[PATCH 05/11] Documentation: security: clarify the environment section

Ahmad Fatoum a.fatoum at pengutronix.de
Mon Sep 28 04:27:00 PDT 2026


From: Ahmad Fatoum <a.fatoum at barebox.org>

CONFIG_ENV_HANDLING can be problematic, even when the environment isn't
mutable, i.e. it's simply read from external unauthenticated storage.

Clarify that in the docs.

Signed-off-by: Ahmad Fatoum <a.fatoum at barebox.org>
---
 Documentation/user/security.rst | 7 ++++---
 1 file changed, 4 insertions(+), 3 deletions(-)

diff --git a/Documentation/user/security.rst b/Documentation/user/security.rst
index d981d89268c8..9a241b0e2e8d 100644
--- a/Documentation/user/security.rst
+++ b/Documentation/user/security.rst
@@ -140,13 +140,14 @@ In addition, there are alternative methods of accessing the shell like
 netconsole, or fastboot. These should preferably be disabled or at least
 not activated by default.
 
-Disabling mutable environment handling
-^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
+Disabling the non-builtin environment
+^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
 
 Anything done interactively by the shell can also be done automatically by
 means of init scripts in the environment. Even without shell support, the
 non-volatile variables in the environment could be used to reconfigure
-barebox in an insecure manner.
+barebox in an insecure manner or to influence the command line and device
+tree passed to the kernel on boot.
 
 A secure barebox should thus only consult the environment that it has built
 in and not parse an externally located environment.
-- 
2.47.3




More information about the barebox mailing list