feat: Kernel files from our own release, checked before install

The kernel-7.1.6-1 release is the first download source. Every file must
match the SHA-256 in the script and have a valid CachyOS signature.
This commit is contained in:
theupriser committed 2026-09-25 08:08:28 +02:00
1 parent c4bd1ca39c
commit 727e6a2302
3 files changed
+43 -7

No files matched your search

+4
View File
@@ -15,6 +15,10 @@ one per merged pull request.
- The packages are kept in `/var/cache/steamify/kernel` and reinstalled - The packages are kept in `/var/cache/steamify/kernel` and reinstalled
from there without downloading; else from pacman's cache, the CachyOS from there without downloading; else from pacman's cache, the CachyOS
archive, the CachyOS mirror, or `PINNED_KERNEL_URL`. archive, the CachyOS mirror, or `PINNED_KERNEL_URL`.
- First download source: the `kernel-7.1.6-1` release of this repo, a
one-off release that always has these files.
- Every file is checked against its SHA-256 (in the script) and its
CachyOS signature before it's installed; a bad file is deleted.
- Installed kernel headers are no longer updated by the wizard, so the - Installed kernel headers are no longer updated by the wizard, so the
pinned kernel keeps matching headers. pinned kernel keeps matching headers.
- The BIOS item moves down one (9 on a Steam Machine). - The BIOS item moves down one (9 on a Steam Machine).
+5 -3
View File
@@ -305,9 +305,11 @@ them. DKMS builds the LED driver for it; restart to boot it.
The packages (and their signatures, which pacman checks) are kept in The packages (and their signatures, which pacman checks) are kept in
`/var/cache/steamify/kernel`, so re-applying needs no download. Missing `/var/cache/steamify/kernel`, so re-applying needs no download. Missing
files are taken from pacman's cache, else downloaded from files are taken from pacman's cache, else downloaded from this repo's
`archive.cachyos.org`, then `mirror.cachyos.org` (which only has the current `kernel-7.1.6-1` release, then `archive.cachyos.org`, then
kernel). Set `PINNED_KERNEL_URL` to a directory URL with the files to try `mirror.cachyos.org` (which only has the current kernel). Every file must
match the SHA-256 in the script and have a valid CachyOS signature; a bad
one is deleted, so the next run downloads it again. Set `PINNED_KERNEL_URL` to a directory URL with the files to try
another source first, or drop them into the kernel directory yourself. another source first, or drop them into the kernel directory yourself.
Unticking it removes the pin and runs `sudo pacman -Syu`, which brings the Unticking it removes the pin and runs `sudo pacman -Syu`, which brings the
+34 -4
View File
@@ -22,11 +22,19 @@ PINNED_KERNEL_VER="7.1.6-1"
PINNED_KERNEL_KVER="7.1.6-1-cachyos" PINNED_KERNEL_KVER="7.1.6-1-cachyos"
PINNED_KERNEL_PKGS=(linux-cachyos linux-cachyos-headers) PINNED_KERNEL_PKGS=(linux-cachyos linux-cachyos-headers)
PINNED_KERNEL_DIR="${PINNED_KERNEL_DIR:-/var/cache/steamify/kernel}" PINNED_KERNEL_DIR="${PINNED_KERNEL_DIR:-/var/cache/steamify/kernel}"
# Tried in order, after the kernel dir and pacman's cache. The archive keeps # SHA-256 of each package, so a file from any source is the one reviewed
# every release; the mirror only the current one. PINNED_KERNEL_URL puts # here; its CachyOS signature is checked as well.
# another source (a directory holding the files) in front. declare -A PINNED_KERNEL_SHA256=(
[linux-cachyos]=417fcd07102192b86e78e92ed7171d5a49378e9f57faea3fa2c7c541e9f68d08
[linux-cachyos-headers]=d069866a11d9092746e1d5133cefd8924f027da2c9bf5af38d30b3aed6ded9bf
)
# Tried in order, after the kernel dir and pacman's cache. Our own release
# always has these files; the archive keeps every release; the mirror only
# the current one. PINNED_KERNEL_URL puts another source (a directory
# holding the files) in front.
PINNED_KERNEL_SOURCES=( PINNED_KERNEL_SOURCES=(
${PINNED_KERNEL_URL:+"$PINNED_KERNEL_URL"} ${PINNED_KERNEL_URL:+"$PINNED_KERNEL_URL"}
"https://github.com/theupriser/steamify-cachyos/releases/download/kernel-$PINNED_KERNEL_VER"
"https://archive.cachyos.org/archive/cachyos" "https://archive.cachyos.org/archive/cachyos"
"https://mirror.cachyos.org/repo/x86_64/cachyos" "https://mirror.cachyos.org/repo/x86_64/cachyos"
) )
@@ -58,6 +66,22 @@ fetch_pinned_kernel_file() {
return 1 return 1
} }
verify_pinned_kernel_pkg() {
# $1 = package name, $2 = file. Both checks must pass: the SHA-256 from
# this script, and the CachyOS signature (pacman on its own installs a
# local file without a .sig: LocalFileSigLevel = Optional).
local sum
sum="$(sha256sum "$2" | cut -d' ' -f1)"
if [[ "$sum" != "${PINNED_KERNEL_SHA256[$1]}" ]]; then
err "$(basename "$2") doesn't match its expected checksum."
return 1
fi
if ! sudo pacman-key --verify "$2.sig" "$2" >/dev/null 2>&1; then
err "$(basename "$2") doesn't have a valid CachyOS signature."
return 1
fi
}
pin_kernel_in_pacman_conf() { pin_kernel_in_pacman_conf() {
# Adds our packages to IgnorePkg in [options], keeping what's there. # Adds our packages to IgnorePkg in [options], keeping what's there.
local p local p
@@ -94,13 +118,19 @@ install_pinned_kernel() {
f="$p-$PINNED_KERNEL_VER-x86_64.pkg.tar.zst" f="$p-$PINNED_KERNEL_VER-x86_64.pkg.tar.zst"
fetch_pinned_kernel_file "$f" && fetch_pinned_kernel_file "$f.sig" || fetch_pinned_kernel_file "$f" && fetch_pinned_kernel_file "$f.sig" ||
{ err "Couldn't download $f from any source."; return 1; } { err "Couldn't download $f from any source."; return 1; }
if ! verify_pinned_kernel_pkg "$p" "$PINNED_KERNEL_DIR/$f"; then
# Removed, so the next run fetches it again.
sudo rm -f "$PINNED_KERNEL_DIR/$f" "$PINNED_KERNEL_DIR/$f.sig"
err "Removed it; run the wizard again to download it once more."
return 1
fi
files+=("$PINNED_KERNEL_DIR/$f") files+=("$PINNED_KERNEL_DIR/$f")
done done
# pacman checks each package against the .sig next to it. # pacman checks each package against the .sig next to it.
info "Installing kernel $PINNED_KERNEL_VER..." info "Installing kernel $PINNED_KERNEL_VER..."
if ! sudo pacman -U --noconfirm "${files[@]}"; then if ! sudo pacman -U --noconfirm "${files[@]}"; then
err "Installing kernel $PINNED_KERNEL_VER failed. If a file is damaged, delete it from $PINNED_KERNEL_DIR and try again." err "Installing kernel $PINNED_KERNEL_VER failed."
return 1 return 1
fi fi
[[ "$(uname -r)" != "$PINNED_KERNEL_KVER" ]] && RESTART_FOR_LOGIN=true [[ "$(uname -r)" != "$PINNED_KERNEL_KVER" ]] && RESTART_FOR_LOGIN=true