Skip to content

Commit 25104ed

Browse files
ralyodioclaude
andcommitted
distribution/: all channels in one place + add Snap, Flatpak, AppImage, FreeBSD
Every channel now lives under distribution/ (moved snap + nfpm/deb-rpm from packaging/). Added: snap (snapcraft.yaml, classic), flatpak (manifest + flatpak-spawn wrapper), appimage (AppRun + .desktop + build.sh, built in CI), freebsd (port Makefile + pkg-descr). release.yml linux job now also builds the AppImage; submit-packages.mjs + workflow know the new channels. README has the full OS matrix (mac, windows, debian/ubuntu, fedora/redhat/suse, arch, gentoo, nixos, snap, flatpak, appimage, freebsd, arm64 mobile linux, ios/android). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
1 parent 7f2ad19 commit 25104ed

14 files changed

Lines changed: 212 additions & 48 deletions

File tree

‎.github/workflows/release.yml‎

Lines changed: 5 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -61,12 +61,14 @@ jobs:
6161
if: matrix.platform != 'windows'
6262
run: bash apps/desktop/scripts/build-release.sh "v${{ needs.create-release.outputs.version }}" ${{ matrix.platform }}
6363

64-
- name: Package (linux deb + rpm)
64+
- name: Package (linux deb + rpm + AppImage)
6565
if: matrix.platform == 'linux'
6666
run: |
6767
curl -sSfL "https://github.com/goreleaser/nfpm/releases/download/v2.41.0/nfpm_2.41.0_amd64.deb" -o /tmp/nfpm.deb
6868
sudo dpkg -i /tmp/nfpm.deb
69-
bash packaging/build-deb-rpm.sh "v${{ needs.create-release.outputs.version }}"
69+
sudo apt-get update -qq && sudo apt-get install -y -qq librsvg2-bin
70+
bash distribution/deb-rpm/build.sh "v${{ needs.create-release.outputs.version }}"
71+
bash distribution/appimage/build.sh "v${{ needs.create-release.outputs.version }}"
7072
7173
- name: Package (windows)
7274
if: matrix.platform == 'windows'
@@ -88,7 +90,7 @@ jobs:
8890
GH_TOKEN: ${{ github.token }}
8991
run: |
9092
shopt -s nullglob
91-
assets=(dist/tronbrowser-*.tar.gz dist/tronbrowser-*.zip dist/*.deb dist/*.rpm)
93+
assets=(dist/tronbrowser-*.tar.gz dist/tronbrowser-*.zip dist/*.deb dist/*.rpm dist/*.AppImage)
9294
gh release upload "${{ needs.create-release.outputs.tag }}" "${assets[@]}" --clobber
9395
9496
# 3) Publish (un-draft) once every platform has uploaded.

‎.github/workflows/submit-packages.yml‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -40,7 +40,7 @@ jobs:
4040
run: |
4141
PMS="${{ github.event.inputs.package_managers }}"
4242
[ -z "$PMS" ] && PMS="all"
43-
if [ "$PMS" = "all" ]; then PMS="homebrew,scoop,winget,aur,apt,rpm,gentoo,nix"; fi
43+
if [ "$PMS" = "all" ]; then PMS="homebrew,scoop,winget,aur,apt,rpm,gentoo,nix,snap,flatpak,appimage,freebsd"; fi
4444
echo "list=$(echo "$PMS" | sed 's/chocolatey,*//g')" >> "$GITHUB_OUTPUT"
4545
4646
- name: Refresh + submit manifests

‎distribution/README.md‎

Lines changed: 41 additions & 35 deletions
Original file line numberDiff line numberDiff line change
@@ -1,50 +1,56 @@
11
# Distribution channels
22

3-
How TronBrowser reaches users — the same channel set as pairux.com, kept in this
4-
**single monorepo** (no per-package repos). GitHub Releases is the source of
5-
truth; package managers consume the release assets.
3+
Every channel lives **here** in the one monorepo (no per-package repos), modeled
4+
on pairux.com. GitHub Releases is the source of truth; each channel consumes the
5+
release assets. Goal: every major OS + open-source platform.
66

7-
## Channels
7+
## Platform matrix
88

9-
| Channel | Manifest | Artifact | Status |
9+
| OS / family | Channel | Manifest | Status |
1010
| --- | --- | --- | --- |
11-
| `curl \| sh` | [`apps/web/public/install.sh`](../apps/web/public/install.sh) | linux tar.gz / macos zip | ✅ live |
12-
| GitHub Releases | [`release.yml`](../.github/workflows/release.yml) | all | ✅ live |
13-
| Homebrew | [`homebrew/tronbrowser.rb`](homebrew/tronbrowser.rb) | linux tar.gz / macos zip | 🟡 formula ready (needs `profullstack/homebrew-tap`) |
14-
| AUR | [`aur/PKGBUILD`](aur/PKGBUILD) | linux tar.gz | 🟡 ready (needs `AUR_SSH_KEY`) |
15-
| Nix | [`nix/tronbrowser.nix`](nix/tronbrowser.nix) | linux tar.gz | 🟡 ready |
16-
| Gentoo | [`gentoo/`](gentoo/) | linux tar.gz | 🟡 ebuild ready |
17-
| apt (.deb) | [`packaging/nfpm.yaml`](../packaging/nfpm.yaml) | built by nfpm in CI | 🟡 built, needs an apt repo |
18-
| rpm (.rpm) | [`packaging/nfpm.yaml`](../packaging/nfpm.yaml) | built by nfpm in CI | 🟡 built, needs a yum repo |
19-
| Scoop | [`scoop/tronbrowser.json`](scoop/tronbrowser.json) | win zip | ⬜ needs Windows artifact hash |
20-
| winget | [`winget/`](winget/) | win zip | ⬜ needs Windows artifact + winget-pkgs PR |
21-
| Chocolatey | [`chocolatey/`](chocolatey/) | win zip | ⬜ needs Windows artifact + `CHOCOLATEY_API_KEY` |
11+
| **All** | `curl \| sh` | [`apps/web/public/install.sh`](../apps/web/public/install.sh) | ✅ live |
12+
| **All** | GitHub Releases | [`release.yml`](../.github/workflows/release.yml) | ✅ live |
13+
| macOS / Linux | Homebrew | [`homebrew/`](homebrew/) | 🟡 formula ready (needs tap repo) |
14+
| Windows | Scoop | [`scoop/`](scoop/) | ⬜ needs win zip hash |
15+
| Windows | winget | [`winget/`](winget/) | ⬜ needs winget-pkgs PR |
16+
| Windows | Chocolatey | [`chocolatey/`](chocolatey/) | ⬜ needs `CHOCOLATEY_API_KEY` |
17+
| Debian / Ubuntu | apt (.deb) | [`deb-rpm/`](deb-rpm/) (nfpm) | ✅ built in CI |
18+
| RedHat / Fedora / SUSE | rpm (.rpm) | [`deb-rpm/`](deb-rpm/) (nfpm) | ✅ built in CI |
19+
| Arch | AUR | [`aur/PKGBUILD`](aur/PKGBUILD) | 🟡 needs `AUR_SSH_KEY` |
20+
| Gentoo | ebuild | [`gentoo/`](gentoo/) | 🟡 overlay ready |
21+
| NixOS | Nix | [`nix/tronbrowser.nix`](nix/tronbrowser.nix) | 🟡 ready |
22+
| Ubuntu / universal | Snap | [`snap/snapcraft.yaml`](snap/snapcraft.yaml) | 🟡 classic snap (Snap Store login) |
23+
| Universal Linux | Flatpak | [`flatpak/`](flatpak/) | 🟡 manifest ready (Flathub PR) |
24+
| Universal Linux | AppImage | [`appimage/`](appimage/) | ✅ built in CI |
25+
| FreeBSD | port | [`freebsd/`](freebsd/) | 🟡 port ready |
26+
| Librem 5 / PinePhone / Ubuntu Touch | `curl \| sh` (arm64) | install.sh | ✅ noarch launcher |
27+
| iOS / Android | Expo / EAS | [`apps/mobile`](../apps/mobile) | 🚧 Phase 2 |
2228

2329
## CI/CD (per platform, one repo)
2430

25-
[`release.yml`](../.github/workflows/release.yml) runs on a `v*` tag:
31+
[`release.yml`](../.github/workflows/release.yml) on a `v*` tag:
2632

27-
1. **create-release** — open a draft GitHub Release.
28-
2. **build** (matrix: `ubuntu-latest` → linux tar.gz + .deb + .rpm,
29-
`macos-latest` → macos zip, `windows-latest` → win zip) — each runner builds
30-
its platform's artifacts and `gh release upload`s them to the draft.
31-
3. **publish** — un-draft once all platforms uploaded.
33+
1. **create-release** — draft GitHub Release.
34+
2. **build** matrix — `ubuntu` (linux tar.gz + .deb + .rpm + AppImage),
35+
`macos` (zip), `windows` (win zip); each uploads via `gh release upload`.
36+
3. **publish** — un-draft.
3237

33-
[`submit-packages.yml`](../.github/workflows/submit-packages.yml) runs on release
34-
publish (or manual dispatch with `version` / `dry_run` / `package_managers`). It
35-
runs [`scripts/submit-packages.mjs`](../scripts/submit-packages.mjs) to refresh
36-
each manifest's version + sha256 from the release assets, then submits per
38+
[`submit-packages.yml`](../.github/workflows/submit-packages.yml) on release publish
39+
(or dispatch) runs [`scripts/submit-packages.mjs`](../scripts/submit-packages.mjs)
40+
to refresh each manifest's version + sha256 from the release assets and submit per
3741
channel — gated on that channel's secret, dry-run by default.
3842

39-
## Secrets needed to actually submit
40-
41-
`AUR_SSH_KEY`, `GPG_PRIVATE_KEY`/`GPG_PASSPHRASE`, `CHOCOLATEY_API_KEY`,
42-
`PKG_SUBMIT_TOKEN` (for tap/bucket/winget-pkgs PRs). Until set, channels dry-run.
43-
44-
## Bump a release
43+
## Build a single channel locally
4544

4645
```bash
47-
pnpm version:set 0.1.1 # sync all app/package versions
48-
git tag v0.1.1 && git push origin v0.1.1
49-
# release.yml builds + publishes; submit-packages.yml refreshes manifests
46+
bash apps/desktop/scripts/build-release.sh v0.1.1 linux # tar.gz
47+
bash distribution/deb-rpm/build.sh v0.1.1 # .deb + .rpm (needs nfpm)
48+
bash distribution/appimage/build.sh v0.1.1 # .AppImage
49+
node scripts/submit-packages.mjs -v 0.1.1 -p all --dry-run
5050
```
51+
52+
## Secrets to actually publish
53+
54+
`AUR_SSH_KEY`, `GPG_PRIVATE_KEY`/`GPG_PASSPHRASE`, `CHOCOLATEY_API_KEY`,
55+
`SNAPCRAFT_STORE_CREDENTIALS`, `PKG_SUBMIT_TOKEN` (tap/bucket/winget-pkgs/Flathub
56+
PRs). Until set, channels dry-run.

