This repository tracks the Fedora Forgejo dist-git package and carries a small EL10-oriented delta for PAM authentication.
The package adds:
- the Forgejo
pambuild tag; - the minimum service capabilities required by
pam_unix; - a local SELinux policy for the
unix_chkpwdhelper; - managed
/etc/shadowread access with uninstall cleanup; - a fix for Forgejo init secret generation.
The RPM release uses the pam1 suffix so it does not collide with Fedora or
EPEL builds from the same source version.
mainfollows the current Fedora stable packaging baseline.rawhidefollows the Fedora Rawhide packaging baseline.
Both branches currently use Fedora commit ced1aa24, Forgejo 15.0.7.
COPR must use the SCM make_srpm source method. Set the spec file to
forgejo.spec; .copr/Makefile downloads the signed upstream sources, checks
the Fedora SHA-512 values, expands RPM auto-spec fields, and creates an SRPM.
The local Codex configuration exposes the official copr-mcp server from the
pinned commit below. .codex/config.toml is intentionally local and untracked.
https://github.com/fedora-copr/copr-mcp@7d804b835c6856beda6966366c600044265c6e40
copr-mcp can manage projects and inspect builds. Initial SCM package setup
still requires copr-cli add-package-scm because this MCP revision does not
expose SCM package creation.
This package grants the forgejo service access needed for system PAM. Review
the systemd drop-in, SELinux module, and /etc/shadow ACL before deployment.
Test upgrades in a separate environment and keep a database and configuration
backup. This repository does not change a running Forgejo instance.
The upstream packaging source is the Fedora Forgejo dist-git.