Development documentation

This is the in-progress lota-next branch. For the released version, see the stable documentation.

LOTA Documentation

Linux Open Trusted Attestation (LOTA) is a Linux attestation and runtime-integrity framework. This tree holds the project's narrative documentation, organised by the role of the reader.

Component documentation (examples, policies, SELinux, Syzkaller, EK roots, benchmarks) lives next to the code it describes, as a README.rst in the relevant directory.

Who are you?

New contributor or automated assistant

Development happens on lota-next. Open pull requests there, not against main.

Operator

Production operation starts with the bring-up document. The agent intentionally fails closed when required gates are missing.

Security reviewer or academic reviewer

Start with the threat model and the reporting policy. Do not file public issues for exploitable vulnerabilities.

TPM or attestation engineer

The hardware trust contract centres on EK root validation, credential activation, AIK certificates, TPM quotes, PCR policy, and PCR14 boot commitment.

Kernel or BPF engineer

The kernel-facing surface lives in the BPF LSM object, loader, runtime measurement path, initramfs PCR14 lock, SELinux policy, and the Syzkaller harness.

Game or anti-cheat integrator

LOTA exposes trust decisions and token verification material. Gameplay policy remains outside this repository.

Distribution maintainer

Packaging must preserve the security contract. Release artifacts are reproducible and verified against signed manifests.