#9537 BLOC 1.5-fir: Test OFW security on XO-1.5

Zarro Boogs per Child bugtracker at laptop.org
Fri Dec 11 14:56:17 EST 2009


#9537: Test OFW security on XO-1.5
-------------------------------------------+--------------------------------
           Reporter:  wmb at firmworks.com    |       Owner:  wmb at firmworks.com   
               Type:  task                 |      Status:  assigned            
           Priority:  blocker              |   Milestone:  1.5-firmware-C1-SMT 
          Component:  ofw - open firmware  |     Version:  Development firmware
         Resolution:                       |    Keywords:                      
        Next_action:  test in build        |    Verified:  0                   
Deployment_affected:                       |   Blockedby:                      
           Blocking:  9858                 |  
-------------------------------------------+--------------------------------

Comment(by reuben):

 6 types of security: All testing was done using keys generated and placed
 in the augment slot of 1 i.e. x1.

 1. OS: Signed runos.zip and runrd.zip. Signature pass and functional up to
 the point of #9867

 2. Activation: symlinked runos.zip and runrd.zip to actos.zip and
 actrd.zip. Signatures pass. DSD says:

 "it doesnt unfreeze dcon and act-gui doesnt support 24bpp framebuffer"

 Placing lease.sig in int:\security\ works correctly.

 3. Developer: Secured XO. XO does not check u:\security\develop.sig only
 int:\security\develop.sig. Removing SD card and placing develop.sig in
 int:\security\ works correctly.

 disable-security - does not work. though this may be due to my
 manipulation of tags.

 4. FS: For Secure reflash. See: #9873 and 9874

 5. FW: Downgrade to q3a18.rom. Signed q3a22a.rom to bootfw.zip. Placed in
 int:\..Rebooted Firmware updated correctly.

 6. OATS -- No idea how to test.

-- 
Ticket URL: <http://dev.laptop.org/ticket/9537#comment:10>
One Laptop Per Child <http://laptop.org/>
OLPC bug tracking system


More information about the Bugs mailing list