[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: HDCP blob still present
From: |
Leah Rowe |
Subject: |
Re: HDCP blob still present |
Date: |
Thu, 31 Oct 2024 20:10:45 +0000 |
User-agent: |
Mozilla Thunderbird |
I've done some further auditing of GNU Boot, as a matter of courtesy and
friendship:
fam15h trees:
src/vendorcode/intel/fsp1_0/baytrail/absf/minnowmax_1gb.absf
src/vendorcode/intel/fsp1_0/baytrail/absf/minnowmax_2gb.absf
src/vendorcode/amd/agesa/f12/Proc/GNB/Nb/Family/LN/F12NbSmuFirmware.h
3rdparty/vboot/tests/preamble_tests/data/dummy_bootloader.bin
3rdparty/vboot/tests/devkeys/firmware_bmpfv.bin
3rdparty/vboot/tests/futility/data_fmap.bin
this, in addition to the other one that i found in gnuboot's default tree:
3rdparty/arm-trusted-firmware/plat/rockchip/rk3399/drivers/dp/hdcp.bin
All of the above binary blobs are still present in GNU Boot 0.1 RC3,
even the "corrected" tarballs recently re-uploaded in October 2024
(initial 0.1 RC3 was in December 2023, with more blobs than the above).
So, this makes for the 3rd revision. I believe that the GNU Boot project
will have to make yet a third revision to its 0.1 RC3 release tarballs.
There are likely still more blobs present in GNU Boot, as I've also been
finding these in Canoeboot and fixing the issue there, as part of a
wider audit that I've been doing.
On 29/10/2024 12:58, Leah Rowe via Gnuboot-patches wrote:
Dear gnuboot developers,
I checked your source code, and you seem to have this binary in some
of your coreboot trees:
3rdparty/arm-trusted-firmware/plat/rockchip/rk3399/drivers/dp/hdcp.bin
This appears to be an executable, and I could not find source code;
someone correct me if I'm wrong, but this appears to be a proprietary
blob.
You should probably fix that.
--
Company director, Minifree Ltd
Registered in England, No. 9361826 | VAT No. GB202190462
Registered Office: 19 Hilton Road, Canvey Island, Essex SS8 9QA, UK
OpenPGP_0x5C654067D383B1FF.asc
Description: OpenPGP public key
OpenPGP_signature.asc
Description: OpenPGP digital signature