yay (yay-bin, AUR-only like calamares/bibata) republished to [breadway] via the same PKGBUILD + Forgejo workflow pattern, so users can reach the wider AUR beyond bakery's bread ecosystem. Disk encryption: Calamares' partition module already has LUKS support enabled by default, but the checkbox led nowhere — no cryptsetup on the live/target image, no mkinitcpio encrypt hook, no GRUB cryptodisk wiring. An encrypted install would partition fine and then never boot. Added cryptsetup, pinned luksGeneration to luks1 (GRUB doesn't support LUKS2 + Argon2id), and post-install.sh now detects an encrypted root (lsblk TYPE == crypt) and conditionally adds the encrypt hook + GRUB_ENABLE_CRYPTODISK + --modules="cryptodisk luks luks2" on both grub-install passes. No effect on a normal unencrypted install. Secure Boot: self-signed via sbctl (shipped in packages.x86_64). BOS can't ship a Microsoft-signed shim without going through Microsoft's own paid UEFI CA process, so post-install.sh enrolls BOS's own keys automatically only when the firmware is already in Setup Mode (sbctl status --json), signs the kernel/bootloader, and leaves it alone otherwise — sbctl's own pacman hook re-signs on every future kernel/GRUB update, no further wiring needed. Release signing: generated a dedicated Ed25519 "BOS Release Signing" key (not reused from anything else), stored as the GPG_PRIVATE_KEY Forgejo Actions secret. release-iso.yml now generates SHA256SUMS and a detached SHA256SUMS.asc signature alongside every ISO upload; public key committed at KEYS.asc with verification instructions in the README. README updated: fixed a stale "greetd + tuigreet" line (breadgreet since round 3), documented yay/encryption/secure-boot/verification.
33 lines
1.5 KiB
Text
33 lines
1.5 KiB
Text
---
|
|
efiSystemPartition: "/boot/efi"
|
|
efiSystemPartitionSize: "512M"
|
|
efiSystemPartitionName: "EFI"
|
|
|
|
defaultFileSystemType: "btrfs"
|
|
|
|
# NOTE: there is no `btrfsSubvolumes:` key in this Calamares version's
|
|
# partition module schema (confirmed against /usr/share/calamares/modules/
|
|
# partition.conf and on real hardware — zero mentions of "subvolume"
|
|
# anywhere in the stock reference config). A previous version of this file
|
|
# had one; Calamares silently ignored it. Calamares' partition module only
|
|
# natively creates @ (root) and @home (home) when btrfs + separate /home is
|
|
# selected — nothing else. @snapshots/@log/@cache are created by hand in
|
|
# post-install.sh instead, after unpackfs has populated the filesystem.
|
|
|
|
userSwapChoices:
|
|
- none
|
|
- small
|
|
- suspend
|
|
- file
|
|
|
|
# Full-disk encryption (LUKS) is enabled by default in Calamares' partition
|
|
# module (enableLuksAutomatedPartitioning defaults to true) — the checkbox
|
|
# already shows on the "Erase disk" page with no config needed here. Pin the
|
|
# LUKS generation explicitly rather than relying on Calamares' own implicit
|
|
# default: GRUB doesn't support LUKS2 + Argon2id, only PBKDF2, and using the
|
|
# wrong KDF produces an encrypted install GRUB can't unlock at boot. luks1
|
|
# is unconditionally safe with BOS's plain grub-install setup (no separate
|
|
# unencrypted /boot — GRUB itself has to unlock the LUKS container to read
|
|
# the kernel). See post-install.sh for the matching cryptsetup/mkinitcpio/
|
|
# GRUB wiring this actually needs to be bootable.
|
|
luksGeneration: luks1
|