release: correct ZUPT 5.2.3 integration

This commit is contained in:
Cristian Cezar Moisés 2026-08-31 15:33:17 -03:00
commit 09dc804b3e
31 changed files with 336 additions and 187 deletions

View file

@ -11,7 +11,7 @@
# Test locally with `makepkg -s` after the release archive is published.
pkgname=zupt
pkgver=5.2.2
pkgver=5.2.3
pkgrel=1
pkgdesc='Pure-C11 post-quantum backup compression utility (AES-256-CTR + HMAC-SHA256 + ML-KEM-768 + X25519)'
arch=('x86_64')
@ -22,8 +22,8 @@ makedepends=('gcc' 'git' 'make')
checkdepends=('python')
source=("${pkgname}-${pkgver}.tar.gz::https://github.com/cristiancmoises/zupt/releases/download/v${pkgver}/${pkgname}-${pkgver}.tar.gz")
# Updated from the byte-reproducible upstream release archive before publishing.
sha256sums=('ee28e7be2b8725189b88ea13e0951c535d3516b44b47d05d5f1fce245d64c553')
# Replace only after generating the byte-reproducible final release archive.
sha256sums=('REPLACE_AFTER_FINAL_ARCHIVE_SHA256')
build() {
cd "${pkgname}-${pkgver}"

View file

@ -1,3 +1,11 @@
zupt (5.2.3-1) UNRELEASED; urgency=medium
* Derive package checks from the upstream version header and stabilize the
GUI version output consumed by package gates.
* Replace busybox-gawk before installing the native openSUSE RPM toolchain.
-- Cristian Cezar Moisés <sac@securityops.co> Mon, 31 Aug 2026 18:15:00 +0000
zupt (5.2.2-1) UNRELEASED; urgency=medium
* Prepare a source-only upstream release and remove incomplete vendored SDK

View file

@ -62,7 +62,7 @@
xcb-util-renderutil xcb-util-wm xcb-util-cursor
libinput-minimal mtdev libevdev eudev))
(define %zupt-version "5.2.2")
(define %zupt-version "5.2.3")
(define %zupt-source
(origin
@ -72,7 +72,7 @@
"/releases/download/v" %zupt-version
"/zupt-" %zupt-version ".tar.gz"))
(sha256
(base32 "0ly5cifj9khzbxfx0isbnhb3apak3jay04zai2dih9c75fzffa7f"))))
(base32 "REPLACE_AFTER_FINAL_ARCHIVE_GUIX_BASE32"))))
(define-public zupt
(package

View file

@ -22,9 +22,9 @@
class Zupt < Formula
desc "Post-quantum backup compression utility (ML-KEM-768 + AES-256-CTR + HMAC-SHA256)"
homepage "https://github.com/cristiancmoises/zupt"
url "https://github.com/cristiancmoises/zupt/releases/download/v5.2.2/zupt-5.2.2.tar.gz"
version "5.2.2"
sha256 "ee28e7be2b8725189b88ea13e0951c535d3516b44b47d05d5f1fce245d64c553"
url "https://github.com/cristiancmoises/zupt/releases/download/v5.2.3/zupt-5.2.3.tar.gz"
version "5.2.3"
sha256 "REPLACE_AFTER_FINAL_ARCHIVE_SHA256"
license all_of: ["AGPL-3.0-or-later", "GPL-3.0-or-later", "BSD-2-Clause", "BSD-3-Clause", "CC0-1.0"]
depends_on "python@3.12" => :test # only for test-suite tamper harness

View file

@ -9,7 +9,7 @@
# nix flake check # lint the flake
#
# To consume from another flake:
# inputs.zupt.url = "github:cristiancmoises/zupt/v5.2.2";
# inputs.zupt.url = "github:cristiancmoises/zupt/v5.2.3";
# ...packages.x86_64-linux.default = inputs.zupt.packages.x86_64-linux.zupt;
#
# `make dist` has its own reproducibility gate. This development flake has no
@ -30,7 +30,7 @@
zupt = pkgs.stdenv.mkDerivation {
pname = "zupt";
version = "5.2.2";
version = "5.2.3";
# When publishing, replace this with `fetchurl` against the
# release tarball. For local development the flake assumes it

View file

@ -1,22 +1,22 @@
# ZUPT 5.2.2 for openSUSE Build Service
# ZUPT 5.2.3 for openSUSE Build Service
This directory is the upstream, source-only OBS recipe for ZUPT. It is a
handoff for the downstream maintainer; its presence does not mean that the
package has been submitted to or accepted by openSUSE Factory.
Cristian Cezar Moisés, ZUPT's creator and current upstream maintainer,
prepared the 5.2.2 source, build, test, documentation, and upstream packaging
prepared the current source, build, test, documentation, and upstream packaging
changes in this handoff. Alessandro de Oliveira Faria (Cabelo) is credited only
as the openSUSE collaborator and downstream OBS package maintainer: he reviews
the handoff, commits it through the portal/project he maintains, and may make
the openSUSE-side adjustments he considers necessary. This role does not
attribute upstream code or the 5.2.2 upstream changes to Cabelo.
attribute upstream code or the 5.2.2/5.2.3 upstream changes to Cabelo.
## Files and source policy
| File | Purpose |
|---|---|
| `_service` | Fetch the immutable `v5.2.2` tag and create `Source0` at build time. |
| `_service` | Fetch the immutable `v5.2.3` tag and create `Source0` at build time. |
| `zupt.spec` | Build and test the CLI with optional external system integrations disabled. |
| `zupt.changes` | openSUSE-format package history. |
| `source-audit.sh` | Handoff wrapper for the repository scanner; run it from the complete handoff tree. |
@ -29,11 +29,11 @@ https://github.com/cristiancmoises/zupt.git
```
`obs_scm` stores an `.obscpio` plus `.obsinfo`. The `tar` and `recompress`
services reconstruct `zupt-5.2.2.tar.gz` inside the build environment, which
services reconstruct `zupt-5.2.3.tar.gz` inside the build environment, which
matches `Source0` in the spec.
This source policy does not prohibit separately built release-page packages.
The upstream 5.2.2 gates may publish the CLI source tarball, DEB, binary RPM,
The upstream 5.2.3 gates may publish the CLI source tarball, DEB, binary RPM,
SRPM, notice-bearing Linux tar.xz, Windows ZIP, and macOS DMG, together with a
GUI DEB, noarch RPM, GUI SRPM, and source-only portable GUI ZIP after each
format-specific test succeeds. None of those files is an OBS `Source0` input
@ -138,7 +138,7 @@ reconstructed by the build-time services. Neither `%build` nor `%check` may
access the network.
For a source RPM check outside OBS, place the service-produced
`zupt-5.2.2.tar.gz` next to the spec and use a disposable RPM build tree:
`zupt-5.2.3.tar.gz` next to the spec and use a disposable RPM build tree:
```sh
rpm_top=$(mktemp -d)
@ -153,9 +153,10 @@ install it in a disposable openSUSE environment and execute
`scripts/test-installed-zupt.sh`. Do not claim a repository or architecture
as supported until its build and installed smoke test have actually passed.
## Committed-candidate local Linux validation
## Prior 5.2.2 committed-candidate local Linux validation
Commit `ff99770` passed the full local `make release-check`. Packaging policy
The immutable 5.2.2 candidate at `ff99770` passed the full local
`make release-check`. Packaging policy
and syntax reported `PASS=49 FAIL=0 SKIP=0`; source-only scanner testing passed
39/39, including GNU thin archives and safe diagnostic cases; strict GCC,
strict Clang, GCC `-fanalyzer`, the 9/9 full tool-enabled static-analysis run,
@ -164,10 +165,12 @@ environment completed six available static checks and reported `cppcheck`
unavailable rather than passing it. Earlier off-screen GUI smoke evidence is
supporting evidence, not an exact-commit package result.
These local upstream results do not establish native Windows or macOS success,
hosted GitHub CI/release promotion, authenticated OBS acceptance, or resolution
of the automatic openSUSE `debugsource` rpmlint `no-binary` finding. Those gates
remain pending.
Post-tag CI integration failures prevented 5.2.2 promotion. These historical
local results do not establish 5.2.3, native Windows or macOS success, hosted
GitHub CI/release promotion, authenticated OBS acceptance, or resolution of the
automatic openSUSE `debugsource` rpmlint `no-binary` finding. The exact 5.2.3
candidate must repeat every applicable gate; those gates remain pending until
recorded otherwise.
## Prior openSUSE packaging validation
@ -205,10 +208,12 @@ gate.
## Handoff procedure for Alessandro/Cabelo
1. Upstream creates and verifies the annotated `v5.2.2` tag only after all
mandatory gates pass.
1. Upstream completes every applicable pre-tag source and local audit gate,
then creates and verifies the annotated `v5.2.3` tag. Exact-tag hosted,
native-platform, package, and promotion gates must pass before release or
downstream handoff; the tag itself is never moved to repair a failure.
2. With Git, `file`, bsdtar, tar, zip, unzip and SHA-256 tools installed, run
`scripts/export-opensuse-package.sh v5.2.2`. Verify the reported ZIP and
`scripts/export-opensuse-package.sh v5.2.3`. Verify the reported ZIP and
SHA-256 outside the Git index. The handoff includes both
`packaging/opensuse/source-audit.sh` and its required
`scripts/check-source-only.sh`; keep that relative layout while auditing.
@ -220,7 +225,7 @@ gate.
```
4. From the extracted handoff root, run
`packaging/opensuse/source-audit.sh --archive /path/to/zupt-5.2.2.tar.gz`.
`packaging/opensuse/source-audit.sh --archive /path/to/zupt-5.2.3.tar.gz`.
Then copy `_service`, `zupt.spec`, `zupt.changes` and `README.md`
into the flat OBS package checkout. The audit wrapper is not an OBS build
source and must not be copied without its companion `scripts/` directory.

View file

@ -4,7 +4,7 @@
<service name="obs_scm" mode="manual">
<param name="url">https://github.com/cristiancmoises/zupt.git</param>
<param name="scm">git</param>
<param name="revision">refs/tags/v5.2.2</param>
<param name="revision">refs/tags/v5.2.3</param>
<param name="versionformat">@PARENT_TAG@</param>
<param name="versionrewrite-pattern">^v(.*)$</param>
<param name="versionrewrite-replacement">\1</param>

View file

@ -1,3 +1,12 @@
-------------------------------------------------------------------
Mon Aug 31 18:15:00 UTC 2026 - Cristian Cezar Moisés <sac@securityops.co>
- Update to 5.2.3:
* Derive package checks from the upstream version header and stabilize the
GUI version output consumed by package gates.
* Replace busybox-gawk before installing the native Tumbleweed RPM tooling.
* Pin the OBS source service to the immutable v5.2.3 tag.
-------------------------------------------------------------------
Mon Aug 31 00:00:00 UTC 2026 - Cristian Cezar Moisés <sac@securityops.co>

View file

@ -18,7 +18,7 @@
#
Name: zupt
Version: 5.2.2
Version: 5.2.3
Release: 0
Summary: Backup compression with authenticated and post-quantum encryption
License: AGPL-3.0-or-later AND GPL-3.0-or-later AND BSD-2-Clause AND BSD-3-Clause AND CC0-1.0

View file

@ -27,7 +27,7 @@ Requirements
------------
1. Python 3.9 or newer.
2. PySide6 6.5 or newer, or a compatible PyQt6 package.
3. ZUPT 5.2.2, installed as `zupt` on PATH or placed beside the launcher
3. ZUPT 5.2.3, installed as `zupt` on PATH or placed beside the launcher
(`zupt.exe` on Windows). A local command must have been built
and tested independently; this bundle never downloads one.
@ -46,7 +46,7 @@ Troubleshooting
---------------
* "requires PySide6 or PyQt6": install one Qt binding through your operating
system package manager or another trusted, preconfigured Python source.
* "zupt not found": install ZUPT 5.2.2 or place its command beside
* "zupt not found": install ZUPT 5.2.3 or place its command beside
the launcher.
* Set ZUPT_DEBUG=1 to print command-discovery diagnostics to stderr.

View file

@ -20,7 +20,7 @@
# installed smoke test.
Name: zupt
Version: 5.2.2
Version: 5.2.3
Release: 1%{?dist}
Summary: Backup compression with authenticated and post-quantum encryption
@ -101,6 +101,11 @@ comments. Plain archives use non-cryptographic checksums.
%endif
%changelog
* Mon Aug 31 2026 Cristian Cezar Moisés <sac@securityops.co> - 5.2.3-1
- Correct the release-package CI version checks and portable GUI version
contract, and make the openSUSE container replace busybox-gawk before
installing the native RPM toolchain.
* Mon Aug 31 2026 Cristian Cezar Moisés <sac@securityops.co> - 5.2.2-1
- Source-only release; optional SDK/PQBOX integrations use system development
packages only and are disabled for this package.