View Issue Details

IDProjectCategoryView StatusLast Update
0001956T99X171.00 SKB EagleSW Issuepublic2024-06-24 09:30
Reporter(ALTech) Younkwang Jung Assigned To(SW) Kinbay Wu Due Date2024-06-14 14:30
PrioritynormalSeveritys4-minorReproducibilityhave not tried
Status closedResolutionfixed 
Summary0001956: [Smart3] AVB key update patch
DescriptionHi Kinbay

SoC mentions that there is an issue of factory initialization when upgrading to the replacement FW of AVB test key,
and this issue has been resolved by each manufacturer.
( I'm guessing it's a Smart3 initial development issue and I'm not sure about it )

Attached here is the patch that I received from AML Kor and can be updated AB key without factory initialization.
Please refer to the pdf document.
1. Apply the 0001 patch and find the new AVB test key's verified key hash
2. Include the value of the verified key hash in the code, as in the 0002 patch.

In addition, it is said that you can contact Taiwan Amlogic FAE for this information.

SoC recommends applying the patch, so please review if this is applicable to UI542.

Thank you
YK.Jung
TagsNo tags attached.
Attach Tags

Users monitoring this issue

User List (ALTech) Jong-Hwa JUNG , (ALTech) JunGyu Kim , (ALTech) Sangmin Choi , (ALTech) SY Yoon , (ALTech) Wooshin Kang

Activities

(ALTech) Younkwang Jung

2024-06-07 13:38

developer  

0001-debug-boot_param-v2015.patch (1,254 bytes)   
From dfb0e57c388ed300680a678b487cbc6ad6bddaef Mon Sep 17 00:00:00 2001
From: Matthew Shyu <matthew.shyu@amlogic.com>
Date: Tue, 3 Jan 2023 08:35:36 +0000
Subject: [PATCH 1/2] debug boot_param v2015

Change-Id: I3d580b83e429071655c7d01bcee2f565e95406eA
---
 common/cmd_bootm.c | 14 ++++++++++++++
 1 file changed, 14 insertions(+)

diff --git a/common/cmd_bootm.c b/common/cmd_bootm.c
index 2f149cefe13..4ae7f9bc2ff 100644
--- a/common/cmd_bootm.c
+++ b/common/cmd_bootm.c
@@ -283,6 +283,20 @@ int do_bootm(cmd_tbl_t *cmdtp, int flag, int argc, char * const argv[])
 			memcpy(boot_params.verified_boot_hash, vbmeta_digest,
 					sizeof(boot_params.verified_boot_hash));
 
+			printf("device_locked = %d.\n", boot_params.device_locked);
+			printf("verified_boot_state = %d.\n", boot_params.verified_boot_state);
+			uint32_t i = 0;
+
+			printf("verified_boot_key\n");
+			for (i = 0; i < SHA256_DIGEST_SIZE; i++)
+				printf("%02x", boot_params.verified_boot_key[i]);
+
+			printf("\n");
+			printf("verified_boot_hash\n");
+			for (i = 0; i < SHA256_DIGEST_SIZE; i++)
+				printf("%02x", boot_params.verified_boot_hash[i]);
+			printf("\n");
+
 			if (set_boot_params(&boot_params) < 0) {
 				printf("failed to set boot params.\n");
 			}
-- 
2.29.0

0002-avb-force-test-key-1-1.patch (1,608 bytes)   
From e895e90dadddcdd631419589d2e7a9f7e7361bcb Mon Sep 17 00:00:00 2001
From: Matthew Shyu <matthew.shyu@amlogic.com>
Date: Wed, 17 Jan 2024 19:38:12 -0800
Subject: [PATCH 2/2] avb: force test key [1/1]

PD#SWPL-154626

Problem:
For projects that uses test key to boot up but wish to change avb key
afterwards.

Solution:
For test key hash.
DANGEROUS:
THINK BEFORE YOU MERGE.

Verify:
Ohm

Change-Id: If975bf4f1d6d1b78556e000c2ba952d8d5e554b3
Signed-off-by: Matthew Shyu <matthew.shyu@amlogic.com>
---
 lib/libavb/avb_slot_verify.c | 12 ++++++++++++
 1 file changed, 12 insertions(+)

diff --git a/lib/libavb/avb_slot_verify.c b/lib/libavb/avb_slot_verify.c
index 4429d4c824d..8790092881f 100644
--- a/lib/libavb/avb_slot_verify.c
+++ b/lib/libavb/avb_slot_verify.c
@@ -28,6 +28,14 @@
 
 uint8_t boot_key_hash[AVB_SHA256_DIGEST_SIZE];
 
+#define FORCE_TEST_KEY (1)
+uint8_t test_key_hash[AVB_SHA256_DIGEST_SIZE] = {
+        0x22, 0xde, 0x39, 0x94, 0x53, 0x21, 0x96, 0xf6,
+        0x1c, 0x03, 0x9e, 0x90, 0x26, 0x0d, 0x78, 0xa9,
+        0x3a, 0x4c, 0x57, 0x36, 0x2c, 0x7e, 0x78, 0x9b,
+        0xe9, 0x28, 0x03, 0x6e, 0x80, 0xb7, 0x7c, 0x8c,
+};
+
 static AvbSlotVerifyResult initialize_persistent_digest(
     AvbOps* ops,
     const char* part_name,
@@ -746,6 +754,10 @@ static AvbSlotVerifyResult load_and_verify_vbmeta(
 					avb_memcpy(boot_key_hash,
 							avb_sha256_final(&boot_key_sha256_ctx),
 							AVB_SHA256_DIGEST_SIZE);
+#if FORCE_TEST_KEY
+                    avb_memcpy(boot_key_hash, test_key_hash,
+                        AVB_SHA256_DIGEST_SIZE);
+#endif
 				}
 			}
 		}
-- 
2.29.0

(SW) Kerwin Chen

2024-06-14 15:59

developer   ~0016039

Hi YK,

According to AML Taiwan FAE, P1 patch is not a 'must'.
If SKB asks to apply the patches, Fii will follow.
Please help to check, thanks.

(ALTech) Younkwang Jung

2024-06-19 12:17

developer   ~0016066

Hi Kerwin

This patch has nothing to do with SKB.
Review it with Taiwan Amlogic FAE and if the patch does not need BFX-AT100, you don't have to apply it.

Thank you
YK.Jung

(ALTech) Wooshin Kang

2024-06-24 09:30

developer   ~0016084

There is no job to do. So I will close.

Issue History

Date Modified Username Field Change
2024-06-07 13:38 (ALTech) Younkwang Jung New Issue
2024-06-07 13:38 (ALTech) Younkwang Jung Status new => assigned
2024-06-07 13:38 (ALTech) Younkwang Jung Assigned To => (SW) Kinbay Wu
2024-06-07 13:38 (ALTech) Younkwang Jung File Added: 0001-debug-boot_param-v2015.patch
2024-06-07 13:38 (ALTech) Younkwang Jung File Added: 0002-avb-force-test-key-1-1.patch
2024-06-07 13:38 (ALTech) Younkwang Jung File Added: Anrdoid R Hailstorm 4.1.1 SDK Mandatory Patch List avb2_testkey_replace P1 readme.pdf
2024-06-07 13:39 (ALTech) Younkwang Jung Issue Monitored: (ALTech) SY Yoon
2024-06-07 13:39 (ALTech) Younkwang Jung Issue Monitored: (ALTech) JunGyu Kim
2024-06-07 13:39 (ALTech) Younkwang Jung Issue Monitored: (ALTech) Wooshin Kang
2024-06-07 13:40 (ALTech) Younkwang Jung Issue Monitored: (ALTech) Sangmin Choi
2024-06-07 14:02 (ALTech) Younkwang Jung Issue Monitored: (ALTech) Jong-Hwa JUNG
2024-06-14 15:59 (SW) Kerwin Chen Note Added: 0016039
2024-06-19 11:11 (ALTech) Younkwang Jung Summary [Smart3] AB key update patch => [Smart3] AVB key update patch
2024-06-19 12:17 (ALTech) Younkwang Jung Note Added: 0016066
2024-06-24 09:30 (ALTech) Wooshin Kang Status assigned => closed
2024-06-24 09:30 (ALTech) Wooshin Kang Resolution open => fixed
2024-06-24 09:30 (ALTech) Wooshin Kang Note Added: 0016084