Skip to content

update_disk: golden slot tried after the A/B attempts, exempt from anti-rollback and never written - #922

Draft
dgarske wants to merge 1 commit into
wolfSSL:masterfrom
dgarske:disk_golden
Draft

dgarske wants to merge 1 commit into
wolfSSL:masterfrom
dgarske:disk_golden

Conversation

@dgarske

@dgarske dgarske commented Oct 3, 2026

Copy link
Copy Markdown
Member

The disk boot path selects between two slots by version, with optional boot confirmation (DISK_BOOT_CONFIRM) to skip a slot that was armed and never confirmed. Nothing brings a device back once both slots are gone: two failed updates, or one failed update next to a slot that anti-rollback refuses, end in a panic.

What it adds

  • src/update_disk.c - DISK_GOLDEN_SLOT: a third slot (BOOT_PART_GOLDEN, default GPT index 2, or BOOT_LABEL_GOLDEN / BOOT_FILE_GOLDEN like the A/B slots) tried exactly once, after the A/B attempts are spent. It goes through the same load, integrity and signature checks as any image. It is exempt from the anti-rollback check, so a deliberately old recovery image still boots, and an anti-rollback refusal of the other update slot now falls through to it instead of halting. It is never written: no confirmation trailer is armed on it. Reaching it is announced on the console.
  • options.mk - DISK_GOLDEN_SLOT=1, gated on a disk-boot target like DISK_BOOT_CONFIRM.
  • tools/unit-tests/unit-update-disk-golden.c - the slot is untouched when A boots; boots after A and B fail with a version below the ceiling; boots when both slots are blank; is verified (a bad golden image still panics); is never written and skips confirmation; boots when A is unconfirmed and B is bad.
  • docs/compile.md - a section under "Disk boot confirmation and rollback".

Builds without DISK_GOLDEN_SLOT are unchanged: the slot array, the attempt count and the anti-rollback panic keep their previous values.

Hardware / test status

PolarFire SoC Video Kit, standalone M-mode wolfBoot from eNVM, SD card with slot A (version 2), an empty slot B and a version-1 golden image: A boots; with A's header zeroed, wolfBoot reports no valid image in the A/B slots, tries them, falls back to the golden image and Linux reaches the login prompt; with A rewritten, A boots again. The existing disk unit suites and the sim build pass.

Scope

A classified failure record for the fallback is left out: wolfBoot_record_failure() needs diagnostics storage the disk targets do not define.

Copilot AI balanced review requested due to automatic review settings October 3, 2026 02:08
@dgarske dgarske self-assigned this Oct 3, 2026

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

The rollback-exempt recovery path needs human security review and has unresolved fallback and configuration issues.

Review effort: Balanced
Findings: 1 High severity · 2 Medium severity

Open (3)
What changed in this PR

Adds an optional recovery image to wolfBoot’s disk loader when normal A/B boot attempts fail.

Changes:

  • Tries golden once, retaining integrity and signature verification.
  • Exempts golden from anti-rollback checks and boot-confirmation writes.
  • Adds configuration gating, documentation, and regression tests.
File Description
tools/​unit-tests/​unit-update-disk-golden.c Tests recovery fallback, verification, and write avoidance.
tools/​unit-tests/​Makefile Registers and builds the golden-slot tests.
src/​update_disk.c Implements golden-slot selection and fallback.
options.mk Gates the option on disk-boot targets.
docs/​compile.md Documents golden-slot configuration and behavior.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread src/update_disk.c
Comment on lines +132 to +133
#define BOOT_PART_GOLDEN 2
#endif
Comment thread src/update_disk.c
Comment on lines +745 to +746
(void)slot_prepare(&boot_slots[SLOT_GOLDEN], BOOT_PART_GOLDEN,
BOOT_LABEL_GOLDEN, BOOT_FILE_GOLDEN, slot_max);
Comment thread src/update_disk.c
if ((pB_ver == 0) && (pA_ver == 0)) {
wolfBoot_printf("No valid OS image found in either partition %d or %d\r\n",
boot_slots[0].part, boot_slots[1].part);
#ifndef DISK_GOLDEN_SLOT
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants