Alpine WDMCH Builder
#

CI

A reproducible build system for creating a USB Rescue Boot image for the single-bay WD My Cloud Home (Realtek RTD1295, 4× Cortex-A53, 1 GiB RAM).

Overview
#

This project builds a complete USB rescue environment:

  • Kernel: symops/monarch-6.18 (Linux 6.18.x, ARM64), all required drivers built in — no kernel modules are built
  • Rootfs: Alpine aarch64 minirootfs with Dropbear SSH + DHCP
  • Boot: raw patched ARM64 Image + WDMCH DTB
  • Rescue: standalone 4 MiB initramfs that can hand off to an installed Alpine root filesystem

Architecture
#

vendor ROM/BL31/U-Boot
    -> boot_rescue_from_usb (reads fixed filenames from the USB stick ROOT)
    -> WDMCH rescue kernel + rescue initramfs
       -> shell / DHCP / SSH
       -> switch_root into installed Alpine (filesystem label wdmch-root)
       -> optional kexec path, no stick needed

The vendor U-Boot cannot boot from the internal SATA disk. Every boot goes through the FAT32 USB stick — either by holding the reset button at power-on, or automatically when no factory partition is found.

Quick Start
#

# Clone and build
git clone https://github.com/dominicusin/alpine-wdmch-builder.git
cd alpine-wdmch-builder
./build-image.sh

# Or dry-run to validate setup
./build-image.sh --dry-run

Using the rescue stick
#

Copy the build tree to the root of a FAT32 stick (MBR, single partition) — there is no boot/ subdirectory, the loader reads fixed filenames from the root:

mount /dev/sdX1 /mnt/stick
cp -r build/usb-tree-root/* /mnt/stick/
sync
cd /mnt/stick && sha256sum -c SHA256SUMS

Then power off the box, insert the stick, and hold the reset button while powering on. See docs/usb-rescue.md.

Installing Alpine to the internal disk
#

From the rescue shell:

install-alpine /dev/sda          # interactive
install-alpine /dev/sda --yes    # non-interactive

The installer writes only the existing p20 (SYSTEM_B), formatted ext4 with the label wdmch-root. The factory 24-partition GPT is preserved; p1 (FW_TABLE), the A/B/GOLD firmware slots, your data (p22) and your storage volume (p24) are untouched. It requires explicit confirmation.

On the next rescue boot the init finds wdmch-root and switch_roots into the installed system. Add an empty file named norescue to the stick root to get the rescue shell instead.

Project Structure
#

config/          - Source locks and build configuration
kernel/          - Kernel fetch, build, and patch scripts
dtb/             - Device tree build and validation
rootfs/          - Alpine rescue rootfs build scripts
image/           - USB rescue artifact packaging
tools/           - Host-side validation tools
tests/           - Repository validation tests
docs/            - Documentation
.github/workflows/ - CI/CD pipelines

Key Files
#

FileDescription
sata.uImageRaw patched ARM64 kernel Image + 512 KiB zero padding (not an mkimage/FIT wrapper)
rescue.sata.dtbWDMCH device tree blob
rescue.root.sata.cpio.gz_pad.imgAlpine rescue initramfs, exactly 4194304 bytes
SHA256SUMSChecksums for the release artifacts
manifest.jsonBuild metadata and artifact manifest

Documentation
#

Source References
#

See docs/SOURCES.md for full source classification.

License
#

MIT License — see LICENSE.

Warnings
#

  • DO NOT boot GOLD partition — it is a factory-reset appliance, not a safe fallback
  • DO NOT write A/B/GOLD slots as part of this project
  • DO back up any existing WDMCH firmware table before future flashing work (dd if=/dev/sda1 of=fw-table-backup.bin bs=512)
  • This is a rescue boot tool; it does not overwrite NAS firmware
  • The factory GPT is preserved — never repartition the internal disk
  • No private SSH key is stored anywhere in this repository or its artifacts

License
#

MIT License

Copyright (c) 2026 dominicusin

Permission is hereby granted, free of charge, to any person obtaining a copy
of this software and associated documentation files (the "Software"), to deal
in the Software without restriction, including without limitation the rights
to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
copies of the Software, and to permit persons to whom the Software is
furnished to do so, subject to the following conditions:

The above copyright notice and this permission notice shall be included in all
copies or substantial portions of the Software.

THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
SOFTWARE.