feat: packages and a signed repository for Debian and Fedora
The code works on those distributions now; there was still nothing to install. This adds the two packages and, more to the point, somewhere for them to live that hands out updates - a package a user has to notice a new version of and download again is not much better than a checkout. Both are built from `make install` and nothing else. A packaging script that lists the installed files a second time is a second description of the layout, and the two drift the first time a file moves; here the Makefile stays the only place that says where anything goes. The .deb is staged and wrapped with dpkg-deb, the .rpm goes through a spec whose %install is the same make invocation. Both are architecture-independent, so one file each covers Debian, Ubuntu and their derivatives on one side and Fedora, RHEL and openSUSE on the other. The version is not written down twice either. The Makefile has it, the control file and the spec take it as a placeholder, and check-version.sh refuses a tag that disagrees - otherwise a v1.0.4 release quietly ships a program that reports 1.0.3. The release workflow builds both in a Debian and a Fedora container, signs the RPM where there is a native rpm-sign, attaches both to the GitHub release, and then adds them to an APT and a DNF repository on gh-pages, regenerating the indexes over every version ever published so that pinning and going back to one still work. Missing the signing key is not an error: it builds, it says in the log that the repositories were left alone, and the packages are still on the release. There is also a check workflow, which is the first time shellcheck actually runs on this. Neither package carries a maintainer script. The units are enabled per user by the program itself, so there is nothing for a package to do as root - and nothing it could do about the changes in a user's home either, which is why both descriptions say to run `disable` before removing. packaging/README.md has the two things that cannot be automated: making the signing key, and pointing Pages at the branch.
This commit is contained in:
1 parent
36498f2acf
commit
a053b4e555
15 files changed
+764
-4
No files matched your search
@@ -0,0 +1,28 @@
|
||||
name: check
|
||||
|
||||
on:
|
||||
push:
|
||||
branches: [main]
|
||||
pull_request:
|
||||
workflow_dispatch:
|
||||
|
||||
jobs:
|
||||
check:
|
||||
name: syntax and shellcheck
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: actions/checkout@v4
|
||||
|
||||
# The Makefile skips whatever is missing rather than failing, so the
|
||||
# tools it looks for have to be here or the check checks less than it
|
||||
# appears to.
|
||||
- name: Install the tools the Makefile looks for
|
||||
run: |
|
||||
sudo apt-get update -qq
|
||||
sudo apt-get install -y --no-install-recommends \
|
||||
shellcheck gettext scdoc
|
||||
|
||||
- run: make check
|
||||
|
||||
- name: Build the catalogs and the man page
|
||||
run: make build
|
||||
@@ -0,0 +1,156 @@
|
||||
name: release
|
||||
|
||||
on:
|
||||
push:
|
||||
tags: ['v*']
|
||||
workflow_dispatch:
|
||||
|
||||
permissions:
|
||||
contents: write
|
||||
|
||||
jobs:
|
||||
deb:
|
||||
name: Debian package
|
||||
runs-on: ubuntu-latest
|
||||
container: debian:stable
|
||||
steps:
|
||||
- name: Install the build tools
|
||||
run: |
|
||||
apt-get update -qq
|
||||
apt-get install -y --no-install-recommends \
|
||||
ca-certificates git make gettext scdoc dpkg-dev
|
||||
|
||||
- uses: actions/checkout@v4
|
||||
|
||||
- name: Check the tag against the Makefile
|
||||
run: packaging/check-version.sh "${{ github.ref_name }}"
|
||||
|
||||
- run: packaging/build-deb.sh
|
||||
|
||||
- name: Look inside what was built
|
||||
run: |
|
||||
dpkg-deb --info dist/*.deb
|
||||
dpkg-deb --contents dist/*.deb
|
||||
|
||||
- uses: actions/upload-artifact@v4
|
||||
with:
|
||||
name: deb
|
||||
path: dist/*.deb
|
||||
if-no-files-found: error
|
||||
|
||||
rpm:
|
||||
name: RPM package
|
||||
runs-on: ubuntu-latest
|
||||
container: fedora:latest
|
||||
steps:
|
||||
- name: Install the build tools
|
||||
run: |
|
||||
dnf install -y --setopt=install_weak_deps=False \
|
||||
git make gettext scdoc tar rpm-build rpm-sign systemd-rpm-macros
|
||||
|
||||
- uses: actions/checkout@v4
|
||||
|
||||
- name: Check the tag against the Makefile
|
||||
run: packaging/check-version.sh "${{ github.ref_name }}"
|
||||
|
||||
- run: packaging/build-rpm.sh
|
||||
|
||||
# Signed here rather than alongside the APT repository, because this is
|
||||
# the one place with a native rpm-sign.
|
||||
- name: Sign the package
|
||||
env:
|
||||
GPG_PRIVATE_KEY: ${{ secrets.GPG_PRIVATE_KEY }}
|
||||
run: |
|
||||
if [ -z "${GPG_PRIVATE_KEY:-}" ]; then
|
||||
echo "No GPG_PRIVATE_KEY secret; leaving the package unsigned."
|
||||
exit 0
|
||||
fi
|
||||
printf '%s' "$GPG_PRIVATE_KEY" | gpg --batch --import
|
||||
keyid="$(gpg --list-secret-keys --with-colons | awk -F: '/^sec:/ { print $5; exit }')"
|
||||
rpmsign --define "_gpg_name $keyid" --addsign dist/*.rpm
|
||||
rpm --checksig dist/*.rpm
|
||||
|
||||
- name: Look inside what was built
|
||||
run: |
|
||||
rpm -qip dist/*.rpm
|
||||
rpm -qlp dist/*.rpm
|
||||
|
||||
- uses: actions/upload-artifact@v4
|
||||
with:
|
||||
name: rpm
|
||||
path: dist/*.rpm
|
||||
if-no-files-found: error
|
||||
|
||||
publish:
|
||||
name: Release and repositories
|
||||
needs: [deb, rpm]
|
||||
if: startsWith(github.ref, 'refs/tags/v')
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: actions/checkout@v4
|
||||
|
||||
- uses: actions/download-artifact@v4
|
||||
with:
|
||||
path: incoming
|
||||
merge-multiple: true
|
||||
|
||||
- name: Attach the packages to the release
|
||||
env:
|
||||
GH_TOKEN: ${{ github.token }}
|
||||
run: |
|
||||
gh release create "${{ github.ref_name }}" \
|
||||
--title "${{ github.ref_name }}" \
|
||||
--generate-notes \
|
||||
incoming/* \
|
||||
|| gh release upload "${{ github.ref_name }}" incoming/* --clobber
|
||||
|
||||
- name: Install the repository tools
|
||||
run: |
|
||||
sudo apt-get update -qq
|
||||
sudo apt-get install -y --no-install-recommends \
|
||||
dpkg-dev apt-utils createrepo-c
|
||||
|
||||
- name: Import the signing key
|
||||
id: key
|
||||
env:
|
||||
GPG_PRIVATE_KEY: ${{ secrets.GPG_PRIVATE_KEY }}
|
||||
run: |
|
||||
if [ -z "${GPG_PRIVATE_KEY:-}" ]; then
|
||||
echo "present=no" >> "$GITHUB_OUTPUT"
|
||||
echo "::warning::No GPG_PRIVATE_KEY secret - the apt and dnf repositories were not updated. The packages are on the release."
|
||||
exit 0
|
||||
fi
|
||||
printf '%s' "$GPG_PRIVATE_KEY" | gpg --batch --import
|
||||
echo "present=yes" >> "$GITHUB_OUTPUT"
|
||||
|
||||
- name: Check out the published repositories
|
||||
if: steps.key.outputs.present == 'yes'
|
||||
uses: actions/checkout@v4
|
||||
with:
|
||||
ref: gh-pages
|
||||
path: pages
|
||||
continue-on-error: true
|
||||
|
||||
- name: Update the repositories
|
||||
if: steps.key.outputs.present == 'yes'
|
||||
run: |
|
||||
# First release: the branch does not exist yet.
|
||||
if [ ! -d pages/.git ]; then
|
||||
rm -rf pages && mkdir pages
|
||||
git -C pages init -q -b gh-pages
|
||||
git -C pages remote add origin "https://github.com/${{ github.repository }}.git"
|
||||
fi
|
||||
packaging/publish-repos.sh pages incoming
|
||||
|
||||
- name: Push them
|
||||
if: steps.key.outputs.present == 'yes'
|
||||
env:
|
||||
GH_TOKEN: ${{ github.token }}
|
||||
run: |
|
||||
cd pages
|
||||
git config user.name "github-actions[bot]"
|
||||
git config user.email "41898282+github-actions[bot]@users.noreply.github.com"
|
||||
git add -A
|
||||
git diff --quiet --cached && { echo "nothing changed"; exit 0; }
|
||||
git commit -q -m "Publish ${{ github.ref_name }}"
|
||||
git push "https://x-access-token:${GH_TOKEN}@github.com/${{ github.repository }}.git" HEAD:gh-pages
|
||||
Reference in new issue
Block a user