[PATCH v2 2/5] binman: add sign option for binman
sjg at chromium.org
Sat Mar 11 02:47:02 CET 2023
On Tue, 7 Mar 2023 at 14:13, Ivan Mikhaylov <fr0st61te at gmail.com> wrote:
> Introduce proof of concept for binman's new option which provides sign
> and replace FIT containers in binary images.
> Usage as example:
> mkimage -G privateky -r -o sha256,rsa4096 -F fit
> binman replace -i flash.bin -f fit.fit fit
> binman sign -i flash.bin -k privatekey -a sha256,rsa4096 -f fit.fit fit
> and to this one if it's need to be extracted, signed with key and put it
> back in image:
> binman sign -i flash.bin -k privatekey -a sha256,rsa4096 fit
> Signed-off-by: Ivan Mikhaylov <fr0st61te at gmail.com>
> tools/binman/cmdline.py | 13 +++++++++++++
> tools/binman/control.py | 29 ++++++++++++++++++++++++++++-
> tools/binman/etype/fit.py | 18 ++++++++++++++++++
> tools/binman/etype/section.py | 3 +++
> 4 files changed, 62 insertions(+), 1 deletion(-)
This needs a few tweaks to get the test coverage up to 100% and use
the mark_build_done() feature added a few days ago.
I have taken the liberty of updating it and will apply it soon, since
this has been outstanding for a while.
Applied to u-boot-dm/next, thanks!
More information about the U-Boot