-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathinstall.sh
More file actions
executable file
·158 lines (141 loc) · 6.36 KB
/
Copy pathinstall.sh
File metadata and controls
executable file
·158 lines (141 loc) · 6.36 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
#!/usr/bin/env bash
# Helix Boot — build a fresh stick.
#
# ./install.sh pick a USB stick interactively
# ./install.sh /dev/sdX use that stick
# ./install.sh --from pack.zip fill it from a pack (`helix pack`), no downloads
#
# Everything is downloaded and verified BEFORE the stick is touched, and you
# must type the device name to confirm the wipe.
set -Eeuo pipefail
HERE=$(cd -- "$(dirname -- "${BASH_SOURCE[0]}")" && pwd)
# shellcheck source=scripts/common.sh
source "$HERE/scripts/common.sh"
trap on_err ERR
HELIX="$HERE/helix"
usage() {
cat <<EOF
Usage: ./install.sh [options] [/dev/sdX]
Installs Ventoy on a USB stick (ERASING it) and fills it with the tools
from tools.toml.
Options:
--mbr MBR partition table instead of GPT (very old BIOS machines)
--no-secure-boot don't add Ventoy's Secure Boot shim
--reserve MB leave MB of unallocated space at the end of the stick
--skip-fetch use what's already cached; don't check upstream
--from PACK use a pack made by "helix pack" instead of downloading
--list just list USB sticks and exit
-h, --help this help
EOF
}
gpt=1 secure=1 reserve='' skip_fetch=0 dev='' list_only=0 from=''
show_sticks() {
local i p s m
for i in "${!sticks[@]}"; do
IFS=$'\t' read -r p s m <<<"${sticks[$i]}"
printf ' %s%d)%s %-14s %8s %s\n' "$B" $((i + 1)) "$X" "$p" "$s" "$m"
done
}
while (($#)); do
case $1 in
--mbr) gpt=0 ;;
--no-secure-boot) secure=0 ;;
--reserve) reserve=${2:?--reserve needs a size in MB}; shift ;;
--skip-fetch) skip_fetch=1 ;;
--from) from=${2:?--from needs a pack .zip}; shift ;;
--list) list_only=1 ;;
-h|--help) usage; exit 0 ;;
/dev/*) dev=$1 ;;
*) usage; die "unknown option: $1" ;;
esac
shift
done
((list_only)) || banner "install"
check_python
[[ -n $from ]] || from=$(bundled_pack "$HERE")
need lsblk util-linux
need findmnt util-linux
if ((list_only)); then
mapfile -t sticks < <(usb_disks)
if ((${#sticks[@]})); then show_sticks; else info "no USB sticks found"; fi
exit 0
fi
[[ $EUID -ne 0 ]] || die "run this as your normal user — it asks for sudo only for the Ventoy step"
need sudo
((gpt)) && need parted # Ventoy can only make GPT sticks with parted
# ── 1. Download + verify everything first ────────────────────────────────
if [[ -n $from ]]; then
[[ -f $from ]] || die "can't find the pack $from"
from=$(realpath -- "$from")
info "using the pack $from (no downloads)"
elif ((skip_fetch)); then
"$HELIX" ventoy-path >/dev/null 2>&1 || "$HELIX" fetch ventoy
else
if ! "$HELIX" fetch; then
warn "some tools failed to download (listed above)."
read -rp "Continue with what was fetched? [y/N] " a
[[ ${a,,} == y* ]] || die "stopped — nothing was written to any disk"
fi
fi
if [[ -n $from ]]; then vdir=$("$HELIX" ventoy-path --from "$from"); else vdir=$("$HELIX" ventoy-path); fi
# ── 2. Pick the stick ────────────────────────────────────────────────────
mapfile -t sticks < <(usb_disks)
mapfile -t protected < <(system_disks)
if [[ -z $dev ]]; then
((${#sticks[@]})) || die "no USB sticks found. Plug one in, or pass the device path."
section "USB sticks"
show_sticks
read -rp "Which one? [1-${#sticks[@]}] " n
if ! [[ $n =~ ^[0-9]+$ ]] || ((n < 1 || n > ${#sticks[@]})); then die "not a choice: $n"; fi
dev=${sticks[$((n - 1))]%%$'\t'*}
fi
[[ -b $dev ]] || die "$dev isn't a block device"
[[ $(lsblk -dno TYPE "$dev") == disk ]] || die "$dev is a partition — pass the whole disk (e.g. /dev/sdb)"
for p in "${protected[@]}"; do
[[ $p == "$dev" ]] && die "$dev holds your running system. Refusing."
done
is_usb=0
for s in "${sticks[@]}"; do [[ ${s%%$'\t'*} == "$dev" ]] && is_usb=1; done
((is_usb)) || die "$dev isn't a USB/removable disk. Refusing (edit install.sh if you really mean it)."
# ── 3. Confirm ───────────────────────────────────────────────────────────
section "This will ERASE everything on:"
lsblk -o NAME,SIZE,FSTYPE,LABEL,MOUNTPOINTS "$dev" | sed 's/^/ /'
echo
bytes=$(lsblk -bdno SIZE "$dev")
((bytes < 300 * 1000 ** 3)) || warn "$dev is $(lsblk -dno SIZE "$dev") — bigger than most sticks. Is this an external drive with your backups on it?"
read -rp "Type ${B}$(basename "$dev")${X} to erase it: " typed
[[ $typed == "$(basename "$dev")" ]] || die "didn't match — nothing was changed"
# ── 4. Ventoy ────────────────────────────────────────────────────────────
while read -r part; do
[[ -n $part ]] && unmount_part "$part"
done < <(lsblk -lnpo NAME,TYPE "$dev" | awk '$2=="part"{print $1}')
flags=(-I)
label=$("$HELIX" setting stick_label) # the stick's name; Ventoy's own is "Ventoy"
[[ $label == Ventoy ]] || flags+=(-L "$label")
((gpt)) && flags+=(-g)
if ((secure)); then flags+=(-s); else flags+=(-S); fi
[[ -n $reserve ]] && flags+=(-r "$reserve")
want=$(basename "$vdir" | sed 's/^ventoy-//')
section "Installing Ventoy $want"
# Ventoy2Disk.sh asks "Continue?" twice; we've already confirmed above.
(cd "$vdir" && printf 'y\ny\n' | sudo ./Ventoy2Disk.sh "${flags[@]}" "$dev")
sudo udevadm settle 2>/dev/null || sleep 3
got=$(ventoy_info "$vdir" "$dev")
[[ ${got%%$'\t'*} == "$want" ]] || die "Ventoy didn't install on $dev — see $vdir/log.txt"
part=$(first_partition "$dev")
[[ -n $part ]] || die "can't find the Ventoy data partition on $dev"
mnt=$(mount_part "$part")
[[ -n $mnt ]] || die "couldn't mount $part"
ok "Ventoy installed, data partition mounted at $mnt"
# ── 5. Fill it ───────────────────────────────────────────────────────────
if [[ -n $from ]]; then
"$HELIX" unpack "$from" "$mnt" --init --verify
else
"$HELIX" sync "$mnt" --init --verify
fi
section "Finishing"
unmount_part "$part"
apply_splash "$dev"
ok "Done. You can unplug the stick."
((secure)) && info "First boot on a Secure Boot PC: pick 'Enroll key' → ENROLL_THIS_KEY_IN_MOKMANAGER.cer, then reboot."
info "Refresh it later with ./refresh.sh"