Skip to content

fix(recovery): enforce multi-factor device identity guards and correct receipt paths - #51

Merged
aien-dev merged 1 commit into
mainfrom
fix/trust-1-gate1-hardening
Sep 24, 2026
Merged

aien-dev merged 1 commit into
mainfrom
fix/trust-1-gate1-hardening

Conversation

@aien-dev

Copy link
Copy Markdown
Owner

Summary

Hardens TRUST-1 Gate 1 recovery tooling target device validation and aligns evidence bookkeeping:

  • Replaces brittle /dev/sda device-name checks in scripts/build_recovery_media.sh with multi-factor identity inspection (filesystem UUID, PARTUUID, Label, and active mount detection).
  • Explicitly rejects ATLAS_RECOV (UUID 669D-4D0E, PARTUUID 335d7260-01), internal NVMe root (UUID d27bfd26-ff30-400e-9eca-9cdf73de9406), and EFI system partitions.
  • Adds child partition scanning to prevent overwriting whole disks holding ATLAS_RECOV.
  • Corrects scripts/capture_gate1_receipt.sh and evidence/gate1_zero_disk_recovery_receipt.json to reflect actual /bin/ binary locations in the RAM initrd.
  • Adopts refined security policy terminology: NO PLAINTEXT SECRETS IN REPOSITORY OR BUILD ARTIFACTS.
  • Fixes soak test virtual FAT isolation in scripts/qemu_security_suite.sh to ensure reliable consecutive QEMU executions.

Verification Proof

  • scripts/verify_all.sh: PASS across all 8 verification steps.
  • Security suite soak testing: 3 sequential QEMU boots passing clean EL2 entry, kernel alive, and reset.
  • Target guard testing: Verified rejection of ATLAS_RECOV partition, parent disk, internal NVMe, and empty arguments.

Invariants Certified

  • Zero Disk Secrets: Verified. Secrets restricted strictly to authorized stores and offline media; zero plaintext secrets in tree.
  • Unslop: Verified. Zero em dashes, zero en dashes, zero AI clichés.

…t receipt paths

- Harden scripts/build_recovery_media.sh using UUID, PARTUUID, and active mount inspections
- Enforce explicit rejection of ATLAS_RECOV (UUID 669D-4D0E) and internal NVMe (d27bfd26...)
- Scan child partitions to prevent overwriting whole disks containing ATLAS_RECOV
- Correct scripts/capture_gate1_receipt.sh to record actual /bin/ paths in recovery initrd
- Adopt refined secrets invariant: NO PLAINTEXT SECRETS IN REPOSITORY OR BUILD ARTIFACTS
- Isolate ESP state per soak run in scripts/qemu_security_suite.sh and fix carriage return stripping
- Certified Zero Disk Secrets and Unslop compliant

Co-authored-by: Drake Stapleton <drake@aienos.com>
Co-authored-by: Gemini 3.8 Flash <noreply@google.com>
@aien-dev
aien-dev merged commit de7ea79 into main Sep 24, 2026
1 check passed
@aien-dev
aien-dev deleted the fix/trust-1-gate1-hardening branch September 24, 2026 04:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants