CI: stage bakery from signed stable index, drop bread-theme cargo build

The tagged ISO workflow fetched bos-settings/src/Cargo.toml from the
dev branch (404 after the Tauri split) and cargo-built bread-theme.
bread-theme 0.7.1 is already on the stable index. Stage required bins,
units, breadhelp content, and desktop/license files from the
minisign-verified index instead; optional bread-emit/module-host skip
until bread publishes them. Fail the bake if a required bin is missing.
This commit is contained in:
Breadway 2026-08-15 22:20:29 +08:00
parent 3ab97c1634
commit a3ead6607a
16 changed files with 687 additions and 154 deletions

View file

@ -41,8 +41,11 @@ passwd -l root || true
# over to the target (unpackfs may skip it / perms differ), leaving the installed
# system unable to verify package signatures — the first `pacman -Syu` then dies
# with "keyring is not writable / required key missing". Initialise it here so a
# fresh install can update out of the box. archlinux-keyring is already present;
# [breadway] is SigLevel=Never so it needs no key.
# fresh install can update out of the box. archlinux-keyring is already present
# and is the only keyring populated — it verifies official Arch packages.
# [breadway] stays SigLevel=Never (Forgejo does not serve pacman-compatible
# db signatures). Do not import KEYS.asc here: that key signs ISO SHA256SUMS,
# not the pacman repo; treating it as a repo key would be a lie.
# ---------------------------------------------------------------------------
if command -v pacman-key &>/dev/null; then
pacman-key --init || echo "WARN: pacman-key --init failed"

View file

@ -34,10 +34,13 @@ Include = /etc/pacman.d/mirrorlist
# Packages are published to the Forgejo Arch registry (group "os") by the
# .forgejo/workflows/*.yml workflows in this repo (and breadlock's).
#
# Forgejo signs the repo db with a key pacman can't look up, so TrustAll
# fails. SigLevel = Never skips verification (acceptable for this private
# repo over TLS). Future improvement: import Forgejo's signing key and
# switch to SigLevel = Required for full package verification.
# Forgejo's Arch package registry does not serve pacman-compatible db
# signatures. SigLevel = Never is TLS-only integrity: the connection is
# HTTPS (or rewritten to hestia's localhost:3002 in CI). breadlock (PAM)
# rides this repo. Do NOT flip to SigLevel = Required unless a signed db
# has been verified to work — Required without signatures breaks the ISO
# and every install that uses [breadway]. KEYS.asc is the ISO SHA256SUMS
# signing key, not a pacman repo key.
# -----------------------------------------------------------------------
# The section name must match Forgejo's served db filename
# ({owner}.{group}.{domain}.db) — pacman fetches "<section>.db" from Server.