chore(pkg): lintian sweep — fix obsolete polkit dep, drop dup systemd path, command -v in pam hooks; override deferred manpages and PPA-only warnings

Real fixes:
- authforge-daemon Depends: policykit-1 -> polkitd | policykit-1
  (policykit-1 was renamed; old name is obsolete on noble).
- debian/rules: drop manual install of authforge-daemon.service to
  /lib/systemd/system/ — dh_installsystemd auto-installs to
  /usr/lib/systemd/system/, the manual line caused a file-in-root-and-usr
  duplicate flagged by usrmerge.
- authforge-pam.{postinst,prerm}: replace [ -x /usr/sbin/pam-auth-update ]
  with command -v pam-auth-update — lintian flags hard-coded paths in
  test syntax; command -v is the portable idiom.

Overrides (with rationale in each file):
- no-manual-page on the three binaries — manpages deferred to Phase 18.
- desktop-command-not-in-package authforge in gnome-integration —
  command lives in authforge-gui (cross-package Depends).
- initial-upload-closes-no-bugs on every package — AuthForge ships
  via PPA, not the Debian archive, so there is no ITP to close.

After fixes, lintian on the five binary debs is silent (zero W/E).
This commit is contained in:
michael
2026-04-27 19:54:15 -07:00
parent 0dc108220d
commit c1b8dd6cb0
11 changed files with 33 additions and 6 deletions

1
.gitignore vendored
View File

@@ -8,6 +8,7 @@ debian/.debhelper/
debian/files
debian/*.substvars
debian/*.debhelper.log
debian/*.debhelper
debian/authforge*/
debian/debhelper-build-stamp
pam/*.so

View File

@@ -0,0 +1,5 @@
# Manpages are deferred to Phase 18 (user docs); shipping 0.1.0 without
# them rather than blocking on docs is the call from the master plan.
authforge-cli: no-manual-page [usr/bin/authforgectl]
# Not destined for the Debian archive — see authforge.lintian-overrides.
authforge-cli: initial-upload-closes-no-bugs

View File

@@ -0,0 +1,5 @@
# Manpages are deferred to Phase 18 (user docs); shipping 0.1.0 without
# them rather than blocking on docs is the call from the master plan.
authforge-daemon: no-manual-page [usr/sbin/authforged]
# Not destined for the Debian archive — see authforge.lintian-overrides.
authforge-daemon: initial-upload-closes-no-bugs

View File

@@ -0,0 +1,7 @@
# The Users-panel desktop entry launches `authforge`, which is shipped
# by the authforge-gui binary package (Depends: authforge-gui). Lintian
# only inspects files inside this package and can't see the cross-
# package binary, so the warning is a false positive.
authforge-gnome-integration: desktop-command-not-in-package authforge [usr/share/applications/io.dangerousthings.AuthForge.UsersPanel.desktop]
# Not destined for the Debian archive — see authforge.lintian-overrides.
authforge-gnome-integration: initial-upload-closes-no-bugs

View File

@@ -0,0 +1,5 @@
# Manpages are deferred to Phase 18 (user docs); shipping 0.1.0 without
# them rather than blocking on docs is the call from the master plan.
authforge-gui: no-manual-page [usr/bin/authforge]
# Not destined for the Debian archive — see authforge.lintian-overrides.
authforge-gui: initial-upload-closes-no-bugs

View File

@@ -0,0 +1,2 @@
# Not destined for the Debian archive — see authforge.lintian-overrides.
authforge-pam: initial-upload-closes-no-bugs

View File

@@ -7,7 +7,7 @@ set -e
case "$1" in
configure)
if [ -x /usr/sbin/pam-auth-update ]; then
if command -v pam-auth-update >/dev/null 2>&1; then
pam-auth-update --package
fi
;;

View File

@@ -7,7 +7,7 @@ set -e
case "$1" in
remove|deconfigure)
if [ -x /usr/sbin/pam-auth-update ]; then
if command -v pam-auth-update >/dev/null 2>&1; then
pam-auth-update --package --remove authforge
fi
;;

3
debian/authforge.lintian-overrides vendored Normal file
View File

@@ -0,0 +1,3 @@
# AuthForge is shipped via the Dangerous Things PPA, not the Debian
# archive — there is no ITP bug to close on initial upload.
authforge: initial-upload-closes-no-bugs

2
debian/control vendored
View File

@@ -31,7 +31,7 @@ Description: Turnkey FIDO2/U2F/TOTP MFA for Linux desktops (metapackage)
Package: authforge-daemon
Architecture: any
Depends: ${shlibs:Depends}, ${misc:Depends}, libpam-u2f, libfido2-1, dbus, policykit-1
Depends: ${shlibs:Depends}, ${misc:Depends}, libpam-u2f, libfido2-1, dbus, polkitd | policykit-1
Recommends: libpam-google-authenticator
Description: System daemon for authforge MFA management
Provides the privileged D-Bus service that orchestrates enrollment,

5
debian/rules vendored
View File

@@ -43,9 +43,8 @@ override_dh_auto_install:
# polkit actions
install -D -m 0644 debian/io.dangerousthings.AuthForge.policy \
debian/authforge-daemon/usr/share/polkit-1/actions/io.dangerousthings.AuthForge.policy
# systemd unit (dh_installsystemd will enable it)
install -D -m 0644 debian/authforge-daemon.service \
debian/authforge-daemon/lib/systemd/system/authforge-daemon.service
# systemd unit: dh_installsystemd auto-installs debian/authforge-daemon.service
# to /usr/lib/systemd/system/ — no manual install line needed.
# GNOME Settings Users-panel overlay (authforge-gnome-integration)
install -D -m 0644 gnome-integration/io.dangerousthings.AuthForge.UsersPanel.desktop \
debian/authforge-gnome-integration/usr/share/applications/io.dangerousthings.AuthForge.UsersPanel.desktop