Ecosyste.ms: OpenCollective
An open API service for software projects hosted on Open Collective.
github.com/QubesOS/qubes-antievilmaid
Qubes component: antievilmaid
https://github.com/QubesOS/qubes-antievilmaid
2d3babf20249de5e2fb6dcc54a81de178d4e67c7 authored over 9 years ago by Rusty Bird <[email protected]>
c6e305d997a35fcd8219f3f7f06848f5eed4a54e authored over 9 years ago by Rusty Bird <[email protected]>
ext4 labels can be up to 16 characters long. That leaves only two chars
after "anti-evil-maid", ...
d9d8f0811e4bbda2d934e693ea60508b3c665999 authored over 9 years ago by Rusty Bird <[email protected]>
3a6319b6692f980be64a88d92f8e79a9a124126c authored over 9 years ago by Rusty Bird <[email protected]>
eac458eafd4172eaa887781ffb0a3a9d401e3c46 authored over 9 years ago by Rusty Bird <[email protected]>
d01ec5c36ed8f10c94d7926a4c7fee900a730968 authored over 9 years ago by Rusty Bird <[email protected]>
63b25eedb965226d3eaf94dbafe17a53384f51a6 authored over 9 years ago by Rusty Bird <[email protected]>
lsblk hex ecapes some characters (e.g. spaces) with(!) -r but not
without -r, and other characte...
d88a61cc0c25d93048be8d47a1cae340400405f1 authored over 9 years ago by Rusty Bird <[email protected]>
When tpm_unsealdata exits prematurely (for example no input file), `tee`
would not write anything.
c1ca4f572712b8cab8868750a4ee194f7eca7f8d authored over 9 years ago by Marek Marczykowski-Górecki <[email protected]>
d174fcfd05295f93ab86d6b9cb094089c2d4391e authored over 9 years ago by Marek Marczykowski-Górecki <[email protected]>
1d7eb3d491425531323bc1aee481be46754a64b4 authored over 9 years ago by Marek Marczykowski-Górecki <[email protected]>
Otherwise padding may be misinterpreted by scripts.
dfc00e5868903f9bf37e3b08688b17e5ad5a942e authored over 9 years ago by Marek Marczykowski-Górecki <[email protected]>2e62d2f26b81b7ac8fe7242b5d940981b0b50646 authored over 9 years ago by Rusty Bird <[email protected]>
3b8733427c0f5c37f61dd713c28d1089a0964542 authored over 9 years ago by Rusty Bird <[email protected]>
b781d2f34ff996cb751ccf3a2a8b6961fd326e6d authored over 9 years ago by Rusty Bird <[email protected]>
efbf7ff3d280ceeb26402855b7bc46a060cec78e authored over 9 years ago by Rusty Bird <[email protected]>
basic.target is soon enough (before the GUI or any of the Qubes stuff
starts, e.g. the USB VM) b...
f47dca188a80b36263709af041b3e7a5c0209d5a authored over 9 years ago by Rusty Bird <[email protected]>
48e52d1d49f70eb3be34de992bb232e01d2f6234 authored over 9 years ago by Rusty Bird <[email protected]>
c43309d0a0b90368b5b2600c886b9deee55e0522 authored over 9 years ago by Rusty Bird <[email protected]>
Move 'dracut --regenerate-all --force', 'grub2-mkconfig', and
chmod -x /etc/grub.d/20_linux_*tbo...
If unsealing fails, and the user chooses to continue the boot process
anyway (so we know they st...
Set the ordering properly using cryptsetup-pre.target, depend on
systemd >= 208-19 to get it.
U...
87dfd2e3418af831b93535722d124d1f9339b833 authored over 9 years ago by Rusty Bird <[email protected]>
With so many changes, it's probably a good idea to switch
anti-evil-maid-unseal to 'set -e -o pi...
These different conventions were such a drag. Now the only remaining
instances of the antievilma...
For the exotic case of a completely missing LUKS device, use the
standard systemd timeout (90 se...
Always invoke 'clear' to hide the secret, because Plymouth can be active
and yet display the con...
- Common variables
- Plymouth detection
- The waitfor function (which replaces all the "wait f...
8cea124dacd34d31bc64072d30e0cb39cd4727fa authored over 9 years ago by Rusty Bird <[email protected]>67ace87ddbf044919defadec50c6f25531cffa51 authored over 9 years ago by Rusty Bird <[email protected]>
c1dca642d5609e93330376bda9f483fbfc9018af authored over 9 years ago by Rusty Bird <[email protected]>
Automatically decide if the user should remove an AEM partition's
device, by applying the follow...
Remove the last of the $GRUB_CMDLINE_AEM_FLAGS by automatically
detecting SRK passwords.
So code can easily be shared between them without a very messy
dependency situation, especially ...
Naming convention: AEM devices' labels *begin with* antievilmaid but can
have an optional suffix...
Install antievilmaid_install to /usr/sbin
Install README to /usr/share/doc/antievilmaid
dfcf976056c8096316c24d3cff7c5fa1d0fda1dc authored over 9 years ago by Rusty Bird <[email protected]>
dee7e5d2db5f733e5024388014572cf172124d97 authored over 9 years ago by Rusty Bird <[email protected]>
If secret.png.sealed exists and Plymouth is active, then show the image.
Otherwise, use secret.t...
e340e80b4d5f5d0ebeb4138c56710b36a8c3b388 authored over 9 years ago by Rusty Bird <[email protected]>
de2b9f180c4c8362bd3b1e6fe14ef52da84238c7 authored over 9 years ago by Rusty Bird <[email protected]>
This wrapper package moves the trousers data files from /var/lib/tpm to
/var/lib/tpms/<hex(sha25...
bef5fece9a6e87098b6403c78ae2963713e84da1 authored over 9 years ago by Rusty Bird <[email protected]>
77d8493edc80aeb2bc05911a5478bd004ae4b6a9 authored over 9 years ago by Rusty Bird <[email protected]>
e787fab085aa61c4c6eecad8a126711187f4fd5c authored over 9 years ago by Rusty Bird <[email protected]>
ad738208ce708bafd03f2109efaf5c2628719b96 authored over 9 years ago by Rusty Bird <[email protected]>
60bfdae30490d8978790314db84406a52eb14755 authored over 9 years ago by Rusty Bird <[email protected]>
d031a0bd1a4a1af0e102a8df8d446203ab8d5775 authored over 9 years ago by Rusty Bird <[email protected]>
5edee3e1c00a462ad7ee20aa1dd6a5e06e1368a1 authored over 9 years ago by Rusty Bird <[email protected]>
5328f7b9a85739f5544db628b1ce944bb719b358 authored over 9 years ago by Rusty Bird <[email protected]>
9b4d3f2855ce361ae0174e1b80b130546f7a49c1 authored over 9 years ago by Marek Marczykowski-Górecki <[email protected]>
Neither the rpm spec nor dracut's inst_script made the file executable,
so anti-evil-maid-check-...
908fbaab373d3df81ac2184197c9337a552c97a6 authored over 9 years ago by Marek Marczykowski-Górecki <[email protected]>
Otherwise attacker could provide similar (in terms of filesystem UUID,
LVM volume group etc) une...
0527fe0babfe9626d17ea526604af48dcb0c7e7b authored over 9 years ago by Robin Schneider <[email protected]>
abbf020bd44cb26feb7c447332636e1dc2753b70 authored over 9 years ago by Marek Marczykowski-Górecki <[email protected]>
Add detection of LUKS header modifications by extending PCR 13 with its
hash. Only volumes liste...
f1631a01430d17688dba19db1bb60e545f59b929 authored over 9 years ago by Marek Marczykowski-Górecki <[email protected]>
19a863b7fc6a950f3918f2d7828dfb1679eb8cec authored over 9 years ago by Marek Marczykowski-Górecki <[email protected]>
Also, use <ENTER> instead of <SPACE> to continue in the case of
dontforcestickremoval: It's easi...
2b011a4e8a062f4b75d74809ec42be4283bfe98a authored over 9 years ago by Rusty Bird <[email protected]>
75fc9aa03e25419c1a7b23c990abc98019e04425 authored over 9 years ago by Rusty Bird <[email protected]>
afcb205ecd2277cf03ad0d6a417a714014e62e28 authored over 9 years ago by Rusty Bird <[email protected]>
4981bfb6ba92de47fd6816ae0d9d80183ac1f5b7 authored over 9 years ago by Rusty Bird <[email protected]>
tpm_unsealdata has its own password prompt when in console mode, don't
wrap another one around i...
aa698174964f7da5eccceb36c623163165fc306b authored over 9 years ago by Rusty Bird <[email protected]>
854028753ce66d2ef4a9129681edf13d9267a9c4 authored over 9 years ago by Rusty Bird <[email protected]>
173561fc9b2939b7d77be626894581c2e057f984 authored over 9 years ago by Marek Marczykowski-Górecki <[email protected]>
Clear the secret etc. even in the dontforcestickremoval case (when it makes sense)
More precise ...
* qubesos/pr/3:
Document GRUB_CMDLINE_TBOOT in README
Add GRUB_CMDLINE_TBOOT grub variable
* qubesos/pr/2:
Avoid storing secrets in the shell history
Note about '-z' vs. SRK passwords...
* qubesos/pr/1:
(3/3) Do the right thing when installing to the internal boot partition
(2/3...
996bc22f6faa6ceeede062ee14ea82bf5a14f3d8 authored over 9 years ago by Rusty Bird <[email protected]>
This commit only indents the code that will be treated conditionally in
the next commit. 'git lo...
6e12384ac0ad882521bdceda7d7cd7217b6b65e9 authored over 9 years ago by Rusty Bird <[email protected]>
This commit only adds the code to detect internal/external installation
mode, but does not use i...
The user instructions (and the script's logic) are complicated by the
implementation detail that...
c74eec07a22b531ba9982f69599b390bf0253a11 authored over 9 years ago by Rusty Bird <[email protected]>
d7a44d92a67b6802e504d48e2cd4b9a86b8177aa authored over 9 years ago by Rusty Bird <[email protected]>
4503e6b1bdc3bcf6b6ff01c30cfc583f149fc57b authored over 9 years ago by Rusty Bird <[email protected]>
bae8cba6ac18501802f37b8258f26cb469fd5dbe authored over 9 years ago by Rusty Bird <[email protected]>
d58e493151599143086d7df8763aec7b55b6fa41 authored over 9 years ago by Rusty Bird <[email protected]>
8c5c89240dfc80aa12c925d2d612c9966f65d0ed authored over 9 years ago by Rusty Bird <[email protected]>
ac42ffba4df16b52ffc7624639231637a2ce6084 authored over 9 years ago by Rusty Bird <[email protected]>
64e166ac2164db9dfd8617921e1bbb6ba6ea6be4 authored over 9 years ago by Rusty Bird <[email protected]>
360021b0c524e1a3abbb2aa818e8edb1cd7fbc55 authored over 9 years ago by Rusty Bird <[email protected]>
Implemented using an array, so put bash in the shebang. There's a
preexisting bashism in this sc...
1a3e5ca9b193221a94bb719bf685764a07d1b887 authored over 9 years ago by Rusty Bird <[email protected]>
http://thread.gmane.org/gmane.comp.boot-loaders.tboot.devel/610/focus=611
6072f35170b6f9e34f878d2c1c306c95b983ccec authored over 9 years ago by Rusty Bird <[email protected]>cfabb4c57c2a68525ad4adbb64f90774c7717cb1 authored over 9 years ago by Rusty Bird <[email protected]>
36901ddfc5822ee2e9fee9615ce4055dba7a5a6e authored over 9 years ago by Rusty Bird <[email protected]>
f64bdfce3465d5d6503fff7f056a3a9adb2c3ae1 authored over 9 years ago by Rusty Bird <[email protected]>
ffaa70c4634c8a882d317f4eef7247905d4ffa5e authored over 9 years ago by Rusty Bird <[email protected]>
0648ec746ee6e70c5b10b8a9a7d220c86d9ad5f6 authored over 9 years ago by Rusty Bird <[email protected]>
51e685cc39ae530709305eaa3b76b7dc01dac95e authored over 10 years ago by Marek Marczykowski-Górecki <[email protected]>
297a0e64358e277323e2d62f25bc7869591e46fa authored over 10 years ago by Marek Marczykowski-Górecki <[email protected]>
20746e5f5824ff9b7cb78a572cf96228afc08789 authored over 10 years ago by Marek Marczykowski-Górecki <[email protected]>
59051ae248f552230d757cb842e37bc1e25ce9ba authored over 10 years ago by Marek Marczykowski-Górecki <[email protected]>