Fix Flatpak manifest drift and automate the Flathub update PR - #511
Merged
Merged
Conversation
- add pcsc-lite and opensc modules, --socket=pcsc, --device=all and --share=ipc, so the bundled Flatpak supports smartcards and YubiKeys - add explicit `command: jsignpdf`, cleanup rules and the openjdk license - drop --socket=pulseaudio - install the 512x512 icon into hicolor/512x512 instead of 256x256 - pin -Dlibdir=lib for pcsc-lite; meson otherwise installs to lib64 and opensc configure fails with "winscard.h is required for pcsc" - replace the stale JSignPdf 2.3.0 SourceForge placeholder URL with a staged `path: jsignpdf-full.zip`; the release workflow and build-local.sh now copy the zip into place instead of rewriting url and sha256 with sed, which would have clobbered the new module hashes - build-local.sh --release looked for jsignpdf-<v>.zip, which the build never produces; use jsignpdf-<v>-full.zip
- new flathub-pr job, final releases only, runs after publish-release so a failure never blocks the release - takes maven-dependencies.json from the release tag, not master, so the offline Maven repo matches the poms in the pinned tarball - idempotent: re-running force-pushes the branch and reuses the open PR, and exits early once Flathub is already at the version - needs a FLATHUB_TOKEN secret; GITHUB_TOKEN cannot push to another org
-Dlibdir collides with the --libdir that newer flatpak-builder passes: "Got argument libdir as both -Dlibdir and --libdir. Pick one."
flathub-pr job:
- only an OPEN PR short-circuits PR creation; `gh pr view <branch>` also
resolves closed and merged PRs, so a re-run after a closed PR pushed the
branch and exited without ever opening one
- `git add -A` + `git diff --cached --quiet`: a manifest that grows a new
file left it untracked, and the tree looked clean ("already at version")
- the url/sha256 assertion moved into the rewrite itself, so a reindented
Flathub manifest fails loudly instead of matching no grep
- timeout-minutes, `permissions: contents: read`, and `${{ }}` in `run:`
routed through env like the rest of the workflow
- `flatpak` added to `needs`: pcsc-lite/opensc/openjdk are shared with the
Flathub manifest, so a failure there predicts a failing Flathub build
build-local.sh: guard the two sed rewrites that can silently no-op (desktop,
metainfo) instead of grepping for the zip path, which sed never touches.
Manifests: move the TSA comment onto the --share=network line it describes,
making finish-args byte-identical to the Flathub manifest.
Also drop the stale claim that aarch64 falls through to Swing -- the full ZIP
ships javafx-*-linux-aarch64.jar and Bootstrap.detectFxClassifier picks it up,
so both Flatpak arches get the JavaFX UI and its XDG portal file chooser.
Release tag is now derived once in `setup` and consumed by the four jobs that
checked it out, instead of being recomputed in each.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Two related Flatpak changes.
Align the local manifests with the Flathub one
distribution/linux/flatpak/*.yamlhad drifted from the manifest Flathub actually builds. Both are used: the release workflow builds the published.flatpakbundle from the release manifest, andbuild-local.shbuilds from both.Effects of the drift:
pcsc-lite/opensc, no--socket=pcscand no--device=all, so smartcard and YubiKey signing did not work there, unlike on Flathubbuild-local.sh --releasealways failed: it looked fordistribution/target/jsignpdf-<v>.zip, but the build only produces-full.zipand-minimal.zipsed "s|sha256: [a-f0-9]\{64\}|...|", which rewrites every matching line — adding modules with their own hashes would have silently corrupted themChanges:
pcsc-lite+openscmodules,--socket=pcsc,--device=all,--share=ipc, explicitcommand: jsignpdf, cleanup rules, openjdk license;--socket=pulseaudiodroppedhicolor/512x512— the PNG is 512x512 and was being installed as 256x256build-options: libdir: /app/libonpcsc-lite: flatpak-builder 1.4.2 does not pass--libdir, meson then installs tolib64,libpcsclite.pcfalls offPKG_CONFIG_PATHand opensc configure fails withwinscard.h is required for pcsc. Newer builders already pass the same flag, so this is a no-op there —-Dlibdirinconfig-optsis not, it makes meson abort withGot argument libdir as both -Dlibdir and --libdirpath: jsignpdf-full.zip; the workflow andbuild-local.shcopy the zip into place, so nourl/sha256rewriting is neededVerified with
build-local.sh --release: the resulting bundle hasshared=network;ipc;,sockets=x11;pcsc;,devices=all;, ships/app/lib/opensc-pkcs11.soand/app/lib/libpcsclite.so.1, and the icon at 512x512.The currently published Flathub build was checked and is unaffected — its files are already in
/app/lib, so thelibdirissue is builder-version specific. flathub/io.github.intoolswetrust.JSignPdf#3 carries the same pin upstream.Automate the Flathub update PR
3.2.0 shipped on 2026-09-14 but never reached Flathub, because updating it is a manual PR nobody opened and the manifest has no
x-checker-datafor the Flathub bot.New
flathub-prjob, final releases only:publish-release, so a failure never blocks the release; re-run just this job to retrymaven-dependencies.jsonfrom the release tag rather thanmaster, so the offline Maven repo matches the poms in the pinned tarballUses the
FLATHUB_TOKENsecret, which already exists and has been verified: a classic PAT withpublic_repo, no expiry, owned bykwart, reportingpush: trueonflathub/io.github.intoolswetrust.JSignPdf. A throwaway ref was pushed to that repo and deleted again to confirm write access end to end.GITHUB_TOKENcannot push to another org, anddo-release.ymlpassessecrets: inherit, so the secret reaches this workflow through theworkflow_call. The job still fails with an explicit error if the secret is ever removed.The patch step was dry-run against a clone of the Flathub repo: it reproduces flathub/io.github.intoolswetrust.JSignPdf#2 (the manual 3.2.0 update) byte for byte.
Review fixes (3ca75ba)
flathub-pronly short-circuits on an open PR;gh pr view <branch>also resolves closed and merged PRs, so a re-run after a closed PR pushed the branch and exited without opening onegit add -A+git diff --cached --quiet: a manifest that grows a new file was left untracked and the tree looked clean, reporting "already at version"grep; dry-run covers the happy path, a 4-space reindent, a missingsha256, and a second archive sourcetimeout-minutes,permissions: contents: read, and${{ }}inrun:routed throughenvlike the rest of the workflowflatpakadded toflathub-pr'sneeds: pcsc-lite/opensc/openjdk are shared with the Flathub manifest, so a failure there predicts a failing Flathub buildbuild-local.shguards the twosedrewrites that can silently no-op (desktop, metainfo); the previousgrepchecked a stringsednever touches--share=networkrather than--env=PATH, makingfinish-argsbyte-identical to the Flathub manifestjavafx-*-linux-aarch64.jarandBootstrap.detectFxClassifierreturnslinux-aarch64, so both Flatpak arches get the JavaFX UI and its XDG portal file choosersetupinstead of being recomputed in four jobs