All of lore.kernel.org
 help / color / mirror / Atom feed
From: Nishanth Menon <nm@ti.com>
To: Manorit Chawdhry <m-chawdhry@ti.com>
Cc: Apurva Nandan <a-nandan@ti.com>, Hari Nagalla <hnagalla@ti.com>,
	Lukasz Majewski <lukma@denx.de>,
	Sean Anderson <seanga2@gmail.com>,
	Jaehoon Chung <jh80.chung@samsung.com>,
	Neha Malcom Francis <n-francis@ti.com>,
	Simon Glass <sjg@chromium.org>, Andrew Davis <afd@ti.com>,
	Kamlesh Gurudasani <kamlesh@ti.com>,
	Dasnavis Sabiya <sabiya.d@ti.com>,
	Aradhya Bhatia <a-bhatia1@ti.com>, Bryan Brattlof <bb@ti.com>,
	Christian Gmeiner <christian.gmeiner@gmail.com>,
	Heinrich Schuchardt <xypron.glpk@gmx.de>,
	Marcel Ziswiler <marcel.ziswiler@toradex.com>,
	Roger Quadros <rogerq@kernel.org>,
	Jayesh Choudhary <j-choudhary@ti.com>,
	Ralph Siemsen <ralph.siemsen@linaro.org>,
	Yanhong Wang <yanhong.wang@starfivetech.com>,
	Marek Vasut <marek.vasut+renesas@mailbox.org>,
	Rasmus Villemoes <rasmus.villemoes@prevas.dk>,
	<u-boot@lists.denx.de>,
	Sinthu Raja M <sinthu.raja@mistralsolutions.com>,
	Udit Kumar <u-kumar1@ti.com>
Subject: Re: [PATCH v4 02/16] arm: mach-k3: Add basic support for J784S4 SoC definition
Date: Wed, 4 Oct 2023 07:24:25 -0500	[thread overview]
Message-ID: <20231004122425.3lvghvwufnx5simt@manhunt> (raw)
In-Reply-To: <20231004051327.jvatwiwpmdz4lykd@ula0497581>

On 10:43-20231004, Manorit Chawdhry wrote:

> These are required to remove the firewall configurations that are done
> by ROM, those are not the ones that are being handled by OIDs. The

I am not sure I understand this clearly. OIDs are setup to open up
firewalls or close firewalls as the system requires and since it
is authenticated, not compromiseable.- U-boot by itself (even if
authenticated), is not a secure entity for it to dictate the firewall
configuration (u-boot must be assumed to be compromised after
authentication is complete). So, doing firewall configuration via APIs
after boot, to me looks broken approach.

> current series that is being worked on is to add additional firewalling
> support with OIDs that TIFS will be handling.
> The above patch is
> essentially added to have the same development experience on GP devices
> similar to HS after the secure boot is done so that people don't end up

huh? the code seems to blindly call the remove_fwl_configs(cbass_hc_cfg0_fwls, ARRAY_SIZE(cbass_hc_cfg0_fwls));
where is the distinction of HS vs GP here? This implementation looks
completely broken to me at least.. please correct what I missed here.

-- 
Regards,
Nishanth Menon
Key (0xDDB5849D1736249D) / Fingerprint: F8A2 8693 54EB 8232 17A3  1A34 DDB5 849D 1736 249D

  reply	other threads:[~2023-10-04 12:24 UTC|newest]

Thread overview: 47+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2023-10-01 16:55 [PATCH v4 00/16] Introduce initial TI's J784S4 and AM69 support Apurva Nandan
2023-10-01 16:55 ` [PATCH v4 01/16] arm: dts: Introduce j784s4 dts from linux kernel Apurva Nandan
2023-10-01 16:55 ` [PATCH v4 02/16] arm: mach-k3: Add basic support for J784S4 SoC definition Apurva Nandan
2023-10-02 16:01   ` Nishanth Menon
2023-10-04  5:13     ` Manorit Chawdhry
2023-10-04 12:24       ` Nishanth Menon [this message]
2023-10-05  4:59         ` Manorit Chawdhry
2023-10-05 11:26           ` Nishanth Menon
2023-10-06  4:16             ` Manorit Chawdhry
2023-10-06 11:13               ` Nishanth Menon
2023-10-09  5:08                 ` Manorit Chawdhry
2023-10-04 17:52     ` Apurva Nandan
2023-10-04 18:06       ` Nishanth Menon
2023-11-22 15:15         ` Andrew Davis
2023-10-04 17:57     ` Apurva Nandan
2023-10-01 16:55 ` [PATCH v4 03/16] arm: mach-k3: Sort SoC JTAG_ID entries Apurva Nandan
2023-10-02 15:54   ` Nishanth Menon
2023-10-01 16:55 ` [PATCH v4 04/16] soc: ti: k3-socinfo: Add entry for J784S4 SoC Apurva Nandan
2023-10-01 16:55 ` [PATCH v4 05/16] arm: mach-k3: j784s4: Add clk and power support Apurva Nandan
2023-10-01 16:55 ` [PATCH v4 06/16] drivers: dma: Add support for J784S4 SoC Apurva Nandan
2023-10-01 16:55 ` [PATCH v4 07/16] remoteproc: k3-r5: Extend support for R5F clusters on J784S4 SoCs Apurva Nandan
2023-10-02 15:52   ` Nishanth Menon
2023-10-01 16:55 ` [PATCH v4 08/16] remoteproc: k3-dsp: Extend support for C71x DSPs " Apurva Nandan
2023-10-01 16:55 ` [PATCH v4 09/16] board: ti: j784s4: Add board support for J784S4 EVM Apurva Nandan
2023-10-02 15:51   ` Nishanth Menon
2023-10-04 18:01     ` Apurva Nandan
2023-10-04 18:05       ` Nishanth Menon
2023-10-12 17:55   ` Tom Rini
2023-10-01 16:55 ` [PATCH v4 10/16] arm: dts: Introduce j784s4 u-boot dts files Apurva Nandan
2023-10-02 14:04   ` Jerome Forissier
2023-10-04 18:02     ` Apurva Nandan
2023-10-01 16:55 ` [PATCH v4 11/16] arm: dts: Introduce am69-sk dts from linux kernel Apurva Nandan
2023-10-01 16:55 ` [PATCH v4 12/16] board: ti: j784s4: Update env to use am69-sk dtb Apurva Nandan
2023-10-02 15:39   ` Nishanth Menon
2023-10-01 16:55 ` [PATCH v4 13/16] arm: dts: Introduce am69-sk u-boot dts files Apurva Nandan
2023-10-01 16:55 ` [PATCH v4 14/16] configs: j784s4_evm: Add defconfig for j784s4 evm board Apurva Nandan
2023-10-01 16:55 ` [PATCH v4 15/16] configs: Add am69_sk_* defconfig fragments Apurva Nandan
2023-10-01 16:55 ` [PATCH v4 16/16] doc: board: ti: k3: Add J784S4 EVM and AM69 SK documentation Apurva Nandan
2023-10-02 15:26   ` Nishanth Menon
2023-10-02 16:58   ` Bryan Brattlof
2023-10-02 22:55     ` Heinrich Schuchardt
2023-10-04 18:03       ` Apurva Nandan
2023-10-02 15:33 ` [PATCH v4 00/16] Introduce initial TI's J784S4 and AM69 support Nishanth Menon
2023-11-15 13:53 ` Maxime Ripard
2023-11-16 22:56   ` Enric Balletbo i Serra
2023-11-17  4:02     ` Kumar, Udit
2023-11-17 12:49       ` Bryan Brattlof

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20231004122425.3lvghvwufnx5simt@manhunt \
    --to=nm@ti.com \
    --cc=a-bhatia1@ti.com \
    --cc=a-nandan@ti.com \
    --cc=afd@ti.com \
    --cc=bb@ti.com \
    --cc=christian.gmeiner@gmail.com \
    --cc=hnagalla@ti.com \
    --cc=j-choudhary@ti.com \
    --cc=jh80.chung@samsung.com \
    --cc=kamlesh@ti.com \
    --cc=lukma@denx.de \
    --cc=m-chawdhry@ti.com \
    --cc=marcel.ziswiler@toradex.com \
    --cc=marek.vasut+renesas@mailbox.org \
    --cc=n-francis@ti.com \
    --cc=ralph.siemsen@linaro.org \
    --cc=rasmus.villemoes@prevas.dk \
    --cc=rogerq@kernel.org \
    --cc=sabiya.d@ti.com \
    --cc=seanga2@gmail.com \
    --cc=sinthu.raja@mistralsolutions.com \
    --cc=sjg@chromium.org \
    --cc=u-boot@lists.denx.de \
    --cc=u-kumar1@ti.com \
    --cc=xypron.glpk@gmx.de \
    --cc=yanhong.wang@starfivetech.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.