openSUSE Leap 16.1 to Add Immutable Mode
openSUSE Leap 16.1 will add an optional immutable mode with a read-only root filesystem and transactional updates.
The official openSUSE blog said, "Leap 16.1 is the first Leap release to offer an Immutable Mode, a transactionally updated system with a read-only root filesystem. This is essentially what our users know from Leap Micro, just integrated directly into Leap." Leap Micro is a specialized, lightweight, immutable and fixed-release operating system for containerized workloads, edge computing and virtualized environments. It is not a desktop operating system, while Leap is. The blog described Leap Immutable as "the way forward for container and virtual machine hosts, edge devices and anyone who prefers atomic updates with easy rollback."
Atomic updates and immutability are not exactly the same thing, but ZDNet reported after checking that Leap Immutable will be fully immutable rather than a lighter version. Immutable mode is an installation option that can be toggled, so users can choose either standard openSUSE Leap or the immutable variant. In immutable mode, the root file system is mounted as read-only. Directories such as /usr and /etc are mounted read-only and cannot be altered. If a malicious script were run accidentally on an immutable system, it would be unable to change anything in those immutable directories.
Leap already carries several security layers. Through version 15.6, openSUSE used AppArmor as its mandatory access control feature to restrict what system resources, files and directories programs could access. Starting with version 16.0, openSUSE switched to SELinux, which was created by the NSA in collaboration with open-source organizations such as Red Hat. SELinux labels every file, process and port on a system, follows the rule of least privilege to block actions not allowed by specific rules and requires the root user to follow those rules.
openSUSE also uses firewalld for dynamic firewall management. Its implementation includes zones, which are predefined trust levels, runtime changes that are removed on reboot versus permanent changes, and management tools including the firewall-cmd command-line tool and the firewall-config GUI application. ZDNet reported that openSUSE's firewalld implementation is similar to that of most Fedora-based distributions and is known as one of the stronger firewall implementations.
Binary hardening is another part of openSUSE's security profile. It consists of default security flags and compiler options used during software compilation to make executable files and libraries more resilient to exploits such as buffer overflows and memory corruption. The key measures include position-independent executables, which allow binaries to use random memory addresses so memory-based exploits are harder to target, and FORTIFY_SOURCE.
The addition of immutable mode would extend that existing security model. According to ZDNet, openSUSE Leap Immutable is intended for specialized deployments and also for anyone who prefers atomic updates on the desktop. With version 16.1, users will be able to select standard or immutable mode during installation.