summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorJack Neus <jackneus@google.com>2021-09-07 22:06:38 +0000
committerGeorge Engelbrecht <engeg@google.com>2021-09-07 22:08:17 +0000
commitaa06c4f7d328b78ef848fe3631b6364f69b674fe (patch)
treea4d207b353700c4eb82bd1f0d02267ae76da79d2
parent1376cfbfdd3b0cbc14da190c744604c4f3d29a23 (diff)
downloadvboot-aa06c4f7d328b78ef848fe3631b6364f69b674fe.tar.gz
Revert "reven signing: skip install_gsetup_certs"
This reverts commit 1376cfbfdd3b0cbc14da190c744604c4f3d29a23. Reason for revert: bad code (missing [[) Original change's description: > reven signing: skip install_gsetup_certs > > BUG=b:199136347,b:194500280 > TEST=none > BRANCH=none > > Change-Id: Iba90c1f4dcc2fadf9cbadac1948d5037b0feb278 > Signed-off-by: Jack Neus <jackneus@google.com> > Reviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform/vboot_reference/+/3145774 > Reviewed-by: George Engelbrecht <engeg@google.com> Bug: b:199136347,b:194500280 Change-Id: I9b1df358a18d043eb0d20d18ed17e1bafbd9e5f3 Reviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform/vboot_reference/+/3146076 Auto-Submit: Jack Neus <jackneus@google.com> Commit-Queue: Rubber Stamper <rubber-stamper@appspot.gserviceaccount.com> Commit-Queue: George Engelbrecht <engeg@google.com> Bot-Commit: Rubber Stamper <rubber-stamper@appspot.gserviceaccount.com> Reviewed-by: George Engelbrecht <engeg@google.com> Tested-by: George Engelbrecht <engeg@google.com> Tested-by: Jack Neus <jackneus@google.com>
-rwxr-xr-xscripts/image_signing/sign_official_build.sh9
1 files changed, 2 insertions, 7 deletions
diff --git a/scripts/image_signing/sign_official_build.sh b/scripts/image_signing/sign_official_build.sh
index 700da038..bb8d69d4 100755
--- a/scripts/image_signing/sign_official_build.sh
+++ b/scripts/image_signing/sign_official_build.sh
@@ -709,7 +709,6 @@ resign_android_image_if_exists() {
# Args: LOOPDEV
sign_uefi_binaries() {
local loopdev="$1"
- local kerna_config="$2"
if [[ ! -d "${KEY_DIR}/uefi" ]]; then
return 0
@@ -722,11 +721,7 @@ sign_uefi_binaries() {
elif [[ -z "${esp_dir}" ]]; then
return 0
fi
- # The reven board has a special signing flow. If this flag is set, don't
- # invoke install_gsetup_certs.sh.
- if " ${kerna_config} " != *" cros_reven "* ]]; then
- "${SCRIPT_DIR}/install_gsetup_certs.sh" "${esp_dir}" "${KEY_DIR}/uefi"
- fi
+ "${SCRIPT_DIR}/install_gsetup_certs.sh" "${esp_dir}" "${KEY_DIR}/uefi"
"${SCRIPT_DIR}/sign_uefi.sh" "${esp_dir}" "${KEY_DIR}/uefi"
sudo umount "${esp_dir}"
@@ -1021,7 +1016,7 @@ sign_image_file() {
resign_firmware_payload "${loopdev}"
remove_old_container_key "${loopdev}"
resign_android_image_if_exists "${loopdev}"
- sign_uefi_binaries "${loopdev}" "${kerna_config}"
+ sign_uefi_binaries "${loopdev}"
# We do NOT strip /boot for factory installer, since some devices need it to
# boot EFI. crbug.com/260512 would obsolete this requirement.
#