Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
61 commits
Select commit Hold shift + click to select a range
e2d02d6
Switch to building a Trixie base image
saiarcot895 Jun 11, 2025
ca74b19
Update some userspace tools to Trixie versions
saiarcot895 Jun 11, 2025
51667fb
Update systemd-sonic-generator to make it work on Trixie
saiarcot895 Jun 11, 2025
20fd5bf
Update Linux kernel to 6.12.30
saiarcot895 Jun 18, 2025
2644efb
Specify the libyang-frr dependency only for Bookworm
saiarcot895 Jun 18, 2025
bd21bc4
Build libpcre3 for libyang
saiarcot895 Jun 30, 2025
bb20620
Loosen help text check, as it might change depending on versions
saiarcot895 Jul 11, 2025
145bf5a
Update sonic-py-common tests and ignore failing test
saiarcot895 Jul 14, 2025
566db33
Allow newer versions of lxml and pyyaml to be used for config-engine
saiarcot895 Jul 14, 2025
9de11b7
Update FIPS for Trixie
saiarcot895 Jul 14, 2025
81c576e
Disable cgroups v1
saiarcot895 Jul 14, 2025
bd1e423
Fix scripts for Python 3.13
saiarcot895 Jul 15, 2025
65c0351
Switch to using Boost 1.83 for Bookworm
saiarcot895 Jul 24, 2025
0d2849a
Recreate all version control files from scratch
saiarcot895 Jul 25, 2025
72f5557
Use pam_systemd for user session management
saiarcot895 Jul 29, 2025
b08c19b
Fix FIPS build issue on trixie (#28)
liuh-80 Jul 31, 2025
bd71538
[nokia bcm platform] trixie support (#29)
jon-nokia Aug 14, 2025
e36ba5f
Upgrade to Rust 1.86 for Trixie
saiarcot895 Aug 19, 2025
40e5801
Start updating the build rules for platform modules and fix some of t…
saiarcot895 Sep 8, 2025
1172f48
saibcm-modules trixie support (#30)
jon-nokia Aug 31, 2025
0db7389
Fix tacacs build issue on trixie (#33)
liuh-80 Sep 15, 2025
8c0ca76
Clear out resolv.conf
saiarcot895 Sep 22, 2025
82b6e42
dell trixie changes (#36)
rohinikumart Sep 25, 2025
f426698
Nexthop modules: Support kernel 6.12 (#37)
nate-nexthop Oct 3, 2025
cf91987
[Arista] Update platform library submodules (#42)
byu343 Oct 19, 2025
8011466
Fix the apt package install abort because of missing -y (#40)
tirupatihemanth Oct 19, 2025
7002b07
Add immediate variable expansion to makefile to fix slowness (#51)
tirupatihemanth Oct 31, 2025
7f58104
[marvell-teralynx] Add Trixie support (#43)
pavannaregundi Oct 20, 2025
b3e7f98
Update RADIUS build for Trixie
saiarcot895 Oct 26, 2025
0bfdf72
[marvell-prestera] add Nokia support on trixie (#44)
yanmarkman Oct 28, 2025
20cd939
platform-modules-cel: adapt for kernel 6.12 and trixie (#46)
rchandramouli Oct 29, 2025
8d34e7a
Update hw-mgmt and sdk automatic integration for Trixie (#47)
tirupatihemanth Oct 31, 2025
83a4d7b
Try to fix UEFI boot issue (#49)
tirupatihemanth Oct 31, 2025
0622968
[Mellanox] Fix ISSU and Mellanox Platform API (#53)
tirupatihemanth Oct 31, 2025
1ef4932
Update hsFlowd to close the pipe immediately (#50)
tirupatihemanth Oct 31, 2025
94a430f
Fix trixie signing (#52)
tirupatihemanth Oct 31, 2025
dce4f58
Update monit to 5.34
saiarcot895 Nov 3, 2025
87b1ae0
[#24386] rsyslog: restore kernel timestamp in the /dev/kmsg logs (#56)
rchandramouli Nov 6, 2025
404abc1
[Debian 13] [Mellanox] Fix Rshim and Linux Kbuild (#61)
tirupatihemanth Nov 8, 2025
492aba2
Secureboot fixes (#62)
bhouse-nexthop Nov 8, 2025
4830da5
marvell-prestera nokia update trixie (#65)
yanmarkman Nov 14, 2025
d5e529a
[Mellanox] Remove Linux Kbuild dependency and Fix Component Versions …
tirupatihemanth Nov 16, 2025
dd96896
Locally compile grub2 2.06 from Debian Bookworm for Trixie
saiarcot895 Nov 16, 2025
94a6d09
[ufispace] Update platform build rules and kernel module to support D…
nonodark Nov 17, 2025
2df2a16
Disable Buster build, it's no longer needed
saiarcot895 Nov 18, 2025
32934b4
Marvell-prestera SAI version 1.16.1-3 (#73)
yanmarkman Nov 20, 2025
cdff468
marvell-prestera: fix script nokia-7215init.sh (#74)
yanmarkman Nov 20, 2025
08f4d4d
[nvidia-bluefield] Fix OFED compilation failure in latest NASA (#75)
tirupatihemanth Nov 21, 2025
29ddaf0
[Mellanox] Add platform support for Trixie (#77)
tirupatihemanth Nov 22, 2025
b84dbdb
[Nvidia-Bluefield] Add platform support for Trixie (#78)
tirupatihemanth Nov 22, 2025
82ee9ac
fixup! Fix scripts for Python 3.13
saiarcot895 Nov 23, 2025
d7075c0
Fix the build failure
vivekverma-arista Nov 23, 2025
1e68e95
Update dplane_fpm_sonic.c
vivekverma-arista Nov 23, 2025
5574718
Revert "Support for single ASIC VOQ Fixed-Systems (#24163)"
saiarcot895 Nov 23, 2025
b705640
fixup! Fix scripts for Python 3.13
saiarcot895 Nov 23, 2025
fda319c
Fix prod build Makefile.work (#79)
tirupatihemanth Nov 25, 2025
1452668
Revert "[Mellanox] Stop SDK health monitor before syncd shutdown (#23…
tirupatihemanth Oct 22, 2025
3d2f56a
Fix Prod Build
tirupatihemanth Nov 22, 2025
2d66ab5
[Debian 13] temporary commit for build in developer repo
tirupatihemanth Nov 19, 2025
9fc60dd
Update SDK 4.8.2066 -> 4.8.2096 and FW 2016.2066 -> 2016.2096
tirupatihemanth Dec 4, 2025
12606e7
Add check for dash-ha service
croos12 Dec 18, 2025
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
2 changes: 1 addition & 1 deletion .azure-pipelines/template-variables.yml
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
variables:
DEFAULT_CONTAINER_REGISTRY: 'publicmirror.azurecr.io'
COMMON_LIB_BUILD_ENVS: 'bookworm'
COMMON_LIB_BUILD_ENVS: 'bookworm trixie'
SONIC_SLAVE_DOCKER_DRIVER: 'overlay2'
SONIC_BUILD_RETRY_COUNT: 3
SONIC_BUILD_RETRY_INTERVAL: 600
Expand Down
6 changes: 3 additions & 3 deletions .gitmodules
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@
url = https://github.com/sonic-net/sonic-linux-kernel
[submodule "sonic-sairedis"]
path = src/sonic-sairedis
url = https://github.com/sonic-net/sonic-sairedis
url = https://github.com/tirupatihemanth/sonic-sairedis
[submodule "sonic-swss"]
path = src/sonic-swss
url = https://github.com/sonic-net/sonic-swss
Expand Down Expand Up @@ -36,7 +36,7 @@
url = https://github.com/aristanetworks/sonic
[submodule "src/sonic-platform-common"]
path = src/sonic-platform-common
url = https://github.com/sonic-net/sonic-platform-common
url = https://github.com/tirupatihemanth/sonic-platform-common
[submodule "src/sonic-platform-daemons"]
path = src/sonic-platform-daemons
url = https://github.com/sonic-net/sonic-platform-daemons
Expand Down Expand Up @@ -117,7 +117,7 @@
url = https://github.com/sonic-net/sonic-dhcpmon.git
[submodule "src/sonic-dash-api"]
path = src/sonic-dash-api
url = https://github.com/sonic-net/sonic-dash-api.git
url = https://github.com/tirupatihemanth/sonic-dash-api.git
[submodule "src/sonic-dash-ha"]
path = src/sonic-dash-ha
url = https://github.com/sonic-net/sonic-dash-ha
Expand Down
8 changes: 4 additions & 4 deletions Makefile
Original file line number Diff line number Diff line change
Expand Up @@ -2,10 +2,10 @@

NOJESSIE ?= 1
NOSTRETCH ?= 1
NOBUSTER ?= 0
NOBUSTER ?= 1
NOBULLSEYE ?= 0
NOBOOKWORM ?= 0
NOTRIXIE ?= 1
NOTRIXIE ?= 0

override Q := @
ifeq ($(QUIET),n)
Expand Down Expand Up @@ -60,10 +60,10 @@ ifeq ($(NOBULLSEYE), 0)
$(MAKE_WITH_RETRY) EXTRA_DOCKER_TARGETS=$(notdir $@) BLDENV=bullseye -f Makefile.work bullseye
endif
ifeq ($(NOBOOKWORM), 0)
$(MAKE_WITH_RETRY) BLDENV=bookworm -f Makefile.work $@
$(MAKE_WITH_RETRY) EXTRA_DOCKER_TARGETS=$(notdir $@) BLDENV=bookworm -f Makefile.work bookworm
endif
ifeq ($(NOTRIXIE), 0)
$(MAKE_WITH_RETRY) BLDENV=trixie -f Makefile.work trixie
$(MAKE_WITH_RETRY) BLDENV=trixie -f Makefile.work $@
endif

BLDENV=bookworm $(MAKE) -f Makefile.work docker-cleanup
Expand Down
12 changes: 9 additions & 3 deletions Makefile.work
Original file line number Diff line number Diff line change
Expand Up @@ -72,9 +72,9 @@ USER := $(shell id -un)
PWD := $(shell realpath $(shell pwd))
USER_LC := $(shell echo $(USER) | tr A-Z a-z)
ifneq ($(DEFAULT_CONTAINER_REGISTRY),)
DOCKER_MACHINE := $(shell docker run --rm $(DEFAULT_CONTAINER_REGISTRY)/debian:buster uname -m)
DOCKER_MACHINE := $(shell docker run --rm $(DEFAULT_CONTAINER_REGISTRY)/debian:trixie uname -m)
else
DOCKER_MACHINE := $(shell docker run --rm debian:buster uname -m)
DOCKER_MACHINE := $(shell docker run --rm debian:trixie uname -m)
endif
HOST_DOCKERD_GID := $(shell getent group docker | cut -d : -f3)

Expand Down Expand Up @@ -217,6 +217,7 @@ $(shell CONFIGURED_ARCH=$(CONFIGURED_ARCH) \
DOCKER_EXTRA_OPTS=$(DOCKER_EXTRA_OPTS) \
DEFAULT_CONTAINER_REGISTRY=$(DEFAULT_CONTAINER_REGISTRY) \
FIPS_VERSION=$(FIPS_VERSION) \
FIPS_GOLANG_MAIN_VERSION=$(FIPS_GOLANG_MAIN_VERSION) \
FIPS_GOLANG_VERSION=$(FIPS_GOLANG_VERSION) \
j2 $(SLAVE_DIR)/Dockerfile.j2 > $(SLAVE_DIR)/Dockerfile)

Expand Down Expand Up @@ -342,6 +343,11 @@ ifneq ($(SECURE_UPGRADE_PROD_SIGNING_TOOL),)
DOCKER_RUN += -v $(SECURE_UPGRADE_PROD_SIGNING_TOOL):/sonic/scripts/$(shell basename -- $(SECURE_UPGRADE_PROD_SIGNING_TOOL)):ro
endif

