diff mbox series

[v2,1/4] boot/arm-trusted-firmware: move to official source for tf-a

Message ID 20240807-tfa-src-update-v2-1-f2cd6166db5f@ti.com
State Accepted
Headers show
Series boot/arm-trusted-firmware: version bump and source update | expand

Commit Message

Bryan Brattlof Aug. 7, 2024, 5:48 p.m. UTC
ARM_TRUSTED_FIRMWARE_SITE is currently pointing to the deprecated
ARM-software github read-only mirror[0] which is no longer publishing
new tags. They do have a newer github mirror under the TrustedFirmware-A
organization[1] which continues to receive tag updates we could use
however because of the way github generates tarballs changing the SITE
to point to TrustedFormware-A changes the pre-calculated hash values
for every version for everyone.

Without much way around changing all hash values if we want these latest
tags, lets drop the github mirrors and move to the official git
source[2] so we can download real tarballs which shouldn't change even
if the ARM_TRUSTED_FIRMWARE_SITE moves again and hopefully preventing
this from ever happening again.

[2] https://git.trustedfirmware.org/TF-A/trusted-firmware-a.git/
[1] https://github.com/TrustedFirmware-A/trusted-firmware-a
[0] https://github.com/ARM-software/arm-trusted-firmware

Signed-off-by: Bryan Brattlof <bb@ti.com>
---
 .../fvp-ebbr/patches/arm-trusted-firmware/arm-trusted-firmware.hash   | 2 +-
 .../patches/arm-trusted-firmware/arm-trusted-firmware.hash            | 2 +-
 .../beagleplay/patches/arm-trusted-firmware/arm-trusted-firmware.hash | 2 +-
 .../patches/arm-trusted-firmware/arm-trusted-firmware.hash            | 2 +-
 .../patches/arm-trusted-firmware/arm-trusted-firmware.hash            | 2 +-
 board/qemu/patches/arm-trusted-firmware/arm-trusted-firmware.hash     | 2 +-
 .../stm32mp157/patches/arm-trusted-firmware/arm-trusted-firmware.hash | 2 +-
 .../am62ax-sk/patches/arm-trusted-firmware/arm-trusted-firmware.hash  | 2 +-
 .../am62x-sk/patches/arm-trusted-firmware/arm-trusted-firmware.hash   | 2 +-
 .../am64x-sk/patches/arm-trusted-firmware/arm-trusted-firmware.hash   | 2 +-
 boot/arm-trusted-firmware/arm-trusted-firmware.hash                   | 4 ++--
 boot/arm-trusted-firmware/arm-trusted-firmware.mk                     | 3 ++-
 12 files changed, 14 insertions(+), 13 deletions(-)

Comments

Thomas Petazzoni Aug. 7, 2024, 10:12 p.m. UTC | #1
On Wed, 7 Aug 2024 12:48:19 -0500
Bryan Brattlof via buildroot <buildroot@buildroot.org> wrote:

> ARM_TRUSTED_FIRMWARE_SITE is currently pointing to the deprecated
> ARM-software github read-only mirror[0] which is no longer publishing
> new tags. They do have a newer github mirror under the TrustedFirmware-A
> organization[1] which continues to receive tag updates we could use
> however because of the way github generates tarballs changing the SITE
> to point to TrustedFormware-A changes the pre-calculated hash values
> for every version for everyone.
> 
> Without much way around changing all hash values if we want these latest
> tags, lets drop the github mirrors and move to the official git
> source[2] so we can download real tarballs which shouldn't change even
> if the ARM_TRUSTED_FIRMWARE_SITE moves again and hopefully preventing
> this from ever happening again.
> 
> [2] https://git.trustedfirmware.org/TF-A/trusted-firmware-a.git/
> [1] https://github.com/TrustedFirmware-A/trusted-firmware-a
> [0] https://github.com/ARM-software/arm-trusted-firmware
> 
> Signed-off-by: Bryan Brattlof <bb@ti.com>
> ---
>  .../fvp-ebbr/patches/arm-trusted-firmware/arm-trusted-firmware.hash   | 2 +-
>  .../patches/arm-trusted-firmware/arm-trusted-firmware.hash            | 2 +-
>  .../beagleplay/patches/arm-trusted-firmware/arm-trusted-firmware.hash | 2 +-
>  .../patches/arm-trusted-firmware/arm-trusted-firmware.hash            | 2 +-
>  .../patches/arm-trusted-firmware/arm-trusted-firmware.hash            | 2 +-
>  board/qemu/patches/arm-trusted-firmware/arm-trusted-firmware.hash     | 2 +-
>  .../stm32mp157/patches/arm-trusted-firmware/arm-trusted-firmware.hash | 2 +-
>  .../am62ax-sk/patches/arm-trusted-firmware/arm-trusted-firmware.hash  | 2 +-
>  .../am62x-sk/patches/arm-trusted-firmware/arm-trusted-firmware.hash   | 2 +-
>  .../am64x-sk/patches/arm-trusted-firmware/arm-trusted-firmware.hash   | 2 +-
>  boot/arm-trusted-firmware/arm-trusted-firmware.hash                   | 4 ++--
>  boot/arm-trusted-firmware/arm-trusted-firmware.mk                     | 3 ++-
>  12 files changed, 14 insertions(+), 13 deletions(-)

