Skip to content

rpi-eeprom-digest: Bubble errors from HSM_WRAPPER invocation - #867

Merged
timg236 merged 1 commit into
raspberrypi:masterfrom
brooswajne:catch-hsm-failures
Aug 10, 2026
Merged

timg236 merged 1 commit into
raspberrypi:masterfrom
brooswajne:catch-hsm-failures

Conversation

@brooswajne

Copy link
Copy Markdown
Contributor

Noticed when passing a custom HSM wrapper using -H to rpi-eeprom-digest, if my wrapper would fail (exit non-zero) then rpi-eeprom-digest would carry on as if everything was fine and end up with an empty signature being written to boot.sig.

As I understand it, errors in sub-shells ($(...)) inside a command aren't bubbled up by set -e, even if the sub-shell fails the outer echo is the only thing which set -e takes into account. And that call succeeds, so the script reports a success.

Assigning the signature to a variable avoids this shell footgun.

This can easily be tested with a purposefully always-failing wrapper, such as this (which also logs something before exiting):

❯ cat /tmp/badwrapper
#!/bin/sh
echo "wrapper exploded" >&2
exit 1

Before:

❯ ./rpi-eeprom-digest -H /tmp/badwrapper -i /tmp/p.img -o /tmp/p.sig
wrapper exploded
❯ echo $?
0
❯ cat /tmp/p.sig
2cf24dba5fb0a30e26e83b2ac5b9e29e1b161e5c1fa7425e73043362938b9824
ts: 1786364891
rsa2048:

After:

❯ ./rpi-eeprom-digest -H /tmp/badwrapper -i /tmp/p.img -o /tmp/p.sig
wrapper exploded
❯ echo $?
1
❯ cat /tmp/p.sig
2cf24dba5fb0a30e26e83b2ac5b9e29e1b161e5c1fa7425e73043362938b9824
ts: 1786364960

(the file is still partially written, but there's not much I can do about that without a bigger change - this is still an improvement as at least the overall exit status can be relied on)

Noticed when passing a custom HSM wrapper using `-H` to `rpi-eeprom-digest`,
if my wrapper would fail (exit non-zero) then `rpi-eeprom-digest` would
carry on as if everything was fine and end up with an empty signature
being written to `boot.sig`.

As I understand it, errors in sub-shells (`$(...)`) *inside* a command
aren't bubbled up by `set -e`, even if the sub-shell fails the outer
`echo` is the only thing which `set -e` takes into account. And that call
succeeds, so the script reports a success.

Assigning the signature to a variable avoids this shell footgun.

This can easily be tested with a purposefully always-failing wrapper,
such as this (which also logs something before exiting):

    ❯ cat /tmp/badwrapper
    #!/bin/sh
    echo "wrapper exploded" >&2
    exit 1

Before:

    ❯ ./rpi-eeprom-digest -H /tmp/badwrapper -i /tmp/p.img -o /tmp/p.sig
    wrapper exploded
    ❯ echo $?
    0
    ❯ cat /tmp/p.sig
    2cf24dba5fb0a30e26e83b2ac5b9e29e1b161e5c1fa7425e73043362938b9824
    ts: 1786364891
    rsa2048:

After:

    ❯ ./rpi-eeprom-digest -H /tmp/badwrapper -i /tmp/p.img -o /tmp/p.sig
    wrapper exploded
    ❯ echo $?
    1
    ❯ cat /tmp/p.sig
    2cf24dba5fb0a30e26e83b2ac5b9e29e1b161e5c1fa7425e73043362938b9824
    ts: 1786364960

(the file is still partially written, but there's not much I can do about
that without a bigger change - this is still an improvement as at least
the overall exit status can be relied on)
@timg236
timg236 merged commit 1c05267 into raspberrypi:master Aug 10, 2026
1 check passed
@brooswajne
brooswajne deleted the catch-hsm-failures branch August 10, 2026 15:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants