From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from phobos.denx.de (phobos.denx.de [85.214.62.61]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.lore.kernel.org (Postfix) with ESMTPS id 5179BC77B7C for ; Sun, 7 May 2023 12:11:47 +0000 (UTC) Received: from h2850616.stratoserver.net (localhost [IPv6:::1]) by phobos.denx.de (Postfix) with ESMTP id 2477782721; Sun, 7 May 2023 14:11:45 +0200 (CEST) Authentication-Results: phobos.denx.de; dmarc=pass (p=reject dis=none) header.from=siemens.com Authentication-Results: phobos.denx.de; spf=pass smtp.mailfrom=u-boot-bounces@lists.denx.de Authentication-Results: phobos.denx.de; dkim=pass (2048-bit key; unprotected) header.d=siemens.com header.i=@siemens.com header.b="enOBGMze"; dkim-atps=neutral Received: by phobos.denx.de (Postfix, from userid 109) id 1C8C68468E; Sun, 7 May 2023 14:11:43 +0200 (CEST) Received: from EUR04-VI1-obe.outbound.protection.outlook.com (mail-vi1eur04on0610.outbound.protection.outlook.com [IPv6:2a01:111:f400:fe0e::610]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by phobos.denx.de (Postfix) with ESMTPS id 60334801CE for ; Sun, 7 May 2023 14:11:39 +0200 (CEST) Authentication-Results: phobos.denx.de; dmarc=pass (p=reject dis=none) header.from=siemens.com Authentication-Results: phobos.denx.de; spf=pass smtp.mailfrom=jan.kiszka@siemens.com ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=E2bMEAQoU07oUSEx/cJe7ahP1NPc22Uwv0OhMDvQnLdx2jf70FHsSMkjtEiuNJbt4TJTOZQONeAzdbCWz5dsez8/jkio93NEDfophSlQZ/AW/6x5nnN4ptRt7/Wox+/b3+gPzwOb4CwVVMFMhqWnXyXiY6ruZXqheh37RobpS0qXkBux9qovVTtxZPPH/9e/seEWpyqQnuCFn4SmILZ6+EDhsLQqHsyZMqEsORu84IonQOknBH7SqaYqmrUAYXxBVo5LQi0DTxjddCW1Hi3jbOf6pyP2LkT+NA1ivxgyuvYCsKYPWWsTaUfJBd5MGMtUEqxQNeRYd4eDmXPmVWLhGg== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=qRPm4lX07fEjxK0JZRmQQhc/u5fza2uspo7JtzcO95k=; b=DycTbc3yYYQy984UKu7/9vEgITR5bYv+u8R50LBfM6cengfHhab5sVMNogsJ85pf6wYNMUodIZOdGwLGo/pGLkwFkHPyDcV3c6eHnLpOTFBQEL0OxRjKQFX7qSFNz5DDQNWR4UL99X94Tk2BvOQoKQNRUl0brIvFGHwacDIlHg9Pfrg1UFf3fuhfar0kNnxJCOAibUDaCVf+fD51sBT535hOtNLp0VC5qBfyQh05HD6wKW4nJR/l23lN1+VNVk580iG4JiH8aDzBVHk9q0qjZxUuPlrqqma2NIxerkaFJDbdENW8ZB8ntTWaxGZ+hpeCdEqJmIh8V79nl6GgSXg4/Q== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=siemens.com; dmarc=pass action=none header.from=siemens.com; dkim=pass header.d=siemens.com; arc=none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=siemens.com; s=selector2; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=qRPm4lX07fEjxK0JZRmQQhc/u5fza2uspo7JtzcO95k=; b=enOBGMze0rEOwCF/YgcwOpV6yFHHeAyU6tA5xLQ6mvzdWg73kVTzkZWOwAk34VeDCUdMl5bTz12hLPOshanTyPqKQd6u/5JuGB3qqSgH/1m1zw/McYwkrd+81Mlz3kTACOdMohNKF8UdVzRCEl6V9M/33NLU5oJIQCvyiSWSViPDizZ035d2FqXWbd2Z0p+6oZjblwKuyNrjmpHqT2Olk/0Mes11ASK2DWRRR6SM/fTLYfe5snihKJwRNzrPGo7vuHufOgRjrDUrRZ23d56ZBoThXPMSNd1c5m+GyykB6Nzh7RlSfwM5Bz0XOvqh4pnK10W5VHA9idipvYX2Ufg6UQ== Authentication-Results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=siemens.com; Received: from AS4PR10MB6181.EURPRD10.PROD.OUTLOOK.COM (2603:10a6:20b:588::19) by AS5PR10MB8294.EURPRD10.PROD.OUTLOOK.COM (2603:10a6:20b:653::13) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.6363.31; Sun, 7 May 2023 12:11:38 +0000 Received: from AS4PR10MB6181.EURPRD10.PROD.OUTLOOK.COM ([fe80::b50a:c627:3d12:6f04]) by AS4PR10MB6181.EURPRD10.PROD.OUTLOOK.COM ([fe80::b50a:c627:3d12:6f04%5]) with mapi id 15.20.6363.027; Sun, 7 May 2023 12:11:37 +0000 Message-ID: <3516dc21-00ab-3307-376d-612c83770cb4@siemens.com> Date: Sun, 7 May 2023 14:11:29 +0200 User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:102.0) Gecko/20100101 Thunderbird/102.9.1 Subject: Re: [PATCH v3 00/19] Migration to using binman for bootloader Content-Language: en-US To: Neha Malcom Francis Cc: u-boot@lists.denx.de, sjg@chromium.org, afd@ti.com, vigneshr@ti.com, rogerq@kernel.org, alpernebiyasak@gmail.com, nm@ti.com, bb@ti.com, u-kumar1@ti.com, Tom Rini References: <20230421123203.1315330-1-n-francis@ti.com> <20230426223750.GA643785@bill-the-cat> From: Jan Kiszka In-Reply-To: Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit X-ClientProxiedBy: AM0PR01CA0176.eurprd01.prod.exchangelabs.com (2603:10a6:208:aa::45) To AS4PR10MB6181.EURPRD10.PROD.OUTLOOK.COM (2603:10a6:20b:588::19) MIME-Version: 1.0 X-MS-PublicTrafficType: Email X-MS-TrafficTypeDiagnostic: AS4PR10MB6181:EE_|AS5PR10MB8294:EE_ X-MS-Office365-Filtering-Correlation-Id: c57f40f4-c1a0-49a4-71eb-08db4ef434ff X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam: BCL:0; X-Microsoft-Antispam-Message-Info: IQBFEz4biW+3OlCxj5ECtnfiKBGJNEnVLezxo8nkWJnWTU8u3FKUt0A5G7UkciOybD8O2nGQoXmNBVMBW7X2ApMmgZ38+SKLQN6bUcsrxUHTWUMVew3nQaHZaFI9+OBfcvxA3gVlSLmhSyHDvk0ocI9Caz5GRyvjNTd10BV4mWxYiXJYa5qWqY80XADMcPEhTf4r0cyhuR8c9vUvCfjNMESUFtawD1dON1CE8I3xCqQ78Hm0VaZKu61sA868Sh325ml3a34TQKuURaisBtuaeTDZuBdgojBUqWttFxnqa8w/G3yzmolSxE0ddNlYiNjzE1f6hRhIreqjqnuKCEkrCetJ45g/uzNhLR3ZHtnuewcTqwXIVn8G3UE5tXBSD2I+S+GLNJiK5nLybi+/KHL2NJwCRBJHnHFJJUy4SGqNLyDfn5Fa5hqJju5mtJ95rPfSkkyb7y6d681m8Ygjc1LK/C8j5FZwwbmYdoYqVV8cNrahv7W/iUrUIZs+oAVzDJ1azC4P0lqqQZYWa1P5mgl8fFfihPXPatSAe73DWEB3sh3g2ZWccWOnf+ihApWgTZgmndfU5CC+At9v8f5vWc6/ULTo1GCKD70NwESa8TNOeRq6t3F5ptzYXLAr42e6lqVuEeS12R2IMNe/7bVs4l+X695h0ZufHKxIrJ0iI9OJ/IM= X-Forefront-Antispam-Report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:AS4PR10MB6181.EURPRD10.PROD.OUTLOOK.COM; PTR:; CAT:NONE; SFS:(13230028)(4636009)(39860400002)(366004)(346002)(376002)(396003)(136003)(451199021)(83380400001)(2616005)(186003)(2906002)(36756003)(38100700002)(86362001)(31696002)(82960400001)(6486002)(8936002)(8676002)(966005)(316002)(6666004)(41300700001)(7416002)(5660300002)(31686004)(66946007)(6916009)(4326008)(66476007)(66556008)(478600001)(6512007)(6506007)(26005)(44832011)(53546011)(45980500001)(43740500002); DIR:OUT; SFP:1101; X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1 X-MS-Exchange-AntiSpam-MessageData-0: =?utf-8?B?ZTg5M3pPTWtSMXNQdURIcFFKNjA0bG02Wm91RUxsWGRWUUF1Z0VzWmtqV0o1?= =?utf-8?B?RlF3dis0cGFnMUZBdi9jR1JSN0FlR3JDVkl2Rmd3U093dlp3cW95NFJuVlN0?= =?utf-8?B?enpwakJqZmNrd2taTmIwUTRKU3RIWGFTYitFY1J2ZmRtWkIzNURnOTBZeDY4?= =?utf-8?B?emNnTVdVUFBNbmtYYkJuK296djFOMU5ZOE83cm5Gb0pJVXl4b0R2czRHUlJ3?= =?utf-8?B?bytTdU9nU2xGOStTbXo2VGtVamppdUV4Vi9XU0Vtcm1TbWR1MUhmUVhnb0pM?= =?utf-8?B?TFZwYWJ0Q1BWVnhoaXRrVmRGZEh2SEFmZUpNUHJDMlBpS0pVaTJwbWtJZ096?= =?utf-8?B?eCszaVZFbms5SGJ0dVJyWFRVMTNFVSt0cFIrTXRkeWdLMDJuY2JqUXBnY2pR?= =?utf-8?B?WXYyN3J3NmJYaU40ZFJXeDNPM1JrVFBkc0lCZ1RyanpJb3RYRTBHN0srb0hU?= =?utf-8?B?dUY5SjRPOHpObkI3aUxuSUh1ay8wWG9YQTkxWkhVL20wR0lWbk1aWE1EVHVh?= =?utf-8?B?SnBhNkhCS1RSQWZ5aWtSY0ZBcDJqZGZjMFI5ME5hTFVGZVZWSFJTeVlNK1Zw?= =?utf-8?B?UDlkdFJWR0N2RlFQd3pxYjlYd2FpUG5uT1R6citMRG9HN1J0a1VPdTVjdVZn?= =?utf-8?B?b2NzbHVoZURWd3NxSlNpMytvUURhWXQvVGx5b1RZVFNuWlVHRFI2Rk9RRUFr?= =?utf-8?B?YWhCVkIrWkE1VThnT3QzSS9mRWlBVDhCc0RySEIxOHRDS00vQXlLOFE5L091?= =?utf-8?B?eVBESzFRTW9pNDlaY1QxdEVkZVhJV0krQTV5U2ZvQWVEdmNOQ2kyTGp4UW00?= =?utf-8?B?QWVqYUZoLzBxSGhYWWZIanhlRTNNZTg2cnpnL0FkMmJtNXJDOGlQOEIzbm5J?= =?utf-8?B?OGdvSmxFZm44RFc0YnliR3lGZ0pLZjlKeDhiTXVncXBkL2w2OEFXODNld3l5?= =?utf-8?B?WitkdHVqRGZJMXR4RzhjUnNvdkJPelE3OWVyQU4zWGEvR2V6ZnJNUXpKN3p5?= =?utf-8?B?dzFwMmlNSmtWZnFnbmsxcE1UMmxOWnEzWXliKzlpMnFJVHBIOFErK2ZyaUx5?= =?utf-8?B?YVI4Z3oyd2pKQkFjcEp6eWw5ZFNzTmlzZlFjSC9GYkpDd1hMNzRKT2Y0SCs2?= =?utf-8?B?eTJCNVh5L0l6dUJEZkxPWnozSUtCNHVjbGVUZm9pQnNrbVFvV1luWGtLbkJj?= =?utf-8?B?MkJuMy85UjluM04rZ1RzSHl6K3NRMHpVdG85WkpUbDJ1OGYxL05TMmtkbmVH?= =?utf-8?B?V3gwRnNDeGl2MzJoRHdqRXlSRmplNHJKVS9Pa2trWEZvYWo2T2xsRDJSUFdD?= =?utf-8?B?c25WcXNUUGdLNm9QOUZoNWlqbVFWaTRtTVA1QnhoSGtBaUFsUEVGRnhIakFP?= =?utf-8?B?U0hhUDdQeXQ0R0JEZjlHd1duT1AyVnBlTUpFTjVRTDJqc2NkVzJnSWs5MkJt?= =?utf-8?B?UlNJSktuUkJNd213aTR2WnRxMlordXFDSE9PRTFCcDU0cDZMRHJPVkJVQmgw?= =?utf-8?B?M1YxeXFzUWlVT1pDditXcXg2dGQxNklGSGxobS9YNVo4T1d4djVTRmpJSkNC?= =?utf-8?B?ZG5hN2JIUnV2SWtreGdoYXJISVJlQThCVzZYUlBHalBCYVNONUEyd3RVZEcy?= =?utf-8?B?My9MN2dCQWhCaUF2R1lwNHdKOW9DYUphLzRFakIzem1kSVZpdDV3YVp4TlpR?= =?utf-8?B?bTQxM2JKUEREN01QbWZuME8vYnBZbEQ4RzRMV3M1aURuR3Nnb3NQRkVoZktP?= =?utf-8?B?b0RYdGhXT09GOG1oUFZNVExHdzJsTkhpQW5KR2NZZnArQXJjSVVSZzAvNEQv?= =?utf-8?B?TVB3RHlwM09vUjQ4K2g5amxLZEt0L0xrVncvbWtIbVRQcm9qUENnN0lpdGNO?= =?utf-8?B?dlFWYVJHLzFBS3ZpQkhpbzVZZjNORTZsdEV1QkU0M0g1RXQzUWZRbk5rSXFp?= =?utf-8?B?QTdoNFFJbi9QMno2cG0xVStKTVBIL1hwT2VMNTRxQWJDSk1xSUUyL2hHZDhN?= =?utf-8?B?YVRBNWljMjh4YVlRQUdvU3BhN1ZRdU9rV3hKWURXemRXTEZyLy83MndKcWdJ?= =?utf-8?B?eWl4ZW5ObGtVSTZJNGI5aEhuMHpuQ3paL1RYSU02ZThXaE9DZGU0aDFrcll3?= =?utf-8?Q?9FUs2haXFoIjneJ1cvBJJh+ZF?= X-OriginatorOrg: siemens.com X-MS-Exchange-CrossTenant-Network-Message-Id: c57f40f4-c1a0-49a4-71eb-08db4ef434ff X-MS-Exchange-CrossTenant-AuthSource: AS4PR10MB6181.EURPRD10.PROD.OUTLOOK.COM X-MS-Exchange-CrossTenant-AuthAs: Internal X-MS-Exchange-CrossTenant-OriginalArrivalTime: 07 May 2023 12:11:37.5807 (UTC) X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted X-MS-Exchange-CrossTenant-Id: 38ae3bcd-9579-4fd4-adda-b42e1495d55a X-MS-Exchange-CrossTenant-MailboxType: HOSTED X-MS-Exchange-CrossTenant-UserPrincipalName: uAgQNl32m2c98B6PnkZ52b/E0Jpj+V3F1Gqhgpaif2wc71aGqhL/PWUADS2hgJNweeOPW/P/RSHhHlxd3v7snw== X-MS-Exchange-Transport-CrossTenantHeadersStamped: AS5PR10MB8294 X-BeenThere: u-boot@lists.denx.de X-Mailman-Version: 2.1.39 Precedence: list List-Id: U-Boot discussion List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: u-boot-bounces@lists.denx.de Sender: "U-Boot" X-Virus-Scanned: clamav-milter 0.103.8 at phobos.denx.de X-Virus-Status: Clean On 04.05.23 08:13, Neha Malcom Francis wrote: > Hi Jan > > On 04/05/23 10:13, Neha Malcom Francis wrote: >> Hi Jan, >> >> On 03/05/23 22:04, Jan Kiszka wrote: >>> On 03.05.23 14:56, Neha Malcom Francis wrote: >>>> Hi Jan, >>>> >>>> On 03/05/23 12:57, Neha Malcom Francis wrote: >>>>> Hi Tom >>>>> >>>>> On 27/04/23 04:07, Tom Rini wrote: >>>>>> On Fri, Apr 21, 2023 at 06:01:44PM +0530, Neha Malcom Francis wrote: >>>>>> >>>>>>> This series aims to eliminate the use of additional custom >>>>>>> repositories >>>>>>> such as k3-image-gen (K3 Image Generation) repo and >>>>>>> core-secdev-k3 (K3 >>>>>>> Security Development Tools) that was plumbed into the U-Boot >>>>>>> build flow >>>>>>> to generate boot images for TI K3 platform devices. And instead, we >>>>>>> move >>>>>>> towards using binman that aligns better with the community standard >>>>>>> build >>>>>>> flow. >>>>>>> >>>>>>> This series uses binman for all K3 platforms supported on U-Boot >>>>>>> currently; >>>>>>> both HS (High Security, both SE and FS) and GP (General Purpose) >>>>>>> devices. >>>>>>> >>>>>>> Background on using k3-image-gen: >>>>>>>      * TI K3 devices require a SYSFW (System Firmware) image >>>>>>> consisting >>>>>>>      of a signed system firmware image and board configuration >>>>>>> binaries, >>>>>>>      this is needed to bring up system firmware during U-Boot R5 SPL >>>>>>>      startup. >>>>>>>      * Board configuration data contain board-specific information >>>>>>>      such as resource management, power management and security. >>>>>>> >>>>>>> Background on using core-secdev-k3: >>>>>>>      * Contains resources to sign x509 certificates for HS devices >>>>>>> >>>>>>> Series intends to use binman to take over the packaging and >>>>>>> signing for >>>>>>> the R5 bootloader images tiboot3.bin (and sysfw.itb, for >>>>>>> non-combined >>>>>>> boot flow) instead of k3-image-gen. >>>>>>> >>>>>>> Series also packages the A72/A53 bootloader images (tispl.bin and >>>>>>> u-boot.img) using ATF, OPTEE and DM (Device Manager) >>>>>> >>>>>> So, next up is fixing this in CI. After taking Andrew's patch to >>>>>> fix the >>>>>> typedef issue, and after my patches to ensure we can get >>>>>> pyyaml/jsonschema for python, there's problems still: >>>>> >>>>> >>>>> Thanks for checking this! Couple things: >>>>> >>>>>> Over at https://source.denx.de/u-boot/u-boot/-/jobs/617966: >>>>>> binman: Filename 'spl/dts/k3-am68-sk-base-board.dtb' not found in >>>>>> input >>>>>> path (.,/builds/u-boot/u-boot,board/ti/j721s2,arch/arm/dts) >>>>>> (cwd='/tmp/.bm-work/j721s2_hs_evm_a72') >>>>> >>>>> 1. This is dependent on the patch merging J721S2 HS and GP configs >>>>> [1]. However it has been reverted on -next, seen in the same thread. >>>>> >>>>>> >>>>>> And then: >>>>>> https://source.denx.de/u-boot/u-boot/-/jobs/617965#L1328 >>>>>> Error: arch/arm/dts/k3-am62a-sk-binman.dtsi:167.1-8 syntax error >>>>>> I've fixed this, minor but serious change. >>>>> >>>>> 2. Regarding iot2050, build fails since it uses >>>>> arch/arm/mach-k3/config.mk which is now entirely binman based. Will >>>>> try moving iot2050 to binman as well. >>>> >>>> I'll need some help with this, might need to know the bootloader >>>> flow to >>>> make a clean migration. >>> >>> Where do I have to look at? Is there a git repo with that experiment >>> somewhere? >>> >>> Jan >>> >> >> There's no experiment yet, I will send one today; but I do not have >> complete understanding of the booting; whether the tispl.bin (which I >> assume is the only boot component that is affecting iot2050 boot since >> k3_fit_atf.sh is no longer there) has any concept of signing? Is >> core-secdev-k3 ever used? >> > > I have a tree posted here [2] that builds flash.bin with no error for > me. Please confirm whether your build flow does the same and also let me > know if the binary actually boots. > > [2] > https://github.com/nehamalcom/u-boot/tree/migration-to-binman-cicd-iot2050 > I've tested the latest version in that branch in the meantime. It compiles but it does not work. This is missing from the original script: diff --git a/arch/arm/dts/k3-am65-iot2050-boot-image.dtsi b/arch/arm/dts/k3-am65-iot2050-boot-image.dtsi index e17ffd7481f..9d83898d33f 100644 --- a/arch/arm/dts/k3-am65-iot2050-boot-image.dtsi +++ b/arch/arm/dts/k3-am65-iot2050-boot-image.dtsi @@ -92,6 +92,15 @@ }; }; }; + + configurations { + default = "spl"; + spl { + fdt = "fdt-0"; + firmware = "atf"; + loadables = "tee", "dm", "spl"; + }; + }; }; fit@0x380000 { I didn't test secure booting yet, though. We are currently still signing via tools/iot2050-sign-fw.sh, partly due to missing features in binman (there were a lot of proposals on the list recently, may that is solved now), but partly also due to some remaining breakages. Jan -- Siemens AG, Technology Competence Center Embedded Linux