Public Access
OTA step 2: signing key, Update File builder, push client
- scripts/ota_keygen.sh: ECDSA P-256 key pair; the private key goes to ~/.config/roro9stack/ (0600), the public key to keys/ and src/platform/ota_public_key.h; .gitignore refuses *key.pem - scripts/make_ota.py: wraps firmware.bin into a signed .ota (openssl) - scripts/ota_push.py: sends it over TCP 3232, prints the device's answer - scripts/flash.sh --ota <host>: build, sign, push Checked: a generated .ota has the documented layout and its signature verifies with openssl against the committed public key. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
This commit is contained in:
Executable
+31
@@ -0,0 +1,31 @@
|
||||
#!/usr/bin/env bash
|
||||
# Creates the Firmware Update signing key pair, once (ADR 0003).
|
||||
# The private key stays in ~/.config/roro9stack/ and must never be committed; the public key is
|
||||
# written into the firmware source. Losing the private key means the next update goes over USB.
|
||||
set -euo pipefail
|
||||
ROOT="$(cd "$(dirname "$0")/.." && pwd)"
|
||||
KEY="${RORO_OTA_KEY:-$HOME/.config/roro9stack/ota-key.pem}"
|
||||
PUB_PEM="$ROOT/keys/ota-public.pem"
|
||||
PUB_H="$ROOT/src/platform/ota_public_key.h"
|
||||
|
||||
if [ -e "$KEY" ]; then
|
||||
echo "A signing key already exists at $KEY; not overwriting it." >&2
|
||||
exit 1
|
||||
fi
|
||||
mkdir -p "$(dirname "$KEY")" "$ROOT/keys"
|
||||
( umask 077; openssl ecparam -name prime256v1 -genkey -noout -out "$KEY" )
|
||||
openssl ec -in "$KEY" -pubout -out "$PUB_PEM" 2>/dev/null
|
||||
|
||||
{
|
||||
echo "#pragma once"
|
||||
echo ""
|
||||
echo "// Public key that Firmware Updates must be signed for (ECDSA P-256). Generated by"
|
||||
echo "// scripts/ota_keygen.sh; the private key is not in this repository (ADR 0003)."
|
||||
echo "namespace roro {"
|
||||
echo "inline constexpr char kOtaPublicKeyPem[] ="
|
||||
sed 's/^/ "/; s/$/\\n"/' "$PUB_PEM"
|
||||
echo " ;"
|
||||
echo "} // namespace roro"
|
||||
} > "$PUB_H"
|
||||
echo "Private key: $KEY (keep it safe)"
|
||||
echo "Public key: $PUB_PEM and $PUB_H (commit these)"
|
||||
Reference in New Issue
Block a user