Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
Getting Your Customized openSUSE Kernel on OBS
Search
shunghsiyu
November 02, 2024
Technology
0
180
Getting Your Customized openSUSE Kernel on OBS
Presented at openSUSE.Asia Summit 2024
shunghsiyu
November 02, 2024
Tweet
Share
More Decks by shunghsiyu
See All by shunghsiyu
管你要 trace 什麼、bpftrace 用下去就對了 — COSCUP 2025
shunghsiyu
0
650
管你要 trace 什麼 bpftrace 用下去就對了 (KaLUG場)
shunghsiyu
0
33
What is an ABI, and Why Should You Care?
shunghsiyu
0
14
Making Sense of Tristate Numbers (tnum)
shunghsiyu
0
12
BPF in Stable Kernels
shunghsiyu
0
130
Peeking into the BPF verifier
shunghsiyu
0
57
ABI 是什麼?跟 API 不一樣嗎?
shunghsiyu
0
200
Value tracking in BPF verifier
shunghsiyu
0
160
Model Checking (what may become part of) the BPF Verifier
shunghsiyu
0
84
Other Decks in Technology
See All in Technology
データの整合性を保ちたいだけなんだ
shoheimitani
8
3.1k
変化するコーディングエージェントとの現実的な付き合い方 〜Cursor安定択説と、ツールに依存しない「資産」〜
empitsu
4
1.4k
AWS Network Firewall Proxyを触ってみた
nagisa53
1
240
usermode linux without MMU - fosdem2026 kernel devroom
thehajime
0
240
Ruby版 JSXのRuxが気になる
sansantech
PRO
0
160
Amazon S3 Vectorsを使って資格勉強用AIエージェントを構築してみた
usanchuu
3
450
AzureでのIaC - Bicep? Terraform? それ早く言ってよ会議
torumakabe
1
570
CDK対応したAWS DevOps Agentを試そう_20260201
masakiokuda
1
330
Introduction to Sansan for Engineers / エンジニア向け会社紹介
sansan33
PRO
6
68k
Digitization部 紹介資料
sansan33
PRO
1
6.8k
Bedrock PolicyでAmazon Bedrock Guardrails利用を強制してみた
yuu551
0
240
30万人の同時アクセスに耐えたい!新サービスの盤石なリリースを支える負荷試験 / SRE Kaigi 2026
genda
4
1.3k
Featured
See All Featured
I Don’t Have Time: Getting Over the Fear to Launch Your Podcast
jcasabona
34
2.6k
CSS Pre-Processors: Stylus, Less & Sass
bermonpainter
359
30k
Conquering PDFs: document understanding beyond plain text
inesmontani
PRO
4
2.3k
Exploring the Power of Turbo Streams & Action Cable | RailsConf2023
kevinliebholz
37
6.3k
ReactJS: Keep Simple. Everything can be a component!
pedronauck
666
130k
Sharpening the Axe: The Primacy of Toolmaking
bcantrill
46
2.7k
Learning to Love Humans: Emotional Interface Design
aarron
275
41k
Measuring Dark Social's Impact On Conversion and Attribution
stephenakadiri
1
130
VelocityConf: Rendering Performance Case Studies
addyosmani
333
24k
Navigating the moral maze — ethical principles for Al-driven product design
skipperchong
2
250
Beyond borders and beyond the search box: How to win the global "messy middle" with AI-driven SEO
davidcarrasco
1
53
Ruling the World: When Life Gets Gamed
codingconduct
0
140
Transcript
How to Maintaining a Linux Kernel Package on openSUSE's Open
Build Service Getting Your Customized openSUSE Kernel on OBS Shung-Hsi Yu, SUSE @shunghsiyu @
[email protected]
About me Shung-Hsi Yu SUSE Based in Taitung, Taiwan Kernel
Engineer BPF Subsystem openSUSE SUSE Enterprise Linux
Agenda - Backgrounds - Problems & Rational - How to
Customize (the Kernel) - Comparisons (of methods) - Takeaways
Backgrounds
Linux Kernel - Core of the system - Talks to
hardware (w/ drivers) - Provide abstractions/features
Open Build Service (OBS) - Build Service - Produce RPM
packages - Compile source code to binaries - Hosts RPM packages
Open Build Service (OBS) Interface - API - osc command-line
tool - WebUI
None
Problems
Additional Feature You want additional security hardening with ABC feature,
however due to performance impact it is disabled in openSUSE’s kernel # CONFIG_ABC is not set
Unsupported Hardware You have XZY device, but openSUSE’s kernel cannot
use it because support is not enabled # CONFIG_XZY is not set
Unsupported Hardware You have XZY device, but openSUSE’s kernel cannot
use it because the driver’s source code is not upstream
Distributing and Installation You have built a kernel on your
laptop, now you need to have it installed on all your machines
Updating the Kernel There a critical security bug the was
fixed, do you have to go through the same again?
Rational
Why Customize? - Missing features / hardware support - Disabled
- Not available - Too many features / hardware support - Security - Size
Why NOT Customize? - Support on your own - Untested
Why use OBS? - Builds RPM packages for you -
Make package distribution easy (and secure) - Works well with openSUSE distros - Support many architectures
How to Customize Overview
#1 - {patches,config}.addon - the “default” way to do customization
- patch and config managed in OBS - OBS keeps it updated (w/ link)
#2 - kernel-$FLAVOR.spec - lightweight customization - single RPM specification
file - repackaging of existing RPM
#3 - fork kernel-source.git - openSUSE/SUSE kernel team’s workflow -
patches and config managed with git repository
How to Customize #1 - {patches,config}.addon
Setup Requirements - osc (cmdline) / web browser - tar
& gzip bzip2 (cmdline) / GUI archiver - (optional) diff
Workflow (changing config) 1. Branch kernel-default project on OBS 2.
Create config.addon.tar.bz2 3. Upload to your branched kernel-default OBS project
Config Modification $ tree config.addon/ config.addon/ ├── arm64 │ └──
default └── x86_64 └── default
Config Modification $ cat config.addon/x86_64/default CONFIG_XYZ=y ...
Workflow (generating patches) 1. Download source code of kernel.git 2.
Extract 3. Modify 4. diff
Workflow (adding patches) 1. Branch kernel-default project on OBS 2.
Create patches.addon.tar.bz2 3. Upload to your branched kernel-default OBS project
Code Modification $ tree . 0001-support-XZY.patch series
Code Modification $ cat 0001-support-XZY.patch --- a/drivers/XYZ/main.c +++ b/drivers/XYZ/main.c @@
-93,7 +93,7 @@ ... $ cat series 0001-support-XZY.patch
How to Customize #2 - kernel-$FLAVOR.spec
Setup Requirements - osc (cmdline) / web browser
Workflow (changing spec) 1. Branch kernel-default-base project on OBS 2.
Modify kernel-default-base.spec 3. (optional) Rename spec file and project
Module Modification $ cat kernel-default-base.spec ... define filesystems autofs4 btrfs
ext4 fuse vfat \ isofs jbd2 mbcache nfsv2 ... %define modules %usb_modules %net_drivers \ %scsi_modules %block_drivers hyperv_modules %virtio_modules %vmware_modules %xen_modules ...
How to Customize #3 - fork kernel-source.git
Setup Requirements - osc - git - quilt - diff
- …
Workflow (adding patches) 1. Clone kernel-source.git 2. cd kernel-source 3.
sequence-patch.sh 4. cd tmp/current 5. add new patch with quilt
Workflow (adding patches) 6. quilt edit 7. refresh_patch.sh 8. cd
patches (kernel-source) 9. log 10. (optional) git push …
Workflow (upload) Push changes to OBS $OBS_BRANCH=home:$USER:branches:Leap:15.6:Update $FLAVOR=default scripts/tar-up.sh scripts/osc_wrapper
upload --enable-debug "$OBS_BRANCH" ./kernel-source/kernel-default.spec
Comparisons
#1 - {config,patches}.addon The Good - good balance between easiness
and flexibility The Bad - some chance of patch failing to apply
#2 - kernel-$FLAVOR.spec The Good - easy, super fast to
build package - identical binaries - low maintenance The Bad - not flexible, can’t add feature / hardware support
#3 - fork kernel-source.git The Good - very flexible -
remove existing patch and or add new upstream patch - scales very well - many collaborators & many custom patches / changes
#3 - fork kernel-source.git The Bad - needs to be
updated manually - needs more resources / tooling - workflow is much more complex - uses command-line-only tools
Takeaways
Takeaways Sometimes you need to customize the Linux Kernel for
feature Using openSUSE’s OBS to do so save you resources and makes distributing easy
Takeaways (cont.) Start with *.addon customization move to other method
if it doesn’t work well
Appendix
Examples home:tiwai:kernel:sle15-sp6-kasan - customize kernel config with config.addon openSUSE:Leap:15.6:Update/kernel-default-base -
customize kernel-default RPM with spec file home:tiwai:kernel:drm-tip - customize kernel config with kernel-source
References - How to maintain kernel-source packages on OBS? -
How to Modify a Package in Open Build Service - openSUSE:Build Service Collaboration - openSUSE:Build Service Concept project linking - Open Build Service Beginnerʼs Guide - SUSE Kernel Site - kernel-source’s README.SUSE
None