commit | 41839cdb8ee74d5fe69794d615b6f940c3f2c5c3 | [log] [tgz] |
---|---|---|
author | Catherine Vlasov <cvlasov@google.com> | Thu Nov 28 17:47:08 2024 +0000 |
committer | Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com> | Thu Nov 28 17:47:08 2024 +0000 |
tree | dd269bd23d9a579f0c121c88f23467c0e476fbf5 | |
parent | 2fc4516466fbce7a7aab35d3cc87c5f8530bf551 [diff] | |
parent | 9caca7e7f071cf86233bd565c3932eb1f50eb8b2 [diff] |
Specify the expected contents of "verifiedBootKey". am: 9caca7e7f0 Original change: https://android-review.googlesource.com/c/platform/hardware/interfaces/+/3359914 Change-Id: I29b3412e6e18d2817741674c45d3984e0afd588a Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
diff --git a/security/keymint/aidl/android/hardware/security/keymint/KeyCreationResult.aidl b/security/keymint/aidl/android/hardware/security/keymint/KeyCreationResult.aidl index eb9d83d..2d2f307 100644 --- a/security/keymint/aidl/android/hardware/security/keymint/KeyCreationResult.aidl +++ b/security/keymint/aidl/android/hardware/security/keymint/KeyCreationResult.aidl
@@ -153,6 +153,9 @@ * } * * RootOfTrust ::= SEQUENCE { + * -- verifiedBootKey must contain a SHA-256 digest of the public key embedded in the + * -- "vbmeta" partition if the device's bootloader is locked, or 32 bytes of zeroes if the + * -- device's bootloader is unlocked. * verifiedBootKey OCTET_STRING, * deviceLocked BOOLEAN, * verifiedBootState VerifiedBootState,