mail archive of the barebox mailing list
 help / color / mirror / Atom feed
* [PATCH 00/11] Documentation: define a barebox threat model
@ 2026-09-28 11:26 Ahmad Fatoum
  2026-09-28 11:26 ` [PATCH 02/11] Documentation: security: clarify development key insecurity Ahmad Fatoum
                   ` (9 more replies)
  0 siblings, 10 replies; 11+ messages in thread
From: Ahmad Fatoum @ 2026-09-28 11:26 UTC (permalink / raw)
  To: barebox; +Cc: Ahmad Fatoum

The security considerations chapter is written for integrators and
tells them what to configure.

Security researchers may not know how barebox is integrated, so let's
document what we count as a security vulnerability and what's a normal
bug.

Ahmad Fatoum (11):
  Documentation: security: unnest hardening sections from dm-verity
    section
  Documentation: security: clarify development key insecurity
  Documentation: security: require signature verification to be pinned
  Documentation: security: document trust for builtin devicetree
  Documentation: security: clarify the environment section
  Documentation: security: describe shell and environment as trust
    boundary
  Documentation: security: document the barebox update attack surface
  Documentation: security: update for barebox dm-verity support
  Documentation: security: add anchors for the different sections
  Documentation: define a barebox threat model
  README, SECURITY.md: link the threat model and security considerations

 Documentation/user/security.rst     | 189 ++++++++++++------
 Documentation/user/threat-model.rst | 297 ++++++++++++++++++++++++++++
 Documentation/user/user-manual.rst  |   1 +
 README.rst                          |  10 +
 SECURITY.md                         |   6 +
 crypto/Kconfig                      |   8 +
 6 files changed, 456 insertions(+), 55 deletions(-)
 create mode 100644 Documentation/user/threat-model.rst

-- 
2.47.3




^ permalink raw reply	[flat|nested] 11+ messages in thread

end of thread, other threads:[~2026-09-28 11:39 UTC | newest]

Thread overview: 11+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-09-28 11:26 [PATCH 00/11] Documentation: define a barebox threat model Ahmad Fatoum
2026-09-28 11:26 ` [PATCH 02/11] Documentation: security: clarify development key insecurity Ahmad Fatoum
2026-09-28 11:26 ` [PATCH 03/11] Documentation: security: require signature verification to be pinned Ahmad Fatoum
2026-09-28 11:26 ` [PATCH 04/11] Documentation: security: document trust for builtin devicetree Ahmad Fatoum
2026-09-28 11:27 ` [PATCH 05/11] Documentation: security: clarify the environment section Ahmad Fatoum
2026-09-28 11:27 ` [PATCH 06/11] Documentation: security: describe shell and environment as trust boundary Ahmad Fatoum
2026-09-28 11:27 ` [PATCH 07/11] Documentation: security: document the barebox update attack surface Ahmad Fatoum
2026-09-28 11:27 ` [PATCH 08/11] Documentation: security: update for barebox dm-verity support Ahmad Fatoum
2026-09-28 11:27 ` [PATCH 09/11] Documentation: security: add anchors for the different sections Ahmad Fatoum
2026-09-28 11:27 ` [PATCH 10/11] Documentation: define a barebox threat model Ahmad Fatoum
2026-09-28 11:27 ` [PATCH 11/11] README, SECURITY.md: link the threat model and security considerations Ahmad Fatoum

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox