Skip to content

Fix Flatpak manifest drift and automate the Flathub update PR - #511

Merged
kwart merged 4 commits into
masterfrom
fix-flatpak-manifest-drift
Sep 23, 2026
Merged

kwart merged 4 commits into
masterfrom
fix-flatpak-manifest-drift

Conversation

@kwart

@kwart kwart commented Sep 22, 2026 •

Copy link
Copy Markdown
Member

Two related Flatpak changes.

Align the local manifests with the Flathub one

distribution/linux/flatpak/*.yaml had drifted from the manifest Flathub actually builds. Both are used: the release workflow builds the published .flatpak bundle from the release manifest, and build-local.sh builds from both.

Effects of the drift:

  • the bundle on the GitHub release had no pcsc-lite/opensc, no --socket=pcsc and no --device=all, so smartcard and YubiKey signing did not work there, unlike on Flathub
  • build-local.sh --release always failed: it looked for distribution/target/jsignpdf-<v>.zip, but the build only produces -full.zip and -minimal.zip
  • the release workflow patched the manifest with sed "s|sha256: [a-f0-9]\{64\}|...|", which rewrites every matching line — adding modules with their own hashes would have silently corrupted them

Changes:

  • both manifests aligned with Flathub: pcsc-lite + opensc modules, --socket=pcsc, --device=all, --share=ipc, explicit command: jsignpdf, cleanup rules, openjdk license; --socket=pulseaudio dropped
  • icon installed into hicolor/512x512 — the PNG is 512x512 and was being installed as 256x256
  • build-options: libdir: /app/lib on pcsc-lite: flatpak-builder 1.4.2 does not pass --libdir, meson then installs to lib64, libpcsclite.pc falls off PKG_CONFIG_PATH and opensc configure fails with winscard.h is required for pcsc. Newer builders already pass the same flag, so this is a no-op there — -Dlibdir in config-opts is not, it makes meson abort with Got argument libdir as both -Dlibdir and --libdir
  • the stale JSignPdf 2.3.0 SourceForge placeholder URL is replaced by a staged path: jsignpdf-full.zip; the workflow and build-local.sh copy the zip into place, so no url/sha256 rewriting is needed

Verified with build-local.sh --release: the resulting bundle has shared=network;ipc;, sockets=x11;pcsc;, devices=all;, ships /app/lib/opensc-pkcs11.so and /app/lib/libpcsclite.so.1, and the icon at 512x512.

The currently published Flathub build was checked and is unaffected — its files are already in /app/lib, so the libdir issue is builder-version specific. flathub/io.github.intoolswetrust.JSignPdf#3 carries the same pin upstream.

Automate the Flathub update PR

3.2.0 shipped on 2026-09-14 but never reached Flathub, because updating it is a manual PR nobody opened and the manifest has no x-checker-data for the Flathub bot.

New flathub-pr job, final releases only:

  • runs after publish-release, so a failure never blocks the release; re-run just this job to retry
  • takes maven-dependencies.json from the release tag rather than master, so the offline Maven repo matches the poms in the pinned tarball
  • idempotent: force-pushes the branch and reuses an already open PR, and exits early once Flathub is at the version

Uses the FLATHUB_TOKEN secret, which already exists and has been verified: a classic PAT with public_repo, no expiry, owned by kwart, reporting push: true on flathub/io.github.intoolswetrust.JSignPdf. A throwaway ref was pushed to that repo and deleted again to confirm write access end to end. GITHUB_TOKEN cannot push to another org, and do-release.yml passes secrets: inherit, so the secret reaches this workflow through the workflow_call. The job still fails with an explicit error if the secret is ever removed.

The patch step was dry-run against a clone of the Flathub repo: it reproduces flathub/io.github.intoolswetrust.JSignPdf#2 (the manual 3.2.0 update) byte for byte.

Review fixes (3ca75ba)

  • flathub-pr only short-circuits on an open PR; gh pr view <branch> also resolves closed and merged PRs, so a re-run after a closed PR pushed the branch and exited without opening one
  • git add -A + git diff --cached --quiet: a manifest that grows a new file was left untracked and the tree looked clean, reporting "already at version"
  • the url/sha256 assertion moved into the rewrite itself, so a reindented Flathub manifest fails loudly instead of matching no grep; dry-run covers the happy path, a 4-space reindent, a missing sha256, and a second archive source
  • timeout-minutes, permissions: contents: read, and ${{ }} in run: routed through env like the rest of the workflow
  • flatpak added to flathub-pr's needs: pcsc-lite/opensc/openjdk are shared with the Flathub manifest, so a failure there predicts a failing Flathub build
  • build-local.sh guards the two sed rewrites that can silently no-op (desktop, metainfo); the previous grep checked a string sed never touches
  • the TSA comment now annotates --share=network rather than --env=PATH, making finish-args byte-identical to the Flathub manifest
  • dropped the stale claim that aarch64 falls through to Swing — the full ZIP ships javafx-*-linux-aarch64.jar and Bootstrap.detectFxClassifier returns linux-aarch64, so both Flatpak arches get the JavaFX UI and its XDG portal file chooser
  • the release tag is derived once in setup instead of being recomputed in four jobs

- add pcsc-lite and opensc modules, --socket=pcsc, --device=all and
  --share=ipc, so the bundled Flatpak supports smartcards and YubiKeys
- add explicit `command: jsignpdf`, cleanup rules and the openjdk license
- drop --socket=pulseaudio
- install the 512x512 icon into hicolor/512x512 instead of 256x256
- pin -Dlibdir=lib for pcsc-lite; meson otherwise installs to lib64 and
  opensc configure fails with "winscard.h is required for pcsc"
- replace the stale JSignPdf 2.3.0 SourceForge placeholder URL with a
  staged `path: jsignpdf-full.zip`; the release workflow and build-local.sh
  now copy the zip into place instead of rewriting url and sha256 with sed,
  which would have clobbered the new module hashes
- build-local.sh --release looked for jsignpdf-<v>.zip, which the build
  never produces; use jsignpdf-<v>-full.zip
- new flathub-pr job, final releases only, runs after publish-release so a
  failure never blocks the release
- takes maven-dependencies.json from the release tag, not master, so the
  offline Maven repo matches the poms in the pinned tarball
- idempotent: re-running force-pushes the branch and reuses the open PR,
  and exits early once Flathub is already at the version
- needs a FLATHUB_TOKEN secret; GITHUB_TOKEN cannot push to another org
@kwart kwart changed the title Align local Flatpak manifests with the Flathub one Fix Flatpak manifest drift and automate the Flathub update PR Sep 22, 2026
-Dlibdir collides with the --libdir that newer flatpak-builder passes:
"Got argument libdir as both -Dlibdir and --libdir. Pick one."
flathub-pr job:
- only an OPEN PR short-circuits PR creation; `gh pr view <branch>` also
  resolves closed and merged PRs, so a re-run after a closed PR pushed the
  branch and exited without ever opening one
- `git add -A` + `git diff --cached --quiet`: a manifest that grows a new
  file left it untracked, and the tree looked clean ("already at version")
- the url/sha256 assertion moved into the rewrite itself, so a reindented
  Flathub manifest fails loudly instead of matching no grep
- timeout-minutes, `permissions: contents: read`, and `${{ }}` in `run:`
  routed through env like the rest of the workflow
- `flatpak` added to `needs`: pcsc-lite/opensc/openjdk are shared with the
  Flathub manifest, so a failure there predicts a failing Flathub build

build-local.sh: guard the two sed rewrites that can silently no-op (desktop,
metainfo) instead of grepping for the zip path, which sed never touches.

Manifests: move the TSA comment onto the --share=network line it describes,
making finish-args byte-identical to the Flathub manifest.

Also drop the stale claim that aarch64 falls through to Swing -- the full ZIP
ships javafx-*-linux-aarch64.jar and Bootstrap.detectFxClassifier picks it up,
so both Flatpak arches get the JavaFX UI and its XDG portal file chooser.

Release tag is now derived once in `setup` and consumed by the four jobs that
checked it out, instead of being recomputed in each.
@kwart
kwart merged commit b15d4a7 into master Sep 23, 2026
2 checks passed
@kwart
kwart deleted the fix-flatpak-manifest-drift branch September 23, 2026 21:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant