Skip to content

build: --bl32 override and OP-TEE notes - #290

Open
nikicat wants to merge 5 commits into
edk2-porting:masterfrom
nikicat:optee
Open

nikicat wants to merge 5 commits into
edk2-porting:masterfrom
nikicat:optee

Conversation

@nikicat

@nikicat nikicat commented Sep 19, 2026

Copy link
Copy Markdown

Rockchip's BL32 from rkbin is only started by Rockchip's BL31; with the open TF-A the FIT's optee slot is dead weight. This adds --bl32 FILE to put a custom OP-TEE image (for example an upstream tee-raw.bin) in the FIT, and a README section on building TF-A with --tfa-flags "SPD=opteed".

Two prerequisites are in flight elsewhere and are referenced from the README: the RK3588 SPL passes BL31 no BL32 entry point, so TF-A needs the fallback proposed to worproject/arm-trusted-firmware (PLAT_RK_BL32_BASE), and upstream OP-TEE needs CFG_RK3588_FIREWALL_BY_BL31=y since programming the firewall from S-EL1 hangs on this chain.

Tested on a Radxa ROCK 5B with the v1.1 UEFI: OP-TEE 4.10 with the PKCS#11 TA starts, keys import and sign, storage persists across reboots.

🤖 Generated with Claude Code

https://claude.ai/code/session_01VPqq7YaURA87cbGTbVXbrZ

Rockchip's BL32 from rkbin is only started by Rockchip's BL31; with the
open TF-A the FIT's optee slot is dead weight. Let the builder swap in an
upstream OP-TEE image and document the TF-A flags that make it start.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01VPqq7YaURA87cbGTbVXbrZ
nikicat and others added 3 commits September 19, 2026 22:59
Two patches on top of the pinned TF-A: fall back to the FIT's BL32 load
address when the SPL passes no entry point (it never does), and program
DDR/DSU firewall region 1 for BL32 from EL3, since OP-TEE's own firewall
write hangs on this chain. With --bl32 this lets the build produce a
working upstream OP-TEE image.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01VPqq7YaURA87cbGTbVXbrZ
The fallback to the FIT's OP-TEE load address only set the entry point.
The SPL also leaves the four BL32 argument words uninitialised, and the
OP-TEE dispatcher reads the first one as the AArch32/AArch64 selector, so
OP-TEE was entered in AArch32 state and hung before UEFI. Refresh patch
0010 with the version that clears them; verified booting on a ROCK 5B.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01VPqq7YaURA87cbGTbVXbrZ
Review feedback on the OP-TEE side (OP-TEE/optee_os#8032): naming
OP-TEE's base and size in TF-A ties the two together, so OP-TEE moving
or growing would need a TF-A change. Regenerate 0010/0011 from the
reworked series: PLAT_RK_BL32_BASE/SIZE become PLAT_RK_SEC_DRAM_BASE/
SIZE, the secure DRAM window this platform reserves, and BL31 checks a
loader-supplied BL32 entry point against it instead of assuming the two
agree. The patches also carry Signed-off-by now.

No functional change to the build: the same window is firewalled.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Rqe5yoJTwPu4ZZKb96vijY
The last MiB was left non-secure so a normal-world reader could pick up
OP-TEE's CFG_RAMCON ring buffer on a board with no reachable debug UART.
That is a bring-up aid, and it is not worth an unconditional gap in the
window's protection: the non-secure world could read whatever OP-TEE
logged there on every build, ramcon or not. Firewall all 16 MiB; a build
that wants the RAM console inside the window shrinks
PLAT_RK_SEC_DRAM_SIZE by the size of the console.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Rqe5yoJTwPu4ZZKb96vijY
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant