OTA step 2: signing key, Update File builder, push client

- scripts/ota_keygen.sh: ECDSA P-256 key pair; the private key goes to
  ~/.config/roro9stack/ (0600), the public key to keys/ and
  src/platform/ota_public_key.h; .gitignore refuses *key.pem
- scripts/make_ota.py: wraps firmware.bin into a signed .ota (openssl)
- scripts/ota_push.py: sends it over TCP 3232, prints the device's answer
- scripts/flash.sh --ota <host>: build, sign, push

Checked: a generated .ota has the documented layout and its signature
verifies with openssl against the committed public key.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
This commit is contained in:
2026-10-03 21:31:39 +02:00
co-authored by Claude Opus 5.5
parent 326e864264
commit 90cb6ef9b2
7 changed files with 156 additions and 1 deletions
+12
View File
@@ -0,0 +1,12 @@
#pragma once
// Public key that Firmware Updates must be signed for (ECDSA P-256). Generated by
// scripts/ota_keygen.sh; the private key is not in this repository (ADR 0003).
namespace roro {
inline constexpr char kOtaPublicKeyPem[] =
"-----BEGIN PUBLIC KEY-----\n"
"MFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAEIWzT07fvTpQxWjTdewMipYH6f42+\n"
"mM8niHm+T8y+Mvjanb3H8hpYXg3VjuJGFtcHw/hFX0Q2f2AiSHMF0DhMbQ==\n"
"-----END PUBLIC KEY-----\n"
;
} // namespace roro