[PATCH 00/11] Documentation: define a barebox threat model
Ahmad Fatoum
a.fatoum at pengutronix.de
Mon Sep 28 04:26:55 PDT 2026
The security considerations chapter is written for integrators and
tells them what to configure.
Security researchers may not know how barebox is integrated, so let's
document what we count as a security vulnerability and what's a normal
bug.
Ahmad Fatoum (11):
Documentation: security: unnest hardening sections from dm-verity
section
Documentation: security: clarify development key insecurity
Documentation: security: require signature verification to be pinned
Documentation: security: document trust for builtin devicetree
Documentation: security: clarify the environment section
Documentation: security: describe shell and environment as trust
boundary
Documentation: security: document the barebox update attack surface
Documentation: security: update for barebox dm-verity support
Documentation: security: add anchors for the different sections
Documentation: define a barebox threat model
README, SECURITY.md: link the threat model and security considerations
Documentation/user/security.rst | 189 ++++++++++++------
Documentation/user/threat-model.rst | 297 ++++++++++++++++++++++++++++
Documentation/user/user-manual.rst | 1 +
README.rst | 10 +
SECURITY.md | 6 +
crypto/Kconfig | 8 +
6 files changed, 456 insertions(+), 55 deletions(-)
create mode 100644 Documentation/user/threat-model.rst
--
2.47.3
More information about the barebox
mailing list