1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
|
<img src="https://git.arslaancodes.com/yerbalinux.git/plain/yerba.png"/>
# Yerba Linux
Versatile, general-purpose, atomic security-focused Linux distro using the runit init system
## Why am I building this?
I am 13, code low-level things for fun, and have too much free time. Why DIDN'T you expect me to make a Linux distro?
Jokes aside, I made this distro because other distros just didn't fit what I wanted to do, and also, just for fun and a new side project. As I am currently developing this distro, I use Gentoo on my laptop. It's a great distro, until you quickly need a package for something and have to compile it. Binary packages exist, but it's no use because they just aren't as streamlined and I find them annoying on Gentoo.
Therefore, I searched for other distros.
- Arch? Uses systemd, which I don't personally like for many reasons
- Debian? Not rolling-release and too normal
- Void? Seems great, but a lot of packages are unmaintained in the repos (to be honest I just want an excuse to not use Void and to make my own distro.. If I wasn't making this distro I'd probably be on Void at the moment)
- ...
Pretty much, I decided to make my own distro for fun, and also, if you make the distro yourself, it will undeniably be the most customisable of them all.
(plus, imagine the aura of someone asking you what your distro is, saying they've never heard about it, and you casually drop "Yeah because I made it myself 🗿")
## How to try it
At the moment, it's not a very usable distro, so I don't recommend you try it, but if you must, then run the following command in the root of the repository:
```shell
kas build kas.yml
```
This will build the distro and all dependencies, leaving the artifacts somewhere in build/. **Good luck finding it**(TM)**!**
## Current Status
- Kernel: working, 7.0.11!
- Bootloader: TBD, currently using runqemu on the rootfs directly
- Libc: working, musl
- Init system: working, runit
- SquashFS image (+ OverlayFS live ISO): TBD
- Networking: working, dhcpcd (TODO: Add NetworkManager and iwd)
- Audio: TBD
- Package manager: TBD
- Installer: TBD
- Graphics: TBD
## Hardening
The focus of this project is shifting to a hardened security-focused versatile Linux distro.
The following notes are for myself so I can remember what hardening features to implement.
- Three LUKS keys: one for NVRAM (TPM), one for system (rootfs, pkgconf, yerbapkg) (TPM), one for userdata (user password derived, maybe also TPM)
- hardened_malloc (from the GrapheneOS project)
- SELinux configuration
- muvm for sandboxing apps
- flatkvm? TODO look at this in more detail
- Flatpak for GUI apps sandboxing
- Hardened kernel
- Blacklist unnecessary/unused modules for security (Auto detect required modules during install?)
- FDE with LUKS (TPM)
- [Research needed] User password/separately encrypted home directory (Android-like) (Also TPM?)
- Atomic updates with dm-verity
- Wayland by default
- Chimera userland (chimerautils/FreeBSD ported)
- Homebrew as the default package manager (no system-wide packages! Securityâ„¢)
- Runit init system (minimal attack surface) - Might be changed to OpenRC
- Secure Boot (TPM)
- Decoy/duress PIN - PAM module, wipe all user-controlled partitions and reboot immediately
- Auto updates (atomic!)
- Root access off by default - doas doesn't even permit, use some custom CLI tool (yerbaroot?) to toggle access (suid binary, sets a flag in an NVRAM partition)
- On boot, generate doas config on the fly based on NVRAM status
- Show a warning in the MOTD/tty login along with whatever login manager used that root is on, like a red banner
- NVRAM partition as mentioned above
- Limine bootloader
- A/B partitions for atomic updates
- dm-verity hash tree is stored in the UKI, which comes with atomic image, no need for a verity (Verity mentioned???) partition
- Atomic update contains:
- UKI (Unified Kernel Image)
- rootfs
- Bootloader entry
- Transient /etc (copied from rootfs on boot to tmpfs and mounted)
### Partitions
- **efi** (1GB) | N/A | FAT32 | `/efi` | Stores EFI bootloader files
- **boot** (1GB) | N/A | ext4 | `/boot` | Boot, kernels, initramfs, etc.
- **nvram** (128MB) | LUKS | FAT32 | `/nvram` | NVRAM for root flags and selected slot
- **rootfs_A** (15GB) | LUKS + dm-verity (atomic) | btrfs | `/` (if selected slot) | Root filesystem — Slot A
- **rootfs_B** (15GB) | LUKS + dm-verity (atomic) | btrfs | `/` (if selected slot) | Root filesystem — Slot B
- **userdata** (Rest of disk) | LUKS | btrfs | `/home` | User files
---
## Contributing
Generate a patch with `git format-patch HEAD~1` and email to [[email protected]](mailto:[email protected]) or send to XMPP address [[email protected]](xmpp:[email protected]), beginning the subject line with [PATCH yerbalinux]
*If you are sending a revised version of a previous patch, please use [PATCH yerbalinux v2, v3, etc].*
|