pub struct BootIntegrity {
pub image_check: Option<String>,
pub image_check_evidence: Option<String>,
pub image_check_result: Option<String>,
pub image_hash_algorithms: Vec<String>,
pub image_signature_checked: bool,
pub image_signature_evidence: Option<String>,
pub image_check_failed: Option<String>,
pub hab_fuse: Option<String>,
pub hab_evidence: Option<String>,
pub ubifs_unauthenticated: Option<String>,
pub env_crc_failed: Option<String>,
}Expand description
What the bootloader actually DID about verifying the image it booted, as opposed to what the environment says it is configured to do.
The distinction this type exists to preserve: a checksum is not a signature.
Verifying Checksum ... OK proves the image was not corrupt. Anyone who can
write the image can recompute the CRC, so it stops bit-rot, not an attacker.
Only a signature establishes that the image came from the signer, and on
i.MX none of it is enforced while the HAB fuse is unblown.
Unlike the engine, this does not raise findings for any of it: the Rust and browser detector sets are pinned to the same 14 labels, and a fifteenth would break that parity. The facts and the verdicts are what the two implementations share.
Fields§
§image_check: Option<String>uimage_crc or fit_hash.
image_check_evidence: Option<String>§image_check_result: Option<String>passed, failed, or not_captured when the check began but the
capture lost its result. “The check ran” is a different claim from “the
check passed”.
image_hash_algorithms: Vec<String>§image_signature_checked: bool§image_signature_evidence: Option<String>§image_check_failed: Option<String>§hab_fuse: Option<String>not_enabled or enabled.
hab_evidence: Option<String>§ubifs_unauthenticated: Option<String>§env_crc_failed: Option<String>