Added linting and package resolution Gitea Actions workflows.
Audit / Package Resolution (push) Successful in 1m6s
CI / Linting (push) Successful in 4s

This commit is contained in:
2026-04-29 16:03:33 -04:00
parent c868ec5107
commit 6441b0114d
14 changed files with 156 additions and 44 deletions
+30
View File
@@ -0,0 +1,30 @@
name: Audit
on:
schedule:
- cron: "0 0 * * 1"
push:
paths:
- config/*.conf
- scripts/check-package-resolution.sh
pull_request:
paths:
- config/*.conf
- scripts/check-package-resolution.sh
permissions:
contents: read
jobs:
package-resolution:
name: Package Resolution
runs-on: logaldeveloper-archlinux
steps:
- name: Checkout repository
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
- name: Refresh pacman databases
run: pacman -Sy --noconfirm
- name: Check package resolution in pacman
run: bash ./scripts/check-package-resolution.sh
+19
View File
@@ -0,0 +1,19 @@
name: CI
on:
push:
pull_request:
permissions:
contents: read
jobs:
linting:
name: Linting
runs-on: logaldeveloper-archlinux
steps:
- name: Checkout repository
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
- name: Check linting with ShellCheck
run: git ls-files -z '*.sh' | xargs -0 -r shellcheck --external-sources
+1
View File
@@ -0,0 +1 @@
disable=SC2034
+14
View File
@@ -60,3 +60,17 @@ BASE_PACKAGES=(
fwupd fwupd
udisks2 udisks2
) )
# CPU microcode packages
INTEL_MICROCODE_PACKAGES=(
intel-ucode
)
AMD_MICROCODE_PACKAGES=(
amd-ucode
)
# Optional Wi-Fi packages
WIFI_PACKAGES=(
iwd
)
+10 -8
View File
@@ -28,9 +28,6 @@ readonly COLOR_CYAN='\033[0;36m'
readonly COLOR_BG_GRAY='\033[48;5;236m' readonly COLOR_BG_GRAY='\033[48;5;236m'
readonly COLOR_RESET='\033[0m' readonly COLOR_RESET='\033[0m'
# Current installation phase (set by set_phase)
CURRENT_PHASE=""
# Step counter for progress indicator # Step counter for progress indicator
CURRENT_STEP=0 CURRENT_STEP=0
TOTAL_STEPS=10 TOTAL_STEPS=10
@@ -117,7 +114,6 @@ run_visible_cmd_in_chroot() {
print_step() { print_step() {
local step="$1" local step="$1"
CURRENT_STEP=$((CURRENT_STEP + 1)) CURRENT_STEP=$((CURRENT_STEP + 1))
CURRENT_PHASE="$step"
echo "" echo ""
echo -e "${COLOR_BLUE}=== [${CURRENT_STEP}/${TOTAL_STEPS}] ${step} ===${COLOR_RESET}" echo -e "${COLOR_BLUE}=== [${CURRENT_STEP}/${TOTAL_STEPS}] ${step} ===${COLOR_RESET}"
} }
@@ -243,11 +239,16 @@ prompt_password() {
# Arguments: # Arguments:
# $1 - menu title # $1 - menu title
# $@ - menu options (remaining arguments) # $@ - menu options (remaining arguments)
# Arguments:
# $1 - variable name to store the selected option number
# $2 - menu title
# Returns: # Returns:
# Selected option number in MENU_SELECTION variable # Selected option number in the provided variable
prompt_menu() { prompt_menu() {
local title="$1" local var_name="$1"
shift local title="$2"
local selection
shift 2
local options=("$@") local options=("$@")
local i=1 local i=1
@@ -257,7 +258,8 @@ prompt_menu() {
((i++)) ((i++))
done done
read -r MENU_SELECTION read -r selection
printf -v "$var_name" '%s' "$selection"
} }
# Wait for user to press enter # Wait for user to press enter
+1 -1
View File
@@ -111,7 +111,7 @@ retry() {
log_cmd "$@" log_cmd "$@"
local attempt=1 local attempt=1
while [ $attempt -le $max_attempts ]; do while [ "$attempt" -le "$max_attempts" ]; do
if "$@"; then if "$@"; then
return 0 return 0
fi fi
+4 -2
View File
@@ -21,9 +21,11 @@
# Prompt user for graphics driver selection and install # Prompt user for graphics driver selection and install
prompt_install_graphics() { prompt_install_graphics() {
prompt_menu "Would you like to install graphics drivers?" "Intel" "NVIDIA" "Skip" local selection
case "$MENU_SELECTION" in prompt_menu selection "Would you like to install graphics drivers?" "Intel" "NVIDIA" "Skip"
case "$selection" in
1) 1)
print "Installing Intel graphics drivers..." print "Installing Intel graphics drivers..."
chroot_pacman_install "${INTEL_PACKAGES[@]}" chroot_pacman_install "${INTEL_PACKAGES[@]}"
+1
View File
@@ -167,6 +167,7 @@ format_and_mount_filesystems() {
local storage_mode="$2" local storage_mode="$2"
# Format EFI partition(s) # Format EFI partition(s)
# shellcheck disable=SC2153
format_efi_partition "$EFI_PARTITION" format_efi_partition "$EFI_PARTITION"
if [ "$storage_mode" = "raid1" ]; then if [ "$storage_mode" = "raid1" ]; then
format_efi_partition "$EFI_PARTITION_2" format_efi_partition "$EFI_PARTITION_2"
+2 -2
View File
@@ -76,10 +76,10 @@ install_microcode() {
case "$vendor" in case "$vendor" in
"intel") "intel")
chroot_pacman_install intel-ucode chroot_pacman_install "${INTEL_MICROCODE_PACKAGES[@]}"
;; ;;
"amd") "amd")
chroot_pacman_install amd-ucode chroot_pacman_install "${AMD_MICROCODE_PACKAGES[@]}"
;; ;;
*) *)
print_warning "Unknown CPU vendor: ${vendor}. Please install microcode manually after installation, if available." print_warning "Unknown CPU vendor: ${vendor}. Please install microcode manually after installation, if available."
+2
View File
@@ -83,8 +83,10 @@ create_boot_entry() {
local storage_mode="$1" local storage_mode="$1"
if [ "$storage_mode" = "raid1" ]; then if [ "$storage_mode" = "raid1" ]; then
# shellcheck disable=SC2153
create_boot_entry_raid1 "$LUKS_UUID" "$LUKS_UUID_2" create_boot_entry_raid1 "$LUKS_UUID" "$LUKS_UUID_2"
elif [ "$storage_mode" = "raid1-3disk" ]; then elif [ "$storage_mode" = "raid1-3disk" ]; then
# shellcheck disable=SC2153
create_boot_entry_raid1_3disk "$LUKS_UUID" "$LUKS_UUID_2" "$LUKS_UUID_3" create_boot_entry_raid1_3disk "$LUKS_UUID" "$LUKS_UUID_2" "$LUKS_UUID_3"
else else
create_boot_entry_single "$LUKS_UUID" create_boot_entry_single "$LUKS_UUID"
+1 -1
View File
@@ -65,7 +65,7 @@ enable_resolved() {
prompt_install_wifi() { prompt_install_wifi() {
if confirm "Would you like to install iwd for Wi-Fi support?"; then if confirm "Would you like to install iwd for Wi-Fi support?"; then
print "Installing iwd..." print "Installing iwd..."
chroot_pacman_install iwd chroot_pacman_install "${WIFI_PACKAGES[@]}"
chroot_systemd_enable iwd.service chroot_systemd_enable iwd.service
fi fi
} }
+7 -30
View File
@@ -44,28 +44,6 @@ list_profiles() {
done done
} }
# Get packages for a profile
# Arguments:
# $1 - profile key
# Outputs:
# Package list to stdout
get_profile_packages() {
local profile_key="$1"
local pkg_var="PROFILE_${profile_key}_PACKAGES[@]"
echo "${!pkg_var}"
}
# Get services for a profile
# Arguments:
# $1 - profile key
# Outputs:
# Service list to stdout
get_profile_services() {
local profile_key="$1"
local svc_var="PROFILE_${profile_key}_SERVICES[@]"
echo "${!svc_var}"
}
# Check if profile requires KDE # Check if profile requires KDE
# Arguments: # Arguments:
# $1 - profile key # $1 - profile key
@@ -95,8 +73,10 @@ validate_profile_selection() {
install_profile() { install_profile() {
local profile_key="$1" local profile_key="$1"
local username="$2" local username="$2"
local packages local pkg_var="PROFILE_${profile_key}_PACKAGES[@]"
local services local svc_var="PROFILE_${profile_key}_SERVICES[@]"
local packages=("${!pkg_var}")
local services=("${!svc_var}")
# Install KDE if required # Install KDE if required
if profile_requires_kde "$profile_key"; then if profile_requires_kde "$profile_key"; then
@@ -105,10 +85,8 @@ install_profile() {
fi fi
# Get and install profile packages # Get and install profile packages
packages=$(get_profile_packages "$profile_key") if [ "${#packages[@]}" -gt 0 ]; then
if [ -n "$packages" ]; then chroot_pacman_install "${packages[@]}"
# shellcheck disable=SC2086
chroot_pacman_install $packages
fi fi
# Add user to wireshark group if wireshark was installed # Add user to wireshark group if wireshark was installed
@@ -117,8 +95,7 @@ install_profile() {
fi fi
# Enable profile services # Enable profile services
services=$(get_profile_services "$profile_key") for service in "${services[@]}"; do
for service in $services; do
chroot_systemd_enable "$service" chroot_systemd_enable "$service"
done done
} }
+2
View File
@@ -25,6 +25,7 @@ prompt_username() {
while true; do while true; do
prompt "Please enter the username you'd like to use for your account:" USERNAME prompt "Please enter the username you'd like to use for your account:" USERNAME
# shellcheck disable=SC2153
if validate_username "$USERNAME"; then if validate_username "$USERNAME"; then
return 0 return 0
fi fi
@@ -85,6 +86,7 @@ set_user_password() {
setup_user() { setup_user() {
prompt_username prompt_username
prompt_display_name prompt_display_name
# shellcheck disable=SC2153
create_user "$USERNAME" "$DISPLAY_NAME" create_user "$USERNAME" "$DISPLAY_NAME"
set_user_password "$USERNAME" set_user_password "$USERNAME"
} }
+62
View File
@@ -0,0 +1,62 @@
#!/bin/bash
set -euo pipefail
SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)"
source "${SCRIPT_DIR}/config/defaults.conf"
source "${SCRIPT_DIR}/config/luks.conf"
source "${SCRIPT_DIR}/config/drivers.conf"
source "${SCRIPT_DIR}/config/profiles.conf"
declare -A seen=()
unique_packages=()
package_array_count=0
add_packages() {
local package
package_array_count=$((package_array_count + 1))
for package in "$@"; do
if [[ -n "$package" && -z "${seen[$package]:-}" ]]; then
seen["$package"]=1
unique_packages+=("$package")
fi
done
}
add_packages "${BASE_PACKAGES[@]}"
add_packages "${INTEL_MICROCODE_PACKAGES[@]}"
add_packages "${AMD_MICROCODE_PACKAGES[@]}"
add_packages "${WIFI_PACKAGES[@]}"
add_packages "${INTEL_PACKAGES[@]}"
add_packages "${NVIDIA_PACKAGES[@]}"
add_packages "${KDE_PACKAGES[@]}"
for profile_key in "${PROFILES[@]}"; do
package_var="PROFILE_${profile_key}_PACKAGES[@]"
add_packages "${!package_var}"
done
if [[ "${#unique_packages[@]}" -eq 0 ]]; then
printf 'No package definitions were found in the sourced config files\n' >&2
exit 1
fi
missing_packages=()
for package in "${unique_packages[@]}"; do
if ! pacman -Si -- "$package" > /dev/null 2>&1; then
missing_packages+=("$package")
fi
done
if [[ "${#missing_packages[@]}" -gt 0 ]]; then
printf 'The following packages were not found by exact name:\n' >&2
printf ' %s\n' "${missing_packages[@]}" >&2
exit 1
fi
printf 'Checking dependency resolution for %d packages from %d package arrays\n' "${#unique_packages[@]}" "$package_array_count"
pacman -Sp --noconfirm -- "${unique_packages[@]}" > /dev/null