAdwaita client for WebUntis (prebuilt, bundles python-webuntis)" pkgdesc="GTK4 + LibAdwaita client for WebUntis (prebuilt)"
arch=('any') arch=('any')
url="https://codeberg.org/ostfriese4/untis" url="https://codeberg.org/ostfriese4/untis"
license=('GPL-3.0-or-later') license=('GPL-3.0-or-later')
depends=('gtk4' 'libadwaita' 'python' 'python-gobject' 'python-requests' 'glib2' 'hicolor-icon-theme') depends=('gtk4' 'libadwaita' 'webkitgtk-6.0' 'libsecret' 'python' 'python-gobject'
'python-requests' 'python-pyotp' 'glib2' 'hicolor-icon-theme')
provides=('untis' 'timetable') provides=('untis' 'timetable')
conflicts=('untis' 'timetable') conflicts=('untis' 'timetable')
source=("https://github.com/Felitendo/PKGBUILDS/releases/download/${pkgname}-${pkgver}/${pkgname}-${pkgver}.tar.zst") source=("https://github.com/Felitendo/PKGBUILDS/releases/download/${pkgname}-${pkgver}/${pkgname}-${pkgver}.tar.zst")
sha256sums=('ffd735d1a08204fe18e563815813b3a62f7625bce5bd5d4c086f1456422e0590') sha256sums=('c68179716fdb5eb6268203168207a1ea7d03a75456c00de38d152dc6098bd0dc')
package() { package() {
cp -a "$srcdir/usr" "$pkgdir/" cp -a "$srcdir/usr" "$pkgdir/"
+1 -6
View File
@@ -8,7 +8,7 @@
UPSTREAM_REPO="ostfriese4/untis" UPSTREAM_REPO="ostfriese4/untis"
# Installed in CI (pacman) before build_artifact runs. # Installed in CI (pacman) before build_artifact runs.
BUILD_DEPS=(meson ninja glib2 glib2-devel gtk4 libadwaita python python-gobject python-pip gettext) BUILD_DEPS=(meson ninja glib2 glib2-devel gtk4 libadwaita python python-gobject gettext)
latest_version() { latest_version() {
curl -sf "https://codeberg.org/api/v1/repos/$UPSTREAM_REPO/releases/latest" \ curl -sf "https://codeberg.org/api/v1/repos/$UPSTREAM_REPO/releases/latest" \
@@ -31,11 +31,6 @@ build_artifact() {
meson setup "$workdir/build" "$workdir/untis" --prefix=/usr --buildtype=release meson setup "$workdir/build" "$workdir/untis" --prefix=/usr --buildtype=release
meson install -C "$workdir/build" --destdir "$destdir" meson install -C "$workdir/build" --destdir "$destdir"
# Bundle the pure-python webuntis library: it is packaged neither in the
# Arch repos nor on the AUR. /usr/share/untis is on the launcher's sys.path.
pip download --no-deps --only-binary :all: --dest "$workdir/wheels" webuntis
python -m zipfile -e "$workdir"/wheels/webuntis-*.whl "$destdir/usr/share/untis/"
# These caches are generated by pacman hooks; shipping them would cause # These caches are generated by pacman hooks; shipping them would cause
# file conflicts on install. # file conflicts on install.
rm -f "$destdir/usr/share/glib-2.0/schemas/gschemas.compiled" \ rm -f "$destdir/usr/share/glib-2.0/schemas/gschemas.compiled" \