Add package-windows-daemon.sh + package-linux-daemon.sh scripts

Move the Windows daemon packaging step and the Linux .deb build into
committed shell scripts under scripts/ci/. This bypasses GitHub Actions'
inline-run-block quirks (silent exit 1 under msys2 + set -e -o pipefail
with multi-line scripts) and makes the packaging logic debuggable locally.
This commit is contained in:
Krystie
2026-06-18 19:49:31 -07:00
parent f0e5dbdebc
commit 8c74f4e228
2 changed files with 213 additions and 0 deletions
+142
View File
@@ -0,0 +1,142 @@
#!/usr/bin/env bash
# scripts/ci/package-linux-daemon.sh
#
# Linux packaging step for the triangles daemon + CLI .deb.
# Called from .github/workflows/build-all.yml build-linux-daemon step.
#
# Builds a self-contained .deb with trianglesd, triangles-cli, bundled libs,
# Tor, systemd service, and CLI launchers. Designed to be reproducible and
# debuggable outside the CI environment.
#
# Usage: bash scripts/ci/package-linux-daemon.sh <version>
set -euo pipefail
VERSION="${1:-0.0.0}"
PKG="cryptographic-triangles-daemon_${VERSION}_amd64"
TOR_VERSION="${TOR_VERSION:-15.0.9}"
echo ">>> Building .deb for triangles ${VERSION}"
# Stage directories
rm -rf "${PKG}"
mkdir -p "${PKG}/DEBIAN"
mkdir -p "${PKG}/usr/lib/cryptographic-triangles/lib"
mkdir -p "${PKG}/usr/lib/cryptographic-triangles/tor"
mkdir -p "${PKG}/usr/bin"
mkdir -p "${PKG}/etc/systemd/system"
# Download + extract Tor
TOR_TARBALL="tor-expert-bundle-linux-x86_64-${TOR_VERSION}.tar.gz"
if [ ! -f "${TOR_TARBALL}" ]; then
echo ">>> Downloading Tor ${TOR_VERSION}..."
curl -sL "https://archive.torproject.org/tor-package-archive/torbrowser/${TOR_VERSION}/${TOR_TARBALL}" -o "${TOR_TARBALL}"
fi
mkdir -p tor-extract
tar -xzf "${TOR_TARBALL}" -C tor-extract
# Copy binaries
cp "build/bin/trianglesd" "${PKG}/usr/lib/cryptographic-triangles/"
cp "build/bin/triangles-cli" "${PKG}/usr/lib/cryptographic-triangles/"
# Copy Tor
cp "tor-extract/tor/tor" "${PKG}/usr/lib/cryptographic-triangles/tor/"
chmod +x "${PKG}/usr/lib/cryptographic-triangles/tor/tor"
if [ -d "tor-extract/data" ]; then
cp -r "tor-extract/data" "${PKG}/usr/lib/cryptographic-triangles/tor/data"
fi
# Bundle shared library dependencies (skip glibc/kernel — always present)
echo ">>> Bundling shared library dependencies..."
ALL_LIBS="$(mktemp)"
trap 'rm -f "${ALL_LIBS}"' EXIT
for bin in trianglesd triangles-cli; do
ldd "build/bin/${bin}" 2>/dev/null \
| grep '=> /' \
| awk '{print $3}' \
>> "${ALL_LIBS}" || true
done
if [ -s "${ALL_LIBS}" ]; then
sort -u "${ALL_LIBS}" | while IFS= read -r lib; do
if [ -z "${lib}" ]; then continue; fi
case "${lib}" in
/lib/x86_64-linux-gnu/libc.so*|/lib/x86_64-linux-gnu/libm.so*|/lib/x86_64-linux-gnu/libpthread.so*|/lib/x86_64-linux-gnu/libdl.so*|/lib/x86_64-linux-gnu/librt.so*|/lib/x86_64-linux-gnu/ld-linux*|/lib64/ld-linux*)
;; # Skip glibc core
*)
cp -L "${lib}" "${PKG}/usr/lib/cryptographic-triangles/lib/" 2>/dev/null || true
;;
esac
done
fi
echo ">>> Bundled libs:"
ls -la "${PKG}/usr/lib/cryptographic-triangles/lib/" | tail -n +2 | wc -l
# Launchers (set LD_LIBRARY_PATH for bundled libs)
cat > "${PKG}/usr/bin/trianglesd" << 'LAUNCHER'
#!/bin/bash
INSTALL_DIR=/usr/lib/cryptographic-triangles
export LD_LIBRARY_PATH="${INSTALL_DIR}/lib:${LD_LIBRARY_PATH}"
exec "${INSTALL_DIR}/trianglesd" "$@"
LAUNCHER
chmod +x "${PKG}/usr/bin/trianglesd"
cat > "${PKG}/usr/bin/triangles-cli" << 'LAUNCHER'
#!/bin/bash
INSTALL_DIR=/usr/lib/cryptographic-triangles
export LD_LIBRARY_PATH="${INSTALL_DIR}/lib:${LD_LIBRARY_PATH}"
exec "${INSTALL_DIR}/triangles-cli" "$@"
LAUNCHER
chmod +x "${PKG}/usr/bin/triangles-cli"
# systemd unit
cat > "${PKG}/etc/systemd/system/trianglesd.service" << 'SVC'
[Unit]
Description=Cryptographic Triangles Daemon
After=network-online.target
Wants=network-online.target
[Service]
Type=simple
Environment=LD_LIBRARY_PATH=/usr/lib/cryptographic-triangles/lib
ExecStart=/usr/lib/cryptographic-triangles/trianglesd
Restart=on-failure
RestartSec=10
[Install]
WantedBy=multi-user.target
SVC
# DEBIAN/control
cat > "${PKG}/DEBIAN/control" << CTRL
Package: cryptographic-triangles-daemon
Version: ${VERSION}
Architecture: amd64
Maintainer: Cryptographic Triangles <dev@cryptographic-triangles.org>
Description: Cryptographic Triangles daemon + CLI with integrated Tor
Fully self-contained headless node + JSON-RPC client with all libraries,
Tor, and systemd service. No external dependencies required.
Section: finance
Priority: optional
CTRL
# DEBIAN/postinst
cat > "${PKG}/DEBIAN/postinst" << 'POST'
#!/bin/bash
systemctl daemon-reload
echo ""
echo "Cryptographic Triangles daemon + CLI installed."
echo " Start daemon: sudo systemctl start trianglesd"
echo " On boot: sudo systemctl enable trianglesd"
echo " Use CLI: triangles-cli getinfo"
echo ""
POST
chmod +x "${PKG}/DEBIAN/postinst"
# Build the .deb
dpkg-deb --build "${PKG}"
echo ">>> Built: ${PKG}.deb"
ls -la "${PKG}.deb"
exit 0
+71
View File
@@ -0,0 +1,71 @@
#!/usr/bin/env bash
# scripts/ci/package-windows-daemon.sh
#
# Windows MSYS2 packaging step for the triangles daemon + CLI.
# Called from .github/workflows/build-all.yml build-windows-daemon step.
#
# Why a script file instead of inline YAML:
# The GitHub Actions msys2 shell wrapper has shown inconsistent handling of
# multi-line inline run: blocks under `set -e -o pipefail` (silent exits with
# code 1). A committed script file bypasses the YAML → shell translation
# quirks and gives us a known-good artifact that we can also run locally in
# MSYS2 for debugging.
#
# Usage: bash scripts/ci/package-windows-daemon.sh <dist-dir> <bin> [<bin> ...]
# Example: bash scripts/ci/package-windows-daemon.sh daemon-dist trianglesd triangles-cli
set -euo pipefail
DIST="${1:-daemon-dist}"
shift
BINS=("$@")
if [ "${#BINS[@]}" -eq 0 ]; then
echo "Usage: $0 <dist-dir> <bin> [<bin> ...]" >&2
echo " e.g. $0 daemon-dist trianglesd triangles-cli" >&2
exit 2
fi
echo ">>> Package step: bins=${BINS[*]} dist=${DIST}"
# Make the dist directory
mkdir -p "${DIST}/tor"
# Copy each binary to dist/
for bin in "${BINS[@]}"; do
src="build/bin/${bin}.exe"
if [ ! -f "${src}" ]; then
echo "ERROR: ${src} not found" >&2
exit 3
fi
cp "${src}" "${DIST}/"
echo " copied ${src} -> ${DIST}/"
done
# Copy linked DLLs (union of all binaries' dependencies, deduped)
echo ">>> Collecting DLLs from ldd output..."
ALL_DLLS="$(mktemp)"
trap 'rm -f "${ALL_DLLS}"' EXIT
for bin in "${BINS[@]}"; do
src="build/bin/${bin}.exe"
ldd "${src}" 2>/dev/null \
| grep '/mingw64' \
| awk '{print $3}' \
>> "${ALL_DLLS}" || true
done
if [ ! -s "${ALL_DLLS}" ]; then
echo "WARNING: no /mingw64 DLLs found in ldd output for ${BINS[*]}" >&2
else
echo ">>> Copying $(sort -u "${ALL_DLLS}" | wc -l) unique DLLs..."
sort -u "${ALL_DLLS}" | while IFS= read -r dll; do
if [ -n "${dll}" ] && [ -f "${dll}" ]; then
cp "${dll}" "${DIST}/" || echo "WARN: failed to copy ${dll}" >&2
fi
done
fi
echo ">>> Package complete: $(ls -1 "${DIST}" | wc -l) files in ${DIST}/"
ls -la "${DIST}/"
exit 0