Author SHA1 Message Date
Bug Bounty Zip 90f06ee77b Add Kali internal IW620 WiFi support 2026-05-29 15:53:36 +03:00
Bug Bounty Zip b68aa667d1 Extend image build timeout 2026-05-27 15:22:44 +03:00
Bug Bounty Zip a1e2bc92e5 Reduce Kali release image scope 2026-05-27 15:19:17 +03:00
Bug Bounty Zip 0adaf1c6d6 Use Kali snapshot for release builds 2026-05-27 10:38:58 +03:00
Bug Bounty Zip d0efec98fe Harden self-hosted image builds 2026-05-27 09:17:16 +03:00
Bug Bounty ZipandGitHub 7f905df12c Merge pull request #11 from ps5-linux/kali-official-support
Include Kali in full image builds
2026-05-27 01:37:57 +03:00
Bug Bounty Zip daf634a6ed Include Kali in full image builds 2026-05-27 01:36:48 +03:00
Bug Bounty ZipandGitHub 703dc736e9 Merge pull request #10 from ps5-linux/fix/arch-cachyos-mirrors
Fix Arch mirror selection in image builds
2026-05-27 01:15:15 +03:00
3 changed files with 126 additions and 6 deletions
+13 -4
View File
@@ -40,7 +40,7 @@ jobs:
run: |
INPUT="${{ inputs.distro || 'ubuntu2604' }}"
if [ "$INPUT" = "all" ]; then
echo 'distros=["ubuntu2604","arch","cachyos"]' >> "$GITHUB_OUTPUT"
echo 'distros=["kali","ubuntu2604","arch","cachyos"]' >> "$GITHUB_OUTPUT"
else
echo "distros=[\"$INPUT\"]" >> "$GITHUB_OUTPUT"
fi
@@ -48,20 +48,29 @@ jobs:
build:
needs: matrix
runs-on: self-hosted
timeout-minutes: 240
timeout-minutes: 720
permissions:
contents: write
strategy:
fail-fast: false
fail-fast: true
max-parallel: 1
matrix:
distro: ${{ fromJson(needs.matrix.outputs.distros) }}
env:
CACHE_DIR: /home/opc/ccache
CCACHE_DIR: /home/opc/ccache
steps:
- name: Clean image workspace
run: |
set -euo pipefail
if [ -z "${GITHUB_WORKSPACE:-}" ] || [ "$GITHUB_WORKSPACE" = "/" ]; then
echo "Invalid GITHUB_WORKSPACE" >&2
exit 1
fi
sudo rm -rf "$GITHUB_WORKSPACE/image"
- name: Checkout image builder
uses: actions/checkout@v6
with:
+9
View File
@@ -81,6 +81,15 @@ sudo timedatectl set-timezone America/Kentucky/Louisville
timedatectl status
```
## Kali Internal WiFi
The Kali image builds and installs the PS5 IW620 `mwifiex` modules for the
PS5-patched kernel. On boot, `ps5-iw620.service` copies the console-specific
firmware dumped by `ps5-linux-loader` from `/boot/efi/lib/nxp/` into
`/lib/firmware/nxp/`, loads the driver, and enables WiFi radio. If the firmware
payload is present, NetworkManager should expose the internal interface as
`mlan0` and the Xfce network applet can be used to scan and connect.
The Kali desktop autologin is enabled for local first boot. SSH is installed
but disabled by default because the initial local account is `kali` with
password `kali`. Before enabling remote access, change that password:
+104 -2
View File
@@ -1,7 +1,8 @@
image:
name: ps5-kali
distribution: debian
release: kali-rolling
# Release images use Kali's last snapshot for stable, repeatable builds.
release: kali-last-snapshot
description: Kali Linux XFCE desktop
architecture: x86_64
@@ -21,7 +22,7 @@ packages:
repositories:
- name: sources.list
url: |-
deb https://kali.download/kali kali-rolling main contrib non-free non-free-firmware
deb https://kali.download/kali kali-last-snapshot main contrib non-free non-free-firmware
architectures:
- amd64
@@ -89,6 +90,13 @@ packages:
- curl
- wget
- git
- ca-certificates
- build-essential
- bc
- bison
- flex
- libssl-dev
- libelf-dev
- vim
- nano
- tmux
@@ -277,6 +285,100 @@ actions:
KVER=$(ls -1t /lib/modules | head -1)
depmod -a "$KVER"
# PS5 internal WiFi uses the Marvell/NXP IW620 at PCI ID 1b4b:2b56. Build
# the PS5-patched NXP mwifiex module for the installed PS5 kernel. Firmware
# is console-provided by ps5-linux-loader on the boot partition, so a boot
# service copies it into /lib/firmware before loading the module.
IW620_SRC=/tmp/ps5-iw620-mwifiex
IW620_PATCHES=/tmp/ps5-linux-mwifiex
IW620_NXP_REF=a5fe4e194bf99315e349d81d77d6dfacec70757a
IW620_PATCH_REF=5cfd063449f27e2f8a7d17c814a3bb21c27aa903
rm -rf "$IW620_SRC" "$IW620_PATCHES"
git clone https://github.com/nxp-imx/mwifiex.git "$IW620_SRC"
git -C "$IW620_SRC" checkout "$IW620_NXP_REF"
git clone https://github.com/ps5-linux/ps5-linux-mwifiex.git "$IW620_PATCHES"
git -C "$IW620_PATCHES" checkout "$IW620_PATCH_REF"
git -C "$IW620_SRC" apply "$IW620_PATCHES/ps5-iw620.patch"
make -C "$IW620_SRC" CONFIG_OBJTOOL= KERNELDIR="/lib/modules/$KVER/build" ARCH=x86 -j"$(nproc)"
test -f "$IW620_SRC/mlan.ko"
test -f "$IW620_SRC/moal.ko"
install -d "/lib/modules/$KVER/extra/ps5-iw620"
install -m 0644 "$IW620_SRC/mlan.ko" "/lib/modules/$KVER/extra/ps5-iw620/mlan.ko"
install -m 0644 "$IW620_SRC/moal.ko" "/lib/modules/$KVER/extra/ps5-iw620/moal.ko"
install -d /etc/modprobe.d /usr/local/sbin /etc/systemd/system /usr/share/doc/ps5-iw620
cat > /etc/modprobe.d/ps5-iw620.conf <<'EOF'
# PS5 IW620 mwifiex
# Prevent udev from auto-loading moal before the loader-provided firmware is
# copied from the boot partition. ps5-iw620.service loads it explicitly.
blacklist moal
blacklist mlan
softdep moal pre: cfg80211 mlan
options moal fw_name=nxp/pcieuartiw620_combo_v1.bin pcie_int_mode=1 drv_mode=1 cfg80211_wext=4 sta_name=mlan ext_scan=0 auto_fw_reload=0 wifi_reset_config=0 sched_scan=0 ps_mode=2 auto_ds=2 amsdu_disable=1
EOF
cat > /usr/local/sbin/ps5-iw620-load <<'EOF'
#!/bin/sh
set -eu
FW_NAME=nxp/pcieuartiw620_combo_v1.bin
FW_DST=/lib/firmware/$FW_NAME
FW_SRC=
for candidate in "/boot/efi/lib/$FW_NAME" "/boot/lib/$FW_NAME" "$FW_DST"; do
if [ -f "$candidate" ]; then
FW_SRC="$candidate"
break
fi
done
if [ -z "$FW_SRC" ]; then
FW_SRC="$(find /boot /boot/efi -path "*/$FW_NAME" -type f 2>/dev/null | head -n 1)"
fi
if [ -n "$FW_SRC" ] && [ -f "$FW_SRC" ]; then
install -D -m 0644 "$FW_SRC" "$FW_DST"
fi
if [ ! -f "$FW_DST" ]; then
echo "PS5 IW620 firmware not found on the boot partition; skipping WiFi load"
exit 0
fi
# If udev raced us and loaded the module before firmware was copied, reload
# it so firmware init can succeed.
modprobe -r moal mlan 2>/dev/null || true
modprobe cfg80211 || true
modprobe moal
rfkill unblock all 2>/dev/null || true
nmcli radio wifi on 2>/dev/null || true
EOF
chmod 0755 /usr/local/sbin/ps5-iw620-load
cat > /etc/systemd/system/ps5-iw620.service <<'EOF'
[Unit]
Description=Load PS5 IW620 internal WiFi
RequiresMountsFor=/boot/efi
Wants=systemd-udev-settle.service
After=local-fs.target boot-efi.mount systemd-udev-settle.service
Before=NetworkManager.service network-pre.target
[Service]
Type=oneshot
ExecStart=/usr/local/sbin/ps5-iw620-load
RemainAfterExit=yes
[Install]
WantedBy=multi-user.target
EOF
cat > /usr/share/doc/ps5-iw620/BUILDINFO <<EOF
NXP mwifiex ref: $IW620_NXP_REF
ps5-linux-mwifiex ref: $IW620_PATCH_REF
Kernel: $KVER
Module options: fw_name=nxp/pcieuartiw620_combo_v1.bin pcie_int_mode=1 drv_mode=1 cfg80211_wext=4 sta_name=mlan ext_scan=0 auto_fw_reload=0 wifi_reset_config=0 sched_scan=0 ps_mode=2 auto_ds=2 amsdu_disable=1
EOF
depmod -a "$KVER"
systemctl enable ps5-iw620.service
rm -rf "$IW620_SRC" "$IW620_PATCHES"
grep -qxF amdgpu /etc/initramfs-tools/modules || printf '\namdgpu\n' >> /etc/initramfs-tools/modules
printf 'MODULES=most\nBUSYBOX=y\n' > /etc/initramfs-tools/conf.d/ps5-amdgpu
update-initramfs -c -k "$KVER"