Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Expand sections dm-verity and hardening #26

Open
ThePlexus opened this issue Feb 11, 2019 · 1 comment
Open

Expand sections dm-verity and hardening #26

ThePlexus opened this issue Feb 11, 2019 · 1 comment
Assignees

Comments

@ThePlexus
Copy link
Contributor

The following need expanding;
"qubes read-only filesystem"
"dm-verity"
"Soldering jumpers on WP# pins, setting BP bits"

@ThePlexus ThePlexus changed the title Expand sections dm-verity and hadening Expand sections dm-verity and hardening Feb 11, 2019
@tlaurion
Copy link
Collaborator

@osresearch I'll remove dm-verity related documentation since it is misleading. Linked to #28

For reference:
dm-verity linked issue and discussion happened here

tlaurion added a commit that referenced this issue May 21, 2019
- Removed dm-verity section and hardware hardening sections (see #26 and originally linuxboot/heads#6)
- Removed recommended partition scheme in link to dm-verity for which changes were never merged into QubesOS (see #28), leaving the user with a unusable partition scheme ( 48Gb / used by QubesOS, the rest given but unused by /home)
tlaurion added a commit to linuxboot/heads that referenced this issue May 21, 2019
- dm-verity related instruction stripped (see linuxboot/heads-wiki#26)
- stripped Xen parts saying it needed to be patched. Was resolved by patching kexec instead of Xen (#227 (comment))
- Added a link to heads-wiki for documentation needs
@tlaurion tlaurion self-assigned this Apr 16, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants