-
Notifications
You must be signed in to change notification settings - Fork 76
lenovo-x1-gen11-hardening: build image with dm-verity #1074
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
22 tasks
mbssrc
reviewed
May 9, 2025
mbssrc
reviewed
May 9, 2025
mbssrc
reviewed
May 9, 2025
mbssrc
reviewed
May 9, 2025
mbssrc
approved these changes
May 13, 2025
Signed-off-by: Humaid Alqasimi <[email protected]>
Disko is able to generate the correct images without having the device path. And this is also not used in the repart image with dm-verity. Signed-off-by: Humaid Alqasimi <[email protected]>
18 tasks
brianmcgillion
added a commit
to brianmcgillion/ghaf
that referenced
this pull request
Jun 11, 2025
The vm test for the installer was broken by tiiuae#1074 and was not seen then. This change just fixes the path to the image that is to be flashed. Signed-off-by: Brian McGillion <[email protected]>
brianmcgillion
added a commit
to brianmcgillion/ghaf
that referenced
this pull request
Jun 11, 2025
The vm test for the installer was broken by tiiuae#1074 and was not seen then. This change just fixes the path to the image that is to be flashed. Signed-off-by: Brian McGillion <[email protected]>
brianmcgillion
added a commit
to brianmcgillion/ghaf
that referenced
this pull request
Jun 15, 2025
The vm test for the installer was broken by tiiuae#1074 and was not seen then. This change just fixes the path to the image that is to be flashed. Signed-off-by: Brian McGillion <[email protected]>
brianmcgillion
added a commit
to brianmcgillion/ghaf
that referenced
this pull request
Jun 15, 2025
The vm test for the installer was broken by tiiuae#1074 and was not seen then. This change just fixes the path to the image that is to be flashed. Signed-off-by: Brian McGillion <[email protected]>
brianmcgillion
added a commit
to brianmcgillion/ghaf
that referenced
this pull request
Jun 15, 2025
The vm test for the installer was broken by tiiuae#1074 and was not seen then. This change just fixes the path to the image that is to be flashed. Signed-off-by: Brian McGillion <[email protected]>
brianmcgillion
added a commit
that referenced
this pull request
Jun 16, 2025
The vm test for the installer was broken by #1074 and was not seen then. This change just fixes the path to the image that is to be flashed. Signed-off-by: Brian McGillion <[email protected]>
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Description of changes
This pull request builds upon #1005.
This pull request adds a new partitioning scheme in a new
lenovo-x1-gen11-hardeningtarget, where it would use the new image-based disk partitioning scheme. All other targets aren't yet updated, as this partitioning scheme is still experimental and to eventually be used for the release targets. For testing we enable it for the extras debug target too, as the release variant might not be functional. The goal of this target is also to be a testing ground for newer hardening techniques.The new partitioning scheme is similar to what is introduced in #1005, but it uses EROFS for the verity tree and root partitions. This is a read-only file system that will make the nix-store completely immutable, allowing us to verify that the system image hasn't been tampered with. EROFS is a modern and fast read-only filesystem, which would also help avoid unintentional tampering of the system.
Some refactoring has been done to allow multiple partitioning schemes without them affecting each other.
laptop-configuration-builder.nixand the ghaf installer script).Checklist for things done
x86_64aarch64riscv64make-checksand it passesnixos-rebuild ... switch: NOInstructions for Testing
lenovo-x1-gen11-hardeningonly.#lenovo-x1-gen11-hardening-debug-installer(do not test release).sudo veritysetup status rooton ghaf-host, should show status verified.