From mboxrd@z Thu Jan 1 00:00:00 1970 Return-path: Received: from magratgarlick.emantor.de ([78.46.208.201]) by bombadil.infradead.org with esmtps (Exim 4.92 #3 (Red Hat Linux)) id 1hg01X-0005TW-F8 for barebox@lists.infradead.org; Wed, 26 Jun 2019 04:59:13 +0000 From: Rouven Czerwinski Date: Wed, 26 Jun 2019 06:58:53 +0200 Message-Id: <7712b5883ab9981b67db3e010c788c8c81aedb57.1561525118.git-series.r.czerwinski@pengutronix.de> In-Reply-To: References: MIME-Version: 1.0 List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit Sender: "barebox" Errors-To: barebox-bounces+u.kleine-koenig=pengutronix.de@lists.infradead.org Subject: [PATCH 12/13] mach-imx: hab: select piggy verification for i.MX8 To: barebox@lists.infradead.org Cc: Rouven Czerwinski Always select the piggy verification if HAB is enabled on i.MX8, otherwise the signed PBL might load untrusted piggydata. Signed-off-by: Rouven Czerwinski --- arch/arm/mach-imx/Kconfig | 1 + 1 file changed, 1 insertion(+) diff --git a/arch/arm/mach-imx/Kconfig b/arch/arm/mach-imx/Kconfig index 3cb8820..7a7684f 100644 --- a/arch/arm/mach-imx/Kconfig +++ b/arch/arm/mach-imx/Kconfig @@ -786,6 +786,7 @@ config HABV4 select IMX_OCOTP depends on ARCH_IMX6 || ARCH_IMX8MQ depends on OFDEVICE + select PBL_VERIFY_PIGGY if ARCH_IMX8MQ help High Assurance Boot, as found on i.MX28/i.MX6/i.MX8MQ. -- git-series 0.9.1 _______________________________________________ barebox mailing list barebox@lists.infradead.org http://lists.infradead.org/mailman/listinfo/barebox