[{"id":3672882,"web_url":"http://patchwork.ozlabs.org/comment/3672882/","msgid":"<20260402193518.GH41863@bill-the-cat>","list_archive_url":null,"date":"2026-04-02T19:35:18","subject":"Re: [PATCH v2 1/3] tools: binman: Test signing an encrypted FIT with\n a preload header","submitter":{"id":65875,"url":"http://patchwork.ozlabs.org/api/people/65875/","name":"Tom Rini","email":"trini@konsulko.com"},"content":"On Thu, Apr 02, 2026 at 09:24:29PM +0200, yan wang wrote:\n\n> From: Paul HENRYS <paul.henrys_ext@softathome.com>\n> \n> Add a test to verify the preload header correctly signs an encrypted\n> FIT. This test exercises the case where encryption uses random IVs that\n> would change between mkimage calls.\n> \n> Signed-off-by: Paul HENRYS <paul.henrys_ext@softathome.com>\n> ---\n> Changes for v2:\n> - Rename test file as 351_pre_load_fit_encrypted.dts\n> - Update the commit message according to the remarks made\n> \n>  tools/binman/ftest.py                         | 17 +++++\n>  .../test/351_pre_load_fit_encrypted.dts       | 63 +++++++++++++++++++\n>  2 files changed, 80 insertions(+)\n>  create mode 100644 tools/binman/test/351_pre_load_fit_encrypted.dts\n\nThis should be against next, and we stopped using a numeric prefix on\ntest files and instead put them in to appropriate directories there (so\ntools/binman/test/fit in this case), thanks.","headers":{"Return-Path":"<u-boot-bounces@lists.denx.de>","X-Original-To":"incoming@patchwork.ozlabs.org","Delivered-To":"patchwork-incoming@legolas.ozlabs.org","Authentication-Results":["legolas.ozlabs.org;\n\tdkim=pass (1024-bit key;\n unprotected) header.d=konsulko.com header.i=@konsulko.com header.a=rsa-sha256\n header.s=google header.b=QjbGvD/F;\n\tdkim-atps=neutral","legolas.ozlabs.org;\n spf=pass (sender SPF authorized) smtp.mailfrom=lists.denx.de\n (client-ip=85.214.62.61; helo=phobos.denx.de;\n envelope-from=u-boot-bounces@lists.denx.de; receiver=patchwork.ozlabs.org)","phobos.denx.de;\n dmarc=pass (p=none dis=none) header.from=konsulko.com","phobos.denx.de;\n spf=pass smtp.mailfrom=u-boot-bounces@lists.denx.de","phobos.denx.de;\n\tdkim=pass (1024-bit key;\n unprotected) header.d=konsulko.com header.i=@konsulko.com\n header.b=\"QjbGvD/F\";\n\tdkim-atps=neutral","phobos.denx.de;\n dmarc=pass (p=none dis=none) header.from=konsulko.com","phobos.denx.de;\n spf=pass smtp.mailfrom=trini@konsulko.com"],"Received":["from phobos.denx.de (phobos.denx.de [85.214.62.61])\n\t(using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)\n\t key-exchange x25519 server-signature ECDSA (secp384r1) server-digest SHA384)\n\t(No client certificate requested)\n\tby legolas.ozlabs.org (Postfix) with ESMTPS