From patchwork Sun Nov 20 20:47:04 2022 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: "Schultschik, Sven" X-Patchwork-Id: 13050145 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id C828FC4332F for ; Sun, 20 Nov 2022 20:48:52 +0000 (UTC) Received: from EUR04-DB3-obe.outbound.protection.outlook.com (EUR04-DB3-obe.outbound.protection.outlook.com [40.107.6.69]) by mx.groups.io with SMTP id smtpd.web11.22460.1668977322351510124 for ; Sun, 20 Nov 2022 12:48:42 -0800 Authentication-Results: mx.groups.io; dkim=fail reason="body hash did not verify" header.i=@siemens.com header.s=selector2 header.b=LE11pevv; spf=pass (domain: siemens.com, ip: 40.107.6.69, mailfrom: sven.schultschik@siemens.com) ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=lI38VG7Y+6fsOV7tWFT2A/IPt9PnBywg7V9GoyaknajvVhQFXRkJ+YgJHYHZjOJiFMy8cNoREz+5d8QtxrP3BzSW4oIuszo/L86dj/RHu9iRrTObodOMUb55KkPixlpGm4MrL+rmJeEfUeV1J8VmLe636eYqMtDHEDWaARoaJU2g4YjiU7p81Y9z3soRkw0gzit8vvK+KMXLEtp7m/35rtKhTmyRSfWvOlleDUyS0NhK8DqEBHk2echJc+Ll5ufkY+isjmLdGdkWjYf/jEVAMIsDAymsP+9ER1t5N+ejh8SDdpVj0cAzzhMn+rbi9hZ8jv9l8UcWQNAXRO1FRvSMUg== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=pL68QCWGeED+kpttQOM0+vg1Bg+XyDS1QDHV3W3qhF0=; b=O4yeBOr4hfka1Jm/RGBmuLlPOjFJeaozX9hA6SoO4GKfwY5R3PZSUQxK5mJBpGTtd+c3MIaXwiAArgfVFDf7DKS2Acun1Rt35DNONj5CWgWy5xyBsZjlzljt1Wyv4lZ1bx7RCclmfstRuxCjKXKJz3tNR8S/9Z0ix1cFiw5L+Bqc9+zEPMbOPQoxvVbllcNP7w9GP6jxj0iP3a6eneltrpIX/YaRKeTyHLs4nXBL2cG1TaRRNOLn5k8z6iCc9+Yo8HI0Qgj7YwuLFV9hDbwdPQTGdunZdQtegVztMm7N+x0o9CYlgbHhUJlzjxE/BjMDa7gZEu4+bATJC1EIcCKMvw== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=siemens.com; dmarc=pass action=none header.from=siemens.com; dkim=pass header.d=siemens.com; arc=none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=siemens.com; s=selector2; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=pL68QCWGeED+kpttQOM0+vg1Bg+XyDS1QDHV3W3qhF0=; b=LE11pevv7flWwQFDTLnjjygJOZnUhSAXHZYI93Vg1p1NS2tGnWOZvjNdILuxLxLMMKIJXAQ0l3T+Wjy34pmdgQnSQoDEK0pN8ByBCNTMDfNG7tcp20t4rzFj8+d18zBQ+BLh5nuM+4boE9T4Zx4bw6sth98/28NsRL0tgVGZTfkZQZHgxpuHFrL/kOP95nVk3P6MUu+z83MjTa7L4L5GmuFWlyqJWuJaNnQMPTdhgwzxt75O0O9AoRCtSaUUQAJYkFuVuR00ltNRGAY5po0jfyxPw6Ji8GkfbSdLSNXQP4tXuQ8kttVcwuxNUbA/vWxeiNGkgar79gKKvVP8eOIM5w== Authentication-Results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=siemens.com; Received: from PAXPR10MB5037.EURPRD10.PROD.OUTLOOK.COM (2603:10a6:102:210::11) by DU0PR10MB7094.EURPRD10.PROD.OUTLOOK.COM (2603:10a6:10:42e::11) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.5834.11; Sun, 20 Nov 2022 20:48:40 +0000 Received: from PAXPR10MB5037.EURPRD10.PROD.OUTLOOK.COM ([fe80::955a:f715:5319:7933]) by PAXPR10MB5037.EURPRD10.PROD.OUTLOOK.COM ([fe80::955a:f715:5319:7933%9]) with mapi id 15.20.5834.015; Sun, 20 Nov 2022 20:48:39 +0000 From: sven.schultschik@siemens.com To: cip-dev@lists.cip-project.org CC: jan.kiszka@siemens.com, Sven Schultschik Subject: [isar-cip-core][PATCH 1/8] add recipe for edk2 Date: Sun, 20 Nov 2022 21:47:04 +0100 Message-ID: <20221120204711.5826-2-sven.schultschik@siemens.com> X-Mailer: git-send-email 2.30.2 In-Reply-To: <20221120204711.5826-1-sven.schultschik@siemens.com> References: <20221120204711.5826-1-sven.schultschik@siemens.com> X-ClientProxiedBy: FR3P281CA0146.DEUP281.PROD.OUTLOOK.COM (2603:10a6:d10:95::18) To PAXPR10MB5037.EURPRD10.PROD.OUTLOOK.COM (2603:10a6:102:210::11) MIME-Version: 1.0 X-MS-PublicTrafficType: Email X-MS-TrafficTypeDiagnostic: PAXPR10MB5037:EE_|DU0PR10MB7094:EE_ X-MS-Office365-Filtering-Correlation-Id: ca42e1a6-fa64-4538-e9a2-08dacb389a6e X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam: BCL:0; X-Microsoft-Antispam-Message-Info: nO1EsCDaFYX0MGkmAO9WP6Ej21MdgLDCnoUOGnSYqSWegLnLzNeSLZcL6FQKJVVVMJoXQAse30s3enLosrVaPGhco9AIT5Nec3kKRHJHAQqxa5+5KKBrmLHp1TxC+HmX9dOgTq1LYECzD1hAAqHDeQA9sB1XGXeXuqutuw/X28N7aQk+nnqIX/VjtI5KyKix1CpoFnapGsLiSLUfSWevpcSMBmy4KCDa33+5Eih2V4GBYLOZrgoTksjadENCKVQ3CNvC7RWg6P21/VnuEDRT3MKVbOhdE43w0R7ftMOEQ3irCeT1rc14bmQvyIG4mYp6UZU7IhSg2Pz7go3lbzNve5GiLRJSoTeYB3DiaxJoeR20HP/hSBENhBU+u6wfIVO09Su0INb/4ZWV7/ID6aErDqDaL+N3nCZgZGCHLYyx1bie63yUCAPEtjA4666kch09vBUQxBorLL0Ld0+FKiWOrAmSoj04dRkG66cecktimAp5LW0BffhjvViUweX69JMlEjW3lDwm3TuhRGtL3eyIirLtPgLEg3AihBInYG2Lvfe4gfhieZBlg0iHp0OBgPZOcdnWbxpbWp+TZlUa7fAh4XbdkqIeBzfxPy0KtV85G5Nx+60prIyVcfoTPlC7ay0TjSP2hAVkWHRSt/rYZq1YkqvD1vSfSrYhCA0Wp9k8RHUrtyNx8DjiEO6pRrf1lffOXJntNJBc/SDHu7/bzP9cnA== X-Forefront-Antispam-Report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:PAXPR10MB5037.EURPRD10.PROD.OUTLOOK.COM;PTR:;CAT:NONE;SFS:(13230022)(4636009)(136003)(366004)(396003)(346002)(39860400002)(376002)(451199015)(2906002)(966005)(26005)(83380400001)(9686003)(86362001)(4326008)(6512007)(8676002)(66556008)(66476007)(82960400001)(66946007)(38100700002)(36756003)(41300700001)(6916009)(8936002)(5660300002)(316002)(107886003)(55236004)(478600001)(186003)(1076003)(6486002)(6666004)(2616005)(6506007);DIR:OUT;SFP:1101; X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1 X-MS-Exchange-AntiSpam-MessageData-0: xtP0pnawp+iJjA//pmJBoGVl6tDNiirsOiO91nT6TZ8d4Loce1WvgxGx28HMF2jZ2YRNNfrPJXVxhojKmBGRi22q8lEcKiUTYWDrEs76NKjH3o3W3zo7cyClwQkmiy/gZj8LMHuPhvHh/uok+ukR6R+JLWREHGps7lfrivgunV5uQZny61OUVOLLKyhH1xNUv2UrmMCLwsZg1XFOQuE30yM7v4bKVcaYYXJD0cT3sZ3lDTYDFoSmNflh4pyfiwv2ptfr+fTDh1Omj6roGkR3wQ66RYowmdBYMcrhH8x7Mor/h/oTbABlMaEpLfgPjt3nZE7KTgUao33Y8ZVgqaKgtHNRRXznBiM6+YhVaxYQiUab6Uqmk89MSzvH15cHDf4p0TrHP59nHmCBT6l+k7Bzuh1NtOKA6zK0YBug+Nk2Q9NUq/xFbJo8ouCKipVhlotws5qFb/iMf5w5xiT3xu9Lohi3agjzJ7CFl3635br/BLCXs6adBUeNCH3XsilqOhnM0dTJ/6Hs2Eu53VlKDyDJBaBvFgS168iLKKZxJAhPvIdFGrN1S29uKzm5Gom7p38dLN4ndf2E9LrLHvaHX9rvJTFn4rZBMgxtKxoNRxRsLTUBeP+SVTFXEAfhjWrqEyGtun8XZs/8oqaBjGFBZl9fIQ4Hp7C4sdXhNKe3lOUHi1q+0pUVVfiXXH/nj0b6LUrMR25Q+b4tH5bjJqc3uR4DpthwPNh9SkqDrtBRL0wu8mvTkerKJZ6arDbnU2QTRHtL6921DfN1+mEP9pFHj+dD9Ud5fkUs+uYzsKnCwifNBi1WHvuFF5sTCsCINQZfg0FhZbtmMnqOATkuqVPoJwGfT+qOe6MsI55u2eR5/OVFD6scDXdJK+xWeBdpZnYqlSSbm5bDrnsD0lC+CvWZDSLFBexunouyXbHkHtQv4ltqi3B9GxQTkc3Q27pqGDt8IrvZc4rnDP+hmiggRK1IHWjmhXPplIkxEje/Pb0OoCeAEmVdwL/5YPhFELB49yGO7AfpE2nRM6OfESztxVlUScQswvERkOYTq5BITWJA+kIdRWksKIMTImCnBP9/tmqAOK98cv0xyErzMqkh51vJU/K2lQbjhzZQtDhtCPjpUgSdUX+B5y/IS1jTE+4URvNkBOFwuaUmitE/FjUfvOgrspB/gy5+cvpclwWpv8yFIL3JA1CsIm8k8KAF548PvU7IAuHRCH6G/80VwwfeIZDu/9BszAJ8GPb8eldGACQqDI5g8FNcsETGWZRzcJiAE27re8ZtGL/v0itI+BavHA7ofXPybj2wT2uxyEzSBNUBXcyo/CkvFAWuPsXdSh6WniLgFSiJQhZ1LA0tXT4wDJGjPrlz79iUMCeGTp5OUoLms5m/GhlDCXnSZhsCu8YBfK5+0HcYH+rrC55Kq/yZZPkHmIEkGiV4vbEvAMv0PFCweI6Cv+Raf1vdDlg2YLLOsX68t/9/EwIvA9qYBTJJRsbVUY05/yACLPOJWcMU0k7sgmc67+22gXb1F3jaNAt3pXa+sdil/T5UPvfUoJic9ScFMB07HtL04OPXAIJzDG35SLLjfNpLDJXktQk4lUPc/jSudPQiCys2WYYMdByyQUOgoITnqg== X-OriginatorOrg: siemens.com X-MS-Exchange-CrossTenant-Network-Message-Id: ca42e1a6-fa64-4538-e9a2-08dacb389a6e X-MS-Exchange-CrossTenant-AuthSource: PAXPR10MB5037.EURPRD10.PROD.OUTLOOK.COM X-MS-Exchange-CrossTenant-AuthAs: Internal X-MS-Exchange-CrossTenant-OriginalArrivalTime: 20 Nov 2022 20:48:39.7007 (UTC) X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted X-MS-Exchange-CrossTenant-Id: 38ae3bcd-9579-4fd4-adda-b42e1495d55a X-MS-Exchange-CrossTenant-MailboxType: HOSTED X-MS-Exchange-CrossTenant-UserPrincipalName: TBA+bmihQ6rTMjt282qJE8gXFnqUhlBBUGhL1WJnZmRXmLFINvpMLafLCXPElNUl4mdkDaiuq2z2Dilk8g7h9VC7wen+C57qhFfHUtC8pB0= X-MS-Exchange-Transport-CrossTenantHeadersStamped: DU0PR10MB7094 List-Id: X-Webhook-Received: from li982-79.members.linode.com [45.33.32.79] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 20 Nov 2022 20:48:52 -0000 X-Groupsio-URL: https://lists.cip-project.org/g/cip-dev/message/10054 From: Sven Schultschik provide a recipe to create the BL32_AP_MM.fd binary by edk2 which is needed for the qemu optee generation as dependency. Signed-off-by: Sven Schultschik --- .../edk2/edk2-platformstandalonemmrpmb.inc | 56 +++++++++++++++++ .../edk2-platformstandalonemmrpmb_202205.bb | 12 ++++ recipes-bsp/edk2/files/rules.tmpl | 61 +++++++++++++++++++ 3 files changed, 129 insertions(+) create mode 100644 recipes-bsp/edk2/edk2-platformstandalonemmrpmb.inc create mode 100644 recipes-bsp/edk2/edk2-platformstandalonemmrpmb_202205.bb create mode 100755 recipes-bsp/edk2/files/rules.tmpl diff --git a/recipes-bsp/edk2/edk2-platformstandalonemmrpmb.inc b/recipes-bsp/edk2/edk2-platformstandalonemmrpmb.inc new file mode 100644 index 0000000..3277cc8 --- /dev/null +++ b/recipes-bsp/edk2/edk2-platformstandalonemmrpmb.inc @@ -0,0 +1,56 @@ +# +# CIP Core, generic profile +# +# Copyright (c) Siemens AG, 2022 +# +# Authors: +# Sven Schultschik +# +# SPDX-License-Identifier: MIT +# + +HOMEPAGE = "https://github.com/tianocore/edk2" +MAINTAINER = "Sven Schultschik " +LICENSE = "BSD-2-Clause-Patent" + +inherit dpkg + +SRC_URI = "https://github.com/tianocore/edk2/archive/refs/tags/edk2-stable${PV}.tar.gz;name=edk2 \ + https://github.com/google/brotli/archive/${SRC_REV_brotli}.tar.gz;name=brotli \ + https://github.com/openssl/openssl/archive/refs/tags/${SRC_REV_openssl}.tar.gz;name=openssl \ + git://github.com/tianocore/edk2-platforms.git;protocol=https;destsuffix=git/edk2-platforms;name=edk2-platforms \ + file://rules.tmpl \ + " +SRC_URI[edk2.sha256sum] = "e6cf93bae78b30a10732b8afb5cc438735dc9ec976ae65d12dab041c18bb7987" +SRC_URI[brotli.sha256sum] = "6d6cacce05086b7debe75127415ff9c3661849f564fe2f5f3b0383d48aa4ed77" +SRC_URI[openssl.sha256sum] = "6b2d2440ced8c802aaa61475919f0870ec556694c466ebea460e35ea2b14839e" + +SRC_REV_brotli = "f4153a09f87cbb9c826d8fc12c74642bb2d879ea" +SRC_REV_openssl = "OpenSSL_1_1_1n" +SRCREV_edk2-platforms = "3b896d1a325686de3942723c42f286090453e37a" + +S = "${WORKDIR}/git" + +DEBIAN_BUILD_DEPENDS = "python3:native, dh-python, uuid-dev:native" + +EDK2_BINARIES ?= "Build/MmStandaloneRpmb/RELEASE_GCC5/FV/BL32_AP_MM.fd" + +BUILD_DEPENDS += "" + +TEMPLATE_FILES = "rules.tmpl" + +do_prepare_build() { + deb_debianize + + mkdir -p ${S}/edk2 + cp -a ${WORKDIR}/edk2-edk2-stable${PV}/* "${S}/edk2/" + cp -a ${WORKDIR}/brotli-${SRC_REV_brotli}/* "${S}/edk2/BaseTools/Source/C/BrotliCompress/brotli" + cp -a ${WORKDIR}/brotli-${SRC_REV_brotli}/* "${S}/edk2/MdeModulePkg/Library/BrotliCustomDecompressLib/brotli" + cp -a ${WORKDIR}/openssl-${SRC_REV_openssl}/* "${S}/edk2/CryptoPkg/Library/OpensslLib/openssl" + + rm -f ${S}/debian/edk2.install + for binary in ${EDK2_BINARIES}; do + echo "$binary /usr/lib/edk2/" >> \ + ${S}/debian/edk2-platformstandalonemmrpmb.install + done +} diff --git a/recipes-bsp/edk2/edk2-platformstandalonemmrpmb_202205.bb b/recipes-bsp/edk2/edk2-platformstandalonemmrpmb_202205.bb new file mode 100644 index 0000000..84761c9 --- /dev/null +++ b/recipes-bsp/edk2/edk2-platformstandalonemmrpmb_202205.bb @@ -0,0 +1,12 @@ +# +# CIP Core, generic profile +# +# Copyright (c) Siemens AG, 2022 +# +# Authors: +# Sven Schultschik +# +# SPDX-License-Identifier: MIT +# + +require edk2-platformstandalonemmrpmb.inc diff --git a/recipes-bsp/edk2/files/rules.tmpl b/recipes-bsp/edk2/files/rules.tmpl new file mode 100755 index 0000000..388e49a --- /dev/null +++ b/recipes-bsp/edk2/files/rules.tmpl @@ -0,0 +1,61 @@ +#!/usr/bin/make -f +# +# Copyright (c) Siemens AG, 2022 +# +# SPDX-License-Identifier: MIT + +ifneq ($(DEB_BUILD_GNU_TYPE),$(DEB_HOST_GNU_TYPE)) +export CROSS_COMPILE=$(DEB_HOST_GNU_TYPE)- +endif + +export WORKSPACE=$(shell pwd) +export PACKAGES_PATH=$(WORKSPACE)/edk2:$(WORKSPACE)/edk2-platforms +export ACTIVE_PLATFORM="Platform/StandaloneMm/PlatformStandaloneMmPkg/PlatformStandaloneMmRpmb.dsc" + +# https://github.com/tianocore/edk2-platforms/blob/master/Readme.md#if-cross-compiling +ifeq (arm64,$(DEB_TARGET_ARCH)) +export TARGET_ARCH = 'AARCH64' +else ifeq ((armhf,$(DEB_TARGET_ARCH)) +export TARGET_ARCH = 'ARM' +else ifeq ((amd64,$(DEB_TARGET_ARCH)) +export TARGET_ARCH = 'X64' +else ifeq ((i386,$(DEB_TARGET_ARCH)) +export TARGET_ARCH = 'IA32' +else +$(error DEB_TARGET_ARCH $(DEB_TARGET_ARCH) unsupported) +endif +# When cross-compiling, or building with a different version of the compiler than +# the default `gcc`, we additionally need to inform the +# build command which toolchain to use. We do this by setting the environment +# variable `{TOOL_CHAIN_TAG}_{TARGET_ARCH}_PREFIX` - in the case above, +# **GCC5_AARCH64_PREFIX**. +# export GCC5_AARCH64_PREFIX=aarch64-linux-gnu- +# using export here at TOP Level does not work, because +# GCC5_$(TARGET_ARCH)_PREFIX gets deleted again for what reason ever +# Therefore it is set right before the build command +# export GCC5_$(TARGET_ARCH)_PREFIX=$(DEB_HOST_GNU_TYPE)- + + +export SHELL=/bin/bash + +# ENV Vars which should get set by edksetup.sh +export PYTHON_COMMAND=python3 +export PYTHONHASHSEED=1 +export CONF_PATH=$(WORKSPACE)/edk2/Conf +export EDK_TOOLS_PATH=$(WORKSPACE)/edk2/BaseTools +export PATH=$(WORKSPACE)/edk2/BaseTools/Bin/Linux-$(TARGET_ARCH):$(WORKSPACE)/edk2/BaseTools/BinWrappers/PosixLike::/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin + +override_dh_auto_build: + source edk2/edksetup.sh --reconfig + + CFLAGS= LDFLAGS= make -C edk2/BaseTools + + (export GCC5_$(TARGET_ARCH)_PREFIX=$(DEB_HOST_GNU_TYPE)- && \ + build -p $(ACTIVE_PLATFORM) -b RELEASE -a $(TARGET_ARCH) -t GCC5 -n $(shell nproc)) + +override_dh_auto_install: + +override_dh_auto_test: + +%: + dh $@ --no-parallel From patchwork Sun Nov 20 20:47:05 2022 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: "Schultschik, Sven" X-Patchwork-Id: 13050146 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id A6620C4332F for ; Sun, 20 Nov 2022 20:49:02 +0000 (UTC) Received: from EUR04-DB3-obe.outbound.protection.outlook.com (EUR04-DB3-obe.outbound.protection.outlook.com [40.107.6.85]) by mx.groups.io with SMTP id smtpd.web11.22465.1668977334826336138 for ; Sun, 20 Nov 2022 12:48:55 -0800 Authentication-Results: mx.groups.io; dkim=fail reason="body hash did not verify" header.i=@siemens.com header.s=selector2 header.b=uHX5SrzJ; spf=pass (domain: siemens.com, ip: 40.107.6.85, mailfrom: sven.schultschik@siemens.com) ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=mcMkgb086a+cfGkf1s8/D+iNNOAVJkcS5Wfvq9KhwI1soPejhXmq1Wlt3mOcM+0vZFcX0egetO83D/NJsGcB2PEavJ4U7qmBorUfNOg1tyHJboW4ATDchDCQOWmp7vchE6ydH73zpBEICMGitTK9tXU80bBz2j3qGKxRirItnRAfuGp1GOhRlSOxXECDsAc26TY5lgkR/nCJFHAzm/+ru/VUvto3pMF6w872eA8RP9XgaBQtDFO3ktW0y9A6SVSbdqql5K+NHi3dnrtlQG/5pqUYZIHMTkvyTwXfmO9zKfPCOIvNAm5O9CEMRkPDuaDhJz360dDfYU3T+RnpkemItA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=oqfvyF6RD9nWdDYRry5FxZOhSCc5UYvo4G6EgFXT3Ms=; b=aZfjBmDxE75IwdcD42TA2ZH5P6sxcW9ViTvIi16z3EJ5ync4M35i6Dxj5Qrxjh8z5VGvSQZ6/LCWb1+mQuZSXD9nu5Uh3J+Fr4SkbykSsTfmiS5+07NSD5KFOp5CaXRgivR+zJGYLwfivfaMjXAAodPjp0tTTUniTlsb1XbMgXUqMzdQt9mXVlls1W2dqCvZrQYO59s1FcOS2K9Z0y9roSodXfaWpy+u0C1wymfh5wPErpq6DOoLkQ/if9KeRfeA/YfiuYFV/tNQ30S98lc72nVWAd0KAgr/B8N/8MxBbdekt2Ge0Fb5Xxpr+jx+uh4B7DzUBbCx8NfJaZ/N9GV7cw== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=siemens.com; dmarc=pass action=none header.from=siemens.com; dkim=pass header.d=siemens.com; arc=none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=siemens.com; s=selector2; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=oqfvyF6RD9nWdDYRry5FxZOhSCc5UYvo4G6EgFXT3Ms=; b=uHX5SrzJQHQSMgLgA7lHRjOuXPzy6czLSa707hnyFHEELuNYkFAp7qOtF5LPSLxLdGzCLypfJbWaUfRExzD2UrN49ASyUhxoLdWz6lJ0O8FSap/rghgI0kVyywry2MAoAjH+7Y+lj90rVltTS0r2VoWeNKHahxD1uYuFw2cn9xPoxp3/raLHXhhcututueExP0KmoM7YF4vN1zMWvFEuwY5Je2IkO4tbm662LG6QaoFIx/kDTI9ZIQ6hXSXRBdywpW5fWRx7T1BbBVeSEQ5nXU4U4lur4tfK3Y5zh+JL4LlIiyJl2DQ49nXiDECJ+9EwIHQ0WtHEEra91mzHaUcBzw== Authentication-Results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=siemens.com; Received: from PAXPR10MB5037.EURPRD10.PROD.OUTLOOK.COM (2603:10a6:102:210::11) by DU0PR10MB7094.EURPRD10.PROD.OUTLOOK.COM (2603:10a6:10:42e::11) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.5834.11; Sun, 20 Nov 2022 20:48:52 +0000 Received: from PAXPR10MB5037.EURPRD10.PROD.OUTLOOK.COM ([fe80::955a:f715:5319:7933]) by PAXPR10MB5037.EURPRD10.PROD.OUTLOOK.COM ([fe80::955a:f715:5319:7933%9]) with mapi id 15.20.5834.015; Sun, 20 Nov 2022 20:48:52 +0000 From: sven.schultschik@siemens.com To: cip-dev@lists.cip-project.org CC: jan.kiszka@siemens.com, Sven Schultschik Subject: [isar-cip-core][PATCH 2/8] add recipe for optee qemu arm64 Date: Sun, 20 Nov 2022 21:47:05 +0100 Message-ID: <20221120204711.5826-3-sven.schultschik@siemens.com> X-Mailer: git-send-email 2.30.2 In-Reply-To: <20221120204711.5826-1-sven.schultschik@siemens.com> References: <20221120204711.5826-1-sven.schultschik@siemens.com> X-ClientProxiedBy: FR3P281CA0098.DEUP281.PROD.OUTLOOK.COM (2603:10a6:d10:a1::14) To PAXPR10MB5037.EURPRD10.PROD.OUTLOOK.COM (2603:10a6:102:210::11) MIME-Version: 1.0 X-MS-PublicTrafficType: Email X-MS-TrafficTypeDiagnostic: PAXPR10MB5037:EE_|DU0PR10MB7094:EE_ X-MS-Office365-Filtering-Correlation-Id: 8c2a9a8a-dd68-4fe7-57f5-08dacb38a245 X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam: BCL:0; X-Microsoft-Antispam-Message-Info: hLL7FLGWh1u3TOcWj7sNVprixzJUUf0gEerSb9P4b6EI15KHrwifu6o/xV3yvhDCyjBnHiJy+lTriv5S+Dz7DRm9t/iKEsEz7i+0PXq5o+spqLMzLexvpWPiH3fXo2MDFd8kOnWvV7oM4Vx46QFbtERSslWucRrDUBBZ06QsYApU+G47Ra8xGhCdiY9sFPlwjgoOfwJ4MyCdHp+RRY44HK1/hoQEMJofxQovEIlAwu3Rz2Cvi9fXcZINYEJpPDmyEbpUrYpom2ikujlAZCHaJhNrxQkbbdkFc0x/IP1BPBoBDfmMpVLu9j/ENRV0WjFeCAAjygmw3vuHQctmVJd0optWsrxaqyW6d5xOoRLy4dtko/4yuE0mdWNMJVugNR4HhI9CPCx6xUjZcKooUpXRu7EDMcjbFUpulw2YzkBdADwgVNKvqfZBaloy9Mfs2W02GfLuvioUHT/E72y+5ZDMNJobxPsvKRd3XzOQ/KVRFC6JTK1WMBJecTeV5WCqkar/5pZMm9YCOIZTUXgjJfC5t4iMglZGrPKy0QfGYo5v6+tCjuaijngF1EPlxvoyb+8oFy293/xQ0FLEYnW0rfV/gEUPiJzJlYZz7L3Wt/fqbuLi4419S78IhyDwV6kg6CEAswHLhQs7ZhqFaVUTLW1iTW6aoShW8bZu9efMMYubFlk= X-Forefront-Antispam-Report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:PAXPR10MB5037.EURPRD10.PROD.OUTLOOK.COM;PTR:;CAT:NONE;SFS:(13230022)(4636009)(136003)(366004)(396003)(346002)(39860400002)(376002)(451199015)(2906002)(26005)(9686003)(86362001)(4326008)(6512007)(8676002)(66556008)(66476007)(82960400001)(66946007)(38100700002)(36756003)(41300700001)(6916009)(8936002)(5660300002)(316002)(107886003)(55236004)(478600001)(186003)(1076003)(6486002)(6666004)(2616005)(6506007);DIR:OUT;SFP:1101; X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1 X-MS-Exchange-AntiSpam-MessageData-0: WFTvI0SrJq8Gwfk9FY6VTLV6KypQlcyKCEDQdMuZz/9OvpQdbGvAN7zxmXGAAb+hMhqsIpCYMBIk+xy6UVvqBDeQQYmeViPdiAQXTiDGwsl9OuBv6Kp7OKCM92ppQP5TBFZgXkbxbZzfyZQGpEUZl4Lc69FYqDJ2iE+0mbajFs0vUb3naki5eqk29NAK6GyScjPiITZvqk4kAj+OsDOa/WpXEhscUnOIoZWmA/I/WBmjvcwpb30XhJquHCnt4v0z9AzUHtCYcmdHotoYzdpfyTSDg2Mdd4X6qevWDXImtLvKu0/oGLGUmcnFtSBOji6aMlP3SAnrj+PtGH0tPBsAgxQMk3w7xUKN4DEemGO2LnGc5moWH6XyIqP7GCSOxd2BGza2mp6oTLvMnDNVvGF974YdcLl78IReEhJfQ2FLD7aSsPXOYP7xG39AIeUezhzdVz9Lf3Im7H0zYrGDvce23eadqTIBToHAxPtk5MvlAfNIEB9WiG6QdcRwl9ET3vPTawubTuhs+8TQ/PeGU6U/cUEb8Gg+PKfXxglWgONkNvuZLaJZfFiSjLHeS1HWrRa+7J/Kep4syOw0uKXrdRoN2zdbku6po0sNJWN7cHEzoOA8pUzA6P81jXTyc24wLI4jG7AI0QzqS6vgGOb1ziCYf1j8R5aoaZ+Ax52lYbsQ4JKqVIV52fRYEZD0X+g2HfTZLsOCNNX60fIlvdB1duogcd3hNCz6DW7S/xwUP3HNR7SaQkucmlVhOjKang71cpAg8iNJrltEDi8OWJN7BhOpDyX5E7vjAlMsZSXpQ/EKL981s5OCoLwHasj2GaGfmAYNVWwRUzQMb4nyVz6vsgoV3iAsrigZXNbEaTD4UmZxwp3GjjOosLs3cqmQIR5Dv7X5i6Ptpt4hRDYIIh/u4viv13VcD4bFJJsNAAt/Z+Btg7BiVIJ8bcbo8p8P0d8CRUXcN0NMVmx3IccuWpd1lEBHHwmNJprow2nFty4bVyZc5RenY90DVYugDF972c/E5dNqoXadUxs2aeM5mEn/IlhSvwWlVqNh6IZcmKKju8hRCEChfMpcoIWeY9nINy96DfimsHMgW51G6UU6FjhyZaWJQl30OGs4ED385WWMp+OPd6+aWSXBCaDXuSReZEjrhAsutyJIpqSSrbO9u+XGVM/Q3eG/w04VJYd183qusN0ZoqprU/I/5KuK2rxiWOfaObgf7zizMg71G4ddJGCDx9YowiNxnDrdpTrrUry5fh1gSaNxoztrKAxPeLLtel92iYJPZoCoGSOREj+s79YtQORxEAYGGd0LwH8C/VthuC8F/i4yqBIVNjMAXQkIa+/n7xI0BmNdTW1zxDADmsopmnjHtjjTjhZIH+D0/yxgABElUw7IP1fUwVdNRCFWHACN9iVet+LcselgZfifISD15+evy5Qw62kpu1kqo0ilzmOMJUZuW4HPZcaGBvpWlGT2qqlzrCnDtp1YAS26X6J7SxQj2yY8FeQp0j0WLxgx0tmdDVziM2MODhpZ+oD916VuOMhEy1rgTwdn/0tFeHLM+L9rzcvwCuCj8YsnF9Au0vgfoVr0gYRRBckr/aeXSsC07BDs4CFLUy/i/x5J7IIeSUkszw== X-OriginatorOrg: siemens.com X-MS-Exchange-CrossTenant-Network-Message-Id: 8c2a9a8a-dd68-4fe7-57f5-08dacb38a245 X-MS-Exchange-CrossTenant-AuthSource: PAXPR10MB5037.EURPRD10.PROD.OUTLOOK.COM X-MS-Exchange-CrossTenant-AuthAs: Internal X-MS-Exchange-CrossTenant-OriginalArrivalTime: 20 Nov 2022 20:48:52.8512 (UTC) X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted X-MS-Exchange-CrossTenant-Id: 38ae3bcd-9579-4fd4-adda-b42e1495d55a X-MS-Exchange-CrossTenant-MailboxType: HOSTED X-MS-Exchange-CrossTenant-UserPrincipalName: YIBu1ExS867Tf3o/ZNWxMtLBw6wR6U1CgpgZmGzWcaudjLz9FhSK9GemxhCvlKSJiqNv9XkNsxriKp3MpmTHWW8cZFPEDRo0h3h/pnu0oSI= X-MS-Exchange-Transport-CrossTenantHeadersStamped: DU0PR10MB7094 List-Id: X-Webhook-Received: from li982-79.members.linode.com [45.33.32.79] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 20 Nov 2022 20:49:02 -0000 X-Groupsio-URL: https://lists.cip-project.org/g/cip-dev/message/10055 From: Sven Schultschik The recipe provides the possibility to create optee-os binaries for use inside of an qemu secureboot setup with edk2, rpmb, u-boot and uefi Signed-off-by: Sven Schultschik --- .../op-tee/optee-os-qemu-arm64_3.17.0.bb | 54 +++++++++++++++++++ 1 file changed, 54 insertions(+) create mode 100644 recipes-bsp/op-tee/optee-os-qemu-arm64_3.17.0.bb diff --git a/recipes-bsp/op-tee/optee-os-qemu-arm64_3.17.0.bb b/recipes-bsp/op-tee/optee-os-qemu-arm64_3.17.0.bb new file mode 100644 index 0000000..2568c0a --- /dev/null +++ b/recipes-bsp/op-tee/optee-os-qemu-arm64_3.17.0.bb @@ -0,0 +1,54 @@ +# +# CIP Core, generic profile +# +# Copyright (c) Siemens AG, 2022 +# +# Authors: +# Sven Schultschik +# +# SPDX-License-Identifier: MIT +# + +HOMEPAGE = "https://github.com/OP-TEE/optee_os" +MAINTAINER = "Sven Schultschik " +LICENSE = "BSD-2-Clause" + +require recipes-bsp/optee-os/optee-os-custom.inc + +SRC_URI += " \ + git://github.com/OP-TEE/optee_os.git;branch=master;protocol=https" +SRCREV = "${PV}" + +S = "${WORKDIR}/git" + +OPTEE_PLATFORM = "vexpress-qemu_armv8a" + +OPTEE_BINARIES = "tee-header_v2.bin \ + tee-pager_v2.bin \ + tee-pageable_v2.bin" + +DEPENDS = "edk2-platformstandalonemmrpmb" +DEBIAN_BUILD_DEPENDS += " ,\ + debhelper(>= 11~), \ + cpio, \ + python3-cryptography:native, \ + python3-serial:native, \ + device-tree-compiler, \ + edk2-platformstandalonemmrpmb, \ + gcc-arm-linux-gnueabihf," + +OPTEE_EXTRA_BUILDARGS = "CFG_STMM_PATH=/usr/lib/edk2/BL32_AP_MM.fd CFG_RPMB_FS=y \ + CFG_RPMB_FS_DEV_ID=0 CFG_CORE_HEAP_SIZE=524288 CFG_RPMB_WRITE_KEY=1 \ + CFG_CORE_DYN_SHM=y CFG_RPMB_TESTKEY=y \ + CFG_REE_FS=n\ + CFG_TEE_CORE_LOG_LEVEL=1 CFG_TEE_TA_LOG_LEVEL=1 CFG_SCTLR_ALIGNMENT_CHECK=n \ + CFG_ARM64_core=y CFG_CORE_ARM64_PA_BITS=48" + +do_prepare_build_append() { + # $(ARCH) is the CPU architecture to be built. + # Currently, the only supported value is arm for 32-bit or 64-bit Armv7-A or Armv8-A. + # Please note that contrary to the Linux kernel, $(ARCH) should not be set to arm64 for 64-bit builds. + sed -i \ + "s/\$(MAKE)/ARCH=\"arm\" CROSS_COMPILE32=arm-linux-gnueabihf- CROSS_COMPILE64=aarch64-linux-gnu- \$(MAKE)/g" \ + ${S}/debian/rules +} From patchwork Sun Nov 20 20:47:06 2022 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: "Schultschik, Sven" X-Patchwork-Id: 13050147 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id A5F6BC4332F for ; Sun, 20 Nov 2022 20:49:12 +0000 (UTC) Received: from EUR04-DB3-obe.outbound.protection.outlook.com (EUR04-DB3-obe.outbound.protection.outlook.com [40.107.6.72]) by mx.groups.io with SMTP id smtpd.web11.22475.1668977348123458741 for ; Sun, 20 Nov 2022 12:49:08 -0800 Authentication-Results: mx.groups.io; dkim=fail reason="body hash did not verify" header.i=@siemens.com header.s=selector2 header.b=LFpj+IEC; spf=pass (domain: siemens.com, ip: 40.107.6.72, mailfrom: sven.schultschik@siemens.com) ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=crBn/rFaXDZ1Jo9Qg5/Ok7MvWgP7E79xN9YrBY9xLN+//8dJLpEvj1fT7wevyiehKeqhTlFmVL7MS77YHKE2fLUwJJoLTwBiljkba9eav8NvL/Xxl7WZL1K9Vi4vpRwMHfZOHUeXatG5SXEN2LRwO/aaaU8yDqE3yqRDA9kE7eQSkDFciIG9yJx1X43+SzPA4qnT0I3hTamwWFGQ/KxVcs3uGYKg4xiTZI8btO10cXvK7vUoUvBBS35kbZ4+BzM8GT0fI8T1ep+RsfgVh1+h5Vz4gmZNad/JzK6Uc2mXaSZKMoZ1T/8kUQPZ69Q6+u8UQTMDz7ClNOp/L6W+aWgfeg== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=OupTKXhYk9qDM1ix+oJWDCIw7U8jecNDIbZldGGWHDk=; b=ndaAxLEqXc8eJd12VZGYH12X05bm9ANMPsJtDY0GMkdfAbUnbp0/LraIwYE4S1YTFQNJszvR8g+e2t69EOFN/75mGPg8u086XF5Qak2SS61G6O+K5xmNYuIP30sm8L78Z7uz/JQcCpQVadxpjT4dNC4wIwZA7eav+4WY1XwYDrmRoJk7ISX6WGjlWJJ/8eIUD21wEtFEJOSDh7Z+pRJalxXJYLYS/ZLMlm0ypEv1zzTvnJ4q3ZuP5o2BSNznMZJoiCA/DePdPP9ns1WjzrcVZCh6hwPc5Qk7UQs1aBd2q3zrt2U8Pxr+oEJHscFY8GGFF92StOODinHgK4sEqVuh5w== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=siemens.com; dmarc=pass action=none header.from=siemens.com; dkim=pass header.d=siemens.com; arc=none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=siemens.com; s=selector2; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=OupTKXhYk9qDM1ix+oJWDCIw7U8jecNDIbZldGGWHDk=; b=LFpj+IECnPT2Kzo27Sxs4axEfrursrkNRJSZypwDcSxQLH7yV3xeSYzJHab2KGOmCvyaV9fmY5pDqG+xDYvdPhXrvDB7kNjwYzBcdAQ5/OQdhvJlVe6cbbdhHCkf+dcwTR6NWtugzVgdCYYSyOFRjCsxbFO5KuzVkgWiBK/I1Dv6WxPD2XIOLOuvVAZYf87RAMis1Z0nDnO3c+3NYtTi8BEaSYzWw4X74oCo3D+dPxQfsQwOjmaB0DTTeesmTTaq/EML6ZzE1uhyoR5R7BfleZWx6x9urbRo+r47ffA+Iw1NC7a+VPo+pAyilMRZ94YRysxc/Xzw2MY2SB4ME9xHzg== Authentication-Results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=siemens.com; Received: from PAXPR10MB5037.EURPRD10.PROD.OUTLOOK.COM (2603:10a6:102:210::11) by DU0PR10MB7094.EURPRD10.PROD.OUTLOOK.COM (2603:10a6:10:42e::11) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.5834.11; Sun, 20 Nov 2022 20:49:06 +0000 Received: from PAXPR10MB5037.EURPRD10.PROD.OUTLOOK.COM ([fe80::955a:f715:5319:7933]) by PAXPR10MB5037.EURPRD10.PROD.OUTLOOK.COM ([fe80::955a:f715:5319:7933%9]) with mapi id 15.20.5834.015; Sun, 20 Nov 2022 20:49:06 +0000 From: sven.schultschik@siemens.com To: cip-dev@lists.cip-project.org CC: jan.kiszka@siemens.com, Sven Schultschik Subject: [isar-cip-core][PATCH 3/8] Include optee into u-boot Date: Sun, 20 Nov 2022 21:47:06 +0100 Message-ID: <20221120204711.5826-4-sven.schultschik@siemens.com> X-Mailer: git-send-email 2.30.2 In-Reply-To: <20221120204711.5826-1-sven.schultschik@siemens.com> References: <20221120204711.5826-1-sven.schultschik@siemens.com> X-ClientProxiedBy: FR0P281CA0083.DEUP281.PROD.OUTLOOK.COM (2603:10a6:d10:1e::18) To PAXPR10MB5037.EURPRD10.PROD.OUTLOOK.COM (2603:10a6:102:210::11) MIME-Version: 1.0 X-MS-PublicTrafficType: Email X-MS-TrafficTypeDiagnostic: PAXPR10MB5037:EE_|DU0PR10MB7094:EE_ X-MS-Office365-Filtering-Correlation-Id: d91d028b-a7fa-4653-7a39-08dacb38aa2e X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam: BCL:0; X-Microsoft-Antispam-Message-Info: ZHea6dKvm6uL88lqm8qoIJk3QyTxWptvAu2tfDJt4QxXJGhzRMjxqw3IJBKX9x5TbPtHrPsQKZdGFzEo1L/rGqN4cU2oP4g2ASgN0q+Se2tXVBdax4B8rP72Mq0eGRudPRNUQAtAR7awNcXbVYWVZV7NFukSkpnnkMYPmBBxb65HOR3KmcMExQdxnBKCrRJoCFFoBRmyIxR1R5pZ44cBqXA36aWqPblauJ0Z5K9mJZ1SCbgxdfAugl/y0oYR5LhH5BF2kCEZVWJaV+OKKUSSO3pqZmAgTAIfcn74nu3HOnGw+m8UyIgZDOZ4MAXonb2EaijBWPF33a1CINhVlC3dhlVT6yAIhaRwm0nSKE94BEsiD/hrf/5uG+oAzKRjBEyLZi9GVs9QmPcd28wQjm1DHque0z8fbZELnbWOALPmfJKF33sgvJbiiFKoBdCi8QNoGcGsitw7tfj1SsIfURoiJ7zCy4gJrKgcyWn3M59y9a/Ij8NTnc3fmMy1dAx/y8ZhknahacLg1vJ1W0mcp+J7Ehdc/lhL8CpeLVCP0Bprw3fFp/UrVOXIh20V13iBfnMBzj5R3TcOUb2TCPhr107/ArnSlHyLaZmJzl/iaHaXgQIZNmRscOOtWO8o9sdgAIsBu21JLEEWKDQ6hO+qCcoVVA== X-Forefront-Antispam-Report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:PAXPR10MB5037.EURPRD10.PROD.OUTLOOK.COM;PTR:;CAT:NONE;SFS:(13230022)(4636009)(136003)(366004)(396003)(346002)(39860400002)(376002)(451199015)(2906002)(26005)(83380400001)(9686003)(86362001)(4326008)(6512007)(8676002)(66556008)(66476007)(82960400001)(66946007)(38100700002)(36756003)(41300700001)(6916009)(8936002)(5660300002)(316002)(107886003)(55236004)(478600001)(186003)(1076003)(6486002)(2616005)(6506007);DIR:OUT;SFP:1101; X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1 X-MS-Exchange-AntiSpam-MessageData-0: bXecD+bEhgxHMypXFmawqe6RTBAraw2gBqidXwZ+SwmynU/lHb++zT+YXs23R2tt4pXwvQa9K2aXnSNPDF6lNE024HbwnRkdgdQCjW9UUwNBgUctCo+r4P9o0wd1tfpt+JGCMwDKLxmEkzJtJCBpYgSrn9OoDKdJhjv/YFAd5ggSKfvUcIhz55fFoOTBsbH4ibzLl1s853ZYrgnVFBqJAgZUdR6d4tmDS9YVyjOGo94IHVVLW8+jg5cfFDbAnEB49DXF3ab5JewOQSGfnTnOmDgb6+au823OOSZpwCtMORaLYuL5FE4K0I7lzW+1swXBxb/eVXcgJoMSrONJRdpKQAxa5bXw14MBhk6HwlRkU06wWQ9qjWwIf33LNZLAJS3kLsixnGqQ09+xqgOU5Raf3uKpX6FgOOeSb7gQNS+EMK8mRtOTSS93NfeARxhuxqYRttMlcBGoWuLNa0dBlRA+Dyq/wYX0GRSkstIVASyW/lSNtu6RQWaJFRj4bFi14Q0gNWTrsZG5uJfwQuOXXz/04UP44m4dbLJdpdIM7veTm/XYCHlxKZ2bGp4HQjPlCsW7H4dnHMgN4TyAf67J5M1GkoC50iCnVRj07yu3+wG45xUMQ5Rc4mcGWOlvfNxpJA6Qqnei62c/gYstabtoU2uAkRPwW+4i/uNDQkixd2Kr7fM2yyj70zcOb3JMTJsYQSJSB9XDJJlHzC83PTDjTQ++HxW5TO8iwrbNHbgf6uMnamqAZFXf7zygWLykr/lt+AtQ0qM/6sYkCy9uu8gyZAOuSodo2E6h7AAh69FU3yjH5nV2nokKe6K6FhzMi56DvBY7h/DeCYJ9DGNZtw+H0AP2SJFY8VZtdgCLdXc9aKQ1H9OrQy9dK29eWXiTqroeqj3Sf5YY188m00hI4p1y+CefiEGhkmrov2ryy5Yequ+zKWBH0gKsDjiFxwPPamhvZPRPppWEeiddEFa+MfqBYNgIsZ4bgduI0P5NL2TYapUDwYsPrUI4RDr8MbFxVwuKcRMEml/ydgD1x+CpPbUwEkWRjB3nWoorRRgVS+4pweK0wUsShzNDnD4VY64zxPyzXK85rDVoGVywyKAX6H56j4vAtQMIAWuUGEjiYOkE9erKLdmTPOxSf9BbnKZEQj1y5pbxoRtLuaWY/quOm0j6qlGKQu7lenA3BIEtw2EMBzH34P+Lq8abQq7fUQs8a1UtOynbZmmuoTivSLQQm3dHNjJMarLzrDw4s29zQwZacjhndcRc7WlsSBGO7BpropXtuwHeDqb6UpZORhxQjbqClMwOJKy5W8fGzxTLcBIAvZJLSnI4rHzKD6dDTeSQB+cbRZJD4KPmBrjhvhDsJnNnfJ2o8sHSpdS54txO8urYhLVsgK5SSntBQwF1a7e3ndwKzT9TIZgOgu6lOo27age9G6sdXYTo1wXZeAfBskh+keJjLknT0hepbYkZvQxpsyCzOD05JrsFbSfbEVJqIUYny0WmkA73Y/l3PQRx42zNiOJtPPssm1JnQ3hSuqFV4/9UJ7e3epqYVry99aaCZxuolDSo4YBrkOwlnfnwMRI2lgT5dkN6jb49tqTUpzDLMSUZmor6U24ELwcgrnpYfpseizmN2Q== X-OriginatorOrg: siemens.com X-MS-Exchange-CrossTenant-Network-Message-Id: d91d028b-a7fa-4653-7a39-08dacb38aa2e X-MS-Exchange-CrossTenant-AuthSource: PAXPR10MB5037.EURPRD10.PROD.OUTLOOK.COM X-MS-Exchange-CrossTenant-AuthAs: Internal X-MS-Exchange-CrossTenant-OriginalArrivalTime: 20 Nov 2022 20:49:06.1064 (UTC) X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted X-MS-Exchange-CrossTenant-Id: 38ae3bcd-9579-4fd4-adda-b42e1495d55a X-MS-Exchange-CrossTenant-MailboxType: HOSTED X-MS-Exchange-CrossTenant-UserPrincipalName: tZqP180HoURcwTWkh98dD0i8aR4pfDG1iToQpqLOCgLC6Jfqo9rfrh/vzn0FCIUt/QFYpKRMy/Mk8QdH5gGtkum4Yt6eAq82LllKXltkF9Y= X-MS-Exchange-Transport-CrossTenantHeadersStamped: DU0PR10MB7094 List-Id: X-Webhook-Received: from li982-79.members.linode.com [45.33.32.79] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 20 Nov 2022 20:49:12 -0000 X-Groupsio-URL: https://lists.cip-project.org/g/cip-dev/message/10056 From: Sven Schultschik Optee is part of u-boot In the secureboot scenario to use optee and RPMB as secure storage. Signed-off-by: Sven Schultschik --- recipes-bsp/u-boot/files/secure-boot.cfg.tmpl | 9 ++++++++- recipes-bsp/u-boot/u-boot-qemu-common.inc | 2 ++ 2 files changed, 10 insertions(+), 1 deletion(-) diff --git a/recipes-bsp/u-boot/files/secure-boot.cfg.tmpl b/recipes-bsp/u-boot/files/secure-boot.cfg.tmpl index 956dcbf..2b75988 100644 --- a/recipes-bsp/u-boot/files/secure-boot.cfg.tmpl +++ b/recipes-bsp/u-boot/files/secure-boot.cfg.tmpl @@ -2,5 +2,12 @@ CONFIG_BOOTDELAY=-2 CONFIG_USE_BOOTCOMMAND=y CONFIG_BOOTCOMMAND="setenv scan_dev_for_boot 'if test -e ${devtype} ${devnum}:${distro_bootpart} efi/boot/boot${EFI_ARCH}.efi; then load ${devtype} ${devnum}:${distro_bootpart} ${kernel_addr_r} efi/boot/boot${EFI_ARCH}.efi; bootefi ${kernel_addr_r} ${fdtcontroladdr}; fi'; run distro_bootcmd; echo 'EFI Boot failed!'; sleep 1000; reset" -CONFIG_EFI_VARIABLES_PRESEED=y +CONFIG_EFI_VARIABLES_PRESEED=n CONFIG_EFI_SECURE_BOOT=y +### OPTEE config +CONFIG_CMD_OPTEE_RPMB=y +CONFIG_MMC=y +CONFIG_SUPPORT_EMMC_RPMB=y +CONFIG_TEE=y +CONFIG_OPTEE=y +CONFIG_EFI_MM_COMM_TEE=y diff --git a/recipes-bsp/u-boot/u-boot-qemu-common.inc b/recipes-bsp/u-boot/u-boot-qemu-common.inc index 0a9a15a..802fc50 100644 --- a/recipes-bsp/u-boot/u-boot-qemu-common.inc +++ b/recipes-bsp/u-boot/u-boot-qemu-common.inc @@ -13,6 +13,8 @@ require recipes-bsp/u-boot/u-boot-common.inc U_BOOT_BIN = "u-boot.bin" +DEPENDS_append_secureboot = " optee-os-${MACHINE}" + do_deploy[dirs] = "${DEPLOY_DIR_IMAGE}" do_deploy() { dpkg --fsys-tarfile "${WORKDIR}/u-boot-${MACHINE}_${PV}_${DISTRO_ARCH}.deb" | \ From patchwork Sun Nov 20 20:47:07 2022 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: "Schultschik, Sven" X-Patchwork-Id: 13050148 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id B7FAEC4332F for ; Sun, 20 Nov 2022 20:49:32 +0000 (UTC) Received: from EUR04-DB3-obe.outbound.protection.outlook.com (EUR04-DB3-obe.outbound.protection.outlook.com [40.107.6.68]) by mx.groups.io with SMTP id smtpd.web11.22483.1668977365343400805 for ; Sun, 20 Nov 2022 12:49:26 -0800 Authentication-Results: mx.groups.io; dkim=fail reason="body hash did not verify" header.i=@siemens.com header.s=selector2 header.b=Z0dusIhj; spf=pass (domain: siemens.com, ip: 40.107.6.68, mailfrom: sven.schultschik@siemens.com) ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=hL3BjsB7JLczsH3EMX3KQCXJm2271WWfi3CmLbQlIBXd4ZuQ2hL5uCnxDmigapawrbQIaqwVdLwO+xWv2EMf76UUd2aokuYl7o7tCuXLDmxKRrQkHTOxzMnspeWZSH2LDi6LAhXv75wi2fv9eOyCGXjnxiyqz25UMXiWNuHQOSDnbNGkPNsWGOK7ULeJM3DNqkpEY82yJRtYh7ldzZsncvRA3bNZPqTJ0eGzD79NlsdtT3x4iKsb5YSau2hMonTc+xrD95OAuFEc6inTmn2L+Q9CAJkQs4FdpO7mmV7FbaBsnZV5yrnKO63/YsLOSqO3qZkk5PA9iKmTLTXZO/23qQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=6Wo2Ra39gq/Pw+esZstrP0YXRbmJJKvHTKntf7zcmr4=; b=CF90JP/2UQMQmeXi3ERy4zhJZXPDcYE64GYUtNTYV5QvR+epC8C6Sc68+RsFHsD2ce17+BUbws+lw5xXJdEQcbiDMNT6XyhBuRRs/ORU26novfOXRq6bGLfngSYJFQHRamX4hTgOfma94AkLl/cQOHyg+gAdm20ElP/duN4eZdwcvnlWM3vhSqV3Abj5ojJBu5a20wZsSV0iwjZR6mv051uiMRhhQl/mYI0v1KnNGT3yL0nptBj43dpaRGNT/SZaGgQgRK8ZQdS7cg2dOp4GBDbyclEm/uZgE3MSCO0OHeSk3WXFVkqaNzXt8mczeYB93t7hBxx82Y16nTbtZcp6yw== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=siemens.com; dmarc=pass action=none header.from=siemens.com; dkim=pass header.d=siemens.com; arc=none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=siemens.com; s=selector2; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=6Wo2Ra39gq/Pw+esZstrP0YXRbmJJKvHTKntf7zcmr4=; b=Z0dusIhjZjSHfqOnXiL/SqWIfmS5nRuRWu1LyIWa5u9OAXuVEauQjFzyufzKJ/4AQAWopPXfRzSp8/GxRqmn06Pu5ChxHVIGKwFa516uqjcY+abIFxuBEOqt4pdxMtLOAv/B/YWxCAg/aa27iHrHq8tXLOszSMcwNx/iec+PqzJD8X9kaeF8hnArApn6FVUOYJP/44PAa9p6MiMyAEhINcqfIHH6Dy/NeWVmSsbQvvqXgVP4FUI/zAygOBqctXv6sR7g5hoqy+XUn2m7bW1w+Y6Xs5K6MmWyLhhSSZaW/tAhfySJDTIL8O+d7FirbXtjH+02rZ4Rh14cwUVVRdZ0vQ== Authentication-Results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=siemens.com; Received: from PAXPR10MB5037.EURPRD10.PROD.OUTLOOK.COM (2603:10a6:102:210::11) by DU0PR10MB7094.EURPRD10.PROD.OUTLOOK.COM (2603:10a6:10:42e::11) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.5834.11; Sun, 20 Nov 2022 20:49:21 +0000 Received: from PAXPR10MB5037.EURPRD10.PROD.OUTLOOK.COM ([fe80::955a:f715:5319:7933]) by PAXPR10MB5037.EURPRD10.PROD.OUTLOOK.COM ([fe80::955a:f715:5319:7933%9]) with mapi id 15.20.5834.015; Sun, 20 Nov 2022 20:49:21 +0000 From: sven.schultschik@siemens.com To: cip-dev@lists.cip-project.org CC: jan.kiszka@siemens.com, Sven Schultschik Subject: [isar-cip-core][PATCH 4/8] add u-boot patch for qemu to support RPMB Date: Sun, 20 Nov 2022 21:47:07 +0100 Message-ID: <20221120204711.5826-5-sven.schultschik@siemens.com> X-Mailer: git-send-email 2.30.2 In-Reply-To: <20221120204711.5826-1-sven.schultschik@siemens.com> References: <20221120204711.5826-1-sven.schultschik@siemens.com> X-ClientProxiedBy: FR3P281CA0127.DEUP281.PROD.OUTLOOK.COM (2603:10a6:d10:94::13) To PAXPR10MB5037.EURPRD10.PROD.OUTLOOK.COM (2603:10a6:102:210::11) MIME-Version: 1.0 X-MS-PublicTrafficType: Email X-MS-TrafficTypeDiagnostic: PAXPR10MB5037:EE_|DU0PR10MB7094:EE_ X-MS-Office365-Filtering-Correlation-Id: d726968c-b2b1-4287-74e9-08dacb38b1fc X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam: BCL:0; X-Microsoft-Antispam-Message-Info: sb/dP+cBv701FKpg/VRhTf2A8cAnnl3dgUhiflUgUumYCdV0h5mmByMjfsRiGxxE8tJ8iSnMK4BnHZRSVjsEAL2AwuoI/a4HA+sqKyPJHF74YqsaXt+omoqIt+imqvr2hGVt5grRBE4+kw4N7zX6SeQtYkSWp8vPoM+p7QVUFTzy/z47hM2ZRYwS9WYELFwLnEwW2s7gZpp6NLYGih0P0CUWNjF2ik7z9+HijufYQ05CVJYe1hypAH/fEgo/tq7/G1aFEmwvoWAvK/EujUV9Tc7tGHMcFiCL2gZ6IagWxyWscYY8FaWeYoSmsGGtCQRERmhTu2cbxaZnCnnysGCHO01D8vu2lW1vgX22bbeeerdfkOatmxDXTpoUvxYM/NcA6/0UL+iAYxlQR6obuaRM3RV20gHMck7e9nFa8htIw0nab+A0JBUwVdXWbr5rMmt3Lwc0teXeIfXcBGL18jzYfczwLtKX//rPzyl95IUL8/PcobB2HwP8ZA/405WCInJaRjmHhLjVqdEY0vZy/FkGP6vZCXZ8z4znAeTi3BGRLLcF/MGuOT/4JVXpOVrof+WLjoYMb+9vqk6hX3KacsrO+iaDWMda9gQI1gkr1ygIc0CNfrv5mfhk+1MZZ0peTUQH5FkOEJ+jGUshSw8+cHEV6A== X-Forefront-Antispam-Report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:PAXPR10MB5037.EURPRD10.PROD.OUTLOOK.COM;PTR:;CAT:NONE;SFS:(13230022)(4636009)(136003)(366004)(396003)(346002)(39860400002)(376002)(451199015)(2906002)(26005)(83380400001)(9686003)(86362001)(4326008)(6512007)(8676002)(66556008)(66476007)(82960400001)(66946007)(38100700002)(36756003)(41300700001)(30864003)(6916009)(8936002)(5660300002)(316002)(107886003)(55236004)(478600001)(186003)(1076003)(6486002)(6666004)(2616005)(6506007)(579004);DIR:OUT;SFP:1101; X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1 X-MS-Exchange-AntiSpam-MessageData-0: wNktTPfl5K9v3ERqBTTz71Zttv4FA6gtJZKB6vLaQwvL4Euh1IhGHO0kGp3i3ZuWrJIdN0URVBEETCbLd3UF7yiwc4Ned/wlRPN27qSlBMYdl/h4WHX8mA5h7oO+nYrxTNbPnNkjzMYpyDlVD+hQQVvmtquRRzffSsaBV1YJ90Wq9NcHgcokvTfV/3dNGATo/jya96yP7DmQwBJkVEdwjX6cv08MIYPlKnm7WHEoN+BCa6wsAW5NUb1oki7VjYTOFClKs50tL/l9dSbT/9qce9do0tm3jhRcZ9QmMbwztNOknrlSJLtzBge7ZgNAk8TFZ5LpQewzaG/MdkK2BRsEq84RMdnJQSfw//T5c+jFblC6mOwN+dBstiCtPuqMQZORu0loKY+9QwW2irYolKCbwrPTY7mZifk4503nOXHPfilGjKIRTR0bO4Rlq29UtrBz0RbMcDzbXQSSlbP4hz/io+Q7pRN18w95+lmFZsrBKK2MOhjn8B2WMIEvAU6Yxz2kezUsjpp8USlkmYirLic8MKqOGnvIimreY3oGzAQ/jp3MBWcR+3mppSm18i8U7ZeQ7BUur/h69OJZl+VIN0WZidkAp84Gub+15GC3Lvz5XaOIqf4YPE7tXGjCEjnfSjxUmL97mt20zX82SCn5oJsdcvbxsAhWnL4sTHtFgZ9102kGTtocY5wofRgxB6IMA7M6mORXX74T3wzBfQmpRx58pLWk2IZrn5KJMc8qmlKVisu7xlXjs4x+SFYLQibB+38FbMMCpI7JmxpB2IKwJvZjbqtZ1HuEWVmrwsWYgX/3iYrp+KAj4FwAz6a9MF4ko/yPtOUR3VxoTKdsf6kna5p+NfpVrXX2c18+H5wZ2g6KtMsIgYkAzV/r9m4zEI1uN/znoPAYcasp/htbUUkXxi6Ics/1K4DQK1p3Iczyvpc5yEhEdAvnPB7K6W2d13wYlA1y+OhIzW2Q3aHSZDeU3WHmjQsjgRUTtYVuzb4AxdMYhdrI3wYxjpm8lWDGaaIcCnoBf89et3dT/SAPlkM1qd7uPW4qUaKo+eQAwPAOeFr0JT1ZEAPBCin1zlmbc5V+O8fyiRcUmB8Mwvxez6OmhRqguYhBHluai1MzjaQkup9KHuohi1oJAwyt1jOM4BJN7vZaysEe4cWyMDm9qieREh7O43nxnmjwuvj0Hp48xA4WNs0H57JDu8LVeXbncb0YOsiwye/RDUjlSzOzHL5Z3qtluHsRo+NRmQw/o4rMEQi2NHt0A5GIWrdQK8X5zURT+yIk0FgSvyq0uu2X8sMMbam6nTK1nrF9BhzrJpAoBiFc6VI99MBNZwUz9UheknZR5dr37jOaT8PeAAO1BAmxlHBxgTFDz1Yk9VkUQ/1umSw1McBcRKStx26LaBRGIHQ//IWXNUwAn0o5FG3y5dKGrFW+P9e1CVKtfpSHhvznvsnw/gmIXR2aTXpb2f2mmA+0MmIG2S0MWAj8ZmhKPeALg8hKWQGGAX2OmMYpGgwNa+bjsmlacvTYemeDpgLICB9e+Q8rsy2XalQD6WnwIisX7Db/7b9V2ylpDkI8caHBt9Q6Yx74mvXzV0Z+TzdR0PfhWOEpAW4Ur6YFSvWVJFAHNOnQrA== X-OriginatorOrg: siemens.com X-MS-Exchange-CrossTenant-Network-Message-Id: d726968c-b2b1-4287-74e9-08dacb38b1fc X-MS-Exchange-CrossTenant-AuthSource: PAXPR10MB5037.EURPRD10.PROD.OUTLOOK.COM X-MS-Exchange-CrossTenant-AuthAs: Internal X-MS-Exchange-CrossTenant-OriginalArrivalTime: 20 Nov 2022 20:49:20.8579 (UTC) X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted X-MS-Exchange-CrossTenant-Id: 38ae3bcd-9579-4fd4-adda-b42e1495d55a X-MS-Exchange-CrossTenant-MailboxType: HOSTED X-MS-Exchange-CrossTenant-UserPrincipalName: BEwM2I17jhkyDssjUZl5CF8oPR55AwT9LPRrt65F1tFIjKXAA83AjmMcBwZuoMXm2dpafTd9TlZANO+grcn47bMnXPPR8dmE0O57MTGaMC4= X-MS-Exchange-Transport-CrossTenantHeadersStamped: DU0PR10MB7094 List-Id: X-Webhook-Received: from li982-79.members.linode.com [45.33.32.79] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 20 Nov 2022 20:49:32 -0000 X-Groupsio-URL: https://lists.cip-project.org/g/cip-dev/message/10057 From: Sven Schultschik Qemu itself is missing a implemented emulation of an RPBM (replay protected memory) which is part of an emmc. Therefore currently a u-boot patch, which adds a RPMB emulation, is needed which breaks the u-boot hardware support. The patch is only included into the qemu u-boot recipes and can be removed if there is an official qemu rpmb emulation, which currently does not have any ETA. Signed-off-by: Sven Schultschik --- ...hack.-Breaks-proper-hardware-support.patch | 1375 +++++++++++++++++ recipes-bsp/u-boot/u-boot-qemu-common.inc | 3 + 2 files changed, 1378 insertions(+) create mode 100644 recipes-bsp/u-boot/files/0002-rpmb-emulation-hack.-Breaks-proper-hardware-support.patch diff --git a/recipes-bsp/u-boot/files/0002-rpmb-emulation-hack.-Breaks-proper-hardware-support.patch b/recipes-bsp/u-boot/files/0002-rpmb-emulation-hack.-Breaks-proper-hardware-support.patch new file mode 100644 index 0000000..26266b5 --- /dev/null +++ b/recipes-bsp/u-boot/files/0002-rpmb-emulation-hack.-Breaks-proper-hardware-support.patch @@ -0,0 +1,1375 @@ +From a4179f663673dbfa48f79761acc3ff781ee9b2b8 Mon Sep 17 00:00:00 2001 +From: Ilias Apalodimas +Date: Thu, 12 Nov 2020 09:44:54 +0200 +Subject: [PATCH] irpmb patch hack + +Signed-off-by: Ilias Apalodimas +--- + arch/arm/include/asm/gpio.h | 3 +- + arch/arm/include/asm/ioctl.h | 1 + + configs/qemu_tfa_mm_defconfig | 53 ++++ + drivers/tee/optee/Makefile | 1 + + drivers/tee/optee/hmac_sha2.c | 126 ++++++++ + drivers/tee/optee/hmac_sha2.h | 74 +++++ + drivers/tee/optee/rpmb.c | 27 +- + drivers/tee/optee/rpmb.h | 1 + + drivers/tee/optee/rpmb_emu.c | 563 ++++++++++++++++++++++++++++++++++ + drivers/tee/optee/rpmb_emu.h | 141 +++++++++ + drivers/tee/optee/sha2.c | 249 +++++++++++++++ + drivers/tee/optee/sha2.h | 75 +++++ + 12 files changed, 1292 insertions(+), 22 deletions(-) + create mode 100644 arch/arm/include/asm/ioctl.h + create mode 100644 configs/qemu_tfa_mm_defconfig + create mode 100644 drivers/tee/optee/hmac_sha2.c + create mode 100644 drivers/tee/optee/hmac_sha2.h + create mode 100644 drivers/tee/optee/rpmb.h + create mode 100644 drivers/tee/optee/rpmb_emu.c + create mode 100644 drivers/tee/optee/rpmb_emu.h + create mode 100644 drivers/tee/optee/sha2.c + create mode 100644 drivers/tee/optee/sha2.h + +diff --git a/arch/arm/include/asm/ioctl.h b/arch/arm/include/asm/ioctl.h +new file mode 100644 +index 000000000000..b279fe06dfe5 +--- /dev/null ++++ b/arch/arm/include/asm/ioctl.h +@@ -0,0 +1 @@ ++#include +diff --git a/drivers/tee/optee/Makefile b/drivers/tee/optee/Makefile +index 928d3f80027f..28108536d231 100644 +--- a/drivers/tee/optee/Makefile ++++ b/drivers/tee/optee/Makefile +@@ -3,3 +3,4 @@ + obj-y += core.o + obj-y += supplicant.o + obj-$(CONFIG_SUPPORT_EMMC_RPMB) += rpmb.o ++obj-y += sha2.o hmac_sha2.o rpmb_emu.o rpmb.o +diff --git a/drivers/tee/optee/hmac_sha2.c b/drivers/tee/optee/hmac_sha2.c +new file mode 100644 +index 000000000000..61b24b128f1d +--- /dev/null ++++ b/drivers/tee/optee/hmac_sha2.c +@@ -0,0 +1,126 @@ ++/* ++ * HMAC-SHA-224/256/384/512 implementation ++ * Last update: 06/15/2005 ++ * Issue date: 06/15/2005 ++ * ++ * Copyright (C) 2005 Olivier Gay ++ * All rights reserved. ++ * ++ * Copyright (c) 2016, Linaro Limited ++ * All rights reserved. ++ * ++ * Redistribution and use in source and binary forms, with or without ++ * modification, are permitted provided that the following conditions ++ * are met: ++ * 1. Redistributions of source code must retain the above copyright ++ * notice, this list of conditions and the following disclaimer. ++ * 2. Redistributions in binary form must reproduce the above copyright ++ * notice, this list of conditions and the following disclaimer in the ++ * documentation and/or other materials provided with the distribution. ++ * 3. Neither the name of the project nor the names of its contributors ++ * may be used to endorse or promote products derived from this software ++ * without specific prior written permission. ++ * ++ * THIS SOFTWARE IS PROVIDED BY THE PROJECT AND CONTRIBUTORS ``AS IS'' AND ++ * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE ++ * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ++ * ARE DISCLAIMED. IN NO EVENT SHALL THE PROJECT OR CONTRIBUTORS BE LIABLE ++ * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL ++ * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS ++ * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) ++ * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT ++ * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY ++ * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF ++ * SUCH DAMAGE. ++ */ ++ ++#include ++ ++#include "hmac_sha2.h" ++ ++/* HMAC-SHA-256 functions */ ++ ++void hmac_sha256_init(hmac_sha256_ctx *ctx, const unsigned char *key, ++ unsigned int key_size) ++{ ++ unsigned int fill = 0; ++ unsigned int num = 0; ++ const unsigned char *key_used = NULL; ++ unsigned char key_temp[SHA256_DIGEST_SIZE] = { 0 }; ++ int i = 0; ++ ++ if (key_size == SHA256_BLOCK_SIZE) { ++ key_used = key; ++ num = SHA256_BLOCK_SIZE; ++ } else { ++ if (key_size > SHA256_BLOCK_SIZE){ ++ num = SHA256_DIGEST_SIZE; ++ sha256(key, key_size, key_temp); ++ key_used = key_temp; ++ } else { /* key_size > SHA256_BLOCK_SIZE */ ++ key_used = key; ++ num = key_size; ++ } ++ fill = SHA256_BLOCK_SIZE - num; ++ ++ memset(ctx->block_ipad + num, 0x36, fill); ++ memset(ctx->block_opad + num, 0x5c, fill); ++ } ++ ++ for (i = 0; i < (int) num; i++) { ++ ctx->block_ipad[i] = key_used[i] ^ 0x36; ++ ctx->block_opad[i] = key_used[i] ^ 0x5c; ++ } ++ ++ sha256_init(&ctx->ctx_inside); ++ sha256_update_tee(&ctx->ctx_inside, ctx->block_ipad, SHA256_BLOCK_SIZE); ++ ++ sha256_init(&ctx->ctx_outside); ++ sha256_update_tee(&ctx->ctx_outside, ctx->block_opad, ++ SHA256_BLOCK_SIZE); ++ ++ /* for hmac_reinit */ ++ memcpy(&ctx->ctx_inside_reinit, &ctx->ctx_inside, ++ sizeof(sha256_ctx)); ++ memcpy(&ctx->ctx_outside_reinit, &ctx->ctx_outside, ++ sizeof(sha256_ctx)); ++} ++ ++void hmac_sha256_reinit(hmac_sha256_ctx *ctx) ++{ ++ memcpy(&ctx->ctx_inside, &ctx->ctx_inside_reinit, ++ sizeof(sha256_ctx)); ++ memcpy(&ctx->ctx_outside, &ctx->ctx_outside_reinit, ++ sizeof(sha256_ctx)); ++} ++ ++void hmac_sha256_update(hmac_sha256_ctx *ctx, const unsigned char *message, ++ unsigned int message_len) ++{ ++ sha256_update_tee(&ctx->ctx_inside, message, message_len); ++} ++ ++void hmac_sha256_final(hmac_sha256_ctx *ctx, unsigned char *mac, ++ unsigned int mac_size) ++{ ++ unsigned char digest_inside[SHA256_DIGEST_SIZE] = { 0 }; ++ unsigned char mac_temp[SHA256_DIGEST_SIZE] = { 0 }; ++ ++ sha256_final(&ctx->ctx_inside, digest_inside); ++ sha256_update_tee(&ctx->ctx_outside, digest_inside, SHA256_DIGEST_SIZE); ++ sha256_final(&ctx->ctx_outside, mac_temp); ++ memcpy(mac, mac_temp, mac_size); ++} ++ ++void hmac_sha256(const unsigned char *key, unsigned int key_size, ++ const unsigned char *message, unsigned int message_len, ++ unsigned char *mac, unsigned mac_size) ++{ ++ hmac_sha256_ctx ctx; ++ ++ memset(&ctx, 0, sizeof(ctx)); ++ ++ hmac_sha256_init(&ctx, key, key_size); ++ hmac_sha256_update(&ctx, message, message_len); ++ hmac_sha256_final(&ctx, mac, mac_size); ++} +diff --git a/drivers/tee/optee/hmac_sha2.h b/drivers/tee/optee/hmac_sha2.h +new file mode 100644 +index 000000000000..1044524d75c5 +--- /dev/null ++++ b/drivers/tee/optee/hmac_sha2.h +@@ -0,0 +1,74 @@ ++/* ++ * HMAC-SHA-224/256/384/512 implementation ++ * Last update: 06/15/2005 ++ * Issue date: 06/15/2005 ++ * ++ * Copyright (C) 2005 Olivier Gay ++ * All rights reserved. ++ * ++ * Copyright (c) 2016, Linaro Limited ++ * All rights reserved. ++ * ++ * Redistribution and use in source and binary forms, with or without ++ * modification, are permitted provided that the following conditions ++ * are met: ++ * 1. Redistributions of source code must retain the above copyright ++ * notice, this list of conditions and the following disclaimer. ++ * 2. Redistributions in binary form must reproduce the above copyright ++ * notice, this list of conditions and the following disclaimer in the ++ * documentation and/or other materials provided with the distribution. ++ * 3. Neither the name of the project nor the names of its contributors ++ * may be used to endorse or promote products derived from this software ++ * without specific prior written permission. ++ * ++ * THIS SOFTWARE IS PROVIDED BY THE PROJECT AND CONTRIBUTORS ``AS IS'' AND ++ * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE ++ * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ++ * ARE DISCLAIMED. IN NO EVENT SHALL THE PROJECT OR CONTRIBUTORS BE LIABLE ++ * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL ++ * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS ++ * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) ++ * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT ++ * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY ++ * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF ++ * SUCH DAMAGE. ++ */ ++ ++#ifndef HMAC_SHA2_H ++#define HMAC_SHA2_H ++ ++#include "sha2.h" ++ ++#ifdef __cplusplus ++extern "C" { ++#endif ++ ++typedef struct { ++ sha256_ctx ctx_inside; ++ sha256_ctx ctx_outside; ++ ++ /* for hmac_reinit */ ++ sha256_ctx ctx_inside_reinit; ++ sha256_ctx ctx_outside_reinit; ++ ++ unsigned char block_ipad[SHA256_BLOCK_SIZE]; ++ unsigned char block_opad[SHA256_BLOCK_SIZE]; ++} hmac_sha256_ctx; ++ ++void hmac_sha256_init(hmac_sha256_ctx *ctx, const unsigned char *key, ++ unsigned int key_size); ++void hmac_sha256_reinit(hmac_sha256_ctx *ctx); ++void hmac_sha256_update(hmac_sha256_ctx *ctx, const unsigned char *message, ++ unsigned int message_len); ++void hmac_sha256_final(hmac_sha256_ctx *ctx, unsigned char *mac, ++ unsigned int mac_size); ++void hmac_sha256(const unsigned char *key, unsigned int key_size, ++ const unsigned char *message, unsigned int message_len, ++ unsigned char *mac, unsigned mac_size); ++ ++#ifdef __cplusplus ++} ++#endif ++ ++#endif /* !HMAC_SHA2_H */ ++ +diff --git a/drivers/tee/optee/rpmb.c b/drivers/tee/optee/rpmb.c +index 0804fc963cf5..275f2112f102 100644 +--- a/drivers/tee/optee/rpmb.c ++++ b/drivers/tee/optee/rpmb.c +@@ -12,35 +12,15 @@ + + #include "optee_msg.h" + #include "optee_private.h" ++#include "rpmb_emu.h" + + /* + * Request and response definitions must be in sync with the secure side of + * OP-TEE. + */ + +-/* Request */ +-struct rpmb_req { +- u16 cmd; +-#define RPMB_CMD_DATA_REQ 0x00 +-#define RPMB_CMD_GET_DEV_INFO 0x01 +- u16 dev_id; +- u16 block_count; +- /* Optional data frames (rpmb_data_frame) follow */ +-}; +- + #define RPMB_REQ_DATA(req) ((void *)((struct rpmb_req *)(req) + 1)) + +-/* Response to device info request */ +-struct rpmb_dev_info { +- u8 cid[16]; +- u8 rpmb_size_mult; /* EXT CSD-slice 168: RPMB Size */ +- u8 rel_wr_sec_c; /* EXT CSD-slice 222: Reliable Write Sector */ +- /* Count */ +- u8 ret_code; +-#define RPMB_CMD_GET_DEV_INFO_RET_OK 0x00 +-#define RPMB_CMD_GET_DEV_INFO_RET_ERROR 0x01 +-}; +- + static void release_mmc(struct optee_private *priv) + { + int rc; +@@ -175,8 +155,13 @@ void optee_suppl_cmd_rpmb(struct udevice *dev, struct optee_msg_arg *arg) + rsp_buf = (u8 *)rsp_shm->addr + arg->params[1].u.rmem.offs; + rsp_size = arg->params[1].u.rmem.size; + ++#ifdef EMU + arg->ret = rpmb_process_request(dev_get_priv(dev), req_buf, req_size, + rsp_buf, rsp_size); ++#else ++ arg->ret = rpmb_process_request_emu(req_buf, req_size, rsp_buf, ++ rsp_size); ++#endif + } + + void optee_suppl_rpmb_release(struct udevice *dev) +diff --git a/drivers/tee/optee/rpmb.h b/drivers/tee/optee/rpmb.h +new file mode 100644 +index 000000000000..8b137891791f +--- /dev/null ++++ b/drivers/tee/optee/rpmb.h +@@ -0,0 +1 @@ ++ +diff --git a/drivers/tee/optee/rpmb_emu.c b/drivers/tee/optee/rpmb_emu.c +new file mode 100644 +index 000000000000..629f36ee6b29 +--- /dev/null ++++ b/drivers/tee/optee/rpmb_emu.c +@@ -0,0 +1,563 @@ ++// SPDX-License-Identifier: BSD-2-Clause ++/* ++ * Copyright (c) 2020 Linaro Limited ++ */ ++ ++#include ++#include ++#include ++#include ++#include ++#include ++#include ++ ++#include "optee_msg.h" ++#include "optee_private.h" ++#include "sha2.h" ++#include "hmac_sha2.h" ++#include "rpmb_emu.h" ++ ++static struct rpmb_emu rpmb_emu = { ++ .size = EMU_RPMB_SIZE_BYTES ++}; ++ ++static struct rpmb_emu *mem_for_fd(int fd) ++{ ++ static int sfd = -1; ++ ++ if (sfd == -1) ++ sfd = fd; ++ if (sfd != fd) { ++ printf("Emulating more than 1 RPMB partition is not supported\n"); ++ return NULL; ++ } ++ ++ return &rpmb_emu; ++} ++ ++#if (DEBUGLEVEL >= TRACE_FLOW) ++static void dump_blocks(size_t startblk, size_t numblk, uint8_t *ptr, ++ bool to_mmc) ++{ ++ char msg[100] = { 0 }; ++ size_t i = 0; ++ ++ for (i = 0; i < numblk; i++) { ++ snprintf(msg, sizeof(msg), "%s MMC block %zu", ++ to_mmc ? "Write" : "Read", startblk + i); ++ //print_hex_dump_bytes("", DUMP_PREFIX_OFFSET, ptr, 256); ++ ptr += 256; ++ } ++} ++#else ++static void dump_blocks(size_t startblk, size_t numblk, uint8_t *ptr, ++ bool to_mmc) ++{ ++ (void)startblk; ++ (void)numblk; ++ (void)ptr; ++ (void)to_mmc; ++} ++#endif ++ ++#define CUC(x) ((const unsigned char *)(x)) ++static void hmac_update_frm(hmac_sha256_ctx *ctx, struct rpmb_data_frame *frm) ++{ ++ hmac_sha256_update(ctx, CUC(frm->data), 256); ++ hmac_sha256_update(ctx, CUC(frm->nonce), 16); ++ hmac_sha256_update(ctx, CUC(&frm->write_counter), 4); ++ hmac_sha256_update(ctx, CUC(&frm->address), 2); ++ hmac_sha256_update(ctx, CUC(&frm->block_count), 2); ++ hmac_sha256_update(ctx, CUC(&frm->op_result), 2); ++ hmac_sha256_update(ctx, CUC(&frm->msg_type), 2); ++} ++ ++static bool is_hmac_valid(struct rpmb_emu *mem, struct rpmb_data_frame *frm, ++ size_t nfrm) ++{ ++ uint8_t mac[32] = { 0 }; ++ size_t i = 0; ++ hmac_sha256_ctx ctx; ++ ++ memset(&ctx, 0, sizeof(ctx)); ++ ++ if (!mem->key_set) { ++ printf("Cannot check MAC (key not set)\n"); ++ return false; ++ } ++ ++ hmac_sha256_init(&ctx, mem->key, sizeof(mem->key)); ++ for (i = 0; i < nfrm; i++, frm++) ++ hmac_update_frm(&ctx, frm); ++ frm--; ++ hmac_sha256_final(&ctx, mac, 32); ++ ++ if (memcmp(mac, frm->key_mac, 32)) { ++ printf("Invalid MAC\n"); ++ return false; ++ } ++ return true; ++} ++ ++static uint16_t gen_msb1st_result(uint8_t byte) ++{ ++ return (uint16_t)byte << 8; ++} ++ ++static uint16_t compute_hmac(struct rpmb_emu *mem, struct rpmb_data_frame *frm, ++ size_t nfrm) ++{ ++ size_t i = 0; ++ hmac_sha256_ctx ctx; ++ ++ memset(&ctx, 0, sizeof(ctx)); ++ ++ if (!mem->key_set) { ++ printf("Cannot compute MAC (key not set)\n"); ++ return gen_msb1st_result(RPMB_RESULT_AUTH_KEY_NOT_PROGRAMMED); ++ } ++ ++ hmac_sha256_init(&ctx, mem->key, sizeof(mem->key)); ++ for (i = 0; i < nfrm; i++, frm++) ++ hmac_update_frm(&ctx, frm); ++ frm--; ++ hmac_sha256_final(&ctx, frm->key_mac, 32); ++ ++ return gen_msb1st_result(RPMB_RESULT_OK); ++} ++ ++static uint16_t ioctl_emu_mem_transfer(struct rpmb_emu *mem, ++ struct rpmb_data_frame *frm, ++ size_t nfrm, int to_mmc) ++{ ++ size_t start = mem->last_op.address * 256; ++ size_t size = nfrm * 256; ++ size_t i = 0; ++ uint8_t *memptr = NULL; ++ ++ if (start > mem->size || start + size > mem->size) { ++ printf("Transfer bounds exceeed emulated memory\n"); ++ return gen_msb1st_result(RPMB_RESULT_ADDRESS_FAILURE); ++ } ++ if (to_mmc && !is_hmac_valid(mem, frm, nfrm)) ++ return gen_msb1st_result(RPMB_RESULT_AUTH_FAILURE); ++ ++ //printf("Transferring %zu 256-byte data block%s %s MMC (block offset=%zu)", ++ //nfrm, (nfrm > 1) ? "s" : "", to_mmc ? "to" : "from", start / 256); ++ for (i = 0; i < nfrm; i++) { ++ memptr = mem->buf + start + i * 256; ++ if (to_mmc) { ++ memcpy(memptr, frm[i].data, 256); ++ mem->write_counter++; ++ frm[i].write_counter = htonl(mem->write_counter); ++ frm[i].msg_type = ++ htons(RPMB_MSG_TYPE_RESP_AUTH_DATA_WRITE); ++ } else { ++ memcpy(frm[i].data, memptr, 256); ++ frm[i].msg_type = ++ htons(RPMB_MSG_TYPE_RESP_AUTH_DATA_READ); ++ frm[i].address = htons(mem->last_op.address); ++ frm[i].block_count = nfrm; ++ memcpy(frm[i].nonce, mem->nonce, 16); ++ } ++ frm[i].op_result = gen_msb1st_result(RPMB_RESULT_OK); ++ } ++ dump_blocks(mem->last_op.address, nfrm, mem->buf + start, to_mmc); ++ ++ if (!to_mmc) ++ compute_hmac(mem, frm, nfrm); ++ ++ return gen_msb1st_result(RPMB_RESULT_OK); ++} ++ ++static void ioctl_emu_get_write_result(struct rpmb_emu *mem, ++ struct rpmb_data_frame *frm) ++{ ++ frm->msg_type = htons(RPMB_MSG_TYPE_RESP_AUTH_DATA_WRITE); ++ frm->op_result = mem->last_op.op_result; ++ frm->address = htons(mem->last_op.address); ++ frm->write_counter = htonl(mem->write_counter); ++ compute_hmac(mem, frm, 1); ++} ++ ++static uint16_t ioctl_emu_setkey(struct rpmb_emu *mem, ++ struct rpmb_data_frame *frm) ++{ ++ if (mem->key_set) { ++ printf("Key already set\n"); ++ return gen_msb1st_result(RPMB_RESULT_GENERAL_FAILURE); ++ } ++ print_hex_dump_bytes("Setting Key:", DUMP_PREFIX_OFFSET, frm->key_mac, ++ 32); ++ memcpy(mem->key, frm->key_mac, 32); ++ mem->key_set = true; ++ ++ return gen_msb1st_result(RPMB_RESULT_OK); ++} ++ ++static void ioctl_emu_get_keyprog_result(struct rpmb_emu *mem, ++ struct rpmb_data_frame *frm) ++{ ++ frm->msg_type = ++ htons(RPMB_MSG_TYPE_RESP_AUTH_KEY_PROGRAM); ++ frm->op_result = mem->last_op.op_result; ++} ++ ++static void ioctl_emu_read_ctr(struct rpmb_emu *mem, ++ struct rpmb_data_frame *frm) ++{ ++ printf("Reading counter\n"); ++ frm->msg_type = htons(RPMB_MSG_TYPE_RESP_WRITE_COUNTER_VAL_READ); ++ frm->write_counter = htonl(mem->write_counter); ++ memcpy(frm->nonce, mem->nonce, 16); ++ frm->op_result = compute_hmac(mem, frm, 1); ++} ++ ++static uint32_t read_cid(uint16_t dev_id, uint8_t *cid) ++{ ++ /* Taken from an actual eMMC chip */ ++ static const uint8_t test_cid[] = { ++ /* MID (Manufacturer ID): Micron */ ++ 0xfe, ++ /* CBX (Device/BGA): BGA */ ++ 0x01, ++ /* OID (OEM/Application ID) */ ++ 0x4e, ++ /* PNM (Product name) "MMC04G" */ ++ 0x4d, 0x4d, 0x43, 0x30, 0x34, 0x47, ++ /* PRV (Product revision): 4.2 */ ++ 0x42, ++ /* PSN (Product serial number) */ ++ 0xc8, 0xf6, 0x55, 0x2a, ++ /* ++ * MDT (Manufacturing date): ++ * June, 2014 ++ */ ++ 0x61, ++ /* (CRC7 (0xA) << 1) | 0x1 */ ++ 0x15 ++ }; ++ ++ (void)dev_id; ++ memcpy(cid, test_cid, sizeof(test_cid)); ++ ++ return TEE_SUCCESS; ++} ++ ++static void ioctl_emu_set_ext_csd(uint8_t *ext_csd) ++{ ++ ext_csd[168] = EMU_RPMB_SIZE_MULT; ++ ext_csd[222] = EMU_RPMB_REL_WR_SEC_C; ++} ++ ++/* A crude emulation of the MMC ioctls we need for RPMB */ ++static int ioctl_emu(int fd, unsigned long request, ...) ++{ ++ struct mmc_ioc_cmd *cmd = NULL; ++ struct rpmb_data_frame *frm = NULL; ++ uint16_t msg_type = 0; ++ struct rpmb_emu *mem = mem_for_fd(fd); ++ va_list ap; ++ ++ if (request != MMC_IOC_CMD) { ++ printf("Unsupported ioctl: 0x%lx\n", request); ++ return -1; ++ } ++ if (!mem) ++ return -1; ++ ++ va_start(ap, request); ++ cmd = va_arg(ap, struct mmc_ioc_cmd *); ++ va_end(ap); ++ ++ switch (cmd->opcode) { ++ case MMC_SEND_EXT_CSD: ++ ioctl_emu_set_ext_csd((uint8_t *)(uintptr_t)cmd->data_ptr); ++ break; ++ ++ case MMC_WRITE_MULTIPLE_BLOCK: ++ frm = (struct rpmb_data_frame *)(uintptr_t)cmd->data_ptr; ++ msg_type = ntohs(frm->msg_type); ++ ++ switch (msg_type) { ++ case RPMB_MSG_TYPE_REQ_AUTH_KEY_PROGRAM: ++ mem->last_op.msg_type = msg_type; ++ mem->last_op.op_result = ioctl_emu_setkey(mem, frm); ++ break; ++ ++ case RPMB_MSG_TYPE_REQ_AUTH_DATA_WRITE: ++ mem->last_op.msg_type = msg_type; ++ mem->last_op.address = ntohs(frm->address); ++ mem->last_op.op_result = ++ ioctl_emu_mem_transfer(mem, frm, ++ cmd->blocks, 1); ++ break; ++ ++ case RPMB_MSG_TYPE_REQ_WRITE_COUNTER_VAL_READ: ++ case RPMB_MSG_TYPE_REQ_AUTH_DATA_READ: ++ memcpy(mem->nonce, frm->nonce, 16); ++ mem->last_op.msg_type = msg_type; ++ mem->last_op.address = ntohs(frm->address); ++ break; ++ default: ++ break; ++ } ++ break; ++ ++ case MMC_READ_MULTIPLE_BLOCK: ++ frm = (struct rpmb_data_frame *)(uintptr_t)cmd->data_ptr; ++ msg_type = ntohs(frm->msg_type); ++ ++ switch (mem->last_op.msg_type) { ++ case RPMB_MSG_TYPE_REQ_AUTH_KEY_PROGRAM: ++ ioctl_emu_get_keyprog_result(mem, frm); ++ break; ++ ++ case RPMB_MSG_TYPE_REQ_AUTH_DATA_WRITE: ++ ioctl_emu_get_write_result(mem, frm); ++ break; ++ ++ case RPMB_MSG_TYPE_REQ_WRITE_COUNTER_VAL_READ: ++ ioctl_emu_read_ctr(mem, frm); ++ break; ++ ++ case RPMB_MSG_TYPE_REQ_AUTH_DATA_READ: ++ ioctl_emu_mem_transfer(mem, frm, cmd->blocks, 0); ++ break; ++ ++ default: ++ printf("Unexpected\n"); ++ break; ++ } ++ break; ++ ++ default: ++ printf("Unsupported ioctl opcode 0x%08x\n", cmd->opcode); ++ return -1; ++ } ++ ++ return 0; ++} ++ ++static int mmc_rpmb_fd(uint16_t dev_id) ++{ ++ (void)dev_id; ++ ++ /* Any value != -1 will do in test mode */ ++ return 0; ++} ++ ++static int mmc_fd(uint16_t dev_id) ++{ ++ (void)dev_id; ++ ++ return 0; ++} ++ ++static void close_mmc_fd(int fd) ++{ ++ (void)fd; ++} ++ ++/* ++ * Extended CSD Register is 512 bytes and defines device properties ++ * and selected modes. ++ */ ++static uint32_t read_ext_csd(int fd, uint8_t *ext_csd) ++{ ++ int st = 0; ++ struct mmc_ioc_cmd cmd = { ++ .blksz = 512, ++ .blocks = 1, ++ .flags = MMC_RSP_R1 | MMC_CMD_ADTC, ++ .opcode = MMC_SEND_EXT_CSD, ++ }; ++ ++ mmc_ioc_cmd_set_data(cmd, ext_csd); ++ ++ st = IOCTL(fd, MMC_IOC_CMD, &cmd); ++ if (st < 0) ++ return TEE_ERROR_GENERIC; ++ ++ return TEE_SUCCESS; ++} ++ ++static uint32_t rpmb_data_req(int fd, struct rpmb_data_frame *req_frm, ++ size_t req_nfrm, struct rpmb_data_frame *rsp_frm, ++ size_t rsp_nfrm) ++{ ++ int st = 0; ++ size_t i = 0; ++ uint16_t msg_type = ntohs(req_frm->msg_type); ++ struct mmc_ioc_cmd cmd = { ++ .blksz = 512, ++ .blocks = req_nfrm, ++ .data_ptr = (uintptr_t)req_frm, ++ .flags = MMC_RSP_R1 | MMC_CMD_ADTC, ++ .opcode = MMC_WRITE_MULTIPLE_BLOCK, ++ .write_flag = 1, ++ }; ++ ++ for (i = 1; i < req_nfrm; i++) { ++ if (req_frm[i].msg_type != msg_type) { ++ printf("All request frames shall be of the same type\n"); ++ return TEE_ERROR_BAD_PARAMETERS; ++ } ++ } ++ ++ //printf("Req: %zu frame(s) of type 0x%04x", req_nfrm, msg_type); ++ //printf("Rsp: %zu frame(s)", rsp_nfrm); ++ ++ switch(msg_type) { ++ case RPMB_MSG_TYPE_REQ_AUTH_KEY_PROGRAM: ++ case RPMB_MSG_TYPE_REQ_AUTH_DATA_WRITE: ++ if (rsp_nfrm != 1) { ++ printf("Expected only one response frame\n"); ++ return TEE_ERROR_BAD_PARAMETERS; ++ } ++ ++ /* Send write request frame(s) */ ++ cmd.write_flag |= MMC_CMD23_ARG_REL_WR; ++ /* ++ * Black magic: tested on a HiKey board with a HardKernel eMMC ++ * module. When postsleep values are zero, the kernel logs ++ * random errors: "mmc_blk_ioctl_cmd: Card Status=0x00000E00" ++ * and ioctl() fails. ++ */ ++ cmd.postsleep_min_us = 20000; ++ cmd.postsleep_max_us = 50000; ++ st = IOCTL(fd, MMC_IOC_CMD, &cmd); ++ if (st < 0) ++ return TEE_ERROR_GENERIC; ++ cmd.postsleep_min_us = 0; ++ cmd.postsleep_max_us = 0; ++ ++ /* Send result request frame */ ++ memset(rsp_frm, 0, 1); ++ rsp_frm->msg_type = htons(RPMB_MSG_TYPE_REQ_RESULT_READ); ++ cmd.data_ptr = (uintptr_t)rsp_frm; ++ cmd.write_flag &= ~MMC_CMD23_ARG_REL_WR; ++ st = IOCTL(fd, MMC_IOC_CMD, &cmd); ++ if (st < 0) ++ return TEE_ERROR_GENERIC; ++ ++ /* Read response frame */ ++ cmd.opcode = MMC_READ_MULTIPLE_BLOCK; ++ cmd.write_flag = 0; ++ cmd.blocks = rsp_nfrm; ++ st = IOCTL(fd, MMC_IOC_CMD, &cmd); ++ if (st < 0) ++ return TEE_ERROR_GENERIC; ++ break; ++ ++ case RPMB_MSG_TYPE_REQ_WRITE_COUNTER_VAL_READ: ++ if (rsp_nfrm != 1) { ++ printf("Expected only one response frame\n"); ++ return TEE_ERROR_BAD_PARAMETERS; ++ } ++//#if __GNUC__ > 6 ++ //__attribute__((fallthrough)); ++//#endif ++ ++ case RPMB_MSG_TYPE_REQ_AUTH_DATA_READ: ++ if (req_nfrm != 1) { ++ printf("Expected only one request frame\n"); ++ return TEE_ERROR_BAD_PARAMETERS; ++ } ++ ++ /* Send request frame */ ++ st = IOCTL(fd, MMC_IOC_CMD, &cmd); ++ if (st < 0) ++ return TEE_ERROR_GENERIC; ++ ++ /* Read response frames */ ++ cmd.data_ptr = (uintptr_t)rsp_frm; ++ cmd.opcode = MMC_READ_MULTIPLE_BLOCK; ++ cmd.write_flag = 0; ++ cmd.blocks = rsp_nfrm; ++ st = IOCTL(fd, MMC_IOC_CMD, &cmd); ++ if (st < 0) ++ return TEE_ERROR_GENERIC; ++ break; ++ ++ default: ++ printf("Unsupported message type: %d", msg_type); ++ return TEE_ERROR_GENERIC; ++ } ++ ++ return TEE_SUCCESS; ++} ++ ++static uint32_t rpmb_get_dev_info(uint16_t dev_id, struct rpmb_dev_info *info) ++{ ++ int fd = 0; ++ uint32_t res = 0; ++ uint8_t ext_csd[512] = { 0 }; ++ ++ res = read_cid(dev_id, info->cid); ++ if (res != TEE_SUCCESS) ++ return res; ++ ++ fd = mmc_fd(dev_id); ++ if (fd < 0) ++ return TEE_ERROR_BAD_PARAMETERS; ++ ++ res = read_ext_csd(fd, ext_csd); ++ if (res != TEE_SUCCESS) ++ goto err; ++ ++ info->rel_wr_sec_c = ext_csd[222]; ++ info->rpmb_size_mult = ext_csd[168]; ++ info->ret_code = RPMB_CMD_GET_DEV_INFO_RET_OK; ++ ++err: ++ close_mmc_fd(fd); ++ return res; ++} ++ ++ ++/* ++ * req is one struct rpmb_req followed by one or more struct rpmb_data_frame ++ * rsp is either one struct rpmb_dev_info or one or more struct rpmb_data_frame ++ */ ++uint32_t rpmb_process_request_emu(void *req, size_t req_size, ++ void *rsp, size_t rsp_size) ++{ ++ struct rpmb_req *sreq = req; ++ size_t req_nfrm = 0; ++ size_t rsp_nfrm = 0; ++ uint32_t res = 0; ++ int fd = 0; ++ ++ if (req_size < sizeof(*sreq)) ++ return TEE_ERROR_BAD_PARAMETERS; ++ ++ switch (sreq->cmd) { ++ case RPMB_CMD_DATA_REQ: ++ req_nfrm = (req_size - sizeof(struct rpmb_req)) / 512; ++ rsp_nfrm = rsp_size / 512; ++ fd = mmc_rpmb_fd(sreq->dev_id); ++ if (fd < 0) ++ return TEE_ERROR_BAD_PARAMETERS; ++ res = rpmb_data_req(fd, RPMB_REQ_DATA(req), req_nfrm, rsp, ++ rsp_nfrm); ++ break; ++ ++ case RPMB_CMD_GET_DEV_INFO: ++ if (req_size != sizeof(struct rpmb_req) || ++ rsp_size != sizeof(struct rpmb_dev_info)) { ++ printf("Invalid req/rsp size"); ++ return TEE_ERROR_BAD_PARAMETERS; ++ } ++ res = rpmb_get_dev_info(sreq->dev_id, ++ (struct rpmb_dev_info *)rsp); ++ break; ++ ++ default: ++ printf("Unsupported RPMB command: %d", sreq->cmd); ++ res = TEE_ERROR_BAD_PARAMETERS; ++ break; ++ } ++ ++ return res; ++} +diff --git a/drivers/tee/optee/rpmb_emu.h b/drivers/tee/optee/rpmb_emu.h +new file mode 100644 +index 000000000000..3471eecf63b5 +--- /dev/null ++++ b/drivers/tee/optee/rpmb_emu.h +@@ -0,0 +1,141 @@ ++#include ++ ++/* mmc_ioc_cmd.opcode */ ++#define MMC_SEND_EXT_CSD 8 ++#define MMC_READ_MULTIPLE_BLOCK 18 ++#define MMC_WRITE_MULTIPLE_BLOCK 25 ++ ++#define IOCTL(fd, request, ...) ioctl_emu((fd), (request), ##__VA_ARGS__) ++#define mmc_ioc_cmd_set_data(ic, ptr) ic.data_ptr = (__u64)(unsigned long) ptr ++#define MMC_CMD23_ARG_REL_WR (1 << 31) /* CMD23 reliable write */ ++ ++/* Emulated rel_wr_sec_c value (reliable write size, *256 bytes) */ ++#define EMU_RPMB_REL_WR_SEC_C 1 ++/* Emulated rpmb_size_mult value (RPMB size, *128 kB) */ ++#define EMU_RPMB_SIZE_MULT 2 ++ ++#define EMU_RPMB_SIZE_BYTES (EMU_RPMB_SIZE_MULT * 128 * 1024) ++ ++struct mmc_ioc_cmd { ++ /* Implies direction of data. true = write, false = read */ ++ int write_flag; ++ ++ /* Application-specific command. true = precede with CMD55 */ ++ int is_acmd; ++ ++ uint32_t opcode; ++ uint32_t arg; ++ uint32_t response[4]; /* CMD response */ ++ unsigned int flags; ++ unsigned int blksz; ++ unsigned int blocks; ++ ++ /* ++ * Sleep at least postsleep_min_us useconds, and at most ++ * postsleep_max_us useconds *after* issuing command. Needed for ++ * some read commands for which cards have no other way of indicating ++ * they're ready for the next command (i.e. there is no equivalent of ++ * a "busy" indicator for read operations). ++ */ ++ unsigned int postsleep_min_us; ++ unsigned int postsleep_max_us; ++ ++ /* ++ * Override driver-computed timeouts. Note the difference in units! ++ */ ++ unsigned int data_timeout_ns; ++ unsigned int cmd_timeout_ms; ++ ++ /* ++ * For 64-bit machines, the next member, ``__u64 data_ptr``, wants to ++ * be 8-byte aligned. Make sure this struct is the same size when ++ * built for 32-bit. ++ */ ++ uint32_t __pad; ++ ++ /* DAT buffer */ ++ uint32_t data_ptr; ++}; ++#define MMC_BLOCK_MAJOR 179 ++#define MMC_IOC_CMD _IOWR(MMC_BLOCK_MAJOR, 0, struct mmc_ioc_cmd) ++ ++/* Request */ ++struct rpmb_req { ++ uint16_t cmd; ++#define RPMB_CMD_DATA_REQ 0x00 ++#define RPMB_CMD_GET_DEV_INFO 0x01 ++ uint16_t dev_id; ++ uint16_t block_count; ++ /* Optional data frames (rpmb_data_frame) follow */ ++}; ++#define RPMB_REQ_DATA(req) ((void *)((struct rpmb_req *)(req) + 1)) ++ ++/* Response to device info request */ ++struct rpmb_dev_info { ++ uint8_t cid[16]; ++ uint8_t rpmb_size_mult; /* EXT CSD-slice 168: RPMB Size */ ++ uint8_t rel_wr_sec_c; /* EXT CSD-slice 222: Reliable Write Sector */ ++ /* Count */ ++ uint8_t ret_code; ++#define RPMB_CMD_GET_DEV_INFO_RET_OK 0x00 ++#define RPMB_CMD_GET_DEV_INFO_RET_ERROR 0x01 ++}; ++/* mmc_ioc_cmd.flags */ ++#define MMC_RSP_PRESENT (1 << 0) ++#define MMC_RSP_136 (1 << 1) /* 136 bit response */ ++#define MMC_RSP_CRC (1 << 2) /* Expect valid CRC */ ++#define MMC_RSP_OPCODE (1 << 4) /* Response contains opcode */ ++ ++#define MMC_RSP_R1 (MMC_RSP_PRESENT|MMC_RSP_CRC|MMC_RSP_OPCODE) ++ ++#define MMC_CMD_ADTC (1 << 5) /* Addressed data transfer command */ ++ ++ ++/* Emulated eMMC device state */ ++struct rpmb_emu { ++ uint8_t buf[EMU_RPMB_SIZE_BYTES]; ++ size_t size; ++ uint8_t key[32]; ++ bool key_set; ++ uint8_t nonce[16]; ++ uint32_t write_counter; ++ struct { ++ uint16_t msg_type; ++ uint16_t op_result; ++ uint16_t address; ++ } last_op; ++}; ++ ++/* ++ * This structure is shared with OP-TEE and the MMC ioctl layer. ++ * It is the "data frame for RPMB access" defined by JEDEC, minus the ++ * start and stop bits. ++ */ ++struct rpmb_data_frame { ++ uint8_t stuff_bytes[196]; ++ uint8_t key_mac[32]; ++ uint8_t data[256]; ++ uint8_t nonce[16]; ++ uint32_t write_counter; ++ uint16_t address; ++ uint16_t block_count; ++ uint16_t op_result; ++#define RPMB_RESULT_OK 0x00 ++#define RPMB_RESULT_GENERAL_FAILURE 0x01 ++#define RPMB_RESULT_AUTH_FAILURE 0x02 ++#define RPMB_RESULT_ADDRESS_FAILURE 0x04 ++#define RPMB_RESULT_AUTH_KEY_NOT_PROGRAMMED 0x07 ++ uint16_t msg_type; ++#define RPMB_MSG_TYPE_REQ_AUTH_KEY_PROGRAM 0x0001 ++#define RPMB_MSG_TYPE_REQ_WRITE_COUNTER_VAL_READ 0x0002 ++#define RPMB_MSG_TYPE_REQ_AUTH_DATA_WRITE 0x0003 ++#define RPMB_MSG_TYPE_REQ_AUTH_DATA_READ 0x0004 ++#define RPMB_MSG_TYPE_REQ_RESULT_READ 0x0005 ++#define RPMB_MSG_TYPE_RESP_AUTH_KEY_PROGRAM 0x0100 ++#define RPMB_MSG_TYPE_RESP_WRITE_COUNTER_VAL_READ 0x0200 ++#define RPMB_MSG_TYPE_RESP_AUTH_DATA_WRITE 0x0300 ++#define RPMB_MSG_TYPE_RESP_AUTH_DATA_READ 0x0400 ++}; ++ ++uint32_t rpmb_process_request_emu(void *req, size_t req_size, ++ void *rsp, size_t rsp_size); +diff --git a/drivers/tee/optee/sha2.c b/drivers/tee/optee/sha2.c +new file mode 100644 +index 000000000000..a9acd7244947 +--- /dev/null ++++ b/drivers/tee/optee/sha2.c +@@ -0,0 +1,249 @@ ++/* ++ * FIPS 180-2 SHA-224/256/384/512 implementation ++ * Last update: 02/02/2007 ++ * Issue date: 04/30/2005 ++ * ++ * Copyright (C) 2005, 2007 Olivier Gay ++ * All rights reserved. ++ * ++ * Copyright (c) 2016, Linaro Limited ++ * All rights reserved. ++ * ++ * Redistribution and use in source and binary forms, with or without ++ * modification, are permitted provided that the following conditions ++ * are met: ++ * 1. Redistributions of source code must retain the above copyright ++ * notice, this list of conditions and the following disclaimer. ++ * 2. Redistributions in binary form must reproduce the above copyright ++ * notice, this list of conditions and the following disclaimer in the ++ * documentation and/or other materials provided with the distribution. ++ * 3. Neither the name of the project nor the names of its contributors ++ * may be used to endorse or promote products derived from this software ++ * without specific prior written permission. ++ * ++ * THIS SOFTWARE IS PROVIDED BY THE PROJECT AND CONTRIBUTORS ``AS IS'' AND ++ * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE ++ * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ++ * ARE DISCLAIMED. IN NO EVENT SHALL THE PROJECT OR CONTRIBUTORS BE LIABLE ++ * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL ++ * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS ++ * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) ++ * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT ++ * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY ++ * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF ++ * SUCH DAMAGE. ++ */ ++ ++#include ++#include "sha2.h" ++ ++#define SHFR(x, n) (x >> n) ++#define ROTR(x, n) ((x >> n) | (x << ((sizeof(x) << 3) - n))) ++#define ROTL(x, n) ((x << n) | (x >> ((sizeof(x) << 3) - n))) ++#define CH(x, y, z) ((x & y) ^ (~x & z)) ++#define MAJ(x, y, z) ((x & y) ^ (x & z) ^ (y & z)) ++ ++#define SHA256_F1(x) (ROTR(x, 2) ^ ROTR(x, 13) ^ ROTR(x, 22)) ++#define SHA256_F2(x) (ROTR(x, 6) ^ ROTR(x, 11) ^ ROTR(x, 25)) ++#define SHA256_F3(x) (ROTR(x, 7) ^ ROTR(x, 18) ^ SHFR(x, 3)) ++#define SHA256_F4(x) (ROTR(x, 17) ^ ROTR(x, 19) ^ SHFR(x, 10)) ++ ++#define UNPACK32(x, str) \ ++{ \ ++ *((str) + 3) = (uint8) ((x) ); \ ++ *((str) + 2) = (uint8) ((x) >> 8); \ ++ *((str) + 1) = (uint8) ((x) >> 16); \ ++ *((str) + 0) = (uint8) ((x) >> 24); \ ++} ++ ++#define PACK32(str, x) \ ++{ \ ++ *(x) = ((uint32) *((str) + 3) ) \ ++ | ((uint32) *((str) + 2) << 8) \ ++ | ((uint32) *((str) + 1) << 16) \ ++ | ((uint32) *((str) + 0) << 24); \ ++} ++ ++#define UNPACK64(x, str) \ ++{ \ ++ *((str) + 7) = (uint8) ((x) ); \ ++ *((str) + 6) = (uint8) ((x) >> 8); \ ++ *((str) + 5) = (uint8) ((x) >> 16); \ ++ *((str) + 4) = (uint8) ((x) >> 24); \ ++ *((str) + 3) = (uint8) ((x) >> 32); \ ++ *((str) + 2) = (uint8) ((x) >> 40); \ ++ *((str) + 1) = (uint8) ((x) >> 48); \ ++ *((str) + 0) = (uint8) ((x) >> 56); \ ++} ++ ++#define PACK64(str, x) \ ++{ \ ++ *(x) = ((uint64) *((str) + 7) ) \ ++ | ((uint64) *((str) + 6) << 8) \ ++ | ((uint64) *((str) + 5) << 16) \ ++ | ((uint64) *((str) + 4) << 24) \ ++ | ((uint64) *((str) + 3) << 32) \ ++ | ((uint64) *((str) + 2) << 40) \ ++ | ((uint64) *((str) + 1) << 48) \ ++ | ((uint64) *((str) + 0) << 56); \ ++} ++ ++#define SHA256_SCR(i) \ ++{ \ ++ w[i] = SHA256_F4(w[i - 2]) + w[i - 7] \ ++ + SHA256_F3(w[i - 15]) + w[i - 16]; \ ++} ++ ++uint32 sha256_h0[8] = ++ {0x6a09e667, 0xbb67ae85, 0x3c6ef372, 0xa54ff53a, ++ 0x510e527f, 0x9b05688c, 0x1f83d9ab, 0x5be0cd19}; ++ ++uint32 sha256_k[64] = ++ {0x428a2f98, 0x71374491, 0xb5c0fbcf, 0xe9b5dba5, ++ 0x3956c25b, 0x59f111f1, 0x923f82a4, 0xab1c5ed5, ++ 0xd807aa98, 0x12835b01, 0x243185be, 0x550c7dc3, ++ 0x72be5d74, 0x80deb1fe, 0x9bdc06a7, 0xc19bf174, ++ 0xe49b69c1, 0xefbe4786, 0x0fc19dc6, 0x240ca1cc, ++ 0x2de92c6f, 0x4a7484aa, 0x5cb0a9dc, 0x76f988da, ++ 0x983e5152, 0xa831c66d, 0xb00327c8, 0xbf597fc7, ++ 0xc6e00bf3, 0xd5a79147, 0x06ca6351, 0x14292967, ++ 0x27b70a85, 0x2e1b2138, 0x4d2c6dfc, 0x53380d13, ++ 0x650a7354, 0x766a0abb, 0x81c2c92e, 0x92722c85, ++ 0xa2bfe8a1, 0xa81a664b, 0xc24b8b70, 0xc76c51a3, ++ 0xd192e819, 0xd6990624, 0xf40e3585, 0x106aa070, ++ 0x19a4c116, 0x1e376c08, 0x2748774c, 0x34b0bcb5, ++ 0x391c0cb3, 0x4ed8aa4a, 0x5b9cca4f, 0x682e6ff3, ++ 0x748f82ee, 0x78a5636f, 0x84c87814, 0x8cc70208, ++ 0x90befffa, 0xa4506ceb, 0xbef9a3f7, 0xc67178f2}; ++ ++/* SHA-256 functions */ ++ ++static void sha256_transf(sha256_ctx *ctx, const unsigned char *message, ++ unsigned int block_nb) ++{ ++ uint32 w[64] = { 0 }; ++ uint32 wv[8] = { 0 }; ++ uint32 t1 = 0; ++ uint32 t2 = 0; ++ const unsigned char *sub_block = NULL; ++ int i = 0; ++ int j = 0; ++ ++ for (i = 0; i < (int) block_nb; i++) { ++ sub_block = message + (i << 6); ++ ++ for (j = 0; j < 16; j++) { ++ PACK32(&sub_block[j << 2], &w[j]); ++ } ++ ++ for (j = 16; j < 64; j++) { ++ SHA256_SCR(j); ++ } ++ ++ for (j = 0; j < 8; j++) { ++ wv[j] = ctx->h[j]; ++ } ++ ++ for (j = 0; j < 64; j++) { ++ t1 = wv[7] + SHA256_F2(wv[4]) + CH(wv[4], wv[5], wv[6]) ++ + sha256_k[j] + w[j]; ++ t2 = SHA256_F1(wv[0]) + MAJ(wv[0], wv[1], wv[2]); ++ wv[7] = wv[6]; ++ wv[6] = wv[5]; ++ wv[5] = wv[4]; ++ wv[4] = wv[3] + t1; ++ wv[3] = wv[2]; ++ wv[2] = wv[1]; ++ wv[1] = wv[0]; ++ wv[0] = t1 + t2; ++ } ++ ++ for (j = 0; j < 8; j++) { ++ ctx->h[j] += wv[j]; ++ } ++ } ++} ++ ++void sha256(const unsigned char *message, unsigned int len, ++ unsigned char *digest) ++{ ++ sha256_ctx ctx; ++ ++ memset(&ctx, 0, sizeof(ctx)); ++ ++ sha256_init(&ctx); ++ sha256_update_tee(&ctx, message, len); ++ sha256_final(&ctx, digest); ++} ++ ++void sha256_init(sha256_ctx *ctx) ++{ ++ int i = 0; ++ ++ for (i = 0; i < 8; i++) { ++ ctx->h[i] = sha256_h0[i]; ++ } ++ ++ ctx->len = 0; ++ ctx->tot_len = 0; ++} ++ ++void sha256_update_tee(sha256_ctx *ctx, const unsigned char *message, ++ unsigned int len) ++{ ++ unsigned int block_nb = 0; ++ unsigned int new_len = 0; ++ unsigned int rem_len = 0; ++ unsigned int tmp_len = 0; ++ const unsigned char *shifted_message = NULL; ++ ++ tmp_len = SHA256_BLOCK_SIZE - ctx->len; ++ rem_len = len < tmp_len ? len : tmp_len; ++ ++ memcpy(&ctx->block[ctx->len], message, rem_len); ++ ++ if (ctx->len + len < SHA256_BLOCK_SIZE) { ++ ctx->len += len; ++ return; ++ } ++ ++ new_len = len - rem_len; ++ block_nb = new_len / SHA256_BLOCK_SIZE; ++ ++ shifted_message = message + rem_len; ++ ++ sha256_transf(ctx, ctx->block, 1); ++ sha256_transf(ctx, shifted_message, block_nb); ++ ++ rem_len = new_len % SHA256_BLOCK_SIZE; ++ ++ memcpy(ctx->block, &shifted_message[block_nb << 6], ++ rem_len); ++ ++ ctx->len = rem_len; ++ ctx->tot_len += (block_nb + 1) << 6; ++} ++ ++void sha256_final(sha256_ctx *ctx, unsigned char *digest) ++{ ++ unsigned int block_nb = 0; ++ unsigned int pm_len = 0; ++ unsigned int len_b = 0; ++ int i = 0; ++ ++ block_nb = (1 + ((SHA256_BLOCK_SIZE - 9) ++ < (ctx->len % SHA256_BLOCK_SIZE))); ++ ++ len_b = (ctx->tot_len + ctx->len) << 3; ++ pm_len = block_nb << 6; ++ ++ memset(ctx->block + ctx->len, 0, pm_len - ctx->len); ++ ctx->block[ctx->len] = 0x80; ++ UNPACK32(len_b, ctx->block + pm_len - 4); ++ ++ sha256_transf(ctx, ctx->block, block_nb); ++ ++ for (i = 0 ; i < 8; i++) { ++ UNPACK32(ctx->h[i], &digest[i << 2]); ++ } ++} +diff --git a/drivers/tee/optee/sha2.h b/drivers/tee/optee/sha2.h +new file mode 100644 +index 000000000000..4ce0f3cd5231 +--- /dev/null ++++ b/drivers/tee/optee/sha2.h +@@ -0,0 +1,75 @@ ++/* ++ * FIPS 180-2 SHA-224/256/384/512 implementation ++ * Last update: 02/02/2007 ++ * Issue date: 04/30/2005 ++ * ++ * Copyright (C) 2005, 2007 Olivier Gay ++ * All rights reserved. ++ * ++ * Copyright (c) 2016, Linaro Limited ++ * All rights reserved. ++ * ++ * Redistribution and use in source and binary forms, with or without ++ * modification, are permitted provided that the following conditions ++ * are met: ++ * 1. Redistributions of source code must retain the above copyright ++ * notice, this list of conditions and the following disclaimer. ++ * 2. Redistributions in binary form must reproduce the above copyright ++ * notice, this list of conditions and the following disclaimer in the ++ * documentation and/or other materials provided with the distribution. ++ * 3. Neither the name of the project nor the names of its contributors ++ * may be used to endorse or promote products derived from this software ++ * without specific prior written permission. ++ * ++ * THIS SOFTWARE IS PROVIDED BY THE PROJECT AND CONTRIBUTORS ``AS IS'' AND ++ * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE ++ * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ++ * ARE DISCLAIMED. IN NO EVENT SHALL THE PROJECT OR CONTRIBUTORS BE LIABLE ++ * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL ++ * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS ++ * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) ++ * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT ++ * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY ++ * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF ++ * SUCH DAMAGE. ++ */ ++ ++#ifndef SHA2_H ++#define SHA2_H ++ ++#define SHA256_DIGEST_SIZE ( 256 / 8) ++#define SHA256_BLOCK_SIZE ( 512 / 8) ++ ++#ifndef SHA2_TYPES ++#define SHA2_TYPES ++typedef unsigned char uint8; ++typedef unsigned int uint32; ++typedef unsigned long long uint64; ++#endif ++ ++#ifdef __cplusplus ++extern "C" { ++#endif ++ ++typedef struct { ++ unsigned int tot_len; ++ unsigned int len; ++ unsigned char block[2 * SHA256_BLOCK_SIZE]; ++ uint32 h[8]; ++} sha256_ctx; ++ ++typedef sha256_ctx sha224_ctx; ++ ++void sha256_init(sha256_ctx * ctx); ++void sha256_update_tee(sha256_ctx *ctx, const unsigned char *message, ++ unsigned int len); ++void sha256_final(sha256_ctx *ctx, unsigned char *digest); ++void sha256(const unsigned char *message, unsigned int len, ++ unsigned char *digest); ++ ++#ifdef __cplusplus ++} ++#endif ++ ++#endif /* !SHA2_H */ ++ +-- +2.29.2 + diff --git a/recipes-bsp/u-boot/u-boot-qemu-common.inc b/recipes-bsp/u-boot/u-boot-qemu-common.inc index 802fc50..6e7158b 100644 --- a/recipes-bsp/u-boot/u-boot-qemu-common.inc +++ b/recipes-bsp/u-boot/u-boot-qemu-common.inc @@ -13,6 +13,9 @@ require recipes-bsp/u-boot/u-boot-common.inc U_BOOT_BIN = "u-boot.bin" +SRC_URI_append_secureboot = " \ + file://0002-rpmb-emulation-hack.