Merge branch 'dey-4.0/master' into dey-4.0/maint
Signed-off-by: Javier Viguera <javier.viguera@digi.com>
This commit is contained in:
commit
18c0c69314
|
|
@ -1,5 +1,5 @@
|
|||
# Digi Embedded Yocto (DEY) 4.0
|
||||
## Release 4.0-r5
|
||||
## Release 4.0-r6
|
||||
|
||||
This document provides information about Digi Embedded Yocto,
|
||||
Digi International's professional embedded Yocto development environment.
|
||||
|
|
@ -292,8 +292,6 @@ updated list can be found on the online documentation.
|
|||
* Wireless
|
||||
* P2P on the ConnectCore MP1 doesn't currently work in concurrency with
|
||||
other modes (station or SoftAP).
|
||||
* Connecting to a 802.11r network throws an unexpected error with the latest
|
||||
CYW4373E wireless firmware.
|
||||
|
||||
## ConnectCore 6UL
|
||||
|
||||
|
|
|
|||
|
|
@ -22,7 +22,7 @@ IMAGE_CMD:boot.vfat() {
|
|||
BOOTIMG_FILES="$(readlink -e ${DEPLOY_DIR_IMAGE}/${KERNEL_IMAGETYPE}-${MACHINE}.bin)"
|
||||
BOOTIMG_FILES_SYMLINK="${DEPLOY_DIR_IMAGE}/${KERNEL_IMAGETYPE}-${MACHINE}.bin"
|
||||
# Exclude DTB and DTBO from VFAT image when creating a FIT image
|
||||
if [ "${TRUSTFENCE_FIT_IMG}" != "1" ]; then
|
||||
if [ "${KERNEL_IMAGETYPE}" != "fitImage" ]; then
|
||||
if [ -n "${KERNEL_DEVICETREE}" ]; then
|
||||
for DTB in ${KERNEL_DEVICETREE}; do
|
||||
# Remove potential sub-folders
|
||||
|
|
@ -61,7 +61,7 @@ IMAGE_CMD:boot.vfat() {
|
|||
mcopy -i ${IMGDEPLOYDIR}/${IMAGE_NAME}.boot.vfat ${BOOTIMG_FILES_SYMLINK} ::/
|
||||
|
||||
# Exclude boot scripts from VFAT image when creating a FIT image
|
||||
if [ "${TRUSTFENCE_FIT_IMG}" != "1" ]; then
|
||||
if [ "${KERNEL_IMAGETYPE}" != "fitImage" ]; then
|
||||
# Copy boot scripts into the VFAT image
|
||||
for item in ${BOOT_SCRIPTS}; do
|
||||
src=`echo $item | awk -F':' '{ print $1 }'`
|
||||
|
|
@ -90,7 +90,7 @@ do_image_boot_ubifs[depends] += " \
|
|||
IMAGE_CMD:boot.ubifs() {
|
||||
BOOTIMG_FILES_SYMLINK="${DEPLOY_DIR_IMAGE}/${KERNEL_IMAGETYPE}-${MACHINE}.bin"
|
||||
# Exclude DTB and DTBO from UBIFS image when creating a FIT image
|
||||
if [ "${TRUSTFENCE_FIT_IMG}" != "1" ]; then
|
||||
if [ "${KERNEL_IMAGETYPE}" != "fitImage" ]; then
|
||||
if [ -n "${KERNEL_DEVICETREE}" ]; then
|
||||
for DTB in ${KERNEL_DEVICETREE}; do
|
||||
# Remove potential sub-folders
|
||||
|
|
@ -117,7 +117,7 @@ IMAGE_CMD:boot.ubifs() {
|
|||
done
|
||||
|
||||
# Exclude boot scripts from UBIFS image when creating a FIT image
|
||||
if [ "${TRUSTFENCE_FIT_IMG}" != "1" ]; then
|
||||
if [ "${KERNEL_IMAGETYPE}" != "fitImage" ]; then
|
||||
# Hard-link boot scripts into the temporary folder
|
||||
for item in ${BOOT_SCRIPTS}; do
|
||||
src="$(echo ${item} | awk -F':' '{ print $1 }')"
|
||||
|
|
@ -148,7 +148,7 @@ IMAGE_CMD:recovery.vfat() {
|
|||
cp --remove-destination ${IMGDEPLOYDIR}/${IMAGE_NAME}.boot.vfat ${IMGDEPLOYDIR}/${IMAGE_NAME}.recovery.vfat
|
||||
|
||||
# Exclude initRAMFS from VFAT image when creating a FIT image
|
||||
if [ "${TRUSTFENCE_FIT_IMG}" != "1" ]; then
|
||||
if [ "${KERNEL_IMAGETYPE}" != "fitImage" ]; then
|
||||
# Copy the recovery initramfs into the VFAT image
|
||||
mcopy -i ${IMGDEPLOYDIR}/${IMAGE_NAME}.recovery.vfat -s ${DEPLOY_DIR_IMAGE}/${RECOVERY_INITRAMFS_IMAGE}-${MACHINE}.cpio.gz.u-boot.tf ::/uramdisk-recovery.img
|
||||
fi
|
||||
|
|
@ -169,7 +169,7 @@ do_image_recovery_ubifs[depends] += " \
|
|||
IMAGE_CMD:recovery.ubifs() {
|
||||
RECOVERYIMG_FILES_SYMLINK="${DEPLOY_DIR_IMAGE}/${KERNEL_IMAGETYPE}-${MACHINE}.bin"
|
||||
# Exclude DTB and DTBO from VFAT image when creating a FIT image
|
||||
if [ "${TRUSTFENCE_FIT_IMG}" != "1" ]; then
|
||||
if [ "${KERNEL_IMAGETYPE}" != "fitImage" ]; then
|
||||
if [ -n "${KERNEL_DEVICETREE}" ]; then
|
||||
for DTB in ${KERNEL_DEVICETREE}; do
|
||||
# Remove potential sub-folders
|
||||
|
|
@ -191,7 +191,7 @@ IMAGE_CMD:recovery.ubifs() {
|
|||
done
|
||||
|
||||
# Exclude bootscript from VFAT image when creating a FIT image
|
||||
if [ "${TRUSTFENCE_FIT_IMG}" != "1" ]; then
|
||||
if [ "${KERNEL_IMAGETYPE}" != "fitImage" ]; then
|
||||
# Hard-link boot scripts into the temporary folder
|
||||
for item in ${BOOT_SCRIPTS}; do
|
||||
src="$(echo ${item} | awk -F':' '{ print $1 }')"
|
||||
|
|
@ -221,10 +221,11 @@ trustence_sign_cpio() {
|
|||
# Image generation code for image type 'cpio.gz.u-boot.tf'
|
||||
# (signed/encrypted ramdisk)
|
||||
#
|
||||
if [ "${TRUSTFENCE_SIGN_ARTIFACTS}" = "1" ]; then
|
||||
if [ "${TRUSTFENCE_SIGN_ARTIFACTS}" = "1" ] && [ "${TRUSTFENCE_SIGN_FIT_NXP}" = "0" ]; then
|
||||
# Set environment variables for trustfence configuration
|
||||
export CONFIG_SIGN_KEYS_PATH="${TRUSTFENCE_SIGN_KEYS_PATH}"
|
||||
[ -n "${TRUSTFENCE_KEY_INDEX}" ] && export CONFIG_KEY_INDEX="${TRUSTFENCE_KEY_INDEX}"
|
||||
[ -n "${TRUSTFENCE_SRK_REVOKE_MASK}" ] && export SRK_REVOKE_MASK="${TRUSTFENCE_SRK_REVOKE_MASK}"
|
||||
[ -n "${TRUSTFENCE_DEK_PATH}" ] && [ "${TRUSTFENCE_DEK_PATH}" != "0" ] && export CONFIG_DEK_PATH="${TRUSTFENCE_DEK_PATH}"
|
||||
# Sign/encrypt the ramdisk
|
||||
trustfence-sign-artifact.sh -p "${DIGI_SOM}" -i "${1}" "${1}.tf"
|
||||
|
|
|
|||
|
|
@ -22,8 +22,10 @@ KERNEL_DEVICETREE ?= " \
|
|||
digi/_ov_board_mikroe-accel2-click_ccimx93-dvk.dtbo \
|
||||
digi/_ov_board_mikroe-gyro-click_ccimx93-dvk.dtbo \
|
||||
digi/_ov_som_bt_ccimx93.dtbo \
|
||||
digi/_ov_som_bt-dtm_ccimx93.dtbo \
|
||||
digi/_ov_som_npu_ccimx93.dtbo \
|
||||
digi/_ov_som_wifi_ccimx93.dtbo \
|
||||
${@bb.utils.contains('DISTRO_FEATURES', 'tsn', 'digi/_ov_board_eqos-tsn_ccimx93-dvk.dtbo', '', d)} \
|
||||
"
|
||||
|
||||
# Wireless external module
|
||||
|
|
@ -32,7 +34,7 @@ WIRELESS_MODULE:append = " ${@oe.utils.conditional('HAVE_WIFI', '1', 'kernel-mod
|
|||
HAS_WIFI_VIRTWLANS = "true"
|
||||
|
||||
# Machine firmware
|
||||
MACHINE_FIRMWARE:append = " ${@oe.utils.conditional('HAVE_WIFI', '1', 'firmware-nxp-wifi-nxpiw612', '', d)}"
|
||||
MACHINE_FIRMWARE:append = " ${@oe.utils.conditional('HAVE_WIFI', '1', 'firmware-nxp-wifi-nxpiw612 firmware-murata-nxp', '', d)}"
|
||||
|
||||
MACHINE_EXTRA_RRECOMMENDS += "${WIRELESS_MODULE}"
|
||||
|
||||
|
|
|
|||
|
|
@ -18,8 +18,8 @@ MACHINEOVERRIDES = "arm:armv7ve:stcommon:stm32mpcommon:stm32mp1common:${DIGI_FAM
|
|||
# boot device
|
||||
# =========================================================================
|
||||
# Configure the list of boards that enable NAND/SDCARD
|
||||
DEVICE_BOARD_ENABLE:NAND += "ccmp13-dvk"
|
||||
DEVICE_BOARD_ENABLE:SDCARD += "${@bb.utils.contains('BOOTDEVICE_LABELS', 'sdcard', 'ccmp13-dvk', '', d)}"
|
||||
DEVICE_BOARD_ENABLE:NAND += "${STM32MP_DEVICETREE}"
|
||||
DEVICE_BOARD_ENABLE:SDCARD += "${@bb.utils.contains('BOOTDEVICE_LABELS', 'sdcard', '${STM32MP_DEVICETREE}', '', d)}"
|
||||
|
||||
# =========================================================================
|
||||
# U-Boot configs
|
||||
|
|
@ -28,14 +28,11 @@ DEVICE_BOARD_ENABLE:SDCARD += "${@bb.utils.contains('BOOTDEVICE_LABELS', 'sdcard
|
|||
UBOOT_CONFIG = "ccmp13-dvk"
|
||||
UBOOT_CONFIG[ccmp13-dvk] = "ccmp13-dvk_defconfig,,u-boot-dtb.${UBOOT_SUFFIX}"
|
||||
|
||||
# Platform U-Boot settings
|
||||
UBOOT_DTB_NAME = "ccmp13-dvk.dtb"
|
||||
|
||||
# =========================================================================
|
||||
# Machine settings
|
||||
# =========================================================================
|
||||
# Define list of devicetree per board
|
||||
STM32MP_DEVICETREE ??= "ccmp13-dvk"
|
||||
STM32MP_DEVICETREE ??= "ccmp13-dvk-256MB"
|
||||
# Extra DTB for board - need to specify it with .dtb ...
|
||||
STM32MP_KERNEL_DEVICETREE:ccmp13-dvk += " \
|
||||
ccmp133-dvk.dtb \
|
||||
|
|
@ -49,7 +46,9 @@ STM32MP_KERNEL_DEVICETREE:ccmp13-dvk += " \
|
|||
_ov_som_wifi_ccmp13.dtbo \
|
||||
"
|
||||
# Set DTB load address to U-Boot fdt_addr_r
|
||||
UBOOT_DTB_LOADADDRESS = "${@bb.utils.contains('TRUSTFENCE_FIT_IMG', '1', '0xc4000000', '', d)}"
|
||||
UBOOT_DTB_LOADADDRESS = "0xc4000000"
|
||||
# List of U-Boot device tree to use
|
||||
UBOOT_DEVICETREE = "${STM32MP_DEVICETREE}"
|
||||
|
||||
# =========================================================================
|
||||
# Machine features
|
||||
|
|
@ -60,7 +59,7 @@ MACHINE_FEATURES += "wifi"
|
|||
# =========================================================================
|
||||
# Firmware
|
||||
# =========================================================================
|
||||
MACHINE_FIRMWARE:append = " firmware-murata firmware-murata-mfgtest"
|
||||
MACHINE_FIRMWARE:append = " firmware-murata-infineon"
|
||||
|
||||
MACHINE_EXTRA_RRECOMMENDS += " \
|
||||
${MACHINE_FIRMWARE} \
|
||||
|
|
@ -77,6 +76,9 @@ IMAGE_FSTYPES += '${@bb.utils.contains("IMAGE_FEATURES", "read-only-rootfs", \
|
|||
# Default image for install scripts
|
||||
DEFAULT_IMAGE_NAME ?= "core-image-base"
|
||||
|
||||
# Wic files
|
||||
WKS_FILE += "ccmp1-256MB.wks.in"
|
||||
|
||||
# For populate_sdk, gcc-arm-none-eabi_9 has a python2 dependency, so we remove it.
|
||||
ST_TOOLS_FOR_SDK:remove = "nativesdk-gcc-arm-none-eabi"
|
||||
|
||||
|
|
@ -100,7 +102,7 @@ ST_DEBUG_TRACE = "0"
|
|||
# optee
|
||||
# =========================================================================
|
||||
# Map OPTEE configuration to device tree list
|
||||
OPTEE_CONF = "ccmp13-dvk"
|
||||
OPTEE_CONF = "${STM32MP_DEVICETREE}"
|
||||
|
||||
# =========================================================================
|
||||
# Flashlayouts
|
||||
|
|
@ -109,8 +111,8 @@ OPTEE_CONF = "ccmp13-dvk"
|
|||
# =========================================================================
|
||||
# Kernel
|
||||
# =========================================================================
|
||||
KERNEL_IMAGETYPE = "${@bb.utils.contains('TRUSTFENCE_FIT_IMG', '1', 'fitImage', 'zImage', d)}"
|
||||
KERNEL_CLASSES = "${@bb.utils.contains('TRUSTFENCE_FIT_IMG', '1', 'kernel-fitimage', 'kernel-uimage', d)}"
|
||||
KERNEL_IMAGETYPE = "${@bb.utils.contains('TRUSTFENCE_SIGN_FIT_STM', '1', 'fitImage', 'zImage', d)}"
|
||||
KERNEL_CLASSES = "kernel-fitimage"
|
||||
KERNEL_ALT_IMAGETYPE = "Image vmlinux"
|
||||
KERNEL_DEFCONFIG ?= "arch/arm/configs/ccmp1_defconfig"
|
||||
|
||||
|
|
@ -158,8 +160,8 @@ ST_VENDORFS = "0"
|
|||
|
||||
# Boot artifacts to be copied from the deploy dir to the installer ZIP
|
||||
BOOTABLE_ARTIFACTS = " \
|
||||
arm-trusted-firmware/tf-a-ccmp13-dvk-nand.stm32 \
|
||||
fip/fip-ccmp13-dvk-optee.bin \
|
||||
arm-trusted-firmware/tf-a-ccmp13-dvk-256MB-nand.stm32 \
|
||||
fip/fip-ccmp13-dvk-256MB-optee.bin \
|
||||
"
|
||||
|
||||
# TRUSTFENCE basic support
|
||||
|
|
|
|||
|
|
@ -18,8 +18,8 @@ MACHINEOVERRIDES = "arm:armv7ve:stcommon:stm32mpcommon:stm32mp1common:${DIGI_FAM
|
|||
# boot device
|
||||
# =========================================================================
|
||||
# Configure the list of boards that enable NAND/SDCARD
|
||||
DEVICE_BOARD_ENABLE:NAND += "ccmp15-dvk"
|
||||
DEVICE_BOARD_ENABLE:SDCARD += "${@bb.utils.contains('BOOTDEVICE_LABELS', 'sdcard', 'ccmp15-dvk', '', d)}"
|
||||
DEVICE_BOARD_ENABLE:NAND += "${STM32MP_DEVICETREE}"
|
||||
DEVICE_BOARD_ENABLE:SDCARD += "${@bb.utils.contains('BOOTDEVICE_LABELS', 'sdcard', '${STM32MP_DEVICETREE}', '', d)}"
|
||||
|
||||
# =========================================================================
|
||||
# U-Boot configs
|
||||
|
|
@ -28,19 +28,17 @@ DEVICE_BOARD_ENABLE:SDCARD += "${@bb.utils.contains('BOOTDEVICE_LABELS', 'sdcard
|
|||
UBOOT_CONFIG = "ccmp15-dvk"
|
||||
UBOOT_CONFIG[ccmp15-dvk] = "ccmp15-dvk_defconfig,,u-boot-dtb.${UBOOT_SUFFIX}"
|
||||
|
||||
# Platform U-Boot settings
|
||||
UBOOT_DTB_NAME = "ccmp15-dvk.dtb"
|
||||
|
||||
# =========================================================================
|
||||
# Machine settings
|
||||
# =========================================================================
|
||||
# Define list of devicetree per board
|
||||
STM32MP_DEVICETREE ??= "ccmp15-dvk"
|
||||
STM32MP_DEVICETREE ??= "ccmp15-dvk-512MB ccmp15-dvk-1GB"
|
||||
# Extra DTB for board - need to specify it with .dtb ...
|
||||
STM32MP_KERNEL_DEVICETREE:ccmp15-dvk += " \
|
||||
ccmp157-dvk.dtb \
|
||||
_ov_board_can1_ccmp15-dvk.dtbo \
|
||||
_ov_board_can2_ccmp15-dvk.dtbo \
|
||||
_ov_board_dlc0200ccp04df-mipi-dsi_ccmp15-dvk.dtbo \
|
||||
_ov_board_eth0-10-100_ccmp15-dvk.dtbo \
|
||||
_ov_board_fusion10-lvds_ccmp15-dvk.dtbo \
|
||||
_ov_board_fusion7-parallel_ccmp15-dvk.dtbo \
|
||||
|
|
@ -48,16 +46,19 @@ STM32MP_KERNEL_DEVICETREE:ccmp15-dvk += " \
|
|||
_ov_board_mikroe-accel2-click_ccmp15-dvk.dtbo \
|
||||
_ov_board_mikroe-gyro-click_ccmp15-dvk.dtbo \
|
||||
_ov_board_mikroe-i2c-to-spi-click_ccmp15-dvk.dtbo \
|
||||
_ov_board_nhd-3-5-640480ef-msxp-mipi-dsi_ccmp15-dvk.dtbo \
|
||||
_ov_board_sv4e-mipi-analyzer_ccmp15-dvk.dtbo \
|
||||
_ov_board_v1_ccmp15-dvk.dtbo \
|
||||
_ov_board_v2_ccmp15-dvk.dtbo \
|
||||
_ov_som_bt_ccmp15.dtbo \
|
||||
_ov_som_bt_test_ccmp15.dtbo \
|
||||
_ov_som_m4_ccmp15.dtbo \
|
||||
_ov_som_v1_ccmp15.dtbo \
|
||||
_ov_som_wifi_ccmp15.dtbo \
|
||||
"
|
||||
# Set DTB load address to U-Boot fdt_addr_r
|
||||
UBOOT_DTB_LOADADDRESS = "${@bb.utils.contains('TRUSTFENCE_FIT_IMG', '1', '0xc4000000', '', d)}"
|
||||
UBOOT_DTB_LOADADDRESS = "0xc4000000"
|
||||
# List of U-Boot device tree to use
|
||||
UBOOT_DEVICETREE = "${STM32MP_DEVICETREE}"
|
||||
|
||||
# =========================================================================
|
||||
# Machine features
|
||||
|
|
@ -69,7 +70,7 @@ MACHINE_FEATURES += "gpu"
|
|||
# =========================================================================
|
||||
# Firmware
|
||||
# =========================================================================
|
||||
MACHINE_FIRMWARE:append = " firmware-murata firmware-murata-mfgtest"
|
||||
MACHINE_FIRMWARE:append = " firmware-murata-infineon"
|
||||
|
||||
MACHINE_EXTRA_RRECOMMENDS += " \
|
||||
${MACHINE_FIRMWARE} \
|
||||
|
|
@ -86,6 +87,12 @@ IMAGE_FSTYPES += '${@bb.utils.contains("IMAGE_FEATURES", "read-only-rootfs", \
|
|||
# Default image for install scripts
|
||||
DEFAULT_IMAGE_NAME ?= "dey-image-webkit"
|
||||
|
||||
# Wic files
|
||||
WKS_FILES += " \
|
||||
ccmp1-512MB.wks.in \
|
||||
ccmp1-1GB.wks.in \
|
||||
"
|
||||
|
||||
# For populate_sdk, gcc-arm-none-eabi_9 has a python2 dependency, so we remove it.
|
||||
ST_TOOLS_FOR_SDK:remove = "nativesdk-gcc-arm-none-eabi"
|
||||
|
||||
|
|
@ -109,7 +116,7 @@ ST_DEBUG_TRACE = "0"
|
|||
# optee
|
||||
# =========================================================================
|
||||
# Map OPTEE configuration to device tree list
|
||||
OPTEE_CONF = "ccmp15-dvk"
|
||||
OPTEE_CONF = "${STM32MP_DEVICETREE}"
|
||||
|
||||
# =========================================================================
|
||||
# Flashlayouts
|
||||
|
|
@ -118,8 +125,8 @@ OPTEE_CONF = "ccmp15-dvk"
|
|||
# =========================================================================
|
||||
# Kernel
|
||||
# =========================================================================
|
||||
KERNEL_IMAGETYPE = "${@bb.utils.contains('TRUSTFENCE_FIT_IMG', '1', 'fitImage', 'zImage', d)}"
|
||||
KERNEL_CLASSES = "${@bb.utils.contains('TRUSTFENCE_FIT_IMG', '1', 'kernel-fitimage', 'kernel-uimage', d)}"
|
||||
KERNEL_IMAGETYPE = "${@bb.utils.contains('TRUSTFENCE_SIGN_FIT_STM', '1', 'fitImage', 'zImage', d)}"
|
||||
KERNEL_CLASSES = "kernel-fitimage"
|
||||
KERNEL_ALT_IMAGETYPE = "Image vmlinux"
|
||||
KERNEL_DEFCONFIG ?= "arch/arm/configs/ccmp1_defconfig"
|
||||
|
||||
|
|
@ -164,8 +171,10 @@ ST_VENDORFS = "0"
|
|||
|
||||
# Boot artifacts to be copied from the deploy dir to the installer ZIP
|
||||
BOOTABLE_ARTIFACTS = " \
|
||||
arm-trusted-firmware/tf-a-ccmp15-dvk-nand.stm32 \
|
||||
fip/fip-ccmp15-dvk-optee.bin \
|
||||
arm-trusted-firmware/tf-a-ccmp15-dvk-512MB-nand.stm32 \
|
||||
arm-trusted-firmware/tf-a-ccmp15-dvk-1GB-nand.stm32 \
|
||||
fip/fip-ccmp15-dvk-512MB-optee.bin \
|
||||
fip/fip-ccmp15-dvk-1GB-optee.bin \
|
||||
"
|
||||
|
||||
# TRUSTFENCE basic support
|
||||
|
|
|
|||
|
|
@ -8,9 +8,18 @@ require conf/machine/include/imx-digi-base.inc
|
|||
require conf/machine/include/arm/armv8-2a/tune-cortexa55.inc
|
||||
|
||||
# Platform u-boot settings
|
||||
UBOOT_DTB_LOADADDRESS = "0x83000000"
|
||||
UBOOT_DTBO_LOADADDRESS = "0x83000000"
|
||||
UBOOT_ENTRYPOINT = "0x80400000"
|
||||
UBOOT_ENV = "boot"
|
||||
UBOOT_PREFIX = "imx-boot"
|
||||
UBOOT_SUFFIX = "bin"
|
||||
|
||||
# Platform kernel settings (keep the override as otherwise KERNEL_IMAGETYPE
|
||||
# from imx-digi-base.inc takes precedence)
|
||||
KERNEL_CLASSES = "kernel-fitimage"
|
||||
KERNEL_IMAGETYPE:ccimx93 = "${@oe.utils.vartrue('TRUSTFENCE_SIGN_ARTIFACTS', 'fitImage', 'Image.gz', d)}"
|
||||
|
||||
# The bootloader image that gets flashed consists of U-Boot and several fw binaries
|
||||
EXTRA_IMAGEDEPENDS += "imx-boot"
|
||||
BOOTLOADER_IMAGE_RECIPE = "imx-boot"
|
||||
|
|
|
|||
|
|
@ -42,6 +42,9 @@ UBOOT_ENV_SIZE ?= "0x20000"
|
|||
# available space in the environment partition)
|
||||
UBOOT_ENV_RANGE ?= ""
|
||||
|
||||
# OPTEE runtime packages to install
|
||||
OPTEE_PKGS ??= "optee-client"
|
||||
|
||||
MACHINE_EXTRA_RDEPENDS += " \
|
||||
mtd-utils-ubifs \
|
||||
"
|
||||
|
|
@ -62,7 +65,6 @@ MULTIUBI_BUILD:remove = "nand_4_256"
|
|||
IMAGE_FSTYPES:remove = "stmultiubi"
|
||||
|
||||
# Wic files
|
||||
WKS_FILE += "ccmp1.wks.in"
|
||||
WKS_FILE_DEPENDS ?= " \
|
||||
virtual/bootloader \
|
||||
virtual/trusted-firmware-a \
|
||||
|
|
@ -79,7 +81,7 @@ TRUSTFENCE_CONSOLE_DISABLE ?= "0"
|
|||
do_create_flashlayout_config[noexec] = "1"
|
||||
|
||||
# Include boot script into the FIT image
|
||||
UBOOT_ENV = "${@bb.utils.contains('TRUSTFENCE_FIT_IMG', '1', 'boot', '', d)}"
|
||||
UBOOT_ENV = "boot"
|
||||
|
||||
# Partitions to blacklist for swupdate:
|
||||
# fsbl1, fsbl2, metadata1, metadata2, fip-a, fip-b
|
||||
|
|
|
|||
|
|
@ -15,6 +15,8 @@ SRC_URI:append:ccimx93 = " \
|
|||
|
||||
BOOT_TOOLS = "imx-boot-tools"
|
||||
|
||||
EXTRA_OEMAKE += "${@oe.utils.conditional('TRUSTFENCE_CONSOLE_DISABLE', '1', 'LOG_LEVEL=0', '', d)}"
|
||||
|
||||
# Build ATF for imx93 SOC revision A0
|
||||
do_compile:append:ccimx93() {
|
||||
oe_runmake SOC_REV_A0=1 BUILD_BASE=build-A0 clean
|
||||
|
|
|
|||
|
|
@ -203,10 +203,12 @@ trustfence_sign_imxboot:ccimx8x() {
|
|||
done
|
||||
|
||||
# Generate symlinks for trustfence artifacts.
|
||||
ln -sf ${UBOOT_PREFIX}-signed-${MACHINE}-${rev}.bin-${IMAGE_IMXBOOT_TARGET} ${DEPLOYDIR}/${UBOOT_PREFIX}-signed-${MACHINE}.bin
|
||||
if [ -n "${TRUSTFENCE_DEK_PATH}" ] && [ "${TRUSTFENCE_DEK_PATH}" != "0" ]; then
|
||||
ln -sf ${UBOOT_PREFIX}-encrypted-${MACHINE}-${rev}.bin-${IMAGE_IMXBOOT_TARGET} ${DEPLOYDIR}/${UBOOT_PREFIX}-encrypted-${MACHINE}.bin
|
||||
fi
|
||||
for rev in ${SOC_REVISIONS}; do
|
||||
ln -sf ${UBOOT_PREFIX}-signed-${MACHINE}-${rev}.bin-${IMAGE_IMXBOOT_TARGET} ${DEPLOYDIR}/${UBOOT_PREFIX}-signed-${MACHINE}-${rev}.bin
|
||||
if [ -n "${TRUSTFENCE_DEK_PATH}" ] && [ "${TRUSTFENCE_DEK_PATH}" != "0" ]; then
|
||||
ln -sf ${UBOOT_PREFIX}-encrypted-${MACHINE}-${rev}.bin-${IMAGE_IMXBOOT_TARGET} ${DEPLOYDIR}/${UBOOT_PREFIX}-encrypted-${MACHINE}-${rev}.bin
|
||||
fi
|
||||
done
|
||||
}
|
||||
|
||||
trustfence_sign_imxboot[dirs] = "${DEPLOYDIR}"
|
||||
|
|
|
|||
|
|
@ -8,6 +8,14 @@ require recipes-security/optee-imx/optee-client_3.19.0.imx.bb
|
|||
SRCBRANCH = "lf-6.1.55_2.2.0"
|
||||
SRCREV = "acb0885c117e73cb6c5c9b1dd9054cb3f93507ee"
|
||||
|
||||
EXTRA_OEMAKE += "PKG_CONFIG=pkg-config"
|
||||
EXTRA_OEMAKE += "PKG_CONFIG=pkg-config CFG_TEE_FS_PARENT_PATH='${localstatedir}/lib/tee'"
|
||||
|
||||
do_install() {
|
||||
oe_runmake DESTDIR=${D} install
|
||||
install -D -p -m0644 ${WORKDIR}/tee-supplicant.service ${D}${systemd_system_unitdir}/tee-supplicant.service
|
||||
sed -i -e s:@sysconfdir@:${sysconfdir}:g \
|
||||
-e s:@sbindir@:${sbindir}:g \
|
||||
${D}${systemd_system_unitdir}/tee-supplicant.service
|
||||
}
|
||||
|
||||
COMPATIBLE_MACHINE = "(ccimx93)"
|
||||
|
|
|
|||
|
|
@ -0,0 +1,714 @@
|
|||
From: Javier Viguera <javier.viguera@digi.com>
|
||||
Date: Tue, 14 May 2024 15:33:17 +0200
|
||||
Subject: [PATCH] core: ccimx93: enable AES_HUK trusted application
|
||||
|
||||
This provides the support for u-boot environment encryption.
|
||||
|
||||
Signed-off-by: Javier Viguera <javier.viguera@digi.com>
|
||||
---
|
||||
core/arch/arm/plat-imx/conf.mk | 2 +
|
||||
ta/aes_huk/Android.mk | 4 +
|
||||
ta/aes_huk/Makefile | 13 +
|
||||
ta/aes_huk/aes_ta.c | 477 ++++++++++++++++++++++++++++
|
||||
ta/aes_huk/include/aes_ta.h | 82 +++++
|
||||
ta/aes_huk/sub.mk | 3 +
|
||||
ta/aes_huk/user_ta.mk | 1 +
|
||||
ta/aes_huk/user_ta_header_defines.h | 48 +++
|
||||
8 files changed, 630 insertions(+)
|
||||
create mode 100644 ta/aes_huk/Android.mk
|
||||
create mode 100644 ta/aes_huk/Makefile
|
||||
create mode 100644 ta/aes_huk/aes_ta.c
|
||||
create mode 100644 ta/aes_huk/include/aes_ta.h
|
||||
create mode 100644 ta/aes_huk/sub.mk
|
||||
create mode 100644 ta/aes_huk/user_ta.mk
|
||||
create mode 100644 ta/aes_huk/user_ta_header_defines.h
|
||||
|
||||
diff --git a/core/arch/arm/plat-imx/conf.mk b/core/arch/arm/plat-imx/conf.mk
|
||||
index 5e4c02e27d2e..40d0bb4116dd 100644
|
||||
--- a/core/arch/arm/plat-imx/conf.mk
|
||||
+++ b/core/arch/arm/plat-imx/conf.mk
|
||||
@@ -456,12 +456,14 @@ endif
|
||||
ifneq (,$(filter $(PLATFORM_FLAVOR),ccimx93dvk))
|
||||
CFG_DDR_SIZE ?= 0x40000000
|
||||
CFG_UART_BASE ?= UART6_BASE
|
||||
+CFG_IN_TREE_EARLY_TAS += aes_huk/c2fad363-5d9f-4fc4-a417-555841e05745
|
||||
endif
|
||||
|
||||
ifneq (,$(filter $(PLATFORM_FLAVOR),ccimx93dvk_a0))
|
||||
CFG_DDR_SIZE ?= 0x40000000
|
||||
CFG_UART_BASE ?= UART6_BASE
|
||||
$(call force,CFG_SOC_REV_A0,y)
|
||||
+CFG_IN_TREE_EARLY_TAS += aes_huk/c2fad363-5d9f-4fc4-a417-555841e05745
|
||||
endif
|
||||
|
||||
# i.MX6 Solo/SL/SoloX/DualLite/Dual/Quad specific config
|
||||
diff --git a/ta/aes_huk/Android.mk b/ta/aes_huk/Android.mk
|
||||
new file mode 100644
|
||||
index 000000000000..931f8e4065c9
|
||||
--- /dev/null
|
||||
+++ b/ta/aes_huk/Android.mk
|
||||
@@ -0,0 +1,4 @@
|
||||
+LOCAL_PATH := $(call my-dir)
|
||||
+
|
||||
+local_module := 5dbac793-f574-4871-8ad3-04331ec17f24.ta
|
||||
+include $(BUILD_OPTEE_MK)
|
||||
diff --git a/ta/aes_huk/Makefile b/ta/aes_huk/Makefile
|
||||
new file mode 100644
|
||||
index 000000000000..e41d9913e6ae
|
||||
--- /dev/null
|
||||
+++ b/ta/aes_huk/Makefile
|
||||
@@ -0,0 +1,13 @@
|
||||
+CFG_TEE_TA_LOG_LEVEL ?= 4
|
||||
+CFG_TA_OPTEE_CORE_API_COMPAT_1_1=y
|
||||
+
|
||||
+# The UUID for the Trusted Application
|
||||
+BINARY=c2fad363-5d9f-4fc4-a417-555841e05745
|
||||
+
|
||||
+-include $(TA_DEV_KIT_DIR)/mk/ta_dev_kit.mk
|
||||
+
|
||||
+ifeq ($(wildcard $(TA_DEV_KIT_DIR)/mk/ta_dev_kit.mk), )
|
||||
+clean:
|
||||
+ @echo 'Note: $$(TA_DEV_KIT_DIR)/mk/ta_dev_kit.mk not found, cannot clean TA'
|
||||
+ @echo 'Note: TA_DEV_KIT_DIR=$(TA_DEV_KIT_DIR)'
|
||||
+endif
|
||||
diff --git a/ta/aes_huk/aes_ta.c b/ta/aes_huk/aes_ta.c
|
||||
new file mode 100644
|
||||
index 000000000000..036d64b83478
|
||||
--- /dev/null
|
||||
+++ b/ta/aes_huk/aes_ta.c
|
||||
@@ -0,0 +1,477 @@
|
||||
+/*
|
||||
+ * Copyright (c) 2017, Linaro Limited
|
||||
+ * All rights reserved.
|
||||
+ *
|
||||
+ * Redistribution and use in source and binary forms, with or without
|
||||
+ * modification, are permitted provided that the following conditions are met:
|
||||
+ *
|
||||
+ * 1. Redistributions of source code must retain the above copyright notice,
|
||||
+ * this list of conditions and the following disclaimer.
|
||||
+ *
|
||||
+ * 2. Redistributions in binary form must reproduce the above copyright notice,
|
||||
+ * this list of conditions and the following disclaimer in the documentation
|
||||
+ * and/or other materials provided with the distribution.
|
||||
+ *
|
||||
+ * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS"
|
||||
+ * AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
|
||||
+ * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
|
||||
+ * ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT HOLDER OR CONTRIBUTORS BE
|
||||
+ * LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
|
||||
+ * CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
|
||||
+ * SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
|
||||
+ * INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN
|
||||
+ * CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
|
||||
+ * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE
|
||||
+ * POSSIBILITY OF SUCH DAMAGE.
|
||||
+ */
|
||||
+#include <inttypes.h>
|
||||
+
|
||||
+#include <pta_system.h>
|
||||
+#include <tee_internal_api.h>
|
||||
+#include <tee_internal_api_extensions.h>
|
||||
+
|
||||
+#include <aes_ta.h>
|
||||
+
|
||||
+#define AES128_KEY_BIT_SIZE 128
|
||||
+#define AES128_KEY_BYTE_SIZE (AES128_KEY_BIT_SIZE / 8)
|
||||
+#define AES256_KEY_BIT_SIZE 256
|
||||
+#define AES256_KEY_BYTE_SIZE (AES256_KEY_BIT_SIZE / 8)
|
||||
+
|
||||
+/*
|
||||
+ * Ciphering context: each opened session relates to a cipehring operation.
|
||||
+ * - configure the AES flavour from a command.
|
||||
+ * - load key from a command (here the key is provided by the REE)
|
||||
+ * - reset init vector (here IV is provided by the REE)
|
||||
+ * - cipher a buffer frame (here input and output buffers are non-secure)
|
||||
+ */
|
||||
+struct aes_cipher {
|
||||
+ uint32_t algo; /* AES flavour */
|
||||
+ uint32_t mode; /* Encode or decode */
|
||||
+ uint32_t key_size; /* AES key size in byte */
|
||||
+ TEE_OperationHandle op_handle; /* AES ciphering operation */
|
||||
+ TEE_ObjectHandle key_handle; /* transient object to load the key */
|
||||
+};
|
||||
+
|
||||
+/*
|
||||
+ * Few routines to convert IDs from TA API into IDs from OP-TEE.
|
||||
+ */
|
||||
+static TEE_Result ta2tee_algo_id(uint32_t param, uint32_t *algo)
|
||||
+{
|
||||
+ switch (param) {
|
||||
+ case TA_AES_ALGO_ECB:
|
||||
+ *algo = TEE_ALG_AES_ECB_NOPAD;
|
||||
+ return TEE_SUCCESS;
|
||||
+ case TA_AES_ALGO_CBC:
|
||||
+ *algo = TEE_ALG_AES_CBC_NOPAD;
|
||||
+ return TEE_SUCCESS;
|
||||
+ case TA_AES_ALGO_CTR:
|
||||
+ *algo = TEE_ALG_AES_CTR;
|
||||
+ return TEE_SUCCESS;
|
||||
+ default:
|
||||
+ EMSG("Invalid algo %u", param);
|
||||
+ return TEE_ERROR_BAD_PARAMETERS;
|
||||
+ }
|
||||
+}
|
||||
+static TEE_Result ta2tee_key_size(uint32_t param, uint32_t *key_size)
|
||||
+{
|
||||
+ switch (param) {
|
||||
+ case AES128_KEY_BYTE_SIZE:
|
||||
+ case AES256_KEY_BYTE_SIZE:
|
||||
+ *key_size = param;
|
||||
+ return TEE_SUCCESS;
|
||||
+ default:
|
||||
+ EMSG("Invalid key size %u", param);
|
||||
+ return TEE_ERROR_BAD_PARAMETERS;
|
||||
+ }
|
||||
+}
|
||||
+static TEE_Result ta2tee_mode_id(uint32_t param, uint32_t *mode)
|
||||
+{
|
||||
+ switch (param) {
|
||||
+ case TA_AES_MODE_ENCODE:
|
||||
+ *mode = TEE_MODE_ENCRYPT;
|
||||
+ return TEE_SUCCESS;
|
||||
+ case TA_AES_MODE_DECODE:
|
||||
+ *mode = TEE_MODE_DECRYPT;
|
||||
+ return TEE_SUCCESS;
|
||||
+ default:
|
||||
+ EMSG("Invalid mode %u", param);
|
||||
+ return TEE_ERROR_BAD_PARAMETERS;
|
||||
+ }
|
||||
+}
|
||||
+
|
||||
+/*
|
||||
+ * Process command TA_AES_CMD_PREPARE. API in aes_ta.h
|
||||
+ *
|
||||
+ * Allocate resources required for the ciphering operation.
|
||||
+ * During ciphering operation, when expect client can:
|
||||
+ * - update the key materials (provided by client)
|
||||
+ * - reset the initial vector (provided by client)
|
||||
+ * - cipher an input buffer into an output buffer (provided by client)
|
||||
+ */
|
||||
+static TEE_Result alloc_resources(void *session, uint32_t param_types,
|
||||
+ TEE_Param params[4])
|
||||
+{
|
||||
+ const uint32_t exp_param_types =
|
||||
+ TEE_PARAM_TYPES(TEE_PARAM_TYPE_VALUE_INPUT,
|
||||
+ TEE_PARAM_TYPE_VALUE_INPUT,
|
||||
+ TEE_PARAM_TYPE_VALUE_INPUT,
|
||||
+ TEE_PARAM_TYPE_NONE);
|
||||
+ struct aes_cipher *sess;
|
||||
+ TEE_Attribute attr;
|
||||
+ TEE_Result res;
|
||||
+ char *key;
|
||||
+
|
||||
+ /* Get ciphering context from session ID */
|
||||
+ DMSG("Session %p: get ciphering resources", session);
|
||||
+ sess = (struct aes_cipher *)session;
|
||||
+
|
||||
+ /* Safely get the invocation parameters */
|
||||
+ if (param_types != exp_param_types)
|
||||
+ return TEE_ERROR_BAD_PARAMETERS;
|
||||
+
|
||||
+ res = ta2tee_algo_id(params[0].value.a, &sess->algo);
|
||||
+ if (res != TEE_SUCCESS)
|
||||
+ return res;
|
||||
+
|
||||
+ res = ta2tee_key_size(params[1].value.a, &sess->key_size);
|
||||
+ if (res != TEE_SUCCESS)
|
||||
+ return res;
|
||||
+
|
||||
+ res = ta2tee_mode_id(params[2].value.a, &sess->mode);
|
||||
+ if (res != TEE_SUCCESS)
|
||||
+ return res;
|
||||
+
|
||||
+ /*
|
||||
+ * Ready to allocate the resources which are:
|
||||
+ * - an operation handle, for an AES ciphering of given configuration
|
||||
+ * - a transient object that will be use to load the key materials
|
||||
+ * into the AES ciphering operation.
|
||||
+ */
|
||||
+
|
||||
+ /* Free potential previous operation */
|
||||
+ if (sess->op_handle != TEE_HANDLE_NULL)
|
||||
+ TEE_FreeOperation(sess->op_handle);
|
||||
+
|
||||
+ /* Allocate operation: AES/CTR, mode and size from params */
|
||||
+ res = TEE_AllocateOperation(&sess->op_handle,
|
||||
+ sess->algo,
|
||||
+ sess->mode,
|
||||
+ sess->key_size * 8);
|
||||
+ if (res != TEE_SUCCESS) {
|
||||
+ EMSG("Failed to allocate operation");
|
||||
+ sess->op_handle = TEE_HANDLE_NULL;
|
||||
+ goto err;
|
||||
+ }
|
||||
+
|
||||
+ /* Free potential previous transient object */
|
||||
+ if (sess->key_handle != TEE_HANDLE_NULL)
|
||||
+ TEE_FreeTransientObject(sess->key_handle);
|
||||
+
|
||||
+ /* Allocate transient object according to target key size */
|
||||
+ res = TEE_AllocateTransientObject(TEE_TYPE_AES,
|
||||
+ sess->key_size * 8,
|
||||
+ &sess->key_handle);
|
||||
+ if (res != TEE_SUCCESS) {
|
||||
+ EMSG("Failed to allocate transient object");
|
||||
+ sess->key_handle = TEE_HANDLE_NULL;
|
||||
+ goto err;
|
||||
+ }
|
||||
+
|
||||
+ /*
|
||||
+ * When loading a key in the cipher session, set_aes_key()
|
||||
+ * will reset the operation and load a key. But we cannot
|
||||
+ * reset and operation that has no key yet (GPD TEE Internal
|
||||
+ * Core API Specification – Public Release v1.1.1, section
|
||||
+ * 6.2.5 TEE_ResetOperation). In consequence, we will load a
|
||||
+ * dummy key in the operation so that operation can be reset
|
||||
+ * when updating the key.
|
||||
+ */
|
||||
+ key = TEE_Malloc(sess->key_size, 0);
|
||||
+ if (!key) {
|
||||
+ res = TEE_ERROR_OUT_OF_MEMORY;
|
||||
+ goto err;
|
||||
+ }
|
||||
+
|
||||
+ TEE_InitRefAttribute(&attr, TEE_ATTR_SECRET_VALUE, key, sess->key_size);
|
||||
+
|
||||
+ res = TEE_PopulateTransientObject(sess->key_handle, &attr, 1);
|
||||
+ if (res != TEE_SUCCESS) {
|
||||
+ EMSG("TEE_PopulateTransientObject failed, %x", res);
|
||||
+ goto err;
|
||||
+ }
|
||||
+
|
||||
+ res = TEE_SetOperationKey(sess->op_handle, sess->key_handle);
|
||||
+ if (res != TEE_SUCCESS) {
|
||||
+ EMSG("TEE_SetOperationKey failed %x", res);
|
||||
+ goto err;
|
||||
+ }
|
||||
+
|
||||
+ return res;
|
||||
+
|
||||
+err:
|
||||
+ if (sess->op_handle != TEE_HANDLE_NULL)
|
||||
+ TEE_FreeOperation(sess->op_handle);
|
||||
+ sess->op_handle = TEE_HANDLE_NULL;
|
||||
+
|
||||
+ if (sess->key_handle != TEE_HANDLE_NULL)
|
||||
+ TEE_FreeTransientObject(sess->key_handle);
|
||||
+ sess->key_handle = TEE_HANDLE_NULL;
|
||||
+
|
||||
+ return res;
|
||||
+}
|
||||
+
|
||||
+static TEE_Result derive_unique_key(uint8_t *key, uint16_t key_size,
|
||||
+ uint8_t *extra, uint16_t extra_size)
|
||||
+{
|
||||
+ TEE_TASessionHandle sess = TEE_HANDLE_NULL;
|
||||
+ TEE_Param params[TEE_NUM_PARAMS] = { };
|
||||
+ TEE_Result res = TEE_ERROR_GENERIC;
|
||||
+ uint32_t ret_orig = 0;
|
||||
+ uint32_t param_types = TEE_PARAM_TYPES(TEE_PARAM_TYPE_MEMREF_INPUT,
|
||||
+ TEE_PARAM_TYPE_MEMREF_OUTPUT,
|
||||
+ TEE_PARAM_TYPE_NONE,
|
||||
+ TEE_PARAM_TYPE_NONE);
|
||||
+
|
||||
+ res = TEE_OpenTASession(&(const TEE_UUID)PTA_SYSTEM_UUID,
|
||||
+ TEE_TIMEOUT_INFINITE, 0, NULL, &sess,
|
||||
+ &ret_orig);
|
||||
+ if (res)
|
||||
+ return res;
|
||||
+
|
||||
+ if (extra && extra_size) {
|
||||
+ params[0].memref.buffer = extra;
|
||||
+ params[0].memref.size = extra_size;
|
||||
+ }
|
||||
+
|
||||
+ params[1].memref.buffer = key;
|
||||
+ params[1].memref.size = key_size;
|
||||
+
|
||||
+ res = TEE_InvokeTACommand(sess, TEE_TIMEOUT_INFINITE,
|
||||
+ PTA_SYSTEM_DERIVE_TA_UNIQUE_KEY,
|
||||
+ param_types, params, &ret_orig);
|
||||
+
|
||||
+ TEE_CloseTASession(sess);
|
||||
+
|
||||
+ return res;
|
||||
+}
|
||||
+
|
||||
+/*
|
||||
+ * Process command TA_AES_CMD_SET_KEY. API in aes_ta.h
|
||||
+ */
|
||||
+static TEE_Result set_aes_key(void *session, uint32_t param_types,
|
||||
+ TEE_Param params[4])
|
||||
+{
|
||||
+ const uint32_t exp_param_types =
|
||||
+ TEE_PARAM_TYPES(TEE_PARAM_TYPE_VALUE_INPUT,
|
||||
+ TEE_PARAM_TYPE_NONE,
|
||||
+ TEE_PARAM_TYPE_NONE,
|
||||
+ TEE_PARAM_TYPE_NONE);
|
||||
+ struct aes_cipher *sess;
|
||||
+ TEE_Attribute attr;
|
||||
+ TEE_Result res;
|
||||
+ uint32_t key_sz;
|
||||
+ uint8_t *key;
|
||||
+
|
||||
+ /* Get ciphering context from session ID */
|
||||
+ DMSG("Session %p: load key material", session);
|
||||
+ sess = (struct aes_cipher *)session;
|
||||
+
|
||||
+ /* Safely get the invocation parameters */
|
||||
+ if (param_types != exp_param_types)
|
||||
+ return TEE_ERROR_BAD_PARAMETERS;
|
||||
+
|
||||
+ key_sz = params[0].value.a;
|
||||
+ if (key_sz != sess->key_size) {
|
||||
+ EMSG("Wrong key size %" PRIu32 ", expect %" PRIu32 " bytes",
|
||||
+ key_sz, sess->key_size);
|
||||
+ return TEE_ERROR_BAD_PARAMETERS;
|
||||
+ }
|
||||
+
|
||||
+ /* Request a derivate of the HUK */
|
||||
+ key = TEE_Malloc(key_sz, 0);
|
||||
+ if (!key)
|
||||
+ return TEE_ERROR_OUT_OF_MEMORY;
|
||||
+ res = derive_unique_key(key, key_sz, NULL, 0);
|
||||
+ if (res) {
|
||||
+ EMSG("derive_unique_key failed: returned %#" PRIx32, res);
|
||||
+ return res;
|
||||
+ }
|
||||
+
|
||||
+ /*
|
||||
+ * Load the key material into the configured operation
|
||||
+ * - create a secret key attribute with the key material
|
||||
+ * TEE_InitRefAttribute()
|
||||
+ * - reset transient object and load attribute data
|
||||
+ * TEE_ResetTransientObject()
|
||||
+ * TEE_PopulateTransientObject()
|
||||
+ * - load the key (transient object) into the ciphering operation
|
||||
+ * TEE_SetOperationKey()
|
||||
+ *
|
||||
+ * TEE_SetOperationKey() requires operation to be in "initial state".
|
||||
+ * We can use TEE_ResetOperation() to reset the operation but this
|
||||
+ * API cannot be used on operation with key(s) not yet set. Hence,
|
||||
+ * when allocating the operation handle, we load a dummy key.
|
||||
+ * Thus, set_key sequence always reset then set key on operation.
|
||||
+ */
|
||||
+
|
||||
+ TEE_InitRefAttribute(&attr, TEE_ATTR_SECRET_VALUE, key, key_sz);
|
||||
+
|
||||
+ TEE_ResetTransientObject(sess->key_handle);
|
||||
+ res = TEE_PopulateTransientObject(sess->key_handle, &attr, 1);
|
||||
+ if (res != TEE_SUCCESS) {
|
||||
+ EMSG("TEE_PopulateTransientObject failed, %x", res);
|
||||
+ return res;
|
||||
+ }
|
||||
+
|
||||
+ TEE_ResetOperation(sess->op_handle);
|
||||
+ res = TEE_SetOperationKey(sess->op_handle, sess->key_handle);
|
||||
+ if (res != TEE_SUCCESS) {
|
||||
+ EMSG("TEE_SetOperationKey failed %x", res);
|
||||
+ return res;
|
||||
+ }
|
||||
+
|
||||
+ return res;
|
||||
+}
|
||||
+
|
||||
+/*
|
||||
+ * Process command TA_AES_CMD_SET_IV. API in aes_ta.h
|
||||
+ */
|
||||
+static TEE_Result reset_aes_iv(void *session, uint32_t param_types,
|
||||
+ TEE_Param params[4])
|
||||
+{
|
||||
+ const uint32_t exp_param_types =
|
||||
+ TEE_PARAM_TYPES(TEE_PARAM_TYPE_MEMREF_INPUT,
|
||||
+ TEE_PARAM_TYPE_NONE,
|
||||
+ TEE_PARAM_TYPE_NONE,
|
||||
+ TEE_PARAM_TYPE_NONE);
|
||||
+ struct aes_cipher *sess;
|
||||
+ size_t iv_sz;
|
||||
+ char *iv;
|
||||
+
|
||||
+ /* Get ciphering context from session ID */
|
||||
+ DMSG("Session %p: reset initial vector", session);
|
||||
+ sess = (struct aes_cipher *)session;
|
||||
+
|
||||
+ /* Safely get the invocation parameters */
|
||||
+ if (param_types != exp_param_types)
|
||||
+ return TEE_ERROR_BAD_PARAMETERS;
|
||||
+
|
||||
+ iv = params[0].memref.buffer;
|
||||
+ iv_sz = params[0].memref.size;
|
||||
+
|
||||
+ /*
|
||||
+ * Init cipher operation with the initialization vector.
|
||||
+ */
|
||||
+ TEE_CipherInit(sess->op_handle, iv, iv_sz);
|
||||
+
|
||||
+ return TEE_SUCCESS;
|
||||
+}
|
||||
+
|
||||
+/*
|
||||
+ * Process command TA_AES_CMD_CIPHER. API in aes_ta.h
|
||||
+ */
|
||||
+static TEE_Result cipher_buffer(void *session, uint32_t param_types,
|
||||
+ TEE_Param params[4])
|
||||
+{
|
||||
+ const uint32_t exp_param_types =
|
||||
+ TEE_PARAM_TYPES(TEE_PARAM_TYPE_MEMREF_INPUT,
|
||||
+ TEE_PARAM_TYPE_MEMREF_OUTPUT,
|
||||
+ TEE_PARAM_TYPE_NONE,
|
||||
+ TEE_PARAM_TYPE_NONE);
|
||||
+ struct aes_cipher *sess;
|
||||
+
|
||||
+ /* Get ciphering context from session ID */
|
||||
+ DMSG("Session %p: cipher buffer", session);
|
||||
+ sess = (struct aes_cipher *)session;
|
||||
+
|
||||
+ /* Safely get the invocation parameters */
|
||||
+ if (param_types != exp_param_types)
|
||||
+ return TEE_ERROR_BAD_PARAMETERS;
|
||||
+
|
||||
+ if (params[1].memref.size < params[0].memref.size) {
|
||||
+ EMSG("Bad sizes: in %zd, out %zd", params[0].memref.size,
|
||||
+ params[1].memref.size);
|
||||
+ return TEE_ERROR_BAD_PARAMETERS;
|
||||
+ }
|
||||
+
|
||||
+ if (sess->op_handle == TEE_HANDLE_NULL)
|
||||
+ return TEE_ERROR_BAD_STATE;
|
||||
+
|
||||
+ /*
|
||||
+ * Process ciphering operation on provided buffers
|
||||
+ */
|
||||
+ return TEE_CipherUpdate(sess->op_handle,
|
||||
+ params[0].memref.buffer, params[0].memref.size,
|
||||
+ params[1].memref.buffer, ¶ms[1].memref.size);
|
||||
+}
|
||||
+
|
||||
+TEE_Result TA_CreateEntryPoint(void)
|
||||
+{
|
||||
+ /* Nothing to do */
|
||||
+ return TEE_SUCCESS;
|
||||
+}
|
||||
+
|
||||
+void TA_DestroyEntryPoint(void)
|
||||
+{
|
||||
+ /* Nothing to do */
|
||||
+}
|
||||
+
|
||||
+TEE_Result TA_OpenSessionEntryPoint(uint32_t __unused param_types,
|
||||
+ TEE_Param __unused params[4],
|
||||
+ void __unused **session)
|
||||
+{
|
||||
+ struct aes_cipher *sess;
|
||||
+
|
||||
+ /*
|
||||
+ * Allocate and init ciphering materials for the session.
|
||||
+ * The address of the structure is used as session ID for
|
||||
+ * the client.
|
||||
+ */
|
||||
+ sess = TEE_Malloc(sizeof(*sess), 0);
|
||||
+ if (!sess)
|
||||
+ return TEE_ERROR_OUT_OF_MEMORY;
|
||||
+
|
||||
+ sess->key_handle = TEE_HANDLE_NULL;
|
||||
+ sess->op_handle = TEE_HANDLE_NULL;
|
||||
+
|
||||
+ *session = (void *)sess;
|
||||
+ DMSG("Session %p: newly allocated", *session);
|
||||
+
|
||||
+ return TEE_SUCCESS;
|
||||
+}
|
||||
+
|
||||
+void TA_CloseSessionEntryPoint(void *session)
|
||||
+{
|
||||
+ struct aes_cipher *sess;
|
||||
+
|
||||
+ /* Get ciphering context from session ID */
|
||||
+ DMSG("Session %p: release session", session);
|
||||
+ sess = (struct aes_cipher *)session;
|
||||
+
|
||||
+ /* Release the session resources */
|
||||
+ if (sess->key_handle != TEE_HANDLE_NULL)
|
||||
+ TEE_FreeTransientObject(sess->key_handle);
|
||||
+ if (sess->op_handle != TEE_HANDLE_NULL)
|
||||
+ TEE_FreeOperation(sess->op_handle);
|
||||
+ TEE_Free(sess);
|
||||
+}
|
||||
+
|
||||
+TEE_Result TA_InvokeCommandEntryPoint(void *session,
|
||||
+ uint32_t cmd,
|
||||
+ uint32_t param_types,
|
||||
+ TEE_Param params[4])
|
||||
+{
|
||||
+ switch (cmd) {
|
||||
+ case TA_AES_CMD_PREPARE:
|
||||
+ return alloc_resources(session, param_types, params);
|
||||
+ case TA_AES_CMD_SET_KEY:
|
||||
+ return set_aes_key(session, param_types, params);
|
||||
+ case TA_AES_CMD_SET_IV:
|
||||
+ return reset_aes_iv(session, param_types, params);
|
||||
+ case TA_AES_CMD_CIPHER:
|
||||
+ return cipher_buffer(session, param_types, params);
|
||||
+ default:
|
||||
+ EMSG("Command ID 0x%x is not supported", cmd);
|
||||
+ return TEE_ERROR_NOT_SUPPORTED;
|
||||
+ }
|
||||
+}
|
||||
diff --git a/ta/aes_huk/include/aes_ta.h b/ta/aes_huk/include/aes_ta.h
|
||||
new file mode 100644
|
||||
index 000000000000..c07b4bc479ee
|
||||
--- /dev/null
|
||||
+++ b/ta/aes_huk/include/aes_ta.h
|
||||
@@ -0,0 +1,82 @@
|
||||
+/*
|
||||
+ * Copyright (c) 2017, Linaro Limited
|
||||
+ * All rights reserved.
|
||||
+ *
|
||||
+ * Redistribution and use in source and binary forms, with or without
|
||||
+ * modification, are permitted provided that the following conditions are met:
|
||||
+ *
|
||||
+ * 1. Redistributions of source code must retain the above copyright notice,
|
||||
+ * this list of conditions and the following disclaimer.
|
||||
+ *
|
||||
+ * 2. Redistributions in binary form must reproduce the above copyright notice,
|
||||
+ * this list of conditions and the following disclaimer in the documentation
|
||||
+ * and/or other materials provided with the distribution.
|
||||
+ *
|
||||
+ * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS"
|
||||
+ * AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
|
||||
+ * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
|
||||
+ * ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT HOLDER OR CONTRIBUTORS BE
|
||||
+ * LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
|
||||
+ * CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
|
||||
+ * SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
|
||||
+ * INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN
|
||||
+ * CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
|
||||
+ * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE
|
||||
+ * POSSIBILITY OF SUCH DAMAGE.
|
||||
+ */
|
||||
+
|
||||
+#ifndef __AES_TA_H__
|
||||
+#define __AES_TA_H__
|
||||
+
|
||||
+/* UUID of the AES example trusted application */
|
||||
+#define TA_AES_UUID \
|
||||
+ { 0xc2fad363, 0x5d9f, 0x4fc4, \
|
||||
+ { 0xa4, 0x17, 0x55, 0x58, 0x41, 0xe0, 0x57, 0x45 } }
|
||||
+
|
||||
+/*
|
||||
+ * TA_AES_CMD_PREPARE - Allocate resources for the AES ciphering
|
||||
+ * param[0] (value) a: TA_AES_ALGO_xxx, b: unused
|
||||
+ * param[1] (value) a: key size in bytes, b: unused
|
||||
+ * param[2] (value) a: TA_AES_MODE_ENCODE/_DECODE, b: unused
|
||||
+ * param[3] unused
|
||||
+ */
|
||||
+#define TA_AES_CMD_PREPARE 0
|
||||
+
|
||||
+#define TA_AES_ALGO_ECB 0
|
||||
+#define TA_AES_ALGO_CBC 1
|
||||
+#define TA_AES_ALGO_CTR 2
|
||||
+
|
||||
+#define TA_AES_SIZE_128BIT (128 / 8)
|
||||
+#define TA_AES_SIZE_256BIT (256 / 8)
|
||||
+
|
||||
+#define TA_AES_MODE_ENCODE 1
|
||||
+#define TA_AES_MODE_DECODE 0
|
||||
+
|
||||
+/*
|
||||
+ * TA_AES_CMD_SET_KEY - Allocate resources for the AES ciphering
|
||||
+ * param[0] (memref) key data, size shall equal key length
|
||||
+ * param[1] unused
|
||||
+ * param[2] unused
|
||||
+ * param[3] unused
|
||||
+ */
|
||||
+#define TA_AES_CMD_SET_KEY 1
|
||||
+
|
||||
+/*
|
||||
+ * TA_AES_CMD_SET_IV - reset IV
|
||||
+ * param[0] (memref) initial vector, size shall equal block length
|
||||
+ * param[1] unused
|
||||
+ * param[2] unused
|
||||
+ * param[3] unused
|
||||
+ */
|
||||
+#define TA_AES_CMD_SET_IV 2
|
||||
+
|
||||
+/*
|
||||
+ * TA_AES_CMD_CIPHER - Cipher input buffer into output buffer
|
||||
+ * param[0] (memref) input buffer
|
||||
+ * param[1] (memref) output buffer (shall be bigger than input buffer)
|
||||
+ * param[2] unused
|
||||
+ * param[3] unused
|
||||
+ */
|
||||
+#define TA_AES_CMD_CIPHER 3
|
||||
+
|
||||
+#endif /* __AES_TA_H */
|
||||
diff --git a/ta/aes_huk/sub.mk b/ta/aes_huk/sub.mk
|
||||
new file mode 100644
|
||||
index 000000000000..cfce14e6c119
|
||||
--- /dev/null
|
||||
+++ b/ta/aes_huk/sub.mk
|
||||
@@ -0,0 +1,3 @@
|
||||
+global-incdirs-y += include
|
||||
+global-incdirs-y += .
|
||||
+srcs-y += aes_ta.c
|
||||
diff --git a/ta/aes_huk/user_ta.mk b/ta/aes_huk/user_ta.mk
|
||||
new file mode 100644
|
||||
index 000000000000..d49d309558ba
|
||||
--- /dev/null
|
||||
+++ b/ta/aes_huk/user_ta.mk
|
||||
@@ -0,0 +1 @@
|
||||
+user-ta-uuid := c2fad363-5d9f-4fc4-a417-555841e05745
|
||||
diff --git a/ta/aes_huk/user_ta_header_defines.h b/ta/aes_huk/user_ta_header_defines.h
|
||||
new file mode 100644
|
||||
index 000000000000..9f944b8b9ab3
|
||||
--- /dev/null
|
||||
+++ b/ta/aes_huk/user_ta_header_defines.h
|
||||
@@ -0,0 +1,48 @@
|
||||
+/*
|
||||
+ * Copyright (c) 2017, Linaro Limited
|
||||
+ * All rights reserved.
|
||||
+ *
|
||||
+ * Redistribution and use in source and binary forms, with or without
|
||||
+ * modification, are permitted provided that the following conditions are met:
|
||||
+ *
|
||||
+ * 1. Redistributions of source code must retain the above copyright notice,
|
||||
+ * this list of conditions and the following disclaimer.
|
||||
+ *
|
||||
+ * 2. Redistributions in binary form must reproduce the above copyright notice,
|
||||
+ * this list of conditions and the following disclaimer in the documentation
|
||||
+ * and/or other materials provided with the distribution.
|
||||
+ *
|
||||
+ * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS"
|
||||
+ * AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
|
||||
+ * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
|
||||
+ * ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT HOLDER OR CONTRIBUTORS BE
|
||||
+ * LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
|
||||
+ * CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
|
||||
+ * SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
|
||||
+ * INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN
|
||||
+ * CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
|
||||
+ * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE
|
||||
+ * POSSIBILITY OF SUCH DAMAGE.
|
||||
+ */
|
||||
+
|
||||
+/*
|
||||
+ * The name of this file must not be modified
|
||||
+ */
|
||||
+
|
||||
+#ifndef USER_TA_HEADER_DEFINES_H
|
||||
+#define USER_TA_HEADER_DEFINES_H
|
||||
+
|
||||
+#include <aes_ta.h>
|
||||
+
|
||||
+#define TA_UUID TA_AES_UUID
|
||||
+
|
||||
+#define TA_FLAGS TA_FLAG_EXEC_DDR
|
||||
+#define TA_STACK_SIZE (2 * 1024)
|
||||
+#define TA_DATA_SIZE (32 * 1024)
|
||||
+
|
||||
+#define TA_CURRENT_TA_EXT_PROPERTIES \
|
||||
+ { "gp.ta.description", USER_TA_PROP_TYPE_STRING, \
|
||||
+ "Example of TA using an AES sequence" }, \
|
||||
+ { "gp.ta.version", USER_TA_PROP_TYPE_U32, &(const uint32_t){ 0x0010 } }
|
||||
+
|
||||
+#endif /*USER_TA_HEADER_DEFINES_H*/
|
||||
|
|
@ -9,6 +9,7 @@ SRC_URI = " \
|
|||
git://github.com/nxp-imx/imx-optee-os.git;protocol=https;branch=${SRCBRANCH} \
|
||||
file://0007-allow-setting-sysroot-for-clang.patch \
|
||||
file://0001-core-imx-support-ccimx93-dvk.patch \
|
||||
file://0002-core-ccimx93-enable-AES_HUK-trusted-application.patch \
|
||||
"
|
||||
SRCBRANCH = "lf-6.1.55_2.2.0"
|
||||
# Tag: lf-6.1.55-2.2.0
|
||||
|
|
|
|||
|
|
@ -0,0 +1,10 @@
|
|||
[Unit]
|
||||
Description=TEE Supplicant
|
||||
|
||||
[Service]
|
||||
User=root
|
||||
EnvironmentFile=-/etc/default/tee-supplicant
|
||||
ExecStart=/usr/sbin/tee-supplicant $OPTARGS
|
||||
|
||||
[Install]
|
||||
WantedBy=basic.target
|
||||
|
|
@ -0,0 +1,33 @@
|
|||
SUMMARY = "OPTEE Client"
|
||||
HOMEPAGE = "https://github.com/OP-TEE/optee_client"
|
||||
|
||||
LICENSE = "BSD-2-Clause"
|
||||
LIC_FILES_CHKSUM = "file://${S}/LICENSE;md5=69663ab153298557a59c67a60a743e5b"
|
||||
|
||||
inherit python3native systemd cmake
|
||||
|
||||
SRC_URI = "git://github.com/OP-TEE/optee_client.git;protocol=https;branch=master \
|
||||
file://tee-supplicant.service \
|
||||
"
|
||||
|
||||
SRCREV = "06db73b3f3fdb8d23eceaedbc46c49c0b45fd1e2"
|
||||
|
||||
PV = "3.16.0+git${SRCPV}"
|
||||
|
||||
S = "${WORKDIR}/git"
|
||||
|
||||
SYSTEMD_SERVICE:${PN} = "tee-supplicant.service"
|
||||
|
||||
EXTRA_OECMAKE = " \
|
||||
-DCFG_TEE_FS_PARENT_PATH='${localstatedir}/lib/tee' \
|
||||
-DCFG_WERROR=OFF \
|
||||
-DCFG_TEE_CLIENT_LOG_LEVEL=2 \
|
||||
-DBUILD_SHARED_LIBS=ON \
|
||||
"
|
||||
|
||||
do_install:append() {
|
||||
if ${@bb.utils.contains('DISTRO_FEATURES','systemd','true','false',d)}; then
|
||||
install -D -p -m0644 ${WORKDIR}/tee-supplicant.service ${D}${systemd_system_unitdir}/tee-supplicant.service
|
||||
fi
|
||||
}
|
||||
FILES:${PN} += "${systemd_system_unitdir}"
|
||||
|
|
@ -1,6 +1,6 @@
|
|||
# Copyright (C) 2016 Freescale Semiconductor
|
||||
# Copyright 2017-2018 NXP
|
||||
# Copyright (C) 2018-2023 Digi International.
|
||||
# Copyright (C) 2018-2024 Digi International.
|
||||
|
||||
DESCRIPTION = "i.MX System Controller Firmware, customized for Digi platforms"
|
||||
LICENSE = "Proprietary"
|
||||
|
|
@ -11,8 +11,8 @@ inherit pkgconfig deploy
|
|||
|
||||
SRC_URI = "${DIGI_PKG_SRC}/${BPN}-${PV}.tar.gz"
|
||||
|
||||
SRC_URI[md5sum] = "d7d74493bb04ff73341481a9fbc551eb"
|
||||
SRC_URI[sha256sum] = "aa4acd333bb8fc137854d276d12961a9bdf29064a94bcf4d3c76761d79afaca9"
|
||||
SRC_URI[md5sum] = "b7b9b5598b9ffc3a0f1663b41992aac0"
|
||||
SRC_URI[sha256sum] = "59ebc2ebbf75c0b96f4fb70f8209f796543c5932e58f09031b9df99f110edcc9"
|
||||
|
||||
S = "${WORKDIR}/${PN}-${PV}"
|
||||
|
||||
|
|
@ -0,0 +1,106 @@
|
|||
# Copyright (C) 2022-2024 Digi International Inc.
|
||||
|
||||
SUMMARY = "Murata Infineon firmware binaries"
|
||||
SECTION = "base"
|
||||
LICENSE = "CYPRESS-EULA"
|
||||
LIC_FILES_CHKSUM = "file://${S}/cyw-bt-patch/LICENCE.cypress;md5=cbc5f665d04f741f1e006d2096236ba7"
|
||||
|
||||
SRC_URI = " \
|
||||
git://github.com/murata-wireless/cyw-fmac-fw;protocol=http;branch=hedorah;destsuffix=cyw-fmac-fw;name=cyw-fmac-fw \
|
||||
git://github.com/murata-wireless/cyw-fmac-nvram;protocol=http;branch=hedorah;destsuffix=cyw-fmac-nvram;name=cyw-fmac-nvram \
|
||||
git://github.com/murata-wireless/cyw-bt-patch;protocol=http;branch=mickledore-hedorah;destsuffix=cyw-bt-patch;name=cyw-bt-patch \
|
||||
git://github.com/murata-wireless/cyw-fmac-utils-imx32;protocol=http;branch=master;destsuffix=cyw-fmac-utils-imx32;name=cyw-fmac-utils-imx32 \
|
||||
git://github.com/murata-wireless/cyw-fmac-utils-imx64;protocol=http;branch=master;destsuffix=cyw-fmac-utils-imx64;name=cyw-fmac-utils-imx64 \
|
||||
file://cyfmac4373-sdio_US.clm_blob \
|
||||
file://cyfmac4373-sdio_World.clm_blob \
|
||||
file://cyw4373-autocountry \
|
||||
file://cyw4373-autocountry.service \
|
||||
"
|
||||
|
||||
SRCREV_cyw-fmac-fw="db8deb03b8d24e5069ac4581d1c35b767012e926"
|
||||
SRCREV_cyw-fmac-nvram="9b7d93eb3e13b2d2ed8ce3a01338ceb54151b77a"
|
||||
SRCREV_cyw-bt-patch="3275a7036dd0d6eacecccccc760b7e7fe91a9e32"
|
||||
SRCREV_cyw-fmac-utils-imx32="fcdd231e9bb23db3c93c10e5dff43a1182f220c5"
|
||||
SRCREV_cyw-fmac-utils-imx64="52cc4cc6be8629781014505aa276b67e18cf6e8d"
|
||||
|
||||
SRCREV_default = "${AUTOREV}"
|
||||
|
||||
S = "${WORKDIR}"
|
||||
|
||||
DEPENDS = "libnl"
|
||||
|
||||
do_install () {
|
||||
bbnote "Installing Murata Infineon firmware binaries: "
|
||||
install -d ${D}${base_libdir}/firmware/cypress
|
||||
install -d ${D}${base_libdir}/firmware/brcm
|
||||
install -d ${D}${sbindir}
|
||||
|
||||
# Install Bluetooth patch *.HCD file
|
||||
# For Murata 2AE (LBEE5PK2AE-564)
|
||||
install -m 444 ${S}/cyw-bt-patch/BCM4373A0_001.001.025.0103.0155.FCC.CE.2AE.hcd ${D}${base_libdir}/firmware/brcm/BCM4373A0_FCC.CE.hcd
|
||||
install -m 444 ${S}/cyw-bt-patch/BCM4373A0_001.001.025.0103.0156.JRL.2AE.hcd ${D}${base_libdir}/firmware/brcm/BCM4373A0_JRL.hcd
|
||||
|
||||
# Install WLAN firmware file (*.bin) and Regulatory binary file (*.clm_blob)
|
||||
# For Murata 2AE (LBEE5PK2AE-564)
|
||||
install -m 444 ${S}/cyw-fmac-fw/cyfmac4373-sdio.2AE.bin ${D}${base_libdir}/firmware/cypress/cyfmac4373-sdio.bin
|
||||
install -m 444 cyfmac4373-sdio_US.clm_blob ${D}${base_libdir}/firmware/cypress/cyfmac4373-sdio_US.clm_blob
|
||||
install -m 444 cyfmac4373-sdio_World.clm_blob ${D}${base_libdir}/firmware/cypress/cyfmac4373-sdio_World.clm_blob
|
||||
|
||||
# Install NVRAM files (*.txt)
|
||||
# For Murata 2AE (LBEE5PK2AE-564)
|
||||
install -m 444 ${S}/cyw-fmac-nvram/cyfmac4373-sdio.2AE.txt ${D}${base_libdir}/firmware/cypress/cyfmac4373-sdio.txt
|
||||
|
||||
# Install WLAN client utility binary based on 32-bit/64-bit arch
|
||||
if [ ${TARGET_ARCH} = "aarch64" ]; then
|
||||
install -m 755 ${S}/cyw-fmac-utils-imx64/wl ${D}${sbindir}
|
||||
else
|
||||
install -m 755 ${S}/cyw-fmac-utils-imx32/wl ${D}${sbindir}
|
||||
fi
|
||||
|
||||
if ${@bb.utils.contains('DISTRO_FEATURES', 'systemd', 'true', 'false', d)}; then
|
||||
# Install systemd unit files
|
||||
install -d ${D}${systemd_unitdir}/system/
|
||||
install -m 0644 ${WORKDIR}/cyw4373-autocountry.service ${D}${systemd_unitdir}/system/cyw4373-autocountry.service
|
||||
fi
|
||||
|
||||
install -d ${D}${sysconfdir}/init.d/
|
||||
install -m 0755 ${WORKDIR}/cyw4373-autocountry ${D}${sysconfdir}/cyw4373-autocountry
|
||||
ln -sf /etc/cyw4373-autocountry ${D}${sysconfdir}/init.d/cyw4373-autocountry
|
||||
}
|
||||
|
||||
inherit update-rc.d systemd
|
||||
|
||||
INITSCRIPT_PACKAGES += "${PN}-autocountry"
|
||||
INITSCRIPT_NAME:${PN}-autocountry = "cyw4373-autocountry"
|
||||
INITSCRIPT_PARAMS:${PN}-autocountry = "start 19 2 3 4 5 . stop 21 0 1 6 ."
|
||||
|
||||
SYSTEMD_PACKAGES = "${PN}-autocountry"
|
||||
SYSTEMD_SERVICE:${PN}-autocountry = "cyw4373-autocountry.service"
|
||||
|
||||
PACKAGES =+ " \
|
||||
${PN}-mfgtest \
|
||||
${PN}-autocountry \
|
||||
"
|
||||
|
||||
FILES:${PN} = " \
|
||||
${base_libdir}/firmware \
|
||||
"
|
||||
|
||||
FILES:${PN}-mfgtest = " \
|
||||
${sbindir} \
|
||||
"
|
||||
|
||||
FILES:${PN}-autocountry = " \
|
||||
${sysconfdir}/cyw4373-autocountry \
|
||||
${sysconfdir}/init.d/cyw4373-autocountry \
|
||||
${systemd_unitdir}/system/cyw4373-autocountry.service \
|
||||
"
|
||||
|
||||
RDEPENDS:${PN}:append = " ${PN}-autocountry"
|
||||
RDEPENDS:${PN}-autocountry:append = " ${PN}-mfgtest"
|
||||
|
||||
INSANE_SKIP:${PN} += "build-deps"
|
||||
INSANE_SKIP:${PN} += "file-rdeps"
|
||||
|
||||
PACKAGE_ARCH = "${MACHINE_ARCH}"
|
||||
COMPATIBLE_MACHINE = "(ccmp1)"
|
||||
Binary file not shown.
Binary file not shown.
|
|
@ -0,0 +1,38 @@
|
|||
#!/bin/sh
|
||||
#===============================================================================
|
||||
#
|
||||
# Copyright (C) 2024 by Digi International Inc.
|
||||
# All rights reserved.
|
||||
#
|
||||
# This program is free software; you can redistribute it and/or modify it
|
||||
# under the terms of the GNU General Public License version 2 as published by
|
||||
# the Free Software Foundation.
|
||||
#
|
||||
#
|
||||
# !Description: Enable Wireless autocountry feature (802.11d)
|
||||
#
|
||||
#===============================================================================
|
||||
|
||||
SCRIPTNAME="$(basename ${0})"
|
||||
|
||||
log() {
|
||||
if type "systemd-cat" >/dev/null 2>/dev/null; then
|
||||
systemd-cat -p "${1}" -t "${SCRIPTNAME}" printf "%s" "${2}"
|
||||
else
|
||||
logger -p "${1}" -t "${SCRIPTNAME}" "${2}"
|
||||
fi
|
||||
}
|
||||
|
||||
# Only for Wireless variants
|
||||
if [ -d "/proc/device-tree/wireless" ]; then
|
||||
# Check if WorldWide regulatory domain is available
|
||||
if wl country list | grep -qs ^XZ; then
|
||||
# Select WorldWide Country Code as driver operational region
|
||||
wl country XZ/0 agg
|
||||
# Select WorldWide Country Code for use with Auto Contry Discovery
|
||||
wl autocountry_default XZ
|
||||
# Enable 802.11d
|
||||
wl autocountry 1
|
||||
log info "Set WorldWide regulatory domain"
|
||||
fi
|
||||
fi
|
||||
|
|
@ -0,0 +1,10 @@
|
|||
[Unit]
|
||||
Description=CYW4373 autocountry (802.11d)
|
||||
After=network.target suspend.target
|
||||
|
||||
[Service]
|
||||
Type=oneshot
|
||||
ExecStart=/etc/cyw4373-autocountry
|
||||
|
||||
[Install]
|
||||
WantedBy=multi-user.target suspend.target
|
||||
|
|
@ -0,0 +1,30 @@
|
|||
# Copyright (C) 2023-2024, Digi International.
|
||||
|
||||
SUMMARY = "Murata NXP firmware binaries"
|
||||
LICENSE = "GPL-2.0-only"
|
||||
LIC_FILES_CHKSUM = "file://LICENSE;md5=ffa10f40b98be2c2bc9608f56827ed23"
|
||||
|
||||
SRCBRANCH = "imx-6-1-1"
|
||||
SRCREV = "6103e224be638f5b421c323993f29bb6c0ada44a"
|
||||
SRC_URI = "git://github.com/murata-wireless/nxp-linux-calibration;protocol=http;branch=${SRCBRANCH}"
|
||||
|
||||
S = "${WORKDIR}/git"
|
||||
|
||||
do_configure[noexec] = "1"
|
||||
do_compile[noexec] = "1"
|
||||
|
||||
do_install () {
|
||||
install -d ${D}${nonarch_base_libdir}/firmware/nxp
|
||||
install -m 0644 murata/files/2DL/* ${D}${nonarch_base_libdir}/firmware/nxp
|
||||
# For the EU BT power file, set the baudrate to 3Mbps (as used by the btnxpuart driver)
|
||||
sed -i -e "s,00 C2 01 00 00 00 00 00 00 00 00 00,C0 C6 2D 00 00 00 00 00 00 00 00 00,g" \
|
||||
${D}${nonarch_base_libdir}/firmware/nxp/bt_power_config_EU.sh
|
||||
# For all the BT power scripts, replace the hcitool reset command to avoid misleading BT behaviour.
|
||||
sed -i -e "s,hcitool -i hci0 cmd 0x03 0x003,hciconfig hci0 reset,g" \
|
||||
${D}${nonarch_base_libdir}/firmware/nxp/bt_power_config*.sh
|
||||
}
|
||||
|
||||
FILES:${PN} = "${nonarch_base_libdir}/firmware"
|
||||
|
||||
PACKAGE_ARCH = "${MACHINE_ARCH}"
|
||||
COMPATIBLE_MACHINE = "ccimx93"
|
||||
|
|
@ -1,70 +0,0 @@
|
|||
# Copyright (C) 2022,2023 Digi International.
|
||||
|
||||
SUMMARY = "Murata firmware binaries"
|
||||
SECTION = "base"
|
||||
LICENSE = "CYPRESS-EULA"
|
||||
LIC_FILES_CHKSUM = "file://${S}/cyw-bt-patch/LICENCE.cypress;md5=cbc5f665d04f741f1e006d2096236ba7"
|
||||
|
||||
SRC_URI = " \
|
||||
git://github.com/murata-wireless/cyw-fmac-fw;protocol=http;branch=fafnir;destsuffix=cyw-fmac-fw;name=cyw-fmac-fw \
|
||||
git://github.com/murata-wireless/cyw-fmac-nvram;protocol=http;branch=fafnir;destsuffix=cyw-fmac-nvram;name=cyw-fmac-nvram \
|
||||
git://github.com/murata-wireless/cyw-bt-patch;protocol=http;branch=master;destsuffix=cyw-bt-patch;name=cyw-bt-patch \
|
||||
git://github.com/murata-wireless/cyw-fmac-utils-imx32;protocol=http;branch=fafnir;destsuffix=cyw-fmac-utils-imx32;name=cyw-fmac-utils-imx32 \
|
||||
git://github.com/murata-wireless/cyw-fmac-utils-imx64;protocol=http;branch=fafnir;destsuffix=cyw-fmac-utils-imx64;name=cyw-fmac-utils-imx64 \
|
||||
file://cyfmac4373-sdio_US.clm_blob \
|
||||
"
|
||||
|
||||
SRCREV_cyw-fmac-fw="1f83e807b8187508c811a7d91a353a768fef2d37"
|
||||
SRCREV_cyw-fmac-nvram="303acf1b04441f62fbc48d278a70a099fabacb4a"
|
||||
SRCREV_cyw-bt-patch="9d24c254dae92af99ddfd661a4ea30af69190038"
|
||||
SRCREV_cyw-fmac-utils-imx32="e248804b6ba386fedcd462ddd9394f42f73a17af"
|
||||
SRCREV_cyw-fmac-utils-imx64="1bc78d68f9609290b2f6578516011c57691f7815"
|
||||
|
||||
SRCREV_default = "${AUTOREV}"
|
||||
|
||||
S = "${WORKDIR}"
|
||||
|
||||
DEPENDS = "libnl"
|
||||
|
||||
do_install () {
|
||||
bbnote "Installing Murata firmware binaries: "
|
||||
install -d ${D}${base_libdir}/firmware/cypress
|
||||
install -d ${D}${base_libdir}/firmware/brcm
|
||||
install -d ${D}${sbindir}
|
||||
|
||||
# Install Bluetooth patch *.HCD file
|
||||
# For Murata 2AE (LBEE5PK2AE-564)
|
||||
install -m 444 ${S}/cyw-bt-patch/BCM4373A0_001.001.025.0103.0155.FCC.CE.2AE.hcd ${D}${base_libdir}/firmware/brcm/BCM4373A0_FCC.CE.hcd
|
||||
|
||||
# Install WLAN firmware file (*.bin) and Regulatory binary file (*.clm_blob)
|
||||
# For Murata 2AE (LBEE5PK2AE-564)
|
||||
install -m 444 ${S}/cyw-fmac-fw/cyfmac4373-sdio.2AE.bin ${D}${base_libdir}/firmware/cypress/cyfmac4373-sdio.bin
|
||||
install -m 444 cyfmac4373-sdio_US.clm_blob ${D}${base_libdir}/firmware/cypress/cyfmac4373-sdio_US.clm_blob
|
||||
|
||||
# Install NVRAM files (*.txt)
|
||||
# For Murata 2AE (LBEE5PK2AE-564)
|
||||
install -m 444 ${S}/cyw-fmac-nvram/cyfmac4373-sdio.2AE.txt ${D}${base_libdir}/firmware/cypress/cyfmac4373-sdio.txt
|
||||
|
||||
# Install WLAN client utility binary based on 32-bit/64-bit arch
|
||||
if [ ${TARGET_ARCH} = "aarch64" ]; then
|
||||
install -m 755 ${S}/cyw-fmac-utils-imx64/wl ${D}${sbindir}
|
||||
else
|
||||
install -m 755 ${S}/cyw-fmac-utils-imx32/wl ${D}${sbindir}
|
||||
fi
|
||||
}
|
||||
|
||||
PACKAGES =+ "${PN}-mfgtest"
|
||||
|
||||
FILES:${PN} = " \
|
||||
${base_libdir}/firmware \
|
||||
"
|
||||
|
||||
FILES:${PN}-mfgtest = " \
|
||||
${sbindir} \
|
||||
"
|
||||
|
||||
INSANE_SKIP:${PN} += "build-deps"
|
||||
INSANE_SKIP:${PN} += "file-rdeps"
|
||||
|
||||
PACKAGE_ARCH = "${MACHINE_ARCH}"
|
||||
COMPATIBLE_MACHINE = "(ccmp1)"
|
||||
Binary file not shown.
|
|
@ -132,6 +132,10 @@ do_install() {
|
|||
length="$(expr $(stat -L -c %s ${D}${base_libdir}/firmware/qca/nvm_tlv_3.2.bin) - 4)"
|
||||
/bin/echo -ne "\x$(printf '%02x' $(expr $length % 256))" | dd of=${D}${base_libdir}/firmware/qca/nvm_tlv_3.2.bin bs=1 seek=1 count=1 conv=notrunc,fsync
|
||||
/bin/echo -ne "\x$(printf '%02x' $(expr $length / 256))" | dd of=${D}${base_libdir}/firmware/qca/nvm_tlv_3.2.bin bs=1 seek=2 count=1 conv=notrunc,fsync
|
||||
|
||||
# Create World BDF file
|
||||
cp ${D}${WIFI_FW_PATH}/bdwlan30_US.bin ${D}${WIFI_FW_PATH}/bdwlan30_World.bin
|
||||
/bin/echo -ne "\x60\x00" | dd of="${D}${WIFI_FW_PATH}/bdwlan30_World.bin" bs=1 seek=12 count=2 conv=notrunc,fsync
|
||||
}
|
||||
|
||||
QCA_MODEL ?= "qca6564"
|
||||
|
|
|
|||
Binary file not shown.
|
|
@ -18,10 +18,10 @@ Signed-off-by: Gabriel Valcazar <gabriel.valcazar@digi.com>
|
|||
2 files changed, 119 insertions(+)
|
||||
|
||||
diff --git a/src/libuboot.h b/src/libuboot.h
|
||||
index bfcaeb1d609f..b15969f89174 100644
|
||||
index 3ed3244..e83b3a5 100644
|
||||
--- a/src/libuboot.h
|
||||
+++ b/src/libuboot.h
|
||||
@@ -159,6 +159,29 @@ const char *libuboot_getname(void *entry);
|
||||
@@ -201,6 +201,29 @@ const char *libuboot_getname(void *entry);
|
||||
*/
|
||||
const char *libuboot_getvalue(void *entry);
|
||||
|
||||
|
|
@ -52,11 +52,11 @@ index bfcaeb1d609f..b15969f89174 100644
|
|||
}
|
||||
#endif
|
||||
diff --git a/src/uboot_env.c b/src/uboot_env.c
|
||||
index 2fd08f5a07db..87f831b0cdc7 100644
|
||||
index ae85c7e..358dfbb 100644
|
||||
--- a/src/uboot_env.c
|
||||
+++ b/src/uboot_env.c
|
||||
@@ -1632,3 +1632,99 @@ void libuboot_close(struct uboot_ctx *ctx) {
|
||||
void libuboot_exit(struct uboot_ctx *ctx) {
|
||||
@@ -2103,3 +2103,99 @@ void libuboot_exit(struct uboot_ctx *ctx)
|
||||
|
||||
free(ctx);
|
||||
}
|
||||
+
|
||||
|
|
@ -27,10 +27,10 @@ Signed-off-by: Gabriel Valcazar <gabriel.valcazar@digi.com>
|
|||
2 files changed, 90 insertions(+), 2 deletions(-)
|
||||
|
||||
diff --git a/src/uboot_env.c b/src/uboot_env.c
|
||||
index 87f831b0cdc7..539e22f9a8ac 100644
|
||||
index 358dfbb..c1f334e 100644
|
||||
--- a/src/uboot_env.c
|
||||
+++ b/src/uboot_env.c
|
||||
@@ -431,6 +431,73 @@ static int check_env_device(struct uboot_ctx *ctx, struct uboot_flash_env *dev)
|
||||
@@ -581,6 +581,73 @@ static int check_env_device(struct uboot_flash_env *dev)
|
||||
return 0;
|
||||
}
|
||||
|
||||
|
|
@ -104,9 +104,9 @@ index 87f831b0cdc7..539e22f9a8ac 100644
|
|||
static bool check_compatible_devices(struct uboot_ctx *ctx)
|
||||
{
|
||||
if (!ctx->redundant)
|
||||
@@ -442,6 +509,12 @@ static bool check_compatible_devices(struct uboot_ctx *ctx)
|
||||
@@ -592,6 +659,12 @@ static bool check_compatible_devices(struct uboot_ctx *ctx)
|
||||
return false;
|
||||
if (ctx->envdevs[0].envsize != ctx->envdevs[1].envsize)
|
||||
if (ctx->envdevs[0].envsize != ctx->envdevs[1].envsize)
|
||||
return false;
|
||||
+ if (ctx->envdevs[0].offset == ctx->envdevs[1].offset) {
|
||||
+ ctx->dynamic_env = true;
|
||||
|
|
@ -117,7 +117,7 @@ index 87f831b0cdc7..539e22f9a8ac 100644
|
|||
|
||||
return true;
|
||||
}
|
||||
@@ -488,7 +561,7 @@ static int fileread(struct uboot_flash_env *dev, void *data)
|
||||
@@ -638,7 +711,7 @@ static int fileread(struct uboot_flash_env *dev, void *data)
|
||||
return ret;
|
||||
}
|
||||
|
||||
|
|
@ -126,7 +126,7 @@ index 87f831b0cdc7..539e22f9a8ac 100644
|
|||
{
|
||||
size_t count;
|
||||
size_t blocksize;
|
||||
@@ -507,6 +580,17 @@ static int mtdread(struct uboot_flash_env *dev, void *data)
|
||||
@@ -657,6 +730,17 @@ static int mtdread(struct uboot_flash_env *dev, void *data)
|
||||
ret = read(dev->fd, data, dev->envsize);
|
||||
break;
|
||||
case MTD_NANDFLASH:
|
||||
|
|
@ -144,7 +144,7 @@ index 87f831b0cdc7..539e22f9a8ac 100644
|
|||
if (dev->offset)
|
||||
if (lseek(dev->fd, dev->offset, SEEK_SET) < 0) {
|
||||
ret = -EIO;
|
||||
@@ -582,7 +666,7 @@ static int devread(struct uboot_ctx *ctx, unsigned int copy, void *data)
|
||||
@@ -732,7 +816,7 @@ static int devread(struct uboot_ctx *ctx, unsigned int copy, void *data)
|
||||
ret = fileread(dev, data);
|
||||
break;
|
||||
case DEVICE_MTD:
|
||||
|
|
@ -154,13 +154,13 @@ index 87f831b0cdc7..539e22f9a8ac 100644
|
|||
case DEVICE_UBI:
|
||||
ret = ubiread(dev, data);
|
||||
diff --git a/src/uboot_private.h b/src/uboot_private.h
|
||||
index 22c8c14ce8cc..591df20d6936 100644
|
||||
index 40e5446..c8fecc4 100644
|
||||
--- a/src/uboot_private.h
|
||||
+++ b/src/uboot_private.h
|
||||
@@ -113,10 +113,14 @@ struct uboot_ctx {
|
||||
@@ -114,10 +114,14 @@ LIST_HEAD(vars, var_entry);
|
||||
struct uboot_ctx {
|
||||
/** true if the environment is redundant */
|
||||
bool redundant;
|
||||
/** true if the environment is encrypted */
|
||||
bool encrypted;
|
||||
+ /** true if the environment is dynamic */
|
||||
+ bool dynamic_env;
|
||||
/** set to valid after a successful load */
|
||||
|
|
@ -169,6 +169,6 @@ index 22c8c14ce8cc..591df20d6936 100644
|
|||
size_t size;
|
||||
+ /** top limit of the dynamic environment */
|
||||
+ loff_t top_limit;
|
||||
/** usable environment size */
|
||||
unsigned int usable_size;
|
||||
/** devices where environment is stored */
|
||||
struct uboot_flash_env envdevs[2];
|
||||
/** Set which device contains the current(last valid) environment */
|
||||
|
|
@ -15,26 +15,63 @@ Signed-off-by: Diaz de Grenu, Jose <Jose.DiazdeGrenu@digi.com>
|
|||
Signed-off-by: Gonzalo Ruiz <Gonzalo.Ruiz@digi.com>
|
||||
Signed-off-by: Hector Palacios <hector.palacios@digi.com>
|
||||
Signed-off-by: Gabriel Valcazar <gabriel.valcazar@digi.com>
|
||||
|
||||
# This is the commit message #2:
|
||||
|
||||
fall back to read HWID from nvmem device if not available on DT
|
||||
|
||||
Old U-Boot versions don't populate the HWID on the device tree. This may
|
||||
be used as a key modifier for TrustFence encryption and, if not available
|
||||
on the DT, newer firmware may be unable to unencrypt the U-Boot
|
||||
environment.
