| Klaus Heinrich Kiwi | 92f659d | 2021-03-09 21:03:42 -0300 | [diff] [blame] | 1 | # ASPEED AST2600 devices can use Aspeed's utility 'socsec' | 
|  | 2 | # to sign the SPL (pubkey written to OTP region) | 
|  | 3 | # The variables below carry default values to the spl_sign() | 
|  | 4 | # function below. | 
|  | 5 | SOCSEC_SIGN_ENABLE ?= "0" | 
|  | 6 | SOCSEC_SIGN_KEY ?= "" | 
|  | 7 | SOCSEC_SIGN_SOC ?= "2600" | 
|  | 8 | SOCSEC_SIGN_ALGO ?= "RSA4096_SHA512" | 
|  | 9 | SOCSEC_SIGN_HELPER ?= "" | 
|  | 10 | # u-boot-aspeed-sdk commit '2c3b53489c ast2600: Modify SPL SRAM layout' | 
|  | 11 | # changes the SDRAM layout so that the verification region does NOT | 
|  | 12 | # intersects the stack. The parameter below can be used to instruct | 
|  | 13 | # socsec to work in either mode (ommitting it throws a warning), but | 
|  | 14 | # newer (post v00.03.03) u-boot-aspeed-sdk need this set to false | 
| Jamin Lin | e73cb4a | 2021-12-17 15:04:35 +0800 | [diff] [blame^] | 15 | # A1 rsa order is little endian and A3 is big endian | 
|  | 16 | # Set big endian for A3 support | 
|  | 17 | SOCSEC_SIGN_EXTRA_OPTS ?= "--stack_intersects_verification_region=false --rsa_key_order=big" | 
| Klaus Heinrich Kiwi | 92f659d | 2021-03-09 21:03:42 -0300 | [diff] [blame] | 18 | DEPENDS += '${@oe.utils.conditional("SOCSEC_SIGN_ENABLE", "1", " socsec-native", "", d)}' | 
|  | 19 |  | 
|  | 20 |  | 
|  | 21 | # Signs the SPL binary with a pre-established key | 
|  | 22 | sign_spl_helper() { | 
|  | 23 | signing_helper_args="" | 
|  | 24 |  | 
|  | 25 | if [ "${SOC_FAMILY}" != "aspeed-g6" ] ; then | 
|  | 26 | echo "Warning: SPL signing is only supported on AST2600 boards" | 
|  | 27 | elif [ ! -e "${SOCSEC_SIGN_KEY}" ] ; then | 
| Andrew Jeffery | bf97bbd | 2021-08-26 10:26:03 +0930 | [diff] [blame] | 28 | echo "Error: Invalid socsec signing key: ${SOCSEC_SIGN_KEY}" | 
|  | 29 | exit 1 | 
| Klaus Heinrich Kiwi | 92f659d | 2021-03-09 21:03:42 -0300 | [diff] [blame] | 30 | else | 
|  | 31 | rm -f ${SPL_BINARY}.staged | 
|  | 32 |  | 
|  | 33 | if [ -n "${SOCSEC_SIGN_HELPER}" ] ; then | 
|  | 34 | signing_helper_args="--signing_helper ${SOCSEC_SIGN_HELPER}" | 
|  | 35 | fi | 
|  | 36 | socsec make_secure_bl1_image \ | 
|  | 37 | --soc ${SOCSEC_SIGN_SOC}  \ | 
|  | 38 | --algorithm ${SOCSEC_SIGN_ALGO} \ | 
|  | 39 | --rsa_sign_key ${SOCSEC_SIGN_KEY} \ | 
|  | 40 | --bl1_image ${DEPLOYDIR}/${SPL_IMAGE} \ | 
|  | 41 | ${signing_helper_args} \ | 
|  | 42 | ${SOCSEC_SIGN_EXTRA_OPTS} \ | 
|  | 43 | --output ${SPL_BINARY}.staged | 
|  | 44 | cp -f ${SPL_BINARY}.staged ${B}/${CONFIG_B_PATH}/${SPL_BINARY} | 
|  | 45 | mv -f ${SPL_BINARY}.staged ${DEPLOYDIR}/${SPL_IMAGE} | 
|  | 46 | fi | 
|  | 47 | } | 
|  | 48 |  | 
|  | 49 | sign_spl() { | 
|  | 50 | mkdir -p ${DEPLOYDIR} | 
|  | 51 | if [ -n "${UBOOT_CONFIG}" ]; then | 
|  | 52 | for config in ${UBOOT_MACHINE}; do | 
|  | 53 | CONFIG_B_PATH="${config}" | 
|  | 54 | cd ${B}/${config} | 
|  | 55 | sign_spl_helper | 
|  | 56 | done | 
|  | 57 | else | 
|  | 58 | CONFIG_B_PATH="" | 
|  | 59 | cd ${B} | 
|  | 60 | sign_spl_helper | 
|  | 61 | fi | 
|  | 62 | } | 
|  | 63 |  | 
|  | 64 |  | 
| Patrick Williams | b9799be | 2021-08-06 09:13:33 -0500 | [diff] [blame] | 65 | do_deploy:append() { | 
| Klaus Heinrich Kiwi | 92f659d | 2021-03-09 21:03:42 -0300 | [diff] [blame] | 66 | if [ "${SOCSEC_SIGN_ENABLE}" = "1" -a -n "${SPL_BINARY}" ] ; then | 
|  | 67 | sign_spl | 
|  | 68 | fi | 
|  | 69 | } |