Applied to master, thanks! Note that your patch didn't apply as-is to
master, one defconfig had changed in the mean time. If possible make
sure to send patches that apply on the latest master.

I hope you didn't forgot any defconfig :-)

Thomas
Bryan Brattlof Aug. 8, 2024, 4:39 p.m. UTC | #2
On August  8, 2024 thus sayeth Thomas Petazzoni via buildroot:
> On Wed, 7 Aug 2024 12:48:19 -0500
> Bryan Brattlof via buildroot <buildroot@buildroot.org> wrote:
> 
> > ARM_TRUSTED_FIRMWARE_SITE is currently pointing to the deprecated
> > ARM-software github read-only mirror[0] which is no longer publishing
> > new tags. They do have a newer github mirror under the TrustedFirmware-A
> > organization[1] which continues to receive tag updates we could use
> > however because of the way github generates tarballs changing the SITE
> > to point to TrustedFormware-A changes the pre-calculated hash values
> > for every version for everyone.
> > 
> > Without much way around changing all hash values if we want these latest
> > tags, lets drop the github mirrors and move to the official git
> > source[2] so we can download real tarballs which shouldn't change even
> > if the ARM_TRUSTED_FIRMWARE_SITE moves again and hopefully preventing
> > this from ever happening again.
> > 
> > [2] https://git.trustedfirmware.org/TF-A/trusted-firmware-a.git/
> > [1] https://github.com/TrustedFirmware-A/trusted-firmware-a
> > [0] https://github.com/ARM-software/arm-trusted-firmware
> > 
> > Signed-off-by: Bryan Brattlof <bb@ti.com>
> > ---
> >  .../fvp-ebbr/patches/arm-trusted-firmware/arm-trusted-firmware.hash   | 2 +-
> >  .../patches/arm-trusted-firmware/arm-trusted-firmware.hash            | 2 +-
> >  .../beagleplay/patches/arm-trusted-firmware/arm-trusted-firmware.hash | 2 +-
> >  .../patches/arm-trusted-firmware/arm-trusted-firmware.hash            | 2 +-
> >  .../patches/arm-trusted-firmware/arm-trusted-firmware.hash            | 2 +-
> >  board/qemu/patches/arm-trusted-firmware/arm-trusted-firmware.hash     | 2 +-
> >  .../stm32mp157/patches/arm-trusted-firmware/arm-trusted-firmware.hash | 2 +-
> >  .../am62ax-sk/patches/arm-trusted-firmware/arm-trusted-firmware.hash  | 2 +-
> >  .../am62x-sk/patches/arm-trusted-firmware/arm-trusted-firmware.hash   | 2 +-
> >  .../am64x-sk/patches/arm-trusted-firmware/arm-trusted-firmware.hash   | 2 +-
> >  boot/arm-trusted-firmware/arm-trusted-firmware.hash                   | 4 ++--
> >  boot/arm-trusted-firmware/arm-trusted-firmware.mk                     | 3 ++-
> >  12 files changed, 14 insertions(+), 13 deletions(-)
> 
> Applied to master, thanks! Note that your patch didn't apply as-is to
> master, one defconfig had changed in the mean time. If possible make
> sure to send patches that apply on the latest master.
>

Ah thank you for all the fixups. I may have hit send a little too fast 
on this one :)

