linux-hwg/PKGBUILD

265 lines
9.6 KiB
Bash
Raw Normal View History

# Maintainer: Tobias Powalowski <tpowa@archlinux.org>
# Maintainer: Thomas Baechler <thomas@archlinux.org>
2011-07-24 16:48:57 +02:00
2012-08-08 10:13:48 +02:00
pkgbase=linux # Build stock -ARCH kernel
#pkgbase=linux-custom # Build kernel with a different name
2017-11-18 16:57:38 +01:00
_srcname=linux-4.14
2018-01-03 08:21:25 +01:00
pkgver=4.14.11
2017-12-10 16:39:51 +01:00
pkgrel=1
2017-11-15 15:11:34 +01:00
arch=('x86_64')
2016-12-06 13:09:59 +01:00
url="https://www.kernel.org/"
license=('GPL2')
2017-09-10 13:06:37 +02:00
makedepends=('xmlto' 'kmod' 'inetutils' 'bc' 'libelf')
2011-07-24 16:48:57 +02:00
options=('!strip')
2017-11-18 16:57:38 +01:00
source=(
"https://www.kernel.org/pub/linux/kernel/v4.x/${_srcname}.tar.xz"
"https://www.kernel.org/pub/linux/kernel/v4.x/${_srcname}.tar.sign"
2017-11-21 12:52:54 +01:00
"https://www.kernel.org/pub/linux/kernel/v4.x/patch-${pkgver}.xz"
"https://www.kernel.org/pub/linux/kernel/v4.x/patch-${pkgver}.sign"
2017-11-18 16:57:38 +01:00
'config' # the main kernel config file
2017-11-18 23:46:07 +01:00
'60-linux.hook' # pacman hook for depmod
2017-11-18 16:57:38 +01:00
'90-linux.hook' # pacman hook for initramfs regeneration
'linux.preset' # standard config files for mkinitcpio ramdisk
2017-12-07 22:38:43 +01:00
0001-add-sysctl-to-disallow-unprivileged-CLONE_NEWUSER-by.patch
2018-01-03 08:21:25 +01:00
0002-e1000e-Fix-e1000_check_for_copper_link_ich8lan-retur.patch
0003-dccp-CVE-2017-8824-use-after-free-in-DCCP-code.patch
0004-Revert-xfrm-Fix-stack-out-of-bounds-read-in-xfrm_sta.patch
0005-xfrm-Fix-stack-out-of-bounds-read-on-socket-policy-l.patch
0006-cgroup-fix-css_task_iter-crash-on-CSS_TASK_ITER_PROC.patch
0007-x86-cpu-x86-pti-Do-not-enable-PTI-on-AMD-processors.patch
2017-11-18 16:57:38 +01:00
)
validpgpkeys=(
'ABAF11C65A2970B130ABE3C479BE3E4300411886' # Linus Torvalds
'647F28654894E3BD457199BE38DBBDC86092693E' # Greg Kroah-Hartman
)
sha256sums=('f81d59477e90a130857ce18dc02f4fbe5725854911db1e7ba770c7cd350f96a7'
2017-11-21 12:52:54 +01:00
'SKIP'
2018-01-03 08:21:25 +01:00
'f588b62d7ee1d2ebdc24afa0e256ff2f8812d5cab3bf572bf02e7c4525922bf9'
2017-07-13 12:44:39 +02:00
'SKIP'
2018-01-03 08:21:25 +01:00
'24b8cf6829dafcb2b5c76cffaae6438ad2d432f13d6551fa1c8f25e66b751ed4'
2017-11-18 23:46:07 +01:00
'ae2e95db94ef7176207c690224169594d49445e04249d2499e9d2fbc117a0b21'
'75f99f5239e03238f88d1a834c50043ec32b1dc568f2cc291b07d04718483919'
2017-12-07 22:38:43 +01:00
'ad6344badc91ad0630caacde83f7f9b97276f80d26a20619a87952be65492c65'
2018-01-03 08:21:25 +01:00
'06bc1d8b1cd153c3146a4376d833f5769b980e5ef5eae99ddaaeb48bf514dae2'
'b90bef87574f30ec66c0f10d089bea56a9e974b6d052fee3071b1ff21360724b'
'f38531dee9fd8a59202ce96ac5b40446f1f035b89788ea9ecb2fb3909f703a25'
'705d5fbfce00ccc20490bdfb5853d67d86ac00c845de6ecb13e414214b48daeb'
'0a249248534a17f14fab7e14994811ae81fe324668a82ff41f3bcabeeae1460f'
'8e1b303957ddd829c0c9ad7c012cd32f2354ff3c8c1b85da3d7f8a54524f3711'
'914a0a019545ad7d14ed8d5c58d417eb0a8ec12a756beec79a545aabda343b31')
2013-11-21 09:49:51 +01:00
_kernelname=${pkgbase#linux}
prepare() {
2017-09-10 13:06:37 +02:00
cd ${_srcname}
2011-07-24 16:48:57 +02:00
# add upstream patch
2017-11-21 12:52:54 +01:00
patch -p1 -i ../patch-${pkgver}
2017-12-29 21:26:04 +01:00
chmod +x tools/objtool/sync-check.sh # GNU patch doesn't support git-style file mode
2017-06-22 15:18:15 +02:00
# security patches
2016-12-11 03:34:09 +01:00
# add latest fixes from stable queue, if needed
# http://git.kernel.org/?p=linux/kernel/git/stable/stable-queue.git
2017-09-10 13:06:37 +02:00
2017-12-07 22:38:43 +01:00
# disable USER_NS for non-root users by default
patch -Np1 -i ../0001-add-sysctl-to-disallow-unprivileged-CLONE_NEWUSER-by.patch
2017-12-14 22:53:24 +01:00
# https://bugs.archlinux.org/task/56575
2018-01-03 08:21:25 +01:00
patch -Np1 -i ../0002-e1000e-Fix-e1000_check_for_copper_link_ich8lan-retur.patch
2017-12-14 22:53:24 +01:00
# https://nvd.nist.gov/vuln/detail/CVE-2017-8824
2018-01-03 08:21:25 +01:00
patch -Np1 -i ../0003-dccp-CVE-2017-8824-use-after-free-in-DCCP-code.patch
2017-12-14 22:53:24 +01:00
2017-12-26 01:24:55 +01:00
# https://bugs.archlinux.org/task/56605
2018-01-03 08:21:25 +01:00
patch -Np1 -i ../0004-Revert-xfrm-Fix-stack-out-of-bounds-read-in-xfrm_sta.patch
patch -Np1 -i ../0005-xfrm-Fix-stack-out-of-bounds-read-on-socket-policy-l.patch
2017-12-26 01:24:55 +01:00
# https://bugs.archlinux.org/task/56846
2018-01-03 08:21:25 +01:00
patch -Np1 -i ../0006-cgroup-fix-css_task_iter-crash-on-CSS_TASK_ITER_PROC.patch
# For AMD processors, keep PTI off by default
patch -Np1 -i ../0007-x86-cpu-x86-pti-Do-not-enable-PTI-on-AMD-processors.patch
2017-12-26 01:24:55 +01:00
2017-11-18 16:57:38 +01:00
cp -Tf ../config .config
2011-07-24 16:48:57 +02:00
if [ "${_kernelname}" != "" ]; then
sed -i "s|CONFIG_LOCALVERSION=.*|CONFIG_LOCALVERSION=\"${_kernelname}\"|g" ./.config
2012-08-08 10:13:48 +02:00
sed -i "s|CONFIG_LOCALVERSION_AUTO=.*|CONFIG_LOCALVERSION_AUTO=n|" ./.config
fi
2011-07-24 16:48:57 +02:00
# set extraversion to pkgrel
sed -ri "s|^(EXTRAVERSION =).*|\1 -${pkgrel}|" Makefile
2011-07-24 16:48:57 +02:00
# don't run depmod on 'make install'. We'll do this ourselves in packaging
sed -i '2iexit 0' scripts/depmod.sh
# get kernel version
make prepare
2011-07-24 16:48:57 +02:00
# load configuration
# Configure the kernel. Replace the line below with one of your choice.
#make menuconfig # CLI menu for configuration
#make nconfig # new CLI menu for configuration
#make xconfig # X-based configuration
#make oldconfig # using old config from previous kernel version
# ... or manually edit .config
2012-08-08 18:01:32 +02:00
2012-08-08 10:13:48 +02:00
# rewrite configuration
yes "" | make config >/dev/null
2014-01-25 13:22:29 +01:00
}
2011-07-24 16:48:57 +02:00
2014-01-25 13:22:29 +01:00
build() {
2017-09-10 13:06:37 +02:00
cd ${_srcname}
2011-07-24 16:48:57 +02:00
2012-08-08 10:13:48 +02:00
make ${MAKEFLAGS} LOCALVERSION= bzImage modules
}
2012-08-08 10:13:48 +02:00
_package() {
pkgdesc="The ${pkgbase/linux/Linux} kernel and modules"
2012-08-08 10:13:48 +02:00
[ "${pkgbase}" = "linux" ] && groups=('base')
depends=('coreutils' 'linux-firmware' 'kmod' 'mkinitcpio>=0.7')
2011-07-24 16:48:57 +02:00
optdepends=('crda: to set the correct wireless channels of your country')
2012-08-08 10:13:48 +02:00
backup=("etc/mkinitcpio.d/${pkgbase}.preset")
install=linux.install
2011-07-24 16:48:57 +02:00
2017-09-10 13:06:37 +02:00
cd ${_srcname}
# get kernel version
2012-08-08 10:13:48 +02:00
_kernver="$(make LOCALVERSION= kernelrelease)"
_basekernel=${_kernver%%-*}
_basekernel=${_basekernel%.*}
2011-07-24 16:48:57 +02:00
mkdir -p "${pkgdir}"/{boot,usr/lib/modules}
make LOCALVERSION= INSTALL_MOD_PATH="${pkgdir}/usr" modules_install
2017-11-18 16:57:38 +01:00
cp arch/x86/boot/bzImage "${pkgdir}/boot/vmlinuz-${pkgbase}"
2011-07-24 16:48:57 +02:00
2017-11-18 23:46:07 +01:00
# make room for external modules
local _extramodules="extramodules-${_basekernel}${_kernelname:--ARCH}"
ln -s "../${_extramodules}" "${pkgdir}/usr/lib/modules/${_kernver}/extramodules"
2017-11-18 23:46:07 +01:00
# add real version for building modules and running depmod from hook
echo "${_kernver}" |
install -Dm644 /dev/stdin "${pkgdir}/usr/lib/modules/${_extramodules}/version"
# remove build and source links
rm "${pkgdir}"/usr/lib/modules/${_kernver}/{source,build}
2017-09-10 13:06:37 +02:00
2017-11-18 23:46:07 +01:00
# now we call depmod...
depmod -b "${pkgdir}/usr" -F System.map "${_kernver}"
2012-09-07 16:56:07 +02:00
2017-11-18 23:46:07 +01:00
# add vmlinux
install -Dt "${pkgdir}/usr/lib/modules/${_kernver}/build" -m644 vmlinux
2014-01-25 19:21:46 +01:00
2017-11-18 23:46:07 +01:00
# sed expression for following substitutions
local _subst="
s|%PKGBASE%|${pkgbase}|g
s|%KERNVER%|${_kernver}|g
s|%EXTRAMODULES%|${_extramodules}|g
"
# hack to allow specifying an initially nonexisting install file
sed "${_subst}" "${startdir}/${install}" > "${startdir}/${install}.pkg"
true && install=${install}.pkg
# install mkinitcpio preset file
sed "${_subst}" ../linux.preset |
install -Dm644 /dev/stdin "${pkgdir}/etc/mkinitcpio.d/${pkgbase}.preset"
# install pacman hooks
sed "${_subst}" ../60-linux.hook |
install -Dm644 /dev/stdin "${pkgdir}/usr/share/libalpm/hooks/60-${pkgbase}.hook"
sed "${_subst}" ../90-linux.hook |
install -Dm644 /dev/stdin "${pkgdir}/usr/share/libalpm/hooks/90-${pkgbase}.hook"
}
2012-08-08 10:13:48 +02:00
_package-headers() {
pkgdesc="Header files and scripts for building modules for ${pkgbase/linux/Linux} kernel"
2011-07-24 16:48:57 +02:00
2017-09-10 13:06:37 +02:00
cd ${_srcname}
local _builddir="${pkgdir}/usr/lib/modules/${_kernver}/build"
2011-07-24 16:48:57 +02:00
2017-09-10 13:06:37 +02:00
install -Dt "${_builddir}" -m644 Makefile .config Module.symvers
install -Dt "${_builddir}/kernel" -m644 kernel/Makefile
2017-09-10 13:06:37 +02:00
mkdir "${_builddir}/.tmp_versions"
2017-09-10 13:06:37 +02:00
cp -t "${_builddir}" -a include scripts
2017-11-18 16:57:38 +01:00
install -Dt "${_builddir}/arch/x86" -m644 arch/x86/Makefile
install -Dt "${_builddir}/arch/x86/kernel" -m644 arch/x86/kernel/asm-offsets.s
2011-07-24 16:48:57 +02:00
2017-11-18 16:57:38 +01:00
cp -t "${_builddir}/arch/x86" -a arch/x86/include
2011-07-24 16:48:57 +02:00
2017-09-10 13:06:37 +02:00
install -Dt "${_builddir}/drivers/md" -m644 drivers/md/*.h
install -Dt "${_builddir}/net/mac80211" -m644 net/mac80211/*.h
2011-07-24 16:48:57 +02:00
# http://bugs.archlinux.org/task/9912
2017-09-10 13:06:37 +02:00
install -Dt "${_builddir}/drivers/media/dvb-core" -m644 drivers/media/dvb-core/*.h
# http://bugs.archlinux.org/task/13146
2017-09-10 13:06:37 +02:00
install -Dt "${_builddir}/drivers/media/i2c" -m644 drivers/media/i2c/msp3400-driver.h
2011-07-24 16:48:57 +02:00
# http://bugs.archlinux.org/task/20402
2017-09-10 13:06:37 +02:00
install -Dt "${_builddir}/drivers/media/usb/dvb-usb" -m644 drivers/media/usb/dvb-usb/*.h
install -Dt "${_builddir}/drivers/media/dvb-frontends" -m644 drivers/media/dvb-frontends/*.h
install -Dt "${_builddir}/drivers/media/tuners" -m644 drivers/media/tuners/*.h
2011-07-24 16:48:57 +02:00
# add xfs and shmem for aufs building
2017-09-10 13:06:37 +02:00
mkdir -p "${_builddir}"/{fs/xfs,mm}
2011-07-24 16:48:57 +02:00
# copy in Kconfig files
2017-09-10 13:06:37 +02:00
find . -name Kconfig\* -exec install -Dm644 {} "${_builddir}/{}" \;
2016-05-16 20:44:11 +02:00
# add objtool for external module building and enabled VALIDATION_STACK option
2017-11-18 16:57:38 +01:00
install -Dt "${_builddir}/tools/objtool" tools/objtool/objtool
2016-05-16 20:44:11 +02:00
2017-09-10 13:06:37 +02:00
# remove unneeded architectures
local _arch
for _arch in "${_builddir}"/arch/*/; do
2017-11-18 16:57:38 +01:00
[[ ${_arch} == */x86/ ]] && continue
rm -r "${_arch}"
2011-07-24 16:48:57 +02:00
done
2017-09-10 13:06:37 +02:00
# remove files already in linux-docs package
rm -r "${_builddir}/Documentation"
# Fix permissions
chmod -R u=rwX,go=rX "${_builddir}"
2016-12-26 01:22:07 +01:00
2017-09-10 13:06:37 +02:00
# strip scripts directory
local _binary _strip
while read -rd '' _binary; do
case "$(file -bi "${_binary}")" in
*application/x-sharedlib*) _strip="${STRIP_SHARED}" ;; # Libraries (.so)
*application/x-archive*) _strip="${STRIP_STATIC}" ;; # Libraries (.a)
*application/x-executable*) _strip="${STRIP_BINARIES}" ;; # Binaries
*) continue ;;
esac
/usr/bin/strip ${_strip} "${_binary}"
done < <(find "${_builddir}/scripts" -type f -perm -u+w -print0 2>/dev/null)
}
2012-08-08 10:13:48 +02:00
_package-docs() {
pkgdesc="Kernel hackers manual - HTML documentation that comes with the ${pkgbase/linux/Linux} kernel"
2011-07-24 16:48:57 +02:00
2017-09-10 13:06:37 +02:00
cd ${_srcname}
local _builddir="${pkgdir}/usr/lib/modules/${_kernver}/build"
2011-07-24 16:48:57 +02:00
2017-09-10 13:06:37 +02:00
mkdir -p "${_builddir}"
cp -t "${_builddir}" -a Documentation
2011-07-24 16:48:57 +02:00
2017-09-10 13:06:37 +02:00
# Fix permissions
chmod -R u=rwX,go=rX "${_builddir}"
}
2012-08-08 10:13:48 +02:00
pkgname=("${pkgbase}" "${pkgbase}-headers" "${pkgbase}-docs")
for _p in ${pkgname[@]}; do
eval "package_${_p}() {
$(declare -f "_package${_p#${pkgbase}}")
_package${_p#${pkgbase}}
2012-08-08 10:13:48 +02:00
}"
done
2013-08-15 14:00:06 +02:00
# vim:set ts=8 sts=2 sw=2 et: