-
Notifications
You must be signed in to change notification settings - Fork 21
Expand file tree
/
Copy pathMakefile
More file actions
217 lines (201 loc) · 11.6 KB
/
Copy pathMakefile
File metadata and controls
217 lines (201 loc) · 11.6 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
# SPDX-License-Identifier: AGPL-3.0-or-later
#
# NONOS microkernel build.
#
# A capability-based, RAM-resident microkernel. The kernel and every capsule
# ship a transparent post-quantum STARK attestation, are dual-signed with
# Ed25519 and ML-DSA-65, and boot behind an anti-rollback floor measured into
# the TPM.
#
# Everything a human needs is on this page; `make help` prints it.
#
# make build the production image (the default)
# make qemu build it and boot under QEMU + OVMF + a software TPM
# make usb build the real-hardware image; DISK=/dev/... writes it
# make menuconfig choose your own components, then: make from-config
# make test the boot-and-verify harness CI gates on
# make bench measured performance, with provenance, never invented
# make doctor check this host has what the build and boot need
# make clean remove build artefacts (fmt to format the tree)
#
# The build is split by concern into mk/*.mk, with per-capsule rules in
# userland/*/Capsule.mk. The nonos-mk-* targets those define are the internals
# CI drives; they all still work, they are just not the surface. This file is
# the curated top over them and defines nothing a person has to memorise.
# Per-user build configuration from `make menuconfig`. Optional: the leading
# dash keeps an absent file from being an error, so a fresh checkout builds.
-include .nonos-config
# Build concerns, included in numeric order (config, qemu, build, image, run,
# ci) so immediate `:=` assignments resolve exactly as in a single file.
include $(sort $(wildcard mk/*.mk))
# `make` with no target builds the shipping image, never nothing.
.DEFAULT_GOAL := nonos
.PHONY: nonos run qemu qemu-serial usb hardware verify test bench doctor clean clean-all distclean fmt
# ── The image that ships ─────────────────────────────────────────────────────
# The full ZeroState system: every capsule and driver, TPM-measured boot, a
# transparent STARK attestation for the kernel and each capsule, dual Ed25519 +
# ML-DSA-65 signatures, and an anti-rollback floor. Fail-closed: without an
# enrolled identity it stops rather than shipping a forgeable one. NONOS_DEV=1
# mints a clearly marked throwaway identity for evaluation (mk/00-config.mk).
#
# The build does not end at packaging: it ends by verifying itself. Five
# independent checks (ledger, signatures, declared caps, STARK membership with
# the same gate the kernel enforces, root embedding) run against the artifacts
# just written, and the build receipt records the measured result. A build
# that cannot prove what it produced does not get to say it is ready.
#
# The kernel, the ESP and the ISO are built from the recipe rather than named
# as prerequisites: prerequisites resolve in parallel, and packing an ESP
# beside the link that produces its kernel puts the previous kernel on the
# shipping image.
nonos:
$(call nonos_kernel_and_esp,nonos-mk-zerostate)
@$(MAKE) --no-print-directory nonos-mk-iso
@$(MAKE) --no-print-directory nonos-mk-trust-ledger
@$(MAKE) --no-print-directory nonos-mk-verify-image
@echo
@echo " Production image ready, and proven:"
@echo " bootable ESP : $(ESP_DIR)"
@echo " ISO : $(TARGET_DIR)/nonos.iso"
@echo " receipt : $(TARGET_DIR)/attestation/build-receipt.json"
@echo " boot in QEMU : make qemu"
@echo " to hardware : make usb DISK=/dev/..."
# ── Verify an already-built image ────────────────────────────────────────────
# The same five checks the default build ends with, standalone. Anyone holding
# the tree can re-run them and diff the receipt; that is the point.
verify: nonos-mk-verify-image
# ── The fast loop ────────────────────────────────────────────────────────────
# Proving is a release cost, never an iteration cost. One changed capsule
# invalidates every membership proof (the policy tree commits to the set), so
# the edit-compile-boot loop must not pay ten minutes of STARK grinding per
# keystroke. `make dev` rebuilds and signs what changed and boots with stale
# proofs tolerated in rollout mode, labelled as such at build and at every
# spawn. `make` stays the only path that proves; `make verify` will correctly
# refuse a dev tree, which is the system working.
dev: nonos-mk-dev
dev-qemu: nonos-mk-run-from-config
.PHONY: dev dev-qemu
# ── Boot it under emulation ──────────────────────────────────────────────────
# Same kernel, signing, attestation, and rollback path as the shipped ISO; the
# real-hardware drivers ride along and simply find no device. A software TPM
# (swtpm, CRB at 0xFED40000) backs the measured boot, so the attestation chain
# is exercised, not stubbed.
qemu: nonos-mk-run
# ── First boot ──────────────────────────────────────────────────────────────
# `make run` builds and boots, whatever state the checkout is in. With an
# enrolled identity it is the production boot; on a clean clone it mints the
# development identity from the public seed, says so on the console, builds
# and boots. One command, so nobody has to learn an internal target name to
# see the desktop, and the warning is printed by the build, not hidden in a
# doc.
run:
@if [ -f "$(ZK_BOOT_ROOT)" ] && [ "$(NONOS_DEV)" != "1" ]; then \
$(MAKE) --no-print-directory nonos-mk-run; \
else \
$(MAKE) --no-print-directory nonos-mk-dev-run; \
fi
.PHONY: run
# Headless desktop cut, serial console to a log: the profile CI's boot harness
# drives. Drops real-hardware-only drivers so the boot reaches ready under QEMU.
qemu-serial: nonos-mk-run-serial-log
# The same boot on more than one CPU. Every other lane pins QEMU to `-smp 1`,
# so the AP bring-up path had never run; this is the one that exercises it.
# Set CPUS=n to change the count (default 4). The [SMP-PROOF] line in the log
# is the kernel reporting how many cores it actually brought online.
qemu-smp: nonos-mk-run-smp-serial-log
.PHONY: qemu-smp
# The same boot with DMA remapping hardware present. Every other lane gives
# QEMU no IOMMU, so the kernel reports "DMA is unrestricted" and the VT-d
# bring-up compiled into every image never executes. Slow: VT-d needs TCG.
qemu-iommu: nonos-mk-run-iommu-serial-log
.PHONY: qemu-iommu
# The installer, end to end. `make qemu-install` boots the desktop with a blank
# NVMe disk beside the store; open Install from the launcher and write it.
# `make qemu-installed` then boots that disk alone, which is the proof: the
# machine comes up from the disk the installer wrote, with no stick attached.
# `make install-target-reset` blanks the target for another run.
qemu-install: nonos-mk-run-install
qemu-installed: nonos-mk-run-installed
install-target-reset: nonos-mk-install-target-reset
.PHONY: qemu-install qemu-installed install-target-reset
# Every machine the images claim to boot on, several times each. Slow by
# design; BOOT_MATRIX_CELLS=q35-up BOOT_MATRIX_REPEAT=1 narrows it.
boot-matrix: nonos-mk-boot-matrix
.PHONY: boot-matrix
# ── Boot it on real hardware ─────────────────────────────────────────────────
# A GPT-partitioned image firmware will boot from a stick, which an El Torito
# ISO is not dependable for. `make usb` builds it; add DISK=/dev/... to write
# it, behind a retype-the-path confirmation, because dd aimed at the wrong disk
# ends a machine. On macOS the raw device is used and the disk unmounted first;
# find yours with `diskutil list` (macOS) or `lsblk` (Linux).
usb: nonos-mk-usb-img
ifeq ($(strip $(DISK)),)
@echo
@echo " Real-hardware image ready: $(USB_IMG)"
@echo " Write it with: make usb DISK=/dev/diskN (macOS: diskutil list)"
@echo " make usb DISK=/dev/sdX (Linux: lsblk)"
else
@echo
@echo " About to OVERWRITE $(DISK) with $(USB_IMG)."
@echo " Everything on that disk is destroyed. This cannot be undone."
@printf " Type the disk path again to confirm: "; read confirm; \
if [ "$$confirm" != "$(DISK)" ]; then echo " Mismatch; not writing."; exit 1; fi; \
if [ "$(UNAME_S)" = "Darwin" ]; then \
diskutil unmountDisk $(DISK) || exit 1; \
raw=$$(echo $(DISK) | sed 's#/dev/disk#/dev/rdisk#'); \
echo " Writing to $$raw (raw device)..."; \
sudo dd if=$(USB_IMG) of=$$raw bs=4m && sync; \
diskutil eject $(DISK); \
else \
echo " Writing to $(DISK)..."; \
sudo dd if=$(USB_IMG) of=$(DISK) bs=4M status=progress conv=fsync; \
fi
@echo " Done. Boot the target machine from the stick."
endif
hardware: usb
# ── Verify ───────────────────────────────────────────────────────────────────
# The boot-and-verify harness: build, boot under QEMU, confirm the ready
# marker, the attestation count, and the trust chain. What CI gates on.
test: nonos-mk-test
# ── Measured performance ─────────────────────────────────────────────────────
# Real numbers only. Every run records host, commit, configuration, workload,
# iterations, and raw results next to the summary, and a QEMU number is a QEMU
# number, never presented as hardware. Harness: nonos-ci/bench_suite.py,
# knobs: NONOS_BENCH_* in mk/00-config.mk.
bench: nonos-mk-bench
# ── Host preflight ───────────────────────────────────────────────────────────
# Says whether this machine can build and boot NONOS before a long build finds
# out the hard way. Native hosts are macOS and Linux; on Windows use WSL2,
# which presents as Linux here and works unchanged.
doctor:
@echo " Host : $(UNAME_S) $(UNAME_M)"
@echo " Toolchain : $(TOOLCHAIN)"
@echo " Jobs : $(NONOS_JOBS) (cores $(NONOS_CORES), ram $(NONOS_RAM_GB) GiB)"
@echo
@ok=1; \
for t in "$(CARGO)" "$(RUSTUP)" "$(QEMU)" "$(SWTPM)" xorriso mformat mcopy "$(NONOS_PYTHON)"; do \
if command -v $$t >/dev/null 2>&1; then printf " ok %s\n" "$$t"; \
else printf " MISS %s\n" "$$t"; ok=0; fi; \
done; \
if $(RUSTUP) toolchain list 2>/dev/null | grep -q "$(TOOLCHAIN)"; then \
echo " ok rust $(TOOLCHAIN)"; \
else echo " MISS rust $(TOOLCHAIN) (rustup toolchain install $(TOOLCHAIN))"; ok=0; fi; \
if [ -n "$(OVMF)" ] && [ -f "$(OVMF)" ]; then echo " ok OVMF $(OVMF)"; \
else echo " MISS OVMF UEFI firmware"; ok=0; fi; \
echo; \
if [ $$ok = 1 ]; then echo " This host can build and boot NONOS."; \
else \
echo " Missing tools. Install with:"; \
if [ "$(UNAME_S)" = "Darwin" ]; then \
echo " brew install qemu swtpm xorriso mtools"; \
else \
echo " apt install qemu-system-x86 swtpm xorriso mtools (or your distro's names)"; \
fi; \
echo " curl https://sh.rustup.rs | sh (then: rustup toolchain install $(TOOLCHAIN))"; \
exit 1; \
fi
# ── Housekeeping ─────────────────────────────────────────────────────────────
clean: nonos-mk-clean
clean-all: nonos-mk-clean-all
distclean: nonos-mk-distclean
fmt: nonos-mk-fmt