Implement the packaging configuration, staging script, maintainer scripts, and container test harness for building native deb and rpm packages. Core files: - packaging/nfpm.yaml: single source of truth for both formats - packaging/stage.sh: builds staged tree (venv, wrapper, helpers, units, polkit, sysusers, tmpfiles) - packaging/fenris.conf: placeholder-commented default configuration - packaging/postinst.sh, prerm.sh, postrm.sh: POSIX-compatible deb maintainer scripts - packaging/rpm/post.sh, preun.sh, postun.sh: RPM scriptlets - packaging/sysusers.d/fenris.conf, tmpfiles.d/fenris.conf: systemd fragments - packaging/fenris.repo: dnf consumer setup - packaging/keys/fenris-packaging.asc: public key placeholder Build targets added to Makefile: stage, package-deb, package-rpm, package, release, clean. Container test harness in tests/test_packaging.py covering dormant install, migration guard, upgrade semantics, and removal semantics across the compatibility matrix (Debian 12, Ubuntu 22.04/24.04, Fedora 40). Dormant CI workflow at .gitea/workflows/release.yml. All 289 existing tests pass without regression. Co-authored-by: CommandCodeBot <noreply@commandcode.ai>
16 lines
625 B
Plaintext
16 lines
625 B
Plaintext
# Fenris Packaging Key — placeholder
|
|
#
|
|
# The public half of the dedicated RSA-3072 packaging key used to sign rpm
|
|
# payloads and clearsign SHA256SUMS manifests.
|
|
#
|
|
# The private half lives only in the password manager. Each release performs:
|
|
# import → sign → delete. No machine permanently holds signing material.
|
|
#
|
|
# Key details (published with the first Release):
|
|
# Algorithm: RSA 3072
|
|
# UID: Fenris Packaging <packaging@bongbetic.com>
|
|
# Expiry: 2 years from creation
|
|
#
|
|
# This file will be replaced with the real public key at the time of the
|
|
# first Release. Its raw URL doubles as the dnf gpgkey target.
|