diff --git a/doc/boot-devices.rst b/doc/boot-devices.rst
new file mode 100644
index 0000000..1f08da1
--- /dev/null
+++ b/doc/boot-devices.rst
@@ -0,0 +1,69 @@
+Supported Boot Devices
+======================
+
+The OpenPower firmware uses Linux as a bootloader in order to discover boot
+devices, and boot the final operating system. In order to discover boot devices
+and load the operating system image from them, the bootloader's kernel needs to
+include support for that hardware.
+
+This table lists the network adaptors and disk controllers that are currently
+enabled.
+
+If you are adding a device to the kernel, please add the details here including
+your email address in the owner field. We will use this to contact users when
+considering the removal of modules.
+
+Likewise, if you are removing an option from the kernel config, please remove
+it from this table and notify the person mentioned in the owner field.
+
++-------------------------------+-----------------------+--------+----------------------------+
+| Device name                   | Kconfig option        | System | Owner                      |
++===============================+=======================+========+============================+
+| AOC-SG-I2 NIC                 | IGB                   | Boston | maurosr@linux.vnet.ibm.com |
++-------------------------------+-----------------------+--------+----------------------------+
+| Broadcom NetExtreme II        | BNX2X                 |        |                            |
++-------------------------------+-----------------------+--------+----------------------------+
+| Mellanox ConnectX-4           | MLX5_CORE_EN          |        |                            |
++-------------------------------+-----------------------+--------+----------------------------+
+| Alteon AceNIC                 | ACENIC                |        |                            |
++-------------------------------+-----------------------+--------+----------------------------+
+| Broadcom Tigon3               | TIGON3                |        |                            |
++-------------------------------+-----------------------+--------+----------------------------+
+| Chelsio 10Gb Ethernet         | CHELSIO_T1            |        |                            |
++-------------------------------+-----------------------+--------+----------------------------+
+| SeverEngine BladeEngine 10Gb  | BE2NET                |        |                            |
++-------------------------------+-----------------------+--------+----------------------------+
+| Exar Xframe 10Gb              | S2IO                  |        |                            |
++-------------------------------+-----------------------+--------+----------------------------+
+| Intel PRO/1000                | E1000                 | Qemu   | stewart@linux.vnet.ibm.com |
++-------------------------------+-----------------------+--------+----------------------------+
+| Intel PRO/10GbE               | IXGB                  |        |                            |
++-------------------------------+-----------------------+--------+----------------------------+
+| Intel 10GbE PCIe              | IXGBE                 |        |                            |
++-------------------------------+-----------------------+--------+----------------------------+
+| Intel XL710 Ethernet          | I40E                  | P9DSU  | jk@ozlabs.org              |
++-------------------------------+-----------------------+--------+----------------------------+
+| Mellanox 1/10/40Gbit Ethernet | MLX4_EN               |        |                            |
++-------------------------------+-----------------------+--------+----------------------------+
+| Myricom Myri-10G Ethernet     | MYRI10GE              |        |                            |
++-------------------------------+-----------------------+--------+----------------------------+
+| QLogic QLGE 10Gb Ethernet     | QLGE                  |        |                            |
++-------------------------------+-----------------------+--------+----------------------------+
+| NetXen Gigabit Ethernet       | NETXEN_NIC            |        |                            |
++-------------------------------+-----------------------+--------+----------------------------+
+| Adaptec AACRAID               | SCSI_AACRAID          |        |                            |
++-------------------------------+-----------------------+--------+----------------------------+
+| QLogic BNX2                   | SCSI_BNX2_ISCSI       |        |                            |
++-------------------------------+-----------------------+--------+----------------------------+
+| Chelsio T3 iSCSI              | SCSI_CXGB3_ISCSI      |        |                            |
++-------------------------------+-----------------------+--------+----------------------------+
+| Chelsio T4 iSCSI              | SCSI_CXGB4_ISCSI      |        |                            |
++-------------------------------+-----------------------+--------+----------------------------+
+| LSI Logic MegaRAID            | MEGARAID_NEWGEN       |        |                            |
++-------------------------------+-----------------------+--------+----------------------------+
+| LSI MPT Fusion SAS (legacy)   | SCSI_MPT2SAS          |        |                            |
++-------------------------------+-----------------------+--------+----------------------------+
+| QLogic QLA2xxx Fibrechannel   | SCSI_QLA_FC           |        |                            |
++-------------------------------+-----------------------+--------+----------------------------+
+| QLogic ISP4xxx and ISP82xxx   | SCSI_QLA_ISCSI        |        |                            |
++-------------------------------+-----------------------+--------+----------------------------+
diff --git a/doc/index.rst b/doc/index.rst
index 4bbc061..d4d9668 100644
--- a/doc/index.rst
+++ b/doc/index.rst
@@ -19,6 +19,7 @@
    introduction
    testing
    process/index
+   boot-devices
    versioning
    release-notes/index
 
diff --git a/openpower/configs/hostboot/vesnin.config b/openpower/configs/hostboot/vesnin.config
new file mode 100644
index 0000000..3aa5fba
--- /dev/null
+++ b/openpower/configs/hostboot/vesnin.config
@@ -0,0 +1,61 @@
+# The Serial Flash Controller is the AST2400 BMC.
