Fix for multi-sign
The new Tianocore multi-sign code fails now for images signed with sbsigntools. The reason is that we don't actually align the signature table, we just slap it straight after the binary data. Unfortunately, the new multi-signature code checks that our alignment offsets are correct and fails the signature for this reason. Fix by adding junk to the end of the image to align the signature section. Signed-off-by: James Bottomley <JBottomley@Parallels.com>
This commit is contained in:
parent
b963c5cb38
commit
592ec2188f
1 changed files with 7 additions and 1 deletions
|
@ -385,7 +385,13 @@ static int image_find_regions(struct image *image)
|
|||
|
||||
/* record the size of non-signature data */
|
||||
r = &image->checksum_regions[image->n_checksum_regions - 1];
|
||||
image->data_size = (r->data - (void *)image->buf) + r->size;
|
||||
/*
|
||||
* The new Tianocore multisign does a stricter check of the signatures
|
||||
* in particular, the signature table must start at an aligned offset
|
||||
* fix this by adding bytes to the end of the text section (which must
|
||||
* be included in the hash)
|
||||
*/
|
||||
image->data_size = align_up((r->data - (void *)image->buf) + r->size, 8);
|
||||
|
||||
return 0;
|
||||
}
|
||||
|
|
Loading…
Reference in a new issue