Files
Fenris-xbps/README.md
T
Xavier KarmaandCommandCodeBot 0376e7e204 Update README with publication mechanism and proof results
- Document automated publication via scripts/xbps-publish.sh
- Add cache behavior note (6-hour max-age, use -S flag)
- Reference proof results document
- Document signing key handling

Co-authored-by: CommandCodeBot <noreply@commandcode.ai>
2026-09-14 22:36:58 +05:30

87 lines
2.2 KiB
Markdown

# Fenris-xbps
XBPS distribution repository for Fenris.
## Repository Structure
```
stable/
x86_64/
fenris-<version>_1.x86_64.xbps # Package archives
fenris-<version>_1.x86_64.xbps.sig2 # Package signatures
x86_64-repodata # Repository index (zstd-compressed tar)
x86_64-repodata.sig2 # Repository metadata signature
keys/
fenris-xbps-signing.pub # Public signing key
```
## Usage
### Adding the repository
```sh
sudo xbps-install -S https://git.bongbetic.com/xavierk/Fenris-xbps/raw/branch/stable/x86_64
```
Or manually add to `/etc/xbps.d/xbps.conf`:
```
repository=https://git.bongbetic.com/xavierk/Fenris-xbps/raw/branch/stable/x86_64
```
### Installing Fenris
```sh
sudo xbps-install -S fenris
```
### Updating Fenris
```sh
sudo xbps-install -Syu fenris
```
**Note**: Always use `-S` to force a fresh repository fetch. The Gitea raw endpoint
advertises a 6-hour cache (`max-age=21600`). The `-S` flag ensures immediate
discovery of newly published versions.
## Signing
Packages and repository metadata are signed with SSH RSA keys via `xbps-rindex`.
The public key is embedded in the repository metadata and also available at
`keys/fenris-xbps-signing.pub`.
First-time installation prompts for key import:
```
Do you want to import this public key? [Y/n]
```
## Publication Mechanism
Automated via `scripts/xbps-publish.sh` from the Fenris repository:
```sh
# Dry-run (print commands)
scripts/xbps-publish.sh --dry-run
# Execute publication
scripts/xbps-publish.sh --publish
```
Or manually:
1. Build: `make package-xbps`
2. Sign: `make sign-xbps`
3. Add to index: `xbps-rindex --add <repo-dir>/<package>.xbps`
4. Sign repository: `xbps-rindex --sign --privkey <key> --signedby "Fenris Packaging <packaging@bongbetic.com>" <repo-dir>`
5. Commit and push to `stable` branch
Raw URLs serve artifacts immediately without LFS indirection.
Index and new packages are committed together. Older artifacts are retained
for clients with cached older indexes.
## Proof of Concept Results
See [docs/spec/xbps-proof-results.md](https://git.bongbetic.com/xavierk/Fenris/src/branch/main/docs/spec/xbps-proof-results.md)
for complete acceptance criteria results from issue #83.