##// END OF EJS Templates
Fixed: Remove SSH_*_AUTHORIZED_KEYS, works with SSH_*_PUB_KEY only
drtyhlpr -
r126:1dfbb1fcf201
parent child
Show More
@@ -1,392 +1,386
1 1 # rpi23-gen-image
2 2 ## Introduction
3 3 `rpi23-gen-image.sh` is an advanced Debian Linux bootstrapping shell script for generating Debian OS images for Raspberry Pi 2 (RPi2) and Raspberry Pi 3 (RPi3) computers. The script at this time supports the bootstrapping of the Debian (armhf) releases `jessie` and `stretch`. Raspberry Pi 3 images are currently generated for 32-bit mode only.
4 4
5 5 ## Build dependencies
6 6 The following list of Debian packages must be installed on the build system because they are essentially required for the bootstrapping process. The script will check if all required packages are installed and missing packages will be installed automatically if confirmed by the user.
7 7
8 8 ```debootstrap debian-archive-keyring qemu-user-static binfmt-support dosfstools rsync bmap-tools whois git bc psmisc```
9 9
10 10 It is recommended to configure the `rpi23-gen-image.sh` script to build and install the latest Raspberry Pi Linux kernel. For the RPi3 this is mandetory. Kernel compilation and linking will be performed on the build system using an ARM (armhf) cross-compiler toolchain.
11 11
12 12 The script has been tested using the default `crossbuild-essential-armhf` toolchain meta package on Debian Linux `jessie` and `stretch` build systems. Please check the [Debian CrossToolchains Wiki](https://wiki.debian.org/CrossToolchains) for further information.
13 13
14 14 If a Debian Linux `jessie` build system is used it will be required to add the [Debian Cross-toolchains repository](http://emdebian.org/tools/debian/) first:
15 15
16 16 ```
17 17 echo "deb http://emdebian.org/tools/debian/ jessie main" > /etc/apt/sources.list.d/crosstools.list
18 18 sudo -u nobody wget -O - http://emdebian.org/tools/debian/emdebian-toolchain-archive.key | apt-key add -
19 19 dpkg --add-architecture armhf
20 20 apt-get update
21 21 ```
22 22
23 23 ## Command-line parameters
24 24 The script accepts certain command-line parameters to enable or disable specific OS features, services and configuration settings. These parameters are passed to the `rpi23-gen-image.sh` script via (simple) shell-variables. Unlike environment shell-variables (simple) shell-variables are defined at the beginning of the command-line call of the `rpi23-gen-image.sh` script.
25 25
26 26 #####Command-line examples:
27 27 ```shell
28 28 ENABLE_UBOOT=true ./rpi23-gen-image.sh
29 29 ENABLE_CONSOLE=false ENABLE_IPV6=false ./rpi23-gen-image.sh
30 30 ENABLE_WM=xfce4 ENABLE_FBTURBO=true ENABLE_MINBASE=true ./rpi23-gen-image.sh
31 31 ENABLE_HARDNET=true ENABLE_IPTABLES=true /rpi23-gen-image.sh
32 32 APT_SERVER=ftp.de.debian.org APT_PROXY="http://127.0.0.1:3142/" ./rpi23-gen-image.sh
33 33 ENABLE_MINBASE=true ./rpi23-gen-image.sh
34 34 BUILD_KERNEL=true ENABLE_MINBASE=true ENABLE_IPV6=false ./rpi23-gen-image.sh
35 35 BUILD_KERNEL=true KERNELSRC_DIR=/tmp/linux ./rpi23-gen-image.sh
36 36 ENABLE_MINBASE=true ENABLE_REDUCE=true ENABLE_MINGPU=true BUILD_KERNEL=true ./rpi23-gen-image.sh
37 37 ENABLE_CRYPTFS=true CRYPTFS_PASSWORD=changeme EXPANDROOT=false ENABLE_MINBASE=true ENABLE_REDUCE=true ENABLE_MINGPU=true BUILD_KERNEL=true ./rpi23-gen-image.sh
38 38 RELEASE=stretch BUILD_KERNEL=true ./rpi23-gen-image.sh
39 39 RPI_MODEL=3 ENABLE_WIRELESS=true ENABLE_MINBASE=true BUILD_KERNEL=true ./rpi23-gen-image.sh
40 40 RELEASE=stretch RPI_MODEL=3 ENABLE_WIRELESS=true ENABLE_MINBASE=true BUILD_KERNEL=true ./rpi23-gen-image.sh
41 41 ```
42 42
43 43 ## Configuration template files
44 44 To avoid long lists of command-line parameters and to help to store the favourite parameter configurations the `rpi23-gen-image.sh` script supports so called configuration template files (`CONFIG_TEMPLATE`=template). These are simple text files located in the `./templates` directory that contain the list of configuration parameters that will be used. New configuration template files can be added to the `./templates` directory.
45 45
46 46 #####Command-line examples:
47 47 ```shell
48 48 CONFIG_TEMPLATE=rpi3stretch ./rpi23-gen-image.sh
49 49 CONFIG_TEMPLATE=rpi2stretch ./rpi23-gen-image.sh
50 50 ```
51 51
52 52 ## Supported parameters and settings
53 53 #### APT settings:
54 54 ##### `APT_SERVER`="ftp.debian.org"
55 55 Set Debian packages server address. Choose a server from the list of Debian worldwide [mirror sites](https://www.debian.org/mirror/list). Using a nearby server will probably speed-up all required downloads within the bootstrapping process.
56 56
57 57 ##### `APT_PROXY`=""
58 58 Set Proxy server address. Using a local Proxy-Cache like `apt-cacher-ng` will speed-up the bootstrapping process because all required Debian packages will only be downloaded from the Debian mirror site once.
59 59
60 60 ##### `APT_INCLUDES`=""
61 61 A comma separated list of additional packages to be installed during bootstrapping.
62 62
63 63 #### General system settings:
64 64 ##### `RPI_MODEL`=2
65 65 Specifiy the target Raspberry Pi hardware model. The script at this time supports the Raspberry Pi models `2` and `3`. `BUILD_KERNEL`=true will automatically be set if the Raspberry Pi model `3` is used.
66 66
67 67 ##### `RELEASE`="jessie"
68 68 Set the desired Debian release name. The script at this time supports the bootstrapping of the Debian releases "jessie" and "stretch". `BUILD_KERNEL`=true will automatically be set if the Debian release `stretch` is used.
69 69
70 70 ##### `HOSTNAME`="rpi$RPI_MODEL-$RELEASE"
71 71 Set system host name. It's recommended that the host name is unique in the corresponding subnet.
72 72
73 73 ##### `PASSWORD`="raspberry"
74 74 Set system `root` password. It's **STRONGLY** recommended that you choose a custom password.
75 75
76 76 ##### `USER_PASSWORD`="raspberry"
77 77 Set password for the created non-root user `USER_NAME`=pi. Ignored if `ENABLE_USER`=false. It's **STRONGLY** recommended that you choose a custom password.
78 78
79 79 ##### `DEFLOCAL`="en_US.UTF-8"
80 80 Set default system locale. This setting can also be changed inside the running OS using the `dpkg-reconfigure locales` command. Please note that on using this parameter the script will automatically install the required packages `locales`, `keyboard-configuration` and `console-setup`.
81 81
82 82 ##### `TIMEZONE`="Europe/Berlin"
83 83 Set default system timezone. All available timezones can be found in the `/usr/share/zoneinfo/` directory. This setting can also be changed inside the running OS using the `dpkg-reconfigure tzdata` command.
84 84
85 85 ##### `EXPANDROOT`=true
86 86 Expand the root partition and filesystem automatically on first boot.
87 87
88 88 #### Keyboard settings:
89 89 These options are used to configure keyboard layout in `/etc/default/keyboard` for console and Xorg. These settings can also be changed inside the running OS using the `dpkg-reconfigure keyboard-configuration` command.
90 90
91 91 ##### `XKB_MODEL`=""
92 92 Set the name of the model of your keyboard type.
93 93
94 94 ##### `XKB_LAYOUT`=""
95 95 Set the supported keyboard layout(s).
96 96
97 97 ##### `XKB_VARIANT`=""
98 98 Set the supported variant(s) of the keyboard layout(s).
99 99
100 100 ##### `XKB_OPTIONS`=""
101 101 Set extra xkb configuration options.
102 102
103 103 #### Networking settings (DHCP):
104 104 This parameter is used to set up networking auto configuration in `/etc/systemd/network/eth.network`. The default location of network configuration files in the Debian `stretch` release was changed to `/lib/systemd/network`.`
105 105
106 106 #####`ENABLE_DHCP`=true
107 107 Set the system to use DHCP. This requires an DHCP server.
108 108
109 109 #### Networking settings (static):
110 110 These parameters are used to set up a static networking configuration in `/etc/systemd/network/eth.network`. The following static networking parameters are only supported if `ENABLE_DHCP` was set to `false`. The default location of network configuration files in the Debian `stretch` release was changed to `/lib/systemd/network`.
111 111
112 112 #####`NET_ADDRESS`=""
113 113 Set a static IPv4 or IPv6 address and its prefix, separated by "/", eg. "192.169.0.3/24".
114 114
115 115 #####`NET_GATEWAY`=""
116 116 Set the IP address for the default gateway.
117 117
118 118 #####`NET_DNS_1`=""
119 119 Set the IP address for the first DNS server.
120 120
121 121 #####`NET_DNS_2`=""
122 122 Set the IP address for the second DNS server.
123 123
124 124 #####`NET_DNS_DOMAINS`=""
125 125 Set the default DNS search domains to use for non fully qualified host names.
126 126
127 127 #####`NET_NTP_1`=""
128 128 Set the IP address for the first NTP server.
129 129
130 130 #####`NET_NTP_2`=""
131 131 Set the IP address for the second NTP server.
132 132
133 133 #### Basic system features:
134 134 ##### `ENABLE_CONSOLE`=true
135 135 Enable serial console interface. Recommended if no monitor or keyboard is connected to the RPi2/3. In case of problems fe. if the network (auto) configuration failed - the serial console can be used to access the system.
136 136
137 137 ##### `ENABLE_I2C`=false
138 138 Enable I2C interface on the RPi2/3. Please check the [RPi2/3 pinout diagrams](http://elinux.org/RPi_Low-level_peripherals) to connect the right GPIO pins.
139 139
140 140 ##### `ENABLE_SPI`=false
141 141 Enable SPI interface on the RPi2/3. Please check the [RPi2/3 pinout diagrams](http://elinux.org/RPi_Low-level_peripherals) to connect the right GPIO pins.
142 142
143 143 ##### `ENABLE_IPV6`=true
144 144 Enable IPv6 support. The network interface configuration is managed via systemd-networkd.
145 145
146 146 ##### `ENABLE_SSHD`=true
147 147 Install and enable OpenSSH service. The default configuration of the service doesn't allow `root` to login. Please use the user `pi` instead and `su -` or `sudo` to execute commands as root.
148 148
149 149 ##### `ENABLE_NONFREE`=false
150 150 Allow the installation of non-free Debian packages that do not comply with the DFSG. This is required to install closed-source firmware binary blobs.
151 151
152 152 ##### `ENABLE_WIRELESS`=false
153 153 Download and install the [closed-source firmware binary blob](https://github.com/RPi-Distro/firmware-nonfree/tree/master/brcm80211/brcm) that is required to run the internal wireless interface of the Raspberry Pi model `3`. This parameter is ignored if the specified `RPI_MODEL` is not `3`.
154 154
155 155 ##### `ENABLE_RSYSLOG`=true
156 156 If set to false, disable and uninstall rsyslog (so logs will be available only
157 157 in journal files)
158 158
159 159 ##### `ENABLE_SOUND`=true
160 160 Enable sound hardware and install Advanced Linux Sound Architecture.
161 161
162 162 ##### `ENABLE_HWRANDOM`=true
163 163 Enable Hardware Random Number Generator. Strong random numbers are important for most network based communications that use encryption. It's recommended to be enabled.
164 164
165 165 ##### `ENABLE_MINGPU`=false
166 166 Minimize the amount of shared memory reserved for the GPU. It doesn't seem to be possible to fully disable the GPU.
167 167
168 168 ##### `ENABLE_DBUS`=true
169 169 Install and enable D-Bus message bus. Please note that systemd should work without D-bus but it's recommended to be enabled.
170 170
171 171 ##### `ENABLE_XORG`=false
172 172 Install Xorg open-source X Window System.
173 173
174 174 ##### `ENABLE_WM`=""
175 175 Install a user defined window manager for the X Window System. To make sure all X related package dependencies are getting installed `ENABLE_XORG` will automatically get enabled if `ENABLE_WM` is used. The `rpi23-gen-image.sh` script has been tested with the following list of window managers: `blackbox`, `openbox`, `fluxbox`, `jwm`, `dwm`, `xfce4`, `awesome`.
176 176
177 177 #### Advanced system features:
178 178 ##### `ENABLE_MINBASE`=false
179 179 Use debootstrap script variant `minbase` which only includes essential packages and apt. This will reduce the disk usage by about 65 MB.
180 180
181 181 ##### `ENABLE_REDUCE`=false
182 182 Reduce the disk space usage by deleting packages and files. See `REDUCE_*` parameters for detailed information.
183 183
184 184 ##### `ENABLE_UBOOT`=false
185 185 Replace the default RPi2/3 second stage bootloader (bootcode.bin) with [U-Boot bootloader](http://git.denx.de/?p=u-boot.git;a=summary). U-Boot can boot images via the network using the BOOTP/TFTP protocol.
186 186
187 187 ##### `ENABLE_FBTURBO`=false
188 188 Install and enable the [hardware accelerated Xorg video driver](https://github.com/ssvb/xf86-video-fbturbo) `fbturbo`. Please note that this driver is currently limited to hardware accelerated window moving and scrolling.
189 189
190 190 ##### `ENABLE_IPTABLES`=false
191 191 Enable iptables IPv4/IPv6 firewall. Simplified ruleset: Allow all outgoing connections. Block all incoming connections except to OpenSSH service.
192 192
193 193 ##### `ENABLE_USER`=true
194 194 Create non-root user with password `USER_PASSWORD`=raspberry. Unless overridden with `USER_NAME`=user, username will be `pi`.
195 195
196 196 ##### `USER_NAME`=pi
197 197 Non-root user to create. Ignored if `ENABLE_USER`=false
198 198
199 199 ##### `ENABLE_ROOT`=false
200 200 Set root user password so root login will be enabled
201 201
202 202 ##### `ENABLE_HARDNET`=false
203 203 Enable IPv4/IPv6 network stack hardening settings.
204 204
205 205 ##### `ENABLE_SPLITFS`=false
206 206 Enable having root partition on an USB drive by creating two image files: one for the `/boot/firmware` mount point, and another for `/`.
207 207
208 208 ##### `CHROOT_SCRIPTS`=""
209 209 Path to a directory with scripts that should be run in the chroot before the image is finally built. Every executable file in this directory is run in lexicographical order.
210 210
211 211 ##### `ENABLE_INITRAMFS`=false
212 212 Create an initramfs that that will be loaded during the Linux startup process. `ENABLE_INITRAMFS` will automatically get enabled if `ENABLE_CRYPTFS`=true. This parameter will be ignored if `BUILD_KERNEL`=false.
213 213
214 214 ##### `ENABLE_IFNAMES`=true
215 215 Enable automatic assignment of predictable, stable network interface names for all local Ethernet, WLAN interfaces. This might create complex and long interface names. This parameter is only supported if the Debian release `stretch` is used.
216 216
217 217 #### SSH settings:
218 218 ##### `SSH_ENABLE_ROOT`=false
219 219 Enable password root login via SSH. This may be a security risk with default password, use only in trusted environments. `ENABLE_ROOT` must be set to `true`.
220 220
221 221 ##### `SSH_DISABLE_PASSWORD_AUTH`=false
222 222 Disable password based SSH authentication. Only public key based SSH (v2) authentication will be supported.
223 223
224 224 ##### `SSH_LIMIT_USERS`=false
225 225 Limit the users that are allowed to login via SSH. Only allow user `USER_NAME`=pi and root if `SSH_ENABLE_ROOT`=true to login.
226 226
227 ##### `SSH_ROOT_AUTHORIZED_KEYS`=""
228 Add specified SSH `authorized_keys` file that contains keys for public key based SSH (v2) authentication of user `root`. SSH protocol version 1 is not supported. `ENABLE_ROOT` **and** `SSH_ENABLE_ROOT` must be set to `true`.
229
230 227 ##### `SSH_ROOT_PUB_KEY`=""
231 Add specified SSH (v2) public key file to `authorized_keys` file to enable public key based SSH (v2) authentication of user `root`. SSH protocol version 1 is not supported. `ENABLE_ROOT` **and** `SSH_ENABLE_ROOT` must be set to `true`.
232
233 ##### `SSH_USER_AUTHORIZED_KEYS`=""
234 Add specified SSH `authorized_keys` file that contains keys for public key based SSH (v2) authentication of user `USER_NAME`=pi. SSH protocol version 1 is not supported.
228 Add specified SSH (v2) public key from file to `authorized_keys` file to enable public key based SSH (v2) authentication of user `root`. The specified file can also contain multiple SSH (v2) public keys. SSH protocol version 1 is not supported. `ENABLE_ROOT` **and** `SSH_ENABLE_ROOT` must be set to `true`.
235 229
236 230 ##### `SSH_USER_PUB_KEY`=""
237 Add specified SSH (v2) public key file to `authorized_keys` file to enable public key based SSH (v2) authentication of user `USER_NAME`=pi. SSH protocol version 1 is not supported.
