The signed repo is live: https://dl.breadway.dev/arch/x86_64/ serves breadway.db + .files + every .pkg.tar.zst with a detached .sig from the BOS release key (56203B86A110695AE7F310934AF3323D678EB5E2 = KEYS.asc), rebuilt from the Forgejo Arch registry by signed-repo.yml + scripts/ci-publish-signed-repo.sh. Verified: db/pkg sigs all GPG-good against KEYS.asc. Executes the "After the signed repo exists" plan in docs/signed-repo.md: - `iso/pacman.conf` + `iso/airootfs/etc/pacman.conf`: section renamed `[Breadway.os.git.breadway.dev]` → `[breadway]` (matches breadway.db), `Server = https://dl.breadway.dev/arch/$arch`, `SigLevel = Required`. The old "Forgejo has no db sigs / KEYS.asc is not a repo key / do NOT flip" comments are gone — both are now false. - `iso/airootfs/etc/pacman.d/breadway-repo.asc`: the public key, baked into the image. - `build-local.sh`: trust the key in the build host's pacman keyring before mkarchiso (so pacstrap can verify [breadway] while assembling the airootfs); drop the now-obsolete Forgejo-registry URL rewrite. - `iso/airootfs/root/customize_airootfs.sh` (new): trust the key in the image keyring so the live medium — and, via calamares unpackfs, the installed target — verify [breadway]. (archiso warns this hook is deprecated; there is no replacement for "add a repo key to the image keyring" and BOS ships no pacman-init.service.) - `calamares/post-install.sh`: `pacman-key --add` + `--lsign-key` the BOS key in the target chroot as a fallback (unpackfs can skip /etc/pacman.d/gnupg). - README.md / DESIGN.md / docs/signed-repo.md updated. NOT yet done: build the ISO (`sudo ./build-local.sh`) and VM-verify `pacman -Sy` + a `[breadway]` install with no signature prompt, on both the live medium and a fresh install. The build-time keyring path (pacstrap -G vs host keyring vs customize_airootfs) may need a tweak once the real build runs.
65 lines
2.6 KiB
PacmanConf
65 lines
2.6 KiB
PacmanConf
#
|
|
# BOS pacman.conf — used during ISO build and installed to the target system.
|
|
# Based on the standard Arch Linux pacman.conf.
|
|
#
|
|
|
|
[options]
|
|
HoldPkg = pacman glibc
|
|
Architecture = auto
|
|
CheckSpace
|
|
ParallelDownloads = 5
|
|
|
|
# Optional NoExtract size levers — left disabled. This file is both the ISO
|
|
# build config AND the installed system's pacman.conf, so enabling any line
|
|
# also stops future pacman -Syu from restoring those files.
|
|
# Measured against the 844-package closure (xz squashfs, profiledef.sh opts):
|
|
# usr/share/locale (non-en) 405.0 MiB raw -> 92.28 MiB ISO
|
|
# usr/share/doc 130.5 MiB raw -> 26.54 MiB ISO
|
|
# usr/share/man 41.5 MiB raw -> 38.77 MiB ISO
|
|
# usr/share/info 12.9 MiB raw -> 11.12 MiB ISO
|
|
# usr/share/gtk-doc 16.0 MiB raw -> 1.18 MiB ISO
|
|
# usr/include 193.6 MiB raw -> 25.26 MiB ISO
|
|
# Non-en locales make every GUI English-only until the package is reinstalled
|
|
# without this NoExtract; dropping man/info means `man` returns nothing.
|
|
#NoExtract = usr/share/locale/* !usr/share/locale/en* !usr/share/locale/locale.alias
|
|
#NoExtract = usr/share/doc/* usr/share/gtk-doc/* usr/share/info/*
|
|
#NoExtract = usr/share/man/*
|
|
#NoExtract = usr/include/*
|
|
|
|
Color
|
|
VerbosePkgLists
|
|
ILoveCandy
|
|
|
|
SigLevel = Required DatabaseOptional
|
|
LocalFileSigLevel = Optional
|
|
|
|
[core]
|
|
Include = /etc/pacman.d/mirrorlist
|
|
|
|
[extra]
|
|
Include = /etc/pacman.d/mirrorlist
|
|
|
|
[multilib]
|
|
Include = /etc/pacman.d/mirrorlist
|
|
|
|
# -----------------------------------------------------------------------
|
|
# Breadway custom repo — breadlock plus AUR republishes the ISO needs
|
|
# (calamares, zen-browser-bin, bibata-cursor-theme-bin, yay-bin,
|
|
# zsh-theme-powerlevel10k). bakery / breadbar / bos-settings / breadhelp
|
|
# are NOT here; they are bakery-baked into /usr/local at ISO build time.
|
|
#
|
|
# Packages are published to the Forgejo Arch registry (group "os") by the
|
|
# .forgejo/workflows/*.yml workflows; scripts/ci-publish-signed-repo.sh then
|
|
# collects them, detach-signs each .pkg.tar.zst with the BOS release key
|
|
# (releases@breadway.dev), runs `repo-add -s`, and publishes the signed db
|
|
# at https://dl.breadway.dev/arch/$arch (signed-repo.yml).
|
|
#
|
|
# SigLevel = Required: every package AND the db carry a .sig from key
|
|
# 56203B86A110695AE7F310934AF3323D678EB5E2 — the same key committed as
|
|
# KEYS.asc / airootfs/etc/pacman.d/breadway-repo.asc, imported into the
|
|
# pacman keyring at build time (build-local.sh), on the live medium, and
|
|
# on the installed target (calamares/post-install.sh).
|
|
# -----------------------------------------------------------------------
|
|
[breadway]
|
|
SigLevel = Required
|
|
Server = https://dl.breadway.dev/arch/$arch
|