Skip to content

The allowlists say stage 06 fails on an unlisted setuid bit or capability, as it does - #237

Merged
DevomB merged 23 commits into
mainfrom
setuid-wording
Oct 7, 2026
Merged

DevomB merged 23 commits into
mainfrom
setuid-wording

Conversation

@DevomB

@DevomB DevomB commented Oct 7, 2026

Copy link
Copy Markdown
Owner

Since c431bf4 stage 06 runs tools/audit-setuid.sh without --strip and fails the build on a setuid bit or file capability the allowlists do not justify. The first line of each allowlist and the tool's usage still said stage 06 strips them. Three comment lines. The allowlist text is part of the rootfs step's fingerprint, so stage 06 runs again once; main's run is the proof. Based on the cleanup tier (#206, #210, #199 reword the same lines), which goes into main with it.

DevomB added 23 commits October 2, 2026 01:21
The workflow's stacked comments become one line, the launcher-gap step loses its shouted name, and two multi-line echo messages are tightened. Step logic is unchanged.
Comment stacks become one line, or a two-line block where the reason
needs it; long doc comments are cut to a line; test names lose their
sentences. Stale comments are corrected (SIT is not built, cgroup.rs
sets cpu and io limits too, Landlock's oldest ABI, misplaced docs).

Code changes: messages that read like essays are tightened, keeping every
substring a suite or test asserts on; explain() builds its rule lines
with one closure; cgroup.rs checks cgroup.procs in one helper, which its
test now exercises; the unused cap::SETPCAP, a no-op tuple binding and a
test that called no kryptikd code are removed.

main.rs, serve.rs, broker.rs, update.rs, time.rs, zone.rs and their tests
are left out: open pull requests change them.
Comment stacks in kryptik-wlproxy and zoneid become one line, or a
two-line block where the reason needs it, and long test names are cut to
a few words.

Code changes: the wlproxy session tests share two setup helpers, and
zoneid's error and audit messages lose their essays. The generated
protocol tables and zone-colours.h are unchanged.
launcher.sh, serve.sh and adversarial.sh lose their stacked comment
blocks, and the zone files and seccomp policies their multi-line notes.
Stale text is corrected: the ephemeral size comment contradicted zone.rs,
the vault note overclaimed, the K skip names zones-test.sh rather than a
developer VM that no longer exists, and F4c's message gives the 30 s it
waits. A dead assignment in E4a goes.

Every check ID, every line the CI workflow or zones-test.sh greps, and
every zone file key and value are unchanged. cli.sh and the probes are
left out: open pull requests change them.
The supply-chain tools (fetch, provenance, licences, source bundle), the
currency, support, kernel and hardening checks, the git hooks and their
suites lose their stacked comments; the data files keep one line per
column. Essay-like die and warn messages become a line or two, keeping
every substring a suite asserts on, and the help ranges still print
exactly each synopsis.

Code changes: verify-provenance.sh's messages no longer carry embedded
newlines and indentation into its report; check-support-status.sh counts
covered packages in its main loop instead of a second identical one; the
unused PASS_LIST, check-source-currency.sh's never-used work directory and
step-errexit.sh's unused yes_/no_ go; literal newlines inside tr arguments
are written as \n.

verify-signatures.sh, provenance-inventory.sh, key-provenance.tsv and the
verify-signatures suite are left out: an open pull request changes them.
The release tools (manifest, notes, channel, channel host, artifact
manifest), the image helpers, the net zone's programs, kryptik-efiboot,
kryptik-recover and their suites lose their stacked comments and essay
messages. Help ranges are fixed so each prints exactly its synopsis.

Code changes: kryptik-efiboot clears the immutable flag through one
make_mutable() helper instead of two copies; the release-manifest suite
checks the unenrolled-key refusal names the signers file; the s6-init
suite names its make target correctly; literal newlines in tr arguments
are written as \n. Output formats, wire strings and markers are unchanged.

acceptance.sh, most image suites, suite-lib.sh, vm-drive.py, tools/kryptik
and the installer are left out: open pull requests change them.
The stamp machinery in common.sh, the stages, every recipe, the service
scripts and s6 run files, the guest checks, the config lists and the
patch-set READMEs lose their stacked comments, history and rhetoric. Each
recipe drops its two-line "a stage 04 recipe, sourced by..." header.
Wrong comments are corrected: bc's shim name, shadow's man pages, the
boot-success re-arm file, testctl's key list, and the glibc README's claim
that the whole patch directory is fingerprinted.

Comments only. bash's declare -f output of every changed script is
unchanged and no heredoc body moves, so no recipe or stage function
re-fingerprints. Files hashed whole still move their step: the service
scripts, run files and sysctl file the late services step, the guest
checks the tests step, the allowlists stage 06's rootfs step, and the
kernel checker's accepted list its check step alone.
Meta-writing, history words, filler and long colon-and-semicolon chains
go from the hardening, threat-model and design docs and the compartments
README; chains become sentences or lists.

Corrected: stop --now kills zone pid 1, not the launcher, which survives
to close the volume; the seccomp filter refuses the set*id calls, capset
and inotify with an errno instead of killing; chown is in the base
allowlist, not net.seccomp; the kernel leaves SIT out, so the launcher's
sysctl matters only on kernels that build it in. Also: the artifact audit
is strict in acceptance too, and no release keeps a module key.
The stamp runner's refusals lose their history ("predates this harness")
and their essay, keeping every phrase step-errexit.sh matches; the
unchrooted escape hatch and stage 05's nested-tree check say what they
mean in a line. The console wrapper the console recipe writes gets one-
line comments, and firmware.list's header a tight format table. Stage
01's collapsed grep continuation is split again.

Fingerprints: the runner functions are excluded from every recipe's, and
stage 01's change leaves declare -f identical. The console recipe's
heredoc and firmware.list are step inputs, so the console step, the
linux-firmware step and every stage 04 step after them rebuild, with
stage 06; stage 05 builds on elfutils, earlier, so the kernel does not.
grep -c exits 1 when it counts nothing, and under the step's pipefail that aborted the recipe at the first such pattern, before its MISSING line and the summary that names them all.
… line each

# Conflicts:
#	.github/actions/prepare/action.yml
…comments to one line

# Conflicts:
#	compartments/tests/adversarial.sh
#	compartments/tests/launcher.sh
…ource, kernel and hardening checks

# Conflicts:
#	tools/git-hooks/pre-commit
…lease, image and on-system tools

# Conflicts:
#	tools/net/netzone-init.sh
#	tools/tests/s6-init-config.sh
#	tools/update/kryptik-recover
…ected against the code

# Conflicts:
#	docs/design/zone-policy-files.md
#	docs/hardening.md
# Conflicts:
#	build/recipes/tests.sh
#	build/services/getty-tty1/run
…and comments; report every missing firmware pattern

# Conflicts:
#	build/recipes/console.sh
…st names

# Conflicts:
#	compartments/kryptikd/src/consent/tests.rs
#	compartments/kryptikd/src/netzone.rs
#	compartments/kryptikd/src/registry.rs
#	compartments/kryptikd/src/seccomp.rs
#	compartments/kryptikd/src/seccomp/tests.rs
#	compartments/kryptikd/src/spawn.rs
…nlisted setuid bit or capability: it fails the build, and strips nothing
assert!(e.contains("user"), "{e}");
assert!(e.contains("net"), "{e}");
assert!(e.contains("tmpfs"), "explain must say what ephemeral storage IS: {e}");
assert!(e.contains("tmpfs"), "explain must say what ephemeral storage is: {e}");
|| e.contains("NAT")
|| e.contains("uid_base");
assert!(honest, "explain must say who opens a routed zone's way out: {e}");
assert!(says_who, "explain must say who opens a routed zone's way out: {e}");
@DevomB
DevomB merged commit 7dc60d4 into main Oct 7, 2026
10 of 11 checks passed
@DevomB
DevomB deleted the setuid-wording branch October 7, 2026 08:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants