# __ ____ ____ _____ # ____ / /_ __ __/ / /___ ____ ___ ___ / __ \/ ___/ # / __ \/ __ \/ / / / / / __ \/ __ `__ \/ _ \ / / / /\__ \ # / /_/ / / / / /_/ / / / /_/ / / / / / / __/ / /_/ /___/ / # / .___/_/ /_/\__, /_/_/\____/_/ /_/ /_/\___/ \____//____/ # /_/ /____/ # What ? This kickstart file provides a basic block to build a minimal, live system # text # Perform installation in text mode keyboard --xlayouts='ch (fr)' # set keyboard layouts for Romandie lang en_US.UTF-8 # Set system language to American English. More languages could be supported: --addsupport=cs_CZ,de_DE,en_UK timezone Europe/Paris --utc # Set system timezone to Paris selinux --enforcing # Make sure SELinux is in enforced mode firewall --enabled --service=mdns # selinux --enforcing # firewall --enabled --service=mdns # xconfig --startxonboot zerombr clearpart --all # part / --size 5120 # bootloader --timeout=2 # services --enabled=NetworkManager --disabled=sshd # network --bootproto=dhcp --device=link --activate --hostname=phyllome # # rootpw --lock --iscrypted locked # # # shutdown # zerombr # clearpart --all # part / --size 5120 --fstype ext4 # services --enabled=NetworkManager,ModemManager --disabled=sshd network --bootproto=dhcp --device=link --activate rootpw --lock --iscrypted locked shutdown # # %packages # Beginning of the packages section. # # # Explicitly specified here: # # walters: because otherwise dependency loops cause yum issues. # kernel # kernel-modules # kernel-modules-extra # # # This was added a while ago, I think it falls into the category of # # "Diagnosis/recovery tool useful from a Live OS image". Leaving this untouched # # for now. # #memtest86+ # #@x86-baremetal-tools # memtest86+ is included # # # The point of a live image is to install # # anaconda # # anaconda-install-env-deps # # anaconda-live # # @anaconda-tools # # Anaconda has a weak dep on this and we don't want it on livecds, see # # https://fedoraproject.org/wiki/Changes/RemoveDeviceMapperMultipathFromWorkstationLiveCD # # -fcoe-utils # # -device-mapper-multipath # # # Need aajohan-comfortaa-fonts for the SVG rnotes images # # aajohan-comfortaa-fonts # # # Without this, initramfs generation during live image creation fails: #1242586 # dracut-live # dracut-config-generic # add that as sugested here : https://www.brianlane.com/post/creating-live-isos-with-livemedia-creator/ # # # For UEFI-boot, see https://github.com/weldr/lorax/blob/master/docs/fedora-livemedia.ks # shim # shim-ia32 # grub2 # grub2-efi # grub2-efi-*-cdboot # grub2-efi-ia32 # efibootmgr # # # syslinux is in @x86-baremetal-tools # # # anaconda needs the locales available to run for different locales # glibc-all-langpacks # # # no longer in @core since 2018-10, but needed for livesys script # initscripts # chkconfig # # @core # minimal installation # pciutils # Pciutils provides lspci commandline tool and is not installed by default # # initial-setup # Install the initial setup package. For the GUI version, use initial-setup-gui instead. # qemu-guest-agent # "QEMU guest agent" # spice-vdagent # "Agent for Spice guests" # -fedora-logos # Fedora logos # -fedora-release # Fedora release-notes # -fedora-release-notes # -fedora-release-common # Fedora release files # -fedora-release-identity-basic # ??? # fedora-remix-logos # Install Fedora remix logos # generic-release # generic-logos # generic-release-common # "Generic release files" # generic-release-notes # "Release Notes" # %end # End of the packages section %packages # Explicitly specified here: # walters: because otherwise dependency loops cause yum issues. kernel kernel-modules kernel-modules-extra # This was added a while ago, I think it falls into the category of # "Diagnosis/recovery tool useful from a Live OS image". Leaving this untouched # for now. #memtest86+ @x86-baremetal-tools # memtest86+ is included # The point of a live image is to install anaconda anaconda-install-env-deps anaconda-live @anaconda-tools # Anaconda has a weak dep on this and we don't want it on livecds, see # https://fedoraproject.org/wiki/Changes/RemoveDeviceMapperMultipathFromWorkstationLiveCD -fcoe-utils -device-mapper-multipath # Need aajohan-comfortaa-fonts for the SVG rnotes images aajohan-comfortaa-fonts # Without this, initramfs generation during live image creation fails: #1242586 dracut-live # syslinux is in @x86-baremetal-tools # anaconda needs the locales available to run for different locales glibc-all-langpacks # no longer in @core since 2018-10, but needed for livesys script initscripts chkconfig %end # End of the packages section %post --log=/root/bl.log # Beginning of the post-installation section. Add logging. # FIXME: it'd be better to get this installed from a package cat > /etc/rc.d/init.d/livesys << EOF #!/bin/bash # # live: Init script for live image # # chkconfig: 345 00 99 # description: Init script for live image. ### BEGIN INIT INFO # X-Start-Before: display-manager chronyd ### END INIT INFO . /etc/init.d/functions if ! strstr "\`cat /proc/cmdline\`" rd.live.image || [ "\$1" != "start" ]; then exit 0 fi if [ -e /.liveimg-configured ] ; then configdone=1 fi exists() { which \$1 >/dev/null 2>&1 || return \$* } livedir="LiveOS" for arg in \`cat /proc/cmdline\` ; do if [ "\${arg##rd.live.dir=}" != "\${arg}" ]; then livedir=\${arg##rd.live.dir=} continue fi if [ "\${arg##live_dir=}" != "\${arg}" ]; then livedir=\${arg##live_dir=} fi done # enable swapfile if it exists if ! strstr "\`cat /proc/cmdline\`" noswap && [ -f /run/initramfs/live/\${livedir}/swap.img ] ; then action "Enabling swap file" swapon /run/initramfs/live/\${livedir}/swap.img fi mountPersistentHome() { # support label/uuid if [ "\${homedev##LABEL=}" != "\${homedev}" -o "\${homedev##UUID=}" != "\${homedev}" ]; then homedev=\`/sbin/blkid -o device -t "\$homedev"\` fi # if we're given a file rather than a blockdev, loopback it if [ "\${homedev##mtd}" != "\${homedev}" ]; then # mtd devs don't have a block device but get magic-mounted with -t jffs2 mountopts="-t jffs2" elif [ ! -b "\$homedev" ]; then loopdev=\`losetup -f\` if [ "\${homedev##/run/initramfs/live}" != "\${homedev}" ]; then action "Remounting live store r/w" mount -o remount,rw /run/initramfs/live fi losetup \$loopdev \$homedev homedev=\$loopdev fi # if it's encrypted, we need to unlock it if [ "\$(/sbin/blkid -s TYPE -o value \$homedev 2>/dev/null)" = "crypto_LUKS" ]; then echo echo "Setting up encrypted /home device" plymouth ask-for-password --command="cryptsetup luksOpen \$homedev EncHome" homedev=/dev/mapper/EncHome fi # and finally do the mount mount \$mountopts \$homedev /home # if we have /home under what's passed for persistent home, then # we should make that the real /home. useful for mtd device on olpc if [ -d /home/home ]; then mount --bind /home/home /home ; fi [ -x /sbin/restorecon ] && /sbin/restorecon /home if [ -d /home/liveuser ]; then USERADDARGS="-M" ; fi } findPersistentHome() { for arg in \`cat /proc/cmdline\` ; do if [ "\${arg##persistenthome=}" != "\${arg}" ]; then homedev=\${arg##persistenthome=} fi done } if strstr "\`cat /proc/cmdline\`" persistenthome= ; then findPersistentHome elif [ -e /run/initramfs/live/\${livedir}/home.img ]; then homedev=/run/initramfs/live/\${livedir}/home.img fi # if we have a persistent /home, then we want to go ahead and mount it if ! strstr "\`cat /proc/cmdline\`" nopersistenthome && [ -n "\$homedev" ] ; then action "Mounting persistent /home" mountPersistentHome fi if [ -n "\$configdone" ]; then exit 0 fi # add liveuser user with no passwd action "Adding live user" useradd \$USERADDARGS -c "Live System User" liveuser passwd -d liveuser > /dev/null usermod -aG wheel liveuser > /dev/null # Remove root password lock passwd -d root > /dev/null # turn off firstboot for livecd boots systemctl --no-reload disable firstboot-text.service 2> /dev/null || : systemctl --no-reload disable firstboot-graphical.service 2> /dev/null || : systemctl stop firstboot-text.service 2> /dev/null || : systemctl stop firstboot-graphical.service 2> /dev/null || : # don't use prelink on a running live image sed -i 's/PRELINKING=yes/PRELINKING=no/' /etc/sysconfig/prelink &>/dev/null || : # turn off mdmonitor by default systemctl --no-reload disable mdmonitor.service 2> /dev/null || : systemctl --no-reload disable mdmonitor-takeover.service 2> /dev/null || : systemctl stop mdmonitor.service 2> /dev/null || : systemctl stop mdmonitor-takeover.service 2> /dev/null || : # don't start cron/at as they tend to spawn things which are # disk intensive that are painful on a live image systemctl --no-reload disable crond.service 2> /dev/null || : systemctl --no-reload disable atd.service 2> /dev/null || : systemctl stop crond.service 2> /dev/null || : systemctl stop atd.service 2> /dev/null || : # turn off abrtd on a live image systemctl --no-reload disable abrtd.service 2> /dev/null || : systemctl stop abrtd.service 2> /dev/null || : # Don't sync the system clock when running live (RHBZ #1018162) sed -i 's/rtcsync//' /etc/chrony.conf # Mark things as configured touch /.liveimg-configured # add static hostname to work around xauth bug # https://bugzilla.redhat.com/show_bug.cgi?id=679486 # the hostname must be something else than 'localhost' # https://bugzilla.redhat.com/show_bug.cgi?id=1370222 hostnamectl set-hostname "localhost-live" EOF # bah, hal starts way too late cat > /etc/rc.d/init.d/livesys-late << EOF #!/bin/bash # # live: Late init script for live image # # chkconfig: 345 99 01 # description: Late init script for live image. . /etc/init.d/functions if ! strstr "\`cat /proc/cmdline\`" rd.live.image || [ "\$1" != "start" ] || [ -e /.liveimg-late-configured ] ; then exit 0 fi exists() { which \$1 >/dev/null 2>&1 || return \$* } touch /.liveimg-late-configured # read some variables out of /proc/cmdline for o in \`cat /proc/cmdline\` ; do case \$o in ks=*) ks="--kickstart=\${o#ks=}" ;; xdriver=*) xdriver="\${o#xdriver=}" ;; esac done # if liveinst or textinst is given, start anaconda if strstr "\`cat /proc/cmdline\`" liveinst ; then plymouth --quit /usr/sbin/liveinst \$ks fi if strstr "\`cat /proc/cmdline\`" textinst ; then plymouth --quit /usr/sbin/liveinst --text \$ks fi # configure X, allowing user to override xdriver if [ -n "\$xdriver" ]; then cat > /etc/X11/xorg.conf.d/00-xdriver.conf <> /etc/fstab << EOF vartmp /var/tmp tmpfs defaults 0 0 EOF # work around for poor key import UI in PackageKit rm -f /var/lib/rpm/__db* echo "Packages within this LiveCD" rpm -qa --qf '%{size}\t%{name}-%{version}-%{release}.%{arch}\n' |sort -rn # Note that running rpm recreates the rpm db files which aren't needed or wanted rm -f /var/lib/rpm/__db* # go ahead and pre-make the man -k cache (#455968) /usr/bin/mandb # make sure there aren't core files lying around rm -f /core* # remove random seed, the newly installed instance should make it's own rm -f /var/lib/systemd/random-seed # convince readahead not to collect # FIXME: for systemd echo 'File created by kickstart. See systemd-update-done.service(8).' \ | tee /etc/.updated >/var/.updated # Drop the rescue kernel and initramfs, we don't need them on the live media itself. # See bug 1317709 rm -f /boot/*-rescue* # Disable network service here, as doing it in the services line # fails due to RHBZ #1369794 /sbin/chkconfig network off # Remove machine-id on pre generated images rm -f /etc/machine-id touch /etc/machine-id %end %post --nochroot --log=/mnt/sysimage/opt/base-live.log # For livecd-creator builds only (lorax/livemedia-creator handles this directly) if [ -n "$LIVE_ROOT" ]; then cp "$INSTALL_ROOT"/usr/share/licenses/*-release-common/* "$LIVE_ROOT/" # only installed on x86, x86_64 if [ -f /usr/bin/livecd-iso-to-disk ]; then mkdir -p "$LIVE_ROOT/LiveOS" cp /usr/bin/livecd-iso-to-disk "$LIVE_ROOT/LiveOS" fi fi %end