[{"id":1758098,"web_url":"http://patchwork.ozlabs.org/comment/1758098/","msgid":"<20170826204454.GS2827@bill-the-cat>","list_archive_url":null,"date":"2017-08-26T20:44:54","subject":"Re: [U-Boot] [Patch v2] configs: SECURE_BOOT: Enable\n\tCONFIG_CMD_EXT4_WRITE","submitter":{"id":65875,"url":"http://patchwork.ozlabs.org/api/people/65875/","name":"Tom Rini","email":"trini@konsulko.com"},"content":"On Fri, Aug 25, 2017 at 03:33:10PM +0530, Sumit Garg wrote:\n\n> As part of chain of trust with confidentiality along with distro\n> boot, linux kernel image needs to be stored in encrypted form on\n> ext4 boot partition. So enable CONFIG_CMD_EXT4_WRITE in case of\n> Secure boot.\n> \n> Signed-off-by: Sumit Garg <sumit.garg@nxp.com>\n\nReviewed-by: Tom Rini <trini@konsulko.com>","headers":{"Return-Path":"<u-boot-bounces@lists.denx.de>","X-Original-To":"incoming@patchwork.ozlabs.org","Delivered-To":"patchwork-incoming@bilbo.ozlabs.org","Authentication-Results":["ozlabs.org;\n\tspf=none (mailfrom) smtp.mailfrom=lists.denx.de\n\t(client-ip=81.169.180.215; helo=lists.denx.de;\n\tenvelope-from=u-boot-bounces@lists.denx.de;\n\treceiver=<UNKNOWN>)","ozlabs.org;\n\tdkim=fail reason=\"signature verification failed\" (1024-bit key;\n\tunprotected) header.d=konsulko.com header.i=@konsulko.com\n\theader.b=\"sfbqSG8T\"; dkim-atps=neutral"],"Received":["from lists.denx.de (dione.denx.de [81.169.180.215])\n\tby ozlabs.org (Postfix) with ESMTP id 3xfqlh6txqz9s8V\n\tfor <incoming@patchwork.ozlabs.org>;\n\tSun, 27 Aug 2017 06:44:48 +1000 (AEST)","by lists.denx.de (Postfix, from userid 105)\n\tid A6DF4C220FB; Sat, 26 Aug 2017 20:44:46 +0000 (UTC)","from lists.denx.de (localhost [IPv6:::1])\n\tby lists.denx.de (Postfix) with ESMTP id AC4AFC220AE;\n\tSat, 26 Aug 2017 20:44:43 +0000 (UTC)","by lists.denx.de (Postfix, from userid 105)\n\tid 9C134C220BB; Sat, 26 Aug 2017 20:44:42 +0000 (UTC)","from mail-yw0-f175.google.com (mail-yw0-f175.google.com\n\t[209.85.161.175])\n\tby lists.denx.de (Postfix) with ESMTPS id 2B135C220AB\n\tfor <u-boot@lists.denx.de>; Sat, 26 Aug 2017 20:44:41 +0000 (UTC)","by mail-yw0-f175.google.com with SMTP id h127so13591148ywf.3\n\tfor <u-boot@lists.denx.de>; Sat, 26 Aug 2017 13:44:41 -0700 (PDT)","from bill-the-cat ([2606:a000:1408:4167:e120:606c:6fb9:7c7a])\n\tby smtp.gmail.com with ESMTPSA id\n\tv2sm3299696ywh.19.2017.08.26.13.44.39\n\t(version=TLS1_2 cipher=AES128-SHA bits=128/128);\n\tSat, 26 Aug 2017 13:44:39 -0700 (PDT)"],"X-Spam-Checker-Version":"SpamAssassin 3.4.0 (2014-02-07) on lists.denx.de","X-Spam-Level":"","X-Spam-Status":"No, score=-0.0 required=5.0 tests=RCVD_IN_DNSWL_NONE,\n\tRCVD_IN_MSPIKE_H3, RCVD_IN_MSPIKE_WL,\n\tT_DKIM_INVALID autolearn=unavailable\n\tautolearn_force=no version=3.4.0","DKIM-Signature":"v=1; a=rsa-sha256; c=relaxed/relaxed; d=konsulko.com;\n\ts=google; \n\th=date:from:to:cc:subject:message-id:references:mime-version\n\t:content-disposition:in-reply-to:user-agent;\n\tbh=4Y76IXEP0ZmgJ9IuJLV60NEGcpNCOAezElJO5pGuiUk=;\n\tb=sfbqSG8TQRd10qC7x1CL2jLEH4nyc6haRB+leCYpYH9QQX1ssrXk9gOaaNpBw0NMw8\n\t/C2mG2RRv8WrZ/XBZPlFYdgR87QFge93T1l8rekJjztgxOAyKFMwZet50H9wlg6SikLS\n\tba6z3rN4wD6BDE5rWypFaBedItUc9QMEP7O6I=","X-Google-DKIM-Signature":"v=1; a=rsa-sha256; c=relaxed/relaxed;\n\td=1e100.net; s=20161025;\n\th=x-gm-message-state:date:from:to:cc:subject:message-id:references\n\t:mime-version:content-disposition:in-reply-to:user-agent;\n\tbh=4Y76IXEP0ZmgJ9IuJLV60NEGcpNCOAezElJO5pGuiUk=;\n\tb=QbDoZYdzn+JPf4ReXGwa6xVyiXLgH8MsSTtQYxxPx0XwjtDmFxH5IgIqDKaZ5C1eqC\n\tVQZ+I0wsasQdY6cO4bdi3a9ingxH6CrVOo6BQWvkMJJ6kASb2eP8W9DOJ4Z9WTm1LSKI\n\t6TV6wS932C6J3nKRsGpqWkadNrnji2U5m5GeyRQNwyXJPLCcbGBE9pVzW/+o2JureNmo\n\t2Qek6Pv0oV01lxcS2lYxiChbzazznIyzzpEg43RQezIO9NsbjgFYujttkE1K6cs6j3Ri\n\tKCU7x1wMBCf/kflp29MCedoI2FynYGEoZZWtULGgDCDiAp8Z0EIoZNgf/i9hg7hNYrdK\n\tbtRg==","X-Gm-Message-State":"AHYfb5gek4+D9pMinXXsoiSRPpfQziqQ7fIMs7pyAmOp5a0+FJtgsYV1\n\tb9WuUIUUfnJ3Tv+N","X-Received":"by 10.129.159.132 with SMTP id\n\tw126mr2237920ywg.393.1503780279899; \n\tSat, 26 Aug 2017 13:44:39 -0700 (PDT)","Date":"Sat, 26 Aug 2017 16:44:54 -0400","From":"Tom Rini <trini@konsulko.com>","To":"Sumit Garg <sumit.garg@nxp.com>","Message-ID":"<20170826204454.GS2827@bill-the-cat>","References":"<1503655390-16829-1-git-send-email-sumit.garg@nxp.com>","MIME-Version":"1.0","In-Reply-To":"<1503655390-16829-1-git-send-email-sumit.garg@nxp.com>","User-Agent":"Mutt/1.5.21 (2010-09-15)","Cc":"u-boot@lists.denx.de, ruchika.gupta@nxp.com","Subject":"Re: [U-Boot] [Patch v2] configs: SECURE_BOOT: Enable\n\tCONFIG_CMD_EXT4_WRITE","X-BeenThere":"u-boot@lists.denx.de","X-Mailman-Version":"2.1.18","Precedence":"list","List-Id":"U-Boot discussion <u-boot.lists.denx.de>","List-Unsubscribe":"<https://lists.denx.de/options/u-boot>,\n\t<mailto:u-boot-request@lists.denx.de?subject=unsubscribe>","List-Archive":"<http://lists.denx.de/pipermail/u-boot/>","List-Post":"<mailto:u-boot@lists.denx.de>","List-Help":"<mailto:u-boot-request@lists.denx.de?subject=help>","List-Subscribe":"<https://lists.denx.de/listinfo/u-boot>,\n\t<mailto:u-boot-request@lists.denx.de?subject=subscribe>","Content-Type":"multipart/mixed;\n\tboundary=\"===============0949308939666296297==\"","Errors-To":"u-boot-bounces@lists.denx.de","Sender":"\"U-Boot\" <u-boot-bounces@lists.denx.de>"}},{"id":1764229,"web_url":"http://patchwork.ozlabs.org/comment/1764229/","msgid":"<VI1PR04MB2078FC2BFB40825D947FC83F9A970@VI1PR04MB2078.eurprd04.prod.outlook.com>","list_archive_url":null,"date":"2017-09-06T16:16:46","subject":"Re: [U-Boot] [Patch v2] configs: SECURE_BOOT: Enable\n\tCONFIG_CMD_EXT4_WRITE","submitter":{"id":67822,"url":"http://patchwork.ozlabs.org/api/people/67822/","name":"York Sun","email":"york.sun@nxp.com"},"content":"On 08/25/2017 03:03 AM, Sumit Garg wrote:\n> As part of chain of trust with confidentiality along with distro\n> boot, linux kernel image needs to be stored in encrypted form on\n> ext4 boot partition. So enable CONFIG_CMD_EXT4_WRITE in case of\n> Secure boot.\n> \n> Signed-off-by: Sumit Garg <sumit.garg@nxp.com>\n> ---\n> \n> Changes in v2:\n> Instead of adding CMD_EXT4_WRITE option in each defconfig, added this\n> option in Kconfig.\n> \n>   board/freescale/common/Kconfig | 2 ++\n>   1 file changed, 2 insertions(+)\n> \n> diff --git a/board/freescale/common/Kconfig b/board/freescale/common/Kconfig\n> index 53b606e..3496eed 100644\n> --- a/board/freescale/common/Kconfig\n> +++ b/board/freescale/common/Kconfig\n> @@ -6,6 +6,8 @@ config CHAIN_OF_TRUST\n>   \tselect SPL_BOARD_INIT if (ARM && SPL)\n>   \tselect SHA_HW_ACCEL\n>   \tselect SHA_PROG_HW_ACCEL\n> +\tselect CMD_EXT4\n> +\tselect CMD_EXT4_WRITE\n>   \tbool\n>   \tdefault y\n\nAre you going to need this for all PowerPC platforms? This changes \nincreases 3K in text section.\n\nWill Ruchika confirm?\n\nYork","headers":{"Return-Path":"<u-boot-bounces@lists.denx.de>","X-Original-To":"incoming@patchwork.ozlabs.org","Delivered-To":"patchwork-incoming@bilbo.ozlabs.org","Authentication-Results":["ozlabs.org;\n\tspf=none (mailfrom) smtp.mailfrom=lists.denx.de\n\t(client-ip=81.169.180.215; helo=lists.denx.de;\n\tenvelope-from=u-boot-bounces@lists.denx.de;\n\treceiver=<UNKNOWN>)","ozlabs.org;\n\tdkim=fail reason=\"signature verification failed\" (1024-bit key;\n\tunprotected) header.d=nxp.com header.i=@nxp.com header.b=\"e1yUwgSS\";\n\tdkim-atps=neutral","spf=none (sender IP is )\n\tsmtp.mailfrom=york.sun@nxp.com; "],"Received":["from lists.denx.de (dione.denx.de [81.169.180.215])\n\tby ozlabs.org (Postfix) with ESMTP id 3xnTHX2bNKz9s7c\n\tfor <incoming@patchwork.ozlabs.org>;\n\tThu,  7 Sep 2017 02:16:56 +1000 (AEST)","by lists.denx.de (Postfix, from userid 105)\n\tid 00EE9C21F35; Wed,  6 Sep 2017 16:16:53 +0000 (UTC)","from lists.denx.de (localhost [IPv6:::1])\n\tby lists.denx.de (Postfix) with ESMTP id 92911C21E3B;\n\tWed,  6 Sep 2017 16:16:51 +0000 (UTC)","by lists.denx.de (Postfix, from userid 105)\n\tid D4BE3C21E3B; Wed,  6 Sep 2017 16:16:49 +0000 (UTC)","from EUR01-HE1-obe.outbound.protection.outlook.com\n\t(mail-he1eur01on0057.outbound.protection.outlook.com [104.47.0.57])\n\tby lists.denx.de (Postfix) with ESMTPS id 52D82C21E11\n\tfor <u-boot@lists.denx.de>; Wed,  6 Sep 2017 16:16:49 +0000 (UTC)","from VI1PR04MB2078.eurprd04.prod.outlook.com (10.166.43.18) by\n\tVI1PR04MB1599.eurprd04.prod.outlook.com (10.164.84.145) with\n\tMicrosoft SMTP Server (version=TLS1_2,\n\tcipher=TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384_P256) id\n\t15.20.13.10; Wed, 6 Sep 2017 16:16:47 +0000","from VI1PR04MB2078.eurprd04.prod.outlook.com\n\t([fe80::6943:4a49:ab20:5920]) by\n\tVI1PR04MB2078.eurprd04.prod.outlook.com\n\t([fe80::6943:4a49:ab20:5920%13]) with mapi id 15.20.0013.018;\n\tWed, 6 Sep 2017 16:16:46 +0000"],"X-Spam-Checker-Version":"SpamAssassin 3.4.0 (2014-02-07) on lists.denx.de","X-Spam-Level":"","X-Spam-Status":"No, score=-1.0 required=5.0 tests=RCVD_IN_DNSWL_NONE,\n\tRCVD_IN_MSPIKE_H5,RCVD_IN_MSPIKE_WL,SPF_HELO_PASS,T_DKIM_INVALID\n\tautolearn=unavailable autolearn_force=no version=3.4.0","DKIM-Signature":"v=1; a=rsa-sha256; c=relaxed/relaxed; d=nxp.com; s=selector1;\n\th=From:Date:Subject:Message-ID:Content-Type:MIME-Version;\n\tbh=+bGN5g99xkzPuVBSH+KFM8E4Q/lCM5Vq375pd1MU73c=;\n\tb=e1yUwgSSOTG/ZL6TSS6X/2Qbidja4B5SDhUlc7K5tDmxWmzrsUvH5T3bTAfDXUq6zqxpehQyqqWgBuemAMneXBCG7ZuRxwTuBNYHSDmtWymWHKNHYoCXjYrNFnJj0t8bjQr7e6tLzKBfJVwpa2VqPGp0HtMuFer4znjNEIjnXPw=","From":"York Sun <york.sun@nxp.com>","To":"Sumit Garg <sumit.garg@nxp.com>, \"u-boot@lists.denx.de\"\n\t<u-boot@lists.denx.de>","Thread-Topic":"[Patch v2] configs: SECURE_BOOT: Enable CONFIG_CMD_EXT4_WRITE","Thread-Index":"AQHTHYljb9V9OglZKE23vqrkyaaWmg==","Date":"Wed, 6 Sep 2017 16:16:46 +0000","Message-ID":"<VI1PR04MB2078FC2BFB40825D947FC83F9A970@VI1PR04MB2078.eurprd04.prod.outlook.com>","References":"<1503655390-16829-1-git-send-email-sumit.garg@nxp.com>","Accept-Language":"en-US","Content-Language":"en-US","X-MS-Has-Attach":"","X-MS-TNEF-Correlator":"","authentication-results":["ozlabs.org;\n\tspf=none (mailfrom) smtp.mailfrom=lists.denx.de\n\t(client-ip=81.169.180.215; helo=lists.denx.de;\n\tenvelope-from=u-boot-bounces@lists.denx.de;\n\treceiver=<UNKNOWN>)","ozlabs.org;\n\tdkim=fail reason=\"signature verification failed\" (1024-bit key;\n\tunprotected) header.d=nxp.com header.i=@nxp.com header.b=\"e1yUwgSS\";\n\tdkim-atps=neutral","spf=none (sender IP is )\n\tsmtp.mailfrom=york.sun@nxp.com; "],"x-originating-ip":"[24.56.243.53]","x-ms-publictraffictype":"Email","x-microsoft-exchange-diagnostics":"1; VI1PR04MB1599;\n\t6:kwkkoPknSdey2P0PjAlNb5m+1mVFe/4x5C4CUIe1YTXIvtXs+4r7fqRqkYRLleO7bix3nxfYEsJ6CkF1BWOwXg+0LLVLucKX6NtrfveiJ6cBOYbP73X71nwHnYIMsEp+kP+R/fLG5wTcvR77dJlwI2m8IHF7FPGAemlYYSsytmd1NED7GTLfvN68cl441X13cn2BOqwpBdtUF+DAM2OoF1M5hIj//f0IFbnf4gWYhPlo1B3GH7NWUr9+gg0teQoB7kKltHKeiR8A0PNYawT0dCH0LKUOR/twQtwkDGKEVSEQmMpSXyFyLFOKGIeL6gJ6vn+DC7wTjKPM8Rh8xEW5IA==;\n\t5:77xbJNUr5hamihHKY8cDYJGtWu0FxSHqkYZHYrdn9myV8U2/K3oI2JdJodNwZHSe3fiWjgjP1VVMs3M+AT8u5RgJwi1OXgExZ3RHG5HZV4qu3gqRjbAvbeaprw/ZIhLqJnrSYOnEleTillj2e75bBA==;\n\t24:iuaqv+ToduBsz0ZwZ8NF3+2I3KnKqKNNE8EP2PSNPk3uk5Z4Do5UnrKxBRkTLGscLo3gdeupogeeoRnfpUFHfF9EognDBQXlgtZkEobEoeU=;\n\t7:LVSAKfbdr6ob0lumCZf1Hf++9lkkvzuQF8znJxcZkLpSeCYZxv5IRpkCwZNcTNnSmxPxxhhRtBoVkApPKBGeTYvmxMxNHqr6OkJPuxC4OjZS0inqWN/yMzrg4nfAA47bf5tbNw+eQnsGpSAcs3VwK8ymssgvY5vlDe3sT7rjOYr7LSZS4FuVNeoRpFvh2kktuw6c9IHVKpMuDYIjaXbC1795i9sY9jmAa99KT0/wvWk=","x-ms-exchange-antispam-srfa-diagnostics":"SSOS;SSOR;","x-forefront-antispam-report":"SFV:SKI; SCL:-1; SFV:NSPM;\n\tSFS:(10009020)(6009001)(39860400002)(199003)(189002)(24454002)(377454003)(4326008)(33656002)(81166006)(229853002)(6506006)(86362001)(6436002)(68736007)(2900100001)(14454004)(53546010)(7696004)(6116002)(3450700001)(50986999)(102836003)(3846002)(2906002)(54356999)(5250100002)(3280700002)(3660700001)(97736004)(2501003)(76176999)(5660300001)(25786009)(43066003)(101416001)(54906002)(55016002)(99286003)(74316002)(305945005)(9686003)(106356001)(7736002)(105586002)(8676002)(189998001)(8936002)(81156014)(66066001)(6246003)(53936002)(478600001)(15760500002);\n\tDIR:OUT; SFP:1101; SCL:1; SRVR:VI1PR04MB1599;\n\tH:VI1PR04MB2078.eurprd04.prod.outlook.com; FPR:; SPF:None;\n\tPTR:InfoNoRecords; A:1; MX:1; LANG:en; ","x-ms-office365-filtering-correlation-id":"227167f5-3f00-4758-1539-08d4f542abad","x-ms-office365-filtering-ht":"Tenant","x-microsoft-antispam":"UriScan:; BCL:0; PCL:0;\n\tRULEID:(300000500095)(300135000095)(300000501095)(300135300095)(22001)(300000502095)(300135100095)(2017030254152)(48565401081)(300000503095)(300135400095)(2017052603199)(201703131423075)(201703031133081)(201702281549075)(300000504095)(300135200095)(300000505095)(300135600095)(300000506095)(300135500095);\n\tSRVR:VI1PR04MB1599; ","x-ms-traffictypediagnostic":"VI1PR04MB1599:","x-exchange-antispam-report-test":"UriScan:(185117386973197);","x-microsoft-antispam-prvs":"<VI1PR04MB1599BFF3B48C85F7C0E9D9FB9A970@VI1PR04MB1599.eurprd04.prod.outlook.com>","x-exchange-antispam-report-cfa-test":"BCL:0; PCL:0;\n\tRULEID:(100000700101)(100105000095)(100000701101)(100105300095)(100000702101)(100105100095)(6040450)(2401047)(8121501046)(5005006)(3002001)(100000703101)(100105400095)(10201501046)(93006095)(93001095)(6055026)(6041248)(20161123564025)(20161123555025)(20161123558100)(20161123560025)(201703131423075)(201702281528075)(201703061421075)(201703061406153)(20161123562025)(6072148)(201708071742011)(100000704101)(100105200095)(100000705101)(100105500095);\n\tSRVR:VI1PR04MB1599; BCL:0; PCL:0;\n\tRULEID:(100000800101)(100110000095)(100000801101)(100110300095)(100000802101)(100110100095)(100000803101)(100110400095)(100000804101)(100110200095)(100000805101)(100110500095);\n\tSRVR:VI1PR04MB1599; ","x-forefront-prvs":"0422860ED4","received-spf":"None (protection.outlook.com: nxp.com does not designate\n\tpermitted sender hosts)","spamdiagnosticoutput":"1:99","spamdiagnosticmetadata":"NSPM","MIME-Version":"1.0","X-OriginatorOrg":"nxp.com","X-MS-Exchange-CrossTenant-originalarrivaltime":"06 Sep 2017 16:16:46.1413\n\t(UTC)","X-MS-Exchange-CrossTenant-fromentityheader":"Hosted","X-MS-Exchange-CrossTenant-id":"686ea1d3-bc2b-4c6f-a92c-d99c5c301635","X-MS-Exchange-Transport-CrossTenantHeadersStamped":"VI1PR04MB1599","Cc":"\"trini@konsulko.com\" <trini@konsulko.com>,\n\tRuchika Gupta <ruchika.gupta@nxp.com>","Subject":"Re: [U-Boot] [Patch v2] configs: SECURE_BOOT: Enable\n\tCONFIG_CMD_EXT4_WRITE","X-BeenThere":"u-boot@lists.denx.de","X-Mailman-Version":"2.1.18","Precedence":"list","List-Id":"U-Boot discussion <u-boot.lists.denx.de>","List-Unsubscribe":"<https://lists.denx.de/options/u-boot>,\n\t<mailto:u-boot-request@lists.denx.de?subject=unsubscribe>","List-Archive":"<http://lists.denx.de/pipermail/u-boot/>","List-Post":"<mailto:u-boot@lists.denx.de>","List-Help":"<mailto:u-boot-request@lists.denx.de?subject=help>","List-Subscribe":"<https://lists.denx.de/listinfo/u-boot>,\n\t<mailto:u-boot-request@lists.denx.de?subject=subscribe>","Reply-To":"York Sun <york.sun@nxp.com>","Content-Type":"text/plain; charset=\"utf-8\"","Content-Transfer-Encoding":"base64","Errors-To":"u-boot-bounces@lists.denx.de","Sender":"\"U-Boot\" <u-boot-bounces@lists.denx.de>"}},{"id":1764492,"web_url":"http://patchwork.ozlabs.org/comment/1764492/","msgid":"<VI1PR04MB14558121F45778F20387247098940@VI1PR04MB1455.eurprd04.prod.outlook.com>","list_archive_url":null,"date":"2017-09-07T04:10:24","subject":"Re: [U-Boot] [Patch v2] configs: SECURE_BOOT: Enable\n\tCONFIG_CMD_EXT4_WRITE","submitter":{"id":68653,"url":"http://patchwork.ozlabs.org/api/people/68653/","name":"Sumit Garg","email":"sumit.garg@nxp.com"},"content":"> -----Original Message-----\n> From: York Sun\n> Sent: Wednesday, September 06, 2017 9:47 PM\n> To: Sumit Garg <sumit.garg@nxp.com>; u-boot@lists.denx.de\n> Cc: Ruchika Gupta <ruchika.gupta@nxp.com>; Prabhakar Kushwaha\n> <prabhakar.kushwaha@nxp.com>; trini@konsulko.com\n> Subject: Re: [Patch v2] configs: SECURE_BOOT: Enable\n> CONFIG_CMD_EXT4_WRITE\n> \n> On 08/25/2017 03:03 AM, Sumit Garg wrote:\n> > As part of chain of trust with confidentiality along with distro boot,\n> > linux kernel image needs to be stored in encrypted form on\n> > ext4 boot partition. So enable CONFIG_CMD_EXT4_WRITE in case of Secure\n> > boot.\n> >\n> > Signed-off-by: Sumit Garg <sumit.garg@nxp.com>\n> > ---\n> >\n> > Changes in v2:\n> > Instead of adding CMD_EXT4_WRITE option in each defconfig, added this\n> > option in Kconfig.\n> >\n> >   board/freescale/common/Kconfig | 2 ++\n> >   1 file changed, 2 insertions(+)\n> >\n> > diff --git a/board/freescale/common/Kconfig\n> > b/board/freescale/common/Kconfig index 53b606e..3496eed 100644\n> > --- a/board/freescale/common/Kconfig\n> > +++ b/board/freescale/common/Kconfig\n> > @@ -6,6 +6,8 @@ config CHAIN_OF_TRUST\n> >   \tselect SPL_BOARD_INIT if (ARM && SPL)\n> >   \tselect SHA_HW_ACCEL\n> >   \tselect SHA_PROG_HW_ACCEL\n> > +\tselect CMD_EXT4\n> > +\tselect CMD_EXT4_WRITE\n> >   \tbool\n> >   \tdefault y\n> \n> Are you going to need this for all PowerPC platforms? This changes increases 3K\n> in text section.\n> \n> Will Ruchika confirm?\n> \n> York\n\nWe don't need this option on PowerPC platforms as we currently don't support distro\nboot on PowerPC platforms. So we can enable this option for ARM platforms only.\n\nSumit","headers":{"Return-Path":"<u-boot-bounces@lists.denx.de>","X-Original-To":"incoming@patchwork.ozlabs.org","Delivered-To":"patchwork-incoming@bilbo.ozlabs.org","Authentication-Results":["ozlabs.org;\n\tspf=none (mailfrom) smtp.mailfrom=lists.denx.de\n\t(client-ip=81.169.180.215; helo=lists.denx.de;\n\tenvelope-from=u-boot-bounces@lists.denx.de;\n\treceiver=<UNKNOWN>)","ozlabs.org;\n\tdkim=fail reason=\"signature verification failed\" (1024-bit key;\n\tunprotected) header.d=nxp.com header.i=@nxp.com header.b=\"UdnvB4sp\";\n\tdkim-atps=neutral","spf=none (sender IP is )\n\tsmtp.mailfrom=sumit.garg@nxp.com; "],"Received":["from lists.denx.de (dione.denx.de [81.169.180.215])\n\tby ozlabs.org (Postfix) with ESMTP id 3xnn7337JWz9sCZ\n\tfor <incoming@patchwork.ozlabs.org>;\n\tThu,  7 Sep 2017 14:10:39 +1000 (AEST)","by lists.denx.de (Postfix, from userid 105)\n\tid 19B1FC21E14; Thu,  7 Sep 2017 04:10:33 +0000 (UTC)","from lists.denx.de (localhost [IPv6:::1])\n\tby lists.denx.de (Postfix) with ESMTP id 65284C21C40;\n\tThu,  7 Sep 2017 04:10:30 +0000 (UTC)","by lists.denx.de (Postfix, from userid 105)\n\tid 96F40C21C40; Thu,  7 Sep 2017 04:10:28 +0000 (UTC)","from EUR01-DB5-obe.outbound.protection.outlook.com\n\t(mail-db5eur01on0061.outbound.protection.outlook.com [104.47.2.61])\n\tby lists.denx.de (Postfix) with ESMTPS id 16A0AC21C3C\n\tfor <u-boot@lists.denx.de>; Thu,  7 Sep 2017 04:10:28 +0000 (UTC)","from VI1PR04MB1455.eurprd04.prod.outlook.com (10.163.166.147) by\n\tVI1PR04MB1567.eurprd04.prod.outlook.com (10.164.84.29) with Microsoft\n\tSMTP Server (version=TLS1_2,\n\tcipher=TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384_P256) id\n\t15.20.13.10; Thu, 7 Sep 2017 04:10:26 +0000","from VI1PR04MB1455.eurprd04.prod.outlook.com\n\t([fe80::f959:755a:bb37:634e]) by\n\tVI1PR04MB1455.eurprd04.prod.outlook.com\n\t([fe80::f959:755a:bb37:634e%13]) with mapi id 15.20.0013.018;\n\tThu, 7 Sep 2017 04:10:24 +0000"],"X-Spam-Checker-Version":"SpamAssassin 3.4.0 (2014-02-07) on lists.denx.de","X-Spam-Level":"","X-Spam-Status":"No, score=-1.0 required=5.0 tests=RCVD_IN_DNSWL_NONE,\n\tRCVD_IN_MSPIKE_H5,RCVD_IN_MSPIKE_WL,SPF_HELO_PASS,T_DKIM_INVALID\n\tautolearn=unavailable autolearn_force=no version=3.4.0","DKIM-Signature":"v=1; a=rsa-sha256; c=relaxed/relaxed; d=nxp.com; s=selector1;\n\th=From:Date:Subject:Message-ID:Content-Type:MIME-Version;\n\tbh=9yzjQXcYK4KB1D/QpanbBsbDf4VzBH4xKk9+/+kRGBI=;\n\tb=UdnvB4sptQi2X9BHZyn63xDLVrA9gq9kYdGo6wvO2m1AXbEj/1mFRHJodbjwV6MgAW5P3K8MqT6cKfuXtXqy+5zK5eD6g9B1tLWsYRD8o0KRMreeXr+8Jz1qN7I+6H5wbw2KGuttB5hhMf+Nyq9nz2k244LZp0YbDAIani4BG80=","From":"Sumit Garg <sumit.garg@nxp.com>","To":"York Sun <york.sun@nxp.com>,\n\t\"u-boot@lists.denx.de\" <u-boot@lists.denx.de>","Thread-Topic":"[Patch v2] configs: SECURE_BOOT: Enable CONFIG_CMD_EXT4_WRITE","Thread-Index":"AQHTHYlkf8p4plZSaE+Lvni7kIZkpqKo4YZw","Date":"Thu, 7 Sep 2017 04:10:24 +0000","Message-ID":"<VI1PR04MB14558121F45778F20387247098940@VI1PR04MB1455.eurprd04.prod.outlook.com>","References":"<1503655390-16829-1-git-send-email-sumit.garg@nxp.com>\n\t<VI1PR04MB2078FC2BFB40825D947FC83F9A970@VI1PR04MB2078.eurprd04.prod.outlook.com>","In-Reply-To":"<VI1PR04MB2078FC2BFB40825D947FC83F9A970@VI1PR04MB2078.eurprd04.prod.outlook.com>","Accept-Language":"en-US","Content-Language":"en-US","X-MS-Has-Attach":"","X-MS-TNEF-Correlator":"","authentication-results":["ozlabs.org;\n\tspf=none (mailfrom) smtp.mailfrom=lists.denx.de\n\t(client-ip=81.169.180.215; helo=lists.denx.de;\n\tenvelope-from=u-boot-bounces@lists.denx.de;\n\treceiver=<UNKNOWN>)","ozlabs.org;\n\tdkim=fail reason=\"signature verification failed\" (1024-bit key;\n\tunprotected) header.d=nxp.com header.i=@nxp.com header.b=\"UdnvB4sp\";\n\tdkim-atps=neutral","spf=none (sender IP is )\n\tsmtp.mailfrom=sumit.garg@nxp.com; "],"x-originating-ip":"[192.88.169.1]","x-ms-publictraffictype":"Email","x-microsoft-exchange-diagnostics":"1; VI1PR04MB1567;\n\t6:EeDPXb1JzqwXKZ7wE4JSbvsOwE3vSPb5NmtGtuEzcev+iM+tcvs+JZ3bWpaI+wGWAoV8SWw5T6SoocKvgsZdZR3IPBXeIyNDSmpwpaCjS7PcltABqsGFtGGeHtkxSigVKTTzN6h1MVGXfFxFx0LeAf1pxS71yAAXWT7LnvSuW7LmdOTGSbha2RGhcEuNAOL8ZQTiNiwzUW9MOvuYajY/ler8k4hamWUOLEy91BYBihmCVJYFUCx3HySFf/+TgLUJo3GqAEvoXHjZbrwjASjVRISizo2Jbh98tD9hHzLLm8Hpoa3NXWst5+wv5DgZqCNCijyIFalLiASenjviuNvOiQ==;\n\t5:u1uf94QTs8FTLkB1FUxJfWHHQThimArL9OAtLnJNR63HqeECU/inPArm1RKwNLnRfQYsF0Zk8NaswtpSMeye7kmDabQUWGt3HuTKYSQfzSrXRQ7BIRZxO2qEkUkGlcFzMsStjYsn0x+Q+NbNbrgbtw==;\n\t24:Soj+yQ1wGhYpJtlmX6hHWgBCC51bBsqyRgicr2ZfrgqxYNi3etjt927hpK4NfJzS02NOlRSv0m5ZZJoGBTgIi7eBUpaeiiM6Jb3zWWSdhFs=;\n\t7:/lHjchZHD5t0dbhd7y1rZ7qaD+O/2CImMEc+N3fm11mpf1L0rHwXx7Zw57EXB5XZvodhx/eEwuJ4D9ZeAp6iBBTJutgvDw7wn6pWljK2vx4IYUmMI1HO5AIxHVwx2vqRD+CW4EWN7r6HhPzqTLB0JMwxTBuR3NxMl5dlEcdpE/r9eYRMoXLRGnXncpTD7k4qSrxMGK7yjW0gQbwDGcGFw8M9YuE0b1lAFkkuiXASbrg=","x-ms-exchange-antispam-srfa-diagnostics":"SSOS;SSOR;","x-forefront-antispam-report":"SFV:SKI; SCL:-1; SFV:NSPM;\n\tSFS:(10009020)(6009001)(39860400002)(377454003)(199003)(189002)(24454002)(13464003)(3280700002)(53936002)(97736004)(7696004)(8936002)(86362001)(68736007)(5250100002)(2900100001)(5660300001)(25786009)(3660700001)(2501003)(478600001)(6246003)(4326008)(6436002)(101416001)(229853002)(106356001)(6506006)(53546010)(54356999)(14454004)(50986999)(105586002)(189998001)(3846002)(2906002)(6116002)(102836003)(305945005)(9686003)(54906002)(81166006)(55016002)(76176999)(81156014)(2950100002)(7736002)(33656002)(99286003)(66066001)(8676002)(74316002)(15760500002);\n\tDIR:OUT; SFP:1101; SCL:1; SRVR:VI1PR04MB1567;\n\tH:VI1PR04MB1455.eurprd04.prod.outlook.com; FPR:; SPF:None;\n\tPTR:InfoNoRecords; A:1; MX:1; LANG:en; ","x-ms-office365-filtering-correlation-id":"a68dc093-4556-42e2-4f3a-08d4f5a65d4e","x-ms-office365-filtering-ht":"Tenant","x-microsoft-antispam":"UriScan:; BCL:0; PCL:0;\n\tRULEID:(300000500095)(300135000095)(300000501095)(300135300095)(22001)(300000502095)(300135100095)(2017030254152)(48565401081)(300000503095)(300135400095)(2017052603199)(201703131423075)(201703031133081)(201702281549075)(300000504095)(300135200095)(300000505095)(300135600095)(300000506095)(300135500095);\n\tSRVR:VI1PR04MB1567; ","x-ms-traffictypediagnostic":"VI1PR04MB1567:","x-exchange-antispam-report-test":"UriScan:(185117386973197)(16074681357397);","x-microsoft-antispam-prvs":"<VI1PR04MB1567A5E8C7FE64B92885006898940@VI1PR04MB1567.eurprd04.prod.outlook.com>","x-exchange-antispam-report-cfa-test":"BCL:0; PCL:0;\n\tRULEID:(100000700101)(100105000095)(100000701101)(100105300095)(100000702101)(100105100095)(6040450)(2401047)(8121501046)(5005006)(10201501046)(100000703101)(100105400095)(3002001)(93006095)(93001095)(6055026)(6041248)(20161123555025)(20161123560025)(20161123558100)(201703131423075)(201702281528075)(201703061421075)(201703061406153)(20161123562025)(20161123564025)(6072148)(201708071742011)(100000704101)(100105200095)(100000705101)(100105500095);\n\tSRVR:VI1PR04MB1567; BCL:0; PCL:0;\n\tRULEID:(100000800101)(100110000095)(100000801101)(100110300095)(100000802101)(100110100095)(100000803101)(100110400095)(100000804101)(100110200095)(100000805101)(100110500095);\n\tSRVR:VI1PR04MB1567; ","x-forefront-prvs":"04238CD941","received-spf":"None (protection.outlook.com: nxp.com does not designate\n\tpermitted sender hosts)","spamdiagnosticoutput":"1:99","spamdiagnosticmetadata":"NSPM","MIME-Version":"1.0","X-OriginatorOrg":"nxp.com","X-MS-Exchange-CrossTenant-originalarrivaltime":"07 Sep 2017 04:10:24.3465\n\t(UTC)","X-MS-Exchange-CrossTenant-fromentityheader":"Hosted","X-MS-Exchange-CrossTenant-id":"686ea1d3-bc2b-4c6f-a92c-d99c5c301635","X-MS-Exchange-Transport-CrossTenantHeadersStamped":"VI1PR04MB1567","Cc":"\"trini@konsulko.com\" <trini@konsulko.com>,\n\tRuchika Gupta <ruchika.gupta@nxp.com>","Subject":"Re: [U-Boot] [Patch v2] configs: SECURE_BOOT: Enable\n\tCONFIG_CMD_EXT4_WRITE","X-BeenThere":"u-boot@lists.denx.de","X-Mailman-Version":"2.1.18","Precedence":"list","List-Id":"U-Boot discussion <u-boot.lists.denx.de>","List-Unsubscribe":"<https://lists.denx.de/options/u-boot>,\n\t<mailto:u-boot-request@lists.denx.de?subject=unsubscribe>","List-Archive":"<http://lists.denx.de/pipermail/u-boot/>","List-Post":"<mailto:u-boot@lists.denx.de>","List-Help":"<mailto:u-boot-request@lists.denx.de?subject=help>","List-Subscribe":"<https://lists.denx.de/listinfo/u-boot>,\n\t<mailto:u-boot-request@lists.denx.de?subject=subscribe>","Content-Type":"text/plain; charset=\"utf-8\"","Content-Transfer-Encoding":"base64","Errors-To":"u-boot-bounces@lists.denx.de","Sender":"\"U-Boot\" <u-boot-bounces@lists.denx.de>"}},{"id":1764788,"web_url":"http://patchwork.ozlabs.org/comment/1764788/","msgid":"<VI1PR04MB20783FCBD776880C8CF1F2E19A940@VI1PR04MB2078.eurprd04.prod.outlook.com>","list_archive_url":null,"date":"2017-09-07T15:30:48","subject":"Re: [U-Boot] [Patch v2] configs: SECURE_BOOT: Enable\n\tCONFIG_CMD_EXT4_WRITE","submitter":{"id":67822,"url":"http://patchwork.ozlabs.org/api/people/67822/","name":"York Sun","email":"york.sun@nxp.com"},"content":"On 09/06/2017 09:10 PM, Sumit Garg wrote:\n>> -----Original Message-----\n>> From: York Sun\n>> Sent: Wednesday, September 06, 2017 9:47 PM\n>> To: Sumit Garg <sumit.garg@nxp.com>; u-boot@lists.denx.de\n>> Cc: Ruchika Gupta <ruchika.gupta@nxp.com>; Prabhakar Kushwaha\n>> <prabhakar.kushwaha@nxp.com>; trini@konsulko.com\n>> Subject: Re: [Patch v2] configs: SECURE_BOOT: Enable\n>> CONFIG_CMD_EXT4_WRITE\n>>\n>> On 08/25/2017 03:03 AM, Sumit Garg wrote:\n>>> As part of chain of trust with confidentiality along with distro boot,\n>>> linux kernel image needs to be stored in encrypted form on\n>>> ext4 boot partition. So enable CONFIG_CMD_EXT4_WRITE in case of Secure\n>>> boot.\n>>>\n>>> Signed-off-by: Sumit Garg <sumit.garg@nxp.com>\n>>> ---\n>>>\n>>> Changes in v2:\n>>> Instead of adding CMD_EXT4_WRITE option in each defconfig, added this\n>>> option in Kconfig.\n>>>\n>>>    board/freescale/common/Kconfig | 2 ++\n>>>    1 file changed, 2 insertions(+)\n>>>\n>>> diff --git a/board/freescale/common/Kconfig\n>>> b/board/freescale/common/Kconfig index 53b606e..3496eed 100644\n>>> --- a/board/freescale/common/Kconfig\n>>> +++ b/board/freescale/common/Kconfig\n>>> @@ -6,6 +6,8 @@ config CHAIN_OF_TRUST\n>>>    \tselect SPL_BOARD_INIT if (ARM && SPL)\n>>>    \tselect SHA_HW_ACCEL\n>>>    \tselect SHA_PROG_HW_ACCEL\n>>> +\tselect CMD_EXT4\n>>> +\tselect CMD_EXT4_WRITE\n>>>    \tbool\n>>>    \tdefault y\n>>\n>> Are you going to need this for all PowerPC platforms? This changes increases 3K\n>> in text section.\n>>\n>> Will Ruchika confirm?\n>>\n>> York\n> \n> We don't need this option on PowerPC platforms as we currently don't support distro\n> boot on PowerPC platforms. So we can enable this option for ARM platforms only.\n\nPlease update the patch to enable these options selectively.\n\nYork","headers":{"Return-Path":"<u-boot-bounces@lists.denx.de>","X-Original-To":"incoming@patchwork.ozlabs.org","Delivered-To":"patchwork-incoming@bilbo.ozlabs.org","Authentication-Results":["ozlabs.org;\n\tspf=none (mailfrom) smtp.mailfrom=lists.denx.de\n\t(client-ip=81.169.180.215; helo=lists.denx.de;\n\tenvelope-from=u-boot-bounces@lists.denx.de;\n\treceiver=<UNKNOWN>)","ozlabs.org;\n\tdkim=fail reason=\"signature verification failed\" (1024-bit key;\n\tunprotected) header.d=nxp.com header.i=@nxp.com header.b=\"EuHintkm\";\n\tdkim-atps=neutral","spf=none (sender IP is )\n\tsmtp.mailfrom=york.sun@nxp.com; "],"Received":["from lists.denx.de (dione.denx.de [81.169.180.215])\n\tby ozlabs.org (Postfix) with ESMTP id 3xp4D24Cdmz9t2r\n\tfor <incoming@patchwork.ozlabs.org>;\n\tFri,  8 Sep 2017 01:30:58 +1000 (AEST)","by lists.denx.de (Postfix, from userid 105)\n\tid 34388C21E27; Thu,  7 Sep 2017 15:30:54 +0000 (UTC)","from lists.denx.de (localhost [IPv6:::1])\n\tby lists.denx.de (Postfix) with ESMTP id B0451C21C73;\n\tThu,  7 Sep 2017 15:30:52 +0000 (UTC)","by lists.denx.de (Postfix, from userid 105)\n\tid 28F05C21C73; Thu,  7 Sep 2017 15:30:51 +0000 (UTC)","from EUR01-HE1-obe.outbound.protection.outlook.com\n\t(mail-he1eur01on0080.outbound.protection.outlook.com [104.47.0.80])\n\tby lists.denx.de (Postfix) with ESMTPS id 92829C21C72\n\tfor <u-boot@lists.denx.de>; Thu,  7 Sep 2017 15:30:50 +0000 (UTC)","from VI1PR04MB2078.eurprd04.prod.outlook.com (10.166.43.18) by\n\tVI1PR04MB2111.eurprd04.prod.outlook.com (10.166.43.27) with Microsoft\n\tSMTP Server (version=TLS1_2,\n\tcipher=TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384_P256) id\n\t15.20.13.10; Thu, 7 Sep 2017 15:30:48 +0000","from VI1PR04MB2078.eurprd04.prod.outlook.com\n\t([fe80::6943:4a49:ab20:5920]) by\n\tVI1PR04MB2078.eurprd04.prod.outlook.com\n\t([fe80::6943:4a49:ab20:5920%13]) with mapi id 15.20.0013.018;\n\tThu, 7 Sep 2017 15:30:48 +0000"],"X-Spam-Checker-Version":"SpamAssassin 3.4.0 (2014-02-07) on lists.denx.de","X-Spam-Level":"","X-Spam-Status":"No, score=-1.0 required=5.0 tests=RCVD_IN_DNSWL_NONE,\n\tRCVD_IN_MSPIKE_H5,RCVD_IN_MSPIKE_WL,SPF_HELO_PASS,T_DKIM_INVALID\n\tautolearn=unavailable autolearn_force=no version=3.4.0","DKIM-Signature":"v=1; a=rsa-sha256; c=relaxed/relaxed; d=nxp.com; s=selector1;\n\th=From:Date:Subject:Message-ID:Content-Type:MIME-Version;\n\tbh=MXY8YDlx383pU11d0vcKma1rRb0n555+4EFdhwA7BlU=;\n\tb=EuHintkmVaSHl+0HaY4XdLMD16PmxfVCJTsQ5VMfQYa9F9xJeYT9SCalD7ysiCshIRd9EsrAdubmJth2PoYJZlbnNuHL0AkCpGjpqbrKZMn5YysrKprWEDqStX3yk6cn9vBfrpNikI+ry1nZbvGkhZh1oQVHObBgI7Anx5krg8s=","From":"York Sun <york.sun@nxp.com>","To":"Sumit Garg <sumit.garg@nxp.com>, \"u-boot@lists.denx.de\"\n\t<u-boot@lists.denx.de>","Thread-Topic":"[Patch v2] configs: SECURE_BOOT: Enable CONFIG_CMD_EXT4_WRITE","Thread-Index":"AQHTHYljb9V9OglZKE23vqrkyaaWmg==","Date":"Thu, 7 Sep 2017 15:30:48 +0000","Message-ID":"<VI1PR04MB20783FCBD776880C8CF1F2E19A940@VI1PR04MB2078.eurprd04.prod.outlook.com>","References":"<1503655390-16829-1-git-send-email-sumit.garg@nxp.com>\n\t<VI1PR04MB2078FC2BFB40825D947FC83F9A970@VI1PR04MB2078.eurprd04.prod.outlook.com>\n\t<VI1PR04MB14558121F45778F20387247098940@VI1PR04MB1455.eurprd04.prod.outlook.com>","Accept-Language":"en-US","Content-Language":"en-US","X-MS-Has-Attach":"","X-MS-TNEF-Correlator":"","authentication-results":["ozlabs.org;\n\tspf=none (mailfrom) smtp.mailfrom=lists.denx.de\n\t(client-ip=81.169.180.215; helo=lists.denx.de;\n\tenvelope-from=u-boot-bounces@lists.denx.de;\n\treceiver=<UNKNOWN>)","ozlabs.org;\n\tdkim=fail reason=\"signature verification failed\" (1024-bit key;\n\tunprotected) header.d=nxp.com header.i=@nxp.com header.b=\"EuHintkm\";\n\tdkim-atps=neutral","spf=none (sender IP is )\n\tsmtp.mailfrom=york.sun@nxp.com; "],"x-originating-ip":"[192.88.168.1]","x-ms-publictraffictype":"Email","x-microsoft-exchange-diagnostics":"1; VI1PR04MB2111;\n\t6:ok6dqKOz7KJ1ET9IIXPVW8/fSF67Nlt3LR2RWkdeQRvg8HPpYkkmrbo8dIEn9N6s4F5HlvoRvBw2AZML9JjOa76/BzXOjk+v2FLpYGfymKHsTGOQnxCFd1vvIotJG5fEvJLK9eJ+tI+bnh/ZiDv4XibLiCdYGrF0S8/6FY0SZhUrdD2HxKzsDq1QRtnKbstwqh5UBCywc5TWSupXuT43pBfrh3XKmYx4pIKhBVAiZ3n8hZtU60cHnz0ETyAIJaWhtRq11jFw0mytU+cFFS5S601AtBZwq3W0yYo+CblY4AqG1jU45UQmMboOSO+Hr3UqEPNe4JAiN1/5aKS2o1gPNQ==;\n\t5:CiMqrV27bsQZ9VhYhNLUGqzQVxWqVs9R3Aq9nflx4sJUjRS4vFkCHPq+HtUlpfaV02yQRhcJ+9TMZbi9F9wu/yMew5Tcm200+tBbjdvCgAGApjQPDyr92/jtRzy4DFXfGl93TER6T9uYwTSBqeX35Q==;\n\t24:ibxneIlrYKmCi6qX78/1nikVgJ7FQhds/nzQsXwybKN6dhlfQuX9dydxNNnUiATtmk05r2iB3S8dhYaUwpYysQ1wdve9r+kVQwQCqZwgClw=;\n\t7:sWXmfFqnW0IbY3U15vBMddz33o9CsQJjNHuEjrGkLLOQj+bFEAnGjywARb5rfY58k+u1ohkaMwfVB3kPZT6GFKiGPdIDfszc1VlmfpOSWTdeIFRcqRtOmdiQf0r+F3eSTe5328yDq7RiM5hVvPnXtfE8XzEhrigL87ifoywTG5pz3lVffpJUzPAIGwocPcnLQErsbSlvKst9s3sysyJ7mAf7oDWCMVPF+TJnHCYArlw=","x-ms-exchange-antispam-srfa-diagnostics":"SSOS;SSOR;","x-forefront-antispam-report":"SFV:SKI; SCL:-1; SFV:NSPM;\n\tSFS:(10009020)(6009001)(39860400002)(199003)(13464003)(24454002)(377454003)(189002)(81166006)(7696004)(189998001)(33656002)(3280700002)(3660700001)(76176999)(106356001)(8936002)(5660300001)(2906002)(81156014)(74316002)(8676002)(3450700001)(2900100001)(2501003)(50986999)(68736007)(5250100002)(105586002)(97736004)(43066003)(101416001)(54356999)(86362001)(6506006)(14454004)(6246003)(7736002)(55016002)(99286003)(54906002)(9686003)(6436002)(478600001)(25786009)(4326008)(53936002)(305945005)(3846002)(102836003)(66066001)(6116002)(229853002)(53546010)(15760500002);\n\tDIR:OUT; SFP:1101; SCL:1; SRVR:VI1PR04MB2111;\n\tH:VI1PR04MB2078.eurprd04.prod.outlook.com; FPR:; SPF:None;\n\tPTR:InfoNoRecords; A:1; MX:1; LANG:en; ","x-ms-office365-filtering-correlation-id":"feaa6c1d-13e0-4ada-3f30-08d4f6056a31","x-ms-office365-filtering-ht":"Tenant","x-microsoft-antispam":"UriScan:; BCL:0; PCL:0;\n\tRULEID:(300000500095)(300135000095)(300000501095)(300135300095)(300000502095)(300135100095)(22001)(2017030254152)(48565401081)(300000503095)(300135400095)(2017052603199)(201703131423075)(201703031133081)(201702281549075)(300000504095)(300135200095)(300000505095)(300135600095)(300000506095)(300135500095);\n\tSRVR:VI1PR04MB2111; ","x-ms-traffictypediagnostic":"VI1PR04MB2111:","x-exchange-antispam-report-test":"UriScan:(185117386973197)(16074681357397);","x-microsoft-antispam-prvs":"<VI1PR04MB2111218D3C764C35B1EB60EF9A940@VI1PR04MB2111.eurprd04.prod.outlook.com>","x-exchange-antispam-report-cfa-test":"BCL:0; PCL:0;\n\tRULEID:(100000700101)(100105000095)(100000701101)(100105300095)(100000702101)(100105100095)(6040450)(2401047)(8121501046)(5005006)(93006095)(93001095)(100000703101)(100105400095)(10201501046)(3002001)(6055026)(6041248)(20161123562025)(20161123564025)(20161123560025)(20161123555025)(201703131423075)(201702281528075)(201703061421075)(201703061406153)(20161123558100)(6072148)(201708071742011)(100000704101)(100105200095)(100000705101)(100105500095);\n\tSRVR:VI1PR04MB2111; BCL:0; PCL:0;\n\tRULEID:(100000800101)(100110000095)(100000801101)(100110300095)(100000802101)(100110100095)(100000803101)(100110400095)(100000804101)(100110200095)(100000805101)(100110500095);\n\tSRVR:VI1PR04MB2111; ","x-forefront-prvs":"04238CD941","received-spf":"None (protection.outlook.com: nxp.com does not designate\n\tpermitted sender hosts)","spamdiagnosticoutput":"1:99","spamdiagnosticmetadata":"NSPM","MIME-Version":"1.0","X-OriginatorOrg":"nxp.com","X-MS-Exchange-CrossTenant-originalarrivaltime":"07 Sep 2017 15:30:48.1401\n\t(UTC)","X-MS-Exchange-CrossTenant-fromentityheader":"Hosted","X-MS-Exchange-CrossTenant-id":"686ea1d3-bc2b-4c6f-a92c-d99c5c301635","X-MS-Exchange-Transport-CrossTenantHeadersStamped":"VI1PR04MB2111","Cc":"\"trini@konsulko.com\" <trini@konsulko.com>,\n\tRuchika Gupta <ruchika.gupta@nxp.com>","Subject":"Re: [U-Boot] [Patch v2] configs: SECURE_BOOT: Enable\n\tCONFIG_CMD_EXT4_WRITE","X-BeenThere":"u-boot@lists.denx.de","X-Mailman-Version":"2.1.18","Precedence":"list","List-Id":"U-Boot discussion <u-boot.lists.denx.de>","List-Unsubscribe":"<https://lists.denx.de/options/u-boot>,\n\t<mailto:u-boot-request@lists.denx.de?subject=unsubscribe>","List-Archive":"<http://lists.denx.de/pipermail/u-boot/>","List-Post":"<mailto:u-boot@lists.denx.de>","List-Help":"<mailto:u-boot-request@lists.denx.de?subject=help>","List-Subscribe":"<https://lists.denx.de/listinfo/u-boot>,\n\t<mailto:u-boot-request@lists.denx.de?subject=subscribe>","Reply-To":"York Sun <york.sun@nxp.com>","Content-Type":"text/plain; charset=\"utf-8\"","Content-Transfer-Encoding":"base64","Errors-To":"u-boot-bounces@lists.denx.de","Sender":"\"U-Boot\" <u-boot-bounces@lists.denx.de>"}},{"id":1764801,"web_url":"http://patchwork.ozlabs.org/comment/1764801/","msgid":"<VI1PR04MB145507F207D6619186C3EE2D98940@VI1PR04MB1455.eurprd04.prod.outlook.com>","list_archive_url":null,"date":"2017-09-07T16:09:11","subject":"Re: [U-Boot] [Patch v2] configs: SECURE_BOOT: Enable\n\tCONFIG_CMD_EXT4_WRITE","submitter":{"id":68653,"url":"http://patchwork.ozlabs.org/api/people/68653/","name":"Sumit Garg","email":"sumit.garg@nxp.com"},"content":"> -----Original Message-----\n> From: York Sun\n> Sent: Thursday, September 07, 2017 9:01 PM\n> To: Sumit Garg <sumit.garg@nxp.com>; u-boot@lists.denx.de\n> Cc: Ruchika Gupta <ruchika.gupta@nxp.com>; Prabhakar Kushwaha\n> <prabhakar.kushwaha@nxp.com>; trini@konsulko.com\n> Subject: Re: [Patch v2] configs: SECURE_BOOT: Enable\n> CONFIG_CMD_EXT4_WRITE\n> \n> On 09/06/2017 09:10 PM, Sumit Garg wrote:\n> >> -----Original Message-----\n> >> From: York Sun\n> >> Sent: Wednesday, September 06, 2017 9:47 PM\n> >> To: Sumit Garg <sumit.garg@nxp.com>; u-boot@lists.denx.de\n> >> Cc: Ruchika Gupta <ruchika.gupta@nxp.com>; Prabhakar Kushwaha\n> >> <prabhakar.kushwaha@nxp.com>; trini@konsulko.com\n> >> Subject: Re: [Patch v2] configs: SECURE_BOOT: Enable\n> >> CONFIG_CMD_EXT4_WRITE\n> >>\n> >> On 08/25/2017 03:03 AM, Sumit Garg wrote:\n> >>> As part of chain of trust with confidentiality along with distro\n> >>> boot, linux kernel image needs to be stored in encrypted form on\n> >>> ext4 boot partition. So enable CONFIG_CMD_EXT4_WRITE in case of\n> >>> Secure boot.\n> >>>\n> >>> Signed-off-by: Sumit Garg <sumit.garg@nxp.com>\n> >>> ---\n> >>>\n> >>> Changes in v2:\n> >>> Instead of adding CMD_EXT4_WRITE option in each defconfig, added\n> >>> this option in Kconfig.\n> >>>\n> >>>    board/freescale/common/Kconfig | 2 ++\n> >>>    1 file changed, 2 insertions(+)\n> >>>\n> >>> diff --git a/board/freescale/common/Kconfig\n> >>> b/board/freescale/common/Kconfig index 53b606e..3496eed 100644\n> >>> --- a/board/freescale/common/Kconfig\n> >>> +++ b/board/freescale/common/Kconfig\n> >>> @@ -6,6 +6,8 @@ config CHAIN_OF_TRUST\n> >>>    \tselect SPL_BOARD_INIT if (ARM && SPL)\n> >>>    \tselect SHA_HW_ACCEL\n> >>>    \tselect SHA_PROG_HW_ACCEL\n> >>> +\tselect CMD_EXT4\n> >>> +\tselect CMD_EXT4_WRITE\n> >>>    \tbool\n> >>>    \tdefault y\n> >>\n> >> Are you going to need this for all PowerPC platforms? This changes\n> >> increases 3K in text section.\n> >>\n> >> Will Ruchika confirm?\n> >>\n> >> York\n> >\n> > We don't need this option on PowerPC platforms as we currently don't\n> > support distro boot on PowerPC platforms. So we can enable this option for\n> ARM platforms only.\n> \n> Please update the patch to enable these options selectively.\n> \n> York\n \nSure I will send this change in v3.\n\nSumit","headers":{"Return-Path":"<u-boot-bounces@lists.denx.de>","X-Original-To":"incoming@patchwork.ozlabs.org","Delivered-To":"patchwork-incoming@bilbo.ozlabs.org","Authentication-Results":["ozlabs.org;\n\tspf=none (mailfrom) smtp.mailfrom=lists.denx.de\n\t(client-ip=81.169.180.215; helo=lists.denx.de;\n\tenvelope-from=u-boot-bounces@lists.denx.de;\n\treceiver=<UNKNOWN>)","ozlabs.org;\n\tdkim=fail reason=\"signature verification failed\" (1024-bit key;\n\tunprotected) header.d=nxp.com header.i=@nxp.com header.b=\"T1Es3IME\";\n\tdkim-atps=neutral","spf=none (sender IP is )\n\tsmtp.mailfrom=sumit.garg@nxp.com; "],"Received":["from lists.denx.de (dione.denx.de [81.169.180.215])\n\tby ozlabs.org (Postfix) with ESMTP id 3xp54S649Vz9s78\n\tfor <incoming@patchwork.ozlabs.org>;\n\tFri,  8 Sep 2017 02:09:27 +1000 (AEST)","by lists.denx.de (Postfix, from userid 105)\n\tid 28B30C21DBE; Thu,  7 Sep 2017 16:09:18 +0000 (UTC)","from lists.denx.de (localhost [IPv6:::1])\n\tby lists.denx.de (Postfix) with ESMTP id 3C76DC21C73;\n\tThu,  7 Sep 2017 16:09:16 +0000 (UTC)","by lists.denx.de (Postfix, from userid 105)\n\tid 8FD0CC21C73; Thu,  7 Sep 2017 16:09:14 +0000 (UTC)","from EUR02-VE1-obe.outbound.protection.outlook.com\n\t(mail-eopbgr20044.outbound.protection.outlook.com [40.107.2.44])\n\tby lists.denx.de (Postfix) with ESMTPS id E0BB2C21C73\n\tfor <u-boot@lists.denx.de>; Thu,  7 Sep 2017 16:09:13 +0000 (UTC)","from VI1PR04MB1455.eurprd04.prod.outlook.com (10.163.166.147) by\n\tVI1PR04MB2175.eurprd04.prod.outlook.com (10.166.43.149) with\n\tMicrosoft SMTP Server (version=TLS1_2,\n\tcipher=TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384_P256) id\n\t15.20.13.10; Thu, 7 Sep 2017 16:09:12 +0000","from VI1PR04MB1455.eurprd04.prod.outlook.com\n\t([fe80::f959:755a:bb37:634e]) by\n\tVI1PR04MB1455.eurprd04.prod.outlook.com\n\t([fe80::f959:755a:bb37:634e%13]) with mapi id 15.20.0013.018;\n\tThu, 7 Sep 2017 16:09:11 +0000"],"X-Spam-Checker-Version":"SpamAssassin 3.4.0 (2014-02-07) on lists.denx.de","X-Spam-Level":"","X-Spam-Status":"No, score=0.0 required=5.0 tests=RCVD_IN_DNSWL_NONE,\n\tRCVD_IN_MSPIKE_H2, SPF_HELO_PASS, T_DKIM_INVALID autolearn=unavailable\n\tautolearn_force=no version=3.4.0","DKIM-Signature":"v=1; a=rsa-sha256; c=relaxed/relaxed; d=nxp.com; s=selector1;\n\th=From:Date:Subject:Message-ID:Content-Type:MIME-Version;\n\tbh=kGL98lXqj+x4dgDXil34BnYVgpH3I0xwDbsJg1+vxQ0=;\n\tb=T1Es3IMEJ8soArUTwWDxEaw/c/7+yd2kfVRU+8r911CgHl1x4LCCrq1Qk9MVZSq9mw9VwURSY1S1dw6NeXsJqadHpCppaEUtviJP3xfNdK73NKEgr4JWfD6O8b31+MjOWgK47kb5iV95qrMpVq4iT7sAEZz5kPE1OsG8cd5Sb1c=","From":"Sumit Garg <sumit.garg@nxp.com>","To":"York Sun <york.sun@nxp.com>,\n\t\"u-boot@lists.denx.de\" <u-boot@lists.denx.de>","Thread-Topic":"[Patch v2] configs: SECURE_BOOT: Enable CONFIG_CMD_EXT4_WRITE","Thread-Index":"AQHTHYlkf8p4plZSaE+Lvni7kIZkpqKpq+lg","Date":"Thu, 7 Sep 2017 16:09:11 +0000","Message-ID":"<VI1PR04MB145507F207D6619186C3EE2D98940@VI1PR04MB1455.eurprd04.prod.outlook.com>","References":"<1503655390-16829-1-git-send-email-sumit.garg@nxp.com>\n\t<VI1PR04MB2078FC2BFB40825D947FC83F9A970@VI1PR04MB2078.eurprd04.prod.outlook.com>\n\t<VI1PR04MB14558121F45778F20387247098940@VI1PR04MB1455.eurprd04.prod.outlook.com>\n\t<VI1PR04MB20783FCBD776880C8CF1F2E19A940@VI1PR04MB2078.eurprd04.prod.outlook.com>","In-Reply-To":"<VI1PR04MB20783FCBD776880C8CF1F2E19A940@VI1PR04MB2078.eurprd04.prod.outlook.com>","Accept-Language":"en-US","Content-Language":"en-US","X-MS-Has-Attach":"","X-MS-TNEF-Correlator":"","authentication-results":["ozlabs.org;\n\tspf=none (mailfrom) smtp.mailfrom=lists.denx.de\n\t(client-ip=81.169.180.215; helo=lists.denx.de;\n\tenvelope-from=u-boot-bounces@lists.denx.de;\n\treceiver=<UNKNOWN>)","ozlabs.org;\n\tdkim=fail reason=\"signature verification failed\" (1024-bit key;\n\tunprotected) header.d=nxp.com header.i=@nxp.com header.b=\"T1Es3IME\";\n\tdkim-atps=neutral","spf=none (sender IP is )\n\tsmtp.mailfrom=sumit.garg@nxp.com; "],"x-originating-ip":"[27.5.8.244]","x-ms-publictraffictype":"Email","x-microsoft-exchange-diagnostics":"1; VI1PR04MB2175;\n\t6:i7gsP57gT8tKFKXzKKEzT1AoIyiKEY3fBd03+hl9fgq4xNULVblqZF3SJqjTSJW7QWygGF8ZPSEU2klqY5W0SmX7XY4pV84uTWk0zz7ywKIHawOAzIvYQF21bUFH89eJCclohU82UyvPMOXn+kApnTnCeiUXQ7qDTCJ7GsLRm2HKrmdZbuvAgPMx8yMRA/N90GFZ4YB1uycPUYiehjV+H5tS5VTgyw5fjp0p0kChpkjTVHoToNrob7npdfmt7yZTHanJgPyh6hK3Gm3O76xhG9BMOZI7qKaDMcTy9Q3eDJczFGJaUKXfwlN8XLWb8+El66IbCiagG0RyIy92IiZAjQ==;\n\t5:u/ZmExBXnB3uXjRcs69I6dH2oi1+gsRraSAzaxFJc2Fd3Ita0Y1mSmxXb7z084/wpU7LWS4XXUBgEMrlj+2Q4laMLflIS5SfpErX3c/egDcC8VTSI+tgyX5ZrDRaUCspZVQTTIMOv9J7ThQ+nyx3Mg==;\n\t24:nf6Yt0PnBWLxw5O0muqpw0aqJb/JQmLWNlFb2qh68dx9tZm5eZPy1y5zV1REAhPSM9sItl2FmBkFhdPTUxhVPff9ajWUX0Evntflc1BbFtQ=;\n\t7:kmB8dieymBpyUkW1Qe0bU8YxuuzTgoRMytuq7BSZLfYb1yNcahgXyi9B09QCwWByP9j0Mkv1J7w6O+PKaHHivcVVao/5HJyclEW8wv/P8ITCp5QlwspKLVqe2/sqmSIYFh435sDK29+KONp2QWBRfH4V0vsUpZkmlffG6SndU6JAw+g8n7dBvIAKWdEmbhYMIdSJQpFO4AVMZPg+lGjmks3sTnQ6qXqNP1gVdfpZl80=","x-ms-exchange-antispam-srfa-diagnostics":"SSOS;SSOR;","x-forefront-antispam-report":"SFV:SKI; SCL:-1; SFV:NSPM;\n\tSFS:(10009020)(6009001)(39860400002)(189002)(13464003)(24454002)(377454003)(199003)(76176999)(305945005)(33656002)(9686003)(93886005)(101416001)(3846002)(478600001)(6116002)(102836003)(54906002)(54356999)(74316002)(105586002)(106356001)(7736002)(99286003)(25786009)(6246003)(68736007)(55016002)(14454004)(2906002)(3660700001)(3280700002)(53546010)(7696004)(6506006)(53936002)(6436002)(4326008)(50986999)(189998001)(66066001)(2501003)(8936002)(86362001)(97736004)(229853002)(8676002)(2950100002)(81166006)(2900100001)(5660300001)(5250100002)(81156014)(15760500002);\n\tDIR:OUT; SFP:1101; SCL:1; SRVR:VI1PR04MB2175;\n\tH:VI1PR04MB1455.eurprd04.prod.outlook.com; FPR:; SPF:None;\n\tPTR:InfoNoRecords; MX:1; A:1; LANG:en; ","x-ms-office365-filtering-correlation-id":"9859b3c6-fa52-4249-fda2-08d4f60ac6fb","x-ms-office365-filtering-ht":"Tenant","x-microsoft-antispam":"UriScan:; BCL:0; PCL:0;\n\tRULEID:(300000500095)(300135000095)(300000501095)(300135300095)(300000502095)(300135100095)(22001)(2017030254152)(48565401081)(300000503095)(300135400095)(2017052603199)(201703131423075)(201703031133081)(201702281549075)(300000504095)(300135200095)(300000505095)(300135600095)(300000506095)(300135500095);\n\tSRVR:VI1PR04MB2175; ","x-ms-traffictypediagnostic":"VI1PR04MB2175:","x-exchange-antispam-report-test":"UriScan:(185117386973197)(16074681357397);","x-microsoft-antispam-prvs":"<VI1PR04MB2175A50BFA0CD29054DBC93C98940@VI1PR04MB2175.eurprd04.prod.outlook.com>","x-exchange-antispam-report-cfa-test":"BCL:0; PCL:0;\n\tRULEID:(100000700101)(100105000095)(100000701101)(100105300095)(100000702101)(100105100095)(6040450)(2401047)(5005006)(8121501046)(100000703101)(100105400095)(93006095)(93001095)(10201501046)(3002001)(6055026)(6041248)(20161123562025)(20161123555025)(20161123564025)(20161123558100)(20161123560025)(201703131423075)(201702281528075)(201703061421075)(201703061406153)(6072148)(201708071742011)(100000704101)(100105200095)(100000705101)(100105500095);\n\tSRVR:VI1PR04MB2175; BCL:0; PCL:0;\n\tRULEID:(100000800101)(100110000095)(100000801101)(100110300095)(100000802101)(100110100095)(100000803101)(100110400095)(100000804101)(100110200095)(100000805101)(100110500095);\n\tSRVR:VI1PR04MB2175; ","x-forefront-prvs":"04238CD941","received-spf":"None (protection.outlook.com: nxp.com does not designate\n\tpermitted sender hosts)","spamdiagnosticoutput":"1:99","spamdiagnosticmetadata":"NSPM","MIME-Version":"1.0","X-OriginatorOrg":"nxp.com","X-MS-Exchange-CrossTenant-originalarrivaltime":"07 Sep 2017 16:09:11.3341\n\t(UTC)","X-MS-Exchange-CrossTenant-fromentityheader":"Hosted","X-MS-Exchange-CrossTenant-id":"686ea1d3-bc2b-4c6f-a92c-d99c5c301635","X-MS-Exchange-Transport-CrossTenantHeadersStamped":"VI1PR04MB2175","Cc":"\"trini@konsulko.com\" <trini@konsulko.com>,\n\tRuchika Gupta <ruchika.gupta@nxp.com>","Subject":"Re: [U-Boot] [Patch v2] configs: SECURE_BOOT: Enable\n\tCONFIG_CMD_EXT4_WRITE","X-BeenThere":"u-boot@lists.denx.de","X-Mailman-Version":"2.1.18","Precedence":"list","List-Id":"U-Boot discussion <u-boot.lists.denx.de>","List-Unsubscribe":"<https://lists.denx.de/options/u-boot>,\n\t<mailto:u-boot-request@lists.denx.de?subject=unsubscribe>","List-Archive":"<http://lists.denx.de/pipermail/u-boot/>","List-Post":"<mailto:u-boot@lists.denx.de>","List-Help":"<mailto:u-boot-request@lists.denx.de?subject=help>","List-Subscribe":"<https://lists.denx.de/listinfo/u-boot>,\n\t<mailto:u-boot-request@lists.denx.de?subject=subscribe>","Content-Type":"text/plain; charset=\"utf-8\"","Content-Transfer-Encoding":"base64","Errors-To":"u-boot-bounces@lists.denx.de","Sender":"\"U-Boot\" <u-boot-bounces@lists.denx.de>"}}]