From c2c330dd9689883a08a61d4981f59bb1cee57db2 Mon Sep 17 00:00:00 2001 From: Coelacanthus Date: Sun, 24 Oct 2021 17:29:45 +0800 Subject: refactor: using specified makepkg.conf to obtain a fixed compilation configuration Signed-off-by: Coelacanthus --- build_all.sh | 4 +- makepkg.conf | 158 +++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ 2 files changed, 161 insertions(+), 1 deletion(-) create mode 100644 makepkg.conf diff --git a/build_all.sh b/build_all.sh index 4325596..15d7c92 100755 --- a/build_all.sh +++ b/build_all.sh @@ -2,6 +2,7 @@ ARCH=$(uname -m) PKGDEST="${PWD}/packages/$ARCH" SRCDEST="${PWD}/build" +CONFDEST="${PWD}/makepkg.conf" REPO_DEST="${PWD}/packages/$ARCH/kunoisayami.db.tar.xz" REPO_PENDING="${PWD}/packages/$ARCH/PENDING" touch "$REPO_PENDING" @@ -9,7 +10,7 @@ pushd kunoisayami for folder in */ ; do PACKAGE_NAME=$(printf $folder | sed 's/.$//') pushd "$folder" - SRCPKGDEST=$SRCDEST SRCDEST=$SRCDEST PKGDEST=$PKGDEST makepkg --clean --sign --key 4A0F0C8BC709ACA4341767FB243975C8DB9656B9 + SRCPKGDEST=$SRCDEST SRCDEST=$SRCDEST PKGDEST=$PKGDEST MAKEPKG_CONF=$CONFDEST makepkg --clean --sign --key 4A0F0C8BC709ACA4341767FB243975C8DB9656B9 if [ $? == 0 ]; then echo "$PACKAGE_NAME" >> "$REPO_PENDING" fi @@ -25,6 +26,7 @@ echo $(date +%s) > "$PKGDEST/LASTBUILD" unset PACKAGE_NAME unset PKGDEST unset SRCDEST +unset CONFDEST unset REPO_DEST rm -rf "$REPO_PENDING" unset REPO_PENDING diff --git a/makepkg.conf b/makepkg.conf new file mode 100644 index 0000000..c37b078 --- /dev/null +++ b/makepkg.conf @@ -0,0 +1,158 @@ +#!/hint/bash +# +# /etc/makepkg.conf +# + +######################################################################### +# SOURCE ACQUISITION +######################################################################### +# +#-- The download utilities that makepkg should use to acquire sources +# Format: 'protocol::agent' +DLAGENTS=('file::/usr/bin/curl -qgC - -o %o %u' + 'ftp::/usr/bin/curl -qgfC - --ftp-pasv --retry 3 --retry-delay 3 -o %o %u' + 'http::/usr/bin/curl -qgb "" -fLC - --retry 3 --retry-delay 3 -o %o %u' + 'https::/usr/bin/curl -qgb "" -fLC - --retry 3 --retry-delay 3 -o %o %u' + 'rsync::/usr/bin/rsync --no-motd -z %u %o' + 'scp::/usr/bin/scp -C %u %o') + +# Other common tools: +# /usr/bin/snarf +# /usr/bin/lftpget -c +# /usr/bin/wget + +#-- The package required by makepkg to download VCS sources +# Format: 'protocol::package' +VCSCLIENTS=('bzr::bzr' + 'fossil::fossil' + 'git::git' + 'hg::mercurial' + 'svn::subversion') + +######################################################################### +# ARCHITECTURE, COMPILE FLAGS +######################################################################### +# +CARCH="x86_64" +CHOST="x86_64-pc-linux-gnu" + +#-- Compiler and Linker Flags +#CPPFLAGS="" +CFLAGS="-march=x86-64 -mtune=generic -O2 -pipe -fno-plt -fexceptions \ + -Wp,-D_FORTIFY_SOURCE=2 -Wformat -Werror=format-security \ + -fstack-clash-protection -fcf-protection" +CXXFLAGS="$CFLAGS -Wp,-D_GLIBCXX_ASSERTIONS" +LDFLAGS="-Wl,-O1,--sort-common,--as-needed,-z,relro,-z,now" +#RUSTFLAGS="-C opt-level=2" +#-- Make Flags: change this for DistCC/SMP systems +#MAKEFLAGS="-j2" +#-- Debugging flags +DEBUG_CFLAGS="-g -fvar-tracking-assignments" +DEBUG_CXXFLAGS="-g -fvar-tracking-assignments" +#DEBUG_RUSTFLAGS="-C debuginfo=2" + +######################################################################### +# BUILD ENVIRONMENT +######################################################################### +# +# Makepkg defaults: BUILDENV=(!distcc !color !ccache check !sign) +# A negated environment option will do the opposite of the comments below. +# +#-- distcc: Use the Distributed C/C++/ObjC compiler +#-- color: Colorize output messages +#-- ccache: Use ccache to cache compilation +#-- check: Run the check() function if present in the PKGBUILD +#-- sign: Generate PGP signature file +# +BUILDENV=(!distcc color !ccache check !sign) +# +#-- If using DistCC, your MAKEFLAGS will also need modification. In addition, +#-- specify a space-delimited list of hosts running in the DistCC cluster. +#DISTCC_HOSTS="" +# +#-- Specify a directory for package building. +#BUILDDIR=/tmp/makepkg + +######################################################################### +# GLOBAL PACKAGE OPTIONS +# These are default values for the options=() settings +######################################################################### +# +# Makepkg defaults: OPTIONS=(!strip docs libtool staticlibs emptydirs !zipman !purge !debug !lto) +# A negated option will do the opposite of the comments below. +# +#-- strip: Strip symbols from binaries/libraries +#-- docs: Save doc directories specified by DOC_DIRS +#-- libtool: Leave libtool (.la) files in packages +#-- staticlibs: Leave static library (.a) files in packages +#-- emptydirs: Leave empty directories in packages +#-- zipman: Compress manual (man and info) pages in MAN_DIRS with gzip +#-- purge: Remove files specified by PURGE_TARGETS +#-- debug: Add debugging flags as specified in DEBUG_* variables +#-- lto: Add compile flags for building with link time optimization +# +OPTIONS=(strip docs !libtool !staticlibs emptydirs zipman purge debug !lto) + +#-- File integrity checks to use. Valid: md5, sha1, sha224, sha256, sha384, sha512, b2 +INTEGRITY_CHECK=(sha256) +#-- Options to be used when stripping binaries. See `man strip' for details. +STRIP_BINARIES="--strip-all" +#-- Options to be used when stripping shared libraries. See `man strip' for details. +STRIP_SHARED="--strip-unneeded" +#-- Options to be used when stripping static libraries. See `man strip' for details. +STRIP_STATIC="--strip-debug" +#-- Manual (man and info) directories to compress (if zipman is specified) +MAN_DIRS=({usr{,/local}{,/share},opt/*}/{man,info}) +#-- Doc directories to remove (if !docs is specified) +DOC_DIRS=(usr/{,local/}{,share/}{doc,gtk-doc} opt/*/{doc,gtk-doc}) +#-- Files to be removed from all packages (if purge is specified) +PURGE_TARGETS=(usr/{,share}/info/dir .packlist *.pod) +#-- Directory to store source code in for debug packages +DBGSRCDIR="/usr/src/debug" + +######################################################################### +# PACKAGE OUTPUT +######################################################################### +# +# Default: put built package and cached source in build directory +# +#-- Destination: specify a fixed directory where all packages will be placed +#PKGDEST=/home/packages +#-- Source cache: specify a fixed directory where source files will be cached +#SRCDEST=/home/sources +#-- Source packages: specify a fixed directory where all src packages will be placed +#SRCPKGDEST=/home/srcpackages +#-- Log files: specify a fixed directory where all log files will be placed +#LOGDEST=/home/makepkglogs +#-- Packager: name/email of the person or organization building packages +#PACKAGER="John Doe " +#-- Specify a key to use for package signing +#GPGKEY="" + +######################################################################### +# COMPRESSION DEFAULTS +######################################################################### +# +COMPRESSGZ=(gzip -c -f -n) +COMPRESSBZ2=(bzip2 -c -f) +COMPRESSXZ=(xz -c -z -) +COMPRESSZST=(zstd -c -z -q -) +COMPRESSLRZ=(lrzip -q) +COMPRESSLZO=(lzop -q) +COMPRESSZ=(compress -c -f) +COMPRESSLZ4=(lz4 -q) +COMPRESSLZ=(lzip -c -f) + +######################################################################### +# EXTENSION DEFAULTS +######################################################################### +# +PKGEXT='.pkg.tar.zst' +SRCEXT='.src.tar.gz' + +######################################################################### +# OTHER +######################################################################### +# +#-- Command used to run pacman as root, instead of trying sudo and su +#PACMAN_AUTH=() -- cgit v1.3.1 From f0ab07957c7ace17af08ffabbbb64eb607f53f28 Mon Sep 17 00:00:00 2001 From: Coelacanthus Date: Sun, 24 Oct 2021 17:41:38 +0800 Subject: refactor(makepkg): enable parallel compilation Signed-off-by: Coelacanthus --- makepkg.conf | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/makepkg.conf b/makepkg.conf index c37b078..a059782 100644 --- a/makepkg.conf +++ b/makepkg.conf @@ -45,7 +45,7 @@ CXXFLAGS="$CFLAGS -Wp,-D_GLIBCXX_ASSERTIONS" LDFLAGS="-Wl,-O1,--sort-common,--as-needed,-z,relro,-z,now" #RUSTFLAGS="-C