mirror of
https://github.com/openglow-org/forgefirm.git
synced 2026-09-28 01:01:12 -07:00
forgeext is the extension host, a component of its own: recipe recipes-forgefirm/forgeext (cmake, pkgconfig, forgefirm-manifest, so it is a manifest component with its own pin file). It links jansson, libarchive, and libsodium, and runs with fwup, the keyring, and forgefirm-sandbox. libarchive and jansson are on the image already; libsodium comes with it. The pin is all zeros because the repository has no pushed commit to name: the recipe builds from a working tree through externalsrc, and a build from pins cannot fetch it until the first push sets the pin. It is not in the image's install list. forgefirm-keys installs a third trust anchor, /etc/forgefirm/keys/ext/forgefirm-ext.pub: the OpenGlow extension-signing public key, the official tier of extension packages. It is a different key from the release key on purpose: it signs more often, and its loss must not sign firmware. forgeext refuses an extension archive whose only valid signature is the release key's or a factory key's. Proven. The recipe cross-builds forgeext from the working tree, and that binary ran the verify-and-install cases on the bench reference (image 20260920211625, from /tmp, with the board's own fwup 1.16.0 and the image's keyring) with the results of the host test. forgefirm-keys builds and packages the key 0644 under ext/ (0755), byte-identical to the file here; it is 32 key bytes and is not the release key. Acceptance. No catalog test reads either yet: forgeext's tests are the exthost suite that comes with its daemon, and the key is layer content, in the platform identity of every fingerprint.
38 lines
1.6 KiB
BlitzBasic
38 lines
1.6 KiB
BlitzBasic
# SPDX-License-Identifier: MIT
|
|
|
|
SUMMARY = "Firmware and extension verification public keys"
|
|
DESCRIPTION = "Trust anchors for archive verification: the ForgeFIRM \
|
|
release-signing public key (verifies release downloads and uploads), the \
|
|
Glowforge factory keyring (verifies factory .fw archives for cloud \
|
|
restore), and the OpenGlow extension-signing public key (the official \
|
|
tier of extension packages). Public keys only."
|
|
# LICENSE covers this recipe, not the key material. The Glowforge factory
|
|
# keyring in files/gf/ is Glowforge, Inc.'s: bare Ed25519 public keys, in which
|
|
# no copyright subsists and over which OpenGlow claims nothing and grants
|
|
# nothing. files/gf/README records that and the public-key-only boundary.
|
|
LICENSE = "MIT"
|
|
LIC_FILES_CHKSUM = "file://${COMMON_LICENSE_DIR}/MIT;md5=0835ade698e0bcf8506ecda2f7b4f302"
|
|
|
|
# The extension key is a different key from the release key on purpose: it
|
|
# signs more often, and its loss must not sign firmware. forgeext refuses an
|
|
# extension archive whose only valid signature is one of the two above.
|
|
SRC_URI = " \
|
|
file://forgefirm-release.pub \
|
|
file://gf \
|
|
file://ext/forgefirm-ext.pub \
|
|
"
|
|
|
|
S = "${WORKDIR}"
|
|
|
|
do_install() {
|
|
install -d ${D}${sysconfdir}/forgefirm/keys/gf
|
|
install -m 0644 ${WORKDIR}/forgefirm-release.pub \
|
|
${D}${sysconfdir}/forgefirm/keys/forgefirm-release.pub
|
|
install -m 0644 ${WORKDIR}/gf/*.pub ${D}${sysconfdir}/forgefirm/keys/gf/
|
|
install -d ${D}${sysconfdir}/forgefirm/keys/ext
|
|
install -m 0644 ${WORKDIR}/ext/forgefirm-ext.pub \
|
|
${D}${sysconfdir}/forgefirm/keys/ext/forgefirm-ext.pub
|
|
}
|
|
|
|
FILES:${PN} = "${sysconfdir}/forgefirm/keys"
|