From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from mail.kernel.org (mail.kernel.org [198.145.29.99]) by smtp.lore.kernel.org (Postfix) with ESMTP id 8E25EC433FE for ; Tue, 26 Oct 2021 06:00:24 +0000 (UTC) Received: from phobos.denx.de (phobos.denx.de [85.214.62.61]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by mail.kernel.org (Postfix) with ESMTPS id 0B34461074 for ; Tue, 26 Oct 2021 06:00:23 +0000 (UTC) DMARC-Filter: OpenDMARC Filter v1.4.1 mail.kernel.org 0B34461074 Authentication-Results: mail.kernel.org; dmarc=fail (p=none dis=none) header.from=linaro.org Authentication-Results: mail.kernel.org; spf=pass smtp.mailfrom=lists.denx.de Received: from h2850616.stratoserver.net (localhost [IPv6:::1]) by phobos.denx.de (Postfix) with ESMTP id BEC7E80F5F; Tue, 26 Oct 2021 08:00:21 +0200 (CEST) Authentication-Results: phobos.denx.de; dmarc=pass (p=none dis=none) header.from=linaro.org Authentication-Results: phobos.denx.de; spf=pass smtp.mailfrom=u-boot-bounces@lists.denx.de Authentication-Results: phobos.denx.de; dkim=pass (2048-bit key; unprotected) header.d=linaro.org header.i=@linaro.org header.b="UV0POy6F"; dkim-atps=neutral Received: by phobos.denx.de (Postfix, from userid 109) id 2A95083395; Tue, 26 Oct 2021 08:00:20 +0200 (CEST) Received: from mail-pj1-x102f.google.com (mail-pj1-x102f.google.com [IPv6:2607:f8b0:4864:20::102f]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits)) (No client certificate requested) by phobos.denx.de (Postfix) with ESMTPS id 7380F807CD for ; Tue, 26 Oct 2021 08:00:15 +0200 (CEST) Authentication-Results: phobos.denx.de; dmarc=pass (p=none dis=none) header.from=linaro.org Authentication-Results: phobos.denx.de; spf=pass smtp.mailfrom=takahiro.akashi@linaro.org Received: by mail-pj1-x102f.google.com with SMTP id na16-20020a17090b4c1000b0019f5bb661f9so812668pjb.0 for ; Mon, 25 Oct 2021 23:00:15 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linaro.org; s=google; h=date:from:to:subject:message-id:mail-followup-to:references :mime-version:content-disposition:in-reply-to; bh=RsEI1sD2wR3MLrDpEExmOrH1c4NfF5sRrWv5N0DnYT0=; b=UV0POy6FXDvrgIFdbtqYIGNtPJeT8Ym7klRk6ibCRlnG+wsFZXSVV8GSOIM7nRH8gw XrnDXTt2gbCTNFqFlajkhjGw1qfJ9s2ZYVIIU3Bu6ut1eMHtMV4vU3arIJik0dci2V5Y adl+5EV7Ay+yfAAgiihE88UPcyxjI7COf8c2UaNanOMcYTaPjLeZUJelP7zqJN4RuHG1 73dR5RlI4mreT+3c1va16VqFRyYxO4vDnppEfFeKIDEsrZj+f1a20kI0WsUl6z9hfPxQ NZJRc1AYqR40fld8mdWmTERtfGWxY70I6JsRao3Qy/tV8b1ER5AbK9erkwC4jwJOXWf7 vl/A== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; h=x-gm-message-state:date:from:to:subject:message-id:mail-followup-to :references:mime-version:content-disposition:in-reply-to; bh=RsEI1sD2wR3MLrDpEExmOrH1c4NfF5sRrWv5N0DnYT0=; b=vcn64bdm24zpbCmH+zh3eSATdLzDGj85bSIh3md4Jc+aggNrGRiuteXjQ0bWFsg0NZ UVnDVCuYeldRMKrn1zc2rm3xOM2NkSBXg28qIfYqqpV0R8t8tTGLDcDE7AVJLA7EWFzl 2Y9M+F+1D0gzfdgqcKpwFCdR/pkoMhE2MpfCZXfwxWTmQIBcvluvhbRDkBrOL4OQFKb0 m3b0wrvqi+RsN6o9rjg4xXz+ZvdPn7mjVn9r7OeoiXzsgvcCUG9VltIK0KDFYCVz0SJe rt3uFw53tCzosfHfswmwhWXQ0Jg+ze1s4d2agvq7l45JLFuMc2EkbCrdA0dKvMTwMuWr nyqQ== X-Gm-Message-State: AOAM531IzptB/hQXlWCJsmT+JkzpaLEyLIpXKMwsSKOFOQf/M7mAKiIi WNxmnSjMHBMq1dPUwlcRp1RGiQ== X-Google-Smtp-Source: ABdhPJyWFPV4noNaecuB/ldMCLPRYFhScVA7mxDK14t079hwrQ7rPTtqy7Mdr2bq/RkmvSMXstVo4g== X-Received: by 2002:a17:903:246:b0:13f:2ff9:8b93 with SMTP id j6-20020a170903024600b0013f2ff98b93mr20870984plh.54.1635228013439; Mon, 25 Oct 2021 23:00:13 -0700 (PDT) Received: from laputa ([2400:4050:c3e1:100:9448:fba4:46e9:6cc8]) by smtp.gmail.com with ESMTPSA id n19sm6109680pjq.40.2021.10.25.23.00.10 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 25 Oct 2021 23:00:13 -0700 (PDT) Date: Tue, 26 Oct 2021 15:00:08 +0900 From: AKASHI Takahiro To: Simon Glass , Heinrich Schuchardt , Alex Graf , Ilias Apalodimas , Sughosh Ganu , Masami Hiramatsu , U-Boot Mailing List Subject: Re: [PATCH v4 04/11] tools: add fdtsig.sh Message-ID: <20211026060008.GB39112@laputa> Mail-Followup-To: AKASHI Takahiro , Simon Glass , Heinrich Schuchardt , Alex Graf , Ilias Apalodimas , Sughosh Ganu , Masami Hiramatsu , U-Boot Mailing List References: <20211007062340.72207-1-takahiro.akashi@linaro.org> <20211007062340.72207-5-takahiro.akashi@linaro.org> <20211012014212.GC38222@laputa> <20211025030639.GA44989@laputa> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <20211025030639.GA44989@laputa> X-BeenThere: u-boot@lists.denx.de X-Mailman-Version: 2.1.34 Precedence: list List-Id: U-Boot discussion List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: u-boot-bounces@lists.denx.de Sender: "U-Boot" X-Virus-Scanned: clamav-milter 0.103.2 at phobos.denx.de X-Virus-Status: Clean On Mon, Oct 25, 2021 at 12:06:39PM +0900, AKASHI Takahiro wrote: > Simon, > > On Thu, Oct 14, 2021 at 06:40:24PM -0600, Simon Glass wrote: > > Hi Takahiro, > > > > On Mon, 11 Oct 2021 at 19:42, AKASHI Takahiro > > wrote: > > > > > > Simon, > > > > > > On Mon, Oct 11, 2021 at 08:54:09AM -0600, Simon Glass wrote: > > > > Hi Takahiro, > > > > > > > > On Thu, 7 Oct 2021 at 00:25, AKASHI Takahiro wrote: > > > > > > > > > > With this script, a public key is added to a device tree blob > > > > > as the default efi_get_public_key_data() expects. > > > > > > > > > > Signed-off-by: AKASHI Takahiro > > > > > --- > > > > > MAINTAINERS | 1 + > > > > > tools/fdtsig.sh | 40 ++++++++++++++++++++++++++++++++++++++++ > > > > > 2 files changed, 41 insertions(+) > > > > > create mode 100755 tools/fdtsig.sh > > > > > > > > Instead of an ad-hoc script with no tests, > > > > > > Basically I intended to provide fdtsig.sh as a *sample* script so that > > > people may want to integrate the logic into their own build rule/systems. > > > But I could use this script in my 'capsule authentication' test > > > that is also added in patch#22. > > > > > > > could we use binman for > > > > putting the image together and inserting it? > > > > > > First, as you can see, the script is quite simple and secondly, > > > the purpose of binman, IIUC, is to help handle/manipulate U-Boot > > > image binaries. > > > So I'm not sure whether it is really useful to add such a feature to binman. > > > > I'm not sure. The script seems very ad-hoc to me, for a feature that > > Linaro is pushing so hard. > > To be honest, I've never used binman :) So I'm not sure whether binman > is the best place to add this feature. For example, README under tools/binman > says, "It seems better to use the mkimage tool to generate binaries and avoid > blurring the boundaries between building input files (mkimage) and packaging > then into a final image (binman)." > Obviously, dtb is not the final image. > > > I don't see where the script is used in the tests or even mentioned in > > the documentation. Am I missing something? > > Due to the history of submissions of this series, the current pytest > scenario doesn't use the script, but you can see the exact same > sequence of commands at test/py/tests/test_efi_capsule/conftest.py: > ---8<--- > # Update dtb adding capsule certificate > check_call('cd %s; cp %s/test/py/tests/test_efi_capsule/signature.dts .' > % (data_dir, u_boot_config.source_dir), shell=True) > check_call('cd %s; dtc -@ -I dts -O dtb -o signature.dtbo signature.dts; fdtoverlay -i %s/arch/sandbox/dts/test.dtb -o test_sig.dtb signature.dtbo' > % (data_dir, u_boot_config.build_dir), shell=True) > --->8--- > (Please see my patch#11.) > > What I meant is that we can directly use fdtsig.sh here if your concern > is that the script is *not exercised* anywhere. Besides binman or fdtsig.sh, I found that the crucial information was missing here; the format or how a public key is encoded in a device tree. With an example of command sequence, we may drop this patch. So will adding some description to uefi.rst satisfy your needs, or do you expect an extra rule for embedding a key to be added in some Makefile? (I don't think this step is part of build process, though.) -Takahiro Akashi > -Takahiro Akashi > > > Regards, > > Simon