Ryan Malloy 3b505644b2 Kernel release 6.18.38-rt-cuckoo+: reproducible build, guarded installer
Rebuilt with KBUILD_BUILD_USER/HOST/TIMESTAMP pinned. Without them the kernel
bakes the builder's user@hostname and wall-clock build time into /proc/version,
which publishes operator identity in a public artifact and makes the build
unreproducible. Pinned, anyone can rebuild and diff the bytes — the only trust
story available for an unsigned community kernel.

The installer refuses to run on anything but a Pi 4, refuses a mismatched
image/modules pair (vermagic failure means no /dev/pps0 on a kernel that
otherwise boots fine — silent and miserable to debug), verifies SHA256SUMS,
never touches kernel8.img, and leaves rollback as deleting one config.txt line.

Boot-tested on the Pi: Stratum 1, 273 ns offset, PPS handler confirmed NOT
threaded. Binaries ship as release assets, not in git.
2026-07-14 09:52:17 -06:00

60 lines
2.1 KiB
Makefile

# cuckoo-escapement docs — make targets follow the warehacking cookie-cutter.
#
# `make prod` builds the static site + brings up Caddy serving it.
# `make dev` starts the Astro dev server with HMR behind Caddy.
# `make down` stops both.
SHELL := /usr/bin/env bash
.SHELLFLAGS := -eu -o pipefail -c
.DEFAULT_GOAL := help
.PHONY: help
help: ## Show this help
@awk 'BEGIN {FS = ":.*##"} /^[a-zA-Z0-9_-]+:.*##/ {printf " \033[36m%-12s\033[0m %s\n", $$1, $$2}' $(MAKEFILE_LIST)
.PHONY: prod
prod: ## Build + run the production docs container (Caddy serves dist/)
docker compose up -d --build docs
.PHONY: dev
dev: ## Run the Astro dev server with HMR (--profile dev)
docker compose --profile dev up --build docs-dev
.PHONY: down
down: ## Stop and remove the docs containers
docker compose --profile dev down
docker compose down
.PHONY: logs
logs: ## Tail logs (works for whichever profile is up)
docker compose logs -f --tail=100
.PHONY: build
build: ## Build the static site WITHOUT bringing up Caddy (CI gate)
docker compose build docs
.PHONY: shell
shell: ## Open a shell in the running dev container (debugging)
docker compose exec docs-dev sh
# ---- Production deploy --------------------------------------------------
#
# `make deploy` pulls origin/main on the warehack.ing prod host and rebuilds
# the docs container. Agent-forwarding (`-A`) lets the remote `git pull` use
# the operator's local SSH key for Gitea — nothing persistent is provisioned
# on the deploy host.
#
# Override DEPLOY_HOST / DEPLOY_PATH for a different deployment without
# editing this file. The defaults are the warehack.ing cookie-cutter shape
# (see ~/.claude/references/warehacking.md).
DEPLOY_HOST ?= warehack-ing@warehack.ing
DEPLOY_PATH ?= ~/cuckoo-escapement
.PHONY: deploy
deploy: ## Pull main + rebuild the docs container on the prod host
@echo "==> deploying $(DEPLOY_HOST):$(DEPLOY_PATH)"
ssh -A $(DEPLOY_HOST) "cd $(DEPLOY_PATH) && git fetch origin main && git reset --hard origin/main && cd docs-site && make prod"
@echo "==> sanity check"
@curl -s -o /dev/null -w " HTTP %{http_code} %{url_effective}\n" "https://cuckoo.warehack.ing/explanation/preempt-rt-made-it-worse/"