Security · esOS 1.0

Security design

esOS reduces risk by removing capability: no network, no persistent storage of its own, and a kernel built from an empty configuration. This page lists what that protects against, what it does not, and every setting involved.

Threat model

What esOS protects against, and what it does not

Designed to prevent

  • Plaintext or keys leaking over a network: there is no IP stack and no network driver to leak through.
  • Keys reaching a disk through swap, hibernation images or crash dumps: all three are compiled out.
  • Software already installed on the computer, including malware on its operating system, seeing your work: that system never runs while esOS is booted.
  • Residue of freed keys in memory: memory is zeroed on allocation and on release.
  • DMA attacks from peripherals: the IOMMU is enabled by default.
  • A corrupted or altered image going unnoticed: each release is published with SHA-256 checksums and its complete source code.

Outside the design

  • Compromised firmware, a hardware keylogger or a modified computer. esOS runs on top of the firmware and cannot detect these.
  • Someone with physical access to the computer while esOS is running, including attacks that read memory shortly after power-off.
  • A verified boot chain: the 1.0 image is not signed for Secure Boot, so your checksum verification is what establishes trust in the image.
  • Weak passwords. esx and LUKS2 slow down guessing; they cannot make a short password strong.

Kernel

Kernel configuration

The Linux 6.18.54 kernel is configured from allnoconfig, so every feature is off unless it is listed in the esOS configuration. The settings below are the ones that matter for security. The complete configuration is in the source archive.

SettingValueEffect
CONFIG_INETnNo IPv4/IPv6 stack. Local sockets (AF_UNIX) and the kernel crypto API (AF_ALG) remain.
CONFIG_MODULESnAll drivers are built in; no code can be loaded into the kernel at run time.
CONFIG_SWAP · HIBERNATION · SUSPENDnMemory is never written to disk.
CONFIG_COREDUMPnA crashing program leaves no memory image.
INIT_ON_ALLOC_DEFAULT_ON · INIT_ON_FREE_DEFAULT_ONyMemory is zeroed when allocated and when freed.
INIT_STACK_ALL_ZERO · ZERO_CALL_USED_REGSyStack variables and used registers are cleared.
CONFIG_KSMnNo memory deduplication, which can act as a side channel.
INTEL_IOMMU_DEFAULT_ONyDevices can only reach the memory assigned to them.
CONFIG_LSMlockdown,yamaLockdown in confidentiality mode; Yama restricts ptrace.
IO_URING · BPF_SYSCALL · USER_NS · USERFAULTFDnRemoves interfaces that are a frequent source of kernel exploits.
KEXEC · DEVMEM · PROC_KCORE · IA32_EMULATIONnNo loading another kernel, no raw physical memory access, no 32-bit system call layer.
MAGIC_SYSRQnNo keyboard shortcuts that bypass the init process.
CONFIG_CPU_MITIGATIONSySpeculative-execution mitigations built in: page-table isolation, retpoline, return thunks, IBRS and IBPB on entry, call-depth tracking and others.

Runtime

Settings applied at boot

The esOS init process is a single statically linked C program. It mounts the virtual file systems, applies these settings, and starts the shell.

kernel.dmesg_restrict1
kernel.kptr_restrict2
kernel.perf_event_paranoid3
kernel.yama.ptrace_scope2
/tmptmpfs, noexec
umask077
Shell historyoff
setuid programsnone
Random number generatorCPU source trusted, boot loader seed not credited

Supply chain

Every source archive is verified before it is built

The build fixes a SHA-256 value and the signing key's fingerprint for each upstream archive. A file with a different hash, or a valid signature made with a different key, stops the build. Keys are fetched from public key servers, not from the server that hosts the archive.

ComponentSigned by
Linux 6.18.54Greg Kroah-Hartman, stable kernel maintainer
GRUB 2.16Leo Sandoval, GRUB maintainer
glibc 2.44Andreas K. Huettel, glibc release manager
GCC 16.2.0 (runtime libraries)Richard Guenther, GCC release manager
OpenSSL 3.5.8OpenSSL release key
cryptsetup 2.8.8Milan Broz, cryptsetup maintainer
LVM2 2.03.42 (libdevmapper)Marian Csontos, LVM2 maintainer
bash, coreutils, grep, sed, gawk, findutils, gzip, tar, nanothe respective GNU maintainers
util-linux, xz, e2fsprogs, dosfstools, less, ncurses, kbdthe respective upstream maintainers
popt 1.19, json-c 0.19, Terminus font 4.49.1not signed upstream; the SHA-256 was matched against independent sources

The pinned hashes and key fingerprints are in config/sources.list in the source archive. The esOS kernel tree was compared file by file with the signed upstream archive and is identical.

Verify what you run.

Check the image before you write it, and the application after you boot.