From: Alexander Sverdlin <[email protected]>

mkimage doesn't fail if it is not able to sign FIT nodes.
This may lead to unbootable images in secure boot configurations.
Make signing failures fatal by parsing the mkimage output.

Signed-off-by: Alexander Sverdlin <[email protected]>
---
Changes in v3:
- bbfatag_log -> bberror + bbfatal_log with relevant mkimage output snippets
Changes in v2:
- bbfatal -> bbfatal_log

 meta/classes-recipe/kernel-fitimage.bbclass | 9 +++++++--
 1 file changed, 7 insertions(+), 2 deletions(-)

diff --git a/meta/classes-recipe/kernel-fitimage.bbclass 
b/meta/classes-recipe/kernel-fitimage.bbclass
index 67c98adb232..ccf848e643f 100644
--- a/meta/classes-recipe/kernel-fitimage.bbclass
+++ b/meta/classes-recipe/kernel-fitimage.bbclass
@@ -753,11 +753,16 @@ fitimage_assemble() {
        # Step 8: Sign the image
        #
        if [ "x${UBOOT_SIGN_ENABLE}" = "x1" ] ; then
-               ${UBOOT_MKIMAGE_SIGN} \
+               output=$(${UBOOT_MKIMAGE_SIGN} \
                        ${@'-D "${UBOOT_MKIMAGE_DTCOPTS}"' if 
len('${UBOOT_MKIMAGE_DTCOPTS}') else ''} \
                        -F -k "${UBOOT_SIGN_KEYDIR}" \
                        -r ${KERNEL_OUTPUT_DIR}/$2 \
-                       ${UBOOT_MKIMAGE_SIGN_ARGS}
+                       ${UBOOT_MKIMAGE_SIGN_ARGS})
+               echo "$output"
+               if err=$(echo "$output" | grep -C9 -E "Sign 
value:\s*unavailable"); then
+                       bberror "${UBOOT_MKIMAGE_SIGN} failed to provide 
signatures for these images:"
+                       bbfatal_log "\n$err"
+               fi
        fi
 }
 
-- 
2.46.0

-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#204109): 
https://lists.openembedded.org/g/openembedded-core/message/204109
Mute This Topic: https://lists.openembedded.org/mt/108229511/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

Reply via email to