]> git.proxmox.com Git - pve-kernel.git/blob - debian/rules
update ZFS to get better work-around for UBSAN bounds-checking
[pve-kernel.git] / debian / rules
1 #!/usr/bin/make -f
2 # -*- makefile -*-
3
4 # Uncomment this to turn on verbose mode.
5 #export DH_VERBOSE=1
6
7 # TODO: check for headers not being installed
8 BUILD_DIR=$(shell pwd)
9
10 include /usr/share/dpkg/default.mk
11 include debian/rules.d/env.mk
12 include debian/rules.d/$(DEB_BUILD_ARCH).mk
13
14 MAKEFLAGS += $(subst parallel=,-j,$(filter parallel=%,${DEB_BUILD_OPTIONS}))
15
16 CHANGELOG_DATE:=$(shell dpkg-parsechangelog -SDate)
17 CHANGELOG_DATE_UTC_ISO := $(shell date -u -d '$(CHANGELOG_DATE)' +%Y-%m-%dT%H:%MZ)
18
19 PMX_KERNEL_PKG=proxmox-kernel-$(KVNAME)
20 PMX_KERNEL_SERIES_PKG=proxmox-kernel-$(KERNEL_MAJMIN)
21 PMX_DEBUG_KERNEL_PKG=proxmox-kernel-$(KVNAME)-dbgsym
22 PMX_HEADER_PKG=proxmox-headers-$(KVNAME)
23 PMX_USR_HEADER_PKG=proxmox-kernel-libc-dev
24 LINUX_TOOLS_PKG=linux-tools-$(KERNEL_MAJMIN)
25 KERNEL_SRC_COPY=$(KERNEL_SRC)_tmp
26
27 # TODO: split for archs, move to files?
28 PMX_CONFIG_OPTS= \
29 -m INTEL_MEI_WDT \
30 -d CONFIG_SND_PCM_OSS \
31 -e CONFIG_TRANSPARENT_HUGEPAGE_MADVISE \
32 -d CONFIG_TRANSPARENT_HUGEPAGE_ALWAYS \
33 -m CONFIG_CEPH_FS \
34 -m CONFIG_BLK_DEV_NBD \
35 -m CONFIG_BLK_DEV_RBD \
36 -m CONFIG_BLK_DEV_UBLK \
37 -d CONFIG_SND_PCSP \
38 -m CONFIG_BCACHE \
39 -m CONFIG_JFS_FS \
40 -m CONFIG_HFS_FS \
41 -m CONFIG_HFSPLUS_FS \
42 -e CIFS_SMB_DIRECT \
43 -e CONFIG_SQUASHFS_DECOMP_MULTI_PERCPU \
44 -e CONFIG_BRIDGE \
45 -e CONFIG_BRIDGE_NETFILTER \
46 -e CONFIG_BLK_DEV_SD \
47 -e CONFIG_BLK_DEV_SR \
48 -e CONFIG_BLK_DEV_DM \
49 -m CONFIG_BLK_DEV_NVME \
50 -e CONFIG_NLS_ISO8859_1 \
51 -d CONFIG_INPUT_EVBUG \
52 -d CONFIG_CPU_FREQ_DEFAULT_GOV_ONDEMAND \
53 -d CONFIG_CPU_FREQ_DEFAULT_GOV_SCHEDUTIL \
54 -e CONFIG_CPU_FREQ_DEFAULT_GOV_PERFORMANCE \
55 -e CONFIG_SYSFB_SIMPLEFB \
56 -e CONFIG_DRM_SIMPLEDRM \
57 -e CONFIG_MODULE_SIG \
58 -e CONFIG_MODULE_SIG_ALL \
59 -e CONFIG_MODULE_SIG_FORMAT \
60 --set-str CONFIG_MODULE_SIG_HASH sha512 \
61 --set-str CONFIG_MODULE_SIG_KEY certs/signing_key.pem \
62 -e CONFIG_MODULE_SIG_KEY_TYPE_RSA \
63 -e CONFIG_MODULE_SIG_SHA512 \
64 -d CONFIG_MEMCG_DISABLED \
65 -e CONFIG_MEMCG_SWAP_ENABLED \
66 -e CONFIG_HYPERV \
67 -m CONFIG_VFIO_IOMMU_TYPE1 \
68 -m CONFIG_VFIO_VIRQFD \
69 -m CONFIG_VFIO \
70 -m CONFIG_VFIO_PCI \
71 -m CONFIG_USB_XHCI_HCD \
72 -m CONFIG_USB_XHCI_PCI \
73 -m CONFIG_USB_EHCI_HCD \
74 -m CONFIG_USB_EHCI_PCI \
75 -m CONFIG_USB_EHCI_HCD_PLATFORM \
76 -m CONFIG_USB_OHCI_HCD \
77 -m CONFIG_USB_OHCI_HCD_PCI \
78 -m CONFIG_USB_OHCI_HCD_PLATFORM \
79 -d CONFIG_USB_OHCI_HCD_SSB \
80 -m CONFIG_USB_UHCI_HCD \
81 -d CONFIG_USB_SL811_HCD_ISO \
82 -e CONFIG_MEMCG_KMEM \
83 -d CONFIG_DEFAULT_CFQ \
84 -e CONFIG_DEFAULT_DEADLINE \
85 -e CONFIG_MODVERSIONS \
86 -e CONFIG_ZSTD_COMPRESS \
87 -d CONFIG_DEFAULT_SECURITY_DAC \
88 -e CONFIG_DEFAULT_SECURITY_APPARMOR \
89 --set-str CONFIG_DEFAULT_SECURITY apparmor \
90 -e CONFIG_MODULE_ALLOW_BTF_MISMATCH \
91 -d CONFIG_UNWINDER_ORC \
92 -d CONFIG_UNWINDER_GUESS \
93 -e CONFIG_UNWINDER_FRAME_POINTER \
94 --set-str CONFIG_SYSTEM_TRUSTED_KEYS ""\
95 --set-str CONFIG_SYSTEM_REVOCATION_KEYS ""\
96 -e CONFIG_SECURITY_LOCKDOWN_LSM \
97 -e CONFIG_SECURITY_LOCKDOWN_LSM_EARLY \
98 --set-str CONFIG_LSM lockdown,yama,integrity,apparmor \
99 -e CONFIG_PAGE_TABLE_ISOLATION \
100 -e CONFIG_ARCH_HAS_CPU_FINALIZE_INIT \
101 -d CONFIG_GDS_FORCE_MITIGATION \
102
103 debian/control: $(wildcard debian/*.in)
104 sed -e 's/@@KVNAME@@/$(KVNAME)/g' < debian/proxmox-kernel.prerm.in > debian/$(PMX_KERNEL_PKG).prerm
105 sed -e 's/@@KVNAME@@/$(KVNAME)/g' < debian/proxmox-kernel.postrm.in > debian/$(PMX_KERNEL_PKG).postrm
106 sed -e 's/@@KVNAME@@/$(KVNAME)/g' < debian/proxmox-kernel.postinst.in > debian/$(PMX_KERNEL_PKG).postinst
107 sed -e 's/@@KVNAME@@/$(KVNAME)/g' < debian/proxmox-headers.postinst.in > debian/$(PMX_HEADER_PKG).postinst
108 sed -e 's/@@KVMAJMIN@@/$(KERNEL_MAJMIN)/g' -e 's/@@KVNAME@@/$(KVNAME)/g' < debian/proxmox-kernel-meta.postrm.in > debian/$(PMX_KERNEL_SERIES_PKG).postrm
109 sed -e 's/@@KVMAJMIN@@/$(KERNEL_MAJMIN)/g' -e 's/@@KVNAME@@/$(KVNAME)/g' < debian/proxmox-kernel-meta.postinst.in > debian/$(PMX_KERNEL_SERIES_PKG).postinst
110 chmod +x debian/$(PMX_KERNEL_PKG).prerm
111 chmod +x debian/$(PMX_KERNEL_PKG).postrm
112 chmod +x debian/$(PMX_KERNEL_PKG).postinst
113 chmod +x debian/$(PMX_KERNEL_SERIES_PKG).postrm
114 chmod +x debian/$(PMX_KERNEL_SERIES_PKG).postinst
115 chmod +x debian/$(PMX_HEADER_PKG).postinst
116 sed -e 's/@KVNAME@/$(KVNAME)/g' -e 's/@KVMAJMIN@/$(KERNEL_MAJMIN)/g' < debian/control.in > debian/control
117
118 build: .compile_mark .tools_compile_mark .modules_compile_mark
119
120 install: .install_mark .tools_install_mark .headers_install_mark .usr_headers_install_mark
121 dh_installdocs -A debian/copyright debian/SOURCE
122 dh_installchangelogs
123 dh_installman
124 dh_strip_nondeterminism
125 dh_compress
126 dh_fixperms
127
128 binary: install
129 debian/rules fwcheck abicheck
130 dh_strip -N$(PMX_HEADER_PKG) -N$(PMX_USR_HEADER_PKG)
131 dh_makeshlibs
132 dh_shlibdeps
133 dh_installdeb
134 dh_gencontrol
135 dh_md5sums
136 dh_builddeb
137
138 .config_mark:
139 cd $(KERNEL_SRC); scripts/config $(PMX_CONFIG_OPTS)
140 $(MAKE) -C $(KERNEL_SRC) oldconfig
141 # copy to allow building in parallel to kernel/module compilation without interference
142 rm -rf $(KERNEL_SRC_COPY)
143 cp -ar $(KERNEL_SRC) $(KERNEL_SRC_COPY)
144 touch $@
145
146 .compile_mark: .config_mark
147 $(MAKE) -C $(KERNEL_SRC) KBUILD_BUILD_VERSION_TIMESTAMP="PMX $(DEB_VERSION) ($(CHANGELOG_DATE_UTC_ISO))"
148 touch $@
149
150 .install_mark: .compile_mark .modules_compile_mark
151 rm -rf debian/$(PMX_KERNEL_PKG)
152 mkdir -p debian/$(PMX_KERNEL_PKG)/lib/modules/$(KVNAME)
153 mkdir debian/$(PMX_KERNEL_PKG)/boot
154 install -m 644 $(KERNEL_SRC)/.config debian/$(PMX_KERNEL_PKG)/boot/config-$(KVNAME)
155 install -m 644 $(KERNEL_SRC)/System.map debian/$(PMX_KERNEL_PKG)/boot/System.map-$(KVNAME)
156 install -m 644 $(KERNEL_SRC)/$(KERNEL_IMAGE_PATH) debian/$(PMX_KERNEL_PKG)/boot/$(KERNEL_INSTALL_FILE)-$(KVNAME)
157 $(MAKE) -C $(KERNEL_SRC) INSTALL_MOD_PATH=$(BUILD_DIR)/debian/$(PMX_KERNEL_PKG)/ modules_install
158 # install zfs drivers
159 install -d -m 0755 debian/$(PMX_KERNEL_PKG)/lib/modules/$(KVNAME)/zfs
160 install -m 644 $(MODULES)/zfs.ko $(MODULES)/spl.ko debian/$(PMX_KERNEL_PKG)/lib/modules/$(KVNAME)/zfs
161 # remove firmware
162 rm -rf debian/$(PMX_KERNEL_PKG)/lib/firmware
163
164 ifeq ($(filter pkg.proxmox-kernel.debug,$(DEB_BUILD_PROFILES)),)
165 echo "'pkg.proxmox-kernel.debug' build profile disabled, skipping -dbgsym creation"
166 else
167 echo "'pkg.proxmox-kernel.debug' build profile enabled, creating -dbgsym contents"
168 mkdir -p debian/$(PMX_DEBUG_KERNEL_PKG)/usr/lib/debug/lib/modules/$(KVNAME)
169 mkdir debian/$(PMX_DEBUG_KERNEL_PKG)/usr/lib/debug/boot
170 install -m 644 $(KERNEL_SRC)/vmlinux debian/$(PMX_DEBUG_KERNEL_PKG)/usr/lib/debug/boot/vmlinux-$(KVNAME)
171 cp -r debian/$(PMX_KERNEL_PKG)/lib/modules/$(KVNAME) debian/$(PMX_DEBUG_KERNEL_PKG)/usr/lib/debug/lib/modules/
172 rm -f debian/$(PMX_DEBUG_KERNEL_PKG)/usr/lib/debug/lib/modules/$(KVNAME)/source
173 rm -f debian/$(PMX_DEBUG_KERNEL_PKG)/usr/lib/debug/lib/modules/$(KVNAME)/build
174 rm -f debian/$(PMX_DEBUG_KERNEL_PKG)/usr/lib/debug/lib/modules/$(KVNAME)/modules.*
175 endif
176
177 # strip debug info
178 find debian/$(PMX_KERNEL_PKG)/lib/modules -name \*.ko -print | while read f ; do strip --strip-debug "$$f"; done
179
180 # sign modules using ephemeral, embedded key
181 if grep -q CONFIG_MODULE_SIG=y ubuntu-kernel/.config ; then \
182 find debian/$(PMX_KERNEL_PKG)/lib/modules -name \*.ko -print | while read f ; do \
183 ./ubuntu-kernel/scripts/sign-file sha512 ./ubuntu-kernel/certs/signing_key.pem ubuntu-kernel/certs/signing_key.x509 "$$f" ; \
184 done; \
185 rm ./ubuntu-kernel/certs/signing_key.pem ; \
186 fi
187 # finalize
188 /sbin/depmod -b debian/$(PMX_KERNEL_PKG)/ $(KVNAME)
189 # Autogenerate blacklist for watchdog devices (see README)
190 install -m 0755 -d debian/$(PMX_KERNEL_PKG)/lib/modprobe.d
191 ls debian/$(PMX_KERNEL_PKG)/lib/modules/$(KVNAME)/kernel/drivers/watchdog/ > watchdog-blacklist.tmp
192 echo ipmi_watchdog.ko >> watchdog-blacklist.tmp
193 cat watchdog-blacklist.tmp|sed -e 's/^/blacklist /' -e 's/.ko$$//'|sort -u > debian/$(PMX_KERNEL_PKG)/lib/modprobe.d/blacklist_$(PMX_KERNEL_PKG).conf
194 rm -f debian/$(PMX_KERNEL_PKG)/lib/modules/$(KVNAME)/source
195 rm -f debian/$(PMX_KERNEL_PKG)/lib/modules/$(KVNAME)/build
196 touch $@
197
198 .tools_compile_mark: .compile_mark
199 $(MAKE) -C $(KERNEL_SRC)/tools/perf prefix=/usr NO_LIBTRACEEVENT=1 HAVE_NO_LIBBFD=1 HAVE_CPLUS_DEMANGLE_SUPPORT=1 NO_LIBPYTHON=1 NO_LIBPERL=1 NO_LIBCRYPTO=1 PYTHON=python3
200 echo "checking GPL-2 only perf binary for library linkage with incompatible licenses.."
201 ! ldd $(KERNEL_SRC)/tools/perf/perf | grep -q -E '\blibbfd'
202 ! ldd $(KERNEL_SRC)/tools/perf/perf | grep -q -E '\blibcrypto'
203 $(MAKE) -C $(KERNEL_SRC)/tools/perf NO_LIBTRACEEVENT=1 man
204 touch $@
205
206 .tools_install_mark: .tools_compile_mark
207 rm -rf debian/$(LINUX_TOOLS_PKG)
208 mkdir -p debian/$(LINUX_TOOLS_PKG)/usr/bin
209 mkdir -p debian/$(LINUX_TOOLS_PKG)/usr/share/man/man1
210 install -m 755 $(BUILD_DIR)/$(KERNEL_SRC)/tools/perf/perf debian/$(LINUX_TOOLS_PKG)/usr/bin/perf_$(KERNEL_MAJMIN)
211 for i in $(BUILD_DIR)/$(KERNEL_SRC)/tools/perf/Documentation/*.1; do \
212 fname="$${i##*/}"; manname="$${fname%.1}"; \
213 install -m644 "$$i" "debian/$(LINUX_TOOLS_PKG)/usr/share/man/man1/$${manname}_$(KERNEL_MAJMIN).1"; \
214 done
215 touch $@
216
217 .headers_prepare_mark: .config_mark
218 rm -rf debian/$(PMX_HEADER_PKG)
219 mkdir -p debian/$(PMX_HEADER_PKG)/usr/src/linux-headers-$(KVNAME)
220 install -m 0644 $(KERNEL_SRC)/.config debian/$(PMX_HEADER_PKG)/usr/src/linux-headers-$(KVNAME)
221 make -C $(KERNEL_SRC_COPY) mrproper
222 cd $(KERNEL_SRC_COPY); find . -path './debian/*' -prune \
223 -o -path './include/*' -prune \
224 -o -path './Documentation' -prune \
225 -o -path './scripts' -prune \
226 -o -type f \
227 \( \
228 -name 'Makefile*' \
229 -o -name 'Kconfig*' \
230 -o -name 'Kbuild*' \
231 -o -name '*.sh' \
232 -o -name '*.pl' \
233 \) \
234 -print | cpio -pd --preserve-modification-time $(BUILD_DIR)/debian/$(PMX_HEADER_PKG)/usr/src/linux-headers-$(KVNAME)
235 cd $(KERNEL_SRC_COPY); \
236 ( \
237 find arch/$(KERNEL_HEADER_ARCH) -name include -type d -print | \
238 xargs -n1 -i: find : -type f \
239 ) | \
240 cpio -pd --preserve-modification-time $(BUILD_DIR)/debian/$(PMX_HEADER_PKG)/usr/src/linux-headers-$(KVNAME)
241 touch $@
242
243 .headers_compile_mark: .headers_prepare_mark
244 # set output to subdir of source to reduce number of hardcoded paths in output files
245 rm -rf $(BUILD_DIR)/$(KERNEL_SRC_COPY)/$(PMX_HEADER_PKG)
246 mkdir -p $(BUILD_DIR)/$(KERNEL_SRC_COPY)/$(PMX_HEADER_PKG)
247 cp $(KERNEL_SRC)/.config $(BUILD_DIR)/$(KERNEL_SRC_COPY)/$(PMX_HEADER_PKG)/.config
248 $(MAKE) -C $(KERNEL_SRC_COPY) O=$(BUILD_DIR)/$(KERNEL_SRC_COPY)/$(PMX_HEADER_PKG) -j1 syncconfig modules_prepare prepare scripts
249 cd $(KERNEL_SRC_COPY); cp -a include scripts $(BUILD_DIR)/debian/$(PMX_HEADER_PKG)/usr/src/linux-headers-$(KVNAME)
250 find $(BUILD_DIR)/$(KERNEL_SRC_COPY)/$(PMX_HEADER_PKG) -name \*.o.ur-\* -o -name '*.cmd' | xargs rm -f
251 rsync --ignore-existing -r -v -a $(addprefix $(BUILD_DIR)/$(KERNEL_SRC_COPY)/$(PMX_HEADER_PKG)/,arch include kernel scripts tools) $(BUILD_DIR)/debian/$(PMX_HEADER_PKG)/usr/src/linux-headers-$(KVNAME)/
252 rm -rf $(BUILD_DIR)/$(KERNEL_SRC_COPY)
253 touch $@
254
255 .headers_install_mark: .compile_mark .modules_compile_mark .headers_compile_mark
