From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from phobos.denx.de (phobos.denx.de [85.214.62.61]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.lore.kernel.org (Postfix) with ESMTPS id D9871CD128A for ; Wed, 10 Apr 2024 18:29:29 +0000 (UTC) Received: from h2850616.stratoserver.net (localhost [IPv6:::1]) by phobos.denx.de (Postfix) with ESMTP id 500A188149; Wed, 10 Apr 2024 20:29:28 +0200 (CEST) Authentication-Results: phobos.denx.de; dmarc=pass (p=quarantine dis=none) header.from=ti.com Authentication-Results: phobos.denx.de; spf=pass smtp.mailfrom=u-boot-bounces@lists.denx.de Authentication-Results: phobos.denx.de; dkim=pass (1024-bit key; unprotected) header.d=ti.com header.i=@ti.com header.b="MHY6oHKf"; dkim-atps=neutral Received: by phobos.denx.de (Postfix, from userid 109) id 578C6881BC; Wed, 10 Apr 2024 20:24:33 +0200 (CEST) Received: from fllv0016.ext.ti.com (fllv0016.ext.ti.com [198.47.19.142]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by phobos.denx.de (Postfix) with ESMTPS id 1845D870AB for ; Wed, 10 Apr 2024 20:24:30 +0200 (CEST) Authentication-Results: phobos.denx.de; dmarc=pass (p=quarantine dis=none) header.from=ti.com Authentication-Results: phobos.denx.de; spf=pass smtp.mailfrom=j-humphreys@ti.com Received: from fllv0035.itg.ti.com ([10.64.41.0]) by fllv0016.ext.ti.com (8.15.2/8.15.2) with ESMTP id 43AION8n126273; Wed, 10 Apr 2024 13:24:23 -0500 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ti.com; s=ti-com-17Q1; t=1712773463; bh=i5cY5MmUSl0E+QRH1H7hzhmlWqWF/3L/Wg0CsYE/+dY=; h=From:To:CC:Subject:In-Reply-To:References:Date; b=MHY6oHKfZ4ZnTeurnSuCi+dgj4vN6NOhk41hVRVG13xcxbbS4F0YveJMMVkb9955d 6Pg1a0Smt1wAu5JwI0gc+7P029pqrZtivqNG5krKnqMQ7MI8PhdWJZ7vJIWJshbMzn k0f1sK/BrIyAo1VdLYxxTpoEcsZWMLvwmYa6ME1Q= Received: from DFLE106.ent.ti.com (dfle106.ent.ti.com [10.64.6.27]) by fllv0035.itg.ti.com (8.15.2/8.15.2) with ESMTPS id 43AION21038679 (version=TLSv1.2 cipher=AES256-GCM-SHA384 bits=256 verify=FAIL); Wed, 10 Apr 2024 13:24:23 -0500 Received: from DFLE101.ent.ti.com (10.64.6.22) by DFLE106.ent.ti.com (10.64.6.27) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256_P256) id 15.1.2507.23; Wed, 10 Apr 2024 13:24:22 -0500 Received: from lelvsmtp6.itg.ti.com (10.180.75.249) by DFLE101.ent.ti.com (10.64.6.22) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256_P256) id 15.1.2507.23 via Frontend Transport; Wed, 10 Apr 2024 13:24:22 -0500 Received: from localhost (udb0321960.dhcp.ti.com [128.247.81.241]) by lelvsmtp6.itg.ti.com (8.15.2/8.15.2) with ESMTP id 43AIOMXD056889; Wed, 10 Apr 2024 13:24:22 -0500 From: Jon Humphreys To: Andrew Davis , Mattijs Korpershoek , Roger Quadros , "Kamlesh Gurudasani" , Manorit Chawdhry , "Simon Glass" , Neha Malcom Francis , "Bryan Brattlof" , Robert Nelson , "Nishanth Menon" , Tom Rini CC: Subject: Re: [PATCH 3/7] dts: j721e: binman: Include firmware capsules binman nodes In-Reply-To: <3b054817-8b1b-459f-b38e-70620bfd9b28@ti.com> References: <20240408221735.164871-1-j-humphreys@ti.com> <20240408221735.164871-4-j-humphreys@ti.com> <3b054817-8b1b-459f-b38e-70620bfd9b28@ti.com> Date: Wed, 10 Apr 2024 13:24:22 -0500 Message-ID: <86ttk9yt2h.fsf@udb0321960.dhcp.ti.com> MIME-Version: 1.0 Content-Type: text/plain X-EXCLAIMER-MD-CONFIG: e1e8a2fd-e40a-4ac6-ac9b-f7e9cc9ee180 X-Mailman-Approved-At: Wed, 10 Apr 2024 20:29:27 +0200 X-BeenThere: u-boot@lists.denx.de X-Mailman-Version: 2.1.39 Precedence: list List-Id: U-Boot discussion List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: u-boot-bounces@lists.denx.de Sender: "U-Boot" X-Virus-Scanned: clamav-milter 0.103.8 at phobos.denx.de X-Virus-Status: Clean Andrew Davis writes: > On 4/8/24 5:17 PM, Jonathan Humphreys wrote: >> Signed-off-by: Jonathan Humphreys >> --- >> arch/arm/dts/k3-j721e-binman.dtsi | 32 +++++++++++++++++++++++++++++++ >> 1 file changed, 32 insertions(+) >> >> diff --git a/arch/arm/dts/k3-j721e-binman.dtsi b/arch/arm/dts/k3-j721e-binman.dtsi >> index 75a6e9599b9..9169551c422 100644 >> --- a/arch/arm/dts/k3-j721e-binman.dtsi >> +++ b/arch/arm/dts/k3-j721e-binman.dtsi >> @@ -207,6 +207,29 @@ >> }; >> }; >> }; >> + >> +#include "k3-binman-capsule-r5.dtsi" >> + >> +// Capsue update GUIDs. See ti_armv7_common.h. >> +#define K3_SYSFW_IMAGE_UUID_STR "6fd10680-361b-431f-80aa-899455819e11" >> + >> +&binman { >> + capsule-sysfw { >> + filename = "sysfw-capsule.bin"; >> + efi-capsule { >> + image-index = <0x4>; >> + image-guid = K3_SYSFW_IMAGE_UUID_STR; >> + private-key = "arch/arm/mach-k3/keys/custMpk.pem"; >> + public-key-cert = "arch/arm/mach-k3/keys/custMpk.crt"; >> + monotonic-count = <0x1>; >> + >> + blob { >> + filename = "sysfw.itb"; >> + }; >> + }; >> + }; >> +}; >> + >> #endif >> >> #ifdef CONFIG_TARGET_J721E_A72_EVM >> @@ -585,4 +608,13 @@ >> }; >> }; >> }; >> + >> +#include "k3-binman-capsule.dtsi" >> +&tispl_name { >> + filename = "tispl.bin_unsigned"; > > Why use the _unsigned images here? HS devices cannot boot unsigned GP images, > but both GP and HS devices *can* boot the normal signed images (GP just strips > the signatures off). So no need to use the _unsigned images anymore (I'm > planning to just remove them at some point to prevent this confusion). > I can do that. Note that you will then see warnings on GP devices during boot: Warning: Detected image signing certificate on GP device. Skipping certificate to prevent boot failure. This will fail if the image was also encrypted Jon > Andrew > >> +}; >> +&uboot_name { >> + filename = "u-boot.img_unsigned"; >> +}; >> + >> #endif