feat(image): distro-agnostic remote unlock via initramfs backends + Debian support
Split the mkinitcpio-only remote-LUKS-unlock path into an InitramfsBackend ABC with a get_backend() dispatch, and add the initramfs-tools backend for Debian / Raspberry Pi OS. - base.py: six-step backend contract; encryption.py becomes a thin, distro-neutral sequencer (get_backend by distribution). - initramfs_tools.py: crypttab `none luks,initramfs`, cmdline rewritten to root=/dev/mapper + ip=::::host:eth0:dhcp, dropbear-initramfs authorized_keys, update-initramfs -k all (no build-host uname leak). - shipped hooks (configuration/initramfs-tools/*): single-hop non-anonymous onion, libnss DNS baking, sed-not-source DHCP, kill-tor-before-pivot. - shared offline onion keygen in keygen.py; tor.py removed (logic moved to mkinitcpio.py). - raspios added to the apt distro family (session.py, raspberry.py). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
21
lim/image/initramfs/__init__.py
Normal file
21
lim/image/initramfs/__init__.py
Normal file
@@ -0,0 +1,21 @@
|
||||
"""Distro-specific initramfs backends for encrypted remote unlock."""
|
||||
|
||||
from lim.errors import LimError
|
||||
from lim.image.initramfs.base import InitramfsBackend
|
||||
from lim.image.initramfs.initramfs_tools import InitramfsToolsBackend
|
||||
from lim.image.initramfs.mkinitcpio import MkinitcpioBackend
|
||||
|
||||
_MKINITCPIO = frozenset({"arch", "manjaro"})
|
||||
_INITRAMFS_TOOLS = frozenset({"raspios", "moode", "retropie"})
|
||||
|
||||
|
||||
def get_backend(distribution: str | None) -> InitramfsBackend:
|
||||
"""Pick the initramfs backend for a distribution's init system."""
|
||||
if distribution in _MKINITCPIO:
|
||||
return MkinitcpioBackend()
|
||||
if distribution in _INITRAMFS_TOOLS:
|
||||
return InitramfsToolsBackend()
|
||||
raise LimError(f"No initramfs backend for distribution {distribution!r}.")
|
||||
|
||||
|
||||
__all__ = ["InitramfsBackend", "get_backend"]
|
||||
Reference in New Issue
Block a user