[{"id":3673130,"web_url":"http://patchwork.ozlabs.org/comment/3673130/","msgid":"<CAFLszTgoEiVfWCBwW=mmqCUKREwH1n9xapKaLH=m2uZHYFJ5aw@mail.gmail.com>","list_archive_url":null,"date":"2026-04-03T13:22:04","subject":"Re: [PATCH v4 1/3] tools: binman: Test signing an encrypted FIT with\n a preload header","submitter":{"id":6170,"url":"http://patchwork.ozlabs.org/api/people/6170/","name":"Simon Glass","email":"sjg@chromium.org"},"content":"Hi Paul,\n\nOn 2026-04-03T07:55:27, Paul HENRYS <paul.henrys_ext@softathome.com> wrote:\n> tools: binman: Test signing an encrypted FIT with a preload header\n>\n> Add a test to verify the preload header correctly signs an encrypted\n> FIT. This test exercises the case where encryption uses random IVs that\n> would change between mkimage calls.\n>\n> Signed-off-by: Paul HENRYS <paul.henrys_ext@softathome.com>\n\n> diff --git a/tools/binman/ftest.py b/tools/binman/ftest.py\n> @@ -5895,6 +5895,27 @@ fdt         fdtmap                Extract the devicetree blob from the fdtmap\n> +    def testPreLoadEncryptedFit(self):\n> +        \"\"\"Test an encrypted FIT image with a pre-load header\"\"\"\n\nnit: for bisectability this should come last, since it relies on fixes\nin patches 2/3 and 3/3.\n\nRegards,\nSimon","headers":{"Return-Path":"<u-boot-bounces@lists.denx.de>","X-Original-To":"incoming@patchwork.ozlabs.org","Delivered-To":"patchwork-incoming@legolas.ozlabs.org","Authentication-Results":["legolas.ozlabs.org;\n\tdkim=pass (1024-bit key;\n unprotected) header.d=chromium.org header.i=@chromium.org header.a=rsa-sha256\n header.s=google header.b=kIOufBex;\n\tdkim-atps=neutral","legolas.ozlabs.org;\n spf=pass (sender SPF authorized) smtp.mailfrom=lists.denx.de\n (client-ip=2a01:238:438b:c500:173d:9f52:ddab:ee01; helo=phobos.denx.de;\n envelope-from=u-boot-bounces@lists.denx.de; receiver=patchwork.ozlabs.org)","phobos.denx.de;\n dmarc=pass (p=none dis=none) header.from=chromium.org","phobos.denx.de;\n spf=pass smtp.mailfrom=u-boot-bounces@lists.denx.de","phobos.denx.de;\n\tdkim=pass (1024-bit key;\n unprotected) header.d=chromium.org header.i=@chromium.org\n header.b=\"kIOufBex\";\n\tdkim-atps=neutral","phobos.denx.de;\n dmarc=pass (p=none dis=none) header.from=chromium.org","phobos.denx.de;\n spf=pass smtp.mailfrom=sjg@chromium.org"],"Received":["from phobos.denx.de (phobos.denx.de\n [IPv6:2a01:238:438b:c500:173d:9f52:ddab:ee01])\n\t(using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)\n\t key-exchange x25519)\n\t(No client certificate requested)\n\tby legolas.ozlabs.org (Postfix) with ESMTPS id 4fnKCQ2s6Kz1yCs\n\tfor <incoming@patchwork.ozlabs.org>; Sat, 04 Apr 2026 00:22:42 +1100 (AEDT)","from h2850616.stratoserver.net (localhost [IPv6:::1])\n\tby phobos.denx.de (Postfix) with ESMTP id C0FDC84105;\n\tFri,  3 Apr 2026 15:22:25 +0200 (CEST)","by phobos.denx.de (Postfix, from userid 109)\n id 1D84F84142; Fri,  3 Apr 2026 15:22:24 +0200 (CEST)","from mail-ed1-x52f.google.com (mail-ed1-x52f.google.com\n [IPv6:2a00:1450:4864:20::52f])\n (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits))\n (No client certificate requested)\n by phobos.denx.de (Postfix) with ESMTPS id 23E1583642\n for <u-boot@lists.denx.de>; Fri,  3 Apr 2026 15:22:22 +0200 (CEST)","by mail-ed1-x52f.google.com with SMTP id\n 4fb4d7f45d1cf-66bf15430ecso3445220a12.3\n for <u-boot@lists.denx.de>; Fri, 03 Apr 2026 06:22:22 -0700 (PDT)"],"X-Spam-Checker-Version":"SpamAssassin 3.4.2 (2018-09-13) on phobos.denx.de","X-Spam-Level":"","X-Spam-Status":"No, score=-2.6 required=5.0 tests=BAYES_00,DKIMWL_WL_HIGH,\n DKIM_SIGNED,DKIM_VALID,DKIM_VALID_AU,DKIM_VALID_EF,\n RCVD_IN_DNSWL_BLOCKED,SPF_HELO_NONE,SPF_PASS autolearn=ham\n autolearn_force=no version=3.4.2","ARC-Seal":"i=1; a=rsa-sha256; t=1775222541; cv=none;\n d=google.com; s=arc-20240605;\n b=F2enodNrDyTJLlniG/1RbVL/Sj46IOn9ZfELDNZdoX635v5iaVk1tLEruuES2yzM75\n S+E4y1VO754LlmCeUxIiTD0Au/b3UeHwCI1t7ysJg74cQ4eexlEY8dAlEtQWEN4ND48d\n cngkURVuY90cmSfZcxQlryToCVki+YNCkm1dn9BLHXlb1TjCQz8iTRL+r2Oqh5cmPKoD\n q+CvBv3Egeu7kQZbF4EI7ajIcv1CYMwFy7xQwjkMwp4bNPO32wnNRYXxUuD5nfOp0kLn\n B8JOM7G/2zCDIRl3RrPpWhHzBI3QOUYuZLtRIgny9qntUDOTpOyBAtmF37gxQxyiuL3J\n WNKg==","ARC-Message-Signature":"i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com;\n s=arc-20240605;\n h=cc:to:subject:message-id:date:from:in-reply-to:references\n :mime-version:dkim-signature;\n bh=ZIixh334PcGj9Ezwz5Ni+6EVLiFW8YDk9Dv4ruWEWt4=;\n fh=2Ai/DF/OygrgX5KD/xptwaXayaptkAAlqyY5KCXDcm8=;\n b=CHUyZcajzDHZtXMvCckPu6Ub5Jj1OreTzBK6ZzmJN+j2p7m3BZFUhUaymNwSQBmSH4\n gQR/jWBg1vP/3O0syXVXeNQBXCfJyllpnFG7Q5cCi8x028V7WWYHRVH7Ej38/L5HIqeX\n w/itxXBKGAugDLNoBpRe9ZVyeq3sXQVkvFveWl5XdP9uz9YcwoiX7236nArYZAYjdYn6\n Ws7nZ7nFkdv0GAG6J8mtHc4ysaaLAl9yQogBSpJ1FY1mo+7IqJfxIwutJXAn8uio63Nt\n RAMfrThk9C07z7dp5LcmvemoS3B40NoAbBuDxYXtWYj7XnFBsckrM06wjBWNCaW3SLZu\n Rk/A==; darn=lists.denx.de","ARC-Authentication-Results":"i=1; mx.google.com; arc=none","DKIM-Signature":"v=1; a=rsa-sha256; c=relaxed/relaxed;\n d=chromium.org; s=google; t=1775222541; x=1775827341; darn=lists.denx.de;\n h=cc:to:subject:message-id:date:from:in-reply-to:references\n :mime-version:from:to:cc:subject:date:message-id:reply-to;\n bh=ZIixh334PcGj9Ezwz5Ni+6EVLiFW8YDk9Dv4ruWEWt4=;\n b=kIOufBexYI91+NzpGWA0FxEishhXclArTMpVtjU3rUSwLDu/gdYlaQK0shBm3h6yfh\n TIAVM34wC9trZOu55QOa7m3ZKYdAq3+StQJ7tm8TuR2BswPwZwHkXdZ3hnePnR2qO/NU\n CLf9DeN2Kavfud0KsA8JIM45eIWVEz67Z3HrM=","X-Google-DKIM-Signature":"v=1; a=rsa-sha256; c=relaxed/relaxed;\n d=1e100.net; s=20251104; t=1775222541; x=1775827341;\n h=cc:to:subject:message-id:date:from:in-reply-to:references\n :mime-version:x-gm-gg:x-gm-message-state:from:to:cc:subject:date\n :message-id:reply-to;\n bh=ZIixh334PcGj9Ezwz5Ni+6EVLiFW8YDk9Dv4ruWEWt4=;\n b=UQ9niipC0p8rjOEsDVbrglp2f+XImoPHCWIg/0qW2DoJDrU8JiQPzfgjtGY8CnxZ0v\n qAJQeXcnP2rqEc3kTuFpHtzUXQXlzRpwrW3pztTCLtJIKVk0+cKcz+77QUV0CqR95fqP\n ga9k816hdjIbX+bH9VjTg0U9Xe7bW9GQennDmyBXLgDBO0uLXfvjyhWLyskM8eW915C7\n bV9UnPzQ8aWBmp65OlsIWs4Kz20JhGbCf8WX0ocPWCMOmwfdJoa07cYAKlkF9DFUyI4K\n VqTL79KZRuRLr/X8/UII3wmvjTNEgOwPf7+m6k/dTJzaUw0TSvlvr/xfuKwNGEMIWg4O\n uIHg==","X-Gm-Message-State":"AOJu0Yx10k2fvqBrhAs14t8kpnpCRakVC7sBv5Vl7pRn6XKXCOnWWTWe\n R0kBl57v1tJINTLaFmaWz+on2OYbIQehrJFWIDIDzrWkgITO3bFuMa6kJFKm/Iz0hg855YGaFwv\n 5f5jEd6Rfp6m900Say11yPlprFbpR/6N7xqqmq8PN","X-Gm-Gg":"AeBDiesHZQcaCxVOqzhgOYBQdU/FVL5ulQvKVm+dNfrNrfurne7ZLFMkrupH3Bm0B7Y\n s65AT4eO1gNgEvR0E3Go2OVBJ5ehTI82eQB5gX8iRkFl0g0OydYLKxOVQlXCiIL6r1Eszy/UvJm\n l4GwqfkiAYNh7JmOYQn4fwGradJ5AtCsS25kmuzGJpg1gkpBy81O3vw/Ln/vULpLYz70ewPupgA\n Hfz5g7S4ohUAHlOerT44Z2Ebt+V/m9SZ6Eit39Mb89S45st9/I0t4OUIlnfvMPBjTLHVORMSUrJ\n EDYcrg==","X-Received":"by 2002:a17:907:93c7:b0:b9b:1511:a865 with SMTP id\n a640c23a62f3a-b9c67b474f4mr107711366b.51.1775222541589; Fri, 03 Apr 2026\n 06:22:21 -0700 (PDT)","MIME-Version":"1.0","References":"<20260403073251.1051533-1-paul.henrys_ext@softathome.com>\n <20260403075528.1150196-1-paul.henrys_ext@softathome.com>","In-Reply-To":"<20260403075528.1150196-1-paul.henrys_ext@softathome.com>","From":"Simon Glass <sjg@chromium.org>","Date":"Fri, 3 Apr 2026 07:22:04 -0600","X-Gm-Features":"AQROBzAxeyLrFafmxUTvmFCgME-u0BOytzcPfVx2get8MFA7lbJ_zE3CEp4ZXzI","Message-ID":"\n <CAFLszTgoEiVfWCBwW=mmqCUKREwH1n9xapKaLH=m2uZHYFJ5aw@mail.gmail.com>","Subject":"Re: [PATCH v4 1/3] tools: binman: Test signing an encrypted FIT with\n a preload header","To":"paul.henrys_ext@softathome.com","Cc":"u-boot+nodisclaimer@lists.denx.de, sjg+nodisclaimer@chromium.org,\n trini+nodisclaimer@konsulko.com, alpernebiyasak+nodisclaimer@gmail.com,\n philippe.reynes+nodisclaimer@softathome.com, u-boot@lists.denx.de","Content-Type":"text/plain; charset=\"UTF-8\"","X-BeenThere":"u-boot@lists.denx.de","X-Mailman-Version":"2.1.39","Precedence":"list","List-Id":"U-Boot discussion <u-boot.lists.denx.de>","List-Unsubscribe":"<https://lists.denx.de/options/u-boot>,\n <mailto:u-boot-request@lists.denx.de?subject=unsubscribe>","List-Archive":"<https://lists.denx.de/pipermail/u-boot/>","List-Post":"<mailto:u-boot@lists.denx.de>","List-Help":"<mailto:u-boot-request@lists.denx.de?subject=help>","List-Subscribe":"<https://lists.denx.de/listinfo/u-boot>,\n <mailto:u-boot-request@lists.denx.de?subject=subscribe>","Errors-To":"u-boot-bounces@lists.denx.de","Sender":"\"U-Boot\" <u-boot-bounces@lists.denx.de>","X-Virus-Scanned":"clamav-milter 0.103.8 at phobos.denx.de","X-Virus-Status":"Clean"}}]