mirror of
https://github.com/chenxiaolong/avbroot.git
synced 2026-07-03 14:05:11 +02:00
e9638d25b0
This supports all features of Android sparse images, including holes, and CRC32 (both full image checksum and CRC32 chunks). Partial sparse images, like those included in GrapheneOS' new optimized factory images, can also be packed and unpacked with these new commands, unlike AOSP's simg2img and img2simg tools. This new functionality is not relevant for avbroot's main use case, but is useful for unpacking certain factory images for comparison with OTAs during troubleshooting. Signed-off-by: Andrew Gunnerson <accounts+github@chiller3.com>
75 lines
2.1 KiB
TOML
75 lines
2.1 KiB
TOML
[advisories]
|
|
version = 2
|
|
yanked = "deny"
|
|
ignore = [
|
|
# https://rustsec.org/advisories/RUSTSEC-2023-0071
|
|
#
|
|
# This is a side-channel vulnerability where secrets can be leaked to an
|
|
# attacker that is able to measure the timing of a large number of RSA
|
|
# operations. As of 2023-12-03, there is no released version of the rsa
|
|
# crate that contains a fix.
|
|
#
|
|
# For avbroot specifically, this vulnerability is not too critical for a
|
|
# couple reasons:
|
|
#
|
|
# 1. avbroot performs RSA signing only at the end of lengthy processes
|
|
# that involve a lot of disk I/O. It's very expensive to run avbroot
|
|
# the millions of times needed to capture a sufficient amount of timing
|
|
# data.
|
|
# 2. During a single run of avbroot, it will only perform RSA signing a
|
|
# handful of times. To get sufficient measurements, the attacker would
|
|
# need to rerun avbroot. If they are able to rerun avbroot, then they
|
|
# are also able to just read and steal the private key directly.
|
|
#
|
|
# avbroot has no network capabilities, so this is not inherently remotely
|
|
# exploitable.
|
|
"RUSTSEC-2023-0071",
|
|
]
|
|
|
|
[licenses]
|
|
version = 2
|
|
include-dev = true
|
|
allow = [
|
|
"Apache-2.0",
|
|
"Apache-2.0 WITH LLVM-exception",
|
|
"BSD-3-Clause",
|
|
"CC0-1.0",
|
|
"GPL-3.0",
|
|
"ISC",
|
|
"MIT",
|
|
"OpenSSL",
|
|
"Unicode-DFS-2016",
|
|
]
|
|
|
|
[[licenses.clarify]]
|
|
name = "ring"
|
|
expression = "MIT AND ISC AND OpenSSL"
|
|
license-files = [
|
|
{ path = "LICENSE", hash = 0xbd0eed23 },
|
|
]
|
|
|
|
[bans]
|
|
multiple-versions = "warn"
|
|
multiple-versions-include-dev = true
|
|
deny = [
|
|
# https://github.com/serde-rs/serde/issues/2538
|
|
{ name = "serde_derive", version = ">=1.0.172,<1.0.184" },
|
|
]
|
|
|
|
[bans.build]
|
|
executables = "deny"
|
|
include-dependencies = true
|
|
include-workspace = true
|
|
bypass = [
|
|
# Copies of unmodified crashwrangler objects for old macOS versions.
|
|
{ name = "honggfuzz", allow-globs = ["honggfuzz/third_party/mac/CrashReport_*.o"] },
|
|
]
|
|
|
|
[sources]
|
|
unknown-registry = "deny"
|
|
unknown-git = "deny"
|
|
allow-git = [
|
|
"https://github.com/chenxiaolong/bzip2-rs",
|
|
"https://github.com/chenxiaolong/zip",
|
|
]
|