release.sh: the release pipeline

Gates (clean tree, version single-source across FORGEFIRM_RELEASE /
rootfs stamp / .fw meta-version / tag, rootfs-vs-slot size with early
warning, installer-embedded pubkey must match the signing key,
factory-era fwup verification of the packed archive), then build,
pack, sign, checksum, and stage forgefirm.fw + sha256sums.txt +
forgefirm-image-glowforge.rootfs.wic.gz with the gh publish command
(--publish runs it where gh is authenticated). release.sh --dev packs
a dev-key-signed forgefirm-dev.fw from the release rootfs for the GUI
upload path. Signing keys are always passed explicitly - no defaults.
kas/README release order and the plan doc updated to match.
This commit is contained in:
ScottW514
2026-08-08 13:28:17 -04:00
parent 4f13d8a43f
commit fcf183eefd
4 changed files with 205 additions and 11 deletions
+13 -7
View File
@@ -142,15 +142,21 @@ demonstrably untouched.*
## Phase 3 — release pipeline
- `scripts/release.sh` (build host): kas build → size gate → pack
`.fw` → sign → `sha256sums.txt` → `gh release create` → post-check
that asset names match what the installer, GUI updater, and (later)
recovery expect.
- One version source: `FORGEFIRM_RELEASE` = git tag =
- `scripts/release.sh` (build host): gates → kas build → pack `.fw` →
sign → `sha256sums.txt` → staged assets + `gh release create`
command (`--publish` runs it where gh is authenticated). Gates:
clean tree, version single-source, rootfs-vs-slot size
(warn ≥ 170 MiB / fail ≥ 195 MiB, under bitbake's own hard cap),
**installer-embedded pubkey must match the signing key**, and
factory-era fwup (0.14.2) verification of the packed archive.
- One version source: `FORGEFIRM_RELEASE` = git tag =
`/etc/forgefirm-version` = `.fw` meta-version; the script enforces
agreement.
- Dev builds emit a `.fw` too (dev-key or unsigned — see open
questions) for the GUI upload path.
- `release.sh --dev` packs a **dev-key-signed** `forgefirm-dev.fw`
from the release rootfs for the GUI upload path (decides open
question 4: dev archives are signed with the dev key, never
unsigned — the GUI exercises the same verification path either
way).
- GitHub Actions: per-push compile checks for grblHAL-glowforge and
forgectrl (minutes, no Yocto); optional `workflow_dispatch`
cold-Yocto reproducibility build whose only product is a checksum.