aboutsummaryrefslogtreecommitdiff
diff options
context:
space:
mode:
-rw-r--r--README.md35
1 files changed, 32 insertions, 3 deletions
diff --git a/README.md b/README.md
index a205a3e..945003f 100644
--- a/README.md
+++ b/README.md
@@ -2,7 +2,7 @@
# Yerba Linux
-Lightweight & minimal atomic security-focused Linux distro using the runit init system
+Versatile, general-purpose, atomic security-focused Linux distro using the runit init system
## Why am I building this?
@@ -47,6 +47,7 @@ This will build the distro and all dependencies, leaving the artifacts somewhere
The focus of this project is shifting to a hardened security-focused versatile Linux distro.
The following notes are for myself so I can remember what hardening features to implement.
+- Three LUKS keys: one for NVRAM (TPM), one for system (rootfs, pkgconf, yerbapkg) (TPM), one for userdata (user password derived, maybe also TPM)
- hardened_malloc (from the GrapheneOS project)
- SELinux configuration
- muvm for sandboxing apps
@@ -54,14 +55,42 @@ The following notes are for myself so I can remember what hardening features to
- Flatpak for GUI apps sandboxing
- Hardened kernel
- Blacklist unnecessary/unused modules for security (Auto detect required modules during install?)
-- FDE with LUKS
-- [Research needed] User password/separately encrypted home directory (Android-like)
+- FDE with LUKS (TPM)
+- [Research needed] User password/separately encrypted home directory (Android-like) (Also TPM?)
- User packages in /opt/yerba-pkg instead of modifying the atomic stuff directly with OverlayFS
- Atomic updates with dm-verity
- Wayland by default
- Chimera userland (chimerautils/FreeBSD ported)
- XBPS package manager
+- XBPS config directories on their own separate non-verity (Verity mentioned??) partition
- Runit init system (minimal attack surface) - Might be changed to OpenRC
+- Secure Boot (TPM)
+- Decoy/duress PIN - PAM module, wipe all user-controlled partitions and reboot immediately
+- Auto updates (atomic!)
+- Root access off by default - doas doesn't even permit, use some custom CLI tool (yerbaroot?) to toggle access (suid binary, sets a flag in an NVRAM partition)
+- On boot, generate doas config on the fly based on NVRAM status
+- Show a warning in the MOTD/tty login along with whatever login manager used that root is on, like a red banner
+- NVRAM partition as mentioned above
+- Limine bootloader
+- A/B partitions for atomic updates
+- dm-verity hash tree is stored in the UKI, which comes with atomic image, no need for a verity (Verity mentioned???) partition
+- Atomic update contains:
+ - UKI (Unified Kernel Image)
+ - rootfs
+ - Bootloader entry
+
+## Partitions list
+
+| Partition | Size | Encryption | Format | Mount Point(s) | Purpose |
+|-----------|------|------------|--------|----------------|---------|
+| **efi** | 1 GB | N/A | FAT32 | `/efi` | Stores EFI bootloader files |
+| **boot** | 1 GB | N/A | ext4 | `/boot` | Boot, kernels, initramfs, etc. |
+| **nvram** | 128 MB | LUKS | FAT32 | `/nvram` | NVRAM for root flags and selected slot |
+| **pkgconf** | 256 MB | LUKS | btrfs + subvol (`@xbpsd`, `@xbps`, `@db`, `@cache`) | `/etc/xbps.d`, `/etc/xbps`, `/var/db/xbps`, `/var/cache/xbps` | XBPS configuration and database files |
+| **yerbapkg** | 8 GB | LUKS | ext4 | `/opt/yerba-pkg` | User-installed system-wide packages |
+| **rootfs_A** | 15 GB | LUKS + dm-verity (atomic) | btrfs | `/` (if selected slot) | Root filesystem — Slot A |
+| **rootfs_B** | 15 GB | LUKS + dm-verity (atomic) | btrfs | `/` (if selected slot) | Root filesystem — Slot B |
+| **userdata** | Rest of disk | LUKS | btrfs | `/home` | User files |
---