]> git.ipfire.org Git - thirdparty/u-boot.git/commitdiff
arm: dts: k3-am64x-binman: Configure firewall for ATF/OPTEE
authorSuhaas Joshi <s-joshi@ti.com>
Tue, 27 Jan 2026 08:16:51 +0000 (13:46 +0530)
committerTom Rini <trini@konsulko.com>
Sat, 7 Feb 2026 17:50:06 +0000 (11:50 -0600)
Add firewall configurations to protect ATF and OP-TEE memory regions
from non-secure reads and writes in AM64x.

Signed-off-by: Suhaas Joshi <s-joshi@ti.com>
arch/arm/dts/k3-am64x-binman.dtsi

index 32e47a3f68888f0b70f0a7b38c38e2e413906f82..f3c7f2c939d9b291ed2af6a01f706ece99c03a17 100644 (file)
                        #address-cells = <1>;
 
                        images {
+                               atf {
+                                       ti-secure {
+                                               auth-in-place = <0xa02>;
+
+                                               firewall-24-5 {
+                                                       insert-template = <&firewall_armv8_atf_fg>;
+                                                       id = <24>;
+                                                       region = <5>;
+                                               };
+                                       };
+                               };
+
+                               tee {
+                                       ti-secure {
+                                               auth-in-place = <0xa02>;
+
+                                               firewall-1-0 {
+                                                       insert-template = <&firewall_bg_3>;
+                                                       id = <1>;
+                                                       region = <0>;
+                                               };
+
+
+                                               firewall-1-1 {
+                                                       insert-template = <&firewall_armv8_optee_fg>;
+                                                       id = <1>;
+                                                       region = <1>;
+                                               };
+                                       };
+                               };
+
                                dm {
                                        blob-ext {
                                                filename = "/dev/null";