secubox-deb/scripts/apt-publish.sh
CyberMind-FR bd7dda0c6f feat(secubox): complete meta-script generator Tasks 14-17
Task 14: Arch Profiles
- Add profiles/arch/arm64.yaml and profiles/arch/amd64.yaml
- Add ResolveWithArch() to merger for base → arch → tier chain
- Add tests for arch profile resolution

Task 15: Package secubox.yaml for All Packages
- Add scripts/generate-secubox-yaml.py generator script
- Generate 131 debian/secubox.yaml files with:
  - Category detection (security, network, system, etc.)
  - Tier assignment (all, lite, standard, pro)
  - API socket and UI path detection

Task 16: APT Repository Setup
- Add apt/conf/ reprepro configuration (multi-arch arm64/amd64)
- Add apt/hooks/lintian-check pre-publish validation
- Add scripts/apt-publish.sh and scripts/apt-sync.sh
- Add apt/README.md documentation

Task 17: CI Integration
- Add .github/workflows/build-secubox-cli.yml
- Build for linux-amd64 and linux-arm64
- Version injection via ldflags
- GitHub releases on tag push

Code Quality Fixes (Tasks 10-13):
- Add atomic writes for OTA boot control files (0600 perms)
- Fix NVME device extraction (nvme0n1p2 → nvme0n1)
- Add scanner.Err() checks in hardware detection
- Fix URL injection validation in fetch command
- Add proper cleanup on checksum failures

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2026-05-11 05:32:29 +02:00

179 lines
4.3 KiB
Bash
Executable File

#!/bin/bash
# scripts/apt-publish.sh
# Publish .deb packages to local APT repository with lintian validation
# SecuBox-DEB - CyberMind
set -euo pipefail
readonly SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
readonly REPO_ROOT="$(dirname "$SCRIPT_DIR")"
readonly APT_LOCAL="/srv/apt"
readonly APT_CONF="$REPO_ROOT/apt/conf"
readonly HOOKS_DIR="$REPO_ROOT/apt/hooks"
readonly CODENAME="${CODENAME:-bookworm}"
readonly COMPONENT="${COMPONENT:-main}"
# Colors
RED='\033[0;31m'
GREEN='\033[0;32m'
YELLOW='\033[1;33m'
NC='\033[0m'
usage() {
cat << EOF
Usage: $(basename "$0") [OPTIONS] <package.deb> [package2.deb ...]
Publish .deb packages to the SecuBox APT repository.
Options:
-c, --codename NAME Distribution codename (default: bookworm)
-C, --component NAME Component (default: main)
-s, --skip-lintian Skip lintian validation
-n, --dry-run Show what would be done
-h, --help Show this help message
Environment:
CODENAME Distribution codename (default: bookworm)
COMPONENT Component (default: main)
Examples:
$(basename "$0") packages/secubox-core/*.deb
$(basename "$0") -c bookworm-testing *.deb
$(basename "$0") --skip-lintian packages/*/*.deb
EOF
}
init_repo() {
if [ ! -d "$APT_LOCAL" ]; then
echo -e "${YELLOW}Initializing APT repository at $APT_LOCAL...${NC}"
sudo mkdir -p "$APT_LOCAL"/{conf,db,dists,pool,incoming,tmp}
sudo cp "$APT_CONF"/* "$APT_LOCAL/conf/"
sudo chown -R "$(whoami)" "$APT_LOCAL"
# Initialize reprepro
cd "$APT_LOCAL"
reprepro export
echo -e "${GREEN}Repository initialized.${NC}"
fi
}
run_lintian() {
local deb_file="$1"
if [ -x "$HOOKS_DIR/lintian-check" ]; then
"$HOOKS_DIR/lintian-check" "$deb_file"
else
echo -e "${YELLOW}Warning: lintian hook not found, skipping validation${NC}"
fi
}
publish_package() {
local deb_file="$1"
local skip_lintian="$2"
local dry_run="$3"
local codename="$4"
local component="$5"
local pkg_name=$(dpkg-deb -f "$deb_file" Package 2>/dev/null || echo "unknown")
local pkg_version=$(dpkg-deb -f "$deb_file" Version 2>/dev/null || echo "unknown")
local pkg_arch=$(dpkg-deb -f "$deb_file" Architecture 2>/dev/null || echo "unknown")
echo -e "Publishing: ${GREEN}${pkg_name}${NC} ${pkg_version} (${pkg_arch})"
# Run lintian if not skipped
if [ "$skip_lintian" != "true" ]; then
if ! run_lintian "$deb_file"; then
echo -e "${RED}Lintian validation failed for $deb_file${NC}"
return 1
fi
fi
if [ "$dry_run" = "true" ]; then
echo -e "${YELLOW}DRY RUN: Would add to $codename/$component${NC}"
return 0
fi
# Add to repository
cd "$APT_LOCAL"
reprepro -C "$component" includedeb "$codename" "$deb_file"
echo -e "${GREEN}Added to repository: $codename/$component${NC}"
}
# Parse arguments
SKIP_LINTIAN=false
DRY_RUN=false
PACKAGES=()
while [[ $# -gt 0 ]]; do
case $1 in
-c|--codename)
CODENAME="$2"
shift 2
;;
-C|--component)
COMPONENT="$2"
shift 2
;;
-s|--skip-lintian)
SKIP_LINTIAN=true
shift
;;
-n|--dry-run)
DRY_RUN=true
shift
;;
-h|--help)
usage
exit 0
;;
-*)
echo "Unknown option: $1"
usage
exit 1
;;
*)
PACKAGES+=("$1")
shift
;;
esac
done
if [ ${#PACKAGES[@]} -eq 0 ]; then
echo "Error: No packages specified"
usage
exit 1
fi
# Initialize repository if needed
init_repo
# Publish packages
success=0
failed=0
for pkg in "${PACKAGES[@]}"; do
if [ ! -f "$pkg" ]; then
echo -e "${RED}File not found: $pkg${NC}"
((failed++))
continue
fi
if [[ "$pkg" != *.deb ]]; then
echo -e "${YELLOW}Skipping non-.deb file: $pkg${NC}"
continue
fi
if publish_package "$pkg" "$SKIP_LINTIAN" "$DRY_RUN" "$CODENAME" "$COMPONENT"; then
((success++))
else
((failed++))
fi
done
echo ""
echo -e "Published: ${GREEN}$success${NC} Failed: ${RED}$failed${NC}"
if [ $failed -gt 0 ]; then
exit 1
fi