Keep debug-tweaks out of release images; harden the installer

- Move the passwordless-root debug-tweaks image feature out of the
  shared kas config into forgefirm-image-dev.bb, so the release
  forgefirm-image built from the same config is not passwordless-root.
  release.sh gains a gate that reads the built rootfs /etc/shadow and
  fails on an empty root password, plus a config-level guard that
  debug-tweaks is not present in the resolved kas dump. (B-1)
- The installer copies ffboot out of the signature-verified new rootfs
  it already mounts, instead of fetching and executing it from a mutable
  GitHub raw ref. (B-2)
- Record audit remediation Phase 2 (GATE B) status in BRINGUP.md,
  including the bench pass still required to close the gate.
This commit is contained in:
ScottW514
2026-08-14 16:20:02 -04:00
parent cc927aca5f
commit e9443a60ef
5 changed files with 86 additions and 21 deletions
+11 -10
View File
@@ -17,7 +17,6 @@
# With no argument the latest release .fw is downloaded from GitHub.
RELEASE_FW_URL="https://github.com/ScottW514/forgefirm/releases/latest/download/forgefirm.fw"
FFBOOT_URL="https://raw.githubusercontent.com/ScottW514/forgefirm/master/scripts/ffboot"
ARCHIVE_DIR="/data/forgefirm/archive"
FW_FILE="/data/forgefirm/forgefirm.fw"
MIN_DATA_FREE_KB=300000
@@ -281,20 +280,22 @@ mount -o ro -t ext4 "/dev/mmcblk2p$TARGET" "$MP" || die "new rootfs does not mou
NEWVER=$(cat "$MP/etc/forgefirm-version" 2>/dev/null)
[ -n "$NEWVER" ] || { umount "$MP"; die "new rootfs has no ForgeFIRM version stamp"; }
[ -f "$MP/boot/zImage" ] || { umount "$MP"; die "new rootfs has no kernel"; }
# Take ffboot (the factory-side boot-slot tool) from the rootfs we just
# signature-verified and mounted read-only - never fetch+exec it from a
# mutable network ref, which would be an unverified code path in an
# otherwise signature-gated install.
[ -s "$MP/usr/sbin/ffboot" ] \
|| { umount "$MP"; die "new rootfs does not contain /usr/sbin/ffboot"; }
cp "$MP/usr/sbin/ffboot" /data/ffboot.new \
|| { umount "$MP"; die "cannot copy ffboot out of the new rootfs"; }
umount "$MP"
rmdir "$MP" 2>/dev/null
echo -e "${ASTERISK}Slot $TARGET now holds ForgeFIRM $NEWVER"
# --- ffboot for the factory side ----------------------------------------------
if curl -fL "$FFBOOT_URL" --output /data/ffboot.new 2>/dev/null \
&& [ -s /data/ffboot.new ]; then
mv /data/ffboot.new /data/ffboot
else
rm -f /data/ffboot.new
[ -x /data/ffboot ] \
|| die "ffboot download failed and no /data/ffboot is present"
echo -e "${ASTERISK}ffboot download failed; keeping the existing /data/ffboot"
fi
mv /data/ffboot.new /data/ffboot
chmod +x /data/ffboot
# --- flip the boot selection --------------------------------------------------
+19
View File
@@ -131,6 +131,25 @@ STAMP=$(debugfs -R "cat /etc/forgefirm-version" "$EXT4" 2>/dev/null)
[ "$STAMP" = "v$VERSION" ] \
|| die "rootfs stamp is '$STAMP', expected 'v$VERSION'"
# Back-door gate: the release image must not ship a passwordless root. A
# debug-tweaks image sets root's password field empty (root::...); a
# hardened image leaves it locked (root:*: / root:!:) or hashed. Read the
# actual built shadow file - this catches the flag however it slipped in
# (recipe, local.conf, an inherited class).
ROOT_PW=$(debugfs -R "cat /etc/shadow" "$EXT4" 2>/dev/null \
| awk -F: '$1=="root"{print $2; exit}')
[ -n "$ROOT_PW" ] \
|| die "release rootfs has a passwordless root (debug-tweaks leaked into forgefirm-image?)"
echo "root login gate OK (root password field is not empty)"
# Config-level guard: debug-tweaks must not sit in the shared kas config,
# where it would apply to every target including the release image.
if ( cd "$REPO" && kas dump kas/forgefirm-glowforge.yml 2>/dev/null ) \
| grep -q 'debug-tweaks'; then
die "debug-tweaks appears in the resolved kas config - it must live only in forgefirm-image-dev.bb"
fi
echo "kas config gate OK (no debug-tweaks in the shared config)"
echo "== pack + sign =="
STAGE="${RELEASE_STAGING_DIR:-$REPO/release-staging}/v$VERSION"
mkdir -p "$STAGE"