Public Access
CI / build (push) Successful in 11m26s
The workflow runs on the runner's host and builds in the project's Docker image through scripts/ci.sh, as on a developer's machine. A tag v*, or a run by hand for an older tag, builds that tag's sources, signs the Update File with the key held in the repository's secrets, checks the signature against the public key in the sources, and publishes a Gitea release with the .ota, the factory image, the ELF and checksums. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
56 lines
2.7 KiB
Bash
Executable File
56 lines
2.7 KiB
Bash
Executable File
#!/usr/bin/env bash
|
|
# Builds what a release publishes, from a checkout of the repository at a tag (docs/milestones/R1.md).
|
|
# Usage: scripts/release_build.sh <checkout> <out folder>
|
|
# <checkout> a clone with its tags, at the commit to release: its own sources are built, with
|
|
# this copy's build image and signing tools, so an old tag can be released today.
|
|
# The signing key is read from $RORO_OTA_KEY (a file), as scripts/make_ota.py does.
|
|
# Out: roro9stack-<version>.ota (signed, checked), -factory.bin (USB), .elf.gz (to decode crashes),
|
|
# SHA256SUMS, and notes.md for the release's text.
|
|
set -euo pipefail
|
|
SRC="$(cd "$1" && pwd)"
|
|
mkdir -p "$2"
|
|
OUT="$(cd "$2" && pwd)"
|
|
TOOLS="$(cd "$(dirname "$0")" && pwd)"
|
|
|
|
VERSION="$(git -C "$SRC" describe --tags --always --dirty)"
|
|
case "$VERSION" in
|
|
*-dirty) echo "release: $SRC has uncommitted changes ($VERSION)" >&2; exit 1 ;;
|
|
esac
|
|
git -C "$SRC" describe --tags --exact-match >/dev/null 2>&1 || { echo "release: $VERSION is not a tag" >&2; exit 1; }
|
|
|
|
source "$TOOLS/_docker.sh"
|
|
ROOT="$SRC" # _docker.sh mounts $ROOT as /work: the checkout to build, not necessarily this copy
|
|
DOCKER_EXTRA=()
|
|
run_in_container bash -c 'git config --global --add safe.directory /work && pio run -e cardputer-adv'
|
|
|
|
BUILD="$SRC/.pio/build/cardputer-adv"
|
|
NAME="roro9stack-$VERSION"
|
|
"$TOOLS/make_ota.py" "$BUILD/firmware.bin" "$VERSION" "$OUT/$NAME.ota"
|
|
# A wrong key must stop the release here, not on a device: checked against the public key the
|
|
# sources being built carry.
|
|
"$TOOLS/ota_verify.py" "$OUT/$NAME.ota" "$SRC/keys/ota-public.pem"
|
|
cp "$BUILD/firmware.factory.bin" "$OUT/$NAME-factory.bin"
|
|
gzip -9 -c "$BUILD/firmware.elf" > "$OUT/$NAME.elf.gz"
|
|
(cd "$OUT" && sha256sum "$NAME.ota" "$NAME-factory.bin" "$NAME.elf.gz" > SHA256SUMS)
|
|
|
|
# The release's text: what the tag says, then what went in since the tag before.
|
|
PREVIOUS="$(git -C "$SRC" describe --tags --abbrev=0 "$VERSION^" 2>/dev/null || true)"
|
|
{
|
|
git -C "$SRC" tag -l --format='%(contents)' "$VERSION" | sed -e '/^-----BEGIN PGP/,$d'
|
|
echo
|
|
echo "## Files"
|
|
echo
|
|
echo "- \`$NAME.ota\`: the signed Update File. Copy it to \`/updates\` on the SD card and install it from Settings > Firmware or the Storage App, or push it over Wi-Fi with \`scripts/ota_push.py\`."
|
|
echo "- \`$NAME-factory.bin\`: the whole flash image, for a first install over USB at offset 0."
|
|
echo "- \`$NAME.elf.gz\`: the symbols, to decode a crash report from this build."
|
|
echo "- \`SHA256SUMS\`: checksums of the three."
|
|
if [ -n "$PREVIOUS" ]; then
|
|
echo
|
|
echo "## Changes since $PREVIOUS"
|
|
echo
|
|
git -C "$SRC" log --no-merges --format='- %s' "$PREVIOUS..$VERSION"
|
|
fi
|
|
} > "$OUT/notes.md"
|
|
echo "$VERSION" > "$OUT/version"
|
|
ls -l "$OUT"
|