Re: Fink 10.15 & read-only root

Remko Scharroo <[email protected]> Tue, 20 Aug 2019 10:54:14 +0200
Newsgroups gmane.os.apple.fink.devel
Message-ID <[email protected]>
Dear developers,

I would like to synthesize a few issues that came up.

1) Using /sw on 10.15 would require disabling SIP and then either change the permissions on / or mount as rw. Either way, I think disabling SIP would be a no-go territory for Fink, so /sw would need to be forsaken.

2) The directory /opt appears to be available, as John points out. Then we have the choice for /opt/sw or /opt/Fink. But since we already have a directory /sw/fink I do not think it would be nice to translate that to /opt/Fink/fink; too much "fink". So I too vote for /opt/sw.

3) As Alexander suggests, we should likely disallow alternative locations to /opt/sw. This would be a small change to fink (the program). However, I would urge to keep supporting locations in ~, since some fink users may not have admin privileges (I actually do not know if that works). So the check would need to be whether the %p directory can be created, with /opt/sw the default.

4) With a new standard location, I suspect that we would need a new package tree 10.15. We could no longer continue the 10.9-libcxx tree because then we would have mixed binaries in the 10.15/stable/main/binary-darwin-x86_64 tree; some with /sw, some with /opt/sw

5) Creating a new tree 10.15 has its advantages. a) Justin can easily pull in his big PR, without disturbing 10.9-libcxx. b) We can remove all the "Distribution:" lines in that tree. c) John can submit PRs for any other changes he already needed to make. d) A new fink can be put in there too, though the only change is likely what I mentioned in 3) above. e) All this development can start from now on (provided the 10.15 tree is created) so we can be ready when 10.15 gets officially released.

6) Those in the development of the 10.15 tree can use the suggestions by John and others and create a link /sw -> /opt/sw so they can use the old binaries for the time being.

These are just a few thoughts as an introduction to the way forward. Of course, I may be wrong about some elements, and open for suggestions.

Let's hear what you all think.

Regards,
Remko

> On 20 Aug 2019, at 03:31, Justin Hallett <[email protected]> wrote:
> 
> I vote for /opt/sw and since we will need a new bandits for it, it would be a GREAT time for a new tree and pulling in my PR
> ---
> TS
> http://www.southofheaven.org/ <http://www.southofheaven.org/>
> Life begins and ends with chaos, live between the chaos!
> 
>> On Aug 19, 2019, at 5:21 PM, Alexander Hansen <[email protected] <mailto:[email protected]>> wrote:
>> 
>> 
>> 
>>> On Aug 19, 2019, at 06:29, John Lillibridge <[email protected] <mailto:[email protected]>> wrote:
>>> 
>>> Thanks Scott,
>>> 
>>> I appreciate your instructions to disable SIP via ‘csrutil’, but that isn’t sufficient for 10.15 Catalina. The “system disk” is now split into a read-only root (/) and a read-write “Data” partition. So, if your system disk was “Mac HD”, there would be a read-only volume by that name and a read-write volume named “Mac HD - Data”. These appear as one in the Finder, and what appear to be writable directories at the root level (e.g. /usr/local) are tied together via a new APFS filetype called “firmlinks”. The current crop of these new links is found in /usr/share/firmlinks.
>>> 
>>> So it is more complicated than disabling SIP under 10.15. What I did find out, surprisingly, is that I could create /sw, and install Fink by first making the read-only filesystem read-write via:
>>> 
>>> sudo mount -o rw /
>>> 
>>> This was NOT supposed to continue working past the first beta, but as of 10.15b5 it still does work. After a reboot, the root filesystem is again read-only.
>>> 
>>> I look forward to continuing to work on this. My hope is that Apple will create a firmlink for /sw (they already provide /opt) so that everything will work as it did with 10.14 & earlier. There is no ability for users (even sudo/root) to make new firmlinks…
>>> 
>>> More to come!
>>> John L.
>> 
>> Unfortunately, that’s very unlikely.  Apple is indifferent about Fink.  We might need to switch to using /opt/Fink and to disallow alternate locations.
>> -- 
>> Alexander Hansen, Ph.D.
>> Fink User Liaison
>> 
>> 
>> 
>> _______________________________________________
>> Fink-devel mailing list
>> [email protected] <mailto:[email protected]>
>> List archive:
>> https://sourceforge.net/p/fink/mailman/fink-devel <https://sourceforge.net/p/fink/mailman/fink-devel>
>> Subscription management:
>> https://lists.sourceforge.net/lists/listinfo/fink-devel <https://lists.sourceforge.net/lists/listinfo/fink-devel>
> _______________________________________________
> Fink-devel mailing list
> [email protected]
> List archive:
> https://sourceforge.net/p/fink/mailman/fink-devel
> Subscription management:
> https://lists.sourceforge.net/lists/listinfo/fink-devel

_______________________________________________
Fink-devel mailing list
[email protected]
List archive:
https://sourceforge.net/p/fink/mailman/fink-devel
Subscription management:
https://lists.sourceforge.net/lists/listinfo/fink-devel