[{"id":3678344,"web_url":"http://patchwork.ozlabs.org/comment/3678344/","msgid":"<CAFLszTgfT=4TLAt4qH42=THs59SzbHfAn5EmZbXaQThkXj4HQQ@mail.gmail.com>","list_archive_url":null,"date":"2026-04-16T19:37:24","subject":"Re: [PATCH v2 2/7] boot: fit: support generating DM verity cmdline\n parameters","submitter":{"id":6170,"url":"http://patchwork.ozlabs.org/api/people/6170/","name":"Simon Glass","email":"sjg@chromium.org"},"content":"Hi Daniel,\n\nOn 2026-04-16T01:46:15, Daniel Golle <daniel@makrotopia.org> wrote:\n> boot: fit: support generating DM verity cmdline parameters\n>\n> Add fit_verity_build_cmdline(): when a FILESYSTEM loadable carries a\n> dm-verity subnode, construct the dm-mod.create= kernel cmdline parameter\n> from the verity metadata (block-size, data-blocks, algo, root-hash,\n> salt) and append it to bootargs.\n>\n> Also add dm-mod.waitfor=/dev/fit0[,/dev/fitN] for each dm-verity device\n> so the kernel waits for the underlying FIT block device to appear before\n> setting up device-mapper targets. This is needed when the block driver\n> probes late, e.g. because it depends on NVMEM calibration data.\n>\n> The dm-verity target references /dev/fitN where N is the loadable's\n> index in the configuration -- matching the order Linux's FIT block\n> driver assigns block devices.  hash-start-block is read directly from\n> the FIT dm-verity node; mkimage ensures its value equals num-data-blocks\n> by invoking veritysetup with --no-superblock.\n>\n> Signed-off-by: Daniel Golle <daniel@makrotopia.org>\n>\n> boot/Kconfig       |  20 ++++\n>  boot/bootm.c       |  13 +++\n>  boot/image-board.c |   5 +\n>  boot/image-fit.c   | 337 +++++++++++++++++++++++++++++++++++++++++++++++++++++\n>  include/image.h    |  80 ++++++++++++-\n>  5 files changed, 454 insertions(+), 1 deletion(-)\n\n> diff --git a/boot/image-fit.c b/boot/image-fit.c\n> @@ -2642,3 +2683,299 @@ out:\n> +     /* Mandatory u32 properties */\n> +     val = fdt_getprop(fit, verity_node, FIT_VERITY_DBS_PROP, NULL);\n> +     if (!val)\n> +             return -EINVAL;\n> +     data_block_size = fdt32_to_cpu(*val);\n\nThis reads an fdt32_t into a signed int\n\ndata_block_size and hash_block_size are never negative, so could you\nuse uint instead?\n\n> diff --git a/boot/image-fit.c b/boot/image-fit.c\n> @@ -2642,3 +2683,299 @@ out:\n> +             printf(\"FIT: broken dm-verity metadata in '%s'\\n\",\n> +                    uname);\n\nThis file defines LOG_CATEGORY as LOGC_BOOT and includes log.h - how\nabout log_err() instead of printf() ?\n\nReviewed-by: Simon Glass <sjg@chromium.org>\n\nRegards,\nSimon","headers":{"Return-Path":"<u-boot-bounces@lists.denx.de>","X-Original-To":"incoming@patchwork.ozlabs.org","Delivered-To":"patchwork-incoming@legolas.ozlabs.org","Authentication-Results":["legolas.ozlabs.org;\n\tdkim=pass (1024-bit key;\n unprotected) header.d=chromium.org header.i=@chromium.org header.a=rsa-sha256\n header.s=google header.b=ArtuQ7XJ;\n\tdkim-atps=neutral","legolas.ozlabs.org;\n spf=pass (sender SPF authorized) smtp.mailfrom=lists.denx.de\n (client-ip=2a01:238:438b:c500:173d:9f52:ddab:ee01; helo=phobos.denx.de;\n envelope-from=u-boot-bounces@lists.denx.de; receiver=patchwork.ozlabs.org)","phobos.denx.de;\n dmarc=pass (p=none dis=none) header.from=chromium.org","phobos.denx.de;\n spf=pass smtp.mailfrom=u-boot-bounces@lists.denx.de","phobos.denx.de;\n\tdkim=pass (1024-bit key;\n unprotected) header.d=chromium.org header.i=@chromium.org\n header.b=\"ArtuQ7XJ\";\n\tdkim-atps=neutral","phobos.denx.de;\n dmarc=pass (p=none dis=none) header.from=chromium.org","phobos.denx.de;\n spf=pass smtp.mailfrom=sjg@chromium.org"],"Received":["from phobos.denx.de (phobos.denx.de\n [IPv6:2a01:238:438b:c500:173d:9f52:ddab:ee01])\n\t(using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)\n\t key-exchange x25519)\n\t(No client certificate requested)\n\tby legolas.ozlabs.org (Postfix) with ESMTPS id 4fxSw70nSDz1yCv\n\tfor <incoming@patchwork.ozlabs.org>; Fri, 17 Apr 2026 05:37:43 +1000 (AEST)","from h2850616.stratoserver.net (localhost [IPv6:::1])\n\tby phobos.denx.de (Postfix) with ESMTP id 0BE2E83EEF;\n\tThu, 16 Apr 2026 21:37:41 +0200 (CEST)","by phobos.denx.de (Postfix, from userid 109)\n id 186548421D; Thu, 16 Apr 2026 21:37:40 +0200 (CEST)","from mail-ej1-x633.google.com (mail-ej1-x633.google.com\n [IPv6:2a00:1450:4864:20::633])\n (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits))\n (No client certificate requested)\n by phobos.denx.de (Postfix) with ESMTPS id 241D480086\n for <u-boot@lists.denx.de>; Thu, 16 Apr 2026 21:37:38 +0200 (CEST)","by mail-ej1-x633.google.com with SMTP id\n a640c23a62f3a-b9d6c8871c7so1296059666b.1\n for <u-boot@lists.denx.de>; Thu, 16 Apr 2026 12:37:38 -0700 (PDT)"],"X-Spam-Checker-Version":"SpamAssassin 3.4.2 (2018-09-13) on phobos.denx.de","X-Spam-Level":"","X-Spam-Status":"No, score=-2.6 required=5.0 tests=BAYES_00,DKIMWL_WL_HIGH,\n DKIM_SIGNED,DKIM_VALID,DKIM_VALID_AU,DKIM_VALID_EF,\n RCVD_IN_DNSWL_BLOCKED,SPF_HELO_NONE,SPF_PASS autolearn=ham\n autolearn_force=no version=3.4.2","ARC-Seal":"i=1; a=rsa-sha256; t=1776368257; cv=none;\n d=google.com; s=arc-20240605;\n b=Y7YFqL0cwFsYSsRAPSBSgFJ0e2l/4m2vTDHSQWhamAEh83Y0plchouNEq/ayMchTII\n K6Z0uZ876dNU9xqCCoOM/0N5OsBYvnrvi5EJKQPCWtIJSj5jZMJNO5LcRWwDv4rOvHdW\n iFd+7a26l/7wsamkNTxiiHP5IztNSmll7fVyB2RH+UaPJC66PnSNcJ16QcOE3eZauwyd\n puWb4flSW0FHmL5TcBfPXx5gOvXWOHXonQmXy/F2VBV2QRzwVPiX7D5vNMxnrKW3LM0k\n Cc1vTCmNXjxkF71F64J+JSz0iT9gNyVVXCLQcw94a1ZQEq/rGZnusNhJm1Ba7p/eFeGR\n UbxQ==","ARC-Message-Signature":"i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com;\n s=arc-20240605;\n h=cc:to:subject:message-id:date:from:in-reply-to:references\n :mime-version:dkim-signature;\n bh=yfSEIeddzgSE0XQ2JozNGBZ9XPOSjVZ+tP7fRnAXNFo=;\n fh=fczxKqGjClYp6kaJlQAeWDTDwoxxX+FUSGPSbQ5yvh8=;\n b=HPGHybUtjl+31ChZCQ4T8gz7DlMi76Ny1JLoxrV2XLFL4ZNE8xnsmuBI+l1nt7EkB/\n KXKfL2fPobK0Ap5WxstkgDlakTqb/97wcg8P2gtSUFQOSYuUu9D6KHPAyfiUu41KtxA8\n aylA+FxJQVHhfJRAjaHDEhh9LJ9+CvM5D2t4BFMimt9mVtCN3sWrCYXhqoiCknjx/SUD\n 43mISMZIgB7yS8hFsyvj33HHBUFlBwxDArIPCRKNpDdgqObKdsaQv3pOCS+00ynXaHPN\n ke0niagZ0C0Mf6rGyp3+dYTeZYIkq7OU6GNuI3KBJhdx3eYeJQweAHc70tJEAlN5Tlio\n 5bOQ==; darn=lists.denx.de","ARC-Authentication-Results":"i=1; mx.google.com; arc=none","DKIM-Signature":"v=1; a=rsa-sha256; c=relaxed/relaxed;\n d=chromium.org; s=google; t=1776368257; x=1776973057; darn=lists.denx.de;\n h=cc:to:subject:message-id:date:from:in-reply-to:references\n :mime-version:from:to:cc:subject:date:message-id:reply-to;\n bh=yfSEIeddzgSE0XQ2JozNGBZ9XPOSjVZ+tP7fRnAXNFo=;\n b=ArtuQ7XJRff68ODN14xMN/K7KDp33SIdZvk7RttQgG5I5zHxCt9Rf8mPrM1AtwyZF3\n wCUcD7ihIlfllLTpTc89sp686QOxHQiJSyaJ+3Ed85oEvEurG4cvxJOH4CwVtrtqPPuX\n BRM8tHc4nGHIsLPwEDiGJCE785mjhBsXB5Ud0=","X-Google-DKIM-Signature":"v=1; a=rsa-sha256; c=relaxed/relaxed;\n d=1e100.net; s=20251104; t=1776368257; x=1776973057;\n h=cc:to:subject:message-id:date:from:in-reply-to:references\n :mime-version:x-gm-gg:x-gm-message-state:from:to:cc:subject:date\n :message-id:reply-to;\n bh=yfSEIeddzgSE0XQ2JozNGBZ9XPOSjVZ+tP7fRnAXNFo=;\n b=PF8uSktNHvx5i/vINZc5B0O2n3Z48pPhjPCLFuV1NaIz9YzHWpIhwteE1P6TXRVLCT\n RysBs9CmdCLywYQfhueQ/UuHGy1BKbrSaOufg8q8AKZALFob8aOHCPFUznJz3TizwDVq\n S+3TCjDjHmH654UWakSiXjQvm5Y+54jd+lyH6f1lcsW1Es0s6jALseeiO3Q6nrMlMs8t\n uQuUrQDppRh1Oq7sawBpk5x1WC8AEOKudBMEAjQTUujlJXwUXq6KZ/41tKnGykQq+3k+\n FYh6Rk+00LcZu4pyKIg93zQCtQTT10J1Jwkz4dUaU48OBpbODJ5M7QjPCpKIvTfUDEsE\n G3aw==","X-Forwarded-Encrypted":"i=1;\n AFNElJ/qOStRza45xV7+BaiVHXu5nMIXvaaFrm23fKc8WxGcmvmgU0nQKQjE1Tcl9Lp/29z+GbYR5Z0=@lists.denx.de","X-Gm-Message-State":"AOJu0YzxqG/nuYC0sNvLh1/Uo9yIpLYu8jlAduv9IMmKIffT3XTDw65y\n hDCUIYOcZFMrLn0MnJQm/IZrcs0Qn18kyYPpLS1xSXuhxgmHWb5R2RSPwjpOynZgcayy9+lo6XC\n sao7FDagXy69Gqu8/NJMM8BliC3RphEgIpXjHDz4Z","X-Gm-Gg":"AeBDieuD5nXjG9lyJWhdSGH/4H4NwS9MEU/oRoTVQH+rWB95dTvDorzO8bX2CYbclJx\n DeRR5U6Krj+2i+0wHoapgTE3Q2ZsSUiqHh4ZBQvNDaI1QUocT48buACeYcSQv/f7gpqdou8mCu2\n NujEtrSjGhehev4NxXVPw55EcJ0zl9jV7iZs0kn9K2QT9hkQfLrNXwJRrfx0u1aATSBjHkE72RM\n CV/keB9i+T97IVDCvOqeR9keu+f/l312asqz25Qp1+g4vOgyJg8Eq3APvuH33ruTAh9O85qaQsK\n XXque65+PPgdPxRBfEz0","X-Received":"by 2002:a17:906:b3a5:b0:b9d:8697:73b8 with SMTP id\n a640c23a62f3a-ba3db09213bmr34064666b.22.1776368257530; Thu, 16 Apr 2026\n 12:37:37 -0700 (PDT)","MIME-Version":"1.0","References":"<cover.1776302805.git.daniel@makrotopia.org>\n <5330ee823542d589e83cf7d2d21ee60ea51d6730.1776302806.git.daniel@makrotopia.org>","In-Reply-To":"\n <5330ee823542d589e83cf7d2d21ee60ea51d6730.1776302806.git.daniel@makrotopia.org>","From":"Simon Glass <sjg@chromium.org>","Date":"Fri, 17 Apr 2026 07:37:24 +1200","X-Gm-Features":"AQROBzCaWOk5CoZwva5Yy-TbuM878-UycYwwu_EdD6DcqXLZ8BMZWCzADgptc-s","Message-ID":"\n <CAFLszTgfT=4TLAt4qH42=THs59SzbHfAn5EmZbXaQThkXj4HQQ@mail.gmail.com>","Subject":"Re: [PATCH v2 2/7] boot: fit: support generating DM verity cmdline\n parameters","To":"daniel@makrotopia.org","Cc":"Tom Rini <trini@konsulko.com>, Simon Glass <sjg@chromium.org>,\n Quentin Schulz <quentin.schulz@cherry.de>,\n Kory Maincent <kory.maincent@bootlin.com>,\n Mattijs Korpershoek <mkorpershoek@kernel.org>, Peng Fan <peng.fan@nxp.com>,\n Heinrich Schuchardt <xypron.glpk@gmx.de>, Martin Schwan <m.schwan@phytec.de>,\n Anshul Dalal <anshuld@ti.com>,\n Ilias Apalodimas <ilias.apalodimas@linaro.org>,\n Sughosh Ganu <sughosh.ganu@arm.com>,\n Aristo Chen <jj251510319013@gmail.com>,\n Ludwig Nussel <ludwig.nussel@siemens.com>,\n Benjamin ROBIN <dev@benjarobin.fr>,\n Marek Vasut <marek.vasut+renesas@mailbox.org>,\n James Hilliard <james.hilliard1@gmail.com>,\n Wolfgang Wallner <wolfgang.wallner@at.abb.com>,\n Kunihiko Hayashi <hayashi.kunihiko@socionext.com>,\n David Lechner <dlechner@baylibre.com>,\n Neil Armstrong <neil.armstrong@linaro.org>,\n Mayuresh Chitale <mchitale@ventanamicro.com>,\n Jonas Karlman <jonas@kwiboo.se>, Shiji Yang <yangshiji66@outlook.com>,\n Rasmus Villemoes <ravi@prevas.dk>, Francois Berder <fberder@outlook.fr>,\n u-boot@lists.denx.de","Content-Type":"text/plain; charset=\"UTF-8\"","X-BeenThere":"u-boot@lists.denx.de","X-Mailman-Version":"2.1.39","Precedence":"list","List-Id":"U-Boot discussion <u-boot.lists.denx.de>","List-Unsubscribe":"<https://lists.denx.de/options/u-boot>,\n <mailto:u-boot-request@lists.denx.de?subject=unsubscribe>","List-Archive":"<https://lists.denx.de/pipermail/u-boot/>","List-Post":"<mailto:u-boot@lists.denx.de>","List-Help":"<mailto:u-boot-request@lists.denx.de?subject=help>","List-Subscribe":"<https://lists.denx.de/listinfo/u-boot>,\n <mailto:u-boot-request@lists.denx.de?subject=subscribe>","Errors-To":"u-boot-bounces@lists.denx.de","Sender":"\"U-Boot\" <u-boot-bounces@lists.denx.de>","X-Virus-Scanned":"clamav-milter 0.103.8 at phobos.denx.de","X-Virus-Status":"Clean"}}]