Compare commits

..
2 Commits
Author SHA1 Message Date
archipelago fcc18b392f Merge #824ffe2c: Add third v1.9.2-alpha release note
Demo images / Build & push demo images (push) Failing after 35s
nostr:nevent1qqsgynl793sxe686xpdpqsfrszlxvf7gwknrj67p4znlndwk8tnd8wspz3mhxue69uhhyetvv9ujumn8d96zuer9wc39sja0

PR-Author: Personal
nostr:npub1w3sqdkrhn0gyuvsex32effzgnfpyde6qrrc4u467flg5e9txh4wsfn5vjg

PR description:

Release manifest check requires at least 3 curated bullets; What is New resynced.
2026-10-11 09:27:02 -04:00
archipelago 597489aa3c docs: add third v1.9.2-alpha release note 2026-10-11 09:26:47 -04:00
9 changed files with 32 additions and 488 deletions
+1
View File
@@ -3,6 +3,7 @@
## v1.9.2-alpha (2026-10-10)
- Ship the Archipelago companion 0.5.37 (build 57) APK so the downloadable app matches the Android source version and its local playback diagnostics.
- Build the installer ISO with a release gate that checks the bundled companion APK version against the Android source version.
- Carries all v1.9.1-alpha changes and known limitations unchanged; v1.9.1-alpha shipped the 0.5.36 companion APK and has no installer ISO.
## v1.9.1-alpha (2026-10-10)
+1 -2
View File
@@ -18,8 +18,7 @@ RUN set -eux; \
mkdir -p /home/bitcoin/.bitcoin; \
chown -R bitcoin:bitcoin /home/bitcoin
# bin/ holds the SHA-256 + GPG-verified bitcoind / bitcoin-cli (Guix-built,
# x86_64-linux-gnu or aarch64-linux-gnu — pass the arch to the build script)
# extracted from the official release tarball.
# x86_64-linux-gnu) extracted from the official release tarball.
COPY bin/bitcoind /usr/local/bin/bitcoind
COPY bin/bitcoin-cli /usr/local/bin/bitcoin-cli
RUN chmod 0755 /usr/local/bin/bitcoind /usr/local/bin/bitcoin-cli
+1 -2
View File
@@ -19,8 +19,7 @@ RUN set -eux; \
mkdir -p /home/bitcoin/.bitcoin; \
chown -R bitcoin:bitcoin /home/bitcoin
# bin/ holds the SHA-256 + GPG-verified bitcoind / bitcoin-cli (Knots, Guix-built,
# x86_64-linux-gnu or aarch64-linux-gnu — pass the arch to the build script)
# extracted from the official release tarball.
# x86_64-linux-gnu) extracted from the official release tarball.
COPY bin/bitcoind /usr/local/bin/bitcoind
COPY bin/bitcoin-cli /usr/local/bin/bitcoin-cli
RUN chmod 0755 /usr/local/bin/bitcoind /usr/local/bin/bitcoin-cli
-125
View File
@@ -1,125 +0,0 @@
# Handoff — ARM64 build on the M2 (supersedes 2026-10-10 handoff where they differ)
**Date:** 2026-10-11
**Goal:** Build Archipelago for ARM (Raspberry Pi and other ARM devices) with an
installer/image. Nothing bootable exists yet.
## Repo state
- Laptop `~/Projects/archy`: sparse + partial clone (`blob:none`). Local `main`
fast-forwarded to `origin/main` = `2d19d03e` (v1.9.2-alpha changelog merge).
Backend/frontend versions on main: `1.9.1-alpha`.
- Branch **`arm64-pi-test`** (from main `2d19d03e`), commit `4cd6449b`
"build: enable aarch64 (Raspberry Pi) backend and bitcoin image builds".
Contents = old `stash@{0}` applied cleanly (build-backend.sh,
build-bitcoin-image.sh, bitcoin-core/knots Dockerfiles, docs/README.md,
docs/raspberry-pi-test-install.md). **Not pushed anywhere.**
- `stash@{0}` still exists on the laptop (safe to drop once the branch is pushed).
- The laptop's working branch was `app/angor-frpc` (untouched). Untracked
handoff/notes files on the laptop are intentionally uncommitted.
- Same commit applied on the M2 as `b158aac` on branch `arm64-pi-test`
(via `git am`, local identity passed with `-c`, global git config untouched).
## The ARM build machine ("the M2")
- `ssh m2` (Host entry in the maintainer's laptop `~/.ssh/config`; address/user not recorded in the repo)
- It is **Arch Linux ARM (aarch64, Asahi) — not macOS.** 8 cores, 7.4 GB RAM + 7.4 GB zram swap, ~124 GB free.
- Key `~/.ssh/id_ed25519_m2` (no passphrase, laptop-side) was created on the laptop for
agent use. The user's main `~/.ssh/id_ed25519` has a passphrase and cannot
be used non-interactively. No passwords are stored in this repo.
- The account's sudo is password-protected; the agent has no sudo. The account was
briefly locked by pam_faillock after failed attempts (cleared by waiting).
- Installed/fixed this session (by the user, via sudo): `xorriso`,
`squashfs-tools`, `mtools`; docker enabled and `mama` in the `docker` group
(docker 29.8.2). podman 6.1.3 rootless also works.
- Rust: mise's rust shim is broken. **Use `export PATH=$HOME/.cargo/bin:$PATH`**
(cargo/rustc 1.99.0). Node: `$HOME/.local/share/mise/installs/node/26.11.1/bin`.
- Checkout: `~/Projects/archy` (NOT sparse), branch `arm64-pi-test`
at `b158aac` on top of origin/main `2d19d03`.
## Built artifacts (on the M2, from 1.9.1-alpha)
- Backend: `~/Projects/archy/image-recipe/build/backend/archipelago`
— ELF aarch64, 53 MB, reports `1.9.1-alpha-dev`,
SHA256 `b32c8cffa9b512e697dedbccc6799b10180b643ce8b158b4263aec3c67da4f99`.
Built with `CARGO_BUILD_JOBS=4 ARCH=aarch64 image-recipe/scripts/build-backend.sh`
(native build, ~5 min; output name is `archipelago`, not `archipelago-aarch64`,
because the host is already aarch64).
- Frontend: `image-recipe/build/frontend/` (69 MB), via `npm ci` +
`image-recipe/scripts/build-frontend.sh`. The stale 1.8.11 `web-ui.tar.gz`
was deleted.
- Bitcoin **Core** 28.4 arm64 image exists on the laptop
(`image-recipe/build/bitcoin-28.4-aarch64.tar`) but is NOT needed for the ISO:
the ISO bundles Bitcoin **Knots** and ~25 other images pulled by the ISO
builder itself (`--platform linux/arm64`). Do not build it for the ISO.
## ISO / installer findings (not started)
`image-recipe/build-debian-iso.sh` wraps
`image-recipe/_archived/build-auto-installer-iso.sh` (archived; OTA tarballs
replaced it upstream). It accepts `ARCH=arm64` (kernel, grub-efi-arm64 vars) but
many x86 assumptions remain:
- l.328 `fips_*_amd64.deb`; l.413 `amd64-microcode`;
l.896 `grub-efi-amd64-bin grub-pc-bin isolinux syslinux-common`
- l.1095 `mksquashfs ... -Xbcj x86`; l.1131 `grub-mkstandalone -O x86_64-efi`
- l.1174 expects `BOOTX64.EFI` (arm64: `BOOTAA64.EFI`)
- ISO layout (l.1146, 4382-4506) uses isolinux/BIOS hybrid boot
- Defaults: `ARCH=x86_64`; `DEV_SERVER=archipelago@192.0.2.10` (placeholder) —
use `DEV_SERVER=localhost` to force registry pulls.
- Debootstrap runs in a `--privileged` container (needs rootful docker — now OK).
- The resulting ISO would be generic arm64 UEFI. **A Pi 4/5 will not boot it
without EDK2/UEFI firmware.** Testable in a UEFI ARM VM.
- Estimate: porting + testing ≈ half a day or more.
## Options (user has not chosen yet)
1. Port the archived ISO builder to arm64 (true installer ISO; longest).
2. Build a Pi SD/USB image from Debian arm64 (check
`image-recipe/raspberrypi/` for existing boot config) — likely what to ship.
3. Manual install on Pi OS Lite per `docs/raspberry-pi-test-install.md` —
fastest way to validate the 1.9.1 build on real hardware.
Agent recommendation: do (3) now to prove backend/frontend on a Pi, then (2).
Ask the user whether they have a Pi to test on and which target they want.
## Known gaps (from earlier handoff, still true)
Architecture-aware OTA/image selection; barkd x86-only asset; catalog audit;
`install-ngit.sh` already has an aarch64 asset. Git anomaly (missing promisor
object `f7208e17…`) on the laptop only matters if it blocks a command.
## Update — Phase 0 progress (later 2026-10-11)
- Transfer bundle on the M2: `~/arm-bundle-1.9.1/` containing
`archipelago-aarch64` (same binary/SHA256 as above), `web-ui.tar.gz` (60 MB),
`archipelago.service`, `nginx-archipelago.conf`. This is exactly what
`docs/raspberry-pi-test-install.md` Part 2 asks to copy to a Pi.
- Compatibility check vs Pi OS (Debian trixie, glibc 2.41): binary needs
GLIBC <= 2.39 (built on Arch, glibc 2.43) — OK. Dynamically links libssl.so.3,
libz, libgcc_s, brotli, zstd (all in trixie; install `libssl3t64`).
- Smoke test in `debian:trixie-slim` linux/arm64 container on the M2: binary
loads, no missing libs, prints `archipelago 1.9.1-alpha-dev`, starts
("Starting Archipelago Bitcoin Node OS"), then exits with
"Neither Podman nor Docker is available" (+ `sudo systemd-run` bootstrap
warnings). That is expected in a bare container; a real test needs a
systemd host with rootless podman (Pi or arm64 VM). /health was not reachable.
- NEXT: need a Pi (or arm64 systemd VM on the M2) to finish the Part 3
validation checklist. Then decide on the Pi image recipe (option 2).
## Update 2 — arm64 systemd test PASSED (2026-10-11)
Ran the Part 2 install inside a privileged `debian:trixie-slim` linux/arm64
systemd container on the M2 (Dockerfile: `~/arm-bundle-1.9.1/Dockerfile.systest`,
image `archy-systest`, container `archy-st`). With the gaps below fixed:
- `archipelago.service` active; backend `GET :5678/health` -> 200
(`version 1.9.1-alpha`, crash_recovery_complete, rpc+sessions up)
- nginx proxy `/health` -> 200; UI `/` -> 200 over http and https
- Non-fatal warnings only (kdump crashkernel fixup, fips anchors/`fipsctl`,
LND macaroon not present) — container-environment related.
Gaps found and documented in `docs/raspberry-pi-test-install.md` (commit on
laptop branch `arm64-pi-test`): groups `debian-tor`/`fips`, dirs under
`/home/archipelago/.{local/share,config}/containers`, `/etc/nginx/snippets/*`
from `image-recipe/configs/snippets`, TLS cert in `/etc/archipelago/ssl/`.
Not covered (needs a real Pi / VM): rootless podman app install from the UI,
real hardware, bitcoind. Still open: ISO/SD image recipe (options above).
-2
View File
@@ -49,8 +49,6 @@ disagree, the code wins and the doc is a bug.
These record why a thing is built the way it is. They are design records, not
step-by-step guides, and some predate the current implementation.
- Apple Silicon M2 development research — `apple-silicon-m2-development-research.md`; Asahi installation approach, ARM64 porting requirements and proposed milestones
- Raspberry Pi ARM64 test install — `raspberry-pi-test-install.md`; Phase-0 ARM64 validation on a Pi 5: native builds on the M2 (x86 cross-build fallback), bring-up runbook, known gaps
- [Registry-Distributed Manifests](registry-manifest-design.md)
- [DHT Distribution](dht-distribution-design.md)
- [Bitcoin Multi-Version](bitcoin-multi-version-design.md)
-196
View File
@@ -1,196 +0,0 @@
# Raspberry Pi ARM64 Test Install
**Status: Phase 0 — tooling + runbook.** Validates the ARM64 port on commodity
hardware (Pi 5) *before* committing to a real Pi image recipe. This is **not**
a shippable ARM image: the ARM image is explicitly out of scope for phase 1
(see `kdump-rasdaemon-design.md`), and the porting gap analysis in
`apple-silicon-m2-development-research.md` (written for M2/Asahi) still has
open items — most notably arch-aware OTA. The Pi is *easier* than that doc's
M2 plan in two ways: stock Debian 13 trixie (no Asahi 16K-page concerns) and
Xorg/Mesa works, so no Wayland kiosk port is needed for a headless test.
Reference material for the eventual image recipe: `image-recipe/raspberrypi/`
holds a dissected Start9 embassyOS Pi image (`config.txt`/`cmdline.txt` boot
chain, embassyOS partition layout, `init_resize.sh`). Nothing consumes it yet.
**Dedicated ARM64 build machine: the M2 Air** (the
`apple-silicon-m2-development-research.md` reference machine). In its *build*
role it needs no Asahi — macOS + Docker / podman machine run arm64 Linux
containers natively, so every build below runs at full speed with no qemu.
Asahi only matters for the M2 as a *target* device, which remains a separate
milestone in that doc. Keep x86_64 builds on the x86_64 fleet hosts —
emulating amd64 on Apple Silicon is the slow direction.
## What changed to enable this
| Change | File |
| --- | --- |
| Optional arch arg (`x86_64` default, `aarch64`); arch-suffixed tags; SHA-256 + GPG fail-closed verification unchanged | `scripts/build-bitcoin-image.sh` |
| `ARCH=aarch64` cross build: cargo-zigbuild on host (fast) or emulated `rust:trixie` Docker (slow, zero setup). Backend is rustls-only, so no sysroot libs needed | `image-recipe/scripts/build-backend.sh` |
| Dockerfile comments mention the aarch64 tarballs | `apps/bitcoin-core/Dockerfile`, `apps/bitcoin-knots/Dockerfile` |
| Frontend | unchanged — Node build, arch-agnostic |
Default (no-arg) behavior of both scripts is byte-identical to before.
## Hardware
- Raspberry Pi 5 — 4 GB is fine for signet; 8 GB for anything mainnet-ish
- 27 W PSU; storage: NVMe HAT recommended for a node, SD works for a smoke test
- Ethernet
## Part 1 — Build on the M2 (native ARM64)
Requirements on the M2: Docker (backend script) and podman + `podman machine`
(bitcoin image script). No binfmt registration — arm64 runs natively.
Backend:
```bash
ARCH=aarch64 image-recipe/scripts/build-backend.sh
# → image-recipe/build/backend/archipelago-aarch64 (native-speed arm64 build)
```
Bitcoin Core image — the app manifest pins
`source.archipelago-foundation.org/lfg2025/bitcoin:28.4` (`apps/bitcoin-core/manifest.yml`),
so build that version for arm64. On the M2 the smoke test also runs natively,
so the full fail-closed pipeline (SHA-256 + GPG + `bitcoind --version`)
executes at full fidelity:
```bash
scripts/build-bitcoin-image.sh core 28.4 aarch64 # builds, verifies, pushes
# or build + verify only, then transfer the image as a tarball:
NO_PUSH=1 scripts/build-bitcoin-image.sh core 28.4 aarch64
podman save -o bitcoin-28.4-aarch64.tar \
source.archipelago-foundation.org/lfg2025/bitcoin:28.4-aarch64
```
If the M2 has registry credentials, just push and let the Pi pull directly
(skip the save/load hop).
Frontend (arch-agnostic — build on either machine):
```bash
image-recipe/scripts/build-frontend.sh
# → image-recipe/build/frontend/ (static dist)
```
Transfer to the Pi: `archipelago-aarch64`, `bitcoin-28.4-aarch64.tar`,
frontend dist tarball, plus `image-recipe/configs/archipelago.service` and
`nginx-archipelago.conf` from the repo.
### Alternative — build on the x86_64 host (ThinkPad)
Backend cross-compiles natively with cargo-zigbuild (no emulation):
```bash
sudo pacman -S cargo-zigbuild # extra repo; pulls zig
ARCH=aarch64 image-recipe/scripts/build-backend.sh
```
The bitcoin image build runs its RUN steps under qemu — register handlers
once; the smoke test there is best-effort (SHA-256 + GPG remain the real
gate, re-verify natively on the Pi):
```bash
podman run --privileged quay.io/podman/qemu-user-static --reset -p yes
NO_PUSH=1 scripts/build-bitcoin-image.sh core 28.4 aarch64
```
## Part 2 — Pi setup
Flash **Raspberry Pi OS Lite (64-bit)** — it's Debian 13 trixie, same base as
the fleet images — headless with SSH enabled. For NVMe boot set
`BOOT_ORDER` in the bootloader EEPROM (`rpiboot`/`rpi-eeprom-config`) and, if
needed, `dtparam=pciex1` in `/boot/firmware/config.txt`.
Then:
```bash
# rootless podman
sudo apt update && sudo apt install -y podman uidmap
image-recipe/scripts/install-podman.sh
# service user — uid 1000 must match XDG_RUNTIME_DIR=/run/user/1000 in the unit
sudo useradd -m -u 1000 -s /bin/bash archipelago
sudo usermod --add-subuids 100000-165535 --add-subgids 100000-165535 archipelago
# backend
sudo install -m755 archipelago-aarch64 /usr/local/bin/archipelago
sudo cp archipelago.service /etc/systemd/system/archipelago.service
# The unit's ExecStartPre lines use -/+ prefixes, so missing helpers
# (ota-crash-guard.sh etc.) are tolerated; trim them if they aren't.
sudo systemctl daemon-reload && sudo systemctl enable --now archipelago
# Gaps found by the arm64 systemd-container test (2026-10-11) — the unit and
# nginx config need these or they fail to start:
sudo groupadd -f debian-tor && sudo groupadd -f fips
sudo usermod -aG dialout,debian-tor,fips archipelago
sudo mkdir -p /home/archipelago/.local/share/containers /home/archipelago/.config/containers \
/var/lib/containers /etc/containers /opt/archipelago/scripts /var/lib/archipelago
sudo chown -R archipelago:archipelago /home/archipelago /var/lib/archipelago
# nginx config includes snippets and a TLS cert (self-signed is fine for a test)
sudo cp -r image-recipe/configs/snippets /etc/nginx/
sudo mkdir -p /etc/archipelago/ssl && sudo openssl req -x509 -newkey rsa:2048 -nodes -days 30 \
-subj /CN=archy-test -keyout /etc/archipelago/ssl/archipelago.key -out /etc/archipelago/ssl/archipelago.crt
sudo cp /etc/archipelago/ssl/archipelago.crt /etc/archipelago/ssl/ca-download.crt
# frontend + nginx (serves static, proxies API to 127.0.0.1:5678)
sudo mkdir -p /opt/archipelago/web-ui && sudo rsync -a dist/ /opt/archipelago/web-ui/
sudo apt install -y nginx
sudo rm -f /etc/nginx/sites-enabled/default
sudo cp nginx-archipelago.conf /etc/nginx/conf.d/archipelago.conf
sudo systemctl reload nginx
# bitcoin image: load, then retag to the pinned manifest ref (see caveat below)
sudo -u archipelago podman load -i bitcoin-28.4-aarch64.tar
sudo -u archipelago podman tag \
source.archipelago-foundation.org/lfg2025/bitcoin:28.4-aarch64 \
source.archipelago-foundation.org/lfg2025/bitcoin:28.4
```
**Registry caveat:** manifests pin exact image refs and the orchestrator has
no arch field, so retagging the loaded image to the pinned ref satisfies the
install without a registry round-trip *only if* the installer doesn't
force-pull. If it does, either push the `-aarch64` image under the pinned
name to a registry you control, or run bitcoind manually for the test and
skip the UI install path.
For a quick sanity check independent of the app installer:
```bash
sudo -u archipelago podman run --rm \
source.archipelago-foundation.org/lfg2025/bitcoin:28.4 bitcoind --version
```
## Part 3 — Validation checklist
- [ ] `uname -m` → `aarch64`; backend up: `systemctl status archipelago`
- [ ] `curl -s http://127.0.0.1/health` (via nginx) responds
- [ ] The retagged 28.4 image runs natively (command above) — proves no
4K-page/alignment surprises (Pi is 4K, so this should be a non-issue —
it's the Asahi targets that need that audit)
- [ ] Dashboard reachable from the LAN at `http://<pi-ip>/`
- [ ] Bitcoin app installs from the UI and the container starts; for a cheap
test run signet or pruned rather than a full mainnet sync
- [ ] Memory headroom: bitcoind + backend RSS vs total RAM (Pi 5 4 GB is the
floor; note it for the eventual image spec)
## Known ARM gaps — expected failures, not test blockers
- **OTA has no architecture field** (`core/archipelago/src/update.rs`) — never
OTA a Pi test node; it would try to replace the backend with x86 binaries.
- **barkd** downloads a `linux-x86_64` binary in its Dockerfile — exclude it.
- **App catalog unaudited for arm64** — treat individual app install failures
as expected until audited (M2 doc, "ARM64 application compatibility").
- **`-aarch64` tag suffix is a stopgap** — real fix is arch-aware image
selection + manifest lists; see the M2 doc's milestones.
- **kdump/rasdaemon** phase 1 is amd64-only by design
(`kdump-rasdaemon-design.md`).
## Where this goes next (if the test passes)
1. Arch-aware image selection in the orchestrator (replaces the tag suffix).
2. A real Pi image recipe modeled on the embassyOS reference dump — Pi
firmware boot (`config.txt`), no GRUB — replacing
`install-to-disk.sh`'s amd64 assumptions.
3. Catalog audit for arm64, starting with the pinned bitcoin stack.
+19 -98
View File
@@ -1,18 +1,5 @@
#!/bin/bash
# Build Archipelago backend binary for Debian Linux
#
# Target architecture:
# (unset) native host build — unchanged default behavior
# ARCH=aarch64 build for ARM64 (Pi 5 test installs — see
# docs/raspberry-pi-test-install.md). On the M2 — our
# dedicated ARM64 build machine — this runs at native speed
# (Apple Silicon runs arm64 Linux containers natively).
# On x86_64 it prefers cargo-zigbuild (fast host cross
# build) or falls back to an emulated rust:trixie Docker
# build (needs qemu binfmt, slow).
#
# The backend is rustls-only (no OpenSSL dependency), so cross-building needs
# just a rustup target + the zig linker — no sysroot libraries.
set -e
@@ -21,39 +8,9 @@ PROJECT_ROOT="$(cd "$SCRIPT_DIR/../.." && pwd)"
BACKEND_DIR="$PROJECT_ROOT/core/archipelago"
OUTPUT_DIR="$SCRIPT_DIR/../build/backend"
# Resolve target architecture / cross-compile triple.
ARCH="${ARCH:-native}"
# Normalize uname -m into our arch vocabulary (macOS reports arm64; the M2
# builder is an arm64 host even though it produces Linux binaries via Docker).
case "$(uname -m)" in
x86_64|amd64) HOST_ARCH="x86_64" ;;
aarch64|arm64) HOST_ARCH="aarch64" ;;
*) HOST_ARCH="$(uname -m)" ;;
esac
CROSS_TARGET=""
case "$ARCH" in
native) ;;
aarch64|x86_64)
if [[ "$ARCH" == "$HOST_ARCH" && "$OSTYPE" != "darwin"* ]]; then
# Linux host building for itself — plain native build
echo "ℹ️ ARCH=$ARCH matches host — building natively"
else
# Explicit target triple — on Apple Silicon (M2) the arm64
# container runs natively; only x86_64 hosts emulate.
CROSS_TARGET="${ARCH}-unknown-linux-gnu"
echo "🎯 Building for $ARCH ($CROSS_TARGET)"
fi
;;
*) echo "❌ ARCH must be 'native', 'aarch64' or 'x86_64' (got: $ARCH)" >&2; exit 1 ;;
esac
OUT_NAME="archipelago"
if [ -n "$CROSS_TARGET" ]; then
OUT_NAME="archipelago-${ARCH}"
fi
echo "🔨 Building Archipelago backend..."
echo " Source: $BACKEND_DIR"
echo " Output: $OUTPUT_DIR/$OUT_NAME"
echo " Output: $OUTPUT_DIR"
echo ""
# Create output directory
@@ -69,79 +26,43 @@ elif ! command -v rustc >/dev/null 2>&1; then
echo "⚠️ Rust not found - using Docker"
fi
# Cross-build without cargo-zigbuild (e.g. system rust without rustup targets)
# falls back to the emulated Docker path instead of hard-failing.
if [ "$USE_DOCKER" != true ] && [ -n "$CROSS_TARGET" ] \
&& ! command -v cargo-zigbuild >/dev/null 2>&1; then
echo "⚠️ cargo-zigbuild not found — using the emulated Docker build (slow)"
USE_DOCKER=true
fi
if [ "$USE_DOCKER" = true ]; then
echo "🐳 Building in Docker container..."
# Cross builds in Docker use --platform for an emulated target-arch rust
# toolchain (needs qemu binfmt; slow but zero host setup). An explicit
# --target keeps the shared target/ dir from colliding with host-arch
# builds.
PLATFORM_ARGS=""
INNER_BUILD="cargo build --release"
INNER_COPY="cp ../target/release/archipelago /output/${OUT_NAME}"
if [ -n "$CROSS_TARGET" ]; then
PLATFORM_ARGS="--platform linux/$([[ "$ARCH" == "aarch64" ]] && echo arm64 || echo amd64)"
INNER_BUILD="rustup target add ${CROSS_TARGET} && cargo build --release --target ${CROSS_TARGET}"
INNER_COPY="cp ../target/${CROSS_TARGET}/release/archipelago /output/${OUT_NAME}"
if [[ "$(uname -m)" == "arm64" && "$ARCH" == "aarch64" ]]; then
echo " (Apple Silicon — arm64 containers run natively here)"
else
echo " (emulated ${ARCH} build — expect it to be slow)"
fi
fi
# shellcheck disable=SC2086
docker run --rm \
-v "$PROJECT_ROOT:/workspace" \
-v "$OUTPUT_DIR:/output" \
-w /workspace/core/archipelago \
$PLATFORM_ARGS \
rust:trixie \
sh -c "
echo '📦 Installing build dependencies...'
sh -c '
echo "📦 Installing build dependencies..."
apt-get update && apt-get install -y pkg-config libssl-dev
echo '🔨 Building Archipelago backend...'
${INNER_BUILD}
echo '📋 Copying binary to output...'