|
||||
|
||||
This patch implements a fall-back function to query the HWID directly from
|
||||
the nvmem device node if it cannot locate it at the DT.
|
||||
This is only implemented for ccimx6 family, which may be in the case of
|
||||
having an old U-Boot.
|
||||
|
||||
https://onedigi.atlassian.net/browse/DEL-8444
|
||||
|
||||
Signed-off-by: Hector Palacios <hector.palacios@digi.com>
|
||||
|
||||
# This is the commit message #3:
|
||||
|
||||
ubootenv: generalize env encryption code
|
||||
|
||||
Generalize the code to make room for Optee-based encryption.
|
||||
* Move the code to the crypt.c/h files to minimize changes on the upstream
|
||||
uboot_env.c file.
|
||||
* Rename env_caam_get_keymod to env_get_keymod as this function is not
|
||||
CAAM-specific.
|
||||
* Create a public env_crypt function that will select the proper (CAAM,
|
||||
Optee) implementation.
|
||||
|
||||
Signed-off-by: Javier Viguera <javier.viguera@digi.com>
|
||||
---
|
||||
src/CMakeLists.txt | 2 +
|
||||
src/caam_keyblob.h | 42 +++++++
|
||||
src/md5.c | 275 ++++++++++++++++++++++++++++++++++++++++++++
|
||||
src/md5.h | 24 ++++
|
||||
src/uboot_env.c | 131 +++++++++++++++++++++
|
||||
src/uboot_private.h | 4 +
|
||||
6 files changed, 478 insertions(+)
|
||||
src/CMakeLists.txt | 4 +
|
||||
src/caam_keyblob.h | 42 +++++++
|
||||
src/crypt.c | 179 +++++++++++++++++++++++++++++
|
||||
src/crypt.h | 10 ++
|
||||
src/md5.c | 275 +++++++++++++++++++++++++++++++++++++++++++++
|
||||
src/md5.h | 24 ++++
|
||||
src/uboot_env.c | 18 +++
|
||||
7 files changed, 552 insertions(+)
|
||||
create mode 100644 src/caam_keyblob.h
|
||||
create mode 100644 src/crypt.c
|
||||
create mode 100644 src/crypt.h
|
||||
create mode 100644 src/md5.c
|
||||
create mode 100644 src/md5.h
|
||||
|
||||
diff --git a/src/CMakeLists.txt b/src/CMakeLists.txt
|
||||
index 4b71bc588827..d7e38a12feed 100644
|
||||
index ababe0f..638f1c1 100644
|
||||
--- a/src/CMakeLists.txt
|
||||
+++ b/src/CMakeLists.txt
|
||||
@@ -1,6 +1,8 @@
|
||||
@@ -4,6 +4,10 @@
|
||||
cmake_minimum_required (VERSION 2.6)
|
||||
# Sources and private headers
|
||||
SET(libubootenv_SOURCES
|
||||
+ crypt.c
|
||||
+ crypt.h
|
||||
+ md5.c
|
||||
+ md5.h
|
||||
uboot_env.c
|
||||
|
|
@ -42,7 +79,7 @@ index 4b71bc588827..d7e38a12feed 100644
|
|||
)
|
||||
diff --git a/src/caam_keyblob.h b/src/caam_keyblob.h
|
||||
new file mode 100644
|
||||
index 000000000000..e313e87a3854
|
||||
index 0000000..e313e87
|
||||
--- /dev/null
|
||||
+++ b/src/caam_keyblob.h
|
||||
@@ -0,0 +1,42 @@
|
||||
|
|
@ -88,9 +125,210 @@ index 000000000000..e313e87a3854
|
|||
+#endif
|
||||
+
|
||||
+#endif /* CAAM_KEYBLOB_H */
|
||||
diff --git a/src/crypt.c b/src/crypt.c
|
||||
new file mode 100644
|
||||
index 0000000..213cffd
|
||||
--- /dev/null
|
||||
+++ b/src/crypt.c
|
||||
@@ -0,0 +1,179 @@
|
||||
+/*
|
||||
+ * Copyright 2024 Digi International Inc
|
||||
+ *
|
||||
+ * SPDX-License-Identifier: GPL-2.0+
|
||||
+ */
|
||||
+
|
||||
+#include <arpa/inet.h>
|
||||
+#include <fcntl.h>
|
||||
+#include <stdbool.h>
|
||||
+#include <stdio.h>
|
||||
+#include <stdlib.h>
|
||||
+#include <string.h>
|
||||
+#include <sys/ioctl.h>
|
||||
+#include <sys/stat.h>
|
||||
+#include <unistd.h>
|
||||
+
|
||||
+#include "caam_keyblob.h"
|
||||
+#include "md5.h"
|
||||
+
|
||||
+/*
|
||||
+ * The BLOB includes a random AES-256 key (32 bytes) and a
|
||||
+ * Message Authentication Code (MAC) (16 bytes)
|
||||
+ */
|
||||
+#define BLOB_OVERHEAD 48
|
||||
+#define CAAM_KEY_DEV "/dev/caam_kb"
|
||||
+#define MAX_HWID_WORDS 4
|
||||
+
|
||||
+/* Function that checks if machine is compatible (on the DT) */
|
||||
+static bool machine_is_compatible(char *machine)
|
||||
+{
|
||||
+ int fd, nchars, len = 0;
|
||||
+ int ret = false;
|
||||
+ char str[256];
|
||||
+ char *p = str;
|
||||
+
|
||||
+ fd = open("/proc/device-tree/compatible", O_RDONLY);
|
||||
+ if (fd < 0)
|
||||
+ return false;
|
||||
+
|
||||
+ nchars = read(fd, str, 255);
|
||||
+ while (len < nchars) {
|
||||
+ if (!strcmp(p, machine)) {
|
||||
+ ret = true;
|
||||
+ break;
|
||||
+ }
|
||||
+ len += strlen(p) + 1;
|
||||
+ p += strlen(p) + 1;
|
||||
+ }
|
||||
+ close(fd);
|
||||
+
|
||||
+ return ret;
|
||||
+}
|
||||
+
|
||||
+static int env_get_keymod(unsigned char output[16])
|
||||
+{
|
||||
+ int i;
|
||||
+ int len;
|
||||
+ int fd;
|
||||
+ uint32_t ocotp_hwid[MAX_HWID_WORDS];
|
||||
+ char dt_prop[32];
|
||||
+ char buf[sizeof(uint32_t)];
|
||||
+
|
||||
+ for (i = 0; i < MAX_HWID_WORDS; i++) {
|
||||
+ sprintf(dt_prop, "/proc/device-tree/digi,hwid_%d", i);
|
||||
+ if (access(dt_prop, F_OK) != -1) {
|
||||
+ fd = open(dt_prop, O_RDONLY);
|
||||
+ if (fd < 0)
|
||||
+ return fd;
|
||||
+ len = read(fd, buf, sizeof(uint32_t));
|
||||
+ if (len < 0) {
|
||||
+ close(fd);
|
||||
+ return -1;
|
||||
+ }
|
||||
+ ocotp_hwid[i] = ntohl(*(uint32_t *) buf);
|
||||
+ close(fd);
|
||||
+ } else if (machine_is_compatible("digi,ccimx6ul") ||
|
||||
+ machine_is_compatible("digi,ccimx6")) {
|
||||
+ /*
|
||||
+ * If HWID not available on the DT (old U-Boot version),
|
||||
+ * fall back to read it directly from the nvmem device.
|
||||
+ */
|
||||
+ int hwid_offset = 136; /* (Bank * 8 + Word) * 4 */
|
||||
+
|
||||
+ /* HWID for CC6 family only has two words */
|
||||
+ if (i == 2)
|
||||
+ break;
|
||||
+
|
||||
+ fd = open("/sys/bus/nvmem/devices/imx-ocotp0/nvmem",
|
||||
+ O_RDONLY);
|
||||
+ if (fd < 0)
|
||||
+ return fd;
|
||||
+ len = lseek(fd, hwid_offset + i * 4, SEEK_SET);
|
||||
+
|
||||
+ len = read(fd, buf, sizeof(unsigned int));
|
||||
+ if (len < 0) {
|
||||
+ close(fd);
|
||||
+ return -1;
|
||||
+ }
|
||||
+ ocotp_hwid[i] = *(unsigned int *)buf;
|
||||
+ close(fd);
|
||||
+ } else {
|
||||
+ break;
|
||||
+ }
|
||||
+ }
|
||||
+
|
||||
+ /* Calculate md5sum on the raw HWID array */
|
||||
+ md5((unsigned char *)(&ocotp_hwid), sizeof(uint32_t) * i, output);
|
||||
+
|
||||
+ return 0;
|
||||
+}
|
||||
+
|
||||
+static int env_caam_crypt(char *data, unsigned int size, const int enc)
|
||||
+{
|
||||
+ struct caam_kb_data enc_data;
|
||||
+ int fd;
|
||||
+ int ret = 0;
|
||||
+ const int len = size;
|
||||
+ int ioctl_mode;
|
||||
+ char *buffer;
|
||||
+ unsigned char key_modifier[16];
|
||||
+
|
||||
+ ret = env_get_keymod(key_modifier);
|
||||
+ if (ret)
|
||||
+ return ret;
|
||||
+
|
||||
+ enc_data.keymod = (char *)key_modifier;
|
||||
+ enc_data.keymod_len = sizeof(key_modifier);
|
||||
+
|
||||
+ enc_data.keyblob_len = len;
|
||||
+ enc_data.rawkey_len = len - BLOB_OVERHEAD;
|
||||
+
|
||||
+ buffer = malloc(len);
|
||||
+ if (!buffer) {
|
||||
+ printf("Could not allocate memory\n");
|
||||
+ return -1;
|
||||
+ }
|
||||
+
|
||||
+ if (enc) {
|
||||
+ enc_data.rawkey = data;
|
||||
+ ioctl_mode = CAAM_KB_ENCRYPT;
|
||||
+ enc_data.keyblob = buffer;
|
||||
+ } else {
|
||||
+ enc_data.keyblob = data;
|
||||
+ ioctl_mode = CAAM_KB_DECRYPT;
|
||||
+ enc_data.rawkey = buffer;
|
||||
+ }
|
||||
+
|
||||
+ if ((fd = open(CAAM_KEY_DEV, O_RDWR)) < 0) {
|
||||
+ ret = fd;
|
||||
+ goto free;
|
||||
+ }
|
||||
+
|
||||
+ ret = ioctl(fd, ioctl_mode, &enc_data);
|
||||
+ if (ret) {
|
||||
+ printf("CAAM_KEY_DEV ioctl failed: %d\n", ret);
|
||||
+ goto out;
|
||||
+ }
|
||||
+
|
||||
+ memcpy(data, buffer, enc ? len : len - BLOB_OVERHEAD);
|
||||
+
|
||||
+out:
|
||||
+ close(fd);
|
||||
+free:
|
||||
+ free(buffer);
|
||||
+
|
||||
+ return ret;
|
||||
+}
|
||||
+
|
||||
+int env_crypt(char *data, unsigned int size, const int enc)
|
||||
+{
|
||||
+ return env_caam_crypt(data, size, enc);
|
||||
+}
|
||||
+
|
||||
+int is_env_encrypted(void)
|
||||
+{
|
||||
+ const char *dt_prop = "/proc/device-tree/digi,uboot-env,encrypted";
|
||||
+
|
||||
+ return access(dt_prop, F_OK) != -1;
|
||||
+}
|
||||
diff --git a/src/crypt.h b/src/crypt.h
|
||||
new file mode 100644
|
||||
index 0000000..8d85c7f
|
||||
--- /dev/null
|
||||
+++ b/src/crypt.h
|
||||
@@ -0,0 +1,10 @@
|
||||
+/*
|
||||
+ * Copyright 2024 Digi International Inc
|
||||
+ *
|
||||
+ * SPDX-License-Identifier: GPL-2.0+
|
||||
+ */
|
||||
+
|
||||
+#pragma once
|
||||
+
|
||||
+int env_crypt(char *data, unsigned int size, const int enc);
|
||||
+int is_env_encrypted(void);
|
||||
diff --git a/src/md5.c b/src/md5.c
|
||||
new file mode 100644
|
||||
index 000000000000..47ae8bf34a4d
|
||||
index 0000000..47ae8bf
|
||||
--- /dev/null
|
||||
+++ b/src/md5.c
|
||||
@@ -0,0 +1,275 @@
|
||||
|
|
@ -371,7 +609,7 @@ index 000000000000..47ae8bf34a4d
|
|||
+}
|
||||
diff --git a/src/md5.h b/src/md5.h
|
||||
new file mode 100644
|
||||
index 000000000000..02a9a9d23e34
|
||||
index 0000000..02a9a9d
|
||||
--- /dev/null
|
||||
+++ b/src/md5.h
|
||||
@@ -0,0 +1,24 @@
|
||||
|
|
@ -400,146 +638,26 @@ index 000000000000..02a9a9d23e34
|
|||
+
|
||||
+#endif /* _MD5_H */
|
||||
diff --git a/src/uboot_env.c b/src/uboot_env.c
|
||||
index 30c39ebf6fa9..2fd08f5a07db 100644
|
||||
index c1f334e..30ef835 100644
|
||||
--- a/src/uboot_env.c
|
||||
+++ b/src/uboot_env.c
|
||||
@@ -33,11 +33,21 @@
|
||||
#include <sys/wait.h>
|
||||
#include <sys/ioctl.h>
|
||||
#include <zlib.h>
|
||||
+#include <arpa/inet.h>
|
||||
@@ -37,6 +37,7 @@
|
||||
#include <mtd/mtd-user.h>
|
||||
#include <mtd/ubi-user.h>
|
||||
|
||||
+#include "caam_keyblob.h"
|
||||
+#include "md5.h"
|
||||
+#include "crypt.h"
|
||||
#include "uboot_private.h"
|
||||
|
||||
+/*
|
||||
+ * The BLOB includes a random AES-256 key (32 bytes) and a
|
||||
+ * Message Authentication Code (MAC) (16 bytes)
|
||||
+ */
|
||||
+#define BLOB_OVERHEAD 48
|
||||
+#define CAAM_KEY_DEV "/dev/caam_kb"
|
||||
+
|
||||
#define UBI_MAX_VOLUME 128
|
||||
|
||||
#define DEVICE_MTD_NAME "/dev/mtd"
|
||||
@@ -844,6 +854,105 @@ static int set_obsolete_flag(struct uboot_flash_env *dev)
|
||||
return ret;
|
||||
}
|
||||
|
||||
+static int is_env_encrypted(void)
|
||||
+{
|
||||
+ const char *dt_prop = "/proc/device-tree/digi,uboot-env,encrypted";
|
||||
+
|
||||
+ return access(dt_prop, F_OK) != -1;
|
||||
+}
|
||||
+
|
||||
+#define MAX_HWID_WORDS 4
|
||||
+static int env_caam_get_keymod(unsigned char output[16])
|
||||
+{
|
||||
+ int i;
|
||||
+ int len;
|
||||
+ int fd;
|
||||
+ uint32_t ocotp_hwid[MAX_HWID_WORDS];
|
||||
+ char dt_prop[32];
|
||||
+
|
||||
+ for (i = 0; i < MAX_HWID_WORDS; i++) {
|
||||
+ sprintf(dt_prop, "/proc/device-tree/digi,hwid_%d", i);
|
||||
+ if (access(dt_prop, F_OK) != -1) {
|
||||
+ char buf[sizeof(uint32_t)];
|
||||
+
|
||||
+ fd = open(dt_prop, O_RDONLY);
|
||||
+ if (fd < 0)
|
||||
+ return fd;
|
||||
+ len = read(fd, buf, sizeof(uint32_t));
|
||||
+ if (len < 0) {
|
||||
+ close(fd);
|
||||
+ return -1;
|
||||
+ }
|
||||
+ ocotp_hwid[i] = ntohl(*(uint32_t *)buf);
|
||||
+ close(fd);
|
||||
+ } else {
|
||||
+ break;
|
||||
+ }
|
||||
+ }
|
||||
+
|
||||
+ /* Calculate md5sum on the raw HWID array */
|
||||
+ md5((unsigned char *)(&ocotp_hwid), sizeof(uint32_t) * i, output);
|
||||
+
|
||||
+ return 0;
|
||||
+}
|
||||
+
|
||||
+static int env_caam_crypt(char *data, unsigned int size, const int enc)
|
||||
+{
|
||||
+ struct caam_kb_data enc_data;
|
||||
+ int fd;
|
||||
+ int ret = 0;
|
||||
+ const int len = size;
|
||||
+ int ioctl_mode;
|
||||
+ char *buffer;
|
||||
+ unsigned char key_modifier[16];
|
||||
+
|
||||
+ ret = env_caam_get_keymod(key_modifier);
|
||||
+ if (ret)
|
||||
+ return ret;
|
||||
+
|
||||
+ enc_data.keymod = (char *)key_modifier;
|
||||
+ enc_data.keymod_len = sizeof(key_modifier);
|
||||
+
|
||||
+ enc_data.keyblob_len = len;
|
||||
+ enc_data.rawkey_len = len - BLOB_OVERHEAD;
|
||||
+
|
||||
+ buffer = malloc(len);
|
||||
+ if (!buffer) {
|
||||
+ printf("Could not allocate memory\n");
|
||||
+ return -1;
|
||||
+ }
|
||||
+
|
||||
+ if (enc) {
|
||||
+ enc_data.rawkey = data;
|
||||
+ ioctl_mode = CAAM_KB_ENCRYPT;
|
||||
+ enc_data.keyblob = buffer;
|
||||
+ } else {
|
||||
+ enc_data.keyblob = data;
|
||||
+ ioctl_mode = CAAM_KB_DECRYPT;
|
||||
+ enc_data.rawkey = buffer;
|
||||
+ }
|
||||
+
|
||||
+ if ((fd = open(CAAM_KEY_DEV, O_RDWR)) < 0) {
|
||||
+ ret = fd;
|
||||
+ goto free;
|
||||
+ }
|
||||
+
|
||||
+ ret = ioctl(fd, ioctl_mode, &enc_data);
|
||||
+ if (ret) {
|
||||
+ printf("CAAM_KEY_DEV ioctl failed: %d\n", ret);
|
||||
+ goto out;
|
||||
+ }
|
||||
+
|
||||
+ memcpy(data, buffer, enc ? len : len - BLOB_OVERHEAD);
|
||||
+
|
||||
+out:
|
||||
+ close(fd);
|
||||
+free:
|
||||
+ free(buffer);
|
||||
+
|
||||
+ return ret;
|
||||
+}
|
||||
+
|
||||
int libuboot_env_store(struct uboot_ctx *ctx)
|
||||
{
|
||||
struct var_entry *entry;
|
||||
@@ -919,6 +1028,15 @@ int libuboot_env_store(struct uboot_ctx *ctx)
|
||||
@@ -1187,6 +1188,15 @@ int libuboot_env_store(struct uboot_ctx *ctx)
|
||||
((struct uboot_env_redund *)image)->flags = flags;
|
||||
}
|
||||
|
||||
+ if (ctx->encrypted) {
|
||||
+ ret = env_caam_crypt(data, ctx->usable_size, 1);
|
||||
+ if (is_env_encrypted()) {
|
||||
+ size_t usable_envsize = ctx->size - offsetdata;
|
||||
+ ret = env_crypt(data, usable_envsize, 1);
|
||||
+ if (ret) {
|
||||
+ fprintf(stderr,
|
||||
+ "Error: can't encrypt env for flash\n");
|
||||
+ fprintf(stderr, "Error: can't encrypt env for flash\n");
|
||||
+ return ret;
|
||||
+ }
|
||||
+ }
|
||||
|
|
@ -547,56 +665,18 @@ index 30c39ebf6fa9..2fd08f5a07db 100644
|
|||
*(uint32_t *)image = crc32(0, (uint8_t *)data, ctx->size - offsetdata);
|
||||
|
||||
copy = ctx->redundant ? (ctx->current ? 0 : 1) : 0;
|
||||
@@ -984,6 +1102,13 @@ static int libuboot_load(struct uboot_ctx *ctx)
|
||||
@@ -1251,6 +1261,14 @@ static int libuboot_load(struct uboot_ctx *ctx)
|
||||
}
|
||||
crc = *(uint32_t *)(buf[i] + offsetcrc);
|
||||
dev->crc = crc32(0, (uint8_t *)data, usable_envsize);
|
||||
+ if (ctx->encrypted) {
|
||||
+ ret = env_caam_crypt((char *)data, ctx->usable_size, 0);
|
||||
+ if (is_env_encrypted()) {
|
||||
+ ret = env_crypt(data, usable_envsize, 0);
|
||||
+ if (ret) {
|
||||
+ fprintf(stderr, "Error: can't decrypt environment\n");
|
||||
+ fprintf(stderr,
|
||||
+ "Error: can't decrypt environment\n");
|
||||
+ return ret;
|
||||
+ }
|
||||
+ }
|
||||
crcenv[i] = dev->crc == crc;
|
||||
if (ctx->redundant)
|
||||
dev->flags = *(uint8_t *)(buf[i] + offsetflags);
|
||||
@@ -1264,6 +1389,11 @@ int libuboot_read_config(struct uboot_ctx *ctx, const char *config)
|
||||
break;
|
||||
}
|
||||
}
|
||||
+
|
||||
+ ctx->usable_size = ctx->size - sizeof(uint32_t);
|
||||
+ if (ctx->redundant)
|
||||
+ ctx->usable_size -= sizeof(char);
|
||||
+
|
||||
if (ndev == 0)
|
||||
retval = -EINVAL;
|
||||
|
||||
@@ -1461,6 +1591,7 @@ int libuboot_initialize(struct uboot_ctx **out,
|
||||
return -ENOMEM;
|
||||
|
||||
ctx->valid = false;
|
||||
+ ctx->encrypted = is_env_encrypted();
|
||||
ret = libuboot_configure(ctx, envdevs);
|
||||
|
||||
if (ret < 0) {
|
||||
diff --git a/src/uboot_private.h b/src/uboot_private.h
|
||||
index 4b7a9f9602a6..22c8c14ce8cc 100644
|
||||
--- a/src/uboot_private.h
|
||||
+++ b/src/uboot_private.h
|
||||
@@ -111,10 +111,14 @@ LIST_HEAD(vars, var_entry);
|
||||
struct uboot_ctx {
|
||||
/** true if the environment is redundant */
|
||||
bool redundant;
|
||||
+ /** true if the environment is encrypted */
|
||||
+ bool encrypted;
|
||||
/** set to valid after a successful load */
|
||||
bool valid;
|
||||
/** size of the environment */
|
||||
size_t size;
|
||||
+ /** usable environment size */
|
||||
+ unsigned int usable_size;
|
||||
/** devices where environment is stored */
|
||||
struct uboot_flash_env envdevs[2];
|
||||
/** Set which device contains the current(last valid) environment */
|
||||
|
|
@ -0,0 +1,259 @@
|
|||
From: Mike Engel <Mike.Engel@digi.com>
|
||||
Date: Fri, 26 May 2023 11:21:43 +0200
|
||||
Subject: [PATCH] Implement support for environment encryption using Optee
|
||||
|
||||
Co-authored-by: Javier Viguera <javier.viguera@digi.com>
|
||||
Signed-off-by: Mike Engel <Mike.Engel@digi.com>
|
||||
Signed-off-by: Javier Viguera <javier.viguera@digi.com>
|
||||
---
|
||||
src/CMakeLists.txt | 3 +
|
||||
src/crypt.c | 10 ++-
|
||||
src/crypt_optee.c | 172 +++++++++++++++++++++++++++++++++++++++++++++
|
||||
src/crypt_optee.h | 10 +++
|
||||
4 files changed, 194 insertions(+), 1 deletion(-)
|
||||
create mode 100644 src/crypt_optee.c
|
||||
create mode 100644 src/crypt_optee.h
|
||||
|
||||
diff --git a/src/CMakeLists.txt b/src/CMakeLists.txt
|
||||
index 638f1c1..f218b35 100644
|
||||
--- a/src/CMakeLists.txt
|
||||
+++ b/src/CMakeLists.txt
|
||||
@@ -6,6 +6,8 @@ cmake_minimum_required (VERSION 2.6)
|
||||
SET(libubootenv_SOURCES
|
||||
crypt.c
|
||||
crypt.h
|
||||
+ crypt_optee.c
|
||||
+ crypt_optee.h
|
||||
md5.c
|
||||
md5.h
|
||||
uboot_env.c
|
||||
@@ -26,6 +28,7 @@ ADD_LIBRARY(ubootenv_static STATIC ${libubootenv_SOURCES} ${include_HEADERS})
|
||||
SET_TARGET_PROPERTIES(ubootenv_static PROPERTIES OUTPUT_NAME ubootenv)
|
||||
add_executable(fw_printenv fw_printenv.c)
|
||||
target_link_libraries(ubootenv z yaml)
|
||||
+target_link_libraries(ubootenv teec)
|
||||
target_link_libraries(fw_printenv ubootenv)
|
||||
add_custom_target(fw_setenv ALL ${CMAKE_COMMAND} -E create_symlink fw_printenv fw_setenv)
|
||||
|
||||
diff --git a/src/crypt.c b/src/crypt.c
|
||||
index 213cffd..e3f9a5d 100644
|
||||
--- a/src/crypt.c
|
||||
+++ b/src/crypt.c
|
||||
@@ -15,6 +15,7 @@
|
||||
#include <unistd.h>
|
||||
|
||||
#include "caam_keyblob.h"
|
||||
+#include "crypt_optee.h"
|
||||
#include "md5.h"
|
||||
|
||||
/*
|
||||
@@ -168,7 +169,14 @@ free:
|
||||
|
||||
int env_crypt(char *data, unsigned int size, const int enc)
|
||||
{
|
||||
- return env_caam_crypt(data, size, enc);
|
||||
+ if (is_env_optee_encrypted()) {
|
||||
+ unsigned char key_modifier[16];
|
||||
+ if (env_get_keymod(key_modifier))
|
||||
+ return -1;
|
||||
+ return env_optee_crypt((char *)key_modifier, data, size, enc);
|
||||
+ } else {
|
||||
+ return env_caam_crypt(data, size, enc);
|
||||
+ }
|
||||
}
|
||||
|
||||
int is_env_encrypted(void)
|
||||
diff --git a/src/crypt_optee.c b/src/crypt_optee.c
|
||||
new file mode 100644
|
||||
index 0000000..fc74141
|
||||
--- /dev/null
|
||||
+++ b/src/crypt_optee.c
|
||||
@@ -0,0 +1,172 @@
|
||||
+/*
|
||||
+ * Copyright 2024 Digi International Inc
|
||||
+ *
|
||||
+ * SPDX-License-Identifier: GPL-2.0+
|
||||
+ */
|
||||
+
|
||||
+#include <arpa/inet.h>
|
||||
+#include <errno.h>
|
||||
+#include <stdio.h>
|
||||
+#include <stdlib.h>
|
||||
+#include <string.h>
|
||||
+#include <tee_client_api.h>
|
||||
+#include <unistd.h>
|
||||
+
|
||||
+#define AES_BLOCK_LENGTH 16
|
||||
+
|
||||
+/* From TA's public header (aes_ta.h) */
|
||||
+#define TA_AES_UUID \
|
||||
+ { 0xc2fad363, 0x5d9f, 0x4fc4, \
|
||||
+ { 0xa4, 0x17, 0x55, 0x58, 0x41, 0xe0, 0x57, 0x45 } }
|
||||
+#define TA_AES_ALGO_ECB 0
|
||||
+#define TA_AES_ALGO_CBC 1
|
||||
+#define TA_AES_ALGO_CTR 2
|
||||
+#define TA_AES_SIZE_128BIT (128 / 8)
|
||||
+#define TA_AES_SIZE_256BIT (256 / 8)
|
||||
+#define TA_AES_MODE_DECODE 0
|
||||
+#define TA_AES_MODE_ENCODE 1
|
||||
+#define TA_AES_CMD_PREPARE 0
|
||||
+#define TA_AES_CMD_SET_KEY 1
|
||||
+#define TA_AES_CMD_SET_IV 2
|
||||
+#define TA_AES_CMD_CIPHER 3
|
||||
+
|
||||
+struct tee_ctx {
|
||||
+ TEEC_Context ctx;
|
||||
+ TEEC_Session sess;
|
||||
+};
|
||||
+
|
||||
+static void prepare_tee_session(struct tee_ctx *ctx)
|
||||
+{
|
||||
+ TEEC_Result ret;
|
||||
+ uint32_t origin;
|
||||
+ TEEC_UUID uuid = TA_AES_UUID;
|
||||
+
|
||||
+ ret = TEEC_InitializeContext(NULL, &ctx->ctx);
|
||||
+ if (ret != TEEC_SUCCESS)
|
||||
+ printf("TEEC_InitializeContext failed with code 0x%x", ret);
|
||||
+
|
||||
+ /* Open a session with the TA */
|
||||
+ ret = TEEC_OpenSession(&ctx->ctx, &ctx->sess, &uuid,
|
||||
+ TEEC_LOGIN_PUBLIC, NULL, NULL, &origin);
|
||||
+ if (ret != TEEC_SUCCESS)
|
||||
+ printf("TEEC_Opensession failed with code 0x%x origin 0x%x",
|
||||
+ ret, origin);
|
||||
+
|
||||
+}
|
||||
+
|
||||
+static void terminate_tee_session(struct tee_ctx *ctx)
|
||||
+{
|
||||
+ TEEC_CloseSession(&ctx->sess);
|
||||
+ TEEC_FinalizeContext(&ctx->ctx);
|
||||
+}
|
||||
+
|
||||
+static void prepare_aes(struct tee_ctx *ctx, int encode)
|
||||
+{
|
||||
+ TEEC_Operation op;
|
||||
+ uint32_t origin;
|
||||
+ TEEC_Result res;
|
||||
+
|
||||
+ memset(&op, 0, sizeof(op));
|
||||
+ op.paramTypes = TEEC_PARAM_TYPES(TEEC_VALUE_INPUT,
|
||||
+ TEEC_VALUE_INPUT,
|
||||
+ TEEC_VALUE_INPUT, TEEC_NONE);
|
||||
+
|
||||
+ op.params[0].value.a = TA_AES_ALGO_CTR;
|
||||
+ op.params[1].value.a = TA_AES_SIZE_256BIT;
|
||||
+ op.params[2].value.a = encode ? TA_AES_MODE_ENCODE : TA_AES_MODE_DECODE;
|
||||
+
|
||||
+ res = TEEC_InvokeCommand(&ctx->sess, TA_AES_CMD_PREPARE, &op, &origin);
|
||||
+ if (res != TEEC_SUCCESS)
|
||||
+ printf("TEEC_InvokeCommand(PREPARE) failed 0x%x origin 0x%x",
|
||||
+ res, origin);
|
||||
+}
|
||||
+
|
||||
+static void set_key(struct tee_ctx *ctx, size_t key_sz)
|
||||
+{
|
||||
+ TEEC_Operation op;
|
||||
+ uint32_t origin;
|
||||
+ TEEC_Result res;
|
||||
+
|
||||
+ memset(&op, 0, sizeof(op));
|
||||
+
|
||||
+ op.paramTypes = TEEC_PARAM_TYPES(TEEC_VALUE_INPUT,
|
||||
+ TEEC_NONE, TEEC_NONE, TEEC_NONE);
|
||||
+
|
||||
+ op.params[0].value.a = key_sz;
|
||||
+
|
||||
+ res = TEEC_InvokeCommand(&ctx->sess, TA_AES_CMD_SET_KEY, &op, &origin);
|
||||
+ if (res != TEEC_SUCCESS)
|
||||
+ printf("TEEC_InvokeCommand(SET_KEY) failed 0x%x origin 0x%x",
|
||||
+ res, origin);
|
||||
+}
|
||||
+
|
||||
+static void set_iv(struct tee_ctx *ctx, char *iv, size_t iv_sz)
|
||||
+{
|
||||
+ TEEC_Operation op;
|
||||
+ uint32_t origin;
|
||||
+ TEEC_Result res;
|
||||
+
|
||||
+ memset(&op, 0, sizeof(op));
|
||||
+ op.paramTypes = TEEC_PARAM_TYPES(TEEC_MEMREF_TEMP_INPUT,
|
||||
+ TEEC_NONE, TEEC_NONE, TEEC_NONE);
|
||||
+ op.params[0].tmpref.buffer = iv;
|
||||
+ op.params[0].tmpref.size = iv_sz;
|
||||
+
|
||||
+ res = TEEC_InvokeCommand(&ctx->sess, TA_AES_CMD_SET_IV, &op, &origin);
|
||||
+ if (res != TEEC_SUCCESS)
|
||||
+ printf("TEEC_InvokeCommand(SET_IV) failed 0x%x origin 0x%x",
|
||||
+ res, origin);
|
||||
+}
|
||||
+
|
||||
+static void cipher_buffer(struct tee_ctx *ctx, char *in, char *out, size_t sz)
|
||||
+{
|
||||
+ TEEC_Operation op;
|
||||
+ uint32_t origin;
|
||||
+ TEEC_Result res;
|
||||
+
|
||||
+ memset(&op, 0, sizeof(op));
|
||||
+ op.paramTypes = TEEC_PARAM_TYPES(TEEC_MEMREF_TEMP_INPUT,
|
||||
+ TEEC_MEMREF_TEMP_OUTPUT,
|
||||
+ TEEC_NONE, TEEC_NONE);
|
||||
+ op.params[0].tmpref.buffer = in;
|
||||
+ op.params[0].tmpref.size = sz;
|
||||
+ op.params[1].tmpref.buffer = out;
|
||||
+ op.params[1].tmpref.size = sz;
|
||||
+
|
||||
+ res = TEEC_InvokeCommand(&ctx->sess, TA_AES_CMD_CIPHER, &op, &origin);
|
||||
+ if (res != TEEC_SUCCESS)
|
||||
+ printf("TEEC_InvokeCommand(CIPHER) failed 0x%x origin 0x%x",
|
||||
+ res, origin);
|
||||
+}
|
||||
+
|
||||
+int env_optee_crypt(char *keymod, char *data, unsigned int size, const int enc)
|
||||
+{
|
||||
+ struct tee_ctx tee;
|
||||
+ char *cryptdata;
|
||||
+ int ret = 0;
|
||||
+
|
||||
+ prepare_tee_session(&tee);
|
||||
+ prepare_aes(&tee, enc);
|
||||
+ set_key(&tee, TA_AES_SIZE_256BIT);
|
||||
+ set_iv(&tee, keymod, AES_BLOCK_LENGTH);
|
||||
+ cryptdata = calloc(1, size);
|
||||
+ if (cryptdata) {
|
||||
+ cipher_buffer(&tee, data, cryptdata, size);
|
||||
+ memcpy(data, cryptdata, size);
|
||||
+ free(cryptdata);
|
||||
+ } else {
|
||||
+ printf("%s: can't allocate memory\n", __func__);
|
||||
+ ret = -ENOMEM;
|
||||
+ }
|
||||
+ terminate_tee_session(&tee);
|
||||
+
|
||||
+ return ret;
|
||||
+}
|
||||
+
|
||||
+int is_env_optee_encrypted(void)
|
||||
+{
|
||||
+ const char *dt_prop =
|
||||
+ "/proc/device-tree/digi,uboot-env,encrypted-optee";
|
||||
+
|
||||
+ return access(dt_prop, F_OK) != -1;
|
||||
+}
|
||||
diff --git a/src/crypt_optee.h b/src/crypt_optee.h
|
||||
new file mode 100644
|
||||
index 0000000..e0c77a7
|
||||
--- /dev/null
|
||||
+++ b/src/crypt_optee.h
|
||||
@@ -0,0 +1,10 @@
|
||||
+/*
|
||||
+ * Copyright 2024 Digi International Inc
|
||||
+ *
|
||||
+ * SPDX-License-Identifier: GPL-2.0+
|
||||
+ */
|
||||
+
|
||||
+#pragma once
|
||||
+
|
||||
+int env_optee_crypt(char *keymod, char *data, unsigned int size, const int enc);
|
||||
+int is_env_optee_encrypted(void);
|
||||
|
|
@ -1,105 +0,0 @@
|
|||
From: Hector Palacios <hector.palacios@digi.com>
|
||||
Date: Mon, 3 Apr 2023 18:21:07 +0200
|
||||
Subject: [PATCH] fall back to read HWID from nvmem device if not available on
|
||||
DT
|
||||
|
||||
Old U-Boot versions don't populate the HWID on the device tree. This may
|
||||
be used as a key modifier for TrustFence encryption and, if not available
|
||||
on the DT, newer firmware may be unable to unencrypt the U-Boot
|
||||
environment.
|
||||
|
||||
This patch implements a fall-back function to query the HWID directly from
|
||||
the nvmem device node if it cannot locate it at the DT.
|
||||
This is only implemented for ccimx6 family, which may be in the case of
|
||||
having an old U-Boot.
|
||||
|
||||
Signed-off-by: Hector Palacios <hector.palacios@digi.com>
|
||||
|
||||
https://onedigi.atlassian.net/browse/DEL-8444
|
||||
---
|
||||
src/uboot_env.c | 54 +++++++++++++++++++++++++++++++++++++++++++++++--
|
||||
1 file changed, 52 insertions(+), 2 deletions(-)
|
||||
|
||||
diff --git a/src/uboot_env.c b/src/uboot_env.c
|
||||
index 539e22f9a8ac..86f9b9ebfec2 100644
|
||||
--- a/src/uboot_env.c
|
||||
+++ b/src/uboot_env.c
|
||||
@@ -945,6 +945,32 @@ static int is_env_encrypted(void)
|
||||
return access(dt_prop, F_OK) != -1;
|
||||
}
|
||||
|
||||
+/* Function that checks if machine is compatible (on the DT) */
|
||||
+static bool machine_is_compatible(char *machine)
|
||||
+{
|
||||
+ int fd, nchars, len = 0;
|
||||
+ int ret = false;
|
||||
+ char str[256];
|
||||
+ char *p = str;
|
||||
+
|
||||
+ fd = open("/proc/device-tree/compatible", O_RDONLY);
|
||||
+ if (fd < 0)
|
||||
+ return false;
|
||||
+
|
||||
+ nchars = read(fd, str, 255);
|
||||
+ while (len < nchars) {
|
||||
+ if (!strcmp(p, machine)) {
|
||||
+ ret = true;
|
||||
+ break;
|
||||
+ }
|
||||
+ len += strlen(p) + 1;
|
||||
+ p += strlen(p) + 1;
|
||||
+ }
|
||||
+
|
||||
+ close(fd);
|
||||
+ return ret;
|
||||
+}
|
||||
+
|
||||
#define MAX_HWID_WORDS 4
|
||||
static int env_caam_get_keymod(unsigned char output[16])
|
||||
{
|
||||
@@ -953,12 +979,11 @@ static int env_caam_get_keymod(unsigned char output[16])
|
||||
int fd;
|
||||
uint32_t ocotp_hwid[MAX_HWID_WORDS];
|
||||
char dt_prop[32];
|
||||
+ char buf[sizeof(uint32_t)];
|
||||
|
||||
for (i = 0; i < MAX_HWID_WORDS; i++) {
|
||||
sprintf(dt_prop, "/proc/device-tree/digi,hwid_%d", i);
|
||||
if (access(dt_prop, F_OK) != -1) {
|
||||
- char buf[sizeof(uint32_t)];
|
||||
-
|
||||
fd = open(dt_prop, O_RDONLY);
|
||||
if (fd < 0)
|
||||
return fd;
|
||||
@@ -969,6 +994,31 @@ static int env_caam_get_keymod(unsigned char output[16])
|
||||
}
|
||||
ocotp_hwid[i] = ntohl(*(uint32_t *)buf);
|
||||
close(fd);
|
||||
+ } else if (machine_is_compatible("digi,ccimx6ul") ||
|
||||
+ machine_is_compatible("digi,ccimx6")) {
|
||||
+ /*
|
||||
+ * If HWID not available on the DT (old U-Boot version),
|
||||
+ * fall back to read it directly from the nvmem device.
