The subtree is in place, so everything that used to fetch and patch core at
build time now just copies it.
tools/build.sh copies wordpress/ — no download, no checksum step,
because there is nothing to fetch and nothing to
trust that is not already in the repository
docker/Dockerfile COPY wordpress/ instead of curl + sha256 + patch;
the build args and the `patch` package are gone
docker-compose.yml no WP_VERSION / WP_URL / WP_SHA256 to keep in step
tools/update-wordpress.sh is rewritten around what the subtree makes
possible. It imports the pristine release onto sirius-press/wordpress-upstream
and then `git subtree merge`s that branch, which three-way merges upstream
against the fork's own commit. A patch either applies with fuzz and hopes or
fails and leaves you re-deriving the change by hand; a merge conflict is
resolved once, in the file, and the next release merges against the
resolution.
patches/ survives as documentation rather than mechanism, and is now
generated: tools/refresh-patches.sh diffs the subtree against the pristine
import and rewrites the directory, with --check for CI. It answers the
question anyone auditing a fork asks first — what exactly did you change
inside WordPress? — in a minute, which `git log wordpress/` cannot, because
that log is mostly upstream imports. Generated documentation stays true; a
hand-maintained record of a core diff drifts, and a stale one is worse than
none because people trust it.
One test change worth noting: the syntax sweep no longer walks all of
wordpress/. It lints the fork's own PHP plus every core file patches/ says
the fork touches, which keeps the suite at seven seconds instead of a minute
while still covering the only core file that can break.
169 lines
6.1 KiB
Markdown
169 lines
6.1 KiB
Markdown
# Installing Sirius Press
|
|
|
|
Three ways in, depending on what you have. All of them end at the same place:
|
|
a WordPress site where accounts are wallets and every page is mirrored to your
|
|
BCNR name.
|
|
|
|
---
|
|
|
|
## A VPS, with Docker (recommended)
|
|
|
|
On a fresh Ubuntu 22.04 or 24.04 box:
|
|
|
|
```bash
|
|
curl -fsSL https://silentmode.st/sirius-press/install.sh | sudo bash
|
|
```
|
|
|
|
It installs Docker from the distribution's own packages if it is missing,
|
|
clones the repository to `/opt/sirius-press`, generates database passwords and
|
|
a `SIRIUS_PRESS_KEY`, builds the image and starts the stack. Then it waits
|
|
until the site answers and prints the setup URL.
|
|
|
|
About five minutes on a 1 GB VPS, nearly all of it compiling PHP extensions.
|
|
|
|
If you would rather read the script before running it as root — a reasonable
|
|
instinct — it is [`install.sh`](../install.sh), and it is about a hundred lines.
|
|
|
|
### By hand, if you prefer
|
|
|
|
```bash
|
|
git clone https://code.silentmode.st/silentmode/sirius-press.git /opt/sirius-press
|
|
cd /opt/sirius-press/docker
|
|
cp .env.example .env
|
|
# edit .env: set DB_PASSWORD and DB_ROOT_PASSWORD at minimum
|
|
docker compose up -d --build
|
|
```
|
|
|
|
### Finishing setup
|
|
|
|
Open `http://your-server/wp-admin/install.php`.
|
|
|
|
The screen is the usual WordPress one with a single change: where it asked for
|
|
your email, it asks for your **wallet address**. You can paste one or leave it
|
|
blank and attach a wallet afterwards from your profile — which is actually the
|
|
better order, because the profile screen makes you *prove* the address by
|
|
signing, and the installer cannot.
|
|
|
|
Set a password too. It is the only way into the site until a wallet is
|
|
attached, and you should turn it off afterwards (**Sirius Press → Sign-in**).
|
|
|
|
---
|
|
|
|
## Shared hosting
|
|
|
|
Download `sirius-press-<version>.zip` from
|
|
[the releases page](https://code.silentmode.st/silentmode/sirius-press/releases),
|
|
check it against the published `.sha256`, and upload its contents the way you
|
|
would upload WordPress — because that is what it is, patched, with the plugins
|
|
already in place.
|
|
|
|
Then create a database and run through `wp-admin/install.php`.
|
|
|
|
Before you start, confirm the host gives you **GMP or BCMath**. Without one of
|
|
them the fork cannot verify a signature and refuses to activate. Most hosts
|
|
have BCMath; ask for GMP if you can get it, since it is roughly twenty times
|
|
faster and signature verification sits on the login path.
