Additive next to the opkg/24.10 lane — nothing existing changed. The same 4 packages (shaterd, shater-core, luci-app-shater, byedpi) are built through the official ImmortalWrt 25.12 apk-SDK and published as per-arch rolling releases apk-latest-<arch> / apk-<tag>-<arch> (x86_64, aarch64_cortex-a53). - ci/sdk-build-apk.sh: drives the 25.12 SDK inside debian:bookworm, compiles .apk, then `apk mkndx --root T --keys-dir T/keys --allow-untrusted --sign KEY --output packages.adb *.apk` — the exact form the OpenWrt 25.12 buildsystem uses (unsigned members, signed index). - ci/build-feed-apk.sh: per-arch runner entrypoint (same --volumes-from and artifact-order contract as ci/build-feed.sh). - ci/gen-apk-key.sh: one-shot EC (prime256v1) keypair generator; private half -> Gitea secret KEY_APK, public dist/shater-apk.pem committed. - release.yml: additive build-apk / release-apk jobs; `on:` triggers untouched (v* tags + workflow_dispatch); apk release tags deliberately non-`v*`. - docs-shater/INSTALL.md section 6, .gitignore (out-apk/), dist/shater-apk.pem. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
52 lines
2.3 KiB
Bash
Executable File
52 lines
2.3 KiB
Bash
Executable File
#!/bin/sh
|
|
# ci/gen-apk-key.sh — generate the Shater **apk** feed signing keypair (25.12 lane).
|
|
#
|
|
# apk (OpenWrt/ImmortalWrt 25.12+) verifies package indexes with EC keys
|
|
# (prime256v1 PEM), NOT usign — the existing usign identity
|
|
# (dist/shater-feed.pub, fp 5ac4b177689cb8e0) keeps signing the opkg/24.10 feed
|
|
# and is NOT touched by this script. This generates a SEPARATE, second identity:
|
|
#
|
|
# dist/shater-apk.key EC PRIVATE key. NEVER commit (dist/ is gitignored).
|
|
# Paste its full PEM contents into the Gitea repo secret
|
|
# KEY_APK (the apk analog of the usign secret KEY_BUILD).
|
|
# Then delete the local file (or keep it in a password
|
|
# manager as the offline backup — losing it means every
|
|
# deployed router must re-trust a new key).
|
|
# dist/shater-apk.pem PUBLIC key. Commit it next to shater-feed.pub:
|
|
# git add -f dist/shater-apk.pem
|
|
# (-f because /dist/ is gitignored). Routers install it
|
|
# as /etc/apk/keys/shater-apk.pem.
|
|
#
|
|
# Run ONCE. Refuses to overwrite: regenerating the key invalidates the trust of
|
|
# every router that already installed shater-apk.pem (same rule as D7 for the
|
|
# usign key).
|
|
set -eu
|
|
|
|
REPO="$(cd "$(dirname "$0")/.." && pwd)"
|
|
SEC="$REPO/dist/shater-apk.key"
|
|
PUB="$REPO/dist/shater-apk.pem"
|
|
|
|
command -v openssl >/dev/null 2>&1 || { echo "[apk-key] ERROR: openssl not found" >&2; exit 1; }
|
|
|
|
if [ -e "$SEC" ] || [ -e "$PUB" ]; then
|
|
echo "[apk-key] ERROR: $SEC or $PUB already exists." >&2
|
|
echo " Regenerating would invalidate every deployed router's trust." >&2
|
|
echo " Delete BOTH files manually if you REALLY mean to rotate the key." >&2
|
|
exit 1
|
|
fi
|
|
|
|
mkdir -p "$REPO/dist"
|
|
umask 077
|
|
# prime256v1 EC key — the exact form the OpenWrt 25.12 buildsystem generates for
|
|
# BUILD_KEY_APK_SEC and `apk mkndx --sign` consumes.
|
|
openssl ecparam -name prime256v1 -genkey -noout -out "$SEC"
|
|
openssl ec -in "$SEC" -pubout -out "$PUB" 2>/dev/null
|
|
chmod 0644 "$PUB"
|
|
|
|
echo "[apk-key] generated:"
|
|
echo " private: $SEC (-> Gitea secret KEY_APK; do NOT commit)"
|
|
echo " public : $PUB (-> git add -f dist/shater-apk.pem; routers: /etc/apk/keys/shater-apk.pem)"
|
|
echo
|
|
echo "[apk-key] public key:"
|
|
cat "$PUB"
|