diff --git a/meta-forgefirm/recipes-forgefirm/forgeext/forgeext-pin.inc b/meta-forgefirm/recipes-forgefirm/forgeext/forgeext-pin.inc new file mode 100644 index 0000000..2e1b359 --- /dev/null +++ b/meta-forgefirm/recipes-forgefirm/forgeext/forgeext-pin.inc @@ -0,0 +1,8 @@ +# SPDX-License-Identifier: MIT + +# forgeext pin. Bump deliberately after pushing forgeext changes; keep +# only SRCREV and PV here - the image manifest leaves *-pin.inc out of the +# layer content hash because the component entry already identifies the +# pinned source (forgefirm-image-manifest.bbclass). +SRCREV = "0000000000000000000000000000000000000000" +PV = "0.1.0" diff --git a/meta-forgefirm/recipes-forgefirm/forgeext/forgeext.bb b/meta-forgefirm/recipes-forgefirm/forgeext/forgeext.bb new file mode 100644 index 0000000..4d98914 --- /dev/null +++ b/meta-forgefirm/recipes-forgefirm/forgeext/forgeext.bb @@ -0,0 +1,25 @@ +# SPDX-License-Identifier: MIT + +DESCRIPTION = "Extension host for ForgeFIRM powered Glowforge" +HOMEPAGE = "https://github.com/openglow-org/forgeext" + +LICENSE = "MIT" +LIC_FILES_CHKSUM = "file://LICENSE;md5=785c97b59b518e7ad943cd9e8b15fc97" + +SRC_URI = "git://github.com/openglow-org/forgeext.git;protocol=https;branch=main" +# SRCREV and PV live in the pin file (forgefirm-image-manifest.bbclass). +require forgeext-pin.inc + +S = "${WORKDIR}/git" + +inherit cmake pkgconfig forgefirm-manifest + +# jansson (the manifest, state.json, every answer), libarchive (the .ffx and +# its payload, read streaming), libsodium (the archive's signature and the +# blake2b-256 of the payload and of every installed file). +DEPENDS += "jansson libarchive libsodium" +# fwup reads an archive's metadata and task list the way the firmware +# paths would; the keyring holds the keys that sign firmware, which an +# extension is never signed with; forgefirm-sandbox is the account pool, +# the cgroup tree, and the deny rules a package's service runs inside. +RDEPENDS:${PN} = "fwup forgefirm-keys forgefirm-sandbox" diff --git a/meta-forgefirm/recipes-forgefirm/forgefirm-keys/files/ext/forgefirm-ext.pub b/meta-forgefirm/recipes-forgefirm/forgefirm-keys/files/ext/forgefirm-ext.pub new file mode 100644 index 0000000..a5cced7 --- /dev/null +++ b/meta-forgefirm/recipes-forgefirm/forgefirm-keys/files/ext/forgefirm-ext.pub @@ -0,0 +1 @@ +rTTFnjdFASq6WR/yswjwmUenMe9OKuYZC6S5K3Ay7uU= \ No newline at end of file diff --git a/meta-forgefirm/recipes-forgefirm/forgefirm-keys/forgefirm-keys.bb b/meta-forgefirm/recipes-forgefirm/forgefirm-keys/forgefirm-keys.bb index 3afbb35..364b167 100644 --- a/meta-forgefirm/recipes-forgefirm/forgefirm-keys/forgefirm-keys.bb +++ b/meta-forgefirm/recipes-forgefirm/forgefirm-keys/forgefirm-keys.bb @@ -1,10 +1,11 @@ # SPDX-License-Identifier: MIT -SUMMARY = "Firmware verification public keys" -DESCRIPTION = "Trust anchors for firmware archive verification: the \ -ForgeFIRM release-signing public key (verifies release downloads and \ -uploads) and the Glowforge factory keyring (verifies factory .fw \ -archives for cloud restore). Public keys only." +SUMMARY = "Firmware and extension verification public keys" +DESCRIPTION = "Trust anchors for archive verification: the ForgeFIRM \ +release-signing public key (verifies release downloads and uploads), the \ +Glowforge factory keyring (verifies factory .fw archives for cloud \ +restore), and the OpenGlow extension-signing public key (the official \ +tier of extension packages). Public keys only." # LICENSE covers this recipe, not the key material. The Glowforge factory # keyring in files/gf/ is Glowforge, Inc.'s: bare Ed25519 public keys, in which # no copyright subsists and over which OpenGlow claims nothing and grants @@ -12,9 +13,13 @@ archives for cloud restore). Public keys only." LICENSE = "MIT" LIC_FILES_CHKSUM = "file://${COMMON_LICENSE_DIR}/MIT;md5=0835ade698e0bcf8506ecda2f7b4f302" +# The extension key is a different key from the release key on purpose: it +# signs more often, and its loss must not sign firmware. forgeext refuses an +# extension archive whose only valid signature is one of the two above. SRC_URI = " \ file://forgefirm-release.pub \ file://gf \ + file://ext/forgefirm-ext.pub \ " S = "${WORKDIR}" @@ -24,6 +29,9 @@ do_install() { install -m 0644 ${WORKDIR}/forgefirm-release.pub \ ${D}${sysconfdir}/forgefirm/keys/forgefirm-release.pub install -m 0644 ${WORKDIR}/gf/*.pub ${D}${sysconfdir}/forgefirm/keys/gf/ + install -d ${D}${sysconfdir}/forgefirm/keys/ext + install -m 0644 ${WORKDIR}/ext/forgefirm-ext.pub \ + ${D}${sysconfdir}/forgefirm/keys/ext/forgefirm-ext.pub } FILES:${PN} = "${sysconfdir}/forgefirm/keys"