feat(package): survive attended sysupgrade - registry self-heal + real v3 feed - #301
Merged
Merged
Conversation
… errors (#296) alpine:3.21 ships apk-tools 2.14, which cannot read OpenWrt 25 apk-v3 packages: apk index failed on every file with IO ERROR and the script swallowed it, publishing a feed with no index and no signing key. Use alpine:edge (apk-tools 3.x) and let index failures fail the job.
…ade (#296) owut/ASU drops packages outside official feeds from the built image: the files survive via /etc/sysupgrade.conf but the apk/opkg registry entry is gone, so the package stops being installed and package managers never upgrade it again. - netgrip-heal-register runs in the background from the init script: exits when the registry is fine, otherwise reinstalls the running version from the feed (apk, OpenWrt 25) or from the latest GitHub release ipk (opkg, OpenWrt 24). Dev builds newer than the feed are left alone. Failures log and retry on next boot. - postinst registers the apk feed and installs its signing key, so upgrades also arrive with apk upgrade from now on. - netgrip -version prints the running version (used by the heal).
…Wrt apk-tools (#296) The Alpine apk-tools cannot read OpenWrt apk packages (file format not supported), and apk index/APKINDEX.tar.gz is the v2 layout no 25.x router requests. Build the v3 index with mkndx from the OpenWrt SDK host tools and sign it with usign; routers still cannot verify third-party adb feeds (official ones are PGP-signed by the OpenWrt build system), so the registry heal installs release assets directly instead of relying on the feed.
gnacho
added a commit
that referenced
this pull request
Sep 22, 2026
…l v3 feed (#301) * fix(ci): build the apk feed with apk-tools 3 and fail closed on index errors (#296) alpine:3.21 ships apk-tools 2.14, which cannot read OpenWrt 25 apk-v3 packages: apk index failed on every file with IO ERROR and the script swallowed it, publishing a feed with no index and no signing key. Use alpine:edge (apk-tools 3.x) and let index failures fail the job. * fix(ci): index the apk feed with apk-tools 3 and --allow-untrusted (#296) apk-tools 3 verifies package signatures while indexing, but the release apks are signed by the SDK build keys: index with --allow-untrusted and keep the trust in the signed APKINDEX. Extract the public key before indexing so it lands in the feed regardless of later steps. * feat(package): self-heal the apk/opkg registry after attended sysupgrade (#296) owut/ASU drops packages outside official feeds from the built image: the files survive via /etc/sysupgrade.conf but the apk/opkg registry entry is gone, so the package stops being installed and package managers never upgrade it again. - netgrip-heal-register runs in the background from the init script: exits when the registry is fine, otherwise reinstalls the running version from the feed (apk, OpenWrt 25) or from the latest GitHub release ipk (opkg, OpenWrt 24). Dev builds newer than the feed are left alone. Failures log and retry on next boot. - postinst registers the apk feed and installs its signing key, so upgrades also arrive with apk upgrade from now on. - netgrip -version prints the running version (used by the heal). * fix(ci): package without the signing key until it exists in the tree (#296) * fix(ci): publish a v3 feed (packages.adb + usign) built with the OpenWrt apk-tools (#296) The Alpine apk-tools cannot read OpenWrt apk packages (file format not supported), and apk index/APKINDEX.tar.gz is the v2 layout no 25.x router requests. Build the v3 index with mkndx from the OpenWrt SDK host tools and sign it with usign; routers still cannot verify third-party adb feeds (official ones are PGP-signed by the OpenWrt build system), so the registry heal installs release assets directly instead of relying on the feed. * fix(ci): install bash for the OpenWrt SDK apk wrapper (#296) * fix(ci): resolve the public key path before cd into the feed (#296) --------- Co-authored-by: gnacho <hnacho@proton.me>
This was referenced Sep 22, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #296
What
Three pieces so an owut/ASU upgrade does not turn netgrip into an unmanaged ghost:
netgrip-heal-registerruns in the background from the init script. If the apk/opkg registry no longer lists netgrip (the files survive via/etc/sysupgrade.conf, the registry does not), it reinstalls the running version from the latest GitHub release: the matching.apkasset withapk add --allow-untrusted(OpenWrt 25) or the matching.ipkwith opkg (24.10). Dev builds newer than the latest release are left alone. Failures log and retry on next boot; the panel is never blocked.netgrip -versionis new (used by the heal).exit 0. Now it buildspackages.adbwithmkndxfrom the OpenWrt SDK host tools, signs it with usign (NETGRIP_FEED_KEYsecret), publishes the matching public key, and fails closed.Findings (verified on a real 25.12 arm64 router)
packages.adbURL; routers also probe<repo>/<arch>/APKINDEX.tar.gz(v2) as fallback.apk upgradecannot pick up this feed on stock routers yet; the heal path above does not depend on it, and the feed structure is ready for whenever OpenWrt documents third-party index signing.Validation
packages.adb,packages.adb.ascandnetgrip-feed.pub. Local verification of the index/signature pair with the SDK tools.go test ./...green;sh -nclean on all touched scripts.