Re: [v3,0/3] boot: fit: authenticate the dm-verity roothash

Daniel Golle <[email protected]>
Newsgroups gmane.comp.boot-loaders.u-boot
Message-ID <[email protected]>
On Tue, Jul 28, 2026 at 12:45:38PM -0600, Simon Glass wrote:
> Hi Daniel,
> 
> On 2026-07-21T02:34:47, Daniel Golle <[email protected]> wrote:
> 
> > v3: address comments by Simon Glass
> 
> Thanks for the rework - the doc additions in signature.rst and
> dm-verity.rst read well, and the test fix is a good catch.
> 
> I still think we should state the compatibility break explicitly
> somehow: because U-Boot rebuilds the node list rather than trusting
> hashed-nodes, an image signed by an older mkimage that carries a
> dm-verity subnode stops verifying under this fix, and an image signed
> by the new mkimage does not verify on an older U-Boot.
> 
> The new language in dm-verity.rst documents the security property (the
> roothash can no longer be swapped out), but it doesn't warn that
> deployed images must be re-signed after upgrading and that mixed
> old/new fleets need care.
> 
> The break is unavoidable I think and I may be overthinking all this,
> but it would be nice to avoid people getting confused.

Technically you are right, there could be, but I strongly believe
there aren't any "deployments" of this right now.

The whole mechanism is built in order to be deployed as part of the
**upcoming** OpenWrt bootstd method. As of today, there aren't
currently any deployments using dm-verity on OpenWrt with this
mechanism (apart from some boards on my desk at least, and people
who have tried the PoC[1] -- which is/was a PoC and obviously subject
to changes as part of upstream review and standartization)

[1]: https://github.com/openwrt/openwrt/pull/22177
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.