COPR repository
Alongside the self-hosted dnf repository of nfpm-built binary packages, LOTA is
intended to be published through COPR. COPR would rebuild the subpackages --
lota-agent, lota-verifier, lota-attest-ca, lota-sdk and
lota-sdk-devel -- from source in a clean chroot for each target Fedora and
EPEL release, which both validates the build across releases and hosts a signed
dnf repository operators can enable directly.
Note
The COPR project is not published yet, so the commands below do not work
today. The spec (packaging/rpm/lota.spec) and the .copr/Makefile
entry point are in the tree, so the project is ready to be created; until
then, build from source with make srpm or use the self-hosted signed
Signed dnf repository.
Installing (once the project is published)
The COPR project will live under the szymon-wilczek COPR account (which is
distinct from the szymonwilczek GitHub handle):
sudo dnf copr enable szymon-wilczek/lota
sudo dnf install lota-agent
The agent still fails closed and is not started by the package. Complete the
host bring-up with lota-install as for any other install path; see
LOTA production bring-up.
How it is built
COPR invokes make -f .copr/Makefile srpm, which delegates to the top-level
make srpm target. That archives the current commit, drops it into
packaging/rpm/lota.spec and builds a source RPM; COPR then rebuilds it in
the chroot. The same make srpm runs locally for a quick check.
Two properties of the spec matter:
External network must be enabled on the COPR project. The Go services (verifier, attest-CA) are not vendored, so the workspace build fetches their modules read-only from the proxy during
%build.No debuginfo subpackage.
debug_packageis disabled because rpm's debuginfo extraction strips the binaries, but the agent binary is fsverity-measured and its hash is pinned, so it must ship exactly as built.
Because the chroot build runs rpmbuild's automatic dependency generator, the library Requires are derived from the binaries' sonames rather than listed by hand as in the nfpm path. The package contents are otherwise identical to the nfpm packages; COPR is the from-source, multi-release mirror of the same deliverables.