Language Selection

English French German Italian Portuguese Spanish

Compartmentalized computing with CLIP OS

Filed under
OS
Gentoo

The design of CLIP OS 5 includes three elements: a bootloader, a core system, and the cages. The system uses secure boot with signed binaries. Only the x86 architecture was supported in the previous versions, and there are no other architectures in the plan for now. The core system is based on Hardened Gentoo. Finally, the cages provide user sessions, with applications and documents.

Processes running in separate cages cannot communicate directly. Instead, they must pass messages using special services on the core system; these services are unprivileged and confined on the cage system, but privileged on the core. These communication paths are shown in this architecture diagram from the documentation. Cages are also isolated from the core system itself — all interactions (system calls, for example) are checked and go through mediation services. The isolation between applications will be using containers, and the team plans to use the Flatpak format. The details of the CLIP OS 5 implementation are not available yet, as this feature is planned for the stable release.

A specific Linux security module (LSM) inspired from Linux-VServer will be used to add additional isolation between the cages, and between the cages and the core system. Linux-VServer is a virtual private server implementation designed for web hosting. It implements partitioning of a computer system in terms of CPU time, memory, the filesystem, and network addressing into security contexts. Starting and stopping a new virtual server corresponds to setting up and tearing down a security context.

Read more

More in Tux Machines

Announcing Oracle Solaris 11.4 SRU12

Today we are releasing the SRU 12 for Oracle Solaris 11.4. It is available via 'pkg update' from the support repository or by downloading the SRU from My Oracle Support Doc ID 2433412.1. Read more Also: Oracle Solaris 11.4 SRU12 Released - Adds GCC 9.1 Compiler & Python 3.7

Redcore Linux 1908 Released, Which Fixes Many of the Pending Bugs

Redcore Linux developer has released the new version of Redcore Linux 1908 and code name is Mira. This release fixes most of the outstanding bugs and some more polishing. Also, added new features as well. Bunch of packages (1000+) got updated because this release is based on Gentoo’s testing branch, unlike previous releases which were based on a mix of Gentoo’s stable and testing branches. Starting from Redcore Linux 1908, the packages shold be up-to-date since it’s using Gentoo’s testing branch. Read more

Red Hat Satellite 6.6 Beta is now available with enhancements across reporting, automation, and supportability

We are pleased to announce that Red Hat Satellite 6.6 is now available in beta to current Satellite customers. Red Hat Satellite is a scalable platform to manage patching, provisioning, and subscription management of your Red Hat infrastructure, regardless of where it is running. The Satellite 6.6 beta is focused on enhancements across reporting, automation, and supportability While Satellite 6.6 Beta supports Red Hat Enterprise Linux 8 hosts, it is important to note that Satellite 6.6 must be installed on a Red Hat Enterprise Linux 7 host. Support for running Satellite itself on a Red Hat Enterprise Linux 8 host is scheduled for a later release. Read more Also: Serverless on Kubernetes, diverse automation, and more industry trends

Android Leftovers