- Add minisign-based signing/verification for the bakery index: scripts/gen-index.sh signs index.json (MINISIGN_SEC_KEY env var, dormant no-op with a loud warning until a key is provisioned); bakery/src/manifest.rs fetches index.json.minisig and verifies it with minisign-verify against a hardcoded PUBKEY before parsing/caching, and re-verifies the cached copy on every load (falls back to one re-fetch if the cache predates signing or fails verification; a fresh fetch that fails verification is a hard error). - Close the previously-unchecksummed config-example and systemd-unit downloads in bakery/src/install.rs (scaffold_config, install_service): index.json now carries `sha256`/`example_sha256` for these artifacts (computed in gen-index.sh), verified via the same download::verify_sha256 used for binaries. Downloads without a matching sha256 in the index are refused rather than installed unverified. - scripts/get.sh now verifies the bakery release binary itself against a pinned minisign public key before installing it (falls back to the existing sha256-only check with a loud warning if no .minisig is published yet or minisign isn't installed; a present-but-invalid signature is a hard failure). - Add dormant "sign release binary" steps to the bakery and bread-theme release workflows (.github/workflows/release.yml, .forgejo/workflows/release-bread-theme.yml), gated on secrets that are not yet configured — binaries ship unsigned exactly as before until the owner wires up the secret. - .gitignore: add *.minisign-sec / minisign.key so the signing key can never be committed by accident. - bread-theme: fix stale docs describing a "Catppuccin Mocha fallback" (BREAD_DESIGN_SYSTEM.md, README.md, Cargo.toml/bakery.toml/registry descriptions) — the actual implementation (palette.rs) uses a fixed BOS dark base with only accent colors from pywal. - bread-theme: fix the legacy css_vars() path, which had its own hand-written @define-color block that predated the `accent` and computed `on-*` ink colors used by the rest of the stylesheet — any caller whose CSS referenced those names against css_vars()'s output would hit undefined colors (the illegible-text bug). css_vars() now delegates to the same define_colors() the full stylesheet uses, so the two can't drift apart again.
121 lines
4 KiB
Bash
Executable file
121 lines
4 KiB
Bash
Executable file
#!/usr/bin/env bash
|
|
# Smoke-test gen-index.sh against a minimal fixture DL_DIR tree.
|
|
# Verifies that services, config, system_deps, optional_system_deps,
|
|
# description, and post_install are all populated correctly.
|
|
set -euo pipefail
|
|
|
|
REPO_ROOT="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)"
|
|
FIXTURE="$(mktemp -d)"
|
|
FAKE_REGISTRY="$(mktemp -d)"
|
|
trap 'rm -rf "${FIXTURE}" "${FAKE_REGISTRY}"' EXIT
|
|
|
|
fail() { echo "FAIL: $*" >&2; exit 1; }
|
|
|
|
# ── Build a minimal release tree for "fakepkg" ───────────────────────────────
|
|
PKG_VER_DIR="${FIXTURE}/fakepkg/0.1.0"
|
|
mkdir -p "${PKG_VER_DIR}"
|
|
|
|
printf 'fake-binary-content' > "${PKG_VER_DIR}/fakepkg-x86_64"
|
|
sha256sum "${PKG_VER_DIR}/fakepkg-x86_64" | awk '{print $1}' \
|
|
> "${PKG_VER_DIR}/fakepkg-x86_64.sha256"
|
|
printf '[Unit]\nDescription=fakepkg\n' > "${PKG_VER_DIR}/fakepkg.service"
