Paul Beesley | 9774302 | 2019-07-12 11:37:07 +0100 | [diff] [blame] | 1 | TF-A Build Instructions for Marvell Platforms |
| 2 | ============================================= |
| 3 | |
| 4 | This section describes how to compile the Trusted Firmware-A (TF-A) project for Marvell's platforms. |
| 5 | |
| 6 | Build Instructions |
| 7 | ------------------ |
| 8 | (1) Set the cross compiler |
| 9 | |
| 10 | .. code:: shell |
| 11 | |
Mark Dykes | ef3a456 | 2020-01-08 20:37:18 +0000 | [diff] [blame] | 12 | > export CROSS_COMPILE=/path/to/toolchain/aarch64-linux-gnu- |
Paul Beesley | 9774302 | 2019-07-12 11:37:07 +0100 | [diff] [blame] | 13 | |
| 14 | (2) Set path for FIP images: |
| 15 | |
| 16 | Set U-Boot image path (relatively to TF-A root or absolute path) |
| 17 | |
| 18 | .. code:: shell |
| 19 | |
| 20 | > export BL33=path/to/u-boot.bin |
| 21 | |
| 22 | For example: if U-Boot project (and its images) is located at ``~/project/u-boot``, |
| 23 | BL33 should be ``~/project/u-boot/u-boot.bin`` |
| 24 | |
| 25 | .. note:: |
| 26 | |
| 27 | *u-boot.bin* should be used and not *u-boot-spl.bin* |
| 28 | |
Konstantin Porotchkin | 2309961 | 2020-10-12 18:13:07 +0300 | [diff] [blame] | 29 | Set MSS/SCP image path (mandatory only for A7K/8K/CN913x when MSS_SUPPORT=1) |
Paul Beesley | 9774302 | 2019-07-12 11:37:07 +0100 | [diff] [blame] | 30 | |
| 31 | .. code:: shell |
| 32 | |
| 33 | > export SCP_BL2=path/to/mrvl_scp_bl2*.img |
| 34 | |
| 35 | (3) Armada-37x0 build requires WTP tools installation. |
| 36 | |
| 37 | See below in the section "Tools and external components installation". |
| 38 | Install ARM 32-bit cross compiler, which is required for building WTMI image for CM3 |
| 39 | |
| 40 | .. code:: shell |
| 41 | |
| 42 | > sudo apt-get install gcc-arm-linux-gnueabi |
| 43 | |
| 44 | (4) Clean previous build residuals (if any) |
| 45 | |
| 46 | .. code:: shell |
| 47 | |
| 48 | > make distclean |
| 49 | |
| 50 | (5) Build TF-A |
| 51 | |
| 52 | There are several build options: |
| 53 | |
Pali Rohár | 179b673 | 2021-02-01 12:22:37 +0100 | [diff] [blame] | 54 | - PLAT |
| 55 | |
| 56 | Supported Marvell platforms are: |
| 57 | |
| 58 | - a3700 - A3720 DB, EspressoBin and Turris MOX |
| 59 | - a70x0 |
| 60 | - a70x0_amc - AMC board |
Robert Marko | 9c523ec | 2021-10-11 16:25:49 +0200 | [diff] [blame] | 61 | - a70x0_mochabin - Globalscale MOCHAbin |
Pali Rohár | 179b673 | 2021-02-01 12:22:37 +0100 | [diff] [blame] | 62 | - a80x0 |
| 63 | - a80x0_mcbin - MacchiatoBin |
| 64 | - a80x0_puzzle - IEI Puzzle-M801 |
| 65 | - t9130 - CN913x |
Marcin Wojtas | e3ade60 | 2021-06-22 23:44:26 +0200 | [diff] [blame] | 66 | - t9130_cex7_eval - CN913x CEx7 Evaluation Board |
Pali Rohár | 179b673 | 2021-02-01 12:22:37 +0100 | [diff] [blame] | 67 | |
Paul Beesley | 9774302 | 2019-07-12 11:37:07 +0100 | [diff] [blame] | 68 | - DEBUG |
| 69 | |
| 70 | Default is without debug information (=0). in order to enable it use ``DEBUG=1``. |
| 71 | Must be disabled when building UART recovery images due to current console driver |
| 72 | implementation that is not compatible with Xmodem protocol used for boot image download. |
| 73 | |
| 74 | - LOG_LEVEL |
| 75 | |
| 76 | Defines the level of logging which will be purged to the default output port. |
| 77 | |
Pali Rohár | 8dc46a0 | 2020-10-29 17:44:27 +0100 | [diff] [blame] | 78 | - 0 - LOG_LEVEL_NONE |
| 79 | - 10 - LOG_LEVEL_ERROR |
| 80 | - 20 - LOG_LEVEL_NOTICE (default for DEBUG=0) |
| 81 | - 30 - LOG_LEVEL_WARNING |
| 82 | - 40 - LOG_LEVEL_INFO (default for DEBUG=1) |
| 83 | - 50 - LOG_LEVEL_VERBOSE |
Paul Beesley | 9774302 | 2019-07-12 11:37:07 +0100 | [diff] [blame] | 84 | |
| 85 | - USE_COHERENT_MEM |
| 86 | |
| 87 | This flag determines whether to include the coherent memory region in the |
Pali Rohár | 8dc46a0 | 2020-10-29 17:44:27 +0100 | [diff] [blame] | 88 | BL memory map or not. Enabled by default. |
Paul Beesley | 9774302 | 2019-07-12 11:37:07 +0100 | [diff] [blame] | 89 | |
| 90 | - LLC_ENABLE |
| 91 | |
| 92 | Flag defining the LLC (L3) cache state. The cache is enabled by default (``LLC_ENABLE=1``). |
| 93 | |
Konstantin Porotchkin | 2ef36a3 | 2019-03-31 16:58:11 +0300 | [diff] [blame] | 94 | - LLC_SRAM |
| 95 | |
Konstantin Porotchkin | 2850326 | 2019-04-15 16:32:59 +0300 | [diff] [blame] | 96 | Flag enabling the LLC (L3) cache SRAM support. The LLC SRAM is activated and used |
| 97 | by Trusted OS (OP-TEE OS, BL32). The TF-A only prepares CCU address translation windows |
| 98 | for SRAM address range at BL31 execution stage with window target set to DRAM-0. |
| 99 | When Trusted OS activates LLC SRAM, the CCU window target is changed to SRAM. |
| 100 | There is no reason to enable this feature if OP-TEE OS built with CFG_WITH_PAGER=n. |
| 101 | Only set LLC_SRAM=1 if OP-TEE OS is built with CFG_WITH_PAGER=y. |
Konstantin Porotchkin | 2ef36a3 | 2019-03-31 16:58:11 +0300 | [diff] [blame] | 102 | |
Paul Beesley | 9774302 | 2019-07-12 11:37:07 +0100 | [diff] [blame] | 103 | - MARVELL_SECURE_BOOT |
| 104 | |
| 105 | Build trusted(=1)/non trusted(=0) image, default is non trusted. |
Pali Rohár | 3278e7e | 2021-07-20 17:42:24 +0200 | [diff] [blame] | 106 | This parameter is used only for ``mrvl_flash`` and ``mrvl_uart`` targets. |
Paul Beesley | 9774302 | 2019-07-12 11:37:07 +0100 | [diff] [blame] | 107 | |
| 108 | - MV_DDR_PATH |
| 109 | |
Pali Rohár | cf44b12 | 2021-06-28 15:27:25 +0200 | [diff] [blame] | 110 | This parameter is required for ``mrvl_flash`` and ``mrvl_uart`` targets. |
Pali Rohár | 111a012 | 2021-07-07 12:14:20 +0200 | [diff] [blame] | 111 | For A7K/8K/CN913x it is used for BLE build and for Armada37x0 it used |
| 112 | for ddr_tool build. |
Pali Rohár | cf44b12 | 2021-06-28 15:27:25 +0200 | [diff] [blame] | 113 | |
Pali Rohár | 111a012 | 2021-07-07 12:14:20 +0200 | [diff] [blame] | 114 | Specify path to the full checkout of Marvell mv-ddr-marvell git |
| 115 | repository. Checkout must contain also .git subdirectory because |
| 116 | mv-ddr build process calls git commands. |
Paul Beesley | 9774302 | 2019-07-12 11:37:07 +0100 | [diff] [blame] | 117 | |
Pali Rohár | 111a012 | 2021-07-07 12:14:20 +0200 | [diff] [blame] | 118 | Do not remove any parts of git checkout becuase build process and other |
| 119 | applications need them for correct building and version determination. |
Pali Rohár | 88f225a | 2021-01-26 10:44:07 +0100 | [diff] [blame] | 120 | |
Pali Rohár | 3278e7e | 2021-07-20 17:42:24 +0200 | [diff] [blame] | 121 | |
| 122 | CN913x specific build options: |
| 123 | |
Konstantin Porotchkin | efcc41e | 2019-02-19 10:40:33 +0200 | [diff] [blame] | 124 | - CP_NUM |
| 125 | |
| 126 | Total amount of CPs (South Bridge) connected to AP. When the parameter is omitted, |
| 127 | the build uses the default number of CPs, which is a number of embedded CPs inside the |
| 128 | package: 1 or 2 depending on the SoC used. The parameter is valid for OcteonTX2 CN913x SoC |
| 129 | family (PLAT=t9130), which can have external CPs connected to the MCI ports. Valid |
| 130 | values with CP_NUM are in a range of 1 to 3. |
| 131 | |
Pali Rohár | 3278e7e | 2021-07-20 17:42:24 +0200 | [diff] [blame] | 132 | |
| 133 | A7K/8K/CN913x specific build options: |
| 134 | |
| 135 | - BLE_PATH |
| 136 | |
| 137 | Points to BLE (Binary ROM extension) sources folder. |
| 138 | The parameter is optional, its default value is ``plat/marvell/armada/a8k/common/ble`` |
| 139 | which uses TF-A in-tree BLE implementation. |
| 140 | |
Pali Rohár | 6a194cc | 2021-08-20 14:35:08 +0200 | [diff] [blame] | 141 | - MSS_SUPPORT |
| 142 | |
| 143 | When ``MSS_SUPPORT=1``, then TF-A includes support for Management SubSystem (MSS). |
| 144 | When enabled it is required to specify path to the MSS firmware image via ``SCP_BL2`` |
| 145 | option. |
| 146 | |
| 147 | This option is by default enabled. |
| 148 | |
| 149 | - SCP_BL2 |
| 150 | |
| 151 | Specify path to the MSS fimware image binary which will run on Cortex-M3 coprocessor. |
| 152 | It is available in Marvell binaries-marvell git repository. Required when ``MSS_SUPPORT=1``. |
| 153 | |
Robert Marko | 9c523ec | 2021-10-11 16:25:49 +0200 | [diff] [blame] | 154 | Globalscale MOCHAbin specific build options: |
| 155 | |
| 156 | - DDR_TOPOLOGY |
| 157 | |
| 158 | The DDR topology map index/name, default is 0. |
| 159 | |
| 160 | Supported Options: |
| 161 | - 0 - DDR4 1CS 2GB |
| 162 | - 1 - DDR4 1CS 4GB |
| 163 | - 2 - DDR4 2CS 8GB |
Pali Rohár | 3278e7e | 2021-07-20 17:42:24 +0200 | [diff] [blame] | 164 | |
| 165 | Armada37x0 specific build options: |
| 166 | |
Pali Rohár | 76f3849 | 2021-07-09 15:10:27 +0200 | [diff] [blame] | 167 | - HANDLE_EA_EL3_FIRST |
| 168 | |
| 169 | When ``HANDLE_EA_EL3_FIRST=1``, External Aborts and SError Interrupts will be always trapped |
| 170 | in TF-A. TF-A in this case enables dirty hack / workaround for a bug found in U-Boot and |
| 171 | Linux kernel PCIe controller driver pci-aardvark.c, traps and then masks SError interrupt |
| 172 | caused by AXI SLVERR on external access (syndrome 0xbf000002). |
| 173 | |
| 174 | Otherwise when ``HANDLE_EA_EL3_FIRST=0``, these exceptions will be trapped in the current |
| 175 | exception level (or in EL1 if the current exception level is EL0). So exceptions caused by |
| 176 | U-Boot will be trapped in U-Boot, exceptions caused by Linux kernel (or user applications) |
| 177 | will be trapped in Linux kernel. |
| 178 | |
| 179 | Mentioned bug in pci-aardvark.c driver is fixed in U-Boot version v2021.07 and Linux kernel |
| 180 | version v5.13 (workarounded since Linux kernel version 5.9) and also backported in Linux |
| 181 | kernel stable releases since versions v5.12.13, v5.10.46, v5.4.128, v4.19.198, v4.14.240. |
| 182 | |
| 183 | If target system has already patched version of U-Boot and Linux kernel then it is strongly |
| 184 | recommended to not enable this workaround as it disallows propagating of all External Aborts |
| 185 | to running Linux kernel and makes correctable errors as fatal aborts. |
| 186 | |
| 187 | This option is now disabled by default. In past this option was enabled by default in |
| 188 | TF-A versions v2.2, v2.3, v2.4 and v2.5. |
| 189 | |
Pali Rohár | 3278e7e | 2021-07-20 17:42:24 +0200 | [diff] [blame] | 190 | - CM3_SYSTEM_RESET |
| 191 | |
| 192 | When ``CM3_SYSTEM_RESET=1``, the Cortex-M3 secure coprocessor will be used for system reset. |
| 193 | |
| 194 | TF-A will send command 0x0009 with a magic value via the rWTM mailbox interface to the |
| 195 | Cortex-M3 secure coprocessor. |
| 196 | The firmware running in the coprocessor must either implement this functionality or |
| 197 | ignore the 0x0009 command (which is true for the firmware from A3700-utils-marvell |
| 198 | repository). If this option is enabled but the firmware does not support this command, |
| 199 | an error message will be printed prior trying to reboot via the usual way. |
| 200 | |
| 201 | This option is needed on Turris MOX as a workaround to a HW bug which causes reset to |
| 202 | sometime hang the board. |
| 203 | |
| 204 | - A3720_DB_PM_WAKEUP_SRC |
| 205 | |
| 206 | For Armada 3720 Development Board only, when ``A3720_DB_PM_WAKEUP_SRC=1``, |
| 207 | TF-A will setup PM wake up src configuration. This option is disabled by default. |
| 208 | |
| 209 | |
| 210 | Armada37x0 specific build options for ``mrvl_flash`` and ``mrvl_uart`` targets: |
| 211 | |
Paul Beesley | 9774302 | 2019-07-12 11:37:07 +0100 | [diff] [blame] | 212 | - DDR_TOPOLOGY |
| 213 | |
Pali Rohár | 3278e7e | 2021-07-20 17:42:24 +0200 | [diff] [blame] | 214 | The DDR topology map index/name, default is 0. |
Paul Beesley | 9774302 | 2019-07-12 11:37:07 +0100 | [diff] [blame] | 215 | |
| 216 | Supported Options: |
Pali Rohár | 38686c2 | 2021-02-01 12:23:31 +0100 | [diff] [blame] | 217 | - 0 - DDR3 1CS 512MB (DB-88F3720-DDR3-Modular, EspressoBin V3-V5) |
| 218 | - 1 - DDR4 1CS 512MB (DB-88F3720-DDR4-Modular) |
| 219 | - 2 - DDR3 2CS 1GB (EspressoBin V3-V5) |
| 220 | - 3 - DDR4 2CS 4GB (DB-88F3720-DDR4-Modular) |
| 221 | - 4 - DDR3 1CS 1GB (DB-88F3720-DDR3-Modular, EspressoBin V3-V5) |
| 222 | - 5 - DDR4 1CS 1GB (EspressoBin V7, EspressoBin-Ultra) |
| 223 | - 6 - DDR4 2CS 2GB (EspressoBin V7) |
| 224 | - 7 - DDR3 2CS 2GB (EspressoBin V3-V5) |
| 225 | - CUST - CUSTOMER BOARD (Customer board settings) |
Paul Beesley | 9774302 | 2019-07-12 11:37:07 +0100 | [diff] [blame] | 226 | |
| 227 | - CLOCKSPRESET |
| 228 | |
Pali Rohár | 3278e7e | 2021-07-20 17:42:24 +0200 | [diff] [blame] | 229 | The clock tree configuration preset including CPU and DDR frequency, |
Paul Beesley | 9774302 | 2019-07-12 11:37:07 +0100 | [diff] [blame] | 230 | default is CPU_800_DDR_800. |
| 231 | |
Pali Rohár | 8dc46a0 | 2020-10-29 17:44:27 +0100 | [diff] [blame] | 232 | - CPU_600_DDR_600 - CPU at 600 MHz, DDR at 600 MHz |
| 233 | - CPU_800_DDR_800 - CPU at 800 MHz, DDR at 800 MHz |
| 234 | - CPU_1000_DDR_800 - CPU at 1000 MHz, DDR at 800 MHz |
| 235 | - CPU_1200_DDR_750 - CPU at 1200 MHz, DDR at 750 MHz |
Paul Beesley | 9774302 | 2019-07-12 11:37:07 +0100 | [diff] [blame] | 236 | |
Pali Rohár | 3514287 | 2021-02-01 12:24:42 +0100 | [diff] [blame] | 237 | Look at Armada37x0 chip package marking on board to identify correct CPU frequency. |
| 238 | The last line on package marking (next line after the 88F37x0 line) should contain: |
| 239 | |
| 240 | - C080 or I080 - chip with 800 MHz CPU - use ``CLOCKSPRESET=CPU_800_DDR_800`` |
| 241 | - C100 or I100 - chip with 1000 MHz CPU - use ``CLOCKSPRESET=CPU_1000_DDR_800`` |
| 242 | - C120 - chip with 1200 MHz CPU - use ``CLOCKSPRESET=CPU_1200_DDR_750`` |
| 243 | |
Paul Beesley | 9774302 | 2019-07-12 11:37:07 +0100 | [diff] [blame] | 244 | - BOOTDEV |
| 245 | |
Pali Rohár | 3278e7e | 2021-07-20 17:42:24 +0200 | [diff] [blame] | 246 | The flash boot device, default is ``SPINOR``. |
Paul Beesley | 9774302 | 2019-07-12 11:37:07 +0100 | [diff] [blame] | 247 | |
| 248 | Currently, Armada37x0 only supports ``SPINOR``, ``SPINAND``, ``EMMCNORM`` and ``SATA``: |
| 249 | |
| 250 | - SPINOR - SPI NOR flash boot |
| 251 | - SPINAND - SPI NAND flash boot |
| 252 | - EMMCNORM - eMMC Download Mode |
| 253 | |
| 254 | Download boot loader or program code from eMMC flash into CM3 or CA53 |
| 255 | Requires full initialization and command sequence |
| 256 | |
| 257 | - SATA - SATA device boot |
| 258 | |
Pali Rohár | a074742 | 2021-01-28 13:09:36 +0100 | [diff] [blame] | 259 | Image needs to be stored at disk LBA 0 or at disk partition with |
| 260 | MBR type 0x4d (ASCII 'M' as in Marvell) or at disk partition with |
Pali Rohár | 3e67cc7 | 2022-02-14 18:27:32 +0100 | [diff] [blame] | 261 | GPT partition type GUID ``6828311A-BA55-42A4-BCDE-A89BB5EDECAE``. |
Pali Rohár | a074742 | 2021-01-28 13:09:36 +0100 | [diff] [blame] | 262 | |
Paul Beesley | 9774302 | 2019-07-12 11:37:07 +0100 | [diff] [blame] | 263 | - PARTNUM |
| 264 | |
Pali Rohár | 3278e7e | 2021-07-20 17:42:24 +0200 | [diff] [blame] | 265 | The boot partition number, default is 0. |
Paul Beesley | 9774302 | 2019-07-12 11:37:07 +0100 | [diff] [blame] | 266 | |
| 267 | To boot from eMMC, the value should be aligned with the parameter in |
| 268 | U-Boot with name of ``CONFIG_SYS_MMC_ENV_PART``, whose value by default is |
| 269 | 1. For details about CONFIG_SYS_MMC_ENV_PART, please refer to the U-Boot |
| 270 | build instructions. |
| 271 | |
| 272 | - WTMI_IMG |
| 273 | |
Pali Rohár | 3278e7e | 2021-07-20 17:42:24 +0200 | [diff] [blame] | 274 | The path of the binary can point to an image which |
Paul Beesley | 9774302 | 2019-07-12 11:37:07 +0100 | [diff] [blame] | 275 | does nothing, an image which supports EFUSE or a customized CM3 firmware |
Pali Rohár | 2da2e6a | 2021-01-27 18:04:32 +0100 | [diff] [blame] | 276 | binary. The default image is ``fuse.bin`` that built from sources in WTP |
Paul Beesley | 9774302 | 2019-07-12 11:37:07 +0100 | [diff] [blame] | 277 | folder, which is the next option. If the default image is OK, then this |
| 278 | option should be skipped. |
| 279 | |
Pali Rohár | 2da2e6a | 2021-01-27 18:04:32 +0100 | [diff] [blame] | 280 | Please note that this is not a full WTMI image, just a main loop without |
| 281 | hardware initialization code. Final WTMI image is built from this WTMI_IMG |
| 282 | binary and sys-init code from the WTP directory which sets DDR and CPU |
| 283 | clocks according to DDR_TOPOLOGY and CLOCKSPRESET options. |
| 284 | |
Pali Rohár | 2c6e0a8 | 2021-04-08 10:33:04 +0200 | [diff] [blame] | 285 | CZ.NIC as part of Turris project released free and open source WTMI |
| 286 | application firmware ``wtmi_app.bin`` for all Armada 3720 devices. |
| 287 | This firmware includes additional features like access to Hardware |
| 288 | Random Number Generator of Armada 3720 SoC which original Marvell's |
| 289 | ``fuse.bin`` image does not have. |
| 290 | |
| 291 | CZ.NIC's Armada 3720 Secure Firmware is available at website: |
| 292 | |
| 293 | https://gitlab.nic.cz/turris/mox-boot-builder/ |
| 294 | |
Paul Beesley | 9774302 | 2019-07-12 11:37:07 +0100 | [diff] [blame] | 295 | - WTP |
| 296 | |
Pali Rohár | 111a012 | 2021-07-07 12:14:20 +0200 | [diff] [blame] | 297 | Specify path to the full checkout of Marvell A3700-utils-marvell git |
| 298 | repository. Checkout must contain also .git subdirectory because WTP |
| 299 | build process calls git commands. |
| 300 | |
| 301 | WTP build process uses also Marvell mv-ddr-marvell git repository |
| 302 | specified in MV_DDR_PATH option. |
Paul Beesley | 9774302 | 2019-07-12 11:37:07 +0100 | [diff] [blame] | 303 | |
Pali Rohár | 111a012 | 2021-07-07 12:14:20 +0200 | [diff] [blame] | 304 | Do not remove any parts of git checkout becuase build process and other |
| 305 | applications need them for correct building and version determination. |
Pali Rohár | 88f225a | 2021-01-26 10:44:07 +0100 | [diff] [blame] | 306 | |
Pali Rohár | 8dc46a0 | 2020-10-29 17:44:27 +0100 | [diff] [blame] | 307 | - CRYPTOPP_PATH |
Paul Beesley | 9774302 | 2019-07-12 11:37:07 +0100 | [diff] [blame] | 308 | |
Pali Rohár | 3278e7e | 2021-07-20 17:42:24 +0200 | [diff] [blame] | 309 | Use this parameter to point to Crypto++ source code |
Pali Rohár | a304cf5 | 2021-01-26 10:44:07 +0100 | [diff] [blame] | 310 | directory. If this option is specified then Crypto++ source code in |
| 311 | CRYPTOPP_PATH directory will be automatically compiled. Crypto++ library |
| 312 | is required for building WTP image tool. Either CRYPTOPP_PATH or |
| 313 | CRYPTOPP_LIBDIR with CRYPTOPP_INCDIR needs to be specified for Armada37x0. |
| 314 | |
| 315 | - CRYPTOPP_LIBDIR |
| 316 | |
Pali Rohár | 3278e7e | 2021-07-20 17:42:24 +0200 | [diff] [blame] | 317 | Use this parameter to point to the directory with |
Pali Rohár | a304cf5 | 2021-01-26 10:44:07 +0100 | [diff] [blame] | 318 | compiled Crypto++ library. By default it points to the CRYPTOPP_PATH. |
| 319 | |
Pali Rohár | a335986 | 2022-02-16 15:15:42 +0100 | [diff] [blame] | 320 | On Debian systems it is possible to install system-wide Crypto++ library |
| 321 | via command ``apt install libcrypto++-dev`` and specify CRYPTOPP_LIBDIR |
| 322 | to ``/usr/lib/``. |
| 323 | |
Pali Rohár | a304cf5 | 2021-01-26 10:44:07 +0100 | [diff] [blame] | 324 | - CRYPTOPP_INCDIR |
| 325 | |
Pali Rohár | 3278e7e | 2021-07-20 17:42:24 +0200 | [diff] [blame] | 326 | Use this parameter to point to the directory with |
Pali Rohár | a304cf5 | 2021-01-26 10:44:07 +0100 | [diff] [blame] | 327 | header files of Crypto++ library. By default it points to the CRYPTOPP_PATH. |
Paul Beesley | 9774302 | 2019-07-12 11:37:07 +0100 | [diff] [blame] | 328 | |
Pali Rohár | a335986 | 2022-02-16 15:15:42 +0100 | [diff] [blame] | 329 | On Debian systems it is possible to install system-wide Crypto++ library |
| 330 | via command ``apt install libcrypto++-dev`` and specify CRYPTOPP_INCDIR |
| 331 | to ``/usr/include/crypto++/``. |
| 332 | |
Paul Beesley | 9774302 | 2019-07-12 11:37:07 +0100 | [diff] [blame] | 333 | |
Pali Rohár | 8dc46a0 | 2020-10-29 17:44:27 +0100 | [diff] [blame] | 334 | For example, in order to build the image in debug mode with log level up to 'notice' level run |
Paul Beesley | 9774302 | 2019-07-12 11:37:07 +0100 | [diff] [blame] | 335 | |
Pali Rohár | 8dc46a0 | 2020-10-29 17:44:27 +0100 | [diff] [blame] | 336 | .. code:: shell |
| 337 | |
| 338 | > make DEBUG=1 USE_COHERENT_MEM=0 LOG_LEVEL=20 PLAT=<MARVELL_PLATFORM> mrvl_flash |
Paul Beesley | 9774302 | 2019-07-12 11:37:07 +0100 | [diff] [blame] | 339 | |
Pali Rohár | 8dc46a0 | 2020-10-29 17:44:27 +0100 | [diff] [blame] | 340 | And if we want to build a Armada37x0 image in debug mode with log level up to 'notice' level, |
| 341 | the image has the preset CPU at 1000 MHz, preset DDR3 at 800 MHz, the DDR topology of DDR4 2CS, |
| 342 | the image boot from SPI NOR flash partition 0, and the image is non trusted in WTP, the command |
| 343 | line is as following |
Paul Beesley | 9774302 | 2019-07-12 11:37:07 +0100 | [diff] [blame] | 344 | |
Pali Rohár | 8dc46a0 | 2020-10-29 17:44:27 +0100 | [diff] [blame] | 345 | .. code:: shell |
| 346 | |
| 347 | > make DEBUG=1 USE_COHERENT_MEM=0 LOG_LEVEL=20 CLOCKSPRESET=CPU_1000_DDR_800 \ |
| 348 | MARVELL_SECURE_BOOT=0 DDR_TOPOLOGY=3 BOOTDEV=SPINOR PARTNUM=0 PLAT=a3700 \ |
| 349 | MV_DDR_PATH=/path/to/mv-ddr-marvell/ WTP=/path/to/A3700-utils-marvell/ \ |
| 350 | CRYPTOPP_PATH=/path/to/cryptopp/ BL33=/path/to/u-boot.bin \ |
Pali Rohár | 9e737b6 | 2021-01-26 10:44:07 +0100 | [diff] [blame] | 351 | all fip mrvl_bootimage mrvl_flash mrvl_uart |
Pali Rohár | 8dc46a0 | 2020-10-29 17:44:27 +0100 | [diff] [blame] | 352 | |
| 353 | To build just TF-A without WTMI image (useful for A3720 Turris MOX board), run following command: |
| 354 | |
| 355 | .. code:: shell |
| 356 | |
Marek Behún | 19d8578 | 2021-01-05 14:01:05 +0100 | [diff] [blame] | 357 | > make USE_COHERENT_MEM=0 PLAT=a3700 CM3_SYSTEM_RESET=1 BL33=/path/to/u-boot.bin \ |
| 358 | CROSS_COMPILE=aarch64-linux-gnu- mrvl_bootimage |
Pali Rohár | 8dc46a0 | 2020-10-29 17:44:27 +0100 | [diff] [blame] | 359 | |
Pali Rohár | 0c0d265 | 2021-02-01 12:32:36 +0100 | [diff] [blame] | 360 | Here is full example how to build production release of Marvell firmware image (concatenated |
Pali Rohár | 2c6e0a8 | 2021-04-08 10:33:04 +0200 | [diff] [blame] | 361 | binary of Marvell's A3720 sys-init, CZ.NIC's Armada 3720 Secure Firmware, TF-A and U-Boot) for |
| 362 | EspressoBin board (PLAT=a3700) with 1GHz CPU (CLOCKSPRESET=CPU_1000_DDR_800) and |
| 363 | 1GB DDR4 RAM (DDR_TOPOLOGY=5): |
Luka Kovacic | eb49835 | 2021-01-14 14:25:15 +0100 | [diff] [blame] | 364 | |
| 365 | .. code:: shell |
| 366 | |
Pali Rohár | 2c6e0a8 | 2021-04-08 10:33:04 +0200 | [diff] [blame] | 367 | > git clone https://git.trustedfirmware.org/TF-A/trusted-firmware-a.git |
| 368 | > git clone https://source.denx.de/u-boot/u-boot.git |
Pali Rohár | 0c0d265 | 2021-02-01 12:32:36 +0100 | [diff] [blame] | 369 | > git clone https://github.com/weidai11/cryptopp.git |
Pali Rohár | 2c6e0a8 | 2021-04-08 10:33:04 +0200 | [diff] [blame] | 370 | > git clone https://github.com/MarvellEmbeddedProcessors/mv-ddr-marvell.git |
| 371 | > git clone https://github.com/MarvellEmbeddedProcessors/A3700-utils-marvell.git |
| 372 | > git clone https://gitlab.nic.cz/turris/mox-boot-builder.git |
Pali Rohár | 0c0d265 | 2021-02-01 12:32:36 +0100 | [diff] [blame] | 373 | > make -C u-boot CROSS_COMPILE=aarch64-linux-gnu- mvebu_espressobin-88f3720_defconfig u-boot.bin |
Pali Rohár | 2c6e0a8 | 2021-04-08 10:33:04 +0200 | [diff] [blame] | 374 | > make -C mox-boot-builder CROSS_CM3=arm-linux-gnueabi- wtmi_app.bin |
Pali Rohár | 0c0d265 | 2021-02-01 12:32:36 +0100 | [diff] [blame] | 375 | > make -C trusted-firmware-a CROSS_COMPILE=aarch64-linux-gnu- CROSS_CM3=arm-linux-gnueabi- \ |
| 376 | USE_COHERENT_MEM=0 PLAT=a3700 CLOCKSPRESET=CPU_1000_DDR_800 DDR_TOPOLOGY=5 \ |
Pali Rohár | 2c6e0a8 | 2021-04-08 10:33:04 +0200 | [diff] [blame] | 377 | MV_DDR_PATH=$PWD/mv-ddr-marvell/ WTP=$PWD/A3700-utils-marvell/ \ |
| 378 | CRYPTOPP_PATH=$PWD/cryptopp/ BL33=$PWD/u-boot/u-boot.bin \ |
| 379 | WTMI_IMG=$PWD/mox-boot-builder/wtmi_app.bin FIP_ALIGN=0x100 mrvl_flash |
Luka Kovacic | eb49835 | 2021-01-14 14:25:15 +0100 | [diff] [blame] | 380 | |
Pali Rohár | 0c0d265 | 2021-02-01 12:32:36 +0100 | [diff] [blame] | 381 | Produced Marvell firmware flash image: ``trusted-firmware-a/build/a3700/release/flash-image.bin`` |
Paul Beesley | 9774302 | 2019-07-12 11:37:07 +0100 | [diff] [blame] | 382 | |
| 383 | Special Build Flags |
| 384 | -------------------- |
| 385 | |
| 386 | - PLAT_RECOVERY_IMAGE_ENABLE |
| 387 | When set this option to enable secondary recovery function when build atf. |
| 388 | In order to build UART recovery image this operation should be disabled for |
Konstantin Porotchkin | efcc41e | 2019-02-19 10:40:33 +0200 | [diff] [blame] | 389 | A7K/8K/CN913x because of hardware limitation (boot from secondary image |
Paul Beesley | 9774302 | 2019-07-12 11:37:07 +0100 | [diff] [blame] | 390 | can interrupt UART recovery process). This MACRO definition is set in |
Grzegorz Jaszczyk | 3039bce | 2019-11-05 13:14:59 +0100 | [diff] [blame] | 391 | ``plat/marvell/armada/a8k/common/include/platform_def.h`` file. |
Paul Beesley | 9774302 | 2019-07-12 11:37:07 +0100 | [diff] [blame] | 392 | |
Alex Leibovich | ed2fb47 | 2019-02-25 12:24:29 +0200 | [diff] [blame] | 393 | - DDR32 |
| 394 | In order to work in 32bit DDR, instead of the default 64bit ECC DDR, |
| 395 | this flag should be set to 1. |
| 396 | |
Paul Beesley | d2fcc4e | 2019-05-29 13:59:40 +0100 | [diff] [blame] | 397 | For more information about build options, please refer to the |
| 398 | :ref:`Build Options` document. |
Paul Beesley | 9774302 | 2019-07-12 11:37:07 +0100 | [diff] [blame] | 399 | |
| 400 | |
| 401 | Build output |
| 402 | ------------ |
Pali Rohár | 8dc46a0 | 2020-10-29 17:44:27 +0100 | [diff] [blame] | 403 | Marvell's TF-A compilation generates 8 files: |
Paul Beesley | 9774302 | 2019-07-12 11:37:07 +0100 | [diff] [blame] | 404 | |
Pali Rohár | e4bfc0a | 2021-02-01 12:25:46 +0100 | [diff] [blame] | 405 | - ble.bin - BLe image (not available for Armada37x0) |
Paul Beesley | 9774302 | 2019-07-12 11:37:07 +0100 | [diff] [blame] | 406 | - bl1.bin - BL1 image |
| 407 | - bl2.bin - BL2 image |
| 408 | - bl31.bin - BL31 image |
| 409 | - fip.bin - FIP image (contains BL2, BL31 & BL33 (U-Boot) images) |
| 410 | - boot-image.bin - TF-A image (contains BL1 and FIP images) |
Pali Rohár | e4bfc0a | 2021-02-01 12:25:46 +0100 | [diff] [blame] | 411 | - flash-image.bin - Flashable Marvell firmware image. For Armada37x0 it |
| 412 | contains TIM, WTMI and boot-image.bin images. For other platforms it contains |
| 413 | BLe and boot-image.bin images. Should be placed on the boot flash/device. |
Pali Rohár | 8dc46a0 | 2020-10-29 17:44:27 +0100 | [diff] [blame] | 414 | - uart-images.tgz.bin - GZIPed TAR archive which contains Armada37x0 images |
