Build Initramfs Rootless
blog.izissise.net
blog.izissise.net
By default the kernel will not mount devtmpfs automatically within an initramfs, even if you've configured your kernel to automatically mount devtmpfs, because it waits until the real rootfs has been mounted to do it. This is fine unless you never plan to actually mount a real rootfs as you've made your initramfs have everything a normal rootfs would have and you want devtmpfs to Just Work.
You don't even need a devtmpfs in the initramfs environment, and it may or may not even persist into the fully booted system. I believe Systemd has a tmpfs unit file, and OpenRC has a service for it which is enabled by default.
In this case, my point is for a system where the "fully booted" state is still within an initramfs. There is no "new root" past the initramfs, it IS the rootfs which will run forever until the system is rebooted or shutdown.
Without it, my favorite way of building images rootless is still fakeroot. fakeroot + mknod + cpio can fully replace gen_init_cpio
It also allows for you to create archives compressed with gz, bz2, lzma, xz (via lzma), or potentially any other option that Python can provide.
Given an mtree file foo.mtree:
#mtree
baz/bar type=file content=quux
You can produce a ZIP containing baz/bar with: bsdtar -c --format=zip -f out.zip @foo.mtree
There’s a much better explanation in the bsdtar manual at https://man.freebsd.org/cgi/man.cgi?query=bsdtar&sektion=1&f...If you’re on Windows, “tar.exe” is bsdtar. With the caveat that the mtree file should be saved with LF line endings, this should still work.
https://github.com/amluto/virtme/blob/master/virtme/cpiowrit...
Debian has jigdo, but the recipe/template for it is derived after that fact by scanning the ISO and then blanking out the parts of it that match external files— there's no mechanism for authoring them pre asset creation.
https://git.distrust.co/public/enclaveos/src/branch/master/C...
And another one for a simple busybox based ISO for airgap operations:
https://git.distrust.co/public/airgap/src/branch/stagex-rewr...
Making Linux images for server/appliance use cases is always more secure and almost always easier than trying to adapt workstation distros like debian. Lots of ways to do it depending on your tooling preferences.
I have used it to convert docker images to Linux bootable initramfs archives for Rpi4.
It's mostly made to work with Gentoo (uses pax-utils for finding dependencies), but should work with any distro. It does most of the initramfs creation process rootless. The main consideration is that you need privileges to make device nodes, but I just create them synthetically within the cpio image.
On most systems, this tool still requires root to copy the mount binary.
Have you found any specific niches that scratch an itch with your tool?
printf '%s\n' '#include <stdio.h>' '#include <unistd.h>' 'int main() { printf("Hello world!\n"); sleep(999999999); }' | gcc -fpic -static -xc - -o init
This is completely irrelevant, but that line reminded me of the old “real programmers write device drivers with cat” joke. I guess even realer programmers would write device drivers directly into gcc stdin.- programatically declare the /dev/ files and their permissions
- link the binaries you want to use
I've learned about crunched binaries (like busybox, but in reverse), so I wonder if there's a BSD way to do that.
There have been others in the past, but this seems to be the most polished and ready to use ATM(for FBSD).
Another would be NanoBSD (also FBSD).
For NetBSD you're on your own, starting from there https://wiki.netbsd.org/tutorials/how_to_create_bootable_net... , and/or asking on https://daemonforums.org/ , https://www.unitedbsd.com/ (taking inspiration from some 'live-distro' discussed there. like 'OS-108'), reddit(?), 'crap-overflow', and even https://www.linuxquestions.org/.
Of course you're free to use the official NetBSD mailing lists, and some obscure IRC-channels in even more obscure IRC-networks also :-)
(You won't be spoon-fed, and are expected to have read the manuals and other documentations...)
However, I need pointers to get started.
> You won't be spoon-fed, and are expected to have read the manuals and other documentations...
I read a lot of FreeBSD and NetBSD documentation to get to the point of compiling my own kernels, but I don't think I ever read about the equivalent concept of Linux cpio/initramfs for BSD. My minimal images use a UFS filesystem.
Here, after checking https://mfsbsd.vx.sk/ and https://github.com/mmatuska/mfsbsd/blob/master/scripts/mdini... I think mfsbsd is just a using tmpfs so it may not exactly the same thing as initramfs, that allows booting linux from a bzImage + initrd
I'll keep searching, it's not super high priority at the moment, but it's something I'd like to do with (Free|Net)BSD.
Back to topic, does it matter if it's using different mechanisms, if achieving the same result at the end of the day? Like running in RAM, and not necessarily having to be 'installed' on some medium, being very minimal, and optionally 'rebooting/remounting/pivoting' into something larger, which may also reside in RAM?
That OS-108 may have been misleading, because it seams rather dead, but I thought it did something like that, eons ago, when I looked at it in emulation.
https://github.com/OS108/OS108/tree/master/LiveImgScripts
Anyways, it's based on this https://github.com/tsutsui/netbsd-teokureliveimage , which isn't, most relevant would be mkimagebuilder.sh and mkliveimage.sh from there, I guess. If that doesn't get you further than your own minimal images, I've understood you wrong, and probably wasted your time.
I did not see anything special that would make it rootless. That seemed to be a point made by the submitter.
>Note this is rootless, we don't need to re-create the filesystem tree locally or use fakeroot to create special file in the archive.
Another related one is about installing grub into an archived filesystem or disk image. Should be trivial, right? But most instructions for this require mounting it, which immediately means you need SYS_ADMIN and therefore a privileged container in your CI setup.
I made my own CPIO library: https://github.com/desultory/pycpio and one of the main goals was this behavior, so I could create CPIO archives with device nodes without privileges. It's really as simple as writing some bytes to a file saying "when you extract this, create this device node". It's not like any archive actually has a device node, just instructions for where to put them, and what properties they have.
Certainly, you can't extract these archives as non-root, but you have to go out of your way to make an initramfs have non-root privileges.