summaryrefslogtreecommitdiffstats
path: root/packaging/rpm
diff options
context:
space:
mode:
authorChristophe Besson <cbesson@gmail.com>2026-08-31 10:49:45 +0200
committerChristophe Besson <cbesson@gmail.com>2026-08-31 10:49:45 +0200
commit8d5c564e75ad2928e77ea66decc979366ca5ccd5 (patch)
tree7f88ceb2ccd838011bb2f399f148c7f9b39f75ec /packaging/rpm
parent0c2754d2d4cb1905d5e324f56fbc64e4afae526f (diff)
downloadmeshbay-8d5c564e75ad2928e77ea66decc979366ca5ccd5.tar.gz
feat(packaging): 4-package .deb/.rpm build system under /opt
Shared venv architecture: meshbay-common owns the Python venv with all pip deps pre-installed; hub and node add only their code into it. Client is a standalone Electron app. No pip runs at install time. - Add build scripts (packaging/build/) for common, hub, node, client - Add orchestrator build-packages.sh with deb/rpm auto-detection - Add .deb control/postinst for all 4 packages - Add .rpm specs for all 4 packages (replaces python3-meshbay-common) - Add Gnome .desktop launcher and icon resizing - Add firewalld services (meshbay-cast, meshbay-node) and UFW profiles - Update systemd units to use /opt/meshbay-common/venv/bin/ paths - TMDB token baked into node package at build time via QE/node.env - Fix package-lock.json sync for protobufjs override Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Diffstat (limited to 'packaging/rpm')
-rw-r--r--packaging/rpm/meshbay-client.spec53
-rw-r--r--packaging/rpm/meshbay-common.spec25
-rw-r--r--packaging/rpm/meshbay-hub.spec107
-rw-r--r--packaging/rpm/meshbay-node.spec99
-rw-r--r--packaging/rpm/python3-meshbay-common.spec59
5 files changed, 127 insertions, 216 deletions
diff --git a/packaging/rpm/meshbay-client.spec b/packaging/rpm/meshbay-client.spec
new file mode 100644
index 0000000..8788e67
--- /dev/null
+++ b/packaging/rpm/meshbay-client.spec
@@ -0,0 +1,53 @@
+Name: meshbay-client
+Version: __VERSION__
+Release: 1%{?dist}
+Summary: MeshBay — peer-to-peer file sharing, streaming and group chat
+License: AGPLv3+
+URL: https://meshbay.org
+
+AutoReqProv: no
+
+Requires: gtk3
+Requires: libnotify
+Requires: nss
+Requires: libXScrnSaver
+Requires: libXtst
+Requires: at-spi2-core
+Requires: libdrm
+Requires: mesa-libgbm
+Requires: alsa-lib
+Recommends: meshbay-node
+
+%description
+Desktop client for MeshBay. Connects to MeshBay nodes over WebRTC for
+file sharing, video streaming, and group chat. Includes Chromecast and
+Smart TV casting support.
+
+Installs the Electron application to /opt/meshbay-client/ and a Gnome
+launcher named "MeshBay".
+
+%install
+cp -a %{_staging_root}/* %{buildroot}/
+
+%post
+if [ -f /opt/meshbay-client/chrome-sandbox ]; then
+ chown root:root /opt/meshbay-client/chrome-sandbox
+ chmod 4755 /opt/meshbay-client/chrome-sandbox
+fi
+update-desktop-database /usr/share/applications 2>/dev/null || true
+gtk-update-icon-cache -f -t /usr/share/icons/hicolor 2>/dev/null || true
+
+%postun
+update-desktop-database /usr/share/applications 2>/dev/null || true
+gtk-update-icon-cache -f -t /usr/share/icons/hicolor 2>/dev/null || true
+
+%files
+/opt/meshbay-client
+/usr/bin/meshbay
+/usr/share/applications/meshbay.desktop
+/usr/share/icons/hicolor/*/apps/meshbay.png
+/usr/lib/firewalld/services/meshbay-cast.xml
+
+%changelog
+* Sun Aug 31 2026 MeshBay Team <team@meshbay.org> - %{version}-1
+- Initial packaging of the desktop client
diff --git a/packaging/rpm/meshbay-common.spec b/packaging/rpm/meshbay-common.spec
new file mode 100644
index 0000000..e1088d4
--- /dev/null
+++ b/packaging/rpm/meshbay-common.spec
@@ -0,0 +1,25 @@
+Name: meshbay-common
+Version: __VERSION__
+Release: 1%{?dist}
+Summary: MeshBay shared Python runtime and libraries
+License: AGPLv3+
+URL: https://meshbay.org
+
+AutoReqProv: no
+
+%description
+Shared Python virtual environment, cryptographic primitives
+(Ed25519, X25519, GEK wrap/unwrap, ChaCha20-Poly1305), protocol types
+(MNP, MHP), and all pip dependencies used by meshbay-hub and meshbay-node.
+
+Installs to /opt/meshbay-common/venv/.
+
+%install
+cp -a %{_staging_root}/* %{buildroot}/
+
+%files
+/opt/meshbay-common
+
+%changelog
+* Sun Aug 31 2026 MeshBay Team <team@meshbay.org> - %{version}-1
+- Packaging overhaul: shared venv under /opt/meshbay-common/venv/
diff --git a/packaging/rpm/meshbay-hub.spec b/packaging/rpm/meshbay-hub.spec
index dd4803f..73df0b9 100644
--- a/packaging/rpm/meshbay-hub.spec
+++ b/packaging/rpm/meshbay-hub.spec
@@ -1,61 +1,38 @@
Name: meshbay-hub
-Version: 0.6.0
+Version: __VERSION__
Release: 1%{?dist}
Summary: MeshBay Hub — identity authority and group registry server
License: AGPLv3+
URL: https://meshbay.org
-Source0: %{name}-%{version}.tar.gz
+AutoReqProv: no
BuildArch: noarch
-BuildRequires: python3-devel >= 3.12
-BuildRequires: python3-pip
-BuildRequires: python3-hatchling
-Requires: python3 >= 3.12
-Requires: python3-meshbay-common = %{version}
-Requires: python3-fastapi
-Requires: python3-uvicorn
-Requires: python3-sqlalchemy >= 2.0
-Requires: python3-alembic
-Requires: python3-asyncpg
-Requires: python3-pyjwt
-Requires: python3-blake3
-Requires: python3-slowapi
-Requires: postgresql-server
+Requires: meshbay-common = %{version}
+Recommends: caddy
+Recommends: postgresql-server
%description
-MeshBay Hub provides identity management, group registry,
-GEK bundle distribution, and coordination for MeshBay nodes.
-Runs as a systemd service behind Caddy (HTTPS).
+MeshBay Hub provides user registration, JWT issuance, group management,
+WebRTC signaling, notifications, and moderation for MeshBay networks.
-%prep
-%autosetup
-
-%build
-%{python3} -m pip wheel --no-deps --wheel-dir dist .
+Installs hub code into the shared venv at /opt/meshbay-common/venv/.
+Runs as a systemd service behind Caddy for HTTPS.
%install
-%{python3} -m pip install --root %{buildroot} --no-index --find-links dist meshbay-hub
-
-# systemd service
-install -Dm644 packaging/systemd/meshbay-hub.service \
- %{buildroot}%{_unitdir}/meshbay-hub.service
-
-# Config file template
-install -Dm644 packaging/conf/hub.toml.example \
- %{buildroot}%{_sysconfdir}/meshbay/hub.toml.example
-
-# Data directory
-install -d %{buildroot}%{_sharedstatedir}/meshbay/hub
+cp -a %{_staging_root}/* %{buildroot}/
%pre
getent group meshbay >/dev/null || groupadd -r meshbay
getent passwd meshbay >/dev/null || \
- useradd -r -g meshbay -d %{_sharedstatedir}/meshbay -s /sbin/nologin \
+ useradd -r -g meshbay -d /var/lib/meshbay -s /sbin/nologin \
-c "MeshBay service account" meshbay
%post
%systemd_post meshbay-hub.service
+install -d -o meshbay -g meshbay -m 750 /var/lib/meshbay/hub
+install -d -o meshbay -g meshbay -m 750 /var/log/meshbay
+install -d -m 755 /etc/meshbay
%preun
%systemd_preun meshbay-hub.service
@@ -64,55 +41,13 @@ getent passwd meshbay >/dev/null || \
%systemd_postun_with_restart meshbay-hub.service
%files
-%license LICENSE
-%doc README.md
-%{python3_sitelib}/meshbay_hub/
-%{python3_sitelib}/meshbay_hub-*.dist-info/
-%{_bindir}/meshbay-hub
+/opt/meshbay-hub
+/opt/meshbay-common/venv/lib/python*/site-packages/meshbay_hub/
+/opt/meshbay-common/venv/lib/python*/site-packages/meshbay_hub-*.dist-info/
+/opt/meshbay-common/venv/bin/meshbay-hub
+/usr/bin/meshbay-hub
%{_unitdir}/meshbay-hub.service
-%config(noreplace) %{_sysconfdir}/meshbay/hub.toml.example
-%dir %attr(750, meshbay, meshbay) %{_sharedstatedir}/meshbay/hub
%changelog
-* Sun Aug 23 2026 MeshBay Team <team@meshbay.org> - 0.6.0-1
-- Group UI split into a pluggable "applications" architecture (Chat, Files
- today; Videos/Music/Photos can register without touching GroupPage)
-- Operators can enable/disable applications per group from Settings
-- Group Settings sections reordered: Invite, Pairing, Applications, Shared
- directories, Uploads, danger zone, Your devices, Members
-- Fixed: a fresh access token was never picked up when a "not a member"
- handshake retry fired, wrongly locking a member (including a group's own
- creator) out of a group they had just joined
-- Fixed: opening Chat on a group with existing messages threw and wedged the
- page's rendering, leaving every button unresponsive until reload
-
-* Sun Aug 16 2026 MeshBay Team <team@meshbay.org> - 0.5.0-1
-- Leave a group; public groups capped at 10 per owner, staff exempt
-- Groups are listed only once a node has announced them; prune-groups collects the rest
-- Node presence dot in the sidebar, from the signaling registry — no polling
-- Chat opens on the newest 100 messages and pages backwards (it used to page forwards)
-- Profile split out of Settings; public groups are open, invite-only is private
-- Streamed downloads verify the service worker is really serving before writing
-- Static assets are revalidated, so a half-updated SPA cannot load
-
-* Sun Aug 16 2026 MeshBay Team <team@meshbay.org> - 0.4.0-1
-- Web client translated into fr, es, pt-BR, zh-CN, ja, de, it, nl and pl
-- Catalogues load on demand, one file per language, English as fallback
-- Plural forms selected through Intl.PluralRules (Polish needs four)
-- Locale matching keeps the region, so pt-BR and zh-CN resolve
-- Static assets are revalidated, so a half-updated SPA cannot load
-
-* Sat Aug 15 2026 MeshBay Team <team@meshbay.org> - 0.3.0-1
-- Transfers survive leaving a group; downloads stream to disk in every browser
-- Download a folder as a zip, built in the browser (zip64, store-only)
-- Group owner can remove a member; editable group description
-- Nodes are recorded at the address their signed announcement arrived from
