Both routers are past opkg: mini_router runs ImmortalWrt 25.12.1 and main_router OpenWrt 25.12.0, both with apk-tools 3.0.5, and main_router has no `opkg` binary at all. The 24.10 lane was building and signing a feed no device could consume. Removed jobs `build` and `release` with the scripts only they called (ci/build-feed.sh, ci/sdk-build.sh, ci/make-index.sh, ci/install-usign.sh) and the usign trust anchor dist/shater-feed.pub. A committed public key is an instruction: it invites the old install path for a feed that is no longer produced. The key is retired, not revoked -- git history keeps it, KEY_BUILD still holds the secret half, and a usign secret contains its own public half, so the identity is reconstructible if a 24.10 device ever needs serving. D7 is marked SUPERSEDED by the new D22 rather than deleted. Separately: the rolling `apk-latest-<arch>` release was frozen at 0.2.0 from 2026-07-24 while every tag run published its versioned release correctly. The publish loop was an either/or -- `TAG=apk-latest-<arch>` when VER=latest (workflow_dispatch only), ELSE `TAG=apk-<ver>-<arch>` -- so a `v*` tag run never touched the rolling pointer. Asset replacement was never the problem; ci/gitea-release.sh already deletes before recreating. A router pinned to the rolling URL sat on 0.2.0 while `apk update` reported success: silent staleness, the failure mode this repo keeps having to close. The rolling pointer is now published on EVERY run, tag runs included, and a new assert reads the release back over the API afterwards: our three tag-versioned packages at the built version plus the index and the key must be present (exit 13), and no package asset at any other version may survive (exit 14). Same class of check as sdk-build-apk.sh's package-version assert, added for the same reason -- the previous failure mode was silent. KEY_BUILD can now be deleted from the Gitea repo secrets; nothing references it. Docs state plainly that mini_router is deliberately pinned to a versioned URL and that the hand-edit per release is the price of pinning. Known consequence: the x86_64 QEMU testbed is still OpenWrt 24.10.3 and can no longer install our packages. Its 25.12 rebuild is in flight separately. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01H4PcWfrBRyg4eWN58axaGN
91 lines
1.9 KiB
Plaintext
91 lines
1.9 KiB
Plaintext
# -- shater overlay -----------------------------------------------
|
|
# testbed downloads / VM images / SDKs (agent-managed, large, machine-local)
|
|
testbed/
|
|
*.img
|
|
*.img.gz
|
|
*.tar.zst
|
|
*.tar.gz
|
|
*.zip
|
|
*.qcow2
|
|
*.vmdk
|
|
|
|
# build outputs
|
|
*.ipk
|
|
*.apk
|
|
bin/
|
|
node_modules/
|
|
out/
|
|
out-apk/
|
|
|
|
# CI caches (SDK tarballs, dl/ sources, apt archives, prebuilt tools) —
|
|
# persisted between runs by actions/cache, never committed
|
|
.cache/
|
|
|
|
# editor / os
|
|
.DS_Store
|
|
Thumbs.db
|
|
*.swp
|
|
|
|
# go build artifacts
|
|
*.exe
|
|
|
|
# windows reserved-name junk from stray > NUL redirects
|
|
NUL
|
|
nul
|
|
|
|
# playwright MCP screenshots/snapshots
|
|
.playwright-mcp/
|
|
|
|
# working-session screenshots dropped in the repo root (not shipped docs)
|
|
/*.png
|
|
|
|
# throwaway build binaries / scratch staged under tmp/
|
|
/tmp/
|
|
|
|
# -- upstream sing-box-lx -----------------------------------------
|
|
/.idea/
|
|
.idea/
|
|
/vendor/
|
|
/*.json
|
|
/*.srs
|
|
/*.db
|
|
/site/
|
|
/build/
|
|
/*.jar
|
|
/*.aar
|
|
/*.xcframework/
|
|
/experimental/libbox/*.aar
|
|
/experimental/libbox/*.xcframework/
|
|
/experimental/libbox/*.nupkg
|
|
/sing-box
|
|
/sing-box.exe
|
|
/config.d/
|
|
/venv/
|
|
/test/cache.db
|
|
|
|
# feed artifacts (the tracked apk trust anchor dist/shater-apk.pem is force-added)
|
|
/dist/
|
|
|
|
# local agent config (CLAUDE.md is deliberately tracked; .claude local settings are not)
|
|
/.claude/
|
|
|
|
# panel SPA embedded into shaterd: build copies panel/dist/* into
|
|
# shater/panel/webroot/; those artifacts are gitignored, the .gitkeep marker
|
|
# (which keeps the dir embeddable when the SPA isn't built) stays tracked.
|
|
/shater/panel/webroot/*
|
|
!/shater/panel/webroot/.gitkeep
|
|
|
|
# prebuilt shaterd binaries staged for the openwrt/shaterd package by
|
|
# scripts/build-shaterd.sh — release artifacts, not source. The .gitkeep marker
|
|
# (which keeps the dir present so the package build can stage into it) stays tracked.
|
|
/openwrt/shaterd/files/shaterd-*
|
|
!/openwrt/shaterd/files/.gitkeep
|
|
|
|
# throwaway VM traffic generator (never shipped)
|
|
shater/cmd/trafgen/
|
|
errors.log
|
|
|
|
# MemPalace per-project files (issue #185)
|
|
mempalace.yaml
|
|
entities.json
|