[PATCH 04/11] Documentation: security: document trust for builtin devicetree
Ahmad Fatoum
a.fatoum at pengutronix.de
Mon Sep 28 04:26:59 PDT 2026
From: Ahmad Fatoum <a.fatoum at barebox.org>
barebox-dt-2nd.img exists to allow booting barebox like one would boot a
Linux kernel. This is a convenient way to use barebox without modifying
existent firmware, but it's not suitable for use as part of a boot chain
if the device tree hasn't been verified beforehand.
Spell that out in the documentations and also add the missing help text
for CONFIG_CRYPTO_BUILTIN_KEYS.
Signed-off-by: Ahmad Fatoum <a.fatoum at barebox.org>
---
Documentation/user/security.rst | 17 +++++++++++++++++
crypto/Kconfig | 8 ++++++++
2 files changed, 25 insertions(+)
diff --git a/Documentation/user/security.rst b/Documentation/user/security.rst
index 7160f8f8e3c2..d981d89268c8 100644
--- a/Documentation/user/security.rst
+++ b/Documentation/user/security.rst
@@ -56,6 +56,23 @@ fusing for both HABv4 and AHAB.
touch the subset of fuses relevant to most users. It's up to the integrators
to fuse away unneeded functionality like USB recovery or JTAG as needed.
+Ensuring the barebox devicetree is verified
+-------------------------------------------
+
+Whoever controls the devicetree barebox uses for itself can inject RSA keys
+to be used for FIT verification and control what drivers are probed.
+
+The devicetree must therefore be either:
+
+- verified by the previous boot stage before passing it to barebox
+
+- part of a barebox image and thus verified by the previous boot stage
+
+``barebox-dt-2nd.img`` is bootable like a Linux kernel and takes its
+devicetree from the previous stage. It's thus only suitable for verified
+boot if that stage verified the devicetree as well, e.g. because both are
+part of the same signed FIP image.
+
Loading firmware
----------------
diff --git a/crypto/Kconfig b/crypto/Kconfig
index 528e9a0d2204..977e502e8a14 100644
--- a/crypto/Kconfig
+++ b/crypto/Kconfig
@@ -130,6 +130,14 @@ config CRYPTO_BUILTIN_KEYS
bool "builtin keys"
select KEYTOC
select IDR
+ help
+ Compile public keys into barebox. See CRYPTO_PUBLIC_KEYS for how to
+ specify them and their keyrings.
+
+ This also enables reading RSA keys from /signature of the devicetree
+ barebox runs on, like U-Boot does with its control FDT. Such keys
+ always end up in the "fit" keyring. Prefer compiled-in keys. Either
+ way, the devicetree must be verified together with barebox.
config CRYPTO_PUBLIC_KEYS
depends on CRYPTO_BUILTIN_KEYS
--
2.47.3
More information about the barebox
mailing list