Thanks Mimi, I am asking if integrity team is working with zip community like the RPM. I will have a look at zip code to see if it is in my capacity to add xattr support or not. A possible solution looks like replacing zip with tar in OTA solution. Thanks Matthew, I am at lower version of kernel therefore portable evm may not be taken in as of now. I will backport it possibly. On Thu, Jan 10, 2019 at 11:50 PM Matthew Garrett <mjg59@xxxxxxxxxx> wrote: > > On Wed, Jan 9, 2019 at 10:47 PM rishi gupta <gupt21@xxxxxxxxx> wrote: > > > > Thanks Mimi. Any plan for zip archive format support. > > Also when using EVM, the files has to be signed on target. So after > > new files has been flashed on device during OTA, does private key also > > needs to be present on system. > > This is what the portable EVM format is for - it allows EVM signatures > to be generated remotely and shipped as part of a package.