Switch all config options that can be toggled to "=n" when not active from board configs
Nobody has claimed this yet.
Assessment
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Newbie friendliness
- 52/100
Research direction
Start with config-gui.sh and cbfs-init.sh, then inspect the board configuration files packed into board.cpio for options that are commented out when inactive. Identify every toggleable option that needs an explicit =n value and verify that disabling it produces no effective config.user change or tampering report after reboot.
Written by the indexing model from the issue text.
Description
config-gui.sh is growing in features.
Current board configs either comment board options when deactivated or set them to option=n
The later is better, concrete example:
- DEBUG is commented in board config, which is packed into CBFS through board.cpio. Since this is commented, the debug=x doesn't exist (not considered)
- User toggles debugging into config gui. This sets
debug=yinto config.user overlay, which is applied on boot by cbfs-init.sh and considered when flashed to rom and rebooted. - Heads picks the change as tampering. User can reseal or not secrets, produce debug.log and upload for bug report.
- User deactivated debug, expects logic to save as override which if the same as board config, produce no change and save, flash back to cbfs, reboot
- since board config never had debug=n, but now config.user has debug=n, Heads measures config.user and sees a change, reports it as tampering.
- User has to reseal secrets since debug=n was never set at the first place.
Tldr: if we want users to be able to test settings without resealing and rollback, options that are deactivated needs to be set to =n in board config so that when toggled back, Heads doesn't see a change because there are none.
- Dominant language
- Makefile
- Stars
- 1.6k
- Forks
- 211
- Avg merge
- 3d 14h
- Merged PRs (30d)
- 6
Getting set up
- No Dockerfile or Docker Compose file
- No pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from linuxboot/heads
-
Difficulty 2/5 1-3 hours Newbie friendliness 86/100
-
Difficulty 1/5 Under an hour Newbie friendliness 90/100
-
Difficulty 1/5 Under an hour Newbie friendliness 65/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 64/100
-
help wanted security SMM upstream
Difficulty 5/5 Over a week Newbie friendliness 25/100
Similar issues
-
type/bug
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
Maintainers usually reply within 1 day
-
component:ktuner
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
agentic-os-org/ANOLISA#4109 · 1 comment ·
Maintainers usually reply within 1 day
-
bug priority:low ready-for-dev
Difficulty 2/5 1-3 hours Newbie friendliness 82/100
OpenHands/software-agent-sdk#5465 · 1 comment ·
Maintainers usually reply within 1 day
-
Difficulty 1/5 Under an hour Newbie friendliness 88/100
Maintainers usually reply within 1 day
-
[Bug]: atuin doctor reports "Hub (authenticated)" while the client syncs with a self-hosted serverOpen
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
Maintainers usually reply within 1 day