Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -86,7 +86,9 @@ Each stage lands on its own, in this order.
- Every volume the loader opens (the slot's FAT partition, the log
partition and the attempts file on it) is found on the boot disk, where
exactly one match is taken. `loaderlog::volume_handle`'s machine-wide
first match goes.
first match goes. Every stick written from one image carries the same
unique GUIDs: `src/image.rs`'s `create_boot_image` draws them once per
image.
- A pass asks firmware once: one `LoadedImage` open, one device-path walk,
one `Disk::open` and slot-table read, and one file reader.
`load_file_bytes`, `MAX_ESP_FILE` and the unsound `alloc_uninit` go.
Expand Down
Original file line number Diff line number Diff line change
@@ -0,0 +1,25 @@
---
status: open
kind: tooling
opened: 2026-09-28
---

# The toolchain install unpacks an asset no digest vouches for

`release::install` (`src/release.rs`) downloads the `toyos-toolchain.tar.zst`
asset of the release its tree's tag names, unpacks it into `rust/build` and
links it as rustup's `toyos`, and checks nothing about its bytes: the tag is
the hash of the tarball's inputs (`trees`), not of the tarball, and the
`toyos-sysroot-witness` an installed toolchain is held to comes inside it.
Every guest job compiles and boots with what it installs.

A job holding this repository's `contents: write` token can replace a
release asset, so any code such a job runs can replace the toolchain every
later job installs. The nightly's `build` job holds that token while it
bootstraps the toolchain.

Owner: the release module (`src/release.rs`).

**Exit condition.** `install` unpacks only an asset whose SHA-256 is one that
no job holding a write token can rewrite — committed to the tree it installs
for — and refuses any other by name.

This file was deleted.

Original file line number Diff line number Diff line change
@@ -0,0 +1,31 @@
---
status: open
kind: tooling
opened: 2026-09-29
---

# Linux's readings of the T14 and the TCG model lack reads owed before the T14's wipe

The floor of
`issues/kernel/the-kernel-is-at-least-as-secure-as-linux-on-every-machine-toyos-supports.md`
is tag `Ubuntu-6.8.0-142.142` (53e5d07aac028a1523ab0b115f079d6d1bc831ef) of
`https://git.launchpad.net/~ubuntu-kernel/ubuntu/+source/linux/+git/noble`,
config sha256 3b8533dd9d235ca634ac58f82c5ce1ee35f12ef620693e17033184d2c9ca5890,
and what it reads on the T14 and on the TCG model are the fixtures
of `issues/kernel/a-pure-function-decides-a-cpus-speculation-mitigations-as-linux-does.md`,
`toyos-cpuvuln/fixtures/`'s `t14.txt`, `t14/` and `tcg/`;
`the_t14s_facts_are_linuxs_reading_of_it` and
`the_tcg_models_signature_gives_its_lines` hold `T14` and `TCG` to them.
Ubuntu leaves the T14 only after this issue and
`issues/hardware/no-program-measures-toyos-against-linux-on-one-machine.md`
close.

**Exit**: before the wipe the T14's readings add CPUID 5, 0x19 and
0x80000001, MSR 0xCF, MSR 0x3A (`rdmsr -a 0x3a`, IA32_FEAT_CTL), the
split-lock line, and the config's `X86_KERNEL_IBT` and
`X86_INTEL_MEMORY_PROTECTION_KEYS`, each committed with the test that reads
it, and `the_t14s_facts_are_linuxs_reading_of_it` holds `T14`'s `feat_ctl`
to 0x3A's. **Mutation**: an added reading off by one bit reds the test that
reads it. **Oracle**: that Linux.

Owner: the orchestrator, which holds the T14 the exit runs on.
Original file line number Diff line number Diff line change
Expand Up @@ -12,7 +12,7 @@ selects, built by the kernel and by a host test. Pull request #602 holds it.

**Exit**: each committed fixture's facts give its lines: the T14's and the TCG
model's from
`issues/hardware/linuxs-readings-of-the-t14-and-the-tcg-model-are-not-committed.md`,
`issues/hardware/linuxs-readings-of-the-t14-and-the-tcg-model-lack-reads-owed-before-the-t14s-wipe.md`,
and each nightly EPYC guest's once its runner is captured. **Mutation**: `GDS`
deleted from `cpu_vuln_blacklist`'s TIGERLAKE_L row reds the T14's fixture,
and `SRSO` deleted from its family 0x19 row reds a family-0x19 EPYC guest's.
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -9,7 +9,7 @@ opened: 2026-09-29
**Exit**: each proving machine's ToyOS boot prints, for each vulnerabilities
file, the line Linux at `Ubuntu-6.8.0-142.142` printed on that machine: the
T14's from
`issues/hardware/linuxs-readings-of-the-t14-and-the-tcg-model-are-not-committed.md`,
`issues/hardware/linuxs-readings-of-the-t14-and-the-tcg-model-lack-reads-owed-before-the-t14s-wipe.md`,
each EPYC guest's from its runner's capture. It omits only clauses about what
ToyOS does not run: `spectre_v1`'s swapgs barriers while it runs no `swapgs`,
the KVM and VM-exit clauses since it runs no guest, and `IBRS_FW` since the
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -14,7 +14,7 @@ probe is a `boot-actuators` arm or a `test-actuators` `SYS_DEBUG` action.

**Exit**: every issue below is closed, in the order listed.

- `issues/hardware/linuxs-readings-of-the-t14-and-the-tcg-model-are-not-committed.md`
- `issues/hardware/linuxs-readings-of-the-t14-and-the-tcg-model-lack-reads-owed-before-the-t14s-wipe.md`
- `issues/kernel/a-pure-function-decides-a-cpus-speculation-mitigations-as-linux-does.md`
- `issues/kernel/spec-ctrl-and-gds-stay-as-firmware-left-them.md`
- `issues/kernel/no-program-runs-with-speculative-store-bypass-disabled.md`
Expand Down
2 changes: 1 addition & 1 deletion issues/kernel/tsx-stays-as-firmware-left-it.md
Original file line number Diff line number Diff line change
Expand Up @@ -21,6 +21,6 @@ T14's `CONFIG_X86_INTEL_TSX_MODE_OFF=y`, runs `tsx_init`
`issues/kernel/a-pure-function-decides-a-cpus-speculation-mitigations-as-linux-does.md`
carries `tsx_init`'s decision and every CPU applies it; on the T14, ToyOS's
reads of 0x122, 0x10F and 0x123 equal the Linux reads of
`issues/hardware/linuxs-readings-of-the-t14-and-the-tcg-model-are-not-committed.md`
`issues/hardware/linuxs-readings-of-the-t14-and-the-tcg-model-lack-reads-owed-before-the-t14s-wipe.md`
where each exists, and dropping the write leaves 0x122 or 0x10F at firmware's
value and reds it.
13 changes: 13 additions & 0 deletions toyos-cpuvuln/fixtures/t14/SOURCE
Original file line number Diff line number Diff line change
@@ -0,0 +1,13 @@
Linux's readings of the ThinkPad T14 this repository is tested on, under that
machine's Ubuntu, read as root on the T14 by `toyos-t14linux/capture.sh` at
commit 44eb3c2e (pull request #601), and it read
CPUID and the MSRs through the running kernel's /dev/cpu/*/cpuid and
/dev/cpu/*/msr, so an MSR holds what that kernel left in it.

vulnerabilities.txt the run's `grep .` over the vulnerabilities directory,
committed as ../t14.txt
cpuid.txt CPU 0's leaves, one per line:
leaf subleaf eax ebx ecx edx
msr.txt one per line: msr cpu value; 0x122 and 0x10F are absent
because ARCH_CAPABILITIES bit 7 and CPUID.(7,0):EDX
bits 11 and 13 do not enumerate them
12 changes: 12 additions & 0 deletions toyos-cpuvuln/fixtures/t14/cpuid.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,12 @@
00000000 00000000 0000001b 756e6547 6c65746e 49656e69
00000001 00000000 000806c1 00100800 7ffafbbf bfebfbff
00000006 00000000 0017eff7 00000002 00000009 00000000
00000007 00000000 00000002 f3bfa7eb 18c05fde fc100710
00000007 00000001 00000000 00000000 00000000 00040000
00000007 00000002 00000000 00000000 00000000 00000001
0000000d 00000000 000002e7 00000a88 00000a88 00000000
0000000d 00000001 0000000f 00000998 00003900 00000000
00000014 00000000 00000001 0000004f 00000007 00000000
80000000 00000000 80000008 00000000 00000000 00000000
80000008 00000000 00003027 00000000 00000000 00000000
80000021 00000000 00000000 00000000 00000000 00000000
Loading
Loading