Re: [PATCH 1/3 v2] efi_capsule: Move signature from DTB to .rodata

2021-08-01 Thread Simon Glass
Hi, On Thu, 22 Jul 2021 at 14:54, Ilias Apalodimas wrote: > > Hi Simon, > > On Thu, Jul 22, 2021 at 10:46:40AM -0600, Simon Glass wrote: > > > > > > > >> In some platforms the key is derived from the relocated DTB, > > > > > > > >> which we > > [...] > > > > > > > > >> can overwrite. But I'll le

Re: [PATCH 1/3 v2] efi_capsule: Move signature from DTB to .rodata

2021-07-22 Thread Ilias Apalodimas
Hi Simon, On Thu, Jul 22, 2021 at 10:46:40AM -0600, Simon Glass wrote: > > > > > > >> In some platforms the key is derived from the relocated DTB, > > > > > > >> which we [...] > > > > > > >> can overwrite. But I'll let Sughosh who figured it out explain > > > > > > >> the > > > > > > >> detai

Re: [PATCH 1/3 v2] efi_capsule: Move signature from DTB to .rodata

2021-07-22 Thread Simon Glass
Hi Ilias, On Thu, 22 Jul 2021 at 07:56, Ilias Apalodimas wrote: > > On Thu, 22 Jul 2021 at 16:30, Simon Glass wrote: > > > > Hi Ilias, > > > > On Thu, 22 Jul 2021 at 07:28, Simon Glass wrote: > > > > > > Hi Ilias, > > > > > > On Wed, 21 Jul 2021 at 00:42, Ilias Apalodimas > > > wrote: > > > >

Re: [PATCH 1/3 v2] efi_capsule: Move signature from DTB to .rodata

2021-07-22 Thread Ilias Apalodimas
On Thu, 22 Jul 2021 at 16:30, Simon Glass wrote: > > Hi Ilias, > > On Thu, 22 Jul 2021 at 07:28, Simon Glass wrote: > > > > Hi Ilias, > > > > On Wed, 21 Jul 2021 at 00:42, Ilias Apalodimas > > wrote: > > > > > > Hi Simon, > > > > > > On Tue, 20 Jul 2021 at 20:42, Simon Glass wrote: > > > > > >

Re: [PATCH 1/3 v2] efi_capsule: Move signature from DTB to .rodata

2021-07-22 Thread Simon Glass
Hi Ilias, On Thu, 22 Jul 2021 at 07:28, Simon Glass wrote: > > Hi Ilias, > > On Wed, 21 Jul 2021 at 00:42, Ilias Apalodimas > wrote: > > > > Hi Simon, > > > > On Tue, 20 Jul 2021 at 20:42, Simon Glass wrote: > > > > > > Hi Sughosh, > > > > > > On Tue, 20 Jul 2021 at 07:32, Sughosh Ganu > > >

Re: [PATCH 1/3 v2] efi_capsule: Move signature from DTB to .rodata

2021-07-22 Thread Simon Glass
Hi Ilias, On Wed, 21 Jul 2021 at 00:42, Ilias Apalodimas wrote: > > Hi Simon, > > On Tue, 20 Jul 2021 at 20:42, Simon Glass wrote: > > > > Hi Sughosh, > > > > On Tue, 20 Jul 2021 at 07:32, Sughosh Ganu wrote: > > > > > > hi Simon, > > > > > > On Tue, 20 Jul 2021 at 18:20, Ilias Apalodimas > >

Re: [PATCH 1/3 v2] efi_capsule: Move signature from DTB to .rodata

2021-07-20 Thread Ilias Apalodimas
Hi Simon, On Tue, 20 Jul 2021 at 20:42, Simon Glass wrote: > > Hi Sughosh, > > On Tue, 20 Jul 2021 at 07:32, Sughosh Ganu wrote: > > > > hi Simon, > > > > On Tue, 20 Jul 2021 at 18:20, Ilias Apalodimas > > wrote: > >> > >> Hi Simon, > >> On Tue, 20 Jul 2021 at 15:33, Simon Glass wrote: > >> >

Re: [PATCH 1/3 v2] efi_capsule: Move signature from DTB to .rodata

2021-07-20 Thread Simon Glass
Hi Sughosh, On Tue, 20 Jul 2021 at 07:32, Sughosh Ganu wrote: > > hi Simon, > > On Tue, 20 Jul 2021 at 18:20, Ilias Apalodimas > wrote: >> >> Hi Simon, >> On Tue, 20 Jul 2021 at 15:33, Simon Glass wrote: >> > >> > Hi Ilias, >> > >> > On Sat, 17 Jul 2021 at 08:27, Ilias Apalodimas >> > wrote:

Re: [PATCH 1/3 v2] efi_capsule: Move signature from DTB to .rodata

2021-07-20 Thread Sughosh Ganu
hi Simon, On Tue, 20 Jul 2021 at 18:20, Ilias Apalodimas wrote: > Hi Simon, > On Tue, 20 Jul 2021 at 15:33, Simon Glass wrote: > > > > Hi Ilias, > > > > On Sat, 17 Jul 2021 at 08:27, Ilias Apalodimas > > wrote: > > > > > > The capsule signature is now part of our DTB. This is problematic > wh

Re: [PATCH 1/3 v2] efi_capsule: Move signature from DTB to .rodata

2021-07-20 Thread Ilias Apalodimas
Hi Simon, On Tue, 20 Jul 2021 at 15:33, Simon Glass wrote: > > Hi Ilias, > > On Sat, 17 Jul 2021 at 08:27, Ilias Apalodimas > wrote: > > > > The capsule signature is now part of our DTB. This is problematic when a > > user is allowed to change/fixup that DTB from U-Boots command line since he >

Re: [PATCH 1/3 v2] efi_capsule: Move signature from DTB to .rodata

2021-07-20 Thread Simon Glass
Hi Ilias, On Sat, 17 Jul 2021 at 08:27, Ilias Apalodimas wrote: > > The capsule signature is now part of our DTB. This is problematic when a > user is allowed to change/fixup that DTB from U-Boots command line since he > can overwrite the signature as well. Just to repeat my question since it l