All of lore.kernel.org
 help / color / mirror / Atom feed
* [PATCH v2 0/7] binman: add nxp_imx93cst etype for i.MX93 flash.bin signing
@ 2026-09-02 13:41 Jérémie Dautheribes (Schneider Electric)
  2026-09-02 13:41 ` [PATCH v2 1/7] binman: add nxp_imxcst base etype for i.MX CST signing Jérémie Dautheribes (Schneider Electric)
                   ` (6 more replies)
  0 siblings, 7 replies; 8+ messages in thread
From: Jérémie Dautheribes (Schneider Electric) @ 2026-09-02 13:41 UTC (permalink / raw)
  To: NXP i.MX U-Boot Team, u-boot
  Cc: Jérémie Dautheribes (Schneider Electric),
	Miquèl Raynal, Thomas Petazzoni, Tom Rini, Simon Glass,
	Alper Nebi Yasak, Stefano Babic, Fabio Estevam, Marek Vasut,
	Denis Mukhin, Rasmus Villemoes, Ilias Apalodimas,
	Krzysztof Drobiński, Peng Fan, Alice Guo, Simona Toaca,
	Ye Li, Quentin Schulz, Christophe Guerreiro

Hello,

This series adds support for signing i.MX93 images by leveraging binman 
and CST, the NXP tool used for secure boot. This introduces a new binman 
entry type (etype) for this purpose.

As the implementation is largely similar to the existing i.MX8M support, 
this series also introduce a new common nxp_imxcst etype to share the 
common functionnalities.

This procedure has been tested on the imx93-evk board, using both ECDSA 
and RSA-PSS keys.

Patches 1-2: introduces the new common etype and convert the imx8cst one
Patch 3: introduce the new nxp_imx93cst etype
Patch 4: updates the imx93-u-boot.dtsi description to include the new 
signing nodes
Patches 5-6: documentation
Patch 7: adds test coverage

Signed-off-by: Jérémie Dautheribes (Schneider Electric) <jeremie.dautheribes@bootlin.com>
---
Changes in v2:
- Following Simong Glass' feedback:
    - Created a new common class shared between the nxp_imx8mcst and the
    nxp_imx93cst etypes
    - rewrote the doc in reStructuredText and mention binman instead of 
    imx-mkimage
    - took into account the other minor suggestions
- Link to v1: https://patch.msgid.link/20260814-imx93-secureboot-v1-0-0c3c78020d03@bootlin.com

To: "NXP i.MX U-Boot Team" <uboot-imx@nxp.com>
To: u-boot@lists.u-boot-project.org
Cc: Miquèl Raynal <miquel.raynal@bootlin.com>
Cc: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Cc: Tom Rini <trini@konsulko.com>
Cc: Simon Glass <sjg@chromium.org>
Cc: Alper Nebi Yasak <alpernebiyasak@gmail.com>
Cc: Stefano Babic <sbabic@nabladev.com>
Cc: Fabio Estevam <festevam@gmail.com>
Cc: "Jérémie Dautheribes (Schneider Electric)" <jeremie.dautheribes@bootlin.com>
Cc: Marek Vasut <marex@nabladev.com>
Cc: Denis Mukhin <dmukhin@ford.com>
Cc: Rasmus Villemoes <rv@rasmusvillemoes.dk>
Cc: Ilias Apalodimas <ilias.apalodimas@linaro.org>
Cc: Krzysztof Drobiński <krzysztof@kd-solutions.pl>
Cc: Peng Fan <peng.fan@nxp.com>
Cc: Alice Guo <alice.guo@nxp.com>
Cc: Simona Toaca <simona.toaca@nxp.com>
Cc: Ye Li <ye.li@nxp.com>
Cc: Quentin Schulz <quentin.schulz@cherry.de>
Cc: Christophe Guerreiro <christophe.guerreiro@non.se.com>

---
Jérémie Dautheribes (Schneider Electric) (7):
      binman: add nxp_imxcst base etype for i.MX CST signing
      binman: nxp_imx8mcst: use the nxp_imxcst base etype
      tools: binman: add nxp_imx93cst etype for i.MX93 flash.bin signing
      imx93-u-boot: wrap SPL and U-Boot nodes in a CST node if AHAB_BOOT enabled
      doc: imx: ahab: add AHAB introduction
      doc: imx: ahab: add i.MX93 secure boot guide
      binman: test: add code coverage for nxp_imx93cst etype

 .gitignore                                         |   2 +
 arch/arm/dts/imx93-u-boot.dtsi                     |  54 ++-
 doc/board/nxp/index.rst                            |   2 +
 doc/imx/ahab/guides/mx93_secure_boot.rst           | 294 +++++++++++++
 doc/imx/ahab/guides/mx93_secure_boot.txt           | 269 ++++++++++++
 doc/imx/ahab/introduction_ahab.rst                 | 465 +++++++++++++++++++++
 doc/imx/ahab/introduction_ahab.txt                 | 445 ++++++++++++++++++++
 doc/imx/index.rst                                  |  14 +
 tools/binman/etype/nxp_imx8mcst.py                 |  60 +--
 tools/binman/etype/nxp_imx93cst.py                 | 112 +++++
 tools/binman/etype/nxp_imxcst.py                   | 121 ++++++
 tools/binman/ftest.py                              |  85 ++++
 tools/binman/test/vendor/nxp_imx93_csf.dts         |  18 +
 .../binman/test/vendor/nxp_imx93_csf_imagename.dts |  24 ++
 14 files changed, 1896 insertions(+), 69 deletions(-)
---
base-commit: 4a4bcb0ada8d43390e2819e62f4baee723631f5d
change-id: 20260814-imx93-secureboot-b914e7b6cbbf

Best regards,
--  
Jérémie Dautheribes (Schneider Electric) <jeremie.dautheribes@bootlin.com>


^ permalink raw reply	[flat|nested] 8+ messages in thread

end of thread, other threads:[~2026-09-02 13:42 UTC | newest]

Thread overview: 8+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-02 13:41 [PATCH v2 0/7] binman: add nxp_imx93cst etype for i.MX93 flash.bin signing Jérémie Dautheribes (Schneider Electric)
2026-09-02 13:41 ` [PATCH v2 1/7] binman: add nxp_imxcst base etype for i.MX CST signing Jérémie Dautheribes (Schneider Electric)
2026-09-02 13:41 ` [PATCH v2 2/7] binman: nxp_imx8mcst: use the nxp_imxcst base etype Jérémie Dautheribes (Schneider Electric)
2026-09-02 13:41 ` [PATCH v2 3/7] tools: binman: add nxp_imx93cst etype for i.MX93 flash.bin signing Jérémie Dautheribes (Schneider Electric)
2026-09-02 13:41 ` [PATCH v2 4/7] imx93-u-boot: wrap SPL and U-Boot nodes in a CST node if AHAB_BOOT enabled Jérémie Dautheribes (Schneider Electric)
2026-09-02 13:41 ` [PATCH v2 5/7] doc: imx: ahab: add AHAB introduction Jérémie Dautheribes (Schneider Electric)
2026-09-02 13:41 ` [PATCH v2 6/7] doc: imx: ahab: add i.MX93 secure boot guide Jérémie Dautheribes (Schneider Electric)
2026-09-02 13:41 ` [PATCH v2 7/7] binman: test: add code coverage for nxp_imx93cst etype Jérémie Dautheribes (Schneider Electric)

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.