public inbox for u-boot@lists.denx.de
 help / color / mirror / Atom feed
From: Wolfgang Denk <wd@denx.de>
To: u-boot@lists.denx.de
Subject: [U-Boot-Users] flash hardware protection with CFI driver does not autoprotect monitor completely
Date: Sun, 18 Nov 2007 20:31:05 +0100	[thread overview]
Message-ID: <20071118193105.53B58243A9@gemini.denx.de> (raw)
In-Reply-To: Your message of "Sun, 18 Nov 2007 19:59:54 +0100." <200711181959.55060.matthias.fuchs@esd-electronics.com>

In message <200711181959.55060.matthias.fuchs@esd-electronics.com> you wrote:
> 
> I noticed that the monitor flash autoprotection from drivers/cfi_flash.c is not completely safe.
> It does not protect all bootloader sectors in some situations:
...
> Question: what's the best way to fix this? We could modify the call to flash_protect()

The bst way is to make sure that all sectors that need to be protected
do get protected.

> like this:
> 
> 	flash_protect (FLAG_PROTECT_SET,
> 		       CFG_MONITOR_BASE,
> 		       CFG_MONITOR_BASE + CFG_MONITOR_LEN  - 1,
> 		       flash_get_info(CFG_MONITOR_BASE));
> 
> But I am not sure if this is fine for all architectures. Any ideas?

The problem is that you don't have any guarantee that CFG_MONITOR_LEN
includes the reset vector; also, there might be configurations  where
the U-Boot image is not stored at the end of the flash, so there is a
bigger  gap  between  the image and the sector with the reset vector,
and it would be not good to enforce  protection  on  that  area  that
might be useful to the user otherwise.

I think as a short term fix we might define an additional  area  that
needs  to  be  protected  (the reset vector). Mid/long term we should
change the code so you  can  pass  a  list  of  areas  (start/end  or
start/length  pairs) that will be protected. This would, for example,
also allow to keep certain other  areas  (FDT,  kernel  image,  etc.)
auto-protected as well - configurable by the user ona per-board base.

Best regards,

Wolfgang Denk

-- 
DENX Software Engineering GmbH,     MD: Wolfgang Denk & Detlev Zundel
HRB 165235 Munich, Office: Kirchenstr.5, D-82194 Groebenzell, Germany
Phone: (+49)-8142-66989-10 Fax: (+49)-8142-66989-80 Email: wd at denx.de
In an organization, each person rises to the level of his own  incom-
petency                                         - The Peter Principle

  reply	other threads:[~2007-11-18 19:31 UTC|newest]

Thread overview: 7+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2007-11-18 18:59 [U-Boot-Users] flash hardware protection with CFI driver does not autoprotect monitor completely Matthias Fuchs
2007-11-18 19:31 ` Wolfgang Denk [this message]
2007-11-18 21:14   ` Matthias Fuchs
2007-11-18 21:52     ` Wolfgang Denk
2007-11-19  6:14       ` Stefan Roese
2007-11-19 10:04         ` Matthias Fuchs
2007-11-19 10:10           ` Stefan Roese

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20071118193105.53B58243A9@gemini.denx.de \
    --to=wd@denx.de \
    --cc=u-boot@lists.denx.de \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox