diff options
| -rw-r--r-- | Dockerfile | 6 | ||||
| -rw-r--r-- | README.md | 15 | ||||
| -rw-r--r-- | docker-compose.yml | 3 | ||||
| -rw-r--r-- | meta-yerba/conf/distro/yerba.conf | 2 | ||||
| -rw-r--r-- | meta-yerba/recipes-connectivity/openresolv/openresolv_3.17.4.bb | 38 | ||||
| -rw-r--r-- | meta-yerba/recipes-core/images/yerba-image.bb | 12 | ||||
| -rw-r--r-- | meta-yerba/recipes-devtools/qemu/qemu-system-native_%.bbappend | 1 | ||||
| -rw-r--r-- | meta-yerba/recipes-kernel/linux-firmware/linux-firmware_%.bbappend | 1 | ||||
| -rwxr-xr-x | qemu-ifup | 23 | ||||
| -rwxr-xr-x | qemu.sh | 4 |
10 files changed, 94 insertions, 11 deletions
@@ -1,7 +1,7 @@ FROM ubuntu:22.04 ENV DEBIAN_FRONTEND=noninteractive -RUN apt-get update && apt-get install -y locales wget unzip git curl python3 python3-pip sudo chrpath diffstat lz4 zstd libtirpc-dev rpcsvc-proto file xz-utils bzip2 cpio gawk g++ make gcc build-essential patch texinfo clang tcc libelf-dev flex bison libncurses-dev openssl libssl-dev bc rsync dwarves kmod iproute2 bash && locale-gen en_US.UTF-8 && update-locale LANG=en_US.UTF-8 && rm -rf /var/lib/apt/lists/* +RUN apt-get update && apt-get install -y locales wget unzip git curl python3 python3-pip sudo chrpath diffstat lz4 zstd libtirpc-dev rpcsvc-proto file xz-utils bzip2 cpio gawk g++ make gcc build-essential patch texinfo clang tcc libelf-dev flex bison libncurses-dev openssl libssl-dev bc rsync dwarves kmod iproute2 bash usbutils && locale-gen en_US.UTF-8 && update-locale LANG=en_US.UTF-8 && rm -rf /var/lib/apt/lists/* ENV LANG=en_US.UTF-8 \ LANGUAGE=en_US:en \ @@ -11,6 +11,9 @@ RUN pip3 install kas RUN groupadd -g 1000 builder && useradd -u 1000 -g 1000 -m -s /bin/bash builder && echo "builder ALL=(ALL) NOPASSWD:ALL" >> /etc/sudoers +COPY qemu-ifup /etc/qemu-ifup +RUN chmod +x /etc/qemu-ifup + USER 1000:1000 WORKDIR /home/builder/yerbalinux @@ -19,3 +22,4 @@ ENV LANG=en_US.UTF-8 \ LC_ALL=en_US.UTF-8 CMD ["kas", "build", "kas.yml"] + @@ -29,6 +29,8 @@ kas build kas.yml This will build the distro and all dependencies, leaving the artifacts somewhere in build/. **Good luck finding it**(TM)**!** +Jokes aside, once it's ready I'll hopefully provide some better documentation on how to build and run the distro in an emulator and how to install it on real hardware. + ## Current Status - Kernel: working, 7.0.11! @@ -36,9 +38,10 @@ This will build the distro and all dependencies, leaving the artifacts somewhere - Libc: working, glibc - Init system: working, runit - SquashFS image (+ OverlayFS live ISO): TBD -- Networking: working, dhcpcd (TODO: Add NetworkManager and iwd) +- Networking: TBD - Audio: TBD -- Package manager: TBD +- Package manager: kinda working, dnf (not configured yet) +- Atomic updates: TBD (note: use RAUC) - Installer: TBD - Graphics: TBD @@ -53,19 +56,19 @@ The following notes are for myself so I can remember what hardening features to - muvm for sandboxing apps - flatkvm? TODO look at this in more detail - Flatpak for GUI apps sandboxing -- Hardened kernel +- Hardened kernel [Kind-of done] - Blacklist unnecessary/unused modules for security (Auto detect required modules during install?) - FDE with LUKS (TPM) - [Research needed] User password/separately encrypted home directory (Android-like) (Also TPM?) - Atomic updates with dm-verity - Wayland by default -- Chimera userland (chimerautils/FreeBSD ported) -- rpm/dnf package manager +- Chimera userland (chimerautils/FreeBSD ported) [DONE] +- rpm/dnf package manager [DONE] - built-in support in yocto yayayayayay - good OpenPGP signature management - set the prefix/installroot to $HOME/.local/pkg/ - set the database to $HOME/.local/pkg/var/db -- Runit init system (minimal attack surface) - Might be changed to OpenRC +- Runit init system (minimal attack surface) - Might be changed to OpenRC [DONE] - Secure Boot (TPM) - Decoy/duress PIN - PAM module, wipe all user-controlled partitions and reboot immediately - Auto updates (atomic!) diff --git a/docker-compose.yml b/docker-compose.yml index 833206d..8a2cb57 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -5,10 +5,13 @@ services: user: "1000:1000" privileged: true # TUN for QEMU needs this hostname: yerbalinux-builder-docker + extra_hosts: + - "yerbalinux-builder-docker:127.0.0.1" stdin_open: true tty: true devices: - /dev/net/tun:/dev/net/tun + - /dev/bus/usb:/dev/bus/usb volumes: - ./:/home/builder/yerbalinux - /opt/yocto:/opt/yocto diff --git a/meta-yerba/conf/distro/yerba.conf b/meta-yerba/conf/distro/yerba.conf index 18d3a6e..6d2a421 100644 --- a/meta-yerba/conf/distro/yerba.conf +++ b/meta-yerba/conf/distro/yerba.conf @@ -5,7 +5,7 @@ MAINTAINER = "Arslaan Pathan <[email protected]>" TCLIBC = "glibc" -IMAGE_INSTALL:append = " runit runit-config" +IMAGE_INSTALL:append = " runit runit-config kernel-modules" APPEND:append = " init=/sbin/runit-init" DISTRO_FEATURES = " pam" diff --git a/meta-yerba/recipes-connectivity/openresolv/openresolv_3.17.4.bb b/meta-yerba/recipes-connectivity/openresolv/openresolv_3.17.4.bb new file mode 100644 index 0000000..a62c033 --- /dev/null +++ b/meta-yerba/recipes-connectivity/openresolv/openresolv_3.17.4.bb @@ -0,0 +1,38 @@ +SUMMARY = "openresolv is a resolvconf implementation which manages /etc/resolv.conf." +DESCRIPTION = "openresolv is a resolvconf implementation which manages /etc/resolv.conf." +HOMEPAGE = "https://github.com/NetworkConfiguration/openresolv" +LICENSE = "BSD-2-Clause" +LIC_FILES_CHKSUM="file://LICENSE;md5=b612f9979838f6126283eec15dfadb86" + +SRC_URI="git://github.com/NetworkConfiguration/openresolv;protocol=https;branch=master" +SRCREV="6489889ce5631364ad2f17d391e1a3ad969619f2" +S = "${WORKDIR}/git" + +PROVIDES += "virtual/base-utils" + +inherit autotools + +EXTRA_OECONF="--sysconfdir=${sysconfdir} --localstatedir=${localstatedir}" + +do_configure() { + ./configure \ + --prefix=${prefix} \ + --sysconfdir=${sysconfdir} \ + --localstatedir=${localstatedir} \ + --mandir=${mandir} +} + +do_compile() { + oe_runmake +} + +do_install() { + oe_runmake