build: build on debian 13 and kubuntu 26.04, one apt repository each
release / Debian package (Kubuntu 26.04) (push) Failing after 1m45s
release / Debian package (Debian 13) (push) Canceled after 1s
release / RPM package (push) Failing after 1m26s
release / Release and repositories (push) Skipped
release / Install from the APT repository (Kubuntu 26.04) (push) Skipped
release / Install from the APT repository (Debian 13) (push) Skipped
release / Install from the RPM repository (push) Skipped

This commit is contained in:
Felitendo committed 2026-09-23 21:10:38 +02:00
1 parent c26eef95b1
commit 8129215d06
8 files changed
+166 -210

No files matched your search

+6
View File
@@ -20,6 +20,12 @@ development packages to build: Debian 13 (trixie) and current Fedora have
them. The Debian package's library dependencies are read off the binaries by
`dpkg-shlibdeps`; RPM does the same on its own.
The program uses Qt's private API, so a package only fits the Qt it was built
against. The `.deb` is therefore built twice, in Debian 13 and in Ubuntu 26.04
(for Kubuntu), with a suffix on the version (`~deb13`, `~ubuntu26.04`), and each
gets an APT repository of its own: `deb/trixie` and `deb/resolute`. The RPM is
built on the current Fedora.
The two networks (YuNet and SFace, from the OpenCV model zoo) are not in the
repository. `make models` downloads them and checks them against the
checksums in the Makefile. The RPM spec and the PKGBUILD list them as sources
+5 -2
View File
@@ -18,6 +18,9 @@ set -euo pipefail
here="$(cd -- "$(dirname -- "${BASH_SOURCE[0]}")/.." && pwd)"
version="${1:-$(make -s -C "$here" version)}"
# The package depends on the exact Qt of the distribution it is built on, so
# each one gets a build of its own, told apart by a suffix: ~deb13, ~ubuntu26.04.
debversion="$version${DEB_SUFFIX:-}"
name=plasma-face-unlock
# A package without its man page or its translations is not a package this
@@ -49,7 +52,7 @@ depends="$(cd "$work" && dpkg-shlibdeps -O "${elves[@]/#/-e}" 2>/dev/null | sed
[[ -n $depends ]] || { echo "$0: dpkg-shlibdeps found no dependencies" >&2; exit 1; }
install -d "$root/DEBIAN"
sed -e "s|@VERSION@|$version|g" -e "s|@ARCH@|$arch|g" -e "s|@DEPENDS@|$depends|g" \
sed -e "s|@VERSION@|$debversion|g" -e "s|@ARCH@|$arch|g" -e "s|@DEPENDS@|$depends|g" \
"$here/packaging/deb/control" > "$root/DEBIAN/control"
install -Dm644 "$here/packaging/deb/copyright" "$root/usr/share/doc/$name/copyright"
@@ -69,7 +72,7 @@ chmod 755 "$root/DEBIAN/prerm"
| LC_ALL=C sort -z | xargs -0 md5sum > DEBIAN/md5sums )
mkdir -p "$here/dist"
out="$here/dist/${name}_${version}_${arch}.deb"
out="$here/dist/${name}_${debversion}_${arch}.deb"
dpkg-deb --root-owner-group --build "$root" "$out" > /dev/null
echo "$out"
+12 -3
View File
@@ -76,16 +76,25 @@
documentation</a> are on GitHub.
</p>
<h2>Debian 13 or newer, Kubuntu 25.04 or newer</h2>
<h2>Debian 13</h2>
<pre><code>sudo install -d -m 0755 /etc/apt/keyrings
curl -fsSL @BASEURL@/KEY.gpg \
| sudo gpg --dearmor -o /etc/apt/keyrings/plasma-face-unlock.gpg
echo "deb [signed-by=/etc/apt/keyrings/plasma-face-unlock.gpg] @BASEURL@/deb ./" \
echo "deb [signed-by=/etc/apt/keyrings/plasma-face-unlock.gpg] @BASEURL@/deb/trixie ./" \
| sudo tee /etc/apt/sources.list.d/plasma-face-unlock.list
sudo apt update
sudo apt install plasma-face-unlock</code></pre>
<h2>Fedora (KDE Plasma)</h2>
<h2>Kubuntu 26.04</h2>
<pre><code>sudo install -d -m 0755 /etc/apt/keyrings
curl -fsSL @BASEURL@/KEY.gpg \
| sudo gpg --dearmor -o /etc/apt/keyrings/plasma-face-unlock.gpg
echo "deb [signed-by=/etc/apt/keyrings/plasma-face-unlock.gpg] @BASEURL@/deb/resolute ./" \
| sudo tee /etc/apt/sources.list.d/plasma-face-unlock.list
sudo apt update
sudo apt install plasma-face-unlock</code></pre>
<h2>Fedora 44 (KDE Plasma)</h2>
<pre><code>sudo curl -fsSL -o /etc/yum.repos.d/plasma-face-unlock.repo \
@BASEURL@/plasma-face-unlock.repo
sudo dnf install plasma-face-unlock</code></pre>
+26 -38
View File
@@ -24,46 +24,34 @@ base_url="${PFU_REPO_URL:-https://loonixtools.github.io/plasma-face-unlock}"
keyid="$(gpg --list-secret-keys --with-colons | awk -F: '/^sec:/ { print $5; exit }')"
[[ -n $keyid ]] || { echo "$0: no secret key in the keyring" >&2; exit 1; }
mkdir -p "$pages/deb" "$pages/rpm"
cp -- "$incoming"/*.deb "$pages/deb/"
mkdir -p "$pages/rpm"
cp -- "$incoming"/*.rpm "$pages/rpm/"
# ---------------------------------------------------------------------------
# APT
# ---------------------------------------------------------------------------
# A flat repository: the packages and their index sit in one directory and the
# sources line ends in "./". There is one distribution here and it is the same
# package for all of them, so the suite and component machinery of a pool
# layout would describe nothing.
(
cd "$pages/deb"
# One APT repository per distribution: each .deb depends on the exact Qt it was
# built against, and its version carries the suffix saying which one that was.
for suite in trixie:deb13 resolute:ubuntu26.04; do
codename="${suite%%:*}"
tag="${suite#*:}"
mkdir -p "$pages/deb/$codename"
cp -- "$incoming"/*"~${tag}_"*.deb "$pages/deb/$codename/"
(
cd "$pages/deb/$codename"
rm -f Packages Packages.gz Release Release.gpg InRelease
dpkg-scanpackages --multiversion . > Packages
gzip -9kf Packages
apt-ftparchive \
-o APT::FTPArchive::Release::Origin=plasma-face-unlock \
-o APT::FTPArchive::Release::Label=plasma-face-unlock \
-o APT::FTPArchive::Release::Suite="$codename" \
-o APT::FTPArchive::Release::Codename="$codename" \
-o APT::FTPArchive::Release::Architectures=amd64 \
-o APT::FTPArchive::Release::Components=main \
release . > Release
gpg --batch --yes --local-user "$keyid" --clearsign --output InRelease Release
gpg --batch --yes --local-user "$keyid" --detach-sign --armor --output Release.gpg Release
)
done
# The old index must be gone before the new one is written: apt-ftparchive
# hashes every file in the directory, and a Release that hashes the
# previous Release is a Release that cannot be verified.
rm -f Packages Packages.gz Release Release.gpg InRelease
dpkg-scanpackages --multiversion . > Packages
gzip -9kf Packages
apt-ftparchive \
-o APT::FTPArchive::Release::Origin=plasma-face-unlock \
-o APT::FTPArchive::Release::Label=plasma-face-unlock \
-o APT::FTPArchive::Release::Suite=stable \
-o APT::FTPArchive::Release::Codename=stable \
-o APT::FTPArchive::Release::Architectures=amd64 \
-o APT::FTPArchive::Release::Components=main \
release . > Release
# Both signatures: InRelease is what current apt fetches, Release.gpg is
# what an older one falls back to.
gpg --batch --yes --local-user "$keyid" --clearsign --output InRelease Release
gpg --batch --yes --local-user "$keyid" --detach-sign --armor --output Release.gpg Release
)
# ---------------------------------------------------------------------------
# RPM
# ---------------------------------------------------------------------------
(
cd "$pages/rpm"
createrepo_c --quiet --update .
@@ -85,4 +73,4 @@ sed "s|@BASEURL@|$base_url|g" "$here/packaging/pages/plasma-face-unlock.repo" \
touch "$pages/.nojekyll"
echo "signed with $keyid"
ls -1 "$pages/deb" "$pages/rpm"
ls -1 "$pages"/deb/* "$pages/rpm"