a23012cee0
BREAKING CHANGE: The patch-based build system is removed. All Red Bear source now lives in local/sources/<component>/ as git repos. Changes: - src/recipe.rs: remove patches field from SourceRecipe::Git/Tar, add Local variant - src/cook/fetch.rs: delete fetch_apply_patches, validate_patches, normalize_patch, fetch_compute_patches_hash, fetch_write_patches_state, fetch_patches_state_stale, fetch_validate_patch_symlinks, fetch_is_patches_newer. Simplify fetch and fetch_offline. Remove recipe_has_patches. Add Local source handler. - src/bin/repo.rs: remove validate-patches command and handle_validate_patches - 70 recipe.toml files: remove patches arrays, convert core recipes to Local source - 272 .patch symlinks deleted from recipe directories - integrate-redbear.sh: replace patch symlink logic with source fork validation - Makefile: replace validate-patches with validate-sources target - AGENTS.md: remove 369 lines of patch documentation, add source ownership model - local/docs/PATCH-GOVERNANCE.md: deleted (replaced by SOURCE-OWNERSHIP-MODEL.md) - local/docs/SOURCE-OWNERSHIP-MODEL.md: new canonical reference - local/sources/: Red Bear fork repos created (kernel, relibc, base, bootloader, installer) from frozen 0.1.0 pre-patched archives - .gitignore: exclude local/sources/ (separate git repos) - create-forks.sh: new script for initializing fork repos Build: cargo check passes (5 warnings, 0 errors). Developer workflow is now: edit local/sources/ → repo cook → test. No patches.
44 lines
1.6 KiB
TOML
44 lines
1.6 KiB
TOML
#TODO resolver runtime on Redox still needs stronger validation; relibc now exports resolv.h/nameser surfaces
|
|
#TODO lack of utmpx.h, expect no way to track login in sshd
|
|
[source]
|
|
tar = "https://cdn.openbsd.org/pub/OpenBSD/OpenSSH/portable/openssh-9.8p1.tar.gz"
|
|
[build]
|
|
template = "custom"
|
|
dependencies = [
|
|
"openssl3",
|
|
"zlib",
|
|
"zstd",
|
|
]
|
|
script = """
|
|
DYNAMIC_INIT
|
|
RELIBC_STAGE_INCLUDE="${COOKBOOK_ROOT}/recipes/core/relibc/target/${TARGET}/stage/usr/include"
|
|
RELIBC_STAGE_LIB="${COOKBOOK_ROOT}/recipes/core/relibc/target/${TARGET}/stage/usr/lib"
|
|
if [ -d "${RELIBC_STAGE_INCLUDE}" ]; then
|
|
export CPPFLAGS="${CPPFLAGS} -I${RELIBC_STAGE_INCLUDE}"
|
|
export CFLAGS="${CFLAGS} -I${RELIBC_STAGE_INCLUDE}"
|
|
fi
|
|
if [ -d "${RELIBC_STAGE_LIB}" ]; then
|
|
export LDFLAGS="-L${RELIBC_STAGE_LIB} -Wl,-rpath-link,${RELIBC_STAGE_LIB} ${LDFLAGS}"
|
|
fi
|
|
COOKBOOK_CONFIGURE_FLAGS+=(
|
|
--disable-strip
|
|
--sysconfdir=/etc/ssh
|
|
)
|
|
export CFLAGS+=" -DSYSTEMD_NOTIFY=1"
|
|
cookbook_configure
|
|
mv "${COOKBOOK_STAGE}"/usr/sbin/sshd "${COOKBOOK_STAGE}"/usr/bin/sshd
|
|
rmdir "${COOKBOOK_STAGE}"/usr/sbin
|
|
|
|
# Extracted from `make host-key-force`
|
|
# TODO: Postscript to generate this
|
|
# ssh-keygen -t dsa -f "${COOKBOOK_STAGE}"/etc/ssh/ssh_host_dsa_key -N ""
|
|
# ssh-keygen -t rsa -f "${COOKBOOK_STAGE}"/etc/ssh/ssh_host_rsa_key -N ""
|
|
# ssh-keygen -t ed25519 -f "${COOKBOOK_STAGE}"/etc/ssh/ssh_host_ed25519_key -N ""
|
|
# ssh-keygen -t ecdsa -f "${COOKBOOK_STAGE}"/etc/ssh/ssh_host_ecdsa_key -N ""
|
|
|
|
CONFIG_FILE="${COOKBOOK_STAGE}"/etc/ssh/sshd_config
|
|
|
|
# ipv6 is not working yet
|
|
sed -i "s/#AddressFamily any/AddressFamily inet/g" "${CONFIG_FILE}"
|
|
"""
|