mail archive of the barebox mailing list
 help / color / mirror / Atom feed
From: Ahmad Fatoum <a.fatoum@pengutronix.de>
To: barebox@lists.infradead.org
Cc: Ahmad Fatoum <a.fatoum@pengutronix.de>
Subject: [PATCH] bootm: change default verification mode from hash to available
Date: Fri, 14 Feb 2025 16:46:22 +0100	[thread overview]
Message-ID: <20250214154622.235998-1-a.fatoum@pengutronix.de> (raw)

The default of global.bootm.verify=hash means that barebox will refuse
to boot images without hashes, but won't bother verifying the signature.

For verified boot setups, this parameter needs to be set to signature,
preferably enforced via CONFIG_BOOTM_FORCE_SIGNED_IMAGES.

For everything else, it's better user experience if barebox would just
verify what's available instead of refusing to boot images without hashes,
like the image.fit that Linux can now generate as part of its build.

Signed-off-by: Ahmad Fatoum <a.fatoum@pengutronix.de>
---
 common/bootm.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/common/bootm.c b/common/bootm.c
index 80905d4cf1ce..dd9ba2eae3b2 100644
--- a/common/bootm.c
+++ b/common/bootm.c
@@ -87,7 +87,7 @@ void bootm_data_restore_defaults(const struct bootm_data *data)
 	bootm_dryrun = data->dryrun;
 }
 
-static enum bootm_verify bootm_verify_mode = BOOTM_VERIFY_HASH;
+static enum bootm_verify bootm_verify_mode = BOOTM_VERIFY_AVAILABLE;
 
 enum bootm_verify bootm_get_verify_mode(void)
 {
-- 
2.39.5




             reply	other threads:[~2025-02-14 15:48 UTC|newest]

Thread overview: 2+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2025-02-14 15:46 Ahmad Fatoum [this message]
2025-02-17  7:39 ` Sascha Hauer

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20250214154622.235998-1-a.fatoum@pengutronix.de \
    --to=a.fatoum@pengutronix.de \
    --cc=barebox@lists.infradead.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox