From de9eea1692d1846740b82fbbcc88c20f28b96ba7 Mon Sep 17 00:00:00 2001 From: Arslaan Pathan Date: Sun, 30 Aug 2026 16:08:17 +1200 Subject: README hardening notes --- README.md | 23 ++++++++++++++++++++++- 1 file changed, 22 insertions(+), 1 deletion(-) (limited to 'README.md') diff --git a/README.md b/README.md index c2c6e9f..a205a3e 100644 --- a/README.md +++ b/README.md @@ -2,7 +2,7 @@ # Yerba Linux -Lightweight rolling-release linux distro using the runit init system +Lightweight & minimal atomic security-focused Linux distro using the runit init system ## Why am I building this? @@ -42,6 +42,27 @@ This will build the distro and all dependencies, leaving the artifacts somewhere - Installer: TBD - Graphics: TBD +## Hardening + +The focus of this project is shifting to a hardened security-focused versatile Linux distro. +The following notes are for myself so I can remember what hardening features to implement. + +- hardened_malloc (from the GrapheneOS project) +- SELinux configuration +- muvm for sandboxing apps +- flatkvm? TODO look at this in more detail +- Flatpak for GUI apps sandboxing +- Hardened kernel +- Blacklist unnecessary/unused modules for security (Auto detect required modules during install?) +- FDE with LUKS +- [Research needed] User password/separately encrypted home directory (Android-like) +- User packages in /opt/yerba-pkg instead of modifying the atomic stuff directly with OverlayFS +- Atomic updates with dm-verity +- Wayland by default +- Chimera userland (chimerautils/FreeBSD ported) +- XBPS package manager +- Runit init system (minimal attack surface) - Might be changed to OpenRC + --- ## Contributing -- cgit v1.2.3