mirror of
https://gitlab.archlinux.org/archlinux/devtools.git
synced 2025-10-05 20:16:19 +02:00
Compare commits
4 Commits
c76fda0bf0
...
run0
Author | SHA1 | Date | |
---|---|---|---|
![]() |
2609e386d4 | ||
![]() |
447f7b4117 | ||
![]() |
3f0ebbc6d2 | ||
![]() |
fc56ebedf3 |
@@ -24,7 +24,7 @@ test:
|
||||
stage: test
|
||||
needs: []
|
||||
script:
|
||||
- pacman -Syu --noconfirm m4 make openssh subversion rsync arch-install-scripts git bzr mercurial diffutils coreutils asciidoctor shellcheck nvchecker bats bats-assert bats-support
|
||||
- pacman -Syu --noconfirm m4 make openssh subversion rsync arch-install-scripts git bzr mercurial diffutils coreutils asciidoctor shellcheck nvchecker bats
|
||||
- make test BATS_EXTRA_ARGS='--formatter junit'
|
||||
artifacts:
|
||||
reports:
|
||||
@@ -34,7 +34,7 @@ coverage:
|
||||
stage: test
|
||||
needs: []
|
||||
script:
|
||||
- pacman -Syu --noconfirm m4 make openssh subversion rsync arch-install-scripts git bzr mercurial diffutils coreutils asciidoctor shellcheck nvchecker bats bats-assert bats-support kcov jq
|
||||
- pacman -Syu --noconfirm m4 make openssh subversion rsync arch-install-scripts git bzr mercurial diffutils coreutils asciidoctor shellcheck nvchecker bats kcov jq
|
||||
- make coverage
|
||||
coverage: '/Percent covered\s+\d+\.\d+/'
|
||||
artifacts:
|
||||
|
@@ -150,6 +150,7 @@ _pkgctl_cmds=(
|
||||
db
|
||||
diff
|
||||
issue
|
||||
license
|
||||
release
|
||||
repo
|
||||
search
|
||||
|
@@ -14,7 +14,7 @@ Description
|
||||
|
||||
Build a PKGBUILD on a remote server using makechrootpkg. Requires a remote user
|
||||
that can run archbuild in a non-interactive manner, e.g. must be able to
|
||||
elevate permissions using passwordless sudo.
|
||||
elevate permissions using passwordless run0.
|
||||
|
||||
Options
|
||||
-------
|
||||
|
@@ -3,7 +3,7 @@ pkgctl-auth(1)
|
||||
|
||||
Name
|
||||
----
|
||||
pkgctl-auth - Authenticate with serivces like GitLab.
|
||||
pkgctl-auth - Authenticate with services like GitLab.
|
||||
|
||||
Synopsis
|
||||
--------
|
||||
|
@@ -15,7 +15,11 @@ check_root() {
|
||||
local orig_argv=("$@")
|
||||
|
||||
(( EUID == 0 )) && return
|
||||
if type -P sudo >/dev/null; then
|
||||
if type -P run0 >/dev/null; then
|
||||
keepenv=",$keepenv"
|
||||
command="run0 ${keepenv//,/ --setenv=}"
|
||||
exec ${command} -- "${orig_argv[@]}"
|
||||
elif type -P sudo >/dev/null; then
|
||||
exec sudo --preserve-env="${keepenv}" -- "${orig_argv[@]}"
|
||||
else
|
||||
exec su root -c "$(printf ' %q' "${orig_argv[@]}")"
|
||||
|
@@ -188,6 +188,7 @@ path = [
|
||||
"README.md",
|
||||
"keys/**",
|
||||
".SRCINFO",
|
||||
".gitignore",
|
||||
".nvchecker.toml",
|
||||
"*.install",
|
||||
"*.sysusers",
|
||||
|
@@ -109,11 +109,6 @@ pkgctl_repo_configure() {
|
||||
local -r command=${_DEVTOOLS_COMMAND:-${BASH_SOURCE[0]##*/}}
|
||||
local path realpath pkgbase remote_url project_path hook
|
||||
local PACKAGER GPGKEY packager_name packager_email
|
||||
|
||||
# Check if we're in a git repo
|
||||
if ! git rev-parse --git-dir &>/dev/null; then
|
||||
die "Not in a git repository"
|
||||
fi
|
||||
|
||||
while (( $# )); do
|
||||
case $1 in
|
||||
@@ -155,8 +150,7 @@ pkgctl_repo_configure() {
|
||||
|
||||
# check if invoked without any path from within a packaging repo
|
||||
if (( ${#paths[@]} == 0 )); then
|
||||
if [[ -d .git ]] || git rev-parse --git-dir &>/dev/null; then
|
||||
# We're in a git repository, so use current directory
|
||||
if [[ -f PKGBUILD ]]; then
|
||||
paths=(".")
