From 514854bd5e818c5d65922344e5a2d2b8aff849c4 Mon Sep 17 00:00:00 2001 From: Arslaan Pathan Date: Fri, 4 Sep 2026 23:31:58 +1200 Subject: [feat/fix] start working on pkgsrc, migrate to glibc, fix doas deps, also docker --- Dockerfile | 2 +- README.md | 11 ++++++++--- docker-compose.yml | 2 ++ meta-yerba/conf/distro/yerba.conf | 2 +- meta-yerba/recipes-devtools/pkgsrc/pkgsrc_%.bb | 17 +++++++++++++++++ meta-yerba/recipes-support/doas/doas_6.8.2.bb | 2 +- 6 files changed, 30 insertions(+), 6 deletions(-) create mode 100644 meta-yerba/recipes-devtools/pkgsrc/pkgsrc_%.bb diff --git a/Dockerfile b/Dockerfile index e8de400..9f327e4 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,7 +1,7 @@ FROM ubuntu:22.04 ENV DEBIAN_FRONTEND=noninteractive -RUN apt-get update && apt-get install -y locales wget unzip git curl python3 python3-pip sudo chrpath diffstat lz4 zstd libtirpc-dev rpcsvc-proto file xz-utils bzip2 cpio gawk g++ make gcc build-essential patch texinfo clang tcc libelf-dev flex bison libncurses-dev openssl libssl-dev bc rsync dwarves kmod iproute2 && locale-gen en_US.UTF-8 && update-locale LANG=en_US.UTF-8 && rm -rf /var/lib/apt/lists/* +RUN apt-get update && apt-get install -y locales wget unzip git curl python3 python3-pip sudo chrpath diffstat lz4 zstd libtirpc-dev rpcsvc-proto file xz-utils bzip2 cpio gawk g++ make gcc build-essential patch texinfo clang tcc libelf-dev flex bison libncurses-dev openssl libssl-dev bc rsync dwarves kmod iproute2 bash && locale-gen en_US.UTF-8 && update-locale LANG=en_US.UTF-8 && rm -rf /var/lib/apt/lists/* ENV LANG=en_US.UTF-8 \ LANGUAGE=en_US:en \ diff --git a/README.md b/README.md index 9b1e016..5cf048a 100644 --- a/README.md +++ b/README.md @@ -33,7 +33,7 @@ This will build the distro and all dependencies, leaving the artifacts somewhere - Kernel: working, 7.0.11! - Bootloader: TBD, currently using runqemu on the rootfs directly -- Libc: working, musl +- Libc: working, glibc - Init system: working, runit - SquashFS image (+ OverlayFS live ISO): TBD - Networking: working, dhcpcd (TODO: Add NetworkManager and iwd) @@ -60,7 +60,12 @@ The following notes are for myself so I can remember what hardening features to - Atomic updates with dm-verity - Wayland by default - Chimera userland (chimerautils/FreeBSD ported) -- pkgsrc (NetBSD) package manager - prefix set to /opt/yerba-pkg +- pkgsrc (NetBSD) package manager + - build into tarball + - on first install and on each update extract the tarball into /home/USER/.local/pkgsrc for each user + - regen mk.conf on each update/install to use correct prefix + - per-user packages only ^_^ + - unprivileged bootstrap - Runit init system (minimal attack surface) - Might be changed to OpenRC - Secure Boot (TPM) - Decoy/duress PIN - PAM module, wipe all user-controlled partitions and reboot immediately @@ -85,7 +90,7 @@ The following notes are for myself so I can remember what hardening features to - **nvram** (128MB) | LUKS | FAT32 | `/nvram` | NVRAM for root flags and selected slot - **rootfs_A** (15GB) | LUKS + dm-verity (atomic) | btrfs | `/` (if selected slot) | Root filesystem — Slot A - **rootfs_B** (15GB) | LUKS + dm-verity (atomic) | btrfs | `/` (if selected slot) | Root filesystem — Slot B -- **userdata** (Rest of disk) | LUKS | btrfs + subvol (home, pkg) | `/home`, `/opt/yerba-pkg` | User files +- **userdata** (Rest of disk) | LUKS | btrfs | `/home` | User files --- diff --git a/docker-compose.yml b/docker-compose.yml index 27a8493..833206d 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -5,6 +5,8 @@ services: user: "1000:1000" privileged: true # TUN for QEMU needs this hostname: yerbalinux-builder-docker + stdin_open: true + tty: true devices: - /dev/net/tun:/dev/net/tun volumes: diff --git a/meta-yerba/conf/distro/yerba.conf b/meta-yerba/conf/distro/yerba.conf index b1368a1..b78e3de 100644 --- a/meta-yerba/conf/distro/yerba.conf +++ b/meta-yerba/conf/distro/yerba.conf @@ -3,7 +3,7 @@ DISTRO_NAME = "Yerba Linux" DISTRO_VERSION = "1.0.0" MAINTAINER = "Arslaan Pathan " -TCLIBC = "musl" +TCLIBC = "glibc" IMAGE_INSTALL:append = " runit runit-config" APPEND:append = " init=/sbin/runit-init" diff --git a/meta-yerba/recipes-devtools/pkgsrc/pkgsrc_%.bb b/meta-yerba/recipes-devtools/pkgsrc/pkgsrc_%.bb new file mode 100644 index 0000000..c760cbd --- /dev/null +++ b/meta-yerba/recipes-devtools/pkgsrc/pkgsrc_%.bb @@ -0,0 +1,17 @@ +SUMMARY = "pkgsrc is a framework for managing third-party software on UNIX-like systems" +DESCRIPTION = "NetBSD package manager" +HOMEPAGE = "https://www.pkgsrc.org" +LICENSE = "BSD-2-Clause" +LIC_FILES_CHKSUM = "file://${COMMON_LICENSE_DIR}/BSD-2-Clause;md5=cb641bc04cda31daea161b1bc15da69f" + +SRC_URI = "git://github.com/NetBSD/pkgsrc;protocol=https;branch=trunk" +SRCREV = "46a4a767eef68a0de0edae7e094a3f09e1fcce5f" +S = "${WORKDIR}/git" + +inherit autotools-brokensep + +do_install() { + cd ${S}/bootstrap + + ./bootstrap --prefix ${D}/usr/pkg --machine-arch ${TARGET_ARCH} --compiler ${CC} --unprivileged --make-jobs ${BB_NUMBER_THREADS} +} diff --git a/meta-yerba/recipes-support/doas/doas_6.8.2.bb b/meta-yerba/recipes-support/doas/doas_6.8.2.bb index 82a1e42..121bbb2 100644 --- a/meta-yerba/recipes-support/doas/doas_6.8.2.bb +++ b/meta-yerba/recipes-support/doas/doas_6.8.2.bb @@ -10,7 +10,7 @@ SRC_URI[sha256sum] = "6da058a0e70b7543bc60624389b0b00b686189ec933828c522bf8b2600 S = "${WORKDIR}/OpenDoas-6.8.2" -DEPENDS = "libbsd bison-native" +DEPENDS = "libbsd bison-native virtual/crypt libxcrypt" do_configure() { cd ${S} -- cgit v1.2.3