python3-cryptography and python3-jose fail during debootstrap due
to complex dependencies. Moving to post-debootstrap apt-get install.
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
python3-zmq has complex dependencies that fail during debootstrap.
Moving it to post-debootstrap apt-get installation resolves this.
Also removed from INCLUDE_PKGS in build-image.sh - installed via pip.
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
The 'arping' and 'iputils-arping' packages conflict with each other.
Using iputils-arping which provides the arping command needed by
the network fallback scripts.
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
- Install live-boot package and rebuild initramfs with live-boot scripts
- Create squashfs filesystem (878MB) on data partition sda4
- Update boot.scr with live boot parameters (boot=live, toram)
- Fix wiki sidebar links from [[Page|Display]] to [Display](Page)
- Add Eye-Remote wiki page documentation
- Add sync-wiki.sh script for wiki repository sync
- Add patch-multiboot-efi.sh for post-build EFI patching
Partition layout:
- sda1 (512MB): EFI with kernel, initrd, dtbs, boot.scr
- sda2 (3GB): ARM64 rootfs reference
- sda3 (3GB): x86 rootfs for VirtualBox/QEMU
- sda4 (9.5GB): Data + /live/filesystem.squashfs
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
- Add announcement banner on wiki home for v2.2.3 multiboot release
- Create wiki/Multiboot.md with full multiboot documentation
- Add Multiboot and Eye Remote links to sidebar navigation
- Update sidebar version to v2.2.3
- Document Eye Remote Pi Zero as USB gadget for ESPRESSObin boot
- Add partition layout, boot flow, and troubleshooting docs
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
- Changed [[ -z "$VAR" ]] && err to if/then/fi pattern
- This prevents early exit when condition is false with set -e
- Removed --minimal flag to install full SecuBox packages
Note: SecuBox packages on AMD64 still require apt.secubox.in SSL fix
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
- Add 5 USB gadget modes: Normal, Flash, Debug, TTY, Auth
- Add HID keyboard emulation for U-Boot automation
- Add FIDO2/U2F security key mode (Eye Remote)
- Add x64/amd64 live boot support
- Update README.md with Eye Remote documentation
- Update WIKI.md with mode mockups and technical details
- Add INFOGRAPHIC-PROMPT.md for Claude.ai image generation
- Bump version from 1.7.0 to 1.8.0
New files:
- secubox-hid-keyboard.sh: Virtual HID keyboard driver
- INFOGRAPHIC-PROMPT.md: 7 prompts for publicity infographics
Eye Remote transforms the Round UI from a status display
into a full remote control device with debugging, flashing,
and authentication capabilities.
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
Complete Remote UI implementation for SecuBox status display:
- Python/PIL dashboard with direct framebuffer rendering (no Chromium)
- KMS overlay support (vc4-kms-dpi-hyperpixel2r) - tested working
- USB OTG composite gadget (CDC-ECM + CDC-ACM) for host connection
- 6 concentric rings showing CPU, MEM, DISK, LOAD, TEMP, WiFi metrics
- Auto-start systemd service (secubox-dashboard.service)
- install_zerow.sh for SD card preparation with all fixes
Key fixes discovered during debugging:
- Use KMS overlay, not non-KMS (GPIO conflicts on Bookworm)
- Framebuffer is RGB565 (16-bit), not BGRA
- RPi OS Bookworm requires userconf file for SSH credentials
- NetworkManager ignores ifupdown; use direct IP config
Files:
- secubox_dashboard.py: PIL-based live metrics dashboard
- install_zerow.sh: SD card flasher with KMS overlay
- secubox-dashboard.service: Auto-start systemd unit
- 24 module icons (AUTH/WALL/BOOT/MIND/ROOT/MESH)
Tested on: RPi Zero W + HyperPixel 2.1 Round 480x480
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
Same fix as build-live-usb.sh X11 setup - the kiosk launcher was also
creating X11 config files that corrupted on bare metal.
