Conversation
Rockchip's BL32 from rkbin is only started by Rockchip's BL31; with the open TF-A the FIT's optee slot is dead weight. Let the builder swap in an upstream OP-TEE image and document the TF-A flags that make it start. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01VPqq7YaURA87cbGTbVXbrZ
Two patches on top of the pinned TF-A: fall back to the FIT's BL32 load address when the SPL passes no entry point (it never does), and program DDR/DSU firewall region 1 for BL32 from EL3, since OP-TEE's own firewall write hangs on this chain. With --bl32 this lets the build produce a working upstream OP-TEE image. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01VPqq7YaURA87cbGTbVXbrZ
The fallback to the FIT's OP-TEE load address only set the entry point. The SPL also leaves the four BL32 argument words uninitialised, and the OP-TEE dispatcher reads the first one as the AArch32/AArch64 selector, so OP-TEE was entered in AArch32 state and hung before UEFI. Refresh patch 0010 with the version that clears them; verified booting on a ROCK 5B. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01VPqq7YaURA87cbGTbVXbrZ
Review feedback on the OP-TEE side (OP-TEE/optee_os#8032): naming OP-TEE's base and size in TF-A ties the two together, so OP-TEE moving or growing would need a TF-A change. Regenerate 0010/0011 from the reworked series: PLAT_RK_BL32_BASE/SIZE become PLAT_RK_SEC_DRAM_BASE/ SIZE, the secure DRAM window this platform reserves, and BL31 checks a loader-supplied BL32 entry point against it instead of assuming the two agree. The patches also carry Signed-off-by now. No functional change to the build: the same window is firewalled. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Rqe5yoJTwPu4ZZKb96vijY
The last MiB was left non-secure so a normal-world reader could pick up OP-TEE's CFG_RAMCON ring buffer on a board with no reachable debug UART. That is a bring-up aid, and it is not worth an unconditional gap in the window's protection: the non-secure world could read whatever OP-TEE logged there on every build, ramcon or not. Firewall all 16 MiB; a build that wants the RAM console inside the window shrinks PLAT_RK_SEC_DRAM_SIZE by the size of the console. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Rqe5yoJTwPu4ZZKb96vijY
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Rockchip's BL32 from rkbin is only started by Rockchip's BL31; with the open TF-A the FIT's
opteeslot is dead weight. This adds--bl32 FILEto put a custom OP-TEE image (for example an upstreamtee-raw.bin) in the FIT, and a README section on building TF-A with--tfa-flags "SPD=opteed".Two prerequisites are in flight elsewhere and are referenced from the README: the RK3588 SPL passes BL31 no BL32 entry point, so TF-A needs the fallback proposed to worproject/arm-trusted-firmware (
PLAT_RK_BL32_BASE), and upstream OP-TEE needsCFG_RK3588_FIREWALL_BY_BL31=ysince programming the firewall from S-EL1 hangs on this chain.Tested on a Radxa ROCK 5B with the v1.1 UEFI: OP-TEE 4.10 with the PKCS#11 TA starts, keys import and sign, storage persists across reboots.
🤖 Generated with Claude Code
https://claude.ai/code/session_01VPqq7YaURA87cbGTbVXbrZ