[PATCH v2 3/4] binman: Flesh out the softhsm2-util bintool docstring

Simon Glass sjg at chromium.org
Tue May 5 20:12:54 CEST 2026


The Sphinx-generated bintools.rst currently produces an empty section
for this bintool, since its class docstring is only a single line and
so the body under the heading is blank.

Extend the docstring with a short description of what softhsm2-util
does and how binman uses it, so the generated documentation has useful
content.

Suggested-by: Heinrich Schuchardt <xypron.glpk at gmx.de>
Signed-off-by: Simon Glass <sjg at chromium.org>
---

Changes in v2:
- Reword the docstring per Quentin's review: binman uses this bintool
  only as an availability check, not for runtime PKCS#11 operations

 tools/binman/btool/softhsm2_util.py | 12 +++++++++++-
 1 file changed, 11 insertions(+), 1 deletion(-)

diff --git a/tools/binman/btool/softhsm2_util.py b/tools/binman/btool/softhsm2_util.py
index 869221d841d..fd2ff2d6473 100644
--- a/tools/binman/btool/softhsm2_util.py
+++ b/tools/binman/btool/softhsm2_util.py
@@ -7,7 +7,17 @@ from binman import bintool
 
 
 class Bintoolsofthsm2_util(bintool.Bintool):
-    """SoftHSMv2 -- support tool for libsofthsm2"""
+    """SoftHSMv2 -- support tool for libsofthsm2
+
+    This bintool wraps the `softhsm2-util` command shipped with SoftHSMv2 (a
+    software implementation of a PKCS#11 token). Binman uses this wrapper only
+    to check that softhsm2-util is installed (and to fetch it if missing); any
+    actual token initialisation or key import for signing FIT images or
+    capsules is done outside binman, typically via mkimage and the OpenSSL
+    PKCS#11 engine.
+
+    See https://www.opendnssec.org/softhsm/ for more details.
+    """
     def __init__(self, name):
         super().__init__('softhsm2-util',
                          'SoftHSMv2 support tool for libsofthsm2',
-- 
2.43.0



More information about the U-Boot mailing list