build: add rpm + gnupg (Fedora RPM GPG verification) - #10

Merged
HarryR merged 4 commits into
mainfrom
fedora44-kernel-bump
Jul 13, 2026
Merged

build: add rpm + gnupg (Fedora RPM GPG verification)#10
HarryR merged 4 commits into
mainfrom
fedora44-kernel-bump

Conversation

@HarryR

@HarryRHarryR commented Jul 10, 2026

Copy link
Copy Markdown
Contributor

What

Bring the stage0 build image and disk layout in line with the Fedora 44 chain bump, plus stable disk identity.

Changes

  • rpm + gnupg added to Dockerfile.build so the UKI build can verify Fedora package GPG signatures (image parity with stage1, kept byte-identical). No effect on compiled artifacts.
  • Stable lockboot GPT GUIDs + FAT volume-id.DISK_GUID / PART_GUID are now constant across releases (4c4f434b-424f-4f54-..., "LOCKBOOT" + a role index), so the initial GPT is byte-stable (stable pre-stage2 PCR5) and the boot disk is identifiable by a fixed GUID rather than by hashing stage0.efi (which changed per release). This is the stable identity stage2's find_boot_device can key on. (stage2 still rewrites the GPT at runtime to add p2/p3, which is why it excludes PCR5 from its key binding.)
  • Pin vaportpm-attest to v0.3.0 (rev + version guard), matching stage1.
  • Extract the shared DOCKER_RUN harness into build.mk (same refactor as stage1).

Verification

🤖 Generated with Claude Code

HarryRand others added 3 commits July 10, 2026 07:54
Needed so the UKI build can verify Fedora package GPG signatures (rpm/rpmkeys +
gnupg). Image parity: Dockerfile.build is kept byte-identical with stage1, whose
tools/build-uki now GPG-verifies the kernel + systemd-boot RPMs it downloads. No
effect on compiled artifacts.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Move the docker-images + DOCKER_RUN plumbing block out of the Makefile into a canonical build.mk that the Makefile now includes. This is the source of truth for the shared harness, vendored byte-identically into stage1/vaportpm via the workspace make sync-harness and guarded by make check-harness. Pure relocation -- make -n expands identically; docker-build-harness (stage0-only) stays in the Makefile.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Both stage0 crates floated on vaportpm main (no rev), and stage0's Cargo.lock is untracked, so vaportpm-attest resolved to main HEAD on every build -- no version stability for a measured bootloader. Pin to the v0.3.0 release commit (7041f461) with a version = "=0.3.0" guard, keeping default-features = false (no_std core: Tpm, PcrOps, TpmTransport). Verified: stage0.efi and payload.efi build clean for x86_64-unknown-uefi against v0.3.0.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@HarryR
HarryRforce-pushed the fedora44-kernel-bump branch from fcda1b0 to 9e64f6eCompareJuly 11, 2026 19:43
…entifiable)
Replace the stage0.efi-hash-derived DISK_GUID/PART_GUID/VOLUME_ID with fixed
constants ("4c4f434b424f4f54" spells "LOCKBOOT"; last group a role index:
disk = 0, ESP = partition 1). Constant across releases so the GPT -- and hence
the firmware's PCR 5 measurement -- is byte-stable, and a lockboot disk is
identifiable by GUID. Dependency of stage2, which locates the boot disk by GUID
and rewrites the GPT to add its runtime/data partitions; a stable base GPT keeps
PCR 5 predictable. The stage0.efi hash still feeds BUILD_ID.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@HarryR
HarryR marked this pull request as ready for review July 13, 2026 18:03
@HarryR
HarryR merged commit 8cb8b11 into mainJul 13, 2026
3 checks passed
@HarryR
HarryR deleted the fedora44-kernel-bump branch July 13, 2026 19:23
HarryR added a commit to lockboot/stage1 that referenced this pull request Jul 13, 2026
…#19)
## What
Bring the UKI to a current, GPG-verified Fedora 44 base, bundle the
kernel modules stage2 needs, and supporting build cleanups.
## Kernel + stub
- Bump kernel `6.12.4-200.fc41` -> `7.0.12-201.fc44` and systemd-boot
stub `256.17-1.fc41` -> `259.6-1.fc44` (what Fedora CoreOS
44.20260621.3.1 ships). `fc41` is EOL; the kernel was ~18 months behind.
- **GPG verification (mandatory):** `download-verify-rpm.sh` fetches
from koji's *signed* path (plain `packages/` is unsigned) and verifies
each RPM against `keys/RPM-GPG-KEY-fedora-44-primary` (fp `36F6 12DC
F27F 7D1A 48A8 35E4 DBFC F71C 6D9F 90A6`) on every build.
- **Automated bumps:** pins live in generated
`tools/build-uki/fedora-deps.mk`; `make update-fedora-deps FCOS=...
SYSTEMD=...` reads the FCOS manifest, downloads + GPG-verifies the
signed RPMs, and rewrites the pins.
## Storage modules for stage2
- Bundle + explicitly load (in dependency order, before the
`modules_disabled` latch) the modules stage2's loader needs:
**dm-crypt** (encrypted /data), **dm-verity** + **reed_solomon**
(integrity-checked erofs runtime + FEC dep), **overlay** (ephemeral
root), **erofs** + **netfs** (RO image fs + dep), and the **nvme** chain
(hkdf -> nvme-auth/keyring -> nvme-core -> nvme; EC2 EBS + the harness
disk are NVMe). The payload cannot load modules itself, and an
unresolved dep can't be pulled once the latch is set, so deps are listed
explicitly.
- Module comments describe each dependency's capability generically.
**Authenticated /data (dm-integrity + async_xor/async_tx) is documented
as an extension point but not shipped** -- stage2 uses
confidentiality-only dm-crypt, so those are omitted to keep the measured
initramfs minimal.
## Build
- Pin `vaportpm-attest` to v0.3.0 (rev + version guard).
- Extract the shared `DOCKER_RUN` harness into `build.mk`.
- Drop a stale `kernel-hash-%` target.
## Verification
- ena (AWS) + gve (GCP) present in 7.0.12; all required `.ko.xz` copy.
- `make test-chain-x86_64 SIGN=1 / MANIFEST=1 / SIGN_ARGS=1` boot `Linux
7.0.12-201.fc44` end to end and run stage2.
- lockboot/stage2's XTS pivot test passes end to end on this UKI
(`PIVOT_TEST=PASS`), dm-integrity absent from the boot.
- aarch64 pins are GPG-verified but not boot-tested here.
Pairs with lockboot/stage0#10 (image parity: rpm+gnupg, shared harness,
vaportpm pin, stable GUIDs).
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@HarryR
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

build: add rpm + gnupg (Fedora RPM GPG verification) - #10

Merged
HarryR merged 4 commits into
mainfrom
fedora44-kernel-bump
Jul 13, 2026
Merged

build: add rpm + gnupg (Fedora RPM GPG verification)#10
HarryR merged 4 commits into
mainfrom
fedora44-kernel-bump

Conversation

@HarryR

@HarryRHarryR commented Jul 10, 2026

Copy link
Copy Markdown
Contributor

What

Bring the stage0 build image and disk layout in line with the Fedora 44 chain bump, plus stable disk identity.

Changes

  • rpm + gnupg added to Dockerfile.build so the UKI build can verify Fedora package GPG signatures (image parity with stage1, kept byte-identical). No effect on compiled artifacts.
  • Stable lockboot GPT GUIDs + FAT volume-id.DISK_GUID / PART_GUID are now constant across releases (4c4f434b-424f-4f54-..., "LOCKBOOT" + a role index), so the initial GPT is byte-stable (stable pre-stage2 PCR5) and the boot disk is identifiable by a fixed GUID rather than by hashing stage0.efi (which changed per release). This is the stable identity stage2's find_boot_device can key on. (stage2 still rewrites the GPT at runtime to add p2/p3, which is why it excludes PCR5 from its key binding.)
  • Pin vaportpm-attest to v0.3.0 (rev + version guard), matching stage1.
  • Extract the shared DOCKER_RUN harness into build.mk (same refactor as stage1).

Verification

🤖 Generated with Claude Code

HarryRand others added 3 commits July 10, 2026 07:54
Needed so the UKI build can verify Fedora package GPG signatures (rpm/rpmkeys +
gnupg). Image parity: Dockerfile.build is kept byte-identical with stage1, whose
tools/build-uki now GPG-verifies the kernel + systemd-boot RPMs it downloads. No
effect on compiled artifacts.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Move the docker-images + DOCKER_RUN plumbing block out of the Makefile into a canonical build.mk that the Makefile now includes. This is the source of truth for the shared harness, vendored byte-identically into stage1/vaportpm via the workspace make sync-harness and guarded by make check-harness. Pure relocation -- make -n expands identically; docker-build-harness (stage0-only) stays in the Makefile.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Both stage0 crates floated on vaportpm main (no rev), and stage0's Cargo.lock is untracked, so vaportpm-attest resolved to main HEAD on every build -- no version stability for a measured bootloader. Pin to the v0.3.0 release commit (7041f461) with a version = "=0.3.0" guard, keeping default-features = false (no_std core: Tpm, PcrOps, TpmTransport). Verified: stage0.efi and payload.efi build clean for x86_64-unknown-uefi against v0.3.0.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@HarryR
HarryRforce-pushed the fedora44-kernel-bump branch from fcda1b0 to 9e64f6eCompareJuly 11, 2026 19:43
…entifiable)
Replace the stage0.efi-hash-derived DISK_GUID/PART_GUID/VOLUME_ID with fixed
constants ("4c4f434b424f4f54" spells "LOCKBOOT"; last group a role index:
disk = 0, ESP = partition 1). Constant across releases so the GPT -- and hence
the firmware's PCR 5 measurement -- is byte-stable, and a lockboot disk is
identifiable by GUID. Dependency of stage2, which locates the boot disk by GUID
and rewrites the GPT to add its runtime/data partitions; a stable base GPT keeps
PCR 5 predictable. The stage0.efi hash still feeds BUILD_ID.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@HarryR
HarryR marked this pull request as ready for review July 13, 2026 18:03
@HarryR
HarryR merged commit 8cb8b11 into mainJul 13, 2026
3 checks passed
@HarryR
HarryR deleted the fedora44-kernel-bump branch July 13, 2026 19:23
HarryR added a commit to lockboot/stage1 that referenced this pull request Jul 13, 2026
…#19)
## What
Bring the UKI to a current, GPG-verified Fedora 44 base, bundle the
kernel modules stage2 needs, and supporting build cleanups.
## Kernel + stub
- Bump kernel `6.12.4-200.fc41` -> `7.0.12-201.fc44` and systemd-boot
stub `256.17-1.fc41` -> `259.6-1.fc44` (what Fedora CoreOS
44.20260621.3.1 ships). `fc41` is EOL; the kernel was ~18 months behind.
- **GPG verification (mandatory):** `download-verify-rpm.sh` fetches
from koji's *signed* path (plain `packages/` is unsigned) and verifies
each RPM against `keys/RPM-GPG-KEY-fedora-44-primary` (fp `36F6 12DC
F27F 7D1A 48A8 35E4 DBFC F71C 6D9F 90A6`) on every build.
- **Automated bumps:** pins live in generated
`tools/build-uki/fedora-deps.mk`; `make update-fedora-deps FCOS=...
SYSTEMD=...` reads the FCOS manifest, downloads + GPG-verifies the
signed RPMs, and rewrites the pins.
## Storage modules for stage2
- Bundle + explicitly load (in dependency order, before the
`modules_disabled` latch) the modules stage2's loader needs:
**dm-crypt** (encrypted /data), **dm-verity** + **reed_solomon**
(integrity-checked erofs runtime + FEC dep), **overlay** (ephemeral
root), **erofs** + **netfs** (RO image fs + dep), and the **nvme** chain
(hkdf -> nvme-auth/keyring -> nvme-core -> nvme; EC2 EBS + the harness
disk are NVMe). The payload cannot load modules itself, and an
unresolved dep can't be pulled once the latch is set, so deps are listed
explicitly.
- Module comments describe each dependency's capability generically.
**Authenticated /data (dm-integrity + async_xor/async_tx) is documented
as an extension point but not shipped** -- stage2 uses
confidentiality-only dm-crypt, so those are omitted to keep the measured
initramfs minimal.
## Build
- Pin `vaportpm-attest` to v0.3.0 (rev + version guard).
- Extract the shared `DOCKER_RUN` harness into `build.mk`.
- Drop a stale `kernel-hash-%` target.
## Verification
- ena (AWS) + gve (GCP) present in 7.0.12; all required `.ko.xz` copy.
- `make test-chain-x86_64 SIGN=1 / MANIFEST=1 / SIGN_ARGS=1` boot `Linux
7.0.12-201.fc44` end to end and run stage2.
- lockboot/stage2's XTS pivot test passes end to end on this UKI
(`PIVOT_TEST=PASS`), dm-integrity absent from the boot.
- aarch64 pins are GPG-verified but not boot-tested here.
Pairs with lockboot/stage0#10 (image parity: rpm+gnupg, shared harness,
vaportpm pin, stable GUIDs).
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@HarryR
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

build: add rpm + gnupg (Fedora RPM GPG verification) - #10

Merged
HarryR merged 4 commits into
mainfrom
fedora44-kernel-bump
Jul 13, 2026
Merged

build: add rpm + gnupg (Fedora RPM GPG verification)#10
HarryR merged 4 commits into
mainfrom
fedora44-kernel-bump

Conversation

@HarryR

@HarryRHarryR commented Jul 10, 2026

Copy link
Copy Markdown
Contributor

What

Bring the stage0 build image and disk layout in line with the Fedora 44 chain bump, plus stable disk identity.

Changes

  • rpm + gnupg added to Dockerfile.build so the UKI build can verify Fedora package GPG signatures (image parity with stage1, kept byte-identical). No effect on compiled artifacts.
  • Stable lockboot GPT GUIDs + FAT volume-id.DISK_GUID / PART_GUID are now constant across releases (4c4f434b-424f-4f54-..., "LOCKBOOT" + a role index), so the initial GPT is byte-stable (stable pre-stage2 PCR5) and the boot disk is identifiable by a fixed GUID rather than by hashing stage0.efi (which changed per release). This is the stable identity stage2's find_boot_device can key on. (stage2 still rewrites the GPT at runtime to add p2/p3, which is why it excludes PCR5 from its key binding.)
  • Pin vaportpm-attest to v0.3.0 (rev + version guard), matching stage1.
  • Extract the shared DOCKER_RUN harness into build.mk (same refactor as stage1).

Verification

🤖 Generated with Claude Code

HarryRand others added 3 commits July 10, 2026 07:54
Needed so the UKI build can verify Fedora package GPG signatures (rpm/rpmkeys +
gnupg). Image parity: Dockerfile.build is kept byte-identical with stage1, whose
tools/build-uki now GPG-verifies the kernel + systemd-boot RPMs it downloads. No
effect on compiled artifacts.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Move the docker-images + DOCKER_RUN plumbing block out of the Makefile into a canonical build.mk that the Makefile now includes. This is the source of truth for the shared harness, vendored byte-identically into stage1/vaportpm via the workspace make sync-harness and guarded by make check-harness. Pure relocation -- make -n expands identically; docker-build-harness (stage0-only) stays in the Makefile.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Both stage0 crates floated on vaportpm main (no rev), and stage0's Cargo.lock is untracked, so vaportpm-attest resolved to main HEAD on every build -- no version stability for a measured bootloader. Pin to the v0.3.0 release commit (7041f461) with a version = "=0.3.0" guard, keeping default-features = false (no_std core: Tpm, PcrOps, TpmTransport). Verified: stage0.efi and payload.efi build clean for x86_64-unknown-uefi against v0.3.0.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@HarryR
HarryRforce-pushed the fedora44-kernel-bump branch from fcda1b0 to 9e64f6eCompareJuly 11, 2026 19:43
…entifiable)
Replace the stage0.efi-hash-derived DISK_GUID/PART_GUID/VOLUME_ID with fixed
constants ("4c4f434b424f4f54" spells "LOCKBOOT"; last group a role index:
disk = 0, ESP = partition 1). Constant across releases so the GPT -- and hence
the firmware's PCR 5 measurement -- is byte-stable, and a lockboot disk is
identifiable by GUID. Dependency of stage2, which locates the boot disk by GUID
and rewrites the GPT to add its runtime/data partitions; a stable base GPT keeps
PCR 5 predictable. The stage0.efi hash still feeds BUILD_ID.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@HarryR
HarryR marked this pull request as ready for review July 13, 2026 18:03
@HarryR
HarryR merged commit 8cb8b11 into mainJul 13, 2026
3 checks passed
@HarryR
HarryR deleted the fedora44-kernel-bump branch July 13, 2026 19:23
HarryR added a commit to lockboot/stage1 that referenced this pull request Jul 13, 2026
…#19)
## What
Bring the UKI to a current, GPG-verified Fedora 44 base, bundle the
kernel modules stage2 needs, and supporting build cleanups.
## Kernel + stub
- Bump kernel `6.12.4-200.fc41` -> `7.0.12-201.fc44` and systemd-boot
stub `256.17-1.fc41` -> `259.6-1.fc44` (what Fedora CoreOS
44.20260621.3.1 ships). `fc41` is EOL; the kernel was ~18 months behind.
- **GPG verification (mandatory):** `download-verify-rpm.sh` fetches
from koji's *signed* path (plain `packages/` is unsigned) and verifies
each RPM against `keys/RPM-GPG-KEY-fedora-44-primary` (fp `36F6 12DC
F27F 7D1A 48A8 35E4 DBFC F71C 6D9F 90A6`) on every build.
- **Automated bumps:** pins live in generated
`tools/build-uki/fedora-deps.mk`; `make update-fedora-deps FCOS=...
SYSTEMD=...` reads the FCOS manifest, downloads + GPG-verifies the
signed RPMs, and rewrites the pins.
## Storage modules for stage2
- Bundle + explicitly load (in dependency order, before the
`modules_disabled` latch) the modules stage2's loader needs:
**dm-crypt** (encrypted /data), **dm-verity** + **reed_solomon**
(integrity-checked erofs runtime + FEC dep), **overlay** (ephemeral
root), **erofs** + **netfs** (RO image fs + dep), and the **nvme** chain
(hkdf -> nvme-auth/keyring -> nvme-core -> nvme; EC2 EBS + the harness
disk are NVMe). The payload cannot load modules itself, and an
unresolved dep can't be pulled once the latch is set, so deps are listed
explicitly.
- Module comments describe each dependency's capability generically.
**Authenticated /data (dm-integrity + async_xor/async_tx) is documented
as an extension point but not shipped** -- stage2 uses
confidentiality-only dm-crypt, so those are omitted to keep the measured
initramfs minimal.
## Build
- Pin `vaportpm-attest` to v0.3.0 (rev + version guard).
- Extract the shared `DOCKER_RUN` harness into `build.mk`.
- Drop a stale `kernel-hash-%` target.
## Verification
- ena (AWS) + gve (GCP) present in 7.0.12; all required `.ko.xz` copy.
- `make test-chain-x86_64 SIGN=1 / MANIFEST=1 / SIGN_ARGS=1` boot `Linux
7.0.12-201.fc44` end to end and run stage2.
- lockboot/stage2's XTS pivot test passes end to end on this UKI
(`PIVOT_TEST=PASS`), dm-integrity absent from the boot.
- aarch64 pins are GPG-verified but not boot-tested here.
Pairs with lockboot/stage0#10 (image parity: rpm+gnupg, shared harness,
vaportpm pin, stable GUIDs).
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@HarryR
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

build: add rpm + gnupg (Fedora RPM GPG verification) - #10

Merged
HarryR merged 4 commits into
mainfrom
fedora44-kernel-bump
Jul 13, 2026
Merged

build: add rpm + gnupg (Fedora RPM GPG verification)#10
HarryR merged 4 commits into
mainfrom
fedora44-kernel-bump

Conversation

@HarryR

@HarryRHarryR commented Jul 10, 2026

Copy link
Copy Markdown
Contributor

What

Bring the stage0 build image and disk layout in line with the Fedora 44 chain bump, plus stable disk identity.

Changes

  • rpm + gnupg added to Dockerfile.build so the UKI build can verify Fedora package GPG signatures (image parity with stage1, kept byte-identical). No effect on compiled artifacts.
  • Stable lockboot GPT GUIDs + FAT volume-id.DISK_GUID / PART_GUID are now constant across releases (4c4f434b-424f-4f54-..., "LOCKBOOT" + a role index), so the initial GPT is byte-stable (stable pre-stage2 PCR5) and the boot disk is identifiable by a fixed GUID rather than by hashing stage0.efi (which changed per release). This is the stable identity stage2's find_boot_device can key on. (stage2 still rewrites the GPT at runtime to add p2/p3, which is why it excludes PCR5 from its key binding.)
  • Pin vaportpm-attest to v0.3.0 (rev + version guard), matching stage1.
  • Extract the shared DOCKER_RUN harness into build.mk (same refactor as stage1).

Verification

🤖 Generated with Claude Code

HarryRand others added 3 commits July 10, 2026 07:54
Needed so the UKI build can verify Fedora package GPG signatures (rpm/rpmkeys +
gnupg). Image parity: Dockerfile.build is kept byte-identical with stage1, whose
tools/build-uki now GPG-verifies the kernel + systemd-boot RPMs it downloads. No
effect on compiled artifacts.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Move the docker-images + DOCKER_RUN plumbing block out of the Makefile into a canonical build.mk that the Makefile now includes. This is the source of truth for the shared harness, vendored byte-identically into stage1/vaportpm via the workspace make sync-harness and guarded by make check-harness. Pure relocation -- make -n expands identically; docker-build-harness (stage0-only) stays in the Makefile.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Both stage0 crates floated on vaportpm main (no rev), and stage0's Cargo.lock is untracked, so vaportpm-attest resolved to main HEAD on every build -- no version stability for a measured bootloader. Pin to the v0.3.0 release commit (7041f461) with a version = "=0.3.0" guard, keeping default-features = false (no_std core: Tpm, PcrOps, TpmTransport). Verified: stage0.efi and payload.efi build clean for x86_64-unknown-uefi against v0.3.0.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@HarryR
HarryRforce-pushed the fedora44-kernel-bump branch from fcda1b0 to 9e64f6eCompareJuly 11, 2026 19:43
…entifiable)
Replace the stage0.efi-hash-derived DISK_GUID/PART_GUID/VOLUME_ID with fixed
constants ("4c4f434b424f4f54" spells "LOCKBOOT"; last group a role index:
disk = 0, ESP = partition 1). Constant across releases so the GPT -- and hence
the firmware's PCR 5 measurement -- is byte-stable, and a lockboot disk is
identifiable by GUID. Dependency of stage2, which locates the boot disk by GUID
and rewrites the GPT to add its runtime/data partitions; a stable base GPT keeps
PCR 5 predictable. The stage0.efi hash still feeds BUILD_ID.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@HarryR
HarryR marked this pull request as ready for review July 13, 2026 18:03
@HarryR
HarryR merged commit 8cb8b11 into mainJul 13, 2026
3 checks passed
@HarryR
HarryR deleted the fedora44-kernel-bump branch July 13, 2026 19:23
HarryR added a commit to lockboot/stage1 that referenced this pull request Jul 13, 2026
…#19)
## What
Bring the UKI to a current, GPG-verified Fedora 44 base, bundle the
kernel modules stage2 needs, and supporting build cleanups.
## Kernel + stub
- Bump kernel `6.12.4-200.fc41` -> `7.0.12-201.fc44` and systemd-boot
stub `256.17-1.fc41` -> `259.6-1.fc44` (what Fedora CoreOS
44.20260621.3.1 ships). `fc41` is EOL; the kernel was ~18 months behind.
- **GPG verification (mandatory):** `download-verify-rpm.sh` fetches
from koji's *signed* path (plain `packages/` is unsigned) and verifies
each RPM against `keys/RPM-GPG-KEY-fedora-44-primary` (fp `36F6 12DC
F27F 7D1A 48A8 35E4 DBFC F71C 6D9F 90A6`) on every build.
- **Automated bumps:** pins live in generated
`tools/build-uki/fedora-deps.mk`; `make update-fedora-deps FCOS=...
SYSTEMD=...` reads the FCOS manifest, downloads + GPG-verifies the
signed RPMs, and rewrites the pins.
## Storage modules for stage2
- Bundle + explicitly load (in dependency order, before the
`modules_disabled` latch) the modules stage2's loader needs:
**dm-crypt** (encrypted /data), **dm-verity** + **reed_solomon**
(integrity-checked erofs runtime + FEC dep), **overlay** (ephemeral
root), **erofs** + **netfs** (RO image fs + dep), and the **nvme** chain
(hkdf -> nvme-auth/keyring -> nvme-core -> nvme; EC2 EBS + the harness
disk are NVMe). The payload cannot load modules itself, and an
unresolved dep can't be pulled once the latch is set, so deps are listed
explicitly.
- Module comments describe each dependency's capability generically.
**Authenticated /data (dm-integrity + async_xor/async_tx) is documented
as an extension point but not shipped** -- stage2 uses
confidentiality-only dm-crypt, so those are omitted to keep the measured
initramfs minimal.
## Build
- Pin `vaportpm-attest` to v0.3.0 (rev + version guard).
- Extract the shared `DOCKER_RUN` harness into `build.mk`.
- Drop a stale `kernel-hash-%` target.
## Verification
- ena (AWS) + gve (GCP) present in 7.0.12; all required `.ko.xz` copy.
- `make test-chain-x86_64 SIGN=1 / MANIFEST=1 / SIGN_ARGS=1` boot `Linux
7.0.12-201.fc44` end to end and run stage2.
- lockboot/stage2's XTS pivot test passes end to end on this UKI
(`PIVOT_TEST=PASS`), dm-integrity absent from the boot.
- aarch64 pins are GPG-verified but not boot-tested here.
Pairs with lockboot/stage0#10 (image parity: rpm+gnupg, shared harness,
vaportpm pin, stable GUIDs).
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@HarryR
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

build: add rpm + gnupg (Fedora RPM GPG verification) - #10

Merged
HarryR merged 4 commits into
mainfrom
fedora44-kernel-bump
Jul 13, 2026
Merged

build: add rpm + gnupg (Fedora RPM GPG verification)#10
HarryR merged 4 commits into
mainfrom
fedora44-kernel-bump

Conversation

@HarryR

@HarryRHarryR commented Jul 10, 2026

Copy link
Copy Markdown
Contributor

What

Bring the stage0 build image and disk layout in line with the Fedora 44 chain bump, plus stable disk identity.

