Skip to content

feat(package): survive attended sysupgrade - registry self-heal + real v3 feed - #301

Merged
gnacho merged 7 commits into
mainfrom
feat/296-asu-survive
Sep 12, 2026
Merged

gnacho merged 7 commits into
mainfrom
feat/296-asu-survive

Conversation

@gnacho

@gnacho gnacho commented Sep 12, 2026

Copy link
Copy Markdown
Owner

Closes #296

What

Three pieces so an owut/ASU upgrade does not turn netgrip into an unmanaged ghost:

  • Registry self-heal: netgrip-heal-register runs in the background from the init script. If the apk/opkg registry no longer lists netgrip (the files survive via /etc/sysupgrade.conf, the registry does not), it reinstalls the running version from the latest GitHub release: the matching .apk asset with apk add --allow-untrusted (OpenWrt 25) or the matching .ipk with opkg (24.10). Dev builds newer than the latest release are left alone. Failures log and retry on next boot; the panel is never blocked. netgrip -version is new (used by the heal).
  • Fixed feed CI: the apk feed job was publishing a broken feed - it ran on Alpine apk-tools 2.14, which cannot read OpenWrt apk packages at all, and swallowed the index failure with a warning + exit 0. Now it builds packages.adb with mkndx from the OpenWrt SDK host tools, signs it with usign (NETGRIP_FEED_KEY secret), publishes the matching public key, and fails closed.
  • Packaging: the heal helper ships in the package and is preserved across sysupgrades.

Findings (verified on a real 25.12 arm64 router)

  • 25.x repositories point at the full packages.adb URL; routers also probe <repo>/<arch>/APKINDEX.tar.gz (v2) as fallback.
  • Official feed indexes are PGP-signed by the OpenWrt build system; third-party adb feeds with usign signatures are read but rejected as UNTRUSTED, and there is no per-repository allow-untrusted flag. So apk upgrade cannot pick up this feed on stock routers yet; the heal path above does not depend on it, and the feed structure is ready for whenever OpenWrt documents third-party index signing.

Validation

  • Feed CI run green end-to-end (dispatch on v0.72.2): gh-pages now carries the apks plus packages.adb, packages.adb.asc and netgrip-feed.pub. Local verification of the index/signature pair with the SDK tools.
  • Heal negative path verified on two live routers (apk 25.12 arm64 and opkg 24.10 mipsel): exits immediately with the registry present, zero log noise.
  • Full go test ./... green; sh -n clean on all touched scripts.

… errors (#296)

alpine:3.21 ships apk-tools 2.14, which cannot read OpenWrt 25 apk-v3
packages: apk index failed on every file with IO ERROR and the script
swallowed it, publishing a feed with no index and no signing key. Use
alpine:edge (apk-tools 3.x) and let index failures fail the job.
)

apk-tools 3 verifies package signatures while indexing, but the release
apks are signed by the SDK build keys: index with --allow-untrusted and
keep the trust in the signed APKINDEX. Extract the public key before
indexing so it lands in the feed regardless of later steps.
…ade (#296)

owut/ASU drops packages outside official feeds from the built image: the
files survive via /etc/sysupgrade.conf but the apk/opkg registry entry is
gone, so the package stops being installed and package managers never
upgrade it again.

- netgrip-heal-register runs in the background from the init script:
  exits when the registry is fine, otherwise reinstalls the running
  version from the feed (apk, OpenWrt 25) or from the latest GitHub
  release ipk (opkg, OpenWrt 24). Dev builds newer than the feed are
  left alone. Failures log and retry on next boot.
- postinst registers the apk feed and installs its signing key, so
  upgrades also arrive with apk upgrade from now on.
- netgrip -version prints the running version (used by the heal).
…Wrt apk-tools (#296)

The Alpine apk-tools cannot read OpenWrt apk packages (file format not
supported), and apk index/APKINDEX.tar.gz is the v2 layout no 25.x router
requests. Build the v3 index with mkndx from the OpenWrt SDK host tools
and sign it with usign; routers still cannot verify third-party adb feeds
(official ones are PGP-signed by the OpenWrt build system), so the
registry heal installs release assets directly instead of relying on the
feed.
@gnacho
gnacho merged commit 216a190 into main Sep 12, 2026
12 checks passed
@gnacho
gnacho deleted the feat/296-asu-survive branch September 12, 2026 19:11
gnacho added a commit that referenced this pull request Sep 22, 2026
…l v3 feed (#301)

* fix(ci): build the apk feed with apk-tools 3 and fail closed on index errors (#296)

alpine:3.21 ships apk-tools 2.14, which cannot read OpenWrt 25 apk-v3
packages: apk index failed on every file with IO ERROR and the script
swallowed it, publishing a feed with no index and no signing key. Use
alpine:edge (apk-tools 3.x) and let index failures fail the job.

* fix(ci): index the apk feed with apk-tools 3 and --allow-untrusted (#296)

apk-tools 3 verifies package signatures while indexing, but the release
apks are signed by the SDK build keys: index with --allow-untrusted and
keep the trust in the signed APKINDEX. Extract the public key before
indexing so it lands in the feed regardless of later steps.

* feat(package): self-heal the apk/opkg registry after attended sysupgrade (#296)

owut/ASU drops packages outside official feeds from the built image: the
files survive via /etc/sysupgrade.conf but the apk/opkg registry entry is
gone, so the package stops being installed and package managers never
upgrade it again.

- netgrip-heal-register runs in the background from the init script:
  exits when the registry is fine, otherwise reinstalls the running
  version from the feed (apk, OpenWrt 25) or from the latest GitHub
  release ipk (opkg, OpenWrt 24). Dev builds newer than the feed are
  left alone. Failures log and retry on next boot.
- postinst registers the apk feed and installs its signing key, so
  upgrades also arrive with apk upgrade from now on.
- netgrip -version prints the running version (used by the heal).

* fix(ci): package without the signing key until it exists in the tree (#296)

* fix(ci): publish a v3 feed (packages.adb + usign) built with the OpenWrt apk-tools (#296)

The Alpine apk-tools cannot read OpenWrt apk packages (file format not
supported), and apk index/APKINDEX.tar.gz is the v2 layout no 25.x router
requests. Build the v3 index with mkndx from the OpenWrt SDK host tools
and sign it with usign; routers still cannot verify third-party adb feeds
(official ones are PGP-signed by the OpenWrt build system), so the
registry heal installs release assets directly instead of relying on the
feed.

* fix(ci): install bash for the OpenWrt SDK apk wrapper (#296)

* fix(ci): resolve the public key path before cd into the feed (#296)

---------

Co-authored-by: gnacho <hnacho@proton.me>
gnacho added a commit that referenced this pull request Sep 22, 2026
The 15 MB binary was committed accidentally in 216a190 (#301). Nothing in
the repo references it: install.sh, packaging and CI all build their own.
Add /netgrip to .gitignore so it cannot be committed again.

Closes #391

Co-authored-by: gnacho <hnacho@proton.me>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Investigate making netgrip survive attended sysupgrade (ASU) as a real package

1 participant