# Pass the Signing prod tool arguments as environment variable to avoid make command-line parsing issues
ifneq ($(SECURE_UPGRADE_PROD_TOOL_ARGS),)
DOCKER_RUN += -e "SECURE_UPGRADE_PROD_TOOL_ARGS=$(SECURE_UPGRADE_PROD_TOOL_ARGS)"
endif

ifneq ($(SONIC_DPKG_CACHE_SOURCE),)
DOCKER_RUN += -v "$(SONIC_DPKG_CACHE_SOURCE):/dpkg_cache:rw"
endif
Expand Down Expand Up @@ -560,7 +566,6 @@ SONIC_BUILD_INSTRUCTION := $(MAKE) \
SECURE_UPGRADE_SIGNING_CERT=$(SECURE_UPGRADE_SIGNING_CERT) \
SECURE_UPGRADE_KERNEL_CAFILE=$(SECURE_UPGRADE_KERNEL_CAFILE) \
SECURE_UPGRADE_PROD_SIGNING_TOOL=$(SECURE_UPGRADE_PROD_SIGNING_TOOL) \
SECURE_UPGRADE_PROD_TOOL_ARGS="\"'$(SECURE_UPGRADE_PROD_TOOL_ARGS)'\"" \
SONIC_DEFAULT_CONTAINER_REGISTRY=$(DEFAULT_CONTAINER_REGISTRY) \
ENABLE_HOST_SERVICE_ON_START=$(ENABLE_HOST_SERVICE_ON_START) \
SLAVE_DIR=$(SLAVE_DIR) \
Expand Down Expand Up @@ -605,6 +610,7 @@ export MIRROR_SECURITY_URLS
export MIRROR_SNAPSHOT
export SONIC_VERSION_CONTROL_COMPONENTS
export PIP_HTTP_TIMEOUT
export SECURE_UPGRADE_PROD_TOOL_ARGS

%:: | sonic-build-hooks
ifneq ($(filter y, $(MULTIARCH_QEMU_ENVIRON) $(CROSS_BUILD_ENVIRON)),)
Expand Down
92 changes: 39 additions & 53 deletions build_debian.sh
Original file line number Diff line number Diff line change
Expand Up @@ -31,9 +31,9 @@ set -x -e
CONFIGURED_ARCH=$([ -f .arch ] && cat .arch || echo amd64)

## docker engine version (with platform)
DOCKER_VERSION=5:24.0.2-1~debian.12~$IMAGE_DISTRO
CONTAINERD_IO_VERSION=1.6.21-1
LINUX_KERNEL_VERSION=6.1.0-29-2
DOCKER_VERSION=5:28.2.2-1~debian.13~$IMAGE_DISTRO
CONTAINERD_IO_VERSION=1.7.27-1
LINUX_KERNEL_VERSION=6.12.41+deb13

## Working directory to prepare the file system
FILESYSTEM_ROOT=./fsroot
Expand Down Expand Up @@ -135,20 +135,12 @@ echo 'Dir::Bin::dpkg "/usr/local/bin/dpkg";' | sudo tee $FILESYSTEM_ROOT/etc/apt
sudo LANG=C chroot $FILESYSTEM_ROOT rm /usr/local/sbin/dpkg -f

echo '[INFO] Install packages for building image'
sudo LANG=C chroot $FILESYSTEM_ROOT apt-get -y install makedev psmisc
sudo LANG=C chroot $FILESYSTEM_ROOT apt-get -y install psmisc

if [[ $CROSS_BUILD_ENVIRON == y ]]; then
sudo LANG=C chroot $FILESYSTEM_ROOT dpkg --add-architecture $CONFIGURED_ARCH
fi

## Create device files
echo '[INFO] MAKEDEV'
if [[ $CONFIGURED_ARCH == armhf || $CONFIGURED_ARCH == arm64 ]]; then
sudo LANG=C chroot $FILESYSTEM_ROOT /bin/bash -c 'cd /dev && MAKEDEV generic-arm'
else
sudo LANG=C chroot $FILESYSTEM_ROOT /bin/bash -c 'cd /dev && MAKEDEV generic'
fi

## docker and mkinitramfs on target system will use pigz/unpigz automatically
sudo LANG=C chroot $FILESYSTEM_ROOT apt-get -y install pigz

Expand All @@ -173,6 +165,9 @@ fi
## Update initramfs for booting with squashfs+overlay
cat files/initramfs-tools/modules | sudo tee -a $FILESYSTEM_ROOT/etc/initramfs-tools/modules > /dev/null

## Install kbuild for sign-file into docker image (not fsroot)
sudo LANG=C DEBIAN_FRONTEND=noninteractive apt -y --allow-downgrades install ./$debs_path/linux-kbuild-${LINUX_KERNEL_VERSION}*_${CONFIGURED_ARCH}.deb

## Hook into initramfs: change fs type from vfat to ext4 on arista switches
sudo mkdir -p $FILESYSTEM_ROOT/etc/initramfs-tools/scripts/init-premount/
sudo cp files/initramfs-tools/arista-convertfs $FILESYSTEM_ROOT/etc/initramfs-tools/scripts/init-premount/arista-convertfs
Expand Down Expand Up @@ -311,7 +306,8 @@ sudo LANG=C chroot $FILESYSTEM_ROOT usermod -aG redis $USERNAME
if [[ $CONFIGURED_ARCH == amd64 ]]; then
## Pre-install hardware drivers
sudo LANG=C chroot $FILESYSTEM_ROOT apt-get -y install \
firmware-linux-nonfree
firmware-linux-nonfree \
firmware-intel-misc
fi

## Pre-install the fundamental packages
Expand Down Expand Up @@ -344,13 +340,16 @@ sudo LANG=C DEBIAN_FRONTEND=noninteractive chroot $FILESYSTEM_ROOT apt-get -y in
pciutils \
iptables-persistent \
ebtables \
linux-sysctl-defaults \
logrotate \
curl \
kexec-tools \
less \
unzip \
fdisk \
gdisk \
sysfsutils \
e2fsprogs \
squashfs-tools \
$bootloader_packages \
rsyslog \
Expand All @@ -365,15 +364,13 @@ sudo LANG=C DEBIAN_FRONTEND=noninteractive chroot $FILESYSTEM_ROOT apt-get -y in
makedumpfile \
conntrack \
python3 \
python3-distutils \
python3-pip \
python-is-python3 \
cron \
libprotobuf32 \
libgrpc29 \
libgrpc++1.51 \
libprotobuf32t64 \
libgrpc29t64 \
libgrpc++1.51t64 \
haveged \
fdisk \
gpg \
dmidecode \
jq \
Expand Down Expand Up @@ -447,16 +444,19 @@ sudo LANG=C DEBIAN_FRONTEND=noninteractive chroot $FILESYSTEM_ROOT apt-get -y in
chrony

if [[ $TARGET_BOOTLOADER == grub ]]; then
sudo cp $debs_path/grub-common*.deb $debs_path/grub2-common*.deb $FILESYSTEM_ROOT
basename_deb_packages=$(basename -a $debs_path/grub-common*.deb $debs_path/grub2-common*.deb | sed 's,^,./,')
sudo LANG=C DEBIAN_FRONTEND=noninteractive chroot $FILESYSTEM_ROOT apt -y --allow-downgrades install $basename_deb_packages
sudo rm $FILESYSTEM_ROOT/grub-common*.deb $FILESYSTEM_ROOT/grub2-common*.deb
( cd $FILESYSTEM_ROOT; sudo rm -f $basename_deb_packages )

if [[ $CONFIGURED_ARCH == amd64 ]]; then
GRUB_PKG=grub-pc-bin
elif [[ $CONFIGURED_ARCH == arm64 ]]; then
GRUB_PKG=grub-efi-arm64-bin
fi

sudo LANG=C DEBIAN_FRONTEND=noninteractive chroot $FILESYSTEM_ROOT apt-get install -d -o dir::cache=/var/cache/apt \
$GRUB_PKG

sudo cp $FILESYSTEM_ROOT/var/cache/apt/archives/grub*.deb $FILESYSTEM_ROOT/$PLATFORM_DIR/grub
sudo cp $debs_path/${GRUB_PKG}*.deb $FILESYSTEM_ROOT/$PLATFORM_DIR/grub
fi

## Disable kexec supported reboot which was installed by default
Expand Down Expand Up @@ -502,6 +502,9 @@ EOF
sudo sed -i 's/^#ListenAddress 0.0.0.0/ListenAddress 0.0.0.0/' $FILESYSTEM_ROOT/etc/ssh/sshd_config
sudo sed -i 's/^#ListenAddress ::/ListenAddress ::/' $FILESYSTEM_ROOT/etc/ssh/sshd_config

# Use libpam_systemd, since that's now needed for limiting login sessions
sudo LANG=C DEBIAN_FRONTEND=noninteractive chroot $FILESYSTEM_ROOT apt-get -y install libpam-systemd

## Config rsyslog
sudo augtool -r $FILESYSTEM_ROOT --autosave "
rm /files/lib/systemd/system/rsyslog.service/Service/ExecStart/arguments
Expand All @@ -510,23 +513,7 @@ set /files/lib/systemd/system/rsyslog.service/Service/ExecStart/arguments/1 -n

sudo mkdir -p $FILESYSTEM_ROOT/var/core

# Config sysctl
sudo augtool --autosave "
set /files/etc/sysctl.conf/kernel.core_pattern '|/usr/local/bin/coredump-compress %e %t %p %P'
set /files/etc/sysctl.conf/kernel.softlockup_panic 1
set /files/etc/sysctl.conf/kernel.panic 10
set /files/etc/sysctl.conf/kernel.hung_task_timeout_secs 300
set /files/etc/sysctl.conf/vm.panic_on_oom 2
set /files/etc/sysctl.conf/fs.suid_dumpable 2
" -r $FILESYSTEM_ROOT

sysctl_net_cmd_string=""
while read line; do
[[ "$line" =~ ^#.*$ ]] && continue
sysctl_net_conf_key=`echo $line | awk -F '=' '{print $1}'`
sysctl_net_conf_value=`echo $line | awk -F '=' '{print $2}'`
sysctl_net_cmd_string=$sysctl_net_cmd_string"set /files/etc/sysctl.conf/$sysctl_net_conf_key $sysctl_net_conf_value"$'\n'
done < files/image_config/sysctl/sysctl-net.conf
sudo cp files/image_config/sysctl/90-sonic.conf $FILESYSTEM_ROOT/usr/lib/sysctl.d/

sudo augtool --autosave "$sysctl_net_cmd_string" -r $FILESYSTEM_ROOT

Expand All @@ -540,7 +527,7 @@ sudo LANG=C DEBIAN_FRONTEND=noninteractive chroot $FILESYSTEM_ROOT apt-get -y in
sudo https_proxy=$https_proxy LANG=C chroot $FILESYSTEM_ROOT pip3 install 'docker==7.1.0'

# Install scapy
sudo https_proxy=$https_proxy LANG=C chroot $FILESYSTEM_ROOT pip3 install 'scapy==2.4.4'
sudo LANG=C DEBIAN_FRONTEND=noninteractive chroot $FILESYSTEM_ROOT apt-get -y install python3-scapy

## Note: keep pip installed for maintainance purpose

Expand All @@ -564,13 +551,6 @@ sudo cp files/dhcp/sethostname6 $FILESYSTEM_ROOT/etc/dhcp/dhclient-exit-hooks.d/
sudo cp files/dhcp/graphserviceurl $FILESYSTEM_ROOT/etc/dhcp/dhclient-exit-hooks.d/
sudo cp files/dhcp/snmpcommunity $FILESYSTEM_ROOT/etc/dhcp/dhclient-exit-hooks.d/
sudo cp files/dhcp/vrf $FILESYSTEM_ROOT/etc/dhcp/dhclient-exit-hooks.d/
if [ -f files/image_config/ntp/ntpsec ]; then
sudo cp ./files/image_config/ntp/ntpsec $FILESYSTEM_ROOT/etc/init.d/
fi

if [ -f files/image_config/ntp/ntp-systemd-wrapper ]; then
sudo cp ./files/image_config/ntp/ntp-systemd-wrapper $FILESYSTEM_ROOT/usr/libexec/ntpsec/
fi

## Version file part 1
sudo mkdir -p $FILESYSTEM_ROOT/etc/sonic
Expand Down Expand Up @@ -696,10 +676,14 @@ sudo LANG=C chroot $FILESYSTEM_ROOT /bin/bash -c "echo 0 > /etc/fips/fips_enable
if [[ $SECURE_UPGRADE_MODE == 'dev' || $SECURE_UPGRADE_MODE == "prod" ]]; then
echo "Secure Boot support build stage: Starting .."