install DESTDIR=${D} +} + +FILES:${PN} = " \ + ${bindir}/* \ + ${sbindir}/* \ + ${sysconfdir}/* \ + ${libexecdir}/* \ +" diff --git a/meta-yerba/recipes-core/images/yerba-image.bb b/meta-yerba/recipes-core/images/yerba-image.bb index 437803c..5073b22 100644 --- a/meta-yerba/recipes-core/images/yerba-image.bb +++ b/meta-yerba/recipes-core/images/yerba-image.bb @@ -12,14 +12,12 @@ IMAGE_INSTALL = "\ runit \ runit-serialgetty \ runit-tty0-getty \ - runit-dhcpcd \ runit-config \ util-linux-agetty \ bash \ zsh \ vim \ nano \ - dhcpcd \ curl \ wget \ file \ @@ -30,4 +28,14 @@ IMAGE_INSTALL = "\ iputils \ procps \ ncurses-terminfo-base \ + kmod \ + usbutils \ + pciutils \ + rfkill \ + iw \ + ethtool \ + wireless-regdb \ + linux-firmware \ + iwd \ + openresolv \ " diff --git a/meta-yerba/recipes-devtools/qemu/qemu-system-native_%.bbappend b/meta-yerba/recipes-devtools/qemu/qemu-system-native_%.bbappend new file mode 100644 index 0000000..f6f3a1f --- /dev/null +++ b/meta-yerba/recipes-devtools/qemu/qemu-system-native_%.bbappend @@ -0,0 +1 @@ +PACKAGECONFIG:append = " libusb" diff --git a/meta-yerba/recipes-kernel/linux-firmware/linux-firmware_%.bbappend b/meta-yerba/recipes-kernel/linux-firmware/linux-firmware_%.bbappend new file mode 100644 index 0000000..20fc9e8 --- /dev/null +++ b/meta-yerba/recipes-kernel/linux-firmware/linux-firmware_%.bbappend @@ -0,0 +1 @@ +RDEPENDS:${PN} += "${@bb.utils.contains('PACKAGES', '${PN}', '', ' '.join(p for p in d.getVar('PACKAGES').split() if p.startswith('${PN}-')), d)}" diff --git a/qemu-ifup b/qemu-ifup new file mode 100755 index 0000000..7b7f70c --- /dev/null +++ b/qemu-ifup @@ -0,0 +1,23 @@ +#!/bin/sh +# script to configure QEMU tap device + +ip link set "$1" up +ip addr add 192.168.7.1/24 dev "$1" 2>/dev/null + +sysctl -w net.ipv4.ip_forward=1 + +DEFAULT_IFACE="$(ip route show default 0.0.0.0/0 | awk '{print $5}')" + +iptables -D FORWARD -s 192.168.7.0/24 -j ACCEPT 2>/dev/null +iptables -D FORWARD -d 192.168.7.0/24 -j ACCEPT 2>/dev/null +iptables -D DOCKER-USER -s 192.168.7.0/24 -j ACCEPT 2>/dev/null +iptables -D DOCKER-USER -d 192.168.7.0/24 -j ACCEPT 2>/dev/null + +iptables -I FORWARD 1 -s 192.168.7.0/24 -j ACCEPT +iptables -I FORWARD 1 -d 192.168.7.0/24 -j ACCEPT + +iptables -I DOCKER-USER 1 -s 192.168.7.0/24 -j ACCEPT 2>/dev/null +iptables -I DOCKER-USER 1 -d 192.168.7.0/24 -j ACCEPT 2>/dev/null + +iptables -t nat -D POSTROUTING -s 192.168.7.0/24 -o "$DEFAULT_IFACE" -j MASQUERADE 2>/dev/null +iptables -t nat -I POSTROUTING 1 -s 192.168.7.0/24 -o "$DEFAULT_IFACE" -j MASQUERADE @@ -1,3 +1,5 @@ #!/bin/sh # This script exists so I don't have to keep remembering the QEMU command when I run my distro testing -runqemu yerba-x86_64 qemuparams="-display vnc=:0 -vga virtio -serial mon:stdio" bootparams="console=tty0" +#export OE_TAP_NAME="tap" + +runqemu yerba-x86_64 nonetwork qemuparams="-display vnc=:0 -vga virtio -serial mon:stdio -device usb-host,vendorid=0x2357,productid=0x011e" bootparams="console=tty0" |
