feat(packaging): nfpm-based deb + rpm build infrastructure (spec §3-7, ADR 0007)

Implement the packaging configuration, staging script, maintainer scripts,
and container test harness for building native deb and rpm packages.

Core files:
- packaging/nfpm.yaml: single source of truth for both formats
- packaging/stage.sh: builds staged tree (venv, wrapper, helpers, units, polkit, sysusers, tmpfiles)
- packaging/fenris.conf: placeholder-commented default configuration
- packaging/postinst.sh, prerm.sh, postrm.sh: POSIX-compatible deb maintainer scripts
- packaging/rpm/post.sh, preun.sh, postun.sh: RPM scriptlets
- packaging/sysusers.d/fenris.conf, tmpfiles.d/fenris.conf: systemd fragments
- packaging/fenris.repo: dnf consumer setup
- packaging/keys/fenris-packaging.asc: public key placeholder

Build targets added to Makefile: stage, package-deb, package-rpm, package, release, clean.
Container test harness in tests/test_packaging.py covering dormant install,
migration guard, upgrade semantics, and removal semantics across the
compatibility matrix (Debian 12, Ubuntu 22.04/24.04, Fedora 40).
Dormant CI workflow at .gitea/workflows/release.yml.

All 289 existing tests pass without regression.

Co-authored-by: CommandCodeBot <noreply@commandcode.ai>
This commit is contained in:
xavierk
2026-09-03 02:36:08 +05:30
co-authored by CommandCodeBot
parent b005049733
commit babc8eeeb1
18 changed files with 1050 additions and 1 deletions
+86
View File
@@ -0,0 +1,86 @@
#!/usr/bin/env bash
# Stage a packaging tree at build/stage/ for nfpm consumption.
#
# Usage: packaging/stage.sh [VERSION]
#
# VERSION defaults to the version in pyproject.toml.
# The staged tree contains:
# /opt/fenris/ — bundled venv with the built wheel
# /usr/bin/fenris — unprivileged wrapper
# /usr/libexec/fenris/ — fenris-monitor, fenris-collect
# /usr/lib/systemd/system/ — fenris-collect.{timer,service}
# /usr/share/polkit-1/actions/ — polkit policy
# /usr/lib/sysusers.d/fenris.conf
# /usr/lib/tmpfiles.d/fenris.conf
set -euo pipefail
REPO_ROOT="$(cd "$(dirname "$0")/.." && pwd)"
STAGE_DIR="${REPO_ROOT}/build/stage"
# --- Resolve version ---
if [ -n "${1:-}" ]; then
VERSION="$1"
else
VERSION="$(sed -n 's/^version = "\(.*\)"/\1/p' "${REPO_ROOT}/pyproject.toml")"
fi
if [ -z "${VERSION}" ]; then
echo "Error: could not determine version" >&2
exit 1
fi
echo "Staging fenris ${VERSION} ..."
# --- Clean previous stage ---
rm -rf "${STAGE_DIR}"
mkdir -p "${STAGE_DIR}"
# --- Use pre-built wheel from dist/ ---
WHEEL=$(ls "${REPO_ROOT}"/dist/fenris-*.whl 2>/dev/null | head -1)
if [ -z "${WHEEL}" ]; then
echo "Error: no wheel found in dist/ — run 'make dist/fenris-*.whl' first" >&2
exit 1
fi
echo " Using wheel: $(basename "${WHEEL}")"
# --- Create venv with --copies and install wheel ---
echo " Creating bundled venv ..."
python3 -m venv --copies "${STAGE_DIR}/opt/fenris"
"${STAGE_DIR}/opt/fenris/bin/pip" install --upgrade pip --quiet 2>&1 | tail -1
"${STAGE_DIR}/opt/fenris/bin/pip" install "${WHEEL}" --quiet 2>&1 | tail -1
# --- Inject version into wrapper from pyproject.toml ---
# The wrapper has a hardcoded version string; patch it for packaging.
WRAPPER_SRC="${REPO_ROOT}/scripts/fenris"
WRAPPER_DST="${STAGE_DIR}/usr/bin/fenris"
mkdir -p "$(dirname "${WRAPPER_DST}")"
sed "s|version=\"%(prog)s [0-9.]*\"|version=\"%(prog)s ${VERSION}\"|g" \
"${WRAPPER_SRC}" > "${WRAPPER_DST}"
chmod 0755 "${WRAPPER_DST}"
# --- Privileged helpers ---
echo " Installing helpers ..."
mkdir -p "${STAGE_DIR}/usr/libexec/fenris"
install -m 0755 "${REPO_ROOT}/src/fenris/monitor.py" "${STAGE_DIR}/usr/libexec/fenris/fenris-monitor"
install -m 0755 "${REPO_ROOT}/src/fenris/collect.py" "${STAGE_DIR}/usr/libexec/fenris/fenris-collect"
# --- systemd units (vendor placement) ---
echo " Installing systemd units ..."
mkdir -p "${STAGE_DIR}/usr/lib/systemd/system"
install -m 0644 "${REPO_ROOT}/units/fenris-collect.timer" "${STAGE_DIR}/usr/lib/systemd/system/"
install -m 0644 "${REPO_ROOT}/units/fenris-collect.service" "${STAGE_DIR}/usr/lib/systemd/system/"
# --- polkit policy ---
echo " Installing polkit policy ..."
mkdir -p "${STAGE_DIR}/usr/share/polkit-1/actions"
install -m 0644 "${REPO_ROOT}/polkit/com.bongbetic.fenris.monitor.policy" \
"${STAGE_DIR}/usr/share/polkit-1/actions/"
# --- sysusers and tmpfiles fragments ---
echo " Installing sysusers/tmpfiles fragments ..."
mkdir -p "${STAGE_DIR}/usr/lib/sysusers.d"
install -m 0644 "${REPO_ROOT}/packaging/sysusers.d/fenris.conf" "${STAGE_DIR}/usr/lib/sysusers.d/"
mkdir -p "${STAGE_DIR}/usr/lib/tmpfiles.d"
install -m 0644 "${REPO_ROOT}/packaging/tmpfiles.d/fenris.conf" "${STAGE_DIR}/usr/lib/tmpfiles.d/"
echo "Stage complete: ${STAGE_DIR}"