Files
roro9stack/docs/milestones/R1.md
T
2026-10-06 12:19:00 +02:00

2.8 KiB

R1 — Releases

Status: in progress (branch ci): CI and signed releases on Gitea (issue #5). The Issues App (#4) and updates from Gitea (#6) come after; #6 waits for this.

Goal: a tag is a release, built the same way every time and published where a device can find it.

CI and releases (issue #5)

Until now the tests, the builds, the signing and the flashing all happened on one machine, through scripts/ci.sh and scripts/flash.sh. Nothing was published.

Decisions (design round 2026-10-06)

# Decision
Q151 Every push, to any branch: the host tests and both builds. A tag v*: the same, then a release.
Q152 CI signs. The signing key is the repository secret OTA_SIGNING_KEY; a tag push makes a complete, signed release with no manual step (ADR 0008).
Q153 The Debug Build is built in CI with a token of the runner's own, to prove it compiles, and isn't published: it would hand everyone its Debug Console token.
Q154 Pull requests from forks don't start a run.
Q155 A release carries roro9stack-<version>.ota (signed), -factory.bin for USB, .elf.gz to decode crashes, and SHA256SUMS.
Q156 Its text is the tag's message, what the files are, and the commits since the tag before.
Q157 No cache service to begin with: measure first.
Q158 Reproducible builds aren't needed for signing any more (Q152); not pursued here.
Q159 The tags from before CI get their releases too, v0.1.0 to v0.10.0, built from each tag's own sources by running the workflow by hand.
Q160 Actions is switched on for the repository.

As built

  • One workflow, .gitea/workflows/ci.yml, one job. The runner (runner0) executes jobs on its own host, where Docker is, so the steps are plain shell and the build runs in the project's image through scripts/ci.sh, exactly as on a developer's machine. The toolchains live in the same roro9stack-pio Docker volume, on the runner: that is the cache.
  • No JavaScript actions: the host has no Node. The checkout is four git commands.
  • The runner's label is registered as ubuntu://docker:ubuntu:resolute, the whole string, and that is what runs-on has to say. It looks like ubuntu:docker://ubuntu:resolute was meant, which would run jobs in a container; the workflow would then need Docker inside that container, or a rewrite. As it is, it works.
  • scripts/release_build.sh <checkout> <out> builds a tag's own sources with today's build image and signing tools, signs, verifies, and writes the files and the release's text. scripts/release_publish.py creates the Gitea release or completes it; run twice, it replaces what's there. Both run the same on a developer's machine.
  • scripts/ota_verify.py checks an Update File as a device does, on a PC.