-Breaks-proper-hardware-support.patch;patch=1" + DEPENDS_append_secureboot = " optee-os-${MACHINE}" do_deploy[dirs] = "${DEPLOY_DIR_IMAGE}" From patchwork Sun Nov 20 20:47:08 2022 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: "Schultschik, Sven" X-Patchwork-Id: 13050149 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id BCDBFC4332F for ; Sun, 20 Nov 2022 20:49:52 +0000 (UTC) Received: from EUR04-DB3-obe.outbound.protection.outlook.com (EUR04-DB3-obe.outbound.protection.outlook.com [40.107.6.73]) by mx.groups.io with SMTP id smtpd.web11.22496.1668977391549596601 for ; Sun, 20 Nov 2022 12:49:52 -0800 Authentication-Results: mx.groups.io; dkim=fail reason="body hash did not verify" header.i=@siemens.com header.s=selector2 header.b=pw+HQcZw; spf=pass (domain: siemens.com, ip: 40.107.6.73, mailfrom: sven.schultschik@siemens.com) ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=SgWABP7VMERou0yVkIKmWc/A509+60Y63BrE61etAKOKdiCU3ks3sm0cEYdW+bqZf0cofvqVW2TP3b+A6MGGqMzq0XCsokTQI4VAvWDS4CwXvHLuwffru2tCA30/LvLVpq5YtsNyZ7FVp73hC/3J3OH+S7mOk+ZAMjU5zqk4LkEAefmfj0VkCUVvqlWs0N2bj4siFG3ctcfrSnP2Kyh6b5Xkx8Z47dQ3BP/1OxVlO/AGUbLEcwzOzw/R+zRilfJuUxpZpqhjQG8B68Gfn9t2WIya5NzTkfSorbL1nzhDDihjHNbDnGVY+mZqPVipgE5eJMreVmbrLog26ysQUqV+4A== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=qVV0ib9XRhyO+bm66mtM2NOd7l1HRjVAWcICguQiQks=; b=T0PPDqU2abN7SKXB+1k1yklJJO3rtIOR5MExy1OipSeLzoy6M79a1ko+XoHF8T5ZAuFrapqm7QXTCQNp/aDosHu0SM1E8lO1bT3Kx71lb7FOwB2zyLUrdW9rNZq/AK11V4ZEDHPfZm0NDoFt/xwnCPpxFLlrsXZiwqO4r4V3uRWSmMPcrsmHlHftCfIGSKw3pnqS+osIBMbCFqDjVm1cJ5AQSnowGQehc2w4+9PERF74uXhGcpvXpDL0TwJDQF0kya/AxibqBlycdk4S/WkyHpxjDOCnFGhlwLvFXAba9h9yq4+tPltA88d14omfW1CRzA9fzp+K3PI4+EEblW8DXg== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=siemens.com; dmarc=pass action=none header.from=siemens.com; dkim=pass header.d=siemens.com; arc=none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=siemens.com; s=selector2; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=qVV0ib9XRhyO+bm66mtM2NOd7l1HRjVAWcICguQiQks=; b=pw+HQcZwsM5hfHJpSgGtG7mdgyo2zyloKb+T7tVBL+D023x8Y5KJma63/upuV2eiSosP1RF0NmiYH76BOy2BoszPFROOb6dT6bIGunLNh/XODrJSV+sdHFWFmCRrz9u2iX+UqyPe09KaKGChAj4vW/y5blH9eGtMXlZeDJxpSXCwv61KkQ1+l7amBvpT6LSfyuswdNF6VcpylWOgV1bQu2o6BapApwtP16lWCXYAcLnYEQm938X85Mb00YspblmPkm24OtgJQaXGtDeNqdTFDxwLFDxkFdTT9zU/ygqg1/Ra2fcOSRDdutCi7wSnGtoXz3omSlqFv4a3Yu30RQRBpA== Authentication-Results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=siemens.com; Received: from PAXPR10MB5037.EURPRD10.PROD.OUTLOOK.COM (2603:10a6:102:210::11) by DU0PR10MB7094.EURPRD10.PROD.OUTLOOK.COM (2603:10a6:10:42e::11) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.5834.11; Sun, 20 Nov 2022 20:49:49 +0000 Received: from PAXPR10MB5037.EURPRD10.PROD.OUTLOOK.COM ([fe80::955a:f715:5319:7933]) by PAXPR10MB5037.EURPRD10.PROD.OUTLOOK.COM ([fe80::955a:f715:5319:7933%9]) with mapi id 15.20.5834.015; Sun, 20 Nov 2022 20:49:49 +0000 From: sven.schultschik@siemens.com To: cip-dev@lists.cip-project.org CC: jan.kiszka@siemens.com, Sven Schultschik Subject: [isar-cip-core][PATCH 5/8] add recipe for trusted firmware a qemu arm64 Date: Sun, 20 Nov 2022 21:47:08 +0100 Message-ID: <20221120204711.5826-6-sven.schultschik@siemens.com> X-Mailer: git-send-email 2.30.2 In-Reply-To: <20221120204711.5826-1-sven.schultschik@siemens.com> References: <20221120204711.5826-1-sven.schultschik@siemens.com> X-ClientProxiedBy: FR0P281CA0047.DEUP281.PROD.OUTLOOK.COM (2603:10a6:d10:48::18) To PAXPR10MB5037.EURPRD10.PROD.OUTLOOK.COM (2603:10a6:102:210::11) MIME-Version: 1.0 X-MS-PublicTrafficType: Email X-MS-TrafficTypeDiagnostic: PAXPR10MB5037:EE_|DU0PR10MB7094:EE_ X-MS-Office365-Filtering-Correlation-Id: aaa1c3ce-c04f-450e-a14e-08dacb38c414 X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam: BCL:0; X-Microsoft-Antispam-Message-Info: mUNb8wdww2pe9VkWxkx/vPJrjmFMxpvibyLIrg0vpE21mx4jZYvgp0Q+MOg1CEqS2OlQ6c5siBrYrDqu7Nsg5SrbMMdlA0ZVilEvLud0x/eqTYivD7RVQ307lmUVd+sH8cS2gSrG7vjOpaSFQtluWYKWVONDkQxAXa8AqNZLH+G1YmLQ60UOtCUCWJpM5z365IZ0pLdeDv7Gn2MbvfVUVXpeKHQ1/JBF/6X52gR2SBwXuvuuBDYF4vxYLtK3L7NXIBzPpSRhxjtGnpMT7H6Uog/CRD48YizAaleuK/LcMEIPUmRaph7vVwm40r5m/e8TGK8VSMp968q6onaa6xVg1TbI4Xggdt6mGwMtudxheh4NuBeasyDSHoazuD8OlPP917FodJsC4GDRRCRrVeIImAhsVZbvu7UNtwkq+pfrO7uOhNY0pFY1bkF3GSksgcFavA5GQXOsDCLkiMDSpeQpQfy44vx7GkKyIXmlW1zWZ4Pq5eEhRWUeD/F8kbDUVGUjaDLvEYe8dSVxX3T5bfANVKu8HosVbzw8pjyBpOxM7cU7xtc4npKotmdnT1/uMe9fVfMPOd9du6+i2JE40lnGZyS4QktbywBe0emERu+DpOZS75Uq6SQnOFG1RIX+IrjtxzM+1unrmmnQnOTJCt3/3vXopSbLEBttzduCMOjzUqo= X-Forefront-Antispam-Report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:PAXPR10MB5037.EURPRD10.PROD.OUTLOOK.COM;PTR:;CAT:NONE;SFS:(13230022)(4636009)(136003)(366004)(396003)(346002)(39860400002)(376002)(451199015)(2906002)(966005)(26005)(9686003)(86362001)(4326008)(6512007)(8676002)(66556008)(66476007)(82960400001)(66946007)(38100700002)(36756003)(41300700001)(6916009)(8936002)(5660300002)(316002)(107886003)(55236004)(478600001)(186003)(1076003)(6486002)(6666004)(2616005)(6506007);DIR:OUT;SFP:1101; X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1 X-MS-Exchange-AntiSpam-MessageData-0: oy2E+jR/kcC/TrH0P+hT5E/sX09uKs/Yc74qe3eB6yyBwCqLp3wr9wOQnMmcnJ/+cLtP5gHNL2tiUx9o5jFmUy39aFN4K7bHuUZZaGghtu/h4ieY1y9XvDXrDMZHDCnnuiozy1J1f3MmR7ipeobIVFMCjhHHPRsyy9LY4jH8e3ZrAVGMP0dQLGlA82mssud2U+lvjciV9iQS3BqImG4vktrkFtIvg2kZk7OJUALNPz2pj8JUpyY4157w8z4XLQu1QWeyA4Sje8SmRsWcBuof4mZIo6ven+xKEYRq1hH2KNxNbKfe1+7ehqEQjMnOlg2gkFsRtkNrRY+uWFMrXU6unGLslgVOzhKg5vtMkgM2WXToiun5fAsBGyZGzX7tba65mpPTY+4XddLAlPuH6j2QvItQYoIPLkp1JSZnt68HEr3CRyouLU1nYREJ2AxSf1zVdeGx7xi8uBiQ/A13r9rLYox/2F9OVHsGaOurWE6/1crTuE7sVKfP3zcJARwNoZ8msFYlvd+b1PGymcFrePd6RnZJ8YMVgU4oQlaXFZ0UwIxej1Vz8cw+ETiTVKQUoPDmTqvOX5gLIqoaqWPXd/HxpqUOtA+tvn6SRupnirWA0VYHg3/l9jIGCvxpkiH6QFlRR+t63wsPKkyJXEZ2hfmveEpWUbb8EKQ2p8XnBXoWOIBxZOTv9hIoFzxQxXBzv2/428yjcsptrA+najSThQvXqMXksSz9Z5u6gQOBHhsqELIPF7o3Fv/QZBbDvul2tLqxLSqR+PY3wEoBWrDGfbuKjmvGpJGUtfAYNndwjtkjLluS2zeFJSbrX+Wu4g0hUfptkpBQ1dlYqU4zSK7nb887JNDFQvBh/4BYNW1Cm/maJrhC89GcF8NUVz9nWjQSI9n3Th5lgtiuePOmTGNDCd4Od0bwu5chKsTzaNjup3MdSepMT1UzPGrr+DM3Rf6hPoUyISDrgaHNv0468Ytzc/6f81249ZGP3kGEjkeV51AOByYY9TR4NVic6ThiF95rtjCSRi7oTGiliS1M44YOafMxjlBbZMvPnIfsBe29j4PPw7f5eiVeVAr+XQ5r14jGIGFtrN/VnvmURuSa8w+u8mXBU40+g25pUFRSzNpwQkAypz882mLKIktyRShQ7YCNyehr2SR2/W6104UPNlo9wLJ5pYONTGq/vhgfgSKnnt6qs8+zUKKV1p9WBjgI4U4az8t4yymYFvtJonlMMhohSrdDpnDBSNFjq/2hHwS7xF6GOYiKJ4d3xMLDJxdfQWwy+TKKL3BKM8lt7cXQA7/GrLM1Q31+BLltQtrEyj17AEi5IZ4gfPzCqRHw8R05r3/lUC4jBXLWCexiARtiPEY9UzyYxbhRPtCSiXrFnsMASX2iqaWjPHycqvGy08Ah/DMFjRnzvglwxvo1sYfjUy383/2F+Bp2CQNKwaRmHBySkQoLOd4ttk8r/tA8TzrJT2wwZRTsgT8sSVgUugL+2ufOZ6pLnkVKMzYoan1ZR+Ytx8odZno4XBtsEbSlyQf8VHV/ehFGIz6oT8wE7Dn0MEh5tsrmFZSfXRuBP3uTA+ZpYIpXYSqEXPDPaNbjCqEKswRyoqmo57gQZ8g/4/d6nHpTVIOWFA== X-OriginatorOrg: siemens.com X-MS-Exchange-CrossTenant-Network-Message-Id: aaa1c3ce-c04f-450e-a14e-08dacb38c414 X-MS-Exchange-CrossTenant-AuthSource: PAXPR10MB5037.EURPRD10.PROD.OUTLOOK.COM X-MS-Exchange-CrossTenant-AuthAs: Internal X-MS-Exchange-CrossTenant-OriginalArrivalTime: 20 Nov 2022 20:49:49.5889 (UTC) X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted X-MS-Exchange-CrossTenant-Id: 38ae3bcd-9579-4fd4-adda-b42e1495d55a X-MS-Exchange-CrossTenant-MailboxType: HOSTED X-MS-Exchange-CrossTenant-UserPrincipalName: RTgIintI3W3anPfwW19tYqbKnZ4lzRb6whOlpW4ZhTqER2Hz5QTUSAFqff8+9NBpP5Wkp8J0ze3aHzTKovQn8zLFwAX1by1I70h2tgJQOpw= X-MS-Exchange-Transport-CrossTenantHeadersStamped: DU0PR10MB7094 List-Id: X-Webhook-Received: from li982-79.members.linode.com [45.33.32.79] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 20 Nov 2022 20:49:52 -0000 X-Groupsio-URL: https://lists.cip-project.org/g/cip-dev/message/10058 From: Sven Schultschik provide a recipe to generate the needed binary to start a secure boot qemu with integrated optee and active RPMB replay protected memory emulation within u-boot Signed-off-by: Sven Schultschik --- kas/opt/ebg-secure-boot-snakeoil.yml | 1 + .../trusted-firmware-a/files/rules.tmpl | 22 +++++++ .../trusted-firmware-a-qemu-arm64_2.7.0.bb | 62 +++++++++++++++++++ 3 files changed, 85 insertions(+) create mode 100755 recipes-bsp/trusted-firmware-a/files/rules.tmpl create mode 100644 recipes-bsp/trusted-firmware-a/trusted-firmware-a-qemu-arm64_2.7.0.bb diff --git a/kas/opt/ebg-secure-boot-snakeoil.yml b/kas/opt/ebg-secure-boot-snakeoil.yml index e92ea5e..6732095 100644 --- a/kas/opt/ebg-secure-boot-snakeoil.yml +++ b/kas/opt/ebg-secure-boot-snakeoil.yml @@ -26,6 +26,7 @@ local_conf_header: secure-boot: | IMAGER_BUILD_DEPS += "ebg-secure-boot-signer" + IMAGER_BUILD_DEPS_append_qemu-arm64 = " trusted-firmware-a-qemu-arm64" IMAGER_INSTALL += "ebg-secure-boot-signer" # Use snakeoil keys PREFERRED_PROVIDER_secure-boot-secrets = "secure-boot-snakeoil" diff --git a/recipes-bsp/trusted-firmware-a/files/rules.tmpl b/recipes-bsp/trusted-firmware-a/files/rules.tmpl new file mode 100755 index 0000000..45eb00b --- /dev/null +++ b/recipes-bsp/trusted-firmware-a/files/rules.tmpl @@ -0,0 +1,22 @@ +#!/usr/bin/make -f + +# Debian rules for custom Trusted Firmware A build +# +# This software is a part of ISAR. +# Copyright (c) Siemens AG, 2020 +# +# SPDX-License-Identifier: MIT + +ifneq ($(DEB_BUILD_GNU_TYPE),$(DEB_HOST_GNU_TYPE)) +export CROSS_COMPILE=$(DEB_HOST_GNU_TYPE)- +endif + +override_dh_auto_build: + CFLAGS= LDFLAGS= $(MAKE) $(PARALLEL_MAKE) PLAT=${TF_A_PLATFORM} \ + ${TF_A_EXTRA_BUILDARGS} + + dd if="build/${TF_A_PLATFORM}/release/bl1.bin" of="build/${TF_A_PLATFORM}/release/flash.bin" bs=4096 conv=notrunc + dd if="build/${TF_A_PLATFORM}/release/fip.bin" of="build/${TF_A_PLATFORM}/release/flash.bin" seek=64 bs=4096 conv=notrunc + +%: + dh $@ diff --git a/recipes-bsp/trusted-firmware-a/trusted-firmware-a-qemu-arm64_2.7.0.bb b/recipes-bsp/trusted-firmware-a/trusted-firmware-a-qemu-arm64_2.7.0.bb new file mode 100644 index 0000000..fcb2729 --- /dev/null +++ b/recipes-bsp/trusted-firmware-a/trusted-firmware-a-qemu-arm64_2.7.0.bb @@ -0,0 +1,62 @@ +# +# CIP Core, generic profile +# +# Copyright (c) Siemens AG, 2022 +# +# Authors: +# Sven Schultschik +# +# SPDX-License-Identifier: MIT +# + +HOMEPAGE = "https://www.trustedfirmware.org/projects/tf-a/" +MAINTAINER = "Sven Schultschik " +LICENSE = "BSD-3-Clause" + +require recipes-bsp/trusted-firmware-a/trusted-firmware-a-custom.inc + +SRC_URI += " \ + https://git.trustedfirmware.org/TF-A/trusted-firmware-a.git/snapshot/trusted-firmware-a-${PV}.tar.gz \ + file://rules.tmpl" + +SRC_URI[sha256sum] = "553eeca87d4296cdf37361079d1a6446d4b36da16bc25feadd7e465537e7bd4d" + +S = "${WORKDIR}/trusted-firmware-a-${PV}" + +DEPENDS = "optee-os-${MACHINE} u-boot-qemu-arm64" +DEBIAN_BUILD_DEPENDS += " \ + debhelper(>= 11~), \ + optee-os-${MACHINE}, \ + u-boot-qemu-arm64, \ + libssl-dev:native, " + +TEMPLATE_FILES += "rules.tmpl" + +TEEHEADER = "/usr/lib/optee-os/${MACHINE}/tee-header_v2.bin" +TEEPAGER = "/usr/lib/optee-os/${MACHINE}/tee-pager_v2.bin" +TEEPAGEABLE = "/usr/lib/optee-os/${MACHINE}/tee-pageable_v2.bin" +BL33 = "/usr/lib/u-boot/${MACHINE}/u-boot.bin" + +TF_A_EXTRA_BUILDARGS = "BL32=${TEEHEADER} \ + BL32_EXTRA1=${TEEPAGER} \ + BL32_EXTRA2=${TEEPAGEABLE} \ + BL33=${BL33} \ + BL32_RAM_LOCATION=tdram SPD=opteed ${DEBUG} all fip" + +TF_A_PLATFORM = "qemu" + +TF_A_BINARIES = "release/flash.bin" + +do_prepare_build_append() { + rm -f ${S}/rules + cp ${WORKDIR}/rules ${S}/debian/ +} + +do_deploy[dirs] = "${DEPLOY_DIR_IMAGE}" +do_deploy() { + dpkg --fsys-tarfile "${WORKDIR}/trusted-firmware-a-${MACHINE}_${PV}_${DISTRO_ARCH}.deb" | \ + tar xOf - "./usr/lib/trusted-firmware-a/${MACHINE}/flash.bin" \ + > "${DEPLOY_DIR_IMAGE}/flash.bin" +} + +addtask deploy after do_dpkg_build before do_deploy_deb \ No newline at end of file From patchwork Sun Nov 20 20:47:09 2022 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: "Schultschik, Sven" X-Patchwork-Id: 13050150 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id AE1A6C4332F for ; Sun, 20 Nov 2022 20:50:12 +0000 (UTC) Received: from EUR04-DB3-obe.outbound.protection.outlook.com (EUR04-DB3-obe.outbound.protection.outlook.com [40.107.6.56]) by mx.groups.io with SMTP id smtpd.web11.22508.1668977405544013151 for ; Sun, 20 Nov 2022 12:50:06 -0800 Authentication-Results: mx.groups.io; dkim=fail reason="body hash did not verify" header.i=@siemens.com header.s=selector2 header.b=Mr0jhzzo; spf=pass (domain: siemens.com, ip: 40.107.6.56, mailfrom: sven.schultschik@siemens.com) ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=QUwRrppoR86EpmoIkfHc7c+L8F6lMiesTCygwh8IhPUdG6NmYyyHFfM+J1ETRgjVYCAy9eL0m8RMAk1zmCd71181L2TjluHurfATklN0s2UUdEd2eVWYuR83gyrIFEq0eDTe4OQ9G7aLgtPZX/4idH+Dr5kpQUX4SHV3HMdiSEveR27/ku8HbZZP7onBKdETvH44FquxA/5SuRa4yyVWucDpQiamoxWPHmGDiOPIgMQJdYk1cYhAwqPiEOGUnxXHnIJQgklyfardzVMdddHxFkDTwCw8wVm+TqZcv0RxA3NDaP6O5jlbBoEutZsIbpJl4+TKy1CZURsItyNhvTzlhQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=8xfYvrWZU2lyTJqQHL5tBCPzVpAR97SSRKbNu88XBoo=; b=OuXBgM+/vykMZnsJqiUth6pSSF08YtIHmp1cSad0AG5y7xHlm/Pv0tRAySD+XT30n80B/vZxpKf7Xho8aVjS1RRPoaoi+P6VWFQYjG7BC1rlAK5JagNX+RJxe9p1UFp5VqFqV+QTfOHzlDL+BcyURJ/bpxcwHVHdeDd5H95+VaZnfv7FZS4PgL9cdpIlcu7mfHHqs8XNVwGf3FaY4Sz5j0kkfCS3IWLAl6fQjqmyfqqGcg4HKROegxetF3v41FCyZxU1xEMW8LWhzNUBTWtQjSSPpQZG9Rl0lH+EuCuXZ5pQWwBFO2utnliw9tLpgBSSfLrnhJhcbj/aRO58lz1KRw== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=siemens.com; dmarc=pass action=none header.from=siemens.com; dkim=pass header.d=siemens.com; arc=none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=siemens.com; s=selector2; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=8xfYvrWZU2lyTJqQHL5tBCPzVpAR97SSRKbNu88XBoo=; b=Mr0jhzzou+XIVBbWN5FnSt8UjE7BenxqJmehsgJbRqqWtW6ln2h4P15jyz7AqQYAHfKGbm9/cmtaVRILOncUBlPplYklNVQN8203V/wfMaXdjejUs3TRBgIXijq995BpQRIP9VAiSv2GPBjPZJ4N0VeIwADH2oz2mYqLrQj6AEbb2gZcxXKJaP4OLJauLQU832vY5tt7bjkyvsZurR4EFBoQK0SirxQ4mt+W/qcSfKgMAwZy7wpdjZLydWSe8R0HcnZE3/yDXeqlMhCDaKliS53PnPVtQ76fkVQcFFQU8oCrI2swaeGrzhD0wldUYOJB7d/KmW1FE5MuFmAINoHkYg== Authentication-Results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=siemens.com; Received: from PAXPR10MB5037.EURPRD10.PROD.OUTLOOK.COM (2603:10a6:102:210::11) by DU0PR10MB7094.EURPRD10.PROD.OUTLOOK.COM (2603:10a6:10:42e::11) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.5834.11; Sun, 20 Nov 2022 20:50:02 +0000 Received: from PAXPR10MB5037.EURPRD10.PROD.OUTLOOK.COM ([fe80::955a:f715:5319:7933]) by PAXPR10MB5037.EURPRD10.PROD.OUTLOOK.COM ([fe80::955a:f715:5319:7933%9]) with mapi id 15.20.5834.015; Sun, 20 Nov 2022 20:50:02 +0000 From: sven.schultschik@siemens.com To: cip-dev@lists.cip-project.org CC: jan.kiszka@siemens.com, Sven Schultschik Subject: [isar-cip-core][PATCH 6/8] change ebg sb signer and secrets to pk kek db Date: Sun, 20 Nov 2022 21:47:09 +0100 Message-ID: <20221120204711.5826-7-sven.schultschik@siemens.com> X-Mailer: git-send-email 2.30.2 In-Reply-To: <20221120204711.5826-1-sven.schultschik@siemens.com> References: <20221120204711.5826-1-sven.schultschik@siemens.com> X-ClientProxiedBy: FR0P281CA0069.DEUP281.PROD.OUTLOOK.COM (2603:10a6:d10:49::22) To PAXPR10MB5037.EURPRD10.PROD.OUTLOOK.COM (2603:10a6:102:210::11) MIME-Version: 1.0 X-MS-PublicTrafficType: Email X-MS-TrafficTypeDiagnostic: PAXPR10MB5037:EE_|DU0PR10MB7094:EE_ X-MS-Office365-Filtering-Correlation-Id: e11863f4-a05c-47d2-3300-08dacb38cbef X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam: BCL:0; X-Microsoft-Antispam-Message-Info: F2fkDpLehFpMPJG3OTewRPxzYM6GOCAxuFiIU2Mw5NePnw+Dyef2Fh6tky4TyrK6xT/Fid37oDbY9oD8OezIlv+V1H8nU2D3F5agkOq19Ao0D+0ETFS0JpMExy8cA29qc72wYLOyydRVbrUtvWHaQyK3XVW9AuHn7jimX1lv2+UlvdTu4quWTHy0S62LeVTW+er6M5wH3qXG4j1U37RurIrea2b1FJvMQC0nhP0I+VnhDg6QiwhxNgsY0yg10zlHEKztJhOA8KnxDOO19/ZSBX725cpOKo5h2cQj9lerf2DaTB41gFraQM5BZWANFoYcD9TCrIu+znrz15ukhIjXZxZqvDxdZmQ6e8xlRxuF1e7y0a35cs2h9PhWJku6qwly5Ae8vkBoE6HG4FiozCOEoYFUzLfiIYdce/Oct2YrgdSUjs5oWZu6uADU9bq9GHtQldF4J7hLAzmb5k7nVdKTO2bjwVj+XJIkn4lRg2YUjetn9k3ADZ1BRmehn0MdmkAHZgm1EYpOGvt+XuJz5iccCBl7DkZRefMmy6orlWR6vWrQi7ayrm8uFw/dNtyd67BuZgY1p7XlQ4XAnOB3hS0HK7F55RfqoZAgDo5dXV0heOOPvAZpS9RN5WhELBF6/zadIrZBfCeQuxuPejx3jdnUDai2R1WX+LagwnWZYi0WrSxei0iR496091xvN8myrkO/VeMTmRjf0ACsyb4yZ/6F4g== X-Forefront-Antispam-Report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:PAXPR10MB5037.EURPRD10.PROD.OUTLOOK.COM;PTR:;CAT:NONE;SFS:(13230022)(4636009)(136003)(366004)(396003)(346002)(39860400002)(376002)(451199015)(2906002)(26005)(83380400001)(9686003)(86362001)(4326008)(6512007)(8676002)(66556008)(66476007)(82960400001)(66946007)(38100700002)(36756003)(41300700001)(30864003)(6916009)(8936002)(19627235002)(5660300002)(316002)(107886003)(55236004)(478600001)(186003)(1076003)(6486002)(2616005)(6506007)(378184002)(14743001);DIR:OUT;SFP:1101; X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1 X-MS-Exchange-AntiSpam-MessageData-0: bIdH6buvz4b+0XO1uBOT4xdO8TgIv2CbthGS9BixcT3C2yfsC28iMkYfiAfaKD/fiwlpEm7SqMej4MQvNrv3CC+k5cmz9I+qtbvC/+UI+ZD2JfvrioY7DW7S2ngRV30u0+WAQXbqZZv8p2DA2POwzuzxnxtAdmihdXxN0borM8SZPWnN18cN6WPI5k1re8e7psw1cH5YFALXIcQvznlN+tAdtVNpkbW5bBkMKttdgq6ffH0wOsZlfUHzvfUZPiDd8xOAwmoMOWhZKH6GhS64UxVHCVGLU7+KYH0MQN4Q7CxCIRhw+fTyh7yfgBUUg327ULMUcFdNfmo2fiKisUgzQRPqGrsEg0a901V7CKPkg4m14ESnYTARzfVDz/DdEE4BDveUahs4+sn+HPEyu0U6HZTOLZjL3vFGqxEmuanJ7ijaboLPd9Bzaw9U8IjVp2a+eZ7f8M+1mNFEW29vu6BAVvK7vi/VR+eOLh1pSETGGa9OABuJUyZiiOIFuBxqZEjRv7Q3U7bZD9rg+Mzy6WIDw+g4+43BzRuwEO+eX6acojjeS5TQMpTYrlGbHivpBuAjAwG/JMDtbIAXG9Afkf/3G/dOn5EKLDTfp5qMVFaAI3yfTOzehm3MN1zECKxsNZXaEWoztOcyfmuDpLenAuGDtIqBQcjm3xTXx5OJDiiVft+myyYrdeCbAOT81VJqV4l4gkWCGxY7Gz7zpdTR7Hm0gGLAH9MBmNQ7sOk0CTs9i69fCmWNbOr4h37+rVHnZpLauKUi2xS3Ni8FF+8wRQYTTl+Cf9KbzbogHc4sa40nj8srFHeAF9b7eFxt+EcmR7h4GJp/UjDQeQMO3QEnqtbfyivYWRWJCgj+s+AN36QSPCXFxLgaY6PmWUcu8jNsS/sdXVMSI5rUDpvRnF2MArnLAp/h1xkv2DZp5NUvtqfg0XiVD5yUEyyiR/thqbZqpnD5/PDTaxy6ba8sJKV23DZaVCDh7v4RGWVePyNap7YP7ekPLAComllfXmaltqHna+gD12Bmc55436ATGzP2IfBsAcuJpfdxINmgcKZwNy48RADJFIz/BGwDSPblevk4aBFakEj7oZvIDZmbrauVnfQSPFjY4uUg92RzMmrcz3FYRj2yQctMaDRIzwK82DccduQ1VQ/ENJEf9ZViEaWpVtEw7OJM0wnAlF+6oAKsMVEub3xS++gKM1p7GrpThKghvxpkTjL9Q+So6rMjqx3q7l0UMqIQBW96tXYXgYsY3o4+ulrghRqvtfyxPcRTR/+zM2RG9XAsPD6nPn27P1RUS9/n15iFejA55pGtWZle6Sskx+0en3zfMVKfVE97d7cY8m1x7n8v/H6Q0EnEm326gxAZ5cov6gL3oSj84y7lUPukZ2c4m/x0wcBgfW44LKgL8C3RXc7dqjYnLwciWT3ojBHhDaU8osz3aVRI1HCKWNSG2AV1pS4ZHdK5xM6Acco0i5qHXyiVTeugpCkYUyxQqx7uYEiaJm2Ro0hL4nr2O9VfqCUtwS+pu/rJO3zzQrGlGHcV8CO/kgREo4ezWUd9FAN655rZ12XJtBgrZm48G69vPmtTbLa7835jlEg/ybnuAr/PVzBzgncC+Geruab7XHvkyw== X-OriginatorOrg: siemens.com X-MS-Exchange-CrossTenant-Network-Message-Id: e11863f4-a05c-47d2-3300-08dacb38cbef X-MS-Exchange-CrossTenant-AuthSource: PAXPR10MB5037.EURPRD10.PROD.OUTLOOK.COM X-MS-Exchange-CrossTenant-AuthAs: Internal X-MS-Exchange-CrossTenant-OriginalArrivalTime: 20 Nov 2022 20:50:02.7340 (UTC) X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted X-MS-Exchange-CrossTenant-Id: 38ae3bcd-9579-4fd4-adda-b42e1495d55a X-MS-Exchange-CrossTenant-MailboxType: HOSTED X-MS-Exchange-CrossTenant-UserPrincipalName: QqkLYI4N0r9hvgmFqyX2deSOaQ/nHe/NYgzFziAvqFL6D2hiNP4iKlt9Y/fovyyOzyNS+TsyxW+fB/vo6r887zbySU4K1Go4Q7h1Qpmm6AY= X-MS-Exchange-Transport-CrossTenantHeadersStamped: DU0PR10MB7094 List-Id: X-Webhook-Received: from li982-79.members.linode.com [45.33.32.79] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 20 Nov 2022 20:50:12 -0000 X-Groupsio-URL: https://lists.cip-project.org/g/cip-dev/message/10059 From: Sven Schultschik The secure boot setup with OP-TEE, u-boot and EFI works with a platform key (pk), key exchange key (kek) and signature database (db). isar-cip-core should only provide one secure boot solution and so the key structure and setup needed to be adjusted. Signed-off-by: Sven Schultschik --- .../files/sign_secure_image.sh | 2 +- .../secure-boot-secrets/files/KEK.auth | Bin 0 -> 2066 bytes .../secure-boot-secrets/files/KEK.crt | 19 +++++++++ .../secure-boot-secrets/files/KEK.esl | Bin 0 -> 839 bytes .../secure-boot-secrets/files/KEK.key | 28 +++++++++++++ .../secure-boot-secrets/files/PK.auth | Bin 0 -> 2064 bytes .../secure-boot-secrets/files/PK.crt | 19 +++++++++ .../secure-boot-secrets/files/PK.esl | Bin 0 -> 837 bytes .../secure-boot-secrets/files/PK.key | 28 +++++++++++++ .../files/PkKek-1-snakeoil.key | 27 ------------- .../files/PkKek-1-snakeoil.pem | 21 ---------- .../secure-boot-secrets/files/db.auth | Bin 0 -> 2067 bytes .../secure-boot-secrets/files/db.crt | 19 +++++++++ .../secure-boot-secrets/files/db.esl | Bin 0 -> 837 bytes .../secure-boot-secrets/files/db.key | 28 +++++++++++++ .../secure-boot-secrets.inc | 37 ++++++++++++++---- .../secure-boot-snakeoil_0.1.bb | 5 ++- 17 files changed, 174 insertions(+), 59 deletions(-) create mode 100644 recipes-devtools/secure-boot-secrets/files/KEK.auth create mode 100644 recipes-devtools/secure-boot-secrets/files/KEK.crt create mode 100644 recipes-devtools/secure-boot-secrets/files/KEK.esl create mode 100644 recipes-devtools/secure-boot-secrets/files/KEK.key create mode 100644 recipes-devtools/secure-boot-secrets/files/PK.auth create mode 100644 recipes-devtools/secure-boot-secrets/files/PK.crt create mode 100644 recipes-devtools/secure-boot-secrets/files/PK.esl create mode 100644 recipes-devtools/secure-boot-secrets/files/PK.key delete mode 100644 recipes-devtools/secure-boot-secrets/files/PkKek-1-snakeoil.key delete mode 100644 recipes-devtools/secure-boot-secrets/files/PkKek-1-snakeoil.pem create mode 100644 recipes-devtools/secure-boot-secrets/files/db.auth create mode 100644 recipes-devtools/secure-boot-secrets/files/db.crt create mode 100644 recipes-devtools/secure-boot-secrets/files/db.esl create mode 100644 recipes-devtools/secure-boot-secrets/files/db.key diff --git a/recipes-devtools/ebg-secure-boot-signer/files/sign_secure_image.sh b/recipes-devtools/ebg-secure-boot-signer/files/sign_secure_image.sh index 0c9b898..42e5b90 100644 --- a/recipes-devtools/ebg-secure-boot-signer/files/sign_secure_image.sh +++ b/recipes-devtools/ebg-secure-boot-signer/files/sign_secure_image.sh @@ -30,4 +30,4 @@ fi keydir=/usr/share/secure-boot-secrets -sbsign --key ${keydir}/secure-boot.key --cert ${keydir}/secure-boot.pem --output $signed $signee +sbsign --key ${keydir}/db.key --cert ${keydir}/db.crt --output $signed $signee \ No newline at end of file diff --git a/recipes-devtools/secure-boot-secrets/files/KEK.auth b/recipes-devtools/secure-boot-secrets/files/KEK.auth new file mode 100644 index 0000000000000000000000000000000000000000..3127ddfd55edd8e07baf97df7fe3ea862b1c3d91 GIT binary patch literal 2066 zcma)+cT|&E7Qpi*A&Al;ARtA^LLihcWh4j+0V4r2fFQ6il%eZV6akT791Mo0bX1D8 zHGm^!fQ%H$3=S5AQ8qLsfS?#$DG4A-lQQwl>^aOH*V*^aefPY3@4M%g-y3mp1z98# z@}JWV7u}$X(k1;r*iW1g+NFO_pqsh}SAz_A8597pGN2Sf;@e~j5DbGu0Wk=;2O(jQ zOi5mm0>puG222HHz>pvV*er)Z0Vq^42;*jER;h5)Da}i_d!;?l>V2f=rx1Vm0DD9s zRIz(OB?Qb34wIB|wIhE`c69YSPIf)+=j;G#C`;jRpefc2OTb}qSTB)^-=TidmjP(+ z{7RH9i~-0%MA_|zG5`Q_3z_^2^Bx1kwAUWPz0`a%5x3Xfi5EmgKP{v@%klR;QyY+% zHF$oezrAGn?Hh4P{kn^_mLE0QW8P|ye4gvS@pVWcTqG4<3JVG4AXS=2#yFw-5F{%d zcXw}cN8$Rn7t{_rd4n{3&qBvct?iZm_7jI4BqHj#n9@ov-_Xr!f58K##xjJp{Pg4G zLx?id8s{!%cG=pXmcSVrsT>`VMC32$jM64XgFoy`D}iZcIEql_tiE8yh}LiY`&%y=nvnWfhsYUru}ZYOPJX zbXd$Zhxp%Vo>BY`3Iia(O;_+3s4l9$x-?t~u9!P;UeH~-$ZBa^6Gle|5$R3y1W@zS zvkqL;rNqx0$b2$T0Dx_{7zh)Ion;qwSX6cZ5}4t8@ zLFQkL3u51jRhH`K)&Q9q{wIwhwNIe}c5lLW9h??wD?$+)X<Y`E?N`;rJt(YRbW2F2c?o;f@ET!BRk!z_DAUo!L_%a{ zN?Z7L3dPSmWJ%a$Uxr|T&5Zh6G7oIf^O@;Bse&8*ocg}H`PML5Vu!9A^6Sulp9{df ze#8zYSW-y|rw+}%W-O{Km>=(5TvC&rJ78O07jnK~%mZ_DMY>p7KJi?^chOnuHopA9 z+^cx0B%0rJ4-P#E9i3N>qYrTO?poBlVHtprX!JZqTLj|1G`IhIX?E`2jvW#WHk<)K zRK-IpB`;^5;Ky)_S}%-14_pC9Ji1AGm#IDm`5*AIPYGzC3lmJKw8qEgd00uLRD-de zMYAme%Ljt8kveX+PU6dj!KfsCSlmzL&2V-Yehe+Cev#FXL~&4WT|S-8A3bk2B`YCB zY_5-W=VZq~wyAL`TTeLx=iZye1~=k)N8VL?oAa%cdLKS**j;3+LR%rX<#Z3G?sYjm zQl^)3G-h4R4nvZgPcWGst^E*;s_L43W%u@*3f+ROkU0yCRh1llwVgu9ynetcZvd9RY6 zUu~aqrv~YbSvX@0`yFZ+k(3i1ZEZaM$Psyh`?(^Hh*HX;W^DgKDVNCnXv5ry^{+xH z>lThCo$5&GtN%5_pc+;MRQ{b(vVWqK1NpBp^+o5u;#B8t%d`it?zxflsE}D%D|UdeZJ0GD(c?5b zTm12PxGK62)4mZiKzdP|AD)*Z*t2z4=`Af*%+beCa=OTA|9z*Cgj^xnWbK0&ZNdOp zJGy+92J;VjR1wQIj)q*zVyf`s!`p{_&GR+d;y=f!D&y5lJ?<@&sp-N9Brx6@2-ima ziBq37_;HNBh)}F0Ujc&JbzC)L*@ZnYm{=y~cmI_@eXY zyZf^a^twKDKpmv-`v+9blPhL(I5mR~0tc_;>Aq<2NY;aIm#~%u7g*ucfrzvWCHj3c z-0^q3zP~k;wC+=oy$3_78by^{3T%s-j)ZOz3QZ0gR`@TgwcEPSW|g(zk93SEu91`#C>TMt=&TC|3U~Xt>Xkuh&WEchH8Y6M>Yi?pxLbi;Nm4Ug5 zk)HwRJ}#yvMn;B1tL!_EJUkHUsP4n?`rWprtgG0AzIU$CU$VowYtuaW9~)*ZaQc?K z;)Z+q{<$q7cOtHLZVqI&ogZHWX-YULd8?}5~qkFe5pSgf}&LfM3?p$ZS9k-4|jJmvrT_3Yo*bEGsbYVZD2 za@q0jnkhMxC%)zWw@d6rRVk}qtPao1S^kQL{clxIdgrSD^J`SqeJ#eHZr{qPm=n{E zEiB!vSIjW2zg6;PWzOy!an@7hc2+VmGcqtP4mJohkOhXnEFX&)i^wv)A1$ZCwm<6V zdY3E8cyC8Ci;{|gJV;uZMZ!R=0lNZzkOE;w#{Vp=2FySTIoN@53=DQghVo0gPyOGC znk#Hx?tJh1k}^e&*wv2R->Vy5SybKdIURMQbyCrxsC(-h?;hH>OR?YVT<}qE6{}jA zEGFs53#`s|9lf;%j8;99)$VQxZ&PRaKX=LJw{=T$d@kp9_KMXWwloU)bn~L>hPgXr zgar;Tt4Qe<&TUEFS@<%K>7U6=eJh=XiQlAmyNA8*H=lic$L*V~cMVrodNAFP`uw)! zTywb4LZ>JD10OkO>aU(EmYs3#=*?wQViWJr_|wGLJJB%dibj*%VGD;l7yd;h>7M#< zwS1jOOupj!<=~{%;!JL^wOpJ_%{06*ioC$3n zjH%2lOpL4y2Hb3%T5TR}-+39?85cA$OBysWiyAaB{$0S##K^=XlA;}IX}MH*v43Zj z+R5*`lO4X~MS_fg>S5#t8X;vUVIaoF9LmDX!yoMF>g(zk93SEu91n3@bh!?VkJX#WQvu&9#kd?0?H|z7r#TEcUwQ zvpDZ|lSapxE!k=5dqgF--MX_UU53rkK{+fe#&!S9UkP>6cK$I2RmP`2?0>b!z30;I z3_EYm+_e|9=PkYPL?_fiamEp`jq}-@gkGL#vt^razB=G|>xB6~uPD3?V9FCOF8yO6 zcvU5HdfcR)0@wdCJ?*!&wYKaPS9-EmxLW&o@}6a_dwR8^WFsbfr}G=f-;h4#`S@kS z?2QctPdiy}mfyKi=2$#e^5(;h25;vt>@zx85EZBJ^JUO}n^)V?61Q%9B~s7C%*epF zIM^W2Ko%JKvV1IJEFzOG*StMB@8go~8-KnlE>5wi-SpnXKprHm%mR$12J8y>K?;N! z8UM4e8ZZMX=vT#_ve5WMB#P+8%dsa?(<)i8E_SB{-Z{Kn4@4Xq{bOTmz zGMH}15$CCXVcEt_zy3d5Zo#c$s9wB1Ezf%H<{vuKOg>Agom-@0e*0sCNnT(3&Yb`4 z9`P}0pWkirn$NbxU|Z9=75qn>HQx7i#df@%b7{}Ii)-KS$QH2JuO=w!oBq5a$>{O1 z&8a5#K91G-wr?IceU$uQ9dhpDXK8^qX6_5trqyh?6Rz#{oo}|dP(#Ix`r>|B=eQ?V zCQUWwZLW%cdCExR5!3DW;^noM_o(l(Sr=;9#25=qdXd0fWMG6Z-QvzP$oUQ_4*?T4 zOA{jlfB(f}Z?dbJs$vc#PyAdRS+MT8&TnUyy2(e|JrfG~#FIN*V&dv;r^Ndt*1Ab; zUR_kX=((cNMK|&%W;8Wr@j8-%S*^ zI<@0x_L=T8fw?o?D!v|QPw`ll9=hO(%n~bC;awS%>gNhdPWyd7BGz(M{o?d~*NujL zd-vW-Vd#^oIMo?z`F4>~Y<{+w!6V};>HB@n>u;@}$Yt@Z(o&Wsz-jk`T!*VwPyej! z|Freo%J$9;r;jOJ;t&rER@E?I;8?xrskEDs%2DYBpP23ys~>tlk2A&O`|DKR3DSSR zEB+S`WIJspwximoePQH*rB9|T_iEp|S~N!cLy;>pq)^iY(t<#sq-1RD;v!@cRxxYO PXel*XN{yCMSV}1Xh66(< literal 0 HcmV?d00001 diff --git a/recipes-devtools/secure-boot-secrets/files/PK.crt b/recipes-devtools/secure-boot-secrets/files/PK.crt new file mode 100644 index 0000000..b775cd9 --- /dev/null +++ b/recipes-devtools/secure-boot-secrets/files/PK.crt @@ -0,0 +1,19 @@ +-----BEGIN CERTIFICATE----- +MIIDFTCCAf2gAwIBAgIUZCtVOTmlE6NPiVomyfe7Y0D0blkwDQYJKoZIhvcNAQEL +BQAwGjEYMBYGA1UEAwwPU0lFTUVOU19URVNUX1BLMB4XDTIyMDcxOTE0MjEyMVoX +DTIzMDcxOTE0MjEyMVowGjEYMBYGA1UEAwwPU0lFTUVOU19URVNUX1BLMIIBIjAN +BgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAqBWGwYXAgiuFSiLcMuAfzN93GFZP +2WRMKM2ZSNaRYV5yrGKTj9R86tK7nfbo5gcMKa2BrD/7H7PcXBvGXdcp5l5LhzSB +QZmEa2ZnvBUZttrcvGccBkFAI1ZWXEW/mfpgfhs+T1wwejPK8L/qrEeM0rtoPksJ +ba3QK56l0OQsVUAhmMQWsZ8GQhLpyIY9Bp83q1DHhZCf+dQg7VACbhdzdfw4EdUk +aZdekrkQ1/0C5Y85PTs5jRci5K0TeyvHY7ymhbyNKlodWJNLZw8zX9gbyknj6YCb +sYBw5YkF2Xfc2HZBc50Z2eGxMO2foY4ywXBaXiD56VK/POq2ZmG1tuoUfwIDAQAB +o1MwUTAdBgNVHQ4EFgQUktN87cme8aS3sfnuc3NkOH2y7zQwHwYDVR0jBBgwFoAU +ktN87cme8aS3sfnuc3NkOH2y7zQwDwYDVR0TAQH/BAUwAwEB/zANBgkqhkiG9w0B +AQsFAAOCAQEAYiDDUdI4DNGzyHGObM+2Xk/WeoosVdhkOzXe7XXoBaWeKZKrAY6N +YWktbiJvJGIK/QQIOunuIhQCBvyJa5psV3nil+68fWUjt7jW/d6Y9i1Qq7Iwlz4I +Xkkn0Kaxsvr/4ac4CyQxJ3O3Zm47nbP4LJY08xomzqIkN9vxgDRujoe5bP+HSF9c +ZvPuskqfBqQwtoKuqA/EQyjvjopdiO2c0ryu0a3vuGsQOL8mERVNZ+d4YjLjxrNl +ND9MQXtvPezjgvEZ8DtUzvHzGxDsNkegrWZ8sNxXK0b3DpsXEoB4mH9zjx1DXuTU +kpUzDYN6X+nKMijiAtvvF3d907wnujyuVQ== +-----END CERTIFICATE----- diff --git a/recipes-devtools/secure-boot-secrets/files/PK.esl b/recipes-devtools/secure-boot-secrets/files/PK.esl new file mode 100644 index 0000000000000000000000000000000000000000..acd616b5ce5fa5fedfcd0a77334821fc834f1a88 GIT binary patch literal 837 zcmZ1&d0^?2Da*aux2_hA(f&~6%FF-;nm}3*2$YnJja^)XOu{N=?J;O#7By&M{JVge ziIIs(Bt<*a(sHTrV*k!4wUgg>Cp&z}i!|V6g(zk93SEu91z-b%DA|a~-s$|t@i(MTc|LyGFneP|!P8FGo8@`>`zAPV$7>mfH%QbIL&ilAz`^KN| zii=Y$YB#+%F^~sIE3*J&sR6qJevkrTM#ldvtOm?L3OU$;F$@fLMusGX!-1D9crI=} zQP`Jrep{UXwW=Jb%ruW{KzF=KCPjk|0#=hRfOx--Ce3c}wzbqV9FW)JNFtPpV z%$}7KUioPHyFIn3%G-Bb`+IN3H{F2Mn+&Ggam0D5Us$$r)35&zms@bF7^)X?mOpJ_%{06*ioC$3n zjH%2lOpL4y2Hb3%T5TR}-+39?85cA$OB*yXiyJgC{$Ie%#K^=X5|lTkSZ7l1FVl37 zUp9XFhh#S5#t8X;{cX&}zV9LmDXBM|KA>g(zk93SEu91`#C>TMt=&TC|3 zU~Xt>Xkuh&WEchH8Y6M>Yi?pxLbeR(Ugjo7eg>fXxR{z485s_(vhO_d@Ia`ex(~za zciWb-u3``R-nmA9$qwhPP4nb`Y?!sc>09!O8}fk@m;d;@!n3v3rjE_Y{OX!QYqbfH zOWq{UKA!UB*M-QdocAXd{cY9L&&geKbBc%H7bn@PDp$gn|2-Kq#qy$wb*;q?-ly(+ ztN4Cx)beqS?%le4<^tw9k1Q6tbDjBi+*Y$cxA}?QThh73vwvUDk_-{IlFJfSx=GMS;@rA z$iTQb*dWkA78w4rd@N!tBFprCw44gt{-~qtU9KqOy&cIcN-75OAZcY52?MbP>| zOxY|=j12s?c735Ig`OsH-^~1DIs5L74v`$U2X-DyTc$2ERn4BgZ0>&33cpjH=evH% z*)-TMy?=J|zsPeuDH3lFSR1tLUlClOzWMdcw_oS%`ZNFag*&UVrAKAE!It9|Qg(HQLyMXt<{a!nIR3j%?XlCiOii;ziJ z#jHKRf=Uz^8-Jk%m2R`C_mYQ()0xbay@%5lGQlZ=Vel4HHvs}y{S>^+aHRk;1lN83w5{ppJJ-xbnrq=+0>f~afhSR;~TVBy6SQ~*>Zo~EPK_L+uZE? zHwi!7bedO6P&!NRS$t`~v1vv4id_w+HA;HoCnsInDciE^aXZ8N8IykJUX9ePzkBFH zbl-`1w+iRNi^3<*9_(Qi3uX4wIEby7$_hOun7lWpF0yaq%p3Ls{!PZmub~uESQQXc zOwF_xD0nGoIBC(Xj{9p1m$h{+BYvqA;@sk&QUFJ~1z+QRPnDyhl z=I6@Y^S(ds@Z2>a(O`R|%Y&PpntQjHl$P%?PUh~uJu_)zbKlPIzQMX(k=sNr>dh^B zkiFfYFT`8&*DE1!s|AnxzD!MWTv?Ugec;Vm=_9>~6Q}oYYPLEwcc$ewVW%obJ03T# zt9suaB~4lsuNxp3eCuqPuKIcXEEZ)Qs|#Nvi%xu1U%JNYW|FOU)|DHMuf(=I+kINa Paf;{kpd$s2M~?siFKstz literal 0 HcmV?d00001 diff --git a/recipes-devtools/secure-boot-secrets/files/db.crt b/recipes-devtools/secure-boot-secrets/files/db.crt new file mode 100644 index 0000000..d8016c0 --- /dev/null +++ b/recipes-devtools/secure-boot-secrets/files/db.crt @@ -0,0 +1,19 @@ +-----BEGIN CERTIFICATE----- +MIIDFTCCAf2gAwIBAgIULYM1S6ThMZcCNiIfnfnXYA/n4awwDQYJKoZIhvcNAQEL +BQAwGjEYMBYGA1UEAwwPU0lFTUVOU19URVNUX2RiMB4XDTIyMDcxOTE0MjEyMloX +DTIzMDcxOTE0MjEyMlowGjEYMBYGA1UEAwwPU0lFTUVOU19URVNUX2RiMIIBIjAN +BgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAp0S/0yPuxYYZIIyrwOCT2Z7u+nxv +6jn1TF8XOZBLqm0LlBL0tjC4NHS/6leQgtKbFs/M/FpBv0OCHDRCpMaNK6ogTHI/ +ScStINv2TCtKICjY7yeOvzrvX88wxZ3l1c1oc+NFVCwz3ylnPwpHzmi8nI6JZ/1i +sYXr9wTMOW/SgLU9PHdIdipnEhDayxtTPS+7/DX5tdctcKeUNSxCwdB8dpXZIF7D +W2dfgCupRS0I5LTfrpo/Jem2Rj+PshPhsssNGhEbai7mX3WPMzV4V6i6gDV8Ii4X +yZLSuR2EuuOHAO+Ykvtt1Vktf93C0FuOyF9GeENx0RPJzcGMBRZVA0oowQIDAQAB +o1MwUTAdBgNVHQ4EFgQUalXGEWO9XH5ZjrGZ2D8QT4Izx9YwHwYDVR0jBBgwFoAU +alXGEWO9XH5ZjrGZ2D8QT4Izx9YwDwYDVR0TAQH/BAUwAwEB/zANBgkqhkiG9w0B +AQsFAAOCAQEAmT8QcOkRMZKi2ojfrXGmhommCJaHZcRF7BzmiOP5tyJORccLRXCl +05zLoW8JJSZmgXlEvWpVEA4LU4JtrhpCG2dqEbotKmkDI8oAVWAzlbraItJfk6L1 +pkB4AAd51TMF8Z6D5yOLnvfjiEm6kGEwt1lE4NmJKb20NHV3vDNjC4vbmWKxg465 +901TLYpZthTRLp1y4Gu3MI5USxn66hJLOqDijvSVYkGpemeLwOzNG8SNYZGXj7KD +OsKdmTm2E0J6QT4MRgrVLvbiYpKiXy1QEVPazXYtJ88vagQjLDrQ9VlyyPUnpaxK +2WI9S2rU2EHqFrTmu8skQZRJl1LEcEHFxA== +-----END CERTIFICATE----- diff --git a/recipes-devtools/secure-boot-secrets/files/db.esl b/recipes-devtools/secure-boot-secrets/files/db.esl new file mode 100644 index 0000000000000000000000000000000000000000..644357bedea2acb605e9f3abbd97423133844c0c GIT binary patch literal 837 zcmZ1&d0^?2Da*aux2_hA(f&~6%FF-;nm}3*2$YnJja^)XOu{N=?J;O#7By&M{JVge ziIIs(M7P=0d&xt?=}cxy@^gP)PvC$4aE$>k8>d#AN85K^Mn-N{1_LQW2?H@U=1>-9 z9{ylYS6^4Z;P?>N;E?!~Bm+5dULzv|b3;o*6C*<-qbMNP7>SElZxf>uvQ><%49rc8 z{0u4~45bZMt-%dW@m4DV-5`ki|oSK52KLIU#;hObH9uGGp7;H6hv%*d zi3ZyvT^`)*)ZDwpq_ljGaWZ%J?U_j%oBMWt_YKzVirgl0QEzV1gY4}FeIeeGzg`J> zTP=9h_ho95oH)IIQ?u2fxic-d2|HCe+VQw?UDf;cC~4B7c-;WO z;9FjSY7xUS#;v7`qDLCH X-Patchwork-Id: 13050151 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id BC056C4332F for ; Sun, 20 Nov 2022 20:50:22 +0000 (UTC) Received: from EUR04-DB3-obe.outbound.protection.outlook.com (EUR04-DB3-obe.outbound.protection.outlook.com [40.107.6.47]) by mx.groups.io with SMTP id smtpd.web11.22513.1668977419572189914 for ; Sun, 20 Nov 2022 12:50:19 -0800 Authentication-Results: mx.groups.io; dkim=fail reason="body hash did not verify" header.i=@siemens.com header.s=selector2 header.b=SlCtJ2bH; spf=pass (domain: siemens.com, ip: 40.107.6.47, mailfrom: sven.schultschik@siemens.com) ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=RujEWRLIpPEB5fAYiU9y75MCsl0+pgfj8CZr6BefY1tAOUKCG/8y8UFgT8fmpMBWzw9n6+7MoBVZpgbSREVcyFsYlWLMpGdi/RpdsPIrgJUgTsZw9vGfGTxsnW+2R1aPH5zLMkvNEgLN3Mi1TWK7/c2y/9sS1out+L0juDcARlVHdhRbGYOWrDwSGt2swNb8/zKQUlkBb6LGuY0fKWG92oB83WXHqBBb+P9ZdBtjrtGKOoTAS3wi7qjzN/7xm7gL/gRhUOVeWr8RBzyHHEFY+do9RDKWP/JhClMDXHsj/0s/+kSGwM3cztzdltQZN43siPofwLlm4Iab3PFFrWdnQw== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=68ObBLUGmv0zSm3gIMEVogaSsDbNOabZGMdqIwrYN/E=; b=amFp3sVfM0AwcfLkCy9vpGh2VMXMuQHI4DD2/EsM+5tlmhaP3qB8ugRVnCEXt/vYDbthSZ9s+qAGlrDbN5wa60ubtXNGT01+ZPUZo4uKoEcPeDRNZxJ01zTS0B4/643qzxn+ateV803mWUl5ffBt3yZZuJJ27QkaSY5iiAMWbjhqtdK1BAzPb7NUDzXPRGlIUEqYYJcq+ebq9Iw5jgTUtyuUwQCNNJ2Y7iJqflVlpOpUbHLbNXjecWXVYh4B2BtXNFK/b1gkAfLE2GGJOEr/JO6WfUNZ7YZoI8jzpWYcVOhKgqRvujKZnZnP5TiXj3P1jh1ykUZFtNf9vFmn7eE7rw== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=siemens.com; dmarc=pass action=none header.from=siemens.com; dkim=pass header.d=siemens.com; arc=none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=siemens.com; s=selector2; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=68ObBLUGmv0zSm3gIMEVogaSsDbNOabZGMdqIwrYN/E=; b=SlCtJ2bHhfeOzbxWL1/IIumRil6Mj0WitMD4lRJDuA+Uz1cfDkuVhaU5sLddx5J2G2H7ViKBp/0ZMYIgUh/b6FzXL+BN0ppLJuDo5ubrIXakBuU05tbKXYoi8c0BlgQ1EKckKQ6dZN2A+I7cjkkvDG3XH21QbPK6kJTT6NxVlSsifVkaO3dgR/qkiFrwKtr/b8b6BegfpVwKmylY1Lo/lLyl07TDxo4smIHVNH2vJX14tITvWX6qu00S/nv8G9Jl/ax37y40zzpcDY5S8nMQFU1C0L/Dfvth6cNJ1Mm3zQPyK2MZ5wiYYUwlYUm7OMB+PCu5F1R0DhH+BrGCAsU2vg== Authentication-Results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=siemens.com; Received: from PAXPR10MB5037.EURPRD10.PROD.OUTLOOK.COM (2603:10a6:102:210::11) by DU0PR10MB7094.EURPRD10.PROD.OUTLOOK.COM (2603:10a6:10:42e::11) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.5834.11; Sun, 20 Nov 2022 20:50:17 +0000 Received: from PAXPR10MB5037.EURPRD10.PROD.OUTLOOK.COM ([fe80::955a:f715:5319:7933]) by PAXPR10MB5037.EURPRD10.PROD.OUTLOOK.COM ([fe80::955a:f715:5319:7933%9]) with mapi id 15.20.5834.015; Sun, 20 Nov 2022 20:50:17 +0000 From: sven.schultschik@siemens.com To: cip-dev@lists.cip-project.org CC: jan.kiszka@siemens.com, Sven Schultschik Subject: [isar-cip-core][PATCH 7/8] enhance start-qemu.sh for arm64 secure boot Date: Sun, 20 Nov 2022 21:47:10 +0100 Message-ID: <20221120204711.5826-8-sven.schultschik@siemens.com> X-Mailer: git-send-email 2.30.2 In-Reply-To: <20221120204711.5826-1-sven.schultschik@siemens.com> References: <20221120204711.5826-1-sven.schultschik@siemens.com> X-ClientProxiedBy: FR0P281CA0067.DEUP281.PROD.OUTLOOK.COM (2603:10a6:d10:49::21) To PAXPR10MB5037.EURPRD10.PROD.OUTLOOK.COM (2603:10a6:102:210::11) MIME-Version: 1.0 X-MS-PublicTrafficType: Email X-MS-TrafficTypeDiagnostic: PAXPR10MB5037:EE_|DU0PR10MB7094:EE_ X-MS-Office365-Filtering-Correlation-Id: cc2f27ea-7e06-47ee-9923-08dacb38d3c0 X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam: BCL:0; X-Microsoft-Antispam-Message-Info: t+jBfSLUROmOp18KV7zG+y/aS691gB4DJFzn5OMtgnp2TeOY4p0rnzsYnh0txchU0G67pyrH7dqPZMJDDp3o9sWIIMOaU/hKkzC4UeXoPSDWYQ087pZE5MQgsDphawxTN++uFxJz9hGYLpOdST1pI0JOCJmHSeoVknfPEHIh/Hcasg7zwDYa2WctpQxRF6DpBKYo3f/m8U+Pm7sLq4IcaA1Ml6SCMh2eEHvS3pN9lRtRnGGvMOoXJBwkcx/ZYkPYUiEVAx0ReIUTZzgNTBDxaOAfoSg87GO/ZYiBYxPiTbtjUZfoQCc1aGIc2PlzvFu5Lq96cOxot9N7r/OEkJnUj6lqvu6STDLVeoZcJpLQBtjI7biG/o1TAu7byclVbGxg3BOAy06Oc36O68hAANINfK3fp/KM4wwoUmwIZvBd3CdyjYqKbPP8stzX3pTZy4PcwQzqCMFvkKKAruPQuB8UheEsENSV2ya/QHrKvTHmF0PFoIZy7T/A8RDUq0LjSw3GvTl9NFm97R6aRWCa1MJzMuIAzQo1L7vgx6c/uuL3WRNGImI8bg0fveg7A+ewxLjayFqSmZ6Vf2W/xrCkP8Uy8F6UI+BzL3YlUjsp0Gi9gCZdhzaEpNQSyzhn0X/MGwyBFO55l3lJNAy4rM9wZ7EFGg== X-Forefront-Antispam-Report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:PAXPR10MB5037.EURPRD10.PROD.OUTLOOK.COM;PTR:;CAT:NONE;SFS:(13230022)(4636009)(136003)(366004)(396003)(346002)(39860400002)(376002)(451199015)(2906002)(26005)(83380400001)(9686003)(86362001)(4326008)(6512007)(8676002)(66556008)(66476007)(82960400001)(66946007)(38100700002)(36756003)(41300700001)(6916009)(8936002)(5660300002)(316002)(107886003)(55236004)(478600001)(186003)(1076003)(6486002)(6666004)(2616005)(6506007);DIR:OUT;SFP:1101; X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1 X-MS-Exchange-AntiSpam-MessageData-0: nKD+tp8ofQWp3Isl18Uw4mFxs5lxkmDeXHNU9AxdkOUv8nTmA/gIaZnln6ZUTnKhzfCRA5u2JNSKpK59w95rdq78EkmuGCuLJfEeYbFw7A5Y1QEMpHbUPg7mZA65pmdj0dpYSIYQcZXoAhwsVX4H5xEouAqEFgfxkARPydJuBiy4jTyEz7Bw75QMwq8DhuD9L/9qAGd0j9q+xC9zrISV/r2tn+DgzK3i14P/9rQWAZnBe+rW8Q3hTCFFsg1sRPbYzjwoMm4yt4cphTXnZMnsqjdvUdgRjooQEFM0z/p2KzLvJDk/HE837g1PjS2iVhcjZHwWwI45BXuOBsaueLC/VgFTCbJph+aaGIRjeUct6Cj1yjDsMK2SCnkPxZMZVtqf4l16GyOfDuse5dHIf4wnxsYBhsJMxR99vn42Oq+WX0+1YN2xuGVNCWkDFu5Fg3+gRrXENQZwEGjCmFYWzj91Gm/Z8hzBHnxDuxttzjiRQvok7fFhMBsru4MCW6xWlHsmHp9wrSlbAlUIUQIbjPzLNVVRHXoc+/vTMrx0C56/ntyUcNAQ5q1wXjAoRCsoCMw9mRJJEPrtkFWd/oqL1Mv+9jXCvy1m6P9Gecs5nyyJlAckBf/u7NH/CDKeCAZX4yNLJz1ZQCV/h9On1iMQm2aWeMYVH0TKDkJEEcz91T0kKuKMNiyuz3tWynUOEOJWypLrXOYf26P1YRND4ZrnMW6imbDLrYXnCvLVPaK0yjkJY5hIbZPWVq86jpHdH/ypTlMEJi9mQ7nUIFvEVDrAde4tae1l4sV86oaJ0CdLkMbMPdtxWG9ASOktzcZCdXMXwGWr7yari/c8Ud/gQyTdUZoxshZlZ+O8ZswyzWV+qZwyzNm4GZyJTccYGVjvjQ/S0v/z2DMCeFCViRmoNPesLNvgsh5/MLL4GWox1we+/kCkdEHRjBngsGUIjhCHsh1XKWDgAwBO5sYLwNGDTWCNw0mHklwCefeA5cdUFgtpAih9tvgKY3Ub+VGRtiTvFM5v7A33XSkflNt1VWQbGneak4K6j7LZbJa91s3QwakI1TrW8pl3mFegitMcbc7VrEFLGI2PTz4OftUovzY0LvIywRYnzzkxrGLY7G6Pd0xEaVgiSUyGYzvl8tnuIy10n+5QRdvxfNmKvU8GaB6mRvzfG1x1CDrAX0GKw3jUlDM39gEXz7WZXbkp9HvLAx28yTn59JmnMTiXDABepSbA7ymYFiJ2+w/YBc13wKVBIyZyAZ6jBRXCOrwYCAYEWts3QDLLSr1saWUaWVbrp0TdvzshgCgjwM0Ty81GLWbslreyu7BIm8dDGyN1t9W6dRW4udrYzzWHOner6ZPQl5Wvh3zmYaeOzbqRsm2tt8N15nMRpgCmeMLOppTcPoxkmXGIe6ONEm3tAocdlKt7EBaT7hYZS2cfOAlT9Z72FLF61RaVuCu7pSkK0HHrs9IZtfo9zB9goO6n7cW5t9endBqbbs21V59jdOIozvhLfaZkQo9gqbZIikGjQpbdztRJyKHy64nNmw1b9AiPrbuE5nvc74fDnyluX3j58LGB1FzfvJYd2AmQfBhTALkwZ9vbcP6Dcq1sOYQNSef8dAAjUvHcRDFc4m6P4w== X-OriginatorOrg: siemens.com X-MS-Exchange-CrossTenant-Network-Message-Id: cc2f27ea-7e06-47ee-9923-08dacb38d3c0 X-MS-Exchange-CrossTenant-AuthSource: PAXPR10MB5037.EURPRD10.PROD.OUTLOOK.COM X-MS-Exchange-CrossTenant-AuthAs: Internal X-MS-Exchange-CrossTenant-OriginalArrivalTime: 20 Nov 2022 20:50:17.4609 (UTC) X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted X-MS-Exchange-CrossTenant-Id: 38ae3bcd-9579-4fd4-adda-b42e1495d55a X-MS-Exchange-CrossTenant-MailboxType: HOSTED X-MS-Exchange-CrossTenant-UserPrincipalName: J83VM/CQHbKGYzKPEclxq5S1wT9w5q5C4PlQ+rTP4+vG3Fa1o1oKEkOVQgo0f9t+HEKi0Loro/QUth4m32AKaG/JrIAg2TkNtNtLDovVTpM= X-MS-Exchange-Transport-CrossTenantHeadersStamped: DU0PR10MB7094 List-Id: X-Webhook-Received: from li982-79.members.linode.com [45.33.32.79] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 20 Nov 2022 20:50:22 -0000 X-Groupsio-URL: https://lists.cip-project.org/g/cip-dev/message/10060 From: Sven Schultschik The start-qemu shell script need some adjustments to switch on secure in the machine statement and adds the virtual random number generator if secure boot is enabled. Signed-off-by: Sven Schultschik --- start-qemu.sh | 17 +++++++++++++++-- 1 file changed, 15 insertions(+), 2 deletions(-) diff --git a/start-qemu.sh b/start-qemu.sh index dd16aed..5617a2a 100755 --- a/start-qemu.sh +++ b/start-qemu.sh @@ -80,13 +80,22 @@ case "${arch}" in QEMU_EXTRA_ARGS=" \ -cpu cortex-a57 \ -smp 4 \ - -machine virt \ -device virtio-serial-device \ -device virtconsole,chardev=con -chardev vc,id=con \ -device virtio-blk-device,drive=disk \ -device virtio-net-device,netdev=net" KERNEL_CMDLINE=" \ root=/dev/vda rw" + if [ -n "${SECURE_BOOT}" ]; then + QEMU_EXTRA_ARGS=" \ + ${QEMU_EXTRA_ARGS} \ + -machine virt,secure=on \ + -device virtio-rng-device" + else + QEMU_EXTRA_ARGS=" \ + ${QEMU_EXTRA_ARGS} \ + -machine virt" + fi ;; arm|armhf) QEMU_ARCH=arm @@ -165,7 +174,11 @@ if [ -n "${SECURE_BOOT}${SWUPDATE_BOOT}" ]; then fi ;; arm64|aarch64|arm|armhf) - u_boot_bin=${FIRMWARE_BIN:-./build/tmp/deploy/images/qemu-${QEMU_ARCH}/firmware.bin} + if [ -n "${SECURE_BOOT}" ]; then + u_boot_bin=${FIRMWARE_BIN:-./build/tmp/deploy/images/qemu-${QEMU_ARCH}/flash.bin} + else + u_boot_bin=${FIRMWARE_BIN:-./build/tmp/deploy/images/qemu-${QEMU_ARCH}/firmware.bin} + fi ${QEMU_PATH}${QEMU} \ -drive file=${IMAGE_PREFIX}.wic,discard=unmap,if=none,id=disk,format=raw \ From patchwork Sun Nov 20 20:47:11 2022 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: "Schultschik, Sven" X-Patchwork-Id: 13050152 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id A8C76C433FE for ; Sun, 20 Nov 2022 20:50:42 +0000 (UTC) Received: from EUR04-DB3-obe.outbound.protection.outlook.com (EUR04-DB3-obe.outbound.protection.outlook.com [40.107.6.88]) by mx.groups.io with SMTP id smtpd.web11.22517.1668977432520165781 for ; Sun, 20 Nov 2022 12:50:32 -0800 Authentication-Results: mx.groups.io; dkim=fail reason="body hash did not verify" header.i=@siemens.com header.s=selector2 header.b=uFhjXs6d; spf=pass (domain: siemens.com, ip: 40.107.6.88, mailfrom: sven.schultschik@siemens.com) ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=fJPNVIA3sZRbR9YLyMRrULQmoB8SlzHFUVvEgVCeZ1GmtQ78SVuFjPINahSLN4V5u1Dco9f44YS1J/doKW0a20+tWX3cg8p7Kb64g+xbNn4nvKrQCj69itAwHyN1IMT7mIVNfDbPCluQGO+Ii7fwNF+WnuqyUxMKWkOK1sshUm+Snv46WfhzIvHcwOq4WHFJVIp2Cib0yeu8//kpoeYLgFhI/0JnOIbVStbsnWAdpYXwcre+PEdf/613Hdxf/igG7jS1vHZrIag6LLNGSGBhHtcZzGLXRMXTX2fJjgkPdwGXKBku1321GhGUqMcLCBV3ImVIVlYQlw5tvLFoHxUvJQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=O8Fuky/XBhRaTNoSeTJD7CL3vYvx6YZSJzfGFV9DHHo=; b=Yt6iXYKWswa4StAMH8z4WwEW3ZRo2RLovyFn0kcWebXnsdjimeRWzaBMAMemvKp4WQktJogs7IUGj609nR7L9nVjuFSVHTwNp4BTyYcxp10OZHqSEu5M4nUoIZFxSumEFj8yBq5vKszfWrlEZS2gCFwO9p09vCeBUuv1zgvwzu7owh1zbqdNTbw/11HRjsHJ0soEqA99fKAc9vgTDX6ZvqN0Ix+f7KvumlDvu0cIJDWh6eMWMXoWw39KHgvCtTgIsoeWU8N1NmBspOJTx4Sb7b3yrgYw9Fbd/aEi/6Ayjt0F811I470dZs4N8Qw1mA7yhIKPo3PEq04azJ8WSGY00Q== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=siemens.com; dmarc=pass action=none header.from=siemens.com; dkim=pass header.d=siemens.com; arc=none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=siemens.com; s=selector2; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=O8Fuky/XBhRaTNoSeTJD7CL3vYvx6YZSJzfGFV9DHHo=; b=uFhjXs6dlr3Cwlw08oDNfBgduWYIUuPxuzp+0IeNuDj3Ry5SKEg+7ejiC8r3m5SlQPlKM+TiCuj1NbFlDcWr0xENe5dBXC+I9R17qx2dOz0K5kIjJx3Rno/WavECKBYSX5XOrK6mnVKTRjmeHU3y7+5KZNnzZqsQzPnMtmQFbujA4NSDaiOIWoTAh0gDttmexrF3sFYQ1+hQx3be3hY0ev2h4zz0AOxS+wz9GqJ3w23rw4aXFGnvln1OBfL0ISDb39tC4wQwLiBBtaTTbH9E0qku6CPECCvn8o1Tpagh97D/+uWGaTB51+SS64wpi6yMw/bsJ0YMfPaknRVrQu9+Vg== Authentication-Results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=siemens.com; Received: from PAXPR10MB5037.EURPRD10.PROD.OUTLOOK.COM (2603:10a6:102:210::11) by DU0PR10MB7094.EURPRD10.PROD.OUTLOOK.COM (2603:10a6:10:42e::11) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.5834.11; Sun, 20 Nov 2022 20:50:30 +0000 Received: from PAXPR10MB5037.EURPRD10.PROD.OUTLOOK.COM ([fe80::955a:f715:5319:7933]) by PAXPR10MB5037.EURPRD10.PROD.OUTLOOK.COM ([fe80::955a:f715:5319:7933%9]) with mapi id 15.20.5834.015; Sun, 20 Nov 2022 20:50:30 +0000 From: sven.schultschik@siemens.com To: cip-dev@lists.cip-project.org CC: jan.kiszka@siemens.com, Sven Schultschik Subject: [isar-cip-core][PATCH 8/8] Use of snakeoil keys for qemu use case Date: Sun, 20 Nov 2022 21:47:11 +0100 Message-ID: <20221120204711.5826-9-sven.schultschik@siemens.com> X-Mailer: git-send-email 2.30.2 In-Reply-To: <20221120204711.5826-1-sven.schultschik@siemens.com> References: <20221120204711.5826-1-sven.schultschik@siemens.com> X-ClientProxiedBy: FR3P281CA0013.DEUP281.PROD.OUTLOOK.COM (2603:10a6:d10:1d::18) To PAXPR10MB5037.EURPRD10.PROD.OUTLOOK.COM (2603:10a6:102:210::11) MIME-Version: 1.0 X-MS-PublicTrafficType: Email X-MS-TrafficTypeDiagnostic: PAXPR10MB5037:EE_|DU0PR10MB7094:EE_ X-MS-Office365-Filtering-Correlation-Id: f4278706-c464-4dc7-ba21-08dacb38dc84 X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam: BCL:0; X-Microsoft-Antispam-Message-Info: SATdCG7OhxK9F4DnvWv1677xRrNwp6DgWPPo9+wx8cS4Z4hNFQQ7fwDJg0QLIglyplzt1dQHa3Od/H5v/4kBTuYyz47zuBpDYtR6ACv+oFoNiMIKcF3b+EXKa04tsOKfqf8ILjVyBbcl+rtXa8yRPVxgXa29AAg81mqmsEjdXHC/gPgwhnBrAUEtyu7QuYpn0H/XLVKxh5Tvw6iO91QBahLyVJem992gmxHlno+FlcS8rKcxAeyMvrSdGxqYRmQcQnQQn0lF6kiPRDdADD80EO0gMrjOqx/c6Jr7l+HSaj2uNv4V7GWqs6lSzVQm9/V2e1tt3BR6zRdm4W6HUt4uFLldZMxNlNs5tIpResEZxnHYO2YhPeb1NbpS/26Wjr0f5sMexqzUCdrT43Fx/Wz1/qhzgthcccHYLIiLdzSpHzROBQE9sY6EcHZUBhmqKWHM6Cdoo4NU5b73fwZcD0TJJw0mncOgbD2HXT3In2GDs6Yg0aRqXtRq1FeWo58DkxyVU6Ovq33hIWxGXUCge8piD2kJng0x2Kfpt2Ya5lXHlOye9rt2om1iWX2B/yD28K9nFs/xxnHs7Q1XUPj48HCfmddJrmf6bNmTAduiZyRTkal4g4kjyKveovkl27swVQ1dps6MIoSzIbpPTEerblL1iw== X-Forefront-Antispam-Report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:PAXPR10MB5037.EURPRD10.PROD.OUTLOOK.COM;PTR:;CAT:NONE;SFS:(13230022)(4636009)(136003)(366004)(396003)(346002)(39860400002)(376002)(451199015)(2906002)(26005)(83380400001)(9686003)(86362001)(4326008)(6512007)(8676002)(66556008)(66476007)(82960400001)(66946007)(38100700002)(36756003)(41300700001)(6916009)(8936002)(5660300002)(316002)(107886003)(55236004)(478600001)(186003)(1076003)(6486002)(6666004)(2616005)(6506007);DIR:OUT;SFP:1101; X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1 X-MS-Exchange-AntiSpam-MessageData-0: v584TU65xakZhv4/qp5Jw4RYf+s4GAxXW5g/YpMRmjoWbNZg1JKX+60ydGvqVucw3EYK3tY1vCrcw12CPUpQbmpWQV4R7p+H1nUddf12JusG4OAjqlwBQRMw9zhXP8+rtA5v5SO6CbKAGr7Klj2KdbBoKrpsUtUB7kC4KZeTt+8z1vyzHv7gC73/e4Cj2W7NnMjaHV080Ww5ufYMv9go5twtmvBkdEKmXaJURvkciAJ1mDjmka3e0Z7NbmUxe565KFilsNupNNp8sOEB1/Yx04Cw8UyCufleMWHsEwQiTJJK+jbDf2qtUWbzA0WWhYlSqim9pbODue4z2hWtRb1p7JdniiINhW5SN1LIUTjCg7fX9/OMVE1l+0JgpKYtE3JiLnPoE7hKiEFsFuwyZwD/zBsj59du7nzyV/ICqSutIwGbraQYgcrXLzvz/yuahd9GsEPZS4SKxupfsZ6RBffWNmxzPd2o3rv+lTCBuJOe9GSmZFt1up8RGMPBIVBWcVcGp1nHUxzhwooXB2XktQxctDbMBqfl4e+IbN3IQeY6wmoq2oBuNLzqVEfz/eHH6LCloPQxABYlD2NOYGTIm6WUg0ailgfl+YD+VSL1i39wyebsY7hwv5E/9c8tV5yFV4k9UER89kV9eb5sewqGSmVd8eUpMF7rFwAhdrG1eTIFINIbdeHx3g9Jpjp88k89jU/afJEwOnUjMXcI1/9fGT+30ePbqSBikHxCpP94fONBTvKrJpTiKQuJTshcMOar0JDbAHYfJu010EXwf/auOHBl/2HxrcopMipM/KvyJzCBOY3oyuxFBwHYYL2RuogCLw530LyIMzvIO5zEysFkWItZJLZnJn+J8hMI+YQFNm1BwK848Le3pwpbxHnDBSon/0Ev0KW5o0B4bjCuy531lbbi58oesG0UPMQQUG35H2mRCOKyN1bJj3hTXOB+P31eLJcPijfVo62H4/vFp41EzE0A4UnYkSGBZspCPo5Jg5qSVIqzf/74Pklj2xoHqiARCtpC9SmUVLz5WrnXXFNoOK3jsPxboEXirEgyAtBUrlvRrlamzX5jqbgDS/PveduUQjJCtD0TnYgxr2rguAZqwSEBX7SbAMNL2lnvxn9z9qfGsFEFFvx5cH2haIFhZApgWGSN+KzZQiKfuJYN7Zfki/ulIaaV+UZQQoW8g4TGO9IblsnowfalJtJ1rgIuZkSCDXvIjMoZmlz4gpUXLq8T1ErWxtjgWQ0RYzanegEv+HL3bmLeGUt8DxngPwR2+kOch/4iRI63a46DsB8TJonce8/cZqeGbC5gYaoG+WN4JVCyDj5Bg/JUxmmyI+L9AaYCC9bv7I+FAcKmarPMZrBsug3JmcDBWDaIht6drGK7St9nlcLsAwV7J6wkTTzCPuomtsIIRAuUBi7L2M/bQF9FE4CHpwdqrgPx6gDcxGBBlm5k8JD9ZVt+gACEgDxxpj9nYk+x96C9B6MEPSTdC0twnYXBM4orjp/n+kQoxcMRYEdGrU+xT/rSDHwFqLied9NNrfIshj97/mSETOqgkECACXErCTI38MiM+nDzuUnIprrsLrjFDMxEhtlBn0qkIs2Hkx1iPPRs7nvZEyGBIGqcoAqUIA== X-OriginatorOrg: siemens.com X-MS-Exchange-CrossTenant-Network-Message-Id: f4278706-c464-4dc7-ba21-08dacb38dc84 X-MS-Exchange-CrossTenant-AuthSource: PAXPR10MB5037.EURPRD10.PROD.OUTLOOK.COM X-MS-Exchange-CrossTenant-AuthAs: Internal X-MS-Exchange-CrossTenant-OriginalArrivalTime: 20 Nov 2022 20:50:30.5733 (UTC) X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted X-MS-Exchange-CrossTenant-Id: 38ae3bcd-9579-4fd4-adda-b42e1495d55a X-MS-Exchange-CrossTenant-MailboxType: HOSTED X-MS-Exchange-CrossTenant-UserPrincipalName: SEoPKLIk5UJqFx6LLqWMlOkWuM2RGsRBX+oPXhlQrfcqtZRpHf1K94X8J0sHSer6OGqCYd4KNwwIJ8Weu/QKfbbbWWyu4dVF3SGal3fPQZU= X-MS-Exchange-Transport-CrossTenantHeadersStamped: DU0PR10MB7094 List-Id: X-Webhook-Received: from li982-79.members.linode.com [45.33.32.79] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 20 Nov 2022 20:50:42 -0000 X-Groupsio-URL: https://lists.cip-project.org/g/cip-dev/message/10061 From: Sven Schultschik The snakeoil keys are copied to the deploy folder if machine is qemu-arm64. The RPMB qemu workaround is not persistent and for that the keys need to be provisioned on every boot of quemu. Therefor the keys are copied to the deploy folder, mounted into the qemu as virtual memory and the boot command automatically loads them on every boot. Signed-off-by: Sven Schultschik --- recipes-bsp/u-boot/u-boot-qemu-common.inc | 4 ++++ .../secure-boot-secrets.inc | 22 +++++++++++++++++++ start-qemu.sh | 3 ++- 3 files changed, 28 insertions(+), 1 deletion(-) diff --git a/recipes-bsp/u-boot/u-boot-qemu-common.inc b/recipes-bsp/u-boot/u-boot-qemu-common.inc index 6e7158b..51dabac 100644 --- a/recipes-bsp/u-boot/u-boot-qemu-common.inc +++ b/recipes-bsp/u-boot/u-boot-qemu-common.inc @@ -18,6 +18,10 @@ SRC_URI_append_secureboot = " \ DEPENDS_append_secureboot = " optee-os-${MACHINE}" +do_prepare_build_append_secureboot() { + sed -i 's/CONFIG_BOOTCOMMAND="/CONFIG_BOOTCOMMAND="fatload virtio 1:1 40000000 PK\.auth; setenv -e -nv -bs -rt -at -i 40000000:\$filesize PK; fatload virtio 1:1 40000000 KEK\.auth; setenv -e -nv -bs -rt -at -i 40000000:\$filesize KEK; fatload virtio 1:1 40000000 db\.auth; setenv -e -nv -bs -rt -at -i 40000000:\$filesize db; /g' ${S}/configs/${U_BOOT_CONFIG} +} + do_deploy[dirs] = "${DEPLOY_DIR_IMAGE}" do_deploy() { dpkg --fsys-tarfile "${WORKDIR}/u-boot-${MACHINE}_${PV}_${DISTRO_ARCH}.deb" | \ diff --git a/recipes-devtools/secure-boot-secrets/secure-boot-secrets.inc b/recipes-devtools/secure-boot-secrets/secure-boot-secrets.inc index 2a30f1e..0fcde72 100644 --- a/recipes-devtools/secure-boot-secrets/secure-boot-secrets.inc +++ b/recipes-devtools/secure-boot-secrets/secure-boot-secrets.inc @@ -53,3 +53,25 @@ do_install() { do_prepare_build_append() { echo "Provides: secure-boot-secrets" >> ${S}/debian/control } + +do_deploy[dirs] = "${DEPLOY_DIR_IMAGE}" +do_deploy() { + if [ "${MACHINE}" = "qemu-arm64" ]; then + DTARGET=${DEPLOY_DIR_IMAGE}/keys + mkdir -p ${DTARGET} + cp ${WORKDIR}/${SB_PK}.auth ${DTARGET}/PK.auth + cp ${WORKDIR}/${SB_PK}.crt ${DTARGET}/PK.crt + cp ${WORKDIR}/${SB_PK}.esl ${DTARGET}/PK.esl + cp ${WORKDIR}/${SB_PK}.key ${DTARGET}/PK.key + cp ${WORKDIR}/${SB_KEK}.auth ${DTARGET}/KEK.auth + cp ${WORKDIR}/${SB_KEK}.crt ${DTARGET}/KEK.crt + cp ${WORKDIR}/${SB_KEK}.esl ${DTARGET}/KEK.esl + cp ${WORKDIR}/${SB_KEK}.key ${DTARGET}/KEK.key + cp ${WORKDIR}/${SB_DB}.auth ${DTARGET}/db.auth + cp ${WORKDIR}/${SB_DB}.crt ${DTARGET}/db.crt + cp ${WORKDIR}/${SB_DB}.esl ${DTARGET}/db.esl + cp ${WORKDIR}/${SB_DB}.key ${DTARGET}/db.key + fi +} + +addtask deploy after do_dpkg_build before do_deploy_deb \ No newline at end of file diff --git a/start-qemu.sh b/start-qemu.sh index 5617a2a..f29b57d 100755 --- a/start-qemu.sh +++ b/start-qemu.sh @@ -183,7 +183,8 @@ if [ -n "${SECURE_BOOT}${SWUPDATE_BOOT}" ]; then ${QEMU_PATH}${QEMU} \ -drive file=${IMAGE_PREFIX}.wic,discard=unmap,if=none,id=disk,format=raw \ -bios ${u_boot_bin} \ - ${QEMU_COMMON_OPTIONS} "$@" + ${QEMU_COMMON_OPTIONS} "$@" \ + -hdb fat:rw:./build/tmp/deploy/images/qemu-${QEMU_ARCH}/keys ;; *) echo "Unsupported architecture: ${arch}"