feat(packaging): nfpm-based deb + rpm build infrastructure (spec §3-7, ADR 0007)

Implement the packaging configuration, staging script, maintainer scripts,
and container test harness for building native deb and rpm packages.

Core files:
- packaging/nfpm.yaml: single source of truth for both formats
- packaging/stage.sh: builds staged tree (venv, wrapper, helpers, units, polkit, sysusers, tmpfiles)
- packaging/fenris.conf: placeholder-commented default configuration
- packaging/postinst.sh, prerm.sh, postrm.sh: POSIX-compatible deb maintainer scripts
- packaging/rpm/post.sh, preun.sh, postun.sh: RPM scriptlets
- packaging/sysusers.d/fenris.conf, tmpfiles.d/fenris.conf: systemd fragments
- packaging/fenris.repo: dnf consumer setup
- packaging/keys/fenris-packaging.asc: public key placeholder

Build targets added to Makefile: stage, package-deb, package-rpm, package, release, clean.
Container test harness in tests/test_packaging.py covering dormant install,
migration guard, upgrade semantics, and removal semantics across the
compatibility matrix (Debian 12, Ubuntu 22.04/24.04, Fedora 40).
Dormant CI workflow at .gitea/workflows/release.yml.

All 289 existing tests pass without regression.

Co-authored-by: CommandCodeBot <noreply@commandcode.ai>
This commit is contained in:
xavierk
2026-09-03 02:36:08 +05:30
co-authored by CommandCodeBot
parent b005049733
commit babc8eeeb1
18 changed files with 1050 additions and 1 deletions
+48
View File
@@ -0,0 +1,48 @@
#!/bin/sh
# RPM %post — post-install/upgrade scriptlet (spec §7).
#
# Fresh install: sysusers, tmpfiles, daemon-reload — nothing else (dormant).
# Upgrade: snapshot, migration, daemon-reload, conditional timer restart.
set -eu
STORE_DIR="/var/lib/fenris"
STORE_DB="${STORE_DIR}/observations.db"
STORE_BAK="${STORE_DIR}/observations.db.bak"
VENV_PYTHON="/opt/fenris/bin/python3"
if [ "$1" -eq 1 ]; then
# Fresh install
systemd-sysusers || true
systemd-tmpfiles --create || true
systemctl daemon-reload || true
elif [ "$1" -ge 2 ]; then
# Upgrade
if [ -f "${STORE_DB}" ]; then
cp "${STORE_DB}" "${STORE_BAK}" 2>/dev/null || true
fi
if [ -x "${VENV_PYTHON}" ] && [ -f "${STORE_DB}" ]; then
"${VENV_PYTHON}" -c "
from fenris.store import migrate_to_latest
from pathlib import Path
n = migrate_to_latest(Path('${STORE_DB}'))
print(f'Fenris migration: {n} step(s) applied') if n else None
" 2>&1 || echo "Fenris: migration skipped (store not yet initialized)"
fi
systemd-sysusers || true
systemd-tmpfiles --create || true
systemctl daemon-reload || true
for unit in fenris-collect.timer fenris-collect.service; do
if systemctl is-active --quiet "${unit}" 2>/dev/null; then
TMPFILE="$(mktemp)"
systemctl cat "${unit}" > "${TMPFILE}" 2>/dev/null || true
UNIT_PATH="/usr/lib/systemd/system/${unit}"
if ! diff -q "${TMPFILE}" "${UNIT_PATH}" > /dev/null 2>&1; then
systemctl restart "${unit}" 2>/dev/null || true
fi
rm -f "${TMPFILE}"
fi
done
fi
+20
View File
@@ -0,0 +1,20 @@
#!/bin/sh
# RPM %postun — post-uninstall scriptlet (spec §7).
#
# On erase ($1 -eq 0): remove config (unmodified removed, modified as .rpmsave),
# store, backups, and group.
# On upgrade ($1 -ge 1): daemon-reload only.
set -eu
if [ "$1" -eq 0 ]; then
# Package fully erased
rm -rf /etc/fenris
rm -rf /var/lib/fenris
# Remove the fenris group if it exists
if getent group fenris > /dev/null 2>&1; then
groupdel fenris 2>/dev/null || true
fi
fi
# Always daemon-reload (units may have been removed)
systemctl daemon-reload 2>/dev/null || true
+16
View File
@@ -0,0 +1,16 @@
#!/bin/sh
# RPM %preun — pre-uninstall scriptlet (spec §7).
#
# On erase ($1 -eq 0): sanctioned disable — close monitoring period.
# On upgrade ($1 -ge 1): no-op — never interrupt monitoring.
set -eu
if [ "$1" -eq 0 ]; then
# Package is being erased (fully removed), not just upgraded
if [ -x /usr/libexec/fenris/fenris-monitor ]; then
/usr/libexec/fenris/fenris-monitor disable --now 2>/dev/null || true
fi
systemctl stop fenris-collect.timer 2>/dev/null || true
systemctl disable fenris-collect.timer 2>/dev/null || true
fi
# On upgrade ($1 -ge 1): do nothing — monitoring continues uninterrupted