[PATCH 00/11] Documentation: define a barebox threat model

Ahmad Fatoum a.fatoum at pengutronix.de
Mon Sep 28 04:26:55 PDT 2026


The security considerations chapter is written for integrators and
tells them what to configure.

Security researchers may not know how barebox is integrated, so let's
document what we count as a security vulnerability and what's a normal
bug.

Ahmad Fatoum (11):
  Documentation: security: unnest hardening sections from dm-verity
    section
  Documentation: security: clarify development key insecurity
  Documentation: security: require signature verification to be pinned
  Documentation: security: document trust for builtin devicetree
  Documentation: security: clarify the environment section
  Documentation: security: describe shell and environment as trust
    boundary
  Documentation: security: document the barebox update attack surface
  Documentation: security: update for barebox dm-verity support
  Documentation: security: add anchors for the different sections
  Documentation: define a barebox threat model
  README, SECURITY.md: link the threat model and security considerations

 Documentation/user/security.rst     | 189 ++++++++++++------
 Documentation/user/threat-model.rst | 297 ++++++++++++++++++++++++++++
 Documentation/user/user-manual.rst  |   1 +
 README.rst                          |  10 +
 SECURITY.md                         |   6 +
 crypto/Kconfig                      |   8 +
 6 files changed, 456 insertions(+), 55 deletions(-)
 create mode 100644 Documentation/user/threat-model.rst

-- 
2.47.3




More information about the barebox mailing list