blob: 40d323e0044c4c8fd4cc21bbcac85e1fdcfa175f [file] [log] [blame]
gaurav ranaf79323c2015-03-10 14:08:50 +05301/*
2 * Copyright 2015 Freescale Semiconductor, Inc.
3 *
4 * SPDX-License-Identifier: GPL-2.0+
5 */
6
Aneesh Bansal43104702016-01-22 16:37:24 +05307#ifndef __CONFIG_FSL_CHAIN_TRUST_H
8#define __CONFIG_FSL_CHAIN_TRUST_H
gaurav ranaf79323c2015-03-10 14:08:50 +05309
Aneesh Bansal43104702016-01-22 16:37:24 +053010/* For secure boot, since ENVIRONMENT in flash/external memories is
11 * not verified, undef CONFIG_ENV_xxx and set default env
12 * (CONFIG_ENV_IS_NOWHERE)
13 */
gaurav ranaf79323c2015-03-10 14:08:50 +053014#ifdef CONFIG_SECURE_BOOT
15
Aneesh Bansal43104702016-01-22 16:37:24 +053016#undef CONFIG_ENV_IS_IN_EEPROM
17#undef CONFIG_ENV_IS_IN_NAND
18#undef CONFIG_ENV_IS_IN_MMC
19#undef CONFIG_ENV_IS_IN_SPI_FLASH
20#undef CONFIG_ENV_IS_IN_FLASH
21
22#define CONFIG_ENV_IS_NOWHERE
23
gaurav ranaf79323c2015-03-10 14:08:50 +053024#endif
25
Aneesh Bansal43104702016-01-22 16:37:24 +053026#ifdef CONFIG_CHAIN_OF_TRUST
27
gaurav ranaf79323c2015-03-10 14:08:50 +053028#ifndef CONFIG_EXTRA_ENV
29#define CONFIG_EXTRA_ENV ""
30#endif
31
32/*
33 * Control should not reach back to uboot after validation of images
34 * for secure boot flow and therefore bootscript should have
35 * the bootm command. If control reaches back to uboot anyhow
36 * after validating images, core should just spin.
37 */
38
39/*
40 * Define the key hash for boot script here if public/private key pair used to
41 * sign bootscript are different from the SRK hash put in the fuse
42 * Example of defining KEY_HASH is
43 * #define CONFIG_BOOTSCRIPT_KEY_HASH \
44 * "41066b564c6ffcef40ccbc1e0a5d0d519604000c785d97bbefd25e4d288d1c8b"
45 */
46
Saksham Jain25484692016-03-23 16:24:43 +053047#ifdef CONFIG_BOOTARGS
48#define CONFIG_SET_BOOTARGS "setenv bootargs \'" CONFIG_BOOTARGS" \';"
49#else
50#define CONFIG_SET_BOOTARGS "setenv bootargs \'root=/dev/ram " \
51 "rw console=ttyS0,115200 ramdisk_size=600000\';"
52#endif
53
54
gaurav ranaf79323c2015-03-10 14:08:50 +053055#ifdef CONFIG_BOOTSCRIPT_KEY_HASH
56#define CONFIG_SECBOOT \
57 "setenv bs_hdraddr " __stringify(CONFIG_BOOTSCRIPT_HDR_ADDR)";" \
Saksham Jain25484692016-03-23 16:24:43 +053058 CONFIG_SET_BOOTARGS \
gaurav ranaf79323c2015-03-10 14:08:50 +053059 CONFIG_EXTRA_ENV \
60 "esbc_validate $bs_hdraddr " \
61 __stringify(CONFIG_BOOTSCRIPT_KEY_HASH)";" \
62 "source $img_addr;" \
63 "esbc_halt\0"
64#else
65#define CONFIG_SECBOOT \
66 "setenv bs_hdraddr " __stringify(CONFIG_BOOTSCRIPT_HDR_ADDR)";" \
Saksham Jain25484692016-03-23 16:24:43 +053067 CONFIG_SET_BOOTARGS \
gaurav ranaf79323c2015-03-10 14:08:50 +053068 CONFIG_EXTRA_ENV \
69 "esbc_validate $bs_hdraddr;" \
70 "source $img_addr;" \
71 "esbc_halt\0"
72#endif
73
Aneesh Bansalb69061d2015-06-16 10:36:43 +053074#ifdef CONFIG_BOOTSCRIPT_COPY_RAM
75#define CONFIG_BS_COPY_ENV \
76 "setenv bs_hdr_ram " __stringify(CONFIG_BS_HDR_ADDR_RAM)";" \
Sumit Garg45642832016-06-14 13:52:39 -040077 "setenv bs_hdr_device " __stringify(CONFIG_BS_HDR_ADDR_DEVICE)";" \
Aneesh Bansalb69061d2015-06-16 10:36:43 +053078 "setenv bs_hdr_size " __stringify(CONFIG_BS_HDR_SIZE)";" \
79 "setenv bs_ram " __stringify(CONFIG_BS_ADDR_RAM)";" \
Sumit Garg45642832016-06-14 13:52:39 -040080 "setenv bs_device " __stringify(CONFIG_BS_ADDR_DEVICE)";" \
Aneesh Bansalb69061d2015-06-16 10:36:43 +053081 "setenv bs_size " __stringify(CONFIG_BS_SIZE)";"
82
Saksham Jain503eab92016-03-23 16:24:37 +053083/* For secure boot flow, default environment used will be used */
Ruchika Guptaba688752017-04-17 18:07:18 +053084#if defined(CONFIG_SYS_RAMBOOT) || defined(CONFIG_NAND_BOOT) || \
85 defined(CONFIG_SD_BOOT)
86#if defined(CONFIG_RAMBOOT_NAND) || defined(CONFIG_NAND_BOOT)
Aneesh Bansalb69061d2015-06-16 10:36:43 +053087#define CONFIG_BS_COPY_CMD \
Sumit Garg45642832016-06-14 13:52:39 -040088 "nand read $bs_hdr_ram $bs_hdr_device $bs_hdr_size ;" \
89 "nand read $bs_ram $bs_device $bs_size ;"
Sumit Garg45642832016-06-14 13:52:39 -040090#elif defined(CONFIG_SD_BOOT)
91#define CONFIG_BS_COPY_CMD \
92 "mmc read $bs_hdr_ram $bs_hdr_device $bs_hdr_size ;" \
93 "mmc read $bs_ram $bs_device $bs_size ;"
Ruchika Guptaba688752017-04-17 18:07:18 +053094#endif
95#else
Saksham Jain503eab92016-03-23 16:24:37 +053096#define CONFIG_BS_COPY_CMD \
Sumit Garg45642832016-06-14 13:52:39 -040097 "cp.b $bs_hdr_device $bs_hdr_ram $bs_hdr_size ;" \
98 "cp.b $bs_device $bs_ram $bs_size ;"
gaurav ranaf79323c2015-03-10 14:08:50 +053099#endif
Saksham Jain503eab92016-03-23 16:24:37 +0530100#endif /* CONFIG_BOOTSCRIPT_COPY_RAM */
gaurav ranaf79323c2015-03-10 14:08:50 +0530101
Aneesh Bansalb69061d2015-06-16 10:36:43 +0530102#ifndef CONFIG_BS_COPY_ENV
103#define CONFIG_BS_COPY_ENV
104#endif
105
106#ifndef CONFIG_BS_COPY_CMD
107#define CONFIG_BS_COPY_CMD
108#endif
109
Aneesh Bansal43104702016-01-22 16:37:24 +0530110#define CONFIG_CHAIN_BOOT_CMD CONFIG_BS_COPY_ENV \
Aneesh Bansalb69061d2015-06-16 10:36:43 +0530111 CONFIG_BS_COPY_CMD \
112 CONFIG_SECBOOT
gaurav ranaf79323c2015-03-10 14:08:50 +0530113
114#endif
115#endif