<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Secure u-boot issues iMX8M Nano in i.MX Processors</title>
    <link>https://community.nxp.com/t5/i-MX-Processors/Secure-u-boot-issues-iMX8M-Nano/m-p/1506618#M193892</link>
    <description>&lt;P&gt;Hello Harvey&lt;/P&gt;&lt;P&gt;We manage do to it, I will upload tutorial here but issue is when I erase eMMC I can't directly flash it only via SD card and I used 7 SD and it is always same story:&lt;/P&gt;&lt;P&gt;Device 0: unknown device&lt;BR /&gt;switch to partitions #0, OK&lt;BR /&gt;mmc1 is current device&lt;BR /&gt;Scanning mmc 1:1...&lt;BR /&gt;Error reading cluster&lt;BR /&gt;** Unable to read file /imx8mn-evk.dtb **&lt;BR /&gt;Failed to load '/imx8mn-evk.dtb'&lt;BR /&gt;** No partition table - mmc 1 **&lt;BR /&gt;** No partition table - mmc 1 **&lt;BR /&gt;libfdt fdt_check_header(): FDT_ERR_BADMAGIC&lt;BR /&gt;Scanning disk mmc@30b50000.blk...&lt;BR /&gt;** fs_devread read error - block&lt;BR /&gt;Failed to mount ext2 filesystem...&lt;BR /&gt;** Unrecognized filesystem type **&lt;BR /&gt;Scanning disk mmc@30b60000.blk...&lt;BR /&gt;** Unrecognized filesystem type **&lt;BR /&gt;Found 2 disks&lt;BR /&gt;No EFI system partition&lt;BR /&gt;adv7535_mipi2hdmi adv7535@3d: Can't find cec device id=0x3c&lt;BR /&gt;fail to probe panel device adv7535@3d&lt;BR /&gt;mxs_video lcd-controller@32e00000: failed to get any video link display timings&lt;BR /&gt;ERROR: invalid device tree&lt;BR /&gt;** No partition table - mmc 1 **&lt;BR /&gt;switch to partitions #0, OK&lt;BR /&gt;mmc2(part 0) is current device&lt;BR /&gt;** No partition table - mmc 2 **&lt;BR /&gt;Running BSP bootcmd ...&lt;BR /&gt;switch to partitions #0, OK&lt;BR /&gt;mmc1 is current device&lt;BR /&gt;Failed to load 'boot.scr'&lt;BR /&gt;Error reading cluster&lt;BR /&gt;** Unable to read file Image **&lt;BR /&gt;Failed to load 'Image'&lt;BR /&gt;Booting from net ...&lt;BR /&gt;ethernet@30be0000 Waiting for PHY auto negotiation to complete......................................... TIMEOUT !&lt;BR /&gt;Could not initialize PHY ethernet@30be0000&lt;BR /&gt;BOOTP broadcast 1&lt;BR /&gt;BOOTP broadcast 2&lt;BR /&gt;BOOTP broadcast 3&lt;BR /&gt;BOOTP broadcast 4&lt;BR /&gt;BOOTP broadcast 5&lt;BR /&gt;BOOTP broadcast 6&lt;BR /&gt;BOOTP broadcast 7&lt;BR /&gt;BOOTP broadcast 8&lt;BR /&gt;BOOTP broadcast 9&lt;BR /&gt;BOOTP broadcast 10&lt;BR /&gt;BOOTP broadcast 11&lt;BR /&gt;BOOTP broadcast 12&lt;BR /&gt;BOOTP broadcast 13&lt;BR /&gt;BOOTP broadcast 14&lt;BR /&gt;BOOTP broadcast 15&lt;BR /&gt;BOOTP broadcast 16&lt;BR /&gt;BOOTP broadcast 17&lt;/P&gt;&lt;P&gt;Retry time exceeded; starting again&lt;BR /&gt;ethernet@30be0000 Waiting for PHY auto negotiation to complete......................................... TIMEOUT !&lt;BR /&gt;Could not initialize PHY ethernet@30be0000&lt;BR /&gt;BOOTP broadcast 1&lt;BR /&gt;BOOTP broadcast 2&lt;BR /&gt;BOOTP broadcast 3&lt;BR /&gt;BOOTP broadcast 4&lt;BR /&gt;BOOTP broadcast 5&lt;BR /&gt;BOOTP broadcast 6&lt;BR /&gt;BOOTP broadcast 7&lt;BR /&gt;BOOTP broadcast 8&lt;BR /&gt;BOOTP broadcast 9&lt;BR /&gt;BOOTP broadcast 10&lt;BR /&gt;BOOTP broadcast 11&lt;BR /&gt;BOOTP broadcast 12&lt;BR /&gt;BOOTP broadcast 13&lt;BR /&gt;BOOTP broadcast 14&lt;BR /&gt;BOOTP broadcast 15&lt;BR /&gt;BOOTP broadcast 16&lt;BR /&gt;BOOTP broadcast 17&lt;/P&gt;&lt;P&gt;Retry time exceeded; starting again&lt;BR /&gt;WARN: Cannot load the DT&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have MCU which is didn't have eMMC erased and everything is working perfectly but for these two which have erased eMMC I got this error. Any ideas ?&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 16 Aug 2022 07:20:33 GMT</pubDate>
    <dc:creator>malicious_mind</dc:creator>
    <dc:date>2022-08-16T07:20:33Z</dc:date>
    <item>
      <title>Secure u-boot issues iMX8M Nano</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/Secure-u-boot-issues-iMX8M-Nano/m-p/1505011#M193737</link>
      <description>&lt;P&gt;Hello crew,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;I was following procedure from link below to do secure u-boot and there are some issues about it:&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.nxp.com/t5/i-MX-Processors-Knowledge-Base/Steps-to-enable-secure-boot-in-i-MX8M-Nano/ta-p/1246417" target="_blank"&gt;Steps to enable secure boot in i.MX8M Nano - NXP Community&lt;/A&gt;&lt;/P&gt;&lt;P&gt;My u-boot is on sd card and there are HAB Events:&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Secure boot disabled&lt;/P&gt;&lt;P&gt;HAB Configuration: 0xf0, HAB State: 0x66&lt;/P&gt;&lt;P&gt;--------- HAB Event 1 -----------------&lt;BR /&gt;event data:&lt;BR /&gt;0xdb 0x00 0x08 0x45 0x33 0x11 0xcf 0x00&lt;/P&gt;&lt;P&gt;STS = HAB_FAILURE (0x33)&lt;BR /&gt;RSN = HAB_INV_CSF (0x11)&lt;BR /&gt;CTX = HAB_CTX_CSF (0xCF)&lt;BR /&gt;ENG = HAB_ENG_ANY (0x00)&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;--------- HAB Event 2 -----------------&lt;BR /&gt;event data:&lt;BR /&gt;0xdb 0x00 0x14 0x45 0x33 0x0c 0xa0 0x00&lt;BR /&gt;0x00 0x00 0x00 0x00 0x00 0x91 0x1f 0xc0&lt;BR /&gt;0x00 0x00 0x00 0x20&lt;/P&gt;&lt;P&gt;STS = HAB_FAILURE (0x33)&lt;BR /&gt;RSN = HAB_INV_ASSERTION (0x0C)&lt;BR /&gt;CTX = HAB_CTX_ASSERT (0xA0)&lt;BR /&gt;ENG = HAB_ENG_ANY (0x00)&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;--------- HAB Event 3 -----------------&lt;BR /&gt;event data:&lt;BR /&gt;0xdb 0x00 0x14 0x45 0x33 0x0c 0xa0 0x00&lt;BR /&gt;0x00 0x00 0x00 0x00 0x00 0x91 0x1f 0xe0&lt;BR /&gt;0x00 0x00 0x00 0x0c&lt;/P&gt;&lt;P&gt;STS = HAB_FAILURE (0x33)&lt;BR /&gt;RSN = HAB_INV_ASSERTION (0x0C)&lt;BR /&gt;CTX = HAB_CTX_ASSERT (0xA0)&lt;BR /&gt;ENG = HAB_ENG_ANY (0x00)&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;--------- HAB Event 4 -----------------&lt;BR /&gt;event data:&lt;BR /&gt;0xdb 0x00 0x14 0x45 0x33 0x0c 0xa0 0x00&lt;BR /&gt;0x00 0x00 0x00 0x00 0x00 0x91 0x20 0x00&lt;BR /&gt;0x00 0x00 0x00 0x04&lt;/P&gt;&lt;P&gt;STS = HAB_FAILURE (0x33)&lt;BR /&gt;RSN = HAB_INV_ASSERTION (0x0C)&lt;BR /&gt;CTX = HAB_CTX_ASSERT (0xA0)&lt;BR /&gt;ENG = HAB_ENG_ANY (0x00)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But when I flash this to the eMMC, hab events are gone, why ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Why procedure from this link is different than procedure on this link&amp;nbsp;&lt;A href="https://source.codeaurora.org/external/imx/uboot-imx/tree/doc/imx/habv4/guides/mx8m_mx8mm_secure_boot.txt?h=imx_v2019.04_4.19.35_1.1.0" target="_blank"&gt;mx8m_mx8mm_secure_boot.txt\guides\habv4\imx\doc - uboot-imx - i.MX U-Boot (codeaurora.org)&lt;/A&gt;&amp;nbsp;?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On codeaurora link they are flashing OTP fuses first and then check HAB events ? What is correct way to do it (please somebody official from NXP to answer) ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Another question is, can I have only secure u-boot with non-secure kernel image and how to do it ? Do I need padding like it is mentioned on&amp;nbsp;&lt;A href="https://source.codeaurora.org/external/imx/uboot-imx/tree/doc/imx/habv4/guides/mx8m_mx8mm_secure_boot.txt?h=imx_v2019.04_4.19.35_1.1.0" target="_blank"&gt;mx8m_mx8mm_secure_boot.txt\guides\habv4\imx\doc - uboot-imx - i.MX U-Boot (codeaurora.org)&lt;/A&gt;&amp;nbsp;paragraph 2 or ?&lt;/P&gt;&lt;P&gt;For now we have u-boot enabled on eMMC but kernel will not start, what's the best way to proceed ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Thu, 11 Aug 2022 12:45:37 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/Secure-u-boot-issues-iMX8M-Nano/m-p/1505011#M193737</guid>
      <dc:creator>malicious_mind</dc:creator>
      <dc:date>2022-08-11T12:45:37Z</dc:date>
    </item>
    <item>
      <title>Re: Secure u-boot issues iMX8M Nano</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/Secure-u-boot-issues-iMX8M-Nano/m-p/1506122#M193851</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.nxp.com/t5/user/viewprofilepage/user-id/203709"&gt;@malicious_mind&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Based on the hab events. There exists problem in your signing process. Let's firstly focus on the signed uboot image which can be boot in eMMC normally, but not with SD Card.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can you please make sure that the eMMC in board is formatted before flashing and the signed uboot image for SD Card with hab events to the eMMC?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best regards&lt;/P&gt;
&lt;P&gt;Harvey&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Aug 2022 09:27:27 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/Secure-u-boot-issues-iMX8M-Nano/m-p/1506122#M193851</guid>
      <dc:creator>Harvey021</dc:creator>
      <dc:date>2022-08-15T09:27:27Z</dc:date>
    </item>
    <item>
      <title>Re: Secure u-boot issues iMX8M Nano</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/Secure-u-boot-issues-iMX8M-Nano/m-p/1506618#M193892</link>
      <description>&lt;P&gt;Hello Harvey&lt;/P&gt;&lt;P&gt;We manage do to it, I will upload tutorial here but issue is when I erase eMMC I can't directly flash it only via SD card and I used 7 SD and it is always same story:&lt;/P&gt;&lt;P&gt;Device 0: unknown device&lt;BR /&gt;switch to partitions #0, OK&lt;BR /&gt;mmc1 is current device&lt;BR /&gt;Scanning mmc 1:1...&lt;BR /&gt;Error reading cluster&lt;BR /&gt;** Unable to read file /imx8mn-evk.dtb **&lt;BR /&gt;Failed to load '/imx8mn-evk.dtb'&lt;BR /&gt;** No partition table - mmc 1 **&lt;BR /&gt;** No partition table - mmc 1 **&lt;BR /&gt;libfdt fdt_check_header(): FDT_ERR_BADMAGIC&lt;BR /&gt;Scanning disk mmc@30b50000.blk...&lt;BR /&gt;** fs_devread read error - block&lt;BR /&gt;Failed to mount ext2 filesystem...&lt;BR /&gt;** Unrecognized filesystem type **&lt;BR /&gt;Scanning disk mmc@30b60000.blk...&lt;BR /&gt;** Unrecognized filesystem type **&lt;BR /&gt;Found 2 disks&lt;BR /&gt;No EFI system partition&lt;BR /&gt;adv7535_mipi2hdmi adv7535@3d: Can't find cec device id=0x3c&lt;BR /&gt;fail to probe panel device adv7535@3d&lt;BR /&gt;mxs_video lcd-controller@32e00000: failed to get any video link display timings&lt;BR /&gt;ERROR: invalid device tree&lt;BR /&gt;** No partition table - mmc 1 **&lt;BR /&gt;switch to partitions #0, OK&lt;BR /&gt;mmc2(part 0) is current device&lt;BR /&gt;** No partition table - mmc 2 **&lt;BR /&gt;Running BSP bootcmd ...&lt;BR /&gt;switch to partitions #0, OK&lt;BR /&gt;mmc1 is current device&lt;BR /&gt;Failed to load 'boot.scr'&lt;BR /&gt;Error reading cluster&lt;BR /&gt;** Unable to read file Image **&lt;BR /&gt;Failed to load 'Image'&lt;BR /&gt;Booting from net ...&lt;BR /&gt;ethernet@30be0000 Waiting for PHY auto negotiation to complete......................................... TIMEOUT !&lt;BR /&gt;Could not initialize PHY ethernet@30be0000&lt;BR /&gt;BOOTP broadcast 1&lt;BR /&gt;BOOTP broadcast 2&lt;BR /&gt;BOOTP broadcast 3&lt;BR /&gt;BOOTP broadcast 4&lt;BR /&gt;BOOTP broadcast 5&lt;BR /&gt;BOOTP broadcast 6&lt;BR /&gt;BOOTP broadcast 7&lt;BR /&gt;BOOTP broadcast 8&lt;BR /&gt;BOOTP broadcast 9&lt;BR /&gt;BOOTP broadcast 10&lt;BR /&gt;BOOTP broadcast 11&lt;BR /&gt;BOOTP broadcast 12&lt;BR /&gt;BOOTP broadcast 13&lt;BR /&gt;BOOTP broadcast 14&lt;BR /&gt;BOOTP broadcast 15&lt;BR /&gt;BOOTP broadcast 16&lt;BR /&gt;BOOTP broadcast 17&lt;/P&gt;&lt;P&gt;Retry time exceeded; starting again&lt;BR /&gt;ethernet@30be0000 Waiting for PHY auto negotiation to complete......................................... TIMEOUT !&lt;BR /&gt;Could not initialize PHY ethernet@30be0000&lt;BR /&gt;BOOTP broadcast 1&lt;BR /&gt;BOOTP broadcast 2&lt;BR /&gt;BOOTP broadcast 3&lt;BR /&gt;BOOTP broadcast 4&lt;BR /&gt;BOOTP broadcast 5&lt;BR /&gt;BOOTP broadcast 6&lt;BR /&gt;BOOTP broadcast 7&lt;BR /&gt;BOOTP broadcast 8&lt;BR /&gt;BOOTP broadcast 9&lt;BR /&gt;BOOTP broadcast 10&lt;BR /&gt;BOOTP broadcast 11&lt;BR /&gt;BOOTP broadcast 12&lt;BR /&gt;BOOTP broadcast 13&lt;BR /&gt;BOOTP broadcast 14&lt;BR /&gt;BOOTP broadcast 15&lt;BR /&gt;BOOTP broadcast 16&lt;BR /&gt;BOOTP broadcast 17&lt;/P&gt;&lt;P&gt;Retry time exceeded; starting again&lt;BR /&gt;WARN: Cannot load the DT&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have MCU which is didn't have eMMC erased and everything is working perfectly but for these two which have erased eMMC I got this error. Any ideas ?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Aug 2022 07:20:33 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/Secure-u-boot-issues-iMX8M-Nano/m-p/1506618#M193892</guid>
      <dc:creator>malicious_mind</dc:creator>
      <dc:date>2022-08-16T07:20:33Z</dc:date>
    </item>
    <item>
      <title>Re: Secure u-boot issues iMX8M Nano</title>
      <link>https://community.nxp.com/t5/i-MX-Processors/Secure-u-boot-issues-iMX8M-Nano/m-p/1506730#M193899</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.nxp.com/t5/user/viewprofilepage/user-id/203709"&gt;@malicious_mind&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Based on the boot log, there are no loading dtb and Image. You can follow up the&amp;nbsp;&lt;SPAN&gt;4.3 Preparing an SD/MMC card to boot of Linux User Guide.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If you still have such issue related to SD/MMC card to boot, please raise another case for further assistance.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;On codeaurora link they are flashing OTP fuses first and then check HAB events ? What is correct way to do it (please somebody official from NXP to answer) ?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;gt; Firstly blow fuse and then check hab events.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Another question is, can I have only secure u-boot with non-secure kernel image and how to do it ?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;gt;&amp;nbsp;&lt;/SPAN&gt;You&amp;nbsp;can disable kernel/DTB image authenticate in u-boot, it's "booti" command for i.mx8 platform.&lt;/P&gt;
&lt;P&gt;diff --git a/cmd/booti.c b/cmd/booti.c&lt;BR /&gt;index a132949091..b66dfbff0e 100644&lt;BR /&gt;--- a/cmd/booti.c&lt;BR /&gt;+++ b/cmd/booti.c&lt;BR /&gt;@@ -42,7 +42,7 @@ static int booti_start(cmd_tbl_t *cmdtp, int flag, int argc,&lt;BR /&gt;if (ret != 0)&lt;BR /&gt;return 1;&lt;/P&gt;
&lt;P&gt;-#if defined(CONFIG_IMX_HAB) &amp;amp;&amp;amp; !defined(CONFIG_AVB_SUPPORT)&lt;BR /&gt;+#if 0&lt;BR /&gt;extern int authenticate_image(&lt;BR /&gt;uint32_t ddr_start, uint32_t raw_image_size);&lt;BR /&gt;if (authenticate_image(ld, image_size) != 0) {&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Best regards&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Harvey&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Aug 2022 22:56:31 GMT</pubDate>
      <guid>https://community.nxp.com/t5/i-MX-Processors/Secure-u-boot-issues-iMX8M-Nano/m-p/1506730#M193899</guid>
      <dc:creator>Harvey021</dc:creator>
      <dc:date>2022-08-16T22:56:31Z</dc:date>
    </item>
  </channel>
</rss>

