Commit Graph

306 Commits

Author SHA1 Message Date
39667e41bc fix: ESPRESSObin v7 eMMC boot - DTB, root device, mv88e6xxx blacklist
- Use armada-3720-espressobin-v7-emmc.dtb to enable both SDHCI controllers
- Fix root device: /dev/mmcblk1p2 (eMMC is mmc1 with dual controller DTB)
- Add modprobe.blacklist=mv88e6xxx,dsa_core to prevent DSA probe loop
- Add sdhci.debug_quirks2=0x40 to fix xenon-sdhci DDR timing issues
- Add initramfs hooks for sdhci-xenon and mv88e6xxx blacklist
- Add systemd service to load mv88e6xxx after rootfs mount
- Fix fstab tmpfs mount (remove non-existent user reference)

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2026-04-06 18:07:30 +02:00
e8d169919c fix: Correct boot.scr paths and make initramfs optional
- build-image.sh: Fix boot.scr to load from boot partition (mmc 1:1)
  with files at root level (Image, not /boot/Image)
- build-rpi-usb.sh: Make initramfs generation failure non-fatal
  (Pi can boot without initramfs, just with reduced functionality)

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2026-04-06 10:33:32 +02:00
592ce34202 feat: Add --slipstream option to build-rpi-usb.sh
Consistent with build-image.sh:
- --slipstream installs packages from output/debs/
- Falls back to cache/repo/pool if not using slipstream
- Installs secubox-core first (dependency)

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2026-04-06 10:11:14 +02:00
a2eefdb99d docs: Add Configuration and Troubleshooting wiki pages (EN/FR/ZH)
- Configuration.md: TOML config, modules, double-buffer system
- Troubleshooting.md: Common issues, diagnostics, recovery
- All pages translated to French and Chinese
- Sidebar updated to v1.5.3 with new sections

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2026-04-06 10:04:02 +02:00
f281a19aae feat: Add debian packaging for secubox-system-hub
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2026-04-06 10:01:08 +02:00
68d0f11c3b docs: Update WIP.md - Session 43 ARM kernel fix + wiki
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2026-04-06 09:37:31 +02:00
43b62317ec docs: Complete wiki translations (FR/ZH)
- ARM-Installation-FR.md (French translation)
- ARM-Installation-ZH.md (Chinese translation)
- ESPRESSObin-ZH.md (Chinese translation)
- UI-COMPARISON.md (moved from docs/wiki/)
- Updated sidebar with all language links

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2026-04-06 09:30:46 +02:00
823a84d86d fix: Install linux-image-arm64 for all ARM boards
- Bug: ARM images had empty /boot (no kernel)
- Fix: Add linux-image-arm64 to debootstrap for all ARM boards
- Copy vmlinuz → /boot/Image for U-Boot
- Copy DTBs from /usr/lib/linux-image-*/marvell/
- Generate extlinux.conf for distroboot
- Generate boot.scr for U-Boot autoboot
- Update wiki with automatic boot methods

Affected boards: espressobin-v7, espressobin-ultra, mochabin

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2026-04-06 09:11:00 +02:00
1ee6513e57 docs: Add ESPRESSObin wiki pages (EN/FR)
- Complete U-Boot flash guide with gzwrite
- Hardware variants (v5/v7/Ultra), eMMC limits
- Board layout, UART pinout, DIP switches
- 4 flash methods: USB, SD, TFTP, mmc write
- DSA switch network interfaces
- Troubleshooting and UART recovery

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2026-04-06 09:02:06 +02:00
ed5f645f5a docs: Update WIP.md - v1.5.2 eMMC size fixes
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2026-04-05 15:21:35 +02:00
4772fc2b0f fix: Use board-specific image sizes for eMMC compatibility
Board configs now define IMG_SIZE:
- ESPRESSObin v7: 3584M (fits 4GB eMMC)
- ESPRESSObin Ultra: 4G (8GB eMMC)
- MOCHAbin: 4G (8GB eMMC + SATA)

CI workflow updated to use board defaults instead of hardcoded 8G.

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2026-04-05 15:20:24 +02:00
41011c57d7 docs: Add eMMC size limits for ESPRESSObin/MOCHAbin
Document storage constraints for ARM boards:
- ESPRESSObin 4GB eMMC: max 3.5GB image
- ESPRESSObin 8GB/MOCHAbin: 4GB default, 6GB max
- MOCHAbin SATA/NVMe alternative for larger installs
- Added MOCHAbin README.md with U-Boot flash guide

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2026-04-05 15:17:49 +02:00
3a25aa87ff docs: Update WIP.md - wiki ARM + modules complete
- ARM Installation wiki page
- 73 new modules documented (119 total)

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2026-04-05 11:28:19 +02:00
37c8d75d0e docs: Add 73 missing modules to wiki (124 total)
Added documentation for all SecuBox modules:
- AI: AI Gateway, AI Insights, LocalAI, LocalRecall, MCP Server, Ollama, Threat Analyst
- Security: Ad Guard, Config Advisor, CVE Triage, CyberFeed, DNS Guard, Interceptor, IoT Guard, IP Block, MAC Guard, Network Anomaly, OpenClaw OSINT, OSSEC, SOC Agent/Gateway, Threats, Vault, Wazuh
- Network: DNS Provider, Master Link, Mirror/CDN, Network Diagnostics, Network Tuning, Routes, SaaS Relay
- Automation: Domoticz, Home Assistant, MQTT, PicoBrew, Zigbee
- Communication: GoToSocial, Jabber, Jitsi, Matrix, SimpleX, TURN/STUN, VoIP
- Media: Jellyfin, Lyrion, PeerTube, PhotoPrism, Web Radio
- Apps: Hexo, MagicMirror, MMPM, Newsbin, Redroid, RezApp, Torrent
- System: Admin, Cloner, Console TUI, Glances, KSM, Reporter, RTTY, VM Manager

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2026-04-05 11:26:45 +02:00
b8ab3237d6 docs: Add ARM installation wiki page (U-Boot flash guide)
Comprehensive guide for flashing SecuBox to ARM boards via U-Boot:
- ESPRESSObin v7/Ultra and MOCHAbin procedures
- USB and SD card source options
- gzwrite to eMMC/SATA
- Troubleshooting section
- Board-specific notes

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2026-04-05 10:07:22 +02:00
6c611ebb15 docs: Update WIP.md for Session 42
- Live USB/RPi build script fixes (parted dependency)
- ESPRESSObin v7 installation guide

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2026-04-05 09:32:20 +02:00
81fa1d77b6 docs: Add ESPRESSObin v7 installation guide
Document U-Boot flash procedure for installing SecuBox to eMMC
from USB drive. Includes:
- USB to eMMC flash via gzwrite
- SD card alternative method
- Network interface mapping
- Troubleshooting tips

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2026-04-05 09:31:11 +02:00
75f0406635 fix: Add parted/dosfstools to RPi 400 image
Include disk partitioning tools (parted, dosfstools, e2fsprogs)
and hardware detection (pciutils, usbutils) in the RPi image
for consistency with other build scripts.

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2026-04-05 09:12:58 +02:00
271f27e927 fix: Add missing parted/dosfstools deps to live USB image
The secubox-install script requires parted for disk partitioning
and dosfstools for mkfs.fat on ESP. Also added grub-pc-bin for
legacy BIOS boot support, matching build-installer-iso.sh.

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2026-04-05 08:23:07 +02:00
f7f5d5b332 docs: Update WIP.md for Session 41 with Phase 9+ modules
- Added 11 new system/infrastructure modules to tracking
- Updated package count from 93 to 124
- Documented nettweak, ksm, avatar, admin, metabolizer, metacatalog,
  cyberfeed, mirror, saas-relay, rezapp, picobrew modules

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2026-04-05 06:33:03 +02:00
9d4c3ef5a4 docs: Update WIP.md - mode switching tested
- TUI mode switch and persist verified
- Kiosk mode switch back verified
- Both modes work with --now flag
- Modes persist across reboots

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2026-04-05 06:28:59 +02:00
384084c87c docs: Update WIP.md - v1.5.1 release verified
- Release v1.5.1 complete with all images
- Downloaded and tested v1.5.1 image
- startup.nsh verified in ESP partition
- VirtualBox boot confirmed working

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2026-04-04 19:08:19 +02:00
d3724a1840 docs: Update WIP.md for Session 40
- VirtualBox EFI boot fix (startup.nsh)
- TUI mode boot fix (systemctl mask)
- CI package slipstream fix (124 packages)
- Wiki update to v1.5.1
- Release v1.5.1 in progress

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2026-04-04 18:17:14 +02:00
10d09e3b77 docs: Update to v1.5.1 with 124 packages
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2026-04-04 18:04:07 +02:00
df8c984bb8 fix(boot): TUI mode now properly overrides kiosk
- cmdline-handler: Use systemctl mask to prevent kiosk startup
- cmdline-handler: Kill X11/Chromium if already running
- cmdline-handler: Create generator drop-in for correct target
- kiosk.service: Wait for cmdline handler before starting
- tui.service: Wait for cmdline handler before starting

Fixes: TUI boot menu option was loading Kiosk GUI instead

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2026-04-04 17:47:08 +02:00
8420db41fd docs: Update WIP.md with CI package slipstream fix
Session 40: VirtualBox EFI fix + CI workflow fixes for 124 packages

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2026-04-04 12:50:09 +02:00
38841a9640 fix(ci): Include all SecuBox packages in image builds
- build-image.yml: Download packages from build-packages workflow
  and pass --slipstream flag to include them in images
- build-live-usb.yml: Remove redundant cache copy, improve logging
- release.yml: Update package count from 93 to 124
- build-image.yml: Update package count from 33 to 124

All 124 SecuBox packages will now be slipstreamed into live USB
and system images when built via CI.

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2026-04-04 12:49:11 +02:00
85d970d6fb docs: Update WIP.md for Session 40
Document VirtualBox EFI boot fix with startup.nsh

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2026-04-04 12:46:39 +02:00
70961cb566 fix(build): Add startup.nsh for VirtualBox EFI compatibility
The VirtualBox EFI firmware doesn't always detect the fallback boot
loader at /EFI/BOOT/BOOTX64.EFI. Adding a startup.nsh script to the
ESP root ensures the EFI shell automatically loads GRUB.

This fixes the "PXE boot" issue when testing live USB images in
VirtualBox with UEFI firmware enabled.

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2026-04-04 12:46:21 +02:00
a2fd0e0cd6 feat(boot): CRT-style banners with colors and emoji indicators
Boot Banner Improvements:
- /etc/issue: Gold ASCII art pre-login banner with credentials
- /etc/motd: Colorful LIVE USB banner with access info
- secubox-status: New command showing system overview with CRT colors
- secubox-help: Quick reference for all secubox commands
- secubox-logs: Live security log viewer shortcut
- profile.d: Login status display with mode/service/IP indicators

Mode Switching:
- cmdline-handler: Fixed TUI mode to start (not just enable) service
- secubox-mode: Updated with CRT colors and emoji status indicators

GRUB Menu:
- Kiosk GUI is now default when --kiosk flag used
- All entries have emoji indicators (🖼️📟🌉🛡️💾🚀🔧🚨🐛)
- CRT-style menu colors (cyan on black, yellow highlights)

CI Workflows:
- build-live-usb.yml: Updated boot options and credentials in release notes
- release.yml: Updated to 93 packages, new boot options, correct credentials

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2026-04-04 12:16:40 +02:00
e0569f4082 feat(live): Add disk installer to live USB image
- Add secubox-install script for interactive disk installation
- Add "Install SecuBox to Disk" GRUB menu entry
- Add secubox.install=1 kernel parameter support
- Auto-launch installer when booted with install option

The installer:
- Lists available disks with size and model
- Asks for confirmation before wiping
- Creates GPT partitions (ESP + root + data)
- Copies live filesystem to disk
- Installs GRUB bootloader (UEFI + BIOS)
- Generates proper fstab

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2026-04-04 11:44:00 +02:00
932ef33be9 fix(ui): Correct module names in menu.d files
- AI Gateway (was: Ai-gateway)
- MCP Server (was: Mcp-server)
- WAF (was: Waf)
- Threat Analyst (was: Threat-analyst)
- Config Advisor (was: Config-advisor)
- DNS Guard (was: Dns-guard)
- IoT Guard (was: Iot-guard)

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2026-04-04 11:22:16 +02:00
2d26ed04cb fix(installer): Use 'secubox' password instead of 'admin' for default user
The installer was creating users.json with SHA256 hash of "admin" instead
of "secubox", causing login failures when trying admin/secubox credentials.

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2026-04-04 11:20:38 +02:00
b372463fba fix(ci): Add workflow_call trigger to enable reusable workflows
- build-packages.yml: Add workflow_call with secrets
- build-image.yml: Add workflow_call with inputs, fix matrix for all event types
- publish-packages.yml: Add workflow_call with inputs and secrets

This fixes the release.yml workflow which was failing because it tried
to call these workflows as reusable workflows without the workflow_call
trigger defined.

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2026-04-04 10:54:52 +02:00
98c4ff85ee docs: Update WIP.md for Session 38
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2026-04-04 10:38:29 +02:00
5d8c32769c docs(wiki): Update sidebar with v1.5.0 and VirtualBox link text
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2026-04-04 10:38:10 +02:00
2265d7cbde docs(wiki): Add VirtualBox quick start to all wiki home pages
- Update Home.md with VirtualBox (2 Minutes) quick start section
- Update Home-FR.md with French translation
- Update Home-ZH.md with Chinese translation
- Update version to v1.5.0 and package count to 93
- Add VM creation script options documentation
- Reference create-secubox-vm.sh script with --download option

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2026-04-04 10:37:53 +02:00
b153527b96 docs: Add VirtualBox quick start guide and VM creation script
New files:
- wiki/Live-USB-VirtualBox.md: Complete guide from download to running VM
- scripts/create-secubox-vm.sh: Automated VM creation with port forwarding
- templates/SecuBox-Live.vbox.template: VirtualBox template file

Updates:
- README.md: Added VirtualBox quick start section, updated package count (93)
- wiki/_Sidebar.md: Added VirtualBox quick start link

Usage:
  ./scripts/create-secubox-vm.sh secubox-live.vdi
  ./scripts/create-secubox-vm.sh --download --headless

Access after boot:
  SSH:  ssh -p 2222 root@localhost
  Web:  https://localhost:9443
  Pass: secubox

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2026-04-04 10:31:21 +02:00
4acd982bac feat(phase10): Complete all 10 Security Extensions modules
New modules created (8):
- secubox-ai-insights: ML threat detection and anomaly analysis
- secubox-ipblock: IP blocklist manager with nftables integration
- secubox-interceptor: Traffic interception and SSL inspection
- secubox-cookies: Cookie tracking and GDPR compliance
- secubox-mac-guard: MAC address whitelist/blacklist control
- secubox-dns-provider: Multi-provider DNS API (OVH, Gandi, Cloudflare)
- secubox-threats: Unified threat dashboard with IOC management
- secubox-openclaw: OSINT reconnaissance tool

Previously built:
- secubox-wazuh: SIEM integration
- secubox-ossec: Host IDS

All modules include:
- FastAPI backend with JWT authentication
- P31 Phosphor light theme frontend
- Debian packaging with systemd integration
- nginx reverse proxy config
- Menu integration

Total packages: 93 (was 85)
All migration phases complete (8, 9, 10)

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2026-04-04 10:26:16 +02:00
ce28d53918 feat(phase8): Complete all 21 Application modules
New modules created (13):
- secubox-hexo: Static blog generator (Hexo)
- secubox-webradio: Internet radio streaming
- secubox-torrent: BitTorrent client (Transmission)
- secubox-newsbin: Usenet downloader (SABnzbd)
- secubox-domoticz: Home automation
- secubox-gotosocial: Fediverse/ActivityPub server
- secubox-simplex: SimpleX secure messaging
- secubox-photoprism: Photo management
- secubox-homeassistant: IoT/Home automation hub
- secubox-matrix: Matrix chat server (Synapse)
- secubox-jitsi: Video conferencing
- secubox-peertube: Video platform
- secubox-voip: VoIP/PBX (Asterisk/FreePBX)

All modules include:
- FastAPI backend with JWT authentication
- P31 Phosphor light theme frontend
- Docker/Podman container management
- Debian packaging (control, rules, postinst, prerm)
- nginx reverse proxy config
- systemd service unit
- Menu integration

Total packages: 85 (was 72)

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2026-04-04 10:04:25 +02:00
074bb042df docs: Update tracking files for Session 36
- Phase 9 marked complete (22/22 modules)
- Total package count: 72
- Updated MIGRATION-MAP.md with Phase 9 completion

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2026-04-04 09:05:29 +02:00
17e40e00e3 feat(phase9): Complete all 22 System Tools modules
New modules (7):
- secubox-metabolizer — Log processor/analyzer
- secubox-metacatalog — Service catalog/registry
- secubox-cyberfeed — Threat feed aggregator
- secubox-mirror — Mirror/CDN caching
- secubox-saas-relay — SaaS API proxy
- secubox-rezapp — App deployment manager
- secubox-picobrew — Homebrew/fermentation controller

Documentation added:
- secubox-ksm/README.md
- secubox-admin/README.md

Phase 9 is now 22/22 complete.
Total packages: 72 (was 65)

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2026-04-04 09:04:48 +02:00
a1c0d563f4 fix(ci): Handle non-existent directories in build-live-usb.sh
With set -euo pipefail, find on non-existent directories causes script
failure even with stderr redirected. Add directory existence checks
before running find commands to prevent CI failures.

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2026-04-04 08:48:32 +02:00
20ce5548c3 fix(daemon): Skip dh_strip and dh_dwz for cross-compiled Go binaries
Go binaries are cross-compiled (arm64 on x86_64 runner) and already
stripped with -ldflags "-s -w". The native strip tool can't recognize
the ARM64 binary format, causing build failures.

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2026-04-04 08:22:26 +02:00
8d5e71f98b fix(core): Set /run/secubox world-writable for service sockets
- Add tmpfiles.d/secubox.conf with mode 1777 (sticky + world-writable)
- Update postinst to create /run/secubox with correct permissions
- Run systemd-tmpfiles --create on package install

This fixes permission denied errors when services try to create
Unix sockets in /run/secubox directory.

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2026-04-04 08:14:51 +02:00
bcc6a781d0 fix(hub): Correct login redirect path to /login.html
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2026-04-04 08:08:58 +02:00
675ee58e75 fix(hub/api): Require JWT auth on all dashboard endpoints
Add require_jwt dependency to all public endpoints:
- /dashboard
- /alerts
- /network_summary
- /system_health
- /network_mode (GET)
- /menu
- /board_summary

Only /health remains public for monitoring.

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2026-04-04 08:08:07 +02:00
07c8fa65c8 fix(hub): Require authentication before loading dashboard
- Add checkAuth() function to verify token on page load
- Redirect to login if no token present
- Clear invalid tokens on 401 response
- Block page content until auth verified

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2026-04-04 08:05:46 +02:00
1ece04a618 feat(phase9): Add rtty, smtp-relay, routes, reporter modules
New Phase 9 System Tools modules:
- secubox-rtty: Remote terminal access via web interface
- secubox-smtp-relay: SMTP relay status and queue monitoring
- secubox-routes: Routing table viewer with IPv4/IPv6 support
- secubox-reporter: System report generation and scheduling

All modules include:
- FastAPI backend with JWT auth
- P31 Phosphor CRT-style web interface
- Auth verification and auto-refresh
- Nginx reverse proxy configuration
- Systemd service and menu integration

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2026-04-04 07:58:44 +02:00
8abe743c40 fix(ci): Build Go c3box binary and pre-build soc-web in CI
- Add c3box binary build alongside secuboxd and secuboxctl
- Pre-build React app for soc-web before dpkg-buildpackage
- Update soc-web debian/rules to skip npm if dist/ pre-built
- Remove nodejs/npm Build-Depends (now pre-built in CI)

Fixes build failures for secubox-daemon and secubox-soc-web packages.

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2026-04-04 07:56:45 +02:00