Builds were dominated by re-fetching the ImmortalWrt 25.12 SDK tarball
(~300 MB) every run, and a stalled downloads.immortalwrt.org transfer wedged
the apk job for 40+ min (plain `wget -q`, no timeout — same class as the
elfutils hang).
- New ci/fetch-sdk.sh (runner-side): cache -> our durable `sdk-cache` release
mirror -> upstream with a stall-kill (curl --speed-limit 64K --speed-time 60
--max-time 1800) + 3 retries + zstd-magic/size validation; seeds the mirror
best-effort (github.token, non-fatal) so cold runs never touch upstream again.
A 40-min hang is now impossible; the in-container fallback wget also gets
--timeout=60 --tries=3.
- actions/cache@v3.3.2 (last release on the OLD cache API that Gitea act_runner
implements; v4/v3.4.x use the new GitHub cache service) for: SDK tarball, SDK
dl/ sources (hash of package Makefiles; PKG_HASH re-verified so a stale cache
can't leak a wrong source), Go mod+build (go.sum), npm node_modules
(package-lock.json) with build-shaterd.sh --fast, apt archives, built usign.
Degrades safely if the cache server is off — the SDK mirror is independent.
- concurrency group release-${github.ref} cancel-in-progress so a re-dispatch
cancels the stale run instead of piling up (tags stay isolated).
Signing (usign/apk), both keys, per-arch publish, manual triggers, LOCALMIRROR
and the scoped 4-package collection are unchanged.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
61 lines
2.4 KiB
Bash
61 lines
2.4 KiB
Bash
#!/bin/bash
|
|
# Make `usign` available on the CI runner so ci/make-index.sh can sign the opkg
|
|
# feed index. The OpenWrt SDK ships usign, but the index/signing step runs on the
|
|
# bare runner (outside the SDK container), so we build the tiny standalone tool
|
|
# from source (no libubox — it is intentionally dependency-free so it can
|
|
# bootstrap a build system). No-op if usign is already on PATH.
|
|
#
|
|
# Ported unchanged from Shater v0.1 (ci/install-usign.sh): usign is
|
|
# format-agnostic and the signing story is identical for the v0.2 4-package feed.
|
|
#
|
|
# CI cache: a previously-built binary is reused from $USIGN_CACHE (default:
|
|
# <repo>/.cache/tools — a workspace dir the workflow persists via actions/cache),
|
|
# skipping the apt + cmake + clone + build (~1 min). After a fresh build the
|
|
# binary is copied there so the NEXT run hits the cache. usign is a tiny static
|
|
# helper with no versioned protocol — a stale cached binary cannot mis-sign.
|
|
set -eu
|
|
|
|
REPO_ROOT="$(cd "$(dirname "$0")/.." && pwd)"
|
|
TOOLS="${USIGN_CACHE:-$REPO_ROOT/.cache/tools}"
|
|
|
|
# place <binary> — install onto PATH (system-wide if we can, else ~/bin)
|
|
place() {
|
|
local SUDO=""; [ "$(id -u)" = 0 ] || SUDO="sudo"
|
|
if $SUDO install -m0755 "$1" /usr/local/bin/usign 2>/dev/null; then
|
|
:
|
|
else
|
|
mkdir -p "$HOME/bin"
|
|
install -m0755 "$1" "$HOME/bin/usign"
|
|
echo "$HOME/bin" >> "${GITHUB_PATH:-/dev/null}"
|
|
export PATH="$HOME/bin:$PATH"
|
|
fi
|
|
}
|
|
|
|
if command -v usign >/dev/null 2>&1; then
|
|
echo "[usign] already present: $(command -v usign)"
|
|
exit 0
|
|
fi
|
|
|
|
if [ -x "$TOOLS/usign" ]; then
|
|
place "$TOOLS/usign"
|
|
echo "[usign] restored from cache: $(command -v usign || echo "$HOME/bin/usign")"
|
|
exit 0
|
|
fi
|
|
|
|
SUDO=""; [ "$(id -u)" = 0 ] || SUDO="sudo"
|
|
if ! command -v cmake >/dev/null 2>&1 || ! command -v cc >/dev/null 2>&1; then
|
|
$SUDO apt-get update -qq
|
|
$SUDO apt-get install -y -qq cmake gcc git
|
|
fi
|
|
|
|
tmp="$(mktemp -d)"
|
|
# Canonical source; fall back to the GitHub mirror if git.openwrt.org is flaky.
|
|
git clone --depth 1 https://git.openwrt.org/project/usign.git "$tmp/usign" \
|
|
|| git clone --depth 1 https://github.com/openwrt/usign.git "$tmp/usign"
|
|
( cd "$tmp/usign" && cmake -DCMAKE_BUILD_TYPE=Release . >/dev/null && make >/dev/null )
|
|
|
|
place "$tmp/usign/usign"
|
|
# seed the cache for the next run (best-effort)
|
|
mkdir -p "$TOOLS" 2>/dev/null && install -m0755 "$tmp/usign/usign" "$TOOLS/usign" 2>/dev/null || true
|
|
echo "[usign] built: $(command -v usign || echo "$HOME/bin/usign")"
|