aboutsummaryrefslogtreecommitdiff
diff options
context:
space:
mode:
-rw-r--r--README.md11
-rw-r--r--meta-yerba/conf/distro/yerba.conf3
-rw-r--r--meta-yerba/recipes-devtools/pkgsrc/pkgsrc_%.bb17
3 files changed, 8 insertions, 23 deletions
diff --git a/README.md b/README.md
index 5cf048a..70e4ce8 100644
--- a/README.md
+++ b/README.md
@@ -60,12 +60,11 @@ The following notes are for myself so I can remember what hardening features to
- Atomic updates with dm-verity
- Wayland by default
- Chimera userland (chimerautils/FreeBSD ported)
-- pkgsrc (NetBSD) package manager
- - build into tarball
- - on first install and on each update extract the tarball into /home/USER/.local/pkgsrc for each user
- - regen mk.conf on each update/install to use correct prefix
- - per-user packages only ^_^
- - unprivileged bootstrap
+- rpm/dnf package manager
+ - built-in support in yocto yayayayayay
+ - good OpenPGP signature management
+ - set the prefix/installroot to $HOME/.local/pkg/
+ - set the database to $HOME/.local/pkg/var/db
- Runit init system (minimal attack surface) - Might be changed to OpenRC
- Secure Boot (TPM)
- Decoy/duress PIN - PAM module, wipe all user-controlled partitions and reboot immediately
diff --git a/meta-yerba/conf/distro/yerba.conf b/meta-yerba/conf/distro/yerba.conf
index b78e3de..18d3a6e 100644
--- a/meta-yerba/conf/distro/yerba.conf
+++ b/meta-yerba/conf/distro/yerba.conf
@@ -21,6 +21,9 @@ VIRTUAL-RUNTIME_base-utils = "chimerautils"
SKIP_RECIPE[busybox] = "Using chimerautils instead"
SKIP_RECIPE[coreutils] = "Using chimerautils instead"
+PACKAGE_CLASSES = "package_rpm"
+EXTRA_IMAGE_FEATURES += " package-management"
+
# some quality assurance stuff? idk tbh
ERROR_QA:append = " textrel host-user-contaminated"
WARN_QA:append = " buildpaths ldflags"
diff --git a/meta-yerba/recipes-devtools/pkgsrc/pkgsrc_%.bb b/meta-yerba/recipes-devtools/pkgsrc/pkgsrc_%.bb
deleted file mode 100644
index c760cbd..0000000
--- a/meta-yerba/recipes-devtools/pkgsrc/pkgsrc_%.bb
+++ /dev/null
@@ -1,17 +0,0 @@
-SUMMARY = "pkgsrc is a framework for managing third-party software on UNIX-like systems"
-DESCRIPTION = "NetBSD package manager"
-HOMEPAGE = "https://www.pkgsrc.org"
-LICENSE = "BSD-2-Clause"
-LIC_FILES_CHKSUM = "file://${COMMON_LICENSE_DIR}/BSD-2-Clause;md5=cb641bc04cda31daea161b1bc15da69f"
-
-SRC_URI = "git://github.com/NetBSD/pkgsrc;protocol=https;branch=trunk"
-SRCREV = "46a4a767eef68a0de0edae7e094a3f09e1fcce5f"
-S = "${WORKDIR}/git"
-
-inherit autotools-brokensep
-
-do_install() {
- cd ${S}/bootstrap
-
- ./bootstrap --prefix ${D}/usr/pkg --machine-arch ${TARGET_ARCH} --compiler ${CC} --unprivileged --make-jobs ${BB_NUMBER_THREADS}
-}