forgefirm-keys: verification trust anchors; forgectrl update manager

/etc/forgefirm/keys ships the ForgeFIRM release-signing public key
and the Glowforge factory keyring (public keys only) - the update
manager verifies release downloads/uploads against the former and
factory archives against the latter. forgectrl SRCREV bumped to the
update-manager commit; runtime deps on ffboot, fwup, the keyring, and
curl made explicit.
This commit is contained in:
ScottW514
2026-08-08 14:02:15 -04:00
parent 419710ef4b
commit d1bbecb9ee
14 changed files with 38 additions and 3 deletions
@@ -9,15 +9,17 @@ PV = "0.1.0"
SRC_URI = "git://github.com/ScottW514/forgectrl.git;protocol=https;branch=main"
# Pinned; bump deliberately after pushing forgectrl changes.
SRCREV = "945d85e37bbb4888b1cb12a837b25e6483f1a95d"
SRCREV = "64bec0edc7e98c0d071ad594c322babe54341d3c"
S = "${WORKDIR}/git"
inherit cmake update-rc.d
DEPENDS += "ulfius jpeg"
# media-ctl / v4l2-ctl configure the imx-media pipeline at runtime
RDEPENDS:${PN} = "v4l-utils"
# media-ctl / v4l2-ctl configure the imx-media pipeline at runtime;
# the update manager drives ffboot + fwup and verifies against the
# shipped keyring; release checks and downloads use curl.
RDEPENDS:${PN} = "v4l-utils ffboot fwup forgefirm-keys curl"
INITSCRIPT_NAME = "forgectrl"
INITSCRIPT_PARAMS = "defaults 90"
@@ -0,0 +1 @@
fHw/N5H/5tuBxjRBS2+r7RRl+ykltrFjsh04y/uFkXU=
@@ -0,0 +1 @@
,md2#U…”‡>0HeáÓ!ÌqW«3éÁƒfàø¨
@@ -0,0 +1 @@
‚ùë™1)«Åˇ “qÏÿqI “,kñn B
@@ -0,0 +1 @@
5x« msç�úsÍá|‚¸ßal¾íˆPð‹«éûu¾ÝÞ
@@ -0,0 +1 @@
��䁮-碥]QG �����5��_�����(
@@ -0,0 +1 @@
XйXgЩД-ё╟╙xP╙87╫ОМf|├z9mЗc╠1
@@ -0,0 +1 @@
ラ�gユ、リp纏怪薤禹€D$ら"ウ�5ォ�
@@ -0,0 +1 @@
¬�©0¹³íôs·GƒôCukH€�»¸Î Å 1OîZÃãŸ
@@ -0,0 +1 @@
�qY\(!κςχƒο7ο1/?7}2Λ�8ς9Ϊ#ϊύ@§�
@@ -0,0 +1 @@
��tj�1�q��S��1x]f+�Bc���b7Uf�
@@ -0,0 +1,23 @@
SUMMARY = "Firmware verification public keys"
DESCRIPTION = "Trust anchors for firmware archive verification: the \
ForgeFIRM release-signing public key (verifies release downloads and \
uploads) and the Glowforge factory keyring (verifies factory .fw \
archives for cloud restore). Public keys only."
LICENSE = "MIT"
LIC_FILES_CHKSUM = "file://${COMMON_LICENSE_DIR}/MIT;md5=0835ade698e0bcf8506ecda2f7b4f302"
SRC_URI = " \
file://forgefirm-release.pub \
file://gf \
"
S = "${WORKDIR}"
do_install() {
install -d ${D}${sysconfdir}/forgefirm/keys/gf
install -m 0644 ${WORKDIR}/forgefirm-release.pub \
${D}${sysconfdir}/forgefirm/keys/forgefirm-release.pub
install -m 0644 ${WORKDIR}/gf/*.pub ${D}${sysconfdir}/forgefirm/keys/gf/
}
FILES:${PN} = "${sysconfdir}/forgefirm/keys"