Files
taninux/iso/bootstrap-profile.sh
karim 8fb8efcbbd packaging/iso: uninstall safety, fail-closed AUR updates, no sshd on live ISO
- tanin-greet.install: post_remove restores the previous greetd config —
  removing the package no longer leaves greetd pointing at a dead binary
- aur-autoupdate: skip packages when the AUR RPC is unreachable instead of
  building blind (fail closed)
- build-tanin-repo: per-package makepkg logs instead of >/dev/null
- live ISO: drop sshd.service enablement (root has an empty password on the
  live medium); encoded in bootstrap-profile.sh so it survives re-bootstrap
- gtklock config: de-personalize hardcoded /home/karim path, mark as
  not-yet-packaged reference
- tanin-desktop PKGBUILD: correct stale AUR-vs-extra comments (gtklock,
  awww, cliphist are in extra), document the eww-git provides=eww contract
- docs/distribution.md: mark SigLevel TrustAll as temporary/insecure, add
  repo-signing TODO (repo-add -s, SigLevel Required), tick done roadmap items
- tanin-calendar + niri-config.kdl: pending session work

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-02 21:22:20 +02:00

59 lines
2.8 KiB
Bash
Executable File

#!/usr/bin/env bash
# Assemble the TANINUX archiso profile = canonical `releng` base + our overrides,
# then (optionally) build the ISO. Run as your user; mkarchiso uses sudo.
#
# sudo pacman -S archiso # once
# ./bootstrap-profile.sh # assemble ./build-profile/
# ./bootstrap-profile.sh --build # assemble + mkarchiso -> ./out/
#
# Why this approach: we don't hand-maintain the bootloader/mkinitcpio boilerplate
# (error-prone) — we take it from the authoritative releng profile and only
# overlay our deltas (profiledef, pacman.conf, packages, airootfs, calamares).
set -euo pipefail
HERE="$(cd "$(dirname "$0")" && pwd)"
RELENG=/usr/share/archiso/configs/releng
PROFILE="$HERE/build-profile"
[ -d "$RELENG" ] || { echo "archiso not installed — run: sudo pacman -S archiso"; exit 1; }
echo "==> base: copy releng -> build-profile"
rm -rf "$PROFILE"
cp -r "$RELENG" "$PROFILE"
echo "==> kernel: live ISO uses linux-zen (matches the target)"
sed -i 's/^linux$/linux-zen/' "$PROFILE/packages.x86_64"
# point the live boot entries at the zen kernel images
grep -rl -e 'vmlinuz-linux' -e 'initramfs-linux' \
"$PROFILE/efiboot" "$PROFILE/syslinux" "$PROFILE/grub" 2>/dev/null \
| xargs -r sed -i -e 's/vmlinuz-linux/vmlinuz-linux-zen/g' \
-e 's/initramfs-linux/initramfs-linux-zen/g'
echo "==> branding: Arch Linux -> TANINUX in the boot menus"
grep -rl 'Arch Linux' "$PROFILE/efiboot" "$PROFILE/syslinux" "$PROFILE/grub" 2>/dev/null \
| xargs -r sed -i -e 's/Arch Linux/TANINUX/g' -e 's/Archlinux/TANINUX/g'
echo "==> overlay TANINUX overrides"
cat "$HERE/overrides/packages.x86_64" >> "$PROFILE/packages.x86_64"
install -m644 "$HERE/overrides/profiledef.sh" "$PROFILE/profiledef.sh"
install -m644 "$HERE/overrides/pacman.conf" "$PROFILE/pacman.conf"
cp -rT "$HERE/overrides/airootfs" "$PROFILE/airootfs"
echo "==> security: do NOT enable sshd on the live ISO"
# releng ships root with an empty password AND enables sshd (PermitRootLogin yes)
# -> open remote root on any network the live ISO joins. We don't need sshd for
# the installer, so drop the wants-symlink. This is re-applied on every bootstrap
# because build-profile is regenerated from releng above (authoritative fix).
rm -f "$PROFILE/airootfs/etc/systemd/system/multi-user.target.wants/sshd.service"
echo "==> profile ready: $PROFILE"
WORK=/tmp/tanin-work
if [ "${1:-}" = "--build" ]; then
echo "==> clean work dir (mkarchiso reuses stale stages otherwise -> 'too short' builds)"
sudo rm -rf "$WORK"
echo "==> building ISO (sudo mkarchiso) … this takes a while (downloads + squashfs)"
sudo mkarchiso -v -w "$WORK" -o "$HERE/out" "$PROFILE"
echo "ISO written to $HERE/out/"
else
echo "build with: sudo rm -rf $WORK && sudo mkarchiso -v -w $WORK -o \"$HERE/out\" \"$PROFILE\""
fi