diff --git a/bin/build b/bin/build index b5f8e68..cc3d033 100755 --- a/bin/build +++ b/bin/build @@ -33,8 +33,16 @@ print_header "Omarchy AUR Package Builder" # Parse command line arguments while [[ $# -gt 0 ]]; do case $1 in + --skip-signing) + SKIP_SIGNING=true + shift + ;; -h | --help) - echo "Usage: $0" + echo "Usage: $0 [OPTIONS]" + echo "" + echo "Options:" + echo " --skip-signing Build packages without GPG signing" + echo " -h, --help Show this help message" echo "" echo "This script builds AUR packages from:" echo " build/packages/omarchy-aur.packages" @@ -54,30 +62,35 @@ if [[ ! -f "$BUILD_DIR/packages/omarchy-aur.packages" ]]; then exit 1 fi -# Get GPG key from 1Password or environment for signing -if [[ -z "$GPG_PRIVATE_KEY" ]]; then - print_info "Fetching GPG signing key from 1Password..." - GPG_PRIVATE_KEY=$(op document get "Omarchy GPG Private Key" --account=omarchy.1password.com) || { - print_error "Failed to fetch GPG key from 1Password or environment" - exit 1 - } +# Handle GPG signing setup +if [[ "$SKIP_SIGNING" == true ]]; then + print_warning "Skipping GPG signing (--skip-signing flag set)" else - print_info "Using existing GPG signing key from environment" -fi -export GPG_PRIVATE_KEY="$GPG_PRIVATE_KEY" + # Get GPG key from 1Password or environment for signing + if [[ -z "$GPG_PRIVATE_KEY" ]]; then + print_info "Fetching GPG signing key from 1Password..." + GPG_PRIVATE_KEY=$(op document get "Omarchy GPG Private Key" --account=omarchy.1password.com) || { + print_error "Failed to fetch GPG key from 1Password or environment" + exit 1 + } + else + print_info "Using existing GPG signing key from environment" + fi + export GPG_PRIVATE_KEY="$GPG_PRIVATE_KEY" -# Get passphrase from 1Password or environment -if [[ -z "$GPG_PASSPHRASE" ]]; then - print_info "Fetching GPG key passphrase from 1Password..." - GPG_PASSPHRASE=$(op item get "Omarchy GPG Private Key" --account=omarchy.1password.com --fields password --reveal) || { - print_error "Failed to fetch GPG passphrase from 1Password or environment" - exit 1 - } -else - print_info "Using existing GPG passphrase from environment" + # Get passphrase from 1Password or environment + if [[ -z "$GPG_PASSPHRASE" ]]; then + print_info "Fetching GPG key passphrase from 1Password..." + GPG_PASSPHRASE=$(op item get "Omarchy GPG Private Key" --account=omarchy.1password.com --fields password --reveal) || { + print_error "Failed to fetch GPG passphrase from 1Password or environment" + exit 1 + } + else + print_info "Using existing GPG passphrase from environment" + fi + export GPG_PASSPHRASE + print_success "GPG signing key and passphrase loaded" fi -export GPG_PASSPHRASE -print_success "GPG signing key and passphrase loaded" # Build/update the Docker image print_info "Building Docker image..." @@ -87,6 +100,7 @@ print_info "Running AUR package build..." # Build Docker arguments DOCKER_ARGS=( --rm + -e SKIP_SIGNING -e GPG_PRIVATE_KEY -e GPG_PASSPHRASE -v "$ARCH_DIR:/output" diff --git a/build/import-gpg-keys.sh b/build/import-gpg-keys.sh index 59a15c2..2e93e0d 100755 --- a/build/import-gpg-keys.sh +++ b/build/import-gpg-keys.sh @@ -3,41 +3,46 @@ echo "==> Importing GPG keys..." -# Import signing key (required) -echo " -> Importing signing key..." -# Import with batch mode and no tty for automated signing -echo "$GPG_PRIVATE_KEY" | gpg --batch --import || { - echo " -> ERROR: Failed to import signing key" - exit 1 -} +# Check if signing is enabled +if [[ "$SKIP_SIGNING" == true ]]; then + echo " -> Skipping signing key import (--skip-signing enabled)" +else + # Import signing key (required for signing) + echo " -> Importing signing key..." + # Import with batch mode and no tty for automated signing + echo "$GPG_PRIVATE_KEY" | gpg --batch --import || { + echo " -> ERROR: Failed to import signing key" + exit 1 + } -# Configure GPG for automated signing with passphrase -echo "allow-loopback-pinentry" >>~/.gnupg/gpg-agent.conf -echo "pinentry-mode loopback" >>~/.gnupg/gpg.conf -gpg-connect-agent reloadagent /bye 2>/dev/null || true + # Configure GPG for automated signing with passphrase + echo "allow-loopback-pinentry" >>~/.gnupg/gpg-agent.conf + echo "pinentry-mode loopback" >>~/.gnupg/gpg.conf + gpg-connect-agent reloadagent /bye 2>/dev/null || true -# Extract key ID and configure -KEY_ID=$(gpg --list-secret-keys --keyid-format LONG | grep "sec" | head -1 | awk '{print $2}' | cut -d'/' -f2) -if [[ -n "$KEY_ID" ]]; then - # Trust the key using fingerprint - FINGERPRINT=$(gpg --list-secret-keys --with-colons | grep "^fpr" | head -1 | cut -d':' -f10) - echo "$FINGERPRINT:6:" | gpg --import-ownertrust - # Set as default key in makepkg.conf - echo "GPGKEY=\"$KEY_ID\"" >>~/.makepkg.conf - echo " -> Signing key configured: $KEY_ID" + # Extract key ID and configure + KEY_ID=$(gpg --list-secret-keys --keyid-format LONG | grep "sec" | head -1 | awk '{print $2}' | cut -d'/' -f2) + if [[ -n "$KEY_ID" ]]; then + # Trust the key using fingerprint + FINGERPRINT=$(gpg --list-secret-keys --with-colons | grep "^fpr" | head -1 | cut -d':' -f10) + echo "$FINGERPRINT:6:" | gpg --import-ownertrust + # Set as default key in makepkg.conf + echo "GPGKEY=\"$KEY_ID\"" >>~/.makepkg.conf + echo " -> Signing key configured: $KEY_ID" - # Test signing with the key and passphrase - echo " -> Testing GPG signing capability..." - echo "test" | gpg --batch --yes --pinentry-mode loopback --passphrase "$GPG_PASSPHRASE" --sign --local-user "$KEY_ID" >/dev/null 2>&1 - if [[ $? -ne 0 ]]; then - echo " -> ERROR: Failed to sign with the provided passphrase" - echo " -> Please check your passphrase and try again" + # Test signing with the key and passphrase + echo " -> Testing GPG signing capability..." + echo "test" | gpg --batch --yes --pinentry-mode loopback --passphrase "$GPG_PASSPHRASE" --sign --local-user "$KEY_ID" >/dev/null 2>&1 + if [[ $? -ne 0 ]]; then + echo " -> ERROR: Failed to sign with the provided passphrase" + echo " -> Please check your passphrase and try again" + exit 1 + fi + echo " -> GPG signing test successful" + else + echo " -> ERROR: Could not extract key ID" exit 1 fi - echo " -> GPG signing test successful" -else - echo " -> ERROR: Could not extract key ID" - exit 1 fi # Read the gpg-keys.txt file for verification keys @@ -68,4 +73,3 @@ else fi echo " -> GPG setup complete" -