sudo cp $debs_path/grub-efi*.deb $FILESYSTEM_ROOT
basename_deb_packages=$(basename -a $debs_path/grub-efi*.deb | sed 's,^,./,')
sudo LANG=C DEBIAN_FRONTEND=noninteractive chroot $FILESYSTEM_ROOT apt -y --allow-downgrades install $basename_deb_packages
sudo rm $FILESYSTEM_ROOT/grub-efi*.deb

# debian secure boot dependecies
sudo LANG=C DEBIAN_FRONTEND=noninteractive chroot $FILESYSTEM_ROOT apt-get -y install \
shim-unsigned \
grub-efi
shim-unsigned

if [ ! -f $SECURE_UPGRADE_SIGNING_CERT ]; then
echo "Error: SONiC SECURE_UPGRADE_SIGNING_CERT=$SECURE_UPGRADE_SIGNING_CERT key missing"
Expand Down Expand Up @@ -740,7 +724,7 @@ if [[ $SECURE_UPGRADE_MODE == 'dev' || $SECURE_UPGRADE_MODE == "prod" ]]; then
-k ${FILESYSTEM_ROOT}/usr/lib/modules

# verifying vmlinuz file.
sudo ./scripts/secure_boot_signature_verification.sh -e $FILESYSTEM_ROOT/boot/vmlinuz-${LINUX_KERNEL_VERSION}-${CONFIGURED_ARCH} \
sudo ./scripts/secure_boot_signature_verification.sh -e $FILESYSTEM_ROOT/boot/vmlinuz-${LINUX_KERNEL_VERSION}-sonic-${CONFIGURED_ARCH} \
-c $SECURE_UPGRADE_SIGNING_CERT
fi
echo "Secure Boot support build stage: END."
Expand All @@ -750,10 +734,10 @@ fi
sudo chroot $FILESYSTEM_ROOT update-initramfs -u
## Convert initrd image to u-boot format
if [[ $TARGET_BOOTLOADER == uboot ]]; then
INITRD_FILE=initrd.img-${LINUX_KERNEL_VERSION}-${CONFIGURED_ARCH}
KERNEL_FILE=vmlinuz-${LINUX_KERNEL_VERSION}-${CONFIGURED_ARCH}
INITRD_FILE=initrd.img-${LINUX_KERNEL_VERSION}-sonic-${CONFIGURED_ARCH}
KERNEL_FILE=vmlinuz-${LINUX_KERNEL_VERSION}-sonic-${CONFIGURED_ARCH}
if [[ $CONFIGURED_ARCH == armhf ]]; then
INITRD_FILE=initrd.img-${LINUX_KERNEL_VERSION}-armmp
INITRD_FILE=initrd.img-${LINUX_KERNEL_VERSION}-sonic-armmp
sudo LANG=C chroot $FILESYSTEM_ROOT mkimage -A arm -O linux -T ramdisk -C gzip -d /boot/$INITRD_FILE /boot/u${INITRD_FILE}
## Overwriting the initrd image with uInitrd
sudo LANG=C chroot $FILESYSTEM_ROOT mv /boot/u${INITRD_FILE} /boot/$INITRD_FILE
Expand Down Expand Up @@ -834,6 +818,8 @@ sudo mkdir -p $FILESYSTEM_ROOT/var/lib/docker
## Clear DNS configuration inherited from the build server
sudo rm -f $FILESYSTEM_ROOT/etc/resolvconf/resolv.conf.d/original
sudo cp files/image_config/resolv-config/resolv.conf.head $FILESYSTEM_ROOT/etc/resolvconf/resolv.conf.d/head
sudo rm -f $FILESYSTEM_ROOT/etc/resolv.conf
sudo touch $FILESYSTEM_ROOT/etc/resolv.conf

## Optimize filesystem size
if [ "$BUILD_REDUCE_IMAGE_SIZE" = "y" ]; then
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -6,6 +6,7 @@
"num_fans_pertray":1,
"num_ports":56,
"num_temps":4,
"num_components":1,
"pddf_dev_types":
{
"description":"DS1000 - Below is the list of supported PDDF device types (chip names) for various components. If any component uses some other driver, we will create the client using 'echo <dev-address> <dev-type> > <path>/new_device' method",
Expand Down
Loading