+set   SFC_IS_AST2400
+set   BMC_DOES_SFC_INIT
+unset SFC_IS_IBM_DPSS
+set   ALLOW_MICRON_PNOR
+set   ALLOW_MACRONIX_PNOR
+
+# VPD options.
+set MVPD_READ_FROM_HW
+set MVPD_WRITE_TO_HW
+set MVPD_READ_FROM_PNOR
+set MVPD_WRITE_TO_PNOR
+set DJVPD_READ_FROM_HW
+set DJVPD_WRITE_TO_HW
+set DJVPD_READ_FROM_PNOR
+set DJVPD_WRITE_TO_PNOR
+set CVPD_READ_FROM_HW
+set CVPD_WRITE_TO_HW
+set CVPD_READ_FROM_PNOR
+set CVPD_WRITE_TO_PNOR
+set PVPD_READ_FROM_HW
+set PVPD_WRITE_TO_HW
+set PVPD_READ_FROM_PNOR
+set PVPD_WRITE_TO_PNOR
+set SKIP_RESTRICT_EX_UNITS
+unset CDIMM_FORMAT_FOR_CVPD
+
+# gpio config
+set GPIODD
+set PALMETTO_VDDR
+
+# Enable SBE updates
+set SBE_UPDATE_INDEPENDENT
+
+unset PCIE_HOTPLUG_CONTROLLER
+
+# turn on console output
+set CONSOLE
+set BMC_AST2400
+
+unset DISABLE_HOSTBOOT_RUNTIME
+
+# Compile in hostboot runtime PRD
+set HBRT_PRD
+set HTMGT
+set START_OCC_DURING_BOOT
+
+#PNOR flags
+set PNOR_TWO_SIDE_SUPPORT
+
+set BMC_BT_LPC_IPMI
+
+# Enable Checktop Analysis
+set ENABLE_CHECKSTOP_ANALYSIS
+set IPLTIME_CHECKSTOP_ANALYSIS
+
+# Hostboot will detect hardware changes
+set HOST_HCDB_SUPPORT
+
+# set for trace debug to console
+unset CONSOLE_OUTPUT_TRACE
diff --git a/openpower/configs/linux/skiroot_defconfig b/openpower/configs/linux/skiroot_defconfig
index 7af1ebe..fd3a786 100644
--- a/openpower/configs/linux/skiroot_defconfig
+++ b/openpower/configs/linux/skiroot_defconfig
@@ -128,9 +128,7 @@
 CONFIG_BE2NET=m
 CONFIG_S2IO=m
 # CONFIG_NET_VENDOR_HUAWEI is not set
-CONFIG_E100=m
 CONFIG_E1000=m
-CONFIG_E1000E=m
 CONFIG_IXGB=m
 CONFIG_IXGBE=m
 CONFIG_I40E=m
diff --git a/openpower/configs/linux/skiroot_p9_defconfig b/openpower/configs/linux/skiroot_p9_defconfig
index 309f182..1c12e98 100644
--- a/openpower/configs/linux/skiroot_p9_defconfig
+++ b/openpower/configs/linux/skiroot_p9_defconfig
@@ -130,9 +130,8 @@
 CONFIG_BE2NET=m
 CONFIG_S2IO=m
 # CONFIG_NET_VENDOR_HUAWEI is not set
-CONFIG_E100=m
 CONFIG_E1000=m
-CONFIG_E1000E=m
+CONFIG_IGB=m
 CONFIG_IXGB=m
 CONFIG_IXGBE=m
 CONFIG_I40E=m
diff --git a/openpower/configs/vesnin_defconfig b/openpower/configs/vesnin_defconfig
new file mode 100644
index 0000000..0425d18
--- /dev/null
+++ b/openpower/configs/vesnin_defconfig
