Files
shater/ci/gen-apk-key.sh
T
omarandClaude Opus 4.8 cd598b0fe2 feat(ci): add apk (ImmortalWrt/BananaWRT 25.12) release lane
Additive next to the opkg/24.10 lane — nothing existing changed. The same 4
packages (shaterd, shater-core, luci-app-shater, byedpi) are built through the
official ImmortalWrt 25.12 apk-SDK and published as per-arch rolling releases
apk-latest-<arch> / apk-<tag>-<arch> (x86_64, aarch64_cortex-a53).

- ci/sdk-build-apk.sh: drives the 25.12 SDK inside debian:bookworm, compiles
  .apk, then `apk mkndx --root T --keys-dir T/keys --allow-untrusted
  --sign KEY --output packages.adb *.apk` — the exact form the OpenWrt 25.12
  buildsystem uses (unsigned members, signed index).
- ci/build-feed-apk.sh: per-arch runner entrypoint (same --volumes-from and
  artifact-order contract as ci/build-feed.sh).
- ci/gen-apk-key.sh: one-shot EC (prime256v1) keypair generator; private half
  -> Gitea secret KEY_APK, public dist/shater-apk.pem committed.
- release.yml: additive build-apk / release-apk jobs; `on:` triggers untouched
  (v* tags + workflow_dispatch); apk release tags deliberately non-`v*`.
- docs-shater/INSTALL.md section 6, .gitignore (out-apk/), dist/shater-apk.pem.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-23 16:11:23 +03:00

52 lines
2.3 KiB
Bash
Executable File

#!/bin/sh
# ci/gen-apk-key.sh — generate the Shater **apk** feed signing keypair (25.12 lane).
#
# apk (OpenWrt/ImmortalWrt 25.12+) verifies package indexes with EC keys
# (prime256v1 PEM), NOT usign — the existing usign identity
# (dist/shater-feed.pub, fp 5ac4b177689cb8e0) keeps signing the opkg/24.10 feed
# and is NOT touched by this script. This generates a SEPARATE, second identity:
#
# dist/shater-apk.key EC PRIVATE key. NEVER commit (dist/ is gitignored).
# Paste its full PEM contents into the Gitea repo secret
# KEY_APK (the apk analog of the usign secret KEY_BUILD).
# Then delete the local file (or keep it in a password
# manager as the offline backup — losing it means every
# deployed router must re-trust a new key).
# dist/shater-apk.pem PUBLIC key. Commit it next to shater-feed.pub:
# git add -f dist/shater-apk.pem
# (-f because /dist/ is gitignored). Routers install it
# as /etc/apk/keys/shater-apk.pem.
#
# Run ONCE. Refuses to overwrite: regenerating the key invalidates the trust of
# every router that already installed shater-apk.pem (same rule as D7 for the
# usign key).
set -eu
REPO="$(cd "$(dirname "$0")/.." && pwd)"
SEC="$REPO/dist/shater-apk.key"
PUB="$REPO/dist/shater-apk.pem"
command -v openssl >/dev/null 2>&1 || { echo "[apk-key] ERROR: openssl not found" >&2; exit 1; }
if [ -e "$SEC" ] || [ -e "$PUB" ]; then
echo "[apk-key] ERROR: $SEC or $PUB already exists." >&2
echo " Regenerating would invalidate every deployed router's trust." >&2
echo " Delete BOTH files manually if you REALLY mean to rotate the key." >&2
exit 1
fi
mkdir -p "$REPO/dist"
umask 077
# prime256v1 EC key — the exact form the OpenWrt 25.12 buildsystem generates for
# BUILD_KEY_APK_SEC and `apk mkndx --sign` consumes.
openssl ecparam -name prime256v1 -genkey -noout -out "$SEC"
openssl ec -in "$SEC" -pubout -out "$PUB" 2>/dev/null
chmod 0644 "$PUB"
echo "[apk-key] generated:"
echo " private: $SEC (-> Gitea secret KEY_APK; do NOT commit)"
echo " public : $PUB (-> git add -f dist/shater-apk.pem; routers: /etc/apk/keys/shater-apk.pem)"
echo
echo "[apk-key] public key:"
cat "$PUB"