Repository navigation
The allowlists say stage 06 fails on an unlisted setuid bit or capability, as it does - #237
Merged
Merged
Conversation
The workflow's stacked comments become one line, the launcher-gap step loses its shouted name, and two multi-line echo messages are tightened. Step logic is unchanged.
Comment stacks become one line, or a two-line block where the reason needs it; long doc comments are cut to a line; test names lose their sentences. Stale comments are corrected (SIT is not built, cgroup.rs sets cpu and io limits too, Landlock's oldest ABI, misplaced docs). Code changes: messages that read like essays are tightened, keeping every substring a suite or test asserts on; explain() builds its rule lines with one closure; cgroup.rs checks cgroup.procs in one helper, which its test now exercises; the unused cap::SETPCAP, a no-op tuple binding and a test that called no kryptikd code are removed. main.rs, serve.rs, broker.rs, update.rs, time.rs, zone.rs and their tests are left out: open pull requests change them.
Comment stacks in kryptik-wlproxy and zoneid become one line, or a two-line block where the reason needs it, and long test names are cut to a few words. Code changes: the wlproxy session tests share two setup helpers, and zoneid's error and audit messages lose their essays. The generated protocol tables and zone-colours.h are unchanged.
launcher.sh, serve.sh and adversarial.sh lose their stacked comment blocks, and the zone files and seccomp policies their multi-line notes. Stale text is corrected: the ephemeral size comment contradicted zone.rs, the vault note overclaimed, the K skip names zones-test.sh rather than a developer VM that no longer exists, and F4c's message gives the 30 s it waits. A dead assignment in E4a goes. Every check ID, every line the CI workflow or zones-test.sh greps, and every zone file key and value are unchanged. cli.sh and the probes are left out: open pull requests change them.
The supply-chain tools (fetch, provenance, licences, source bundle), the currency, support, kernel and hardening checks, the git hooks and their suites lose their stacked comments; the data files keep one line per column. Essay-like die and warn messages become a line or two, keeping every substring a suite asserts on, and the help ranges still print exactly each synopsis. Code changes: verify-provenance.sh's messages no longer carry embedded newlines and indentation into its report; check-support-status.sh counts covered packages in its main loop instead of a second identical one; the unused PASS_LIST, check-source-currency.sh's never-used work directory and step-errexit.sh's unused yes_/no_ go; literal newlines inside tr arguments are written as \n. verify-signatures.sh, provenance-inventory.sh, key-provenance.tsv and the verify-signatures suite are left out: an open pull request changes them.
The release tools (manifest, notes, channel, channel host, artifact manifest), the image helpers, the net zone's programs, kryptik-efiboot, kryptik-recover and their suites lose their stacked comments and essay messages. Help ranges are fixed so each prints exactly its synopsis. Code changes: kryptik-efiboot clears the immutable flag through one make_mutable() helper instead of two copies; the release-manifest suite checks the unenrolled-key refusal names the signers file; the s6-init suite names its make target correctly; literal newlines in tr arguments are written as \n. Output formats, wire strings and markers are unchanged. acceptance.sh, most image suites, suite-lib.sh, vm-drive.py, tools/kryptik and the installer are left out: open pull requests change them.
The stamp machinery in common.sh, the stages, every recipe, the service scripts and s6 run files, the guest checks, the config lists and the patch-set READMEs lose their stacked comments, history and rhetoric. Each recipe drops its two-line "a stage 04 recipe, sourced by..." header. Wrong comments are corrected: bc's shim name, shadow's man pages, the boot-success re-arm file, testctl's key list, and the glibc README's claim that the whole patch directory is fingerprinted. Comments only. bash's declare -f output of every changed script is unchanged and no heredoc body moves, so no recipe or stage function re-fingerprints. Files hashed whole still move their step: the service scripts, run files and sysctl file the late services step, the guest checks the tests step, the allowlists stage 06's rootfs step, and the kernel checker's accepted list its check step alone.
Meta-writing, history words, filler and long colon-and-semicolon chains go from the hardening, threat-model and design docs and the compartments README; chains become sentences or lists. Corrected: stop --now kills zone pid 1, not the launcher, which survives to close the volume; the seccomp filter refuses the set*id calls, capset and inotify with an errno instead of killing; chown is in the base allowlist, not net.seccomp; the kernel leaves SIT out, so the launcher's sysctl matters only on kernels that build it in. Also: the artifact audit is strict in acceptance too, and no release keeps a module key.
The stamp runner's refusals lose their history ("predates this harness")
and their essay, keeping every phrase step-errexit.sh matches; the
unchrooted escape hatch and stage 05's nested-tree check say what they
mean in a line. The console wrapper the console recipe writes gets one-
line comments, and firmware.list's header a tight format table. Stage
01's collapsed grep continuation is split again.
Fingerprints: the runner functions are excluded from every recipe's, and
stage 01's change leaves declare -f identical. The console recipe's
heredoc and firmware.list are step inputs, so the console step, the
linux-firmware step and every stage 04 step after them rebuild, with
stage 06; stage 05 builds on elfutils, earlier, so the kernel does not.
grep -c exits 1 when it counts nothing, and under the step's pipefail that aborted the recipe at the first such pattern, before its MISSING line and the summary that names them all.
… line each # Conflicts: # .github/actions/prepare/action.yml
…comments to one line # Conflicts: # compartments/tests/adversarial.sh # compartments/tests/launcher.sh
…ource, kernel and hardening checks # Conflicts: # tools/git-hooks/pre-commit
…lease, image and on-system tools # Conflicts: # tools/net/netzone-init.sh # tools/tests/s6-init-config.sh # tools/update/kryptik-recover
…ected against the code # Conflicts: # docs/design/zone-policy-files.md # docs/hardening.md
# Conflicts: # build/recipes/tests.sh # build/services/getty-tty1/run
…and comments; report every missing firmware pattern # Conflicts: # build/recipes/console.sh
…st names # Conflicts: # compartments/kryptikd/src/consent/tests.rs # compartments/kryptikd/src/netzone.rs # compartments/kryptikd/src/registry.rs # compartments/kryptikd/src/seccomp.rs # compartments/kryptikd/src/seccomp/tests.rs # compartments/kryptikd/src/spawn.rs
…nlisted setuid bit or capability: it fails the build, and strips nothing
| assert!(e.contains("user"), "{e}"); | ||
| assert!(e.contains("net"), "{e}"); | ||
| assert!(e.contains("tmpfs"), "explain must say what ephemeral storage IS: {e}"); | ||
| assert!(e.contains("tmpfs"), "explain must say what ephemeral storage is: {e}"); |
| || e.contains("NAT") | ||
| || e.contains("uid_base"); | ||
| assert!(honest, "explain must say who opens a routed zone's way out: {e}"); | ||
| assert!(says_who, "explain must say who opens a routed zone's way out: {e}"); |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Since c431bf4 stage 06 runs tools/audit-setuid.sh without --strip and fails the build on a setuid bit or file capability the allowlists do not justify. The first line of each allowlist and the tool's usage still said stage 06 strips them. Three comment lines. The allowlist text is part of the rootfs step's fingerprint, so stage 06 runs again once; main's run is the proof. Based on the cleanup tier (#206, #210, #199 reword the same lines), which goes into main with it.