From 7cc17b6d848ef2e32e3292955517c198687b2376 Mon Sep 17 00:00:00 2001 From: Jon Staab Date: Fri, 25 Sep 2026 10:20:16 -0700 Subject: [PATCH] Install Node from a tar.gz in the F-Droid recipe, since the buildserver has no xz --- fdroid/README.md | 4 ++-- fdroid/metadata/social.flotilla.fdroid.yml | 15 +++++++-------- 2 files changed, 9 insertions(+), 10 deletions(-) diff --git a/fdroid/README.md b/fdroid/README.md index 0165b396..6e08eeb1 100644 --- a/fdroid/README.md +++ b/fdroid/README.md @@ -45,8 +45,8 @@ and use its configured Gradle runner for `assembleFdroidRelease`. to `fdroiddata`. The listing's text, icon, feature graphic and per-version changelogs come from `fastlane/metadata/android/en-US/` at the tag F-Droid builds. Preparation installs dependencies before F-Droid's source scan, so the recipe scan-ignores `node_modules`, which holds FLOSS build -tools such as esbuild and sharp. The build server's JDK is older than the 21 Capacitor needs, so -the recipe installs it from Debian trixie, along with Node from nodejs.org at a pinned checksum. +tools such as esbuild and sharp. The recipe installs JDK 21, which Capacitor needs, and Node from +nodejs.org at a pinned checksum, as a `.tar.gz` since the build server has no `xz`. ## Reproducible builds diff --git a/fdroid/metadata/social.flotilla.fdroid.yml b/fdroid/metadata/social.flotilla.fdroid.yml index 0a560020..730e5676 100644 --- a/fdroid/metadata/social.flotilla.fdroid.yml +++ b/fdroid/metadata/social.flotilla.fdroid.yml @@ -20,15 +20,14 @@ Builds: commit: 95cbb9b6f736df21199185ac4c8dc5c841e2c1b1 subdir: android/app sudo: - - echo "deb https://deb.debian.org/debian trixie main" > /etc/apt/sources.list.d/trixie.list - apt-get update - - apt-get install -y -t trixie openjdk-21-jdk-headless + - apt-get install -y openjdk-21-jdk-headless - update-alternatives --auto java - - curl -Lo node.tar.xz https://nodejs.org/dist/v22.23.3/node-v22.23.3-linux-x64.tar.xz - - echo "df450af89261115ef9f9e3830c3eeb2cc9213b63c720b1af623cb5dcbe2e02de node.tar.xz" + - curl -Lo node.tar.gz https://nodejs.org/dist/v22.23.3/node-v22.23.3-linux-x64.tar.gz + - echo "1084aa36196bba4c3a5e69a1ee388a6e4ff729dad09445fbcd434b28fe3c24af node.tar.gz" | sha256sum -c - - - tar xJf node.tar.xz --strip-components=1 -C /usr/local/ - - rm node.tar.xz + - tar xzf node.tar.gz --strip-components=1 -C /usr/local/ + - rm node.tar.gz - corepack enable gradle: - fdroid @@ -43,8 +42,8 @@ MaintainerNotes: |- scripts/fdroid/prepare.sh removes Firebase, Google Services, Plausible and the ACINQ native secp256k1 library, then installs dependencies, so it runs as prebuild ahead of the scanner. node_modules holds FLOSS build tools (esbuild, sharp), hence scanignore. - Capacitor needs JDK 21, installed from trixie, and Node comes from nodejs.org at a - pinned checksum to match the lts/jod in .nvmrc. + Capacitor needs JDK 21, and Node comes from nodejs.org at a pinned checksum to match + the lts/jod in .nvmrc. Builds are reproducible: upstream's release workflow runs this recipe in the buildserver-trixie image (scripts/fdroid/reproduce.sh) and publishes that apk, signed