Splits the ARM64 build into two tracks per docs/arm64-architecture.md: Generic ARM64 (mainline kernel.org, UEFI, virtio, GRUB): - New build/scripts/build-kernel-arm64.sh builds mainline LTS (6.12.x by default) from arm64 defconfig + shared container fragment + arm64-virt enables (VIRTIO_*, EFI_STUB, NVMe). Output: build/cache/kernel-arm64-generic/. - New Makefile targets: kernel-arm64, rootfs-arm64 (now consumes the mainline kernel modules via TARGET_VARIANT=generic). - versions.env: pin MAINLINE_KERNEL_VERSION=6.12.10, declare cdn.kernel.org URL and SHA256 placeholder. Raspberry Pi (raspberrypi/linux fork, custom DTBs, autoboot.txt): - build-kernel-arm64.sh (RPi-flavoured) renamed to build-kernel-rpi.sh; cache dir renamed from custom-kernel-arm64 to custom-kernel-rpi. - New Makefile targets: kernel-rpi, rootfs-arm64-rpi (uses TARGET_VARIANT=rpi). - rpi-image now depends on rootfs-arm64-rpi + kernel-rpi instead of the generic rootfs-arm64. - create-rpi-image.sh + inject-kubesolo.sh updated to reference the new cache path. inject-kubesolo.sh now takes a TARGET_VARIANT env var (rpi|generic) to select which ARM64 kernel modules to consume. Shared substrate: - rpi-kernel-config.fragment renamed to kernel-container.fragment. The contents were never RPi-specific (cgroup, namespaces, AppArmor, netfilter) — just misnamed. Extended with extra subsystem disables (KVM, WLAN, CFG80211, INFINIBAND, PCMCIA, HAMRADIO, ISDN, ATM, INPUT_JOYSTICK, INPUT_TABLET, FPGA) and CONFIG_LSM=lockdown,yama,apparmor. - build-kernel.sh (x86) refactored to apply the shared fragment via a generic apply_fragment function (two-pass for the TC stock config security dance), killing ~50 lines of inline config duplication. Note: rename detection shows build-kernel-arm64.sh as 'modified' because the new file at that path is the mainline build, while the old RPi-flavoured content lives in build-kernel-rpi.sh (which appears as a new file). The git log for build-kernel-rpi.sh is empty; the RPi history is preserved at the original path until this commit. No actual kernel build runs in this commit — that's Phase 3 work. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
91 lines
2.2 KiB
Plaintext
91 lines
2.2 KiB
Plaintext
# KubeSolo OS — Shared kernel config fragment for container workloads
|
|
#
|
|
# Applied on top of:
|
|
# - Tiny Core stock config (x86_64) via build-kernel.sh
|
|
# - mainline kernel.org arm64 defconfig via build-kernel-arm64.sh
|
|
# - bcm2711_defconfig / bcm2712_defconfig via build-kernel-rpi.sh
|
|
#
|
|
# All entries here are architecture-agnostic.
|
|
# Apply this fragment twice with `make olddefconfig` between passes — TC's stock
|
|
# config has CONFIG_SECURITY disabled, which causes a single-pass olddefconfig
|
|
# to strip the security subtree before its dependencies (SYSFS, MULTIUSER) are
|
|
# resolved.
|
|
|
|
# cgroup v2 (mandatory for containerd/runc)
|
|
CONFIG_CGROUPS=y
|
|
CONFIG_CGROUP_CPUACCT=y
|
|
CONFIG_CGROUP_DEVICE=y
|
|
CONFIG_CGROUP_FREEZER=y
|
|
CONFIG_CGROUP_SCHED=y
|
|
CONFIG_CGROUP_PIDS=y
|
|
CONFIG_MEMCG=y
|
|
CONFIG_CGROUP_BPF=y
|
|
CONFIG_CFS_BANDWIDTH=y
|
|
|
|
# BPF (required for cgroup v2 device control)
|
|
CONFIG_BPF=y
|
|
CONFIG_BPF_SYSCALL=y
|
|
|
|
# Namespaces (mandatory for containers)
|
|
CONFIG_NAMESPACES=y
|
|
CONFIG_NET_NS=y
|
|
CONFIG_PID_NS=y
|
|
CONFIG_USER_NS=y
|
|
CONFIG_UTS_NS=y
|
|
CONFIG_IPC_NS=y
|
|
|
|
# Device management
|
|
CONFIG_DEVTMPFS=y
|
|
CONFIG_DEVTMPFS_MOUNT=y
|
|
|
|
# Filesystem
|
|
CONFIG_OVERLAY_FS=y
|
|
CONFIG_SQUASHFS=y
|
|
CONFIG_EXT4_FS=y
|
|
CONFIG_VFAT_FS=y
|
|
|
|
# Networking
|
|
CONFIG_BRIDGE=m
|
|
CONFIG_NETFILTER=y
|
|
CONFIG_NF_CONNTRACK=m
|
|
CONFIG_NF_NAT=m
|
|
CONFIG_NF_TABLES=m
|
|
CONFIG_VETH=m
|
|
CONFIG_VXLAN=m
|
|
|
|
# Security: AppArmor + Audit
|
|
CONFIG_AUDIT=y
|
|
CONFIG_AUDITSYSCALL=y
|
|
CONFIG_SECURITY=y
|
|
CONFIG_SECURITYFS=y
|
|
CONFIG_SECURITY_NETWORK=y
|
|
CONFIG_SECURITY_APPARMOR=y
|
|
CONFIG_DEFAULT_SECURITY_APPARMOR=y
|
|
CONFIG_LSM=lockdown,yama,apparmor
|
|
|
|
# Security: seccomp
|
|
CONFIG_SECCOMP=y
|
|
CONFIG_SECCOMP_FILTER=y
|
|
|
|
# Crypto (image verification)
|
|
CONFIG_CRYPTO_SHA256=y
|
|
|
|
# Disable unnecessary subsystems for headless edge appliance
|
|
# CONFIG_SOUND is not set
|
|
# CONFIG_DRM is not set
|
|
# CONFIG_KVM is not set
|
|
# CONFIG_MEDIA_SUPPORT is not set
|
|
# CONFIG_WIRELESS is not set
|
|
# CONFIG_WLAN is not set
|
|
# CONFIG_CFG80211 is not set
|
|
# CONFIG_BT is not set
|
|
# CONFIG_NFC is not set
|
|
# CONFIG_INFINIBAND is not set
|
|
# CONFIG_PCMCIA is not set
|
|
# CONFIG_HAMRADIO is not set
|
|
# CONFIG_ISDN is not set
|
|
# CONFIG_ATM is not set
|
|
# CONFIG_INPUT_JOYSTICK is not set
|
|
# CONFIG_INPUT_TABLET is not set
|
|
# CONFIG_FPGA is not set
|