From bf4a2084615d484ef7edddbee4cccfcaf8b934e1 Mon Sep 17 00:00:00 2001 From: Rohit Kumar Date: Thu, 12 Mar 2026 09:24:01 +0530 Subject: [PATCH 1/9] ci: unify native and remote multi-architecture build pipelines --- .github/workflows/build.yml | 56 ++++++++++++++++++++----- snapcraft.yaml | 83 +++++-------------------------------- 2 files changed, 56 insertions(+), 83 deletions(-) diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml index 17643a5b..7bef1a57 100644 --- a/.github/workflows/build.yml +++ b/.github/workflows/build.yml @@ -1,4 +1,5 @@ -name: CUPS Snap CI - Native Build Pipeline +name: CUPS Snap CI - Unified Build Pipeline + on: push: branches: @@ -8,49 +9,47 @@ on: - master workflow_dispatch: - jobs: - build-snap: - name: Build CUPS Snap (${{ matrix.arch }}) + # Job 1: Native builds for amd64 and arm64 + build-native: + name: Build Native (${{ matrix.arch }}) runs-on: ${{ matrix.runs-on }} strategy: fail-fast: false matrix: include: - # x86_64 native build on standard Ubuntu runner - - arch: x86_64 + - arch: amd64 runs-on: ubuntu-latest - - # arm64 native build on ARM64-capable runner - arch: arm64 runs-on: ubuntu-24.04-arm steps: - name: Checkout cups-snap sources uses: actions/checkout@v4 + - name: Print Ubuntu version run: | set -e cat /etc/os-release | grep PRETTY_NAME | awk -F '=' '{print $2}' + - name: Build CUPS snap with Snapcraft action id: snapcraft uses: snapcore/action-build@v1 with: path: . + - name: Install built snap (smoke test setup) run: | set -e SNAP_FILE="${{ steps.snapcraft.outputs.snap }}" echo "Installing snap: ${SNAP_FILE}" sudo snap install --dangerous "${SNAP_FILE}" + - name: Run smoke tests run: | set -e - - # Verify snap is listed echo "Checking snap list..." snap list | grep "^cups " || (echo "CUPS snap not found in snap list"; exit 1) - # Test ghostscript binary with -h flag echo "Testing ghostscript binary..." snap run cups.gs -h || true @@ -65,4 +64,39 @@ jobs: with: name: cups-snap-${{ matrix.arch }} path: ./*.snap + if-no-files-found: error + + # Job 2: Remote build via Launchpad for armhf + build-remote: + name: Build Remote (armhf) + runs-on: ubuntu-latest + steps: + - name: Checkout cups-snap sources + uses: actions/checkout@v4 + with: + fetch-depth: 0 + + - name: Install Snapcraft + run: | + sudo snap install snapcraft --channel latest/stable --classic + + - name: Setup Launchpad credentials + env: + LP_CREDENTIALS: ${{ secrets.LP_CREDENTIALS }} + run: | + set -e + mkdir -p ~/.local/share/snapcraft/provider/launchpad ~/.local/share/snapcraft + echo "$LP_CREDENTIALS" > ~/.local/share/snapcraft/provider/launchpad/credentials + echo "$LP_CREDENTIALS" > ~/.local/share/snapcraft/launchpad-credentials + + - name: Remote build CUPS snap on Launchpad + run: | + set -e + snapcraft remote-build --launchpad-accept-public-upload --build-for=armhf + + - name: Upload CUPS snap artifact + uses: actions/upload-artifact@v4 + with: + name: cups-snap-armhf + path: ./*.snap if-no-files-found: error \ No newline at end of file diff --git a/snapcraft.yaml b/snapcraft.yaml index 3e8c08cd..f02df223 100644 --- a/snapcraft.yaml +++ b/snapcraft.yaml @@ -11,12 +11,16 @@ adopt-info: cups # `cups` interface in snapd assumes: [snapd2.55] -# Only build on the architectures supported +# Explicit architecture mapping to support both native runners and Launchpad remote-build architectures: - build-on: amd64 + build-for: amd64 - build-on: arm64 + build-for: arm64 - build-on: armhf + build-for: armhf - build-on: riscv64 + build-for: riscv64 # System user for filters and backends to drop privileges, "lp" is not # available in a Snap @@ -175,15 +179,10 @@ parts: source-type: git source-tag: 'v2.4.16' source-depth: 1 -# ext:updatesnap -# version-format: -# lower-than: '3' -# no-9x-revisions: true plugin: autotools autotools-configure-parameters: - --prefix=/ - --exec-prefix=/ - # Prevent the libraries from being put into lib64 - --libdir=/lib - --datadir=/share - --datarootdir=/share @@ -196,20 +195,10 @@ parts: - --without-rcdir - --with-docdir=/share/cups/doc - --with-container=snap - # We use "--with-tls=gnutls" here, as current CUPS defaults to SSL here - # and this is buggy, causing a segfault when serving out a HTTPS web - # interface page. - --with-tls=gnutls - #- --enable-debug-printfs override-pull: | set -eux - # Do the actual pull task craftctl default - # Settings: - # Patch to use snapctl with the slot name "cups-server" for Snap mediation - #patch -p1 < $CRAFT_PROJECT_DIR/patches/use-snapctl-with-slot-cups-server.patch - # Longer timeout for Avahi resolving for cupsGetDests() API function, used - # by "lpstat -l -e" (https://github.com/OpenPrinting/cups/issues/751) perl -p -i -e 's/(#\s*define\s+_CUPS_DNSSD_GET_DESTS\s+)250(\s+)/\1 1000\2/' cups/dest.c build-packages: - perl-base @@ -237,8 +226,6 @@ parts: organize: var/snap/cups/common/etc: etc stage: - # The *.la file which gets installed by "make install" contains a - # wrong prefix, breaking parts of this Snap which use this library - -lib/lib*.la prime: - -etc/fonts @@ -252,7 +239,6 @@ parts: - -usr/share/doc - -usr/share/doc-base - -usr/share/lintian - # Reported unused by snapcraft linter - -lib/libcupsimage.* - -usr/lib/*/libdconf.* - -usr/lib/*/libicuio.* @@ -264,10 +250,6 @@ parts: source: https://github.com/qpdf/qpdf.git source-tag: 'v11.10.1' source-depth: 1 -# ext:updatesnap -# version-format: -# lower-than: '12' -# no-9x-revisions: true plugin: cmake cmake-parameters: - -DCMAKE_INSTALL_PREFIX=/usr @@ -286,8 +268,6 @@ parts: stage-packages: - libjpeg-turbo8 stage: - # The *.la file which gets installed by "make install" contains a - # wrong prefix, breaking parts of this Snap which use this library - -usr/lib/lib*.la prime: - -etc/fonts @@ -304,23 +284,10 @@ parts: - -usr/share/lintian ghostscript: - # use GitHub mirror of GhostPDL here, as original GIT, self-hosted by - # Artifex is not supported by ubuntu/desktop-snaps - #source: https://git.ghostscript.com/ghostpdl.git source: https://github.com/ArtifexSoftware/ghostpdl.git source-type: git source-tag: 'ghostpdl-10.07.0rc1_test001' source-depth: 1 -# ext:updatesnap -# version-format: -# format: "ghostpdl-%M.%m.%R" -# lower-than: '11' -# no-9x-revisions: true -# The repo is actually ghostpdl and not only Ghostscript, so a wider -# variety of print data renderers/interpreters/converters. One of -# them, gpdl, does not build with our ./configure settings but we -# actually do not need it. So build without gpdl. Also, no need to -# build pcl and xps. plugin: autotools autotools-configure-parameters: - --prefix=/ @@ -339,7 +306,9 @@ parts: - --with-cups-serverroot=/var/snap/cups/common/etc/cups - --with-cups-datadir=/snap/cups/current/share/cups build-environment: - # To find the libraries built in this Snap + # Universal fixes: Forces C99 standard, compatible across all architectures. + - CFLAGS: "-std=gnu99 -Wno-error=declaration-after-statement" + - CXXFLAGS: "-std=gnu++99" - LD_LIBRARY_PATH: "${LD_LIBRARY_PATH:+$LD_LIBRARY_PATH:}$CRAFT_STAGE/usr/lib:$CRAFT_STAGE/usr/lib/${CRAFT_ARCH_TRIPLET_BUILD_FOR}:$CRAFT_STAGE/lib" stage-packages: - libpaper1 @@ -368,10 +337,6 @@ parts: source-type: git source-tag: '2.1.1' source-depth: 1 -# ext:updatesnap -# version-format: -# lower-than: '3' -# no-9x-revisions: true plugin: autotools autotools-configure-parameters: - --prefix=/ @@ -382,7 +347,6 @@ parts: - --disable-avahi - --disable-mutool build-environment: - # To find the libraries built in this Snap - LD_LIBRARY_PATH: "${LD_LIBRARY_PATH:+$LD_LIBRARY_PATH:}$CRAFT_STAGE/usr/lib:$CRAFT_STAGE/usr/lib/${CRAFT_ARCH_TRIPLET_BUILD_FOR}:$CRAFT_STAGE/lib" build-packages: - gettext @@ -409,8 +373,6 @@ parts: - libexif12 stage: - -lib/lib*.la - # The *.la file which gets installed by "make install" contains a - # wrong prefix, breaking parts of this Snap which use this library prime: - -etc - -var @@ -429,7 +391,6 @@ parts: - usr/lib/lib*.so* - usr/lib/*/lib*.so* - usr/lib/*/nss - # Reported unused by snapcraft linter - -usr/lib/*/libssl3.* after: [cups, qpdf, ghostscript] @@ -438,12 +399,7 @@ parts: source-type: git source-tag: '2.1.1' source-depth: 1 -# ext:updatesnap -# version-format: -# lower-than: '3' -# no-9x-revisions: true plugin: autotools - # We only need libppd itself autotools-configure-parameters: - --prefix=/ - --exec-prefix=/ @@ -456,7 +412,6 @@ parts: - --disable-pdftocairo - --disable-acroread build-environment: - # To find the libraries built in this Snap - LD_LIBRARY_PATH: "${LD_LIBRARY_PATH:+$LD_LIBRARY_PATH:}$CRAFT_STAGE/usr/lib:$CRAFT_STAGE/usr/lib/${CRAFT_ARCH_TRIPLET_BUILD_FOR}:$CRAFT_STAGE/lib" build-packages: - gettext @@ -468,8 +423,6 @@ parts: craftctl default sed -i 's|/usr/bin/pdftops|pdftops|' $CRAFT_PART_SRC/configure.ac stage: - # The *.la file which gets installed by "make install" contains a - # wrong prefix, breaking parts of this Snap which use this library - -lib/lib*.la prime: - -etc @@ -497,10 +450,6 @@ parts: source-type: git source-tag: '2.0.1' source-depth: 1 -# ext:updatesnap -# version-format: -# lower-than: '3' -# no-9x-revisions: true plugin: autotools autotools-configure-parameters: - --prefix=/ @@ -512,7 +461,6 @@ parts: - --disable-universal-cups-filter - --enable-individual-cups-filters build-environment: - # To find the libraries built in this Snap - LD_LIBRARY_PATH: "${LD_LIBRARY_PATH:+$LD_LIBRARY_PATH:}$CRAFT_STAGE/usr/lib:$CRAFT_STAGE/usr/lib/${CRAFT_ARCH_TRIPLET_BUILD_FOR}:$CRAFT_STAGE/lib" build-packages: - sharutils @@ -540,7 +488,6 @@ parts: - -usr/share/doc - -usr/share/doc-base - -usr/share/lintian - # Reported unused by snapcraft linter - -usr/lib/*/libssl3.* after: [cups, qpdf, ghostscript, libcupsfilters, libppd] @@ -549,10 +496,6 @@ parts: source-type: git source-tag: '2.1.1' source-depth: 1 -# ext:updatesnap -# version-format: -# lower-than: '3' -# no-9x-revisions: true plugin: autotools autotools-configure-parameters: - --prefix=/ @@ -562,7 +505,6 @@ parts: - --includedir=/include - --without-rcdir build-environment: - # To find the libraries built in this Snap - LD_LIBRARY_PATH: "${LD_LIBRARY_PATH:+$LD_LIBRARY_PATH:}$CRAFT_STAGE/usr/lib:$CRAFT_STAGE/usr/lib/${CRAFT_ARCH_TRIPLET_BUILD_FOR}:$CRAFT_STAGE/lib" build-packages: - sharutils @@ -594,7 +536,8 @@ parts: source: scripts/ override-build: | set -eux - gcc -o port-occupied port-occupied.c + # Uses CRAFT_ARCH_TRIPLET_BUILD_FOR to gracefully support all architectures natively and via remote + "${CRAFT_ARCH_TRIPLET_BUILD_FOR}-gcc" -o port-occupied port-occupied.c craftctl default organize: run-cupsd: scripts/run-cupsd @@ -616,13 +559,9 @@ parts: source: cups-proxyd override-build: | set -eux - # We do "make clean" here that we do not accidentally use - # binaries manually built in the source tree for development and - # copied into a local Snap build process make clean craftctl default build-environment: - # To find the libraries built in this Snap - LD_LIBRARY_PATH: "${LD_LIBRARY_PATH:+$LD_LIBRARY_PATH:}$CRAFT_STAGE/usr/lib:$CRAFT_STAGE/usr/lib/${CRAFT_ARCH_TRIPLET_BUILD_FOR}:$CRAFT_STAGE/lib" build-packages: - gcc @@ -633,4 +572,4 @@ parts: organize: usr/lib/cups/backend: lib/cups/backend usr/sbin: sbin - after: [cups, cups-filters] + after: [cups, cups-filters] \ No newline at end of file From 7386d51964e350657f7c384cc8545cc6c2b9e3ff Mon Sep 17 00:00:00 2001 From: Rohit Kumar Date: Thu, 12 Mar 2026 11:07:40 +0530 Subject: [PATCH 2/9] Added credentials warning for remote armhf build --- .github/workflows/build.yml | 20 +++++++++++++++++++- 1 file changed, 19 insertions(+), 1 deletion(-) diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml index 7bef1a57..c032e017 100644 --- a/.github/workflows/build.yml +++ b/.github/workflows/build.yml @@ -8,7 +8,8 @@ on: branches: - master workflow_dispatch: - +permissions: + contents: read jobs: # Job 1: Native builds for amd64 and arm64 build-native: @@ -66,6 +67,7 @@ jobs: path: ./*.snap if-no-files-found: error + # Job 2: Remote build via Launchpad for armhf # Job 2: Remote build via Launchpad for armhf build-remote: name: Build Remote (armhf) @@ -76,11 +78,25 @@ jobs: with: fetch-depth: 0 + - name: Check Launchpad Credentials + id: check-secrets + env: + LP_CREDENTIALS: ${{ secrets.LP_CREDENTIALS }} + run: | + if [ -z "$LP_CREDENTIALS" ]; then + echo "available=false" >> $GITHUB_OUTPUT + echo "Notice: Launchpad credentials not available (likely a PR from a fork). Skipping remote build." + else + echo "available=true" >> $GITHUB_OUTPUT + fi + - name: Install Snapcraft + if: steps.check-secrets.outputs.available == 'true' run: | sudo snap install snapcraft --channel latest/stable --classic - name: Setup Launchpad credentials + if: steps.check-secrets.outputs.available == 'true' env: LP_CREDENTIALS: ${{ secrets.LP_CREDENTIALS }} run: | @@ -90,11 +106,13 @@ jobs: echo "$LP_CREDENTIALS" > ~/.local/share/snapcraft/launchpad-credentials - name: Remote build CUPS snap on Launchpad + if: steps.check-secrets.outputs.available == 'true' run: | set -e snapcraft remote-build --launchpad-accept-public-upload --build-for=armhf - name: Upload CUPS snap artifact + if: steps.check-secrets.outputs.available == 'true' uses: actions/upload-artifact@v4 with: name: cups-snap-armhf From 1d690600e154d62a3c416c1b07e98ba4848632cd Mon Sep 17 00:00:00 2001 From: "github-actions[bot]" <41898282+github-actions[bot]@users.noreply.github.com> Date: Thu, 12 Mar 2026 07:52:17 +0000 Subject: [PATCH 3/9] Update snap version and tag --- snapcraft.yaml | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/snapcraft.yaml b/snapcraft.yaml index f02df223..1ba0c8b3 100644 --- a/snapcraft.yaml +++ b/snapcraft.yaml @@ -1,6 +1,6 @@ name: cups base: core22 # The base Snap is the execution environment for this Snap -version: '2.4.16-1' +version: '2.4.16-2' grade: stable summary: CUPS-based printing stack Snap description: Complete printing environment in a Snap @@ -248,7 +248,7 @@ parts: qpdf: source: https://github.com/qpdf/qpdf.git - source-tag: 'v11.10.1' + source-tag: 'v12.3.2' source-depth: 1 plugin: cmake cmake-parameters: @@ -572,4 +572,4 @@ parts: organize: usr/lib/cups/backend: lib/cups/backend usr/sbin: sbin - after: [cups, cups-filters] \ No newline at end of file + after: [cups, cups-filters] From 57d56d5af208dadb13a84f3099aa62f94659046e Mon Sep 17 00:00:00 2001 From: Rohit Kumar Date: Thu, 12 Mar 2026 16:54:35 +0530 Subject: [PATCH 4/9] ci: enhance Launchpad build error handling and PR bypass logic --- .github/workflows/build.yml | 44 ++++++++++++++++++++++++++++++++----- 1 file changed, 38 insertions(+), 6 deletions(-) diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml index c032e017..5a5b013d 100644 --- a/.github/workflows/build.yml +++ b/.github/workflows/build.yml @@ -8,8 +8,11 @@ on: branches: - master workflow_dispatch: + permissions: contents: read + pull-requests: write # Added this so the bot can post the PR comment + jobs: # Job 1: Native builds for amd64 and arm64 build-native: @@ -67,7 +70,6 @@ jobs: path: ./*.snap if-no-files-found: error - # Job 2: Remote build via Launchpad for armhf # Job 2: Remote build via Launchpad for armhf build-remote: name: Build Remote (armhf) @@ -78,18 +80,36 @@ jobs: with: fetch-depth: 0 - - name: Check Launchpad Credentials + - name: Check Launchpad Credentials & Scenarios id: check-secrets env: LP_CREDENTIALS: ${{ secrets.LP_CREDENTIALS }} run: | if [ -z "$LP_CREDENTIALS" ]; then - echo "available=false" >> $GITHUB_OUTPUT - echo "Notice: Launchpad credentials not available (likely a PR from a fork). Skipping remote build." + if [ "${{ github.event_name }}" == "pull_request" ]; then + echo "available=false" >> $GITHUB_OUTPUT + echo "::notice::Launchpad credentials not available in external PRs. Safely skipping remote build." + else + echo "available=false" >> $GITHUB_OUTPUT + echo "::error::No secrets found. LP_CREDENTIALS is missing from the repository." + exit 1 + fi else echo "available=true" >> $GITHUB_OUTPUT fi + - name: Notify Maintainers via PR Comment + if: steps.check-secrets.outputs.available == 'false' && github.event_name == 'pull_request' + uses: actions/github-script@v7 + with: + script: | + github.rest.issues.createComment({ + issue_number: context.issue.number, + owner: context.repo.owner, + repo: context.repo.repo, + body: '⚠️ **Launchpad CI Notice:** \n\nGitHub Actions cannot securely access repository secrets (`LP_CREDENTIALS`) in Pull Requests originating from external forks.\n\nBecause of this, we are **bypassing the `armhf` Launchpad remote build** for this PR check so it does not falsely fail and block your merge. \n\nThe actual `armhf` compilation results will be verified automatically in the `push` workflow where secrets are fully accessible, immediately after this PR is merged into `master`.' + }) + - name: Install Snapcraft if: steps.check-secrets.outputs.available == 'true' run: | @@ -108,8 +128,20 @@ jobs: - name: Remote build CUPS snap on Launchpad if: steps.check-secrets.outputs.available == 'true' run: | - set -e - snapcraft remote-build --launchpad-accept-public-upload --build-for=armhf + set +e # Disable auto-exit to capture output + OUTPUT=$(snapcraft remote-build --launchpad-accept-public-upload --build-for=armhf 2>&1) + EXIT_CODE=$? + set -e # Re-enable auto-exit + + if [ $EXIT_CODE -ne 0 ]; then + echo "$OUTPUT" # Print the full log for debugging + if echo "$OUTPUT" | grep -iqE "macaroon|unauthorized|authentication|login|credentials"; then + echo "::error::Secrets are invalid or expired. Launchpad authentication failed." + else + echo "::error::Launchpad build failed due to a code compilation error or infrastructure issue." + fi + exit $EXIT_CODE + fi - name: Upload CUPS snap artifact if: steps.check-secrets.outputs.available == 'true' From 07b5673140e0022604623d8635a0fbd573b2d808 Mon Sep 17 00:00:00 2001 From: Rohit Kumar Date: Thu, 12 Mar 2026 17:03:10 +0530 Subject: [PATCH 5/9] ci: removed comment in PR due to securrity regoins --- .github/workflows/build.yml | 15 ++------------- 1 file changed, 2 insertions(+), 13 deletions(-) diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml index 5a5b013d..2cf8f325 100644 --- a/.github/workflows/build.yml +++ b/.github/workflows/build.yml @@ -70,6 +70,7 @@ jobs: path: ./*.snap if-no-files-found: error + # Job 2: Remote build via Launchpad for armhf # Job 2: Remote build via Launchpad for armhf build-remote: name: Build Remote (armhf) @@ -88,7 +89,7 @@ jobs: if [ -z "$LP_CREDENTIALS" ]; then if [ "${{ github.event_name }}" == "pull_request" ]; then echo "available=false" >> $GITHUB_OUTPUT - echo "::notice::Launchpad credentials not available in external PRs. Safely skipping remote build." + echo "::notice title=Launchpad CI Bypassed::GitHub Actions cannot securely access repository secrets in PRs from external forks. Bypassing the armhf remote build so it does not falsely block your merge. The compilation will be verified automatically in the push workflow immediately after merging into master." else echo "available=false" >> $GITHUB_OUTPUT echo "::error::No secrets found. LP_CREDENTIALS is missing from the repository." @@ -98,18 +99,6 @@ jobs: echo "available=true" >> $GITHUB_OUTPUT fi - - name: Notify Maintainers via PR Comment - if: steps.check-secrets.outputs.available == 'false' && github.event_name == 'pull_request' - uses: actions/github-script@v7 - with: - script: | - github.rest.issues.createComment({ - issue_number: context.issue.number, - owner: context.repo.owner, - repo: context.repo.repo, - body: '⚠️ **Launchpad CI Notice:** \n\nGitHub Actions cannot securely access repository secrets (`LP_CREDENTIALS`) in Pull Requests originating from external forks.\n\nBecause of this, we are **bypassing the `armhf` Launchpad remote build** for this PR check so it does not falsely fail and block your merge. \n\nThe actual `armhf` compilation results will be verified automatically in the `push` workflow where secrets are fully accessible, immediately after this PR is merged into `master`.' - }) - - name: Install Snapcraft if: steps.check-secrets.outputs.available == 'true' run: | From 56dffafa8c7be7ed43d569e6d98d820c9f8754db Mon Sep 17 00:00:00 2001 From: Rohit Kumar Date: Thu, 12 Mar 2026 19:36:55 +0530 Subject: [PATCH 6/9] restores the original snapcraft.yaml to recover essential maintainer comments and ext:updatesnap blocks that were accidentally overwritten in a previous commit --- snapcraft.yaml | 74 ++++++++++++++++++++++++++++++++++++++++++++++++-- 1 file changed, 72 insertions(+), 2 deletions(-) diff --git a/snapcraft.yaml b/snapcraft.yaml index 1ba0c8b3..ed1e9204 100644 --- a/snapcraft.yaml +++ b/snapcraft.yaml @@ -11,6 +11,7 @@ adopt-info: cups # `cups` interface in snapd assumes: [snapd2.55] +# Only build on the architectures supported # Explicit architecture mapping to support both native runners and Launchpad remote-build architectures: - build-on: amd64 @@ -179,10 +180,15 @@ parts: source-type: git source-tag: 'v2.4.16' source-depth: 1 +# ext:updatesnap +# version-format: +# lower-than: '3' +# no-9x-revisions: true plugin: autotools autotools-configure-parameters: - --prefix=/ - --exec-prefix=/ + # Prevent the libraries from being put into lib64 - --libdir=/lib - --datadir=/share - --datarootdir=/share @@ -195,10 +201,20 @@ parts: - --without-rcdir - --with-docdir=/share/cups/doc - --with-container=snap + # We use "--with-tls=gnutls" here, as current CUPS defaults to SSL here + # and this is buggy, causing a segfault when serving out a HTTPS web + # interface page. - --with-tls=gnutls + #- --enable-debug-printfs override-pull: | set -eux + # Do the actual pull task craftctl default + # Settings: + # Patch to use snapctl with the slot name "cups-server" for Snap mediation + #patch -p1 < $CRAFT_PROJECT_DIR/patches/use-snapctl-with-slot-cups-server.patch + # Longer timeout for Avahi resolving for cupsGetDests() API function, used + # by "lpstat -l -e" (https://github.com/OpenPrinting/cups/issues/751) perl -p -i -e 's/(#\s*define\s+_CUPS_DNSSD_GET_DESTS\s+)250(\s+)/\1 1000\2/' cups/dest.c build-packages: - perl-base @@ -226,6 +242,8 @@ parts: organize: var/snap/cups/common/etc: etc stage: + # The *.la file which gets installed by "make install" contains a + # wrong prefix, breaking parts of this Snap which use this library - -lib/lib*.la prime: - -etc/fonts @@ -239,6 +257,7 @@ parts: - -usr/share/doc - -usr/share/doc-base - -usr/share/lintian + # Reported unused by snapcraft linter - -lib/libcupsimage.* - -usr/lib/*/libdconf.* - -usr/lib/*/libicuio.* @@ -248,8 +267,12 @@ parts: qpdf: source: https://github.com/qpdf/qpdf.git - source-tag: 'v12.3.2' + source-tag: 'v11.10.1' source-depth: 1 +# ext:updatesnap +# version-format: +# lower-than: '12' +# no-9x-revisions: true plugin: cmake cmake-parameters: - -DCMAKE_INSTALL_PREFIX=/usr @@ -268,6 +291,8 @@ parts: stage-packages: - libjpeg-turbo8 stage: + # The *.la file which gets installed by "make install" contains a + # wrong prefix, breaking parts of this Snap which use this library - -usr/lib/lib*.la prime: - -etc/fonts @@ -284,10 +309,23 @@ parts: - -usr/share/lintian ghostscript: + # use GitHub mirror of GhostPDL here, as original GIT, self-hosted by + # Artifex is not supported by ubuntu/desktop-snaps + #source: https://git.ghostscript.com/ghostpdl.git source: https://github.com/ArtifexSoftware/ghostpdl.git source-type: git source-tag: 'ghostpdl-10.07.0rc1_test001' source-depth: 1 +# ext:updatesnap +# version-format: +# format: "ghostpdl-%M.%m.%R" +# lower-than: '11' +# no-9x-revisions: true +# The repo is actually ghostpdl and not only Ghostscript, so a wider +# variety of print data renderers/interpreters/converters. One of +# them, gpdl, does not build with our ./configure settings but we +# actually do not need it. So build without gpdl. Also, no need to +# build pcl and xps. plugin: autotools autotools-configure-parameters: - --prefix=/ @@ -309,6 +347,7 @@ parts: # Universal fixes: Forces C99 standard, compatible across all architectures. - CFLAGS: "-std=gnu99 -Wno-error=declaration-after-statement" - CXXFLAGS: "-std=gnu++99" + # To find the libraries built in this Snap - LD_LIBRARY_PATH: "${LD_LIBRARY_PATH:+$LD_LIBRARY_PATH:}$CRAFT_STAGE/usr/lib:$CRAFT_STAGE/usr/lib/${CRAFT_ARCH_TRIPLET_BUILD_FOR}:$CRAFT_STAGE/lib" stage-packages: - libpaper1 @@ -337,6 +376,10 @@ parts: source-type: git source-tag: '2.1.1' source-depth: 1 +# ext:updatesnap +# version-format: +# lower-than: '3' +# no-9x-revisions: true plugin: autotools autotools-configure-parameters: - --prefix=/ @@ -347,6 +390,7 @@ parts: - --disable-avahi - --disable-mutool build-environment: + # To find the libraries built in this Snap - LD_LIBRARY_PATH: "${LD_LIBRARY_PATH:+$LD_LIBRARY_PATH:}$CRAFT_STAGE/usr/lib:$CRAFT_STAGE/usr/lib/${CRAFT_ARCH_TRIPLET_BUILD_FOR}:$CRAFT_STAGE/lib" build-packages: - gettext @@ -373,6 +417,8 @@ parts: - libexif12 stage: - -lib/lib*.la + # The *.la file which gets installed by "make install" contains a + # wrong prefix, breaking parts of this Snap which use this library prime: - -etc - -var @@ -391,6 +437,7 @@ parts: - usr/lib/lib*.so* - usr/lib/*/lib*.so* - usr/lib/*/nss + # Reported unused by snapcraft linter - -usr/lib/*/libssl3.* after: [cups, qpdf, ghostscript] @@ -399,7 +446,12 @@ parts: source-type: git source-tag: '2.1.1' source-depth: 1 +# ext:updatesnap +# version-format: +# lower-than: '3' +# no-9x-revisions: true plugin: autotools + # We only need libppd itself autotools-configure-parameters: - --prefix=/ - --exec-prefix=/ @@ -412,6 +464,7 @@ parts: - --disable-pdftocairo - --disable-acroread build-environment: + # To find the libraries built in this Snap - LD_LIBRARY_PATH: "${LD_LIBRARY_PATH:+$LD_LIBRARY_PATH:}$CRAFT_STAGE/usr/lib:$CRAFT_STAGE/usr/lib/${CRAFT_ARCH_TRIPLET_BUILD_FOR}:$CRAFT_STAGE/lib" build-packages: - gettext @@ -423,6 +476,8 @@ parts: craftctl default sed -i 's|/usr/bin/pdftops|pdftops|' $CRAFT_PART_SRC/configure.ac stage: + # The *.la file which gets installed by "make install" contains a + # wrong prefix, breaking parts of this Snap which use this library - -lib/lib*.la prime: - -etc @@ -450,6 +505,10 @@ parts: source-type: git source-tag: '2.0.1' source-depth: 1 +# ext:updatesnap +# version-format: +# lower-than: '3' +# no-9x-revisions: true plugin: autotools autotools-configure-parameters: - --prefix=/ @@ -461,6 +520,7 @@ parts: - --disable-universal-cups-filter - --enable-individual-cups-filters build-environment: + # To find the libraries built in this Snap - LD_LIBRARY_PATH: "${LD_LIBRARY_PATH:+$LD_LIBRARY_PATH:}$CRAFT_STAGE/usr/lib:$CRAFT_STAGE/usr/lib/${CRAFT_ARCH_TRIPLET_BUILD_FOR}:$CRAFT_STAGE/lib" build-packages: - sharutils @@ -488,6 +548,7 @@ parts: - -usr/share/doc - -usr/share/doc-base - -usr/share/lintian + # Reported unused by snapcraft linter - -usr/lib/*/libssl3.* after: [cups, qpdf, ghostscript, libcupsfilters, libppd] @@ -496,6 +557,10 @@ parts: source-type: git source-tag: '2.1.1' source-depth: 1 +# ext:updatesnap +# version-format: +# lower-than: '3' +# no-9x-revisions: true plugin: autotools autotools-configure-parameters: - --prefix=/ @@ -505,6 +570,7 @@ parts: - --includedir=/include - --without-rcdir build-environment: + # To find the libraries built in this Snap - LD_LIBRARY_PATH: "${LD_LIBRARY_PATH:+$LD_LIBRARY_PATH:}$CRAFT_STAGE/usr/lib:$CRAFT_STAGE/usr/lib/${CRAFT_ARCH_TRIPLET_BUILD_FOR}:$CRAFT_STAGE/lib" build-packages: - sharutils @@ -559,9 +625,13 @@ parts: source: cups-proxyd override-build: | set -eux + # We do "make clean" here that we do not accidentally use + # binaries manually built in the source tree for development and + # copied into a local Snap build process make clean craftctl default build-environment: + # To find the libraries built in this Snap - LD_LIBRARY_PATH: "${LD_LIBRARY_PATH:+$LD_LIBRARY_PATH:}$CRAFT_STAGE/usr/lib:$CRAFT_STAGE/usr/lib/${CRAFT_ARCH_TRIPLET_BUILD_FOR}:$CRAFT_STAGE/lib" build-packages: - gcc @@ -572,4 +642,4 @@ parts: organize: usr/lib/cups/backend: lib/cups/backend usr/sbin: sbin - after: [cups, cups-filters] + after: [cups, cups-filters] \ No newline at end of file From ca53ef7d7bf4ba331e744bc887599a68e09faa71 Mon Sep 17 00:00:00 2001 From: Rohit Kumar Date: Thu, 12 Mar 2026 20:28:36 +0530 Subject: [PATCH 7/9] Restore newline at end of snapcraft.yaml --- snapcraft.yaml | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/snapcraft.yaml b/snapcraft.yaml index