|
||||
+ */
|
||||
+ int hwid_offset = 136; /* (Bank * 8 + Word) * 4 */
|
||||
+
|
||||
+ /* HWID for CC6 family only has two words */
|
||||
+ if (i == 2)
|
||||
+ break;
|
||||
+
|
||||
+ fd = open("/sys/bus/nvmem/devices/imx-ocotp0/nvmem",
|
||||
+ O_RDONLY);
|
||||
+ if (fd < 0)
|
||||
+ return fd;
|
||||
+ len = lseek(fd, hwid_offset + i * 4, SEEK_SET);
|
||||
+
|
||||
+ len = read(fd, buf, sizeof(unsigned int));
|
||||
+ if (len < 0) {
|
||||
+ close(fd);
|
||||
+ return -1;
|
||||
+ }
|
||||
+ ocotp_hwid[i] = *(unsigned int *)buf;
|
||||
+ close(fd);
|
||||
} else {
|
||||
break;
|
||||
}
|
||||
File diff suppressed because it is too large
Load Diff
|
|
@ -15,13 +15,18 @@ FW_CONFIG_FILE:ccmp1 = "${@bb.utils.contains('IMAGE_FEATURES', 'read-only-rootfs
|
|||
'ubi/fw_env.config_default', \
|
||||
'ubi/fw_env.config', d)}"
|
||||
|
||||
DEPENDS += "${@oe.utils.conditional('OPTEE_PATCHES', '', '', 'optee-client', d)}"
|
||||
|
||||
OPTEE_PATCHES = ""
|
||||
OPTEE_PATCHES:ccimx93 = "file://0004-Implement-support-for-environment-encryption-using-O.patch"
|
||||
OPTEE_PATCHES:ccmp1 = "file://0004-Implement-support-for-environment-encryption-using-O.patch"
|
||||
|
||||
SRC_URI += " \
|
||||
file://${FW_CONFIG_FILE} \
|
||||
file://0001-Implement-support-for-environment-encryption-by-CAAM.patch \
|
||||
file://0002-Implement-U-Boot-environment-access-functions.patch \
|
||||
file://0003-tools-env-add-support-to-set-dynamic-location-of-env.patch \
|
||||
file://0004-fall-back-to-read-HWID-from-nvmem-device-if-not-avai.patch \
|
||||
file://0005-Implement-support-for-environment-encryption-for-CCM.patch \
|
||||
file://0001-Implement-U-Boot-environment-access-functions.patch \
|
||||
file://0002-tools-env-add-support-to-set-dynamic-location-of-env.patch \
|
||||
file://0003-Implement-support-for-environment-encryption-by-CAAM.patch \
|
||||
${@bb.utils.contains('MACHINE_FEATURES', 'optee', '${OPTEE_PATCHES}', '', d)} \
|
||||
"
|
||||
|
||||
do_install:append() {
|
||||
|
|
|
|||
|
|
@ -1,9 +0,0 @@
|
|||
# Copyright (C) 2023 Digi International.
|
||||
|
||||
require trustfence-stm-signtools.inc
|
||||
inherit nativesdk
|
||||
|
||||
# STM signing tools binaries depend on libQt5Core.so.5
|
||||
RDEPENDS:${PN} += " \
|
||||
nativesdk-qtbase \
|
||||
"
|
||||
|
|
@ -0,0 +1,4 @@
|
|||
# Copyright (C) 2023,2024 Digi International.
|
||||
|
||||
require trustfence-stm-signtools.inc
|
||||
inherit nativesdk
|
||||
|
|
@ -1,17 +1,17 @@
|
|||
# Copyright (C) 2023 Digi International.
|
||||
# Copyright (C) 2023,2024 Digi International.
|
||||
|
||||
SUMMARY = "STM key generation and signing tools"
|
||||
SECTION = "console/tools"
|
||||
LICENSE = "Proprietary"
|
||||
|
||||
LIC_FILES_CHKSUM = "file://en.SLA0048.txt;md5=108361d167deef887d204830aba9cf94"
|
||||
LIC_FILES_CHKSUM = "file://licenses/en.SLA0048.txt;md5=108361d167deef887d204830aba9cf94"
|
||||
|
||||
PKGNAME = "trustfence-stm-signtools"
|
||||
|
||||
# tarball
|
||||
SRC_URI = "${DIGI_PKG_SRC}/${PKGNAME}-${PV}.tar.gz"
|
||||
SRC_URI[md5sum] = "38ce0cd682350b15e773e725ee842da4"
|
||||
SRC_URI[sha256sum] = "cc349bdcaa764d5af25b12ee9e0c143f93dc80d531f42f8a57a735e170cd378b"
|
||||
SRC_URI[md5sum] = "995b612c1da7e3d9b9b402ede578f41d"
|
||||
SRC_URI[sha256sum] = "b3c975c12f71acda356e086c1440398ca95256e104fd4813ef6a720237f6dd72"
|
||||
|
||||
inherit bin_package
|
||||
|
||||
|
|
|
|||
|
|
@ -1,4 +1,4 @@
|
|||
# Copyright (C) 2018-2023 Digi International
|
||||
# Copyright (C) 2018-2024 Digi International
|
||||
|
||||
require recipes-bsp/u-boot/u-boot.inc
|
||||
|
||||
|
|
@ -49,9 +49,13 @@ python __anonymous() {
|
|||
|
||||
do_configure[prefuncs] += "${@oe.utils.ifelse(d.getVar('UBOOT_TF_CONF'), 'trustfence_config', '')}"
|
||||
python trustfence_config() {
|
||||
import shlex
|
||||
config_path = d.expand('${WORKDIR}/uboot-trustfence.cfg')
|
||||
with open(config_path, 'w') as f:
|
||||
for cfg in d.getVar('UBOOT_TF_CONF').split():
|
||||
for cfg in shlex.split(d.getVar('UBOOT_TF_CONF'), posix=False):
|
||||
# strip quotes for "is not set" options
|
||||
if 'is not set' in cfg:
|
||||
cfg = cfg.strip('"\'')
|
||||
f.write('%s\n' % cfg)
|
||||
d.appendVar('SRC_URI', ' file://%s' % config_path)
|
||||
}
|
||||
|
|
@ -81,6 +85,24 @@ build_uboot_scripts() {
|
|||
-e 's,##GRAPHICAL_IMAGES##,${GRAPHICAL_IMAGES},g' \
|
||||
-e 's,##DEFAULT_IMAGE_NAME##,${DEFAULT_IMAGE_NAME},g' \
|
||||
${WORKDIR}/${f} > ${TMP_INSTALL_SCR}
|
||||
# Change the u-boot name when TrustFence is enabled
|
||||
if [ "${TRUSTFENCE_SIGN}" = "1" ]; then
|
||||
if [ "${DEY_SOC_VENDOR}" = "NXP" ]; then
|
||||
if [ "${TRUSTFENCE_DEK_PATH}" != "0" ]; then
|
||||
sed -i -e 's,##SIGNED##,encrypted,g' ${TMP_INSTALL_SCR}
|
||||
else
|
||||
sed -i -e 's,##SIGNED##,signed,g' ${TMP_INSTALL_SCR}
|
||||
fi
|
||||
else
|
||||
sed -i -e 's,##SIGNED##,_Signed,g' ${TMP_INSTALL_SCR}
|
||||
sed -i -e 's,##SIGNED_TFA##,_signed,g' ${TMP_INSTALL_SCR}
|
||||
fi
|
||||
else
|
||||
sed -i -e 's,-##SIGNED##,,g' -e 's,##SIGNED##,,g' ${TMP_INSTALL_SCR}
|
||||
if [ "${DEY_SOC_VENDOR}" = "STM" ]; then
|
||||
sed -i -e 's,##SIGNED_TFA##,,g' ${TMP_INSTALL_SCR}
|
||||
fi
|
||||
fi
|
||||
if [ "${f_ext}" = "txt" ]; then
|
||||
mkimage -T script -n "DEY firmware install script" -C none -d ${TMP_INSTALL_SCR} ${DEPLOYDIR}/${f%.*}.scr
|
||||
else
|
||||
|
|
@ -95,10 +117,11 @@ build_uboot_scripts() {
|
|||
mkimage -T script -n bootscript -C none -d ${TMP_BOOTSCR} ${DEPLOYDIR}/boot.scr
|
||||
rm -f ${TMP_BOOTSCR}
|
||||
|
||||
# Sign the boot script
|
||||
if [ "${TRUSTFENCE_SIGN_ARTIFACTS}" = "1" ]; then
|
||||
# Sign the boot script if not contained in a FIT image
|
||||
if [ "${TRUSTFENCE_SIGN_ARTIFACTS}" = "1" ] && [ "${TRUSTFENCE_SIGN_FIT_NXP}" = "0" ]; then
|
||||
export CONFIG_SIGN_KEYS_PATH="${TRUSTFENCE_SIGN_KEYS_PATH}"
|
||||
[ -n "${TRUSTFENCE_KEY_INDEX}" ] && export CONFIG_KEY_INDEX="${TRUSTFENCE_KEY_INDEX}"
|
||||
[ -n "${TRUSTFENCE_SRK_REVOKE_MASK}" ] && export SRK_REVOKE_MASK="${TRUSTFENCE_SRK_REVOKE_MASK}"
|
||||
[ -n "${TRUSTFENCE_DEK_PATH}" ] && [ "${TRUSTFENCE_DEK_PATH}" != "0" ] && export CONFIG_DEK_PATH="${TRUSTFENCE_DEK_PATH}"
|
||||
|
||||
# Sign boot script
|
||||
|
|
@ -168,10 +191,35 @@ sign_uboot() {
|
|||
fi
|
||||
}
|
||||
|
||||
# -----------------------------------------------------------------------------
|
||||
# Append compile to handle specific device tree compilation
|
||||
#
|
||||
do_compile:append:ccmp1() {
|
||||
if [ -n "${UBOOT_DEVICETREE}" ]; then
|
||||
unset i j
|
||||
for config in ${UBOOT_MACHINE}; do
|
||||
i=$(expr $i + 1);
|
||||
for devicetree in ${UBOOT_DEVICETREE}; do
|
||||
# Cleanup previous build artifact
|
||||
[ -f "${B}/${config}/dts/dt.dtb" ] && rm "${B}/${config}/dts/dt.dtb"
|
||||
# Build target for specific device tree
|
||||
oe_runmake -C ${S} O=${B}/${config} DEVICE_TREE=${devicetree} DEVICE_TREE_EXT=${devicetree}.dtb
|
||||
# Install specific binary
|
||||
for binary in ${UBOOT_BINARIES}; do
|
||||
j=$(expr $j + 1);
|
||||
if [ $j -eq $i ]; then
|
||||
binarysuffix=$(echo ${binary} | cut -d'.' -f2)
|
||||
install -m 644 ${B}/${config}/${binary} ${B}/${config}/u-boot-${devicetree}.${binarysuffix}
|
||||
fi
|
||||
done
|
||||
unset j
|
||||
done
|
||||
done
|
||||
fi
|
||||
}
|
||||
|
||||
BOOT_TOOLS = "imx-boot-tools"
|
||||
BOOT_TOOLS:ccmp1 = "u-boot"
|
||||
FIP_UBOOT_HEADER = "ccmp15-dvk"
|
||||
FIP_UBOOT_HEADER:ccmp13 = "ccmp13-dvk"
|
||||
|
||||
do_deploy:append:ccimx8m() {
|
||||
# Deploy u-boot-nodtb.bin and ccimx8m[m|n]-dvk.dtb, to be packaged in boot binary by imx-boot
|
||||
|
|
@ -195,21 +243,30 @@ do_deploy:append:ccimx8m() {
|
|||
}
|
||||
|
||||
do_deploy:append:ccmp1() {
|
||||
# Deploy u-boot-nodtb.bin and ccmp1x-dvk.dtb, to be packaged in fip binary by tf-a
|
||||
# Deploy u-boot-nodtb.bin and ccmp1x-dvk-xxxx.dtb, to be packaged in fip binary by tf-a
|
||||
install -d ${DEPLOYDIR}/${BOOT_TOOLS}
|
||||
install -m 0777 ${B}/${config}/arch/arm/dts/${UBOOT_DTB_NAME} ${DEPLOYDIR}/${BOOT_TOOLS}/${FIP_UBOOT_DTB}-${FIP_UBOOT_HEADER}.dtb
|
||||
if [ -n "${UBOOT_DEVICETREE}" ]; then
|
||||
for devicetree in ${UBOOT_DEVICETREE}; do
|
||||
# Install u-boot dtb
|
||||
install -m 644 ${B}/${config}/arch/arm/dts/${devicetree}.dtb ${DEPLOYDIR}/${BOOT_TOOLS}/${FIP_UBOOT_DTB}-${devicetree}.dtb
|
||||
done
|
||||
fi
|
||||
install -m 0777 ${B}/${config}/u-boot-nodtb.bin ${DEPLOYDIR}/${BOOT_TOOLS}/u-boot-nodtb.bin
|
||||
|
||||
# Append signature to u-boot DT
|
||||
if [ "x${UBOOT_SIGN_ENABLE}" = "x1" ] ; then
|
||||
# get name of u-boot devicetree without signature
|
||||
ubootdevicetree="${DEPLOYDIR}/${BOOT_TOOLS}/u-boot-${UBOOT_DTB_NAME}"
|
||||
namewithoutsignature=`echo $ubootdevicetree | sed "s/\.dtb/-without-signature.dtb/g"`
|
||||
namewithsignature=`echo $ubootdevicetree | sed "s/\.dtb/-with-signature.dtb/g"`
|
||||
mv $ubootdevicetree $namewithoutsignature
|
||||
# get name of U-Boot device tree from DEPLOY_DIR
|
||||
nameonkernel="${DEPLOY_DIR_IMAGE}/u-boot-${MACHINE}*.dtb"
|
||||
cp $nameonkernel $namewithsignature
|
||||
cp $nameonkernel $ubootdevicetree
|
||||
if [ "x${UBOOT_SIGN_ENABLE}" = "x1" ] && [ -n "${UBOOT_DEVICETREE}" ] ; then
|
||||
for devicetree in ${UBOOT_DEVICETREE}; do
|
||||
# get name of u-boot devicetree without signature
|
||||
ubootdevicetree="${DEPLOYDIR}/${BOOT_TOOLS}/${FIP_UBOOT_DTB}-${devicetree}.dtb"
|
||||
namewithoutsignature=`echo $ubootdevicetree | sed "s/\.dtb/-without-signature.dtb/g"`
|
||||
namewithsignature=`echo $ubootdevicetree | sed "s/\.dtb/-with-signature.dtb/g"`
|
||||
mv $ubootdevicetree $namewithoutsignature
|
||||
# get name of U-Boot device tree from DEPLOY_DIR
|
||||
nameonkernel="${DEPLOY_DIR_IMAGE}/${FIP_UBOOT_DTB}-${devicetree}-with-signature.dtb"
|
||||
cp $nameonkernel $namewithsignature
|
||||
cp $nameonkernel $ubootdevicetree
|
||||
done
|
||||
fi
|
||||
}
|
||||
|
||||
SYSROOT_DIRS += "/boot"
|
||||
|
|
|
|||
|
|
@ -8,13 +8,13 @@ install_abort=0
|
|||
BASEFILENAME=0
|
||||
|
||||
# Determine U-Boot file to program basing on module variant
|
||||
if test -n "${module_variant}"; then
|
||||
if test "${module_variant}" = "0x01" || test "${module_variant}" = "0x02"; then
|
||||
setenv INSTALL_UBOOT_FILENAME u-boot-##MACHINE##2GB.imx;
|
||||
elif test "${module_variant}" = "0x03"; then
|
||||
setenv INSTALL_UBOOT_FILENAME u-boot-##MACHINE##1GB.imx;
|
||||
fi
|
||||
# If module_variant is unknown or not set, return error asking the user
|
||||
if test "${module_variant}" = "0x01" || test "${module_variant}" = "0x02"; then
|
||||
setenv INSTALL_UBOOT_FILENAME u-boot-##MACHINE##2GB.imx;
|
||||
elif test "${module_variant}" = "0x03"; then
|
||||
setenv INSTALL_UBOOT_FILENAME u-boot-##MACHINE##1GB.imx;
|
||||
fi
|
||||
|
||||
# Use 'test -n ...' because 'test -z ...' does not work well on old versions of
|
||||
# u-boot when the checked value is empty.
|
||||
if test -n "${INSTALL_UBOOT_FILENAME}"; then
|
||||
|
|
@ -56,7 +56,11 @@ setenv INSTALL_RECOVERY_FILENAME ${BASEFILENAME}-##MACHINE##.recovery.vfat
|
|||
setenv INSTALL_ROOTFS_FILENAME ${BASEFILENAME}-##MACHINE##.ext4
|
||||
|
||||
# Check for presence of firmware files on the SD card
|
||||
for install_f in ${INSTALL_UBOOT_FILENAME} ${INSTALL_LINUX_FILENAME} ${INSTALL_RECOVERY_FILENAME}; do
|
||||
FILES="${INSTALL_UBOOT_FILENAME} ${INSTALL_LINUX_FILENAME}"
|
||||
if test "${dualboot}" != "yes"; then
|
||||
FILES="${FILES} ${INSTALL_RECOVERY_FILENAME}"
|
||||
fi
|
||||
for install_f in ${FILES}; do
|
||||
if test ! -e mmc ${INSTALL_MMCDEV} ${install_f}; then
|
||||
echo "ERROR: Could not find file ${install_f}";
|
||||
install_abort=1;
|
||||
|
|
|
|||
|
|
@ -8,13 +8,13 @@ install_abort=0
|
|||
BASEFILENAME=0
|
||||
|
||||
# Determine U-Boot file to program basing on module variant
|
||||
if test -n "${module_variant}"; then
|
||||
if test "${module_variant}" = "0x01" || test "${module_variant}" = "0x02"; then
|
||||
setenv INSTALL_UBOOT_FILENAME u-boot-##MACHINE##2GB.imx;
|
||||
elif test "${module_variant}" = "0x03"; then
|
||||
setenv INSTALL_UBOOT_FILENAME u-boot-##MACHINE##1GB.imx;
|
||||
fi
|
||||
# If module_variant is unknown or not set, return error asking the user
|
||||
if test "${module_variant}" = "0x01" || test "${module_variant}" = "0x02"; then
|
||||
setenv INSTALL_UBOOT_FILENAME u-boot-##MACHINE##2GB.imx;
|
||||
elif test "${module_variant}" = "0x03"; then
|
||||
setenv INSTALL_UBOOT_FILENAME u-boot-##MACHINE##1GB.imx;
|
||||
fi
|
||||
|
||||
# Use 'test -n ...' because 'test -z ...' does not work well on old versions of
|
||||
# u-boot when the checked value is empty.
|
||||
if test -n "${INSTALL_UBOOT_FILENAME}"; then
|
||||
|
|
@ -56,7 +56,11 @@ setenv INSTALL_RECOVERY_FILENAME ${BASEFILENAME}-##MACHINE##.recovery.vfat
|
|||
setenv INSTALL_ROOTFS_FILENAME ${BASEFILENAME}-##MACHINE##.ext4
|
||||
|
||||
# Check for presence of firmware files on the USB
|
||||
for install_f in ${INSTALL_UBOOT_FILENAME} ${INSTALL_LINUX_FILENAME} ${INSTALL_RECOVERY_FILENAME}; do
|
||||
FILES="${INSTALL_UBOOT_FILENAME} ${INSTALL_LINUX_FILENAME}"
|
||||
if test "${dualboot}" != "yes"; then
|
||||
FILES="${FILES} ${INSTALL_RECOVERY_FILENAME}"
|
||||
fi
|
||||
for install_f in ${FILES}; do
|
||||
if test ! -e usb ${INSTALL_USBDEV} ${install_f}; then
|
||||
echo "ERROR: Could not find file ${install_f}";
|
||||
install_abort=1;
|
||||
|
|
|
|||
|
|
@ -1,7 +1,7 @@
|
|||
#!/bin/sh
|
||||
#===============================================================================
|
||||
#
|
||||
# Copyright (C) 2021-2023 by Digi International Inc.
|
||||
# Copyright (C) 2021-2024 by Digi International Inc.
|
||||
# All rights reserved.
|
||||
#
|
||||
# This program is free software; you can redistribute it and/or modify it
|
||||
|
|
@ -39,7 +39,10 @@ show_usage()
|
|||
echo " -i <dey-image-name> Image name that prefixes the image filenames, such as 'dey-image-qt', "
|
||||
echo " 'dey-image-webkit', 'core-image-base'..."
|
||||
echo " Defaults to '##DEFAULT_IMAGE_NAME##' if not provided."
|
||||
echo " -k <dek-filename> Update includes dek file."
|
||||
echo " (implies -t)."
|
||||
echo " -n No wait. Skips 10 seconds delay to stop script."
|
||||
echo " -t Install Trustfence artifacts."
|
||||
echo " -u <u-boot-filename> U-Boot filename."
|
||||
echo " Auto-determined by variant if not provided."
|
||||
exit 2
|
||||
|
|
@ -49,6 +52,7 @@ show_usage()
|
|||
# Params:
|
||||
# 1. partition
|
||||
# 2. file
|
||||
# 3. dek file when updating an encrypted bootloader
|
||||
part_update()
|
||||
{
|
||||
echo "\033[36m"
|
||||
|
|
@ -57,10 +61,23 @@ part_update()
|
|||
echo "====================================================================================="
|
||||
echo "\033[0m"
|
||||
|
||||
if [ "${1}" = "bootloader" ]; then
|
||||
uuu fb: flash "${1}" "${2}"
|
||||
if [ "${TRUSTFENCE}" = "true" ] && [ "${1}" = "bootloader" ]; then
|
||||
uuu fb: download -f "${2}"
|
||||
if [ -n "${DEK_FILE}" ]; then
|
||||
uuu fb: ucmd setenv uboot_size \${filesize}
|
||||
uuu fb: ucmd setenv fastboot_buffer \${initrd_addr}
|
||||
uuu fb: download -f "${3}"
|
||||
uuu fb: ucmd setenv dek_size \${filesize}
|
||||
uuu fb: ucmd trustfence update ram \${loadaddr} \${uboot_size} \${initrd_addr} \${dek_size}
|
||||
else
|
||||
uuu fb: ucmd trustfence update ram \${fastboot_buffer} \${fastboot_bytes}
|
||||
fi
|
||||
else
|
||||
uuu fb: flash -raw2sparse "${1}" "${2}"
|
||||
if [ "${1}" = "bootloader" ]; then
|
||||
uuu fb: flash "${1}" "${2}"
|
||||
else
|
||||
uuu fb: flash -raw2sparse "${1}" "${2}"
|
||||
fi
|
||||
fi
|
||||
}
|
||||
|
||||
|
|
@ -70,16 +87,27 @@ echo "# Linux firmware install through USB OTG #"
|
|||
echo "############################################################"
|
||||
|
||||
# Command line admits the following parameters:
|
||||
# -u <u-boot-filename>
|
||||
# -b, -d, -n (booleans)
|
||||
# -i <image-name>
|
||||
while getopts 'bdhi:nu:' c
|
||||
# -u <u-boot-filename>
|
||||
# -k <dek-filename>
|
||||
while getopts ':bdhi:k:ntu:' c
|
||||
do
|
||||
if [ "${c}" = ":" ]; then
|
||||
c="${OPTARG}"
|
||||
unset OPTARG
|
||||
elif echo "${OPTARG}" | grep -qs '^-'; then
|
||||
OPTIND="$((OPTIND-1))"
|
||||
unset OPTARG
|
||||
fi
|
||||
case $c in
|
||||
b) BOOTCOUNT=true ;;
|
||||
d) INSTALL_DUALBOOT=true && BOOTCOUNT=true ;;
|
||||
h) show_usage ;;
|
||||
i) IMAGE_NAME=${OPTARG} ;;
|
||||
k) DEK_FILE=${OPTARG} ;;
|
||||
n) NOWAIT=true ;;
|
||||
t) TRUSTFENCE=true ;;
|
||||
u) INSTALL_UBOOT_FILENAME=${OPTARG} ;;
|
||||
esac
|
||||
done
|
||||
|
|
@ -100,13 +128,12 @@ echo "Determining image files to use..."
|
|||
if [ -z ${INSTALL_UBOOT_FILENAME} ]; then
|
||||
module_variant=$(getenv "module_variant")
|
||||
# Determine U-Boot file to program basing on SOM's variant
|
||||
if [ -n "$module_variant" ]; then
|
||||
if [ "$module_variant" = "0x01" ] || \
|
||||
[ "$module_variant" = "0x02" ]; then
|
||||
INSTALL_UBOOT_FILENAME="u-boot-##MACHINE##2GB.imx"
|
||||
elif [ "$module_variant" = "0x03" ]; then
|
||||
INSTALL_UBOOT_FILENAME="u-boot-##MACHINE##1GB.imx"
|
||||
fi
|
||||
# If module_variant is unknown or not set, return error asking the user
|
||||
if [ "$module_variant" = "0x01" ] || \
|
||||
[ "$module_variant" = "0x02" ]; then
|
||||
INSTALL_UBOOT_FILENAME="u-boot-##MACHINE##2GB.imx"
|
||||
elif [ "$module_variant" = "0x03" ] || \
|
||||
INSTALL_UBOOT_FILENAME="u-boot-##MACHINE##1GB.imx"
|
||||
fi
|
||||
|
||||
# U-Boot when the checked value is empty.
|
||||
|
|
@ -130,7 +157,7 @@ if [ -z ${INSTALL_UBOOT_FILENAME} ]; then
|
|||
echo ""
|
||||
echo "Aborted"
|
||||
echo ""
|
||||
exit
|
||||
exit 1
|
||||
fi
|
||||
fi
|
||||
|
||||
|
|
@ -167,7 +194,10 @@ if [ -f ${COMPRESSED_ROOTFS_IMAGE} ] && [ ! -f ${INSTALL_ROOTFS_FILENAME} ]; the
|
|||
fi
|
||||
|
||||
# Verify existence of files before starting the update
|
||||
FILES="${INSTALL_UBOOT_FILENAME} ${INSTALL_LINUX_FILENAME} ${INSTALL_RECOVERY_FILENAME}"
|
||||
FILES="${INSTALL_UBOOT_FILENAME} ${INSTALL_LINUX_FILENAME}"
|
||||
if [ "${DUALBOOT}" != true ]; then
|
||||
FILES="${FILES} ${INSTALL_RECOVERY_FILENAME}"
|
||||
fi
|
||||
for f in ${FILES}; do
|
||||
if [ ! -f ${f} ]; then
|
||||
echo "\033[31m[ERROR] Could not find file '${f}'\033[0m"
|
||||
|
|
@ -186,13 +216,13 @@ if [ ! -f ${INSTALL_ROOTFS_FILENAME} ]; then
|
|||
fi
|
||||
fi
|
||||
|
||||
[ "${ABORT}" = true ] && exit 1
|
||||
|
||||
# Enable bootcount mechanism by setting a bootlimit
|
||||
if [ "${BOOTCOUNT}" = true ]; then
|
||||
bootlimit_cmd="setenv bootlimit 3"
|
||||
fi
|
||||
|
||||
[ "${ABORT}" = true ] && exit 1
|
||||
|
||||
# parts names
|
||||
LINUX_NAME="linux"
|
||||
RECOVERY_NAME="recovery"
|
||||
|
|
@ -240,7 +270,7 @@ fi
|
|||
uuu fb: ucmd setenv forced_update 1
|
||||
|
||||
# Update U-Boot
|
||||
part_update "bootloader" "${INSTALL_UBOOT_FILENAME}"
|
||||
part_update "bootloader" "${INSTALL_UBOOT_FILENAME}" "${DEK_FILE}"
|
||||
|
||||
# Set MMC to boot from BOOT1 partition
|
||||
uuu fb: ucmd mmc partconf 0 1 1 1
|
||||
|
|
|
|||
|
|
@ -8,19 +8,15 @@ install_abort=0
|
|||
BASEFILENAME=0
|
||||
|
||||
# Determine U-Boot file to program basing on module variant
|
||||
if test -n "${module_variant}"; then
|
||||
if test "${module_variant}" = "0x12"; then
|
||||
setenv INSTALL_UBOOT_FILENAME u-boot-ccimx6qsbc2GB.imx;
|
||||
elif test "${module_variant}" = "0x02" || test "${module_variant}" = "0x04" || test "${module_variant}" = "0x05" || test "${module_variant}" = "0x11" || test "${module_variant}" = "0x14" || test "${module_variant}" = "0x16"; then
|
||||
setenv INSTALL_UBOOT_FILENAME u-boot-ccimx6qsbc.imx;
|
||||
elif test "${module_variant}" = "0x03" || test "${module_variant}" = "0x0e" || test "${module_variant}" = "0x0f"; then
|
||||
setenv INSTALL_UBOOT_FILENAME u-boot-ccimx6qsbc512MB.imx;
|
||||
elif test "${module_variant}" = "0x0b" || test "${module_variant}" = "0x15"; then
|
||||
setenv INSTALL_UBOOT_FILENAME u-boot-ccimx6dlsbc.imx;
|
||||
elif test "${module_variant}" = "0x0c" || test "${module_variant}" = "0x13"; then
|
||||
setenv INSTALL_UBOOT_FILENAME u-boot-ccimx6dlsbc512MB.imx;
|
||||
fi
|
||||
# If module_variant is unknown or not set, return error asking the user
|
||||
if test "${module_variant}" = "0x12"; then
|
||||
setenv INSTALL_UBOOT_FILENAME u-boot-ccimx6qsbc2GB.imx;
|
||||
elif test "${module_variant}" = "0x02" || test "${module_variant}" = "0x04" || test "${module_variant}" = "0x05" || test "${module_variant}" = "0x0b" || test "${module_variant}" = "0x11" || test "${module_variant}" = "0x14" || test "${module_variant}" = "0x15" || test "${module_variant}" = "0x16"; then
|
||||
setenv INSTALL_UBOOT_FILENAME u-boot-cc${soc_family}sbc.imx;
|
||||
elif test "${module_variant}" = "0x03" || test "${module_variant}" = "0x0c" || test "${module_variant}" = "0x0e" || test "${module_variant}" = "0x0f" || test "${module_variant}" = "0x13"; then
|
||||
setenv INSTALL_UBOOT_FILENAME u-boot-cc${soc_family}sbc512MB.imx;
|
||||
fi
|
||||
|
||||
# Use 'test -n ...' because 'test -z ...' does not work well on old versions of
|
||||
# u-boot when the checked value is empty.
|
||||
if test -n "${INSTALL_UBOOT_FILENAME}"; then
|
||||
|
|
@ -67,7 +63,11 @@ setenv INSTALL_RECOVERY_FILENAME ${BASEFILENAME}-##MACHINE##.recovery.vfat
|
|||
setenv INSTALL_ROOTFS_FILENAME ${BASEFILENAME}-##MACHINE##.ext4
|
||||
|
||||
# Check for presence of firmware files on the SD card
|
||||
for install_f in ${INSTALL_UBOOT_FILENAME} ${INSTALL_LINUX_FILENAME} ${INSTALL_RECOVERY_FILENAME}; do
|
||||
FILES="${INSTALL_UBOOT_FILENAME} ${INSTALL_LINUX_FILENAME}"
|
||||
if test "${dualboot}" != "yes"; then
|
||||
FILES="${FILES} ${INSTALL_RECOVERY_FILENAME}"
|
||||
fi
|
||||
for install_f in ${FILES}; do
|
||||
if test ! -e mmc ${INSTALL_MMCDEV} ${install_f}; then
|
||||
echo "ERROR: Could not find file ${install_f}";
|
||||
install_abort=1;
|
||||
|
|
|
|||
|
|
@ -8,19 +8,15 @@ install_abort=0
|
|||
BASEFILENAME=0
|
||||
|
||||
# Determine U-Boot file to program basing on module variant
|
||||
if test -n "${module_variant}"; then
|
||||
if test "${module_variant}" = "0x12"; then
|
||||
setenv INSTALL_UBOOT_FILENAME u-boot-ccimx6qsbc2GB.imx;
|
||||
elif test "${module_variant}" = "0x02" || test "${module_variant}" = "0x04" || test "${module_variant}" = "0x05" || test "${module_variant}" = "0x11" || test "${module_variant}" = "0x14" || test "${module_variant}" = "0x16"; then
|
||||
setenv INSTALL_UBOOT_FILENAME u-boot-ccimx6qsbc.imx;
|
||||
elif test "${module_variant}" = "0x03" || test "${module_variant}" = "0x0e" || test "${module_variant}" = "0x0f"; then
|
||||
setenv INSTALL_UBOOT_FILENAME u-boot-ccimx6qsbc512MB.imx;
|
||||
elif test "${module_variant}" = "0x0b" || test "${module_variant}" = "0x15"; then
|
||||
setenv INSTALL_UBOOT_FILENAME u-boot-ccimx6dlsbc.imx;
|
||||
elif test "${module_variant}" = "0x0c" || test "${module_variant}" = "0x13"; then
|
||||
setenv INSTALL_UBOOT_FILENAME u-boot-ccimx6dlsbc512MB.imx;
|
||||
fi
|
||||
# If module_variant is unknown or not set, return error asking the user
|
||||
if test "${module_variant}" = "0x12"; then
|
||||
setenv INSTALL_UBOOT_FILENAME u-boot-ccimx6qsbc2GB.imx;
|
||||
elif test "${module_variant}" = "0x02" || test "${module_variant}" = "0x04" || test "${module_variant}" = "0x05" || test "${module_variant}" = "0x0b" || test "${module_variant}" = "0x11" || test "${module_variant}" = "0x14" || test "${module_variant}" = "0x15" || test "${module_variant}" = "0x16"; then
|
||||
setenv INSTALL_UBOOT_FILENAME u-boot-cc${soc_family}sbc.imx;
|
||||
elif test "${module_variant}" = "0x03" || test "${module_variant}" = "0x0c" || test "${module_variant}" = "0x0e" || test "${module_variant}" = "0x0f" || test "${module_variant}" = "0x13"; then
|
||||
setenv INSTALL_UBOOT_FILENAME u-boot-cc${soc_family}sbc512MB.imx;
|
||||
fi
|
||||
|
||||
# Use 'test -n ...' because 'test -z ...' does not work well on old versions of
|
||||
# u-boot when the checked value is empty.
|
||||
if test -n "${INSTALL_UBOOT_FILENAME}"; then
|
||||
|
|
@ -67,7 +63,11 @@ setenv INSTALL_RECOVERY_FILENAME ${BASEFILENAME}-##MACHINE##.recovery.vfat
|
|||
setenv INSTALL_ROOTFS_FILENAME ${BASEFILENAME}-##MACHINE##.ext4
|
||||
|
||||
# Check for presence of firmware files on the USB
|
||||
for install_f in ${INSTALL_UBOOT_FILENAME} ${INSTALL_LINUX_FILENAME} ${INSTALL_RECOVERY_FILENAME}; do
|
||||
FILES="${INSTALL_UBOOT_FILENAME} ${INSTALL_LINUX_FILENAME}"
|
||||
if test "${dualboot}" != "yes"; then
|
||||
FILES="${FILES} ${INSTALL_RECOVERY_FILENAME}"
|
||||
fi
|
||||
for install_f in ${FILES}; do
|
||||
if test ! -e usb ${INSTALL_USBDEV} ${install_f}; then
|
||||
echo "ERROR: Could not find file ${install_f}";
|
||||
install_abort=1;
|
||||
|
|
|
|||
|
|
@ -1,7 +1,7 @@
|
|||
#!/bin/sh
|
||||
#===============================================================================
|
||||
#
|
||||
# Copyright (C) 2021-2023 by Digi International Inc.
|
||||
# Copyright (C) 2021-2024 by Digi International Inc.
|
||||
# All rights reserved.
|
||||
#
|
||||
# This program is free software; you can redistribute it and/or modify it
|
||||
|
|
@ -39,7 +39,10 @@ show_usage()
|
|||
echo " -i <dey-image-name> Image name that prefixes the image filenames, such as 'dey-image-qt', "
|
||||
echo " 'dey-image-webkit', 'core-image-base'..."
|
||||
echo " Defaults to '##DEFAULT_IMAGE_NAME##' if not provided."
|
||||
echo " -k <dek-filename> Update includes dek file."
|
||||
echo " (implies -t)."
|
||||
echo " -n No wait. Skips 10 seconds delay to stop script."
|
||||
echo " -t Install TrustFence artifacts."
|
||||
echo " -u <u-boot-filename> U-Boot filename."
|
||||
echo " Auto-determined by variant if not provided."
|
||||
exit 2
|
||||
|
|
@ -49,6 +52,7 @@ show_usage()
|
|||
# Params:
|
||||
# 1. partition
|
||||
# 2. file
|
||||
# 3. dek file when updating an encrypted bootloader
|
||||
part_update()
|
||||
{
|
||||
echo "\033[36m"
|
||||
|
|
@ -57,10 +61,23 @@ part_update()
|
|||
echo "====================================================================================="
|
||||
echo "\033[0m"
|
||||
|
||||
if [ "${1}" = "bootloader" ]; then
|
||||
uuu fb: flash "${1}" "${2}"
|
||||
if [ "${TRUSTFENCE}" = "true" ] && [ "${1}" = "bootloader" ]; then
|
||||
uuu fb: download -f "${2}"
|
||||
if [ -n "${DEK_FILE}" ]; then
|
||||
uuu fb: ucmd setenv uboot_size \${filesize}
|
||||
uuu fb: ucmd setenv fastboot_buffer \${initrd_addr}
|
||||
uuu fb: download -f "${3}"
|
||||
uuu fb: ucmd setenv dek_size \${filesize}
|
||||
uuu fb: ucmd trustfence update ram \${loadaddr} \${uboot_size} \${initrd_addr} \${dek_size}
|
||||
else
|
||||
uuu fb: ucmd trustfence update ram \${fastboot_buffer} \${fastboot_bytes}
|
||||
fi
|
||||
else
|
||||
uuu fb: flash -raw2sparse "${1}" "${2}"
|
||||
if [ "${1}" = "bootloader" ]; then
|
||||
uuu fb: flash "${1}" "${2}"
|
||||
else
|
||||
uuu fb: flash -raw2sparse "${1}" "${2}"
|
||||
fi
|
||||
fi
|
||||
}
|
||||
|
||||
|
|
@ -70,16 +87,27 @@ echo "# Linux firmware install through USB OTG #"
|
|||
echo "############################################################"
|
||||
|
||||
# Command line admits the following parameters:
|
||||
# -u <u-boot-filename>
|
||||
# -b, -d, -n (booleans)
|
||||
# -i <image-name>
|
||||
while getopts 'bdhi:nu:' c
|
||||
# -u <u-boot-filename>
|
||||
# -k <dek-filename>
|
||||
while getopts ':bdhi:k:ntu:' c
|
||||
do
|
||||
if [ "${c}" = ":" ]; then
|
||||
c="${OPTARG}"
|
||||
unset OPTARG
|
||||
elif echo "${OPTARG}" | grep -qs '^-'; then
|
||||
OPTIND="$((OPTIND-1))"
|
||||
unset OPTARG
|
||||
fi
|
||||
case $c in
|
||||
b) BOOTCOUNT=true ;;
|
||||
d) INSTALL_DUALBOOT=true && BOOTCOUNT=true ;;
|
||||
h) show_usage ;;
|
||||
i) IMAGE_NAME=${OPTARG} ;;
|
||||
k) DEK_FILE=${OPTARG} && TRUSTFENCE=true ;;
|
||||
n) NOWAIT=true ;;
|
||||
t) TRUSTFENCE=true ;;
|
||||
u) INSTALL_UBOOT_FILENAME=${OPTARG} ;;
|
||||
esac
|
||||
done
|
||||
|
|
@ -102,28 +130,23 @@ if [ -z ${INSTALL_UBOOT_FILENAME} ]; then
|
|||
if [ -n "$soc_family" ]; then
|
||||
module_variant=$(getenv "module_variant")
|
||||
# Determine U-Boot file to program basing on SOM's variant
|
||||
if [ -n "$module_variant" ]; then
|
||||
if [ "$module_variant" = "0x12" ]; then
|
||||
INSTALL_UBOOT_FILENAME="u-boot-cc${soc_family}sbc2GB.imx"
|
||||
elif [ "$module_variant" = "0x01" ] || \
|
||||
[ "$module_variant" = "0x02" ] || \
|
||||
[ "$module_variant" = "0x04" ] || \
|
||||
[ "$module_variant" = "0x05" ] || \
|
||||
[ "$module_variant" = "0x0b" ] || \
|
||||
[ "$module_variant" = "0x0d" ] || \
|
||||
[ "$module_variant" = "0x10" ] || \
|
||||
[ "$module_variant" = "0x11" ] || \
|
||||
[ "$module_variant" = "0x14" ] || \
|
||||
[ "$module_variant" = "0x15" ] || \
|
||||
[ "$module_variant" = "0x16" ]; then
|
||||
INSTALL_UBOOT_FILENAME="u-boot-cc${soc_family}sbc.imx"
|
||||
elif [ "$module_variant" = "0x03" ] || \
|
||||
[ "$module_variant" = "0x0c" ] || \
|
||||
[ "$module_variant" = "0x0e" ] || \
|
||||
[ "$module_variant" = "0x0f" ] || \
|
||||
[ "$module_variant" = "0x13" ]; then
|
||||
INSTALL_UBOOT_FILENAME="u-boot-cc${soc_family}sbc512MB.imx"
|
||||
fi
|
||||
if [ "$module_variant" = "0x12" ]; then
|
||||
INSTALL_UBOOT_FILENAME="u-boot-cc${soc_family}sbc2GB.imx"
|
||||
elif [ "$module_variant" = "0x02" ] || \
|
||||
[ "$module_variant" = "0x04" ] || \
|
||||
[ "$module_variant" = "0x05" ] || \
|
||||
[ "$module_variant" = "0x0b" ] || \
|
||||
[ "$module_variant" = "0x11" ] || \
|
||||
[ "$module_variant" = "0x14" ] || \
|
||||
[ "$module_variant" = "0x15" ] || \
|
||||
[ "$module_variant" = "0x16" ]; then
|
||||
INSTALL_UBOOT_FILENAME="u-boot-cc${soc_family}sbc.imx"
|
||||
elif [ "$module_variant" = "0x03" ] || \
|
||||
[ "$module_variant" = "0x0c" ] || \
|
||||
[ "$module_variant" = "0x0e" ] || \
|
||||
[ "$module_variant" = "0x0f" ] || \
|
||||
[ "$module_variant" = "0x13" ]; then
|
||||
INSTALL_UBOOT_FILENAME="u-boot-cc${soc_family}sbc512MB.imx"
|
||||
fi
|
||||
fi
|
||||
|
||||
|
|
@ -153,7 +176,7 @@ if [ -z ${INSTALL_UBOOT_FILENAME} ]; then
|
|||
echo ""
|
||||
echo "Aborted"
|
||||
echo ""
|
||||
exit
|
||||
exit 1
|
||||
fi
|
||||
fi
|
||||
|
||||
|
|
@ -190,7 +213,10 @@ if [ -f ${COMPRESSED_ROOTFS_IMAGE} ] && [ ! -f ${INSTALL_ROOTFS_FILENAME} ]; the
|
|||
fi
|
||||
|
||||
# Verify existence of files before starting the update
|
||||
FILES="${INSTALL_UBOOT_FILENAME} ${INSTALL_LINUX_FILENAME} ${INSTALL_RECOVERY_FILENAME}"
|
||||
FILES="${INSTALL_UBOOT_FILENAME} ${INSTALL_LINUX_FILENAME}"
|
||||
if [ "${DUALBOOT}" != true ]; then
|
||||
FILES="${FILES} ${INSTALL_RECOVERY_FILENAME}"
|
||||
fi
|
||||
for f in ${FILES}; do
|
||||
if [ ! -f ${f} ]; then
|
||||
echo "\033[31m[ERROR] Could not find file '${f}'\033[0m"
|
||||
|
|
@ -209,13 +235,13 @@ if [ ! -f ${INSTALL_ROOTFS_FILENAME} ]; then
|
|||
fi
|
||||
fi
|
||||
|
||||
[ "${ABORT}" = true ] && exit 1
|
||||
|
||||
# Enable bootcount mechanism by setting a bootlimit
|
||||
if [ "${BOOTCOUNT}" = true ]; then
|
||||
bootlimit_cmd="setenv bootlimit 3"
|
||||
fi
|
||||
|
||||
[ "${ABORT}" = true ] && exit 1
|
||||
|
||||
# parts names
|
||||
LINUX_NAME="linux"
|
||||
RECOVERY_NAME="recovery"
|
||||
|
|
@ -263,7 +289,7 @@ fi
|
|||
uuu fb: ucmd setenv forced_update 1
|
||||
|
||||
# Update U-Boot
|
||||
part_update "bootloader" "${INSTALL_UBOOT_FILENAME}"
|
||||
part_update "bootloader" "${INSTALL_UBOOT_FILENAME}" "${DEK_FILE}"
|
||||
|
||||
# Set MMC to boot from BOOT1 partition
|
||||
uuu fb: ucmd mmc partconf 0 1 1 1
|
||||
|
|
|
|||
|
|
@ -8,14 +8,13 @@ install_abort=0
|
|||
BASEFILENAME=0
|
||||
|
||||
# Determine U-Boot file to program basing on module variant
|
||||
if test -n "${module_variant}"; then
|
||||
if test "${module_variant}" = "0x02" || test "${module_variant}" = "0x03" || test "${module_variant}" = "0x06" || test "${module_variant}" = "0x09"; then
|
||||
setenv INSTALL_UBOOT_FILENAME u-boot-##MACHINE##.imx;
|
||||
elif test "${module_variant}" = "0x04" || test "${module_variant}" = "0x05" || test "${module_variant}" = "0x07"; then
|
||||
setenv INSTALL_UBOOT_FILENAME u-boot-##MACHINE##1GB.imx;
|
||||
elif test "${module_variant}" = "0x08" || test "${module_variant}" = "0x0a"; then
|
||||
setenv INSTALL_UBOOT_FILENAME u-boot-##MACHINE##512MB.imx
|
||||
fi
|
||||
# If module_variant is unknown or not set, return error asking the user
|
||||
if test "${module_variant}" = "0x02" || test "${module_variant}" = "0x03" || test "${module_variant}" = "0x06" || test "${module_variant}" = "0x09"; then
|
||||
setenv INSTALL_UBOOT_FILENAME u-boot-##MACHINE##.imx;
|
||||
elif test "${module_variant}" = "0x04" || test "${module_variant}" = "0x05" || test "${module_variant}" = "0x07"; then
|
||||
setenv INSTALL_UBOOT_FILENAME u-boot-##MACHINE##1GB.imx;
|
||||
elif test "${module_variant}" = "0x08" || test "${module_variant}" = "0x0a"; then
|
||||
setenv INSTALL_UBOOT_FILENAME u-boot-##MACHINE##512MB.imx
|
||||
fi
|
||||
|
||||
# Use 'test -n ...' because 'test -z ...' does not work well on old versions of
|
||||
|
|
@ -60,7 +59,11 @@ setenv INSTALL_RECOVERY_FILENAME ${BASEFILENAME}-##MACHINE##.recovery.ubifs
|
|||
setenv INSTALL_ROOTFS_FILENAME ${BASEFILENAME}-##MACHINE##.ubifs
|
||||
|
||||
# Check for presence of firmware files on the SD card
|
||||
for install_f in ${INSTALL_UBOOT_FILENAME} ${INSTALL_LINUX_FILENAME} ${INSTALL_RECOVERY_FILENAME}; do
|
||||
FILES="${INSTALL_UBOOT_FILENAME} ${INSTALL_LINUX_FILENAME}"
|
||||
if test "${dualboot}" != "yes"; then
|
||||
FILES="${FILES} ${INSTALL_RECOVERY_FILENAME}"
|
||||
fi
|
||||
for install_f in ${FILES}; do
|
||||
if test ! -e mmc ${INSTALL_MMCDEV} ${install_f}; then
|
||||
echo "ERROR: Could not find file ${install_f}";
|
||||
install_abort=1;
|
||||
|
|
|
|||
|
|
@ -8,14 +8,13 @@ install_abort=0
|
|||
BASEFILENAME=0
|
||||
|
||||
# Determine U-Boot file to program basing on module variant
|
||||
if test -n "${module_variant}"; then
|
||||
if test "${module_variant}" = "0x02" || test "${module_variant}" = "0x03" || test "${module_variant}" = "0x06" || test "${module_variant}" = "0x09"; then
|
||||
setenv INSTALL_UBOOT_FILENAME u-boot-##MACHINE##.imx;
|
||||
elif test "${module_variant}" = "0x04" || test "${module_variant}" = "0x05" || test "${module_variant}" = "0x07"; then
|
||||
setenv INSTALL_UBOOT_FILENAME u-boot-##MACHINE##1GB.imx;
|
||||
elif test "${module_variant}" = "0x08" || test "${module_variant}" = "0x0a"; then
|
||||
setenv INSTALL_UBOOT_FILENAME u-boot-##MACHINE##512MB.imx
|
||||
fi
|
||||
# If module_variant is unknown or not set, return error asking the user
|
||||
if test "${module_variant}" = "0x02" || test "${module_variant}" = "0x03" || test "${module_variant}" = "0x06" || test "${module_variant}" = "0x09"; then
|
||||
setenv INSTALL_UBOOT_FILENAME u-boot-##MACHINE##.imx;
|
||||
elif test "${module_variant}" = "0x04" || test "${module_variant}" = "0x05" || test "${module_variant}" = "0x07"; then
|
||||
setenv INSTALL_UBOOT_FILENAME u-boot-##MACHINE##1GB.imx;
|
||||
elif test "${module_variant}" = "0x08" || test "${module_variant}" = "0x0a"; then
|
||||
setenv INSTALL_UBOOT_FILENAME u-boot-##MACHINE##512MB.imx
|
||||
fi
|
||||
|
||||
# Use 'test -n ...' because 'test -z ...' does not work well on old versions of
|
||||
|
|
@ -60,7 +59,11 @@ setenv INSTALL_RECOVERY_FILENAME ${BASEFILENAME}-##MACHINE##.recovery.ubifs
|
|||
setenv INSTALL_ROOTFS_FILENAME ${BASEFILENAME}-##MACHINE##.ubifs
|
||||
|
||||
# Check for presence of firmware files on the USB
|
||||
for install_f in ${INSTALL_UBOOT_FILENAME} ${INSTALL_LINUX_FILENAME} ${INSTALL_RECOVERY_FILENAME}; do
|
||||
FILES="${INSTALL_UBOOT_FILENAME} ${INSTALL_LINUX_FILENAME}"
|
||||
if test "${dualboot}" != "yes"; then
|
||||
FILES="${FILES} ${INSTALL_RECOVERY_FILENAME}"
|
||||
fi
|
||||
for install_f in ${FILES}; do
|
||||
if test ! -e usb ${INSTALL_USBDEV} ${install_f}; then
|
||||
echo "ERROR: Could not find file ${install_f}";
|
||||
install_abort=1;
|
||||
|
|
|
|||
|
|
@ -1,7 +1,7 @@
|
|||
#!/bin/sh
|
||||
#===============================================================================
|
||||
#
|
||||
# Copyright (C) 2020-2023 by Digi International Inc.
|
||||
# Copyright (C) 2020-2024 by Digi International Inc.
|
||||
# All rights reserved.
|
||||
#
|
||||
# This program is free software; you can redistribute it and/or modify it
|
||||
|
|
@ -39,7 +39,10 @@ show_usage()
|
|||
echo " -i <dey-image-name> Image name that prefixes the image filenames, such as 'dey-image-qt', "
|
||||
echo " 'dey-image-webkit', 'core-image-base'..."
|
||||
echo " Defaults to '##DEFAULT_IMAGE_NAME##' if not provided."
|
||||
echo " -k <dek-filename> Update includes dek file."
|
||||
echo " (implies -t)."
|
||||
echo " -n No wait. Skips 10 seconds delay to stop script."
|
||||
echo " -t Install TrustFence artifacts."
|
||||
echo " -u <u-boot-filename> U-Boot filename."
|
||||
echo " Auto-determined by variant if not provided."
|
||||
exit 2
|
||||
|
|
@ -53,6 +56,7 @@ show_usage()
|
|||
# Description:
|
||||
# - downloads image to RAM
|
||||
# - runs 'update' command from RAM
|
||||
# 4. dek file when updating an encrypted u-boot
|
||||
part_update()
|
||||
{
|
||||
echo "\033[36m"
|
||||
|
|
@ -70,7 +74,19 @@ part_update()
|
|||
ERASE="-e"
|
||||
fi
|
||||
uuu fb: download -f "${2}"
|
||||
uuu "fb[-t ${3}]:" ucmd update "${1}" ram \${fastboot_buffer} \${fastboot_bytes} ${ERASE}
|
||||
if [ "${TRUSTFENCE}" = "true" ] && [ "${1}" = "uboot" ]; then
|
||||
if [ -n "${DEK_FILE}" ]; then
|
||||
uuu fb: ucmd setenv uboot_size \${filesize}
|
||||
uuu fb: ucmd setenv fastboot_buffer \${initrd_addr}
|
||||
uuu fb: download -f "${4}"
|
||||
uuu fb: ucmd setenv dek_size \${filesize}
|
||||
uuu "fb[-t ${3}]:" ucmd trustfence update ram \${loadaddr} \${uboot_size} \${initrd_addr} \${dek_size}
|
||||
else
|
||||
uuu "fb[-t ${3}]:" ucmd trustfence update ram \${fastboot_buffer} \${fastboot_bytes}
|
||||
fi
|
||||
else
|
||||
uuu "fb[-t ${3}]:" ucmd update "${1}" ram \${fastboot_buffer} \${fastboot_bytes} ${ERASE}
|
||||
fi
|
||||
}
|
||||
|
||||
clear
|
||||
|
|
@ -79,16 +95,27 @@ echo "# Linux firmware install through USB OTG #"
|
|||
echo "############################################################"
|
||||
|
||||
# Command line admits the following parameters:
|
||||
# -u <u-boot-filename>
|
||||
# -b, -d, -n (booleans)
|
||||
# -i <image-name>
|
||||
while getopts 'bdhi:nu:' c
|
||||
# -u <u-boot-filename>
|
||||
# -k <dek-filename>
|
||||
while getopts ':bdhi:k:ntu:' c
|
||||
do
|
||||
if [ "${c}" = ":" ]; then
|
||||
c="${OPTARG}"
|
||||
unset OPTARG
|
||||
elif echo "${OPTARG}" | grep -qs '^-'; then
|
||||
OPTIND="$((OPTIND-1))"
|
||||
unset OPTARG
|
||||
fi
|
||||
case $c in
|
||||
b) BOOTCOUNT=true ;;
|
||||
d) INSTALL_DUALBOOT=true && BOOTCOUNT=true ;;
|
||||
h) show_usage ;;
|
||||
i) IMAGE_NAME=${OPTARG} ;;
|
||||
k) DEK_FILE=${OPTARG} && TRUSTFENCE=true ;;
|
||||
n) NOWAIT=true ;;
|
||||
t) TRUSTFENCE=true ;;
|
||||
u) INSTALL_UBOOT_FILENAME=${OPTARG} ;;
|
||||
esac
|
||||
done
|
||||
|
|
@ -118,7 +145,7 @@ if [ -z "${INSTALL_UBOOT_FILENAME}" ]; then
|
|||
if [ -n "$module_variant" ]; then
|
||||
if [ "$module_variant" = "0x08" ] || \
|
||||
[ "$module_variant" = "0x0a" ]; then
|
||||
INSTALL_UBOOT_FILENAME="u-boot-##MACHINE##512MB.imx"
|
||||
INSTALL_UBOOT_FILENAME="u-boot-##SIGNED##-##MACHINE##512MB.imx"
|
||||
elif [ "$module_variant" = "0x04" ] || \
|
||||
[ "$module_variant" = "0x05" ] || \
|
||||
[ "$module_variant" = "0x07" ]; then
|
||||
|
|
@ -153,7 +180,7 @@ if [ -z "${INSTALL_UBOOT_FILENAME}" ]; then
|
|||
echo ""
|
||||
echo "Aborted"
|
||||
echo ""
|
||||
exit
|
||||
exit 1
|
||||
fi
|
||||
fi
|
||||
|
||||
|
|
@ -178,7 +205,10 @@ INSTALL_RECOVERY_FILENAME="${BASEFILENAME}-##MACHINE##.recovery.ubifs"
|
|||
INSTALL_ROOTFS_FILENAME="${BASEFILENAME}-##MACHINE##.ubifs"
|
||||
|
||||
# Verify existence of files before starting the update
|
||||
FILES="${INSTALL_UBOOT_FILENAME} ${INSTALL_LINUX_FILENAME} ${INSTALL_RECOVERY_FILENAME}"
|
||||
FILES="${INSTALL_UBOOT_FILENAME} ${INSTALL_LINUX_FILENAME}"
|
||||
if [ "${DUALBOOT}" != true ]; then
|
||||
FILES="${FILES} ${INSTALL_RECOVERY_FILENAME}"
|
||||
fi
|
||||
for f in ${FILES}; do
|
||||
if [ ! -f ${f} ]; then
|
||||
echo "\033[31m[ERROR] Could not find file '${f}'\033[0m"
|
||||
|
|
@ -199,13 +229,13 @@ if [ ! -f ${INSTALL_ROOTFS_FILENAME} ]; then
|
|||
fi
|
||||
fi
|
||||
|
||||
[ "${ABORT}" = true ] && exit 1
|
||||
|
||||
# Enable bootcount mechanism by setting a bootlimit
|
||||
if [ "${BOOTCOUNT}" = true ]; then
|
||||
bootlimit_cmd="setenv bootlimit 3"
|
||||
fi
|
||||
|
||||
[ "${ABORT}" = true ] && exit 1
|
||||
|
||||
# parts names
|
||||
LINUX_NAME="linux"
|
||||
RECOVERY_NAME="recovery"
|
||||
|
|
@ -256,7 +286,7 @@ uuu fb: ucmd setenv fastboot_buffer \${loadaddr}
|
|||
uuu fb: ucmd setenv forced_update 1
|
||||
|
||||
# Update U-Boot
|
||||
part_update "uboot" "${INSTALL_UBOOT_FILENAME}" 5000
|
||||
part_update "uboot" "${INSTALL_UBOOT_FILENAME}" 5000 "${DEK_FILE}"
|
||||
|
||||
# Set 'bootcmd' for the second part of the script that will
|
||||
# - Reset environment to defaults
|
||||
|
|
|
|||
|
|
@ -27,7 +27,11 @@ setenv INSTALL_RECOVERY_FILENAME ${BASEFILENAME}-##MACHINE##.recovery.vfat
|
|||
setenv INSTALL_ROOTFS_FILENAME ${BASEFILENAME}-##MACHINE##.ext4
|
||||
|
||||
# Check for presence of firmware files on the SD card
|
||||
for install_f in ${INSTALL_UBOOT_FILENAME} ${INSTALL_LINUX_FILENAME} ${INSTALL_RECOVERY_FILENAME}; do
|
||||
FILES="${INSTALL_UBOOT_FILENAME} ${INSTALL_LINUX_FILENAME}"
|
||||
if test "${dualboot}" != "yes"; then
|
||||
FILES="${FILES} ${INSTALL_RECOVERY_FILENAME}"
|
||||
fi
|
||||
for install_f in ${FILES}; do
|
||||
if test ! -e mmc ${INSTALL_MMCDEV} ${install_f}; then
|
||||
echo "ERROR: Could not find file ${install_f}";
|
||||
install_abort=1;
|
||||
|
|
|
|||
|
|
@ -27,7 +27,11 @@ setenv INSTALL_RECOVERY_FILENAME ${BASEFILENAME}-##MACHINE##.recovery.vfat
|
|||
setenv INSTALL_ROOTFS_FILENAME ${BASEFILENAME}-##MACHINE##.ext4
|
||||
|
||||
# Check for presence of firmware files on the USB
|
||||
for install_f in ${INSTALL_UBOOT_FILENAME} ${INSTALL_LINUX_FILENAME} ${INSTALL_RECOVERY_FILENAME}; do
|
||||
FILES="${INSTALL_UBOOT_FILENAME} ${INSTALL_LINUX_FILENAME}"
|
||||
if test "${dualboot}" != "yes"; then
|
||||
FILES="${FILES} ${INSTALL_RECOVERY_FILENAME}"
|
||||
fi
|
||||
for install_f in ${FILES}; do
|
||||
if test ! -e usb ${INSTALL_USBDEV} ${install_f}; then
|
||||
echo "ERROR: Could not find file ${install_f}";
|
||||
install_abort=1;
|
||||
|
|
|
|||
|
|
@ -1,7 +1,7 @@
|
|||
#!/bin/sh
|
||||
#===============================================================================
|
||||
#
|
||||
# Copyright (C) 2020-2023 by Digi International Inc.
|
||||
# Copyright (C) 2020-2024 by Digi International Inc.
|
||||
# All rights reserved.
|
||||
#
|
||||
# This program is free software; you can redistribute it and/or modify it
|
||||
|
|
@ -39,7 +39,10 @@ show_usage()
|
|||
echo " -i <dey-image-name> Image name that prefixes the image filenames, such as 'dey-image-qt', "
|
||||
echo " 'dey-image-webkit', 'core-image-base'..."
|
||||
echo " Defaults to '##DEFAULT_IMAGE_NAME##' if not provided."
|
||||
echo " -k <dek-filename> Update includes dek file."
|
||||
echo " (implies -t)."
|
||||
echo " -n No wait. Skips 10 seconds delay to stop script."
|
||||
echo " -t Install TrustFence artifacts."
|
||||
echo " -u <u-boot-filename> U-Boot filename."
|
||||
echo " Auto-determined by variant if not provided."
|
||||
exit 2
|
||||
|
|
@ -49,6 +52,7 @@ show_usage()
|
|||
# Params:
|
||||
# 1. partition
|
||||
# 2. file
|
||||
# 3. dek file when updating an encrypted bootloader
|
||||
part_update()
|
||||
{
|
||||
echo "\033[36m"
|
||||
|
|
@ -57,10 +61,23 @@ part_update()
|
|||
echo "====================================================================================="
|
||||
echo "\033[0m"
|
||||
|
||||
if [ "${1}" = "bootloader" ]; then
|
||||
uuu fb: flash "${1}" "${2}"
|
||||
if [ "${TRUSTFENCE}" = "true" ] && [ "${1}" = "bootloader" ]; then
|
||||
uuu fb: download -f "${2}"
|
||||
if [ -n "${DEK_FILE}" ]; then
|
||||
uuu fb: ucmd setenv uboot_size \${filesize}
|
||||
uuu fb: ucmd setenv fastboot_buffer \${initrd_addr}
|
||||
uuu fb: download -f "${3}"
|
||||
uuu fb: ucmd setenv dek_size \${filesize}
|
||||
uuu fb: ucmd trustfence update ram \${loadaddr} \${uboot_size} \${initrd_addr} \${dek_size}
|
||||
else
|
||||
uuu fb: ucmd trustfence update ram \${fastboot_buffer} \${fastboot_bytes}
|
||||
fi
|
||||
else
|
||||
uuu fb: flash -raw2sparse "${1}" "${2}"
|
||||
if [ "${1}" = "bootloader" ]; then
|
||||
uuu fb: flash "${1}" "${2}"
|
||||
else
|
||||
uuu fb: flash -raw2sparse "${1}" "${2}"
|
||||
fi
|
||||
fi
|
||||
}
|
||||
|
||||
|
|
@ -70,16 +87,27 @@ echo "# Linux firmware install through USB OTG #"
|
|||
echo "############################################################"
|
||||
|
||||
# Command line admits the following parameters:
|
||||
# -u <u-boot-filename>
|
||||
# -b, -d, -n (booleans)
|
||||
# -i <image-name>
|
||||
while getopts 'bdhi:nu:' c
|
||||
# -u <u-boot-filename>
|
||||
# -k <dek-filename>
|
||||
while getopts ':bdhi:k:ntu:' c
|
||||
do
|
||||
if [ "${c}" = ":" ]; then
|
||||
c="${OPTARG}"
|
||||
unset OPTARG
|
||||
elif echo "${OPTARG}" | grep -qs '^-'; then
|
||||
OPTIND="$((OPTIND-1))"
|
||||
unset OPTARG
|
||||
fi
|
||||
case $c in
|
||||
b) BOOTCOUNT=true ;;
|
||||
d) INSTALL_DUALBOOT=true && BOOTCOUNT=true ;;
|
||||
h) show_usage ;;
|
||||
i) IMAGE_NAME=${OPTARG} ;;
|
||||
k) DEK_FILE=${OPTARG} && TRUSTFENCE=true ;;
|
||||
n) NOWAIT=true ;;
|
||||
t) TRUSTFENCE=true ;;
|
||||
u) INSTALL_UBOOT_FILENAME=${OPTARG} ;;
|
||||
esac
|
||||
done
|
||||
|
|
@ -101,7 +129,7 @@ echo "Determining image files to use..."
|
|||
|
||||
# Determine U-Boot file to program basing on SOM's SOC type (linked to bus width)
|
||||
if [ -z "${INSTALL_UBOOT_FILENAME}" ]; then
|
||||
INSTALL_UBOOT_FILENAME="imx-boot-##MACHINE##.bin"
|
||||
INSTALL_UBOOT_FILENAME="imx-boot-##SIGNED##-##MACHINE##.bin"
|
||||
fi
|
||||
|
||||
# Determine linux, recovery, and rootfs image filenames to update
|
||||
|
|
@ -134,7 +162,10 @@ if [ -f ${COMPRESSED_ROOTFS_IMAGE} ] && [ ! -f ${INSTALL_ROOTFS_FILENAME} ]; the
|
|||
fi
|
||||
|
||||
# Verify existence of files before starting the update
|
||||
FILES="${INSTALL_UBOOT_FILENAME} ${INSTALL_LINUX_FILENAME} ${INSTALL_RECOVERY_FILENAME}"
|
||||
FILES="${INSTALL_UBOOT_FILENAME} ${INSTALL_LINUX_FILENAME}"
|
||||
if [ "${DUALBOOT}" != true ]; then
|
||||
FILES="${FILES} ${INSTALL_RECOVERY_FILENAME}"
|
||||
fi
|
||||
for f in ${FILES}; do
|
||||
if [ ! -f ${f} ]; then
|
||||
echo "\033[31m[ERROR] Could not find file '${f}'\033[0m"
|
||||
|
|
@ -153,13 +184,13 @@ if [ ! -f ${INSTALL_ROOTFS_FILENAME} ]; then
|
|||
fi
|
||||
fi
|
||||
|
||||
[ "${ABORT}" = true ] && exit 1
|
||||
|
||||
# Enable bootcount mechanism by setting a bootlimit
|
||||
if [ "${BOOTCOUNT}" = true ]; then
|
||||
bootlimit_cmd="setenv bootlimit 3"
|
||||
fi
|
||||
|
||||
[ "${ABORT}" = true ] && exit 1
|
||||
|
||||
# parts names
|
||||
LINUX_NAME="linux"
|
||||
RECOVERY_NAME="recovery"
|
||||
|
|
@ -210,7 +241,7 @@ uuu fb: ucmd setenv fastboot_buffer \${loadaddr}
|
|||
uuu fb: ucmd setenv forced_update 1
|
||||
|
||||
# Update U-Boot
|
||||
part_update "bootloader" "${INSTALL_UBOOT_FILENAME}"
|
||||
part_update "bootloader" "${INSTALL_UBOOT_FILENAME}" "${DEK_FILE}"
|
||||
|
||||
# Set MMC to boot from BOOT1 partition
|
||||
uuu fb: ucmd mmc partconf 0 1 1 1
|
||||
|
|
|
|||
|
|
@ -39,7 +39,11 @@ setenv INSTALL_RECOVERY_FILENAME ${BASEFILENAME}-##MACHINE##.recovery.vfat
|
|||
setenv INSTALL_ROOTFS_FILENAME ${BASEFILENAME}-##MACHINE##.ext4
|
||||
|
||||
# Check for presence of firmware files on the SD card
|
||||
for install_f in ${INSTALL_UBOOT_FILENAME} ${INSTALL_LINUX_FILENAME} ${INSTALL_RECOVERY_FILENAME}; do
|
||||
FILES="${INSTALL_UBOOT_FILENAME} ${INSTALL_LINUX_FILENAME}"
|
||||
if test "${dualboot}" != "yes"; then
|
||||
FILES="${FILES} ${INSTALL_RECOVERY_FILENAME}"
|
||||
fi
|
||||
for install_f in ${FILES}; do
|
||||
if test ! -e mmc ${INSTALL_MMCDEV} ${install_f}; then
|
||||
echo "ERROR: Could not find file ${install_f}";
|
||||
install_abort=1;
|
||||
|
|
|
|||
|
|
@ -39,7 +39,11 @@ setenv INSTALL_RECOVERY_FILENAME ${BASEFILENAME}-##MACHINE##.recovery.vfat
|
|||
setenv INSTALL_ROOTFS_FILENAME ${BASEFILENAME}-##MACHINE##.ext4
|
||||
|
||||
# Check for presence of firmware files on the USB
|
||||
for install_f in ${INSTALL_UBOOT_FILENAME} ${INSTALL_LINUX_FILENAME} ${INSTALL_RECOVERY_FILENAME}; do
|
||||
FILES="${INSTALL_UBOOT_FILENAME} ${INSTALL_LINUX_FILENAME}"
|
||||
if test "${dualboot}" != "yes"; then
|
||||
FILES="${FILES} ${INSTALL_RECOVERY_FILENAME}"
|
||||
fi
|
||||
for install_f in ${FILES}; do
|
||||
if test ! -e usb ${INSTALL_USBDEV} ${install_f}; then
|
||||
echo "ERROR: Could not find file ${install_f}";
|
||||
install_abort=1;
|
||||
|
|
|
|||
|
|
@ -1,7 +1,7 @@
|
|||
#!/bin/sh
|
||||
#===============================================================================
|
||||
#
|
||||
# Copyright (C) 2020-2023 by Digi International Inc.
|
||||
# Copyright (C) 2020-2024 by Digi International Inc.
|
||||
# All rights reserved.
|
||||
#
|
||||
# This program is free software; you can redistribute it and/or modify it
|
||||
|
|
@ -39,7 +39,10 @@ show_usage()
|
|||
echo " -i <dey-image-name> Image name that prefixes the image filenames, such as 'dey-image-qt', "
|
||||
echo " 'dey-image-webkit', 'core-image-base'..."
|
||||
echo " Defaults to '##DEFAULT_IMAGE_NAME##' if not provided."
|
||||
echo " -k <dek-filename> Update includes dek file."
|
||||
echo " (implies -t)."
|
||||
echo " -n No wait. Skips 10 seconds delay to stop script."
|
||||
echo " -t Install TrustFence artifacts."
|
||||
echo " -u <u-boot-filename> U-Boot filename."
|
||||
echo " Auto-determined by variant if not provided."
|
||||
exit 2
|
||||
|
|
@ -49,6 +52,7 @@ show_usage()
|
|||
# Params:
|
||||
# 1. partition
|
||||
# 2. file
|
||||
# 3. dek file when updating an encrypted bootloader
|
||||
part_update()
|
||||
{
|
||||
echo "\033[36m"
|
||||
|
|
@ -57,10 +61,23 @@ part_update()
|
|||
echo "====================================================================================="
|
||||
echo "\033[0m"
|
||||
|
||||
if [ "${1}" = "bootloader" ]; then
|
||||
uuu fb: flash "${1}" "${2}"
|
||||
if [ "${TRUSTFENCE}" = "true" ] && [ "${1}" = "bootloader" ]; then
|
||||
uuu fb: download -f "${2}"
|
||||
if [ -n "${DEK_FILE}" ]; then
|
||||
uuu fb: ucmd setenv uboot_size \${filesize}
|
||||
uuu fb: ucmd setenv fastboot_buffer \${initrd_addr}
|
||||
uuu fb: download -f "${3}"
|
||||
uuu fb: ucmd setenv dek_size \${filesize}
|
||||
uuu fb: ucmd trustfence update ram \${loadaddr} \${uboot_size} \${initrd_addr} \${dek_size}
|
||||
else
|
||||
uuu fb: ucmd trustfence update ram \${fastboot_buffer} \${fastboot_bytes}
|
||||
fi
|
||||
else
|
||||
uuu fb: flash -raw2sparse "${1}" "${2}"
|
||||
if [ "${1}" = "bootloader" ]; then
|
||||
uuu fb: flash "${1}" "${2}"
|
||||
else
|
||||
uuu fb: flash -raw2sparse "${1}" "${2}"
|
||||
fi
|
||||
fi
|
||||
}
|
||||
|
||||
|
|
@ -70,16 +87,27 @@ echo "# Linux firmware install through USB OTG #"
|
|||
echo "############################################################"
|
||||
|
||||
# Command line admits the following parameters:
|
||||
# -u <u-boot-filename>
|
||||
# -b, -d, -n (booleans)
|
||||
# -i <image-name>
|
||||
while getopts 'bdhi:nu:' c
|
||||
# -u <u-boot-filename>
|
||||
# -k <dek-filename>
|
||||
while getopts ':bdhi:k:ntu:' c
|
||||
do
|
||||
if [ "${c}" = ":" ]; then
|
||||
c="${OPTARG}"
|
||||
unset OPTARG
|
||||
elif echo "${OPTARG}" | grep -qs '^-'; then
|
||||
OPTIND="$((OPTIND-1))"
|
||||
unset OPTARG
|
||||
fi
|
||||
case $c in
|
||||
b) BOOTCOUNT=true ;;
|
||||
d) INSTALL_DUALBOOT=true && BOOTCOUNT=true ;;
|
||||
h) show_usage ;;
|
||||
i) IMAGE_NAME=${OPTARG} ;;
|
||||
k) DEK_FILE=${OPTARG} && TRUSTFENCE=true ;;
|
||||
n) NOWAIT=true ;;
|
||||
t) TRUSTFENCE=true ;;
|
||||
u) INSTALL_UBOOT_FILENAME=${OPTARG} ;;
|
||||
esac
|
||||
done
|
||||
|
|
@ -105,7 +133,7 @@ if [ -z ${INSTALL_UBOOT_FILENAME} ]; then
|
|||
soc_rev="B0"
|
||||
fi
|
||||
|
||||
INSTALL_UBOOT_FILENAME="imx-boot-##MACHINE##-${soc_rev}.bin"
|
||||
INSTALL_UBOOT_FILENAME="imx-boot-##SIGNED##-##MACHINE##-${soc_rev}.bin"
|
||||
fi
|
||||
|
||||
# remove redirect
|
||||
|
|
@ -141,7 +169,10 @@ if [ -f ${COMPRESSED_ROOTFS_IMAGE} ] && [ ! -f ${INSTALL_ROOTFS_FILENAME} ]; the
|
|||
fi
|
||||
|
||||
# Verify existence of files before starting the update
|
||||
FILES="${INSTALL_UBOOT_FILENAME} ${INSTALL_LINUX_FILENAME} ${INSTALL_RECOVERY_FILENAME}"
|
||||
FILES="${INSTALL_UBOOT_FILENAME} ${INSTALL_LINUX_FILENAME}"
|
||||
if [ "${DUALBOOT}" != true ]; then
|
||||
FILES="${FILES} ${INSTALL_RECOVERY_FILENAME}"
|
||||
fi
|
||||
for f in ${FILES}; do
|
||||
if [ ! -f ${f} ]; then
|
||||
echo "\033[31m[ERROR] Could not find file '${f}'\033[0m"
|
||||
|
|
@ -160,13 +191,13 @@ if [ ! -f ${INSTALL_ROOTFS_FILENAME} ]; then
|
|||
fi
|
||||
fi
|
||||
|
||||
[ "${ABORT}" = true ] && exit 1
|
||||
|
||||
# Enable bootcount mechanism by setting a bootlimit
|
||||
if [ "${BOOTCOUNT}" = true ]; then
|
||||
bootlimit_cmd="setenv bootlimit 3"
|
||||
fi
|
||||
|
||||
[ "${ABORT}" = true ] && exit 1
|
||||
|
||||
# parts names
|
||||
LINUX_NAME="linux"
|
||||
RECOVERY_NAME="recovery"
|
||||
|
|
@ -210,11 +241,14 @@ if [ "${NOWAIT}" != true ]; then
|
|||
printf " Starting update process\n"
|
||||
fi
|
||||
|
||||
# Set fastboot buffer address to $loadaddr, just in case
|
||||
uuu fb: ucmd setenv fastboot_buffer \${loadaddr}
|
||||
|
||||
# Skip user confirmation for U-Boot update
|
||||
uuu fb: ucmd setenv forced_update 1
|
||||
|
||||
# Update U-Boot
|
||||
part_update "bootloader" "${INSTALL_UBOOT_FILENAME}"
|
||||
part_update "bootloader" "${INSTALL_UBOOT_FILENAME}" "${DEK_FILE}"
|
||||
|
||||
# Set MMC to boot from BOOT1 partition
|
||||
uuu fb: ucmd mmc partconf 0 1 1 1
|
||||
|
|
|
|||
|
|
@ -84,6 +84,10 @@ if test "${module_has_npu}" = "1" && test -z "${disable_npu}"; then
|
|||
setenv overlays _ov_som_npu_ccimx93.dtbo,${overlays}
|
||||
fi
|
||||
|
||||
if test "${dboot_kernel_var}" = "fitimage" && test -z "${temp-fitimg-loaded}"; then
|
||||
# Set temp var to avoid re-loading fitimage
|
||||
setenv temp-fitimg-loaded yes
|
||||
fi
|
||||
dboot linux mmc ${mmcbootdev}:${mmcpart}
|
||||
|
||||
#
|
||||
|
|
|
|||
|
|
@ -40,7 +40,11 @@ setenv INSTALL_RECOVERY_FILENAME ${BASEFILENAME}-##MACHINE##.recovery.vfat
|
|||
setenv INSTALL_ROOTFS_FILENAME ${BASEFILENAME}-##MACHINE##.ext4
|
||||
|
||||
# Check for presence of firmware files on the SD card
|
||||
for install_f in ${INSTALL_UBOOT_FILENAME} ${INSTALL_LINUX_FILENAME} ${INSTALL_RECOVERY_FILENAME}; do
|
||||
FILES="${INSTALL_UBOOT_FILENAME} ${INSTALL_LINUX_FILENAME}"
|
||||
if test "${dualboot}" != "yes"; then
|
||||
FILES="${FILES} ${INSTALL_RECOVERY_FILENAME}"
|
||||
fi
|
||||
for install_f in ${FILES}; do
|
||||
if test ! -e mmc ${INSTALL_MMCDEV} ${install_f}; then
|
||||
echo "ERROR: Could not find file ${install_f}";
|
||||
install_abort=1;
|
||||
|
|
@ -72,7 +76,10 @@ echo " on the partitions of the eMMC."
|
|||
echo ""
|
||||
echo " PARTITION FILENAME"
|
||||
echo " --------- --------"
|
||||
echo " bootloader ${INSTALL_UBOOT_FILENAME}"
|
||||
echo " bootloader1 ${INSTALL_UBOOT_FILENAME}"
|
||||
if test "${install_redundant_bootloader}" = "yes"; then
|
||||
echo " bootloader2 ${INSTALL_UBOOT_FILENAME}"
|
||||
fi
|
||||
if test "${dualboot}" = "yes"; then
|
||||
echo " linux_a ${INSTALL_LINUX_FILENAME}"
|
||||
if test "${install_dualboot}" = "yes"; then
|
||||
|
|
@ -125,6 +132,21 @@ if test $? -eq 1; then
|
|||
fi
|
||||
fi
|
||||
|
||||
if test "${install_redundant_bootloader}" = yes; then
|
||||
echo "";
|
||||
echo "";
|
||||
echo ">> Installing U-Boot boot loader image ${INSTALL_UBOOT_FILENAME} on redundant partition";
|
||||
echo "";
|
||||
echo "";
|
||||
update uboot-redundant mmc ${INSTALL_MMCDEV} ${INSTALL_UBOOT_FILENAME};
|
||||
if test $? -eq 1; then
|
||||
echo "[ERROR] Failed to update redundant U-Boot boot loader!";
|
||||
echo "";
|
||||
echo "Aborted.";
|
||||
exit;
|
||||
fi;
|
||||
fi;
|
||||
|
||||
# Set 'bootcmd' to the second part of the script that will
|
||||
# - Reset environment to defaults
|
||||
# - Restore 'dualboot' if previously set
|
||||
|
|
|
|||
|
|
@ -40,7 +40,11 @@ setenv INSTALL_RECOVERY_FILENAME ${BASEFILENAME}-##MACHINE##.recovery.vfat
|
|||
setenv INSTALL_ROOTFS_FILENAME ${BASEFILENAME}-##MACHINE##.ext4
|
||||
|
||||
# Check for presence of firmware files on the USB
|
||||
for install_f in ${INSTALL_UBOOT_FILENAME} ${INSTALL_LINUX_FILENAME} ${INSTALL_RECOVERY_FILENAME}; do
|
||||
FILES="${INSTALL_UBOOT_FILENAME} ${INSTALL_LINUX_FILENAME}"
|
||||
if test "${dualboot}" != "yes"; then
|
||||
FILES="${FILES} ${INSTALL_RECOVERY_FILENAME}"
|
||||
fi
|
||||
for install_f in ${FILES}; do
|
||||
if test ! -e usb ${INSTALL_USBDEV} ${install_f}; then
|
||||
echo "ERROR: Could not find file ${install_f}";
|
||||
install_abort=1;
|
||||
|
|
@ -72,7 +76,10 @@ echo " on the partitions of the eMMC."
|
|||
echo ""
|
||||
echo " PARTITION FILENAME"
|
||||
echo " --------- --------"
|
||||
echo " bootloader ${INSTALL_UBOOT_FILENAME}"
|
||||
echo " bootloader1 ${INSTALL_UBOOT_FILENAME}"
|
||||
if test "${install_redundant_bootloader}" = "yes"; then
|
||||
echo " bootloader2 ${INSTALL_UBOOT_FILENAME}"
|
||||
fi
|
||||
if test "${dualboot}" = "yes"; then
|
||||
echo " linux_a ${INSTALL_LINUX_FILENAME}"
|
||||
if test "${install_dualboot}" = "yes"; then
|
||||
|
|
@ -125,6 +132,21 @@ if test $? -eq 1; then
|
|||
fi
|
||||
fi
|
||||
|
||||
if test "${install_redundant_bootloader}" = yes; then
|
||||
echo "";
|
||||
echo "";
|
||||
echo ">> Installing U-Boot boot loader image ${INSTALL_UBOOT_FILENAME} on redundant partition";
|
||||
echo "";
|
||||
echo "";
|
||||
update uboot-redundant usb ${INSTALL_USBDEV} ${INSTALL_UBOOT_FILENAME};
|
||||
if test $? -eq 1; then
|
||||
echo "[ERROR] Failed to update redundant U-Boot boot loader!";
|
||||
echo "";
|
||||
echo "Aborted.";
|
||||
exit;
|
||||
fi;
|
||||
fi;
|
||||
|
||||
# Set 'bootcmd' to the second part of the script that will
|
||||
# - Reset environment to defaults
|
||||
# - Restore 'dualboot' if previously set
|
||||
|
|
|
|||
|
|
@ -1,7 +1,7 @@
|
|||
#!/bin/sh
|
||||
#===============================================================================
|
||||
#
|
||||
# Copyright (C) 2020-2023 by Digi International Inc.
|
||||
# Copyright (C) 2020-2024 by Digi International Inc.
|
||||
# All rights reserved.
|
||||
#
|
||||
# This program is free software; you can redistribute it and/or modify it
|
||||
|
|
@ -39,9 +39,14 @@ show_usage()
|
|||
echo " -i <dey-image-name> Image name that prefixes the image filenames, such as 'dey-image-qt', "
|
||||
echo " 'dey-image-webkit', 'core-image-base'..."
|
||||
echo " Defaults to '##DEFAULT_IMAGE_NAME##' if not provided."
|
||||
echo " -k <dek-filename> Update includes dek file."
|
||||
echo " (implies -t)."
|
||||
echo " -n No wait. Skips 10 seconds delay to stop script."
|
||||
echo " -u <u-boot-filename> U-Boot filename."
|
||||
echo " -t Install TrustFence artifacts."
|
||||
echo " Auto-determined by variant if not provided."
|
||||
echo " -U Update redundant bootloader partition."
|
||||
|
||||
exit 2
|
||||
}
|
||||
|
||||
|
|
@ -49,6 +54,7 @@ show_usage()
|
|||
# Params:
|
||||
# 1. partition
|
||||
# 2. file
|
||||
# 3. dek file when updating an encrypted bootloader
|
||||
part_update()
|
||||
{
|
||||
echo "\033[36m"
|
||||
|
|
@ -57,10 +63,23 @@ part_update()
|
|||
echo "====================================================================================="
|
||||
echo "\033[0m"
|
||||
|
||||
if [ "${1}" = "bootloader" ]; then
|
||||
uuu fb: flash "${1}" "${2}"
|
||||
if [ "${TRUSTFENCE}" = "true" ] && [ "${1}" = "bootloader" ]; then
|
||||
uuu fb: download -f "${2}"
|
||||
if [ -n "${DEK_FILE}" ]; then
|
||||
uuu fb: ucmd setenv uboot_size \${filesize}
|
||||
uuu fb: ucmd setenv fastboot_buffer \${initrd_addr}
|
||||
uuu fb: download -f "${3}"
|
||||
uuu fb: ucmd setenv dek_size \${filesize}
|
||||
uuu fb: ucmd trustfence update ram \${loadaddr} \${uboot_size} \${initrd_addr} \${dek_size}
|
||||
else
|
||||
uuu fb: ucmd trustfence update ram \${fastboot_buffer} \${fastboot_bytes}
|
||||
fi
|
||||
else
|
||||
uuu fb: flash -raw2sparse "${1}" "${2}"
|
||||
if [ "${1}" = "bootloader" ] || [ "${1}" = "bootloader_redundant" ]; then
|
||||
uuu fb: flash "${1}" "${2}"
|
||||
else
|
||||
uuu fb: flash -raw2sparse "${1}" "${2}"
|
||||
fi
|
||||
fi
|
||||
}
|
||||
|
||||
|
|
@ -70,17 +89,29 @@ echo "# Linux firmware install through USB OTG #"
|
|||
echo "############################################################"
|
||||
|
||||
# Command line admits the following parameters:
|
||||
# -u <u-boot-filename>
|
||||
# -b, -d, -n (booleans)
|
||||
# -i <image-name>
|
||||
while getopts 'bdhi:nu:' c
|
||||
# -u <u-boot-filename>
|
||||
# -k <dek-filename>
|
||||
while getopts ':bdhti:nu:Uk:' c
|
||||
do
|
||||
if [ "${c}" = ":" ]; then
|
||||
c="${OPTARG}"
|
||||
unset OPTARG
|
||||
elif echo "${OPTARG}" | grep -qs '^-'; then
|
||||
OPTIND="$((OPTIND-1))"
|
||||
unset OPTARG
|
||||
fi
|
||||
case $c in
|
||||
b) BOOTCOUNT=true ;;
|
||||
d) INSTALL_DUALBOOT=true && BOOTCOUNT=true ;;
|
||||
h) show_usage ;;
|
||||
i) IMAGE_NAME=${OPTARG} ;;
|
||||
k) DEK_FILE=${OPTARG} && TRUSTFENCE=true ;;
|
||||
n) NOWAIT=true ;;
|
||||
u) INSTALL_UBOOT_FILENAME=${OPTARG} ;;
|
||||
t) TRUSTFENCE=true ;;
|
||||
U) INSTALL_REDUNDANT_UBOOT=true ;;
|
||||
esac
|
||||
done
|
||||
|
||||
|
|
@ -108,7 +139,7 @@ if [ -z "${INSTALL_UBOOT_FILENAME}" ]; then
|
|||
som_hv="$(((hwid_2 & 0x78) >> 3))"
|
||||
[ "${som_hv}" -lt "2" ] && SOCREV="-A0"
|
||||
fi
|
||||
INSTALL_UBOOT_FILENAME="imx-boot-##MACHINE##${SOCREV}.bin"
|
||||
INSTALL_UBOOT_FILENAME="imx-boot-##SIGNED##-##MACHINE##${SOCREV}.bin"
|
||||
fi
|
||||
|
||||
# remove redirect
|
||||
|
|
@ -144,7 +175,10 @@ if [ -f ${COMPRESSED_ROOTFS_IMAGE} ] && [ ! -f ${INSTALL_ROOTFS_FILENAME} ]; the
|
|||
fi
|
||||
|
||||
# Verify existence of files before starting the update
|
||||
FILES="${INSTALL_UBOOT_FILENAME} ${INSTALL_LINUX_FILENAME} ${INSTALL_RECOVERY_FILENAME}"
|
||||
FILES="${INSTALL_UBOOT_FILENAME} ${INSTALL_LINUX_FILENAME}"
|
||||
if [ "${DUALBOOT}" != true ]; then
|
||||
FILES="${FILES} ${INSTALL_RECOVERY_FILENAME}"
|
||||
fi
|
||||
for f in ${FILES}; do
|
||||
if [ ! -f ${f} ]; then
|
||||
echo "\033[31m[ERROR] Could not find file '${f}'\033[0m"
|
||||
|
|
@ -163,13 +197,13 @@ if [ ! -f ${INSTALL_ROOTFS_FILENAME} ]; then
|
|||
fi
|
||||
fi
|
||||
|
||||
[ "${ABORT}" = true ] && exit 1
|
||||
|
||||
# Enable bootcount mechanism by setting a bootlimit
|
||||
if [ "${BOOTCOUNT}" = true ]; then
|
||||
bootlimit_cmd="setenv bootlimit 3"
|
||||
fi
|
||||
|
||||
[ "${ABORT}" = true ] && exit 1
|
||||
|
||||
# parts names
|
||||
LINUX_NAME="linux"
|
||||
RECOVERY_NAME="recovery"
|
||||
|
|
@ -187,6 +221,9 @@ if [ "${NOWAIT}" != true ]; then
|
|||
printf " PARTITION\tFILENAME\n"
|
||||
printf " ---------\t--------\n"
|
||||
printf " bootloader\t${INSTALL_UBOOT_FILENAME}\n"
|
||||
if [ "${INSTALL_REDUNDANT_UBOOT}" = true ]; then
|
||||
printf " bootloader_redundant\t${INSTALL_UBOOT_FILENAME}\n"
|
||||
fi
|
||||
if [ "${DUALBOOT}" = true ]; then
|
||||
printf " ${LINUX_NAME}_a\t${INSTALL_LINUX_FILENAME}\n"
|
||||
if [ "${INSTALL_DUALBOOT}" = true ]; then
|
||||
|
|
@ -220,7 +257,10 @@ uuu fb: ucmd setenv fastboot_buffer \${loadaddr}
|
|||
uuu fb: ucmd setenv forced_update 1
|
||||
|
||||
# Update U-Boot
|
||||
part_update "bootloader" "${INSTALL_UBOOT_FILENAME}"
|
||||
part_update "bootloader" "${INSTALL_UBOOT_FILENAME}" "${DEK_FILE}"
|
||||
if [ "${INSTALL_REDUNDANT_UBOOT}" = true ]; then
|
||||
part_update bootloader_redundant "${INSTALL_UBOOT_FILENAME}"
|
||||
fi
|
||||
|
||||
# Set MMC to boot from BOOT1 partition
|
||||
uuu fb: ucmd mmc partconf 0 1 1 1
|
||||
|
|
@ -300,6 +340,10 @@ fi
|
|||
if [ -f ${COMPRESSED_ROOTFS_IMAGE} ] && [ -f ${INSTALL_ROOTFS_FILENAME} ]; then
|
||||
rm -f "${INSTALL_ROOTFS_FILENAME}"
|
||||
fi
|
||||
# Set the dboot_kernel_var to fitimage if Trustfence is enabled
|
||||
if [ "${TRUSTFENCE}" = "true" ] || echo "$INSTALL_UBOOT_FILENAME" | grep -q -e "signed" -e "encrypted"; then
|
||||
uuu fb: ucmd setenv dboot_kernel_var fitimage
|
||||
fi
|
||||
|
||||
if [ "${DUALBOOT}" != true ]; then
|
||||
# Configure u-boot to boot into recovery mode
|
||||
|
|
|
|||
|
|
@ -1 +0,0 @@
|
|||
# CONFIG_LEGACY_IMAGE_FORMAT is not set
|
||||
|
|
@ -1,4 +1,6 @@
|
|||
# CONFIG_LEGACY_IMAGE_FORMAT is not set
|
||||
CONFIG_FIT_SIGNATURE=y
|
||||
CONFIG_RSA=y
|
||||
CONFIG_ECDSA=y
|
||||
CONFIG_ECDSA_VERIFY=y
|
||||
# CONFIG_CMD_BOOTZ is not set
|
||||
|
|
|
|||
|
|
@ -7,8 +7,8 @@
|
|||
install_abort=0
|
||||
BASEFILENAME=0
|
||||
|
||||
setenv INSTALL_ATF_FILENAME tf-a-##MACHINE##-nand.stm32
|
||||
setenv INSTALL_FIP_FILENAME fip-##MACHINE##-optee.bin
|
||||
setenv INSTALL_ATF_FILENAME tf-a-##MACHINE##-${module_ram}-nand.stm32
|
||||
setenv INSTALL_FIP_FILENAME fip-##MACHINE##-${module_ram}-optee.bin
|
||||
setenv INSTALL_MMCDEV 1
|
||||
|
||||
if test -z "${image-name}"; then
|
||||
|
|
@ -28,7 +28,11 @@ setenv INSTALL_RECOVERY_FILENAME ${BASEFILENAME}-##MACHINE##.recovery.ubifs
|
|||
setenv INSTALL_ROOTFS_FILENAME ${BASEFILENAME}-##MACHINE##.ubifs
|
||||
|
||||
# Check for presence of firmware files on the SD card
|
||||
for install_f in ${INSTALL_ATF_FILENAME} ${INSTALL_FIP_FILENAME} ${INSTALL_LINUX_FILENAME} ${INSTALL_RECOVERY_FILENAME}; do
|
||||
FILES="${INSTALL_ATF_FILENAME} ${INSTALL_FIP_FILENAME} ${INSTALL_LINUX_FILENAME}"
|
||||
if test "${dualboot}" != "yes"; then
|
||||
FILES="${FILES} ${INSTALL_RECOVERY_FILENAME}"
|
||||
fi
|
||||
for install_f in ${FILES}; do
|
||||
if test ! -e mmc ${INSTALL_MMCDEV} ${install_f}; then
|
||||
echo "ERROR: Could not find file ${install_f}";
|
||||
install_abort=1;
|
||||
|
|
|
|||
|
|
@ -7,8 +7,8 @@
|
|||
install_abort=0
|
||||
BASEFILENAME=0
|
||||
|
||||
setenv INSTALL_ATF_FILENAME tf-a-##MACHINE##-nand.stm32
|
||||
setenv INSTALL_FIP_FILENAME fip-##MACHINE##-optee.bin
|
||||
setenv INSTALL_ATF_FILENAME tf-a-##MACHINE##-${module_ram}-nand.stm32
|
||||
setenv INSTALL_FIP_FILENAME fip-##MACHINE##-${module_ram}-optee.bin
|
||||
setenv INSTALL_USBDEV 0
|
||||
|
||||
if test -z "${image-name}"; then
|
||||
|
|
@ -28,7 +28,11 @@ setenv INSTALL_RECOVERY_FILENAME ${BASEFILENAME}-##MACHINE##.recovery.ubifs
|
|||
setenv INSTALL_ROOTFS_FILENAME ${BASEFILENAME}-##MACHINE##.ubifs
|
||||
|
||||
# Check for presence of firmware files on the USB
|
||||
for install_f in ${INSTALL_ATF_FILENAME} ${INSTALL_FIP_FILENAME} ${INSTALL_LINUX_FILENAME} ${INSTALL_RECOVERY_FILENAME}; do
|
||||
FILES="${INSTALL_ATF_FILENAME} ${INSTALL_FIP_FILENAME} ${INSTALL_LINUX_FILENAME}"
|
||||
if test "${dualboot}" != "yes"; then
|
||||
FILES="${FILES} ${INSTALL_RECOVERY_FILENAME}"
|
||||
fi
|
||||
for install_f in ${FILES}; do
|
||||
if test ! -e usb ${INSTALL_USBDEV} ${install_f}; then
|
||||
echo "ERROR: Could not find file ${install_f}";
|
||||
install_abort=1;
|
||||
|
|
|
|||
|
|
@ -1,7 +1,7 @@
|
|||
#!/bin/sh
|
||||
#===============================================================================
|
||||
#
|
||||
# Copyright (C) 2022-2023 by Digi International Inc.
|
||||
# Copyright (C) 2022-2024 by Digi International Inc.
|
||||
# All rights reserved.
|
||||
#
|
||||
# This program is free software; you can redistribute it and/or modify it
|
||||
|
|
@ -50,6 +50,7 @@ show_usage()
|
|||
echo " 'dey-image-webkit', 'core-image-base'..."
|
||||
echo " Defaults to '##DEFAULT_IMAGE_NAME##' if not provided."
|
||||
echo " -n No wait. Skips 10 seconds delay to stop script."
|
||||
echo " -t Install TrustFence artifacts."
|
||||
exit 2
|
||||
}
|
||||
|
||||
|
|
@ -80,6 +81,7 @@ echo "############################################################"
|
|||
|
||||
# Command line admits the following parameters:
|
||||
# -a <atf-filename>
|
||||
# -b, -d, -n (booleans)
|
||||
# -f <fip-filename>
|
||||
# -i <image-name>
|
||||
while getopts 'a:bdf:hi:n' c
|
||||
|
|
@ -92,6 +94,7 @@ do
|
|||
h) show_usage ;;
|
||||
i) IMAGE_NAME=${OPTARG} ;;
|
||||
n) NOWAIT=true ;;
|
||||
t) TRUSTFENCE=true ;;
|
||||
esac
|
||||
done
|
||||
|
||||
|
|
@ -111,6 +114,12 @@ if [ "${check}" = "1" ]; then
|
|||
RUNVOLS=true
|
||||
fi
|
||||
|
||||
# Check module_ram variable exists
|
||||
module_ram=$(getenv "module_ram")
|
||||
if [ -z "${module_ram}" ]; then
|
||||
module_ram="512MB" # Default variant
|
||||
fi
|
||||
|
||||
# remove redirect
|
||||
uuu fb: ucmd setenv stdout serial
|
||||
|
||||
|
|
@ -119,12 +128,12 @@ echo "Determining image files to use..."
|
|||
|
||||
# Determine ATF file to program
|
||||
if [ -z "${INSTALL_ATF_FILENAME}" ]; then
|
||||
INSTALL_ATF_FILENAME="tf-a-##MACHINE##-nand.stm32"
|
||||
INSTALL_ATF_FILENAME="tf-a-##MACHINE##-${module_ram}-nand.stm32##SIGNED_TFA##"
|
||||
fi
|
||||
|
||||
# Determine FIP file to program
|
||||
if [ -z "${INSTALL_FIP_FILENAME}" ]; then
|
||||
INSTALL_FIP_FILENAME="fip-##MACHINE##-optee.bin"
|
||||
INSTALL_FIP_FILENAME="fip-##MACHINE##-${module_ram}-optee##SIGNED##.bin"
|
||||
fi
|
||||
|
||||
# Determine linux, recovery, and rootfs image filenames to update
|
||||
|
|
@ -145,7 +154,11 @@ INSTALL_RECOVERY_FILENAME="${BASEFILENAME}-##MACHINE##.recovery.ubifs"
|
|||
INSTALL_ROOTFS_FILENAME="${BASEFILENAME}-##MACHINE##.ubifs"
|
||||
|
||||
# Verify existence of files before starting the update
|
||||
FILES="${INSTALL_ATF_FILENAME} ${INSTALL_FIP_FILENAME} ${INSTALL_LINUX_FILENAME} ${INSTALL_RECOVERY_FILENAME}"
|
||||
FILES="${INSTALL_ATF_FILENAME} ${INSTALL_FIP_FILENAME} ${INSTALL_LINUX_FILENAME}"
|
||||
if [ "${DUALBOOT}" != true ]; then
|
||||
FILES="${FILES} ${INSTALL_RECOVERY_FILENAME}"
|
||||
fi
|
||||
|
||||
for f in ${FILES}; do
|
||||
if [ ! -f ${f} ]; then
|
||||
echo "\033[31m[ERROR] Could not find file '${f}'\033[0m"
|
||||
|
|
@ -166,13 +179,13 @@ if [ ! -f ${INSTALL_ROOTFS_FILENAME} ]; then
|
|||
fi
|
||||
fi
|
||||
|
||||
[ "${ABORT}" = true ] && exit 1
|
||||
|
||||
# Enable bootcount mechanism by setting a bootlimit
|
||||
if [ "${BOOTCOUNT}" = true ]; then
|
||||
bootlimit_cmd="setenv bootlimit 3"
|
||||
fi
|
||||
|
||||
[ "${ABORT}" = true ] && exit 1
|
||||
|
||||
# parts names
|
||||
LINUX_NAME="linux"
|
||||
RECOVERY_NAME="recovery"
|
||||
|
|
@ -301,6 +314,11 @@ else
|
|||
uuu fb: ucmd saveenv
|
||||
fi
|
||||
|
||||
# Set the dboot_kernel_var to fitimage if Trustfence is enabled
|
||||
if [ "${TRUSTFENCE}" = "true" ] || echo "$INSTALL_UBOOT_FILENAME" | grep -q -e "signed"; then
|
||||
uuu fb: ucmd setenv dboot_kernel_var fitimage
|
||||
uuu fb: ucmd saveenv
|
||||
fi
|
||||
# Set the rootfstype if squashfs
|
||||
if [ "${SQUASHFS}" = true ]; then
|
||||
uuu fb: ucmd setenv rootfstype squashfs
|
||||
|
|
|
|||
|
|
@ -1,4 +1,4 @@
|
|||
# Copyright (C) 2022,2023 Digi International
|
||||
# Copyright (C) 2022-2024 Digi International
|
||||
|
||||
require u-boot-dey.inc
|
||||
LIC_FILES_CHKSUM = "file://Licenses/README;md5=5a7450c57ffe5ae63fd732446b988025"
|
||||
|
|
@ -9,30 +9,26 @@ DEPENDS += "python3-setuptools-native"
|
|||
SRCBRANCH = "v2021.10/maint"
|
||||
SRCREV = "${AUTOREV}"
|
||||
|
||||
UBOOT_FIT_CFG_FRAGMENTS = " \
|
||||
file://fit_legacy.cfg \
|
||||
file://fit_signature.cfg \
|
||||
SRC_URI += " \
|
||||
${@oe.utils.conditional('TRUSTFENCE_SIGN_FIT_STM', '1', 'file://fit_signature.cfg', '', d)} \
|
||||
"
|
||||
|
||||
SRC_URI += " \
|
||||
${@oe.utils.conditional('TRUSTFENCE_SIGN', '1', '${UBOOT_FIT_CFG_FRAGMENTS}', '', d)} \
|
||||
"
|
||||
# Install UBOOT_ENV_BINARY to datadir, so that kernel can use it
|
||||
# to include it into the FIT image.
|
||||
install_helper_bootscr() {
|
||||
if [ -f "${D}/boot/${UBOOT_ENV_BINARY}" ]; then
|
||||
# Install UBOOT_ENV_BINARY into datadir to share it with the kernel
|
||||
install -Dm 0644 ${D}/boot/${UBOOT_ENV_BINARY} ${D}${datadir}/${UBOOT_ENV_IMAGE}
|
||||
ln -sf ${UBOOT_ENV_IMAGE} ${D}${datadir}/${UBOOT_ENV_BINARY}
|
||||
install_helper_files() {
|
||||
# Install dtbs from UBOOT_DEVICETREE to datadir, so that kernel
|
||||
# can use it for signing, and kernel will deploy after signs it.
|
||||
if [ -n "${UBOOT_DEVICETREE}" ]; then
|
||||
for devicetree in ${UBOOT_DEVICETREE}; do
|
||||
install -Dm 0644 ${B}/${config}/arch/arm/dts/${devicetree}.dtb ${D}${datadir}/${devicetree}.dtb
|
||||
done
|
||||
else
|
||||
bbwarn "${D}/boot/${UBOOT_ENV_BINARY} not found"
|
||||
bbwarn "${UBOOT_DEVICETREE} not found"
|
||||
fi
|
||||
}
|
||||
|
||||
do_install:append() {
|
||||
# Copy boot script, so kernel can include it when creating the FIT image
|
||||
if [ "${TRUSTFENCE_FIT_IMG}" = "1" ] && [ -n "${UBOOT_ENV_BINARY}" ]; then
|
||||
install_helper_bootscr
|
||||
# Copy additional files, so kernel can use it when creating the FIT image
|
||||
if [ "${KERNEL_IMAGETYPE}" = "fitImage" ]; then
|
||||
install_helper_files
|
||||
fi
|
||||
}
|
||||
|
||||
|
|
|
|||
|
|
@ -0,0 +1,233 @@
|
|||
From: Roman Kopytin <Roman.Kopytin@kaspersky.com>
|
||||
Date: Wed, 8 Mar 2023 01:13:41 +0000
|
||||
Subject: [PATCH] tools: add fdt_add_pubkey
|
||||
|
||||
Having to use the -K option to mkimage to populate U-Boot's .dtb with the
|
||||
public key while signing the kernel FIT image is often a little
|
||||
awkward. In particular, when using a meta-build system such as
|
||||
bitbake/Yocto, having the tasks of the kernel and U-Boot recipes
|
||||
intertwined, modifying deployed artifacts and rebuilding U-Boot with
|
||||
an updated .dtb is quite cumbersome. Also, in some scenarios one may
|
||||
wish to build U-Boot complete with the public key(s) embedded in the
|
||||
.dtb without the corresponding private keys being present on the same
|
||||
build host.
|
||||
|
||||
So this adds a simple tool that allows one to disentangle the kernel
|
||||
and U-Boot builds, by simply copy-pasting just enough of the mkimage
|
||||
code to allow one to add a public key to a .dtb. When using mkimage,
|
||||
some of the information is taken from the .its used to build the
|
||||
kernel (algorithm and key name), so that of course needs to be
|
||||
supplied on the command line.
|
||||
|
||||
Signed-off-by: Roman Kopytin <Roman.Kopytin@kaspersky.com>
|
||||
Signed-off-by: Ivan Mikhaylov <fr0st61te@gmail.com>
|
||||
Signed-off-by: Jan Kiszka <jan.kiszka@siemens.com>
|
||||
Cc: Rasmus Villemoes <rasmus.villemoes@prevas.dk>
|
||||
|
||||
---
|
||||
tools/.gitignore | 1 +
|
||||
tools/Makefile | 3 +
|
||||
tools/fdt_add_pubkey.c | 138 +++++++++++++++++++++++++++++++++++++++++
|
||||
3 files changed, 142 insertions(+)
|
||||
create mode 100644 tools/fdt_add_pubkey.c
|
||||
|
||||
diff --git a/tools/.gitignore b/tools/.gitignore
|
||||
index a88453f64d..f312b760e4 100644
|
||||
--- a/tools/.gitignore
|
||||
+++ b/tools/.gitignore
|
||||
@@ -4,10 +4,11 @@
|
||||
/bmp_logo
|
||||
/common/
|
||||
/dumpimage
|
||||
/easylogo/easylogo
|
||||
/envcrc
|
||||
+/fdt_add_pubkey
|
||||
/fdtgrep
|
||||
/file2include
|
||||
/fit_check_sign
|
||||
/fit_info
|
||||
/gdb/gdbcont
|
||||
diff --git a/tools/Makefile b/tools/Makefile
|
||||
index 1763f44cac..ce7a49ff61 100644
|
||||
--- a/tools/Makefile
|
||||
+++ b/tools/Makefile
|
||||
@@ -71,10 +71,11 @@ HOSTCFLAGS_xway-swap-bytes.o := -pedantic
|
||||
hostprogs-y += mkenvimage
|
||||
mkenvimage-objs := mkenvimage.o os_support.o lib/crc32.o
|
||||
|
||||
hostprogs-y += dumpimage mkimage
|
||||
hostprogs-$(CONFIG_TOOLS_LIBCRYPTO) += fit_info fit_check_sign
|
||||
+hostprogs-$(CONFIG_TOOLS_LIBCRYPTO) += fdt_add_pubkey
|
||||
|
||||
hostprogs-$(CONFIG_CMD_BOOTEFI_SELFTEST) += file2include
|
||||
|
||||
FIT_OBJS-y := fit_common.o fit_image.o image-host.o boot/image-fit.o
|
||||
FIT_SIG_OBJS-$(CONFIG_TOOLS_LIBCRYPTO) := image-sig-host.o boot/image-fit-sig.o
|
||||
@@ -152,10 +153,11 @@ dumpimage-mkimage-objs := aisimage.o \
|
||||
|
||||
dumpimage-objs := $(dumpimage-mkimage-objs) dumpimage.o
|
||||
mkimage-objs := $(dumpimage-mkimage-objs) mkimage.o
|
||||
fit_info-objs := $(dumpimage-mkimage-objs) fit_info.o
|
||||
fit_check_sign-objs := $(dumpimage-mkimage-objs) fit_check_sign.o
|
||||
+fdt_add_pubkey-objs := $(dumpimage-mkimage-objs) fdt_add_pubkey.o
|
||||
file2include-objs := file2include.o
|
||||
|
||||
ifneq ($(CONFIG_MX23)$(CONFIG_MX28)$(CONFIG_TOOLS_LIBCRYPTO),)
|
||||
# Add CONFIG_MXS into host CFLAGS, so we can check whether or not register
|
||||
# the mxsimage support within tools/mxsimage.c .
|
||||
@@ -189,10 +191,11 @@ endif
|
||||
HOSTCFLAGS_fit_image.o += -DMKIMAGE_DTC=\"$(CONFIG_MKIMAGE_DTC_PATH)\"
|
||||
|
||||
HOSTLDLIBS_dumpimage := $(HOSTLDLIBS_mkimage)
|
||||
HOSTLDLIBS_fit_info := $(HOSTLDLIBS_mkimage)
|
||||
HOSTLDLIBS_fit_check_sign := $(HOSTLDLIBS_mkimage)
|
||||
+HOSTLDLIBS_fdt_add_pubkey := $(HOSTLDLIBS_mkimage)
|
||||
|
||||
hostprogs-$(CONFIG_EXYNOS5250) += mkexynosspl
|
||||
hostprogs-$(CONFIG_EXYNOS5420) += mkexynosspl
|
||||
HOSTCFLAGS_mkexynosspl.o := -pedantic
|
||||
|
||||
diff --git a/tools/fdt_add_pubkey.c b/tools/fdt_add_pubkey.c
|
||||
new file mode 100644
|
||||
index 0000000000..999f5a7e83
|
||||
--- /dev/null
|
||||
+++ b/tools/fdt_add_pubkey.c
|
||||
@@ -0,0 +1,138 @@
|
||||
+// SPDX-License-Identifier: GPL-2.0+
|
||||
+#include <image.h>
|
||||
+#include "fit_common.h"
|
||||
+
|
||||
+static const char *cmdname;
|
||||
+
|
||||
+static const char *algo_name = "sha1,rsa2048"; /* -a <algo> */
|
||||
+static const char *keydir = "."; /* -k <keydir> */
|
||||
+static const char *keyname = "key"; /* -n <keyname> */
|
||||
+static const char *require_keys; /* -r <conf|image> */
|
||||
+static const char *keydest; /* argv[n] */
|
||||
+
|
||||
+static void print_usage(const char *msg)
|
||||
+{
|
||||
+ fprintf(stderr, "Error: %s\n", msg);
|
||||
+ fprintf(stderr, "Usage: %s [-a <algo>] [-k <keydir>] [-n <keyname>] [-r <conf|image>]"
|
||||
+ " <fdt blob>\n", cmdname);
|
||||
+ fprintf(stderr, "Help information: %s [-h]\n", cmdname);
|
||||
+ exit(EXIT_FAILURE);
|
||||
+}
|
||||
+
|
||||
+static void print_help(void)
|
||||
+{
|
||||
+ fprintf(stderr, "Options:\n"
|
||||
+ "\t-a <algo> Cryptographic algorithm. Optional parameter, default value: sha1,rsa2048\n"
|
||||
+ "\t-k <keydir> Directory with public key. Optional parameter, default value: .\n"
|
||||
+ "\t-n <keyname> Public key name. Optional parameter, default value: key\n"
|
||||
+ "\t-r <conf|image> Required: If present this indicates that the key must be verified for the image / configuration to be considered valid.\n"
|
||||
+ "\t<fdt blob> FDT blob file for adding of the public key. Required parameter.\n");
|
||||
+ exit(EXIT_FAILURE);
|
||||
+}
|
||||
+
|
||||
+static void process_args(int argc, char *argv[])
|
||||
+{
|
||||
+ int opt;
|
||||
+
|
||||
+ while ((opt = getopt(argc, argv, "a:k:n:r:h")) != -1) {
|
||||
+ switch (opt) {
|
||||
+ case 'k':
|
||||
+ keydir = optarg;
|
||||
+ break;
|
||||
+ case 'a':
|
||||
+ algo_name = optarg;
|
||||
+ break;
|
||||
+ case 'n':
|
||||
+ keyname = optarg;
|
||||
+ break;
|
||||
+ case 'r':
|
||||
+ require_keys = optarg;
|
||||
+ break;
|
||||
+ case 'h':
|
||||
+ print_help();
|
||||
+ default:
|
||||
+ print_usage("Invalid option");
|
||||
+ }
|
||||
+ }
|
||||
+ /* The last parameter is expected to be the .dtb to add the public key to */
|
||||
+ if (optind < argc)
|
||||
+ keydest = argv[optind];
|
||||
+
|
||||
+ if (!keydest)
|
||||
+ print_usage("Missing dtb file to update");
|
||||
+}
|
||||
+
|
||||
+static void reset_info(struct image_sign_info *info)
|
||||
+{
|
||||
+ if (!info)
|
||||
+ fprintf(stderr, "Error: info is NULL in %s\n", __func__);
|
||||
+
|
||||
+ memset(info, 0, sizeof(struct image_sign_info));
|
||||
+
|
||||
+ info->keydir = keydir;
|
||||
+ info->keyname = keyname;
|
||||
+ info->name = algo_name;
|
||||
+ info->require_keys = require_keys;
|
||||
+ info->crypto = image_get_crypto_algo(algo_name);
|
||||
+
|
||||
+ if (!info->crypto) {
|
||||
+ fprintf(stderr, "Unsupported signature algorithm '%s'\n",
|
||||
+ algo_name);
|
||||
+ exit(EXIT_FAILURE);
|
||||
+ }
|
||||
+}
|
||||
+
|
||||
+static int add_pubkey(struct image_sign_info *info)
|
||||
+{
|
||||
+ int destfd = -1, ret;
|
||||
+ void *dest_blob = NULL;
|
||||
+ struct stat dest_sbuf;
|
||||
+ size_t size_inc = 0;
|
||||
+
|
||||
+ if (!info)
|
||||
+ fprintf(stderr, "Error: info is NULL in %s\n", __func__);
|
||||
+
|
||||
+ do {
|
||||
+ if (destfd >= 0) {
|
||||
+ munmap(dest_blob, dest_sbuf.st_size);
|
||||
+ close(destfd);
|
||||
+
|
||||
+ fprintf(stderr, ".dtb too small, increasing size by 1024 bytes\n");
|
||||
+ size_inc = 1024;
|
||||
+ }
|
||||
+
|
||||
+ destfd = mmap_fdt(cmdname, keydest, size_inc, &dest_blob,
|
||||
+ &dest_sbuf, false, false);
|
||||
+ if (destfd < 0)
|
||||
+ exit(EXIT_FAILURE);
|
||||
+
|
||||
+ ret = info->crypto->add_verify_data(info, dest_blob);
|
||||
+ if (ret == -ENOSPC)
|
||||
+ continue;
|
||||
+ else if (ret < 0)
|
||||
+ break;
|
||||
+ } while (ret == -ENOSPC);
|
||||
+
|
||||
+ return ret;
|
||||
+}
|
||||
+
|
||||
+int main(int argc, char *argv[])
|
||||
+{
|
||||
+ struct image_sign_info info;
|
||||
+ int ret;
|
||||
+
|
||||
+ cmdname = argv[0];
|
||||
+
|
||||
+ process_args(argc, argv);
|
||||
+ reset_info(&info);
|
||||
+ ret = add_pubkey(&info);
|
||||
+
|
||||
+ if (ret < 0) {
|
||||
+ fprintf(stderr, "%s: Cannot add public key to FIT blob: %s\n",
|
||||
+ cmdname, strerror(ret));
|
||||
+ exit(EXIT_FAILURE);
|
||||
+ }
|
||||
+
|
||||
+ exit(EXIT_SUCCESS);
|
||||
+}
|
||||
+
|
||||
|
|
@ -0,0 +1,48 @@
|
|||
From: Heinrich Schuchardt <heinrich.schuchardt@canonical.com>
|
||||
Date: Sat, 1 Apr 2023 08:09:34 +0200
|
||||
Subject: [PATCH] tools: avoid implicit fallthrough in fdt_add_pubkey
|
||||
|
||||
When building with -Wimplicit-fallthrough we get a warning
|
||||
|
||||
tools/fdt_add_pubkey.c:52:25: warning:
|
||||
this statement may fall through [-Wimplicit-fallthrough=]
|
||||
52 | print_help();
|
||||
|
|
||||
|
||||
Explicitly declare which functions don't return.
|
||||
|
||||
Fixes: 30238e99619c ("tools: add fdt_add_pubkey")
|
||||
Signed-off-by: Heinrich Schuchardt <heinrich.schuchardt@canonical.com>
|
||||
Reviewed-by: Simon Glass <sjg@chromium.org>
|
||||
|
||||
---
|
||||
tools/fdt_add_pubkey.c | 4 ++--
|
||||
1 file changed, 2 insertions(+), 2 deletions(-)
|
||||
|
||||
diff --git a/tools/fdt_add_pubkey.c b/tools/fdt_add_pubkey.c
|
||||
index 999f5a7e83..5582d7a8ef 100644
|
||||
--- a/tools/fdt_add_pubkey.c
|
||||
+++ b/tools/fdt_add_pubkey.c
|
||||
@@ -8,20 +8,20 @@ static const char *algo_name = "sha1,rsa2048"; /* -a <algo> */
|
||||
static const char *keydir = "."; /* -k <keydir> */
|
||||
static const char *keyname = "key"; /* -n <keyname> */
|
||||
static const char *require_keys; /* -r <conf|image> */
|
||||
static const char *keydest; /* argv[n] */
|
||||
|
||||
-static void print_usage(const char *msg)
|
||||
+static void __attribute__((__noreturn__)) print_usage(const char *msg)
|
||||
{
|
||||
fprintf(stderr, "Error: %s\n", msg);
|
||||
fprintf(stderr, "Usage: %s [-a <algo>] [-k <keydir>] [-n <keyname>] [-r <conf|image>]"
|
||||
" <fdt blob>\n", cmdname);
|
||||
fprintf(stderr, "Help information: %s [-h]\n", cmdname);
|
||||
exit(EXIT_FAILURE);
|
||||
}
|
||||
|
||||
-static void print_help(void)
|
||||
+static void __attribute__((__noreturn__)) print_help(void)
|
||||
{
|
||||
fprintf(stderr, "Options:\n"
|
||||
"\t-a <algo> Cryptographic algorithm. Optional parameter, default value: sha1,rsa2048\n"
|
||||
"\t-k <keydir> Directory with public key. Optional parameter, default value: .\n"
|
||||
"\t-n <keyname> Public key name. Optional parameter, default value: key\n"
|
||||
|
|
@ -0,0 +1,24 @@
|
|||
# Copyright (C) 2024 Digi International
|
||||
|
||||
FILESEXTRAPATHS:prepend := "${THISDIR}/${BPN}:"
|
||||
|
||||
# Backport from v2023.07
|
||||
SRC_URI:append = " \
|
||||
file://0001-tools-add-fdt_add_pubkey.patch \
|
||||
file://0002-tools-avoid-implicit-fallthrough-in-fdt_add_pubkey.patch \
|
||||
"
|
||||
|
||||
do_install:append () {
|
||||
install -d ${D}${bindir}
|
||||
|
||||
# fdt_add_pubkey
|
||||
if [ -f tools/fdt_add_pubkey ]; then
|
||||
install -m 0755 tools/fdt_add_pubkey ${D}${bindir}/uboot-fdt_add_pubkey
|
||||
ln -sf uboot-fdt_add_pubkey ${D}${bindir}/fdt_add_pubkey
|
||||
fi
|
||||
}
|
||||
|
||||
FILES:${PN}-mkimage += " \
|
||||
${bindir}/uboot-fdt_add_pubkey \
|
||||
${bindir}/fdt_add_pubkey \
|
||||
"
|
||||
|
|
@ -146,8 +146,8 @@ if [ "${SUBSYSTEM}" = "block" ]; then
|
|||
elif [ "${SUBSYSTEM}" = "mtd" ]; then
|
||||
# Before attaching, find out if partition already attached
|
||||
MTD_NUM="$(echo ${MTDN} | sed -ne 's,.*mtd\([0-9]\+\),\1,g;T;p')"
|
||||
for ubidev in /sys/devices/virtual/ubi/*; do
|
||||
echo "${ubidev}" | grep -qs '/sys/devices/virtual/ubi/\*' && continue
|
||||
for ubidev in /sys/class/ubi/*; do
|
||||
echo "${ubidev}" | grep -qs '/sys/class/ubi/\*' && continue
|
||||
mtd_att="$(cat ${ubidev}/mtd_num)"
|
||||
if [ "${mtd_att}" = "${MTD_NUM}" ]; then
|
||||
dev_number="$(echo ${ubidev} | sed -ne 's,.*ubi\([0-9]\+\),\1,g;T;p')"
|
||||
|
|
|
|||
|
|
@ -14,7 +14,7 @@
|
|||
# Type of SRK set (NXP or OEM)
|
||||
Source set = OEM
|
||||
# bitmask of the revoked SRKs
|
||||
Revocations = 0x0
|
||||
Revocations = %srk_rvk_mask%
|
||||
|
||||
[Authenticate Data]
|
||||
# Binary to be signed generated by mkimage
|
||||
|
|
|
|||
|
|
@ -14,7 +14,7 @@
|
|||
# Type of SRK set (NXP or OEM)
|
||||
Source set = OEM
|
||||
# bitmask of the revoked SRKs
|
||||
Revocations = 0x0
|
||||
Revocations = %srk_rvk_mask%
|
||||
|
||||
[Authenticate Data]
|
||||
# Binary to be signed generated by mkimage
|
||||
|
|
|
|||
|
|
@ -3,7 +3,7 @@
|
|||
#
|
||||
# trustfence-sign-artifact.sh
|
||||
#
|
||||
# Copyright (C) 2016-2022 by Digi International Inc.
|
||||
# Copyright (C) 2016-2024 by Digi International Inc.
|
||||
# All rights reserved.
|
||||
#
|
||||
# This program is free software; you can redistribute it and/or modify it
|
||||
|
|
@ -17,6 +17,7 @@
|
|||
# The following environment variables define the script behaviour:
|
||||
# CONFIG_SIGN_KEYS_PATH: (mandatory) path to the CST folder by NXP with keys generated.
|
||||
# CONFIG_KEY_INDEX: (optional) key index to use for signing. Default is 0.
|
||||
# SRK_REVOKE_MASK: (optional) bitmask of the revoked SRKs.
|
||||
# CONFIG_DEK_PATH: (optional) Path to keyfile. Define it to generate
|
||||
# encrypted images
|
||||
#
|
||||
|
|
@ -63,6 +64,10 @@ Supported platforms: ccimx6, ccimx6qp, ccimx6ul, ccimx8x, ccimx8mn, ccimx8mm
|
|||
EOF
|
||||
}
|
||||
|
||||
to_hex() {
|
||||
printf '0x%x' "${1}"
|
||||
}
|
||||
|
||||
if [ "${#}" != "2" ]; then
|
||||
usage
|
||||
exit 1
|
||||
|
|
@ -80,36 +85,38 @@ if [ -z "${CONFIG_SIGN_KEYS_PATH}" ]; then
|
|||
fi
|
||||
[ -d "${CONFIG_SIGN_KEYS_PATH}" ] || mkdir "${CONFIG_SIGN_KEYS_PATH}"
|
||||
|
||||
# Get RAM_START address
|
||||
if [ "${PLATFORM}" = "ccimx6" ] || [ "${PLATFORM}" = "ccimx6qp" ]; then
|
||||
CONFIG_FDT_LOADADDR="0x18000000"
|
||||
CONFIG_RAMDISK_LOADADDR="0x19000000"
|
||||
CONFIG_KERNEL_LOADADDR="0x12000000"
|
||||
CONFIG_CSF_SIZE="0x4000"
|
||||
CONFIG_SIGN_MODE="HAB"
|
||||
elif [ "${PLATFORM}" = "ccimx6ul" ]; then
|
||||
CONFIG_FDT_LOADADDR="0x83000000"
|
||||
CONFIG_RAMDISK_LOADADDR="0x83800000"
|
||||
CONFIG_KERNEL_LOADADDR="0x80800000"
|
||||
CONFIG_CSF_SIZE="0x4000"
|
||||
CONFIG_SIGN_MODE="HAB"
|
||||
elif [ "${PLATFORM}" = "ccimx8x" ]; then
|
||||
CONFIG_FDT_LOADADDR="0x82000000"
|
||||
CONFIG_RAMDISK_LOADADDR="0x82100000"
|
||||
CONFIG_KERNEL_LOADADDR="0x80280000"
|
||||
CONFIG_SIGN_MODE="AHAB"
|
||||
elif [ "${PLATFORM}" = "ccimx8mn" ] || [ "${PLATFORM}" = "ccimx8mm" ]; then
|
||||
CONFIG_FDT_LOADADDR="0x43000000"
|
||||
CONFIG_RAMDISK_LOADADDR="0x43800000"
|
||||
CONFIG_KERNEL_LOADADDR="0x40480000"
|
||||
CONFIG_CSF_SIZE="0x2000"
|
||||
CONFIG_SIGN_MODE="HAB"
|
||||
else
|
||||
while read -r pl kaddr raddr fdtaddr fitaddr mode csf srk; do
|
||||
AVAILABLE_PLATFORMS="${AVAILABLE_PLATFORMS:+${AVAILABLE_PLATFORMS} }${pl}"
|
||||
eval "${pl}_kernel_addr=\"${kaddr}\""
|
||||
eval "${pl}_ramdisk_addr=\"${raddr}\""
|
||||
eval "${pl}_fdt_addr=\"${fdtaddr}\""
|
||||
eval "${pl}_fit_addr=\"${fitaddr}\""
|
||||
eval "${pl}_mode=\"${mode}\""
|
||||
eval "${pl}_csf_size=\"${csf}\""
|
||||
eval "${pl}_srk_params=${srk}"
|
||||
done<<-_EOF_
|
||||
ccimx6 0x12000000 0x19000000 0x18000000 - HAB 0x4000 "-h 4 -d sha256"
|
||||
ccimx6qp 0x12000000 0x19000000 0x18000000 - HAB 0x4000 "-h 4 -d sha256"
|
||||
ccimx6ul 0x80800000 0x83800000 0x83000000 - HAB 0x4000 "-h 4 -d sha256"
|
||||
ccimx8mm 0x40480000 0x43800000 0x43000000 - HAB 0x2000 "-h 4 -d sha256"
|
||||
ccimx8mn 0x40480000 0x43800000 0x43000000 - HAB 0x2000 "-h 4 -d sha256"
|
||||
ccimx8x 0x80280000 0x82100000 0x82000000 - AHAB - "-a -d sha512 -s sha512"
|
||||
ccimx93 - - - 0x84000000 AHAB - "-a -d sha256 -s sha512"
|
||||
_EOF_
|
||||
|
||||
if ! echo "${AVAILABLE_PLATFORMS}" | grep -qs -F -w "${PLATFORM}"; then
|
||||
echo "Invalid platform: ${PLATFORM}"
|
||||
echo "Supported platforms: ccimx6, ccimx6ul, ccimx8x, ccimx8mn, ccimx8mm"
|
||||
echo "Supported platforms: ${AVAILABLE_PLATFORMS}"
|
||||
exit 1
|
||||
fi
|
||||
|
||||
eval "CONFIG_KERNEL_LOADADDR=\"\${${PLATFORM}_kernel_addr}\""
|
||||
eval "CONFIG_RAMDISK_LOADADDR=\"\${${PLATFORM}_ramdisk_addr}\""
|
||||
eval "CONFIG_FDT_LOADADDR=\"\${${PLATFORM}_fdt_addr}\""
|
||||
eval "CONFIG_FIT_LOADADDR=\"\${${PLATFORM}_fit_addr}\""
|
||||
eval "CONFIG_SIGN_MODE=\"\${${PLATFORM}_mode}\""
|
||||
eval "CONFIG_CSF_SIZE=\"\${${PLATFORM}_csf_size}\""
|
||||
|
||||
[ "${ARTIFACT_DTB}" = "y" ] && CONFIG_RAM_START="${CONFIG_FDT_LOADADDR}"
|
||||
[ "${ARTIFACT_INITRAMFS}" = "y" ] && CONFIG_RAM_START="${CONFIG_RAMDISK_LOADADDR}"
|
||||
[ "${ARTIFACT_KERNEL}" = "y" ] && CONFIG_RAM_START="${CONFIG_KERNEL_LOADADDR}"
|
||||
|
|
@ -120,6 +127,9 @@ fi
|
|||
# Rootfs is loaded to $initrd_addr, just like the ramdisk
|
||||
[ "${ARTIFACT_ROOTFS}" = "y" ] && CONFIG_RAM_START="${CONFIG_RAMDISK_LOADADDR}"
|
||||
|
||||
# For ccimx93 do not require image type (assume FIT image)
|
||||
[ "${PLATFORM}" = "ccimx93" ] && CONFIG_RAM_START="${CONFIG_FIT_LOADADDR}"
|
||||
|
||||
if [ -z "${CONFIG_RAM_START}" ]; then
|
||||
echo "Specify the type of image to process (-b, -i, -d, -l, -r, or -o)"
|
||||
exit 1
|
||||
|
|
@ -152,6 +162,12 @@ if [ "${CONFIG_SIGN_MODE}" = "HAB" ]; then
|
|||
DEK_BLOB_OFFSET="0x100"
|
||||
fi
|
||||
|
||||
[ -z "${SRK_REVOKE_MASK}" ] && SRK_REVOKE_MASK="0x0"
|
||||
if [ "$((SRK_REVOKE_MASK & 0x8))" != 0 ]; then
|
||||
echo "Key 3 cannot be revoked. Removed from mask."
|
||||
SRK_REVOKE_MASK="$((SRK_REVOKE_MASK - 8))"
|
||||
fi
|
||||
|
||||
# Function to generate a PKI tree (with lock dir protection)
|
||||
GENPKI_LOCK_DIR="${CONFIG_SIGN_KEYS_PATH}/.genpki.lock"
|
||||
gen_pki_tree() {
|
||||
|
|
@ -224,10 +240,6 @@ get_image_size()
|
|||
|
||||
SRK_TABLE="$(pwd)/SRK_table.bin"
|
||||
if [ "${CONFIG_SIGN_MODE}" = "HAB" ]; then
|
||||
HAB_VER="hab_ver 4"
|
||||
DIGEST="digest"
|
||||
DIGEST_ALGO="sha256"
|
||||
|
||||
# Other constants
|
||||
GAP_FILLER="0x00"
|
||||
|
||||
|
|
@ -302,12 +314,13 @@ elif [ "${CONFIG_SIGN_MODE}" = "AHAB" ]; then
|
|||
KERNEL_START_OFFSET="0x0"
|
||||
KERNEL_SIG_BLOCK_OFFSET="0x90"
|
||||
|
||||
HAB_VER="ahab"
|
||||
DIGEST="sign_digest"
|
||||
DIGEST_ALGO="sha512"
|
||||
|
||||
# Prepare the image container
|
||||
mkimage_imx8 -soc "QX" -rev "B0" -c -ap ${UIMAGE_PATH} a35 ${CONFIG_RAM_START} -out temp-mkimg
|
||||
if [ "${PLATFORM}" = "ccimx93" ]; then
|
||||
# Only FIT image supported for CC93
|
||||
mkimage_imx8 -soc IMX9 -c -ap ${UIMAGE_PATH} a55 ${CONFIG_FIT_LOADADDR} -out temp-mkimg
|
||||
else
|
||||
mkimage_imx8 -soc "QX" -rev "B0" -c -ap ${UIMAGE_PATH} a35 ${CONFIG_RAM_START} -out temp-mkimg
|
||||
fi
|
||||
KERNEL_NAME="$(readlink -e temp-mkimg)"
|
||||
|
||||
# Compute the layout: sizes and offsets.
|
||||
|
|
@ -322,6 +335,7 @@ elif [ "${CONFIG_SIGN_MODE}" = "AHAB" ]; then
|
|||
-e "s,%cert_img%,${SRK_CERT_KEY_IMG},g" \
|
||||
-e "s,%kernel-img%,${KERNEL_NAME},g" \
|
||||
-e "s,%key_index%,${CONFIG_KEY_INDEX},g" \
|
||||
-e "s,%srk_rvk_mask%,$(to_hex "${SRK_REVOKE_MASK}"),g" \
|
||||
-e "s,%container_offset%,${container_header_offset},g" \
|
||||
-e "s,%block_offset%,${signature_block_offset},g" \
|
||||
-e "s,%dek_path%,${CONFIG_DEK_PATH},g" \
|
||||
|
|
@ -332,14 +346,15 @@ elif [ "${CONFIG_SIGN_MODE}" = "AHAB" ]; then
|
|||
-e "s,%cert_img%,${SRK_CERT_KEY_IMG},g" \
|
||||
-e "s,%kernel-img%,${KERNEL_NAME},g" \
|
||||
-e "s,%key_index%,${CONFIG_KEY_INDEX},g" \
|
||||
-e "s,%srk_rvk_mask%,$(to_hex "${SRK_REVOKE_MASK}"),g" \
|
||||
-e "s,%container_offset%,${container_header_offset},g" \
|
||||
-e "s,%block_offset%,${signature_block_offset},g" \
|
||||
"${SCRIPT_PATH}/csf_templates/sign_ahab" > csf_descriptor
|
||||
fi
|
||||
fi
|
||||
|
||||
# Generate SRK tables
|
||||
srktool --${HAB_VER} --certs "${SRK_KEYS}" --table "${SRK_TABLE}" --efuses /dev/null --${DIGEST} "${DIGEST_ALGO}"
|
||||
eval "PDATA_SRKTOOL=\"\${${PLATFORM}_srk_params}\""
|
||||
srktool ${PDATA_SRKTOOL} --certs "${SRK_KEYS}" --table "${SRK_TABLE}" --efuses /dev/null
|
||||
if [ $? -ne 0 ]; then
|
||||
echo "[ERROR] Could not generate SRK tables"
|
||||
exit 1
|
||||
|
|
|
|||
|
|
@ -20,3 +20,4 @@ FILES:${PN}:append = " \
|
|||
"
|
||||
|
||||
RDEPENDS:${PN}:remove = "wireless-tools"
|
||||
RDEPENDS:${PN}:append = " firmware-murata-nxp"
|
||||
|
|
|
|||
|
|
@ -20,6 +20,9 @@ host_mlme=1 \
|
|||
drv_mode=${DRIVER_MODE} \
|
||||
drvdbg=${DRIVER_DEBUG} \
|
||||
sta_name=wlan \
|
||||
country_ie_ignore=1 \
|
||||
txpwrlimit_cfg=nxp/txpower_US.bin \
|
||||
init_hostcmd_cfg=nxp/rutxpower_US.bin \
|
||||
fw_name=nxp/sd_w61x_v1.bin.se\
|
||||
"
|
||||
|
||||
|
|
@ -33,6 +36,8 @@ if ! [ -e "/proc/device-tree/wireless/mac-address" ]; then
|
|||
fi
|
||||
|
||||
WLANADDR=$(hexdump -ve '1/1 "%02X" ":"' /proc/device-tree/wireless/mac-address 2>/dev/null | sed 's/:$//g')
|
||||
|
||||
iw reg set US && \
|
||||
modprobe mlan && \
|
||||
modprobe moal ${MOAL_PARAMS} mac_addr=${WLANADDR} && \
|
||||
[ -d "/sys/class/net/wlan0" ] && log "Wi-Fi activated" && exit 0
|
||||
|
|
|
|||
|
|
@ -5,7 +5,6 @@ LIC_FILES_CHKSUM = "file://COPYING;md5=6bc538ed5bd9a7fc9398086aedcd7e46"
|
|||
|
||||
inherit kernel
|
||||
inherit ${@oe.utils.conditional('DEY_SOC_VENDOR', 'NXP', 'fsl-kernel-localversion', '', d)}
|
||||
require ${@bb.utils.contains('DISTRO_FEATURES', 'virtualization', 'linux-virtualization.inc', '', d)}
|
||||
require ${@oe.utils.conditional('TRUSTFENCE_SIGN', '1', 'recipes-kernel/linux/linux-trustfence.inc', '', d)}
|
||||
|
||||
# CONFIG_KERNEL_LZO in defconfig
|
||||
|
|
@ -18,6 +17,7 @@ LINUX_GIT_URI ?= "${@oe.utils.conditional('DIGI_INTERNAL_GIT', '1', '${LINUX_URI
|
|||
SRC_URI = " \
|
||||
${LINUX_GIT_URI};branch=${SRCBRANCH} \
|
||||
${@oe.utils.conditional('KERNEL_DEFCONFIG', '', 'file://defconfig', '', d)} \
|
||||
${@bb.utils.contains('DISTRO_FEATURES', 'virtualization', 'file://docker_conf.cfg', '', d)} \
|
||||
"
|
||||
S = "${WORKDIR}/git"
|
||||
|
||||
|
|
@ -71,6 +71,20 @@ do_configure:append() {
|
|||
if [ -n "${@' '.join(find_cfgs(d))}" ]; then
|
||||
${S}/scripts/kconfig/merge_config.sh -m -O ${B} ${B}/.config ${@" ".join(find_cfgs(d))}
|
||||
fi
|
||||
# Apply ST-specific config fragments (ending in .config and stored in a different folder)
|
||||
if [ ! -z "${KERNEL_CONFIG_FRAGMENTS}" ]; then
|
||||
for f in ${KERNEL_CONFIG_FRAGMENTS}
|
||||
do
|
||||
# Check if the config fragment was copied into the WORKDIR from
|
||||
# the OE meta data
|
||||
if [ ! -e "$f" ]; then
|
||||
bb_warn "Could not find kernel config fragment $f"
|
||||
exit 1
|
||||
fi
|
||||
done
|
||||
# Now that all the fragments are located merge them.
|
||||
(${S}/scripts/kconfig/merge_config.sh -m -r -O ${B} ${B}/.config ${KERNEL_CONFIG_FRAGMENTS} 1>&2 )
|
||||
fi
|
||||
}
|
||||
|
||||
# Don't create custom folder for kernel artifacts
|
||||
|
|
|
|||
File diff suppressed because it is too large
Load Diff
|
|
@ -0,0 +1,21 @@
|
|||
From 5a9357f51ccd92dd11f188a14edf4b92ba1543ee Mon Sep 17 00:00:00 2001
|
||||
From: Mike Engel <Mike.Engel@digi.com>
|
||||
Date: Fri, 23 Feb 2024 10:12:23 +0100
|
||||
Subject: [PATCH 02/10] RT: add RT localversion
|
||||
|
||||
Signed-off-by: Mike Engel <Mike.Engel@digi.com>
|
||||
---
|
||||
localversion-rt | 1 +
|
||||
1 file changed, 1 insertion(+)
|
||||
create mode 100644 localversion-rt
|
||||
|
||||
diff --git a/localversion-rt b/localversion-rt
|
||||
new file mode 100644
|
||||
index 000000000000..6e44e540b927
|
||||
--- /dev/null
|
||||
+++ b/localversion-rt
|
||||
@@ -0,0 +1 @@
|
||||
+-rt12
|
||||
--
|
||||
2.34.1
|
||||
|
||||
File diff suppressed because it is too large
Load Diff
|
|
@ -0,0 +1,581 @@
|
|||
From e418c26b14e840304aa6e00ef847ec41ac0b995e Mon Sep 17 00:00:00 2001
|
||||
From: Mike Engel <Mike.Engel@digi.com>
|
||||
Date: Fri, 23 Feb 2024 12:28:42 +0100
|
||||
Subject: [PATCH 04/10] Documentation: add NXP RT support
|
||||
|
||||
Signed-off-by: Mike Engel <Mike.Engel@digi.com>
|
||||
---
|
||||
.../mailbox/generic-software-mbox.yaml | 65 +++
|
||||
.../devicetree/bindings/net/fsl,fec.yaml | 24 ++
|
||||
.../devicetree/bindings/tty/rpmsg_tty.yaml | 67 ++++
|
||||
Documentation/printk-ringbuffer.txt | 377 ++++++++++++++++++
|
||||
4 files changed, 533 insertions(+)
|
||||
create mode 100644 Documentation/devicetree/bindings/mailbox/generic-software-mbox.yaml
|
||||
create mode 100644 Documentation/devicetree/bindings/tty/rpmsg_tty.yaml
|
||||
create mode 100644 Documentation/printk-ringbuffer.txt
|
||||
|
||||
diff --git a/Documentation/devicetree/bindings/mailbox/generic-software-mbox.yaml b/Documentation/devicetree/bindings/mailbox/generic-software-mbox.yaml
|
||||
new file mode 100644
|
||||
index 000000000000..57c91ab2c80a
|
||||
--- /dev/null
|
||||
+++ b/Documentation/devicetree/bindings/mailbox/generic-software-mbox.yaml
|
||||
@@ -0,0 +1,65 @@
|
||||
+# SPDX-License-Identifier: (GPL-2.0-only OR BSD-2-Clause)
|
||||
+%YAML 1.2
|
||||
+---
|
||||
+$id: http://devicetree.org/schemas/mailbox/generic-software-mbox.yaml#
|
||||
+$schema: http://devicetree.org/meta-schemas/core.yaml#
|
||||
+
|
||||
+title: Generic Software Mailbox
|
||||
+
|
||||
+maintainers:
|
||||
+ - Hou Zhiqiang <Zhiqiang.Hou@nxp.com>
|
||||
+
|
||||
+description: |
|
||||
+ The Generic Software Mailbox is a virtual device, which uses unused
|
||||
+ interrupt line to notify remote side and shared memory to emulate
|
||||
+ device MMIO registers.
