fix(packaging): address review findings for #44

- nfpm.yaml: type:config → config_noreplace (RPM noreplace semantics)
- nfpm.yaml: type:ghost → type:dir for /var/lib/fenris (deb compatibility)
- postinst.sh/rpm/post.sh: fix timer restart — capture running unit before
  daemon-reload so the diff actually detects changes
- README: fix Python floor to ≥3.10 (was ≥3.9, inconsistent with Makefile)
- signing-key-ceremony.md: fix stale claim about nfpm signing RPMs
  (actual path is post-build rpmsign)
- tests/conftest.py: extract shared _get_version() and _read() helpers
- tests: wire up to shared conftest helpers
- release.yml: extract VERSION once via GITHUB_OUTPUT step

Co-authored-by: CommandCodeBot <noreply@commandcode.ai>
This commit is contained in:
xavierk
2026-09-03 15:25:35 +05:30
co-authored by CommandCodeBot
parent 120d80b28c
commit 1e2ddfb928
10 changed files with 72 additions and 40 deletions
+2 -2
View File
@@ -79,8 +79,8 @@ make release # builds, signs RPM, clearsigns SHA256SUMS, prints upload steps
Under the hood:
1. `nfpm pkg -p rpm` signs the RPM payload via `rpm.signature.key_file` and
`rpm.signature.key_id` in `packaging/nfpm.yaml`.
1. `rpmsign --addsign` signs the RPM payload with the packaging key
(invoked by `make sign-rpm`).
2. `sha256sum` generates the checksum manifest.
3. `gpg --clearsign` produces `SHA256SUMS.asc` with the packaging key.