docs: complete zupt → vaptvupt rename; README v4.0.0 refresh
- README: add 'What's new in 4.0.0' section, extend release history v2.2.4 → v4.0.0, fix stale section titles (benchmark/security/feature tables), point fast-install at short.securityops.co/vaptvupt, fix related-project links (vaptvupt-codec, libvuptsdk, real repo names) - install.sh: clone the renamed repo, vaptvupt success message - Rename remaining zupt → vaptvupt across INSTALL.md, DISTRIBUTION.md, SECURITY.md, THREAT_MODEL.md, ROADMAP.md, THIRD-PARTY-NOTICES.md, gui/ + sdk/ + packaging READMEs, doc/vaptvupt.1, spec comments/URLs - New doc/vaptvupt-gui.1 (GUI 1.3.0, VAPTVUPT_BIN/ZUPT_BIN env vars); doc/zupt-gui.1 kept as hardlinked compat copy - Deliberately unchanged: .zupt extension, ZUPT header magic, ZUPT-* crypto domain-separation constants, zupt_*/ZUPT_* code identifiers, libzuptsdk artifact names, legacy symlink notes, CHANGELOG/AUDIT historical entries, Provides/Obsoletes upgrade path - tests/test_packaging_syntax.sh: THREAT_MODEL section titles updated
This commit is contained in:
parent
544a2cd647
commit
136a96ed20
18 changed files with 471 additions and 306 deletions
|
|
@ -1,4 +1,4 @@
|
|||
# Distributing Zupt
|
||||
# Distributing VaptVupt
|
||||
|
||||
This document describes the upstream packaging recipes shipped under
|
||||
`packaging/` and the path from "local source tree" to "package
|
||||
|
|
@ -10,13 +10,13 @@ work outside this repository.
|
|||
|
||||
## Producing a reproducible source tarball
|
||||
|
||||
Every packaging recipe expects an upstream tarball `zupt-VERSION.tar.gz`
|
||||
Every packaging recipe expects an upstream tarball `vaptvupt-VERSION.tar.gz`
|
||||
produced by the project's `make dist` target. The tarball is
|
||||
**byte-reproducible**:
|
||||
|
||||
```sh
|
||||
make dist
|
||||
# → /tmp/zupt-2.4.4.tar.gz
|
||||
# → /tmp/vaptvupt-2.4.4.tar.gz
|
||||
# → sha256: 407d20ef03e5bf857195b99e04843ef3b07357416a4115add1e8aaa2007a769f
|
||||
# → bytes: 813113
|
||||
```
|
||||
|
|
@ -48,18 +48,18 @@ SOURCE_DATE_EPOCH=1727740800 make dist # 2024-10-01 UTC
|
|||
|-------------------|---------------------------------|----------------|
|
||||
| Arch Linux | `packaging/aur/PKGBUILD` | AUR PKGBUILD |
|
||||
| Debian / Ubuntu | `packaging/debian/` | Source package (`3.0 (quilt)`) |
|
||||
| Fedora / RHEL | `packaging/rpm/zupt.spec` | RPM .spec |
|
||||
| macOS | `packaging/homebrew/zupt.rb` | Homebrew formula |
|
||||
| Fedora / RHEL | `packaging/rpm/vaptvupt.spec` | RPM .spec |
|
||||
| macOS | `packaging/homebrew/vaptvupt.rb` | Homebrew formula |
|
||||
| NixOS / Nix flake | `packaging/nix/flake.nix` | Nix flake |
|
||||
|
||||
All recipes:
|
||||
|
||||
- Install the binary to `$PREFIX/bin/zupt` (default `/usr/bin/zupt`)
|
||||
- Install the vendored `libzuptsdk.so*` triple to `$PREFIX/lib/zupt/`
|
||||
- Install the binary to `$PREFIX/bin/vaptvupt` (default `/usr/bin/vaptvupt`)
|
||||
- Install the vendored `libzuptsdk.so*` triple to `$PREFIX/lib/vaptvupt/`
|
||||
(the binary uses relative `rpath` so users don't need `LD_LIBRARY_PATH`)
|
||||
- Install manpage to `$PREFIX/share/man/man1/zupt.1.gz`
|
||||
- Install manpage to `$PREFIX/share/man/man1/vaptvupt.1.gz`
|
||||
- Install docs (README, SECURITY, CHANGELOG, AUDIT) to
|
||||
`$PREFIX/share/doc/zupt/`
|
||||
`$PREFIX/share/doc/vaptvupt/`
|
||||
- Run the full upstream regression suite (`make test`) during build
|
||||
when the distro's package guidelines allow check-phase execution
|
||||
|
||||
|
|
@ -70,13 +70,13 @@ Maintainer flow:
|
|||
```sh
|
||||
# 1. Produce the upstream tarball
|
||||
make dist
|
||||
# → /tmp/zupt-2.4.4.tar.gz
|
||||
# → /tmp/vaptvupt-2.4.4.tar.gz
|
||||
|
||||
# 2. Upload to a stable URL (e.g. git.securityops.co releases)
|
||||
|
||||
# 3. Update packaging/aur/PKGBUILD:
|
||||
# - Set pkgver=2.4.4
|
||||
# - Set sha256sums=("$(sha256sum /tmp/zupt-2.4.4.tar.gz | awk '{print $1}')")
|
||||
# - Set sha256sums=("$(sha256sum /tmp/vaptvupt-2.4.4.tar.gz | awk '{print $1}')")
|
||||
|
||||
# 4. Generate .SRCINFO
|
||||
cd packaging/aur && makepkg --printsrcinfo > .SRCINFO
|
||||
|
|
@ -85,15 +85,15 @@ cd packaging/aur && makepkg --printsrcinfo > .SRCINFO
|
|||
makepkg -s
|
||||
|
||||
# 6. Push to AUR
|
||||
git clone ssh://aur@aur.archlinux.org/zupt.git aur-zupt
|
||||
cp packaging/aur/PKGBUILD packaging/aur/.SRCINFO aur-zupt/
|
||||
cd aur-zupt && git add -A && git commit -m "v2.4.4" && git push
|
||||
git clone ssh://aur@aur.archlinux.org/vaptvupt.git aur-vaptvupt
|
||||
cp packaging/aur/PKGBUILD packaging/aur/.SRCINFO aur-vaptvupt/
|
||||
cd aur-vaptvupt && git add -A && git commit -m "v2.4.4" && git push
|
||||
```
|
||||
|
||||
User install:
|
||||
|
||||
```sh
|
||||
yay -S zupt # or paru, pikaur, etc.
|
||||
yay -S vaptvupt # or paru, pikaur, etc.
|
||||
```
|
||||
|
||||
## Shell completions (v2.4.7+)
|
||||
|
|
@ -103,9 +103,9 @@ files alongside the binary and manpage:
|
|||
|
||||
| Shell | Path |
|
||||
|---|---|
|
||||
| Bash | `$PREFIX/share/bash-completion/completions/zupt` |
|
||||
| zsh | `$PREFIX/share/zsh/site-functions/_zupt` |
|
||||
| fish | `$PREFIX/share/fish/vendor_completions.d/zupt.fish` |
|
||||
| Bash | `$PREFIX/share/bash-completion/completions/vaptvupt` |
|
||||
| zsh | `$PREFIX/share/zsh/site-functions/_vaptvupt` |
|
||||
| fish | `$PREFIX/share/fish/vendor_completions.d/vaptvupt.fish` |
|
||||
|
||||
The source files live under `completions/` in the project tree.
|
||||
Distros that prefer a different install location should override
|
||||
|
|
@ -116,13 +116,13 @@ For per-user installation without root:
|
|||
|
||||
```sh
|
||||
# Bash
|
||||
cp completions/zupt.bash ~/.local/share/bash-completion/completions/zupt
|
||||
cp completions/vaptvupt.bash ~/.local/share/bash-completion/completions/vaptvupt
|
||||
|
||||
# zsh (somewhere in $fpath; add the directory to ~/.zshrc if needed)
|
||||
cp completions/_zupt ~/.zsh/completion/_zupt
|
||||
cp completions/_vaptvupt ~/.zsh/completion/_vaptvupt
|
||||
|
||||
# fish
|
||||
cp completions/zupt.fish ~/.config/fish/completions/zupt.fish
|
||||
cp completions/vaptvupt.fish ~/.config/fish/completions/vaptvupt.fish
|
||||
```
|
||||
|
||||
Completions cover every CLI flag the binary actually parses
|
||||
|
|
@ -139,18 +139,18 @@ Maintainer flow:
|
|||
# 1. Produce the upstream tarball with the standard Debian
|
||||
# orig.tar.gz naming convention:
|
||||
make dist
|
||||
cp /tmp/zupt-2.4.4.tar.gz /tmp/zupt_2.4.4.orig.tar.gz
|
||||
cp /tmp/vaptvupt-2.4.4.tar.gz /tmp/vaptvupt_2.4.4.orig.tar.gz
|
||||
|
||||
# 2. Unpack and overlay the debian/ tree:
|
||||
cd /tmp && tar xzf zupt_2.4.4.orig.tar.gz && cd zupt-2.4.4
|
||||
cp -a /path/to/zupt/packaging/debian ./debian
|
||||
cd /tmp && tar xzf vaptvupt_2.4.4.orig.tar.gz && cd vaptvupt-2.4.4
|
||||
cp -a /path/to/vaptvupt/packaging/debian ./debian
|
||||
|
||||
# 3. Build the source package:
|
||||
dpkg-buildpackage -S -us -uc # source-only
|
||||
dpkg-buildpackage -b -us -uc # binary
|
||||
|
||||
# 4. Lint:
|
||||
lintian zupt_2.4.4-1_*.deb
|
||||
lintian vaptvupt_2.4.4-1_*.deb
|
||||
|
||||
# 5. Submit via the standard Debian mentors process:
|
||||
# https://mentors.debian.net/intro-maintainers/
|
||||
|
|
@ -159,7 +159,7 @@ lintian zupt_2.4.4-1_*.deb
|
|||
User install (after the package lands in Debian unstable / Ubuntu):
|
||||
|
||||
```sh
|
||||
sudo apt install zupt
|
||||
sudo apt install vaptvupt
|
||||
```
|
||||
|
||||
## Fedora / RHEL / CentOS
|
||||
|
|
@ -167,16 +167,16 @@ sudo apt install zupt
|
|||
```sh
|
||||
# 1. Produce the tarball
|
||||
make dist
|
||||
cp /tmp/zupt-2.4.4.tar.gz ~/rpmbuild/SOURCES/
|
||||
cp /tmp/vaptvupt-2.4.4.tar.gz ~/rpmbuild/SOURCES/
|
||||
|
||||
# 2. Drop the .spec into the SPECS directory:
|
||||
cp packaging/rpm/zupt.spec ~/rpmbuild/SPECS/
|
||||
cp packaging/rpm/vaptvupt.spec ~/rpmbuild/SPECS/
|
||||
|
||||
# 3. Build source + binary RPMs:
|
||||
cd ~/rpmbuild && rpmbuild -ba SPECS/zupt.spec
|
||||
cd ~/rpmbuild && rpmbuild -ba SPECS/vaptvupt.spec
|
||||
|
||||
# 4. Lint:
|
||||
rpmlint RPMS/x86_64/zupt-2.4.4-1.fc*.rpm
|
||||
rpmlint RPMS/x86_64/vaptvupt-2.4.4-1.fc*.rpm
|
||||
|
||||
# 5. Submit via the Fedora new-package review process:
|
||||
# https://docs.fedoraproject.org/en-US/package-maintainers/Package_Review_Process/
|
||||
|
|
@ -186,8 +186,8 @@ rpmlint RPMS/x86_64/zupt-2.4.4-1.fc*.rpm
|
|||
User install (after the package lands in Fedora / EPEL):