@@ -0,0 +1,57 @@
+BR2_powerpc64le=y
+BR2_powerpc_power8=y
+BR2_BINUTILS_EXTRA_CONFIG_OPTIONS="--enable-targets=powerpc64-linux"
+BR2_EXTRA_GCC_CONFIG_OPTIONS="--enable-targets=powerpc64-linux --disable-libsanitizer"
+BR2_TOOLCHAIN_BUILDROOT_CXX=y
+BR2_TARGET_GENERIC_HOSTNAME="skiroot"
+BR2_ROOTFS_DEVICE_CREATION_DYNAMIC_EUDEV=y
+BR2_ROOTFS_DEVICE_TABLE="../openpower/device_table.txt"
+BR2_TARGET_GENERIC_GETTY_PORT="hvc0"
+BR2_GENERATE_LOCALE="en_US.UTF-8"
+BR2_ROOTFS_OVERLAY="../openpower/overlay"
+BR2_ROOTFS_POST_BUILD_SCRIPT="../openpower/scripts/fixup-target-var ../openpower/scripts/firmware-whitelist"
+BR2_LINUX_KERNEL=y
+BR2_LINUX_KERNEL_CUSTOM_VERSION=y
+BR2_LINUX_KERNEL_CUSTOM_VERSION_VALUE="4.15.6"
+BR2_LINUX_KERNEL_PATCH="$(BR2_EXTERNAL_OP_BUILD_PATH)/linux"
+BR2_LINUX_KERNEL_USE_CUSTOM_CONFIG=y
+BR2_LINUX_KERNEL_CUSTOM_CONFIG_FILE="$(BR2_EXTERNAL_OP_BUILD_PATH)/configs/linux/skiroot_defconfig"
+BR2_LINUX_KERNEL_ZIMAGE_EPAPR=y
+BR2_PACKAGE_BUSYBOX_CONFIG_FRAGMENT_FILES="$(BR2_EXTERNAL_OP_BUILD_PATH)/configs/busybox.fragment"
+BR2_PACKAGE_BUSYBOX_SHOW_OTHERS=y
+BR2_PACKAGE_I2C_TOOLS=y
+BR2_PACKAGE_IPMITOOL=y
+BR2_PACKAGE_MDADM=y
+BR2_PACKAGE_NCURSES_WCHAR=y
+BR2_PACKAGE_DROPBEAR=y
+# BR2_PACKAGE_DROPBEAR_SERVER is not set
+BR2_PACKAGE_ETHTOOL=y
+BR2_PACKAGE_NETCAT=y
+BR2_PACKAGE_RSYNC=y
+BR2_TARGET_ROOTFS_CPIO_XZ=y
+BR2_TARGET_ROOTFS_INITRAMFS=y
+BR2_OPENPOWER_PLATFORM=y
+BR2_OPENPOWER_POWER8=y
+BR2_HOSTBOOT_CONFIG_FILE="vesnin.config"
+BR2_OPENPOWER_MACHINE_XML_GITHUB_PROJECT_VALUE="vesnin-xml"
+BR2_OPENPOWER_MACHINE_XML_VERSION="38ff4b8db62d43e330fab404cd2b76bd35a4a062"
+BR2_OPENPOWER_MACHINE_XML_FILENAME="vesnin.xml"
+BR2_OPENPOWER_SYSTEM_XML_FILENAME="VESNIN_hb.system.xml"
+BR2_OPENPOWER_MRW_XML_FILENAME="VESNIN_hb.mrw.xml"
+BR2_OPENPOWER_BIOS_XML_FILENAME="VESNIN_bios.xml"
+BR2_OPENPOWER_PNOR_XML_LAYOUT_FILENAME="defaultPnorLayoutWithGoldenSide.xml"
+BR2_OPENPOWER_CONFIG_NAME="vesnin"
+BR2_OPENPOWER_PNOR_FILENAME="vesnin.pnor"
+BR2_OPENPOWER_PNOR_UPDATE_FILENAME="vesnin_update.pnor"
+BR2_HOSTBOOT_BINARY_SBE_FILENAME="venice_sbe.img.ecc"
+BR2_HOSTBOOT_BINARY_SBEC_FILENAME="centaur_sbec_pad.img.ecc"
+BR2_HOSTBOOT_BINARY_WINK_FILENAME="p8.ref_image.hdr.bin.ecc"
+BR2_IMA_CATALOG_FILENAME="ima_catalog.bin"
+BR2_OPENPOWER_TARGETING_BIN_FILENAME="VESNIN_HB.targeting.bin"
+BR2_OPENPOWER_TARGETING_ECC_FILENAME="VESNIN_HB.targeting.bin.ecc"
+BR2_PACKAGE_PETITBOOT=y
+BR2_PACKAGE_PETITBOOT_MTD=y
+BR2_OCC_BIN_FILENAME="occ.bin"
+BR2_CAPP_UCODE_BIN_FILENAME="cappucode.bin"
+BR2_PACKAGE_LOADKEYS=y
+BR2_IMA_CATALOG_DTS="POWER8"
diff --git a/openpower/package/hostboot/hostboot.mk b/openpower/package/hostboot/hostboot.mk
index 70fac21..de013f6 100644
--- a/openpower/package/hostboot/hostboot.mk
+++ b/openpower/package/hostboot/hostboot.mk
@@ -4,7 +4,7 @@
 #
 ################################################################################
 HOSTBOOT_VERSION_BRANCH_MASTER_P8 ?= d3025f5d7ddd0723946bb54fcb471d2bf1fd2da4
-HOSTBOOT_VERSION_BRANCH_MASTER ?= c82b626e6ea1d56c0d25cbd5954064e256135002
+HOSTBOOT_VERSION_BRANCH_MASTER ?= 5fc3b529c69246a6706577351bccd7898f1c227b
 
 HOSTBOOT_VERSION ?= $(if $(BR2_OPENPOWER_POWER9),$(HOSTBOOT_VERSION_BRANCH_MASTER),$(HOSTBOOT_VERSION_BRANCH_MASTER_P8))
 HOSTBOOT_SITE ?= $(call github,open-power,hostboot,$(HOSTBOOT_VERSION))
diff --git a/openpower/package/hostboot/p9Patches/hostboot-0001-Revert-Check-the-Section-Headers-in-Non-Secure-Mode.patch b/openpower/package/hostboot/p9Patches/hostboot-0001-Revert-Check-the-Section-Headers-in-Non-Secure-Mode.patch
new file mode 100644
index 0000000..9d33b53
--- /dev/null
+++ b/openpower/package/hostboot/p9Patches/hostboot-0001-Revert-Check-the-Section-Headers-in-Non-Secure-Mode.patch
@@ -0,0 +1,306 @@
+From 7a948065fdb903e280757eb92c70b5594298ce56 Mon Sep 17 00:00:00 2001
+From: Stewart Smith <stewart@linux.vnet.ibm.com>
+Date: Thu, 15 Mar 2018 18:45:54 +1100
+Subject: [PATCH] Revert "Check the Section Headers in Non-Secure Mode"
+
+This reverts commit c82b626e6ea1d56c0d25cbd5954064e256135002.
+
+It breaks flashing custom skiboot (PAYLOAD) as the code checking
+headers checks the name of the partition against the secureboot
+header magic number, and this obviously does not work at all.
+
+This ends up being the case as I *believe* that older pflash
+may clear FFS_VERS_SHA512 flag that causes hostboot to go down
+code paths it doesn't expect.
+
+As always, FFS structures are full of lies :)
+
+Change-Id: I6f3994cd1ceb67a17b53487a45b26a9e4c10270e
+Signed-off-by: Stewart Smith <stewart@linux.vnet.ibm.com>
+---
+ src/include/usr/pnor/pnor_reasoncodes.H |  4 +-
+ src/include/usr/pnor/pnorif.H           | 12 +-----
+ src/usr/pnor/pnor_common.C              | 19 +--------
+ src/usr/pnor/pnor_utils.C               | 24 ++++++++++-
+ src/usr/pnor/pnorrp.C                   | 73 ++++++---------------------------
+ src/usr/pnor/runtime/rt_pnor.C          |  7 ----
+ 6 files changed, 39 insertions(+), 100 deletions(-)
+
+diff --git a/src/include/usr/pnor/pnor_reasoncodes.H b/src/include/usr/pnor/pnor_reasoncodes.H
+index e0c156e746de..589337a3be47 100644
+--- a/src/include/usr/pnor/pnor_reasoncodes.H
++++ b/src/include/usr/pnor/pnor_reasoncodes.H
+@@ -5,7 +5,7 @@
+ /*                                                                        */
+ /* OpenPOWER HostBoot Project                                             */
+ /*                                                                        */
+-/* Contributors Listed Below - COPYRIGHT 2011,2018                        */
++/* Contributors Listed Below - COPYRIGHT 2011,2017                        */
+ /* [+] Google Inc.                                                        */
+ /* [+] International Business Machines Corp.                              */
+ /*                                                                        */
+@@ -96,7 +96,6 @@ namespace PNOR
+ 
+         // pnor_common.C
+         MOD_PNORCOMMON_PARSETOC         = 0xC0, /**< PNOR::parseTOC */
+-        MOD_PNORCOMMON_GETSECTIONINFO   = 0xC1, /**< PNOR::getSectionInfo */
+ 
+         // spnorrp.C
+         // Note: 0xD0 is available, so should be the next one used for spnorrp.
+@@ -188,7 +187,6 @@ namespace PNOR
+         RC_SECURE_SIZE_MISMATCH      = PNOR_COMP_ID | 0x3A,
+         RC_NOT_PAGE_ALIGNED          = PNOR_COMP_ID | 0x3B,
+         RC_SECURE_PRO_SIZE_MISMATCH  = PNOR_COMP_ID | 0x3C,
+-        RC_BAD_HEADER_FORMAT         = PNOR_COMP_ID | 0x3D,
+ 
+         //@fixme-RTC:131607-Temporary value to allow HWSV compile
+         //termination_rc
+diff --git a/src/include/usr/pnor/pnorif.H b/src/include/usr/pnor/pnorif.H
+index b4d1a668fe8b..cef8617fdcb1 100644
+--- a/src/include/usr/pnor/pnorif.H
++++ b/src/include/usr/pnor/pnorif.H
+@@ -5,7 +5,7 @@
+ /*                                                                        */
+ /* OpenPOWER HostBoot Project                                             */
+ /*                                                                        */
+-/* Contributors Listed Below - COPYRIGHT 2011,2018                        */
++/* Contributors Listed Below - COPYRIGHT 2011,2017                        */
+ /* [+] Google Inc.                                                        */
+ /* [+] International Business Machines Corp.                              */
+ /*                                                                        */
+@@ -225,16 +225,6 @@ const char * SectionIdToString( uint32_t i_secIdIndex );
+  */
+ bool cmpSecurebootMagicNumber(const uint8_t* i_vaddr);
+ 
+-/**
+- *  @brief Determines whether requested PNOR section has a recognized header
+- *  @param[in]  i_vaddr: vaddr of the beginning of the secureboot header.
+- *  @param[in]  o_magicNumber: the read value of the header's magic number.
+-                Used for error logging purposes. Always populated.
+- *  @return     bool: True if the header was recognized, false otherwise.
+- */
+-bool hasKnownHeader(const uint8_t* i_vaddr,
+-                          uint64_t& o_magicNumber);
+-
+ /**
+  * @brief  Determine if a PNOR section is empty by checking if first PAGE
+  *         is all 0xFF's or 0x00's depending on ECC or not.
