Public Access
- scripts/ota_keygen.sh: ECDSA P-256 key pair; the private key goes to ~/.config/roro9stack/ (0600), the public key to keys/ and src/platform/ota_public_key.h; .gitignore refuses *key.pem - scripts/make_ota.py: wraps firmware.bin into a signed .ota (openssl) - scripts/ota_push.py: sends it over TCP 3232, prints the device's answer - scripts/flash.sh --ota <host>: build, sign, push Checked: a generated .ota has the documented layout and its signature verifies with openssl against the committed public key. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
32 lines
1.2 KiB
Bash
Executable File
32 lines
1.2 KiB
Bash
Executable File
#!/usr/bin/env bash
|
|
# Creates the Firmware Update signing key pair, once (ADR 0003).
|
|
# The private key stays in ~/.config/roro9stack/ and must never be committed; the public key is
|
|
# written into the firmware source. Losing the private key means the next update goes over USB.
|
|
set -euo pipefail
|
|
ROOT="$(cd "$(dirname "$0")/.." && pwd)"
|
|
KEY="${RORO_OTA_KEY:-$HOME/.config/roro9stack/ota-key.pem}"
|
|
PUB_PEM="$ROOT/keys/ota-public.pem"
|
|
PUB_H="$ROOT/src/platform/ota_public_key.h"
|
|
|
|
if [ -e "$KEY" ]; then
|
|
echo "A signing key already exists at $KEY; not overwriting it." >&2
|
|
exit 1
|
|
fi
|
|
mkdir -p "$(dirname "$KEY")" "$ROOT/keys"
|
|
( umask 077; openssl ecparam -name prime256v1 -genkey -noout -out "$KEY" )
|
|
openssl ec -in "$KEY" -pubout -out "$PUB_PEM" 2>/dev/null
|
|
|
|
{
|
|
echo "#pragma once"
|
|
echo ""
|
|
echo "// Public key that Firmware Updates must be signed for (ECDSA P-256). Generated by"
|
|
echo "// scripts/ota_keygen.sh; the private key is not in this repository (ADR 0003)."
|
|
echo "namespace roro {"
|
|
echo "inline constexpr char kOtaPublicKeyPem[] ="
|
|
sed 's/^/ "/; s/$/\\n"/' "$PUB_PEM"
|
|
echo " ;"
|
|
echo "} // namespace roro"
|
|
} > "$PUB_H"
|
|
echo "Private key: $KEY (keep it safe)"
|
|
echo "Public key: $PUB_PEM and $PUB_H (commit these)"
|