-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathJustfile
More file actions
215 lines (186 loc) · 9.61 KB
/
Copy pathJustfile
File metadata and controls
215 lines (186 loc) · 9.61 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
set shell := ["bash", "-eu", "-o", "pipefail", "-c"]
# Format every crate.
fmt:
cargo fmt --all
# Check formatting without mutating the worktree. The `ci` recipe uses
# this so a local pre-push doesn't silently rewrite files.
fmt-check:
cargo fmt --all -- --check
# Cargo build (debug) for the whole workspace.
build:
cargo build --workspace
# Cargo build (release) for the whole workspace.
build-release:
cargo build --workspace --release
# Run all tests.
#
# We set LINSYNC_SANDBOX_SKIP=1 (matching the standard CI test job) so that
# `just ci` and `just test` are reliable and non-flaky across environments:
# containers, GitHub runners, and dev setups (including this one) where
# Landlock ABI >=1 may be reported by the probe but actual filesystem
# read restriction does not take effect (e.g. due to user namespaces,
# container LSM policy, or tmpfs/overlay specifics). Real enforcement is
# covered by `just test-sandbox` — run it on kernels/envs where Landlock
# bites before touching linsync-sandbox or the plugin/archive spawn paths.
#
# See crates/linsync-sandbox/tests/sandbox_integration.rs and the comment
# in .github/workflows/ci.yml for the full contract.
test:
LINSYNC_SANDBOX_SKIP=1 cargo test --workspace
# Run the sandbox enforcement tests WITHOUT the skip — asserts real EACCES
# denial from Landlock/seccomp. Only meaningful on hosts where enforcement
# actually takes effect (see the `test` recipe comment); flaky-by-design
# elsewhere, which is why it is not part of `just ci`.
test-sandbox:
env -u LINSYNC_SANDBOX_SKIP cargo test -p linsync-sandbox --test sandbox_integration
# Best-effort sandbox enforcement test used by CI. It runs the same integration
# test as `test-sandbox` but lets the file self-skip when the backend is absent
# or a no-op, so it does not flake on shared runners.
test-sandbox-ci:
cargo test -p linsync-sandbox --test sandbox_integration
# Type-check without producing binaries.
check:
cargo check --workspace
# Strict lint pass.
lint:
cargo clippy --workspace --all-targets -- -D warnings
# License/advisory check (requires `cargo install cargo-deny`).
deny:
cargo deny --all-features check
# Advisory check (requires `cargo install cargo-audit`).
audit:
cargo audit
# Generate an HTML + terminal coverage report (requires `cargo install
# cargo-llvm-cov` and the `llvm-tools-preview` rustup component). Opens
# target/llvm-cov/html/index.html. Sandbox tests are skipped (same
# rationale as `just test`) so the report is reproducible off-host.
coverage:
LINSYNC_SANDBOX_SKIP=1 cargo llvm-cov --workspace --html --output-dir target/llvm-cov
@echo "coverage report at target/llvm-cov/html/index.html"
# Regenerate (or print) the authoritative third-party crate/license table for
# the shipped feature set (cxxqt + cxxqt-app + web-engine on the Linux target,
# build deps included, dev deps excluded). The single generator
# (scripts/generate-credits.py) also maintains docs/third-party-crates.json
# (the canonical machine-readable list) and refreshes the generated blocks
# inside the three credit surfaces.
#
# `just credits` prints the table (for review or copy).
# `just credits-update` writes the JSON and patches the surfaces so that
# future dep changes only require running the update target (drift for the
# data parts becomes impossible by construction).
credits:
python3 scripts/generate-credits.py table
# Update the committed JSON and the generated sections of the three surfaces
# (md table, CreditsPage crates array, LicensesPage counts+table). Run this
# after any Cargo.lock change that affects the shipped graph, then commit.
credits-update:
python3 scripts/generate-credits.py update
# Build the release binaries and bundle a self-contained AppImage via
# linuxdeploy + linuxdeploy-plugin-qt. Falls back to staging the AppDir when
# linuxdeploy isn't on PATH.
#
# Strips by default (smaller artifact). On hosts with very new
# glibc/toolchain (relr.dyn sections) where linuxdeploy's bundled strip
# fails, build-appdir.sh automatically retries with NO_STRIP=1, so release
# containers keep producing stripped artifacts while dev hosts still get a
# working (slightly larger) AppImage. Set NO_STRIP=1 to skip the first
# attempt entirely.
package:
bash packaging/appimage/build-appdir.sh
# Build the Arch / CachyOS pacman package via makepkg (pacman-based hosts only).
package-arch:
cd packaging/arch && makepkg -sf
# Build the Debian / Ubuntu .deb package via dpkg-buildpackage (Debian-based hosts only).
package-deb:
dpkg-buildpackage -us -uc -b
# Links against the host's Qt. On non-Fedora hosts the resulting RPM
# will fail to install on Fedora because Qt's AOT QML output binds to
# private symbols that are pinned to the Qt minor version - use
# `package-rpm-fedora44` from any host to get a Fedora-installable RPM.
# Build the Fedora / RHEL .rpm via on-host rpmbuild (RPM-based hosts only).
package-rpm:
bash -c 'set -euo pipefail; \
cd packaging/rpm; \
version=$(awk -F'"'"'"'"'"' '"'"'/^\[workspace\.package\]/ {s=1; next} s && /^\[/ {exit} s && $1 ~ /^version[[:space:]]*=/ {print $2; exit}'"'"' ../../Cargo.toml); \
( cd ../.. && git archive --format=tar.gz --prefix=linsync-${version}/ --output=packaging/rpm/linsync-${version}.tar.gz HEAD ); \
rpmbuild --define "_topdir $(pwd)/_rpmbuild" --define "_sourcedir $(pwd)" -bb linsync.spec'
# The container path matters because cxx-qt-build's QML AOT compiler
# links against Qt's private API, which is pinned to the exact Qt
# minor version. An RPM built on Arch / CachyOS (Qt 6.11) fails to
# install on Fedora 44 (Qt 6.9). See packaging/rpm/Containerfile.fedora44.
# Build the Fedora 44 .rpm inside a podman container (Qt 6.9 matched).
package-rpm-fedora44:
bash packaging/rpm/build-in-container.sh
# Run the CLI with arbitrary arguments. Example: `just run-cli compare a.txt b.txt`.
run-cli *args:
cargo run -p linsync-cli -- {{args}}
# Launch the GUI (Qt 6 / Kirigami shell with an eight-section layout:
# Compare, Sessions, Filters, Plugins, Settings, About in the sidebar;
# Credits and Licenses reachable from About). The default build spawns
# an external `qml6`/`qml` runner; pass `--features cxxqt-app` for the
# in-process cxx-qt host the packaged builds use.
run-gui:
cargo run -p linsync
# Vendor every cargo dependency into target/flatpak/vendor. Required
# before `just flatpak` so the sandboxed build can compile with no
# network access. Re-runs are cheap (cargo only re-downloads crates
# that aren't already in vendor/). Note: this does NOT touch
# .cargo/config.toml — `just flatpak` writes / removes it around the
# build so host cargo builds aren't redirected at the vendor tree.
flatpak-vendor:
mkdir -p target/flatpak
cargo vendor --locked target/flatpak/vendor > target/flatpak/vendor-config.toml
@echo "wrote target/flatpak/vendor + target/flatpak/vendor-config.toml"
# Build the Flatpak into a local OSTree repo at target/flatpak/repo and
# the install tree at target/flatpak/build. Requires:
# flatpak-builder
# org.kde.Platform//6.10
# org.kde.Sdk//6.10
# org.freedesktop.Sdk.Extension.rust-stable//25.08
flatpak: flatpak-vendor
# Stage the vendor config at .cargo/config.toml just long enough
# for flatpak-builder to copy the source tree into the sandbox,
# then restore the dev config (mold+sccache wiring) so subsequent
# host cargo builds use the registry cache + accelerated linker
# again. Without the backup/restore the dev config would be
# silently deleted on every flatpak build. The trap also fires
# on failure to keep the worktree clean.
mkdir -p .cargo
if [ -f .cargo/config.toml ]; then mv .cargo/config.toml .cargo/config.toml.bak; fi
cp target/flatpak/vendor-config.toml .cargo/config.toml
trap 'if [ -f .cargo/config.toml.bak ]; then mv .cargo/config.toml.bak .cargo/config.toml; else rm -f .cargo/config.toml; fi' EXIT INT TERM; \
flatpak-builder --user --force-clean --disable-rofiles-fuse \
--repo=target/flatpak/repo \
target/flatpak/build \
packaging/flatpak/com.visorcraft.LinSync.yml
@echo "built target/flatpak/repo"
# Bundle the Flatpak repo into a single redistributable .flatpak file
# at target/release/linsync.flatpak.
flatpak-bundle: flatpak
mkdir -p target/release
flatpak build-bundle target/flatpak/repo \
target/release/linsync.flatpak \
com.visorcraft.LinSync master
@echo "wrote target/release/linsync.flatpak"
# Convenience target for local CI. Uses `fmt-check` (not `fmt`) so
# the worktree isn't silently reformatted as a side effect.
ci: fmt-check lint test
@echo "ci preflight passed"
# Validate release metadata and packaging stubs.
release-smoke:
bash scripts/release-smoke.sh
# Extract translatable qsTr() strings from the QML into every i18n catalog
# (the source-language baseline is apps/linsync-gui/i18n/linsync_en.ts).
# Requires Qt's lupdate from qt6-tools. Translators copy the baseline to
# linsync_<lang>.ts and translate; rerunning refreshes existing catalogs.
l10n-update:
lupdate=$(command -v lupdate6 || command -v lupdate-qt6 || command -v lupdate || echo /usr/lib/qt6/bin/lupdate); \
for ts in apps/linsync-gui/i18n/*.ts; do "$lupdate" apps/linsync-gui/qml -ts "$ts"; done
# Compile every i18n/*.ts catalog to a runtime .qm (one per locale).
# Requires Qt's lrelease from qt6-tools.
l10n-release:
lrelease=$(command -v lrelease6 || command -v lrelease-qt6 || command -v lrelease || echo /usr/lib/qt6/bin/lrelease); \
for ts in apps/linsync-gui/i18n/*.ts; do "$lrelease" "$ts"; done
# Generate a per-locale translation completeness report from i18n/*.ts.
l10n-report:
python3 scripts/l10n-report.py