| Filename | Latest commit message | Latest commit date |
|---|---|---|
The machine seed moves out of the user session: souveraine-machined owns /var/lib/souveraine/seed-id as the souveraine system user and serves pubkey/sign over /run/souveraine/machined.sock (SO_PEERCRED logged, domain-separated signatures, group-gated socket). Seed is a precondition - provision via 'souveraine machine init --fresh|--migrate-from', the daemon never generates. reach/consult now resolves the machine key through the daemon with a loud legacy fallback. Hardened system unit + sysusers shipped in the Arch package. |
||
| .. | ||
| arch | ||
| deploy-phone.sh | ||
| souveraine-machined.service | ||
| souveraine.service | ||