Implement XBPS proof of concept (issue #83)

Prove signed XBPS installation and immediate updates through Gitea.

Changes:
- Add scripts/xbps-publish.sh for automated XBPS publication
- Add Makefile targets: package-xbps, sign-xbps, xbps-publish
- Add docs/spec/xbps-proof-results.md with acceptance criteria results
- Add docs/adr/0008-native-void-support.md (architecture decision)
- Add docs/spec/native-void-support.md (feature specification)
- Add docs/spec/native-void-tickets.md (implementation tickets)

Proof results:
- Raw URL delivery verified (no LFS indirection)
- Signing key handling established (SSH RSA via xbps-rindex)
- Install and update flow demonstrated (v0.3.5 → v0.3.6)
- Cache behavior documented (6-hour max-age, -S flag for immediate discovery)
- Publication mechanism documented and automated
- Failure recovery demonstrated (git revert)

Repository: https://git.bongbetic.com/xavierk/Fenris-xbps

Co-authored-by: CommandCodeBot <noreply@commandcode.ai>
This commit is contained in:
xavierk
2026-09-14 22:37:49 +05:30
co-authored by CommandCodeBot
parent ed61c4e1ec
commit 985efed906
6 changed files with 515 additions and 1 deletions
+34 -1
View File
@@ -18,7 +18,7 @@ MANIFEST := $(DATA_DIR)/manifest.txt
# Legacy history path (IN-4)
LEGACY_HISTORY := ./data/history.jsonl
.PHONY: help install upgrade uninstall purge update-deps test lint check-python check-smartctl import-legacy stage package-deb package-rpm package generate-test-key sign-rpm checksums clearsign release release-run release-dry-run clean
.PHONY: help install upgrade uninstall purge update-deps test lint check-python check-smartctl import-legacy stage package-deb package-rpm package-xbps package generate-test-key sign-rpm sign-xbps checksums clearsign release release-run release-dry-run xbps-publish xbps-publish-dry-run clean
help:
@echo "Fenris NVMe endurance monitor"
@@ -35,6 +35,8 @@ help:
@echo " package - Build deb + rpm packages"
@echo " package-deb - Build deb package only"
@echo " package-rpm - Build rpm package only"
@echo " package-xbps - Build XBPS package only"
@echo " sign-xbps - Sign XBPS package with signing key"
@echo " generate-test-key - Create throwaway GPG key for CI/testing"
@echo " sign-rpm - Sign RPM payload with packaging key"
@echo " checksums - Generate SHA256SUMS manifest"
@@ -42,6 +44,8 @@ help:
@echo " release - Full release (build, sign, checksum, print upload steps)"
@echo " release-run - Execute the full release flow via scripts/release.sh"
@echo " release-dry-run - Dry-run of the release flow (prints commands only)"
@echo " xbps-publish - Publish XBPS package to distribution repository"
@echo " xbps-publish-dry-run - Dry-run of XBPS publication (prints commands only)"
@echo " clean - Remove build artifacts"
# ─── Pre-install gates ──────────────────────────────────────────────────────
@@ -257,6 +261,35 @@ package-rpm: stage
package: package-deb package-rpm
@echo "=== Both packages built in dist/ ==="
# ─── XBPS packaging (ADR 0008) ─────────────────────────────────────────────
XBPS_SIGNING_KEY ?= $(HOME)/.ssh/id_rsa
XBPS_SIGNED_BY ?= Fenris Packaging <packaging@bongbetic.com>
package-xbps: stage
@echo "=== Building XBPS package ==="
xbps-create -A x86_64 \
-n fenris-$(FENRIS_VERSION)_1 \
-s "Fenris NVMe wear monitor" \
-S "NVMe wear monitor with persistent TUI" \
-m "Fenris Packaging <packaging@bongbetic.com>" \
-H "https://git.bongbetic.com/xavierk/Fenris" \
-l "MIT" \
build/stage
@echo "=== XBPS package built: fenris-$(FENRIS_VERSION)_1.x86_64.xbps ==="
sign-xbps: package-xbps
@echo "=== Signing XBPS package ==="
xbps-rindex --sign-pkg --privkey $(XBPS_SIGNING_KEY) \
fenris-$(FENRIS_VERSION)_1.x86_64.xbps
@echo "=== XBPS package signed ==="
xbps-publish:
bash scripts/xbps-publish.sh --publish
xbps-publish-dry-run:
bash scripts/xbps-publish.sh --dry-run
# ─── GPG key management ─────────────────────────────────────────────────────
generate-test-key: