Public Access
CI / build (push) Successful in 8m5s
The runner now gives each job a container. The workflow asks for python:3.12-slim, installs git, a compiler and PlatformIO, and mounts the roro9stack-pio volume as the cache; the scripts skip their own docker run when RORO_NO_DOCKER says they're in the build container already. A tag from before the framework was rebuilt gets the stock framework libraries back before it builds. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
63 lines
3.2 KiB
Bash
Executable File
63 lines
3.2 KiB
Bash
Executable File
#!/usr/bin/env bash
|
|
# Builds what a release publishes, from a checkout of the repository at a tag (docs/milestones/R1.md).
|
|
# Usage: scripts/release_build.sh <checkout> <out folder>
|
|
# <checkout> a clone with its tags, at the commit to release: its own sources are built, with
|
|
# this copy's build image and signing tools, so an old tag can be released today.
|
|
# The signing key is read from $RORO_OTA_KEY (a file), as scripts/make_ota.py does.
|
|
# Out: roro9stack-<version>.ota (signed, checked), -factory.bin (USB), .elf.gz (to decode crashes),
|
|
# SHA256SUMS, and notes.md for the release's text.
|
|
set -euo pipefail
|
|
SRC="$(cd "$1" && pwd)"
|
|
mkdir -p "$2"
|
|
OUT="$(cd "$2" && pwd)"
|
|
TOOLS="$(cd "$(dirname "$0")" && pwd)"
|
|
|
|
VERSION="$(git -C "$SRC" describe --tags --always --dirty)"
|
|
case "$VERSION" in
|
|
*-dirty) echo "release: $SRC has uncommitted changes ($VERSION)" >&2; exit 1 ;;
|
|
esac
|
|
git -C "$SRC" describe --tags --exact-match >/dev/null 2>&1 || { echo "release: $VERSION is not a tag" >&2; exit 1; }
|
|
|
|
source "$TOOLS/_docker.sh"
|
|
ROOT="$SRC" # _docker.sh mounts $ROOT as /work: the checkout to build, not necessarily this copy
|
|
DOCKER_EXTRA=()
|
|
# A tag from before the framework was rebuilt with our settings (ADR 0006) can't link against a
|
|
# rebuilt one left in the toolchain cache: it gets the framework's libraries as they come.
|
|
if ! grep -q custom_sdkconfig "$SRC/platformio.ini"; then
|
|
run_in_container bash -c 'rm -rf "${PLATFORMIO_CORE_DIR:-/pio}/packages/framework-arduinoespressif32-libs"'
|
|
fi
|
|
run_in_container bash -c 'git config --global --add safe.directory "$PWD" && pio run -e cardputer-adv'
|
|
|
|
BUILD="$SRC/.pio/build/cardputer-adv"
|
|
NAME="roro9stack-$VERSION"
|
|
"$TOOLS/make_ota.py" "$BUILD/firmware.bin" "$VERSION" "$OUT/$NAME.ota"
|
|
# A wrong key must stop the release here, not on a device: checked against the public key the
|
|
# sources being built carry (the tags from before Firmware Updates have none: today's, then).
|
|
PUBLIC="$SRC/keys/ota-public.pem"
|
|
[ -e "$PUBLIC" ] || PUBLIC="$TOOLS/../keys/ota-public.pem"
|
|
"$TOOLS/ota_verify.py" "$OUT/$NAME.ota" "$PUBLIC"
|
|
cp "$BUILD/firmware.factory.bin" "$OUT/$NAME-factory.bin"
|
|
gzip -9 -c "$BUILD/firmware.elf" > "$OUT/$NAME.elf.gz"
|
|
(cd "$OUT" && sha256sum "$NAME.ota" "$NAME-factory.bin" "$NAME.elf.gz" > SHA256SUMS)
|
|
|
|
# The release's text: what the tag says, then what went in since the tag before.
|
|
PREVIOUS="$(git -C "$SRC" describe --tags --abbrev=0 "$VERSION^" 2>/dev/null || true)"
|
|
{
|
|
git -C "$SRC" tag -l --format='%(contents)' "$VERSION" | sed -e '/^-----BEGIN PGP/,$d'
|
|
echo
|
|
echo "## Files"
|
|
echo
|
|
echo "- \`$NAME.ota\`: the signed Update File. Copy it to \`/updates\` on the SD card and install it from Settings > Firmware or the Storage App, or push it over Wi-Fi with \`scripts/ota_push.py\`."
|
|
echo "- \`$NAME-factory.bin\`: the whole flash image, for a first install over USB at offset 0."
|
|
echo "- \`$NAME.elf.gz\`: the symbols, to decode a crash report from this build."
|
|
echo "- \`SHA256SUMS\`: checksums of the three."
|
|
if [ -n "$PREVIOUS" ]; then
|
|
echo
|
|
echo "## Changes since $PREVIOUS"
|
|
echo
|
|
git -C "$SRC" log --no-merges --format='- %s' "$PREVIOUS..$VERSION"
|
|
fi
|
|
} > "$OUT/notes.md"
|
|
echo "$VERSION" > "$OUT/version"
|
|
ls -l "$OUT"
|