Update README with publication mechanism and proof results

- Document automated publication via scripts/xbps-publish.sh
- Add cache behavior note (6-hour max-age, use -S flag)
- Reference proof results document
- Document signing key handling

Co-authored-by: CommandCodeBot <noreply@commandcode.ai>
This commit is contained in:
Xavier Karma
2026-09-14 22:36:58 +05:30
co-authored by CommandCodeBot
parent 6fc696f846
commit 0376e7e204
+38 -10
View File
@@ -7,10 +7,10 @@ XBPS distribution repository for Fenris.
``` ```
stable/ stable/
x86_64/ x86_64/
fenris-<version>_1.x86_64.xbps # Package files fenris-<version>_1.x86_64.xbps # Package archives
fenris-<version>_1.x86_64.xbps.sig2 # Package signatures fenris-<version>_1.x86_64.xbps.sig2 # Package signatures
x86_64-repodata # Repository index x86_64-repodata # Repository index (zstd-compressed tar)
x86_64-repodata.sig2 # Repository index signature x86_64-repodata.sig2 # Repository metadata signature
keys/ keys/
fenris-xbps-signing.pub # Public signing key fenris-xbps-signing.pub # Public signing key
``` ```
@@ -20,7 +20,6 @@ stable/
### Adding the repository ### Adding the repository
```sh ```sh
# Import the signing key
sudo xbps-install -S https://git.bongbetic.com/xavierk/Fenris-xbps/raw/branch/stable/x86_64 sudo xbps-install -S https://git.bongbetic.com/xavierk/Fenris-xbps/raw/branch/stable/x86_64
``` ```
@@ -39,20 +38,49 @@ sudo xbps-install -S fenris
### Updating Fenris ### Updating Fenris
```sh ```sh
sudo xbps-install -Su fenris sudo xbps-install -Syu fenris
``` ```
**Note**: Always use `-S` to force a fresh repository fetch. The Gitea raw endpoint
advertises a 6-hour cache (`max-age=21600`). The `-S` flag ensures immediate
discovery of newly published versions.
## Signing ## Signing
Packages and repository metadata are signed with the Fenris XBPS signing key. Packages and repository metadata are signed with SSH RSA keys via `xbps-rindex`.
The public key is available at `keys/fenris-xbps-signing.pub`. The public key is embedded in the repository metadata and also available at
`keys/fenris-xbps-signing.pub`.
First-time installation prompts for key import:
```
Do you want to import this public key? [Y/n]
```
## Publication Mechanism ## Publication Mechanism
1. Build the XBPS package using `xbps-create` Automated via `scripts/xbps-publish.sh` from the Fenris repository:
2. Sign the package: `xbps-rindex --sign-pkg --privkey <key> <package>.xbps`
```sh
# Dry-run (print commands)
scripts/xbps-publish.sh --dry-run
# Execute publication
scripts/xbps-publish.sh --publish
```
Or manually:
1. Build: `make package-xbps`
2. Sign: `make sign-xbps`
3. Add to index: `xbps-rindex --add <repo-dir>/<package>.xbps` 3. Add to index: `xbps-rindex --add <repo-dir>/<package>.xbps`
4. Sign the repository: `xbps-rindex --sign --privkey <key> --signedby "Fenris Packaging <packaging@bongbetic.com>" <repo-dir>` 4. Sign repository: `xbps-rindex --sign --privkey <key> --signedby "Fenris Packaging <packaging@bongbetic.com>" <repo-dir>`
5. Commit and push to `stable` branch 5. Commit and push to `stable` branch
Raw URLs serve artifacts immediately without LFS indirection. Raw URLs serve artifacts immediately without LFS indirection.
Index and new packages are committed together. Older artifacts are retained
for clients with cached older indexes.
## Proof of Concept Results
See [docs/spec/xbps-proof-results.md](https://git.bongbetic.com/xavierk/Fenris/src/branch/main/docs/spec/xbps-proof-results.md)
for complete acceptance criteria results from issue #83.