opt-level=2" #-- Make Flags: change this for DistCC/SMP systems -#MAKEFLAGS="-j2" +MAKEFLAGS="-j$(nproc)" #-- Debugging flags DEBUG_CFLAGS="-g -fvar-tracking-assignments" DEBUG_CXXFLAGS="-g -fvar-tracking-assignments" -- cgit v1.3.1 From 9330288186a6c17ffee9b90d628c7d2ae25ec5a1 Mon Sep 17 00:00:00 2001 From: Coelacanthus Date: Sun, 24 Oct 2021 17:44:53 +0800 Subject: refactor(makepkg): enable zstd parallel compression and using max compression The decompression time of zstd increases slowly with the compression ratio, so it is beneficial for users to enable the highest compression ratio. (as Fedora does) Signed-off-by: Coelacanthus --- makepkg.conf | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/makepkg.conf b/makepkg.conf index a059782..5f886c5 100644 --- a/makepkg.conf +++ b/makepkg.conf @@ -136,7 +136,7 @@ DBGSRCDIR="/usr/src/debug" COMPRESSGZ=(gzip -c -f -n) COMPRESSBZ2=(bzip2 -c -f) COMPRESSXZ=(xz -c -z -) -COMPRESSZST=(zstd -c -z -q -) +COMPRESSZST=(zstd -c -z -q --ultra -22 --threads=0 -) COMPRESSLRZ=(lrzip -q) COMPRESSLZO=(lzop -q) COMPRESSZ=(compress -c -f) @@ -148,7 +148,7 @@ COMPRESSLZ=(lzip -c -f) ######################################################################### # PKGEXT='.pkg.tar.zst' -SRCEXT='.src.tar.gz' +SRCEXT='.src.tar.zst' ######################################################################### # OTHER -- cgit v1.3.1 From 31674b7581a3638667db705e6deb81608ca3ba76 Mon Sep 17 00:00:00 2001 From: Coelacanthus Date: Sun, 24 Oct 2021 17:57:49 +0800 Subject: refactor(makepkg): move sign, ACKAGER and GPGKEY to makepkg.conf Signed-off-by: Coelacanthus --- build_all.sh | 2 +- makepkg.conf | 6 +++--- 2 files changed, 4 insertions(+), 4 deletions(-) diff --git a/build_all.sh b/build_all.sh index 15d7c92..7f22e11 100755 --- a/build_all.sh +++ b/build_all.sh @@ -10,7 +10,7 @@ pushd kunoisayami for folder in */ ; do PACKAGE_NAME=$(printf $folder | sed 's/.$//') pushd "$folder" - SRCPKGDEST=$SRCDEST SRCDEST=$SRCDEST PKGDEST=$PKGDEST MAKEPKG_CONF=$CONFDEST makepkg --clean --sign --key 4A0F0C8BC709ACA4341767FB243975C8DB9656B9 + SRCPKGDEST=$SRCDEST SRCDEST=$SRCDEST PKGDEST=$PKGDEST MAKEPKG_CONF=$CONFDEST makepkg --clean if [ $? == 0 ]; then echo "$PACKAGE_NAME" >> "$REPO_PENDING" fi diff --git a/makepkg.conf b/makepkg.conf index 5f886c5..92af8df 100644 --- a/makepkg.conf +++ b/makepkg.conf @@ -64,7 +64,7 @@ DEBUG_CXXFLAGS="-g -fvar-tracking-assignments" #-- check: Run the check() function if present in the PKGBUILD #-- sign: Generate PGP signature file # -BUILDENV=(!distcc color !ccache check !sign) +BUILDENV=(!distcc color !ccache check sign) # #-- If using DistCC, your MAKEFLAGS will also need modification. In addition, #-- specify a space-delimited list of hosts running in the DistCC cluster. @@ -125,9 +125,9 @@ DBGSRCDIR="/usr/src/debug" #-- Log files: specify a fixed directory where all log files will be placed #LOGDEST=/home/makepkglogs #-- Packager: name/email of the person or organization building packages -#PACKAGER="John Doe " +PACKAGER="KunoiSayami " #-- Specify a key to use for package signing -#GPGKEY="" +GPGKEY="4A0F0C8BC709ACA4341767FB243975C8DB9656B9" ######################################################################### # COMPRESSION DEFAULTS -- cgit v1.3.1 From 1ff92522616e44c5a5d7577fd14e41f905ba3dd2 Mon Sep 17 00:00:00 2001 From: Coelacanthus Date: Sun, 24 Oct 2021 18:06:14 +0800 Subject: refactor(makepkg): using SHA512 and BLAKE2 as hash algo to harden it Signed-off-by: Coelacanthus --- makepkg.conf | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/makepkg.conf b/makepkg.conf index 92af8df..bcc1cb2 100644 --- a/makepkg.conf +++ b/makepkg.conf @@ -94,7 +94,7 @@ BUILDENV=(!distcc color !ccache check sign) OPTIONS=(strip docs !libtool !staticlibs emptydirs zipman purge debug !lto) #-- File integrity checks to use. Valid: md5, sha1, sha224, sha256, sha384, sha512, b2 -INTEGRITY_CHECK=(sha256) +INTEGRITY_CHECK=(sha512 b2) #-- Options to be used when stripping binaries. See `man strip' for details. STRIP_BINARIES="--strip-all" #-- Options to be used when stripping shared libraries. See `man strip' for details. -- cgit v1.3.1