From c972517b38709031277c23c4b963880272ee1ca6 Mon Sep 17 00:00:00 2001 From: JumpyVi Date: Sun, 27 Sep 2026 12:09:24 -0400 Subject: [PATCH 1/6] Add passphrase encryption support --- mkosi.conf | 11 +++ .../usr/lib/dracut.conf.d/base-ubuntu.conf | 4 -- .../usr/lib/dracut.conf.d/lvm2.conf | 1 - .../mkosi.extra/usr/sbin/elementary-install | 69 ++++++++++++------- mkosi.images/sysupdate/mkosi.conf | 3 +- 5 files changed, 57 insertions(+), 31 deletions(-) delete mode 100644 mkosi.images/base/mkosi.extra/usr/lib/dracut.conf.d/base-ubuntu.conf delete mode 100644 mkosi.images/base/mkosi.extra/usr/lib/dracut.conf.d/lvm2.conf diff --git a/mkosi.conf b/mkosi.conf index 7d2ba08a2..5c385052e 100644 --- a/mkosi.conf +++ b/mkosi.conf @@ -6,6 +6,17 @@ Distribution=ubuntu Release=resolute Repositories=main,universe,restricted +[Content] +InitrdVolatilePackages= + systemd + udev + systemd-cryptsetup + cryptsetup-bin + bash + coreutils + util-linux + plymouth + plymouth-theme-elementary [Build] ToolsTree=default CacheDirectory=mkosi.cache diff --git a/mkosi.images/base/mkosi.extra/usr/lib/dracut.conf.d/base-ubuntu.conf b/mkosi.images/base/mkosi.extra/usr/lib/dracut.conf.d/base-ubuntu.conf deleted file mode 100644 index bc2e09618..000000000 --- a/mkosi.images/base/mkosi.extra/usr/lib/dracut.conf.d/base-ubuntu.conf +++ /dev/null @@ -1,4 +0,0 @@ -export DRACUT_NO_XATTR=1 -reproducible=yes -hostonly=no -compress=zstd diff --git a/mkosi.images/base/mkosi.extra/usr/lib/dracut.conf.d/lvm2.conf b/mkosi.images/base/mkosi.extra/usr/lib/dracut.conf.d/lvm2.conf deleted file mode 100644 index fa0c03dab..000000000 --- a/mkosi.images/base/mkosi.extra/usr/lib/dracut.conf.d/lvm2.conf +++ /dev/null @@ -1 +0,0 @@ -add_dracutmodules+=" lvm dm crypt fips " diff --git a/mkosi.images/liveiso/mkosi.extra/usr/sbin/elementary-install b/mkosi.images/liveiso/mkosi.extra/usr/sbin/elementary-install index f2d00b02a..7a4681168 100755 --- a/mkosi.images/liveiso/mkosi.extra/usr/sbin/elementary-install +++ b/mkosi.images/liveiso/mkosi.extra/usr/sbin/elementary-install @@ -9,7 +9,6 @@ extra="$medium/extra" raw_squashfs=$(find "$extra" -maxdepth 1 -type f -name '*.raw.squashfs' | head -n1) repart_src="/opt/repart-target" - # Exit if iso wasnt properly built if [ -z "$raw_squashfs" ]; then echo "Installation aborted: No .raw.squashfs file found." @@ -18,15 +17,14 @@ fi echo "Using source image: $raw_squashfs" - # Disk selector PS3="Select installation disk (ALL DATA WILL BE LOST): " select selected_disk in $(lsblk -d -n -p -o NAME -e 7,11); do -if [[ -n "$selected_disk" ]]; then - break -fi -echo "Invalid selection, try again." + if [[ -n "$selected_disk" ]]; then + break + fi + echo "Invalid selection, try again." done if [ -z "$selected_disk" ]; then @@ -36,15 +34,15 @@ fi dest_dev=$(echo "$selected_disk" | awk '{print $1}') - # Encryption selector PS3="Select encryption method: " repart_args=() +keyfile="" -crypt_options=("off") +crypt_options=("off" "passphrase") -# Add tpm option if there is a tpm device -if [ -e /dev/tpm0 ] || [ -e /dev/tpmrm0 ]; then +# Check if systemd thinks you got a good tpm (only "yes", don't show on "partial" and "no") +if [ "$(systemd-analyze has-tpm2 2>/dev/null | head -n1)" = "yes" ]; then crypt_options+=("tpm2") fi @@ -55,6 +53,27 @@ select crypt in "${crypt_options[@]}"; do sed -i 's/Encrypt=.*/Encrypt=tpm2/' "$repart_src/40-root.conf" break ;; + passphrase) + echo "Selected passphrase encryption." + sed -i 's/Encrypt=.*/Encrypt=key-file/' "$repart_src/40-root.conf" + keyfile=$(mktemp) + chmod 600 "$keyfile" + + while true; do + read -rs -p "Enter encryption passphrase: " pass1; echo + read -rs -p "Confirm passphrase: " pass2; echo + if [ -n "$pass1" ] && [ "$pass1" = "$pass2" ]; then + printf '%s' "$pass1" > "$keyfile" + unset pass1 pass2 + break + fi + echo "Passphrases didn't match or were empty, try again." + unset pass1 pass2 + done + + repart_args+=(--key-file="$keyfile") + break + ;; off) echo "Encryption disabled." sed -i 's/Encrypt=.*/Encrypt=off/' "$repart_src/40-root.conf" @@ -67,31 +86,30 @@ select crypt in "${crypt_options[@]}"; do done echo "$dest_dev selected for repartitioning..." -echo "Destroying drive in 3s ..." +echo "Wiping drive in 3s ..." sleep 1 -echo "Destroying drive in 2s ..." +echo "Wiping drive in 2s ..." sleep 1 -echo "Destroying drive in 1s ..." +echo "Wiping drive in 1s ..." sleep 1 - -# Wipe disk, wipefs -a seems to be the most reliable option for this... +# Wipe disk /usr/sbin/wipefs -a "$dest_dev" - # Mount the squashed sysupdate install image squash_mount=/mnt/source-image mkdir -p "$squash_mount" echo "Mounting compressed image..." if ! mount -t squashfs -o loop,ro "$raw_squashfs" "$squash_mount"; then -echo "Could not mount image, aborting." -exit 1 + echo "Could not mount image, aborting." + exit 1 fi # Cleanup on exit cleanup() { -umount "$squash_mount" 2>/dev/null || true -rmdir "$squash_mount" 2>/dev/null || true + umount "$squash_mount" 2>/dev/null || true + rmdir "$squash_mount" 2>/dev/null || true + [ -n "$keyfile" ] && shred -u "$keyfile" 2>/dev/null || true } trap cleanup EXIT @@ -106,11 +124,12 @@ fi # The actual install! raw_src has the system partitions, while repart_src has the root partition echo "Flashing image (efi, root, usr, ...) onto $dest_dev..." systemd-repart \ ---copy-from="$raw_src" \ ---definitions="$repart_src/" \ ---dry-run=no \ ---empty=force \ -"$dest_dev" + --copy-from="$raw_src" \ + --definitions="$repart_src/" \ + --dry-run=no \ + --empty=force \ + "${repart_args[@]}" \ + "$dest_dev" partprobe "$dest_dev" udevadm settle diff --git a/mkosi.images/sysupdate/mkosi.conf b/mkosi.images/sysupdate/mkosi.conf index 649819195..6d1d03693 100644 --- a/mkosi.images/sysupdate/mkosi.conf +++ b/mkosi.images/sysupdate/mkosi.conf @@ -27,6 +27,7 @@ Bootloader=systemd-boot KernelInitrdModules= default ahci + crypt nvme xhci_pci usb_storage @@ -36,7 +37,7 @@ KernelInitrdModules= KernelCommandLine= splash quiet - root=dissect + root=gpt-auto mount.usr=dissect rw audit=0 From 95d6f7fcc5236abbae323c1208baf711a008049e Mon Sep 17 00:00:00 2001 From: JumpyVi <62212220+jumpyvi@users.noreply.github.com> Date: Sun, 27 Sep 2026 13:11:38 -0400 Subject: [PATCH 2/6] Update mkosi.conf Co-authored-by: Lewis Goddard --- mkosi.conf | 1 + 1 file changed, 1 insertion(+) diff --git a/mkosi.conf b/mkosi.conf index 5c385052e..06de800bc 100644 --- a/mkosi.conf +++ b/mkosi.conf @@ -7,6 +7,7 @@ Release=resolute Repositories=main,universe,restricted [Content] +InitrdProfiles=plymouth InitrdVolatilePackages= systemd udev From