|
||||
+
|
||||
+properties:
|
||||
+ compatible:
|
||||
+ oneOf:
|
||||
+ - const: fsl,generic-software-mbox
|
||||
+ reg:
|
||||
+ maxItems: 1
|
||||
+
|
||||
+ "#mbox-cells":
|
||||
+ description: |
|
||||
+ <&phandle type channel ack>
|
||||
+ phandle : Label name of controller
|
||||
+ type : Channel type
|
||||
+ channel : Channel index
|
||||
+ ack : 0: Receiver doesn't trigger an ACK interrupt to sender after receive message
|
||||
+ 1: Receiver triggers an ACK interrupt to sender after receive message
|
||||
+
|
||||
+ This mailbox support 3 type of unidirectional channels, each type
|
||||
+ has 32 channels. Following types are supported:
|
||||
+ 0 - TX channel with 32bit transmit register
|
||||
+ 1 - RX channel with 32bit receive register and IRQ support
|
||||
+ 2 - RX doorbell channel.
|
||||
+ const: 2
|
||||
+
|
||||
+required:
|
||||
+ - compatible
|
||||
+ - reg
|
||||
+ - "#mbox-cells"
|
||||
+ - interrupts
|
||||
+ - interrupt-names
|
||||
+
|
||||
+additionalProperties: false
|
||||
+
|
||||
+examples:
|
||||
+ - |
|
||||
+ reserved-memory {
|
||||
+ gen-sw-mbox@b8500000 {
|
||||
+ no-map;
|
||||
+ reg = <0 0xb8500000 0 0x1000>;
|
||||
+ };
|
||||
+ };
|
||||
+
|
||||
+ generic-software-mailbox@b8500000 {
|
||||
+ compatible = "fsl,generic-software-mbox";
|
||||
+ reg = <0 0xb8500000 0 0x1000>;
|
||||
+ #mbox-cells = <3>;
|
||||
+ interrupts = <GIC_SPI 76 IRQ_TYPE_LEVEL_HIGH>,
|
||||
+ <GIC_SPI 77 IRQ_TYPE_LEVEL_HIGH>;
|
||||
+ interrupt-names = "irq", "remote_irq";
|
||||
+ };
|
||||
diff --git a/Documentation/devicetree/bindings/net/fsl,fec.yaml b/Documentation/devicetree/bindings/net/fsl,fec.yaml
|
||||
index 18f04d110d6e..f53b6ba17d5d 100644
|
||||
--- a/Documentation/devicetree/bindings/net/fsl,fec.yaml
|
||||
+++ b/Documentation/devicetree/bindings/net/fsl,fec.yaml
|
||||
@@ -176,6 +176,30 @@ properties:
|
||||
description:
|
||||
Register bits of stop mode control, the format is <&gpr req_gpr req_bit>.
|
||||
|
||||
+ fsl,rx-phy-delay-100-ns:
|
||||
+ $ref: /schemas/types.yaml#/definitions/uint32
|
||||
+ description:
|
||||
+ If present, should specify the delay (MAC-PHY) compensation
|
||||
+ in ns to be applied on packets timestamps on receive for 100 Mbps link speed
|
||||
+
|
||||
+ fsl,tx-phy-delay-100-ns:
|
||||
+ $ref: /schemas/types.yaml#/definitions/uint32
|
||||
+ description:
|
||||
+ If present, should specify the delay (MAC-PHY) compensation
|
||||
+ in ns to be applied on packets timestamps on transmit for 100 Mbps link speed
|
||||
+
|
||||
+ fsl,rx-phy-delay-1000-ns:
|
||||
+ $ref: /schemas/types.yaml#/definitions/uint32
|
||||
+ description:
|
||||
+ If present, should specify the delay (MAC-PHY) compensation
|
||||
+ in ns to be applied on packets timestamps on receive for 1 Gbps link speed
|
||||
+
|
||||
+ fsl,tx-phy-delay-1000-ns:
|
||||
+ $ref: /schemas/types.yaml#/definitions/uint32
|
||||
+ description:
|
||||
+ If present, should specify the delay (MAC-PHY) compensation
|
||||
+ in ns to be applied on packets timestamps on transmit for 1 Gbps link speed
|
||||
+
|
||||
mii-exclusive:
|
||||
$ref: /schemas/types.yaml#/definitions/flag
|
||||
description:
|
||||
diff --git a/Documentation/devicetree/bindings/tty/rpmsg_tty.yaml b/Documentation/devicetree/bindings/tty/rpmsg_tty.yaml
|
||||
new file mode 100644
|
||||
index 000000000000..9e11fadd16eb
|
||||
--- /dev/null
|
||||
+++ b/Documentation/devicetree/bindings/tty/rpmsg_tty.yaml
|
||||
@@ -0,0 +1,67 @@
|
||||
+# SPDX-License-Identifier: (GPL-2.0-only OR BSD-2-Clause)
|
||||
+%YAML 1.2
|
||||
+---
|
||||
+$id: http://devicetree.org/schemas/tty/rpmsg_tty.yaml#
|
||||
+$schema: http://devicetree.org/meta-schemas/core.yaml#
|
||||
+
|
||||
+title: rpmsg tty driver
|
||||
+
|
||||
+maintainers:
|
||||
+ - Biwen Li <biwen.li@nxp.com>
|
||||
+
|
||||
+properties:
|
||||
+ compatible:
|
||||
+ const: fsl,uart-rpbus
|
||||
+
|
||||
+ bus_id:
|
||||
+ items:
|
||||
+ - description: Used for imx srtm uart application protocol. Specify which real uart(LPUARTx/UARTx, x is instance number) will be used by a virtual tty(/dev/ttyRPMSGx), bus_id = 0xff when bus_id is not specified in dts and specified the flag(IMX_SRTM_UART_SUPPORT_MULTI_UART_MSG_FLAG).
|
||||
+ maxItems: 1
|
||||
+
|
||||
+ flags:
|
||||
+ items:
|
||||
+ - description: used for imx srtm uart application protocol(IMX_SRTM_UART_SUPPORT_MULTI_UART_MSG_FLAG: support multi uart message protocol; IMX_SRTM_UART_SPECIFY_PORT_NUM_MASK: whether specify destination uart id; IMX_SRTM_UART_PORT_NUM_MASK: which destination uart id will be used)
|
||||
+ maxItems: 1
|
||||
+
|
||||
+ status:
|
||||
+ maxItems: 1
|
||||
+
|
||||
+examples:
|
||||
+ - |
|
||||
+ #include <dt-bindings/rpmsg/imx_srtm.h>
|
||||
+
|
||||
+ uart-rpbus-0 {
|
||||
+ compatible = "fsl,uart-rpbus";
|
||||
+ bus_id = <3>; /* use uart3 */
|
||||
+ flags=<IMX_SRTM_UART_SUPPORT_MULTI_UART_MSG_FLAG>;
|
||||
+ status = "okay";
|
||||
+ }; /* /dev/ttyRPMSG0 on linux(running on acore) <--SRTM PROTOCOL--> srtm uart channel 0(endpoint on mcore) <---MULTI UART MSG PROTOCOL---> UART3(mcore is the owner) */
|
||||
+
|
||||
+ uart-rpbus-1 {
|
||||
+ compatible = "fsl,uart-rpbus";
|
||||
+ bus_id = <3>; /* use uart3 */
|
||||
+ flags=<IMX_SRTM_UART_SUPPORT_MULTI_UART_MSG_FLAG>;
|
||||
+ status = "okay";
|
||||
+ }; /* /dev/ttyRPMSG1 on linux(running on acore) <--SRTM PROTOCOL--> srtm uart channel 1(endpoint on mcore) <---MULTI UART MSG PROTOCOL---> UART3(mcore is the owner) */
|
||||
+
|
||||
+ uart-rpbus-2 {
|
||||
+ compatible = "fsl,uart-rpbus";
|
||||
+ bus_id = <2>; /* use uart2 */
|
||||
+ flags=<IMX_SRTM_UART_SUPPORT_MULTI_UART_MSG_FLAG>;
|
||||
+ status = "okay";
|
||||
+ }; /* /dev/ttyRPMSG2 on linux(running on acore) <--SRTM PROTOCOL--> srtm uart channel 2(endpoint on mcore) <---MULTI UART MSG PROTOCOL---> UART2(mcore is the owner) */
|
||||
+
|
||||
+ uart-rpbus-3 {
|
||||
+ compatible = "fsl,uart-rpbus";
|
||||
+ bus_id = <4>; /* use uart4 */
|
||||
+ flags=<IMX_SRTM_UART_SUPPORT_MULTI_UART_MSG_FLAG | IMX_SRTM_UART_SPECIFY_PORT_NUM_MASK | IMX_SRTM_UART_PORT_NUM_MASK(0x8)>;
|
||||
+ status = "okay";
|
||||
+ }; /* [/dev/ttyRPMSG3 on linux(running on acore) <--SRTM PROTOCOL--> srtm uart channel 3(endpoint on mcore) <---MULTI UART MSG PROTOCOL---> UART4(mcore is the owner), first board] <---MULTI UART MSG PROTOCOL--> [UARTx(mcore is the owner) <---MULTI UART MSG PROTOCOL---> srtm uart channel 8 <---SRTM PROTOCOL--> /dev/ttyRPMSG8 on linux(running on acore), second board ] */
|
||||
+
|
||||
+ uart-rpbus-4 {
|
||||
+ compatible = "fsl,uart-rpbus";
|
||||
+ bus_id = <5>; /* use uart5 */
|
||||
+ status = "okay";
|
||||
+ }; /* /dev/ttyRPMSG4 on linux(running on acore) <--SRTM PROTOCOL--> srtm uart channel 4(endpoint on mcore) <-----> UART5(mcore is the owner) <----> GPS device(The device have exclusive use of the UART5, other virtual tty cannot use UART5) */
|
||||
+
|
||||
+ /* Note: when nothing is specified(include compatible, bus_id, flags, status), it's a normal rpmsg tty. /dev/ttyRPMSG7(running on acore) <--RPMSG--> rpmsg endpoint(running on mcore) */
|
||||
diff --git a/Documentation/printk-ringbuffer.txt b/Documentation/printk-ringbuffer.txt
|
||||
new file mode 100644
|
||||
index 000000000000..6bde5dbd8545
|
||||
--- /dev/null
|
||||
+++ b/Documentation/printk-ringbuffer.txt
|
||||
@@ -0,0 +1,377 @@
|
||||
+struct printk_ringbuffer
|
||||
+------------------------
|
||||
+John Ogness <john.ogness@linutronix.de>
|
||||
+
|
||||
+Overview
|
||||
+~~~~~~~~
|
||||
+As the name suggests, this ring buffer was implemented specifically to serve
|
||||
+the needs of the printk() infrastructure. The ring buffer itself is not
|
||||
+specific to printk and could be used for other purposes. _However_, the
|
||||
+requirements and semantics of printk are rather unique. If you intend to use
|
||||
+this ring buffer for anything other than printk, you need to be very clear on
|
||||
+its features, behavior, and pitfalls.
|
||||
+
|
||||
+Features
|
||||
+^^^^^^^^
|
||||
+The printk ring buffer has the following features:
|
||||
+
|
||||
+- single global buffer
|
||||
+- resides in initialized data section (available at early boot)
|
||||
+- lockless readers
|
||||
+- supports multiple writers
|
||||
+- supports multiple non-consuming readers
|
||||
+- safe from any context (including NMI)
|
||||
+- groups bytes into variable length blocks (referenced by entries)
|
||||
+- entries tagged with sequence numbers
|
||||
+
|
||||
+Behavior
|
||||
+^^^^^^^^
|
||||
+Since the printk ring buffer readers are lockless, there exists no
|
||||
+synchronization between readers and writers. Basically writers are the tasks
|
||||
+in control and may overwrite any and all committed data at any time and from
|
||||
+any context. For this reason readers can miss entries if they are overwritten
|
||||
+before the reader was able to access the data. The reader API implementation
|
||||
+is such that reader access to entries is atomic, so there is no risk of
|
||||
+readers having to deal with partial or corrupt data. Also, entries are
|
||||
+tagged with sequence numbers so readers can recognize if entries were missed.
|
||||
+
|
||||
+Writing to the ring buffer consists of 2 steps. First a writer must reserve
|
||||
+an entry of desired size. After this step the writer has exclusive access
|
||||
+to the memory region. Once the data has been written to memory, it needs to
|
||||
+be committed to the ring buffer. After this step the entry has been inserted
|
||||
+into the ring buffer and assigned an appropriate sequence number.
|
||||
+
|
||||
+Once committed, a writer must no longer access the data directly. This is
|
||||
+because the data may have been overwritten and no longer exists. If a
|
||||
+writer must access the data, it should either keep a private copy before
|
||||
+committing the entry or use the reader API to gain access to the data.
|
||||
+
|
||||
+Because of how the data backend is implemented, entries that have been
|
||||
+reserved but not yet committed act as barriers, preventing future writers
|
||||
+from filling the ring buffer beyond the location of the reserved but not
|
||||
+yet committed entry region. For this reason it is *important* that writers
|
||||
+perform both reserve and commit as quickly as possible. Also, be aware that
|
||||
+preemption and local interrupts are disabled and writing to the ring buffer
|
||||
+is processor-reentrant locked during the reserve/commit window. Writers in
|
||||
+NMI contexts can still preempt any other writers, but as long as these
|
||||
+writers do not write a large amount of data with respect to the ring buffer
|
||||
+size, this should not become an issue.
|
||||
+
|
||||
+API
|
||||
+~~~
|
||||
+
|
||||
+Declaration
|
||||
+^^^^^^^^^^^
|
||||
+The printk ring buffer can be instantiated as a static structure:
|
||||
+
|
||||
+ /* declare a static struct printk_ringbuffer */
|
||||
+ #define DECLARE_STATIC_PRINTKRB(name, szbits, cpulockptr)
|
||||
+
|
||||
+The value of szbits specifies the size of the ring buffer in bits. The
|
||||
+cpulockptr field is a pointer to a prb_cpulock struct that is used to
|
||||
+perform processor-reentrant spin locking for the writers. It is specified
|
||||
+externally because it may be used for multiple ring buffers (or other
|
||||
+code) to synchronize writers without risk of deadlock.
|
||||
+
|
||||
+Here is an example of a declaration of a printk ring buffer specifying a
|
||||
+32KB (2^15) ring buffer:
|
||||
+
|
||||
+....
|
||||
+DECLARE_STATIC_PRINTKRB_CPULOCK(rb_cpulock);
|
||||
+DECLARE_STATIC_PRINTKRB(rb, 15, &rb_cpulock);
|
||||
+....
|
||||
+
|
||||
+If writers will be using multiple ring buffers and the ordering of that usage
|
||||
+is not clear, the same prb_cpulock should be used for both ring buffers.
|
||||
+
|
||||
+Writer API
|
||||
+^^^^^^^^^^
|
||||
+The writer API consists of 2 functions. The first is to reserve an entry in
|
||||
+the ring buffer, the second is to commit that data to the ring buffer. The
|
||||
+reserved entry information is stored within a provided `struct prb_handle`.
|
||||
+
|
||||
+ /* reserve an entry */
|
||||
+ char *prb_reserve(struct prb_handle *h, struct printk_ringbuffer *rb,
|
||||
+ unsigned int size);
|
||||
+
|
||||
+ /* commit a reserved entry to the ring buffer */
|
||||
+ void prb_commit(struct prb_handle *h);
|
||||
+
|
||||
+Here is an example of a function to write data to a ring buffer:
|
||||
+
|
||||
+....
|
||||
+int write_data(struct printk_ringbuffer *rb, char *data, int size)
|
||||
+{
|
||||
+ struct prb_handle h;
|
||||
+ char *buf;
|
||||
+
|
||||
+ buf = prb_reserve(&h, rb, size);
|
||||
+ if (!buf)
|
||||
+ return -1;
|
||||
+ memcpy(buf, data, size);
|
||||
+ prb_commit(&h);
|
||||
+
|
||||
+ return 0;
|
||||
+}
|
||||
+....
|
||||
+
|
||||
+Pitfalls
|
||||
+++++++++
|
||||
+Be aware that prb_reserve() can fail. A retry might be successful, but it
|
||||
+depends entirely on whether or not the next part of the ring buffer to
|
||||
+overwrite belongs to reserved but not yet committed entries of other writers.
|
||||
+Writers can use the prb_inc_lost() function to allow readers to notice that a
|
||||
+message was lost.
|
||||
+
|
||||
+Reader API
|
||||
+^^^^^^^^^^
|
||||
+The reader API utilizes a `struct prb_iterator` to track the reader's
|
||||
+position in the ring buffer.
|
||||
+
|
||||
+ /* declare a pre-initialized static iterator for a ring buffer */
|
||||
+ #define DECLARE_STATIC_PRINTKRB_ITER(name, rbaddr)
|
||||
+
|
||||
+ /* initialize iterator for a ring buffer (if static macro NOT used) */
|
||||
+ void prb_iter_init(struct prb_iterator *iter,
|
||||
+ struct printk_ringbuffer *rb, u64 *seq);
|
||||
+
|
||||
+ /* make a deep copy of an iterator */
|
||||
+ void prb_iter_copy(struct prb_iterator *dest,
|
||||
+ struct prb_iterator *src);
|
||||
+
|
||||
+ /* non-blocking, advance to next entry (and read the data) */
|
||||
+ int prb_iter_next(struct prb_iterator *iter, char *buf,
|
||||
+ int size, u64 *seq);
|
||||
+
|
||||
+ /* blocking, advance to next entry (and read the data) */
|
||||
+ int prb_iter_wait_next(struct prb_iterator *iter, char *buf,
|
||||
+ int size, u64 *seq);
|
||||
+
|
||||
+ /* position iterator at the entry seq */
|
||||
+ int prb_iter_seek(struct prb_iterator *iter, u64 seq);
|
||||
+
|
||||
+ /* read data at current position */
|
||||
+ int prb_iter_data(struct prb_iterator *iter, char *buf,
|
||||
+ int size, u64 *seq);
|
||||
+
|
||||
+Typically prb_iter_data() is not needed because the data can be retrieved
|
||||
+directly with prb_iter_next().
|
||||
+
|
||||
+Here is an example of a non-blocking function that will read all the data in
|
||||
+a ring buffer:
|
||||
+
|
||||
+....
|
||||
+void read_all_data(struct printk_ringbuffer *rb, char *buf, int size)
|
||||
+{
|
||||
+ struct prb_iterator iter;
|
||||
+ u64 prev_seq = 0;
|
||||
+ u64 seq;
|
||||
+ int ret;
|
||||
+
|
||||
+ prb_iter_init(&iter, rb, NULL);
|
||||
+
|
||||
+ for (;;) {
|
||||
+ ret = prb_iter_next(&iter, buf, size, &seq);
|
||||
+ if (ret > 0) {
|
||||
+ if (seq != ++prev_seq) {
|
||||
+ /* "seq - prev_seq" entries missed */
|
||||
+ prev_seq = seq;
|
||||
+ }
|
||||
+ /* process buf here */
|
||||
+ } else if (ret == 0) {
|
||||
+ /* hit the end, done */
|
||||
+ break;
|
||||
+ } else if (ret < 0) {
|
||||
+ /*
|
||||
+ * iterator is invalid, a writer overtook us, reset the
|
||||
+ * iterator and keep going, entries were missed
|
||||
+ */
|
||||
+ prb_iter_init(&iter, rb, NULL);
|
||||
+ }
|
||||
+ }
|
||||
+}
|
||||
+....
|
||||
+
|
||||
+Pitfalls
|
||||
+++++++++
|
||||
+The reader's iterator can become invalid at any time because the reader was
|
||||
+overtaken by a writer. Typically the reader should reset the iterator back
|
||||
+to the current oldest entry (which will be newer than the entry the reader
|
||||
+was at) and continue, noting the number of entries that were missed.
|
||||
+
|
||||
+Utility API
|
||||
+^^^^^^^^^^^
|
||||
+Several functions are available as convenience for external code.
|
||||
+
|
||||
+ /* query the size of the data buffer */
|
||||
+ int prb_buffer_size(struct printk_ringbuffer *rb);
|
||||
+
|
||||
+ /* skip a seq number to signify a lost record */
|
||||
+ void prb_inc_lost(struct printk_ringbuffer *rb);
|
||||
+
|
||||
+ /* processor-reentrant spin lock */
|
||||
+ void prb_lock(struct prb_cpulock *cpu_lock, unsigned int *cpu_store);
|
||||
+
|
||||
+ /* processor-reentrant spin unlock */
|
||||
+ void prb_lock(struct prb_cpulock *cpu_lock, unsigned int *cpu_store);
|
||||
+
|
||||
+Pitfalls
|
||||
+++++++++
|
||||
+Although the value returned by prb_buffer_size() does represent an absolute
|
||||
+upper bound, the amount of data that can be stored within the ring buffer
|
||||
+is actually less because of the additional storage space of a header for each
|
||||
+entry.
|
||||
+
|
||||
+The prb_lock() and prb_unlock() functions can be used to synchronize between
|
||||
+ring buffer writers and other external activities. The function of a
|
||||
+processor-reentrant spin lock is to disable preemption and local interrupts
|
||||
+and synchronize against other processors. It does *not* protect against
|
||||
+multiple contexts of a single processor, i.e NMI.
|
||||
+
|
||||
+Implementation
|
||||
+~~~~~~~~~~~~~~
|
||||
+This section describes several of the implementation concepts and details to
|
||||
+help developers better understand the code.
|
||||
+
|
||||
+Entries
|
||||
+^^^^^^^
|
||||
+All ring buffer data is stored within a single static byte array. The reason
|
||||
+for this is to ensure that any pointers to the data (past and present) will
|
||||
+always point to valid memory. This is important because the lockless readers
|
||||
+may be preempted for long periods of time and when they resume may be working
|
||||
+with expired pointers.
|
||||
+
|
||||
+Entries are identified by start index and size. (The start index plus size
|
||||
+is the start index of the next entry.) The start index is not simply an
|
||||
+offset into the byte array, but rather a logical position (lpos) that maps
|
||||
+directly to byte array offsets.
|
||||
+
|
||||
+For example, for a byte array of 1000, an entry may have have a start index
|
||||
+of 100. Another entry may have a start index of 1100. And yet another 2100.
|
||||
+All of these entry are pointing to the same memory region, but only the most
|
||||
+recent entry is valid. The other entries are pointing to valid memory, but
|
||||
+represent entries that have been overwritten.
|
||||
+
|
||||
+Note that due to overflowing, the most recent entry is not necessarily the one
|
||||
+with the highest lpos value. Indeed, the printk ring buffer initializes its
|
||||
+data such that an overflow happens relatively quickly in order to validate the
|
||||
+handling of this situation. The implementation assumes that an lpos (unsigned
|
||||
+long) will never completely wrap while a reader is preempted. If this were to
|
||||
+become an issue, the seq number (which never wraps) could be used to increase
|
||||
+the robustness of handling this situation.
|
||||
+
|
||||
+Buffer Wrapping
|
||||
+^^^^^^^^^^^^^^^
|
||||
+If an entry starts near the end of the byte array but would extend beyond it,
|
||||
+a special terminating entry (size = -1) is inserted into the byte array and
|
||||
+the real entry is placed at the beginning of the byte array. This can waste
|
||||
+space at the end of the byte array, but simplifies the implementation by
|
||||
+allowing writers to always work with contiguous buffers.
|
||||
+
|
||||
+Note that the size field is the first 4 bytes of the entry header. Also note
|
||||
+that calc_next() always ensures that there are at least 4 bytes left at the
|
||||
+end of the byte array to allow room for a terminating entry.
|
||||
+
|
||||
+Ring Buffer Pointers
|
||||
+^^^^^^^^^^^^^^^^^^^^
|
||||
+Three pointers (lpos values) are used to manage the ring buffer:
|
||||
+
|
||||
+ - _tail_: points to the oldest entry
|
||||
+ - _head_: points to where the next new committed entry will be
|
||||
+ - _reserve_: points to where the next new reserved entry will be
|
||||
+
|
||||
+These pointers always maintain a logical ordering:
|
||||
+
|
||||
+ tail <= head <= reserve
|
||||
+
|
||||
+The reserve pointer moves forward when a writer reserves a new entry. The
|
||||
+head pointer moves forward when a writer commits a new entry.
|
||||
+
|
||||
+The reserve pointer cannot overwrite the tail pointer in a wrap situation. In
|
||||
+such a situation, the tail pointer must be "pushed forward", thus
|
||||
+invalidating that oldest entry. Readers identify if they are accessing a
|
||||
+valid entry by ensuring their entry pointer is `>= tail && < head`.
|
||||
+
|
||||
+If the tail pointer is equal to the head pointer, it cannot be pushed and any
|
||||
+reserve operation will fail. The only resolution is for writers to commit
|
||||
+their reserved entries.
|
||||
+
|
||||
+Processor-Reentrant Locking
|
||||
+^^^^^^^^^^^^^^^^^^^^^^^^^^^
|
||||
+The purpose of the processor-reentrant locking is to limit the interruption
|
||||
+scenarios of writers to 2 contexts. This allows for a simplified
|
||||
+implementation where:
|
||||
+
|
||||
+- The reserve/commit window only exists on 1 processor at a time. A reserve
|
||||
+ can never fail due to uncommitted entries of other processors.
|
||||
+
|
||||
+- When committing entries, it is trivial to handle the situation when
|
||||
+ subsequent entries have already been committed, i.e. managing the head
|
||||
+ pointer.
|
||||
+
|
||||
+Performance
|
||||
+~~~~~~~~~~~
|
||||
+Some basic tests were performed on a quad Intel(R) Xeon(R) CPU E5-2697 v4 at
|
||||
+2.30GHz (36 cores / 72 threads). All tests involved writing a total of
|
||||
+32,000,000 records at an average of 33 bytes each. Each writer was pinned to
|
||||
+its own CPU and would write as fast as it could until a total of 32,000,000
|
||||
+records were written. All tests involved 2 readers that were both pinned
|
||||
+together to another CPU. Each reader would read as fast as it could and track
|
||||
+how many of the 32,000,000 records it could read. All tests used a ring buffer
|
||||
+of 16KB in size, which holds around 350 records (header + data for each
|
||||
+entry).
|
||||
+
|
||||
+The only difference between the tests is the number of writers (and thus also
|
||||
+the number of records per writer). As more writers are added, the time to
|
||||
+write a record increases. This is because data pointers, modified via cmpxchg,
|
||||
+and global data access in general become more contended.
|
||||
+
|
||||
+1 writer
|
||||
+^^^^^^^^
|
||||
+ runtime: 0m 18s
|
||||
+ reader1: 16219900/32000000 (50%) records
|
||||
+ reader2: 16141582/32000000 (50%) records
|
||||
+
|
||||
+2 writers
|
||||
+^^^^^^^^^
|
||||
+ runtime: 0m 32s
|
||||
+ reader1: 16327957/32000000 (51%) records
|
||||
+ reader2: 16313988/32000000 (50%) records
|
||||
+
|
||||
+4 writers
|
||||
+^^^^^^^^^
|
||||
+ runtime: 0m 42s
|
||||
+ reader1: 16421642/32000000 (51%) records
|
||||
+ reader2: 16417224/32000000 (51%) records
|
||||
+
|
||||
+8 writers
|
||||
+^^^^^^^^^
|
||||
+ runtime: 0m 43s
|
||||
+ reader1: 16418300/32000000 (51%) records
|
||||
+ reader2: 16432222/32000000 (51%) records
|
||||
+
|
||||
+16 writers
|
||||
+^^^^^^^^^^
|
||||
+ runtime: 0m 54s
|
||||
+ reader1: 16539189/32000000 (51%) records
|
||||
+ reader2: 16542711/32000000 (51%) records
|
||||
+
|
||||
+32 writers
|
||||
+^^^^^^^^^^
|
||||
+ runtime: 1m 13s
|
||||
+ reader1: 16731808/32000000 (52%) records
|
||||
+ reader2: 16735119/32000000 (52%) records
|
||||
+
|
||||
+Comments
|
||||
+^^^^^^^^
|
||||
+It is particularly interesting to compare/contrast the 1-writer and 32-writer
|
||||
+tests. Despite the writing of the 32,000,000 records taking over 4 times
|
||||
+longer, the readers (which perform no cmpxchg) were still unable to keep up.
|
||||
+This shows that the memory contention between the increasing number of CPUs
|
||||
+also has a dramatic effect on readers.
|
||||
+
|
||||
+It should also be noted that in all cases each reader was able to read >=50%
|
||||
+of the records. This means that a single reader would have been able to keep
|
||||
+up with the writer(s) in all cases, becoming slightly easier as more writers
|
||||
+are added. This was the purpose of pinning 2 readers to 1 CPU: to observe how
|
||||
+maximum reader performance changes.
|
||||
--
|
||||
2.34.1
|
||||
|
||||
File diff suppressed because it is too large
Load Diff
File diff suppressed because it is too large
Load Diff
File diff suppressed because it is too large
Load Diff
File diff suppressed because it is too large
Load Diff
|
|
@ -0,0 +1,28 @@
|
|||
From 98287df3a9d231a31fbc8b2e15be6174d6af1673 Mon Sep 17 00:00:00 2001
|
||||
From: Mike Engel <Mike.Engel@digi.com>
|
||||
Date: Mon, 26 Feb 2024 09:43:05 +0100
|
||||
Subject: [PATCH 09/10] init: add NXP RT support
|
||||
|
||||
Signed-off-by: Mike Engel <Mike.Engel@digi.com>
|
||||
---
|
||||
init/Kconfig | 4 ++++
|
||||
1 file changed, 4 insertions(+)
|
||||
|
||||
diff --git a/init/Kconfig b/init/Kconfig
|
||||
index de255842f5d0..d45312780b3a 100644
|
||||
--- a/init/Kconfig
|
||||
+++ b/init/Kconfig
|
||||
@@ -1582,6 +1582,10 @@ config PRINTK
|
||||
very difficult to diagnose system problems, saying N here is
|
||||
strongly discouraged.
|
||||
|
||||
+config HAVE_ATOMIC_CONSOLE
|
||||
+ bool
|
||||
+ default n
|
||||
+
|
||||
config BUG
|
||||
bool "BUG() support" if EXPERT
|
||||
default y
|
||||
--
|
||||
2.34.1
|
||||
|
||||
|
|
@ -0,0 +1,31 @@
|
|||
..........................................................................
|
||||
. WARNING
|
||||
.
|
||||
. This file is a kernel configuration fragment, and not a full kernel
|
||||
. configuration file. The final kernel configuration is made up of
|
||||
. an assembly of processed fragments, each of which is designed to
|
||||
. capture a specific part of the final configuration (e.g. platform
|
||||
. configuration, feature configuration, and board specific hardware
|
||||
. configuration). For more information on kernel configuration, please
|
||||
. consult the product documentation.
|
||||
.
|
||||
..........................................................................
|
||||
CONFIG_PREEMPT_RT=y
|
||||
CONFIG_EXPERT=y
|
||||
|
||||
# disable SCHED_MC
|
||||
# CONFIG_MCPM is not set
|
||||
|
||||
# Disable CPUFREQ and CPUIDLE
|
||||
# CONFIG_CPU_FREQ is not set
|
||||
# CONFIG_CPU_IDLE is not set
|
||||
|
||||
# CONFIG_NUMA_BALANCING in not set
|
||||
# CONFIG_TRANSPARENT_HUGEPAGE is not set
|
||||
# CONFIG_EFI_DISABLE_RUNTIME is not set
|
||||
CONFIG_MEDIA_SUPPORT_FILTER=y
|
||||
CONFIG_FRAMEBUFFER_CONSOLE=y
|
||||
# CONFIG_LEDS_TRIGGER_CPU is not set
|
||||
# CONFIG_DEBUG_KERNEL is not set
|
||||
# CONFIG_HID_MULTITOUCH is not set
|
||||
CONFIG_FRAMEBUFFER_CONSOLE=y
|
||||
|
|
@ -0,0 +1,26 @@
|
|||
From 63e709173a20b85b473bbf4832f4e909692fd361 Mon Sep 17 00:00:00 2001
|
||||
From: Lionel VITTE <lionel.vitte@st.com>
|
||||
Date: Wed, 8 Feb 2023 09:54:24 +0100
|
||||
Subject: [PATCH 23/28] 5.15-stm32mp-rt-49-r1 CLOCK
|
||||
|
||||
Signed-off-by: Lionel VITTE <lionel.vitte@st.com>
|
||||
---
|
||||
drivers/clk/stm32/clk-stm32mp13.c | 2 +-
|
||||
1 file changed, 1 insertion(+), 1 deletion(-)
|
||||
|
||||
diff --git a/drivers/clk/stm32/clk-stm32mp13.c b/drivers/clk/stm32/clk-stm32mp13.c
|
||||
index 15ee05df8..2f7a823bf 100644
|
||||
--- a/drivers/clk/stm32/clk-stm32mp13.c
|
||||
+++ b/drivers/clk/stm32/clk-stm32mp13.c
|
||||
@@ -840,7 +840,7 @@ static CLK_STM32_GATE(sai1, "pclk2", 0, GATE_SAI1);
|
||||
static CLK_STM32_GATE(sai2, "pclk2", 0, GATE_SAI2);
|
||||
static CLK_STM32_GATE(spi1, "pclk2", 0, GATE_SPI1);
|
||||
|
||||
-static CLK_STM32_GATE(syscfg, "pclk3", 0, GATE_SYSCFG);
|
||||
+static CLK_STM32_GATE(syscfg, "pclk3", CLK_IS_CRITICAL, GATE_SYSCFG);
|
||||
static CLK_STM32_GATE(vref, "pclk3", 0, GATE_VREF);
|
||||
static CLK_STM32_GATE(dts, "pclk3", 0, GATE_DTS);
|
||||
static CLK_STM32_GATE(pmbctrl, "pclk3", 0, GATE_PMBCTRL);
|
||||
--
|
||||
2.34.1
|
||||
|
||||
|
|
@ -0,0 +1,131 @@
|
|||
From 5a55de398d12848f13f7df59fb2f1853b7dd9ee8 Mon Sep 17 00:00:00 2001
|
||||
From: Lionel VITTE <lionel.vitte@st.com>
|
||||
Date: Wed, 8 Feb 2023 09:56:07 +0100
|
||||
Subject: [PATCH 24/28] 5.15-stm32mp-rt-49-r1 DMA
|
||||
|
||||
Signed-off-by: Lionel VITTE <lionel.vitte@st.com>
|
||||
---
|
||||
drivers/dma/stm32-dma.c | 35 +++++++++++++++++++++++++----------
|
||||
drivers/dma/stm32-mdma.c | 4 ++++
|
||||
2 files changed, 29 insertions(+), 10 deletions(-)
|
||||
|
||||
diff --git a/drivers/dma/stm32-dma.c b/drivers/dma/stm32-dma.c
|
||||
index 7c6078c6c..128edfb4f 100644
|
||||
--- a/drivers/dma/stm32-dma.c
|
||||
+++ b/drivers/dma/stm32-dma.c
|
||||
@@ -238,6 +238,7 @@ struct stm32_dma_chan {
|
||||
u32 residue_after_drain;
|
||||
struct workqueue_struct *mdma_wq;
|
||||
struct work_struct mdma_work;
|
||||
+ struct completion mdma_drain_completion;
|
||||
};
|
||||
|
||||
struct stm32_dma_device {
|
||||
@@ -570,8 +571,9 @@ static u32 stm32_dma_get_remaining_bytes(struct stm32_dma_chan *chan)
|
||||
return ndtr << width;
|
||||
}
|
||||
|
||||
-static int stm32_dma_mdma_drain(struct stm32_dma_chan *chan)
|
||||
+static void stm32_dma_mdma_drain_worker(struct work_struct *work)
|
||||
{
|
||||
+ struct stm32_dma_chan *chan = container_of(work, struct stm32_dma_chan, mdma_work);
|
||||
struct stm32_dma_mdma *mchan = &chan->mchan;
|
||||
struct stm32_dma_sg_req *sg_req;
|
||||
struct dma_device *ddev = mchan->chan->device;
|
||||
@@ -583,14 +585,12 @@ static int stm32_dma_mdma_drain(struct stm32_dma_chan *chan)
|
||||
int ret;
|
||||
unsigned long flags;
|
||||
|
||||
- flush_workqueue(chan->mdma_wq);
|
||||
-
|
||||
/* DMA/MDMA chain: drain remaining data in SRAM */
|
||||
|
||||
/* Get the residue on MDMA side */
|
||||
status = dmaengine_tx_status(mchan->chan, mchan->chan->cookie, &state);
|
||||
if (status == DMA_COMPLETE)
|
||||
- return status;
|
||||
+ goto mdma_complete;
|
||||
|
||||
mdma_residue = state.residue;
|
||||
sg_req = &chan->desc->sg_req[chan->next_sg - 1];
|
||||
@@ -623,24 +623,25 @@ static int stm32_dma_mdma_drain(struct stm32_dma_chan *chan)
|
||||
desc = ddev->device_prep_dma_memcpy(mchan->chan, dst_buf, src_buf, dma_to_write,
|
||||
DMA_PREP_INTERRUPT);
|
||||
if (!desc)
|
||||
- return -EINVAL;
|
||||
+ return;
|
||||
|
||||
ret = dma_submit_error(dmaengine_submit(desc));
|
||||
if (ret < 0)
|
||||
- return ret;
|
||||
+ return;
|
||||
|
||||
status = dma_wait_for_async_tx(desc);
|
||||
if (status != DMA_COMPLETE) {
|
||||
dev_err(chan2dev(chan), "%s dma_wait_for_async_tx error\n", __func__);
|
||||
dmaengine_terminate_async(mchan->chan);
|
||||
- return -EBUSY;
|
||||
+ return;
|
||||
}
|
||||
|
||||
/* We need to store residue for tx_status() */
|
||||
chan->residue_after_drain = len - (mdma_wrote + dma_to_write);
|
||||
}
|
||||
|
||||
- return 0;
|
||||
+mdma_complete:
|
||||
+ complete(&chan->mdma_drain_completion);
|
||||
}
|
||||
|
||||
static void stm32_dma_synchronize(struct dma_chan *c)
|
||||
@@ -648,9 +649,22 @@ static void stm32_dma_synchronize(struct dma_chan *c)
|
||||
struct stm32_dma_chan *chan = to_stm32_dma_chan(c);
|
||||
struct stm32_dma_mdma *mchan = &chan->mchan;
|
||||
|
||||
- if (chan->desc && chan->use_mdma && mchan->dir == DMA_DEV_TO_MEM)
|
||||
- if (stm32_dma_mdma_drain(chan))
|
||||
+ if (chan->desc && chan->use_mdma && mchan->dir == DMA_DEV_TO_MEM) {
|
||||
+ unsigned long ms = 5000 + 100; /* dma_sync_wait_timeout + extra 100ms */
|
||||
+
|
||||
+ reinit_completion(&chan->mdma_drain_completion);
|
||||
+
|
||||
+ flush_workqueue(chan->mdma_wq);
|
||||
+ INIT_WORK(&chan->mdma_work, stm32_dma_mdma_drain_worker);
|
||||
+
|
||||
+ if (!queue_work(chan->mdma_wq, &chan->mdma_work))
|
||||
+ dev_warn(chan2dev(chan), "Work already queued\n");
|
||||
+
|
||||
+ ms = wait_for_completion_timeout(&chan->mdma_drain_completion,
|
||||
+ msecs_to_jiffies(ms));
|
||||
+ if (ms == 0)
|
||||
dev_err(chan2dev(chan), "%s: can't drain DMA\n", __func__);
|
||||
+ }
|
||||
|
||||
if (chan->use_mdma)
|
||||
dmaengine_synchronize(mchan->chan);
|
||||
@@ -2338,6 +2352,7 @@ static int stm32_dma_probe(struct platform_device *pdev)
|
||||
dev_warn(&pdev->dev,
|
||||
"can't alloc MDMA workqueue for %s\n", name);
|
||||
}
|
||||
+ init_completion(&chan->mdma_drain_completion);
|
||||
}
|
||||
}
|
||||
}
|
||||
diff --git a/drivers/dma/stm32-mdma.c b/drivers/dma/stm32-mdma.c
|
||||
index 133534663..a08c94638 100644
|
||||
--- a/drivers/dma/stm32-mdma.c
|
||||
+++ b/drivers/dma/stm32-mdma.c
|
||||
@@ -1270,6 +1270,10 @@ static int stm32_mdma_resume(struct dma_chan *c)
|
||||
unsigned long flags;
|
||||
u32 status, reg;
|
||||
|
||||
+ /* Transfer can be terminated */
|
||||
+ if (!chan->desc || (stm32_mdma_read(dmadev, STM32_MDMA_CCR(chan->id)) & STM32_MDMA_CCR_EN))
|
||||
+ return -EPERM;
|
||||
+
|
||||
hwdesc = chan->desc->node[chan->curr_hwdesc].hwdesc;
|
||||
|
||||
spin_lock_irqsave(&chan->vchan.lock, flags);
|
||||
--
|
||||
2.34.1
|
||||
|
||||
|
|
@ -0,0 +1,27 @@
|
|||
From be5ec688053e6d136bc8ea54ed1e93d523b24580 Mon Sep 17 00:00:00 2001
|
||||
From: Lionel VITTE <lionel.vitte@st.com>
|
||||
Date: Wed, 8 Feb 2023 09:56:45 +0100
|
||||
Subject: [PATCH 25/28] 5.15-stm32mp-rt-49-r1 MFD
|
||||
|
||||
Signed-off-by: Lionel VITTE <lionel.vitte@st.com>
|
||||
---
|
||||
drivers/mfd/syscon.c | 3 +++
|
||||
1 file changed, 3 insertions(+)
|
||||
|
||||
diff --git a/drivers/mfd/syscon.c b/drivers/mfd/syscon.c
|
||||
index 191fdb87c..24530dfe5 100644
|
||||
--- a/drivers/mfd/syscon.c
|
||||
+++ b/drivers/mfd/syscon.c
|
||||
@@ -38,6 +38,9 @@ static const struct regmap_config syscon_regmap_config = {
|
||||
.reg_bits = 32,
|
||||
.val_bits = 32,
|
||||
.reg_stride = 4,
|
||||
+#ifdef CONFIG_PREEMPT_RT
|
||||
+ .use_raw_spinlock = true,
|
||||
+#endif
|
||||
};
|
||||
|
||||
static struct syscon *of_syscon_register(struct device_node *np, bool check_clk)
|
||||
--
|
||||
2.34.1
|
||||
|
||||
|
|
@ -0,0 +1,64 @@
|
|||
From 1f4b70cda804c4f3771902254a2614d87a1d366c Mon Sep 17 00:00:00 2001
|
||||
From: Lionel VITTE <lionel.vitte@st.com>
|
||||
Date: Wed, 8 Feb 2023 09:57:06 +0100
|
||||
Subject: [PATCH 26/28] 5.15-stm32mp-rt-49-r1 NET-TTY
|
||||
|
||||
Signed-off-by: Lionel VITTE <lionel.vitte@st.com>
|
||||
---
|
||||
drivers/tty/serial/stm32-usart.c | 32 +++++++++++---------------------
|
||||
1 file changed, 11 insertions(+), 21 deletions(-)
|
||||
|
||||
diff --git a/drivers/tty/serial/stm32-usart.c b/drivers/tty/serial/stm32-usart.c
|
||||
index 4d7a31664..0cd8e9672 100644
|
||||
--- a/drivers/tty/serial/stm32-usart.c
|
||||
+++ b/drivers/tty/serial/stm32-usart.c
|
||||
@@ -772,26 +772,16 @@ static irqreturn_t stm32_usart_interrupt(int irq, void *ptr)
|
||||
}
|
||||
|
||||
if ((sr & USART_SR_RTOF) && !(stm32_port->throttled) &&
|
||||
- stm32_usart_rx_dma_started(stm32_port))
|
||||
- return IRQ_WAKE_THREAD;
|
||||
- else
|
||||
- return IRQ_HANDLED;
|
||||
-}
|
||||
-
|
||||
-static irqreturn_t stm32_usart_threaded_interrupt(int irq, void *ptr)
|
||||
-{
|
||||
- struct uart_port *port = ptr;
|
||||
- struct tty_port *tport = &port->state->port;
|
||||
- unsigned int size;
|
||||
- unsigned long flags;
|
||||
-
|
||||
- /* Receiver timeout irq for DMA RX */
|
||||
- spin_lock_irqsave(&port->lock, flags);
|
||||
- size = stm32_usart_receive_chars(port, false);
|
||||
- uart_unlock_and_check_sysrq_irqrestore(port, flags);
|
||||
- if (size)
|
||||
- tty_flip_buffer_push(tport);
|
||||
+ stm32_usart_rx_dma_started(stm32_port)) {
|
||||
+ unsigned long flags;
|
||||
|
||||
+ spin_lock_irqsave(&port->lock, flags);
|
||||
+ /* Receiver timeout irq for DMA RX */
|
||||
+ size = stm32_usart_receive_chars(port, false);
|
||||
+ uart_unlock_and_check_sysrq_irqrestore(port, flags);
|
||||
+ if (size)
|
||||
+ tty_flip_buffer_push(tport);
|
||||
+ }
|
||||
return IRQ_HANDLED;
|
||||
}
|
||||
|
||||
@@ -980,8 +970,8 @@ static int stm32_usart_startup(struct uart_port *port)
|
||||
u32 val;
|
||||
int ret;
|
||||
|
||||
- ret = request_threaded_irq(port->irq, stm32_usart_interrupt,
|
||||
- stm32_usart_threaded_interrupt,
|
||||
+ ret = request_threaded_irq(port->irq, NULL,
|
||||
+ stm32_usart_interrupt,
|
||||
IRQF_ONESHOT | IRQF_NO_SUSPEND,
|
||||
name, port);
|
||||
if (ret)
|
||||
--
|
||||
2.34.1
|
||||
|
||||
|
|
@ -0,0 +1,25 @@
|
|||
From e1bd8bc5502e661be4feaadfca1889da1d48cd73 Mon Sep 17 00:00:00 2001
|
||||
From: Lionel VITTE <lionel.vitte@st.com>
|
||||
Date: Wed, 8 Feb 2023 09:57:43 +0100
|
||||
Subject: [PATCH 27/28] 5.15-stm32mp-rt-49-r1 DEVICETREE
|
||||
|
||||
Signed-off-by: Lionel VITTE <lionel.vitte@st.com>
|
||||
---
|
||||
arch/arm/boot/dts/stm32mp131.dtsi | 1 -
|
||||
1 file changed, 1 deletion(-)
|
||||
|
||||
diff --git a/arch/arm/boot/dts/stm32mp131.dtsi b/arch/arm/boot/dts/stm32mp131.dtsi
|
||||
index 8121ddc97..3fc06961a 100644
|
||||
--- a/arch/arm/boot/dts/stm32mp131.dtsi
|
||||
+++ b/arch/arm/boot/dts/stm32mp131.dtsi
|
||||
@@ -1241,7 +1241,6 @@ exti-interrupt-map {
|
||||
syscfg: syscon@50020000 {
|
||||
compatible = "st,stm32mp157-syscfg", "syscon";
|
||||
reg = <0x50020000 0x400>;
|
||||
- clocks = <&rcc SYSCFG>;
|
||||
};
|
||||
|
||||
lptimer2: timer@50021000 {
|
||||
--
|
||||
2.34.1
|
||||
|
||||
|
|
@ -0,0 +1,82 @@
|
|||
From 05ea3c26ccad3359d94dbe3c7ba758c2ba2f7dd9 Mon Sep 17 00:00:00 2001
|
||||
From: Lionel VITTE <lionel.vitte@st.com>
|
||||
Date: Wed, 8 Feb 2023 09:59:08 +0100
|
||||
Subject: [PATCH 28/28] 5.15-stm32mp-rt-49-r1 CONFIG
|
||||
|
||||
Signed-off-by: Lionel VITTE <lionel.vitte@st.com>
|
||||
---
|
||||
.../configs/fragment-07-rt-sysvinit.config | 12 +++++++
|
||||
arch/arm/configs/fragment-07-rt.config | 32 +++++++++++++++++++
|
||||
arch/arm/configs/fragment-08-rt-mp13.config | 2 ++
|
||||
3 files changed, 46 insertions(+)
|
||||
create mode 100644 arch/arm/configs/fragment-07-rt-sysvinit.config
|
||||
create mode 100644 arch/arm/configs/fragment-07-rt.config
|
||||
create mode 100644 arch/arm/configs/fragment-08-rt-mp13.config
|
||||
|
||||
diff --git a/arch/arm/configs/fragment-07-rt-sysvinit.config b/arch/arm/configs/fragment-07-rt-sysvinit.config
|
||||
new file mode 100644
|
||||
index 000000000..49a4baf60
|
||||
--- /dev/null
|
||||
+++ b/arch/arm/configs/fragment-07-rt-sysvinit.config
|
||||
@@ -0,0 +1,12 @@
|
||||
+CONFIG_CGROUPS=y
|
||||
+# CONFIG_CGROUP_SCHED is not set
|
||||
+# CONFIG_CGROUP_PIDS is not set
|
||||
+# CONFIG_CGROUP_RDMA is not set
|
||||
+# CONFIG_CGROUP_FREEZER is not set
|
||||
+# CONFIG_CGROUP_DEVICE is not set
|
||||
+# CONFIG_CGROUP_CPUACCT is not set
|
||||
+# CONFIG_CGROUP_PERF is not set
|
||||
+# CONFIG_CGROUP_DEBUG is not set
|
||||
+# CONFIG_CGROUP_NET_PRIO is not set
|
||||
+# CONFIG_CGROUP_NET_CLASSID is not set
|
||||
+
|
||||
diff --git a/arch/arm/configs/fragment-07-rt.config b/arch/arm/configs/fragment-07-rt.config
|
||||
new file mode 100644
|
||||
index 000000000..98bb8735f
|
||||
--- /dev/null
|
||||
+++ b/arch/arm/configs/fragment-07-rt.config
|
||||
@@ -0,0 +1,32 @@
|
||||
+CONFIG_PREEMPT_RT=y
|
||||
+
|
||||
+# disable SCHED_MC
|
||||
+# CONFIG_MCPM is not set
|
||||
+
|
||||
+# Disable CPUFREQ and CPUIDLE
|
||||
+# CONFIG_CPU_FREQ is not set
|
||||
+# CONFIG_CPU_IDLE is not set
|
||||
+
|
||||
+# Force to have HIGH_RES_TIMERS
|
||||
+CONFIG_HIGH_RES_TIMERS=y
|
||||
+
|
||||
+# force do not go to sleep
|
||||
+# For multiple core, you should set the specific boot options
|
||||
+# for isolate the core and render it tickless: "isolcpus=2,3 nohz_full=2,3"
|
||||
+# Warning: to active only if SMP are present
|
||||
+# CONFIG_HZ_PERIODIC=y
|
||||
+
|
||||
+# to Enable ftrace, you need to enable the following configuraiton:
|
||||
+# CONFIG_FTRACE=y
|
||||
+# CONFIG_IRQSOFF_TRACER=y
|
||||
+# CONFIG_PREEMPT_TRACER=y
|
||||
+# CONFIG_SCHED_TRACER=y
|
||||
+# CONFIG_FUNCTION_TRACER=y
|
||||
+# By default, the ftrace for RT kernel are disabled
|
||||
+# CONFIG_FTRACE is not set
|
||||
+# CONFIG_IRQSOFF_TRACER is not set
|
||||
+# CONFIG_PREEMPT_TRACER is not set
|
||||
+# CONFIG_SCHED_TRACER is not set
|
||||
+# CONFIG_FUNCTION_TRACER is not set
|
||||
+
|
||||
+
|
||||
diff --git a/arch/arm/configs/fragment-08-rt-mp13.config b/arch/arm/configs/fragment-08-rt-mp13.config
|
||||
new file mode 100644
|
||||
index 000000000..c70d7adc6
|
||||
--- /dev/null
|
||||
+++ b/arch/arm/configs/fragment-08-rt-mp13.config
|
||||
@@ -0,0 +1,2 @@
|
||||
+# Disable SMP on MP13
|
||||
+# CONFIG_SMP is not set
|
||||
--
|
||||
2.34.1
|
||||
|
||||
File diff suppressed because it is too large
Load Diff
|
|
@ -0,0 +1,55 @@
|
|||
..........................................................................
