| Message ID | 20250904115704.58413-1-Michael.Glembotzki@iris-sensing.com |
|---|---|
| Headers | show
Return-Path: <swupdate+bncBDY5JUXLVIEBBGH54XCQMGQETXQV6DQ@googlegroups.com>
X-Original-To: incoming@patchwork.ozlabs.org
Delivered-To: patchwork-incoming@legolas.ozlabs.org
Authentication-Results: legolas.ozlabs.org;
dkim=pass (2048-bit key;
unprotected) header.d=googlegroups.com header.i=@googlegroups.com
header.a=rsa-sha256 header.s=20230601 header.b=SSNm4dCG;
dkim=pass (2048-bit key;
unprotected) header.d=gmail.com header.i=@gmail.com header.a=rsa-sha256
header.s=20230601 header.b=AG9ztQ0J;
dkim-atps=neutral
Authentication-Results: legolas.ozlabs.org;
spf=pass (sender SPF authorized) smtp.mailfrom=googlegroups.com
(client-ip=2a00:1450:4864:20::23a; helo=mail-lj1-x23a.google.com;
envelope-from=swupdate+bncbdy5juxlviebbgh54xcqmgqetxqv6dq@googlegroups.com;
receiver=patchwork.ozlabs.org)
Received: from mail-lj1-x23a.google.com (mail-lj1-x23a.google.com
[IPv6:2a00:1450:4864:20::23a])
(using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)
key-exchange X25519 server-signature ECDSA (secp384r1) server-digest SHA384)
(No client certificate requested)
by legolas.ozlabs.org (Postfix) with ESMTPS id 4cHdJM12nDz1y0F
for <incoming@patchwork.ozlabs.org>; Thu, 4 Sep 2025 21:57:22 +1000 (AEST)
Received: by mail-lj1-x23a.google.com with SMTP id
38308e7fff4ca-336be2f22cesf4093491fa.2
for <incoming@patchwork.ozlabs.org>;
Thu, 04 Sep 2025 04:57:22 -0700 (PDT)
ARC-Seal: i=2; a=rsa-sha256; t=1756987035; cv=pass;
d=google.com; s=arc-20240605;
b=Mg+xVVJSCam92ofr8XhUn4hp3etARKiNPg4RylSL30DNDSyhwKsfb2KOg8d7mY4bX2
Dhe9ziuidGkPpikish5j7bqyTplFDm1NzN8HSjZcA6lKoeKXLlcR32Ct+fyzGIbuqXj5
4FoCdzEZWd9hiAJH6xD9cUCaSPmwyA7WyD0jFmv7u1AJJdKMmSduuMp4BI/8fdf0WPL3
vKXq8LvMGElo6mryUEnj0K12yW8gnpfZQnLvEba5fEVaRCqwfKRbM4hLjxN0qgEtd2T0
6y0/fBj2UEQSlMZLlC+9xQ6eIt+9KJMtHe2AhhrRpWVa1D0VQvobafr0gL8J9vuTzy7B
VlCQ==
ARC-Message-Signature: i=2; a=rsa-sha256; c=relaxed/relaxed; d=google.com;
s=arc-20240605;
h=list-unsubscribe:list-subscribe:list-archive:list-help:list-post
:list-id:mailing-list:precedence:content-transfer-encoding
:mime-version:message-id:date:subject:to:from:sender:dkim-signature
:dkim-signature;
bh=f2Kzs3uPx011Fpb5LVUGRsgCD4tUtE5IC0x8imNMtLs=;
fh=6uUJQLGu5LTPduXQ344N8F2aGw1H5cBDiKj7P65l3P0=;
b=kMNCJ1WxW4TqI2/+OQENEAZ8HmGHQNftY2u/mBQL3CyyoDxDTtYVv7aPM1Uoq3mB0U
kPd7QeoRFgfJ/8b1nEWxlfTPGy8JuijmvsdL3qMIg5W8BjZ4zbgp7rmXEJS3R0dbdJaY
SzaENQbwwSoREDmuEu6htTOw6JxIF3zhi7RYVOXLXXKhJjzK2p8G59HQeqtMCJL8siKP
eEDSAEQFNdOAO6u5Y28ymuw0V7h+YtIacV1Rot5scsKW7c/uTWoCP7g5auU7Zmg1K/7B
w89lbAMSdOukiOxtvEsN3H+0DILcqd+mQ1sBQGwjx7X0esjbDTWzvTu52KF5XChwT9uu
vCUg==;
darn=patchwork.ozlabs.org
ARC-Authentication-Results: i=2; gmr-mx.google.com;
dkim=pass header.i=@gmail.com header.s=20230601 header.b=MhoQFgKn;
spf=pass (google.com: domain of m.glembo@gmail.com designates
2a00:1450:4864:20::636 as permitted sender) smtp.mailfrom=m.glembo@gmail.com;
dmarc=pass (p=NONE sp=QUARANTINE dis=NONE) header.from=gmail.com;
dara=pass header.i=@googlegroups.com
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=googlegroups.com; s=20230601; t=1756987035; x=1757591835;
darn=patchwork.ozlabs.org;
h=list-unsubscribe:list-subscribe:list-archive:list-help:list-post
:list-id:mailing-list:precedence:x-original-authentication-results
:x-original-sender:content-transfer-encoding:mime-version:message-id
:date:subject:to:from:sender:from:to:cc:subject:date:message-id
:reply-to;
bh=f2Kzs3uPx011Fpb5LVUGRsgCD4tUtE5IC0x8imNMtLs=;
b=SSNm4dCGPM6WpOFJQeS4jlw0TnwWA4nIhnxUlWOTtaWTdnRLizl6MqfUzg3Jq6eFpS
95esZ8ih1viXbzpX9zX0Rjj6pu2l7MhzTVaU9Sh2pOrc0J1tq70AZlnC2bLa5+17hb48
Vzb2NHGeDa6eNAOrIYsIsl90IKUkdGol8jqxPDSPuFpFiH2xwndZDOLVwHHu/RDp/yty
fWZNFh5qH6g8k7kO4yBduMPSTakbF/CZUBI1Oo41AD2Nh4or2dIphqauA0WtWflFUykn
SJbLdzEE4x8XDvGOReDep9wonW6lEDrm0QlzjFo17aNOEC0zZr0J0ORkKO4T5iNfdPfH
uc5Q==
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=gmail.com; s=20230601; t=1756987035; x=1757591835;
darn=patchwork.ozlabs.org;
h=list-unsubscribe:list-subscribe:list-archive:list-help:list-post
:list-id:mailing-list:precedence:x-original-authentication-results
:x-original-sender:content-transfer-encoding:mime-version:message-id
:date:subject:to:from:from:to:cc:subject:date:message-id:reply-to;
bh=f2Kzs3uPx011Fpb5LVUGRsgCD4tUtE5IC0x8imNMtLs=;
b=AG9ztQ0JSSW6StZ4YQ04T64Uga/obndmYdmAC+fl3ZInrOZjryXFOTc9T4g7G3kVf9
8R7AQt3mRqhRRsYOqRNuBNWTDNnBp8y9inmoTFdgUXt3oRjACS+7QJgX3ZLImr0Sl2vY
OFe069Bwt2T36PyV+A6sTr6wtdptxsHQOr7f0ogr6fe5hTrOIQ2LKY/aOdcqS8S5mJrc
d3+zdYEZ21hSbJILy8po3andxSt16fb6yJVpIgtb9y8yT3fUXkJptpAPUalxOmYX962e
sYYPEdODWB8x4McQxhztl7sFxONNiriBw6y1m+NTT9Y+m93OgE4cOEzpeOcy4AIunanz
Ciqg==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=1e100.net; s=20230601; t=1756987035; x=1757591835;
h=list-unsubscribe:list-subscribe:list-archive:list-help:list-post
:x-spam-checked-in-group:list-id:mailing-list:precedence
:x-original-authentication-results:x-original-sender
:content-transfer-encoding:mime-version:message-id:date:subject:to
:from:x-beenthere:x-gm-message-state:sender:from:to:cc:subject:date
:message-id:reply-to;
bh=f2Kzs3uPx011Fpb5LVUGRsgCD4tUtE5IC0x8imNMtLs=;
b=T4+fFA3GE7u/rhe+YDkxmklGnHlBpqyeGx4KFoJoBLjrZhq3nStE9ai2vRjI+lyvDa
/mebBZAgg1BJ8FIjCuDrVEbGaWKMPcwSHvrMUuyHbpoVORmEDYeAHNi9qU/l46A+Ua+z
Dra/Tpgjs9Sk5x2QkUR/p5TSgnn/dIm07+6tGiAzmLeHeq/oFJ5sSD6XT1xXJ+14CbAk