e4b93e547b582d74129a8b2c4c1fef1d5d58732c Mon Sep 17 00:00:00 2001 From: JumpyVi <62212220+jumpyvi@users.noreply.github.com> Date: Sun, 27 Sep 2026 13:12:58 -0400 Subject: [PATCH 3/6] Update mkosi.images/sysupdate/mkosi.conf Co-authored-by: Lewis Goddard --- mkosi.images/sysupdate/mkosi.conf | 1 - 1 file changed, 1 deletion(-) diff --git a/mkosi.images/sysupdate/mkosi.conf b/mkosi.images/sysupdate/mkosi.conf index 6d1d03693..7f10d47ee 100644 --- a/mkosi.images/sysupdate/mkosi.conf +++ b/mkosi.images/sysupdate/mkosi.conf @@ -27,7 +27,6 @@ Bootloader=systemd-boot KernelInitrdModules= default ahci - crypt nvme xhci_pci usb_storage From d2b166512dc10e5bc4f263c984cf468307ddcc89 Mon Sep 17 00:00:00 2001 From: JumpyVi <62212220+jumpyvi@users.noreply.github.com> Date: Sun, 27 Sep 2026 13:13:14 -0400 Subject: [PATCH 4/6] Update mkosi.images/liveiso/mkosi.extra/usr/sbin/elementary-install Co-authored-by: Lewis Goddard --- mkosi.images/liveiso/mkosi.extra/usr/sbin/elementary-install | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/mkosi.images/liveiso/mkosi.extra/usr/sbin/elementary-install b/mkosi.images/liveiso/mkosi.extra/usr/sbin/elementary-install index 7a4681168..a1e35edf7 100755 --- a/mkosi.images/liveiso/mkosi.extra/usr/sbin/elementary-install +++ b/mkosi.images/liveiso/mkosi.extra/usr/sbin/elementary-install @@ -60,8 +60,8 @@ select crypt in "${crypt_options[@]}"; do chmod 600 "$keyfile" while true; do - read -rs -p "Enter encryption passphrase: " pass1; echo - read -rs -p "Confirm passphrase: " pass2; echo + IFS= read -rs -p "Enter encryption passphrase: " pass1; echo + IFS= read -rs -p "Confirm passphrase: " pass2; echo if [ -n "$pass1" ] && [ "$pass1" = "$pass2" ]; then printf '%s' "$pass1" > "$keyfile" unset pass1 pass2 From 50df37609677809ed2ae1f60bb6af42a67b7d333 Mon Sep 17 00:00:00 2001 From: JumpyVi <62212220+jumpyvi@users.noreply.github.com> Date: Sun, 27 Sep 2026 13:13:26 -0400 Subject: [PATCH 5/6] Update mkosi.conf Co-authored-by: Lewis Goddard --- mkosi.conf | 1 + 1 file changed, 1 insertion(+) diff --git a/mkosi.conf b/mkosi.conf index 06de800bc..99efc6c1e 100644 --- a/mkosi.conf +++ b/mkosi.conf @@ -18,6 +18,7 @@ InitrdVolatilePackages= util-linux plymouth plymouth-theme-elementary + [Build] ToolsTree=default CacheDirectory=mkosi.cache From c75b3bf795836e40f90aecf732f9a89b888660eb Mon Sep 17 00:00:00 2001 From: JumpyVi Date: Sun, 27 Sep 2026 13:25:06 -0400 Subject: [PATCH 6/6] Allow encrypted root --- mkosi.images/sysupdate/mkosi.conf | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/mkosi.images/sysupdate/mkosi.conf b/mkosi.images/sysupdate/mkosi.conf index 7f10d47ee..e4faab5f5 100644 --- a/mkosi.images/sysupdate/mkosi.conf +++ b/mkosi.images/sysupdate/mkosi.conf @@ -36,11 +36,11 @@ KernelInitrdModules= KernelCommandLine= splash quiet - root=gpt-auto + root=dissect mount.usr=dissect rw audit=0 - systemd.image_policy=esp=unprotected:xbootldr=unprotected+unused+absent:usr=signed:root=unprotected+absent:home=unprotected+absent:=ignore + systemd.image_policy=esp=unprotected:xbootldr=unprotected+unused+absent:usr=signed:root=unprotected+encrypted+absent:home=unprotected+absent:=ignore systemd.image_filter=usr=elementary_*:usr-verity=elementary_*:usr-verity-sig=elementary_*:root=elementary-*:home=elementary-* ipe.enforce=0