<feed xmlns='http://www.w3.org/2005/Atom'>
<title>labUI.git/core/version.py, branch main</title>
<subtitle>Data acquisition program written in Python for use with serial communication devices.
</subtitle>
<id>https://git.kolset.xyz/labUI.git/atom?h=main</id>
<link rel='self' href='https://git.kolset.xyz/labUI.git/atom?h=main'/>
<link rel='alternate' type='text/html' href='https://git.kolset.xyz/labUI.git/'/>
<updated>2026-08-04T21:51:33Z</updated>
<entry>
<title>Fixed version number to be v0 for pre-release</title>
<updated>2026-08-04T21:51:33Z</updated>
<author>
<name>Christian Kolset</name>
<email>ckolset@colostate.edu</email>
</author>
<published>2026-08-04T21:51:33Z</published>
<link rel='alternate' type='text/html' href='https://git.kolset.xyz/labUI.git/commit/?id=4a77f5825efe2905e22998cd784983eb914c1fc2'/>
<id>urn:sha1:4a77f5825efe2905e22998cd784983eb914c1fc2</id>
<content type='text'>
</content>
</entry>
<entry>
<title>Add PyInstaller packaging and tufup-based auto-update pipeline</title>
<updated>2026-07-31T21:52:28Z</updated>
<author>
<name>Christian Kolset</name>
<email>ckolset@colostate.edu</email>
</author>
<published>2026-07-31T21:52:28Z</published>
<link rel='alternate' type='text/html' href='https://git.kolset.xyz/labUI.git/commit/?id=bfbdd0c19910f464e779fa64cc0ec8590f8e37c1'/>
<id>urn:sha1:bfbdd0c19910f464e779fa64cc0ec8590f8e37c1</id>
<content type='text'>
Full pipeline, verified end-to-end against the real installed tufup
0.10.0 API (initial docs/summaries turned out inaccurate in places —
e.g. the apply method is download_and_apply_update, not update;
confirmed by inspecting installed package source directly rather than
trusting docs alone):

- core/version.py: single-source app version constant.
- labdaq.spec: PyInstaller onedir build (must be onedir, not onefile —
  tufup replaces individual files in the install dir on update).
  Bundles ui/*.qss, plugins/ (needed for runtime plugin discovery), and
  repository/metadata/root.json once repo_init.py has produced one.
  Built and smoke-tested: the frozen exe launches and stays running.
- scripts/release/{repo_init,repo_release}.py: maintainer-run release
  tooling using tufup.repo.Repository, manual local signing (keys never
  touch CI). Both actually run end-to-end during development of this
  feature against a real build, not just written and assumed correct.
  Longer expiration_days than tufup-example's CI-oriented defaults
  (targets/snapshot/timestamp 90d instead of 7d/7d/1d), since we're
  signing manually, not on an automated daily schedule — see
  scripts/release/README.md for the re-signing cadence this still
  requires even between releases.
- core/updater.py: thin Client wrapper. Refuses to run outside a
  frozen build (getattr(sys, "frozen", False)) since there's no
  installed bundle for tufup to update in `python main.py` dev mode.
  Bootstraps the bundled root.json into the metadata cache dir on
  first run — tuf.ngclient.Updater loads root.json from local disk on
  construction, it does not fetch it remotely by design (the root of
  trust can't come from the same server being verified).
- core/app_settings.py: factored out app_data_dir() (was inline in
  _settings_path()) so the updater's metadata/target cache dirs live
  in the same per-user location as settings.json, deliberately outside
  the install directory an update can replace/move.
- Settings &gt; General: version display + "Check for Updates" button,
  manual-only per discussion (no silent background network calls or
  surprise restarts for a lab-instrument-control app).

Metadata/targets are hosted on this repo's "updates" GitHub Release —
a fixed tag, not a normal per-version tag, because TUF's top-level
metadata needs a stable URL across app versions. No such GitHub-Releases-
hosting example exists in tufup or tufup-example; verified this by
fetching tufup-example's actual GitHub Actions workflow file directly
after a web search wrongly suggested one existed — the design here is
ours, not copied from upstream.

Not yet done, deliberately left for the user: running repo_init.py for
real (generates production signing keys), and creating the actual
"updates" GitHub Release. Both are irreversible-ish, security-sensitive,
externally-visible actions outside what should happen without the
user directly driving them.

Co-Authored-By: Claude Sonnet 5 &lt;noreply@anthropic.com&gt;
</content>
</entry>
</feed>
