Commit 2f5115f
committed
initrd+boards: feature-freeze hardening across TPM, tracing, root-hashes, and prompts
- add cross-script full trace-stack context in initrd/etc/functions (TRACE_STACK + TRACE_FUNC chaining) for end-to-end call-path visibility
- harden TPM/TOTP/HOTP and rollback flows across initrd/bin/gui-init, initrd/bin/tpmr, initrd/bin/seal-totp, initrd/bin/unseal-totp, initrd/bin/unseal-hotp, initrd/bin/kexec-sign-config, and initrd/bin/oem-factory-reset
- improve reset-vs-reseal guidance, TPM2 primary-handle checks, and ensure reseal failures propagate to callers
- make counter increment/create pipeline error handling reliable with local pipefail in initrd/etc/functions
- remove sensitive TPM owner-password length debug metadata and apply helper cleanups (partition parsing compatibility, local scoping, formatting)
- fix root-hashes LVM handling for Qubes/device-mapper naming by robust VG detection and dashed VG/LV mapper escaping in initrd/bin/root-hashes-gui.sh + initrd/etc/functions
- fix DUK passphrase prompt UX in initrd/bin/kexec-seal-key (repeat prompt placement and inline entry behavior)
- add qemu tpm1/tpm2 prod_quiet board configs and correct *_hotp-prod_quiet board-name exports for coverage/testing
Signed-off-by: Thierry Laurion <insurgo@riseup.net>1 parent b175948 commit 2f5115f
File tree
13 files changed
+481
-57
lines changed- boards
- qemu-coreboot-fbwhiptail-tpm1-hotp-prod_quiet
- qemu-coreboot-fbwhiptail-tpm1-prod_quiet
- qemu-coreboot-fbwhiptail-tpm2-hotp-prod_quiet
- qemu-coreboot-fbwhiptail-tpm2-prod_quiet
- initrd
- bin
- etc
13 files changed
+481
-57
lines changedLines changed: 1 addition & 1 deletion
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
91 | 91 | | |
92 | 92 | | |
93 | 93 | | |
94 | | - | |
| 94 | + | |
95 | 95 | | |
96 | 96 | | |
97 | 97 | | |
| |||
Lines changed: 97 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
| 54 | + | |
| 55 | + | |
| 56 | + | |
| 57 | + | |
| 58 | + | |
| 59 | + | |
| 60 | + | |
| 61 | + | |
| 62 | + | |
| 63 | + | |
| 64 | + | |
| 65 | + | |
| 66 | + | |
| 67 | + | |
| 68 | + | |
| 69 | + | |
| 70 | + | |
| 71 | + | |
| 72 | + | |
| 73 | + | |
| 74 | + | |
| 75 | + | |
| 76 | + | |
| 77 | + | |
| 78 | + | |
| 79 | + | |
| 80 | + | |
| 81 | + | |
| 82 | + | |
| 83 | + | |
| 84 | + | |
| 85 | + | |
| 86 | + | |
| 87 | + | |
| 88 | + | |
| 89 | + | |
| 90 | + | |
| 91 | + | |
| 92 | + | |
| 93 | + | |
| 94 | + | |
| 95 | + | |
| 96 | + | |
| 97 | + | |
Lines changed: 2 additions & 1 deletion
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
17 | 17 | | |
18 | 18 | | |
19 | 19 | | |
| 20 | + | |
20 | 21 | | |
21 | 22 | | |
22 | 23 | | |
| |||
90 | 91 | | |
91 | 92 | | |
92 | 93 | | |
93 | | - | |
| 94 | + | |
94 | 95 | | |
95 | 96 | | |
96 | 97 | | |
| |||
Lines changed: 98 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
| 54 | + | |
| 55 | + | |
| 56 | + | |
| 57 | + | |
| 58 | + | |
| 59 | + | |
| 60 | + | |
| 61 | + | |
| 62 | + | |
| 63 | + | |
| 64 | + | |
| 65 | + | |
| 66 | + | |
| 67 | + | |
| 68 | + | |
| 69 | + | |
| 70 | + | |
| 71 | + | |
| 72 | + | |
| 73 | + | |
| 74 | + | |
| 75 | + | |
| 76 | + | |
| 77 | + | |
| 78 | + | |
| 79 | + | |
| 80 | + | |
| 81 | + | |
| 82 | + | |
| 83 | + | |
| 84 | + | |
| 85 | + | |
| 86 | + | |
| 87 | + | |
| 88 | + | |
| 89 | + | |
| 90 | + | |
| 91 | + | |
| 92 | + | |
| 93 | + | |
| 94 | + | |
| 95 | + | |
| 96 | + | |
| 97 | + | |
| 98 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
174 | 174 | | |
175 | 175 | | |
176 | 176 | | |
177 | | - | |
178 | | - | |
| 177 | + | |
| 178 | + | |
| 179 | + | |
| 180 | + | |
179 | 181 | | |
180 | 182 | | |
181 | 183 | | |
| 184 | + | |
| 185 | + | |
| 186 | + | |
| 187 | + | |
| 188 | + | |
| 189 | + | |
| 190 | + | |
| 191 | + | |
| 192 | + | |
| 193 | + | |
| 194 | + | |
| 195 | + | |
| 196 | + | |
| 197 | + | |
| 198 | + | |
| 199 | + | |
| 200 | + | |
| 201 | + | |
| 202 | + | |
| 203 | + | |
| 204 | + | |
| 205 | + | |
| 206 | + | |
| 207 | + | |
| 208 | + | |
| 209 | + | |
| 210 | + | |
182 | 211 | | |
183 | 212 | | |
184 | 213 | | |
| |||
218 | 247 | | |
219 | 248 | | |
220 | 249 | | |
221 | | - | |
| 250 | + | |
| 251 | + | |
| 252 | + | |
222 | 253 | | |
223 | 254 | | |
224 | 255 | | |
225 | 256 | | |
226 | 257 | | |
227 | 258 | | |
228 | 259 | | |
229 | | - | |
| 260 | + | |
| 261 | + | |
| 262 | + | |
230 | 263 | | |
231 | 264 | | |
232 | 265 | | |
| |||
290 | 323 | | |
291 | 324 | | |
292 | 325 | | |
293 | | - | |
| 326 | + | |
| 327 | + | |
| 328 | + | |
294 | 329 | | |
295 | 330 | | |
296 | 331 | | |
| |||
510 | 545 | | |
511 | 546 | | |
512 | 547 | | |
513 | | - | |
| 548 | + | |
| 549 | + | |
| 550 | + | |
514 | 551 | | |
515 | 552 | | |
516 | | - | |
| 553 | + | |
| 554 | + | |
| 555 | + | |
517 | 556 | | |
518 | 557 | | |
519 | 558 | | |
| |||
566 | 605 | | |
567 | 606 | | |
568 | 607 | | |
569 | | - | |
| 608 | + | |
570 | 609 | | |
571 | 610 | | |
572 | 611 | | |
573 | 612 | | |
574 | 613 | | |
575 | 614 | | |
576 | 615 | | |
577 | | - | |
| 616 | + | |
| 617 | + | |
| 618 | + | |
| 619 | + | |
578 | 620 | | |
579 | 621 | | |
580 | 622 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
69 | 69 | | |
70 | 70 | | |
71 | 71 | | |
72 | | - | |
| 72 | + | |
| 73 | + | |
| 74 | + | |
| 75 | + | |
73 | 76 | | |
74 | 77 | | |
75 | 78 | | |
| |||
103 | 106 | | |
104 | 107 | | |
105 | 108 | | |
106 | | - | |
107 | | - | |
| 109 | + | |
| 110 | + | |
| 111 | + | |
| 112 | + | |
108 | 113 | | |
| 114 | + | |
109 | 115 | | |
110 | 116 | | |
111 | 117 | | |
112 | 118 | | |
113 | 119 | | |
114 | | - | |
| 120 | + | |
| 121 | + | |
115 | 122 | | |
116 | 123 | | |
117 | 124 | | |
| |||
0 commit comments