]> git.ipfire.org Git - thirdparty/u-boot.git/commitdiff
arm: dts: k3-am642-phycore-binman: Configure firewall for ATF/OPTEE
authorSuhaas Joshi <s-joshi@ti.com>
Tue, 27 Jan 2026 08:16:52 +0000 (13:46 +0530)
committerTom Rini <trini@konsulko.com>
Sat, 7 Feb 2026 17:50:06 +0000 (11:50 -0600)
Add firewall configurations to protect ATF and OP-TEE memory regions
from non-secure read's and write's in Phycore AM64 SOM.

Signed-off-by: Suhaas Joshi <s-joshi@ti.com>
arch/arm/dts/k3-am642-phycore-som-binman.dtsi

index 966905bd64db98742eb131b7d3eeb5a51ca14889..07cb79fd04a30a050dd061e94ae0c00bc31c06cc 100644 (file)
                        #address-cells = <1>;
 
                        images {
+                               atf {
+                                       ti-secure {
+                                               auth-in-place = <0xa02>;
+
+                                               firewall-24-5 {
+                                                       insert-template = <&firewall_armv8_atf_fg>;
+                                                       id = <24>;
+                                                       region = <5>;
+                                               };
+                                       };
+                               };
+
+                               tee {
+                                       ti-secure {
+                                               auth-in-place = <0xa02>;
+
+                                               firewall-1-0 {
+                                                       insert-template = <&firewall_bg_3>;
+                                                       id = <1>;
+                                                       region = <0>;
+                                               };
+
+
+                                               firewall-1-1 {
+                                                       insert-template = <&firewall_armv8_optee_fg>;
+                                                       id = <1>;
+                                                       region = <1>;
+                                               };
+                                       };
+                               };
+
                                dm {
                                        blob-ext {
                                                filename = "/dev/null";