Security

What is verified, and what isn't.

Rime's security rests on one signed image, checked before every update. This page says exactly what that covers, and where the gaps are.

Signed images

Every image is signed in CI with cosign, keyless: the signature is tied to the GitHub Actions workflow that built it, not to a key someone holds. CI verifies the signature and the attestation itself before it moves any tag.

  • Signer identity: https://github.com/AndreNijman/rime-os/.github/workflows/build-image.yml@refs/heads/main
  • Every image carries a signed SPDX software bill of materials, recorded in the public Rekor log.
  • During the rename, clients accept both the old apex-os and the new rime-os identity.
cosign verify ghcr.io/andrenijman/rime-os:rime --certificate-identity https://github.com/AndreNijman/rime-os/.github/workflows/build-image.yml@refs/heads/main --certificate-oidc-issuer https://token.actions.githubusercontent.com

Checked before every update

rime update verifies the digest the registry is serving right now: the payload hash, the signature, the certificate chain up to a Fulcio root pinned inside the image, the signer identity and issuer, and that the signature names this digest. Under the default policy anything that fails or is missing is refused, and an offline check refuses too.

rime trust --gate

Secure Boot is your choice

Installed machines boot through Fedora's Microsoft-signed shim, then GRUB, then a kernel signed with Rime's Secure Boot key. The installer offers to enrol that key; if you skip it, leave Secure Boot off. Out-of-tree drivers such as NVIDIA's are signed with the same key.

  • The kernel does not enforce module signatures and is not locked down under Secure Boot.
  • systemd-boot with signed unified kernel images, and automatic rollback after a failed boot, are built but not yet what any published install uses.

Encrypted by default

The installer encrypts the whole disk with LUKS2 and always enrols a recovery key first, which you must acknowledge before you can reboot.

  • A TPM unlock is added only when Secure Boot is enforcing, bound to PCR 7 and with no PIN by default.
  • The installer's automated tests don't exercise TPM enrolment yet.

Agent sessions are sandboxed

Rime can supervise command-line coding agents. A session runs in a default-deny bubblewrap sandbox, holds no root, and asks a person to approve privilege requests from a fixed list. Credentials are brokered: the API that hands out access has no verb that returns a secret.

  • The sandbox is meant for a cooperating but fallible agent, not a determined kernel attacker.
  • Ordinary terminals are never sandboxed.
  • Agents covers the sandbox, privilege requests and the credential broker in full.

No telemetry service

Rime runs no telemetry service and uploads no health reports. The one service Rime operates is the relay for Rime Remote, which carries encrypted traffic it cannot read. Every default network contact is listed on Privacy on Rime.

Reporting a vulnerability

Please report security problems privately through GitHub's private vulnerability reporting on the rime-os repository (or rime-shell for the desktop). Please don't open a public issue with exploit details.

Machine-readable contact: /.well-known/security.txt.