Startup gate matrix and automated bring-up
Startup gate matrix
The agent's startup chain refuses to load BPF / attach LSM programs unless
every entry below is satisfied. Source references are file::line into the
current tree.
Gate |
Check site |
Operator action |
|---|---|---|
|
|
Boot under Secure Boot or pass |
|
|
Fedora 44 ships this by default. On distros that do not, add
|
IMA appraisal in an enforcing mode |
|
Add |
|
|
Install the udev rule under configs/udev/99-lota-tpm.rules (handled by
|
Kernel-enforced immutability of |
|
fs-verity OR a signed |
BPF object Ed25519 signature |
|
Ships signed: the agent package carries |
AIK persistent handle + metadata in sync |
|
Evict any stale persistent handle ( |
PCR14 fresh after boot |
|
Cold reboot before the first agent start; PCR14 only resets on hardware reset. |
Every gate maps to a lota_err() line in the journal when it fails, so
journalctl -u lota-agent is the canonical debugging surface.
Automated developer bring-up
scripts/lota-dev-bringup.sh runs the steps above in a fixed order:
sudo make install # land agent + BPF + units
sudo scripts/lota-dev-bringup.sh # gate the host
sudo reboot # PCR14 baseline rebind
sudo systemctl start lota-agent.socket lota-agent.service
sudo systemctl status lota-agent.service --no-pager
The script is idempotent and prints which step it ran or skipped so re-runs after a partial failure are safe. Read it before running.