diff --git a/.forgejo/workflows/build.yml b/.forgejo/workflows/build.yml index c506318..0477ce1 100644 --- a/.forgejo/workflows/build.yml +++ b/.forgejo/workflows/build.yml @@ -94,3 +94,9 @@ jobs: override: true release-dir: dist token: ${{ secrets.GITHUB_TOKEN }} + # Empty, NOT 'false': the action guards its release-notes-assistant + # cache step with `if: ${{ inputs.release-notes-assistant }}`, where + # the default string 'false' is truthy. That step then can't reach the + # runner's cache server (it advertises the host's public IP) and burns + # ~4m40s per run on a connect timeout before reporting a miss. + release-notes-assistant: '' diff --git a/README.md b/README.md index 3bc0da1..01a42ad 100644 --- a/README.md +++ b/README.md @@ -37,13 +37,10 @@ cd fp6-img ./install.sh ``` -[`install.sh`](install.sh) and this README are attached to every release -uncompressed as well, so you can read them before committing to the download. - -It erases dtbo, flashes the rootfs, **RAM-boots** the kernel (`fastboot -boot` — verified to write nothing), writes the boot partition from inside -Linux where the bootloader's NV-wipe cannot see it, then reads the modem NV -back and reports the result. The bootloader never writes `boot`. +`install.sh` erases dtbo, flashes the rootfs, **RAM-boots** the kernel +(`fastboot boot` — verified to write nothing), writes the boot partition from +inside Linux where the bootloader's NV-wipe cannot see it, then reads the modem +NV back and reports the result. The bootloader never writes `boot`. Default login: `user` / `147147` (same as official postmarketOS images — change it). **Never re-lock the bootloader** with a custom image installed. diff --git a/build.sh b/build.sh index a596a3f..34d1141 100755 --- a/build.sh +++ b/build.sh @@ -177,20 +177,12 @@ EXPORT=/tmp/postmarketOS-export rm -rf "$EXPORT" pmbootstrap export "$EXPORT" -{ - echo "kernel: $KERNEL_REPO $KERNEL_BRANCH @ $COMMIT" - echo "built: $(date -u +%Y-%m-%dT%H:%M:%SZ)" - echo "default login: user / 147147 (same as official postmarketOS images)" - echo "imsd: $IMSD_REPO @ $IMSD_COMMIT (0.3.0)" -} > dist/build-info.txt -cp README.md dist/README.md -cp install.sh dist/install.sh - -# The images ship as one archive, not as loose files: the rootfs is 3.0 GiB -# raw and 812 MiB under xz -6 (gzip -6 stops at 1144 MiB), and a bundle makes -# it impossible to pair a boot.img with a rootfs from a different build. -# README/install.sh/build-info stay loose in dist too, so they can be read -# before committing to the download. +# Everything ships as ONE archive, and dist/ holds nothing else: the rootfs is +# 3.0 GiB raw and 812 MiB under xz -6 (gzip -6 stops at 1144 MiB), and a bundle +# makes it impossible to pair a boot.img with a rootfs from a different build. +# README/install.sh are not attached loose as well — they are readable in the +# repository, and a second copy in the release only invites reading a stale one +# (and a loose sha256sums.txt next to the archive's own is pure confusion). # # pmbootstrap export writes symlinks into its work dir; tar -h resolves them, # so the archive is built without a second 3 GiB copy on disk. @@ -199,11 +191,16 @@ rm -rf "$STAGE" mkdir -p "$STAGE/fp6-img" ln -s "$EXPORT/boot.img" "$STAGE/fp6-img/boot.img" ln -s "$EXPORT/fairphone-fp6.img" "$STAGE/fp6-img/fairphone-fp6.img" -cp dist/build-info.txt dist/README.md dist/install.sh "$STAGE/fp6-img/" -# sums of the extracted contents (the outer sha256sums.txt covers the archive) +cp README.md install.sh "$STAGE/fp6-img/" +{ + echo "kernel: $KERNEL_REPO $KERNEL_BRANCH @ $COMMIT" + echo "built: $(date -u +%Y-%m-%dT%H:%M:%SZ)" + echo "default login: user / 147147 (same as official postmarketOS images)" + echo "imsd: $IMSD_REPO @ $IMSD_COMMIT (0.3.0)" +} > "$STAGE/fp6-img/build-info.txt" +# sums of the extracted contents (cd "$STAGE/fp6-img" && sha256sum -- * > sha256sums.txt) tar -C "$STAGE" -chf - fp6-img | xz -T0 -6 > dist/fp6-img.tar.xz rm -rf "$STAGE" -(cd dist && sha256sum -- * > sha256sums.txt) ls -la dist/