From a2fbd4e4625f1629e245c7023e063afd0f6d2c4e Mon Sep 17 00:00:00 2001 From: DevomB Date: Fri, 2 Oct 2026 02:21:17 -0700 Subject: [PATCH 1/3] Cut the build system's comments to one line The stamp machinery in common.sh, the stages, every recipe, the service scripts and s6 run files, the guest checks, the config lists and the patch-set READMEs lose their stacked comments, history and rhetoric. Each recipe drops its two-line "a stage 04 recipe, sourced by..." header. Wrong comments are corrected: bc's shim name, shadow's man pages, the boot-success re-arm file, testctl's key list, and the glibc README's claim that the whole patch directory is fingerprinted. Comments only. bash's declare -f output of every changed script is unchanged and no heredoc body moves, so no recipe or stage function re-fingerprints. Files hashed whole still move their step: the service scripts, run files and sysctl file the late services step, the guest checks the tests step, the allowlists stage 06's rootfs step, and the kernel checker's accepted list its check step alone. --- build/config/artifact-accepted.txt | 7 +- build/config/capability-allowlist.txt | 4 +- build/config/hardening-exceptions.txt | 8 +- build/config/hardening.env | 11 +-- build/config/kernel/checker-accepted.txt | 13 +-- build/config/licence-exceptions.txt | 4 +- build/config/setuid-allowlist.txt | 9 +- .../config/sysctl.d/99-kryptik-hardening.conf | 11 +-- build/guest-tests/icmp-echo.py | 6 +- build/lib/common.sh | 92 +++++-------------- build/lib/kconfig-check.sh | 12 +-- build/patches/dwl-0.8/README.md | 26 +++--- build/patches/gawk-5.3.0/README.md | 8 +- build/patches/glibc-2.40/README.md | 20 ++-- build/patches/iputils-20250605/README.md | 6 +- build/patches/readline-8.3/README.md | 4 +- build/patches/shadow-4.16.0/README.md | 10 +- build/patches/tar-1.35/README.md | 2 +- build/patches/zlib-1.3.1/README.md | 2 +- build/recipes/bc.sh | 4 +- build/recipes/binutils.sh | 10 +- build/recipes/bzip2.sh | 6 +- build/recipes/ca-bundle.sh | 6 +- build/recipes/cmake.sh | 2 - build/recipes/compiler-check.sh | 6 +- build/recipes/console.sh | 7 +- build/recipes/coreutils.sh | 2 - build/recipes/cryptsetup.sh | 5 +- build/recipes/desktop.sh | 9 +- build/recipes/dhcpcd.sh | 2 - build/recipes/dnsmasq.sh | 8 +- build/recipes/dwl.sh | 14 +-- build/recipes/e2fsprogs.sh | 2 - build/recipes/efiboot.sh | 7 +- build/recipes/elfutils.sh | 2 - build/recipes/eudev.sh | 2 - build/recipes/firmware.sh | 13 +-- build/recipes/fonts.sh | 6 +- build/recipes/gawk.sh | 7 +- build/recipes/gcc.sh | 26 ++---- build/recipes/gdbm.sh | 2 - build/recipes/glibc.sh | 28 ++---- build/recipes/groff.sh | 7 +- build/recipes/hardened-malloc.sh | 8 +- build/recipes/havoc.sh | 2 - build/recipes/hwdata.sh | 2 - build/recipes/iana-etc.sh | 2 - build/recipes/inetutils.sh | 7 +- build/recipes/installer.sh | 5 +- build/recipes/iproute2.sh | 2 - build/recipes/iputils.sh | 10 +- build/recipes/iw.sh | 5 +- build/recipes/json-c.sh | 12 +-- build/recipes/kbd.sh | 5 +- build/recipes/kryptikd.sh | 21 +---- build/recipes/libaio.sh | 2 - build/recipes/libcap.sh | 2 - build/recipes/libdrm.sh | 2 - build/recipes/libinput.sh | 2 - build/recipes/libxkbcommon.sh | 2 - build/recipes/licences.sh | 24 ++--- build/recipes/locales.sh | 6 +- build/recipes/lvm2.sh | 11 +-- build/recipes/lynx.sh | 2 - build/recipes/man-db.sh | 3 - build/recipes/meson.sh | 5 +- build/recipes/netzone.sh | 5 +- build/recipes/ninja.sh | 2 - build/recipes/openssh.sh | 7 +- build/recipes/openssl.sh | 5 +- build/recipes/perl.sh | 13 +-- build/recipes/pkgconf.sh | 5 +- build/recipes/python.sh | 9 +- build/recipes/readline.sh | 7 +- build/recipes/s6.sh | 8 +- build/recipes/seatd.sh | 2 - build/recipes/shadow.sh | 8 +- build/recipes/tar.sh | 5 +- build/recipes/tests.sh | 9 +- build/recipes/updater.sh | 2 - build/recipes/wayland.sh | 2 - build/recipes/wlroots.sh | 5 +- build/recipes/wpa-supplicant.sh | 9 +- build/recipes/xz.sh | 2 - build/recipes/zlib.sh | 2 - build/recipes/zstd.sh | 2 - build/service-scripts/ask.sh | 17 ++-- build/service-scripts/boot-smoke.sh | 24 ++--- build/service-scripts/devices.sh | 11 +-- build/service-scripts/eudev-trigger.sh | 3 +- build/service-scripts/kryptikd-check.sh | 3 +- build/service-scripts/watchdog.sh | 6 +- build/services/getty-tty1/run | 5 +- build/services/getty-tty2/run | 4 +- build/services/kryptikd-serve/run | 3 +- build/services/net-zone/run | 6 +- build/services/watchdog/run | 4 +- build/stages/00-host-check.sh | 6 +- build/stages/01-toolchain.sh | 45 +++------ build/stages/02-temp-tools.sh | 8 +- build/stages/05-kernel.sh | 69 ++++---------- 101 files changed, 245 insertions(+), 658 deletions(-) diff --git a/build/config/artifact-accepted.txt b/build/config/artifact-accepted.txt index 581b6fea..60a14f35 100644 --- a/build/config/artifact-accepted.txt +++ b/build/config/artifact-accepted.txt @@ -1,8 +1,5 @@ -# Findings of tools/check-artifact-hardening.sh that the image keeps, each with -# its reason: `FINDING PATH # why`, or `RPATH PATH RPATH # why`, since an RPATH -# entry accepts one rpath. PATH and RPATH are globs on the object's path in the -# image and on its rpath. A finding not listed here fails --strict, and so does -# an entry that no longer matches anything. +# Findings of tools/check-artifact-hardening.sh the image keeps, as globs: `FINDING PATH # why` +# or `RPATH PATH RPATH # why`. --strict fails on an unlisted finding and on a stale entry. NO-CET usr/bin/kryptikd # stable rustc marks nothing for CET, nor does the std it links NO-CET usr/bin/kryptik-wlproxy # the same diff --git a/build/config/capability-allowlist.txt b/build/config/capability-allowlist.txt index f7c716c2..11db5e18 100644 --- a/build/config/capability-allowlist.txt +++ b/build/config/capability-allowlist.txt @@ -1,4 +1,2 @@ -# Files allowed to carry file capabilities (security.capability) in a Kryptik -# image; stage 06 removes them from every other file in its root -# (tools/audit-setuid.sh --strip). Nothing in the image needs one yet. +# Files allowed file capabilities; stage 06 strips the rest (tools/audit-setuid.sh --strip). # /absolute/path # justification diff --git a/build/config/hardening-exceptions.txt b/build/config/hardening-exceptions.txt index 2b383062..ab4c0327 100644 --- a/build/config/hardening-exceptions.txt +++ b/build/config/hardening-exceptions.txt @@ -1,6 +1,4 @@ -# Packages exempted from part of the hardening flag set: -# # justification -# An entry without a justification fails the build. Say what breaks and what -# you tried; exceptions are meant to be removed, not accumulated. +# Packages exempted from a hardening flag; an entry without a justification fails the build. +# # what breaks, and what was tried -glibc -D_FORTIFY_SOURCE=3 # glibc DEFINES the fortify machinery; fortifying it against itself fails to build +glibc -D_FORTIFY_SOURCE=3 # glibc provides the fortify machinery; fortifying it against itself fails to build diff --git a/build/config/hardening.env b/build/config/hardening.env index 239ab445..4f30bb3a 100644 --- a/build/config/hardening.env +++ b/build/config/hardening.env @@ -1,10 +1,6 @@ -# Hardening flags for the target packages; docs/hardening.md has the reasons. -# Loaded by stage 04 only: stages 01 and 02 build the compiler that implements -# these flags, and set no flags at all. +# Hardening flags for the target packages, loaded by stage 04; docs/hardening.md has the reasons. -# No -fPIE or -pie: GCC is built with --enable-default-pie, so executables are -# PIE anyway, and -pie links Scrt1.o into shared libraries, which then fail on -# an undefined main. +# No -fPIE or -pie: GCC defaults to PIE, and -pie breaks shared libraries (Scrt1.o, undefined main). # _FORTIFY_SOURCE needs -O1 or more; -O2 is the tested level. KRYPTIK_OPT="-O2" @@ -29,6 +25,5 @@ export CFLAGS="${KRYPTIK_OPT} ${KRYPTIK_CFLAGS_HARDENING}" export CXXFLAGS="${KRYPTIK_OPT} ${KRYPTIK_CFLAGS_HARDENING}" export LDFLAGS="${KRYPTIK_LDFLAGS_HARDENING}" -# Packages exempted from some flags. Each needs a justification, which -# validate_hardening_exceptions in build/lib/common.sh enforces. +# Per-package flag exemptions, each with the justification validate_hardening_exceptions enforces. KRYPTIK_HARDENING_EXCEPTIONS="build/config/hardening-exceptions.txt" diff --git a/build/config/kernel/checker-accepted.txt b/build/config/kernel/checker-accepted.txt index adac4c2e..f9995dfe 100644 --- a/build/config/kernel/checker-accepted.txt +++ b/build/config/kernel/checker-accepted.txt @@ -1,13 +1,8 @@ -# kernel-hardening-checker failures on the resolved config and the shipped -# command line that Kryptik accepts, each with its reason: +# kernel-hardening-checker failures Kryptik accepts, read by tools/check-kernel-hardening.sh: #