Description
On ConnectCore 93 (Scarthgap, u-boot-dey 2024.04, v2024.04/maint), enabling TrustFence artifact signing together with the read-only-rootfs image feature results in two options that are handled as mutually exclusive in U-Boot, although trustfence.bbclass enables both:
CONFIG_AHAB_BOOT=y
CONFIG_AUTH_FIT_ARTIFACT=y # TRUSTFENCE_SIGN_FIT_NXP:ccimx9 = "${TRUSTFENCE_SIGN_ARTIFACTS}"
CONFIG_AUTHENTICATE_SQUASHFS_ROOTFS=y # TRUSTFENCE_READ_ONLY_ROOTFS = "1"
CONFIG_AUTH_SQUASHFS_ADDR=0x90000000
This combination causes the problem:
1. Build failure: digi_auth_image() prototype conflict
board/digi/common/trustfence/auth.h (and auth.c) use an #if / #elif, so only the squashfs variant is declared and built:
#if defined(CONFIG_AUTH_DISCRETE_ARTIFACTS) || defined(CONFIG_AUTHENTICATE_SQUASHFS_ROOTFS)
int digi_auth_image(ulong *ddr_start, ulong raw_image_size);
#elif defined(CONFIG_AUTH_FIT_ARTIFACT)
int digi_auth_image(ulong addr);
#endif
cmd/source.c calls the FIT variant and fails to build:
cmd/source.c: error: too few arguments to function 'digi_auth_image'
Steps to Reproduce
- Initialize the Scarthgap manifest and sync layers.
- In
conf/local.conf, set:
MACHINE = "ccimx93-dvk"
INHERIT += "trustfence"
EXTRA_IMAGE_FEATURES += "read-only-rootfs"
- Run
bitbake dey-image-qt (or any DEY image) → U-Boot build fails (issue 1).
(Reproduced on a custom carrier board based on ccimx93-dvk; the affected code is common to all ccimx9 platforms.)
Expected Behavior
A ccimx9 image with TrustFence signing and a read-only squashfs rootfs should build, authenticate the rootfs and FIT image, and boot Linux.
Description
On ConnectCore 93 (Scarthgap,
u-boot-dey2024.04,v2024.04/maint), enabling TrustFence artifact signing together with theread-only-rootfsimage feature results in two options that are handled as mutually exclusive in U-Boot, althoughtrustfence.bbclassenables both:This combination causes the problem:
1. Build failure:
digi_auth_image()prototype conflictboard/digi/common/trustfence/auth.h(andauth.c) use an#if / #elif, so only the squashfs variant is declared and built:cmd/source.ccalls the FIT variant and fails to build:Steps to Reproduce
conf/local.conf, set:bitbake dey-image-qt(or any DEY image) → U-Boot build fails (issue 1).(Reproduced on a custom carrier board based on
ccimx93-dvk; the affected code is common to all ccimx9 platforms.)Expected Behavior
A ccimx9 image with TrustFence signing and a read-only squashfs rootfs should build, authenticate the rootfs and FIT image, and boot Linux.