Prepare XBPS repository publication

This commit is contained in:
xavierk
2026-09-15 16:43:41 +05:30
parent 967ba6964f
commit dea2186d6b
3 changed files with 76 additions and 16 deletions
+6 -4
View File
@@ -277,28 +277,30 @@ package: package-deb package-rpm
# XBPS signing key (separate from SSH authentication key) # XBPS signing key (separate from SSH authentication key)
XBPS_SIGNING_KEY ?= $(HOME)/.ssh/id_xbps XBPS_SIGNING_KEY ?= $(HOME)/.ssh/id_xbps
XBPS_REVISION ?= 1
package-xbps: stage package-xbps: stage
@echo "=== Building XBPS package ===" @echo "=== Building XBPS package ==="
cp packaging/xbps/install.sh build/stage/INSTALL cp packaging/xbps/install.sh build/stage/INSTALL
cp packaging/xbps/remove.sh build/stage/REMOVE cp packaging/xbps/remove.sh build/stage/REMOVE
install -D -m 0644 packaging/fenris.conf build/stage/etc/fenris/fenris.conf
chmod 755 build/stage/INSTALL build/stage/REMOVE chmod 755 build/stage/INSTALL build/stage/REMOVE
xbps-create -A x86_64 \ xbps-create -A x86_64 \
-n fenris-$(FENRIS_VERSION)_1 \ -n fenris-$(FENRIS_VERSION)_$(XBPS_REVISION) \
-s "Fenris NVMe wear monitor" \ -s "Fenris NVMe wear monitor" \
-S "NVMe wear monitor with persistent TUI" \ -S "NVMe wear monitor with persistent TUI" \
-m "Fenris Packaging <packaging@bongbetic.com>" \ -m "Fenris Packaging <packaging@bongbetic.com>" \
-H "https://git.bongbetic.com/xavierk/Fenris" \ -H "https://git.bongbetic.com/xavierk/Fenris" \
-l "MIT" \ -l "MIT" \
-D "python3>=3.10 smartmontools" \ -D "python3>=3.10 smartmontools>=0" \
-F "/etc/fenris/fenris.conf" \ -F "/etc/fenris/fenris.conf" \
build/stage build/stage
@echo "=== XBPS package built: fenris-$(FENRIS_VERSION)_1.x86_64.xbps ===" @echo "=== XBPS package built: fenris-$(FENRIS_VERSION)_$(XBPS_REVISION).x86_64.xbps ==="
sign-xbps: package-xbps sign-xbps: package-xbps
@echo "=== Signing XBPS package ===" @echo "=== Signing XBPS package ==="
xbps-rindex --sign-pkg --privkey $(XBPS_SIGNING_KEY) \ xbps-rindex --sign-pkg --privkey $(XBPS_SIGNING_KEY) \
fenris-$(FENRIS_VERSION)_1.x86_64.xbps fenris-$(FENRIS_VERSION)_$(XBPS_REVISION).x86_64.xbps
@echo "=== XBPS package signed ===" @echo "=== XBPS package signed ==="
xbps-publish: xbps-publish:
+67 -8
View File
@@ -2,7 +2,7 @@
*Observes an NVMe drive's real-world use and translates that history into an understandable endurance outlook.* *Observes an NVMe drive's real-world use and translates that history into an understandable endurance outlook.*
Fenris is a persistent TUI monitor backed by a short-lived privileged collector on a systemd timer. It reads SMART data every few minutes, stores compact observation history in SQLite, and recomputes a usage-adjusted theoretical lifespan on every screen render — no fairy dust, just your actual bytes. Fenris is a persistent TUI monitor backed by a short-lived privileged collector on the host's native scheduler. It reads SMART data every few minutes, stores compact observation history in SQLite, and recomputes a usage-adjusted theoretical lifespan on every screen render — no fairy dust, just your actual bytes.
--- ---
@@ -10,7 +10,7 @@ Fenris is a persistent TUI monitor backed by a short-lived privileged collector
- **Python ≥ 3.10** (verified at install time) - **Python ≥ 3.10** (verified at install time)
- **smartmontools** (`smartctl` — verified at install time) - **smartmontools** (`smartctl` — verified at install time)
- **systemd** with a polkit agent (the collector runs as root oneshot; elevation is exclusively polkit) - **systemd** or **runit**, with a polkit agent (the collector runs as root; elevation is exclusively polkit)
No other OS packages or Python dependencies beyond [Textual](https://textual.textualize.io/) (pinned in the lockfile). No other OS packages or Python dependencies beyond [Textual](https://textual.textualize.io/) (pinned in the lockfile).
@@ -66,6 +66,44 @@ The repo file sets `gpgcheck=1` against the Fenris packaging key (downloaded
from the raw URL in `gpgkey`) and `repo_gpgcheck=0` (metadata check left to from the raw URL in `gpgkey`) and `repo_gpgcheck=0` (metadata check left to
TLS). TLS).
### Void Linux (XBPS)
Void x86_64 with glibc and runit is the native target. Its XBPS channel is
withheld until the host-acceptance gate passes; do not install proof artifacts
from it. Once a Fenris Release lists XBPS as available, add the permanent
signed repository, refresh its metadata, and install the package:
```bash
sudo install -d -m 0755 /etc/xbps.d
echo 'repository=https://git.bongbetic.com/xavierk/Fenris-xbps/raw/branch/stable/x86_64' \
| sudo tee /etc/xbps.d/fenris.conf
sudo xbps-install -S fenris
```
XBPS requires remote repositories to be signed. On the first refresh it
displays the repository signing key embedded in the signed metadata; accept it
only when its RSA SHA256 fingerprint is
`SHA256:AvPMRlKMikPg75u0iKr8AUkxlfU/Ad4k/S4o2M9W4/w`. The public key is also
available at
`https://git.bongbetic.com/xavierk/Fenris-xbps/raw/branch/stable/keys/fenris-xbps-signing.pub`.
For later updates, always refresh first so XBPS fetches the current index:
```bash
sudo xbps-install -Syu
```
The runit service remains dormant after installation. `fenris monitor resume`
creates `/var/service/fenris-collect`; pause removes that link and records a
deliberate disable in the observation history.
Fenris keeps the observation store root-written and readable by the `fenris`
group. Add each TUI user to that group, then start a new login session before
running Fenris:
```bash
sudo usermod -aG fenris "$USER"
```
### Package signature verification ### Package signature verification
The RPM payload is signed with the Fenris packaging key (RSA 3072). The RPM payload is signed with the Fenris packaging key (RSA 3072).
@@ -84,12 +122,12 @@ The packaging public key is published in-repo — no keyservers. See
### Dormant install ### Dormant install
A fresh package install is fully dormant. Units are present but disabled; A fresh package install is fully dormant. Its native scheduler is present but
nothing runs. The only opt-in is the sanctioned toggle: disabled; nothing runs. The only opt-in is the sanctioned toggle:
```bash ```bash
fenris monitor resume # enable timer + open first monitoring period fenris monitor resume # enable scheduling + open first monitoring period
fenris monitor pause # close the period, disable timer fenris monitor pause # close the period, disable scheduling
``` ```
## Development install (make install) ## Development install (make install)
@@ -117,6 +155,7 @@ make purge # also removes /etc/fenris and /var/lib/fenris
```bash ```bash
sudo apt update && sudo apt upgrade fenris # Debian/Ubuntu sudo apt update && sudo apt upgrade fenris # Debian/Ubuntu
sudo dnf upgrade fenris # Fedora sudo dnf upgrade fenris # Fedora
sudo xbps-install -Syu # Void Linux
``` ```
### Development upgrade ### Development upgrade
@@ -133,6 +172,12 @@ What it does:
5. Applies forward-only schema migrations (the store directory is never rebuilt; automatic downgrade does not exist). 5. Applies forward-only schema migrations (the store directory is never rebuilt; automatic downgrade does not exist).
Rollback: reinstall the previous version and restore `observations.db.bak`. Rollback: reinstall the previous version and restore `observations.db.bak`.
On Void, pause monitoring first, copy the compatible snapshot back to
`/var/lib/fenris/observations.db`, then force-install the matching older
package version. If that version is no longer indexed, add its retained XBPS
archive to a local repository with `xbps-rindex -a` and use
`xbps-install -R <local-repository> -f fenris-<version>`. Installing an older
package over a newer observation store is unsupported.
## Migration from make install ## Migration from make install
@@ -150,6 +195,7 @@ continuity. Over-installing the package over a `make install` is
sudo apt remove fenris # preserves config and store sudo apt remove fenris # preserves config and store
sudo apt purge fenris # also removes config and store sudo apt purge fenris # also removes config and store
sudo dnf remove fenris # preserves config and store sudo dnf remove fenris # preserves config and store
sudo xbps-remove fenris # preserves config and store
``` ```
### Development removal ### Development removal
@@ -174,6 +220,19 @@ sudo systemctl edit fenris-collect.timer
No interval key exists in `/etc/fenris/fenris.conf`. Cadence is a systemd concern, not a Fenris configuration key. No interval key exists in `/etc/fenris/fenris.conf`. Cadence is a systemd concern, not a Fenris configuration key.
On Void, Fenris uses its native runit service instead: its initial collection
is delayed by two minutes and later collections run five minutes after the
previous run finishes. Inspect its state and diagnostics with:
```bash
sv status fenris-collect
sudo tail -n 50 /var/log/fenris-collect/current
```
`fenris status` also reports the separate boot-enabled, runtime-active,
collection outcome, and observation-store freshness facts. A failed collection
is retried at the next interval; it never fabricates missing observations.
## CLI reference ## CLI reference
| Command | Behavior | | Command | Behavior |
@@ -181,8 +240,8 @@ No interval key exists in `/etc/fenris/fenris.conf`. Cadence is a systemd concer
| `fenris` | Opens the TUI (no arguments). | | `fenris` | Opens the TUI (no arguments). |
| `fenris status` | Projection facts, enabled/active state, last collect outcome, journal hint on failure or staleness. Never auto-samples. | | `fenris status` | Projection facts, enabled/active state, last collect outcome, journal hint on failure or staleness. Never auto-samples. |
| `fenris sample` | On-demand collection via the privileged helper. Blocks until the run completes. | | `fenris sample` | On-demand collection via the privileged helper. Blocks until the run completes. |
| `fenris monitor pause` | Sanctioned disable — asks for confirmation, then disables the timer and closes the monitoring period. | | `fenris monitor pause` | Sanctioned disable — asks for confirmation, then disables native scheduling and closes the monitoring period. |
| `fenris monitor resume` | Sanctioned enable — enables the timer and opens a monitoring period. No confirmation. | | `fenris monitor resume` | Sanctioned enable — enables native scheduling and opens a monitoring period. No confirmation. |
| `fenris baseline set <json>` | CLI-side validation, then polkit-guarded persistence. | | `fenris baseline set <json>` | CLI-side validation, then polkit-guarded persistence. |
| `fenris baseline clear` | Remove the endurance baseline. | | `fenris baseline clear` | Remove the endurance baseline. |
| `fenris import <path>` | Idempotent single-transaction legacy import. | | `fenris import <path>` | Idempotent single-transaction legacy import. |
+3 -4
View File
@@ -84,13 +84,13 @@ for tool in xbps-create xbps-rindex git; do
if ! command -v "$tool" &>/dev/null; then if ! command -v "$tool" &>/dev/null; then
echo "ERROR: Required tool not found: $tool" >&2 echo "ERROR: Required tool not found: $tool" >&2
exit 1 exit 1
done fi
done done
# ── Main ───────────────────────────────────────────────────────────────── # ── Main ─────────────────────────────────────────────────────────────────
VERSION=$(_version) VERSION=$(_version)
REVISION=1 REVISION="${XBPS_REVISION:-1}"
PKGVER="fenris-${VERSION}_${REVISION}" PKGVER="fenris-${VERSION}_${REVISION}"
XBPS_FILE="${PKGVER}.${ARCH}.xbps" XBPS_FILE="${PKGVER}.${ARCH}.xbps"
@@ -105,8 +105,7 @@ fi
# ── Step 1: Build XBPS package ─────────────────────────────────────────── # ── Step 1: Build XBPS package ───────────────────────────────────────────
echo "--- Build XBPS package ---" echo "--- Build XBPS package ---"
_run "make stage" _run "make XBPS_REVISION=${REVISION} package-xbps"
_run "xbps-create -A ${ARCH} -n ${PKGVER} -s 'Fenris NVMe wear monitor' -S 'NVMe wear monitor with persistent TUI' -m 'Fenris Packaging <packaging@bongbetic.com>' -H 'https://git.bongbetic.com/xavierk/Fenris' -l 'MIT' build/stage"
echo "" echo ""
# ── Step 2: Sign package ───────────────────────────────────────────────── # ── Step 2: Sign package ─────────────────────────────────────────────────