#!/bin/bash # SPDX-Version: 3.0 # SPDX-CreationInfo: 2025-06-17; WEIDNER, Marc S.; # SPDX-ExternalRef: GIT https://git.coresecret.dev/msw/CISS.debian.installer.git # SPDX-FileContributor: WEIDNER, Marc S.; Centurion Intelligence Consulting Agency # SPDX-FileCopyrightText: 2024-2025; WEIDNER, Marc S.; # SPDX-FileType: SOURCE # SPDX-License-Identifier: EUPL-1.2 OR LicenseRef-CCLA-1.0 # SPDX-LicenseComment: This file is part of the CISS.debian.installer.secure framework. # SPDX-PackageName: CISS.debian.installer # SPDX-Security-Contact: security@coresecret.eu guard_sourcing ####################################### # Function to format the respective partition on each device according to the recipe string chosen. # Globals: # DIR_LOG # VAR_RECIPE_STRING # VAR_SETUP_PART # Arguments: # None ####################################### partition_formatting() { ### Declare Arrays and Variables. declare var_dev var_part \ var_encryption_enable var_encryption_label var_fs_btrfs_checksum var_fs_btrfs_compress var_fs_btrfs_dedup \ var_fs_format var_fs_label var_fs_options var_fs_version var_mount_path ### Iterate over all devices in the recipe. for var_dev in $(yq e ".recipe.${VAR_RECIPE_STRING}.dev | keys | .[]" "${VAR_SETUP_PART}"); do ### Iterate over all partitions for this device. for var_part in $(yq e ".recipe.${VAR_RECIPE_STRING}.dev.${var_dev} | keys | .[]" "${VAR_SETUP_PART}"); do ### Extract parameters from YAML. var_encryption_enable=$(yq e ".recipe.${VAR_RECIPE_STRING}.dev.${var_dev}.${var_part}.encryption.enable" "${VAR_SETUP_PART}") var_encryption_label=$(yq e ".recipe.${VAR_RECIPE_STRING}.dev.${var_dev}.${var_part}.encryption.label" "${VAR_SETUP_PART}") var_fs_btrfs_checksum=$(yq e ".recipe.${VAR_RECIPE_STRING}.dev.${var_dev}.${var_part}.filesystem.btrfs.checksum" "${VAR_SETUP_PART}") var_fs_btrfs_compress=$(yq e ".recipe.${VAR_RECIPE_STRING}.dev.${var_dev}.${var_part}.filesystem.btrfs.compress" "${VAR_SETUP_PART}") var_fs_btrfs_dedup=$(yq e ".recipe.${VAR_RECIPE_STRING}.dev.${var_dev}.${var_part}.filesystem.btrfs.dedup" "${VAR_SETUP_PART}") var_fs_format=$(yq e ".recipe.${VAR_RECIPE_STRING}.dev.${var_dev}.${var_part}.filesystem.format" "${VAR_SETUP_PART}") var_fs_label=$(yq e ".recipe.${VAR_RECIPE_STRING}.dev.${var_dev}.${var_part}.filesystem.label" "${VAR_SETUP_PART}") var_fs_options=$(yq e ".recipe.${VAR_RECIPE_STRING}.dev.${var_dev}.${var_part}.filesystem.options" "${VAR_SETUP_PART}") var_fs_version=$(yq e ".recipe.${VAR_RECIPE_STRING}.dev.${var_dev}.${var_part}.filesystem.version" "${VAR_SETUP_PART}") var_mount_path=$(yq e ".recipe.${VAR_RECIPE_STRING}.dev.${var_dev}.${var_part}.mount.path" "${VAR_SETUP_PART}") if [[ "${var_encryption_enable,,}" == "true" && "${var_mount_path}" == "SWAP" ]]; then mkfs.ext4 -L "${var_fs_label}" "/dev/${var_dev}${var_part}" 1M do_log "info" "false" "Partition: '/dev/${var_dev}${var_part}' formatted: '${var_fs_version}'." elif [[ "${var_encryption_enable,,}" == "true" && "${var_mount_path}" == "/tmp" ]]; then mkfs.ext4 -L "${var_fs_label}" "/dev/${var_dev}${var_part}" 1M do_log "info" "false" "Partition: '/dev/${var_dev}${var_part}' formatted: '${var_fs_version}'." fi ### Formatting partition if [[ "${var_encryption_enable,,}" == "true" && "${var_mount_path}" != "SWAP" && "${var_mount_path}" != "/tmp" ]]; then if [[ "${var_fs_format,,}" == "true" && "${var_fs_version}" == "btrfs" ]]; then if [[ "${var_fs_btrfs_dedup,,}" == "true" ]]; then mkfs.btrfs -L "${var_fs_label}" "/dev/mapper/${var_encryption_label}" -f --csum "${var_fs_btrfs_checksum}" -m dup -O compress="${var_fs_btrfs_compress}" do_log "info" "false" "Partition: '/dev/mapper/${var_encryption_label}' formatted: '${var_fs_version}'." # shellcheck disable=SC2129 echo "Partition: '/dev/mapper/${var_encryption_label}':" >> "${DIR_LOG}/btrfs.log" btrfs filesystem show "/dev/mapper/${var_encryption_label}" >> "${DIR_LOG}/btrfs.log" echo "" >> "${DIR_LOG}/btrfs.log" elif [[ "${var_fs_btrfs_dedup,,}" == "false" ]]; then mkfs.btrfs -L "${var_fs_label}" "/dev/mapper/${var_encryption_label}" -f --csum "${var_fs_btrfs_checksum}" -O compress="${var_fs_btrfs_compress}" do_log "info" "false" "Partition: '/dev/mapper/${var_encryption_label}' formatted: '${var_fs_version}'." # shellcheck disable=SC2129 echo "Partition: '/dev/mapper/${var_encryption_label}':" >> "${DIR_LOG}/btrfs.log" btrfs filesystem show "/dev/mapper/${var_encryption_label}" >> "${DIR_LOG}/btrfs.log" echo "" >> "${DIR_LOG}/btrfs.log" else do_log "error" "false" "Partition: '/dev/mapper/${var_encryption_label}': Unsupported deduplication method: '${var_fs_btrfs_dedup}'." fi elif [[ "${var_fs_format,,}" == "true" && "${var_fs_version}" == "ext4" ]]; then mkfs.ext4 -L "${var_fs_label}" "/dev/mapper/${var_encryption_label}" "${var_fs_options:+ $var_fs_options}" do_log "info" "false" "Partition: '/dev/mapper/${var_encryption_label}' formatted: '${var_fs_version}'." # shellcheck disable=SC2129 echo "Partition: '/dev/mapper/${var_encryption_label}':" >> "${DIR_LOG}/ext4.log" tune2fs -l "/dev/mapper/${var_encryption_label}" >> "${DIR_LOG}/ext4.log" echo "" >> "${DIR_LOG}/ext4.log" else do_log "error" "false" "Partition: '/dev/mapper/${var_encryption_label}': Unsupported filesystem format: '${var_fs_version}'." fi elif [[ "${var_encryption_enable,,}" == "false" && "${var_mount_path}" != "SWAP" && "${var_mount_path}" != "/tmp" ]]; then if [[ "${var_fs_format,,}" == "true" && "${var_fs_version}" == "btrfs" ]]; then if [[ "${var_fs_btrfs_dedup,,}" == "true" ]]; then mkfs.btrfs -L "${var_fs_label}" "/dev/${var_dev}${var_part}" -f --csum "${var_fs_btrfs_checksum}" -m dup -O compress="${var_fs_btrfs_compress}" do_log "info" "false" "Partition: '/dev/${var_dev}${var_part}' formatted: '${var_fs_version}'." # shellcheck disable=SC2129 echo "Partition: '/dev/${var_dev}${var_part}':" >> "${DIR_LOG}/btrfs.log" btrfs filesystem show "/dev/${var_dev}${var_part}" >> "${DIR_LOG}/btrfs.log" echo "" >> "${DIR_LOG}/btrfs.log" elif [[ "${var_fs_btrfs_dedup,,}" == "false" ]]; then mkfs.btrfs -L "${var_fs_label}" "/dev/${var_dev}${var_part}" -f --csum "${var_fs_btrfs_checksum}" -O compress="${var_fs_btrfs_compress}" do_log "info" "false" "Partition: '/dev/${var_dev}${var_part}' formatted: '${var_fs_version}'." # shellcheck disable=SC2129 echo "Partition: '/dev/${var_dev}${var_part}':" >> "${DIR_LOG}/btrfs.log" btrfs filesystem show "/dev/${var_dev}${var_part}" >> "${DIR_LOG}/btrfs.log" echo "" >> "${DIR_LOG}/btrfs.log" else do_log "error" "false" "Partition: '/dev/${var_dev}${var_part}': Unsupported deduplication method: '${var_fs_btrfs_dedup}'." fi elif [[ "${var_fs_format,,}" == "true" && "${var_fs_version}" == "ext4" ]]; then mkfs.ext4 -L "${var_fs_label}" "/dev/${var_dev}${var_part}" "${var_fs_options:+ $var_fs_options}" do_log "info" "false" "Partition: '/dev/${var_dev}${var_part}' formatted: '${var_fs_version}'." # shellcheck disable=SC2129 echo "Partition: '/dev/${var_dev}${var_part}':" >> "${DIR_LOG}/ext4.log" tune2fs -l "/dev/${var_dev}${var_part}" >> "${DIR_LOG}/ext4.log" echo "" >> "${DIR_LOG}/ext4.log" elif [[ "${var_fs_format,,}" == "true" && "${var_fs_version}" == "FAT32" ]]; then mkfs.fat -F 32 "/dev/${var_dev}${var_part}" do_log "info" "false" "Partition: '/dev/${var_dev}${var_part}' formatted: '${var_fs_version}'." else do_log "error" "false" "Partition: '/dev/${var_dev}${var_part}': Unsupported filesystem format: '${var_fs_version}'." fi fi done done } # vim: number et ts=2 sw=2 sts=2 ai tw=128 ft=sh