bos/iso/airootfs/etc
Breadway 98cfe9d60b ISO: flip [breadway] to the signed dl.breadway.dev/arch repo
The signed repo is live: https://dl.breadway.dev/arch/x86_64/ serves
breadway.db + .files + every .pkg.tar.zst with a detached .sig from the
BOS release key (56203B86A110695AE7F310934AF3323D678EB5E2 = KEYS.asc),
rebuilt from the Forgejo Arch registry by signed-repo.yml +
scripts/ci-publish-signed-repo.sh. Verified: db/pkg sigs all GPG-good
against KEYS.asc.

Executes the "After the signed repo exists" plan in docs/signed-repo.md:

- `iso/pacman.conf` + `iso/airootfs/etc/pacman.conf`: section renamed
  `[Breadway.os.git.breadway.dev]` → `[breadway]` (matches breadway.db),
  `Server = https://dl.breadway.dev/arch/$arch`, `SigLevel = Required`.
  The old "Forgejo has no db sigs / KEYS.asc is not a repo key / do NOT
  flip" comments are gone — both are now false.
- `iso/airootfs/etc/pacman.d/breadway-repo.asc`: the public key, baked
  into the image.
- `build-local.sh`: trust the key in the build host's pacman keyring
  before mkarchiso (so pacstrap can verify [breadway] while assembling
  the airootfs); drop the now-obsolete Forgejo-registry URL rewrite.
- `iso/airootfs/root/customize_airootfs.sh` (new): trust the key in the
  image keyring so the live medium — and, via calamares unpackfs, the
  installed target — verify [breadway]. (archiso warns this hook is
  deprecated; there is no replacement for "add a repo key to the image
  keyring" and BOS ships no pacman-init.service.)
- `calamares/post-install.sh`: `pacman-key --add` + `--lsign-key` the
  BOS key in the target chroot as a fallback (unpackfs can skip
  /etc/pacman.d/gnupg).
- README.md / DESIGN.md / docs/signed-repo.md updated.

NOT yet done: build the ISO (`sudo ./build-local.sh`) and VM-verify
`pacman -Sy` + a `[breadway]` install with no signature prompt, on both
the live medium and a fresh install. The build-time keyring path
(pacstrap -G vs host keyring vs customize_airootfs) may need a tweak
once the real build runs.
2026-08-31 18:22:55 +08:00
..
bakery iso: bake bakery apps into /usr/local 2026-08-16 00:10:32 +08:00
calamares ISO: flip [breadway] to the signed dl.breadway.dev/arch repo 2026-08-31 18:22:55 +08:00
default iso: enable bakery user units globally for later accounts 2026-08-16 00:27:14 +08:00
greetd iso: bake bakery apps into /usr/local 2026-08-16 00:10:32 +08:00
mkinitcpio.conf.d Fix install-breaking and live-boot bugs, verified on real hardware 2026-07-03 13:31:40 +08:00
mkinitcpio.d Add archiso initramfs hooks so the live ISO can switch root 2026-06-14 02:55:53 +08:00
pacman.d ISO: flip [breadway] to the signed dl.breadway.dev/arch repo 2026-08-31 18:22:55 +08:00
plymouth Fix install-breaking and live-boot bugs, verified on real hardware 2026-07-03 13:31:40 +08:00
profile.d iso: bake bakery apps into /usr/local 2026-08-16 00:10:32 +08:00
skel iso: add external-monitors bread module for zero-config docking 2026-08-23 15:23:07 +08:00
sudoers.d Run the live session as an unprivileged user (Hyprland won't run as root) 2026-06-14 04:13:10 +08:00
systemd iso: enable bakery user units globally for later accounts 2026-08-16 00:27:14 +08:00
hostname Add live-environment config so the ISO boots straight to the session 2026-06-14 03:13:54 +08:00
locale.conf Add live-environment config so the ISO boots straight to the session 2026-06-14 03:13:54 +08:00
localtime Add live-environment config so the ISO boots straight to the session 2026-06-14 03:13:54 +08:00
os-release 1.0 polish: os-release, snapper pre, lockfile pins, listen, docs 2026-08-15 22:53:01 +08:00
pacman.conf ISO: flip [breadway] to the signed dl.breadway.dev/arch repo 2026-08-31 18:22:55 +08:00
passwd Add live-environment config so the ISO boots straight to the session 2026-06-14 03:13:54 +08:00
shadow Add live-environment config so the ISO boots straight to the session 2026-06-14 03:13:54 +08:00
vconsole.conf Add live-environment config so the ISO boots straight to the session 2026-06-14 03:13:54 +08:00