mirror of
https://github.com/openglow-org/forgefirm.git
synced 2026-09-27 16:51:12 -07:00
Keep debug-tweaks out of release images; harden the installer
- Move the passwordless-root debug-tweaks image feature out of the shared kas config into forgefirm-image-dev.bb, so the release forgefirm-image built from the same config is not passwordless-root. release.sh gains a gate that reads the built rootfs /etc/shadow and fails on an empty root password, plus a config-level guard that debug-tweaks is not present in the resolved kas dump. (B-1) - The installer copies ffboot out of the signature-verified new rootfs it already mounts, instead of fetching and executing it from a mutable GitHub raw ref. (B-2) - Record audit remediation Phase 2 (GATE B) status in BRINGUP.md, including the bench pass still required to close the gate.
This commit is contained in:
@@ -131,6 +131,25 @@ STAMP=$(debugfs -R "cat /etc/forgefirm-version" "$EXT4" 2>/dev/null)
|
||||
[ "$STAMP" = "v$VERSION" ] \
|
||||
|| die "rootfs stamp is '$STAMP', expected 'v$VERSION'"
|
||||
|
||||
# Back-door gate: the release image must not ship a passwordless root. A
|
||||
# debug-tweaks image sets root's password field empty (root::...); a
|
||||
# hardened image leaves it locked (root:*: / root:!:) or hashed. Read the
|
||||
# actual built shadow file - this catches the flag however it slipped in
|
||||
# (recipe, local.conf, an inherited class).
|
||||
ROOT_PW=$(debugfs -R "cat /etc/shadow" "$EXT4" 2>/dev/null \
|
||||
| awk -F: '$1=="root"{print $2; exit}')
|
||||
[ -n "$ROOT_PW" ] \
|
||||
|| die "release rootfs has a passwordless root (debug-tweaks leaked into forgefirm-image?)"
|
||||
echo "root login gate OK (root password field is not empty)"
|
||||
|
||||
# Config-level guard: debug-tweaks must not sit in the shared kas config,
|
||||
# where it would apply to every target including the release image.
|
||||
if ( cd "$REPO" && kas dump kas/forgefirm-glowforge.yml 2>/dev/null ) \
|
||||
| grep -q 'debug-tweaks'; then
|
||||
die "debug-tweaks appears in the resolved kas config - it must live only in forgefirm-image-dev.bb"
|
||||
fi
|
||||
echo "kas config gate OK (no debug-tweaks in the shared config)"
|
||||
|
||||
echo "== pack + sign =="
|
||||
STAGE="${RELEASE_STAGING_DIR:-$REPO/release-staging}/v$VERSION"
|
||||
mkdir -p "$STAGE"
|
||||
|
||||
Reference in New Issue
Block a user