|
|
printf '# example config\n' > "${PKG_VER_DIR}/fakepkg.example.toml"
|
|
|
|
cat > "${PKG_VER_DIR}/bakery.toml" <<'TOML'
|
|
name = "fakepkg"
|
|
description = "A fake package for testing"
|
|
binaries = ["fakepkg"]
|
|
system_deps = ["gtk4"]
|
|
optional_system_deps = ["hyprland"]
|
|
bread_deps = []
|
|
|
|
[[service]]
|
|
unit = "fakepkg.service"
|
|
enable = true
|
|
|
|
[config]
|
|
dir = "~/.config/fakepkg"
|
|
example = "fakepkg.example.toml"
|
|
|
|
[install]
|
|
post_install = ["echo installed"]
|
|
TOML
|
|
|
|
# gen-index looks for bakery.toml at ${DL_DIR}/<name>/bakery.toml (no version)
|
|
cp "${PKG_VER_DIR}/bakery.toml" "${FIXTURE}/fakepkg/bakery.toml"
|
|
ln -s "${PKG_VER_DIR}" "${FIXTURE}/fakepkg/latest"
|
|
|
|
# ── Minimal registry pointing only at fakepkg ────────────────────────────────
|
|
mkdir -p "${FAKE_REGISTRY}/registry"
|
|
cat > "${FAKE_REGISTRY}/registry/bread-ecosystem.toml" <<'TOML'
|
|
[ecosystem]
|
|
name = "test"
|
|
|
|
[[products]]
|
|
name = "fakepkg"
|
|
repo = "Test/fakepkg"
|
|
description = "A fake package"
|
|
TOML
|
|
|
|
# ── Run gen-index with overridden SCRIPT_DIR and DL_DIR ──────────────────────
|
|
OUT="${FIXTURE}/index.json"
|
|
SCRIPT_DIR="${FAKE_REGISTRY}" DL_DIR="${FIXTURE}" DL_BASE="https://dl.test" \
|
|
bash "${REPO_ROOT}/scripts/gen-index.sh" 2>&1 | sed 's/^/ [gen-index] /'
|
|
|
|
[[ -f "${OUT}" ]] || fail "index.json was not produced"
|
|
|
|
# ── Assertions ────────────────────────────────────────────────────────────────
|
|
jq -e '.packages.fakepkg' "${OUT}" > /dev/null \
|
|
|| fail "fakepkg missing from index"
|
|
|
|
check() {
|
|
local label="$1" expected="$2" actual="$3"
|
|
[[ "${actual}" == "${expected}" ]] \
|
|
|| fail "${label}: expected '${expected}', got '${actual}'"
|
|
}
|
|
|
|
check "description" \
|
|
"A fake package for testing" \
|
|
"$(jq -r '.packages.fakepkg.description' "${OUT}")"
|
|
|
|
check "system_deps" \
|
|
"gtk4" \
|
|
"$(jq -r '.packages.fakepkg.system_deps | join(",")' "${OUT}")"
|
|
|
|
check "optional_system_deps" \
|
|
"hyprland" \
|
|
"$(jq -r '.packages.fakepkg.optional_system_deps | join(",")' "${OUT}")"
|
|
|
|
check "services[0].unit" \
|
|
"fakepkg.service" \
|
|
"$(jq -r '.packages.fakepkg.services[0].unit' "${OUT}")"
|
|
|
|
check "services[0].enable" \
|
|
"true" \
|
|
"$(jq -r '.packages.fakepkg.services[0].enable' "${OUT}")"
|
|
|
|
check "config.dir" \
|
|
"~/.config/fakepkg" \
|
|
"$(jq -r '.packages.fakepkg.config.dir' "${OUT}")"
|
|
|
|
check "config.example" \
|
|
"fakepkg.example.toml" \
|
|
"$(jq -r '.packages.fakepkg.config.example' "${OUT}")"
|
|
|
|
check "binaries[0].name" \
|
|
"fakepkg-x86_64" \
|
|
"$(jq -r '.packages.fakepkg.binaries[0].name' "${OUT}")"
|
|
|
|
check "post_install[0]" \
|
|
"echo installed" \
|
|
"$(jq -r '.packages.fakepkg.post_install[0]' "${OUT}")"
|
|
|
|
check "services[0].sha256" \
|
|
"$(sha256sum "${PKG_VER_DIR}/fakepkg.service" | awk '{print $1}')" \
|
|
"$(jq -r '.packages.fakepkg.services[0].sha256' "${OUT}")"
|
|
|
|
check "config.example_sha256" \
|
|
"$(sha256sum "${PKG_VER_DIR}/fakepkg.example.toml" | awk '{print $1}')" \
|
|
"$(jq -r '.packages.fakepkg.config.example_sha256' "${OUT}")"
|
|
|
|
echo "OK: all gen-index assertions passed"
|