* [PATCH] mkimage: Allow 'auto-conf' signing of scripts
@ 2024-06-20 14:20 Alexander Dahl
2024-07-05 22:39 ` Tom Rini
0 siblings, 1 reply; 2+ messages in thread
From: Alexander Dahl @ 2024-06-20 14:20 UTC (permalink / raw)
To: u-boot; +Cc: Massimo Pegorer, Tom Rini, Simon Glass, Sean Anderson
U-Boot configured for verified boot with the "required" option set to
"conf" also checks scripts put in FIT images for a valid signature, and
refuses to source and run such a script if the signature for the
configuration is bad or missing. Such a script could not be packaged
before, because mkimage failed like this:
% tools/mkimage -T script -C none -d tmp/my.scr -f auto-conf -k tmp -g dev -o sha256,rsa4096 my.uimg
Failed to find any images for configuration 'conf-1/signature'
tools/mkimage Can't add hashes to FIT blob: -1
Error: Bad parameters for FIT image type
This is especially unfortunate if LEGACY_IMAGE_FORMAT is disabled as
recommended.
Listing the script configuration in a "sign-images" subnode instead,
would have added even more complexity to the already complex auto fit
generation code.
Signed-off-by: Alexander Dahl <ada@thorsis.com>
---
tools/image-host.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/tools/image-host.c b/tools/image-host.c
index 7bfc0cb6b18..49ce7436bb9 100644
--- a/tools/image-host.c
+++ b/tools/image-host.c
@@ -730,7 +730,7 @@ static const char *fit_config_get_image_list(const void *fit, int noffset,
int *lenp, int *allow_missingp)
{
static const char default_list[] = FIT_KERNEL_PROP "\0"
- FIT_FDT_PROP;
+ FIT_FDT_PROP "\0" FIT_SCRIPT_PROP;
const char *prop;
/* If there is an "sign-image" property, use that */
base-commit: fe2ce09a0753634543c32cafe85eb87a625f76ca
--
2.39.2
^ permalink raw reply related [flat|nested] 2+ messages in thread
* Re: [PATCH] mkimage: Allow 'auto-conf' signing of scripts
2024-06-20 14:20 [PATCH] mkimage: Allow 'auto-conf' signing of scripts Alexander Dahl
@ 2024-07-05 22:39 ` Tom Rini
0 siblings, 0 replies; 2+ messages in thread
From: Tom Rini @ 2024-07-05 22:39 UTC (permalink / raw)
To: Alexander Dahl; +Cc: u-boot, Massimo Pegorer, Simon Glass, Sean Anderson
[-- Attachment #1: Type: text/plain, Size: 1050 bytes --]
On Thu, Jun 20, 2024 at 04:20:59PM +0200, Alexander Dahl wrote:
> U-Boot configured for verified boot with the "required" option set to
> "conf" also checks scripts put in FIT images for a valid signature, and
> refuses to source and run such a script if the signature for the
> configuration is bad or missing. Such a script could not be packaged
> before, because mkimage failed like this:
>
> % tools/mkimage -T script -C none -d tmp/my.scr -f auto-conf -k tmp -g dev -o sha256,rsa4096 my.uimg
> Failed to find any images for configuration 'conf-1/signature'
> tools/mkimage Can't add hashes to FIT blob: -1
> Error: Bad parameters for FIT image type
>
> This is especially unfortunate if LEGACY_IMAGE_FORMAT is disabled as
> recommended.
>
> Listing the script configuration in a "sign-images" subnode instead,
> would have added even more complexity to the already complex auto fit
> generation code.
>
> Signed-off-by: Alexander Dahl <ada@thorsis.com>
Applied to u-boot/master, thanks!
--
Tom
[-- Attachment #2: signature.asc --]
[-- Type: application/pgp-signature, Size: 659 bytes --]
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2024-07-05 22:39 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2024-06-20 14:20 [PATCH] mkimage: Allow 'auto-conf' signing of scripts Alexander Dahl
2024-07-05 22:39 ` Tom Rini
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.