From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-12.2 required=3.0 tests=BAYES_00,DKIM_SIGNED, DKIM_VALID,DKIM_VALID_AU,HEADER_FROM_DIFFERENT_DOMAINS,MAILING_LIST_MULTI, MENTIONS_GIT_HOSTING,SPF_HELO_NONE,SPF_PASS,USER_AGENT_SANE_1 autolearn=ham autolearn_force=no version=3.4.0 Received: from mail.kernel.org (mail.kernel.org [198.145.29.99]) by smtp.lore.kernel.org (Postfix) with ESMTP id 435BFC433F5 for ; Wed, 15 Sep 2021 13:03:08 +0000 (UTC) Received: from phobos.denx.de (phobos.denx.de [85.214.62.61]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by mail.kernel.org (Postfix) with ESMTPS id 8214A6121E for ; Wed, 15 Sep 2021 13:03:07 +0000 (UTC) DMARC-Filter: OpenDMARC Filter v1.4.1 mail.kernel.org 8214A6121E Authentication-Results: mail.kernel.org; dmarc=none (p=none dis=none) header.from=konsulko.com Authentication-Results: mail.kernel.org; spf=pass smtp.mailfrom=lists.denx.de Received: from h2850616.stratoserver.net (localhost [IPv6:::1]) by phobos.denx.de (Postfix) with ESMTP id 6DDA182C88; Wed, 15 Sep 2021 15:03:05 +0200 (CEST) Authentication-Results: phobos.denx.de; dmarc=none (p=none dis=none) header.from=konsulko.com Authentication-Results: phobos.denx.de; spf=pass smtp.mailfrom=u-boot-bounces@lists.denx.de Authentication-Results: phobos.denx.de; dkim=pass (1024-bit key; unprotected) header.d=konsulko.com header.i=@konsulko.com header.b="g86SD8cm"; dkim-atps=neutral Received: by phobos.denx.de (Postfix, from userid 109) id 7F14482D50; Wed, 15 Sep 2021 15:03:02 +0200 (CEST) Received: from mail-qk1-x729.google.com (mail-qk1-x729.google.com [IPv6:2607:f8b0:4864:20::729]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits)) (No client certificate requested) by phobos.denx.de (Postfix) with ESMTPS id 2070A82C7F for ; Wed, 15 Sep 2021 15:02:58 +0200 (CEST) Authentication-Results: phobos.denx.de; dmarc=none (p=none dis=none) header.from=konsulko.com Authentication-Results: phobos.denx.de; spf=pass smtp.mailfrom=trini@konsulko.com Received: by mail-qk1-x729.google.com with SMTP id m21so3216395qkm.13 for ; Wed, 15 Sep 2021 06:02:58 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=konsulko.com; s=google; h=date:from:to:cc:subject:message-id:references:mime-version :content-disposition:in-reply-to:user-agent; bh=mequ/mXa/Fegyw3WMn6U2GJrSBpJOiDhOhPLAp5bNmQ=; b=g86SD8cmY6ALBIjpWVl9YzN1H4waZ69vaCN2Em87wMv41MCCtuuU+xreuQJsa/rLzi K5voIWrB6d2FZsbLdtCP/zuJ8rMOKSiklUNCgmZ/ETiVCIGZL14IvKHAQLOcMfyLrso4 3Ka2VBubi77aibtEjxwddo7J7GpAeUnIcralU= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; h=x-gm-message-state:date:from:to:cc:subject:message-id:references :mime-version:content-disposition:in-reply-to:user-agent; bh=mequ/mXa/Fegyw3WMn6U2GJrSBpJOiDhOhPLAp5bNmQ=; b=S6TiEAaKpxgMNTGhHerDbEXMsWWutevYqb3357Qxbous1asiOaC1pVLQ2WKQNNPnyz GnCkfCIoZtJglj+Aqx+Vpz8SDrYQHAFSUQHznG3KxbCkK/z2WqdihJF+eSXgr/6GWmpn JwXUWz5IPTbht/OroNxhGEHfcNhkDltGMmEqJlA6HjKpc3600w5/4j/WaivM9g1jGqgi 3kdlPOr9sNwa/bXK/nNpwjMrtSUBjvYrbwUkXM9MJMDZWWIoWUdyldm4PhVZ93ONLtiu 1mlzkldsdamXDZIO/8/DobM7DnPLBpA0/x2us+/R8jCU7HKvcmuM0xUF0f+xN3lxIeYo apSw== X-Gm-Message-State: AOAM532l5pzfNleXjgLucwGjwQ7zmNYI6xPCrDTtfCdgr5iNTUPn5CdQ eTpSS2UDPVwonfLxbLXCbDQmdg== X-Google-Smtp-Source: ABdhPJwkBRlPXsLKarLSrN0XWQJ+HT1wBUV/J4xWBFkUZxQuNJ2XhN6aB17eGTv6gvY5alCmCE4o9w== X-Received: by 2002:a37:a58b:: with SMTP id o133mr9657219qke.120.1631710976790; Wed, 15 Sep 2021 06:02:56 -0700 (PDT) Received: from bill-the-cat (2603-6081-7b01-cbda-682c-a086-e3f8-65b4.res6.spectrum.com. [2603:6081:7b01:cbda:682c:a086:e3f8:65b4]) by smtp.gmail.com with ESMTPSA id a9sm10074041qko.27.2021.09.15.06.02.55 (version=TLS1_2 cipher=ECDHE-ECDSA-CHACHA20-POLY1305 bits=256/256); Wed, 15 Sep 2021 06:02:55 -0700 (PDT) Date: Wed, 15 Sep 2021 09:02:53 -0400 From: Tom Rini To: Moiz Imtiaz Cc: Simon Glass , Mark Kettenis , U-Boot Mailing List , moiz.imtiaz@skyelectric.com, Jehannaz Khan Subject: Re: Problem with U-boot | Configuration Signature not being checked while booting Message-ID: <20210915130253.GT12964@bill-the-cat> References: <561452b36639d218@bloch.sibelius.xs4all.nl> <20210911210545.GX12964@bill-the-cat> <561452f953d600b5@bloch.sibelius.xs4all.nl> <20210911213441.GY12964@bill-the-cat> <20210912150255.GZ12964@bill-the-cat> MIME-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha512; protocol="application/pgp-signature"; boundary="9lyFAvUd3a6A+HzB" Content-Disposition: inline In-Reply-To: X-Clacks-Overhead: GNU Terry Pratchett User-Agent: Mutt/1.9.4 (2018-02-28) X-BeenThere: u-boot@lists.denx.de X-Mailman-Version: 2.1.34 Precedence: list List-Id: U-Boot discussion List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: u-boot-bounces@lists.denx.de Sender: "U-Boot" X-Virus-Scanned: clamav-milter 0.103.2 at phobos.denx.de X-Virus-Status: Clean --9lyFAvUd3a6A+HzB Content-Type: text/plain; charset=us-ascii Content-Disposition: inline Content-Transfer-Encoding: quoted-printable On Mon, Sep 13, 2021 at 01:45:56AM +0500, Moiz Imtiaz wrote: > Thanks a lot Tom and U-boot Team, >=20 > What I did is that I made a control FDT (with Public_key and > signature_node) and replaced the default dtb (bcm2711-rpi-4-b.dtb) in the > boot directory of rpi_4-b(the board I am using) with the Control FDT >=20 > I compiled U-boot with "Config_OF_BOARD" and thought that since the pi > second stage bootloader is gonna decide what dtb to use, how about > replacing the default with our Contro FDT and it worked :) >=20 > [image: image.png] >=20 > It's like when I will be copying u-boot.bin in the /boot directory I will > replace the default dtb with the Control FDT. If there is any concern with > the above implementation from a security perspective (i.e manually > replacing the default dtb of pi with control FDT), please let me know so > that I can improve it. I am completely open to suggestions. >=20 > I also checked by modifying the config kernel hash and it throw rejection > and didn't boot up. > [image: changing_the_hash_verfication.png] >=20 > Kudos on the awesome writeup > > of > manual verification by modifying the hash, saved me a couple of hours of > googling :D Nice! If you want to write something up extending the documentation on how you made this work for Pi it would be much appreciated. > Also, one quick question, why do we not accept boot scripts with FIT > enabled? I really like the idea of disabling legacy image support with FIT > enabled but what is the recommended way of achieving boot scripts action > then, if we won't allow boot script for e.g loading the FIT image in memo= ry > and then booting it up with bootm? > Currently, I am using the following in my boot script. >=20 > setenv bootargs 8250.nr_uarts=3D1 console=3DttyS0,115200 root=3D/dev/mmcb= lk0p2 > > rootwait rw; > > fatload mmc 0:1 0x20000000 image.itb; > > bootm 0x20000000; >=20 >=20 > Again, thanks a lot and appreciate your input and suggestions. I believe the general reason is that we want to have the vboot build as locked down as possible. You should be able to embed the bootargs in to the FIT image, if you don't need to support some sort of A/B rootfs scheme, or in to the default U-Boot environment otherwise. --=20 Tom --9lyFAvUd3a6A+HzB Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iQGzBAABCgAdFiEEGjx/cOCPqxcHgJu/FHw5/5Y0tywFAmFB7voACgkQFHw5/5Y0 tyy87Qv+NyIRcnP3qrCr/WZT3ExBr4UauaUvIt67Djq95DM06qV5q/R8TnG2M9ce AItdhQFc0e5v/toFWb3avtSJXLRTlh04npELnJ7zeKwam5Bt/QRbZefZCB/MiI4r wAsv/gwkIzGZbAvkbx9lJdgxKtKmpyCZHUxLrC15r2kga0MAvUV1oFM+rM9A7H17 9G8Q+CaXtuVrueX92cIi69qwNwU/i5ntjcPRLhC39R6LEo6d9kroO2tZq/zX2yS3 MKmftPrFctC4xWE0eTEg9A1W9NRMImF2sIZT3bFKdZsd+LAej1EG2VpxGiN//VFu ZEUm+M470lCwBZlkghHRfeS/50/0yVsR+gWfkHMThyVbM68W0R4Wi0rw3u5mvblP aBhEsq1vqo897PX24Z4qBGDsTea/6xh6OTByMiYrmkM69z322fTj+9SFu7jUnK/M 39k4P2H6dtULFTE7e8AycclQ6TVl4c4hcrHU8iDM7PnGf15maZMqpVrnfZldyoka eruVmQFS =JC5y -----END PGP SIGNATURE----- --9lyFAvUd3a6A+HzB--