SHA256
Compare commits
7
Commits
| Author | SHA256 | Date | |
|---|---|---|---|
|
|
04e65e38b9 | ||
|
|
972a98b3b8 | ||
|
|
de9ab24cb9 | ||
|
|
fdf3c9e4bf | ||
|
|
c3bb4bde9c | ||
|
|
0a013aa05a | ||
|
|
16c5046636 |
@@ -0,0 +1,19 @@
|
|||||||
|
#!/bin/sh
|
||||||
|
|
||||||
|
|
||||||
|
repodir=$1
|
||||||
|
reponame=kira-base
|
||||||
|
pattern="*.pkg.tar.zst"
|
||||||
|
|
||||||
|
# Combine directory and pattern.
|
||||||
|
# Quote the directory to handle spaces, leave pattern unquoted for expansion.
|
||||||
|
for pkgfile in "$repodir"/$pattern; do
|
||||||
|
# CRITICAL: Check if file exists.
|
||||||
|
# If no files match, 'sh' returns the literal string (e.g., /dir/*.txt)
|
||||||
|
if [ -e "$pkgfile" ]; then
|
||||||
|
echo "Signing $pkgfile"
|
||||||
|
repo-add --verify --sign "$repodir"/"$reponame".db.tar.gz "${pkgfile}"
|
||||||
|
fi
|
||||||
|
done
|
||||||
|
|
||||||
|
|
||||||
@@ -1,16 +1,41 @@
|
|||||||
FROM artixlinux/artixlinux:base-dinit
|
FROM artixlinux/artixlinux:base-dinit
|
||||||
|
|
||||||
|
|
||||||
|
# Add kira-base repo
|
||||||
|
RUN pacman-key --init \
|
||||||
|
&& pacman-key --recv-keys CAF78E41A83A6D64 \
|
||||||
|
&& pacman-key --lsign-key CAF78E41A83A6D64 \
|
||||||
|
&& printf '[kira-base]\nSigLevel = Required TrustedOnly\nServer = https://repos.kira-linux.org/kira-base/x86_64\n' >> /etc/pacman.conf
|
||||||
|
|
||||||
|
|
||||||
|
# Update mirrors
|
||||||
|
# RUN pacman -Syu --noconfirm artix-mirrorlist && mv /etc/pacman.d/mirrorlist.pacnew /etc/pacman.d/mirrorlist
|
||||||
|
COPY ./mirrorlist /etc/pacman.d/mirrorlist
|
||||||
|
|
||||||
|
# Update system
|
||||||
|
RUN pacman -Suy --noconfirm
|
||||||
|
|
||||||
# Install necessary build tools
|
# Install necessary build tools
|
||||||
RUN pacman -Suy --noconfirm base-devel git wget sudo make pacman-contrib
|
RUN pacman -S --noconfirm base-devel git wget sudo make pacman-contrib binutils rust rust-bindgen rust-src libgcc graphviz imagemagick python python-sphinx python-yaml texlive-latexextra llvm
|
||||||
|
|
||||||
|
# Clean pacman cache
|
||||||
|
RUN pacman -Scc
|
||||||
|
|
||||||
# Config to use 16 thread for building
|
# Config to use 16 thread for building
|
||||||
RUN printf 'MAKEFLAGS="-j16"\n' > /etc/makepkg.conf.d/j16.conf
|
RUN printf 'MAKEFLAGS="-j16"\n' > /etc/makepkg.conf.d/j16.conf
|
||||||
|
|
||||||
|
# Add packager
|
||||||
|
RUN printf 'PACKAGER="Build Bee <hive@kira-linux.org>"\n' > /etc/makepkg.conf.d/77-packager.conf
|
||||||
|
|
||||||
# Create a build user
|
# Create a build user
|
||||||
RUN useradd -m builduser \
|
RUN useradd -m builduser \
|
||||||
&& passwd -d builduser \
|
&& passwd -d builduser \
|
||||||
&& printf 'builduser ALL=(ALL) ALL\n' >> /etc/sudoers
|
&& printf 'builduser ALL=(ALL) ALL\n' >> /etc/sudoers
|
||||||
|
|
||||||
|
|
||||||
|
COPY ./makepkg.conf /etc/makepkg.conf
|
||||||
|
COPY ./rust.conf /etc/makepkg.conf.d/rust.conf
|
||||||
|
|
||||||
# Set working directory
|
# Set working directory
|
||||||
WORKDIR /home/builduser
|
WORKDIR /home/builduser
|
||||||
|
|
||||||
|
|||||||
@@ -2,6 +2,25 @@
|
|||||||
|
|
||||||
echo "Package src dir: $1"
|
echo "Package src dir: $1"
|
||||||
echo "Package bin dir: $2"
|
echo "Package bin dir: $2"
|
||||||
docker run --interactive --tty --rm --volume $1:/pkgsrc:z --volume $2:/artifact:z artix-build-env bash -c "cp /pkgsrc/* ./ && makepkg -Ccsf --noconfirm && cp *.pkg.tar.zst /artifact/"
|
|
||||||
|
keys_dir="$1/keys/pgp"
|
||||||
|
|
||||||
|
pgp_keys=""
|
||||||
|
|
||||||
|
# Check if pgp dir exist and it is not symlink
|
||||||
|
if [ -d "$keys_dir" ] && [ ! -L "$keys_dir" ]; then
|
||||||
|
echo "PGP keys dir exist: $keys_dir"
|
||||||
|
pgp_keys="gpg --recv-keys "
|
||||||
|
for f in "$keys_dir"/*; do
|
||||||
|
filename="${f##*/}"
|
||||||
|
echo "Located PGP key: $filename"
|
||||||
|
pgp_keys="$pgp_keys ${filename%.*}"
|
||||||
|
done
|
||||||
|
pgp_keys="${pgp_keys# }" # strip leading space instead
|
||||||
|
pgp_keys="$pgp_keys && "
|
||||||
|
fi
|
||||||
|
|
||||||
|
|
||||||
|
docker run --interactive --tty --rm --volume $1:/pkgsrc:z --volume $2:/artifact:z artix-build-env bash -c "$pgp_keys sudo pacman -Sy --noconfirm && cp -r /pkgsrc/* ./ && makepkg -Ccsf --noconfirm && cp *.pkg.tar.zst /artifact/"
|
||||||
|
|
||||||
|
|
||||||
|
|||||||
@@ -0,0 +1,168 @@
|
|||||||
|
#!/hint/bash
|
||||||
|
# shellcheck disable=2034
|
||||||
|
|
||||||
|
#
|
||||||
|
# /etc/makepkg.conf
|
||||||
|
#
|
||||||
|
|
||||||
|
#########################################################################
|
||||||
|
# SOURCE ACQUISITION
|
||||||
|
#########################################################################
|
||||||
|
#
|
||||||
|
#-- The download utilities that makepkg should use to acquire sources
|
||||||
|
# Format: 'protocol::agent'
|
||||||
|
DLAGENTS=('file::/usr/bin/curl -qgC - -o %o %u'
|
||||||
|
'ftp::/usr/bin/curl -qgfC - --ftp-pasv --retry 3 --retry-delay 3 -o %o %u'
|
||||||
|
'http::/usr/bin/curl -qgb "" -fLC - --retry 3 --retry-delay 3 -o %o %u'
|
||||||
|
'https::/usr/bin/curl -qgb "" -fLC - --retry 3 --retry-delay 3 -o %o %u'
|
||||||
|
'rsync::/usr/bin/rsync --no-motd -z %u %o'
|
||||||
|
'scp::/usr/bin/scp -C %u %o')
|
||||||
|
|
||||||
|
# Other common tools:
|
||||||
|
# /usr/bin/snarf
|
||||||
|
# /usr/bin/lftpget -c
|
||||||
|
# /usr/bin/wget
|
||||||
|
|
||||||
|
#-- The package required by makepkg to download VCS sources
|
||||||
|
# Format: 'protocol::package'
|
||||||
|
VCSCLIENTS=('bzr::breezy'
|
||||||
|
'fossil::fossil'
|
||||||
|
'git::git'
|
||||||
|
'hg::mercurial'
|
||||||
|
'svn::subversion')
|
||||||
|
|
||||||
|
#########################################################################
|
||||||
|
# ARCHITECTURE, COMPILE FLAGS
|
||||||
|
#########################################################################
|
||||||
|
#
|
||||||
|
CARCH="x86_64"
|
||||||
|
CHOST="x86_64-pc-linux-gnu"
|
||||||
|
|
||||||
|
#NPROC=2
|
||||||
|
|
||||||
|
#-- Compiler and Linker Flags
|
||||||
|
#CPPFLAGS=""
|
||||||
|
CFLAGS="-march=x86-64-v2 -O2 -pipe -fno-plt -fexceptions \
|
||||||
|
-Wp,-D_FORTIFY_SOURCE=3 -Wformat -Werror=format-security \
|
||||||
|
-fstack-clash-protection -fcf-protection \
|
||||||
|
-fno-omit-frame-pointer -mno-omit-leaf-frame-pointer"
|
||||||
|
CXXFLAGS="$CFLAGS -Wp,-D_GLIBCXX_ASSERTIONS"
|
||||||
|
LDFLAGS="-Wl,-O1 -Wl,--sort-common -Wl,--as-needed -Wl,-z,relro -Wl,-z,now \
|
||||||
|
-Wl,-z,pack-relative-relocs"
|
||||||
|
LTOFLAGS="-flto=auto"
|
||||||
|
#-- Make Flags: change this for DistCC/SMP systems
|
||||||
|
MAKEFLAGS="-j16"
|
||||||
|
#-- Debugging flags
|
||||||
|
DEBUG_CFLAGS="-g"
|
||||||
|
DEBUG_CXXFLAGS="$DEBUG_CFLAGS"
|
||||||
|
|
||||||
|
#########################################################################
|
||||||
|
# BUILD ENVIRONMENT
|
||||||
|
#########################################################################
|
||||||
|
#
|
||||||
|
# Makepkg defaults: BUILDENV=(!distcc !color !ccache check !sign)
|
||||||
|
# A negated environment option will do the opposite of the comments below.
|
||||||
|
#
|
||||||
|
#-- distcc: Use the Distributed C/C++/ObjC compiler
|
||||||
|
#-- color: Colorize output messages
|
||||||
|
#-- ccache: Use ccache to cache compilation
|
||||||
|
#-- check: Run the check() function if present in the PKGBUILD
|
||||||
|
#-- sign: Generate PGP signature file
|
||||||
|
#
|
||||||
|
BUILDENV=(!distcc color !ccache check !sign)
|
||||||
|
#
|
||||||
|
#-- If using DistCC, your MAKEFLAGS will also need modification. In addition,
|
||||||
|
#-- specify a space-delimited list of hosts running in the DistCC cluster.
|
||||||
|
#DISTCC_HOSTS=""
|
||||||
|
#
|
||||||
|
#-- Specify a directory for package building.
