diff --git a/build/config/artifact-accepted.txt b/build/config/artifact-accepted.txt index 581b6fea..60a14f35 100644 --- a/build/config/artifact-accepted.txt +++ b/build/config/artifact-accepted.txt @@ -1,8 +1,5 @@ -# Findings of tools/check-artifact-hardening.sh that the image keeps, each with -# its reason: `FINDING PATH # why`, or `RPATH PATH RPATH # why`, since an RPATH -# entry accepts one rpath. PATH and RPATH are globs on the object's path in the -# image and on its rpath. A finding not listed here fails --strict, and so does -# an entry that no longer matches anything. +# Findings of tools/check-artifact-hardening.sh the image keeps, as globs: `FINDING PATH # why` +# or `RPATH PATH RPATH # why`. --strict fails on an unlisted finding and on a stale entry. NO-CET usr/bin/kryptikd # stable rustc marks nothing for CET, nor does the std it links NO-CET usr/bin/kryptik-wlproxy # the same diff --git a/build/config/capability-allowlist.txt b/build/config/capability-allowlist.txt index f7c716c2..11db5e18 100644 --- a/build/config/capability-allowlist.txt +++ b/build/config/capability-allowlist.txt @@ -1,4 +1,2 @@ -# Files allowed to carry file capabilities (security.capability) in a Kryptik -# image; stage 06 removes them from every other file in its root -# (tools/audit-setuid.sh --strip). Nothing in the image needs one yet. +# Files allowed file capabilities; stage 06 strips the rest (tools/audit-setuid.sh --strip). # /absolute/path # justification diff --git a/build/config/firmware.list b/build/config/firmware.list index 4db6e0e1..9d718aad 100644 --- a/build/config/firmware.list +++ b/build/config/firmware.list @@ -1,17 +1,10 @@ # The only firmware shipped under /lib/firmware on the verified root (ADR-012). -# One `find -path` pattern per line, matched in the tree linux-firmware's -# copy-firmware.sh lays out; a selected link brings its target. -# `newest N PATTERN` keeps the N highest trailing -NUMBERs per device, since a -# driver falls back only a few firmware API versions. A pattern that matches -# nothing fails the build. +# PATTERN a `find -path` pattern in copy-firmware.sh's layout; a link brings its target +# newest N PATTERN only the N highest trailing -NUMBERs (API versions) per device +# A pattern that matches nothing fails the build. -# Intel Wi-Fi: the newest three API versions per device, and every PNVM. -# Not the version MODULE_FIRMWARE names, on purpose: the driver loads the -# highest one inside its MAC's range intersected with its RF's (iwl-drv.c), so -# AX210 with a gf radio declares -100 and loads -89, and the newest parts try -# cNN names, which newest-N keeps whole, before NN ones. Picking exactly takes -# that logic and a real card to test on. The glob also keeps the DVM parts' -# firmware, about 2 MB this kernel cannot load, rather than a way to exclude it. +# Intel Wi-Fi: three API versions per device, as which one loads depends on MAC and RF (iwl-drv.c). +# The glob also keeps about 2 MB of DVM firmware this kernel cannot load. newest 3 iwlwifi-*.ucode iwlwifi-*.pnvm @@ -42,8 +35,7 @@ rtlwifi/rtl8188eufw.bin # Broadcom over PCIe (Dell and Apple machines); the SDIO parts are not. brcm/brcmfmac*-pcie* -# Graphics: all of Intel's and AMD's. Not NVIDIA: nouveau's GSP firmware is tens -# of MB per generation, and the firmware framebuffer still gives a display. +# Graphics: Intel and AMD, not NVIDIA (GSP firmware is tens of MB; the framebuffer still works). i915/* xe/* amdgpu/* diff --git a/build/config/hardening-exceptions.txt b/build/config/hardening-exceptions.txt index 2b383062..ab4c0327 100644 --- a/build/config/hardening-exceptions.txt +++ b/build/config/hardening-exceptions.txt @@ -1,6 +1,4 @@ -# Packages exempted from part of the hardening flag set: -# # justification -# An entry without a justification fails the build. Say what breaks and what -# you tried; exceptions are meant to be removed, not accumulated. +# Packages exempted from a hardening flag; an entry without a justification fails the build. +# # what breaks, and what was tried -glibc -D_FORTIFY_SOURCE=3 # glibc DEFINES the fortify machinery; fortifying it against itself fails to build +glibc -D_FORTIFY_SOURCE=3 # glibc provides the fortify machinery; fortifying it against itself fails to build diff --git a/build/config/hardening.env b/build/config/hardening.env index 239ab445..4f30bb3a 100644 --- a/build/config/hardening.env +++ b/build/config/hardening.env @@ -1,10 +1,6 @@ -# Hardening flags for the target packages; docs/hardening.md has the reasons. -# Loaded by stage 04 only: stages 01 and 02 build the compiler that implements -# these flags, and set no flags at all. +# Hardening flags for the target packages, loaded by stage 04; docs/hardening.md has the reasons. -# No -fPIE or -pie: GCC is built with --enable-default-pie, so executables are -# PIE anyway, and -pie links Scrt1.o into shared libraries, which then fail on -# an undefined main. +# No -fPIE or -pie: GCC defaults to PIE, and -pie breaks shared libraries (Scrt1.o, undefined main). # _FORTIFY_SOURCE needs -O1 or more; -O2 is the tested level. KRYPTIK_OPT="-O2" @@ -29,6 +25,5 @@ export CFLAGS="${KRYPTIK_OPT} ${KRYPTIK_CFLAGS_HARDENING}" export CXXFLAGS="${KRYPTIK_OPT} ${KRYPTIK_CFLAGS_HARDENING}" export LDFLAGS="${KRYPTIK_LDFLAGS_HARDENING}" -# Packages exempted from some flags. Each needs a justification, which -# validate_hardening_exceptions in build/lib/common.sh enforces. +# Per-package flag exemptions, each with the justification validate_hardening_exceptions enforces. KRYPTIK_HARDENING_EXCEPTIONS="build/config/hardening-exceptions.txt" diff --git a/build/config/kernel/checker-accepted.txt b/build/config/kernel/checker-accepted.txt index adac4c2e..f9995dfe 100644 --- a/build/config/kernel/checker-accepted.txt +++ b/build/config/kernel/checker-accepted.txt @@ -1,13 +1,8 @@ -# kernel-hardening-checker failures on the resolved config and the shipped -# command line that Kryptik accepts, each with its reason: +# kernel-hardening-checker failures Kryptik accepts, read by tools/check-kernel-hardening.sh: #