ISO: flip [breadway] to the signed dl.breadway.dev/arch repo
The signed repo is live: https://dl.breadway.dev/arch/x86_64/ serves breadway.db + .files + every .pkg.tar.zst with a detached .sig from the BOS release key (56203B86A110695AE7F310934AF3323D678EB5E2 = KEYS.asc), rebuilt from the Forgejo Arch registry by signed-repo.yml + scripts/ci-publish-signed-repo.sh. Verified: db/pkg sigs all GPG-good against KEYS.asc. Executes the "After the signed repo exists" plan in docs/signed-repo.md: - `iso/pacman.conf` + `iso/airootfs/etc/pacman.conf`: section renamed `[Breadway.os.git.breadway.dev]` → `[breadway]` (matches breadway.db), `Server = https://dl.breadway.dev/arch/$arch`, `SigLevel = Required`. The old "Forgejo has no db sigs / KEYS.asc is not a repo key / do NOT flip" comments are gone — both are now false. - `iso/airootfs/etc/pacman.d/breadway-repo.asc`: the public key, baked into the image. - `build-local.sh`: trust the key in the build host's pacman keyring before mkarchiso (so pacstrap can verify [breadway] while assembling the airootfs); drop the now-obsolete Forgejo-registry URL rewrite. - `iso/airootfs/root/customize_airootfs.sh` (new): trust the key in the image keyring so the live medium — and, via calamares unpackfs, the installed target — verify [breadway]. (archiso warns this hook is deprecated; there is no replacement for "add a repo key to the image keyring" and BOS ships no pacman-init.service.) - `calamares/post-install.sh`: `pacman-key --add` + `--lsign-key` the BOS key in the target chroot as a fallback (unpackfs can skip /etc/pacman.d/gnupg). - README.md / DESIGN.md / docs/signed-repo.md updated. NOT yet done: build the ISO (`sudo ./build-local.sh`) and VM-verify `pacman -Sy` + a `[breadway]` install with no signature prompt, on both the live medium and a fresh install. The build-time keyring path (pacstrap -G vs host keyring vs customize_airootfs) may need a tweak once the real build runs.
This commit is contained in:
parent
b38bbbac1a
commit
98cfe9d60b
9 changed files with 137 additions and 67 deletions
13
README.md
13
README.md
|
|
@ -174,10 +174,10 @@ dedicated release-signing key (not reused from anything else):
|
|||
5620 3B86 A110 695A E7F3 1093 4AF3 323D 678E B5E2
|
||||
```
|
||||
|
||||
The public half is committed at [`KEYS.asc`](KEYS.asc). That key signs
|
||||
**ISO checksums only** — it does not sign the `[breadway]` pacman repo
|
||||
(Forgejo's Arch registry has no pacman-compatible db signatures; that
|
||||
section stays `SigLevel = Never` until a signed repo exists — see
|
||||
The public half is committed at [`KEYS.asc`](KEYS.asc). The same key signs
|
||||
the ISO checksums **and** the `[breadway]` pacman repo — every package and
|
||||
the db at `https://dl.breadway.dev/arch` carry a `.sig` from it, and that
|
||||
section is `SigLevel = Required` (see
|
||||
[docs/signed-repo.md](docs/signed-repo.md)). To verify a download:
|
||||
|
||||
```sh
|
||||
|
|
@ -381,8 +381,9 @@ until `dl.breadway.dev/arch` exists).
|
|||
- **Snapshots assume btrfs**: the snapper/grub-btrfs tooling expects the default
|
||||
btrfs subvolume layout the installer creates. Recovery is the GRUB
|
||||
snapshots submenu, not `snapper rollback` — [docs/hardware.md](docs/hardware.md).
|
||||
- **`[breadway]` signatures**: `SigLevel = Never` until a signed repo is
|
||||
stood up at `dl.breadway.dev/arch`. See [docs/signed-repo.md](docs/signed-repo.md).
|
||||
- **`[breadway]` signatures**: `SigLevel = Required` — the signed repo at
|
||||
`dl.breadway.dev/arch` is live (db + every package `.sig`ned with the BOS
|
||||
release key). See [docs/signed-repo.md](docs/signed-repo.md).
|
||||
|
||||
## Recovery
|
||||
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue