From 80daf8e448d61c8087e5158591018d80420c7d92 Mon Sep 17 00:00:00 2001 From: guiohm Date: Feb 02 2025 14:51:57 +0000 Subject: libre/filesystem: upgrade to v2024.11.21 --- diff --git a/libre/filesystem/PKGBUILD b/libre/filesystem/PKGBUILD index a37813e..2a879c6 100644 --- a/libre/filesystem/PKGBUILD +++ b/libre/filesystem/PKGBUILD @@ -11,30 +11,75 @@ pkgname=filesystem -pkgver=2023.09.18 +pkgver=2024.11.21 pkgrel=1 pkgrel+=.parabola1 pkgdesc='Base Parabola GNU/Linux-libre files' arch=('x86_64') arch+=('armv7h' 'i686' 'ppc64le') -license=('GPL') +license=('GPL') # FIXME: Arch says GPL-3.0-or-later url='https://www.parabola.nu' depends=('iana-etc') -backup=('etc/crypttab' 'etc/fstab' 'etc/group' 'etc/gshadow' 'etc/host.conf' - 'etc/hosts' 'etc/issue' 'etc/ld.so.conf' 'etc/nsswitch.conf' - 'etc/passwd' 'etc/profile' 'etc/resolv.conf' 'etc/securetty' - 'etc/shadow' 'etc/shells' 'etc/subuid' 'etc/subgid') +backup=( + 'etc/crypttab' + 'etc/fstab' + 'etc/group' + 'etc/gshadow' + 'etc/host.conf' + 'etc/hosts' + 'etc/issue' + 'etc/ld.so.conf' + 'etc/nsswitch.conf' + 'etc/passwd' + 'etc/profile' + 'etc/resolv.conf' + 'etc/securetty' + 'etc/shadow' + 'etc/shells' + 'etc/subgid' + 'etc/subuid' +) backup+=('etc/motd') -source=('crypttab' 'env-generator' 'fstab' 'group' 'gshadow' 'host.conf' 'hosts' - 'issue' 'ld.so.conf' 'locale.sh' 'nsswitch.conf' 'os-release' 'profile' - 'passwd' 'resolv.conf' 'securetty' 'shadow' 'shells' 'sysctl' 'sysusers' - 'tmpfiles' 'subuid' 'subgid' 'archlinux-logo.svg' 'archlinux-logo.png' - 'archlinux-logo-text.svg' 'archlinux-logo-text-dark.svg') +source=( + 'arch-release' + 'archlinux-logo.png' + 'archlinux-logo.svg' + 'archlinux-logo-text.svg' + 'archlinux-logo-text-dark.svg' + 'crypttab' + 'env-generator' + 'fstab' + 'group' + 'gshadow' + 'host.conf' + 'hosts' + 'issue' + 'ld.so.conf' + 'locale.sh' + 'nsswitch.conf' + 'os-release' + 'passwd' + 'profile' + 'resolv.conf' + 'securetty' + 'shadow' + 'shells' + 'sysctl' + 'sysusers' + 'tmpfiles' + 'subgid' + 'subuid' +) source=( ${source[*]//archlinux-logo/parabola-logo} ) source+=('motd') source+=('disable-dotnet-telemetry.sh') # NOTE: the commented files below, are those which should differ from arch -sha256sums=('e03bede3d258d680548696623d5979c6edf03272e801a813c81ba5a5c64f4f82' +sha256sums=('01ba4719c80b6fe911b091a7c05124b64eeece964e09c058ef8f9805daca546b' + 'c6486f4c9456fa62a75727adfcc8f2403a1a9fac29386f942c0678c109cc72e8' # parabola-logo.png + 'd5f0a4f75761afd5ebbc6970ac9aba5be3c28bb660adf7118353a0e018911e68' # parabola-logo.svg + '09838fea00c5ceff6e7ed28bb1b6d62feb1e2471df9fe5a4328071ecb9e837f3' # parabola-logo-text.svg + 'bc9be3442fab17ac6990814db4c0cc76c2ac6112c70a6c103530f607aa54c11e' # parabola-logo-text-dark.svg + 'e03bede3d258d680548696623d5979c6edf03272e801a813c81ba5a5c64f4f82' 'ed0cb4f1db4021f8c3b5ce78fdf91d2c0624708f58f36c9cf867f4d93c3bc6da' 'e54626e74ed8fee4173b62a545ab1c3a3a069e4217a0ee8fc398d9933e9c1696' '244f0718ee2a9d6862ae59d6c18c1dd1568651eada91a704574fa527fbac2b3a' @@ -42,25 +87,21 @@ sha256sums=('e03bede3d258d680548696623d5979c6edf03272e801a813c81ba5a5c64f4f82' '4d7b647169063dfedbff5e1e22cee77bd1a4183dbcfd5e802e68939da4bbf733' 'd9cd8a77d9e0aa5e90d7f4ed74c8745c17b525e720e28e4c44364150003c35f9' '8b8f24af3454e87b4e316b4978d0de7958a98cc44606aa801d9696d2c21f4385' # issue (branding) - 'dad04a370e488aa85fb0a813a5c83cf6fd981ce01883fc59685447b092de84b5' - '8ca2d8eef6fb5143c9ef7e9174ccfef59ac7ad2deee243574cd10c763156cc10' + '785c6c3614a27ae6115a27c1ca55bbf333654780997c4ba7e181172b021d1bf3' + '153d848ed51f2774e5a1578ea08e0c8586ecc63f7562697e035b84247edb2f82' 'c8ee7a9faf798caab178ec51afae4146f1efd8a716b7acedf28345b6c75f9697' '359623c74da854d93e7dcc5335f3e3c95c378af75f640fc728596268ce4391a9' # os-release (branding) - '8f08231922fe185d3132f9aedded5cd688fb7c482a6f6f272402ded82fa4849a' - '5e06477834f51abf42ea4e8dc199632afc6afbfd8c44354685a271e9a48d2c0a' + '13e2783884783ef46b8345fbcdf7880f0414c0a9c42e2b2fc6a2b048cbc2d86e' + 'e97ae25dc1b9cb6633f823ec2384bb88e9bffcfa16a0839adabcd62f4aa77d6f' # profile '5557d8e601b17a80d1ea7de78a9869be69637cb6a02fbfe334e22fdf64e61d4c' 'd88be2b45b43605ff31dd83d6a138069b6c2e92bc8989b7b9ab9eba8da5f8c7b' '6e13705ac4d6f69cdba118c6b70c722346fd3c45224133e6bbfe28aca719563c' 'ec289c03aa0d150e90e8287f001c8e6552ab9dd54f450bdb5c2d2254e477965b' - '89e43a0b7028f52d5c8e7fb961d962c4b4f4e9595880a6157274ddb2c7c0b6b4' + '2905b91729fd252d50064460862ab78c567ac3c103847e5e10c267d1f85928ca' '59877ca8c00192776d06d0c11087083e31e5c5ba6830c4faaa924d858df42f8a' # sysusers (branding) - '5d8e61479f0093852365090e84d8d95b1e7fccfab068274ee25863bde6ff3e07' + 'f1b45f29b1a6b6796190bea821aebdd85ea5107115d6e95a4f9f2f5c9292b575' 'e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855' - 'e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855' - 'd5f0a4f75761afd5ebbc6970ac9aba5be3c28bb660adf7118353a0e018911e68' # parabola-logo.svg - 'c6486f4c9456fa62a75727adfcc8f2403a1a9fac29386f942c0678c109cc72e8' # parabola-logo.png - '09838fea00c5ceff6e7ed28bb1b6d62feb1e2471df9fe5a4328071ecb9e837f3' # parabola-logo-text.svg - 'bc9be3442fab17ac6990814db4c0cc76c2ac6112c70a6c103530f607aa54c11e') # parabola-logo-text-dark.svg + 'e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855') sha256sums+=('0018e0387155ee65472f71f0003fcbcb863355d12442150922e7156da12cabad') # motd sha256sums+=('0869a4e09afceabf9dbc3c46622b254e373eda48af71e2936acd0652c7d3518e') # disable-dotnet-telemetry.sh @@ -73,92 +114,166 @@ prepare() { } package() { - cd "$pkgdir" + local group link mode source_file user + declare -A directories + declare -A files + declare -A symlinks - # setup root filesystem - for d in boot dev etc home mnt usr var opt srv/http run; do - install -d -m755 $d - done - install -d -m555 proc - install -d -m555 sys - install -d -m0750 root - install -d -m1777 tmp - # vsftpd won't run with write perms on /srv/ftp - # ftp (uid 14/gid 11) - install -d -m555 -g 11 srv/ftp - - # setup /etc and /usr/share/factory/etc - install -d etc/{ld.so.conf.d,skel,profile.d} usr/share/factory/etc - for f in fstab group host.conf hosts issue ld.so.conf nsswitch.conf \ - passwd resolv.conf securetty shells profile subuid subgid; do - install -m644 "$srcdir"/$f etc/ - install -m644 "$srcdir"/$f usr/share/factory/etc/ - done - ln -s ../proc/self/mounts etc/mtab - for f in gshadow shadow crypttab; do - install -m600 "$srcdir"/$f etc/ - install -m600 "$srcdir"/$f usr/share/factory/etc/ - done - touch etc/arch-release - touch etc/parabola-release - install -m644 "$srcdir"/motd etc/ - install -m644 "$srcdir"/locale.sh etc/profile.d/locale.sh - install -Dm644 "$srcdir"/os-release usr/lib/os-release + # associative array with directories and their assigned mode, user and group + # all paths are relative to the root directory / + directories=( + ["boot"]="755:0:0" + ["dev"]="755:0:0" + ["etc"]="755:0:0" + ["etc/ld.so.conf.d"]="755:0:0" + ["etc/profile.d"]="755:0:0" + ["etc/skel"]="755:0:0" + ["home"]="755:0:0" + ["mnt"]="755:0:0" + ["opt"]="755:0:0" + ["proc"]="555:0:0" + ["root"]="0750:0:0" + ["run"]="755:0:0" + ["srv/http"]="755:0:0" + ["srv/ftp"]="555:0:11" # vsftpd won't run with write perms on /srv/ftp + ["sys"]="555:0:0" + ["tmp"]="1777:0:0" + ["usr"]="755:0:0" + ["usr/bin"]="755:0:0" + ["usr/include"]="755:0:0" + ["usr/lib"]="755:0:0" + ["usr/lib/ld.so.conf.d"]="755:0:0" + ["usr/local/bin"]="755:0:0" + ["usr/local/etc"]="755:0:0" + ["usr/local/games"]="755:0:0" + ["usr/local/include"]="755:0:0" + ["usr/local/lib"]="755:0:0" + ["usr/local/man"]="755:0:0" + ["usr/local/sbin"]="755:0:0" + ["usr/local/share"]="755:0:0" + ["usr/local/src"]="755:0:0" + ["usr/share/factory/etc"]="755:0:0" + ["usr/share/man/man1"]="755:0:0" + ["usr/share/man/man2"]="755:0:0" + ["usr/share/man/man3"]="755:0:0" + ["usr/share/man/man4"]="755:0:0" + ["usr/share/man/man5"]="755:0:0" + ["usr/share/man/man6"]="755:0:0" + ["usr/share/man/man7"]="755:0:0" + ["usr/share/man/man8"]="755:0:0" + ["usr/share/misc"]="755:0:0" + ["usr/share/pixmaps"]="755:0:0" + ["usr/src"]="755:0:0" + ["var"]="755:0:0" + ["var/cache"]="755:0:0" + ["var/empty"]="755:0:0" + ["var/games"]="775:0:50" # allow setgid games (gid 50) to write scores + ["var/lib/misc"]="755:0:0" + ["var/local"]="755:0:0" + ["var/log/old"]="755:0:0" + ["var/opt"]="755:0:0" + ["var/spool/mail"]="1777:0:0" + ["var/tmp"]="1777:0:0" + ) - # stop-gap fix for https://labs.parabola.nu/issues/2894 - install -m644 "$srcdir"/disable-dotnet-telemetry.sh etc/profile.d/disable-dotnet-telemetry.sh + # associative array with symlink names and their respective targets + # all paths are relative to the root directory / + symlinks=( + ["bin"]="usr/bin" + ["etc/mtab"]="../proc/self/mounts" + ["lib"]="usr/lib" + ["sbin"]="usr/bin" + ["usr/local/share/man"]="../man" + ["usr/sbin"]="bin" + ["var/lock"]="../run/lock" + ["var/mail"]="spool/mail" + ["var/run"]="../run" + ) + [[ $CARCH = 'x86_64' ]] || \ + [[ $CARCH = 'ppc64le' ]] && { # 'ppc64le' is Parabola specific + symlinks["lib64"]="usr/lib" + symlinks["usr/lib64"]="lib" + } - # setup /var - for d in cache local opt log/old lib/misc empty; do - install -d -m755 var/$d - done - install -d -m1777 var/{tmp,spool/mail} + # associative array of target files, their source file, file mode, user and group ownership + files=( + ["etc/arch-release"]="arch-release:644:0:0" + ["etc/crypttab"]="crypttab:600:0:0" + ["etc/fstab"]="fstab:644:0:0" + ["etc/group"]="group:644:0:0" + ["etc/gshadow"]="gshadow:600:0:0" + ["etc/host.conf"]="host.conf:644:0:0" + ["etc/hosts"]="hosts:644:0:0" + ["etc/issue"]="issue:644:0:0" + ["etc/ld.so.conf"]="ld.so.conf:644:0:0" + ["etc/nsswitch.conf"]="nsswitch.conf:644:0:0" + ["etc/passwd"]="passwd:644:0:0" + ["etc/profile"]="profile:644:0:0" + ["etc/profile.d/locale.sh"]="locale.sh:644:0:0" + ["etc/resolv.conf"]="resolv.conf:644:0:0" + ["etc/securetty"]="securetty:644:0:0" + ["etc/shells"]="shells:644:0:0" + ["etc/shadow"]="shadow:600:0:0" + ["etc/subgid"]="subgid:644:0:0" + ["etc/subuid"]="subuid:644:0:0" + ["usr/lib/os-release"]="os-release:644:0:0" + ["usr/lib/sysctl.d/10-arch.conf"]="sysctl:644:0:0" + ["usr/lib/sysusers.d/arch.conf"]="sysusers:644:0:0" + ["usr/lib/tmpfiles.d/arch.conf"]="tmpfiles:644:0:0" + ["usr/lib/systemd/system-environment-generators/10-arch"]="env-generator:755:0:0" + ["usr/share/factory/etc/arch-release"]="arch-release:644:0:0" + ["usr/share/factory/etc/crypttab"]="crypttab:600:0:0" + ["usr/share/factory/etc/fstab"]="fstab:644:0:0" + ["usr/share/factory/etc/group"]="group:644:0:0" + ["usr/share/factory/etc/gshadow"]="gshadow:600:0:0" + ["usr/share/factory/etc/host.conf"]="host.conf:644:0:0" + ["usr/share/factory/etc/hosts"]="hosts:644:0:0" + ["usr/share/factory/etc/issue"]="issue:644:0:0" + ["usr/share/factory/etc/ld.so.conf"]="ld.so.conf:644:0:0" + ["usr/share/factory/etc/nsswitch.conf"]="nsswitch.conf:644:0:0" + ["usr/share/factory/etc/passwd"]="passwd:644:0:0" + ["usr/share/factory/etc/profile"]="profile:644:0:0" + ["usr/share/factory/etc/profile.d/locale.sh"]="locale.sh:644:0:0" + ["usr/share/factory/etc/resolv.conf"]="resolv.conf:644:0:0" + ["usr/share/factory/etc/securetty"]="securetty:644:0:0" + ["usr/share/factory/etc/shadow"]="shadow:600:0:0" + ["usr/share/factory/etc/shells"]="shells:644:0:0" + ["usr/share/factory/etc/subgid"]="subgid:644:0:0" + ["usr/share/factory/etc/subuid"]="subuid:644:0:0" + ["usr/share/pixmaps/parabola-logo.png"]="parabola-logo.png:644:0:0" + ["usr/share/pixmaps/parabola-logo.svg"]="parabola-logo.svg:644:0:0" + ["usr/share/pixmaps/parabola-logo-text.svg"]="parabola-logo-text.svg:644:0:0" + ["usr/share/pixmaps/parabola-logo-text-dark.svg"]="parabola-logo-text-dark.svg:644:0:0" + ) + + # Add Parabola specifics + files+=( + ["etc/motd"]="motd:644:0:0" + ["etc/profile.d/disable-dotnet-telemetry.sh"]="disable-dotnet-telemetry.sh:644:0:0" + ) + cd "$pkgdir" - # allow setgid games (gid 50) to write scores - install -d -m775 -g 50 var/games - ln -s spool/mail var/mail - ln -s ../run var/run - ln -s ../run/lock var/lock + for dir in "${!directories[@]}"; do + mode="$(cut -f 1 -d ':' <<< "${directories[$dir]}")" + user="$(cut -f 2 -d ':' <<< "${directories[$dir]}")" + group="$(cut -f 3 -d ':' <<< "${directories[$dir]}")" - # setup /usr hierarchy - for d in bin include lib share/{misc,pixmaps} src; do - install -d -m755 usr/$d - done - for d in {1..8}; do - install -d -m755 usr/share/man/man$d + install -vdm "$mode" -o "$user" -g "$group" "$dir" done - # add lib symlinks - ln -s usr/lib lib - [[ $CARCH = 'ppc64le' ]] || \ - [[ $CARCH = 'x86_64' ]] && { - ln -s usr/lib lib64 - ln -s lib usr/lib64 - } - - # add bin symlinks - ln -s usr/bin bin - ln -s usr/bin sbin - ln -s bin usr/sbin - - # setup /usr/local hierarchy - for d in bin etc games include lib man sbin share src; do - install -d -m755 usr/local/$d + for link in "${!symlinks[@]}"; do + ln -sv "${symlinks[$link]}" "$link" done - ln -s ../man usr/local/share/man - - # setup systemd-sysctl - install -D -m644 "$srcdir"/sysctl usr/lib/sysctl.d/10-arch.conf - # setup systemd-sysusers - install -D -m644 "$srcdir"/sysusers usr/lib/sysusers.d/arch.conf + for target_file in "${!files[@]}"; do + source_file="$(cut -f 1 -d ':' <<< "${files[$target_file]}")" + mode="$(cut -f 2 -d ':' <<< "${files[$target_file]}")" + user="$(cut -f 3 -d ':' <<< "${files[$target_file]}")" + group="$(cut -f 4 -d ':' <<< "${files[$target_file]}")" - # setup systemd-tmpfiles - install -D -m644 "$srcdir"/tmpfiles usr/lib/tmpfiles.d/arch.conf + install -vDm "$mode" -o "$user" -g "$group" "$srcdir/$source_file" "$target_file" + done - # setup systemd.environment-generator - install -D -m755 "$srcdir"/env-generator usr/lib/systemd/system-environment-generators/10-arch + touch etc/parabola-release - # add logo - install -D -m644 "$srcdir"/parabola-logo{.png,.svg,-text.svg,-text-dark.svg} usr/share/pixmaps } diff --git a/libre/filesystem/arch-release b/libre/filesystem/arch-release new file mode 100644 index 0000000..8b13789 --- /dev/null +++ b/libre/filesystem/arch-release @@ -0,0 +1 @@ + diff --git a/libre/filesystem/ld.so.conf b/libre/filesystem/ld.so.conf index 1f620fa..a1c0559 100644 --- a/libre/filesystem/ld.so.conf +++ b/libre/filesystem/ld.so.conf @@ -2,3 +2,4 @@ # See ld.so(8) and ldconfig(8) for details. include /etc/ld.so.conf.d/*.conf +include /usr/lib/ld.so.conf.d/*.conf diff --git a/libre/filesystem/locale.sh b/libre/filesystem/locale.sh index 48dd748..bb5fcbb 100644 --- a/libre/filesystem/locale.sh +++ b/libre/filesystem/locale.sh @@ -13,8 +13,8 @@ if [ -z "$LANG" ]; then fi fi -# define default LANG to C if not already defined -LANG=${LANG:-C} +# define default LANG to C.UTF-8 if not already defined +LANG=${LANG:-C.UTF-8} # export all locale (7) variables when they exist export LANG LANGUAGE LC_CTYPE LC_NUMERIC LC_TIME LC_COLLATE LC_MONETARY \ diff --git a/libre/filesystem/passwd b/libre/filesystem/passwd index 909d89b..a929ad4 100644 --- a/libre/filesystem/passwd +++ b/libre/filesystem/passwd @@ -1 +1 @@ -root:x:0:0::/root:/bin/bash +root:x:0:0::/root:/usr/bin/bash diff --git a/libre/filesystem/profile b/libre/filesystem/profile index 78ed69f..5eb2764 100644 --- a/libre/filesystem/profile +++ b/libre/filesystem/profile @@ -27,6 +27,12 @@ if test -d /etc/profile.d/; then unset profile fi +# unset GLOBSORT, before anything else is sourced +# This variable will be part of bash => 5.3 +# The rationale is that the user should always be able +# to expect that the snippets be processed in a deterministic order. +unset -v GLOBSORT + # Unload our profile API functions unset -f append_path diff --git a/libre/filesystem/sysctl b/libre/filesystem/sysctl index b585ea2..c79094d 100644 --- a/libre/filesystem/sysctl +++ b/libre/filesystem/sysctl @@ -1,3 +1,8 @@ # Raise inotify resource limits +# https://bugs.archlinux.org/task/47830 fs.inotify.max_user_instances = 1024 fs.inotify.max_user_watches = 524288 + +# Increase the default vm.max_map_count value +# https://archlinux.org/news/increasing-the-default-vmmax_map_count-value/ +vm.max_map_count = 1048576 diff --git a/libre/filesystem/tmpfiles b/libre/filesystem/tmpfiles index 04f8d12..1ce557e 100644 --- a/libre/filesystem/tmpfiles +++ b/libre/filesystem/tmpfiles @@ -1,5 +1,6 @@ # copy from factory when missing +C /etc/arch-release C /etc/crypttab C /etc/fstab C /etc/group @@ -11,8 +12,13 @@ C /etc/ld.so.conf C /etc/nsswitch.conf C /etc/passwd C /etc/profile +C /etc/profile.d/locale.sh C /etc/securetty C /etc/shadow C /etc/shells C /etc/subuid C /etc/subgid + +# The package ships `/var/lock`, which is a symlink to `../run/lock`. +# As the latter resides on a tmpfs it needs to be created after boot. +d /run/lock 0755 root root -