The TuxTape project aims to deploy infrastructure for live patching the Linux kernel.

The insurance company GEICO has released a preliminary version of the TuxTape toolkit, which enables the deployment of an infrastructure for creating, assembling, and delivering live patches for the Linux kernel. Live patches allow for the application of fixes to the Linux kernel on-the-fly, without rebooting or stopping the system. The project's code is written in Rust and is distributed under the Apache 2.0 license.

Companies like Red Hat, Oracle, Canonical, and SUSE provide live patches that address vulnerabilities for their distributions, but the only open part they offer is the low-level toolkit for working with patches, while the actual patches are developed behind closed doors. The Gentoo and Debian distributions tried to develop open projects like elivepatch and linux-livepatching, but the first has been abandoned for 6 years, and the second has stalled at the prototype testing stage.

TuxTape aims to establish its own system for creating and delivering live patches that is independent of third-party providers and can be adapted for any Linux kernels, rather than just those associated with specific distribution packages. TuxTape can generate live patches compatible with the kpatch toolkit developed by Red Hat (besides kpatch, there are similar tools: kGraft from SUSE, Ksplice from Oracle, and the universal livepatch). Patches are created as loadable kernel modules that replace functions in the kernel, using the ftrace subsystem to redirect to new functions included in the module.

The TuxTape project aims to deploy infrastructure for live patching the Linux kernel.

TuxTape can track information about vulnerability fixes in the Linux kernel, published in the linux-cve-announce mailing list and the Git repository, rank vulnerabilities by severity, determine applicability to the supported Linux kernels, and generate live patches based on regular patches for LTS kernel branches. The applicability of the original patches is evaluated through kernel build profiling. Patches with vulnerabilities that do not affect the target kernel are ignored.

TuxTape includes a system for tracking new vulnerabilities in the kernel, a patch and vulnerability database builder. server for storing metadata, the core build dispatch system, kernel builder, patch generator, patch archive, client for obtaining patches for end hosts, and an interactive interface for managing the creation of live patches.

The TuxTape project aims to deploy infrastructure for live patching the Linux kernel.

The development is in the experimental prototype stage. For initial testing, the following tools are suggested: tuxtape-cve-parser for parsing vulnerability information and building a patch database; tuxtape-server with gRPC interface implementation for services generating patches; tuxtape-kernel-builder for building the kernel in a specified configuration and generating a build profile; tuxtape-dashboard — a console interface for reviewing and creating live patches based on source patches received from tuxtape-server.

The TuxTape project aims to deploy infrastructure for live patching the Linux kernel.


Source: opennet.ru
Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster