From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-12.2 required=3.0 tests=BAYES_00,DKIM_SIGNED, DKIM_VALID,DKIM_VALID_AU,HEADER_FROM_DIFFERENT_DOMAINS,INCLUDES_CR_TRAILER, MAILING_LIST_MULTI,SPF_HELO_NONE,SPF_PASS,URIBL_BLOCKED,USER_AGENT_SANE_1 autolearn=ham autolearn_force=no version=3.4.0 Received: from mail.kernel.org (mail.kernel.org [198.145.29.99]) by smtp.lore.kernel.org (Postfix) with ESMTP id EA776C4338F for ; Thu, 5 Aug 2021 01:19:01 +0000 (UTC) Received: from phobos.denx.de (phobos.denx.de [85.214.62.61]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by mail.kernel.org (Postfix) with ESMTPS id C81E360F25 for ; Thu, 5 Aug 2021 01:19:00 +0000 (UTC) DMARC-Filter: OpenDMARC Filter v1.4.1 mail.kernel.org C81E360F25 Authentication-Results: mail.kernel.org; dmarc=none (p=none dis=none) header.from=konsulko.com Authentication-Results: mail.kernel.org; spf=pass smtp.mailfrom=lists.denx.de Received: from h2850616.stratoserver.net (localhost [IPv6:::1]) by phobos.denx.de (Postfix) with ESMTP id 2531C82C47; Thu, 5 Aug 2021 03:18:58 +0200 (CEST) Authentication-Results: phobos.denx.de; dmarc=none (p=none dis=none) header.from=konsulko.com Authentication-Results: phobos.denx.de; spf=pass smtp.mailfrom=u-boot-bounces@lists.denx.de Authentication-Results: phobos.denx.de; dkim=pass (1024-bit key; unprotected) header.d=konsulko.com header.i=@konsulko.com header.b="bBMfu0hd"; dkim-atps=neutral Received: by phobos.denx.de (Postfix, from userid 109) id 168F382C40; Thu, 5 Aug 2021 03:18:56 +0200 (CEST) Received: from mail-qt1-x836.google.com (mail-qt1-x836.google.com [IPv6:2607:f8b0:4864:20::836]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits)) (No client certificate requested) by phobos.denx.de (Postfix) with ESMTPS id 38DD882BEC for ; Thu, 5 Aug 2021 03:18:53 +0200 (CEST) Authentication-Results: phobos.denx.de; dmarc=none (p=none dis=none) header.from=konsulko.com Authentication-Results: phobos.denx.de; spf=pass smtp.mailfrom=trini@konsulko.com Received: by mail-qt1-x836.google.com with SMTP id m11so2779823qtx.7 for ; Wed, 04 Aug 2021 18:18:53 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=konsulko.com; s=google; h=date:from:to:cc:subject:message-id:references:mime-version :content-disposition:in-reply-to:user-agent; bh=dg1nqxU1A1hxCrEXvNgJesIBwdHYaPZlF5HCQ09fLc4=; b=bBMfu0hd8ZmeAHwxuASQm1/WNJGSRKKdDEsjICYf7AHtsdSkG+KSoBvAqD5g2kx1r5 A6/oXiYAaPLGop+iSIkbqvCGUafLhzmVuKhbDLSVEBYjHuO8eeDcy785Zl45t3s1+BZC 6poeGClRVNUzsJr9VtcXaSZGw4tr4D3evuj+o= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:date:from:to:cc:subject:message-id:references :mime-version:content-disposition:in-reply-to:user-agent; bh=dg1nqxU1A1hxCrEXvNgJesIBwdHYaPZlF5HCQ09fLc4=; b=pDAN6alEpMYqo0qH65/vOW36YhQNUL3u7+QvGNOYuATwJwM1hzyw/+Shqv3h+Eecp/ xO+gq89h25YOXGsLssl6Wjmbwd72lMHsX+t9HhP/39kURFwwtUD23pA5Sna+XkV2N2wf ytOdCOEluoKQEBW1YOSbj+IUAym17Yfnkz8AQzThxevq46Ap1GrsbbEAm4D5SSJk5VWm P6Qc7vQcVhkYQm6JHVkmZ02B83n+b/MlF1NihdRCQkDZdP1/NZmJgjU6wB+328WyQ45n JIFRt78AWE1DSLjm/U2g9UauKfqTRs2Z6KwUBQnFQEEQMmCHs1bm0h3bt6jfGcl63SnX d+Lg== X-Gm-Message-State: AOAM532rOYdIC7rIoYxuI8ZpF2Ye1145Audn2P50R+l9Kreoz86pD49I I/lu35/oD0+g7Jn3vSTLVrmj9ViG0etCDg== X-Google-Smtp-Source: ABdhPJyemrunRovPFKjIHVzvp7MjNIdskG0wNbdZA696W4IvBVChJY2CAhOzbMmizk1woMzrV9FFog== X-Received: by 2002:ac8:7695:: with SMTP id g21mr2287307qtr.83.1628126331881; Wed, 04 Aug 2021 18:18:51 -0700 (PDT) Received: from bill-the-cat (2603-6081-7b01-cbda-a9d9-7fe0-6131-a526.res6.spectrum.com. [2603:6081:7b01:cbda:a9d9:7fe0:6131:a526]) by smtp.gmail.com with ESMTPSA id r4sm1670856qtc.66.2021.08.04.18.18.50 (version=TLS1_2 cipher=ECDHE-ECDSA-CHACHA20-POLY1305 bits=256/256); Wed, 04 Aug 2021 18:18:51 -0700 (PDT) Date: Wed, 4 Aug 2021 21:18:48 -0400 From: Tom Rini To: John Keeping Cc: u-boot@lists.denx.de Subject: Re: [PATCH] fit: Fix verification of images with external data Message-ID: <20210805011848.GD858@bill-the-cat> References: <20210420181944.3945713-1-john@metanate.com> MIME-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha512; protocol="application/pgp-signature"; boundary="DrWhICOqskFTAXiy" Content-Disposition: inline In-Reply-To: <20210420181944.3945713-1-john@metanate.com> X-Clacks-Overhead: GNU Terry Pratchett User-Agent: Mutt/1.9.4 (2018-02-28) X-BeenThere: u-boot@lists.denx.de X-Mailman-Version: 2.1.34 Precedence: list List-Id: U-Boot discussion List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: u-boot-bounces@lists.denx.de Sender: "U-Boot" X-Virus-Scanned: clamav-milter 0.103.2 at phobos.denx.de X-Virus-Status: Clean --DrWhICOqskFTAXiy Content-Type: text/plain; charset=us-ascii Content-Disposition: inline Content-Transfer-Encoding: quoted-printable On Tue, Apr 20, 2021 at 07:19:44PM +0100, John Keeping wrote: > The "-E" option to mkimage generates a FIT with external data using the > data-size and data-offset properties which must both be ignored when > verifying a signature. >=20 > Add "data-offset" to the list of excluded properties for signature > verification; since the line is now too long, re-format the list to > one-per-line and make it static since the data is constant. >=20 > Signed-off-by: John Keeping > Reviewed-by: Simon Glass Applied to u-boot/master, thanks! --=20 Tom --DrWhICOqskFTAXiy Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iQGzBAABCgAdFiEEGjx/cOCPqxcHgJu/FHw5/5Y0tywFAmELPHQACgkQFHw5/5Y0 tyyWigv/V8iZhWh6ujiA/lV0MxP8jbGYQEzU3cMeh9XsEZ8zC3ZVuMZArRyHnyFh Gd69NkGoJftv3S23wNsK3kX3njFvbF4KXFI7VByP8yXin/0vWsiedLbRyj1H6xdf aM3Xm3qqhRdjv+rFQGHuGF1HGQb2AondhULJVrlR7+k+ckFKHG9T6Otizqc63qEy +sES2jSA/+sJ4yeu9RyuNavvOoy4JkmB60UyOncJYoOIBQ6mXz1tgHqOp6f6i9hT agrIv1q5t/67P6yOwV8iEwtUvoc/hCD9qDIsoHviwR9P2JezEq3dBQvcV35Qg1iu /I/bZ0IJU4deV/0zCXuP5DNKGrOaMdHPigIQ94Obwu47lZpoD3yfdIo0LlWep8SS Fe+YZVRRzmzU30oxbH0EADAJX3L5D4Mq5xUyO/NKthxc/s5icb1/W5rCEn37O4/R Q65LQfN3pMQWLyPAcZuF3EzLv0KshHoXxWkc0ZdrN46zSdbr1zl3Q/ftxo7VCIiu nS4RXibh =/AtK -----END PGP SIGNATURE----- --DrWhICOqskFTAXiy--