From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from mail.kernel.org (mail.kernel.org [198.145.29.99]) by smtp.lore.kernel.org (Postfix) with ESMTP id 4CA51C433EF for ; Wed, 20 Oct 2021 02:45:26 +0000 (UTC) Received: from phobos.denx.de (phobos.denx.de [85.214.62.61]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by mail.kernel.org (Postfix) with ESMTPS id 9248A6109F for ; Wed, 20 Oct 2021 02:45:25 +0000 (UTC) DMARC-Filter: OpenDMARC Filter v1.4.1 mail.kernel.org 9248A6109F Authentication-Results: mail.kernel.org; dmarc=none (p=none dis=none) header.from=sholland.org Authentication-Results: mail.kernel.org; spf=pass smtp.mailfrom=lists.denx.de Received: from h2850616.stratoserver.net (localhost [IPv6:::1]) by phobos.denx.de (Postfix) with ESMTP id CB09181545; Wed, 20 Oct 2021 04:45:12 +0200 (CEST) Authentication-Results: phobos.denx.de; dmarc=none (p=none dis=none) header.from=sholland.org Authentication-Results: phobos.denx.de; spf=pass smtp.mailfrom=u-boot-bounces@lists.denx.de Authentication-Results: phobos.denx.de; dkim=pass (2048-bit key; unprotected) header.d=sholland.org header.i=@sholland.org header.b="CifS/e3r"; dkim=pass (2048-bit key; unprotected) header.d=messagingengine.com header.i=@messagingengine.com header.b="L9KvtNbt"; dkim-atps=neutral Received: by phobos.denx.de (Postfix, from userid 109) id 5C41081D1F; Wed, 20 Oct 2021 04:45:05 +0200 (CEST) Received: from out5-smtp.messagingengine.com (out5-smtp.messagingengine.com [66.111.4.29]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)) (No client certificate requested) by phobos.denx.de (Postfix) with ESMTPS id D259781197 for ; Wed, 20 Oct 2021 04:44:58 +0200 (CEST) Authentication-Results: phobos.denx.de; dmarc=none (p=none dis=none) header.from=sholland.org Authentication-Results: phobos.denx.de; spf=pass smtp.mailfrom=samuel@sholland.org Received: from compute5.internal (compute5.nyi.internal [10.202.2.45]) by mailout.nyi.internal (Postfix) with ESMTP id 7EF1B5C00F7; Tue, 19 Oct 2021 22:44:57 -0400 (EDT) Received: from mailfrontend2 ([10.202.2.163]) by compute5.internal (MEProxy); Tue, 19 Oct 2021 22:44:57 -0400 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=sholland.org; h= from:to:cc:subject:date:message-id:mime-version:content-type :content-transfer-encoding; s=fm1; bh=QGYgjbx6aYJqBP3bk4Mj4tPma6 mcFuo5ujIbHhLLBbc=; b=CifS/e3r1ojcXdd6vrfh9ltwPV9lWBWm+mf2+POG3K KoSEXp22/Uue5WKgo8Ws18I4d54QotVNNPxJdYnzJDJ/cljr1WLi2ZGyksflaxD2 L2yI+VkulKQ0fDEpHtsu3JOf+rM06iZnYQc4fgBpe4p5DCbgo6errgkWb+GReOh8 Vd3FEkf+bmDooW7bku5gmQy8ho08+3NIFE06VvsbGHSQDmyGZ1LmG2gXFQdf4KIr h8S0oSvcEDrKrLb6zV/xuthsZvHFF0ra0B5oynjtXpEtyp5OmCLnDc6GvwvU3BwZ OwvQiglFhe0BydWuQuF0deyijqixrma/727H+wny2MXA== DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=cc:content-transfer-encoding:content-type :date:from:message-id:mime-version:subject:to:x-me-proxy :x-me-proxy:x-me-sender:x-me-sender:x-sasl-enc; s=fm1; bh=QGYgjb x6aYJqBP3bk4Mj4tPma6mcFuo5ujIbHhLLBbc=; b=L9KvtNbtcIsm9GhWpjaeKd pvGAKbuJ4A1prdr/bnSzcEmjQa2xrSCrZ1wH9WVlNmj09qaeT40ZiIUUXH6qWCxd F8t7i88c60K6tdDaxT8YxPUErgirXPADG6s0+BM2A0u5mxSyiEytZquNIltI89Jz ppCZ6VDbPbL6LlxVpCgKs4wzgYz/MmZA2EradC6qwb1hffpzef4idXwtGe5Ey+5A LVOd1Vo43O02eBIYHet3GdtK46fxyBOTjrcCBIS7WnhpHj0jCyroXm3JX0sKg8Vg xIX5MBVVXzLAxZQIeFiu+NjRnFp/wDSdauCgo02vUQa8eSf19kc5vkJbxkWL+qnw == X-ME-Sender: X-ME-Received: X-ME-Proxy-Cause: gggruggvucftvghtrhhoucdtuddrgedvtddrvddvfedgheejucetufdoteggodetrfdotf fvucfrrhhofhhilhgvmecuhfgrshhtofgrihhlpdfqfgfvpdfurfetoffkrfgpnffqhgen uceurghilhhouhhtmecufedttdenucesvcftvggtihhpihgvnhhtshculddquddttddmne cujfgurhephffvufffkffogggtgfesthekredtredtjeenucfhrhhomhepufgrmhhuvghl ucfjohhllhgrnhguuceoshgrmhhuvghlsehshhholhhlrghnugdrohhrgheqnecuggftrf grthhtvghrnhepvdfhffekjeffueelvdefhfekuedutdejgfdvhfevgeegleekgfefhfev kedttedunecuffhomhgrihhnpehoiihlrggsshdrohhrghenucevlhhushhtvghrufhiii gvpedtnecurfgrrhgrmhepmhgrihhlfhhrohhmpehsrghmuhgvlhesshhhohhllhgrnhgu rdhorhhg X-ME-Proxy: Received: by mail.messagingengine.com (Postfix) with ESMTPA; Tue, 19 Oct 2021 22:44:56 -0400 (EDT) From: Samuel Holland To: u-boot@lists.denx.de, Jagan Teki , Andre Przywara Cc: "Alex G ." , =?UTF-8?q?Pali=20Roh=C3=A1r?= , Samuel Holland , Artem Lapkin , Priyanka Jain , Sughosh Ganu Subject: [PATCH v4 0/4] sunxi: TOC0 image type support Date: Tue, 19 Oct 2021 21:44:50 -0500 Message-Id: <20211020024455.48136-1-samuel@sholland.org> X-Mailer: git-send-email 2.32.0 MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit X-BeenThere: u-boot@lists.denx.de X-Mailman-Version: 2.1.34 Precedence: list List-Id: U-Boot discussion List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: u-boot-bounces@lists.denx.de Sender: "U-Boot" X-Virus-Scanned: clamav-milter 0.103.2 at phobos.denx.de X-Virus-Status: Clean This series adds support for the TOC0 image format used by the Allwinner secure boot ROM (SBROM). This series has been tested on the following SoCs/boards, with the eFuse burnt to enable secure mode: - A50: Ainol Q88 Tablet - A64: Pine A64 Plus - H5: Orange Pi Zero Plus - H6: Pine H64 Model B - H616: Orange Pi Zero 2 This time I also tested it on boards that are not switched to secure mode (with A64, H3, and H5). Due to both series changing Makefile.spl, the last patch depends on: https://patchwork.ozlabs.org/project/uboot/list/?series=267136 Since this series no longer selects TOOLS_LIBCRYPTO anywhere, building certain platforms/options may fail with an error like the following if TOOLS_LIBCRYPTO is disabled: MKIMAGE spl/sunxi-spl.bin ./tools/mkimage: unsupported type Allwinner TOC0 Boot Image make[1]: *** [scripts/Makefile.spl:426: spl/sunxi-spl.bin] Error 1 make: *** [Makefile:1982: spl/u-boot-spl] Error 2 Hopefully this is clear enough. Changes in v4: - Do not select TOOLS_LIBCRYPTO anywhere Changes in v3: - Selected TOOLS_LIBCRYPTO on all platforms that use kwbimage (as best as I can tell, using the suggestions from Pali Rohár) - Removed TOOLS_LIBCRYPTO selection for sunxi, since most boards do not need it - Added __packed to all new "ABI" structs - Added entry to MAINTAINERS for sunxi tools - Fixed offset of magic passed to memcmp - Refactored functions to not return pointers (fixes ambiguous NULL) Changes in v2: - Refactored the first patch on top of TOOLS_LIBCRYPTO - Moved certificate and key item structures out of sunxi_image.h - Renamed "main" and "item" variables for clarity - Improved error messages, and added a hint about key generation - Added a comment explaining the purpose of the various key files - Mentioned testing this code on A50 in the commit message - Moved SPL header signature checks out of sunxi_image.h - Refactored SPL header signature checks to use fewer casts - Rebase on top of Icenowy's RISC-V support series - Rename Kconfig symbols to include the full image type name Samuel Holland (4): tools: Separate image types which depend on OpenSSL tools: mkimage: Add Allwinner TOC0 support sunxi: Support SPL in both eGON and TOC0 images sunxi: Support building a SPL as a TOC0 image MAINTAINERS | 1 + arch/arm/include/asm/arch-sunxi/spl.h | 2 - arch/arm/mach-sunxi/Kconfig | 2 + arch/arm/mach-sunxi/board.c | 34 +- board/sunxi/Kconfig | 24 + common/image.c | 1 + include/image.h | 1 + include/sunxi_image.h | 37 ++ scripts/Makefile.spl | 5 +- scripts/config_whitelist.txt | 1 - tools/Makefile | 20 +- tools/mxsimage.c | 3 - tools/sunxi_toc0.c | 907 ++++++++++++++++++++++++++ 13 files changed, 1011 insertions(+), 27 deletions(-) create mode 100644 board/sunxi/Kconfig create mode 100644 tools/sunxi_toc0.c -- 2.32.0