diff options
| -rw-r--r-- | README.md | 23 |
1 files changed, 22 insertions, 1 deletions
@@ -2,7 +2,7 @@ # Yerba Linux -Lightweight rolling-release linux distro using the runit init system +Lightweight & minimal atomic security-focused Linux distro using the runit init system ## Why am I building this? @@ -42,6 +42,27 @@ This will build the distro and all dependencies, leaving the artifacts somewhere - Installer: TBD - Graphics: TBD +## Hardening + +The focus of this project is shifting to a hardened security-focused versatile Linux distro. +The following notes are for myself so I can remember what hardening features to implement. + +- hardened_malloc (from the GrapheneOS project) +- SELinux configuration +- muvm for sandboxing apps +- flatkvm? TODO look at this in more detail +- Flatpak for GUI apps sandboxing +- Hardened kernel +- Blacklist unnecessary/unused modules for security (Auto detect required modules during install?) +- FDE with LUKS +- [Research needed] User password/separately encrypted home directory (Android-like) +- User packages in /opt/yerba-pkg instead of modifying the atomic stuff directly with OverlayFS +- Atomic updates with dm-verity +- Wayland by default +- Chimera userland (chimerautils/FreeBSD ported) +- XBPS package manager +- Runit init system (minimal attack surface) - Might be changed to OpenRC + --- ## Contributing |
