From b9799be79de3f0a15a14be392ee90574433435ad Mon Sep 17 00:00:00 2001 From: Patrick Williams Date: Fri, 6 Aug 2021 09:13:33 -0500 Subject: meta-aspeed: prep for new override syntax Signed-off-by: Patrick Williams Change-Id: I8135871ae0e3b360aff7d878f7cf04a2504f2dd0 --- meta-aspeed/classes/socsec-sign.bbclass | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) (limited to 'meta-aspeed/classes/socsec-sign.bbclass') diff --git a/meta-aspeed/classes/socsec-sign.bbclass b/meta-aspeed/classes/socsec-sign.bbclass index 1b1576592..b5866e29e 100644 --- a/meta-aspeed/classes/socsec-sign.bbclass +++ b/meta-aspeed/classes/socsec-sign.bbclass @@ -59,7 +59,7 @@ sign_spl() { } -do_deploy_append() { +do_deploy:append() { if [ "${SOCSEC_SIGN_ENABLE}" = "1" -a -n "${SPL_BINARY}" ] ; then sign_spl fi -- cgit v1.2.3 From bf97bbd459bde95346a00ca85e3f7995feb2d098 Mon Sep 17 00:00:00 2001 From: Andrew Jeffery Date: Thu, 26 Aug 2021 10:26:03 +0930 Subject: meta-aspeed: socsec-sign: Make invalid key configuration fatal Building the SPL and "silently" leaving it unsigned gives us a build that cannot be booted on systems that have secure-boot enabled. Change-Id: Ie788a04ef35c7031897a2bfa7d348caa4292305d Signed-off-by: Andrew Jeffery --- meta-aspeed/classes/socsec-sign.bbclass | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) (limited to 'meta-aspeed/classes/socsec-sign.bbclass') diff --git a/meta-aspeed/classes/socsec-sign.bbclass b/meta-aspeed/classes/socsec-sign.bbclass index b5866e29e..0af88d9f5 100644 --- a/meta-aspeed/classes/socsec-sign.bbclass +++ b/meta-aspeed/classes/socsec-sign.bbclass @@ -23,7 +23,8 @@ sign_spl_helper() { if [ "${SOC_FAMILY}" != "aspeed-g6" ] ; then echo "Warning: SPL signing is only supported on AST2600 boards" elif [ ! -e "${SOCSEC_SIGN_KEY}" ] ; then - echo "Warning: Invalid socsec signing key - SPL verified boot won't be available" + echo "Error: Invalid socsec signing key: ${SOCSEC_SIGN_KEY}" + exit 1 else rm -f ${SPL_BINARY}.staged -- cgit v1.2.3