scripts/Makefile.lib: EFI: Use capsule CRT instead of ESL file
The EFI Capsule ESL file (EFI Signature List File) used for authentication is a binary generated from the EFI Capsule public key certificate. Instead of including it in the source repo, automatically generate it from the certificate file during the build process. Currently, sandbox is the only device using this, so removed its ESL file and set the (new) CONFIG_EFI_CAPSULE_CRT_FILE config to point to its public key certificate. Signed-off-by: Jonathan Humphreys <j-humphreys@ti.com>
This commit is contained in:
committed by
Heinrich Schuchardt
parent
809141812e
commit
659f97eb1f
+15
-9
@@ -342,21 +342,27 @@ cmd_dtc = mkdir -p $(dir ${dtc-tmp}) ; \
|
||||
; \
|
||||
sed "s:$(pre-tmp):$(<):" $(depfile).pre.tmp $(depfile).dtc.tmp > $(depfile)
|
||||
|
||||
quiet_cmd_capsule_esl_gen = CAPSULE_ESL_GEN $@
|
||||
cmd_capsule_esl_gen = \
|
||||
$(shell sed "s:ESL_BIN_FILE:$(capsule_esl_path):" $(capsule_esl_input_file) > $@)
|
||||
capsule_esl_input_file=$(srctree)/lib/efi_loader/capsule_esl.dtsi.in
|
||||
capsule_crt_file=$(subst $(quote),,$(CONFIG_EFI_CAPSULE_CRT_FILE))
|
||||
capsule_esl_dtsi=.capsule_esl.dtsi
|
||||
|
||||
$(obj)/.capsule_esl.dtsi: FORCE
|
||||
ifeq ($(CONFIG_EFI_CAPSULE_ESL_FILE),"")
|
||||
$(error "CONFIG_EFI_CAPSULE_ESL_FILE is empty, EFI capsule authentication \
|
||||
quiet_cmd_capsule_esl_gen = CAPSULE_ESL_GEN $@
|
||||
cmd_capsule_esl_gen = cert-to-efi-sig-list $< $@
|
||||
|
||||
$(obj)/capsule_esl_file: $(capsule_crt_file) FORCE
|
||||
ifeq ($(CONFIG_EFI_CAPSULE_CRT_FILE),"")
|
||||
$(error "CONFIG_EFI_CAPSULE_CRT_FILE is empty, EFI capsule authentication \
|
||||
public key must be specified when CONFIG_EFI_CAPSULE_AUTHENTICATE is enabled")
|
||||
else
|
||||
$(call cmd,capsule_esl_gen)
|
||||
endif
|
||||
|
||||
capsule_esl_input_file=$(srctree)/lib/efi_loader/capsule_esl.dtsi.in
|
||||
capsule_esl_dtsi = .capsule_esl.dtsi
|
||||
capsule_esl_path=$(abspath $(srctree)/$(subst $(quote),,$(CONFIG_EFI_CAPSULE_ESL_FILE)))
|
||||
quiet_cmd_capsule_dtsi_gen = CAPSULE_DTSI_GEN $@
|
||||
cmd_capsule_dtsi_gen = \
|
||||
$(shell sed "s:ESL_BIN_FILE:$(abspath $<):" $(capsule_esl_input_file) > $@)
|
||||
|
||||
$(obj)/$(capsule_esl_dtsi): $(obj)/capsule_esl_file FORCE
|
||||
$(call cmd,capsule_dtsi_gen)
|
||||
|
||||
dtsi_include_list_deps := $(addprefix $(u_boot_dtsi_loc),$(subst $(quote),,$(dtsi_include_list)))
|
||||
|
||||
|
||||
Reference in New Issue
Block a user