From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from phobos.denx.de (phobos.denx.de [85.214.62.61]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.lore.kernel.org (Postfix) with ESMTPS id 33C15C7EE21 for ; Thu, 4 May 2023 06:13:32 +0000 (UTC) Received: from h2850616.stratoserver.net (localhost [IPv6:::1]) by phobos.denx.de (Postfix) with ESMTP id 1C272847BC; Thu, 4 May 2023 08:13:30 +0200 (CEST) Authentication-Results: phobos.denx.de; dmarc=pass (p=quarantine dis=none) header.from=ti.com Authentication-Results: phobos.denx.de; spf=pass smtp.mailfrom=u-boot-bounces@lists.denx.de Authentication-Results: phobos.denx.de; dkim=pass (1024-bit key; unprotected) header.d=ti.com header.i=@ti.com header.b="Q4cAKr30"; dkim-atps=neutral Received: by phobos.denx.de (Postfix, from userid 109) id 44756847CA; Thu, 4 May 2023 08:13:29 +0200 (CEST) Received: from lelv0143.ext.ti.com (lelv0143.ext.ti.com [198.47.23.248]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by phobos.denx.de (Postfix) with ESMTPS id C8B9F847AF for ; Thu, 4 May 2023 08:13:25 +0200 (CEST) Authentication-Results: phobos.denx.de; dmarc=pass (p=quarantine dis=none) header.from=ti.com Authentication-Results: phobos.denx.de; spf=pass smtp.mailfrom=n-francis@ti.com Received: from lelv0266.itg.ti.com ([10.180.67.225]) by lelv0143.ext.ti.com (8.15.2/8.15.2) with ESMTP id 3446DJUv130750; Thu, 4 May 2023 01:13:19 -0500 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ti.com; s=ti-com-17Q1; t=1683180799; bh=4RvN7xdET28s7ffs2ZJ8joStWCLnPo5ycEkz8Th5Uhk=; h=Date:Subject:From:To:CC:References:In-Reply-To; b=Q4cAKr30ysHFHob+Dav0CHeOHSGJxlBV1T0mNRJYJ6CxTXqsVkiRA+qa1kBDct7a2 alxTxHG9vyjbJ2hyjqqSgKb2A0c2F27YxoZg3I8Tp7Q5zeY9wl8GagYPi6EtGAO9Lu 33PpeijHbc0sgFWAUbg546C6Ud02koDLoc0xvF1s= Received: from DLEE115.ent.ti.com (dlee115.ent.ti.com [157.170.170.26]) by lelv0266.itg.ti.com (8.15.2/8.15.2) with ESMTPS id 3446DJb6031497 (version=TLSv1.2 cipher=AES256-GCM-SHA384 bits=256 verify=FAIL); Thu, 4 May 2023 01:13:19 -0500 Received: from DLEE107.ent.ti.com (157.170.170.37) by DLEE115.ent.ti.com (157.170.170.26) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256_P256) id 15.1.2507.23; Thu, 4 May 2023 01:13:19 -0500 Received: from fllv0039.itg.ti.com (10.64.41.19) by DLEE107.ent.ti.com (157.170.170.37) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256_P256) id 15.1.2507.23 via Frontend Transport; Thu, 4 May 2023 01:13:19 -0500 Received: from [172.24.145.195] (ileaxei01-snat2.itg.ti.com [10.180.69.6]) by fllv0039.itg.ti.com (8.15.2/8.15.2) with ESMTP id 3446DFSw124314; Thu, 4 May 2023 01:13:16 -0500 Message-ID: Date: Thu, 4 May 2023 11:43:15 +0530 MIME-Version: 1.0 User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:102.0) Gecko/20100101 Thunderbird/102.10.0 Subject: Re: [PATCH v3 00/19] Migration to using binman for bootloader Content-Language: en-US From: Neha Malcom Francis To: Jan Kiszka CC: , , , , , , , , , Tom Rini References: <20230421123203.1315330-1-n-francis@ti.com> <20230426223750.GA643785@bill-the-cat> In-Reply-To: Content-Type: text/plain; charset="UTF-8"; format=flowed Content-Transfer-Encoding: 8bit X-EXCLAIMER-MD-CONFIG: e1e8a2fd-e40a-4ac6-ac9b-f7e9cc9ee180 X-BeenThere: u-boot@lists.denx.de X-Mailman-Version: 2.1.39 Precedence: list List-Id: U-Boot discussion List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: u-boot-bounces@lists.denx.de Sender: "U-Boot" X-Virus-Scanned: clamav-milter 0.103.8 at phobos.denx.de X-Virus-Status: Clean Hi Jan On 04/05/23 10:13, Neha Malcom Francis wrote: > Hi Jan, > > On 03/05/23 22:04, Jan Kiszka wrote: >> On 03.05.23 14:56, Neha Malcom Francis wrote: >>> Hi Jan, >>> >>> On 03/05/23 12:57, Neha Malcom Francis wrote: >>>> Hi Tom >>>> >>>> On 27/04/23 04:07, Tom Rini wrote: >>>>> On Fri, Apr 21, 2023 at 06:01:44PM +0530, Neha Malcom Francis wrote: >>>>> >>>>>> This series aims to eliminate the use of additional custom >>>>>> repositories >>>>>> such as k3-image-gen (K3 Image Generation) repo and core-secdev-k3 >>>>>> (K3 >>>>>> Security Development Tools) that was plumbed into the U-Boot build >>>>>> flow >>>>>> to generate boot images for TI K3 platform devices. And instead, we >>>>>> move >>>>>> towards using binman that aligns better with the community standard >>>>>> build >>>>>> flow. >>>>>> >>>>>> This series uses binman for all K3 platforms supported on U-Boot >>>>>> currently; >>>>>> both HS (High Security, both SE and FS) and GP (General Purpose) >>>>>> devices. >>>>>> >>>>>> Background on using k3-image-gen: >>>>>>      * TI K3 devices require a SYSFW (System Firmware) image >>>>>> consisting >>>>>>      of a signed system firmware image and board configuration >>>>>> binaries, >>>>>>      this is needed to bring up system firmware during U-Boot R5 SPL >>>>>>      startup. >>>>>>      * Board configuration data contain board-specific information >>>>>>      such as resource management, power management and security. >>>>>> >>>>>> Background on using core-secdev-k3: >>>>>>      * Contains resources to sign x509 certificates for HS devices >>>>>> >>>>>> Series intends to use binman to take over the packaging and >>>>>> signing for >>>>>> the R5 bootloader images tiboot3.bin (and sysfw.itb, for non-combined >>>>>> boot flow) instead of k3-image-gen. >>>>>> >>>>>> Series also packages the A72/A53 bootloader images (tispl.bin and >>>>>> u-boot.img) using ATF, OPTEE and DM (Device Manager) >>>>> >>>>> So, next up is fixing this in CI. After taking Andrew's patch to >>>>> fix the >>>>> typedef issue, and after my patches to ensure we can get >>>>> pyyaml/jsonschema for python, there's problems still: >>>> >>>> >>>> Thanks for checking this! Couple things: >>>> >>>>> Over at https://source.denx.de/u-boot/u-boot/-/jobs/617966: >>>>> binman: Filename 'spl/dts/k3-am68-sk-base-board.dtb' not found in >>>>> input >>>>> path (.,/builds/u-boot/u-boot,board/ti/j721s2,arch/arm/dts) >>>>> (cwd='/tmp/.bm-work/j721s2_hs_evm_a72') >>>> >>>> 1. This is dependent on the patch merging J721S2 HS and GP configs >>>> [1]. However it has been reverted on -next, seen in the same thread. >>>> >>>>> >>>>> And then: >>>>> https://source.denx.de/u-boot/u-boot/-/jobs/617965#L1328 >>>>> Error: arch/arm/dts/k3-am62a-sk-binman.dtsi:167.1-8 syntax error >>>>> I've fixed this, minor but serious change. >>>> >>>> 2. Regarding iot2050, build fails since it uses >>>> arch/arm/mach-k3/config.mk which is now entirely binman based. Will >>>> try moving iot2050 to binman as well. >>> >>> I'll need some help with this, might need to know the bootloader flow to >>> make a clean migration. >> >> Where do I have to look at? Is there a git repo with that experiment >> somewhere? >> >> Jan >> > > There's no experiment yet, I will send one today; but I do not have > complete understanding of the booting; whether the tispl.bin (which I > assume is the only boot component that is affecting iot2050 boot since > k3_fit_atf.sh is no longer there) has any concept of signing? Is > core-secdev-k3 ever used? > I have a tree posted here [2] that builds flash.bin with no error for me. Please confirm whether your build flow does the same and also let me know if the binary actually boots. [2] https://github.com/nehamalcom/u-boot/tree/migration-to-binman-cicd-iot2050 -- Thanking You Neha Malcom Francis