mirror of
https://github.com/JasonN3/build-container-installer.git
synced 2025-12-25 10:57:55 +01:00
* feat: Allow users to override secure boot key and password when using container or action * fix: follow redirects * chore: update docs * fix: added comments and removed additional \n * fix: removed defaults * fix: added conditional for adding public key * chore(ci): Added additional test for secure boot * chore(ci): fixed up workflows to match production * fix(ci): added workflow dispatch to test * fix(ci): fixed version and added IMAGE_TAG * chore(ci): changed to bluefin to test both 38 and 39 secure boot * chore(ci): added required variables to entrypoint * chore(ci): added merge_group and added paths-ignore * chore(ci): updated description * chore(ci): set to Silverblue since we are testing Bluefin * chore(ci): Fixed secure boot key not found error Received error in anaconda when check was hit, need to set as a soft failure to exit the script early without stopping anaconda installation. * chore: fixed formatting * chore: fixed whitespace * chore(ci): Removed duplicate test * chore: fix whitespace * chore(ci): fixed test and removed upload to Github Artifacts * chore: updated README * fix: set password to ublue default * fix: changed enrollment password in containerfile
25 lines
665 B
Bash
Executable file
25 lines
665 B
Bash
Executable file
#!/bin/sh
|
|
|
|
set -oue pipefail
|
|
|
|
readonly ENROLLMENT_PASSWORD=@ENROLLMENT_PASSWORD@
|
|
readonly SECUREBOOT_KEY="/run/install/repo/sb_pubkey.der"
|
|
|
|
if [[ ! -d "/sys/firmware/efi" ]]; then
|
|
echo "EFI mode not detected. Skipping key enrollment."
|
|
exit 0
|
|
fi
|
|
|
|
if [[ ! -f "${SECUREBOOT_KEY}" ]]; then
|
|
echo "Secure boot key not provided: ${SECUREBOOT_KEY}"
|
|
exit 0
|
|
fi
|
|
|
|
SYS_ID="$(cat /sys/devices/virtual/dmi/id/product_name)"
|
|
if [[ ":Jupiter:Galileo:" =~ ":$SYS_ID:" ]]; then
|
|
echo "Steam Deck hardware detected. Skipping key enrollment."
|
|
exit 0
|
|
fi
|
|
|
|
mokutil --timeout -1 || :
|
|
echo -e "${ENROLLMENT_PASSWORD}\n${ENROLLMENT_PASSWORD}" | mokutil --import "${SECUREBOOT_KEY}" || :
|