signer: update legacy bootloader templates after image signing

Specifically, this patch updates 'root_hexdigest' in legacy bootloader
templates in EFI system partition to match the signed rootfs.

TEST=Ran locally and booted the image on kvm
(using BIOS).
TEST=Ran by locally changing vboot_stable_hash to
include this patch.

$ ./ base chromiumos_base_image.bin \
  ../../tests/devkeys chromiumos_base_image_signed.bin

Change-Id: Ied021c4464b113a64508f5081605069bdcecbc1f
Commit-Ready: Amey Deshpande <>
Tested-by: Amey Deshpande <>
Reviewed-by: Mike Frysinger <>
2 files changed