‎distribution/appimage/build.sh‎

Lines changed: 35 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,35 @@
1+
#!/usr/bin/env bash
2+
# Build a universal-Linux AppImage from the linux release tarball.
3+
# Usage: distribution/appimage/build.sh <version> (expects dist/tronbrowser-linux-x64.tar.gz)
4+
set -euo pipefail
5+
6+
VERSION="${1:?usage: build.sh <version>}"
7+
ROOT="$(cd "$(dirname "${BASH_SOURCE[0]}")/../.." && pwd)"
8+
HERE="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
9+
TARBALL="$ROOT/dist/tronbrowser-linux-x64.tar.gz"
10+
[ -f "$TARBALL" ] || { echo "missing $TARBALL — run build-release.sh linux first" >&2; exit 1; }
11+
12+
appdir="$(mktemp -d)/TronBrowser.AppDir"
13+
mkdir -p "$appdir/usr/lib" "$appdir/usr/bin"
14+
tar -xzf "$TARBALL" -C "$appdir/usr/lib" # -> usr/lib/tronbrowser
15+
16+
# AppRun -> the launcher.
17+
cat > "$appdir/AppRun" <<'EOF'
18+
#!/bin/sh
19+
HERE="$(dirname "$(readlink -f "$0")")"
20+
exec "$HERE/usr/lib/tronbrowser/tronbrowser" "$@"
21+
EOF
22+
chmod +x "$appdir/AppRun"
23+
24+
cp "$HERE/tronbrowser.desktop" "$appdir/tronbrowser.desktop"
25+
if command -v rsvg-convert >/dev/null 2>&1; then
26+
rsvg-convert -w 256 -h 256 "$ROOT/apps/web/public/favicon.svg" -o "$appdir/tronbrowser.png"
27+
else
28+
cp "$ROOT/apps/web/public/favicon.svg" "$appdir/tronbrowser.svg"
29+
fi
30+
31+
tool=/tmp/appimagetool
32+
[ -x "$tool" ] || curl -sSfL "https://github.com/AppImage/appimagetool/releases/download/continuous/appimagetool-x86_64.AppImage" -o "$tool"
33+
chmod +x "$tool"
34+
ARCH=x86_64 "$tool" --appimage-extract-and-run "$appdir" "$ROOT/dist/TronBrowser-x86_64.AppImage"
35+
echo "built: $ROOT/dist/TronBrowser-x86_64.AppImage"
Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,10 @@
1+
[Desktop Entry]
2+
Type=Application
3+
Name=TronBrowser
4+
GenericName=Web Browser
5+
Comment=Privacy-first, AI-native browser (Ungoogled Chromium fork)
6+
Exec=tron %u
7+
Icon=tronbrowser
8+
Terminal=false
9+
Categories=Network;WebBrowser;
10+
MimeType=text/html;x-scheme-handler/http;x-scheme-handler/https;
Original file line numberDiff line numberDiff line change
@@ -1,13 +1,13 @@
11
#!/usr/bin/env bash
22
# Build .deb and .rpm from the linux release tarball using nfpm.
3-
# Usage: build-deb-rpm.sh <version> (expects dist/tronbrowser-linux-x64.tar.gz)
3+
# Usage: distribution/deb-rpm/build.sh <version> (expects dist/tronbrowser-linux-x64.tar.gz)
44
set -euo pipefail
55

6-
VERSION="${1:?usage: build-deb-rpm.sh <version>}"
7-
ROOT="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)"
6+
VERSION="${1:?usage: build.sh <version>}"
7+
ROOT="$(cd "$(dirname "${BASH_SOURCE[0]}")/../.." && pwd)"
8+
HERE="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
89
TARBALL="$ROOT/dist/tronbrowser-linux-x64.tar.gz"
910
[ -f "$TARBALL" ] || { echo "missing $TARBALL — run build-release.sh linux first" >&2; exit 1; }
10-
1111
command -v nfpm >/dev/null 2>&1 || { echo "nfpm not installed (https://nfpm.goreleaser.com)" >&2; exit 1; }
1212

1313
work="$(mktemp -d)"
@@ -16,14 +16,12 @@ tar -xzf "$TARBALL" -C "$work" # -> $work/tronbrowser
1616
TB_VERSION="${VERSION#v}"
1717
TB_ROOT="$work/tronbrowser"
1818

19-
# Render the config (nfpm doesn't reliably expand env in contents.src globs).
2019
rendered="$work/nfpm.yaml"
2120
sed -e "s|\${TB_VERSION}|${TB_VERSION}|g" -e "s|\${TB_ROOT}|${TB_ROOT}|g" \
22-
"$ROOT/packaging/nfpm.yaml" > "$rendered"
21+
"$HERE/nfpm.yaml" > "$rendered"
2322

2423
nfpm package -f "$rendered" -p deb -t "$ROOT/dist"
2524
nfpm package -f "$rendered" -p rpm -t "$ROOT/dist"
26-
2725
rm -rf "$work"
2826
echo "built deb + rpm:"
2927
ls -lh "$ROOT/dist"/*.deb "$ROOT/dist"/*.rpm 2>/dev/null | awk '{print " "$9" ("$5")"}'
Lines changed: 29 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,29 @@
1+
# Flatpak manifest. Build: flatpak-builder build dev.tronbrowser.TronBrowser.yml
2+
# Publish via Flathub PR. The launcher is sandboxed, so it uses flatpak-spawn to
3+
# run the host's Chromium (see the tron wrapper below).
4+
app-id: dev.tronbrowser.TronBrowser
5+
runtime: org.freedesktop.Platform
6+
runtime-version: '24.08'
7+
sdk: org.freedesktop.Sdk
8+
command: tron
9+
finish-args:
10+
- --share=network
11+
- --socket=wayland
12+
- --socket=fallback-x11
13+
- --device=dri
14+
- --filesystem=home
15+
# Allow running the host browser binary from inside the sandbox.
16+
- --talk-name=org.freedesktop.Flatpak
17+
modules:
18+
- name: tronbrowser
19+
buildsystem: simple
20+
build-commands:
21+
- mkdir -p /app/lib/tronbrowser
22+
- cp -r tronbrowser/. /app/lib/tronbrowser/
23+
- install -Dm755 tron-wrapper /app/bin/tron
24+
sources:
25+
- type: archive
26+
url: https://github.com/profullstack/tronbrowser.dev/releases/download/v0.1.1/tronbrowser-linux-x64.tar.gz
27+
sha256: __SHA256_LINUX__
28+
- type: file
29+
path: tron-wrapper

‎distribution/flatpak/tron-wrapper‎

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,4 @@
1+
#!/bin/sh
2+
# Flatpak entrypoint: the bundled launcher needs the HOST's Chromium, so run it
3+
# outside the sandbox via flatpak-spawn.
4+
exec flatpak-spawn --host /app/lib/tronbrowser/tronbrowser "$@"

‎distribution/freebsd/Makefile‎

Lines changed: 29 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,29 @@
1+
# FreeBSD port — www/tronbrowser. Consumes the GitHub release tarball.
2+
PORTNAME= tronbrowser
3+
DISTVERSION= 0.1.1
4+
CATEGORIES= www
5+
6+
MASTER_SITES= https://github.com/profullstack/tronbrowser.dev/releases/download/v${DISTVERSION}/
7+
DISTNAME= tronbrowser-linux-x64
8+
9+
MAINTAINER= security@profullstack.com
10+
COMMENT= Privacy-first, AI-native browser (Ungoogled Chromium fork)
11+
WWW= https://tronbrowser.dev
12+
13+
LICENSE= MIT
14+
LICENSE_FILE= ${WRKSRC}/LICENSE
15+
16+
RUN_DEPENDS= chrome:www/chromium
17+
18+
NO_BUILD= yes
19+
NO_ARCH= yes
20+
WRKSRC= ${WRKDIR}/tronbrowser
21+
22+
do-install:
23+
@${MKDIR} ${STAGEDIR}${PREFIX}/lib/tronbrowser
24+
(cd ${WRKSRC} && ${COPYTREE_SHARE} . ${STAGEDIR}${PREFIX}/lib/tronbrowser)
25+
@${CHMOD} +x ${STAGEDIR}${PREFIX}/lib/tronbrowser/tronbrowser
26+
${LN} -sf ${PREFIX}/lib/tronbrowser/tronbrowser ${STAGEDIR}${PREFIX}/bin/tron
27+
${LN} -sf ${PREFIX}/lib/tronbrowser/tronbrowser ${STAGEDIR}${PREFIX}/bin/tronbrowser
28+
29+
.include <bsd.port.mk>

0 commit comments

Comments
 (0)