- modules_mgmt.rs: reject module names containing path separators, `..`,
or absolute paths before joining onto modules_dir (install_from_local,
remove_module, read_module_manifest); adds canonicalized containment
check as defense in depth. Manifest-supplied names and CLI args were
previously joined unsanitized, allowing path traversal on install/remove.
- breadd/src/lua/mod.rs: bread.exec now runs via `sh -c` instead of
`sh -lc`; no documented reason was found for login-shell semantics.
- Unify the two independently hand-written glob matchers (subscription
dispatch in breadd/src/core/subscriptions.rs vs. the CLI --filter path
in breadd/src/ipc/mod.rs) into one implementation in
bread-shared/src/glob.rs, used by both call sites.
- Remove the dead bread-sync/ tree (already excluded from the workspace
and fully unreferenced) and its stale PKGBUILD deps (libgit2, git
optdepend) and packaging docs mention.
- Correct the version-number transposition bug ("6.2.0" instead of
"0.6.2"/"0.6.6") across bread-shared, breadd, and bread-cli Cargo.toml,
and fix PKGBUILD's stale pkgver, so Cargo.toml/doctor/PKGBUILD all agree
with the latest git tag (v0.6.6).
28 lines
733 B
Markdown
28 lines
733 B
Markdown
Arch packaging
|
|
==============
|
|
|
|
`PKGBUILD` builds and installs both `breadd` and `bread` from source.
|
|
|
|
## Local build
|
|
|
|
```bash
|
|
makepkg -si
|
|
```
|
|
|
|
## Before publishing to AUR
|
|
|
|
1. Tag a release on GitHub.
|
|
2. Update `pkgver` to match the tag.
|
|
3. Update `source` to the release tarball URL.
|
|
4. Run `updpkgsums` (or manually set `sha256sums`).
|
|
5. Update `url` if the repository has moved.
|
|
6. Set `depends` accurately — at minimum: `glibc`. Add `udev` if not linking statically.
|
|
|
|
## Runtime dependencies
|
|
|
|
| Package | Required | Notes |
|
|
|---------|----------|-------|
|
|
| `glibc` | yes | always |
|
|
| `udev` | yes | device events |
|
|
| `dbus` | optional | UPower battery events |
|
|
| `libnotify` | optional | `bread.notify()` (uses `notify-send`) |
|