Hi,

On 9/24/26 19:59, Thomas Bonnefille wrote:
> The cmdline parameter of the fitimage is an additional optional property
> in a configuration node that is used to transmit information to the next
> bootstage.
> Just like description, compatible and default, this property doesn't
> reference an image (e.g. a kernel, a ramdisk or an fdt) and so it isn't
> hashed and shouldn't be added to the list of hashed images.

While the content of the patch is correct, this sentence isn't completely:
The property is being hashed (otherwise it would be a glaring security hole),
but it's not hashed as an image, meaning its content isn't resolved to a node.

I'll Cc you on an amend! commit to clarify this.

Thanks,
Ahmad

> Add `cmdline` to the whitelist of property in a configuration node that
> aren't images.
> 
> Signed-off-by: Thomas Bonnefille <[email protected]>
> ---
>  common/image-fit.c | 1 +
>  1 file changed, 1 insertion(+)
> 
> diff --git a/common/image-fit.c b/common/image-fit.c
> index 635f63c9e2..cd477911cc 100644
> --- a/common/image-fit.c
> +++ b/common/image-fit.c
> @@ -333,6 +333,7 @@ static int fit_config_build_hash_nodes(struct fit_handle 
> *handle,
>       for_each_property_of_node(conf_node, prop) {
>               if (!strcmp(prop->name, "description") ||
>                   !strcmp(prop->name, "compatible") ||
> +                 !strcmp(prop->name, "cmdline") ||
>                   !strcmp(prop->name, "default"))
>                       continue;
>  
> 


-- 
Pengutronix e.K.                           |                             |
Steuerwalder Str. 21                       | http://www.pengutronix.de/  |
31137 Hildesheim, Germany                  | Phone: +49-5121-206917-0    |
Amtsgericht Hildesheim, HRA 2686           | Fax:   +49-5121-206917-5555 |

Reply via email to