board: ti: am43xx: Add TEE loading and firewall setup
authorAndrew F. Davis <afd@ti.com>
Mon, 10 Jul 2017 19:45:53 +0000 (14:45 -0500)
committerTom Rini <trini@konsulko.com>
Sun, 23 Jul 2017 02:22:45 +0000 (22:22 -0400)
Add support for loading a TEE and setting up firewalled regions to
AM43xx HS boards.

Signed-off-by: Andrew F. Davis <afd@ti.com>
board/ti/am43xx/board.c
configs/am43xx_hs_evm_defconfig

index 54f40e64a4560b433b7fceafc299ba1cca4c67fb..96032215a65030d6ee688ee7c08c20497cd395dc 100644 (file)
@@ -859,4 +859,11 @@ void board_fit_image_post_process(void **p_image, size_t *p_size)
 {
        secure_boot_verify_image(p_image, p_size);
 }
+
+void board_tee_image_process(ulong tee_image, size_t tee_size)
+{
+       secure_tee_install((u32)tee_image);
+}
+
+U_BOOT_FIT_LOADABLE_HANDLER(IH_TYPE_TEE, board_tee_image_process);
 #endif
index fb4bb037dd9f3686a553b501ec3999e0fe3e4404..0cb2ee90add1e7f3939256c64940ad116569d522 100644 (file)
@@ -4,6 +4,9 @@ CONFIG_TI_COMMON_CMD_OPTIONS=y
 CONFIG_SYS_MALLOC_F_LEN=0x2000
 CONFIG_AM43XX=y
 CONFIG_TI_SECURE_DEVICE=y
+CONFIG_TI_SECURE_EMIF_REGION_START=0xbdb00000
+CONFIG_TI_SECURE_EMIF_TOTAL_REGION_SIZE=0x02000000
+CONFIG_TI_SECURE_EMIF_PROTECTED_REGION_SIZE=0x01c00000
 CONFIG_ISW_ENTRY_ADDR=0x403018e0
 CONFIG_SPL_STACK_R_ADDR=0x82000000
 CONFIG_DEFAULT_DEVICE_TREE="am437x-gp-evm"