[debian-edu-commits] [Git][debian-edu/debian-edu-config][personal/sunweaver/debian-edu-pxeinstall-multiple-version-support] 12 commits: bin/debian-edu-ldapserver: Don't use $ldapserver uninitialised.

Mike Gabriel (@sunweaver) gitlab at salsa.debian.org
Fri Sep 25 07:42:35 BST 2026



Mike Gabriel pushed to branch personal/sunweaver/debian-edu-pxeinstall-multiple-version-support at Debian Edu / debian-edu-config


Commits:
b89ecda1 by Mike Gabriel at 2026-09-15T21:56:17+02:00
bin/debian-edu-ldapserver: Don't use $ldapserver uninitialised.

- - - - -
14abce68 by Mike Gabriel at 2026-09-23T19:46:09+00:00
sbin/debian-edu-ltsp-install: Support KDE in X2Go sessions again.

The X2Go Server fix for #955128 maps old clients' startkde command to
startplasma-x11:

https://code.x2go.org/gitweb?p=x2goserver.git;a=commit;h=28e7669e64ad2ffc629222a017757dd7022f4066

- - - - -
c9c3eaf2 by Mike Gabriel at 2026-09-23T19:47:00+00:00
share/debian-edu-config/tools/run-at-firstboot: Silence warnings during D-I installation about unability to use an interactive debconf frontend.

- - - - -
9d3bec79 by Mike Gabriel at 2026-09-25T06:42:27+00:00
debian-edu-pxeinstall: When downloading the netinstaller, skip if download fails. (Closes: #1147699).

- - - - -
bbbb9dc3 by Mike Gabriel at 2026-09-25T06:42:27+00:00
debian-edu-pxeinstall: Support multiple D-I versions if installed as DEB. (Closes: #1147764).

- - - - -
46ba1213 by Mike Gabriel at 2026-09-25T06:42:27+00:00
debian-edu-pxeinstall: Default to amd64 only, since trixie there is no i386 Debian-Installer anymore.

- - - - -
c20b6960 by Mike Gabriel at 2026-09-25T06:42:27+00:00
tools/pxe-addfirmware: Refactor script. Adjust for trixie and for multi-version netboot D-I.

- - - - -
ed512915 by Mike Gabriel at 2026-09-25T06:42:27+00:00
sbin/debian-edu-pxeinstall: Stop and abort if no netboot installers could be found, don't create/touch the TFTP config in that case.

- - - - -
313eff72 by Mike Gabriel at 2026-09-25T06:42:27+00:00
sbin/debian-edu-pxeinstall: Enable iPXE graphical background image.

- - - - -
9503a5a6 by Mike Gabriel at 2026-09-25T06:42:27+00:00
debian/control: Require debian-edu-artwork (>= 2.13.5-1~). Needed for debian-edu-pxeinstall to be able to use the correct Debian Installer version's logo banner in the graphical installer (relevant for multi-version-netboot-di setups).

- - - - -
f57ca9c2 by Mike Gabriel at 2026-09-25T06:42:27+00:00
sbin/debian-edu-pxeinstall: Use Debian-version-specific installer logo PNG in Debian Installers installing older versons of Debian Edu.

- - - - -
dfdd806e by Mike Gabriel at 2026-09-25T06:42:27+00:00
sbin/debian-edu-pxeinstall: When generating ltsp.ipxe, make the script continue/ignore if console iPXE command is unknown to the iPXE firmware build/version.

- - - - -


7 changed files:

- bin/debian-edu-ldapserver
- debian/control
- etc/debian-edu/pxeinstall.conf
- sbin/debian-edu-ltsp-install
- sbin/debian-edu-pxeinstall
- share/debian-edu-config/tools/pxe-addfirmware
- share/debian-edu-config/tools/run-at-firstboot


Changes:

=====================================
bin/debian-edu-ldapserver
=====================================
@@ -63,7 +63,7 @@ if (on_main_server() && during_installation()) {
             print STDERR "warning: no DNS name from dnsdomainname call.  using $dnsdomain from /etc/resolv.conf.\n" if $opts{d};
         }
         $ldapserver = $opts{s} || find_ldap_server($dnsdomain);
-        print STDERR "info: found ldap server $ldapserver\n" if $opts{d};
+        print STDERR "info: found ldap server $ldapserver\n" if $opts{d} && $ldapserver;
         $krbserver = find_kerberos_server($dnsdomain);
     }
 }


=====================================
debian/control
=====================================
@@ -26,7 +26,7 @@ Depends: ${misc:Depends},
          cfengine3,
          curl,
          debconf-utils,
-         debian-edu-artwork,
+         debian-edu-artwork (>= 2.13.5-1~),
          e2fsprogs,
          education-tasks,
          fping,


=====================================
etc/debian-edu/pxeinstall.conf
=====================================
@@ -13,3 +13,6 @@ graphicdi=true
 
 # Set this during development to test if daily d-i netboot.tar.gz is working.
 #dailydi=true
+
+# Architectures to support by Debian-Installer via PXE boot.
+#archs=amd64


=====================================
sbin/debian-edu-ltsp-install
=====================================
@@ -28,10 +28,8 @@ select_desktop () {
     # support
     if [ -x /usr/bin/startxfce4 ]; then # from xfce4-session
         echo XFCE
-    # FIXME x2goclient and x2goserver (x2goruncommand) in Debian only support
-    # startkde which does not exist any more (#955128)
-    #elif [ -x /usr/bin/startplasma-x11 ]; then # from plasma-workspace
-    #    echo KDE
+    elif [ -x /usr/bin/startplasma-x11 ]; then # from plasma-workspace
+        echo KDE
     elif [ -x /usr/bin/gnome-session ]; then # from gnome-session-bin
         echo GNOME
     elif [ -x /usr/bin/mate-session ]; then # from mate-session


=====================================
sbin/debian-edu-pxeinstall
=====================================
@@ -52,14 +52,18 @@ fi
 
 # Grab dist value for both testing and stable release cases.
 if grep -q / /etc/debian_version ; then
-	dist=$(cat /etc/debian_version | cut -d/ -f1)
+	# Likely a Debian testing/unstable system this script is executed on.
+	dist_codename=$(cat /etc/debian_version | cut -d/ -f1)
+	dist_version=${dist_codename}
 else
-	dist=$(lsb_release -sc)
+	# A stable release of Debian.
+	dist_codename=$(lsb_release -sc)
+	dist_version=$(lsb_release -sr)
 fi
 
 default_mydesktop="xfce"
 
-[ "$archs" ]      || archs="amd64 i386"
+[ "$archs" ]      || archs="amd64"
 [ "$mirrorurl" ]  || mirrorurl=http://deb.debian.org/debian
 [ "$hostname" ]   || hostname=pxeinstall
 [ "$domain" ]     || domain=intern
@@ -136,28 +140,52 @@ fi
 [ -d $tftpdir ] || mkdir $tftpdir
 [ -d $tftpdir/debian-edu ] || mkdir $tftpdir/debian-edu
 
+[ -d $tftpdir/debian-installer ] || \
+mkdir $tftpdir/debian-installer
+cd $tftpdir/debian-installer
+
+# We require to have at least debian-installer-<dist_version>-netboot-* installed,
+# if not, we fallback to http download from Debian archive servers
+if [ -d "/usr/lib/debian-installer/images/${dist_version}" ]; then
+	di_versions_supported="$(cd /usr/lib/debian-installer/images/; ls -1 | grep -E '^[0-9]+$' | sort -r -h)"
+else
+	di_versions_supported="${dist_version}"
+fi
+
 for arch in $archs ; do
-	(
-		if [ true = "$dailydi" ] ; then
-			diurl=https://d-i.debian.org/daily-images/$arch/daily/netboot
-		else
-			diurl=$mirrorurl/dists/$dist/main/installer-$arch/current/images/netboot
-		fi
-		[ -d $tftpdir/debian-installer ] || \
-		mkdir $tftpdir/debian-installer
+	for di_ver in ${di_versions_supported}; do
+		(
 		cd $tftpdir/debian-installer
-		di_ver=11
+
 		tarball=""
-		if [ -d /usr/lib/debian-installer/images/$di_ver/$arch ]; then
-			di_img_dir="/usr/lib/debian-installer/images/$di_ver/$arch"
-			# Use the debian/installer netboot debs
-			tarball=""
-			if [ true = "$graphicdi" ]; then
-				cp -r -u $di_img_dir/gtk/debian-installer/$arch $arch
+		if [ -d /usr/lib/debian-installer/images/ ] && [ -n "$(find /usr/lib/debian-installer/images/ -mindepth 1 -maxdepth 1 -type d  2>/dev/null)" ]; then
+
+			di_img_dir="/usr/lib/debian-installer/images/${di_ver}/${arch}"
+			if [ -d ${di_img_dir} ]; then
+				# Use the debian/installer netboot debs
+				mkdir -p ${di_ver}/
+				if [ true = "$graphicdi" ]; then
+					cp -r -u ${di_img_dir}/gtk/debian-installer/${arch}  ${di_ver}/
+				else
+					cp -r -u ${di_img_dir}/text/debian-installer/${arch} ${di_ver}/
+				fi
 			else
-				cp -r -u $di_img_dir/text/debian-installer/$arch $arch
+				continue
 			fi
-		elif [ ! -f netboot-$arch.tar.gz ] ; then
+
+		elif [ ! -f ${dist_version}/netboot-$arch.tar.gz ] ; then
+
+			# Daily DI vs. released netboot images
+			if [ true = "$dailydi" ] ; then
+				diurl=https://d-i.debian.org/daily-images/$arch/daily/netboot
+			else
+				diurl=${mirrorurl}/dists/${dist_codename}/main/installer-${arch}/current/images/netboot
+			fi
+
+			# Only support D-I version of the server's distro version
+			di_ver=${dist_version}
+
+			# This only supports Debian Installer netboot setup for the same version as this server.
 			if [ true = "$graphicdi" ]; then
 				# Use this URL for graphical installer, and fix
 				# gtkvideo setting below
@@ -166,16 +194,24 @@ for arch in $archs ; do
 				url=$diurl/netboot.tar.gz
 			fi
 			echo "Fetching $url"
-			if wget -q -O netboot-$arch.tar.gz.new $url ; then
-				mv netboot-$arch.tar.gz.new netboot-$arch.tar.gz
+			set +e
+			if wget -q -O netboot-$arch.tar.gz.new $url; then
+				mkdir -p ${di_ver}/
+				cd ${di_ver}
+				mv ../netboot-$arch.tar.gz.new netboot-$arch.tar.gz
 				tarball=netboot-$arch.tar.gz
 			else
-				echo "error: Unable to download $url"
-				exit 1
+				echo "warning: Unable to download $url"
+				# remove cruft
+				rm -f netboot-$arch.tar.gz.new
+				continue
 			fi
+			set -e
 		fi
 		if [ "$tarball" ] ; then
 			tar --strip-components=2 -zxvf $tarball
+			# remove downloaded netboot installer tarball
+			rm $tarball
 		fi
 		if [ true = "$graphicdi" ]; then
 			# Replace Debian installer logo with Debian Edu one.
@@ -184,19 +220,26 @@ for arch in $archs ; do
 			cd $TMP/$arch
 			mkdir new
 			cd new
-			unmkinitramfs $tftpdir/debian-installer/$arch/initrd.gz .
+			unmkinitramfs ${tftpdir}/debian-installer/${di_ver}/${arch}/initrd.gz .
 			if [ ! -z "$theme" ] ; then
-				cp /usr/share/pixmaps/$theme-installer-logo.png usr/share/graphics/logo_debian.png
+				cp /usr/share/pixmaps/debian-edu-${di_ver}-installer-logo.png usr/share/graphics/logo_debian.png
 			fi
 			find . | cpio -H newc -o > ../initrd
 			cd ..
 			gzip initrd
-			cp initrd.gz $tftpdir/debian-installer/$arch
+			cp initrd.gz ${tftpdir}/debian-installer/${di_ver}/${arch}/
 			rm -rf $TMP
 		fi
-	)
+		)
+	done
 done
 
