| Age | Commit message (Collapse) | Author | Files | Lines |
|
socsec fails to build with the latest openembedded core due to
Python package updates and socsec using deprecated libraries.
Add a patch that fixes issues, which has been submitted to
AspeedTech-BMC's repository.
Signed-off-by: Patrick Williams <patrick@stwcx.xyz>
Change-Id: I11018b6494c6adcaca2762ca43b747d5f92bccd8
|
|
- Bump socsec recipe from version 2.0.2 to 2.0.12.
- Add python3-cryptography to DEPENDS and RDEPENDS in socsec.inc for
improved cryptographic support.
- Set OPENSSL_MODULES in socsec-sign.bbclass to ensure correct OpenSSL
module path during signing.
Change-Id: Iccb9822f5e2eb817fcb3f19eff0d018766adc836
Signed-off-by: Vince Chang <vince_chang@aspeedtech.com>
|
|
Yocto seems to have once again tightened the strings on how to correctly
use S, UNPACKDIR, and WORKDIR. These are the needed changes to get it to
compile.
There are migration instructions in migration-5.3.rst.
Also remove the general setting of S within files if it's only setting
it to a default.
Change-Id: I184922c609efebe4434ed71e9b381fd40159242d
Signed-off-by: Andrew Geissler <geissonator@yahoo.com>
Signed-off-by: Patrick Williams <patrick@stwcx.xyz>
|
|
- prebuilt: remove unused public key entries
- prebuilt: add ast2700-caliptra-fw-v1.2-ecc-lms.bin
- prebuilt: add ast2700-caliptra-fw-v1.2.bin
Change-Id: I03ec6dc3681081a7fdef2ab1de7a39f59db9e621
Signed-off-by: Vince Chang <vince_chang@aspeedtech.com>
|
|
AST2700 uese fmc-imgtool to generate bootmcu firmware.
Change-Id: I90c8a5cabbdac90fe4e230b40a869999a243b700
Signed-off-by: Vince Chang <vince_chang@aspeedtech.com>
|
|
Newer yocto has removed the "Accepted" status[1] and requires a Backport
with the version it will come in.
[1]: https://docs.yoctoproject.org/contributor-guide/recipe-style-guide.html#patch-upstream-status
Change-Id: I5b788dfa7788c021f6d10298016b58943e188808
Signed-off-by: Andrew Geissler <geissonator@yahoo.com>
|
|
There's a bug in socsec that prevents the IBM's configuration from
successfully building an OTP image.
I have got the fix merged upstream:
https://github.com/AspeedTech-BMC/socsec/pull/18
However, Aspeed do not plan on doing a release until October:
> [ 17:51 ] arj: @Troy Lee any chance Neal can tag a new socsec release so we can bump it in OpenBMC and pick up some recent fixes?
> [ 18:25 ] Troy Lee: Current schedule is October.
https://discord.com/channels/775381525260664832/922871693008068638/1144547174286377062
For now, fix otptool using a recipe patch, in violation of the usual
guidelines.
I prefer we do this over switching to a "git" version for the recipe as
instability with these tools really cannot be tolerated.
Change-Id: I65b1992b5479ea257cfa65fd8b3cfc021b7d3dea
Signed-off-by: Andrew Jeffery <andrew@aj.id.au>
|
|
Change-Id: I95010b4925632b4384b90b2f113b9b826b5b63bd
Signed-off-by: Andrew Jeffery <andrew@aj.id.au>
|
|
This removes support for the v1 OTP format and introduces v2, which uses
SHA384 checksums.
Johnny Huang (6):
socsec: add ecdsa sign helper
otp_info: update ast10xx header
otp: update otptool to v2.0.0
Merge branch 'develop'
update test case for 2.0.0
otptool: fix checksum compare
Change-Id: I049bd34898be912043e010ef39ff05a888a365da
Signed-off-by: Joel Stanley <joel@jms.id.au>
|
|
Signed-off-by: Jamin Lin <jamin_lin@aspeedtech.com>
Change-Id: Iabba6e2d3f2c4e19af821b22164681f1d69a2501
|
|
With the latest yocto subtree update, this function has been moved into
the global python package.
Signed-off-by: Andrew Geissler <geissonator@yahoo.com>
Change-Id: I60fd8a2160e45823065a9a28ae36af263baa15cb
|
|
1. To fix python modules not found such as bitarray at do_compile task
, adds "DEPEND" to install dependencies.
2. Create a socsec.inc to place the common settings.
3. Create a socsec_1.0.0.bb to build socsec tool v1.0.0.
Signed-off-by: Jamin Lin <jamin_lin@aspeedtech.com>
Change-Id: I27a9216419555b58e7484e85506fa229f0e230b7
|
|
Andrew Jeffery (10):
resocsec: Style cleanup via autopep8
resocsec: Use env(1) for shebang
resocsec: Consistently use single-quotes for strings
resocsec: Make signing helper options mutually exclusive
resocsec: Add a helper for frobbing the RSA algorithm slug
resocsec: Attempt at ergonomic Chain-of-Trust options
resocsec: Rename secure-bootloader to secure-bootstrap-image
resocsec: Add secure-chained-images subcommand
resocsec: Add verify-secure-image subcommand
setup: Install resocsec
Johnny Huang (43):
Merge branch 'develop' into resocsec
Merge pull request #7 from amboar/resocsec
resocsec: fix typo
socsec: add support for ast2605
socsec: remove hexdump module dependcy
schema: update otp schema
otptool: fix making strap region
otptool: fix schema typo
readme: add descripton of verify
strap: fix "VGA class code" info
otptool: fix schema key
otptool: fix OTPCFG0[14] description for 2600A1
socsec: move hexdump to global
otptool: add 'print' function for otptool
socsec: fix public key exponent
otp_info: fix config typo
otptool: add AST2600A3 support
socsec: add rsa pss padding for AST1030A1
socsec: fix cot public key exponent
socsec: Add new test item
socsec: Add 2600A3 test item
Merge branch 'develop'
socsec: add mode2v2aes2 pub and priv test
socsec: add ecdsa mode for AST1030A1
socsec: Add ecdsa test item
otp_info: remove ast1030 from otp_info
otp_info: update schema
socsec: update revision id
otptool: update schema for manifest id config
socsec: fix revision id range.
socsec: fix f-strings giving SyntaxError
socsec: deprecate the CoT sing function
otptool: fix bitarray AttributeError
readme: update readme and fix typo
otp_info: update otp info
tool: add info2sample tool
otp_info: Add AST2600A3 otp config
otp_info: update and add OTPSTRAP Reserved info
otptool: fix otptool print
otptool: make image also generate OTPCFG1
tool: add script to generate otp config schema
setup: update version number
Merge branch 'develop'
Change-Id: Ie78aa2c0ddb18d823e1055a67c76967aa9762285
Signed-off-by: Andrew Jeffery <andrew@aj.id.au>
|
|
Signed-off-by: Patrick Williams <patrick@stwcx.xyz>
Change-Id: I8135871ae0e3b360aff7d878f7cf04a2504f2dd0
|
|
socsec is required for securing firmware leveraging the hardware root of
trust in the AST2600.
Change-Id: I7f44609df1d303e8211eb9286442afdfcd77c4b8
Signed-off-by: Andrew Jeffery <andrew@aj.id.au>
|