Add --skip-signing option
This commit is contained in:
@@ -33,8 +33,16 @@ print_header "Omarchy AUR Package Builder"
|
||||
# Parse command line arguments
|
||||
while [[ $# -gt 0 ]]; do
|
||||
case $1 in
|
||||
--skip-signing)
|
||||
SKIP_SIGNING=true
|
||||
shift
|
||||
;;
|
||||
-h | --help)
|
||||
echo "Usage: $0"
|
||||
echo "Usage: $0 [OPTIONS]"
|
||||
echo ""
|
||||
echo "Options:"
|
||||
echo " --skip-signing Build packages without GPG signing"
|
||||
echo " -h, --help Show this help message"
|
||||
echo ""
|
||||
echo "This script builds AUR packages from:"
|
||||
echo " build/packages/omarchy-aur.packages"
|
||||
@@ -54,30 +62,35 @@ if [[ ! -f "$BUILD_DIR/packages/omarchy-aur.packages" ]]; then
|
||||
exit 1
|
||||
fi
|
||||
|
||||
# Get GPG key from 1Password or environment for signing
|
||||
if [[ -z "$GPG_PRIVATE_KEY" ]]; then
|
||||
print_info "Fetching GPG signing key from 1Password..."
|
||||
GPG_PRIVATE_KEY=$(op document get "Omarchy GPG Private Key" --account=omarchy.1password.com) || {
|
||||
print_error "Failed to fetch GPG key from 1Password or environment"
|
||||
exit 1
|
||||
}
|
||||
# Handle GPG signing setup
|
||||
if [[ "$SKIP_SIGNING" == true ]]; then
|
||||
print_warning "Skipping GPG signing (--skip-signing flag set)"
|
||||
else
|
||||
print_info "Using existing GPG signing key from environment"
|
||||
fi
|
||||
export GPG_PRIVATE_KEY="$GPG_PRIVATE_KEY"
|
||||
# Get GPG key from 1Password or environment for signing
|
||||
if [[ -z "$GPG_PRIVATE_KEY" ]]; then
|
||||
print_info "Fetching GPG signing key from 1Password..."
|
||||
GPG_PRIVATE_KEY=$(op document get "Omarchy GPG Private Key" --account=omarchy.1password.com) || {
|
||||
print_error "Failed to fetch GPG key from 1Password or environment"
|
||||
exit 1
|
||||
}
|
||||
else
|
||||
print_info "Using existing GPG signing key from environment"
|
||||
fi
|
||||
export GPG_PRIVATE_KEY="$GPG_PRIVATE_KEY"
|
||||
|
||||
# Get passphrase from 1Password or environment
|
||||
if [[ -z "$GPG_PASSPHRASE" ]]; then
|
||||
print_info "Fetching GPG key passphrase from 1Password..."
|
||||
GPG_PASSPHRASE=$(op item get "Omarchy GPG Private Key" --account=omarchy.1password.com --fields password --reveal) || {
|
||||
print_error "Failed to fetch GPG passphrase from 1Password or environment"
|
||||
exit 1
|
||||
}
|
||||
else
|
||||
print_info "Using existing GPG passphrase from environment"
|
||||
# Get passphrase from 1Password or environment
|
||||
if [[ -z "$GPG_PASSPHRASE" ]]; then
|
||||
print_info "Fetching GPG key passphrase from 1Password..."
|
||||
GPG_PASSPHRASE=$(op item get "Omarchy GPG Private Key" --account=omarchy.1password.com --fields password --reveal) || {
|
||||
print_error "Failed to fetch GPG passphrase from 1Password or environment"
|
||||
exit 1
|
||||
}
|
||||
else
|
||||
print_info "Using existing GPG passphrase from environment"
|
||||
fi
|
||||
export GPG_PASSPHRASE
|
||||
print_success "GPG signing key and passphrase loaded"
|
||||
fi
|
||||
export GPG_PASSPHRASE
|
||||
print_success "GPG signing key and passphrase loaded"
|
||||
|
||||
# Build/update the Docker image
|
||||
print_info "Building Docker image..."
|
||||
@@ -87,6 +100,7 @@ print_info "Running AUR package build..."
|
||||
# Build Docker arguments
|
||||
DOCKER_ARGS=(
|
||||
--rm
|
||||
-e SKIP_SIGNING
|
||||
-e GPG_PRIVATE_KEY
|
||||
-e GPG_PASSPHRASE
|
||||
-v "$ARCH_DIR:/output"
|
||||
|
||||
+35
-31
@@ -3,41 +3,46 @@
|
||||
|
||||
echo "==> Importing GPG keys..."
|
||||
|
||||
# Import signing key (required)
|
||||
echo " -> Importing signing key..."
|
||||
# Import with batch mode and no tty for automated signing
|
||||
echo "$GPG_PRIVATE_KEY" | gpg --batch --import || {
|
||||
echo " -> ERROR: Failed to import signing key"
|
||||
exit 1
|
||||
}
|
||||
# Check if signing is enabled
|
||||
if [[ "$SKIP_SIGNING" == true ]]; then
|
||||
echo " -> Skipping signing key import (--skip-signing enabled)"
|
||||
else
|
||||
# Import signing key (required for signing)
|
||||
echo " -> Importing signing key..."
|
||||
# Import with batch mode and no tty for automated signing
|
||||
echo "$GPG_PRIVATE_KEY" | gpg --batch --import || {
|
||||
echo " -> ERROR: Failed to import signing key"
|
||||
exit 1
|
||||
}
|
||||
|
||||
# Configure GPG for automated signing with passphrase
|
||||
echo "allow-loopback-pinentry" >>~/.gnupg/gpg-agent.conf
|
||||
echo "pinentry-mode loopback" >>~/.gnupg/gpg.conf
|
||||
gpg-connect-agent reloadagent /bye 2>/dev/null || true
|
||||
# Configure GPG for automated signing with passphrase
|
||||
echo "allow-loopback-pinentry" >>~/.gnupg/gpg-agent.conf
|
||||
echo "pinentry-mode loopback" >>~/.gnupg/gpg.conf
|
||||
gpg-connect-agent reloadagent /bye 2>/dev/null || true
|
||||
|
||||
# Extract key ID and configure
|
||||
KEY_ID=$(gpg --list-secret-keys --keyid-format LONG | grep "sec" | head -1 | awk '{print $2}' | cut -d'/' -f2)
|
||||
if [[ -n "$KEY_ID" ]]; then
|
||||
# Trust the key using fingerprint
|
||||
FINGERPRINT=$(gpg --list-secret-keys --with-colons | grep "^fpr" | head -1 | cut -d':' -f10)
|
||||
echo "$FINGERPRINT:6:" | gpg --import-ownertrust
|
||||
# Set as default key in makepkg.conf
|
||||
echo "GPGKEY=\"$KEY_ID\"" >>~/.makepkg.conf
|
||||
echo " -> Signing key configured: $KEY_ID"
|
||||
# Extract key ID and configure
|
||||
KEY_ID=$(gpg --list-secret-keys --keyid-format LONG | grep "sec" | head -1 | awk '{print $2}' | cut -d'/' -f2)
|
||||
if [[ -n "$KEY_ID" ]]; then
|
||||
# Trust the key using fingerprint
|
||||
FINGERPRINT=$(gpg --list-secret-keys --with-colons | grep "^fpr" | head -1 | cut -d':' -f10)
|
||||
echo "$FINGERPRINT:6:" | gpg --import-ownertrust
|
||||
# Set as default key in makepkg.conf
|
||||
echo "GPGKEY=\"$KEY_ID\"" >>~/.makepkg.conf
|
||||
echo " -> Signing key configured: $KEY_ID"
|
||||
|
||||
# Test signing with the key and passphrase
|
||||
echo " -> Testing GPG signing capability..."
|
||||
echo "test" | gpg --batch --yes --pinentry-mode loopback --passphrase "$GPG_PASSPHRASE" --sign --local-user "$KEY_ID" >/dev/null 2>&1
|
||||
if [[ $? -ne 0 ]]; then
|
||||
echo " -> ERROR: Failed to sign with the provided passphrase"
|
||||
echo " -> Please check your passphrase and try again"
|
||||
# Test signing with the key and passphrase
|
||||
echo " -> Testing GPG signing capability..."
|
||||
echo "test" | gpg --batch --yes --pinentry-mode loopback --passphrase "$GPG_PASSPHRASE" --sign --local-user "$KEY_ID" >/dev/null 2>&1
|
||||
if [[ $? -ne 0 ]]; then
|
||||
echo " -> ERROR: Failed to sign with the provided passphrase"
|
||||
echo " -> Please check your passphrase and try again"
|
||||
exit 1
|
||||
fi
|
||||
echo " -> GPG signing test successful"
|
||||
else
|
||||
echo " -> ERROR: Could not extract key ID"
|
||||
exit 1
|
||||
fi
|
||||
echo " -> GPG signing test successful"
|
||||
else
|
||||
echo " -> ERROR: Could not extract key ID"
|
||||
exit 1
|
||||
fi
|
||||
|
||||
# Read the gpg-keys.txt file for verification keys
|
||||
@@ -68,4 +73,3 @@ else
|
||||
fi
|
||||
|
||||
echo " -> GPG setup complete"
|
||||
|
||||
|
||||
Reference in New Issue
Block a user