From: Ahmad Fatoum <[email protected]> CONFIG_ENV_HANDLING can be problematic, even when the environment isn't mutable, i.e. it's simply read from external unauthenticated storage.
Clarify that in the docs. Signed-off-by: Ahmad Fatoum <[email protected]> --- Documentation/user/security.rst | 7 ++++--- 1 file changed, 4 insertions(+), 3 deletions(-) diff --git a/Documentation/user/security.rst b/Documentation/user/security.rst index d981d89268c8..9a241b0e2e8d 100644 --- a/Documentation/user/security.rst +++ b/Documentation/user/security.rst @@ -140,13 +140,14 @@ In addition, there are alternative methods of accessing the shell like netconsole, or fastboot. These should preferably be disabled or at least not activated by default. -Disabling mutable environment handling -^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ +Disabling the non-builtin environment +^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ Anything done interactively by the shell can also be done automatically by means of init scripts in the environment. Even without shell support, the non-volatile variables in the environment could be used to reconfigure -barebox in an insecure manner. +barebox in an insecure manner or to influence the command line and device +tree passed to the kernel on boot. A secure barebox should thus only consult the environment that it has built in and not parse an externally located environment. -- 2.47.3
