No description
make_rootfs wiped the rootfs with `rm -rf "$ROOT"` and no check on what was mounted under it. A diagnostic session had left `mount --rbind /dev "$ROOT/dev"` in place; the next run deleted straight through it into the real /dev. Every device node went -- zero, full, random, urandom, tty, console -- and /dev/null came back later as a regular file created by a redirection, which broke every `> /dev/null` on the machine and stopped the pass at its first pacman call. Two guards now, because unmounting alone is not enough: umount_chroot, then findmnt to CHECK, then refuse. A stale mount is a reason to stop, never a thing to delete through. /dev is also no longer written to at all. The bind became --rbind with --make-rslave, which brings the host's /dev/shm along as the tmpfs it already is -- so the separate tmpfs and the chmod that reached the host are both gone. That chmod was the reason this driver could touch /dev in the first place. The plain --bind was itself the original bug: it does not carry submounts, so the chroot saw /dev/shm as an empty 0755 stub, CPython's configure got EACCES from sem_open, and python was built without POSIX semaphores. --- FR --- make_rootfs effaçait le rootfs par `rm -rf "$ROOT"` sans vérifier ce qui était monté dessous. Une session de diagnostic avait laissé `mount --rbind /dev "$ROOT/dev"` en place ; l'exécution suivante a supprimé au travers, dans le /dev réel. Tous les nœuds de périphériques ont disparu — zero, full, random, urandom, tty, console — et /dev/null est revenu en fichier ordinaire créé par une redirection, ce qui a cassé tout `> /dev/null` sur la machine et arrêté la passe à son premier appel à pacman. Deux gardes désormais, car démonter ne suffit pas : umount_chroot, puis findmnt pour VÉRIFIER, puis refuser. Un montage résiduel est une raison de s'arrêter, jamais une chose à traverser. Et /dev n'est plus écrit du tout. Le bind devient --rbind avec --make-rslave, ce qui apporte le /dev/shm de l'hôte tel qu'il est déjà — un tmpfs — donc le tmpfs séparé et le chmod qui atteignait l'hôte disparaissent tous deux. Ce chmod était la raison pour laquelle ce pilote pouvait toucher /dev. Le --bind simple était lui-même le défaut d'origine : il ne porte pas les sous-montages, le chroot voyait donc /dev/shm comme une souche vide en 0755, le configure de CPython recevait EACCES de sem_open, et python était bâti sans sémaphores POSIX. Assisted-by: Claude Opus 5 |
||
|---|---|---|
| .github/workflows | ||
| arch-kernel | ||
| boot | ||
| patches | ||
| scripts | ||
| .env.example | ||
| .gitignore | ||
| CODEOWNERS | ||
| Containerfile | ||
| LICENSE | ||
| Makefile | ||
| README.md | ||
| RELAIS.md | ||
| TODO.md | ||
Arch Linux s390x
A port of Arch Linux to IBM s390x mainframe architecture with systemd support.
Boots a full Arch Linux system on IBM mainframes (or QEMU s390x emulation) using a hybrid build: cross-compilation for the kernel, native s390x compilation on z/VM for userspace.
Quick Start
make container # build dev container (first time)
cp .env.example .env # configure z/VM access
make all # build kernel + initramfs + systemd
make test-systemd # boot it
What Works
- Arch Linux kernel 6.18.6-arch1 with Arch patches, cross-compiled
- Initramfs via modified mkinitcpio
- Static busybox built natively on z/VM, 2.3MB
- Root filesystem with ext4, switch_root to real rootfs
- Systemd as PID 1
Pacman, bash, and GNU coreutils are not yet ported.
Build System
The build uses two tiers:
Cross-compilation (x86_64 host): Kernel is built in a Fedora 43 container with s390x-linux-gnu-gcc. Initramfs is generated with a patched mkinitcpio that handles cross-architecture binary injection.
Native compilation (s390x z/VM): Busybox and systemd must be built on real s390x hardware. The z/VM system runs RHEL 9.6 with GCC 11.5.0. Scripts handle SSH deployment and retrieval automatically via .env configuration.