Ship yay, wire up LUKS disk encryption, self-signed Secure Boot, release signing
yay (yay-bin, AUR-only like calamares/bibata) republished to [breadway] via the same PKGBUILD + Forgejo workflow pattern, so users can reach the wider AUR beyond bakery's bread ecosystem. Disk encryption: Calamares' partition module already has LUKS support enabled by default, but the checkbox led nowhere — no cryptsetup on the live/target image, no mkinitcpio encrypt hook, no GRUB cryptodisk wiring. An encrypted install would partition fine and then never boot. Added cryptsetup, pinned luksGeneration to luks1 (GRUB doesn't support LUKS2 + Argon2id), and post-install.sh now detects an encrypted root (lsblk TYPE == crypt) and conditionally adds the encrypt hook + GRUB_ENABLE_CRYPTODISK + --modules="cryptodisk luks luks2" on both grub-install passes. No effect on a normal unencrypted install. Secure Boot: self-signed via sbctl (shipped in packages.x86_64). BOS can't ship a Microsoft-signed shim without going through Microsoft's own paid UEFI CA process, so post-install.sh enrolls BOS's own keys automatically only when the firmware is already in Setup Mode (sbctl status --json), signs the kernel/bootloader, and leaves it alone otherwise — sbctl's own pacman hook re-signs on every future kernel/GRUB update, no further wiring needed. Release signing: generated a dedicated Ed25519 "BOS Release Signing" key (not reused from anything else), stored as the GPG_PRIVATE_KEY Forgejo Actions secret. release-iso.yml now generates SHA256SUMS and a detached SHA256SUMS.asc signature alongside every ISO upload; public key committed at KEYS.asc with verification instructions in the README. README updated: fixed a stale "greetd + tuigreet" line (breadgreet since round 3), documented yay/encryption/secure-boot/verification.
This commit is contained in:
parent
489d472240
commit
5aaf71e80a
8 changed files with 282 additions and 35 deletions
|
|
@ -30,6 +30,15 @@ efibootmgr
|
|||
btrfs-progs
|
||||
dosfstools
|
||||
mtools
|
||||
# LUKS full-disk encryption — Calamares' partition module has encryption
|
||||
# support built in and enabled by default, but needs cryptsetup actually
|
||||
# present (live, to create the container; installed, to unlock at boot via
|
||||
# mkinitcpio's encrypt hook) or the checkbox leads to an unbootable system.
|
||||
cryptsetup
|
||||
# Secure Boot key enrollment/signing (self-signed — see post-install.sh).
|
||||
# Ships its own pacman hook (zz-sbctl.hook) that re-signs the kernel/
|
||||
# bootloader automatically on every future update once enrolled.
|
||||
sbctl
|
||||
# squashfs-tools: provides unsquashfs, which Calamares' unpackfs module uses
|
||||
# to extract airootfs.sfs onto the target during install.
|
||||
squashfs-tools
|
||||
|
|
@ -161,6 +170,12 @@ mailcap
|
|||
# (calamares 3.4.x is already Qt6; there is no separate calamares-qt6 package)
|
||||
calamares
|
||||
|
||||
# AUR helper — yay-bin is AUR-only (no AUR helper ships in the official
|
||||
# repos), so it's republished to [breadway] the same way (see
|
||||
# packaging/yay-bin). Lets users reach the wider AUR beyond bakery's bread
|
||||
# ecosystem + [breadway]'s own small set of republished packages.
|
||||
yay-bin
|
||||
|
||||
# Bread ecosystem.
|
||||
#
|
||||
# The bread apps themselves (bakery, bread, breadbar, breadbox, breadcrumbs,
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue