Parameterize the raw recovery beacon, add one-time JD resident preparation and return verification, and provide an external ICMP peer for HLDP login, code, branch, and recovery commands.
129 lines
4.9 KiB
Shell
Executable file
129 lines
4.9 KiB
Shell
Executable file
#!/usr/bin/env bash
|
|
set -euo pipefail
|
|
|
|
[[ $# -eq 5 ]] || {
|
|
echo "usage: prepare-jd-native-resident-once.sh <world-root> <resident-image> <recovery-root> <expected-image-sha256> <probe-recovery-root>" >&2
|
|
exit 64
|
|
}
|
|
[[ ${EUID} -eq 0 ]] || exit 77
|
|
|
|
world_root=$(readlink -f "$1")
|
|
candidate=$(readlink -f "$2")
|
|
recovery_root=$(readlink -m "$3")
|
|
expected_candidate_sha=$4
|
|
probe_recovery_root=$(readlink -f "$5")
|
|
source_root=$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)
|
|
render_root=$(mktemp -d)
|
|
trap 'rm -rf "${render_root}"' EXIT
|
|
|
|
grep -q '^node_id: JD-FD-PRIMARY$' "${world_root}/CURRENT.hldp"
|
|
grep -q '^status: PASS_100$' "${probe_recovery_root}/RETURN-RECEIPT.hldp"
|
|
/guanghu/bin/ghctl authorize "${world_root}" \
|
|
write_bootloader_and_system_partitions >/dev/null
|
|
[[ ${expected_candidate_sha} =~ ^[0-9a-f]{64}$ ]]
|
|
[[ $(stat -c %s "${candidate}") -eq 14848 ]]
|
|
[[ $(sha256sum "${candidate}" | awk '{print $1}') == \
|
|
"${expected_candidate_sha}" ]]
|
|
[[ ! -e ${recovery_root} ]]
|
|
|
|
partition_dump=$(sfdisk -d /dev/vda)
|
|
grep -q '^label: dos$' <<<"${partition_dump}"
|
|
grep -q '^label-id: 0xf4bb72a5$' <<<"${partition_dump}"
|
|
grep -Eq '^/dev/vda1 : start= *2048, size= *209713119, type=83$' \
|
|
<<<"${partition_dump}"
|
|
[[ $(dd if=/dev/vda bs=512 count=105 status=none | sha256sum |
|
|
awk '{print $1}') == \
|
|
32291877e37647ee5b778f968676cc69b59fb5b07604366a21cbfd8e4a4b87a8 ]]
|
|
[[ $(dd if=/dev/vda bs=512 skip=105 count=38 status=none | sha256sum |
|
|
awk '{print $1}') == \
|
|
c597b1b463b7cec49548fac00d7588c9652bb67cc2b1b0c88676bf8f1558571e ]]
|
|
|
|
mkdir -m 0700 "${recovery_root}"
|
|
printf '%s\n' "${partition_dump}" >"${recovery_root}/sfdisk-before.txt"
|
|
dd if=/dev/vda of="${recovery_root}/first-2MiB.before.bin" \
|
|
bs=1M count=2 status=none
|
|
disk_sectors=$(blockdev --getsz /dev/vda)
|
|
dd if=/dev/vda of="${recovery_root}/last-2MiB.before.bin" \
|
|
bs=512 skip=$((disk_sectors - 4096)) count=4096 status=none
|
|
cp /boot/grub/grub.cfg "${recovery_root}/grub.cfg.before"
|
|
cp /boot/grub/grubenv "${recovery_root}/grubenv.before"
|
|
cp /etc/default/grub "${recovery_root}/default-grub.before"
|
|
cp /etc/grub.d/40_custom "${recovery_root}/40_custom.before"
|
|
cp "${candidate}" "${recovery_root}/jd-native-resident.img"
|
|
cat /proc/sys/kernel/random/boot_id >"${recovery_root}/linux-boot-id.before"
|
|
|
|
"${source_root}/scripts/render-native-recovery-beacon.sh" "${render_root}" \
|
|
139 gnulinux-simple-9e4550a0-452b-4f28-b5a5-d5364aa450f6
|
|
install -m 0755 "${render_root}/08_guanghu_native_recovery" \
|
|
/etc/grub.d/08_guanghu_native_recovery
|
|
install -m 0755 /dev/stdin /etc/grub.d/41_guanghu_jd_native_once <<'EOF'
|
|
#!/bin/sh
|
|
exec tail -n +3 $0
|
|
menuentry 'Guanghu OS JD native one-time resident' --id 'guanghu-jd-native-once' {
|
|
insmod chain
|
|
chainloader (hd0)105+1
|
|
}
|
|
EOF
|
|
install -D -m 0644 "${render_root}/guanghu-recovery-clear.env" \
|
|
/usr/lib/guanghu-os/jd-recovery-clear.env
|
|
install -D -m 0755 "${source_root}/scripts/clear-native-recovery-beacon.sh" \
|
|
/usr/local/sbin/guanghu-clear-native-recovery-beacon
|
|
install -m 0644 /dev/stdin \
|
|
/etc/systemd/system/guanghu-jd-native-recovery-clear.service <<'EOF'
|
|
[Unit]
|
|
Description=Verify and clear the JD Guanghu native recovery beacon
|
|
After=local-fs.target
|
|
Before=multi-user.target
|
|
|
|
[Service]
|
|
Type=oneshot
|
|
ExecStart=/usr/local/sbin/guanghu-clear-native-recovery-beacon /dev/vda /usr/lib/guanghu-os/jd-recovery-clear.env 139
|
|
|
|
[Install]
|
|
WantedBy=multi-user.target
|
|
EOF
|
|
systemctl enable guanghu-jd-native-recovery-clear.service >/dev/null
|
|
dd if="${render_root}/guanghu-recovery-clear.env" of=/dev/vda \
|
|
bs=512 seek=139 count=2 conv=notrunc,fsync status=none
|
|
dd if="${candidate}" of=/dev/vda bs=512 seek=105 count=29 \
|
|
conv=notrunc,fsync status=none
|
|
update-grub >/dev/null
|
|
grub-script-check /boot/grub/grub.cfg
|
|
grep -q "load_env --file '(hd0)139+2' guanghu_recovery" \
|
|
/boot/grub/grub.cfg
|
|
grep -q "menuentry 'Guanghu OS JD native one-time resident'.*'guanghu-jd-native-once'" \
|
|
/boot/grub/grub.cfg
|
|
[[ $(dd if=/dev/vda bs=512 skip=105 count=29 status=none | sha256sum |
|
|
awk '{print $1}') == "${expected_candidate_sha}" ]]
|
|
[[ $(dd if=/dev/vda bs=512 skip=139 count=2 status=none | sha256sum |
|
|
awk '{print $1}') == \
|
|
$(sha256sum "${render_root}/guanghu-recovery-clear.env" | awk '{print $1}') ]]
|
|
|
|
observed_at=$(date --iso-8601=seconds)
|
|
cat >"${recovery_root}/PREPARE-RECEIPT.hldp" <<EOF
|
|
schema: guanghu.jd-native-resident-prepare/v1
|
|
receipt_id: GH-OS-JD-FD-PRIMARY-001-RESIDENT-PREPARE
|
|
status: VERIFIED_NOT_ARMED
|
|
observed_at: ${observed_at}
|
|
node_id: JD-FD-PRIMARY
|
|
candidate:
|
|
lba_start: 105
|
|
sector_count: 29
|
|
sha256: ${expected_candidate_sha}
|
|
proof_lba: 134
|
|
world_store_lba: 135
|
|
code_channel_lba: 136
|
|
code_object_lba: 137
|
|
branch_receipt_lba: 138
|
|
recovery_beacon_lba_start: 139
|
|
gestational_index_lba_start: 141
|
|
rollback:
|
|
recovery_root: ${recovery_root}
|
|
first_and_last_2mib_backed_up: true
|
|
grub_backed_up: true
|
|
one_time_entry_installed_not_armed: true
|
|
next_action: ARM_ONE_TIME_RESIDENT_AND_RUN_EXTERNAL_HLDP_PEER
|
|
EOF
|
|
chmod 0400 "${recovery_root}"/*
|
|
sync
|
|
cat "${recovery_root}/PREPARE-RECEIPT.hldp"
|