From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from atuin.qyliss.net (localhost [IPv6:::1]) by atuin.qyliss.net (Postfix) with ESMTP id 1B810EC9C; Wed, 05 Nov 2025 22:34:39 +0000 (UTC) Received: by atuin.qyliss.net (Postfix, from userid 993) id 6B1B2EC12; Wed, 05 Nov 2025 22:34:36 +0000 (UTC) X-Spam-Checker-Version: SpamAssassin 4.0.1 (2024-03-26) on atuin.qyliss.net X-Spam-Level: X-Spam-Status: No, score=-0.1 required=3.0 tests=DKIM_SIGNED,DKIM_VALID, DKIM_VALID_AU,DMARC_PASS,FREEMAIL_FROM,RCVD_IN_DNSWL_NONE, SPF_HELO_NONE autolearn=unavailable autolearn_force=no version=4.0.1 Received: from mail-yw1-x1132.google.com (mail-yw1-x1132.google.com [IPv6:2607:f8b0:4864:20::1132]) by atuin.qyliss.net (Postfix) with ESMTPS id 93146EB66 for ; Wed, 05 Nov 2025 22:34:34 +0000 (UTC) Received: by mail-yw1-x1132.google.com with SMTP id 00721157ae682-7869dee42cdso18140097b3.1 for ; Wed, 05 Nov 2025 14:34:34 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20230601; t=1762382073; x=1762986873; darn=spectrum-os.org; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :mime-version:subject:date:from:from:to:cc:subject:date:message-id :reply-to; bh=gXw2yVjGM5k7mJy6VDlNPyuhYxK8jXEK0sDcpt5polA=; b=Y5DBCRnl9LWH4GKzHOjaWiShfCvGfrpkHVJJug85+S7ZZG6YFgBpE/Pb1dDwOcgAUV 0sdlRBZYe32C/UiaxvkdfFG9JAzsCPfGCObuAU9q59HXkcPJ83ma71t0K748JehVdAL9 fjPxlQVYzwgCnfaJ5c2TknmPWz6a8UbhWogKzan9vm01iG9TlswXq7evm8bT+/loxGw5 NzJHRcm9QMyHfdPXEqKUERznclqMy4lmFSwYg0X3VbHQmxgQ415k58/FbT289k/CS7NX GWLNclWR/BkOmr2Q2HuOJ9fxbfgY8f4t6Wez+JYrpi0g93ynUYztWp+/Pbj0W7hlM1IE jh3Q== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1762382073; x=1762986873; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :mime-version:subject:date:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to; bh=gXw2yVjGM5k7mJy6VDlNPyuhYxK8jXEK0sDcpt5polA=; b=dSKWe9vpxU6pHl23oaao+nS9TlTJ0nndkKLKbm7y7HMCB9lF+fAd9jNUZyVVnWiyeX Ev9SmHVmzojMEj9czDQLvh1A+OC5cL51MUdRxsRTPvwctmGv/T3EcGtPFGMX4A7fN6GE 52RsWJCq3tF1JLLhvzZa2HgXUeQnGFfK5jvRFr8eox6UbrurAtbjGKXQvpBYU2Xxfpa8 OK74fl8TsQuA3K6unxcdWGSVEUcaAdsYB5trdNm97MH0AgcDLZbBiZECsm7Qg8/0zzmJ 4RbQalnb0fNWFBilaEgtzyHwm7VxCpq2U3ephOHSwPPQjxc1YvDwvp6fh/Uoi1hcy+T0 IGqg== X-Gm-Message-State: AOJu0Ywl2S3KOGr36J6TznstbxP7yu2nRcFOWYtfCR+bDH/tB97lq8r5 FyhaCPdb4V9r4QHd+ufkZvQDkZxNWf9Tn0Uv+Wkfb9Y6g75VhfuvjqnqWN9VN0ct X-Gm-Gg: ASbGncu7gxkWOM94FWl+ZgDWtwHc7lQZhbuWflDFguIzU0mtZVX0cu/4s6Fu/s5+Fds UUCPGm8w1oJh6GgjEuv+oT5eNLOF3z8ZSMuCrgWLpORejQVZxyicEmwMWslemHZsKnAGZNxtqF5 U1gFeqYvc+m6P/5CCHzUzXtgTM0Y0ctXnRJ+fkZ/1V9PuVZOciA/sEryvU/7IqbOW3xZg6u4HDW QN4tgdmJ8PKNKD2SYCuQltbIPUi5sjOxA2o45i1SlBTBdo9meS/kMy2Qu1zlVln4Kkc/bJzg2Z+ 04r9hvi+O/Lmb5z2yh5cVNx6J3/BUT9GcsL5CxctCJBrgIdemuU/LcnxtPAU5HmIinJoLWKhY8h 6LjjqQw2BfNlIOB41VyaH2nYjRRObk6gR02kiwaOz/dw5Mx2UJzA4HaA45PP5BHBMZpK7UiB9LA EmAudFxF1uWWAeDke9HtkI/4eUc4c0vWWWq+N8Yym+H7h9TgDhqmdnPpzmRgZtSO6iZyDyWh7N9 Mwh2GzlXWoAPHuIBEY+iwjk X-Google-Smtp-Source: AGHT+IGZ2RqPLN3WsmcHTTu5RV3TdGCpvjQ58cfMDmcIZPWXaGEJtHf1FgzU733nIP7zzofM9/L7cg== X-Received: by 2002:a05:690e:164c:b0:63c:f5a6:f307 with SMTP id 956f58d0204a3-640b54ae604mr768919d50.30.1762382072987; Wed, 05 Nov 2025 14:34:32 -0800 (PST) Received: from localhost.localdomain (h96-60-249-169.cncrtn.broadband.dynamic.tds.net. [96.60.249.169]) by smtp.gmail.com with UTF8SMTPSA id 00721157ae682-787b13b6f08sm2866157b3.10.2025.11.05.14.34.32 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 05 Nov 2025 14:34:32 -0800 (PST) From: Demi