From mboxrd@z Thu Jan 1 00:00:00 1970 Delivery-date: Fri, 11 Sep 2026 15:39:37 +0200 Received: from mx1.white.stw.pengutronix.de ([185.203.200.13]) by lore.white.stw.pengutronix.de with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.96) (envelope-from ) id 1x51Td-000xk4-0V for lore@lore.pengutronix.de; Fri, 11 Sep 2026 15:39:37 +0200 Authentication-Results: mx1.white.stw.pengutronix.de; dkim=pass header.d=lists.infradead.org header.s=bombadil.20210309 header.b="3p9G3bY/"; spf=pass (mx1.white.stw.pengutronix.de: domain of "barebox-bounces+lore=pengutronix.de@lists.infradead.org" designates 2607:7c80:54:3::133 as permitted sender) smtp.mailfrom="barebox-bounces+lore=pengutronix.de@lists.infradead.org"; dmarc=none Received: from bombadil.infradead.org (bombadil.infradead.org [IPv6:2607:7c80:54:3::133]) by mx1.white.stw.pengutronix.de (Postfix) with ESMTPS id F0C3D20203C for ; Fri, 11 Sep 2026 15:39:36 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.infradead.org; s=bombadil.20210309; h=Sender:List-Subscribe:List-Help :List-Post:List-Archive:List-Unsubscribe:List-Id:Content-Transfer-Encoding: Content-Type:MIME-Version:Date:Message-Id:Subject:References:In-Reply-To:Cc: To:From:Reply-To:Content-ID:Content-Description:Resent-Date:Resent-From: Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Owner; bh=SfAehHpeNuXS0M7EHPye5zsrC0VcbvCFIbFXuqkOdSQ=; b=3p9G3bY/x7T5tOHZ5dIMxhX9v2 IFBoyUpl7Rz+qMzEB/rSKNNTZeeKiNhFP9givMxa8gb8ZvxwtpFv/FsePEWXVCsa/Hy+Lwf7o5OD8 1S+NiayX+zhT6AORM4rdULDI7YpYZUtEG98ZI4fSfPYr9RtU2r2DoS2oWy1+4IINCzwHTU//tay2E 5TqkLkliLCMGVvoURRDJ8eNr8QBVnIwW2khFQlks3w/aCSvbgcDAr5Cc0ssmdelez6TW1HOfg4cJq sp2PgJdv6k2p/wq+Dq9/53QCuyWxllIL+iWFotzOjmrQtfXwUbERORQo9AHIrHTctpEHYwyjIeLEW Ex4qVZxA==; Received: from localhost ([::1] helo=bombadil.infradead.org) by bombadil.infradead.org with esmtp (Exim 4.99.1 #2 (Red Hat Linux)) id 1x51SK-0000000GleD-2Ghq; Fri, 11 Sep 2026 13:38:16 +0000 Received: from mx1.white.stw.pengutronix.de ([185.203.200.13]) by bombadil.infradead.org with esmtps (Exim 4.99.1 #2 (Red Hat Linux)) id 1x51SH-0000000GldN-0A0p for barebox@lists.infradead.org; Fri, 11 Sep 2026 13:38:15 +0000 Received: from drehscheibe.grey.stw.pengutronix.de (drehscheibe.grey.stw.pengutronix.de [IPv6:2a0a:edc0:0:c01:1d::a2]) (Authenticated sender: relay-from-drehscheibe.grey.stw.pengutronix.de) by mx1.white.stw.pengutronix.de (Postfix) with ESMTPSA id CB11A20203C; Fri, 11 Sep 2026 15:38:10 +0200 (CEST) Received: from dude02.red.stw.pengutronix.de ([2a0a:edc0:0:1101:1d::28]) by drehscheibe.grey.stw.pengutronix.de with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.96) (envelope-from ) id 1x51SE-000QcB-2M; Fri, 11 Sep 2026 15:38:10 +0200 Received: from [::1] (helo=dude02.red.stw.pengutronix.de) by dude02.red.stw.pengutronix.de with esmtp (Exim 4.98.2) (envelope-from ) id 1x51SE-0000000A8Mx-2jkg; Fri, 11 Sep 2026 15:38:10 +0200 From: Sascha Hauer To: barebox@lists.infradead.org, Ahmad Fatoum Cc: uol@pengutronix.de In-Reply-To: <20260910102141.170024-1-a.fatoum@pengutronix.de> References: <20260910102141.170024-1-a.fatoum@pengutronix.de> Subject: Re: [PATCH v2] commands: bootm: remove -c and -s options Message-Id: <178913389064.2415444.13831101912356780978.b4-ty@pengutronix.de> Date: Fri, 11 Sep 2026 15:38:10 +0200 MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: 7bit X-Mailer: b4 0.14.3 X-CRM114-Version: 20100106-BlameMichelson ( TRE 0.9.0 (BSD) ) MR-646709E3 X-CRM114-CacheID: sfid-20260911_063813_236287_E5592E55 X-CRM114-Status: UNSURE ( 7.02 ) X-CRM114-Notice: Please train this message. X-Spam-Score: -1.9 (-) X-Spam-Report: Spam detection software, running on the system "bombadil.infradead.org", has NOT identified this incoming email as spam. The original message has been attached to this so you can view it or label similar future email. If you have any questions, see the administrator of that system for details. Content preview: On Thu, 10 Sep 2026 12:21:06 +0200, Ahmad Fatoum wrote: > We have inconsistencies about what verification level is used for FIT > images when they are used for both booting and for overlays if > boot [...] Content analysis details: (-1.9 points, 5.0 required) pts rule name description ---- ---------------------- -------------------------------------------------- -0.0 SPF_HELO_PASS SPF: HELO matches SPF record -0.0 SPF_PASS SPF: sender matches SPF record -1.9 BAYES_00 BODY: Bayes spam probability is 0 to 1% [score: 0.0000] 0.0 DMARC_MISSING Missing DMARC policy X-BeenThere: barebox@lists.infradead.org X-Mailman-Version: 2.1.34 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: "barebox" X-Rspamd-Server: mx1 X-Stat-Signature: xfx3uy4ggw7edkc8q3zxkzdjcz6jsfxd X-Rspamd-Queue-Id: F0C3D20203C X-Spamd-Result: default: False [-57.77 / 15.00]; RECEIVED_AUTHENTICATED_BY_MX1(-50.00)[]; BAYES_HAM(-2.96)[99.81%]; DWL_DNSWL_MED(-2.00)[infradead.org:dkim]; KNOWN_LIST_ID(-1.00)[barebox.lists.infradead.org]; RCVD_IN_DNSWL_MED(-0.60)[2607:7c80:54:3::133:from,2a0a:edc0:0:c01:1d::a2:received,2a0a:edc0:0:1101:1d::28:received]; RCVD_DKIM_ARC_DNSWL_MED(-0.50)[]; R_SPF_ALLOW(-0.20)[+mx:c]; MAILLIST(-0.20)[mailman]; R_DKIM_ALLOW(-0.20)[lists.infradead.org:s=bombadil.20210309]; MIME_GOOD(-0.10)[text/plain]; HAS_LIST_UNSUB(-0.01)[]; RCVD_TLS_LAST(0.00)[]; MIME_TRACE(0.00)[0:+]; ARC_NA(0.00)[]; TAGGED_FROM(0.00)[lore=pengutronix.de]; RECEIVED_HELO_LOCALHOST(0.00)[]; DMARC_NA(0.00)[pengutronix.de]; ASN(0.00)[asn:7247, ipnet:2607:7c80:54::/48, country:US]; RCPT_COUNT_THREE(0.00)[3]; RCVD_COUNT_FIVE(0.00)[5]; FROM_NEQ_ENVFROM(0.00)[s.hauer@pengutronix.de,barebox-bounces@lists.infradead.org]; FROM_HAS_DN(0.00)[]; DKIM_TRACE(0.00)[lists.infradead.org:+]; NEURAL_HAM(-0.00)[-1.000]; RCVD_VIA_SMTP_AUTH(0.00)[]; MID_RHS_MATCH_FROM(0.00)[]; TO_DN_SOME(0.00)[]; FORGED_SENDER_MAILLIST(0.00)[] X-Rspamd-Action: no action On Thu, 10 Sep 2026 12:21:06 +0200, Ahmad Fatoum wrote: > We have inconsistencies about what verification level is used for FIT > images when they are used for both booting and for overlays if > bootm -c/-s is used to raise the verification level. > > Properly fixing them would increase the complexity, which could > in turn negatively impact security. > > [...] Applied, thanks! [1/1] commands: bootm: remove -c and -s options https://git.pengutronix.de/cgit/barebox/commit/?id=93e0ed81f13a (link may not be stable) Best regards, -- Sascha Hauer