From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from smtp3.osuosl.org (smtp3.osuosl.org [140.211.166.136]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.lore.kernel.org (Postfix) with ESMTPS id 64E6EC44515 for ; Tue, 21 Jul 2026 02:15:10 +0000 (UTC) Received: from localhost (localhost [127.0.0.1]) by smtp3.osuosl.org (Postfix) with ESMTP id 62AC3607AC; Tue, 21 Jul 2026 02:15:08 +0000 (UTC) X-Virus-Scanned: amavis at osuosl.org Received: from smtp3.osuosl.org ([127.0.0.1]) by localhost (smtp3.osuosl.org [127.0.0.1]) (amavis, port 10024) with ESMTP id 7NJn2lPFm4iI; Tue, 21 Jul 2026 02:15:06 +0000 (UTC) X-Comment: SPF check N/A for local connections - client-ip=140.211.166.142; helo=lists1.osuosl.org; envelope-from=u-boot-bounces@lists.u-boot-project.org; receiver= DKIM-Filter: OpenDKIM Filter v2.11.0 smtp3.osuosl.org 34CCE6078C DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=lists.u-boot-project.org ; s=default; t=1784600106; bh=GE4pcE2Hk1uwD5D9NABewVzVAqgrbOoj/A8jh2WhxNs=; h=To:Cc:Subject:Date:List-Id:List-Unsubscribe:List-Archive: List-Post:List-Help:List-Subscribe:From:Reply-To:From; b=lhvXSjWSJlv7FqVAoQVj5dqWJn01wMdqODdpI2DNuhToVGD2gG49OmTFtFs19p8LD r8sjZh1W5DODZYkXdBslpdju6YEfpO6Svp3rh8Es+BSisQAOhaYdPPyvx7dNqCqhTy rhgjKlvuyi9YVPggTdKyNhmPfJqSnqibcBeiuvTH2UOuUv6Cw+1VV+aPSdqGNeUtFZ vqqiC9ZW2angvFUPmb+8ytcbcaMgA1kLA3Q/y19QP8zxiAqJ9ZElKm+0YaNnp3T0ow 0V+sD35Ugrz9GiHYp3e4xSPRk6LtYBVlXU7S+Ce7I7wrFkJLt5r5hBC7vSOppPLwa1 Kj935CO/KwMcQ== Received: from lists1.osuosl.org (lists1.osuosl.org [140.211.166.142]) by smtp3.osuosl.org (Postfix) with ESMTP id 34CCE6078C; Tue, 21 Jul 2026 02:15:06 +0000 (UTC) Received: from smtp4.osuosl.org (smtp4.osuosl.org [140.211.166.137]) by lists1.osuosl.org (Postfix) with ESMTP id 24B80313 for ; Tue, 21 Jul 2026 02:15:04 +0000 (UTC) Received: from localhost (localhost [127.0.0.1]) by smtp4.osuosl.org (Postfix) with ESMTP id 165B3406F1 for ; Tue, 21 Jul 2026 02:15:04 +0000 (UTC) X-Virus-Scanned: amavis at osuosl.org Received: from smtp4.osuosl.org ([127.0.0.1]) by localhost (smtp4.osuosl.org [127.0.0.1]) (amavis, port 10024) with ESMTP id ncpkcKyT9Qjl for ; Tue, 21 Jul 2026 02:15:03 +0000 (UTC) X-Greylist: delayed 333 seconds by postgrey-1.37 at util1.osuosl.org; Tue, 21 Jul 2026 02:15:02 UTC DMARC-Filter: OpenDMARC Filter v1.4.2 smtp4.osuosl.org 92C0340523 DKIM-Filter: OpenDKIM Filter v2.11.0 smtp4.osuosl.org 92C0340523 Received-SPF: Pass (mailfrom) identity=mailfrom; client-ip=2a00:f820:417:0:178:251:229:89; helo=mx.nabladev.com; envelope-from=marex@nabladev.com; receiver= Received: from mx.nabladev.com (mx.nabladev.com [IPv6:2a00:f820:417:0:178:251:229:89]) by smtp4.osuosl.org (Postfix) with ESMTPS id 92C0340523 for ; Tue, 21 Jul 2026 02:15:02 +0000 (UTC) Received: from [127.0.0.1] (localhost [127.0.0.1]) by localhost (Mailerdaemon) with ESMTPSA id CE27C11A94E; Tue, 21 Jul 2026 04:09:24 +0200 (CEST) To: u-boot@lists.u-boot-project.org Cc: Marek Vasut , "NXP i.MX U-Boot Team" , Fabio Estevam , Simon Glass , Stefano Babic , Tom Rini , u-boot@lists.denx.de Subject: [PATCH v2] binman: nxp_imx8mcst: Handle FCFB header during SPI NOR boot Date: Tue, 21 Jul 2026 04:09:14 +0200 Message-ID: <20260721020918.150615-1-marex@nabladev.com> X-Mailer: git-send-email 2.53.0 MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Last-TLS-Session-Version: TLSv1.3 X-Mailman-Original-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=nabladev.com; s=dkim; t=1784599766; h=from:subject:date:message-id:to:cc:mime-version: content-transfer-encoding; bh=GE4pcE2Hk1uwD5D9NABewVzVAqgrbOoj/A8jh2WhxNs=; b=e62LB+8Auxo3XqIKIlLw7A/a4M0ZgiOJ2yh6aJSuKWwQCxkNSeWVUVcu2xKvgNDIR4/BBv +5H+0S1rVrQqLOj2Q+fj60NY2RmiRHaH1tYkn1/m669JmUttUHY49APGbRLiacJTjx/Xu7 Yp6nEL0LVXC1qnPsXhQ2gND+k5LJbZRUn6Oe0n7ELqLbCY3PIz7gc8gIUeFibfyq02smSU FjOxFAGduol2k5DJd1zD0WwpDCz5e2LfhTUDaJ8y/nuKBUIeBDsmu7JOn57VwCf24iF2CM 44LZlgPlz+wR9ZA9I3WsZcVeAhlvxhw5HF/Orz4TwVU7/bRKJFKxqT98NE7CsQ== X-Mailman-Original-Authentication-Results: smtp4.osuosl.org; dmarc=pass (p=reject dis=none) header.from=nabladev.com X-Mailman-Original-Authentication-Results: smtp4.osuosl.org; dkim=pass (2048-bit key, unprotected) header.d=nabladev.com header.i=@nabladev.com header.a=rsa-sha256 header.s=dkim header.b=e62LB+8A X-BeenThere: u-boot@lists.u-boot-project.org X-Mailman-Version: 2.1.30 Precedence: list List-Id: U-Boot discussion List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , From: Marek Vasut via U-Boot Reply-To: Marek Vasut Errors-To: u-boot-bounces@lists.u-boot-project.org Sender: "U-Boot" In case the image that is wrapped in the nxp_imx8mcst already contains an FCFB header which is mandatory for SPI NOR boot, then the IVT is at offset 0x1000 instead of offset 0x0, but the whole image including the FCFB header must be signed to prevent attacker from tampering with any of the headers. Add the FCFB handling. Signed-off-by: Marek Vasut --- Cc: "NXP i.MX U-Boot Team" Cc: Fabio Estevam Cc: Simon Glass Cc: Stefano Babic Cc: Tom Rini Cc: u-boot@lists.denx.de --- V2: Update the block comment to mention the FCFB --- tools/binman/etype/nxp_imx8mcst.py | 15 +++++++++++++-- 1 file changed, 13 insertions(+), 2 deletions(-) diff --git a/tools/binman/etype/nxp_imx8mcst.py b/tools/binman/etype/nxp_imx8mcst.py index a10f61aa01f..de7032c88f3 100644 --- a/tools/binman/etype/nxp_imx8mcst.py +++ b/tools/binman/etype/nxp_imx8mcst.py @@ -20,8 +20,9 @@ from binman import elf from dtoc import fdt_util from u_boot_pylib import tools -MAGIC_NXP_IMX_IVT = 0x412000d1 -MAGIC_FITIMAGE = 0xedfe0dd0 +MAGIC_NXP_IMX_IVT = 0x412000d1 +MAGIC_NXP_IMX_FCFB = 0x42464346 +MAGIC_FITIMAGE = 0xedfe0dd0 KEY_NAME = 'sha256_4096_65537_v3_usr_crt' @@ -112,6 +113,9 @@ class Entry_nxp_imx8mcst(Entry_mkimage): # - If it is mkimage'd imx8mimage, then extract to be signed data size # from imx8mimage header, and calculate CSF blob offset right past # the SPL from this information. + # - If it is mkimage'd imx8mimage wrapped in FCFB, then extract to be + # signed data size from imx8mimage header past the FCFB header, and + # calculate CSF blob offset right past the SPL from this information. # - If it is fitImage, then pad the image to 4k, add generated IVT and # sign the whole payload, then append CSF blob at the end right past # the IVT. @@ -125,6 +129,13 @@ class Entry_nxp_imx8mcst(Entry_mkimage): signsize = struct.unpack('