mirror of
https://github.com/theupriser/steamify-cachyos.git
synced 2026-10-03 17:41:58 +02:00
feat: Kernel files from our own release, checked before install
The kernel-7.1.6-1 release is the first download source. Every file must match the SHA-256 in the script and have a valid CachyOS signature.
This commit is contained in:
1 parent
c4bd1ca39c
commit
727e6a2302
3 files changed
+43
-7
No files matched your search
@@ -15,6 +15,10 @@ one per merged pull request.
|
|||||||
- The packages are kept in `/var/cache/steamify/kernel` and reinstalled
|
- The packages are kept in `/var/cache/steamify/kernel` and reinstalled
|
||||||
from there without downloading; else from pacman's cache, the CachyOS
|
from there without downloading; else from pacman's cache, the CachyOS
|
||||||
archive, the CachyOS mirror, or `PINNED_KERNEL_URL`.
|
archive, the CachyOS mirror, or `PINNED_KERNEL_URL`.
|
||||||
|
- First download source: the `kernel-7.1.6-1` release of this repo, a
|
||||||
|
one-off release that always has these files.
|
||||||
|
- Every file is checked against its SHA-256 (in the script) and its
|
||||||
|
CachyOS signature before it's installed; a bad file is deleted.
|
||||||
- Installed kernel headers are no longer updated by the wizard, so the
|
- Installed kernel headers are no longer updated by the wizard, so the
|
||||||
pinned kernel keeps matching headers.
|
pinned kernel keeps matching headers.
|
||||||
- The BIOS item moves down one (9 on a Steam Machine).
|
- The BIOS item moves down one (9 on a Steam Machine).
|
||||||
|
|||||||
@@ -305,9 +305,11 @@ them. DKMS builds the LED driver for it; restart to boot it.
|
|||||||
|
|
||||||
The packages (and their signatures, which pacman checks) are kept in
|
The packages (and their signatures, which pacman checks) are kept in
|
||||||
`/var/cache/steamify/kernel`, so re-applying needs no download. Missing
|
`/var/cache/steamify/kernel`, so re-applying needs no download. Missing
|
||||||
files are taken from pacman's cache, else downloaded from
|
files are taken from pacman's cache, else downloaded from this repo's
|
||||||
`archive.cachyos.org`, then `mirror.cachyos.org` (which only has the current
|
`kernel-7.1.6-1` release, then `archive.cachyos.org`, then
|
||||||
kernel). Set `PINNED_KERNEL_URL` to a directory URL with the files to try
|
`mirror.cachyos.org` (which only has the current kernel). Every file must
|
||||||
|
match the SHA-256 in the script and have a valid CachyOS signature; a bad
|
||||||
|
one is deleted, so the next run downloads it again. Set `PINNED_KERNEL_URL` to a directory URL with the files to try
|
||||||
another source first, or drop them into the kernel directory yourself.
|
another source first, or drop them into the kernel directory yourself.
|
||||||
|
|
||||||
Unticking it removes the pin and runs `sudo pacman -Syu`, which brings the
|
Unticking it removes the pin and runs `sudo pacman -Syu`, which brings the
|
||||||
|
|||||||
+34
-4
@@ -22,11 +22,19 @@ PINNED_KERNEL_VER="7.1.6-1"
|
|||||||
PINNED_KERNEL_KVER="7.1.6-1-cachyos"
|
PINNED_KERNEL_KVER="7.1.6-1-cachyos"
|
||||||
PINNED_KERNEL_PKGS=(linux-cachyos linux-cachyos-headers)
|
PINNED_KERNEL_PKGS=(linux-cachyos linux-cachyos-headers)
|
||||||
PINNED_KERNEL_DIR="${PINNED_KERNEL_DIR:-/var/cache/steamify/kernel}"
|
PINNED_KERNEL_DIR="${PINNED_KERNEL_DIR:-/var/cache/steamify/kernel}"
|
||||||
# Tried in order, after the kernel dir and pacman's cache. The archive keeps
|
# SHA-256 of each package, so a file from any source is the one reviewed
|
||||||
# every release; the mirror only the current one. PINNED_KERNEL_URL puts
|
# here; its CachyOS signature is checked as well.
|
||||||
# another source (a directory holding the files) in front.
|
declare -A PINNED_KERNEL_SHA256=(
|
||||||
|
[linux-cachyos]=417fcd07102192b86e78e92ed7171d5a49378e9f57faea3fa2c7c541e9f68d08
|
||||||
|
[linux-cachyos-headers]=d069866a11d9092746e1d5133cefd8924f027da2c9bf5af38d30b3aed6ded9bf
|
||||||
|
)
|
||||||
|
# Tried in order, after the kernel dir and pacman's cache. Our own release
|
||||||
|
# always has these files; the archive keeps every release; the mirror only
|
||||||
|
# the current one. PINNED_KERNEL_URL puts another source (a directory
|
||||||
|
# holding the files) in front.
|
||||||
PINNED_KERNEL_SOURCES=(
|
PINNED_KERNEL_SOURCES=(
|
||||||
${PINNED_KERNEL_URL:+"$PINNED_KERNEL_URL"}
|
${PINNED_KERNEL_URL:+"$PINNED_KERNEL_URL"}
|
||||||
|
"https://github.com/theupriser/steamify-cachyos/releases/download/kernel-$PINNED_KERNEL_VER"
|
||||||
"https://archive.cachyos.org/archive/cachyos"
|
"https://archive.cachyos.org/archive/cachyos"
|
||||||
"https://mirror.cachyos.org/repo/x86_64/cachyos"
|
"https://mirror.cachyos.org/repo/x86_64/cachyos"
|
||||||
)
|
)
|
||||||
@@ -58,6 +66,22 @@ fetch_pinned_kernel_file() {
|
|||||||
return 1
|
return 1
|
||||||
}
|
}
|
||||||
|
|
||||||
|
verify_pinned_kernel_pkg() {
|
||||||
|
# $1 = package name, $2 = file. Both checks must pass: the SHA-256 from
|
||||||
|
# this script, and the CachyOS signature (pacman on its own installs a
|
||||||
|
# local file without a .sig: LocalFileSigLevel = Optional).
|
||||||
|
local sum
|
||||||
|
sum="$(sha256sum "$2" | cut -d' ' -f1)"
|
||||||
|
if [[ "$sum" != "${PINNED_KERNEL_SHA256[$1]}" ]]; then
|
||||||
|
err "$(basename "$2") doesn't match its expected checksum."
|
||||||
|
return 1
|
||||||
|
fi
|
||||||
|
if ! sudo pacman-key --verify "$2.sig" "$2" >/dev/null 2>&1; then
|
||||||
|
err "$(basename "$2") doesn't have a valid CachyOS signature."
|
||||||
|
return 1
|
||||||
|
fi
|
||||||
|
}
|
||||||
|
|
||||||
pin_kernel_in_pacman_conf() {
|
pin_kernel_in_pacman_conf() {
|
||||||
# Adds our packages to IgnorePkg in [options], keeping what's there.
|
# Adds our packages to IgnorePkg in [options], keeping what's there.
|
||||||
local p
|
local p
|
||||||
@@ -94,13 +118,19 @@ install_pinned_kernel() {
|
|||||||
f="$p-$PINNED_KERNEL_VER-x86_64.pkg.tar.zst"
|
f="$p-$PINNED_KERNEL_VER-x86_64.pkg.tar.zst"
|
||||||
fetch_pinned_kernel_file "$f" && fetch_pinned_kernel_file "$f.sig" ||
|
fetch_pinned_kernel_file "$f" && fetch_pinned_kernel_file "$f.sig" ||
|
||||||
{ err "Couldn't download $f from any source."; return 1; }
|
{ err "Couldn't download $f from any source."; return 1; }
|
||||||
|
if ! verify_pinned_kernel_pkg "$p" "$PINNED_KERNEL_DIR/$f"; then
|
||||||
|
# Removed, so the next run fetches it again.
|
||||||
|
sudo rm -f "$PINNED_KERNEL_DIR/$f" "$PINNED_KERNEL_DIR/$f.sig"
|
||||||
|
err "Removed it; run the wizard again to download it once more."
|
||||||
|
return 1
|
||||||
|
fi
|
||||||
files+=("$PINNED_KERNEL_DIR/$f")
|
files+=("$PINNED_KERNEL_DIR/$f")
|
||||||
done
|
done
|
||||||
|
|
||||||
# pacman checks each package against the .sig next to it.
|
# pacman checks each package against the .sig next to it.
|
||||||
info "Installing kernel $PINNED_KERNEL_VER..."
|
info "Installing kernel $PINNED_KERNEL_VER..."
|
||||||
if ! sudo pacman -U --noconfirm "${files[@]}"; then
|
if ! sudo pacman -U --noconfirm "${files[@]}"; then
|
||||||
err "Installing kernel $PINNED_KERNEL_VER failed. If a file is damaged, delete it from $PINNED_KERNEL_DIR and try again."
|
err "Installing kernel $PINNED_KERNEL_VER failed."
|
||||||
return 1
|
return 1
|
||||||
fi
|
fi
|
||||||
[[ "$(uname -r)" != "$PINNED_KERNEL_KVER" ]] && RESTART_FOR_LOGIN=true
|
[[ "$(uname -r)" != "$PINNED_KERNEL_KVER" ]] && RESTART_FOR_LOGIN=true
|
||||||
|
|||||||
Reference in new issue
Block a user