[U-Boot] [PATCH 0/9] spl: Add full fit and u-boot dto support
Marek Vasut
marex at denx.de
Thu Dec 28 12:06:12 UTC 2017
Add support for using the full fitImage parsing code in SPL. This is useful
ie. if we want SPL to verify the U-Boot proper fitImage using RSA signature.
While verifying image signature can be added to the simplified fitImage
handling code in U-Boot SPL, verifying configuration signatures becomes
quite hairy. Thus, loading the entire fitImage and then applying the full
fitImage handling code on it is far less intrusive change. The size of the
SPL with full fitImage code obviously grows, so this might not be suitable
for size-constrained systems.
The remaining four patches allow applying a DTO from fitImage onto the SPL's
internal DT and restart the image loading process. The usecase here is ie. to
put a replacement public key into the DTO, patch the /signature node and load
offset node of the U-Boot SPL's DT and restart the image loading process to
load U-Boot proper signed with the replacement private key. The user is then
able to replace the DTO and sign own U-Boot fitImage without replacing the
SPL binary itself.
Marek Vasut (9):
fit: Fix CONFIG_FIT_SPL_PRINT
fit: Add empty fit_print_contents() and fit_image_print()
fit: Add standalone image type handling
fit: Verify all configuration signatures
spl: Add full fitImage support
spl: Add support for overlaying U-Boot DT
spl: Restart loading if load_image returns -EAGAIN
spl: ram: Add support for fetching image position from control DT
spl: spi: Add support for fetching image position from control DT
Kconfig | 17 +++++++++++
README | 2 +-
common/image-fit.c | 36 +++++++++++++---------
common/spl/spl.c | 86 +++++++++++++++++++++++++++++++++++++++++++++++++++-
common/spl/spl_ram.c | 21 ++++++++++---
common/spl/spl_spi.c | 13 ++++++++
include/image.h | 1 +
7 files changed, 154 insertions(+), 22 deletions(-)
--
2.15.0
More information about the U-Boot
mailing list