gnuboot-patches
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: HDCP blob still present


From: Leah Rowe
Subject: Re: HDCP blob still present
Date: Thu, 31 Oct 2024 20:10:45 +0000
User-agent: Mozilla Thunderbird


I've done some further auditing of GNU Boot, as a matter of courtesy and friendship:


fam15h trees:

src/vendorcode/intel/fsp1_0/baytrail/absf/minnowmax_1gb.absf
src/vendorcode/intel/fsp1_0/baytrail/absf/minnowmax_2gb.absf
src/vendorcode/amd/agesa/f12/Proc/GNB/Nb/Family/LN/F12NbSmuFirmware.h
3rdparty/vboot/tests/preamble_tests/data/dummy_bootloader.bin
3rdparty/vboot/tests/devkeys/firmware_bmpfv.bin
3rdparty/vboot/tests/futility/data_fmap.bin

this, in addition to the other one that i found in gnuboot's default tree:

3rdparty/arm-trusted-firmware/plat/rockchip/rk3399/drivers/dp/hdcp.bin

All of the above binary blobs are still present in GNU Boot 0.1 RC3, even the "corrected" tarballs recently re-uploaded in October 2024 (initial 0.1 RC3 was in December 2023, with more blobs than the above).

So, this makes for the 3rd revision. I believe that the GNU Boot project will have to make yet a third revision to its 0.1 RC3 release tarballs.

There are likely still more blobs present in GNU Boot, as I've also been finding these in Canoeboot and fixing the issue there, as part of a wider audit that I've been doing.



On 29/10/2024 12:58, Leah Rowe via Gnuboot-patches wrote:
Dear gnuboot developers,

I checked your source code, and you seem to have this binary in some of your coreboot trees:

3rdparty/arm-trusted-firmware/plat/rockchip/rk3399/drivers/dp/hdcp.bin

This appears to be an executable, and I could not find source code; someone correct me if I'm wrong, but this appears to be a proprietary blob.

You should probably fix that.

--
Company director, Minifree Ltd
Registered in England, No. 9361826 | VAT No. GB202190462
Registered Office: 19 Hilton Road, Canvey Island, Essex SS8 9QA, UK

Attachment: OpenPGP_0x5C654067D383B1FF.asc
Description: OpenPGP public key

Attachment: OpenPGP_signature.asc
Description: OpenPGP digital signature


reply via email to

[Prev in Thread] Current Thread [Next in Thread]