release.sh: the release pipeline

Gates (clean tree, version single-source across FORGEFIRM_RELEASE /
rootfs stamp / .fw meta-version / tag, rootfs-vs-slot size with early
warning, installer-embedded pubkey must match the signing key,
factory-era fwup verification of the packed archive), then build,
pack, sign, checksum, and stage forgefirm.fw + sha256sums.txt +
forgefirm-image-glowforge.rootfs.wic.gz with the gh publish command
(--publish runs it where gh is authenticated). release.sh --dev packs
a dev-key-signed forgefirm-dev.fw from the release rootfs for the GUI
upload path. Signing keys are always passed explicitly - no defaults.
kas/README release order and the plan doc updated to match.
This commit is contained in:
ScottW514
2026-08-08 13:28:17 -04:00
parent 4f13d8a43f
commit fcf183eefd
4 changed files with 205 additions and 11 deletions
+10 -4
View File
@@ -109,10 +109,16 @@ config move in the right order. The sequence, with current status:
base recipe) so a fresh clone is fully self-contained;
- refresh `kas lock`, tag all repos, and prove self-containment by building
from a **fresh clone**.
5. **GitHub release**: upload the image asset under the exact name the
installer downloads — Scarthgap emits
`forgefirm-image-glowforge.rootfs.wic.gz`; align BUILD.md and
`install-forgefirm.sh` to one name before the first release.
5. **GitHub release**: run `scripts/release.sh <version>` on the build
host. It gates (version single-source, rootfs-vs-slot size,
installer-embedded pubkey vs the signing key, factory-era fwup
verification), builds, packs and signs `forgefirm.fw`, stages the
assets with `sha256sums.txt`, and prints the `gh release create`
command. Assets and their exact names (the installer and the update
manager download them verbatim): `forgefirm.fw`, `sha256sums.txt`,
`forgefirm-image-glowforge.rootfs.wic.gz`. The release tag
`v<version>` = `FORGEFIRM_RELEASE` = the rootfs `/etc/forgefirm-version`
= the `.fw` meta-version; `release.sh` enforces the agreement.
For gfhardware development, either bump the recipe pin per iteration or add a
tracked externalsrc bbappend mirroring the kernel-module pattern.