Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 4 additions & 0 deletions Cargo.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

1 change: 1 addition & 0 deletions Cargo.toml
Original file line number Diff line number Diff line change
Expand Up @@ -54,6 +54,7 @@ members = [
"toyos-sched/sim",
"toyos-swap",
"toyos-symbols",
"toyos-t14linux",
"toyos-tco",
"toyos-tmpdir",
"toyos-transport",
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -131,8 +131,11 @@ comes from S1's T14 fixture and the T14 run, never from KVM.
names 6.8.0-142, both packages are 6.8.0-142.142 and the config's sha256 is
the one above. The capture is one-time: the kernel
image, `s0.cpio` and busybox are never committed and no build or test boots
them. **Exit**: the captured text outputs committed as S1's fixtures. Ubuntu
is wiped from the T14 only after that commit.
them. **Exit**: the captured text outputs committed as S1's fixtures — done,
at `toyos-t14linux/s0/t14/` (the T14, `capture.sh` through sudo) and
`toyos-t14linux/s0/tcg/` (the TCG model, `tcg.sh` on QEMU 11.1.1). Ubuntu is
wiped from the T14 only after that commit and #568's LLVM-bar capture, which
still waits on the T14.
- **S1 — The decision, a host-tested function.** A pure function, in a crate
the kernel and a host test both build, maps (vendor, family, model,
stepping, microcode revision, CPUID.1, CPUID.(7,0), CPUID.(7,2),
Expand Down
13 changes: 13 additions & 0 deletions toyos-t14linux/Cargo.toml
Original file line number Diff line number Diff line change
@@ -0,0 +1,13 @@
# A member of the host workspace (root `Cargo.toml`): the T14 under Linux,
# captured once, and the reader of what the capture wrote.

[package]
name = "toyos-t14linux"
description = "The T14 under its pinned Ubuntu and that kernel on the TCG model, captured once: the scripts that capture them and the reader of what they write."
version = "0.1.0"
edition = "2021"
license = "MIT OR Apache-2.0"
publish = false

[lints.rust]
warnings = "deny"
78 changes: 78 additions & 0 deletions toyos-t14linux/capture.sh
Original file line number Diff line number Diff line change
@@ -0,0 +1,78 @@
#!/bin/bash
# S0 of issues/kernel/the-kernel-mitigates-what-linux-mitigates-on-the-t14.md: on the T14 under
# its stock Ubuntu, through sudo, `capture.sh <out> <kit>`. <out> is the evidence src/lib.rs
# reads; <kit> is the kernel and initramfs tcg.sh boots, never committed. It installs nothing,
# asks no network, and writes nothing but the two directories it creates.
set -euo pipefail
trap 'echo "capture.sh:$LINENO: failed" >&2' ERR
k=6.8.0-142-generic
refuse() { echo "capture.sh: refused: $1" >&2; exit 1; }
: "${SUDO_UID:?run capture.sh through sudo}"
case $(cat /proc/version) in "Linux version $k "*) ;; *) refuse "the running kernel is not $k";; esac
[ "$(dpkg-query -W -f '${Version} ' linux-image-$k linux-modules-$k)" = "6.8.0-142.142 6.8.0-142.142 " ] ||
refuse "the packages are not 6.8.0-142.142"
echo "3b8533dd9d235ca634ac58f82c5ce1ee35f12ef620693e17033184d2c9ca5890 /boot/config-$k" |
sha256sum -c --status || refuse "/boot/config-$k is not the pinned config"
modprobe -a cpuid msr
mkdir "$1" "$2"
out=$(cd "$1" && pwd) kit=$(cd "$2" && pwd)
cd "$out"

cat /proc/version > version.txt
uname -a > uname.txt
cat /proc/cmdline > cmdline.txt
dpkg-query -W linux-image-$k linux-modules-$k > packages.txt
sha256sum /boot/config-$k > config-sha256.txt
# The track's hardening table and the CPU_MITIGATIONS menu, with the config's line numbers.
opts='RANDOMIZE_BASE|RANDOMIZE_MEMORY|ARCH_MMAP_RND_BITS|STACKPROTECTOR_STRONG|SLS|X86_USER_SHADOW_STACK'
opts+='|RESET_ATTACK_MITIGATION|RANDOMIZE_KSTACK_OFFSET_DEFAULT|ZERO_CALL_USED_REGS|VMAP_STACK'
opts+='|STRICT_KERNEL_RWX|DEBUG_WX|SLAB_FREELIST_RANDOM|SLAB_FREELIST_HARDENED|RANDOM_KMALLOC_CACHES'
opts+='|X86_INTEL_TSX_MODE_OFF|INTEL_IOMMU_DEFAULT_ON|INIT_ON_ALLOC_DEFAULT_ON|SCHED_STACK_END_CHECK'
opts+='|HARDENED_USERCOPY|X86_UMIP|INIT_STACK_ALL_ZERO|FORTIFY_SOURCE|UBSAN_(BOUNDS|SHIFT|BOOL|ENUM)'
opts+='|STRICT_MODULE_RWX|LEGACY_VSYSCALL_XONLY|SHUFFLE_PAGE_ALLOCATOR|BPF_JIT_ALWAYS_ON|MODULE_SIG'
opts+='|KEXEC_SIG|CPU_MITIGATIONS|MITIGATION_[A-Z0-9_]+'
grep -nE "^(# )?CONFIG_($opts)(=| is not set)" /boot/config-$k > config-hardening.txt
sysctl vm.mmap_rnd_bits > mmap_rnd_bits.txt
grep . /sys/devices/system/cpu/vulnerabilities/* > vulnerabilities.txt
cat /proc/cpuinfo > cpuinfo.txt
# dmesg's lines, from the journal's copy of this boot so a wrapped ring loses none.
journalctl -k -b 0 -o cat | grep -iE 'mitigat|vulnerab|not affected|spectre|microcode|x86/bugs|tsx' \
> kernel-log.txt
shopt -s nullglob
grep . /sys/class/dmi/id/{bios_*,ec_*,sys_vendor,product_name,product_version} > dmi.txt

# CPU 0's leaves as `leaf subleaf eax ebx ecx edx`; the device reads subleaf:leaf at its offset.
cpuid() { dd if=/dev/cpu/0/cpuid bs=16 count=1 skip=$(($1 | $2 << 32)) iflag=skip_bytes status=none | od -An -tx4; }
for l in 0:0 1:0 6:0 7:0 7:1 7:2 0xd:0 0xd:1 0x14:0 0x80000000:0 0x80000008:0 0x80000021:0; do
r=$(cpuid ${l%:*} ${l#*:})
printf '%08x %08x%s\n' ${l%:*} ${l#*:} "$r"
done > cpuid.txt

# Every CPU's MSRs as `msr cpu value`. 0x122 exists where ARCH_CAPABILITIES bit 7
# (TSX_CTRL_MSR) is set, 0x10F where CPUID.(7,0):EDX bits 11 and 13 both are.
rdmsr() { dd if=/dev/cpu/$1/msr bs=8 count=1 skip=$(($2)) iflag=skip_bytes status=none | od -An -tx8 | tr -d ' '; }
msrs=(0x8b 0x48 0x10a 0x123)
arch=$(rdmsr 0 0x10a)
r=$(cpuid 7 0)
read -r _ _ _ edx <<< "$r"
(( 0x$arch >> 7 & 1 )) && msrs+=(0x122)
(( 0x$edx >> 11 & 1 && 0x$edx >> 13 & 1 )) && msrs+=(0x10f)
for m in "${msrs[@]}"; do
for c in /dev/cpu/[0-9]*; do
v=$(rdmsr ${c##*/} $m)
printf '%08x %s %s\n' $m ${c##*/} $v
done
done > msr.txt

# The TCG model's kit: the track's initramfs around this machine's busybox and, where
# it is dynamic, what it links.
cp /boot/vmlinuz-$k "$kit"
bb=$(command -v busybox)
mkdir -p "$kit"/rd/bin "$kit"/rd/sys "$kit"/rd/proc
cp "$bb" "$kit"/rd/bin/busybox
if ldd "$bb" > /dev/null 2>&1; then cp --parents $(ldd "$bb" | grep -o '/[^ ]*') "$kit"/rd; fi
printf '#!/bin/busybox sh\n/bin/busybox mount -t sysfs s /sys\n/bin/busybox mount -t proc p /proc\n/bin/busybox cat /proc/version\n/bin/busybox grep . /sys/devices/system/cpu/vulnerabilities/*\n/bin/busybox poweroff -f\n' > "$kit"/rd/init
chmod +x "$kit"/rd/init
(cd "$kit"/rd && find . | cpio -o -H newc --quiet) > "$kit"/s0.cpio
chown -R "$SUDO_UID:$SUDO_GID" "$out" "$kit"
echo "capture.sh: wrote $out and $kit"
1 change: 1 addition & 0 deletions toyos-t14linux/s0/t14/cmdline.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
BOOT_IMAGE=/vmlinuz-6.8.0-142-generic root=/dev/mapper/ubuntu--vg-ubuntu--lv ro
41 changes: 41 additions & 0 deletions toyos-t14linux/s0/t14/config-hardening.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,41 @@
124:CONFIG_BPF_JIT_ALWAYS_ON=y
318:CONFIG_KEXEC_SIG=y
493:CONFIG_X86_UMIP=y
498:CONFIG_X86_INTEL_TSX_MODE_OFF=y
502:CONFIG_X86_USER_SHADOW_STACK=y
528:CONFIG_RANDOMIZE_BASE=y
532:CONFIG_RANDOMIZE_MEMORY=y
536:CONFIG_LEGACY_VSYSCALL_XONLY=y
554:CONFIG_CPU_MITIGATIONS=y
556:CONFIG_MITIGATION_RETPOLINE=y
557:CONFIG_MITIGATION_RETHUNK=y
564:CONFIG_SLS=y
566:CONFIG_MITIGATION_RFDS=y
567:CONFIG_MITIGATION_SPECTRE_BHI=y
568:CONFIG_MITIGATION_ITS=y
569:CONFIG_MITIGATION_TSA=y
570:CONFIG_MITIGATION_VMSCAPE=y
882:CONFIG_STACKPROTECTOR_STRONG=y
909:CONFIG_ARCH_MMAP_RND_BITS=32
930:CONFIG_VMAP_STACK=y
933:CONFIG_RANDOMIZE_KSTACK_OFFSET_DEFAULT=y
935:CONFIG_STRICT_KERNEL_RWX=y
937:CONFIG_STRICT_MODULE_RWX=y
982:CONFIG_MODULE_SIG=y
1132:CONFIG_SLAB_FREELIST_RANDOM=y
1133:CONFIG_SLAB_FREELIST_HARDENED=y
1136:CONFIG_RANDOM_KMALLOC_CACHES=y
1139:CONFIG_SHUFFLE_PAGE_ALLOCATOR=y
2457:CONFIG_RESET_ATTACK_MITIGATION=y
9892:CONFIG_INTEL_IOMMU_DEFAULT_ON=y
11376:CONFIG_HARDENED_USERCOPY=y
11377:CONFIG_FORTIFY_SOURCE=y
11473:CONFIG_INIT_STACK_ALL_ZERO=y
11474:CONFIG_INIT_ON_ALLOC_DEFAULT_ON=y
11477:CONFIG_ZERO_CALL_USED_REGS=y
12040:CONFIG_UBSAN_BOUNDS=y
12042:CONFIG_UBSAN_SHIFT=y
12044:CONFIG_UBSAN_BOOL=y
12045:CONFIG_UBSAN_ENUM=y
12074:CONFIG_DEBUG_WX=y
12084:CONFIG_SCHED_STACK_END_CHECK=y
1 change: 1 addition & 0 deletions toyos-t14linux/s0/t14/config-sha256.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
3b8533dd9d235ca634ac58f82c5ce1ee35f12ef620693e17033184d2c9ca5890 /boot/config-6.8.0-142-generic
12 changes: 12 additions & 0 deletions toyos-t14linux/s0/t14/cpuid.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,12 @@
00000000 00000000 0000001b 756e6547 6c65746e 49656e69
00000001 00000000 000806c1 00100800 7ffafbbf bfebfbff
00000006 00000000 0017eff7 00000002 00000009 00000000
00000007 00000000 00000002 f3bfa7eb 18c05fde fc100710
00000007 00000001 00000000 00000000 00000000 00040000
00000007 00000002 00000000 00000000 00000000 00000001
0000000d 00000000 000002e7 00000a88 00000a88 00000000
0000000d 00000001 0000000f 00000998 00003900 00000000
00000014 00000000 00000001 0000004f 00000007 00000000
80000000 00000000 80000008 00000000 00000000 00000000
80000008 00000000 00003027 00000000 00000000 00000000
80000021 00000000 00000000 00000000 00000000 00000000
Loading
Loading