packaging/debian/apt/README.md (3907 bytes)
1 # Building the .deb, and serving it from your own apt repository 2 3 `../debian/` is a complete `debian/` directory. It is kept one level down so 4 that `packaging/debian/` can hold this note beside it. To use it, copy it to 5 the top of a source tree: 6 7 cp -r packaging/debian/debian /path/to/sbm-0.3/debian 8 9 ## Before the first build 10 11 Two things in `debian/` are placeholders. 12 13 * `debian/copyright` says `SBM_LICENSE_TBD`. Nothing can be uploaded 14 anywhere until a real licence is chosen: an unlicensed work is not 15 distributable. 16 * `debian/changelog` says `UNRELEASED` and has no `Closes:` line, because no 17 ITP bug has been filed. 18 19 Git does not carry the execute bit through every path this directory may 20 travel, so check it: 21 22 chmod 755 debian/rules debian/tests/smoke debian/tests/upstream-suite 23 24 ## Building 25 26 `3.0 (quilt)` needs an orig tarball beside the source directory: 27 28 sbm-0.3.orig.tar.gz 29 sbm-0.3/debian/... 30 31 Once v0.3 is tagged, the tarball is the release archive renamed: 32 33 wget -O sbm-0.3.orig.tar.gz \ 34 https://github.com/equwal/sbm/archive/refs/tags/v0.3.tar.gz 35 36 Until then, `make dist` in the source tree produces `sbm-0.3.tar.gz` with the 37 same top level directory name, which works for local builds. 38 39 Build a binary package: 40 41 cd sbm-0.3 42 dpkg-buildpackage -us -uc -b 43 44 Build source and binary, in a clean chroot, which is what an upload needs: 45 46 sbuild -d unstable 47 # or 48 pbuilder build ../sbm_0.3-1.dsc 49 50 Check it: 51 52 lintian -i -I --pedantic ../sbm_0.3-1_all.deb ../sbm_0.3-1.dsc 53 autopkgtest ../sbm_0.3-1_all.deb -- null 54 55 Install it locally: 56 57 sudo apt install ./sbm_0.3-1_all.deb 58 59 ## Getting into Debian proper 60 61 Debian needs a Debian Developer to sponsor the first upload. 62 63 1. Choose a licence and add a `LICENSE` file upstream. 64 2. Tag `v0.3` upstream so `debian/watch` has something to find. 65 3. File an ITP bug: `reportbug wnpp`, type `ITP`. Put the bug number in 66 `debian/changelog` as `Closes: #NNNNNN`. 67 4. Build in a clean chroot and get `lintian --pedantic` quiet. 68 5. Upload the source package to <https://mentors.debian.net/>. 69 6. Ask for a sponsor on debian-mentors@lists.debian.org, or in the RFS bug. 70 71 This takes weeks to months. The apt repository below works the same day. 72 73 ## Your own signed apt repository 74 75 Both tools below produce a repository that `apt` trusts once the user adds 76 your key. Pick one. 77 78 ### reprepro 79 80 `conf/distributions`: 81 82 Origin: equwal.com 83 Label: sbm 84 Codename: stable 85 Architectures: amd64 arm64 source 86 Components: main 87 Description: sbm packages 88 SignWith: YOURKEYID 89 90 Then: 91 92 mkdir -p ~/apt/conf # put the file above in there 93 cd ~/apt 94 reprepro includedeb stable /path/to/sbm_0.3-1_all.deb 95 reprepro include stable /path/to/sbm_0.3-1_amd64.changes # source too 96 97 `reprepro` signs `Release` with the key named in `SignWith`. Copy `~/apt` 98 to any static web server; nothing server side is needed. 99 100 ### aptly 101 102 aptly repo create -distribution=stable -component=main sbm 103 aptly repo add sbm /path/to/sbm_0.3-1_all.deb 104 aptly publish repo -gpg-key=YOURKEYID sbm 105 # publishes under ~/.aptly/public; copy that to the web server 106 107 `aptly` can also mirror and snapshot, which matters once there is more than 108 one package. 109 110 ### The key 111 112 Export the public half in binary form, which is what modern apt wants: 113 114 gpg --export YOURKEYID > equwal-archive-keyring.gpg 115 116 Serve it next to the repository. Users then write 117 `/etc/apt/sources.list.d/sbm.sources`: 118 119 Types: deb 120 URIs: https://example.com/apt 121 Suites: stable 122 Components: main 123 Signed-By: /usr/share/keyrings/equwal-archive-keyring.gpg 124 125 and put the exported key at that path. Do not tell users to pipe a key into 126 `apt-key`: it has been removed. 127 128 `Architectures: amd64 arm64` is only about the index. The package itself is 129 `Architecture: all`, so one build serves every architecture.