[Skiboot] [PATCH 3/3] core/init: move imc catalog preload init after the STB init.
ppaidipe at linux.vnet.ibm.com
Fri Feb 9 23:49:48 AEDT 2018
On 2018-02-09 10:35, Stewart Smith wrote:
> Vasant Hegde <hegdevasant at linux.vnet.ibm.com> writes:
>> On 02/06/2018 07:46 AM, Pridhiviraj Paidipeddi wrote:
>>> As a safer side move the imc catalog preload after the STB init
>>> to make sure the imc catalog resource get's verified and measured
>>> properly during loading when both secure and trusted boot modes
>>> are on.
>>> Signed-off-by: Pridhiviraj Paidipeddi <ppaidipe at linux.vnet.ibm.com>
>>> core/init.c | 6 +++---
>>> 1 file changed, 3 insertions(+), 3 deletions(-)
>>> diff --git a/core/init.c b/core/init.c
>>> index ec9f329..6eb4d83 100644
>>> --- a/core/init.c
>>> +++ b/core/init.c
>>> @@ -997,9 +997,6 @@ void __noreturn __nomcount main_cpu_entry(const
>>> void *fdt)
>>> /* Read in NVRAM and set it up */
>>> - /* preload the IMC catalog dtb */
>>> - imc_catalog_preload();
>>> /* Set the console level */
>>> @@ -1007,6 +1004,9 @@ void __noreturn __nomcount main_cpu_entry(const
>>> void *fdt)
>> Can we initialize secureboot before platform init ? That would solve
>> all the issues.
> Probably? Maybe?
> I wonder if we have / may have any quirks though...
I checked that, STB init depends on nvram_init, which again depends on
which we are doing currently it in platform init, so moving it above
platform init has lot of
dependencies. So i have come up with this fix by re-orderings inits to
do verify and measure
best out of it.
But we have a dependency issue is there for this fix, which needs to be
before this patch merges, otherwise we will be having boot abort failure
in secure mode
More information about the Skiboot