blob: be00d79fb03b4e52631c11d138016cde09f7fc27 [file] [log] [blame]
Lokesh Vutlabc5bd3a2018-08-27 15:57:15 +05301# SPDX-License-Identifier: GPL-2.0+
2#
3# Copyright (C) 2017-2018 Texas Instruments Incorporated - http://www.ti.com/
4# Lokesh Vutla <lokeshvutla@ti.com>
5
6ifdef CONFIG_SPL_BUILD
7
Lokesh Vutla6b6a3942018-11-02 19:51:04 +05308# Openssl is required to generate x509 certificate.
9# Error out if openssl is not available.
10ifeq ($(shell which openssl),)
11$(error "No openssl in $(PATH), consider installing openssl")
12endif
13
14SHA_VALUE= $(shell openssl dgst -sha512 -hex $(obj)/u-boot-spl.bin | sed -e "s/^.*= //g")
15IMAGE_SIZE= $(shell cat $(obj)/u-boot-spl.bin | wc -c)
16LOADADDR= $(shell echo $(CONFIG_SPL_TEXT_BASE) | sed -e "s/^0x//g")
17MAX_SIZE= $(shell printf "%d" $(CONFIG_SYS_K3_MAX_DOWNLODABLE_IMAGE_SIZE))
18
19# Parameters to get populated into the x509 template
20SED_OPTS= -e s/TEST_IMAGE_LENGTH/$(IMAGE_SIZE)/
21SED_OPTS+= -e s/TEST_IMAGE_SHA_VAL/$(SHA_VALUE)/
22SED_OPTS+= -e s/TEST_CERT_TYPE/1/ # CERT_TYPE_PRIMARY_IMAGE_BIN
23SED_OPTS+= -e s/TEST_BOOT_CORE/$(CONFIG_SYS_K3_BOOT_CORE_ID)/
24SED_OPTS+= -e s/TEST_BOOT_ARCH_WIDTH/32/
25SED_OPTS+= -e s/TEST_BOOT_ADDR/$(LOADADDR)/
26
27# Command to generate ecparam key
28quiet_cmd_genkey = OPENSSL $@
29cmd_genkey = openssl ecparam -out $@ -name prime256v1 -genkey
30
31# Command to generate x509 certificate
32quiet_cmd_gencert = OPENSSL $@
33cmd_gencert = cat $(srctree)/tools/k3_x509template.txt | sed $(SED_OPTS) > u-boot-spl-x509.txt; \
34 openssl req -new -x509 -key $(KEY) -nodes -outform DER -out $@ -config u-boot-spl-x509.txt -sha512
35
36# If external key is not provided, generate key using openssl.
37ifeq ($(CONFIG_SYS_K3_KEY), "")
38KEY=u-boot-spl-eckey.pem
39else
Lokesh Vutlac39337c2018-12-19 12:53:31 +053040KEY=$(patsubst "%",$(srctree)/%,$(CONFIG_SYS_K3_KEY))
Lokesh Vutla6b6a3942018-11-02 19:51:04 +053041endif
42
43u-boot-spl-eckey.pem: FORCE
44 $(call if_changed,genkey)
45
46# tiboot3.bin is mandated by ROM and ROM only supports R5 boot.
47# So restrict tiboot3.bin creation for CPU_V7R.
48ifdef CONFIG_CPU_V7R
49u-boot-spl-cert.bin: $(KEY) $(obj)/u-boot-spl.bin image_check FORCE
50 $(call if_changed,gencert)
51
52image_check: $(obj)/u-boot-spl.bin FORCE
53 @if [ $(IMAGE_SIZE) -gt $(MAX_SIZE) ]; then \
54 echo "===============================================" >&2; \
55 echo "ERROR: Final Image too big. " >&2; \
56 echo "$< size = $(IMAGE_SIZE), max size = $(MAX_SIZE)" >&2; \
57 echo "===============================================" >&2; \
58 exit 1; \
59 fi
60
61tiboot3.bin: u-boot-spl-cert.bin $(obj)/u-boot-spl.bin FORCE
62 $(call if_changed,cat)
63
64ALL-y += tiboot3.bin
65endif
66
Lokesh Vutlabc5bd3a2018-08-27 15:57:15 +053067ifdef CONFIG_ARM64
68SPL_ITS := u-boot-spl-k3.its
69$(SPL_ITS): FORCE
70 $(srctree)/tools/k3_fit_atf.sh \
71 $(patsubst %,$(obj)/dts/%.dtb,$(subst ",,$(CONFIG_SPL_OF_LIST))) > $@
72
73ALL-y += tispl.bin
74endif
75
76else
77ALL-y += u-boot.img
78endif