[{"id":1800116,"web_url":"http://patchwork.ozlabs.org/comment/1800116/","msgid":"<20171106232754.GA32663@bill-the-cat>","list_archive_url":null,"date":"2017-11-06T23:27:54","subject":"Re: [U-Boot] [U-Boot,\n\t1/2] tools: image: allow to sign image nodes without -K option","submitter":{"id":65875,"url":"http://patchwork.ozlabs.org/api/people/65875/","name":"Tom Rini","email":"trini@konsulko.com"},"content":"On Fri, Oct 27, 2017 at 03:04:20PM +0900, Masahiro Yamada wrote:\n\n> If -K option is missing when you sign image nodes, it fails with\n> an unclear error message:\n> \n>   tools/mkimage Can't add hashes to FIT blob: -1\n> \n> It is hard to figure out the cause of the failure.\n> \n> In contrast, when you sign configuration nodes, -K is optional because\n> fit_config_process_sig() returns successfully if keydest is unset.\n> Probably this is a preferred behavior when you want to update FIT with\n> the same key; you do not have to update the public key in this case.\n> \n> So, this commit changes fit_image_process_sig() to continue signing\n> without keydest.  If ->add_verify_data() fails, show a clearer error\n> message, which has been borrowed from fit_config_process_sig().\n> \n> Signed-off-by: Masahiro Yamada <yamada.masahiro@socionext.com>\n\nApplied to u-boot/master, thanks!","headers":{"Return-Path":"<u-boot-bounces@lists.denx.de>","X-Original-To":"incoming@patchwork.ozlabs.org","Delivered-To":"patchwork-incoming@bilbo.ozlabs.org","Authentication-Results":["ozlabs.org;\n\tspf=none (mailfrom) smtp.mailfrom=lists.denx.de\n\t(client-ip=81.169.180.215; helo=lists.denx.de;\n\tenvelope-from=u-boot-bounces@lists.denx.de;\n\treceiver=<UNKNOWN>)","ozlabs.org;\n\tdkim=fail reason=\"signature verification failed\" (1024-bit key;\n\tunprotected) header.d=konsulko.com header.i=@konsulko.com\n\theader.b=\"d5woJlVG\"; dkim-atps=neutral"],"Received":["from lists.denx.de (dione.denx.de [81.169.180.215])\n\tby ozlabs.org (Postfix) with ESMTP id 3yW85Q6Y6cz9sPr\n\tfor <incoming@patchwork.ozlabs.org>;\n\tTue,  7 Nov 2017 10:33:46 +1100 (AEDT)","by lists.denx.de (Postfix, from userid 105)\n\tid 854EEC21F40; Mon,  6 Nov 2017 23:30:07 +0000 (UTC)","from lists.denx.de (localhost [IPv6:::1])\n\tby lists.denx.de (Postfix) with ESMTP id EAD45C21FA1;\n\tMon,  6 Nov 2017 23:28:45 +0000 (UTC)","by lists.denx.de (Postfix, from userid 105)\n\tid 82AF6C21F8A; Mon,  6 Nov 2017 23:28:01 +0000 (UTC)","from mail-yw0-f177.google.com (mail-yw0-f177.google.com\n\t[209.85.161.177])\n\tby lists.denx.de (Postfix) with ESMTPS id 6DE22C21F6C\n\tfor <u-boot@lists.denx.de>; Mon,  6 Nov 2017 23:27:57 +0000 (UTC)","by mail-yw0-f177.google.com with SMTP id w2so9366747ywa.9\n\tfor <u-boot@lists.denx.de>; Mon, 06 Nov 2017 15:27:57 -0800 (PST)","from bill-the-cat (cpe-65-184-142-68.ec.res.rr.com.\n\t[65.184.142.68]) by smtp.gmail.com with ESMTPSA id\n\th26sm6662686ywk.67.2017.11.06.15.27.55\n\t(version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128);\n\tMon, 06 Nov 2017 15:27:55 -0800 (PST)"],"X-Spam-Checker-Version":"SpamAssassin 3.4.0 (2014-02-07) on lists.denx.de","X-Spam-Level":"","X-Spam-Status":"No, score=-0.0 required=5.0 tests=RCVD_IN_MSPIKE_H3,\n\tRCVD_IN_MSPIKE_WL,\n\tT_DKIM_INVALID autolearn=unavailable autolearn_force=no\n\tversion=3.4.0","DKIM-Signature":"v=1; a=rsa-sha256; c=relaxed/relaxed; d=konsulko.com;\n\ts=google; \n\th=date:from:to:cc:subject:message-id:references:mime-version\n\t:content-disposition:in-reply-to:user-agent;\n\tbh=HsmClAZnhoISzsdyfAdMwALB3cH9qwp8iQ0TrhVSC2o=;\n\tb=d5woJlVGX+hYN8r+CIOyUmd6Jtn+60LAIAGyg5lJFfqlt2vSQ5xqCKyxTL4NSYGVPE\n\tyKFpO3VEqWFURzmbdQVj6XYO1yzTN7K9cLLHcM+wlLLfdb3RGUDRcyFHRX7K7CP/FOXR\n\t9Nm00Hzv+DY6RANhGEq6pCnw23ujPnBUOOavU=","X-Google-DKIM-Signature":"v=1; a=rsa-sha256; c=relaxed/relaxed;\n\td=1e100.net; s=20161025;\n\th=x-gm-message-state:date:from:to:cc:subject:message-id:references\n\t:mime-version:content-disposition:in-reply-to:user-agent;\n\tbh=HsmClAZnhoISzsdyfAdMwALB3cH9qwp8iQ0TrhVSC2o=;\n\tb=oAgEw7uY2MPamZYzdf/jAeWXqtOzPWeukTbNlRUFxnCrsAMlnZCYKNgJZWtT7ow1sA\n\tt90xiJSYYKPHqetsBkNj5z18HZfDgcBKvAm3MANE4anjFW5s81oZUwSkmBDOA/amBNyQ\n\ttGpMhHDFcFTgiN5dhQYRGH2CnkaN8k8jy4Wdli4F2//f5FZuOlNq2M3BSiYQvgqjNPbF\n\twLY8L4s0WuqlDTKagpJi5XGDu4DWD6ySnmvg3D71ZeXTiDyQcipMq+3hUhnfhkqwxM0m\n\tXGGwYG5vSUZi7PjFaMebZ5H2EsFhqdfbE336pJvEF0TY7hZ6BQuS0FEjV1Ov8/m5Pwdq\n\tQLgw==","X-Gm-Message-State":"AMCzsaXdLsUaBhiFWyrfpmGd7x14DGegHnAp6kzf1we+xpdbUnNPMAgi\n\t6QQabqxTe8/SZ2BLNYjJfuoAURZ+8uA=","X-Google-Smtp-Source":"ABhQp+QW1wBTOTV8tTLx/knmxCPVamy0D/SQFGU8GrSfEThe/juIHyv4wh2NHv0lvuBF0aNaJiVwmA==","X-Received":"by 10.129.175.39 with SMTP id n39mr11278418ywh.231.1510010876361;\n\tMon, 06 Nov 2017 15:27:56 -0800 (PST)","Date":"Mon, 6 Nov 2017 18:27:54 -0500","From":"Tom Rini <trini@konsulko.com>","To":"Masahiro Yamada <yamada.masahiro@socionext.com>","Message-ID":"<20171106232754.GA32663@bill-the-cat>","References":"<1509084261-16126-1-git-send-email-yamada.masahiro@socionext.com>","MIME-Version":"1.0","In-Reply-To":"<1509084261-16126-1-git-send-email-yamada.masahiro@socionext.com>","User-Agent":"Mutt/1.5.24 (2015-08-30)","Cc":"u-boot@lists.denx.de","Subject":"Re: [U-Boot] [U-Boot,\n\t1/2] tools: image: allow to sign image nodes without -K option","X-BeenThere":"u-boot@lists.denx.de","X-Mailman-Version":"2.1.18","Precedence":"list","List-Id":"U-Boot discussion <u-boot.lists.denx.de>","List-Unsubscribe":"<https://lists.denx.de/options/u-boot>,\n\t<mailto:u-boot-request@lists.denx.de?subject=unsubscribe>","List-Archive":"<http://lists.denx.de/pipermail/u-boot/>","List-Post":"<mailto:u-boot@lists.denx.de>","List-Help":"<mailto:u-boot-request@lists.denx.de?subject=help>","List-Subscribe":"<https://lists.denx.de/listinfo/u-boot>,\n\t<mailto:u-boot-request@lists.denx.de?subject=subscribe>","Content-Type":"multipart/mixed;\n\tboundary=\"===============4548930228554832877==\"","Errors-To":"u-boot-bounces@lists.denx.de","Sender":"\"U-Boot\" <u-boot-bounces@lists.denx.de>"}}]