-- Deleted accounts stop being counted; the connection log keeps their name
-
-* Fri Aug 14 2026 MeshBay Team <team@meshbay.org> - 0.2.0-1
-- Hub no longer stores or publishes user identity keys (H3); schema migration
-- Access tokens carry no pk_user claim
-- SPA: Argon2id for the keypair bundle, per-node identity, invitation codes
-
-* Sat Aug 09 2026 MeshBay Team <team@meshbay.org> - 0.1.0-1
-- Initial package
+* Sun Aug 31 2026 MeshBay Team <team@meshbay.org> - %{version}-1
+- Packaging overhaul: installs into shared venv under /opt
diff --git a/packaging/rpm/meshbay-node.spec b/packaging/rpm/meshbay-node.spec
index e4f386e..20d69bc 100644
--- a/packaging/rpm/meshbay-node.spec
+++ b/packaging/rpm/meshbay-node.spec
@@ -1,92 +1,49 @@
Name: meshbay-node
-Version: 0.6.0
+Version: __VERSION__
Release: 1%{?dist}
Summary: MeshBay Node — local file host, streaming server, and group daemon
License: AGPLv3+
URL: https://meshbay.org
-Source0: %{name}-%{version}.tar.gz
+AutoReqProv: no
BuildArch: noarch
-BuildRequires: python3-devel >= 3.12
-BuildRequires: python3-pip
-BuildRequires: python3-hatchling
-Requires: python3 >= 3.12
-Requires: python3-meshbay-common = %{version}
-Requires: python3-fastapi
-Requires: python3-uvicorn
-Requires: python3-httpx
-Requires: python3-watchdog
-Requires: python3-aioquic >= 1.0
-Requires: python3-aioice
-Requires: python3-pyjwt
-Requires: python3-blake3
-Requires: python3-msgpack
-Requires: python3-zstandard
-# Optional: ffmpeg for HLS streaming
+Requires: meshbay-common = %{version}
Recommends: ffmpeg
%description
-MeshBay Node indexes local directories and serves encrypted files
-to authenticated group members over QUIC (MNP v2) or TCP+TLS (MNP v1).
-Includes a local web UI at http://localhost:18000.
+MeshBay Node indexes local directories and serves encrypted files to
+authenticated group members over WebRTC. Includes video streaming (fMP4
+remux via ffmpeg), group chat, and a local admin UI on localhost:18000.
-%prep
-%autosetup
-
-%build
-%{python3} -m pip wheel --no-deps --wheel-dir dist .
+Installs node code into the shared venv at /opt/meshbay-common/venv/.
+Ships a default TMDB API token for the Videos app.
+Runs as a systemd user service.
%install
-%{python3} -m pip install --root %{buildroot} --no-index --find-links dist meshbay-node
+cp -a %{_staging_root}/* %{buildroot}/
+
+%post
+if [ -d /run/systemd/system ]; then
+ systemctl daemon-reload || true
+fi
-# Two units, because there are two personas and one file cannot be both.
-#
-# The SYSTEM template carries User=%%i and is instantiated per person by root
-# (`systemctl enable --now meshbay-node@alice`) — the server case. A *user* unit
-# cannot carry User= at all: it already runs as its owner, and systemd refuses
-# the file. This spec used to install the template into the user unit directory,
-# where it could never have started.
-install -Dm644 packaging/systemd/meshbay-node.service \
- %{buildroot}%{_unitdir}/meshbay-node@.service
-install -Dm644 packaging/systemd/meshbay-node-user.service \
- %{buildroot}%{_userunitdir}/meshbay-node.service
+%preun
+if [ -d /run/systemd/system ]; then
+ systemctl daemon-reload || true
+fi
%files
-%license LICENSE
-%doc README.md
-%{python3_sitelib}/meshbay_node/
-%{python3_sitelib}/meshbay_node-*.dist-info/
-%{_bindir}/meshbay-node
+/opt/meshbay-node
+/opt/meshbay-common/venv/lib/python*/site-packages/meshbay_node/
+/opt/meshbay-common/venv/lib/python*/site-packages/meshbay_node-*.dist-info/
+/opt/meshbay-common/venv/bin/meshbay-node
+/usr/bin/meshbay-node
%{_unitdir}/meshbay-node@.service
%{_userunitdir}/meshbay-node.service
+/usr/lib/firewalld/services/meshbay-node.xml
+/etc/ufw/applications.d/meshbay
%changelog
-* Sun Aug 23 2026 MeshBay Team <team@meshbay.org> - 0.6.0-1
-- Per-group application enablement: roster setting, signed apps_enabled op,
- enforced by the same admin-authority check as member_upload
-
-* Sun Aug 16 2026 MeshBay Team <team@meshbay.org> - 0.5.0-1
-- Abandoned video streams release their transcode slot at once
-- Background tasks are held, so none is collected mid-flight losing a slot
-- ffmpeg is reaped without deadlocking on its own unread output
-- Chunk replies wait for room on the channel instead of queueing 8 MB
-- Chat history pages backwards; upload names accept any script, and errors name the file
-
-* Sun Aug 16 2026 MeshBay Team <team@meshbay.org> - 0.4.0-1
-- No functional change; released in step with the other packages
-
-* Sat Aug 15 2026 MeshBay Team <team@meshbay.org> - 0.3.0-1
-- Video streaming is paced by the client; stream_stop frees the transcode slot
-- Operator can remove an empty directory and revoke a member over MNP
-- meshbay-node group add: host another of your hub groups
-- admin_pk_ed25519 removed; the roster is the only source of node authority
-
-* Fri Aug 14 2026 MeshBay Team <team@meshbay.org> - 0.2.0-1
-- Node wraps the group key itself; members are admitted from a local roster
-- Identity keys are per node, created at first contact and pinned there
-- Operator surface over SSH: operator pair, member list|invite|revoke|unpin
-- Unauthenticated HTTP file API and TCP transport removed (C1, C6)
-
-* Sat Aug 09 2026 MeshBay Team <team@meshbay.org> - 0.1.0-1
-- Initial package
+* Sun Aug 31 2026 MeshBay Team <team@meshbay.org> - %{version}-1
+- Packaging overhaul: installs into shared venv under /opt
diff --git a/packaging/rpm/python3-meshbay-common.spec b/packaging/rpm/python3-meshbay-common.spec
deleted file mode 100644
index 6af8ed9..0000000
--- a/packaging/rpm/python3-meshbay-common.spec
+++ /dev/null
@@ -1,59 +0,0 @@
-Name: python3-meshbay-common
-Version: 0.6.0
-Release: 1%{?dist}
-Summary: MeshBay shared cryptographic primitives and protocol types
-License: AGPLv3+
-URL: https://meshbay.org
-Source0: meshbay-common-%{version}.tar.gz
-
-BuildArch: noarch
-BuildRequires: python3-devel >= 3.12
-BuildRequires: python3-pip
-BuildRequires: python3-hatchling
-
-Requires: python3 >= 3.12
-Requires: python3-cryptography >= 43.0
-Requires: python3-pyjwt >= 2.9
-Requires: python3-blake3 >= 1.0
-Requires: python3-msgpack >= 1.1
-Requires: python3-zstandard >= 0.23
-
-%description
-Shared library for MeshBay hub and node packages.
-Provides: Ed25519/X25519 operations, GEK wrap/unwrap, chunk
-encryption/signing, keystore AES-256-GCM, and MNP protocol types.
-
-%prep
-%autosetup -n meshbay-common-%{version}
-
-%build
-%{python3} -m pip wheel --no-deps --wheel-dir dist .
-
-%install
-%{python3} -m pip install --root %{buildroot} --no-index --find-links dist meshbay-common
-
-%files
-%license LICENSE
-%{python3_sitelib}/meshbay_common/
-%{python3_sitelib}/meshbay_common-*.dist-info/
-
-%changelog
-* Sun Aug 23 2026 MeshBay Team <team@meshbay.org> - 0.6.0-1
-- MNP 0.4: apps_enabled/apps_enabled_ack, enabled_apps on the handshake ack
-
-* Sun Aug 16 2026 MeshBay Team <team@meshbay.org> - 0.5.0-1
-- MNP 0.2: PING/PONG, and backward chat paging (before / has_more)
-
-* Sun Aug 16 2026 MeshBay Team <team@meshbay.org> - 0.4.0-1
-- No functional change; released in step with the other packages
-
-* Sat Aug 15 2026 MeshBay Team <team@meshbay.org> - 0.3.0-1
-- MNP: dir_delete, member_revoke, stream_more/stream_stop; file_chunk names its file
-
-* Fri Aug 14 2026 MeshBay Team <team@meshbay.org> - 0.2.0-1
-- Join and pairing transcripts (meshbay:join:v1)
-- Handshake refusals carry a machine-readable code
-- gek_bundle_store removed from the protocol; no member supplies key material
-
-* Sat Aug 09 2026 MeshBay Team <team@meshbay.org> - 0.1.0-1
-- Initial package