SYSTEMS
JLR
A Linux security-governance prototype that combines content-addressed software identity, signed policy, evidence ledgers and confinement.
- Current state
- Linux prototype
- Discipline
- Systems
- Built with
- Rust / Linux namespaces / Landlock / seccomp / fanotify / Ed25519 / Merkle trees / QEMU
The idea
Explore a Linux governance boundary that makes permitted operations, operator authority and decision evidence explicit.
How it works
Measured artifact records feed a deterministic policy engine. Signed evidence records track decisions; execution cells reduce authority through namespaces, seccomp, Landlock and capability controls. Separate boot work explores signed releases, A/B slots and rollback policy.
What’s implemented
- Deterministic trust decisions with explicit evidence and revocation
- Canonical CBOR records, Ed25519 envelopes and content-addressed artifact identity
- Merkle evidence ledger with signed checkpoints
- Sealed execution cells and an audit/enforcement exec gate
- Reproducible base-image and initramfs tooling with QEMU test coverage
PROJECT STATUS / LINUX PROTOTYPE
Where it stands
Pre-release Linux prototype
- Not externally audited or production-ready
- Companion mode depends on host trust and has documented execution-gate boundaries
- Firmware/TPM authentication, installer/recovery integration and post-quantum signatures remain design work
Source & resources
GitHub repositorySource code and project documentation ↗OverviewOpen resource ↗Security boundariesOpen resource ↗
Documentation behind this project page
Reviewed October 1, 2026. Project descriptions reflect a source review; repository validation claims were not independently reproduced.