[PATCH 05/11] Documentation: security: clarify the environment section
Ahmad Fatoum
a.fatoum at pengutronix.de
Mon Sep 28 04:27:00 PDT 2026
From: Ahmad Fatoum <a.fatoum at barebox.org>
CONFIG_ENV_HANDLING can be problematic, even when the environment isn't
mutable, i.e. it's simply read from external unauthenticated storage.
Clarify that in the docs.
Signed-off-by: Ahmad Fatoum <a.fatoum at barebox.org>
---
Documentation/user/security.rst | 7 ++++---
1 file changed, 4 insertions(+), 3 deletions(-)
diff --git a/Documentation/user/security.rst b/Documentation/user/security.rst
index d981d89268c8..9a241b0e2e8d 100644
--- a/Documentation/user/security.rst
+++ b/Documentation/user/security.rst
@@ -140,13 +140,14 @@ In addition, there are alternative methods of accessing the shell like
netconsole, or fastboot. These should preferably be disabled or at least
not activated by default.
-Disabling mutable environment handling
-^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
+Disabling the non-builtin environment
+^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
Anything done interactively by the shell can also be done automatically by
means of init scripts in the environment. Even without shell support, the
non-volatile variables in the environment could be used to reconfigure
-barebox in an insecure manner.
+barebox in an insecure manner or to influence the command line and device
+tree passed to the kernel on boot.
A secure barebox should thus only consult the environment that it has built
in and not parse an externally located environment.
--
2.47.3
More information about the barebox
mailing list