U-Boot Archive on lore.kernel.org
 help / color / mirror / Atom feed
From: Udit Kumar <u-kumar1@ti.com>
To: <vigneshr@ti.com>, <nm@ti.com>, <trini@konsulko.com>
Cc: <joe.hershberger@ni.com>, <m-chawdhry@ti.com>, <afd@ti.com>,
	<devarsht@ti.com>, <sjg@chromium.org>,
	<emanuele.ghidoli@toradex.com>,
	<matthias.schiffer@ew.tq-group.com>, <a-bhatia1@ti.com>,
	<vitor.soares@toradex.com>, <danishanwar@ti.com>,
	<andriy.shevchenko@linux.intel.com>, <bmeng.cn@gmail.com>,
	<mkorpershoek@baylibre.com>, <s-vadapalli@ti.com>,
	<u-boot@lists.denx.de>, <joao.goncalves@toradex.com>,
	<hnagalla@ti.com>
Subject: [PATCH 2/4] drivers: remoteproc: ti_k3 : enable secure booting with firmware images
Date: Tue, 21 May 2024 16:26:46 +0530	[thread overview]
Message-ID: <20240521105648.3780072-3-u-kumar1@ti.com> (raw)
In-Reply-To: <20240521105648.3780072-1-u-kumar1@ti.com>

From: Manorit Chawdhry <m-chawdhry@ti.com>

Remoteproc firmware images aren't authenticated in the current boot flow.
Authenticates remoteproc firmware images to complete the root of trust
in secure booting.

Signed-off-by: Manorit Chawdhry <m-chawdhry@ti.com>
---
 drivers/remoteproc/ti_k3_dsp_rproc.c | 4 ++++
 drivers/remoteproc/ti_k3_r5f_rproc.c | 4 ++++
 2 files changed, 8 insertions(+)

diff --git a/drivers/remoteproc/ti_k3_dsp_rproc.c b/drivers/remoteproc/ti_k3_dsp_rproc.c
index 57fe1037da..7617bbb986 100644
--- a/drivers/remoteproc/ti_k3_dsp_rproc.c
+++ b/drivers/remoteproc/ti_k3_dsp_rproc.c
@@ -21,6 +21,7 @@
 #include <linux/sizes.h>
 #include <linux/soc/ti/ti_sci_protocol.h>
 #include "ti_sci_proc.h"
+#include <mach/security.h>
 
 #define KEYSTONE_RPROC_LOCAL_ADDRESS_MASK	(SZ_16M - 1)
 
@@ -127,6 +128,7 @@ static int k3_dsp_load(struct udevice *dev, ulong addr, ulong size)
 	struct k3_dsp_privdata *dsp = dev_get_priv(dev);
 	struct k3_dsp_boot_data *data = dsp->data;
 	u32 boot_vector;
+	void *image_addr = (void *)addr;
 	int ret;
 
 	if (dsp->in_use) {
@@ -148,6 +150,8 @@ static int k3_dsp_load(struct udevice *dev, ulong addr, ulong size)
 		goto proc_release;
 	}
 
+	ti_secure_image_post_process(&image_addr, &size);
+
 	ret = rproc_elf_load_image(dev, addr, size);
 	if (ret < 0) {
 		dev_err(dev, "Loading elf failed %d\n", ret);
diff --git a/drivers/remoteproc/ti_k3_r5f_rproc.c b/drivers/remoteproc/ti_k3_r5f_rproc.c
index b55b1dc10d..b9c6549e18 100644
--- a/drivers/remoteproc/ti_k3_r5f_rproc.c
+++ b/drivers/remoteproc/ti_k3_r5f_rproc.c
@@ -20,6 +20,7 @@
 #include <linux/kernel.h>
 #include <linux/soc/ti/ti_sci_protocol.h>
 #include "ti_sci_proc.h"
+#include <mach/security.h>
 
 /*
  * R5F's view of this address can either be for ATCM or BTCM with the other
@@ -301,6 +302,7 @@ static int k3_r5f_load(struct udevice *dev, ulong addr, ulong size)
 	u64 boot_vector;
 	u32 ctrl, sts, cfg = 0;
 	bool mem_auto_init;
+	void *image_addr = (void *)addr;
 	int ret;
 
 	dev_dbg(dev, "%s addr = 0x%lx, size = 0x%lx\n", __func__, addr, size);
@@ -328,6 +330,8 @@ static int k3_r5f_load(struct udevice *dev, ulong addr, ulong size)
 
 	k3_r5f_init_tcm_memories(core, mem_auto_init);
 
+	ti_secure_image_post_process(&image_addr, &size);
+
 	ret = rproc_elf_load_image(dev, addr, size);
 	if (ret < 0) {
 		dev_err(dev, "Loading elf failedi %d\n", ret);
-- 
2.34.1


  parent reply	other threads:[~2024-05-21 10:57 UTC|newest]

Thread overview: 16+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2024-05-21 10:56 [PATCH 0/4] Adding support to load secure firmware for HS devices Udit Kumar
2024-05-21 10:56 ` [PATCH 1/4] include: mach-k3: move k3 security functions to security.h Udit Kumar
2024-05-21 10:56 ` Udit Kumar [this message]
2024-05-21 10:56 ` [PATCH 3/4] include: env: ti: Add support for secure firmwares Udit Kumar
2024-05-21 10:56 ` [PATCH 4/4] mach-k3: common.c: add a flag for booting authenticated rproc binaries Udit Kumar
2024-05-21 14:29 ` [PATCH 0/4] Adding support to load secure firmware for HS devices Andy Shevchenko
2024-05-21 15:29   ` Kumar, Udit
2024-05-21 16:12     ` Andy Shevchenko
2024-05-21 16:21       ` Tom Rini
2024-05-21 16:35         ` Andy Shevchenko
2024-05-21 16:45           ` Tom Rini
2024-05-21 17:48             ` Andy Shevchenko
2024-05-21 17:52               ` Tom Rini
2024-05-21 18:55                 ` Andy Shevchenko
2024-05-21 19:23                   ` Tom Rini
2024-06-07 22:03 ` Tom Rini

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20240521105648.3780072-3-u-kumar1@ti.com \
    --to=u-kumar1@ti.com \
    --cc=a-bhatia1@ti.com \
    --cc=afd@ti.com \
    --cc=andriy.shevchenko@linux.intel.com \
    --cc=bmeng.cn@gmail.com \
    --cc=danishanwar@ti.com \
    --cc=devarsht@ti.com \
    --cc=emanuele.ghidoli@toradex.com \
    --cc=hnagalla@ti.com \
    --cc=joao.goncalves@toradex.com \
    --cc=joe.hershberger@ni.com \
    --cc=m-chawdhry@ti.com \
    --cc=matthias.schiffer@ew.tq-group.com \
    --cc=mkorpershoek@baylibre.com \
    --cc=nm@ti.com \
    --cc=s-vadapalli@ti.com \
    --cc=sjg@chromium.org \
    --cc=trini@konsulko.com \
    --cc=u-boot@lists.denx.de \
    --cc=vigneshr@ti.com \
    --cc=vitor.soares@toradex.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox