bos/iso/airootfs/etc
Breadway 5aaf71e80a Ship yay, wire up LUKS disk encryption, self-signed Secure Boot, release signing
yay (yay-bin, AUR-only like calamares/bibata) republished to [breadway] via
the same PKGBUILD + Forgejo workflow pattern, so users can reach the wider
AUR beyond bakery's bread ecosystem.

Disk encryption: Calamares' partition module already has LUKS support
enabled by default, but the checkbox led nowhere — no cryptsetup on the
live/target image, no mkinitcpio encrypt hook, no GRUB cryptodisk wiring.
An encrypted install would partition fine and then never boot. Added
cryptsetup, pinned luksGeneration to luks1 (GRUB doesn't support LUKS2 +
Argon2id), and post-install.sh now detects an encrypted root (lsblk TYPE
== crypt) and conditionally adds the encrypt hook + GRUB_ENABLE_CRYPTODISK +
--modules="cryptodisk luks luks2" on both grub-install passes. No effect on
a normal unencrypted install.

Secure Boot: self-signed via sbctl (shipped in packages.x86_64). BOS can't
ship a Microsoft-signed shim without going through Microsoft's own paid
UEFI CA process, so post-install.sh enrolls BOS's own keys automatically
only when the firmware is already in Setup Mode (sbctl status --json),
signs the kernel/bootloader, and leaves it alone otherwise — sbctl's own
pacman hook re-signs on every future kernel/GRUB update, no further
wiring needed.

Release signing: generated a dedicated Ed25519 "BOS Release Signing" key
(not reused from anything else), stored as the GPG_PRIVATE_KEY Forgejo
Actions secret. release-iso.yml now generates SHA256SUMS and a detached
SHA256SUMS.asc signature alongside every ISO upload; public key committed
at KEYS.asc with verification instructions in the README.

README updated: fixed a stale "greetd + tuigreet" line (breadgreet since
round 3), documented yay/encryption/secure-boot/verification.
2026-07-04 10:39:44 +08:00
..
calamares Ship yay, wire up LUKS disk encryption, self-signed Secure Boot, release signing 2026-07-04 10:39:44 +08:00
default Default to zsh distro-wide (live user + useradd default) 2026-06-17 17:45:07 +08:00
greetd Fix boot-critical, session, and UX bugs found in round-3 UX audit 2026-07-03 22:04:26 +08:00
mkinitcpio.conf.d Fix install-breaking and live-boot bugs, verified on real hardware 2026-07-03 13:31:40 +08:00
mkinitcpio.d Add archiso initramfs hooks so the live ISO can switch root 2026-06-14 02:55:53 +08:00
pacman.d Make BOS a complete, bootable, themed desktop OS 2026-06-16 09:09:34 +08:00
plymouth Fix install-breaking and live-boot bugs, verified on real hardware 2026-07-03 13:31:40 +08:00
profile.d Make BOS a complete, bootable, themed desktop OS 2026-06-16 09:09:34 +08:00
skel Fix pywal-brown theme regression: stop clobbering the curated black palette 2026-07-03 22:35:50 +08:00
sudoers.d Run the live session as an unprivileged user (Hyprland won't run as root) 2026-06-14 04:13:10 +08:00
systemd Complete the desktop: default apps, mDNS, firewall, zram, fonts 2026-06-16 14:47:06 +08:00
hostname Add live-environment config so the ISO boots straight to the session 2026-06-14 03:13:54 +08:00
locale.conf Add live-environment config so the ISO boots straight to the session 2026-06-14 03:13:54 +08:00
localtime Add live-environment config so the ISO boots straight to the session 2026-06-14 03:13:54 +08:00
os-release Fix boot-critical, session, and UX bugs found in round-3 UX audit 2026-07-03 22:04:26 +08:00
pacman.conf Minor cleanups: gitignore out/, expect() messages, comment wording 2026-06-17 22:57:58 +08:00
passwd Add live-environment config so the ISO boots straight to the session 2026-06-14 03:13:54 +08:00
shadow Add live-environment config so the ISO boots straight to the session 2026-06-14 03:13:54 +08:00
vconsole.conf Add live-environment config so the ISO boots straight to the session 2026-06-14 03:13:54 +08:00