scan_repo_files() in fdroidserver picks up any .json file under repo/ whose name isn't in its ignore list. Our renamed index-v2-<hash>.json from the prior rehash run isn't in that list, so the next fdroid update indexed it as an installable "package" with packageName == its sha256. cleanup_stale_indexes in rehash.py already does the right thing — it just ran too late, after the bogus entry was already in the new index. Move the same sweep into the entrypoint, before fdroid update runs, so scan_repo_files() sees a clean directory. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
fdroidserver-ipfs
Downstream of registry.gitlab.com/fdroid/docker-executable-fdroidserver:master,
patched for publishing F-Droid repos over IPFS. See SPEC.md for the why.
Usage
Drop-in replacement for the upstream image. Run fdroid update exactly as
before — the image's entrypoint chains fdroidserver-ipfs-rehash after any
successful update, so you never have to remember the second step:
docker run --rm -v "$PWD:/repo" your-image-tag update
# ↑ runs `fdroid update`, then automatically renames index, adds ipfsCIDv1,
# re-signs entry.jar (and regenerates entry.json.asc if GPG was in the loop).
Every other subcommand (build, publish, gpgsign, …) passes straight
through to fdroid unchanged.
Running the rehash standalone
If you want to invoke the rehash directly (e.g. on an already-published repo):
docker run --rm -v "$PWD:/repo" \
--entrypoint fdroidserver-ipfs-rehash \
your-image-tag
fdroidserver-ipfs-rehash discovers repo/ (and archive/ if configured)
from config.yml. If GPG signing was already part of your pipeline (i.e.
entry.json.asc exists), it invokes fdroid gpgsign itself to regenerate
the invalidated signatures. Pass repodirs explicitly to override discovery:
fdroidserver-ipfs-rehash repo archive