]> git.ipfire.org Git - thirdparty/u-boot.git/commitdiff
arm: dts: k3-am62p-binman: Configure firewall for ATF/OPTEE
authorSuhaas Joshi <s-joshi@ti.com>
Tue, 27 Jan 2026 08:16:47 +0000 (13:46 +0530)
committerTom Rini <trini@konsulko.com>
Sat, 7 Feb 2026 17:50:06 +0000 (11:50 -0600)
Add firewall configurations to protect ATF and OP-TEE memory regions
from non-secure reads and writes in AM62P.

Signed-off-by: Suhaas Joshi <s-joshi@ti.com>
arch/arm/dts/k3-am62p-sk-binman.dtsi

index e1443d6226b8f060219ddd26a45744b871889c0a..603487341d26a54be0cff57a3a2c7a3ab155d2ae 100644 (file)
 
                fit {
                        images {
+                               atf {
+                                       ti-secure {
+                                               auth-in-place = <0xa02>;
+
+                                               firewall-1-0 {
+                                                       insert-template = <&firewall_bg_3>;
+                                                       id = <1>;
+                                                       region = <0>;
+                                               };
+
+                                               firewall-1-1 {
+                                                       insert-template = <&firewall_armv8_atf_fg>;
+                                                       id = <1>;
+                                                       region = <1>;
+                                               };
+
+                                       };
+                               };
+
+                               tee {
+                                       ti-secure {
+                                               auth-in-place = <0xa02>;
+
+                                               firewall-1-2 {
+                                                       insert-template = <&firewall_armv8_optee_fg>;
+                                                       id = <1>;
+                                                       region = <2>;
+                                               };
+
+                                       };
+                               };
+
                                tifsstub-hs {
                                        description = "TIFSSTUB";
                                        type = "firmware";