Compare commits
148 Commits
v1.6.2
...
ec7b959893
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
ec7b959893 | ||
|
|
6363709987 | ||
|
|
7764a2946c | ||
|
|
85d1abf61c | ||
|
|
b4e0594901 | ||
|
|
14b95d5639 | ||
|
|
8294bce436 | ||
|
|
f1517963a5 | ||
|
|
d0e99b6483 | ||
|
|
13fc8fe885 | ||
|
|
e8aed49a4c | ||
|
|
87ee6c66c8 | ||
|
|
f6228988e1 | ||
|
|
5c7171acd9 | ||
|
|
06cc5b6725 | ||
|
|
ece575cc73 | ||
|
|
a4099717be | ||
|
|
a37b9ed8a7 | ||
|
|
a4a5b661b9 | ||
|
|
43fbcfb227 | ||
|
|
a6c40451fe | ||
|
|
5fa2709a84 | ||
|
|
386d8aa2f2 | ||
|
|
70b06d2b3a | ||
|
|
00c668b595 | ||
|
|
12a38b7e6a | ||
|
|
37fd2192a5 | ||
|
|
607102e7f8 | ||
|
|
133cf63b9f | ||
|
|
6334936e8a | ||
|
|
946965f016 | ||
|
|
541a7f679f | ||
|
|
128f71745a | ||
|
|
df2ce636c8 | ||
|
|
3b0dabf2a7 | ||
|
|
697370c906 | ||
|
|
bc57172d92 | ||
|
|
0e7e23dce5 | ||
|
|
9d53f4c6f5 | ||
|
|
a46d85b541 | ||
|
|
acaea11eb6 | ||
|
|
056d21a859 | ||
|
|
612ba5069d | ||
|
|
551e245218 | ||
|
|
814523eac2 | ||
|
|
4f2c5013a7 | ||
|
|
e01bb8c39a | ||
|
|
461a3c334d | ||
|
|
e3de46c6a4 | ||
|
|
b20882f492 | ||
|
|
430f21735e | ||
|
|
acf1b69b70 | ||
|
|
7d574e67ec | ||
|
|
aad6814fc5 | ||
|
|
411cd2df66 | ||
|
|
849d29c044 | ||
|
|
0947dea01e | ||
|
|
5d7e1fdbb3 | ||
|
|
ac6981ad4d | ||
|
|
f3a7b69bac | ||
|
|
5bcad7f5f3 | ||
|
|
d39582d1da | ||
|
|
043d389a76 | ||
|
|
cc1e543ebc | ||
|
|
25a0579809 | ||
|
|
d4e461bb63 | ||
|
|
1864d0700e | ||
|
|
a9bd8d202f | ||
|
|
28df54503e | ||
|
|
aa489811e3 | ||
|
|
f66af0157b | ||
|
|
b0b3ccf5aa | ||
|
|
e178afde31 | ||
|
|
9802293871 | ||
|
|
a2138c9985 | ||
|
|
10998e50ad | ||
|
|
a20814cb37 | ||
|
|
feb5ba267f | ||
|
|
591be4ef35 | ||
|
|
3e6ef0fd68 | ||
|
|
3d5c770def | ||
|
|
f4339a746a | ||
|
|
763f02a9a4 | ||
|
|
2eec873a17 | ||
|
|
17ee947930 | ||
|
|
b989bdd4eb | ||
|
|
c4da8368d8 | ||
|
|
997c265cfb | ||
|
|
955028288f | ||
|
|
866572e252 | ||
|
|
b0a733369e | ||
|
|
c5843ccd30 | ||
|
|
3cb7852cb4 | ||
|
|
f995e3d368 | ||
|
|
ffa9d9660a | ||
|
|
be70dd4239 | ||
|
|
74876e2e15 | ||
|
|
54058c7f4d | ||
|
|
8583fdf172 | ||
|
|
374f4ed745 | ||
|
|
63e1b3d145 | ||
|
|
2f89de1ff5 | ||
|
|
019aa4b0d9 | ||
|
|
9c22c7dbb4 | ||
|
|
f83e192e37 | ||
|
|
486863eb58 | ||
|
|
bb23bd94f2 | ||
|
|
2a66c082eb | ||
|
|
ee9d7758ed | ||
|
|
0119af330f | ||
|
|
e117115b7f | ||
|
|
755b78fcb7 | ||
|
|
9485bc9e3f | ||
|
|
dcda23435d | ||
|
|
a69e81c44b | ||
|
|
2ca004d056 | ||
|
|
f7bd5bfd0b | ||
|
|
2c15a4016b | ||
|
|
9e3ce34626 | ||
|
|
1a13fcaa4e | ||
|
|
48a0d1d458 | ||
|
|
783d2b921a | ||
|
|
6effacefef | ||
|
|
65903e740b | ||
|
|
aa80a2ddb4 | ||
|
|
9456ad4475 | ||
|
|
3d7d7e9c09 | ||
|
|
328203ccd7 | ||
|
|
ac16378807 | ||
|
|
f7a86bc353 | ||
|
|
06a6a77a48 | ||
|
|
4883e40812 | ||
|
|
031ae5ac69 | ||
|
|
1c4fc531fa | ||
|
|
33dfbf3a4d | ||
|
|
a3aa7b6394 | ||
|
|
724c262a4a | ||
|
|
dcbe16c5f0 | ||
|
|
f63b0a9f08 | ||
|
|
822c418503 | ||
|
|
562a6da291 | ||
|
|
e61b30d9af | ||
|
|
27c0c7c01f | ||
|
|
0d652d995e | ||
|
|
0e03fbbee2 | ||
|
|
7cfd7e8d5c | ||
|
|
84b6c71748 | ||
|
|
db9aaf920e |
17
.claude/settings.json
Normal file
17
.claude/settings.json
Normal file
@@ -0,0 +1,17 @@
|
|||||||
|
{
|
||||||
|
"permissions": {
|
||||||
|
"ask": [
|
||||||
|
"Skill(update-config)",
|
||||||
|
"Skill(update-config:*)",
|
||||||
|
"Bash(git commit)",
|
||||||
|
"Bash(git commit *)",
|
||||||
|
"Bash(git push)",
|
||||||
|
"Bash(git push *)"
|
||||||
|
]
|
||||||
|
},
|
||||||
|
"sandbox": {
|
||||||
|
"enabled": true,
|
||||||
|
"failIfUnavailable": true,
|
||||||
|
"autoAllowBashIfSandboxed": true
|
||||||
|
}
|
||||||
|
}
|
||||||
50
.github/workflows/ci.yml
vendored
50
.github/workflows/ci.yml
vendored
@@ -2,34 +2,72 @@ name: CI
|
|||||||
|
|
||||||
on:
|
on:
|
||||||
push:
|
push:
|
||||||
branches-ignore:
|
branches:
|
||||||
- main
|
- '**'
|
||||||
pull_request:
|
pull_request:
|
||||||
|
|
||||||
|
permissions:
|
||||||
|
contents: read
|
||||||
|
|
||||||
|
concurrency:
|
||||||
|
group: global-ci-${{ github.repository }}-${{ github.ref_name }}
|
||||||
|
cancel-in-progress: false
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
|
security-codeql:
|
||||||
|
permissions:
|
||||||
|
contents: read
|
||||||
|
packages: read
|
||||||
|
security-events: write
|
||||||
|
uses: ./.github/workflows/security-codeql.yml
|
||||||
|
|
||||||
test-unit:
|
test-unit:
|
||||||
|
permissions:
|
||||||
|
contents: read
|
||||||
uses: ./.github/workflows/test-unit.yml
|
uses: ./.github/workflows/test-unit.yml
|
||||||
|
|
||||||
test-integration:
|
test-integration:
|
||||||
|
permissions:
|
||||||
|
contents: read
|
||||||
uses: ./.github/workflows/test-integration.yml
|
uses: ./.github/workflows/test-integration.yml
|
||||||
|
|
||||||
test-env-virtual:
|
test-env-virtual:
|
||||||
|
permissions:
|
||||||
|
contents: read
|
||||||
uses: ./.github/workflows/test-env-virtual.yml
|
uses: ./.github/workflows/test-env-virtual.yml
|
||||||
|
|
||||||
test-env-nix:
|
test-env-nix:
|
||||||
|
permissions:
|
||||||
|
contents: read
|
||||||
uses: ./.github/workflows/test-env-nix.yml
|
uses: ./.github/workflows/test-env-nix.yml
|
||||||
|
|
||||||
test-e2e:
|
test-e2e:
|
||||||
|
permissions:
|
||||||
|
contents: read
|
||||||
uses: ./.github/workflows/test-e2e.yml
|
uses: ./.github/workflows/test-e2e.yml
|
||||||
|
|
||||||
test-virgin-user:
|
test-virgin-user:
|
||||||
|
permissions:
|
||||||
|
contents: read
|
||||||
uses: ./.github/workflows/test-virgin-user.yml
|
uses: ./.github/workflows/test-virgin-user.yml
|
||||||
|
|
||||||
test-virgin-root:
|
test-virgin-root:
|
||||||
|
permissions:
|
||||||
|
contents: read
|
||||||
uses: ./.github/workflows/test-virgin-root.yml
|
uses: ./.github/workflows/test-virgin-root.yml
|
||||||
|
|
||||||
codesniffer-shellcheck:
|
lint-shell:
|
||||||
uses: ./.github/workflows/codesniffer-shellcheck.yml
|
permissions:
|
||||||
|
contents: read
|
||||||
|
uses: ./.github/workflows/lint-shell.yml
|
||||||
|
|
||||||
codesniffer-ruff:
|
lint-python:
|
||||||
uses: ./.github/workflows/codesniffer-ruff.yml
|
permissions:
|
||||||
|
contents: read
|
||||||
|
uses: ./.github/workflows/lint-python.yml
|
||||||
|
|
||||||
|
lint-docker:
|
||||||
|
permissions:
|
||||||
|
contents: read
|
||||||
|
security-events: write
|
||||||
|
uses: ./.github/workflows/lint-docker.yml
|
||||||
|
|||||||
40
.github/workflows/lint-docker.yml
vendored
Normal file
40
.github/workflows/lint-docker.yml
vendored
Normal file
@@ -0,0 +1,40 @@
|
|||||||
|
name: Docker Linter
|
||||||
|
|
||||||
|
on:
|
||||||
|
workflow_call:
|
||||||
|
|
||||||
|
permissions:
|
||||||
|
contents: read
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
lint-docker:
|
||||||
|
name: Lint Dockerfile
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
permissions:
|
||||||
|
contents: read
|
||||||
|
security-events: write
|
||||||
|
steps:
|
||||||
|
- name: Checkout code
|
||||||
|
uses: actions/checkout@v4
|
||||||
|
|
||||||
|
- name: Run hadolint (produce SARIF)
|
||||||
|
id: hadolint
|
||||||
|
continue-on-error: true
|
||||||
|
uses: hadolint/hadolint-action@2332a7b74a6de0dda2e2221d575162eba76ba5e5
|
||||||
|
with:
|
||||||
|
dockerfile: ./Dockerfile
|
||||||
|
format: sarif
|
||||||
|
output-file: hadolint-results.sarif
|
||||||
|
failure-threshold: warning
|
||||||
|
|
||||||
|
- name: Upload analysis results to GitHub
|
||||||
|
if: always()
|
||||||
|
uses: github/codeql-action/upload-sarif@v4
|
||||||
|
with:
|
||||||
|
sarif_file: hadolint-results.sarif
|
||||||
|
wait-for-processing: true
|
||||||
|
category: hadolint
|
||||||
|
|
||||||
|
- name: Fail if SARIF contains warnings or errors
|
||||||
|
if: always()
|
||||||
|
run: python3 src/pkgmgr/github/check_hadolint_sarif.py hadolint-results.sarif
|
||||||
@@ -3,8 +3,11 @@ name: Ruff (Python code sniffer)
|
|||||||
on:
|
on:
|
||||||
workflow_call:
|
workflow_call:
|
||||||
|
|
||||||
|
permissions:
|
||||||
|
contents: read
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
codesniffer-ruff:
|
lint-python:
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
|
|
||||||
steps:
|
steps:
|
||||||
@@ -3,8 +3,11 @@ name: ShellCheck
|
|||||||
on:
|
on:
|
||||||
workflow_call:
|
workflow_call:
|
||||||
|
|
||||||
|
permissions:
|
||||||
|
contents: read
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
codesniffer-shellcheck:
|
lint-shell:
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
- uses: actions/checkout@v4
|
- uses: actions/checkout@v4
|
||||||
113
.github/workflows/mark-stable.yml
vendored
113
.github/workflows/mark-stable.yml
vendored
@@ -1,110 +1,39 @@
|
|||||||
name: Mark stable commit
|
name: Mark stable commit
|
||||||
|
|
||||||
|
concurrency:
|
||||||
|
group: mark-stable-${{ github.repository }}-main
|
||||||
|
cancel-in-progress: true
|
||||||
|
|
||||||
on:
|
on:
|
||||||
push:
|
push:
|
||||||
branches:
|
|
||||||
- main # still run tests for main
|
|
||||||
tags:
|
tags:
|
||||||
- 'v*' # run tests for version tags (e.g. v0.9.1)
|
- 'v*'
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
test-unit:
|
|
||||||
uses: ./.github/workflows/test-unit.yml
|
|
||||||
|
|
||||||
test-integration:
|
|
||||||
uses: ./.github/workflows/test-integration.yml
|
|
||||||
|
|
||||||
test-env-virtual:
|
|
||||||
uses: ./.github/workflows/test-env-virtual.yml
|
|
||||||
|
|
||||||
test-env-nix:
|
|
||||||
uses: ./.github/workflows/test-env-nix.yml
|
|
||||||
|
|
||||||
test-e2e:
|
|
||||||
uses: ./.github/workflows/test-e2e.yml
|
|
||||||
|
|
||||||
test-virgin-user:
|
|
||||||
uses: ./.github/workflows/test-virgin-user.yml
|
|
||||||
|
|
||||||
test-virgin-root:
|
|
||||||
uses: ./.github/workflows/test-virgin-root.yml
|
|
||||||
|
|
||||||
codesniffer-shellcheck:
|
|
||||||
uses: ./.github/workflows/codesniffer-shellcheck.yml
|
|
||||||
|
|
||||||
codesniffer-ruff:
|
|
||||||
uses: ./.github/workflows/codesniffer-ruff.yml
|
|
||||||
|
|
||||||
mark-stable:
|
mark-stable:
|
||||||
needs:
|
|
||||||
- codesniffer-shellcheck
|
|
||||||
- codesniffer-ruff
|
|
||||||
- test-unit
|
|
||||||
- test-integration
|
|
||||||
- test-env-nix
|
|
||||||
- test-env-virtual
|
|
||||||
- test-e2e
|
|
||||||
- test-virgin-user
|
|
||||||
- test-virgin-root
|
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
|
timeout-minutes: 330
|
||||||
# Only run this job if the push is for a version tag (v*)
|
|
||||||
if: startsWith(github.ref, 'refs/tags/v')
|
|
||||||
|
|
||||||
permissions:
|
permissions:
|
||||||
contents: write # Required to move/update the tag
|
actions: read
|
||||||
|
contents: write
|
||||||
|
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout repository
|
- name: Checkout repository
|
||||||
uses: actions/checkout@v4
|
uses: actions/checkout@v4
|
||||||
with:
|
with:
|
||||||
fetch-depth: 0
|
fetch-depth: 0
|
||||||
fetch-tags: true # We need all tags for version comparison
|
fetch-tags: true # We need tags and main history for version comparison
|
||||||
|
|
||||||
|
- name: Check whether tagged commit is on main
|
||||||
|
id: branch-check
|
||||||
|
run: bash scripts/github/common/check-tagged-commit-on-main.sh
|
||||||
|
|
||||||
|
- name: Wait for CI success on main for this commit
|
||||||
|
if: steps.branch-check.outputs.is_on_main == 'true'
|
||||||
|
env:
|
||||||
|
GH_TOKEN: ${{ github.token }}
|
||||||
|
run: bash scripts/github/mark-stable/wait-for-main-ci-success.sh
|
||||||
|
|
||||||
- name: Move 'stable' tag only if this version is the highest
|
- name: Move 'stable' tag only if this version is the highest
|
||||||
run: |
|
if: steps.branch-check.outputs.is_on_main == 'true'
|
||||||
set -euo pipefail
|
run: bash scripts/github/mark-stable/mark-stable-if-highest-version.sh
|
||||||
|
|
||||||
git config user.name "github-actions[bot]"
|
|
||||||
git config user.email "github-actions[bot]@users.noreply.github.com"
|
|
||||||
|
|
||||||
echo "Ref: $GITHUB_REF"
|
|
||||||
echo "SHA: $GITHUB_SHA"
|
|
||||||
|
|
||||||
VERSION="${GITHUB_REF#refs/tags/}"
|
|
||||||
echo "Current version tag: ${VERSION}"
|
|
||||||
|
|
||||||
echo "Collecting all version tags..."
|
|
||||||
ALL_V_TAGS="$(git tag --list 'v*' || true)"
|
|
||||||
|
|
||||||
if [[ -z "${ALL_V_TAGS}" ]]; then
|
|
||||||
echo "No version tags found. Skipping stable update."
|
|
||||||
exit 0
|
|
||||||
fi
|
|
||||||
|
|
||||||
echo "All version tags:"
|
|
||||||
echo "${ALL_V_TAGS}"
|
|
||||||
|
|
||||||
# Determine highest version using natural version sorting
|
|
||||||
LATEST_TAG="$(printf '%s\n' ${ALL_V_TAGS} | sort -V | tail -n1)"
|
|
||||||
|
|
||||||
echo "Highest version tag: ${LATEST_TAG}"
|
|
||||||
|
|
||||||
if [[ "${VERSION}" != "${LATEST_TAG}" ]]; then
|
|
||||||
echo "Current version ${VERSION} is NOT the highest version."
|
|
||||||
echo "Stable tag will NOT be updated."
|
|
||||||
exit 0
|
|
||||||
fi
|
|
||||||
|
|
||||||
echo "Current version ${VERSION} IS the highest version."
|
|
||||||
echo "Updating 'stable' tag..."
|
|
||||||
|
|
||||||
# Delete existing stable tag (local + remote)
|
|
||||||
git tag -d stable 2>/dev/null || true
|
|
||||||
git push origin :refs/tags/stable || true
|
|
||||||
|
|
||||||
# Create new stable tag
|
|
||||||
git tag stable "$GITHUB_SHA"
|
|
||||||
git push origin stable
|
|
||||||
|
|
||||||
echo "✅ Stable tag updated to ${VERSION}."
|
|
||||||
|
|||||||
49
.github/workflows/publish-containers.yml
vendored
49
.github/workflows/publish-containers.yml
vendored
@@ -19,48 +19,41 @@ jobs:
|
|||||||
uses: actions/checkout@v4
|
uses: actions/checkout@v4
|
||||||
with:
|
with:
|
||||||
fetch-depth: 0
|
fetch-depth: 0
|
||||||
fetch-tags: true
|
|
||||||
|
|
||||||
- name: Checkout workflow_run commit and refresh tags
|
- name: Checkout workflow_run commit and refresh tags
|
||||||
run: |
|
env:
|
||||||
set -euo pipefail
|
WORKFLOW_RUN_SHA: ${{ github.event.workflow_run.head_sha }}
|
||||||
git checkout -f "${{ github.event.workflow_run.head_sha }}"
|
run: bash scripts/github/publish-containers/checkout-workflow-run-commit.sh
|
||||||
git fetch --tags --force
|
|
||||||
git tag --list 'stable' 'v*' --sort=version:refname | tail -n 20
|
- name: Check whether tagged commit is on main
|
||||||
|
id: branch-check
|
||||||
|
env:
|
||||||
|
TARGET_SHA: ${{ github.event.workflow_run.head_sha }}
|
||||||
|
run: bash scripts/github/common/check-tagged-commit-on-main.sh
|
||||||
|
|
||||||
- name: Compute version and stable flag
|
- name: Compute version and stable flag
|
||||||
id: info
|
id: info
|
||||||
run: |
|
if: steps.branch-check.outputs.is_on_main == 'true'
|
||||||
set -euo pipefail
|
run: bash scripts/github/publish-containers/compute-publish-container-info.sh
|
||||||
SHA="$(git rev-parse HEAD)"
|
|
||||||
|
|
||||||
V_TAG="$(git tag --points-at "${SHA}" --list 'v*' | sort -V | tail -n1)"
|
|
||||||
[[ -n "$V_TAG" ]] || { echo "No version tag found"; exit 1; }
|
|
||||||
VERSION="${V_TAG#v}"
|
|
||||||
|
|
||||||
STABLE_SHA="$(git rev-parse -q --verify refs/tags/stable^{commit} 2>/dev/null || true)"
|
|
||||||
IS_STABLE=false
|
|
||||||
[[ -n "${STABLE_SHA}" && "${STABLE_SHA}" == "${SHA}" ]] && IS_STABLE=true
|
|
||||||
|
|
||||||
echo "version=${VERSION}" >> "$GITHUB_OUTPUT"
|
|
||||||
echo "is_stable=${IS_STABLE}" >> "$GITHUB_OUTPUT"
|
|
||||||
|
|
||||||
- name: Set up Docker Buildx
|
- name: Set up Docker Buildx
|
||||||
uses: docker/setup-buildx-action@v3
|
if: ${{ steps.info.outputs.should_publish == 'true' }}
|
||||||
|
uses: docker/setup-buildx-action@8d2750c68a42422c14e847fe6c8ac0403b4cbd6f
|
||||||
with:
|
with:
|
||||||
use: true
|
use: true
|
||||||
|
|
||||||
- name: Login to GHCR
|
- name: Login to GHCR
|
||||||
uses: docker/login-action@v3
|
if: ${{ steps.info.outputs.should_publish == 'true' }}
|
||||||
|
uses: docker/login-action@c94ce9fb468520275223c153574b00df6fe4bcc9
|
||||||
with:
|
with:
|
||||||
registry: ghcr.io
|
registry: ghcr.io
|
||||||
username: ${{ github.actor }}
|
username: ${{ github.actor }}
|
||||||
password: ${{ secrets.GITHUB_TOKEN }}
|
password: ${{ secrets.GITHUB_TOKEN }}
|
||||||
|
|
||||||
- name: Publish all images
|
- name: Publish all images
|
||||||
run: |
|
if: ${{ steps.info.outputs.should_publish == 'true' }}
|
||||||
set -euo pipefail
|
env:
|
||||||
OWNER="${{ github.repository_owner }}" \
|
OWNER: ${{ github.repository_owner }}
|
||||||
VERSION="${{ steps.info.outputs.version }}" \
|
VERSION: ${{ steps.info.outputs.version }}
|
||||||
IS_STABLE="${{ steps.info.outputs.is_stable }}" \
|
IS_STABLE: ${{ steps.info.outputs.is_stable }}
|
||||||
bash scripts/build/publish.sh
|
run: bash scripts/github/publish-containers/publish-container-images.sh
|
||||||
|
|||||||
47
.github/workflows/security-codeql.yml
vendored
Normal file
47
.github/workflows/security-codeql.yml
vendored
Normal file
@@ -0,0 +1,47 @@
|
|||||||
|
name: CodeQL Advanced
|
||||||
|
|
||||||
|
on:
|
||||||
|
workflow_call:
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
analyze:
|
||||||
|
name: Check security
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
permissions:
|
||||||
|
security-events: write
|
||||||
|
packages: read
|
||||||
|
contents: read
|
||||||
|
|
||||||
|
strategy:
|
||||||
|
fail-fast: false
|
||||||
|
matrix:
|
||||||
|
include:
|
||||||
|
- language: actions
|
||||||
|
build-mode: none
|
||||||
|
- language: python
|
||||||
|
build-mode: none
|
||||||
|
|
||||||
|
steps:
|
||||||
|
- name: Checkout repository
|
||||||
|
uses: actions/checkout@v4
|
||||||
|
|
||||||
|
- name: Initialize CodeQL
|
||||||
|
uses: github/codeql-action/init@v4
|
||||||
|
with:
|
||||||
|
languages: ${{ matrix.language }}
|
||||||
|
build-mode: ${{ matrix.build-mode }}
|
||||||
|
queries: security-extended,security-and-quality
|
||||||
|
|
||||||
|
- name: Run manual build steps
|
||||||
|
if: matrix.build-mode == 'manual'
|
||||||
|
shell: bash
|
||||||
|
run: |
|
||||||
|
echo 'If you are using a "manual" build mode for one or more of the' \
|
||||||
|
'languages you are analyzing, replace this with the commands to build' \
|
||||||
|
'your code.'
|
||||||
|
exit 1
|
||||||
|
|
||||||
|
- name: Perform CodeQL Analysis
|
||||||
|
uses: github/codeql-action/analyze@v4
|
||||||
|
with:
|
||||||
|
category: "/language:${{ matrix.language }}"
|
||||||
7
.github/workflows/test-e2e.yml
vendored
7
.github/workflows/test-e2e.yml
vendored
@@ -3,6 +3,9 @@ name: Test End-To-End
|
|||||||
on:
|
on:
|
||||||
workflow_call:
|
workflow_call:
|
||||||
|
|
||||||
|
permissions:
|
||||||
|
contents: read
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
test-e2e:
|
test-e2e:
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
@@ -11,7 +14,9 @@ jobs:
|
|||||||
fail-fast: false
|
fail-fast: false
|
||||||
matrix:
|
matrix:
|
||||||
distro: [arch, debian, ubuntu, fedora, centos]
|
distro: [arch, debian, ubuntu, fedora, centos]
|
||||||
|
env:
|
||||||
|
NIX_CONFIG: |
|
||||||
|
access-tokens = github.com=${{ secrets.GITHUB_TOKEN }}
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout repository
|
- name: Checkout repository
|
||||||
uses: actions/checkout@v4
|
uses: actions/checkout@v4
|
||||||
|
|||||||
7
.github/workflows/test-env-nix.yml
vendored
7
.github/workflows/test-env-nix.yml
vendored
@@ -3,6 +3,9 @@ name: Test Virgin Nix (flake only)
|
|||||||
on:
|
on:
|
||||||
workflow_call:
|
workflow_call:
|
||||||
|
|
||||||
|
permissions:
|
||||||
|
contents: read
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
test-env-nix:
|
test-env-nix:
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
@@ -12,7 +15,9 @@ jobs:
|
|||||||
fail-fast: false
|
fail-fast: false
|
||||||
matrix:
|
matrix:
|
||||||
distro: [arch, debian, ubuntu, fedora, centos]
|
distro: [arch, debian, ubuntu, fedora, centos]
|
||||||
|
env:
|
||||||
|
NIX_CONFIG: |
|
||||||
|
access-tokens = github.com=${{ secrets.GITHUB_TOKEN }}
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout repository
|
- name: Checkout repository
|
||||||
uses: actions/checkout@v4
|
uses: actions/checkout@v4
|
||||||
|
|||||||
7
.github/workflows/test-env-virtual.yml
vendored
7
.github/workflows/test-env-virtual.yml
vendored
@@ -3,6 +3,9 @@ name: Test OS Containers
|
|||||||
on:
|
on:
|
||||||
workflow_call:
|
workflow_call:
|
||||||
|
|
||||||
|
permissions:
|
||||||
|
contents: read
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
test-env-virtual:
|
test-env-virtual:
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
@@ -11,7 +14,9 @@ jobs:
|
|||||||
fail-fast: false
|
fail-fast: false
|
||||||
matrix:
|
matrix:
|
||||||
distro: [arch, debian, ubuntu, fedora, centos]
|
distro: [arch, debian, ubuntu, fedora, centos]
|
||||||
|
env:
|
||||||
|
NIX_CONFIG: |
|
||||||
|
access-tokens = github.com=${{ secrets.GITHUB_TOKEN }}
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout repository
|
- name: Checkout repository
|
||||||
uses: actions/checkout@v4
|
uses: actions/checkout@v4
|
||||||
|
|||||||
7
.github/workflows/test-integration.yml
vendored
7
.github/workflows/test-integration.yml
vendored
@@ -3,11 +3,16 @@ name: Test Code Integration
|
|||||||
on:
|
on:
|
||||||
workflow_call:
|
workflow_call:
|
||||||
|
|
||||||
|
permissions:
|
||||||
|
contents: read
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
test-integration:
|
test-integration:
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
timeout-minutes: 30
|
timeout-minutes: 30
|
||||||
|
env:
|
||||||
|
NIX_CONFIG: |
|
||||||
|
access-tokens = github.com=${{ secrets.GITHUB_TOKEN }}
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout repository
|
- name: Checkout repository
|
||||||
uses: actions/checkout@v4
|
uses: actions/checkout@v4
|
||||||
|
|||||||
7
.github/workflows/test-unit.yml
vendored
7
.github/workflows/test-unit.yml
vendored
@@ -3,11 +3,16 @@ name: Test Units
|
|||||||
on:
|
on:
|
||||||
workflow_call:
|
workflow_call:
|
||||||
|
|
||||||
|
permissions:
|
||||||
|
contents: read
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
test-unit:
|
test-unit:
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
timeout-minutes: 30
|
timeout-minutes: 30
|
||||||
|
env:
|
||||||
|
NIX_CONFIG: |
|
||||||
|
access-tokens = github.com=${{ secrets.GITHUB_TOKEN }}
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout repository
|
- name: Checkout repository
|
||||||
uses: actions/checkout@v4
|
uses: actions/checkout@v4
|
||||||
|
|||||||
18
.github/workflows/test-virgin-root.yml
vendored
18
.github/workflows/test-virgin-root.yml
vendored
@@ -3,6 +3,9 @@ name: Test Virgin Root
|
|||||||
on:
|
on:
|
||||||
workflow_call:
|
workflow_call:
|
||||||
|
|
||||||
|
permissions:
|
||||||
|
contents: read
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
test-virgin-root:
|
test-virgin-root:
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
@@ -11,7 +14,9 @@ jobs:
|
|||||||
fail-fast: false
|
fail-fast: false
|
||||||
matrix:
|
matrix:
|
||||||
distro: [arch, debian, ubuntu, fedora, centos]
|
distro: [arch, debian, ubuntu, fedora, centos]
|
||||||
|
env:
|
||||||
|
NIX_CONFIG: |
|
||||||
|
access-tokens = github.com=${{ secrets.GITHUB_TOKEN }}
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout repository
|
- name: Checkout repository
|
||||||
uses: actions/checkout@v4
|
uses: actions/checkout@v4
|
||||||
@@ -19,27 +24,26 @@ jobs:
|
|||||||
- name: Show Docker version
|
- name: Show Docker version
|
||||||
run: docker version
|
run: docker version
|
||||||
|
|
||||||
# 🔹 BUILD virgin image if missing
|
|
||||||
- name: Build virgin container (${{ matrix.distro }})
|
- name: Build virgin container (${{ matrix.distro }})
|
||||||
run: |
|
run: |
|
||||||
set -euo pipefail
|
set -euo pipefail
|
||||||
PKGMGR_DISTRO="${{ matrix.distro }}" make build-missing-virgin
|
PKGMGR_DISTRO="${{ matrix.distro }}" make build-missing-virgin
|
||||||
|
|
||||||
# 🔹 RUN test inside virgin image
|
|
||||||
- name: Virgin ${{ matrix.distro }} pkgmgr test (root)
|
- name: Virgin ${{ matrix.distro }} pkgmgr test (root)
|
||||||
run: |
|
run: |
|
||||||
set -euo pipefail
|
set -euo pipefail
|
||||||
|
|
||||||
docker run --rm \
|
docker run --rm \
|
||||||
-v "$PWD":/src \
|
-v "$PWD":/opt/src/pkgmgr \
|
||||||
-v pkgmgr_repos:/root/Repositories \
|
-v pkgmgr_repos:/root/Repositories \
|
||||||
-v pkgmgr_pip_cache:/root/.cache/pip \
|
-v pkgmgr_pip_cache:/root/.cache/pip \
|
||||||
-w /src \
|
-e NIX_CONFIG="${NIX_CONFIG}" \
|
||||||
|
-w /opt/src/pkgmgr \
|
||||||
"pkgmgr-${{ matrix.distro }}-virgin" \
|
"pkgmgr-${{ matrix.distro }}-virgin" \
|
||||||
bash -lc '
|
bash -lc '
|
||||||
set -euo pipefail
|
set -euo pipefail
|
||||||
|
|
||||||
git config --global --add safe.directory /src
|
git config --global --add safe.directory /opt/src/pkgmgr
|
||||||
|
|
||||||
make install
|
make install
|
||||||
make setup
|
make setup
|
||||||
@@ -50,5 +54,5 @@ jobs:
|
|||||||
pkgmgr version pkgmgr
|
pkgmgr version pkgmgr
|
||||||
|
|
||||||
echo ">>> Running Nix-based: nix run .#pkgmgr -- version pkgmgr"
|
echo ">>> Running Nix-based: nix run .#pkgmgr -- version pkgmgr"
|
||||||
nix run /src#pkgmgr -- version pkgmgr
|
nix run /opt/src/pkgmgr#pkgmgr -- version pkgmgr
|
||||||
'
|
'
|
||||||
|
|||||||
28
.github/workflows/test-virgin-user.yml
vendored
28
.github/workflows/test-virgin-user.yml
vendored
@@ -3,6 +3,9 @@ name: Test Virgin User
|
|||||||
on:
|
on:
|
||||||
workflow_call:
|
workflow_call:
|
||||||
|
|
||||||
|
permissions:
|
||||||
|
contents: read
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
test-virgin-user:
|
test-virgin-user:
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
@@ -11,7 +14,9 @@ jobs:
|
|||||||
fail-fast: false
|
fail-fast: false
|
||||||
matrix:
|
matrix:
|
||||||
distro: [arch, debian, ubuntu, fedora, centos]
|
distro: [arch, debian, ubuntu, fedora, centos]
|
||||||
|
env:
|
||||||
|
NIX_CONFIG: |
|
||||||
|
access-tokens = github.com=${{ secrets.GITHUB_TOKEN }}
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout repository
|
- name: Checkout repository
|
||||||
uses: actions/checkout@v4
|
uses: actions/checkout@v4
|
||||||
@@ -19,20 +24,19 @@ jobs:
|
|||||||
- name: Show Docker version
|
- name: Show Docker version
|
||||||
run: docker version
|
run: docker version
|
||||||
|
|
||||||
# 🔹 BUILD virgin image if missing
|
|
||||||
- name: Build virgin container (${{ matrix.distro }})
|
- name: Build virgin container (${{ matrix.distro }})
|
||||||
run: |
|
run: |
|
||||||
set -euo pipefail
|
set -euo pipefail
|
||||||
PKGMGR_DISTRO="${{ matrix.distro }}" make build-missing-virgin
|
PKGMGR_DISTRO="${{ matrix.distro }}" make build-missing-virgin
|
||||||
|
|
||||||
# 🔹 RUN test inside virgin image as non-root
|
|
||||||
- name: Virgin ${{ matrix.distro }} pkgmgr test (user)
|
- name: Virgin ${{ matrix.distro }} pkgmgr test (user)
|
||||||
run: |
|
run: |
|
||||||
set -euo pipefail
|
set -euo pipefail
|
||||||
|
|
||||||
docker run --rm \
|
docker run --rm \
|
||||||
-v "$PWD":/src \
|
-v "$PWD":/opt/src/pkgmgr \
|
||||||
-w /src \
|
-e NIX_CONFIG="${NIX_CONFIG}" \
|
||||||
|
-w /opt/src/pkgmgr \
|
||||||
"pkgmgr-${{ matrix.distro }}-virgin" \
|
"pkgmgr-${{ matrix.distro }}-virgin" \
|
||||||
bash -lc '
|
bash -lc '
|
||||||
set -euo pipefail
|
set -euo pipefail
|
||||||
@@ -42,23 +46,25 @@ jobs:
|
|||||||
useradd -m dev
|
useradd -m dev
|
||||||
echo "dev ALL=(ALL) NOPASSWD: ALL" > /etc/sudoers.d/dev
|
echo "dev ALL=(ALL) NOPASSWD: ALL" > /etc/sudoers.d/dev
|
||||||
chmod 0440 /etc/sudoers.d/dev
|
chmod 0440 /etc/sudoers.d/dev
|
||||||
chown -R dev:dev /src
|
chown -R dev:dev /opt/src/pkgmgr
|
||||||
|
|
||||||
mkdir -p /nix/store /nix/var/nix /nix/var/log/nix /nix/var/nix/profiles
|
mkdir -p /nix/store /nix/var/nix /nix/var/log/nix /nix/var/nix/profiles
|
||||||
chown -R dev:dev /nix
|
chown -R dev:dev /nix
|
||||||
chmod 0755 /nix
|
chmod 0755 /nix
|
||||||
chmod 1777 /nix/store
|
chmod 1777 /nix/store
|
||||||
|
sudo -H -u dev env \
|
||||||
sudo -H -u dev env HOME=/home/dev PKGMGR_DISABLE_NIX_FLAKE_INSTALLER=1 bash -lc "
|
HOME=/home/dev \
|
||||||
|
NIX_CONFIG="$NIX_CONFIG" \
|
||||||
|
PKGMGR_DISABLE_NIX_FLAKE_INSTALLER=1 \
|
||||||
|
bash -lc "
|
||||||
set -euo pipefail
|
set -euo pipefail
|
||||||
cd /src
|
cd /opt/src/pkgmgr
|
||||||
|
|
||||||
make setup-venv
|
make setup-venv
|
||||||
. \"\$HOME/.venvs/pkgmgr/bin/activate\"
|
. \"\$HOME/.venvs/pkgmgr/bin/activate\"
|
||||||
|
|
||||||
pkgmgr version pkgmgr
|
pkgmgr version pkgmgr
|
||||||
|
|
||||||
export NIX_REMOTE=local
|
export NIX_REMOTE=local
|
||||||
nix run /src#pkgmgr -- version pkgmgr
|
nix run /opt/src/pkgmgr#pkgmgr -- version pkgmgr
|
||||||
"
|
"
|
||||||
'
|
'
|
||||||
|
|||||||
3
.gitignore
vendored
3
.gitignore
vendored
@@ -24,10 +24,9 @@ package-manager-*
|
|||||||
.DS_Store
|
.DS_Store
|
||||||
Thumbs.db
|
Thumbs.db
|
||||||
|
|
||||||
# Nix Cache to speed up tests
|
# Nix cache to speed up tests
|
||||||
.nix/
|
.nix/
|
||||||
.nix-dev-installed
|
.nix-dev-installed
|
||||||
flake.lock
|
|
||||||
|
|
||||||
# Ignore logs
|
# Ignore logs
|
||||||
*.log
|
*.log
|
||||||
|
|||||||
293
CHANGELOG.md
293
CHANGELOG.md
@@ -1,3 +1,296 @@
|
|||||||
|
# Changelog
|
||||||
|
|
||||||
|
## [1.16.0] - 2026-06-28
|
||||||
|
|
||||||
|
* New *code-scanning* command: *pkgmgr code-scanning* downloads a repository's GitHub code scanning alerts and analysis metadata via the *gh* CLI into a timestamped directory (default */tmp/<repo>/code-scanner/<timestamp>*), together with a readable summary, for offline analysis.
|
||||||
|
* The release flow now lints and normalises the changelog message before writing it: a leading heading becomes bold, inline code becomes italic, and the entry is validated against the repository's markdown rules, re-prompting interactively until it is clean.
|
||||||
|
* The Debian changelog and the RPM *%changelog* now mirror the full multi-line message correctly — every change line is indented or dash-prefixed — fixing a package build failure where un-indented bodies broke *dpkg-buildpackage* and *rpmspec*; the changelog entry no longer gains an auto-inserted leading bullet.
|
||||||
|
|
||||||
|
## [1.15.2] - 2026-05-28
|
||||||
|
|
||||||
|
* Restore `infinito` as an alias for the infinito-nexus/core repository so `pkgmgr install infinito` (and friends) resolves again.
|
||||||
|
|
||||||
|
## [1.15.1] - 2026-05-28
|
||||||
|
|
||||||
|
* Insert pkgmgr release changelog entry under the H1 instead of above it. Fixes the markdownlint MD041 (first-line-h1) and MD012 (no-multiple-blanks) regressions that previously trashed every CHANGELOG.md after a release.
|
||||||
|
|
||||||
|
## [1.15.0] - 2026-05-28
|
||||||
|
|
||||||
|
* Add pkgmgr archive subcommand: promote fully-checked NNN-topic.md spec files into the directorys README Archive section and delete the source files. Lookup pattern, README path, and template handling are configurable. Extracted from infinito-nexus-core so every kpmx-managed repo gets the same archival flow.
|
||||||
|
|
||||||
|
|
||||||
|
## [1.14.0] - 2026-05-27
|
||||||
|
|
||||||
|
* Added
|
||||||
|
|
||||||
|
* New release --retry mode re-deploys the HEAD release without
|
||||||
|
re-tagging or modifying any files. It re-pushes the existing version
|
||||||
|
tag, re-aligns the floating latest tag, and (unless --no-publish)
|
||||||
|
re-runs publish. Use this to recover from a release whose post-tag
|
||||||
|
push or PyPI upload failed mid-flight. The release_type argument
|
||||||
|
becomes optional under --retry.
|
||||||
|
* New module pkgmgr.actions.release.retry hosts the retry_release
|
||||||
|
helper so the workflow orchestrator stays focused on the forward
|
||||||
|
path.
|
||||||
|
* RepoPaths now exposes a debian_control slot, discovered alongside
|
||||||
|
debian_changelog under both packaging/debian and the legacy debian
|
||||||
|
layout.
|
||||||
|
* pkgmgr.actions.release.package_name.resolve_package_name centralises
|
||||||
|
the distro-name lookup chain and is unit-tested under
|
||||||
|
tests/unit/pkgmgr/actions/release/test_package_name.py.
|
||||||
|
* tests/unit/pkgmgr/actions/release/test_retry.py covers routing,
|
||||||
|
idempotent push, latest-tag re-alignment, missing-tag error path,
|
||||||
|
and branch-detection fallback.
|
||||||
|
|
||||||
|
Changed
|
||||||
|
|
||||||
|
* pkgmgr release now derives the distro-package name from existing
|
||||||
|
packaging metadata instead of the repository folder name. The lookup
|
||||||
|
order is packaging/debian/control Package field, then
|
||||||
|
packaging/arch/PKGBUILD pkgname value, then RPM spec Name field,
|
||||||
|
then folder basename as legacy fallback. Renaming a repository
|
||||||
|
folder no longer silently flips the debian/changelog top entry and
|
||||||
|
the RPM changelog stanza to a new identifier. Those keep matching
|
||||||
|
the authoritative value in the packaging files, which is what apt,
|
||||||
|
pacman, and dnf index against.
|
||||||
|
|
||||||
|
Fixed
|
||||||
|
|
||||||
|
* dpkg-source --before-build no longer fails with the message about
|
||||||
|
source package having two conflicting values after a repo-folder
|
||||||
|
rename, because the changelog and control file stay in agreement
|
||||||
|
on the next release.
|
||||||
|
|
||||||
|
|
||||||
|
## [1.13.4] - 2026-05-27
|
||||||
|
|
||||||
|
* Changed
|
||||||
|
|
||||||
|
* pkgmgr release now derives the distro-package name from existing
|
||||||
|
packaging metadata instead of the repository folder name. The lookup
|
||||||
|
order is packaging/debian/control Package field, then
|
||||||
|
packaging/arch/PKGBUILD pkgname value, then RPM spec Name field, then
|
||||||
|
folder basename as legacy fallback. Renaming a repository folder (for
|
||||||
|
example infinito-nexus to infinito-nexus-core) no longer silently
|
||||||
|
flips the debian/changelog top entry and the RPM changelog stanza to
|
||||||
|
a new identifier. Those keep matching the authoritative Package,
|
||||||
|
pkgname, or Name value in the packaging files, which is what apt,
|
||||||
|
pacman, and dnf index against.
|
||||||
|
|
||||||
|
Added
|
||||||
|
|
||||||
|
* RepoPaths gains a debian_control slot that is discovered alongside
|
||||||
|
debian_changelog under both packaging/debian (new layout) and debian
|
||||||
|
(legacy layout).
|
||||||
|
* pkgmgr.actions.release.package_name.resolve_package_name centralises
|
||||||
|
the priority chain and is unit-tested under
|
||||||
|
tests/unit/pkgmgr/actions/release/test_package_name.py.
|
||||||
|
|
||||||
|
Fixed
|
||||||
|
|
||||||
|
* dpkg-source --before-build no longer fails with the message about
|
||||||
|
source package having two conflicting values after a repo-folder
|
||||||
|
rename, because the changelog and control file stay in agreement.
|
||||||
|
|
||||||
|
|
||||||
|
## [1.13.3] - 2026-03-26
|
||||||
|
|
||||||
|
* CI pipelines now include automated security scanning (CodeQL, Docker lint), increasing detection of vulnerabilities and misconfigurations
|
||||||
|
* Workflow permissions were tightened and fixed, ensuring secure and reliable execution of reusable workflows
|
||||||
|
* Publishing and “stable” tagging are now restricted to the `main` branch, preventing accidental releases from other branches
|
||||||
|
* Stale CI runs are automatically cancelled, reducing wasted resources and speeding up feedback cycles
|
||||||
|
* Overall CI reliability and security posture improved, with fewer false positives and more consistent pipeline results
|
||||||
|
|
||||||
|
|
||||||
|
## [1.13.2] - 2026-03-26
|
||||||
|
|
||||||
|
* Fail fast with a clear error when the Nix bootstrap or nix binary is unavailable instead of continuing with a broken startup path.
|
||||||
|
|
||||||
|
|
||||||
|
## [1.13.1] - 2026-03-20
|
||||||
|
|
||||||
|
* Fixed misleading GPG verification failures by adding explicit git and gnupg runtime dependencies and surfacing signing-key lookup errors accurately.
|
||||||
|
|
||||||
|
|
||||||
|
## [1.13.0] - 2026-03-20
|
||||||
|
|
||||||
|
* Set CentOS docker image to latest
|
||||||
|
|
||||||
|
|
||||||
|
## [1.12.5] - 2026-02-24
|
||||||
|
|
||||||
|
* The stable-tag workflow now waits up to two hours for a successful main-branch CI run on the same commit before updating stable.
|
||||||
|
|
||||||
|
|
||||||
|
## [1.12.4] - 2026-02-24
|
||||||
|
|
||||||
|
* The release pipeline now updates the stable tag only for v* tags after a successful CI run on main for the same commit, while avoiding duplicate test executions.
|
||||||
|
|
||||||
|
|
||||||
|
## [1.12.3] - 2026-02-24
|
||||||
|
|
||||||
|
* Stabilized Nix-based builds by switching to nixos-25.11 and committing flake.lock, ensuring reproducible pkgmgr test/runtime environments (with pip) and avoiding transient sphinx/Python 3.11 breakage.
|
||||||
|
|
||||||
|
|
||||||
|
## [1.12.2] - 2026-02-24
|
||||||
|
|
||||||
|
* Removed infinito-sphinx package
|
||||||
|
|
||||||
|
|
||||||
|
## [1.12.1] - 2026-02-14
|
||||||
|
|
||||||
|
* pkgmgr now prefers distro-managed nix binaries on Arch before profile/PATH resolution, preventing libllhttp mismatch failures after pacman system upgrades.
|
||||||
|
|
||||||
|
|
||||||
|
## [1.12.0] - 2026-02-08
|
||||||
|
|
||||||
|
* Adds explicit concurrency groups to the CI and mark-stable workflows to prevent overlapping runs on the same branch and make pipeline execution more predictable.
|
||||||
|
|
||||||
|
|
||||||
|
## [1.11.2] - 2026-02-08
|
||||||
|
|
||||||
|
* Removes the v* tag trigger from the mark-stable workflow so it runs only on branch pushes and avoids duplicate executions during releases.
|
||||||
|
|
||||||
|
|
||||||
|
## [1.11.1] - 2026-02-08
|
||||||
|
|
||||||
|
* Implements pushing the branch and the version tag together in a single command so the CI release workflow can reliably detect the version tag on HEAD.
|
||||||
|
|
||||||
|
|
||||||
|
## [1.11.0] - 2026-01-21
|
||||||
|
|
||||||
|
* Adds a dedicated slim Docker image for pkgmgr and publishes slim variants for all supported distros.
|
||||||
|
|
||||||
|
|
||||||
|
## [1.10.0] - 2026-01-20
|
||||||
|
|
||||||
|
* Introduce safe verbose image cleanup to reduce Docker image size and build artifacts
|
||||||
|
|
||||||
|
## [1.9.5] - 2026-01-16
|
||||||
|
|
||||||
|
* Release patch: improve git pull error diagnostics
|
||||||
|
|
||||||
|
|
||||||
|
## [1.9.4] - 2026-01-13
|
||||||
|
|
||||||
|
* fix(ci): replace sudo with su for user switching to avoid PAM failures in minimal container images
|
||||||
|
|
||||||
|
|
||||||
|
## [1.9.3] - 2026-01-07
|
||||||
|
|
||||||
|
* Made the Nix dependency optional on non-x86_64 architectures to avoid broken Arch Linux ARM repository packages.
|
||||||
|
|
||||||
|
|
||||||
|
## [1.9.2] - 2025-12-21
|
||||||
|
|
||||||
|
* Default configuration files are now packaged and loaded correctly when no user config exists, while fully preserving custom user configurations.
|
||||||
|
|
||||||
|
|
||||||
|
## [1.9.1] - 2025-12-21
|
||||||
|
|
||||||
|
* Fixed installation issues and improved loading of default configuration files.
|
||||||
|
|
||||||
|
|
||||||
|
## [1.9.0] - 2025-12-20
|
||||||
|
|
||||||
|
* * New ***mirror visibility*** command to set remote Git repositories to ***public*** or ***private***.
|
||||||
|
* New ***--public*** flag for ***mirror provision*** to create repositories and immediately make them public.
|
||||||
|
* All configured git mirrors are now provisioned.
|
||||||
|
|
||||||
|
|
||||||
|
## [1.8.7] - 2025-12-19
|
||||||
|
|
||||||
|
* * **Release version updates now correctly modify ***pyproject.toml*** files that follow PEP 621**, ensuring the ***[project].version*** field is updated as expected.
|
||||||
|
* **Invalid or incomplete ***pyproject.toml*** files are now handled gracefully** with clear error messages instead of abrupt process termination.
|
||||||
|
* **RPM spec files remain compatible during releases**: existing macros such as ***%{?dist}*** are preserved and no longer accidentally modified.
|
||||||
|
|
||||||
|
|
||||||
|
## [1.8.6] - 2025-12-17
|
||||||
|
|
||||||
|
* Prevent Rate Limits during GitHub Nix Setups
|
||||||
|
|
||||||
|
|
||||||
|
## [1.8.5] - 2025-12-17
|
||||||
|
|
||||||
|
* * Clearer Git error handling, especially when a directory is not a Git repository.
|
||||||
|
* More reliable repository verification with improved commit and GPG signature checks.
|
||||||
|
* Better error messages and overall robustness when working with Git-based workflows.
|
||||||
|
|
||||||
|
|
||||||
|
## [1.9.0] - 2025-12-17
|
||||||
|
|
||||||
|
* Automated release.
|
||||||
|
|
||||||
|
|
||||||
|
## [1.8.4] - 2025-12-17
|
||||||
|
|
||||||
|
* * Made pkgmgr’s base-layer role explicit by standardizing the Docker/CI mount path to *`/opt/src/pkgmgr`*.
|
||||||
|
|
||||||
|
|
||||||
|
## [1.8.3] - 2025-12-16
|
||||||
|
|
||||||
|
* MIRRORS now supports plain URL entries, ensuring metadata-only sources like PyPI are recorded without ever being added to the Git configuration.
|
||||||
|
|
||||||
|
|
||||||
|
## [1.8.2] - 2025-12-16
|
||||||
|
|
||||||
|
* * ***pkgmgr tools code*** is more robust and predictable: it now fails early with clear errors if VS Code is not installed or a repository is not yet identified.
|
||||||
|
|
||||||
|
|
||||||
|
## [1.8.1] - 2025-12-16
|
||||||
|
|
||||||
|
* * Improved stability and consistency of all Git operations (clone, pull, push, release, branch handling) with clearer error messages and predictable preview behavior.
|
||||||
|
* Mirrors are now handled cleanly: only valid Git remotes are used for Git operations, while non-Git URLs (e.g. PyPI) are excluded, preventing broken or confusing repository configs.
|
||||||
|
* GitHub authentication is more robust: tokens are automatically resolved via the GitHub CLI (`gh`), invalid stored tokens are replaced, and interactive prompts occur only when necessary.
|
||||||
|
* Repository creation and release workflows are more reliable, producing cleaner Git configurations and more predictable version handling.
|
||||||
|
|
||||||
|
|
||||||
|
## [1.8.0] - 2025-12-15
|
||||||
|
|
||||||
|
* *** New Features: ***
|
||||||
|
- **Silent Updates**: You can now use the `--silent` flag during installs and updates to suppress error messages for individual repositories and get a single summary at the end. This ensures the process continues even if some repositories fail, while still preserving interactive checks when not in silent mode.
|
||||||
|
- **Repository Scaffolding**: The process for creating new repositories has been improved. You can now use templates to scaffold repositories with a preview and automatic mirror setup.
|
||||||
|
|
||||||
|
*** Bug Fixes: ***
|
||||||
|
- **Pip Installation**: Pip is now installed automatically on all supported systems. This includes `python-pip` for Arch and `python3-pip` for CentOS, Debian, Fedora, and Ubuntu, ensuring that pip is available for Python package installations.
|
||||||
|
- **Pacman Keyring**: Fixed an issue on Arch Linux where package installation would fail due to missing keys. The pacman keyring is now properly initialized before installing packages.
|
||||||
|
|
||||||
|
|
||||||
|
## [1.7.2] - 2025-12-15
|
||||||
|
|
||||||
|
* * Git mirrors are now resolved consistently (origin → MIRRORS file → config → default).
|
||||||
|
* The `origin` remote is always enforced to use the primary URL for both fetch and push.
|
||||||
|
* Additional mirrors are added as extra push targets without duplication.
|
||||||
|
* Local and remote mirror setup behaves more predictably and consistently.
|
||||||
|
* Improved test coverage ensures stable origin and push URL handling.
|
||||||
|
|
||||||
|
|
||||||
|
## [1.7.1] - 2025-12-14
|
||||||
|
|
||||||
|
* Patched package-manager to kpmx to publish on pypi
|
||||||
|
|
||||||
|
|
||||||
|
## [1.7.0] - 2025-12-14
|
||||||
|
|
||||||
|
* * New *pkgmgr publish* command to publish repository artifacts to PyPI based on the *MIRRORS* file.
|
||||||
|
* Automatically selects the current repository when no explicit selection is given.
|
||||||
|
* Publishes only when a semantic version tag is present on *HEAD*; otherwise skips with a clear info message.
|
||||||
|
* Supports non-interactive mode for CI environments via *--non-interactive*.
|
||||||
|
|
||||||
|
|
||||||
|
## [1.6.4] - 2025-12-14
|
||||||
|
|
||||||
|
* * Improved reliability of Nix installs and updates, including automatic resolution of profile conflicts and better handling of GitHub 403 rate limits.
|
||||||
|
* More stable launcher behavior in packaged and virtual-env setups.
|
||||||
|
* Enhanced mirror and remote handling: repository owner/name are derived from URLs, with smoother provisioning and clearer credential handling.
|
||||||
|
* More reliable releases and artifacts due to safer CI behavior when no version tag is present.
|
||||||
|
|
||||||
|
|
||||||
|
## [1.6.3] - 2025-12-14
|
||||||
|
|
||||||
|
* ***Fixed:*** Corrected repository path resolution so release and version logic consistently use the canonical packaging/* layout, preventing changelog and packaging files from being read or updated from incorrect locations.
|
||||||
|
|
||||||
|
|
||||||
## [1.6.2] - 2025-12-14
|
## [1.6.2] - 2025-12-14
|
||||||
|
|
||||||
* **pkgmgr version** now also shows the installed pkgmgr version when run outside a repository.
|
* **pkgmgr version** now also shows the installed pkgmgr version when run outside a repository.
|
||||||
|
|||||||
18
Dockerfile
18
Dockerfile
@@ -33,6 +33,7 @@ CMD ["bash"]
|
|||||||
# - inherits from virgin
|
# - inherits from virgin
|
||||||
# - builds + installs pkgmgr
|
# - builds + installs pkgmgr
|
||||||
# - sets entrypoint + default cmd
|
# - sets entrypoint + default cmd
|
||||||
|
# - NOTE: does NOT run slim.sh (that is done in slim stage)
|
||||||
# ============================================================
|
# ============================================================
|
||||||
FROM virgin AS full
|
FROM virgin AS full
|
||||||
|
|
||||||
@@ -42,14 +43,25 @@ WORKDIR /build
|
|||||||
COPY . .
|
COPY . .
|
||||||
|
|
||||||
# Build and install distro-native package-manager package
|
# Build and install distro-native package-manager package
|
||||||
RUN set -euo pipefail; \
|
RUN set -eu; \
|
||||||
echo "Building and installing package-manager via make install..."; \
|
echo "Building and installing package-manager via make install..."; \
|
||||||
make install; \
|
make install; \
|
||||||
cd /; rm -rf /build
|
rm -rf /build
|
||||||
|
|
||||||
# Entry point
|
# Entry point
|
||||||
COPY scripts/docker/entry.sh /usr/local/bin/docker-entry.sh
|
COPY scripts/docker/entry.sh /usr/local/bin/docker-entry.sh
|
||||||
|
|
||||||
WORKDIR /src
|
WORKDIR /opt/src/pkgmgr
|
||||||
ENTRYPOINT ["/usr/local/bin/docker-entry.sh"]
|
ENTRYPOINT ["/usr/local/bin/docker-entry.sh"]
|
||||||
CMD ["pkgmgr", "--help"]
|
CMD ["pkgmgr", "--help"]
|
||||||
|
|
||||||
|
|
||||||
|
# ============================================================
|
||||||
|
# Target: slim
|
||||||
|
# - based on full
|
||||||
|
# - runs slim.sh
|
||||||
|
# ============================================================
|
||||||
|
FROM full AS slim
|
||||||
|
|
||||||
|
COPY scripts/docker/slim.sh /usr/local/bin/slim.sh
|
||||||
|
RUN chmod +x /usr/local/bin/slim.sh && /usr/local/bin/slim.sh
|
||||||
|
|||||||
3
MIRRORS
3
MIRRORS
@@ -1,3 +1,4 @@
|
|||||||
git@github.com:kevinveenbirkenbach/package-manager.git
|
git@github.com:kevinveenbirkenbach/package-manager.git
|
||||||
ssh://git@git.veen.world:2201/kevinveenbirkenbach/pkgmgr.git
|
ssh://git@git.veen.world:2201/kevinveenbirkenbach/pkgmgr.git
|
||||||
ssh://git@code.cymais.cloud:2201/kevinveenbirkenbach/pkgmgr.git
|
ssh://git@code.infinito.nexus:2201/kevinveenbirkenbach/pkgmgr.git
|
||||||
|
https://pypi.org/project/kpmx/
|
||||||
|
|||||||
16
Makefile
16
Makefile
@@ -2,6 +2,7 @@
|
|||||||
build build-no-cache build-no-cache-all build-missing \
|
build build-no-cache build-no-cache-all build-missing \
|
||||||
delete-volumes purge \
|
delete-volumes purge \
|
||||||
test test-unit test-e2e test-integration test-env-virtual test-env-nix \
|
test test-unit test-e2e test-integration test-env-virtual test-env-nix \
|
||||||
|
lint \
|
||||||
setup setup-venv setup-nix
|
setup setup-venv setup-nix
|
||||||
|
|
||||||
# Distro
|
# Distro
|
||||||
@@ -10,6 +11,10 @@ DISTROS ?= arch debian ubuntu fedora centos
|
|||||||
PKGMGR_DISTRO ?= arch
|
PKGMGR_DISTRO ?= arch
|
||||||
export PKGMGR_DISTRO
|
export PKGMGR_DISTRO
|
||||||
|
|
||||||
|
# Nix Config Variable (To avoid rate limit)
|
||||||
|
NIX_CONFIG ?=
|
||||||
|
export NIX_CONFIG
|
||||||
|
|
||||||
# ------------------------------------------------------------
|
# ------------------------------------------------------------
|
||||||
# Base images
|
# Base images
|
||||||
# (kept for documentation/reference; actual build logic is in scripts/build)
|
# (kept for documentation/reference; actual build logic is in scripts/build)
|
||||||
@@ -78,6 +83,13 @@ build-no-cache-all:
|
|||||||
PKGMGR_DISTRO="$$d" $(MAKE) build-no-cache; \
|
PKGMGR_DISTRO="$$d" $(MAKE) build-no-cache; \
|
||||||
done
|
done
|
||||||
|
|
||||||
|
# ------------------------------------------------------------
|
||||||
|
# Lint targets (run on the host, not in a container)
|
||||||
|
# ------------------------------------------------------------
|
||||||
|
|
||||||
|
lint:
|
||||||
|
@bash scripts/lint/python.sh
|
||||||
|
|
||||||
# ------------------------------------------------------------
|
# ------------------------------------------------------------
|
||||||
# Test targets (delegated to scripts/test)
|
# Test targets (delegated to scripts/test)
|
||||||
# ------------------------------------------------------------
|
# ------------------------------------------------------------
|
||||||
@@ -97,8 +109,8 @@ test-env-virtual: build-missing
|
|||||||
test-env-nix: build-missing
|
test-env-nix: build-missing
|
||||||
@bash scripts/test/test-env-nix.sh
|
@bash scripts/test/test-env-nix.sh
|
||||||
|
|
||||||
# Combined test target for local + CI (unit + integration + e2e)
|
# Combined test target for local + CI (lint + unit + integration + e2e)
|
||||||
test: test-env-virtual test-unit test-integration test-e2e
|
test: lint test-env-virtual test-unit test-integration test-e2e
|
||||||
|
|
||||||
delete-volumes:
|
delete-volumes:
|
||||||
@docker volume rm "pkgmgr_nix_store_${PKGMGR_DISTRO}" "pkgmgr_nix_cache_${PKGMGR_DISTRO}" || echo "No volumes to delete."
|
@docker volume rm "pkgmgr_nix_store_${PKGMGR_DISTRO}" "pkgmgr_nix_cache_${PKGMGR_DISTRO}" || echo "No volumes to delete."
|
||||||
|
|||||||
27
flake.lock
generated
Normal file
27
flake.lock
generated
Normal file
@@ -0,0 +1,27 @@
|
|||||||
|
{
|
||||||
|
"nodes": {
|
||||||
|
"nixpkgs": {
|
||||||
|
"locked": {
|
||||||
|
"lastModified": 1771714954,
|
||||||
|
"narHash": "sha256-nhZJPnBavtu40/L2aqpljrfUNb2rxmWTmSjK2c9UKds=",
|
||||||
|
"owner": "NixOS",
|
||||||
|
"repo": "nixpkgs",
|
||||||
|
"rev": "afbbf774e2087c3d734266c22f96fca2e78d3620",
|
||||||
|
"type": "github"
|
||||||
|
},
|
||||||
|
"original": {
|
||||||
|
"owner": "NixOS",
|
||||||
|
"ref": "nixos-25.11",
|
||||||
|
"repo": "nixpkgs",
|
||||||
|
"type": "github"
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"root": {
|
||||||
|
"inputs": {
|
||||||
|
"nixpkgs": "nixpkgs"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"root": "root",
|
||||||
|
"version": 7
|
||||||
|
}
|
||||||
13
flake.nix
13
flake.nix
@@ -6,7 +6,7 @@
|
|||||||
};
|
};
|
||||||
|
|
||||||
inputs = {
|
inputs = {
|
||||||
nixpkgs.url = "github:NixOS/nixpkgs/nixos-unstable";
|
nixpkgs.url = "github:NixOS/nixpkgs/nixos-25.11";
|
||||||
};
|
};
|
||||||
|
|
||||||
outputs = { self, nixpkgs }:
|
outputs = { self, nixpkgs }:
|
||||||
@@ -32,7 +32,7 @@
|
|||||||
rec {
|
rec {
|
||||||
pkgmgr = pyPkgs.buildPythonApplication {
|
pkgmgr = pyPkgs.buildPythonApplication {
|
||||||
pname = "package-manager";
|
pname = "package-manager";
|
||||||
version = "1.6.2";
|
version = "1.16.0";
|
||||||
|
|
||||||
# Use the git repo as source
|
# Use the git repo as source
|
||||||
src = ./.;
|
src = ./.;
|
||||||
@@ -40,6 +40,10 @@
|
|||||||
# Build using pyproject.toml
|
# Build using pyproject.toml
|
||||||
format = "pyproject";
|
format = "pyproject";
|
||||||
|
|
||||||
|
# Clear any stale wheels carried in from the source tree so
|
||||||
|
# pypaInstallPhase doesn't collide on bin/pkgmgr.
|
||||||
|
preBuild = "rm -rf dist";
|
||||||
|
|
||||||
# Build backend requirements from [build-system]
|
# Build backend requirements from [build-system]
|
||||||
nativeBuildInputs = [
|
nativeBuildInputs = [
|
||||||
pyPkgs.setuptools
|
pyPkgs.setuptools
|
||||||
@@ -49,7 +53,10 @@
|
|||||||
# Runtime dependencies (matches [project.dependencies] in pyproject.toml)
|
# Runtime dependencies (matches [project.dependencies] in pyproject.toml)
|
||||||
propagatedBuildInputs = [
|
propagatedBuildInputs = [
|
||||||
pyPkgs.pyyaml
|
pyPkgs.pyyaml
|
||||||
|
pyPkgs.jinja2
|
||||||
pyPkgs.pip
|
pyPkgs.pip
|
||||||
|
pkgs.git
|
||||||
|
pkgs.gnupg
|
||||||
];
|
];
|
||||||
|
|
||||||
doCheck = false;
|
doCheck = false;
|
||||||
@@ -78,6 +85,7 @@
|
|||||||
pythonWithDeps = python.withPackages (ps: [
|
pythonWithDeps = python.withPackages (ps: [
|
||||||
ps.pip
|
ps.pip
|
||||||
ps.pyyaml
|
ps.pyyaml
|
||||||
|
ps.jinja2
|
||||||
]);
|
]);
|
||||||
in
|
in
|
||||||
{
|
{
|
||||||
@@ -85,6 +93,7 @@
|
|||||||
buildInputs = [
|
buildInputs = [
|
||||||
pythonWithDeps
|
pythonWithDeps
|
||||||
pkgs.git
|
pkgs.git
|
||||||
|
pkgs.gnupg
|
||||||
ansiblePkg
|
ansiblePkg
|
||||||
];
|
];
|
||||||
|
|
||||||
|
|||||||
@@ -1,15 +1,25 @@
|
|||||||
# Maintainer: Kevin Veen-Birkenbach <info@veen.world>
|
# Maintainer: Kevin Veen-Birkenbach <info@veen.world>
|
||||||
|
|
||||||
pkgname=package-manager
|
pkgname=package-manager
|
||||||
pkgver=0.9.1
|
pkgver=1.16.0
|
||||||
pkgrel=1
|
pkgrel=1
|
||||||
pkgdesc="Local-flake wrapper for Kevin's package-manager (Nix-based)."
|
pkgdesc="Local-flake wrapper for Kevin's package-manager (Nix-based)."
|
||||||
arch=('any')
|
arch=('any')
|
||||||
url="https://github.com/kevinveenbirkenbach/package-manager"
|
url="https://github.com/kevinveenbirkenbach/package-manager"
|
||||||
license=('MIT')
|
license=('MIT')
|
||||||
|
|
||||||
# Nix is the only runtime dependency; Python is provided by the Nix closure.
|
# Nix is required at runtime to run pkgmgr via the flake.
|
||||||
depends=('nix')
|
# On Arch x86_64 we can depend on the distro package.
|
||||||
|
# On other arches (e.g. ARM) we only declare it as optional because the
|
||||||
|
# repo package may be broken/out-of-sync; installation can be done via the official installer.
|
||||||
|
depends=()
|
||||||
|
optdepends=('nix: required to run pkgmgr via flake')
|
||||||
|
|
||||||
|
if [[ "${CARCH}" == "x86_64" ]]; then
|
||||||
|
depends=('nix')
|
||||||
|
optdepends=()
|
||||||
|
fi
|
||||||
|
|
||||||
makedepends=('rsync')
|
makedepends=('rsync')
|
||||||
|
|
||||||
install=${pkgname}.install
|
install=${pkgname}.install
|
||||||
|
|||||||
@@ -1,9 +1,9 @@
|
|||||||
post_install() {
|
post_install() {
|
||||||
/usr/lib/package-manager/nix/init.sh || echo ">>> ERROR: /usr/lib/package-manager/nix/init.sh not found or not executable."
|
/usr/lib/package-manager/nix/init.sh
|
||||||
}
|
}
|
||||||
|
|
||||||
post_upgrade() {
|
post_upgrade() {
|
||||||
/usr/lib/package-manager/nix/init.sh || echo ">>> ERROR: /usr/lib/package-manager/nix/init.sh not found or not executable."
|
/usr/lib/package-manager/nix/init.sh
|
||||||
}
|
}
|
||||||
|
|
||||||
post_remove() {
|
post_remove() {
|
||||||
|
|||||||
@@ -1,3 +1,338 @@
|
|||||||
|
package-manager (1.16.0-1) unstable; urgency=medium
|
||||||
|
|
||||||
|
* New *code-scanning* command: *pkgmgr code-scanning* downloads a repository's GitHub code scanning alerts and analysis metadata via the *gh* CLI into a timestamped directory (default */tmp/<repo>/code-scanner/<timestamp>*), together with a readable summary, for offline analysis.
|
||||||
|
* The release flow now lints and normalises the changelog message before writing it: a leading heading becomes bold, inline code becomes italic, and the entry is validated against the repository's markdown rules, re-prompting interactively until it is clean.
|
||||||
|
* The Debian changelog and the RPM *%changelog* now mirror the full multi-line message correctly — every change line is indented or dash-prefixed — fixing a package build failure where un-indented bodies broke *dpkg-buildpackage* and *rpmspec*; the changelog entry no longer gains an auto-inserted leading bullet.
|
||||||
|
|
||||||
|
-- Kevin Veen-Birkenbach <kevin@veen.world> Sun, 28 Jun 2026 16:54:16 +0200
|
||||||
|
|
||||||
|
package-manager (1.15.2-1) unstable; urgency=medium
|
||||||
|
|
||||||
|
* Restore `infinito` as an alias for the infinito-nexus/core repository so `pkgmgr install infinito` (and friends) resolves again.
|
||||||
|
|
||||||
|
-- Kevin Veen-Birkenbach <kevin@veen.world> Thu, 28 May 2026 11:06:43 +0200
|
||||||
|
|
||||||
|
package-manager (1.15.1-1) unstable; urgency=medium
|
||||||
|
|
||||||
|
* Insert pkgmgr release changelog entry under the H1 instead of above it. Fixes the markdownlint MD041 (first-line-h1) and MD012 (no-multiple-blanks) regressions that previously trashed every CHANGELOG.md after a release.
|
||||||
|
|
||||||
|
-- Kevin Veen-Birkenbach <kevin@veen.world> Thu, 28 May 2026 08:18:23 +0200
|
||||||
|
|
||||||
|
package-manager (1.15.0-1) unstable; urgency=medium
|
||||||
|
|
||||||
|
* Add pkgmgr archive subcommand: promote fully-checked NNN-topic.md spec files into the directorys README Archive section and delete the source files. Lookup pattern, README path, and template handling are configurable. Extracted from infinito-nexus-core so every kpmx-managed repo gets the same archival flow.
|
||||||
|
|
||||||
|
-- Kevin Veen-Birkenbach <kevin@veen.world> Thu, 28 May 2026 07:56:07 +0200
|
||||||
|
|
||||||
|
package-manager (1.14.0-1) unstable; urgency=medium
|
||||||
|
|
||||||
|
* Added
|
||||||
|
|
||||||
|
* New release --retry mode re-deploys the HEAD release without
|
||||||
|
re-tagging or modifying any files. It re-pushes the existing version
|
||||||
|
tag, re-aligns the floating latest tag, and (unless --no-publish)
|
||||||
|
re-runs publish. Use this to recover from a release whose post-tag
|
||||||
|
push or PyPI upload failed mid-flight. The release_type argument
|
||||||
|
becomes optional under --retry.
|
||||||
|
* New module pkgmgr.actions.release.retry hosts the retry_release
|
||||||
|
helper so the workflow orchestrator stays focused on the forward
|
||||||
|
path.
|
||||||
|
* RepoPaths now exposes a debian_control slot, discovered alongside
|
||||||
|
debian_changelog under both packaging/debian and the legacy debian
|
||||||
|
layout.
|
||||||
|
* pkgmgr.actions.release.package_name.resolve_package_name centralises
|
||||||
|
the distro-name lookup chain and is unit-tested under
|
||||||
|
tests/unit/pkgmgr/actions/release/test_package_name.py.
|
||||||
|
* tests/unit/pkgmgr/actions/release/test_retry.py covers routing,
|
||||||
|
idempotent push, latest-tag re-alignment, missing-tag error path,
|
||||||
|
and branch-detection fallback.
|
||||||
|
|
||||||
|
Changed
|
||||||
|
|
||||||
|
* pkgmgr release now derives the distro-package name from existing
|
||||||
|
packaging metadata instead of the repository folder name. The lookup
|
||||||
|
order is packaging/debian/control Package field, then
|
||||||
|
packaging/arch/PKGBUILD pkgname value, then RPM spec Name field,
|
||||||
|
then folder basename as legacy fallback. Renaming a repository
|
||||||
|
folder no longer silently flips the debian/changelog top entry and
|
||||||
|
the RPM changelog stanza to a new identifier. Those keep matching
|
||||||
|
the authoritative value in the packaging files, which is what apt,
|
||||||
|
pacman, and dnf index against.
|
||||||
|
|
||||||
|
Fixed
|
||||||
|
|
||||||
|
* dpkg-source --before-build no longer fails with the message about
|
||||||
|
source package having two conflicting values after a repo-folder
|
||||||
|
rename, because the changelog and control file stay in agreement
|
||||||
|
on the next release.
|
||||||
|
|
||||||
|
-- Kevin Veen-Birkenbach <kevin@veen.world> Wed, 27 May 2026 20:53:14 +0200
|
||||||
|
|
||||||
|
package-manager (1.13.4-1) unstable; urgency=medium
|
||||||
|
|
||||||
|
* Changed
|
||||||
|
|
||||||
|
* pkgmgr release now derives the distro-package name from existing
|
||||||
|
packaging metadata instead of the repository folder name. The lookup
|
||||||
|
order is packaging/debian/control Package field, then
|
||||||
|
packaging/arch/PKGBUILD pkgname value, then RPM spec Name field, then
|
||||||
|
folder basename as legacy fallback. Renaming a repository folder (for
|
||||||
|
example infinito-nexus to infinito-nexus-core) no longer silently
|
||||||
|
flips the debian/changelog top entry and the RPM changelog stanza to
|
||||||
|
a new identifier. Those keep matching the authoritative Package,
|
||||||
|
pkgname, or Name value in the packaging files, which is what apt,
|
||||||
|
pacman, and dnf index against.
|
||||||
|
|
||||||
|
Added
|
||||||
|
|
||||||
|
* RepoPaths gains a debian_control slot that is discovered alongside
|
||||||
|
debian_changelog under both packaging/debian (new layout) and debian
|
||||||
|
(legacy layout).
|
||||||
|
* pkgmgr.actions.release.package_name.resolve_package_name centralises
|
||||||
|
the priority chain and is unit-tested under
|
||||||
|
tests/unit/pkgmgr/actions/release/test_package_name.py.
|
||||||
|
|
||||||
|
Fixed
|
||||||
|
|
||||||
|
* dpkg-source --before-build no longer fails with the message about
|
||||||
|
source package having two conflicting values after a repo-folder
|
||||||
|
rename, because the changelog and control file stay in agreement.
|
||||||
|
|
||||||
|
-- Kevin Veen-Birkenbach <kevin@veen.world> Wed, 27 May 2026 20:32:39 +0200
|
||||||
|
|
||||||
|
package-manager (1.13.3-1) unstable; urgency=medium
|
||||||
|
|
||||||
|
* CI pipelines now include automated security scanning (CodeQL, Docker lint), increasing detection of vulnerabilities and misconfigurations
|
||||||
|
* Workflow permissions were tightened and fixed, ensuring secure and reliable execution of reusable workflows
|
||||||
|
* Publishing and “stable” tagging are now restricted to the `main` branch, preventing accidental releases from other branches
|
||||||
|
* Stale CI runs are automatically cancelled, reducing wasted resources and speeding up feedback cycles
|
||||||
|
* Overall CI reliability and security posture improved, with fewer false positives and more consistent pipeline results
|
||||||
|
|
||||||
|
-- Kevin Veen-Birkenbach <kevin@veen.world> Thu, 26 Mar 2026 17:10:21 +0100
|
||||||
|
|
||||||
|
package-manager (1.13.2-1) unstable; urgency=medium
|
||||||
|
|
||||||
|
* Fail fast with a clear error when the Nix bootstrap or nix binary is unavailable instead of continuing with a broken startup path.
|
||||||
|
|
||||||
|
-- Kevin Veen-Birkenbach <kevin@veen.world> Thu, 26 Mar 2026 12:26:55 +0100
|
||||||
|
|
||||||
|
package-manager (1.13.1-1) unstable; urgency=medium
|
||||||
|
|
||||||
|
* Fixed misleading GPG verification failures by adding explicit git and gnupg runtime dependencies and surfacing signing-key lookup errors accurately.
|
||||||
|
|
||||||
|
-- Kevin Veen-Birkenbach <kevin@veen.world> Fri, 20 Mar 2026 02:57:25 +0100
|
||||||
|
|
||||||
|
package-manager (1.13.0-1) unstable; urgency=medium
|
||||||
|
|
||||||
|
* Set CentOS docker image to latest
|
||||||
|
|
||||||
|
-- Kevin Veen-Birkenbach <kevin@veen.world> Fri, 20 Mar 2026 01:29:38 +0100
|
||||||
|
|
||||||
|
package-manager (1.12.5-1) unstable; urgency=medium
|
||||||
|
|
||||||
|
* The stable-tag workflow now waits up to two hours for a successful main-branch CI run on the same commit before updating stable.
|
||||||
|
|
||||||
|
-- Kevin Veen-Birkenbach <kevin@veen.world> Tue, 24 Feb 2026 09:35:39 +0100
|
||||||
|
|
||||||
|
package-manager (1.12.4-1) unstable; urgency=medium
|
||||||
|
|
||||||
|
* The release pipeline now updates the stable tag only for v* tags after a successful CI run on main for the same commit, while avoiding duplicate test executions.
|
||||||
|
|
||||||
|
-- Kevin Veen-Birkenbach <kevin@veen.world> Tue, 24 Feb 2026 09:32:01 +0100
|
||||||
|
|
||||||
|
package-manager (1.12.3-1) unstable; urgency=medium
|
||||||
|
|
||||||
|
* Stabilized Nix-based builds by switching to nixos-25.11 and committing flake.lock, ensuring reproducible pkgmgr test/runtime environments (with pip) and avoiding transient sphinx/Python 3.11 breakage.
|
||||||
|
|
||||||
|
-- Kevin Veen-Birkenbach <kevin@veen.world> Tue, 24 Feb 2026 08:29:34 +0100
|
||||||
|
|
||||||
|
package-manager (1.12.2-1) unstable; urgency=medium
|
||||||
|
|
||||||
|
* Removed infinito-sphinx package
|
||||||
|
|
||||||
|
-- Kevin Veen-Birkenbach <kevin@veen.world> Tue, 24 Feb 2026 07:40:55 +0100
|
||||||
|
|
||||||
|
package-manager (1.12.1-1) unstable; urgency=medium
|
||||||
|
|
||||||
|
* pkgmgr now prefers distro-managed nix binaries on Arch before profile/PATH resolution, preventing libllhttp mismatch failures after pacman system upgrades.
|
||||||
|
|
||||||
|
-- Kevin Veen-Birkenbach <kevin@veen.world> Sat, 14 Feb 2026 23:26:17 +0100
|
||||||
|
|
||||||
|
package-manager (1.12.0-1) unstable; urgency=medium
|
||||||
|
|
||||||
|
* Adds explicit concurrency groups to the CI and mark-stable workflows to prevent overlapping runs on the same branch and make pipeline execution more predictable.
|
||||||
|
|
||||||
|
-- Kevin Veen-Birkenbach <kevin@veen.world> Sun, 08 Feb 2026 18:26:25 +0100
|
||||||
|
|
||||||
|
package-manager (1.11.2-1) unstable; urgency=medium
|
||||||
|
|
||||||
|
* Removes the v* tag trigger from the mark-stable workflow so it runs only on branch pushes and avoids duplicate executions during releases.
|
||||||
|
|
||||||
|
-- Kevin Veen-Birkenbach <kevin@veen.world> Sun, 08 Feb 2026 18:21:50 +0100
|
||||||
|
|
||||||
|
package-manager (1.11.1-1) unstable; urgency=medium
|
||||||
|
|
||||||
|
* Implements pushing the branch and the version tag together in a single command so the CI release workflow can reliably detect the version tag on HEAD.
|
||||||
|
|
||||||
|
-- Kevin Veen-Birkenbach <kevin@veen.world> Sun, 08 Feb 2026 18:18:09 +0100
|
||||||
|
|
||||||
|
package-manager (1.11.0-1) unstable; urgency=medium
|
||||||
|
|
||||||
|
* Adds a dedicated slim Docker image for pkgmgr and publishes slim variants for all supported distros.
|
||||||
|
|
||||||
|
-- Kevin Veen-Birkenbach <kevin@veen.world> Wed, 21 Jan 2026 01:18:31 +0100
|
||||||
|
|
||||||
|
package-manager (1.10.0-1) unstable; urgency=medium
|
||||||
|
|
||||||
|
* Automated release.
|
||||||
|
|
||||||
|
-- Kevin Veen-Birkenbach <kevin@veen.world> Tue, 20 Jan 2026 10:44:58 +0100
|
||||||
|
|
||||||
|
package-manager (1.9.5-1) unstable; urgency=medium
|
||||||
|
|
||||||
|
* Release patch: improve git pull error diagnostics
|
||||||
|
|
||||||
|
-- Kevin Veen-Birkenbach <kevin@veen.world> Fri, 16 Jan 2026 10:09:43 +0100
|
||||||
|
|
||||||
|
package-manager (1.9.4-1) unstable; urgency=medium
|
||||||
|
|
||||||
|
* fix(ci): replace sudo with su for user switching to avoid PAM failures in minimal container images
|
||||||
|
|
||||||
|
-- Kevin Veen-Birkenbach <kevin@veen.world> Tue, 13 Jan 2026 14:48:50 +0100
|
||||||
|
|
||||||
|
package-manager (1.9.3-1) unstable; urgency=medium
|
||||||
|
|
||||||
|
* Made the Nix dependency optional on non-x86_64 architectures to avoid broken Arch Linux ARM repository packages.
|
||||||
|
|
||||||
|
-- Kevin Veen-Birkenbach <kevin@veen.world> Wed, 07 Jan 2026 13:44:40 +0100
|
||||||
|
|
||||||
|
package-manager (1.9.2-1) unstable; urgency=medium
|
||||||
|
|
||||||
|
* Default configuration files are now packaged and loaded correctly when no user config exists, while fully preserving custom user configurations.