|
||||
else
|
||||
pkgctl_repo_configure_usage
|
||||
@@ -232,19 +226,10 @@ pkgctl_repo_configure() {
|
||||
|
||||
pushd "${path}" >/dev/null
|
||||
|
||||
# Check if this is a packaging repository
|
||||
local is_packaging_repo=0
|
||||
if [[ -f PKGBUILD ]]; then
|
||||
is_packaging_repo=1
|
||||
fi
|
||||
|
||||
# Configure remote only for packaging repositories
|
||||
if (( is_packaging_repo )); then
|
||||
project_path=$(gitlab_project_name_to_path "${pkgbase}")
|
||||
remote_url="${GIT_REPO_BASE_URL}/${project_path}.git"
|
||||
if ! git remote add origin "${remote_url}" &>/dev/null; then
|
||||
git remote set-url origin "${remote_url}"
|
||||
fi
|
||||
project_path=$(gitlab_project_name_to_path "${pkgbase}")
|
||||
remote_url="${GIT_REPO_BASE_URL}/${project_path}.git"
|
||||
if ! git remote add origin "${remote_url}" &>/dev/null; then
|
||||
git remote set-url origin "${remote_url}"
|
||||
fi
|
||||
|
||||
# move the master branch to main
|
||||
@@ -254,7 +239,7 @@ pkgctl_repo_configure() {
|
||||
fi
|
||||
|
||||
# configure spec version and variant to avoid using development hooks in production
|
||||
git config devtools.version "${GIT_REPO_SPEC_VERSION:-1.0.0}"
|
||||
git config devtools.version "${GIT_REPO_SPEC_VERSION}"
|
||||
if [[ ${_DEVTOOLS_LIBRARY_DIR} == /usr/share/devtools ]]; then
|
||||
git config devtools.variant canonical
|
||||
else
|
||||
@@ -264,12 +249,8 @@ pkgctl_repo_configure() {
|
||||
|
||||
git config pull.rebase true
|
||||
git config branch.autoSetupRebase always
|
||||
|
||||
# Configure branch remote settings only for packaging repositories with remotes
|
||||
if (( is_packaging_repo )) && git remote | grep -q "^origin$"; then
|
||||
git config branch.main.remote origin
|
||||
git config branch.main.rebase true
|
||||
fi
|
||||
git config branch.main.remote origin
|
||||
git config branch.main.rebase true
|
||||
|
||||
git config transfer.fsckobjects true
|
||||
git config fetch.fsckobjects true
|
||||
|
@@ -185,10 +185,18 @@ prepare_chroot() {
|
||||
echo "$x" >>"$copydir/etc/makepkg.conf"
|
||||
done
|
||||
|
||||
cat > "$copydir/etc/sudoers.d/builduser-pacman" <<EOF
|
||||
builduser ALL = NOPASSWD: /usr/bin/pacman
|
||||
# TODO(gromit): check if this rule is sane
|
||||
# TODO(gromit): this will require a full container
|
||||
cat > "$copydir/etc/polkit-1/rules.d/10-systemd-nopasswd.rules" <<EOF
|
||||
polkit.addRule(function(action, subject) {
|
||||
if (action.id == "org.freedesktop.systemd1.manage-units") {
|
||||
if (subject.isInGroup("wheel")) {
|
||||
return polkit.Result.YES;
|
||||
}
|
||||
}
|
||||
});
|
||||
EOF
|
||||
chmod 440 "$copydir/etc/sudoers.d/builduser-pacman"
|
||||
chmod 440 "$copydir/etc/polkit-1/rules.d/10-systemd-nopasswd.rules"
|
||||
|
||||
cat > "$copydir/etc/gitconfig" <<EOF
|
||||
[safe]
|
||||
@@ -222,17 +230,14 @@ _chrootbuild() {
|
||||
# shellcheck source=/dev/null
|
||||
. /etc/profile
|
||||
|
||||
# Beware, there are some stupid arbitrary rules on how you can
|
||||
# use "$" in arguments to commands with "sudo -i". ${foo} or
|
||||
# ${1} is OK, but $foo or $1 isn't.
|
||||
# https://bugzilla.sudo.ws/show_bug.cgi?id=765
|
||||
sudo --preserve-env=SOURCE_DATE_EPOCH \
|
||||
--preserve-env=BUILDTOOL \
|
||||
--preserve-env=BUILDTOOLVER \
|
||||
-iu builduser bash -c 'cd /startdir; makepkg "$@"' -bash "$@"
|
||||
run0 --setenv=SOURCE_DATE_EPOCH \
|
||||
--setenv=BUILDTOOL \
|
||||
--setenv=BUILDTOOLVER \
|
||||
--via-shell --chdir='~' \
|
||||
--user=builduser -- bash -c 'cd /startdir; makepkg "$@"' -bash "$@"
|
||||
ret=$?
|
||||
case $ret in
|
||||
0|14)
|
||||
0)
|
||||
return 0;;
|
||||
*)
|
||||
return $ret;;
|
||||
@@ -243,7 +248,7 @@ _chrootnamcap() {
|
||||
pacman -S --needed --noconfirm namcap
|
||||
for pkgfile in /startdir/PKGBUILD /pkgdest/*; do
|
||||
echo "Checking ${pkgfile##*/}"
|
||||
sudo -u builduser namcap "$pkgfile" 2>&1 | tee "/logdest/${pkgfile##*/}-namcap.log"
|
||||
run0 --user=builduser -- namcap "$pkgfile" 2>&1 | tee "/logdest/${pkgfile##*/}-namcap.log"
|
||||
done
|
||||
}
|
||||
|
||||
@@ -252,8 +257,12 @@ download_sources() {
|
||||
chown "$makepkg_user:" "$WORKDIR"
|
||||
|
||||
# Ensure sources are downloaded
|
||||
sudo -u "$makepkg_user" --preserve-env=GNUPGHOME,SSH_AUTH_SOCK \
|
||||
env SRCDEST="$SRCDEST" BUILDDIR="$WORKDIR" \
|
||||
run0 --user="$makepkg_user" \
|
||||
--setenv=GNUPGHOME \
|
||||
--setenv=SSH_AUTH_SOCK \
|
||||
--setenv=SRCDEST="$SRCDEST" \
|
||||
--setenv=BUILDDIR="$WORKDIR" \
|
||||
--chdir=. -- \
|
||||
makepkg --config="$copydir/etc/makepkg.conf" --verifysource -o "${verifysource_args[@]}" ||
|
||||
die "Could not download sources."
|
||||
}
|
||||
@@ -400,7 +409,7 @@ if arch-nspawn "$copydir" \
|
||||
"${nspawn_build_args[@]}" \
|
||||
/chrootbuild "${makepkg_args[@]}"
|
||||
then
|
||||
mapfile -t pkgnames < <(sudo -u "$makepkg_user" bash -c 'source PKGBUILD; printf "%s\n" "${pkgname[@]}"')
|
||||
mapfile -t pkgnames < <(run0 --user="$makepkg_user" -- bash -c 'source PKGBUILD; printf "%s\n" "${pkgname[@]}"')
|
||||
move_products
|
||||
else
|
||||
(( ret += 1 ))
|
||||
@@ -453,7 +462,7 @@ else
|
||||
done
|
||||
|
||||
msg2 "Checking packages"
|
||||
sudo -u "$makepkg_user" checkpkg --rmdir --warn --makepkg-config "$copydir/etc/makepkg.conf" "${remotepkgs[@]/#file:\/\//}"
|
||||
run0 --user="$makepkg_user" -- checkpkg --rmdir --warn --makepkg-config "$copydir/etc/makepkg.conf" "${remotepkgs[@]/#file:\/\//}"
|
||||
fi
|
||||
true
|
||||
fi
|
||||
|
@@ -192,7 +192,7 @@ for p in "$@"; do
|
||||
pkgfile=${pkgfile_remote#file://}
|
||||
if [[ ! -f ${pkgfile} ]]; then
|
||||
msg "Downloading package '%s' into pacman's cache" "${pkgfile}"
|
||||
sudo pacman -Swdd --noconfirm --logfile /dev/null "${p}" || exit 1
|
||||
run0 -- pacman -Swdd --noconfirm --logfile /dev/null "${p}" || exit 1
|
||||
pkgfile_remote=$(pacman -Sddp "${p}" 2>/dev/null)
|
||||
pkgfile="${pkgfile_remote#file://}"
|
||||
fi
|
||||
|
@@ -1,71 +0,0 @@
|
||||
#!/usr/bin/env bats
|
||||
bats_require_minimum_version 1.5.0
|
||||
|
||||
# Load bats libraries
|
||||
load "/usr/lib/bats/bats-support/load.bash"
|
||||
load "/usr/lib/bats/bats-assert/load.bash"
|
||||
|
||||
export _DEVTOOLS_LIBRARY_DIR="${PWD}/src"
|
||||
|
||||
_pkgctl_repo_configure() {
|
||||
source "${_DEVTOOLS_LIBRARY_DIR}"/lib/repo/configure.sh
|
||||
pkgctl_repo_configure "$@"
|
||||
}
|
||||
|
||||
@test "repo-configure-valid-packaging" {
|
||||
local tmpdir
|
||||
tmpdir=$(mktemp -dt devtools.test.repo-configure.XXXXXX)
|
||||
pushd "${tmpdir}"
|
||||
git init
|
||||
git remote add origin "https://gitlab.archlinux.org/archlinux/packaging/packages/devtools.git"
|
||||
run _pkgctl_repo_configure
|
||||
assert_success
|
||||
popd
|
||||
rm -rf "${tmpdir}"
|
||||
}
|
||||
|
||||
@test "repo-configure-non-packaging" {
|
||||
local tmpdir
|
||||
tmpdir=$(mktemp -dt devtools.test.repo-configure.XXXXXX)
|
||||
pushd "${tmpdir}"
|
||||
git init
|
||||
git remote add origin "https://gitlab.com/kicad/libraries/kicad-packages3D.git"
|
||||
run _pkgctl_repo_configure
|
||||
assert_success
|
||||
popd
|
||||
rm -rf "${tmpdir}"
|
||||
}
|
||||
|
||||
@test "repo-configure-non-arch" {
|
||||
local tmpdir
|
||||
tmpdir=$(mktemp -dt devtools.test.repo-configure.XXXXXX)
|
||||
pushd "${tmpdir}"
|
||||
git init
|
||||
git remote add origin "https://github.com/torvalds/linux.git"
|
||||
run _pkgctl_repo_configure
|
||||
assert_success
|
||||
popd
|
||||
rm -rf "${tmpdir}"
|
||||
}
|
||||
|
||||
@test "repo-configure-no-git" {
|
||||
local tmpdir
|
||||
tmpdir=$(mktemp -dt devtools.test.repo-configure.XXXXXX)
|
||||
pushd "${tmpdir}"
|
||||
run ! _pkgctl_repo_configure
|
||||
assert_failure
|
||||
assert_output --partial "Not in a git repository"
|
||||
popd
|
||||
rm -rf "${tmpdir}"
|
||||
}
|
||||
|
||||
@test "repo-configure-local-git" {
|
||||
local tmpdir
|
||||
tmpdir=$(mktemp -dt devtools.test.repo-configure.XXXXXX)
|
||||
pushd "${tmpdir}"
|
||||
git init
|
||||
run _pkgctl_repo_configure
|
||||
assert_success
|
||||
popd
|
||||
rm -rf "${tmpdir}"
|
||||
}
|
Reference in New Issue
Block a user