diff --git a/openpower/configs/hostboot/p9dsu.config b/openpower/configs/hostboot/p9dsu.config
index 5b8ee8e..87b7c39 100644
--- a/openpower/configs/hostboot/p9dsu.config
+++ b/openpower/configs/hostboot/p9dsu.config
@@ -63,9 +63,6 @@
 set ENABLE_CHECKSTOP_ANALYSIS
 unset IPLTIME_CHECKSTOP_ANALYSIS
 
-# Hostboot will not detect hardware changes
-unset HOST_HCDB_SUPPORT
-
 # set for trace debug to console
 set CONSOLE_OUTPUT_TRACE
 set CONSOLE_OUTPUT_FFDCDISPLAY
diff --git a/openpower/configs/hostboot/romulus.config b/openpower/configs/hostboot/romulus.config
index ef027ea..486017d 100755
--- a/openpower/configs/hostboot/romulus.config
+++ b/openpower/configs/hostboot/romulus.config
@@ -60,9 +60,6 @@
 unset ENABLE_CHECKSTOP_ANALYSIS
 unset IPLTIME_CHECKSTOP_ANALYSIS
 
-# Hostboot will detect hardware changes
-unset HOST_HCDB_SUPPORT
-
 # set for trace debug to console
 set CONSOLE_OUTPUT_TRACE
 
diff --git a/openpower/configs/hostboot/witherspoon.config b/openpower/configs/hostboot/witherspoon.config
index 0bcf28c..106b303 100755
--- a/openpower/configs/hostboot/witherspoon.config
+++ b/openpower/configs/hostboot/witherspoon.config
@@ -64,9 +64,6 @@
 set ENABLE_CHECKSTOP_ANALYSIS
 set IPLTIME_CHECKSTOP_ANALYSIS
 
-# Hostboot will not detect hardware changes
-unset HOST_HCDB_SUPPORT
-
 # set for trace debug to console
 unset CONSOLE_OUTPUT_TRACE
 set CONSOLE_OUTPUT_FFDCDISPLAY
diff --git a/openpower/configs/hostboot/zaius.config b/openpower/configs/hostboot/zaius.config
index cbfa242..6e03400 100755
--- a/openpower/configs/hostboot/zaius.config
+++ b/openpower/configs/hostboot/zaius.config
@@ -63,9 +63,6 @@
 set ENABLE_CHECKSTOP_ANALYSIS
 set IPLTIME_CHECKSTOP_ANALYSIS
 
-# Hostboot will not detect hardware changes
-unset HOST_HCDB_SUPPORT
-
 # set for trace debug to console
 unset CONSOLE_OUTPUT_TRACE
 set CONSOLE_OUTPUT_FFDCDISPLAY
diff --git a/openpower/configs/linux/skiroot_p9_defconfig b/openpower/configs/linux/skiroot_p9_defconfig
index 1130b8e..20a0501 100644
--- a/openpower/configs/linux/skiroot_p9_defconfig
+++ b/openpower/configs/linux/skiroot_p9_defconfig
@@ -1,14 +1,12 @@
 CONFIG_PPC64=y
 CONFIG_ALTIVEC=y
 CONFIG_VSX=y
-CONFIG_SMP=y
 CONFIG_NR_CPUS=2048
 CONFIG_CPU_LITTLE_ENDIAN=y
 # CONFIG_SWAP is not set
 CONFIG_SYSVIPC=y
 CONFIG_POSIX_MQUEUE=y
 # CONFIG_CROSS_MEMORY_ATTACH is not set
-CONFIG_IRQ_DOMAIN_DEBUG=y
 CONFIG_NO_HZ=y
 CONFIG_HIGH_RES_TIMERS=y
 CONFIG_TASKSTATS=y
@@ -29,6 +27,7 @@
 CONFIG_PERF_EVENTS=y
 # CONFIG_COMPAT_BRK is not set
 CONFIG_JUMP_LABEL=y
+CONFIG_STRICT_KERNEL_RWX=y
 CONFIG_MODULES=y
 CONFIG_MODULE_UNLOAD=y
 CONFIG_MODULE_SIG=y
@@ -131,6 +130,8 @@
 CONFIG_E1000E=m
 CONFIG_IXGB=m
 CONFIG_IXGBE=m
+CONFIG_I40E=m
+CONFIG_IGB=m
 CONFIG_MLX4_EN=m
 CONFIG_MLX5_CORE=m
 CONFIG_MLX5_CORE_EN=y
@@ -168,6 +169,8 @@
 # CONFIG_BACKLIGHT_GENERIC is not set
 # CONFIG_VGA_CONSOLE is not set
 CONFIG_LOGO=y
+# CONFIG_LOGO_LINUX_MONO is not set
+# CONFIG_LOGO_LINUX_VGA16 is not set
 CONFIG_USB_HIDDEV=y
 CONFIG_USB=y
 CONFIG_USB_MON=y
@@ -209,7 +212,11 @@
 CONFIG_MAGIC_SYSRQ=y
 CONFIG_DEBUG_KERNEL=y
 CONFIG_DEBUG_STACKOVERFLOW=y
-CONFIG_LOCKUP_DETECTOR=y
+CONFIG_SOFTLOCKUP_DETECTOR=y
+CONFIG_HARDLOCKUP_DETECTOR=y
+CONFIG_BOOTPARAM_HARDLOCKUP_PANIC=y
+CONFIG_BOOTPARAM_SOFTLOCKUP_PANIC=y
+CONFIG_WQ_WATCHDOG=y
 CONFIG_SCHEDSTATS=y
 # CONFIG_FTRACE is not set
 CONFIG_XMON=y
diff --git a/openpower/configs/witherspoon-sequoia_defconfig b/openpower/configs/witherspoon-sequoia_defconfig
deleted file mode 100644
index b79fb02..0000000
--- a/openpower/configs/witherspoon-sequoia_defconfig
+++ /dev/null
@@ -1,63 +0,0 @@
-BR2_powerpc64le=y
-BR2_powerpc_power8=y
-BR2_GLOBAL_PATCH_DIR="$(BR2_EXTERNAL_OP_BUILD_PATH)/patches/witherspoon-patches"
-BR2_BINUTILS_EXTRA_CONFIG_OPTIONS="--enable-targets=powerpc64-linux"
-BR2_EXTRA_GCC_CONFIG_OPTIONS="--enable-targets=powerpc64-linux"
-BR2_TOOLCHAIN_BUILDROOT_CXX=y
-BR2_TARGET_GENERIC_HOSTNAME="skiroot"
-BR2_ROOTFS_DEVICE_CREATION_DYNAMIC_EUDEV=y
-BR2_ROOTFS_DEVICE_TABLE="../openpower/device_table.txt"
-BR2_TARGET_GENERIC_GETTY_PORT="hvc0"
-BR2_ENABLE_LOCALE_WHITELIST="C de en es fr it ja ko pt_BR ru zh_CN zh_TW"
-BR2_GENERATE_LOCALE="en_US.UTF-8 de_DE.UTF-8 es_ES.UTF-8 fr_FR.UTF-8 it_IT.UTF-8 ja_JP.UTF-8 ko_KR.UTF-8 pt_BR.UTF-8 ru_RU.UTF-8 zh_CN.UTF-8 zh_TW.UTF-8"
-BR2_SYSTEM_ENABLE_NLS=y
-BR2_ROOTFS_OVERLAY="../openpower/overlay"
-BR2_ROOTFS_POST_BUILD_SCRIPT="../openpower/scripts/fixup-target-var ../openpower/scripts/firmware-whitelist"
-BR2_LINUX_KERNEL=y
-BR2_LINUX_KERNEL_CUSTOM_VERSION=y
-BR2_LINUX_KERNEL_CUSTOM_VERSION_VALUE="4.13.4"
-BR2_LINUX_KERNEL_PATCH="$(BR2_EXTERNAL_OP_BUILD_PATH)/linux"
-BR2_LINUX_KERNEL_USE_CUSTOM_CONFIG=y
-BR2_LINUX_KERNEL_CUSTOM_CONFIG_FILE="$(BR2_EXTERNAL_OP_BUILD_PATH)/configs/linux/skiroot_p9_defconfig"
-BR2_LINUX_KERNEL_ZIMAGE_EPAPR=y
-BR2_LINUX_KERNEL_XZ=y
-BR2_PACKAGE_BUSYBOX_CONFIG_FRAGMENT_FILES="$(BR2_EXTERNAL_OP_BUILD_PATH)/configs/busybox.fragment"
-BR2_PACKAGE_BUSYBOX_SHOW_OTHERS=y
-BR2_PACKAGE_LINUX_FIRMWARE=y
-BR2_PACKAGE_LINUX_FIRMWARE_BNX2X=y
-BR2_PACKAGE_LINUX_FIRMWARE_CXGB4_T4=y
-BR2_PACKAGE_IPMITOOL=y
-BR2_PACKAGE_IPMITOOL_USB=y
-BR2_PACKAGE_MDADM=y
-BR2_PACKAGE_NCURSES_WCHAR=y
-BR2_PACKAGE_DROPBEAR=y
-# BR2_PACKAGE_DROPBEAR_SERVER is not set
-BR2_PACKAGE_ETHTOOL=y
-BR2_PACKAGE_NETCAT=y
-BR2_PACKAGE_RSYNC=y
-BR2_TARGET_ROOTFS_CPIO_XZ=y
-BR2_TARGET_ROOTFS_INITRAMFS=y
-BR2_OPENPOWER_PLATFORM=y
-BR2_OPENPOWER_POWER9=y
-BR2_HOSTBOOT_CONFIG_FILE="witherspoon.config"
-BR2_OPENPOWER_MACHINE_XML_GITHUB_PROJECT_VALUE="witherspoon-xml"
-BR2_OPENPOWER_MACHINE_XML_VERSION="f8aaa73b75564d6b845147afd3b2ab7c433838bc"
-BR2_OPENPOWER_MACHINE_XML_FILENAME="witherspoon.xml"
-BR2_OPENPOWER_SYSTEM_XML_FILENAME="WITHERSPOON_hb.system.xml"
-BR2_OPENPOWER_MRW_XML_FILENAME="WITHERSPOON_hb.mrw.xml"
-BR2_OPENPOWER_BIOS_XML_FILENAME="WITHERSPOON_bios.xml"
-BR2_OPENPOWER_PNOR_XML_LAYOUT_FILENAME="defaultPnorLayout_64.xml"
-BR2_OPENPOWER_CONFIG_NAME="witherspoon"
-BR2_OPENPOWER_PNOR_FILENAME="witherspoon-sequoia.pnor"
-BR2_HOSTBOOT_BINARY_SBE_FILENAME="nimbus_sbe.img.ecc"
-BR2_HOSTBOOT_BINARY_SBEC_FILENAME="centaur_sbec_pad.img.ecc"
-BR2_HOSTBOOT_BINARY_WINK_FILENAME="p9n.ref_image.hdr.bin.ecc"
-BR2_IMA_CATALOG_FILENAME="ima_catalog.bin"
-BR2_OPENPOWER_TARGETING_BIN_FILENAME="WITHERSPOON_HB.targeting.bin"
-BR2_OPENPOWER_TARGETING_ECC_FILENAME="WITHERSPOON_HB.targeting.bin.ecc"
-BR2_PACKAGE_PETITBOOT=y
-BR2_PACKAGE_PETITBOOT_MTD=y
-BR2_OCC_BIN_FILENAME="occ.bin"
-BR2_CAPP_UCODE_BIN_FILENAME="cappucode.bin"
-BR2_PACKAGE_LOADKEYS=y
-BR2_IMA_CATALOG_DTS="POWER9"
diff --git a/openpower/configs/witherspoon_defconfig b/openpower/configs/witherspoon_defconfig
index f98a884..7fe0481 100644
--- a/openpower/configs/witherspoon_defconfig
+++ b/openpower/configs/witherspoon_defconfig
@@ -40,7 +40,7 @@
 BR2_OPENPOWER_POWER9=y
 BR2_HOSTBOOT_CONFIG_FILE="witherspoon.config"
 BR2_OPENPOWER_MACHINE_XML_GITHUB_PROJECT_VALUE="witherspoon-xml"
-BR2_OPENPOWER_MACHINE_XML_VERSION="7bec10c197071f8fa78b108275675693bfe13403"
+BR2_OPENPOWER_MACHINE_XML_VERSION="24d2f6d98568f0b23d1eb3bb9f876a638be4ae37"
 BR2_OPENPOWER_MACHINE_XML_FILENAME="witherspoon.xml"
 BR2_OPENPOWER_SYSTEM_XML_FILENAME="WITHERSPOON_hb.system.xml"
 BR2_OPENPOWER_MRW_XML_FILENAME="WITHERSPOON_hb.mrw.xml"
@@ -57,6 +57,8 @@
 BR2_PACKAGE_PETITBOOT=y
 BR2_PACKAGE_PETITBOOT_MTD=y
 BR2_OCC_BIN_FILENAME="occ.bin"
+BR2_OCC_GPU_BIN_FILENAME="gpu_gpe1.bin"
+BR2_OCC_GPU_BIN_BUILD=y
 BR2_CAPP_UCODE_BIN_FILENAME="cappucode.bin"
 BR2_PACKAGE_LOADKEYS=y
 BR2_IMA_CATALOG_DTS="POWER9"
diff --git a/openpower/configs/zaius_defconfig b/openpower/configs/zaius_defconfig
index 3c01088..d788da0 100644
--- a/openpower/configs/zaius_defconfig
+++ b/openpower/configs/zaius_defconfig
@@ -40,7 +40,7 @@
 BR2_OPENPOWER_POWER9=y
 BR2_HOSTBOOT_CONFIG_FILE="zaius.config"
 BR2_OPENPOWER_MACHINE_XML_GITHUB_PROJECT_VALUE="zaius-xml"
-BR2_OPENPOWER_MACHINE_XML_VERSION="9325c75307807915197f4704ab7e6d8994e2c837"
+BR2_OPENPOWER_MACHINE_XML_VERSION="7b63cfae75ef13789db5c71557c24c69d854413f"
 BR2_OPENPOWER_MACHINE_XML_FILENAME="zaius.xml"
 BR2_OPENPOWER_SYSTEM_XML_FILENAME="ZAIUS_hb.system.xml"
 BR2_OPENPOWER_MRW_XML_FILENAME="ZAIUS_hb.mrw.xml"
diff --git a/openpower/linux/0001-xhci-Use-xhci_pci_remove-for-xhci-device-shutdown.patch b/openpower/linux/0001-xhci-Use-xhci_pci_remove-for-xhci-device-shutdown.patch
index 0ff68d8..e2b40d5 100644
--- a/openpower/linux/0001-xhci-Use-xhci_pci_remove-for-xhci-device-shutdown.patch
+++ b/openpower/linux/0001-xhci-Use-xhci_pci_remove-for-xhci-device-shutdown.patch
@@ -1,7 +1,7 @@
 From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001
 From: Thadeu Lima De Souza Cascardo <thadeul@br.ibm.com>
 Date: Tue, 25 Mar 2014 10:45:16 -0400
-Subject: [PATCH 1/2] xhci: Use xhci_pci_remove for xhci device shutdown
+Subject: [PATCH 1/4] xhci: Use xhci_pci_remove for xhci device shutdown
 
 Signed-off-by: Jeremy Kerr <jk@ozlabs.org>
 Signed-off-by: Joel Stanley <joel@jms.id.au>
diff --git a/openpower/linux/0002-powerpc-mce-Move-64-bit-machine-check-code-into-mce..patch b/openpower/linux/0002-powerpc-mce-Move-64-bit-machine-check-code-into-mce..patch
new file mode 100644
index 0000000..6a5783f
--- /dev/null
+++ b/openpower/linux/0002-powerpc-mce-Move-64-bit-machine-check-code-into-mce..patch
@@ -0,0 +1,114 @@
+From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001
+From: Michael Ellerman <mpe@ellerman.id.au>
+Date: Wed, 4 Oct 2017 13:42:51 +1100
+Subject: [PATCH 2/4] powerpc/mce: Move 64-bit machine check code into mce.c
+
+We already have mce.c which is built for 64bit and contains other parts
+of the machine check code, so move these bits in there too.
+
+Signed-off-by: Michael Ellerman <mpe@ellerman.id.au>
+(cherry picked from commit ccd3cd361341b71ae2afa596f6b470fcb32a916e)
+Signed-off-by: Samuel Mendoza-Jonas <sam@mendozajonas.com>
+Signed-off-by: Joel Stanley <joel@jms.id.au>
+---
+ arch/powerpc/kernel/mce.c   | 33 +++++++++++++++++++++++++++++++++
+ arch/powerpc/kernel/traps.c | 33 ---------------------------------
+ 2 files changed, 33 insertions(+), 33 deletions(-)
+
+diff --git a/arch/powerpc/kernel/mce.c b/arch/powerpc/kernel/mce.c
+index e0e131e662ed..9b2ea7e71c06 100644
+--- a/arch/powerpc/kernel/mce.c
++++ b/arch/powerpc/kernel/mce.c
+@@ -22,11 +22,14 @@
+ #undef DEBUG
+ #define pr_fmt(fmt) "mce: " fmt
+ 
++#include <linux/hardirq.h>
+ #include <linux/types.h>
+ #include <linux/ptrace.h>
+ #include <linux/percpu.h>
+ #include <linux/export.h>
+ #include <linux/irq_work.h>
++
++#include <asm/machdep.h>
+ #include <asm/mce.h>
+ 
+ static DEFINE_PER_CPU(int, mce_nest_count);
+@@ -446,3 +449,33 @@ uint64_t get_mce_fault_addr(struct machine_check_event *evt)
+ 	return 0;
+ }
+ EXPORT_SYMBOL(get_mce_fault_addr);
++
++/*
++ * This function is called in real mode. Strictly no printk's please.
++ *
++ * regs->nip and regs->msr contains srr0 and ssr1.
++ */
++long machine_check_early(struct pt_regs *regs)
++{
++	long handled = 0;
++
++	__this_cpu_inc(irq_stat.mce_exceptions);
++
++	if (cur_cpu_spec && cur_cpu_spec->machine_check_early)
++		handled = cur_cpu_spec->machine_check_early(regs);
++	return handled;
++}
++
++long hmi_exception_realmode(struct pt_regs *regs)
++{
++	__this_cpu_inc(irq_stat.hmi_exceptions);
++
++	wait_for_subcore_guest_exit();
++
++	if (ppc_md.hmi_exception_early)
++		ppc_md.hmi_exception_early(regs);
++
++	wait_for_tb_resync();
++
++	return 0;
++}
+diff --git a/arch/powerpc/kernel/traps.c b/arch/powerpc/kernel/traps.c
+index bfcfd9ef09f2..559664e75fb5 100644
+--- a/arch/powerpc/kernel/traps.c
++++ b/arch/powerpc/kernel/traps.c
+@@ -312,39 +312,6 @@ void system_reset_exception(struct pt_regs *regs)
+ 	/* What should we do here? We could issue a shutdown or hard reset. */
+ }
+ 
+-#ifdef CONFIG_PPC64
+-/*
+- * This function is called in real mode. Strictly no printk's please.
+- *
+- * regs->nip and regs->msr contains srr0 and ssr1.
+- */
+-long machine_check_early(struct pt_regs *regs)
+-{
+-	long handled = 0;
+-
+-	__this_cpu_inc(irq_stat.mce_exceptions);
+-
+-	if (cur_cpu_spec && cur_cpu_spec->machine_check_early)
+-		handled = cur_cpu_spec->machine_check_early(regs);
+-	return handled;
+-}
+-
+-long hmi_exception_realmode(struct pt_regs *regs)
+-{
+-	__this_cpu_inc(irq_stat.hmi_exceptions);
+-
+-	wait_for_subcore_guest_exit();
+-
+-	if (ppc_md.hmi_exception_early)
+-		ppc_md.hmi_exception_early(regs);
+-
+-	wait_for_tb_resync();
+-
+-	return 0;
+-}
+-
+-#endif
+-
+ /*
+  * I/O accesses can cause machine checks on powermacs.
+  * Check if the NIP corresponds to the address of a sync
diff --git a/openpower/linux/0003-powerpc-64s-Add-workaround-for-P9-vector-CI-load-iss.patch b/openpower/linux/0003-powerpc-64s-Add-workaround-for-P9-vector-CI-load-iss.patch
new file mode 100644
index 0000000..444337c
--- /dev/null
+++ b/openpower/linux/0003-powerpc-64s-Add-workaround-for-P9-vector-CI-load-iss.patch
@@ -0,0 +1,439 @@
+From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001
+From: Michael Neuling <mikey@neuling.org>
+Date: Wed, 4 Oct 2017 13:42:52 +1100
+Subject: [PATCH 3/4] powerpc/64s: Add workaround for P9 vector CI load issue
+
+POWER9 DD2.1 and earlier has an issue where some cache inhibited
+vector load will return bad data. The workaround is two part, one
+firmware/microcode part triggers HMI interrupts when hitting such
+loads, the other part is this patch which then emulates the
+instructions in Linux.
+
+The affected instructions are limited to lxvd2x, lxvw4x, lxvb16x and
+lxvh8x.
+
+When an instruction triggers the HMI, all threads in the core will be
+sent to the HMI handler, not just the one running the vector load.
+
+In general, these spurious HMIs are detected by the emulation code and
+we just return back to the running process. Unfortunately, if a
+spurious interrupt occurs on a vector load that's to normal memory we
+have no way to detect that it's spurious (unless we walk the page
+tables, which is very expensive). In this case we emulate the load but
+we need do so using a vector load itself to ensure 128bit atomicity is
+preserved.
+
+Some additional debugfs emulated instruction counters are added also.
+
+Signed-off-by: Michael Neuling <mikey@neuling.org>
+Signed-off-by: Benjamin Herrenschmidt <benh@kernel.crashing.org>
+[mpe: Switch CONFIG_PPC_BOOK3S_64 to CONFIG_VSX to unbreak the build]
+Signed-off-by: Michael Ellerman <mpe@ellerman.id.au>
+(cherry picked from commit 5080332c2c893118dbc18755f35c8b0131cf0fc4)
+Signed-off-by: Samuel Mendoza-Jonas <sam@mendozajonas.com>
+Signed-off-by: Joel Stanley <joel@jms.id.au>
+---
+ arch/powerpc/include/asm/emulated_ops.h |   4 +
+ arch/powerpc/include/asm/paca.h         |   1 +
+ arch/powerpc/include/asm/uaccess.h      |  17 +++
+ arch/powerpc/kernel/exceptions-64s.S    |  16 ++-
+ arch/powerpc/kernel/mce.c               |  30 ++++-
+ arch/powerpc/kernel/traps.c             | 201 ++++++++++++++++++++++++++++++++
+ arch/powerpc/platforms/powernv/smp.c    |   7 ++
+ 7 files changed, 271 insertions(+), 5 deletions(-)
+
+diff --git a/arch/powerpc/include/asm/emulated_ops.h b/arch/powerpc/include/asm/emulated_ops.h
+index f00e10e2a335..651e1354498e 100644
+--- a/arch/powerpc/include/asm/emulated_ops.h
++++ b/arch/powerpc/include/asm/emulated_ops.h
+@@ -55,6 +55,10 @@ extern struct ppc_emulated {
+ 	struct ppc_emulated_entry mfdscr;
+ 	struct ppc_emulated_entry mtdscr;
+ 	struct ppc_emulated_entry lq_stq;
++	struct ppc_emulated_entry lxvw4x;
++	struct ppc_emulated_entry lxvh8x;
++	struct ppc_emulated_entry lxvd2x;
++	struct ppc_emulated_entry lxvb16x;
+ #endif
+ } ppc_emulated;
+ 
+diff --git a/arch/powerpc/include/asm/paca.h b/arch/powerpc/include/asm/paca.h
+index dc88a31cc79a..21061773149b 100644
+--- a/arch/powerpc/include/asm/paca.h
++++ b/arch/powerpc/include/asm/paca.h
+@@ -203,6 +203,7 @@ struct paca_struct {
+ 	 */
+ 	u16 in_mce;
+ 	u8 hmi_event_available;		/* HMI event is available */
++	u8 hmi_p9_special_emu;		/* HMI P9 special emulation */
+ #endif
+ 
+ 	/* Stuff for accurate time accounting */
+diff --git a/arch/powerpc/include/asm/uaccess.h b/arch/powerpc/include/asm/uaccess.h
+index 9c0e60ca1666..e34f15e727d9 100644
+--- a/arch/powerpc/include/asm/uaccess.h
++++ b/arch/powerpc/include/asm/uaccess.h
+@@ -173,6 +173,23 @@ do {								\
+ 
+ extern long __get_user_bad(void);
+ 
++/*
++ * This does an atomic 128 byte aligned load from userspace.
++ * Upto caller to do enable_kernel_vmx() before calling!
++ */
++#define __get_user_atomic_128_aligned(kaddr, uaddr, err)		\
++	__asm__ __volatile__(				\
++		"1:	lvx  0,0,%1	# get user\n"	\
++		" 	stvx 0,0,%2	# put kernel\n"	\
++		"2:\n"					\
++		".section .fixup,\"ax\"\n"		\
++		"3:	li %0,%3\n"			\
++		"	b 2b\n"				\
++		".previous\n"				\
++		EX_TABLE(1b, 3b)			\
++		: "=r" (err)			\
++		: "b" (uaddr), "b" (kaddr), "i" (-EFAULT), "0" (err))
++
+ #define __get_user_asm(x, addr, err, op)		\
+ 	__asm__ __volatile__(				\
+ 		"1:	"op" %1,0(%2)	# get_user\n"	\
+diff --git a/arch/powerpc/kernel/exceptions-64s.S b/arch/powerpc/kernel/exceptions-64s.S
+index f14f3c04ec7e..1a976aa1a7e9 100644
+--- a/arch/powerpc/kernel/exceptions-64s.S
++++ b/arch/powerpc/kernel/exceptions-64s.S
+@@ -1010,6 +1010,8 @@ TRAMP_REAL_BEGIN(hmi_exception_early)
+ 	EXCEPTION_PROLOG_COMMON_3(0xe60)
+ 	addi	r3,r1,STACK_FRAME_OVERHEAD
+ 	BRANCH_LINK_TO_FAR(hmi_exception_realmode) /* Function call ABI */
++	cmpdi	cr0,r3,0
++
+ 	/* Windup the stack. */
+ 	/* Move original HSRR0 and HSRR1 into the respective regs */
+ 	ld	r9,_MSR(r1)
+@@ -1026,10 +1028,15 @@ TRAMP_REAL_BEGIN(hmi_exception_early)
+ 	REST_8GPRS(2, r1)
+ 	REST_GPR(10, r1)
+ 	ld	r11,_CCR(r1)
++	REST_2GPRS(12, r1)
++	bne	1f
+ 	mtcr	r11
+ 	REST_GPR(11, r1)
+-	REST_2GPRS(12, r1)
+-	/* restore original r1. */
++	ld	r1,GPR1(r1)
++	hrfid
++
++1:	mtcr	r11
++	REST_GPR(11, r1)
+ 	ld	r1,GPR1(r1)
+ 
+ 	/*
+@@ -1042,8 +1049,9 @@ hmi_exception_after_realmode:
+ 	EXCEPTION_PROLOG_0(PACA_EXGEN)
+ 	b	tramp_real_hmi_exception
+ 
+-EXC_COMMON_ASYNC(hmi_exception_common, 0xe60, handle_hmi_exception)
+-
++EXC_COMMON_BEGIN(hmi_exception_common)
++EXCEPTION_COMMON(PACA_EXGEN, 0xe60, hmi_exception_common, handle_hmi_exception,
++        ret_from_except, FINISH_NAP;ADD_NVGPRS;ADD_RECONCILE;RUNLATCH_ON)
+ 
+ EXC_REAL_OOL_MASKABLE_HV(h_doorbell, 0xe80, 0x20)
+ EXC_VIRT_OOL_MASKABLE_HV(h_doorbell, 0x4e80, 0x20, 0xe80)
+diff --git a/arch/powerpc/kernel/mce.c b/arch/powerpc/kernel/mce.c
+index 9b2ea7e71c06..f588951b171d 100644
+--- a/arch/powerpc/kernel/mce.c
++++ b/arch/powerpc/kernel/mce.c
+@@ -470,6 +470,34 @@ long hmi_exception_realmode(struct pt_regs *regs)
+ {
+ 	__this_cpu_inc(irq_stat.hmi_exceptions);
+ 
++#ifdef CONFIG_PPC_BOOK3S_64
++	/* Workaround for P9 vector CI loads (see p9_hmi_special_emu) */
++	if (pvr_version_is(PVR_POWER9)) {
++		unsigned long hmer = mfspr(SPRN_HMER);
++
++		/* Do we have the debug bit set */
++		if (hmer & PPC_BIT(17)) {
++			hmer &= ~PPC_BIT(17);
++			mtspr(SPRN_HMER, hmer);
++
++			/*
++			 * Now to avoid problems with soft-disable we
++			 * only do the emulation if we are coming from
++			 * user space
++			 */
++			if (user_mode(regs))
++				local_paca->hmi_p9_special_emu = 1;
++
++			/*
++			 * Don't bother going to OPAL if that's the
++			 * only relevant bit.
++			 */
++			if (!(hmer & mfspr(SPRN_HMEER)))
++				return local_paca->hmi_p9_special_emu;
++		}
++	}
++#endif /* CONFIG_PPC_BOOK3S_64 */
++
+ 	wait_for_subcore_guest_exit();
+ 
+ 	if (ppc_md.hmi_exception_early)
+@@ -477,5 +505,5 @@ long hmi_exception_realmode(struct pt_regs *regs)
+ 
+ 	wait_for_tb_resync();
+ 
+-	return 0;
++	return 1;
+ }
+diff --git a/arch/powerpc/kernel/traps.c b/arch/powerpc/kernel/traps.c
+index 559664e75fb5..5fbe81d4e648 100644
+--- a/arch/powerpc/kernel/traps.c
++++ b/arch/powerpc/kernel/traps.c
+@@ -37,6 +37,7 @@
+ #include <linux/kdebug.h>
+ #include <linux/ratelimit.h>
+ #include <linux/context_tracking.h>
++#include <linux/smp.h>
+ 
+ #include <asm/emulated_ops.h>
+ #include <asm/pgtable.h>
+@@ -761,6 +762,187 @@ void SMIException(struct pt_regs *regs)
+ 	die("System Management Interrupt", regs, SIGABRT);
+ }
+ 
++#ifdef CONFIG_VSX
++static void p9_hmi_special_emu(struct pt_regs *regs)
++{
++	unsigned int ra, rb, t, i, sel, instr, rc;
++	const void __user *addr;
++	u8 vbuf[16], *vdst;
++	unsigned long ea, msr, msr_mask;
++	bool swap;
++
++	if (__get_user_inatomic(instr, (unsigned int __user *)regs->nip))
++		return;
++
++	/*
++	 * lxvb16x	opcode: 0x7c0006d8
++	 * lxvd2x	opcode: 0x7c000698
++	 * lxvh8x	opcode: 0x7c000658
++	 * lxvw4x	opcode: 0x7c000618
++	 */
++	if ((instr & 0xfc00073e) != 0x7c000618) {
++		pr_devel("HMI vec emu: not vector CI %i:%s[%d] nip=%016lx"
++			 " instr=%08x\n",
++			 smp_processor_id(), current->comm, current->pid,
++			 regs->nip, instr);
++		return;
++	}
++
++	/* Grab vector registers into the task struct */
++	msr = regs->msr; /* Grab msr before we flush the bits */
++	flush_vsx_to_thread(current);
++	enable_kernel_altivec();
++
++	/*
++	 * Is userspace running with a different endian (this is rare but
++	 * not impossible)
++	 */
++	swap = (msr & MSR_LE) != (MSR_KERNEL & MSR_LE);
++
++	/* Decode the instruction */
++	ra = (instr >> 16) & 0x1f;
++	rb = (instr >> 11) & 0x1f;
++	t = (instr >> 21) & 0x1f;
++	if (instr & 1)
++		vdst = (u8 *)&current->thread.vr_state.vr[t];
++	else
++		vdst = (u8 *)&current->thread.fp_state.fpr[t][0];
++
++	/* Grab the vector address */
++	ea = regs->gpr[rb] + (ra ? regs->gpr[ra] : 0);
++	if (is_32bit_task())
++		ea &= 0xfffffffful;
++	addr = (__force const void __user *)ea;
++
++	/* Check it */
++	if (!access_ok(VERIFY_READ, addr, 16)) {
++		pr_devel("HMI vec emu: bad access %i:%s[%d] nip=%016lx"
++			 " instr=%08x addr=%016lx\n",
++			 smp_processor_id(), current->comm, current->pid,
++			 regs->nip, instr, (unsigned long)addr);
++		return;
++	}
++
++	/* Read the vector */
++	rc = 0;
++	if ((unsigned long)addr & 0xfUL)
++		/* unaligned case */
++		rc = __copy_from_user_inatomic(vbuf, addr, 16);
++	else
++		__get_user_atomic_128_aligned(vbuf, addr, rc);
++	if (rc) {
++		pr_devel("HMI vec emu: page fault %i:%s[%d] nip=%016lx"
++			 " instr=%08x addr=%016lx\n",
++			 smp_processor_id(), current->comm, current->pid,
++			 regs->nip, instr, (unsigned long)addr);
++		return;
++	}
++
++	pr_devel("HMI vec emu: emulated vector CI %i:%s[%d] nip=%016lx"
++		 " instr=%08x addr=%016lx\n",
++		 smp_processor_id(), current->comm, current->pid, regs->nip,
++		 instr, (unsigned long) addr);
++
++	/* Grab instruction "selector" */
++	sel = (instr >> 6) & 3;
++
++	/*
++	 * Check to make sure the facility is actually enabled. This
++	 * could happen if we get a false positive hit.
++	 *
++	 * lxvd2x/lxvw4x always check MSR VSX sel = 0,2
++	 * lxvh8x/lxvb16x check MSR VSX or VEC depending on VSR used sel = 1,3
++	 */
++	msr_mask = MSR_VSX;
++	if ((sel & 1) && (instr & 1)) /* lxvh8x & lxvb16x + VSR >= 32 */
++		msr_mask = MSR_VEC;
++	if (!(msr & msr_mask)) {
++		pr_devel("HMI vec emu: MSR fac clear %i:%s[%d] nip=%016lx"
++			 " instr=%08x msr:%016lx\n",
++			 smp_processor_id(), current->comm, current->pid,
++			 regs->nip, instr, msr);
++		return;
++	}
++
++	/* Do logging here before we modify sel based on endian */
++	switch (sel) {
++	case 0:	/* lxvw4x */
++		PPC_WARN_EMULATED(lxvw4x, regs);
++		break;
++	case 1: /* lxvh8x */
++		PPC_WARN_EMULATED(lxvh8x, regs);
++		break;
++	case 2: /* lxvd2x */
++		PPC_WARN_EMULATED(lxvd2x, regs);
++		break;
++	case 3: /* lxvb16x */
++		PPC_WARN_EMULATED(lxvb16x, regs);
++		break;
++	}
++
++#ifdef __LITTLE_ENDIAN__
++	/*
++	 * An LE kernel stores the vector in the task struct as an LE
++	 * byte array (effectively swapping both the components and
++	 * the content of the components). Those instructions expect
++	 * the components to remain in ascending address order, so we
++	 * swap them back.
++	 *
++	 * If we are running a BE user space, the expectation is that
++	 * of a simple memcpy, so forcing the emulation to look like
++	 * a lxvb16x should do the trick.
++	 */
++	if (swap)
++		sel = 3;
++
++	switch (sel) {
++	case 0:	/* lxvw4x */
++		for (i = 0; i < 4; i++)
++			((u32 *)vdst)[i] = ((u32 *)vbuf)[3-i];
++		break;
++	case 1: /* lxvh8x */
++		for (i = 0; i < 8; i++)
++			((u16 *)vdst)[i] = ((u16 *)vbuf)[7-i];
++		break;
++	case 2: /* lxvd2x */
++		for (i = 0; i < 2; i++)
++			((u64 *)vdst)[i] = ((u64 *)vbuf)[1-i];
++		break;
++	case 3: /* lxvb16x */
++		for (i = 0; i < 16; i++)
++			vdst[i] = vbuf[15-i];
++		break;
++	}
++#else /* __LITTLE_ENDIAN__ */
++	/* On a big endian kernel, a BE userspace only needs a memcpy */
++	if (!swap)
++		sel = 3;
++
++	/* Otherwise, we need to swap the content of the components */
++	switch (sel) {
++	case 0:	/* lxvw4x */
++		for (i = 0; i < 4; i++)
++			((u32 *)vdst)[i] = cpu_to_le32(((u32 *)vbuf)[i]);
++		break;
++	case 1: /* lxvh8x */
++		for (i = 0; i < 8; i++)
++			((u16 *)vdst)[i] = cpu_to_le16(((u16 *)vbuf)[i]);
++		break;
++	case 2: /* lxvd2x */
++		for (i = 0; i < 2; i++)
++			((u64 *)vdst)[i] = cpu_to_le64(((u64 *)vbuf)[i]);
++		break;
++	case 3: /* lxvb16x */
++		memcpy(vdst, vbuf, 16);
++		break;
++	}
++#endif /* !__LITTLE_ENDIAN__ */
++
++	/* Go to next instruction */
++	regs->nip += 4;
++}
++#endif /* CONFIG_VSX */
++
+ void handle_hmi_exception(struct pt_regs *regs)
+ {
+ 	struct pt_regs *old_regs;
+@@ -768,6 +950,21 @@ void handle_hmi_exception(struct pt_regs *regs)
+ 	old_regs = set_irq_regs(regs);
+ 	irq_enter();
+ 
++#ifdef CONFIG_VSX
++	/* Real mode flagged P9 special emu is needed */
++	if (local_paca->hmi_p9_special_emu) {
++		local_paca->hmi_p9_special_emu = 0;
++
++		/*
++		 * We don't want to take page faults while doing the
++		 * emulation, we just replay the instruction if necessary.
++		 */
++		pagefault_disable();
++		p9_hmi_special_emu(regs);
++		pagefault_enable();
++	}
++#endif /* CONFIG_VSX */
++
+ 	if (ppc_md.handle_hmi_exception)
+ 		ppc_md.handle_hmi_exception(regs);
+ 
+@@ -2004,6 +2201,10 @@ struct ppc_emulated ppc_emulated = {
+ 	WARN_EMULATED_SETUP(mfdscr),
+ 	WARN_EMULATED_SETUP(mtdscr),
+ 	WARN_EMULATED_SETUP(lq_stq),
++	WARN_EMULATED_SETUP(lxvw4x),
++	WARN_EMULATED_SETUP(lxvh8x),
++	WARN_EMULATED_SETUP(lxvd2x),
++	WARN_EMULATED_SETUP(lxvb16x),
+ #endif
+ };
+ 
+diff --git a/arch/powerpc/platforms/powernv/smp.c b/arch/powerpc/platforms/powernv/smp.c
+index 40dae96f7e20..b9dd3cc1d217 100644
+--- a/arch/powerpc/platforms/powernv/smp.c
++++ b/arch/powerpc/platforms/powernv/smp.c
+@@ -49,6 +49,13 @@
+ 
+ static void pnv_smp_setup_cpu(int cpu)
+ {
++	/*
++	 * P9 workaround for CI vector load (see traps.c),
++	 * enable the corresponding HMI interrupt
++	 */
++	if (pvr_version_is(PVR_POWER9))
++		mtspr(SPRN_HMEER, mfspr(SPRN_HMEER) | PPC_BIT(17));
++
+ 	if (xive_enabled())
+ 		xive_smp_setup_cpu();
+ 	else if (cpu != boot_cpuid)
diff --git a/openpower/linux/0002-Release-OpenPower-kernel.patch b/openpower/linux/0004-Release-OpenPower-kernel.patch
similarity index 72%
rename from openpower/linux/0002-Release-OpenPower-kernel.patch
rename to openpower/linux/0004-Release-OpenPower-kernel.patch
index da99bae..47062f1 100644
--- a/openpower/linux/0002-Release-OpenPower-kernel.patch
+++ b/openpower/linux/0004-Release-OpenPower-kernel.patch
@@ -1,7 +1,7 @@
 From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001
 From: Joel Stanley <joel@jms.id.au>
-Date: Thu, 28 Sep 2017 11:52:54 +0930
-Subject: [PATCH 2/2] Release OpenPower kernel
+Date: Wed, 4 Oct 2017 13:32:14 +1030
+Subject: [PATCH 4/4] Release OpenPower kernel
 
 Signed-off-by: Joel Stanley <joel@jms.id.au>
 ---
@@ -9,7 +9,7 @@
  1 file changed, 1 insertion(+), 1 deletion(-)
 
 diff --git a/Makefile b/Makefile
-index 159901979dec..b6ca367a928c 100644
+index 159901979dec..a8ecdef4cd33 100644
 --- a/Makefile
 +++ b/Makefile
 @@ -1,7 +1,7 @@
@@ -17,7 +17,7 @@
  PATCHLEVEL = 13
  SUBLEVEL = 4
 -EXTRAVERSION =
-+EXTRAVERSION = -openpower1
++EXTRAVERSION = -openpower2
  NAME = Fearless Coyote
  
  # *DOCUMENTATION*
diff --git a/openpower/package/Config.in b/openpower/package/Config.in
index 68699e0..aed88b6 100755
--- a/openpower/package/Config.in
+++ b/openpower/package/Config.in
@@ -17,4 +17,5 @@
 source "$BR2_EXTERNAL_OP_BUILD_PATH/package/ima-catalog/Config.in"
 source "$BR2_EXTERNAL_OP_BUILD_PATH/package/sbe/Config.in"
 source "$BR2_EXTERNAL_OP_BUILD_PATH/package/sb-signing-utils/Config.in"
+source "$BR2_EXTERNAL_OP_BUILD_PATH/package/sb-signing-framework/Config.in"
 
diff --git a/openpower/package/hostboot-binaries/hostboot_binaries.mk b/openpower/package/hostboot-binaries/hostboot_binaries.mk
index e65dea4..4ea66d7 100644
--- a/openpower/package/hostboot-binaries/hostboot_binaries.mk
+++ b/openpower/package/hostboot-binaries/hostboot_binaries.mk
@@ -4,7 +4,8 @@
 #
 ################################################################################
 
-HOSTBOOT_BINARIES_VERSION ?= d45f5e3c086decb9c437cc3c6410108487334663
+
+HOSTBOOT_BINARIES_VERSION ?= ed06137f062d6a716d2a89d852aac984036db256
 HOSTBOOT_BINARIES_SITE ?= $(call github,open-power,hostboot-binaries,$(HOSTBOOT_BINARIES_VERSION))
 
 HOSTBOOT_BINARIES_LICENSE = Apache-2.0
diff --git a/openpower/package/hostboot/hostboot.mk b/openpower/package/hostboot/hostboot.mk
index 0accc0c..9ac41bd 100644
--- a/openpower/package/hostboot/hostboot.mk
+++ b/openpower/package/hostboot/hostboot.mk
@@ -4,7 +4,7 @@
 #
 ################################################################################
 HOSTBOOT_VERSION_BRANCH_MASTER_P8 ?= 695bd891343faf1f0ef85fe53148590e58239efd
-HOSTBOOT_VERSION_BRANCH_MASTER ?= a19748cc4dbe3feff90fb95ffa7b9a474fdc7660
+HOSTBOOT_VERSION_BRANCH_MASTER ?= 4b9c63c334eda4e0363e5117a2a4eb375cd92252
 
 HOSTBOOT_VERSION ?= $(if $(BR2_OPENPOWER_POWER9),$(HOSTBOOT_VERSION_BRANCH_MASTER),$(HOSTBOOT_VERSION_BRANCH_MASTER_P8))
 HOSTBOOT_SITE ?= $(call github,open-power,hostboot,$(HOSTBOOT_VERSION))
diff --git a/openpower/package/ima-catalog/ima-catalog.mk b/openpower/package/ima-catalog/ima-catalog.mk
index 961e235..e37021d 100644
--- a/openpower/package/ima-catalog/ima-catalog.mk
+++ b/openpower/package/ima-catalog/ima-catalog.mk
@@ -3,7 +3,7 @@
 # ima-catalog.mk
 #
 ################################################################################
-IMA_CATALOG_VERSION ?= f9da5d6feb3c407cd24c88d61b73d7d01b2d1400
+IMA_CATALOG_VERSION ?= 7c7a388ae0bb734cc9e4fe10593c45d8946a8fd7
 IMA_CATALOG_SITE ?= $(call github,open-power,ima-catalog,$(IMA_CATALOG_VERSION))
 IMA_CATALOG_LICENSE = Apache-2.0
 IMA_CATALOG_DEPENDENCIES = host-dtc host-xz
diff --git a/openpower/package/libflash/libflash.mk b/openpower/package/libflash/libflash.mk
index c1c1a15..98ce0ed 100644
--- a/openpower/package/libflash/libflash.mk
+++ b/openpower/package/libflash/libflash.mk
@@ -4,7 +4,7 @@
 #
 ################################################################################
 
-LIBFLASH_VERSION = v5.7-76-g830fc9a0ed0a
+LIBFLASH_VERSION = v5.8-123-gc06ed583
 LIBFLASH_SITE = $(call github,open-power,skiboot,$(LIBFLASH_VERSION))
 
 LIBFLASH_INSTALL_STAGING = YES
diff --git a/openpower/package/occ/Config.in b/openpower/package/occ/Config.in
index 29b5eb4..1d77dff 100644
--- a/openpower/package/occ/Config.in
+++ b/openpower/package/occ/Config.in
@@ -9,3 +9,15 @@
         string "Name of OCC image file"
         help
             String used to define name of the OCC binary image file
+
+config BR2_OCC_GPU_BIN_BUILD
+        bool "Enables Compilation of GPU Binary Image"
+        default n
+        help
+            Boolean used to flag whether to compile OCC GPU binary
+
+config BR2_OCC_GPU_GPE_BIN_FILENAME
+        string "Name of OCC GPU GPE Binary file"
+        help
+            String used to define name of the OCC GPUE GPE binary image file
+
diff --git a/openpower/package/occ/occ.mk b/openpower/package/occ/occ.mk
index 65fd28a..92f60b3 100644
--- a/openpower/package/occ/occ.mk
+++ b/openpower/package/occ/occ.mk
@@ -23,7 +23,7 @@
 OCC_IMAGE_BIN_PATH = $(if $(BR2_OPENPOWER_POWER9),obj/image.bin,src/image.bin)
 
 OCC_DEPENDENCIES_P8 = host-binutils host-p8-pore-binutils
-OCC_DEPENDENCIES_P9 = host-binutils host-ppe42-gcc
+OCC_DEPENDENCIES_P9 = host-binutils host-ppe42-gcc hostboot-binaries
 OCC_DEPENDENCIES ?= $(if $(BR2_OPENPOWER_POWER9),$(OCC_DEPENDENCIES_P9),$(OCC_DEPENDENCIES_P8))
 
 define OCC_APPLY_PATCHES
@@ -50,8 +50,13 @@
         make combineImage
 endef
 define OCC_BUILD_CMDS_P9
-        cd $(@D)/src && \
-        make PPE_TOOL_PATH=$(PPE42_GCC_BIN) OCC_OP_BUILD=1 CROSS_PREFIX=$(TARGET_CROSS) LD_LIBRARY_PATH=$(HOST_DIR)/usr/lib all 
+	if ["$(BR2_OCC_GPU_BIN_BUILD)" == "y"  ]; then \
+	    cd $(@D)/src && \
+            make PPE_TOOL_PATH=$(PPE42_GCC_BIN) OCC_OP_BUILD=1 CROSS_PREFIX=$(TARGET_CROSS) LD_LIBRARY_PATH=$(HOST_DIR)/usr/lib GPE1_BIN_IMAGE_PATH=$(STAGING_DIR)/hostboot_build_images/ OPOCC_GPU_SUPPORT=1 all; \
+	else \
+            cd $(@D)/src && \
+            make PPE_TOOL_PATH=$(PPE42_GCC_BIN) OCC_OP_BUILD=1 CROSS_PREFIX=$(TARGET_CROSS) LD_LIBRARY_PATH=$(HOST_DIR)/usr/lib all; \
+	fi;
 endef
 OCC_BUILD_CMDS ?= $(if $(BR2_OPENPOWER_POWER9),$(OCC_BUILD_CMDS_P9),$(OCC_BUILD_CMDS_P8))
 
diff --git a/openpower/package/openpower-pnor/Config.in b/openpower/package/openpower-pnor/Config.in
index 644d281..37c4470 100644
--- a/openpower/package/openpower-pnor/Config.in
+++ b/openpower/package/openpower-pnor/Config.in
@@ -39,6 +39,7 @@
 
 config BR2_OPENPOWER_SECUREBOOT_SIGN_MODE
         string "Secureboot signing mode"
+        default "development"
         help
             Available options [development | production]
             Indicates the signing mode when generating the PNOR image.  Only
diff --git a/openpower/package/pkg-versions.mk b/openpower/package/pkg-versions.mk
index 9a37bbb..be50245 100644
--- a/openpower/package/pkg-versions.mk
+++ b/openpower/package/pkg-versions.mk
@@ -134,7 +134,7 @@
 
 UPPER_CASE_PKG = $(call UPPERCASE,$(1))
 $$(UPPER_CASE_PKG)_VERSION_FILE = $$(OPENPOWER_VERSION_DIR)/$(1).version.txt
-
+UPPER_CASE_SIGN_MODE = $(call UPPERCASE,$$(BR2_OPENPOWER_SECUREBOOT_SIGN_MODE))
 
 $$(eval $$(foreach pkg,$$(OPENPOWER_VERSIONED_SUBPACKAGES), \
 		$$(call OPENPOWER_SUBPACKAGE_VERSION,$$(pkg),$$(call UPPERCASE,$$(pkg)))))
@@ -168,6 +168,11 @@
 	>> $$($$(UPPER_CASE_PKG)_VERSION_FILE); \
 fi
 
+# Flag whether op-build is production signed
+if [ "$$(UPPER_CASE_SIGN_MODE)" == 'PRODUCTION' ]; then \
+	echo -n "-prod" >> $$($$(UPPER_CASE_PKG)_VERSION_FILE); \
+fi
+
 # Add new line to $$($$(UPPER_CASE_PKG)_VERSION_FILE)
 echo "" >> $$($$(UPPER_CASE_PKG)_VERSION_FILE);
 
diff --git a/openpower/package/sb-signing-framework/Config.in b/openpower/package/sb-signing-framework/Config.in
new file mode 100644
index 0000000..7ac3848
--- /dev/null
+++ b/openpower/package/sb-signing-framework/Config.in
@@ -0,0 +1,5 @@
+config BR2_PACKAGE_HOST_SB_SIGNING_FRAMEWORK
+        bool "OpenPOWER secureboot signing server interface"
+        default y if BR2_OPENPOWER_PLATFORM && ((BR2_OPENPOWER_SECUREBOOT_SIGN_MODE = "production") || (BR2_OPENPOWER_SECUREBOOT_KEY_TRANSITION_TO_PROD) )
+        help
+            Client interface to signing server for signing OpenPOWER firmware images
diff --git a/openpower/package/sb-signing-framework/sb-signing-framework.mk b/openpower/package/sb-signing-framework/sb-signing-framework.mk
new file mode 100644
index 0000000..6338ae0
--- /dev/null
+++ b/openpower/package/sb-signing-framework/sb-signing-framework.mk
@@ -0,0 +1,27 @@
+################################################################################
+#
+#  sb-signing-framework
+#
+################################################################################
+
+SB_SIGNING_FRAMEWORK_SITE ?= $(call github,open-power,sb-signing-framework,$(SB_SIGNING_FRAMEWORK_VERSION))
+
+SB_SIGNING_FRAMEWORK_LICENSE = Apache-2.0
+SB_SIGNING_FRAMEWORK_LICENSE_FILES = LICENSE
+SB_SIGNING_FRAMEWORK_VERSION ?= 02ed29aa11136a6d9a6e1f075772532c43cb7289
+
+HOST_SB_SIGNING_FRAMEWORK_DEPENDENCIES = host-openssl
+
+define HOST_SB_SIGNING_FRAMEWORK_BUILD_CMDS
+	CFLAGS="-I $(HOST_DIR)/usr/include -Wl,-rpath -Wl,$(HOST_DIR)/usr/lib" \
+		$(HOST_MAKE_ENV) $(MAKE) -C $(@D)/src/client/
+endef
+
+define HOST_SB_SIGNING_FRAMEWORK_COPY_FILES
+		$(INSTALL) -m 0755 $(@D)/src/client/sf_client $(HOST_DIR)/usr/bin/
+endef
+
+HOST_SB_SIGNING_FRAMEWORK_POST_INSTALL_HOOKS += HOST_SB_SIGNING_FRAMEWORK_COPY_FILES
+
+$(eval $(host-generic-package))
+
diff --git a/openpower/package/sb-signing-utils/Config.in b/openpower/package/sb-signing-utils/Config.in
index 87df6f3..b834f46 100644
--- a/openpower/package/sb-signing-utils/Config.in
+++ b/openpower/package/sb-signing-utils/Config.in
@@ -1,5 +1,5 @@
 config BR2_PACKAGE_HOST_SB_SIGNING_UTILS
         bool "OpenPOWER secureboot signing utilities"
-        default y if (BR2_OPENPOWER_PLATFORM && BR2_OPENPOWER_SECUREBOOT_ENABLED)
+        default y if (BR2_OPENPOWER_PLATFORM)
         help
             Secureboot utilities for signing OpenPOWER firmware images
diff --git a/openpower/package/sb-signing-utils/sb-signing-utils.mk b/openpower/package/sb-signing-utils/sb-signing-utils.mk
index de8b5eb..0dbb4d0 100644
--- a/openpower/package/sb-signing-utils/sb-signing-utils.mk
+++ b/openpower/package/sb-signing-utils/sb-signing-utils.mk
@@ -12,6 +12,12 @@
 
 HOST_SB_SIGNING_UTILS_DEPENDENCIES = host-openssl
 
+ifeq ($(BR2_OPENPOWER_SECUREBOOT_SIGN_MODE),production)
+HOST_SB_SIGNING_UTILS_DEPENDENCIES += host-sb-signing-framework
+else ifeq ($(BR2_OPENPOWER_SECUREBOOT_KEY_TRANSITION_TO_PROD),y)
+HOST_SB_SIGNING_UTILS_DEPENDENCIES += host-sb-signing-framework
+endif
+
 HOST_SB_SIGNING_UTILS_AUTORECONF = YES
 HOST_SB_SIGNING_UTILS_AUTORECONF_OPTS = -i
 
diff --git a/openpower/package/sbe/sbe.mk b/openpower/package/sbe/sbe.mk
index 891d992..728699f 100644
--- a/openpower/package/sbe/sbe.mk
+++ b/openpower/package/sbe/sbe.mk
@@ -4,7 +4,7 @@
 #
 ################################################################################
 
-SBE_VERSION ?= ff713dfd14ecf97b050a737cc5da2d6f01db493f
+SBE_VERSION ?= 374add4ab977460d1793ddcfa64548732c4cbe18
 SBE_SITE ?= $(call github,open-power,sbe,$(SBE_VERSION))
 
 SBE_LICENSE = Apache-2.0
