Skip to content

Add the loopwire-git AUR channel - #32

Merged
dskvr merged 1 commit into
masterfrom
feature/29-loopwire-git
Sep 4, 2026
Merged

dskvr merged 1 commit into
masterfrom
feature/29-loopwire-git

Conversation

@dskvr

@dskvr dskvr commented Sep 4, 2026

Copy link
Copy Markdown
Member

Closes #29.

Summary

  • add a separate loopwire-git AUR recipe for the protected default branch
  • derive monotonic VCS package versions and semver-compatible Tauri development versions
  • preserve stable loopwire and prebuilt loopwire-bin as independent package bases
  • extend local/CI build proof, metadata smoke, publisher selection, protected workflow input, and docs

Security boundary

The moving-source build runs in the keyless verification lane. The AUR-key publisher never executes VCS source; it validates and pushes reviewed PKGBUILD, .SRCINFO, and LICENSE-MIT metadata only. Default-branch identity is passed and validated end-to-end, including the PKGBUILD #branch= selector.

Live AUR evidence

  • loopwire-git 0.1.0.r8.g007e47e-1
  • AUR commit e9ad7fbe8d2f3c2d6a9885125849daf7bda4d1f2
  • package page and remote Git commit verified after push

Validation

  • full makepkg build of loopwire-git 0.1.0.r8.g007e47e-1
  • complete runtime, desktop entry, icon, and license content checks
  • namcap warnings only; no errors
  • pnpm verify:aur
  • pnpm verify:requirements
  • pnpm verify:docs
  • pnpm verify:scripts
  • pnpm verify:workflows
  • pnpm typecheck
  • pnpm test — core 81, audio-host 123, desktop 91 passed
  • pnpm build
  • pnpm verify:site
  • security re-review: no remaining blocker

Known gap

The package was built but not installed into a fresh Arch VM. Automated AUR publication still requires a dedicated passphrase-free key in the protected aur GitHub environment; local publication used the existing interactive AUR key.

Add loopwire-git as a third package base that follows the protected default
branch and derives a monotonic version from Git history. Keep its moving-source
build in a keyless verification lane; the AUR-key publisher only pushes reviewed
metadata after that independent proof.

Constraint: VCS packages must use a -git suffix and cannot execute moving source with publication credentials present
Rejected: Fold rolling behavior into loopwire | would make the stable package non-reproducible and mislabel its update contract
Confidence: high
Scope-risk: moderate
Reversibility: clean
Directive: Keep loopwire, loopwire-bin, and loopwire-git as isolated package bases with one canonical default branch
Tested: Full makepkg build at 0.1.0.r8.g007e47e, namcap, worktree publication preflight, AUR metadata smoke, requirements, docs, scripts, workflows, typecheck, tests, build
Not-tested: Installation into a fresh Arch VM; workflow publication without a configured automation key
Related: #29
@dskvr
dskvr force-pushed the feature/29-loopwire-git branch from 677ab30 to f107186 Compare September 4, 2026 13:29
@dskvr
dskvr merged commit 20b816e into master Sep 4, 2026
3 checks passed
@dskvr
dskvr deleted the feature/29-loopwire-git branch September 4, 2026 13:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Add a loopwire-git AUR package

1 participant