Files
omarandClaude Opus 5 f86501bf77 ci!: drop the opkg lane — apk only, and fix the stale rolling release
Both routers are past opkg: mini_router runs ImmortalWrt 25.12.1 and
main_router OpenWrt 25.12.0, both with apk-tools 3.0.5, and main_router has
no `opkg` binary at all. The 24.10 lane was building and signing a feed no
device could consume.

Removed jobs `build` and `release` with the scripts only they called
(ci/build-feed.sh, ci/sdk-build.sh, ci/make-index.sh, ci/install-usign.sh)
and the usign trust anchor dist/shater-feed.pub. A committed public key is
an instruction: it invites the old install path for a feed that is no longer
produced. The key is retired, not revoked -- git history keeps it, KEY_BUILD
still holds the secret half, and a usign secret contains its own public half,
so the identity is reconstructible if a 24.10 device ever needs serving.
D7 is marked SUPERSEDED by the new D22 rather than deleted.

Separately: the rolling `apk-latest-<arch>` release was frozen at 0.2.0 from
2026-07-24 while every tag run published its versioned release correctly.
The publish loop was an either/or -- `TAG=apk-latest-<arch>` when VER=latest
(workflow_dispatch only), ELSE `TAG=apk-<ver>-<arch>` -- so a `v*` tag run
never touched the rolling pointer. Asset replacement was never the problem;
ci/gitea-release.sh already deletes before recreating. A router pinned to
the rolling URL sat on 0.2.0 while `apk update` reported success: silent
staleness, the failure mode this repo keeps having to close.

The rolling pointer is now published on EVERY run, tag runs included, and a
new assert reads the release back over the API afterwards: our three
tag-versioned packages at the built version plus the index and the key must
be present (exit 13), and no package asset at any other version may survive
(exit 14). Same class of check as sdk-build-apk.sh's package-version assert,
added for the same reason -- the previous failure mode was silent.

KEY_BUILD can now be deleted from the Gitea repo secrets; nothing references
it. Docs state plainly that mini_router is deliberately pinned to a
versioned URL and that the hand-edit per release is the price of pinning.

Known consequence: the x86_64 QEMU testbed is still OpenWrt 24.10.3 and can
no longer install our packages. Its 25.12 rebuild is in flight separately.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01H4PcWfrBRyg4eWN58axaGN
2026-07-25 18:46:21 +03:00

91 lines
1.9 KiB
Plaintext

# -- shater overlay -----------------------------------------------
# testbed downloads / VM images / SDKs (agent-managed, large, machine-local)
testbed/
*.img
*.img.gz
*.tar.zst
*.tar.gz
*.zip
*.qcow2
*.vmdk
# build outputs
*.ipk
*.apk
bin/
node_modules/
out/
out-apk/
# CI caches (SDK tarballs, dl/ sources, apt archives, prebuilt tools) —
# persisted between runs by actions/cache, never committed
.cache/
# editor / os
.DS_Store
Thumbs.db
*.swp
# go build artifacts
*.exe
# windows reserved-name junk from stray > NUL redirects
NUL
nul
# playwright MCP screenshots/snapshots
.playwright-mcp/
# working-session screenshots dropped in the repo root (not shipped docs)
/*.png
# throwaway build binaries / scratch staged under tmp/
/tmp/
# -- upstream sing-box-lx -----------------------------------------
/.idea/
.idea/
/vendor/
/*.json
/*.srs
/*.db
/site/
/build/
/*.jar
/*.aar
/*.xcframework/
/experimental/libbox/*.aar
/experimental/libbox/*.xcframework/
/experimental/libbox/*.nupkg
/sing-box
/sing-box.exe
/config.d/
/venv/
/test/cache.db
# feed artifacts (the tracked apk trust anchor dist/shater-apk.pem is force-added)
/dist/
# local agent config (CLAUDE.md is deliberately tracked; .claude local settings are not)
/.claude/
# panel SPA embedded into shaterd: build copies panel/dist/* into
# shater/panel/webroot/; those artifacts are gitignored, the .gitkeep marker
# (which keeps the dir embeddable when the SPA isn't built) stays tracked.
/shater/panel/webroot/*
!/shater/panel/webroot/.gitkeep
# prebuilt shaterd binaries staged for the openwrt/shaterd package by
# scripts/build-shaterd.sh — release artifacts, not source. The .gitkeep marker
# (which keeps the dir present so the package build can stage into it) stays tracked.
/openwrt/shaterd/files/shaterd-*
!/openwrt/shaterd/files/.gitkeep
# throwaway VM traffic generator (never shipped)
shater/cmd/trafgen/
errors.log
# MemPalace per-project files (issue #185)
mempalace.yaml
entities.json