Re: [PATCH v2] tools: fit: sign all config image references

Tom Rini <[email protected]>
Newsgroups gmane.comp.boot-loaders.u-boot
Message-ID <20260810213225.GE1160436__37804.6298444801$1786397569$gmane$org@bill-the-cat>
On Tue, Jul 28, 2026 at 10:18:39AM -0600, James Hilliard wrote:

> Target-side configuration verification builds the signed-region list from
> every image-reference property in the selected configuration. Host-side
> signing still uses either the signature node sign-images property or the
> legacy kernel/fdt/script default list.
> 
> This lets mkimage generate configuration signatures which U-Boot cannot
> verify when the configuration references other image types, such as
> firmware, loadables or ramdisk entries. It also lets the host and target
> disagree when sign-images names only a subset of the configuration images.
> 
> Build the host-side signing list from the configuration properties in the
> same way as target-side verification. Use one shared property classifier so
> the host and target cannot drift apart again. This makes signed
> configurations cover the root node, the configuration node, every
> referenced image node, and its hash/cipher subnodes, regardless of image
> type.
> 
> Warn when a legacy sign-images property is present, since it no longer
> limits the signed image list. Require every referenced image to have at
> least one hash subnode. Add sandbox coverage proving that a firmware
> reference omitted from sign-images is still recorded in hashed-nodes and
> verified.
> 
> Update the signed-configuration documentation to describe the same rule and
> the hash-subnode requirement.
> 
> Fixes: 2092322b31cc ("boot: Add fit_config_get_hash_list() to build signed node list")
> Signed-off-by: James Hilliard <[email protected]>
> ---
> Changes v1 -> v2:
>   - Add vboot coverage for an extra firmware reference omitted from
>     sign-images  (suggested by Simon Glass)
>   - Warn when mkimage ignores sign-images  (suggested by Simon Glass)
>   - Share configuration-property classification between host and target
>     code and remove the stale load-only comment  (suggested by Simon Glass)
>   - Document that every referenced image needs a hash subnode
>     (suggested by Simon Glass)
> ---
>  boot/image-fit-sig.c                          |  9 +-
>  boot/image-fit.c                              | 17 ++++
>  doc/board/ti/k3.rst                           | 10 +--
>  doc/usage/fit/beaglebone_vboot.rst            |  5 +-
>  doc/usage/fit/sign-configs.rst                | 13 ++-
>  doc/usage/fit/signature.rst                   | 26 +++---
>  doc/usage/fit/uefi.rst                        |  2 -
>  include/image.h                               |  9 ++
>  test/py/tests/test_vboot.py                   | 11 ++-
>  test/py/tests/vboot/sign-configs-algo-arg.its |  1 -
>  test/py/tests/vboot/sign-configs-sha1-pss.its |  1 -
>  test/py/tests/vboot/sign-configs-sha1.its     | 11 +++
>  .../vboot/sign-configs-sha256-pss-prod.its    |  1 -
>  .../tests/vboot/sign-configs-sha256-pss.its   |  1 -
>  test/py/tests/vboot/sign-configs-sha256.its   |  1 -
>  test/py/tests/vboot/sign-configs-sha384.its   |  1 -
>  tools/fit_image.c                             | 12 ++-
>  tools/image-host.c                            | 84 ++++++++-----------
>  18 files changed, 121 insertions(+), 94 deletions(-)

After some other changes, this no longer applies correctly, can you
please rebase? Sorry, thanks!

-- 
Tom
signature.asc (application/pgp-signature, 228 B)
-----BEGIN PGP SIGNATURE-----

iHUEABYKAB0WIQTzzqh0PWDgGS+bTHor4qD1Cr/kCgUCanpDZgAKCRAr4qD1Cr/k
Ci5qAQCxaszvRa+xvxS4/ZBHNf7TqyhNBZrku38GmV1Iijhu3gEA8C3zJlxakxzt
2a4urS7qcb/tCZtYw2ddKo1hLhaGsQA=
=FYu0
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.