Files
ScottW514 11031ad87f GnuTLS with kernel TLS, and forgectrl.tls-records
The gnutls bbappend builds GnuTLS with --enable-ktls and installs
/etc/gnutls/config with ktls = true, so after the handshake the kernel
seals and opens forgectrl's HTTPS records (the kernel side is
meta-openglow's CONFIG_TLS and patch 0016). It also backports GnuTLS
dc016daf: 3.8.4 hands the kernel the record sequence number where a TLS
1.2 ChaCha20-Poly1305 connection's IV belongs, so every such connection
failed the kernel's first decryption. forgectrl is the only program on
the image that links GnuTLS.

forgectrl.tls-records, in its own module (suite/tlsrec.py), reads the
result from the outside with openssl s_client on loopback: a desktop
offer (AES-GCM first) gets ChaCha20-Poly1305 over TLS 1.3 and 1.2 and the
kernel takes both directions' keys; an AES-128-GCM-only offer, three
times over each protocol, gets it, the kernel takes its keys, and the
CAAM's job-ring interrupt counts the records; a TLS 1.2 CBC-only offer
connects and stays in GnuTLS (the control for the kernel's counters);
every copy of the panel page equals the plain-HTTP copy byte for byte,
with no decrypt error; the kernel's drivers are
rfc7539(chacha20-neon,poly1305-neon) and ctr-aes-caam with ghash-ce.

Proof: on the image before these fixes the test failed on both bugs it
names (the TLS 1.2 ChaCha20 page arrived empty with a decrypt error; the
AES-GCM pages arrived damaged); on image 20260927224418 it passes. The
unit suite (500 tests) and the coverage lint (0 uncovered paths) pass on
the host.
2026-09-27 20:01:31 -04:00

76 lines
3.8 KiB
Plaintext

# SPDX-License-Identifier: MIT
require conf/distro/include/fslc-base.inc
DISTRO = "forgefirm"
DISTRO_NAME = "OpenGlow/ForgeFIRM"
DISTRO_VERSION = "0.0.0"
DISTRO_FEATURES:remove = " \
3g alsa avahi bluetooth bluez5 ext2 irda nfc nfs pci pcmcia \
pulseaudio vulkan wayland x11 zeroconf "
# The name the image ships in /etc/hostname. forgefirm-hostname replaces
# it at S38 in rcS with forgefirm-<xxxx>, from the machine's MAC address;
# this is what the few seconds before that show, and the fallback on a
# machine whose MAC address cannot be read.
hostname:pn-base-files = "forgefirm"
# No mDNS. The panel is reached at the machine's address, which every
# network resolves; the machine's own name (forgefirm-<xxxx>, from
# forgefirm-hostname) goes out in the DHCP request, so a network with
# dynamic DNS publishes it as well. The avahi and zeroconf features stay
# removed above: zeroconf would install packagegroup-base-zeroconf (the
# daemon plus libnss-mdns), and avahi would switch other recipes' avahi
# options on.
# TLS: forgectrl serves HTTPS on 443 with a self-signed certificate
# through libmicrohttpd and ulfius, and links GnuTLS itself. GnuTLS is
# trimmed to the library:
# no seccomp the distro default adds libseccomp for the gnutls test
# programs; the library does not use it
# no libidn internationalized host names in certificates; the
# machine's own certificate is plain ASCII (saves libidn2)
# no p11-kit PKCS#11 tokens and the system trust store; the machine
# presents its own certificate and verifies no peer
# through GnuTLS (saves p11-kit and its modules)
# libtasn1 stays a shared library: the bundled copy is the same
# code without poky's CVE patches
# no tpm, fips, dane, and no certificate compression (brotli, zlib,
# zstd), none of which the panel uses
# Kernel TLS is built in and turned on by the gnutls bbappend
# (recipes-support/gnutls), which also installs /etc/gnutls/config.
PACKAGECONFIG:pn-gnutls = "libtasn1"
# opengl stays: forgectrl's camera demosaic runs as GLES2 fragment
# shaders on the GC880 (etnaviv), reached through surfaceless EGL with
# no display stack. Mesa is trimmed to exactly that: the etnaviv
# gallium driver, GLES/EGL/GBM, no GLX, no X11/Wayland platforms
# (both remain removed above), so the cost is the libraries and the one
# driver, not a graphics stack.
PACKAGECONFIG:pn-mesa = "opengl gles egl gbm gallium etnaviv"
# udev's hardware database is USB and PCI vendor/product identities (7.7 MB);
# the board has neither bus.
BAD_RECOMMENDATIONS += "eudev-hwdb"
# System logger: rsyslog replaces busybox syslogd/klogd. Every ForgeFIRM
# process logs through it and it is the only log writer (one directory
# per logger under /data/log/forgefirm; per-logger levels and the remote
# target come from the machine settings). Trimmed to what the image uses:
# the local socket and kernel inputs, file output, plain UDP/TCP
# forwarding, and rainerscript filters - no TLS, database, HTTP, or
# signing modules (rootfs must fit the 200 MiB factory slot).
VIRTUAL-RUNTIME_base-utils-syslog = "rsyslog"
PACKAGECONFIG:pn-rsyslog = "rsyslogd rsyslogrt klog inet regexp"
# nftables: the extension sandbox's rule loader (forgefirm-sandbox). The nft
# binary and its library, with JSON output so a program can read back what
# the kernel holds; no interactive shell (readline) and no Python binding.
# gmp and jansson are on the image already.
PACKAGECONFIG:pn-nftables = "json"
# Local (file://) source checksums leave out a workstation's Python bytecode
# caches: the forgetest recipe fetches its package directory whole, and a
# host test run must not move a task hash without a source change.
BB_SIGNATURE_LOCAL_DIRS_EXCLUDE = "CVS .bzr .git .hg .osc .p4 .repo .svn __pycache__ .pytest_cache"