rpi-eeprom-digest: Bubble errors from HSM_WRAPPER invocation - #867
Merged
Merged
Conversation
Noticed when passing a custom HSM wrapper using `-H` to `rpi-eeprom-digest`,
if my wrapper would fail (exit non-zero) then `rpi-eeprom-digest` would
carry on as if everything was fine and end up with an empty signature
being written to `boot.sig`.
As I understand it, errors in sub-shells (`$(...)`) *inside* a command
aren't bubbled up by `set -e`, even if the sub-shell fails the outer
`echo` is the only thing which `set -e` takes into account. And that call
succeeds, so the script reports a success.
Assigning the signature to a variable avoids this shell footgun.
This can easily be tested with a purposefully always-failing wrapper,
such as this (which also logs something before exiting):
❯ cat /tmp/badwrapper
#!/bin/sh
echo "wrapper exploded" >&2
exit 1
Before:
❯ ./rpi-eeprom-digest -H /tmp/badwrapper -i /tmp/p.img -o /tmp/p.sig
wrapper exploded
❯ echo $?
0
❯ cat /tmp/p.sig
2cf24dba5fb0a30e26e83b2ac5b9e29e1b161e5c1fa7425e73043362938b9824
ts: 1786364891
rsa2048:
After:
❯ ./rpi-eeprom-digest -H /tmp/badwrapper -i /tmp/p.img -o /tmp/p.sig
wrapper exploded
❯ echo $?
1
❯ cat /tmp/p.sig
2cf24dba5fb0a30e26e83b2ac5b9e29e1b161e5c1fa7425e73043362938b9824
ts: 1786364960
(the file is still partially written, but there's not much I can do about
that without a bigger change - this is still an improvement as at least
the overall exit status can be relied on)
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Noticed when passing a custom HSM wrapper using
-Htorpi-eeprom-digest, if my wrapper would fail (exit non-zero) thenrpi-eeprom-digestwould carry on as if everything was fine and end up with an empty signature being written toboot.sig.As I understand it, errors in sub-shells (
$(...)) inside a command aren't bubbled up byset -e, even if the sub-shell fails the outerechois the only thing whichset -etakes into account. And that call succeeds, so the script reports a success.Assigning the signature to a variable avoids this shell footgun.
This can easily be tested with a purposefully always-failing wrapper, such as this (which also logs something before exiting):
Before:
After:
(the file is still partially written, but there's not much I can do about that without a bigger change - this is still an improvement as at least the overall exit status can be relied on)