Skip to content

EBLDR_REQUIRE_SIGNATURES and EBLDR_RECOVERY_AUTH are build options that no source file reads #132

Description

@Kartikey1306

Where

CMakeLists.txt:24-25 (option(...)), CMakeLists.txt:57-62 (add_compile_definitions(...)), README.md "Security options" table, docs/book/book.md §24.1.

What

Both options are offered with default ON, each is forwarded to the compiler as a definition, and the README presents them as the switches that require Ed25519 signatures and recovery authentication. Nothing reads them:

$ git grep -n "EBLDR_REQUIRE_SIGNATURES\|EBLDR_RECOVERY_AUTH" -- '*.c' '*.h'
(no output)

Measured: configuring the same tree with -DCMAKE_C_FLAGS="-DEBLDR_REQUIRE_SIGNATURES -DEBLDR_RECOVERY_AUTH" and without produces byte-identical output for all 41 non-test object files (cmp over CMakeFiles/**/*.c.o; only the archive timestamps differ). So OFF builds the verifying bootloader too -- fail-closed by accident, but:

  • an integrator who reads CMakeCache.txt concludes that these two flags are what enforce verification; they are not, and a future toggle added "to match the option" would be a way to build a non-verifying bootloader;
  • a bring-up script that sets either OFF gets no signal that the request was ignored;
  • tests/simulate_tests.py:172-173 "verify" the defaults by checking that the option names appear in CMakeLists.txt, which holds while the switch does nothing (that script is run by no workflow and already fails 9 unrelated checks on master).

docs/book/book.md §24.1 goes further and lists EBLDR_SECURE_BOOT, EBLDR_MULTICORE, EBLDR_RECOVERY and EBLDR_BOOT_MENU as build options. None has ever existed in CMakeLists.txt.

Expected

Signature verification and recovery authentication are unconditional, and the build system and docs should say exactly that: no option that claims to disable them, a configure that refuses OFF instead of silently building the verifying firmware, doc tables that list only options that exist, and a guard so that a forwarded EBLDR_ definition nothing reads cannot come back.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions