diff options
Diffstat (limited to 'README.md')
| -rw-r--r-- | README.md | 11 |
1 files changed, 8 insertions, 3 deletions
@@ -33,7 +33,7 @@ This will build the distro and all dependencies, leaving the artifacts somewhere - Kernel: working, 7.0.11! - Bootloader: TBD, currently using runqemu on the rootfs directly -- Libc: working, musl +- Libc: working, glibc - Init system: working, runit - SquashFS image (+ OverlayFS live ISO): TBD - Networking: working, dhcpcd (TODO: Add NetworkManager and iwd) @@ -60,7 +60,12 @@ The following notes are for myself so I can remember what hardening features to - Atomic updates with dm-verity - Wayland by default - Chimera userland (chimerautils/FreeBSD ported) -- pkgsrc (NetBSD) package manager - prefix set to /opt/yerba-pkg +- pkgsrc (NetBSD) package manager + - build into tarball + - on first install and on each update extract the tarball into /home/USER/.local/pkgsrc for each user + - regen mk.conf on each update/install to use correct prefix + - per-user packages only ^_^ + - unprivileged bootstrap - Runit init system (minimal attack surface) - Might be changed to OpenRC - Secure Boot (TPM) - Decoy/duress PIN - PAM module, wipe all user-controlled partitions and reboot immediately @@ -85,7 +90,7 @@ The following notes are for myself so I can remember what hardening features to - **nvram** (128MB) | LUKS | FAT32 | `/nvram` | NVRAM for root flags and selected slot - **rootfs_A** (15GB) | LUKS + dm-verity (atomic) | btrfs | `/` (if selected slot) | Root filesystem — Slot A - **rootfs_B** (15GB) | LUKS + dm-verity (atomic) | btrfs | `/` (if selected slot) | Root filesystem — Slot B -- **userdata** (Rest of disk) | LUKS | btrfs + subvol (home, pkg) | `/home`, `/opt/yerba-pkg` | User files +- **userdata** (Rest of disk) | LUKS | btrfs | `/home` | User files --- |
