X-Git-Url: http://git.ozlabs.org/?a=blobdiff_plain;f=lib%2Fflash%2Fflash.c;h=3505cb4f959be52b5cf9068bb6e7b6359f980e83;hb=cf9e0cd6f7caf7b171457f7bf9f56f23ec3e478c;hp=b7e5b88b95684f737eeaa4366cda298387c046c1;hpb=c78f9ec47ba92b74698dacdae963dbbefd9b676f;p=petitboot diff --git a/lib/flash/flash.c b/lib/flash/flash.c index b7e5b88..3505cb4 100644 --- a/lib/flash/flash.c +++ b/lib/flash/flash.c @@ -31,6 +31,8 @@ #include #include +#define SECURE_BOOT_HEADERS_SIZE 4096 +#define ROM_MAGIC_NUMBER 0x17082011 struct flash_info { /* Device information */ @@ -148,6 +150,16 @@ out: return NULL; } +/* See stb_is_container() in Skiboot */ +static bool is_signed(char *buffer, uint32_t len) +{ + if (!buffer || len <= SECURE_BOOT_HEADERS_SIZE) + return false; + if (be32_to_cpu(*(uint32_t *)buffer) != ROM_MAGIC_NUMBER) + return false; + return true; +} + int flash_parse_version(void *ctx, char ***versions, bool current) { char *saveptr, *tok, **tmp, *buffer; @@ -182,6 +194,10 @@ int flash_parse_version(void *ctx, char ***versions, bool current) goto out; } + /* Check if this partition is signed */ + if (is_signed(buffer, len)) + buffer += SECURE_BOOT_HEADERS_SIZE; + /* open-power-platform */ tok = strtok_r(buffer, delim, &saveptr); if (tok) {