The security considerations chapter is written for integrators and
tells them what to configure.
Security researchers may not know how barebox is integrated, so let's
document what we count as a security vulnerability and what's a normal
bug.
Ahmad Fatoum (11):
Documentation: security: unnest hardening sections from dm-verity
section
Documentation: security: clarify development key insecurity
Documentation: security: require signature verification to be pinned
Documentation: security: document trust for builtin devicetree
Documentation: security: clarify the environment section
Documentation: security: describe shell and environment as trust
boundary
Documentation: security: document the barebox update attack surface
Documentation: security: update for barebox dm-verity support
Documentation: security: add anchors for the different sections
Documentation: define a barebox threat model
README, SECURITY.md: link the threat model and security considerations
Documentation/user/security.rst | 189 ++++++++++++------
Documentation/user/threat-model.rst | 297 ++++++++++++++++++++++++++++
Documentation/user/user-manual.rst | 1 +
README.rst | 10 +
SECURITY.md | 6 +
crypto/Kconfig | 8 +
6 files changed, 456 insertions(+), 55 deletions(-)
create mode 100644 Documentation/user/threat-model.rst
--
2.47.3