mirror of
https://github.com/openglow-org/forgefirm.git
synced 2026-09-27 16:51:12 -07:00
image: slot-sized release rootfs, ext4 artifact, fwup, mkfw.sh
The release image now targets the 200 MiB factory eMMC slot: content plus 40 MiB working space, hard build failure past the slot size. The raw ext4 is deployed alongside the wic; scripts/mkfw.sh packs it into a signed .fw with factory-pattern upgrade.a/upgrade.b tasks. fwup 1.16.0 recipe (applies ForgeFIRM and Glowforge-signed archives on device) is installed in both images. Dev images stay SD-sized with a 256 MiB working margin and no ceiling. Verified on the 20260808153331 build: release ext4 180.8 MiB; signed .fw applies byte-exact with fwup 1.16.0 and with the factory's 0.14.2 (raw-format pubkey), and 0.14.2 -V verifies the signature.
This commit is contained in:
@@ -113,6 +113,15 @@ motion constants were extracted from the `_RESOURCES` pulse files
|
||||
kas/forgefirm-glowforge.yml -c 'bitbake forgefirm-image
|
||||
forgefirm-image-dev'`. Artifacts:
|
||||
`forgefirm/build/tmp/deploy/images/glowforge/`.
|
||||
- **fwup lab (host)**: `~/fwup-lab/bin/` holds host-built `fwup-0.14.2`
|
||||
(factory-era) and `fwup-v1.16.0`; `~/fwup-lab/devkeys/fwup-key.{priv,pub}`
|
||||
is the DEV signing keypair (`fwup-key-raw.pub` = raw 32-byte form —
|
||||
what fwup 0.14.2 expects; 1.x reads both). Cross-version compat is
|
||||
proven both ways (modern-packed signed archives apply with 0.14.2;
|
||||
modern fwup verifies+applies the factory .fw — signer key
|
||||
2017-05-001.pub). The production release key does not exist yet —
|
||||
generation/custody is an operator ceremony (UPDATE-SYSTEM.md gate 3).
|
||||
Pack releases with `scripts/mkfw.sh`.
|
||||
- **Shell gotchas** (cost real time): PowerShell mangles embedded double
|
||||
quotes in git-commit here-strings (avoid `"` in messages); `wsl -- bash
|
||||
-c '...'` eats `$VAR` expansions (use script files run via PowerShell,
|
||||
|
||||
Reference in New Issue
Block a user