- Skip config creation entirely for bare metal (vm_type=none)
- Intel/AMD/NVIDIA auto-detection works perfectly without configs
- Sanitize gpu_info for VMs (remove special chars)
- Only create explicit driver configs for VMs that need them
Fixes: "M2G_" parse error in /etc/X11/xorg.conf.d/10-kiosk.conf
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
The fallback script was pinging 192.168.255.1 (dummy0 interface) and
thinking it found a gateway, then assigning 192.168.255.250 to the
ethernet interface - which doesn't provide internet connectivity.
- Add check to skip gateway IPs that are already assigned locally
- Verify ARP discovery results aren't local IPs
- Prevents self-discovery of dummy0 (192.168.255.1)
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
- Add iputils-arping for ARP-based gateway discovery
- Add arp_discover() function to scan for responding devices
- Expand gateway probe list: .254 variants, 10.x, 172.16.x subnets
- Try ARP discovery before slower ping-based gateway probing
- More reliable network auto-configuration on diverse networks
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
- X11 setup now exits early for bare metal (VM_TYPE=none) without
creating config files - Intel/AMD/NVIDIA auto-detect perfectly
- Remove static fallback 10-modesetting.conf that caused conflicts
- Sanitize GPU_INFO in config comments to remove special chars
- Disable PrivateTmp and ProtectSystem for haproxy, metrics, threats
services - causes Python symlink namespace errors on some kernels
- Add fix-namespace-errors.sh script for quick fixes on running systems
Fixes: X11 "no screens found" on Intel HD Graphics 630
Fixes: "Failed to set up mount namespacing" for Python services
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
- build-all-live-usb.yml: Check for .img.gz first since build-image.sh
already compresses and removes the .img file
- build-rpi-usb.sh: Handle multiple kernel/initrd files by selecting
the latest version instead of globbing which breaks cp
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
- Create secubox-x11-setup.service for boot-time VM/driver detection
- VirtualBox VMSVGA controller requires vmware X11 driver (not modesetting)
- Add driver selection: VBox+VMSVGA→vmware, VBox+VBoxVGA→modesetting
- Update secubox-kiosk.service to depend on x11-setup service
- Update secubox-kiosk-launcher v3.3 to defer to setup service
- Change SLIPSTREAM_DEBS default to 1 (126 packages by default)
- Fix EspressoBin live USB boot partition sizing for embedded images
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
- Use find instead of glob to locate DTB directory reliably
- Copy only EspressoBin DTBs (armada-3720-espressobin*.dtb)
- Add logging for DTB count and warning if missing
- Fixes boot failure due to missing device tree files
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
- Fix $HOME issue when running with sudo by using SUDO_USER to get
original user's home directory for cache lookup
- Change ls to find to avoid set -e failures when no files match
- Add error handling for dpkg installation step
- Fix grep in package count verification to prevent pipefail
Both AMD64 (8GB) and EspressoBin V7 (2GB) live USB images now build
successfully with all 126 SecuBox packages slipstreamed.
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
- Add IP address discovery to network_summary API endpoint
- Add _get_package_version() helper for fetching installed versions
- Update _svc() to include package versions in status data
- Fix loadNetwork() to use API data instead of hardcoded IPs
- Add loadMemory() and loadDisk() functions for actual used/total values
- Update modules table to display real versions from dpkg
- Make EspressoBin build consistent with AMD64 slipstream (check cache too)
Fixes dashboard showing placeholder values (Memory: -/-, Storage: -/-, etc.)
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
- Fixed bug where discover_lan() function existed but was never called
- Now probes common gateways (192.168.1.1, 192.168.0.1, etc.) before link-local
- Only falls back to link-local (169.254.1.1) if gateway discovery also fails
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
- Add ARP-based IP collision detection for multi-device environments
- MAC-based pseudo-random IP offset to spread devices across range
- Gratuitous ARP announcement to prevent IP conflicts
- Fix EspressoBin DSA network: target wan interface, not eth0 CPU port
- Static IP fallback 192.168.255.250 when DHCP unavailable
- Sync all build scripts to version 1.7.0
- Add screenshot script with 90+ module URLs
- Add mock HTML screenshots for documentation
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
- Add Noto Color Emoji font-family to all icon elements
- Separate category icon into .cat-icon element with emoji font
- Put 'Noto Color Emoji' first in font stack (installed on live USB)
- Add explicit emoji font installation in build script
- Update both light and dark sidebar themes
Fixes emoji/icon boxes showing as empty squares on real hardware.
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
- Dashboard footer: version, boot mode, auth mode, uptime
- Login page: auth mode badge + version display
- Plymouth splash: version v1.7.0 + boot mode indicator
- GRUB menu: descriptive echo messages for each boot option
- New API endpoints: /boot_mode, /auth_mode, /public/info
- Version bump to 1.7.0 across all components
Phase 11 tasks completed: P11-01 through P11-04, P11-07 through P11-09
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
Problem: VirtualBox with VMSVGA shows as "VMware SVGA" in lspci,
causing wrong driver selection and X11 failure.
Fix: Use systemd-detect-virt as primary VM detection:
- "oracle" → VirtualBox → vboxvideo driver
- "vmware" → VMware → vmware driver
- "kvm"/"qemu" → KVM/QEMU → modesetting driver
- Fall back to lspci for bare metal
Also loads vboxsf module for shared folders support.
Addresses #27
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
Fixes:
- Add fallback EFI bootloader at /EFI/BOOT/BOOTX64.EFI for Lenovo/HP/Dell
- Add --slipstream flag to build-live-usb.sh (CI fix)
- Fix banner alignment in secubox-flash-disk
- Update kiosk launcher to v1.6.7.12
Wiki:
- Use generic /releases/latest/download/ URLs (no more hardcoded versions)
- Fix script paths (scripts/ → image/)
- Update all languages (EN, FR, DE, ZH)
Tested: Lenovo hardware install - PASSED
Closes#26
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
Root cause: GRUB Kiosk entry used systemd.unit=graphical.target
but no display manager was installed. systemd waited forever
for graphical.target → getty never started → no keyboard input.
Fixes:
- Remove systemd.unit=graphical.target from Kiosk GRUB entry
- Revert getty Type=idle to simple service (v1.6.7.3)
- Enable backup TTYs (tty2-6) for emergency access
Closes#24
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
- Add generate_debug_report() to secubox-kiosk-launcher
- Capture system info, virtualization, graphics hardware
- Log DRM/KMS devices, kernel modules, Xorg status
- Enhanced error reporting with dmesg and VT status
- Debug reports saved to /tmp/kiosk-debug-*.log
- Add v1.6.7.2 overlay installer scripts
- Add emoji font fixes for navbar icons
- Add screenshots for v1.6.7.1
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
- Remove prefix="/auth" from secubox_core/auth.py router definition
- Add prefix="/auth" when including auth_router in hub main.py
- Fixes login endpoint from /auth/auth/login to /auth/login
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
Changes in v1.6.7:
- Fix X11/VT switching (critical fix - X server now runs as root)
- Add portal users.json reset in firstboot
- Default admin password: secubox (not random)
- Hide Chromium warning banner with --test-type flag
- Hub API auth endpoint at /api/v1/hub/auth/login
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
- Create /etc/secubox/users.json with admin user on firstboot
- Default password: secubox (instead of random)
- SHA256 hash password same as portal expects
- Hide Chromium --ignore-certificate-errors warning with --test-type
Credentials: admin / secubox
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
- Start Xorg as root directly (required for VT allocation)
- Add proper Xauthority setup with magic cookie
- Explicit chvt 7 to switch to graphical VT
- Wait for X11 socket before launching session
- Run session as kiosk user with correct environment
- Add extensive debug logging
Tested in QEMU: Xorg starts, Chromium runs fullscreen
Version: v1.6.6
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
- Remove --no-sandbox from Chromium to eliminate warning banner
- Add --disable-infobars to hide any remaining info bars
- Add X11 InputClass sections for libinput keyboard/pointer/touchpad
- Set AutoAddDevices=true, AllowEmptyInput=false in ServerFlags
- Restore 'splash' to kernel cmdline for Plymouth boot splash
- Update version strings to 1.6.5
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
- Remove 'splash' from kernel cmdline (Plymouth disabled by default)
- Add secubox-simple fallback theme (minimal, compatible)
- Set secubox-simple as default theme if Plymouth enabled manually
- Keep secubox-3d theme available for advanced users
- Fixes boot freeze on both QEMU/KVM and real hardware
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
Plymouth:
- New secubox-3d theme with nested cubes + triple lemniscate
- 3 cubes (outer/middle/inner) with desync rotation
- AUTH/MIND/MESH colored lemniscates with glowing heads
- SecuBox color palette integration
Kiosk:
- Fix session script: use --start-fullscreen (not --kiosk)
- Allows Ctrl+Alt+Fn VT switching
- Clean exec chromium (no background process issues)
- Consistent session between build script and launcher
Build:
- Version bump to 1.6.3
- Plymouth theme set to secubox-3d
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
secubox-flash-disk:
- Add efibootmgr verification after GRUB EFI install
- Show manual fix instructions if EFI entry not created
- Mount /dev/pts for chroot compatibility
- Pass target device to grub-install
- Better error handling and summary
netplan (x64-live):
- Remove invalid routes (via: 0.0.0.0)
- Add dhcp4-overrides for proper DNS/routes
- Rename wan to wan0 to avoid conflicts
Fixes Error 1962 on Lenovo ThinkCentre M710q
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
- Plymouth: Integrate secubox-cube theme with 3D rotating module icons
- Auth: Create users.json for portal login (admin/secubox)
- flash-disk: Fix 'local' outside function error on line 236
- netplan: Add br-lan/wan structure for x64-live mode
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
- Add fonts-terminus and kbd packages for UTF-8 box-drawing chars
- Configure console-setup with Terminus font (FONTFACE/FONTSIZE)
- Add vconsole.conf with ter-v16n font for systemd
- Include flash-emmc.scr on boot partition for U-Boot flashing
- Copy embedded eMMC image to boot partition for U-Boot access
- Update README with Live USB Quick Flash instructions
- Bump version to 1.6.1
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
- xinitrc: Change KIOSK_URL from https://localhost to http://localhost
- secubox-kiosk.sh: Change default from https://127.0.0.1 to http://127.0.0.1
nginx config serves:
- HTTP on port 80 for localhost/127.0.0.1 (direct content, no redirect)
- HTTPS on port 443 for secubox.local and external access
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
- Create secubox-flash-disk tool for flashing to internal storage
- Smart device detection (NVMe, SATA, eMMC, VirtIO)
- Safety checks to prevent flashing boot device
- Interactive device selection with disk info
- Progress display with pv or dd status
- Optional root partition resize to fill disk
- Checksum verification support
- Update secubox-console-tui with x64 flash support
- Add is_live_x64() detection function
- Add flash_disk() function calling secubox-flash-disk
- Show 'd' key option when running x64 live
- Update build-live-usb.sh with --embed-image option
- Bundle target image in /secubox/ for disk installation
- Auto-generate checksum if not present
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
New components for bootable live USB with eMMC flashing capability:
- image/build-ebin-live-usb.sh: Build script for ARM64 live USB
- SquashFS-based live filesystem
- Cross-compilation support via QEMU
- Optional embedded eMMC image for flashing
- Distroboot configuration for U-Boot
- image/sbin/secubox-flash-emmc: Interactive eMMC flasher
- Safety checks (won't flash if running from eMMC)
- Progress display and checksum verification
- Auto mode for unattended installation
- Dry-run option for testing
- board/espressobin-v7/boot-live-usb.cmd: U-Boot boot script
- USB boot priority configuration
- Live-boot kernel parameters
- board/espressobin-v7/extlinux/extlinux.conf: Distroboot menu
- Live, To-RAM, Flash, and Rescue boot options
- Updated secubox-console-tui with "Flash to eMMC" menu option
Usage:
# Build eMMC image first
sudo bash image/build-image.sh --board espressobin-v7
# Build live USB with embedded image
sudo bash image/build-ebin-live-usb.sh \
--embed-image output/secubox-espressobin-v7-bookworm.img.gz
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
- Create secubox user explicitly in build script before package install
- Configure tmpfiles.d for /run/secubox at boot time
- Add ExecStartPre with + prefix to hub service for root permissions
- Ensure hub.conf created in nginx secubox.d
- Fix service dependency chain (Wants instead of Requires)
- Change UMask to 0002 for proper socket permissions
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>