build: gate firmware image signing behind SIGN_FIRMWARE

Firmware image signing in append-metadata/append-gl-metadata was conditional
only by the presence of the build key. Add an explicit SIGN_FIRMWARE option
(default enabled except with BUILDBOT) so appending the fwtool signature can be
toggled on its own.

It's disable on buildbot since we use a decentralized building with no
individual keys on builders. Instead, a fake key is currently used, which adds
an insecure signature.

The future of signing firmware  and key distribution across the build
infrastructure should be discussed separately.

Link: https://github.com/openwrt/openwrt/pull/24291
Signed-off-by: Paul Spooren <mail@aparcar.org>
This commit is contained in:
Paul Spooren
2026-07-20 10:33:41 +02:00
parent 3ec398f0c3
commit ff41ddea1c
2 changed files with 13 additions and 4 deletions
+9
View File
@@ -83,6 +83,15 @@ menu "Global build settings"
--allow-untrusted when installing self-compiled packages to a
firmware compiled by the same buildhost as public key matches.
config SIGN_FIRMWARE
bool "Cryptographically sign firmware images"
default n if BUILDBOT
default y
help
Append a signature to firmware images so that sysupgrade can verify
their authenticity before flashing. OpenWrt's build infrastructure
signs images with temporary keys; disabling this drops the signature.
comment "General build options"
config TESTING_KERNEL