update_disk: golden slot tried after the A/B attempts, exempt from anti-rollback and never written - #922
Draft
dgarske wants to merge 1 commit into
Draft
update_disk: golden slot tried after the A/B attempts, exempt from anti-rollback and never written#922dgarske wants to merge 1 commit into
dgarske wants to merge 1 commit into
Conversation
…ti-rollback and never written
Contributor
There was a problem hiding this comment.
Copilot review overview
🔵 Needs a closer look
The rollback-exempt recovery path needs human security review and has unresolved fallback and configuration issues.
Review effort: Balanced
Findings: 1
Open (3)
What changed in this PR
Adds an optional recovery image to wolfBoot’s disk loader when normal A/B boot attempts fail.
Changes:
- Tries golden once, retaining integrity and signature verification.
- Exempts golden from anti-rollback checks and boot-confirmation writes.
- Adds configuration gating, documentation, and regression tests.
| File | Description |
|---|---|
| tools/unit-tests/unit-update-disk-golden.c | Tests recovery fallback, verification, and write avoidance. |
| tools/unit-tests/Makefile | Registers and builds the golden-slot tests. |
| src/update_disk.c | Implements golden-slot selection and fallback. |
| options.mk | Gates the option on disk-boot targets. |
| docs/compile.md | Documents golden-slot configuration and behavior. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Comment on lines
+132
to
+133
| #define BOOT_PART_GOLDEN 2 | ||
| #endif |
Comment on lines
+745
to
+746
| (void)slot_prepare(&boot_slots[SLOT_GOLDEN], BOOT_PART_GOLDEN, | ||
| BOOT_LABEL_GOLDEN, BOOT_FILE_GOLDEN, slot_max); |
| if ((pB_ver == 0) && (pA_ver == 0)) { | ||
| wolfBoot_printf("No valid OS image found in either partition %d or %d\r\n", | ||
| boot_slots[0].part, boot_slots[1].part); | ||
| #ifndef DISK_GOLDEN_SLOT |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.


The disk boot path selects between two slots by version, with optional boot confirmation (
DISK_BOOT_CONFIRM) to skip a slot that was armed and never confirmed. Nothing brings a device back once both slots are gone: two failed updates, or one failed update next to a slot that anti-rollback refuses, end in a panic.What it adds
src/update_disk.c-DISK_GOLDEN_SLOT: a third slot (BOOT_PART_GOLDEN, default GPT index 2, orBOOT_LABEL_GOLDEN/BOOT_FILE_GOLDENlike the A/B slots) tried exactly once, after the A/B attempts are spent. It goes through the same load, integrity and signature checks as any image. It is exempt from the anti-rollback check, so a deliberately old recovery image still boots, and an anti-rollback refusal of the other update slot now falls through to it instead of halting. It is never written: no confirmation trailer is armed on it. Reaching it is announced on the console.options.mk-DISK_GOLDEN_SLOT=1, gated on a disk-boot target likeDISK_BOOT_CONFIRM.tools/unit-tests/unit-update-disk-golden.c- the slot is untouched when A boots; boots after A and B fail with a version below the ceiling; boots when both slots are blank; is verified (a bad golden image still panics); is never written and skips confirmation; boots when A is unconfirmed and B is bad.docs/compile.md- a section under "Disk boot confirmation and rollback".Builds without
DISK_GOLDEN_SLOTare unchanged: the slot array, the attempt count and the anti-rollback panic keep their previous values.Hardware / test status
PolarFire SoC Video Kit, standalone M-mode wolfBoot from eNVM, SD card with slot A (version 2), an empty slot B and a version-1 golden image: A boots; with A's header zeroed, wolfBoot reports no valid image in the A/B slots, tries them, falls back to the golden image and Linux reaches the login prompt; with A rewritten, A boots again. The existing disk unit suites and the
simbuild pass.Scope
A classified failure record for the fallback is left out:
wolfBoot_record_failure()needs diagnostics storage the disk targets do not define.