All of lore.kernel.org
 help / color / mirror / Atom feed
From: Tom Rini <trini@konsulko.com>
To: Raymond Mao <raymond.mao@linaro.org>
Cc: u-boot@lists.denx.de, manish.pandey2@arm.com,
	"Stefan Bosch" <stefan_b@posteo.net>,
	"Mario Six" <mario.six@gdsys.cc>,
	"Andy Shevchenko" <andriy.shevchenko@linux.intel.com>,
	"Michal Simek" <michal.simek@amd.com>,
	"Tuomas Tynkkynen" <tuomas.tynkkynen@iki.fi>,
	"Simon Glass" <sjg@chromium.org>,
	"Ilias Apalodimas" <ilias.apalodimas@linaro.org>,
	"Leo Yu-Chi Liang" <ycliang@andestech.com>,
	"Andrejs Cainikovs" <andrejs.cainikovs@toradex.com>,
	"Marek Vasut" <marek.vasut+renesas@mailbox.org>,
	"Sean Anderson" <seanga2@gmail.com>,
	"Jesse Taube" <mr.bossman075@gmail.com>,
	"Bryan Brattlof" <bb@ti.com>,
	"Leon M. Busch-George" <leon@georgemail.eu>,
	"Ilya Lukin" <4.shket@gmail.com>,
	"Sergei Antonov" <saproj@gmail.com>,
	"Igor Opaniuk" <igor.opaniuk@gmail.com>,
	"Heinrich Schuchardt" <xypron.glpk@gmx.de>,
	"Bin Meng" <bmeng@tinylab.org>,
	"Alper Nebi Yasak" <alpernebiyasak@gmail.com>,
	"Abdellatif El Khlifi" <abdellatif.elkhlifi@arm.com>,
	"AKASHI Takahiro" <akashi.tkhro@gmail.com>,
	"Alexander Gendin" <agendin@matrox.com>,
	"Vincent Stehlé" <vincent.stehle@arm.com>,
	"Oleksandr Suvorov" <oleksandr.suvorov@foundries.io>
Subject: Re: [PATCH v4 00/29] Integrate MbedTLS v3.6 LTS with U-Boot
Date: Tue, 23 Jul 2024 14:45:02 -0600	[thread overview]
Message-ID: <20240723204502.GJ989285@bill-the-cat> (raw)
In-Reply-To: <CAEfUkUKhso=O4oFDoJsEd=m+o-avKYvTHMDUHGQsLFQs7vpy-w@mail.gmail.com>

[-- Attachment #1: Type: text/plain, Size: 5987 bytes --]

