Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
80 commits
Select commit Hold shift + click to select a range
84eb782
Set up TinyPilot virtual environment from Debian package
mtlynch Apr 10, 2023
d431518
work in progress
mtlynch Apr 10, 2023
216a61c
Spaces to tabs
mtlynch Apr 10, 2023
895eb98
work in progress
mtlynch Apr 10, 2023
d31b42a
Use venv as suffix
mtlynch Apr 10, 2023
2e1c955
Declare armhf arch
mtlynch Apr 10, 2023
2de5d2d
work in progress
mtlynch Apr 10, 2023
62fd679
Build with ARM emulation
mtlynch Apr 10, 2023
638ca2f
Escape backslash
mtlynch Apr 10, 2023
239f801
Disable debug symbols
mtlynch Apr 10, 2023
5d51512
Drop unused var
mtlynch Apr 10, 2023
bf54f5a
Add doc
mtlynch Apr 10, 2023
fe5447b
work in progress
mtlynch Apr 10, 2023
6d0dd9e
Use environment variable
mtlynch Apr 10, 2023
d5e295f
Fix characters
mtlynch Apr 10, 2023
1201645
Fix interest command
mtlynch Apr 10, 2023
bb0a7ab
Add TODO
mtlynch Apr 10, 2023
41f098d
Remove junk after dh_virtualenv
mtlynch Apr 10, 2023
be7322d
Fix path
mtlynch Apr 10, 2023
736269b
Remove gitignore rule
mtlynch Apr 10, 2023
a46a6e3
Fix find command
mtlynch Apr 10, 2023
a6ecb78
Build multi-arch
mtlynch Apr 10, 2023
ea20152
Remove more cruft
mtlynch Apr 11, 2023
0fa25b5
work in progress
mtlynch Apr 11, 2023
d5245b6
Don't hardcode python version
mtlynch Apr 11, 2023
ce3fe25
work in progress
mtlynch Apr 11, 2023
ecb44ff
work in progress
mtlynch Apr 11, 2023
c0c8884
Docker buildx
mtlynch Apr 11, 2023
913a471
work in progress
mtlynch Apr 11, 2023
1600718
work in progress
mtlynch Apr 11, 2023
dda0807
work in progress
mtlynch Apr 11, 2023
456989c
Merge branch 'dh-venv-multiarch' into dh-venv
mtlynch Apr 11, 2023
70a363a
Fix verify-bundle
mtlynch Apr 11, 2023
9ff701d
Fix create-bundle
mtlynch Apr 11, 2023
b80d22a
Exclude amd64 build
mtlynch Apr 11, 2023
2e4959c
Fix quote
mtlynch Apr 11, 2023
9e70e7f
Fix rules
mtlynch Apr 11, 2023
52acfc0
work in progress
mtlynch Apr 11, 2023
acedf1a
work in progress
mtlynch Apr 11, 2023
0c9c513
work in progress
mtlynch Apr 11, 2023
cafb927
work in progress
mtlynch Apr 11, 2023
60eed62
Update lintian overrides
mtlynch Apr 11, 2023
f335fa7
Merge branch 'master' into dh-venv
mtlynch Apr 11, 2023
6a3631b
work in progress
mtlynch Apr 11, 2023
7b8160f
Simplify overrides with wildcards
mtlynch Apr 11, 2023
5481ca6
work in progress
mtlynch Apr 11, 2023
c23ab0b
Revert changes to VS code settings
mtlynch Apr 11, 2023
b63183f
Document multiarch better
mtlynch Apr 12, 2023
7680b44
Stop testing Debian 10 in molecule
mtlynch Apr 12, 2023
c14dfeb
Only build bundles from master
mtlynch Apr 12, 2023
075ca3e
work in progress
mtlynch Apr 12, 2023
6160b59
Add better documentation
mtlynch Apr 14, 2023
f7d8f84
Adjust syntax for lintian override
mtlynch Apr 14, 2023
fa2e97a
Revert "Adjust syntax for lintian override"
mtlynch May 8, 2023
2ed82f5
Merge branch 'master' into dh-venv
mtlynch May 8, 2023
3f56284
Fix script comments
mtlynch May 8, 2023
e09e2dc
Remove old workaround
mtlynch May 8, 2023
a36e93c
Merge branch 'master' into dh-venv
jotaen4tinypilot May 19, 2023
2e53b36
Ignore if the AMD64 doesn't exist.
jdeanwallace May 30, 2023
c2d47f1
Merge branch 'master' into dh-venv
jdeanwallace May 30, 2023
af18c57
Overwrite destination directory.
jdeanwallace May 30, 2023
53b394c
Only build armv7 binaries on master branch.
jdeanwallace May 30, 2023
ede7351
Handle dynamic architecture directory structure.
jdeanwallace May 30, 2023
ac09887
Move Debian packages to a predictable location.
jdeanwallace May 30, 2023
ebb2caf
Enable Docker later caching.
jdeanwallace May 30, 2023
95ba48b
Enable hardening.
jdeanwallace May 31, 2023
c30c1d6
Enable hardening build flags.
jdeanwallace May 31, 2023
3615792
Suppress lintian tags.
jdeanwallace May 31, 2023
eb82746
Suppress lintian tags.
jdeanwallace May 31, 2023
1170895
Suppress lintian tags.
jdeanwallace May 31, 2023
3a9408a
Use case statement for deciding target arch.
jdeanwallace Jun 1, 2023
3564a54
Remove unnecessary mkdir.
jdeanwallace Jun 1, 2023
e7279f0
Always clear Ansible roles.
jdeanwallace Jun 1, 2023
67d2fee
Fix quote style.
jdeanwallace Jun 1, 2023
e968c19
Move clean up to dh_auto_clean.
jdeanwallace Jun 1, 2023
7361a2f
Merge branch 'master' into dh-venv
jdeanwallace Jun 1, 2023
79fe3e6
Revert "Move clean up to dh_auto_clean."
jdeanwallace Jun 1, 2023
e84daf3
Set bash options.
jdeanwallace Jun 2, 2023
5616c26
Add comment explaining Debian package paths.
jdeanwallace Jun 2, 2023
4ebe94a
Expand comment.
jdeanwallace Jun 2, 2023
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
57 changes: 47 additions & 10 deletions .circleci/continue_config.yml
Original file line number Diff line number Diff line change
Expand Up @@ -84,12 +84,40 @@ jobs:
- checkout
- setup_remote_docker:
version: 20.10.11
docker_layer_caching: true
- run:
name: Enable multiarch builds with QEMU
command: ./dev-scripts/enable-multiarch-docker
- run:
name: Build Debian package
command: ./dev-scripts/build-debian-pkg
# Building ARMv7 binaries is slow, so we only build them on the master
# branch.
command: |
set -exu
if [[ "${CIRCLE_BRANCH}" == 'master' ]]; then
readonly BUILD_TARGETS='linux/arm/v7,linux/amd64'
else
readonly BUILD_TARGETS='linux/amd64'
fi
./dev-scripts/build-debian-pkg "${BUILD_TARGETS}"
- run:
