Fix Void package acceptance gaps

This commit is contained in:
xavierk
2026-09-15 19:43:00 +05:30
parent 95c75badd5
commit a3e6cc3b3c
10 changed files with 114 additions and 38 deletions
+12 -5
View File
@@ -68,10 +68,9 @@ TLS).
### Void Linux (XBPS)
Void x86_64 with glibc and runit is the native target. Its XBPS channel is
withheld until the host-acceptance gate passes; do not install proof artifacts
from it. Once a Fenris Release lists XBPS as available, add the permanent
signed repository, refresh its metadata, and install the package:
Void x86_64 with glibc and runit is the native target. Its signed XBPS channel
is available from the permanent repository below. Add it, refresh its
metadata, and install the released package:
```bash
sudo install -d -m 0755 /etc/xbps.d
@@ -83,7 +82,7 @@ sudo xbps-install -S fenris
XBPS requires remote repositories to be signed. On the first refresh it
displays the repository signing key embedded in the signed metadata; accept it
only when its RSA SHA256 fingerprint is
`SHA256:kC1+z5Z9OtW5qcoXcV7sxr7m1wEvxbTUgRxd9Yib/Qk`. The public key is also
`SHA256:AvPMRlKMikPg75u0iKr8AUkxlfU/Ad4k/S4o2M9W4/w`. The public key is also
available at
`https://git.bongbetic.com/xavierk/Fenris-xbps/raw/branch/stable/keys/fenris-xbps-signing.pub`.
For later updates, always refresh first so XBPS fetches the current index:
@@ -96,6 +95,14 @@ The runit service remains dormant after installation. `fenris monitor resume`
creates `/var/service/fenris-collect`; pause removes that link and records a
deliberate disable in the observation history.
Fenris keeps the observation store root-written and readable by the `fenris`
group. Add each TUI user to that group, then start a new login session before
running Fenris:
```bash
sudo usermod -aG fenris "$USER"
```
### Package signature verification
The RPM payload is signed with the Fenris packaging key (RSA 3072).