Building an Offline Transfer Bundle
Goal
You bundle one package and all of its dependencies into an "import bundle", verify it with a checksum manifest, and reproduce the installation from that bundle alone. It is a scaled-down version of the procedure for importing into an air-gapped network.
Why it matters
The most common failure on an air-gapped network is "I took it in but the dependencies were short, so I have to go back out". In an organization where the import review happens only once a day, one round trip is a day. That is why an experienced person goes in carrying the result of solving the dependency graph in full on the outside. And you need a way to confirm that the files that passed through the medium are intact — a checksum catches corruption in transit, and a signature guarantees the origin. This lab gets the skeleton of that procedure into your hands.
Steps
- Create the
/root/offlinedirectory and save the list of URIs of the files you would need to download to installcowsayto/root/offline/uris.txt. (You must not actually install it.) - Only download
cowsayand its dependencies, and gather the downloaded.debfiles in/root/offline/pool/. There must be at least 2. - Create a SHA-256 manifest for all the
.debfiles in/root/offline/poolas/root/offline/manifest.sha256. - Run the verification with that manifest and save the result to
/root/offline/verify.txt. Every line must be OK. - To turn
/root/offline/poolinto a repository, generatePackagesandPackages.gz. - Register this repository as
/etc/apt/sources.list.d/labhub-airgap.listand refresh the index. - Reinstall
cowsayto confirm that the install also works from the imported files, and after installing, save the result of runningcowsay labhubto/root/offline/run.txt. - Make
/root/offline/report.txtwith the following 4 lines.PACKAGES=<pool 안 .deb 개수>/BYTES=<pool 안 .deb 파일 크기 합계(바이트)>/VERIFY=OK/SNAPSHOT=<오늘 날짜 YYYY-MM-DD>(that is, the number of .deb files in the pool, the total size in bytes of the .deb files in the pool, OK, and today's date)
Notes
- Downloaded files usually pile up in
/var/cache/apt/archives/. If you runapt-get cleanbeforehand, only what was downloaded this time remains, which makes it easy to tell apart. - You can get the total size with
du -bc /root/offline/pool/*.deb | tail -1or as a sum ofstat -c %s. - Common mistake 1: if you make the manifest in step 3 with absolute paths, the verification in step 4 breaks from a different directory. It is safer to
cdfirst and make it with relative paths. - Common mistake 2: if you actually install in step 1, step 2 downloads nothing, saying "already the newest version".
- Common mistake 3: the index refresh fails with
Permission deniedin step 6. apt drops to an unprivileged user called_aptonly when it downloads files, and because/rootis 700, that user cannot pass through. Opening just the one "enter" bit withchmod o+x /rootis enough (listing is still blocked).
First calculate what must be downloaded
Create the /root/offline directory and save the list of URIs of the files you would need to download to install cowsay to /root/offline/uris.txt. (You must not actually install it.)
apt-get install has an option that does not actually download and only prints the list of URIs to download. Look for the simulation-family options.
Downloading the packages
Only download cowsay and its dependencies, and gather the downloaded .deb files in /root/offline/pool/. There must be at least 2.
There is an option that only downloads without installing. The downloaded files pile up in the apt cache directory.
Creating the checksum manifest
Create a SHA-256 manifest for all the .deb files in /root/offline/pool as /root/offline/manifest.sha256.
If you run sha256sum on several files at once, you get the 'hash, space, file name' format. It is a format you can use as is for verification later.
Verifying with the manifest
Run the verification with that manifest and save the result to /root/offline/verify.txt. Every line must be OK.
sha256sum has an option that reads a manifest instead of a file and checks against it. You have to run the verification in the directory that holds the manifest for the paths to match.
Making a repository index from the imported files
To turn /root/offline/pool into a repository, generate Packages and Packages.gz.
It is the same method as in the previous lab. This time, though, there are several files, so check the number of Package entries in the index.
Registering the import repository
Register this repository as /etc/apt/sources.list.d/labhub-airgap.list and refresh the index.
Give the repository a name different from the previous lab. It is fine if both repositories are valid at the same time.
Reinstalling from the import repository
Reinstall cowsay to confirm that the install also works from the imported files, and after installing, save the result of running cowsay labhub to /root/offline/run.txt.
To install an already installed package again at the same version, you need the reinstall option.
Import report
Make /root/offline/report.txt with the following 4 lines.
PACKAGES=<pool 안 .deb 개수> / BYTES=<pool 안 .deb 파일 크기 합계(바이트)> / VERIFY=OK / SNAPSHOT=<오늘 날짜 YYYY-MM-DD> (that is, the number of .deb files in the pool, the total size in bytes of the .deb files in the pool, OK, and today's date)
Just gather the number of manifest lines, the total bytes, and the verification result. You can get the total bytes with du or stat.