gpimage type requires only that two first 32-bit words of data file are
non-zero. So basically every random data file can be guessed and verified
as gpimage. So completely skip gpimage type from image autodetection code
to prevent lot of false positive results. Data file with gpimage type can
be still verified and parsed by explicitly specifying -T gpimage.

Signed-off-by: Pali Rohár <[email protected]>
---
 tools/imagetool.c | 6 ++++++
 1 file changed, 6 insertions(+)

diff --git a/tools/imagetool.c b/tools/imagetool.c
index e1021f44f5ad..87eee4ad04ed 100644
--- a/tools/imagetool.c
+++ b/tools/imagetool.c
@@ -49,6 +49,12 @@ int imagetool_verify_print_header(
                return imagetool_verify_print_header_by_type(ptr, sbuf, 
tparams, params);
 
        for (curr = start; curr != end; curr++) {
+               /*
+                * Basically every data file can be guessed / verified as 
gpimage,
+                * so skip autodetection of data file as gpimage as it does not 
work.
+                */
+               if ((*curr)->check_image_type && 
(*curr)->check_image_type(IH_TYPE_GPIMAGE) == 0)
+                       continue;
                if ((*curr)->verify_header) {
                        retval = (*curr)->verify_header((unsigned char *)ptr,
                                                     sbuf->st_size, params);
-- 
2.20.1

Reply via email to