diff mbox series

remove fatal error when .crt file is missing at fitimage sanity check

Message ID 20260924085202.21862-1-pistora.tobias@gmail.com
State New
Headers show
Series remove fatal error when .crt file is missing at fitimage sanity check | expand

Commit Message

Tobias Pistora Sept. 24, 2026, 8:52 a.m. UTC
Fixes [YOCTO #16427]

The minimal requirement of mkimage for signing a fitImage is a private
key file (.key -> using -k). Passing a public key file (.crt) is only
necessary when a key-destination is provided (-K). The -K option is
optional in the kernel-fit-image signing process and can be passed only
by the user via UBOOT_MKIMAGE_SIGN_ARGS. Therefore, providing a private
.crt key file is optional and should not cause a fatal error when
missing.

Signed-off-by: Tobias Pistora <pistora.tobias@gmail.com>
---
 meta/lib/oe/fitimage.py | 7 +++++--
 1 file changed, 5 insertions(+), 2 deletions(-)

Comments

patchtest@automation.yoctoproject.org Sept. 24, 2026, 9:01 a.m. UTC | #1
Thank you for your submission. Patchtest identified one
or more issues with the patch. Please see the log below for
more information:

---
Testing patch /home/patchtest/share/mboxes/remove-fatal-error-when-.crt-file-is-missing-at-fitimage-sanity-check.patch

FAIL: test shortlog format: Commit shortlog (first line of commit message) should follow the format "<target>: <summary>" (test_mbox.TestMbox.test_shortlog_format)

PASS: pretest pylint (test_python_pylint.PyLint.pretest_pylint)
PASS: test Signed-off-by presence (test_mbox.TestMbox.test_signed_off_by_presence)
PASS: test auh changelog truncation notice (test_mbox.TestMbox.test_auh_changelog_truncation_notice)
PASS: test author valid (test_mbox.TestMbox.test_author_valid)
PASS: test bugzilla entry format (test_mbox.TestMbox.test_bugzilla_entry_format)
PASS: test commit message presence (test_mbox.TestMbox.test_commit_message_presence)
PASS: test commit message user tags (test_mbox.TestMbox.test_commit_message_user_tags)
PASS: test max line length (test_metadata.TestMetadata.test_max_line_length)
PASS: test mbox format (test_mbox.TestMbox.test_mbox_format)
PASS: test non-AUH upgrade (test_mbox.TestMbox.test_non_auh_upgrade)
PASS: test pylint (test_python_pylint.PyLint.test_pylint)
PASS: test shortlog length (test_mbox.TestMbox.test_shortlog_length)
PASS: test target mailing list (test_mbox.TestMbox.test_target_mailing_list)

SKIP: pretest src uri left files: No modified recipes, skipping pretest (test_metadata.TestMetadata.pretest_src_uri_left_files)
SKIP: test CVE check ignore: No modified recipes or older target branch, skipping test (test_metadata.TestMetadata.test_cve_check_ignore)
SKIP: test CVE tag format: No new source patches introduced (test_patch.TestPatch.test_cve_tag_format)
SKIP: test Signed-off-by presence: No new source patches introduced (test_patch.TestPatch.test_signed_off_by_presence)
SKIP: test Upstream-Status presence: No new source patches introduced (test_patch.TestPatch.test_upstream_status_presence_format)
SKIP: test lic files chksum modified not mentioned: No modified recipes, skipping test (test_metadata.TestMetadata.test_lic_files_chksum_modified_not_mentioned)
SKIP: test lic files chksum presence: No added recipes, skipping test (test_metadata.TestMetadata.test_lic_files_chksum_presence)
SKIP: test license presence: No added recipes, skipping test (test_metadata.TestMetadata.test_license_presence)
SKIP: test series merge on head: Merge test is disabled for now (test_mbox.TestMbox.test_series_merge_on_head)
SKIP: test src uri left files: No modified recipes, skipping test (test_metadata.TestMetadata.test_src_uri_left_files)
SKIP: test summary presence: No added recipes, skipping test (test_metadata.TestMetadata.test_summary_presence)

---

Please address the issues identified and
submit a new revision of the patch, or alternatively, reply to this
email with an explanation of why the patch should be accepted. If you
believe these results are due to an error in patchtest, please submit a
bug at https://bugzilla.yoctoproject.org/ (use the 'Patchtest' category
under 'Yocto Project Subprojects'). For more information on specific
failures, see: https://wiki.yoctoproject.org/wiki/Patchtest. Thank
you!
diff mbox series

Patch

diff --git a/meta/lib/oe/fitimage.py b/meta/lib/oe/fitimage.py
index 1ac4b2c59d..484e5c5ee0 100644
--- a/meta/lib/oe/fitimage.py
+++ b/meta/lib/oe/fitimage.py
@@ -593,8 +593,11 @@  class ItsNodeRootKernel(ItsNode):
             if not os.path.exists(key_path + '.pem'):
                 bb.fatal("ECDSA signing requires '%s.pem'" % key_path)
         else:
-            if not os.path.exists(key_path + '.key') or not os.path.exists(key_path + '.crt'):
-                bb.fatal("%s.key or .crt does not exist" % key_path)
+            if not os.path.exists(key_path + '.key'):
+                bb.fatal("%s.key (private key) does not exist" % key_path)
+            # public key is only necessary when passing -K option to mkimage
+            if not os.path.exists(key_path + '.crt'):
+                bb.debug(1, "%s.crt (public key) does not exist" % key_path)
 
     def run_mkimage_sign(self, fitfile):
         if not self._sign_enable: