[][openwrt][mt7988][image][Add hkdf to mt7988.mk]
[Description]
Add hkdf to mt7988.mk to generate kdf key for firmware encryption.
[Release-log]
N/A
Change-Id: I86dde63b632fa26f235d8a5b92fd5ad4577a28da
Reviewed-on: https://gerrit.mediatek.inc/c/openwrt/feeds/mtk_openwrt_feeds/+/8106486
diff --git a/target/linux/mediatek/image/mt7988.mk b/target/linux/mediatek/image/mt7988.mk
index e01ac40..a02d00e 100644
--- a/target/linux/mediatek/image/mt7988.mk
+++ b/target/linux/mediatek/image/mt7988.mk
@@ -34,19 +34,23 @@
IMAGE/sysupgrade.bin := sysupgrade-tar rootfs=$$$$(IMAGE_ROOTFS)-hashed-$$(firstword $$(DEVICE_DTS)) | \
append-metadata
FIT_KEY_DIR := $(TOPDIR)/../../keys
+ ROE_KEY_DIR := $(TOPDIR)/../../keys
FIT_KEY_NAME := fit_key
+ ROE_KEY_NAME := roe_key
+ FIRMWARE_ENC_ALGO := tee_aes256
ANTI_ROLLBACK_TABLE := $(TOPDIR)/../../fw_ar_table.xml
AUTO_AR_CONF := $(TOPDIR)/../../auto_ar_conf.mk
HASHED_BOOT_DEVICE := 253:0
BASIC_KERNEL_CMDLINE := console=ttyS0,115200n1 rootfstype=squashfs loglevel=8
KERNEL = append-opteenode $$(KDIR)/image-$$(firstword $$(DEVICE_DTS)).dtb | \
- kernel-bin | lzma | squashfs-hashed | fw-ar-ver | \
+ kernel-bin | lzma | squashfs-hashed | fw-ar-ver | hkdf | \
fit-sign lzma $$(KDIR)/image-sb-$$(firstword $$(DEVICE_DTS)).dtb
KERNEL_INITRAMFS =
endef
TARGET_DEVICES += mediatek_mt7988a-gsw-10g-spim-nand-sb
DEFAULT_DEVICE_VARS += FIT_KEY_DIR FIT_KEY_NAME ANTI_ROLLBACK_TABLE \
- AUTO_AR_CONF HASHED_BOOT_DEVICE BASIC_KERNEL_CMDLINE
+ AUTO_AR_CONF HASHED_BOOT_DEVICE BASIC_KERNEL_CMDLINE ROE_KEY_DIR \
+ ROE_KEY_NAME FIRMWARE_ENC_ALGO
define Device/mediatek_mt7988a-dsa-10g-emmc-sb
DEVICE_VENDOR := MediaTek