mirror of
https://github.com/openglow-org/forgefirm.git
synced 2026-09-28 09:11:11 -07:00
docs: decision-gate statuses; key-ceremony procedure defined (gate 8)
This commit is contained in:
+1
-1
@@ -120,7 +120,7 @@ motion constants were extracted from the `_RESOURCES` pulse files
|
|||||||
proven both ways (modern-packed signed archives apply with 0.14.2;
|
proven both ways (modern-packed signed archives apply with 0.14.2;
|
||||||
modern fwup verifies+applies the factory .fw — signer key
|
modern fwup verifies+applies the factory .fw — signer key
|
||||||
2017-05-001.pub). The production release key does not exist yet —
|
2017-05-001.pub). The production release key does not exist yet —
|
||||||
generation/custody is an operator ceremony (UPDATE-SYSTEM.md gate 3).
|
generation/custody is an operator ceremony (UPDATE-SYSTEM.md gate 8).
|
||||||
Pack releases with `scripts/mkfw.sh`; the full pipeline is
|
Pack releases with `scripts/mkfw.sh`; the full pipeline is
|
||||||
`scripts/release.sh`, invoked on this host as:
|
`scripts/release.sh`, invoked on this host as:
|
||||||
`FWUP=~/fwup-lab/bin/fwup-v1.16.0 FWUP_COMPAT=~/fwup-lab/bin/fwup-0.14.2
|
`FWUP=~/fwup-lab/bin/fwup-v1.16.0 FWUP_COMPAT=~/fwup-lab/bin/fwup-0.14.2
|
||||||
|
|||||||
+21
-7
@@ -224,13 +224,27 @@ selector, factory restore and return — without touching a shell.*
|
|||||||
|
|
||||||
## Open questions / decision gates
|
## Open questions / decision gates
|
||||||
|
|
||||||
1. Exact minimal `uEnv.txt` contents (Phase 0.1 spike decides).
|
1. **RESOLVED** (Phase 0): uEnv.txt keeps its `mmcargs` override with
|
||||||
2. fwup archive compatibility with the factory 0.14.2 binary — else
|
`root=${mmcroot}` — slot-agnostic, hardware-verified.
|
||||||
ship a static fwup alongside the installer.
|
2. **RESOLVED** (Phase 0): modern-fwup-packed signed archives apply
|
||||||
3. Size-gate thresholds (proposal: warn > 170 MiB, fail > 190 MiB
|
with the factory 0.14.2 binary (raw 32-byte pubkey form); no
|
||||||
image vs the ~195 MiB usable slot).
|
shipped fwup needed on the factory side.
|
||||||
4. Dev-image signing policy: dedicated dev key vs unsigned-with-warning
|
3. **RESOLVED** (Phase 3): size gates live in two layers — bitbake
|
||||||
only.
|
fails past the 200 MiB slot; release.sh warns ≥ 170 MiB and fails
|
||||||
|
≥ 195 MiB.
|
||||||
|
4. **RESOLVED** (Phase 3): dev archives are always signed with the
|
||||||
|
dedicated dev key (`release.sh --dev`), never unsigned.
|
||||||
|
8. Production signing-key ceremony — **procedure defined, execution
|
||||||
|
pending**: generate with fwup on the build host (never in the
|
||||||
|
repo, CI, or cloud-synced plaintext; the build-host copy is the
|
||||||
|
only online copy), keep ≥ 2 verified offline backups (USB /
|
||||||
|
paper — the private key is 128 hex chars — / passphrase-encrypted
|
||||||
|
file), embed the public key in the installer (release.sh's
|
||||||
|
key-match gate enforces the swap), and verify a signed test
|
||||||
|
archive with both fwup generations before first use. Custody
|
||||||
|
optimizes against compromise over loss: loss means users re-run a
|
||||||
|
fresh installer; compromise means attacker-signed firmware on
|
||||||
|
fielded machines.
|
||||||
5. Periodic GUI update check default-on vs opt-in (it pings the GitHub
|
5. Periodic GUI update check default-on vs opt-in (it pings the GitHub
|
||||||
API; proposal: on by default, apply always manual, config switch to
|
API; proposal: on by default, apply always manual, config switch to
|
||||||
disable).
|
disable).
|
||||||
|
|||||||
Reference in New Issue
Block a user