Files
roro9stack/scripts/release_build.sh
T
twislaandClaude Opus 5.5 db7e6ccc18
CI / build (push) Successful in 8m5s
CI: jobs run in a container, PlatformIO directly in it, the toolchains in a volume
The runner now gives each job a container. The workflow asks for
python:3.12-slim, installs git, a compiler and PlatformIO, and mounts the
roro9stack-pio volume as the cache; the scripts skip their own docker run
when RORO_NO_DOCKER says they're in the build container already. A tag
from before the framework was rebuilt gets the stock framework libraries
back before it builds.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-06 12:39:37 +02:00

63 lines
3.2 KiB
Bash
Executable File

#!/usr/bin/env bash
# Builds what a release publishes, from a checkout of the repository at a tag (docs/milestones/R1.md).
# Usage: scripts/release_build.sh <checkout> <out folder>
# <checkout> a clone with its tags, at the commit to release: its own sources are built, with
# this copy's build image and signing tools, so an old tag can be released today.
# The signing key is read from $RORO_OTA_KEY (a file), as scripts/make_ota.py does.
# Out: roro9stack-<version>.ota (signed, checked), -factory.bin (USB), .elf.gz (to decode crashes),
# SHA256SUMS, and notes.md for the release's text.
set -euo pipefail
SRC="$(cd "$1" && pwd)"
mkdir -p "$2"
OUT="$(cd "$2" && pwd)"
TOOLS="$(cd "$(dirname "$0")" && pwd)"
VERSION="$(git -C "$SRC" describe --tags --always --dirty)"
case "$VERSION" in
*-dirty) echo "release: $SRC has uncommitted changes ($VERSION)" >&2; exit 1 ;;
esac
git -C "$SRC" describe --tags --exact-match >/dev/null 2>&1 || { echo "release: $VERSION is not a tag" >&2; exit 1; }
source "$TOOLS/_docker.sh"
ROOT="$SRC" # _docker.sh mounts $ROOT as /work: the checkout to build, not necessarily this copy
DOCKER_EXTRA=()
# A tag from before the framework was rebuilt with our settings (ADR 0006) can't link against a
# rebuilt one left in the toolchain cache: it gets the framework's libraries as they come.
if ! grep -q custom_sdkconfig "$SRC/platformio.ini"; then
run_in_container bash -c 'rm -rf "${PLATFORMIO_CORE_DIR:-/pio}/packages/framework-arduinoespressif32-libs"'
fi
run_in_container bash -c 'git config --global --add safe.directory "$PWD" && pio run -e cardputer-adv'
BUILD="$SRC/.pio/build/cardputer-adv"
NAME="roro9stack-$VERSION"
"$TOOLS/make_ota.py" "$BUILD/firmware.bin" "$VERSION" "$OUT/$NAME.ota"
# A wrong key must stop the release here, not on a device: checked against the public key the
# sources being built carry (the tags from before Firmware Updates have none: today's, then).
PUBLIC="$SRC/keys/ota-public.pem"
[ -e "$PUBLIC" ] || PUBLIC="$TOOLS/../keys/ota-public.pem"
"$TOOLS/ota_verify.py" "$OUT/$NAME.ota" "$PUBLIC"
cp "$BUILD/firmware.factory.bin" "$OUT/$NAME-factory.bin"
gzip -9 -c "$BUILD/firmware.elf" > "$OUT/$NAME.elf.gz"
(cd "$OUT" && sha256sum "$NAME.ota" "$NAME-factory.bin" "$NAME.elf.gz" > SHA256SUMS)
# The release's text: what the tag says, then what went in since the tag before.
PREVIOUS="$(git -C "$SRC" describe --tags --abbrev=0 "$VERSION^" 2>/dev/null || true)"
{
git -C "$SRC" tag -l --format='%(contents)' "$VERSION" | sed -e '/^-----BEGIN PGP/,$d'
echo
echo "## Files"
echo
echo "- \`$NAME.ota\`: the signed Update File. Copy it to \`/updates\` on the SD card and install it from Settings > Firmware or the Storage App, or push it over Wi-Fi with \`scripts/ota_push.py\`."
echo "- \`$NAME-factory.bin\`: the whole flash image, for a first install over USB at offset 0."
echo "- \`$NAME.elf.gz\`: the symbols, to decode a crash report from this build."
echo "- \`SHA256SUMS\`: checksums of the three."
if [ -n "$PREVIOUS" ]; then
echo
echo "## Changes since $PREVIOUS"
echo
git -C "$SRC" log --no-merges --format='- %s' "$PREVIOUS..$VERSION"
fi
} > "$OUT/notes.md"
echo "$VERSION" > "$OUT/version"
ls -l "$OUT"