release / aarch64_cortex-a53 (push) Successful in 7m3s
release / x86_64 (push) Successful in 3m13s
release / apk aarch64_cortex-a53 (push) Failing after 4m34s
release / apk x86_64 (push) Failing after 2m35s
release / release (push) Successful in 8s
release / release apk (push) Successful in 5s
- ci/make-index.sh: set -e → set -euo pipefail so a failing sha256sum|cut in the signed Packages index can't mask an empty SHA256. Script survives -u (all vars use :? or :- defaults). - .github/deb2ipk.sh: quote $2/$DEB_NAME/output, derive the deb name from the copied file via basename instead of parsing `ls *.deb` (glob-fragile), add a trap-based tmpdir cleanup, and set -euo pipefail. bash -n clean on both. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
40 lines
2.0 KiB
Bash
40 lines
2.0 KiB
Bash
#!/bin/bash
|
|
# Build the opkg feed index (Packages + Packages.gz) with SHA256 for a dir of
|
|
# .ipk files, then optionally usign-sign it if $KEY_BUILD (the Gitea repo secret)
|
|
# is set and usign is present. Arg $1 = feed dir.
|
|
#
|
|
# Ported from Shater v0.1 (ci/make-index.sh), unchanged. It is package-count and
|
|
# package-name agnostic: it indexes whatever .ipk are in the dir, so it serves
|
|
# BOTH the per-arch feed built by ci/build-feed.sh AND the combined release feed
|
|
# assembled in the release job (shaterd + byedpi per-arch, shater-core +
|
|
# luci-app-shater = _all). opkg filters by Architecture at install time, so one
|
|
# combined URL serves every device.
|
|
#
|
|
# Feed format: opkg `src/gz` (.ipk + text Packages index, usign signature).
|
|
# OpenWrt 24.10 (our SDK) still uses opkg; apk arrives at 25.12. The committed
|
|
# trust anchor dist/shater-feed.pub is a usign (Ed25519) key, matching this.
|
|
set -euo pipefail
|
|
OUT="${1:?feed dir required}"; cd "$OUT"
|
|
: > Packages
|
|
for ipk in *.ipk; do
|
|
[ -e "$ipk" ] || continue
|
|
ctrl=$(tar -xzOf "$ipk" ./control.tar.gz | tar -xzO ./control)
|
|
sz=$(wc -c < "$ipk"); sha=$(sha256sum "$ipk" | cut -d' ' -f1)
|
|
printf '%s\n' "$ctrl" | sed '/^[[:space:]]*$/d' >> Packages
|
|
printf 'Filename: %s\nSize: %s\nSHA256sum: %s\n\n' "$ipk" "$sz" "$sha" >> Packages
|
|
done
|
|
gzip -kf Packages
|
|
|
|
if [ -n "${KEY_BUILD:-}" ]; then
|
|
# Signing was requested — a missing/broken signer must FAIL the build, not
|
|
# silently ship an unsigned feed that routers with check_signature on reject.
|
|
command -v usign >/dev/null 2>&1 || { echo "[index] ERROR: KEY_BUILD set but usign not found" >&2; exit 1; }
|
|
umask 077; printf '%s\n' "$KEY_BUILD" > /tmp/usign.sec
|
|
usign -S -m Packages -s /tmp/usign.sec || { rm -f /tmp/usign.sec; echo "[index] ERROR: usign signing failed" >&2; exit 1; }
|
|
rm -f /tmp/usign.sec
|
|
echo "[index] signed -> Packages.sig ($(head -1 Packages.sig))"
|
|
else
|
|
echo "[index] no KEY_BUILD -> UNSIGNED feed (opkg needs check_signature off, or set the secret)"
|
|
fi
|
|
echo "[index] contents:"; ls -l
|