+diff --git a/src/usr/pnor/pnor_common.C b/src/usr/pnor/pnor_common.C
+index ceb7709b8c54..d262ebe8238f 100644
+--- a/src/usr/pnor/pnor_common.C
++++ b/src/usr/pnor/pnor_common.C
+@@ -5,7 +5,7 @@
+ /*                                                                        */
+ /* OpenPOWER HostBoot Project                                             */
+ /*                                                                        */
+-/* Contributors Listed Below - COPYRIGHT 2014,2018                        */
++/* Contributors Listed Below - COPYRIGHT 2014,2017                        */
+ /* [+] Google Inc.                                                        */
+ /* [+] International Business Machines Corp.                              */
+ /*                                                                        */
+@@ -406,20 +406,3 @@ bool PNOR::isSectionEmpty(const PNOR::SectionId i_section)
+ 
+     return l_result;
+ }
+-
+-bool PNOR::hasKnownHeader(const uint8_t* i_vaddr,
+-                          uint64_t& o_magicNumber)
+-{
+-    // Left symbolic constant defined in the function so it's easier to strip
+-    // out later and nothing becomes dependent on it
+-    const char VERSION_MAGIC[] = "VERSION";
+-    const auto versionMagicSize = sizeof(VERSION_MAGIC);
+-
+-    bool secureHeader = PNOR::cmpSecurebootMagicNumber(i_vaddr);
+-    bool versionHeader = (memcmp(i_vaddr,VERSION_MAGIC,versionMagicSize) == 0);
+-
+-    memcpy(&o_magicNumber, i_vaddr, sizeof(o_magicNumber));
+-
+-    return (versionHeader || secureHeader);
+-}
+-
+diff --git a/src/usr/pnor/pnor_utils.C b/src/usr/pnor/pnor_utils.C
+index 4fcad21c635f..9e0753066a92 100644
+--- a/src/usr/pnor/pnor_utils.C
++++ b/src/usr/pnor/pnor_utils.C
+@@ -5,7 +5,7 @@
+ /*                                                                        */
+ /* OpenPOWER HostBoot Project                                             */
+ /*                                                                        */
+-/* Contributors Listed Below - COPYRIGHT 2011,2018                        */
++/* Contributors Listed Below - COPYRIGHT 2011,2017                        */
+ /* [+] International Business Machines Corp.                              */
+ /*                                                                        */
+ /*                                                                        */
+@@ -328,6 +328,28 @@ PNOR::parseEntries (ffs_hdr* i_ffs_hdr,
+ #else
+         io_TOC[secId].secure = false;
+ #endif
++
++        // If secureboot is compiled in, skip header if not a secure section
++        // Otherwise always skip header as the secure flag is always false and
++        // SpnorRp will not handle skipping the header if one is indicated in PNOR
++        if ( (io_TOC[secId].version & FFS_VERS_SHA512)
++              && !io_TOC[secId].secure)
++        {
++            //increment flash addr for sha header
++            if (io_TOC[secId].integrity == FFS_INTEG_ECC_PROTECT)
++            {
++                io_TOC[secId].flashAddr += PAGESIZE_PLUS_ECC ;
++            }
++            else
++            {
++                io_TOC[secId].flashAddr += PAGESIZE ;
++            }
++
++            // now that we've skipped the header
++            // adjust the size to reflect that
++            io_TOC[secId].size -= PAGESIZE;
++        }
++
+     } // For TOC Entries
+ 
+ #ifndef BOOTLOADER
+diff --git a/src/usr/pnor/pnorrp.C b/src/usr/pnor/pnorrp.C
+index 1262db0b889f..e33a1b0c377c 100644
+--- a/src/usr/pnor/pnorrp.C
++++ b/src/usr/pnor/pnorrp.C
+@@ -489,8 +489,6 @@ errlHndl_t PnorRP::getSectionInfo( PNOR::SectionId i_section,
+         {
+             TRACDCOMP( g_trac_pnor, "PnorRP::getSectionInfo: i_section=%d, id=%d", i_section, iv_TOC[i_section].id );
+ 
+-            uint64_t l_sectionVaddr = iv_TOC[id].virtAddr;
+-            uint64_t l_sectionSize = iv_TOC[id].size;
+             // copy my data into the external format
+             o_info.id = iv_TOC[id].id;
+             o_info.name = SectionIdToString(id);
+@@ -504,17 +502,16 @@ errlHndl_t PnorRP::getSectionInfo( PNOR::SectionId i_section,
+             // sections in SPnorRP's address space
+             if (o_info.secure)
+             {
+-                uint8_t* l_vaddrPtr =
+-                                reinterpret_cast<uint8_t*>(l_sectionVaddr);
++                uint8_t* l_vaddr = reinterpret_cast<uint8_t*>(iv_TOC[id].virtAddr);
+                 // By adding VMM_VADDR_SPNOR_DELTA twice we can translate a pnor
+-                // address into a secure pnor address, since pnor, temp, and
+-                // spnor spaces are equidistant.
