public inbox for u-boot@lists.denx.de
 help / color / mirror / Atom feed
From: Marek Vasut <marex@denx.de>
To: u-boot@lists.denx.de
Subject: [PATCH 5/6] env: Add option to only ever append environment
Date: Wed,  3 Jun 2020 02:01:10 +0200	[thread overview]
Message-ID: <20200603000111.7919-5-marex@denx.de> (raw)
In-Reply-To: <20200603000111.7919-1-marex@denx.de>

Add configuration option which prevents the environment hash table to be
ever cleared and reloaded with different content. This is useful in case
the first environment loaded into the hash table contains e.g. sensitive
content which must not be dropped or reloaded.

Signed-off-by: Marek Vasut <marex@denx.de>
---
 env/Kconfig     | 9 +++++++++
 env/env.c       | 2 ++
 lib/hashtable.c | 4 ++++
 3 files changed, 15 insertions(+)

diff --git a/env/Kconfig b/env/Kconfig
index ca7fef682b..8166e5df91 100644
--- a/env/Kconfig
+++ b/env/Kconfig
@@ -604,6 +604,15 @@ config DELAY_ENVIRONMENT
 	  later by U-Boot code. With CONFIG_OF_CONTROL this is instead
 	  controlled by the value of /config/load-environment.
 
+config ENV_APPEND
+	bool "Always append the environment with new data"
+	default n
+	help
+	  If defined, the environment hash table is only ever appended with new
+	  data, but the existing hash table can never be dropped and reloaded
+	  with newly imported data. This may be used in combination with static
+	  flags to e.g. to protect variables which must not be modified.
+
 config ENV_ACCESS_IGNORE_FORCE
 	bool "Block forced environment operations"
 	default n
diff --git a/env/env.c b/env/env.c
index 024d36fdbe..d85f925bcb 100644
--- a/env/env.c
+++ b/env/env.c
@@ -204,7 +204,9 @@ int env_load(void)
 		ret = drv->load();
 		if (!ret) {
 			printf("OK\n");
+#ifdef CONFIG_ENV_APPEND
 			return 0;
+#endif
 		} else if (ret == -ENOMSG) {
 			/* Handle "bad CRC" case */
 			if (best_prio == -1)
diff --git a/lib/hashtable.c b/lib/hashtable.c
index b96dbe19be..24aef5a085 100644
--- a/lib/hashtable.c
+++ b/lib/hashtable.c
@@ -822,6 +822,10 @@ int himport_r(struct hsearch_data *htab,
 	if (nvars)
 		memcpy(localvars, vars, sizeof(vars[0]) * nvars);
 
+#ifdef CONFIG_ENV_APPEND
+	flag |= H_NOCLEAR;
+#endif
+
 	if ((flag & H_NOCLEAR) == 0 && !nvars) {
 		/* Destroy old hash table if one exists */
 		debug("Destroy Hash Table: %p table = %p\n", htab,
-- 
2.25.1

  parent reply	other threads:[~2020-06-03  0:01 UTC|newest]

Thread overview: 23+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2020-06-03  0:01 [PATCH 1/6] env: Warn on force access if ENV_ACCESS_IGNORE_FORCE set Marek Vasut
2020-06-03  0:01 ` [PATCH 2/6] env: Add H_DEFAULT flag Marek Vasut
2020-06-05 19:07   ` Tom Rini
2020-06-03  0:01 ` [PATCH 3/6] env: Fix invalid env handling in env_init() Marek Vasut
2020-06-05 19:07   ` Tom Rini
2020-06-05 20:47     ` Marek Vasut
2020-06-05 21:11       ` Tom Rini
2020-06-06 14:54         ` Marek Vasut
2020-06-06 16:24           ` Tom Rini
2020-06-08 21:45             ` Marek Vasut
2020-06-08 22:57               ` Tom Rini
2020-06-09  1:50                 ` Marek Vasut
2020-06-09 15:06                   ` Tom Rini
2020-06-03  0:01 ` [PATCH 4/6] env: nowhere: Implement .load callback Marek Vasut
2020-06-05 19:07   ` Tom Rini
2020-06-03  0:01 ` Marek Vasut [this message]
2020-06-05 19:07   ` [PATCH 5/6] env: Add option to only ever append environment Tom Rini
2020-06-03  0:01 ` [PATCH 6/6] env: Add support for explicit write access list Marek Vasut
2020-06-05 19:07   ` Tom Rini
2020-06-05 20:48     ` Marek Vasut
2020-06-25 18:12   ` Harald Seiler
2020-06-25 21:42     ` Tom Rini
2020-06-05 19:07 ` [PATCH 1/6] env: Warn on force access if ENV_ACCESS_IGNORE_FORCE set Tom Rini

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20200603000111.7919-5-marex@denx.de \
    --to=marex@denx.de \
    --cc=u-boot@lists.denx.de \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox