diff --git a/docs/adr/0003-own-signature-check-not-secure-boot.md b/docs/adr/0003-own-signature-check-not-secure-boot.md index 2fb1644..3c79a54 100644 --- a/docs/adr/0003-own-signature-check-not-secure-boot.md +++ b/docs/adr/0003-own-signature-check-not-secure-boot.md @@ -9,4 +9,4 @@ We chose this over the ESP32's hardware Secure Boot. Secure Boot is enforced by - Someone with physical USB access can still flash anything. Only Wi-Fi and SD card updates are guarded. - **Losing the private key** means the next update has to go over USB, carrying a new public key. - P-256 rather than Ed25519, because the firmware's TLS library (mbedTLS) already verifies it, so it costs no extra code. -- **Rollback is done by the firmware, not the bootloader.** On the device, the prebuilt bootloader that PlatformIO flashes did not roll back a crashing update, even though the app's configuration enables it. So the firmware counts its own boots on Probation, very first thing in `setup()`, and reverts itself on the second unconfirmed start. A crash before that counter is written (the first few milliseconds) would not be caught: recovery is then over USB. +- **Rollback: the bootloader first, the firmware as a second line.** Arduino-ESP32 marks a new image valid before `setup()` unless the sketch overrides `verifyRollbackLater()`, which once made every update look good and hid the bootloader's rollback (it had looked like the prebuilt bootloader ignored it). With the override, an image stays pending until Probation confirms it, and the bootloader reverts one that restarts unconfirmed, however early it crashes. The firmware also counts its own boots on Probation, very first thing in `setup()`, and reverts itself on the second unconfirmed start.