|
||||
|
||||
```sh
|
||||
sudo dnf install zupt # Fedora
|
||||
sudo dnf install epel-release zupt # RHEL/CentOS via EPEL
|
||||
sudo dnf install vaptvupt # Fedora
|
||||
sudo dnf install epel-release vaptvupt # RHEL/CentOS via EPEL
|
||||
```
|
||||
|
||||
## macOS (Homebrew)
|
||||
|
|
@ -195,14 +195,14 @@ sudo dnf install epel-release zupt # RHEL/CentOS via EPEL
|
|||
```sh
|
||||
# 1. Produce the tarball and upload to a stable release URL.
|
||||
|
||||
# 2. Update packaging/homebrew/zupt.rb:
|
||||
# 2. Update packaging/homebrew/vaptvupt.rb:
|
||||
# - Set url to the release URL
|
||||
# - Set sha256 to the upstream tarball sha256
|
||||
|
||||
# 3. Test locally:
|
||||
brew install --build-from-source ./packaging/homebrew/zupt.rb
|
||||
brew test zupt
|
||||
brew audit --strict --online zupt
|
||||
brew install --build-from-source ./packaging/homebrew/vaptvupt.rb
|
||||
brew test vaptvupt
|
||||
brew audit --strict --online vaptvupt
|
||||
|
||||
# 4. Submit to homebrew-core (preferred, requires popularity threshold):
|
||||
# https://docs.brew.sh/Adding-Software-to-Homebrew
|
||||
|
|
@ -214,25 +214,25 @@ brew audit --strict --online zupt
|
|||
User install (after submission lands):
|
||||
|
||||
```sh
|
||||
brew install zupt
|
||||
brew install vaptvupt
|
||||
# OR from a custom tap:
|
||||
brew install cristiancmoises/tap/zupt
|
||||
brew install cristiancmoises/tap/vaptvupt
|
||||
```
|
||||
|
||||
## NixOS / Nix flake
|
||||
|
||||
```sh
|
||||
# 1. Build directly from the flake (no central submission needed):
|
||||
nix build github:cristiancmoises/zupt#zupt
|
||||
nix run github:cristiancmoises/zupt#zupt -- version
|
||||
nix build github:cristiancmoises/vaptvupt#vaptvupt
|
||||
nix run github:cristiancmoises/vaptvupt#vaptvupt -- version
|
||||
|
||||
# 2. To consume from another flake:
|
||||
# inputs.zupt.url = "github:cristiancmoises/zupt?ref=v2.4.4";
|
||||
# inputs.zupt.url = "github:cristiancmoises/vaptvupt?ref=v2.4.4";
|
||||
# packages.x86_64-linux.default = inputs.zupt.packages.x86_64-linux.zupt;
|
||||
|
||||
# 3. To submit to nixpkgs (https://github.com/NixOS/nixpkgs):
|
||||
# - Adapt packaging/nix/flake.nix's `zupt` derivation into a
|
||||
# pkgs/by-name/zu/zupt/package.nix using fetchurl and a hash.
|
||||
# - Adapt packaging/nix/flake.nix's `vaptvupt` derivation into a
|
||||
# pkgs/by-name/zu/vaptvupt/package.nix using fetchurl and a hash.
|
||||
# - Follow the nixpkgs contribution guide:
|
||||
# https://github.com/NixOS/nixpkgs/blob/master/CONTRIBUTING.md
|
||||
```
|
||||
|
|
@ -245,10 +245,10 @@ Before pushing any recipe to a distro repository:
|
|||
`tests/test_dist_reproducible.sh` on every `make test`)
|
||||
- [ ] The tarball is uploaded to a stable, immutable URL
|
||||
- [ ] The recipe's checksum field is updated to match
|
||||
`sha256sum /tmp/zupt-VERSION.tar.gz`
|
||||
`sha256sum /tmp/vaptvupt-VERSION.tar.gz`
|
||||
- [ ] The recipe builds and tests pass in a clean chroot/container
|
||||
- [ ] The CHANGELOG mentions distro-relevant changes since the last release
|
||||
- [ ] The license metadata is correct (AGPL-3.0-or-later for Zupt core;
|
||||
- [ ] The license metadata is correct (AGPL-3.0-or-later for VaptVupt core;
|
||||
GPL-3.0-or-later for the vendored VaptVupt codec)
|
||||
|
||||
## Security posture for downstream
|
||||
|
|
|
|||
Loading…
Reference in a new issue