From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from phobos.denx.de (phobos.denx.de [85.214.62.61]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.lore.kernel.org (Postfix) with ESMTPS id C90B2C25B50 for ; Sat, 21 Jan 2023 15:58:33 +0000 (UTC) Received: from h2850616.stratoserver.net (localhost [IPv6:::1]) by phobos.denx.de (Postfix) with ESMTP id E393B8568C; Sat, 21 Jan 2023 16:58:26 +0100 (CET) Authentication-Results: phobos.denx.de; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: phobos.denx.de; spf=pass smtp.mailfrom=u-boot-bounces@lists.denx.de Authentication-Results: phobos.denx.de; dkim=pass (2048-bit key; unprotected) header.d=gmail.com header.i=@gmail.com header.b="i2+uEdEA"; dkim-atps=neutral Received: by phobos.denx.de (Postfix, from userid 109) id E84D285463; Sat, 21 Jan 2023 16:48:40 +0100 (CET) Received: from mail-wm1-x334.google.com (mail-wm1-x334.google.com [IPv6:2a00:1450:4864:20::334]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits)) (No client certificate requested) by phobos.denx.de (Postfix) with ESMTPS id A359D8554F for ; Sat, 21 Jan 2023 16:48:37 +0100 (CET) Authentication-Results: phobos.denx.de; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: phobos.denx.de; spf=pass smtp.mailfrom=paulerwan.rio@gmail.com Received: by mail-wm1-x334.google.com with SMTP id l41-20020a05600c1d2900b003daf986faaeso5669830wms.3 for ; Sat, 21 Jan 2023 07:48:37 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20210112; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to; bh=hgPpB/jFAS+6QcHhA6i8it3RB1pBND2jLLjRKdjwdfo=; b=i2+uEdEA9o3GKiEBNNSKiRQyAvMTqeoGEmJaTGghJ0oWpqSC6hvRdGmrToh99sqKAU +sEr70HHNU4J04BGvzRHP7gyT3QkwAMPvSm+dagNIFC00NzYTem8UOBWvBbUGZODDmEY Zyj9euvvMasFYQ3TusXPXNJ2LT5Zg6hxeddRVorp2z1LKakS8wpHwFr8v3UmUuvcyZ5y 2OuUYhd8saeeJ2uOw0J7EEXysu55oej6sWhxhoIe36qgTWCtMFgV53zV0d5o1nnWqq7g WKz5Y8vJ9XbWkjtVIue603GNyYilZRyKWmVhWv4bWI+JvZK4XNiuM+bCRYI35qRMfP0P kt1g== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to; bh=hgPpB/jFAS+6QcHhA6i8it3RB1pBND2jLLjRKdjwdfo=; b=aQcKxcfscIr4t75RinwhxeOmgIuTVxporiwfrxOWq4gRXjsobSYQrXclpxJH0yTM8E kFk/+f6pzbcm8JVrTEp1MnjZXsceRvNn9OPOCoOYpyJW9QNXX4+AMSUuqZS6Y3GTm6XE tvVSZyM10uPfvswFKIztjWNfDw88s2eO0ak7KBZhM+CmERVYrVqCz03hxKQ0gQZfaOc5 RayNo/CehFX9LfLcTYgkV6QMklpA8evgK26I3ESe4FzSQnLZx/Dvy5Pdz6Qfjc3TJib/ lUufa0o/kxxhbQDLhrkykzJcVWRq43wO/0T9ekh0eu/Vdg+FRDPq+xqcuqw3NnM6CaWB iGBg== X-Gm-Message-State: AFqh2krX7MavPjX8sQbo1T0cLNdiZi1zQ8U+01TDitcVOZXO1JLpBFNS CEgeB/DIHczBA0Yl2mhDOAEpSLR8YbC1HNot X-Google-Smtp-Source: AMrXdXucRlDhtG+yYnBkR1zdi4rk0FeQW/Pydo1EnlfckV/OyUxh8PYJJW3lt8HJa8aT49XGGHkuMQ== X-Received: by 2002:a05:600c:181b:b0:3da:ff1f:e8d3 with SMTP id n27-20020a05600c181b00b003daff1fe8d3mr17734553wmp.15.1674316117046; Sat, 21 Jan 2023 07:48:37 -0800 (PST) Received: from localhost.localdomain ([2a01:e0a:359:6c00:9194:e12b:fad2:6b35]) by smtp.gmail.com with ESMTPSA id j8-20020a05600c190800b003d9aa76dc6asm7744143wmq.0.2023.01.21.07.48.36 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 21 Jan 2023 07:48:36 -0800 (PST) From: Paul-Erwan Rio To: u-boot@lists.denx.de Cc: Simon Glass , Paul-Erwan Rio , Marek Behun , Pali Rohar , Stefan Roese Subject: [PATCH v1 1/2] tools: kwbimage: disable secure boot build without LIBCRYPTO support Date: Sat, 21 Jan 2023 16:47:41 +0100 Message-Id: <20230121154743.667253-2-paulerwan.rio@gmail.com> X-Mailer: git-send-email 2.39.0 In-Reply-To: <20230121154743.667253-1-paulerwan.rio@gmail.com> References: <20230121154743.667253-1-paulerwan.rio@gmail.com> MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Mailman-Approved-At: Sat, 21 Jan 2023 16:58:23 +0100 X-BeenThere: u-boot@lists.denx.de X-Mailman-Version: 