${INNER_COPY}
echo '✅ Build complete!'
ls -lh /output/
"
elif [ -n "$CROSS_TARGET" ]; then
# Host-side cross build: cargo-zigbuild (zig as linker) — much faster than
# the emulated Docker path. On Arch: pacman -S cargo-zigbuild (pulls zig).
echo "🐧 Cross-compiling on host with cargo-zigbuild..."
rustup target add "$CROSS_TARGET"
cd "$BACKEND_DIR"
cargo zigbuild --release --target "$CROSS_TARGET"
cp "../target/${CROSS_TARGET}/release/archipelago" "$OUTPUT_DIR/$OUT_NAME"
echo "🔨 Building Archipelago backend..."
cargo build --release
echo "📋 Copying binary to output..."
cp ../target/release/archipelago /output/
echo "✅ Build complete!"
ls -lh /output/archipelago
'
else
# Native Linux build
echo "🐧 Building natively..."
cd "$BACKEND_DIR"
cargo build --release
cp "../target/release/archipelago" "$OUTPUT_DIR/archipelago"
fi
# Strip binary for smaller size (GNU strip handles foreign-arch ELF too).
if [ -f "$OUTPUT_DIR/$OUT_NAME" ]; then
# Strip binary for smaller size
if [ -f "$OUTPUT_DIR/archipelago" ]; then
if command -v strip >/dev/null 2>&1 && [[ "$OSTYPE" != "darwin"* ]]; then
strip "$OUTPUT_DIR/$OUT_NAME"
strip "$OUTPUT_DIR/archipelago"
fi
echo ""
echo "✅ Backend built: $OUTPUT_DIR/$OUT_NAME"
ls -lh "$OUTPUT_DIR/$OUT_NAME"
echo "✅ Backend built: $OUTPUT_DIR/archipelago"
ls -lh "$OUTPUT_DIR/archipelago"
else
echo "❌ Build failed - binary not found"
exit 1
@@ -370,6 +370,7 @@ init()
</div>
<div class="space-y-3 text-sm text-white/80 pl-3 border-l border-white/10">
<p>Ship the Archipelago companion 0.5.37 (build 57) APK so the downloadable app matches the Android source version and its local playback diagnostics.</p>
<p>Build the installer ISO with a release gate that checks the bundled companion APK version against the Android source version.</p>
<p>Carries all v1.9.1-alpha changes and known limitations unchanged; v1.9.1-alpha shipped the 0.5.36 companion APK and has no installer ISO.</p>
</div>
</div>
+9 -63
View File
@@ -11,47 +11,19 @@
# Usage:
# scripts/build-bitcoin-image.sh core 31.0
# scripts/build-bitcoin-image.sh knots 29.3.knots20260508
# scripts/build-bitcoin-image.sh core 31.0 aarch64 # ARM64 (Pi 5) images
# NO_PUSH=1 scripts/build-bitcoin-image.sh core 31.0 # build + verify only
# NO_PUSH=1 scripts/build-bitcoin-image.sh core 31.0 # build + verify only
#
# Env:
# NO_PUSH=1 build + verify, do not push
# ALLOW_UNSIGNED=1 skip the GPG signature check (NOT for production)
# REQUIRE_PINNED=1 additionally require a signature from a pinned release key
# ARCHY_REGISTRY overrides the push registry (default from image-versions.sh)
# ARCHY_ARCH x86_64 (default) or aarch64; 3rd positional arg also works.
# aarch64 tags as :<version>-aarch64 — the orchestrator has
# no arch field yet (docs/raspberry-pi-test-install.md)
set -euo pipefail
IMPL="${1:?usage: build-bitcoin-image.sh <core|knots> <version> [x86_64|aarch64]}"
VERSION="${2:?usage: build-bitcoin-image.sh <core|knots> <version> [x86_64|aarch64]}"
ARCH="${3:-${ARCHY_ARCH:-x86_64}}"
case "$ARCH" in
x86_64|aarch64) ;;
*) echo "arch must be 'x86_64' or 'aarch64' (got: $ARCH)" >&2; exit 2 ;;
esac
# Core publishes aarch64-linux-gnu tarballs for every release; Knots for recent
# ones. A missing platform fails closed at the SHA256SUMS grep below.
# Normalize uname -m into our arch vocabulary: an Apple Silicon host (arm64)
# is a NATIVE arm64 build host, not a cross one.
case "$(uname -m)" in
x86_64|amd64) HOST_ARCH="x86_64" ;;
aarch64|arm64) HOST_ARCH="aarch64" ;;
*) HOST_ARCH="$(uname -m)" ;;
esac
if [[ "$ARCH" != "$HOST_ARCH" ]]; then
echo "==> cross-build: target $ARCH on $HOST_ARCH"
echo " podman RUN steps run under qemu; register binfmt handlers once:"
echo " podman run --privileged quay.io/podman/qemu-user-static --reset -p yes"
fi
IMPL="${1:?usage: build-bitcoin-image.sh <core|knots> <version>}"
VERSION="${2:?usage: build-bitcoin-image.sh <core|knots> <version>}"
ROOT="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)"
# Container runtime: podman is canonical; docker is a fallback for test builds
# on hosts without podman. Push still prefers podman (tls-verify flag differs).
CTR="$(command -v podman || command -v docker)" \
|| { echo "FATAL: need podman or docker" >&2; exit 1; }
# shellcheck disable=SC1091
source "$ROOT/scripts/image-versions.sh"
REGISTRY="${ARCHY_REGISTRY:?ARCHY_REGISTRY unset}"
@@ -76,14 +48,14 @@ KNOTS_SIGNERS=(
case "$IMPL" in
core)
TARBALL="bitcoin-${VERSION}-${ARCH}-linux-gnu.tar.gz"
TARBALL="bitcoin-${VERSION}-x86_64-linux-gnu.tar.gz"
BASEURL="https://bitcoincore.org/bin/bitcoin-core-${VERSION}"
IMAGE_REPO="bitcoin"
SIGNERS=("${CORE_SIGNERS[@]}")
;;
knots)
MAJOR="${VERSION%%.*}"
TARBALL="bitcoin-${VERSION}-${ARCH}-linux-gnu.tar.gz"
TARBALL="bitcoin-${VERSION}-x86_64-linux-gnu.tar.gz"
BASEURL="https://bitcoinknots.org/files/${MAJOR}.x/${VERSION}"
IMAGE_REPO="bitcoin-knots"
SIGNERS=("${KNOTS_SIGNERS[@]}")
@@ -91,13 +63,7 @@ case "$IMPL" in
*) echo "impl must be 'core' or 'knots'" >&2; exit 2 ;;
esac
# Non-x86_64 builds carry an arch suffix so per-platform images coexist in the
# registry until the orchestrator learns arch-aware selection.
if [[ "$ARCH" == "x86_64" ]]; then
TAG="${REGISTRY}/${IMAGE_REPO}:${VERSION}"
else
TAG="${REGISTRY}/${IMAGE_REPO}:${VERSION}-${ARCH}"
fi
TAG="${REGISTRY}/${IMAGE_REPO}:${VERSION}"
WORK="$(mktemp -d)"
trap 'rm -rf "$WORK"' EXIT
cd "$WORK"
@@ -189,25 +155,10 @@ VOLUME ["/home/bitcoin/.bitcoin"]
EXPOSE 8332 8333
ENTRYPOINT ["bitcoind"]
EOF
# --platform keeps the base image (debian:bookworm-slim is multi-arch) and the
# resulting image arch correct for cross builds; no-op for native ones.
PLATFORM="$([[ "$ARCH" == "x86_64" ]] && echo amd64 || echo arm64)"
# -f is explicit because docker (unlike podman) doesn't auto-detect Containerfile.
"$CTR" build --platform "linux/${PLATFORM}" -f ctx/Containerfile -t "$TAG" ctx
podman build -t "$TAG" ctx
echo "==> smoke test (bitcoind --version)"
if [[ "$ARCH" != "$HOST_ARCH" ]]; then
# Emulated run: works when qemu binfmt is registered; otherwise non-fatal —
# SHA-256 + OpenPGP verification above is the fail-closed gate.
if "$CTR" run --rm --entrypoint bitcoind "$TAG" --version 2>/dev/null | head -1; then
:
else
echo " NOTE: emulated smoke test unavailable (no qemu binfmt handler?)"
echo " SHA-256 + GPG verification already passed; continuing."
fi
else
"$CTR" run --rm --entrypoint bitcoind "$TAG" --version | head -1
fi
podman run --rm --entrypoint bitcoind "$TAG" --version | head -1
if [[ "${NO_PUSH:-0}" == "1" ]]; then
echo "==> NO_PUSH=1 — built + verified $TAG (not pushed)"
@@ -215,11 +166,6 @@ else
echo "==> pushing $TAG"
# The lfg2025 registry serves plain HTTP (matches image_uses_insecure_registry
# in the Rust runtime). PODMAN_PUSH_TLS_VERIFY=true forces TLS for HTTPS regs.
if [[ "$(basename "$CTR")" == "podman" ]]; then
"$CTR" push --tls-verify="${PODMAN_PUSH_TLS_VERIFY:-false}" "$TAG"
else
echo " (docker fallback — daemon insecure-registry config governs TLS)"
"$CTR" push "$TAG"
fi
podman push --tls-verify="${PODMAN_PUSH_TLS_VERIFY:-false}" "$TAG"
echo "==> pushed $TAG"
fi