aboutsummaryrefslogtreecommitdiff
path: root/README.md
diff options
context:
space:
mode:
authorArslaan Pathan <[email protected]>2026-08-30 16:08:17 +1200
committerArslaan Pathan <[email protected]>2026-08-30 16:08:17 +1200
commitde9eea1692d1846740b82fbbcc88c20f28b96ba7 (patch)
treedb00b84d7beaf9fc44b8b8c05b26a08cd38ba567 /README.md
parentce6c8e94d4d486fd0bf7175aa366b3789ae2dc10 (diff)
downloadyerbalinux-de9eea1692d1846740b82fbbcc88c20f28b96ba7.tar.xz
yerbalinux-de9eea1692d1846740b82fbbcc88c20f28b96ba7.zip
README hardening notes
Diffstat (limited to 'README.md')
-rw-r--r--README.md23
1 files changed, 22 insertions, 1 deletions
diff --git a/README.md b/README.md
index c2c6e9f..a205a3e 100644
--- a/README.md
+++ b/README.md
@@ -2,7 +2,7 @@
# Yerba Linux
-Lightweight rolling-release linux distro using the runit init system
+Lightweight & minimal atomic security-focused Linux distro using the runit init system
## Why am I building this?
@@ -42,6 +42,27 @@ This will build the distro and all dependencies, leaving the artifacts somewhere
- Installer: TBD
- Graphics: TBD
+## Hardening
+
+The focus of this project is shifting to a hardened security-focused versatile Linux distro.
+The following notes are for myself so I can remember what hardening features to implement.
+
+- hardened_malloc (from the GrapheneOS project)
+- SELinux configuration
+- muvm for sandboxing apps
+- flatkvm? TODO look at this in more detail
+- Flatpak for GUI apps sandboxing
+- Hardened kernel
+- Blacklist unnecessary/unused modules for security (Auto detect required modules during install?)
+- FDE with LUKS
+- [Research needed] User password/separately encrypted home directory (Android-like)
+- User packages in /opt/yerba-pkg instead of modifying the atomic stuff directly with OverlayFS
+- Atomic updates with dm-verity
+- Wayland by default
+- Chimera userland (chimerautils/FreeBSD ported)
+- XBPS package manager
+- Runit init system (minimal attack surface) - Might be changed to OpenRC
+
---
## Contributing