Skip to content

Plumb flashing support for open-firmware boot for IQ-9075 EVK and RB3Gen2 - #3258

Merged
Ricardo Salveti (ricardosalveti) merged 8 commits into
qualcomm-linux:masterfrom
b49020:open_fw_flash_plumbing
Oct 4, 2026
Merged

Ricardo Salveti (ricardosalveti) merged 8 commits into
qualcomm-linux:masterfrom
b49020:open_fw_flash_plumbing

Conversation

@b49020

Copy link
Copy Markdown
Member

Enables the open TF-A BL2 + FIP boot flow for the  iq-9075-evk-open-fw  and  rb3gen2-core-kit-open-fw  machines, and makes the UKI carry the EL2 device tree these platforms boot under.

In this flow the boot ROM loads a signed BL2 from the tz partition, and BL2 loads the FIP payload (BL31 + OP-TEE BL32 + U-Boot BL33) from the uefi partition. Previously the TF-A recipe only signed fip.elf, nothing prepared BL2 as the trust-zone image, and qcomflash never installed either artifact, so these machines could not boot the open firmware.

The major blocker has been the OEM only signing feature for TZ image which should be fixed in current boot firmware releases in meta-qcom.

@github-actions

github-actions Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

Test run workflow

Test jobs for commit cc60528

qcom-distro_linux-qcom-6.18
Pass: 233 | Fail: 2 | Total: 253
nodistro
Pass: 10 | Fail: 0 | Total: 10
qcom-distro
Pass: 335 | Fail: 2 | Total: 367

Comment thread classes-recipe/image_types_qcom.bbclass Outdated
Comment thread conf/machine/iq-9075-evk-open-fw.conf Outdated
Comment thread conf/machine/rb3gen2-core-kit-open-fw.conf Outdated
Comment thread recipes-kernel/images/esp-qcom-image.bb
@qcomlnxci

Copy link
Copy Markdown

Test Coral run workflow

Test jobs for commit 062a0e7

  • qcomdistro: multimedia image-prop
    Pass: 27 | Fail: 1 | Others: 2 | Total: 30
  • qcomdistro: multimedia image
    Pass: 5 | Fail: 3 | Others: 1 | Total: 9

Comment thread conf/machine/iq-9075-evk-open-fw-spl.conf
Comment thread conf/machine/iq-9075-evk-open-fw.conf Outdated
Comment thread conf/machine/rb3gen2-core-kit-open-fw.conf Outdated
The SWIV platform annotation is not specific to the U-Boot SPL; the TF-A
BL2 signing needs the same platform name. Rename the variable to the
firmware-generic QCOM_FW_SWIV_PLATFORM so both consumers can share it.

Assisted-by: GitHub Copilot CLI:claude-opus-4-8
Signed-off-by: Sumit Garg <sumit.garg@oss.qualcomm.com>
Open-firmware boot loads a signed BL2 from the trust-zone partition, but
only fip.elf was signed before, so BL2 was never prepared as a bootable
trust-zone image.

Sign BL2 with qtestsign, with an optional SWIV pre-step for platforms
that require it, reusing the shared QCOM_FW_SWIV_PLATFORM. Both fip.elf
and bl2.mbn land in ${D}${FIRMWARE_DIR}, which meta-arm's firmware.bbclass
already deploys under ${DEPLOY_DIR_IMAGE}/${PN}/, so no extra deploy step
is needed.

Assisted-by: GitHub Copilot CLI:claude-opus-4-8
Signed-off-by: Sumit Garg <sumit.garg@oss.qualcomm.com>
Open-firmware machines boot through a signed BL2 that loads the FIP
payload, which qcomflash never installed.

Add QCOM_TFA_FIP_FLASH to install fip.elf as uefi.elf and bl2.mbn into
the tz slot, reading both from the TF-A recipe deploy directory named by
QCOM_TFA_RECIPE. The same variable drives the do_image_qcomflash deploy
dependency, so machines only set QCOM_TFA_FIP_FLASH and QCOM_TFA_RECIPE.
Fail when the trust-zone image is missing, since FIP boot cannot work
without it, and leave the u-boot and SPL-FIT paths unchanged when
disabled.

Assisted-by: GitHub Copilot CLI:claude-opus-4-8
Signed-off-by: Sumit Garg <sumit.garg@oss.qualcomm.com>
rb3gen2-core-kit-open-fw boots the open TF-A BL2 plus FIP payload. Enable
QCOM_TFA_FIP_FLASH and point QCOM_TFA_RECIPE at its TF-A recipe so
do_image_qcomflash orders after the TF-A deploy and flashes the signed
BL2 and FIP.

Assisted-by: GitHub Copilot CLI:claude-opus-4-8
Signed-off-by: Sumit Garg <sumit.garg@oss.qualcomm.com>
@b49020

Copy link
Copy Markdown
Member Author

Thanks Jose Quaresma (@quaresmajose) Ricardo Salveti (@ricardosalveti) for your comments, addressed them. Feel free to review again.

@qcomlnxci

Copy link
Copy Markdown

Test Coral run workflow

Test jobs for commit aa15200

  • qcomdistro: multimedia image-prop
    Pass: 28 | Fail: 0 | Total: 28

@lumag

Copy link
Copy Markdown
Contributor

This has failed yocto-check-layers check. Could you please check, why?

Comment thread conf/machine/rb3gen2-core-kit-open-fw.conf Outdated
@ricardosalveti

Copy link
Copy Markdown
Contributor

The failure is from oe-selftest (test_machine_dtb_entries_exist_for_kernel_providers), not check-layer. The test only looks for .dts/.dtso files, and qcs6490-rb3gen2-el2.dtb is a Makefile composite (qcs6490-rb3gen2.dtb + kodiak-el2.dtbo). The test needs to also consider the -dtbs targets from the Makefile, same will be needed for lemans-evk-el2.dtb.

test_machine_dtb_entries_exist_for_kernel_providers only scans
arch/*/boot/dts for .dts/.dtso sources, so it misses composite DTBs like
qcs6490-rb3gen2-el2.dtb that the kernel assembles from a "<name>-dtbs :="
rule instead.

Parse those Makefile rules too and add each resulting DTB to the set of
available outputs.

Assisted-by: GitHub Copilot CLI:claude-opus-4-8
Signed-off-by: Sumit Garg <sumit.garg@oss.qualcomm.com>
The open firmware UKI runs at EL2, so it must carry the merged
qcs6490-rb3gen2-el2.dtb that ukify embeds whole instead of applying the
.dtbo overlays itself.

That DTB only exists in linux-qcom kernels, so build it through
LINUX_QCOM_KERNEL_DEVICETREE to keep linux-yocto builds working, and
embed it into the ESP image. The machine already defaults to a
linux-qcom kernel through qcom-base.inc.

Assisted-by: GitHub Copilot CLI:claude-opus-4-8
Signed-off-by: Sumit Garg <sumit.garg@oss.qualcomm.com>
iq-9075-evk-open-fw boots the open TF-A BL2 plus FIP payload. Enable
QCOM_TFA_FIP_FLASH and point QCOM_TFA_RECIPE at its TF-A recipe so
do_image_qcomflash orders after the TF-A deploy and flashes the signed
BL2 and FIP. The SPL variant inherits this config but flashes the U-Boot
SPL instead, so keep QCOM_TFA_FIP_FLASH disabled there and note why.

Assisted-by: GitHub Copilot CLI:claude-opus-4-8
Signed-off-by: Sumit Garg <sumit.garg@oss.qualcomm.com>
The open firmware UKI runs at EL2, so it must carry the merged
lemans-evk-el2.dtb that ukify embeds whole instead of applying the .dtbo
overlays itself. That DTB is upstream, so build it through the regular
KERNEL_DEVICETREE and embed it into the ESP image.

Assisted-by: GitHub Copilot CLI:claude-opus-4-8
Signed-off-by: Sumit Garg <sumit.garg@oss.qualcomm.com>
@b49020

Copy link
Copy Markdown
Member Author

This has failed yocto-check-layers check. Could you please check, why?

Thanks Ricardo Salveti (@ricardosalveti) for the pointer, the -dtbs Makefile check is now added for yocto-check-layers to succeed.

@qcomlnxci

Copy link
Copy Markdown

Test Coral run workflow

Test jobs for commit cc60528

  • qcomdistro: multimedia image-prop
    Pass: 32 | Fail: 0 | Total: 32
  • qcomdistro: multimedia image
    Pass: 4 | Fail: 0 | Total: 4

@b49020

Copy link
Copy Markdown
Member Author

Dmitry Baryshkov (@lumag) Jose Quaresma (@quaresmajose) gentle ping if there are any further comments. I know people are going to be travelling next week for the conferences.

@test-reporting-app

Copy link
Copy Markdown

Test Results

  117 files    717 suites   6h 6m 20s ⏱️
  195 tests   190 ✅  2 💤 3 ❌
4 613 runs  4 561 ✅ 48 💤 4 ❌

For more details on these failures, see this check.

Results for commit cc60528.

@ricardosalveti

Copy link
Copy Markdown
Contributor

Known issues.

@ricardosalveti
Ricardo Salveti (ricardosalveti) merged commit 95fb72a into qualcomm-linux:master Oct 4, 2026
210 of 211 checks passed
@quic-yocto-ci

Copy link
Copy Markdown
Contributor

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants