Skip to content

Zephyr signed fit uboot cortex a - #3790

Merged
jasonrandrews merged 14 commits into
ArmDeveloperEcosystem:mainfrom
RoyAc6:zephyr-signed-fit-uboot-cortex-a
Oct 5, 2026
Merged

jasonrandrews merged 14 commits into
ArmDeveloperEcosystem:mainfrom
RoyAc6:zephyr-signed-fit-uboot-cortex-a

Conversation

@RoyAc6

@RoyAc6 RoyAc6 commented Sep 23, 2026 •

Copy link
Copy Markdown
Contributor

Before submitting a pull request for a new Learning Path, please review Create a Learning Path

  • I have reviewed Create a Learning Path

Please do not include any confidential information in your contribution. This includes confidential microarchitecture details and unannounced product information.

  • I have checked my contribution for confidential information

By submitting this pull request, I confirm that you can use, modify, copy, and redistribute this contribution, under the terms of the Creative Commons Attribution 4.0 International License.

… Cortex-A

New Learning Path under embedded-and-microcontrollers, with the TI AM62L EVM as
the worked example: sign a Zephyr image into a FIT, build the public key into
U-Boot through CONFIG_DEVICE_TREE_INCLUDES, add a boot command that starts
Zephyr only after bootm verifies it, and prove it on the board with a wrong-key
and a tampered image. Adds Roy Jamil to the contributors list.
…sal tests out, redo diagrams

- Page 3 now uses Workbench for Zephyr in VS Code: import the AArch64 toolchain,
  add a Zephyr 4.4.2 workspace (Texas Instruments template), create and build
  the application, with annotated screenshots of each wizard and of the build.
- New page 7 holds the optional tests: second image signed with key-b, tampered
  copy, fit_check_sign on both, and the two refusals on the board. Pages 3-6 keep
  only the trusted image; the production review is now page 8.
- Page 1 shows a generic Cortex-A boot chain first, then the AM62L one; the
  diagrams use Arial and the AM62L labels match the binman packaging (BL1+TIFS,
  BL31+OP-TEE+SPL).
- Prerequisites point at the Workbench for Zephyr Learning Path; further reading
  links the three Ac6 courses, and page 8 ends with a short pointer to them.
- Cut about a quarter of the prose on every page: tool-option explanations,
  repeated justifications and asides are gone; the reasons that prevent
  mistakes stay, one sentence each.
- The four Workbench for Zephyr screenshots no longer show the Windows user
  name in paths, and the activity bar is cropped out.
- The fit_check_sign, mkimage and board-run outputs are complete again:
  no line is replaced by an ellipsis.
- Every output block is followed by a "Lines to look for" call-out that
  names the lines carrying the verdict, then the explanation of those lines
  as it stood before the prose was lightened.
- env.sh opens with a board block (BOARD, ZEPHYR_ADDR, FIT_ADDR, BOOT_DEV,
  UBOOT_DEFCONFIG) and a vendor SDK block; the .its, the CONFIG_PREBOOT
  fragment and the make lines take their values from it. The expanded
  fragment is byte-identical to the former literal one.
- Each page keeps a generic section first and marks the TI-specific parts
  (SDK install, card image, boot switches, console, binman make variables)
  as AM62L EVM sections. HS-FS and HS-SE are TI's names for the development
  and production security states, given once on the first page.
- The porting section on the last page is a checklist that maps onto the
  env.sh blocks.
- Review fixes: the ROM/partition claims are no longer stated for every
  Cortex-A SoC; any key passes in the development state; the wrong-key
  mkimage output is shown in full; timestamps agree across pages.
- The boot log, the trusted boot and the two refusals on pages 6 and 7 now
  reproduce what the EVM printed (Tera Term recording of 11 September):
  TF-A and SPL lines, the U-Boot banner with SoC AM62LX SR1.1 HS-FS, the
  real read times and FIT timestamp, and Zephyr's second-core line.
- The demo-only echo lines of the recording are replaced by the echo the
  Learning Path's own boot command prints.
- Page 8 quotes the same banner line.
…boxes

- The range brackets in both diagrams now open downwards, towards the boxes
  they group, and start and end exactly on those boxes' edges; the blue
  bracket no longer starts in the gap before the Zephyr box.
- Bracket labels are centred on their bracket and no wider than it.
- The generic diagram names who checks each box under that box, as the
  AM62L one does, instead of under the gaps between boxes.
- The grey labels say what TI's documentation says: before the key is
  fused, any key passes.
- The prerequisites link the extension's Visual Studio Marketplace page.
- The setup page links both, in the same sentence form as the published
  Workbench for Zephyr Learning Path.
- The Zephyr build page links the Workbench for Zephyr site where the
  walkthrough starts.
- About 30% less prose; every command and output a reader runs or checks
  is still there.
- Each idea is explained once: the security states on the production page,
  the required-signature rule on the boot chain page, the fail-closed &&
  chain on the U-Boot page.
- The boot switch section keeps the SW3 setting; the full pincount setting
  is a link in the troubleshooting list.
- env.sh carries a comment per board value instead of two paragraphs.
- Removed the branch-byte check, which the header magic check covers, the
  mkimage -l tip and a duplicate signature-node block.
The Learning Path needed a board. It now runs on the TI AM62L EVM or in
QEMU, as one generic story with tabs where the two targets differ.

- page 1 gains a comparison table and tabs the target-specific chain
- page 2 writes env-am62l.sh or env-qemu.sh and takes the U-Boot source
  from the TI SDK or from the U-Boot project
- pages 4 and 5 use UBOOT_CC, and page 5 tabs how the key reaches the
  control device tree: CONFIG_DEVICE_TREE_INCLUDES on the EVM, a dumped
  QEMU device tree merged with signature.dtsi and passed with EXT_DTB
- 6-boot-the-board.md becomes 6-boot-the-target.md, "Boot the target":
  the vendor card image or a 64 MiB disk image, the board or QEMU
- page 7 uses BOOT_IMG, so its commands are identical on both targets
- the Add Application screenshot gains a QEMU call-out

Page 8 drops the "what you've proved" framing: a Summary section says
what U-Boot checks with key-a and what the stages below it accept, the
boot-path audit table is gone, and the closing section says what to
change next instead of listing courses.

The FIT signature diagram loses its failure-modes box, which repeated
messages the test page already shows.

The QEMU track was run end to end with unpatched U-Boot 2025.07: trusted
boot, wrong-key refusal and tampered-image refusal.
Every page now presents QEMU first and the AM62L EVM as the same work on
hardware: the comparison table, all nine tab blocks, the environment
lines, the prerequisites and the board lists. Where an output block is
the board's, the text now says so, and page 3 warns that the Workbench
screenshots were captured with the EVM selected.

Also corrects the name of TI's tool: the AM62L uses Keywriter Lite.
@jasonrandrews
jasonrandrews merged commit 6b164c9 into ArmDeveloperEcosystem:main Oct 5, 2026
2 checks passed
@anupras-mohapatra-arm anupras-mohapatra-arm added ready_to_publish Ready for final review and publish and removed editorial_review labels Oct 6, 2026
@jasonrandrews jasonrandrews added publish and removed ready_to_publish Ready for final review and publish labels Oct 7, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

3 participants