Ship yay, wire up LUKS disk encryption, self-signed Secure Boot, release signing
yay (yay-bin, AUR-only like calamares/bibata) republished to [breadway] via the same PKGBUILD + Forgejo workflow pattern, so users can reach the wider AUR beyond bakery's bread ecosystem. Disk encryption: Calamares' partition module already has LUKS support enabled by default, but the checkbox led nowhere — no cryptsetup on the live/target image, no mkinitcpio encrypt hook, no GRUB cryptodisk wiring. An encrypted install would partition fine and then never boot. Added cryptsetup, pinned luksGeneration to luks1 (GRUB doesn't support LUKS2 + Argon2id), and post-install.sh now detects an encrypted root (lsblk TYPE == crypt) and conditionally adds the encrypt hook + GRUB_ENABLE_CRYPTODISK + --modules="cryptodisk luks luks2" on both grub-install passes. No effect on a normal unencrypted install. Secure Boot: self-signed via sbctl (shipped in packages.x86_64). BOS can't ship a Microsoft-signed shim without going through Microsoft's own paid UEFI CA process, so post-install.sh enrolls BOS's own keys automatically only when the firmware is already in Setup Mode (sbctl status --json), signs the kernel/bootloader, and leaves it alone otherwise — sbctl's own pacman hook re-signs on every future kernel/GRUB update, no further wiring needed. Release signing: generated a dedicated Ed25519 "BOS Release Signing" key (not reused from anything else), stored as the GPG_PRIVATE_KEY Forgejo Actions secret. release-iso.yml now generates SHA256SUMS and a detached SHA256SUMS.asc signature alongside every ISO upload; public key committed at KEYS.asc with verification instructions in the README. README updated: fixed a stale "greetd + tuigreet" line (breadgreet since round 3), documented yay/encryption/secure-boot/verification.
This commit is contained in:
parent
489d472240
commit
5aaf71e80a
8 changed files with 282 additions and 35 deletions
40
packaging/yay-bin/PKGBUILD
Normal file
40
packaging/yay-bin/PKGBUILD
Normal file
|
|
@ -0,0 +1,40 @@
|
|||
# BOS in-house rebuild of yay-bin (AUR-only upstream — no AUR helper is in
|
||||
# the official Arch repos, including yay itself). Republished to the
|
||||
# [breadway] repo so the ISO build can pull it via pacman (same pattern as
|
||||
# bibata-cursor-theme and calamares). Prebuilt release tarball — no build step.
|
||||
# Upstream maintainer: Jguer <pkgbuilds at jguer.space>
|
||||
pkgname=yay-bin
|
||||
pkgver=13.0.1
|
||||
pkgrel=1
|
||||
pkgdesc="Yet another yogurt. Pacman wrapper and AUR helper written in go. Pre-compiled."
|
||||
arch=('x86_64')
|
||||
url="https://github.com/Jguer/yay"
|
||||
license=('GPL-3.0-or-later')
|
||||
depends=(
|
||||
'pacman>6.1'
|
||||
'git'
|
||||
)
|
||||
optdepends=(
|
||||
'sudo: privilege elevation'
|
||||
'doas: privilege elevation'
|
||||
)
|
||||
provides=('yay')
|
||||
conflicts=('yay')
|
||||
|
||||
source=("https://github.com/Jguer/yay/releases/download/v${pkgver}/${pkgname/-bin/}_${pkgver}_x86_64.tar.gz")
|
||||
sha256sums=('1fdfcb5f7f387bc858d3a5754bdf4e4575bfbddac9560535a716d0ed7189c057')
|
||||
|
||||
package() {
|
||||
_output="${srcdir}/${pkgname/-bin/}_${pkgver}_${CARCH}"
|
||||
install -Dm755 "${_output}/${pkgname/-bin/}" "${pkgdir}/usr/bin/${pkgname/-bin/}"
|
||||
install -Dm644 "${_output}/yay.8" "${pkgdir}/usr/share/man/man8/yay.8"
|
||||
|
||||
install -Dm644 "${_output}/bash" "${pkgdir}/usr/share/bash-completion/completions/yay"
|
||||
install -Dm644 "${_output}/zsh" "${pkgdir}/usr/share/zsh/site-functions/_yay"
|
||||
install -Dm644 "${_output}/fish" "${pkgdir}/usr/share/fish/vendor_completions.d/yay.fish"
|
||||
|
||||
LANGS="ca cs de en es eu fr_FR he id it_IT ja ko pl_PL pt_BR pt ru_RU ru sv tr uk zh_CN zh_TW"
|
||||
for lang in ${LANGS}; do
|
||||
install -Dm644 "${_output}/${lang}.mo" "${pkgdir}/usr/share/locale/${lang}/LC_MESSAGES/yay.mo"
|
||||
done
|
||||
}
|
||||
Loading…
Add table
Add a link
Reference in a new issue