[PATCH 07/11] Documentation: security: document the barebox update attack surface
Ahmad Fatoum
a.fatoum at pengutronix.de
Mon Sep 28 04:27:02 PDT 2026
From: Ahmad Fatoum <a.fatoum at barebox.org>
Any checks that generic barebox code currently does at update time are
meant to reduce the likelihood of bricking a board and not as a security
measure. Spell that out.
Signed-off-by: Ahmad Fatoum <a.fatoum at barebox.org>
---
Documentation/user/security.rst | 11 +++++++++++
1 file changed, 11 insertions(+)
diff --git a/Documentation/user/security.rst b/Documentation/user/security.rst
index a618c05b1102..b204e6df8d23 100644
--- a/Documentation/user/security.rst
+++ b/Documentation/user/security.rst
@@ -56,6 +56,17 @@ fusing for both HABv4 and AHAB.
touch the subset of fuses relevant to most users. It's up to the integrators
to fuse away unneeded functionality like USB recovery or JTAG as needed.
+Any verified boot setup that doesn't ensure that barebox was correctly signed
+before execution is thus fundamentally flawed. A corollary to this is that
+it's not enough to restrict the ways that barebox can be updated: An attacker
+can often overwrite barebox without its knowledge, via physical access or
+after having booted into the OS. barebox's signature being validated by the
+previous boot stage is thus paramount.
+
+Specifically, the checks :ref:`barebox update <update>` performs on an image,
+e.g. that it targets the right board, exist to reduce the risk of bricking
+the board and can be skipped with ``-f``. They are not a security measure.
+
Ensuring the barebox devicetree is verified
-------------------------------------------
--
2.47.3
More information about the barebox
mailing list