From: Marcel Ziswiler <marcel@ziswiler.com>
To: u-boot@lists.denx.de
Cc: Heiko Thiery <heiko.thiery@gmail.com>,
Frieder Schrempf <frieder.schrempf@kontron.de>,
Fabio Estevam <festevam@gmail.com>,
Stefano Babic <sbabic@denx.de>,
Marcel Ziswiler <marcel.ziswiler@toradex.com>,
"NXP i.MX U-Boot Team" <uboot-imx@nxp.com>,
Simon Glass <sjg@chromium.org>, Tom Rini <trini@konsulko.com>
Subject: [PATCH v6 03/11] ARM: dts: imx8mm-verdin: prepare for dek blob encapsulation
Date: Sat, 9 Oct 2021 22:41:05 +0200 [thread overview]
Message-ID: <20211009204113.1208641-4-marcel@ziswiler.com> (raw)
In-Reply-To: <20211009204113.1208641-1-marcel@ziswiler.com>
From: Marcel Ziswiler <marcel.ziswiler@toradex.com>
Prepare for DEK blob encapsulation support through "dek_blob" command.
On ARMv8, u-boot runs in non-secure, thus cannot encapsulate a DEK blob
for encrypted boot.
The DEK blob is encapsulated by OP-TEE through a trusted application
call. U-boot sends and receives the DEK and the DEK blob binaries
through OP-TEE dynamic shared memory.
To enable the DEK blob encapsulation, add to the defconfig:
CONFIG_SECURE_BOOT=y
CONFIG_FAT_WRITE=y
CONFIG_CMD_DEKBLOB=y
Taken from NXP's commit 56d2050f4028 ("imx8m: Add DEK blob encapsulation
for imx8m").
Signed-off-by: Marcel Ziswiler <marcel.ziswiler@toradex.com>
Reviewed-by: Fabio Estevam <festevam@gmail.com>
---
(no changes since v1)
arch/arm/dts/imx8mm-verdin-u-boot.dtsi | 7 +++++++
1 file changed, 7 insertions(+)
diff --git a/arch/arm/dts/imx8mm-verdin-u-boot.dtsi b/arch/arm/dts/imx8mm-verdin-u-boot.dtsi
index 67c31c49b6c..a97626fa0c1 100644
--- a/arch/arm/dts/imx8mm-verdin-u-boot.dtsi
+++ b/arch/arm/dts/imx8mm-verdin-u-boot.dtsi
@@ -6,6 +6,13 @@
#include "imx8mm-u-boot.dtsi"
/ {
+ firmware {
+ optee {
+ compatible = "linaro,optee-tz";
+ method = "smc";
+ };
+ };
+
wdt-reboot {
compatible = "wdt-reboot";
wdt = <&wdog1>;
--
2.26.2
next prev parent reply other threads:[~2021-10-09 20:42 UTC|newest]
Thread overview: 25+ messages / expand[flat|nested] mbox.gz Atom feed top
2021-10-09 20:41 [PATCH v6 00/11] board: toradex: verdin-imx8mm: target refresh Marcel Ziswiler
2021-10-09 20:41 ` [PATCH v6 01/11] imx8m: clean-up kconfig indentation Marcel Ziswiler
2021-10-20 14:43 ` sbabic
2021-10-09 20:41 ` [PATCH v6 02/11] verdin-imx8mm: fix ethernet Marcel Ziswiler
2021-10-20 14:44 ` sbabic
2021-10-09 20:41 ` Marcel Ziswiler [this message]
2021-10-20 14:43 ` [PATCH v6 03/11] ARM: dts: imx8mm-verdin: prepare for dek blob encapsulation sbabic
2021-10-09 20:41 ` [PATCH v6 04/11] arm64: dts: imx8mm-verdin-u-boot.dtsi: alphabetically re-order Marcel Ziswiler
2021-10-20 14:43 ` sbabic
2021-10-09 20:41 ` [PATCH v6 05/11] verdin-imx8mm: switch to use binman to pack images Marcel Ziswiler
2021-10-20 14:43 ` sbabic
2021-10-09 20:41 ` [PATCH v6 06/11] verdin-imx8mm: enable sleep_moci output Marcel Ziswiler
2021-10-20 14:44 ` sbabic
2021-10-09 20:41 ` [PATCH v6 07/11] verdin-imx8mm: clean-up include order Marcel Ziswiler
2021-10-20 14:43 ` sbabic
2021-10-09 20:41 ` [PATCH v6 08/11] verdin-imx8mm: drop support for v1.0 hardware Marcel Ziswiler
2021-10-20 14:44 ` sbabic
2021-10-09 20:41 ` [PATCH v6 09/11] include/configs: apalis-imx8/verdin-imx8mm: rename kernel image variable Marcel Ziswiler
2021-10-20 14:44 ` sbabic
2021-10-09 20:41 ` [PATCH v6 10/11] verdin-imx8mm: use preboot for fdtfile evaluation Marcel Ziswiler
2021-10-20 14:44 ` sbabic
2021-10-09 20:41 ` [PATCH v6 11/11] verdin-imx8mm: fix watchdog pinctrl issue Marcel Ziswiler
2021-10-20 14:43 ` sbabic
2021-10-12 19:46 ` [PATCH v6 00/11] board: toradex: verdin-imx8mm: target refresh Tim Harvey
2021-10-12 21:16 ` Marcel Ziswiler
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20211009204113.1208641-4-marcel@ziswiler.com \
--to=marcel@ziswiler.com \
--cc=festevam@gmail.com \
--cc=frieder.schrempf@kontron.de \
--cc=heiko.thiery@gmail.com \
--cc=marcel.ziswiler@toradex.com \
--cc=sbabic@denx.de \
--cc=sjg@chromium.org \
--cc=trini@konsulko.com \
--cc=u-boot@lists.denx.de \
--cc=uboot-imx@nxp.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).