The signed repo is live: https://dl.breadway.dev/arch/x86_64/ serves breadway.db + .files + every .pkg.tar.zst with a detached .sig from the BOS release key (56203B86A110695AE7F310934AF3323D678EB5E2 = KEYS.asc), rebuilt from the Forgejo Arch registry by signed-repo.yml + scripts/ci-publish-signed-repo.sh. Verified: db/pkg sigs all GPG-good against KEYS.asc. Executes the "After the signed repo exists" plan in docs/signed-repo.md: - `iso/pacman.conf` + `iso/airootfs/etc/pacman.conf`: section renamed `[Breadway.os.git.breadway.dev]` → `[breadway]` (matches breadway.db), `Server = https://dl.breadway.dev/arch/$arch`, `SigLevel = Required`. The old "Forgejo has no db sigs / KEYS.asc is not a repo key / do NOT flip" comments are gone — both are now false. - `iso/airootfs/etc/pacman.d/breadway-repo.asc`: the public key, baked into the image. - `build-local.sh`: trust the key in the build host's pacman keyring before mkarchiso (so pacstrap can verify [breadway] while assembling the airootfs); drop the now-obsolete Forgejo-registry URL rewrite. - `iso/airootfs/root/customize_airootfs.sh` (new): trust the key in the image keyring so the live medium — and, via calamares unpackfs, the installed target — verify [breadway]. (archiso warns this hook is deprecated; there is no replacement for "add a repo key to the image keyring" and BOS ships no pacman-init.service.) - `calamares/post-install.sh`: `pacman-key --add` + `--lsign-key` the BOS key in the target chroot as a fallback (unpackfs can skip /etc/pacman.d/gnupg). - README.md / DESIGN.md / docs/signed-repo.md updated. NOT yet done: build the ISO (`sudo ./build-local.sh`) and VM-verify `pacman -Sy` + a `[breadway]` install with no signature prompt, on both the live medium and a fresh install. The build-time keyring path (pacstrap -G vs host keyring vs customize_airootfs) may need a tweak once the real build runs.
27 lines
1.2 KiB
Bash
27 lines
1.2 KiB
Bash
#!/usr/bin/env bash
|
|
# Run by mkarchiso inside the airootfs chroot, after packages are installed
|
|
# and before the squashfs is built. (archiso prints a deprecation warning for
|
|
# this hook, but there is no non-deprecated replacement for "trust an extra
|
|
# pacman repo key in the image keyring", and BOS ships no pacman-init.service.)
|
|
#
|
|
# Purpose: trust the BOS release key (56203B86…) in the image's pacman
|
|
# keyring so the signed [breadway] repo (SigLevel = Required,
|
|
# https://dl.breadway.dev/arch) verifies both on the live medium and — via
|
|
# calamares' unpackfs, which copies this squashfs to the target — on the
|
|
# installed system. calamares/post-install.sh re-does this in the target
|
|
# chroot as a fallback (unpackfs can skip /etc/pacman.d/gnupg).
|
|
set -euo pipefail
|
|
|
|
BREADWAY_KEY_FPR="56203B86A110695AE7F310934AF3323D678EB5E2"
|
|
KEY_FILE="/etc/pacman.d/breadway-repo.asc"
|
|
|
|
pacman-key --init
|
|
pacman-key --populate archlinux
|
|
|
|
if [[ -f "$KEY_FILE" ]]; then
|
|
pacman-key --add "$KEY_FILE"
|
|
pacman-key --lsign-key "$BREADWAY_KEY_FPR"
|
|
echo "customize_airootfs: trusted [breadway] repo key $BREADWAY_KEY_FPR"
|
|
else
|
|
echo "customize_airootfs: WARNING $KEY_FILE missing; [breadway] will not verify" >&2
|
|
fi
|