Marie Obenour Date: Wed, 05 Nov 2025 17:33:33 -0500 Subject: [PATCH 2/2] Move UKI creation to a separate derivation MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: 7bit Message-Id: <20251105-refactor-verity-v1-2-b8ba27dfdf06@gmail.com> References: <20251105-refactor-verity-v1-0-b8ba27dfdf06@gmail.com> In-Reply-To: <20251105-refactor-verity-v1-0-b8ba27dfdf06@gmail.com> To: Spectrum OS Development X-Mailer: b4 0.14.3 X-Developer-Signature: v=1; a=ed25519-sha256; t=1762382012; l=5919; i=demiobenour@gmail.com; s=20250729; h=from:subject:message-id; bh=36qnYoLsRiAar/xqHoxfxy37P5s+Wm4NAfI4+6Jm024=; b=qyJqklgLIh92mRijtl9Y32CK+kVz5Y6ROsFJumzEPMjuL+mHa79Xoh85mNPDxlfvZFzNb6qOI Tzw96CK3ZIzCNWTLr8BJ0zXp9jAornHCjWCd1XYGfctCK0Jr8qT4+zo X-Developer-Key: i=demiobenour@gmail.com; a=ed25519; pk=X57Q4/YQDj9t4SBeKaDwvXYKB6quZJVx/DE2Ly2out0= Message-ID-Hash: FAOE5XKWFIM7PNUVQ7ROELBWWTBPTYYH X-Message-ID-Hash: FAOE5XKWFIM7PNUVQ7ROELBWWTBPTYYH X-MailFrom: demiobenour@gmail.com X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-devel.spectrum-os.org-0; header-match-devel.spectrum-os.org-1; header-match-devel.spectrum-os.org-2; header-match-devel.spectrum-os.org-3; header-match-devel.spectrum-os.org-4; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header CC: Demi Marie Obenour , Alyssa Ross X-Mailman-Version: 3.3.9 Precedence: list List-Id: Patches and low-level development discussion Archived-At: List-Archive: List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: It will be used by the update code later. No functional change intended, other than a trivial shell script refactoring. Signed-off-by: Demi Marie Obenour --- host/efi.nix | 46 ++++++++++++++++++++++++++++++++++++++++++++++ pkgs/default.nix | 1 + release/live/Makefile | 15 ++------------- release/live/default.nix | 20 +++++--------------- 4 files changed, 54 insertions(+), 28 deletions(-) diff --git a/host/efi.nix b/host/efi.nix new file mode 100644 index 0000000000000000000000000000000000000000..45c76e4f37f52a62744318df3590dd429c005fe9 --- /dev/null +++ b/host/efi.nix @@ -0,0 +1,46 @@ +# SPDX-License-Identifier: EUPL-1.2+ +# SPDX-FileCopyrightText: 2021-2024 Alyssa Ross +# SPDX-FileCopyrightText: 2025 Demi Marie Obenour + +import ../lib/call-package.nix ( +{ bash, callSpectrumPackage, cryptsetup, runCommand +, stdenv, systemdUkify, rootfs, verity +}: +let + initramfs = callSpectrumPackage ./initramfs {}; + kernel = "${rootfs.kernel}/${stdenv.hostPlatform.linux-kernel.target}"; + systemd = systemdUkify.overrideAttrs ({ mesonFlags ? [], ... }: { + # The default limit is too low to build a generic aarch64 distro image: + # https://github.com/systemd/systemd/pull/37417 + mesonFlags = mesonFlags ++ [ "-Defi-stub-extra-sections=3000" ]; + }); +in + +runCommand "spectrum-efi" { + nativeBuildInputs = [ cryptsetup systemd bash ]; + __structuredAttrs = true; + unsafeDiscardReferences = { out = true; }; + dontFixup = true; + passthru = { inherit systemd; }; + env = { + DTBS = "${rootfs.kernel}/dtbs"; + KERNEL = kernel; + INITRAMFS = initramfs; + VERITY = verity; + }; +} '' + read -r roothash < "$VERITY/rootfs.verity.roothash" + { \ + printf "[UKI]\nDeviceTreeAuto=" + if [ -d "$DTBS" ]; then + find "$DTBS" -name '*.dtb' -print0 | tr '\0' ' ' + fi + } | ukify build \ + --output "$out" \ + --config /dev/stdin \ + --linux "$KERNEL" \ + --initrd "$INITRAMFS" \ + --os-release $'NAME="Spectrum"\n' \ + --cmdline "ro intel_iommu=on roothash=$roothash" + '' +) (_: {}) diff --git a/pkgs/default.nix b/pkgs/default.nix index bc02f6b2f532f3ee1a2ea3aa45de3c9561bbb6ab..95f431f560f6bf61dd56141a349210526a519838 100644 --- a/pkgs/default.nix +++ b/pkgs/default.nix @@ -37,6 +37,7 @@ let rootfs = self.callSpectrumPackage ../host/rootfs {}; verity = self.callSpectrumPackage ../host/verity.nix {}; + efi = self.callSpectrumPackage ../host/efi.nix {}; spectrum-build-tools = self.callSpectrumPackage ../tools { appSupport = false; buildSupport = true; diff --git a/release/live/Makefile b/release/live/Makefile index 191b44944af0adf965e1d5f2785719b236bfd99c..4de8743f42dec65aa863c3020cd70124316a6118 100644 --- a/release/live/Makefile +++ b/release/live/Makefile @@ -19,19 +19,8 @@ $(dest): ../../scripts/format-uuid.sh ../../scripts/make-gpt.sh ../../scripts/sf build/empty: mkdir -p $@ -build/spectrum.efi: $(DTBS) $(KERNEL) $(INITRAMFS) $(ROOT_FS_VERITY_ROOTHASH) - { \ - printf "[UKI]\nDeviceTreeAuto=" && \ - find $(DTBS) -name '*.dtb' -print0 | tr '\0' ' ' ;\ - } | $(UKIFY) build \ - --output $@ \ - --config /dev/stdin \ - --linux $(KERNEL) \ - --initrd $(INITRAMFS) \ - --os-release $$'NAME="Spectrum"\n' \ - --cmdline "ro intel_iommu=on roothash=$$(cat "$$ROOT_FS_VERITY_ROOTHASH")" - -build/boot.fat: $(SYSTEMD_BOOT_EFI) build/spectrum.efi +build/boot.fat: $(SYSTEMD_BOOT_EFI) $(EFI_IMAGE) build/empty + ln -sf -- "$$EFI_IMAGE" build/spectrum.efi $(TRUNCATE) -s 440401920 $@ $(MKFS_FAT) $@ $(MMD) -i $@ ::/EFI ::/EFI/BOOT ::/EFI/Linux diff --git a/release/live/default.nix b/release/live/default.nix index 32901f00a270f6dae005563b2e4082ad225c61e1..8b9f48997963608db86a1d3346bfe2b66f55adf5 100644 --- a/release/live/default.nix +++ b/release/live/default.nix @@ -6,7 +6,7 @@ import ../../lib/call-package.nix ( { callSpectrumPackage, spectrum-build-tools, rootfs, src , lib, pkgsStatic, stdenvNoCC , cryptsetup, dosfstools, jq, mtools, util-linux -, systemdUkify, verity +, verity, efi }: let @@ -14,13 +14,6 @@ let stdenv = stdenvNoCC; - systemd = systemdUkify.overrideAttrs ({ mesonFlags ? [], ... }: { - # The default limit is too low to build a generic aarch64 distro image: - # https://github.com/systemd/systemd/pull/37417 - mesonFlags = mesonFlags ++ [ "-Defi-stub-extra-sections=3000" ]; - }); - - initramfs = callSpectrumPackage ../../host/initramfs {}; efiArch = stdenv.hostPlatform.efiArch; in @@ -40,19 +33,16 @@ stdenv.mkDerivation { sourceRoot = "source/release/live"; nativeBuildInputs = [ - cryptsetup dosfstools jq spectrum-build-tools mtools systemd util-linux + cryptsetup dosfstools jq spectrum-build-tools mtools util-linux ]; env = { - INITRAMFS = initramfs; - KERNEL = "${rootfs.kernel}/${stdenv.hostPlatform.linux-kernel.target}"; ROOT_FS = rootfs; ROOT_FS_VERITY = "${verity}/rootfs.verity.superblock"; ROOT_FS_VERITY_ROOTHASH = "${verity}/rootfs.verity.roothash"; - SYSTEMD_BOOT_EFI = "${systemd}/lib/systemd/boot/efi/systemd-boot${efiArch}.efi"; + SYSTEMD_BOOT_EFI = "${efi.systemd}/lib/systemd/boot/efi/systemd-boot${efiArch}.efi"; + EFI_IMAGE = efi; EFINAME = "BOOT${toUpper efiArch}.EFI"; - } // lib.optionalAttrs stdenv.hostPlatform.linux-kernel.DTB or false { - DTBS = "${rootfs.kernel}/dtbs"; }; buildFlags = [ "dest=$(out)" ]; @@ -65,6 +55,6 @@ stdenv.mkDerivation { unsafeDiscardReferences = { out = true; }; dontFixup = true; - passthru = { inherit initramfs rootfs; }; + passthru = { inherit rootfs; }; } ) (_: {}) -- 2.51.2