|
| 1 | +- commits: |
| 2 | + - subject: Update layers/meta-balena to 3033e1adebd2ec79f9528e83d616ccf27bee4035 |
| 3 | + hash: 7f29d80122b2727bb7d3dd8240f6797190e55494 |
| 4 | + body: Update layers/meta-balena |
| 5 | + footer: |
| 6 | + Changelog-entry: Update layers/meta-balena to 3033e1adebd2ec79f9528e83d616ccf27bee4035 |
| 7 | + changelog-entry: Update layers/meta-balena to 3033e1adebd2ec79f9528e83d616ccf27bee4035 |
| 8 | + author: balena-renovate[bot] |
| 9 | + nested: |
| 10 | + - commits: |
| 11 | + - subject: "resin-init-flasher: with secure boot, authenticate the inner image" |
| 12 | + hash: 1ae37ac158b93df836126030abec8c3d3f69d92b |
| 13 | + body: > |
| 14 | + At this moment resin-init-flasher just takes whatever image lies |
| 15 | + in /opt |
| 16 | + |
| 17 | + and dd's it to the target drive. This is fine for general use, |
| 18 | + but with |
| 19 | + |
| 20 | + secure boot enabled, we want to perform at least basic |
| 21 | + authentication |
| 22 | + |
| 23 | + of the image being written. |
| 24 | + |
| 25 | + |
| 26 | + This patch gets the image signed at build time and makes flasher |
| 27 | + verify |
| 28 | + |
| 29 | + the signature against a key built-in the kernel trust store. At |
| 30 | + this |
| 31 | + |
| 32 | + very moment it fails hard if the signature does not match, but |
| 33 | + this may |
| 34 | + |
| 35 | + change in the future. Technically we only want to know if we are |
| 36 | + about |
| 37 | + |
| 38 | + to flash a balena-provided image or not, we might want to |
| 39 | + support both |
| 40 | + |
| 41 | + but behave slightly differently in each scenario. |
| 42 | + footer: |
| 43 | + Change-type: minor |
| 44 | + change-type: minor |
| 45 | + Signed-off-by: Michal Toman <michalt@balena.io> |
| 46 | + signed-off-by: Michal Toman <michalt@balena.io> |
| 47 | + author: Michal Toman |
| 48 | + nested: [] |
| 49 | + version: meta-balena-6.2.0 |
| 50 | + title: "" |
| 51 | + date: 2024-12-16T14:06:35.499Z |
| 52 | + version: 6.2.0 |
| 53 | + title: "" |
| 54 | + date: 2024-12-18T11:02:37.924Z |
1 | 55 | - commits:
|
2 | 56 | - subject: Update contracts to 9ce0ad766c4f9b46cd78462813ff01600a61cde5
|
3 | 57 | hash: d34f26fa2689f577acdfd699486a84dbdca87668
|
|
0 commit comments