256 cp $(KERNEL_SRC)/include/generated/compile.h debian/$(PMX_HEADER_PKG)/usr/src/linux-headers-$(KVNAME)/include/generated/compile.h
257 install -m 0644 $(KERNEL_SRC)/Module.symvers debian/$(PMX_HEADER_PKG)/usr/src/linux-headers-$(KVNAME)
258 mkdir -p debian/$(PMX_HEADER_PKG)/lib/modules/$(KVNAME)
259 ln -sf /usr/src/linux-headers-$(KVNAME) debian/$(PMX_HEADER_PKG)/lib/modules/$(KVNAME)/build
260 touch $@
261
262 .usr_headers_install_mark: PKG_DIR = debian/$(PMX_USR_HEADER_PKG)
263 .usr_headers_install_mark: OUT_DIR = $(PKG_DIR)/usr
264 .usr_headers_install_mark: .config_mark
265 rm -rf '$(PKG_DIR)'
266 mkdir -p '$(PKG_DIR)'
267 $(MAKE) -C $(KERNEL_SRC) headers_install ARCH=$(KERNEL_HEADER_ARCH) INSTALL_HDR_PATH='$(CURDIR)'/$(OUT_DIR)
268 rm -rf $(OUT_DIR)/include/drm $(OUT_DIR)/include/scsi
269 find $(OUT_DIR)/include \( -name .install -o -name ..install.cmd \) -execdir rm {} +
270
271 # Move include/asm to arch-specific directory
272 mkdir -p $(OUT_DIR)/include/$(DEB_HOST_MULTIARCH)
273 mv $(OUT_DIR)/include/asm $(OUT_DIR)/include/$(DEB_HOST_MULTIARCH)/
274 test ! -d $(OUT_DIR)/include/arch || \
275 mv $(OUT_DIR)/include/arch $(OUT_DIR)/include/$(DEB_HOST_MULTIARCH)/
276 touch $@
277
278 .modules_compile_mark: $(MODULES)/zfs.ko
279 touch $@
280
281 $(MODULES)/zfs.ko: .compile_mark
282 cd $(MODULES)/$(ZFSDIR); ./autogen.sh
283 cd $(MODULES)/$(ZFSDIR); ./configure --with-config=kernel --with-linux=$(BUILD_DIR)/$(KERNEL_SRC) --with-linux-obj=$(BUILD_DIR)/$(KERNEL_SRC)
284 $(MAKE) -C $(MODULES)/$(ZFSDIR)
285 cp $(MODULES)/$(ZFSDIR)/module/zfs.ko $(MODULES)/
286 cp $(MODULES)/$(ZFSDIR)/module/spl.ko $(MODULES)/
287
288 fwlist-$(KVNAME): .compile_mark .modules_compile_mark
289 debian/scripts/find-firmware.pl debian/$(PMX_KERNEL_PKG)/lib/modules/$(KVNAME) >fwlist.tmp
290 mv fwlist.tmp $@
291
292 .PHONY: fwcheck
293 fwcheck: fwlist-$(KVNAME) fwlist-previous
294 @echo "checking fwlist for changes since last built firmware package.."
295 @echo "if this check fails, add fwlist-$(KVNAME) to the pve-firmware repository and upload a new firmware package together with the $(KVNAME) kernel"
296 sort fwlist-previous | uniq > fwlist-previous.sorted
297 sort fwlist-$(KVNAME) | uniq > fwlist-$(KVNAME).sorted
298 diff -up -N fwlist-previous.sorted fwlist-$(KVNAME).sorted > fwlist.diff
299 rm fwlist.diff fwlist-previous.sorted fwlist-$(KVNAME).sorted
300 @echo "done, no need to rebuild pve-firmware"
301
302
303 abi-$(KVNAME): .compile_mark
304 debian/scripts/abi-generate debian/$(PMX_HEADER_PKG)/usr/src/linux-headers-$(KVNAME)/Module.symvers abi-$(KVNAME) $(KVNAME)
305
306 .PHONY: abicheck
307 abicheck: debian/scripts/abi-check abi-$(KVNAME) abi-prev-* abi-blacklist
308 debian/scripts/abi-check abi-$(KVNAME) abi-prev-* $(SKIPABI)
309
310 .PHONY: clean