makepad/tools/arch_usb/firstboot.sh
Admin 384d0e031c tools: the Builder replaces makepad_loader, the web server moves to makepad/webserver, fleet scripts, docs and the workspace members
tools/makepad_builder replaces tools/makepad_loader: one build target
shared across app builds, workspace package selection, checkout
progress on the public Git API, detached built apps with a completion
state, waits for Windows security scans, manual retry after compiler
locks, dedicated-folder installer checks, catalog and runtime fixes.
tools/web_server and its scripts leave for github.com/makepad/webserver.
Arch USB clone/restore scripts, the qwen38 box scripts and the G-belt
serial test join tools/. docs/agents records the agent workflow and the
remote-control handoff protocol; AGENTS.md forbids vendored sources and
bulk imports. Cargo.toml lists apps/wm-dyn, libs/code_language,
libs/search, libs/tar, libs/loader_bundle and tools/makepad_builder,
and drops the two removed crates.

Squashed from work:
- Share Builder target across Makepad app builds
- Fix Builder workspace package selection
- Align Builder checkout progress with public Git API
- Detach built apps and show completion state
- Wait for Windows security scans
- Offer manual retry after Windows compiler locks
- docs: the agent workflow of record and the remote-control handoff protocol
- builder: dedicated-folder installer checks, catalog and runtime fixes; Windows job objects hold c_void handles
- tools: Arch USB clone/restore scripts, the qwen38 box scripts, and the G-belt serial test
- tools: the web server moves to makepad/webserver
- AGENTS.md: no vendored sources or bulk imports in the tree

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-18 12:17:59 +02:00

84 lines
4.5 KiB
Bash

#!/usr/bin/bash
# Configure the fresh official Arch root. Run directly from the read-only seed.
set -Eeuo pipefail
export PATH=/usr/local/sbin:/usr/local/bin:/usr/bin
seed=/run/makepad-seed
state=/var/lib/makepad-firstboot
mkdir -p "$state" /var/log
exec > >(tee -a /var/log/makepad-firstboot.log) 2>&1
trap 'rc=$?; echo "First-boot setup failed at line $LINENO (exit $rc). See /var/log/makepad-firstboot.log"; exit "$rc"' ERR
test ! -f "$state/complete" || exit 0
echo 'Configuring console login, sudo, SSH and Ethernet.'
(cd "$seed" && sha256sum --quiet -c config.sha256)
test -x /usr/bin/pacman
for group in wheel audio video input render storage uucp games; do
getent group "$group" >/dev/null || groupadd -r "$group"
done
getent group arch >/dev/null || groupadd arch
id arch >/dev/null 2>&1 || useradd -m -u 1000 -g arch -s /bin/bash arch
usermod -aG wheel,audio,video,input,render,storage,uucp,games -s /bin/bash arch
chmod go-w /home/arch
install -d -m 0750 /etc/sudoers.d
printf 'arch ALL=(ALL:ALL) ALL\n' > /etc/sudoers.d/10-arch
chmod 0440 /etc/sudoers.d/10-arch
grep -Eq '^([@#]includedir)[[:space:]]+/etc/sudoers.d([[:space:]]|$)' /etc/sudoers || printf '\n@includedir /etc/sudoers.d\n' >> /etc/sudoers
visudo -c
sudo -l -U arch /usr/bin/id
# Install without starting SSH yet: cloud-init orders it after this stage.
# The helper writes the password only to root-readable local console files.
bash "$seed/ssh.sh" install
# Firmware is available before re-probing the Realtek Ethernet adapter.
mkdir -p /usr/lib/firmware /etc/systemd/network /etc/modprobe.d /etc/iwd
tar -xf "$seed/realtek-firmware.tar" -C /usr/lib/firmware
install -m 0644 "$seed/wired.network" /etc/systemd/network/05-makepad-wired.network
install -m 0644 "$seed/wifi.network" /etc/systemd/network/25-makepad-wireless.network
install -m 0644 "$seed/no-bluetooth.conf" /etc/modprobe.d/makepad-no-bluetooth.conf
install -m 0644 "$seed/iwd.conf" /etc/iwd/main.conf
ln -sfn /run/systemd/resolve/stub-resolv.conf /etc/resolv.conf
printf 'makepad-arch\n' > /etc/hostname
printf 'makepad-arch\n' > /proc/sys/kernel/hostname
printf '127.0.0.1 localhost\n::1 localhost\n127.0.1.1 makepad-arch\n' > /etc/hosts
printf 'LANG=C.UTF-8\n' > /etc/locale.conf
ln -sfn /usr/share/zoneinfo/Europe/Amsterdam /etc/localtime
mkdir -p /usr/local/sbin /usr/local/bin /etc/udev/rules.d
install -m 0755 "$seed/provision.sh" /usr/local/sbin/makepad-provision
install -m 0755 "$seed/mount-win.sh" /usr/local/sbin/makepad-mount-win
install -m 0755 "$seed/status.sh" /usr/local/bin/makepad-status
install -m 0644 "$seed/makepad-provision.service" /etc/systemd/system/makepad-provision.service
install -m 0644 "$seed/makepad-mount-win.service" /etc/systemd/system/makepad-mount-win.service
install -m 0644 "$seed/fanatec-access.rules" /etc/udev/rules.d/70-makepad-fanatec-access.rules
# Networkd is already enabled in the checked base. Enabling it again would
# also enable its wait-online service, which is deliberately masked at boot.
systemctl --root=/ unmask sshd.service systemd-resolved.service iwd.service
systemctl --root=/ is-enabled systemd-networkd.service
systemctl --root=/ enable sshd.service systemd-resolved.service systemd-timesyncd.service makepad-provision.service makepad-mount-win.service
for unit in pacman-init.service systemd-networkd-wait-online.service systemd-networkd-wait-online@.service systemd-time-wait-sync.service bluetooth.service wpa_supplicant.service; do
systemctl --root=/ disable "$unit" || true
if test -f "/etc/systemd/system/$unit" && ! test -L "/etc/systemd/system/$unit"; then
mv "/etc/systemd/system/$unit" "$state/$unit.original"
fi
systemctl --root=/ mask --force "$unit"
done
systemctl --root=/ set-default multi-user.target
systemctl --root=/ is-enabled sshd.service
systemctl daemon-reload
modprobe r8169 || echo 'Realtek module loading needs inspection; see this log.'
if test "${MAKEPAD_KEEP_NETWORK:-0}" != 1; then
networkctl reload || echo 'Networkd will load the Ethernet configuration when it starts.'
for path in /sys/class/net/eth* /sys/class/net/en*; do
test -e "$path" || continue
networkctl reconfigure "${path##*/}" || echo "Networkd will configure ${path##*/} when the interface appears."
done
fi
# SSH is ordered after this cloud-init stage. Queue it without waiting for
# that dependency; returning from this script lets it start normally.
systemctl start --no-block systemd-networkd.service systemd-resolved.service sshd.service makepad-provision.service
sync
touch "$state/complete"
sync
echo 'First-boot configuration validated. SSH is queued; package setup follows SSH startup.'