From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from mail.kernel.org (mail.kernel.org [198.145.29.99]) by smtp.lore.kernel.org (Postfix) with ESMTP id D303EC433F5 for ; Thu, 4 Nov 2021 02:59:59 +0000 (UTC) Received: from phobos.denx.de (phobos.denx.de [85.214.62.61]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by mail.kernel.org (Postfix) with ESMTPS id 13D9361050 for ; Thu, 4 Nov 2021 02:59:59 +0000 (UTC) DMARC-Filter: OpenDMARC Filter v1.4.1 mail.kernel.org 13D9361050 Authentication-Results: mail.kernel.org; dmarc=fail (p=none dis=none) header.from=linaro.org Authentication-Results: mail.kernel.org; spf=pass smtp.mailfrom=lists.denx.de Received: from h2850616.stratoserver.net (localhost [IPv6:::1]) by phobos.denx.de (Postfix) with ESMTP id E1B1883645; Thu, 4 Nov 2021 03:59:56 +0100 (CET) Authentication-Results: phobos.denx.de; dmarc=pass (p=none dis=none) header.from=linaro.org Authentication-Results: phobos.denx.de; spf=pass smtp.mailfrom=u-boot-bounces@lists.denx.de Authentication-Results: phobos.denx.de; dkim=pass (2048-bit key; unprotected) header.d=linaro.org header.i=@linaro.org header.b="jZX94UOh"; dkim-atps=neutral Received: by phobos.denx.de (Postfix, from userid 109) id 2E7AB83645; Thu, 4 Nov 2021 03:59:55 +0100 (CET) Received: from mail-pg1-x529.google.com (mail-pg1-x529.google.com [IPv6:2607:f8b0:4864:20::529]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits)) (No client certificate requested) by phobos.denx.de (Postfix) with ESMTPS id 44C4183434 for ; Thu, 4 Nov 2021 03:59:51 +0100 (CET) Authentication-Results: phobos.denx.de; dmarc=pass (p=none dis=none) header.from=linaro.org Authentication-Results: phobos.denx.de; spf=pass smtp.mailfrom=takahiro.akashi@linaro.org Received: by mail-pg1-x529.google.com with SMTP id p17so4171807pgj.2 for ; Wed, 03 Nov 2021 19:59:51 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linaro.org; s=google; h=date:from:to:cc:subject:message-id:mail-followup-to:references :mime-version:content-disposition:in-reply-to; bh=rzKPaDZoOLwYQdEWzS65wvSkvN+mo0dxfXAzEasuKfw=; b=jZX94UOhpy3yJWON8K4jeu5WVZ8aknUvI53jI9Mlvg+gRpl0LfXivTcH6sZqsQWAyY I2noO9vaLkluCoriwLCJDBYEAJEqb+359BdVqFQnuHpKbXVb3BJa/D5fmrLKV0j0E/ql IUtwkgrLy523RKRgbgG22er9I3YAmd80P1eOQjaLLmwkrWh4eodtBrio7ZQApJzS7FHE MCicolnJMLZlPjgAdA/0H+rnTbKo4HdxxS4A1QCL5vAxYVW0lCq2Nhhhbl05P0vdksMP SVv8iIxbOdR/s44aG/wOJZ8h8IqvZYE7YwyFnNVxj4l8nQJSEDYjv/vDCmB+eAypn1Zs gGWw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; h=x-gm-message-state:date:from:to:cc:subject:message-id :mail-followup-to:references:mime-version:content-disposition :in-reply-to; bh=rzKPaDZoOLwYQdEWzS65wvSkvN+mo0dxfXAzEasuKfw=; b=3R//wrr6cDRV1a4bVBqt65mic5wwrsG1T90jg/af3sYi5av/Jnwx5n/fsWFkwO9eZY Bq/6hdWHYiP3UybY3UqrWRc74fgFz0Lw3bXBXiXQAa+t9NUaXzrGDT5zC+Wqu8LKHqCU 2e0veXpq+823ckDncMocQdTKH/DTm93pYoSliYg/L5YuGWx6DLLd5NKvp2vJYx5WTVUT ic0XucAjN/IlYxEEB+IrrJ/6/p5prp7uh7DTnsYzQto1lRO+ZutjrNUvb71aA4FOTeGu qTA1ZCA8hHyuqGAirkuX8VnEC8VSucvhFjYD9bOHD3CA4hrjzRywxuAaAPeMlvG6GoST TN2g== X-Gm-Message-State: AOAM5315FO/DDG6wAZ4zku8+TUDoXFJOQzEpJBcaMqZZJey/BfbhuJSp hPJysSXdiHb9U3Yy3dhLIglXtw== X-Google-Smtp-Source: ABdhPJzdzGuPo0VX+NxyQJCfIS2kRUqtkiyk5+44OYM0ZZNCSF+IJ7ufJXJ8IyOcfrDhSU+PRuaPgQ== X-Received: by 2002:a65:4008:: with SMTP id f8mr36362839pgp.310.1635994789660; Wed, 03 Nov 2021 19:59:49 -0700 (PDT) Received: from laputa ([2400:4050:c3e1:100:9171:d985:c6fb:194d]) by smtp.gmail.com with ESMTPSA id s2sm2830610pgd.13.2021.11.03.19.59.47 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 03 Nov 2021 19:59:49 -0700 (PDT) Date: Thu, 4 Nov 2021 11:59:45 +0900 From: AKASHI Takahiro To: Simon Glass Cc: Heinrich Schuchardt , Alex Graf , Ilias Apalodimas , Sughosh Ganu , Masami Hiramatsu , U-Boot Mailing List Subject: Re: [PATCH v5 02/11] tools: mkeficapsule: add firmwware image signing Message-ID: <20211104025945.GE46422@laputa> Mail-Followup-To: AKASHI Takahiro , Simon Glass , Heinrich Schuchardt , Alex Graf , Ilias Apalodimas , Sughosh Ganu , Masami Hiramatsu , U-Boot Mailing List References: <20211028062356.98224-1-takahiro.akashi@linaro.org> <20211028062356.98224-3-takahiro.akashi@linaro.org> <20211029045628.GA33977@laputa> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: X-BeenThere: u-boot@lists.denx.de X-Mailman-Version: 2.1.34 Precedence: list List-Id: U-Boot discussion List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: u-boot-bounces@lists.denx.de Sender: "U-Boot" X-Virus-Scanned: clamav-milter 0.103.2 at phobos.denx.de X-Virus-Status: Clean On Tue, Nov 02, 2021 at 08:56:50AM -0600, Simon Glass wrote: > Hi Takahiro, > > On Thu, 28 Oct 2021 at 22:56, AKASHI Takahiro > wrote: > > > > On Thu, Oct 28, 2021 at 09:17:45PM -0600, Simon Glass wrote: > > > Hi Takahiro, > > > > > > On Thu, 28 Oct 2021 at 00:25, AKASHI Takahiro > > > wrote: > > > > > > > > With this enhancement, mkeficapsule will be able to sign a capsule > > > > file when it is created. A signature added will be used later > > > > in the verification at FMP's SetImage() call. > > > > > > > > To do that, We need specify additional command parameters: > > > > -monotonic-cout : monotonic count > > > > -private-key : private key file > > > > -certificate : certificate file > > > > Only when all of those parameters are given, a signature will be added > > > > to a capsule file. > > > > > > > > Users are expected to maintain and increment the monotonic count at > > > > every time of the update for each firmware image. > > > > > > > > Signed-off-by: AKASHI Takahiro > > > > --- > > > > tools/Kconfig | 8 + > > > > tools/Makefile | 8 +- > > > > tools/mkeficapsule.c | 435 +++++++++++++++++++++++++++++++++++++++---- > > > > 3 files changed, 417 insertions(+), 34 deletions(-) > > > > > > Reviewed-by: Simon Glass > > > > Thank you for your reviewing. > > > > > This looks OK but I have some suggestions > > > > > > - I don't think you should return -1 from main > > > > exit(EXIT_FAILURE)? > > Yeah, but when I first wrote this tool (without authentication support), > > 'return -1' was used everywhere. So I didn't want to have mixed styles > > in this patch. > > I will make a change with the tweak below. > > OK. I just mean that I think the return code is supposed to be 1 or 2 > or maybe 3 on error, not 255. > > > > > > - could you split up your create_fwbin() to return the number of gotos? > > > > Yeah, lots of gotos are messy. > > > > > - could we have a man page for the tool? > > > > Patch#3 > > OK > > > > > > - should the files be opened in binary mode? > > > > Well, the man page of fopen() says, > > This is strictly for compatibility with C89 and has no effect; > > the 'b' is ignored on all POSIX conforming sys- tems, including Linux. > > > > U-Boot now requires C11, and so no need? > > Ah OK. I suppose no one builds this on Windows. > > > > > > - can we just build the tool always? > > > > This is one of my questions. > > Why do you want to do so while there are bunch of tools that are > > not always built. > > Because I think all tools should be built always. It is fine if that > happens due to CONFIG options but we should try to avoid making it > complicated. > > > > > # I saw some discussion in another topic thread, and some distro guy said > > # that they used sandbox_defconfig for tool packaging. > > What about tools-only ? > > So long as the options are enabled it is fine to have options for the > tools. But I think we should try to build all the tools. I forgot to add CMD_MKEFITOOL in tools-only_defconfig in v6. If I need to send v7, I will include it, otherwise send it in a separate patch. -Takahiro Akashi > Regards, > Simon