From bbb73aad2b5877a0db953219fd1013b934a954fb Mon Sep 17 00:00:00 2001 From: Arturo Buzarra Date: Fri, 4 Sep 2020 14:31:37 +0200 Subject: [PATCH] imx-boot: generate signed U-Boot binary even when encryption is enabled This commit fixed the sdcard generation when encryption is enabled. In the sdcard image always is included the signed image instead of the encrypted. https://jira.digi.com/browse/DEL-7200 Signed-off-by: Arturo Buzarra --- meta-digi-arm/recipes-bsp/imx-mkimage/imx-boot_1.0.bbappend | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/meta-digi-arm/recipes-bsp/imx-mkimage/imx-boot_1.0.bbappend b/meta-digi-arm/recipes-bsp/imx-mkimage/imx-boot_1.0.bbappend index 1c01b9f4e..918378d8d 100644 --- a/meta-digi-arm/recipes-bsp/imx-mkimage/imx-boot_1.0.bbappend +++ b/meta-digi-arm/recipes-bsp/imx-mkimage/imx-boot_1.0.bbappend @@ -221,11 +221,12 @@ do_deploy_append () { for target in ${IMXBOOT_TARGETS}; do # Link to current "target" mkimage log ln -sf mkimage-${target}.log mkimage.log + trustfence-sign-uboot.sh ${DEPLOYDIR}/${UBOOT_PREFIX}-${MACHINE}-${rev}-${ramc}.bin-${target} ${DEPLOYDIR}/${UBOOT_PREFIX}-signed-${MACHINE}-${rev}-${ramc}.bin-${target} + if [ "${TRUSTFENCE_DEK_PATH}" != "0" ]; then export ENABLE_ENCRYPTION=y trustfence-sign-uboot.sh ${DEPLOYDIR}/${UBOOT_PREFIX}-${MACHINE}-${rev}-${ramc}.bin-${target} ${DEPLOYDIR}/${UBOOT_PREFIX}-encrypted-${MACHINE}-${rev}-${ramc}.bin-${target} - else - trustfence-sign-uboot.sh ${DEPLOYDIR}/${UBOOT_PREFIX}-${MACHINE}-${rev}-${ramc}.bin-${target} ${DEPLOYDIR}/${UBOOT_PREFIX}-signed-${MACHINE}-${rev}-${ramc}.bin-${target} + unset ENABLE_ENCRYPTION fi done done