From patchwork Fri May 19 10:32:13 2023 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Masahisa Kojima X-Patchwork-Id: 683902 Delivered-To: patch@linaro.org Received: by 2002:a5d:4e01:0:0:0:0:0 with SMTP id p1csp853445wrt; Fri, 19 May 2023 03:34:14 -0700 (PDT) X-Google-Smtp-Source: ACHHUZ7ztPqbJL3Q7Vdu0IcjWrBMVQTeL0eU2jVu8kN8Enrxm5URrD/CSYQzfeuLLN1nXvFlpGuv X-Received: by 2002:a17:903:1111:b0:1a2:8c7e:f310 with SMTP id n17-20020a170903111100b001a28c7ef310mr2713911plh.35.1684492454314; Fri, 19 May 2023 03:34:14 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1684492454; cv=none; d=google.com; s=arc-20160816; b=hyyCKIcKsDYdgdWA4Qe4XjzegavlfIvwSKIAJ/y/3sKGoMy8F9tBqX56d0vabR07Tg HbmebfGtBV1YIJDFgnY0W7WjcV8Yw07FUcf3g08K5vyFuQ0WTG+Fx6tMpwMRRAM/+F76 itgHUBAL2xzgoe2O0XNkqunHI+VtSiT+PUUeORbjOsOKupd4zr1PFL8cPBMJPP/6yvI9 MqdP7ourtocqaz576tBIE7BpQr65nnC2+kyzK4R8O9qlxbXkBvaYlREc8dihTpco4cP6 HCmLmyyv5jgRG4uMXMqnisS7W2n396Qip4WaWv8POWmfSHNjYkg4VtFuyO7cMtu6XsvC 2x2w== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=sender:errors-to:list-subscribe:list-help:list-post:list-archive :list-unsubscribe:list-id:precedence:content-transfer-encoding :mime-version:references:in-reply-to:message-id:date:subject:cc:to :from:dkim-signature; bh=N4BJBX01dzwodMzXdwvK9cB8Al9t6G1fXCXpWPWmfZE=; b=urOJS5UgL1rg8DOMvJeD2D1LG1JYM9UOKgZEDCoua7ineG2d6WK0WDxDpHyL8Y2TuV 6CLZHzr5GyA44NUhFOfoDfp+hjXoK7Al4u+C2X/D1kUdZnHJ/Rh0cxTHXyYvMHtWxLYa +N4zeOfRxyu2M3vLRPT9KwuDSeZtW4LeiC2kiMQNgPFbhwAN+/c/Jje4JJZNU+K5g/IL /7x+FdTkxFfcMjKDU8ulSZXuSUG3VTvRyC5uLjULj0yNIfjYe7MunfsnvuL9CRoNMR6c 8vEdYnajscYhPQXMt42LuwpdaetVlVhzlmd+22GEjxEl9Hm4LlJHBpK8uDtq3uprp7rt /1Zg== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@linaro.org header.s=google header.b="n/EuoC5v"; spf=pass (google.com: domain of u-boot-bounces@lists.denx.de designates 2a01:238:438b:c500:173d:9f52:ddab:ee01 as permitted sender) smtp.mailfrom=u-boot-bounces@lists.denx.de; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=linaro.org Return-Path: Received: from phobos.denx.de (phobos.denx.de. [2a01:238:438b:c500:173d:9f52:ddab:ee01]) by mx.google.com with ESMTPS id h8-20020a170902ac8800b001adf24718c1si3415270plr.256.2023.05.19.03.34.13 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 19 May 2023 03:34:14 -0700 (PDT) Received-SPF: pass (google.com: domain of u-boot-bounces@lists.denx.de designates 2a01:238:438b:c500:173d:9f52:ddab:ee01 as permitted sender) client-ip=2a01:238:438b:c500:173d:9f52:ddab:ee01; Authentication-Results: mx.google.com; dkim=pass header.i=@linaro.org header.s=google header.b="n/EuoC5v"; spf=pass (google.com: domain of u-boot-bounces@lists.denx.de designates 2a01:238:438b:c500:173d:9f52:ddab:ee01 as permitted sender) smtp.mailfrom=u-boot-bounces@lists.denx.de; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=linaro.org Received: from h2850616.stratoserver.net (localhost [IPv6:::1]) by phobos.denx.de (Postfix) with ESMTP id C9A36862F1; Fri, 19 May 2023 12:33:12 +0200 (CEST) Authentication-Results: phobos.denx.de; dmarc=pass (p=none dis=none) header.from=linaro.org Authentication-Results: phobos.denx.de; spf=pass smtp.mailfrom=u-boot-bounces@lists.denx.de Authentication-Results: phobos.denx.de; dkim=pass (2048-bit key; unprotected) header.d=linaro.org header.i=@linaro.org header.b="n/EuoC5v"; dkim-atps=neutral Received: by phobos.denx.de (Postfix, from userid 109) id 0AAC0862CB; Fri, 19 May 2023 12:33:07 +0200 (CEST) X-Spam-Checker-Version: SpamAssassin 3.4.2 (2018-09-13) on phobos.denx.de X-Spam-Level: X-Spam-Status: No, score=-2.1 required=5.0 tests=BAYES_00,DKIM_SIGNED, DKIM_VALID,DKIM_VALID_AU,DKIM_VALID_EF,SPF_HELO_NONE,SPF_PASS, T_SCC_BODY_TEXT_LINE autolearn=ham autolearn_force=no version=3.4.2 Received: from mail-pj1-x102b.google.com (mail-pj1-x102b.google.com [IPv6:2607:f8b0:4864:20::102b]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits)) (No client certificate requested) by phobos.denx.de (Postfix) with ESMTPS id E434781DCF for ; Fri, 19 May 2023 12:33:02 +0200 (CEST) Authentication-Results: phobos.denx.de; dmarc=pass (p=none dis=none) header.from=linaro.org Authentication-Results: phobos.denx.de; spf=pass smtp.mailfrom=masahisa.kojima@linaro.org Received: by mail-pj1-x102b.google.com with SMTP id 98e67ed59e1d1-2533a03388dso2162337a91.2 for ; Fri, 19 May 2023 03:33:02 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linaro.org; s=google; t=1684492381; x=1687084381; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to; bh=N4BJBX01dzwodMzXdwvK9cB8Al9t6G1fXCXpWPWmfZE=; b=n/EuoC5vfFRuIUoTRscsvH0e1MDT6SJoqJ120p+AYnEz6UVotD5mfc05RcUrr2uB7j 6l+BMQSmKVNWbjfGmoFHfZWDajFcpMIhTTa0Xrxp9WzcXPUoNZjjjNYmVntL0ccm+2mY 57+Ua78UMXVHhC7Lkmdzjg7WmAdCHQJE0GF7nnkB4R/QX7ousITWbl50Vv6iz/HfH0Dm JJpcLv7wOFwy/4fyOKbokt+HH36G/4DKQiaCLmyeAOV09XMlbtastZ+hRkpTchGdeTOi +IteBbz+GnnvP5L+0BwWlMESa/BWRKoTyHSXkK30ZPyW6YQEJtSxt0oM5i+K47JeLDz4 82Zg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20221208; t=1684492381; x=1687084381; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to; bh=N4BJBX01dzwodMzXdwvK9cB8Al9t6G1fXCXpWPWmfZE=; b=CRjkwj/HWld3rsME55+bL1CoG1kkVwNY4+7drEgHc1gA77PiCs18H5Q/Z37NjkRmy5 D86cQLMWGrhqFR7vssrYPxWUy4K2higPazPV9ftKIhrrTOfq5DcQCD8sbQHN0h9OPgLC OOU9bVfuxcvnv7QI6O3sHrUwSr0J8vWgF+8SC20W9XNalZhT4tan+App1c/tqvM9XZqa kMKrNac0WVaHQeAJTFN23eFpM9LuJq4PRpAwtWj0BcN5upkUW3HtuUSQ2rqQagkyFpB7 b35xR6sAuWQhYIs2Tuh9Q4/MW6ePhMIr6yrUNy/0Mrjlw8v46/o+EYGdJHhgVnN8crBQ ZiHw== X-Gm-Message-State: AC+VfDzC9tlxUX1O5fgkhlsNSoBBISQnZVWGd+dzHL738/rcv5XzlW6K X6/prS4ouAgiom12Ckj1YFa9P5NlW7TqZV4ViLA= X-Received: by 2002:a17:90b:194:b0:253:8abb:b613 with SMTP id t20-20020a17090b019400b002538abbb613mr820169pjs.46.1684492380912; Fri, 19 May 2023 03:33:00 -0700 (PDT) Received: from ubuntu-SVE15129CJS.. ([240d:1a:cf7:5800:8e72:6c60:18e6:c4c4]) by smtp.gmail.com with ESMTPSA id r13-20020a17090a940d00b0025352448ba9sm1195870pjo.0.2023.05.19.03.32.59 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 19 May 2023 03:33:00 -0700 (PDT) From: Masahisa Kojima To: u-boot@lists.denx.de Cc: Heinrich Schuchardt , Ilias Apalodimas , Simon Glass , Takahiro Akashi , Masahisa Kojima Subject: [PATCH v6 7/8] doc: uefi: add firmware versioning documentation Date: Fri, 19 May 2023 19:32:13 +0900 Message-Id: <20230519103214.1239656-8-masahisa.kojima@linaro.org> X-Mailer: git-send-email 2.34.1 In-Reply-To: <20230519103214.1239656-1-masahisa.kojima@linaro.org> References: <20230519103214.1239656-1-masahisa.kojima@linaro.org> MIME-Version: 1.0 X-BeenThere: u-boot@lists.denx.de X-Mailman-Version: 2.1.39 Precedence: list List-Id: U-Boot discussion List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: u-boot-bounces@lists.denx.de Sender: "U-Boot" X-Virus-Scanned: clamav-milter 0.103.8 at phobos.denx.de X-Virus-Status: Clean This commit describes the procedure to add the firmware version into the capsule file. Signed-off-by: Masahisa Kojima --- Newly created in v6 doc/develop/uefi/uefi.rst | 29 +++++++++++++++++++++++++++++ 1 file changed, 29 insertions(+) diff --git a/doc/develop/uefi/uefi.rst b/doc/develop/uefi/uefi.rst index ffe25ca231..efab0fc7b1 100644 --- a/doc/develop/uefi/uefi.rst +++ b/doc/develop/uefi/uefi.rst @@ -510,6 +510,35 @@ where signature.dts looks like:: }; }; +Enabling Firmware Versioning +**************************** + +The UEFI specification does not define the firmware versioning mechanism. +EDK II reference implementation inserts the FMP Payload Header right before +the payload. It coutains the fw_version and lowest supported version, +EDK II reference implementation uses these information to implement the +firmware versioning and anti-rollback protection, the firmware version and +lowest supported version is stored into EFI non-volatile variable. + +In U-Boot, the firmware versioning is implemented utilizing +the FMP Payload Header same as EDK II reference implementation, +reads the FMP Payload Header and stores the firmware version into +"FmpStateXXXX" EFI non-volatile variable. XXXX indicates the image index, +since FMP protocol handles multiple image indexes. + + +1. Run the following command to add firmware version into the capsule file + +.. code-block:: console + + $ mkeficapsule --monotonic-count 1 \ + --private-key CRT.key \ + --certificate CRT.crt \ + --index 1 --instance 0 \ + --fw-version 5 \ + [--fit | --raw | --guid + Executing the boot manager ~~~~~~~~~~~~~~~~~~~~~~~~~~