From 2bc4ebc458f7b4ec8138d2ec97a2511e6be3c2a9 Mon Sep 17 00:00:00 2001 From: jc_gargma Date: Wed, 27 Jun 2018 16:08:45 -0700 Subject: Initial commit --- PKGBUILD | 303 +++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 303 insertions(+) create mode 100644 PKGBUILD (limited to 'PKGBUILD') diff --git a/PKGBUILD b/PKGBUILD new file mode 100644 index 0000000..32e88af --- /dev/null +++ b/PKGBUILD @@ -0,0 +1,303 @@ +# Maintainer: Levente Polyak +# Contributor: Daniel Micay +# Contributor: Tobias Powalowski +# Contributor: Thomas Baechler + +pkgbase=linux-hardened-ck +_majver=4.17 +_minver=3 +_fullver=${_majver}.${_minver} +_basever=${_majver} +_pkgver=${_fullver} +_hardver=a +_NUMAdisable=y +_ckpatchversion=1 +_ckpatchname="patch-${_majver}-ck${_ckpatchversion}" +_jcpatchversion="jcmod1" +_gcc_more_v='20180509' +_srcname=linux-${_majver} +pkgver=${_fullver}.${_hardver} +pkgrel=1 +conflicts=('linux-libre-hardened-ck') +url='https://github.com/anthraxx/linux-hardened' +#url='http://ck.kolivas.org/patches/' +arch=('x86_64') +license=('GPL2') +makedepends=('xmlto' 'kmod' 'inetutils' 'bc' 'libelf') +options=('!strip') +source=(https://www.kernel.org/pub/linux/kernel/v4.x/${_srcname}.tar.xz + https://www.kernel.org/pub/linux/kernel/v4.x/${_srcname}.tar.sign + https://www.kernel.org/pub/linux/kernel/v4.x/patch-${_pkgver}.xz + https://www.kernel.org/pub/linux/kernel/v4.x/patch-${_pkgver}.sign + https://github.com/anthraxx/linux-hardened/releases/download/${_fullver}.${_hardver}/linux-hardened-${_fullver}.${_hardver}.patch{,.sig} + patch-${_majver}-ck${_ckpatchversion}-${_jcpatchversion}.patch + #http://ck.kolivas.org/patches/4.0/${_majver}/${_majver}-ck${_ckpatchversion}/${_ckpatchname}.xz + enable_additional_cpu_optimizations-$_gcc_more_v.tar.gz::https://github.com/graysky2/kernel_gcc_patch/archive/$_gcc_more_v.tar.gz + ath9k-regdom-hack.patch + config.x86_64 # the main kernel config files + 60-linux.hook # pacman hook for depmod + 90-linux.hook # pacman hook for initramfs regeneration + linux.preset # standard config files for mkinitcpio ramdisk + + # https://bugs.archlinux.org/task/56780 + ACPI-watchdog-Prefer-iTCO_wdt-always-when-WDAT-table.patch + # https://bugs.archlinux.org/task/56711 + Revert-drm-i915-edp-Allow-alternate-fixed-mode-for-e.patch +) +sha256sums=('63f6dc8e3c9f3a0273d5d6f4dca38a2413ca3a5f689329d05b750e4c87bb21b9' + 'SKIP' + 'fd8a68ffcc729e69f0c0a3d202d08d7c5fa612d1ac65dfff3c5ef2f64d183a2e' + 'SKIP' + 'daf408ea562fbf27daefd2b2759790ba000b8a077fa319a57e678dbde3ad327e' + 'SKIP' + 'be8b6d11af7f0c99f2f601b179eaab4409184fcc3db22f8616e28f5a443f5323' + '226e30068ea0fecdb22f337391385701996bfbdba37cdcf0f1dbf55f1080542d' + 'e7ebf050c22bcec0028c0b3c79fd6d3913b0370ecc6a23dfe78ce475630cf503' + '263391ed43ef1cc5d3381b87647688e070e27460bb2dec41f8b240379c0e7017' + 'ae2e95db94ef7176207c690224169594d49445e04249d2499e9d2fbc117a0b21' + '75f99f5239e03238f88d1a834c50043ec32b1dc568f2cc291b07d04718483919' + 'ad6344badc91ad0630caacde83f7f9b97276f80d26a20619a87952be65492c65' + '655534c9dda90ff8cea6f48f114bf3cd9118826bd6cb7bd24734dabde9997221' + '8114295b8c07795a15b9f8eafb0f515c34661a1e05512da818a34581dd30f87e') +validpgpkeys=( + 'ABAF11C65A2970B130ABE3C479BE3E4300411886' # Linus Torvalds + '647F28654894E3BD457199BE38DBBDC86092693E' # Greg Kroah-Hartman + '65EEFE022108E2B708CBFCF7F9E712E59AF5F22A' # Daniel Micay + 'E240B57E2C4630BA768E2F26FC1B547C8D8172C8' # Levente Polyak + ) +_kernelname=${pkgbase#linux} +: ${_kernelname:=-ARCH} + +prepare() { + cd ${_srcname} + + # add upstream patch + msg2 "Applying upstream patch" + patch -p1 -i "${srcdir}/patch-${_fullver}" + + # Hotfixes + msg2 "Applying hotfixes" + patch -p1 -i "${srcdir}/ACPI-watchdog-Prefer-iTCO_wdt-always-when-WDAT-table.patch" + patch -p1 -i "${srcdir}/Revert-drm-i915-edp-Allow-alternate-fixed-mode-for-e.patch" + + # fix naming schema in EXTRAVERSION of ck patch set + #sed -i -re "s/^(.EXTRAVERSION).*$/\1 = /" "../${_ckpatchname}" + + # linux hardened patch + msg2 "Applying hardened patch" + patch -p1 -i "${srcdir}/linux-hardened-${pkgver}.patch" + + # Patch source with ck patchset + msg2 "Applying ck patch" + #patch -p1 -i "${srcdir}/${_ckpatchname}" + patch -p1 -i "${srcdir}/${_ckpatchname}-${_jcpatchversion}.patch" + + # Patch source to unlock additional gcc CPU optimizatons + # https://github.com/graysky2/kernel_gcc_patch + msg2 "Applying graysky2 patch" + patch -p1 -i "${srcdir}/kernel_gcc_patch-$_gcc_more_v/enable_additional_cpu_optimizations_for_gcc_v8.1+_kernel_v4.13+.patch" + + # Ignore ath9k eeprom patch + patch -p1 -i "${srcdir}/ath9k-regdom-hack.patch" + + + # add latest fixes from stable queue, if needed + # http://git.kernel.org/?p=linux/kernel/git/stable/stable-queue.git + + cat ../config.x86_64 - >.config </dev/null +} + +build() { + cd ${_srcname} + + make bzImage modules +} + +_package() { + pkgdesc="The ${pkgbase/linux/Linux} kernel and modules" + [ "${pkgbase}" = "linux-hardened" ] && groups=('base') + depends=('coreutils' 'linux-firmware' 'kmod' 'mkinitcpio>=0.7') + optdepends=('crda: to set the correct wireless channels of your country') + backup=("etc/mkinitcpio.d/${pkgbase}.preset") + install=linux.install + + cd ${_srcname} + + # get kernel version + _kernver="$(make kernelrelease)" + _basekernel=${_kernver%%-*} + _basekernel=${_basekernel%.*} + + mkdir -p "${pkgdir}"/{boot,usr/lib/modules} + make INSTALL_MOD_PATH="${pkgdir}/usr" modules_install + cp arch/x86/boot/bzImage "${pkgdir}/boot/vmlinuz-${pkgbase}" + + # make room for external modules + local _extramodules="extramodules-${_basekernel}${_kernelname}" + ln -s "../${_extramodules}" "${pkgdir}/usr/lib/modules/${_kernver}/extramodules" + + # add real version for building modules and running depmod from hook + echo "${_kernver}" | + install -Dm644 /dev/stdin "${pkgdir}/usr/lib/modules/${_extramodules}/version" + + # remove build and source links + rm "${pkgdir}"/usr/lib/modules/${_kernver}/{source,build} + + # now we call depmod... + depmod -b "${pkgdir}/usr" -F System.map "${_kernver}" + + # add vmlinux + install -Dt "${pkgdir}/usr/lib/modules/${_kernver}/build" -m644 vmlinux + + # sed expression for following substitutions + local _subst=" + s|%PKGBASE%|${pkgbase}|g + s|%KERNVER%|${_kernver}|g + s|%EXTRAMODULES%|${_extramodules}|g + " + + # hack to allow specifying an initially nonexisting install file + sed "${_subst}" "${startdir}/${install}" > "${startdir}/${install}.pkg" + true && install=${install}.pkg + + # install mkinitcpio preset file + sed "${_subst}" ../linux.preset | + install -Dm644 /dev/stdin "${pkgdir}/etc/mkinitcpio.d/${pkgbase}.preset" + + # install pacman hooks + sed "${_subst}" ../60-linux.hook | + install -Dm644 /dev/stdin "${pkgdir}/usr/share/libalpm/hooks/60-${pkgbase}.hook" + sed "${_subst}" ../90-linux.hook | + install -Dm644 /dev/stdin "${pkgdir}/usr/share/libalpm/hooks/90-${pkgbase}.hook" +} + +_package-headers() { + pkgdesc="Header files and scripts for building modules for ${pkgbase/linux/Linux} kernel" + + cd ${_srcname} + local _builddir="${pkgdir}/usr/lib/modules/${_kernver}/build" + + install -Dt "${_builddir}" -m644 Makefile .config Module.symvers + install -Dt "${_builddir}/kernel" -m644 kernel/Makefile + + mkdir "${_builddir}/.tmp_versions" + + cp -t "${_builddir}" -a include scripts + + install -Dt "${_builddir}/arch/x86" -m644 arch/x86/Makefile + install -Dt "${_builddir}/arch/x86/kernel" -m644 arch/x86/kernel/asm-offsets.s + + cp -t "${_builddir}/arch/x86" -a arch/x86/include + + install -Dt "${_builddir}/drivers/md" -m644 drivers/md/*.h + install -Dt "${_builddir}/net/mac80211" -m644 net/mac80211/*.h + + # http://bugs.archlinux.org/task/13146 + install -Dt "${_builddir}/drivers/media/i2c" -m644 drivers/media/i2c/msp3400-driver.h + + # http://bugs.archlinux.org/task/20402 + install -Dt "${_builddir}/drivers/media/usb/dvb-usb" -m644 drivers/media/usb/dvb-usb/*.h + install -Dt "${_builddir}/drivers/media/dvb-frontends" -m644 drivers/media/dvb-frontends/*.h + install -Dt "${_builddir}/drivers/media/tuners" -m644 drivers/media/tuners/*.h + + # add xfs and shmem for aufs building + mkdir -p "${_builddir}"/{fs/xfs,mm} + + # copy in Kconfig files + find . -name Kconfig\* -exec install -Dm644 {} "${_builddir}/{}" \; + + # add objtool for external module building and enabled VALIDATION_STACK option + install -Dt "${_builddir}/tools/objtool" tools/objtool/objtool + + # remove unneeded architectures + local _arch + for _arch in "${_builddir}"/arch/*/; do + [[ ${_arch} == */x86/ ]] && continue + rm -r "${_arch}" + done + + # remove files already in linux-docs package + rm -r "${_builddir}/Documentation" + + # remove now broken symlinks + find -L "${_builddir}" -type l -printf 'Removing %P\n' -delete + + # Fix permissions + chmod -R u=rwX,go=rX "${_builddir}" + + # strip scripts directory + local _binary _strip + while read -rd '' _binary; do + case "$(file -bi "${_binary}")" in + *application/x-sharedlib*) _strip="${STRIP_SHARED}" ;; # Libraries (.so) + *application/x-archive*) _strip="${STRIP_STATIC}" ;; # Libraries (.a) + *application/x-executable*) _strip="${STRIP_BINARIES}" ;; # Binaries + *) continue ;; + esac + /usr/bin/strip ${_strip} "${_binary}" + done < <(find "${_builddir}/scripts" -type f -perm -u+w -print0 2>/dev/null) +} + +_package-docs() { + pkgdesc="Kernel hackers manual - HTML documentation that comes with the ${pkgbase/linux/Linux} kernel" + + cd ${_srcname} + local _builddir="${pkgdir}/usr/lib/modules/${_kernver}/build" + + mkdir -p "${_builddir}" + cp -t "${_builddir}" -a Documentation + + # Fix permissions + chmod -R u=rwX,go=rX "${_builddir}" +} + +pkgname=("${pkgbase}" "${pkgbase}-headers" "${pkgbase}-docs") +for _p in ${pkgname[@]}; do + eval "package_${_p}() { + $(declare -f "_package${_p#${pkgbase}}") + _package${_p#${pkgbase}} + }" +done + +# vim:set ts=8 sts=2 sw=2 et: -- cgit v1.2.1