ci: add an arch tarball with static opencv

This commit is contained in:
Felitendo committed 2026-09-28 10:21:39 +02:00
1 parent 0a48ba9338
commit fd8449ea31
4 files changed
+209 -13

No files matched your search

+21 -10
View File
@@ -8,13 +8,15 @@ description of the layout, and two descriptions drift.
|---|---|
| `deb/control`, `deb/copyright` | metadata for the Debian binary package |
| `rpm/face-unlock.spec` | the RPM spec |
| `build-deb.sh`, `build-rpm.sh` | build one package into `dist/` |
| `build-deb.sh`, `build-rpm.sh`, `build-tarball.sh` | build one package into `dist/` |
| `build-opencv.sh` | builds the static OpenCV the Arch tarball links in |
| `check-version.sh` | refuses a tag that disagrees with the Makefile |
| `publish-repos.sh` | regenerates the APT and RPM repositories |
| `pages/` | the landing page and the `.repo` file served from GitHub Pages |
The AUR package lives in [Felitendo/PKGBUILDS](https://github.com/Felitendo/PKGBUILDS/tree/main/face-unlock).
Its CI notices a new GitHub release, updates the checksum and pushes to the AUR.
The AUR packages live in [Felitendo/PKGBUILDS](https://github.com/Felitendo/PKGBUILDS):
`face-unlock` builds from source, `face-unlock-bin` takes the Arch tarball.
Its CI notices a new GitHub release, updates the checksums and pushes to the AUR.
Unlike the shell-only LoonixTools, this one is compiled. The packages are per
architecture (amd64 and x86_64), and they need the Qt 6 and KDE Frameworks 6
@@ -28,6 +30,13 @@ against. The `.deb` is therefore built twice, in Debian 13 and in Ubuntu 26.04
gets an APT repository of its own: `deb/trixie` and `deb/resolute`. The RPM is
built on the current Fedora.
The Arch tarball (`face-unlock-<version>-arch-x86_64.tar.zst`) is built on Arch,
for the same reason. It holds a folder with the `make install` tree. Arch
changes the OpenCV soname with every new OpenCV, so OpenCV is linked in
statically (`build-opencv.sh`: only the modules the daemon uses, nothing it
would load at run time). Qt stays shared, so a new Qt minor version on Arch
needs a new release.
The two networks (YuNet and SFace, from the OpenCV model zoo) are not in the
repository. `make models` downloads them and checks them against the
checksums in the Makefile. The RPM spec and the PKGBUILD list them as sources
@@ -44,9 +53,10 @@ disables the socket.
```bash
packaging/build-deb.sh # in a Debian 13 container, with the -dev packages from release.yml
packaging/build-rpm.sh # in a Fedora container, with the -devel packages from the spec
packaging/build-opencv.sh && packaging/build-tarball.sh # in an Arch container, with the packages from release.yml
```
Both take the version from `make version` unless one is passed as the first
All three take the version from `make version` unless one is passed as the first
argument.
## Making a release
@@ -56,10 +66,11 @@ argument.
2. Add the release to `CHANGELOG.md`, in the format CLAUDE.md describes.
3. Commit, then `git tag vX.Y.Z && git push --tags`.
The `release` workflow builds both packages in a Debian and a Fedora container,
refuses the tag if it disagrees with the Makefile or has no changelog entry,
attaches the packages to a GitHub release with the entry as its notes, and adds
them to the APT and RPM repositories on the `gh-pages` branch.
The `release` workflow builds the packages in Debian, Ubuntu, Fedora and Arch
containers, refuses the tag if it disagrees with the Makefile or has no
changelog entry, attaches the packages to a GitHub release with the entry as
its notes, and adds the deb and rpm files to the APT and RPM repositories on
the `gh-pages` branch.
## Trying the release path first
@@ -67,7 +78,7 @@ them to the APT and RPM repositories on the `gh-pages` branch.
gh workflow run release.yml -f dry_run=true
```
Builds both packages, builds both repositories with a key generated on the
Builds the packages, builds both repositories with a key generated on the
spot, checks the signatures, and installs the packages back out of the
repositories. Nothing is pushed and no release is made.
@@ -81,7 +92,7 @@ gpg --armor --export-secret-keys 'face-unlock repository' \
| gh secret set GPG_PRIVATE_KEY
```
Without the secret the workflow still builds both packages and attaches them to
Without the secret the workflow still builds the packages and attaches them to
the release; it says so in the log and leaves the repositories alone.
## Pointing Pages at it, once, in this order
+77
View File
@@ -0,0 +1,77 @@
#!/usr/bin/env bash
#
# Builds the OpenCV the Arch tarball links in, as static libraries.
#
# Arch moves to a new OpenCV now and then, each with a new soname, and a
# daemon linked against the old one then no longer starts. Linked in
# statically, the daemon brings its own. Only the modules face-unlock uses are
# built, with OpenCV's own copies of zlib, libjpeg and libpng, so nothing is
# left to load at run time. The camera is read through V4L2, which OpenCV
# talks to directly.
#
# packaging/build-opencv.sh [PREFIX]
#
# Installs into PREFIX (build/opencv-static by default) and does nothing when
# PREFIX already holds what this script builds. Needs: cmake, a C++ compiler,
# curl.
set -euo pipefail
here="$(cd -- "$(dirname -- "${BASH_SOURCE[0]}")/.." && pwd)"
prefix="${1:-$here/build/opencv-static}"
# 4.x, like the deb and the rpm. The static dnn of 5.0.0 does not link
# (https://github.com/opencv/opencv/issues/29342).
version=4.14.0
sha256=ee8fb9b30eb60850431b4656447080e3737b56e45719c92b67f245950609f86e
# A change to this script is a different build.
stamp="$(sha256sum "${BASH_SOURCE[0]}" | cut -d' ' -f1)"
if [[ -f $prefix/.stamp && $(<"$prefix/.stamp") == "$stamp" ]]; then
echo "$prefix already has this OpenCV"
exit 0
fi
# It is emptied before the install, so it has to be one of ours.
if [[ -e $prefix && ! -f $prefix/.stamp ]]; then
echo "$0: $prefix exists and was not made by this script" >&2
exit 1
fi
work="$(mktemp -d)"
trap 'rm -rf -- "$work"' EXIT
curl -fL --retry 3 -o "$work/opencv.tar.gz" \
"https://github.com/opencv/opencv/archive/refs/tags/$version.tar.gz"
echo "$sha256 $work/opencv.tar.gz" | sha256sum -c --quiet -
tar -xzf "$work/opencv.tar.gz" -C "$work"
src="$work/opencv-$version"
# BUILD_LIST adds what the listed modules need (calib3d, features2d, flann).
# The rest is switched off because it would be picked up from the system or
# downloaded: codecs, video backends, IPP and the other accelerators.
cmake -S "$src" -B "$work/build" \
-DCMAKE_BUILD_TYPE=Release \
-DCMAKE_INSTALL_PREFIX="$prefix" \
-DBUILD_SHARED_LIBS=OFF \
-DBUILD_LIST=core,imgproc,imgcodecs,videoio,objdetect,dnn \
-DBUILD_TESTS=OFF -DBUILD_PERF_TESTS=OFF -DBUILD_EXAMPLES=OFF \
-DBUILD_DOCS=OFF -DBUILD_opencv_apps=OFF -DBUILD_JAVA=OFF \
-DBUILD_ZLIB=ON -DBUILD_JPEG=ON -DBUILD_PNG=ON -DBUILD_PROTOBUF=ON \
-DWITH_V4L=ON \
-DWITH_FFMPEG=OFF -DWITH_GSTREAMER=OFF -DWITH_OBSENSOR=OFF \
-DWITH_TIFF=OFF -DWITH_WEBP=OFF -DWITH_AVIF=OFF -DWITH_OPENEXR=OFF \
-DWITH_OPENJPEG=OFF -DWITH_JASPER=OFF \
-DWITH_IPP=OFF -DWITH_ITT=OFF -DWITH_OPENCL=OFF -DWITH_VA=OFF -DWITH_VA_INTEL=OFF \
-DWITH_LAPACK=OFF -DWITH_EIGEN=OFF -DWITH_FLATBUFFERS=OFF -DWITH_QUIRC=OFF -DWITH_ADE=OFF
cmake --build "$work/build" --parallel "$(nproc)"
rm -rf -- "$prefix"
cmake --install "$work/build"
# OpenCV installs the licences of the libraries in it, but not its own.
mv "$prefix"/share/licenses/opencv* "$prefix/share/licenses/opencv"
install -Dm644 "$src/LICENSE" "$prefix/share/licenses/opencv/LICENSE"
# A picture with a face, for the check that the models load and find one.
install -Dm644 "$src/samples/data/messi5.jpg" "$prefix/share/face-unlock-check/face.jpg"
echo "$stamp" > "$prefix/.stamp"
+70
View File
@@ -0,0 +1,70 @@
#!/usr/bin/env bash
#
# Builds the tarball for Arch Linux into dist/. The AUR package
# face-unlock-bin is made from it.
#
# Like the deb and the rpm, it holds what `make install` produced, under a
# folder named like the tarball. One thing is different: OpenCV is linked in
# statically (packaging/build-opencv.sh), so a new OpenCV on Arch does not
# break the daemon. Qt stays shared. The agent uses Qt's private API, so the
# tarball fits the Qt that Arch had when it was built.
#
# Needs: make, cmake, a C++ compiler, the packages check.yml installs (without
# opencv), msgfmt (gettext), scdoc, curl, zstd, and the static OpenCV:
#
# packaging/build-opencv.sh && packaging/build-tarball.sh
set -euo pipefail
here="$(cd -- "$(dirname -- "${BASH_SOURCE[0]}")/.." && pwd)"
version="${1:-$(make -s -C "$here" version)}"
opencv="${OPENCV_PREFIX:-$here/build/opencv-static}"
name="face-unlock-$version-arch-$(uname -m)"
for tool in msgfmt scdoc cmake readelf zstd; do
command -v "$tool" > /dev/null || { echo "$0: $tool is not installed" >&2; exit 1; }
done
opencv_dir="$(dirname "$(find "$opencv" -name OpenCVConfig.cmake -print -quit 2>/dev/null)")"
[[ $opencv_dir != . ]] || { echo "$0: no OpenCV in $opencv, run packaging/build-opencv.sh first" >&2; exit 1; }
root="$(mktemp -d)"
work="$(mktemp -d)"
trap 'rm -rf -- "$root" "$work"' EXIT
dest="$root/$name"
make -C "$here" models
make -C "$here" install \
DESTDIR="$dest" \
PREFIX=/usr \
VERSION="$version" \
BUILDDIR="$work/build" \
PAMDIR=/usr/lib/security \
SYSTEMUNITDIR=/usr/lib/systemd/system \
USERUNITDIR=/usr/lib/systemd/user \
CMAKE_FLAGS="-DOpenCV_DIR=$opencv_dir"
# The tests, and the models on a real face: the part a smaller OpenCV could
# break without anything else noticing.
ctest --test-dir "$work/build" --output-on-failure
face="$opencv/share/face-unlock-check/face.jpg"
"$work/build/test_images" "$dest/usr/share/face-unlock/models" "$face" "$face" | tee "$work/faces"
grep -q 'similarity' "$work/faces" || { echo "$0: the models found no face" >&2; exit 1; }
if readelf -d "$dest/usr/lib/face-unlock/face-unlockd" | grep -q 'libopencv'; then
echo "$0: the daemon still loads a shared OpenCV" >&2
exit 1
fi
# The program is GPL, OpenCV and the libraries in it come with their own
# licences, and the copyright file names the models' authors and licences.
lic="$dest/usr/share/licenses/face-unlock"
install -Dm644 "$here/LICENSE" "$lic/LICENSE"
install -Dm644 "$here/packaging/deb/copyright" "$lic/copyright"
cp -r "$opencv/share/licenses/opencv" "$lic/opencv"
mkdir -p "$here/dist"
out="$here/dist/$name.tar.zst"
tar -C "$root" --owner=0 --group=0 --numeric-owner --sort=name \
-I 'zstd -19 -T0' -cf "$out" "$name"
echo "$out"