|
||||
. WARNING
|
||||
.
|
||||
. This file is a kernel configuration fragment, and not a full kernel
|
||||
. configuration file. The final kernel configuration is made up of
|
||||
. an assembly of processed fragments, each of which is designed to
|
||||
. capture a specific part of the final configuration (e.g. platform
|
||||
. configuration, feature configuration, and board specific hardware
|
||||
. configuration). For more information on kernel configuration, please
|
||||
. consult the product documentation.
|
||||
.
|
||||
..........................................................................
|
||||
CONFIG_COMPAT=y
|
||||
CONFIG_NETFILTER_NETLINK=y
|
||||
CONFIG_NF_CONNTRACK=m
|
||||
CONFIG_NF_CONNTRACK_EVENTS=y
|
||||
CONFIG_NF_NAT=y
|
||||
CONFIG_NF_TABLES=y
|
||||
CONFIG_NFT_NAT=y
|
||||
CONFIG_NETFILTER_XTABLES=y
|
||||
CONFIG_NETFILTER_XTABLES_COMPAT=y
|
||||
CONFIG_NETFILTER_XT_NAT=y
|
||||
CONFIG_NETFILTER_XT_TARGET_NETMAP=y
|
||||
CONFIG_NETFILTER_XT_TARGET_REDIRECT=y
|
||||
CONFIG_NETFILTER_XT_TARGET_MASQUERADE=y
|
||||
CONFIG_NETFILTER_XT_MARK=m
|
||||
CONFIG_NETFILTER_XT_MATCH_ADDRTYPE=m
|
||||
CONFIG_NETFILTER_XT_MATCH_CONNTRACK=m
|
||||
CONFIG_IP_NF_IPTABLES=y
|
||||
CONFIG_IP6_NF_IPTABLES=y
|
||||
CONFIG_IP_NF_NAT=y
|
||||
CONFIG_IP_NF_TARGET_MASQUERADE=y
|
||||
CONFIG_IP_NF_TARGET_NETMAP=y
|
||||
CONFIG_IP_NF_TARGET_REDIRECT=y
|
||||
CONFIG_VETH=y
|
||||
CONFIG_CGROUPS=y
|
||||
CONFIG_CGROUP_CPUACCT=y
|
||||
CONFIG_CGROUP_DEVICE=y
|
||||
CONFIG_CGROUP_FREEZER=y
|
||||
CONFIG_CGROUP_SCHED=y
|
||||
CONFIG_CGROUP_BPF=y
|
||||
CONFIG_CGROUP_NS=y
|
||||
CONFIG_CGROUP_FREEZER=y
|
||||
CONFIG_CGROUP_DEVICE=y
|
||||
CONFIG_BLK_CGROUP=y
|
||||
CONFIG_NETFILTER=y
|
||||
CONFIG_BRIDGE_NETFILTER=m
|
||||
CONFIG_BRIDGE=m
|
||||
CONFIG_BRIDGE_VLAN_FILTERING=y
|
||||
CONFIG_CHECKPOINT_RESTORE=y
|
||||
CONFIG_PACKET_DIAG=m
|
||||
CONFIG_UNIX_DIAG=m
|
||||
CONFIG_NETFILTER_XT_MATCH_COMMENT=m
|
||||
CONFIG_NETLINK_DIAG=m
|
||||
CONFIG_MACVLAN=y
|
||||
|
|
@ -0,0 +1,27 @@
|
|||
..........................................................................
|
||||
. WARNING
|
||||
.
|
||||
. This file is a kernel configuration fragment, and not a full kernel
|
||||
. configuration file. The final kernel configuration is made up of
|
||||
. an assembly of processed fragments, each of which is designed to
|
||||
. capture a specific part of the final configuration (e.g. platform
|
||||
. configuration, feature configuration, and board specific hardware
|
||||
. configuration). For more information on kernel configuration, please
|
||||
. consult the product documentation.
|
||||
.
|
||||
..........................................................................
|
||||
CONFIG_NET_SCH_MULTIQ=m
|
||||
CONFIG_NET_SCH_CBS=m
|
||||
CONFIG_NET_SCH_ETF=m
|
||||
CONFIG_NET_SCH_TAPRIO=m
|
||||
CONFIG_NET_SCH_MQPRIO=m
|
||||
CONFIG_NET_SCH_INGRESS=m
|
||||
CONFIG_NET_CLS_BASIC=m
|
||||
CONFIG_NET_CLS_U32=m
|
||||
CONFIG_NET_CLS_FLOWER=m
|
||||
CONFIG_NET_CLS_ACT=y
|
||||
CONFIG_NET_ACT_GACT=m
|
||||
CONFIG_NET_ACT_MIRRED=m
|
||||
CONFIG_NET_ACT_GATE=m
|
||||
CONFIG_NET_ACT_SKBEDIT=m
|
||||
CONFIG_FSL_ENETC_QOS=y
|
||||
|
|
@ -1,4 +1,4 @@
|
|||
# Copyright (C) 2022,2023 Digi International
|
||||
# Copyright (C) 2022-2024 Digi International
|
||||
|
||||
require recipes-kernel/linux/linux-dey.inc
|
||||
|
||||
|
|
@ -7,10 +7,63 @@ SRCBRANCH:stm32mpcommon = "v5.15/stm/dey-4.0/maint"
|
|||
SRCREV = "${AUTOREV}"
|
||||
SRCREV:stm32mpcommon = "${AUTOREV}"
|
||||
|
||||
do_assemble_fitimage:prepend:ccmp1() {
|
||||
# Deploy u-boot script to be included into the FIT image
|
||||
install -d ${STAGING_DIR_HOST}/boot
|
||||
install -m 0644 ${RECIPE_SYSROOT}/${datadir}/${UBOOT_ENV_BINARY} ${STAGING_DIR_HOST}/boot/
|
||||
STM_RT_PATCHES = " \
|
||||
file://patch-5.15.119-rt65.patch \
|
||||
file://0023-5.15-stm32mp-rt-49-r1-CLOCK.patch \
|
||||
file://0024-5.15-stm32mp-rt-49-r1-DMA.patch \
|
||||
file://0025-5.15-stm32mp-rt-49-r1-MFD.patch \
|
||||
file://0026-5.15-stm32mp-rt-49-r1-NET-TTY.patch \
|
||||
file://0027-5.15-stm32mp-rt-49-r1-DEVICETREE.patch \
|
||||
file://0028-5.15-stm32mp-rt-49-r1-CONFIG.patch \
|
||||
"
|
||||
|
||||
SRC_URI:append:stm32mpcommon = " \
|
||||
${@bb.utils.contains('DISTRO_FEATURES', 'rt', '${STM_RT_PATCHES}', '', d)} \
|
||||
"
|
||||
|
||||
KERNEL_CONFIG_FRAGMENTS:append:stm32mpcommon = " ${@bb.utils.contains('DISTRO_FEATURES', 'rt', '${S}/arch/arm/configs/fragment-07-rt.config', '', d)}"
|
||||
KERNEL_CONFIG_FRAGMENTS:append:stm32mpcommon = " ${@bb.utils.contains('DISTRO_FEATURES', 'rt', '${S}/arch/arm/configs/fragment-07-rt-sysvinit.config', '', d)}"
|
||||
KERNEL_CONFIG_FRAGMENTS:append:ccmp13 = " ${@bb.utils.contains('DISTRO_FEATURES', 'rt', '${S}/arch/arm/configs/fragment-08-rt-mp13.config', '', d)}"
|
||||
|
||||
do_assemble_fitimage:append:ccmp1() {
|
||||
#
|
||||
# Step 9: Add public keys to the different U-Boot dtb files
|
||||
#
|
||||
if [ "${UBOOT_SIGN_ENABLE}" = "1" ] && [ -n "${UBOOT_DEVICETREE}" ]; then
|
||||
for devicetree in ${UBOOT_DEVICETREE}; do
|
||||
if [ -f "${STAGING_DATADIR}/${devicetree}.dtb" ]; then
|
||||
cp -P "${STAGING_DATADIR}/${devicetree}.dtb" ${B}
|
||||
|
||||
# Add image public key in U-Boot dtb file
|
||||
fdt_add_pubkey -a "${FIT_HASH_ALG},${FIT_SIGN_ALG}" \
|
||||
-k "${UBOOT_SIGN_KEYDIR}" \
|
||||
-n "${UBOOT_SIGN_IMG_KEYNAME}" \
|
||||
-r "image" \
|
||||
"${B}/${devicetree}.dtb"
|
||||
|
||||
# Add configuration public key in U-Boot dtb file
|
||||
fdt_add_pubkey -a "${FIT_HASH_ALG},${FIT_SIGN_ALG}" \
|
||||
-k "${UBOOT_SIGN_KEYDIR}" \
|
||||
-n "${UBOOT_SIGN_KEYNAME}" \
|
||||
-r "conf" \
|
||||
"${B}/${devicetree}.dtb"
|
||||
fi
|
||||
done
|
||||
fi
|
||||
}
|
||||
|
||||
kernel_do_deploy:append:ccmp1() {
|
||||
if [ "${UBOOT_SIGN_ENABLE}" = "1" ] && \
|
||||
[ -n "${UBOOT_DTB_BINARY}" ] ; then
|
||||
# Install device tree files with signature
|
||||
if [ -n "${UBOOT_DEVICETREE}" ]; then
|
||||
for devicetree in ${UBOOT_DEVICETREE}; do
|
||||
if [ -f "${B}/${devicetree}.dtb" ]; then
|
||||
install -m 0644 ${B}/${devicetree}.dtb "${DEPLOYDIR}/${FIP_UBOOT_DTB}-${devicetree}-with-signature.dtb"
|
||||
fi
|
||||
done
|
||||
fi
|
||||
fi
|
||||
}
|
||||
|
||||
COMPATIBLE_MACHINE = "(ccimx6|ccimx6ul|ccimx8m|ccimx8x|ccmp1)"
|
||||
|
|
|
|||
|
|
@ -1,8 +1,28 @@
|
|||
# Copyright (C) 2023 Digi International
|
||||
# Copyright (C) 2023-2024 Digi International
|
||||
|
||||
require recipes-kernel/linux/linux-dey.inc
|
||||
|
||||
SRCBRANCH = "v6.1/nxp/dey-4.0/maint"
|
||||
|
||||
# Patch series for RT Kernel
|
||||
NXP_RT_PATCHES = " \
|
||||
file://0001-arch-arm-add-NXP-RT-support.patch \
|
||||
file://0002-RT-add-RT-localversion.patch \
|
||||
file://0003-arch-arm64-add-NXP-RT-support.patch \
|
||||
file://0004-Documentation-add-NXP-RT-support.patch \
|
||||
file://0005-include-add-NXP-RT-support.patch \
|
||||
file://0006-kernel-add-NXP-RT-support.patch \
|
||||
file://0007-drivers-add-NXP-RT-support.patch \
|
||||
file://0008-net-add-RT-NXP-support.patch \
|
||||
file://0009-init-add-NXP-RT-support.patch \
|
||||
file://nxp_rt_conf.cfg \
|
||||
"
|
||||
|
||||
SRC_URI:append = " \
|
||||
${@bb.utils.contains('DISTRO_FEATURES', 'rt', '${NXP_RT_PATCHES}', '', d)} \
|
||||
${@bb.utils.contains('DISTRO_FEATURES', 'tsn', 'file://tsn_conf.cfg', '', d)} \
|
||||
"
|
||||
|
||||
SRCREV = "${AUTOREV}"
|
||||
|
||||
# Blacklist btnxpuart module. It will be managed by the bluetooth-init script
|
||||
|
|
|
|||
|
|
@ -7,8 +7,8 @@ trustfence_sign() {
|
|||
# Set environment variables for trustfence configuration
|
||||
export CONFIG_SIGN_KEYS_PATH="${TRUSTFENCE_SIGN_KEYS_PATH}"
|
||||
[ -n "${TRUSTFENCE_KEY_INDEX}" ] && export CONFIG_KEY_INDEX="${TRUSTFENCE_KEY_INDEX}"
|
||||
[ -n "${TRUSTFENCE_SRK_REVOKE_MASK}" ] && export SRK_REVOKE_MASK="${TRUSTFENCE_SRK_REVOKE_MASK}"
|
||||
[ -n "${TRUSTFENCE_DEK_PATH}" ] && [ "${TRUSTFENCE_DEK_PATH}" != "0" ] && export CONFIG_DEK_PATH="${TRUSTFENCE_DEK_PATH}"
|
||||
[ -n "${TRUSTFENCE_SIGN_MODE}" ] && export CONFIG_SIGN_MODE="${TRUSTFENCE_SIGN_MODE}"
|
||||
|
||||
# Sign/encrypt the kernel images
|
||||
for type in ${KERNEL_IMAGETYPES}; do
|
||||
|
|
@ -31,6 +31,9 @@ trustfence_sign() {
|
|||
mv "${TMP_KERNEL_IMAGE_SIGNED}" "${KERNEL_IMAGE}"
|
||||
done
|
||||
|
||||
# For FIT images there is no need to sign the rest of artifacts
|
||||
[ "${TRUSTFENCE_SIGN_FIT_NXP}" = "1" ] && return 0
|
||||
|
||||
# Sign/encrypt the device tree blobs
|
||||
for DTB in ${KERNEL_DEVICETREE}; do
|
||||
DTB=`normalize_dtb "${DTB}"`
|
||||
|
|
|
|||
|
|
@ -1,50 +0,0 @@
|
|||
# Copyright (C) 2019 Digi International
|
||||
|
||||
# Apply kernel configuration required for Docker
|
||||
do_configure:prepend() {
|
||||
mkdir -p ${B}
|
||||
|
||||
kernel_conf_variable NAMESPACES y
|
||||
kernel_conf_variable MULTIUSER y
|
||||
kernel_conf_variable NET_NS y
|
||||
kernel_conf_variable NET y
|
||||
kernel_conf_variable PID_NS y
|
||||
kernel_conf_variable IPC_NS y
|
||||
kernel_conf_variable POSIX_MQUEUE y
|
||||
kernel_conf_variable UTS_NS y
|
||||
kernel_conf_variable CGROUPS y
|
||||
kernel_conf_variable CGROUP_CPUACCT y
|
||||
kernel_conf_variable CGROUP_DEVICE y
|
||||
kernel_conf_variable CGROUP_FREEZER y
|
||||
kernel_conf_variable CGROUP_SCHED y
|
||||
kernel_conf_variable CPUSETS y
|
||||
kernel_conf_variable SMP y
|
||||
kernel_conf_variable MEMCG y
|
||||
kernel_conf_variable KEYS y
|
||||
kernel_conf_variable VETH y
|
||||
kernel_conf_variable NETDEVICES y
|
||||
kernel_conf_variable NET_CORE y
|
||||
kernel_conf_variable BRIDGE y
|
||||
kernel_conf_variable BRIDGE_NETFILTER y
|
||||
kernel_conf_variable NETFILTER y
|
||||
kernel_conf_variable INET y
|
||||
kernel_conf_variable NETFILTER_ADVANCED y
|
||||
kernel_conf_variable NF_NAT_IPV4 y
|
||||
kernel_conf_variable NF_CONNTRACK_IPV4 y
|
||||
kernel_conf_variable NF_CONNTRACK y
|
||||
kernel_conf_variable IP_NF_FILTER y
|
||||
kernel_conf_variable IP_NF_IPTABLES y
|
||||
kernel_conf_variable IP_NF_TARGET_MASQUERADE y
|
||||
kernel_conf_variable IP_NF_NAT y
|
||||
kernel_conf_variable NETFILTER_XT_MATCH_ADDRTYPE y
|
||||
kernel_conf_variable NETFILTER_XT_MATCH_CONNTRACK y
|
||||
kernel_conf_variable NETFILTER_XT_MATCH_IPVS y
|
||||
kernel_conf_variable IP_VS y
|
||||
kernel_conf_variable IP_NF_NAT y
|
||||
kernel_conf_variable POSIX_MQUEUE y
|
||||
kernel_conf_variable OVERLAY_FS y
|
||||
|
||||
sed -e "${CONF_SED_SCRIPT}" < '${WORKDIR}/defconfig' >> '${B}/.config'
|
||||
}
|
||||
|
||||
KERNEL_MODULE_AUTOLOAD += "nf_conntrack_ipv6 openvswitch"
|
||||
|
|
@ -12,16 +12,16 @@
|
|||
#
|
||||
|
||||
# FSBL partitions aka TF-A BL2
|
||||
part fsbl1 --source rawcopy --fstype=ext4 --fsoptions "noauto" --part-name=fsbl1 --sourceparams="file=${DEPLOY_DIR_IMAGE}/arm-trusted-firmware/tf-a-${MACHINE}-sdcard.stm32" --ondisk mmcblk --part-type 0x8301 --fixed-size 256K --align 17
|
||||
part fsbl2 --source rawcopy --fstype=ext4 --fsoptions "noauto" --part-name=fsbl2 --sourceparams="file=${DEPLOY_DIR_IMAGE}/arm-trusted-firmware/tf-a-${MACHINE}-sdcard.stm32" --ondisk mmcblk --part-type 0x8301 --fixed-size 256K
|
||||
part fsbl1 --source rawcopy --fstype=ext4 --fsoptions "noauto" --part-name=fsbl1 --sourceparams="file=${DEPLOY_DIR_IMAGE}/arm-trusted-firmware/tf-a-${MACHINE}-1GB-sdcard.stm32" --ondisk mmcblk --part-type 0x8301 --fixed-size 256K --align 17
|
||||
part fsbl2 --source rawcopy --fstype=ext4 --fsoptions "noauto" --part-name=fsbl2 --sourceparams="file=${DEPLOY_DIR_IMAGE}/arm-trusted-firmware/tf-a-${MACHINE}-1GB-sdcard.stm32" --ondisk mmcblk --part-type 0x8301 --fixed-size 256K
|
||||
|
||||
# Metadata partitions
|
||||
part metadata1 --source rawcopy --fstype=ext4 --fsoptions "noauto" --part-name=metadata1 --sourceparams="file=${DEPLOY_DIR_IMAGE}/arm-trusted-firmware/metadata.bin" --ondisk mmcblk --part-type 0x8301 --fixed-size 256K
|
||||
part metadata2 --source rawcopy --fstype=ext4 --fsoptions "noauto" --part-name=metadata2 --sourceparams="file=${DEPLOY_DIR_IMAGE}/arm-trusted-firmware/metadata.bin" --ondisk mmcblk --part-type 0x8301 --fixed-size 256K
|
||||
|
||||
# Fip partitions
|
||||
part fip-a --source rawcopy --fstype=ext4 --fsoptions "noauto" --part-name=fip-a --sourceparams="file=${DEPLOY_DIR_IMAGE}/fip/fip-${MACHINE}-optee.bin" --ondisk mmcblk --part-type 19d5df83-11b0-457b-be2c-7559c13142a5 --fixed-size 4096K --uuid 4fd84c93-54ef-463f-a7ef-ae25ff887087
|
||||
part fip-b --source rawcopy --fstype=ext4 --fsoptions "noauto" --part-name=fip-b --sourceparams="file=${DEPLOY_DIR_IMAGE}/fip/fip-${MACHINE}-optee.bin" --ondisk mmcblk --part-type 19d5df83-11b0-457b-be2c-7559c13142a5 --fixed-size 4096K --uuid 09c54952-d5bf-45af-acee-335303766fb3
|
||||
part fip-a --source rawcopy --fstype=ext4 --fsoptions "noauto" --part-name=fip-a --sourceparams="file=${DEPLOY_DIR_IMAGE}/fip/fip-${MACHINE}-1GB-optee.bin" --ondisk mmcblk --part-type 19d5df83-11b0-457b-be2c-7559c13142a5 --fixed-size 4096K --uuid 4fd84c93-54ef-463f-a7ef-ae25ff887087
|
||||
part fip-b --source rawcopy --fstype=ext4 --fsoptions "noauto" --part-name=fip-b --sourceparams="file=${DEPLOY_DIR_IMAGE}/fip/fip-${MACHINE}-1GB-optee.bin" --ondisk mmcblk --part-type 19d5df83-11b0-457b-be2c-7559c13142a5 --fixed-size 4096K --uuid 09c54952-d5bf-45af-acee-335303766fb3
|
||||
|
||||
# U-BOOT env
|
||||
part u-boot-env --source empty --part-name=uboot-env --ondisk mmcblk --part-type 0x8301 --fixed-size 512K
|
||||
|
|
@ -0,0 +1,37 @@
|
|||
# short-description: Create SD card image with a boot partition (1GB)
|
||||
# long-description: Creates a partitioned SD card image (1GB)
|
||||
#
|
||||
# - -------- ------------- ------ ------ ------------ -------- --------- --------
|
||||
# | | TFA(2) | Metadata(2) | FIPA | FIPB | U-BOOT ENV | linux | rootfs | data |
|
||||
# - -------- ------------- ------ ------ ------------ -------- --------- --------
|
||||
# ^ ^ ^ ^ ^ ^ ^ ^ ^ ^
|
||||
# | | | | | | | | | |
|
||||
# 0 17kB 542kB 1.06MB 5.26MB 9.45MB 9.97MB 77.1MB 898MB 1032MB
|
||||
#
|
||||
# Warning: the first stage of boot (here fsbl1, fsbl2, metadata1, metadata2, fipa, fipb) MUST be on GPT partition to be detected.
|
||||
#
|
||||
|
||||
# FSBL partitions aka TF-A BL2
|
||||
part fsbl1 --source rawcopy --fstype=ext4 --fsoptions "noauto" --part-name=fsbl1 --sourceparams="file=${DEPLOY_DIR_IMAGE}/arm-trusted-firmware/tf-a-${MACHINE}-256MB-sdcard.stm32" --ondisk mmcblk --part-type 0x8301 --fixed-size 256K --align 17
|
||||
part fsbl2 --source rawcopy --fstype=ext4 --fsoptions "noauto" --part-name=fsbl2 --sourceparams="file=${DEPLOY_DIR_IMAGE}/arm-trusted-firmware/tf-a-${MACHINE}-256MB-sdcard.stm32" --ondisk mmcblk --part-type 0x8301 --fixed-size 256K
|
||||
|
||||
# Metadata partitions
|
||||
part metadata1 --source rawcopy --fstype=ext4 --fsoptions "noauto" --part-name=metadata1 --sourceparams="file=${DEPLOY_DIR_IMAGE}/arm-trusted-firmware/metadata.bin" --ondisk mmcblk --part-type 0x8301 --fixed-size 256K
|
||||
part metadata2 --source rawcopy --fstype=ext4 --fsoptions "noauto" --part-name=metadata2 --sourceparams="file=${DEPLOY_DIR_IMAGE}/arm-trusted-firmware/metadata.bin" --ondisk mmcblk --part-type 0x8301 --fixed-size 256K
|
||||
|
||||
# Fip partitions
|
||||
part fip-a --source rawcopy --fstype=ext4 --fsoptions "noauto" --part-name=fip-a --sourceparams="file=${DEPLOY_DIR_IMAGE}/fip/fip-${MACHINE}-256MB-optee.bin" --ondisk mmcblk --part-type 19d5df83-11b0-457b-be2c-7559c13142a5 --fixed-size 4096K --uuid 4fd84c93-54ef-463f-a7ef-ae25ff887087
|
||||
part fip-b --source rawcopy --fstype=ext4 --fsoptions "noauto" --part-name=fip-b --sourceparams="file=${DEPLOY_DIR_IMAGE}/fip/fip-${MACHINE}-256MB-optee.bin" --ondisk mmcblk --part-type 19d5df83-11b0-457b-be2c-7559c13142a5 --fixed-size 4096K --uuid 09c54952-d5bf-45af-acee-335303766fb3
|
||||
|
||||
# U-BOOT env
|
||||
part u-boot-env --source empty --part-name=uboot-env --ondisk mmcblk --part-type 0x8301 --fixed-size 512K
|
||||
|
||||
# linux
|
||||
part --source rawcopy --sourceparams="file=${DEPLOY_DIR_IMAGE}/${IMAGE_LINK_NAME}.boot.vfat" --ondisk mmcblk --fstype=vfat --part-name=linux --active --fixed-size 64M
|
||||
|
||||
# Rootfs
|
||||
part / --source rootfs --ondisk mmcblk --fstype=ext4 --label rootfs --fixed-size 783M --uuid e91c4e10-16e6-4c0e-bd0e-77becf4a3582 --part-name=rootfs
|
||||
# data
|
||||
part data --ondisk mmcblk --fstype=ext4 --label data --fixed-size 128M --part-name=data
|
||||
|
||||
bootloader --ptable gpt
|
||||
|
|
@ -0,0 +1,37 @@
|
|||
# short-description: Create SD card image with a boot partition (1GB)
|
||||
# long-description: Creates a partitioned SD card image (1GB)
|
||||
#
|
||||
# - -------- ------------- ------ ------ ------------ -------- --------- --------
|
||||
# | | TFA(2) | Metadata(2) | FIPA | FIPB | U-BOOT ENV | linux | rootfs | data |
|
||||
# - -------- ------------- ------ ------ ------------ -------- --------- --------
|
||||
# ^ ^ ^ ^ ^ ^ ^ ^ ^ ^
|
||||
# | | | | | | | | | |
|
||||
# 0 17kB 542kB 1.06MB 5.26MB 9.45MB 9.97MB 77.1MB 898MB 1032MB
|
||||
#
|
||||
# Warning: the first stage of boot (here fsbl1, fsbl2, metadata1, metadata2, fipa, fipb) MUST be on GPT partition to be detected.
|
||||
#
|
||||
|
||||
# FSBL partitions aka TF-A BL2
|
||||
part fsbl1 --source rawcopy --fstype=ext4 --fsoptions "noauto" --part-name=fsbl1 --sourceparams="file=${DEPLOY_DIR_IMAGE}/arm-trusted-firmware/tf-a-${MACHINE}-512MB-sdcard.stm32" --ondisk mmcblk --part-type 0x8301 --fixed-size 256K --align 17
|
||||
part fsbl2 --source rawcopy --fstype=ext4 --fsoptions "noauto" --part-name=fsbl2 --sourceparams="file=${DEPLOY_DIR_IMAGE}/arm-trusted-firmware/tf-a-${MACHINE}-512MB-sdcard.stm32" --ondisk mmcblk --part-type 0x8301 --fixed-size 256K
|
||||
|
||||
# Metadata partitions
|
||||
part metadata1 --source rawcopy --fstype=ext4 --fsoptions "noauto" --part-name=metadata1 --sourceparams="file=${DEPLOY_DIR_IMAGE}/arm-trusted-firmware/metadata.bin" --ondisk mmcblk --part-type 0x8301 --fixed-size 256K
|
||||
part metadata2 --source rawcopy --fstype=ext4 --fsoptions "noauto" --part-name=metadata2 --sourceparams="file=${DEPLOY_DIR_IMAGE}/arm-trusted-firmware/metadata.bin" --ondisk mmcblk --part-type 0x8301 --fixed-size 256K
|
||||
|
||||
# Fip partitions
|
||||
part fip-a --source rawcopy --fstype=ext4 --fsoptions "noauto" --part-name=fip-a --sourceparams="file=${DEPLOY_DIR_IMAGE}/fip/fip-${MACHINE}-512MB-optee.bin" --ondisk mmcblk --part-type 19d5df83-11b0-457b-be2c-7559c13142a5 --fixed-size 4096K --uuid 4fd84c93-54ef-463f-a7ef-ae25ff887087
|
||||
part fip-b --source rawcopy --fstype=ext4 --fsoptions "noauto" --part-name=fip-b --sourceparams="file=${DEPLOY_DIR_IMAGE}/fip/fip-${MACHINE}-512MB-optee.bin" --ondisk mmcblk --part-type 19d5df83-11b0-457b-be2c-7559c13142a5 --fixed-size 4096K --uuid 09c54952-d5bf-45af-acee-335303766fb3
|
||||
|
||||
# U-BOOT env
|
||||
part u-boot-env --source empty --part-name=uboot-env --ondisk mmcblk --part-type 0x8301 --fixed-size 512K
|
||||
|
||||
# linux
|
||||
part --source rawcopy --sourceparams="file=${DEPLOY_DIR_IMAGE}/${IMAGE_LINK_NAME}.boot.vfat" --ondisk mmcblk --fstype=vfat --part-name=linux --active --fixed-size 64M
|
||||
|
||||
# Rootfs
|
||||
part / --source rootfs --ondisk mmcblk --fstype=ext4 --label rootfs --fixed-size 783M --uuid e91c4e10-16e6-4c0e-bd0e-77becf4a3582 --part-name=rootfs
|
||||
# data
|
||||
part data --ondisk mmcblk --fstype=ext4 --label data --fixed-size 128M --part-name=data
|
||||
|
||||
bootloader --ptable gpt
|
||||
|
|
@ -23,14 +23,13 @@ TRUSTFENCE_CONSOLE_DISABLE ?= "0"
|
|||
# Default secure boot configuration
|
||||
TRUSTFENCE_SIGN ?= "1"
|
||||
TRUSTFENCE_SIGN_KEYS_PATH ?= "default"
|
||||
TRUSTFENCE_DEK_PATH ?= "default"
|
||||
TRUSTFENCE_DEK_PATH:ccimx93 ?= "0"
|
||||
TRUSTFENCE_DEK_PATH:ccmp1 ?= "0"
|
||||
TRUSTFENCE_DEK_PATH ?= "${TF_DEK_PATH}"
|
||||
TRUSTFENCE_ENCRYPT_ENVIRONMENT ?= "1"
|
||||
TRUSTFENCE_ENCRYPT_ENVIRONMENT:ccimx93 ?= "0"
|
||||
TRUSTFENCE_SRK_REVOKE_MASK ?= "0x0"
|
||||
TRUSTFENCE_KEY_INDEX ?= "0"
|
||||
TRUSTFENCE_FIT_IMG:ccmp1 ?= "1"
|
||||
TRUSTFENCE_SIGN_ARTIFACTS = "1"
|
||||
TRUSTFENCE_SIGN_ARTIFACTS:ccmp1 = "0"
|
||||
TRUSTFENCE_SIGN_FIT_STM:ccmp1 ?= "1"
|
||||
|
||||
# Partition encryption configuration
|
||||
TRUSTFENCE_ENCRYPT_PARTITIONS ?= "1"
|
||||
|
|
@ -45,10 +44,14 @@ TRUSTFENCE_READ_ONLY_ROOTFS ?= "${@bb.utils.contains("IMAGE_FEATURES", "read-onl
|
|||
# NOTHING TO CUSTOMIZE BELOW THIS LINE
|
||||
#
|
||||
|
||||
# TrustFence sign artifacts is not supported on all platforms
|
||||
TRUSTFENCE_SIGN_ARTIFACTS = "1"
|
||||
TRUSTFENCE_SIGN_ARTIFACTS:ccmp1 = "0"
|
||||
TRUSTFENCE_SIGN_ARTIFACTS:ccimx93 = "0"
|
||||
# Platform specific defaults
|
||||
TF_DEK_PATH = "default"
|
||||
TF_DEK_PATH:ccimx93 = "0"
|
||||
TF_DEK_PATH:ccmp1 = "0"
|
||||
|
||||
# NXP-based sign a FIT-format boot artifact
|
||||
TRUSTFENCE_SIGN_FIT_NXP = "0"
|
||||
TRUSTFENCE_SIGN_FIT_NXP:ccimx93 = "${TRUSTFENCE_SIGN_ARTIFACTS}"
|
||||
|
||||
IMAGE_FEATURES += "dey-trustfence"
|
||||
|
||||
|
|
@ -56,8 +59,6 @@ IMAGE_FEATURES += "dey-trustfence"
|
|||
# Usage of FIT Image signed
|
||||
# ---------------------------------
|
||||
|
||||
# Enable FIT image build when Trustfence is enabled
|
||||
MACHINE_FEATURES += "${@oe.utils.conditional('TRUSTFENCE_FIT_IMG', '1', 'fit', '', d)}"
|
||||
# key to sign FIT config nodes
|
||||
TRUSTFENCE_FIT_CFG_SIGN_KEYNAME ?= "fitcfg"
|
||||
# key to sign FIT image nodes
|
||||
|
|
@ -153,6 +154,12 @@ python () {
|
|||
elif d.getVar("TRUSTFENCE_CONSOLE_GPIO_ENABLE"):
|
||||
if (d.getVar("DEY_SOC_VENDOR") == "NXP"):
|
||||
d.appendVar("UBOOT_TF_CONF", "CONFIG_CONSOLE_ENABLE_GPIO=y CONFIG_CONSOLE_ENABLE_GPIO_NR=%s " % d.getVar("TRUSTFENCE_CONSOLE_GPIO_ENABLE"))
|
||||
if d.getVar("TRUSTFENCE_CONSOLE_GPIO_ENABLE_NAME"):
|
||||
d.appendVar("UBOOT_TF_CONF", 'CONFIG_CONSOLE_ENABLE_GPIO_NAME="%s" ' % d.getVar("TRUSTFENCE_CONSOLE_GPIO_ENABLE_NAME"))
|
||||
if d.getVar("TRUSTFENCE_CONSOLE_GPIO_ENABLE_ACTIVE_LOW"):
|
||||
d.appendVar("UBOOT_TF_CONF", "CONFIG_CONSOLE_ENABLE_GPIO_ACTIVE_LOW=y ")
|
||||
else:
|
||||
d.appendVar("UBOOT_TF_CONF", '"# CONFIG_CONSOLE_ENABLE_GPIO_ACTIVE_LOW is not set" ')
|
||||
elif (d.getVar("DEY_SOC_VENDOR") == "STM"):
|
||||
d.appendVar("UBOOT_TF_CONF", 'CONFIG_CONSOLE_ENABLE_GPIO=y CONFIG_CONSOLE_ENABLE_GPIO_NAME="%s" ' % d.getVar("TRUSTFENCE_CONSOLE_GPIO_ENABLE_NAME"))
|
||||
|
||||
|
|
@ -185,6 +192,9 @@ python () {
|
|||
d.appendVar("UBOOT_TF_CONF", "CONFIG_SIGN_IMAGE=y ")
|
||||
if (d.getVar("TRUSTFENCE_SIGN_ARTIFACTS") == "1"):
|
||||
d.appendVar("UBOOT_TF_CONF", "CONFIG_AUTH_ARTIFACTS=y ")
|
||||
if (d.getVar("TRUSTFENCE_SIGN_FIT_NXP") == "1"):
|
||||
d.appendVar("UBOOT_TF_CONF", '"# CONFIG_CMD_BOOTI is not set" ')
|
||||
d.appendVar("UBOOT_TF_CONF", '"# CONFIG_LEGACY_IMAGE_FORMAT is not set" ')
|
||||
if (d.getVar("TRUSTFENCE_READ_ONLY_ROOTFS") == "1"):
|
||||
d.appendVar("UBOOT_TF_CONF", "CONFIG_AUTHENTICATE_SQUASHFS_ROOTFS=y ")
|
||||
if d.getVar("TRUSTFENCE_SIGN_KEYS_PATH"):
|
||||
|
|
@ -200,7 +210,7 @@ python () {
|
|||
d.appendVar("UBOOT_TF_CONF", 'CONFIG_SIGN_MODE="%s" ' % d.getVar("TRUSTFENCE_SIGN_MODE"))
|
||||
|
||||
|
||||
if (d.getVar("TRUSTFENCE_FIT_IMG") == "1"):
|
||||
if (d.getVar("TRUSTFENCE_SIGN_FIT_STM") == "1"):
|
||||
# FIT-related variables
|
||||
# Create keys if not defined
|
||||
d.setVar("FIT_GENERATE_KEYS", "1")
|
||||
|
|
@ -221,7 +231,7 @@ python () {
|
|||
|
||||
if (d.getVar("TRUSTFENCE_ENCRYPT_ENVIRONMENT") == "1"):
|
||||
if (d.getVar("DEY_SOC_VENDOR") == "NXP"):
|
||||
d.appendVar("UBOOT_TF_CONF", "CONFIG_ENV_AES=y CONFIG_ENV_AES_CAAM_KEY=y ")
|
||||
d.appendVar("UBOOT_TF_CONF", "CONFIG_ENV_AES=y CONFIG_ENV_AES_CAAM_KEY=y CONFIG_ENV_ENCRYPT=y ")
|
||||
elif (d.getVar("DEY_SOC_VENDOR") == "STM"):
|
||||
d.appendVar("UBOOT_TF_CONF", "CONFIG_ENV_AES_CCMP1=y ")
|
||||
|
||||
|
|
|
|||
|
|
@ -3,8 +3,8 @@ require conf/distro/poky.conf
|
|||
# Discrete version values.
|
||||
YOCTO_MAJOR = "4"
|
||||
YOCTO_MINOR = "0"
|
||||
DEY_RELEASE = "5"
|
||||
DEY_BUILD = "2"
|
||||
DEY_RELEASE = "6"
|
||||
DEY_BUILD = "1"
|
||||
|
||||
# Firmware version of the system.
|
||||
DEY_FIRMWARE_VERSION ?= "${YOCTO_MAJOR}.${YOCTO_MINOR}.${DEY_RELEASE}.${DEY_BUILD}"
|
||||
|
|
@ -57,13 +57,6 @@ FEATURE_PACKAGES_dey-wireless = "packagegroup-dey-wireless"
|
|||
# 5.65 version should be used, which is provided by the poky layer.
|
||||
PREFERRED_VERSION_bluez5 ?= "5.65"
|
||||
|
||||
# The latest available versions of swupdate and libubootenv are 2023.12 and
|
||||
# 0.3.5, respectively. However, our custom patches haven't been ported or
|
||||
# tested for these versions yet, so until then, continue using the versions
|
||||
# we've been using in DEY 4.0 (2023.05 and 0.3.2) to guarantee stability.
|
||||
PREFERRED_VERSION_swupdate ?= "2023.05"
|
||||
PREFERRED_VERSION_libubootenv ?= "0.3.2"
|
||||
|
||||
# There's a generic opencl-headers recipe in the thud branch of
|
||||
# meta-openembedded, but we should use the package provided by the imx-gpu-viv
|
||||
# recipe in case there are NXP-specific changes in it
|
||||
|
|
|
|||
Some files were not shown because too many files have changed in this diff Show More
Loading…
Reference in New Issue