mirror of
https://github.com/openglow-org/forgefirm.git
synced 2026-09-28 09:11:11 -07:00
forgefirm-keys: verification trust anchors; forgectrl update manager
/etc/forgefirm/keys ships the ForgeFIRM release-signing public key and the Glowforge factory keyring (public keys only) - the update manager verifies release downloads/uploads against the former and factory archives against the latter. forgectrl SRCREV bumped to the update-manager commit; runtime deps on ffboot, fwup, the keyring, and curl made explicit.
This commit is contained in:
@@ -9,15 +9,17 @@ PV = "0.1.0"
|
|||||||
|
|
||||||
SRC_URI = "git://github.com/ScottW514/forgectrl.git;protocol=https;branch=main"
|
SRC_URI = "git://github.com/ScottW514/forgectrl.git;protocol=https;branch=main"
|
||||||
# Pinned; bump deliberately after pushing forgectrl changes.
|
# Pinned; bump deliberately after pushing forgectrl changes.
|
||||||
SRCREV = "945d85e37bbb4888b1cb12a837b25e6483f1a95d"
|
SRCREV = "64bec0edc7e98c0d071ad594c322babe54341d3c"
|
||||||
|
|
||||||
S = "${WORKDIR}/git"
|
S = "${WORKDIR}/git"
|
||||||
|
|
||||||
inherit cmake update-rc.d
|
inherit cmake update-rc.d
|
||||||
|
|
||||||
DEPENDS += "ulfius jpeg"
|
DEPENDS += "ulfius jpeg"
|
||||||
# media-ctl / v4l2-ctl configure the imx-media pipeline at runtime
|
# media-ctl / v4l2-ctl configure the imx-media pipeline at runtime;
|
||||||
RDEPENDS:${PN} = "v4l-utils"
|
# the update manager drives ffboot + fwup and verifies against the
|
||||||
|
# shipped keyring; release checks and downloads use curl.
|
||||||
|
RDEPENDS:${PN} = "v4l-utils ffboot fwup forgefirm-keys curl"
|
||||||
|
|
||||||
INITSCRIPT_NAME = "forgectrl"
|
INITSCRIPT_NAME = "forgectrl"
|
||||||
INITSCRIPT_PARAMS = "defaults 90"
|
INITSCRIPT_PARAMS = "defaults 90"
|
||||||
|
|||||||
@@ -0,0 +1 @@
|
|||||||
|
fHw/N5H/5tuBxjRBS2+r7RRl+ykltrFjsh04y/uFkXU=
|
||||||
@@ -0,0 +1 @@
|
|||||||
|
,md2#U…”‡>0HeáÓ!ÌqW«3éÁƒfàø¨
|
||||||
Binary file not shown.
@@ -0,0 +1 @@
|
|||||||
|
‚ùë™1)«Åˇ“qÏÿqI“,kñnB
|
||||||
@@ -0,0 +1 @@
|
|||||||
|
5x« msç�úsÍá|‚¸ßal¾íˆPð‹«éûu¾ÝÞ
|
||||||
@@ -0,0 +1 @@
|
|||||||
|
��䁮-碥]QG�����5��_�����(
|
||||||
@@ -0,0 +1 @@
|
|||||||
|
XйXgЩД-ё╟╙xP╙87╫ОМf|├z9mЗc╠1
|
||||||
@@ -0,0 +1 @@
|
|||||||
|
ラ�gユ、リp纏怪薤禹D$ら"ウ�5ォ�
|
||||||
@@ -0,0 +1 @@
|
|||||||
|
¬�©0¹³íôs·GƒôCukH€�»¸Î Å1OîZÃãŸ
|
||||||
@@ -0,0 +1 @@
|
|||||||
|
�qY\(!κςχƒο7ο1/?7}2Λ�8ς9Ϊ#ϊύ@§�
|
||||||
Binary file not shown.
@@ -0,0 +1 @@
|
|||||||
|
��tj�1�q��S��1x]f+�Bc���b7Uf�
|
||||||
@@ -0,0 +1,23 @@
|
|||||||
|
SUMMARY = "Firmware verification public keys"
|
||||||
|
DESCRIPTION = "Trust anchors for firmware archive verification: the \
|
||||||
|
ForgeFIRM release-signing public key (verifies release downloads and \
|
||||||
|
uploads) and the Glowforge factory keyring (verifies factory .fw \
|
||||||
|
archives for cloud restore). Public keys only."
|
||||||
|
LICENSE = "MIT"
|
||||||
|
LIC_FILES_CHKSUM = "file://${COMMON_LICENSE_DIR}/MIT;md5=0835ade698e0bcf8506ecda2f7b4f302"
|
||||||
|
|
||||||
|
SRC_URI = " \
|
||||||
|
file://forgefirm-release.pub \
|
||||||
|
file://gf \
|
||||||
|
"
|
||||||
|
|
||||||
|
S = "${WORKDIR}"
|
||||||
|
|
||||||
|
do_install() {
|
||||||
|
install -d ${D}${sysconfdir}/forgefirm/keys/gf
|
||||||
|
install -m 0644 ${WORKDIR}/forgefirm-release.pub \
|
||||||
|
${D}${sysconfdir}/forgefirm/keys/forgefirm-release.pub
|
||||||
|
install -m 0644 ${WORKDIR}/gf/*.pub ${D}${sysconfdir}/forgefirm/keys/gf/
|
||||||
|
}
|
||||||
|
|
||||||
|
FILES:${PN} = "${sysconfdir}/forgefirm/keys"
|
||||||
Reference in New Issue
Block a user