]> git.proxmox.com Git - pve-kernel.git/blob - debian/rules
d/rules: temporarily disable UBSAN bound checks again
[pve-kernel.git] / debian / rules
1 #!/usr/bin/make -f
2 # -*- makefile -*-
3
4 # Uncomment this to turn on verbose mode.
5 #export DH_VERBOSE=1
6
7 # TODO: check for headers not being installed
8 BUILD_DIR=$(shell pwd)
9
10 include /usr/share/dpkg/default.mk
11 include debian/rules.d/env.mk
12 include debian/rules.d/$(DEB_BUILD_ARCH).mk
13
14 MAKEFLAGS += $(subst parallel=,-j,$(filter parallel=%,${DEB_BUILD_OPTIONS}))
15
16 CHANGELOG_DATE:=$(shell dpkg-parsechangelog -SDate)
17 CHANGELOG_DATE_UTC_ISO := $(shell date -u -d '$(CHANGELOG_DATE)' +%Y-%m-%dT%H:%MZ)
18
19 PMX_KERNEL_PKG=proxmox-kernel-$(KVNAME)
20 PMX_KERNEL_SERIES_PKG=proxmox-kernel-$(KERNEL_MAJMIN)
21 PMX_DEBUG_KERNEL_PKG=proxmox-kernel-$(KVNAME)-dbgsym
22 PMX_HEADER_PKG=proxmox-headers-$(KVNAME)
23 PMX_USR_HEADER_PKG=proxmox-kernel-libc-dev
24 LINUX_TOOLS_PKG=linux-tools-$(KERNEL_MAJMIN)
25 KERNEL_SRC_COPY=$(KERNEL_SRC)_tmp
26
27 # TODO: split for archs, move to files?
28 PMX_CONFIG_OPTS= \
29 -m INTEL_MEI_WDT \
30 -d CONFIG_SND_PCM_OSS \
31 -e CONFIG_TRANSPARENT_HUGEPAGE_MADVISE \
32 -d CONFIG_TRANSPARENT_HUGEPAGE_ALWAYS \
33 -m CONFIG_CEPH_FS \
34 -m CONFIG_BLK_DEV_NBD \
35 -m CONFIG_BLK_DEV_RBD \
36 -m CONFIG_BLK_DEV_UBLK \
37 -d CONFIG_SND_PCSP \
38 -m CONFIG_BCACHE \
39 -m CONFIG_JFS_FS \
40 -m CONFIG_HFS_FS \
41 -m CONFIG_HFSPLUS_FS \
42 -e CIFS_SMB_DIRECT \
43 -e CONFIG_SQUASHFS_DECOMP_MULTI_PERCPU \
44 -e CONFIG_BRIDGE \
45 -e CONFIG_BRIDGE_NETFILTER \
46 -e CONFIG_BLK_DEV_SD \
47 -e CONFIG_BLK_DEV_SR \
48 -e CONFIG_BLK_DEV_DM \
49 -m CONFIG_BLK_DEV_NVME \
50 -e CONFIG_NLS_ISO8859_1 \
51 -d CONFIG_INPUT_EVBUG \
52 -d CONFIG_CPU_FREQ_DEFAULT_GOV_ONDEMAND \
53 -d CONFIG_CPU_FREQ_DEFAULT_GOV_SCHEDUTIL \
54 -e CONFIG_CPU_FREQ_DEFAULT_GOV_PERFORMANCE \
55 -e CONFIG_SYSFB_SIMPLEFB \
56 -e CONFIG_DRM_SIMPLEDRM \
57 -e CONFIG_MODULE_SIG \
58 -e CONFIG_MODULE_SIG_ALL \
59 -e CONFIG_MODULE_SIG_FORMAT \
60 --set-str CONFIG_MODULE_SIG_HASH sha512 \
61 --set-str CONFIG_MODULE_SIG_KEY certs/signing_key.pem \
62 -e CONFIG_MODULE_SIG_KEY_TYPE_RSA \
63 -e CONFIG_MODULE_SIG_SHA512 \
64 -d CONFIG_MEMCG_DISABLED \
65 -e CONFIG_MEMCG_SWAP_ENABLED \
