Watch
1
0
Fork
You've already forked SouveraineOS
0
Commit graph SouveraineOS/docs/STORAGE-ENCRYPTION.md
Author SHA1 Message Date
Fimeg
341a2fe060 docs: take the lockscreen out of casey's uid
The current user unit wins the boot race but still runs as the human whose Personal key the lock is meant to evict. Record the target souveraine-session principal, its narrow Wayland/PAM/data reach, and the fact that the rich shell is presentation—not release authority.
2026-08-17 12:43:45 -04:00
Fimeg
9815185caa docs: put agent identity behind a real uid
Join the older storage and authority audits to the SAF principal contract. Passwd entries are not isolation while one human-owned process still executes every agent, and the existing souveraine account is machined's—not Souvie's.\n\nKeep the readiness task honest: its current health fields inventory paths, but do not yet prove admission or the UID handling a live turn.
2026-08-17 12:36:45 -04:00
Fimeg
4aa61d735c docs: reconcile USB, Waydroid, audio and charging 2026-08-07 14:52:28 -04:00
Fimeg
931e794701 docs: kernel handoff (gitea blueline FF to f56b1ae, one build path), QCE-off note, shell-tree unify task 2026-07-21 15:49:15 -04:00
Fimeg
ae6e2be533 secrets landed: archive TASK-11, storage-encryption status, handoff
souveraine-secrets is live on the phone (reboot-verified, keyring
masked) — TASK-11 complete, moved to tasks/archive/ with the outcome.
STORAGE-ENCRYPTION.md: add the doc (design of record, 2026-07-20) with
status updated to match code — secrets-store AEAD + machine wrap built,
Argon2id wrap built with ingress pending; the derive_storage_key gap
paragraph now scoped to what remains. Add session handoff.
2026-07-20 21:20:38 -04:00