feat: add plasma-face-unlock

This commit is contained in:
Felitendo committed 2026-09-22 19:39:04 +02:00
commit f671acc93b
105 files changed
+13862

No files matched your search

+254
View File
@@ -0,0 +1,254 @@
name: release
on:
push:
tags: ['v*']
workflow_dispatch:
inputs:
dry_run:
description: >-
Build the repositories with a throwaway key and install from them,
without publishing anything.
type: boolean
default: false
permissions:
contents: write
jobs:
deb:
name: Debian package
runs-on: ubuntu-latest
# Plasma 6 arrived in Debian with trixie.
container: debian:trixie
steps:
- name: Install the build tools
run: |
apt-get update -qq
apt-get install -y --no-install-recommends \
ca-certificates curl git make cmake g++ pkg-config gettext scdoc dpkg-dev \
qt6-base-dev qt6-base-private-dev qt6-declarative-dev \
qt6-wayland-dev qt6-wayland-dev-tools qt6-wayland-private-dev \
liblayershellqtinterface-dev libkf6idletime-dev libkf6i18n-dev \
libopencv-dev libpam0g-dev libsystemd-dev
- uses: actions/checkout@v7
- name: Check the tag against the Makefile
run: packaging/check-version.sh "${{ github.ref_name }}"
- run: packaging/build-deb.sh
- name: Look inside what was built
run: |
dpkg-deb --info dist/*.deb
dpkg-deb --contents dist/*.deb
- uses: actions/upload-artifact@v7
with:
name: deb
path: dist/*.deb
if-no-files-found: error
rpm:
name: RPM package
runs-on: ubuntu-latest
container: fedora:latest
steps:
- name: Install the build tools
run: |
dnf install -y --setopt=install_weak_deps=False \
git make cmake gcc-c++ gettext scdoc tar curl rpm-build rpm-sign systemd-rpm-macros \
'pkgconfig(systemd)' 'pkgconfig(libsystemd)' pam-devel opencv-devel \
qt6-qtbase-devel qt6-qtbase-private-devel qt6-qtdeclarative-devel qt6-qtwayland-devel \
layer-shell-qt-devel kf6-kidletime-devel kf6-ki18n-devel
- uses: actions/checkout@v7
- name: Check the tag against the Makefile
run: packaging/check-version.sh "${{ github.ref_name }}"
- run: packaging/build-rpm.sh
- name: Sign the package
env:
GPG_PRIVATE_KEY: ${{ secrets.GPG_PRIVATE_KEY }}
DRY_RUN: ${{ inputs.dry_run }}
run: |
if [ "$DRY_RUN" = "true" ]; then
gpg --batch --passphrase '' --quick-generate-key \
'dry run <dry-run@example.invalid>' rsa2048 sign never
elif [ -n "${GPG_PRIVATE_KEY:-}" ]; then
printf '%s' "$GPG_PRIVATE_KEY" | gpg --batch --import
else
echo "No GPG_PRIVATE_KEY secret; leaving the package unsigned."
exit 0
fi
keyid="$(gpg --list-secret-keys --with-colons | awk -F: '/^sec:/ { print $5; exit }')"
rpmsign --define "_gpg_name $keyid" --addsign dist/*.rpm
gpg --armor --export "$keyid" > dist/rpm-signer.asc
rpm --import dist/rpm-signer.asc
rpm --checksig dist/*.rpm
- name: Look inside what was built
run: |
rpm -qip dist/plasma-face-unlock-[0-9]*.rpm
rpm -qlp dist/plasma-face-unlock-[0-9]*.rpm
- uses: actions/upload-artifact@v7
with:
name: rpm
path: |
dist/*.rpm
dist/rpm-signer.asc
if-no-files-found: error
publish:
name: Release and repositories
needs: [deb, rpm]
if: startsWith(github.ref, 'refs/tags/v') || inputs.dry_run
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7
- uses: actions/download-artifact@v8
with:
path: incoming
merge-multiple: true
- name: Attach the packages to the release
if: ${{ !inputs.dry_run }}
env:
GH_TOKEN: ${{ github.token }}
run: |
gh release create "${{ github.ref_name }}" \
--title "${{ github.ref_name }}" \
--generate-notes \
incoming/*.deb incoming/*.rpm \
|| gh release upload "${{ github.ref_name }}" \
incoming/*.deb incoming/*.rpm --clobber
- name: Install the repository tools
run: |
sudo apt-get update -qq
sudo apt-get install -y --no-install-recommends \
dpkg-dev apt-utils createrepo-c
- name: Get a signing key
id: key
env:
GPG_PRIVATE_KEY: ${{ secrets.GPG_PRIVATE_KEY }}
DRY_RUN: ${{ inputs.dry_run }}
run: |
if [ "$DRY_RUN" = "true" ]; then
gpg --batch --passphrase '' --quick-generate-key \
'dry run <dry-run@example.invalid>' rsa2048 sign never
elif [ -n "${GPG_PRIVATE_KEY:-}" ]; then
printf '%s' "$GPG_PRIVATE_KEY" | gpg --batch --import
else
echo "present=no" >> "$GITHUB_OUTPUT"
echo "::warning::No GPG_PRIVATE_KEY secret, so the apt and dnf repositories were not updated. The packages are on the release."
exit 0
fi
echo "present=yes" >> "$GITHUB_OUTPUT"
- name: Check out the published repositories
if: steps.key.outputs.present == 'yes' && !inputs.dry_run
uses: actions/checkout@v7
with:
ref: gh-pages
path: pages
continue-on-error: true
- name: Update the repositories
if: steps.key.outputs.present == 'yes'
run: |
if [ ! -d pages/.git ]; then
rm -rf pages && mkdir pages
git -C pages init -q -b gh-pages
git -C pages remote add origin "https://github.com/${{ github.repository }}.git"
fi
rm -f incoming/rpm-signer.asc
packaging/publish-repos.sh pages incoming
- name: Check that what was written can be verified
if: steps.key.outputs.present == 'yes'
run: |
gpg --verify pages/deb/InRelease
gpg --verify pages/deb/Release.gpg pages/deb/Release
gpg --verify pages/rpm/repodata/repomd.xml.asc pages/rpm/repodata/repomd.xml
- uses: actions/upload-artifact@v7
if: inputs.dry_run
with:
name: pages
path: pages
include-hidden-files: true
- name: Push them
if: steps.key.outputs.present == 'yes' && !inputs.dry_run
env:
GH_TOKEN: ${{ github.token }}
run: |
cd pages
git config user.name "github-actions[bot]"
git config user.email "41898282+github-actions[bot]@users.noreply.github.com"
git add -A
git diff --quiet --cached && { echo "nothing changed"; exit 0; }
git commit -q -m "Publish ${{ github.ref_name }}"
git push "https://x-access-token:${GH_TOKEN}@github.com/${{ github.repository }}.git" HEAD:gh-pages
verify-apt:
name: Install from the APT repository
needs: publish
if: inputs.dry_run
runs-on: ubuntu-latest
container: debian:trixie
steps:
- uses: actions/download-artifact@v8
with:
name: pages
path: pages
- name: Install from the repository that was just built
run: |
apt-get update -qq && apt-get install -y --no-install-recommends gpg
install -d -m 0755 /etc/apt/keyrings
gpg --dearmor -o /etc/apt/keyrings/plasma-face-unlock.gpg < pages/KEY.gpg
echo "deb [signed-by=/etc/apt/keyrings/plasma-face-unlock.gpg] file://$PWD/pages/deb ./" \
> /etc/apt/sources.list.d/plasma-face-unlock.list
apt-get update
apt-get install -y plasma-face-unlock
useradd -m tester
runuser -u tester -- plasma-face-unlock --version
verify-dnf:
name: Install from the RPM repository
needs: publish
if: inputs.dry_run
runs-on: ubuntu-latest
container: fedora:latest
steps:
- uses: actions/download-artifact@v8
with:
name: pages
path: pages
- uses: actions/download-artifact@v8
with:
name: rpm
path: signer
- name: Install from the repository that was just built
run: |
rpm --import pages/KEY.gpg
rpm --import signer/rpm-signer.asc
cat > /etc/yum.repos.d/plasma-face-unlock.repo <<EOF
[plasma-face-unlock]
name=plasma-face-unlock
baseurl=file://$PWD/pages/rpm
enabled=1
gpgcheck=1
repo_gpgcheck=1
gpgkey=file://$PWD/pages/KEY.gpg
EOF
dnf install -y plasma-face-unlock util-linux
useradd -m tester
runuser -u tester -- plasma-face-unlock --version