On Tue, Jul 23, 2024 at 03:24:29PM -0400, Raymond Mao wrote:
> Hi Tom,
> 
> On Tue, 2 Jul 2024 at 21:26, Tom Rini <trini@konsulko.com> wrote:
> 
> > On Tue, Jul 02, 2024 at 11:22:36AM -0700, Raymond Mao wrote:
> >
> > > Integrate MbedTLS v3.6 LTS (currently v3.6.0-RC1) with U-Boot.
> > >
> > > Motivations:
> > > ------------
> > >
> > > 1. MbedTLS is well maintained with LTS versions.
> > > 2. LWIP is integrated with MbedTLS and easily to enable HTTPS.
> > > 3. MbedTLS recently switched license back to GPLv2.
> > >
> > > Prerequisite:
> > > -------------
> > >
> > > This patch series requires mbedtls git repo to be added as a
> > > subtree to the main U-Boot repo via:
> > >     $ git subtree add --prefix lib/mbedtls/external/mbedtls \
> > >           https://github.com/Mbed-TLS/mbedtls.git \
> > >           v3.6.0 --squash
> > > Moreover, due to the Windows-style files from mbedtls git repo,
> > > we need to convert the CRLF endings to LF and do a commit manually:
> > >     $ git add --renormalize .
> > >     $ git commit
> > >
> > > New Kconfig options:
> > > --------------------
> > >
> > > `MBEDTLS_LIB` is for MbedTLS general switch.
> > > `MBEDTLS_LIB_CRYPTO` is for replacing original digest and crypto libs
> > with
> > > MbedTLS.
> > > `MBEDTLS_LIB_X509` is for replacing original X509, PKCS7, MSCode, ASN1,
> > > and Pubkey parser with MbedTLS.
> > > `MBEDTLS_LIB_TLS` is for SSL/TLS (Disabled until LWIP port for MbedTLS is
> > > ready).
> > > `LEGACY_CRYPTO` is introduced as a main switch for legacy crypto library.
> > > `LEGACY_CRYPTO_BASIC` is for the basic crypto functionalities and
> > > `LEGACY_CRYPTO_CERT` is for the certificate related functionalities.
> > > For each of the algorithm, a pair of `<alg>_LEGACY` and `<alg>_MBEDTLS`
> > > Kconfig options are introduced. Meanwhile, `SPL_` Kconfig options are
> > > introduced.
> > >
> > > In this patch set, MBEDTLS_LIB, MBEDTLS_LIB_CRYPTO and MBEDTLS_LIB_X509
> > > are by default enabled in qemu_arm64_defconfig for testing purpose.
> > >
> > > Patches for external MbedTLS project:
> > > -------------------------------------
> > >
> > > Since U-Boot uses Microsoft Authentication Code to verify PE/COFFs
> > > executables which is not supported by MbedTLS at the moment,
> > > addtional patches for MbedTLS are created to adapt with the EFI loader:
> > > 1. Decoding of Microsoft Authentication Code.
> > > 2. Decoding of PKCS#9 Authenticate Attributes.
> > > 3. Extending MbedTLS PKCS#7 lib to support multiple signer's
> > certificates.
> > > 4. MbedTLS native test suites for PKCS#7 signer's info.
> > >
> > > All above 4 patches (tagged with `mbedtls/external`) are submitted to
> > > MbedTLS project and being reviewed, eventually they should be part of
> > > MbedTLS LTS release.
> > > But before that, please merge them into U-Boot, otherwise the building
> > > will be broken when MBEDTLS_LIB_X509 is enabled.
> > >
> > > See below PR link for the reference:
> > > https://github.com/Mbed-TLS/mbedtls/pull/9001
> > >
> > > Miscellaneous:
> > > --------------
> > >
> > > Optimized MbedTLS library size by tailoring the config file
> > > and disabling all unnecessary features for EFI loader.
> > > From v2, original libs (rsa, asn1_decoder, rsa_helper, md5, sha1, sha256,
> > > sha512) are completely replaced when MbedTLS is enabled.
> > > From v3, the size-growth is slightly reduced by refactoring Hash
> > functions.
> > >
> > > Target(QEMU arm64) size-growth when enabling MbedTLS:
> > > v1: 6.03%
> > > v2: 4.66%
> > > v3 & v4: 4.55%
> > >
> > > Please see the latest output of bloat-o-meter for the reference of the
> > > size-growth on QEMU arm64 target [1].
> > >
> > > Tests done:
> > > -----------
> > >
> > > EFI Secure Boot test (EFI variables loading and verifying, EFI signed
> > image
> > > verifying and booting) via U-Boot console.
> > > EFI Secure Boot and Capsule sandbox test passed.
> > >
> > > Known issues:
> > > -------------
> > >
> > > None.
> > >
> > > [1]: bloat-o-meter output between disabling/enabling MbedTLS (QEMU arm64)
> > > ```
> > > add/remove: 206/81 grow/shrink: 19/17 up/down: 55548/-17495 (38053)
> >
> > bloat-o-meter is a bit off then, since buildman shows:
> > u-boot: add: 243/-17, grow: 18/-17 bytes: 65723/-8480 (57243)
> >
> > (Please use buildman for the size comparisons in the future).
> >
> 
> I have a problem with buildman.
> As I followed the buildman/README.rst and run below command, but cannot get
> any
> output size summary. Is anything missing? I saw some artifacts of building
> each
> commit being generated in the upper dir though.
> ```
> ./tools/buildman/buildman -b <my_branch_name> --boards qemu_arm64 -sSdB
> ```
> I have set my branch upstream to upstream/next.

You have to tell it twice, once to build and a second to summarize
things. My wrapper looks like:
#!/bin/bash

# Initial and constant buildman args
ARGS="-devl -PEWM"
ALL=0
KEEP=0

# Find our arguments
while test $# -ne 0; do
	if [ "$1" == "--all" ]; then
		ALL=1
		shift 1
	elif [ "$1" == "--branch" ]; then
		BRANCH=$2
		shift 2
	elif [ "$1" == "--keep" ]; then
		KEEP=1
		ARGS="$ARGS -k"
		shift 1
	elif [ "$1" == "--board" ]; then
		MACHINE="--board $2"
		OUTDIR=/tmp/$2
		shift 2
	else
		MACHINE=$1
		shift 1
	fi
done

OUTDIR=${OUTDIR:-/tmp/$MACHINE}

if [ -z "$MACHINE" ]; then
	echo Usage: $0 MACHINE [--all] [--keep] [--branch BRANCH]
	exit 1
fi

# If not all, then only first/last
if [ $ALL -ne 1 ]; then
	ARGS="$ARGS --step 0"
fi

if [ ! -z $BRANCH ]; then
	ARGS="$ARGS -b $BRANCH"
else
	ARGS="$ARGS -b `git rev-parse --abbrev-ref HEAD`"
fi

mkdir -p ${OUTDIR}

export SOURCE_DATE_EPOCH=`date +%s`
./tools/buildman/buildman -o ${OUTDIR} $ARGS -SBC $MACHINE
./tools/buildman/buildman -o ${OUTDIR} $ARGS -SsB $MACHINE

[ $KEEP -eq 0 ] && rm -rf ${OUTDIR}

-- 
Tom

[-- Attachment #2: signature.asc --]
[-- Type: application/pgp-signature, Size: 659 bytes --]

  reply	other threads:[~2024-07-23 20:45 UTC|newest]

Thread overview: 81+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2024-07-02 18:22 [PATCH v4 00/29] Integrate MbedTLS v3.6 LTS with U-Boot Raymond Mao
2024-07-02 18:22 ` [PATCH v4 01/29] CI: Exclude MbedTLS subtree for CONFIG checks Raymond Mao
2024-07-02 18:22 ` [PATCH v4 02/29] mbedtls: Add script to update MbedTLS subtree Raymond Mao
2024-07-02 20:56   ` Tom Rini
2024-07-03  7:16     ` Jerome Forissier
2024-07-03 14:36       ` Raymond Mao
2024-07-03 14:35     ` Raymond Mao
2024-07-02 18:22 ` [PATCH v4 03/29] mbedtls: add mbedtls into the build system Raymond Mao
2024-07-02 18:22 ` [PATCH v4 04/29] lib: Adapt digest header files to MbedTLS Raymond Mao
2024-07-02 22:48   ` Tom Rini
2024-07-03  0:02     ` Raymond Mao
2024-07-03  0:15       ` Tom Rini
2024-07-02 18:22 ` [PATCH v4 05/29] md5: Remove md5 non-watchdog API Raymond Mao
2024-07-02 18:22 ` [PATCH v4 06/29] sha1: Remove sha1 " Raymond Mao
2024-07-03  7:39   ` Ilias Apalodimas
2024-07-02 18:22 ` [PATCH v4 07/29] mbedtls: add digest shim layer for MbedTLS Raymond Mao
2024-07-26 10:18   ` Ilias Apalodimas
2024-07-26 14:01     ` Tom Rini
2024-07-26 14:29     ` Raymond Mao
2024-07-02 18:22 ` [PATCH v4 08/29] hash: integrate hash on mbedtls Raymond Mao
2024-07-03  8:56   ` Ilias Apalodimas
2024-07-05  8:35     ` Simon Glass
2024-07-18 16:45       ` Raymond Mao
2024-07-19 15:05         ` Simon Glass
2024-07-19 15:25           ` Tom Rini
2024-07-20 12:36             ` Simon Glass
2024-07-20 17:13               ` Tom Rini
2024-07-21 10:08                 ` Simon Glass
2024-07-22 14:21                 ` Raymond Mao
2024-07-22 14:35               ` Raymond Mao
2024-07-18 16:49     ` Raymond Mao
2024-07-02 18:22 ` [PATCH v4 09/29] makefile: add mbedtls include directories Raymond Mao
2024-07-03 11:34   ` Ilias Apalodimas
2024-07-18 20:01     ` Raymond Mao
2024-07-18 20:12     ` Raymond Mao
2024-07-23  7:44       ` Ilias Apalodimas
2024-07-23 17:05         ` Raymond Mao
2024-07-02 18:22 ` [PATCH v4 10/29] mbedtls/external: support Microsoft Authentication Code Raymond Mao
2024-07-02 18:22 ` [PATCH v4 11/29] mbedtls/external: support PKCS9 Authenticate Attributes Raymond Mao
2024-07-02 18:22 ` [PATCH v4 12/29] mbedtls/external: support decoding multiple signer's cert Raymond Mao
2024-07-02 18:22 ` [PATCH v4 13/29] mbedtls/external: update MbedTLS PKCS7 test suites Raymond Mao
2024-07-02 18:22 ` [PATCH v4 14/29] public_key: move common functions to public key helper Raymond Mao
2024-07-03 11:31   ` Ilias Apalodimas
2024-07-02 18:22 ` [PATCH v4 15/29] x509: move common functions to x509 helper Raymond Mao
2024-07-03  9:36   ` Ilias Apalodimas
2024-07-02 18:22 ` [PATCH v4 16/29] pkcs7: move common functions to PKCS7 helper Raymond Mao
2024-07-03  9:33   ` Ilias Apalodimas
2024-07-02 18:22 ` [PATCH v4 17/29] mbedtls: add public key porting layer Raymond Mao
2024-07-03 11:46   ` Ilias Apalodimas
2024-07-18 20:39     ` Raymond Mao
2024-07-02 18:22 ` [PATCH v4 18/29] lib/crypto: Adapt public_key header with MbedTLS Raymond Mao
2024-07-29 13:28   ` Ilias Apalodimas
2024-07-02 18:22 ` [PATCH v4 19/29] mbedtls: add X509 cert parser porting layer Raymond Mao
2024-07-02 18:22 ` [PATCH v4 20/29] lib/crypto: Adapt x509_cert_parser to MbedTLS Raymond Mao
2024-07-29 13:19   ` Ilias Apalodimas
2024-07-29 13:55     ` Raymond Mao
2024-07-02 18:22 ` [PATCH v4 21/29] mbedtls: add PKCS7 parser porting layer Raymond Mao
2024-07-02 18:22 ` [PATCH v4 22/29] lib/crypto: Adapt PKCS7 parser to MbedTLS Raymond Mao
2024-07-02 18:22 ` [PATCH v4 23/29] mbedtls: add MSCode parser porting layer Raymond Mao
2024-07-26 10:09   ` Ilias Apalodimas
2024-07-26 14:04     ` Raymond Mao
2024-07-02 18:23 ` [PATCH v4 24/29] lib/crypto: Adapt mscode_parser to MbedTLS Raymond Mao
2024-07-30  8:03   ` Ilias Apalodimas
2024-07-30 14:07     ` Raymond Mao
2024-07-02 18:23 ` [PATCH v4 25/29] mbedtls: add RSA helper layer on MbedTLS Raymond Mao
2024-07-30  8:04   ` Ilias Apalodimas
2024-07-30 14:05     ` Raymond Mao
2024-07-02 18:23 ` [PATCH v4 26/29] lib/rypto: Adapt rsa_helper to MbedTLS Raymond Mao
2024-07-23  9:14   ` Ilias Apalodimas
2024-07-02 18:23 ` [PATCH v4 27/29] asn1_decoder: add build options for ASN1 decoder Raymond Mao
2024-07-02 18:23 ` [PATCH v4 28/29] test: Remove ASN1 library test Raymond Mao
2024-07-02 18:23 ` [PATCH v4 29/29] configs: enable MbedTLS as default setting Raymond Mao
2024-07-03 11:56   ` Ilias Apalodimas
2024-07-03  1:25 ` [PATCH v4 00/29] Integrate MbedTLS v3.6 LTS with U-Boot Tom Rini
2024-07-23 19:24   ` Raymond Mao
2024-07-23 20:45     ` Tom Rini [this message]
2024-07-24 14:36       ` Simon Glass
2024-07-24 14:34   ` Raymond Mao
2024-07-24 14:37     ` Simon Glass
2024-07-24 22:42     ` Tom Rini
2024-07-25 13:36       ` Raymond Mao

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20240723204502.GJ989285@bill-the-cat \
    --to=trini@konsulko.com \
    --cc=4.shket@gmail.com \
    --cc=abdellatif.elkhlifi@arm.com \
    --cc=agendin@matrox.com \
    --cc=akashi.tkhro@gmail.com \
    --cc=alpernebiyasak@gmail.com \
    --cc=andrejs.cainikovs@toradex.com \
    --cc=andriy.shevchenko@linux.intel.com \
    --cc=bb@ti.com \
    --cc=bmeng@tinylab.org \
    --cc=igor.opaniuk@gmail.com \
    --cc=ilias.apalodimas@linaro.org \
    --cc=leon@georgemail.eu \
    --cc=manish.pandey2@arm.com \
    --cc=marek.vasut+renesas@mailbox.org \
    --cc=mario.six@gdsys.cc \
    --cc=michal.simek@amd.com \
    --cc=mr.bossman075@gmail.com \
    --cc=oleksandr.suvorov@foundries.io \
    --cc=raymond.mao@linaro.org \
    --cc=saproj@gmail.com \
    --cc=seanga2@gmail.com \
    --cc=sjg@chromium.org \
    --cc=stefan_b@posteo.net \
    --cc=tuomas.tynkkynen@iki.fi \
    --cc=u-boot@lists.denx.de \
    --cc=vincent.stehle@arm.com \
    --cc=xypron.glpk@gmx.de \
    --cc=ycliang@andestech.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.