2.1.39 Precedence: list List-Id: U-Boot discussion List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: u-boot-bounces@lists.denx.de Sender: "U-Boot" X-Virus-Scanned: clamav-milter 0.103.6 at phobos.denx.de X-Virus-Status: Clean The secure boot features cannot be built without 'LIBCRYPTO' enabled. This kind of reverts some of changes. Signed-off-by: Paul-Erwan Rio --- tools/kwbimage.c | 18 ++++++++++++++++++ 1 file changed, 18 insertions(+) diff --git a/tools/kwbimage.c b/tools/kwbimage.c index 6abb9f2d5c..0db99dbb02 100644 --- a/tools/kwbimage.c +++ b/tools/kwbimage.c @@ -19,6 +19,7 @@ #include #include "kwbimage.h" +#if CONFIG_IS_ENABLED(LIBCRYPTO) #include #include #include @@ -44,6 +45,7 @@ void EVP_MD_CTX_cleanup(EVP_MD_CTX *ctx) EVP_MD_CTX_reset(ctx); } #endif +#endif /* fls - find last (most-significant) bit set in 4-bit integer */ static inline int fls4(int num) @@ -62,7 +64,9 @@ static inline int fls4(int num) static struct image_cfg_element *image_cfg; static int cfgn; +#if CONFIG_IS_ENABLED(LIBCRYPTO) static int verbose_mode; +#endif struct boot_mode { unsigned int id; @@ -278,6 +282,7 @@ image_count_options(unsigned int optiontype) return count; } +#if CONFIG_IS_ENABLED(LIBCRYPTO) static int image_get_csk_index(void) { struct image_cfg_element *e; @@ -299,6 +304,7 @@ static bool image_get_spezialized_img(void) return e->sec_specialized_img; } +#endif static int image_get_bootfrom(void) { @@ -432,6 +438,7 @@ static uint8_t baudrate_to_option(unsigned int baudrate) } } +#if CONFIG_IS_ENABLED(LIBCRYPTO) static void kwb_msg(const char *fmt, ...) { if (verbose_mode) { @@ -926,6 +933,7 @@ static int kwb_dump_fuse_cmds(struct secure_hdr_v1 *sec_hdr) done: return ret; } +#endif static size_t image_headersz_align(size_t headersz, uint8_t blockid) { @@ -1079,11 +1087,13 @@ static size_t image_headersz_v1(int *hasext) */ headersz = sizeof(struct main_hdr_v1); +#if CONFIG_IS_ENABLED(LIBCRYPTO) if (image_get_csk_index() >= 0) { headersz += sizeof(struct secure_hdr_v1); if (hasext) *hasext = 1; } +#endif cpu_sheeva = image_is_cpu_sheeva(); @@ -1270,6 +1280,7 @@ err_close: return -1; } +#if CONFIG_IS_ENABLED(LIBCRYPTO) static int export_pub_kak_hash(RSA *kak, struct secure_hdr_v1 *secure_hdr) { FILE *hashf; @@ -1382,6 +1393,7 @@ static int add_secure_header_v1(struct image_tool_params *params, uint8_t *ptr, return 0; } +#endif static void finish_register_set_header_v1(uint8_t **cur, uint8_t **next_ext, struct register_set_hdr_v1 *register_set_hdr, @@ -1406,7 +1418,9 @@ static void *image_create_v1(size_t *imagesz, struct image_tool_params *params, struct main_hdr_v1 *main_hdr; struct opt_hdr_v1 *ohdr; struct register_set_hdr_v1 *register_set_hdr; +#if CONFIG_IS_ENABLED(LIBCRYPTO) struct secure_hdr_v1 *secure_hdr = NULL; +#endif size_t headersz; uint8_t *image, *cur; int hasext = 0; @@ -1491,6 +1505,7 @@ static void *image_create_v1(size_t *imagesz, struct image_tool_params *params, if (main_hdr->blockid == IBR_HDR_PEX_ID) main_hdr->srcaddr = cpu_to_le32(0xFFFFFFFF); +#if CONFIG_IS_ENABLED(LIBCRYPTO) if (image_get_csk_index() >= 0) { /* * only reserve the space here; we fill the header later since @@ -1501,6 +1516,7 @@ static void *image_create_v1(size_t *imagesz, struct image_tool_params *params, *next_ext = 1; next_ext = &secure_hdr->next; } +#endif datai = 0; for (cfgi = 0; cfgi < cfgn; cfgi++) { @@ -1552,9 +1568,11 @@ static void *image_create_v1(size_t *imagesz, struct image_tool_params *params, &datai, delay); } +#if CONFIG_IS_ENABLED(LIBCRYPTO) if (secure_hdr && add_secure_header_v1(params, ptr, payloadsz + headersz, headersz, image, secure_hdr)) return NULL; +#endif *imagesz = headersz; -- 2.39.0