Changes

  • rpm + gnupg added to Dockerfile.build so the UKI build can verify Fedora package GPG signatures (image parity with stage1, kept byte-identical). No effect on compiled artifacts.
  • Stable lockboot GPT GUIDs + FAT volume-id.DISK_GUID / PART_GUID are now constant across releases (4c4f434b-424f-4f54-..., "LOCKBOOT" + a role index), so the initial GPT is byte-stable (stable pre-stage2 PCR5) and the boot disk is identifiable by a fixed GUID rather than by hashing stage0.efi (which changed per release). This is the stable identity stage2's find_boot_device can key on. (stage2 still rewrites the GPT at runtime to add p2/p3, which is why it excludes PCR5 from its key binding.)
  • Pin vaportpm-attest to v0.3.0 (rev + version guard), matching stage1.
  • Extract the shared DOCKER_RUN harness into build.mk (same refactor as stage1).

Verification

🤖 Generated with Claude Code

HarryRand others added 3 commits July 10, 2026 07:54
Needed so the UKI build can verify Fedora package GPG signatures (rpm/rpmkeys +
gnupg). Image parity: Dockerfile.build is kept byte-identical with stage1, whose
tools/build-uki now GPG-verifies the kernel + systemd-boot RPMs it downloads. No
effect on compiled artifacts.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Move the docker-images + DOCKER_RUN plumbing block out of the Makefile into a canonical build.mk that the Makefile now includes. This is the source of truth for the shared harness, vendored byte-identically into stage1/vaportpm via the workspace make sync-harness and guarded by make check-harness. Pure relocation -- make -n expands identically; docker-build-harness (stage0-only) stays in the Makefile.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Both stage0 crates floated on vaportpm main (no rev), and stage0's Cargo.lock is untracked, so vaportpm-attest resolved to main HEAD on every build -- no version stability for a measured bootloader. Pin to the v0.3.0 release commit (7041f461) with a version = "=0.3.0" guard, keeping default-features = false (no_std core: Tpm, PcrOps, TpmTransport). Verified: stage0.efi and payload.efi build clean for x86_64-unknown-uefi against v0.3.0.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@HarryR
HarryRforce-pushed the fedora44-kernel-bump branch from fcda1b0 to 9e64f6eCompareJuly 11, 2026 19:43
…entifiable)
Replace the stage0.efi-hash-derived DISK_GUID/PART_GUID/VOLUME_ID with fixed
constants ("4c4f434b424f4f54" spells "LOCKBOOT"; last group a role index:
disk = 0, ESP = partition 1). Constant across releases so the GPT -- and hence
the firmware's PCR 5 measurement -- is byte-stable, and a lockboot disk is
identifiable by GUID. Dependency of stage2, which locates the boot disk by GUID
and rewrites the GPT to add its runtime/data partitions; a stable base GPT keeps
PCR 5 predictable. The stage0.efi hash still feeds BUILD_ID.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@HarryR
HarryR marked this pull request as ready for review July 13, 2026 18:03
@HarryR
HarryR merged commit 8cb8b11 into mainJul 13, 2026
3 checks passed
@HarryR
HarryR deleted the fedora44-kernel-bump branch July 13, 2026 19:23
HarryR added a commit to lockboot/stage1 that referenced this pull request Jul 13, 2026
…#19)
## What
Bring the UKI to a current, GPG-verified Fedora 44 base, bundle the
kernel modules stage2 needs, and supporting build cleanups.
## Kernel + stub
- Bump kernel `6.12.4-200.fc41` -> `7.0.12-201.fc44` and systemd-boot
stub `256.17-1.fc41` -> `259.6-1.fc44` (what Fedora CoreOS
44.20260621.3.1 ships). `fc41` is EOL; the kernel was ~18 months behind.
- **GPG verification (mandatory):** `download-verify-rpm.sh` fetches
from koji's *signed* path (plain `packages/` is unsigned) and verifies
each RPM against `keys/RPM-GPG-KEY-fedora-44-primary` (fp `36F6 12DC
F27F 7D1A 48A8 35E4 DBFC F71C 6D9F 90A6`) on every build.
- **Automated bumps:** pins live in generated
`tools/build-uki/fedora-deps.mk`; `make update-fedora-deps FCOS=...
SYSTEMD=...` reads the FCOS manifest, downloads + GPG-verifies the
signed RPMs, and rewrites the pins.
## Storage modules for stage2
- Bundle + explicitly load (in dependency order, before the
`modules_disabled` latch) the modules stage2's loader needs:
**dm-crypt** (encrypted /data), **dm-verity** + **reed_solomon**
(integrity-checked erofs runtime + FEC dep), **overlay** (ephemeral
root), **erofs** + **netfs** (RO image fs + dep), and the **nvme** chain
(hkdf -> nvme-auth/keyring -> nvme-core -> nvme; EC2 EBS + the harness
disk are NVMe). The payload cannot load modules itself, and an
unresolved dep can't be pulled once the latch is set, so deps are listed
explicitly.
- Module comments describe each dependency's capability generically.
**Authenticated /data (dm-integrity + async_xor/async_tx) is documented
as an extension point but not shipped** -- stage2 uses
confidentiality-only dm-crypt, so those are omitted to keep the measured
initramfs minimal.
## Build
- Pin `vaportpm-attest` to v0.3.0 (rev + version guard).
- Extract the shared `DOCKER_RUN` harness into `build.mk`.
- Drop a stale `kernel-hash-%` target.
## Verification
- ena (AWS) + gve (GCP) present in 7.0.12; all required `.ko.xz` copy.
- `make test-chain-x86_64 SIGN=1 / MANIFEST=1 / SIGN_ARGS=1` boot `Linux
7.0.12-201.fc44` end to end and run stage2.
- lockboot/stage2's XTS pivot test passes end to end on this UKI
(`PIVOT_TEST=PASS`), dm-integrity absent from the boot.
- aarch64 pins are GPG-verified but not boot-tested here.
Pairs with lockboot/stage0#10 (image parity: rpm+gnupg, shared harness,
vaportpm pin, stable GUIDs).
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@HarryR
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

build: add rpm + gnupg (Fedora RPM GPG verification) - #10

Merged
HarryR merged 4 commits into
mainfrom
fedora44-kernel-bump
Jul 13, 2026
Merged

build: add rpm + gnupg (Fedora RPM GPG verification)#10
HarryR merged 4 commits into
mainfrom
fedora44-kernel-bump

Conversation

@HarryR

@HarryRHarryR commented Jul 10, 2026

Copy link
Copy Markdown
Contributor

What

Bring the stage0 build image and disk layout in line with the Fedora 44 chain bump, plus stable disk identity.

Changes

  • rpm + gnupg added to Dockerfile.build so the UKI build can verify Fedora package GPG signatures (image parity with stage1, kept byte-identical). No effect on compiled artifacts.
  • Stable lockboot GPT GUIDs + FAT volume-id.DISK_GUID / PART_GUID are now constant across releases (4c4f434b-424f-4f54-..., "LOCKBOOT" + a role index), so the initial GPT is byte-stable (stable pre-stage2 PCR5) and the boot disk is identifiable by a fixed GUID rather than by hashing stage0.efi (which changed per release). This is the stable identity stage2's find_boot_device can key on. (stage2 still rewrites the GPT at runtime to add p2/p3, which is why it excludes PCR5 from its key binding.)
  • Pin vaportpm-attest to v0.3.0 (rev + version guard), matching stage1.
  • Extract the shared DOCKER_RUN harness into build.mk (same refactor as stage1).

Verification

🤖 Generated with Claude Code

HarryRand others added 3 commits July 10, 2026 07:54
Needed so the UKI build can verify Fedora package GPG signatures (rpm/rpmkeys +
gnupg). Image parity: Dockerfile.build is kept byte-identical with stage1, whose
tools/build-uki now GPG-verifies the kernel + systemd-boot RPMs it downloads. No
effect on compiled artifacts.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Move the docker-images + DOCKER_RUN plumbing block out of the Makefile into a canonical build.mk that the Makefile now includes. This is the source of truth for the shared harness, vendored byte-identically into stage1/vaportpm via the workspace make sync-harness and guarded by make check-harness. Pure relocation -- make -n expands identically; docker-build-harness (stage0-only) stays in the Makefile.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Both stage0 crates floated on vaportpm main (no rev), and stage0's Cargo.lock is untracked, so vaportpm-attest resolved to main HEAD on every build -- no version stability for a measured bootloader. Pin to the v0.3.0 release commit (7041f461) with a version = "=0.3.0" guard, keeping default-features = false (no_std core: Tpm, PcrOps, TpmTransport). Verified: stage0.efi and payload.efi build clean for x86_64-unknown-uefi against v0.3.0.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@HarryR
HarryRforce-pushed the fedora44-kernel-bump branch from fcda1b0 to 9e64f6eCompareJuly 11, 2026 19:43
…entifiable)
Replace the stage0.efi-hash-derived DISK_GUID/PART_GUID/VOLUME_ID with fixed
constants ("4c4f434b424f4f54" spells "LOCKBOOT"; last group a role index:
disk = 0, ESP = partition 1). Constant across releases so the GPT -- and hence
the firmware's PCR 5 measurement -- is byte-stable, and a lockboot disk is
identifiable by GUID. Dependency of stage2, which locates the boot disk by GUID
and rewrites the GPT to add its runtime/data partitions; a stable base GPT keeps
PCR 5 predictable. The stage0.efi hash still feeds BUILD_ID.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@HarryR
HarryR marked this pull request as ready for review July 13, 2026 18:03
@HarryR
HarryR merged commit 8cb8b11 into mainJul 13, 2026
3 checks passed
@HarryR
HarryR deleted the fedora44-kernel-bump branch July 13, 2026 19:23
HarryR added a commit to lockboot/stage1 that referenced this pull request Jul 13, 2026
…#19)
## What
Bring the UKI to a current, GPG-verified Fedora 44 base, bundle the
kernel modules stage2 needs, and supporting build cleanups.
## Kernel + stub
- Bump kernel `6.12.4-200.fc41` -> `7.0.12-201.fc44` and systemd-boot
stub `256.17-1.fc41` -> `259.6-1.fc44` (what Fedora CoreOS
44.20260621.3.1 ships). `fc41` is EOL; the kernel was ~18 months behind.
- **GPG verification (mandatory):** `download-verify-rpm.sh` fetches
from koji's *signed* path (plain `packages/` is unsigned) and verifies
each RPM against `keys/RPM-GPG-KEY-fedora-44-primary` (fp `36F6 12DC
F27F 7D1A 48A8 35E4 DBFC F71C 6D9F 90A6`) on every build.
- **Automated bumps:** pins live in generated
`tools/build-uki/fedora-deps.mk`; `make update-fedora-deps FCOS=...
SYSTEMD=...` reads the FCOS manifest, downloads + GPG-verifies the
signed RPMs, and rewrites the pins.
## Storage modules for stage2
- Bundle + explicitly load (in dependency order, before the
`modules_disabled` latch) the modules stage2's loader needs:
**dm-crypt** (encrypted /data), **dm-verity** + **reed_solomon**
(integrity-checked erofs runtime + FEC dep), **overlay** (ephemeral
root), **erofs** + **netfs** (RO image fs + dep), and the **nvme** chain
(hkdf -> nvme-auth/keyring -> nvme-core -> nvme; EC2 EBS + the harness
disk are NVMe). The payload cannot load modules itself, and an
unresolved dep can't be pulled once the latch is set, so deps are listed
explicitly.
- Module comments describe each dependency's capability generically.
**Authenticated /data (dm-integrity + async_xor/async_tx) is documented
as an extension point but not shipped** -- stage2 uses
confidentiality-only dm-crypt, so those are omitted to keep the measured
initramfs minimal.
## Build
- Pin `vaportpm-attest` to v0.3.0 (rev + version guard).
- Extract the shared `DOCKER_RUN` harness into `build.mk`.
- Drop a stale `kernel-hash-%` target.
## Verification
- ena (AWS) + gve (GCP) present in 7.0.12; all required `.ko.xz` copy.
- `make test-chain-x86_64 SIGN=1 / MANIFEST=1 / SIGN_ARGS=1` boot `Linux
7.0.12-201.fc44` end to end and run stage2.
- lockboot/stage2's XTS pivot test passes end to end on this UKI
(`PIVOT_TEST=PASS`), dm-integrity absent from the boot.
- aarch64 pins are GPG-verified but not boot-tested here.
Pairs with lockboot/stage0#10 (image parity: rpm+gnupg, shared harness,
vaportpm pin, stable GUIDs).
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@HarryR
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

build: add rpm + gnupg (Fedora RPM GPG verification) - #10

Merged
HarryR merged 4 commits into
mainfrom
fedora44-kernel-bump
Jul 13, 2026
Merged

build: add rpm + gnupg (Fedora RPM GPG verification)#10
HarryR merged 4 commits into
mainfrom
fedora44-kernel-bump

Conversation

@HarryR

@HarryRHarryR commented Jul 10, 2026

Copy link
Copy Markdown
Contributor

What

Bring the stage0 build image and disk layout in line with the Fedora 44 chain bump, plus stable disk identity.

Changes

  • rpm + gnupg added to Dockerfile.build so the UKI build can verify Fedora package GPG signatures (image parity with stage1, kept byte-identical). No effect on compiled artifacts.
  • Stable lockboot GPT GUIDs + FAT volume-id.DISK_GUID / PART_GUID are now constant across releases (4c4f434b-424f-4f54-..., "LOCKBOOT" + a role index), so the initial GPT is byte-stable (stable pre-stage2 PCR5) and the boot disk is identifiable by a fixed GUID rather than by hashing stage0.efi (which changed per release). This is the stable identity stage2's find_boot_device can key on. (stage2 still rewrites the GPT at runtime to add p2/p3, which is why it excludes PCR5 from its key binding.)
  • Pin vaportpm-attest to v0.3.0 (rev + version guard), matching stage1.
  • Extract the shared DOCKER_RUN harness into build.mk (same refactor as stage1).

Verification

🤖 Generated with Claude Code

HarryRand others added 3 commits July 10, 2026 07:54
Needed so the UKI build can verify Fedora package GPG signatures (rpm/rpmkeys +
gnupg). Image parity: Dockerfile.build is kept byte-identical with stage1, whose
tools/build-uki now GPG-verifies the kernel + systemd-boot RPMs it downloads. No
effect on compiled artifacts.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Move the docker-images + DOCKER_RUN plumbing block out of the Makefile into a canonical build.mk that the Makefile now includes. This is the source of truth for the shared harness, vendored byte-identically into stage1/vaportpm via the workspace make sync-harness and guarded by make check-harness. Pure relocation -- make -n expands identically; docker-build-harness (stage0-only) stays in the Makefile.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Both stage0 crates floated on vaportpm main (no rev), and stage0's Cargo.lock is untracked, so vaportpm-attest resolved to main HEAD on every build -- no version stability for a measured bootloader. Pin to the v0.3.0 release commit (7041f461) with a version = "=0.3.0" guard, keeping default-features = false (no_std core: Tpm, PcrOps, TpmTransport). Verified: stage0.efi and payload.efi build clean for x86_64-unknown-uefi against v0.3.0.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@HarryR
HarryRforce-pushed the fedora44-kernel-bump branch from fcda1b0 to 9e64f6eCompareJuly 11, 2026 19:43
…entifiable)
Replace the stage0.efi-hash-derived DISK_GUID/PART_GUID/VOLUME_ID with fixed
constants ("4c4f434b424f4f54" spells "LOCKBOOT"; last group a role index:
disk = 0, ESP = partition 1). Constant across releases so the GPT -- and hence
the firmware's PCR 5 measurement -- is byte-stable, and a lockboot disk is
identifiable by GUID. Dependency of stage2, which locates the boot disk by GUID
and rewrites the GPT to add its runtime/data partitions; a stable base GPT keeps
PCR 5 predictable. The stage0.efi hash still feeds BUILD_ID.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@HarryR
HarryR marked this pull request as ready for review July 13, 2026 18:03
@HarryR
HarryR merged commit 8cb8b11 into mainJul 13, 2026
3 checks passed
@HarryR
HarryR deleted the fedora44-kernel-bump branch July 13, 2026 19:23
HarryR added a commit to lockboot/stage1 that referenced this pull request Jul 13, 2026
…#19)
## What
Bring the UKI to a current, GPG-verified Fedora 44 base, bundle the
kernel modules stage2 needs, and supporting build cleanups.
## Kernel + stub
- Bump kernel `6.12.4-200.fc41` -> `7.0.12-201.fc44` and systemd-boot
stub `256.17-1.fc41` -> `259.6-1.fc44` (what Fedora CoreOS
44.20260621.3.1 ships). `fc41` is EOL; the kernel was ~18 months behind.
- **GPG verification (mandatory):** `download-verify-rpm.sh` fetches
from koji's *signed* path (plain `packages/` is unsigned) and verifies
each RPM against `keys/RPM-GPG-KEY-fedora-44-primary` (fp `36F6 12DC
F27F 7D1A 48A8 35E4 DBFC F71C 6D9F 90A6`) on every build.
- **Automated bumps:** pins live in generated
`tools/build-uki/fedora-deps.mk`; `make update-fedora-deps FCOS=...
SYSTEMD=...` reads the FCOS manifest, downloads + GPG-verifies the
signed RPMs, and rewrites the pins.
## Storage modules for stage2
- Bundle + explicitly load (in dependency order, before the
`modules_disabled` latch) the modules stage2's loader needs:
**dm-crypt** (encrypted /data), **dm-verity** + **reed_solomon**
(integrity-checked erofs runtime + FEC dep), **overlay** (ephemeral
root), **erofs** + **netfs** (RO image fs + dep), and the **nvme** chain
(hkdf -> nvme-auth/keyring -> nvme-core -> nvme; EC2 EBS + the harness
disk are NVMe). The payload cannot load modules itself, and an
unresolved dep can't be pulled once the latch is set, so deps are listed
explicitly.
- Module comments describe each dependency's capability generically.
**Authenticated /data (dm-integrity + async_xor/async_tx) is documented
as an extension point but not shipped** -- stage2 uses
confidentiality-only dm-crypt, so those are omitted to keep the measured
initramfs minimal.
## Build
- Pin `vaportpm-attest` to v0.3.0 (rev + version guard).
- Extract the shared `DOCKER_RUN` harness into `build.mk`.
- Drop a stale `kernel-hash-%` target.
## Verification
- ena (AWS) + gve (GCP) present in 7.0.12; all required `.ko.xz` copy.
- `make test-chain-x86_64 SIGN=1 / MANIFEST=1 / SIGN_ARGS=1` boot `Linux
7.0.12-201.fc44` end to end and run stage2.
- lockboot/stage2's XTS pivot test passes end to end on this UKI
(`PIVOT_TEST=PASS`), dm-integrity absent from the boot.
- aarch64 pins are GPG-verified but not boot-tested here.
Pairs with lockboot/stage0#10 (image parity: rpm+gnupg, shared harness,
vaportpm pin, stable GUIDs).
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@HarryR
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

build: add rpm + gnupg (Fedora RPM GPG verification) - #10

Merged
HarryR merged 4 commits into
mainfrom
fedora44-kernel-bump
Jul 13, 2026
Merged

build: add rpm + gnupg (Fedora RPM GPG verification)#10
HarryR merged 4 commits into
mainfrom
fedora44-kernel-bump

Conversation

@HarryR

@HarryRHarryR commented Jul 10, 2026

Copy link
Copy Markdown
Contributor

What

Bring the stage0 build image and disk layout in line with the Fedora 44 chain bump, plus stable disk identity.

Changes

  • rpm + gnupg added to Dockerfile.build so the UKI build can verify Fedora package GPG signatures (image parity with stage1, kept byte-identical). No effect on compiled artifacts.
  • Stable lockboot GPT GUIDs + FAT volume-id.DISK_GUID / PART_GUID are now constant across releases (4c4f434b-424f-4f54-..., "LOCKBOOT" + a role index), so the initial GPT is byte-stable (stable pre-stage2 PCR5) and the boot disk is identifiable by a fixed GUID rather than by hashing stage0.efi (which changed per release). This is the stable identity stage2's find_boot_device can key on. (stage2 still rewrites the GPT at runtime to add p2/p3, which is why it excludes PCR5 from its key binding.)
  • Pin vaportpm-attest to v0.3.0 (rev + version guard), matching stage1.
  • Extract the shared DOCKER_RUN harness into build.mk (same refactor as stage1).

Verification

🤖 Generated with Claude Code

HarryRand others added 3 commits July 10, 2026 07:54
Needed so the UKI build can verify Fedora package GPG signatures (rpm/rpmkeys +
gnupg). Image parity: Dockerfile.build is kept byte-identical with stage1, whose
tools/build-uki now GPG-verifies the kernel + systemd-boot RPMs it downloads. No
effect on compiled artifacts.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Move the docker-images + DOCKER_RUN plumbing block out of the Makefile into a canonical build.mk that the Makefile now includes. This is the source of truth for the shared harness, vendored byte-identically into stage1/vaportpm via the workspace make sync-harness and guarded by make check-harness. Pure relocation -- make -n expands identically; docker-build-harness (stage0-only) stays in the Makefile.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Both stage0 crates floated on vaportpm main (no rev), and stage0's Cargo.lock is untracked, so vaportpm-attest resolved to main HEAD on every build -- no version stability for a measured bootloader. Pin to the v0.3.0 release commit (7041f461) with a version = "=0.3.0" guard, keeping default-features = false (no_std core: Tpm, PcrOps, TpmTransport). Verified: stage0.efi and payload.efi build clean for x86_64-unknown-uefi against v0.3.0.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@HarryR
HarryRforce-pushed the fedora44-kernel-bump branch from fcda1b0 to 9e64f6eCompareJuly 11, 2026 19:43
…entifiable)
Replace the stage0.efi-hash-derived DISK_GUID/PART_GUID/VOLUME_ID with fixed
constants ("4c4f434b424f4f54" spells "LOCKBOOT"; last group a role index:
disk = 0, ESP = partition 1). Constant across releases so the GPT -- and hence
the firmware's PCR 5 measurement -- is byte-stable, and a lockboot disk is
identifiable by GUID. Dependency of stage2, which locates the boot disk by GUID
and rewrites the GPT to add its runtime/data partitions; a stable base GPT keeps
PCR 5 predictable. The stage0.efi hash still feeds BUILD_ID.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@HarryR
HarryR marked this pull request as ready for review July 13, 2026 18:03
@HarryR
HarryR merged commit 8cb8b11 into mainJul 13, 2026
3 checks passed
@HarryR
HarryR deleted the fedora44-kernel-bump branch July 13, 2026 19:23
HarryR added a commit to lockboot/stage1 that referenced this pull request Jul 13, 2026
…#19)
## What
Bring the UKI to a current, GPG-verified Fedora 44 base, bundle the
kernel modules stage2 needs, and supporting build cleanups.
## Kernel + stub
- Bump kernel `6.12.4-200.fc41` -> `7.0.12-201.fc44` and systemd-boot
stub `256.17-1.fc41` -> `259.6-1.fc44` (what Fedora CoreOS
44.20260621.3.1 ships). `fc41` is EOL; the kernel was ~18 months behind.
- **GPG verification (mandatory):** `download-verify-rpm.sh` fetches
from koji's *signed* path (plain `packages/` is unsigned) and verifies
each RPM against `keys/RPM-GPG-KEY-fedora-44-primary` (fp `36F6 12DC
F27F 7D1A 48A8 35E4 DBFC F71C 6D9F 90A6`) on every build.
- **Automated bumps:** pins live in generated
`tools/build-uki/fedora-deps.mk`; `make update-fedora-deps FCOS=...
SYSTEMD=...` reads the FCOS manifest, downloads + GPG-verifies the
signed RPMs, and rewrites the pins.
## Storage modules for stage2
- Bundle + explicitly load (in dependency order, before the
`modules_disabled` latch) the modules stage2's loader needs:
**dm-crypt** (encrypted /data), **dm-verity** + **reed_solomon**
(integrity-checked erofs runtime + FEC dep), **overlay** (ephemeral
root), **erofs** + **netfs** (RO image fs + dep), and the **nvme** chain
(hkdf -> nvme-auth/keyring -> nvme-core -> nvme; EC2 EBS + the harness
disk are NVMe). The payload cannot load modules itself, and an
unresolved dep can't be pulled once the latch is set, so deps are listed
explicitly.
- Module comments describe each dependency's capability generically.
**Authenticated /data (dm-integrity + async_xor/async_tx) is documented
as an extension point but not shipped** -- stage2 uses
confidentiality-only dm-crypt, so those are omitted to keep the measured
initramfs minimal.
## Build
- Pin `vaportpm-attest` to v0.3.0 (rev + version guard).
- Extract the shared `DOCKER_RUN` harness into `build.mk`.
- Drop a stale `kernel-hash-%` target.
## Verification
- ena (AWS) + gve (GCP) present in 7.0.12; all required `.ko.xz` copy.
- `make test-chain-x86_64 SIGN=1 / MANIFEST=1 / SIGN_ARGS=1` boot `Linux
7.0.12-201.fc44` end to end and run stage2.
- lockboot/stage2's XTS pivot test passes end to end on this UKI
(`PIVOT_TEST=PASS`), dm-integrity absent from the boot.
- aarch64 pins are GPG-verified but not boot-tested here.
Pairs with lockboot/stage0#10 (image parity: rpm+gnupg, shared harness,
vaportpm pin, stable GUIDs).
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@HarryR