From patchwork Thu Oct 8 06:09:33 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Marta Rybczynska X-Patchwork-Id: 100172 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 5B708CA6002 for ; Thu, 8 Oct 2026 06:09:57 +0000 (UTC) Received: from mail-wr1-f41.google.com (mail-wr1-f41.google.com [209.85.221.41]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.9463.1791439794013362062 for ; Wed, 07 Oct 2026 23:09:54 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=tK+VwhuQ; spf=pass (domain: gmail.com, ip: 209.85.221.41, mailfrom: rybczynska@gmail.com) Received: by mail-wr1-f41.google.com with SMTP id ffacd0b85a97d-48b042c0759so2090667f8f.2 for ; Wed, 07 Oct 2026 23:09:53 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1791439792; x=1792044592; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=B8uiRONi4/efkTVyJszkz4CHIoSlpeBTvCcSzw94xfA=; b=tK+VwhuQaCYQpb/C3XVubKvA7sr/sY2we6JLDrT7UjKv6EJoGkKVCL7a0ulzw2AB2f 1ndWipOyhsQuKxCNIY0KsgIGSknVK/PHZKnI9cRubM90M3L8uBweiG93DYWqSBb5qtrJ ttdfa1cpcsLJlLTwMc6sMI5JnM4dsaBV//6Yzjd3IjBEy2c3u+wWqAQyYoFc4x9uZ/W9 xWXjMZOthQsPGD7+cM2RVUAaq1wZj26uwc6rZcrQ0Cm/anuNsPA8lxoCuxgu8odB/dw7 xnfcWZ9iG2HpqIEwJD/lkiQcEXKwLeWXummq1v7TG7NAroNVva7/jRUi8m/WlDnJFAnU s8Ag== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1791439792; x=1792044592; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=B8uiRONi4/efkTVyJszkz4CHIoSlpeBTvCcSzw94xfA=; b=kaJT5WSwCVAOTg2F83IiE4X68/j0ZWiysfdxxGXMvZ4r3Vw3MhjEalhoJpKgmkack0 i3edxAj/lbqb6/m9W/0j4XV5fSheHtFc4CMoAdybj27PlDx5yJUMZ8s3nODFAA/nBBv9 2dKTnO2DDGBwqR79XlZpw7JpaGSEnSfPUW+ywsQNr6IcEhTlIvh3KelLLZfEQ8rjvt+s ANEejpSL64/oATE4aQTP6Ep2vYuLXRVZAe3U1cC7DlbQIcje+66TMs9+344nSGxYtUxl 7KEYc+EClCDTq59spXLtvdikZ8WdXiDfFotpO7WsxKRtiRGd+T76nBA7MOfHVKUg5RLX to/Q== X-Gm-Message-State: AFq9FYIVdnzX56wB1ctG2Qjzxh+wjR1V2iirWU+BI596k3DLmdPowZ7H 0ViZ7zv9bDqTjM6NnNS6lC7jiQN+tQqPozC6TVrHIXv60XpAKIHowV6RHbIWvmz+ X-Gm-Gg: AYBFou3iMiTfqZrVetNYBjdrWJ3jm4ABGHyNj7KQfIX7BD0MeOD3fzY6vKuTvtpC2F4 T74eza7ALFlSuCo9Sc0W0c43Wphz7D8+J8Py21mdWQr5C642ESHNw3ZVjZkckXcL0W5XRuookTf jPvwfWiTXmgwIBvUlsu7yn7CbySLv3kFBRc/xmkyyhkbR5c+YKDomcBWvh1LtyAUcDpQMiR4iuM 8gj58rvBEOnzlaSfs6FtkfIcgWlToAdifXpwRZdGB9wOm2xqSqOcHwuGW93kf4OX9K+iwWPev5f o0g7Ljb6SLpYo4IbTr95s91n2Ic2HTwphyGs0f8scBsJ1TQdx9/GYpNKLJoqLPixvDC+fu2FCad vAKPPRNDw0t0vkeEi3hb741qxEKB7FJa9dpHT6zTvQA43LuPCeqAD746dTVri92fkphYbb5En1O NMB2UXSG9kEG0Qsr9mmp8dzTqfkhTLE1SYsMVWihFpkLajUnXBwu6cQ8MJJBojIQ4bPsFQmAgtZ cWXGRgAn3+UPkkcZbv+666alPE= X-Received: by 2002:a5d:584c:0:b0:48c:7719:8e56 with SMTP id ffacd0b85a97d-48c77198f37mr6139279f8f.8.1791439791750; Wed, 07 Oct 2026 23:09:51 -0700 (PDT) Received: from penguin.lxd ([81.0.251.149]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48c71d3d3eesm10630219f8f.53.2026.10.07.23.09.49 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 07 Oct 2026 23:09:49 -0700 (PDT) From: Marta Rybczynska To: openembedded-core@lists.openembedded.org Cc: a.fatoum@pengutronix.de, adrian.freihofer@siemens.com, Marta Rybczynska Subject: [PATCH v4 1/3] uboot-sign: add the option to sign SPL FIT configurations Date: Thu, 8 Oct 2026 08:09:33 +0200 Message-Id: <20261008060935.4225-1-rybczynska@gmail.com> X-Mailer: git-send-email 2.39.5 MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 08 Oct 2026 06:09:57 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/247413 The SPL FIT signing path was signing individual images, but not the configuration. Introduce signing of configuration with images under a separate option SPL_SIGN_CONF. For now it is disabled. Enabling this option implies changes in the DTB content. The old behaviour is possible with SPL_SIGN_INDIVIDUAL, but should be removed in a subsequent patch. Signed-off-by: Marta Rybczynska --- meta/classes-recipe/uboot-sign.bbclass | 86 ++++++++++++++++++++++++-- 1 file changed, 82 insertions(+), 4 deletions(-) diff --git a/meta/classes-recipe/uboot-sign.bbclass b/meta/classes-recipe/uboot-sign.bbclass index 236d19925e..42319d15ff 100644 --- a/meta/classes-recipe/uboot-sign.bbclass +++ b/meta/classes-recipe/uboot-sign.bbclass @@ -33,6 +33,16 @@ UBOOT_FITIMAGE_ENABLE ?= "0" # Signature activation - this requires UBOOT_FITIMAGE_ENABLE = "1" SPL_SIGN_ENABLE ?= "0" +# Sign the FIT configuration in the SPL signing flow. Configuration +# signatures bind the selected images and boot metadata together. +SPL_SIGN_CONF ?= "0" + +# Legacy compatibility knob for per-image signatures in the SPL FIT path. +# Individual image signatures do not protect the configuration metadata +# which selects and parameterizes the boot images. +# INSECURE, use at your own risk +SPL_SIGN_INDIVIDUAL ?= "1" + # Default value for deployment filenames. UBOOT_DTB_IMAGE ?= "u-boot-${MACHINE}-${PV}-${PR}.dtb" UBOOT_DTB_BINARY ?= "u-boot.dtb" @@ -327,7 +337,15 @@ uboot_fitimage_atf() { entry = <${UBOOT_FIT_ARM_TRUSTED_FIRMWARE_ENTRYPOINT}>; compression = "none"; EOF - if [ "${SPL_SIGN_ENABLE}" = "1" ] ; then + if [ "${SPL_SIGN_ENABLE}" = "1" ] && [ "${SPL_SIGN_CONF}" = "1" ] ; then + cat << EOF >> ${UBOOT_ITS} + hash-1 { + algo = "${UBOOT_FIT_HASH_ALG}"; + }; +EOF + fi + + if [ "${SPL_SIGN_ENABLE}" = "1" ] && [ "${SPL_SIGN_INDIVIDUAL}" = "1" ] ; then cat << EOF >> ${UBOOT_ITS} signature { algo = "${UBOOT_FIT_HASH_ALG},${UBOOT_FIT_SIGN_ALG}"; @@ -354,7 +372,15 @@ uboot_fitimage_tee() { entry = <${UBOOT_FIT_TEE_ENTRYPOINT}>; compression = "none"; EOF - if [ "${SPL_SIGN_ENABLE}" = "1" ] ; then + if [ "${SPL_SIGN_ENABLE}" = "1" ] && [ "${SPL_SIGN_CONF}" = "1" ] ; then + cat << EOF >> ${UBOOT_ITS} + hash-1 { + algo = "${UBOOT_FIT_HASH_ALG}"; + }; +EOF + fi + + if [ "${SPL_SIGN_ENABLE}" = "1" ] && [ "${SPL_SIGN_INDIVIDUAL}" = "1" ] ; then cat << EOF >> ${UBOOT_ITS} signature { algo = "${UBOOT_FIT_HASH_ALG},${UBOOT_FIT_SIGN_ALG}"; @@ -395,7 +421,15 @@ uboot_fitimage_assemble() { entry = <${UBOOT_FIT_UBOOT_ENTRYPOINT}>; EOF - if [ "${SPL_SIGN_ENABLE}" = "1" ] ; then + if [ "${SPL_SIGN_ENABLE}" = "1" ] && [ "${SPL_SIGN_CONF}" = "1" ] ; then + cat << EOF >> ${UBOOT_ITS} + hash-1 { + algo = "${UBOOT_FIT_HASH_ALG}"; + }; +EOF + fi + + if [ "${SPL_SIGN_ENABLE}" = "1" ] && [ "${SPL_SIGN_INDIVIDUAL}" = "1" ] ; then cat << EOF >> ${UBOOT_ITS} signature { algo = "${UBOOT_FIT_HASH_ALG},${UBOOT_FIT_SIGN_ALG}"; @@ -414,7 +448,15 @@ EOF compression = "none"; EOF - if [ "${SPL_SIGN_ENABLE}" = "1" ] ; then + if [ "${SPL_SIGN_ENABLE}" = "1" ] && [ "${SPL_SIGN_CONF}" = "1" ] ; then + cat << EOF >> ${UBOOT_ITS} + hash-1 { + algo = "${UBOOT_FIT_HASH_ALG}"; + }; +EOF + fi + + if [ "${SPL_SIGN_ENABLE}" = "1" ] && [ "${SPL_SIGN_INDIVIDUAL}" = "1" ] ; then cat << EOF >> ${UBOOT_ITS} signature { algo = "${UBOOT_FIT_HASH_ALG},${UBOOT_FIT_SIGN_ALG}"; @@ -447,9 +489,20 @@ EOF conf_loadables="${conf_loadables}${UBOOT_FIT_CONF_USER_LOADABLES}" fi + conf_sign_images="" + conf_sign_images_sep="" + if [ -n "${UBOOT_FIT_CONF_FIRMWARE}" ] ; then conf_firmware="firmware = \"${UBOOT_FIT_CONF_FIRMWARE}\";" + conf_sign_images="${conf_sign_images}${conf_sign_images_sep}\"firmware\"" + conf_sign_images_sep=", " + fi + + if [ -n "${conf_loadables}" ] ; then + conf_sign_images="${conf_sign_images}${conf_sign_images_sep}\"loadables\"" + conf_sign_images_sep=", " fi + conf_sign_images="${conf_sign_images}${conf_sign_images_sep}\"fdt\"" cat << EOF >> ${UBOOT_ITS} }; @@ -461,6 +514,19 @@ EOF ${conf_firmware} loadables = ${conf_loadables}; fdt = "fdt"; +EOF + + if [ "${SPL_SIGN_ENABLE}" = "1" ] && [ "${SPL_SIGN_CONF}" = "1" ] ; then + cat << EOF >> ${UBOOT_ITS} + signature { + algo = "${UBOOT_FIT_HASH_ALG},${UBOOT_FIT_SIGN_ALG}"; + key-name-hint = "${SPL_SIGN_KEYNAME}"; + sign-images = ${conf_sign_images}; + }; +EOF + fi + + cat << EOF >> ${UBOOT_ITS} }; }; }; @@ -475,6 +541,18 @@ EOF ${UBOOT_FITIMAGE_BINARY} if [ "${SPL_SIGN_ENABLE}" = "1" ] ; then + if [ "${SPL_SIGN_CONF}" != "1" ] && [ "${SPL_SIGN_INDIVIDUAL}" != "1" ] ; then + bbfatal "SPL_SIGN_ENABLE=1 requires SPL_SIGN_CONF=1 or SPL_SIGN_INDIVIDUAL=1" + fi + + if [ "${SPL_SIGN_CONF}" != "1" ] ; then + bbwarn "SPL_SIGN_CONF is disabled. FIT configuration signing is recommended for SPL verified boot." + fi + + if [ "${SPL_SIGN_INDIVIDUAL}" = "1" ] ; then + bbwarn "SPL_SIGN_INDIVIDUAL=1 is enabled for compatibility only. It is INSECURE. Individual image signatures do not replace configuration signing." + fi + if [ -n "${SPL_DTB_BINARY}" ] ; then # # Sign the U-boot FIT image and add public key to SPL dtb. From patchwork Thu Oct 8 06:09:34 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Marta Rybczynska X-Patchwork-Id: 100174 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 37173CA6002 for ; Thu, 8 Oct 2026 06:10:07 +0000 (UTC) Received: from mail-wm1-f53.google.com (mail-wm1-f53.google.com [209.85.128.53]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.9710.1791439797155008046 for ; Wed, 07 Oct 2026 23:09:57 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=aohKPwcf; spf=pass (domain: gmail.com, ip: 209.85.128.53, mailfrom: rybczynska@gmail.com) Received: by mail-wm1-f53.google.com with SMTP id 5b1f17b1804b1-4a061a13884so22168015e9.3 for ; Wed, 07 Oct 2026 23:09:56 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1791439795; x=1792044595; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=lHzf74VzW4UNJzDJcezB2eztP4Cx36s6onVelBTZecw=; b=aohKPwcfa82ZkYoRmRQ/kyq2h2N6rOou0kmMXZTEudlJiH/bwWftZKVDExgwHoMO0l kqJCr15/sp0UOqpQ46ll+CvRlBv6Td3VjeH5lvwC4KzP321H/cCFDt+mqQTi5rL2KvwN fd5jycryo0o9FmdlzAux6iDRVf2nh3iofRebnrXKiPfabjhFMiQni5+6HwGi3z2X9N66 tqR0AwcQzAOB8SrFtynSMHb5iOUVkQ0SUQW0ebmRaoZzyoyEJzZ2CvEtqb0n3C8eov+y l+fzKJ2swaFjAggvVMeijeMdLEJAthV5k1CE20/FUFsKYn7gofxjICqCVdse2dQSF2B+ Hw8g== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1791439795; x=1792044595; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=lHzf74VzW4UNJzDJcezB2eztP4Cx36s6onVelBTZecw=; b=ABV3HWCqhOSYn6zNXp83t9E2jYaHTPGvQ3gP4nXxAxMVxD3fiPtYPOhZ7xgBooAkKz ECqTR63psLudxvUyoOFxfkQ0KU/ET9G6CRzWRwugfn58s1ZM+dQXB6LRWHFFlQIe6w08 RkgdrcnrBSf/8ICAwMGizf8cVEBiL1hxsKbsvFiZcUnt1kQcQ0RgW6ESSTbUIokw333u 3yFSrM4gZdg+WArDh/kPwYizGrpAI3JznsxqFkWRx2SElasKW0W/II0FdsgXz6LSAFDB wRPcej9BX0Vu+CoUWdB39+IxX1AeeMmwYZmOtdZWyOF8eZwneCOwjQ1MQfWdv39J64r+ CgWA== X-Gm-Message-State: AFuF++lcJHIr9e6Rayw+lBOEfq7oijkQKaKdxc1ch+3mJLzjV4S6tegY QWM1f9IQD5Lxg6EN/I85Jr0NsrLb0sfEk6KJjrN6orvUuxLoDeRZgOnBSfyjRbyX X-Gm-Gg: AYBFou0hbz2MqnC4AtIVM6Pbc3RDgrgJnygx72FT6LZOcMitaIcTSUAARkfvJbYh4Bi fZbER70aqAR6f3ssb8DC4cJ3EGrs19YtD6HXdnea+RyQ74rMyFiLdQFRcXOrqtL91EWAjcQ4dRP khcr09WW2f5Vg56y3PBmEhTn2mD3w4yp0fmxD4zoooxlCtup0zO4y460Wgn7GIoINN4hnFCI2Ch 7JI3NM36MJ77MnFZ4o10VxyjiiKPdFJzJ7joEsg7fNAEVF+07V7u5qQ2QQWXnQJQmPslBvKCD+O 9LiaFvmgZ1m0rFDpPBCU/h5ndb7YUs4wOJZFTN6OqVAf4ZLa6O0z0qX4J0jdONYrmABF+yGF+At NGYJD2g72+wQhm8CUIkENJV9vm6XWnaJsEHwXHPAdRD8ZmmfxvtflRCRBWb6ue3NqMHGGDyh8mR zdIPpSzykVunCZLZlWcuVQxxUIMSR7rI2UgFgFg7XsmTHyxe5vPb42E3oE6yehnvRYv6Jk0KNX+ CRVioU1Ew31O12DK2QNcR/T07w= X-Received: by 2002:a05:600c:4708:b0:4a0:1b14:e283 with SMTP id 5b1f17b1804b1-4a1800d5941mr77927805e9.1.1791439795225; Wed, 07 Oct 2026 23:09:55 -0700 (PDT) Received: from penguin.lxd ([81.0.251.149]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48c71d3d3eesm10630219f8f.53.2026.10.07.23.09.52 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 07 Oct 2026 23:09:53 -0700 (PDT) From: Marta Rybczynska To: openembedded-core@lists.openembedded.org Cc: a.fatoum@pengutronix.de, adrian.freihofer@siemens.com, Marta Rybczynska Subject: [PATCH v4 2/3] oe-selftest: fitimage: support new schema for uboot configuration signing Date: Thu, 8 Oct 2026 08:09:34 +0200 Message-Id: <20261008060935.4225-2-rybczynska@gmail.com> X-Mailer: git-send-email 2.39.5 In-Reply-To: <20261008060935.4225-1-rybczynska@gmail.com> References: <20261008060935.4225-1-rybczynska@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 08 Oct 2026 06:10:07 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/247414 Modify testcases after adding signing of a configuration of uboot instead of various sections separately. This change includes an additional parameter to _check_signing that allows more flexible configuration and avoids assumptions on what section has, and which section does not have a signature - now they are defined in a data structure. Signed-off-by: Marta Rybczynska --- meta/lib/oeqa/selftest/cases/fitimage.py | 53 +++++++++++++++--------- 1 file changed, 34 insertions(+), 19 deletions(-) diff --git a/meta/lib/oeqa/selftest/cases/fitimage.py b/meta/lib/oeqa/selftest/cases/fitimage.py index 5d77e6da09..b95e6c158c 100644 --- a/meta/lib/oeqa/selftest/cases/fitimage.py +++ b/meta/lib/oeqa/selftest/cases/fitimage.py @@ -614,7 +614,7 @@ class FitImageTestCase(OESelftestTestCase): self._is_req_dict_in_dict(sections, req_sections) # Call the signing related checks if the function is provided by a inherited class - self._check_signing(bb_vars, sections, num_signatures, uboot_tools_bindir, fitimage_path) + self._check_signing(bb_vars, sections, req_sections, num_signatures, uboot_tools_bindir, fitimage_path) def _get_req_its_paths(self, bb_vars): self.logger.error("This function needs to be implemented") @@ -636,7 +636,7 @@ class FitImageTestCase(OESelftestTestCase): self.logger.error("This function needs to be implemented") return ({}, 0) - def _check_signing(self, bb_vars, sections, num_signatures, uboot_tools_bindir, fitimage_path): + def _check_signing(self, bb_vars, sections, req_sections, num_signatures, uboot_tools_bindir, fitimage_path): """Verify the signatures in the FIT image.""" self.fail("Function needs to be implemented by inheriting classes") @@ -1076,7 +1076,7 @@ class KernelFitImageBase(FitImageTestCase): req_sections[section]['Hash algo'] = fit_hash_alg return (req_sections, num_signatures) - def _check_signing(self, bb_vars, sections, num_signatures, uboot_tools_bindir, fitimage_path): + def _check_signing(self, bb_vars, sections, req_sections, num_signatures, uboot_tools_bindir, fitimage_path): """Verify the signature nodes in the FIT image""" if bb_vars['UBOOT_SIGN_ENABLE'] == "1": self.logger.debug("Verifying signatures in the FIT image") @@ -1105,6 +1105,8 @@ class KernelFitImageBase(FitImageTestCase): for section, values in sections.items(): # Configuration nodes are always signed with UBOOT_SIGN_KEYNAME (if UBOOT_SIGN_ENABLE = "1") if section.startswith(bb_vars['FIT_CONF_PREFIX']): + if 'Sign algo' not in req_values[section]: + continue sign_algo = values.get('Sign algo', None) req_sign_algo = "%s,%s:%s" % (fit_hash_alg, fit_sign_alg, uboot_sign_keyname) self.assertEqual(sign_algo, req_sign_algo, 'Signature algorithm for %s not expected value' % section) @@ -1688,6 +1690,8 @@ class UBootFitImageTests(FitImageTestCase): 'SPL_MKIMAGE_SIGN_ARGS', 'SPL_SIGN_ENABLE', 'SPL_SIGN_KEYNAME', + 'SPL_SIGN_INDIVIDUAL', + 'SPL_SIGN_CONF', 'TOPDIR', 'UBOOT_ARCH', 'UBOOT_DTB_BINARY', @@ -1763,10 +1767,14 @@ class UBootFitImageTests(FitImageTestCase): req_its_paths = [] for image in images: req_its_paths.append(['/', 'images', image]) - if bb_vars['SPL_SIGN_ENABLE'] == "1": + if bb_vars['SPL_SIGN_ENABLE'] == "1" and bb_vars['SPL_SIGN_INDIVIDUAL'] == "1": req_its_paths.append(['/', 'images', image, 'signature']) + elif bb_vars['SPL_SIGN_ENABLE'] == "1" and bb_vars['SPL_SIGN_CONF'] == "1": + req_its_paths.append(['/', 'images', image, 'hash-1']) for configuration in configurations: req_its_paths.append(['/', 'configurations', configuration]) + if bb_vars['SPL_SIGN_ENABLE'] == "1" and bb_vars['SPL_SIGN_CONF'] == "1": + req_its_paths.append(['/', 'configurations', 'conf', 'signature']) return (req_its_paths, []) def _get_req_its_fields(self, bb_vars): @@ -1874,16 +1882,26 @@ class UBootFitImageTests(FitImageTestCase): uboot_fit_sign_alg = bb_vars['UBOOT_FIT_SIGN_ALG'] spl_sign_enable = bb_vars['SPL_SIGN_ENABLE'] spl_sign_keyname = bb_vars['SPL_SIGN_KEYNAME'] + spl_sign_conf = bb_vars['SPL_SIGN_CONF'] + spl_sign_individual = bb_vars['SPL_SIGN_INDIVIDUAL'] num_signatures = 0 if spl_sign_enable == "1": for section in req_sections: - if not section.startswith('conf'): - req_sections[section]['Sign algo'] = "%s,%s:%s" % \ - (uboot_fit_hash_alg, uboot_fit_sign_alg, spl_sign_keyname) - num_signatures += 1 + if section.startswith('conf'): + if spl_sign_conf == "1": + req_sections[section]['Sign algo'] = "%s,%s:%s" % \ + (uboot_fit_hash_alg, uboot_fit_sign_alg, spl_sign_keyname) + num_signatures += 1 + else: + if spl_sign_conf == "1": + req_sections[section]['Hash algo'] = uboot_fit_hash_alg + elif spl_sign_individual == "1": + req_sections[section]['Sign algo'] = "%s,%s:%s" % \ + (uboot_fit_hash_alg, uboot_fit_sign_alg, spl_sign_keyname) + num_signatures += 1 return (req_sections, num_signatures) - def _check_signing(self, bb_vars, sections, num_signatures, uboot_tools_bindir, fitimage_path): + def _check_signing(self, bb_vars, sections, req_sections, num_signatures, uboot_tools_bindir, fitimage_path): if bb_vars['UBOOT_FITIMAGE_ENABLE'] == '1' and bb_vars['SPL_SIGN_ENABLE'] == "1": self.logger.debug("Verifying signatures in the FIT image") else: @@ -1896,16 +1914,13 @@ class UBootFitImageTests(FitImageTestCase): fit_sign_alg_len = FitImageTestCase.MKIMAGE_SIGNATURE_LENGTHS[uboot_fit_sign_alg] for section, values in sections.items(): # Configuration nodes are always signed with UBOOT_SIGN_KEYNAME (if UBOOT_SIGN_ENABLE = "1") - if section.startswith("conf"): - # uboot-sign does not sign configuration nodes - pass - else: - # uboot-sign does not add hash nodes, only image signatures - sign_algo = values.get('Sign algo', None) - req_sign_algo = "%s,%s:%s" % (uboot_fit_hash_alg, uboot_fit_sign_alg, spl_sign_keyname) - self.assertEqual(sign_algo, req_sign_algo, 'Signature algorithm for %s not expected value' % section) - sign_value = values.get('Sign value', None) - self.assertEqual(len(sign_value), fit_sign_alg_len, 'Signature value for section %s not expected length' % section) + if 'Sign algo' not in req_sections[section]: + continue + sign_algo = values.get('Sign algo', None) + req_sign_algo = "%s,%s:%s" % (uboot_fit_hash_alg, uboot_fit_sign_alg, spl_sign_keyname) + self.assertEqual(sign_algo, req_sign_algo, 'Signature algorithm for %s not expected value' % section) + sign_value = values.get('Sign value', None) + self.assertEqual(len(sign_value), fit_sign_alg_len, 'Signature value for section %s not expected length' % section) # Search for the string passed to mkimage in each signed section of the FIT image. # Looks like mkimage supports to add a comment but does not support to read it back. From patchwork Thu Oct 8 06:09:35 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Marta Rybczynska X-Patchwork-Id: 100173 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 24428CA6007 for ; Thu, 8 Oct 2026 06:10:07 +0000 (UTC) Received: from mail-wr1-f49.google.com (mail-wr1-f49.google.com [209.85.221.49]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.9712.1791439799776979328 for ; Wed, 07 Oct 2026 23:10:00 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=VYeeOHkC; spf=pass (domain: gmail.com, ip: 209.85.221.49, mailfrom: rybczynska@gmail.com) Received: by mail-wr1-f49.google.com with SMTP id ffacd0b85a97d-48c14a06c95so2033269f8f.1 for ; Wed, 07 Oct 2026 23:09:59 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1791439798; x=1792044598; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=WxcHRJfugXMLiqdeXIvqIsmL/ixZl6F8nmN4Ef0u2Gs=; b=VYeeOHkCcn8/Rizzva3x0t0O3KBPQEezeUR8bLCNhRFuH8dy5h3qvvhjA2IIrzndxZ yqnl8/USt0cZWzU+0NHBxjH3hvTepIeHseNwGRkAuGzxn6Qh64ezS34/EPVPnkb+xKGb aO9gI9jHVBdlN9vcvB4MjJRuoWryckbLP+q/BndeoiWYWOyJEJtRiSVZJtCgSmA0lQVY 26dCSJ6QleLIaJ3mNcpMROItCJo+xYFpnDTGUhjLtER2bxxGrFRvsQvCm10Jc2fdbqWN MLaKaX2cXeKCrNRBYYFW/eic6Pn2ng9AapIU61eASID3aIeeO8r6mpbBlOrDRJvsB4OI EHNg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1791439798; x=1792044598; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=WxcHRJfugXMLiqdeXIvqIsmL/ixZl6F8nmN4Ef0u2Gs=; b=fWZ1kSfycnVTW5zPSA8DiwAcJOsUGJSXctJmqLY9IHtkvx05yS41sWLwKum4fteY01 kV68QuTUKy/AIJmDmr0kijFTNoEVbK5Vw4M2XHL6C7XKkkGV0NgwTpeyDX7O1cgCssbV //raXu8bl0M3QQcOLnQn7u8WA0jA8uClq542weJu9hDwBFNqIoh4FcZTnOlqDooJKIpE H3L5PhQqh9A38/kxwOQaTkQTCkhFxbleUtsyhygBPPvMn211I/SQP1Ud9mbSTIeUIsCk jDUy7Yo5EdsOu4xrKnRjHgJfRSS9z9yctGqUxjO0zjXZn5afxaaeRfFvt3qUPEtL6fBY QlUQ== X-Gm-Message-State: AFq9FYIV9CxiO2d8Iz8IqCLRLb5IFp1wxqsxzDsbnl7C+ZzVwo1zF6uu qFN44KhujIvfKavJW1F+AQo4nC5tl7gafMjtDqviWyrco/7iRl56QQ5ClAk/oyYD X-Gm-Gg: AYBFou3j4do90PxNFKOuRF08qNTyYjeqCXs57aZQoHRFGEd2v8xi4waV6bBOMdySIhS kwZUKTA1RjjJXw6wgAMVCXYajAKsg2Dh93m25VU3tNekO7Cmy5X2mLLzwKaYmL1DfZqhhgrXH/b kc70c/Oe4Mmsxe7SzhDcQ1O6TuHonzxxb0fKREp3JYdVSNu7eYJM2cJ1QJToEYTrGobOCIMWAGZ /iN5QWTETT9pTvGH/LK2dverEJsoIen8NR0+N0PZ4T98dj5WCk4rDjrfYlA/Y7yqHgM0EE1HrCt kQgCncIm7hiSIJOfKSge82hw29N71CxSu1Pe+chmeOCnQ9Ijq7hcaEvJf+GkW+72pFvs8Tn27Q/ 7N1VjsGiYziDENcTPEVFUJo75tpbkiuqjprH+Zs295yq9JHuPkZ05DdT3GgmvsLq5/RTmtvuQnC n5BXCwtrNPhXAc/PujQLTvgc7G4XOvU+xMCeWLmDoIvoeGYrPSYRWM3Pms4QO4K1/3BQok0Jk8z HHb3Ab/ZV4LRY0lJGPHuJ0I24I= X-Received: by 2002:a05:6000:2489:b0:48b:60d:2b28 with SMTP id ffacd0b85a97d-48c7288f27emr8792392f8f.39.1791439797927; Wed, 07 Oct 2026 23:09:57 -0700 (PDT) Received: from penguin.lxd ([81.0.251.149]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48c71d3d3eesm10630219f8f.53.2026.10.07.23.09.56 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 07 Oct 2026 23:09:56 -0700 (PDT) From: Marta Rybczynska To: openembedded-core@lists.openembedded.org Cc: a.fatoum@pengutronix.de, adrian.freihofer@siemens.com, Marta Rybczynska Subject: [PATCH v4 3/3] uboot-sign: enable signing SPL FIT configuration Date: Thu, 8 Oct 2026 08:09:35 +0200 Message-Id: <20261008060935.4225-3-rybczynska@gmail.com> X-Mailer: git-send-email 2.39.5 In-Reply-To: <20261008060935.4225-1-rybczynska@gmail.com> References: <20261008060935.4225-1-rybczynska@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 08 Oct 2026 06:10:07 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/247415 This commit enables signing SPL FIT configuration instead of specific elements. This introduces an incompatibility with the previous behavior, but is the correct way to do. Signed-off-by: Marta Rybczynska --- meta/classes-recipe/uboot-sign.bbclass | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/meta/classes-recipe/uboot-sign.bbclass b/meta/classes-recipe/uboot-sign.bbclass index 42319d15ff..85138bc948 100644 --- a/meta/classes-recipe/uboot-sign.bbclass +++ b/meta/classes-recipe/uboot-sign.bbclass @@ -35,13 +35,13 @@ SPL_SIGN_ENABLE ?= "0" # Sign the FIT configuration in the SPL signing flow. Configuration # signatures bind the selected images and boot metadata together. -SPL_SIGN_CONF ?= "0" +SPL_SIGN_CONF ?= "1" # Legacy compatibility knob for per-image signatures in the SPL FIT path. # Individual image signatures do not protect the configuration metadata # which selects and parameterizes the boot images. # INSECURE, use at your own risk -SPL_SIGN_INDIVIDUAL ?= "1" +SPL_SIGN_INDIVIDUAL ?= "0" # Default value for deployment filenames. UBOOT_DTB_IMAGE ?= "u-boot-${MACHINE}-${PV}-${PR}.dtb"