ChanServ changed the topic of #linux-sunxi to: Allwinner/sunxi development - Did you try looking at our wiki? https://linux-sunxi.org - Don't ask to ask. Just ask and wait for an answer! - This channel is logged at https://oftc.irclog.whitequark.org/linux-sunxi
<lschmid> So, okay. I've got signatures somewhat working now. The only issue is that i need to use binman to put the public key into spl. But spl is signed by mkimage before binman gets to it
<lschmid> apritzel: Any idea how I could have either mkimage sign the spl after binman has gotten to it, or run mkimage from within binman to sign it
<apritzel> but that's a generic issue, nothing Allwinner specific, isn't it?
<lschmid> Maybe, yes. But I may have just figured out how to do it...
<lschmid> It finally works! So yes, removing SPL_DM dependency and adding the DM-if to rsa works fine. You need a lot of changes in the sunxi-u-boot.dtsi for the hashes, signature and spl public key injection
<apritzel> hey, that's great, thanks for figuring this out. Can you put this in some patches, so that others can benefit? The request for a signed boot chain comes up every now and then
<lschmid> I already tried to do this as cleanly as possible. I'll have a go at upstreaming this when I get to upstreaming all the SoM support stuff
<lschmid> Primarily I'd like to wait for the kernel to have the dt's so that I don't need to have them in repos twice (if thats a good reason)
<apritzel> well, it sounds like enabling the SPL signature support is completely board or SoC agnostic, that's pretty much fixing a gap in the Allwinner platform configuration
<apritzel> I have the secure register setup in proper patches now, but need to somehow test the H3 changes I made. Will probably use my secure Pine64 board for that, with some hacks to run it in 32-bit ...
<lschmid> We'll I've just had a look and yes it seems that I could submit this without any large dependencies on my side. I'll probably see about making a clean series of this the next few days. If you don't mind, could you maybe have a look beforehand to catch some things early? It's currently only a single commit but I'd split up the DM-Depenency fix of RSA and the actual changes to the dtsi later. Heres the current commit: https://gitlab.com/netcube-sy
<lschmid> stems-austria/u-boot/-/commit/e62786d5dd6d9c81fe84f34f847ca84a6a962927
<lschmid> And if you need anyone to test your patches on the T113-s3 just let me know
apritzel has quit [Ping timeout: 480 seconds]
ftg has quit [Read error: Connection reset by peer]
bpye_ has quit [Remote host closed the connection]
hexdump01 has joined #linux-sunxi
skylar has joined #linux-sunxi
skylar has quit [Remote host closed the connection]
hexdump0815 has quit [Ping timeout: 480 seconds]
cnxsoft has joined #linux-sunxi
JohnDoe_71Rus has joined #linux-sunxi
gsz has joined #linux-sunxi
apritzel has joined #linux-sunxi
gsz has quit [Ping timeout: 480 seconds]
ungeskriptet has quit [Ping timeout: 480 seconds]
ungeskriptet has joined #linux-sunxi
apritzel has quit [Ping timeout: 480 seconds]
Sensu_Be1 has quit [Read error: Connection reset by peer]
Sensu_Bean has joined #linux-sunxi
Schimsalabim has quit [Ping timeout: 480 seconds]
Schimsalabim has joined #linux-sunxi
gsz has joined #linux-sunxi
gsz has quit [Ping timeout: 480 seconds]
Schimsalabim has quit [Ping timeout: 480 seconds]
Schimsalabim has joined #linux-sunxi
Schimsalabim has quit [Read error: Connection reset by peer]
Schimsalabim has joined #linux-sunxi
gsz has joined #linux-sunxi
gsz has quit [Ping timeout: 480 seconds]
cnxsoft has quit [Ping timeout: 480 seconds]
Schimsalabim has quit [Ping timeout: 480 seconds]
Schimsalabim has joined #linux-sunxi
gsz has joined #linux-sunxi
dsimic is now known as Guest23869
dsimic has joined #linux-sunxi
Guest23869 has quit [Ping timeout: 480 seconds]
Sensu_Be1 has joined #linux-sunxi
gsz has quit [Ping timeout: 480 seconds]
Sensu_Bean has quit [Ping timeout: 480 seconds]
ftg has joined #linux-sunxi
maz_ has joined #linux-sunxi
maz_ has quit []
bauen1 has quit [Ping timeout: 480 seconds]
maz_ has joined #linux-sunxi
maz_ has quit []
vagrantc has joined #linux-sunxi
warpme has joined #linux-sunxi
pitillo has quit []
pitillo has joined #linux-sunxi
warpme has quit []
hazardchem has quit [Read error: Connection reset by peer]
hazardchem has joined #linux-sunxi
gsz has joined #linux-sunxi
hazardchem has quit [Read error: Connection reset by peer]
hazardchem has joined #linux-sunxi
Sensu_Bean has joined #linux-sunxi
Sensu_Be1 has quit [Read error: Connection reset by peer]
wingrime-ww has quit [Quit: WeeChat 4.7.0]
wingrime-ww has joined #linux-sunxi
JohnDoe_71Rus has quit [Quit: KVIrc KVIrc Quasar 5.2.6, revision: 5.2.6+git-7614-6f23368f1, build type: debug, sources date: 20160102, built on: 2025-03-30 13:34:35 UTC 5.2.6+git-7614-]
Schimsalabim has quit [Read error: Connection reset by peer]
Schimsalabim has joined #linux-sunxi
apritzel has joined #linux-sunxi
Sensu_Be1 has joined #linux-sunxi
Sensu_Bean has quit [Ping timeout: 480 seconds]
Sensu_Bean has joined #linux-sunxi
Sensu_Be1 has quit [Read error: Connection reset by peer]
Sensu_Be1 has joined #linux-sunxi
Sensu_Bean has quit [Ping timeout: 480 seconds]
gsz has quit [Ping timeout: 480 seconds]
Schimsalabim has quit [Ping timeout: 480 seconds]
Schimsalabim has joined #linux-sunxi
ftg has quit [Read error: Connection reset by peer]