The security considerations chapter is written for integrators and
tells them what to configure.

Security researchers may not know how barebox is integrated, so let's
document what we count as a security vulnerability and what's a normal
bug.

Ahmad Fatoum (11):
  Documentation: security: unnest hardening sections from dm-verity
    section
  Documentation: security: clarify development key insecurity
  Documentation: security: require signature verification to be pinned
  Documentation: security: document trust for builtin devicetree
  Documentation: security: clarify the environment section
  Documentation: security: describe shell and environment as trust
    boundary
  Documentation: security: document the barebox update attack surface
  Documentation: security: update for barebox dm-verity support
  Documentation: security: add anchors for the different sections
  Documentation: define a barebox threat model
  README, SECURITY.md: link the threat model and security considerations

 Documentation/user/security.rst     | 189 ++++++++++++------
 Documentation/user/threat-model.rst | 297 ++++++++++++++++++++++++++++
 Documentation/user/user-manual.rst  |   1 +
 README.rst                          |  10 +
 SECURITY.md                         |   6 +
 crypto/Kconfig                      |   8 +
 6 files changed, 456 insertions(+), 55 deletions(-)
 create mode 100644 Documentation/user/threat-model.rst

-- 
2.47.3


Reply via email to