summaryrefslogtreecommitdiff
path: root/meta-google/recipes-phosphor/flash/inplace-gbmc-update/inplace-gbmc-verify.sh
diff options
context:
space:
mode:
authorBrandon Kim <brandonkim@google.com>2021-07-21 01:59:47 +0300
committerBrandon Kim <brandonkim@google.com>2021-08-02 19:23:11 +0300
commit0547cc4c492e6a4c42b710b98dc6ab414bf46c5d (patch)
tree10a4230a2b5d69bee3afbd007cef77f98b0a7462 /meta-google/recipes-phosphor/flash/inplace-gbmc-update/inplace-gbmc-verify.sh
parent4e2735e0dc487c0cb3c3e38e10df7b728ff85cef (diff)
downloadopenbmc-0547cc4c492e6a4c42b710b98dc6ab414bf46c5d.tar.xz
meta-google: flash: Import inplace-gbmc-update
Google BMC inplace update script and bitbake recipe. Google-Bug-Id: 179618162 Upstream: 22e2c3dd5f610777dee173a09d8e82dc2509a975 Signed-off-by: Brandon Kim <brandonkim@google.com> Change-Id: Ia1beded107382dacb9f2f7e3cb9bbd86ae99d8c1
Diffstat (limited to 'meta-google/recipes-phosphor/flash/inplace-gbmc-update/inplace-gbmc-verify.sh')
-rw-r--r--meta-google/recipes-phosphor/flash/inplace-gbmc-update/inplace-gbmc-verify.sh57
1 files changed, 57 insertions, 0 deletions
diff --git a/meta-google/recipes-phosphor/flash/inplace-gbmc-update/inplace-gbmc-verify.sh b/meta-google/recipes-phosphor/flash/inplace-gbmc-update/inplace-gbmc-verify.sh
new file mode 100644
index 000000000..d5307d3d1
--- /dev/null
+++ b/meta-google/recipes-phosphor/flash/inplace-gbmc-update/inplace-gbmc-verify.sh
@@ -0,0 +1,57 @@
+#!/bin/bash
+# Copyright 2021 Google LLC
+#
+# Licensed under the Apache License, Version 2.0 (the "License");
+# you may not use this file except in compliance with the License.
+# You may obtain a copy of the License at
+#
+# http://www.apache.org/licenses/LICENSE-2.0
+#
+# Unless required by applicable law or agreed to in writing, software
+# distributed under the License is distributed on an "AS IS" BASIS,
+# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+# See the License for the specific language governing permissions and
+# limitations under the License.
+
+
+# This script will check the signature for the BMC image against
+# the baked in keyring available. If any aspect of this fails,
+# the scripts returns non-zero and this can be reported to the
+# host.
+#
+# 1. Verify the image
+# 2. Rename the image
+
+KEYRING=/etc/googlekeys/gbmc/gbmc.gpg
+SIGNATURE_FILE=/tmp/bmc.sig
+STATUS_FILE=/tmp/bmc.verify
+
+# Store in /run/initramfs because the behaviour of mv changes
+# depending on whether the file is moving within a tree or not.
+IMAGE_FILE=/run/initramfs/bmc-image
+VERIFIED_FILE=/run/initramfs/image-bmc
+
+# Make sure we run ERR traps when a function returns an error
+set -e
+
+# Write out the result of the script to a status file upon exiting
+# normally or due to an error
+exit_handler() {
+ local status="$?"
+ if (( status == 0 )); then
+ echo "success" >"${STATUS_FILE}"
+ else
+ echo "failed" >"${STATUS_FILE}"
+ fi
+ trap - EXIT ERR
+ exit "$status"
+}
+trap exit_handler EXIT ERR
+
+echo "running" > ${STATUS_FILE}
+
+# Verify the image.
+verify-bmc-image.sh @ALLOW_DEV@ "$IMAGE_FILE" "$SIGNATURE_FILE" || exit
+
+# Rename the staged file for initramfs updates.
+mv ${IMAGE_FILE} ${VERIFIED_FILE}#!/bin/bash