Re: [PATCH] bootm: change default verification mode from hash to available

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On Fri, 14 Feb 2025 16:46:22 +0100, Ahmad Fatoum wrote:
> The default of global.bootm.verify=hash means that barebox will refuse
> to boot images without hashes, but won't bother verifying the signature.
> 
> For verified boot setups, this parameter needs to be set to signature,
> preferably enforced via CONFIG_BOOTM_FORCE_SIGNED_IMAGES.
> 
> For everything else, it's better user experience if barebox would just
> verify what's available instead of refusing to boot images without hashes,
> like the image.fit that Linux can now generate as part of its build.
> 
> [...]

Applied, thanks!

[1/1] bootm: change default verification mode from hash to available
      https://git.pengutronix.de/cgit/barebox/commit/?id=824314cbade2 (link may not be stable)

Best regards,
-- 
Sascha Hauer <s.hauer@xxxxxxxxxxxxxx>





[Index of Archives]     [Linux Embedded]     [Linux USB Devel]     [Linux Audio Users]     [Yosemite News]     [Linux Kernel]     [Linux SCSI]     [XFree86]

  Powered by Linux