ed1e9204..7432e5d3 100644 --- a/snapcraft.yaml +++ b/snapcraft.yaml @@ -642,4 +642,5 @@ parts: organize: usr/lib/cups/backend: lib/cups/backend usr/sbin: sbin - after: [cups, cups-filters] \ No newline at end of file + after: [cups, cups-filters] + \ No newline at end of file From 9edd1ff969aa88e94460707393c907d6846c31d2 Mon Sep 17 00:00:00 2001 From: Rohit Kumar Date: Thu, 12 Mar 2026 20:33:25 +0530 Subject: [PATCH 8/9] Remove trailing whitespace at end of file --- snapcraft.yaml | 1 - 1 file changed, 1 deletion(-) diff --git a/snapcraft.yaml b/snapcraft.yaml index 7432e5d3..289fc1be 100644 --- a/snapcraft.yaml +++ b/snapcraft.yaml @@ -643,4 +643,3 @@ parts: usr/lib/cups/backend: lib/cups/backend usr/sbin: sbin after: [cups, cups-filters] - \ No newline at end of file From 3aec167fa265d2e3a0ff85f3243aa5cffd0bcbb4 Mon Sep 17 00:00:00 2001 From: Rohit Kumar Date: Thu, 12 Mar 2026 22:27:50 +0530 Subject: [PATCH 9/9] Added documentation for LP_CREDENTIALS generation and added a newLine in build.yml --- .github/workflows/build.yml | 2 +- README.md | 73 +++++++++++++++++++++++++++++++++++++ 2 files changed, 74 insertions(+), 1 deletion(-) diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml index 2cf8f325..96582637 100644 --- a/.github/workflows/build.yml +++ b/.github/workflows/build.yml @@ -138,4 +138,4 @@ jobs: with: name: cups-snap-armhf path: ./*.snap - if-no-files-found: error \ No newline at end of file + if-no-files-found: error diff --git a/README.md b/README.md index eb25ce56..75c7f0e3 100644 --- a/README.md +++ b/README.md @@ -264,6 +264,79 @@ This repository uses a custom GitHub Actions workflow for CodeQL static analysis *Note: If the Default setup is active, GitHub may reject the results uploaded by the manual workflow, causing the CI job to fail.* +## Launchpad Credentials for armhf Remote Build + +The `armhf` build in CI uses **Snapcraft remote-build with Launchpad**. +Since GitHub runners do not have a Launchpad identity, authentication credentials must be generated locally and stored as a **GitHub repository secret**. + +Follow the steps below to generate and configure the credentials. + +### 1. Generate Launchpad Credentials +The credentials are generated via an interactive **Snapcraft OAuth login**. +First navigate to the project directory: +``` +cd path/to/cups-snap +``` +Run the following command: +```bash +snapcraft remote-build +``` +Snapcraft will display a Launchpad authorization URL. +- Copy the URL shown in the terminal. +- Open it in your browser. +- Click Authorize. +- Return to the terminal. +- Once the upload starts, stop the process using: + ``` + Ctrl + C + ``` +Stopping the process here is expected. The credentials will already have been generated. + +### 2. Extract the Credentials +Snapcraft stores the generated credentials locally. +Run: +``` +cat ~/.local/share/snapcraft/provider/launchpad/credentials +``` +If the file is not present, check: +``` +cat ~/.local/share/snapcraft/launchpad-credentials +``` +You will see output similar to: +``` +[1] +consumer_key = System-wide: Ubuntu (...) +consumer_secret = +access_token = +access_secret = +``` +Copy the entire block, including [1]. + +### 3. Store the Credentials in GitHub Secrets +The credentials must be added as a repository secret. +Navigate to: +``` +Repository → Settings → Secrets and variables → Actions +``` +Create a new secret: +``` +LP_CREDENTIALS +``` +Value: +Paste the complete credential block copied in the previous step. + +Example: +``` +[1] +consumer_key = System-wide: Ubuntu (...) +consumer_secret = +access_token = XXXXX +access_secret = XXXXX +``` +These credentials will then be used automatically by the CI workflow when performing the armhf remote build. + +*Note: Launchpad OAuth credentials generated by Snapcraft expire after approximately one year.If the CI workflow begins failing with authentication or authorization errors, new credentials must be generated by repeating the steps above and updating the LP_CREDENTIALS repository secret.* + ## Discussion and Links Call for testing: