On Tue, Jul 14, 2026 at 03:33:23AM +0100, Daniel Golle wrote: > A signed FIT configuration can delegate the integrity of a (potentially > large) root filesystem image to the kernel's dm-verity instead of having > U-Boot hash the whole payload at boot: the FIT carries a "dm-verity" > subnode with the roothash, salt and block parameters, U-Boot passes the > roothash to Linux through the dm-mod.create bootargs, and dm-verity then > validates the filesystem block by block against it. > > For that to be safe the roothash has to be trusted, and in a signed > configuration the only thing that establishes trust is the configuration > signature. The roothash was not covered by it. fit_config_add_hash() > collected the image node, its hash subnodes and its cipher subnode into > the signed region, but not the dm-verity subnode, so the roothash, the > sole integrity anchor for the filesystem, was left unsigned. > > The result is a verified-boot bypass for the root filesystem: an > attacker who can rewrite the boot medium can replace the filesystem, > recompute a matching dm-verity tree, write the new roothash into the > unsigned dm-verity subnode, and the configuration signature still > verifies. dm-verity then faithfully validates the malicious filesystem > against the attacker's roothash.
This fails in CI: https://git.u-boot-project.org/u-boot/u-boot/-/jobs/50414 I've just made you a contributor area, so at least pushing this through CI until it works will be easier now. -- Tom
signature.asc
Description: PGP signature
