From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from phobos.denx.de (phobos.denx.de [85.214.62.61]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.lore.kernel.org (Postfix) with ESMTPS id AE118C433EF for ; Tue, 31 May 2022 08:21:57 +0000 (UTC) Received: from h2850616.stratoserver.net (localhost [IPv6:::1]) by phobos.denx.de (Postfix) with ESMTP id BBCB783E63; Tue, 31 May 2022 10:21:54 +0200 (CEST) Authentication-Results: phobos.denx.de; dmarc=pass (p=none dis=none) header.from=kernel.org Authentication-Results: phobos.denx.de; spf=pass smtp.mailfrom=u-boot-bounces@lists.denx.de Authentication-Results: phobos.denx.de; dkim=pass (2048-bit key; unprotected) header.d=kernel.org header.i=@kernel.org header.b="Inhlg1HW"; dkim-atps=neutral Received: by phobos.denx.de (Postfix, from userid 109) id 01EF2842C6; Tue, 31 May 2022 10:21:53 +0200 (CEST) Received: from dfw.source.kernel.org (dfw.source.kernel.org [139.178.84.217]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by phobos.denx.de (Postfix) with ESMTPS id 059F483E3C for ; Tue, 31 May 2022 10:21:48 +0200 (CEST) Authentication-Results: phobos.denx.de; dmarc=pass (p=none dis=none) header.from=kernel.org Authentication-Results: phobos.denx.de; spf=pass smtp.mailfrom=rogerq@kernel.org Received: from smtp.kernel.org (relay.kernel.org [52.25.139.140]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by dfw.source.kernel.org (Postfix) with ESMTPS id F09AA61234; Tue, 31 May 2022 08:21:45 +0000 (UTC) Received: by smtp.kernel.org (Postfix) with ESMTPSA id 3A71EC3411E; Tue, 31 May 2022 08:21:45 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1653985305; bh=SzHQ5UP1t5EGFl8+f5EL9F7fDGGJ78c8cQXS/TJ6a4Q=; h=Date:Subject:To:References:From:In-Reply-To:From; b=Inhlg1HWJmmKUw7E/UkEnKmco3f5AlQRvB4w25p+lpiKWrbykoqhMKcEXuJhbyacd 36ZNJY2nMID4rbvJIglWeZspOQRD7Y/pyVt200OrJ3KHaB9h+urguSI0T0UhuZQnqR brvK1puHxSkfPrUPcYeP/mIoKP4CAU8fVHG6xZ8eR3G8I+JN3Xo9RWsr+nXdm17pJB L9v8+/2U+19BodIBB2btK7CiK54xAy7mMtvsizYNEnXcaVFrXXp0IhdsZxefrhWZV3 Yn9SBBDrLmyeP2XtQmPOLnFaHsLYirdCB0PqOxS2PqIP13T5dxseF3V6iv5HczYNME MEd8suwHWzpow== Message-ID: Date: Tue, 31 May 2022 11:21:42 +0300 MIME-Version: 1.0 User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:91.0) Gecko/20100101 Thunderbird/91.7.0 Subject: Re: [PATCH RFC v2 00/11] Integration of sysfw, tispl and tiboot3 Content-Language: en-US To: Neha Malcom Francis , u-boot@lists.denx.de References: <20220506043759.8193-1-n-francis@ti.com> From: Roger Quadros In-Reply-To: <20220506043759.8193-1-n-francis@ti.com> Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit X-BeenThere: u-boot@lists.denx.de X-Mailman-Version: 2.1.39 Precedence: list List-Id: U-Boot discussion List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: u-boot-bounces@lists.denx.de Sender: "U-Boot" X-Virus-Scanned: clamav-milter 0.103.5 at phobos.denx.de X-Virus-Status: Clean Hi, On 06/05/2022 07:37, Neha Malcom Francis wrote: > Devices that belong to the K3 architecture require SYSFW which is a FIT > image consisting of a signed system firmware image and board config > binaries. > > Board config binaries are needed to bring up SYSFW during U-Boot SPL > startup. The board config data is given in YAML as input. These board > configs contain board-specific information such as resource management, > power management and security. > > The following series intends to plumb the system firmware generation > into U-Boot using binman for packaging. Thus it will eliminate the need > for additional custom repositories for SYSFW generation and also moves t > owards the community standard build flow. We use binman to package > tiboot3.bin and sysfw.itb images. > > These images also require x509 certificates which are created using the > etype x509-cert. > > The series also plumbs the generation of tispl.bin into the build flow. > This image is required for loading u-boot in K3 devices. The image is > packaged using ATF, OPTEE and DM (Device Manager). > > Please note that the following series has implemented the above for > J721E general purpose board. The board configs and device trees added > are specific to J721E GP devices. > > Also note the introduction of three new etypes: ti-sysfw, ti-dm and > x509-cert. > > On running CI tests on Github, errors were produced during world builds > of keystone2_keystone3 and siemens (I0T2050 which is based on AM65x). > This patch series is intended for only J721E and future work is to expand > to the remaining K3 devices as well. The errors that come are mainly due > to the boards other than J721E trying to generate tispl.bin. You will have to implement it such that none of the existing board build/functionality breaks. Otherwise it will be impossible to get this merged. Is this series tested for High-Security (HS) J721E as well? cheers, -roger > > v2: > - Added etype x509-cert for creating x509 Texas Instruments certificate > binary > - Added packaging of tiboot3.bin > - Packaging of tiboot3.bin and sysfw.itb using new etype x509 > - sysfw --> ti-sysfw > - Reformatted and re-arranged patches > - Removed k3_fit_atf.sh and k3_gen_x509_cert.sh as their functionality > is provided by binman now > > Neha Malcom Francis (11): > j721e_evm: schema: yaml: Add general schema and J721E board config > files > ti: tools: config: Add board config class to generate config binaries > ti: etype: sysfw: Add entry type for sysfw > ti: etype: dm: Add entry type for TI DM > ti: etype: x509: Add etype for x509 certificate for K3 devices > ti: sysfw: Add support for packaging sysfw.itb > ti: tiboot3.bin: Remove tiboot3.bin target from makefile > ti: tispl.bin: Removed script that packages tispl.bin > ti: x509: Remove shell script used for signing > ti: dtsi: j721e: Use binman to package sysfw.itb and tiboot3.bin > ti: dtsi: j721e: Use binman to package tispl.bin > > Makefile | 2 + > arch/arm/dts/k3-j721e-a72-binman.dtsi | 86 + > .../k3-j721e-common-proc-board-u-boot.dtsi | 1 + > arch/arm/dts/k3-j721e-r5-binman.dtsi | 88 + > .../k3-j721e-r5-common-proc-board-u-boot.dtsi | 1 + > arch/arm/mach-k3/config.mk | 64 +- > board/ti/common/schema.yaml | 355 ++ > board/ti/j721e/Kconfig | 2 + > board/ti/j721e/config.yaml | 3162 +++++++++++++++++ > scripts/Makefile.spl | 4 - > test/py/requirements.txt | 1 + > tools/binman/entries.rst | 36 + > tools/binman/etype/ti_dm.py | 23 + > tools/binman/etype/ti_sysfw.py | 28 + > tools/binman/etype/x509_cert.py | 248 ++ > tools/binman/ftest.py | 21 + > tools/binman/test/225_ti_dm.dts | 13 + > tools/binman/test/232_ti_sysfw.dts | 13 + > tools/binman/test/232_x509_cert.dts | 18 + > tools/k3_fit_atf.sh | 123 - > tools/k3_gen_x509_cert.sh | 252 -- > tools/tibcfg_gen.py | 114 + > 22 files changed, 4227 insertions(+), 428 deletions(-) > create mode 100644 arch/arm/dts/k3-j721e-a72-binman.dtsi > create mode 100644 arch/arm/dts/k3-j721e-r5-binman.dtsi > create mode 100644 board/ti/common/schema.yaml > create mode 100644 board/ti/j721e/config.yaml > create mode 100644 tools/binman/etype/ti_dm.py > create mode 100644 tools/binman/etype/ti_sysfw.py > create mode 100644 tools/binman/etype/x509_cert.py > create mode 100644 tools/binman/test/225_ti_dm.dts > create mode 100644 tools/binman/test/232_ti_sysfw.dts > create mode 100644 tools/binman/test/232_x509_cert.dts > delete mode 100755 tools/k3_fit_atf.sh > delete mode 100755 tools/k3_gen_x509_cert.sh > create mode 100644 tools/tibcfg_gen.py >