+# We know that this script has been able to provide at least one netinstaller if its initrd.gz has been created successfully.
+if [ -z "$(find ${tftpdir}/debian-installer/*/*/initrd.gz)" ]; then
+	echo "ERROR: no D-I netboot image could be obtained, aborting further PXE setup for PXE-based Debian Installer."
+	exit 1
+fi
+
 echo "Generating $preseedfile"
 (
 	cat <<EOF
@@ -267,15 +310,19 @@ echo "Generating $menufile"
 		gtkvideo="vga=788"
 	fi
 	for arch in $archs ; do
-		cat <<EOF
+		for di_ver in ${di_versions_supported}; do
+			if [ -d "${tftpdir}/debian-installer/${di_ver}/${arch}" ]; then
+				cat <<EOF
 
 # Based upon locale, keymap and desktop values used during main-server installation; auto URL added.
-:$arch
+:${arch}_${di_ver}
 set params auto url=http://www/debian-edu-install.dat hostname=$hostname domain=$domain $installconfig $gtkvideo --- quiet
-kernel /debian-installer/$arch/linux initrd=initrd.gz \${params}
-initrd /debian-installer/$arch/initrd.gz
+kernel /debian-installer/${di_ver}/${arch}/linux initrd=initrd.gz \${params}
+initrd /debian-installer/${di_ver}/${arch}/initrd.gz
 boot || goto failed
 EOF
+			fi
+		done
 	done
 ) > $menufile
 
@@ -287,14 +334,19 @@ fi
 if [ -f $tftpdir/ltsp/ltsp.ipxe ] ; then
 	# ltsp is installed already, modify existing ipxe menu
 	if ! grep -q main-server $tftpdir/ltsp/ltsp.ipxe ; then
-	echo "Modifying $tftpdir/ltsp/ltsp.ipxe"
-	sed -i '/^menu.*/ a item\
+		echo "Modifying $tftpdir/ltsp/ltsp.ipxe"
+
+		# FIXME: also support other installer versions here, currently only latest version gets
+		# integrated into LTSP servers ltsp.ipxe file.
+
+		sed -i "/^menu.*/ a item\
 item --gap                        Installation:\
-item --key a amd64                Install Debian Edu/amd64 (64-Bit)\
-item --key i i386                 Install Debian Edu/i386  (32-Bit)\
+item --key a amd64_${dist_version} Install Debian Edu ${dist_version} / amd64 (64-Bit)\
+# BEGIN: Debian-Installer other versions
+# END: Debian-Installer other versions
 item\
-' /srv/tftp/ltsp/ltsp.ipxe
-	cat $menufile >> $tftpdir/ltsp/ltsp.ipxe
+" ${tftpdir}/ltsp/ltsp.ipxe
+		cat $menufile >> $tftpdir/ltsp/ltsp.ipxe
 	fi
 else
 	# generate ipxe menu on a plain main server for PXE installations
@@ -304,13 +356,15 @@ else
 	cp /boot/memtest86+ia32.bin $tftpdir/ltsp/memtest.0
 	cp /boot/memtest86+x64.efi $tftpdir/ltsp/memtest.efi
 	echo "Generating $tftpdir/ltsp/ltsp.ipxe"
-	cat <<EOF > /srv/tftp/ltsp/ltsp.ipxe
+	cat <<EOF > ${tftpdir}/ltsp/ltsp.ipxe
 #!ipxe
 #
 # Configure iPXE for network installations
 
+console --picture /debian-edu/debian-edu-pxe.png ||
+
 # Set the default image (img) based on arch, or to root-path if it's not empty
-cpuid --ext 29 && set img amd64 || set img i386
+cpuid --ext 29 && set img amd64_${dist_version} || set img i386_${dist_version}
 
 goto start
 
@@ -321,8 +375,10 @@ iseq "\${menu-timeout}" "-1" && goto \${img} ||
 menu Debian Edu iPXE boot menu || goto \${img}
 item
 item --gap                        Debian Edu installation:
-item --key a amd64                Install Debian Edu/amd64 (64-Bit)
-item --key i i386                 Install Debian Edu/i386  (32-Bit)
+item --key a amd64_${dist_version} Install Debian Edu ${dist_version} / amd64
+item
+# BEGIN: Debian-Installer other versions
+# END: Debian-Installer other versions
 item
 item --gap                        Other options:
 item --key m memtest              Memory test
@@ -369,3 +425,23 @@ EOF
 	fi
 fi
 
