bos/iso/pacman.conf
Breadway 98cfe9d60b ISO: flip [breadway] to the signed dl.breadway.dev/arch repo
The signed repo is live: https://dl.breadway.dev/arch/x86_64/ serves
breadway.db + .files + every .pkg.tar.zst with a detached .sig from the
BOS release key (56203B86A110695AE7F310934AF3323D678EB5E2 = KEYS.asc),
rebuilt from the Forgejo Arch registry by signed-repo.yml +
scripts/ci-publish-signed-repo.sh. Verified: db/pkg sigs all GPG-good
against KEYS.asc.

Executes the "After the signed repo exists" plan in docs/signed-repo.md:

- `iso/pacman.conf` + `iso/airootfs/etc/pacman.conf`: section renamed
  `[Breadway.os.git.breadway.dev]` → `[breadway]` (matches breadway.db),
  `Server = https://dl.breadway.dev/arch/$arch`, `SigLevel = Required`.
  The old "Forgejo has no db sigs / KEYS.asc is not a repo key / do NOT
  flip" comments are gone — both are now false.
- `iso/airootfs/etc/pacman.d/breadway-repo.asc`: the public key, baked
  into the image.
- `build-local.sh`: trust the key in the build host's pacman keyring
  before mkarchiso (so pacstrap can verify [breadway] while assembling
  the airootfs); drop the now-obsolete Forgejo-registry URL rewrite.
- `iso/airootfs/root/customize_airootfs.sh` (new): trust the key in the
  image keyring so the live medium — and, via calamares unpackfs, the
  installed target — verify [breadway]. (archiso warns this hook is
  deprecated; there is no replacement for "add a repo key to the image
  keyring" and BOS ships no pacman-init.service.)
- `calamares/post-install.sh`: `pacman-key --add` + `--lsign-key` the
  BOS key in the target chroot as a fallback (unpackfs can skip
  /etc/pacman.d/gnupg).
- README.md / DESIGN.md / docs/signed-repo.md updated.

NOT yet done: build the ISO (`sudo ./build-local.sh`) and VM-verify
`pacman -Sy` + a `[breadway]` install with no signature prompt, on both
the live medium and a fresh install. The build-time keyring path
(pacstrap -G vs host keyring vs customize_airootfs) may need a tweak
once the real build runs.
2026-08-31 18:22:55 +08:00

65 lines
2.6 KiB
PacmanConf

#
# BOS pacman.conf — used during ISO build and installed to the target system.
# Based on the standard Arch Linux pacman.conf.
#
[options]
HoldPkg = pacman glibc
Architecture = auto
CheckSpace
ParallelDownloads = 5
# Optional NoExtract size levers — left disabled. This file is both the ISO
# build config AND the installed system's pacman.conf, so enabling any line
# also stops future pacman -Syu from restoring those files.
# Measured against the 844-package closure (xz squashfs, profiledef.sh opts):
# usr/share/locale (non-en) 405.0 MiB raw -> 92.28 MiB ISO
# usr/share/doc 130.5 MiB raw -> 26.54 MiB ISO
# usr/share/man 41.5 MiB raw -> 38.77 MiB ISO
# usr/share/info 12.9 MiB raw -> 11.12 MiB ISO
# usr/share/gtk-doc 16.0 MiB raw -> 1.18 MiB ISO
# usr/include 193.6 MiB raw -> 25.26 MiB ISO
# Non-en locales make every GUI English-only until the package is reinstalled
# without this NoExtract; dropping man/info means `man` returns nothing.
#NoExtract = usr/share/locale/* !usr/share/locale/en* !usr/share/locale/locale.alias
#NoExtract = usr/share/doc/* usr/share/gtk-doc/* usr/share/info/*
#NoExtract = usr/share/man/*
#NoExtract = usr/include/*
Color
VerbosePkgLists
ILoveCandy
SigLevel = Required DatabaseOptional
LocalFileSigLevel = Optional
[core]
Include = /etc/pacman.d/mirrorlist
[extra]
Include = /etc/pacman.d/mirrorlist
[multilib]
Include = /etc/pacman.d/mirrorlist
# -----------------------------------------------------------------------
# Breadway custom repo — breadlock plus AUR republishes the ISO needs
# (calamares, zen-browser-bin, bibata-cursor-theme-bin, yay-bin,
# zsh-theme-powerlevel10k). bakery / breadbar / bos-settings / breadhelp
# are NOT here; they are bakery-baked into /usr/local at ISO build time.
#
# Packages are published to the Forgejo Arch registry (group "os") by the
# .forgejo/workflows/*.yml workflows; scripts/ci-publish-signed-repo.sh then
# collects them, detach-signs each .pkg.tar.zst with the BOS release key
# (releases@breadway.dev), runs `repo-add -s`, and publishes the signed db
# at https://dl.breadway.dev/arch/$arch (signed-repo.yml).
#
# SigLevel = Required: every package AND the db carry a .sig from key
# 56203B86A110695AE7F310934AF3323D678EB5E2 — the same key committed as
# KEYS.asc / airootfs/etc/pacman.d/breadway-repo.asc, imported into the
# pacman keyring at build time (build-local.sh), on the live medium, and
# on the installed target (calamares/post-install.sh).
# -----------------------------------------------------------------------
[breadway]
SigLevel = Required
Server = https://dl.breadway.dev/arch/$arch