On Tue, Jul 14, 2026 at 03:33:23AM +0100, Daniel Golle wrote:

> A signed FIT configuration can delegate the integrity of a (potentially
> large) root filesystem image to the kernel's dm-verity instead of having
> U-Boot hash the whole payload at boot: the FIT carries a "dm-verity"
> subnode with the roothash, salt and block parameters, U-Boot passes the
> roothash to Linux through the dm-mod.create bootargs, and dm-verity then
> validates the filesystem block by block against it.
> 
> For that to be safe the roothash has to be trusted, and in a signed
> configuration the only thing that establishes trust is the configuration
> signature. The roothash was not covered by it. fit_config_add_hash()
> collected the image node, its hash subnodes and its cipher subnode into
> the signed region, but not the dm-verity subnode, so the roothash, the
> sole integrity anchor for the filesystem, was left unsigned.
> 
> The result is a verified-boot bypass for the root filesystem: an
> attacker who can rewrite the boot medium can replace the filesystem,
> recompute a matching dm-verity tree, write the new roothash into the
> unsigned dm-verity subnode, and the configuration signature still
> verifies. dm-verity then faithfully validates the malicious filesystem
> against the attacker's roothash.

This fails in CI:
https://git.u-boot-project.org/u-boot/u-boot/-/jobs/50414

I've just made you a contributor area, so at least pushing this through
CI until it works will be easier now.

-- 
Tom

Attachment: signature.asc
Description: PGP signature

Reply via email to