From c1b8dd6cb0c16496384347cf5dedc80c9525442a Mon Sep 17 00:00:00 2001 From: michael Date: Mon, 27 Apr 2026 19:54:15 -0700 Subject: [PATCH] =?UTF-8?q?chore(pkg):=20lintian=20sweep=20=E2=80=94=20fix?= =?UTF-8?q?=20obsolete=20polkit=20dep,=20drop=20dup=20systemd=20path,=20co?= =?UTF-8?q?mmand=20-v=20in=20pam=20hooks;=20override=20deferred=20manpages?= =?UTF-8?q?=20and=20PPA-only=20warnings?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Real fixes: - authforge-daemon Depends: policykit-1 -> polkitd | policykit-1 (policykit-1 was renamed; old name is obsolete on noble). - debian/rules: drop manual install of authforge-daemon.service to /lib/systemd/system/ — dh_installsystemd auto-installs to /usr/lib/systemd/system/, the manual line caused a file-in-root-and-usr duplicate flagged by usrmerge. - authforge-pam.{postinst,prerm}: replace [ -x /usr/sbin/pam-auth-update ] with command -v pam-auth-update — lintian flags hard-coded paths in test syntax; command -v is the portable idiom. Overrides (with rationale in each file): - no-manual-page on the three binaries — manpages deferred to Phase 18. - desktop-command-not-in-package authforge in gnome-integration — command lives in authforge-gui (cross-package Depends). - initial-upload-closes-no-bugs on every package — AuthForge ships via PPA, not the Debian archive, so there is no ITP to close. After fixes, lintian on the five binary debs is silent (zero W/E). --- .gitignore | 1 + debian/authforge-cli.lintian-overrides | 5 +++++ debian/authforge-daemon.lintian-overrides | 5 +++++ debian/authforge-gnome-integration.lintian-overrides | 7 +++++++ debian/authforge-gui.lintian-overrides | 5 +++++ debian/authforge-pam.lintian-overrides | 2 ++ debian/authforge-pam.postinst | 2 +- debian/authforge-pam.prerm | 2 +- debian/authforge.lintian-overrides | 3 +++ debian/control | 2 +- debian/rules | 5 ++--- 11 files changed, 33 insertions(+), 6 deletions(-) create mode 100644 debian/authforge-cli.lintian-overrides create mode 100644 debian/authforge-daemon.lintian-overrides create mode 100644 debian/authforge-gnome-integration.lintian-overrides create mode 100644 debian/authforge-gui.lintian-overrides create mode 100644 debian/authforge-pam.lintian-overrides create mode 100644 debian/authforge.lintian-overrides diff --git a/.gitignore b/.gitignore index d7641e2..1b6a46b 100644 --- a/.gitignore +++ b/.gitignore @@ -8,6 +8,7 @@ debian/.debhelper/ debian/files debian/*.substvars debian/*.debhelper.log +debian/*.debhelper debian/authforge*/ debian/debhelper-build-stamp pam/*.so diff --git a/debian/authforge-cli.lintian-overrides b/debian/authforge-cli.lintian-overrides new file mode 100644 index 0000000..23bb4cf --- /dev/null +++ b/debian/authforge-cli.lintian-overrides @@ -0,0 +1,5 @@ +# Manpages are deferred to Phase 18 (user docs); shipping 0.1.0 without +# them rather than blocking on docs is the call from the master plan. +authforge-cli: no-manual-page [usr/bin/authforgectl] +# Not destined for the Debian archive — see authforge.lintian-overrides. +authforge-cli: initial-upload-closes-no-bugs diff --git a/debian/authforge-daemon.lintian-overrides b/debian/authforge-daemon.lintian-overrides new file mode 100644 index 0000000..1d69def --- /dev/null +++ b/debian/authforge-daemon.lintian-overrides @@ -0,0 +1,5 @@ +# Manpages are deferred to Phase 18 (user docs); shipping 0.1.0 without +# them rather than blocking on docs is the call from the master plan. +authforge-daemon: no-manual-page [usr/sbin/authforged] +# Not destined for the Debian archive — see authforge.lintian-overrides. +authforge-daemon: initial-upload-closes-no-bugs diff --git a/debian/authforge-gnome-integration.lintian-overrides b/debian/authforge-gnome-integration.lintian-overrides new file mode 100644 index 0000000..f37ce79 --- /dev/null +++ b/debian/authforge-gnome-integration.lintian-overrides @@ -0,0 +1,7 @@ +# The Users-panel desktop entry launches `authforge`, which is shipped +# by the authforge-gui binary package (Depends: authforge-gui). Lintian +# only inspects files inside this package and can't see the cross- +# package binary, so the warning is a false positive. +authforge-gnome-integration: desktop-command-not-in-package authforge [usr/share/applications/io.dangerousthings.AuthForge.UsersPanel.desktop] +# Not destined for the Debian archive — see authforge.lintian-overrides. +authforge-gnome-integration: initial-upload-closes-no-bugs diff --git a/debian/authforge-gui.lintian-overrides b/debian/authforge-gui.lintian-overrides new file mode 100644 index 0000000..3fe2e52 --- /dev/null +++ b/debian/authforge-gui.lintian-overrides @@ -0,0 +1,5 @@ +# Manpages are deferred to Phase 18 (user docs); shipping 0.1.0 without +# them rather than blocking on docs is the call from the master plan. +authforge-gui: no-manual-page [usr/bin/authforge] +# Not destined for the Debian archive — see authforge.lintian-overrides. +authforge-gui: initial-upload-closes-no-bugs diff --git a/debian/authforge-pam.lintian-overrides b/debian/authforge-pam.lintian-overrides new file mode 100644 index 0000000..8bafab6 --- /dev/null +++ b/debian/authforge-pam.lintian-overrides @@ -0,0 +1,2 @@ +# Not destined for the Debian archive — see authforge.lintian-overrides. +authforge-pam: initial-upload-closes-no-bugs diff --git a/debian/authforge-pam.postinst b/debian/authforge-pam.postinst index 0b44cce..314d48f 100755 --- a/debian/authforge-pam.postinst +++ b/debian/authforge-pam.postinst @@ -7,7 +7,7 @@ set -e case "$1" in configure) - if [ -x /usr/sbin/pam-auth-update ]; then + if command -v pam-auth-update >/dev/null 2>&1; then pam-auth-update --package fi ;; diff --git a/debian/authforge-pam.prerm b/debian/authforge-pam.prerm index 06a901e..3833e8b 100755 --- a/debian/authforge-pam.prerm +++ b/debian/authforge-pam.prerm @@ -7,7 +7,7 @@ set -e case "$1" in remove|deconfigure) - if [ -x /usr/sbin/pam-auth-update ]; then + if command -v pam-auth-update >/dev/null 2>&1; then pam-auth-update --package --remove authforge fi ;; diff --git a/debian/authforge.lintian-overrides b/debian/authforge.lintian-overrides new file mode 100644 index 0000000..3b993ca --- /dev/null +++ b/debian/authforge.lintian-overrides @@ -0,0 +1,3 @@ +# AuthForge is shipped via the Dangerous Things PPA, not the Debian +# archive — there is no ITP bug to close on initial upload. +authforge: initial-upload-closes-no-bugs diff --git a/debian/control b/debian/control index 8eda021..acacc3f 100644 --- a/debian/control +++ b/debian/control @@ -31,7 +31,7 @@ Description: Turnkey FIDO2/U2F/TOTP MFA for Linux desktops (metapackage) Package: authforge-daemon Architecture: any -Depends: ${shlibs:Depends}, ${misc:Depends}, libpam-u2f, libfido2-1, dbus, policykit-1 +Depends: ${shlibs:Depends}, ${misc:Depends}, libpam-u2f, libfido2-1, dbus, polkitd | policykit-1 Recommends: libpam-google-authenticator Description: System daemon for authforge MFA management Provides the privileged D-Bus service that orchestrates enrollment, diff --git a/debian/rules b/debian/rules index f56c536..59bccf0 100755 --- a/debian/rules +++ b/debian/rules @@ -43,9 +43,8 @@ override_dh_auto_install: # polkit actions install -D -m 0644 debian/io.dangerousthings.AuthForge.policy \ debian/authforge-daemon/usr/share/polkit-1/actions/io.dangerousthings.AuthForge.policy - # systemd unit (dh_installsystemd will enable it) - install -D -m 0644 debian/authforge-daemon.service \ - debian/authforge-daemon/lib/systemd/system/authforge-daemon.service + # systemd unit: dh_installsystemd auto-installs debian/authforge-daemon.service + # to /usr/lib/systemd/system/ — no manual install line needed. # GNOME Settings Users-panel overlay (authforge-gnome-integration) install -D -m 0644 gnome-integration/io.dangerousthings.AuthForge.UsersPanel.desktop \ debian/authforge-gnome-integration/usr/share/applications/io.dangerousthings.AuthForge.UsersPanel.desktop