id 4fmsX32W6vz1yCs\n\tfor <incoming@patchwork.ozlabs.org>; Fri, 03 Apr 2026 06:35:31 +1100 (AEDT)","from h2850616.stratoserver.net (localhost [IPv6:::1])\n\tby phobos.denx.de (Postfix) with ESMTP id 8D8C883F7D;\n\tThu,  2 Apr 2026 21:35:27 +0200 (CEST)","by phobos.denx.de (Postfix, from userid 109)\n id 887CE84020; Thu,  2 Apr 2026 21:35:26 +0200 (CEST)","from mail-ot1-x32c.google.com (mail-ot1-x32c.google.com\n [IPv6:2607:f8b0:4864:20::32c])\n (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits))\n (No client certificate requested)\n by phobos.denx.de (Postfix) with ESMTPS id 51E6C83CF5\n for <u-boot+nodisclaimer@lists.denx.de>;\n Thu,  2 Apr 2026 21:35:22 +0200 (CEST)","by mail-ot1-x32c.google.com with SMTP id\n 46e09a7af769-7d91f82d819so1319627a34.1\n for <u-boot+nodisclaimer@lists.denx.de>;\n Thu, 02 Apr 2026 12:35:22 -0700 (PDT)","from bill-the-cat (fixed-189-203-97-235.totalplay.net.\n [189.203.97.235]) by smtp.gmail.com with ESMTPSA id\n 586e51a60fabf-422eb42db1bsm3428575fac.17.2026.04.02.12.35.19\n (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256);\n Thu, 02 Apr 2026 12:35:20 -0700 (PDT)"],"X-Spam-Checker-Version":"SpamAssassin 3.4.2 (2018-09-13) on phobos.denx.de","X-Spam-Level":"","X-Spam-Status":"No, score=-2.1 required=5.0 tests=BAYES_00,DKIM_SIGNED,\n DKIM_VALID,DKIM_VALID_AU,DKIM_VALID_EF,RCVD_IN_DNSWL_BLOCKED,\n SPF_HELO_NONE,SPF_PASS autolearn=ham autolearn_force=no version=3.4.2","DKIM-Signature":"v=1; a=rsa-sha256; c=relaxed/relaxed;\n d=konsulko.com; s=google; t=1775158521; x=1775763321; darn=lists.denx.de;\n h=in-reply-to:content-disposition:mime-version:references:message-id\n :subject:cc:to:from:date:from:to:cc:subject:date:message-id:reply-to;\n bh=VGk8wOg0mDTuSTaW3C1fPXaoll9hckIOYGNUL5g5yB8=;\n b=QjbGvD/FxMR7CxkvgSLiC6uAEP2R0EMmN7iJDrBap+Ymm294QpCXzwVhl9QVo3MGDX\n aDDU8BCOkNUk0m2DcjpTxb1rjX2JvIiC7FcSa738Ghx5FO30j7vUvg5QMWLgyv+Qwold\n qmuFrR1jhRuyjgu7OoHFX5OSiXZUC+wN3XUHA=","X-Google-DKIM-Signature":"v=1; a=rsa-sha256; c=relaxed/relaxed;\n d=1e100.net; s=20251104; t=1775158521; x=1775763321;\n h=in-reply-to:content-disposition:mime-version:references:message-id\n :subject:cc:to:from:date:x-gm-gg:x-gm-message-state:from:to:cc\n :subject:date:message-id:reply-to;\n bh=VGk8wOg0mDTuSTaW3C1fPXaoll9hckIOYGNUL5g5yB8=;\n b=hz0UiZWCyhmeMQqwfNHDDu4fzUI6vS3dviBvGuTZpcaZ2SpNsi7RS/T9CDNH0hKAFG\n c++ZwtdKDsd01Jwi5CWrLyYLGUJpOSZ8MMJYJ94/9DNxGJfzcbMg4pXqc4nf3GP6Kr4F\n TAjzSxjVJlVEsLNfX7tEW2/+SFbTjkISVT/4iIybh5/ZorX5hiertnvupkJVz/uwBDJT\n UzrYoT5QFCSj9i3Rp+cQDIy4LCn22aM/+IkOE7VNF4PQ9q02QvBkDzBZXT+sYspn+MeC\n kRPMbh6E6BE8oYHl3M1+nMA5co4ijeG7VOzXD+QtL8hTjsrJPm17nYeJ63YBk3msyzW8\n X3gA==","X-Forwarded-Encrypted":"i=1;\n AJvYcCUH50zAk1lVhQJB6XqcXsdKcvCxL4PcrQXjYleDC+2CJM7vrpF1q22l06BAf6JcS27/Vjj4NPU=@lists.denx.de","X-Gm-Message-State":"AOJu0YzvNMY2tHueUrklyV6WiM0wes4k1LPODtYPu340bZNyM7i9LMYd\n vtYQlECWj5qDtqHZnBfZiKtvog0oIbTQa5BjN5Zh5aTdk94V+/61TorFqgwxkzfJ6hbPLYXCxvz\n BbYJUv3s=","X-Gm-Gg":"ATEYQzzXH5yBP9cv2BiWaLSFyS3yo7JT7hLo66AOTVEHkk0vp4VX2mpbKoPzMcHQesn\n nPUL1Vno5ljJpbUe3ECAp4Omzt711DFy0n+r96iuwwzlu8Y/NgC/2RjZp0JSqKL4fIZUKaVOnhS\n 6WKEj/28JdHJllQAeM+2yqDHC3LC3pniGyLW245jt/NP+uT0qMPpW+2nJP+AWq5gp9Aua/XCaVL\n R5nCnHErFW1UX7ZT/byJZD5vnZS7dgybTJvx5uJRyLRx2LL2ewpf+KHunxZ2HzurNDDGFCc/4N2\n yE9ugEOSM5WZj7xTMArjPxUIpU4NgKsJyENJ6kEgtkyZmbSxBjOs7/WtYzBXpHxi3zt9h1/Rise\n ryAd7ZIKgJk5huf2YKu+QyxtEK0B9b8kLPYLrBs6Tac/HSl2HZpswgBYWXNXGrdGTi97D+WlHB3\n 6LsHbqDO/4glvPnVpdy7ao7ZlCkJ5y0suS+6SklOP36Z3APeqXQJTIdB/ZYoWdTZSge8yTsjiuL\n gdtaCsM3FMYih4nRqaXvayXBULPecPfpZEVXYih6tAdhdO9","X-Received":"by 2002:a4a:e84c:0:b0:67e:3028:8bc with SMTP id\n 006d021491bc7-68220a48281mr240709eaf.57.1775158520874;\n Thu, 02 Apr 2026 12:35:20 -0700 (PDT)","Date":"Thu, 2 Apr 2026 13:35:18 -0600","From":"Tom Rini <trini@konsulko.com>","To":"yan wang <yan.wang@softathome.com>","Cc":"trini+nodisclaimer@konsulko.com, sjg+nodisclaimer@chromium.org,\n alpernebiyasak+nodisclaimer@gmail.com,\n philippe.reynes+nodisclaimer@softathome.com,\n paul.henrys_ext+nodisclaimer@softathome.com,\n u-boot+nodisclaimer@lists.denx.de,\n Paul HENRYS <paul.henrys_ext@softathome.com>","Subject":"Re: [PATCH v2 1/3] tools: binman: Test signing an encrypted FIT with\n a preload header","Message-ID":"<20260402193518.GH41863@bill-the-cat>","References":"<20260402192431.2421155-1-yan.wang@softathome.com>","MIME-Version":"1.0","Content-Type":"multipart/signed; micalg=pgp-sha512;\n protocol=\"application/pgp-signature\"; boundary=\"0LtXj98g8+HqjAIw\"","Content-Disposition":"inline","In-Reply-To":"<20260402192431.2421155-1-yan.wang@softathome.com>","X-Clacks-Overhead":"GNU Terry Pratchett","X-BeenThere":"u-boot@lists.denx.de","X-Mailman-Version":"2.1.39","Precedence":"list","List-Id":"U-Boot discussion <u-boot.lists.denx.de>","List-Unsubscribe":"<https://lists.denx.de/options/u-boot>,\n <mailto:u-boot-request@lists.denx.de?subject=unsubscribe>","List-Archive":"<https://lists.denx.de/pipermail/u-boot/>","List-Post":"<mailto:u-boot@lists.denx.de>","List-Help":"<mailto:u-boot-request@lists.denx.de?subject=help>","List-Subscribe":"<https://lists.denx.de/listinfo/u-boot>,\n <mailto:u-boot-request@lists.denx.de?subject=subscribe>","Errors-To":"u-boot-bounces@lists.denx.de","Sender":"\"U-Boot\" <u-boot-bounces@lists.denx.de>","X-Virus-Scanned":"clamav-milter 0.103.8 at phobos.denx.de","X-Virus-Status":"Clean"}}]