Skip to content

dropbear-openipc: name the hash file so buildroot reads it - #2456

Merged
openipc-ai merged 1 commit into
masterfrom
dropbear-hash-name
Sep 19, 2026
Merged

openipc-ai merged 1 commit into
masterfrom
dropbear-hash-name

Conversation

@openipc-ai

Copy link
Copy Markdown
Collaborator

Closes #2450.

Problem

general/package/dropbear-openipc/ ships its checksums as dropbear.hash, named after the upstream project. Buildroot resolves a package's hash file to <RAWNAME>.hash (package/pkg-generic.mk:512), which for this package is dropbear-openipc.hash — so the file we ship is never opened. Buildroot will say so itself:

$ make -C output/buildroot-2024.02.10 BR2_EXTERNAL=$PWD/general O=$PWD/output \
       printvars VARS="DROPBEAR_OPENIPC_HASH_FILES DROPBEAR_OPENIPC_RAWNAME"

DROPBEAR_OPENIPC_HASH_FILES=general/package/dropbear-openipc//dropbear-openipc.hash \
                            general/package/all-patches/dropbear-openipc/dropbear-openipc.hash
DROPBEAR_OPENIPC_RAWNAME=dropbear-openipc

Neither of those exists. support/download/check-hash then warns and returns success, and we do not set BR2_DOWNLOAD_FORCE_CHECK_HASHES, so the tarball is fetched from http://sources.buildroot.net/dropbear over plain HTTP and built with no integrity check. Dropbear is the SSH daemon on every image that enables it, and the three LICENSE hashes are equally dead, so legal-info loses its check too.

This is not a claim about the mirror. The point is that we ship a file whose only purpose is verification, it looks correct in review, and it does nothing.

Every other .hash in the tree is named correctly (libjpeg-openipc, webrtc-audio-processing-openipc, legacy/gst1-plugins-bad-openipc); this was the only one left. #2449 had introduced a second instance, fixed there before merge.

Hardware tested on

Not applicable, and I want to be explicit rather than leave it blank. This renames a checksum file. It changes nothing Buildroot fetches, compiles or installs — the dropbear tarball and every byte of the resulting image are identical — it only decides whether the download is verified on the way in. There is no camera-observable behaviour to exercise.

The risk it does carry is the opposite one: these hashes have never been read, so nothing had ever proven them correct, and a wrong entry would turn a silent no-check into a hard build failure on 100 boards. So I verified all four against the released tarball before renaming, and the evidence below is that check rather than a board.

Evidence

All four entries verify against the real tarball:

$ curl -sSL -O http://sources.buildroot.net/dropbear/dropbear-2022.82.tar.bz2
$ sha256sum dropbear-2022.82.tar.bz2
3a038d2bbc02bf28bbdd20c012091f741a3ec5cbe460691811d714876aad75d1  dropbear-2022.82.tar.bz2   <- matches
$ tar -xjf dropbear-2022.82.tar.bz2 && cd dropbear-2022.82
$ sha256sum LICENSE libtomcrypt/LICENSE libtommath/LICENSE
a99ce657d790b761c132ee7e0de18edb437ae6361e536d991c6a12f36e770445  LICENSE               <- matches
8f196cb13afd271f5e267fd29543fc454596382ad580e7592709492843996ac8  libtomcrypt/LICENSE   <- matches
2fa64b163659f41965c9815882a8296d3d03ff546b76153e11445f9bdecf955a  libtommath/LICENSE    <- matches

The three licence hashes also match Buildroot's own current package/dropbear/dropbear.hash (for 2024.85) — those files have not changed upstream, which is an independent corroboration.

Running Buildroot's own support/download/check-hash against the real tarball, before and after:

Before:

$ check-hash dropbear-2022.82.tar.bz2 dropbear-2022.82.tar.bz2 \
             general/package/dropbear-openipc/dropbear-openipc.hash
WARNING: no hash file for dropbear-2022.82.tar.bz2
exit=0

After:

$ check-hash dropbear-2022.82.tar.bz2 dropbear-2022.82.tar.bz2 \
             general/package/dropbear-openipc/dropbear-openipc.hash
dropbear-2022.82.tar.bz2: OK (sha256: 3a038d2bbc02bf28bbdd20c012091f741a3ec5cbe460691811d714876aad75d1)
exit=0

And it now actually catches a bad download — one byte flipped in the tarball:

$ check-hash tampered.tar.bz2 dropbear-2022.82.tar.bz2 \
             general/package/dropbear-openipc/dropbear-openipc.hash
ERROR: dropbear-2022.82.tar.bz2 has wrong sha256 hash:
ERROR: expected: 3a038d2bbc02bf28bbdd20c012091f741a3ec5cbe460691811d714876aad75d1
ERROR: got     : 21fbdbfd632eae3efa8f4c6e2c46a3c3b1875f25b422ed34764ab934b1ecc9fe
ERROR: Incomplete download, or man-in-the-middle (MITM) attack
exit=2

Selector and self-test:

$ python3 .github/scripts/ci-matrix.py --self-test
ci-matrix: self-test ok (100 boards, 137 packages, 60 cases)

$ git diff --name-only origin/master | python3 .github/scripts/ci-matrix.py --stdin
ci-matrix: 100/100 boards (needs_build=True) --- narrowed to the affected boards

The full matrix is the right answer here even for a rename: if a hash were wrong, every board that builds dropbear would fail, so every board should prove it does not.

Scope

  • No kernel patches under general/package/all-patches/linux/
  • No files specific to a single retail camera model
  • No probing or bring-up tooling
  • Nothing under general/overlay/ or in a shared load_<vendor> script hardcodes a value specific to my board
  • (left unticked deliberately: DROPBEAR_OPENIPC_SITE is Buildroot's sources.buildroot.net mirror rather than an OpenIPC repository. That is pre-existing and untouched here — no *_SITE or *_VERSION changes in this diff — but I am not going to tick a box asserting something this PR did not establish.)
  • No LD_PRELOAD, and no binaries that cannot be rebuilt from source
  • No new code; the package this belongs to is selected by defconfigs and CI builds it on all 100 boards

Buildroot resolves a package's checksums to <RAWNAME>.hash, which for this
package is dropbear-openipc.hash. The file shipped as dropbear.hash and was
therefore never opened: check-hash printed "WARNING: no hash file for
dropbear-2022.82.tar.bz2" and returned 0, so the tarball was fetched from
sources.buildroot.net over plain HTTP and built with no integrity check at
all. BR2_DOWNLOAD_FORCE_CHECK_HASHES is off, so nothing ever failed and the
gap stayed invisible -- the .hash file is present in the tree and looks
right, which is exactly why this survived review.

The contents were already correct, all four hashes verifying against the
released tarball, so this is a rename and verification simply starts
working. Found while reviewing #2449, which had introduced the same mistake
in a new package.
@qodo-free-for-open-source-projects

Copy link
Copy Markdown

PR Summary by Qodo

Enable Dropbear OpenIPC checksum verification

🐞 Bug fix 🕐 Less than 5 minutes

Grey Divider

AI Description

• Renames the checksum manifest to match Buildroot’s package naming convention.
• Enables integrity checks for Dropbear downloads and license files.
• Preserves all previously verified checksum values unchanged.
Diagram

graph TD
  A["Package Name"] -->|resolves| B["Hash Filename"] -->|loads| C["Buildroot Checker"] -->|verifies| D["Dropbear Tarball"]
  C -->|validates| E["License Files"]
Loading
High-Level Assessment

The rename is the optimal approach because it follows Buildroot’s established .hash discovery convention without changing package metadata or generic infrastructure. Explicit overrides or Buildroot-wide fallback logic would add unnecessary complexity for a package-local naming defect.

Files changed (1) +0 / -0

Bug fix (1) +0 / -0
dropbear-openipc.hashRename checksum manifest for Buildroot discovery +0/-0

Rename checksum manifest for Buildroot discovery

• Renames the former dropbear.hash manifest to dropbear-openipc.hash so Buildroot loads it for this package. Existing source and license checksum values remain unchanged.

general/package/dropbear-openipc/dropbear-openipc.hash

@qodo-free-for-open-source-projects

Copy link
Copy Markdown

Code Review by Qodo

🐞 Bugs (0) 📘 Rule violations (0) 📎 Requirement gaps (0)

Grey Divider

Great, no issues found!

Qodo reviewed your code and found no material issues that require review

Grey Divider

Tip of the day
💡 Did you know, you can describe a rule in plain language on the Rules page and Qodo drafts it for you

More tips ↗ | Customize Qodo ↗ | Qodo docs ↗

Grey Divider

Qodo Logo

@openipc-ai
openipc-ai merged commit 06eba5f into master Sep 19, 2026
119 of 120 checks passed
@openipc-ai
openipc-ai deleted the dropbear-hash-name branch September 19, 2026 14:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

dropbear-openipc: hash file is named dropbear.hash, so Buildroot never verifies the tarball

1 participant