[PATCH 08/11] Documentation: security: update for barebox dm-verity support

Ahmad Fatoum a.fatoum at pengutronix.de
Mon Sep 28 04:27:03 PDT 2026


From: Ahmad Fatoum <a.fatoum at barebox.org>

We have gained dm-verity support in the meantime, so there is actually
something we can offer users that want to use file systems in a secure
manner, even though they will need to bring their own scheme on how to
discover the signed root hash.

Reflect this in the documentation.

Signed-off-by: Ahmad Fatoum <a.fatoum at barebox.org>
---
 Documentation/user/security.rst | 12 ++++++++----
 1 file changed, 8 insertions(+), 4 deletions(-)

diff --git a/Documentation/user/security.rst b/Documentation/user/security.rst
index b204e6df8d23..185adac2d51c 100644
--- a/Documentation/user/security.rst
+++ b/Documentation/user/security.rst
@@ -190,14 +190,18 @@ Avoiding use of file systems
 
 File systems are among the most complex parser code in barebox and a common
 source of bugs.
-Unlike Linux with its dm-verity support, barebox currently has no way to
-verify a file system before mounting it.
 
 The consequence is that in a verified boot setup, barebox should **never**
 be allowed to mount file systems.
-Especially, :ref:`bootloader spec files <bootloader_spec>` should not be used
+Especially, :ref:`bootloader spec files <bootloader_spec>` or
+:ref:`extlinux.conf <extlinux_conf>` should not be used
 in verified boot setups and signed FIT images **must** be located outside
-a file system and directly in a raw partition.
+a file system and directly in a raw partition and not pointed at by a plain
+unsigned file on an unsigned file system that can both be tampered with.
+
+If file system use is desired anyway, its integrity should be ensured by
+other means, e.g. by being mounted from a dm-verity block device that was
+setup with a correctly signed root hash.
 
 Prevent the kernel from booting the rootfs in verity boots
 ----------------------------------------------------------
-- 
2.47.3




More information about the barebox mailing list