No description
Find a file
X27 899364718f
All checks were successful
build / plan (push) Successful in 19s
build / finamp (fedora 44) (44, finamp) (push) Successful in 5m20s
build / zed (fedora 44) (44, zed) (push) Successful in 5m39s
build / finamp (fedora 45) (45, finamp) (push) Successful in 3m38s
build / zen-browser (fedora 44) (44, zen-browser) (push) Successful in 8m17s
build / zed (fedora 45) (45, zed) (push) Successful in 5m8s
build / zen-browser (fedora 45) (45, zen-browser) (push) Successful in 8m10s
bump-github: don't send Forgejo's GITHUB_TOKEN to GitHub
Forgejo Actions sets GITHUB_TOKEN to its own job token. The script
forwarded it to api.github.com, which answered 401, so every scheduled
update run failed. Read GITHUB_API_TOKEN instead.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-10-10 17:59:45 +02:00
.forgejo/workflows CI: one build job per package and Fedora release 2026-10-10 00:45:17 +02:00
packages Add Zen Browser and Zed; pin Release to 1 and prune old versions 2026-10-10 00:10:26 +02:00
scripts bump-github: don't send Forgejo's GITHUB_TOKEN to GitHub 2026-10-10 17:59:45 +02:00
.gitignore Add Fedora RPM package repo with Finamp 2026-10-09 19:20:45 +02:00
README.md CI: one build job per package and Fedora release 2026-10-10 00:45:17 +02:00
RPM-GPG-KEY-x27 Sign RPMs so dnf accepts them 2026-10-09 19:59:05 +02:00
x27-packages.repo Sign RPMs so dnf accepts them 2026-10-09 19:59:05 +02:00

X27-Linux-Packages

RPM packages for Fedora that aren't in the official repos, published to the Forgejo RPM registry on git.xlabsx27.com. Built for Fedora 44 and 45, on x86_64 and aarch64.

Package Upstream Notes
finamp finamp-app/finamp Jellyfin music player. Repackages upstream's prebuilt Linux bundle. Upstream tags 1.0.1-beta become version 1.0.1~beta
zen-browser zen-browser/desktop Firefox-based browser. Run it with zen-browser. The built-in updater is removed and turned off by policy, so dnf handles updates
zed zed-industries/zed Code editor. Stable releases only, no -pre. Set "auto_update": false in Zed's settings, because its updater can't write to the system install

All packages repackage upstream's prebuilt Linux builds. Each one installs under /usr/lib64/<name>, with a launcher in /usr/bin.

Install

sudo dnf config-manager addrepo \
  --from-repofile=https://git.xlabsx27.com/X27/X27-Linux-Packages/raw/branch/main/x27-packages.repo
sudo dnf install finamp zen-browser zed

Use x27-packages.repo, not the .repo that Forgejo generates. Forgejo's file only trusts the registry key, which signs the repo index, so dnf rejects the packages as unsigned. Packages are signed with RPM-GPG-KEY-x27 (fingerprint DD7B E061 9639 FAF9 14BD A11C D606 0113 B5C3 B4F7). dnf asks you to import both keys on the first install.

dnf saves the repo as /etc/yum.repos.d/x27-packages.repo. dnf names the file after the URL's file name, not the repo ID.

If you added Forgejo's .repo before, remove it first. It's saved as /etc/yum.repos.d/fedora-<release>.repo (e.g. fedora-44.repo), and its repo ID is gitea-x27-fedora-44. Check the file before deleting it, so you don't remove one of Fedora's own repos:

grep -l gitea-x27 /etc/yum.repos.d/*.repo   # should print only fedora-44.repo
sudo rm /etc/yum.repos.d/fedora-44.repo

In a BlueBuild recipe (X27-Linux), add the same .repo URL under dnf.repos.files.

How it works

  • packages/<name>/<name>.spec: one folder per package. Files next to the spec, like patches or configs, are copied into SOURCES.
  • packages/<name>/update.sh (optional): checks upstream and bumps the spec (Version, Release, %changelog) when there's a new release. For GitHub releases it's a single call to scripts/bump-github.sh <spec> <owner/repo> <asset-suffix> [--pre].
  • scripts/build.sh <name> [arch...]: builds into out/. With no arch given, it builds every arch in the spec's ExclusiveArch, or the host's if there's none.
  • scripts/sign.sh: signs out/*.rpm with the key in RPM_SIGNING_KEY, then checks them against RPM-GPG-KEY-x27.
  • scripts/publish.sh <group>: uploads out/*.rpm to the registry group, e.g. fedora-44. If that exact version is already there, it's replaced.
  • scripts/prune.sh <group>: deletes every other version of the packages in out/ from the group, so the registry only keeps the newest version of each program.
  • scripts/changed-packages.sh [base]: lists the packages that changed since base. If anything shared changed (scripts, workflows, the key), it lists every package.
  • scripts/update-all.sh: runs every update.sh.

Forgejo Actions:

  • .forgejo/workflows/update.yml runs daily. It runs update-all.sh and pushes any spec bumps to main.
  • .forgejo/workflows/build.yml runs on pushes to main. A plan job picks the packages to build, then each package gets its own job per Fedora release, e.g. zed (fedora 44), in a fedora:<release> container. Each job builds the package, checks it installs, signs it, publishes it, and deletes its older versions. A push rebuilds only the packages it changed; a manual run rebuilds all of them. PRs build without signing or publishing.

The workflows need these repo secrets:

Secret Value
PACKAGES_USER X27
PACKAGES_TOKEN Forgejo access token for X27 with write:package and write:repository
RPM_SIGNING_KEY Armored private key for RPM-GPG-KEY-x27, without a passphrase (build only)

The runner needs the docker label.

Build locally

podman run --rm -v "$PWD:/src:Z" -w /src fedora:44 bash -c '
  dnf -y install rpm-build rpmdevtools dnf-plugins-core &&
  dnf -y builddep packages/finamp/finamp.spec &&
  scripts/build.sh finamp'

Add a package

  1. Create packages/<name>/<name>.spec. If it repackages prebuilt binaries, set debug_package %{nil} and __strip /bin/true, as finamp.spec does, so other arches can be built on an x86_64 runner.
  2. Optionally add an update.sh. For GitHub releases, copy packages/zed/update.sh; the spec needs a %global upstream_version line.
  3. Build it locally, then push to main.

Versions: a package's version is the program's version. Release always stays 1, so never bump it. If you change a spec without changing the version, CI replaces the build in the registry. Users who already have that version installed only get the new build with dnf reinstall <name>.