Skip to content

feat(recovery): add standalone UEFI recovery media builder - #47

Merged
aien-dev merged 1 commit into
mainfrom
feat/trust-1-gate1-recovery-media
Sep 24, 2026
Merged

aien-dev merged 1 commit into
mainfrom
feat/trust-1-gate1-recovery-media

Conversation

@aien-dev

Copy link
Copy Markdown
Owner

Summary

Provisions the standalone UEFI recovery media on USB partition /dev/sda1 per TRUST-1 Gate 1 requirements:

  • Deploys signed Shim (BOOTAA64.EFI) and Canonical-signed GRUB (grubaa64.efi) for Secure Boot compliance.
  • Installs standalone emergency target kernel and initrd into /aienos-recovery/.
  • Configures standalone emergency recovery boot entry in /EFI/BOOT/grub.cfg.
  • Preserves offline recovery key atlas-forge-state-luks-recovery-key.txt.age (SHA-256: 4b2893e5bfc123a962a68602087a35da5fe52f7fb9c8b3cb7ac69ac9713075c3), with redundant backup verified on operator Mac shell.
  • Confirmed firmware detects partition as Boot0004 UEFI: USB USB Hard Drive, Partition 1.

Verification

  • Validated via efibootmgr -v and filesystem inspection.
  • Zero disk secrets.
  • Unslop compliance verified.

- Builds UEFI bootable recovery image on USB partition (/dev/sda1)
- Integrates Microsoft-signed Shim and Canonical-signed GRUB for Secure Boot execution
- Provisions emergency maintenance recovery boot entry
- Records operator variance authorizing /dev/sda repurposing with key preserved
- Unslop and Zero Disk Secrets compliant
@aien-dev
aien-dev merged commit ede6cdf into main Sep 24, 2026
1 check passed
@aien-dev
aien-dev deleted the feat/trust-1-gate1-recovery-media branch September 24, 2026 03:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants