| Message ID | 20240304153253.732708-6-dario.binacchi@amarulasolutions.com |
|---|---|
| State | New |
| Headers |
Return-Path: <linux-amarula+bncBCQ4XFG47UFRB56TS6XQMGQEAHMSFVQ@amarulasolutions.com> X-Original-To: linux-amarula@patchwork.amarulasolutions.com Delivered-To: linux-amarula@patchwork.amarulasolutions.com Received: from mail-lf1-f71.google.com (mail-lf1-f71.google.com [209.85.167.71]) by ganimede.amarulasolutions.com (Postfix) with ESMTPS id 8BD573FA2C for <linux-amarula@patchwork.amarulasolutions.com>; Mon, 4 Mar 2024 16:34:16 +0100 (CET) Received: by mail-lf1-f71.google.com with SMTP id 2adb3069b0e04-5131bf5d244sf3587418e87.3 for <linux-amarula@patchwork.amarulasolutions.com>; Mon, 04 Mar 2024 07:34:16 -0800 (PST) ARC-Seal: i=2; a=rsa-sha256; t=1709566456; cv=pass; d=google.com; s=arc-20160816; b=1CpIlsN96b9xsjLDcyiVwtWAAccxGdfc9zYlMuFSEKZe9ZCuwHm/jj1F7gWTm6XoUp ydfRHy6fKFRfpFdTpqXLmq5heg2svA/Q5eGAUyokaWEQUCqoKS/s0XLLp/lY9apeSLMB JI4JkfDgC3f4hhmzZl9OzgQzLJitccadJFZKU1f7DkhdIpvAG3LmOixNJ7XyUj48wLx9 /4yKs8+7NYEBIaJdeJJ4ogYs1NsisIOj4aGIv7hMiX77tMCpOc9m79eWvsYARJssfRO0 Tfj9i8DzYnF4Dh/zwEOYUV0s23f7wD6Mowyz/KLGsrHvfScflXBGZAqQc8vFeP1zcbhB XC4A== ARC-Message-Signature: i=2; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-unsubscribe:list-archive:list-help:list-post:list-id :mailing-list:precedence:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:dkim-signature; bh=z8e7hb1DieBR0X5vyULxTq7hZbeHbaOQZe/7WdvUEeE=; fh=4hJe3zhUL33o62S5+AXvMb7GEhOyF5BB6AsIhNwwQvk=; b=txUd4J9XsloFQhisBWvwmXB3m8VH2QM+GlLlgWrNvCsv/gppLtq1fGvxLaW0T5ScAX +4Uv13Vc1KSBrCNyu0ei+3epx2hCHkSMuzDqeQh0DB8rvZYcl7u0zbr9dkjmxIxI6zDt 47M8REIXuhYzgq33cM2zxKc2i9JajnsE+dwBgApqSVeFwEH0yo2sMW3bxnxzdfHhFf9P zlKKPaZRvof1uU2TnxCFQMb67kiUaQehzSJDdcanBDgVD9/vlw7oSoFU+JFHT9zQ+nNd EhQRLMnILO0CFNcF8FFoooVm1MEm0aWWcSJyAF1TvbtxDSQ0B3dFcy10IIhBNxC+xYxd HgJQ==; darn=patchwork.amarulasolutions.com ARC-Authentication-Results: i=2; mx.google.com; dkim=pass header.i=@amarulasolutions.com header.s=google header.b=id39ZQYu; spf=pass (google.com: domain of dario.binacchi@amarulasolutions.com designates 209.85.220.41 as permitted sender) smtp.mailfrom=dario.binacchi@amarulasolutions.com; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=amarulasolutions.com DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=amarulasolutions.com; s=google; t=1709566456; x=1710171256; darn=patchwork.amarulasolutions.com; h=list-unsubscribe:list-archive:list-help:list-post:list-id :mailing-list:precedence:x-original-authentication-results :x-original-sender:mime-version:references:in-reply-to:message-id :date:subject:cc:to:from:from:to:cc:subject:date:message-id:reply-to; bh=z8e7hb1DieBR0X5vyULxTq7hZbeHbaOQZe/7WdvUEeE=; b=jjva8AfeobWKLse6cqGJ45mWekJpGjh5PBhTh/FJ1oeLTaQTJd1jvJxBUKxJ6ndN68 dDAIYgOmbVF45MK4gW7FpHJp30AKiycwBlOcx87BiI0OzhnSd71rDK3BSt8vfUxD0hyU CKdq4BgWCwcZxwApJWZKLvd3bfbe7ZBDa3R48= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1709566456; x=1710171256; h=list-unsubscribe:list-archive:list-help:list-post :x-spam-checked-in-group:list-id:mailing-list:precedence :x-original-authentication-results:x-original-sender:mime-version :references:in-reply-to:message-id:date:subject:cc:to:from :x-beenthere:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=z8e7hb1DieBR0X5vyULxTq7hZbeHbaOQZe/7WdvUEeE=; b=OR3DhQLkbfzCcWwNtgXsAB60U5/rsq9pWrVDxsfJEDfgTGb0UJid3P7S1qQUNNDnhx IPN46X81LuP0iG5lv3P/Ep3xSXRCfJhtcrfMEeM3v2FYCRjWfOnxsiFNnhVPS0+vHiXO AY+PrFf96NnuDfdVrrLvwWwjeYPJmPDdieX3C7HfjgSxelMLCTJYEThYEWvL93otBX/2 UPSwcxC9py7a2xk8ko7jWsZ5JCnxxUfKoGSue5crL5aGQ87HrkItnSBpNJ0JyoP/qUiz t3ZHzCl+hyxOj1Fbv0/hIUayoFt7NwoWV2T0ti2pAMzE0cu+oQnaDBPGd1ODVYXav+J1 yyYg== X-Forwarded-Encrypted: i=2; AJvYcCWbILq9DymYB6N8IoDcKPDPMEkNk1v82vYT1seuav4GpLJoS15BtfJgLIs3gYlgTF4tBBEWWzZUfZvgJmKVC2LuGKpuGWU8PWUjA2XpkbTFEvOLeQOfo/X677Hn7g== X-Gm-Message-State: AOJu0YyP48SADpbcfe6WE9j5nbRZGK0uMXpB4s2K0y6MGd4VxjzDupPI fdmjpTvSY7z3ZEDAe4pL4k/59fktkXy1ANrmaxW/4FR0hBkeBHbK5p6SCUCTclZIAw== X-Google-Smtp-Source: AGHT+IHPAuMuUxXOvEkbomIGZ19h7UJ8tvhSmlGTjhVJNURUr5YhIhta9Yz4+EOT8I0730MvVX5CLA== X-Received: by 2002:ac2:5054:0:b0:513:2cb2:53a1 with SMTP id a20-20020ac25054000000b005132cb253a1mr6171420lfm.53.1709566455998; Mon, 04 Mar 2024 07:34:15 -0800 (PST) X-BeenThere: linux-amarula@amarulasolutions.com Received: by 2002:a05:6402:1f05:b0:566:295a:fd3e with SMTP id b5-20020a0564021f0500b00566295afd3els560151edb.1.-pod-prod-04-eu; Mon, 04 Mar 2024 07:34:14 -0800 (PST) X-Forwarded-Encrypted: i=2; AJvYcCUBWUXBspKkpSPiOG8EnBYVREtgtvtDHuXB/dI2M5zER4cMhkdGsD3f4bft72ja1H5pRkZX+bG9Llw/hYD1TBMz8UI4a/0h259pXz+Ell3asZ+y X-Received: by 2002:a17:906:f911:b0:a44:7bbe:d774 with SMTP id lc17-20020a170906f91100b00a447bbed774mr6322807ejb.9.1709566454491; Mon, 04 Mar 2024 07:34:14 -0800 (PST) ARC-Seal: i=1; a=rsa-sha256; t=1709566454; cv=none; d=google.com; s=arc-20160816; b=F9lbkjuoeFbUngR4iYppwoyqKG3fV4w81Krpc1NX4dVXDYutR6zPDsiF+ljdt5xfNi yrckjXp5QA55bfuDcLKozk0rkptK2MWTA+DhyYNiwcfOAdk2P8zTTk6LDtij5V8kLxiE 7JG+9rZ9QWOqchRiRptWmv8LTos6bfy0dsNweU8zKcu5Uc1YXLKXsU6GeMcDH4RLh5tE jyeY1q3eZiCu09E0fdvoJKxpFuL7LIJ/rK+Rrqnjy/pu4pmXZIfQpYN4mh2WuE/r5gy6 HWIazprrNz4MoEJ8CE8T7Zp9CvdJSbyd5188aBHY//7TCM07PrGuMlipQMghqW/QJvFg CX+Q== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:dkim-signature; bh=kqwXj0Cwjbnuj3JXbq7I8NEydeF4lxxZvlM/8Q2Wx7Q=; fh=Ch9JiNII/TjAl8r0bN1XVSVF63vl3FoOJJ5GA1LuMJA=; b=AjZ3uJHy9IUWZlCEbbxuoaN4BiZeHawox0qqoMgFRnXD4mczv8FVdUd4H44qKZcoiV FlGG6Rl5rPssGv2TXqivn8cxx+1M9C1dbkbF1rLoNNgrJ+AI8w/w1v1Z9Uf+qV5zuOIQ WOYRlZQi0YTEvo9wxxRVXO2YjXVjBc7c6d7jBKosKKK78edSebE+JbzD0JLv/veeBlQU hnhlYTKiMm1VcPKAHZO22AX7YRX21IcI6pNmENKygaeKrtez9Z9gzdA5sS/MvCGfOhsO oigyrCqpb1bspbrIR1rQe5598FYo4pp5tH1B8K1dbc7z3ste5m1qPaXOQDQQUdPjJiXe 7DsQ==; dara=google.com ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@amarulasolutions.com header.s=google header.b=id39ZQYu; spf=pass (google.com: domain of dario.binacchi@amarulasolutions.com designates 209.85.220.41 as permitted sender) smtp.mailfrom=dario.binacchi@amarulasolutions.com; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=amarulasolutions.com Received: from mail-sor-f41.google.com (mail-sor-f41.google.com. [209.85.220.41]) by mx.google.com with SMTPS id n8-20020a170906b30800b00a4578e2ed98sor441954ejz.20.2024.03.04.07.34.14 for <linux-amarula@amarulasolutions.com> (Google Transport Security); Mon, 04 Mar 2024 07:34:14 -0800 (PST) Received-SPF: pass (google.com: domain of dario.binacchi@amarulasolutions.com designates 209.85.220.41 as permitted sender) client-ip=209.85.220.41; X-Forwarded-Encrypted: i=1; AJvYcCW7UY/Ysmn9serRxnncEw4+FOpfNfme69vPHsuVwbUGvMGCfj9FQ+dlHNuMcDPc3J5/tTaCSchhWD6/oaJ/ho3RNLhKw6T71cH+aKao0LiwQeJd X-Received: by 2002:a17:906:abd0:b0:a45:293a:c94c with SMTP id kq16-20020a170906abd000b00a45293ac94cmr2488612ejb.60.1709566454053; Mon, 04 Mar 2024 07:34:14 -0800 (PST) Received: from dario-ThinkPad-T14s-Gen-2i.amarulasolutions.com ([2001:b07:6474:ebbf:72fe:558f:d55e:d423]) by smtp.gmail.com with ESMTPSA id sa20-20020a1709076d1400b00a4432543b21sm4936082ejc.198.2024.03.04.07.34.13 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 04 Mar 2024 07:34:13 -0800 (PST) From: Dario Binacchi <dario.binacchi@amarulasolutions.com> To: buildroot@buildroot.org Cc: Romain Naour <romain.naour@smile.fr>, Alexander Sverdlin <alexander.sverdlin@gmail.com>, Andreas Dannenberg <dannenberg@ti.com>, Yegor Yefremov <yegorslists@googlemail.com>, Xuanhao Shi <X15000177@gmail.com>, Anand Gadiyar <gadiyar@ti.com>, James Hilliard <james.hilliard1@gmail.com>, Thomas Petazzoni <thomas.petazzoni@bootlin.com>, Dario Binacchi <dario.binacchi@amarulasolutions.com>, michael@amarulasolutions.com, Asaf Kahlon <asafka7@gmail.com>, francois.perrad@gadz.org, linux-amarula@amarulasolutions.com, bryce@redpinelabs.com Subject: [PATCH v9 05/22] boot/ti-k3-r5-loader: bump to version 2024.01 Date: Mon, 4 Mar 2024 16:32:36 +0100 Message-ID: <20240304153253.732708-6-dario.binacchi@amarulasolutions.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20240304153253.732708-1-dario.binacchi@amarulasolutions.com> References: <20240304153253.732708-1-dario.binacchi@amarulasolutions.com> MIME-Version: 1.0 X-Original-Sender: dario.binacchi@amarulasolutions.com X-Original-Authentication-Results: mx.google.com; dkim=pass header.i=@amarulasolutions.com header.s=google header.b=id39ZQYu; spf=pass (google.com: domain of dario.binacchi@amarulasolutions.com designates 209.85.220.41 as permitted sender) smtp.mailfrom=dario.binacchi@amarulasolutions.com; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=amarulasolutions.com Content-Type: text/plain; charset="UTF-8" Precedence: list Mailing-list: list linux-amarula@amarulasolutions.com; contact linux-amarula+owners@amarulasolutions.com List-ID: <linux-amarula.amarulasolutions.com> X-Spam-Checked-In-Group: linux-amarula@amarulasolutions.com X-Google-Group-Id: 476853432473 List-Post: <https://groups.google.com/a/amarulasolutions.com/group/linux-amarula/post>, <mailto:linux-amarula@amarulasolutions.com> List-Help: <https://support.google.com/a/amarulasolutions.com/bin/topic.py?topic=25838>, <mailto:linux-amarula+help@amarulasolutions.com> List-Archive: <https://groups.google.com/a/amarulasolutions.com/group/linux-amarula/> List-Unsubscribe: <mailto:googlegroups-manage+476853432473+unsubscribe@googlegroups.com>, <https://groups.google.com/a/amarulasolutions.com/group/linux-amarula/subscribe> |
| Series |
Add support for AM62x-SK HS-FS devices
|
|
Commit Message
Dario Binacchi
March 4, 2024, 3:32 p.m. UTC
All in-tree configs with the ti-k3-r5 bootloader use a custom version,
so this patch is mostly for the menuconfig default version
Suggested-by: Romain Naour <romain.naour@smile.fr>
Signed-off-by: Dario Binacchi <dario.binacchi@amarulasolutions.com>
---
no changes since v4
Added in v4
boot/ti-k3-r5-loader/Config.in | 4 ++--
boot/ti-k3-r5-loader/ti-k3-r5-loader.hash | 2 +-
2 files changed, 3 insertions(+), 3 deletions(-)
Comments
Dario, All, On 2024-03-04 16:32 +0100, Dario Binacchi spake thusly: > All in-tree configs with the ti-k3-r5 bootloader use a custom version, > so this patch is mostly for the menuconfig default version > > Suggested-by: Romain Naour <romain.naour@smile.fr> > Signed-off-by: Dario Binacchi <dario.binacchi@amarulasolutions.com> [--SNIP--] > diff --git a/boot/ti-k3-r5-loader/ti-k3-r5-loader.hash b/boot/ti-k3-r5-loader/ti-k3-r5-loader.hash > index c5d1cb8e09f0..fbe5d215409d 100644 > --- a/boot/ti-k3-r5-loader/ti-k3-r5-loader.hash > +++ b/boot/ti-k3-r5-loader/ti-k3-r5-loader.hash > @@ -1,3 +1,3 @@ > # Locally computed: > -sha256 50b4482a505bc281ba8470c399a3c26e145e29b23500bc35c50debd7fa46bdf8 u-boot-2022.10.tar.bz2 Removing this hash means that defconfigs that still reference the 2022.10 version, no longer have a hash to validate the download against, which make it susceptible to CVE-2023-43608 [0] [1]. That was already the case for the two ti-am6?x defconfig in the the two previous patches, as they already used a custom kernel, a custm ATF, a custom u-boot: the hashes can't be checked for those versions, so the two ti am?x defconfigs already hit CVE-2023-43608. We already fixed another defconfig for a similar issue, see commit 9ebbfeff387 (configs/rock5b: add hash for custom kernel). Could you look into doing the same for those to TI am6?x defconfig, please? In the meantime, I kept the hash for 2022.10 for ti-k3-r5-loader (really, for uboot), to abvoid the issue at least for ti-k3-r5-loader. Speaking of that, by the way, ti-k3-r5-loader really is uboot, so I think that it should share: 1. the same DL_DIR: TI_K3_R5_LOADER_DL_SUBDIR = uboot 2. the same hash file: have ti-k3-r5-loader.hash be a symlink to uboot.hash (and have a xomment at the top of that hash file that it is shared and that old hashes should/can be kept) Do you think that makes sense? If so, would you like to look into it? [0] https://cve.mitre.org/cgi-bin/cvename.cgi?name=2023-43608 [1] https://talosintelligence.com/vulnerability_reports/TALOS-2023-1844 Regards, Yann E. MORIN. > +sha256 b99611f1ed237bf3541bdc8434b68c96a6e05967061f992443cb30aabebef5b3 u-boot-2024.01.tar.bz2 > sha256 8177f97513213526df2cf6184d8ff986c675afb514d4e68a404010521b880643 Licenses/gpl-2.0.txt > -- > 2.43.0 > > _______________________________________________ > buildroot mailing list > buildroot@buildroot.org > https://lists.buildroot.org/mailman/listinfo/buildroot
Hi Yann, On Tue, Mar 19, 2024 at 11:09:32PM +0100, Yann E. MORIN wrote: > Dario, All, > > On 2024-03-04 16:32 +0100, Dario Binacchi spake thusly: > > All in-tree configs with the ti-k3-r5 bootloader use a custom version, > > so this patch is mostly for the menuconfig default version > > > > Suggested-by: Romain Naour <romain.naour@smile.fr> > > Signed-off-by: Dario Binacchi <dario.binacchi@amarulasolutions.com> > [--SNIP--] > > diff --git a/boot/ti-k3-r5-loader/ti-k3-r5-loader.hash b/boot/ti-k3-r5-loader/ti-k3-r5-loader.hash > > index c5d1cb8e09f0..fbe5d215409d 100644 > > --- a/boot/ti-k3-r5-loader/ti-k3-r5-loader.hash > > +++ b/boot/ti-k3-r5-loader/ti-k3-r5-loader.hash > > @@ -1,3 +1,3 @@ > > # Locally computed: > > -sha256 50b4482a505bc281ba8470c399a3c26e145e29b23500bc35c50debd7fa46bdf8 u-boot-2022.10.tar.bz2 > > Removing this hash means that defconfigs that still reference the > 2022.10 version, no longer have a hash to validate the download against, > which make it susceptible to CVE-2023-43608 [0] [1]. > > That was already the case for the two ti-am6?x defconfig in the the two > previous patches, as they already used a custom kernel, a custm ATF, a > custom u-boot: the hashes can't be checked for those versions, so the > two ti am?x defconfigs already hit CVE-2023-43608. > > We already fixed another defconfig for a similar issue, see commit > 9ebbfeff387 (configs/rock5b: add hash for custom kernel). > > Could you look into doing the same for those to TI am6?x defconfig, > please? > > In the meantime, I kept the hash for 2022.10 for ti-k3-r5-loader > (really, for uboot), to abvoid the issue at least for ti-k3-r5-loader. > > Speaking of that, by the way, ti-k3-r5-loader really is uboot, so I > think that it should share: > > 1. the same DL_DIR: TI_K3_R5_LOADER_DL_SUBDIR = uboot > > 2. the same hash file: have ti-k3-r5-loader.hash be a symlink to > uboot.hash (and have a xomment at the top of that hash file that it > is shared and that old hashes should/can be kept) > The entire boot chain for TI K3 devices (like all of AM62x) comprising what's known as ti-k3-r5-loaer in Buildroot as well as U-Boot SPL/U-Boot [proper] should _always_ be built from the same U-Boot source commit, as this is how it's developed, tested, and used by pretty much everybody. So your suggestion to more closely tie those things together makes a lot of sense IMHO. -- Andreas Dannenberg Texas Instruments Inc > Do you think that makes sense? If so, would you like to look into it? > > [0] https://cve.mitre.org/cgi-bin/cvename.cgi?name=2023-43608 > [1] https://talosintelligence.com/vulnerability_reports/TALOS-2023-1844 > > Regards, > Yann E. MORIN. > > > +sha256 b99611f1ed237bf3541bdc8434b68c96a6e05967061f992443cb30aabebef5b3 u-boot-2024.01.tar.bz2 > > sha256 8177f97513213526df2cf6184d8ff986c675afb514d4e68a404010521b880643 Licenses/gpl-2.0.txt > > -- > > 2.43.0 > > > > _______________________________________________ > > buildroot mailing list > > buildroot@buildroot.org > > https://lists.buildroot.org/mailman/listinfo/buildroot > > -- > .-----------------.--------------------.------------------.--------------------. > | Yann E. MORIN | Real-Time Embedded | /"\ ASCII RIBBON | Erics' conspiracy: | > | +33 662 376 056 | Software Designer | \ / CAMPAIGN | ___ | > | +33 561 099 427 `------------.-------: X AGAINST | \e/ There is no | > | http://ymorin.is-a-geek.org/ | _/*\_ | / \ HTML MAIL | v conspiracy. | > '------------------------------^-------^------------------^--------------------'
Andreas, All, On 2024-03-19 21:18 -0500, Andreas Dannenberg via buildroot spake thusly: > On Tue, Mar 19, 2024 at 11:09:32PM +0100, Yann E. MORIN wrote: > > On 2024-03-04 16:32 +0100, Dario Binacchi spake thusly: > > > All in-tree configs with the ti-k3-r5 bootloader use a custom version, > > > so this patch is mostly for the menuconfig default version [--SNIP--] > > Speaking of that, by the way, ti-k3-r5-loader really is uboot, so I > > think that it should share: > > 1. the same DL_DIR: TI_K3_R5_LOADER_DL_SUBDIR = uboot > > 2. the same hash file: have ti-k3-r5-loader.hash be a symlink to > > uboot.hash (and have a xomment at the top of that hash file that it > > is shared and that old hashes should/can be kept) > The entire boot chain for TI K3 devices (like all of AM62x) comprising > what's known as ti-k3-r5-loaer in Buildroot as well as U-Boot SPL/U-Boot > [proper] should _always_ be built from the same U-Boot source commit, as > this is how it's developed, tested, and used by pretty much everybody. > So your suggestion to more closely tie those things together makes a lot > of sense IMHO. Ah, interesting, thanks for the feedback. So, it looks like for the situation for ti-k3-r5-loaer vs. U-Boot is very similar to the one for barebox: it can build a "base" barebox, and an "aux" barebox; they both share the same implementation (the barebox-package mini-infra), they each provide their own (def|.)config file, and they each have their own set of (Buildroot) options (the aux one has fewer options). So it looks like this is what we should have done for ti-k3-r5-loaer, no? Also, does it make sense to use ti-k3-r5-loaer without U-Boot? Regards, Yann E. MORIN.