| 415 | for booting via UART. Could be loaded via Marvell's WtpDownload tool from |
| 416 | A3700-utils-marvell repository. |
Paul Beesley | 9774302 | 2019-07-12 11:37:07 +0100 | [diff] [blame] | 417 | |
Pali Rohár | 9e737b6 | 2021-01-26 10:44:07 +0100 | [diff] [blame] | 418 | Additional make target ``mrvl_bootimage`` produce ``boot-image.bin`` file. Target |
| 419 | ``mrvl_flash`` produce final ``flash-image.bin`` file and target ``mrvl_uart`` |
| 420 | produce ``uart-images.tgz.bin`` file. |
Pali Rohár | 8dc46a0 | 2020-10-29 17:44:27 +0100 | [diff] [blame] | 421 | |
Paul Beesley | 9774302 | 2019-07-12 11:37:07 +0100 | [diff] [blame] | 422 | |
| 423 | Tools and external components installation |
| 424 | ------------------------------------------ |
| 425 | |
Pali Rohár | 3278e7e | 2021-07-20 17:42:24 +0200 | [diff] [blame] | 426 | Armada37x0 Builds require installation of additional components |
| 427 | ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ |
Paul Beesley | 9774302 | 2019-07-12 11:37:07 +0100 | [diff] [blame] | 428 | |
| 429 | (1) ARM cross compiler capable of building images for the service CPU (CM3). |
| 430 | This component is usually included in the Linux host packages. |
| 431 | On Debian/Ubuntu hosts the default GNU ARM tool chain can be installed |
| 432 | using the following command |
| 433 | |
| 434 | .. code:: shell |
| 435 | |
| 436 | > sudo apt-get install gcc-arm-linux-gnueabi |
| 437 | |
| 438 | Only if required, the default tool chain prefix ``arm-linux-gnueabi-`` can be |
| 439 | overwritten using the environment variable ``CROSS_CM3``. |
| 440 | Example for BASH shell |
| 441 | |
| 442 | .. code:: shell |
| 443 | |
| 444 | > export CROSS_CM3=/opt/arm-cross/bin/arm-linux-gnueabi |
| 445 | |
| 446 | (2) DDR initialization library sources (mv_ddr) available at the following repository |
Pali Rohár | eaeb527 | 2021-01-26 10:44:07 +0100 | [diff] [blame] | 447 | (use the "master" branch): |
Paul Beesley | 9774302 | 2019-07-12 11:37:07 +0100 | [diff] [blame] | 448 | |
| 449 | https://github.com/MarvellEmbeddedProcessors/mv-ddr-marvell.git |
| 450 | |
Pali Rohár | 65c8d11 | 2020-10-07 11:01:00 +0200 | [diff] [blame] | 451 | (3) Armada3700 tools available at the following repository |
Pali Rohár | eaeb527 | 2021-01-26 10:44:07 +0100 | [diff] [blame] | 452 | (use the "master" branch): |
Paul Beesley | 9774302 | 2019-07-12 11:37:07 +0100 | [diff] [blame] | 453 | |
| 454 | https://github.com/MarvellEmbeddedProcessors/A3700-utils-marvell.git |
| 455 | |
Pali Rohár | 8dc46a0 | 2020-10-29 17:44:27 +0100 | [diff] [blame] | 456 | (4) Crypto++ library available at the following repository: |
| 457 | |
| 458 | https://github.com/weidai11/cryptopp.git |
| 459 | |
Pali Rohár | 3278e7e | 2021-07-20 17:42:24 +0200 | [diff] [blame] | 460 | (5) Optional CZ.NIC's Armada 3720 Secure Firmware: |
| 461 | |
| 462 | https://gitlab.nic.cz/turris/mox-boot-builder.git |
| 463 | |
Pali Rohár | 6a194cc | 2021-08-20 14:35:08 +0200 | [diff] [blame] | 464 | Armada70x0, Armada80x0 and CN913x Builds require installation of additional components |
| 465 | ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ |
Paul Beesley | 9774302 | 2019-07-12 11:37:07 +0100 | [diff] [blame] | 466 | |
| 467 | (1) DDR initialization library sources (mv_ddr) available at the following repository |
Pali Rohár | eaeb527 | 2021-01-26 10:44:07 +0100 | [diff] [blame] | 468 | (use the "master" branch): |
Paul Beesley | 9774302 | 2019-07-12 11:37:07 +0100 | [diff] [blame] | 469 | |
| 470 | https://github.com/MarvellEmbeddedProcessors/mv-ddr-marvell.git |
Pali Rohár | 6a194cc | 2021-08-20 14:35:08 +0200 | [diff] [blame] | 471 | |
| 472 | (2) MSS Management SubSystem Firmware available at the following repository |
| 473 | (use the "binaries-marvell-armada-SDK10.0.1.0" branch): |
| 474 | |
| 475 | https://github.com/MarvellEmbeddedProcessors/binaries-marvell.git |