]> git.dujemihanovic.xyz Git - u-boot.git/commitdiff
ls1021atwr: caam: Enable Uboot validaion in SPL.
authorGaurav Jain <gaurav.jain@nxp.com>
Thu, 23 Jun 2022 11:01:35 +0000 (16:31 +0530)
committerPeng Fan <peng.fan@nxp.com>
Tue, 16 Aug 2022 09:07:30 +0000 (17:07 +0800)
caam driver model enabled in spl for secure boot.
fsl_rsa_mod_exp driver enabled in spl for validating uboot image.

Signed-off-by: Gaurav Jain <gaurav.jain@nxp.com>
MAINTAINERS
arch/arm/dts/ls1021a-twr-u-boot.dtsi [new file with mode: 0644]
arch/arm/dts/ls1021a-twr.dtsi
board/freescale/common/fsl_chain_of_trust.c
board/freescale/common/fsl_validate.c
board/freescale/ls1021atwr/ls1021atwr.c

index fa8c13fc7dfbf0b83c58256170d20b61e6fae2da..5857fbf39869dcbaff5a629e54c9cae705836415 100644 (file)
@@ -1499,5 +1499,6 @@ F:        */
 CAAM
 M:     Gaurav Jain <gaurav.jain@nxp.com>
 S:     Maintained
+F:     arch/arm/dts/ls1021a-twr-u-boot.dtsi
 F:     drivers/crypto/fsl/
 F:     include/fsl_sec.h
diff --git a/arch/arm/dts/ls1021a-twr-u-boot.dtsi b/arch/arm/dts/ls1021a-twr-u-boot.dtsi
new file mode 100644 (file)
index 0000000..3711e42
--- /dev/null
@@ -0,0 +1,29 @@
+// SPDX-License-Identifier: GPL-2.0-or-later
+/*
+ * Copyright 2022 NXP
+ */
+
+&{/soc} {
+       u-boot,dm-spl;
+       u-boot,dm-pre-reloc;
+};
+
+&crypto {
+       u-boot,dm-spl;
+};
+
+&sec_jr0 {
+       u-boot,dm-spl;
+};
+
+&sec_jr1 {
+       u-boot,dm-spl;
+};
+
+&sec_jr2 {
+       u-boot,dm-spl;
+};
+
+&sec_jr3 {
+       u-boot,dm-spl;
+};
index bf96af7e360f0b1179beb616f744b0db9c9c2f51..82df2f11bb9586f21b3de42fc2535f9d8b18afc4 100644 (file)
@@ -6,6 +6,7 @@
  */
 
 #include "ls1021a.dtsi"
+#include "ls1021a-twr-u-boot.dtsi"
 
 / {
        model = "LS1021A TWR Board";
index d31fb821817c388ee70d5b5b0d2e9d5e734bf3fb..ad723534402105286211e457f46e16ef9c67f02d 100644 (file)
@@ -1,6 +1,7 @@
 // SPDX-License-Identifier: GPL-2.0+
 /*
  * Copyright 2015 Freescale Semiconductor, Inc.
+ * Copyright 2022 NXP
  */
 
 #include <common.h>
@@ -114,11 +115,6 @@ void spl_validate_uboot(uint32_t hdr_addr, uintptr_t img_addr)
                fsl_secboot_handle_error(ERROR_ESBC_PAMU_INIT);
 #endif
 
-#ifdef CONFIG_FSL_CAAM
-       if (sec_init() < 0)
-               fsl_secboot_handle_error(ERROR_ESBC_SEC_INIT);
-#endif
-
 /*
  * dm_init_and_scan() is called as part of common SPL framework, so no
  * need to call it again but in case of powerpc platforms which currently
index f56e4e857af1d18351eaa41b71d1793bfe6d2d4a..7a23d8f4c7c1254ecc5808bf5131ebb960be4962 100644 (file)
@@ -1,7 +1,7 @@
 // SPDX-License-Identifier: GPL-2.0+
 /*
  * Copyright 2015 Freescale Semiconductor, Inc.
- * Copyright 2021 NXP
+ * Copyright 2021-2022 NXP
  */
 
 #include <common.h>
@@ -19,6 +19,7 @@
 #ifdef CONFIG_ARCH_LS1021A
 #include <asm/arch/immap_ls102xa.h>
 #endif
+#include <dm/lists.h>
 
 #define SHA256_BITS    256
 #define SHA256_BYTES   (256/8)
@@ -807,6 +808,13 @@ static int calculate_cmp_img_sig(struct fsl_secboot_img_priv *img)
        prop.num_bits = key_len * 8;
        prop.exp_len = key_len;
 
+#if defined(CONFIG_SPL_BUILD)
+       ret = device_bind_driver(NULL, "fsl_rsa_mod_exp", "fsl_rsa_mod_exp", NULL);
+       if (ret) {
+               printf("Couldn't bind fsl_rsa_mod_exp driver (%d)\n", ret);
+               return -EINVAL;
+       }
+#endif
        ret = uclass_get_device(UCLASS_MOD_EXP, 0, &mod_exp_dev);
        if (ret) {
                printf("RSA: Can't find Modular Exp implementation\n");
index a3aa84deb25150563fbbc61c85981a2c66835fe7..746b35a678b0d15fef4a9b917a0e2464134c828f 100644 (file)
@@ -1,7 +1,7 @@
 // SPDX-License-Identifier: GPL-2.0+
 /*
  * Copyright 2014 Freescale Semiconductor, Inc.
- * Copyright 2019, 2021 NXP
+ * Copyright 2019, 2021-2022 NXP
  */
 
 #include <common.h>
@@ -34,7 +34,7 @@
 #include <fsl_qe.h>
 #endif
 #include <fsl_validate.h>
-
+#include <dm/uclass.h>
 
 DECLARE_GLOBAL_DATA_PTR;
 
@@ -530,6 +530,15 @@ int board_init(void)
 #if defined(CONFIG_SPL_BUILD)
 void spl_board_init(void)
 {
+       if (IS_ENABLED(CONFIG_FSL_CAAM)) {
+               struct udevice *dev;
+               int ret;
+
+               ret = uclass_get_device_by_driver(UCLASS_MISC, DM_DRIVER_GET(caam_jr), &dev);
+               if (ret)
+                       printf("Failed to initialize caam_jr: %d\n", ret);
+       }
+
        ls102xa_smmu_stream_id_init();
 }
 #endif