From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-10.8 required=3.0 tests=BAYES_00,DKIM_SIGNED, DKIM_VALID,DKIM_VALID_AU,FREEMAIL_FORGED_FROMDOMAIN,FREEMAIL_FROM, HEADER_FROM_DIFFERENT_DOMAINS,INCLUDES_PATCH,MAILING_LIST_MULTI,SPF_HELO_NONE, SPF_PASS,USER_AGENT_GIT autolearn=ham autolearn_force=no version=3.4.0 Received: from mail.kernel.org (mail.kernel.org [198.145.29.99]) by smtp.lore.kernel.org (Postfix) with ESMTP id 38CDFC433F5 for ; Tue, 7 Sep 2021 17:07:27 +0000 (UTC) Received: from phobos.denx.de (phobos.denx.de [85.214.62.61]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by mail.kernel.org (Postfix) with ESMTPS id 1F35A60187 for ; Tue, 7 Sep 2021 17:07:25 +0000 (UTC) DMARC-Filter: OpenDMARC Filter v1.4.1 mail.kernel.org 1F35A60187 Authentication-Results: mail.kernel.org; dmarc=fail (p=none dis=none) header.from=gmail.com Authentication-Results: mail.kernel.org; spf=pass smtp.mailfrom=lists.denx.de Received: from h2850616.stratoserver.net (localhost [IPv6:::1]) by phobos.denx.de (Postfix) with ESMTP id EA34982D3C; Tue, 7 Sep 2021 19:07:21 +0200 (CEST) Authentication-Results: phobos.denx.de; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: phobos.denx.de; spf=pass smtp.mailfrom=u-boot-bounces@lists.denx.de Authentication-Results: phobos.denx.de; dkim=pass (2048-bit key; unprotected) header.d=gmail.com header.i=@gmail.com header.b="GDm85oBH"; dkim-atps=neutral Received: by phobos.denx.de (Postfix, from userid 109) id B2838832B7; Tue, 7 Sep 2021 19:07:18 +0200 (CEST) Received: from mail-ot1-x32f.google.com (mail-ot1-x32f.google.com [IPv6:2607:f8b0:4864:20::32f]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits)) (No client certificate requested) by phobos.denx.de (Postfix) with ESMTPS id AE89582C30 for ; Tue, 7 Sep 2021 19:07:13 +0200 (CEST) Authentication-Results: phobos.denx.de; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: phobos.denx.de; spf=pass smtp.mailfrom=mr.nuke.me@gmail.com Received: by mail-ot1-x32f.google.com with SMTP id a20-20020a0568300b9400b0051b8ca82dfcso13622577otv.3 for ; Tue, 07 Sep 2021 10:07:13 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20210112; h=from:to:cc:subject:date:message-id:mime-version :content-transfer-encoding; bh=xNzqAsjFA4urBVNkA1rvJliWMFzgF8YViXBhM9qfuKg=; b=GDm85oBHKy2diXUXpyY8YxQcIJ0+AAdtX2vvAmM6nnusrEhcmkb6jmaBcrC+Q8a08B mJ/1mqI15fR5sm3Gxa6BUT64m4zZjTDvFJKUUBR6jI+ckpBlARiHr5Cksqv7D57vXD+H LoDQroundClC4DPRA/IMZu3ogTelpScGl6VKdS9tGaHnZYcQF12vGO9hHt8TJik4+4ji IZsd0kLuDJmPAPZ0+kCPuAbuCLtK7/JZlo0jJMupFJkhbOPpDNAmjZbi02wW40z0+Eu4 Fkq1V0AAbFEFYicRYo8qJ2Vk5b3XfgA06IImtL8cEFrbhJk0wcMgLOwulR02U/LRtkyr O11A== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:to:cc:subject:date:message-id:mime-version :content-transfer-encoding; bh=xNzqAsjFA4urBVNkA1rvJliWMFzgF8YViXBhM9qfuKg=; b=T67d6GgKX4n316yCz5Ek53RHOnpDnmKBRYH7Y1z3LuVCQAR2U/imBI+0+t2Cbsv/K/ NkVZH5NSHH8FkFynQHPpcZYg0jXGhukaNcqymB4kBxP7ctxQ2leEfr0IK8H2dT6I/acq UCtXBszNh+D/KHiwUc3jNa7PlC3TGfTc3Hzm7hKJqtdiYvhJUn+pSXRrGQ6GwTk6JsAr 4Y9dTvqFgwRE7UKfVe0ym9tj4SFjWQE/5JKSoQp4NFs0OGFPcUsZtNMFK2QA3hPuDIZV 0VrNKVziSlFvahIINgLy6zMnk1/TcAQwGdS4WhL8h2mvbSsUdj9F4G+9Xm/p6Xh82jBY EBJQ== X-Gm-Message-State: AOAM532G11rgnX7bbUFXMPCKVe1YwbE0tNkOtaGmrk3b8+7dRXWUT+8N iSgl534/5Wbp5J+tgMIymrFntpnhRe8= X-Google-Smtp-Source: ABdhPJxgDOT94WnZLZv8yXtE/llPGL6RXbed4DOfTNnMR8U7ZTsYXIuSJZula4dHoIRTKDhuHrYQ3w== X-Received: by 2002:a9d:6391:: with SMTP id w17mr16019822otk.19.1631034431802; Tue, 07 Sep 2021 10:07:11 -0700 (PDT) Received: from nuclearis3.lan (c-98-195-139-126.hsd1.tx.comcast.net. [98.195.139.126]) by smtp.gmail.com with ESMTPSA id z1sm2340898ooj.25.2021.09.07.10.07.10 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 07 Sep 2021 10:07:11 -0700 (PDT) From: Alexandru Gagniuc To: u-boot@lists.denx.de Cc: Alexandru Gagniuc , patrick.delaunay@foss.st.com, etienne.carriere@linaro.org, sbabic@denx.de, festevam@gmail.com Subject: [PATCH 0/4] Repeal and replace TZDRAM_ related config options Date: Tue, 7 Sep 2021 12:07:05 -0500 Message-Id: <20210907170709.2684890-1-mr.nuke.me@gmail.com> X-Mailer: git-send-email 2.31.1 MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-BeenThere: u-boot@lists.denx.de X-Mailman-Version: 2.1.34 Precedence: list List-Id: U-Boot discussion List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: u-boot-bounces@lists.denx.de Sender: "U-Boot" X-Virus-Scanned: clamav-milter 0.103.2 at phobos.denx.de X-Virus-Status: Clean When enabling OPTEE support in the config menu, one is asked for the TZDRAM region and OPTEE load address. It would seem that these are very important values, not just some half-assed bollocks. There are currently three sources of information regarding OPTEE and its associated DRAM region: 1) Devicetree "/reserved-memory" nodes 2) uImage and FIT load-address and entry-point 3) The CONFIG_s currently under scrutiny (1) and (2) are sufficient to identify and reject OP-TEE images which fall outside TZDRAM. Such a check might make sense in the context of not bricking a device. But if an incompatible image was already installed, the device is likely soft-bricked anyway and needs manual intervention. This series doesn't implement such a check. It is possible for (1) and (3) to be in conflict. Because the values in (3) default to 0x0, it is very likely to happen. Such a situation causes the "bootm" command to reject otherwise valid OP-TEE images. Thus a perfectly tuned u-boot which doesn't also set (3) will be non-functional with respect to OP-TEE images. This becomes confusing, and has caused yours truly a disproportionate amount of grief. Fortunately, SPL can also load OP-TEE images, and does not even look at the values in (3). It only uses (1) and (2) to determine the appropriate values for firing up OP-TEE. It is more reliable and easy to use than "bootm". We are able to remove these configs without breaking anything. This also resolves the problems with "bootm" mentioned earlier. I hypothesize that one could re-add the removed checks from optee_verify_image() by deriving TZDRAM information from (1) instead of (3). I chose not to implement it because I don't see the value. Alexandru Gagniuc (4): lib: optee: Avoid CONFIG_TZDRAM_* in optee_verify_bootm_image() lib: optee: Remove CONFIG_OPTEE_TZDRAM_BASE lib: optee: Remove CONFIG_OPTEE_LOAD_ADDR arm: imx: mx7: Move CONFIG_OPTEE_TZDRAM_SIZE from lib/optee arch/arm/mach-imx/mx7/Kconfig | 8 ++++++++ configs/warp7_bl33_defconfig | 1 - configs/warp7_defconfig | 2 -- include/configs/warp7.h | 5 ----- include/tee/optee.h | 14 -------------- lib/optee/Kconfig | 23 ----------------------- lib/optee/optee.c | 21 ++++++--------------- 7 files changed, 14 insertions(+), 60 deletions(-) -- 2.31.1