feat(packaging): nfpm-based deb + rpm build infrastructure (spec §3-7, ADR 0007)

Implement the packaging configuration, staging script, maintainer scripts,
and container test harness for building native deb and rpm packages.

Core files:
- packaging/nfpm.yaml: single source of truth for both formats
- packaging/stage.sh: builds staged tree (venv, wrapper, helpers, units, polkit, sysusers, tmpfiles)
- packaging/fenris.conf: placeholder-commented default configuration
- packaging/postinst.sh, prerm.sh, postrm.sh: POSIX-compatible deb maintainer scripts
- packaging/rpm/post.sh, preun.sh, postun.sh: RPM scriptlets
- packaging/sysusers.d/fenris.conf, tmpfiles.d/fenris.conf: systemd fragments
- packaging/fenris.repo: dnf consumer setup
- packaging/keys/fenris-packaging.asc: public key placeholder

Build targets added to Makefile: stage, package-deb, package-rpm, package, release, clean.
Container test harness in tests/test_packaging.py covering dormant install,
migration guard, upgrade semantics, and removal semantics across the
compatibility matrix (Debian 12, Ubuntu 22.04/24.04, Fedora 40).
Dormant CI workflow at .gitea/workflows/release.yml.

All 289 existing tests pass without regression.

Co-authored-by: CommandCodeBot <noreply@commandcode.ai>
This commit is contained in:
xavierk
2026-09-03 02:36:08 +05:30
co-authored by CommandCodeBot
parent b005049733
commit babc8eeeb1
18 changed files with 1050 additions and 1 deletions
+23
View File
@@ -0,0 +1,23 @@
#!/bin/sh
# postrm — deb post-removal (spec §7, §9).
#
# dpkg calls: postrm remove (after package files removed)
# postrm purge (after conffiles and config removed)
# postrm upgrade (after new version installed)
set -eu
case "${1:-}" in
purge)
rm -rf /etc/fenris
rm -rf /var/lib/fenris
# Remove the fenris group if it exists
if getent group fenris > /dev/null 2>&1; then
groupdel fenris 2>/dev/null || true
fi
;;
remove|upgrade|failed-upgrade|abort-install|abort-upgrade|disappear)
;;
esac
# Always daemon-reload after removal (units may be gone)
systemctl daemon-reload 2>/dev/null || true