All of lore.kernel.org
 help / color / mirror / Atom feed
From: Detlev Zundel <dzu@denx.de>
To: u-boot@lists.denx.de
Subject: [U-Boot] how to get u-boot code with arm64: core support
Date: Thu, 23 Jan 2014 16:58:14 +0100	[thread overview]
Message-ID: <m2d2jizo4p.fsf@lamuella.denx.de> (raw)
In-Reply-To: <0c84fe49dcae45249138a2b1ced36294@BN1PR03MB220.namprd03.prod.outlook.com> (bhupesh's message of "Thu, 23 Jan 2014 07:15:08 +0000")

Hi Bhupesh,

>> -----Original Message-----
>> From: u-boot-bounces at lists.denx.de [mailto:u-boot-bounces at lists.denx.de]
>> On Behalf Of drambo
>> Sent: Thursday, January 23, 2014 12:32 AM
>> To: u-boot at lists.denx.de
>> Subject: Re: [U-Boot] how to get u-boot code with arm64: core support
>> 
>> Hi Bhupesh,
>> 
>> > U-boot doesn't have ARM trusted firmware support as of now. U-boot for
>> > ARMv8 starts in EL3, whereas UEFI starts in EL2 as trusted firmware
>> > itself is working in EL3.
>> 
>> Since the ATF software doesn't really care whether it is loading uefi or
>> u-boot and since it wants to load non-secure images as EL2 or EL1
>> (https://github.com/ARM-software/arm-trusted-
>> firmware/blob/master/docs/user-guide.md
>> See section "Normal World Software Execution"), why would we want to
>> assume u-boot starts in EL3 mode by default?
>> 
>> If we want to support EL3 execution for convenience to those that don't
>> have ATF setup, that might make sense, but then shouldn't initial EL3
>> execution and subsequent switching levels be debug CONFIG options?
>> Thanks.
>> 
>
> In the past I remember using u-boot as the bare-metal s/w to debug a
> Silicon without any BootROM/firmware code running before the same on
> ARM 32-bit architectures.

Many of our customers (in the embedded market) use U-Boot in such a way
very successfully.

> The ATF is presently tested only for UEFI and UEFI comes up in EL2
> while the ATF itself is running in EL3.
>
> I don't know what would be the popular vote on this, but personally I
> feel that the u-boot for ARMv8 should also be launched by the ATF
> (similar to UEFI) and should start execution in EL2 so that it can
> launch a hypervisor (running in EL2) or Linux (running in EL1).  But
> this might hurt the popular premise that u-boot can be used as a
> bare-metal s/w to debug a silicon without additional firmware
> components.
>
> Perhaps u-boot experts can guide us on this !

I have to admit that I'm only reading up on the complexities of the
security model of aarch64, but my gut response (cf. [1] is that "real
security" stems from "few code" rather than adding layer over layer.
With this in mind, I'd really like to see that U-Boot with its well
known and tested code base can still be the "root of trust" in an
embedded product (i.e. EL3 as far as I understand).

Many of the embedded U-Boot users who excercise full control over the
whole software stack very likely want to see the same.

The interesting question will be if we can reconcile the requirements of
"classic embedded U-Boot users" and this "OEM server market" that seems
to drive much of these new concepts here.  But I sincerely hope so.
After all, in the end we want to boot an OS to get the real work done ;)

Best wishes
  Detlev

[1] Reading one presentation I found about ATF[2] actually made my head
    hurt around page 12 which looks more like "security soup" than
    clearcut concepts, but maybe I'm just not into all the details yet.

[2] http://lcu-13.zerista.com/event/member/85121

-- 
Our choice isn't between a digital world where the NSA can eavesdrop and one
where the NSA is prevented from eavesdropping; it's between a digital world
that is vulnerable to allattackers, and one that is secure for all users.
                              -- Bruce Schneier
--
DENX Software Engineering GmbH,      MD: Wolfgang Denk & Detlev Zundel
HRB 165235 Munich,  Office: Kirchenstr.5, D-82194 Groebenzell, Germany
Phone: (+49)-8142-66989-40 Fax: (+49)-8142-66989-80 Email: dzu at denx.de

  parent reply	other threads:[~2014-01-23 15:58 UTC|newest]

Thread overview: 60+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2013-11-15  3:45 [U-Boot] [PATCH v15 00/10] arm64 patch fenghua at phytium.com.cn
2013-11-15  3:45 ` [U-Boot] [PATCH v15 01/10] fdt_support: 64bit initrd start address support fenghua at phytium.com.cn
2013-11-15  3:45   ` [U-Boot] [PATCH v15 02/10] cmd_pxe: remove compiling warnings fenghua at phytium.com.cn
2013-11-15  3:45     ` [U-Boot] [PATCH v15 03/10] add weak entry definition fenghua at phytium.com.cn
2013-11-15  3:45       ` [U-Boot] [PATCH v15 04/10] arm64: Add tool to statically apply RELA relocations fenghua at phytium.com.cn
2013-11-15  3:45         ` [U-Boot] [PATCH v15 05/10] arm64: Turn u-boot.bin back into an ELF file after relocate-rela fenghua at phytium.com.cn
2013-11-15  3:45           ` [U-Boot] [PATCH v15 06/10] arm64: Make checkarmreloc accept arm64 relocations fenghua at phytium.com.cn
2013-11-15  3:45             ` [U-Boot] [PATCH v15 07/10] arm64: core support fenghua at phytium.com.cn
2013-11-15  3:45               ` [U-Boot] [PATCH v15 08/10] arm64: generic board support fenghua at phytium.com.cn
2013-11-15  3:45                 ` [U-Boot] [PATCH v15 09/10] arm64: board support of vexpress_aemv8a fenghua at phytium.com.cn
2013-11-15  3:45                   ` [U-Boot] [PATCH v15 10/10] arm64: MAKEALL, filter armv8 boards from LIST_arm fenghua at phytium.com.cn
2013-11-27 20:38               ` [U-Boot] [PATCH v15 07/10] arm64: core support Bhupesh SHARMA
2013-11-29 13:35                 ` FengHua
2013-11-30 18:44                   ` Bhupesh Sharma
     [not found]                     ` <bcf7ed.a55.142ae85d276.Coremail.fenghua@phytium.com.cn>
2013-12-03 10:02                       ` Bhupesh Sharma
2014-01-13 11:24                         ` bhupesh.sharma at freescale.com
2014-01-14  1:52                           ` FengHua
2014-01-23  0:28                             ` Scott Wood
2014-01-23  1:06                               ` drambo
2014-01-24  1:20                               ` FengHua
2014-01-09  9:49               ` [U-Boot] how to get u-boot code with " TigerLiu at viatech.com.cn
2014-01-11  6:44                 ` FengHua
2014-01-11  6:50                   ` Jagan Teki
2014-01-13  0:54                     ` TigerLiu at viatech.com.cn
2014-01-14  9:12                   ` TigerLiu at viatech.com.cn
2014-01-15  6:37                     ` Wolfgang Denk
2014-01-15 11:27                       ` Abraham Varricatt
2014-01-15 12:25                         ` Wolfgang Denk
2014-01-20 10:54                 ` TigerLiu at viatech.com.cn
2014-01-20 11:57                   ` bhupesh.sharma at freescale.com
2014-01-21  0:49                     ` TigerLiu at viatech.com.cn
2014-01-22 19:02                     ` drambo
2014-01-23  7:15                       ` bhupesh.sharma at freescale.com
2014-01-23  7:54                         ` TigerLiu at viatech.com.cn
2014-02-11 13:33                           ` bhupesh.sharma at freescale.com
2014-02-12  2:08                             ` TigerLiu at viatech.com.cn
2014-02-12  7:15                               ` bhupesh.sharma at freescale.com
2014-02-12  7:26                                 ` TigerLiu at viatech.com.cn
2014-02-12  7:52                               ` Inderpal Singh
2014-02-12  8:02                                 ` TigerLiu at viatech.com.cn
2014-02-12  8:06                                   ` Inderpal Singh
2014-02-12  8:14                                     ` TigerLiu at viatech.com.cn
2014-02-12  8:25                                       ` bhupesh.sharma at freescale.com
2014-02-12  9:37                                         ` Inderpal Singh
2014-01-23 15:58                         ` Detlev Zundel [this message]
2014-01-23 17:04                           ` Darwin Rambo
2014-01-25 19:46                             ` bhupesh.sharma at freescale.com
2014-01-26  1:42                               ` drambo
2013-12-11 21:14 ` [U-Boot] [PATCH v15 00/10] arm64 patch Albert ARIBAUD
  -- strict thread matches above, loose matches on Subject: below --
2014-01-14 10:43 [U-Boot] how to get u-boot code with arm64: core support TigerLiu at viatech.com.cn
2014-01-14 10:47 ` bhupesh.sharma at freescale.com
2014-01-14 11:02   ` TigerLiu at viatech.com.cn
2014-01-14 11:10   ` TigerLiu at viatech.com.cn
2014-01-14 11:13     ` bhupesh.sharma at freescale.com
2014-01-14 11:21       ` TigerLiu at viatech.com.cn
2014-01-14 11:23         ` bhupesh.sharma at freescale.com
2014-01-14 11:37           ` TigerLiu at viatech.com.cn
2014-01-14 20:09           ` Scott Wood
2014-01-15  0:45             ` TigerLiu at viatech.com.cn
2014-01-15  5:02               ` FengHua

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=m2d2jizo4p.fsf@lamuella.denx.de \
    --to=dzu@denx.de \
    --cc=u-boot@lists.denx.de \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.