From ababfaf9938745b2794a451547a64a5d460ffaa6 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Cl=C3=A9ment=20Martin?= Date: Tue, 6 Oct 2026 12:25:20 +0200 Subject: [PATCH] Release build: tags from before Firmware Updates carry no public key to check against Co-Authored-By: Claude Opus 5.5 Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT --- scripts/release_build.sh | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/scripts/release_build.sh b/scripts/release_build.sh index c421329..cc4c0ee 100755 --- a/scripts/release_build.sh +++ b/scripts/release_build.sh @@ -27,8 +27,10 @@ BUILD="$SRC/.pio/build/cardputer-adv" NAME="roro9stack-$VERSION" "$TOOLS/make_ota.py" "$BUILD/firmware.bin" "$VERSION" "$OUT/$NAME.ota" # A wrong key must stop the release here, not on a device: checked against the public key the -# sources being built carry. -"$TOOLS/ota_verify.py" "$OUT/$NAME.ota" "$SRC/keys/ota-public.pem" +# sources being built carry (the tags from before Firmware Updates have none: today's, then). +PUBLIC="$SRC/keys/ota-public.pem" +[ -e "$PUBLIC" ] || PUBLIC="$TOOLS/../keys/ota-public.pem" +"$TOOLS/ota_verify.py" "$OUT/$NAME.ota" "$PUBLIC" cp "$BUILD/firmware.factory.bin" "$OUT/$NAME-factory.bin" gzip -9 -c "$BUILD/firmware.elf" > "$OUT/$NAME.elf.gz" (cd "$OUT" && sha256sum "$NAME.ota" "$NAME-factory.bin" "$NAME.elf.gz" > SHA256SUMS)