Arch Linux and Valve Collaboration
lists.archlinux.org
lists.archlinux.org
It sounds like Valve is investing in the security of Arch Linux's build infrastructure to prevent supply chain attacks.
Because they’re not! Many packages (including the kernel itself, python, gcc, et al.), are not reproducible. See https://reproducible.archlinux.org/
Why not have the package maintainer build once (with all the modules that arch distributes), sign the output with temporary keys, and then add the signatures to the package source?
If the build is reproducible, the signatures will match the output of future builds.
If the user wants to use a custom kernel module, they’ll need to either rebuild with a new key, or turn off safe boot.
That’s vastly preferable than opening the entire kernel to build infrastructure attacks!
Anything that contains traces of a private key is not reproducible. The public key needs to be embedded in the kernel to be able to load the signed modules. If you distribute them without signature you can't load them due to the kernel not trusting them, if you sign them in any way with a private key they aren't reproducable since you don't want to hand out the private key. And to prevent additional random stuff being signed with the private key it gets discarded.
> If the user wants to use a custom kernel module, they’ll need to either rebuild with a new key, or turn off safe boot.
Or you can just sign the additional modules (e.g. DKMS) with the same key you sign the kernel & bootloader that you need to enroll into the UEFI anyway. It is less work on the users end and if the distro themselves wanna enable secure boot without user intervention via shim they need to do the signing stuff anyway.
wonder what this involves? TPM stuff?
There are some parallels with a TPM, but also a great deal of divergence (more so than in common, really).
https://media.ccc.de/v/all-systems-go-2024-263-boring-infras...
I learned this by putting Arch on a laptop I barely use.
This is actually all that Arch needs to have something called a stable branch, and I would love to roll that out to my fleet.
I don't think you understand how the Deck handles packaging. You cannot install most pacman or AUR packages on the Deck - root is locked by design and the main way you ingest packages is through filesystem overlays. This works great for centralized update models like the Deck relies on, and forcing users to adopt Flatpak avoids the dynamic linking breakage you would get otherwise. For games, this is excellent. For desktop/developer use, this is unusable.
You should check out NixOS for an Arch-like system with an emphasis on stability and huge package repos. Unlike Arch, NixOS is designed from the ground-up to operate on a read-only filesystem, while providing both declarative (configuration.nix) and iterative package (nix profile install) installation options. There are also read-only verions of other OSes like Bazzite and Kinoite, but Nix is the only one that really feels like Arch with more stability.