++                // address into a secure pnor address, since pnor, temp, and spnor
++                // spaces are equidistant.
+                 // See comments in SPnorRP::verifySections() method in spnorrp.C
+                 // and the definition of VMM_VADDR_SPNOR_DELTA in vmmconst.h
+                 // for specifics.
+-                l_sectionVaddr = reinterpret_cast<uint64_t>(l_vaddrPtr)
+-                                                        + VMM_VADDR_SPNOR_DELTA
+-                                                        + VMM_VADDR_SPNOR_DELTA;
++                o_info.vaddr = reinterpret_cast<uint64_t>(l_vaddr)
++                                                           + VMM_VADDR_SPNOR_DELTA
++                                                           + VMM_VADDR_SPNOR_DELTA;
+ 
+                 // Get size of the secured payload for the secure section
+                 // Note: the payloadSize we get back is untrusted because
+@@ -524,7 +521,7 @@ errlHndl_t PnorRP::getSectionInfo( PNOR::SectionId i_section,
+                 // and has valid beginning bytes. For optional Secure PNOR sections.
+ 
+                 SECUREBOOT::ContainerHeader l_conHdr;
+-                l_errhdl = l_conHdr.setHeader(l_vaddrPtr);
++                l_errhdl = l_conHdr.setHeader(l_vaddr);
+                 if (l_errhdl)
+                 {
+                     TRACFCOMP(g_trac_pnor, ERR_MRK"PnorRP::getSectionInfo: setheader failed");
+@@ -560,69 +557,25 @@ errlHndl_t PnorRP::getSectionInfo( PNOR::SectionId i_section,
+                 }
+ 
+                 // skip secure header for secure sections at this point in time
+-                l_sectionVaddr += PAGESIZE;
++                o_info.vaddr += PAGESIZE;
+                 // now that we've skipped the header we also need to adjust the
+                 // size of the section to reflect that.
+                 // Note: For unsecured sections, the header skip and size decrement
+                 // was done previously in pnor_common.C
+-                l_sectionSize -= PAGESIZE;
++                o_info.size -= PAGESIZE;
+ 
+                 // cache the value in SectionInfo struct so that we can
+                 // parse the container header less often
+                 o_info.secureProtectedPayloadSize = payloadTextSize;
+             }
+-#else
+-            // If secureboot is not compiled, still check the sections that are
+-            // marked with sha512 tag in the xml to catch sections without fake
+-            // headers. If we expect a header to be present and it's not,
+-            // the virtual address of the section will not be pointing to the
+-            // correct offset into the section.
+-            if(iv_TOC[id].version & FFS_VERS_SHA512)
++            else
++#endif
+             {
+-                uint64_t l_magicNumber = 0;
+-                bool l_knownHeader = PNOR::hasKnownHeader(
+-                                reinterpret_cast<uint8_t*>(l_sectionVaddr),
+-                                l_magicNumber);
+-                if(!l_knownHeader)
+-                {
+-                    TRACFCOMP(g_trac_pnor, ERR_MRK"PnorRP::getSectionInfo: "
+-                        "The header of the partition %s"
+-                        " is not of a known header format. Magic number"
+-                        " = 0x%016llx",
+-                         PNOR::SectionIdToString(id),
+-                         l_magicNumber);
+-                    /*@
+-                    * @errortype       ERRORLOG::ERRL_SEV_UNRECOVERABLE
+-                    * @moduleid        PNOR::MOD_PNORCOMMON_GETSECTIONINFO
+-                    * @reasoncode      PNOR::RC_BAD_HEADER_FORMAT
+-                    * @userdata1       Partition ID
+-                    * @userdata2       Partition's magic number
+-                    * @devdesc         Error parsing partition header
+-                    * @custdesc        Boot firmware integrity error;
+-                    *                  reinstall the boot firmware
+-                    */
+-                    l_errhdl = new ERRORLOG::ErrlEntry(
+-                                        ERRORLOG::ERRL_SEV_UNRECOVERABLE,
+-                                        PNOR::MOD_PNORCOMMON_GETSECTIONINFO,
+-                                        PNOR::RC_BAD_HEADER_FORMAT,
+-                                        id,
+-                                        l_magicNumber,
+-                                        true/*SW Error*/);
+-                    l_errhdl->collectTrace(PNOR_COMP_NAME);
+-                    l_errhdl->collectTrace(SECURE_COMP_NAME);
+-                    break;
+-                }
+-                // Skip the fake header in memory after we've checked it.
+-                // The vaddr of the parition will now point to the start
+-                // of the actual partition.
+-                l_sectionSize -= PAGESIZE;
+-                l_sectionVaddr += PAGESIZE;
++                o_info.vaddr = iv_TOC[id].virtAddr;
+             }
+ 
+-#endif
+             o_info.flashAddr = iv_TOC[id].flashAddr;
+-            o_info.size = l_sectionSize;
+-            o_info.vaddr = l_sectionVaddr;
++            o_info.size = iv_TOC[id].size;
+             o_info.eccProtected = ((iv_TOC[id].integrity & FFS_INTEG_ECC_PROTECT)
+                                     != 0) ? true : false;
+             o_info.sha512Version = ((iv_TOC[id].version & FFS_VERS_SHA512)
+diff --git a/src/usr/pnor/runtime/rt_pnor.C b/src/usr/pnor/runtime/rt_pnor.C
+index 02b230456661..ba23cecb5ab4 100644
+--- a/src/usr/pnor/runtime/rt_pnor.C
++++ b/src/usr/pnor/runtime/rt_pnor.C
+@@ -263,13 +263,6 @@ errlHndl_t RtPnor::getSectionInfo(PNOR::SectionId i_section,
+         o_info.sha512perEC  =
+            (iv_TOC[i_section].version & FFS_VERS_SHA512_PER_EC) ? true : false;
+         o_info.secure = iv_TOC[i_section].secure;
+-#ifndef CONFIG_SECUREBOOT
+-        if(iv_TOC[i_section].version & FFS_VERS_SHA512)
+-        {
+-            o_info.size -= PAGESIZE;
+-            o_info.vaddr += PAGESIZE;
+-        }
+-#endif
+     } while (0);
+ 
+     TRACFCOMP(g_trac_pnor, EXIT_MRK"RtPnor::getSectionInfo %d", i_section);
+-- 
+2.14.3
+
diff --git a/openpower/package/ima-catalog/ima-catalog.mk b/openpower/package/ima-catalog/ima-catalog.mk
index 7e469bd..9ee205f 100644
--- a/openpower/package/ima-catalog/ima-catalog.mk
+++ b/openpower/package/ima-catalog/ima-catalog.mk
@@ -3,7 +3,7 @@
 # ima-catalog.mk
 #
 ################################################################################
-IMA_CATALOG_VERSION ?= 01b26a136da16a87c0b6b3c4d9f27555dca104dc 
+IMA_CATALOG_VERSION ?= 90237254664cadab529a397965083e38806d92e6 
 IMA_CATALOG_SITE ?= $(call github,open-power,ima-catalog,$(IMA_CATALOG_VERSION))
 IMA_CATALOG_LICENSE = Apache-2.0
 IMA_CATALOG_DEPENDENCIES = host-dtc host-xz
diff --git a/openpower/package/sbe/sbe.mk b/openpower/package/sbe/sbe.mk
index 537ab4c..fa50a0c 100644
--- a/openpower/package/sbe/sbe.mk
+++ b/openpower/package/sbe/sbe.mk
@@ -4,7 +4,7 @@
 #
 ################################################################################
 
-SBE_VERSION ?= 75ddac2a41a9f5cb32a7028b811e6852d5aead89
+SBE_VERSION ?= ab0fc4ba6ffbc830c9e48b8b6542a1bb12ebdbbd
 SBE_SITE ?= $(call github,open-power,sbe,$(SBE_VERSION))
 
 SBE_LICENSE = Apache-2.0