|
|
|
|
### Building the zip yourself
|
|
|
|
```bash
|
|
tools/build.sh --zip
|
|
```
|
|
|
|
Copies the vendored WordPress out of `wordpress/`, adds the plugins, and
|
|
writes `dist/sirius-press-<version>.zip` alongside its checksum. Nothing is
|
|
downloaded — core is in the repository.
|
|
|
|
---
|
|
|
|
## An existing WordPress site
|
|
|
|
Sirius Press can be added to a site you already run, without the core patch.
|
|
You lose only the setup-wizard change, which you have already been through.
|
|
|
|
1. Copy the four directories in `plugins/` into `wp-content/plugins/`.
|
|
2. Copy `mu-plugins/sirius-press-bootstrap.php` into `wp-content/mu-plugins/`
|
|
(create the directory if it does not exist).
|
|
3. Activate **Sirius Press Core** first, then Auth, Publishing and
|
|
Compatibility.
|
|
4. Attach a wallet to your own account at **Users → Profile**.
|
|
5. Turn passwords off at **Sirius Press → Sign-in** — but read the list of
|
|
accounts without wallets on that screen first. Every one of them is somebody
|
|
who will be locked out.
|
|
|
|
Existing accounts keep working with passwords until each attaches a wallet.
|
|
Nothing is migrated, deleted or rewritten.
|
|
|
|
---
|
|
|
|
## Pointing your name at it
|
|
|
|
See **[bcnr-records.md](bcnr-records.md)**. The short version: set your name's
|
|
`ip` record to the server's address, or its `p` record to a hostname that
|
|
resolves there.
|
|
|
|
---
|
|
|
|
## After it is up
|
|
|
|
Three things, in this order:
|
|
|
|
1. **Sirius Press → Settings**: set the BCNR name this site publishes under,
|
|
and the network (mainnet or chipnet).
|
|
2. **Users → Profile**: attach your wallet by signing. Check the address that
|
|
appears is the one you expect.
|
|
3. **Sirius Press → Sign-in**: turn off password sign-in once every account
|
|
that needs access has a wallet.
|
|
|
|
Then decide how exports get signed — see [publishing.md](publishing.md). The
|
|
default is manual, meaning nothing sensitive is stored on the server and you
|
|
sign from your browser when you publish.
|
|
|
|
---
|
|
|
|
## Upgrading
|
|
|
|
```bash
|
|
cd /opt/sirius-press
|
|
git pull
|
|
cd docker && docker compose build && docker compose up -d
|
|
```
|
|
|
|
Core and the fork's plugins both come from the image, so this upgrades both.
|
|
Your uploads, your database, your other plugins and themes, and
|
|
`wp-config.php` live in volumes and are untouched.
|
|
|
|
This is why the document root is refilled from the image on every start rather
|
|
than being a volume of its own — the usual WordPress-in-Docker layout pins core
|
|
at whatever version first created the volume, and turns every security release
|
|
into a manual migration.
|
|
|
|
---
|
|
|
|
## When it does not work
|
|
|
|
**The site does not answer.**
|
|
`cd /opt/sirius-press/docker && docker compose logs -f app`. The most common
|
|
cause on a first run is the database still initialising; the entrypoint waits
|
|
sixty seconds and then starts anyway, so give it another minute.
|
|
|
|
**"Sirius Press needs either the GMP or the BCMath PHP extension."**
|
|
The host has neither. Nothing in the fork works without one. On Debian or
|
|
Ubuntu outside Docker: `apt install php-gmp && systemctl restart php-fpm`.
|
|
|
|
**Signing in does nothing, and no error appears.**
|
|
JavaScript did not load, or the page is being served over plain HTTP where
|
|
WebCrypto is unavailable. Open "Paste a signature instead" and use any wallet —
|
|
that path needs no JavaScript at all.
|
|
|
|
**"That signature does not match the text this site asked you to sign."**
|
|
Usually the challenge was copied without its trailing blank line, or with a
|
|
line wrapped. Copy it straight out of the box with the copy button rather than
|
|
selecting it by hand.
|
|
|
|
**Exports fail with "the stored publishing key is not the address that
|
|
currently owns this name."**
|
|
The phrase on the server derives a different address than the one holding the
|
|
name's NFT. **Sirius Press → Settings** shows both side by side. The usual
|
|
cause is a wallet created on a different derivation path — see
|
|
[publishing.md](publishing.md#derivation-paths).
|