feat: graphical installer in the live ISO

The ISO now boots straight into a GTK installer instead of dropping to a
tty. Structure:

- installer/arcline-installer: small GTK3 (Python) frontend that drives
  scripts/deploy-disk.sh — pick a disk, choose boot mode, type the device
  path to confirm, watch the deploy log, reboot. Pure helper logic is
  tested against lsblk (lowercase keys, pseudo-devices filtered).
- scripts/build-live.sh: builds build/rootfs/<edition>-live by cloning the
  CLEAN rootfs and layering on live-boot, a minimal X session (Xorg +
  openbox), the installer, and the deploy tooling under /usr/lib/arcline
  (deploy-disk.sh + btrfs/init.sh + edition fstabs, laid out so the
  scripts' own path resolution works unchanged).
- overlays/live/: arcline-installer.service + session script that start
  Xorg on vt1 (with -allow-root) and run the installer as the X client.
- build-iso.sh: builds the live rootfs for the squashfs AND stages the
  clean rootfs archive into isofiles/install/ — the installer deploys the
  clean archive, so what's installed is the hardened system, never the
  live session with the installer in it.
- Refactor: ARCLINE_LIVE handling removed from build-rootfs.sh and
  configure-system.sh (now lives entirely in build-live.sh).
- validate.sh now checks overlays shell scripts + installer python.
- docs updated (building.md, architecture.md, installer/README.md).
This commit is contained in:
Blake Ridgway
2026-08-21 20:24:09 -05:00
parent 578c518553
commit 0ea8b713dd
11 changed files with 522 additions and 46 deletions

View File

@@ -1,14 +1,17 @@
#!/usr/bin/env bash
# ─────────────────────────────────────────────────────────────────────────────
# Arcline OS — live ISO builder
# Arcline OS — live ISO builder (with graphical installer)
#
# scripts/build-iso.sh <edition>
#
# Wraps a rootfs into a hybrid (BIOS+UEFI) live ISO:
# 1. ensure the rootfs exists (build it with live-boot support if needed)
# 2. stage kernel + initramfs + squashfs in isofiles/live
# 3. write the grub boot config (live-boot: boot=live)
# 4. grub-mkrescue → build/artifacts/arcline-<edition>-<version>-<arch>.iso
# Produces a hybrid (BIOS+UEFI) live ISO that boots straight into the Arcline
# graphical installer:
# 1. ensure the CLEAN rootfs exists (what the installer deploys)
# 2. build-live.sh → build/rootfs/<edition>-live (live-boot + X + installer)
# 3. stage kernel + initramfs + squashfs in isofiles/live, and the clean
# rootfs archive in isofiles/install (the installer's install source)
# 4. write the grub boot config (live-boot: boot=live)
# 5. grub-mkrescue → build/artifacts/arcline-<edition>-<version>-<arch>.iso
#
# Requires root for the rootfs stage; the ISO assembly itself runs unprivileged.
# ─────────────────────────────────────────────────────────────────────────────
@@ -18,48 +21,54 @@ source "$(dirname "${BASH_SOURCE[0]}")/common.sh"
EDITION="${1:?usage: build-iso.sh <edition>}"
validate_edition "$EDITION"
ROOTFS="$ROOTFS_DIR/$EDITION"
CLEAN="$ROOTFS_DIR/$EDITION"
LIVE_ROOT="$ROOTFS_DIR/$EDITION-live"
INSTALL_ARC="$ARTIFACT_DIR/arcline-$EDITION-$VERSION-$ARCH.tar.xz"
ISOFILES="$IMAGE_DIR/$EDITION/isofiles"
ARTIFACT="$ARTIFACT_DIR/arcline-$EDITION-$VERSION-$ARCH.iso"
# ── 1. rootfs ───────────────────────────────────────────────────────────────
if [[ ! -d "$ROOTFS" ]]; then
log "rootfs missing — building with live-boot support"
ARCLINE_LIVE=1 "$ROOT/scripts/build-rootfs.sh" "$EDITION"
# ── 1. rootfs(es) ───────────────────────────────────────────────────────────
# The ISO is a live session (built on top of the clean rootfs) and carries the
# CLEAN rootfs archive as the install source for the graphical installer.
if [[ ! -d "$CLEAN" ]]; then
log "clean rootfs missing — building it first"
"$ROOT/scripts/build-rootfs.sh" "$EDITION"
fi
# live-boot must be present in the rootfs for the ISO to boot
if [[ ! -d "$ROOTFS/lib/live" && ! -d "$ROOTFS/usr/lib/live" ]]; then
warn "rootfs has no live-boot support; rebuilding with ARCLINE_LIVE=1"
ARCLINE_LIVE=1 "$ROOT/scripts/build-rootfs.sh" "$EDITION"
if [[ ! -f "$INSTALL_ARC" ]]; then
log "clean rootfs archive missing — building it first"
"$ROOT/scripts/build-rootfs.sh" "$EDITION"
fi
"$ROOT/scripts/build-live.sh" "$EDITION"
# ── 2. stage files ──────────────────────────────────────────────────────────
log "staging ISO files for edition '$EDITION'"
rm -rf "$ISOFILES"
mkdir -p "$ISOFILES/live" "$ISOFILES/boot/grub"
mkdir -p "$ISOFILES/live" "$ISOFILES/boot/grub" "$ISOFILES/install"
KERNEL="$(find "$ROOTFS/boot" -maxdepth 1 -name 'vmlinuz-*' | sort -V | tail -1)"
INITRD="$(find "$ROOTFS/boot" -maxdepth 1 -name 'initrd.img-*' | sort -V | tail -1)"
[[ -n "$KERNEL" && -n "$INITRD" ]] || die "kernel or initramfs not found in rootfs"
KERNEL="$(find "$LIVE_ROOT/boot" -maxdepth 1 -name 'vmlinuz-*' | sort -V | tail -1)"
INITRD="$(find "$LIVE_ROOT/boot" -maxdepth 1 -name 'initrd.img-*' | sort -V | tail -1)"
[[ -n "$KERNEL" && -n "$INITRD" ]] || die "kernel or initramfs not found in live rootfs"
cp -L "$KERNEL" "$ISOFILES/live/vmlinuz"
cp -L "$INITRD" "$ISOFILES/live/initrd.img"
# the clean (installed-system) rootfs is what the installer deploys
cp "$INSTALL_ARC" "$ISOFILES/install/arcline-$EDITION.tar.xz"
# ── 2b. secure boot (optional: ARCLINE_SIGN=1 + a MOK keypair) ──────────────
if [[ "${ARCLINE_SIGN:-0}" == "1" ]]; then
log "secure boot: signing boot chain and shipping MOK in the live image"
[[ -f "$BUILD_DIR/keys/MOK.der" ]] || die "ARCLINE_SIGN=1 but no MOK keypair — run: scripts/secureboot/gen-keys.sh"
mkdir -p "$ROOTFS/etc/arcline"
cp "$BUILD_DIR/keys/MOK.der" "$ROOTFS/etc/arcline/MOK.der"
"$ROOT/scripts/secureboot/sign-image.sh" "$ROOTFS" --keydir "$BUILD_DIR/keys"
mkdir -p "$LIVE_ROOT/etc/arcline"
cp "$BUILD_DIR/keys/MOK.der" "$LIVE_ROOT/etc/arcline/MOK.der"
"$ROOT/scripts/secureboot/sign-image.sh" "$LIVE_ROOT" --keydir "$BUILD_DIR/keys"
"$ROOT/scripts/secureboot/sign-image.sh" "$ISOFILES" --keydir "$BUILD_DIR/keys"
fi
log "compressing rootfs → squashfs (this takes a while)"
# The squashfs is the live root. Keep it complete — offline man pages and
# docs are a product promise (see the landing page), so nothing is excluded.
mksquashfs "$ROOTFS" "$ISOFILES/live/arcline.squashfs" -noappend -comp zstd -Xcompression-level 15 2>/dev/null || \
mksquashfs "$ROOTFS" "$ISOFILES/live/arcline.squashfs" -noappend -comp xz
log "compressing live rootfs → squashfs (this takes a while)"
# The squashfs is the live session root. Keep it complete — offline man pages
# and docs are a product promise (see the landing page), so nothing is excluded.
mksquashfs "$LIVE_ROOT" "$ISOFILES/live/arcline.squashfs" -noappend -comp zstd -Xcompression-level 15 2>/dev/null || \
mksquashfs "$LIVE_ROOT" "$ISOFILES/live/arcline.squashfs" -noappend -comp xz
# ── 3. grub boot config ─────────────────────────────────────────────────────
log "writing grub config"