name: Move Debian packages to a predictable location
# Building for multiple architectures at once, changes the path of the
# resulting Debian package. For example:
# - Building for both AMD64 and ARMv7, produces files in:
# - `releases/linux_arm_v7/*.deb`
# - `releases/linux_amd64/*.deb`
# - Building for only AMD64, produces files in:
# - `releases/*.deb`
# For consistency, we move all packages to `releases/*.deb`.
command: find . -name '*.deb' -exec mv {} ./debian-pkg/releases/ \;
- run:
name: Print Debian package contents
command: dpkg --contents debian-pkg/releases/tinypilot*.deb
command: |
set -exu
while read -r file; do
dpkg --contents "${file}"
done < <(ls ./debian-pkg/releases/*.deb)
- persist_to_workspace:
root: ./debian-pkg/releases
paths:
Expand All @@ -113,13 +141,16 @@ jobs:
- run:
name: Run lintian
command: |
lintian \
--check \
--no-tag-display-limit \
--suppress-tags-from-file .lintianignore \
--no-cfg \
--fail-on warning,error \
tinypilot*.deb
set -exu
while read -r file; do
lintian \
--check \
--no-tag-display-limit \
--suppress-tags-from-file .lintianignore \
--no-cfg \
--fail-on warning,error \
"${file}"
done < <(ls *.deb)
build_ansible_role:
machine:
image: ubuntu-2004:202010-01
Expand All @@ -142,7 +173,7 @@ jobs:
- run:
name: Add TinyPilot Debian package name as an environment variable
command: |
TINYPILOT_DEBIAN_PACKAGE="$(ls ./debian-pkgs/tinypilot*.deb | xargs basename)"
TINYPILOT_DEBIAN_PACKAGE="$(ls ./debian-pkgs/tinypilot*amd64.deb | xargs basename)"
echo "export TINYPILOT_DEBIAN_PACKAGE="${TINYPILOT_DEBIAN_PACKAGE}"" >> "${BASH_ENV}"
- run:
name: Create virtual environment
Expand Down Expand Up @@ -258,6 +289,12 @@ workflows:
- build_bundle:
requires:
- build_debian_package
# Creating the bundle assumes an ARMv7 build, so we only do this on
# master, because it's slow building the ARMv7 binaries from a
# CircleCI AMD64 instance.
filters:
branches:
only: master
- verify_bundle:
requires:
- build_bundle
Expand Down
3 changes: 3 additions & 0 deletions .lintianignore
Original file line number Diff line number Diff line change
@@ -1,3 +1,6 @@
# These are rules for Lintian to ignore globally. For more targeted rules, see
# debian-pkg/debian/tinypilot.lintian-overrides.

# Debian doesn't want packages to install to /opt, but it also doesn't give
# clear guidance on where they *should* go. It's too much churn at this point to
# change, so we're going to ignore this.
Expand Down
3 changes: 2 additions & 1 deletion CONTRIBUTING.md
Original file line number Diff line number Diff line change
Expand Up @@ -22,7 +22,8 @@ python3 -m venv venv && \
. venv/bin/activate && \
pip install --requirement requirements.txt && \
pip install --requirement dev_requirements.txt && \
npm install
npm install && \
./dev-scripts/enable-multiarch-docker
```

### Run automated tests
Expand Down
1 change: 0 additions & 1 deletion ansible-role/defaults/main.yml
Original file line number Diff line number Diff line change
Expand Up @@ -12,5 +12,4 @@ tinypilot_port: 8000
tinypilot_keyboard_interface: /dev/hidg0
tinypilot_mouse_interface: /dev/hidg1
tinypilot_enable_debug_logging: no
tinypilot_pip_args: ""
tinypilot_app_settings_file: "/home/{{ tinypilot_user }}/app_settings.cfg"
18 changes: 0 additions & 18 deletions ansible-role/tasks/main.yml
Original file line number Diff line number Diff line change
Expand Up @@ -8,24 +8,6 @@
apt:
deb: "{{ tinypilot_debian_package_path }}"

- name: find absolute path to python3
shell: realpath $(which python3)
register: realpath_python3
changed_when: false

- name: save absolute path to python3
set_fact:
python3_abs_path: "{{ realpath_python3.stdout }}"

- name: create TinyPilot virtualenv
pip:
virtualenv: "{{ tinypilot_dir }}/venv"
virtualenv_command: "{{ python3_abs_path }} -m venv venv"
requirements: "{{ tinypilot_dir }}/requirements.txt"
extra_args: "{{ tinypilot_pip_args }}"
notify:
- restart TinyPilot service

- name: create TinyPilot app settings
template:
src: tinypilot-app-settings.cfg.j2
Expand Down
16 changes: 12 additions & 4 deletions bundler/create-bundle
Original file line number Diff line number Diff line change
Expand Up @@ -27,8 +27,11 @@ readonly OUTPUT_DIR='dist'
readonly ANSIBLE_ROLES_DIR="${BUNDLE_DIR}/roles"
readonly ANSIBLE_ROLE_TINYPILOT_DIR="${ANSIBLE_ROLES_DIR}/ansible-role-tinypilot"

# Exclude the AMD64 package from the production bundle.
rm -f "${BUNDLE_DIR}/tinypilot"*amd64.deb

# Ensure that a TinyPilot Debian package exists.
if ! ls "${BUNDLE_DIR}/tinypilot"*.deb 1> /dev/null 2>&1; then
if ! ls "${BUNDLE_DIR}/tinypilot"*armhf.deb 1> /dev/null 2>&1; then
echo 'Failed to create bundle: no TinyPilot Debian package found.' >&2
exit 1
fi
Expand All @@ -44,7 +47,7 @@ print_tinypilot_version() {
dpkg-deb \
--show \
--showformat '${Tinypilot-Version}' \
"${BUNDLE_DIR}/tinypilot"*.deb
"${BUNDLE_DIR}/tinypilot"*armhf.deb
}

# Compose bundle file name, which consists of these hyphen-separated parts:
Expand All @@ -69,9 +72,14 @@ python3 -m venv venv
pip install "pip>=21.3.1"
pip install --requirement "${BUNDLE_DIR}/requirements.txt"

# Copy Ansible role.
# Clear Ansible roles from any previous bundle builds.
rm -rf "${ANSIBLE_ROLES_DIR}"
mkdir "${ANSIBLE_ROLES_DIR}"
cp -r ../ansible-role "${ANSIBLE_ROLE_TINYPILOT_DIR}"

# Copy Ansible role.
cp -r \
--no-target-directory \
../ansible-role "${ANSIBLE_ROLE_TINYPILOT_DIR}"

# Download Ansible role dependencies.
ansible-galaxy install \
Expand Down
2 changes: 1 addition & 1 deletion bundler/verify-bundle
Original file line number Diff line number Diff line change
Expand Up @@ -42,7 +42,7 @@ if [[ ! -f install ]]; then
fi

# List Debian package contents.
dpkg --contents tinypilot*.deb
dpkg --contents tinypilot*armhf.deb

# Check that Ansible roles exist.
readonly ANSIBLE_ROLES=(
Expand Down
65 changes: 50 additions & 15 deletions debian-pkg/Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -4,12 +4,17 @@

FROM debian:bullseye-20220328-slim AS build

RUN set -x && \
RUN set -exu && \
apt-get update && \
DEBIAN_FRONTEND=noninteractive apt-get install -y \
debhelper \
dh-virtualenv \
dpkg-dev

# Docker populates this value from the --platform argument. See
# https://docs.docker.com/build/building/multi-platform/
ARG TARGETPLATFORM

# The canonical, SemVer-compliant TinyPilot version.
ARG TINYPILOT_VERSION

Expand All @@ -20,14 +25,34 @@ ARG TINYPILOT_VERSION
# recently built TinyPilot package.
ARG PKG_VERSION

ARG PKG_NAME="tinypilot"
ARG PKG_BUILD_NUMBER="1"
ARG PKG_ARCH="all"
ARG PKG_ID="${PKG_NAME}-${PKG_VERSION}-${PKG_BUILD_NUMBER}-${PKG_ARCH}"

RUN mkdir -p "/releases/${PKG_ID}"
ARG PKG_NAME='tinypilot'
ARG PKG_BUILD_NUMBER='1'

# Docker's platform names don't match Debian's platform names, so we translate
# the platform name from the Docker version to the Debian version and save the
# result to a file so we can re-use it in later stages.
RUN cat | bash <<'EOF'
set -exu
case "${TARGETPLATFORM}" in
'linux/amd64')
PKG_ARCH='amd64'
;;
'linux/arm/v7')
PKG_ARCH='armhf'
;;
*)
echo "Unrecognized target platform: ${TARGETPLATFORM}" >&2
exit 1
esac
echo "${PKG_ARCH}" > /tmp/pkg-arch
echo "${PKG_NAME}-${PKG_VERSION}-${PKG_BUILD_NUMBER}-${PKG_ARCH}" > /tmp/pkg-id
EOF

WORKDIR "/releases/${PKG_ID}"
