mirror of
https://github.com/openglow-org/forgefirm.git
synced 2026-09-27 16:51:12 -07:00
Keep debug-tweaks out of release images; harden the installer
- Move the passwordless-root debug-tweaks image feature out of the shared kas config into forgefirm-image-dev.bb, so the release forgefirm-image built from the same config is not passwordless-root. release.sh gains a gate that reads the built rootfs /etc/shadow and fails on an empty root password, plus a config-level guard that debug-tweaks is not present in the resolved kas dump. (B-1) - The installer copies ffboot out of the signature-verified new rootfs it already mounts, instead of fetching and executing it from a mutable GitHub raw ref. (B-2) - Record audit remediation Phase 2 (GATE B) status in BRINGUP.md, including the bench pass still required to close the gate.
This commit is contained in:
@@ -17,7 +17,6 @@
|
||||
# With no argument the latest release .fw is downloaded from GitHub.
|
||||
|
||||
RELEASE_FW_URL="https://github.com/ScottW514/forgefirm/releases/latest/download/forgefirm.fw"
|
||||
FFBOOT_URL="https://raw.githubusercontent.com/ScottW514/forgefirm/master/scripts/ffboot"
|
||||
ARCHIVE_DIR="/data/forgefirm/archive"
|
||||
FW_FILE="/data/forgefirm/forgefirm.fw"
|
||||
MIN_DATA_FREE_KB=300000
|
||||
@@ -281,20 +280,22 @@ mount -o ro -t ext4 "/dev/mmcblk2p$TARGET" "$MP" || die "new rootfs does not mou
|
||||
NEWVER=$(cat "$MP/etc/forgefirm-version" 2>/dev/null)
|
||||
[ -n "$NEWVER" ] || { umount "$MP"; die "new rootfs has no ForgeFIRM version stamp"; }
|
||||
[ -f "$MP/boot/zImage" ] || { umount "$MP"; die "new rootfs has no kernel"; }
|
||||
|
||||
# Take ffboot (the factory-side boot-slot tool) from the rootfs we just
|
||||
# signature-verified and mounted read-only - never fetch+exec it from a
|
||||
# mutable network ref, which would be an unverified code path in an
|
||||
# otherwise signature-gated install.
|
||||
[ -s "$MP/usr/sbin/ffboot" ] \
|
||||
|| { umount "$MP"; die "new rootfs does not contain /usr/sbin/ffboot"; }
|
||||
cp "$MP/usr/sbin/ffboot" /data/ffboot.new \
|
||||
|| { umount "$MP"; die "cannot copy ffboot out of the new rootfs"; }
|
||||
|
||||
umount "$MP"
|
||||
rmdir "$MP" 2>/dev/null
|
||||
echo -e "${ASTERISK}Slot $TARGET now holds ForgeFIRM $NEWVER"
|
||||
|
||||
# --- ffboot for the factory side ----------------------------------------------
|
||||
if curl -fL "$FFBOOT_URL" --output /data/ffboot.new 2>/dev/null \
|
||||
&& [ -s /data/ffboot.new ]; then
|
||||
mv /data/ffboot.new /data/ffboot
|
||||
else
|
||||
rm -f /data/ffboot.new
|
||||
[ -x /data/ffboot ] \
|
||||
|| die "ffboot download failed and no /data/ffboot is present"
|
||||
echo -e "${ASTERISK}ffboot download failed; keeping the existing /data/ffboot"
|
||||
fi
|
||||
mv /data/ffboot.new /data/ffboot
|
||||
chmod +x /data/ffboot
|
||||
|
||||
# --- flip the boot selection --------------------------------------------------
|
||||
|
||||
@@ -131,6 +131,25 @@ STAMP=$(debugfs -R "cat /etc/forgefirm-version" "$EXT4" 2>/dev/null)
|
||||
[ "$STAMP" = "v$VERSION" ] \
|
||||
|| die "rootfs stamp is '$STAMP', expected 'v$VERSION'"
|
||||
|
||||
# Back-door gate: the release image must not ship a passwordless root. A
|
||||
# debug-tweaks image sets root's password field empty (root::...); a
|
||||
# hardened image leaves it locked (root:*: / root:!:) or hashed. Read the
|
||||
# actual built shadow file - this catches the flag however it slipped in
|
||||
# (recipe, local.conf, an inherited class).
|
||||
ROOT_PW=$(debugfs -R "cat /etc/shadow" "$EXT4" 2>/dev/null \
|
||||
| awk -F: '$1=="root"{print $2; exit}')
|
||||
[ -n "$ROOT_PW" ] \
|
||||
|| die "release rootfs has a passwordless root (debug-tweaks leaked into forgefirm-image?)"
|
||||
echo "root login gate OK (root password field is not empty)"
|
||||
|
||||
# Config-level guard: debug-tweaks must not sit in the shared kas config,
|
||||
# where it would apply to every target including the release image.
|
||||
if ( cd "$REPO" && kas dump kas/forgefirm-glowforge.yml 2>/dev/null ) \
|
||||
| grep -q 'debug-tweaks'; then
|
||||
die "debug-tweaks appears in the resolved kas config - it must live only in forgefirm-image-dev.bb"
|
||||
fi
|
||||
echo "kas config gate OK (no debug-tweaks in the shared config)"
|
||||
|
||||
echo "== pack + sign =="
|
||||
STAGE="${RELEASE_STAGING_DIR:-$REPO/release-staging}/v$VERSION"
|
||||
mkdir -p "$STAGE"
|
||||
|
||||
Reference in New Issue
Block a user