| -rw-r--r-- | Jenkinsfile | 1 | ||||
| -rw-r--r-- | README.md | 46 | ||||
| -rw-r--r-- | components/boot.xml | 2 | ||||
| -rwxr-xr-x | config.sh | 35 | ||||
| -rw-r--r-- | docs/Fedora45Progress.jpg | bin | 2694880 -> 0 bytes | |||
| -rw-r--r-- | iio-qipcrtr.pp | bin | 1288 -> 0 bytes | |||
| -rw-r--r-- | iio-qipcrtr.te | 20 | ||||
| -rw-r--r-- | root/tmp/SayaAndy/surface-pro-12-inch-linux-fedora/etc/dconf/db/local.d/00-power-button (renamed from root/tmp/SayaAndy/surface-pro-12-inch-linux-fedora/etc/dconf/db/local.d/00-als) | 2 | ||||
| -rw-r--r-- | root/tmp/SayaAndy/surface-pro-12-inch-linux-fedora/etc/systemd/system/hexagonrpc.service | 3 | ||||
| -rw-r--r-- | root/tmp/SayaAndy/surface-pro-12-inch-linux-fedora/etc/udev/rules.d/61-sensors-surface-pro-12-inch.rules | 4 | ||||
| -rw-r--r-- | root/tmp/SayaAndy/surface-pro-12-inch-linux-fedora/etc/yum.repos.d/kernel-sp12in.repo | 7 | ||||
| -rw-r--r-- | root/tmp/SayaAndy/surface-pro-12-inch-linux-fedora/usr/local/share/selinux/iio-qipcrtr.te | 19 |
12 files changed, 26 insertions, 113 deletions
diff --git a/Jenkinsfile b/Jenkinsfile index 1732307..9662632 100644 --- a/Jenkinsfile +++ b/Jenkinsfile @@ -151,7 +151,6 @@ spec: ls -lh /s5cmd --endpoint-url "${B2_ENDPOINT}" cp \\ - --content-type "application/x-iso9660-image" \\ "${dst}" \\ "s3://${ISO_BUCKET}/fedora/${IMAGE_VERSION}/aarch64/${dst}" ''' @@ -1,13 +1,9 @@ # Fedora KIWI image descriptions, modified to build & launch for Surface Pro 12" Gen 1 - - -**UPD Sep 10 2026:** There has been huge progress made in this project since August! Thanks to kernel patches, pushed onto Linux 7.2 mainstream and [Gentoo overlay](https://github.com/miasvanklei/Gentoo-overlay), most of the previous features which this release lacked (stable suspend on GNOME, accelerometer sensor, dedicated video output, cameras) are now implemented. The project has diverged into [patched kernel](https://sayag.it/fedora-linux-surface-pro-12in/kernel-surface.git) + [libcamera](https://sayag.it/fedora-linux-surface-pro-12in/libcamera.git) builds with an [RPM repo](https://rpm.sayag.it/kernel-sp12in/) publicly available. You can see current state of things in a [feature matrix](#feature-matrix) down below. -  -It is the fork of the original [KIWI image descriptions](https://forge.fedoraproject.org/releng/kiwi-descriptions), modified for launching Fedora Linux 45 Live ISO on Surface Pro 12" Gen 1 (and further installing it on the device). +It is the fork of the original [KIWI image descriptions](https://forge.fedoraproject.org/releng/kiwi-descriptions), modified for launching Fedora Linux Rawhide Live ISO on Surface Pro 12" Gen 1 (and further installing it on the device). I bought this device as I viewed it as a great Linux GNOME tablet, but after several days, many hours of work of trying to do so, I must say that installing a distribution here (and then having it work fine) is a huge pain in the ass. @@ -15,9 +11,9 @@ I bought this device as I viewed it as a great Linux GNOME tablet, but after sev ## How to run -**The compiled ISOs can be downloaded [here](https://dist.sayag.it/fedora/45/aarch64).** +**The compiled ISOs can be downloaded [here](https://dist.sayag.it/surface-pro-12in-ports/fedora/rawhide).** -This KIWI project is built mainly on the base of Fedora Workstation 45 (Pre-release) LiveCD ISO. Trying a stable version (the latest is Fedora 44 at the time of writing this) is possible, but not tested for now. +This KIWI project is built mainly on the base of Fedora Workstation Rawhide LiveCD ISO. Trying a stable version (the latest is Fedora 44 at the time of writing this) is possible, but not tested for now. If you want to compile this image manually, **the build arch must be `aarch64`**. It means that if you are on an `amd64` machine, you would have to use aarch64 instructions emulation tools like `binfmt`. Unfortunately, such a tool will drastically increase the compilation time. @@ -34,29 +30,7 @@ To build this on Fedora Linux: []$ sudo ./kiwi-build --kiwi-file=Fedora.kiwi --image-type=iso --image-profile=Workstation-Live --output-dir ./outdir ``` -## Feature matrix - -| Hardware | State | Nuances | -| --- | --- | --- | -| Keyboard | ✓ | | -| Touchpad | ✓ | | -| Tablet Mode | ✓ | | -| Touchscreen | ✓ | | -| Pen | ✓ | Tested with Surface Slim Pen | -| WiFi | ✓ | 2.4/5 GHz networks | -| Bluetooth | ✓ | | -| Speakers | ✓ | | -| Buttons | ✓ | | -| Suspend | ✓ | `s2idle` tested | -| Hibernate | ? | | -| Sensors | ✓ | Accelerometer works, but light sensor outputs garbage, so adaptive brightness is disabled | -| Battery Status | ✓ | | -| Cameras | ✓ | Front camera -- overexposured areas tend to get green; back camera -- uncalibrated | -| GPU acceleration | ✓ | Video encoding/decoding driver is taken dynamically from a Windows partition | -| USB 3 | ✓ | Video passthrough on hubs (via HDMI) also tested and works | -| DisplayPort out | ✓ | Found issues with suspending while an external monitor is active, where the system freezes | - -## Compromises +## What is left out (for now) * Live CD has to run in RAM, so `rd.live.ram=1` is set for cmdline. Otherwise, at least on my ancient flash drive, it fails to load multiple necessary services, including `polkit`. So, ~5 minutes of loading on USB 2 drive, while screen is not backlit, is to be expected. * No rescue vmlinuz. @@ -64,17 +38,21 @@ To build this on Fedora Linux: * No GRUB auto hidden menu. Trying to have the menu hidden results in system restarting after trying to boot it. * Hardware video encoding/decoding needs a firmware blob the image is not allowed to ship. The `qcom/vpu/vpu30_p1_s7.mbn` that `linux-firmware` provides is the same codec signed with Qualcomm's SecTools *test* key chain, which a retail Surface's TrustZone rejects -- `qcom_scm_pas_init_image()` fails and the kernel logs `qcom-iris aa00000.video-codec: error -22 initializing firmware`. The production-signed build exists only inside Microsoft's Surface driver package, which grants no redistribution right, so what ships here is the means and not the blob: * If you kept the Windows ARM64 partition, `surface-video-firmware.service` finds it on the first boot after install and copies `qcvss8380_pa.mbn` out of its DriverStore. Nothing to do. - * If Windows is gone, download the [Surface Pro 12-inch driver pack](https://www.microsoft.com/en-us/download/details.aspx?id=108199) (~500 MB MSI) and run `sudo surface-video-firmware.sh -m /path/to/SurfacePro_12in_*.msi`. + * If Windows is gone, download the [Surface Pro 12-inch driver pack](https://www.microsoft.com/en-us/download/details.aspx?id=108199) (~500 MB MSI) and run `sudo surface-video-firmware.sh -m /path/to/SurfacePro_12in_*.msi`. There is no automatic download: the Download Center hands out per-session links. The kernel's device tree already points `iris` at `/lib/firmware/qcom/x1p42100/Microsoft/Surface12/qcvss8380_pa.mbn`, so the driver picks it up as soon as it is there. -* Explicitly set `s2idle` suspend mode, as `deep` mode did not work properly as of August (when the iso was built without kernel patches). Currently untested if `deep` mode works now. -* No 6 GHz network support (at least my device does not detect mine). -* Adaptive brightness is disabled, as of now the light sensor outputs garbage. +* Suspend on Snapdragon X is still very unstable. No deep sleep is available, so `mem_sleep_default=s2idle` was set. Even that leads to compromises as suspending via GNOME results in hard freeze, so the default power button behavior was changed to `interactive` and should not be changed back to `suspend`. ## Image variants Please look at [`VARIANTS`](VARIANTS.md) for details on the available configurations that can be built. +## CI information + +This project is yet to adapt CI, but it is coming. + +For now the images are being built and tested manually on my personal Surface Pro 12" Gen 1 (16 GB RAM, 512 GB storage). + ## Licensing This is free software: you can redistribute it and/or modify diff --git a/components/boot.xml b/components/boot.xml index 11b48a5..36d8ffa 100644 --- a/components/boot.xml +++ b/components/boot.xml @@ -50,7 +50,7 @@ set for this board (device tree, SAM RTC, SAM suspend workaround, CAMSS/CSI-2, remoteproc attach, clk/PCI/irqchip fixes). It is built from the sibling ../kernel-surface checkout and comes from the repository - repositories/kernel-sp12in.xml adds. + repositories/kernel-surface.xml adds. It is a single package (kernel image, every module, device trees) and Provides kernel, kernel-core, kernel-modules, kernel-modules-core and @@ -436,9 +436,6 @@ fi # Surface Pro 12" customizations #-------------------------------------- -install -Dm644 /tmp/SayaAndy/surface-pro-12-inch-linux-fedora/etc/yum.repos.d/kernel-sp12in.repo \ - /etc/yum.repos.d/kernel-sp12in.repo - # Device tree. kernel-surface compiles the patched dts in-tree and installs the # result twice: into its own module tree (dtb/qcom, from dtbs_install) and into # /usr/lib/surface-dtb/<kver>/. The latter is the master copy @@ -644,22 +641,6 @@ install -Dm644 /tmp/SayaAndy/surface-pro-12-inch-linux-fedora/etc/systemd/system # hexagonrpc.service in through the drop-in above. systemctl enable hexagonrpc.service -# Fedora's SELinux policy has no qipcrtr_socket permissions for -# iiosensorproxy_t; the libssc backend needs them to probe the QRTR bus, and -# without them the daemon exits with "No sensors or missing kernel drivers". -# Compile and install the local module that grants them (see the .te for -# details). checkmodule/semodule_package come from checkpolicy; it stays -# installed because removing it takes policycoreutils-python-utils -# (semanage, audit2allow) with it. -dnf install -y checkpolicy -install -Dm644 /tmp/SayaAndy/surface-pro-12-inch-linux-fedora/usr/local/share/selinux/iio-qipcrtr.te \ - /usr/local/share/selinux/iio-qipcrtr.te -checkmodule -M -m -o /usr/local/share/selinux/iio-qipcrtr.mod \ - /usr/local/share/selinux/iio-qipcrtr.te -semodule_package -o /usr/local/share/selinux/iio-qipcrtr.pp \ - -m /usr/local/share/selinux/iio-qipcrtr.mod -semodule -i /usr/local/share/selinux/iio-qipcrtr.pp - # Cameras (msm/camss). Nothing has to be wired up at boot. libcamera's "simple" # pipeline handler claims qcom-camss and builds the media graph itself in # configure(), including flipping the csiphy -> msm_csid0 link between the rear @@ -709,19 +690,23 @@ install -Dm644 /tmp/SayaAndy/surface-pro-12-inch-linux-fedora/etc/systemd/system /etc/systemd/system/surface-video-firmware.service systemctl enable surface-video-firmware.service +# Suspend on Snapdragon is still very unstable. This is the reason why +# 'mem_sleep_default=s2idle' is set explicitly in the cmdline as 'deep' mode +# does not function at all. +# Even then, suspending via gnome settings daemon results in hard freeze. +# This is why: +# logind behavior is kept intact with suspend behavior. +# gnome default power button behavior was replaced with 'interactive'. install -Dm644 /tmp/SayaAndy/surface-pro-12-inch-linux-fedora/etc/systemd/logind.conf.d/60-surface-power-key.conf \ /etc/systemd/logind.conf.d/60-surface-power-key.conf - -# Ambient light sensor seems to go nuts after I fixed iio-sensor-proxy. Turning -# it off for now. -install -Dm644 /tmp/SayaAndy/surface-pro-12-inch-linux-fedora/etc/dconf/db/local.d/00-als \ - /etc/dconf/db/local.d/00-als +install -Dm644 /tmp/SayaAndy/surface-pro-12-inch-linux-fedora/etc/dconf/db/local.d/00-power-button \ + /etc/dconf/db/local.d/00-power-button install -Dm644 /tmp/SayaAndy/surface-pro-12-inch-linux-fedora/etc/dconf/profile/user \ /etc/dconf/profile/user dconf update -restorecon -Rv /usr /lib /etc/systemd /etc/dconf /etc/udev/rules.d /etc/yum.repos.d +restorecon -Rv /usr /lib /etc/systemd /etc/dconf /etc/udev/rules.d #====================================== # Set the WSL name for ELN diff --git a/docs/Fedora45Progress.jpg b/docs/Fedora45Progress.jpg Binary files differdeleted file mode 100644 index 0f4a22b..0000000 --- a/docs/Fedora45Progress.jpg +++ /dev/null diff --git a/iio-qipcrtr.pp b/iio-qipcrtr.pp Binary files differdeleted file mode 100644 index 9eedadb..0000000 --- a/iio-qipcrtr.pp +++ /dev/null diff --git a/iio-qipcrtr.te b/iio-qipcrtr.te deleted file mode 100644 index 5ea7434..0000000 --- a/iio-qipcrtr.te +++ /dev/null @@ -1,20 +0,0 @@ - -module iio-qipcrtr 1.0; - -require { - type iiosensorproxy_t; - type systemd_userdbd_t; - type xdm_var_run_t; - class sock_file read; - class qipcrtr_socket { create getattr getopt setopt }; -} - -#============= iiosensorproxy_t ============== - -#!!!! This avc is allowed in the current policy -allow iiosensorproxy_t self:qipcrtr_socket { create getattr getopt setopt }; - -#============= systemd_userdbd_t ============== - -#!!!! This avc is allowed in the current policy -allow systemd_userdbd_t xdm_var_run_t:sock_file read; diff --git a/root/tmp/SayaAndy/surface-pro-12-inch-linux-fedora/etc/dconf/db/local.d/00-als b/root/tmp/SayaAndy/surface-pro-12-inch-linux-fedora/etc/dconf/db/local.d/00-power-button index ae14928..1b69eab 100644 --- a/root/tmp/SayaAndy/surface-pro-12-inch-linux-fedora/etc/dconf/db/local.d/00-als +++ b/root/tmp/SayaAndy/surface-pro-12-inch-linux-fedora/etc/dconf/db/local.d/00-power-button @@ -1,2 +1,2 @@ [org/gnome/settings-daemon/plugins/power] -ambient-enabled=false +power-button-action='interactive' diff --git a/root/tmp/SayaAndy/surface-pro-12-inch-linux-fedora/etc/systemd/system/hexagonrpc.service b/root/tmp/SayaAndy/surface-pro-12-inch-linux-fedora/etc/systemd/system/hexagonrpc.service index 4ec7250..2e3cf82 100644 --- a/root/tmp/SayaAndy/surface-pro-12-inch-linux-fedora/etc/systemd/system/hexagonrpc.service +++ b/root/tmp/SayaAndy/surface-pro-12-inch-linux-fedora/etc/systemd/system/hexagonrpc.service @@ -1,9 +1,8 @@ [Unit] Description=HexagonRPC Service -ConditionPathExists=/dev/fastrpc-adsp [Service] -ExecStart=/usr/local/bin/hexagonrpcd -f /dev/fastrpc-adsp -d adsp -s +ExecStart=/usr/local/bin/hexagonrpcd -f /dev/fastrpc-adsp-secure -s Restart=on-failure [Install] diff --git a/root/tmp/SayaAndy/surface-pro-12-inch-linux-fedora/etc/udev/rules.d/61-sensors-surface-pro-12-inch.rules b/root/tmp/SayaAndy/surface-pro-12-inch-linux-fedora/etc/udev/rules.d/61-sensors-surface-pro-12-inch.rules index 82051c5..e6ddb1f 100644 --- a/root/tmp/SayaAndy/surface-pro-12-inch-linux-fedora/etc/udev/rules.d/61-sensors-surface-pro-12-inch.rules +++ b/root/tmp/SayaAndy/surface-pro-12-inch-linux-fedora/etc/udev/rules.d/61-sensors-surface-pro-12-inch.rules @@ -1,3 +1 @@ -ACTION=="add|change", SUBSYSTEM=="misc", KERNEL=="fastrpc-adsp*", ENV{ACCEL_MOUNT_MATRIX}="-1, 0, 0; 0, -1, 0; 0, 0, 1" -SUBSYSTEM=="misc", KERNEL=="fastrpc-adsp*", ENV{IIO_SENSOR_PROXY_TYPE}+="ssc-accel" -ACTION=="add", SUBSYSTEM=="misc", KERNEL=="fastrpc-adsp", TAG+="systemd", ENV{SYSTEMD_WANTS}+="hexagonrpc.service" +ACTION=="add|change", SUBSYSTEM=="misc", KERNEL=="fastrpc-adsp-secure", ENV{ACCEL_MOUNT_MATRIX}="-1, 0, 0; 0, -1, 0; 0, 0, 1" diff --git a/root/tmp/SayaAndy/surface-pro-12-inch-linux-fedora/etc/yum.repos.d/kernel-sp12in.repo b/root/tmp/SayaAndy/surface-pro-12-inch-linux-fedora/etc/yum.repos.d/kernel-sp12in.repo deleted file mode 100644 index 24fe9f3..0000000 --- a/root/tmp/SayaAndy/surface-pro-12-inch-linux-fedora/etc/yum.repos.d/kernel-sp12in.repo +++ /dev/null @@ -1,7 +0,0 @@ -[kernel-sp12in] -name=kernel-sp12in for Fedora $releasever - $basearch -baseurl=https://rpm.sayag.it/kernel-sp12in/fedora/$releasever/$basearch/ -enabled=1 -priority=1 -gpgcheck=0 -metadata_expire=6h diff --git a/root/tmp/SayaAndy/surface-pro-12-inch-linux-fedora/usr/local/share/selinux/iio-qipcrtr.te b/root/tmp/SayaAndy/surface-pro-12-inch-linux-fedora/usr/local/share/selinux/iio-qipcrtr.te deleted file mode 100644 index b3be8fb..0000000 --- a/root/tmp/SayaAndy/surface-pro-12-inch-linux-fedora/usr/local/share/selinux/iio-qipcrtr.te +++ /dev/null @@ -1,19 +0,0 @@ -module iio-qipcrtr 1.0; - -# Fedora's policy grants iiosensorproxy_t no qipcrtr_socket permissions at -# all: the class exists but nothing allows it, because upstream -# iio-sensor-proxy talks to sensors over IIO and never needed QRTR. The SSC -# backend libssc brings in here reaches the Qualcomm Sensor Core over the -# QRTR bus (libssc probes AF_QIPCRTR first; the fastrpc/hexagonrpcd path is -# what actually serves this board, but the probe alone gets the daemon -# killed by "QRTR bus unavailable" + "No sensors" without these perms). -# -# Hand-written rather than audit2allow'd per-incident: create/bind/... is -# the full client lifecycle, so a policy reload or libssc update cannot -# surface a new denied perm one at a time. -require { - type iiosensorproxy_t; - class qipcrtr_socket { create bind connect read write getattr setattr getopt setopt shutdown }; -} - -allow iiosensorproxy_t self:qipcrtr_socket { create bind connect read write getattr setattr getopt setopt shutdown }; |