23 Commits
Author SHA1 Message Date
xavierk 3c07f37c78 fix(release): refresh published XBPS assets 2026-09-29 04:38:58 +05:30
xavierk b098132595 fix(ci): authenticate XBPS repository publish
Set the existing Fenris commit identity and pass the Gitea publish token to Git without storing credentials on the runner.
2026-09-29 04:32:54 +05:30
xavierk 1dbe372714 fix(ci): honor XBPS dispatch input
Handle Gitea boolean inputs in the publish condition. Mark Void available only after the repository publish step succeeds.
2026-09-29 04:27:57 +05:30
xavierk 3f2dd6a5a1 fix(release): retain XBPS key through publication
The optional XBPS publisher signs repository metadata after package signing. Remove the runner key only after publication and release asset upload.
2026-09-29 04:06:45 +05:30
xavierk 917c94fd65 chore: prepare v0.6.0 release 2026-09-29 03:51:35 +05:30
xavierk 714e69be52 Expose XBPS tools during CI setup
Release / release (push) Successful in 1m11s
2026-09-16 08:18:49 +05:30
xavierk ba16413363 Provision XBPS tools in release CI
Release / release (push) Failing after 40s
2026-09-16 08:17:31 +05:30
xavierk 1c3037c2f8 Implement independent format gates for release workflow (issue #86)
Add XBPS build and sign steps to CI workflow
Add XBPS publication as independent gate (requires manual trigger)
Track format availability in release notes
Update release-footer.md with XBPS install instructions
Add --available/--withheld arguments to extract_changelog.py
Attach XBPS artifacts to Gitea release
Clean up XBPS signing key material after use
2026-09-15 10:50:38 +05:30
xavierk cfdef63388 fix(release): execute publication request safely 2026-09-10 20:04:29 +05:30
xavierk f077fa671e feat(release): publish changelog-driven notes 2026-09-10 20:02:19 +05:30
xavierk bdcd321f4c ci: make release publication idempotent
Release / release (push) Successful in 1m12s
2026-09-03 19:51:55 +05:30
xavierk 25ead13ab9 ci: remove unsupported artifact upload 2026-09-03 19:41:04 +05:30
xavierk be9ce01ebf ci: use Gitea-compatible package token name
Release / release (push) Failing after 1m9s
2026-09-03 19:23:44 +05:30
xavierk 122c9f327e ci: use PAT for package publication 2026-09-03 19:12:47 +05:30
xavierk 460dde4aad ci: verify clearsigned checksum manifest correctly 2026-09-03 19:08:01 +05:30
xavierk ba270d7812 ci: preserve signed RPM for checksum validation 2026-09-03 19:06:05 +05:30
xavierk 2aed923043 ci: install RPM GPG signer dependency 2026-09-03 19:02:03 +05:30
xavierk 38ecfc2093 ci: validate signatures and use Gitea job token 2026-09-03 17:04:20 +05:30
xavierk f1ba8bdccc ci: add controlled release dispatch 2026-09-03 16:51:21 +05:30
xavierk e794310a76 ci: make Gitea release runner workflow executable 2026-09-03 16:49:54 +05:30
xavierkandCommandCodeBot 1e2ddfb928 fix(packaging): address review findings for #44
- nfpm.yaml: type:config → config_noreplace (RPM noreplace semantics)
- nfpm.yaml: type:ghost → type:dir for /var/lib/fenris (deb compatibility)
- postinst.sh/rpm/post.sh: fix timer restart — capture running unit before
  daemon-reload so the diff actually detects changes
- README: fix Python floor to ≥3.10 (was ≥3.9, inconsistent with Makefile)
- signing-key-ceremony.md: fix stale claim about nfpm signing RPMs
  (actual path is post-build rpmsign)
- tests/conftest.py: extract shared _get_version() and _read() helpers
- tests: wire up to shared conftest helpers
- release.yml: extract VERSION once via GITHUB_OUTPUT step

Co-authored-by: CommandCodeBot <noreply@commandcode.ai>
2026-09-03 15:25:35 +05:30
xavierkandCommandCodeBot 120d80b28c release: one-command build, sign, publish, and attach — plus dormant workflow (#52)
Implements the full release flow: a single script builds both deb and rpm
packages, signs the RPM payload, generates and clearsigns SHA256SUMS, uploads
to the Gitea package registry (deb to bookworm/jammy/noble pools, rpm to the
fenris group), creates a Gitea release entry with notes, and attaches all
artifacts.

Key changes:
- scripts/release.sh: new release script with --dry-run and --publish modes
- tests/test_release.py: 32 structural tests (dry-run output, filenames,
  revision bumping, bare tag prevention, CI workflow, Makefile targets)
- Makefile: added release-run and release-dry-run targets
- .gitea/workflows/release.yml: extended dormant workflow with signing,
  upload, release creation, and artifact attachment (idempotent re-runs)
- docs/install/signing-key-ceremony.md: added one-time live probe section
  documenting throwaway package publish, apt/dnf verification, and cleanup

Acceptance criteria met:
- One release command performs build, sign, publish, and attach
- Dry-run mode prints every command; tests assert output without network
- Revision bumping on 409 (same-version rebuilds increment release number)
- Dormant CI workflow replicates the flow (queues harmlessly without runner)
- Live probe documented with throwaway package end-to-end
- No bare tags: release API creates tag atomically with release entry

Co-authored-by: CommandCodeBot <noreply@commandcode.ai>
2026-09-03 14:44:49 +05:30
xavierkandCommandCodeBot babc8eeeb1 feat(packaging): nfpm-based deb + rpm build infrastructure (spec §3-7, ADR 0007)
Implement the packaging configuration, staging script, maintainer scripts,
and container test harness for building native deb and rpm packages.

Core files:
- packaging/nfpm.yaml: single source of truth for both formats
- packaging/stage.sh: builds staged tree (venv, wrapper, helpers, units, polkit, sysusers, tmpfiles)
- packaging/fenris.conf: placeholder-commented default configuration
- packaging/postinst.sh, prerm.sh, postrm.sh: POSIX-compatible deb maintainer scripts
- packaging/rpm/post.sh, preun.sh, postun.sh: RPM scriptlets
- packaging/sysusers.d/fenris.conf, tmpfiles.d/fenris.conf: systemd fragments
- packaging/fenris.repo: dnf consumer setup
- packaging/keys/fenris-packaging.asc: public key placeholder

Build targets added to Makefile: stage, package-deb, package-rpm, package, release, clean.
Container test harness in tests/test_packaging.py covering dormant install,
migration guard, upgrade semantics, and removal semantics across the
compatibility matrix (Debian 12, Ubuntu 22.04/24.04, Fedora 40).
Dormant CI workflow at .gitea/workflows/release.yml.

All 289 existing tests pass without regression.

Co-authored-by: CommandCodeBot <noreply@commandcode.ai>
2026-09-03 02:36:08 +05:30