# We ultimately need the directory name to be the package ID, but there's no
# way to specify a dynamic value in Docker's WORKDIR command, so we use a
# placeholder directory name to assemble the Debian package and then rename the
# directory to its package ID name in the final stages of packaging.
WORKDIR /releases/placeholder-pkg-id

COPY ./debian-pkg ./
COPY ./COPYRIGHT ./
Expand All @@ -39,9 +64,11 @@ COPY ./scripts ./scripts

RUN echo "${TINYPILOT_VERSION}" > VERSION

WORKDIR "/releases/${PKG_ID}/debian"
WORKDIR /releases/placeholder-pkg-id/debian

RUN cat >control <<EOF
RUN set -exu && \
PKG_ARCH="$(cat /tmp/pkg-arch)" && \
cat >control <<EOF
Source: ${PKG_NAME}
Section: net
Priority: optional
Expand All @@ -50,23 +77,31 @@ Build-Depends: debhelper (>= 11)

Package: ${PKG_NAME}
Architecture: ${PKG_ARCH}
Depends: adduser, python3, python3-pip, python3-venv, sudo
Depends: \${shlibs:Depends}, adduser, python3, python3-pip, python3-venv, sudo
Homepage: https://tinypilotkvm.com
Description: Simple, easy-to-use KVM over IP
XBS-Tinypilot-Version: ${TINYPILOT_VERSION}
EOF

RUN cat >changelog <<EOF
RUN set -exu && \
cat >changelog <<EOF
tinypilot (${PKG_VERSION}) bullseye; urgency=medium

* Latest TinyPilot release.

-- TinyPilot Support <support@tinypilotkvm.com> $(date '+%a, %d %b %Y %H:%M:%S %z')
EOF

WORKDIR "/releases/${PKG_ID}"
RUN dpkg-buildpackage --build=binary
# Rename the placeholder release directory to the final package ID.
WORKDIR /releases
RUN cat | bash <<'EOF'
set -exu
PKG_ID="$(cat /tmp/pkg-id)"
mv placeholder-pkg-id "${PKG_ID}"
cd "${PKG_ID}"
dpkg-buildpackage --build=binary
EOF

FROM scratch as artifact

COPY --from=build "/releases/*.deb" ./
COPY --from=build /releases/*.deb ./
21 changes: 20 additions & 1 deletion debian-pkg/debian/rules
Original file line number Diff line number Diff line change
@@ -1,8 +1,27 @@
#!/usr/bin/make -f

# Enable hardening build flags.
export DEB_BUILD_MAINT_OPTIONS = hardening=+all
DPKG_EXPORT_BUILDFLAGS = 1
include /usr/share/dpkg/buildflags.mk

export DH_VIRTUALENV_INSTALL_ROOT=/opt/tinypilot
# Prevent debhelper from generating an extra package with debug symbols.
export DEB_BUILD_OPTIONS=noddebs

%:
dh $@
dh $@ --with python-virtualenv

override_dh_installsystemd:
dh_installsystemd --name=tinypilot-updater --no-start --no-enable
dh_installsystemd --name=usb-gadget --no-start

override_dh_virtualenv:
# Skip install because TinyPilot doesn't need to run setup.py to install.
# Use the venv directory because that's where we've historically kept it.
dh_virtualenv --skip-install --install-suffix venv
# dh_virtualenv doesn't remove __pycache__ directories, so we clean them up
# manually.
find . -type d -name __pycache__ -prune -exec rm -rf {} \;
# Lintian will complain if the .gitignore stays in venv.
rm ./debian/tinypilot$(DH_VIRTUALENV_INSTALL_ROOT)/venv/.gitignore
17 changes: 17 additions & 0 deletions debian-pkg/debian/tinypilot.lintian-overrides
Original file line number Diff line number Diff line change
@@ -0,0 +1,17 @@
# Suppress complaints about third-party dependencies we don't control.
tinypilot: embedded-javascript-library opt/tinypilot/venv/lib/python*/site-packages/werkzeug/debug/shared/jquery.js please use libjs-jquery
tinypilot: script-not-executable [opt/tinypilot/venv/lib/python*/site-packages/greenlet/tests/test_version.py]
tinypilot: script-not-executable [opt/tinypilot/venv/lib/python*/site-packages/pkg_resources/_vendor/appdirs.py]
tinypilot: script-not-executable [opt/tinypilot/venv/lib/python*/site-packages/setuptools/command/easy_install.py]
tinypilot: embedded-library libyaml opt/tinypilot/venv/lib/python*/site-packages/yaml/*.so
tinypilot: hardening-no-relro [opt/tinypilot/venv/lib/python*/site-packages/yaml/*.so]

# Lintian doesn't recognize the Python interpreter when it's within the
# virtualenv.
tinypilot: unusual-interpreter /opt/tinypilot/venv/bin/python [opt/tinypilot/venv/bin/easy_install*]
tinypilot: unusual-interpreter /opt/tinypilot/venv/bin/python [opt/tinypilot/venv/bin/flask]
tinypilot: unusual-interpreter /opt/tinypilot/venv/bin/python [opt/tinypilot/venv/bin/pip*]
tinypilot: unusual-interpreter /opt/tinypilot/venv/bin/python [opt/tinypilot/venv/bin/wheel*]
tinypilot: unusual-interpreter python [opt/tinypilot/venv/lib/python*/site-packages/greenlet/tests/test_version.py]
tinypilot: unusual-interpreter python [opt/tinypilot/venv/lib/python*/site-packages/pkg_resources/_vendor/appdirs.py]
tinypilot: unusual-interpreter python [opt/tinypilot/venv/lib/python*/site-packages/setuptools/command/easy_install.py]
9 changes: 9 additions & 0 deletions debian-pkg/debian/tinypilot.triggers
Original file line number Diff line number Diff line change
@@ -0,0 +1,9 @@
# These triggers are based on guidance from the dh-virtualenv documentation.
# https://dh-virtualenv.readthedocs.io/en/1.2.1/tutorial.html#step-2-set-up-packaging-for-your-project

# Register interest in Python interpreter changes and don't make the Python
# package dependent on the virtualenv package processing (noawait).
interest-noawait /usr/bin/python3

# Also provide a symbolic trigger for all dh-virtualenv packages.
interest-await dh-virtualenv-interpreter-update
21 changes: 19 additions & 2 deletions dev-scripts/build-debian-pkg
Original file line number Diff line number Diff line change
@@ -1,6 +1,20 @@
#!/bin/bash

# Exit on first failure.
# Build TinyPilot Debian packages.
#
# Usage:
# build-debian-pkg [target architectures]
#
# target architecture: A comma-separated list of architectures that Docker
# accepts for its --platform argument. If omitted, defaults to
# "linux/arm/v7,linux/amd64". The only supported targets are linux/arm/v7 and
# linux/amd64.
#
# Examples
# build-debian-pkg "linux/arm/v7"
# build-debian-pkg "linux/arm/v7,linux/amd64"

# Exit build script on first failure.
set -e

# Echo commands before executing them, by default to stderr.
Expand All @@ -9,6 +23,8 @@ set -x
# Exit on unset variable.
set -u

BUILD_TARGETS="${1:-linux/arm/v7,linux/amd64}"

print_tinypilot_version() {
# Format build hash suffix according to SemVer (`-ghhhhhhh` -> `+hhhhhhh`).
git describe --tags --long |
Expand All @@ -28,8 +44,9 @@ if [[ -n "${CI:-}" ]]; then
fi
readonly DOCKER_PROGRESS

DOCKER_BUILDKIT=1 docker build \
DOCKER_BUILDKIT=1 docker buildx build \
--file debian-pkg/Dockerfile \
--platform "${BUILD_TARGETS}" \
--build-arg TINYPILOT_VERSION="${TINYPILOT_VERSION}" \
--build-arg PKG_VERSION="${PKG_VERSION}" \
--target=artifact \
Expand Down
Loading