Skip to content

Commit 1ce9f45

Browse files
Merge pull request #594 from ExtremeFiretop/TLCFeedback
Implement TLC Feedback and Razor Feedback
2 parents d24814b + 54b3696 commit 1ce9f45

8 files changed

Lines changed: 889 additions & 71 deletions

File tree

Lines changed: 121 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,121 @@
1+
name: Update Merlin SHA256 Checksums
2+
3+
on:
4+
schedule:
5+
# Every 15 minutes, offset from the top of the hour to reduce scheduler congestion.
6+
- cron: '7,22,37,52 * * * *'
7+
workflow_dispatch:
8+
9+
permissions:
10+
contents: write
11+
12+
concurrency:
13+
group: update-merlin-sha256
14+
cancel-in-progress: false
15+
16+
jobs:
17+
scrape-and-commit:
18+
runs-on: ubuntu-latest
19+
timeout-minutes: 5
20+
21+
steps:
22+
- name: Checkout repository
23+
uses: actions/checkout@v7
24+
with:
25+
ssh-key: ${{ secrets.DEPLOY_KEY }}
26+
27+
- name: Fetch, parse, and validate SHA256 signatures
28+
shell: bash
29+
run: |
30+
set -euo pipefail
31+
32+
readonly SOURCE_URL='https://www.asuswrt-merlin.net/download'
33+
readonly TARGET_FILE='merlin-sha256.txt'
34+
readonly MIN_EXPECTED_ENTRIES=5
35+
36+
page_file="$(mktemp)"
37+
candidate_file="$(mktemp)"
38+
trap 'rm -f "$page_file" "$candidate_file"' EXIT
39+
40+
echo "Fetching SHA256 signatures from ${SOURCE_URL}..."
41+
curl --fail --location --silent --show-error \
42+
--retry 4 --retry-delay 5 --retry-connrefused \
43+
--connect-timeout 15 --max-time 60 \
44+
--user-agent 'MerlinAutoUpdate checksum mirror (+https://github.com/ExtremeFiretop/MerlinAutoUpdate-Router)' \
45+
--output "$page_file" \
46+
"$SOURCE_URL"
47+
48+
# Keep the same source section MerlinAU consumes today, but write to a
49+
# temporary candidate so a scrape/parser failure cannot destroy the
50+
# last-known-good mirror in the repository.
51+
sed -n '/<.*>SHA256 signatures:<\/.*>/,/<\/pre>/p' "$page_file" | \
52+
sed -n '/<pre[^>]*>/,/<\/pre>/p' | \
53+
sed -e 's/^.*<pre[^>]*>//' \
54+
-e 's/<[^>]*>//g' \
55+
-e 's/^[[:space:]]*//' \
56+
-e 's/[[:space:]]*$//' | \
57+
tr -d '\r' | \
58+
sed '/^[[:space:]]*$/d' > "$candidate_file"
59+
60+
echo "Validating candidate checksum list..."
61+
awk -v min_entries="$MIN_EXPECTED_ENTRIES" '
62+
BEGIN {
63+
valid = 1
64+
count = 0
65+
}
66+
{
67+
count++
68+
69+
if (NF != 2) {
70+
printf "Invalid field count on line %d: %s\n", NR, $0 > "/dev/stderr"
71+
valid = 0
72+
next
73+
}
74+
75+
if (length($1) != 64 || $1 ~ /[^0-9A-Fa-f]/) {
76+
printf "Invalid SHA256 on line %d: %s\n", NR, $1 > "/dev/stderr"
77+
valid = 0
78+
}
79+
80+
if (seen[$2]++) {
81+
printf "Duplicate firmware filename on line %d: %s\n", NR, $2 > "/dev/stderr"
82+
valid = 0
83+
}
84+
}
85+
END {
86+
if (count < min_entries) {
87+
printf "Only %d checksum entries were parsed; expected at least %d.\n", count, min_entries > "/dev/stderr"
88+
valid = 0
89+
}
90+
91+
if (!valid)
92+
exit 1
93+
}
94+
' "$candidate_file"
95+
96+
echo "Validated $(wc -l < "$candidate_file") checksum entries."
97+
echo "Candidate preview:"
98+
head -n 5 "$candidate_file"
99+
100+
# Replace the working-tree copy only after the candidate has passed
101+
# every validation check. A failed run therefore leaves the repository
102+
# and its last-known-good checksum mirror unchanged.
103+
mv -f "$candidate_file" "$TARGET_FILE"
104+
105+
- name: Commit and push changes
106+
shell: bash
107+
run: |
108+
set -euo pipefail
109+
110+
git config user.name 'github-actions[bot]'
111+
git config user.email '41898282+github-actions[bot]@users.noreply.github.com'
112+
113+
git add merlin-sha256.txt
114+
115+
if git diff --cached --quiet; then
116+
echo 'No checksum changes detected. Nothing to commit.'
117+
exit 0
118+
fi
119+
120+
git commit -m 'Automated update: refresh Merlin SHA256 checksums'
121+
git push

‎ADDITIONAL_TERMS.md‎

Lines changed: 178 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,178 @@
1+
# MerlinAU Additional Terms Under GNU GPLv3 Section 7
2+
3+
Effective date: [YYYY-MM-DD]
4+
5+
The MerlinAU software is licensed under the GNU General Public License
6+
version 3.0 ("GPLv3").
7+
8+
This document contains additional terms authorized under Section 7 of
9+
GPLv3 for MerlinAU material whose copyright holders have authorized
10+
these terms.
11+
12+
These Additional Terms supplement, and do not replace, GPLv3.
13+
14+
Nothing in these Additional Terms is intended to restrict the rights to
15+
run, study, copy, modify, or redistribute the software that are granted
16+
under GPLv3.
17+
18+
## 1. Scope
19+
20+
These Additional Terms apply to MerlinAU material for which the
21+
applicable copyright holder or copyright holders have authorized their
22+
application.
23+
24+
They do not purport to impose additional terms on third-party material
25+
for which the MerlinAU project does not have authority to impose such
26+
terms.
27+
28+
Contributions accepted after the effective date of these Additional
29+
Terms may be distributed subject to these Additional Terms where the
30+
contributor has agreed to them.
31+
32+
## 2. Preservation of Attribution and Legal Notices
33+
34+
Pursuant to Section 7(b) of GPLv3, reasonable legal notices and author
35+
attributions contained in covered MerlinAU material must be preserved.
36+
37+
This includes, where applicable, notices identifying:
38+
39+
- ExtremeFiretop as the original creator of the MerlinAU project;
40+
- Martinski W. as an official co-author of the MerlinAU project;
41+
- the applicable copyright notices;
42+
- the GNU General Public License version 3.0;
43+
- these Additional Terms; and
44+
- the official MerlinAU project source.
45+
46+
The official MerlinAU project is:
47+
48+
https://github.com/ExtremeFiretop/MerlinAutoUpdate-Router
49+
50+
These requirements do not prevent a modified version from adding
51+
appropriate attribution for its own authors and contributors.
52+
53+
## 3. Identification of Modified Versions
54+
55+
Pursuant to Section 7(c) of GPLv3, a version of covered MerlinAU
56+
material that has been modified and conveyed to others must be
57+
reasonably identified as different from the official MerlinAU version
58+
from which it was derived.
59+
60+
A modified version must not misrepresent its origin or represent itself
61+
as an unmodified official MerlinAU release.
62+
63+
Where reasonably visible to users, the modified version must identify
64+
that:
65+
66+
1. it contains modifications to MerlinAU;
67+
2. it is not an official MerlinAU release unless expressly authorized
68+
as such by the MerlinAU project; and
69+
3. the modifications were made by persons other than the maintainers of
70+
the official MerlinAU release, where applicable.
71+
72+
This requirement supplements the modified-version notice requirements
73+
already contained in Section 5 of GPLv3.
74+
75+
Nothing in this section prevents a derivative project from truthfully
76+
describing itself as being based on, derived from, or forked from
77+
MerlinAU.
78+
79+
## 4. No Misrepresentation of Origin
80+
81+
Pursuant to Section 7(c) of GPLv3, covered MerlinAU material may not be
82+
conveyed in a manner that misrepresents the origin of that material.
83+
84+
A person distributing a modified version must not falsely state or
85+
imply that the modifications:
86+
87+
- were created by the official MerlinAU project;
88+
- were created by ExtremeFiretop;
89+
- were created by Martinski W.;
90+
- are maintained by the official MerlinAU project; or
91+
- constitute an official MerlinAU release,
92+
93+
unless such a statement is factually correct or the distributor has
94+
received authorization to make it.
95+
96+
## 5. Names of Authors and Maintainers
97+
98+
Pursuant to Section 7(d) of GPLv3, the names, usernames, or identities
99+
of MerlinAU authors, contributors, or licensors may not be used for
100+
publicity or promotional purposes in a manner that falsely implies
101+
their sponsorship, endorsement, or approval of a modified or derivative
102+
version.
103+
104+
This provision does not prohibit reasonable attribution or truthful
105+
statements describing the origin or history of the software.
106+
107+
## 6. Trademark Rights Are Not Granted
108+
109+
Pursuant to Section 7(e) of GPLv3, no rights under trademark law are
110+
granted by the GPLv3 license or by these Additional Terms for the use
111+
of the following project marks:
112+
113+
- MerlinAU™
114+
- MerlinAutoUpdate™
115+
- the official MerlinAU logo or logos
116+
- other distinctive MerlinAU project branding
117+
118+
Rights to copy, modify, and redistribute the underlying GPL-licensed
119+
software are separate from rights that may exist in project names,
120+
logos, and other trademarks.
121+
122+
Refer to `TRADEMARKS.md` for the MerlinAU trademark-use policy.
123+
124+
Nothing in this section is intended to prohibit uses of a mark that are
125+
independently permitted by applicable trademark law, including
126+
truthful use reasonably necessary to identify the origin of a
127+
derivative work.
128+
129+
## 7. Official Project
130+
131+
For purposes of these Additional Terms, the official MerlinAU project
132+
is the project maintained at:
133+
134+
https://github.com/ExtremeFiretop/MerlinAutoUpdate-Router
135+
136+
A fork, clone, mirror, modified distribution, or derivative work does
137+
not become an official MerlinAU release merely because it originates
138+
from the official repository.
139+
140+
Official status requires authorization from the person or persons
141+
authorized to control the official MerlinAU project and its branding.
142+
143+
## 8. Relationship to GPLv3
144+
145+
These Additional Terms are intended to fall only within the categories
146+
permitted by Section 7 of GPLv3.
147+
148+
They do not prohibit:
149+
150+
- creating a fork;
151+
- privately modifying MerlinAU;
152+
- publicly distributing a modified version;
153+
- changing MerlinAU functionality;
154+
- removing or replacing MerlinAU functionality; or
155+
- creating an independently maintained derivative,
156+
157+
provided the applicable requirements of GPLv3 and valid Additional
158+
Terms are followed.
159+
160+
If any provision of this document would constitute a "further
161+
restriction" prohibited by GPLv3 rather than a valid Section 7
162+
additional term, that provision is not intended to restrict rights
163+
otherwise granted by GPLv3.
164+
165+
## 9. Applicable Version
166+
167+
These Additional Terms apply only to MerlinAU material released with a
168+
notice stating that these Additional Terms apply.
169+
170+
Earlier copies of MerlinAU received without these Additional Terms
171+
remain governed by the licensing terms applicable to those copies.
172+
173+
---
174+
175+
MerlinAU™ / MerlinAutoUpdate™
176+
177+
Official project:
178+
https://github.com/ExtremeFiretop/MerlinAutoUpdate-Router

0 commit comments

Comments
 (0)