Thanks Troy. I got secure booting of the complete chain after copying to DRAM.
 
Also for u-boot verification I had to add "u-boot,dm-pre-reloc;" to the ast2600-evb.dts file to enable the hace engine to be available before u-boot is relocated.
 
Thanks,
Sandhya
 
----- Original message -----
From: "Troy Lee" <leetroy@gmail.com>
Sent by: "openbmc" <openbmc-bounces+sandhya.koteshwara=ibm.com@lists.ozlabs.org>
To: "Sandhya Koteshwara" <Sandhya.Koteshwara@ibm.com>
Cc: "OpenBMC Maillist" <openbmc@lists.ozlabs.org>, "Troy Lee" <troy_lee@aspeedtech.com>
Subject: [EXTERNAL] Re: [PATCH u-boot v2019.04-aspeed-openbmc v1 1/2] ast2600: spl: Fixes boot from RAM device
Date: Mon, Jul 26, 2021 10:23 PM
 
Hi Sandhya,

The AST2600 hardware hash and crypto engine (HACE) can only exame data
in DRAM, please make sure you copy the kernel fit-image into dram
first.

Thanks,
Troy Lee
--
Yu-Ting Lee (Troy Lee) <LeeTroy@gmail.com>

On Tue, Jul 27, 2021 at 1:53 AM Sandhya Koteshwara
<Sandhya.Koteshwara@ibm.com> wrote:
>
> Hi Troy, Joel,
>
> I am looking to use these patches to secure boot OpenBMC from flash on the AST2600 evaluation board. Is there a relevant UBOOT_MACHINE configuration file I can use?
>
> I am currently porting configuration for secure boot from the ast2600_openbmc_spl_emmc_defconfig to the ast2600_openbmc_spl_defconfig. I was only able to get the u-boot-spl to verify u-boot but kernel verification fails.
>
> Thanks,
> Sandhya
>
> ----- Original message -----
> From: Troy Lee <troy_lee@aspeedtech.com>
> Sent by: "openbmc" <openbmc-bounces+sandhya.koteshwara=ibm.com@lists.ozlabs.org>
> To: <leetroy@gmail.com>, <openbmc@lists.ozlabs.org>, <joel@jms.id.au>
> Cc:
> Subject: [EXTERNAL] [PATCH u-boot v2019.04-aspeed-openbmc v1 1/2] ast2600: spl: Fixes boot from RAM device
> Date: Wed, Jun 23, 2021 2:08 AM
>
> Reporting a BOOT_DEVICE_RAM can leverage common/spl/spl_ram.c
> to bring up u-boot.bin by memory offset 0x00010000.
>
> Fixes: 13dd0b0f7273 ("ast2600: spl: Support common boot loader features")
> Signed-off-by: Troy Lee <troy_lee@aspeedtech.com>
> ---
>  arch/arm/mach-aspeed/ast2600/spl.c | 2 +-
>  1 file changed, 1 insertion(+), 1 deletion(-)
>
> diff --git a/arch/arm/mach-aspeed/ast2600/spl.c b/arch/arm/mach-aspeed/ast2600/spl.c
> index 778b326755..c759a7575d 100644
> --- a/arch/arm/mach-aspeed/ast2600/spl.c
> +++ b/arch/arm/mach-aspeed/ast2600/spl.c
> @@ -66,7 +66,7 @@ u32 spl_boot_device(void)
>   case AST_BOOTMODE_EMMC:
>   return BOOT_DEVICE_MMC1;
>   case AST_BOOTMODE_SPI:
> - return BOOT_DEVICE_SPI;
> + return BOOT_DEVICE_RAM;
>   case AST_BOOTMODE_UART:
>   return BOOT_DEVICE_UART;
>   }
> --
> 2.17.1
>
>
>
>
>