Hi Yann, On Wed, Mar 20, 2024 at 07:14:06AM +0100, Yann E. MORIN wrote: > Andreas, All, > > On 2024-03-19 21:18 -0500, Andreas Dannenberg via buildroot spake thusly: > > On Tue, Mar 19, 2024 at 11:09:32PM +0100, Yann E. MORIN wrote: > > > On 2024-03-04 16:32 +0100, Dario Binacchi spake thusly: > > > > All in-tree configs with the ti-k3-r5 bootloader use a custom version, > > > > so this patch is mostly for the menuconfig default version > [--SNIP--] > > > Speaking of that, by the way, ti-k3-r5-loader really is uboot, so I > > > think that it should share: > > > 1. the same DL_DIR: TI_K3_R5_LOADER_DL_SUBDIR = uboot > > > 2. the same hash file: have ti-k3-r5-loader.hash be a symlink to > > > uboot.hash (and have a xomment at the top of that hash file that it > > > is shared and that old hashes should/can be kept) > > The entire boot chain for TI K3 devices (like all of AM62x) comprising > > what's known as ti-k3-r5-loaer in Buildroot as well as U-Boot SPL/U-Boot > > [proper] should _always_ be built from the same U-Boot source commit, as > > this is how it's developed, tested, and used by pretty much everybody. > > So your suggestion to more closely tie those things together makes a lot > > of sense IMHO. > > Ah, interesting, thanks for the feedback. > > So, it looks like for the situation for ti-k3-r5-loaer vs. U-Boot is > very similar to the one for barebox: it can build a "base" barebox, and > an "aux" barebox; they both share the same implementation (the > barebox-package mini-infra), they each provide their own (def|.)config > file, and they each have their own set of (Buildroot) options (the aux > one has fewer options). > > So it looks like this is what we should have done for ti-k3-r5-loaer, > no? I'm not familiar with barebox but what you are describing looks similar. Note that ti-k3-r5-loader (building the initial boot binary) is building for 32-bit ARMv7, and the next boot stages (U-Boot SPL, U-Boot) are all 64-bit ARMv8, so this might complicate any possible unification efforts. > Also, does it make sense to use ti-k3-r5-loaer without U-Boot? Yes, you could do "Falcon Boot" where the ti-k3-r5-loader would directly load the Linux kernel, greatly simplifing the boot flow and booting much MUCH faster. Actually it's a much-requested feature from our customers (you know, the real world use cases :) so I wrote a technical note [1] about that last year on how to set this up manually but it would be great if we could bring this into Buildroot as a package/option somehow at some point, after we get the base support accepted into the tree. [1] https://e2e.ti.com/support/processors-group/processors/f/processors-forum/1205638/faq-am625-how-to-boot-from-r5-u-boot-spl-directly-into-the-linux-kernel-skipping-a53-spl-and-a53-u-boot-falcon-mode -- Andreas Dannenberg Texas Instruments Inc > > Regards, > Yann E. MORIN. > > -- > .-----------------.--------------------.------------------.--------------------. > | Yann E. MORIN | Real-Time Embedded | /"\ ASCII RIBBON | Erics' conspiracy: | > | +33 662 376 056 | Software Designer | \ / CAMPAIGN | ___ | > | +33 561 099 427 `------------.-------: X AGAINST | \e/ There is no | > | http://ymorin.is-a-geek.org/ | _/*\_ | / \ HTML MAIL | v conspiracy. | > '------------------------------^-------^------------------^--------------------'
Hi Yann, On Tue, Mar 19, 2024 at 11:09 PM Yann E. MORIN <yann.morin.1998@free.fr> wrote: > > Dario, All, > > On 2024-03-04 16:32 +0100, Dario Binacchi spake thusly: > > All in-tree configs with the ti-k3-r5 bootloader use a custom version, > > so this patch is mostly for the menuconfig default version > > > > Suggested-by: Romain Naour <romain.naour@smile.fr> > > Signed-off-by: Dario Binacchi <dario.binacchi@amarulasolutions.com> > [--SNIP--] > > diff --git a/boot/ti-k3-r5-loader/ti-k3-r5-loader.hash b/boot/ti-k3-r5-loader/ti-k3-r5-loader.hash > > index c5d1cb8e09f0..fbe5d215409d 100644 > > --- a/boot/ti-k3-r5-loader/ti-k3-r5-loader.hash > > +++ b/boot/ti-k3-r5-loader/ti-k3-r5-loader.hash > > @@ -1,3 +1,3 @@ > > # Locally computed: > > -sha256 50b4482a505bc281ba8470c399a3c26e145e29b23500bc35c50debd7fa46bdf8 u-boot-2022.10.tar.bz2 > > Removing this hash means that defconfigs that still reference the > 2022.10 version, no longer have a hash to validate the download against, > which make it susceptible to CVE-2023-43608 [0] [1]. > > That was already the case for the two ti-am6?x defconfig in the the two > previous patches, as they already used a custom kernel, a custm ATF, a > custom u-boot: the hashes can't be checked for those versions, so the > two ti am?x defconfigs already hit CVE-2023-43608. > > We already fixed another defconfig for a similar issue, see commit > 9ebbfeff387 (configs/rock5b: add hash for custom kernel). > > Could you look into doing the same for those to TI am6?x defconfig, > please? Thanks for the info. Yes I will add a patch for this point in version 10 of the series. > > In the meantime, I kept the hash for 2022.10 for ti-k3-r5-loader > (really, for uboot), to abvoid the issue at least for ti-k3-r5-loader. > > Speaking of that, by the way, ti-k3-r5-loader really is uboot, so I > think that it should share: > > 1. the same DL_DIR: TI_K3_R5_LOADER_DL_SUBDIR = uboot > > 2. the same hash file: have ti-k3-r5-loader.hash be a symlink to > uboot.hash (and have a xomment at the top of that hash file that it > is shared and that old hashes should/can be kept) > > Do you think that makes sense? If so, would you like to look into it? I think like you that where possible it is better not to replicate code. This series has been ongoing since November 2023, started to fix the compilation for the HS_FS device for the ti_am62x_sk_defconfig configuration. During the review process, it has added additional patches (ti_am64x_sk_defconfig, and removal of the ti-k3-image-gen package) which still today have not allowed the series to be merged and therefore to fix the issue. So, I would prefer to address this aspect in a separate series from this one in order not to further slow it down. Do you agree? Thanks and regards, Dario > > [0] https://cve.mitre.org/cgi-bin/cvename.cgi?name=2023-43608 > [1] https://talosintelligence.com/vulnerability_reports/TALOS-2023-1844 > > Regards, > Yann E. MORIN. > > > +sha256 b99611f1ed237bf3541bdc8434b68c96a6e05967061f992443cb30aabebef5b3 u-boot-2024.01.tar.bz2 > > sha256 8177f97513213526df2cf6184d8ff986c675afb514d4e68a404010521b880643 Licenses/gpl-2.0.txt > > -- > > 2.43.0 > > > > _______________________________________________ > > buildroot mailing list > > buildroot@buildroot.org > > https://lists.buildroot.org/mailman/listinfo/buildroot > > -- > .-----------------.--------------------.------------------.--------------------. > | Yann E. MORIN | Real-Time Embedded | /"\ ASCII RIBBON | Erics' conspiracy: | > | +33 662 376 056 | Software Designer | \ / CAMPAIGN | ___ | > | +33 561 099 427 `------------.-------: X AGAINST | \e/ There is no | > | http://ymorin.is-a-geek.org/ | _/*\_ | / \ HTML MAIL | v conspiracy. | > '------------------------------^-------^------------------^--------------------'
Hi Yann, On Sun, Mar 24, 2024 at 05:22:33PM +0100, Dario Binacchi wrote: > Hi Yann, > > On Tue, Mar 19, 2024 at 11:09 PM Yann E. MORIN <yann.morin.1998@free.fr> wrote: > > > > Dario, All, > > > > On 2024-03-04 16:32 +0100, Dario Binacchi spake thusly: > > > All in-tree configs with the ti-k3-r5 bootloader use a custom version, > > > so this patch is mostly for the menuconfig default version > > > > > > Suggested-by: Romain Naour <romain.naour@smile.fr> > > > Signed-off-by: Dario Binacchi <dario.binacchi@amarulasolutions.com> > > [--SNIP--] > > > diff --git a/boot/ti-k3-r5-loader/ti-k3-r5-loader.hash b/boot/ti-k3-r5-loader/ti-k3-r5-loader.hash > > > index c5d1cb8e09f0..fbe5d215409d 100644 > > > --- a/boot/ti-k3-r5-loader/ti-k3-r5-loader.hash > > > +++ b/boot/ti-k3-r5-loader/ti-k3-r5-loader.hash > > > @@ -1,3 +1,3 @@ > > > # Locally computed: > > > -sha256 50b4482a505bc281ba8470c399a3c26e145e29b23500bc35c50debd7fa46bdf8 u-boot-2022.10.tar.bz2 > > > > Removing this hash means that defconfigs that still reference the > > 2022.10 version, no longer have a hash to validate the download against, > > which make it susceptible to CVE-2023-43608 [0] [1]. > > > > That was already the case for the two ti-am6?x defconfig in the the two > > previous patches, as they already used a custom kernel, a custm ATF, a > > custom u-boot: the hashes can't be checked for those versions, so the > > two ti am?x defconfigs already hit CVE-2023-43608. > > > > We already fixed another defconfig for a similar issue, see commit > > 9ebbfeff387 (configs/rock5b: add hash for custom kernel). > > > > Could you look into doing the same for those to TI am6?x defconfig, > > please? > > Thanks for the info. > Yes I will add a patch for this point in version 10 of the series. > > > > > In the meantime, I kept the hash for 2022.10 for ti-k3-r5-loader > > (really, for uboot), to abvoid the issue at least for ti-k3-r5-loader. > > > > Speaking of that, by the way, ti-k3-r5-loader really is uboot, so I > > think that it should share: > > > > 1. the same DL_DIR: TI_K3_R5_LOADER_DL_SUBDIR = uboot > > > > 2. the same hash file: have ti-k3-r5-loader.hash be a symlink to > > uboot.hash (and have a xomment at the top of that hash file that it > > is shared and that old hashes should/can be kept) > > > > Do you think that makes sense? If so, would you like to look into it? > > I think like you that where possible it is better not to replicate code. > This series has been ongoing since November 2023, started to fix the > compilation for the HS_FS device for the ti_am62x_sk_defconfig configuration. > During the review process, it has added additional patches > (ti_am64x_sk_defconfig, > and removal of the ti-k3-image-gen package) which still today have not > allowed the > series to be merged and therefore to fix the issue. > So, I would prefer to address this aspect in a separate series from > this one in order > not to further slow it down. I'd like to finish GPU support for AM6xx too and push this here, but as long as we don't have base support I'm kind of blocked on this. And that's probably just one example. I think as long as there are no regressions in what this series is trying to do why not agree to merge & iterate to get the base support out of the way. But definitely appreciating all your great feedback here for further improvement so please don't mis-interpret my comment. -- Andreas Dannenberg Texas Instruments Inc > Do you agree? > > Thanks and regards, > Dario > > > > [0] https://cve.mitre.org/cgi-bin/cvename.cgi?name=2023-43608 > > [1] https://talosintelligence.com/vulnerability_reports/TALOS-2023-1844 > > > > Regards, > > Yann E. MORIN. > > > > > +sha256 b99611f1ed237bf3541bdc8434b68c96a6e05967061f992443cb30aabebef5b3 u-boot-2024.01.tar.bz2 > > > sha256 8177f97513213526df2cf6184d8ff986c675afb514d4e68a404010521b880643 Licenses/gpl-2.0.txt > > > -- > > > 2.43.0 > > > > > > _______________________________________________ > > > buildroot mailing list > > > buildroot@buildroot.org > > > https://lists.buildroot.org/mailman/listinfo/buildroot > > > > -- > > .-----------------.--------------------.------------------.--------------------. > > | Yann E. MORIN | Real-Time Embedded | /"\ ASCII RIBBON | Erics' conspiracy: | > > | +33 662 376 056 | Software Designer | \ / CAMPAIGN | ___ | > > | +33 561 099 427 `------------.-------: X AGAINST | \e/ There is no | > > | http://ymorin.is-a-geek.org/ | _/*\_ | / \ HTML MAIL | v conspiracy. | > > '------------------------------^-------^------------------^--------------------' > > > > -- > > Dario Binacchi > > Senior Embedded Linux Developer > > dario.binacchi@amarulasolutions.com > > __________________________________ > > > Amarula Solutions SRL > > Via Le Canevare 30, 31100 Treviso, Veneto, IT > > T. +39 042 243 5310 > info@amarulasolutions.com > > www.amarulasolutions.com
diff --git a/boot/ti-k3-r5-loader/Config.in b/boot/ti-k3-r5-loader/Config.in index 8c8368a1a5a8..5f86c045c99f 100644 --- a/boot/ti-k3-r5-loader/Config.in +++ b/boot/ti-k3-r5-loader/Config.in @@ -16,7 +16,7 @@ choice here as it is used to build the main U-Boot package. config BR2_TARGET_TI_K3_R5_LOADER_LATEST_VERSION - bool "2022.10" + bool "2024.01" config BR2_TARGET_TI_K3_R5_LOADER_CUSTOM_VERSION bool "Custom version" @@ -60,7 +60,7 @@ endif config BR2_TARGET_TI_K3_R5_LOADER_VERSION string - default "2022.10" if BR2_TARGET_TI_K3_R5_LOADER_LATEST_VERSION + default "2024.01" if BR2_TARGET_TI_K3_R5_LOADER_LATEST_VERSION default BR2_TARGET_TI_K3_R5_LOADER_CUSTOM_VERSION_VALUE \ if BR2_TARGET_TI_K3_R5_LOADER_CUSTOM_VERSION default "custom" if BR2_TARGET_TI_K3_R5_LOADER_CUSTOM_TARBALL diff --git a/boot/ti-k3-r5-loader/ti-k3-r5-loader.hash b/boot/ti-k3-r5-loader/ti-k3-r5-loader.hash index c5d1cb8e09f0..fbe5d215409d 100644 --- a/boot/ti-k3-r5-loader/ti-k3-r5-loader.hash +++ b/boot/ti-k3-r5-loader/ti-k3-r5-loader.hash @@ -1,3 +1,3 @@ # Locally computed: -sha256 50b4482a505bc281ba8470c399a3c26e145e29b23500bc35c50debd7fa46bdf8 u-boot-2022.10.tar.bz2 +sha256 b99611f1ed237bf3541bdc8434b68c96a6e05967061f992443cb30aabebef5b3 u-boot-2024.01.tar.bz2 sha256 8177f97513213526df2cf6184d8ff986c675afb514d4e68a404010521b880643 Licenses/gpl-2.0.txt