feat(bundle): Publish the digests of the kernel and initrd - #13
Merged
Merged
Conversation
6 tasks done
ananos
marked this pull request as ready for review
September 29, 2026 07:04
Contributor
Author
|
@claude-fleet review |
ananos
force-pushed
the
feat/boot-asset-digests
branch
2 times, most recently
from
September 29, 2026 07:49
6603b9b to
ae6d1e2
Compare
Contributor
Author
|
Review round on this PR: no must-fix, six should-fix and a handful of nits. All of them are addressed in the current head, Build (6fd90db)
Install (26943eb)
Elsewhere
|
ananos
force-pushed
the
feat/boot-asset-digests
branch
from
September 29, 2026 17:14
ae6d1e2 to
26943eb
Compare
The amd64 kernel came from bunny's linux-kernel-cloud-hypervisor:latest, a moving tag on an image nothing signs, copied out with docker. arm64 already took its kernel from hull-assets, the artifact hull and brig boot from, so the two arches drew from different places. Both arches now take the kernel from hull-assets. The build resolves the version tag once, checks the signature on that digest with the bundled cosign against the identity brig checks (the build-assets.yml workflow in NOFireAI/hull-assets), and pulls that digest. pins.env names it as KERNEL_SOURCE, <repo>:<tag>@<digest>. KERNEL_IMAGE_AMD64 and the docker path are gone; ASSETS_SIGNER and ASSETS_ISSUER set the identity for a fork. On arm64 the kernel is the file hull boots on macOS. On amd64 under cloud-hypervisor, a sandbox's agent answers about 0.25 s later than with bunny's kernel (20 boots each on two hosts). Refs: brig-sh/brig#234 Signed-off-by: Anastassios Nanos <ananos@nofire.ai>
On Linux the kernel and initrd that boot come from this bundle, and nothing recorded what they hash to, so brig had nothing to compare them with before a boot. The build now writes share/guest/SHA256SUMS with the sha256 of the kernel and of the initrd, and publishes the same bytes as <bundle>.boot-assets.sha256. The release job checksums every asset, so the signed checksums.txt covers the record. The kernel's line is its layer digest in the signed hull-assets manifest. CI checks that the published record is the one in the tree, that it lists the kernel and the initrd, that it matches them, and that pins.env names the kernel by digest. --help prints the whole header, which now lists the record. Refs: brig-sh/brig#234 Signed-off-by: Anastassios Nanos <ananos@nofire.ai>
The release's checksums.txt lists <bundle>.boot-assets.sha256, which is share/guest/SHA256SUMS. The installer checked the tarball against it, and its signature too when cosign was present, then dropped all of it, so nothing on the host tied the kernel and initrd to the release. A release install now keeps checksums.txt, checksums.txt.sig and checksums.txt.pem in share/guest, beside SHA256SUMS, when checksums.txt lists that SHA256SUMS. The signature is fetched even when cosign is missing at install time, because brig checks it with the bundle's own cosign before a boot. A local tarball keeps the three files when they were copied across beside it. A remote install under INSTALL_BRIG_SKIP_SIGCHECK, a bundle with no SHA256SUMS, and a local tarball with nothing beside it keep none. A release whose signature is missing, or whose checksums.txt does not list the record, keeps none and says so, because brig would warn before every run. Refs: brig-sh/brig#234 Signed-off-by: Anastassios Nanos <ananos@nofire.ai>
ananos
force-pushed
the
feat/boot-asset-digests
branch
from
September 29, 2026 19:42
26943eb to
b93e44b
Compare
hull-assets 0.1.6 carries the minimal kernel profile, which drops the drivers for hardware no VMM presents and builds in the memory cgroup controller, cgroup BPF and virtio-rng: - amd64: bzImage 11.3 MB (was 16.6 MB) - arm64: Image 23.5 MB (was 52.4 MB) The bundle builds its own initrd, so the kernel is the only part it takes from 0.1.6. Signed-off-by: Anastassios Nanos <ananos@nofire.ai>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
brig-sh/brig#392 makes brig refuse to boot a kernel or initrd whose digest does not match what it was told to expect. On Linux, the kernel and initrd come from this bundle: the launcher hands
share/guestto brig asBRIG_BOOT_ASSETS. Nothing recorded what those two files hash to, so brig had nothing to compare them with. UnderBRIG_VERIFY=require, every default Linux run would refuse. The amd64 kernel also came from bunny'slinux-kernel-cloud-hypervisor:latest, a moving tag on an image nothing signs, while arm64 took its kernel from hull-assets.This patch takes the kernel from hull-assets on both arches, makes the bundle publish the digests, and keeps a signed record of them on the host:
ghcr.io/nofireai/hull-assets, the artifact hull and brig boot from. The build resolves the version tag once, checks the signature on that digest with the bundled cosign against the identity brig checks (thebuild-assets.ymlworkflow inNOFireAI/hull-assets), and pulls that digest. The kernel's sha256 is its layer digest in the signed manifest, and on arm64 it is the file hull boots on macOS;share/guest/SHA256SUMSwith the sha256 of the kernel and ofcontainer-initrd, and publishes the same bytes as<bundle>.boot-assets.sha256. The release job checksums every asset, so the cosign-signedchecksums.txtcovers the record with no change torelease.yml;checksums.txt,checksums.txt.sigandchecksums.txt.peminshare/guest, besideSHA256SUMS, whenchecksums.txtlists that record. It fetches the signature even without cosign at install time, since brig checks it before a boot with the bundle's own cosign;pins.envnames the kernel by digest.brig's side is brig-sh/brig#403, stacked on #392. Once this and #14 land, cut v0.1.0-rc12 from
mainby pushing the tag: the certificate has to namerelease.yml@refs/tags/…, which both this installer and brig check for. brig'sinstall.shthen moves its runtime pin to rc12 in #403.Changes
scripts/build-bundle.sh:oras resolvethe hull-assets tag, check the answer is a sha256 digest,cosign verifythat digest with the bundled cosign againstASSETS_SIGNERandASSETS_ISSUER(default: brig's identity for hull-assets), pullhull-assets@<digest>, and record…:<tag>@<digest>asKERNEL_SOURCE.ASSETS_VERSIONdefaults to 0.1.6, the first hull-assets release with the minimal kernel profile: the bzImage is 11.3 MB on amd64 (was 16.6) and the Image 23.5 MB on arm64 (was 52.4).KERNEL_IMAGE_AMD64and the docker path are gone.share/guest/SHA256SUMSnext tobundle.json, and copy it to$OUT/<bundle>.boot-assets.sha256. Remove a record an earlier build left in--outfirst, so a--variant stockbuild (no guest record) cannot pass off an old one.--helpprints the whole header, output list included..github/workflows/ci.yml: a new step, "Check the boot-asset digests":share/guest/SHA256SUMS;container-initrd;sha256sum -cagainst both files;pins.envnames the kernel by digest.install.sh:checksums.txt.sigand.pemwhether or not cosign is present;keep_release_recordkeeps the three files whenchecksums.txtlists thisSHA256SUMSunder a*.boot-assets.sha256name. If the signature or the listing is missing, it keeps none and warns, because brig would then warn before every run;--helpline forINSTALL_BRIG_SKIP_SIGCHECKsays that option keeps no record.tests/install-record.sh(new) serves a fake release over http and covers eight cases:checksums.txtthat does not list the record keeps none and warns;*.boot-assets.sha256;SHA256SUMSkeeps none.README.md,DESIGN.mdanddocs/variants.md:SHA256SUMSand the kept files in the tree;Testing
shellcheck -s shis clean oninstall.sh,scripts/build-bundle.shandtests/*.shat every commit, andci.ymlparses.hull-assets:0.1.6-linux-amd64(sha256:e95a433d…) and0.1.6-linux-arm64(sha256:f86d1ca9…);release.ymlis refused: "no matching signatures: none of the expected identities matched".tests/*.shpass in an Ubuntu 24.04 container as a normal user with a subuid range (rootless-setup.shskips: no/dev/kvm). Each newinstall-record.shcase was revert-checked:verify_tarball, "without cosign the signature was not fetched";warnturned back intosay, "a release with no signature was dropped without a warning".(…, signature verified), andpins.envnames…:0.1.6-linux-amd64@sha256:e95a433d…and…:0.1.6-linux-arm64@sha256:f86d1ca9…. Installed under a scratchHOMEwith brig v0.3.0:sha256sum -c SHA256SUMSinshare/guestprintsOKfor the kernel and the initrd;brig sh ubuntu@x uname -ron a fresh sandbox returns6.12.95, rc 0, three times on each host, after "boot assets verified";brig sh ubuntu@x trueon 10 fresh sandboxes takes 3024 ms (median) against 2882 ms on nofire, in separate runs; the hull-assets kernel before 0.1.6 took 3090 ms. hull-assets ships a gzip bzImage and bunny an uncompressed vmlinux, and most of the gap is the bzImage decompressing itself.checksums.txt. An end-to-end check against a published record waits for rc12.