[U-Boot] [REGRESSION] commit e04916a "SECURE_BOOT : enable esbc_validate..." breaks MX6

Tom Rini trini at konsulko.com
Thu Apr 2 22:18:37 CEST 2015


On Thu, Apr 02, 2015 at 10:19:11AM -0600, Ulises Cardenas wrote:
> Hi,
> The aforementioned commit e04916a721a2069fc770412c57974d02e153ad18, causes MX6 boards to break
> 
> Configuring CONFIG_SECURE_BOOT makes the u-boot build fail for any MX6 board. This was reproduced in mx6dl, mx6q and mx6sx. The log for the mx6q build is:
> 
> ==============
> In file included from /home/ulises/Security/u-boot-imx/include/fsl_validate.h:11:0,
>                  from /home/ulises/Security/u-boot-imx/board/freescale/common/fsl_validate.c:8:
> /home/ulises/Security/u-boot-imx/include/fsl_sec_mon.h:27:2: error: #error Neither CONFIG_SYS_FSL_SEC_MON_LE nor CONFIG_SYS_FSL_SEC_MON_BE defined
>  #error Neither CONFIG_SYS_FSL_SEC_MON_LE nor CONFIG_SYS_FSL_SEC_MON_BE defined
>   ^
> In file included from /home/ulises/Security/u-boot-imx/board/freescale/common/fsl_validate.c:10:0:
> /home/ulises/Security/u-boot-imx/include/fsl_sfp.h:29:2: error: #error Neither CONFIG_SYS_FSL_SFP_LE nor CONFIG_SYS_FSL_SFP_BE is defined
>  #error Neither CONFIG_SYS_FSL_SFP_LE nor CONFIG_SYS_FSL_SFP_BE is defined
>   ^
> /home/ulises/Security/u-boot-imx/board/freescale/common/fsl_validate.c:19:36: fatal error: asm/arch/immap_ls102xa.h: No such file or directory
>  #include <asm/arch/immap_ls102xa.h>
>                                     ^
> compilation terminated.
>   AS      arch/arm/lib/vectors.o
> /home/ulises/Security/u-boot-imx/scripts/Makefile.build:276: recipe for target 'board/freescale/common/fsl_validate.o' failed
> make[2]: *** [board/freescale/common/fsl_validate.o] Error 1
> /home/ulises/Security/u-boot-imx/Makefile:1112: recipe for target 'board/freescale/common' failed
> make[1]: *** [board/freescale/common] Error 2
> make[1]: *** Waiting for unfinished jobs....
> ==========
> 
> If I revert the commit, the build successfully builds and the I am able to boot the boards on secure mode.

Well, lets start with seeing which one of those needs to be set as well
for secure boot to continue to work.  From there we can find a good spot
to whack that default in.

-- 
> 
> Thanks,
> Ulises
> 
> _______________________________________________
> U-Boot mailing list
> U-Boot at lists.denx.de
> http://lists.denx.de/mailman/listinfo/u-boot

-- 
Tom
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 836 bytes
Desc: Digital signature
URL: <http://lists.denx.de/pipermail/u-boot/attachments/20150402/9f06c38f/attachment.sig>


More information about the U-Boot mailing list