mirror of
https://github.com/openglow-org/forgefirm.git
synced 2026-09-28 09:11:11 -07:00
forgeext: the recipe, and the extension-signing key in the keyring
forgeext is the extension host, a component of its own: recipe recipes-forgefirm/forgeext (cmake, pkgconfig, forgefirm-manifest, so it is a manifest component with its own pin file). It links jansson, libarchive, and libsodium, and runs with fwup, the keyring, and forgefirm-sandbox. libarchive and jansson are on the image already; libsodium comes with it. The pin is all zeros because the repository has no pushed commit to name: the recipe builds from a working tree through externalsrc, and a build from pins cannot fetch it until the first push sets the pin. It is not in the image's install list. forgefirm-keys installs a third trust anchor, /etc/forgefirm/keys/ext/forgefirm-ext.pub: the OpenGlow extension-signing public key, the official tier of extension packages. It is a different key from the release key on purpose: it signs more often, and its loss must not sign firmware. forgeext refuses an extension archive whose only valid signature is the release key's or a factory key's. Proven. The recipe cross-builds forgeext from the working tree, and that binary ran the verify-and-install cases on the bench reference (image 20260920211625, from /tmp, with the board's own fwup 1.16.0 and the image's keyring) with the results of the host test. forgefirm-keys builds and packages the key 0644 under ext/ (0755), byte-identical to the file here; it is 32 key bytes and is not the release key. Acceptance. No catalog test reads either yet: forgeext's tests are the exthost suite that comes with its daemon, and the key is layer content, in the platform identity of every fingerprint.
This commit is contained in:
@@ -0,0 +1,8 @@
|
|||||||
|
# SPDX-License-Identifier: MIT
|
||||||
|
|
||||||
|
# forgeext pin. Bump deliberately after pushing forgeext changes; keep
|
||||||
|
# only SRCREV and PV here - the image manifest leaves *-pin.inc out of the
|
||||||
|
# layer content hash because the component entry already identifies the
|
||||||
|
# pinned source (forgefirm-image-manifest.bbclass).
|
||||||
|
SRCREV = "0000000000000000000000000000000000000000"
|
||||||
|
PV = "0.1.0"
|
||||||
@@ -0,0 +1,25 @@
|
|||||||
|
# SPDX-License-Identifier: MIT
|
||||||
|
|
||||||
|
DESCRIPTION = "Extension host for ForgeFIRM powered Glowforge"
|
||||||
|
HOMEPAGE = "https://github.com/openglow-org/forgeext"
|
||||||
|
|
||||||
|
LICENSE = "MIT"
|
||||||
|
LIC_FILES_CHKSUM = "file://LICENSE;md5=785c97b59b518e7ad943cd9e8b15fc97"
|
||||||
|
|
||||||
|
SRC_URI = "git://github.com/openglow-org/forgeext.git;protocol=https;branch=main"
|
||||||
|
# SRCREV and PV live in the pin file (forgefirm-image-manifest.bbclass).
|
||||||
|
require forgeext-pin.inc
|
||||||
|
|
||||||
|
S = "${WORKDIR}/git"
|
||||||
|
|
||||||
|
inherit cmake pkgconfig forgefirm-manifest
|
||||||
|
|
||||||
|
# jansson (the manifest, state.json, every answer), libarchive (the .ffx and
|
||||||
|
# its payload, read streaming), libsodium (the archive's signature and the
|
||||||
|
# blake2b-256 of the payload and of every installed file).
|
||||||
|
DEPENDS += "jansson libarchive libsodium"
