Attention is currently required from: Matt DeVillier, Paul Menzel, Arthur Heymans. Leah Rowe has posted comments on this change. ( https://review.coreboot.org/c/coreboot/+/51168 )
Change subject: util/chromeos: Verify sha1sums of downloaded recovery images ......................................................................
Patch Set 1:
(3 comments)
File util/chromeos/crosfirmware.sh:
https://review.coreboot.org/c/coreboot/+/51168/comment/4a42e1c8_0008e200 PS1, Line 51: sha1_list="$(grep sha1 ${_cfgfile} | sed 's/sha1=//g')"
Why check against all sha1sums and not just the one for the board you need?
Because the way the inventory is structured, there's no way to reliably do that. So I currently make an assumption that google always has the correct sha1sum defined for each image.
With that assumption in mind, the logic works just fine.
https://review.coreboot.org/c/coreboot/+/51168/comment/e575d939_34f0dfad PS1, Line 138:
Please remove.
done
https://review.coreboot.org/c/coreboot/+/51168/comment/58f463c6_196287ef PS1, Line 168:
Please remove.
done