
19 Jul
2016
19 Jul
'16
7:46 a.m.
On 18.7.2016 14:05, Mario Six wrote:
In certain circumstances it comes in handy to be able to boot into a second U-Boot. But as of now it is not possible to boot a U-Boot binary that is inside a FIT image, which is problematic for projects that e.g. need to guarantee a unbroken chain of trust from SOC all the way into the OS, since the FIT signing mechanism cannot be used.
This patch adds the capability to load such FIT images.
An example its snippet (utilizing signature verification) might look like the following:
images { kernel@1 { description = "2nd stage U-Boot image"; data = /incbin/("u-boot-dtb.img.gz"); type = "kernel";
Isn't this type weird for u-boot itself?
The rest is good.
Thanks, Michal