##// END OF EJS Templates
remerge
Unknown -
r385:fa8b2a18246e
parent child
Show More
@@ -1,499 +1,499
1 # rpi23-gen-image
1 # rpi23-gen-image
2 ## Introduction
2 ## Introduction
3 `rpi23-gen-image.sh` is an advanced Debian Linux bootstrapping shell script for generating Debian OS images for Raspberry Pi 2 (RPi2) and Raspberry Pi 3 (RPi3) computers. The script at this time supports the bootstrapping of the Debian (armhf) releases `stretch` and `buster`. Raspberry Pi 3 images are generated for 32-bit mode only. Raspberry Pi 3 64-bit images can be generated using custom configuration parameters (```templates/rpi3-stretch-arm64-4.11.y```).
3 `rpi23-gen-image.sh` is an advanced Debian Linux bootstrapping shell script for generating Debian OS images for Raspberry Pi 2 (RPi2) and Raspberry Pi 3 (RPi3) computers. The script at this time supports the bootstrapping of the Debian (armhf) releases `stretch` and `buster`. Raspberry Pi 3 images are generated for 32-bit mode only. Raspberry Pi 3 64-bit images can be generated using custom configuration parameters (```templates/rpi3-stretch-arm64-4.11.y```).
4
4
5 ## Build dependencies
5 ## Build dependencies
6 The following list of Debian packages must be installed on the build system because they are essentially required for the bootstrapping process. The script will check if all required packages are installed and missing packages will be installed automatically if confirmed by the user.
6 The following list of Debian packages must be installed on the build system because they are essentially required for the bootstrapping process. The script will check if all required packages are installed and missing packages will be installed automatically if confirmed by the user.
7
7
8 ```debootstrap debian-archive-keyring qemu-user-static binfmt-support dosfstools rsync bmap-tools whois git bc psmisc dbus sudo```
8 ```debootstrap debian-archive-keyring qemu-user-static binfmt-support dosfstools rsync bmap-tools whois git bc psmisc dbus sudo```
9
9
10 It is recommended to configure the `rpi23-gen-image.sh` script to build and install the latest Raspberry Pi Linux kernel. For the RPi3 this is mandatory. Kernel compilation and linking will be performed on the build system using an ARM (armhf) cross-compiler toolchain.
10 It is recommended to configure the `rpi23-gen-image.sh` script to build and install the latest Raspberry Pi Linux kernel. For the RPi3 this is mandatory. Kernel compilation and linking will be performed on the build system using an ARM (armhf) cross-compiler toolchain.
11
11
12 The script has been tested using the default `crossbuild-essential-armhf` toolchain meta package on Debian Linux and `stretch` build systems. Please check the [Debian CrossToolchains Wiki](https://wiki.debian.org/CrossToolchains) for further information.
12 The script has been tested using the default `crossbuild-essential-armhf` toolchain meta package on Debian Linux and `stretch` build systems. Please check the [Debian CrossToolchains Wiki](https://wiki.debian.org/CrossToolchains) for further information.
13
13
14 ## Command-line parameters
14 ## Command-line parameters
15 The script accepts certain command-line parameters to enable or disable specific OS features, services and configuration settings. These parameters are passed to the `rpi23-gen-image.sh` script via (simple) shell-variables. Unlike environment shell-variables (simple) shell-variables are defined at the beginning of the command-line call of the `rpi23-gen-image.sh` script.
15 The script accepts certain command-line parameters to enable or disable specific OS features, services and configuration settings. These parameters are passed to the `rpi23-gen-image.sh` script via (simple) shell-variables. Unlike environment shell-variables (simple) shell-variables are defined at the beginning of the command-line call of the `rpi23-gen-image.sh` script.
16
16
17 ##### Command-line examples:
17 ##### Command-line examples:
18 ```shell
18 ```shell
19 ENABLE_UBOOT=true ./rpi23-gen-image.sh
19 ENABLE_UBOOT=true ./rpi23-gen-image.sh
20 ENABLE_CONSOLE=false ENABLE_IPV6=false ./rpi23-gen-image.sh
20 ENABLE_CONSOLE=false ENABLE_IPV6=false ./rpi23-gen-image.sh
21 ENABLE_WM=xfce4 ENABLE_FBTURBO=true ENABLE_MINBASE=true ./rpi23-gen-image.sh
21 ENABLE_WM=xfce4 ENABLE_FBTURBO=true ENABLE_MINBASE=true ./rpi23-gen-image.sh
22 ENABLE_HARDNET=true ENABLE_IPTABLES=true /rpi23-gen-image.sh
22 ENABLE_HARDNET=true ENABLE_IPTABLES=true /rpi23-gen-image.sh
23 APT_SERVER=ftp.de.debian.org APT_PROXY="http://127.0.0.1:3142/" ./rpi23-gen-image.sh
23 APT_SERVER=ftp.de.debian.org APT_PROXY="http://127.0.0.1:3142/" ./rpi23-gen-image.sh
24 ENABLE_MINBASE=true ./rpi23-gen-image.sh
24 ENABLE_MINBASE=true ./rpi23-gen-image.sh
25 BUILD_KERNEL=true ENABLE_MINBASE=true ENABLE_IPV6=false ./rpi23-gen-image.sh
25 BUILD_KERNEL=true ENABLE_MINBASE=true ENABLE_IPV6=false ./rpi23-gen-image.sh
26 BUILD_KERNEL=true KERNELSRC_DIR=/tmp/linux ./rpi23-gen-image.sh
26 BUILD_KERNEL=true KERNELSRC_DIR=/tmp/linux ./rpi23-gen-image.sh
27 ENABLE_MINBASE=true ENABLE_REDUCE=true ENABLE_MINGPU=true BUILD_KERNEL=true ./rpi23-gen-image.sh
27 ENABLE_MINBASE=true ENABLE_REDUCE=true ENABLE_MINGPU=true BUILD_KERNEL=true ./rpi23-gen-image.sh
28 ENABLE_CRYPTFS=true CRYPTFS_PASSWORD=changeme EXPANDROOT=false ENABLE_MINBASE=true ENABLE_REDUCE=true ENABLE_MINGPU=true BUILD_KERNEL=true ./rpi23-gen-image.sh
28 ENABLE_CRYPTFS=true CRYPTFS_PASSWORD=changeme EXPANDROOT=false ENABLE_MINBASE=true ENABLE_REDUCE=true ENABLE_MINGPU=true BUILD_KERNEL=true ./rpi23-gen-image.sh
29 RELEASE=stretch BUILD_KERNEL=true ./rpi23-gen-image.sh
29 RELEASE=stretch BUILD_KERNEL=true ./rpi23-gen-image.sh
30 RPI_MODEL=3 ENABLE_WIRELESS=true ENABLE_MINBASE=true BUILD_KERNEL=true ./rpi23-gen-image.sh
30 RPI_MODEL=3 ENABLE_WIRELESS=true ENABLE_MINBASE=true BUILD_KERNEL=true ./rpi23-gen-image.sh
31 RELEASE=stretch RPI_MODEL=3 ENABLE_WIRELESS=true ENABLE_MINBASE=true BUILD_KERNEL=true ./rpi23-gen-image.sh
31 RELEASE=stretch RPI_MODEL=3 ENABLE_WIRELESS=true ENABLE_MINBASE=true BUILD_KERNEL=true ./rpi23-gen-image.sh
32 ```
32 ```
33
33
34 ## Configuration template files
34 ## Configuration template files
35 To avoid long lists of command-line parameters and to help to store the favourite parameter configurations the `rpi23-gen-image.sh` script supports so called configuration template files (`CONFIG_TEMPLATE`=template). These are simple text files located in the `./templates` directory that contain the list of configuration parameters that will be used. New configuration template files can be added to the `./templates` directory.
35 To avoid long lists of command-line parameters and to help to store the favourite parameter configurations the `rpi23-gen-image.sh` script supports so called configuration template files (`CONFIG_TEMPLATE`=template). These are simple text files located in the `./templates` directory that contain the list of configuration parameters that will be used. New configuration template files can be added to the `./templates` directory.
36
36
37 ##### Command-line examples:
37 ##### Command-line examples:
38 ```shell
38 ```shell
39 CONFIG_TEMPLATE=rpi3stretch ./rpi23-gen-image.sh
39 CONFIG_TEMPLATE=rpi3stretch ./rpi23-gen-image.sh
40 CONFIG_TEMPLATE=rpi2stretch ./rpi23-gen-image.sh
40 CONFIG_TEMPLATE=rpi2stretch ./rpi23-gen-image.sh
41 ```
41 ```
42
42
43 ## Supported parameters and settings
43 ## Supported parameters and settings
44 #### APT settings:
44 #### APT settings:
45 ##### `APT_SERVER`="ftp.debian.org/debian"
45 ##### `APT_SERVER`="ftp.debian.org/debian"
46 Set Debian packages server address. Choose a server from the list of Debian worldwide [mirror sites](https://www.debian.org/mirror/list). Using a nearby server will probably speed-up all required downloads within the bootstrapping process.
46 Set Debian packages server address. Choose a server from the list of Debian worldwide [mirror sites](https://www.debian.org/mirror/list). Using a nearby server will probably speed-up all required downloads within the bootstrapping process.
47
47
48 ##### `APT_PROXY`=""
48 ##### `APT_PROXY`=""
49 Set Proxy server address. Using a local Proxy-Cache like `apt-cacher-ng` will speed-up the bootstrapping process because all required Debian packages will only be downloaded from the Debian mirror site once. If `apt-cacher-ng` is running on default `http://127.0.0.1:3142` it is autodetected and you don't need to set this.
49 Set Proxy server address. Using a local Proxy-Cache like `apt-cacher-ng` will speed-up the bootstrapping process because all required Debian packages will only be downloaded from the Debian mirror site once. If `apt-cacher-ng` is running on default `http://127.0.0.1:3142` it is autodetected and you don't need to set this.
50
50
51 ##### `APT_INCLUDES`=""
51 ##### `APT_INCLUDES`=""
52 A comma separated list of additional packages to be installed by debootstrap during bootstrapping.
52 A comma separated list of additional packages to be installed by debootstrap during bootstrapping.
53
53
54 ##### `APT_INCLUDES_LATE`=""
54 ##### `APT_INCLUDES_LATE`=""
55 A comma separated list of additional packages to be installed by apt after bootstrapping and after APT sources are set up. This is useful for packages with pre-depends, which debootstrap do not handle well.
55 A comma separated list of additional packages to be installed by apt after bootstrapping and after APT sources are set up. This is useful for packages with pre-depends, which debootstrap do not handle well.
56
56
57 ---
57 ---
58
58
59 #### General system settings:
59 #### General system settings:
60 ##### `RPI_MODEL`=2
60 ##### `RPI_MODEL`=2
61 Specifiy the target Raspberry Pi hardware model. The script at this time supports the following Raspberry Pi models:
61 Specifiy the target Raspberry Pi hardware model. The script at this time supports the following Raspberry Pi models:
62 `0` = Used for Raspberry Pi 0 and Raspberry Pi 0 W
62 `0` = Used for Raspberry Pi 0 and Raspberry Pi 0 W
63 `1` = Used for Pi 1 model A and B
63 `1` = Used for Pi 1 model A and B
64 `1P` = Used for Pi 1 model B+ and A+
64 `1P` = Used for Pi 1 model B+ and A+
65 `2` = Used for Pi 2 model B
65 `2` = Used for Pi 2 model B
66 `3` = Used for Pi 3 model B
66 `3` = Used for Pi 3 model B
67 `3P` = Used for Pi 3 model B+
67 `3P` = Used for Pi 3 model B+
68 `BUILD_KERNEL`=true will automatically be set if the Raspberry Pi model `3` or `3P` is used.
68 `BUILD_KERNEL`=true will automatically be set if the Raspberry Pi model `3` or `3P` is used.
69
69
70 ##### `RELEASE`="buster"
70 ##### `RELEASE`="buster"
71 Set the desired Debian release name. The script at this time supports the bootstrapping of the Debian releases "stretch" and "buster". `BUILD_KERNEL`=true will automatically be set if the Debian releases `stretch` or `buster` are used.
71 Set the desired Debian release name. The script at this time supports the bootstrapping of the Debian releases "stretch" and "buster". `BUILD_KERNEL`=true will automatically be set if the Debian releases `stretch` or `buster` are used.
72
72
73 ##### `RELEASE_ARCH`="armhf"
73 ##### `RELEASE_ARCH`="armhf"
74 Set the desired Debian release architecture.
74 Set the desired Debian release architecture.
75
75
76 ##### `HOSTNAME`="rpi$RPI_MODEL-$RELEASE"
76 ##### `HOSTNAME`="rpi$RPI_MODEL-$RELEASE"
77 Set system host name. It's recommended that the host name is unique in the corresponding subnet.
77 Set system host name. It's recommended that the host name is unique in the corresponding subnet.
78
78
79 ##### `PASSWORD`="raspberry"
79 ##### `PASSWORD`="raspberry"
80 Set system `root` password. It's **STRONGLY** recommended that you choose a custom password.
80 Set system `root` password. It's **STRONGLY** recommended that you choose a custom password.
81
81
82 ##### `USER_PASSWORD`="raspberry"
82 ##### `USER_PASSWORD`="raspberry"
83 Set password for the created non-root user `USER_NAME`=pi. Ignored if `ENABLE_USER`=false. It's **STRONGLY** recommended that you choose a custom password.
83 Set password for the created non-root user `USER_NAME`=pi. Ignored if `ENABLE_USER`=false. It's **STRONGLY** recommended that you choose a custom password.
84
84
85 ##### `DEFLOCAL`="en_US.UTF-8"
85 ##### `DEFLOCAL`="en_US.UTF-8"
86 Set default system locale. This setting can also be changed inside the running OS using the `dpkg-reconfigure locales` command. Please note that on using this parameter the script will automatically install the required packages `locales`, `keyboard-configuration` and `console-setup`.
86 Set default system locale. This setting can also be changed inside the running OS using the `dpkg-reconfigure locales` command. Please note that on using this parameter the script will automatically install the required packages `locales`, `keyboard-configuration` and `console-setup`.
87
87
88 ##### `TIMEZONE`="Europe/Berlin"
88 ##### `TIMEZONE`="Europe/Berlin"
89 Set default system timezone. All available timezones can be found in the `/usr/share/zoneinfo/` directory. This setting can also be changed inside the running OS using the `dpkg-reconfigure tzdata` command.
89 Set default system timezone. All available timezones can be found in the `/usr/share/zoneinfo/` directory. This setting can also be changed inside the running OS using the `dpkg-reconfigure tzdata` command.
90
90
91 ##### `EXPANDROOT`=true
91 ##### `EXPANDROOT`=true
92 Expand the root partition and filesystem automatically on first boot.
92 Expand the root partition and filesystem automatically on first boot.
93
93
94 ##### `ENABLE_QEMU`=false
94 ##### `ENABLE_QEMU`=false
95 Generate kernel (`vexpress_defconfig`), file system image (`qcow2`) and DTB files that can be used for QEMU full system emulation (`vexpress-A15`). The output files are stored in the `$(pwd)/images/qemu` directory. You can find more information about running the generated image in the QEMU section of this readme file.
95 Generate kernel (`vexpress_defconfig`), file system image (`qcow2`) and DTB files that can be used for QEMU full system emulation (`vexpress-A15`). The output files are stored in the `$(pwd)/images/qemu` directory. You can find more information about running the generated image in the QEMU section of this readme file.
96
96
97 ---
97 ---
98
98
99 #### Keyboard settings:
99 #### Keyboard settings:
100 These options are used to configure keyboard layout in `/etc/default/keyboard` for console and Xorg. These settings can also be changed inside the running OS using the `dpkg-reconfigure keyboard-configuration` command.
100 These options are used to configure keyboard layout in `/etc/default/keyboard` for console and Xorg. These settings can also be changed inside the running OS using the `dpkg-reconfigure keyboard-configuration` command.
101
101
102 ##### `XKB_MODEL`=""
102 ##### `XKB_MODEL`=""
103 Set the name of the model of your keyboard type.
103 Set the name of the model of your keyboard type.
104
104
105 ##### `XKB_LAYOUT`=""
105 ##### `XKB_LAYOUT`=""
106 Set the supported keyboard layout(s).
106 Set the supported keyboard layout(s).
107
107
108 ##### `XKB_VARIANT`=""
108 ##### `XKB_VARIANT`=""
109 Set the supported variant(s) of the keyboard layout(s).
109 Set the supported variant(s) of the keyboard layout(s).
110
110
111 ##### `XKB_OPTIONS`=""
111 ##### `XKB_OPTIONS`=""
112 Set extra xkb configuration options.
112 Set extra xkb configuration options.
113
113
114 ---
114 ---
115
115
116 #### Networking settings (DHCP):
116 #### Networking settings (DHCP):
117 This parameter is used to set up networking auto configuration in `/etc/systemd/network/eth.network`. The default location of network configuration files in the Debian `stretch` release was changed to `/lib/systemd/network`.`
117 This parameter is used to set up networking auto configuration in `/etc/systemd/network/eth.network`. The default location of network configuration files in the Debian `stretch` release was changed to `/lib/systemd/network`.`
118
118
119 ##### `ENABLE_DHCP`=true
119 ##### `ENABLE_DHCP`=true
120 Set the system to use DHCP. This requires an DHCP server.
120 Set the system to use DHCP. This requires an DHCP server.
121
121
122 ---
122 ---
123
123
124 #### Networking settings (static):
124 #### Networking settings (static):
125 These parameters are used to set up a static networking configuration in `/etc/systemd/network/eth.network`. The following static networking parameters are only supported if `ENABLE_DHCP` was set to `false`. The default location of network configuration files in the Debian `stretch` release was changed to `/lib/systemd/network`.
125 These parameters are used to set up a static networking configuration in `/etc/systemd/network/eth.network`. The following static networking parameters are only supported if `ENABLE_DHCP` was set to `false`. The default location of network configuration files in the Debian `stretch` release was changed to `/lib/systemd/network`.
126
126
127 ##### `NET_ADDRESS`=""
127 ##### `NET_ADDRESS`=""
128 Set a static IPv4 or IPv6 address and its prefix, separated by "/", eg. "192.169.0.3/24".
128 Set a static IPv4 or IPv6 address and its prefix, separated by "/", eg. "192.169.0.3/24".
129
129
130 ##### `NET_GATEWAY`=""
130 ##### `NET_GATEWAY`=""
131 Set the IP address for the default gateway.
131 Set the IP address for the default gateway.
132
132
133 ##### `NET_DNS_1`=""
133 ##### `NET_DNS_1`=""
134 Set the IP address for the first DNS server.
134 Set the IP address for the first DNS server.
135
135
136 ##### `NET_DNS_2`=""
136 ##### `NET_DNS_2`=""
137 Set the IP address for the second DNS server.
137 Set the IP address for the second DNS server.
138
138
139 ##### `NET_DNS_DOMAINS`=""
139 ##### `NET_DNS_DOMAINS`=""
140 Set the default DNS search domains to use for non fully qualified host names.
140 Set the default DNS search domains to use for non fully qualified host names.
141
141
142 ##### `NET_NTP_1`=""
142 ##### `NET_NTP_1`=""
143 Set the IP address for the first NTP server.
143 Set the IP address for the first NTP server.
144
144
145 ##### `NET_NTP_2`=""
145 ##### `NET_NTP_2`=""
146 Set the IP address for the second NTP server.
146 Set the IP address for the second NTP server.
147
147
148 ---
148 ---
149
149
150 #### Basic system features:
150 #### Basic system features:
151 ##### `ENABLE_CONSOLE`=true
151 ##### `ENABLE_CONSOLE`=true
152 Enable serial console interface. Recommended if no monitor or keyboard is connected to the RPi2/3. In case of problems fe. if the network (auto) configuration failed - the serial console can be used to access the system.
152 Enable serial console interface. Recommended if no monitor or keyboard is connected to the RPi2/3. In case of problems fe. if the network (auto) configuration failed - the serial console can be used to access the system.
153
153
154 ##### `ENABLE_I2C`=false
154 ##### `ENABLE_I2C`=false
155 Enable I2C interface on the RPi2/3. Please check the [RPi2/3 pinout diagrams](https://elinux.org/RPi_Low-level_peripherals) to connect the right GPIO pins.
155 Enable I2C interface on the RPi2/3. Please check the [RPi2/3 pinout diagrams](https://elinux.org/RPi_Low-level_peripherals) to connect the right GPIO pins.
156
156
157 ##### `ENABLE_SPI`=false
157 ##### `ENABLE_SPI`=false
158 Enable SPI interface on the RPi2/3. Please check the [RPi2/3 pinout diagrams](https://elinux.org/RPi_Low-level_peripherals) to connect the right GPIO pins.
158 Enable SPI interface on the RPi2/3. Please check the [RPi2/3 pinout diagrams](https://elinux.org/RPi_Low-level_peripherals) to connect the right GPIO pins.
159
159
160 ##### `ENABLE_IPV6`=true
160 ##### `ENABLE_IPV6`=true
161 Enable IPv6 support. The network interface configuration is managed via systemd-networkd.
161 Enable IPv6 support. The network interface configuration is managed via systemd-networkd.
162
162
163 ##### `ENABLE_SSHD`=true
163 ##### `ENABLE_SSHD`=true
164 Install and enable OpenSSH service. The default configuration of the service doesn't allow `root` to login. Please use the user `pi` instead and `su -` or `sudo` to execute commands as root.
164 Install and enable OpenSSH service. The default configuration of the service doesn't allow `root` to login. Please use the user `pi` instead and `su -` or `sudo` to execute commands as root.
165
165
166 ##### `ENABLE_NONFREE`=false
166 ##### `ENABLE_NONFREE`=false
167 Allow the installation of non-free Debian packages that do not comply with the DFSG. This is required to install closed-source firmware binary blobs.
167 Allow the installation of non-free Debian packages that do not comply with the DFSG. This is required to install closed-source firmware binary blobs.
168
168
169 ##### `ENABLE_WIRELESS`=false
169 ##### `ENABLE_WIRELESS`=false
170 Download and install the [closed-source firmware binary blob](https://github.com/RPi-Distro/firmware-nonfree/raw/master/brcm) that is required to run the internal wireless interface of the Raspberry Pi model `3`. This parameter is ignored if the specified `RPI_MODEL` is not `3`.
170 Download and install the [closed-source firmware binary blob](https://github.com/RPi-Distro/firmware-nonfree/raw/master/brcm) that is required to run the internal wireless interface of the Raspberry Pi model `3`. This parameter is ignored if the specified `RPI_MODEL` is not `3`.
171
171
172 ##### `ENABLE_RSYSLOG`=true
172 ##### `ENABLE_RSYSLOG`=true
173 If set to false, disable and uninstall rsyslog (so logs will be available only
173 If set to false, disable and uninstall rsyslog (so logs will be available only
174 in journal files)
174 in journal files)
175
175
176 ##### `ENABLE_SOUND`=true
176 ##### `ENABLE_SOUND`=true
177 Enable sound hardware and install Advanced Linux Sound Architecture.
177 Enable sound hardware and install Advanced Linux Sound Architecture.
178
178
179 ##### `ENABLE_HWRANDOM`=true
179 ##### `ENABLE_HWRANDOM`=true
180 Enable Hardware Random Number Generator. Strong random numbers are important for most network based communications that use encryption. It's recommended to be enabled.
180 Enable Hardware Random Number Generator. Strong random numbers are important for most network based communications that use encryption. It's recommended to be enabled.
181
181
182 ##### `ENABLE_MINGPU`=false
182 ##### `ENABLE_MINGPU`=false
183 Minimize the amount of shared memory reserved for the GPU. It doesn't seem to be possible to fully disable the GPU.
183 Minimize the amount of shared memory reserved for the GPU. It doesn't seem to be possible to fully disable the GPU.
184
184
185 ##### `ENABLE_DBUS`=true
185 ##### `ENABLE_DBUS`=true
186 Install and enable D-Bus message bus. Please note that systemd should work without D-bus but it's recommended to be enabled.
186 Install and enable D-Bus message bus. Please note that systemd should work without D-bus but it's recommended to be enabled.
187
187
188 ##### `ENABLE_XORG`=false
188 ##### `ENABLE_XORG`=false
189 Install Xorg open-source X Window System.
189 Install Xorg open-source X Window System.
190
190
191 ##### `ENABLE_WM`=""
191 ##### `ENABLE_WM`=""
192 Install a user defined window manager for the X Window System. To make sure all X related package dependencies are getting installed `ENABLE_XORG` will automatically get enabled if `ENABLE_WM` is used. The `rpi23-gen-image.sh` script has been tested with the following list of window managers: `blackbox`, `openbox`, `fluxbox`, `jwm`, `dwm`, `xfce4`, `awesome`.
192 Install a user defined window manager for the X Window System. To make sure all X related package dependencies are getting installed `ENABLE_XORG` will automatically get enabled if `ENABLE_WM` is used. The `rpi23-gen-image.sh` script has been tested with the following list of window managers: `blackbox`, `openbox`, `fluxbox`, `jwm`, `dwm`, `xfce4`, `awesome`.
193
193
194 ---
194 ---
195
195
196 #### Advanced system features:
196 #### Advanced system features:
197 ##### `ENABLE_MINBASE`=false
197 ##### `ENABLE_MINBASE`=false
198 Use debootstrap script variant `minbase` which only includes essential packages and apt. This will reduce the disk usage by about 65 MB.
198 Use debootstrap script variant `minbase` which only includes essential packages and apt. This will reduce the disk usage by about 65 MB.
199
199
200 ##### `ENABLE_REDUCE`=false
200 ##### `ENABLE_REDUCE`=false
201 Reduce the disk space usage by deleting packages and files. See `REDUCE_*` parameters for detailed information.
201 Reduce the disk space usage by deleting packages and files. See `REDUCE_*` parameters for detailed information.
202
202
203 ##### `ENABLE_UBOOT`=false
203 ##### `ENABLE_UBOOT`=false
204 Replace the default RPi2/3 second stage bootloader (bootcode.bin) with [U-Boot bootloader](https://git.denx.de/?p=u-boot.git;a=summary). U-Boot can boot images via the network using the BOOTP/TFTP protocol.
204 Replace the default RPi2/3 second stage bootloader (bootcode.bin) with [U-Boot bootloader](https://git.denx.de/?p=u-boot.git;a=summary). U-Boot can boot images via the network using the BOOTP/TFTP protocol.
205
205
206 ##### `UBOOTSRC_DIR`=""
206 ##### `UBOOTSRC_DIR`=""
207 Path to a directory (`u-boot`) of [U-Boot bootloader sources](https://git.denx.de/?p=u-boot.git;a=summary) that will be copied, configured, build and installed inside the chroot.
207 Path to a directory (`u-boot`) of [U-Boot bootloader sources](https://git.denx.de/?p=u-boot.git;a=summary) that will be copied, configured, build and installed inside the chroot.
208
208
209 ##### `ENABLE_FBTURBO`=false
209 ##### `ENABLE_FBTURBO`=false
210 Install and enable the [hardware accelerated Xorg video driver](https://github.com/ssvb/xf86-video-fbturbo) `fbturbo`. Please note that this driver is currently limited to hardware accelerated window moving and scrolling.
210 Install and enable the [hardware accelerated Xorg video driver](https://github.com/ssvb/xf86-video-fbturbo) `fbturbo`. Please note that this driver is currently limited to hardware accelerated window moving and scrolling.
211
211
212 ##### `FBTURBOSRC_DIR`=""
212 ##### `FBTURBOSRC_DIR`=""
213 Path to a directory (`xf86-video-fbturbo`) of [hardware accelerated Xorg video driver sources](https://github.com/ssvb/xf86-video-fbturbo) that will be copied, configured, build and installed inside the chroot.
213 Path to a directory (`xf86-video-fbturbo`) of [hardware accelerated Xorg video driver sources](https://github.com/ssvb/xf86-video-fbturbo) that will be copied, configured, build and installed inside the chroot.
214
214
215 ##### `ENABLE_VIDEOCORE`=false
215 ##### `ENABLE_VIDEOCORE`=false
216 Install and enable the [Source code for ARM side libraries for interfacing to Raspberry Pi GPU](https://github.com/raspberrypi/userland) `vcgencmd`. Please note that this driver is currently limited to hardware accelerated window moving and scrolling.
216 Install and enable the [Source code for ARM side libraries for interfacing to Raspberry Pi GPU](https://github.com/raspberrypi/userland) `vcgencmd`. Please note that this driver is currently limited to hardware accelerated window moving and scrolling.
217
217
218 ##### `VIDEOCORESRC_DIR`=""
218 ##### `VIDEOCORESRC_DIR`=""
219 Path to a directory (`userland`) of [Source code for ARM side libraries for interfacing to Raspberry Pi GPU](https://github.com/raspberrypi/userland) that will be copied, configured, build and installed inside the chroot.
219 Path to a directory (`userland`) of [Source code for ARM side libraries for interfacing to Raspberry Pi GPU](https://github.com/raspberrypi/userland) that will be copied, configured, build and installed inside the chroot.
220
220
221 ##### `ENABLE_IPTABLES`=false
221 ##### `ENABLE_IPTABLES`=false
222 Enable iptables IPv4/IPv6 firewall. Simplified ruleset: Allow all outgoing connections. Block all incoming connections except to OpenSSH service.
222 Enable iptables IPv4/IPv6 firewall. Simplified ruleset: Allow all outgoing connections. Block all incoming connections except to OpenSSH service.
223
223
224 ##### `ENABLE_USER`=true
224 ##### `ENABLE_USER`=true
225 Create non-root user with password `USER_PASSWORD`=raspberry. Unless overridden with `USER_NAME`=user, username will be `pi`.
225 Create non-root user with password `USER_PASSWORD`=raspberry. Unless overridden with `USER_NAME`=user, username will be `pi`.
226
226
227 ##### `USER_NAME`=pi
227 ##### `USER_NAME`=pi
228 Non-root user to create. Ignored if `ENABLE_USER`=false
228 Non-root user to create. Ignored if `ENABLE_USER`=false
229
229
230 ##### `ENABLE_ROOT`=false
230 ##### `ENABLE_ROOT`=false
231 Set root user password so root login will be enabled
231 Set root user password so root login will be enabled
232
232
233 ##### `ENABLE_HARDNET`=false
233 ##### `ENABLE_HARDNET`=false
234 Enable IPv4/IPv6 network stack hardening settings.
234 Enable IPv4/IPv6 network stack hardening settings.
235
235
236 ##### `ENABLE_SPLITFS`=false
236 ##### `ENABLE_SPLITFS`=false
237 Enable having root partition on an USB drive by creating two image files: one for the `/boot/firmware` mount point, and another for `/`.
237 Enable having root partition on an USB drive by creating two image files: one for the `/boot/firmware` mount point, and another for `/`.
238
238
239 ##### `CHROOT_SCRIPTS`=""
239 ##### `CHROOT_SCRIPTS`=""
240 Path to a directory with scripts that should be run in the chroot before the image is finally built. Every executable file in this directory is run in lexicographical order.
240 Path to a directory with scripts that should be run in the chroot before the image is finally built. Every executable file in this directory is run in lexicographical order.
241
241
242 ##### `ENABLE_INITRAMFS`=false
242 ##### `ENABLE_INITRAMFS`=false
243 Create an initramfs that that will be loaded during the Linux startup process. `ENABLE_INITRAMFS` will automatically get enabled if `ENABLE_CRYPTFS`=true. This parameter will be ignored if `BUILD_KERNEL`=false.
243 Create an initramfs that that will be loaded during the Linux startup process. `ENABLE_INITRAMFS` will automatically get enabled if `ENABLE_CRYPTFS`=true. This parameter will be ignored if `BUILD_KERNEL`=false.
244
244
245 ##### `ENABLE_IFNAMES`=true
245 ##### `ENABLE_IFNAMES`=true
246 Enable automatic assignment of predictable, stable network interface names for all local Ethernet, WLAN interfaces. This might create complex and long interface names. This parameter is only supported if the Debian releases `stretch` or `buster` are used.
246 Enable automatic assignment of predictable, stable network interface names for all local Ethernet, WLAN interfaces. This might create complex and long interface names. This parameter is only supported if the Debian releases `stretch` or `buster` are used.
247
247
248 ##### `DISABLE_UNDERVOLT_WARNINGS`=
248 ##### `DISABLE_UNDERVOLT_WARNINGS`=
249 Disable RPi2/3 under-voltage warnings and overlays. Setting the parameter to `1` will disable the warning overlay. Setting it to `2` will additionally allow RPi2/3 turbo mode when low-voltage is present.
249 Disable RPi2/3 under-voltage warnings and overlays. Setting the parameter to `1` will disable the warning overlay. Setting it to `2` will additionally allow RPi2/3 turbo mode when low-voltage is present.
250
250
251 ---
251 ---
252
252
253 #### SSH settings:
253 #### SSH settings:
254 ##### `SSH_ENABLE_ROOT`=false
254 ##### `SSH_ENABLE_ROOT`=false
255 Enable password root login via SSH. This may be a security risk with default password, use only in trusted environments. `ENABLE_ROOT` must be set to `true`.
255 Enable password root login via SSH. This may be a security risk with default password, use only in trusted environments. `ENABLE_ROOT` must be set to `true`.
256
256
257 ##### `SSH_DISABLE_PASSWORD_AUTH`=false
257 ##### `SSH_DISABLE_PASSWORD_AUTH`=false
258 Disable password based SSH authentication. Only public key based SSH (v2) authentication will be supported.
258 Disable password based SSH authentication. Only public key based SSH (v2) authentication will be supported.
259
259
260 ##### `SSH_LIMIT_USERS`=false
260 ##### `SSH_LIMIT_USERS`=false
261 Limit the users that are allowed to login via SSH. Only allow user `USER_NAME`=pi and root if `SSH_ENABLE_ROOT`=true to login. This parameter will be ignored if `dropbear` SSH is used (`REDUCE_SSHD`=true).
261 Limit the users that are allowed to login via SSH. Only allow user `USER_NAME`=pi and root if `SSH_ENABLE_ROOT`=true to login. This parameter will be ignored if `dropbear` SSH is used (`REDUCE_SSHD`=true).
262
262
263 ##### `SSH_ROOT_PUB_KEY`=""
263 ##### `SSH_ROOT_PUB_KEY`=""
264 Add SSH (v2) public key(s) from specified file to `authorized_keys` file to enable public key based SSH (v2) authentication of user `root`. The specified file can also contain multiple SSH (v2) public keys. SSH protocol version 1 is not supported. `ENABLE_ROOT` **and** `SSH_ENABLE_ROOT` must be set to `true`.
264 Add SSH (v2) public key(s) from specified file to `authorized_keys` file to enable public key based SSH (v2) authentication of user `root`. The specified file can also contain multiple SSH (v2) public keys. SSH protocol version 1 is not supported. `ENABLE_ROOT` **and** `SSH_ENABLE_ROOT` must be set to `true`.
265
265
266 ##### `SSH_USER_PUB_KEY`=""
266 ##### `SSH_USER_PUB_KEY`=""
267 Add SSH (v2) public key(s) from specified file to `authorized_keys` file to enable public key based SSH (v2) authentication of user `USER_NAME`=pi. The specified file can also contain multiple SSH (v2) public keys. SSH protocol version 1 is not supported.
267 Add SSH (v2) public key(s) from specified file to `authorized_keys` file to enable public key based SSH (v2) authentication of user `USER_NAME`=pi. The specified file can also contain multiple SSH (v2) public keys. SSH protocol version 1 is not supported.
268
268
269 ---
269 ---
270
270
271 #### Kernel compilation:
271 #### Kernel compilation:
272 ##### `BUILD_KERNEL`=false
272 ##### `BUILD_KERNEL`=false
273 Build and install the latest RPi2/3 Linux kernel. Currently only the default RPi2/3 kernel configuration is used. `BUILD_KERNEL`=true will automatically be set if the Raspberry Pi model `3` is used.
273 Build and install the latest RPi2/3 Linux kernel. Currently only the default RPi2/3 kernel configuration is used. `BUILD_KERNEL`=true will automatically be set if the Raspberry Pi model `3` is used.
274
274
275 ##### `CROSS_COMPILE`="arm-linux-gnueabihf-"
275 ##### `CROSS_COMPILE`="arm-linux-gnueabihf-"
276 This sets the cross compile enviornment for the compiler.
276 This sets the cross compile enviornment for the compiler.
277
277
278 ##### `KERNEL_ARCH`="arm"
278 ##### `KERNEL_ARCH`="arm"
279 This sets the kernel architecture for the compiler.
279 This sets the kernel architecture for the compiler.
280
280
281 ##### `KERNEL_IMAGE`="kernel7.img"
281 ##### `KERNEL_IMAGE`="kernel7.img"
282 Name of the image file in the boot partition. If not set, `KERNEL_IMAGE` will be set to "kernel8.img" automatically if building for arm64.
282 Name of the image file in the boot partition. If not set, `KERNEL_IMAGE` will be set to "kernel8.img" automatically if building for arm64.
283
283
284 ##### `KERNEL_BRANCH`=""
284 ##### `KERNEL_BRANCH`=""
285 Name of the requested branch from the GIT location for the RPi Kernel. Default is using the current default branch from the GIT site.
285 Name of the requested branch from the GIT location for the RPi Kernel. Default is using the current default branch from the GIT site.
286
286
287 ##### `QEMU_BINARY`="/usr/bin/qemu-arm-static"
287 ##### `QEMU_BINARY`="/usr/bin/qemu-arm-static"
288 Sets the QEMU enviornment for the Debian archive. If not set, `QEMU_BINARY` will be set to "/usr/bin/qemu-aarch64-static" automatically if building for arm64.
288 Sets the QEMU enviornment for the Debian archive. If not set, `QEMU_BINARY` will be set to "/usr/bin/qemu-aarch64-static" automatically if building for arm64.
289
289
290 ##### `KERNEL_DEFCONFIG`="bcm2709_defconfig"
290 ##### `KERNEL_DEFCONFIG`="bcm2709_defconfig"
291 Sets the default config for kernel compiling. If not set, `KERNEL_DEFCONFIG` will be set to "bcmrpi3\_defconfig" automatically if building for arm64.
291 Sets the default config for kernel compiling. If not set, `KERNEL_DEFCONFIG` will be set to "bcmrpi3\_defconfig" automatically if building for arm64.
292
292
293 ##### `KERNEL_REDUCE`=false
293 ##### `KERNEL_REDUCE`=false
294 Reduce the size of the generated kernel by removing unwanted device, network and filesystem drivers (experimental).
294 Reduce the size of the generated kernel by removing unwanted device, network and filesystem drivers (experimental).
295
295
296 ##### `KERNEL_THREADS`=1
296 ##### `KERNEL_THREADS`=1
297 Number of parallel kernel building threads. If the parameter is left untouched the script will automatically determine the number of CPU cores to set the number of parallel threads to speed the kernel compilation.
297 Number of parallel kernel building threads. If the parameter is left untouched the script will automatically determine the number of CPU cores to set the number of parallel threads to speed the kernel compilation.
298
298
299 ##### `KERNEL_HEADERS`=true
299 ##### `KERNEL_HEADERS`=true
300 Install kernel headers with built kernel.
300 Install kernel headers with built kernel.
301
301
302 ##### `KERNEL_MENUCONFIG`=false
302 ##### `KERNEL_MENUCONFIG`=false
303 Start `make menuconfig` interactive menu-driven kernel configuration. The script will continue after `make menuconfig` was terminated.
303 Start `make menuconfig` interactive menu-driven kernel configuration. The script will continue after `make menuconfig` was terminated.
304
304
305 ##### `KERNEL_OLDDEFCONFIG`=false
305 ##### `KERNEL_OLDDEFCONFIG`=false
306 Run `make olddefconfig` to automatically set all new kernel configuration options to their recommended default values.
306 Run `make olddefconfig` to automatically set all new kernel configuration options to their recommended default values.
307
307
308 ##### `KERNEL_CCACHE`=false
308 ##### `KERNEL_CCACHE`=false
309 Compile the kernel using ccache. This speeds up kernel recompilation by caching previous compilations and detecting when the same compilation is being done again.
309 Compile the kernel using ccache. This speeds up kernel recompilation by caching previous compilations and detecting when the same compilation is being done again.
310
310
311 ##### `KERNEL_REMOVESRC`=true
311 ##### `KERNEL_REMOVESRC`=true
312 Remove all kernel sources from the generated OS image after it was built and installed.
312 Remove all kernel sources from the generated OS image after it was built and installed.
313
313
314 ##### `KERNELSRC_DIR`=""
314 ##### `KERNELSRC_DIR`=""
315 Path to a directory (`linux`) of [RaspberryPi Linux kernel sources](https://github.com/raspberrypi/linux) that will be copied, configured, build and installed inside the chroot.
315 Path to a directory (`linux`) of [RaspberryPi Linux kernel sources](https://github.com/raspberrypi/linux) that will be copied, configured, build and installed inside the chroot.
316
316
317 ##### `KERNELSRC_CLEAN`=false
317 ##### `KERNELSRC_CLEAN`=false
318 Clean the existing kernel sources directory `KERNELSRC_DIR` (using `make mrproper`) after it was copied to the chroot and before the compilation of the kernel has started. This parameter will be ignored if no `KERNELSRC_DIR` was specified or if `KERNELSRC_PREBUILT`=true.
318 Clean the existing kernel sources directory `KERNELSRC_DIR` (using `make mrproper`) after it was copied to the chroot and before the compilation of the kernel has started. This parameter will be ignored if no `KERNELSRC_DIR` was specified or if `KERNELSRC_PREBUILT`=true.
319
319
320 ##### `KERNELSRC_CONFIG`=true
320 ##### `KERNELSRC_CONFIG`=true
321 Run `make bcm2709_defconfig` (and optional `make menuconfig`) to configure the kernel sources before building. This parameter is automatically set to `true` if no existing kernel sources directory was specified using `KERNELSRC_DIR`. This parameter is ignored if `KERNELSRC_PREBUILT`=true.
321 Run `make bcm2709_defconfig` (and optional `make menuconfig`) to configure the kernel sources before building. This parameter is automatically set to `true` if no existing kernel sources directory was specified using `KERNELSRC_DIR`. This parameter is ignored if `KERNELSRC_PREBUILT`=true.
322
322
323 ##### `KERNELSRC_USRCONFIG`=""
323 ##### `KERNELSRC_USRCONFIG`=""
324 Copy own config file to kernel `.config`. If `KERNEL_MENUCONFIG`=true then running after copy.
324 Copy own config file to kernel `.config`. If `KERNEL_MENUCONFIG`=true then running after copy.
325
325
326 ##### `KERNELSRC_PREBUILT`=false
326 ##### `KERNELSRC_PREBUILT`=false
327 With this parameter set to true the script expects the existing kernel sources directory to be already successfully cross-compiled. The parameters `KERNELSRC_CLEAN`, `KERNELSRC_CONFIG`, `KERNELSRC_USRCONFIG` and `KERNEL_MENUCONFIG` are ignored and no kernel compilation tasks are performed.
327 With this parameter set to true the script expects the existing kernel sources directory to be already successfully cross-compiled. The parameters `KERNELSRC_CLEAN`, `KERNELSRC_CONFIG`, `KERNELSRC_USRCONFIG` and `KERNEL_MENUCONFIG` are ignored and no kernel compilation tasks are performed.
328
328
329 ##### `RPI_FIRMWARE_DIR`=""
329 ##### `RPI_FIRMWARE_DIR`=""
330 The directory (`firmware`) containing a local copy of the firmware from the [RaspberryPi firmware project](https://github.com/raspberrypi/firmware). Default is to download the latest firmware directly from the project.
330 The directory (`firmware`) containing a local copy of the firmware from the [RaspberryPi firmware project](https://github.com/raspberrypi/firmware). Default is to download the latest firmware directly from the project.
331
331
332 ##### `KERNEL_NF`=false
332 ##### `KERNEL_NF`=false
333 Enable Netfilter modules as kernel modules
333 Enable Netfilter modules as kernel modules
334
334
335 ##### `KERNEL_VIRT`=false
335 ##### `KERNEL_VIRT`=false
336 Enable Kernel KVM support (/dev/kvm)
336 Enable Kernel KVM support (/dev/kvm)
337
337
338 ##### `KERNEL_ZSWAP`=false
338 ##### `KERNEL_ZSWAP`=false
339 Enable Kernel Zswap support. Best use on high RAM load and mediocre CPU load usecases
339 Enable Kernel Zswap support. Best use on high RAM load and mediocre CPU load usecases
340
340
341 ##### `KERNEL_BPF`=true
341 ##### `KERNEL_BPF`=true
342 Allow attaching eBPF programs to a cgroup using the bpf syscall (CONFIG_BPF_SYSCALL CONFIG_CGROUP_BPF) [systemd compilations about it - File /lib/systemd/system/systemd-journald.server:36 configures an IP firewall (IPAddressDeny=all), but the local system does not support BPF/cgroup based firewalls]
342 Allow attaching eBPF programs to a cgroup using the bpf syscall (CONFIG_BPF_SYSCALL CONFIG_CGROUP_BPF) [systemd compilations about it - File /lib/systemd/system/systemd-journald.server:36 configures an IP firewall (IPAddressDeny=all), but the local system does not support BPF/cgroup based firewalls]
343
343
344 ---
344 ---
345
345
346 #### Reduce disk usage:
346 #### Reduce disk usage:
347 The following list of parameters is ignored if `ENABLE_REDUCE`=false.
347 The following list of parameters is ignored if `ENABLE_REDUCE`=false.
348
348
349 ##### `REDUCE_APT`=true
349 ##### `REDUCE_APT`=true
350 Configure APT to use compressed package repository lists and no package caching files.
350 Configure APT to use compressed package repository lists and no package caching files.
351
351
352 ##### `REDUCE_DOC`=true
352 ##### `REDUCE_DOC`=true
353 Remove all doc files (harsh). Configure APT to not include doc files on future `apt-get` package installations.
353 Remove all doc files (harsh). Configure APT to not include doc files on future `apt-get` package installations.
354
354
355 ##### `REDUCE_MAN`=true
355 ##### `REDUCE_MAN`=true
356 Remove all man pages and info files (harsh). Configure APT to not include man pages on future `apt-get` package installations.
356 Remove all man pages and info files (harsh). Configure APT to not include man pages on future `apt-get` package installations.
357
357
358 ##### `REDUCE_VIM`=false
358 ##### `REDUCE_VIM`=false
359 Replace `vim-tiny` package by `levee` a tiny vim clone.
359 Replace `vim-tiny` package by `levee` a tiny vim clone.
360
360
361 ##### `REDUCE_BASH`=false
361 ##### `REDUCE_BASH`=false
362 Remove `bash` package and switch to `dash` shell (experimental).
362 Remove `bash` package and switch to `dash` shell (experimental).
363
363
364 ##### `REDUCE_HWDB`=true
364 ##### `REDUCE_HWDB`=true
365 Remove PCI related hwdb files (experimental).
365 Remove PCI related hwdb files (experimental).
366
366
367 ##### `REDUCE_SSHD`=true
367 ##### `REDUCE_SSHD`=true
368 Replace `openssh-server` with `dropbear`.
368 Replace `openssh-server` with `dropbear`.
369
369
370 ##### `REDUCE_LOCALE`=true
370 ##### `REDUCE_LOCALE`=true
371 Remove all `locale` translation files.
371 Remove all `locale` translation files.
372
372
373 ---
373 ---
374
374
375 #### Encrypted root partition:
375 #### Encrypted root partition:
376 ##### `ENABLE_CRYPTFS`=false
376 ##### `ENABLE_CRYPTFS`=false
377 Enable full system encryption with dm-crypt. Setup a fully LUKS encrypted root partition (aes-xts-plain64:sha512) and generate required initramfs. The /boot directory will not be encrypted. This parameter will be ignored if `BUILD_KERNEL`=false. `ENABLE_CRYPTFS` is experimental. SSH-to-initramfs is currently not supported but will be soon - feel free to help.
377 Enable full system encryption with dm-crypt. Setup a fully LUKS encrypted root partition (aes-xts-plain64:sha512) and generate required initramfs. The /boot directory will not be encrypted. This parameter will be ignored if `BUILD_KERNEL`=false. `ENABLE_CRYPTFS` is experimental. SSH-to-initramfs is currently not supported but will be soon - feel free to help.
378
378
379 ##### `CRYPTFS_PASSWORD`=""
379 ##### `CRYPTFS_PASSWORD`=""
380 Set password of the encrypted root partition. This parameter is mandatory if `ENABLE_CRYPTFS`=true.
380 Set password of the encrypted root partition. This parameter is mandatory if `ENABLE_CRYPTFS`=true.
381
381
382 ##### `CRYPTFS_MAPPING`="secure"
382 ##### `CRYPTFS_MAPPING`="secure"
383 Set name of dm-crypt managed device-mapper mapping.
383 Set name of dm-crypt managed device-mapper mapping.
384
384
385 ##### `CRYPTFS_CIPHER`="aes-xts-plain64:sha512"
385 ##### `CRYPTFS_CIPHER`="aes-xts-plain64:sha512"
386 Set cipher specification string. `aes-xts*` ciphers are strongly recommended.
386 Set cipher specification string. `aes-xts*` ciphers are strongly recommended.
387
387
388 ##### `CRYPTFS_XTSKEYSIZE`=512
388 ##### `CRYPTFS_XTSKEYSIZE`=512
389 Sets key size in bits. The argument has to be a multiple of 8.
389 Sets key size in bits. The argument has to be a multiple of 8.
390
390
391 ---
391 ---
392
392
393 #### Build settings:
393 #### Build settings:
394 ##### `BASEDIR`=$(pwd)/images/${RELEASE}
394 ##### `BASEDIR`=$(pwd)/images/${RELEASE}
395 Set a path to a working directory used by the script to generate an image.
395 Set a path to a working directory used by the script to generate an image.
396
396
397 ##### `IMAGE_NAME`=${BASEDIR}/${DATE}-${KERNEL_ARCH}-${KERNEL_BRANCH}-rpi${RPI_MODEL}-${RELEASE}-${RELEASE_ARCH}
397 ##### `IMAGE_NAME`=${BASEDIR}/${DATE}-${KERNEL_ARCH}-${KERNEL_BRANCH}-rpi${RPI_MODEL}-${RELEASE}-${RELEASE_ARCH}
398 Set a filename for the output file(s). Note: the script will create $IMAGE_NAME.img if `ENABLE_SPLITFS`=false or $IMAGE_NAME-frmw.img and $IMAGE_NAME-root.img if `ENABLE_SPLITFS`=true. Note 2: If the KERNEL_BRANCH is not set, the word "CURRENT" is used.
398 Set a filename for the output file(s). Note: the script will create $IMAGE_NAME.img if `ENABLE_SPLITFS`=false or $IMAGE_NAME-frmw.img and $IMAGE_NAME-root.img if `ENABLE_SPLITFS`=true. Note 2: If the KERNEL_BRANCH is not set, the word "CURRENT" is used.
399
399
400 ## Understanding the script
400 ## Understanding the script
401 The functions of this script that are required for the different stages of the bootstrapping are split up into single files located inside the `bootstrap.d` directory. During the bootstrapping every script in this directory gets executed in lexicographical order:
401 The functions of this script that are required for the different stages of the bootstrapping are split up into single files located inside the `bootstrap.d` directory. During the bootstrapping every script in this directory gets executed in lexicographical order:
402
402
403 | Script | Description |
403 | Script | Description |
404 | --- | --- |
404 | --- | --- |
405 | `10-bootstrap.sh` | Debootstrap basic system |
405 | `10-bootstrap.sh` | Debootstrap basic system |
406 | `11-apt.sh` | Setup APT repositories |
406 | `11-apt.sh` | Setup APT repositories |
407 | `12-locale.sh` | Setup Locales and keyboard settings |
407 | `12-locale.sh` | Setup Locales and keyboard settings |
408 | `13-kernel.sh` | Build and install RPi2/3 Kernel |
408 | `13-kernel.sh` | Build and install RPi2/3 Kernel |
409 | `14-fstab.sh` | Setup fstab and initramfs |
409 | `14-fstab.sh` | Setup fstab and initramfs |
410 | `15-rpi-config.sh` | Setup RPi2/3 config and cmdline |
410 | `15-rpi-config.sh` | Setup RPi2/3 config and cmdline |
411 | `20-networking.sh` | Setup Networking |
411 | `20-networking.sh` | Setup Networking |
412 | `21-firewall.sh` | Setup Firewall |
412 | `21-firewall.sh` | Setup Firewall |
413 | `30-security.sh` | Setup Users and Security settings |
413 | `30-security.sh` | Setup Users and Security settings |
414 | `31-logging.sh` | Setup Logging |
414 | `31-logging.sh` | Setup Logging |
415 | `32-sshd.sh` | Setup SSH and public keys |
415 | `32-sshd.sh` | Setup SSH and public keys |
416 | `41-uboot.sh` | Build and Setup U-Boot |
416 | `41-uboot.sh` | Build and Setup U-Boot |
417 | `42-fbturbo.sh` | Build and Setup fbturbo Xorg driver |
417 | `42-fbturbo.sh` | Build and Setup fbturbo Xorg driver |
418 | `50-firstboot.sh` | First boot actions |
418 | `50-firstboot.sh` | First boot actions |
419 | `99-reduce.sh` | Reduce the disk space usage |
419 | `99-reduce.sh` | Reduce the disk space usage |
420
420
421 All the required configuration files that will be copied to the generated OS image are located inside the `files` directory. It is not recommended to modify these configuration files manually.
421 All the required configuration files that will be copied to the generated OS image are located inside the `files` directory. It is not recommended to modify these configuration files manually.
422
422
423 | Directory | Description |
423 | Directory | Description |
424 | --- | --- |
424 | --- | --- |
425 | `apt` | APT management configuration files |
425 | `apt` | APT management configuration files |
426 | `boot` | Boot and RPi2/3 configuration files |
426 | `boot` | Boot and RPi2/3 configuration files |
427 | `dpkg` | Package Manager configuration |
427 | `dpkg` | Package Manager configuration |
428 | `etc` | Configuration files and rc scripts |
428 | `etc` | Configuration files and rc scripts |
429 | `firstboot` | Scripts that get executed on first boot |
429 | `firstboot` | Scripts that get executed on first boot |
430 | `initramfs` | Initramfs scripts |
430 | `initramfs` | Initramfs scripts |
431 | `iptables` | Firewall configuration files |
431 | `iptables` | Firewall configuration files |
432 | `locales` | Locales configuration |
432 | `locales` | Locales configuration |
433 | `modules` | Kernel Modules configuration |
433 | `modules` | Kernel Modules configuration |
434 | `mount` | Fstab configuration |
434 | `mount` | Fstab configuration |
435 | `network` | Networking configuration files |
435 | `network` | Networking configuration files |
436 | `sysctl.d` | Swapping and Network Hardening configuration |
436 | `sysctl.d` | Swapping and Network Hardening configuration |
437 | `xorg` | fbturbo Xorg driver configuration |
437 | `xorg` | fbturbo Xorg driver configuration |
438
438
439 ## Custom packages and scripts
439 ## Custom packages and scripts
440 Debian custom packages, i.e. those not in the debian repositories, can be installed by placing them in the `packages` directory. They are installed immediately after packages from the repositories are installed. Any dependencies listed in the custom packages will be downloaded automatically from the repositories. Do not list these custom packages in `APT_INCLUDES`.
440 Debian custom packages, i.e. those not in the debian repositories, can be installed by placing them in the `packages` directory. They are installed immediately after packages from the repositories are installed. Any dependencies listed in the custom packages will be downloaded automatically from the repositories. Do not list these custom packages in `APT_INCLUDES`.
441
441
442 Scripts in the custom.d directory will be executed after all other installation is complete but before the image is created.
442 Scripts in the custom.d directory will be executed after all other installation is complete but before the image is created.
443
443
444 ## Logging of the bootstrapping process
444 ## Logging of the bootstrapping process
445 All information related to the bootstrapping process and the commands executed by the `rpi23-gen-image.sh` script can easily be saved into a logfile. The common shell command `script` can be used for this purpose:
445 All information related to the bootstrapping process and the commands executed by the `rpi23-gen-image.sh` script can easily be saved into a logfile. The common shell command `script` can be used for this purpose:
446
446
447 ```shell
447 ```shell
448 script -c 'APT_SERVER=ftp.de.debian.org ./rpi23-gen-image.sh' ./build.log
448 script -c 'APT_SERVER=ftp.de.debian.org ./rpi23-gen-image.sh' ./build.log
449 ```
449 ```
450
450
451 ## Flashing the image file
451 ## Flashing the image file
452 After the image file was successfully created by the `rpi23-gen-image.sh` script it can be copied to the microSD card that will be used by the RPi2/3 computer. This can be performed by using the tools `bmaptool` or `dd`. Using `bmaptool` will probably speed-up the copy process because `bmaptool` copies more wisely than `dd`.
452 After the image file was successfully created by the `rpi23-gen-image.sh` script it can be copied to the microSD card that will be used by the RPi2/3 computer. This can be performed by using the tools `bmaptool` or `dd`. Using `bmaptool` will probably speed-up the copy process because `bmaptool` copies more wisely than `dd`.
453
453
454 ##### Flashing examples:
454 ##### Flashing examples:
455 ```shell
455 ```shell
456 bmaptool copy ./images/jessie/2017-01-23-rpi3-jessie.img /dev/mmcblk0
456 bmaptool copy ./images/buster/2017-01-23-rpi3-buster.img /dev/mmcblk0
457 dd bs=4M if=./images/jessie/2017-01-23-rpi3-jessie.img of=/dev/mmcblk0
457 dd bs=4M if=./images/buster/2017-01-23-rpi3-buster.img of=/dev/mmcblk0
458 ```
458 ```
459 If you have set `ENABLE_SPLITFS`, copy the `-frmw` image on the microSD card, then the `-root` one on the USB drive:
459 If you have set `ENABLE_SPLITFS`, copy the `-frmw` image on the microSD card, then the `-root` one on the USB drive:
460 ```shell
460 ```shell
461 bmaptool copy ./images/jessie/2017-01-23-rpi3-jessie-frmw.img /dev/mmcblk0
461 bmaptool copy ./images/buster/2017-01-23-rpi3-buster-frmw.img /dev/mmcblk0
462 bmaptool copy ./images/jessie/2017-01-23-rpi3-jessie-root.img /dev/sdc
462 bmaptool copy ./images/buster/2017-01-23-rpi3-buster-root.img /dev/sdc
463 ```
463 ```
464
464
465 ## QEMU emulation
465 ## QEMU emulation
466 Start QEMU full system emulation:
466 Start QEMU full system emulation:
467 ```shell
467 ```shell
468 qemu-system-arm -m 2048M -M vexpress-a15 -cpu cortex-a15 -kernel kernel7.img -no-reboot -dtb vexpress-v2p-ca15_a7.dtb -sd ${IMAGE_NAME}.qcow2 -append "root=/dev/mmcblk0p2 rw rootfstype=ext4 console=tty1"
468 qemu-system-arm -m 2048M -M vexpress-a15 -cpu cortex-a15 -kernel kernel7.img -no-reboot -dtb vexpress-v2p-ca15_a7.dtb -sd ${IMAGE_NAME}.qcow2 -append "root=/dev/mmcblk0p2 rw rootfstype=ext4 console=tty1"
469 ```
469 ```
470
470
471 Start QEMU full system emulation and output to console:
471 Start QEMU full system emulation and output to console:
472 ```shell
472 ```shell
473 qemu-system-arm -m 2048M -M vexpress-a15 -cpu cortex-a15 -kernel kernel7.img -no-reboot -dtb vexpress-v2p-ca15_a7.dtb -sd ${IMAGE_NAME}.qcow2 -append "root=/dev/mmcblk0p2 rw rootfstype=ext4 console=ttyAMA0,115200 init=/bin/systemd" -serial stdio
473 qemu-system-arm -m 2048M -M vexpress-a15 -cpu cortex-a15 -kernel kernel7.img -no-reboot -dtb vexpress-v2p-ca15_a7.dtb -sd ${IMAGE_NAME}.qcow2 -append "root=/dev/mmcblk0p2 rw rootfstype=ext4 console=ttyAMA0,115200 init=/bin/systemd" -serial stdio
474 ```
474 ```
475
475
476 Start QEMU full system emulation with SMP and output to console:
476 Start QEMU full system emulation with SMP and output to console:
477 ```shell
477 ```shell
478 qemu-system-arm -m 2048M -M vexpress-a15 -cpu cortex-a15 -smp cpus=2,maxcpus=2 -kernel kernel7.img -no-reboot -dtb vexpress-v2p-ca15_a7.dtb -sd ${IMAGE_NAME}.qcow2 -append "root=/dev/mmcblk0p2 rw rootfstype=ext4 console=ttyAMA0,115200 init=/bin/systemd" -serial stdio
478 qemu-system-arm -m 2048M -M vexpress-a15 -cpu cortex-a15 -smp cpus=2,maxcpus=2 -kernel kernel7.img -no-reboot -dtb vexpress-v2p-ca15_a7.dtb -sd ${IMAGE_NAME}.qcow2 -append "root=/dev/mmcblk0p2 rw rootfstype=ext4 console=ttyAMA0,115200 init=/bin/systemd" -serial stdio
479 ```
479 ```
480
480
481 Start QEMU full system emulation with cryptfs, initramfs and output to console:
481 Start QEMU full system emulation with cryptfs, initramfs and output to console:
482 ```shell
482 ```shell
483 qemu-system-arm -m 2048M -M vexpress-a15 -cpu cortex-a15 -kernel kernel7.img -no-reboot -dtb vexpress-v2p-ca15_a7.dtb -sd ${IMAGE_NAME}.qcow2 -initrd "initramfs-${KERNEL_VERSION}" -append "root=/dev/mapper/secure cryptdevice=/dev/mmcblk0p2:secure rw rootfstype=ext4 console=ttyAMA0,115200 init=/bin/systemd" -serial stdio
483 qemu-system-arm -m 2048M -M vexpress-a15 -cpu cortex-a15 -kernel kernel7.img -no-reboot -dtb vexpress-v2p-ca15_a7.dtb -sd ${IMAGE_NAME}.qcow2 -initrd "initramfs-${KERNEL_VERSION}" -append "root=/dev/mapper/secure cryptdevice=/dev/mmcblk0p2:secure rw rootfstype=ext4 console=ttyAMA0,115200 init=/bin/systemd" -serial stdio
484 ```
484 ```
485
485
486 ## Weekly image builds
486 ## Weekly image builds
487 The image files are provided by JRWR'S I/O PORT and are built once a Sunday at midnight UTC!
487 The image files are provided by JRWR'S I/O PORT and are built once a Sunday at midnight UTC!
488 * [Debian Stretch Raspberry Pi2/3 Weekly Image Builds](https://jrwr.io/doku.php?id=projects:debianpi)
488 * [Debian Stretch Raspberry Pi2/3 Weekly Image Builds](https://jrwr.io/doku.php?id=projects:debianpi)
489
489
490 ## External links and references
490 ## External links and references
491 * [Debian worldwide mirror sites](https://www.debian.org/mirror/list)
491 * [Debian worldwide mirror sites](https://www.debian.org/mirror/list)
492 * [Debian Raspberry Pi 2 Wiki](https://wiki.debian.org/RaspberryPi2)
492 * [Debian Raspberry Pi 2 Wiki](https://wiki.debian.org/RaspberryPi2)
493 * [Debian CrossToolchains Wiki](https://wiki.debian.org/CrossToolchains)
493 * [Debian CrossToolchains Wiki](https://wiki.debian.org/CrossToolchains)
494 * [Official Raspberry Pi Firmware on github](https://github.com/raspberrypi/firmware)
494 * [Official Raspberry Pi Firmware on github](https://github.com/raspberrypi/firmware)
495 * [Official Raspberry Pi Kernel on github](https://github.com/raspberrypi/linux)
495 * [Official Raspberry Pi Kernel on github](https://github.com/raspberrypi/linux)
496 * [U-BOOT git repository](https://git.denx.de/?p=u-boot.git;a=summary)
496 * [U-BOOT git repository](https://git.denx.de/?p=u-boot.git;a=summary)
497 * [Xorg DDX driver fbturbo](https://github.com/ssvb/xf86-video-fbturbo)
497 * [Xorg DDX driver fbturbo](https://github.com/ssvb/xf86-video-fbturbo)
498 * [RPi3 Wireless interface firmware](https://github.com/RPi-Distro/firmware-nonfree/tree/master/brcm80211/brcm)
498 * [RPi3 Wireless interface firmware](https://github.com/RPi-Distro/firmware-nonfree/tree/master/brcm80211/brcm)
499 * [Collabora RPi2 Kernel precompiled](https://repositories.collabora.co.uk/debian/)
499 * [Collabora RPi2 Kernel precompiled](https://repositories.collabora.co.uk/debian/)
@@ -1,214 +1,209
1 #
1 #
2 # Setup RPi2/3 config and cmdline
2 # Setup RPi2/3 config and cmdline
3 #
3 #
4
4
5 # Load utility functions
5 # Load utility functions
6 . ./functions.sh
6 . ./functions.sh
7
7
8 if [ "$BUILD_KERNEL" = true ] ; then
8 if [ "$BUILD_KERNEL" = true ] ; then
9 if [ -n "$RPI_FIRMWARE_DIR" ] && [ -d "$RPI_FIRMWARE_DIR" ] ; then
9 if [ -n "$RPI_FIRMWARE_DIR" ] && [ -d "$RPI_FIRMWARE_DIR" ] ; then
10 # Install boot binaries from local directory
10 # Install boot binaries from local directory
11 cp "${RPI_FIRMWARE_DIR}"/boot/bootcode.bin "${BOOT_DIR}"/bootcode.bin
11 cp "${RPI_FIRMWARE_DIR}"/boot/bootcode.bin "${BOOT_DIR}"/bootcode.bin
12 cp "${RPI_FIRMWARE_DIR}"/boot/fixup.dat "${BOOT_DIR}"/fixup.dat
12 cp "${RPI_FIRMWARE_DIR}"/boot/fixup.dat "${BOOT_DIR}"/fixup.dat
13 cp "${RPI_FIRMWARE_DIR}"/boot/fixup_cd.dat "${BOOT_DIR}"/fixup_cd.dat
13 cp "${RPI_FIRMWARE_DIR}"/boot/fixup_cd.dat "${BOOT_DIR}"/fixup_cd.dat
14 cp "${RPI_FIRMWARE_DIR}"/boot/fixup_x.dat "${BOOT_DIR}"/fixup_x.dat
14 cp "${RPI_FIRMWARE_DIR}"/boot/fixup_x.dat "${BOOT_DIR}"/fixup_x.dat
15 cp "${RPI_FIRMWARE_DIR}"/boot/start.elf "${BOOT_DIR}"/start.elf
15 cp "${RPI_FIRMWARE_DIR}"/boot/start.elf "${BOOT_DIR}"/start.elf
16 cp "${RPI_FIRMWARE_DIR}"/boot/start_cd.elf "${BOOT_DIR}"/start_cd.elf
16 cp "${RPI_FIRMWARE_DIR}"/boot/start_cd.elf "${BOOT_DIR}"/start_cd.elf
17 cp "${RPI_FIRMWARE_DIR}"/boot/start_x.elf "${BOOT_DIR}"/start_x.elf
17 cp "${RPI_FIRMWARE_DIR}"/boot/start_x.elf "${BOOT_DIR}"/start_x.elf
18 else
18 else
19 # Create temporary directory for boot binaries
19 # Create temporary directory for boot binaries
20 temp_dir=$(as_nobody mktemp -d)
20 temp_dir=$(as_nobody mktemp -d)
21
21
22 # Install latest boot binaries from raspberry/firmware github
22 # Install latest boot binaries from raspberry/firmware github
23 as_nobody wget -q -O "${temp_dir}/bootcode.bin" "${FIRMWARE_URL}/bootcode.bin"
23 as_nobody wget -q -O "${temp_dir}/bootcode.bin" "${FIRMWARE_URL}/bootcode.bin"
24 as_nobody wget -q -O "${temp_dir}/fixup.dat" "${FIRMWARE_URL}/fixup.dat"
24 as_nobody wget -q -O "${temp_dir}/fixup.dat" "${FIRMWARE_URL}/fixup.dat"
25 as_nobody wget -q -O "${temp_dir}/fixup_cd.dat" "${FIRMWARE_URL}/fixup_cd.dat"
25 as_nobody wget -q -O "${temp_dir}/fixup_cd.dat" "${FIRMWARE_URL}/fixup_cd.dat"
26 as_nobody wget -q -O "${temp_dir}/fixup_x.dat" "${FIRMWARE_URL}/fixup_x.dat"
26 as_nobody wget -q -O "${temp_dir}/fixup_x.dat" "${FIRMWARE_URL}/fixup_x.dat"
27 as_nobody wget -q -O "${temp_dir}/start.elf" "${FIRMWARE_URL}/start.elf"
27 as_nobody wget -q -O "${temp_dir}/start.elf" "${FIRMWARE_URL}/start.elf"
28 as_nobody wget -q -O "${temp_dir}/start_cd.elf" "${FIRMWARE_URL}/start_cd.elf"
28 as_nobody wget -q -O "${temp_dir}/start_cd.elf" "${FIRMWARE_URL}/start_cd.elf"
29 as_nobody wget -q -O "${temp_dir}/start_x.elf" "${FIRMWARE_URL}/start_x.elf"
29 as_nobody wget -q -O "${temp_dir}/start_x.elf" "${FIRMWARE_URL}/start_x.elf"
30
30
31 # Move downloaded boot binaries
31 # Move downloaded boot binaries
32 mv "${temp_dir}/"* "${BOOT_DIR}/"
32 mv "${temp_dir}/"* "${BOOT_DIR}/"
33
33
34 # Remove temporary directory for boot binaries
34 # Remove temporary directory for boot binaries
35 rm -fr "${temp_dir}"
35 rm -fr "${temp_dir}"
36
36
37 # Set permissions of the boot binaries
37 # Set permissions of the boot binaries
38 chown -R root:root "${BOOT_DIR}"
38 chown -R root:root "${BOOT_DIR}"
39 chmod -R 600 "${BOOT_DIR}"
39 chmod -R 600 "${BOOT_DIR}"
40 fi
40 fi
41 fi
41 fi
42
42
43 # Setup firmware boot cmdline
43 # Setup firmware boot cmdline
44 if [ "$ENABLE_UBOOTUSB" = true ] ; then
44 if [ "$ENABLE_UBOOTUSB" = true ] ; then
45 CMDLINE="dwc_otg.lpm_enable=0 root=/dev/sda2 rootfstype=ext4 rootflags=commit=100,data=writeback elevator=deadline rootwait console=tty1"
45 CMDLINE="dwc_otg.lpm_enable=0 root=/dev/sda2 rootfstype=ext4 rootflags=commit=100,data=writeback elevator=deadline rootwait console=tty1"
46 else
46 else
47 if [ "$ENABLE_SPLITFS" = true ] ; then
47 if [ "$ENABLE_SPLITFS" = true ] ; then
48 CMDLINE="dwc_otg.lpm_enable=0 root=/dev/sda1 rootfstype=ext4 rootflags=commit=100,data=writeback elevator=deadline rootwait console=tty1"
48 CMDLINE="dwc_otg.lpm_enable=0 root=/dev/sda1 rootfstype=ext4 rootflags=commit=100,data=writeback elevator=deadline rootwait console=tty1"
49 else
49 else
50 CMDLINE="dwc_otg.lpm_enable=0 root=/dev/mmcblk0p2 rootfstype=ext4 rootflags=commit=100,data=writeback elevator=deadline rootwait console=tty1"
50 CMDLINE="dwc_otg.lpm_enable=0 root=/dev/mmcblk0p2 rootfstype=ext4 rootflags=commit=100,data=writeback elevator=deadline rootwait console=tty1"
51 fi
51 fi
52 fi
52 fi
53
53
54
54
55
55
56 # Add encrypted root partition to cmdline.txt
56 # Add encrypted root partition to cmdline.txt
57 if [ "$ENABLE_CRYPTFS" = true ] ; then
57 if [ "$ENABLE_CRYPTFS" = true ] ; then
58 if [ "$ENABLE_SPLITFS" = true ] ; then
58 if [ "$ENABLE_SPLITFS" = true ] ; then
59 CMDLINE=$(echo "${CMDLINE}" | sed "s/sda1/mapper\/${CRYPTFS_MAPPING} cryptdevice=\/dev\/sda1:${CRYPTFS_MAPPING}/")
59 CMDLINE=$(echo "${CMDLINE}" | sed "s/sda1/mapper\/${CRYPTFS_MAPPING} cryptdevice=\/dev\/sda1:${CRYPTFS_MAPPING}/")
60 else
60 else
61 if [ "$ENABLE_UBOOTUSB" = true ] ; then
61 if [ "$ENABLE_UBOOTUSB" = true ] ; then
62 CMDLINE=$(echo "${CMDLINE}" | sed "s/sda2/mapper\/${CRYPTFS_MAPPING} cryptdevice=\/dev\/sda2:${CRYPTFS_MAPPING}/")
62 CMDLINE=$(echo "${CMDLINE}" | sed "s/sda2/mapper\/${CRYPTFS_MAPPING} cryptdevice=\/dev\/sda2:${CRYPTFS_MAPPING}/")
63 else
63 else
64 CMDLINE=$(echo "${CMDLINE}" | sed "s/mmcblk0p2/mapper\/${CRYPTFS_MAPPING} cryptdevice=\/dev\/mmcblk0p2:${CRYPTFS_MAPPING}/")
64 CMDLINE=$(echo "${CMDLINE}" | sed "s/mmcblk0p2/mapper\/${CRYPTFS_MAPPING} cryptdevice=\/dev\/mmcblk0p2:${CRYPTFS_MAPPING}/")
65 fi
65 fi
66 fi
66 fi
67 fi
67 fi
68
68
69 # Add serial console support
69 # Add serial console support
70 if [ "$ENABLE_CONSOLE" = true ] ; then
70 if [ "$ENABLE_CONSOLE" = true ] ; then
71 CMDLINE="${CMDLINE} console=ttyAMA0,115200 kgdboc=ttyAMA0,115200"
71 CMDLINE="${CMDLINE} console=ttyAMA0,115200 kgdboc=ttyAMA0,115200"
72 fi
72 fi
73
73
74 # Remove IPv6 networking support
74 # Remove IPv6 networking support
75 if [ "$ENABLE_IPV6" = false ] ; then
75 if [ "$ENABLE_IPV6" = false ] ; then
76 CMDLINE="${CMDLINE} ipv6.disable=1"
76 CMDLINE="${CMDLINE} ipv6.disable=1"
77 fi
77 fi
78
78
79 # Automatically assign predictable network interface names
79 # Automatically assign predictable network interface names
80 if [ "$ENABLE_IFNAMES" = false ] ; then
80 if [ "$ENABLE_IFNAMES" = false ] ; then
81 CMDLINE="${CMDLINE} net.ifnames=0"
81 CMDLINE="${CMDLINE} net.ifnames=0"
82 else
82 else
83 CMDLINE="${CMDLINE} net.ifnames=1"
83 CMDLINE="${CMDLINE} net.ifnames=1"
84 fi
84 fi
85
85
86 # Set init to systemd if required by Debian release
87 if [ "$RELEASE" = "stretch" ] || [ "$RELEASE" = "buster" ] ; then
88 CMDLINE="${CMDLINE} init=/bin/systemd"
89 fi
90
91 # Install firmware boot cmdline
86 # Install firmware boot cmdline
92 echo "${CMDLINE}" > "${BOOT_DIR}/cmdline.txt"
87 echo "${CMDLINE}" > "${BOOT_DIR}/cmdline.txt"
93
88
94 # Install firmware config
89 # Install firmware config
95 install_readonly files/boot/config.txt "${BOOT_DIR}/config.txt"
90 install_readonly files/boot/config.txt "${BOOT_DIR}/config.txt"
96
91
97 # Setup minimal GPU memory allocation size: 16MB (no X)
92 # Setup minimal GPU memory allocation size: 16MB (no X)
98 if [ "$ENABLE_MINGPU" = true ] ; then
93 if [ "$ENABLE_MINGPU" = true ] ; then
99 echo "gpu_mem=16" >> "${BOOT_DIR}/config.txt"
94 echo "gpu_mem=16" >> "${BOOT_DIR}/config.txt"
100 fi
95 fi
101
96
102 # Setup boot with initramfs
97 # Setup boot with initramfs
103 if [ "$ENABLE_INITRAMFS" = true ] ; then
98 if [ "$ENABLE_INITRAMFS" = true ] ; then
104 echo "initramfs initramfs-${KERNEL_VERSION} followkernel" >> "${BOOT_DIR}/config.txt"
99 echo "initramfs initramfs-${KERNEL_VERSION} followkernel" >> "${BOOT_DIR}/config.txt"
105 fi
100 fi
106
101
107 # Disable RPi3 Bluetooth and restore ttyAMA0 serial device
102 # Disable RPi3 Bluetooth and restore ttyAMA0 serial device
108 if [ "$RPI_MODEL" = 3 ] || [ "$RPI_MODEL" = 3P ] || [ "$RPI_MODEL" = 3P ]; then
103 if [ "$RPI_MODEL" = 3 ] || [ "$RPI_MODEL" = 3P ] || [ "$RPI_MODEL" = 3P ]; then
109 if [ "$ENABLE_CONSOLE" = true ] && [ "$ENABLE_UBOOT" = false ] ; then
104 if [ "$ENABLE_CONSOLE" = true ] && [ "$ENABLE_UBOOT" = false ] ; then
110 echo "dtoverlay=pi3-disable-bt" >> "${BOOT_DIR}/config.txt"
105 echo "dtoverlay=pi3-disable-bt" >> "${BOOT_DIR}/config.txt"
111 echo "enable_uart=1" >> "${BOOT_DIR}/config.txt"
106 echo "enable_uart=1" >> "${BOOT_DIR}/config.txt"
112 else
107 else
113 # Create temporary directory for Bluetooth sources
108 # Create temporary directory for Bluetooth sources
114 temp_dir=$(as_nobody mktemp -d)
109 temp_dir=$(as_nobody mktemp -d)
115
110
116 # Fetch Bluetooth sources
111 # Fetch Bluetooth sources
117 as_nobody git -C "${temp_dir}" clone "${BLUETOOTH_URL}"
112 as_nobody git -C "${temp_dir}" clone "${BLUETOOTH_URL}"
118
113
119 # Copy downloaded sources
114 # Copy downloaded sources
120 mv "${temp_dir}/pi-bluetooth" "${R}/tmp/"
115 mv "${temp_dir}/pi-bluetooth" "${R}/tmp/"
121
116
122 # Raspberry-sys-mod package for /dev/serial device needed by bluetooth service
117 # Raspberry-sys-mod package for /dev/serial device needed by bluetooth service
123 wget -O "${R}/tmp/pi-bluetooth/99-com.rules" https://raw.githubusercontent.com/RPi-Distro/raspberrypi-sys-mods/master/etc.armhf/udev/rules.d/99-com.rules
118 wget -O "${R}/tmp/pi-bluetooth/99-com.rules" https://raw.githubusercontent.com/RPi-Distro/raspberrypi-sys-mods/master/etc.armhf/udev/rules.d/99-com.rules
124
119
125 # Bluetooth firmware from arch aur https://aur.archlinux.org/packages/pi-bluetooth/
120 # Bluetooth firmware from arch aur https://aur.archlinux.org/packages/pi-bluetooth/
126 wget -O "${R}/tmp/pi-bluetooth/LICENCE.broadcom_bcm43xx" https://aur.archlinux.org/cgit/aur.git/plain/LICENCE.broadcom_bcm43xx?h=pi-bluetooth
121 wget -O "${R}/tmp/pi-bluetooth/LICENCE.broadcom_bcm43xx" https://aur.archlinux.org/cgit/aur.git/plain/LICENCE.broadcom_bcm43xx?h=pi-bluetooth
127 wget -O "${R}/tmp/pi-bluetooth/BCM43430A1.hcd" https://aur.archlinux.org/cgit/aur.git/plain/BCM43430A1.hcd?h=pi-bluetooth
122 wget -O "${R}/tmp/pi-bluetooth/BCM43430A1.hcd" https://aur.archlinux.org/cgit/aur.git/plain/BCM43430A1.hcd?h=pi-bluetooth
128
123
129 # Set permissions
124 # Set permissions
130 chown -R root:root "${R}/tmp/pi-bluetooth"
125 chown -R root:root "${R}/tmp/pi-bluetooth"
131
126
132 # Install files to chroot
127 # Install files to chroot
133 # Install tools
128 # Install tools
134 install_readonly "${R}/tmp/pi-bluetooth/usr/bin/btuart" "${R}/usr/bin/btuart"
129 install_readonly "${R}/tmp/pi-bluetooth/usr/bin/btuart" "${R}/usr/bin/btuart"
135 install_readonly "${R}/tmp/pi-bluetooth/usr/bin/bthelper" "${R}/usr/bin/bthelper"
130 install_readonly "${R}/tmp/pi-bluetooth/usr/bin/bthelper" "${R}/usr/bin/bthelper"
136
131
137 # Install bluetooth udev rule
132 # Install bluetooth udev rule
138 install_readonly "${R}/tmp/pi-bluetooth/lib/udev/rules.d/90-pi-bluetooth.rules" "${LIB_DIR}/udev/rules.d/90-pi-bluetooth.rules"
133 install_readonly "${R}/tmp/pi-bluetooth/lib/udev/rules.d/90-pi-bluetooth.rules" "${LIB_DIR}/udev/rules.d/90-pi-bluetooth.rules"
139 # aur
134 # aur
140 # install_readonly "${R}/tmp/pi-bluetooth/50-bluetooth-hci-auto-poweron.rules" "${ETC_DIR}/udev/rules.d/50-bluetooth-hci-auto-poweron.rules"
135 # install_readonly "${R}/tmp/pi-bluetooth/50-bluetooth-hci-auto-poweron.rules" "${ETC_DIR}/udev/rules.d/50-bluetooth-hci-auto-poweron.rules"
141
136
142 # Install Firmware Flash file and apropiate licence
137 # Install Firmware Flash file and apropiate licence
143 mkdir "${ETC_DIR}/firmware/"
138 mkdir "${ETC_DIR}/firmware/"
144
139
145 # Install firmware and licence
140 # Install firmware and licence
146 # install_readonly "${R}/tmp/pi-bluetooth/LICENCE.broadcom_bcm43xx" "${ETC_DIR}/firmware/LICENCE.broadcom_bcm43xx"
141 # install_readonly "${R}/tmp/pi-bluetooth/LICENCE.broadcom_bcm43xx" "${ETC_DIR}/firmware/LICENCE.broadcom_bcm43xx"
147 # install_readonly "${R}/tmp/pi-bluetooth/BCM43430A1.hcd" "${ETC_DIR}/firmware/BCM43430A1.hcd"
142 # install_readonly "${R}/tmp/pi-bluetooth/BCM43430A1.hcd" "${ETC_DIR}/firmware/BCM43430A1.hcd"
148 install_readonly "${R}/tmp/pi-bluetooth/LICENCE.broadcom_bcm43xx" "${ETC_DIR}/firmware/LICENCE.broadcom_bcm43xx"
143 install_readonly "${R}/tmp/pi-bluetooth/LICENCE.broadcom_bcm43xx" "${ETC_DIR}/firmware/LICENCE.broadcom_bcm43xx"
149 install_readonly "${R}/tmp/pi-bluetooth/BCM43430A1.hcd" "${ETC_DIR}/firmware/LICENCE.broadcom_bcm43xx"
144 install_readonly "${R}/tmp/pi-bluetooth/BCM43430A1.hcd" "${ETC_DIR}/firmware/LICENCE.broadcom_bcm43xx"
150
145
151 # Install systemd service for bluetooth
146 # Install systemd service for bluetooth
152 # install_readonly "${R}/tmp/pi-bluetooth/brcm43438.service" "${ETC_DIR}/systemd/system/brcm43438.service"
147 # install_readonly "${R}/tmp/pi-bluetooth/brcm43438.service" "${ETC_DIR}/systemd/system/brcm43438.service"
153 install_readonly "${R}/tmp/pi-bluetooth/debian/pi-bluetooth.bthelper@.service" "${ETC_DIR}/systemd/system/pi-bluetooth.bthelper@.service"
148 install_readonly "${R}/tmp/pi-bluetooth/debian/pi-bluetooth.bthelper@.service" "${ETC_DIR}/systemd/system/pi-bluetooth.bthelper@.service"
154 install_readonly "${R}/tmp/pi-bluetooth/debian/pi-bluetooth.hciuart.service" "${ETC_DIR}/systemd/system/pi-bluetooth.hciuart.service"
149 install_readonly "${R}/tmp/pi-bluetooth/debian/pi-bluetooth.hciuart.service" "${ETC_DIR}/systemd/system/pi-bluetooth.hciuart.service"
155
150
156
151
157 install_readonly "${R}/tmp/pi-bluetooth/99-com.rules" "${ETC_DIR}/udev/rules.d/99-com.rules"
152 install_readonly "${R}/tmp/pi-bluetooth/99-com.rules" "${ETC_DIR}/udev/rules.d/99-com.rules"
158
153
159 # Remove temporary directory
154 # Remove temporary directory
160 rm -fr "${temp_dir}"
155 rm -fr "${temp_dir}"
161
156
162 # Get /dev/serial back for compability
157 # Get /dev/serial back for compability
163
158
164
159
165 fi
160 fi
166 fi
161 fi
167
162
168 # Create firmware configuration and cmdline symlinks
163 # Create firmware configuration and cmdline symlinks
169 ln -sf firmware/config.txt "${R}/boot/config.txt"
164 ln -sf firmware/config.txt "${R}/boot/config.txt"
170 ln -sf firmware/cmdline.txt "${R}/boot/cmdline.txt"
165 ln -sf firmware/cmdline.txt "${R}/boot/cmdline.txt"
171
166
172 # Install and setup kernel modules to load at boot
167 # Install and setup kernel modules to load at boot
173 mkdir -p "${LIB_DIR}/modules-load.d/"
168 mkdir -p "${LIB_DIR}/modules-load.d/"
174 install_readonly files/modules/rpi2.conf "${LIB_DIR}/modules-load.d/rpi2.conf"
169 install_readonly files/modules/rpi2.conf "${LIB_DIR}/modules-load.d/rpi2.conf"
175
170
176 # Load hardware random module at boot
171 # Load hardware random module at boot
177 if [ "$ENABLE_HWRANDOM" = true ] && [ "$BUILD_KERNEL" = false ] ; then
172 if [ "$ENABLE_HWRANDOM" = true ] && [ "$BUILD_KERNEL" = false ] ; then
178 sed -i "s/^# bcm2708_rng/bcm2708_rng/" "${LIB_DIR}/modules-load.d/rpi2.conf"
173 sed -i "s/^# bcm2708_rng/bcm2708_rng/" "${LIB_DIR}/modules-load.d/rpi2.conf"
179 fi
174 fi
180
175
181 # Load sound module at boot
176 # Load sound module at boot
182 if [ "$ENABLE_SOUND" = true ] ; then
177 if [ "$ENABLE_SOUND" = true ] ; then
183 sed -i "s/^# snd_bcm2835/snd_bcm2835/" "${LIB_DIR}/modules-load.d/rpi2.conf"
178 sed -i "s/^# snd_bcm2835/snd_bcm2835/" "${LIB_DIR}/modules-load.d/rpi2.conf"
184 else
179 else
185 echo "dtparam=audio=off" >> "${BOOT_DIR}/config.txt"
180 echo "dtparam=audio=off" >> "${BOOT_DIR}/config.txt"
186 fi
181 fi
187
182
188 # Enable I2C interface
183 # Enable I2C interface
189 if [ "$ENABLE_I2C" = true ] ; then
184 if [ "$ENABLE_I2C" = true ] ; then
190 echo "dtparam=i2c_arm=on" >> "${BOOT_DIR}/config.txt"
185 echo "dtparam=i2c_arm=on" >> "${BOOT_DIR}/config.txt"
191 sed -i "s/^# i2c-bcm2708/i2c-bcm2708/" "${LIB_DIR}/modules-load.d/rpi2.conf"
186 sed -i "s/^# i2c-bcm2708/i2c-bcm2708/" "${LIB_DIR}/modules-load.d/rpi2.conf"
192 sed -i "s/^# i2c-dev/i2c-dev/" "${LIB_DIR}/modules-load.d/rpi2.conf"
187 sed -i "s/^# i2c-dev/i2c-dev/" "${LIB_DIR}/modules-load.d/rpi2.conf"
193 fi
188 fi
194
189
195 # Enable SPI interface
190 # Enable SPI interface
196 if [ "$ENABLE_SPI" = true ] ; then
191 if [ "$ENABLE_SPI" = true ] ; then
197 echo "dtparam=spi=on" >> "${BOOT_DIR}/config.txt"
192 echo "dtparam=spi=on" >> "${BOOT_DIR}/config.txt"
198 echo "spi-bcm2708" >> "${LIB_DIR}/modules-load.d/rpi2.conf"
193 echo "spi-bcm2708" >> "${LIB_DIR}/modules-load.d/rpi2.conf"
199 if [ "$RPI_MODEL" = 3 ] || [ "$RPI_MODEL" = 3P ]; then
194 if [ "$RPI_MODEL" = 3 ] || [ "$RPI_MODEL" = 3P ]; then
200 sed -i "s/spi-bcm2708/spi-bcm2835/" "${LIB_DIR}/modules-load.d/rpi2.conf"
195 sed -i "s/spi-bcm2708/spi-bcm2835/" "${LIB_DIR}/modules-load.d/rpi2.conf"
201 fi
196 fi
202 fi
197 fi
203
198
204 # Disable RPi2/3 under-voltage warnings
199 # Disable RPi2/3 under-voltage warnings
205 if [ -n "$DISABLE_UNDERVOLT_WARNINGS" ] ; then
200 if [ -n "$DISABLE_UNDERVOLT_WARNINGS" ] ; then
206 echo "avoid_warnings=${DISABLE_UNDERVOLT_WARNINGS}" >> "${BOOT_DIR}/config.txt"
201 echo "avoid_warnings=${DISABLE_UNDERVOLT_WARNINGS}" >> "${BOOT_DIR}/config.txt"
207 fi
202 fi
208
203
209 # Install kernel modules blacklist
204 # Install kernel modules blacklist
210 mkdir -p "${ETC_DIR}/modprobe.d/"
205 mkdir -p "${ETC_DIR}/modprobe.d/"
211 install_readonly files/modules/raspi-blacklist.conf "${ETC_DIR}/modprobe.d/raspi-blacklist.conf"
206 install_readonly files/modules/raspi-blacklist.conf "${ETC_DIR}/modprobe.d/raspi-blacklist.conf"
212
207
213 # Install sysctl.d configuration files
208 # Install sysctl.d configuration files
214 install_readonly files/sysctl.d/81-rpi-vm.conf "${ETC_DIR}/sysctl.d/81-rpi-vm.conf"
209 install_readonly files/sysctl.d/81-rpi-vm.conf "${ETC_DIR}/sysctl.d/81-rpi-vm.conf"
@@ -1,134 +1,133
1 #
1 #
2 # Setup Networking
2 # Setup Networking
3 #
3 #
4
4
5 # Load utility functions
5 # Load utility functions
6 . ./functions.sh
6 . ./functions.sh
7
7
8 # Install and setup hostname
8 # Install and setup hostname
9 install_readonly files/network/hostname "${ETC_DIR}/hostname"
9 install_readonly files/network/hostname "${ETC_DIR}/hostname"
10 sed -i "s/^rpi2-jessie/${HOSTNAME}/" "${ETC_DIR}/hostname"
10 sed -i "s/^RaspberryPI/${HOSTNAME}/" "${ETC_DIR}/hostname"
11
11
12 # Install and setup hosts
12 # Install and setup hosts
13 install_readonly files/network/hosts "${ETC_DIR}/hosts"
13 install_readonly files/network/hosts "${ETC_DIR}/hosts"
14 sed -i "s/rpi2-jessie/${HOSTNAME}/" "${ETC_DIR}/hosts"
14 sed -i "s/RaspberryPI/${HOSTNAME}/" "${ETC_DIR}/hosts"
15
15
16 # Setup hostname entry with static IP
16 # Setup hostname entry with static IP
17 if [ "$NET_ADDRESS" != "" ] ; then
17 if [ "$NET_ADDRESS" != "" ] ; then
18 NET_IP=$(echo "${NET_ADDRESS}" | cut -f 1 -d'/')
18 NET_IP=$(echo "${NET_ADDRESS}" | cut -f 1 -d'/')
19 sed -i "s/^127.0.1.1/${NET_IP}/" "${ETC_DIR}/hosts"
19 sed -i "s/^127.0.1.1/${NET_IP}/" "${ETC_DIR}/hosts"
20 fi
20 fi
21
21
22 # Remove IPv6 hosts
22 # Remove IPv6 hosts
23 if [ "$ENABLE_IPV6" = false ] ; then
23 if [ "$ENABLE_IPV6" = false ] ; then
24 sed -i -e "/::[1-9]/d" -e "/^$/d" "${ETC_DIR}/hosts"
24 sed -i -e "/::[1-9]/d" -e "/^$/d" "${ETC_DIR}/hosts"
25 fi
25 fi
26
26
27 # Install hint about network configuration
27 # Install hint about network configuration
28 install_readonly files/network/interfaces "${ETC_DIR}/network/interfaces"
28 install_readonly files/network/interfaces "${ETC_DIR}/network/interfaces"
29
29
30 # Install configuration for interface eth0
30 # Install configuration for interface eth0
31 install_readonly files/network/eth.network "${ETC_DIR}/systemd/network/eth.network"
31 install_readonly files/network/eth.network "${ETC_DIR}/systemd/network/eth.network"
32
32
33 # Install configuration for interface wl*
33 # Install configuration for interface wl*
34 install_readonly files/network/wlan.network "${ETC_DIR}/systemd/network/wlan.network"
34 install_readonly files/network/wlan.network "${ETC_DIR}/systemd/network/wlan.network"
35
35
36 #always with dhcp since wpa_supplicant integration is missing
36 #always with dhcp since wpa_supplicant integration is missing
37 sed -i -e "s/DHCP=.*/DHCP=yes/" -e "/DHCP/q" "${ETC_DIR}/systemd/network/wlan.network"
37 sed -i -e "s/DHCP=.*/DHCP=yes/" -e "/DHCP/q" "${ETC_DIR}/systemd/network/wlan.network"
38
38
39 if [ "$ENABLE_DHCP" = true ] ; then
39 if [ "$ENABLE_DHCP" = true ] ; then
40 # Enable DHCP configuration for interface eth0
40 # Enable DHCP configuration for interface eth0
41 sed -i -e "s/DHCP=.*/DHCP=yes/" -e "/DHCP/q" "${ETC_DIR}/systemd/network/eth.network"
41 sed -i -e "s/DHCP=.*/DHCP=yes/" -e "/DHCP/q" "${ETC_DIR}/systemd/network/eth.network"
42
42
43 # Set DHCP configuration to IPv4 only
43 # Set DHCP configuration to IPv4 only
44 if [ "$ENABLE_IPV6" = false ] ; then
44 if [ "$ENABLE_IPV6" = false ] ; then
45 sed -i "s/DHCP=.*/DHCP=v4/" "${ETC_DIR}/systemd/network/eth.network"
45 sed -i "s/DHCP=.*/DHCP=v4/" "${ETC_DIR}/systemd/network/eth.network"
46 fi
46 fi
47
47
48 else # ENABLE_DHCP=false
48 else # ENABLE_DHCP=false
49 # Set static network configuration for interface eth0
49 # Set static network configuration for interface eth0
50 sed -i\
50 sed -i\
51 -e "s|DHCP=.*|DHCP=no|"\
51 -e "s|DHCP=.*|DHCP=no|"\
52 -e "s|Address=\$|Address=${NET_ADDRESS}|"\
52 -e "s|Address=\$|Address=${NET_ADDRESS}|"\
53 -e "s|Gateway=\$|Gateway=${NET_GATEWAY}|"\
53 -e "s|Gateway=\$|Gateway=${NET_GATEWAY}|"\
54 -e "0,/DNS=\$/ s|DNS=\$|DNS=${NET_DNS_1}|"\
54 -e "0,/DNS=\$/ s|DNS=\$|DNS=${NET_DNS_1}|"\
55 -e "0,/DNS=\$/ s|DNS=\$|DNS=${NET_DNS_2}|"\
55 -e "0,/DNS=\$/ s|DNS=\$|DNS=${NET_DNS_2}|"\
56 -e "s|Domains=\$|Domains=${NET_DNS_DOMAINS}|"\
56 -e "s|Domains=\$|Domains=${NET_DNS_DOMAINS}|"\
57 -e "0,/NTP=\$/ s|NTP=\$|NTP=${NET_NTP_1}|"\
57 -e "0,/NTP=\$/ s|NTP=\$|NTP=${NET_NTP_1}|"\
58 -e "0,/NTP=\$/ s|NTP=\$|NTP=${NET_NTP_2}|"\
58 -e "0,/NTP=\$/ s|NTP=\$|NTP=${NET_NTP_2}|"\
59 "${ETC_DIR}/systemd/network/eth.network"
59 "${ETC_DIR}/systemd/network/eth.network"
60 fi
60 fi
61
61
62 # Remove empty settings from network configuration
62 # Remove empty settings from network configuration
63 sed -i "/.*=\$/d" "${ETC_DIR}/systemd/network/eth.network"
63 sed -i "/.*=\$/d" "${ETC_DIR}/systemd/network/eth.network"
64 # Remove empty settings from wlan configuration
64 # Remove empty settings from wlan configuration
65 sed -i "/.*=\$/d" "${ETC_DIR}/systemd/network/wlan.network"
65 sed -i "/.*=\$/d" "${ETC_DIR}/systemd/network/wlan.network"
66
66
67 # Move systemd network configuration if required by Debian release
67 # Move systemd network configuration if required by Debian release
68 if [ "$RELEASE" = "stretch" ] || [ "$RELEASE" = "buster" ] ; then
69 mv -v "${ETC_DIR}/systemd/network/eth.network" "${LIB_DIR}/systemd/network/10-eth.network"
68 mv -v "${ETC_DIR}/systemd/network/eth.network" "${LIB_DIR}/systemd/network/10-eth.network"
69 # If WLAN is enabled copy wlan configuration too
70 if [ "$ENABLE_WIRELESS" = true ] ; then
70 if [ "$ENABLE_WIRELESS" = true ] ; then
71 mv -v "${ETC_DIR}/systemd/network/wlan.network" "${LIB_DIR}/systemd/network/11-wlan.network"
71 mv -v "${ETC_DIR}/systemd/network/wlan.network" "${LIB_DIR}/systemd/network/11-wlan.network"
72 fi
72 fi
73 rm -fr "${ETC_DIR}/systemd/network"
73 rm -fr "${ETC_DIR}/systemd/network"
74 fi
75
74
76 # Enable systemd-networkd service
75 # Enable systemd-networkd service
77 chroot_exec systemctl enable systemd-networkd
76 chroot_exec systemctl enable systemd-networkd
78
77
79 # Install host.conf resolver configuration
78 # Install host.conf resolver configuration
80 install_readonly files/network/host.conf "${ETC_DIR}/host.conf"
79 install_readonly files/network/host.conf "${ETC_DIR}/host.conf"
81
80
82 # Enable network stack hardening
81 # Enable network stack hardening
83 if [ "$ENABLE_HARDNET" = true ] ; then
82 if [ "$ENABLE_HARDNET" = true ] ; then
84 # Install sysctl.d configuration files
83 # Install sysctl.d configuration files
85 install_readonly files/sysctl.d/82-rpi-net-hardening.conf "${ETC_DIR}/sysctl.d/82-rpi-net-hardening.conf"
84 install_readonly files/sysctl.d/82-rpi-net-hardening.conf "${ETC_DIR}/sysctl.d/82-rpi-net-hardening.conf"
86
85
87 # Setup resolver warnings about spoofed addresses
86 # Setup resolver warnings about spoofed addresses
88 sed -i "s/^# spoof warn/spoof warn/" "${ETC_DIR}/host.conf"
87 sed -i "s/^# spoof warn/spoof warn/" "${ETC_DIR}/host.conf"
89 fi
88 fi
90
89
91 # Enable time sync
90 # Enable time sync
92 if [ "$NET_NTP_1" != "" ] ; then
91 if [ "$NET_NTP_1" != "" ] ; then
93 chroot_exec systemctl enable systemd-timesyncd.service
92 chroot_exec systemctl enable systemd-timesyncd.service
94 fi
93 fi
95
94
96 # Download the firmware binary blob required to use the RPi3 wireless interface
95 # Download the firmware binary blob required to use the RPi3 wireless interface
97 if [ "$ENABLE_WIRELESS" = true ] ; then
96 if [ "$ENABLE_WIRELESS" = true ] ; then
98 if [ ! -d "${WLAN_FIRMWARE_DIR}" ] ; then
97 if [ ! -d "${WLAN_FIRMWARE_DIR}" ] ; then
99 mkdir -p "${WLAN_FIRMWARE_DIR}"
98 mkdir -p "${WLAN_FIRMWARE_DIR}"
100 fi
99 fi
101
100
102 # Create temporary directory for firmware binary blob
101 # Create temporary directory for firmware binary blob
103 temp_dir=$(as_nobody mktemp -d)
102 temp_dir=$(as_nobody mktemp -d)
104
103
105 # Fetch firmware binary blob for RPI3B+
104 # Fetch firmware binary blob for RPI3B+
106 if [ "$RPI_MODEL" = 3P ] ; then
105 if [ "$RPI_MODEL" = 3P ] ; then
107 as_nobody wget -q -O "${temp_dir}/brcmfmac43455-sdio.bin" "${WLAN_FIRMWARE_URL}/brcmfmac43455-sdio.bin"
106 as_nobody wget -q -O "${temp_dir}/brcmfmac43455-sdio.bin" "${WLAN_FIRMWARE_URL}/brcmfmac43455-sdio.bin"
108 as_nobody wget -q -O "${temp_dir}/brcmfmac43455-sdio.txt" "${WLAN_FIRMWARE_URL}/brcmfmac43455-sdio.txt"
107 as_nobody wget -q -O "${temp_dir}/brcmfmac43455-sdio.txt" "${WLAN_FIRMWARE_URL}/brcmfmac43455-sdio.txt"
109 as_nobody wget -q -O "${temp_dir}/brcmfmac43455-sdio.clm_blob" "${WLAN_FIRMWARE_URL}/brcmfmac43455-sdio.clm_blob"
108 as_nobody wget -q -O "${temp_dir}/brcmfmac43455-sdio.clm_blob" "${WLAN_FIRMWARE_URL}/brcmfmac43455-sdio.clm_blob"
110 elif [ "$RPI_MODEL" = 3 ] || [ "$RPI_MODEL" = 0 ] ; then
109 elif [ "$RPI_MODEL" = 3 ] || [ "$RPI_MODEL" = 0 ] ; then
111 # Fetch firmware binary blob for RPI3
110 # Fetch firmware binary blob for RPI3
112 as_nobody wget -q -O "${temp_dir}/brcmfmac43430-sdio.bin" "${WLAN_FIRMWARE_URL}/brcmfmac43430-sdio.bin"
111 as_nobody wget -q -O "${temp_dir}/brcmfmac43430-sdio.bin" "${WLAN_FIRMWARE_URL}/brcmfmac43430-sdio.bin"
113 as_nobody wget -q -O "${temp_dir}/brcmfmac43430-sdio.txt" "${WLAN_FIRMWARE_URL}/brcmfmac43430-sdio.txt"
112 as_nobody wget -q -O "${temp_dir}/brcmfmac43430-sdio.txt" "${WLAN_FIRMWARE_URL}/brcmfmac43430-sdio.txt"
114 fi
113 fi
115
114
116 # Move downloaded firmware binary blob
115 # Move downloaded firmware binary blob
117 if [ "$RPI_MODEL" = 3P ] ; then
116 if [ "$RPI_MODEL" = 3P ] ; then
118 mv "${temp_dir}/brcmfmac43455-sdio."* "${WLAN_FIRMWARE_DIR}/"
117 mv "${temp_dir}/brcmfmac43455-sdio."* "${WLAN_FIRMWARE_DIR}/"
119 elif [ "$RPI_MODEL" = 3 ] || [ "$RPI_MODEL" = 0 ] ; then
118 elif [ "$RPI_MODEL" = 3 ] || [ "$RPI_MODEL" = 0 ] ; then
120 mv "${temp_dir}/brcmfmac43430-sdio."* "${WLAN_FIRMWARE_DIR}/"
119 mv "${temp_dir}/brcmfmac43430-sdio."* "${WLAN_FIRMWARE_DIR}/"
121 fi
120 fi
122
121
123 # Remove temporary directory for firmware binary blob
122 # Remove temporary directory for firmware binary blob
124 rm -fr "${temp_dir}"
123 rm -fr "${temp_dir}"
125
124
126 # Set permissions of the firmware binary blob
125 # Set permissions of the firmware binary blob
127 if [ "$RPI_MODEL" = 3P ] ; then
126 if [ "$RPI_MODEL" = 3P ] ; then
128 chown root:root "${WLAN_FIRMWARE_DIR}/brcmfmac43455-sdio."*
127 chown root:root "${WLAN_FIRMWARE_DIR}/brcmfmac43455-sdio."*
129 chmod 600 "${WLAN_FIRMWARE_DIR}/brcmfmac43455-sdio."*
128 chmod 600 "${WLAN_FIRMWARE_DIR}/brcmfmac43455-sdio."*
130 elif [ "$RPI_MODEL" = 3 ] || [ "$RPI_MODEL" = 0 ] ; then
129 elif [ "$RPI_MODEL" = 3 ] || [ "$RPI_MODEL" = 0 ] ; then
131 chown root:root "${WLAN_FIRMWARE_DIR}/brcmfmac43430-sdio."*
130 chown root:root "${WLAN_FIRMWARE_DIR}/brcmfmac43430-sdio."*
132 chmod 600 "${WLAN_FIRMWARE_DIR}/brcmfmac43430-sdio."*
131 chmod 600 "${WLAN_FIRMWARE_DIR}/brcmfmac43430-sdio."*
133 fi
132 fi
134 fi
133 fi
@@ -1,50 +1,48
1 #
1 #
2 # Setup Firewall
2 # Setup Firewall
3 #
3 #
4
4
5 # Load utility functions
5 # Load utility functions
6 . ./functions.sh
6 . ./functions.sh
7
7
8 if [ "$ENABLE_IPTABLES" = true ] ; then
8 if [ "$ENABLE_IPTABLES" = true ] ; then
9 # Create iptables configuration directory
9 # Create iptables configuration directory
10 mkdir -p "${ETC_DIR}/iptables"
10 mkdir -p "${ETC_DIR}/iptables"
11
11
12 # make sure iptables-legacy is the used alternatives
12 # make sure iptables-legacy is the used alternatives
13 #iptables-save and -restore are slaves of iptables and thus are set accordingly
13 #iptables-save and -restore are slaves of iptables and thus are set accordingly
14 if ! [ "$RELEASE" = jessie ] ; then
15 chroot_exec update-alternatives --verbose --set iptables /usr/sbin/iptables-legacy
14 chroot_exec update-alternatives --verbose --set iptables /usr/sbin/iptables-legacy
16 fi
17
15
18 # Install iptables systemd service
16 # Install iptables systemd service
19 install_readonly files/iptables/iptables.service "${ETC_DIR}/systemd/system/iptables.service"
17 install_readonly files/iptables/iptables.service "${ETC_DIR}/systemd/system/iptables.service"
20
18
21 # Install flush-table script called by iptables service
19 # Install flush-table script called by iptables service
22 install_exec files/iptables/flush-iptables.sh "${ETC_DIR}/iptables/flush-iptables.sh"
20 install_exec files/iptables/flush-iptables.sh "${ETC_DIR}/iptables/flush-iptables.sh"
23
21
24 # Install iptables rule file
22 # Install iptables rule file
25 install_readonly files/iptables/iptables.rules "${ETC_DIR}/iptables/iptables.rules"
23 install_readonly files/iptables/iptables.rules "${ETC_DIR}/iptables/iptables.rules"
26
24
27 # Reload systemd configuration and enable iptables service
25 # Reload systemd configuration and enable iptables service
28 chroot_exec systemctl daemon-reload
26 chroot_exec systemctl daemon-reload
29 chroot_exec systemctl enable iptables.service
27 chroot_exec systemctl enable iptables.service
30
28
31 if [ "$ENABLE_IPV6" = true ] ; then
29 if [ "$ENABLE_IPV6" = true ] ; then
32 # Install ip6tables systemd service
30 # Install ip6tables systemd service
33 install_readonly files/iptables/ip6tables.service "${ETC_DIR}/systemd/system/ip6tables.service"
31 install_readonly files/iptables/ip6tables.service "${ETC_DIR}/systemd/system/ip6tables.service"
34
32
35 # Install ip6tables file
33 # Install ip6tables file
36 install_exec files/iptables/flush-ip6tables.sh "${ETC_DIR}/iptables/flush-ip6tables.sh"
34 install_exec files/iptables/flush-ip6tables.sh "${ETC_DIR}/iptables/flush-ip6tables.sh"
37
35
38 install_readonly files/iptables/ip6tables.rules "${ETC_DIR}/iptables/ip6tables.rules"
36 install_readonly files/iptables/ip6tables.rules "${ETC_DIR}/iptables/ip6tables.rules"
39
37
40 # Reload systemd configuration and enable iptables service
38 # Reload systemd configuration and enable iptables service
41 chroot_exec systemctl daemon-reload
39 chroot_exec systemctl daemon-reload
42 chroot_exec systemctl enable ip6tables.service
40 chroot_exec systemctl enable ip6tables.service
43 fi
41 fi
44
42
45 if [ "$ENABLE_SSHD" = false ] ; then
43 if [ "$ENABLE_SSHD" = false ] ; then
46 # Remove SSHD related iptables rules
44 # Remove SSHD related iptables rules
47 sed -i "/^#/! {/SSH/ s/^/# /}" "${ETC_DIR}/iptables/iptables.rules" 2> /dev/null
45 sed -i "/^#/! {/SSH/ s/^/# /}" "${ETC_DIR}/iptables/iptables.rules" 2> /dev/null
48 sed -i "/^#/! {/SSH/ s/^/# /}" "${ETC_DIR}/iptables/ip6tables.rules" 2> /dev/null
46 sed -i "/^#/! {/SSH/ s/^/# /}" "${ETC_DIR}/iptables/ip6tables.rules" 2> /dev/null
49 fi
47 fi
50 fi
48 fi
@@ -1,51 +1,47
1 #
1 #
2 # Build and Setup fbturbo Xorg driver
2 # Build and Setup fbturbo Xorg driver
3 #
3 #
4
4
5 # Load utility functions
5 # Load utility functions
6 . ./functions.sh
6 . ./functions.sh
7
7
8 if [ "$ENABLE_FBTURBO" = true ] ; then
8 if [ "$ENABLE_FBTURBO" = true ] ; then
9 # Install c/c++ build environment inside the chroot
9 # Install c/c++ build environment inside the chroot
10 chroot_install_cc
10 chroot_install_cc
11
11
12 # Copy existing fbturbo sources into chroot directory
12 # Copy existing fbturbo sources into chroot directory
13 if [ -n "$FBTURBOSRC_DIR" ] && [ -d "$FBTURBOSRC_DIR" ] ; then
13 if [ -n "$FBTURBOSRC_DIR" ] && [ -d "$FBTURBOSRC_DIR" ] ; then
14 # Copy local fbturbo sources
14 # Copy local fbturbo sources
15 cp -r "${FBTURBOSRC_DIR}" "${R}/tmp"
15 cp -r "${FBTURBOSRC_DIR}" "${R}/tmp"
16 else
16 else
17 # Create temporary directory for fbturbo sources
17 # Create temporary directory for fbturbo sources
18 temp_dir=$(as_nobody mktemp -d)
18 temp_dir=$(as_nobody mktemp -d)
19
19
20 # Fetch fbturbo sources
20 # Fetch fbturbo sources
21 as_nobody git -C "${temp_dir}" clone "${FBTURBO_URL}"
21 as_nobody git -C "${temp_dir}" clone "${FBTURBO_URL}"
22
22
23 # Move downloaded fbturbo sources
23 # Move downloaded fbturbo sources
24 mv "${temp_dir}/xf86-video-fbturbo" "${R}/tmp/"
24 mv "${temp_dir}/xf86-video-fbturbo" "${R}/tmp/"
25
25
26 # Remove temporary directory for fbturbo sources
26 # Remove temporary directory for fbturbo sources
27 rm -fr "${temp_dir}"
27 rm -fr "${temp_dir}"
28 fi
28 fi
29
29
30 # Install Xorg build dependencies
30 # Install Xorg build dependencies
31 if [ "$RELEASE" = "jessie" ] ; then
32 chroot_exec apt-get -q -y --no-install-recommends install xorg-dev xutils-dev x11proto-dri2-dev libltdl-dev libtool automake libdrm-dev
33 elif [ "$RELEASE" = "stretch" ] || [ "$RELEASE" = "buster" ] ; then
34 chroot_exec apt-get -q -y --no-install-recommends --allow-unauthenticated install xorg-dev xutils-dev x11proto-dri2-dev libltdl-dev libtool automake libdrm-dev
31 chroot_exec apt-get -q -y --no-install-recommends --allow-unauthenticated install xorg-dev xutils-dev x11proto-dri2-dev libltdl-dev libtool automake libdrm-dev
35 fi
36
32
37 # Build and install fbturbo driver inside chroot
33 # Build and install fbturbo driver inside chroot
38 chroot_exec /bin/bash -x <<'EOF'
34 chroot_exec /bin/bash -x <<'EOF'
39 cd /tmp/xf86-video-fbturbo
35 cd /tmp/xf86-video-fbturbo
40 autoreconf -vi
36 autoreconf -vi
41 ./configure --prefix=/usr
37 ./configure --prefix=/usr
42 make
38 make
43 make install
39 make install
44 EOF
40 EOF
45
41
46 # Install fbturbo driver Xorg configuration
42 # Install fbturbo driver Xorg configuration
47 install_readonly files/xorg/99-fbturbo.conf "${R}/usr/share/X11/xorg.conf.d/99-fbturbo.conf"
43 install_readonly files/xorg/99-fbturbo.conf "${R}/usr/share/X11/xorg.conf.d/99-fbturbo.conf"
48
44
49 # Remove Xorg build dependencies
45 # Remove Xorg build dependencies
50 chroot_exec apt-get -qq -y --auto-remove purge xorg-dev xutils-dev x11proto-dri2-dev libltdl-dev libtool automake libdrm-dev
46 chroot_exec apt-get -qq -y --auto-remove purge xorg-dev xutils-dev x11proto-dri2-dev libltdl-dev libtool automake libdrm-dev
51 fi
47 fi
@@ -1,85 +1,76
1 #
1 #
2 # Reduce system disk usage
2 # Reduce system disk usage
3 #
3 #
4
4
5 # Load utility functions
5 # Load utility functions
6 . ./functions.sh
6 . ./functions.sh
7
7
8 # Reduce the image size by various operations
8 # Reduce the image size by various operations
9 if [ "$ENABLE_REDUCE" = true ] ; then
9 if [ "$ENABLE_REDUCE" = true ] ; then
10 if [ "$REDUCE_APT" = true ] ; then
10 if [ "$REDUCE_APT" = true ] ; then
11 # Install dpkg configuration file
11 # Install dpkg configuration file
12 if [ "$REDUCE_DOC" = true ] || [ "$REDUCE_MAN" = true ] ; then
12 if [ "$REDUCE_DOC" = true ] || [ "$REDUCE_MAN" = true ] ; then
13 install_readonly files/dpkg/01nodoc "${ETC_DIR}/dpkg/dpkg.cfg.d/01nodoc"
13 install_readonly files/dpkg/01nodoc "${ETC_DIR}/dpkg/dpkg.cfg.d/01nodoc"
14 fi
14 fi
15
15
16 # Install APT configuration files
16 # Install APT configuration files
17 install_readonly files/apt/02nocache "${ETC_DIR}/apt/apt.conf.d/02nocache"
17 install_readonly files/apt/02nocache "${ETC_DIR}/apt/apt.conf.d/02nocache"
18 install_readonly files/apt/03compress "${ETC_DIR}/apt/apt.conf.d/03compress"
18 install_readonly files/apt/03compress "${ETC_DIR}/apt/apt.conf.d/03compress"
19 install_readonly files/apt/04norecommends "${ETC_DIR}/apt/apt.conf.d/04norecommends"
19 install_readonly files/apt/04norecommends "${ETC_DIR}/apt/apt.conf.d/04norecommends"
20
20
21 # Remove APT cache files
21 # Remove APT cache files
22 rm -fr "${R}/var/cache/apt/pkgcache.bin"
22 rm -fr "${R}/var/cache/apt/pkgcache.bin"
23 rm -fr "${R}/var/cache/apt/srcpkgcache.bin"
23 rm -fr "${R}/var/cache/apt/srcpkgcache.bin"
24 fi
24 fi
25
25
26 # Remove all doc files
26 # Remove all doc files
27 if [ "$REDUCE_DOC" = true ] ; then
27 if [ "$REDUCE_DOC" = true ] ; then
28 find "${R}/usr/share/doc" -depth -type f ! -name copyright -print0 | xargs -0 rm || true
28 find "${R}/usr/share/doc" -depth -type f ! -name copyright -print0 | xargs -0 rm || true
29 find "${R}/usr/share/doc" -empty -print0 | xargs -0 rmdir || true
29 find "${R}/usr/share/doc" -empty -print0 | xargs -0 rmdir || true
30 fi
30 fi
31
31
32 # Remove all man pages and info files
32 # Remove all man pages and info files
33 if [ "$REDUCE_MAN" = true ] ; then
33 if [ "$REDUCE_MAN" = true ] ; then
34 rm -rf "${R}/usr/share/man" "${R}/usr/share/groff" "${R}/usr/share/info" "${R}/usr/share/lintian" "${R}/usr/share/linda" "${R}/var/cache/man"
34 rm -rf "${R}/usr/share/man" "${R}/usr/share/groff" "${R}/usr/share/info" "${R}/usr/share/lintian" "${R}/usr/share/linda" "${R}/var/cache/man"
35 fi
35 fi
36
36
37 # Remove all locale translation files
37 # Remove all locale translation files
38 if [ "$REDUCE_LOCALE" = true ] ; then
38 if [ "$REDUCE_LOCALE" = true ] ; then
39 find "${R}/usr/share/locale" -mindepth 1 -maxdepth 1 ! -name 'en' -print0 | xargs -0 rm -r
39 find "${R}/usr/share/locale" -mindepth 1 -maxdepth 1 ! -name 'en' -print0 | xargs -0 rm -r
40 fi
40 fi
41
41
42 # Remove hwdb PCI device classes (experimental)
42 # Remove hwdb PCI device classes (experimental)
43 if [ "$REDUCE_HWDB" = true ] ; then
43 if [ "$REDUCE_HWDB" = true ] ; then
44 rm -fr "/lib/udev/hwdb.d/20-pci-*"
44 rm -fr "/lib/udev/hwdb.d/20-pci-*"
45 fi
45 fi
46
46
47 # Replace bash shell by dash shell (experimental)
47 # Replace bash shell by dash shell (experimental)
48 if [ "$REDUCE_BASH" = true ] ; then
48 if [ "$REDUCE_BASH" = true ] ; then
49 if [ "$RELEASE" = "stretch" ] || [ "$RELEASE" = "buster" ] ; then
49 # Purge bash and update alternatives
50 echo "Yes, do as I say!" | chroot_exec apt-get purge -qq -y --allow-remove-essential bash
50 echo "Yes, do as I say!" | chroot_exec apt-get purge -qq -y --allow-remove-essential bash
51 else
52 echo "Yes, do as I say!" | chroot_exec apt-get purge -qq -y --force-yes bash
53 fi
54
55 chroot_exec update-alternatives --install /bin/bash bash /bin/dash 100
51 chroot_exec update-alternatives --install /bin/bash bash /bin/dash 100
56 fi
52 fi
57
53
58 # Remove sound utils and libraries
54 # Remove sound utils and libraries
59 if [ "$ENABLE_SOUND" = false ] ; then
55 if [ "$ENABLE_SOUND" = false ] ; then
60 chroot_exec apt-get -qq -y purge alsa-utils libsamplerate0 libasound2 libasound2-data
56 chroot_exec apt-get -qq -y purge alsa-utils libsamplerate0 libasound2 libasound2-data
61 fi
57 fi
62
58
63 # Re-install tools for managing kernel modules
64 if [ "$RELEASE" = "jessie" ] ; then
65 chroot_exec apt-get -qq -y install module-init-tools
66 fi
67
68 # Remove GPU kernels
59 # Remove GPU kernels
69 if [ "$ENABLE_MINGPU" = true ] ; then
60 if [ "$ENABLE_MINGPU" = true ] ; then
70 rm -f "${BOOT_DIR}/start.elf"
61 rm -f "${BOOT_DIR}/start.elf"
71 rm -f "${BOOT_DIR}/fixup.dat"
62 rm -f "${BOOT_DIR}/fixup.dat"
72 rm -f "${BOOT_DIR}/start_x.elf"
63 rm -f "${BOOT_DIR}/start_x.elf"
73 rm -f "${BOOT_DIR}/fixup_x.dat"
64 rm -f "${BOOT_DIR}/fixup_x.dat"
74 fi
65 fi
75
66
76 # Remove kernel and initrd from /boot (already in /boot/firmware)
67 # Remove kernel and initrd from /boot (already in /boot/firmware)
77 if [ "$BUILD_KERNEL" = false ] ; then
68 if [ "$BUILD_KERNEL" = false ] ; then
78 rm -f "${R}/boot/vmlinuz-*"
69 rm -f "${R}/boot/vmlinuz-*"
79 rm -f "${R}/boot/initrd.img-*"
70 rm -f "${R}/boot/initrd.img-*"
80 fi
71 fi
81
72
82 # Clean APT list of repositories
73 # Clean APT list of repositories
83 rm -fr "${R}/var/lib/apt/lists/*"
74 rm -fr "${R}/var/lib/apt/lists/*"
84 chroot_exec apt-get -qq -y update
75 chroot_exec apt-get -qq -y update
85 fi
76 fi
@@ -1,1 +1,1
1 rpi2-jessie
1 RaspberryPI
@@ -1,6 +1,6
1 127.0.0.1 localhost
1 127.0.0.1 localhost
2 127.0.1.1 rpi2-jessie
2 127.0.1.1 RaspberryPI
3
3
4 ::1 localhost ip6-localhost ip6-loopback
4 ::1 localhost ip6-localhost ip6-loopback
5 ff02::1 ip6-allnodes
5 ff02::1 ip6-allnodes
6 ff02::2 ip6-allrouters
6 ff02::2 ip6-allrouters
@@ -1,104 +1,100
1 # This file contains utility functions used by rpi23-gen-image.sh
1 # This file contains utility functions used by rpi23-gen-image.sh
2
2
3 cleanup (){
3 cleanup (){
4 set +x
4 set +x
5 set +e
5 set +e
6
6
7 # Identify and kill all processes still using files
7 # Identify and kill all processes still using files
8 echo "killing processes using mount point ..."
8 echo "killing processes using mount point ..."
9 fuser -k "${R}"
9 fuser -k "${R}"
10 sleep 3
10 sleep 3
11 fuser -9 -k -v "${R}"
11 fuser -9 -k -v "${R}"
12
12
13 # Clean up temporary .password file
13 # Clean up temporary .password file
14 if [ -r ".password" ] ; then
14 if [ -r ".password" ] ; then
15 shred -zu .password
15 shred -zu .password
16 fi
16 fi
17
17
18 # Clean up all temporary mount points
18 # Clean up all temporary mount points
19 echo "removing temporary mount points ..."
19 echo "removing temporary mount points ..."
20 umount -l "${R}/proc" 2> /dev/null
20 umount -l "${R}/proc" 2> /dev/null
21 umount -l "${R}/sys" 2> /dev/null
21 umount -l "${R}/sys" 2> /dev/null
22 umount -l "${R}/dev/pts" 2> /dev/null
22 umount -l "${R}/dev/pts" 2> /dev/null
23 umount "$BUILDDIR/mount/boot/firmware" 2> /dev/null
23 umount "$BUILDDIR/mount/boot/firmware" 2> /dev/null
24 umount "$BUILDDIR/mount" 2> /dev/null
24 umount "$BUILDDIR/mount" 2> /dev/null
25 cryptsetup close "${CRYPTFS_MAPPING}" 2> /dev/null
25 cryptsetup close "${CRYPTFS_MAPPING}" 2> /dev/null
26 losetup -d "$ROOT_LOOP" 2> /dev/null
26 losetup -d "$ROOT_LOOP" 2> /dev/null
27 losetup -d "$FRMW_LOOP" 2> /dev/null
27 losetup -d "$FRMW_LOOP" 2> /dev/null
28 trap - 0 1 2 3 6
28 trap - 0 1 2 3 6
29 }
29 }
30
30
31 chroot_exec() {
31 chroot_exec() {
32 # Exec command in chroot
32 # Exec command in chroot
33 LANG=C LC_ALL=C DEBIAN_FRONTEND=noninteractive chroot ${R} $*
33 LANG=C LC_ALL=C DEBIAN_FRONTEND=noninteractive chroot ${R} $*
34 }
34 }
35
35
36 as_nobody() {
36 as_nobody() {
37 # Exec command as user nobody
37 # Exec command as user nobody
38 sudo -E -u nobody LANG=C LC_ALL=C $*
38 sudo -E -u nobody LANG=C LC_ALL=C $*
39 }
39 }
40
40
41 install_readonly() {
41 install_readonly() {
42 # Install file with user read-only permissions
42 # Install file with user read-only permissions
43 install -o root -g root -m 644 $*
43 install -o root -g root -m 644 $*
44 }
44 }
45
45
46 install_exec() {
46 install_exec() {
47 # Install file with root exec permissions
47 # Install file with root exec permissions
48 install -o root -g root -m 744 $*
48 install -o root -g root -m 744 $*
49 }
49 }
50
50
51 use_template () {
51 use_template () {
52 # Test if configuration template file exists
52 # Test if configuration template file exists
53 if [ ! -r "./templates/${CONFIG_TEMPLATE}" ] ; then
53 if [ ! -r "./templates/${CONFIG_TEMPLATE}" ] ; then
54 echo "error: configuration template ${CONFIG_TEMPLATE} not found"
54 echo "error: configuration template ${CONFIG_TEMPLATE} not found"
55 exit 1
55 exit 1
56 fi
56 fi
57
57
58 # Load template configuration parameters
58 # Load template configuration parameters
59 . "./templates/${CONFIG_TEMPLATE}"
59 . "./templates/${CONFIG_TEMPLATE}"
60 }
60 }
61
61
62 chroot_install_cc() {
62 chroot_install_cc() {
63 # Install c/c++ build environment inside the chroot
63 # Install c/c++ build environment inside the chroot
64 if [ -z "${COMPILER_PACKAGES}" ] ; then
64 if [ -z "${COMPILER_PACKAGES}" ] ; then
65 COMPILER_PACKAGES=$(chroot_exec apt-get -s install g++ make bc | grep "^Inst " | awk -v ORS=" " '{ print $2 }')
65 COMPILER_PACKAGES=$(chroot_exec apt-get -s install g++ make bc | grep "^Inst " | awk -v ORS=" " '{ print $2 }')
66
66 # Install COMPILER_PACKAGES in chroot
67 if [ "$RELEASE" = "jessie" ] ; then
68 chroot_exec apt-get -q -y --no-install-recommends install ${COMPILER_PACKAGES}
69 elif [ "$RELEASE" = "stretch" ] || [ "$RELEASE" = "buster" ] ; then
70 chroot_exec apt-get -q -y --allow-unauthenticated --no-install-recommends install ${COMPILER_PACKAGES}
67 chroot_exec apt-get -q -y --allow-unauthenticated --no-install-recommends install ${COMPILER_PACKAGES}
71 fi
68 fi
72 fi
73 }
69 }
74
70
75 chroot_remove_cc() {
71 chroot_remove_cc() {
76 # Remove c/c++ build environment from the chroot
72 # Remove c/c++ build environment from the chroot
77 if [ ! -z "${COMPILER_PACKAGES}" ] ; then
73 if [ ! -z "${COMPILER_PACKAGES}" ] ; then
78 chroot_exec apt-get -qq -y --auto-remove purge ${COMPILER_PACKAGES}
74 chroot_exec apt-get -qq -y --auto-remove purge ${COMPILER_PACKAGES}
79 COMPILER_PACKAGES=""
75 COMPILER_PACKAGES=""
80 fi
76 fi
81 }
77 }
82 #GPL v2.0
78 #GPL v2.0
83 #https://github.com/sakaki-/bcmrpi3-kernel-bis/blob/master/conform_config.sh
79 #https://github.com/sakaki-/bcmrpi3-kernel-bis/blob/master/conform_config.sh
84 # edited with thir param
80 # edited with thir param
85 #start
81 #start
86 set_kernel_config() {
82 set_kernel_config() {
87 # flag as $1, value to set as $2, config must exist at "./.config"
83 # flag as $1, value to set as $2, config must exist at "./.config"
88 local TGT="CONFIG_${1}"
84 local TGT="CONFIG_${1}"
89 local REP="${2//\//\\/}"
85 local REP="${2//\//\\/}"
90 if grep -q "^${TGT}[^_]" .config; then
86 if grep -q "^${TGT}[^_]" .config; then
91 sed -i "s/^\(${TGT}=.*\|# ${TGT} is not set\)/${TGT}=${REP}/" .config
87 sed -i "s/^\(${TGT}=.*\|# ${TGT} is not set\)/${TGT}=${REP}/" .config
92 else
88 else
93 echo "${TGT}=${2}" >> .config
89 echo "${TGT}=${2}" >> .config
94 fi
90 fi
95 }
91 }
96
92
97 unset_kernel_config() {
93 unset_kernel_config() {
98 # unsets flag with the value of $1, config must exist at "./.config"
94 # unsets flag with the value of $1, config must exist at "./.config"
99 local TGT="CONFIG_${1}"
95 local TGT="CONFIG_${1}"
100 sed -i "s/^${TGT}=.*/# ${TGT} is not set/" .config
96 sed -i "s/^${TGT}=.*/# ${TGT} is not set/" .config
101 }
97 }
102 #
98 #
103 #end
99 #end
104 #
100 #
@@ -1,829 +1,829
1 #!/bin/bash
1 #!/bin/sh
2 ########################################################################
2 ########################################################################
3 # rpi23-gen-image.sh 2015-2017
3 # rpi23-gen-image.sh 2015-2017
4 #
4 #
5 # Advanced Debian "stretch" and "buster" bootstrap script for RPi2/3
5 # Advanced Debian "stretch" and "buster" bootstrap script for RPi2/3
6 #
6 #
7 # This program is free software; you can redistribute it and/or
7 # This program is free software; you can redistribute it and/or
8 # modify it under the terms of the GNU General Public License
8 # modify it under the terms of the GNU General Public License
9 # as published by the Free Software Foundation; either version 2
9 # as published by the Free Software Foundation; either version 2
10 # of the License, or (at your option) any later version.
10 # of the License, or (at your option) any later version.
11 #
11 #
12 # Copyright (C) 2015 Jan Wagner <mail@jwagner.eu>
12 # Copyright (C) 2015 Jan Wagner <mail@jwagner.eu>
13 #
13 #
14 # Big thanks for patches and enhancements by 20+ github contributors!
14 # Big thanks for patches and enhancements by 20+ github contributors!
15 ########################################################################
15 ########################################################################
16
16
17 # Are we running as root?
17 # Are we running as root?
18 if [ "$(id -u)" -ne "0" ] ; then
18 if [ "$(id -u)" -ne "0" ] ; then
19 echo "error: this script must be executed with root privileges!"
19 echo "error: this script must be executed with root privileges!"
20 exit 1
20 exit 1
21 fi
21 fi
22
22
23 # Check if ./functions.sh script exists
23 # Check if ./functions.sh script exists
24 if [ ! -r "./functions.sh" ] ; then
24 if [ ! -r "./functions.sh" ] ; then
25 echo "error: './functions.sh' required script not found!"
25 echo "error: './functions.sh' required script not found!"
26 exit 1
26 exit 1
27 fi
27 fi
28
28
29 # Load utility functions
29 # Load utility functions
30 . ./functions.sh
30 . ./functions.sh
31
31
32 # Load parameters from configuration template file
32 # Load parameters from configuration template file
33 if [ -n "$CONFIG_TEMPLATE" ] ; then
33 if [ -n "$CONFIG_TEMPLATE" ] ; then
34 use_template
34 use_template
35 fi
35 fi
36
36
37 # Introduce settings
37 # Introduce settings
38 set -e
38 set -e
39 echo -n -e "\n#\n# RPi2/3 Bootstrap Settings\n#\n"
39 echo -n -e "\n#\n# RPi2/3 Bootstrap Settings\n#\n"
40 set -x
40 set -x
41
41
42 # Raspberry Pi model configuration
42 # Raspberry Pi model configuration
43 export RPI_MODEL=${RPI_MODEL:=2}
43 export RPI_MODEL=${RPI_MODEL:=2}
44
44
45 # Debian release
45 # Debian release
46 export RELEASE=${RELEASE:=buster}
46 export RELEASE=${RELEASE:=buster}
47
47
48 #Kernel Branch
48 #Kernel Branch
49 export KERNEL_BRANCH=${KERNEL_BRANCH:=""}
49 export KERNEL_BRANCH=${KERNEL_BRANCH:=""}
50
50
51 # URLs
51 # URLs
52 KERNEL_URL=${KERNEL_URL:=https://github.com/raspberrypi/linux}
52 KERNEL_URL=${KERNEL_URL:=https://github.com/raspberrypi/linux}
53 FIRMWARE_URL=${FIRMWARE_URL:=https://github.com/raspberrypi/firmware/raw/master/boot}
53 FIRMWARE_URL=${FIRMWARE_URL:=https://github.com/raspberrypi/firmware/raw/master/boot}
54 WLAN_FIRMWARE_URL=${WLAN_FIRMWARE_URL:=https://github.com/RPi-Distro/firmware-nonfree/raw/master/brcm}
54 WLAN_FIRMWARE_URL=${WLAN_FIRMWARE_URL:=https://github.com/RPi-Distro/firmware-nonfree/raw/master/brcm}
55 COLLABORA_URL=${COLLABORA_URL:=https://repositories.collabora.co.uk/debian}
55 COLLABORA_URL=${COLLABORA_URL:=https://repositories.collabora.co.uk/debian}
56 FBTURBO_URL=${FBTURBO_URL:=https://github.com/ssvb/xf86-video-fbturbo.git}
56 FBTURBO_URL=${FBTURBO_URL:=https://github.com/ssvb/xf86-video-fbturbo.git}
57 UBOOT_URL=${UBOOT_URL:=https://git.denx.de/u-boot.git}
57 UBOOT_URL=${UBOOT_URL:=https://git.denx.de/u-boot.git}
58 VIDEOCORE_URL=${VIDEOCORE_URL:=https://github.com/raspberrypi/userland}
58 VIDEOCORE_URL=${VIDEOCORE_URL:=https://github.com/raspberrypi/userland}
59 #BIS= Kernel has KVM and zswap enabled
59 #BIS= Kernel has KVM and zswap enabled
60 RPI3_64_BIS_KERNEL_URL=${RPI3_64_BIS_KERNEL_URL:=https://github.com/sakaki-/bcmrpi3-kernel-bis/releases/download/4.14.80.20181113/bcmrpi3-kernel-bis-4.14.80.20181113.tar.xz}
60 RPI3_64_BIS_KERNEL_URL=${RPI3_64_BIS_KERNEL_URL:=https://github.com/sakaki-/bcmrpi3-kernel-bis/releases/download/4.14.80.20181113/bcmrpi3-kernel-bis-4.14.80.20181113.tar.xz}
61 #default bcmrpi3_defconfig target kernel
61 #default bcmrpi3_defconfig target kernel
62 RPI3_64_DEF_KERNEL_URL=${RPI3_64_DEF_KERNEL_URL:=https://github.com/sakaki-/bcmrpi3-kernel/releases/download/4.14.80.20181113/bcmrpi3-kernel-4.14.80.20181113.tar.xz}
62 RPI3_64_DEF_KERNEL_URL=${RPI3_64_DEF_KERNEL_URL:=https://github.com/sakaki-/bcmrpi3-kernel/releases/download/4.14.80.20181113/bcmrpi3-kernel-4.14.80.20181113.tar.xz}
63 #enhanced kernel
63 #enhanced kernel
64 RPI3_64_KERNEL_URL=${RPI3_64_KERNEL_URL:=$RPI3_64_BIS_KERNEL_URL}
64 RPI3_64_KERNEL_URL=${RPI3_64_KERNEL_URL:=$RPI3_64_BIS_KERNEL_URL}
65 BLUETOOTH_URL=${BLUETOOTH_URL:=https://github.com/RPi-Distro/pi-bluetooth.git}
65 BLUETOOTH_URL=${BLUETOOTH_URL:=https://github.com/RPi-Distro/pi-bluetooth.git}
66
66
67 # Build directories
67 # Build directories
68 BASEDIR=${BASEDIR:=$(pwd)/images/${RELEASE}}
68 BASEDIR=${BASEDIR:=$(pwd)/images/${RELEASE}}
69 BUILDDIR="${BASEDIR}/build"
69 BUILDDIR="${BASEDIR}/build"
70
70
71 # Prepare date string for default image file name
71 # Prepare date string for default image file name
72 DATE="$(date +%Y-%m-%d)"
72 DATE="$(date +%Y-%m-%d)"
73 if [ -z "$KERNEL_BRANCH" ] ; then
73 if [ -z "$KERNEL_BRANCH" ] ; then
74 IMAGE_NAME=${IMAGE_NAME:=${BASEDIR}/${DATE}-${KERNEL_ARCH}-CURRENT-rpi${RPI_MODEL}-${RELEASE}-${RELEASE_ARCH}}
74 IMAGE_NAME=${IMAGE_NAME:=${BASEDIR}/${DATE}-${KERNEL_ARCH}-CURRENT-rpi${RPI_MODEL}-${RELEASE}-${RELEASE_ARCH}}
75 else
75 else
76 IMAGE_NAME=${IMAGE_NAME:=${BASEDIR}/${DATE}-${KERNEL_ARCH}-${KERNEL_BRANCH}-rpi${RPI_MODEL}-${RELEASE}-${RELEASE_ARCH}}
76 IMAGE_NAME=${IMAGE_NAME:=${BASEDIR}/${DATE}-${KERNEL_ARCH}-${KERNEL_BRANCH}-rpi${RPI_MODEL}-${RELEASE}-${RELEASE_ARCH}}
77 fi
77 fi
78
78
79 # Chroot directories
79 # Chroot directories
80 R="${BUILDDIR}/chroot"
80 R="${BUILDDIR}/chroot"
81 ETC_DIR="${R}/etc"
81 ETC_DIR="${R}/etc"
82 LIB_DIR="${R}/lib"
82 LIB_DIR="${R}/lib"
83 BOOT_DIR="${R}/boot/firmware"
83 BOOT_DIR="${R}/boot/firmware"
84 KERNEL_DIR="${R}/usr/src/linux"
84 KERNEL_DIR="${R}/usr/src/linux"
85 WLAN_FIRMWARE_DIR="${LIB_DIR}/firmware/brcm"
85 WLAN_FIRMWARE_DIR="${LIB_DIR}/firmware/brcm"
86
86
87 # Firmware directory: Blank if download from github
87 # Firmware directory: Blank if download from github
88 RPI_FIRMWARE_DIR=${RPI_FIRMWARE_DIR:=""}
88 RPI_FIRMWARE_DIR=${RPI_FIRMWARE_DIR:=""}
89 # General settings
89 # General settings
90 SET_ARCH=${SET_ARCH:=32}
90 SET_ARCH=${SET_ARCH:=32}
91 HOSTNAME=${HOSTNAME:=rpi${RPI_MODEL}-${RELEASE}}
91 HOSTNAME=${HOSTNAME:=rpi${RPI_MODEL}-${RELEASE}}
92 PASSWORD=${PASSWORD:=raspberry}
92 PASSWORD=${PASSWORD:=raspberry}
93 USER_PASSWORD=${USER_PASSWORD:=raspberry}
93 USER_PASSWORD=${USER_PASSWORD:=raspberry}
94 DEFLOCAL=${DEFLOCAL:="en_US.UTF-8"}
94 DEFLOCAL=${DEFLOCAL:="en_US.UTF-8"}
95 TIMEZONE=${TIMEZONE:="Europe/Berlin"}
95 TIMEZONE=${TIMEZONE:="Europe/Berlin"}
96 EXPANDROOT=${EXPANDROOT:=true}
96 EXPANDROOT=${EXPANDROOT:=true}
97
97
98 # Keyboard settings
98 # Keyboard settings
99 XKB_MODEL=${XKB_MODEL:=""}
99 XKB_MODEL=${XKB_MODEL:=""}
100 XKB_LAYOUT=${XKB_LAYOUT:=""}
100 XKB_LAYOUT=${XKB_LAYOUT:=""}
101 XKB_VARIANT=${XKB_VARIANT:=""}
101 XKB_VARIANT=${XKB_VARIANT:=""}
102 XKB_OPTIONS=${XKB_OPTIONS:=""}
102 XKB_OPTIONS=${XKB_OPTIONS:=""}
103
103
104 # Network settings (DHCP)
104 # Network settings (DHCP)
105 ENABLE_DHCP=${ENABLE_DHCP:=true}
105 ENABLE_DHCP=${ENABLE_DHCP:=true}
106
106
107 # Network settings (static)
107 # Network settings (static)
108 NET_ADDRESS=${NET_ADDRESS:=""}
108 NET_ADDRESS=${NET_ADDRESS:=""}
109 NET_GATEWAY=${NET_GATEWAY:=""}
109 NET_GATEWAY=${NET_GATEWAY:=""}
110 NET_DNS_1=${NET_DNS_1:=""}
110 NET_DNS_1=${NET_DNS_1:=""}
111 NET_DNS_2=${NET_DNS_2:=""}
111 NET_DNS_2=${NET_DNS_2:=""}
112 NET_DNS_DOMAINS=${NET_DNS_DOMAINS:=""}
112 NET_DNS_DOMAINS=${NET_DNS_DOMAINS:=""}
113 NET_NTP_1=${NET_NTP_1:=""}
113 NET_NTP_1=${NET_NTP_1:=""}
114 NET_NTP_2=${NET_NTP_2:=""}
114 NET_NTP_2=${NET_NTP_2:=""}
115
115
116 # APT settings
116 # APT settings
117 APT_PROXY=${APT_PROXY:=""}
117 APT_PROXY=${APT_PROXY:=""}
118 APT_SERVER=${APT_SERVER:="ftp.debian.org"}
118 APT_SERVER=${APT_SERVER:="ftp.debian.org"}
119
119
120 # Feature settings
120 # Feature settings
121 ENABLE_CONSOLE=${ENABLE_CONSOLE:=true}
121 ENABLE_CONSOLE=${ENABLE_CONSOLE:=true}
122 ENABLE_I2C=${ENABLE_I2C:=false}
122 ENABLE_I2C=${ENABLE_I2C:=false}
123 ENABLE_SPI=${ENABLE_SPI:=false}
123 ENABLE_SPI=${ENABLE_SPI:=false}
124 ENABLE_IPV6=${ENABLE_IPV6:=true}
124 ENABLE_IPV6=${ENABLE_IPV6:=true}
125 ENABLE_SSHD=${ENABLE_SSHD:=true}
125 ENABLE_SSHD=${ENABLE_SSHD:=true}
126 ENABLE_NONFREE=${ENABLE_NONFREE:=false}
126 ENABLE_NONFREE=${ENABLE_NONFREE:=false}
127 ENABLE_WIRELESS=${ENABLE_WIRELESS:=false}
127 ENABLE_WIRELESS=${ENABLE_WIRELESS:=false}
128 ENABLE_SOUND=${ENABLE_SOUND:=true}
128 ENABLE_SOUND=${ENABLE_SOUND:=true}
129 ENABLE_DBUS=${ENABLE_DBUS:=true}
129 ENABLE_DBUS=${ENABLE_DBUS:=true}
130 ENABLE_HWRANDOM=${ENABLE_HWRANDOM:=true}
130 ENABLE_HWRANDOM=${ENABLE_HWRANDOM:=true}
131 ENABLE_MINGPU=${ENABLE_MINGPU:=false}
131 ENABLE_MINGPU=${ENABLE_MINGPU:=false}
132 ENABLE_XORG=${ENABLE_XORG:=false}
132 ENABLE_XORG=${ENABLE_XORG:=false}
133 ENABLE_WM=${ENABLE_WM:=""}
133 ENABLE_WM=${ENABLE_WM:=""}
134 ENABLE_RSYSLOG=${ENABLE_RSYSLOG:=true}
134 ENABLE_RSYSLOG=${ENABLE_RSYSLOG:=true}
135 ENABLE_USER=${ENABLE_USER:=true}
135 ENABLE_USER=${ENABLE_USER:=true}
136 USER_NAME=${USER_NAME:="pi"}
136 USER_NAME=${USER_NAME:="pi"}
137 ENABLE_ROOT=${ENABLE_ROOT:=false}
137 ENABLE_ROOT=${ENABLE_ROOT:=false}
138 ENABLE_QEMU=${ENABLE_QEMU:=false}
138 ENABLE_QEMU=${ENABLE_QEMU:=false}
139 ENABLE_SYSVINIT=${ENABLE_SYSVINIT:=false}
139 ENABLE_SYSVINIT=${ENABLE_SYSVINIT:=false}
140
140
141 # SSH settings
141 # SSH settings
142 SSH_ENABLE_ROOT=${SSH_ENABLE_ROOT:=false}
142 SSH_ENABLE_ROOT=${SSH_ENABLE_ROOT:=false}
143 SSH_DISABLE_PASSWORD_AUTH=${SSH_DISABLE_PASSWORD_AUTH:=false}
143 SSH_DISABLE_PASSWORD_AUTH=${SSH_DISABLE_PASSWORD_AUTH:=false}
144 SSH_LIMIT_USERS=${SSH_LIMIT_USERS:=false}
144 SSH_LIMIT_USERS=${SSH_LIMIT_USERS:=false}
145 SSH_ROOT_PUB_KEY=${SSH_ROOT_PUB_KEY:=""}
145 SSH_ROOT_PUB_KEY=${SSH_ROOT_PUB_KEY:=""}
146 SSH_USER_PUB_KEY=${SSH_USER_PUB_KEY:=""}
146 SSH_USER_PUB_KEY=${SSH_USER_PUB_KEY:=""}
147
147
148 # Advanced settings
148 # Advanced settings
149 ENABLE_MINBASE=${ENABLE_MINBASE:=false}
149 ENABLE_MINBASE=${ENABLE_MINBASE:=false}
150 ENABLE_REDUCE=${ENABLE_REDUCE:=false}
150 ENABLE_REDUCE=${ENABLE_REDUCE:=false}
151 ENABLE_UBOOT=${ENABLE_UBOOT:=false}
151 ENABLE_UBOOT=${ENABLE_UBOOT:=false}
152 UBOOTSRC_DIR=${UBOOTSRC_DIR:=""}
152 UBOOTSRC_DIR=${UBOOTSRC_DIR:=""}
153 ENABLE_UBOOTUSB=${ENABLE_UBOOTUSB=false}
153 ENABLE_UBOOTUSB=${ENABLE_UBOOTUSB=false}
154 ENABLE_FBTURBO=${ENABLE_FBTURBO:=false}
154 ENABLE_FBTURBO=${ENABLE_FBTURBO:=false}
155 ENABLE_VIDEOCORE=${ENABLE_VIDEOCORE:=true}
155 ENABLE_VIDEOCORE=${ENABLE_VIDEOCORE:=true}
156 VIDEOCORESRC_DIR=${VIDEOCORESRC_DIR:=""}
156 VIDEOCORESRC_DIR=${VIDEOCORESRC_DIR:=""}
157 FBTURBOSRC_DIR=${FBTURBOSRC_DIR:=""}
157 FBTURBOSRC_DIR=${FBTURBOSRC_DIR:=""}
158 ENABLE_HARDNET=${ENABLE_HARDNET:=false}
158 ENABLE_HARDNET=${ENABLE_HARDNET:=false}
159 ENABLE_IPTABLES=${ENABLE_IPTABLES:=false}
159 ENABLE_IPTABLES=${ENABLE_IPTABLES:=false}
160 ENABLE_SPLITFS=${ENABLE_SPLITFS:=false}
160 ENABLE_SPLITFS=${ENABLE_SPLITFS:=false}
161 ENABLE_INITRAMFS=${ENABLE_INITRAMFS:=false}
161 ENABLE_INITRAMFS=${ENABLE_INITRAMFS:=false}
162 ENABLE_IFNAMES=${ENABLE_IFNAMES:=true}
162 ENABLE_IFNAMES=${ENABLE_IFNAMES:=true}
163 DISABLE_UNDERVOLT_WARNINGS=${DISABLE_UNDERVOLT_WARNINGS:=}
163 DISABLE_UNDERVOLT_WARNINGS=${DISABLE_UNDERVOLT_WARNINGS:=}
164
164
165 # Kernel compilation settings
165 # Kernel compilation settings
166 BUILD_KERNEL=${BUILD_KERNEL:=true}
166 BUILD_KERNEL=${BUILD_KERNEL:=true}
167 KERNEL_REDUCE=${KERNEL_REDUCE:=false}
167 KERNEL_REDUCE=${KERNEL_REDUCE:=false}
168 KERNEL_THREADS=${KERNEL_THREADS:=1}
168 KERNEL_THREADS=${KERNEL_THREADS:=1}
169 KERNEL_HEADERS=${KERNEL_HEADERS:=true}
169 KERNEL_HEADERS=${KERNEL_HEADERS:=true}
170 KERNEL_MENUCONFIG=${KERNEL_MENUCONFIG:=false}
170 KERNEL_MENUCONFIG=${KERNEL_MENUCONFIG:=false}
171 KERNEL_REMOVESRC=${KERNEL_REMOVESRC:=true}
171 KERNEL_REMOVESRC=${KERNEL_REMOVESRC:=true}
172 KERNEL_OLDDEFCONFIG=${KERNEL_OLDDEFCONFIG:=false}
172 KERNEL_OLDDEFCONFIG=${KERNEL_OLDDEFCONFIG:=false}
173 KERNEL_CCACHE=${KERNEL_CCACHE:=false}
173 KERNEL_CCACHE=${KERNEL_CCACHE:=false}
174 KERNEL_ZSWAP=${KERNEL_ZSWAP:=false}
174 KERNEL_ZSWAP=${KERNEL_ZSWAP:=false}
175 KERNEL_VIRT=${KERNEL_VIRT:=false}
175 KERNEL_VIRT=${KERNEL_VIRT:=false}
176 KERNEL_BPF=${KERNEL_BPF:=true}
176 KERNEL_BPF=${KERNEL_BPF:=true}
177
177
178 # Kernel compilation from source directory settings
178 # Kernel compilation from source directory settings
179 KERNELSRC_DIR=${KERNELSRC_DIR:=""}
179 KERNELSRC_DIR=${KERNELSRC_DIR:=""}
180 KERNELSRC_CLEAN=${KERNELSRC_CLEAN:=false}
180 KERNELSRC_CLEAN=${KERNELSRC_CLEAN:=false}
181 KERNELSRC_CONFIG=${KERNELSRC_CONFIG:=true}
181 KERNELSRC_CONFIG=${KERNELSRC_CONFIG:=true}
182 KERNELSRC_PREBUILT=${KERNELSRC_PREBUILT:=false}
182 KERNELSRC_PREBUILT=${KERNELSRC_PREBUILT:=false}
183
183
184 # Reduce disk usage settings
184 # Reduce disk usage settings
185 REDUCE_APT=${REDUCE_APT:=true}
185 REDUCE_APT=${REDUCE_APT:=true}
186 REDUCE_DOC=${REDUCE_DOC:=true}
186 REDUCE_DOC=${REDUCE_DOC:=true}
187 REDUCE_MAN=${REDUCE_MAN:=true}
187 REDUCE_MAN=${REDUCE_MAN:=true}
188 REDUCE_VIM=${REDUCE_VIM:=false}
188 REDUCE_VIM=${REDUCE_VIM:=false}
189 REDUCE_BASH=${REDUCE_BASH:=false}
189 REDUCE_BASH=${REDUCE_BASH:=false}
190 REDUCE_HWDB=${REDUCE_HWDB:=true}
190 REDUCE_HWDB=${REDUCE_HWDB:=true}
191 REDUCE_SSHD=${REDUCE_SSHD:=true}
191 REDUCE_SSHD=${REDUCE_SSHD:=true}
192 REDUCE_LOCALE=${REDUCE_LOCALE:=true}
192 REDUCE_LOCALE=${REDUCE_LOCALE:=true}
193
193
194 # Encrypted filesystem settings
194 # Encrypted filesystem settings
195 ENABLE_CRYPTFS=${ENABLE_CRYPTFS:=false}
195 ENABLE_CRYPTFS=${ENABLE_CRYPTFS:=false}
196 CRYPTFS_PASSWORD=${CRYPTFS_PASSWORD:=""}
196 CRYPTFS_PASSWORD=${CRYPTFS_PASSWORD:=""}
197 CRYPTFS_MAPPING=${CRYPTFS_MAPPING:="secure"}
197 CRYPTFS_MAPPING=${CRYPTFS_MAPPING:="secure"}
198 CRYPTFS_CIPHER=${CRYPTFS_CIPHER:="aes-xts-plain64:sha512"}
198 CRYPTFS_CIPHER=${CRYPTFS_CIPHER:="aes-xts-plain64:sha512"}
199 CRYPTFS_XTSKEYSIZE=${CRYPTFS_XTSKEYSIZE:=512}
199 CRYPTFS_XTSKEYSIZE=${CRYPTFS_XTSKEYSIZE:=512}
200
200
201 # Chroot scripts directory
201 # Chroot scripts directory
202 CHROOT_SCRIPTS=${CHROOT_SCRIPTS:=""}
202 CHROOT_SCRIPTS=${CHROOT_SCRIPTS:=""}
203
203
204 # Packages required in the chroot build environment
204 # Packages required in the chroot build environment
205 APT_INCLUDES=${APT_INCLUDES:=""}
205 APT_INCLUDES=${APT_INCLUDES:=""}
206 APT_INCLUDES="${APT_INCLUDES},apt-transport-https,apt-utils,ca-certificates,debian-archive-keyring,dialog,sudo,systemd,sysvinit-utils,locales,keyboard-configuration,console-setup"
206 APT_INCLUDES="${APT_INCLUDES},apt-transport-https,apt-utils,ca-certificates,debian-archive-keyring,dialog,sudo,systemd,sysvinit-utils,locales,keyboard-configuration,console-setup"
207
207
208 #Packages to exclude from chroot build environment
208 #Packages to exclude from chroot build environment
209 APT_EXCLUDES=${APT_EXCLUDES:=""}
209 APT_EXCLUDES=${APT_EXCLUDES:=""}
210
210
211 # Packages required for bootstrapping
211 # Packages required for bootstrapping
212 REQUIRED_PACKAGES="debootstrap debian-archive-keyring qemu-user-static binfmt-support dosfstools rsync bmap-tools whois git bc psmisc dbus sudo netselect-apt"
212 REQUIRED_PACKAGES="debootstrap debian-archive-keyring qemu-user-static binfmt-support dosfstools rsync bmap-tools whois git bc psmisc dbus sudo netselect-apt"
213 MISSING_PACKAGES=""
213 MISSING_PACKAGES=""
214
214
215 # Packages installed for c/c++ build environment in chroot (keep empty)
215 # Packages installed for c/c++ build environment in chroot (keep empty)
216 COMPILER_PACKAGES=""
216 COMPILER_PACKAGES=""
217
217
218 #If init and systemd-sysv are wanted e.g. halt/reboot/shutdown scripts
218 #If init and systemd-sysv are wanted e.g. halt/reboot/shutdown scripts
219 if [ "$ENABLE_SYSVINIT" = false ] ; then
219 if [ "$ENABLE_SYSVINIT" = false ] ; then
220 APT_EXCLUDES="--exclude=${APT_EXCLUDES},init,systemd-sysv"
220 APT_EXCLUDES="--exclude=${APT_EXCLUDES},init,systemd-sysv"
221 fi
221 fi
222
222
223 #Check if apt-cacher-ng has its default port open on and set APT_PROXY
223 #Check if apt-cacher-ng has its default port open on and set APT_PROXY
224 if [ -n "$(lsof -i :3142)" ] ; then
224 if [ -n "$(lsof -i :3142)" ] ; then
225 HTTP_PROXY=http://127.0.0.1:3142/
225 HTTP_PROXY=http://127.0.0.1:3142/
226 fi
226 fi
227
227
228 #ipinfo=$(curl ipinfo.io | grep country )
228 #ipinfo=$(curl ipinfo.io | grep country )
229 #grep -o '\"[^"]*\"' $ipinfo | tr -d '"'
229 #grep -o '\"[^"]*\"' $ipinfo | tr -d '"'
230 #grep -Po '"country":.*?[^\\]",' $(curl ipinfo.io | grep country )
230 #grep -Po '"country":.*?[^\\]",' $(curl ipinfo.io | grep country )
231 #sed -i "s,http:,https:,g" "${ETC_DIR}/apt/sources.list"
231 #sed -i "s,http:,https:,g" "${ETC_DIR}/apt/sources.list"
232 #autconfigure best apt server to not spam ftp.debian.org
232 #autconfigure best apt server to not spam ftp.debian.org
233 #rm files/apt/sources.list
233 #rm files/apt/sources.list
234 #netselect-apt does not know buster yet
234 #netselect-apt does not know buster yet
235 if [ "$RELEASE" = "buster" ] ; then
235 if [ "$RELEASE" = "buster" ] ; then
236 RLS=testing
236 RLS=testing
237 else
237 else
238 RLS="$RELEASE"
238 RLS="$RELEASE"
239 fi
239 fi
240
240
241 if [ -f "$(pwd)/files/apt/sources.list" ] ; then
241 if [ -f "$(pwd)/files/apt/sources.list" ] ; then
242 rm "$(pwd)/files/apt/sources.list"
242 rm "$(pwd)/files/apt/sources.list"
243 fi
243 fi
244
244
245 if [ "$ENABLE_NONFREE" = true ] ; then
245 if [ "$ENABLE_NONFREE" = true ] ; then
246 netselect-apt --arch "$RELEASE_ARCH" --tests 10 --sources --nonfree --outfile "$(pwd)/files/apt/sources.list" -d "$RLS"
246 netselect-apt --arch "$RELEASE_ARCH" --tests 10 --sources --nonfree --outfile "$(pwd)/files/apt/sources.list" -d "$RLS"
247 else
247 else
248 netselect-apt --arch "$RELEASE_ARCH" --tests 10 --sources --outfile "$(pwd)/files/apt/sources.list" -d "$RLS"
248 netselect-apt --arch "$RELEASE_ARCH" --tests 10 --sources --outfile "$(pwd)/files/apt/sources.list" -d "$RLS"
249 fi
249 fi
250
250
251 #sed and cut the result string so we can use it as APT_SERVER
251 #sed and cut the result string so we can use it as APT_SERVER
252 APT_SERVER=$(grep -m 1 http files/apt/sources.list | sed "s|http://| |g" | cut -d ' ' -f 3)
252 APT_SERVER=$(grep -m 1 http files/apt/sources.list | sed "s|http://| |g" | cut -d ' ' -f 3)
253 APT_SERVER=${APT_SERVER::-1}
253 APT_SERVER=${APT_SERVER::-1}
254
254
255 #make script easier and more stable to use with convenient setup switch. Just setup SET_ARCH and RPI_MODEL and your good to go!
255 #make script easier and more stable to use with convenient setup switch. Just setup SET_ARCH and RPI_MODEL and your good to go!
256 if [ -n "$SET_ARCH" ] ; then
256 if [ -n "$SET_ARCH" ] ; then
257 echo "Setting Architecture specific settings"
257 echo "Setting Architecture specific settings"
258 ##################################
258 ##################################
259 # 64 bit config
259 # 64 bit config
260 ##################################
260 ##################################
261 if [ "$SET_ARCH" = 64 ] ; then
261 if [ "$SET_ARCH" = 64 ] ; then
262 echo "64 bit mode selected - Setting up enviroment"
262 echo "64 bit mode selected - Setting up enviroment"
263 # 64 bit depended settings
263 # 64 bit depended settings
264 QEMU_BINARY=${QEMU_BINARY:=/usr/bin/qemu-aarch64-static}
264 QEMU_BINARY=${QEMU_BINARY:=/usr/bin/qemu-aarch64-static}
265 KERNEL_ARCH=${KERNEL_ARCH:=arm64}
265 KERNEL_ARCH=${KERNEL_ARCH:=arm64}
266 KERNEL_BIN_IMAGE=${KERNEL_BIN_IMAGE:="Image"}
266 KERNEL_BIN_IMAGE=${KERNEL_BIN_IMAGE:="Image"}
267
267
268 if [ "$RPI_MODEL" = 3 ] || [ "$RPI_MODEL" = 3P ] ; then
268 if [ "$RPI_MODEL" = 3 ] || [ "$RPI_MODEL" = 3P ] ; then
269 REQUIRED_PACKAGES="${REQUIRED_PACKAGES} crossbuild-essential-arm64"
269 REQUIRED_PACKAGES="${REQUIRED_PACKAGES} crossbuild-essential-arm64"
270 KERNEL_DEFCONFIG=${KERNEL_DEFCONFIG:=bcmrpi3_defconfig}
270 KERNEL_DEFCONFIG=${KERNEL_DEFCONFIG:=bcmrpi3_defconfig}
271 RELEASE_ARCH=${RELEASE_ARCH:=arm64}
271 RELEASE_ARCH=${RELEASE_ARCH:=arm64}
272 KERNEL_IMAGE=${KERNEL_IMAGE:=kernel8.img}
272 KERNEL_IMAGE=${KERNEL_IMAGE:=kernel8.img}
273 CROSS_COMPILE=${CROSS_COMPILE:=aarch64-linux-gnu-}
273 CROSS_COMPILE=${CROSS_COMPILE:=aarch64-linux-gnu-}
274 else
274 else
275 echo "error: Only Raspberry PI 3 and 3B+ support 64bit"
275 echo "error: Only Raspberry PI 3 and 3B+ support 64bit"
276 exit 1
276 exit 1
277 fi
277 fi
278 fi
278 fi
279
279
280 ##################################
280 ##################################
281 # 32 bit config
281 # 32 bit config
282 ##################################
282 ##################################
283 if [ "$SET_ARCH" = 32 ] ; then
283 if [ "$SET_ARCH" = 32 ] ; then
284 echo "32 bit mode selected - Setting up enviroment"
284 echo "32 bit mode selected - Setting up enviroment"
285 #General 32bit configuration
285 #General 32bit configuration
286 QEMU_BINARY=${QEMU_BINARY:=/usr/bin/qemu-arm-static}
286 QEMU_BINARY=${QEMU_BINARY:=/usr/bin/qemu-arm-static}
287 KERNEL_ARCH=${KERNEL_ARCH:=arm}
287 KERNEL_ARCH=${KERNEL_ARCH:=arm}
288 KERNEL_BIN_IMAGE=${KERNEL_BIN_IMAGE:="zImage"}
288 KERNEL_BIN_IMAGE=${KERNEL_BIN_IMAGE:="zImage"}
289
289
290 #Raspberry setting grouped by board compability
290 #Raspberry setting grouped by board compability
291 if [ "$RPI_MODEL" = 0 ] || [ "$RPI_MODEL" = 1 ] || [ "$RPI_MODEL" = 1P ] ; then
291 if [ "$RPI_MODEL" = 0 ] || [ "$RPI_MODEL" = 1 ] || [ "$RPI_MODEL" = 1P ] ; then
292 echo "Setting settings for bcm2835 Raspberry PI boards"
292 echo "Setting settings for bcm2835 Raspberry PI boards"
293 REQUIRED_PACKAGES="${REQUIRED_PACKAGES} crossbuild-essential-armel"
293 REQUIRED_PACKAGES="${REQUIRED_PACKAGES} crossbuild-essential-armel"
294 KERNEL_DEFCONFIG=${KERNEL_DEFCONFIG:=bcmrpi_defconfig}
294 KERNEL_DEFCONFIG=${KERNEL_DEFCONFIG:=bcmrpi_defconfig}
295 RELEASE_ARCH=${RELEASE_ARCH:=armel}
295 RELEASE_ARCH=${RELEASE_ARCH:=armel}
296 KERNEL_IMAGE=${KERNEL_IMAGE:=kernel.img}
296 KERNEL_IMAGE=${KERNEL_IMAGE:=kernel.img}
297 CROSS_COMPILE=${CROSS_COMPILE:=arm-linux-gnueabi-}
297 CROSS_COMPILE=${CROSS_COMPILE:=arm-linux-gnueabi-}
298 fi
298 fi
299 if [ "$RPI_MODEL" = 2 ] || [ "$RPI_MODEL" = 3 ] || [ "$RPI_MODEL" = 3P ] ; then
299 if [ "$RPI_MODEL" = 2 ] || [ "$RPI_MODEL" = 3 ] || [ "$RPI_MODEL" = 3P ] ; then
300 echo "Setting settings for bcm2837 Raspberry PI boards"
300 echo "Setting settings for bcm2837 Raspberry PI boards"
301 REQUIRED_PACKAGES="${REQUIRED_PACKAGES} crossbuild-essential-armhf"
301 REQUIRED_PACKAGES="${REQUIRED_PACKAGES} crossbuild-essential-armhf"
302 KERNEL_DEFCONFIG=${KERNEL_DEFCONFIG:=bcm2709_defconfig}
302 KERNEL_DEFCONFIG=${KERNEL_DEFCONFIG:=bcm2709_defconfig}
303 RELEASE_ARCH=${RELEASE_ARCH:=armhf}
303 RELEASE_ARCH=${RELEASE_ARCH:=armhf}
304 KERNEL_IMAGE=${KERNEL_IMAGE:=kernel7.img}
304 KERNEL_IMAGE=${KERNEL_IMAGE:=kernel7.img}
305 CROSS_COMPILE=${CROSS_COMPILE:=arm-linux-gnueabihf-}
305 CROSS_COMPILE=${CROSS_COMPILE:=arm-linux-gnueabihf-}
306 fi
306 fi
307 fi
307 fi
308 #SET_ARCH not set
308 #SET_ARCH not set
309 else
309 else
310 echo "error: Please set '32' or '64' as value for SET_ARCH"
310 echo "error: Please set '32' or '64' as value for SET_ARCH"
311 exit 1
311 exit 1
312 fi
312 fi
313
313
314 #Device specific configuration
314 #Device specific configuration
315 echo "Select DTB-File"
315 echo "Select DTB-File"
316 case "$RPI_MODEL" in
316 case "$RPI_MODEL" in
317 0)
317 0)
318 DTB_FILE=${DTB_FILE:=bcm2708-rpi-0-w.dtb}
318 DTB_FILE=${DTB_FILE:=bcm2708-rpi-0-w.dtb}
319 UBOOT_CONFIG=${UBOOT_CONFIG:=rpi_defconfig}
319 UBOOT_CONFIG=${UBOOT_CONFIG:=rpi_defconfig}
320 ;;
320 ;;
321 1)
321 1)
322 DTB_FILE=${DTB_FILE:=bcm2708-rpi-b.dtb}
322 DTB_FILE=${DTB_FILE:=bcm2708-rpi-b.dtb}
323 UBOOT_CONFIG=${UBOOT_CONFIG:=rpi_defconfig}
323 UBOOT_CONFIG=${UBOOT_CONFIG:=rpi_defconfig}
324 ;;
324 ;;
325 1P)
325 1P)
326 DTB_FILE=${DTB_FILE:=bcm2708-rpi-b-plus.dtb}
326 DTB_FILE=${DTB_FILE:=bcm2708-rpi-b-plus.dtb}
327 UBOOT_CONFIG=${UBOOT_CONFIG:=rpi_defconfig}
327 UBOOT_CONFIG=${UBOOT_CONFIG:=rpi_defconfig}
328 ;;
328 ;;
329 2)
329 2)
330 DTB_FILE=${DTB_FILE:=bcm2709-rpi-2-b.dtb}
330 DTB_FILE=${DTB_FILE:=bcm2709-rpi-2-b.dtb}
331 UBOOT_CONFIG=${UBOOT_CONFIG:=rpi_2_defconfig}
331 UBOOT_CONFIG=${UBOOT_CONFIG:=rpi_2_defconfig}
332 ;;
332 ;;
333 3)
333 3)
334 DTB_FILE=${DTB_FILE:=bcm2710-rpi-3-b.dtb}
334 DTB_FILE=${DTB_FILE:=bcm2710-rpi-3-b.dtb}
335 UBOOT_CONFIG=${UBOOT_CONFIG:=rpi_3_defconfig}
335 UBOOT_CONFIG=${UBOOT_CONFIG:=rpi_3_defconfig}
336 ;;
336 ;;
337 3P)
337 3P)
338 DTB_FILE=${DTB_FILE:=bcm2710-rpi-3-b.dtb}
338 DTB_FILE=${DTB_FILE:=bcm2710-rpi-3-b.dtb}
339 UBOOT_CONFIG=${UBOOT_CONFIG:=rpi_3_defconfig}
339 UBOOT_CONFIG=${UBOOT_CONFIG:=rpi_3_defconfig}
340 ;;
340 ;;
341 *)
341 *)
342 echo "error: Raspberry Pi model $RPI_MODEL is not supported!"
342 echo "error: Raspberry Pi model $RPI_MODEL is not supported!"
343 exit 1
343 exit 1
344 ;;
344 ;;
345 esac
345 esac
346 echo "$DTB_FILE selected"
346 echo "$DTB_FILE selected"
347
347
348 #DEBUG off
348 #DEBUG off
349 set +x
349 set +x
350
350
351 # Check if the internal wireless interface is supported by the RPi model
351 # Check if the internal wireless interface is supported by the RPi model
352 if [ "$ENABLE_WIRELESS" = true ] ; then
352 if [ "$ENABLE_WIRELESS" = true ] ; then
353 if [ "$RPI_MODEL" = 1 ] || [ "$RPI_MODEL" = 1P ] || [ "$RPI_MODEL" = 2 ] ; then
353 if [ "$RPI_MODEL" = 1 ] || [ "$RPI_MODEL" = 1P ] || [ "$RPI_MODEL" = 2 ] ; then
354 echo "error: The selected Raspberry Pi model has no internal wireless interface"
354 echo "error: The selected Raspberry Pi model has no internal wireless interface"
355 exit 1
355 exit 1
356 else
356 else
357 echo "Raspberry Pi $RPI_MODEL has WIFI support"
357 echo "Raspberry Pi $RPI_MODEL has WIFI support"
358 fi
358 fi
359 fi
359 fi
360
360
361 # Check if DISABLE_UNDERVOLT_WARNINGS parameter value is supported
361 # Check if DISABLE_UNDERVOLT_WARNINGS parameter value is supported
362 if [ -n "$DISABLE_UNDERVOLT_WARNINGS" ] ; then
362 if [ -n "$DISABLE_UNDERVOLT_WARNINGS" ] ; then
363 if [ "$DISABLE_UNDERVOLT_WARNINGS" != 1 ] && [ "$DISABLE_UNDERVOLT_WARNINGS" != 2 ] ; then
363 if [ "$DISABLE_UNDERVOLT_WARNINGS" != 1 ] && [ "$DISABLE_UNDERVOLT_WARNINGS" != 2 ] ; then
364 echo "error: DISABLE_UNDERVOLT_WARNINGS=${DISABLE_UNDERVOLT_WARNINGS} is not supported"
364 echo "error: DISABLE_UNDERVOLT_WARNINGS=${DISABLE_UNDERVOLT_WARNINGS} is not supported"
365 exit 1
365 exit 1
366 fi
366 fi
367 fi
367 fi
368
368
369 if [ "$ENABLE_VIDEOCORE" = true ] ; then
369 if [ "$ENABLE_VIDEOCORE" = true ] ; then
370 REQUIRED_PACKAGES="${REQUIRED_PACKAGES} cmake"
370 REQUIRED_PACKAGES="${REQUIRED_PACKAGES} cmake"
371 fi
371 fi
372
372
373 # Add libncurses5 to enable kernel menuconfig
373 # Add libncurses5 to enable kernel menuconfig
374 if [ "$KERNEL_MENUCONFIG" = true ] ; then
374 if [ "$KERNEL_MENUCONFIG" = true ] ; then
375 REQUIRED_PACKAGES="${REQUIRED_PACKAGES} libncurses-dev"
375 REQUIRED_PACKAGES="${REQUIRED_PACKAGES} libncurses-dev"
376 fi
376 fi
377
377
378 # Add ccache compiler cache for (faster) kernel cross (re)compilation
378 # Add ccache compiler cache for (faster) kernel cross (re)compilation
379 if [ "$KERNEL_CCACHE" = true ] ; then
379 if [ "$KERNEL_CCACHE" = true ] ; then
380 REQUIRED_PACKAGES="${REQUIRED_PACKAGES} ccache"
380 REQUIRED_PACKAGES="${REQUIRED_PACKAGES} ccache"
381 fi
381 fi
382
382
383 # Add cryptsetup package to enable filesystem encryption
383 # Add cryptsetup package to enable filesystem encryption
384 if [ "$ENABLE_CRYPTFS" = true ] && [ "$BUILD_KERNEL" = true ] ; then
384 if [ "$ENABLE_CRYPTFS" = true ] && [ "$BUILD_KERNEL" = true ] ; then
385 REQUIRED_PACKAGES="${REQUIRED_PACKAGES} cryptsetup"
385 REQUIRED_PACKAGES="${REQUIRED_PACKAGES} cryptsetup"
386 APT_INCLUDES="${APT_INCLUDES},cryptsetup,busybox,console-setup"
386 APT_INCLUDES="${APT_INCLUDES},cryptsetup,busybox,console-setup"
387
387
388 if [ -z "$CRYPTFS_PASSWORD" ] ; then
388 if [ -z "$CRYPTFS_PASSWORD" ] ; then
389 echo "error: no password defined (CRYPTFS_PASSWORD)!"
389 echo "error: no password defined (CRYPTFS_PASSWORD)!"
390 exit 1
390 exit 1
391 fi
391 fi
392 ENABLE_INITRAMFS=true
392 ENABLE_INITRAMFS=true
393 fi
393 fi
394
394
395 # Add initramfs generation tools
395 # Add initramfs generation tools
396 if [ "$ENABLE_INITRAMFS" = true ] && [ "$BUILD_KERNEL" = true ] ; then
396 if [ "$ENABLE_INITRAMFS" = true ] && [ "$BUILD_KERNEL" = true ] ; then
397 APT_INCLUDES="${APT_INCLUDES},initramfs-tools"
397 APT_INCLUDES="${APT_INCLUDES},initramfs-tools"
398 fi
398 fi
399
399
400 # Add device-tree-compiler required for building the U-Boot bootloader
400 # Add device-tree-compiler required for building the U-Boot bootloader
401 if [ "$ENABLE_UBOOT" = true ] ; then
401 if [ "$ENABLE_UBOOT" = true ] ; then
402 APT_INCLUDES="${APT_INCLUDES},device-tree-compiler,bison,flex,bc"
402 APT_INCLUDES="${APT_INCLUDES},device-tree-compiler,bison,flex,bc"
403 else
403 else
404 if [ "$ENABLE_UBOOTUSB" = true ] ; then
404 if [ "$ENABLE_UBOOTUSB" = true ] ; then
405 echo "error: Enabling UBOOTUSB requires u-boot to be enabled"
405 echo "error: Enabling UBOOTUSB requires u-boot to be enabled"
406 exit 1
406 exit 1
407 fi
407 fi
408 fi
408 fi
409
409
410 # Check if root SSH (v2) public key file exists
410 # Check if root SSH (v2) public key file exists
411 if [ -n "$SSH_ROOT_PUB_KEY" ] ; then
411 if [ -n "$SSH_ROOT_PUB_KEY" ] ; then
412 if [ ! -f "$SSH_ROOT_PUB_KEY" ] ; then
412 if [ ! -f "$SSH_ROOT_PUB_KEY" ] ; then
413 echo "error: '$SSH_ROOT_PUB_KEY' specified SSH public key file not found (SSH_ROOT_PUB_KEY)!"
413 echo "error: '$SSH_ROOT_PUB_KEY' specified SSH public key file not found (SSH_ROOT_PUB_KEY)!"
414 exit 1
414 exit 1
415 fi
415 fi
416 fi
416 fi
417
417
418 # Check if $USER_NAME SSH (v2) public key file exists
418 # Check if $USER_NAME SSH (v2) public key file exists
419 if [ -n "$SSH_USER_PUB_KEY" ] ; then
419 if [ -n "$SSH_USER_PUB_KEY" ] ; then
420 if [ ! -f "$SSH_USER_PUB_KEY" ] ; then
420 if [ ! -f "$SSH_USER_PUB_KEY" ] ; then
421 echo "error: '$SSH_USER_PUB_KEY' specified SSH public key file not found (SSH_USER_PUB_KEY)!"
421 echo "error: '$SSH_USER_PUB_KEY' specified SSH public key file not found (SSH_USER_PUB_KEY)!"
422 exit 1
422 exit 1
423 fi
423 fi
424 fi
424 fi
425
425
426 # Check if all required packages are installed on the build system
426 # Check if all required packages are installed on the build system
427 for package in $REQUIRED_PACKAGES ; do
427 for package in $REQUIRED_PACKAGES ; do
428 if [ "$(dpkg-query -W -f='${Status}' $package)" != "install ok installed" ] ; then
428 if [ "$(dpkg-query -W -f='${Status}' $package)" != "install ok installed" ] ; then
429 MISSING_PACKAGES="${MISSING_PACKAGES} $package"
429 MISSING_PACKAGES="${MISSING_PACKAGES} $package"
430 fi
430 fi
431 done
431 done
432
432
433 # If there are missing packages ask confirmation for install, or exit
433 # If there are missing packages ask confirmation for install, or exit
434 if [ -n "$MISSING_PACKAGES" ] ; then
434 if [ -n "$MISSING_PACKAGES" ] ; then
435 echo "the following packages needed by this script are not installed:"
435 echo "the following packages needed by this script are not installed:"
436 echo "$MISSING_PACKAGES"
436 echo "$MISSING_PACKAGES"
437
437
438 printf "\ndo you want to install the missing packages right now? [y/n] "
438 printf "\ndo you want to install the missing packages right now? [y/n] "
439 read -r confirm
439 read -r confirm
440 [ "$confirm" != "y" ] && exit 1
440 [ "$confirm" != "y" ] && exit 1
441
441
442 # Make sure all missing required packages are installed
442 # Make sure all missing required packages are installed
443 apt-get -qq -y install "${MISSING_PACKAGES}"
443 apt-get -qq -y install "${MISSING_PACKAGES}"
444 fi
444 fi
445
445
446 # Check if ./bootstrap.d directory exists
446 # Check if ./bootstrap.d directory exists
447 if [ ! -d "./bootstrap.d/" ] ; then
447 if [ ! -d "./bootstrap.d/" ] ; then
448 echo "error: './bootstrap.d' required directory not found!"
448 echo "error: './bootstrap.d' required directory not found!"
449 exit 1
449 exit 1
450 fi
450 fi
451
451
452 # Check if ./files directory exists
452 # Check if ./files directory exists
453 if [ ! -d "./files/" ] ; then
453 if [ ! -d "./files/" ] ; then
454 echo "error: './files' required directory not found!"
454 echo "error: './files' required directory not found!"
455 exit 1
455 exit 1
456 fi
456 fi
457
457
458 # Check if specified KERNELSRC_DIR directory exists
458 # Check if specified KERNELSRC_DIR directory exists
459 if [ -n "$KERNELSRC_DIR" ] && [ ! -d "$KERNELSRC_DIR" ] ; then
459 if [ -n "$KERNELSRC_DIR" ] && [ ! -d "$KERNELSRC_DIR" ] ; then
460 echo "error: '${KERNELSRC_DIR}' specified directory not found (KERNELSRC_DIR)!"
460 echo "error: '${KERNELSRC_DIR}' specified directory not found (KERNELSRC_DIR)!"
461 exit 1
461 exit 1
462 fi
462 fi
463
463
464 # Check if specified UBOOTSRC_DIR directory exists
464 # Check if specified UBOOTSRC_DIR directory exists
465 if [ -n "$UBOOTSRC_DIR" ] && [ ! -d "$UBOOTSRC_DIR" ] ; then
465 if [ -n "$UBOOTSRC_DIR" ] && [ ! -d "$UBOOTSRC_DIR" ] ; then
466 echo "error: '${UBOOTSRC_DIR}' specified directory not found (UBOOTSRC_DIR)!"
466 echo "error: '${UBOOTSRC_DIR}' specified directory not found (UBOOTSRC_DIR)!"
467 exit 1
467 exit 1
468 fi
468 fi
469
469
470 # Check if specified VIDEOCORESRC_DIR directory exists
470 # Check if specified VIDEOCORESRC_DIR directory exists
471 if [ -n "$VIDEOCORESRC_DIR" ] && [ ! -d "$VIDEOCORESRC_DIR" ] ; then
471 if [ -n "$VIDEOCORESRC_DIR" ] && [ ! -d "$VIDEOCORESRC_DIR" ] ; then
472 echo "error: '${VIDEOCORESRC_DIR}' specified directory not found (VIDEOCORESRC_DIR)!"
472 echo "error: '${VIDEOCORESRC_DIR}' specified directory not found (VIDEOCORESRC_DIR)!"
473 exit 1
473 exit 1
474 fi
474 fi
475
475
476 # Check if specified FBTURBOSRC_DIR directory exists
476 # Check if specified FBTURBOSRC_DIR directory exists
477 if [ -n "$FBTURBOSRC_DIR" ] && [ ! -d "$FBTURBOSRC_DIR" ] ; then
477 if [ -n "$FBTURBOSRC_DIR" ] && [ ! -d "$FBTURBOSRC_DIR" ] ; then
478 echo "error: '${FBTURBOSRC_DIR}' specified directory not found (FBTURBOSRC_DIR)!"
478 echo "error: '${FBTURBOSRC_DIR}' specified directory not found (FBTURBOSRC_DIR)!"
479 exit 1
479 exit 1
480 fi
480 fi
481
481
482 # Check if specified CHROOT_SCRIPTS directory exists
482 # Check if specified CHROOT_SCRIPTS directory exists
483 if [ -n "$CHROOT_SCRIPTS" ] && [ ! -d "$CHROOT_SCRIPTS" ] ; then
483 if [ -n "$CHROOT_SCRIPTS" ] && [ ! -d "$CHROOT_SCRIPTS" ] ; then
484 echo "error: ${CHROOT_SCRIPTS} specified directory not found (CHROOT_SCRIPTS)!"
484 echo "error: ${CHROOT_SCRIPTS} specified directory not found (CHROOT_SCRIPTS)!"
485 exit 1
485 exit 1
486 fi
486 fi
487
487
488 # Check if specified device mapping already exists (will be used by cryptsetup)
488 # Check if specified device mapping already exists (will be used by cryptsetup)
489 if [ -r "/dev/mapping/${CRYPTFS_MAPPING}" ] ; then
489 if [ -r "/dev/mapping/${CRYPTFS_MAPPING}" ] ; then
490 echo "error: mapping /dev/mapping/${CRYPTFS_MAPPING} already exists, not proceeding"
490 echo "error: mapping /dev/mapping/${CRYPTFS_MAPPING} already exists, not proceeding"
491 exit 1
491 exit 1
492 fi
492 fi
493
493
494 # Don't clobber an old build
494 # Don't clobber an old build
495 if [ -e "$BUILDDIR" ] ; then
495 if [ -e "$BUILDDIR" ] ; then
496 echo "error: directory ${BUILDDIR} already exists, not proceeding"
496 echo "error: directory ${BUILDDIR} already exists, not proceeding"
497 exit 1
497 exit 1
498 fi
498 fi
499
499
500 # Setup chroot directory
500 # Setup chroot directory
501 mkdir -p "${R}"
501 mkdir -p "${R}"
502
502
503 # Check if build directory has enough of free disk space >512MB
503 # Check if build directory has enough of free disk space >512MB
504 if [ "$(df --output=avail "${BUILDDIR}" | sed "1d")" -le "524288" ] ; then
504 if [ "$(df --output=avail "${BUILDDIR}" | sed "1d")" -le "524288" ] ; then
505 echo "error: ${BUILDDIR} not enough space left to generate the output image!"
505 echo "error: ${BUILDDIR} not enough space left to generate the output image!"
506 exit 1
506 exit 1
507 fi
507 fi
508
508
509 set -x
509 set -x
510
510
511 # Call "cleanup" function on various signals and errors
511 # Call "cleanup" function on various signals and errors
512 trap cleanup 0 1 2 3 6
512 trap cleanup 0 1 2 3 6
513
513
514 # Add required packages for the minbase installation
514 # Add required packages for the minbase installation
515 if [ "$ENABLE_MINBASE" = true ] ; then
515 if [ "$ENABLE_MINBASE" = true ] ; then
516 APT_INCLUDES="${APT_INCLUDES},vim-tiny,netbase,net-tools,ifupdown"
516 APT_INCLUDES="${APT_INCLUDES},vim-tiny,netbase,net-tools,ifupdown"
517 fi
517 fi
518
518
519 # Add parted package, required to get partprobe utility
519 # Add parted package, required to get partprobe utility
520 if [ "$EXPANDROOT" = true ] ; then
520 if [ "$EXPANDROOT" = true ] ; then
521 APT_INCLUDES="${APT_INCLUDES},parted"
521 APT_INCLUDES="${APT_INCLUDES},parted"
522 fi
522 fi
523
523
524 # Add dbus package, recommended if using systemd
524 # Add dbus package, recommended if using systemd
525 if [ "$ENABLE_DBUS" = true ] ; then
525 if [ "$ENABLE_DBUS" = true ] ; then
526 APT_INCLUDES="${APT_INCLUDES},dbus"
526 APT_INCLUDES="${APT_INCLUDES},dbus"
527 fi
527 fi
528
528
529 # Add iptables IPv4/IPv6 package
529 # Add iptables IPv4/IPv6 package
530 if [ "$ENABLE_IPTABLES" = true ] ; then
530 if [ "$ENABLE_IPTABLES" = true ] ; then
531 APT_INCLUDES="${APT_INCLUDES},iptables,iptables-persistent"
531 APT_INCLUDES="${APT_INCLUDES},iptables,iptables-persistent"
532 fi
532 fi
533
533
534 # Add openssh server package
534 # Add openssh server package
535 if [ "$ENABLE_SSHD" = true ] ; then
535 if [ "$ENABLE_SSHD" = true ] ; then
536 APT_INCLUDES="${APT_INCLUDES},openssh-server"
536 APT_INCLUDES="${APT_INCLUDES},openssh-server"
537 fi
537 fi
538
538
539 # Add alsa-utils package
539 # Add alsa-utils package
540 if [ "$ENABLE_SOUND" = true ] ; then
540 if [ "$ENABLE_SOUND" = true ] ; then
541 APT_INCLUDES="${APT_INCLUDES},alsa-utils"
541 APT_INCLUDES="${APT_INCLUDES},alsa-utils"
542 fi
542 fi
543
543
544 # Add rng-tools package
544 # Add rng-tools package
545 if [ "$ENABLE_HWRANDOM" = true ] ; then
545 if [ "$ENABLE_HWRANDOM" = true ] ; then
546 APT_INCLUDES="${APT_INCLUDES},rng-tools"
546 APT_INCLUDES="${APT_INCLUDES},rng-tools"
547 fi
547 fi
548
548
549 # Add fbturbo video driver
549 # Add fbturbo video driver
550 if [ "$ENABLE_FBTURBO" = true ] ; then
550 if [ "$ENABLE_FBTURBO" = true ] ; then
551 # Enable xorg package dependencies
551 # Enable xorg package dependencies
552 ENABLE_XORG=true
552 ENABLE_XORG=true
553 fi
553 fi
554
554
555 # Add user defined window manager package
555 # Add user defined window manager package
556 if [ -n "$ENABLE_WM" ] ; then
556 if [ -n "$ENABLE_WM" ] ; then
557 APT_INCLUDES="${APT_INCLUDES},${ENABLE_WM}"
557 APT_INCLUDES="${APT_INCLUDES},${ENABLE_WM}"
558
558
559 # Enable xorg package dependencies
559 # Enable xorg package dependencies
560 ENABLE_XORG=true
560 ENABLE_XORG=true
561 fi
561 fi
562
562
563 # Add xorg package
563 # Add xorg package
564 if [ "$ENABLE_XORG" = true ] ; then
564 if [ "$ENABLE_XORG" = true ] ; then
565 APT_INCLUDES="${APT_INCLUDES},xorg,dbus-x11"
565 APT_INCLUDES="${APT_INCLUDES},xorg,dbus-x11"
566 fi
566 fi
567
567
568 # Replace selected packages with smaller clones
568 # Replace selected packages with smaller clones
569 if [ "$ENABLE_REDUCE" = true ] ; then
569 if [ "$ENABLE_REDUCE" = true ] ; then
570 # Add levee package instead of vim-tiny
570 # Add levee package instead of vim-tiny
571 if [ "$REDUCE_VIM" = true ] ; then
571 if [ "$REDUCE_VIM" = true ] ; then
572 APT_INCLUDES="$(echo ${APT_INCLUDES} | sed "s/vim-tiny/levee/")"
572 APT_INCLUDES="$(echo ${APT_INCLUDES} | sed "s/vim-tiny/levee/")"
573 fi
573 fi
574
574
575 # Add dropbear package instead of openssh-server
575 # Add dropbear package instead of openssh-server
576 if [ "$REDUCE_SSHD" = true ] ; then
576 if [ "$REDUCE_SSHD" = true ] ; then
577 APT_INCLUDES="$(echo "${APT_INCLUDES}" | sed "s/openssh-server/dropbear/")"
577 APT_INCLUDES="$(echo "${APT_INCLUDES}" | sed "s/openssh-server/dropbear/")"
578 fi
578 fi
579 fi
579 fi
580
580
581 # Configure kernel sources if no KERNELSRC_DIR
581 # Configure kernel sources if no KERNELSRC_DIR
582 if [ "$BUILD_KERNEL" = true ] && [ -z "$KERNELSRC_DIR" ] ; then
582 if [ "$BUILD_KERNEL" = true ] && [ -z "$KERNELSRC_DIR" ] ; then
583 KERNELSRC_CONFIG=true
583 KERNELSRC_CONFIG=true
584 fi
584 fi
585
585
586 # Configure reduced kernel
586 # Configure reduced kernel
587 if [ "$KERNEL_REDUCE" = true ] ; then
587 if [ "$KERNEL_REDUCE" = true ] ; then
588 KERNELSRC_CONFIG=false
588 KERNELSRC_CONFIG=false
589 fi
589 fi
590
590
591 # Configure qemu compatible kernel
591 # Configure qemu compatible kernel
592 if [ "$ENABLE_QEMU" = true ] ; then
592 if [ "$ENABLE_QEMU" = true ] ; then
593 DTB_FILE=vexpress-v2p-ca15_a7.dtb
593 DTB_FILE=vexpress-v2p-ca15_a7.dtb
594 UBOOT_CONFIG=vexpress_ca15_tc2_defconfig
594 UBOOT_CONFIG=vexpress_ca15_tc2_defconfig
595 KERNEL_DEFCONFIG="vexpress_defconfig"
595 KERNEL_DEFCONFIG="vexpress_defconfig"
596 if [ "$KERNEL_MENUCONFIG" = false ] ; then
596 if [ "$KERNEL_MENUCONFIG" = false ] ; then
597 KERNEL_OLDDEFCONFIG=true
597 KERNEL_OLDDEFCONFIG=true
598 fi
598 fi
599 fi
599 fi
600
600
601 # Execute bootstrap scripts
601 # Execute bootstrap scripts
602 for SCRIPT in bootstrap.d/*.sh; do
602 for SCRIPT in bootstrap.d/*.sh; do
603 head -n 3 "$SCRIPT"
603 head -n 3 "$SCRIPT"
604 . "$SCRIPT"
604 . "$SCRIPT"
605 done
605 done
606
606
607 ## Execute custom bootstrap scripts
607 ## Execute custom bootstrap scripts
608 if [ -d "custom.d" ] ; then
608 if [ -d "custom.d" ] ; then
609 for SCRIPT in custom.d/*.sh; do
609 for SCRIPT in custom.d/*.sh; do
610 . "$SCRIPT"
610 . "$SCRIPT"
611 done
611 done
612 fi
612 fi
613
613
614 # Execute custom scripts inside the chroot
614 # Execute custom scripts inside the chroot
615 if [ -n "$CHROOT_SCRIPTS" ] && [ -d "$CHROOT_SCRIPTS" ] ; then
615 if [ -n "$CHROOT_SCRIPTS" ] && [ -d "$CHROOT_SCRIPTS" ] ; then
616 cp -r "${CHROOT_SCRIPTS}" "${R}/chroot_scripts"
616 cp -r "${CHROOT_SCRIPTS}" "${R}/chroot_scripts"
617 chroot_exec /bin/bash -x <<'EOF'
617 chroot_exec /bin/bash -x <<'EOF'
618 for SCRIPT in /chroot_scripts/* ; do
618 for SCRIPT in /chroot_scripts/* ; do
619 if [ -f $SCRIPT -a -x $SCRIPT ] ; then
619 if [ -f $SCRIPT -a -x $SCRIPT ] ; then
620 $SCRIPT
620 $SCRIPT
621 fi
621 fi
622 done
622 done
623 EOF
623 EOF
624 rm -rf "${R}/chroot_scripts"
624 rm -rf "${R}/chroot_scripts"
625 fi
625 fi
626
626
627 # Remove c/c++ build environment from the chroot
627 # Remove c/c++ build environment from the chroot
628 chroot_remove_cc
628 chroot_remove_cc
629
629
630 # Generate required machine-id
630 # Generate required machine-id
631 MACHINE_ID=$(dbus-uuidgen)
631 MACHINE_ID=$(dbus-uuidgen)
632 echo -n "${MACHINE_ID}" > "${R}/var/lib/dbus/machine-id"
632 echo -n "${MACHINE_ID}" > "${R}/var/lib/dbus/machine-id"
633 echo -n "${MACHINE_ID}" > "${ETC_DIR}/machine-id"
633 echo -n "${MACHINE_ID}" > "${ETC_DIR}/machine-id"
634
634
635 # APT Cleanup
635 # APT Cleanup
636 chroot_exec apt-get -y clean
636 chroot_exec apt-get -y clean
637 chroot_exec apt-get -y autoclean
637 chroot_exec apt-get -y autoclean
638 chroot_exec apt-get -y autoremove
638 chroot_exec apt-get -y autoremove
639
639
640 # Unmount mounted filesystems
640 # Unmount mounted filesystems
641 umount -l "${R}/proc"
641 umount -l "${R}/proc"
642 umount -l "${R}/sys"
642 umount -l "${R}/sys"
643
643
644 # Clean up directories
644 # Clean up directories
645 rm -rf "${R}/run/*"
645 rm -rf "${R}/run/*"
646 rm -rf "${R}/tmp/*"
646 rm -rf "${R}/tmp/*"
647
647
648 # Clean up files
648 # Clean up files
649 rm -f "${ETC_DIR}/ssh/ssh_host_*"
649 rm -f "${ETC_DIR}/ssh/ssh_host_*"
650 rm -f "${ETC_DIR}/dropbear/dropbear_*"
650 rm -f "${ETC_DIR}/dropbear/dropbear_*"
651 rm -f "${ETC_DIR}/apt/sources.list.save"
651 rm -f "${ETC_DIR}/apt/sources.list.save"
652 rm -f "${ETC_DIR}/resolvconf/resolv.conf.d/original"
652 rm -f "${ETC_DIR}/resolvconf/resolv.conf.d/original"
653 rm -f "${ETC_DIR}/*-"
653 rm -f "${ETC_DIR}/*-"
654 rm -f "${ETC_DIR}/apt/apt.conf.d/10proxy"
654 rm -f "${ETC_DIR}/apt/apt.conf.d/10proxy"
655 rm -f "${ETC_DIR}/resolv.conf"
655 rm -f "${ETC_DIR}/resolv.conf"
656 rm -f "${R}/root/.bash_history"
656 rm -f "${R}/root/.bash_history"
657 rm -f "${R}/var/lib/urandom/random-seed"
657 rm -f "${R}/var/lib/urandom/random-seed"
658 rm -f "${R}/initrd.img"
658 rm -f "${R}/initrd.img"
659 rm -f "${R}/vmlinuz"
659 rm -f "${R}/vmlinuz"
660 rm -f "${R}${QEMU_BINARY}"
660 rm -f "${R}${QEMU_BINARY}"
661
661
662 if [ "$ENABLE_QEMU" = true ] ; then
662 if [ "$ENABLE_QEMU" = true ] ; then
663 # Setup QEMU directory
663 # Setup QEMU directory
664 mkdir "${BASEDIR}/qemu"
664 mkdir "${BASEDIR}/qemu"
665
665
666 # Copy kernel image to QEMU directory
666 # Copy kernel image to QEMU directory
667 install_readonly "${BOOT_DIR}/${KERNEL_IMAGE}" "${BASEDIR}/qemu/${KERNEL_IMAGE}"
667 install_readonly "${BOOT_DIR}/${KERNEL_IMAGE}" "${BASEDIR}/qemu/${KERNEL_IMAGE}"
668
668
669 # Copy kernel config to QEMU directory
669 # Copy kernel config to QEMU directory
670 install_readonly "${R}/boot/config-${KERNEL_VERSION}" "${BASEDIR}/qemu/config-${KERNEL_VERSION}"
670 install_readonly "${R}/boot/config-${KERNEL_VERSION}" "${BASEDIR}/qemu/config-${KERNEL_VERSION}"
671
671
672 # Copy kernel dtbs to QEMU directory
672 # Copy kernel dtbs to QEMU directory
673 for dtb in "${BOOT_DIR}/"*.dtb ; do
673 for dtb in "${BOOT_DIR}/"*.dtb ; do
674 if [ -f "${dtb}" ] ; then
674 if [ -f "${dtb}" ] ; then
675 install_readonly "${dtb}" "${BASEDIR}/qemu/"
675 install_readonly "${dtb}" "${BASEDIR}/qemu/"
676 fi
676 fi
677 done
677 done
678
678
679 # Copy kernel overlays to QEMU directory
679 # Copy kernel overlays to QEMU directory
680 if [ -d "${BOOT_DIR}/overlays" ] ; then
680 if [ -d "${BOOT_DIR}/overlays" ] ; then
681 # Setup overlays dtbs directory
681 # Setup overlays dtbs directory
682 mkdir "${BASEDIR}/qemu/overlays"
682 mkdir "${BASEDIR}/qemu/overlays"
683
683
684 for dtb in "${BOOT_DIR}/overlays/"*.dtb ; do
684 for dtb in "${BOOT_DIR}/overlays/"*.dtb ; do
685 if [ -f "${dtb}" ] ; then
685 if [ -f "${dtb}" ] ; then
686 install_readonly "${dtb}" "${BASEDIR}/qemu/overlays/"
686 install_readonly "${dtb}" "${BASEDIR}/qemu/overlays/"
687 fi
687 fi
688 done
688 done
689 fi
689 fi
690
690
691 # Copy u-boot files to QEMU directory
691 # Copy u-boot files to QEMU directory
692 if [ "$ENABLE_UBOOT" = true ] ; then
692 if [ "$ENABLE_UBOOT" = true ] ; then
693 if [ -f "${BOOT_DIR}/u-boot.bin" ] ; then
693 if [ -f "${BOOT_DIR}/u-boot.bin" ] ; then
694 install_readonly "${BOOT_DIR}/u-boot.bin" "${BASEDIR}/qemu/u-boot.bin"
694 install_readonly "${BOOT_DIR}/u-boot.bin" "${BASEDIR}/qemu/u-boot.bin"
695 fi
695 fi
696 if [ -f "${BOOT_DIR}/uboot.mkimage" ] ; then
696 if [ -f "${BOOT_DIR}/uboot.mkimage" ] ; then
697 install_readonly "${BOOT_DIR}/uboot.mkimage" "${BASEDIR}/qemu/uboot.mkimage"
697 install_readonly "${BOOT_DIR}/uboot.mkimage" "${BASEDIR}/qemu/uboot.mkimage"
698 fi
698 fi
699 if [ -f "${BOOT_DIR}/boot.scr" ] ; then
699 if [ -f "${BOOT_DIR}/boot.scr" ] ; then
700 install_readonly "${BOOT_DIR}/boot.scr" "${BASEDIR}/qemu/boot.scr"
700 install_readonly "${BOOT_DIR}/boot.scr" "${BASEDIR}/qemu/boot.scr"
701 fi
701 fi
702 fi
702 fi
703
703
704 # Copy initramfs to QEMU directory
704 # Copy initramfs to QEMU directory
705 if [ -f "${BOOT_DIR}/initramfs-${KERNEL_VERSION}" ] ; then
705 if [ -f "${BOOT_DIR}/initramfs-${KERNEL_VERSION}" ] ; then
706 install_readonly "${BOOT_DIR}/initramfs-${KERNEL_VERSION}" "${BASEDIR}/qemu/initramfs-${KERNEL_VERSION}"
706 install_readonly "${BOOT_DIR}/initramfs-${KERNEL_VERSION}" "${BASEDIR}/qemu/initramfs-${KERNEL_VERSION}"
707 fi
707 fi
708 fi
708 fi
709
709
710 # Calculate size of the chroot directory in KB
710 # Calculate size of the chroot directory in KB
711 CHROOT_SIZE=$(expr "$(du -s "${R}" | awk '{ print $1 }')")
711 CHROOT_SIZE=$(expr "$(du -s "${R}" | awk '{ print $1 }')")
712
712
713 # Calculate the amount of needed 512 Byte sectors
713 # Calculate the amount of needed 512 Byte sectors
714 TABLE_SECTORS=$(expr 1 \* 1024 \* 1024 \/ 512)
714 TABLE_SECTORS=$(expr 1 \* 1024 \* 1024 \/ 512)
715 FRMW_SECTORS=$(expr 64 \* 1024 \* 1024 \/ 512)
715 FRMW_SECTORS=$(expr 64 \* 1024 \* 1024 \/ 512)
716 ROOT_OFFSET=$(expr "${TABLE_SECTORS}" + "${FRMW_SECTORS}")
716 ROOT_OFFSET=$(expr "${TABLE_SECTORS}" + "${FRMW_SECTORS}")
717
717
718 # The root partition is EXT4
718 # The root partition is EXT4
719 # This means more space than the actual used space of the chroot is used.
719 # This means more space than the actual used space of the chroot is used.
720 # As overhead for journaling and reserved blocks 35% are added.
720 # As overhead for journaling and reserved blocks 35% are added.
721 ROOT_SECTORS=$(expr "$(expr "${CHROOT_SIZE}" + "${CHROOT_SIZE}" \/ 100 \* 35)" \* 1024 \/ 512)
721 ROOT_SECTORS=$(expr "$(expr "${CHROOT_SIZE}" + "${CHROOT_SIZE}" \/ 100 \* 35)" \* 1024 \/ 512)
722
722
723 # Calculate required image size in 512 Byte sectors
723 # Calculate required image size in 512 Byte sectors
724 IMAGE_SECTORS=$(expr "${TABLE_SECTORS}" + "${FRMW_SECTORS}" + "${ROOT_SECTORS}")
724 IMAGE_SECTORS=$(expr "${TABLE_SECTORS}" + "${FRMW_SECTORS}" + "${ROOT_SECTORS}")
725
725
726 # Prepare image file
726 # Prepare image file
727 if [ "$ENABLE_SPLITFS" = true ] ; then
727 if [ "$ENABLE_SPLITFS" = true ] ; then
728 dd if=/dev/zero of="$IMAGE_NAME-frmw.img" bs=512 count="${TABLE_SECTORS}"
728 dd if=/dev/zero of="$IMAGE_NAME-frmw.img" bs=512 count="${TABLE_SECTORS}"
729 dd if=/dev/zero of="$IMAGE_NAME-frmw.img" bs=512 count=0 seek="${FRMW_SECTORS}"
729 dd if=/dev/zero of="$IMAGE_NAME-frmw.img" bs=512 count=0 seek="${FRMW_SECTORS}"
730 dd if=/dev/zero of="$IMAGE_NAME-root.img" bs=512 count="${TABLE_SECTORS}"
730 dd if=/dev/zero of="$IMAGE_NAME-root.img" bs=512 count="${TABLE_SECTORS}"
731 dd if=/dev/zero of="$IMAGE_NAME-root.img" bs=512 count=0 seek="${ROOT_SECTORS}"
731 dd if=/dev/zero of="$IMAGE_NAME-root.img" bs=512 count=0 seek="${ROOT_SECTORS}"
732
732
733 # Write firmware/boot partition tables
733 # Write firmware/boot partition tables
734 sfdisk -q -L -uS -f "$IMAGE_NAME-frmw.img" 2> /dev/null <<EOM
734 sfdisk -q -L -uS -f "$IMAGE_NAME-frmw.img" 2> /dev/null <<EOM
735 ${TABLE_SECTORS},${FRMW_SECTORS},c,*
735 ${TABLE_SECTORS},${FRMW_SECTORS},c,*
736 EOM
736 EOM
737
737
738 # Write root partition table
738 # Write root partition table
739 sfdisk -q -L -uS -f "$IMAGE_NAME-root.img" 2> /dev/null <<EOM
739 sfdisk -q -L -uS -f "$IMAGE_NAME-root.img" 2> /dev/null <<EOM
740 ${TABLE_SECTORS},${ROOT_SECTORS},83
740 ${TABLE_SECTORS},${ROOT_SECTORS},83
741 EOM
741 EOM
742
742
743 # Setup temporary loop devices
743 # Setup temporary loop devices
744 FRMW_LOOP="$(losetup -o 1M --sizelimit 64M -f --show "$IMAGE_NAME"-frmw.img)"
744 FRMW_LOOP="$(losetup -o 1M --sizelimit 64M -f --show "$IMAGE_NAME"-frmw.img)"
745 ROOT_LOOP="$(losetup -o 1M -f --show "$IMAGE_NAME"-root.img)"
745 ROOT_LOOP="$(losetup -o 1M -f --show "$IMAGE_NAME"-root.img)"
746 else # ENABLE_SPLITFS=false
746 else # ENABLE_SPLITFS=false
747 dd if=/dev/zero of="$IMAGE_NAME.img" bs=512 count="${TABLE_SECTORS}"
747 dd if=/dev/zero of="$IMAGE_NAME.img" bs=512 count="${TABLE_SECTORS}"
748 dd if=/dev/zero of="$IMAGE_NAME.img" bs=512 count=0 seek="${IMAGE_SECTORS}"
748 dd if=/dev/zero of="$IMAGE_NAME.img" bs=512 count=0 seek="${IMAGE_SECTORS}"
749
749
750 # Write partition table
750 # Write partition table
751 sfdisk -q -L -uS -f "$IMAGE_NAME.img" 2> /dev/null <<EOM
751 sfdisk -q -L -uS -f "$IMAGE_NAME.img" 2> /dev/null <<EOM
752 ${TABLE_SECTORS},${FRMW_SECTORS},c,*
752 ${TABLE_SECTORS},${FRMW_SECTORS},c,*
753 ${ROOT_OFFSET},${ROOT_SECTORS},83
753 ${ROOT_OFFSET},${ROOT_SECTORS},83
754 EOM
754 EOM
755
755
756 # Setup temporary loop devices
756 # Setup temporary loop devices
757 FRMW_LOOP="$(losetup -o 1M --sizelimit 64M -f --show "$IMAGE_NAME".img)"
757 FRMW_LOOP="$(losetup -o 1M --sizelimit 64M -f --show "$IMAGE_NAME".img)"
758 ROOT_LOOP="$(losetup -o 65M -f --show "$IMAGE_NAME".img)"
758 ROOT_LOOP="$(losetup -o 65M -f --show "$IMAGE_NAME".img)"
759 fi
759 fi
760
760
761 if [ "$ENABLE_CRYPTFS" = true ] ; then
761 if [ "$ENABLE_CRYPTFS" = true ] ; then
762 # Create dummy ext4 fs
762 # Create dummy ext4 fs
763 mkfs.ext4 "$ROOT_LOOP"
763 mkfs.ext4 "$ROOT_LOOP"
764
764
765 # Setup password keyfile
765 # Setup password keyfile
766 touch .password
766 touch .password
767 chmod 600 .password
767 chmod 600 .password
768 echo -n ${CRYPTFS_PASSWORD} > .password
768 echo -n ${CRYPTFS_PASSWORD} > .password
769
769
770 # Initialize encrypted partition
770 # Initialize encrypted partition
771 echo "YES" | cryptsetup luksFormat "${ROOT_LOOP}" -c "${CRYPTFS_CIPHER}" -s "${CRYPTFS_XTSKEYSIZE}" .password
771 echo "YES" | cryptsetup luksFormat "${ROOT_LOOP}" -c "${CRYPTFS_CIPHER}" -s "${CRYPTFS_XTSKEYSIZE}" .password
772
772
773 # Open encrypted partition and setup mapping
773 # Open encrypted partition and setup mapping
774 cryptsetup luksOpen "${ROOT_LOOP}" -d .password "${CRYPTFS_MAPPING}"
774 cryptsetup luksOpen "${ROOT_LOOP}" -d .password "${CRYPTFS_MAPPING}"
775
775
776 # Secure delete password keyfile
776 # Secure delete password keyfile
777 shred -zu .password
777 shred -zu .password
778
778
779 # Update temporary loop device
779 # Update temporary loop device
780 ROOT_LOOP="/dev/mapper/${CRYPTFS_MAPPING}"
780 ROOT_LOOP="/dev/mapper/${CRYPTFS_MAPPING}"
781
781
782 # Wipe encrypted partition (encryption cipher is used for randomness)
782 # Wipe encrypted partition (encryption cipher is used for randomness)
783 dd if=/dev/zero of="${ROOT_LOOP}" bs=512 count="$(blockdev --getsz "${ROOT_LOOP}")"
783 dd if=/dev/zero of="${ROOT_LOOP}" bs=512 count="$(blockdev --getsz "${ROOT_LOOP}")"
784 fi
784 fi
785
785
786 # Build filesystems
786 # Build filesystems
787 mkfs.vfat "$FRMW_LOOP"
787 mkfs.vfat "$FRMW_LOOP"
788 mkfs.ext4 "$ROOT_LOOP"
788 mkfs.ext4 "$ROOT_LOOP"
789
789
790 # Mount the temporary loop devices
790 # Mount the temporary loop devices
791 mkdir -p "$BUILDDIR/mount"
791 mkdir -p "$BUILDDIR/mount"
792 mount "$ROOT_LOOP" "$BUILDDIR/mount"
792 mount "$ROOT_LOOP" "$BUILDDIR/mount"
793
793
794 mkdir -p "$BUILDDIR/mount/boot/firmware"
794 mkdir -p "$BUILDDIR/mount/boot/firmware"
795 mount "$FRMW_LOOP" "$BUILDDIR/mount/boot/firmware"
795 mount "$FRMW_LOOP" "$BUILDDIR/mount/boot/firmware"
796
796
797 # Copy all files from the chroot to the loop device mount point directory
797 # Copy all files from the chroot to the loop device mount point directory
798 rsync -a "${R}/" "$BUILDDIR/mount/"
798 rsync -a "${R}/" "$BUILDDIR/mount/"
799
799
800 # Unmount all temporary loop devices and mount points
800 # Unmount all temporary loop devices and mount points
801 cleanup
801 cleanup
802
802
803 # Create block map file(s) of image(s)
803 # Create block map file(s) of image(s)
804 if [ "$ENABLE_SPLITFS" = true ] ; then
804 if [ "$ENABLE_SPLITFS" = true ] ; then
805 # Create block map files for "bmaptool"
805 # Create block map files for "bmaptool"
806 bmaptool create -o "$IMAGE_NAME-frmw.bmap" "$IMAGE_NAME-frmw.img"
806 bmaptool create -o "$IMAGE_NAME-frmw.bmap" "$IMAGE_NAME-frmw.img"
807 bmaptool create -o "$IMAGE_NAME-root.bmap" "$IMAGE_NAME-root.img"
807 bmaptool create -o "$IMAGE_NAME-root.bmap" "$IMAGE_NAME-root.img"
808
808
809 # Image was successfully created
809 # Image was successfully created
810 echo "$IMAGE_NAME-frmw.img ($(expr \( "${TABLE_SECTORS}" + "${FRMW_SECTORS}" \) \* 512 \/ 1024 \/ 1024)M)" ": successfully created"
810 echo "$IMAGE_NAME-frmw.img ($(expr \( "${TABLE_SECTORS}" + "${FRMW_SECTORS}" \) \* 512 \/ 1024 \/ 1024)M)" ": successfully created"
811 echo "$IMAGE_NAME-root.img ($(expr \( "${TABLE_SECTORS}" + "${ROOT_SECTORS}" \) \* 512 \/ 1024 \/ 1024)M)" ": successfully created"
811 echo "$IMAGE_NAME-root.img ($(expr \( "${TABLE_SECTORS}" + "${ROOT_SECTORS}" \) \* 512 \/ 1024 \/ 1024)M)" ": successfully created"
812 else
812 else
813 # Create block map file for "bmaptool"
813 # Create block map file for "bmaptool"
814 bmaptool create -o "$IMAGE_NAME.bmap" "$IMAGE_NAME.img"
814 bmaptool create -o "$IMAGE_NAME.bmap" "$IMAGE_NAME.img"
815
815
816 # Image was successfully created
816 # Image was successfully created
817 echo "$IMAGE_NAME.img ($(expr \( "${TABLE_SECTORS}" + "${FRMW_SECTORS}" + "${ROOT_SECTORS}" \) \* 512 \/ 1024 \/ 1024)M)" ": successfully created"
817 echo "$IMAGE_NAME.img ($(expr \( "${TABLE_SECTORS}" + "${FRMW_SECTORS}" + "${ROOT_SECTORS}" \) \* 512 \/ 1024 \/ 1024)M)" ": successfully created"
818
818
819 # Create qemu qcow2 image
819 # Create qemu qcow2 image
820 if [ "$ENABLE_QEMU" = true ] ; then
820 if [ "$ENABLE_QEMU" = true ] ; then
821 QEMU_IMAGE=${QEMU_IMAGE:=${BASEDIR}/qemu/${DATE}-${KERNEL_ARCH}-CURRENT-rpi${RPI_MODEL}-${RELEASE}-${RELEASE_ARCH}}
821 QEMU_IMAGE=${QEMU_IMAGE:=${BASEDIR}/qemu/${DATE}-${KERNEL_ARCH}-CURRENT-rpi${RPI_MODEL}-${RELEASE}-${RELEASE_ARCH}}
822 QEMU_SIZE=16G
822 QEMU_SIZE=16G
823
823
824 qemu-img convert -f raw -O qcow2 "$IMAGE_NAME".img "$QEMU_IMAGE".qcow2
824 qemu-img convert -f raw -O qcow2 "$IMAGE_NAME".img "$QEMU_IMAGE".qcow2
825 qemu-img resize "$QEMU_IMAGE".qcow2 $QEMU_SIZE
825 qemu-img resize "$QEMU_IMAGE".qcow2 $QEMU_SIZE
826
826
827 echo "$QEMU_IMAGE.qcow2 ($QEMU_SIZE)" ": successfully created"
827 echo "$QEMU_IMAGE.qcow2 ($QEMU_SIZE)" ": successfully created"
828 fi
828 fi
829 fi
829 fi
General Comments 0
Vous devez vous connecter pour laisser un commentaire. Se connecter maintenant