Keep debug-tweaks out of release images; harden the installer

- Move the passwordless-root debug-tweaks image feature out of the
  shared kas config into forgefirm-image-dev.bb, so the release
  forgefirm-image built from the same config is not passwordless-root.
  release.sh gains a gate that reads the built rootfs /etc/shadow and
  fails on an empty root password, plus a config-level guard that
  debug-tweaks is not present in the resolved kas dump. (B-1)
- The installer copies ffboot out of the signature-verified new rootfs
  it already mounts, instead of fetching and executing it from a mutable
  GitHub raw ref. (B-2)
- Record audit remediation Phase 2 (GATE B) status in BRINGUP.md,
  including the bench pass still required to close the gate.
This commit is contained in:
ScottW514
2026-08-14 16:20:02 -04:00
parent cc927aca5f
commit e9443a60ef
5 changed files with 86 additions and 21 deletions
@@ -8,8 +8,12 @@ IMAGE_INSTALL += " \
forgectrl \
"
# debug-tweaks (passwordless root, root SSH login) belongs ONLY to the dev
# image - never the release image. It lives here, not in the shared kas
# local.conf, so the release forgefirm-image cannot inherit it.
IMAGE_FEATURES += " \
tools-debug \
debug-tweaks \
"
# Dev images boot from SD, never from a 200 MiB eMMC slot: lift the slot