Opened 5 years ago

Closed 4 years ago

#9434 closed defect (fixed)

XO-1: nbclone to secure XO possible

Reported by: reuben Owned by: wmb@…
Priority: normal Milestone: 1-firmware-security
Component: ofw - open firmware Version: not specified
Keywords: nandblast Cc: martin
Blocked By: Blocking:
Deployments affected: Action Needed: no action
Verified: no

Description

"If the system is secure, the sender must be sending a signed image; otherwise the receiver will stop before writing to it NAND, saying "Placement spec bad signature!"."

From: http://wiki.laptop.org/go/Multicast_NAND_FLASH_Update#..._with_Game_Buttons

Q2E41 on sender and receiver.

Steps taken:
Create USB Stick: gg802-1img and fs.zip
Flash XO (sender).
Make changes on XO(sender).
On XO sender with USB key inserted get to OFW prompt: run nbclone
On XO receiver initiate nandblast using 4 Games Keys.

Receiver successfully receives cloned nand. No error message received.

Change History (8)

comment:1 Changed 5 years ago by wmb@…

  • Status changed from new to assigned

Fixed by svn 1295. The fix will appear in Q2E42.

comment:2 Changed 5 years ago by wmb@…

The correct fix requires svn 1346.

comment:3 Changed 5 years ago by wmb@…

  • Action Needed changed from review to add to release
  • Milestone Not Triaged deleted

comment:4 Changed 5 years ago by wmb@…

  • Summary changed from nbclone to secure XO possible to XO-1: nbclone to secure XO possible

comment:5 Changed 5 years ago by wmb@…

  • Milestone set to Future Release

comment:6 Changed 5 years ago by wmb@…

  • Milestone changed from Future Release to 1.0-firmware-security

comment:7 Changed 5 years ago by wmb@…

  • Action Needed changed from add to release to test in release

Test in Q2E42.

comment:8 Changed 4 years ago by wmb@…

  • Action Needed changed from test in release to no action
  • Resolution set to fixed
  • Status changed from assigned to closed

The fix was deployed 5 months ago and nobody has stepped forward to test it, so I am closing it due to apparent lack of interest.

Note: See TracTickets for help on using tickets.