Files
forgefirm/meta-forgefirm/recipes-forgefirm/forgefirm-keys/forgefirm-keys.bb
T
ScottW514 5ad7ee6faa forgeext: the recipe, and the extension-signing key in the keyring
forgeext is the extension host, a component of its own: recipe
recipes-forgefirm/forgeext (cmake, pkgconfig, forgefirm-manifest, so it is
a manifest component with its own pin file). It links jansson, libarchive,
and libsodium, and runs with fwup, the keyring, and forgefirm-sandbox.
libarchive and jansson are on the image already; libsodium comes with it.
The pin is all zeros because the repository has no pushed commit to name:
the recipe builds from a working tree through externalsrc, and a build
from pins cannot fetch it until the first push sets the pin. It is not in
the image's install list.

forgefirm-keys installs a third trust anchor,
/etc/forgefirm/keys/ext/forgefirm-ext.pub: the OpenGlow extension-signing
public key, the official tier of extension packages. It is a different key
from the release key on purpose: it signs more often, and its loss must
not sign firmware. forgeext refuses an extension archive whose only valid
signature is the release key's or a factory key's.

Proven. The recipe cross-builds forgeext from the working tree, and that
binary ran the verify-and-install cases on the bench reference (image
20260920211625, from /tmp, with the board's own fwup 1.16.0 and the
image's keyring) with the results of the host test. forgefirm-keys builds
and packages the key 0644 under ext/ (0755), byte-identical to the file
here; it is 32 key bytes and is not the release key.

Acceptance. No catalog test reads either yet: forgeext's tests are the
exthost suite that comes with its daemon, and the key is layer content, in
the platform identity of every fingerprint.
2026-09-20 19:34:45 -04:00

38 lines
1.6 KiB
BlitzBasic

# SPDX-License-Identifier: MIT
SUMMARY = "Firmware and extension verification public keys"
DESCRIPTION = "Trust anchors for archive verification: the ForgeFIRM \
release-signing public key (verifies release downloads and uploads), the \
Glowforge factory keyring (verifies factory .fw archives for cloud \
restore), and the OpenGlow extension-signing public key (the official \
tier of extension packages). Public keys only."
# LICENSE covers this recipe, not the key material. The Glowforge factory
# keyring in files/gf/ is Glowforge, Inc.'s: bare Ed25519 public keys, in which
# no copyright subsists and over which OpenGlow claims nothing and grants
# nothing. files/gf/README records that and the public-key-only boundary.
LICENSE = "MIT"
LIC_FILES_CHKSUM = "file://${COMMON_LICENSE_DIR}/MIT;md5=0835ade698e0bcf8506ecda2f7b4f302"
# The extension key is a different key from the release key on purpose: it
# signs more often, and its loss must not sign firmware. forgeext refuses an
# extension archive whose only valid signature is one of the two above.
SRC_URI = " \
file://forgefirm-release.pub \
file://gf \
file://ext/forgefirm-ext.pub \
"
S = "${WORKDIR}"
do_install() {
install -d ${D}${sysconfdir}/forgefirm/keys/gf
install -m 0644 ${WORKDIR}/forgefirm-release.pub \
${D}${sysconfdir}/forgefirm/keys/forgefirm-release.pub
install -m 0644 ${WORKDIR}/gf/*.pub ${D}${sysconfdir}/forgefirm/keys/gf/
install -d ${D}${sysconfdir}/forgefirm/keys/ext
install -m 0644 ${WORKDIR}/ext/forgefirm-ext.pub \
${D}${sysconfdir}/forgefirm/keys/ext/forgefirm-ext.pub
}
FILES:${PN} = "${sysconfdir}/forgefirm/keys"