In practice, the filename limit was overly small, this change allows
us to better describe the content of some kernels currently in use.
Signed-off-by: Murilo Belluzzo <murilo.belluzzo@intel.com>
gummiboot hasn't been supported upstream or by Clear Linux for an age,
and due to format bumps no compatibility is required with it, thus it
can be completely removed from source.
goofiboot, the fork of gummiboot, was initially created to address concerns
in systemd-boot in their tooling. However, the concerns were mitigated by
opting to entirely bypass their tooling, and clr-boot-manager absorbed all
safety and distribution support that was part of libnica and goofiboot.
At this point, both of the legacy bootloaders are safe to be nuked from
orbit and are no longer used in CBM-using distributions.
Signed-off-by: Ikey Doherty <ikey@solus-project.com>
To align with image mode update (and for the same reasons) move the
freestanding initrd update to before the kernel update. This prevents
creating an invalid kernel bootloader entry if there was a problem
with installing a freestanding initrd.
Validate that update fails and kernels aren't installed when a
freestanding initrd is missing. This test ensures that an invalid boot
menu entry (due to it listing initrd files that do not exist) are not
installed when update fails.
Copy freestand initrd files when cbm is run in image mode. Note the
initrd installation call happens prior to kernel install. This is done
as failure to install/update an initrd is fatal and if kernel install
happens before initrd install then an installed kernel could exist
with a configuration file referencing initrds that won't be available.
cbm_get_luks_uuid get the uuid of the decrypted root partition when this
is in a LVM partition this mean looking for the device information here:
/sys/block/dm-1/slaves/dm-0/slaves/sdb1/dev
without LVM the path would be this:
/sys/block/dm-1/slaves/sdb1/dev
Signed-off-by: Josue David Hernandez <josue.d.hernandez.gutierrez@intel.com>
add suport for freestanding initrd in /usr/lib/initrd.d
for systemd-boot, grub2 and syslinux
Signed-off-by: Josue David Hernandez <josue.d.hernandez.gutierrez@intel.com>
When clr-boot-manager (CBM) is forked/exec'd via swupd-client, file
descriptor leak checks are performed first by CBM, and then by
swupd-client.
However, not all file descriptors opened by swupd-client will be closed
during the exec of CBM, leading to CBM falsely reporting leaks for file
descriptors inherited from the parent process. In cases when CBM reports
valid leaks, swupd-client will later report them as well, making the CBM
reports extraneous.
Arguably, swupd-client should try to mark its open file descriptors
O_CLOEXEC, but at least one of the descriptors is managed by libcurl,
and no API exists to set O_CLOEXEC on it (as far as I know).
So, for now, remove the file descriptor leak here. Perhaps reintroduce
it later when more testing is implemented to ensure that relevant file
descriptors opened by CBM are not leaked.
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
We should never directly include the linux headers, as the libc headers
should always suffice for this. For glibc, the headers should forward to
the linux kernel headers, however musl provides a self contained set of
headers that do not rely on the glibc-enabling linux headers.
Signed-off-by: Ikey Doherty <ikey@solus-project.com>
This change is required to allow portability changes for libnica, as
required to allow building against musl for static compilation.
Signed-off-by: Ikey Doherty <ikey@solus-project.com>
This change is designed to make it simpler to maintain clr-boot-manager
by switching to the much easier meson build system. Care is taken to
preserve the original functionality, but this will allow us to avoid
repeated issues of "failed distcheck", etc.
Additionally, a new test entry point is now included for Travis, to ensure
all relevant codepaths are properly tested. This now enables us to trivially
merge multiple runs into a single coverage report so that we can test the
code base in various "deployments".
To alleviate the issue of distributing without a `make distcheck` target,
this change vendors the `git-archive-all.sh` script into `scripts/` and
provides a port of the `budgie-desktop` `mkrelease.sh` script to quickly
and easily create a signed distribution tarball straight from git, along
with the submodules (i.e. nica).
Lastly, we'll only build the bootvar support + systemd-shim when we've
actually selected this bootloader, to ensure the project can still be built
without needing gnu-efi/efivar.
Signed-off-by: Ikey Doherty <ikey@solus-project.com>
kernel.c no longer creates any layout, but systemd-class was not
creating/ensuring kernel target directory either. This fixes the issue.
Also, tests are fixed to use proper ESP standard names throughout.
clang-format changes its output too much between versions to block
commits so go back to users being on their own for format following
the style rules.
This change allows the installation of a shim when using systemd-boot as
the bootloader. It also enables the management of EFI variables to
manage the default boot device.
The shim will eventually become a required piece for secure-boot enabled
booting.
This fixes a segfault occuring within clr-boot-manager's usage of the
`blkid_partlist_numof_partitions` function that will now segfault when
passed a NULL blkid_partlist, as of util-linux 2.30.x series.
This change will ensure all consumers of the cbm_blkid API will continue to
function as before, but safe guard against the util-linux internal changes
that broke the counter function to determine how many partitions are present.
Note that this behaviour only manifested on LVM installations, which have
a more advanced probing scheme within clr-boot-manager.
Solus Issue: https://dev.solus-project.com/T4763
Signed-off-by: Ikey Doherty <ikey@solus-project.com>
This change introduces support for vendor kernel configuration fragments,
which typically live within the /usr/share/kernel/cmdline.d directory.
These are useful to vendors and OEMs to pre-enable some hardware quirks
such as acpi_os, i8042 tweaks, etc.
These files take a higher precedence than the /etc/ files, however to
ensure we abide by a proper stateless policy we allow the concept of masking
and disabling in the style of systemd. The files in the "vendor config"
directory are considered masked when a file with the same base name lives
within the "system config" (/etc/kernel/cmdline.d) tree. The vendor file
will be skipped regardless of system config validity in this instance.
To allow disabling entirely of the vendor config file, the local system
administrator may follow the masking approach as described as above, but
instead of creating a override, symlink this file to /dev/null. This will
cause the file to be removed entirely from any kind of parsing. This link
logic is only valid within the context of the system config directory.
Signed-off-by: Ikey Doherty <ikey@solus-project.com>
Using automake default modifiers ('cru') makes ar warn about
meaningless 'u':
/usr/bin/ar: `u' modifier ignored since `D' is the default (see `U')
Instead of using the defaults, specify all the modifiers explicitly:
'crD'.
The first and most important change is to ensure that we never try to
grab the host ESP when we're operating in image mode. This alone causes
issues when producing images using "--path", i.e. VHD imagery.
Secondly, we ensure that we *always* set image mode *before* we set the
prefix, as this prefix is only ever set once. This is the part where we
inspect the root of the system we're looking at, and determine whether
we're dealing with legacy or UEFI, or legacy+gpt (i.e. Azure images).
Lastly, we make sure that update_image follows the lead of update_native
by re-initialising the bootloader prior to using it, with the current
root + boot directory settings, ensuring we're always using fresh
values and world view.
Signed-off-by: Ikey Doherty <michael.i.doherty@intel.com>
The lack of kernel modules during install isn't necessarily fatal, and
some kernel configurations might be without modules entirely. Notably,
given that kernel modules are to be marked as resident on disk, even if
we have multiple packages compromising a kernel and separate modules, those
old modules will be removed at the time of the kernel change, and at no
other time, ensuring an atomic update.
This resolves#67.
Signed-off-by: Ikey Doherty <michael.i.doherty@intel.com>
As of glibc 2.25, warnings will be emitted at compile time to state
that you must explicitly include the header now, due to libraries
tending to have their own definitions.
Signed-off-by: Ikey Doherty <michael.i.doherty@intel.com>
Prior to this change, the kernel and initrd paths were not using the
namespace directory during kernel removal, leading to assets being left
on the disk and filling up the ESP with junk that could not be reclaimed.
This change introduces the simple fix, as well as the UEFI specific test
to ensure that the files are being removed.
Signed-off-by: Ikey Doherty <michael.i.doherty@intel.com>