packaging/README.md (15830 bytes)
1 # Packaging sbm 2 3 Package definitions for sbm 0.3, one directory per format. Nothing here is 4 submitted anywhere yet, and nothing here changes the rest of the repository. 5 6 Two facts shape every file below. 7 8 1. **There is no licence.** The repository has no `LICENSE` file and no 9 licence has been chosen. Every format needs a licence field, so every 10 licence field holds the token `SBM_LICENSE_TBD`. It is not a guess and it 11 is not a default. Every occurrence is listed under 12 [Placeholders](#placeholders). 13 2. **There is no release tag and no tarball.** The source URL pattern is 14 `https://github.com/equwal/sbm/archive/refs/tags/v0.3.tar.gz`, which 15 returns 404 today. Checksums hold placeholder tokens. Where a format has a 16 live or VCS variant, it is provided as well, because those work now: 17 `arch/sbm-git`, `gentoo/.../sbm-9999.ebuild`, and `head` in the Homebrew 18 formula. 19 20 This is the edition without cloud sync. Nothing here packages, requires or 21 mentions a sync client. 22 23 ## What gets installed 24 25 `make install` copies the programs in `TOOLS` to `${DESTDIR}${PREFIX}/bin`: 26 27 bm bm-migrate bm-import bm-check bm-html bm-title bm-commit bm-watch 28 29 Nothing is compiled. There are no man pages. Every package calls 30 `make DESTDIR=... PREFIX=... install` rather than copying the scripts itself, 31 except the Windows packages, which unpack the release archive and generate 32 `.cmd` shims instead. 33 34 `README` is installed as documentation. `usertags` and `engines` are 35 examples, not configuration: they go to the examples directory of whatever 36 format is in use, and the user copies them to `~/.local/share/sbm/`. 37 38 ## Dependencies, as the packages express them 39 40 | | Programs | Why | 41 |---|---|---| 42 | Required | POSIX sh, awk | everything | 43 | Required | dmenu **or** fzf | the menu | 44 | Required | xclip **or** xsel **or** wl-clipboard | `bm --copy` | 45 | Recommended | xdg-utils | opening URLs (`xdg-open`) | 46 | Optional | curl | `bm-title`, `bm-check` | 47 | Optional | jq | `bm-import` of Chromium JSON files | 48 | Optional | git | `bm-commit` | 49 50 Only Debian, Gentoo and RPM can say "a or b". The others pick one program as 51 the hard dependency and name the alternatives in the optional list, with a 52 comment saying so: 53 54 * **Arch, FreeBSD, Gentoo, Debian, RPM**: dmenu is the first choice, because 55 `bm` prefers it whenever there is a display. 56 * **Alpine, Void, Homebrew, MacPorts, Chocolatey, Scoop, Nix**: fzf, because 57 it needs no display, and on macOS and Windows dmenu is not an option at 58 all. 59 60 `bm` picks dmenu when `$DISPLAY` or `$WAYLAND_DISPLAY` is set and fzf 61 otherwise, so installing both is fine and needs no configuration. 62 63 ## The formats 64 65 | Format | Path | Build and test locally | Where it goes | Status | 66 |---|---|---|---|---| 67 | Homebrew | `homebrew/sbm.rb` | `brew install --build-from-source ./sbm.rb`, `brew test sbm`, `brew audit --strict --new sbm` | Your own tap (`brew tap equwal/sbm`) first. homebrew-core has a notability bar: roughly 30 forks, 30 watchers, 75 stars, and a maintained, versioned release. sbm meets none of it today. | Written, not built. `license` and `sha256` are placeholders, so `brew audit` fails until they are real. `head` works now. | 68 | Gentoo | `gentoo/app-misc/sbm/` | Put it in a local overlay, then `ebuild sbm-0.3.ebuild manifest`, `emerge -av app-misc/sbm`, `FEATURES=test emerge app-misc/sbm`, `pkgcheck scan` | GURU (the user overlay) first: it takes anyone. `::gentoo` needs a developer or the proxy-maintainers project; `metadata.xml` already names proxy-maint. | Written, not built. `pkgcheck` will flag `SBM_LICENSE_TBD` as a nonexistent licence. `sbm-9999.ebuild` works now. | 69 | Arch | `arch/sbm/PKGBUILD`, `arch/sbm-git/PKGBUILD` | `makepkg -si`, `makepkg --printsrcinfo > .SRCINFO`, `namcap PKGBUILD` and `namcap *.pkg.tar.zst` | AUR: `git clone ssh://aur@aur.archlinux.org/sbm.git`, commit `PKGBUILD` and `.SRCINFO`, push. No review queue. `[extra]` needs a Trusted User. | Written, not built. `sbm-git` works now; `sbm` needs the tag. `.SRCINFO` is not committed here: it is generated, and it would go stale. | 70 | Debian | `debian/debian/`, notes in `debian/apt/README.md` | `dpkg-buildpackage -us -uc -b`, `lintian -i -I --pedantic`, `autopkgtest`. See `debian/apt/README.md`. | Debian proper needs an ITP bug and a sponsor through mentors.debian.net, which takes weeks. Your own signed apt repository (reprepro or aptly) works the same day; `debian/apt/README.md` covers both. | Written, not built. `debian/rules` and `debian/tests/*` need the execute bit set after copying. | 71 | Chocolatey | `chocolatey/sbm.nuspec`, `chocolatey/tools/` | `choco pack` (done, see below), then `choco install sbm -s .` on a throwaway machine | community.chocolatey.org, with automated checks plus human moderation. Moderators dislike embedded binaries and like package scripts that download from the official source, which is what this does. | `choco pack` succeeds. Not installed or pushed from here. | 72 | Scoop | `scoop/sbm.json` | `scoop install .\sbm.json`, `scoop checkver sbm <bucket>`, `scoop bucket add` your own bucket | Your own bucket repository. `ScoopInstaller/Extras` takes pull requests; `Main` is for widely used, well known programs. | Written, not installed. JSON parses and the shim generator was run for real. | 73 | Nix | `nix/default.nix`, `nix/flake.nix` | `nix build -f default.nix`, or `nix build .#sbm` in this directory, then `nixpkgs-review` | A pull request against NixOS/nixpkgs, package file under `pkgs/by-name/sb/sbm/package.nix`. | Written, not evaluated. `meta.license` must become `lib.licenses.<id>`, an attribute and not a string, before nixpkgs will take it. | 74 | RPM | `rpm/sbm.spec` | `rpmbuild -ba sbm.spec`, `mock -r fedora-rawhide-x86_64 --rebuild *.src.rpm`, `rpmlint sbm.spec` | Fedora: a package review bug in Bugzilla and a sponsor for the first package. openSUSE: a submit request to Factory through the Open Build Service, which is faster. | Written, not built. Rich dependencies `(dmenu or fzf)` need rpm 4.13 or newer: Fedora, and openSUSE Leap 15 and later. | 75 | Alpine | `alpine/APKBUILD` | `abuild -r`, `abuild checksum`, `apkbuild-lint APKBUILD` | A merge request against `alpinelinux/aports`, in `community/`. | Written, not built. Alpine hashes with sha512, so the token there is `SBM_SHA512_TBD`. | 76 | Void | `void/srcpkgs/sbm/template` | Inside a void-packages checkout: `./xbps-src pkg sbm`, `xlint srcpkgs/sbm/template` | A pull request against `void-linux/void-packages`. | Written, not built. | 77 | FreeBSD | `freebsd/deskutils/sbm/` | In a ports tree: `make makesum`, `make stage`, `make check-plist`, `make test`, `portlint -A` | A `ports` bug in Bugzilla with the shar or a patch, or a pull request against `freebsd/freebsd-ports`. | Written, not built. `USES=gmake` is needed; see [Upstream notes](#upstream-notes). | 78 | MacPorts | `macports/Portfile` | `port lint --nitpick`, `sudo port -v install` from a local ports tree | A pull request against `macports/macports-ports`. | Written, not built. `checksums` needs three tokens replaced, not one. | 79 | Guix | `guix/sbm.scm` | `guix build -L packaging/guix sbm`, `guix shell -L packaging/guix sbm -- bm --list`, `guix lint -L packaging/guix sbm` | A patch to `guix-patches@gnu.org`, or a channel of your own, which works immediately. | Written, not evaluated. The `#:use-module` lines are a best guess at where each program lives in `gnu/packages/`; `guix build` will say if one is wrong. | 80 81 ## Placeholders 82 83 One search and replace per token finishes each job. Nothing else in these 84 files is a placeholder. 85 86 ### `SBM_LICENSE_TBD` — 31 lines in 16 files 87 88 Replace with the licence, in whatever spelling the format wants: an SPDX 89 identifier for most, a name from `licenses/` for Gentoo, an abbreviation from 90 `Mk/bsd.licenses.db.mk` for FreeBSD, a `(guix licenses)` variable for Guix, a 91 `lib.licenses` attribute for Nix, and the full text plus a short name for 92 Debian. 93 94 | File | Lines | 95 |---|---| 96 | `alpine/APKBUILD` | 10 (comment), 13 | 97 | `arch/sbm/PKGBUILD` | 10 (comment), 14 | 98 | `arch/sbm-git/PKGBUILD` | 14 | 99 | `chocolatey/sbm.nuspec` | 16 (comment), 19 | 100 | `debian/apt/README.md` | 13 (prose) | 101 | `debian/debian/copyright` | 8, 12, 14, 18 (prose) | 102 | `freebsd/deskutils/sbm/Makefile` | 11 (comment), 14 | 103 | `gentoo/app-misc/sbm/sbm-0.3.ebuild` | 14 (comment), 16 | 104 | `gentoo/app-misc/sbm/sbm-9999.ebuild` | 14 (comment), 15 | 105 | `guix/sbm.scm` | 128 (comment), 131 | 106 | `homebrew/sbm.rb` | 7 (comment), 9 | 107 | `macports/Portfile` | 26 (comment), 29 | 108 | `nix/default.nix` | 101 | 109 | `rpm/sbm.spec` | 7 (comment), 10 | 110 | `scoop/sbm.json` | 10 (comment), 17 | 111 | `void/srcpkgs/sbm/template` | 15 (comment), 17 | 112 113 One of these is not a bare token. `choco pack` refuses a `licenseUrl` that 114 does not parse as a URL (error CHCU0001), so 115 `chocolatey/sbm.nuspec` line 19 carries the token inside a URL path: 116 `https://github.com/equwal/sbm/blob/master/SBM_LICENSE_TBD`. That URL does 117 not resolve. The same search and replace still finds it. 118 119 ### Checksum placeholders 120 121 No tag means no tarball means no checksum. Four tokens, because the formats 122 do not agree on a hash. 123 124 `SBM_SHA256_TBD` — 15 lines in 9 files: 125 126 | File | Lines | Replace by running | 127 |---|---|---| 128 | `arch/sbm/PKGBUILD` | 32 (comment), 33 | `makepkg -g` | 129 | `chocolatey/tools/chocolateyInstall.ps1` | 24 (comment), 26 | `Get-FileHash .\v0.3.tar.gz -Algorithm SHA256` | 130 | `freebsd/deskutils/sbm/distinfo` | 2 | `make makesum` | 131 | `guix/sbm.scm` | 40 (comment), 42 | `guix download <url>` (base32, not hex) | 132 | `homebrew/sbm.rb` | 5 | `brew fetch --build-from-source sbm` | 133 | `macports/Portfile` | 34 | `port -v checksum sbm` | 134 | `nix/default.nix` | 34 (comment), 36 | `nix-prefetch-url --unpack <url>` (SRI, not hex) | 135 | `scoop/sbm.json` | 11 (comment), 26 | `scoop checkver sbm <bucket> -u` | 136 | `void/srcpkgs/sbm/template` | 21 (comment), 22 | `xgensum -i srcpkgs/sbm/template` | 137 138 `SBM_SHA512_TBD` — `alpine/APKBUILD` lines 53 (comment) and 55. Alpine hashes 139 with sha512. Replace by running `abuild checksum`. 140 141 `SBM_RMD160_TBD` and `SBM_SIZE_TBD` — `macports/Portfile` lines 33 and 35. 142 MacPorts wants rmd160, sha256 and the byte size. `port -v checksum sbm` 143 prints all three. 144 145 `freebsd/deskutils/sbm/distinfo` also has `TIMESTAMP = 0` and `SIZE ... = 0`. 146 `make makesum` rewrites the whole file, so those need no hand editing. 147 148 ### Native "skip" values, used on purpose 149 150 `arch/sbm-git/PKGBUILD` line 29 uses `sha256sums=('SKIP')`. That is correct, 151 not a placeholder: a git source has no fixed archive to hash. 152 153 ## Upstream notes 154 155 Things a reviewer will raise, none of which are fixed in this directory, 156 because nothing outside `packaging/` was touched. 157 158 * **No `LICENSE` file, no licence chosen.** Every repository above will 159 refuse the package, and an unlicensed work is not distributable at all. 160 This is the one blocker. 161 * **No tags.** Nine of the twelve formats need a versioned archive. 162 `debian/watch`, `checkver` and `autoupdate` all look for `v*` tags and find 163 nothing. 164 * **No man pages.** `TODO` lists them as unfinished. Debian, Fedora and 165 FreeBSD all expect a man page for a program in `bin`, and lintian will say 166 so. `config.mk` defines `MANPREFIX` and the `Makefile` never uses it. 167 * **`Makefile` needs GNU make, not POSIX make.** The first line is 168 `include config.mk`. BSD make wants `.include "config.mk"` and cannot parse 169 the file at all. That is why the FreeBSD port sets `USES=gmake`, which is 170 an odd thing to need in a project whose README says it keeps to POSIX. POSIX 171 make only gained `include` in the 2024 edition. Changing the line to 172 `.include` would break GNU make instead; supporting both means a small 173 shim, or moving the variables into the `Makefile`. 174 * **`install` and `uninstall` disagree.** `install` copies `${TOOLS}`; 175 `uninstall` removes `${SCRIPTS}`, the full list. Harmless for packages, 176 which never call `uninstall`, but surprising. 177 * **`.gitignore` contains `bm`.** The main program is already tracked, so it 178 is unaffected today, but deleting and re-adding `bm` would silently fail. 179 `bmks` and `tags.*` in the same file are fine. 180 * **`bm` has no `--version`.** Several ecosystems' smoke tests reach for it 181 first. The test blocks here use `bm --list` and `bm --merge` instead, which 182 are the two actions that never open a menu. 183 * **`make check` is not hermetic.** It runs shellcheck only when shellcheck 184 happens to be installed, so the same command lints or does not lint 185 depending on the machine. The Gentoo, Nix, Guix and MacPorts definitions 186 call `sh test/run.sh` directly for that reason, and declare shellcheck as a 187 build-time dependency where the format has one. 188 * **The test suite is not declared anywhere.** It uses `jq`, `git`, `node` 189 and `make` when they are present and skips those groups otherwise, so it 190 passes either way, but a build that has none of them tests less than a 191 build that has all of them. 192 * `DESTDIR` itself is well behaved: `make install DESTDIR=... PREFIX=...` 193 creates the directory and copies the scripts with mode 755, and the test 194 suite has its own check that `TOOLS` is honoured. 195 196 ## Release checklist 197 198 1. **Choose a licence.** Add `LICENSE` at the top of the repository and a 199 line in `README`. Nothing else on this list matters until this is done. 200 2. Replace `SBM_LICENSE_TBD` everywhere listed above. Then add the licence 201 file to the packages that install one: 202 * Arch: `install -Dm644 LICENSE "$pkgdir/usr/share/licenses/$pkgname/LICENSE"` 203 * Alpine: `install -Dm644 LICENSE "$pkgdir"/usr/share/licenses/$pkgname/LICENSE` 204 * Void: `vlicense LICENSE` 205 * RPM: `%license LICENSE` in `%files` 206 * FreeBSD: `LICENSE_FILE=${WRKSRC}/LICENSE` 207 * Debian: the full text goes into `debian/copyright` 208 3. Tag the release: `git tag -a v0.3 -m 'sbm 0.3' && git push --tags`, and 209 check that 210 `https://github.com/equwal/sbm/archive/refs/tags/v0.3.tar.gz` downloads 211 and unpacks to `sbm-0.3/`. 212 4. Compute the checksums and replace the four checksum tokens, using the 213 commands in the table above. 214 5. Optional, and worth doing first: write the man pages that `TODO` asks for, 215 and decide what to do about `include config.mk` versus BSD make. 216 6. Submit, easiest first: 217 * **AUR** (`sbm`, `sbm-git`): push. No review. 218 * **Your own apt repository**: `debian/apt/README.md`. 219 * **Your own Homebrew tap and Scoop bucket**: push. 220 * **A Guix channel**: push. 221 * **GURU** (Gentoo user overlay): pull request. 222 * **Void, Alpine, nixpkgs, macports-ports, freebsd-ports**: pull request 223 or bug, reviewed but not sponsored. 224 * **Chocolatey community**: push, then wait for moderation. 225 * **Fedora, openSUSE Factory**: review bug or submit request. 226 * **Debian proper**: ITP bug, then a sponsor. Slowest. 227 * **homebrew-core**: only once the project clears the notability bar. 228 229 ## What was checked on this machine, and what was not 230 231 Checked: `bash -n` on both PKGBUILDs, the APKBUILD, the Void template and 232 both ebuilds; `sh -n` on the autopkgtest scripts; Python XML parsing of 233 `metadata.xml` and `sbm.nuspec`; Python JSON parsing of `sbm.json`; the 234 PowerShell language parser on both `.ps1` files; `choco pack`, which built a 235 `.nupkg` that was then deleted; bracket balance and field syntax for the Nix, 236 Guix, Tcl, Ruby and Debian files; and the generated Windows `.cmd` shim, run 237 for real against the `bm` and `bm-html` in this repository. 238 239 Not checked: nothing was installed or built as a package, because that needs 240 each distribution. There is no Ruby here, so the formula was not run through 241 `ruby -c`. There is no `make` and no shellcheck here, and `test/run.sh` does 242 not run under Git Bash: `mkdir -m 700` inside the Windows temporary directory 243 fails with "cannot change permissions". That is an MSYS and Windows problem, 244 not a fault in the suite.