xavierk
a3e6cc3b3c
Fix Void package acceptance gaps
2026-09-15 19:43:00 +05:30
xavierk and CommandCodeBot
985efed906
Implement XBPS proof of concept (issue #83 )
...
Prove signed XBPS installation and immediate updates through Gitea.
Changes:
- Add scripts/xbps-publish.sh for automated XBPS publication
- Add Makefile targets: package-xbps, sign-xbps, xbps-publish
- Add docs/spec/xbps-proof-results.md with acceptance criteria results
- Add docs/adr/0008-native-void-support.md (architecture decision)
- Add docs/spec/native-void-support.md (feature specification)
- Add docs/spec/native-void-tickets.md (implementation tickets)
Proof results:
- Raw URL delivery verified (no LFS indirection)
- Signing key handling established (SSH RSA via xbps-rindex)
- Install and update flow demonstrated (v0.3.5 → v0.3.6)
- Cache behavior documented (6-hour max-age, -S flag for immediate discovery)
- Publication mechanism documented and automated
- Failure recovery demonstrated (git revert)
Repository: https://git.bongbetic.com/xavierk/Fenris-xbps
Co-authored-by: CommandCodeBot <noreply@commandcode.ai >
2026-09-14 22:37:49 +05:30
xavierk
bb5bc9a72e
docs(spec): assemble dashboard clarity spec, DC-1–DC-8 criteria, TUI-4 amendment (wayfinder #60 )
2026-09-10 12:03:31 +05:30
xavierk
b593a2742e
fix: make RPM runtime portable on Tumbleweed
2026-09-04 11:46:58 +05:30
xavierk and CommandCodeBot
1e2ddfb928
fix(packaging): address review findings for #44
...
- nfpm.yaml: type:config → config_noreplace (RPM noreplace semantics)
- nfpm.yaml: type:ghost → type:dir for /var/lib/fenris (deb compatibility)
- postinst.sh/rpm/post.sh: fix timer restart — capture running unit before
daemon-reload so the diff actually detects changes
- README: fix Python floor to ≥3.10 (was ≥3.9, inconsistent with Makefile)
- signing-key-ceremony.md: fix stale claim about nfpm signing RPMs
(actual path is post-build rpmsign)
- tests/conftest.py: extract shared _get_version() and _read() helpers
- tests: wire up to shared conftest helpers
- release.yml: extract VERSION once via GITHUB_OUTPUT step
Co-authored-by: CommandCodeBot <noreply@commandcode.ai >
2026-09-03 15:25:35 +05:30
xavierk and CommandCodeBot
120d80b28c
release: one-command build, sign, publish, and attach — plus dormant workflow ( #52 )
...
Implements the full release flow: a single script builds both deb and rpm
packages, signs the RPM payload, generates and clearsigns SHA256SUMS, uploads
to the Gitea package registry (deb to bookworm/jammy/noble pools, rpm to the
fenris group), creates a Gitea release entry with notes, and attaches all
artifacts.
Key changes:
- scripts/release.sh: new release script with --dry-run and --publish modes
- tests/test_release.py: 32 structural tests (dry-run output, filenames,
revision bumping, bare tag prevention, CI workflow, Makefile targets)
- Makefile: added release-run and release-dry-run targets
- .gitea/workflows/release.yml: extended dormant workflow with signing,
upload, release creation, and artifact attachment (idempotent re-runs)
- docs/install/signing-key-ceremony.md: added one-time live probe section
documenting throwaway package publish, apt/dnf verification, and cleanup
Acceptance criteria met:
- One release command performs build, sign, publish, and attach
- Dry-run mode prints every command; tests assert output without network
- Revision bumping on 409 (same-version rebuilds increment release number)
- Dormant CI workflow replicates the flow (queues harmlessly without runner)
- Live probe documented with throwaway package end-to-end
- No bare tags: release API creates tag atomically with release entry
Co-authored-by: CommandCodeBot <noreply@commandcode.ai >
2026-09-03 14:44:49 +05:30
xavierk and CommandCodeBot
d8fa6df072
signing: rpm payload signing, key publication, consumer repo setup for #51
...
Implement the signing and consumer-repo trust infrastructure:
- Makefile: add generate-test-key, sign-rpm, checksums, clearsign targets;
make release now automates the full build→sign→checksum→clearsign flow
- Key ceremony: document the import→sign→delete lifecycle, key rotation
outline, and private-key-in-password-manager policy
- Public key: update placeholder with raw URL, algorithm, and ceremony ref
- Consumer docs: README now covers apt signed-by keyring flow, dnf repo
file setup, signature verification commands, and migration runbook link
- Release spec: updated to reference ceremony doc and rpmsign workflow
- Tests: 36 structural signing tests (nfpm config, Makefile targets,
repo file, key publication, ceremony doc, consumer docs, spec refs)
plus throwaway-key RPM signature and clearsign mechanics; no network
or real key required
Co-authored-by: CommandCodeBot <noreply@commandcode.ai >
2026-09-03 14:14:55 +05:30
xavierk and CommandCodeBot
c45b07003a
docs(migration): add make-install-to-package runbook and no-move continuity tests for #50
...
Migration runbook at docs/install/migrate-from-makeinstall.md covers the
mandatory remove-then-install path, why over-install is forbidden, no-move
continuity guarantees, and reset-to-dormant expectations.
Acceptance criteria MG-1 through MG-4 added to the install criteria section.
Containerized tests verify no-move continuity: existing group makes sysusers
a no-op, existing store dir makes tmpfiles a no-op, hand-edited config
survives as a non-database file, and store schema is caught up by the
upgrade-path migration. Dead code from a prior merge removed.
Co-authored-by: CommandCodeBot <noreply@commandcode.ai >
2026-09-03 12:56:43 +05:30
xavierk
b005049733
docs: release & packaging spec + ADR 0007 amending 0004 (map #33 , task #42 )
...
- docs/spec/release-packaging.md: decision-complete spec — compat matrix,
Gitea 1.27.1 registry channel, nfpm toolchain, signing/key policy,
release mechanics, package layout/ownership, maintainer-script
contracts, initial config, make-install migration runbook.
- docs/adr/0007: package delivery amends ADR 0004 (delivery/ownership
only; runtime semantics inherited verbatim). 0004 status updated.
- docs/research/: toolchain, gitea-registry, obs findings merged from
research branches (assets of map tickets #34/#35/#36).
- CONTEXT.md: Release + Rollback glossary terms (ticket #43 ).
2026-09-03 01:44:37 +05:30
xavierk
566d1c81b1
docs(spec): fenris-redesign.md — implementation-ready specification from ADRs 0001-0006 with two-way traceability matrix
2026-08-31 23:43:22 +05:30
xavierk
ff51be2d8a
docs(spec): fill assembly traceability gaps — PR-17 projection arithmetic, TUI-4 Panes layout, IN-10 artifact placement, CI-3 /run prohibition
2026-08-31 23:43:22 +05:30
xavierk
b2ef1308b0
docs(adr): 0006 collector acquisition path — smartctl counters + sysfs identity, hard pin, no partial samples; SLOT-B filled (AC-1–5)
2026-08-31 23:02:25 +05:30
xavierk
580fab26be
docs(adr): amend 0002 — blank identity key caps confidence at Limited, blank-key change semantics; SLOT-A filled (PR-15/16, ID-4); glossary term degraded identity
2026-08-31 22:30:40 +05:30
xavierk
bf83ac5481
docs(spec): acceptance criteria for the redesign — subsystem gates, A/P/M evidence classes, ADR traceability; state-matrix and parity gates, prohibition set
2026-08-31 22:13:20 +05:30
xavierk
305bdd4779
docs(adr): amend 0001 — controller-segment metadata snapshot: normalized identity diagnostics, vid/ssvid/transport, frozen at open, nullable
2026-08-31 21:57:54 +05:30
xavierk
4d332bef53
docs(adr): amend 0001 + 0003 — baseline provenance and validation; glossary terms for verified and unverified override
2026-08-31 21:02:09 +05:30
xavierk
d45d931a0d
docs(adr): 0005 failure and recovery — refuse bad writes, never backfill, degrade store faults; glossary term for store fault
2026-08-31 20:14:23 +05:30
xavierk
ffa6f22777
docs(adr): 0004 installation lifecycle — Makefile venv install, dormant install, sanctioned teardown
2026-08-31 18:58:05 +05:30
xavierk
de1e8c753b
docs(agents): issue-tracker and domain guidance for agents; ignore .pi session state
2026-08-31 17:25:10 +05:30
xavierk
26a6703152
docs(adr): 0003 service lifecycle — timer-driven collector, sanctioned control helper; glossary terms for collection run, deliberate disable
2026-08-31 16:14:52 +05:30
xavierk
43467f8957
docs(adr): 0002 projection model — sustained regime, categorical confidence; glossary terms for regime, habit change, scenario range, coverage
2026-08-31 15:38:41 +05:30
xavierk
a63da74e44
docs(adr): 0001 observation store in SQLite; glossary terms for store entities
2026-08-31 14:48:14 +05:30