All of lore.kernel.org
 help / color / mirror / Atom feed
From: Kane Chen <kane_chen@aspeedtech.com>
To: "Cédric Le Goater" <clg@kaod.org>,
	"Peter Maydell" <peter.maydell@linaro.org>,
	"Steven Lee" <steven_lee@aspeedtech.com>,
	"Troy Lee" <leetroy@gmail.com>,
	"Jamin Lin" <jamin_lin@aspeedtech.com>,
	"Andrew Jeffery" <andrew@codeconstruct.com.au>,
	"Joel Stanley" <joel@jms.id.au>,
	"open list:ASPEED BMCs" <qemu-arm@nongnu.org>,
	"open list:All patches CC here" <qemu-devel@nongnu.org>
Cc: Troy Lee <troy_lee@aspeedtech.com>, Kane Chen <kane_chen@aspeedtech.com>
Subject: [PATCH v1 2/2] hw/misc/aspeed_sbc: Derive secure boot state from OTP config straps
Date: Mon, 31 Aug 2026 05:37:01 +0000	[thread overview]
Message-ID: <20260831053658.462203-3-kane_chen@aspeedtech.com> (raw)
In-Reply-To: <20260831053658.462203-1-kane_chen@aspeedtech.com>

The secure boot enable bit in R_STATUS and the R_QSR signing settings
were both driven by a fixed "signing-settings" machine property, but
the two ended up inconsistent: the logic guarding the R_STATUS enable
bit was broken and never actually set it, while R_QSR still reported
the configured signing settings, so a machine could show secure boot
configured in R_QSR while R_STATUS said it was disabled.

Instead of relying on the property, read the relevant OTP
configuration bits directly and derive both the R_STATUS secure boot
enable state and the QSR value from them, matching how the real
hardware determines these settings. The now-unused "signing-settings"
property is removed.

Signed-off-by: Kane-Chen-AS <kane_chen@aspeedtech.com>
---
 include/hw/misc/aspeed_sbc.h |  2 --
 hw/misc/aspeed_sbc.c         | 34 ++++++++++++++++++++++++----------
 2 files changed, 24 insertions(+), 12 deletions(-)

diff --git a/include/hw/misc/aspeed_sbc.h b/include/hw/misc/aspeed_sbc.h
index 7152497b2a..474922cbd2 100644
--- a/include/hw/misc/aspeed_sbc.h
+++ b/include/hw/misc/aspeed_sbc.h
@@ -32,8 +32,6 @@ OBJECT_DECLARE_TYPE(AspeedSBCState, AspeedSBCClass, ASPEED_SBC)
 struct AspeedSBCState {
     SysBusDevice parent;
 
-    uint32_t signing_settings;
-
     MemoryRegion iomem;
 
     uint32_t regs[ASPEED_SBC_NR_REGS];
diff --git a/hw/misc/aspeed_sbc.c b/hw/misc/aspeed_sbc.c
index 5d4da39d30..ce03f717a9 100644
--- a/hw/misc/aspeed_sbc.c
+++ b/hw/misc/aspeed_sbc.c
@@ -63,6 +63,19 @@
 /* OTP Address */
 #define OTP_CFG0                (0x800)
 
+static bool aspeed_sbc_otp_read(AspeedSBCState *s, uint32_t otp_addr);
+
+static uint32_t aspeed_otp_read_cfg0(AspeedSBCState *s)
+{
+    uint32_t value = 0;
+
+    if (aspeed_sbc_otp_read(s, OTP_CFG0)) {
+        value = s->regs[R_CAMP1];
+    }
+
+    return value;
+}
+
 static uint64_t aspeed_sbc_read(void *opaque, hwaddr addr, unsigned int size)
 {
     AspeedSBCState *s = ASPEED_SBC(opaque);
@@ -76,7 +89,12 @@ static uint64_t aspeed_sbc_read(void *opaque, hwaddr addr, unsigned int size)
         return 0;
     }
 
-    return s->regs[addr];
+    switch (addr) {
+    case R_QSR:
+        return aspeed_otp_read_cfg0(s);
+    default:
+        return s->regs[addr];
+    }
 }
 
 static bool aspeed_sbc_otp_read(AspeedSBCState *s,
@@ -291,6 +309,7 @@ static bool aspeed_get_abr_state(AspeedSBCState *s)
 static void aspeed_sbc_reset_hold(Object *obj, ResetType type)
 {
     AspeedSBCState *s = ASPEED_SBC(obj);
+    uint32_t value;
     bool abr;
 
     memset(s->regs, 0, sizeof(s->regs));
@@ -304,11 +323,11 @@ static void aspeed_sbc_reset_hold(Object *obj, ResetType type)
         s->regs[R_STATUS] |= ABR_EN;
     }
 
-    if (s->signing_settings) {
-        s->regs[R_STATUS] &= SECURE_BOOT_EN;
-    }
+    value = aspeed_otp_read_cfg0(s);
 
-    s->regs[R_QSR] = s->signing_settings;
+    if (value & BIT(1)) {
+        s->regs[R_STATUS] |= SECURE_BOOT_EN;
+    }
 }
 
 static void aspeed_sbc_instance_init(Object *obj)
@@ -352,10 +371,6 @@ static const VMStateDescription vmstate_aspeed_sbc = {
     }
 };
 
-static const Property aspeed_sbc_properties[] = {
-    DEFINE_PROP_UINT32("signing-settings", AspeedSBCState, signing_settings, 0),
-};
-
 static void aspeed_sbc_class_init(ObjectClass *klass, const void *data)
 {
     DeviceClass *dc = DEVICE_CLASS(klass);
@@ -364,7 +379,6 @@ static void aspeed_sbc_class_init(ObjectClass *klass, const void *data)
     dc->realize = aspeed_sbc_realize;
     rc->phases.hold = aspeed_sbc_reset_hold;
     dc->vmsd = &vmstate_aspeed_sbc;
-    device_class_set_props(dc, aspeed_sbc_properties);
 }
 
 
-- 
2.43.0


  parent reply	other threads:[~2026-08-31  5:38 UTC|newest]

Thread overview: 10+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-31  5:36 [PATCH v1 0/2] hw/misc/aspeed_sbc: Fix ABR and secure boot state reporting Kane Chen
2026-08-31  5:37 ` [PATCH v1 1/2] hw/misc/aspeed_sbc: Derive ABR state from OTP config straps Kane Chen
2026-08-31  5:40   ` Jamin Lin
2026-08-31 11:10   ` Cédric Le Goater
2026-09-01  9:25     ` Kane Chen
2026-09-03  7:22       ` Cédric Le Goater
2026-09-03  7:35         ` Kane Chen
2026-08-31  5:37 ` Kane Chen [this message]
2026-08-31  5:41   ` [PATCH v1 2/2] hw/misc/aspeed_sbc: Derive secure boot " Jamin Lin
2026-08-31 11:14   ` Cédric Le Goater

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260831053658.462203-3-kane_chen@aspeedtech.com \
    --to=kane_chen@aspeedtech.com \
    --cc=andrew@codeconstruct.com.au \
    --cc=clg@kaod.org \
    --cc=jamin_lin@aspeedtech.com \
    --cc=joel@jms.id.au \
    --cc=leetroy@gmail.com \
    --cc=peter.maydell@linaro.org \
    --cc=qemu-arm@nongnu.org \
    --cc=qemu-devel@nongnu.org \
    --cc=steven_lee@aspeedtech.com \
    --cc=troy_lee@aspeedtech.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.