@@ -292,7 +292,6 @@ bootutil_img_hash(struct boot_loader_state *state,
292
292
# define KEY_BUF_SIZE (SIG_BUF_SIZE + 24)
293
293
#endif /* !MCUBOOT_HW_KEY */
294
294
295
- #if !defined(CONFIG_BOOT_SIGNATURE_USING_KMU )
296
295
#if !defined(MCUBOOT_HW_KEY )
297
296
static int
298
297
bootutil_find_key (uint8_t * keyhash , uint8_t keyhash_len )
@@ -361,7 +360,6 @@ bootutil_find_key(uint8_t image_index, uint8_t *key, uint16_t key_len)
361
360
}
362
361
#endif /* !MCUBOOT_HW_KEY */
363
362
#endif /* !MCUBOOT_BUILTIN_KEY */
364
- #endif /* !defined(CONFIG_BOOT_SIGNATURE_USING_KMU) */
365
363
#endif /* EXPECTED_SIG_TLV */
366
364
367
365
/**
@@ -734,7 +732,6 @@ bootutil_img_validate(struct boot_loader_state *state,
734
732
break ;
735
733
}
736
734
#endif /* defined(EXPECTED_HASH_TLV) && !defined(MCUBOOT_SIGN_PURE) */
737
- #if !defined(CONFIG_BOOT_SIGNATURE_USING_KMU )
738
735
#ifdef EXPECTED_KEY_TLV
739
736
case EXPECTED_KEY_TLV :
740
737
{
@@ -766,18 +763,15 @@ bootutil_img_validate(struct boot_loader_state *state,
766
763
break ;
767
764
}
768
765
#endif /* EXPECTED_KEY_TLV */
769
- #endif /* !defined(CONFIG_BOOT_SIGNATURE_USING_KMU) */
770
766
#ifdef EXPECTED_SIG_TLV
771
767
case EXPECTED_SIG_TLV :
772
768
{
773
769
BOOT_LOG_DBG ("bootutil_img_validate: EXPECTED_SIG_TLV == %d" , EXPECTED_SIG_TLV );
774
- #if !defined(CONFIG_BOOT_SIGNATURE_USING_KMU )
775
770
/* Ignore this signature if it is out of bounds. */
776
771
if (key_id < 0 || key_id >= bootutil_key_cnt ) {
777
772
key_id = -1 ;
778
773
continue ;
779
774
}
780
- #endif /* !defined(CONFIG_BOOT_SIGNATURE_USING_KMU) */
781
775
if (!EXPECTED_SIG_LEN (len ) || len > sizeof (buf )) {
782
776
rc = -1 ;
783
777
goto out ;
@@ -952,7 +946,7 @@ bootutil_img_validate(struct boot_loader_state *state,
952
946
}
953
947
954
948
#ifdef EXPECTED_SIG_TLV
955
- #if !defined( CONFIG_BOOT_SIGNATURE_USING_KMU ) && defined( EXPECTED_KEY_TLV )
949
+ #ifdef EXPECTED_KEY_TLV
956
950
rc = bootutil_tlv_iter_begin (& it , hdr , fap , EXPECTED_KEY_TLV , false);
957
951
if (rc ) {
958
952
goto out ;
@@ -998,7 +992,7 @@ bootutil_img_validate(struct boot_loader_state *state,
998
992
*/
999
993
}
1000
994
}
1001
- #endif /* !CONFIG_BOOT_SIGNATURE_USING_KMU && EXPECTED_KEY_TLV */
995
+ #endif /* EXPECTED_KEY_TLV */
1002
996
1003
997
rc = bootutil_tlv_iter_begin (& it , hdr , fap , IMAGE_TLV_DECOMP_SIGNATURE , true);
1004
998
if (rc ) {
@@ -1021,12 +1015,10 @@ bootutil_img_validate(struct boot_loader_state *state,
1021
1015
1022
1016
if (type == IMAGE_TLV_DECOMP_SIGNATURE ) {
1023
1017
/* Ignore this signature if it is out of bounds. */
1024
- #if !defined(CONFIG_BOOT_SIGNATURE_USING_KMU )
1025
1018
if (key_id < 0 || key_id >= bootutil_key_cnt ) {
1026
1019
key_id = -1 ;
1027
1020
continue ;
1028
1021
}
1029
- #endif
1030
1022
1031
1023
if (!EXPECTED_SIG_LEN (len ) || len > sizeof (buf )) {
1032
1024
rc = -1 ;
0 commit comments