mail archive of the barebox mailing list
 help / color / mirror / Atom feed
* [PATCH 0/3] Add generic OP-TEE loading for i.MX6
@ 2025-12-08  9:28 Fabian Pflug
  2025-12-08  9:28 ` [PATCH 1/3] ARM: make arm_mem_scratch respect the OP-TEE stack Fabian Pflug
                   ` (2 more replies)
  0 siblings, 3 replies; 9+ messages in thread
From: Fabian Pflug @ 2025-12-08  9:28 UTC (permalink / raw)
  To: BAREBOX; +Cc: Fabian Pflug

Add a generic way to load OP-TEE from i.MX6 CPU's with config options
instead of board and low level code.

This is build upon the work of Marco for i.MX8M.

Signed-off-by: Fabian Pflug <f.pflug@pengutronix.de>
---
Fabian Pflug (3):
      ARM: make arm_mem_scratch respect the OP-TEE stack
      ARM: i.MX: scratch: add generic init for imx
      ARM: i.MX6: load optee in PBL before barebox proper

 arch/arm/include/asm/barebox-arm.h |  2 +-
 arch/arm/mach-imx/Kconfig          |  2 +-
 arch/arm/mach-imx/esdctl.c         | 49 +++++++++++++++++++++++++++++++++++---
 arch/arm/mach-imx/scratch.c        | 18 +++++++-------
 common/Kconfig                     |  1 +
 firmware/Kconfig                   |  8 +++++++
 firmware/Makefile                  |  1 +
 include/mach/imx/scratch.h         |  1 +
 include/tee/optee.h                |  9 ++++++-
 9 files changed, 76 insertions(+), 15 deletions(-)
---
base-commit: adf5ebc913ae657d29faa2eff4d91e4230da8290
change-id: 20251205-v2025-11-0-topic-optee-imx6-start-c6aec57d1a13
prerequisite-change-id: 20251110-v2025-09-0-topic-optee-of-handling-e9f51531c464:v1
prerequisite-patch-id: a9d242490e6b89fad3f7479575b66a5a2dbc2529
prerequisite-patch-id: a1436008413ee47f88ca724b5624935fa14b0e0b
prerequisite-patch-id: 8b59da44ed6ff90982f13979feac4a0e036a8c0e
prerequisite-patch-id: 4b1f8dd05b5a6974b728e457646d41f5f20023e7
prerequisite-patch-id: f426a6784461579368b2cd0142a357664038705c
prerequisite-patch-id: 35e792c79c983d2b21fce6d423aca326f9667a6d
prerequisite-patch-id: e9d8948b45921666d931253bfed355de5ac54c0f
prerequisite-patch-id: 810625536dd1a8c92c393384950c16a5f7590d6d
prerequisite-patch-id: 5e40ae531579bdaea7a9a30f3da5dc24855166c8
prerequisite-patch-id: d1881ceddf54a2ba8227afd366493dd582be56da
prerequisite-patch-id: 3e1fa756532433c41f45ab0faaf16d0930e4c060
prerequisite-patch-id: a6b464e45b729c5050b6a666708f956af926d086
prerequisite-patch-id: a688b082e9dc5ec1d3dc57e34f0aa615349dc661
prerequisite-patch-id: 93a2db629bee13ae25c6c3e75e53652826eb1ad0
prerequisite-patch-id: 794b3b4488859497b5aadc8b6df27beecbf69f6d
prerequisite-patch-id: 8ded8fd093a4f2bbcfc8a09b028c8ce6ee6f48ae
prerequisite-patch-id: ce9866af93b0bccbe707531397eb949956f936f4
prerequisite-patch-id: fd487c8e4e41c105a5ea928c484f3a819eb25101
prerequisite-patch-id: ec605c8fffc2c54e4ec9989aa50d4761d5eebc95
prerequisite-patch-id: 9142d258abe17c510cc2e608939cdc08880ec54a
prerequisite-patch-id: d7489c3dd4dabbf0988a16bd7cbcd8a7d872713e
prerequisite-patch-id: f852d62d4fae1cab4a86157d797429ccefd18f5a
prerequisite-patch-id: 05f9029826c5329c88ce39d45c725718cda4c93a

Best regards,
-- 
Fabian Pflug <f.pflug@pengutronix.de>




^ permalink raw reply	[flat|nested] 9+ messages in thread

* [PATCH 1/3] ARM: make arm_mem_scratch respect the OP-TEE stack
  2025-12-08  9:28 [PATCH 0/3] Add generic OP-TEE loading for i.MX6 Fabian Pflug
@ 2025-12-08  9:28 ` Fabian Pflug
  2025-12-10  7:18   ` Sascha Hauer
  2025-12-08  9:28 ` [PATCH 2/3] ARM: i.MX: scratch: add generic init for imx Fabian Pflug
  2025-12-08  9:28 ` [PATCH 3/3] ARM: i.MX6: load optee in PBL before barebox proper Fabian Pflug
  2 siblings, 1 reply; 9+ messages in thread
From: Fabian Pflug @ 2025-12-08  9:28 UTC (permalink / raw)
  To: BAREBOX; +Cc: Fabian Pflug

According to the ASCII-ART above, before the end of memory comes the
optee memory, then the scratch stack.

Signed-off-by: Fabian Pflug <f.pflug@pengutronix.de>
---
 arch/arm/include/asm/barebox-arm.h | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/arch/arm/include/asm/barebox-arm.h b/arch/arm/include/asm/barebox-arm.h
index 11be8b8583..e630969796 100644
--- a/arch/arm/include/asm/barebox-arm.h
+++ b/arch/arm/include/asm/barebox-arm.h
@@ -159,7 +159,7 @@ static inline unsigned long arm_mem_stack_top(unsigned long endmem)
 
 static inline const void *arm_mem_scratch_get(void)
 {
-	return (const void *)arm_mem_scratch(arm_mem_endmem_get());
+	return (const void *)arm_mem_scratch(arm_mem_optee(arm_mem_endmem_get()));
 }
 
 static inline unsigned long arm_mem_guard_page_get(void)

-- 
2.47.3




^ permalink raw reply	[flat|nested] 9+ messages in thread

* [PATCH 2/3] ARM: i.MX: scratch: add generic init for imx
  2025-12-08  9:28 [PATCH 0/3] Add generic OP-TEE loading for i.MX6 Fabian Pflug
  2025-12-08  9:28 ` [PATCH 1/3] ARM: make arm_mem_scratch respect the OP-TEE stack Fabian Pflug
@ 2025-12-08  9:28 ` Fabian Pflug
  2025-12-08  9:28 ` [PATCH 3/3] ARM: i.MX6: load optee in PBL before barebox proper Fabian Pflug
  2 siblings, 0 replies; 9+ messages in thread
From: Fabian Pflug @ 2025-12-08  9:28 UTC (permalink / raw)
  To: BAREBOX; +Cc: Fabian Pflug

The zero_init, memset and scratch assignment were the same, and will be
the same for i.MX6. Why not make it generic?

Signed-off-by: Fabian Pflug <f.pflug@pengutronix.de>
---
 arch/arm/mach-imx/Kconfig   |  2 +-
 arch/arm/mach-imx/scratch.c | 18 +++++++++---------
 include/mach/imx/scratch.h  |  1 +
 3 files changed, 11 insertions(+), 10 deletions(-)

diff --git a/arch/arm/mach-imx/Kconfig b/arch/arm/mach-imx/Kconfig
index 99b6c51333..208e6488bd 100644
--- a/arch/arm/mach-imx/Kconfig
+++ b/arch/arm/mach-imx/Kconfig
@@ -57,7 +57,7 @@ config ARCH_IMX_ROMAPI
 
 config ARCH_IMX_SCRATCHMEM
 	def_bool y
-	depends on ARCH_IMX8M || ARCH_IMX9
+	depends on ARCH_IMX6 || ARCH_IMX8M || ARCH_IMX9
 
 config ARCH_IMX_TZASC
 	bool
diff --git a/arch/arm/mach-imx/scratch.c b/arch/arm/mach-imx/scratch.c
index 393d3a976f..f26038b029 100644
--- a/arch/arm/mach-imx/scratch.c
+++ b/arch/arm/mach-imx/scratch.c
@@ -24,25 +24,25 @@ static_assert(sizeof(struct imx_scratch_space) <= CONFIG_SCRATCH_SIZE);
 
 static struct imx_scratch_space *scratch;
 
-void imx8m_init_scratch_space(int ddr_buswidth, bool zero_init)
+void imx_init_scratch_space(ulong endmem, bool zero_init)
 {
-	ulong endmem = MX8M_DDR_CSD1_BASE_ADDR +
-		imx8m_barebox_earlymem_size(ddr_buswidth);
-
 	scratch = (void *)arm_mem_scratch(endmem);
 
 	if (zero_init)
 		memset(scratch, 0, sizeof(*scratch));
 }
 
+void imx8m_init_scratch_space(int ddr_buswidth, bool zero_init)
+{
+	ulong endmem = MX8M_DDR_CSD1_BASE_ADDR +
+		imx8m_barebox_earlymem_size(ddr_buswidth);
+	imx_init_scratch_space(endmem, zero_init);
+}
+
 void imx93_init_scratch_space(bool zero_init)
 {
 	ulong endmem = MX9_DDR_CSD1_BASE_ADDR + imx9_ddrc_sdram_size();
-
-	scratch = (void *)arm_mem_scratch(endmem);
-
-	if (zero_init)
-		memset(scratch, 0, sizeof(*scratch));
+	imx_init_scratch_space(endmem, zero_init);
 }
 
 void imx8m_scratch_save_bootrom_log(const u32 *rom_log)
diff --git a/include/mach/imx/scratch.h b/include/mach/imx/scratch.h
index a9745a9573..a86f5ca38a 100644
--- a/include/mach/imx/scratch.h
+++ b/include/mach/imx/scratch.h
@@ -3,6 +3,7 @@
 #ifndef __MACH_IMX_SCRATCH_H
 #define __MACH_IMX_SCRATCH_H
 
+void imx_init_scratch_space(ulong endmem, bool zero_init);
 void imx8m_init_scratch_space(int ddr_buswidth, bool zero_init);
 void imx93_init_scratch_space(bool zero_init);
 

-- 
2.47.3




^ permalink raw reply	[flat|nested] 9+ messages in thread

* [PATCH 3/3] ARM: i.MX6: load optee in PBL before barebox proper
  2025-12-08  9:28 [PATCH 0/3] Add generic OP-TEE loading for i.MX6 Fabian Pflug
  2025-12-08  9:28 ` [PATCH 1/3] ARM: make arm_mem_scratch respect the OP-TEE stack Fabian Pflug
  2025-12-08  9:28 ` [PATCH 2/3] ARM: i.MX: scratch: add generic init for imx Fabian Pflug
@ 2025-12-08  9:28 ` Fabian Pflug
  2025-12-10  7:40   ` Sascha Hauer
  2 siblings, 1 reply; 9+ messages in thread
From: Fabian Pflug @ 2025-12-08  9:28 UTC (permalink / raw)
  To: BAREBOX; +Cc: Fabian Pflug

This patch uses the space in the scratch memory to hand over to OP-TEE
for device-tree overlays. If OP-TEE is configured with CFG_DT_ADDR=,
then it will write its devicetree-overlay into the address and it will
be picked up and applied by barebox.

This allows for generic OP-TEE loading for i.MX6 devices without changes
to the board or lowlevel code.

Signed-off-by: Fabian Pflug <f.pflug@pengutronix.de>
---
 arch/arm/mach-imx/esdctl.c | 49 +++++++++++++++++++++++++++++++++++++++++++---
 common/Kconfig             |  1 +
 firmware/Kconfig           |  8 ++++++++
 firmware/Makefile          |  1 +
 include/tee/optee.h        |  9 ++++++++-
 5 files changed, 64 insertions(+), 4 deletions(-)

diff --git a/arch/arm/mach-imx/esdctl.c b/arch/arm/mach-imx/esdctl.c
index b9393fba4a..2434844c96 100644
--- a/arch/arm/mach-imx/esdctl.c
+++ b/arch/arm/mach-imx/esdctl.c
@@ -6,6 +6,7 @@
 #include <common.h>
 #include <io.h>
 #include <errno.h>
+#include <firmware.h>
 #include <linux/sizes.h>
 #include <init.h>
 #include <of.h>
@@ -30,6 +31,7 @@
 #include <mach/imx/imx7-regs.h>
 #include <mach/imx/imx9-regs.h>
 #include <mach/imx/scratch.h>
+#include <mach/imx/tzasc.h>
 #include <tee/optee.h>
 
 struct imx_esdctl_data {
@@ -976,18 +978,59 @@ void __noreturn imx53_barebox_entry(void *boarddata)
 static void __noreturn
 imx6_barebox_entry(unsigned long membase, void *boarddata)
 {
-	barebox_arm_entry(membase,
-			  imx6_mmdc_sdram_size(IOMEM(MX6_MMDC_P0_BASE_ADDR)),
-			  boarddata);
+	ulong memsize = imx6_mmdc_sdram_size(IOMEM(MX6_MMDC_P0_BASE_ADDR));
+
+	if (IS_ENABLED(CONFIG_FIRMWARE_IMX6_OPTEE) &&
+	    IS_ENABLED(CONFIG_PBL_OPTEE) && imx6_can_access_tzasc()) {
+		void *fdto;
+		unsigned int fdto_size;
+		int tee_size;
+		void *tee;
+
+		get_builtin_firmware(imx6_optee_bin, &tee, &tee_size);
+
+		ulong endmem = arm_mem_barebox_image_end(membase + memsize);
+		imx_init_scratch_space(endmem, 1);
+		imx_scratch_get_optee_fdto(&fdto, &fdto_size);
+		if (!fdto_size) {
+			pr_warn("No space configured for OP-TEE devicetree\n");
+			fdto = NULL;
+		}
+
+		start_optee_early(fdto, tee);
+		if (fdto_size)
+			handoff_data_add(HANDOFF_DATA_BL32_DT_OVL, fdto,
+					 fdto_size);
+	}
+
+	barebox_arm_entry(membase, memsize, boarddata);
 }
 
 void __noreturn imx6q_barebox_entry(void *boarddata)
 {
+	if (IS_ENABLED(CONFIG_FIRMWARE_IMX6_OPTEE) &&
+	    IS_ENABLED(CONFIG_PBL_OPTEE) && imx6_can_access_tzasc()) {
+		if (imx6q_tzc380_is_bypassed())
+			panic("TZC380 is bypassed, abort OP-TEE loading\n");
+
+		/* Add early non-secure TZASC region1 to pass DTO */
+		imx6q_tzc380_early_ns_region1();
+	}
+
 	imx6_barebox_entry(MX6_MMDC_PORT01_BASE_ADDR, boarddata);
 }
 
 void __noreturn imx6ul_barebox_entry(void *boarddata)
 {
+	if (IS_ENABLED(CONFIG_FIRMWARE_IMX6_OPTEE) &&
+	    IS_ENABLED(CONFIG_PBL_OPTEE) && imx6_can_access_tzasc()) {
+		if (imx6ul_tzc380_is_bypassed())
+			panic("TZC380 is bypassed, abort OP-TEE loading\n");
+
+		/* Add early non-secure TZASC region1 to pass DTO */
+		imx6ul_tzc380_early_ns_region1();
+	}
+
 	imx6_barebox_entry(MX6_MMDC_PORT0_BASE_ADDR, boarddata);
 }
 
diff --git a/common/Kconfig b/common/Kconfig
index c42dc88ccf..20012cdc2c 100644
--- a/common/Kconfig
+++ b/common/Kconfig
@@ -322,6 +322,7 @@ config SCRATCH_FDTO_SIZE
 	hex
 	default 0x0
 	default 0x4000 if PBL_EARLY_FDT_LOAD
+	default 0x4000 if FIRMWARE_IMX6_OPTEE
 	prompt "Scratch FDTO size"
 	help
 	  The size of possible FDT overlay areas used by BL3x binaries to store
diff --git a/firmware/Kconfig b/firmware/Kconfig
index a97a1e0dd3..3e4245989c 100644
--- a/firmware/Kconfig
+++ b/firmware/Kconfig
@@ -49,6 +49,14 @@ config FIRMWARE_IMX93_ATF
 config FIRMWARE_AGILEX5_ATF
 	bool
 
+config FIRMWARE_IMX6_OPTEE
+	bool "install OP-TEE on i.MX6 boards"
+	depends on PBL_OPTEE
+	help
+	  This enables OP-TEE loading and starting on i.MX6. Place the OP-TEE binary
+	  in CONFIG_EXTRA_FIRMWARE_DIR/imx6-optee.bin. If this is enabled, then
+	  the OP-TEE will automagically be loaded during boot.
+
 config FIRMWARE_IMX8MM_OPTEE
 	bool "install OP-TEE on i.MX8MM boards"
 	depends on FIRMWARE_IMX8MM_ATF && PBL_OPTEE
diff --git a/firmware/Makefile b/firmware/Makefile
index 163055554d..fef7b837d1 100644
--- a/firmware/Makefile
+++ b/firmware/Makefile
@@ -22,6 +22,7 @@ pbl-firmware-$(CONFIG_FIRMWARE_IMX8MP_ATF) += imx8mp-bl31.bin$(if $(CONFIG_FIRMW
 pbl-firmware-$(CONFIG_FIRMWARE_IMX8MQ_ATF) += imx8mq-bl31.bin
 pbl-firmware-$(CONFIG_FIRMWARE_IMX93_ATF) += imx93-bl31.bin$(if $(CONFIG_FIRMWARE_IMX93_OPTEE),-optee,)
 pbl-firmware-$(CONFIG_FIRMWARE_AGILEX5_ATF) += agilex5-bl31.bin
+pbl-firmware-$(CONFIG_FIRMWARE_IMX6_OPTEE) += imx6-optee.bin
 fw-external-$(CONFIG_FIRMWARE_IMX8MM_OPTEE) += imx8mm-bl32.bin
 fw-external-$(CONFIG_FIRMWARE_IMX8MN_OPTEE) += imx8mn-bl32.bin
 fw-external-$(CONFIG_FIRMWARE_IMX8MP_OPTEE) += imx8mp-bl32.bin
diff --git a/include/tee/optee.h b/include/tee/optee.h
index a3f1917f63..db8a87b8b9 100644
--- a/include/tee/optee.h
+++ b/include/tee/optee.h
@@ -70,12 +70,19 @@ static inline bool optee_overlay_applied(void)
 
 #ifdef __PBL__
 
-int start_optee_early(void* fdt, void* tee);
+int start_optee_early(void *fdt, void *tee);
 int imx6q_start_optee_early(void *fdt, void *tee, void *data_location,
 			    unsigned int data_location_size);
 int imx6ul_start_optee_early(void *fdt, void *tee, void *data_location,
 			     unsigned int data_location_size);
 
+#else
+
+static inline int start_optee_early(void *fdt, void *tee)
+{
+	return -ENOSYS;
+}
+
 #endif /* __PBL__ */
 
 struct device_node;

-- 
2.47.3




^ permalink raw reply	[flat|nested] 9+ messages in thread

* Re: [PATCH 1/3] ARM: make arm_mem_scratch respect the OP-TEE stack
  2025-12-08  9:28 ` [PATCH 1/3] ARM: make arm_mem_scratch respect the OP-TEE stack Fabian Pflug
@ 2025-12-10  7:18   ` Sascha Hauer
  2025-12-10  9:32     ` Fabian Pflug
  0 siblings, 1 reply; 9+ messages in thread
From: Sascha Hauer @ 2025-12-10  7:18 UTC (permalink / raw)
  To: Fabian Pflug; +Cc: BAREBOX

Hi Fabian,

On Mon, Dec 08, 2025 at 10:28:38AM +0100, Fabian Pflug wrote:
> According to the ASCII-ART above, before the end of memory comes the
> optee memory, then the scratch stack.
> 
> Signed-off-by: Fabian Pflug <f.pflug@pengutronix.de>
> ---
>  arch/arm/include/asm/barebox-arm.h | 2 +-
>  1 file changed, 1 insertion(+), 1 deletion(-)
> 
> diff --git a/arch/arm/include/asm/barebox-arm.h b/arch/arm/include/asm/barebox-arm.h
> index 11be8b8583..e630969796 100644
> --- a/arch/arm/include/asm/barebox-arm.h
> +++ b/arch/arm/include/asm/barebox-arm.h
> @@ -159,7 +159,7 @@ static inline unsigned long arm_mem_stack_top(unsigned long endmem)
>  
>  static inline const void *arm_mem_scratch_get(void)
>  {
> -	return (const void *)arm_mem_scratch(arm_mem_endmem_get());
> +	return (const void *)arm_mem_scratch(arm_mem_optee(arm_mem_endmem_get()));

arm_mem_scratch() is:

static inline unsigned long arm_mem_scratch(unsigned long endmem)
{
	return arm_mem_optee(endmem) - SCRATCH_SIZE;
}

So this already has the OPTEE space substracted. With your patch it's
substracted twice.

Sascha

-- 
Pengutronix e.K.                           |                             |
Steuerwalder Str. 21                       | http://www.pengutronix.de/  |
31137 Hildesheim, Germany                  | Phone: +49-5121-206917-0    |
Amtsgericht Hildesheim, HRA 2686           | Fax:   +49-5121-206917-5555 |



^ permalink raw reply	[flat|nested] 9+ messages in thread

* Re: [PATCH 3/3] ARM: i.MX6: load optee in PBL before barebox proper
  2025-12-08  9:28 ` [PATCH 3/3] ARM: i.MX6: load optee in PBL before barebox proper Fabian Pflug
@ 2025-12-10  7:40   ` Sascha Hauer
  2025-12-10  9:20     ` Fabian Pflug
  0 siblings, 1 reply; 9+ messages in thread
From: Sascha Hauer @ 2025-12-10  7:40 UTC (permalink / raw)
  To: Fabian Pflug; +Cc: BAREBOX

On Mon, Dec 08, 2025 at 10:28:40AM +0100, Fabian Pflug wrote:
> This patch uses the space in the scratch memory to hand over to OP-TEE
> for device-tree overlays. If OP-TEE is configured with CFG_DT_ADDR=,
> then it will write its devicetree-overlay into the address and it will
> be picked up and applied by barebox.
> 
> This allows for generic OP-TEE loading for i.MX6 devices without changes
> to the board or lowlevel code.
> 
> Signed-off-by: Fabian Pflug <f.pflug@pengutronix.de>
> ---
>  arch/arm/mach-imx/esdctl.c | 49 +++++++++++++++++++++++++++++++++++++++++++---
>  common/Kconfig             |  1 +
>  firmware/Kconfig           |  8 ++++++++
>  firmware/Makefile          |  1 +
>  include/tee/optee.h        |  9 ++++++++-
>  5 files changed, 64 insertions(+), 4 deletions(-)
> 
> diff --git a/arch/arm/mach-imx/esdctl.c b/arch/arm/mach-imx/esdctl.c
> index b9393fba4a..2434844c96 100644
> --- a/arch/arm/mach-imx/esdctl.c
> +++ b/arch/arm/mach-imx/esdctl.c
> @@ -6,6 +6,7 @@
>  #include <common.h>
>  #include <io.h>
>  #include <errno.h>
> +#include <firmware.h>
>  #include <linux/sizes.h>
>  #include <init.h>
>  #include <of.h>
> @@ -30,6 +31,7 @@
>  #include <mach/imx/imx7-regs.h>
>  #include <mach/imx/imx9-regs.h>
>  #include <mach/imx/scratch.h>
> +#include <mach/imx/tzasc.h>
>  #include <tee/optee.h>
>  
>  struct imx_esdctl_data {
> @@ -976,18 +978,59 @@ void __noreturn imx53_barebox_entry(void *boarddata)
>  static void __noreturn
>  imx6_barebox_entry(unsigned long membase, void *boarddata)
>  {
> -	barebox_arm_entry(membase,
> -			  imx6_mmdc_sdram_size(IOMEM(MX6_MMDC_P0_BASE_ADDR)),
> -			  boarddata);
> +	ulong memsize = imx6_mmdc_sdram_size(IOMEM(MX6_MMDC_P0_BASE_ADDR));
> +
> +	if (IS_ENABLED(CONFIG_FIRMWARE_IMX6_OPTEE) &&
> +	    IS_ENABLED(CONFIG_PBL_OPTEE) && imx6_can_access_tzasc()) {
> +		void *fdto;
> +		unsigned int fdto_size;
> +		int tee_size;
> +		void *tee;
> +
> +		get_builtin_firmware(imx6_optee_bin, &tee, &tee_size);
> +
> +		ulong endmem = arm_mem_barebox_image_end(membase + memsize);
> +		imx_init_scratch_space(endmem, 1);
> +		imx_scratch_get_optee_fdto(&fdto, &fdto_size);
> +		if (!fdto_size) {
> +			pr_warn("No space configured for OP-TEE devicetree\n");
> +			fdto = NULL;
> +		}
> +
> +		start_optee_early(fdto, tee);
> +		if (fdto_size)
> +			handoff_data_add(HANDOFF_DATA_BL32_DT_OVL, fdto,
> +					 fdto_size);
> +	}
> +
> +	barebox_arm_entry(membase, memsize, boarddata);
>  }
>  
>  void __noreturn imx6q_barebox_entry(void *boarddata)
>  {
> +	if (IS_ENABLED(CONFIG_FIRMWARE_IMX6_OPTEE) &&
> +	    IS_ENABLED(CONFIG_PBL_OPTEE) && imx6_can_access_tzasc()) {
> +		if (imx6q_tzc380_is_bypassed())
> +			panic("TZC380 is bypassed, abort OP-TEE loading\n");
> +
> +		/* Add early non-secure TZASC region1 to pass DTO */
> +		imx6q_tzc380_early_ns_region1();
> +	}
> +
>  	imx6_barebox_entry(MX6_MMDC_PORT01_BASE_ADDR, boarddata);
>  }
>  
>  void __noreturn imx6ul_barebox_entry(void *boarddata)
>  {
> +	if (IS_ENABLED(CONFIG_FIRMWARE_IMX6_OPTEE) &&
> +	    IS_ENABLED(CONFIG_PBL_OPTEE) && imx6_can_access_tzasc()) {
> +		if (imx6ul_tzc380_is_bypassed())
> +			panic("TZC380 is bypassed, abort OP-TEE loading\n");
> +
> +		/* Add early non-secure TZASC region1 to pass DTO */
> +		imx6ul_tzc380_early_ns_region1();
> +	}
> +
>  	imx6_barebox_entry(MX6_MMDC_PORT0_BASE_ADDR, boarddata);
>  }
>  
> diff --git a/common/Kconfig b/common/Kconfig
> index c42dc88ccf..20012cdc2c 100644
> --- a/common/Kconfig
> +++ b/common/Kconfig
> @@ -322,6 +322,7 @@ config SCRATCH_FDTO_SIZE
>  	hex
>  	default 0x0
>  	default 0x4000 if PBL_EARLY_FDT_LOAD
> +	default 0x4000 if FIRMWARE_IMX6_OPTEE
>  	prompt "Scratch FDTO size"
>  	help
>  	  The size of possible FDT overlay areas used by BL3x binaries to store
> diff --git a/firmware/Kconfig b/firmware/Kconfig
> index a97a1e0dd3..3e4245989c 100644
> --- a/firmware/Kconfig
> +++ b/firmware/Kconfig
> @@ -49,6 +49,14 @@ config FIRMWARE_IMX93_ATF
>  config FIRMWARE_AGILEX5_ATF
>  	bool
>  
> +config FIRMWARE_IMX6_OPTEE
> +	bool "install OP-TEE on i.MX6 boards"
> +	depends on PBL_OPTEE
> +	help
> +	  This enables OP-TEE loading and starting on i.MX6. Place the OP-TEE binary
> +	  in CONFIG_EXTRA_FIRMWARE_DIR/imx6-optee.bin. If this is enabled, then
> +	  the OP-TEE will automagically be loaded during boot.

automatically please.

> -int start_optee_early(void* fdt, void* tee);
> +int start_optee_early(void *fdt, void *tee);
>  int imx6q_start_optee_early(void *fdt, void *tee, void *data_location,
>  			    unsigned int data_location_size);
>  int imx6ul_start_optee_early(void *fdt, void *tee, void *data_location,
>  			     unsigned int data_location_size);
>  
> +#else
> +
> +static inline int start_optee_early(void *fdt, void *tee)
> +{
> +	return -ENOSYS;
> +}

Is this needed?

Sascha

-- 
Pengutronix e.K.                           |                             |
Steuerwalder Str. 21                       | http://www.pengutronix.de/  |
31137 Hildesheim, Germany                  | Phone: +49-5121-206917-0    |
Amtsgericht Hildesheim, HRA 2686           | Fax:   +49-5121-206917-5555 |



^ permalink raw reply	[flat|nested] 9+ messages in thread

* Re: [PATCH 3/3] ARM: i.MX6: load optee in PBL before barebox proper
  2025-12-10  7:40   ` Sascha Hauer
@ 2025-12-10  9:20     ` Fabian Pflug
  2025-12-10 10:58       ` Sascha Hauer
  0 siblings, 1 reply; 9+ messages in thread
From: Fabian Pflug @ 2025-12-10  9:20 UTC (permalink / raw)
  To: Sascha Hauer; +Cc: BAREBOX

Hey :)

On Wed, 2025-12-10 at 08:40 +0100, Sascha Hauer wrote:
> On Mon, Dec 08, 2025 at 10:28:40AM +0100, Fabian Pflug wrote:
> > This patch uses the space in the scratch memory to hand over to OP-TEE
> > for device-tree overlays. If OP-TEE is configured with CFG_DT_ADDR=,
> > then it will write its devicetree-overlay into the address and it will
> > be picked up and applied by barebox.
> > 
> > This allows for generic OP-TEE loading for i.MX6 devices without changes
> > to the board or lowlevel code.
> > 
> > Signed-off-by: Fabian Pflug <f.pflug@pengutronix.de>
> > ---
> >  arch/arm/mach-imx/esdctl.c | 49 +++++++++++++++++++++++++++++++++++++++++++---
> >  common/Kconfig             |  1 +
> >  firmware/Kconfig           |  8 ++++++++
> >  firmware/Makefile          |  1 +
> >  include/tee/optee.h        |  9 ++++++++-
> >  5 files changed, 64 insertions(+), 4 deletions(-)
> > 
> > diff --git a/arch/arm/mach-imx/esdctl.c b/arch/arm/mach-imx/esdctl.c
> > index b9393fba4a..2434844c96 100644
> > --- a/arch/arm/mach-imx/esdctl.c
> > +++ b/arch/arm/mach-imx/esdctl.c
> > @@ -6,6 +6,7 @@
> >  #include <common.h>
> >  #include <io.h>
> >  #include <errno.h>
> > +#include <firmware.h>
> >  #include <linux/sizes.h>
> >  #include <init.h>
> >  #include <of.h>
> > @@ -30,6 +31,7 @@
> >  #include <mach/imx/imx7-regs.h>
> >  #include <mach/imx/imx9-regs.h>
> >  #include <mach/imx/scratch.h>
> > +#include <mach/imx/tzasc.h>
> >  #include <tee/optee.h>
> >  
> >  struct imx_esdctl_data {
> > @@ -976,18 +978,59 @@ void __noreturn imx53_barebox_entry(void *boarddata)
> >  static void __noreturn
> >  imx6_barebox_entry(unsigned long membase, void *boarddata)
> >  {
> > -	barebox_arm_entry(membase,
> > -			  imx6_mmdc_sdram_size(IOMEM(MX6_MMDC_P0_BASE_ADDR)),
> > -			  boarddata);
> > +	ulong memsize = imx6_mmdc_sdram_size(IOMEM(MX6_MMDC_P0_BASE_ADDR));
> > +
> > +	if (IS_ENABLED(CONFIG_FIRMWARE_IMX6_OPTEE) &&
> > +	    IS_ENABLED(CONFIG_PBL_OPTEE) && imx6_can_access_tzasc()) {
> > +		void *fdto;
> > +		unsigned int fdto_size;
> > +		int tee_size;
> > +		void *tee;
> > +
> > +		get_builtin_firmware(imx6_optee_bin, &tee, &tee_size);
> > +
> > +		ulong endmem = arm_mem_barebox_image_end(membase + memsize);
> > +		imx_init_scratch_space(endmem, 1);
> > +		imx_scratch_get_optee_fdto(&fdto, &fdto_size);
> > +		if (!fdto_size) {
> > +			pr_warn("No space configured for OP-TEE devicetree\n");
> > +			fdto = NULL;
> > +		}
> > +
> > +		start_optee_early(fdto, tee);
> > +		if (fdto_size)
> > +			handoff_data_add(HANDOFF_DATA_BL32_DT_OVL, fdto,
> > +					 fdto_size);
> > +	}
> > +
> > +	barebox_arm_entry(membase, memsize, boarddata);
> >  }
> >  
> >  void __noreturn imx6q_barebox_entry(void *boarddata)
> >  {
> > +	if (IS_ENABLED(CONFIG_FIRMWARE_IMX6_OPTEE) &&
> > +	    IS_ENABLED(CONFIG_PBL_OPTEE) && imx6_can_access_tzasc()) {
> > +		if (imx6q_tzc380_is_bypassed())
> > +			panic("TZC380 is bypassed, abort OP-TEE loading\n");
> > +
> > +		/* Add early non-secure TZASC region1 to pass DTO */
> > +		imx6q_tzc380_early_ns_region1();
> > +	}
> > +
> >  	imx6_barebox_entry(MX6_MMDC_PORT01_BASE_ADDR, boarddata);
> >  }
> >  
> >  void __noreturn imx6ul_barebox_entry(void *boarddata)
> >  {
> > +	if (IS_ENABLED(CONFIG_FIRMWARE_IMX6_OPTEE) &&
> > +	    IS_ENABLED(CONFIG_PBL_OPTEE) && imx6_can_access_tzasc()) {
> > +		if (imx6ul_tzc380_is_bypassed())
> > +			panic("TZC380 is bypassed, abort OP-TEE loading\n");
> > +
> > +		/* Add early non-secure TZASC region1 to pass DTO */
> > +		imx6ul_tzc380_early_ns_region1();
> > +	}
> > +
> >  	imx6_barebox_entry(MX6_MMDC_PORT0_BASE_ADDR, boarddata);
> >  }
> >  
> > diff --git a/common/Kconfig b/common/Kconfig
> > index c42dc88ccf..20012cdc2c 100644
> > --- a/common/Kconfig
> > +++ b/common/Kconfig
> > @@ -322,6 +322,7 @@ config SCRATCH_FDTO_SIZE
> >  	hex
> >  	default 0x0
> >  	default 0x4000 if PBL_EARLY_FDT_LOAD
> > +	default 0x4000 if FIRMWARE_IMX6_OPTEE
> >  	prompt "Scratch FDTO size"
> >  	help
> >  	  The size of possible FDT overlay areas used by BL3x binaries to store
> > diff --git a/firmware/Kconfig b/firmware/Kconfig
> > index a97a1e0dd3..3e4245989c 100644
> > --- a/firmware/Kconfig
> > +++ b/firmware/Kconfig
> > @@ -49,6 +49,14 @@ config FIRMWARE_IMX93_ATF
> >  config FIRMWARE_AGILEX5_ATF
> >  	bool
> >  
> > +config FIRMWARE_IMX6_OPTEE
> > +	bool "install OP-TEE on i.MX6 boards"
> > +	depends on PBL_OPTEE
> > +	help
> > +	  This enables OP-TEE loading and starting on i.MX6. Place the OP-TEE binary
> > +	  in CONFIG_EXTRA_FIRMWARE_DIR/imx6-optee.bin. If this is enabled, then
> > +	  the OP-TEE will automagically be loaded during boot.
> 
> automatically please.
> 
> > -int start_optee_early(void* fdt, void* tee);
> > +int start_optee_early(void *fdt, void *tee);
> >  int imx6q_start_optee_early(void *fdt, void *tee, void *data_location,
> >  			    unsigned int data_location_size);
> >  int imx6ul_start_optee_early(void *fdt, void *tee, void *data_location,
> >  			     unsigned int data_location_size);
> >  
> > +#else
> > +
> > +static inline int start_optee_early(void *fdt, void *tee)
> > +{
> > +	return -ENOSYS;
> > +}
> 
> Is this needed?


Without it, I get
| /patch/to/barebox/arch/arm/mach-imx/esdctl.c: In function 'imx6_barebox_entry':
| /patch/to/barebox/arch/arm/mach-imx/esdctl.c:1000:17: error: implicit declaration of function 'start_optee_early' [-
Werror=implicit-function-declaration]
|  1000 |                 start_optee_early(fdto, tee);
|       |                 ^~~~~~~~~~~~~~~~~

during compile.

That leaves three choices:
* Add a -ENOSYS to header
* disable compiling esdctl.c for barebox
* wrap call to start_optee_early in esdctl.c with #ifdef

Is there an error with esdctl being compiled for non-PBL?

Kind regards
Fabian

> 
> Sascha



^ permalink raw reply	[flat|nested] 9+ messages in thread

* Re: [PATCH 1/3] ARM: make arm_mem_scratch respect the OP-TEE stack
  2025-12-10  7:18   ` Sascha Hauer
@ 2025-12-10  9:32     ` Fabian Pflug
  0 siblings, 0 replies; 9+ messages in thread
From: Fabian Pflug @ 2025-12-10  9:32 UTC (permalink / raw)
  To: Sascha Hauer; +Cc: BAREBOX

Hello Sascha :)

On Wed, 2025-12-10 at 08:18 +0100, Sascha Hauer wrote:
> Hi Fabian,
> 
> On Mon, Dec 08, 2025 at 10:28:38AM +0100, Fabian Pflug wrote:
> > According to the ASCII-ART above, before the end of memory comes the
> > optee memory, then the scratch stack.
> > 
> > Signed-off-by: Fabian Pflug <f.pflug@pengutronix.de>
> > ---
> >  arch/arm/include/asm/barebox-arm.h | 2 +-
> >  1 file changed, 1 insertion(+), 1 deletion(-)
> > 
> > diff --git a/arch/arm/include/asm/barebox-arm.h b/arch/arm/include/asm/barebox-arm.h
> > index 11be8b8583..e630969796 100644
> > --- a/arch/arm/include/asm/barebox-arm.h
> > +++ b/arch/arm/include/asm/barebox-arm.h
> > @@ -159,7 +159,7 @@ static inline unsigned long arm_mem_stack_top(unsigned long endmem)
> >  
> >  static inline const void *arm_mem_scratch_get(void)
> >  {
> > -	return (const void *)arm_mem_scratch(arm_mem_endmem_get());
> > +	return (const void *)arm_mem_scratch(arm_mem_optee(arm_mem_endmem_get()));
> 
> arm_mem_scratch() is:
> 
> static inline unsigned long arm_mem_scratch(unsigned long endmem)
> {
> 	return arm_mem_optee(endmem) - SCRATCH_SIZE;
> }
> 
> So this already has the OPTEE space substracted. With your patch it's
> substracted twice.

Yes, you are right! Don't know why I did not see that...

This also makes the third patch in the series wrong, because it will remove the offset twice in another way.

I will send a new series after resolving the comment on the other patch. :)

Fabian

> 
> Sascha



^ permalink raw reply	[flat|nested] 9+ messages in thread

* Re: [PATCH 3/3] ARM: i.MX6: load optee in PBL before barebox proper
  2025-12-10  9:20     ` Fabian Pflug
@ 2025-12-10 10:58       ` Sascha Hauer
  0 siblings, 0 replies; 9+ messages in thread
From: Sascha Hauer @ 2025-12-10 10:58 UTC (permalink / raw)
  To: Fabian Pflug; +Cc: BAREBOX

On Wed, Dec 10, 2025 at 10:20:18AM +0100, Fabian Pflug wrote:
> Hey :)
> 
> On Wed, 2025-12-10 at 08:40 +0100, Sascha Hauer wrote:
> > On Mon, Dec 08, 2025 at 10:28:40AM +0100, Fabian Pflug wrote:
> > > This patch uses the space in the scratch memory to hand over to OP-TEE
> > > for device-tree overlays. If OP-TEE is configured with CFG_DT_ADDR=,
> > > then it will write its devicetree-overlay into the address and it will
> > > be picked up and applied by barebox.
> > > 
> > > This allows for generic OP-TEE loading for i.MX6 devices without changes
> > > to the board or lowlevel code.
> > > 
> > > Signed-off-by: Fabian Pflug <f.pflug@pengutronix.de>
> > > ---
> > >  arch/arm/mach-imx/esdctl.c | 49 +++++++++++++++++++++++++++++++++++++++++++---
> > >  common/Kconfig             |  1 +
> > >  firmware/Kconfig           |  8 ++++++++
> > >  firmware/Makefile          |  1 +
> > >  include/tee/optee.h        |  9 ++++++++-
> > >  5 files changed, 64 insertions(+), 4 deletions(-)
> > > 
> > > diff --git a/arch/arm/mach-imx/esdctl.c b/arch/arm/mach-imx/esdctl.c
> > > index b9393fba4a..2434844c96 100644
> > > --- a/arch/arm/mach-imx/esdctl.c
> > > +++ b/arch/arm/mach-imx/esdctl.c
> > > @@ -6,6 +6,7 @@
> > >  #include <common.h>
> > >  #include <io.h>
> > >  #include <errno.h>
> > > +#include <firmware.h>
> > >  #include <linux/sizes.h>
> > >  #include <init.h>
> > >  #include <of.h>
> > > @@ -30,6 +31,7 @@
> > >  #include <mach/imx/imx7-regs.h>
> > >  #include <mach/imx/imx9-regs.h>
> > >  #include <mach/imx/scratch.h>
> > > +#include <mach/imx/tzasc.h>
> > >  #include <tee/optee.h>
> > >  
> > >  struct imx_esdctl_data {
> > > @@ -976,18 +978,59 @@ void __noreturn imx53_barebox_entry(void *boarddata)
> > >  static void __noreturn
> > >  imx6_barebox_entry(unsigned long membase, void *boarddata)
> > >  {
> > > -	barebox_arm_entry(membase,
> > > -			  imx6_mmdc_sdram_size(IOMEM(MX6_MMDC_P0_BASE_ADDR)),
> > > -			  boarddata);
> > > +	ulong memsize = imx6_mmdc_sdram_size(IOMEM(MX6_MMDC_P0_BASE_ADDR));
> > > +
> > > +	if (IS_ENABLED(CONFIG_FIRMWARE_IMX6_OPTEE) &&
> > > +	    IS_ENABLED(CONFIG_PBL_OPTEE) && imx6_can_access_tzasc()) {
> > > +		void *fdto;
> > > +		unsigned int fdto_size;
> > > +		int tee_size;
> > > +		void *tee;
> > > +
> > > +		get_builtin_firmware(imx6_optee_bin, &tee, &tee_size);
> > > +
> > > +		ulong endmem = arm_mem_barebox_image_end(membase + memsize);
> > > +		imx_init_scratch_space(endmem, 1);
> > > +		imx_scratch_get_optee_fdto(&fdto, &fdto_size);
> > > +		if (!fdto_size) {
> > > +			pr_warn("No space configured for OP-TEE devicetree\n");
> > > +			fdto = NULL;
> > > +		}
> > > +
> > > +		start_optee_early(fdto, tee);
> > > +		if (fdto_size)
> > > +			handoff_data_add(HANDOFF_DATA_BL32_DT_OVL, fdto,
> > > +					 fdto_size);
> > > +	}
> > > +
> > > +	barebox_arm_entry(membase, memsize, boarddata);
> > >  }
> > >  
> > >  void __noreturn imx6q_barebox_entry(void *boarddata)
> > >  {
> > > +	if (IS_ENABLED(CONFIG_FIRMWARE_IMX6_OPTEE) &&
> > > +	    IS_ENABLED(CONFIG_PBL_OPTEE) && imx6_can_access_tzasc()) {
> > > +		if (imx6q_tzc380_is_bypassed())
> > > +			panic("TZC380 is bypassed, abort OP-TEE loading\n");
> > > +
> > > +		/* Add early non-secure TZASC region1 to pass DTO */
> > > +		imx6q_tzc380_early_ns_region1();
> > > +	}
> > > +
> > >  	imx6_barebox_entry(MX6_MMDC_PORT01_BASE_ADDR, boarddata);
> > >  }
> > >  
> > >  void __noreturn imx6ul_barebox_entry(void *boarddata)
> > >  {
> > > +	if (IS_ENABLED(CONFIG_FIRMWARE_IMX6_OPTEE) &&
> > > +	    IS_ENABLED(CONFIG_PBL_OPTEE) && imx6_can_access_tzasc()) {
> > > +		if (imx6ul_tzc380_is_bypassed())
> > > +			panic("TZC380 is bypassed, abort OP-TEE loading\n");
> > > +
> > > +		/* Add early non-secure TZASC region1 to pass DTO */
> > > +		imx6ul_tzc380_early_ns_region1();
> > > +	}
> > > +
> > >  	imx6_barebox_entry(MX6_MMDC_PORT0_BASE_ADDR, boarddata);
> > >  }
> > >  
> > > diff --git a/common/Kconfig b/common/Kconfig
> > > index c42dc88ccf..20012cdc2c 100644
> > > --- a/common/Kconfig
> > > +++ b/common/Kconfig
> > > @@ -322,6 +322,7 @@ config SCRATCH_FDTO_SIZE
> > >  	hex
> > >  	default 0x0
> > >  	default 0x4000 if PBL_EARLY_FDT_LOAD
> > > +	default 0x4000 if FIRMWARE_IMX6_OPTEE
> > >  	prompt "Scratch FDTO size"
> > >  	help
> > >  	  The size of possible FDT overlay areas used by BL3x binaries to store
> > > diff --git a/firmware/Kconfig b/firmware/Kconfig
> > > index a97a1e0dd3..3e4245989c 100644
> > > --- a/firmware/Kconfig
> > > +++ b/firmware/Kconfig
> > > @@ -49,6 +49,14 @@ config FIRMWARE_IMX93_ATF
> > >  config FIRMWARE_AGILEX5_ATF
> > >  	bool
> > >  
> > > +config FIRMWARE_IMX6_OPTEE
> > > +	bool "install OP-TEE on i.MX6 boards"
> > > +	depends on PBL_OPTEE
> > > +	help
> > > +	  This enables OP-TEE loading and starting on i.MX6. Place the OP-TEE binary
> > > +	  in CONFIG_EXTRA_FIRMWARE_DIR/imx6-optee.bin. If this is enabled, then
> > > +	  the OP-TEE will automagically be loaded during boot.
> > 
> > automatically please.
> > 
> > > -int start_optee_early(void* fdt, void* tee);
> > > +int start_optee_early(void *fdt, void *tee);
> > >  int imx6q_start_optee_early(void *fdt, void *tee, void *data_location,
> > >  			    unsigned int data_location_size);
> > >  int imx6ul_start_optee_early(void *fdt, void *tee, void *data_location,
> > >  			     unsigned int data_location_size);
> > >  
> > > +#else
> > > +
> > > +static inline int start_optee_early(void *fdt, void *tee)
> > > +{
> > > +	return -ENOSYS;
> > > +}
> > 
> > Is this needed?
> 
> 
> Without it, I get
> | /patch/to/barebox/arch/arm/mach-imx/esdctl.c: In function 'imx6_barebox_entry':
> | /patch/to/barebox/arch/arm/mach-imx/esdctl.c:1000:17: error: implicit declaration of function 'start_optee_early' [-
> Werror=implicit-function-declaration]
> |  1000 |                 start_optee_early(fdto, tee);
> |       |                 ^~~~~~~~~~~~~~~~~
> 
> during compile.
> 
> That leaves three choices:
> * Add a -ENOSYS to header
> * disable compiling esdctl.c for barebox
> * wrap call to start_optee_early in esdctl.c with #ifdef
> 
> Is there an error with esdctl being compiled for non-PBL?

esdctl.c is needed for non-PBL. Keep it like it is with returning
-ENOSYS. I was just curious.

Sascha

-- 
Pengutronix e.K.                           |                             |
Steuerwalder Str. 21                       | http://www.pengutronix.de/  |
31137 Hildesheim, Germany                  | Phone: +49-5121-206917-0    |
Amtsgericht Hildesheim, HRA 2686           | Fax:   +49-5121-206917-5555 |



^ permalink raw reply	[flat|nested] 9+ messages in thread

end of thread, other threads:[~2025-12-10 10:59 UTC | newest]

Thread overview: 9+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2025-12-08  9:28 [PATCH 0/3] Add generic OP-TEE loading for i.MX6 Fabian Pflug
2025-12-08  9:28 ` [PATCH 1/3] ARM: make arm_mem_scratch respect the OP-TEE stack Fabian Pflug
2025-12-10  7:18   ` Sascha Hauer
2025-12-10  9:32     ` Fabian Pflug
2025-12-08  9:28 ` [PATCH 2/3] ARM: i.MX: scratch: add generic init for imx Fabian Pflug
2025-12-08  9:28 ` [PATCH 3/3] ARM: i.MX6: load optee in PBL before barebox proper Fabian Pflug
2025-12-10  7:40   ` Sascha Hauer
2025-12-10  9:20     ` Fabian Pflug
2025-12-10 10:58       ` Sascha Hauer

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox