- nfpm.yaml: type:config → config_noreplace (RPM noreplace semantics) - nfpm.yaml: type:ghost → type:dir for /var/lib/fenris (deb compatibility) - postinst.sh/rpm/post.sh: fix timer restart — capture running unit before daemon-reload so the diff actually detects changes - README: fix Python floor to ≥3.10 (was ≥3.9, inconsistent with Makefile) - signing-key-ceremony.md: fix stale claim about nfpm signing RPMs (actual path is post-build rpmsign) - tests/conftest.py: extract shared _get_version() and _read() helpers - tests: wire up to shared conftest helpers - release.yml: extract VERSION once via GITHUB_OUTPUT step Co-authored-by: CommandCodeBot <noreply@commandcode.ai>
Implement the signing and consumer-repo trust infrastructure: - Makefile: add generate-test-key, sign-rpm, checksums, clearsign targets; make release now automates the full build→sign→checksum→clearsign flow - Key ceremony: document the import→sign→delete lifecycle, key rotation outline, and private-key-in-password-manager policy - Public key: update placeholder with raw URL, algorithm, and ceremony ref - Consumer docs: README now covers apt signed-by keyring flow, dnf repo file setup, signature verification commands, and migration runbook link - Release spec: updated to reference ceremony doc and rpmsign workflow - Tests: 36 structural signing tests (nfpm config, Makefile targets, repo file, key publication, ceremony doc, consumer docs, spec refs) plus throwaway-key RPM signature and clearsign mechanics; no network or real key required Co-authored-by: CommandCodeBot <noreply@commandcode.ai>