231 Add specified SSH (v2) public key from file to `authorized_keys` file to enable public key based SSH (v2) authentication of user `USER_NAME`=pi. The specified file can also contain multiple SSH (v2) public keys. SSH protocol version 1 is not supported.
238 232
239 233 #### Kernel compilation:
240 234 ##### `BUILD_KERNEL`=false
241 235 Build and install the latest RPi2/3 Linux kernel. Currently only the default RPi2/3 kernel configuration is used. `BUILD_KERNEL`=true will automatically be set if the Raspberry Pi model `3` is used.
242 236
243 237 ##### `KERNEL_REDUCE`=false
244 238 Reduce the size of the generated kernel by removing unwanted device, network and filesystem drivers (experimental).
245 239
246 240 ##### `KERNEL_THREADS`=1
247 241 Number of parallel kernel building threads. If the parameter is left untouched the script will automatically determine the number of CPU cores to set the number of parallel threads to speed the kernel compilation.
248 242
249 243 ##### `KERNEL_HEADERS`=true
250 244 Install kernel headers with built kernel.
251 245
252 246 ##### `KERNEL_MENUCONFIG`=false
253 247 Start `make menuconfig` interactive menu-driven kernel configuration. The script will continue after `make menuconfig` was terminated.
254 248
255 249 ##### `KERNEL_REMOVESRC`=true
256 250 Remove all kernel sources from the generated OS image after it was built and installed.
257 251
258 252 ##### `KERNELSRC_DIR`=""
259 253 Path to a directory of [RaspberryPi Linux kernel sources](https://github.com/raspberrypi/linux) that will be copied, configured, build and installed inside the chroot.
260 254
261 255 ##### `KERNELSRC_CLEAN`=false
262 256 Clean the existing kernel sources directory `KERNELSRC_DIR` (using `make mrproper`) after it was copied to the chroot and before the compilation of the kernel has started. This parameter will be ignored if no `KERNELSRC_DIR` was specified or if `KERNELSRC_PREBUILT`=true.
263 257
264 258 ##### `KERNELSRC_CONFIG`=true
265 259 Run `make bcm2709_defconfig` (and optional `make menuconfig`) to configure the kernel sources before building. This parameter is automatically set to `true` if no existing kernel sources directory was specified using `KERNELSRC_DIR`. This parameter is ignored if `KERNELSRC_PREBUILT`=true.
266 260
267 261 ##### `KERNELSRC_USRCONFIG`=""
268 262 Copy own config file to kernel `.config`. If `KERNEL_MENUCONFIG`=true then running after copy.
269 263
270 264 ##### `KERNELSRC_PREBUILT`=false
271 265 With this parameter set to true the script expects the existing kernel sources directory to be already successfully cross-compiled. The parameters `KERNELSRC_CLEAN`, `KERNELSRC_CONFIG`, `KERNELSRC_USRCONFIG` and `KERNEL_MENUCONFIG` are ignored and no kernel compilation tasks are performed.
272 266
273 267 ##### `RPI_FIRMWARE_DIR`=""
274 268 The directory containing a local copy of the firmware from the [RaspberryPi firmware project](https://github.com/raspberrypi/firmware). Default is to download the latest firmware directly from the project.
275 269
276 270 #### Reduce disk usage:
277 271 The following list of parameters is ignored if `ENABLE_REDUCE`=false.
278 272
279 273 ##### `REDUCE_APT`=true
280 274 Configure APT to use compressed package repository lists and no package caching files.
281 275
282 276 ##### `REDUCE_DOC`=true
283 277 Remove all doc files (harsh). Configure APT to not include doc files on future `apt-get` package installations.
284 278
285 279 ##### `REDUCE_MAN`=true
286 280 Remove all man pages and info files (harsh). Configure APT to not include man pages on future `apt-get` package installations.
287 281
288 282 ##### `REDUCE_VIM`=false
289 283 Replace `vim-tiny` package by `levee` a tiny vim clone.
290 284
291 285 ##### `REDUCE_BASH`=false
292 286 Remove `bash` package and switch to `dash` shell (experimental).
293 287
294 288 ##### `REDUCE_HWDB`=true
295 289 Remove PCI related hwdb files (experimental).
296 290
297 291 ##### `REDUCE_SSHD`=true
298 292 Replace `openssh-server` with `dropbear`.
299 293
300 294 ##### `REDUCE_LOCALE`=true
301 295 Remove all `locale` translation files.
302 296
303 297 #### Encrypted root partition:
304 298
305 299 ##### `ENABLE_CRYPTFS`=false
306 300 Enable full system encryption with dm-crypt. Setup a fully LUKS encrypted root partition (aes-xts-plain64:sha512) and generate required initramfs. The /boot directory will not be encrypted. This parameter will be ignored if `BUILD_KERNEL`=false. `ENABLE_CRYPTFS` is experimental. SSH-to-initramfs is currently not supported but will be soon - feel free to help.
307 301
308 302 ##### `CRYPTFS_PASSWORD`=""
309 303 Set password of the encrypted root partition. This parameter is mandatory if `ENABLE_CRYPTFS`=true.
310 304
311 305 ##### `CRYPTFS_MAPPING`="secure"
312 306 Set name of dm-crypt managed device-mapper mapping.
313 307
314 308 ##### `CRYPTFS_CIPHER`="aes-xts-plain64:sha512"
315 309 Set cipher specification string. `aes-xts*` ciphers are strongly recommended.
316 310
317 311 ##### `CRYPTFS_XTSKEYSIZE`=512
318 312 Sets key size in bits. The argument has to be a multiple of 8.
319 313
320 314 ## Understanding the script
321 315 The functions of this script that are required for the different stages of the bootstrapping are split up into single files located inside the `bootstrap.d` directory. During the bootstrapping every script in this directory gets executed in lexicographical order:
322 316
323 317 | Script | Description |
324 318 | --- | --- |
325 319 | `10-bootstrap.sh` | Debootstrap basic system |
326 320 | `11-apt.sh` | Setup APT repositories |
327 321 | `12-locale.sh` | Setup Locales and keyboard settings |
328 322 | `13-kernel.sh` | Build and install RPi2/3 Kernel |
329 323 | `20-networking.sh` | Setup Networking |
330 324 | `21-firewall.sh` | Setup Firewall |
331 325 | `30-security.sh` | Setup Users and Security settings |
332 326 | `31-logging.sh` | Setup Logging |
333 327 | `32-sshd.sh` | Setup SSH and public keys |
334 328 | `41-uboot.sh` | Build and Setup U-Boot |
335 329 | `42-fbturbo.sh` | Build and Setup fbturbo Xorg driver |
336 330 | `50-firstboot.sh` | First boot actions |
337 331 | `99-reduce.sh` | Reduce the disk space usage |
338 332
339 333 All the required configuration files that will be copied to the generated OS image are located inside the `files` directory. It is not recommended to modify these configuration files manually.
340 334
341 335 | Directory | Description |
342 336 | --- | --- |
343 337 | `apt` | APT management configuration files |
344 338 | `boot` | Boot and RPi2/3 configuration files |
345 339 | `dpkg` | Package Manager configuration |
346 340 | `etc` | Configuration files and rc scripts |
347 341 | `firstboot` | Scripts that get executed on first boot |
348 342 | `initramfs` | Initramfs scripts |
349 343 | `iptables` | Firewall configuration files |
350 344 | `locales` | Locales configuration |
351 345 | `modules` | Kernel Modules configuration |
352 346 | `mount` | Fstab configuration |
353 347 | `network` | Networking configuration files |
354 348 | `sysctl.d` | Swapping and Network Hardening configuration |
355 349 | `xorg` | fbturbo Xorg driver configuration |
356 350
357 351 ## Custom packages and scripts
358 352 Debian custom packages, i.e. those not in the debian repositories, can be installed by placing them in the `packages` directory. They are installed immediately after packages from the repositories are installed. Any dependencies listed in the custom packages will be downloaded automatically from the repositories. Do not list these custom packages in `APT_INCLUDES`.
359 353
360 354 Scripts in the custom.d directory will be executed after all other installation is complete but before the image is created.
361 355
362 356 ## Logging of the bootstrapping process
363 357 All information related to the bootstrapping process and the commands executed by the `rpi23-gen-image.sh` script can easily be saved into a logfile. The common shell command `script` can be used for this purpose:
364 358
365 359 ```shell
366 360 script -c 'APT_SERVER=ftp.de.debian.org ./rpi23-gen-image.sh' ./build.log
367 361 ```
368 362
369 363 ## Flashing the image file
370 364 After the image file was successfully created by the `rpi23-gen-image.sh` script it can be copied to the microSD card that will be used by the RPi2/3 computer. This can be performed by using the tools `bmaptool` or `dd`. Using `bmaptool` will probably speed-up the copy process because `bmaptool` copies more wisely than `dd`.
371 365
372 366 #####Flashing examples:
373 367 ```shell
374 368 bmaptool copy ./images/jessie/2017-01-23-rpi3-jessie.img /dev/mmcblk0
375 369 dd bs=4M if=./images/jessie/2017-01-23-rpi3-jessie.img of=/dev/mmcblk0
376 370 ```
377 371 If you have set `ENABLE_SPLITFS`, copy the `-frmw` image on the microSD card, then the `-root` one on the USB drive:
378 372 ```shell
379 373 bmaptool copy ./images/jessie/2017-01-23-rpi3-jessie-frmw.img /dev/mmcblk0
380 374 bmaptool copy ./images/jessie/2017-01-23-rpi3-jessie-root.img /dev/sdc
381 375 ```
382 376
383 377 ## External links and references
384 378 * [Debian worldwide mirror sites](https://www.debian.org/mirror/list)
385 379 * [Debian Raspberry Pi 2 Wiki](https://wiki.debian.org/RaspberryPi2)
386 380 * [Debian CrossToolchains Wiki](https://wiki.debian.org/CrossToolchains)
387 381 * [Official Raspberry Pi Firmware on github](https://github.com/raspberrypi/firmware)
388 382 * [Official Raspberry Pi Kernel on github](https://github.com/raspberrypi/linux)
389 383 * [U-BOOT git repository](http://git.denx.de/?p=u-boot.git;a=summary)
390 384 * [Xorg DDX driver fbturbo](https://github.com/ssvb/xf86-video-fbturbo)
391 385 * [RPi3 Wireless interface firmware](https://github.com/RPi-Distro/firmware-nonfree/tree/master/brcm80211/brcm)
392 386 * [Collabora RPi2 Kernel precompiled](https://repositories.collabora.co.uk/debian/)
@@ -1,99 +1,87
1 1 #
2 2 # Setup SSH settings and public keys
3 3 #
4 4
5 5 # Load utility functions
6 6 . ./functions.sh
7 7
8 8 if [ "$ENABLE_SSHD" = true ] ; then
9 9 if [ "$SSH_ENABLE_ROOT" = false ] ; then
10 10 # User root is not allowed to log in
11 11 sed -i "s|[#]*PermitRootLogin.*|PermitRootLogin no|g" "${ETC_DIR}/ssh/sshd_config"
12 12 fi
13 13
14 14 if [ "$ENABLE_ROOT" = true ] && [ "$SSH_ENABLE_ROOT" = true ] ; then
15 15 # Permit SSH root login
16 16 sed -i "s|[#]*PermitRootLogin.*|PermitRootLogin yes|g" "${ETC_DIR}/ssh/sshd_config"
17 17
18 # Create root SSH config directory
19 mkdir -p "${R}/root/.ssh"
20
21 # Set permissions of root SSH config directory
22 chroot_exec chmod 700 "/root/.ssh"
23 chroot_exec chown root:root "/root/.ssh"
24
25 # Install SSH (v2) authorized keys file for user root
26 if [ ! -z "$SSH_ROOT_AUTHORIZED_KEYS" ] ; then
27 install_readonly "$SSH_ROOT_AUTHORIZED_KEYS" "${R}/root/.ssh/authorized_keys"
28 fi
29
30 18 # Add SSH (v2) public key for user root
31 19 if [ ! -z "$SSH_ROOT_PUB_KEY" ] ; then
20 # Create root SSH config directory
21 mkdir -p "${R}/root/.ssh"
22
23 # Set permissions of root SSH config directory
24 chroot_exec chmod 700 "/root/.ssh"
25 chroot_exec chown root:root "/root/.ssh"
26
27 # Add SSH (v2) public key(s) to authorized_keys file
32 28 cat "$SSH_ROOT_PUB_KEY" >> "${R}/root/.ssh/authorized_keys"
33 fi
34 29
35 # Set permissions of root SSH authorized keys file
36 if [ -f "${R}/root/.ssh/authorized_keys" ] ; then
30 # Set permissions of root SSH authorized_keys file
37 31 chroot_exec chmod 600 "/root/.ssh/authorized_keys"
38 32 chroot_exec chown root:root "/root/.ssh/authorized_keys"
39 33
40 34 # Allow SSH public key authentication
41 35 sed -i "s|[#]*PubkeyAuthentication.*|PubkeyAuthentication yes|g" "${ETC_DIR}/ssh/sshd_config"
42 36 fi
43 37 fi
44 38
45 39 if [ "$ENABLE_USER" = true ] ; then
46 # Create $USER_NAME SSH config directory
47 mkdir -p "${R}/home/${USER_NAME}/.ssh"
48
49 # Set permissions of $USER_NAME SSH config directory
50 chroot_exec chmod 700 "/home/${USER_NAME}/.ssh"
51 chroot_exec chown ${USER_NAME}:${USER_NAME} "/home/${USER_NAME}/.ssh"
52
53 # Install SSH (v2) authorized keys file for user $USER_NAME
54 if [ ! -z "$SSH_USER_AUTHORIZED_KEYS" ] ; then
55 install_readonly "$SSH_USER_AUTHORIZED_KEYS" "${R}/home/${USER_NAME}/.ssh/authorized_keys"
56 fi
57
58 40 # Add SSH (v2) public key for user $USER_NAME
59 41 if [ ! -z "$SSH_USER_PUB_KEY" ] ; then
42 # Create $USER_NAME SSH config directory
43 mkdir -p "${R}/home/${USER_NAME}/.ssh"
44
45 # Set permissions of $USER_NAME SSH config directory
46 chroot_exec chmod 700 "/home/${USER_NAME}/.ssh"
47 chroot_exec chown ${USER_NAME}:${USER_NAME} "/home/${USER_NAME}/.ssh"
48
49 # Add SSH (v2) public key(s) to authorized_keys file
60 50 cat "$SSH_USER_PUB_KEY" >> "${R}/home/${USER_NAME}/.ssh/authorized_keys"
61 fi
62 51
63 # Set permissions of $USER_NAME SSH authorized keys file
64 if [ -f "${R}/home/${USER_NAME}/.ssh/authorized_keys" ] ; then
52 # Set permissions of $USER_NAME SSH config directory
65 53 chroot_exec chmod 600 "/home/${USER_NAME}/.ssh/authorized_keys"
66 54 chroot_exec chown ${USER_NAME}:${USER_NAME} "/home/${USER_NAME}/.ssh/authorized_keys"
67 55
68 56 # Allow SSH public key authentication
69 57 sed -i "s|[#]*PubkeyAuthentication.*|PubkeyAuthentication yes|g" "${ETC_DIR}/ssh/sshd_config"
70 58 fi
71 59 fi
72 60
73 61 # Limit the users that are allowed to login via SSH
74 62 if [ "$SSH_LIMIT_USERS" = true ] ; then
75 63 allowed_users=""
76 64 if [ "$ENABLE_ROOT" = true ] && [ "$SSH_ENABLE_ROOT" = true ] ; then
77 65 allowed_users="root"
78 66 fi
79 67
80 68 if [ "$ENABLE_USER" = true ] ; then
81 69 allowed_users="${allowed_users} ${USER_NAME}"
82 70 fi
83 71
84 72 if [ ! -z "$allowed_users" ] ; then
85 73 echo "AllowUsers ${allowed_users}" >> "${ETC_DIR}/ssh/sshd_config"
86 74 fi
87 75 fi
88 76
89 77 # Disable password-based authentication
90 78 if [ "$SSH_DISABLE_PASSWORD_AUTH" = true ] ; then
91 79 if [ "$ENABLE_ROOT" = true ] && [ "$SSH_ENABLE_ROOT" = true ] ; then
92 80 sed -i "s|[#]*PermitRootLogin.*|PermitRootLogin without-password|g" "${ETC_DIR}/ssh/sshd_config"
93 81 fi
94 82
95 83 sed -i "s|[#]*PasswordAuthentication.*|PasswordAuthentication no|g" "${ETC_DIR}/ssh/sshd_config"
96 84 sed -i "s|[#]*ChallengeResponseAuthentication no.*|ChallengeResponseAuthentication no|g" "${ETC_DIR}/ssh/sshd_config"
97 85 sed -i "s|[#]*UsePAM.*|UsePAM no|g" "${ETC_DIR}/ssh/sshd_config"
98 86 fi
99 87 fi
@@ -1,633 +1,605
1 1 #!/bin/sh
2 2
3 3 ########################################################################
4 4 # rpi23-gen-image.sh 2015-2017
5 5 #
6 6 # Advanced Debian "jessie" and "stretch" bootstrap script for RPi2/3
7 7 #
8 8 # This program is free software; you can redistribute it and/or
9 9 # modify it under the terms of the GNU General Public License
10 10 # as published by the Free Software Foundation; either version 2
11 11 # of the License, or (at your option) any later version.
12 12 #
13 13 # Copyright (C) 2015 Jan Wagner <mail@jwagner.eu>
14 14 #
15 15 # Big thanks for patches and enhancements by 10+ github contributors!
16 16 ########################################################################
17 17
18 18 # Are we running as root?
19 19 if [ "$(id -u)" -ne "0" ] ; then
20 20 echo "error: this script must be executed with root privileges!"
21 21 exit 1
22 22 fi
23 23
24 24 # Check if ./functions.sh script exists
25 25 if [ ! -r "./functions.sh" ] ; then
26 26 echo "error: './functions.sh' required script not found!"
27 27 exit 1
28 28 fi
29 29
30 30 # Load utility functions
31 31 . ./functions.sh
32 32
33 33 # Load parameters from configuration template file
34 34 if [ ! -z "$CONFIG_TEMPLATE" ] ; then
35 35 use_template
36 36 fi
37 37
38 38 # Introduce settings
39 39 set -e
40 40 echo -n -e "\n#\n# RPi2/3 Bootstrap Settings\n#\n"
41 41 set -x
42 42
43 43 # Raspberry Pi model configuration
44 44 RPI_MODEL=${RPI_MODEL:=2}
45 45 RPI2_DTB_FILE=${RPI2_DTB_FILE:=bcm2709-rpi-2-b.dtb}
46 46 RPI2_UBOOT_CONFIG=${RPI2_UBOOT_CONFIG:=rpi_2_defconfig}
47 47 RPI3_DTB_FILE=${RPI3_DTB_FILE:=bcm2710-rpi-3-b.dtb}
48 48 RPI3_UBOOT_CONFIG=${RPI3_UBOOT_CONFIG:=rpi_3_32b_defconfig}
49 49
50 50 # Debian release
51 51 RELEASE=${RELEASE:=jessie}
52 52 KERNEL_ARCH=${KERNEL_ARCH:=arm}
53 53 RELEASE_ARCH=${RELEASE_ARCH:=armhf}
54 54 CROSS_COMPILE=${CROSS_COMPILE:=arm-linux-gnueabihf-}
55 55 COLLABORA_KERNEL=${COLLABORA_KERNEL:=3.18.0-trunk-rpi2}
56 56 KERNEL_DEFCONFIG=${KERNEL_DEFCONFIG:=bcm2709_defconfig}
57 57 KERNEL_IMAGE=${KERNEL_IMAGE:=kernel7.img}
58 58 QEMU_BINARY=${QEMU_BINARY:=/usr/bin/qemu-arm-static}
59 59
60 60 # URLs
61 61 KERNEL_URL=${KERNEL_URL:=https://github.com/raspberrypi/linux}
62 62 FIRMWARE_URL=${FIRMWARE_URL:=https://github.com/raspberrypi/firmware/raw/master/boot}
63 63 WLAN_FIRMWARE_URL=${WLAN_FIRMWARE_URL:=https://github.com/RPi-Distro/firmware-nonfree/raw/master/brcm80211/brcm}
64 64 COLLABORA_URL=${COLLABORA_URL:=https://repositories.collabora.co.uk/debian}
65 65 FBTURBO_URL=${FBTURBO_URL:=https://github.com/ssvb/xf86-video-fbturbo.git}
66 66 UBOOT_URL=${UBOOT_URL:=git://git.denx.de/u-boot.git}
67 67
68 68 # Build directories
69 69 BASEDIR="$(pwd)/images/${RELEASE}"
70 70 BUILDDIR="${BASEDIR}/build"
71 71
72 72 # Chroot directories
73 73 R="${BUILDDIR}/chroot"
74 74 ETC_DIR="${R}/etc"
75 75 LIB_DIR="${R}/lib"
76 76 BOOT_DIR="${R}/boot/firmware"
77 77 KERNEL_DIR="${R}/usr/src/linux"
78 78 WLAN_FIRMWARE_DIR="${R}/lib/firmware/brcm"
79 79
80 80 # Firmware directory: Blank if download from github
81 81 RPI_FIRMWARE_DIR=${RPI_FIRMWARE_DIR:=""}
82 82
83 83 # General settings
84 84 HOSTNAME=${HOSTNAME:=rpi${RPI_MODEL}-${RELEASE}}
85 85 PASSWORD=${PASSWORD:=raspberry}
86 86 USER_PASSWORD=${USER_PASSWORD:=raspberry}
87 87 DEFLOCAL=${DEFLOCAL:="en_US.UTF-8"}
88 88 TIMEZONE=${TIMEZONE:="Europe/Berlin"}
89 89 EXPANDROOT=${EXPANDROOT:=true}
90 90
91 91 # Keyboard settings
92 92 XKB_MODEL=${XKB_MODEL:=""}
93 93 XKB_LAYOUT=${XKB_LAYOUT:=""}
94 94 XKB_VARIANT=${XKB_VARIANT:=""}
95 95 XKB_OPTIONS=${XKB_OPTIONS:=""}
96 96
97 97 # Network settings (DHCP)
98 98 ENABLE_DHCP=${ENABLE_DHCP:=true}
99 99
100 100 # Network settings (static)
101 101 NET_ADDRESS=${NET_ADDRESS:=""}
102 102 NET_GATEWAY=${NET_GATEWAY:=""}
103 103 NET_DNS_1=${NET_DNS_1:=""}
104 104 NET_DNS_2=${NET_DNS_2:=""}
105 105 NET_DNS_DOMAINS=${NET_DNS_DOMAINS:=""}
106 106 NET_NTP_1=${NET_NTP_1:=""}
107 107 NET_NTP_2=${NET_NTP_2:=""}
108 108
109 109 # APT settings
110 110 APT_PROXY=${APT_PROXY:=""}
111 111 APT_SERVER=${APT_SERVER:="ftp.debian.org"}
112 112
113 113 # Feature settings
114 114 ENABLE_CONSOLE=${ENABLE_CONSOLE:=true}
115 115 ENABLE_I2C=${ENABLE_I2C:=false}
116 116 ENABLE_SPI=${ENABLE_SPI:=false}
117 117 ENABLE_IPV6=${ENABLE_IPV6:=true}
118 118 ENABLE_SSHD=${ENABLE_SSHD:=true}
119 119 ENABLE_NONFREE=${ENABLE_NONFREE:=false}
120 120 ENABLE_WIRELESS=${ENABLE_WIRELESS:=false}
121 121 ENABLE_SOUND=${ENABLE_SOUND:=true}
122 122 ENABLE_DBUS=${ENABLE_DBUS:=true}
123 123 ENABLE_HWRANDOM=${ENABLE_HWRANDOM:=true}
124 124 ENABLE_MINGPU=${ENABLE_MINGPU:=false}
125 125 ENABLE_XORG=${ENABLE_XORG:=false}
126 126 ENABLE_WM=${ENABLE_WM:=""}
127 127 ENABLE_RSYSLOG=${ENABLE_RSYSLOG:=true}
128 128 ENABLE_USER=${ENABLE_USER:=true}
129 129 USER_NAME=${USER_NAME:="pi"}
130 130 ENABLE_ROOT=${ENABLE_ROOT:=false}
131 131
132 132 # SSH settings
133 133 SSH_ENABLE_ROOT=${SSH_ENABLE_ROOT:=false}
134 134 SSH_DISABLE_PASSWORD_AUTH=${SSH_DISABLE_PASSWORD_AUTH:=false}
135 135 SSH_LIMIT_USERS=${SSH_LIMIT_USERS:=false}
136 SSH_ROOT_AUTHORIZED_KEYS=${SSH_ROOT_AUTHORIZED_KEYS:=""}
137 SSH_USER_AUTHORIZED_KEYS=${SSH_USER_AUTHORIZED_KEYS:=""}
138 136 SSH_ROOT_PUB_KEY=${SSH_ROOT_PUB_KEY:=""}
139 137 SSH_USER_PUB_KEY=${SSH_USER_PUB_KEY:=""}
140 138
141 139 # Advanced settings
142 140 ENABLE_MINBASE=${ENABLE_MINBASE:=false}
143 141 ENABLE_REDUCE=${ENABLE_REDUCE:=false}
144 142 ENABLE_UBOOT=${ENABLE_UBOOT:=false}
145 143 ENABLE_FBTURBO=${ENABLE_FBTURBO:=false}
146 144 ENABLE_HARDNET=${ENABLE_HARDNET:=false}
147 145 ENABLE_IPTABLES=${ENABLE_IPTABLES:=false}
148 146 ENABLE_SPLITFS=${ENABLE_SPLITFS:=false}
149 147 ENABLE_INITRAMFS=${ENABLE_INITRAMFS:=false}
150 148 ENABLE_IFNAMES=${ENABLE_IFNAMES:=true}
151 149
152 150 # Kernel compilation settings
153 151 BUILD_KERNEL=${BUILD_KERNEL:=false}
154 152 KERNEL_REDUCE=${KERNEL_REDUCE:=false}
155 153 KERNEL_THREADS=${KERNEL_THREADS:=1}
156 154 KERNEL_HEADERS=${KERNEL_HEADERS:=true}
157 155 KERNEL_MENUCONFIG=${KERNEL_MENUCONFIG:=false}
158 156 KERNEL_REMOVESRC=${KERNEL_REMOVESRC:=true}
159 157
160 158 # Kernel compilation from source directory settings
161 159 KERNELSRC_DIR=${KERNELSRC_DIR:=""}
162 160 KERNELSRC_CLEAN=${KERNELSRC_CLEAN:=false}
163 161 KERNELSRC_CONFIG=${KERNELSRC_CONFIG:=true}
164 162 KERNELSRC_PREBUILT=${KERNELSRC_PREBUILT:=false}
165 163
166 164 # Reduce disk usage settings
167 165 REDUCE_APT=${REDUCE_APT:=true}
168 166 REDUCE_DOC=${REDUCE_DOC:=true}
169 167 REDUCE_MAN=${REDUCE_MAN:=true}
170 168 REDUCE_VIM=${REDUCE_VIM:=false}
171 169 REDUCE_BASH=${REDUCE_BASH:=false}
