From 1cdc5dd8ab2e86cd6679bea879f5478308fd203c Mon Sep 17 00:00:00 2001 From: igneum-labs <337424239+igneum-labs@users.noreply.github.com> Date: Wed, 7 Oct 2026 21:49:03 +0000 Subject: [PATCH] publish-public.sh: the public manifest leaves the signed interface entry out (the apps read it from the token manifest; the --public arm had refused every publish since interface 1.0.1 because the entry carried the token) Co-Authored-By: Claude Fable 5.1 --- packaging/ota/publish-public.sh | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/packaging/ota/publish-public.sh b/packaging/ota/publish-public.sh index 04892852a..55ffb3bcf 100755 --- a/packaging/ota/publish-public.sh +++ b/packaging/ota/publish-public.sh @@ -94,6 +94,10 @@ src, out, base = sys.argv[1:4] m = json.load(open(src)) for e in m.get("platforms", {}).values(): e["url"] = base + "/" + e["url"].rsplit("/", 1)[1] +# the interface entry is signed over its own URL in the token folder and the apps read it from the token manifest, +# never from here; the public copy is the site's download index, so the entry is left out (7 October 2026: the +# --public arm had refused every publish since interface 1.0.1 because the entry carried the token) +m.pop("ui", None) open(out, "w").write(json.dumps(m, sort_keys=True, separators=(",", ":"), ensure_ascii=False)) PY if grep -q "$TOKEN" "$tmp"; then rm -f "$tmp"; log "ERROR: the public $name would still carry the token" >&2; return 1; fi