Bill Richardson | 6f39615 | 2014-07-15 12:52:19 -0700 | [diff] [blame^] | 1 | /* Copyright 2011 The Chromium OS Authors. All rights reserved. |
Randall Spangler | dcab8fa | 2010-06-15 14:50:51 -0700 | [diff] [blame] | 2 | * Use of this source code is governed by a BSD-style license that can be |
| 3 | * found in the LICENSE file. |
| 4 | * |
| 5 | * Verified boot firmware utility |
| 6 | */ |
| 7 | |
| 8 | #include <getopt.h> |
| 9 | #include <inttypes.h> /* For PRIu64 */ |
| 10 | #include <stddef.h> |
| 11 | #include <stdio.h> |
| 12 | #include <stdlib.h> |
| 13 | #include <unistd.h> |
| 14 | |
| 15 | #include "cryptolib.h" |
Bill Richardson | 6f39615 | 2014-07-15 12:52:19 -0700 | [diff] [blame^] | 16 | #include "futility.h" |
Randall Spangler | dcab8fa | 2010-06-15 14:50:51 -0700 | [diff] [blame] | 17 | #include "host_common.h" |
| 18 | #include "kernel_blob.h" |
Bill Richardson | 7829902 | 2014-06-20 14:33:00 -0700 | [diff] [blame] | 19 | #include "util_misc.h" |
Randall Spangler | dcab8fa | 2010-06-15 14:50:51 -0700 | [diff] [blame] | 20 | #include "vboot_common.h" |
| 21 | |
| 22 | |
| 23 | /* Command line options */ |
| 24 | enum { |
| 25 | OPT_MODE_VBLOCK = 1000, |
| 26 | OPT_MODE_VERIFY, |
| 27 | OPT_KEYBLOCK, |
| 28 | OPT_SIGNPUBKEY, |
| 29 | OPT_SIGNPRIVATE, |
| 30 | OPT_VERSION, |
| 31 | OPT_FV, |
| 32 | OPT_KERNELKEY, |
Randall Spangler | a712e01 | 2011-07-13 09:48:41 -0700 | [diff] [blame] | 33 | OPT_FLAGS, |
Randall Spangler | dcab8fa | 2010-06-15 14:50:51 -0700 | [diff] [blame] | 34 | }; |
| 35 | |
| 36 | static struct option long_opts[] = { |
| 37 | {"vblock", 1, 0, OPT_MODE_VBLOCK }, |
| 38 | {"verify", 1, 0, OPT_MODE_VERIFY }, |
| 39 | {"keyblock", 1, 0, OPT_KEYBLOCK }, |
| 40 | {"signpubkey", 1, 0, OPT_SIGNPUBKEY }, |
| 41 | {"signprivate", 1, 0, OPT_SIGNPRIVATE }, |
| 42 | {"version", 1, 0, OPT_VERSION }, |
| 43 | {"fv", 1, 0, OPT_FV }, |
| 44 | {"kernelkey", 1, 0, OPT_KERNELKEY }, |
Randall Spangler | a712e01 | 2011-07-13 09:48:41 -0700 | [diff] [blame] | 45 | {"flags", 1, 0, OPT_FLAGS }, |
Randall Spangler | dcab8fa | 2010-06-15 14:50:51 -0700 | [diff] [blame] | 46 | {NULL, 0, 0, 0} |
| 47 | }; |
| 48 | |
| 49 | |
| 50 | /* Print help and return error */ |
| 51 | static int PrintHelp(void) { |
| 52 | |
| 53 | puts("vbutil_firmware - Verified boot key block utility\n" |
| 54 | "\n" |
| 55 | "Usage: vbutil_firmware <--vblock|--verify> <file> [OPTIONS]\n" |
| 56 | "\n" |
| 57 | "For '--vblock <file>', required OPTIONS are:\n" |
| 58 | " --keyblock <file> Key block in .keyblock format\n" |
Randall Spangler | ceef83f | 2010-07-02 13:14:42 -0700 | [diff] [blame] | 59 | " --signprivate <file> Signing private key in .vbprivk format\n" |
Randall Spangler | dcab8fa | 2010-06-15 14:50:51 -0700 | [diff] [blame] | 60 | " --version <number> Firmware version\n" |
| 61 | " --fv <file> Firmware volume to sign\n" |
| 62 | " --kernelkey <file> Kernel subkey in .vbpubk format\n" |
Randall Spangler | a712e01 | 2011-07-13 09:48:41 -0700 | [diff] [blame] | 63 | "optional OPTIONS are:\n" |
| 64 | " --flags <number> Preamble flags (defaults to 0)\n" |
Randall Spangler | dcab8fa | 2010-06-15 14:50:51 -0700 | [diff] [blame] | 65 | "\n" |
| 66 | "For '--verify <file>', required OPTIONS are:\n" |
| 67 | " --signpubkey <file> Signing public key in .vbpubk format\n" |
| 68 | " --fv <file> Firmware volume to verify\n" |
Bill Richardson | 60bcbe3 | 2010-09-09 14:53:56 -0700 | [diff] [blame] | 69 | "\n" |
| 70 | "For '--verify <file>', optional OPTIONS are:\n" |
| 71 | " --kernelkey <file> Write the kernel subkey to this file\n" |
Randall Spangler | dcab8fa | 2010-06-15 14:50:51 -0700 | [diff] [blame] | 72 | ""); |
| 73 | return 1; |
| 74 | } |
| 75 | |
| 76 | |
| 77 | /* Create a firmware .vblock */ |
| 78 | static int Vblock(const char* outfile, const char* keyblock_file, |
| 79 | const char* signprivate, uint64_t version, |
Randall Spangler | a712e01 | 2011-07-13 09:48:41 -0700 | [diff] [blame] | 80 | const char* fv_file, const char* kernelkey_file, |
| 81 | uint32_t preamble_flags) { |
Randall Spangler | dcab8fa | 2010-06-15 14:50:51 -0700 | [diff] [blame] | 82 | |
| 83 | VbPrivateKey* signing_key; |
| 84 | VbPublicKey* kernel_subkey; |
| 85 | VbSignature* body_sig; |
| 86 | VbFirmwarePreambleHeader* preamble; |
| 87 | VbKeyBlockHeader* key_block; |
| 88 | uint64_t key_block_size; |
| 89 | uint8_t* fv_data; |
| 90 | uint64_t fv_size; |
| 91 | FILE* f; |
| 92 | uint64_t i; |
| 93 | |
| 94 | if (!outfile) { |
Randall Spangler | 32a6526 | 2011-06-27 10:49:11 -0700 | [diff] [blame] | 95 | VbExError("Must specify output filename\n"); |
Randall Spangler | dcab8fa | 2010-06-15 14:50:51 -0700 | [diff] [blame] | 96 | return 1; |
| 97 | } |
| 98 | if (!keyblock_file || !signprivate || !kernelkey_file) { |
Randall Spangler | 32a6526 | 2011-06-27 10:49:11 -0700 | [diff] [blame] | 99 | VbExError("Must specify all keys\n"); |
Randall Spangler | dcab8fa | 2010-06-15 14:50:51 -0700 | [diff] [blame] | 100 | return 1; |
| 101 | } |
| 102 | if (!fv_file) { |
Randall Spangler | 32a6526 | 2011-06-27 10:49:11 -0700 | [diff] [blame] | 103 | VbExError("Must specify firmware volume\n"); |
Randall Spangler | dcab8fa | 2010-06-15 14:50:51 -0700 | [diff] [blame] | 104 | return 1; |
| 105 | } |
| 106 | |
| 107 | /* Read the key block and keys */ |
| 108 | key_block = (VbKeyBlockHeader*)ReadFile(keyblock_file, &key_block_size); |
| 109 | if (!key_block) { |
Randall Spangler | 32a6526 | 2011-06-27 10:49:11 -0700 | [diff] [blame] | 110 | VbExError("Error reading key block.\n"); |
Randall Spangler | dcab8fa | 2010-06-15 14:50:51 -0700 | [diff] [blame] | 111 | return 1; |
| 112 | } |
| 113 | |
Randall Spangler | ceef83f | 2010-07-02 13:14:42 -0700 | [diff] [blame] | 114 | signing_key = PrivateKeyRead(signprivate); |
Randall Spangler | dcab8fa | 2010-06-15 14:50:51 -0700 | [diff] [blame] | 115 | if (!signing_key) { |
Randall Spangler | 32a6526 | 2011-06-27 10:49:11 -0700 | [diff] [blame] | 116 | VbExError("Error reading signing key.\n"); |
Randall Spangler | dcab8fa | 2010-06-15 14:50:51 -0700 | [diff] [blame] | 117 | return 1; |
| 118 | } |
| 119 | |
| 120 | kernel_subkey = PublicKeyRead(kernelkey_file); |
| 121 | if (!kernel_subkey) { |
Randall Spangler | 32a6526 | 2011-06-27 10:49:11 -0700 | [diff] [blame] | 122 | VbExError("Error reading kernel subkey.\n"); |
Randall Spangler | dcab8fa | 2010-06-15 14:50:51 -0700 | [diff] [blame] | 123 | return 1; |
| 124 | } |
| 125 | |
| 126 | /* Read and sign the firmware volume */ |
| 127 | fv_data = ReadFile(fv_file, &fv_size); |
| 128 | if (!fv_data) |
| 129 | return 1; |
| 130 | if (!fv_size) { |
Randall Spangler | 32a6526 | 2011-06-27 10:49:11 -0700 | [diff] [blame] | 131 | VbExError("Empty firmware volume file\n"); |
Randall Spangler | dcab8fa | 2010-06-15 14:50:51 -0700 | [diff] [blame] | 132 | return 1; |
| 133 | } |
| 134 | body_sig = CalculateSignature(fv_data, fv_size, signing_key); |
| 135 | if (!body_sig) { |
Randall Spangler | 32a6526 | 2011-06-27 10:49:11 -0700 | [diff] [blame] | 136 | VbExError("Error calculating body signature\n"); |
Randall Spangler | dcab8fa | 2010-06-15 14:50:51 -0700 | [diff] [blame] | 137 | return 1; |
| 138 | } |
Randall Spangler | 32a6526 | 2011-06-27 10:49:11 -0700 | [diff] [blame] | 139 | free(fv_data); |
Randall Spangler | dcab8fa | 2010-06-15 14:50:51 -0700 | [diff] [blame] | 140 | |
| 141 | /* Create preamble */ |
| 142 | preamble = CreateFirmwarePreamble(version, |
| 143 | kernel_subkey, |
| 144 | body_sig, |
Randall Spangler | a712e01 | 2011-07-13 09:48:41 -0700 | [diff] [blame] | 145 | signing_key, |
| 146 | preamble_flags); |
Randall Spangler | dcab8fa | 2010-06-15 14:50:51 -0700 | [diff] [blame] | 147 | if (!preamble) { |
Randall Spangler | 32a6526 | 2011-06-27 10:49:11 -0700 | [diff] [blame] | 148 | VbExError("Error creating preamble.\n"); |
Randall Spangler | dcab8fa | 2010-06-15 14:50:51 -0700 | [diff] [blame] | 149 | return 1; |
| 150 | } |
| 151 | |
| 152 | /* Write the output file */ |
| 153 | f = fopen(outfile, "wb"); |
| 154 | if (!f) { |
Randall Spangler | 32a6526 | 2011-06-27 10:49:11 -0700 | [diff] [blame] | 155 | VbExError("Can't open output file %s\n", outfile); |
Randall Spangler | dcab8fa | 2010-06-15 14:50:51 -0700 | [diff] [blame] | 156 | return 1; |
| 157 | } |
| 158 | i = ((1 != fwrite(key_block, key_block_size, 1, f)) || |
| 159 | (1 != fwrite(preamble, preamble->preamble_size, 1, f))); |
| 160 | fclose(f); |
| 161 | if (i) { |
Randall Spangler | 32a6526 | 2011-06-27 10:49:11 -0700 | [diff] [blame] | 162 | VbExError("Can't write output file %s\n", outfile); |
Randall Spangler | dcab8fa | 2010-06-15 14:50:51 -0700 | [diff] [blame] | 163 | unlink(outfile); |
| 164 | return 1; |
| 165 | } |
| 166 | |
| 167 | /* Success */ |
| 168 | return 0; |
| 169 | } |
| 170 | |
Randall Spangler | dcab8fa | 2010-06-15 14:50:51 -0700 | [diff] [blame] | 171 | static int Verify(const char* infile, const char* signpubkey, |
Bill Richardson | 60bcbe3 | 2010-09-09 14:53:56 -0700 | [diff] [blame] | 172 | const char* fv_file, const char* kernelkey_file) { |
Randall Spangler | dcab8fa | 2010-06-15 14:50:51 -0700 | [diff] [blame] | 173 | |
| 174 | VbKeyBlockHeader* key_block; |
| 175 | VbFirmwarePreambleHeader* preamble; |
| 176 | VbPublicKey* data_key; |
| 177 | VbPublicKey* sign_key; |
Bill Richardson | 60bcbe3 | 2010-09-09 14:53:56 -0700 | [diff] [blame] | 178 | VbPublicKey* kernel_subkey; |
Randall Spangler | dcab8fa | 2010-06-15 14:50:51 -0700 | [diff] [blame] | 179 | RSAPublicKey* rsa; |
| 180 | uint8_t* blob; |
| 181 | uint64_t blob_size; |
| 182 | uint8_t* fv_data; |
| 183 | uint64_t fv_size; |
| 184 | uint64_t now = 0; |
Tom Wai-Hong Tam | efea801 | 2011-08-22 18:45:31 +0800 | [diff] [blame] | 185 | uint32_t flags; |
Randall Spangler | dcab8fa | 2010-06-15 14:50:51 -0700 | [diff] [blame] | 186 | |
| 187 | if (!infile || !signpubkey || !fv_file) { |
Randall Spangler | 32a6526 | 2011-06-27 10:49:11 -0700 | [diff] [blame] | 188 | VbExError("Must specify filename, signpubkey, and fv\n"); |
Randall Spangler | dcab8fa | 2010-06-15 14:50:51 -0700 | [diff] [blame] | 189 | return 1; |
| 190 | } |
| 191 | |
| 192 | /* Read public signing key */ |
| 193 | sign_key = PublicKeyRead(signpubkey); |
| 194 | if (!sign_key) { |
Randall Spangler | 32a6526 | 2011-06-27 10:49:11 -0700 | [diff] [blame] | 195 | VbExError("Error reading signpubkey.\n"); |
Randall Spangler | dcab8fa | 2010-06-15 14:50:51 -0700 | [diff] [blame] | 196 | return 1; |
| 197 | } |
| 198 | |
| 199 | /* Read blob */ |
| 200 | blob = ReadFile(infile, &blob_size); |
| 201 | if (!blob) { |
Randall Spangler | 32a6526 | 2011-06-27 10:49:11 -0700 | [diff] [blame] | 202 | VbExError("Error reading input file\n"); |
Randall Spangler | dcab8fa | 2010-06-15 14:50:51 -0700 | [diff] [blame] | 203 | return 1; |
| 204 | } |
| 205 | |
| 206 | /* Read firmware volume */ |
| 207 | fv_data = ReadFile(fv_file, &fv_size); |
| 208 | if (!fv_data) { |
Randall Spangler | 32a6526 | 2011-06-27 10:49:11 -0700 | [diff] [blame] | 209 | VbExError("Error reading firmware volume\n"); |
Randall Spangler | dcab8fa | 2010-06-15 14:50:51 -0700 | [diff] [blame] | 210 | return 1; |
| 211 | } |
| 212 | |
| 213 | /* Verify key block */ |
| 214 | key_block = (VbKeyBlockHeader*)blob; |
Randall Spangler | 138acfe | 2010-08-17 15:45:21 -0700 | [diff] [blame] | 215 | if (0 != KeyBlockVerify(key_block, blob_size, sign_key, 0)) { |
Randall Spangler | 32a6526 | 2011-06-27 10:49:11 -0700 | [diff] [blame] | 216 | VbExError("Error verifying key block.\n"); |
Randall Spangler | dcab8fa | 2010-06-15 14:50:51 -0700 | [diff] [blame] | 217 | return 1; |
| 218 | } |
Randall Spangler | 32a6526 | 2011-06-27 10:49:11 -0700 | [diff] [blame] | 219 | free(sign_key); |
Randall Spangler | dcab8fa | 2010-06-15 14:50:51 -0700 | [diff] [blame] | 220 | now += key_block->key_block_size; |
| 221 | |
| 222 | printf("Key block:\n"); |
| 223 | data_key = &key_block->data_key; |
| 224 | printf(" Size: %" PRIu64 "\n", key_block->key_block_size); |
Bill Richardson | 60bcbe3 | 2010-09-09 14:53:56 -0700 | [diff] [blame] | 225 | printf(" Flags: %" PRIu64 " (ignored)\n", |
| 226 | key_block->key_block_flags); |
Randall Spangler | dcab8fa | 2010-06-15 14:50:51 -0700 | [diff] [blame] | 227 | printf(" Data key algorithm: %" PRIu64 " %s\n", data_key->algorithm, |
| 228 | (data_key->algorithm < kNumAlgorithms ? |
| 229 | algo_strings[data_key->algorithm] : "(invalid)")); |
| 230 | printf(" Data key version: %" PRIu64 "\n", data_key->key_version); |
Bill Richardson | 60bcbe3 | 2010-09-09 14:53:56 -0700 | [diff] [blame] | 231 | printf(" Data key sha1sum: "); |
| 232 | PrintPubKeySha1Sum(data_key); |
| 233 | printf("\n"); |
Randall Spangler | dcab8fa | 2010-06-15 14:50:51 -0700 | [diff] [blame] | 234 | |
| 235 | rsa = PublicKeyToRSA(&key_block->data_key); |
| 236 | if (!rsa) { |
Randall Spangler | 32a6526 | 2011-06-27 10:49:11 -0700 | [diff] [blame] | 237 | VbExError("Error parsing data key.\n"); |
Randall Spangler | dcab8fa | 2010-06-15 14:50:51 -0700 | [diff] [blame] | 238 | return 1; |
| 239 | } |
| 240 | |
| 241 | /* Verify preamble */ |
| 242 | preamble = (VbFirmwarePreambleHeader*)(blob + now); |
Randall Spangler | 87c13d8 | 2010-07-19 10:35:40 -0700 | [diff] [blame] | 243 | if (0 != VerifyFirmwarePreamble(preamble, blob_size - now, rsa)) { |
Randall Spangler | 32a6526 | 2011-06-27 10:49:11 -0700 | [diff] [blame] | 244 | VbExError("Error verifying preamble.\n"); |
Randall Spangler | dcab8fa | 2010-06-15 14:50:51 -0700 | [diff] [blame] | 245 | return 1; |
| 246 | } |
| 247 | now += preamble->preamble_size; |
| 248 | |
Tom Wai-Hong Tam | efea801 | 2011-08-22 18:45:31 +0800 | [diff] [blame] | 249 | flags = VbGetFirmwarePreambleFlags(preamble); |
Randall Spangler | dcab8fa | 2010-06-15 14:50:51 -0700 | [diff] [blame] | 250 | printf("Preamble:\n"); |
| 251 | printf(" Size: %" PRIu64 "\n", preamble->preamble_size); |
| 252 | printf(" Header version: %" PRIu32 ".%" PRIu32"\n", |
| 253 | preamble->header_version_major, preamble->header_version_minor); |
| 254 | printf(" Firmware version: %" PRIu64 "\n", preamble->firmware_version); |
Bill Richardson | 60bcbe3 | 2010-09-09 14:53:56 -0700 | [diff] [blame] | 255 | kernel_subkey = &preamble->kernel_subkey; |
Randall Spangler | dcab8fa | 2010-06-15 14:50:51 -0700 | [diff] [blame] | 256 | printf(" Kernel key algorithm: %" PRIu64 " %s\n", |
Bill Richardson | 60bcbe3 | 2010-09-09 14:53:56 -0700 | [diff] [blame] | 257 | kernel_subkey->algorithm, |
| 258 | (kernel_subkey->algorithm < kNumAlgorithms ? |
| 259 | algo_strings[kernel_subkey->algorithm] : "(invalid)")); |
Randall Spangler | dcab8fa | 2010-06-15 14:50:51 -0700 | [diff] [blame] | 260 | printf(" Kernel key version: %" PRIu64 "\n", |
Bill Richardson | 60bcbe3 | 2010-09-09 14:53:56 -0700 | [diff] [blame] | 261 | kernel_subkey->key_version); |
| 262 | printf(" Kernel key sha1sum: "); |
| 263 | PrintPubKeySha1Sum(kernel_subkey); |
| 264 | printf("\n"); |
Randall Spangler | dcab8fa | 2010-06-15 14:50:51 -0700 | [diff] [blame] | 265 | printf(" Firmware body size: %" PRIu64 "\n", |
| 266 | preamble->body_signature.data_size); |
Tom Wai-Hong Tam | efea801 | 2011-08-22 18:45:31 +0800 | [diff] [blame] | 267 | printf(" Preamble flags: %" PRIu32 "\n", flags); |
Randall Spangler | dcab8fa | 2010-06-15 14:50:51 -0700 | [diff] [blame] | 268 | |
| 269 | /* TODO: verify body size same as signature size */ |
| 270 | |
| 271 | /* Verify body */ |
Tom Wai-Hong Tam | efea801 | 2011-08-22 18:45:31 +0800 | [diff] [blame] | 272 | if (flags & VB_FIRMWARE_PREAMBLE_USE_RO_NORMAL) { |
| 273 | printf("Preamble requests USE_RO_NORMAL; skipping body verification.\n"); |
| 274 | } else { |
| 275 | if (0 != VerifyData(fv_data, fv_size, &preamble->body_signature, rsa)) { |
| 276 | VbExError("Error verifying firmware body.\n"); |
| 277 | return 1; |
| 278 | } |
| 279 | printf("Body verification succeeded.\n"); |
Randall Spangler | dcab8fa | 2010-06-15 14:50:51 -0700 | [diff] [blame] | 280 | } |
Bill Richardson | 60bcbe3 | 2010-09-09 14:53:56 -0700 | [diff] [blame] | 281 | |
| 282 | if (kernelkey_file) { |
| 283 | if (0 != PublicKeyWrite(kernelkey_file, kernel_subkey)) { |
| 284 | fprintf(stderr, |
| 285 | "vbutil_firmware: unable to write kernel subkey\n"); |
| 286 | return 1; |
| 287 | } |
| 288 | } |
| 289 | |
Randall Spangler | dcab8fa | 2010-06-15 14:50:51 -0700 | [diff] [blame] | 290 | return 0; |
| 291 | } |
| 292 | |
| 293 | |
Bill Richardson | 6f39615 | 2014-07-15 12:52:19 -0700 | [diff] [blame^] | 294 | int do_vbutil_firmware(int argc, char* argv[]) { |
Randall Spangler | dcab8fa | 2010-06-15 14:50:51 -0700 | [diff] [blame] | 295 | |
| 296 | char* filename = NULL; |
| 297 | char* key_block_file = NULL; |
| 298 | char* signpubkey = NULL; |
| 299 | char* signprivate = NULL; |
| 300 | uint64_t version = 0; |
| 301 | char* fv_file = NULL; |
| 302 | char* kernelkey_file = NULL; |
Randall Spangler | a712e01 | 2011-07-13 09:48:41 -0700 | [diff] [blame] | 303 | uint32_t preamble_flags = 0; |
Randall Spangler | dcab8fa | 2010-06-15 14:50:51 -0700 | [diff] [blame] | 304 | int mode = 0; |
| 305 | int parse_error = 0; |
| 306 | char* e; |
| 307 | int i; |
| 308 | |
| 309 | while ((i = getopt_long(argc, argv, "", long_opts, NULL)) != -1) { |
| 310 | switch (i) { |
| 311 | case '?': |
| 312 | /* Unhandled option */ |
| 313 | printf("Unknown option\n"); |
| 314 | parse_error = 1; |
| 315 | break; |
| 316 | |
| 317 | case OPT_MODE_VBLOCK: |
| 318 | case OPT_MODE_VERIFY: |
| 319 | mode = i; |
| 320 | filename = optarg; |
| 321 | break; |
| 322 | |
| 323 | case OPT_KEYBLOCK: |
| 324 | key_block_file = optarg; |
| 325 | break; |
| 326 | |
| 327 | case OPT_SIGNPUBKEY: |
| 328 | signpubkey = optarg; |
| 329 | break; |
| 330 | |
| 331 | case OPT_SIGNPRIVATE: |
| 332 | signprivate = optarg; |
| 333 | break; |
| 334 | |
| 335 | case OPT_FV: |
| 336 | fv_file = optarg; |
| 337 | break; |
| 338 | |
| 339 | case OPT_KERNELKEY: |
| 340 | kernelkey_file = optarg; |
| 341 | break; |
| 342 | |
| 343 | case OPT_VERSION: |
| 344 | version = strtoul(optarg, &e, 0); |
| 345 | if (!*optarg || (e && *e)) { |
| 346 | printf("Invalid --version\n"); |
| 347 | parse_error = 1; |
| 348 | } |
| 349 | break; |
Randall Spangler | a712e01 | 2011-07-13 09:48:41 -0700 | [diff] [blame] | 350 | |
| 351 | case OPT_FLAGS: |
| 352 | preamble_flags = strtoul(optarg, &e, 0); |
| 353 | if (!*optarg || (e && *e)) { |
| 354 | printf("Invalid --flags\n"); |
| 355 | parse_error = 1; |
| 356 | } |
| 357 | break; |
Randall Spangler | dcab8fa | 2010-06-15 14:50:51 -0700 | [diff] [blame] | 358 | } |
| 359 | } |
| 360 | |
| 361 | if (parse_error) |
| 362 | return PrintHelp(); |
| 363 | |
| 364 | switch(mode) { |
| 365 | case OPT_MODE_VBLOCK: |
| 366 | return Vblock(filename, key_block_file, signprivate, version, fv_file, |
Randall Spangler | a712e01 | 2011-07-13 09:48:41 -0700 | [diff] [blame] | 367 | kernelkey_file, preamble_flags); |
Randall Spangler | dcab8fa | 2010-06-15 14:50:51 -0700 | [diff] [blame] | 368 | case OPT_MODE_VERIFY: |
Bill Richardson | 60bcbe3 | 2010-09-09 14:53:56 -0700 | [diff] [blame] | 369 | return Verify(filename, signpubkey, fv_file, kernelkey_file); |
Randall Spangler | dcab8fa | 2010-06-15 14:50:51 -0700 | [diff] [blame] | 370 | default: |
| 371 | printf("Must specify a mode.\n"); |
| 372 | return PrintHelp(); |
| 373 | } |
| 374 | } |
Bill Richardson | 6f39615 | 2014-07-15 12:52:19 -0700 | [diff] [blame^] | 375 | |
| 376 | DECLARE_FUTIL_COMMAND(vbutil_firmware, do_vbutil_firmware, |
| 377 | "Verified boot firmware utility"); |