- Shell 100%
|
All checks were successful
build / plan (push) Successful in 19s
build / finamp (fedora 44) (44, finamp) (push) Successful in 5m20s
build / zed (fedora 44) (44, zed) (push) Successful in 5m39s
build / finamp (fedora 45) (45, finamp) (push) Successful in 3m38s
build / zen-browser (fedora 44) (44, zen-browser) (push) Successful in 8m17s
build / zed (fedora 45) (45, zed) (push) Successful in 5m8s
build / zen-browser (fedora 45) (45, zen-browser) (push) Successful in 8m10s
Forgejo Actions sets GITHUB_TOKEN to its own job token. The script forwarded it to api.github.com, which answered 401, so every scheduled update run failed. Read GITHUB_API_TOKEN instead. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> |
||
|---|---|---|
| .forgejo/workflows | ||
| packages | ||
| scripts | ||
| .gitignore | ||
| README.md | ||
| RPM-GPG-KEY-x27 | ||
| x27-packages.repo | ||
X27-Linux-Packages
RPM packages for Fedora that aren't in the official repos, published to the Forgejo RPM registry on git.xlabsx27.com. Built for Fedora 44 and 45, on x86_64 and aarch64.
| Package | Upstream | Notes |
|---|---|---|
finamp |
finamp-app/finamp | Jellyfin music player. Repackages upstream's prebuilt Linux bundle. Upstream tags 1.0.1-beta become version 1.0.1~beta |
zen-browser |
zen-browser/desktop | Firefox-based browser. Run it with zen-browser. The built-in updater is removed and turned off by policy, so dnf handles updates |
zed |
zed-industries/zed | Code editor. Stable releases only, no -pre. Set "auto_update": false in Zed's settings, because its updater can't write to the system install |
All packages repackage upstream's prebuilt Linux builds. Each one installs under
/usr/lib64/<name>, with a launcher in /usr/bin.
Install
sudo dnf config-manager addrepo \
--from-repofile=https://git.xlabsx27.com/X27/X27-Linux-Packages/raw/branch/main/x27-packages.repo
sudo dnf install finamp zen-browser zed
Use x27-packages.repo, not the .repo that Forgejo generates.
Forgejo's file only trusts the registry key, which signs the repo index, so dnf rejects
the packages as unsigned. Packages are signed with RPM-GPG-KEY-x27
(fingerprint DD7B E061 9639 FAF9 14BD A11C D606 0113 B5C3 B4F7). dnf asks you to
import both keys on the first install.
dnf saves the repo as /etc/yum.repos.d/x27-packages.repo. dnf names the file after the
URL's file name, not the repo ID.
If you added Forgejo's .repo before, remove it first. It's saved as
/etc/yum.repos.d/fedora-<release>.repo (e.g. fedora-44.repo), and its repo ID is
gitea-x27-fedora-44. Check the file before deleting it, so you don't remove one of
Fedora's own repos:
grep -l gitea-x27 /etc/yum.repos.d/*.repo # should print only fedora-44.repo
sudo rm /etc/yum.repos.d/fedora-44.repo
In a BlueBuild recipe (X27-Linux), add the same .repo URL under dnf.repos.files.
How it works
packages/<name>/<name>.spec: one folder per package. Files next to the spec, like patches or configs, are copied intoSOURCES.packages/<name>/update.sh(optional): checks upstream and bumps the spec (Version,Release,%changelog) when there's a new release. For GitHub releases it's a single call toscripts/bump-github.sh <spec> <owner/repo> <asset-suffix> [--pre].scripts/build.sh <name> [arch...]: builds intoout/. With no arch given, it builds every arch in the spec'sExclusiveArch, or the host's if there's none.scripts/sign.sh: signsout/*.rpmwith the key inRPM_SIGNING_KEY, then checks them againstRPM-GPG-KEY-x27.scripts/publish.sh <group>: uploadsout/*.rpmto the registry group, e.g.fedora-44. If that exact version is already there, it's replaced.scripts/prune.sh <group>: deletes every other version of the packages inout/from the group, so the registry only keeps the newest version of each program.scripts/changed-packages.sh [base]: lists the packages that changed sincebase. If anything shared changed (scripts, workflows, the key), it lists every package.scripts/update-all.sh: runs everyupdate.sh.
Forgejo Actions:
.forgejo/workflows/update.ymlruns daily. It runsupdate-all.shand pushes any spec bumps tomain..forgejo/workflows/build.ymlruns on pushes tomain. Aplanjob picks the packages to build, then each package gets its own job per Fedora release, e.g.zed (fedora 44), in afedora:<release>container. Each job builds the package, checks it installs, signs it, publishes it, and deletes its older versions. A push rebuilds only the packages it changed; a manual run rebuilds all of them. PRs build without signing or publishing.
The workflows need these repo secrets:
| Secret | Value |
|---|---|
PACKAGES_USER |
X27 |
PACKAGES_TOKEN |
Forgejo access token for X27 with write:package and write:repository |
RPM_SIGNING_KEY |
Armored private key for RPM-GPG-KEY-x27, without a passphrase (build only) |
The runner needs the docker label.
Build locally
podman run --rm -v "$PWD:/src:Z" -w /src fedora:44 bash -c '
dnf -y install rpm-build rpmdevtools dnf-plugins-core &&
dnf -y builddep packages/finamp/finamp.spec &&
scripts/build.sh finamp'
Add a package
- Create
packages/<name>/<name>.spec. If it repackages prebuilt binaries, setdebug_package %{nil}and__strip /bin/true, asfinamp.specdoes, so other arches can be built on an x86_64 runner. - Optionally add an
update.sh. For GitHub releases, copypackages/zed/update.sh; the spec needs a%global upstream_versionline. - Build it locally, then push to
main.
Versions: a package's version is the program's version. Release always stays 1,
so never bump it. If you change a spec without changing the version, CI replaces the
build in the registry. Users who already have that version installed only get the new
build with dnf reinstall <name>.