172 170 REDUCE_HWDB=${REDUCE_HWDB:=true}
173 171 REDUCE_SSHD=${REDUCE_SSHD:=true}
174 172 REDUCE_LOCALE=${REDUCE_LOCALE:=true}
175 173
176 174 # Encrypted filesystem settings
177 175 ENABLE_CRYPTFS=${ENABLE_CRYPTFS:=false}
178 176 CRYPTFS_PASSWORD=${CRYPTFS_PASSWORD:=""}
179 177 CRYPTFS_MAPPING=${CRYPTFS_MAPPING:="secure"}
180 178 CRYPTFS_CIPHER=${CRYPTFS_CIPHER:="aes-xts-plain64:sha512"}
181 179 CRYPTFS_XTSKEYSIZE=${CRYPTFS_XTSKEYSIZE:=512}
182 180
183 181 # Stop the Crypto Wars
184 182 DISABLE_FBI=${DISABLE_FBI:=false}
185 183
186 184 # Chroot scripts directory
187 185 CHROOT_SCRIPTS=${CHROOT_SCRIPTS:=""}
188 186
189 187 # Packages required in the chroot build environment
190 188 APT_INCLUDES=${APT_INCLUDES:=""}
191 189 APT_INCLUDES="${APT_INCLUDES},apt-transport-https,apt-utils,ca-certificates,debian-archive-keyring,dialog,sudo,systemd,sysvinit-utils"
192 190
193 191 # Packages required for bootstrapping
194 192 REQUIRED_PACKAGES="debootstrap debian-archive-keyring qemu-user-static binfmt-support dosfstools rsync bmap-tools whois git bc psmisc"
195 193 MISSING_PACKAGES=""
196 194
197 195 set +x
198 196
199 197 # Set Raspberry Pi model specific configuration
200 198 if [ "$RPI_MODEL" = 2 ] ; then
201 199 DTB_FILE=${RPI2_DTB_FILE}
202 200 UBOOT_CONFIG=${RPI2_UBOOT_CONFIG}
203 201 elif [ "$RPI_MODEL" = 3 ] ; then
204 202 DTB_FILE=${RPI3_DTB_FILE}
205 203 UBOOT_CONFIG=${RPI3_UBOOT_CONFIG}
206 204 BUILD_KERNEL=true
207 205 else
208 206 echo "error: Raspberry Pi model ${RPI_MODEL} is not supported!"
209 207 exit 1
210 208 fi
211 209
212 210 # Check if the internal wireless interface is supported by the RPi model
213 211 if [ "$ENABLE_WIRELESS" = true ] && [ "$RPI_MODEL" != 3 ] ; then
214 212 echo "error: The selected Raspberry Pi model has no internal wireless interface"
215 213 exit 1
216 214 fi
217 215
218 216 # Set compiler packages and build RPi2/3 Linux kernel if required by Debian release
219 217 if [ "$RELEASE" = "jessie" ] ; then
220 218 COMPILER_PACKAGES="linux-compiler-gcc-4.8-arm g++ make bc"
221 219 elif [ "$RELEASE" = "stretch" ] ; then
222 220 COMPILER_PACKAGES="linux-compiler-gcc-5-arm g++ make bc"
223 221 BUILD_KERNEL=true
224 222 else
225 223 echo "error: Debian release ${RELEASE} is not supported!"
226 224 exit 1
227 225 fi
228 226
229 227 # Add packages required for kernel cross compilation
230 228 if [ "$BUILD_KERNEL" = true ] ; then
231 229 REQUIRED_PACKAGES="${REQUIRED_PACKAGES} crossbuild-essential-armhf"
232 230 fi
233 231
234 232 # Add libncurses5 to enable kernel menuconfig
235 233 if [ "$KERNEL_MENUCONFIG" = true ] ; then
236 234 REQUIRED_PACKAGES="${REQUIRED_PACKAGES} libncurses5-dev"
237 235 fi
238 236
239 237 # Stop the Crypto Wars
240 238 if [ "$DISABLE_FBI" = true ] ; then
241 239 ENABLE_CRYPTFS=true
242 240 fi
243 241
244 242 # Add cryptsetup package to enable filesystem encryption
245 243 if [ "$ENABLE_CRYPTFS" = true ] && [ "$BUILD_KERNEL" = true ] ; then
246 244 REQUIRED_PACKAGES="${REQUIRED_PACKAGES} cryptsetup"
247 245 APT_INCLUDES="${APT_INCLUDES},cryptsetup"
248 246
249 247 if [ -z "$CRYPTFS_PASSWORD" ] ; then
250 248 echo "error: no password defined (CRYPTFS_PASSWORD)!"
251 249 exit 1
252 250 fi
253 251 ENABLE_INITRAMFS=true
254 252 fi
255 253
256 254 # Add initramfs generation tools
257 255 if [ "$ENABLE_INITRAMFS" = true ] && [ "$BUILD_KERNEL" = true ] ; then
258 256 APT_INCLUDES="${APT_INCLUDES},initramfs-tools"
259 257 fi
260 258
261 259 # Add device-tree-compiler required for building the U-Boot bootloader
262 260 if [ "$ENABLE_UBOOT" = true ] ; then
263 261 APT_INCLUDES="${APT_INCLUDES},device-tree-compiler"
264 262 fi
265 263
266 # Check if root SSH authorized keys file exists
267 if [ ! -z "$SSH_ROOT_AUTHORIZED_KEYS" ] ; then
268 if [ ! -f "$SSH_ROOT_AUTHORIZED_KEYS" ] ; then
269 echo "error: '$SSH_ROOT_AUTHORIZED_KEYS' specified SSH authorized keys file not found (SSH_ROOT_AUTHORIZED_KEYS)!"
270 exit 1
271 fi
272 fi
273
274 # Check if $USER_NAME SSH authorized keys file exists
275 if [ ! -z "$SSH_USER_AUTHORIZED_KEYS" ] ; then
276 if [ ! -f "$SSH_USER_AUTHORIZED_KEYS" ] ; then
277 echo "error: '$SSH_USER_AUTHORIZED_KEYS' specified SSH authorized keys file not found (SSH_USER_AUTHORIZED_KEYS)!"
278 exit 1
279 fi
280 fi
281
282 264 # Check if root SSH (v2) public key file exists
283 265 if [ ! -z "$SSH_ROOT_PUB_KEY" ] ; then
284 266 if [ ! -f "$SSH_ROOT_PUB_KEY" ] ; then
285 267 echo "error: '$SSH_ROOT_PUB_KEY' specified SSH public key file not found (SSH_ROOT_PUB_KEY)!"
286 268 exit 1
287 269 fi
288 270 fi
289 271
290 272 # Check if $USER_NAME SSH (v2) public key file exists
291 273 if [ ! -z "$SSH_USER_PUB_KEY" ] ; then
292 274 if [ ! -f "$SSH_USER_PUB_KEY" ] ; then
293 275 echo "error: '$SSH_USER_PUB_KEY' specified SSH public key file not found (SSH_USER_PUB_KEY)!"
294 276 exit 1
295 277 fi
296 278 fi
297 279
298 280 # Check if all required packages are installed on the build system
299 281 for package in $REQUIRED_PACKAGES ; do
300 282 if [ "`dpkg-query -W -f='${Status}' $package`" != "install ok installed" ] ; then
301 283 MISSING_PACKAGES="${MISSING_PACKAGES} $package"
302 284 fi
303 285 done
304 286
305 287 # If there are missing packages ask confirmation for install, or exit
306 288 if [ -n "$MISSING_PACKAGES" ] ; then
307 289 echo "the following packages needed by this script are not installed:"
308 290 echo "$MISSING_PACKAGES"
309 291
310 292 echo -n "\ndo you want to install the missing packages right now? [y/n] "
311 293 read confirm
312 294 [ "$confirm" != "y" ] && exit 1
313 295
314 296 # Make sure all missing required packages are installed
315 297 apt-get -qq -y install ${MISSING_PACKAGES}
316 298 fi
317 299
318 300 # Check if ./bootstrap.d directory exists
319 301 if [ ! -d "./bootstrap.d/" ] ; then
320 302 echo "error: './bootstrap.d' required directory not found!"
321 303 exit 1
322 304 fi
323 305
324 306 # Check if ./files directory exists
325 307 if [ ! -d "./files/" ] ; then
326 308 echo "error: './files' required directory not found!"
327 309 exit 1
328 310 fi
329 311
330 312 # Check if specified KERNELSRC_DIR directory exists
331 313 if [ -n "$KERNELSRC_DIR" ] && [ ! -d "$KERNELSRC_DIR" ] ; then
332 314 echo "error: '${KERNELSRC_DIR}' specified directory not found (KERNELSRC_DIR)!"
333 315 exit 1
334 316 fi
335 317
336 318 # Check if specified CHROOT_SCRIPTS directory exists
337 319 if [ -n "$CHROOT_SCRIPTS" ] && [ ! -d "$CHROOT_SCRIPTS" ] ; then
338 320 echo "error: ${CHROOT_SCRIPTS} specified directory not found (CHROOT_SCRIPTS)!"
339 321 exit 1
340 322 fi
341 323
342 324 # Check if specified device mapping already exists (will be used by cryptsetup)
343 325 if [ -r "/dev/mapping/${CRYPTFS_MAPPING}" ] ; then
344 326 echo "error: mapping /dev/mapping/${CRYPTFS_MAPPING} already exists, not proceeding"
345 327 exit 1
346 328 fi
347 329
348 330 # Don't clobber an old build
349 331 if [ -e "$BUILDDIR" ] ; then
350 332 echo "error: directory ${BUILDDIR} already exists, not proceeding"
351 333 exit 1
352 334 fi
353 335
354 336 # Setup chroot directory
355 337 mkdir -p "${R}"
356 338
357 339 # Check if build directory has enough of free disk space >512MB
358 340 if [ "$(df --output=avail ${BUILDDIR} | sed "1d")" -le "524288" ] ; then
359 341 echo "error: ${BUILDDIR} not enough space left to generate the output image!"
360 342 exit 1
361 343 fi
362 344
363 345 set -x
364 346
365 347 # Call "cleanup" function on various signals and errors
366 348 trap cleanup 0 1 2 3 6
367 349
368 350 # Add required packages for the minbase installation
369 351 if [ "$ENABLE_MINBASE" = true ] ; then
370 352 APT_INCLUDES="${APT_INCLUDES},vim-tiny,netbase,net-tools,ifupdown"
371 353 fi
372 354
373 355 # Add required locales packages
374 356 if [ "$DEFLOCAL" != "en_US.UTF-8" ] ; then
375 357 APT_INCLUDES="${APT_INCLUDES},locales,keyboard-configuration,console-setup"
376 358 fi
377 359
378 360 # Add parted package, required to get partprobe utility
379 361 if [ "$EXPANDROOT" = true ] ; then
380 362 APT_INCLUDES="${APT_INCLUDES},parted"
381 363 fi
382 364
383 365 # Add dbus package, recommended if using systemd
384 366 if [ "$ENABLE_DBUS" = true ] ; then
385 367 APT_INCLUDES="${APT_INCLUDES},dbus"
386 368 fi
387 369
388 370 # Add iptables IPv4/IPv6 package
389 371 if [ "$ENABLE_IPTABLES" = true ] ; then
390 372 APT_INCLUDES="${APT_INCLUDES},iptables"
391 373 fi
392 374
393 375 # Add openssh server package
394 376 if [ "$ENABLE_SSHD" = true ] ; then
395 377 APT_INCLUDES="${APT_INCLUDES},openssh-server"
396 378 fi
397 379
398 380 # Add alsa-utils package
399 381 if [ "$ENABLE_SOUND" = true ] ; then
400 382 APT_INCLUDES="${APT_INCLUDES},alsa-utils"
401 383 fi
402 384
403 385 # Add rng-tools package
404 386 if [ "$ENABLE_HWRANDOM" = true ] ; then
405 387 APT_INCLUDES="${APT_INCLUDES},rng-tools"
406 388 fi
407 389
408 390 # Add fbturbo video driver
409 391 if [ "$ENABLE_FBTURBO" = true ] ; then
410 392 # Enable xorg package dependencies
411 393 ENABLE_XORG=true
412 394 fi
413 395
414 396 # Add user defined window manager package
415 397 if [ -n "$ENABLE_WM" ] ; then
416 398 APT_INCLUDES="${APT_INCLUDES},${ENABLE_WM}"
417 399
418 400 # Enable xorg package dependencies
419 401 ENABLE_XORG=true
420 402 fi
421 403
422 404 # Add xorg package
423 405 if [ "$ENABLE_XORG" = true ] ; then
424 406 APT_INCLUDES="${APT_INCLUDES},xorg"
425 407 fi
426 408
427 409 # Replace selected packages with smaller clones
428 410 if [ "$ENABLE_REDUCE" = true ] ; then
429 411 # Add levee package instead of vim-tiny
430 412 if [ "$REDUCE_VIM" = true ] ; then
431 413 APT_INCLUDES="$(echo ${APT_INCLUDES} | sed "s/vim-tiny/levee/")"
432 414 fi
433 415
434 416 # Add dropbear package instead of openssh-server
435 417 if [ "$REDUCE_SSHD" = true ] ; then
436 418 APT_INCLUDES="$(echo ${APT_INCLUDES} | sed "s/openssh-server/dropbear/")"
437 419 fi
438 420 fi
439 421
440 422 # Configure kernel sources if no KERNELSRC_DIR
441 423 if [ "$BUILD_KERNEL" = true ] && [ -z "$KERNELSRC_DIR" ] ; then
442 424 KERNELSRC_CONFIG=true
443 425 fi
444 426
445 427 # Configure reduced kernel
446 428 if [ "$KERNEL_REDUCE" = true ] ; then
447 429 KERNELSRC_CONFIG=false
448 430 fi
449 431
450 432 # Execute bootstrap scripts
451 433 for SCRIPT in bootstrap.d/*.sh; do
452 434 head -n 3 "$SCRIPT"
453 435 . "$SCRIPT"
454 436 done
455 437
456 438 ## Execute custom bootstrap scripts
457 439 if [ -d "custom.d" ] ; then
458 440 for SCRIPT in custom.d/*.sh; do
459 441 . "$SCRIPT"
460 442 done
461 443 fi
462 444
463 445 # Execute custom scripts inside the chroot
464 446 if [ -n "$CHROOT_SCRIPTS" ] && [ -d "$CHROOT_SCRIPTS" ] ; then
465 447 cp -r "${CHROOT_SCRIPTS}" "${R}/chroot_scripts"
466 448 chroot_exec /bin/bash -x <<'EOF'
467 449 for SCRIPT in /chroot_scripts/* ; do
468 450 if [ -f $SCRIPT -a -x $SCRIPT ] ; then
469 451 $SCRIPT
470 452 fi
471 453 done
472 454 EOF
473 455 rm -rf "${R}/chroot_scripts"
474 456 fi
475 457
476 458 # Remove apt-utils
477 459 if [ "$RELEASE" = "jessie" ] ; then
478 460 chroot_exec apt-get purge -qq -y --force-yes apt-utils
479 461 fi
480 462
481 463 # Generate required machine-id
482 464 MACHINE_ID=$(dbus-uuidgen)
483 465 echo -n "${MACHINE_ID}" > "${R}/var/lib/dbus/machine-id"
484 466 echo -n "${MACHINE_ID}" > "${ETC_DIR}/machine-id"
485 467
486 468 # APT Cleanup
487 469 chroot_exec apt-get -y clean
488 470 chroot_exec apt-get -y autoclean
489 471 chroot_exec apt-get -y autoremove
490 472
491 473 # Unmount mounted filesystems
492 474 umount -l "${R}/proc"
493 475 umount -l "${R}/sys"
494 476
495 477 # Clean up directories
496 478 rm -rf "${R}/run/*"
497 479 rm -rf "${R}/tmp/*"
498 480
499 481 # Clean up files
500 482 rm -f "${ETC_DIR}/ssh/ssh_host_*"
501 483 rm -f "${ETC_DIR}/dropbear/dropbear_*"
502 484 rm -f "${ETC_DIR}/apt/sources.list.save"
503 485 rm -f "${ETC_DIR}/resolvconf/resolv.conf.d/original"
504 486 rm -f "${ETC_DIR}/*-"
505 487 rm -f "${ETC_DIR}/apt/apt.conf.d/10proxy"
506 488 rm -f "${ETC_DIR}/resolv.conf"
507 489 rm -f "${R}/root/.bash_history"
508 490 rm -f "${R}/var/lib/urandom/random-seed"
509 491 rm -f "${R}/initrd.img"
510 492 rm -f "${R}/vmlinuz"
511 493 rm -f "${R}${QEMU_BINARY}"
512 494
513 # Remove root .ssh directory if it's empty
514 if [ -d "${R}/root/.ssh" ] ; then
515 rmdir --ignore-fail-on-non-empty "${R}/root/.ssh"
516 fi
517
518 # Remove $USER_NAME .ssh directory if it's empty
519 if [ -d "${R}/home/${USER_NAME}/.ssh" ] ; then
520 rmdir --ignore-fail-on-non-empty "${R}/home/${USER_NAME}/.ssh"
521 fi
522
523 495 # Calculate size of the chroot directory in KB
524 496 CHROOT_SIZE=$(expr `du -s "${R}" | awk '{ print $1 }'`)
525 497
526 498 # Calculate the amount of needed 512 Byte sectors
527 499 TABLE_SECTORS=$(expr 1 \* 1024 \* 1024 \/ 512)
528 500 FRMW_SECTORS=$(expr 64 \* 1024 \* 1024 \/ 512)
529 501 ROOT_OFFSET=$(expr ${TABLE_SECTORS} + ${FRMW_SECTORS})
530 502
531 503 # The root partition is EXT4
532 504 # This means more space than the actual used space of the chroot is used.
533 505 # As overhead for journaling and reserved blocks 25% are added.
534 506 ROOT_SECTORS=$(expr $(expr ${CHROOT_SIZE} + ${CHROOT_SIZE} \/ 100 \* 25) \* 1024 \/ 512)
535 507
536 508 # Calculate required image size in 512 Byte sectors
537 509 IMAGE_SECTORS=$(expr ${TABLE_SECTORS} + ${FRMW_SECTORS} + ${ROOT_SECTORS})
538 510
539 511 # Prepare date string for image file name
540 512 DATE="$(date +%Y-%m-%d)"
541 513
542 514 # Prepare image file
543 515 if [ "$ENABLE_SPLITFS" = true ] ; then
544 516 dd if=/dev/zero of="$BASEDIR/${DATE}-rpi${RPI_MODEL}-${RELEASE}-frmw.img" bs=512 count=${TABLE_SECTORS}
545 517 dd if=/dev/zero of="$BASEDIR/${DATE}-rpi${RPI_MODEL}-${RELEASE}-frmw.img" bs=512 count=0 seek=${FRMW_SECTORS}
546 518 dd if=/dev/zero of="$BASEDIR/${DATE}-rpi${RPI_MODEL}-${RELEASE}-root.img" bs=512 count=${TABLE_SECTORS}
547 519 dd if=/dev/zero of="$BASEDIR/${DATE}-rpi${RPI_MODEL}-${RELEASE}-root.img" bs=512 count=0 seek=${ROOT_SECTORS}
548 520
549 521 # Write firmware/boot partition tables
550 522 sfdisk -q -L -uS -f "$BASEDIR/${DATE}-rpi${RPI_MODEL}-${RELEASE}-frmw.img" 2> /dev/null <<EOM
551 523 ${TABLE_SECTORS},${FRMW_SECTORS},c,*
552 524 EOM
553 525
554 526 # Write root partition table
555 527 sfdisk -q -L -uS -f "$BASEDIR/${DATE}-rpi${RPI_MODEL}-${RELEASE}-root.img" 2> /dev/null <<EOM
556 528 ${TABLE_SECTORS},${ROOT_SECTORS},83
557 529 EOM
558 530
559 531 # Setup temporary loop devices
560 532 FRMW_LOOP="$(losetup -o 1M --sizelimit 64M -f --show $BASEDIR/${DATE}-rpi${RPI_MODEL}-${RELEASE}-frmw.img)"
561 533 ROOT_LOOP="$(losetup -o 1M -f --show $BASEDIR/${DATE}-rpi${RPI_MODEL}-${RELEASE}-root.img)"
562 534 else # ENABLE_SPLITFS=false
563 535 dd if=/dev/zero of="$BASEDIR/${DATE}-rpi${RPI_MODEL}-${RELEASE}.img" bs=512 count=${TABLE_SECTORS}
564 536 dd if=/dev/zero of="$BASEDIR/${DATE}-rpi${RPI_MODEL}-${RELEASE}.img" bs=512 count=0 seek=${IMAGE_SECTORS}
565 537
566 538 # Write partition table
567 539 sfdisk -q -L -uS -f "$BASEDIR/${DATE}-rpi${RPI_MODEL}-${RELEASE}.img" 2> /dev/null <<EOM
568 540 ${TABLE_SECTORS},${FRMW_SECTORS},c,*
569 541 ${ROOT_OFFSET},${ROOT_SECTORS},83
570 542 EOM
571 543
572 544 # Setup temporary loop devices
573 545 FRMW_LOOP="$(losetup -o 1M --sizelimit 64M -f --show $BASEDIR/${DATE}-rpi${RPI_MODEL}-${RELEASE}.img)"
574 546 ROOT_LOOP="$(losetup -o 65M -f --show $BASEDIR/${DATE}-rpi${RPI_MODEL}-${RELEASE}.img)"
575 547 fi
576 548
577 549 if [ "$ENABLE_CRYPTFS" = true ] ; then
578 550 # Create dummy ext4 fs
579 551 mkfs.ext4 "$ROOT_LOOP"
580 552
581 553 # Setup password keyfile
582 554 echo -n ${CRYPTFS_PASSWORD} > .password
583 555 chmod 600 .password
584 556
585 557 # Initialize encrypted partition
586 558 echo "YES" | cryptsetup luksFormat "${ROOT_LOOP}" -c "${CRYPTFS_CIPHER}" -s "${CRYPTFS_XTSKEYSIZE}" .password
587 559
588 560 # Open encrypted partition and setup mapping
589 561 cryptsetup luksOpen "${ROOT_LOOP}" -d .password "${CRYPTFS_MAPPING}"
590 562
591 563 # Secure delete password keyfile
592 564 shred -zu .password
593 565
594 566 # Update temporary loop device
595 567 ROOT_LOOP="/dev/mapper/${CRYPTFS_MAPPING}"
596 568
597 569 # Wipe encrypted partition (encryption cipher is used for randomness)
598 570 dd if=/dev/zero of="${ROOT_LOOP}" bs=512 count=$(blockdev --getsz "${ROOT_LOOP}")
599 571 fi
600 572
601 573 # Build filesystems
602 574 mkfs.vfat "$FRMW_LOOP"
603 575 mkfs.ext4 "$ROOT_LOOP"
604 576
605 577 # Mount the temporary loop devices
606 578 mkdir -p "$BUILDDIR/mount"
607 579 mount "$ROOT_LOOP" "$BUILDDIR/mount"
608 580
609 581 mkdir -p "$BUILDDIR/mount/boot/firmware"
610 582 mount "$FRMW_LOOP" "$BUILDDIR/mount/boot/firmware"
611 583
612 584 # Copy all files from the chroot to the loop device mount point directory
613 585 rsync -a "${R}/" "$BUILDDIR/mount/"
614 586
615 587 # Unmount all temporary loop devices and mount points
616 588 cleanup
617 589
618 590 # Create block map file(s) of image(s)
619 591 if [ "$ENABLE_SPLITFS" = true ] ; then
620 592 # Create block map files for "bmaptool"
621 593 bmaptool create -o "$BASEDIR/${DATE}-rpi${RPI_MODEL}-${RELEASE}-frmw.bmap" "$BASEDIR/${DATE}-rpi${RPI_MODEL}-${RELEASE}-frmw.img"
622 594 bmaptool create -o "$BASEDIR/${DATE}-rpi${RPI_MODEL}-${RELEASE}-root.bmap" "$BASEDIR/${DATE}-rpi${RPI_MODEL}-${RELEASE}-root.img"
623 595
624 596 # Image was successfully created
625 597 echo "$BASEDIR/${DATE}-rpi${RPI_MODEL}-${RELEASE}-frmw.img ($(expr \( ${TABLE_SECTORS} + ${FRMW_SECTORS} \) \* 512 \/ 1024 \/ 1024)M)" ": successfully created"
626 598 echo "$BASEDIR/${DATE}-rpi${RPI_MODEL}-${RELEASE}-root.img ($(expr \( ${TABLE_SECTORS} + ${ROOT_SECTORS} \) \* 512 \/ 1024 \/ 1024)M)" ": successfully created"
627 599 else
628 600 # Create block map file for "bmaptool"
629 601 bmaptool create -o "$BASEDIR/${DATE}-rpi${RPI_MODEL}-${RELEASE}.bmap" "$BASEDIR/${DATE}-rpi${RPI_MODEL}-${RELEASE}.img"
630 602
631 603 # Image was successfully created
632 604 echo "$BASEDIR/${DATE}-rpi${RPI_MODEL}-${RELEASE}.img ($(expr \( ${TABLE_SECTORS} + ${FRMW_SECTORS} + ${ROOT_SECTORS} \) \* 512 \/ 1024 \/ 1024)M)" ": successfully created"
633 605 fi
General Comments 0
Vous devez vous connecter pour laisser un commentaire. Se connecter maintenant