Security · esOS 1.0
Security design
esOS reduces risk by removing capability: no network, no persistent storage of its own, and a kernel built from an empty configuration. This page lists what that protects against, what it does not, and every setting involved.
Threat model
What esOS protects against, and what it does not
Designed to prevent
- Plaintext or keys leaking over a network: there is no IP stack and no network driver to leak through.
- Keys reaching a disk through swap, hibernation images or crash dumps: all three are compiled out.
- Software already installed on the computer, including malware on its operating system, seeing your work: that system never runs while esOS is booted.
- Residue of freed keys in memory: memory is zeroed on allocation and on release.
- DMA attacks from peripherals: the IOMMU is enabled by default.
- A corrupted or altered image going unnoticed: each release is published with SHA-256 checksums and its complete source code.
Outside the design
- Compromised firmware, a hardware keylogger or a modified computer. esOS runs on top of the firmware and cannot detect these.
- Someone with physical access to the computer while esOS is running, including attacks that read memory shortly after power-off.
- A verified boot chain: the 1.0 image is not signed for Secure Boot, so your checksum verification is what establishes trust in the image.
- Weak passwords. esx and LUKS2 slow down guessing; they cannot make a short password strong.
Kernel
Kernel configuration
The Linux 6.18.54 kernel is configured from allnoconfig, so every feature is off unless it is listed in the esOS configuration. The settings below are the ones that matter for security. The complete configuration is in the source archive.
| Setting | Value | Effect |
|---|---|---|
| CONFIG_INET | n | No IPv4/IPv6 stack. Local sockets (AF_UNIX) and the kernel crypto API (AF_ALG) remain. |
| CONFIG_MODULES | n | All drivers are built in; no code can be loaded into the kernel at run time. |
| CONFIG_SWAP · HIBERNATION · SUSPEND | n | Memory is never written to disk. |
| CONFIG_COREDUMP | n | A crashing program leaves no memory image. |
| INIT_ON_ALLOC_DEFAULT_ON · INIT_ON_FREE_DEFAULT_ON | y | Memory is zeroed when allocated and when freed. |
| INIT_STACK_ALL_ZERO · ZERO_CALL_USED_REGS | y | Stack variables and used registers are cleared. |
| CONFIG_KSM | n | No memory deduplication, which can act as a side channel. |
| INTEL_IOMMU_DEFAULT_ON | y | Devices can only reach the memory assigned to them. |
| CONFIG_LSM | lockdown,yama | Lockdown in confidentiality mode; Yama restricts ptrace. |
| IO_URING · BPF_SYSCALL · USER_NS · USERFAULTFD | n | Removes interfaces that are a frequent source of kernel exploits. |
| KEXEC · DEVMEM · PROC_KCORE · IA32_EMULATION | n | No loading another kernel, no raw physical memory access, no 32-bit system call layer. |
| MAGIC_SYSRQ | n | No keyboard shortcuts that bypass the init process. |
| CONFIG_CPU_MITIGATIONS | y | Speculative-execution mitigations built in: page-table isolation, retpoline, return thunks, IBRS and IBPB on entry, call-depth tracking and others. |
Runtime
Settings applied at boot
The esOS init process is a single statically linked C program. It mounts the virtual file systems, applies these settings, and starts the shell.
| kernel.dmesg_restrict | 1 |
|---|---|
| kernel.kptr_restrict | 2 |
| kernel.perf_event_paranoid | 3 |
| kernel.yama.ptrace_scope | 2 |
| /tmp | tmpfs, noexec |
| umask | 077 |
| Shell history | off |
| setuid programs | none |
| Random number generator | CPU source trusted, boot loader seed not credited |
Supply chain
Every source archive is verified before it is built
The build fixes a SHA-256 value and the signing key's fingerprint for each upstream archive. A file with a different hash, or a valid signature made with a different key, stops the build. Keys are fetched from public key servers, not from the server that hosts the archive.
| Component | Signed by |
|---|---|
| Linux 6.18.54 | Greg Kroah-Hartman, stable kernel maintainer |
| GRUB 2.16 | Leo Sandoval, GRUB maintainer |
| glibc 2.44 | Andreas K. Huettel, glibc release manager |
| GCC 16.2.0 (runtime libraries) | Richard Guenther, GCC release manager |
| OpenSSL 3.5.8 | OpenSSL release key |
| cryptsetup 2.8.8 | Milan Broz, cryptsetup maintainer |
| LVM2 2.03.42 (libdevmapper) | Marian Csontos, LVM2 maintainer |
| bash, coreutils, grep, sed, gawk, findutils, gzip, tar, nano | the respective GNU maintainers |
| util-linux, xz, e2fsprogs, dosfstools, less, ncurses, kbd | the respective upstream maintainers |
| popt 1.19, json-c 0.19, Terminus font 4.49.1 | not signed upstream; the SHA-256 was matched against independent sources |
The pinned hashes and key fingerprints are in config/sources.list in the source archive. The esOS kernel tree was compared file by file with the signed upstream archive and is identical.
Verify what you run.
Check the image before you write it, and the application after you boot.