Verified boot support with FIT

Simon Glass sjg at chromium.org
Fri Jan 15 17:18:06 PST 2016


Hi Jan,

On 15 January 2016 at 01:36, Jan Lübbe <jlu at pengutronix.de> wrote:
> On Do, 2016-01-14 at 21:03 +0100, Marc Kleine-Budde wrote:
>> On 01/14/2016 08:30 PM, Simon Glass wrote:
>> > Someone pointed me to this support that is being added in Barebox. I see
>> > that it still has the copyright but does not attribute U-Boot. I'm just
>> > checking if that is that an oversight?
>>
>> I've Cc'ed Jan, who has written the code. Quoting from his first patch
>> to the barebox mailinglist:
>>
>> > this is the current work-in-progress state of my FIT support patches.
>> > The FIT loading code has basically been rewritten from scratch, as the
>> > original U-Boot code uses libfdt and barebox's DT support works on an
>> > in-memory tree.
>
> Yes, this is still correct for the recent submissions.
>
> The barebox code only supports the signed configurations with hashed
> images, as the goal was to use this for verified boot. Supporting only
> this mode keeps the complexity down.
>
> Simon, do you think it is a derived work of the U-Boot FIT code?

The verified boot implementation looks like it came from U-Boot.

Regards,
Simon



More information about the barebox mailing list