Merge pull request #695 from Foundation-Devices/fix/pin-build-inputs
What changed, and why it matters
This commit locks down the versions of software building blocks used when compiling Passport's Rust code. It adds the '--locked' flag to cargo commands and pins the exact version of a code-generation tool (cbindgen). This is a hardening change meant to make builds more reproducible and prevent unexpected dependency updates from sneaking in, rather than a fix for an active security bug.
No immediate user action is required. This is a build-hardening improvement. Developers should verify that CI and local builds still pass with --locked, and consider auditing other build tools and dependencies for similar pinning opportunities.
Security signals we found
Adds --locked to cargo commands to enforce Cargo.lock resolution
Pins cbindgen to exact version '=0.24.5'
Updates critical-section dependency lockfile entry from 1.1.2 to 1.2.0
Hardens CI/Dockerfile/Makefile/Justfile build reproducibility
Evidence from the diff
The commit enforces deterministic Rust builds by adding ‘–locked’ to cargo build, check, clippy, test, and run invocations across CI, the Dockerfile, the Justfile, and the Makefile. It also pins cbindgen to exactly version 0.24.5 (previously allowed ‘^0.24’) and updates the Cargo.lock for the ‘critical-section’ crate from 1.1.2 to 1.2.0. These are supply-chain/build-integrity hardening measures; no runtime vulnerability in Passport firmware is directly patched.
Changed components
.github/workflows/lint.yamlDockerfileextmod/foundation-rust/Cargo.lockextmod/foundation-rust/Justfilepy/py.mkInspect captured patch +13 / −10
### .github/workflows/lint.yaml
@@ -28,11 +28,13 @@ jobs:
toolchain: 1.77.1
targets: thumbv7em-none-eabihf
- run: |
- cargo check --manifest-path extmod/foundation-rust/Cargo.toml
+ cargo check --manifest-path extmod/foundation-rust/Cargo.toml \
+ --locked
# Required by secp256k1-sys.
- run: sudo apt-get install -y gcc-arm-none-eabi
- run: |
cargo check --manifest-path extmod/foundation-rust/Cargo.toml \
+ --locked \
--target thumbv7em-none-eabihf
is-the-rust-code-formatted:
@@ -66,7 +68,7 @@ jobs:
- uses: ./.github/actions/rust-toolchain
with:
toolchain: 1.77.1
- - run: cargo install cbindgen@^0.24 --locked
+ - run: cargo install cbindgen --version '=0.24.5' --locked
- run: |
cbindgen --config extmod/foundation-rust/cbindgen.toml \
--output extmod/foundation-rust/include/foundation.h \
@@ -85,4 +87,5 @@ jobs:
targets:
- run: |
cargo test --manifest-path extmod/foundation-rust/Cargo.toml \
+ --locked \
--features std
### Dockerfile
@@ -41,7 +41,7 @@ RUN rustup component add clippy && \
rustup target add thumbv7em-none-eabihf
# Install binaries using cargo.
-RUN cargo install cbindgen@^0.24 --locked && \
+RUN cargo install cbindgen --version '=0.24.5' --locked && \
cargo install just@1.23.0 --locked && \
mv /cargo/bin/cbindgen /usr/local/bin/cbindgen && \
mv /cargo/bin/just /usr/local/bin/just && \
### extmod/foundation-rust/Cargo.lock
@@ -80,9 +80,9 @@ checksum = "19d374276b40fb8bbdee95aef7c7fa6b5316ec764510eb64b8dd0e2ed0d7e7f5"
[[package]]
name = "critical-section"
-version = "1.1.2"
+version = "1.2.0"
source = "registry+https://github.com/rust-lang/crates.io-index"
-checksum = "7059fff8937831a9ae6f0fe4d658ffabf58f2ca96aa9dec1c889f936f705f216"
+checksum = "790eea4361631c5e7d22598ecd5723ff611904e3344ce8720784c93e3d83d40b"
[[package]]
name = "either"
### extmod/foundation-rust/Justfile
@@ -13,18 +13,18 @@ generate:
# Build the crate.
build:
- cargo build --target thumbv7em-none-eabihf --release
+ cargo build --locked --target thumbv7em-none-eabihf --release
# Lint the crate.
lint:
- cargo clippy --target thumbv7em-none-eabihf
+ cargo clippy --locked --target thumbv7em-none-eabihf
cargo fmt --check
cbindgen --config cbindgen.toml \
--crate foundation \
--output include/foundation.h \
--verify
- cargo test --features std
+ cargo test --locked --features std
# Print size information
sizes:
- cargo run --features std
+ cargo run --locked --features std
### py/py.mk
@@ -148,7 +148,7 @@ LDFLAGS_MOD += -L$(shell dirname $(FOUNDATION_RUST_LIB)) -lfoundation
$(FOUNDATION_RUST_LIB): $(FOUNDATION_RUST_SRC)
$(ECHO) "CARGO foundation-rust"
- cargo build --manifest-path $(FOUNDATION_RUST)/Cargo.toml --target $(RUST_TARGET) $(RUST_FEATURES) --release
+ cargo build --manifest-path $(FOUNDATION_RUST)/Cargo.toml --locked --target $(RUST_TARGET) $(RUST_FEATURES) --release
# FOUNDATION CHANGE: END
Why this scored 29/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.