|
||||||
|
# fwup reads an archive's metadata and task list the way the firmware
|
||||||
|
# paths would; the keyring holds the keys that sign firmware, which an
|
||||||
|
# extension is never signed with; forgefirm-sandbox is the account pool,
|
||||||
|
# the cgroup tree, and the deny rules a package's service runs inside.
|
||||||
|
RDEPENDS:${PN} = "fwup forgefirm-keys forgefirm-sandbox"
|
||||||
@@ -0,0 +1 @@
|
|||||||
|
rTTFnjdFASq6WR/yswjwmUenMe9OKuYZC6S5K3Ay7uU=
|
||||||
@@ -1,10 +1,11 @@
|
|||||||
# SPDX-License-Identifier: MIT
|
# SPDX-License-Identifier: MIT
|
||||||
|
|
||||||
SUMMARY = "Firmware verification public keys"
|
SUMMARY = "Firmware and extension verification public keys"
|
||||||
DESCRIPTION = "Trust anchors for firmware archive verification: the \
|
DESCRIPTION = "Trust anchors for archive verification: the ForgeFIRM \
|
||||||
ForgeFIRM release-signing public key (verifies release downloads and \
|
release-signing public key (verifies release downloads and uploads), the \
|
||||||
uploads) and the Glowforge factory keyring (verifies factory .fw \
|
Glowforge factory keyring (verifies factory .fw archives for cloud \
|
||||||
archives for cloud restore). Public keys only."
|
restore), and the OpenGlow extension-signing public key (the official \
|
||||||
|
tier of extension packages). Public keys only."
|
||||||
# LICENSE covers this recipe, not the key material. The Glowforge factory
|
# LICENSE covers this recipe, not the key material. The Glowforge factory
|
||||||
# keyring in files/gf/ is Glowforge, Inc.'s: bare Ed25519 public keys, in which
|
# keyring in files/gf/ is Glowforge, Inc.'s: bare Ed25519 public keys, in which
|
||||||
# no copyright subsists and over which OpenGlow claims nothing and grants
|
# no copyright subsists and over which OpenGlow claims nothing and grants
|
||||||
@@ -12,9 +13,13 @@ archives for cloud restore). Public keys only."
|
|||||||
LICENSE = "MIT"
|
LICENSE = "MIT"
|
||||||
LIC_FILES_CHKSUM = "file://${COMMON_LICENSE_DIR}/MIT;md5=0835ade698e0bcf8506ecda2f7b4f302"
|
LIC_FILES_CHKSUM = "file://${COMMON_LICENSE_DIR}/MIT;md5=0835ade698e0bcf8506ecda2f7b4f302"
|
||||||
|
|
||||||
|
# The extension key is a different key from the release key on purpose: it
|
||||||
|
# signs more often, and its loss must not sign firmware. forgeext refuses an
|
||||||
|
# extension archive whose only valid signature is one of the two above.
|
||||||
SRC_URI = " \
|
SRC_URI = " \
|
||||||
file://forgefirm-release.pub \
|
file://forgefirm-release.pub \
|
||||||
file://gf \
|
file://gf \
|
||||||
|
file://ext/forgefirm-ext.pub \
|
||||||
"
|
"
|
||||||
|
|
||||||
S = "${WORKDIR}"
|
S = "${WORKDIR}"
|
||||||
@@ -24,6 +29,9 @@ do_install() {
|
|||||||
install -m 0644 ${WORKDIR}/forgefirm-release.pub \
|
install -m 0644 ${WORKDIR}/forgefirm-release.pub \
|
||||||
${D}${sysconfdir}/forgefirm/keys/forgefirm-release.pub
|
${D}${sysconfdir}/forgefirm/keys/forgefirm-release.pub
|
||||||
install -m 0644 ${WORKDIR}/gf/*.pub ${D}${sysconfdir}/forgefirm/keys/gf/
|
install -m 0644 ${WORKDIR}/gf/*.pub ${D}${sysconfdir}/forgefirm/keys/gf/
|
||||||
|
install -d ${D}${sysconfdir}/forgefirm/keys/ext
|
||||||
|
install -m 0644 ${WORKDIR}/ext/forgefirm-ext.pub \
|
||||||
|
${D}${sysconfdir}/forgefirm/keys/ext/forgefirm-ext.pub
|
||||||
}
|
}
|
||||||
|
|
||||||
FILES:${PN} = "${sysconfdir}/forgefirm/keys"
|
FILES:${PN} = "${sysconfdir}/forgefirm/keys"
|
||||||
|
|||||||
Reference in New Issue
Block a user