|
||||||
|
|
||||||
|
-- Kevin Veen-Birkenbach <kevin@veen.world> Sun, 21 Dec 2025 15:30:22 +0100
|
||||||
|
|
||||||
|
package-manager (1.9.1-1) unstable; urgency=medium
|
||||||
|
|
||||||
|
* Fixed installation issues and improved loading of default configuration files.
|
||||||
|
|
||||||
|
-- Kevin Veen-Birkenbach <kevin@veen.world> Sun, 21 Dec 2025 13:38:58 +0100
|
||||||
|
|
||||||
|
package-manager (1.9.0-1) unstable; urgency=medium
|
||||||
|
|
||||||
|
* * New ***mirror visibility*** command to set remote Git repositories to ***public*** or ***private***.
|
||||||
|
* New ***--public*** flag for ***mirror provision*** to create repositories and immediately make them public.
|
||||||
|
* All configured git mirrors are now provisioned.
|
||||||
|
|
||||||
|
-- Kevin Veen-Birkenbach <kevin@veen.world> Sat, 20 Dec 2025 14:37:58 +0100
|
||||||
|
|
||||||
|
package-manager (1.8.7-1) unstable; urgency=medium
|
||||||
|
|
||||||
|
* * **Release version updates now correctly modify ***pyproject.toml*** files that follow PEP 621**, ensuring the ***[project].version*** field is updated as expected.
|
||||||
|
* **Invalid or incomplete ***pyproject.toml*** files are now handled gracefully** with clear error messages instead of abrupt process termination.
|
||||||
|
* **RPM spec files remain compatible during releases**: existing macros such as ***%{?dist}*** are preserved and no longer accidentally modified.
|
||||||
|
|
||||||
|
-- Kevin Veen-Birkenbach <kevin@veen.world> Fri, 19 Dec 2025 14:15:47 +0100
|
||||||
|
|
||||||
|
package-manager (1.8.6-1) unstable; urgency=medium
|
||||||
|
|
||||||
|
* Prevent Rate Limits during GitHub Nix Setups
|
||||||
|
|
||||||
|
-- Kevin Veen-Birkenbach <kevin@veen.world> Wed, 17 Dec 2025 23:50:31 +0100
|
||||||
|
|
||||||
|
package-manager (1.8.5-1) unstable; urgency=medium
|
||||||
|
|
||||||
|
* * Clearer Git error handling, especially when a directory is not a Git repository.
|
||||||
|
* More reliable repository verification with improved commit and GPG signature checks.
|
||||||
|
* Better error messages and overall robustness when working with Git-based workflows.
|
||||||
|
|
||||||
|
-- Kevin Veen-Birkenbach <kevin@veen.world> Wed, 17 Dec 2025 22:15:48 +0100
|
||||||
|
|
||||||
|
package-manager (1.9.0-1) unstable; urgency=medium
|
||||||
|
|
||||||
|
* Automated release.
|
||||||
|
|
||||||
|
-- Kevin Veen-Birkenbach <kevin@veen.world> Wed, 17 Dec 2025 22:10:31 +0100
|
||||||
|
|
||||||
|
package-manager (1.8.4-1) unstable; urgency=medium
|
||||||
|
|
||||||
|
* * Made pkgmgr’s base-layer role explicit by standardizing the Docker/CI mount path to *`/opt/src/pkgmgr`*.
|
||||||
|
|
||||||
|
-- Kevin Veen-Birkenbach <kevin@veen.world> Wed, 17 Dec 2025 11:20:16 +0100
|
||||||
|
|
||||||
|
package-manager (1.8.3-1) unstable; urgency=medium
|
||||||
|
|
||||||
|
* MIRRORS now supports plain URL entries, ensuring metadata-only sources like PyPI are recorded without ever being added to the Git configuration.
|
||||||
|
|
||||||
|
-- Kevin Veen-Birkenbach <kevin@veen.world> Tue, 16 Dec 2025 19:49:51 +0100
|
||||||
|
|
||||||
|
package-manager (1.8.2-1) unstable; urgency=medium
|
||||||
|
|
||||||
|
* * ***pkgmgr tools code*** is more robust and predictable: it now fails early with clear errors if VS Code is not installed or a repository is not yet identified.
|
||||||
|
|
||||||
|
-- Kevin Veen-Birkenbach <kevin@veen.world> Tue, 16 Dec 2025 19:22:41 +0100
|
||||||
|
|
||||||
|
package-manager (1.8.1-1) unstable; urgency=medium
|
||||||
|
|
||||||
|
* * Improved stability and consistency of all Git operations (clone, pull, push, release, branch handling) with clearer error messages and predictable preview behavior.
|
||||||
|
* Mirrors are now handled cleanly: only valid Git remotes are used for Git operations, while non-Git URLs (e.g. PyPI) are excluded, preventing broken or confusing repository configs.
|
||||||
|
* GitHub authentication is more robust: tokens are automatically resolved via the GitHub CLI (`gh`), invalid stored tokens are replaced, and interactive prompts occur only when necessary.
|
||||||
|
* Repository creation and release workflows are more reliable, producing cleaner Git configurations and more predictable version handling.
|
||||||
|
|
||||||
|
-- Kevin Veen-Birkenbach <kevin@veen.world> Tue, 16 Dec 2025 18:06:35 +0100
|
||||||
|
|
||||||
|
package-manager (1.8.0-1) unstable; urgency=medium
|
||||||
|
|
||||||
|
* *** New Features: ***
|
||||||
|
- **Silent Updates**: You can now use the `--silent` flag during installs and updates to suppress error messages for individual repositories and get a single summary at the end. This ensures the process continues even if some repositories fail, while still preserving interactive checks when not in silent mode.
|
||||||
|
- **Repository Scaffolding**: The process for creating new repositories has been improved. You can now use templates to scaffold repositories with a preview and automatic mirror setup.
|
||||||
|
|
||||||
|
*** Bug Fixes: ***
|
||||||
|
- **Pip Installation**: Pip is now installed automatically on all supported systems. This includes `python-pip` for Arch and `python3-pip` for CentOS, Debian, Fedora, and Ubuntu, ensuring that pip is available for Python package installations.
|
||||||
|
- **Pacman Keyring**: Fixed an issue on Arch Linux where package installation would fail due to missing keys. The pacman keyring is now properly initialized before installing packages.
|
||||||
|
|
||||||
|
-- Kevin Veen-Birkenbach <kevin@veen.world> Mon, 15 Dec 2025 13:37:42 +0100
|
||||||
|
|
||||||
|
package-manager (1.7.2-1) unstable; urgency=medium
|
||||||
|
|
||||||
|
* * Git mirrors are now resolved consistently (origin → MIRRORS file → config → default).
|
||||||
|
* The `origin` remote is always enforced to use the primary URL for both fetch and push.
|
||||||
|
* Additional mirrors are added as extra push targets without duplication.
|
||||||
|
* Local and remote mirror setup behaves more predictably and consistently.
|
||||||
|
* Improved test coverage ensures stable origin and push URL handling.
|
||||||
|
|
||||||
|
-- Kevin Veen-Birkenbach <kevin@veen.world> Mon, 15 Dec 2025 00:53:26 +0100
|
||||||
|
|
||||||
|
package-manager (1.7.1-1) unstable; urgency=medium
|
||||||
|
|
||||||
|
* Patched package-manager to kpmx to publish on pypi
|
||||||
|
|
||||||
|
-- Kevin Veen-Birkenbach <kevin@veen.world> Sun, 14 Dec 2025 21:19:11 +0100
|
||||||
|
|
||||||
|
package-manager (1.7.0-1) unstable; urgency=medium
|
||||||
|
|
||||||
|
* * New *pkgmgr publish* command to publish repository artifacts to PyPI based on the *MIRRORS* file.
|
||||||
|
* Automatically selects the current repository when no explicit selection is given.
|
||||||
|
* Publishes only when a semantic version tag is present on *HEAD*; otherwise skips with a clear info message.
|
||||||
|
* Supports non-interactive mode for CI environments via *--non-interactive*.
|
||||||
|
|
||||||
|
-- Kevin Veen-Birkenbach <kevin@veen.world> Sun, 14 Dec 2025 21:10:06 +0100
|
||||||
|
|
||||||
|
package-manager (1.6.4-1) unstable; urgency=medium
|
||||||
|
|
||||||
|
* * Improved reliability of Nix installs and updates, including automatic resolution of profile conflicts and better handling of GitHub 403 rate limits.
|
||||||
|
* More stable launcher behavior in packaged and virtual-env setups.
|
||||||
|
* Enhanced mirror and remote handling: repository owner/name are derived from URLs, with smoother provisioning and clearer credential handling.
|
||||||
|
* More reliable releases and artifacts due to safer CI behavior when no version tag is present.
|
||||||
|
|
||||||
|
-- Kevin Veen-Birkenbach <kevin@veen.world> Sun, 14 Dec 2025 19:33:07 +0100
|
||||||
|
|
||||||
|
package-manager (1.6.3-1) unstable; urgency=medium
|
||||||
|
|
||||||
|
* ***Fixed:*** Corrected repository path resolution so release and version logic consistently use the canonical packaging/* layout, preventing changelog and packaging files from being read or updated from incorrect locations.
|
||||||
|
|
||||||
|
-- Kevin Veen-Birkenbach <kevin@veen.world> Sun, 14 Dec 2025 13:39:52 +0100
|
||||||
|
|
||||||
package-manager (0.9.1-1) unstable; urgency=medium
|
package-manager (0.9.1-1) unstable; urgency=medium
|
||||||
|
|
||||||
* * Refactored installer: new `venv-create.sh`, cleaner root/user setup flow, updated README with architecture map.
|
* * Refactored installer: new `venv-create.sh`, cleaner root/user setup flow, updated README with architecture map.
|
||||||
|
|||||||
@@ -3,7 +3,7 @@ set -e
|
|||||||
|
|
||||||
case "$1" in
|
case "$1" in
|
||||||
configure)
|
configure)
|
||||||
/usr/lib/package-manager/nix/init.sh || echo ">>> ERROR: /usr/lib/package-manager/nix/init.sh not found or not executable."
|
/usr/lib/package-manager/nix/init.sh
|
||||||
;;
|
;;
|
||||||
esac
|
esac
|
||||||
|
|
||||||
|
|||||||
@@ -1,5 +1,5 @@
|
|||||||
Name: package-manager
|
Name: package-manager
|
||||||
Version: 0.9.1
|
Version: 1.16.0
|
||||||
Release: 1%{?dist}
|
Release: 1%{?dist}
|
||||||
Summary: Wrapper that runs Kevin's package-manager via Nix flake
|
Summary: Wrapper that runs Kevin's package-manager via Nix flake
|
||||||
|
|
||||||
@@ -62,7 +62,7 @@ rm -rf \
|
|||||||
%{buildroot}/usr/lib/package-manager/.gitkeep || true
|
%{buildroot}/usr/lib/package-manager/.gitkeep || true
|
||||||
|
|
||||||
%post
|
%post
|
||||||
/usr/lib/package-manager/nix/init.sh || echo ">>> ERROR: /usr/lib/package-manager/nix/init.sh not found or not executable."
|
/usr/lib/package-manager/nix/init.sh
|
||||||
|
|
||||||
%postun
|
%postun
|
||||||
echo ">>> package-manager removed. Nix itself was not removed."
|
echo ">>> package-manager removed. Nix itself was not removed."
|
||||||
@@ -74,6 +74,221 @@ echo ">>> package-manager removed. Nix itself was not removed."
|
|||||||
/usr/lib/package-manager/
|
/usr/lib/package-manager/
|
||||||
|
|
||||||
%changelog
|
%changelog
|
||||||
|
* Sun Jun 28 2026 Kevin Veen-Birkenbach <kevin@veen.world> - 1.16.0-1
|
||||||
|
- * New *code-scanning* command: *pkgmgr code-scanning* downloads a repository's GitHub code scanning alerts and analysis metadata via the *gh* CLI into a timestamped directory (default */tmp/<repo>/code-scanner/<timestamp>*), together with a readable summary, for offline analysis.
|
||||||
|
- * The release flow now lints and normalises the changelog message before writing it: a leading heading becomes bold, inline code becomes italic, and the entry is validated against the repository's markdown rules, re-prompting interactively until it is clean.
|
||||||
|
- * The Debian changelog and the RPM *%changelog* now mirror the full multi-line message correctly — every change line is indented or dash-prefixed — fixing a package build failure where un-indented bodies broke *dpkg-buildpackage* and *rpmspec*; the changelog entry no longer gains an auto-inserted leading bullet.
|
||||||
|
|
||||||
|
* Thu May 28 2026 Kevin Veen-Birkenbach <kevin@veen.world> - 1.15.2-1
|
||||||
|
- Restore `infinito` as an alias for the infinito-nexus/core repository so `pkgmgr install infinito` (and friends) resolves again.
|
||||||
|
|
||||||
|
* Thu May 28 2026 Kevin Veen-Birkenbach <kevin@veen.world> - 1.15.1-1
|
||||||
|
- Insert pkgmgr release changelog entry under the H1 instead of above it. Fixes the markdownlint MD041 (first-line-h1) and MD012 (no-multiple-blanks) regressions that previously trashed every CHANGELOG.md after a release.
|
||||||
|
|
||||||
|
* Thu May 28 2026 Kevin Veen-Birkenbach <kevin@veen.world> - 1.15.0-1
|
||||||
|
- Add pkgmgr archive subcommand: promote fully-checked NNN-topic.md spec files into the directorys README Archive section and delete the source files. Lookup pattern, README path, and template handling are configurable. Extracted from infinito-nexus-core so every kpmx-managed repo gets the same archival flow.
|
||||||
|
|
||||||
|
* Wed May 27 2026 Kevin Veen-Birkenbach <kevin@veen.world> - 1.14.0-1
|
||||||
|
- Added
|
||||||
|
|
||||||
|
* New release --retry mode re-deploys the HEAD release without
|
||||||
|
re-tagging or modifying any files. It re-pushes the existing version
|
||||||
|
tag, re-aligns the floating latest tag, and (unless --no-publish)
|
||||||
|
re-runs publish. Use this to recover from a release whose post-tag
|
||||||
|
push or PyPI upload failed mid-flight. The release_type argument
|
||||||
|
becomes optional under --retry.
|
||||||
|
* New module pkgmgr.actions.release.retry hosts the retry_release
|
||||||
|
helper so the workflow orchestrator stays focused on the forward
|
||||||
|
path.
|
||||||
|
* RepoPaths now exposes a debian_control slot, discovered alongside
|
||||||
|
debian_changelog under both packaging/debian and the legacy debian
|
||||||
|
layout.
|
||||||
|
* pkgmgr.actions.release.package_name.resolve_package_name centralises
|
||||||
|
the distro-name lookup chain and is unit-tested under
|
||||||
|
tests/unit/pkgmgr/actions/release/test_package_name.py.
|
||||||
|
* tests/unit/pkgmgr/actions/release/test_retry.py covers routing,
|
||||||
|
idempotent push, latest-tag re-alignment, missing-tag error path,
|
||||||
|
and branch-detection fallback.
|
||||||
|
|
||||||
|
Changed
|
||||||
|
|
||||||
|
* pkgmgr release now derives the distro-package name from existing
|
||||||
|
packaging metadata instead of the repository folder name. The lookup
|
||||||
|
order is packaging/debian/control Package field, then
|
||||||
|
packaging/arch/PKGBUILD pkgname value, then RPM spec Name field,
|
||||||
|
then folder basename as legacy fallback. Renaming a repository
|
||||||
|
folder no longer silently flips the debian/changelog top entry and
|
||||||
|
the RPM changelog stanza to a new identifier. Those keep matching
|
||||||
|
the authoritative value in the packaging files, which is what apt,
|
||||||
|
pacman, and dnf index against.
|
||||||
|
|
||||||
|
Fixed
|
||||||
|
|
||||||
|
* dpkg-source --before-build no longer fails with the message about
|
||||||
|
source package having two conflicting values after a repo-folder
|
||||||
|
rename, because the changelog and control file stay in agreement
|
||||||
|
on the next release.
|
||||||
|
|
||||||
|
* Wed May 27 2026 Kevin Veen-Birkenbach <kevin@veen.world> - 1.13.4-1
|
||||||
|
- Changed
|
||||||
|
|
||||||
|
* pkgmgr release now derives the distro-package name from existing
|
||||||
|
packaging metadata instead of the repository folder name. The lookup
|
||||||
|
order is packaging/debian/control Package field, then
|
||||||
|
packaging/arch/PKGBUILD pkgname value, then RPM spec Name field, then
|
||||||
|
folder basename as legacy fallback. Renaming a repository folder (for
|
||||||
|
example infinito-nexus to infinito-nexus-core) no longer silently
|
||||||
|
flips the debian/changelog top entry and the RPM changelog stanza to
|
||||||
|
a new identifier. Those keep matching the authoritative Package,
|
||||||
|
pkgname, or Name value in the packaging files, which is what apt,
|
||||||
|
pacman, and dnf index against.
|
||||||
|
|
||||||
|
Added
|
||||||
|
|
||||||
|
* RepoPaths gains a debian_control slot that is discovered alongside
|
||||||
|
debian_changelog under both packaging/debian (new layout) and debian
|
||||||
|
(legacy layout).
|
||||||
|
* pkgmgr.actions.release.package_name.resolve_package_name centralises
|
||||||
|
the priority chain and is unit-tested under
|
||||||
|
tests/unit/pkgmgr/actions/release/test_package_name.py.
|
||||||
|
|
||||||
|
Fixed
|
||||||
|
|
||||||
|
* dpkg-source --before-build no longer fails with the message about
|
||||||
|
source package having two conflicting values after a repo-folder
|
||||||
|
rename, because the changelog and control file stay in agreement.
|
||||||
|
|
||||||
|
* Thu Mar 26 2026 Kevin Veen-Birkenbach <kevin@veen.world> - 1.13.3-1
|
||||||
|
- CI pipelines now include automated security scanning (CodeQL, Docker lint), increasing detection of vulnerabilities and misconfigurations
|
||||||
|
* Workflow permissions were tightened and fixed, ensuring secure and reliable execution of reusable workflows
|
||||||
|
* Publishing and “stable” tagging are now restricted to the `main` branch, preventing accidental releases from other branches
|
||||||
|
* Stale CI runs are automatically cancelled, reducing wasted resources and speeding up feedback cycles
|
||||||
|
* Overall CI reliability and security posture improved, with fewer false positives and more consistent pipeline results
|
||||||
|
|
||||||
|
* Thu Mar 26 2026 Kevin Veen-Birkenbach <kevin@veen.world> - 1.13.2-1
|
||||||
|
- Fail fast with a clear error when the Nix bootstrap or nix binary is unavailable instead of continuing with a broken startup path.
|
||||||
|
|
||||||
|
* Fri Mar 20 2026 Kevin Veen-Birkenbach <kevin@veen.world> - 1.13.1-1
|
||||||
|
- Fixed misleading GPG verification failures by adding explicit git and gnupg runtime dependencies and surfacing signing-key lookup errors accurately.
|
||||||
|
|
||||||
|
* Fri Mar 20 2026 Kevin Veen-Birkenbach <kevin@veen.world> - 1.13.0-1
|
||||||
|
- Set CentOS docker image to latest
|
||||||
|
|
||||||
|
* Tue Feb 24 2026 Kevin Veen-Birkenbach <kevin@veen.world> - 1.12.5-1
|
||||||
|
- The stable-tag workflow now waits up to two hours for a successful main-branch CI run on the same commit before updating stable.
|
||||||
|
|
||||||
|
* Tue Feb 24 2026 Kevin Veen-Birkenbach <kevin@veen.world> - 1.12.4-1
|
||||||
|
- The release pipeline now updates the stable tag only for v* tags after a successful CI run on main for the same commit, while avoiding duplicate test executions.
|
||||||
|
|
||||||
|
* Tue Feb 24 2026 Kevin Veen-Birkenbach <kevin@veen.world> - 1.12.3-1
|
||||||
|
- Stabilized Nix-based builds by switching to nixos-25.11 and committing flake.lock, ensuring reproducible pkgmgr test/runtime environments (with pip) and avoiding transient sphinx/Python 3.11 breakage.
|
||||||
|
|
||||||
|
* Tue Feb 24 2026 Kevin Veen-Birkenbach <kevin@veen.world> - 1.12.2-1
|
||||||
|
- Removed infinito-sphinx package
|
||||||
|
|
||||||
|
* Sat Feb 14 2026 Kevin Veen-Birkenbach <kevin@veen.world> - 1.12.1-1
|
||||||
|
- pkgmgr now prefers distro-managed nix binaries on Arch before profile/PATH resolution, preventing libllhttp mismatch failures after pacman system upgrades.
|
||||||
|
|
||||||
|
* Sun Feb 08 2026 Kevin Veen-Birkenbach <kevin@veen.world> - 1.12.0-1
|
||||||
|
- Adds explicit concurrency groups to the CI and mark-stable workflows to prevent overlapping runs on the same branch and make pipeline execution more predictable.
|
||||||
|
|
||||||
|
* Sun Feb 08 2026 Kevin Veen-Birkenbach <kevin@veen.world> - 1.11.2-1
|
||||||
|
- Removes the v* tag trigger from the mark-stable workflow so it runs only on branch pushes and avoids duplicate executions during releases.
|
||||||
|
|
||||||
|
* Sun Feb 08 2026 Kevin Veen-Birkenbach <kevin@veen.world> - 1.11.1-1
|
||||||
|
- Implements pushing the branch and the version tag together in a single command so the CI release workflow can reliably detect the version tag on HEAD.
|
||||||
|
|
||||||
|
* Wed Jan 21 2026 Kevin Veen-Birkenbach <kevin@veen.world> - 1.11.0-1
|
||||||
|
- Adds a dedicated slim Docker image for pkgmgr and publishes slim variants for all supported distros.
|
||||||
|
|
||||||
|
* Tue Jan 20 2026 Kevin Veen-Birkenbach <kevin@veen.world> - 1.10.0-1
|
||||||
|
- Automated release.
|
||||||
|
|
||||||
|
* Fri Jan 16 2026 Kevin Veen-Birkenbach <kevin@veen.world> - 1.9.5-1
|
||||||
|
- Release patch: improve git pull error diagnostics
|
||||||
|
|
||||||
|
* Tue Jan 13 2026 Kevin Veen-Birkenbach <kevin@veen.world> - 1.9.4-1
|
||||||
|
- fix(ci): replace sudo with su for user switching to avoid PAM failures in minimal container images
|
||||||
|
|
||||||
|
* Wed Jan 07 2026 Kevin Veen-Birkenbach <kevin@veen.world> - 1.9.3-1
|
||||||
|
- Made the Nix dependency optional on non-x86_64 architectures to avoid broken Arch Linux ARM repository packages.
|
||||||
|
|
||||||
|
* Sun Dec 21 2025 Kevin Veen-Birkenbach <kevin@veen.world> - 1.9.2-1
|
||||||
|
- Default configuration files are now packaged and loaded correctly when no user config exists, while fully preserving custom user configurations.
|
||||||
|
|
||||||
|
* Sun Dec 21 2025 Kevin Veen-Birkenbach <kevin@veen.world> - 1.9.1-1
|
||||||
|
- Fixed installation issues and improved loading of default configuration files.
|
||||||
|
|
||||||
|
* Sat Dec 20 2025 Kevin Veen-Birkenbach <kevin@veen.world> - 1.9.0-1
|
||||||
|
- * New ***mirror visibility*** command to set remote Git repositories to ***public*** or ***private***.
|
||||||
|
* New ***--public*** flag for ***mirror provision*** to create repositories and immediately make them public.
|
||||||
|
* All configured git mirrors are now provisioned.
|
||||||
|
|
||||||
|
* Fri Dec 19 2025 Kevin Veen-Birkenbach <kevin@veen.world> - 1.8.7-1
|
||||||
|
- * **Release version updates now correctly modify ***pyproject.toml*** files that follow PEP 621**, ensuring the ***[project].version*** field is updated as expected.
|
||||||
|
* **Invalid or incomplete ***pyproject.toml*** files are now handled gracefully** with clear error messages instead of abrupt process termination.
|
||||||
|
* **RPM spec files remain compatible during releases**: existing macros such as ***%{?dist}*** are preserved and no longer accidentally modified.
|
||||||
|
|
||||||
|
* Wed Dec 17 2025 Kevin Veen-Birkenbach <kevin@veen.world> - 1.8.6-1
|
||||||
|
- Prevent Rate Limits during GitHub Nix Setups
|
||||||
|
|
||||||
|
* Wed Dec 17 2025 Kevin Veen-Birkenbach <kevin@veen.world> - 1.8.5-1
|
||||||
|
- * Clearer Git error handling, especially when a directory is not a Git repository.
|
||||||
|
* More reliable repository verification with improved commit and GPG signature checks.
|
||||||
|
* Better error messages and overall robustness when working with Git-based workflows.
|
||||||
|
|
||||||
|
* Wed Dec 17 2025 Kevin Veen-Birkenbach <kevin@veen.world> - 1.9.0-1
|
||||||
|
- Automated release.
|
||||||
|
|
||||||
|
* Wed Dec 17 2025 Kevin Veen-Birkenbach <kevin@veen.world> - 1.8.4-1
|
||||||
|
- * Made pkgmgr’s base-layer role explicit by standardizing the Docker/CI mount path to *`/opt/src/pkgmgr`*.
|
||||||
|
|
||||||
|
* Tue Dec 16 2025 Kevin Veen-Birkenbach <kevin@veen.world> - 1.8.3-1
|
||||||
|
- MIRRORS now supports plain URL entries, ensuring metadata-only sources like PyPI are recorded without ever being added to the Git configuration.
|
||||||
|
|
||||||
|
* Tue Dec 16 2025 Kevin Veen-Birkenbach <kevin@veen.world> - 1.8.2-1
|
||||||
|
- * ***pkgmgr tools code*** is more robust and predictable: it now fails early with clear errors if VS Code is not installed or a repository is not yet identified.
|
||||||
|
|
||||||
|
* Tue Dec 16 2025 Kevin Veen-Birkenbach <kevin@veen.world> - 1.8.1-1
|
||||||
|
- * Improved stability and consistency of all Git operations (clone, pull, push, release, branch handling) with clearer error messages and predictable preview behavior.
|
||||||
|
* Mirrors are now handled cleanly: only valid Git remotes are used for Git operations, while non-Git URLs (e.g. PyPI) are excluded, preventing broken or confusing repository configs.
|
||||||
|
* GitHub authentication is more robust: tokens are automatically resolved via the GitHub CLI (`gh`), invalid stored tokens are replaced, and interactive prompts occur only when necessary.
|
||||||
|
* Repository creation and release workflows are more reliable, producing cleaner Git configurations and more predictable version handling.
|
||||||
|
|
||||||
|
* Mon Dec 15 2025 Kevin Veen-Birkenbach <kevin@veen.world> - 1.8.0-1
|
||||||
|
- *** New Features: ***
|
||||||
|
- **Silent Updates**: You can now use the `--silent` flag during installs and updates to suppress error messages for individual repositories and get a single summary at the end. This ensures the process continues even if some repositories fail, while still preserving interactive checks when not in silent mode.
|
||||||
|
- **Repository Scaffolding**: The process for creating new repositories has been improved. You can now use templates to scaffold repositories with a preview and automatic mirror setup.
|
||||||
|
|
||||||
|
*** Bug Fixes: ***
|
||||||
|
- **Pip Installation**: Pip is now installed automatically on all supported systems. This includes `python-pip` for Arch and `python3-pip` for CentOS, Debian, Fedora, and Ubuntu, ensuring that pip is available for Python package installations.
|
||||||
|
- **Pacman Keyring**: Fixed an issue on Arch Linux where package installation would fail due to missing keys. The pacman keyring is now properly initialized before installing packages.
|
||||||
|
|
||||||
|
* Mon Dec 15 2025 Kevin Veen-Birkenbach <kevin@veen.world> - 1.7.2-1
|
||||||
|
- * Git mirrors are now resolved consistently (origin → MIRRORS file → config → default).
|
||||||
|
* The `origin` remote is always enforced to use the primary URL for both fetch and push.
|
||||||
|
* Additional mirrors are added as extra push targets without duplication.
|
||||||
|
* Local and remote mirror setup behaves more predictably and consistently.
|
||||||
|
* Improved test coverage ensures stable origin and push URL handling.
|
||||||
|
|
||||||
|
* Sun Dec 14 2025 Kevin Veen-Birkenbach <kevin@veen.world> - 1.7.1-1
|
||||||
|
- Patched package-manager to kpmx to publish on pypi
|
||||||
|
|
||||||
|
* Sun Dec 14 2025 Kevin Veen-Birkenbach <kevin@veen.world> - 1.7.0-1
|
||||||
|
- * New *pkgmgr publish* command to publish repository artifacts to PyPI based on the *MIRRORS* file.
|
||||||
|
* Automatically selects the current repository when no explicit selection is given.
|
||||||
|
* Publishes only when a semantic version tag is present on *HEAD*; otherwise skips with a clear info message.
|
||||||
|
* Supports non-interactive mode for CI environments via *--non-interactive*.
|
||||||
|
|
||||||
|
* Sun Dec 14 2025 Kevin Veen-Birkenbach <kevin@veen.world> - 1.6.4-1
|
||||||
|
- * Improved reliability of Nix installs and updates, including automatic resolution of profile conflicts and better handling of GitHub 403 rate limits.
|
||||||
|
* More stable launcher behavior in packaged and virtual-env setups.
|
||||||
|
* Enhanced mirror and remote handling: repository owner/name are derived from URLs, with smoother provisioning and clearer credential handling.
|
||||||
|
* More reliable releases and artifacts due to safer CI behavior when no version tag is present.
|
||||||
|
|
||||||
|
* Sun Dec 14 2025 Kevin Veen-Birkenbach <kevin@veen.world> - 1.6.3-1
|
||||||
|
- ***Fixed:*** Corrected repository path resolution so release and version logic consistently use the canonical packaging/* layout, preventing changelog and packaging files from being read or updated from incorrect locations.
|
||||||
|
|
||||||
* Wed Dec 10 2025 Kevin Veen-Birkenbach <kevin@veen.world> - 0.9.1-1
|
* Wed Dec 10 2025 Kevin Veen-Birkenbach <kevin@veen.world> - 0.9.1-1
|
||||||
- * Refactored installer: new `venv-create.sh`, cleaner root/user setup flow, updated README with architecture map.
|
- * Refactored installer: new `venv-create.sh`, cleaner root/user setup flow, updated README with architecture map.
|
||||||
* Split virgin tests into root/user workflows; stabilized Nix installer across distros; improved test scripts with dynamic distro selection and isolated Nix stores.
|
* Split virgin tests into root/user workflows; stabilized Nix installer across distros; improved test scripts with dynamic distro selection and isolated Nix stores.
|
||||||
|
|||||||
@@ -6,8 +6,8 @@ requires = [
|
|||||||
build-backend = "setuptools.build_meta"
|
build-backend = "setuptools.build_meta"
|
||||||
|
|
||||||
[project]
|
[project]
|
||||||
name = "package-manager"
|
name = "kpmx"
|
||||||
version = "1.6.2"
|
version = "1.16.0"
|
||||||
description = "Kevin's package-manager tool (pkgmgr)"
|
description = "Kevin's package-manager tool (pkgmgr)"
|
||||||
readme = "README.md"
|
readme = "README.md"
|
||||||
requires-python = ">=3.9"
|
requires-python = ">=3.9"
|
||||||
@@ -21,6 +21,7 @@ authors = [
|
|||||||
dependencies = [
|
dependencies = [
|
||||||
"PyYAML>=6.0",
|
"PyYAML>=6.0",
|
||||||
"tomli; python_version < \"3.11\"",
|
"tomli; python_version < \"3.11\"",
|
||||||
|
"jinja2>=3.1"
|
||||||
]
|
]
|
||||||
|
|
||||||
[project.urls]
|
[project.urls]
|
||||||
@@ -42,11 +43,12 @@ pkgmgr = "pkgmgr.cli:main"
|
|||||||
# -----------------------------
|
# -----------------------------
|
||||||
# Source layout: all packages live under "src/"
|
# Source layout: all packages live under "src/"
|
||||||
[tool.setuptools]
|
[tool.setuptools]
|
||||||
package-dir = { "" = "src", "config" = "config" }
|
package-dir = { "" = "src" }
|
||||||
|
include-package-data = true
|
||||||
|
|
||||||
[tool.setuptools.packages.find]
|
[tool.setuptools.packages.find]
|
||||||
where = ["src", "."]
|
where = ["src"]
|
||||||
include = ["pkgmgr*", "config*"]
|
include = ["pkgmgr*"]
|
||||||
|
|
||||||
[tool.setuptools.package-data]
|
[tool.setuptools.package-data]
|
||||||
"config" = ["defaults.yaml"]
|
"pkgmgr.config" = ["*.yml", "*.yaml"]
|
||||||
|
|||||||
@@ -5,7 +5,7 @@ set -euo pipefail
|
|||||||
: "${BASE_IMAGE_DEBIAN:=debian:stable-slim}"
|
: "${BASE_IMAGE_DEBIAN:=debian:stable-slim}"
|
||||||
: "${BASE_IMAGE_UBUNTU:=ubuntu:latest}"
|
: "${BASE_IMAGE_UBUNTU:=ubuntu:latest}"
|
||||||
: "${BASE_IMAGE_FEDORA:=fedora:latest}"
|
: "${BASE_IMAGE_FEDORA:=fedora:latest}"
|
||||||
: "${BASE_IMAGE_CENTOS:=quay.io/centos/centos:stream9}"
|
: "${BASE_IMAGE_CENTOS:=quay.io/centos/centos:latest}"
|
||||||
|
|
||||||
resolve_base_image() {
|
resolve_base_image() {
|
||||||
local PKGMGR_DISTRO="$1"
|
local PKGMGR_DISTRO="$1"
|
||||||
|
|||||||
@@ -33,7 +33,7 @@ Usage: PKGMGR_DISTRO=<distro> $0 [options]
|
|||||||
Build options:
|
Build options:
|
||||||
--missing Build only if the image does not already exist (local build only)
|
--missing Build only if the image does not already exist (local build only)
|
||||||
--no-cache Build with --no-cache
|
--no-cache Build with --no-cache
|
||||||
--target <name> Build a specific Dockerfile target (e.g. virgin)
|
--target <name> Build a specific Dockerfile target (e.g. virgin, slim)
|
||||||
--tag <image> Override the output image tag (default: ${default_tag})
|
--tag <image> Override the output image tag (default: ${default_tag})
|
||||||
|
|
||||||
Publish options:
|
Publish options:
|
||||||
@@ -47,7 +47,7 @@ Publish options:
|
|||||||
|
|
||||||
Notes:
|
Notes:
|
||||||
- --publish implies --push and requires --registry, --owner, and --version.
|
- --publish implies --push and requires --registry, --owner, and --version.
|
||||||
- Local build (no --push) uses "docker build" and creates local images like "pkgmgr-arch" / "pkgmgr-arch-virgin".
|
- Local build (no --push) uses "docker build" and creates local images like "pkgmgr-arch" / "pkgmgr-arch-virgin" / "pkgmgr-arch-slim".
|
||||||
EOF
|
EOF
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -57,7 +57,7 @@ while [[ $# -gt 0 ]]; do
|
|||||||
--missing) MISSING_ONLY=1; shift ;;
|
--missing) MISSING_ONLY=1; shift ;;
|
||||||
--target)
|
--target)
|
||||||
TARGET="${2:-}"
|
TARGET="${2:-}"
|
||||||
[[ -n "${TARGET}" ]] || { echo "ERROR: --target requires a value (e.g. virgin)"; exit 2; }
|
[[ -n "${TARGET}" ]] || { echo "ERROR: --target requires a value (e.g. virgin|slim)"; exit 2; }
|
||||||
shift 2
|
shift 2
|
||||||
;;
|
;;
|
||||||
--tag)
|
--tag)
|
||||||
|
|||||||
@@ -1,7 +1,7 @@
|
|||||||
#!/usr/bin/env bash
|
#!/usr/bin/env bash
|
||||||
set -euo pipefail
|
set -euo pipefail
|
||||||
|
|
||||||
# Publish all distro images (full + virgin) to a registry via image.sh --publish
|
# Publish all distro images (full + virgin + slim) to a registry via image.sh --publish
|
||||||
#
|
#
|
||||||
# Required env:
|
# Required env:
|
||||||
# OWNER (e.g. GITHUB_REPOSITORY_OWNER)
|
# OWNER (e.g. GITHUB_REPOSITORY_OWNER)
|
||||||
@@ -11,6 +11,9 @@ set -euo pipefail
|
|||||||
# REGISTRY (default: ghcr.io)
|
# REGISTRY (default: ghcr.io)
|
||||||
# IS_STABLE (default: false)
|
# IS_STABLE (default: false)
|
||||||
# DISTROS (default: "arch debian ubuntu fedora centos")
|
# DISTROS (default: "arch debian ubuntu fedora centos")
|
||||||
|
#
|
||||||
|
# Notes:
|
||||||
|
# - This expects Dockerfile targets: virgin, full (default), slim
|
||||||
|
|
||||||
SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd)"
|
SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd)"
|
||||||
|
|
||||||
@@ -33,7 +36,10 @@ for d in ${DISTROS}; do
|
|||||||
echo "[publish] PKGMGR_DISTRO=${d}"
|
echo "[publish] PKGMGR_DISTRO=${d}"
|
||||||
echo "============================================================"
|
echo "============================================================"
|
||||||
|
|
||||||
|
# ----------------------------------------------------------
|
||||||
# virgin
|
# virgin
|
||||||
|
# -> ghcr.io/<owner>/pkgmgr-<distro>-virgin:{latest,<version>,stable?}
|
||||||
|
# ----------------------------------------------------------
|
||||||
PKGMGR_DISTRO="${d}" bash "${SCRIPT_DIR}/image.sh" \
|
PKGMGR_DISTRO="${d}" bash "${SCRIPT_DIR}/image.sh" \
|
||||||
--publish \
|
--publish \
|
||||||
--registry "${REGISTRY}" \
|
--registry "${REGISTRY}" \
|
||||||
@@ -42,13 +48,29 @@ for d in ${DISTROS}; do
|
|||||||
--stable "${IS_STABLE}" \
|
--stable "${IS_STABLE}" \
|
||||||
--target virgin
|
--target virgin
|
||||||
|
|
||||||
|
# ----------------------------------------------------------
|
||||||
# full (default target)
|
# full (default target)
|
||||||
|
# -> ghcr.io/<owner>/pkgmgr-<distro>:{latest,<version>,stable?}
|
||||||
|
# ----------------------------------------------------------
|
||||||
PKGMGR_DISTRO="${d}" bash "${SCRIPT_DIR}/image.sh" \
|
PKGMGR_DISTRO="${d}" bash "${SCRIPT_DIR}/image.sh" \
|
||||||
--publish \
|
--publish \
|
||||||
--registry "${REGISTRY}" \
|
--registry "${REGISTRY}" \
|
||||||
--owner "${OWNER}" \
|
--owner "${OWNER}" \
|
||||||
--version "${VERSION}" \
|
--version "${VERSION}" \
|
||||||
--stable "${IS_STABLE}"
|
--stable "${IS_STABLE}"
|
||||||
|
|
||||||
|
# ----------------------------------------------------------
|
||||||
|
# slim
|
||||||
|
# -> ghcr.io/<owner>/pkgmgr-<distro>-slim:{latest,<version>,stable?}
|
||||||
|
# + alias for default distro: ghcr.io/<owner>/pkgmgr-slim:{...}
|
||||||
|
# ----------------------------------------------------------
|
||||||
|
PKGMGR_DISTRO="${d}" bash "${SCRIPT_DIR}/image.sh" \
|
||||||
|
--publish \
|
||||||
|
--registry "${REGISTRY}" \
|
||||||
|
--owner "${OWNER}" \
|
||||||
|
--version "${VERSION}" \
|
||||||
|
--stable "${IS_STABLE}" \
|
||||||
|
--target slim
|
||||||
done
|
done
|
||||||
|
|
||||||
echo
|
echo
|
||||||
|
|||||||
@@ -1,7 +1,7 @@
|
|||||||
#!/usr/bin/env bash
|
#!/usr/bin/env bash
|
||||||
set -euo pipefail
|
set -euo pipefail
|
||||||
|
|
||||||
echo "[docker] Starting package-manager container"
|
echo "[docker-pkgmgr] Starting package-manager container"
|
||||||
|
|
||||||
# ---------------------------------------------------------------------------
|
# ---------------------------------------------------------------------------
|
||||||
# Log distribution info
|
# Log distribution info
|
||||||
@@ -9,19 +9,19 @@ echo "[docker] Starting package-manager container"
|
|||||||
if [[ -f /etc/os-release ]]; then
|
if [[ -f /etc/os-release ]]; then
|
||||||
# shellcheck disable=SC1091
|
# shellcheck disable=SC1091
|
||||||
. /etc/os-release
|
. /etc/os-release
|
||||||
echo "[docker] Detected distro: ${ID:-unknown} (like: ${ID_LIKE:-})"
|
echo "[docker-pkgmgr] Detected distro: ${ID:-unknown} (like: ${ID_LIKE:-})"
|
||||||
fi
|
fi
|
||||||
|
|
||||||
# Always use /src (mounted from host) as working directory
|
# Always use /opt/src/pkgmgr (mounted from host) as working directory
|
||||||
echo "[docker] Using /src as working directory"
|
echo "[docker-pkgmgr] Using /opt/src/pkgmgr as working directory"
|
||||||
cd /src
|
cd /opt/src/pkgmgr
|
||||||
|
|
||||||
# ---------------------------------------------------------------------------
|
# ---------------------------------------------------------------------------
|
||||||
# DEV mode: rebuild package-manager from the mounted /src tree
|
# DEV mode: rebuild package-manager from the mounted /opt/src/pkgmgr tree
|
||||||
# ---------------------------------------------------------------------------
|
# ---------------------------------------------------------------------------
|
||||||
if [[ "${REINSTALL_PKGMGR:-0}" == "1" ]]; then
|
if [[ "${REINSTALL_PKGMGR:-0}" == "1" ]]; then
|
||||||
echo "[docker] DEV mode enabled (REINSTALL_PKGMGR=1)"
|
echo "[docker-pkgmgr] DEV mode enabled (REINSTALL_PKGMGR=1)"
|
||||||
echo "[docker] Rebuilding package-manager from /src via scripts/installation/package.sh..."
|
echo "[docker-pkgmgr] Rebuilding package-manager from /opt/src/pkgmgr via scripts/installation/package.sh..."
|
||||||
bash scripts/installation/package.sh || exit 1
|
bash scripts/installation/package.sh || exit 1
|
||||||
fi
|
fi
|
||||||
|
|
||||||
@@ -29,9 +29,9 @@ fi
|
|||||||
# Hand off to pkgmgr or arbitrary command
|
# Hand off to pkgmgr or arbitrary command
|
||||||
# ---------------------------------------------------------------------------
|
# ---------------------------------------------------------------------------
|
||||||
if [[ $# -eq 0 ]]; then
|
if [[ $# -eq 0 ]]; then
|
||||||
echo "[docker] No arguments provided. Showing pkgmgr help..."
|
echo "[docker-pkgmgr] No arguments provided. Showing pkgmgr help..."
|
||||||
exec pkgmgr --help
|
exec pkgmgr --help
|
||||||
else
|
else
|
||||||
echo "[docker] Executing command: $*"
|
echo "[docker-pkgmgr] Executing command: $*"
|
||||||
exec "$@"
|
exec "$@"
|
||||||
fi
|
fi
|
||||||
|
|||||||
130
scripts/docker/slim.sh
Normal file
130
scripts/docker/slim.sh
Normal file
@@ -0,0 +1,130 @@
|
|||||||
|
#!/usr/bin/env bash
|
||||||
|
set -euo pipefail
|
||||||
|
|
||||||
|
log() { echo "[cleanup] $*"; }
|
||||||
|
warn() { echo "[cleanup][WARN] $*" >&2; }
|
||||||
|
|
||||||
|
MODE="${MODE:-safe}" # safe | aggressive
|
||||||
|
# safe: caches/logs/tmp only
|
||||||
|
# aggressive: safe + docs/man/info (optional)
|
||||||
|
|
||||||
|
ID="unknown"
|
||||||
|
if [ -f /etc/os-release ]; then
|
||||||
|
# shellcheck disable=SC1091
|
||||||
|
. /etc/os-release
|
||||||
|
ID="${ID:-unknown}"
|
||||||
|
fi
|
||||||
|
|
||||||
|
log "Starting image cleanup"
|
||||||
|
log "Mode: ${MODE}"
|
||||||
|
log "Detected OS: ${ID}"
|
||||||
|
|
||||||
|
# ------------------------------------------------------------
|
||||||
|
# Package manager caches (SAFE)
|
||||||
|
# ------------------------------------------------------------
|
||||||
|
case "${ID}" in
|
||||||
|
alpine)
|
||||||
|
log "Cleaning apk cache"
|
||||||
|
if [ -d /var/cache/apk ]; then
|
||||||
|
du -sh /var/cache/apk || true
|
||||||
|
rm -rvf /var/cache/apk/* || true
|
||||||
|
else
|
||||||
|
log "apk cache directory not present (already clean)"
|
||||||
|
fi
|
||||||
|
;;
|
||||||
|
arch)
|
||||||
|
log "Cleaning pacman cache"
|
||||||
|
du -sh /var/cache/pacman/pkg 2>/dev/null || true
|
||||||
|
pacman -Scc --noconfirm || true
|
||||||
|
rm -rvf /var/cache/pacman/pkg/* || true
|
||||||
|
;;
|
||||||
|
debian|ubuntu)
|
||||||
|
log "Cleaning apt cache"
|
||||||
|
du -sh /var/lib/apt/lists 2>/dev/null || true
|
||||||
|
apt-get clean || true
|
||||||
|
rm -rvf /var/lib/apt/lists/* || true
|
||||||
|
;;
|
||||||
|
fedora)
|
||||||
|
log "Cleaning dnf cache"
|
||||||
|
du -sh /var/cache/dnf 2>/dev/null || true
|
||||||
|
dnf clean all || true
|
||||||
|
rm -rvf /var/cache/dnf/* || true
|
||||||
|
;;
|
||||||
|
centos|rhel)
|
||||||
|
log "Cleaning yum/dnf cache"
|
||||||
|
du -sh /var/cache/yum /var/cache/dnf 2>/dev/null || true
|
||||||
|
(command -v dnf >/dev/null 2>&1 && dnf clean all) || true
|
||||||
|
(command -v yum >/dev/null 2>&1 && yum clean all) || true
|
||||||
|
rm -rvf /var/cache/yum/* /var/cache/dnf/* || true
|
||||||
|
;;
|
||||||
|
*)
|
||||||
|
warn "Unknown distro '${ID}' — skipping package manager cleanup"
|
||||||
|
;;
|
||||||
|
esac
|
||||||
|
|
||||||
|
# ------------------------------------------------------------
|
||||||
|
# Python caches (SAFE)
|
||||||
|
# ------------------------------------------------------------
|
||||||
|
log "Cleaning pip cache"
|
||||||
|
du -sh /root/.cache/pip 2>/dev/null || true
|
||||||
|
rm -rvf /root/.cache/pip 2>/dev/null || true
|
||||||
|
rm -rvf /home/*/.cache/pip 2>/dev/null || true
|
||||||
|
|
||||||
|
log "Cleaning __pycache__ directories"
|
||||||
|
find /opt /usr /root /home -type d -name "__pycache__" -print -prune 2>/dev/null || true
|
||||||
|
find /opt /usr /root /home -type d -name "__pycache__" -prune -exec rm -rvf {} + 2>/dev/null || true
|
||||||
|
|
||||||
|
# ------------------------------------------------------------
|
||||||
|
# Logs (SAFE)
|
||||||
|
# ------------------------------------------------------------
|
||||||
|
log "Truncating log files (keeping paths intact)"
|
||||||
|
if [ -d /var/log ]; then
|
||||||
|
find /var/log -type f -name "*.log" -print 2>/dev/null || true
|
||||||
|
find /var/log -type f -name "*.log" -exec sh -lc ': > "$1" 2>/dev/null || true' _ {} \; 2>/dev/null || true
|
||||||
|
|
||||||
|
find /var/log -type f -name "*.out" -print 2>/dev/null || true
|
||||||
|
find /var/log -type f -name "*.out" -exec sh -lc ': > "$1" 2>/dev/null || true' _ {} \; 2>/dev/null || true
|
||||||
|
fi
|
||||||
|
|
||||||
|
if command -v journalctl >/dev/null 2>&1; then
|
||||||
|
log "Vacuuming journald logs"
|
||||||
|
journalctl --disk-usage || true
|
||||||
|
journalctl --vacuum-size=10M || true
|
||||||
|
journalctl --vacuum-time=1s || true
|
||||||
|
journalctl --disk-usage || true
|
||||||
|
else
|
||||||
|
log "journald not present (skipping)"
|
||||||
|
fi
|
||||||
|
|
||||||
|
# ------------------------------------------------------------
|
||||||
|
# Temporary files (SAFE)
|
||||||
|
# ------------------------------------------------------------
|
||||||
|
log "Cleaning temporary directories"
|
||||||
|
if [ -d /tmp ]; then
|
||||||
|
du -sh /tmp 2>/dev/null || true
|
||||||
|
rm -rvf /tmp/* || true
|
||||||
|
fi
|
||||||
|
|
||||||
|
if [ -d /var/tmp ]; then
|
||||||
|
du -sh /var/tmp 2>/dev/null || true
|
||||||
|
rm -rvf /var/tmp/* || true
|
||||||
|
fi
|
||||||
|
|
||||||
|
# ------------------------------------------------------------
|
||||||
|
# Generic caches (SAFE)
|
||||||
|
# ------------------------------------------------------------
|
||||||
|
log "Cleaning generic caches"
|
||||||
|
du -sh /root/.cache 2>/dev/null || true
|
||||||
|
rm -rvf /root/.cache/* 2>/dev/null || true
|
||||||
|
rm -rvf /home/*/.cache/* 2>/dev/null || true
|
||||||
|
|
||||||
|
# ------------------------------------------------------------
|
||||||
|
# Optional aggressive extras (still safe for runtime)
|
||||||
|
# ------------------------------------------------------------
|
||||||
|
if [[ "${MODE}" == "aggressive" ]]; then
|
||||||
|
log "Aggressive mode enabled: removing docs/man/info"
|
||||||
|
du -sh /usr/share/doc /usr/share/man /usr/share/info 2>/dev/null || true
|
||||||
|
rm -rvf /usr/share/doc/* /usr/share/man/* /usr/share/info/* 2>/dev/null || true
|
||||||
|
fi
|
||||||
|
|
||||||
|
log "Cleanup finished successfully"
|
||||||
14
scripts/github/common/check-tagged-commit-on-main.sh
Normal file
14
scripts/github/common/check-tagged-commit-on-main.sh
Normal file
@@ -0,0 +1,14 @@
|
|||||||
|
#!/usr/bin/env bash
|
||||||
|
set -euo pipefail
|
||||||
|
|
||||||
|
TARGET_SHA="${TARGET_SHA:-${GITHUB_SHA:?GITHUB_SHA must be set}}"
|
||||||
|
|
||||||
|
git fetch --no-tags origin main
|
||||||
|
|
||||||
|
if git merge-base --is-ancestor "${TARGET_SHA}" "origin/main"; then
|
||||||
|
echo "is_on_main=true" >> "$GITHUB_OUTPUT"
|
||||||
|
echo "Target commit ${TARGET_SHA} is contained in origin/main."
|
||||||
|
else
|
||||||
|
echo "is_on_main=false" >> "$GITHUB_OUTPUT"
|
||||||
|
echo "Target commit ${TARGET_SHA} is not contained in origin/main. Skipping main-only action."
|
||||||
|
fi
|
||||||
43
scripts/github/mark-stable/mark-stable-if-highest-version.sh
Normal file
43
scripts/github/mark-stable/mark-stable-if-highest-version.sh
Normal file
@@ -0,0 +1,43 @@
|
|||||||
|
#!/usr/bin/env bash
|
||||||
|
set -euo pipefail
|
||||||
|
|
||||||
|
git config user.name "github-actions[bot]"
|
||||||
|
git config user.email "github-actions[bot]@users.noreply.github.com"
|
||||||
|
|
||||||
|
echo "Ref: $GITHUB_REF"
|
||||||
|
echo "SHA: $GITHUB_SHA"
|
||||||
|
|
||||||
|
VERSION="${GITHUB_REF#refs/tags/}"
|
||||||
|
echo "Current version tag: ${VERSION}"
|
||||||
|
|
||||||
|
echo "Collecting all version tags..."
|
||||||
|
ALL_V_TAGS="$(git tag --list 'v*' || true)"
|
||||||
|
|
||||||
|
if [[ -z "${ALL_V_TAGS}" ]]; then
|
||||||
|
echo "No version tags found. Skipping stable update."
|
||||||
|
exit 0
|
||||||
|
fi
|
||||||
|
|
||||||
|
echo "All version tags:"
|
||||||
|
echo "${ALL_V_TAGS}"
|
||||||
|
|
||||||
|
LATEST_TAG="$(printf '%s\n' "${ALL_V_TAGS}" | sort -V | tail -n1)"
|
||||||
|
|
||||||
|
echo "Highest version tag: ${LATEST_TAG}"
|
||||||
|
|
||||||
|
if [[ "${VERSION}" != "${LATEST_TAG}" ]]; then
|
||||||
|
echo "Current version ${VERSION} is NOT the highest version."
|
||||||
|
echo "Stable tag will NOT be updated."
|
||||||
|
exit 0
|
||||||
|
fi
|
||||||
|
|
||||||
|
echo "Current version ${VERSION} IS the highest version."
|
||||||
|
echo "Updating 'stable' tag..."
|
||||||
|
|
||||||
|
git tag -d stable 2>/dev/null || true
|
||||||
|
git push origin :refs/tags/stable || true
|
||||||
|
|
||||||
|
git tag stable "$GITHUB_SHA"
|
||||||
|
git push origin stable
|
||||||
|
|
||||||
|
echo "Stable tag updated to ${VERSION}."
|
||||||
43
scripts/github/mark-stable/wait-for-main-ci-success.sh
Normal file
43
scripts/github/mark-stable/wait-for-main-ci-success.sh
Normal file
@@ -0,0 +1,43 @@
|
|||||||
|
#!/usr/bin/env bash
|
||||||
|
set -euo pipefail
|
||||||
|
|
||||||
|
SHA="${GITHUB_SHA}"
|
||||||
|
API_URL="https://api.github.com/repos/${GITHUB_REPOSITORY}/actions/workflows/ci.yml/runs?head_sha=${SHA}&event=push&per_page=20"
|
||||||
|
WAIT_INTERVAL_SECONDS=20
|
||||||
|
MAX_ATTEMPTS=990 # 5 hours 30 minutes max wait
|
||||||
|
|
||||||
|
STATUS=""
|
||||||
|
CONCLUSION=""
|
||||||
|
|
||||||
|
echo "Waiting for CI on main for ${SHA} (up to 5 hours 30 minutes)..."
|
||||||
|
for attempt in $(seq 1 "${MAX_ATTEMPTS}"); do
|
||||||
|
RESPONSE="$(curl -fsSL \
|
||||||
|
-H "Authorization: Bearer ${GH_TOKEN}" \
|
||||||
|
-H "Accept: application/vnd.github+json" \
|
||||||
|
"${API_URL}")"
|
||||||
|
|
||||||
|
STATUS="$(printf '%s' "${RESPONSE}" | jq -r '.workflow_runs[] | select(.head_branch=="main") | .status' | head -n1)"
|
||||||
|
CONCLUSION="$(printf '%s' "${RESPONSE}" | jq -r '.workflow_runs[] | select(.head_branch=="main") | .conclusion' | head -n1)"
|
||||||
|
|
||||||
|
if [[ -n "${STATUS}" ]]; then
|
||||||
|
echo "CI status=${STATUS} conclusion=${CONCLUSION:-none} (attempt ${attempt}/${MAX_ATTEMPTS})"
|
||||||
|
else
|
||||||
|
echo "No CI run for main found yet (attempt ${attempt}/${MAX_ATTEMPTS})"
|
||||||
|
fi
|
||||||
|
|
||||||
|
if [[ "${STATUS}" == "completed" ]]; then
|
||||||
|
if [[ "${CONCLUSION}" == "success" ]]; then
|
||||||
|
echo "CI succeeded for ${SHA}."
|
||||||
|
break
|
||||||
|
fi
|
||||||
|
echo "CI failed for ${SHA} (conclusion=${CONCLUSION})."
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
sleep "${WAIT_INTERVAL_SECONDS}"
|
||||||
|
done
|
||||||
|
|
||||||
|
if [[ "${STATUS}" != "completed" || "${CONCLUSION}" != "success" ]]; then
|
||||||
|
echo "Timed out waiting for successful CI on main for ${SHA}."
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
@@ -0,0 +1,8 @@
|
|||||||
|
#!/usr/bin/env bash
|
||||||
|
set -euo pipefail
|
||||||
|
|
||||||
|
WORKFLOW_RUN_SHA="${WORKFLOW_RUN_SHA:?WORKFLOW_RUN_SHA must be set}"
|
||||||
|
|
||||||
|
git checkout -f "${WORKFLOW_RUN_SHA}"
|
||||||
|
git fetch --tags --force
|
||||||
|
git tag --list 'stable' 'v*' --sort=version:refname | tail -n 20
|
||||||
@@ -0,0 +1,23 @@
|
|||||||
|
#!/usr/bin/env bash
|
||||||
|
set -euo pipefail
|
||||||
|
|
||||||
|
SHA="$(git rev-parse HEAD)"
|
||||||
|
|
||||||
|
V_TAG="$(git tag --points-at "${SHA}" --list 'v*' | sort -V | tail -n1)"
|
||||||
|
if [[ -z "${V_TAG}" ]]; then
|
||||||
|
echo "No version tag found for ${SHA}. Skipping publish."
|
||||||
|
echo "should_publish=false" >> "$GITHUB_OUTPUT"
|
||||||
|
exit 0
|
||||||
|
fi
|
||||||
|
|
||||||
|
VERSION="${V_TAG#v}"
|
||||||
|
|
||||||
|
STABLE_SHA="$(git rev-parse -q --verify 'refs/tags/stable^{commit}' 2>/dev/null || true)"
|
||||||
|
IS_STABLE=false
|
||||||
|
[[ -n "${STABLE_SHA}" && "${STABLE_SHA}" == "${SHA}" ]] && IS_STABLE=true
|
||||||
|
|
||||||
|
{
|
||||||
|
echo "should_publish=true"
|
||||||
|
echo "version=${VERSION}"
|
||||||
|
echo "is_stable=${IS_STABLE}"
|
||||||
|
} >> "$GITHUB_OUTPUT"
|
||||||
@@ -0,0 +1,8 @@
|
|||||||
|
#!/usr/bin/env bash
|
||||||
|
set -euo pipefail
|
||||||
|
|
||||||
|
: "${OWNER:?OWNER must be set}"
|
||||||
|
: "${VERSION:?VERSION must be set}"
|
||||||
|
: "${IS_STABLE:?IS_STABLE must be set}"
|
||||||
|
|
||||||
|
bash scripts/build/publish.sh
|
||||||
@@ -38,11 +38,7 @@ echo "[aur-builder-setup] Configuring sudoers for aur_builder..."
|
|||||||
${ROOT_CMD} bash -c "echo '%aur_builder ALL=(ALL) NOPASSWD: /usr/bin/pacman' > /etc/sudoers.d/aur_builder"
|
${ROOT_CMD} bash -c "echo '%aur_builder ALL=(ALL) NOPASSWD: /usr/bin/pacman' > /etc/sudoers.d/aur_builder"
|
||||||
${ROOT_CMD} chmod 0440 /etc/sudoers.d/aur_builder
|
${ROOT_CMD} chmod 0440 /etc/sudoers.d/aur_builder
|
||||||
|
|
||||||
if command -v sudo >/dev/null 2>&1; then
|
RUN_AS_AUR=(runuser -u aur_builder -- bash -c)
|
||||||
RUN_AS_AUR=(sudo -u aur_builder bash -lc)
|
|
||||||
else
|
|
||||||
RUN_AS_AUR=(su - aur_builder -c)
|
|
||||||
fi
|
|
||||||
|
|
||||||
echo "[aur-builder-setup] Ensuring yay is installed for aur_builder..."
|
echo "[aur-builder-setup] Ensuring yay is installed for aur_builder..."
|
||||||
|
|
||||||
|
|||||||
@@ -6,13 +6,22 @@ SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
|
|||||||
echo "[arch/dependencies] Installing Arch build dependencies..."
|
echo "[arch/dependencies] Installing Arch build dependencies..."
|
||||||
|
|
||||||
pacman -Syu --noconfirm
|
pacman -Syu --noconfirm
|
||||||
|
|
||||||
|
if ! pacman-key --list-sigs &>/dev/null; then
|
||||||
|
echo "[arch/dependencies] Initializing pacman keyring..."
|
||||||
|
pacman-key --init
|
||||||
|
pacman-key --populate archlinux
|
||||||
|
fi
|
||||||
|
|
||||||
pacman -S --noconfirm --needed \
|
pacman -S --noconfirm --needed \
|
||||||
base-devel \
|
base-devel \
|
||||||
git \
|
git \
|
||||||
|
gnupg \
|
||||||
rsync \
|
rsync \
|
||||||
curl \
|
curl \
|
||||||
ca-certificates \
|
ca-certificates \
|
||||||
python \
|
python \
|
||||||
|
python-pip \
|
||||||
xz
|
xz
|
||||||
|
|
||||||
pacman -Scc --noconfirm
|
pacman -Scc --noconfirm
|
||||||
|
|||||||
@@ -6,7 +6,7 @@ echo "[arch/package] Building Arch package (makepkg --nodeps) in an isolated bui
|
|||||||
SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
|
SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
|
||||||
PROJECT_ROOT="$(cd "${SCRIPT_DIR}/../../.." && pwd)"
|
PROJECT_ROOT="$(cd "${SCRIPT_DIR}/../../.." && pwd)"
|
||||||
|
|
||||||
# We must not build inside /src (mounted repo). Build in /tmp to avoid permission issues.
|
# We must not build inside /opt/src/pkgmgr (mounted repo). Build in /tmp to avoid permission issues.
|
||||||
BUILD_ROOT="/tmp/package-manager-arch-build"
|
BUILD_ROOT="/tmp/package-manager-arch-build"
|
||||||
PKG_SRC_DIR="${PROJECT_ROOT}/packaging/arch"
|
PKG_SRC_DIR="${PROJECT_ROOT}/packaging/arch"
|
||||||
PKG_BUILD_DIR="${BUILD_ROOT}/packaging/arch"
|
PKG_BUILD_DIR="${BUILD_ROOT}/packaging/arch"
|
||||||
@@ -47,7 +47,7 @@ echo "[arch/package] Using 'aur_builder' user for makepkg..."
|
|||||||
chown -R aur_builder:aur_builder "${BUILD_ROOT}"
|
chown -R aur_builder:aur_builder "${BUILD_ROOT}"
|
||||||
|
|
||||||
echo "[arch/package] Running makepkg in: ${PKG_BUILD_DIR}"
|
echo "[arch/package] Running makepkg in: ${PKG_BUILD_DIR}"
|
||||||
su aur_builder -c "cd '${PKG_BUILD_DIR}' && rm -f package-manager-*.pkg.tar.* && makepkg --noconfirm --clean --nodeps"
|
runuser -u aur_builder -- bash -c "cd '${PKG_BUILD_DIR}' && rm -f package-manager-*.pkg.tar.* && makepkg --noconfirm --clean --nodeps"
|
||||||
|
|
||||||
echo "[arch/package] Installing generated Arch package..."
|
echo "[arch/package] Installing generated Arch package..."
|
||||||
pkg_path="$(find "${PKG_BUILD_DIR}" -maxdepth 1 -type f -name 'package-manager-*.pkg.tar.*' | head -n1)"
|
pkg_path="$(find "${PKG_BUILD_DIR}" -maxdepth 1 -type f -name 'package-manager-*.pkg.tar.*' | head -n1)"
|
||||||
|
|||||||
@@ -6,6 +6,7 @@ echo "[centos/dependencies] Installing CentOS build dependencies..."
|
|||||||
dnf -y update
|
dnf -y update
|
||||||
dnf -y install \
|
dnf -y install \
|
||||||
git \
|
git \
|
||||||
|
gnupg2 \
|
||||||
rsync \
|
rsync \
|
||||||
rpm-build \
|
rpm-build \
|
||||||
make \
|
make \
|
||||||
@@ -14,6 +15,7 @@ dnf -y install \
|
|||||||
curl-minimal \
|
curl-minimal \
|
||||||
ca-certificates \
|
ca-certificates \
|
||||||
python3 \
|
python3 \
|
||||||
|
python3-pip \
|
||||||
sudo \
|
sudo \
|
||||||
xz
|
xz
|
||||||
|
|
||||||
|
|||||||
@@ -9,12 +9,14 @@ DEBIAN_FRONTEND=noninteractive apt-get install -y --no-install-recommends \
|
|||||||
debhelper \
|
debhelper \
|
||||||
dpkg-dev \
|
dpkg-dev \
|
||||||
git \
|
git \
|
||||||
|
gnupg \
|
||||||
rsync \
|
rsync \
|
||||||
bash \
|
bash \
|
||||||
curl \
|
curl \
|
||||||
ca-certificates \
|
ca-certificates \
|
||||||
python3 \
|
python3 \
|
||||||
python3-venv \
|
python3-venv \
|
||||||
|
python3-pip \
|
||||||
xz-utils
|
xz-utils
|
||||||
|
|
||||||
rm -rf /var/lib/apt/lists/*
|
rm -rf /var/lib/apt/lists/*
|
||||||
|
|||||||
@@ -6,6 +6,7 @@ echo "[fedora/dependencies] Installing Fedora build dependencies..."
|
|||||||
dnf -y update
|
dnf -y update
|
||||||
dnf -y install \
|
dnf -y install \
|
||||||
git \
|
git \
|
||||||
|
gnupg2 \
|
||||||
rsync \
|
rsync \
|
||||||
rpm-build \
|
rpm-build \
|
||||||
make \
|
make \
|
||||||
@@ -14,6 +15,7 @@ dnf -y install \
|
|||||||
curl \
|
curl \
|
||||||
ca-certificates \
|
ca-certificates \
|
||||||
python3 \
|
python3 \
|
||||||
|
python3-pip \
|
||||||
xz
|
xz
|
||||||
|
|
||||||
dnf clean all
|
dnf clean all
|
||||||
|
|||||||
@@ -2,8 +2,8 @@
|
|||||||
set -euo pipefail
|
set -euo pipefail
|
||||||
|
|
||||||
if [[ "${EUID:-$(id -u)}" -ne 0 ]]; then
|
if [[ "${EUID:-$(id -u)}" -ne 0 ]]; then
|
||||||
echo "[installation/install] Warning: Installation is just possible via root."
|
echo "[installation/install] ERROR: Installation requires root. Re-run with sudo." >&2
|
||||||
exit 0
|
exit 1
|
||||||
fi
|
fi
|
||||||
|
|
||||||
echo "[installation] Running as root (EUID=0)."
|
echo "[installation] Running as root (EUID=0)."
|
||||||
|
|||||||
@@ -9,6 +9,7 @@ DEBIAN_FRONTEND=noninteractive apt-get install -y --no-install-recommends \
|
|||||||
debhelper \
|
debhelper \
|
||||||
dpkg-dev \
|
dpkg-dev \
|
||||||
git \
|
git \
|
||||||
|
gnupg \
|
||||||
tzdata \
|
tzdata \
|
||||||
lsb-release \
|
lsb-release \
|
||||||
rsync \
|
rsync \
|
||||||
@@ -17,6 +18,7 @@ DEBIAN_FRONTEND=noninteractive apt-get install -y --no-install-recommends \
|
|||||||
make \
|
make \
|
||||||
python3 \
|
python3 \
|
||||||
python3-venv \
|
python3-venv \
|
||||||
|
python3-pip \
|
||||||
ca-certificates \
|
ca-certificates \
|
||||||
xz-utils
|
xz-utils
|
||||||
|
|
||||||
|
|||||||
@@ -2,6 +2,16 @@
|
|||||||
set -euo pipefail
|
set -euo pipefail
|
||||||
|
|
||||||
FLAKE_DIR="/usr/lib/package-manager"
|
FLAKE_DIR="/usr/lib/package-manager"
|
||||||
|
NIX_LIB_DIR="${FLAKE_DIR}/nix/lib"
|
||||||
|
RETRY_LIB="${NIX_LIB_DIR}/retry_403.sh"
|
||||||
|
|
||||||
|
# ---------------------------------------------------------------------------
|
||||||
|
# Hard requirement: retry helper must exist (fail if missing)
|
||||||
|
# ---------------------------------------------------------------------------
|
||||||
|
if [[ ! -f "${RETRY_LIB}" ]]; then
|
||||||
|
echo "[launcher] ERROR: Required retry helper not found: ${RETRY_LIB}" >&2
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
# ---------------------------------------------------------------------------
|
# ---------------------------------------------------------------------------
|
||||||
# Try to ensure that "nix" is on PATH (common locations + container user)
|
# Try to ensure that "nix" is on PATH (common locations + container user)
|
||||||
@@ -27,17 +37,23 @@ fi
|
|||||||
# ---------------------------------------------------------------------------
|
# ---------------------------------------------------------------------------
|
||||||
if ! command -v nix >/dev/null 2>&1; then
|
if ! command -v nix >/dev/null 2>&1; then
|
||||||
if [[ -x "${FLAKE_DIR}/nix/init.sh" ]]; then
|
if [[ -x "${FLAKE_DIR}/nix/init.sh" ]]; then
|
||||||
"${FLAKE_DIR}/nix/init.sh" || true
|
"${FLAKE_DIR}/nix/init.sh"
|
||||||
fi
|
fi
|
||||||
fi
|
fi
|
||||||
|
|
||||||
# ---------------------------------------------------------------------------
|
if ! command -v nix >/dev/null 2>&1; then
|
||||||
# Primary path: use Nix flake if available
|
echo "[launcher] ERROR: 'nix' binary not found on PATH after init." >&2
|
||||||
# ---------------------------------------------------------------------------
|
echo "[launcher] Nix is required to run pkgmgr (no Python fallback)." >&2
|
||||||
if command -v nix >/dev/null 2>&1; then
|
exit 1
|
||||||
exec nix run "${FLAKE_DIR}#pkgmgr" -- "$@"
|
|
||||||
fi
|
fi
|
||||||
|
|
||||||
echo "[launcher] ERROR: 'nix' binary not found on PATH after init."
|
# ---------------------------------------------------------------------------
|
||||||
echo "[launcher] Nix is required to run pkgmgr (no Python fallback)."
|
# Primary path: use Nix flake if available (with GitHub 403 retry)
|
||||||
exit 1
|
# ---------------------------------------------------------------------------
|
||||||
|
if declare -F run_with_github_403_retry >/dev/null; then
|
||||||
|
# shellcheck source=./scripts/nix/lib/retry_403.sh
|
||||||
|
source "${RETRY_LIB}"
|
||||||
|
exec run_with_github_403_retry nix run "${FLAKE_DIR}#pkgmgr" -- "$@"
|
||||||
|
else
|
||||||
|
exec nix run "${FLAKE_DIR}#pkgmgr" -- "$@"
|
||||||
|
fi
|
||||||
|
|||||||
15
scripts/lint/python.sh
Executable file
15
scripts/lint/python.sh
Executable file
@@ -0,0 +1,15 @@
|
|||||||
|
#!/usr/bin/env bash
|
||||||
|
set -euo pipefail
|
||||||
|
|
||||||
|
echo "============================================================"
|
||||||
|
echo ">>> Running RUFF lint on src and tests (local, no container)"
|
||||||
|
echo "============================================================"
|
||||||
|
|
||||||
|
if ! command -v ruff >/dev/null 2>&1; then
|
||||||
|
echo "ruff is not installed or not on PATH." >&2
|
||||||
|
echo "Install it with: pip install ruff" >&2
|
||||||
|
exit 127
|
||||||
|
fi
|
||||||
|
|
||||||
|
ruff --version
|
||||||
|
ruff check src tests
|
||||||
@@ -49,11 +49,7 @@ install_nix_with_retry() {
|
|||||||
if [[ -n "$run_as" ]]; then
|
if [[ -n "$run_as" ]]; then
|
||||||
chown "$run_as:$run_as" "$installer" 2>/dev/null || true
|
chown "$run_as:$run_as" "$installer" 2>/dev/null || true
|
||||||
echo "[init-nix] Running installer as user '$run_as' ($mode_flag)..."
|
echo "[init-nix] Running installer as user '$run_as' ($mode_flag)..."
|
||||||
if command -v sudo >/dev/null 2>&1; then
|
su - "$run_as" -s /bin/bash -c "bash -lc \"sh '$installer' $mode_flag\""
|
||||||
sudo -u "$run_as" bash -lc "sh '$installer' $mode_flag"
|
|
||||||
else
|
|
||||||
su - "$run_as" -c "sh '$installer' $mode_flag"
|
|
||||||
fi
|
|
||||||
else
|
else
|
||||||
echo "[init-nix] Running installer as current user ($mode_flag)..."
|
echo "[init-nix] Running installer as current user ($mode_flag)..."
|
||||||
sh "$installer" "$mode_flag"
|
sh "$installer" "$mode_flag"
|
||||||
|
|||||||
@@ -36,16 +36,17 @@ real_exe() {
|
|||||||
|
|
||||||
# Resolve nix binary path robustly (works across distros + Arch /usr/sbin)
|
# Resolve nix binary path robustly (works across distros + Arch /usr/sbin)
|
||||||
resolve_nix_bin() {
|
resolve_nix_bin() {
|
||||||
local nix_cmd=""
|
# IMPORTANT: prefer distro-managed locations first.
|
||||||
nix_cmd="$(command -v nix 2>/dev/null || true)"
|
# This avoids pinning /usr/local/bin/nix to a stale user-profile nix binary.
|
||||||
[[ -n "$nix_cmd" ]] && real_exe "$nix_cmd" && return 0
|
|
||||||
|
|
||||||
# IMPORTANT: prefer system locations before /usr/local to avoid self-symlink traps
|
|
||||||
[[ -x /usr/sbin/nix ]] && { echo "/usr/sbin/nix"; return 0; } # Arch package can land here
|
[[ -x /usr/sbin/nix ]] && { echo "/usr/sbin/nix"; return 0; } # Arch package can land here
|
||||||
[[ -x /usr/bin/nix ]] && { echo "/usr/bin/nix"; return 0; }
|
[[ -x /usr/bin/nix ]] && { echo "/usr/bin/nix"; return 0; }
|
||||||
[[ -x /bin/nix ]] && { echo "/bin/nix"; return 0; }
|
[[ -x /bin/nix ]] && { echo "/bin/nix"; return 0; }
|
||||||
|
|
||||||
# /usr/local last, and only if it resolves to a real executable
|
local nix_cmd=""
|
||||||
|
nix_cmd="$(command -v nix 2>/dev/null || true)"
|
||||||
|
[[ -n "$nix_cmd" ]] && real_exe "$nix_cmd" && return 0
|
||||||
|
|
||||||
|
# /usr/local after system locations, and only if it resolves to a real executable
|
||||||
[[ -e /usr/local/bin/nix ]] && real_exe "/usr/local/bin/nix" && return 0
|
[[ -e /usr/local/bin/nix ]] && real_exe "/usr/local/bin/nix" && return 0
|
||||||
|
|
||||||
[[ -x /nix/var/nix/profiles/default/bin/nix ]] && {
|
[[ -x /nix/var/nix/profiles/default/bin/nix ]] && {
|
||||||
|
|||||||
@@ -6,12 +6,13 @@ echo ">>> Running E2E tests: $PKGMGR_DISTRO"
|
|||||||
echo "============================================================"
|
echo "============================================================"
|
||||||
|
|
||||||
docker run --rm \
|
docker run --rm \
|
||||||
-v "$(pwd):/src" \
|
-v "$(pwd):/opt/src/pkgmgr" \
|
||||||
-v "pkgmgr_nix_store_${PKGMGR_DISTRO}:/nix" \
|
-v "pkgmgr_nix_store_${PKGMGR_DISTRO}:/nix" \
|
||||||
-v "pkgmgr_nix_cache_${PKGMGR_DISTRO}:/root/.cache/nix" \
|
-v "pkgmgr_nix_cache_${PKGMGR_DISTRO}:/root/.cache/nix" \
|
||||||
-e REINSTALL_PKGMGR=1 \
|
-e REINSTALL_PKGMGR=1 \
|
||||||
-e TEST_PATTERN="${TEST_PATTERN}" \
|
-e TEST_PATTERN="${TEST_PATTERN}" \
|
||||||
--workdir /src \
|
-e NIX_CONFIG="${NIX_CONFIG}" \
|
||||||
|
--workdir /opt/src/pkgmgr \
|
||||||
"pkgmgr-${PKGMGR_DISTRO}" \
|
"pkgmgr-${PKGMGR_DISTRO}" \
|
||||||
bash -lc '
|
bash -lc '
|
||||||
set -euo pipefail
|
set -euo pipefail
|
||||||
@@ -40,14 +41,14 @@ docker run --rm \
|
|||||||
}
|
}
|
||||||
|
|
||||||
# Mark the mounted repository as safe to avoid Git ownership errors.
|
# Mark the mounted repository as safe to avoid Git ownership errors.
|
||||||
# Newer Git (e.g. on Ubuntu) complains about the gitdir (/src/.git),
|
# Newer Git (e.g. on Ubuntu) complains about the gitdir (/opt/src/pkgmgr/.git),
|
||||||
# older versions about the worktree (/src). Nix turns "." into the
|
# older versions about the worktree (/opt/src/pkgmgr). Nix turns "." into the
|
||||||
# flake input "git+file:///src", which then uses Git under the hood.
|
# flake input "git+file:///opt/src/pkgmgr", which then uses Git under the hood.
|
||||||
if command -v git >/dev/null 2>&1; then
|
if command -v git >/dev/null 2>&1; then
|
||||||
# Worktree path
|
# Worktree path
|
||||||
git config --global --add safe.directory /src || true
|
git config --global --add safe.directory /opt/src/pkgmgr || true
|
||||||
# Gitdir path shown in the "dubious ownership" error
|
# Gitdir path shown in the "dubious ownership" error
|
||||||
git config --global --add safe.directory /src/.git || true
|
git config --global --add safe.directory /opt/src/pkgmgr/.git || true
|
||||||
# Ephemeral CI containers: allow all paths as a last resort
|
# Ephemeral CI containers: allow all paths as a last resort
|
||||||
git config --global --add safe.directory "*" || true
|
git config --global --add safe.directory "*" || true
|
||||||
fi
|
fi
|
||||||
@@ -55,6 +56,6 @@ docker run --rm \
|
|||||||
# Run the E2E tests inside the Nix development shell
|
# Run the E2E tests inside the Nix development shell
|
||||||
nix develop .#default --no-write-lock-file -c \
|
nix develop .#default --no-write-lock-file -c \
|
||||||
python3 -m unittest discover \
|
python3 -m unittest discover \
|
||||||
-s /src/tests/e2e \
|
-s /opt/src/pkgmgr/tests/e2e \
|
||||||
-p "$TEST_PATTERN"
|
-p "$TEST_PATTERN"
|
||||||
'
|
'
|
||||||
|
|||||||
@@ -9,18 +9,19 @@ echo ">>> Image: ${IMAGE}"
|
|||||||
echo "============================================================"
|
echo "============================================================"
|
||||||
|
|
||||||
docker run --rm \
|
docker run --rm \
|
||||||
-v "$(pwd):/src" \
|
-v "$(pwd):/opt/src/pkgmgr" \
|
||||||
-v "pkgmgr_nix_store_${PKGMGR_DISTRO}:/nix" \
|
-v "pkgmgr_nix_store_${PKGMGR_DISTRO}:/nix" \
|
||||||
-v "pkgmgr_nix_cache_${PKGMGR_DISTRO}:/root/.cache/nix" \
|
-v "pkgmgr_nix_cache_${PKGMGR_DISTRO}:/root/.cache/nix" \
|
||||||
--workdir /src \
|
--workdir /opt/src/pkgmgr \
|
||||||
-e REINSTALL_PKGMGR=1 \
|
-e REINSTALL_PKGMGR=1 \
|
||||||
|
-e NIX_CONFIG="${NIX_CONFIG}" \
|
||||||
"${IMAGE}" \
|
"${IMAGE}" \
|
||||||
bash -lc '
|
bash -lc '
|
||||||
set -euo pipefail
|
set -euo pipefail
|
||||||
|
|
||||||
if command -v git >/dev/null 2>&1; then
|
if command -v git >/dev/null 2>&1; then
|
||||||
git config --global --add safe.directory /src || true
|
git config --global --add safe.directory /opt/src/pkgmgr || true
|
||||||
git config --global --add safe.directory /src/.git || true
|
git config --global --add safe.directory /opt/src/pkgmgr/.git || true
|
||||||
git config --global --add safe.directory "*" || true
|
git config --global --add safe.directory "*" || true
|
||||||
fi
|
fi
|
||||||
|
|
||||||
@@ -38,9 +39,9 @@ docker run --rm \
|
|||||||
# ------------------------------------------------------------
|
# ------------------------------------------------------------
|
||||||
# Retry helper for GitHub API rate-limit (HTTP 403)
|
# Retry helper for GitHub API rate-limit (HTTP 403)
|
||||||
# ------------------------------------------------------------
|
# ------------------------------------------------------------
|
||||||
if [[ -f /src/scripts/nix/lib/retry_403.sh ]]; then
|
if [[ -f /opt/src/pkgmgr/scripts/nix/lib/retry_403.sh ]]; then
|
||||||
# shellcheck source=./scripts/nix/lib/retry_403.sh
|
# shellcheck source=./scripts/nix/lib/retry_403.sh
|
||||||
source /src/scripts/nix/lib/retry_403.sh
|
source /opt/src/pkgmgr/scripts/nix/lib/retry_403.sh
|
||||||
elif [[ -f ./scripts/nix/lib/retry_403.sh ]]; then
|
elif [[ -f ./scripts/nix/lib/retry_403.sh ]]; then
|
||||||
# shellcheck source=./scripts/nix/lib/retry_403.sh
|
# shellcheck source=./scripts/nix/lib/retry_403.sh
|
||||||
source ./scripts/nix/lib/retry_403.sh
|
source ./scripts/nix/lib/retry_403.sh
|
||||||
|
|||||||
@@ -1,32 +1,50 @@
|
|||||||
#!/usr/bin/env bash
|
#!/usr/bin/env bash
|
||||||
set -euo pipefail
|
set -euo pipefail
|
||||||
|
|
||||||
IMAGE="pkgmgr-$PKGMGR_DISTRO"
|
IMAGE="pkgmgr-${PKGMGR_DISTRO}"
|
||||||
|
|
||||||
echo
|
echo
|
||||||
echo "------------------------------------------------------------"
|
echo "------------------------------------------------------------"
|
||||||
echo ">>> Testing VENV: $IMAGE"
|
echo ">>> Testing VENV: ${IMAGE}"
|
||||||
echo "------------------------------------------------------------"
|
echo "------------------------------------------------------------"
|
||||||
|
|
||||||
echo "[test-env-virtual] Inspect image metadata:"
|
echo "[test-env-virtual] Inspect image metadata:"
|
||||||
docker image inspect "$IMAGE" | sed -n '1,40p'
|
docker image inspect "${IMAGE}" | sed -n '1,40p'
|
||||||
|
|
||||||
echo "[test-env-virtual] Running: docker run --rm --entrypoint pkgmgr $IMAGE --help"
|
|
||||||
echo
|
echo
|
||||||
|
|
||||||
# Run the command and capture the output
|
# ------------------------------------------------------------
|
||||||
|
# Run VENV-based pkgmgr test inside container
|
||||||
|
# ------------------------------------------------------------
|
||||||
if OUTPUT=$(docker run --rm \
|
if OUTPUT=$(docker run --rm \
|
||||||
-e REINSTALL_PKGMGR=1 \
|
-e REINSTALL_PKGMGR=1 \
|
||||||
-v "pkgmgr_nix_store_${PKGMGR_DISTRO}:/nix" \
|
-v "$(pwd):/opt/src/pkgmgr" \
|
||||||
-v "$(pwd):/src" \
|
-w /opt/src/pkgmgr \
|
||||||
-v "pkgmgr_nix_cache_${PKGMGR_DISTRO}:/root/.cache/nix" \
|
-e NIX_CONFIG="${NIX_CONFIG}" \
|
||||||
"$IMAGE" 2>&1); then
|
"${IMAGE}" \
|
||||||
|
bash -lc '
|
||||||
|
set -euo pipefail
|
||||||
|
|
||||||
|
echo "[test-env-virtual] Installing pkgmgr (distro package)..."
|
||||||
|
make install
|
||||||
|
|
||||||
|
echo "[test-env-virtual] Setting up Python venv..."
|
||||||
|
make setup-venv
|
||||||
|
|
||||||
|
echo "[test-env-virtual] Activating venv..."
|
||||||
|
. "$HOME/.venvs/pkgmgr/bin/activate"
|
||||||
|
|
||||||
|
echo "[test-env-virtual] Using pkgmgr from:"
|
||||||
|
command -v pkgmgr
|
||||||
|
pkgmgr --help
|
||||||
|
' 2>&1); then
|
||||||
|
|
||||||
echo "$OUTPUT"
|
echo "$OUTPUT"
|
||||||
echo
|
echo
|
||||||
echo "[test-env-virtual] SUCCESS: $IMAGE responded to 'pkgmgr --help'"
|
echo "[test-env-virtual] SUCCESS: venv-based pkgmgr works in ${IMAGE}"
|
||||||
|
|
||||||
else
|
else
|
||||||
echo "$OUTPUT"
|
echo "$OUTPUT"
|
||||||
echo
|
echo
|
||||||
echo "[test-env-virtual] ERROR: $IMAGE failed to run 'pkgmgr --help'"
|
echo "[test-env-virtual] ERROR: venv-based pkgmgr failed in ${IMAGE}"
|
||||||
exit 1
|
exit 1
|
||||||
fi
|
fi
|
||||||
@@ -6,19 +6,20 @@ echo ">>> Running INTEGRATION tests in ${PKGMGR_DISTRO} container"
|
|||||||
echo "============================================================"
|
echo "============================================================"
|
||||||
|
|
||||||
docker run --rm \
|
docker run --rm \
|
||||||
-v "$(pwd):/src" \
|
-v "$(pwd):/opt/src/pkgmgr" \
|
||||||
-v "pkgmgr_nix_store_${PKGMGR_DISTRO}:/nix" \
|
-v "pkgmgr_nix_store_${PKGMGR_DISTRO}:/nix" \
|
||||||
-v "pkgmgr_nix_cache_${PKGMGR_DISTRO}:/root/.cache/nix" \
|
-v "pkgmgr_nix_cache_${PKGMGR_DISTRO}:/root/.cache/nix" \
|
||||||
--workdir /src \
|
--workdir /opt/src/pkgmgr \
|
||||||
-e REINSTALL_PKGMGR=1 \
|
-e REINSTALL_PKGMGR=1 \
|
||||||
-e TEST_PATTERN="${TEST_PATTERN}" \
|
-e TEST_PATTERN="${TEST_PATTERN}" \
|
||||||
|
-e NIX_CONFIG="${NIX_CONFIG}" \
|
||||||
"pkgmgr-${PKGMGR_DISTRO}" \
|
"pkgmgr-${PKGMGR_DISTRO}" \
|
||||||
bash -lc '
|
bash -lc '
|
||||||
set -e;
|
set -e;
|
||||||
git config --global --add safe.directory /src || true;
|
git config --global --add safe.directory /opt/src/pkgmgr || true;
|
||||||
nix develop .#default --no-write-lock-file -c \
|
nix develop .#default --no-write-lock-file -c \
|
||||||
python3 -m unittest discover \
|
python3 -m unittest discover \
|
||||||
-s tests/integration \
|
-s tests/integration \
|
||||||
-t /src \
|
-t /opt/src/pkgmgr \
|
||||||
-p "$TEST_PATTERN";
|
-p "$TEST_PATTERN";
|
||||||
'
|
'
|
||||||
|
|||||||
@@ -6,19 +6,20 @@ echo ">>> Running UNIT tests in ${PKGMGR_DISTRO} container"
|
|||||||
echo "============================================================"
|
echo "============================================================"
|
||||||
|
|
||||||
docker run --rm \
|
docker run --rm \
|
||||||
-v "$(pwd):/src" \
|
-v "$(pwd):/opt/src/pkgmgr" \
|
||||||
-v "pkgmgr_nix_cache_${PKGMGR_DISTRO}:/root/.cache/nix" \
|
-v "pkgmgr_nix_cache_${PKGMGR_DISTRO}:/root/.cache/nix" \
|
||||||
-v "pkgmgr_nix_store_${PKGMGR_DISTRO}:/nix" \
|
-v "pkgmgr_nix_store_${PKGMGR_DISTRO}:/nix" \
|
||||||
--workdir /src \
|
--workdir /opt/src/pkgmgr \
|
||||||
-e REINSTALL_PKGMGR=1 \
|
-e REINSTALL_PKGMGR=1 \
|
||||||
-e TEST_PATTERN="${TEST_PATTERN}" \
|
-e TEST_PATTERN="${TEST_PATTERN}" \
|
||||||
|
-e NIX_CONFIG="${NIX_CONFIG}" \
|
||||||
"pkgmgr-${PKGMGR_DISTRO}" \
|
"pkgmgr-${PKGMGR_DISTRO}" \
|
||||||
bash -lc '
|
bash -lc '
|
||||||
set -e;
|
set -e;
|
||||||
git config --global --add safe.directory /src || true;
|
git config --global --add safe.directory /opt/src/pkgmgr || true;
|
||||||
nix develop .#default --no-write-lock-file -c \
|
nix develop .#default --no-write-lock-file -c \
|
||||||
python3 -m unittest discover \
|
python3 -m unittest discover \
|
||||||
-s tests/unit \
|
-s tests/unit \
|
||||||
-t /src \
|
-t /opt/src/pkgmgr \
|
||||||
-p "$TEST_PATTERN";
|
-p "$TEST_PATTERN";
|
||||||
'
|
'
|
||||||
|
|||||||
@@ -1,6 +1,3 @@
|
|||||||
#!/usr/bin/env python3
|
|
||||||
# -*- coding: utf-8 -*-
|
|
||||||
|
|
||||||
"""
|
"""
|
||||||
Top-level pkgmgr package.
|
Top-level pkgmgr package.
|
||||||
|
|
||||||
|
|||||||
@@ -0,0 +1,6 @@
|
|||||||
|
from __future__ import annotations
|
||||||
|
|
||||||
|
# expose subpackages for patch() / resolve_name() friendliness
|
||||||
|
from . import release as release
|
||||||
|
|
||||||
|
__all__ = ["release"]
|
||||||
|
|||||||
31
src/pkgmgr/actions/archive/__init__.py
Normal file
31
src/pkgmgr/actions/archive/__init__.py
Normal file
@@ -0,0 +1,31 @@
|
|||||||
|
"""Archive fully-checked Markdown files into a README index, then delete them.
|
||||||
|
|
||||||
|
The archive action walks a directory for numbered ``NNN-topic.md`` files
|
||||||
|
(default pattern ``^\\d{3}-[^/]+\\.md$``), promotes every file with zero
|
||||||
|
unchecked ``- [ ]`` task-list markers into a ``## Archive`` index inside
|
||||||
|
the directory README, and deletes the per-file source. Useful for
|
||||||
|
keeping ``docs/requirements/`` (or any other task-tracked spec folder)
|
||||||
|
short and focused on open work.
|
||||||
|
|
||||||
|
The module was extracted from
|
||||||
|
``cli/contributing/requirements/archive`` in infinito-nexus-core so
|
||||||
|
every kpmx-managed repository can rely on the same archival convention
|
||||||
|
without copy-pasting the helpers.
|
||||||
|
"""
|
||||||
|
|
||||||
|
from __future__ import annotations
|
||||||
|
|
||||||
|
from .discovery import iter_archivable_files
|
||||||
|
from .inspect import count_unchecked_items, extract_h1
|
||||||
|
from .readme import existing_archive_entries, merge_archive_section
|
||||||
|
from .workflow import ArchivePlan, run_archive
|
||||||
|
|
||||||
|
__all__ = [
|
||||||
|
"ArchivePlan",
|
||||||
|
"count_unchecked_items",
|
||||||
|
"existing_archive_entries",
|
||||||
|
"extract_h1",
|
||||||
|
"iter_archivable_files",
|
||||||
|
"merge_archive_section",
|
||||||
|
"run_archive",
|
||||||
|
]
|
||||||
53
src/pkgmgr/actions/archive/discovery.py
Normal file
53
src/pkgmgr/actions/archive/discovery.py
Normal file
@@ -0,0 +1,53 @@
|
|||||||
|
"""Locate archivable Markdown files under a target directory."""
|
||||||
|
|
||||||
|
from __future__ import annotations
|
||||||
|
|
||||||
|
import re
|
||||||
|
from collections.abc import Iterable
|
||||||
|
from pathlib import Path
|
||||||
|
|
||||||
|
DEFAULT_FILENAME_PATTERN = re.compile(r"^\d{3}-[^/]+\.md$")
|
||||||
|
TEMPLATE_FILENAME = "000-template.md"
|
||||||
|
|
||||||
|
|
||||||
|
def iter_archivable_files(
|
||||||
|
directory: Path,
|
||||||
|
*,
|
||||||
|
include_template: bool = False,
|
||||||
|
pattern: re.Pattern[str] = DEFAULT_FILENAME_PATTERN,
|
||||||
|
template_filename: str = TEMPLATE_FILENAME,
|
||||||
|
) -> list[Path]:
|
||||||
|
"""Return all files in *directory* whose name matches *pattern*, sorted.
|
||||||
|
|
||||||
|
``000-template.md`` (or whatever *template_filename* matches) is
|
||||||
|
excluded unless *include_template* is true. The check is filename
|
||||||
|
based; nested directories are not traversed.
|
||||||
|
"""
|
||||||
|
if not directory.is_dir():
|
||||||
|
return []
|
||||||
|
files: list[Path] = []
|
||||||
|
for path in sorted(directory.iterdir()):
|
||||||
|
if not path.is_file() or not pattern.match(path.name):
|
||||||
|
continue
|
||||||
|
if not include_template and path.name == template_filename:
|
||||||
|
continue
|
||||||
|
files.append(path)
|
||||||
|
return files
|
||||||
|
|
||||||
|
|
||||||
|
def filter_archivable_files(
|
||||||
|
paths: Iterable[Path],
|
||||||
|
*,
|
||||||
|
include_template: bool = False,
|
||||||
|
pattern: re.Pattern[str] = DEFAULT_FILENAME_PATTERN,
|
||||||
|
template_filename: str = TEMPLATE_FILENAME,
|
||||||
|
) -> list[Path]:
|
||||||
|
"""Same predicate as :func:`iter_archivable_files`, applied to an iterable."""
|
||||||
|
result: list[Path] = []
|
||||||
|
for path in paths:
|
||||||
|
if not path.is_file() or not pattern.match(path.name):
|
||||||
|
continue
|
||||||
|
if not include_template and path.name == template_filename:
|
||||||
|
continue
|
||||||
|
result.append(path)
|
||||||
|
return result
|
||||||
35
src/pkgmgr/actions/archive/inspect.py
Normal file
35
src/pkgmgr/actions/archive/inspect.py
Normal file
@@ -0,0 +1,35 @@
|
|||||||
|
"""Parse a single Markdown file: H1 heading and task-list completeness."""
|
||||||
|
|
||||||
|
from __future__ import annotations
|
||||||
|
|
||||||
|
import re
|
||||||
|
from pathlib import Path
|
||||||
|
|
||||||
|
H1_RE = re.compile(r"^#\s+(?P<title>\S.*?)\s*$")
|
||||||
|
UNCHECKED_TASK_RE = re.compile(r"^\s*[-*+]\s+\[\s\]\s")
|
||||||
|
|
||||||
|
|
||||||
|
def extract_h1(path: Path) -> str | None:
|
||||||
|
"""Return the first H1 title in *path* or ``None`` if there is none."""
|
||||||
|
try:
|
||||||
|
with path.open(encoding="utf-8") as fh:
|
||||||
|
for line in fh:
|
||||||
|
match = H1_RE.match(line.rstrip("\n"))
|
||||||
|
if match:
|
||||||
|
return match.group("title")
|
||||||
|
except OSError:
|
||||||
|
return None
|
||||||
|
return None
|
||||||
|
|
||||||
|
|
||||||
|
def count_unchecked_items(path: Path) -> int:
|
||||||
|
"""Return the number of ``- [ ]`` task-list markers anywhere in *path*.
|
||||||
|
|
||||||
|
A non-zero count means the file is not yet fully complete and MUST
|
||||||
|
NOT be archived.
|
||||||
|
"""
|
||||||
|
try:
|
||||||
|
with path.open(encoding="utf-8") as fh:
|
||||||
|
return sum(1 for line in fh if UNCHECKED_TASK_RE.match(line))
|
||||||
|
except OSError:
|
||||||
|
return 0
|
||||||
76
src/pkgmgr/actions/archive/readme.py
Normal file
76
src/pkgmgr/actions/archive/readme.py
Normal file
@@ -0,0 +1,76 @@
|
|||||||
|
"""Read and update the ``## Archive`` section of a directory README."""
|
||||||
|
|
||||||
|
from __future__ import annotations
|
||||||
|
|
||||||
|
import re
|
||||||
|
|
||||||
|
ARCHIVE_HEADING = "## Archive"
|
||||||
|
LIST_ITEM_RE = re.compile(r"^\s*-\s+(?P<body>\S.*)$")
|
||||||
|
|
||||||
|
|
||||||
|
def existing_archive_entries(readme_text: str) -> set[str]:
|
||||||
|
"""Return the deduplicated set of list-item bodies under ``## Archive``."""
|
||||||
|
lines = readme_text.splitlines()
|
||||||
|
in_archive = False
|
||||||
|
entries: set[str] = set()
|
||||||
|
for line in lines:
|
||||||
|
stripped = line.rstrip()
|
||||||
|
if stripped == ARCHIVE_HEADING:
|
||||||
|
in_archive = True
|
||||||
|
continue
|
||||||
|
if in_archive and stripped.startswith("## "):
|
||||||
|
break
|
||||||
|
if not in_archive:
|
||||||
|
continue
|
||||||
|
match = LIST_ITEM_RE.match(stripped)
|
||||||
|
if match:
|
||||||
|
entries.add(match.group("body").strip())
|
||||||
|
return entries
|
||||||
|
|
||||||
|
|
||||||
|
def merge_archive_section(readme_text: str, new_entries: list[str]) -> str:
|
||||||
|
"""Return ``readme_text`` with *new_entries* appended under ``## Archive``.
|
||||||
|
|
||||||
|
Existing entries are preserved verbatim. If the section is missing it
|
||||||
|
is created at the end of the document.
|
||||||
|
"""
|
||||||
|
if not new_entries:
|
||||||
|
return readme_text
|
||||||
|
|
||||||
|
lines = readme_text.splitlines()
|
||||||
|
archive_index = next(
|
||||||
|
(i for i, line in enumerate(lines) if line.rstrip() == ARCHIVE_HEADING),
|
||||||
|
None,
|
||||||
|
)
|
||||||
|
|
||||||
|
if archive_index is None:
|
||||||
|
suffix = [""] if (lines and lines[-1] != "") else []
|
||||||
|
suffix.append(ARCHIVE_HEADING)
|
||||||
|
suffix.append("")
|
||||||
|
suffix.extend(f"- {entry}" for entry in new_entries)
|
||||||
|
merged = lines + suffix
|
||||||
|
return "\n".join(merged) + "\n"
|
||||||
|
|
||||||
|
section_end = next(
|
||||||
|
(i for i in range(archive_index + 1, len(lines)) if lines[i].startswith("## ")),
|
||||||
|
len(lines),
|
||||||
|
)
|
||||||
|
|
||||||
|
body_start = archive_index + 1
|
||||||
|
while body_start < section_end and not lines[body_start].strip():
|
||||||
|
body_start += 1
|
||||||
|
|
||||||
|
last_item = body_start - 1
|
||||||
|
for i in range(body_start, section_end):
|
||||||
|
if LIST_ITEM_RE.match(lines[i]):
|
||||||
|
last_item = i
|
||||||
|
|
||||||
|
insertion_point = (last_item + 1) if last_item >= body_start else body_start
|
||||||
|
if insertion_point == body_start and body_start == archive_index + 1:
|
||||||
|
new_block = ["", *[f"- {entry}" for entry in new_entries]]
|
||||||
|
else:
|
||||||
|
new_block = [f"- {entry}" for entry in new_entries]
|
||||||
|
|
||||||
|
merged = lines[:insertion_point] + new_block + lines[insertion_point:]
|
||||||
|
trailing = "\n" if readme_text.endswith("\n") else ""
|
||||||
|
return "\n".join(merged) + trailing
|
||||||
114
src/pkgmgr/actions/archive/workflow.py
Normal file
114
src/pkgmgr/actions/archive/workflow.py
Normal file
@@ -0,0 +1,114 @@
|
|||||||
|
"""Orchestrator for archiving fully-checked Markdown files."""
|
||||||
|
|
||||||
|
from __future__ import annotations
|
||||||
|
|
||||||
|
import contextlib
|
||||||
|
from dataclasses import dataclass
|
||||||
|
from pathlib import Path
|
||||||
|
|
||||||
|
from .discovery import iter_archivable_files
|
||||||
|
from .inspect import count_unchecked_items, extract_h1
|
||||||
|
from .readme import existing_archive_entries, merge_archive_section
|
||||||
|
|
||||||
|
|
||||||
|
@dataclass(frozen=True)
|
||||||
|
class ArchivePlan:
|
||||||
|
"""Outcome of an archive analysis run.
|
||||||
|
|
||||||
|
Attributes:
|
||||||
|
archived: ``(source_path, title)`` for every file that was (or
|
||||||
|
would be) archived. Order matches the original directory
|
||||||
|
listing.
|
||||||
|
skipped_incomplete: ``(source_path, unchecked_count)`` for files
|
||||||
|
that still hold ``- [ ]`` markers.
|
||||||
|
skipped_without_h1: files that had no H1 heading to use as title.
|
||||||
|
new_entries: titles that will be appended to the README index.
|
||||||
|
existing_entries: titles already present in the README index.
|
||||||
|
"""
|
||||||
|
|
||||||
|
archived: list[tuple[Path, str]]
|
||||||
|
skipped_incomplete: list[tuple[Path, int]]
|
||||||
|
skipped_without_h1: list[Path]
|
||||||
|
new_entries: list[str]
|
||||||
|
existing_entries: set[str]
|
||||||
|
|
||||||
|
|
||||||
|
def _bucket_files(
|
||||||
|
files: list[Path],
|
||||||
|
) -> tuple[
|
||||||
|
list[tuple[Path, str]],
|
||||||
|
list[tuple[Path, int]],
|
||||||
|
list[Path],
|
||||||
|
]:
|
||||||
|
plan: list[tuple[Path, str]] = []
|
||||||
|
skipped_incomplete: list[tuple[Path, int]] = []
|
||||||
|
skipped_without_h1: list[Path] = []
|
||||||
|
for path in files:
|
||||||
|
unchecked = count_unchecked_items(path)
|
||||||
|
if unchecked > 0:
|
||||||
|
skipped_incomplete.append((path, unchecked))
|
||||||
|
continue
|
||||||
|
title = extract_h1(path)
|
||||||
|
if title is None:
|
||||||
|
skipped_without_h1.append(path)
|
||||||
|
continue
|
||||||
|
plan.append((path, title))
|
||||||
|
return plan, skipped_incomplete, skipped_without_h1
|
||||||
|
|
||||||
|
|
||||||
|
def _dedupe_titles(
|
||||||
|
plan: list[tuple[Path, str]], already_archived: set[str]
|
||||||
|
) -> list[str]:
|
||||||
|
new_entries: list[str] = []
|
||||||
|
for _path, title in plan:
|
||||||
|
if title in already_archived or title in new_entries:
|
||||||
|
continue
|
||||||
|
new_entries.append(title)
|
||||||
|
return new_entries
|
||||||
|
|
||||||
|
|
||||||
|
def run_archive(
|
||||||
|
directory: Path,
|
||||||
|
readme_path: Path,
|
||||||
|
*,
|
||||||
|
dry_run: bool = False,
|
||||||
|
include_template: bool = False,
|
||||||
|
) -> ArchivePlan:
|
||||||
|
"""Walk *directory* and archive every fully-checked file into *readme_path*.
|
||||||
|
|
||||||
|
Returns an :class:`ArchivePlan` describing the outcome. When
|
||||||
|
``dry_run`` is true no files are deleted and the README is not
|
||||||
|
rewritten — the plan still reflects what *would* happen.
|
||||||
|
|
||||||
|
Raises ``FileNotFoundError`` if *directory* or *readme_path* does
|
||||||
|
not exist.
|
||||||
|
"""
|
||||||
|
if not directory.is_dir():
|
||||||
|
raise FileNotFoundError(f"Archive directory not found: {directory}")
|
||||||
|
if not readme_path.is_file():
|
||||||
|
raise FileNotFoundError(f"README not found: {readme_path}")
|
||||||
|
|
||||||
|
files = iter_archivable_files(directory, include_template=include_template)
|
||||||
|
readme_text = readme_path.read_text(encoding="utf-8")
|
||||||
|
already_archived = existing_archive_entries(readme_text)
|
||||||
|
|
||||||
|
archived, skipped_incomplete, skipped_without_h1 = _bucket_files(files)
|
||||||
|
new_entries = _dedupe_titles(archived, already_archived)
|
||||||
|
|
||||||
|
if not dry_run and new_entries:
|
||||||
|
merged_text = merge_archive_section(readme_text, new_entries)
|
||||||
|
if merged_text != readme_text:
|
||||||
|
readme_path.write_text(merged_text, encoding="utf-8")
|
||||||
|
|
||||||
|
if not dry_run:
|
||||||
|
for path, _title in archived:
|
||||||
|
with contextlib.suppress(FileNotFoundError):
|
||||||
|
path.unlink()
|
||||||
|
|
||||||
|
return ArchivePlan(
|
||||||
|
archived=archived,
|
||||||
|
skipped_incomplete=skipped_incomplete,
|
||||||
|
skipped_without_h1=skipped_without_h1,
|
||||||
|
new_entries=new_entries,
|
||||||
|
existing_entries=already_archived,
|
||||||
|
)
|
||||||
@@ -1,14 +1,13 @@
|
|||||||
# -*- coding: utf-8 -*-
|
|
||||||
"""
|
"""
|
||||||
Public API for branch actions.
|
Public API for branch actions.
|
||||||
"""
|
"""
|
||||||
|
|
||||||
from .open_branch import open_branch
|
|
||||||
from .close_branch import close_branch
|
from .close_branch import close_branch
|
||||||
from .drop_branch import drop_branch
|
from .drop_branch import drop_branch
|
||||||
|
from .open_branch import open_branch
|
||||||
|
|
||||||
__all__ = [
|
__all__ = [
|
||||||
"open_branch",
|
|
||||||
"close_branch",
|
"close_branch",
|
||||||
"drop_branch",
|
"drop_branch",
|
||||||
|
"open_branch",
|
||||||
]
|
]
|
||||||
|
|||||||
@@ -1,11 +1,21 @@
|
|||||||
from __future__ import annotations
|
from __future__ import annotations
|
||||||
from typing import Optional
|
|
||||||
from pkgmgr.core.git import run_git, GitError, get_current_branch
|
from pkgmgr.core.git.commands import (
|
||||||
from .utils import _resolve_base_branch
|
GitDeleteRemoteBranchError,
|
||||||
|
checkout,
|
||||||
|
delete_local_branch,
|
||||||
|
delete_remote_branch,
|
||||||
|
fetch,
|
||||||
|
merge_no_ff,
|
||||||
|
pull,
|
||||||
|
push,
|
||||||
|
)
|
||||||
|
from pkgmgr.core.git.errors import GitRunError
|
||||||
|
from pkgmgr.core.git.queries import get_current_branch, resolve_base_branch
|
||||||
|
|
||||||
|
|
||||||
def close_branch(
|
def close_branch(
|
||||||
name: Optional[str],
|
name: str | None,
|
||||||
base_branch: str = "main",
|
base_branch: str = "main",
|
||||||
fallback_base: str = "master",
|
fallback_base: str = "master",
|
||||||
cwd: str = ".",
|
cwd: str = ".",
|
||||||
@@ -14,18 +24,17 @@ def close_branch(
|
|||||||
"""
|
"""
|
||||||
Merge a feature branch into the base branch and delete it afterwards.
|
Merge a feature branch into the base branch and delete it afterwards.
|
||||||
"""
|
"""
|
||||||
|
|
||||||
# Determine branch name
|
# Determine branch name
|
||||||
if not name:
|
if not name:
|
||||||
try:
|
try:
|
||||||
name = get_current_branch(cwd=cwd)
|
name = get_current_branch(cwd=cwd)
|
||||||
except GitError as exc:
|
except GitRunError as exc:
|
||||||
raise RuntimeError(f"Failed to detect current branch: {exc}") from exc
|
raise RuntimeError(f"Failed to detect current branch: {exc}") from exc
|
||||||
|
|
||||||
if not name:
|
if not name:
|
||||||
raise RuntimeError("Branch name must not be empty.")
|
raise RuntimeError("Branch name must not be empty.")
|
||||||
|
|
||||||
target_base = _resolve_base_branch(base_branch, fallback_base, cwd=cwd)
|
target_base = resolve_base_branch(base_branch, fallback_base, cwd=cwd)
|
||||||
|
|
||||||
if name == target_base:
|
if name == target_base:
|
||||||
raise RuntimeError(
|
raise RuntimeError(
|
||||||
@@ -35,65 +44,31 @@ def close_branch(
|
|||||||
|
|
||||||
# Confirmation
|
# Confirmation
|
||||||
if not force:
|
if not force:
|
||||||
answer = input(
|
answer = (
|
||||||
|
input(
|
||||||
f"Merge branch '{name}' into '{target_base}' and delete it afterwards? (y/N): "
|
f"Merge branch '{name}' into '{target_base}' and delete it afterwards? (y/N): "
|
||||||
).strip().lower()
|
)
|
||||||
|
.strip()
|
||||||
|
.lower()
|
||||||
|
)
|
||||||
if answer != "y":
|
if answer != "y":
|
||||||
print("Aborted closing branch.")
|
print("Aborted closing branch.")
|
||||||
return
|
return
|
||||||
|
|
||||||
# Fetch
|
# Execute workflow (commands raise specific GitRunError subclasses)
|
||||||
try:
|
fetch("origin", cwd=cwd)
|
||||||
run_git(["fetch", "origin"], cwd=cwd)
|
checkout(target_base, cwd=cwd)
|
||||||
except GitError as exc:
|
pull("origin", target_base, cwd=cwd)
|
||||||
raise RuntimeError(
|
merge_no_ff(name, cwd=cwd)
|
||||||
f"Failed to fetch from origin before closing branch {name!r}: {exc}"
|
push("origin", target_base, cwd=cwd)
|
||||||
) from exc
|
|
||||||
|
|
||||||
# Checkout base
|
# Delete local branch (safe delete by default)
|
||||||
try:
|
delete_local_branch(name, cwd=cwd, force=False)
|
||||||
run_git(["checkout", target_base], cwd=cwd)
|
|
||||||
except GitError as exc:
|
|
||||||
raise RuntimeError(
|
|
||||||
f"Failed to checkout base branch {target_base!r}: {exc}"
|
|
||||||
) from exc
|
|
||||||
|
|
||||||
# Pull latest
|
# Delete remote branch (special-case error message)
|
||||||
try:
|
try:
|
||||||
run_git(["pull", "origin", target_base], cwd=cwd)
|
delete_remote_branch("origin", name, cwd=cwd)
|
||||||
except GitError as exc:
|
except GitDeleteRemoteBranchError as exc:
|
||||||
raise RuntimeError(
|
|
||||||
f"Failed to pull latest changes for base branch {target_base!r}: {exc}"
|
|
||||||
) from exc
|
|
||||||
|
|
||||||
# Merge
|
|
||||||
try:
|
|
||||||
run_git(["merge", "--no-ff", name], cwd=cwd)
|
|
||||||
except GitError as exc:
|
|
||||||
raise RuntimeError(
|
|
||||||
f"Failed to merge branch {name!r} into {target_base!r}: {exc}"
|
|
||||||
) from exc
|
|
||||||
|
|
||||||
# Push result
|
|
||||||
try:
|
|
||||||
run_git(["push", "origin", target_base], cwd=cwd)
|
|
||||||
except GitError as exc:
|
|
||||||
raise RuntimeError(
|
|
||||||
f"Failed to push base branch {target_base!r} after merge: {exc}"
|
|
||||||
) from exc
|
|
||||||
|
|
||||||
# Delete local
|
|
||||||
try:
|
|
||||||
run_git(["branch", "-d", name], cwd=cwd)
|
|
||||||
except GitError as exc:
|
|
||||||
raise RuntimeError(
|
|
||||||
f"Failed to delete local branch {name!r}: {exc}"
|
|
||||||
) from exc
|
|
||||||
|
|
||||||
# Delete remote
|
|
||||||
try:
|
|
||||||
run_git(["push", "origin", "--delete", name], cwd=cwd)
|
|
||||||
except GitError as exc:
|
|
||||||
raise RuntimeError(
|
raise RuntimeError(
|
||||||
f"Branch {name!r} deleted locally, but remote deletion failed: {exc}"
|
f"Branch {name!r} deleted locally, but remote deletion failed: {exc}"
|
||||||
) from exc
|
) from exc
|
||||||
|
|||||||
@@ -1,11 +1,16 @@
|
|||||||
from __future__ import annotations
|
from __future__ import annotations
|
||||||
from typing import Optional
|
|
||||||
from pkgmgr.core.git import run_git, GitError, get_current_branch
|
from pkgmgr.core.git.commands import (
|
||||||
from .utils import _resolve_base_branch
|
GitDeleteRemoteBranchError,
|
||||||
|
delete_local_branch,
|
||||||
|
delete_remote_branch,
|
||||||
|
)
|
||||||
|
from pkgmgr.core.git.errors import GitRunError
|
||||||
|
from pkgmgr.core.git.queries import get_current_branch, resolve_base_branch
|
||||||
|
|
||||||
|
|
||||||
def drop_branch(
|
def drop_branch(
|
||||||
name: Optional[str],
|
name: str | None,
|
||||||
base_branch: str = "main",
|
base_branch: str = "main",
|
||||||
fallback_base: str = "master",
|
fallback_base: str = "master",
|
||||||
cwd: str = ".",
|
cwd: str = ".",
|
||||||
@@ -14,17 +19,16 @@ def drop_branch(
|
|||||||
"""
|
"""
|
||||||
Delete a branch locally and remotely without merging.
|
Delete a branch locally and remotely without merging.
|
||||||
"""
|
"""
|
||||||
|
|
||||||
if not name:
|
if not name:
|
||||||
try:
|
try:
|
||||||
name = get_current_branch(cwd=cwd)
|
name = get_current_branch(cwd=cwd)
|
||||||
except GitError as exc:
|
except GitRunError as exc:
|
||||||
raise RuntimeError(f"Failed to detect current branch: {exc}") from exc
|
raise RuntimeError(f"Failed to detect current branch: {exc}") from exc
|
||||||
|
|
||||||
if not name:
|
if not name:
|
||||||
raise RuntimeError("Branch name must not be empty.")
|
raise RuntimeError("Branch name must not be empty.")
|
||||||
|
|
||||||
target_base = _resolve_base_branch(base_branch, fallback_base, cwd=cwd)
|
target_base = resolve_base_branch(base_branch, fallback_base, cwd=cwd)
|
||||||
|
|
||||||
if name == target_base:
|
if name == target_base:
|
||||||
raise RuntimeError(
|
raise RuntimeError(
|
||||||
@@ -33,23 +37,23 @@ def drop_branch(
|
|||||||
|
|
||||||
# Confirmation
|
# Confirmation
|
||||||
if not force:
|
if not force:
|
||||||
answer = input(
|
answer = (
|
||||||
|
input(
|
||||||
f"Delete branch '{name}' locally and on origin? This is destructive! (y/N): "
|
f"Delete branch '{name}' locally and on origin? This is destructive! (y/N): "
|
||||||
).strip().lower()
|
)
|
||||||
|
.strip()
|
||||||
|
.lower()
|
||||||
|
)
|
||||||
if answer != "y":
|
if answer != "y":
|
||||||
print("Aborted dropping branch.")
|
print("Aborted dropping branch.")
|
||||||
return
|
return
|
||||||
|
|
||||||
# Local delete
|
delete_local_branch(name, cwd=cwd, force=False)
|
||||||
try:
|
|
||||||
run_git(["branch", "-d", name], cwd=cwd)
|
|
||||||
except GitError as exc:
|
|
||||||
raise RuntimeError(f"Failed to delete local branch {name!r}: {exc}") from exc
|
|
||||||
|
|
||||||
# Remote delete
|
# Remote delete (special-case message)
|
||||||
try:
|
try:
|
||||||
run_git(["push", "origin", "--delete", name], cwd=cwd)
|
delete_remote_branch("origin", name, cwd=cwd)
|
||||||
except GitError as exc:
|
except GitDeleteRemoteBranchError as exc:
|
||||||
raise RuntimeError(
|
raise RuntimeError(
|
||||||
f"Branch {name!r} was deleted locally, but remote deletion failed: {exc}"
|
f"Branch {name!r} was deleted locally, but remote deletion failed: {exc}"
|
||||||
) from exc
|
) from exc
|
||||||
|
|||||||
@@ -1,11 +1,17 @@
|
|||||||
from __future__ import annotations
|
from __future__ import annotations
|
||||||
from typing import Optional
|
|
||||||
from pkgmgr.core.git import run_git, GitError
|
from pkgmgr.core.git.commands import (
|
||||||
from .utils import _resolve_base_branch
|
checkout,
|
||||||
|
create_branch,
|
||||||
|
fetch,
|
||||||
|
pull,
|
||||||
|
push_upstream,
|
||||||
|
)
|
||||||
|
from pkgmgr.core.git.queries import resolve_base_branch
|
||||||
|
|
||||||
|
|
||||||
def open_branch(
|
def open_branch(
|
||||||
name: Optional[str],
|
name: str | None,
|
||||||
base_branch: str = "main",
|
base_branch: str = "main",
|
||||||
fallback_base: str = "master",
|
fallback_base: str = "master",
|
||||||
cwd: str = ".",
|
cwd: str = ".",
|
||||||
@@ -13,7 +19,6 @@ def open_branch(
|
|||||||
"""
|
"""
|
||||||
Create and push a new feature branch on top of a base branch.
|
Create and push a new feature branch on top of a base branch.
|
||||||
"""
|
"""
|
||||||
|
|
||||||
# Request name interactively if not provided
|
# Request name interactively if not provided
|
||||||
if not name:
|
if not name:
|
||||||
name = input("Enter new branch name: ").strip()
|
name = input("Enter new branch name: ").strip()
|
||||||
@@ -21,44 +26,13 @@ def open_branch(
|
|||||||
if not name:
|
if not name:
|
||||||
raise RuntimeError("Branch name must not be empty.")
|
raise RuntimeError("Branch name must not be empty.")
|
||||||
|
|
||||||
resolved_base = _resolve_base_branch(base_branch, fallback_base, cwd=cwd)
|
resolved_base = resolve_base_branch(base_branch, fallback_base, cwd=cwd)
|
||||||
|
|
||||||
# 1) Fetch from origin
|
# Workflow (commands raise specific GitBaseError subclasses)
|
||||||
try:
|
fetch("origin", cwd=cwd)
|
||||||
run_git(["fetch", "origin"], cwd=cwd)
|
checkout(resolved_base, cwd=cwd)
|
||||||
except GitError as exc:
|
pull("origin", resolved_base, cwd=cwd)
|
||||||
raise RuntimeError(
|
|
||||||
f"Failed to fetch from origin before creating branch {name!r}: {exc}"
|
|
||||||
) from exc
|
|
||||||
|
|
||||||
# 2) Checkout base branch
|
# Create new branch from resolved base and push it with upstream tracking
|
||||||
try:
|
create_branch(name, resolved_base, cwd=cwd)
|
||||||
run_git(["checkout", resolved_base], cwd=cwd)
|
push_upstream("origin", name, cwd=cwd)
|
||||||
except GitError as exc:
|
|
||||||
raise RuntimeError(
|
|
||||||
f"Failed to checkout base branch {resolved_base!r}: {exc}"
|
|
||||||
) from exc
|
|
||||||
|
|
||||||
# 3) Pull latest changes
|
|
||||||
try:
|
|
||||||
run_git(["pull", "origin", resolved_base], cwd=cwd)
|
|
||||||
except GitError as exc:
|
|
||||||
raise RuntimeError(
|
|
||||||
f"Failed to pull latest changes for base branch {resolved_base!r}: {exc}"
|
|
||||||
) from exc
|
|
||||||
|
|
||||||
# 4) Create new branch
|
|
||||||
try:
|
|
||||||
run_git(["checkout", "-b", name], cwd=cwd)
|
|
||||||
except GitError as exc:
|
|
||||||
raise RuntimeError(
|
|
||||||
f"Failed to create new branch {name!r} from base {resolved_base!r}: {exc}"
|
|
||||||
) from exc
|
|
||||||
|
|
||||||
# 5) Push new branch
|
|
||||||
try:
|
|
||||||
run_git(["push", "-u", "origin", name], cwd=cwd)
|
|
||||||
except GitError as exc:
|
|
||||||
raise RuntimeError(
|
|
||||||
f"Failed to push new branch {name!r} to origin: {exc}"
|
|
||||||
) from exc
|
|
||||||
|
|||||||
@@ -1,27 +0,0 @@
|
|||||||
from __future__ import annotations
|
|
||||||
from pkgmgr.core.git import run_git, GitError
|
|
||||||
|
|
||||||
|
|
||||||
def _resolve_base_branch(
|
|
||||||
preferred: str,
|
|
||||||
fallback: str,
|
|
||||||
cwd: str,
|
|
||||||
) -> str:
|
|
||||||
"""
|
|
||||||
Resolve the base branch to use.
|
|
||||||
|
|
||||||
Try `preferred` first (default: main),
|
|
||||||
fall back to `fallback` (default: master).
|
|
||||||
|
|
||||||
Raise RuntimeError if neither exists.
|
|
||||||
"""
|
|
||||||
for candidate in (preferred, fallback):
|
|
||||||
try:
|
|
||||||
run_git(["rev-parse", "--verify", candidate], cwd=cwd)
|
|
||||||
return candidate
|
|
||||||
except GitError:
|
|
||||||
continue
|
|
||||||
|
|
||||||
raise RuntimeError(
|
|
||||||
f"Neither {preferred!r} nor {fallback!r} exist in this repository."
|
|
||||||
)
|
|
||||||
@@ -1,72 +1,38 @@
|
|||||||
#!/usr/bin/env python3
|
|
||||||
# -*- coding: utf-8 -*-
|
|
||||||
|
|
||||||
"""
|
"""
|
||||||
Helpers to generate changelog information from Git history.
|
Helpers to generate changelog information from Git history.
|
||||||
|
|
||||||
This module provides a small abstraction around `git log` so that
|
|
||||||
CLI commands can request a changelog between two refs (tags, branches,
|
|
||||||
commits) without dealing with raw subprocess calls.
|
|
||||||
"""
|
"""
|
||||||
|
|
||||||
from __future__ import annotations
|
from __future__ import annotations
|
||||||
|
|
||||||
from typing import Optional
|
from pkgmgr.core.git.queries import (
|
||||||
|
GitChangelogQueryError,
|
||||||
from pkgmgr.core.git import run_git, GitError
|
get_changelog,
|
||||||
|
)
|
||||||
|
|
||||||
|
|
||||||
def generate_changelog(
|
def generate_changelog(
|
||||||
cwd: str,
|
cwd: str,
|
||||||
from_ref: Optional[str] = None,
|
from_ref: str | None = None,
|
||||||
to_ref: Optional[str] = None,
|
to_ref: str | None = None,
|
||||||
include_merges: bool = False,
|
include_merges: bool = False,
|
||||||
) -> str:
|
) -> str:
|
||||||
"""
|
"""
|
||||||
Generate a plain-text changelog between two Git refs.
|
Generate a plain-text changelog between two Git refs.
|
||||||
|
|
||||||
Parameters
|
Returns a human-readable message instead of raising.
|
||||||
----------
|
|
||||||
cwd:
|
|
||||||
Repository directory in which to run Git commands.
|
|
||||||
from_ref:
|
|
||||||
Optional starting reference (exclusive). If provided together
|
|
||||||
with `to_ref`, the range `from_ref..to_ref` is used.
|
|
||||||
If only `from_ref` is given, the range `from_ref..HEAD` is used.
|
|
||||||
to_ref:
|
|
||||||
Optional end reference (inclusive). If omitted, `HEAD` is used.
|
|
||||||
include_merges:
|
|
||||||
If False (default), merge commits are filtered out.
|
|
||||||
|
|
||||||
Returns
|
|
||||||
-------
|
|
||||||
str
|
|
||||||
The output of `git log` formatted as a simple text changelog.
|
|
||||||
If no commits are found or Git fails, an explanatory message
|
|
||||||
is returned instead of raising.
|
|
||||||
"""
|
"""
|
||||||
# Determine the revision range
|
|
||||||
if to_ref is None:
|
if to_ref is None:
|
||||||
to_ref = "HEAD"
|
to_ref = "HEAD"
|
||||||
|
|
||||||
if from_ref:
|
rev_range = f"{from_ref}..{to_ref}" if from_ref else to_ref
|
||||||
rev_range = f"{from_ref}..{to_ref}"
|
|
||||||
else:
|
|
||||||
rev_range = to_ref
|
|
||||||
|
|
||||||
# Use a custom pretty format that includes tags/refs (%d)
|
|
||||||
cmd = [
|
|
||||||
"log",
|
|
||||||
"--pretty=format:%h %d %s",
|
|
||||||
]
|
|
||||||
if not include_merges:
|
|
||||||
cmd.append("--no-merges")
|
|
||||||
cmd.append(rev_range)
|
|
||||||
|
|
||||||
try:
|
try:
|
||||||
output = run_git(cmd, cwd=cwd)
|
output = get_changelog(
|
||||||
except GitError as exc:
|
cwd=cwd,
|
||||||
# Do not raise to the CLI, return a human-readable error instead.
|
from_ref=from_ref,
|
||||||
|
to_ref=to_ref,
|
||||||
|
include_merges=include_merges,
|
||||||
|
)
|
||||||
|
except GitChangelogQueryError as exc:
|
||||||
return (
|
return (
|
||||||
f"[ERROR] Failed to generate changelog in {cwd!r} "
|
f"[ERROR] Failed to generate changelog in {cwd!r} "
|
||||||
f"for range {rev_range!r}:\n{exc}"
|
f"for range {rev_range!r}:\n{exc}"
|
||||||
|
|||||||
161
src/pkgmgr/actions/code_scanning/__init__.py
Normal file
161
src/pkgmgr/actions/code_scanning/__init__.py
Normal file
@@ -0,0 +1,161 @@
|
|||||||
|
"""Download GitHub code scanning results via the ``gh`` CLI.
|
||||||
|
|
||||||
|
Fetches all code scanning alerts (and the analysis metadata) for a
|
||||||
|
repository and writes them, plus a readable digest, into a timestamped
|
||||||
|
directory so they can be read and analysed offline. Authentication is
|
||||||
|
delegated to ``gh`` (credentials from its keyring/login).
|
||||||
|
"""
|
||||||
|
|
||||||
|
from __future__ import annotations
|
||||||
|
|
||||||
|
import json
|
||||||
|
import os
|
||||||
|
import shutil
|
||||||
|
import subprocess
|
||||||
|
from collections import Counter
|
||||||
|
from dataclasses import dataclass, field
|
||||||
|
from datetime import datetime, timezone
|
||||||
|
from typing import Any
|
||||||
|
|
||||||
|
|
||||||
|
class CodeScanningError(RuntimeError):
|
||||||
|
"""Raised when code scanning results cannot be downloaded."""
|
||||||
|
|
||||||
|
|
||||||
|
@dataclass
|
||||||
|
class CodeScanningResult:
|
||||||
|
repo: str
|
||||||
|
output_dir: str
|
||||||
|
alert_count: int
|
||||||
|
files: list[str] = field(default_factory=list)
|
||||||
|
|
||||||
|
|
||||||
|
def _gh(args: list[str]) -> subprocess.CompletedProcess[str]:
|
||||||
|
return subprocess.run(["gh", *args], capture_output=True, text=True, check=False)
|
||||||
|
|
||||||
|
|
||||||
|
def _resolve_repo(repo: str | None) -> str:
|
||||||
|
if repo:
|
||||||
|
return repo
|
||||||
|
proc = _gh(["repo", "view", "--json", "nameWithOwner", "-q", ".nameWithOwner"])
|
||||||
|
name = proc.stdout.strip()
|
||||||
|
if proc.returncode != 0 or not name:
|
||||||
|
raise CodeScanningError(
|
||||||
|
"could not resolve the current repository; run inside a GitHub "
|
||||||
|
"repo or pass --repo OWNER/REPO "
|
||||||
|
f"({proc.stderr.strip()})"
|
||||||
|
)
|
||||||
|
return name
|
||||||
|
|
||||||
|
|
||||||
|
def _fetch_json(endpoint: str, params: list[str] | None = None) -> Any:
|
||||||
|
args = ["api", endpoint, "--paginate"]
|
||||||
|
for param in params or []:
|
||||||
|
args += ["-f", param]
|
||||||
|
proc = _gh(args)
|
||||||
|
if proc.returncode != 0:
|
||||||
|
raise CodeScanningError(
|
||||||
|
f"gh api {endpoint} failed: {proc.stderr.strip() or 'unknown error'}"
|
||||||
|
)
|
||||||
|
body = proc.stdout.strip()
|
||||||
|
return json.loads(body) if body else []
|
||||||
|
|
||||||
|
|
||||||
|
def _alert_row(alert: dict) -> str:
|
||||||
|
rule = alert.get("rule") or {}
|
||||||
|
instance = alert.get("most_recent_instance") or {}
|
||||||
|
location = instance.get("location") or {}
|
||||||
|
message = (instance.get("message") or {}).get("text", "").strip().replace("\n", " ")
|
||||||
|
severity = rule.get("security_severity_level") or rule.get("severity") or "unknown"
|
||||||
|
path = location.get("path", "?")
|
||||||
|
line = location.get("start_line", "?")
|
||||||
|
state = alert.get("state", "?")
|
||||||
|
rule_id = rule.get("id", "?")
|
||||||
|
return f"- [{severity}] {rule_id} — {path}:{line} ({state})\n {message}"
|
||||||
|
|
||||||
|
|
||||||
|
def _build_summary(repo: str, generated_at: str, alerts: list[dict]) -> str:
|
||||||
|
by_severity: Counter = Counter()
|
||||||
|
by_state: Counter = Counter()
|
||||||
|
by_rule: Counter = Counter()
|
||||||
|
for alert in alerts:
|
||||||
|
rule = alert.get("rule") or {}
|
||||||
|
by_severity[
|
||||||
|
rule.get("security_severity_level") or rule.get("severity") or "unknown"
|
||||||
|
] += 1
|
||||||
|
by_state[alert.get("state", "unknown")] += 1
|
||||||
|
by_rule[rule.get("id", "unknown")] += 1
|
||||||
|
|
||||||
|
lines = [
|
||||||
|
f"# Code scanning summary — {repo}",
|
||||||
|
"",
|
||||||
|
f"- Generated: {generated_at}",
|
||||||
|
f"- Total alerts: {len(alerts)}",
|
||||||
|
"",
|
||||||
|
"## By severity",
|
||||||
|
"",
|
||||||
|
]
|
||||||
|
lines += [f"- {sev}: {count}" for sev, count in by_severity.most_common()] or [
|
||||||
|
"- none"
|
||||||
|
]
|
||||||
|
lines += ["", "## By state", ""]
|
||||||
|
lines += [f"- {state}: {count}" for state, count in by_state.most_common()] or [
|
||||||
|
"- none"
|
||||||
|
]
|
||||||
|
lines += ["", "## By rule", ""]
|
||||||
|
lines += [f"- {rule}: {count}" for rule, count in by_rule.most_common()] or [
|
||||||
|
"- none"
|
||||||
|
]
|
||||||
|
lines += ["", "## Alerts", ""]
|
||||||
|
lines += [_alert_row(alert) for alert in alerts] or ["- none"]
|
||||||
|
return "\n".join(lines) + "\n"
|
||||||
|
|
||||||
|
|
||||||
|
def download_code_scanning(
|
||||||
|
repo: str | None = None,
|
||||||
|
output_dir: str | None = None,
|
||||||
|
state: str | None = None,
|
||||||
|
) -> CodeScanningResult:
|
||||||
|
if not shutil.which("gh"):
|
||||||
|
raise CodeScanningError("the GitHub CLI 'gh' is not installed or not on PATH")
|
||||||
|
|
||||||
|
repo = _resolve_repo(repo)
|
||||||
|
repo_name = repo.rstrip("/").split("/")[-1]
|
||||||
|
|
||||||
|
if output_dir is None:
|
||||||
|
timestamp = datetime.now(timezone.utc).strftime("%Y%m%d%H%M%S")
|
||||||
|
output_dir = os.path.join("/tmp", repo_name, "code-scanner", timestamp)
|
||||||
|
output_dir = os.path.abspath(os.path.expanduser(output_dir))
|
||||||
|
os.makedirs(output_dir, exist_ok=True)
|
||||||
|
generated_at = datetime.now(timezone.utc).isoformat(timespec="seconds")
|
||||||
|
|
||||||
|
alerts = _fetch_json(
|
||||||
|
f"repos/{repo}/code-scanning/alerts",
|
||||||
|
params=[f"state={state}"] if state else None,
|
||||||
|
)
|
||||||
|
|
||||||
|
files: list[str] = []
|
||||||
|
|
||||||
|
def _write(name: str, content: str) -> None:
|
||||||
|
path = os.path.join(output_dir, name)
|
||||||
|
with open(path, "w", encoding="utf-8") as handle:
|
||||||
|
handle.write(content)
|
||||||
|
files.append(path)
|
||||||
|
|
||||||
|
_write("alerts.json", json.dumps(alerts, indent=2, ensure_ascii=False) + "\n")
|
||||||
|
_write("summary.md", _build_summary(repo, generated_at, alerts))
|
||||||
|
|
||||||
|
try:
|
||||||
|
analyses = _fetch_json(f"repos/{repo}/code-scanning/analyses")
|
||||||
|
_write(
|
||||||
|
"analyses.json", json.dumps(analyses, indent=2, ensure_ascii=False) + "\n"
|
||||||
|
)
|
||||||
|
except CodeScanningError as exc:
|
||||||
|
_write("analyses.json", json.dumps({"error": str(exc)}, indent=2) + "\n")
|
||||||
|
|
||||||
|
return CodeScanningResult(
|
||||||
|
repo=repo,
|
||||||
|
output_dir=output_dir,
|
||||||
|
alert_count=len(alerts),
|
||||||
|
files=files,
|
||||||
|
)
|
||||||
@@ -1,15 +1,20 @@
|
|||||||
import yaml
|
|
||||||
import os
|
import os
|
||||||
|
|
||||||
|
import yaml
|
||||||
|
|
||||||
from pkgmgr.core.config.save import save_user_config
|
from pkgmgr.core.config.save import save_user_config
|
||||||
|
|
||||||
def interactive_add(config,USER_CONFIG_PATH:str):
|
|
||||||
|
def interactive_add(config, USER_CONFIG_PATH: str):
|
||||||
"""Interactively prompt the user to add a new repository entry to the user config."""
|
"""Interactively prompt the user to add a new repository entry to the user config."""
|
||||||
print("Adding a new repository configuration entry.")
|
print("Adding a new repository configuration entry.")
|
||||||
new_entry = {}
|
new_entry = {}
|
||||||
new_entry["provider"] = input("Provider (e.g., github.com): ").strip()
|
new_entry["provider"] = input("Provider (e.g., github.com): ").strip()
|
||||||
new_entry["account"] = input("Account (e.g., yourusername): ").strip()
|
new_entry["account"] = input("Account (e.g., yourusername): ").strip()
|
||||||
new_entry["repository"] = input("Repository name (e.g., mytool): ").strip()
|
new_entry["repository"] = input("Repository name (e.g., mytool): ").strip()
|
||||||
new_entry["command"] = input("Command (optional, leave blank to auto-detect): ").strip()
|
new_entry["command"] = input(
|
||||||
|
"Command (optional, leave blank to auto-detect): "
|
||||||
|
).strip()
|
||||||
new_entry["description"] = input("Description (optional): ").strip()
|
new_entry["description"] = input("Description (optional): ").strip()
|
||||||
new_entry["replacement"] = input("Replacement (optional): ").strip()
|
new_entry["replacement"] = input("Replacement (optional): ").strip()
|
||||||
new_entry["alias"] = input("Alias (optional): ").strip()
|
new_entry["alias"] = input("Alias (optional): ").strip()
|
||||||
@@ -25,12 +30,12 @@ def interactive_add(config,USER_CONFIG_PATH:str):
|
|||||||
confirm = input("Add this entry to user config? (y/N): ").strip().lower()
|
confirm = input("Add this entry to user config? (y/N): ").strip().lower()
|
||||||
if confirm == "y":
|
if confirm == "y":
|
||||||
if os.path.exists(USER_CONFIG_PATH):
|
if os.path.exists(USER_CONFIG_PATH):
|
||||||
with open(USER_CONFIG_PATH, 'r') as f:
|
with open(USER_CONFIG_PATH) as f:
|
||||||
user_config = yaml.safe_load(f) or {}
|
user_config = yaml.safe_load(f) or {}
|
||||||
else:
|
else:
|
||||||
user_config = {"repositories": []}
|
user_config = {"repositories": []}
|
||||||
user_config.setdefault("repositories", [])
|
user_config.setdefault("repositories", [])
|
||||||
user_config["repositories"].append(new_entry)
|
user_config["repositories"].append(new_entry)
|
||||||
save_user_config(user_config,USER_CONFIG_PATH)
|
save_user_config(user_config, USER_CONFIG_PATH)
|
||||||
else:
|
else:
|
||||||
print("Entry not added.")
|
print("Entry not added.")
|
||||||
@@ -1,6 +1,3 @@
|
|||||||
#!/usr/bin/env python3
|
|
||||||
# -*- coding: utf-8 -*-
|
|
||||||
|
|
||||||
"""
|
"""
|
||||||
Initialize user configuration by scanning the repositories base directory.
|
Initialize user configuration by scanning the repositories base directory.
|
||||||
|
|
||||||
@@ -14,7 +11,7 @@ with the expected structure:
|
|||||||
|
|
||||||
For each discovered repository, the function:
|
For each discovered repository, the function:
|
||||||
• derives provider, account, repository from the folder structure
|
• derives provider, account, repository from the folder structure
|
||||||
• (optionally) determines the latest commit hash via git log
|
• (optionally) determines the latest commit hash via git
|
||||||
• generates a unique CLI alias
|
• generates a unique CLI alias
|
||||||
• marks ignore=True for newly discovered repos
|
• marks ignore=True for newly discovered repos
|
||||||
• skips repos already known in defaults or user config
|
• skips repos already known in defaults or user config
|
||||||
@@ -23,16 +20,16 @@ For each discovered repository, the function:
|
|||||||
from __future__ import annotations
|
from __future__ import annotations
|
||||||
|
|
||||||
import os
|
import os
|
||||||
import subprocess
|
from typing import Any
|
||||||
from typing import Any, Dict
|
|
||||||
|
|
||||||
from pkgmgr.core.command.alias import generate_alias
|
from pkgmgr.core.command.alias import generate_alias
|
||||||
from pkgmgr.core.config.save import save_user_config
|
from pkgmgr.core.config.save import save_user_config
|
||||||
|
from pkgmgr.core.git.queries import get_latest_commit
|
||||||
|
|
||||||
|
|
||||||
def config_init(
|
def config_init(
|
||||||
user_config: Dict[str, Any],
|
user_config: dict[str, Any],
|
||||||
defaults_config: Dict[str, Any],
|
defaults_config: dict[str, Any],
|
||||||
bin_dir: str,
|
bin_dir: str,
|
||||||
user_config_path: str,
|
user_config_path: str,
|
||||||
) -> None:
|
) -> None:
|
||||||
@@ -55,7 +52,7 @@ def config_init(
|
|||||||
|
|
||||||
print("[INIT] Scanning repository base directory:")
|
print("[INIT] Scanning repository base directory:")
|
||||||
print(f" {repositories_base_dir}")
|
print(f" {repositories_base_dir}")
|
||||||
print("")
|
print()
|
||||||
|
|
||||||
if not os.path.isdir(repositories_base_dir):
|
if not os.path.isdir(repositories_base_dir):
|
||||||
print(f"[ERROR] Base directory does not exist: {repositories_base_dir}")
|
print(f"[ERROR] Base directory does not exist: {repositories_base_dir}")
|
||||||
@@ -107,36 +104,33 @@ def config_init(
|
|||||||
# Already known?
|
# Already known?
|
||||||
if key in default_keys:
|
if key in default_keys:
|
||||||
skipped += 1
|
skipped += 1
|
||||||
print(f"[SKIP] (defaults) {provider}/{account}/{repo_name}")
|
print(
|
||||||
|
f"[SKIP] (defaults) {provider}/{account}/{repo_name}"
|
||||||
|
)
|
||||||
continue
|
continue
|
||||||
if key in existing_keys:
|
if key in existing_keys:
|
||||||
skipped += 1
|
skipped += 1
|
||||||
print(f"[SKIP] (user-config) {provider}/{account}/{repo_name}")
|
print(
|
||||||
|
f"[SKIP] (user-config) {provider}/{account}/{repo_name}"
|
||||||
|
)
|
||||||
continue
|
continue
|
||||||
|
|
||||||
print(f"[ADD] {provider}/{account}/{repo_name}")
|
print(f"[ADD] {provider}/{account}/{repo_name}")
|
||||||
|
|
||||||
# Determine commit hash
|
# Determine commit hash via git query
|
||||||
try:
|
verified_commit = get_latest_commit(repo_path) or ""
|
||||||
result = subprocess.run(
|
if verified_commit:
|
||||||
["git", "log", "-1", "--format=%H"],
|
print(f"[INFO] Latest commit: {verified_commit}")
|
||||||
cwd=repo_path,
|
else:
|
||||||
stdout=subprocess.PIPE,
|
print(
|
||||||
stderr=subprocess.PIPE,
|
"[WARN] Could not read commit (not a git repo or no commits)."
|
||||||
text=True,
|
|
||||||
check=True,
|
|
||||||
)
|
)
|
||||||
verified = result.stdout.strip()
|
|
||||||
print(f"[INFO] Latest commit: {verified}")
|
|
||||||
except Exception as exc:
|
|
||||||
verified = ""
|
|
||||||
print(f"[WARN] Could not read commit: {exc}")
|
|
||||||
|
|
||||||
entry = {
|
entry: dict[str, Any] = {
|
||||||
"provider": provider,
|
"provider": provider,
|
||||||
"account": account,
|
"account": account,
|
||||||
"repository": repo_name,
|
"repository": repo_name,
|
||||||
"verified": {"commit": verified},
|
"verified": {"commit": verified_commit},
|
||||||
"ignore": True,
|
"ignore": True,
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -156,7 +150,7 @@ def config_init(
|
|||||||
|
|
||||||
new_entries.append(entry)
|
new_entries.append(entry)
|
||||||
|
|
||||||
print("") # blank line between accounts
|
print() # blank line between accounts
|
||||||
|
|
||||||
# ------------------------------------------------------------
|
# ------------------------------------------------------------
|
||||||
# Summary
|
# Summary
|
||||||
|
|||||||
@@ -1,6 +1,8 @@
|
|||||||
import yaml
|
import yaml
|
||||||
|
|
||||||
from pkgmgr.core.config.load import load_config
|
from pkgmgr.core.config.load import load_config
|
||||||
|
|
||||||
|
|
||||||
def show_config(selected_repos, user_config_path, full_config=False):
|
def show_config(selected_repos, user_config_path, full_config=False):
|
||||||
"""Display configuration for one or more repositories, or the entire merged config."""
|
"""Display configuration for one or more repositories, or the entire merged config."""
|
||||||
if full_config:
|
if full_config:
|
||||||
@@ -8,7 +10,9 @@ def show_config(selected_repos, user_config_path, full_config=False):
|
|||||||
print(yaml.dump(merged, default_flow_style=False))
|
print(yaml.dump(merged, default_flow_style=False))
|
||||||
else:
|
else:
|
||||||
for repo in selected_repos:
|
for repo in selected_repos:
|
||||||
identifier = f'{repo.get("provider")}/{repo.get("account")}/{repo.get("repository")}'
|
identifier = (
|
||||||
|
f"{repo.get('provider')}/{repo.get('account')}/{repo.get('repository')}"
|
||||||
|
)
|
||||||
print(f"Repository: {identifier}")
|
print(f"Repository: {identifier}")
|
||||||
for key, value in repo.items():
|
for key, value in repo.items():
|
||||||
print(f" {key}: {value}")
|
print(f" {key}: {value}")
|
||||||
|
|||||||
@@ -1,6 +1,4 @@
|
|||||||
# src/pkgmgr/actions/install/__init__.py
|
# src/pkgmgr/actions/install/__init__.py
|
||||||
#!/usr/bin/env python3
|
|
||||||
# -*- coding: utf-8 -*-
|
|
||||||
|
|
||||||
"""
|
"""
|
||||||
High-level entry point for repository installation.
|
High-level entry point for repository installation.
|
||||||
@@ -16,28 +14,28 @@ Responsibilities:
|
|||||||
from __future__ import annotations
|
from __future__ import annotations
|
||||||
|
|
||||||
import os
|
import os
|
||||||
from typing import Any, Dict, List, Optional
|
from typing import Any
|
||||||
|
|
||||||
from pkgmgr.core.repository.identifier import get_repo_identifier
|
|
||||||
from pkgmgr.core.repository.dir import get_repo_dir
|
|
||||||
from pkgmgr.core.repository.verify import verify_repository
|
|
||||||
from pkgmgr.actions.repository.clone import clone_repos
|
|
||||||
from pkgmgr.actions.install.context import RepoContext
|
from pkgmgr.actions.install.context import RepoContext
|
||||||
|
from pkgmgr.actions.install.installers.makefile import (
|
||||||
|
MakefileInstaller,
|
||||||
|
)
|
||||||
|
from pkgmgr.actions.install.installers.nix import (
|
||||||
|
NixFlakeInstaller,
|
||||||
|
)
|
||||||
from pkgmgr.actions.install.installers.os_packages import (
|
from pkgmgr.actions.install.installers.os_packages import (
|
||||||
ArchPkgbuildInstaller,
|
ArchPkgbuildInstaller,
|
||||||
DebianControlInstaller,
|
DebianControlInstaller,
|
||||||
RpmSpecInstaller,
|
RpmSpecInstaller,
|
||||||
)
|
)
|
||||||
from pkgmgr.actions.install.installers.nix import (
|
|
||||||
NixFlakeInstaller,
|
|
||||||
)
|
|
||||||
from pkgmgr.actions.install.installers.python import PythonInstaller
|
from pkgmgr.actions.install.installers.python import PythonInstaller
|
||||||
from pkgmgr.actions.install.installers.makefile import (
|
|
||||||
MakefileInstaller,
|
|
||||||
)
|
|
||||||
from pkgmgr.actions.install.pipeline import InstallationPipeline
|
from pkgmgr.actions.install.pipeline import InstallationPipeline
|
||||||
|
from pkgmgr.actions.repository.clone import clone_repos
|
||||||
|
from pkgmgr.core.repository.dir import get_repo_dir
|
||||||
|
from pkgmgr.core.repository.identifier import get_repo_identifier
|
||||||
|
from pkgmgr.core.repository.verify import verify_repository
|
||||||
|
|
||||||
Repository = Dict[str, Any]
|
Repository = dict[str, Any]
|
||||||
|
|
||||||
INSTALLERS = [
|
INSTALLERS = [
|
||||||
ArchPkgbuildInstaller(),
|
ArchPkgbuildInstaller(),
|
||||||
@@ -52,12 +50,12 @@ INSTALLERS = [
|
|||||||
def _ensure_repo_dir(
|
def _ensure_repo_dir(
|
||||||
repo: Repository,
|
repo: Repository,
|
||||||
repositories_base_dir: str,
|
repositories_base_dir: str,
|
||||||
all_repos: List[Repository],
|
all_repos: list[Repository],
|
||||||
preview: bool,
|
preview: bool,
|
||||||
no_verification: bool,
|
no_verification: bool,
|
||||||
clone_mode: str,
|
clone_mode: str,
|
||||||
identifier: str,
|
identifier: str,
|
||||||
) -> Optional[str]:
|
) -> str | None:
|
||||||
"""
|
"""
|
||||||
Compute and, if necessary, clone the repository directory.
|
Compute and, if necessary, clone the repository directory.
|
||||||
|
|
||||||
@@ -66,10 +64,7 @@ def _ensure_repo_dir(
|
|||||||
repo_dir = get_repo_dir(repositories_base_dir, repo)
|
repo_dir = get_repo_dir(repositories_base_dir, repo)
|
||||||
|
|
||||||
if not os.path.exists(repo_dir):
|
if not os.path.exists(repo_dir):
|
||||||
print(
|
print(f"Repository directory '{repo_dir}' does not exist. Cloning it now...")
|
||||||
f"Repository directory '{repo_dir}' does not exist. "
|
|
||||||
"Cloning it now..."
|
|
||||||
)
|
|
||||||
clone_repos(
|
clone_repos(
|
||||||
[repo],
|
[repo],
|
||||||
repositories_base_dir,
|
repositories_base_dir,
|
||||||
@@ -79,10 +74,7 @@ def _ensure_repo_dir(
|
|||||||
clone_mode,
|
clone_mode,
|
||||||
)
|
)
|
||||||
if not os.path.exists(repo_dir):
|
if not os.path.exists(repo_dir):
|
||||||
print(
|
print(f"Cloning failed for repository {identifier}. Skipping installation.")
|
||||||
f"Cloning failed for repository {identifier}. "
|
|
||||||
"Skipping installation."
|
|
||||||
)
|
|
||||||
return None
|
return None
|
||||||
|
|
||||||
return repo_dir
|
return repo_dir
|
||||||
@@ -93,6 +85,7 @@ def _verify_repo(
|
|||||||
repo_dir: str,
|
repo_dir: str,
|
||||||
no_verification: bool,
|
no_verification: bool,
|
||||||
identifier: str,
|
identifier: str,
|
||||||
|
silent: bool,
|
||||||
) -> bool:
|
) -> bool:
|
||||||
"""
|
"""
|
||||||
Verify a repository using the configured verification data.
|
Verify a repository using the configured verification data.
|
||||||
@@ -111,6 +104,13 @@ def _verify_repo(
|
|||||||
print(f"Warning: Verification failed for {identifier}:")
|
print(f"Warning: Verification failed for {identifier}:")
|
||||||
for err in errors:
|
for err in errors:
|
||||||
print(f" - {err}")
|
print(f" - {err}")
|
||||||
|
|
||||||
|
if silent:
|
||||||
|
# Non-interactive mode: continue with a warning.
|
||||||
|
print(
|
||||||
|
f"[Warning] Continuing despite verification failure for {identifier} (--silent)."
|
||||||
|
)
|
||||||
|
else:
|
||||||
choice = input("Continue anyway? [y/N]: ").strip().lower()
|
choice = input("Continue anyway? [y/N]: ").strip().lower()
|
||||||
if choice != "y":
|
if choice != "y":
|
||||||
print(f"Skipping installation for {identifier}.")
|
print(f"Skipping installation for {identifier}.")
|
||||||
@@ -125,7 +125,7 @@ def _create_context(
|
|||||||
repo_dir: str,
|
repo_dir: str,
|
||||||
repositories_base_dir: str,
|
repositories_base_dir: str,
|
||||||
bin_dir: str,
|
bin_dir: str,
|
||||||
all_repos: List[Repository],
|
all_repos: list[Repository],
|
||||||
no_verification: bool,
|
no_verification: bool,
|
||||||
preview: bool,
|
preview: bool,
|
||||||
quiet: bool,
|
quiet: bool,
|
||||||
@@ -153,16 +153,18 @@ def _create_context(
|
|||||||
|
|
||||||
|
|
||||||
def install_repos(
|
def install_repos(
|
||||||
selected_repos: List[Repository],
|
selected_repos: list[Repository],
|
||||||
repositories_base_dir: str,
|
repositories_base_dir: str,
|
||||||
bin_dir: str,
|
bin_dir: str,
|
||||||
all_repos: List[Repository],
|
all_repos: list[Repository],
|
||||||
no_verification: bool,
|
no_verification: bool,
|
||||||
preview: bool,
|
preview: bool,
|
||||||
quiet: bool,
|
quiet: bool,
|
||||||
clone_mode: str,
|
clone_mode: str,
|
||||||
update_dependencies: bool,
|
update_dependencies: bool,
|
||||||
force_update: bool = False,
|
force_update: bool = False,
|
||||||
|
silent: bool = False,
|
||||||
|
emit_summary: bool = True,
|
||||||
) -> None:
|
) -> None:
|
||||||
"""
|
"""
|
||||||
Install one or more repositories according to the configured installers
|
Install one or more repositories according to the configured installers
|
||||||
@@ -170,12 +172,17 @@ def install_repos(
|
|||||||
|
|
||||||
If force_update=True, installers of the currently active layer are allowed
|
If force_update=True, installers of the currently active layer are allowed
|
||||||
to run again (upgrade/refresh), even if that layer is already loaded.
|
to run again (upgrade/refresh), even if that layer is already loaded.
|
||||||
|
|
||||||
|
If silent=True, repository failures are downgraded to warnings and the
|
||||||
|
overall command never exits non-zero because of per-repository failures.
|
||||||
"""
|
"""
|
||||||
pipeline = InstallationPipeline(INSTALLERS)
|
pipeline = InstallationPipeline(INSTALLERS)
|
||||||
|
failures: list[tuple[str, str]] = []
|
||||||
|
|
||||||
for repo in selected_repos:
|
for repo in selected_repos:
|
||||||
identifier = get_repo_identifier(repo, all_repos)
|
identifier = get_repo_identifier(repo, all_repos)
|
||||||
|
|
||||||
|
try:
|
||||||
repo_dir = _ensure_repo_dir(
|
repo_dir = _ensure_repo_dir(
|
||||||
repo=repo,
|
repo=repo,
|
||||||
repositories_base_dir=repositories_base_dir,
|
repositories_base_dir=repositories_base_dir,
|
||||||
@@ -186,6 +193,7 @@ def install_repos(
|
|||||||
identifier=identifier,
|
identifier=identifier,
|
||||||
)
|
)
|
||||||
if not repo_dir:
|
if not repo_dir:
|
||||||
|
failures.append((identifier, "clone/ensure repo directory failed"))
|
||||||
continue
|
continue
|
||||||
|
|
||||||
if not _verify_repo(
|
if not _verify_repo(
|
||||||
@@ -193,6 +201,7 @@ def install_repos(
|
|||||||
repo_dir=repo_dir,
|
repo_dir=repo_dir,
|
||||||
no_verification=no_verification,
|
no_verification=no_verification,
|
||||||
identifier=identifier,
|
identifier=identifier,
|
||||||
|
silent=silent,
|
||||||
):
|
):
|
||||||
continue
|
continue
|
||||||
|
|
||||||
@@ -212,3 +221,27 @@ def install_repos(
|
|||||||
)
|
)
|
||||||
|
|
||||||
pipeline.run(ctx)
|
pipeline.run(ctx)
|
||||||
|
|
||||||
|
except SystemExit as exc:
|
||||||
|
code = exc.code if isinstance(exc.code, int) else str(exc.code)
|
||||||
|
failures.append((identifier, f"installer failed (exit={code})"))
|
||||||
|
if not quiet:
|
||||||
|
print(
|
||||||
|
f"[Warning] install: repository {identifier} failed (exit={code}). Continuing..."
|
||||||
|
)
|
||||||
|
continue
|
||||||
|
except Exception as exc: # noqa: BLE001 - batch boundary: one repository must never abort the run
|
||||||
|
failures.append((identifier, f"unexpected error: {exc}"))
|
||||||
|
if not quiet:
|
||||||
|
print(
|
||||||
|
f"[Warning] install: repository {identifier} hit an unexpected error: {exc}. Continuing..."
|
||||||
|
)
|
||||||
|
continue
|
||||||
|
|
||||||
|
if failures and emit_summary and not quiet:
|
||||||
|
print("\n[pkgmgr] Installation finished with warnings:")
|
||||||
|
for ident, msg in failures:
|
||||||
|
print(f" - {ident}: {msg}")
|
||||||
|
|
||||||
|
if failures and not silent:
|
||||||
|
raise SystemExit(1)
|
||||||
|
|||||||
@@ -1,6 +1,3 @@
|
|||||||
#!/usr/bin/env python3
|
|
||||||
# -*- coding: utf-8 -*-
|
|
||||||
|
|
||||||
"""
|
"""
|
||||||
Capability detection for pkgmgr.
|
Capability detection for pkgmgr.
|
||||||
|
|
||||||
@@ -35,7 +32,8 @@ from __future__ import annotations
|
|||||||
import glob
|
import glob
|
||||||
import os
|
import os
|
||||||
from abc import ABC, abstractmethod
|
from abc import ABC, abstractmethod
|
||||||
from typing import Iterable, TYPE_CHECKING, Optional
|
from collections.abc import Iterable
|
||||||
|
from typing import TYPE_CHECKING
|
||||||
|
|
||||||
if TYPE_CHECKING:
|
if TYPE_CHECKING:
|
||||||
from pkgmgr.actions.install.context import RepoContext
|
from pkgmgr.actions.install.context import RepoContext
|
||||||
@@ -46,12 +44,12 @@ if TYPE_CHECKING:
|
|||||||
# ---------------------------------------------------------------------------
|
# ---------------------------------------------------------------------------
|
||||||
|
|
||||||
|
|
||||||
def _read_text_if_exists(path: str) -> Optional[str]:
|
def _read_text_if_exists(path: str) -> str | None:
|
||||||
"""Read a file as UTF-8 text, returning None if it does not exist or fails."""
|
"""Read a file as UTF-8 text, returning None if it does not exist or fails."""
|
||||||
if not os.path.exists(path):
|
if not os.path.exists(path):
|
||||||
return None
|
return None
|
||||||
try:
|
try:
|
||||||
with open(path, "r", encoding="utf-8") as f:
|
with open(path, encoding="utf-8") as f:
|
||||||
return f.read()
|
return f.read()
|
||||||
except OSError:
|
except OSError:
|
||||||
return None
|
return None
|
||||||
@@ -75,12 +73,12 @@ def _scan_files_for_patterns(files: Iterable[str], patterns: Iterable[str]) -> b
|
|||||||
return False
|
return False
|
||||||
|
|
||||||
|
|
||||||
def _first_spec_file(repo_dir: str) -> Optional[str]:
|
def _first_spec_file(repo_dir: str) -> str | None:
|
||||||
"""Return the first *.spec file in repo_dir, if any."""
|
"""Return the first *.spec file in repo_dir, if any."""
|
||||||
matches = glob.glob(os.path.join(repo_dir, "*.spec"))
|
matches = glob.glob(os.path.join(repo_dir, "*.spec"))
|
||||||
if not matches:
|
if not matches:
|
||||||
return None
|
return None
|
||||||
return sorted(matches)[0]
|
return min(matches)
|
||||||
|
|
||||||
|
|
||||||
# ---------------------------------------------------------------------------
|
# ---------------------------------------------------------------------------
|
||||||
@@ -100,7 +98,7 @@ class CapabilityMatcher(ABC):
|
|||||||
raise NotImplementedError
|
raise NotImplementedError
|
||||||
|
|
||||||
@abstractmethod
|
@abstractmethod
|
||||||
def is_provided(self, ctx: "RepoContext", layer: str) -> bool:
|
def is_provided(self, ctx: RepoContext, layer: str) -> bool:
|
||||||
"""
|
"""
|
||||||
Return True if this capability is actually provided by the given layer
|
Return True if this capability is actually provided by the given layer
|
||||||
for this repository.
|
for this repository.
|
||||||
@@ -133,7 +131,7 @@ class PythonRuntimeCapability(CapabilityMatcher):
|
|||||||
# OS packages may wrap Python builds, but must explicitly prove it
|
# OS packages may wrap Python builds, but must explicitly prove it
|
||||||
return layer in {"python", "nix", "os-packages"}
|
return layer in {"python", "nix", "os-packages"}
|
||||||
|
|
||||||
def is_provided(self, ctx: "RepoContext", layer: str) -> bool:
|
def is_provided(self, ctx: RepoContext, layer: str) -> bool:
|
||||||
repo_dir = ctx.repo_dir
|
repo_dir = ctx.repo_dir
|
||||||
|
|
||||||
if layer == "python":
|
if layer == "python":
|
||||||
@@ -208,7 +206,7 @@ class MakeInstallCapability(CapabilityMatcher):
|
|||||||
def applies_to_layer(self, layer: str) -> bool:
|
def applies_to_layer(self, layer: str) -> bool:
|
||||||
return layer in {"makefile", "python", "nix", "os-packages"}
|
return layer in {"makefile", "python", "nix", "os-packages"}
|
||||||
|
|
||||||
def is_provided(self, ctx: "RepoContext", layer: str) -> bool:
|
def is_provided(self, ctx: RepoContext, layer: str) -> bool:
|
||||||
repo_dir = ctx.repo_dir
|
repo_dir = ctx.repo_dir
|
||||||
|
|
||||||
if layer == "makefile":
|
if layer == "makefile":
|
||||||
@@ -216,7 +214,7 @@ class MakeInstallCapability(CapabilityMatcher):
|
|||||||
if not os.path.exists(makefile):
|
if not os.path.exists(makefile):
|
||||||
return False
|
return False
|
||||||
try:
|
try:
|
||||||
with open(makefile, "r", encoding="utf-8") as f:
|
with open(makefile, encoding="utf-8") as f:
|
||||||
for line in f:
|
for line in f:
|
||||||
if line.strip().startswith("install:"):
|
if line.strip().startswith("install:"):
|
||||||
return True
|
return True
|
||||||
@@ -274,7 +272,7 @@ class NixFlakeCapability(CapabilityMatcher):
|
|||||||
# Only Nix itself and OS packages that explicitly wrap Nix
|
# Only Nix itself and OS packages that explicitly wrap Nix
|
||||||
return layer in {"nix", "os-packages"}
|
return layer in {"nix", "os-packages"}
|
||||||
|
|
||||||
def is_provided(self, ctx: "RepoContext", layer: str) -> bool:
|
def is_provided(self, ctx: RepoContext, layer: str) -> bool:
|
||||||
repo_dir = ctx.repo_dir
|
repo_dir = ctx.repo_dir
|
||||||
|
|
||||||
if layer == "nix":
|
if layer == "nix":
|
||||||
@@ -328,7 +326,7 @@ LAYER_ORDER: list[str] = [
|
|||||||
|
|
||||||
|
|
||||||
def detect_capabilities(
|
def detect_capabilities(
|
||||||
ctx: "RepoContext",
|
ctx: RepoContext,
|
||||||
layers: Iterable[str],
|
layers: Iterable[str],
|
||||||
) -> dict[str, set[str]]:
|
) -> dict[str, set[str]]:
|
||||||
"""
|
"""
|
||||||
@@ -359,8 +357,8 @@ def detect_capabilities(
|
|||||||
|
|
||||||
|
|
||||||
def resolve_effective_capabilities(
|
def resolve_effective_capabilities(
|
||||||
ctx: "RepoContext",
|
ctx: RepoContext,
|
||||||
layers: Optional[Iterable[str]] = None,
|
layers: Iterable[str] | None = None,
|
||||||
) -> dict[str, set[str]]:
|
) -> dict[str, set[str]]:
|
||||||
"""
|
"""
|
||||||
Resolve *effective* capabilities for each layer using a bottom-up strategy.
|
Resolve *effective* capabilities for each layer using a bottom-up strategy.
|
||||||
@@ -381,10 +379,7 @@ def resolve_effective_capabilities(
|
|||||||
This means *any* higher layer can overshadow a lower layer, not just
|
This means *any* higher layer can overshadow a lower layer, not just
|
||||||
a specific one like Nix. The resolver is completely generic.
|
a specific one like Nix. The resolver is completely generic.
|
||||||
"""
|
"""
|
||||||
if layers is None:
|
layers_list = list(LAYER_ORDER) if layers is None else list(layers)
|
||||||
layers_list = list(LAYER_ORDER)
|
|
||||||
else:
|
|
||||||
layers_list = list(layers)
|
|
||||||
|
|
||||||
raw_caps = detect_capabilities(ctx, layers_list)
|
raw_caps = detect_capabilities(ctx, layers_list)
|
||||||
effective: dict[str, set[str]] = {layer: set() for layer in layers_list}
|
effective: dict[str, set[str]] = {layer: set() for layer in layers_list}
|
||||||
|
|||||||
@@ -1,6 +1,4 @@
|
|||||||
# src/pkgmgr/actions/install/context.py
|
# src/pkgmgr/actions/install/context.py
|
||||||
#!/usr/bin/env python3
|
|
||||||
# -*- coding: utf-8 -*-
|
|
||||||
|
|
||||||
"""
|
"""
|
||||||
Shared context object for repository installation steps.
|
Shared context object for repository installation steps.
|
||||||
@@ -10,19 +8,19 @@ they do not depend on global state or long parameter lists.
|
|||||||
"""
|
"""
|
||||||
|
|
||||||
from dataclasses import dataclass
|
from dataclasses import dataclass
|
||||||
from typing import Any, Dict, List
|
from typing import Any
|
||||||
|
|
||||||
|
|
||||||
@dataclass
|
@dataclass
|
||||||
class RepoContext:
|
class RepoContext:
|
||||||
"""Container for all repository-related data used during installation."""
|
"""Container for all repository-related data used during installation."""
|
||||||
|
|
||||||
repo: Dict[str, Any]
|
repo: dict[str, Any]
|
||||||
identifier: str
|
identifier: str
|
||||||
repo_dir: str
|
repo_dir: str
|
||||||
repositories_base_dir: str
|
repositories_base_dir: str
|
||||||
bin_dir: str
|
bin_dir: str
|
||||||
all_repos: List[Dict[str, Any]]
|
all_repos: list[dict[str, Any]]
|
||||||
|
|
||||||
no_verification: bool
|
no_verification: bool
|
||||||
preview: bool
|
preview: bool
|
||||||
|
|||||||
@@ -1,6 +1,3 @@
|
|||||||
#!/usr/bin/env python3
|
|
||||||
# -*- coding: utf-8 -*-
|
|
||||||
|
|
||||||
"""
|
"""
|
||||||
Installer package for pkgmgr.
|
Installer package for pkgmgr.
|
||||||
|
|
||||||
@@ -9,11 +6,17 @@ pkgmgr.actions.install.installers.
|
|||||||
"""
|
"""
|
||||||
|
|
||||||
from pkgmgr.actions.install.installers.base import BaseInstaller # noqa: F401
|
from pkgmgr.actions.install.installers.base import BaseInstaller # noqa: F401
|
||||||
from pkgmgr.actions.install.installers.nix import NixFlakeInstaller # noqa: F401
|
|
||||||
from pkgmgr.actions.install.installers.python import PythonInstaller # noqa: F401
|
|
||||||
from pkgmgr.actions.install.installers.makefile import MakefileInstaller # noqa: F401
|
from pkgmgr.actions.install.installers.makefile import MakefileInstaller # noqa: F401
|
||||||
|
from pkgmgr.actions.install.installers.nix import NixFlakeInstaller # noqa: F401
|
||||||
|
|
||||||
# OS-specific installers
|
# OS-specific installers
|
||||||
from pkgmgr.actions.install.installers.os_packages.arch_pkgbuild import ArchPkgbuildInstaller # noqa: F401
|
from pkgmgr.actions.install.installers.os_packages.arch_pkgbuild import (
|
||||||
from pkgmgr.actions.install.installers.os_packages.debian_control import DebianControlInstaller # noqa: F401
|
ArchPkgbuildInstaller as ArchPkgbuildInstaller,
|
||||||
from pkgmgr.actions.install.installers.os_packages.rpm_spec import RpmSpecInstaller # noqa: F401
|
)
|
||||||
|
from pkgmgr.actions.install.installers.os_packages.debian_control import (
|
||||||
|
DebianControlInstaller as DebianControlInstaller,
|
||||||
|
)
|
||||||
|
from pkgmgr.actions.install.installers.os_packages.rpm_spec import (
|
||||||
|
RpmSpecInstaller, # noqa: F401
|
||||||
|
)
|
||||||
|
from pkgmgr.actions.install.installers.python import PythonInstaller # noqa: F401
|
||||||
|
|||||||
@@ -1,15 +1,12 @@
|
|||||||
#!/usr/bin/env python3
|
|
||||||
# -*- coding: utf-8 -*-
|
|
||||||
|
|
||||||
"""
|
"""
|
||||||
Base interface for all installer components in the pkgmgr installation pipeline.
|
Base interface for all installer components in the pkgmgr installation pipeline.
|
||||||
"""
|
"""
|
||||||
|
from __future__ import annotations
|
||||||
|
|
||||||
from abc import ABC, abstractmethod
|
from abc import ABC, abstractmethod
|
||||||
from typing import Set, Optional
|
|
||||||
|
|
||||||
from pkgmgr.actions.install.context import RepoContext
|
|
||||||
from pkgmgr.actions.install.capabilities import CAPABILITY_MATCHERS
|
from pkgmgr.actions.install.capabilities import CAPABILITY_MATCHERS
|
||||||
|
from pkgmgr.actions.install.context import RepoContext
|
||||||
|
|
||||||
|
|
||||||
class BaseInstaller(ABC):
|
class BaseInstaller(ABC):
|
||||||
@@ -24,9 +21,9 @@ class BaseInstaller(ABC):
|
|||||||
# Examples: "nix", "python", "makefile".
|
# Examples: "nix", "python", "makefile".
|
||||||
# This is used by capability matchers to decide which patterns to
|
# This is used by capability matchers to decide which patterns to
|
||||||
# search for in the repository.
|
# search for in the repository.
|
||||||
layer: Optional[str] = None
|
layer: str | None = None
|
||||||
|
|
||||||
def discover_capabilities(self, ctx: RepoContext) -> Set[str]:
|
def discover_capabilities(self, ctx: RepoContext) -> set[str]:
|
||||||
"""
|
"""
|
||||||
Determine which logical capabilities this installer will provide
|
Determine which logical capabilities this installer will provide
|
||||||
for this specific repository instance.
|
for this specific repository instance.
|
||||||
@@ -36,12 +33,14 @@ class BaseInstaller(ABC):
|
|||||||
Makefile, etc.) and decide, via string matching, whether a given
|
Makefile, etc.) and decide, via string matching, whether a given
|
||||||
capability is actually provided by this layer.
|
capability is actually provided by this layer.
|
||||||
"""
|
"""
|
||||||
caps: Set[str] = set()
|
caps: set[str] = set()
|
||||||
if not self.layer:
|
if not self.layer:
|
||||||
return caps
|
return caps
|
||||||
|
|
||||||
for matcher in CAPABILITY_MATCHERS:
|
for matcher in CAPABILITY_MATCHERS:
|
||||||
if matcher.applies_to_layer(self.layer) and matcher.is_provided(ctx, self.layer):
|
if matcher.applies_to_layer(self.layer) and matcher.is_provided(
|
||||||
|
ctx, self.layer
|
||||||
|
):
|
||||||
caps.add(matcher.name)
|
caps.add(matcher.name)
|
||||||
|
|
||||||
return caps
|
return caps
|
||||||
|
|||||||
@@ -16,7 +16,9 @@ class MakefileInstaller(BaseInstaller):
|
|||||||
def supports(self, ctx: RepoContext) -> bool:
|
def supports(self, ctx: RepoContext) -> bool:
|
||||||
if os.environ.get("PKGMGR_DISABLE_MAKEFILE_INSTALLER") == "1":
|
if os.environ.get("PKGMGR_DISABLE_MAKEFILE_INSTALLER") == "1":
|
||||||
if not ctx.quiet:
|
if not ctx.quiet:
|
||||||
print("[INFO] PKGMGR_DISABLE_MAKEFILE_INSTALLER=1 – skipping MakefileInstaller.")
|
print(
|
||||||
|
"[INFO] PKGMGR_DISABLE_MAKEFILE_INSTALLER=1 – skipping MakefileInstaller."
|
||||||
|
)
|
||||||
return False
|
return False
|
||||||
|
|
||||||
makefile_path = os.path.join(ctx.repo_dir, self.MAKEFILE_NAME)
|
makefile_path = os.path.join(ctx.repo_dir, self.MAKEFILE_NAME)
|
||||||
@@ -24,16 +26,14 @@ class MakefileInstaller(BaseInstaller):
|
|||||||
|
|
||||||
def _has_install_target(self, makefile_path: str) -> bool:
|
def _has_install_target(self, makefile_path: str) -> bool:
|
||||||
try:
|
try:
|
||||||
with open(makefile_path, "r", encoding="utf-8", errors="ignore") as f:
|
with open(makefile_path, encoding="utf-8", errors="ignore") as f:
|
||||||
content = f.read()
|
content = f.read()
|
||||||
except OSError:
|
except OSError:
|
||||||
return False
|
return False
|
||||||
|
|
||||||
if re.search(r"^install\s*:", content, flags=re.MULTILINE):
|
if re.search(r"^install\s*:", content, flags=re.MULTILINE):
|
||||||
return True
|
return True
|
||||||
if re.search(r"^install-[a-zA-Z0-9_-]*\s*:", content, flags=re.MULTILINE):
|
return bool(re.search(r"^install-[a-zA-Z0-9_-]*\s*:", content, flags=re.MULTILINE))
|
||||||
return True
|
|
||||||
return False
|
|
||||||
|
|
||||||
def run(self, ctx: RepoContext) -> None:
|
def run(self, ctx: RepoContext) -> None:
|
||||||
makefile_path = os.path.join(ctx.repo_dir, self.MAKEFILE_NAME)
|
makefile_path = os.path.join(ctx.repo_dir, self.MAKEFILE_NAME)
|
||||||
@@ -46,7 +46,9 @@ class MakefileInstaller(BaseInstaller):
|
|||||||
return
|
return
|
||||||
|
|
||||||
if not ctx.quiet:
|
if not ctx.quiet:
|
||||||
print(f"[pkgmgr] Running make install for {ctx.identifier} (MakefileInstaller)")
|
print(
|
||||||
|
f"[pkgmgr] Running make install for {ctx.identifier} (MakefileInstaller)"
|
||||||
|
)
|
||||||
|
|
||||||
run_command("make install", cwd=ctx.repo_dir, preview=ctx.preview)
|
run_command("make install", cwd=ctx.repo_dir, preview=ctx.preview)
|
||||||
|
|
||||||
|
|||||||
104
src/pkgmgr/actions/install/installers/nix/conflicts.py
Normal file
104
src/pkgmgr/actions/install/installers/nix/conflicts.py
Normal file
@@ -0,0 +1,104 @@
|
|||||||
|
from __future__ import annotations
|
||||||
|
|
||||||
|
from typing import TYPE_CHECKING
|
||||||
|
|
||||||
|
from .profile import NixProfileInspector
|
||||||
|
from .retry import GitHubRateLimitRetry
|
||||||
|
from .runner import CommandRunner
|
||||||
|
from .textparse import NixConflictTextParser
|
||||||
|
|
||||||
|
if TYPE_CHECKING:
|
||||||
|
from pkgmgr.actions.install.context import RepoContext
|
||||||
|
|
||||||
|
|
||||||
|
class NixConflictResolver:
|
||||||
|
"""
|
||||||
|
Resolves nix profile file conflicts by:
|
||||||
|
1. Parsing conflicting store paths from stderr
|
||||||
|
2. Mapping them to profile remove tokens via `nix profile list --json`
|
||||||
|
3. Removing those tokens deterministically
|
||||||
|
4. Retrying install
|
||||||
|
"""
|
||||||
|
|
||||||
|
def __init__(
|
||||||
|
self,
|
||||||
|
runner: CommandRunner,
|
||||||
|
retry: GitHubRateLimitRetry,
|
||||||
|
profile: NixProfileInspector,
|
||||||
|
) -> None:
|
||||||
|
self._runner = runner
|
||||||
|
self._retry = retry
|
||||||
|
self._profile = profile
|
||||||
|
self._parser = NixConflictTextParser()
|
||||||
|
|
||||||
|
def resolve(
|
||||||
|
self,
|
||||||
|
ctx: RepoContext,
|
||||||
|
install_cmd: str,
|
||||||
|
stdout: str,
|
||||||
|
stderr: str,
|
||||||
|
*,
|
||||||
|
output: str,
|
||||||
|
max_rounds: int = 10,
|
||||||
|
) -> bool:
|
||||||
|
quiet = bool(getattr(ctx, "quiet", False))
|
||||||
|
combined = f"{stdout}\n{stderr}"
|
||||||
|
|
||||||
|
for _ in range(max_rounds):
|
||||||
|
# 1) Extract conflicting store prefixes from nix error output
|
||||||
|
store_prefixes = self._parser.existing_store_prefixes(combined)
|
||||||
|
|
||||||
|
# 2) Resolve them to concrete remove tokens
|
||||||
|
tokens: list[str] = self._profile.find_remove_tokens_for_store_prefixes(
|
||||||
|
ctx,
|
||||||
|
self._runner,
|
||||||
|
store_prefixes,
|
||||||
|
)
|
||||||
|
|
||||||
|
# 3) Fallback: output-name based lookup (also covers nix suggesting: `nix profile remove pkgmgr`)
|
||||||
|
if not tokens:
|
||||||
|
tokens = self._profile.find_remove_tokens_for_output(
|
||||||
|
ctx, self._runner, output
|
||||||
|
)
|
||||||
|
|
||||||
|
if tokens:
|
||||||
|
if not quiet:
|
||||||
|
print(
|
||||||
|
"[nix] conflict detected; removing existing profile entries: "
|
||||||
|
+ ", ".join(tokens)
|
||||||
|
)
|
||||||
|
|
||||||
|
for t in tokens:
|
||||||
|
# tokens may contain things like "pkgmgr" or "pkgmgr-1" or quoted tokens (we keep raw)
|
||||||
|
self._runner.run(ctx, f"nix profile remove {t}", allow_failure=True)
|
||||||
|
|
||||||
|
res = self._retry.run_with_retry(ctx, self._runner, install_cmd)
|
||||||
|
if res.returncode == 0:
|
||||||
|
return True
|
||||||
|
|
||||||
|
combined = f"{res.stdout}\n{res.stderr}"
|
||||||
|
continue
|
||||||
|
|
||||||
|
# 4) Last-resort fallback: use textual remove tokens from stderr (“nix profile remove X”)
|
||||||
|
tokens = self._parser.remove_tokens(combined)
|
||||||
|
if tokens:
|
||||||
|
if not quiet:
|
||||||
|
print("[nix] fallback remove tokens: " + ", ".join(tokens))
|
||||||
|
|
||||||
|
for t in tokens:
|
||||||
|
self._runner.run(ctx, f"nix profile remove {t}", allow_failure=True)
|
||||||
|
|
||||||
|
res = self._retry.run_with_retry(ctx, self._runner, install_cmd)
|
||||||
|
if res.returncode == 0:
|
||||||
|
return True
|
||||||
|
|
||||||
|
combined = f"{res.stdout}\n{res.stderr}"
|
||||||
|
continue
|
||||||
|
|
||||||
|
if not quiet:
|
||||||
|
print(
|
||||||
|
"[nix] conflict detected but could not resolve profile entries to remove."
|
||||||
|
)
|
||||||
|
return False
|
||||||
|
|
||||||
|
return False
|
||||||
@@ -1,12 +1,12 @@
|
|||||||
# src/pkgmgr/actions/install/installers/nix/installer.py
|
|
||||||
from __future__ import annotations
|
from __future__ import annotations
|
||||||
|
|
||||||
import os
|
import os
|
||||||
import shutil
|
import shutil
|
||||||
from typing import List, Tuple, TYPE_CHECKING
|
from typing import TYPE_CHECKING
|
||||||
|
|
||||||
from pkgmgr.actions.install.installers.base import BaseInstaller
|
from pkgmgr.actions.install.installers.base import BaseInstaller
|
||||||
|
|
||||||
|
from .conflicts import NixConflictResolver
|
||||||
from .profile import NixProfileInspector
|
from .profile import NixProfileInspector
|
||||||
from .retry import GitHubRateLimitRetry, RetryPolicy
|
from .retry import GitHubRateLimitRetry, RetryPolicy
|
||||||
from .runner import CommandRunner
|
from .runner import CommandRunner
|
||||||
@@ -14,6 +14,7 @@ from .runner import CommandRunner
|
|||||||
if TYPE_CHECKING:
|
if TYPE_CHECKING:
|
||||||
from pkgmgr.actions.install.context import RepoContext
|
from pkgmgr.actions.install.context import RepoContext
|
||||||
|
|
||||||
|
|
||||||
class NixFlakeInstaller(BaseInstaller):
|
class NixFlakeInstaller(BaseInstaller):
|
||||||
layer = "nix"
|
layer = "nix"
|
||||||
FLAKE_FILE = "flake.nix"
|
FLAKE_FILE = "flake.nix"
|
||||||
@@ -22,15 +23,18 @@ class NixFlakeInstaller(BaseInstaller):
|
|||||||
self._runner = CommandRunner()
|
self._runner = CommandRunner()
|
||||||
self._retry = GitHubRateLimitRetry(policy=policy)
|
self._retry = GitHubRateLimitRetry(policy=policy)
|
||||||
self._profile = NixProfileInspector()
|
self._profile = NixProfileInspector()
|
||||||
|
self._conflicts = NixConflictResolver(self._runner, self._retry, self._profile)
|
||||||
|
|
||||||
# ------------------------------------------------------------------ #
|
# Newer nix rejects numeric indices; we learn this at runtime and cache the decision.
|
||||||
# Compatibility: supports()
|
self._indices_supported: bool | None = None
|
||||||
# ------------------------------------------------------------------ #
|
|
||||||
|
|
||||||
def supports(self, ctx: "RepoContext") -> bool:
|
def supports(self, ctx: RepoContext) -> bool:
|
||||||
if os.environ.get("PKGMGR_DISABLE_NIX_FLAKE_INSTALLER") == "1":
|
if os.environ.get("PKGMGR_DISABLE_NIX_FLAKE_INSTALLER") == "1":
|
||||||
if not ctx.quiet:
|
if not ctx.quiet:
|
||||||
print("[INFO] PKGMGR_DISABLE_NIX_FLAKE_INSTALLER=1 – skipping NixFlakeInstaller.")
|
print(
|
||||||
|
"[INFO] PKGMGR_DISABLE_NIX_FLAKE_INSTALLER=1 – "
|
||||||
|
"skipping NixFlakeInstaller."
|
||||||
|
)
|
||||||
return False
|
return False
|
||||||
|
|
||||||
if shutil.which("nix") is None:
|
if shutil.which("nix") is None:
|
||||||
@@ -38,32 +42,25 @@ class NixFlakeInstaller(BaseInstaller):
|
|||||||
|
|
||||||
return os.path.exists(os.path.join(ctx.repo_dir, self.FLAKE_FILE))
|
return os.path.exists(os.path.join(ctx.repo_dir, self.FLAKE_FILE))
|
||||||
|
|
||||||
# ------------------------------------------------------------------ #
|
def _profile_outputs(self, ctx: RepoContext) -> list[tuple[str, bool]]:
|
||||||
# Compatibility: output selection
|
|
||||||
# ------------------------------------------------------------------ #
|
|
||||||
|
|
||||||
def _profile_outputs(self, ctx: "RepoContext") -> List[Tuple[str, bool]]:
|
|
||||||
# (output_name, allow_failure)
|
# (output_name, allow_failure)
|
||||||
if ctx.identifier in {"pkgmgr", "package-manager"}:
|
if ctx.identifier in {"pkgmgr", "package-manager"}:
|
||||||
return [("pkgmgr", False), ("default", True)]
|
return [("pkgmgr", False), ("default", True)]
|
||||||
return [("default", False)]
|
return [("default", False)]
|
||||||
|
|
||||||
# ------------------------------------------------------------------ #
|
def run(self, ctx: RepoContext) -> None:
|
||||||
# Compatibility: run()
|
|
||||||
# ------------------------------------------------------------------ #
|
|
||||||
|
|
||||||
def run(self, ctx: "RepoContext") -> None:
|
|
||||||
if not self.supports(ctx):
|
if not self.supports(ctx):
|
||||||
return
|
return
|
||||||
|
|
||||||
outputs = self._profile_outputs(ctx)
|
outputs = self._profile_outputs(ctx)
|
||||||
|
|
||||||
if not ctx.quiet:
|
if not ctx.quiet:
|
||||||
print(
|
msg = (
|
||||||
"[nix] flake detected in "
|
"[nix] flake detected in "
|
||||||
f"{ctx.identifier}, ensuring outputs: "
|
f"{ctx.identifier}, ensuring outputs: "
|
||||||
+ ", ".join(name for name, _ in outputs)
|
+ ", ".join(name for name, _ in outputs)
|
||||||
)
|
)
|
||||||
|
print(msg)
|
||||||
|
|
||||||
for output, allow_failure in outputs:
|
for output, allow_failure in outputs:
|
||||||
if ctx.force_update:
|
if ctx.force_update:
|
||||||
@@ -71,98 +68,184 @@ class NixFlakeInstaller(BaseInstaller):
|
|||||||
else:
|
else:
|
||||||
self._install_only(ctx, output, allow_failure)
|
self._install_only(ctx, output, allow_failure)
|
||||||
|
|
||||||
# ------------------------------------------------------------------ #
|
def _installable(self, ctx: RepoContext, output: str) -> str:
|
||||||
# Core logic (unchanged semantics)
|
|
||||||
# ------------------------------------------------------------------ #
|
|
||||||
|
|
||||||
def _installable(self, ctx: "RepoContext", output: str) -> str:
|
|
||||||
return f"{ctx.repo_dir}#{output}"
|
return f"{ctx.repo_dir}#{output}"
|
||||||
|
|
||||||
def _install_only(self, ctx: "RepoContext", output: str, allow_failure: bool) -> None:
|
# ---------------------------------------------------------------------
|
||||||
|
# Core install path
|
||||||
|
# ---------------------------------------------------------------------
|
||||||
|
|
||||||
|
def _install_only(
|
||||||
|
self, ctx: RepoContext, output: str, allow_failure: bool
|
||||||
|
) -> None:
|
||||||
install_cmd = f"nix profile install {self._installable(ctx, output)}"
|
install_cmd = f"nix profile install {self._installable(ctx, output)}"
|
||||||
|
|
||||||
if not ctx.quiet:
|
if not ctx.quiet:
|
||||||
print(f"[nix] install: {install_cmd}")
|
print(f"[nix] install: {install_cmd}")
|
||||||
|
|
||||||
res = self._retry.run_with_retry(ctx, self._runner, install_cmd)
|
res = self._retry.run_with_retry(ctx, self._runner, install_cmd)
|
||||||
|
|
||||||
if res.returncode == 0:
|
if res.returncode == 0:
|
||||||
if not ctx.quiet:
|
if not ctx.quiet:
|
||||||
print(f"[nix] output '{output}' successfully installed.")
|
print(f"[nix] output '{output}' successfully installed.")
|
||||||
return
|
return
|
||||||
|
|
||||||
|
# Conflict resolver first (handles the common “existing package already provides file” case)
|
||||||
|
if self._conflicts.resolve(
|
||||||
|
ctx,
|
||||||
|
install_cmd,
|
||||||
|
res.stdout,
|
||||||
|
res.stderr,
|
||||||
|
output=output,
|
||||||
|
):
|
||||||
|
if not ctx.quiet:
|
||||||
|
print(
|
||||||
|
f"[nix] output '{output}' successfully installed after conflict cleanup."
|
||||||
|
)
|
||||||
|
return
|
||||||
|
|
||||||
if not ctx.quiet:
|
if not ctx.quiet:
|
||||||
print(
|
print(
|
||||||
f"[nix] install failed for '{output}' (exit {res.returncode}), "
|
f"[nix] install failed for '{output}' (exit {res.returncode}), "
|
||||||
"trying index-based upgrade/remove+install..."
|
"trying upgrade/remove+install..."
|
||||||
)
|
)
|
||||||
|
|
||||||
indices = self._profile.find_installed_indices_for_output(ctx, self._runner, output)
|
# If indices are supported, try legacy index-upgrade path.
|
||||||
|
if self._indices_supported is not False:
|
||||||
|
indices = self._profile.find_installed_indices_for_output(
|
||||||
|
ctx, self._runner, output
|
||||||
|
)
|
||||||
|
|
||||||
upgraded = False
|
upgraded = False
|
||||||
for idx in indices:
|
for idx in indices:
|
||||||
if self._upgrade_index(ctx, idx):
|
if self._upgrade_index(ctx, idx):
|
||||||
upgraded = True
|
upgraded = True
|
||||||
if not ctx.quiet:
|
if not ctx.quiet:
|
||||||
print(f"[nix] output '{output}' successfully upgraded (index {idx}).")
|
print(
|
||||||
|
f"[nix] output '{output}' successfully upgraded (index {idx})."
|
||||||
|
)
|
||||||
|
|
||||||
if upgraded:
|
if upgraded:
|
||||||
return
|
return
|
||||||
|
|
||||||
if indices and not ctx.quiet:
|
if indices and not ctx.quiet:
|
||||||
print(f"[nix] upgrade failed; removing indices {indices} and reinstalling '{output}'.")
|
print(
|
||||||
|
f"[nix] upgrade failed; removing indices {indices} and reinstalling '{output}'."
|
||||||
|
)
|
||||||
|
|
||||||
for idx in indices:
|
for idx in indices:
|
||||||
self._remove_index(ctx, idx)
|
self._remove_index(ctx, idx)
|
||||||
|
|
||||||
|
# If we learned indices are unsupported, immediately fall back below
|
||||||
|
if self._indices_supported is False:
|
||||||
|
self._remove_tokens_for_output(ctx, output)
|
||||||
|
|
||||||
|
else:
|
||||||
|
# indices explicitly unsupported
|
||||||
|
self._remove_tokens_for_output(ctx, output)
|
||||||
|
|
||||||
final = self._runner.run(ctx, install_cmd, allow_failure=True)
|
final = self._runner.run(ctx, install_cmd, allow_failure=True)
|
||||||
if final.returncode == 0:
|
if final.returncode == 0:
|
||||||
if not ctx.quiet:
|
if not ctx.quiet:
|
||||||
print(f"[nix] output '{output}' successfully re-installed.")
|
print(f"[nix] output '{output}' successfully re-installed.")
|
||||||
return
|
return
|
||||||
|
|
||||||
print(f"[ERROR] Failed to install Nix flake output '{output}' (exit {final.returncode})")
|
print(
|
||||||
|
f"[ERROR] Failed to install Nix flake output '{output}' (exit {final.returncode})"
|
||||||
|
)
|
||||||
if not allow_failure:
|
if not allow_failure:
|
||||||
raise SystemExit(final.returncode)
|
raise SystemExit(final.returncode)
|
||||||
|
|
||||||
print(f"[WARNING] Continuing despite failure of optional output '{output}'.")
|
print(f"[WARNING] Continuing despite failure of optional output '{output}'.")
|
||||||
|
|
||||||
# ------------------------------------------------------------------ #
|
# ---------------------------------------------------------------------
|
||||||
# force_update path (unchanged semantics)
|
# force_update path
|
||||||
# ------------------------------------------------------------------ #
|
# ---------------------------------------------------------------------
|
||||||
|
|
||||||
def _force_upgrade_output(self, ctx: "RepoContext", output: str, allow_failure: bool) -> None:
|
def _force_upgrade_output(
|
||||||
indices = self._profile.find_installed_indices_for_output(ctx, self._runner, output)
|
self, ctx: RepoContext, output: str, allow_failure: bool
|
||||||
|
) -> None:
|
||||||
|
# Prefer token path if indices unsupported (new nix)
|
||||||
|
if self._indices_supported is False:
|
||||||
|
self._remove_tokens_for_output(ctx, output)
|
||||||
|
self._install_only(ctx, output, allow_failure)
|
||||||
|
if not ctx.quiet:
|
||||||
|
print(f"[nix] output '{output}' successfully upgraded.")
|
||||||
|
return
|
||||||
|
|
||||||
|
indices = self._profile.find_installed_indices_for_output(
|
||||||
|
ctx, self._runner, output
|
||||||
|
)
|
||||||
|
|
||||||
upgraded_any = False
|
upgraded_any = False
|
||||||
for idx in indices:
|
for idx in indices:
|
||||||
if self._upgrade_index(ctx, idx):
|
if self._upgrade_index(ctx, idx):
|
||||||
upgraded_any = True
|
upgraded_any = True
|
||||||
if not ctx.quiet:
|
if not ctx.quiet:
|
||||||
print(f"[nix] output '{output}' successfully upgraded (index {idx}).")
|
print(
|
||||||
|
f"[nix] output '{output}' successfully upgraded (index {idx})."
|
||||||
|
)
|
||||||
|
|
||||||
if upgraded_any:
|
if upgraded_any:
|
||||||
|
if not ctx.quiet:
|
||||||
print(f"[nix] output '{output}' successfully upgraded.")
|
print(f"[nix] output '{output}' successfully upgraded.")
|
||||||
return
|
return
|
||||||
|
|
||||||
if indices and not ctx.quiet:
|
if indices and not ctx.quiet:
|
||||||
print(f"[nix] upgrade failed; removing indices {indices} and reinstalling '{output}'.")
|
print(
|
||||||
|
f"[nix] upgrade failed; removing indices {indices} and reinstalling '{output}'."
|
||||||
|
)
|
||||||
|
|
||||||
for idx in indices:
|
for idx in indices:
|
||||||
self._remove_index(ctx, idx)
|
self._remove_index(ctx, idx)
|
||||||
|
|
||||||
|
# If we learned indices are unsupported, also remove by token to actually clear conflicts
|
||||||
|
if self._indices_supported is False:
|
||||||
|
self._remove_tokens_for_output(ctx, output)
|
||||||
|
|
||||||
self._install_only(ctx, output, allow_failure)
|
self._install_only(ctx, output, allow_failure)
|
||||||
|
|
||||||
|
if not ctx.quiet:
|
||||||
print(f"[nix] output '{output}' successfully upgraded.")
|
print(f"[nix] output '{output}' successfully upgraded.")
|
||||||
|
|
||||||
# ------------------------------------------------------------------ #
|
# ---------------------------------------------------------------------
|
||||||
# Helpers
|
# Helpers
|
||||||
# ------------------------------------------------------------------ #
|
# ---------------------------------------------------------------------
|
||||||
|
|
||||||
|
def _stderr_says_indices_unsupported(self, stderr: str) -> bool:
|
||||||
|
s = (stderr or "").lower()
|
||||||
|
return "no longer supports indices" in s or "does not support indices" in s
|
||||||
|
|
||||||
|
def _upgrade_index(self, ctx: RepoContext, idx: int) -> bool:
|
||||||
|
cmd = f"nix profile upgrade --refresh {idx}"
|
||||||
|
res = self._runner.run(ctx, cmd, allow_failure=True)
|
||||||
|
|
||||||
|
if self._stderr_says_indices_unsupported(getattr(res, "stderr", "")):
|
||||||
|
self._indices_supported = False
|
||||||
|
return False
|
||||||
|
|
||||||
|
if self._indices_supported is None:
|
||||||
|
self._indices_supported = True
|
||||||
|
|
||||||
def _upgrade_index(self, ctx: "RepoContext", idx: int) -> bool:
|
|
||||||
res = self._runner.run(ctx, f"nix profile upgrade --refresh {idx}", allow_failure=True)
|
|
||||||
return res.returncode == 0
|
return res.returncode == 0
|
||||||
|
|
||||||
def _remove_index(self, ctx: "RepoContext", idx: int) -> None:
|
def _remove_index(self, ctx: RepoContext, idx: int) -> None:
|
||||||
self._runner.run(ctx, f"nix profile remove {idx}", allow_failure=True)
|
res = self._runner.run(ctx, f"nix profile remove {idx}", allow_failure=True)
|
||||||
|
|
||||||
|
if self._stderr_says_indices_unsupported(getattr(res, "stderr", "")):
|
||||||
|
self._indices_supported = False
|
||||||
|
|
||||||
|
if self._indices_supported is None:
|
||||||
|
self._indices_supported = True
|
||||||
|
|
||||||
|
def _remove_tokens_for_output(self, ctx: RepoContext, output: str) -> None:
|
||||||
|
tokens = self._profile.find_remove_tokens_for_output(ctx, self._runner, output)
|
||||||
|
if not tokens:
|
||||||
|
return
|
||||||
|
|
||||||
|
if not ctx.quiet:
|
||||||
|
print(
|
||||||
|
f"[nix] indices unsupported; removing by token(s): {', '.join(tokens)}"
|
||||||
|
)
|
||||||
|
|
||||||
|
for t in tokens:
|
||||||
|
self._runner.run(ctx, f"nix profile remove {t}", allow_failure=True)
|
||||||
|
|||||||
@@ -1,71 +0,0 @@
|
|||||||
from __future__ import annotations
|
|
||||||
|
|
||||||
import json
|
|
||||||
from typing import Any, List, TYPE_CHECKING
|
|
||||||
|
|
||||||
|
|
||||||
if TYPE_CHECKING:
|
|
||||||
from pkgmgr.actions.install.context import RepoContext
|
|
||||||
from .runner import CommandRunner
|
|
||||||
|
|
||||||
class NixProfileInspector:
|
|
||||||
"""
|
|
||||||
Reads and interprets `nix profile list --json` and provides helpers for
|
|
||||||
finding indices matching a given output name.
|
|
||||||
"""
|
|
||||||
|
|
||||||
def find_installed_indices_for_output(self, ctx: "RepoContext", runner: "CommandRunner", output: str) -> List[int]:
|
|
||||||
res = runner.run(ctx, "nix profile list --json", allow_failure=True)
|
|
||||||
if res.returncode != 0:
|
|
||||||
return []
|
|
||||||
|
|
||||||
try:
|
|
||||||
data = json.loads(res.stdout or "{}")
|
|
||||||
except json.JSONDecodeError:
|
|
||||||
return []
|
|
||||||
|
|
||||||
indices: List[int] = []
|
|
||||||
|
|
||||||
elements = data.get("elements")
|
|
||||||
if isinstance(elements, dict):
|
|
||||||
for idx_str, elem in elements.items():
|
|
||||||
try:
|
|
||||||
idx = int(idx_str)
|
|
||||||
except (TypeError, ValueError):
|
|
||||||
continue
|
|
||||||
if self._element_matches_output(elem, output):
|
|
||||||
indices.append(idx)
|
|
||||||
return sorted(indices)
|
|
||||||
|
|
||||||
if isinstance(elements, list):
|
|
||||||
for elem in elements:
|
|
||||||
idx = elem.get("index") if isinstance(elem, dict) else None
|
|
||||||
if isinstance(idx, int) and self._element_matches_output(elem, output):
|
|
||||||
indices.append(idx)
|
|
||||||
return sorted(indices)
|
|
||||||
|
|
||||||
return []
|
|
||||||
|
|
||||||
@staticmethod
|
|
||||||
def element_matches_output(elem: Any, output: str) -> bool:
|
|
||||||
return NixProfileInspector._element_matches_output(elem, output)
|
|
||||||
|
|
||||||
@staticmethod
|
|
||||||
def _element_matches_output(elem: Any, output: str) -> bool:
|
|
||||||
out = (output or "").strip()
|
|
||||||
if not out or not isinstance(elem, dict):
|
|
||||||
return False
|
|
||||||
|
|
||||||
candidates: List[str] = []
|
|
||||||
for k in ("attrPath", "originalUrl", "url", "storePath", "name"):
|
|
||||||
v = elem.get(k)
|
|
||||||
if isinstance(v, str) and v:
|
|
||||||
candidates.append(v)
|
|
||||||
|
|
||||||
for c in candidates:
|
|
||||||
if c == out:
|
|
||||||
return True
|
|
||||||
if f"#{out}" in c:
|
|
||||||
return True
|
|
||||||
|
|
||||||
return False
|
|
||||||
@@ -0,0 +1,4 @@
|
|||||||
|
from .inspector import NixProfileInspector
|
||||||
|
from .models import NixProfileEntry
|
||||||
|
|
||||||
|
__all__ = ["NixProfileEntry", "NixProfileInspector"]
|
||||||
164
src/pkgmgr/actions/install/installers/nix/profile/inspector.py
Normal file
164
src/pkgmgr/actions/install/installers/nix/profile/inspector.py
Normal file
@@ -0,0 +1,164 @@
|
|||||||
|
from __future__ import annotations
|
||||||
|
|
||||||
|
from typing import TYPE_CHECKING, Any
|
||||||
|
|
||||||
|
from .matcher import (
|
||||||
|
entry_matches_output,
|
||||||
|
entry_matches_store_path,
|
||||||
|
stable_unique_ints,
|
||||||
|
)
|
||||||
|
from .normalizer import normalize_elements
|
||||||
|
from .parser import parse_profile_list_json
|
||||||
|
from .result import extract_stdout_text
|
||||||
|
|
||||||
|
if TYPE_CHECKING:
|
||||||
|
# Keep these as TYPE_CHECKING-only to avoid runtime import cycles.
|
||||||
|
from pkgmgr.actions.install.context import RepoContext
|
||||||
|
from pkgmgr.core.command.runner import CommandRunner
|
||||||
|
|
||||||
|
|
||||||
|
class NixProfileInspector:
|
||||||
|
"""
|
||||||
|
Reads and inspects the user's Nix profile list (JSON).
|
||||||
|
|
||||||
|
Public API:
|
||||||
|
- list_json()
|
||||||
|
- find_installed_indices_for_output() (legacy; may not work on newer nix)
|
||||||
|
- find_indices_by_store_path() (legacy; may not work on newer nix)
|
||||||
|
- find_remove_tokens_for_output()
|
||||||
|
- find_remove_tokens_for_store_prefixes()
|
||||||
|
"""
|
||||||
|
|
||||||
|
def list_json(self, ctx: RepoContext, runner: CommandRunner) -> dict[str, Any]:
|
||||||
|
res = runner.run(ctx, "nix profile list --json", allow_failure=False)
|
||||||
|
raw = extract_stdout_text(res)
|
||||||
|
return parse_profile_list_json(raw)
|
||||||
|
|
||||||
|
# ---------------------------------------------------------------------
|
||||||
|
# Legacy index helpers (still useful on older nix; newer nix may reject indices)
|
||||||
|
# ---------------------------------------------------------------------
|
||||||
|
|
||||||
|
def find_installed_indices_for_output(
|
||||||
|
self,
|
||||||
|
ctx: RepoContext,
|
||||||
|
runner: CommandRunner,
|
||||||
|
output: str,
|
||||||
|
) -> list[int]:
|
||||||
|
data = self.list_json(ctx, runner)
|
||||||
|
entries = normalize_elements(data)
|
||||||
|
|
||||||
|
hits: list[int] = []
|
||||||
|
for e in entries:
|
||||||
|
if e.index is None:
|
||||||
|
continue
|
||||||
|
if entry_matches_output(e, output):
|
||||||
|
hits.append(e.index)
|
||||||
|
|
||||||
|
return stable_unique_ints(hits)
|
||||||
|
|
||||||
|
def find_indices_by_store_path(
|
||||||
|
self,
|
||||||
|
ctx: RepoContext,
|
||||||
|
runner: CommandRunner,
|
||||||
|
store_path: str,
|
||||||
|
) -> list[int]:
|
||||||
|
needle = (store_path or "").strip()
|
||||||
|
if not needle:
|
||||||
|
return []
|
||||||
|
|
||||||
|
data = self.list_json(ctx, runner)
|
||||||
|
entries = normalize_elements(data)
|
||||||
|
|
||||||
|
hits: list[int] = []
|
||||||
|
for e in entries:
|
||||||
|
if e.index is None:
|
||||||
|
continue
|
||||||
|
if entry_matches_store_path(e, needle):
|
||||||
|
hits.append(e.index)
|
||||||
|
|
||||||
|
return stable_unique_ints(hits)
|
||||||
|
|
||||||
|
# ---------------------------------------------------------------------
|
||||||
|
# New token-based helpers (works with newer nix where indices are rejected)
|
||||||
|
# ---------------------------------------------------------------------
|
||||||
|
|
||||||
|
def find_remove_tokens_for_output(
|
||||||
|
self,
|
||||||
|
ctx: RepoContext,
|
||||||
|
runner: CommandRunner,
|
||||||
|
output: str,
|
||||||
|
) -> list[str]:
|
||||||
|
"""
|
||||||
|
Returns profile remove tokens to remove entries matching a given output.
|
||||||
|
|
||||||
|
We always include the raw output token first because nix itself suggests:
|
||||||
|
nix profile remove pkgmgr
|
||||||
|
"""
|
||||||
|
out = (output or "").strip()
|
||||||
|
if not out:
|
||||||
|
return []
|
||||||
|
|
||||||
|
data = self.list_json(ctx, runner)
|
||||||
|
entries = normalize_elements(data)
|
||||||
|
|
||||||
|
tokens: list[str] = [
|
||||||
|
out
|
||||||
|
] # critical: matches nix's own suggestion for conflicts
|
||||||
|
|
||||||
|
for e in entries:
|
||||||
|
if entry_matches_output(e, out):
|
||||||
|
# Prefer removing by key/name (non-index) when possible.
|
||||||
|
# New nix rejects numeric indices; these tokens are safer.
|
||||||
|
k = (e.key or "").strip()
|
||||||
|
n = (e.name or "").strip()
|
||||||
|
|
||||||
|
if k and not k.isdigit():
|
||||||
|
tokens.append(k)
|
||||||
|
elif n and not n.isdigit():
|
||||||
|
tokens.append(n)
|
||||||
|
|
||||||
|
# stable unique preserving order
|
||||||
|
seen: set[str] = set()
|
||||||
|
uniq: list[str] = []
|
||||||
|
for t in tokens:
|
||||||
|
if t and t not in seen:
|
||||||
|
uniq.append(t)
|
||||||
|
seen.add(t)
|
||||||
|
return uniq
|
||||||
|
|
||||||
|
def find_remove_tokens_for_store_prefixes(
|
||||||
|
self,
|
||||||
|
ctx: RepoContext,
|
||||||
|
runner: CommandRunner,
|
||||||
|
prefixes: list[str],
|
||||||
|
) -> list[str]:
|
||||||
|
"""
|
||||||
|
Returns remove tokens for entries whose store path matches any prefix.
|
||||||
|
"""
|
||||||
|
prefixes = [(p or "").strip() for p in (prefixes or []) if p]
|
||||||
|
prefixes = [p for p in prefixes if p]
|
||||||
|
if not prefixes:
|
||||||
|
return []
|
||||||
|
|
||||||
|
data = self.list_json(ctx, runner)
|
||||||
|
entries = normalize_elements(data)
|
||||||
|
|
||||||
|
tokens: list[str] = []
|
||||||
|
for e in entries:
|
||||||
|
if not e.store_paths:
|
||||||
|
continue
|
||||||
|
if any(sp == p for sp in e.store_paths for p in prefixes):
|
||||||
|
k = (e.key or "").strip()
|
||||||
|
n = (e.name or "").strip()
|
||||||
|
if k and not k.isdigit():
|
||||||
|
tokens.append(k)
|
||||||
|
elif n and not n.isdigit():
|
||||||
|
tokens.append(n)
|
||||||
|
|
||||||
|
seen: set[str] = set()
|
||||||
|
uniq: list[str] = []
|
||||||
|
for t in tokens:
|
||||||
|
if t and t not in seen:
|
||||||
|
uniq.append(t)
|
||||||
|
seen.add(t)
|
||||||
|
return uniq
|
||||||
60
src/pkgmgr/actions/install/installers/nix/profile/matcher.py
Normal file
60
src/pkgmgr/actions/install/installers/nix/profile/matcher.py
Normal file
@@ -0,0 +1,60 @@
|
|||||||
|
from __future__ import annotations
|
||||||
|
|
||||||
|
from .models import NixProfileEntry
|
||||||
|
|
||||||
|
|
||||||
|
def entry_matches_output(entry: NixProfileEntry, output: str) -> bool:
|
||||||
|
"""
|
||||||
|
Heuristic matcher: output is typically a flake output name (e.g. "pkgmgr"),
|
||||||
|
and we match against name/attrPath patterns.
|
||||||
|
"""
|
||||||
|
out = (output or "").strip()
|
||||||
|
if not out:
|
||||||
|
return False
|
||||||
|
|
||||||
|
candidates = [entry.name, entry.attr_path]
|
||||||
|
|
||||||
|
for c in candidates:
|
||||||
|
c = (c or "").strip()
|
||||||
|
if not c:
|
||||||
|
continue
|
||||||
|
|
||||||
|
# Direct match
|
||||||
|
if c == out:
|
||||||
|
return True
|
||||||
|
|
||||||
|
# AttrPath contains "#<output>"
|
||||||
|
if f"#{out}" in c:
|
||||||
|
return True
|
||||||
|
|
||||||
|
# AttrPath ends with ".<output>"
|
||||||
|
if c.endswith(f".{out}"):
|
||||||
|
return True
|
||||||
|
|
||||||
|
# Name pattern "<output>-<n>" (common, e.g. pkgmgr-1)
|
||||||
|
if c.startswith(f"{out}-"):
|
||||||
|
return True
|
||||||
|
|
||||||
|
# Historical special case: repo is "package-manager" but output is "pkgmgr"
|
||||||
|
if out == "pkgmgr" and c.startswith("package-manager-"):
|
||||||
|
return True
|
||||||
|
|
||||||
|
return False
|
||||||
|
|
||||||
|
|
||||||
|
def entry_matches_store_path(entry: NixProfileEntry, store_path: str) -> bool:
|
||||||
|
needle = (store_path or "").strip()
|
||||||
|
if not needle:
|
||||||
|
return False
|
||||||
|
return any((p or "") == needle for p in entry.store_paths)
|
||||||
|
|
||||||
|
|
||||||
|
def stable_unique_ints(values: list[int]) -> list[int]:
|
||||||
|
seen: set[int] = set()
|
||||||
|
uniq: list[int] = []
|
||||||
|
for v in values:
|
||||||
|
if v in seen:
|
||||||
|
continue
|
||||||
|
uniq.append(v)
|
||||||
|
seen.add(v)
|
||||||
|
return uniq
|
||||||
16
src/pkgmgr/actions/install/installers/nix/profile/models.py
Normal file
16
src/pkgmgr/actions/install/installers/nix/profile/models.py
Normal file
@@ -0,0 +1,16 @@
|
|||||||
|
from __future__ import annotations
|
||||||
|
|
||||||
|
from dataclasses import dataclass
|
||||||
|
|
||||||
|
|
||||||
|
@dataclass(frozen=True)
|
||||||
|
class NixProfileEntry:
|
||||||
|
"""
|
||||||
|
Minimal normalized representation of one nix profile element entry.
|
||||||
|
"""
|
||||||
|
|
||||||
|
key: str
|
||||||
|
index: int | None
|
||||||
|
name: str
|
||||||
|
attr_path: str
|
||||||
|
store_paths: list[str]
|
||||||
129
src/pkgmgr/actions/install/installers/nix/profile/normalizer.py
Normal file
129
src/pkgmgr/actions/install/installers/nix/profile/normalizer.py
Normal file
@@ -0,0 +1,129 @@
|
|||||||
|
from __future__ import annotations
|
||||||
|
|
||||||
|
import re
|
||||||
|
from collections.abc import Iterable
|
||||||
|
from typing import Any
|
||||||
|
|
||||||
|
from .models import NixProfileEntry
|
||||||
|
|
||||||
|
|
||||||
|
def coerce_index(key: str, entry: dict[str, Any]) -> int | None:
|
||||||
|
"""
|
||||||
|
Nix JSON schema varies:
|
||||||
|
- elements keys might be "0", "1", ...
|
||||||
|
- or might be names like "pkgmgr-1"
|
||||||
|
Some versions include an explicit index field.
|
||||||
|
We try safe options in order.
|
||||||
|
"""
|
||||||
|
k = (key or "").strip()
|
||||||
|
|
||||||
|
# 1) Classic: numeric keys
|
||||||
|
if k.isdigit():
|
||||||
|
try:
|
||||||
|
return int(k)
|
||||||
|
except ValueError:
|
||||||
|
return None
|
||||||
|
|
||||||
|
# 2) Explicit index fields (schema-dependent)
|
||||||
|
for field in ("index", "id", "position"):
|
||||||
|
v = entry.get(field)
|
||||||
|
if isinstance(v, int):
|
||||||
|
return v
|
||||||
|
if isinstance(v, str) and v.strip().isdigit():
|
||||||
|
try:
|
||||||
|
return int(v.strip())
|
||||||
|
except ValueError:
|
||||||
|
pass
|
||||||
|
|
||||||
|
# 3) Last resort: extract trailing number from key if it looks like "<name>-<n>"
|
||||||
|
m = re.match(r"^.+-(\d+)$", k)
|
||||||
|
if m:
|
||||||
|
try:
|
||||||
|
return int(m.group(1))
|
||||||
|
except ValueError:
|
||||||
|
return None
|
||||||
|
|
||||||
|
return None
|
||||||
|
|
||||||
|
|
||||||
|
def iter_store_paths(entry: dict[str, Any]) -> Iterable[str]:
|
||||||
|
"""
|
||||||
|
Yield all possible store paths from a nix profile JSON entry.
|
||||||
|
|
||||||
|
Nix has had schema shifts. We support common variants:
|
||||||
|
- "storePaths": ["/nix/store/..", ...]
|
||||||
|
- "storePaths": "/nix/store/.." (rare)
|
||||||
|
- "storePath": "/nix/store/.." (some variants)
|
||||||
|
- nested "outputs" dict(s) with store paths (best-effort)
|
||||||
|
"""
|
||||||
|
if not isinstance(entry, dict):
|
||||||
|
return
|
||||||
|
|
||||||
|
sp = entry.get("storePaths")
|
||||||
|
if isinstance(sp, list):
|
||||||
|
for p in sp:
|
||||||
|
if isinstance(p, str):
|
||||||
|
yield p
|
||||||
|
elif isinstance(sp, str):
|
||||||
|
yield sp
|
||||||
|
|
||||||
|
sp2 = entry.get("storePath")
|
||||||
|
if isinstance(sp2, str):
|
||||||
|
yield sp2
|
||||||
|
|
||||||
|
outs = entry.get("outputs")
|
||||||
|
if isinstance(outs, dict):
|
||||||
|
for ov in outs.values():
|
||||||
|
if isinstance(ov, dict):
|
||||||
|
p = ov.get("storePath")
|
||||||
|
if isinstance(p, str):
|
||||||
|
yield p
|
||||||
|
|
||||||
|
|
||||||
|
def normalize_store_path(store_path: str) -> str:
|
||||||
|
"""
|
||||||
|
Normalize store path for matching.
|
||||||
|
Currently just strips whitespace; hook for future normalization if needed.
|
||||||
|
"""
|
||||||
|
return (store_path or "").strip()
|
||||||
|
|
||||||
|
|
||||||
|
def normalize_elements(data: dict[str, Any]) -> list[NixProfileEntry]:
|
||||||
|
"""
|
||||||
|
Converts nix profile list JSON into a list of normalized entries.
|
||||||
|
|
||||||
|
JSON formats observed:
|
||||||
|
- {"elements": {"0": {...}, "1": {...}}}
|
||||||
|
- {"elements": {"pkgmgr-1": {...}, "pkgmgr-2": {...}}}
|
||||||
|
"""
|
||||||
|
elements = data.get("elements")
|
||||||
|
if not isinstance(elements, dict):
|
||||||
|
return []
|
||||||
|
|
||||||
|
normalized: list[NixProfileEntry] = []
|
||||||
|
|
||||||
|
for k, entry in elements.items():
|
||||||
|
if not isinstance(entry, dict):
|
||||||
|
continue
|
||||||
|
|
||||||
|
idx = coerce_index(str(k), entry)
|
||||||
|
name = str(entry.get("name", "") or "")
|
||||||
|
attr = str(entry.get("attrPath", "") or "")
|
||||||
|
|
||||||
|
store_paths: list[str] = []
|
||||||
|
for p in iter_store_paths(entry):
|
||||||
|
sp = normalize_store_path(p)
|
||||||
|
if sp:
|
||||||
|
store_paths.append(sp)
|
||||||
|
|
||||||
|
normalized.append(
|
||||||
|
NixProfileEntry(
|
||||||
|
key=str(k),
|
||||||
|
index=idx,
|
||||||
|
name=name,
|
||||||
|
attr_path=attr,
|
||||||
|
store_paths=store_paths,
|
||||||
|
)
|
||||||
|
)
|
||||||
|
|
||||||
|
return normalized
|
||||||
19
src/pkgmgr/actions/install/installers/nix/profile/parser.py
Normal file
19
src/pkgmgr/actions/install/installers/nix/profile/parser.py
Normal file
@@ -0,0 +1,19 @@
|
|||||||
|
from __future__ import annotations
|
||||||
|
|
||||||
|
import json
|
||||||
|
from typing import Any
|
||||||
|
|
||||||
|
|
||||||
|
def parse_profile_list_json(raw: str) -> dict[str, Any]:
|
||||||
|
"""
|
||||||
|
Parse JSON output from `nix profile list --json`.
|
||||||
|
|
||||||
|
Raises SystemExit with a helpful excerpt on parse failure.
|
||||||
|
"""
|
||||||
|
try:
|
||||||
|
return json.loads(raw)
|
||||||
|
except json.JSONDecodeError as e:
|
||||||
|
excerpt = (raw or "")[:5000]
|
||||||
|
raise SystemExit(
|
||||||
|
f"[nix] Failed to parse `nix profile list --json`: {e}\n{excerpt}"
|
||||||
|
) from e
|
||||||
28
src/pkgmgr/actions/install/installers/nix/profile/result.py
Normal file
28
src/pkgmgr/actions/install/installers/nix/profile/result.py
Normal file
@@ -0,0 +1,28 @@
|
|||||||
|
from __future__ import annotations
|
||||||
|
|
||||||
|
from typing import Any
|
||||||
|
|
||||||
|
|
||||||
|
def extract_stdout_text(result: Any) -> str:
|
||||||
|
"""
|
||||||
|
Normalize different runner return types to a stdout string.
|
||||||
|
|
||||||
|
Supported patterns:
|
||||||
|
- result is str -> returned as-is
|
||||||
|
- result is bytes/bytearray -> decoded UTF-8 (replace errors)
|
||||||
|
- result has `.stdout` (str or bytes) -> used
|
||||||
|
- fallback: str(result)
|
||||||
|
"""
|
||||||
|
if isinstance(result, str):
|
||||||
|
return result
|
||||||
|
|
||||||
|
if isinstance(result, (bytes, bytearray)):
|
||||||
|
return bytes(result).decode("utf-8", errors="replace")
|
||||||
|
|
||||||
|
stdout = getattr(result, "stdout", None)
|
||||||
|
if isinstance(stdout, str):
|
||||||
|
return stdout
|
||||||
|
if isinstance(stdout, (bytes, bytearray)):
|
||||||
|
return bytes(stdout).decode("utf-8", errors="replace")
|
||||||
|
|
||||||
|
return str(result)
|
||||||
71
src/pkgmgr/actions/install/installers/nix/profile_list.py
Normal file
71
src/pkgmgr/actions/install/installers/nix/profile_list.py
Normal file
@@ -0,0 +1,71 @@
|
|||||||
|
from __future__ import annotations
|
||||||
|
|
||||||
|
import re
|
||||||
|
from typing import TYPE_CHECKING
|
||||||
|
|
||||||
|
from .runner import CommandRunner
|
||||||
|
|
||||||
|
if TYPE_CHECKING:
|
||||||
|
from pkgmgr.actions.install.context import RepoContext
|
||||||
|
|
||||||
|
|
||||||
|
class NixProfileListReader:
|
||||||
|
def __init__(self, runner: CommandRunner) -> None:
|
||||||
|
self._runner = runner
|
||||||
|
|
||||||
|
@staticmethod
|
||||||
|
def _store_prefix(path: str) -> str:
|
||||||
|
raw = (path or "").strip()
|
||||||
|
m = re.match(r"^(/nix/store/[0-9a-z]{32}-[^/ \t]+)", raw)
|
||||||
|
return m.group(1) if m else raw
|
||||||
|
|
||||||
|
def entries(self, ctx: RepoContext) -> list[tuple[int, str]]:
|
||||||
|
res = self._runner.run(ctx, "nix profile list", allow_failure=True)
|
||||||
|
if res.returncode != 0:
|
||||||
|
return []
|
||||||
|
|
||||||
|
entries: list[tuple[int, str]] = []
|
||||||
|
pat = re.compile(
|
||||||
|
r"^\s*(\d+)\s+.*?(/nix/store/[0-9a-z]{32}-[^/ \t]+)",
|
||||||
|
re.MULTILINE,
|
||||||
|
)
|
||||||
|
|
||||||
|
for m in pat.finditer(res.stdout or ""):
|
||||||
|
idx_s = m.group(1)
|
||||||
|
sp = m.group(2)
|
||||||
|
try:
|
||||||
|
idx = int(idx_s)
|
||||||
|
except ValueError:
|
||||||
|
continue
|
||||||
|
entries.append((idx, self._store_prefix(sp)))
|
||||||
|
|
||||||
|
seen: set[int] = set()
|
||||||
|
uniq: list[tuple[int, str]] = []
|
||||||
|
for idx, sp in entries:
|
||||||
|
if idx not in seen:
|
||||||
|
seen.add(idx)
|
||||||
|
uniq.append((idx, sp))
|
||||||
|
|
||||||
|
return uniq
|
||||||
|
|
||||||
|
def indices_matching_store_prefixes(
|
||||||
|
self, ctx: RepoContext, prefixes: list[str]
|
||||||
|
) -> list[int]:
|
||||||
|
prefixes = [self._store_prefix(p) for p in prefixes if p]
|
||||||
|
prefixes = [p for p in prefixes if p]
|
||||||
|
if not prefixes:
|
||||||
|
return []
|
||||||
|
|
||||||
|
hits: list[int] = []
|
||||||
|
for idx, sp in self.entries(ctx):
|
||||||
|
if any(sp == p for p in prefixes):
|
||||||
|
hits.append(idx)
|
||||||
|
|
||||||
|
seen: set[int] = set()
|
||||||
|
uniq: list[int] = []
|
||||||
|
for i in hits:
|
||||||
|
if i not in seen:
|
||||||
|
seen.add(i)
|
||||||
|
uniq.append(i)
|
||||||
|
|
||||||
|
return uniq
|
||||||
@@ -2,15 +2,18 @@ from __future__ import annotations
|
|||||||
|
|
||||||
import random
|
import random
|
||||||
import time
|
import time
|
||||||
|
from collections.abc import Iterable
|
||||||
from dataclasses import dataclass
|
from dataclasses import dataclass
|
||||||
from typing import Iterable, TYPE_CHECKING
|
from typing import TYPE_CHECKING
|
||||||
|
|
||||||
from .types import RunResult
|
from .types import RunResult
|
||||||
|
|
||||||
if TYPE_CHECKING:
|
if TYPE_CHECKING:
|
||||||
from pkgmgr.actions.install.context import RepoContext
|
from pkgmgr.actions.install.context import RepoContext
|
||||||
|
|
||||||
from .runner import CommandRunner
|
from .runner import CommandRunner
|
||||||
|
|
||||||
|
|
||||||
@dataclass(frozen=True)
|
@dataclass(frozen=True)
|
||||||
class RetryPolicy:
|
class RetryPolicy:
|
||||||
max_attempts: int = 7
|
max_attempts: int = 7
|
||||||
@@ -30,18 +33,24 @@ class GitHubRateLimitRetry:
|
|||||||
|
|
||||||
def run_with_retry(
|
def run_with_retry(
|
||||||
self,
|
self,
|
||||||
ctx: "RepoContext",
|
ctx: RepoContext,
|
||||||
runner: "CommandRunner",
|
runner: CommandRunner,
|
||||||
install_cmd: str,
|
install_cmd: str,
|
||||||
) -> RunResult:
|
) -> RunResult:
|
||||||
quiet = bool(getattr(ctx, "quiet", False))
|
quiet = bool(getattr(ctx, "quiet", False))
|
||||||
delays = list(self._fibonacci_backoff(self._policy.base_delay_seconds, self._policy.max_attempts))
|
delays = list(
|
||||||
|
self._fibonacci_backoff(
|
||||||
|
self._policy.base_delay_seconds, self._policy.max_attempts
|
||||||
|
)
|
||||||
|
)
|
||||||
|
|
||||||
last: RunResult | None = None
|
last: RunResult | None = None
|
||||||
|
|
||||||
for attempt, base_delay in enumerate(delays, start=1):
|
for attempt, base_delay in enumerate(delays, start=1):
|
||||||
if not quiet:
|
if not quiet:
|
||||||
print(f"[nix] attempt {attempt}/{self._policy.max_attempts}: {install_cmd}")
|
print(
|
||||||
|
f"[nix] attempt {attempt}/{self._policy.max_attempts}: {install_cmd}"
|
||||||
|
)
|
||||||
|
|
||||||
res = runner.run(ctx, install_cmd, allow_failure=True)
|
res = runner.run(ctx, install_cmd, allow_failure=True)
|
||||||
last = res
|
last = res
|
||||||
@@ -56,7 +65,9 @@ class GitHubRateLimitRetry:
|
|||||||
if attempt >= self._policy.max_attempts:
|
if attempt >= self._policy.max_attempts:
|
||||||
break
|
break
|
||||||
|
|
||||||
jitter = random.randint(self._policy.jitter_seconds_min, self._policy.jitter_seconds_max)
|
jitter = random.randint(
|
||||||
|
self._policy.jitter_seconds_min, self._policy.jitter_seconds_max
|
||||||
|
)
|
||||||
wait_time = base_delay + jitter
|
wait_time = base_delay + jitter
|
||||||
|
|
||||||
if not quiet:
|
if not quiet:
|
||||||
@@ -67,7 +78,11 @@ class GitHubRateLimitRetry:
|
|||||||
|
|
||||||
time.sleep(wait_time)
|
time.sleep(wait_time)
|
||||||
|
|
||||||
return last if last is not None else RunResult(returncode=1, stdout="", stderr="nix install retry failed")
|
return (
|
||||||
|
last
|
||||||
|
if last is not None
|
||||||
|
else RunResult(returncode=1, stdout="", stderr="nix install retry failed")
|
||||||
|
)
|
||||||
|
|
||||||
@staticmethod
|
@staticmethod
|
||||||
def _is_github_rate_limit_error(text: str) -> bool:
|
def _is_github_rate_limit_error(text: str) -> bool:
|
||||||
|
|||||||
@@ -1,7 +1,6 @@
|
|||||||
from __future__ import annotations
|
from __future__ import annotations
|
||||||
|
|
||||||
import subprocess
|
import subprocess
|
||||||
|
|
||||||
from typing import TYPE_CHECKING
|
from typing import TYPE_CHECKING
|
||||||
|
|
||||||
from .types import RunResult
|
from .types import RunResult
|
||||||
@@ -9,13 +8,14 @@ from .types import RunResult
|
|||||||
if TYPE_CHECKING:
|
if TYPE_CHECKING:
|
||||||
from pkgmgr.actions.install.context import RepoContext
|
from pkgmgr.actions.install.context import RepoContext
|
||||||
|
|
||||||
|
|
||||||
class CommandRunner:
|
class CommandRunner:
|
||||||
"""
|
"""
|
||||||
Executes commands (shell=True) inside a repository directory (if provided).
|
Executes commands (shell=True) inside a repository directory (if provided).
|
||||||
Supports preview mode and compact failure output logging.
|
Supports preview mode and compact failure output logging.
|
||||||
"""
|
"""
|
||||||
|
|
||||||
def run(self, ctx: "RepoContext", cmd: str, allow_failure: bool) -> RunResult:
|
def run(self, ctx: RepoContext, cmd: str, allow_failure: bool) -> RunResult:
|
||||||
repo_dir = getattr(ctx, "repo_dir", None) or getattr(ctx, "repo_path", None)
|
repo_dir = getattr(ctx, "repo_dir", None) or getattr(ctx, "repo_path", None)
|
||||||
preview = bool(getattr(ctx, "preview", False))
|
preview = bool(getattr(ctx, "preview", False))
|
||||||
quiet = bool(getattr(ctx, "quiet", False))
|
quiet = bool(getattr(ctx, "quiet", False))
|
||||||
@@ -31,8 +31,7 @@ class CommandRunner:
|
|||||||
shell=True,
|
shell=True,
|
||||||
cwd=repo_dir,
|
cwd=repo_dir,
|
||||||
check=False,
|
check=False,
|
||||||
stdout=subprocess.PIPE,
|
capture_output=True,
|
||||||
stderr=subprocess.PIPE,
|
|
||||||
text=True,
|
text=True,
|
||||||
)
|
)
|
||||||
except Exception as e:
|
except Exception as e:
|
||||||
@@ -40,7 +39,9 @@ class CommandRunner:
|
|||||||
raise
|
raise
|
||||||
return RunResult(returncode=1, stdout="", stderr=str(e))
|
return RunResult(returncode=1, stdout="", stderr=str(e))
|
||||||
|
|
||||||
res = RunResult(returncode=p.returncode, stdout=p.stdout or "", stderr=p.stderr or "")
|
res = RunResult(
|
||||||
|
returncode=p.returncode, stdout=p.stdout or "", stderr=p.stderr or ""
|
||||||
|
)
|
||||||
|
|
||||||
if res.returncode != 0 and not quiet:
|
if res.returncode != 0 and not quiet:
|
||||||
self._print_compact_failure(res)
|
self._print_compact_failure(res)
|
||||||
|
|||||||
77
src/pkgmgr/actions/install/installers/nix/textparse.py
Normal file
77
src/pkgmgr/actions/install/installers/nix/textparse.py
Normal file
@@ -0,0 +1,77 @@
|
|||||||
|
from __future__ import annotations
|
||||||
|
|
||||||
|
import re
|
||||||
|
|
||||||
|
|
||||||
|
class NixConflictTextParser:
|
||||||
|
@staticmethod
|
||||||
|
def _store_prefix(path: str) -> str:
|
||||||
|
raw = (path or "").strip()
|
||||||
|
m = re.match(r"^(/nix/store/[0-9a-z]{32}-[^/ \t]+)", raw)
|
||||||
|
return m.group(1) if m else raw
|
||||||
|
|
||||||
|
def remove_tokens(self, text: str) -> list[str]:
|
||||||
|
pat = re.compile(
|
||||||
|
r"^\s*nix profile remove\s+([^\s'\"`]+|'[^']+'|\"[^\"]+\")\s*$",
|
||||||
|
re.MULTILINE,
|
||||||
|
)
|
||||||
|
|
||||||
|
tokens: list[str] = []
|
||||||
|
for m in pat.finditer(text or ""):
|
||||||
|
t = (m.group(1) or "").strip()
|
||||||
|
if (t.startswith("'") and t.endswith("'")) or (
|
||||||
|
t.startswith('"') and t.endswith('"')
|
||||||
|
):
|
||||||
|
t = t[1:-1]
|
||||||
|
if t:
|
||||||
|
tokens.append(t)
|
||||||
|
|
||||||
|
seen: set[str] = set()
|
||||||
|
uniq: list[str] = []
|
||||||
|
for t in tokens:
|
||||||
|
if t not in seen:
|
||||||
|
seen.add(t)
|
||||||
|
uniq.append(t)
|
||||||
|
|
||||||
|
return uniq
|
||||||
|
|
||||||
|
def existing_store_prefixes(self, text: str) -> list[str]:
|
||||||
|
lines = (text or "").splitlines()
|
||||||
|
prefixes: list[str] = []
|
||||||
|
|
||||||
|
in_existing = False
|
||||||
|
in_new = False
|
||||||
|
|
||||||
|
store_pat = re.compile(r"^\s*(/nix/store/[0-9a-z]{32}-[^ \t]+)")
|
||||||
|
|
||||||
|
for raw in lines:
|
||||||
|
line = raw.strip()
|
||||||
|
|
||||||
|
if "An existing package already provides the following file" in line:
|
||||||
|
in_existing = True
|
||||||
|
in_new = False
|
||||||
|
continue
|
||||||
|
|
||||||
|
if "This is the conflicting file from the new package" in line:
|
||||||
|
in_existing = False
|
||||||
|
in_new = True
|
||||||
|
continue
|
||||||
|
|
||||||
|
if in_existing:
|
||||||
|
m = store_pat.match(raw)
|
||||||
|
if m:
|
||||||
|
prefixes.append(m.group(1))
|
||||||
|
continue
|
||||||
|
|
||||||
|
_ = in_new
|
||||||
|
|
||||||
|
norm = [self._store_prefix(p) for p in prefixes if p]
|
||||||
|
|
||||||
|
seen: set[str] = set()
|
||||||
|
uniq: list[str] = []
|
||||||
|
for p in norm:
|
||||||
|
if p and p not in seen:
|
||||||
|
seen.add(p)
|
||||||
|
uniq.append(p)
|
||||||
|
|
||||||
|
return uniq
|
||||||
@@ -36,7 +36,7 @@ class ArchPkgbuildInstaller(BaseInstaller):
|
|||||||
try:
|
try:
|
||||||
if hasattr(os, "geteuid") and os.geteuid() == 0:
|
if hasattr(os, "geteuid") and os.geteuid() == 0:
|
||||||
return False
|
return False
|
||||||
except Exception:
|
except (AttributeError, OSError):
|
||||||
# On non-POSIX platforms just ignore this check.
|
# On non-POSIX platforms just ignore this check.
|
||||||
pass
|
pass
|
||||||
|
|
||||||
|
|||||||
@@ -1,6 +1,3 @@
|
|||||||
#!/usr/bin/env python3
|
|
||||||
# -*- coding: utf-8 -*-
|
|
||||||
|
|
||||||
"""
|
"""
|
||||||
Installer for Debian/Ubuntu packages defined via debian/control.
|
Installer for Debian/Ubuntu packages defined via debian/control.
|
||||||
|
|
||||||
@@ -13,11 +10,11 @@ This installer:
|
|||||||
It is intended for Debian-based systems where dpkg-buildpackage and
|
It is intended for Debian-based systems where dpkg-buildpackage and
|
||||||
apt/dpkg tooling are available.
|
apt/dpkg tooling are available.
|
||||||
"""
|
"""
|
||||||
|
from __future__ import annotations
|
||||||
|
|
||||||
import glob
|
import glob
|
||||||
import os
|
import os
|
||||||
import shutil
|
import shutil
|
||||||
from typing import List, Optional
|
|
||||||
|
|
||||||
from pkgmgr.actions.install.context import RepoContext
|
from pkgmgr.actions.install.context import RepoContext
|
||||||
from pkgmgr.actions.install.installers.base import BaseInstaller
|
from pkgmgr.actions.install.installers.base import BaseInstaller
|
||||||
@@ -56,7 +53,7 @@ class DebianControlInstaller(BaseInstaller):
|
|||||||
|
|
||||||
return os.path.exists(self._control_path(ctx))
|
return os.path.exists(self._control_path(ctx))
|
||||||
|
|
||||||
def _find_built_debs(self, repo_dir: str) -> List[str]:
|
def _find_built_debs(self, repo_dir: str) -> list[str]:
|
||||||
"""
|
"""
|
||||||
Find .deb files built by dpkg-buildpackage.
|
Find .deb files built by dpkg-buildpackage.
|
||||||
|
|
||||||
@@ -67,7 +64,7 @@ class DebianControlInstaller(BaseInstaller):
|
|||||||
pattern = os.path.join(parent, "*.deb")
|
pattern = os.path.join(parent, "*.deb")
|
||||||
return sorted(glob.glob(pattern))
|
return sorted(glob.glob(pattern))
|
||||||
|
|
||||||
def _privileged_prefix(self) -> Optional[str]:
|
def _privileged_prefix(self) -> str | None:
|
||||||
"""
|
"""
|
||||||
Determine how to run privileged commands:
|
Determine how to run privileged commands:
|
||||||
|
|
||||||
|
|||||||
@@ -1,6 +1,3 @@
|
|||||||
#!/usr/bin/env python3
|
|
||||||
# -*- coding: utf-8 -*-
|
|
||||||
|
|
||||||
"""
|
"""
|
||||||
Installer for RPM-based packages defined in *.spec files.
|
Installer for RPM-based packages defined in *.spec files.
|
||||||
|
|
||||||
@@ -14,12 +11,12 @@ This installer:
|
|||||||
|
|
||||||
It targets RPM-based systems (Fedora / RHEL / CentOS / Rocky / Alma, etc.).
|
It targets RPM-based systems (Fedora / RHEL / CentOS / Rocky / Alma, etc.).
|
||||||
"""
|
"""
|
||||||
|
from __future__ import annotations
|
||||||
|
|
||||||
import glob
|
import glob
|
||||||
import os
|
import os
|
||||||
import shutil
|
import shutil
|
||||||
import tarfile
|
import tarfile
|
||||||
from typing import List, Optional, Tuple
|
|
||||||
|
|
||||||
from pkgmgr.actions.install.context import RepoContext
|
from pkgmgr.actions.install.context import RepoContext
|
||||||
from pkgmgr.actions.install.installers.base import BaseInstaller
|
from pkgmgr.actions.install.installers.base import BaseInstaller
|
||||||
@@ -53,7 +50,7 @@ class RpmSpecInstaller(BaseInstaller):
|
|||||||
|
|
||||||
return has_dnf or has_yum or has_yum_builddep
|
return has_dnf or has_yum or has_yum_builddep
|
||||||
|
|
||||||
def _spec_path(self, ctx: RepoContext) -> Optional[str]:
|
def _spec_path(self, ctx: RepoContext) -> str | None:
|
||||||
"""Return the first *.spec file in the repository root, if any."""
|
"""Return the first *.spec file in the repository root, if any."""
|
||||||
pattern = os.path.join(ctx.repo_dir, "*.spec")
|
pattern = os.path.join(ctx.repo_dir, "*.spec")
|
||||||
matches = sorted(glob.glob(pattern))
|
matches = sorted(glob.glob(pattern))
|
||||||
@@ -92,7 +89,7 @@ class RpmSpecInstaller(BaseInstaller):
|
|||||||
for sub in ("BUILD", "BUILDROOT", "RPMS", "SOURCES", "SPECS", "SRPMS"):
|
for sub in ("BUILD", "BUILDROOT", "RPMS", "SOURCES", "SPECS", "SRPMS"):
|
||||||
os.makedirs(os.path.join(topdir, sub), exist_ok=True)
|
os.makedirs(os.path.join(topdir, sub), exist_ok=True)
|
||||||
|
|
||||||
def _parse_name_version(self, spec_path: str) -> Optional[Tuple[str, str]]:
|
def _parse_name_version(self, spec_path: str) -> tuple[str, str] | None:
|
||||||
"""
|
"""
|
||||||
Parse Name and Version from the given .spec file.
|
Parse Name and Version from the given .spec file.
|
||||||
|
|
||||||
@@ -101,7 +98,7 @@ class RpmSpecInstaller(BaseInstaller):
|
|||||||
name = None
|
name = None
|
||||||
version = None
|
version = None
|
||||||
|
|
||||||
with open(spec_path, "r", encoding="utf-8") as f:
|
with open(spec_path, encoding="utf-8") as f:
|
||||||
for raw_line in f:
|
for raw_line in f:
|
||||||
line = raw_line.strip()
|
line = raw_line.strip()
|
||||||
# Ignore comments
|
# Ignore comments
|
||||||
@@ -183,7 +180,7 @@ class RpmSpecInstaller(BaseInstaller):
|
|||||||
|
|
||||||
return self._spec_path(ctx) is not None
|
return self._spec_path(ctx) is not None
|
||||||
|
|
||||||
def _find_built_rpms(self) -> List[str]:
|
def _find_built_rpms(self) -> list[str]:
|
||||||
"""
|
"""
|
||||||
Find RPMs built by rpmbuild.
|
Find RPMs built by rpmbuild.
|
||||||
|
|
||||||
@@ -202,9 +199,7 @@ class RpmSpecInstaller(BaseInstaller):
|
|||||||
|
|
||||||
if shutil.which("dnf") is not None:
|
if shutil.which("dnf") is not None:
|
||||||
cmd = f"sudo dnf builddep -y {spec_basename}"
|
cmd = f"sudo dnf builddep -y {spec_basename}"
|
||||||
elif shutil.which("yum-builddep") is not None:
|
elif shutil.which("yum-builddep") is not None or shutil.which("yum") is not None:
|
||||||
cmd = f"sudo yum-builddep -y {spec_basename}"
|
|
||||||
elif shutil.which("yum") is not None:
|
|
||||||
cmd = f"sudo yum-builddep -y {spec_basename}"
|
cmd = f"sudo yum-builddep -y {spec_basename}"
|
||||||
else:
|
else:
|
||||||
print(
|
print(
|
||||||
@@ -215,7 +210,7 @@ class RpmSpecInstaller(BaseInstaller):
|
|||||||
|
|
||||||
run_command(cmd, cwd=ctx.repo_dir, preview=ctx.preview)
|
run_command(cmd, cwd=ctx.repo_dir, preview=ctx.preview)
|
||||||
|
|
||||||
def _install_built_rpms(self, ctx: RepoContext, rpms: List[str]) -> None:
|
def _install_built_rpms(self, ctx: RepoContext, rpms: list[str]) -> None:
|
||||||
"""
|
"""
|
||||||
Install or upgrade the built RPMs.
|
Install or upgrade the built RPMs.
|
||||||
|
|
||||||
|
|||||||
@@ -4,8 +4,8 @@ from __future__ import annotations
|
|||||||
import os
|
import os
|
||||||
import sys
|
import sys
|
||||||
|
|
||||||
from pkgmgr.actions.install.installers.base import BaseInstaller
|
|
||||||
from pkgmgr.actions.install.context import RepoContext
|
from pkgmgr.actions.install.context import RepoContext
|
||||||
|
from pkgmgr.actions.install.installers.base import BaseInstaller
|
||||||
from pkgmgr.core.command.run import run_command
|
from pkgmgr.core.command.run import run_command
|
||||||
|
|
||||||
|
|
||||||
@@ -14,7 +14,9 @@ class PythonInstaller(BaseInstaller):
|
|||||||
|
|
||||||
def supports(self, ctx: RepoContext) -> bool:
|
def supports(self, ctx: RepoContext) -> bool:
|
||||||
if os.environ.get("PKGMGR_DISABLE_PYTHON_INSTALLER") == "1":
|
if os.environ.get("PKGMGR_DISABLE_PYTHON_INSTALLER") == "1":
|
||||||
print("[INFO] PythonInstaller disabled via PKGMGR_DISABLE_PYTHON_INSTALLER.")
|
print(
|
||||||
|
"[INFO] PythonInstaller disabled via PKGMGR_DISABLE_PYTHON_INSTALLER."
|
||||||
|
)
|
||||||
return False
|
return False
|
||||||
|
|
||||||
return os.path.exists(os.path.join(ctx.repo_dir, "pyproject.toml"))
|
return os.path.exists(os.path.join(ctx.repo_dir, "pyproject.toml"))
|
||||||
|
|||||||
@@ -1,6 +1,3 @@
|
|||||||
#!/usr/bin/env python3
|
|
||||||
# -*- coding: utf-8 -*-
|
|
||||||
|
|
||||||
"""
|
"""
|
||||||
CLI layer model for the pkgmgr installation pipeline.
|
CLI layer model for the pkgmgr installation pipeline.
|
||||||
|
|
||||||
@@ -19,7 +16,6 @@ from __future__ import annotations
|
|||||||
|
|
||||||
import os
|
import os
|
||||||
from enum import Enum
|
from enum import Enum
|
||||||
from typing import Optional
|
|
||||||
|
|
||||||
|
|
||||||
class CliLayer(str, Enum):
|
class CliLayer(str, Enum):
|
||||||
@@ -38,7 +34,7 @@ CLI_LAYERS: list[CliLayer] = [
|
|||||||
]
|
]
|
||||||
|
|
||||||
|
|
||||||
def layer_priority(layer: Optional[CliLayer]) -> int:
|
def layer_priority(layer: CliLayer | None) -> int:
|
||||||
"""
|
"""
|
||||||
Return a numeric priority index for a given layer.
|
Return a numeric priority index for a given layer.
|
||||||
|
|
||||||
@@ -70,13 +66,11 @@ def classify_command_layer(command: str, repo_dir: str) -> CliLayer:
|
|||||||
home = os.path.expanduser("~")
|
home = os.path.expanduser("~")
|
||||||
|
|
||||||
# OS package managers
|
# OS package managers
|
||||||
if command_abs.startswith("/usr/") or command_abs.startswith("/bin/"):
|
if command_abs.startswith(("/usr/", "/bin/")):
|
||||||
return CliLayer.OS_PACKAGES
|
return CliLayer.OS_PACKAGES
|
||||||
|
|
||||||
# Nix store / profile
|
# Nix store / profile
|
||||||
if command_abs.startswith("/nix/store/") or command_abs.startswith(
|
if command_abs.startswith(("/nix/store/", os.path.join(home, ".nix-profile"))):
|
||||||
os.path.join(home, ".nix-profile")
|
|
||||||
):
|
|
||||||
return CliLayer.NIX
|
return CliLayer.NIX
|
||||||
|
|
||||||
# User-local bin
|
# User-local bin
|
||||||
|
|||||||
@@ -1,6 +1,4 @@
|
|||||||
# src/pkgmgr/actions/install/pipeline.py
|
# src/pkgmgr/actions/install/pipeline.py
|
||||||
#!/usr/bin/env python3
|
|
||||||
# -*- coding: utf-8 -*-
|
|
||||||
|
|
||||||
"""
|
"""
|
||||||
Installation pipeline orchestration for repositories.
|
Installation pipeline orchestration for repositories.
|
||||||
@@ -8,8 +6,8 @@ Installation pipeline orchestration for repositories.
|
|||||||
|
|
||||||
from __future__ import annotations
|
from __future__ import annotations
|
||||||
|
|
||||||
|
from collections.abc import Sequence
|
||||||
from dataclasses import dataclass
|
from dataclasses import dataclass
|
||||||
from typing import Optional, Sequence, Set
|
|
||||||
|
|
||||||
from pkgmgr.actions.install.context import RepoContext
|
from pkgmgr.actions.install.context import RepoContext
|
||||||
from pkgmgr.actions.install.installers.base import BaseInstaller
|
from pkgmgr.actions.install.installers.base import BaseInstaller
|
||||||
@@ -24,8 +22,8 @@ from pkgmgr.core.command.resolve import resolve_command_for_repo
|
|||||||
|
|
||||||
@dataclass
|
@dataclass
|
||||||
class CommandState:
|
class CommandState:
|
||||||
command: Optional[str]
|
command: str | None
|
||||||
layer: Optional[CliLayer]
|
layer: CliLayer | None
|
||||||
|
|
||||||
|
|
||||||
class CommandResolver:
|
class CommandResolver:
|
||||||
@@ -83,7 +81,7 @@ class InstallationPipeline:
|
|||||||
else:
|
else:
|
||||||
repo.pop("command", None)
|
repo.pop("command", None)
|
||||||
|
|
||||||
provided_capabilities: Set[str] = set()
|
provided_capabilities: set[str] = set()
|
||||||
|
|
||||||
for installer in self._installers:
|
for installer in self._installers:
|
||||||
layer_name = getattr(installer, "layer", None)
|
layer_name = getattr(installer, "layer", None)
|
||||||
@@ -132,7 +130,11 @@ class InstallationPipeline:
|
|||||||
continue
|
continue
|
||||||
|
|
||||||
if not quiet:
|
if not quiet:
|
||||||
if ctx.force_update and state.layer is not None and installer_layer == state.layer:
|
if (
|
||||||
|
ctx.force_update
|
||||||
|
and state.layer is not None
|
||||||
|
and installer_layer == state.layer
|
||||||
|
):
|
||||||
print(
|
print(
|
||||||
f"[pkgmgr] Running installer {installer.__class__.__name__} "
|
f"[pkgmgr] Running installer {installer.__class__.__name__} "
|
||||||
f"for {identifier} in '{repo_dir}' (upgrade requested)..."
|
f"for {identifier} in '{repo_dir}' (upgrade requested)..."
|
||||||
|
|||||||
@@ -9,17 +9,20 @@ Public API:
|
|||||||
"""
|
"""
|
||||||
|
|
||||||
from __future__ import annotations
|
from __future__ import annotations
|
||||||
from .types import Repository, MirrorMap
|
|
||||||
from .list_cmd import list_mirrors
|
|
||||||
from .diff_cmd import diff_mirrors
|
from .diff_cmd import diff_mirrors
|
||||||
|
from .list_cmd import list_mirrors
|
||||||
from .merge_cmd import merge_mirrors
|
from .merge_cmd import merge_mirrors
|
||||||
from .setup_cmd import setup_mirrors
|
from .setup_cmd import setup_mirrors
|
||||||
|
from .types import MirrorMap, Repository
|
||||||
|
from .visibility_cmd import set_mirror_visibility
|
||||||
|
|
||||||
__all__ = [
|
__all__ = [
|
||||||
"Repository",
|
|
||||||
"MirrorMap",
|
"MirrorMap",
|
||||||
"list_mirrors",
|
"Repository",
|
||||||
"diff_mirrors",
|
"diff_mirrors",
|
||||||
|
"list_mirrors",
|
||||||
"merge_mirrors",
|
"merge_mirrors",
|
||||||
|
"set_mirror_visibility",
|
||||||
"setup_mirrors",
|
"setup_mirrors",
|
||||||
]
|
]
|
||||||
|
|||||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user