zcIh7CfcUD3QKdXdDweTbIudJ59GimCF2VzknKwT/PLDzLgh91hY67A4oI6fUhTj4BrA
/exVHjkLlDkwm3AM/X5lBEX71nZIAiQ1nV/XHi4//nfJhiIJYmE5mFBiC+jHM1DvP2zi
bpCA==
Sender: swupdate@googlegroups.com
X-Forwarded-Encrypted: i=2;
AJvYcCV9tBn3WdC1wvohrY3XtmGOtlXPyC/JCj76FJx19yisyCAlrQr6V+k/cgKTdzXjXZfDXz240I/lHA==@patchwork.ozlabs.org
X-Gm-Message-State: AOJu0YzfVp9OCXH62e2Du9g71J1L1Fsd3J+v7UEtJtz7fDr/fvuVVo3B
n/CEx4AAQByr9yLs6rSlt1YIe6CXuYOJgN8Cru+dvwjr1PICb6mxNqni
X-Google-Smtp-Source:
AGHT+IGT7jd2vs2Kp7USLec3Z7VHyaYNMNOvkwCBKLv+jEd9zW8yBokd/BQf7kjvbqA1FbqWT9GHGQ==
X-Received: by 2002:a05:6512:10d5:b0:55f:63ef:b2bc with SMTP id
2adb3069b0e04-55f708a3797mr6596810e87.8.1756987035044;
Thu, 04 Sep 2025 04:57:15 -0700 (PDT)
X-BeenThere: swupdate@googlegroups.com;
h=AZMbMZeEXZnGIz/exgHYeS+4yIRDRAv2zfvK3jDagz0NCZjh1Q==
Received: by 2002:a05:6512:638b:10b0:55f:4af2:a564 with SMTP id
2adb3069b0e04-55f5dd0b21cls772562e87.0.-pod-prod-03-eu; Thu, 04 Sep 2025
04:57:10 -0700 (PDT)
X-Received: by 2002:a05:651c:514:b0:336:ac3a:73b6 with SMTP id
38308e7fff4ca-336cad33d7bmr57183881fa.28.1756987029800;
Thu, 04 Sep 2025 04:57:09 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1756987029; cv=none;
d=google.com; s=arc-20240605;
b=bdcqfZCUuts8AaceRQn4Dleds+m786+/vXkGTVSFl9bU8A72jlWheul3hJBnAEoF6I
iYmw+VkcbcC65yNXSBR10aXqyWrIjepXkQjkJNbeQQGpH9WtaeLwzIFeIwr4TTClpi3t
+PIc6Qw4mZ2cMruIEoa5NPd24xoYx5WL3wAE9/66t/babGeiF4jfcH8leAlON/FGc3Fb
8fkbfxuyRkANJuGIHixCWRoep6zZOkLh84vEsA2XU2M/MchYr0R4r/dRrUyW6D9xKEiV
I1dMlKtAUOGfeGxpyQ1c4+mdRAE+PxhGDiUJtxD01CczrWe/4W2BIPG8R/p4SEUyx6Yq
Wjcg==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com;
s=arc-20240605;
h=content-transfer-encoding:mime-version:message-id:date:subject:to
:from:dkim-signature;
bh=W8V1Ji1vFiIBVpmNrGrJ9nH981KsaeEViw4x/4eDe94=;
fh=nvZsCFpxgpf+fsVXzjnWA8g1K3V/kNbRAKogjNDW4HY=;
b=Jdm6G3lO9bkoj8hHyfF59DDpMwmU9SarcSGEjQkTzg8DONkjhlHB5oa8vGsCGz9ZAl
n3579rOO2eR5thGRGyKDip2eWvvAJ4USx1LSIx2yrH+MrVazmibH2ou4GyhQFTumCnzw
oV0+w3WM8POzc2T8lPq2bIM93BfuOhrgaOnbFmL2dvqamLztr50hX52KFHVDqE7bwPgx
HfInLBcrlG9pQwoNvK2xmgrj8eqFzSOfu4y68gIrbZrYLjQk+d/PQzDxq3FGoUD/vx+w
zBP12mUSHQ3Sdd8kRtqK26s5sVt8twRyMP7JOabD/MtW2QA/5Dd8PJk2aPQUg4okyohV
+6ZQ==;
dara=google.com
ARC-Authentication-Results: i=1; gmr-mx.google.com;
dkim=pass header.i=@gmail.com header.s=20230601 header.b=MhoQFgKn;
spf=pass (google.com: domain of m.glembo@gmail.com designates
2a00:1450:4864:20::636 as permitted sender) smtp.mailfrom=m.glembo@gmail.com;
dmarc=pass (p=NONE sp=QUARANTINE dis=NONE) header.from=gmail.com;
dara=pass header.i=@googlegroups.com
Received: from mail-ej1-x636.google.com (mail-ej1-x636.google.com.
[2a00:1450:4864:20::636])
by gmr-mx.google.com with ESMTPS id
38308e7fff4ca-337f49f1a57si1441871fa.0.2025.09.04.04.57.09
for <swupdate@googlegroups.com>
(version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128);
Thu, 04 Sep 2025 04:57:09 -0700 (PDT)
Received-SPF: pass (google.com: domain of m.glembo@gmail.com designates
2a00:1450:4864:20::636 as permitted sender) client-ip=2a00:1450:4864:20::636;
Received: by mail-ej1-x636.google.com with SMTP id
a640c23a62f3a-afebb6d4093so182641166b.1
for <swupdate@googlegroups.com>; Thu, 04 Sep 2025 04:57:09 -0700 (PDT)
X-Gm-Gg: ASbGncu6euRi2+tHq5esXaZkRGJ/EkG6uMxfjQTEpeO1p/vOedXgANfRO0BFeg+I4qP
EuMLoyB1T0UGwmMYnpe/PQeAT4JdfY8LkewaQU5VaoCR0/zv/uEYPxnn169q6jIW2vEhNES9+Mj
UwT2hJm8D0dpgxy0OYqhYmq2oYolJWVg9GwiwRExNjRMPFOOF2S4xIeyvHdgsn11sgi1MPCSHN6
5qaKguj7I69YN/S59V8v+zaPl8D1kblOmwHIaYIbv5G+NCZm1uVg7BADOmuC/hMwrl46NJTqq+f
XDuTjUVCQnzRdeRI0DBX2MS42EuWGulhIQBR7FM0/oSZugEnWSGBAnCcMkhmMjQ7MbnRHdt8Gkz
TaHc5VHelvF2MNeF0/YpJnvxoOvVrvBF6AKWXlbcYfNE=
X-Received: by 2002:a17:907:934d:b0:afe:dbfb:b10e with SMTP id
a640c23a62f3a-b01d979d48dmr1691091166b.47.1756987028750;
Thu, 04 Sep 2025 04:57:08 -0700 (PDT)
Received: from PC-2635.irisgmbh.local ([2a02:8108:96a3:5d00::454d])
by smtp.gmail.com with ESMTPSA id
a640c23a62f3a-b04129eccbfsm1203751066b.7.2025.09.04.04.57.07
for <swupdate@googlegroups.com>
(version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256);
Thu, 04 Sep 2025 04:57:08 -0700 (PDT)
From: Michael Glembotzki <m.glembo@gmail.com>
To: swupdate@googlegroups.com
Subject: [swupdate] [PATCH v5 00/16] Add support for asymmetric decryption
Date: Thu, 4 Sep 2025 13:49:47 +0200
Message-ID: <20250904115704.58413-1-Michael.Glembotzki@iris-sensing.com>
X-Mailer: git-send-email 2.50.1
MIME-Version: 1.0
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable
X-Original-Sender: m.glembo@gmail.com
X-Original-Authentication-Results: gmr-mx.google.com; dkim=pass
header.i=@gmail.com header.s=20230601 header.b=MhoQFgKn; spf=pass
(google.com: domain of m.glembo@gmail.com designates 2a00:1450:4864:20::636
as permitted sender) smtp.mailfrom=m.glembo@gmail.com; dmarc=pass
(p=NONE sp=QUARANTINE dis=NONE) header.from=gmail.com;
dara=pass header.i=@googlegroups.com
Precedence: list
Mailing-list: list swupdate@googlegroups.com;
contact swupdate+owners@googlegroups.com
List-ID: <swupdate.googlegroups.com>
X-Spam-Checked-In-Group: swupdate@googlegroups.com
X-Google-Group-Id: 605343134186
List-Post: <https://groups.google.com/group/swupdate/post>,
<mailto:swupdate@googlegroups.com>
List-Help: <https://groups.google.com/support/>,
<mailto:swupdate+help@googlegroups.com>
List-Archive: <https://groups.google.com/group/swupdate
List-Subscribe: <https://groups.google.com/group/swupdate/subscribe>,
<mailto:swupdate+subscribe@googlegroups.com>
List-Unsubscribe:
<mailto:googlegroups-manage+605343134186+unsubscribe@googlegroups.com>,
<https://groups.google.com/group/swupdate/subscribe>
|
| Series |
Add support for asymmetric decryption
|
expand
|
Hi everyone, I’ve just updated the long-pending Asymmetric Decryption feature. Now that Stefano has finished the crypto rework, there shouldn’t be any blockers left. The first few patch files are basically independent of the OpenSSL CMS part and could already be merged. Thanks a lot for your feedback and please test it thoroughly. Best regards, Michael Michael Glembotzki (12): openssl_DECRYPT_init: Fix error message on missing iv swupdate.c: Abort if no key for encrypted sw-description is provided swupdate: Add -K / --decryption-key param and decryption-key-file config parser: Read aes-key from sw-description into struct img_type Add openssl cms decryption functions for asymmetric decryption util.h: Propagate cipher and image aes key to copy pipeline stream_interface.c: Force opensslCMS as crypto lib for sw-description cpio_utils.c: use per-image AES key / iv from sw-description decrypt_keys: make ivt dynamically allocated cpio_utils: handle -EAGAIN and set eof only on success crypto: store cipher in decryption_key and use default key only if it matches doc: Add documentation for asymmetric decryption Stefano Babic (4): core: don't check for writen output to terminate crypto: prepare to support multiple cipher Move accessors for keys in own file decrypt_keys.c: Store key filename for opensslCMS decryption core/Makefile | 1 + core/cpio_utils.c | 34 +++++++++++-- core/crypto.c | 4 +- core/decrypt_keys.c | 194 +++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ core/installer.c | 2 + core/stream_interface.c | 39 ++++++++++----- core/swupdate.c | 15 ++++-- core/util.c | 134 ------------------------------------------------- crypto/Kconfig | 18 +++++++ crypto/Makefile | 1 + crypto/swupdate_decrypt_mbedtls.c | 7 ++- crypto/swupdate_decrypt_openssl.c | 7 ++- crypto/swupdate_decrypt_openssl_cms.c | 202 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ crypto/swupdate_decrypt_wolfssl.c | 6 ++- crypto/swupdate_openssl.h | 3 ++ doc/source/asym_encrypted_images.rst | 159 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ doc/source/encrypted_images.rst | 2 + doc/source/index.rst | 1 + doc/source/sw-description.rst | 25 +++++++--- include/swupdate_aes.h | 55 ++++++++++++++++++++ include/swupdate_crypto.h | 5 +- include/swupdate_image.h | 3 ++ include/util.h | 9 +++- parser/parser.c | 35 ++++++++++++- 24 files changed, 789 insertions(+), 172 deletions(-)