+# Insert other Debian-Installer versions, if any.
+if [ "${dist_version}" != "${di_versions_supported}" ]; then
+	# We have more D-I netboot versions installed, so inject them into the iPXE boot menu
+	for di_ver in ${di_versions_supported}; do
+		for arch in ${archs}; do
+			if [ "${di_ver}" = "${dist_version}" ]; then
+				# we already have this, see above
+				:
+			else
+				if [ -d $tftpdir/debian-installer/${di_ver}/${arch} ]; then
+					sed -i "/^# END: Debian-Installer other versions/i \
+item ${arch}_${di_ver}         Install Debian Edu ${di_ver} / ${arch}\
+" ${tftpdir}/ltsp/ltsp.ipxe
+				fi
+			fi
+		done
+	done
+else
+	sed -E -i "${tftpdir}/ltsp/ltsp.ipxe" -e "/# (BEGIN|END): Debian-Installer other versions/d"
+fi


=====================================
share/debian-edu-config/tools/pxe-addfirmware
=====================================
@@ -1,74 +1,100 @@
 #!/bin/sh
 #
-# Adds (non-free) firmware to the debian-installer initrd used by the
+# Adds (non-free-firmware) firmware to the debian-installer initrd used by the
 # PXE installation to make sure it works on more hardware out of the
 # box.
 
 set -e
 
-add_firmware_to_initrd() {
-    initrd=$1
+export TMPDIR=/var/tmp
 
-    tmpdir=$(mktemp -d)
-    cd $tmpdir
+echo Finding and downloading firmware .debs
+# Find files. This requires non-free-firmware to be enabled as APT
+# repository.
+# Skip installer debs to avoid the b43 installers that conflict
+# with each other.
+# For bookworm, also exclude firmware-microbit-micropython{-dl}.
+# For trixie, exclude various other 'huge' firmware packages and metadata packages.
+# FIXME Review if this needs to be adjusted after trixie.
+debnames="$(apt-cache search ^firmware-.* | grep -v installer \
+                                  | grep -v firmware-micropython \
+                                  | grep -v firmware-nvidia \
+                                  | grep -v firmware-qcom \
+                                  | grep -v firmware-marvell-prestera \
+                                  | grep -v firmware-linux-nonfree \
+                                  | grep -v firmware-linux \
+                                  | grep -v fxload \
+                                  | grep -v dfu-util \
+                                  | grep -v ap51-flash \
+                                  | cut -d" " -f1)"
 
-    echo Finding and downloading firmware .debs
-    # Find files. This requires non-free to be enabled as APT
-    # repository.
-    # Skip installer debs to avoid the b43 installers that conflict
-    # with each other.
-    # For bookworm, also exclude firmware-microbit-micropython{-dl}.
-    # FIXME Review if this is still needed after bookworm.
-    debnames="$(apt-cache search ^firmware-.* | grep -v installer | grep -v micropython | cut -d" " -f1)"
+# Allow caller to ask for extra debs using environment variable
+debnames="$debnames $FIRMWAREDEBNAMES"
 
-    # Allow caller to ask for extra debs using environment variable
-    debnames="$debnames $FIRMWAREDEBNAMES"
+add_firmware_to_initrd() {
+	initrd=$1
 
-    apt-get --download-only -y -q install $debnames
+	tmpdir=$(mktemp -d)
+	cd $tmpdir
 
-    # Find firmware .deb files
-    for name in $debnames ; do
-	for deb in /var/cache/apt/archives/${name}_* ; do
-	    if [ -f $deb ] ; then
-		debs="$debs $deb"
-	    fi
+	# Find firmware .deb files
+	for name in $debnames ; do
+		for deb in /var/cache/apt/archives/${name}_* ; do
+			if [ -f $deb ] ; then
+				debs="$debs $deb"
+			fi
+		done
 	done
-    done
 
-    echo Unpacking current initrd
-    gunzip < $initrd | cpio --quiet -id
+	echo Unpacking current initrd
+	gunzip < $initrd | cpio --quiet -id
 
-    echo Unpacking firmware files, overwriting any in the original initrd
-    for deb in $debs ; do
-	if ar p $deb data.tar.gz | tar zxf - ./lib/firmware/ >/dev/null 2>&1 ; then
-            :
-        else
-            echo "Ignoring $deb without /lib/firmware/"
-        fi
-    done
+	echo Unpacking firmware files, overwriting any in the original initrd
+	for deb in $debs ; do
+		data_tarball="$(ar t $deb | grep data.tar.)"
+		if ar p ${deb} ${data_tarball} > ${data_tarball} && tar axf ${data_tarball} ./usr/lib/firmware ; then
+			:
+			# and clean up...
+			rm ${data_tarball}
+		else
+			echo "Ignoring $deb without /usr/lib/firmware/"
+		fi
+	done
 
-    timestamp=$(date +%Y%m%dT%H:%M)
-    echo Wrapping up new initrd
-    find . | cpio --quiet -o -H newc | gzip -9 > $initrd.new &&
-        mv $initrd $initrd.old-$timestamp &&
-        mv $initrd.new $initrd
-    cd /
-    rm -rf $tmpdir
+	timestamp=$(date +%Y%m%dT%H:%M)
+	echo Wrapping up new initrd
+	echo $(pwd)
+	echo ${initrd}.new
+	find . | cpio --quiet -o -H newc | gzip -9 > $initrd.new &&
+	    mv $initrd $initrd.old-$timestamp &&
+	    mv $initrd.new $initrd
+	    cd /
+	    rm -rf $tmpdir
 }
 
 if [ "$1" ] ; then
-    diroot="$1"
+	diroot="$1"
 fi
 
 # Path to where the d-i pxe boot images were unpacked
 if [ -z "$diroot" ] ; then
-    diroot=/srv/tftp/debian-installer
+	diroot=/srv/tftp/debian-installer
 fi
 
-for initrd in $diroot/*/initrd.gz ; do
-    if [ -e $initrd ] ; then
-        add_firmware_to_initrd "$initrd"
-    else
-        echo "Unable to open $initrd"
-    fi
+# Retrieve .deb packages that we will extract firmware files from.
+apt-get --download-only --no-install-recommends -y -q install $debnames
+
+# We will use firmware files available for this host's Debian version for
+# all Debian-Installer initrd files (also for older/newer D-I versions).
+# For older D-I versions, this will likely work well.
+# FIXME: For newer D-I versions, we need to find a better solution at some point
+# (e.g. debootstrap a minimal system based on the D-I version and obtain the
+# firmware files into that chroot, FTR: firmware packages are arch:all, so only
+# one amd64 chroot for Debian version based downloads are sufficient).
+for initrd in $diroot/*/*/initrd.gz ; do
+	if [ -e $initrd ] ; then
+		add_firmware_to_initrd "$initrd"
+	else
+		echo "Unable to open $initrd"
+	fi
 done


=====================================
share/debian-edu-config/tools/run-at-firstboot
=====================================
@@ -114,7 +114,7 @@ fi
 # we would have to wait for the weekly cron job to run before golearn
 # was usable.
 if [ -x /usr/sbin/update-apt-xapian-index ] ; then
-	dpkg-reconfigure apt-xapian-index
+	DEBCONF_FRONTEND=noninteractive dpkg-reconfigure apt-xapian-index
 else
 	info "apt-xapian-index/goplay is not installed"
 fi



View it on GitLab: https://salsa.debian.org/debian-edu/debian-edu-config/-/compare/f146fa7f0fa4d5a7e2e4cbfc59d471a6b82c1682...dfdd806e2360044a419929ee93b28a25ea761020

-- 
View it on GitLab: https://salsa.debian.org/debian-edu/debian-edu-config/-/compare/f146fa7f0fa4d5a7e2e4cbfc59d471a6b82c1682...dfdd806e2360044a419929ee93b28a25ea761020
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-edu-commits/attachments/20260925/78edd0be/attachment-0001.htm>


More information about the debian-edu-commits mailing list