Validate and release on the user's Void machine #87

Closed
opened 2026-09-14 16:11:50 +00:00 by xavierk · 4 comments
Owner

Parent

Support native Void Linux and signed XBPS distribution through Gitea

What to build

Deliver recorded host acceptance and the validated XBPS release, ending with Fenris installed and monitoring.

Preserve the parent specification’s existing Debian/RPM compatibility, observation-history safety, and scoped privilege requirements.

Acceptance criteria

  • Recheck host state, identify/configure the intended NVMe drive, and preserve pre-existing data before package lifecycle operations.
  • Verify real acquisition, authenticated controls, scheduling, failure reporting, full dashboard behavior, and pause/resume semantics.
  • Coordinate and verify reboot persistence; absence of the reboot test leaves that gate pending.
  • Verify native upgrade/removal/reinstall with history preservation and immediate update discovery through Gitea.
  • Publish only after the XBPS gate passes, then verify downloads and released-package installation.
  • Preserve acceptance-test observation history and leave the released package monitoring; document installation, trust setup, diagnostics and rollback for Void users.

Blocked by

## Parent [Support native Void Linux and signed XBPS distribution through Gitea](https://git.bongbetic.com/xavierk/Fenris/issues/82) ## What to build Deliver recorded host acceptance and the validated XBPS release, ending with Fenris installed and monitoring. Preserve the parent specification’s existing Debian/RPM compatibility, observation-history safety, and scoped privilege requirements. ## Acceptance criteria - [ ] Recheck host state, identify/configure the intended NVMe drive, and preserve pre-existing data before package lifecycle operations. - [ ] Verify real acquisition, authenticated controls, scheduling, failure reporting, full dashboard behavior, and pause/resume semantics. - [ ] Coordinate and verify reboot persistence; absence of the reboot test leaves that gate pending. - [ ] Verify native upgrade/removal/reinstall with history preservation and immediate update discovery through Gitea. - [ ] Publish only after the XBPS gate passes, then verify downloads and released-package installation. - [ ] Preserve acceptance-test observation history and leave the released package monitoring; document installation, trust setup, diagnostics and rollback for Void users. ## Blocked by - [Publish validated package formats independently from the release workflow](https://git.bongbetic.com/xavierk/Fenris/issues/86)
xavierk added the ready-for-agent label 2026-09-14 16:11:50 +00:00
xavierk self-assigned this 2026-09-15 05:22:15 +00:00
Author
Owner

Host preflight recorded: Void x86_64/glibc with runit; root filesystem is mounted from the selected Micron 2400 NVMe at /dev/nvme0n1. Fenris and smartmontools were absent before testing, and no device, filesystem, configuration, or observation-store data was modified.

XBPS release gate is pending: the permanent Gitea endpoint responds, but xbps-install -n -S --repository https://git.bongbetic.com/xavierk/Fenris-xbps/raw/branch/stable/x86_64 fenris reports that fenris is not in the repository pool. The remote fenris-0.3.5_1.x86_64.xbps is a 731-byte proof artifact and does not match the current 2.4 MB local build, so it was not installed or published as a release. A signed production artifact must be indexed and its direct download verified before host lifecycle acceptance can continue.

Reboot persistence is also pending coordination. README guidance for Void installation, trust fingerprint, diagnostics, upgrade/removal, and rollback was added in commit fca0724; it explicitly marks the XBPS channel withheld pending this acceptance gate.

Host preflight recorded: Void x86_64/glibc with runit; root filesystem is mounted from the selected Micron 2400 NVMe at /dev/nvme0n1. Fenris and smartmontools were absent before testing, and no device, filesystem, configuration, or observation-store data was modified. XBPS release gate is pending: the permanent Gitea endpoint responds, but `xbps-install -n -S --repository https://git.bongbetic.com/xavierk/Fenris-xbps/raw/branch/stable/x86_64 fenris` reports that fenris is not in the repository pool. The remote fenris-0.3.5_1.x86_64.xbps is a 731-byte proof artifact and does not match the current 2.4 MB local build, so it was not installed or published as a release. A signed production artifact must be indexed and its direct download verified before host lifecycle acceptance can continue. Reboot persistence is also pending coordination. README guidance for Void installation, trust fingerprint, diagnostics, upgrade/removal, and rollback was added in commit fca0724; it explicitly marks the XBPS channel withheld pending this acceptance gate.
Author
Owner

Void host acceptance and Gitea XBPS publication completed.

  • Reboot verified: fenris-0.3.5_14 is installed; runit service is enabled, running, fresh, and persistent.
  • Published signed fenris-0.3.5_14.x86_64.xbps and matching .sig2 to xavierk/Fenris-xbps branch stable.
  • Removed the committed XBPS validation artifacts so repository resolution selects only the release package.
  • Verified the raw x86_64-repodata matches the Gitea branch, repository discovery resolves fenris-0.3.5_14, and a download-only transaction verifies both repository and package RSA signatures.
  • Performed a forced in-place install from the permanent Gitea URL. XBPS treats a forced same-version reinstall as remove/install, so it deliberately paused monitoring; monitoring was restored through the sanctioned enable path and is active again.

Source publication fixes are on main through 34bfc70 (complete XBPS package build, revision-aware reproducible publisher, correct repository indexing, and fresh package signatures).

Void host acceptance and Gitea XBPS publication completed. - Reboot verified: `fenris-0.3.5_14` is installed; runit service is enabled, running, fresh, and persistent. - Published signed `fenris-0.3.5_14.x86_64.xbps` and matching `.sig2` to `xavierk/Fenris-xbps` branch `stable`. - Removed the committed XBPS validation artifacts so repository resolution selects only the release package. - Verified the raw `x86_64-repodata` matches the Gitea branch, repository discovery resolves `fenris-0.3.5_14`, and a download-only transaction verifies both repository and package RSA signatures. - Performed a forced in-place install from the permanent Gitea URL. XBPS treats a forced same-version reinstall as remove/install, so it deliberately paused monitoring; monitoring was restored through the sanctioned enable path and is active again. Source publication fixes are on `main` through `34bfc70` (complete XBPS package build, revision-aware reproducible publisher, correct repository indexing, and fresh package signatures).
Author
Owner

Follow-up acceptance evidence for the production revision:

  • Fixed publisher verification in commit 9d22525: XBPS repository signatures are embedded in x86_64-repodata, so verification now checks the package, package .sig2, and repodata only. The stale repository-layout documentation was corrected as well.
  • Permanent Gitea stable serves fenris-0.3.5_15.x86_64.xbps (1,977,553 bytes), its 384-byte .sig2, signed x86_64-repodata (1,401 bytes), and retains fenris-0.3.5_14. The downloaded _15 package and signature match the local release artifacts byte-for-byte.
  • A real Void client fetched the signed metadata and verified the _15 package RSA signature; the host upgraded from fenris-0.3.5_14 to fenris-0.3.5_15 and now reports the package up to date.
  • Observation-store counts were 56 samples / 6 hour observations / 1 day aggregate / 3 monitoring periods before the upgrade. The store and observations.db.bak remain present afterward; current counts are 58 / 6 / 1 / 3.
  • Final host state: runit service and logger both running, /var/log/fenris-collect is 2770 root:fenris, logger output reports successful collection, and the selected Micron NVMe remains monitored.
  • The live refresh test showed that -S can reuse the cached repodata archive; -M -S bypasses it and immediately discovers the published revision. README and ADR 0008 now document that command.

Source follow-up commits: 9d22525 and fae72bb.

Follow-up acceptance evidence for the production revision: - Fixed publisher verification in commit 9d22525: XBPS repository signatures are embedded in x86_64-repodata, so verification now checks the package, package .sig2, and repodata only. The stale repository-layout documentation was corrected as well. - Permanent Gitea stable serves fenris-0.3.5_15.x86_64.xbps (1,977,553 bytes), its 384-byte .sig2, signed x86_64-repodata (1,401 bytes), and retains fenris-0.3.5_14. The downloaded _15 package and signature match the local release artifacts byte-for-byte. - A real Void client fetched the signed metadata and verified the _15 package RSA signature; the host upgraded from fenris-0.3.5_14 to fenris-0.3.5_15 and now reports the package up to date. - Observation-store counts were 56 samples / 6 hour observations / 1 day aggregate / 3 monitoring periods before the upgrade. The store and observations.db.bak remain present afterward; current counts are 58 / 6 / 1 / 3. - Final host state: runit service and logger both running, /var/log/fenris-collect is 2770 root:fenris, logger output reports successful collection, and the selected Micron NVMe remains monitored. - The live refresh test showed that -S can reuse the cached repodata archive; -M -S bypasses it and immediately discovers the published revision. README and ADR 0008 now document that command. Source follow-up commits: 9d22525 and fae72bb.
Author
Owner

Release surface follow-up: updated the existing v0.3.5 Gitea release notes to list Debian/Ubuntu, Fedora/openSUSE, and Void XBPS as available (none withheld), added the _15 XBPS package and .sig2 as release assets, and verified both asset downloads byte-for-byte against the published channel artifacts.

Release surface follow-up: updated the existing v0.3.5 Gitea release notes to list Debian/Ubuntu, Fedora/openSUSE, and Void XBPS as available (none withheld), added the _15 XBPS package and .sig2 as release assets, and verified both asset downloads byte-for-byte against the published channel artifacts.
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Reference: xavierk/Fenris#87