The published feed is now usign-signed, so routers keep opkg's signature verification ON instead of needing --no-check-signature. - ci/install-usign.sh builds the standalone usign on the runner (the index steps run on the bare runner, not in the SDK container). - ci/make-index.sh signs Packages -> Packages.sig with the secret key from the Gitea repo secret KEY_BUILD; it now FAILS the build if KEY_BUILD is set but usign is missing/broken, rather than silently shipping an unsigned feed. - build.yml installs usign in both the per-arch build and the combined-index release step, passes KEY_BUILD to the release step, and publishes the public key (dist/shater-feed.pub) as the release asset shater-feed.pub. - Setup is now: install the public key once into /etc/opkg/keys/<fingerprint>, then plain opkg update/install/upgrade with check_signature left on. Verified locally on the VM: usign -S/-V round-trips, and with check_signature=1 and only the signed feed, `opkg update` + `opkg install luci-app-shater` succeed with no --no-check-signature. FEED.md/README updated (key rotation documented). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01LLthkP2S8WAfxu7fcYbPfE
3 lines
100 B
Plaintext
3 lines
100 B
Plaintext
untrusted comment: shater feed signing key
|
|
RWRaxLF3aJy44JbcxSFujtrFFEQ8lIsnTkd1K5TdjIhdlC2c0wa0fv4V
|