|
||||||
|
#BUILDDIR=/tmp/makepkg
|
||||||
|
|
||||||
|
#########################################################################
|
||||||
|
# GLOBAL PACKAGE OPTIONS
|
||||||
|
# These are default values for the options=() settings
|
||||||
|
#########################################################################
|
||||||
|
#
|
||||||
|
# Makepkg defaults:
|
||||||
|
# OPTIONS=(!strip docs libtool staticlibs emptydirs !zipman !purge !debug !lto !autodeps)
|
||||||
|
# A negated option will do the opposite of the comments below.
|
||||||
|
#
|
||||||
|
#-- strip: Strip symbols from binaries/libraries
|
||||||
|
#-- docs: Save doc directories specified by DOC_DIRS
|
||||||
|
#-- libtool: Leave libtool (.la) files in packages
|
||||||
|
#-- staticlibs: Leave static library (.a) files in packages
|
||||||
|
#-- emptydirs: Leave empty directories in packages
|
||||||
|
#-- zipman: Compress manual (man and info) pages in MAN_DIRS with gzip
|
||||||
|
#-- purge: Remove files specified by PURGE_TARGETS
|
||||||
|
#-- debug: Add debugging flags as specified in DEBUG_* variables
|
||||||
|
#-- lto: Add compile flags for building with link time optimization
|
||||||
|
#-- autodeps: Automatically add depends/provides
|
||||||
|
#
|
||||||
|
OPTIONS=(strip docs !libtool !staticlibs emptydirs zipman purge !debug lto)
|
||||||
|
|
||||||
|
#-- File integrity checks to use. Valid: md5, sha1, sha224, sha256, sha384, sha512, b2
|
||||||
|
INTEGRITY_CHECK=(sha256)
|
||||||
|
#-- Options to be used when stripping binaries. See `man strip' for details.
|
||||||
|
STRIP_BINARIES="--strip-all"
|
||||||
|
#-- Options to be used when stripping shared libraries. See `man strip' for details.
|
||||||
|
STRIP_SHARED="--strip-unneeded"
|
||||||
|
#-- Options to be used when stripping static libraries. See `man strip' for details.
|
||||||
|
STRIP_STATIC="--strip-debug"
|
||||||
|
#-- Manual (man and info) directories to compress (if zipman is specified)
|
||||||
|
MAN_DIRS=(usr{,/local}{,/share}/{man,info})
|
||||||
|
#-- Doc directories to remove (if !docs is specified)
|
||||||
|
DOC_DIRS=(usr/{,local/}{,share/}{doc,gtk-doc})
|
||||||
|
#-- Files to be removed from all packages (if purge is specified)
|
||||||
|
PURGE_TARGETS=(usr/{,share}/info/dir .packlist *.pod)
|
||||||
|
#-- Directory to store source code in for debug packages
|
||||||
|
DBGSRCDIR="/usr/src/debug"
|
||||||
|
#-- Prefix and directories for library autodeps
|
||||||
|
LIB_DIRS=('lib:usr/lib' 'lib32:usr/lib32')
|
||||||
|
|
||||||
|
#########################################################################
|
||||||
|
# PACKAGE OUTPUT
|
||||||
|
#########################################################################
|
||||||
|
#
|
||||||
|
# Default: put built package and cached source in build directory
|
||||||
|
#
|
||||||
|
#-- Destination: specify a fixed directory where all packages will be placed
|
||||||
|
#PKGDEST=/home/packages
|
||||||
|
#-- Source cache: specify a fixed directory where source files will be cached
|
||||||
|
#SRCDEST=/home/sources
|
||||||
|
#-- Source packages: specify a fixed directory where all src packages will be placed
|
||||||
|
#SRCPKGDEST=/home/srcpackages
|
||||||
|
#-- Log files: specify a fixed directory where all log files will be placed
|
||||||
|
#LOGDEST=/home/makepkglogs
|
||||||
|
#-- Packager: name/email of the person or organization building packages
|
||||||
|
#PACKAGER="John Doe <john@doe.com>"
|
||||||
|
#-- Specify a key to use for package signing
|
||||||
|
#GPGKEY=""
|
||||||
|
|
||||||
|
#########################################################################
|
||||||
|
# COMPRESSION DEFAULTS
|
||||||
|
#########################################################################
|
||||||
|
#
|
||||||
|
COMPRESSGZ=(gzip -c -f -n)
|
||||||
|
COMPRESSBZ2=(bzip2 -c -f)
|
||||||
|
COMPRESSXZ=(xz -c -z -)
|
||||||
|
COMPRESSZST=(zstd -c -T0 -)
|
||||||
|
COMPRESSLRZ=(lrzip -q)
|
||||||
|
COMPRESSLZO=(lzop -q)
|
||||||
|
COMPRESSZ=(compress -c -f)
|
||||||
|
COMPRESSLZ4=(lz4 -q)
|
||||||
|
COMPRESSLZ=(lzip -c -f)
|
||||||
|
|
||||||
|
#########################################################################
|
||||||
|
# EXTENSION DEFAULTS
|
||||||
|
#########################################################################
|
||||||
|
#
|
||||||
|
PKGEXT='.pkg.tar.zst'
|
||||||
|
SRCEXT='.src.tar.gz'
|
||||||
|
|
||||||
|
#########################################################################
|
||||||
|
# OTHER
|
||||||
|
#########################################################################
|
||||||
|
#
|
||||||
|
#-- Command used to run pacman as root, instead of trying sudo and su
|
||||||
|
#PACMAN_AUTH=()
|
||||||
|
# vim: set ft=sh ts=2 sw=2 et:
|
||||||
@@ -0,0 +1,7 @@
|
|||||||
|
# Server list generated by rankmirrors on 2026-10-05
|
||||||
|
Server = http://mirror1.artixlinux.org/repos/$repo/os/$arch
|
||||||
|
Server = http://ftp.ntua.gr/pub/linux/artix-linux/$repo/os/$arch
|
||||||
|
Server = http://www.nylxs.com/mirror/repos/$repo/os/$arch
|
||||||
|
Server = https://artix.rw-net.de/repos/$repo/os/$arch
|
||||||
|
Server = https://artix.unixpeople.org/repos/$repo/os/$arch
|
||||||
|
Server = https://artix.wheaton.edu/repos/$repo/os/$arch
|
||||||
@@ -0,0 +1,20 @@
|
|||||||
|
#!/hint/bash
|
||||||
|
# shellcheck disable=2034
|
||||||
|
|
||||||
|
#
|
||||||
|
# /etc/makepkg.conf.d/rust.conf
|
||||||
|
#
|
||||||
|
|
||||||
|
#########################################################################
|
||||||
|
# RUST LANGUAGE SUPPORT
|
||||||
|
#########################################################################
|
||||||
|
|
||||||
|
# Flags used for the Rust compiler, similar in spirit to CFLAGS. Read
|
||||||
|
# linkman:rustc[1] for more details on the available flags.
|
||||||
|
RUSTFLAGS="-C opt-level=2 -C target-cpu=x86-64-v2 -C force-frame-pointers=yes"
|
||||||
|
|
||||||
|
# Additional compiler flags appended to `RUSTFLAGS` for use in debugging.
|
||||||
|
# Usually this would include: ``-C debuginfo=2''. Read linkman:rustc[1] for
|
||||||
|
# more details on the available flags.
|
||||||
|
# debuginfo=0 - no debug symbols
|
||||||
|
DEBUG_RUSTFLAGS="-C debuginfo=0"
|
||||||
@@ -0,0 +1,18 @@
|
|||||||
|
#!/bin/sh
|
||||||
|
|
||||||
|
|
||||||
|
repodir=$1
|
||||||
|
pattern="*.pkg.tar.zst"
|
||||||
|
|
||||||
|
# Combine directory and pattern.
|
||||||
|
# Quote the directory to handle spaces, leave pattern unquoted for expansion.
|
||||||
|
for pkgfile in "$repodir"/$pattern; do
|
||||||
|
# CRITICAL: Check if file exists.
|
||||||
|
# If no files match, 'sh' returns the literal string (e.g., /dir/*.txt)
|
||||||
|
if [ -e "$pkgfile" ]; then
|
||||||
|
echo "Signing $pkgfile"
|
||||||
|
gpg --use-agent --output "${pkgfile}".sig --detach-sig "${pkgfile}"
|
||||||
|
fi
|
||||||
|
done
|
||||||
|
|
||||||
|
|
||||||
Reference in New Issue
Block a user