Repository navigation
The clock's, the boot check's and the integrity and installer suites' comments are shorter, with their reasons kept - #248
Merged
Conversation
… comments are shorter, with their reasons kept: cleanup-held's cut of time.rs, docs/design/time.md, boot-check.sh, integrity-test.sh and tests/installer.sh, redone on main by hand, comments only Only comment regions are taken from 65a6fbb. Main's text stays wherever the cut would drop what main now relies on: the floor may be a later committed release; integrity-test.sh's header is its --help text, step 5 points at sysinit.sh's trust boundary and says why the attacker's payload is signed; the regulatory database is compressed like all of /lib/firmware. time.rs's module doc keeps why the time is a claim: only zone 0 sets the clock, and it has no network.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Part of the cleanup-held redo, after #241-#244, #246 and #247: the files that my merged batch (#231, #234, #236, #238) had held. Comments only in
compartments/kryptikd/src/time.rs,build/recipes/boot-check.sh,tools/image/integrity-test.shandtools/tests/installer.sh, and one sentence of prose indocs/design/time.md.How it was done. The same procedure as #242. Cleanup-held's change was merged onto main, and only regions where every changed line is a comment or blank were kept; code, messages and conflicts went back to main. Each kept cut was then read by hand. Stripping comments from main's version and this one gives the same code in all four files, and
bash -npasses on the shell ones. integrity-test.sh's--helpprints lines 2-22, and those lines are unchanged.Changed from the cut, to keep a reason it dropped: time.rs's module doc keeps why the time is a claim: only zone 0 sets the clock, and it has no network. As in the cut,
decide's purity moves ontodecide. boot-check.sh loses the stage 04 recipe header, as services.sh did in #241.Kept from main, because the cut is stale or loses what a reader needs:
Knowledge::flooris the build date or a later release this machine has committed to. The cut said the build date only, and it conflicted onfloor_of_this_systemfor the same reason.--help, so it keeps its charter. Step 5's introduction keeps its pointer to sysinit.sh's trust boundary. The attacker's payload keeps why it is signed: valid against the planted anchor, not against the image's.regulatory.db.zst.Dropped from the cut:
time/tests.rsrenames a test, which is code.docs/design/time.md's "Open points" says the committed release's date "is not used yet", but main now uses it.installer.sh: the cut removes the harness self-check and the unusednotehelper, and rewords a failure message. Those are code and messages.integrity-test.sh: the cut removes the--commit-slotrepair check and changessbattach's error handling, both code.How the run proves it. CI's compartment layer builds and tests kryptikd, and shell lint and the fixture step cover the shell files. Nothing else changes.