66 -e CONFIG_HYPERV \
67 -m CONFIG_VFIO_IOMMU_TYPE1 \
68 -m CONFIG_VFIO_VIRQFD \
69 -m CONFIG_VFIO \
70 -m CONFIG_VFIO_PCI \
71 -m CONFIG_USB_XHCI_HCD \
72 -m CONFIG_USB_XHCI_PCI \
73 -m CONFIG_USB_EHCI_HCD \
74 -m CONFIG_USB_EHCI_PCI \
75 -m CONFIG_USB_EHCI_HCD_PLATFORM \
76 -m CONFIG_USB_OHCI_HCD \
77 -m CONFIG_USB_OHCI_HCD_PCI \
78 -m CONFIG_USB_OHCI_HCD_PLATFORM \
79 -d CONFIG_USB_OHCI_HCD_SSB \
80 -m CONFIG_USB_UHCI_HCD \
81 -d CONFIG_USB_SL811_HCD_ISO \
82 -e CONFIG_MEMCG_KMEM \
83 -d CONFIG_DEFAULT_CFQ \
84 -e CONFIG_DEFAULT_DEADLINE \
85 -e CONFIG_MODVERSIONS \
86 -e CONFIG_ZSTD_COMPRESS \
87 -d CONFIG_DEFAULT_SECURITY_DAC \
88 -e CONFIG_DEFAULT_SECURITY_APPARMOR \
89 --set-str CONFIG_DEFAULT_SECURITY apparmor \
90 -e CONFIG_MODULE_ALLOW_BTF_MISMATCH \
91 -d CONFIG_UNWINDER_ORC \
92 -d CONFIG_UNWINDER_GUESS \
93 -e CONFIG_UNWINDER_FRAME_POINTER \
94 --set-str CONFIG_SYSTEM_TRUSTED_KEYS ""\
95 --set-str CONFIG_SYSTEM_REVOCATION_KEYS ""\
96 -e CONFIG_SECURITY_LOCKDOWN_LSM \
97 -e CONFIG_SECURITY_LOCKDOWN_LSM_EARLY \
98 --set-str CONFIG_LSM lockdown,yama,integrity,apparmor \
99 -e CONFIG_PAGE_TABLE_ISOLATION \
100 -e CONFIG_ARCH_HAS_CPU_FINALIZE_INIT \
101 -d CONFIG_GDS_FORCE_MITIGATION \
102 -d CONFIG_WQ_CPU_INTENSIVE_REPORT \
103 -d UBSAN_BOUNDS \
104
105 debian/control: $(wildcard debian/*.in)
106 sed -e 's/@@KVNAME@@/$(KVNAME)/g' < debian/proxmox-kernel.prerm.in > debian/$(PMX_KERNEL_PKG).prerm
107 sed -e 's/@@KVNAME@@/$(KVNAME)/g' < debian/proxmox-kernel.postrm.in > debian/$(PMX_KERNEL_PKG).postrm
108 sed -e 's/@@KVNAME@@/$(KVNAME)/g' < debian/proxmox-kernel.postinst.in > debian/$(PMX_KERNEL_PKG).postinst
109 sed -e 's/@@KVNAME@@/$(KVNAME)/g' < debian/proxmox-headers.postinst.in > debian/$(PMX_HEADER_PKG).postinst
110 sed -e 's/@@KVMAJMIN@@/$(KERNEL_MAJMIN)/g' -e 's/@@KVNAME@@/$(KVNAME)/g' < debian/proxmox-kernel-meta.postrm.in > debian/$(PMX_KERNEL_SERIES_PKG).postrm
111 sed -e 's/@@KVMAJMIN@@/$(KERNEL_MAJMIN)/g' -e 's/@@KVNAME@@/$(KVNAME)/g' < debian/proxmox-kernel-meta.postinst.in > debian/$(PMX_KERNEL_SERIES_PKG).postinst
112 chmod +x debian/$(PMX_KERNEL_PKG).prerm
113 chmod +x debian/$(PMX_KERNEL_PKG).postrm
114 chmod +x debian/$(PMX_KERNEL_PKG).postinst
115 chmod +x debian/$(PMX_KERNEL_SERIES_PKG).postrm
116 chmod +x debian/$(PMX_KERNEL_SERIES_PKG).postinst
117 chmod +x debian/$(PMX_HEADER_PKG).postinst
118 sed -e 's/@KVNAME@/$(KVNAME)/g' -e 's/@KVMAJMIN@/$(KERNEL_MAJMIN)/g' < debian/control.in > debian/control
119
120 build: .compile_mark .tools_compile_mark .modules_compile_mark
121
122 install: .install_mark .tools_install_mark .headers_install_mark .usr_headers_install_mark
123 dh_installdocs -A debian/copyright debian/SOURCE
124 dh_installchangelogs
125 dh_installman
126 dh_strip_nondeterminism
127 dh_compress
128 dh_fixperms
129
130 binary: install
131 debian/rules fwcheck abicheck
132 dh_strip -N$(PMX_HEADER_PKG) -N$(PMX_USR_HEADER_PKG)
133 dh_makeshlibs
134 dh_shlibdeps
135 dh_installdeb
136 dh_gencontrol
137 dh_md5sums
138 dh_builddeb
139
140 .config_mark:
141 cd $(KERNEL_SRC); scripts/config $(PMX_CONFIG_OPTS)
142 $(MAKE) -C $(KERNEL_SRC) olddefconfig
143 # copy to allow building in parallel to kernel/module compilation without interference
144 rm -rf $(KERNEL_SRC_COPY)
145 cp -ar $(KERNEL_SRC) $(KERNEL_SRC_COPY)
146 touch $@
147
148 .compile_mark: .config_mark
149 $(MAKE) -C $(KERNEL_SRC) KBUILD_BUILD_VERSION_TIMESTAMP="PMX $(DEB_VERSION) ($(CHANGELOG_DATE_UTC_ISO))"
150 touch $@
151
152 .install_mark: .compile_mark .modules_compile_mark
153 rm -rf debian/$(PMX_KERNEL_PKG)
154 mkdir -p debian/$(PMX_KERNEL_PKG)/lib/modules/$(KVNAME)
155 mkdir debian/$(PMX_KERNEL_PKG)/boot
156 install -m 644 $(KERNEL_SRC)/.config debian/$(PMX_KERNEL_PKG)/boot/config-$(KVNAME)
157 install -m 644 $(KERNEL_SRC)/System.map debian/$(PMX_KERNEL_PKG)/boot/System.map-$(KVNAME)
158 install -m 644 $(KERNEL_SRC)/$(KERNEL_IMAGE_PATH) debian/$(PMX_KERNEL_PKG)/boot/$(KERNEL_INSTALL_FILE)-$(KVNAME)
159 $(MAKE) -C $(KERNEL_SRC) INSTALL_MOD_PATH=$(BUILD_DIR)/debian/$(PMX_KERNEL_PKG)/ modules_install
160 # install zfs drivers
161 install -d -m 0755 debian/$(PMX_KERNEL_PKG)/lib/modules/$(KVNAME)/zfs
162 install -m 644 $(MODULES)/zfs.ko $(MODULES)/spl.ko debian/$(PMX_KERNEL_PKG)/lib/modules/$(KVNAME)/zfs
163 # remove firmware
164 rm -rf debian/$(PMX_KERNEL_PKG)/lib/firmware
165
166 ifeq ($(filter pkg.proxmox-kernel.debug,$(DEB_BUILD_PROFILES)),)
167 echo "'pkg.proxmox-kernel.debug' build profile disabled, skipping -dbgsym creation"
168 else
169 echo "'pkg.proxmox-kernel.debug' build profile enabled, creating -dbgsym contents"
170 mkdir -p debian/$(PMX_DEBUG_KERNEL_PKG)/usr/lib/debug/lib/modules/$(KVNAME)
171 mkdir debian/$(PMX_DEBUG_KERNEL_PKG)/usr/lib/debug/boot
172 install -m 644 $(KERNEL_SRC)/vmlinux debian/$(PMX_DEBUG_KERNEL_PKG)/usr/lib/debug/boot/vmlinux-$(KVNAME)
173 cp -r debian/$(PMX_KERNEL_PKG)/lib/modules/$(KVNAME) debian/$(PMX_DEBUG_KERNEL_PKG)/usr/lib/debug/lib/modules/
174 rm -f debian/$(PMX_DEBUG_KERNEL_PKG)/usr/lib/debug/lib/modules/$(KVNAME)/source
175 rm -f debian/$(PMX_DEBUG_KERNEL_PKG)/usr/lib/debug/lib/modules/$(KVNAME)/build
176 rm -f debian/$(PMX_DEBUG_KERNEL_PKG)/usr/lib/debug/lib/modules/$(KVNAME)/modules.*
177 endif
178
179 # strip debug info
180 find debian/$(PMX_KERNEL_PKG)/lib/modules -name \*.ko -print | while read f ; do strip --strip-debug "$$f"; done
181
182 # sign modules using ephemeral, embedded key
183 if grep -q CONFIG_MODULE_SIG=y ubuntu-kernel/.config ; then \
184 find debian/$(PMX_KERNEL_PKG)/lib/modules -name \*.ko -print | while read f ; do \
185 ./ubuntu-kernel/scripts/sign-file sha512 ./ubuntu-kernel/certs/signing_key.pem ubuntu-kernel/certs/signing_key.x509 "$$f" ; \
186 done; \
187 rm ./ubuntu-kernel/certs/signing_key.pem ; \
188 fi
189 # finalize
190 /sbin/depmod -b debian/$(PMX_KERNEL_PKG)/ $(KVNAME)
191 # Autogenerate blacklist for watchdog devices (see README)
192 install -m 0755 -d debian/$(PMX_KERNEL_PKG)/lib/modprobe.d
193 ls debian/$(PMX_KERNEL_PKG)/lib/modules/$(KVNAME)/kernel/drivers/watchdog/ > watchdog-blacklist.tmp
194 echo ipmi_watchdog.ko >> watchdog-blacklist.tmp
195 cat watchdog-blacklist.tmp|sed -e 's/^/blacklist /' -e 's/.ko$$//'|sort -u > debian/$(PMX_KERNEL_PKG)/lib/modprobe.d/blacklist_$(PMX_KERNEL_PKG).conf
196 rm -f debian/$(PMX_KERNEL_PKG)/lib/modules/$(KVNAME)/source
197 rm -f debian/$(PMX_KERNEL_PKG)/lib/modules/$(KVNAME)/build
198 touch $@
199
200 .tools_compile_mark: .compile_mark
201 $(MAKE) -C $(KERNEL_SRC)/tools/perf prefix=/usr NO_LIBTRACEEVENT=1 HAVE_NO_LIBBFD=1 HAVE_CPLUS_DEMANGLE_SUPPORT=1 NO_LIBPYTHON=1 NO_LIBPERL=1 NO_LIBCRYPTO=1 PYTHON=python3
202 echo "checking GPL-2 only perf binary for library linkage with incompatible licenses.."
203 ! ldd $(KERNEL_SRC)/tools/perf/perf | grep -q -E '\blibbfd'
204 ! ldd $(KERNEL_SRC)/tools/perf/perf | grep -q -E '\blibcrypto'
205 $(MAKE) -C $(KERNEL_SRC)/tools/perf NO_LIBTRACEEVENT=1 man
206 touch $@
207
208 .tools_install_mark: .tools_compile_mark
209 rm -rf debian/$(LINUX_TOOLS_PKG)
210 mkdir -p debian/$(LINUX_TOOLS_PKG)/usr/bin
211 mkdir -p debian/$(LINUX_TOOLS_PKG)/usr/share/man/man1
212 install -m 755 $(BUILD_DIR)/$(KERNEL_SRC)/tools/perf/perf debian/$(LINUX_TOOLS_PKG)/usr/bin/perf_$(KERNEL_MAJMIN)
213 for i in $(BUILD_DIR)/$(KERNEL_SRC)/tools/perf/Documentation/*.1; do \
214 fname="$${i##*/}"; manname="$${fname%.1}"; \
215 install -m644 "$$i" "debian/$(LINUX_TOOLS_PKG)/usr/share/man/man1/$${manname}_$(KERNEL_MAJMIN).1"; \
216 done
217 touch $@
218
219 .headers_prepare_mark: .config_mark
220 rm -rf debian/$(PMX_HEADER_PKG)
221 mkdir -p debian/$(PMX_HEADER_PKG)/usr/src/linux-headers-$(KVNAME)
222 install -m 0644 $(KERNEL_SRC)/.config debian/$(PMX_HEADER_PKG)/usr/src/linux-headers-$(KVNAME)
223 make -C $(KERNEL_SRC_COPY) mrproper
224 cd $(KERNEL_SRC_COPY); find . -path './debian/*' -prune \
225 -o -path './include/*' -prune \
226 -o -path './Documentation' -prune \
227 -o -path './scripts' -prune \
228 -o -type f \
229 \( \
230 -name 'Makefile*' \
231 -o -name 'Kconfig*' \
232 -o -name 'Kbuild*' \
233 -o -name '*.sh' \
234 -o -name '*.pl' \
235 \) \
236 -print | cpio -pd --preserve-modification-time $(BUILD_DIR)/debian/$(PMX_HEADER_PKG)/usr/src/linux-headers-$(KVNAME)
237 cd $(KERNEL_SRC_COPY); \
238 ( \
239 find arch/$(KERNEL_HEADER_ARCH) -name include -type d -print | \
240 xargs -n1 -i: find : -type f \
241 ) | \
242 cpio -pd --preserve-modification-time $(BUILD_DIR)/debian/$(PMX_HEADER_PKG)/usr/src/linux-headers-$(KVNAME)
243 touch $@
244
245 .headers_compile_mark: .headers_prepare_mark
246 # set output to subdir of source to reduce number of hardcoded paths in output files
247 rm -rf $(BUILD_DIR)/$(KERNEL_SRC_COPY)/$(PMX_HEADER_PKG)
248 mkdir -p $(BUILD_DIR)/$(KERNEL_SRC_COPY)/$(PMX_HEADER_PKG)
249 cp $(KERNEL_SRC)/.config $(BUILD_DIR)/$(KERNEL_SRC_COPY)/$(PMX_HEADER_PKG)/.config
250 $(MAKE) -C $(KERNEL_SRC_COPY) O=$(BUILD_DIR)/$(KERNEL_SRC_COPY)/$(PMX_HEADER_PKG) -j1 syncconfig modules_prepare prepare scripts
251 cd $(KERNEL_SRC_COPY); cp -a include scripts $(BUILD_DIR)/debian/$(PMX_HEADER_PKG)/usr/src/linux-headers-$(KVNAME)
252 find $(BUILD_DIR)/$(KERNEL_SRC_COPY)/$(PMX_HEADER_PKG) -name \*.o.ur-\* -o -name '*.cmd' | xargs rm -f
253 rsync --ignore-existing -r -v -a $(addprefix $(BUILD_DIR)/$(KERNEL_SRC_COPY)/$(PMX_HEADER_PKG)/,arch include kernel scripts tools) $(BUILD_DIR)/debian/$(PMX_HEADER_PKG)/usr/src/linux-headers-$(KVNAME)/
254 rm -rf $(BUILD_DIR)/$(KERNEL_SRC_COPY)
255 touch $@
256
257 .headers_install_mark: .compile_mark .modules_compile_mark .headers_compile_mark
258 cp $(KERNEL_SRC)/include/generated/compile.h debian/$(PMX_HEADER_PKG)/usr/src/linux-headers-$(KVNAME)/include/generated/compile.h
259 install -m 0644 $(KERNEL_SRC)/Module.symvers debian/$(PMX_HEADER_PKG)/usr/src/linux-headers-$(KVNAME)
260 mkdir -p debian/$(PMX_HEADER_PKG)/lib/modules/$(KVNAME)
261 ln -sf /usr/src/linux-headers-$(KVNAME) debian/$(PMX_HEADER_PKG)/lib/modules/$(KVNAME)/build
262 touch $@
263
264 .usr_headers_install_mark: PKG_DIR = debian/$(PMX_USR_HEADER_PKG)
265 .usr_headers_install_mark: OUT_DIR = $(PKG_DIR)/usr
266 .usr_headers_install_mark: .config_mark
267 rm -rf '$(PKG_DIR)'
268 mkdir -p '$(PKG_DIR)'
269 $(MAKE) -C $(KERNEL_SRC) headers_install ARCH=$(KERNEL_HEADER_ARCH) INSTALL_HDR_PATH='$(CURDIR)'/$(OUT_DIR)
270 rm -rf $(OUT_DIR)/include/drm $(OUT_DIR)/include/scsi
271 find $(OUT_DIR)/include \( -name .install -o -name ..install.cmd \) -execdir rm {} +
272
273 # Move include/asm to arch-specific directory
274 mkdir -p $(OUT_DIR)/include/$(DEB_HOST_MULTIARCH)
275 mv $(OUT_DIR)/include/asm $(OUT_DIR)/include/$(DEB_HOST_MULTIARCH)/
276 test ! -d $(OUT_DIR)/include/arch || \
277 mv $(OUT_DIR)/include/arch $(OUT_DIR)/include/$(DEB_HOST_MULTIARCH)/
278 touch $@
279
280 .modules_compile_mark: $(MODULES)/zfs.ko
281 touch $@
282
283 $(MODULES)/zfs.ko: .compile_mark
284 cd $(MODULES)/$(ZFSDIR); ./autogen.sh
285 cd $(MODULES)/$(ZFSDIR); ./configure --with-config=kernel --with-linux=$(BUILD_DIR)/$(KERNEL_SRC) --with-linux-obj=$(BUILD_DIR)/$(KERNEL_SRC)
286 $(MAKE) -C $(MODULES)/$(ZFSDIR)
287 cp $(MODULES)/$(ZFSDIR)/module/zfs.ko $(MODULES)/
288 cp $(MODULES)/$(ZFSDIR)/module/spl.ko $(MODULES)/
289
290 fwlist-$(KVNAME): .compile_mark .modules_compile_mark
291 debian/scripts/find-firmware.pl debian/$(PMX_KERNEL_PKG)/lib/modules/$(KVNAME) >fwlist.tmp
292 mv fwlist.tmp $@
293
294 .PHONY: fwcheck
295 fwcheck: fwlist-$(KVNAME) fwlist-previous
296 @echo "checking fwlist for changes since last built firmware package.."
297 @echo "if this check fails, add fwlist-$(KVNAME) to the pve-firmware repository and upload a new firmware package together with the $(KVNAME) kernel"
298 sort fwlist-previous | uniq > fwlist-previous.sorted
299 sort fwlist-$(KVNAME) | uniq > fwlist-$(KVNAME).sorted
300 diff -up -N fwlist-previous.sorted fwlist-$(KVNAME).sorted > fwlist.diff
301 rm fwlist.diff fwlist-previous.sorted fwlist-$(KVNAME).sorted
302 @echo "done, no need to rebuild pve-firmware"
303
304
305 abi-$(KVNAME): .compile_mark
306 debian/scripts/abi-generate debian/$(PMX_HEADER_PKG)/usr/src/linux-headers-$(KVNAME)/Module.symvers abi-$(KVNAME) $(KVNAME)
307
308 .PHONY: abicheck
309 abicheck: debian/scripts/abi-check abi-$(KVNAME) abi-prev-* abi-blacklist
310 debian/scripts/abi-check abi-$(KVNAME) abi-prev-* $(SKIPABI)
311
312 .PHONY: clean