diff options
| author | Arslaan Pathan <[email protected]> | 2026-08-30 20:34:48 +1200 |
|---|---|---|
| committer | Arslaan Pathan <[email protected]> | 2026-08-30 20:34:48 +1200 |
| commit | 507ef01648749f1114fb74d47b792187e6a6c281 (patch) | |
| tree | 6718adb9f99f4731601a1b361b58d18737dc6a04 | |
| parent | de9eea1692d1846740b82fbbcc88c20f28b96ba7 (diff) | |
| download | yerbalinux-507ef01648749f1114fb74d47b792187e6a6c281.tar.xz yerbalinux-507ef01648749f1114fb74d47b792187e6a6c281.zip | |
Spent a lot of time planning in the README
| -rw-r--r-- | README.md | 35 |
1 files changed, 32 insertions, 3 deletions
@@ -2,7 +2,7 @@ # Yerba Linux -Lightweight & minimal atomic security-focused Linux distro using the runit init system +Versatile, general-purpose, atomic security-focused Linux distro using the runit init system ## Why am I building this? @@ -47,6 +47,7 @@ This will build the distro and all dependencies, leaving the artifacts somewhere The focus of this project is shifting to a hardened security-focused versatile Linux distro. The following notes are for myself so I can remember what hardening features to implement. +- Three LUKS keys: one for NVRAM (TPM), one for system (rootfs, pkgconf, yerbapkg) (TPM), one for userdata (user password derived, maybe also TPM) - hardened_malloc (from the GrapheneOS project) - SELinux configuration - muvm for sandboxing apps @@ -54,14 +55,42 @@ The following notes are for myself so I can remember what hardening features to - Flatpak for GUI apps sandboxing - Hardened kernel - Blacklist unnecessary/unused modules for security (Auto detect required modules during install?) -- FDE with LUKS -- [Research needed] User password/separately encrypted home directory (Android-like) +- FDE with LUKS (TPM) +- [Research needed] User password/separately encrypted home directory (Android-like) (Also TPM?) - User packages in /opt/yerba-pkg instead of modifying the atomic stuff directly with OverlayFS - Atomic updates with dm-verity - Wayland by default - Chimera userland (chimerautils/FreeBSD ported) - XBPS package manager +- XBPS config directories on their own separate non-verity (Verity mentioned??) partition - Runit init system (minimal attack surface) - Might be changed to OpenRC +- Secure Boot (TPM) +- Decoy/duress PIN - PAM module, wipe all user-controlled partitions and reboot immediately +- Auto updates (atomic!) +- Root access off by default - doas doesn't even permit, use some custom CLI tool (yerbaroot?) to toggle access (suid binary, sets a flag in an NVRAM partition) +- On boot, generate doas config on the fly based on NVRAM status +- Show a warning in the MOTD/tty login along with whatever login manager used that root is on, like a red banner +- NVRAM partition as mentioned above +- Limine bootloader +- A/B partitions for atomic updates +- dm-verity hash tree is stored in the UKI, which comes with atomic image, no need for a verity (Verity mentioned???) partition +- Atomic update contains: + - UKI (Unified Kernel Image) + - rootfs + - Bootloader entry + +## Partitions list + +| Partition | Size | Encryption | Format | Mount Point(s) | Purpose | +|-----------|------|------------|--------|----------------|---------| +| **efi** | 1 GB | N/A | FAT32 | `/efi` | Stores EFI bootloader files | +| **boot** | 1 GB | N/A | ext4 | `/boot` | Boot, kernels, initramfs, etc. | +| **nvram** | 128 MB | LUKS | FAT32 | `/nvram` | NVRAM for root flags and selected slot | +| **pkgconf** | 256 MB | LUKS | btrfs + subvol (`@xbpsd`, `@xbps`, `@db`, `@cache`) | `/etc/xbps.d`, `/etc/xbps`, `/var/db/xbps`, `/var/cache/xbps` | XBPS configuration and database files | +| **yerbapkg** | 8 GB | LUKS | ext4 | `/opt/yerba-pkg` | User-installed system-wide packages | +| **rootfs_A** | 15 GB | LUKS + dm-verity (atomic) | btrfs | `/` (if selected slot) | Root filesystem — Slot A | +| **rootfs_B** | 15 GB | LUKS + dm-verity (atomic) | btrfs | `/` (if selected slot) | Root filesystem — Slot B | +| **userdata** | Rest of disk | LUKS | btrfs | `/home` | User files | --- |