~Bryan
diff mbox series

Patch

diff --git a/board/arm/fvp-ebbr/patches/arm-trusted-firmware/arm-trusted-firmware.hash b/board/arm/fvp-ebbr/patches/arm-trusted-firmware/arm-trusted-firmware.hash
index 02714d06a09c0..6f02bfbb22efc 100644
--- a/board/arm/fvp-ebbr/patches/arm-trusted-firmware/arm-trusted-firmware.hash
+++ b/board/arm/fvp-ebbr/patches/arm-trusted-firmware/arm-trusted-firmware.hash
@@ -1,2 +1,2 @@ 
 # Locally calculated
-sha256  2e18b881ada9198173238cca80086c787b1fa3f698944bde1743142823fc511c  arm-trusted-firmware-v2.10.tar.gz
+sha256  7efa89e1b4e4106ee05d68e876c8efbb146364d89cfd5d26bf4647b09c08f32b  arm-trusted-firmware-v2.10-git4.tar.gz
diff --git a/board/beagleboard/beagleboneai64/patches/arm-trusted-firmware/arm-trusted-firmware.hash b/board/beagleboard/beagleboneai64/patches/arm-trusted-firmware/arm-trusted-firmware.hash
index 02714d06a09c0..6f02bfbb22efc 100644
--- a/board/beagleboard/beagleboneai64/patches/arm-trusted-firmware/arm-trusted-firmware.hash
+++ b/board/beagleboard/beagleboneai64/patches/arm-trusted-firmware/arm-trusted-firmware.hash
@@ -1,2 +1,2 @@ 
 # Locally calculated
-sha256  2e18b881ada9198173238cca80086c787b1fa3f698944bde1743142823fc511c  arm-trusted-firmware-v2.10.tar.gz
+sha256  7efa89e1b4e4106ee05d68e876c8efbb146364d89cfd5d26bf4647b09c08f32b  arm-trusted-firmware-v2.10-git4.tar.gz
diff --git a/board/beagleboard/beagleplay/patches/arm-trusted-firmware/arm-trusted-firmware.hash b/board/beagleboard/beagleplay/patches/arm-trusted-firmware/arm-trusted-firmware.hash
index 02714d06a09c0..6f02bfbb22efc 100644
--- a/board/beagleboard/beagleplay/patches/arm-trusted-firmware/arm-trusted-firmware.hash
+++ b/board/beagleboard/beagleplay/patches/arm-trusted-firmware/arm-trusted-firmware.hash
@@ -1,2 +1,2 @@ 
 # Locally calculated
-sha256  2e18b881ada9198173238cca80086c787b1fa3f698944bde1743142823fc511c  arm-trusted-firmware-v2.10.tar.gz
+sha256  7efa89e1b4e4106ee05d68e876c8efbb146364d89cfd5d26bf4647b09c08f32b  arm-trusted-firmware-v2.10-git4.tar.gz
diff --git a/board/bsh/common/imx8mn-bsh-smm-s2/patches/arm-trusted-firmware/arm-trusted-firmware.hash b/board/bsh/common/imx8mn-bsh-smm-s2/patches/arm-trusted-firmware/arm-trusted-firmware.hash
index 80e592dab6065..90060567d6c93 100644
--- a/board/bsh/common/imx8mn-bsh-smm-s2/patches/arm-trusted-firmware/arm-trusted-firmware.hash
+++ b/board/bsh/common/imx8mn-bsh-smm-s2/patches/arm-trusted-firmware/arm-trusted-firmware.hash
@@ -1,2 +1,2 @@ 
 # Locally calculated
-sha256  fc4cdac7c08fc398b6d4b705285dc13ac2d2b30a7449c6f07e9ccd81207241df  arm-trusted-firmware-v2.5.tar.gz
+sha256  df46a00a7f4d5c30ca1b9b6dc736de6b7bf13fef527d1640c49d18d74875a28e  arm-trusted-firmware-v2.5-git4.tar.gz
diff --git a/board/orangepi/orangepi-zero2w/patches/arm-trusted-firmware/arm-trusted-firmware.hash b/board/orangepi/orangepi-zero2w/patches/arm-trusted-firmware/arm-trusted-firmware.hash
index c9d043c46f129..8b3df439a0539 100644
--- a/board/orangepi/orangepi-zero2w/patches/arm-trusted-firmware/arm-trusted-firmware.hash
+++ b/board/orangepi/orangepi-zero2w/patches/arm-trusted-firmware/arm-trusted-firmware.hash
@@ -1,2 +1,2 @@ 
 # Locally computed:
-sha256  2e18b881ada9198173238cca80086c787b1fa3f698944bde1743142823fc511c  arm-trusted-firmware-v2.10.tar.gz
+sha256  7efa89e1b4e4106ee05d68e876c8efbb146364d89cfd5d26bf4647b09c08f32b  arm-trusted-firmware-v2.10-git4.tar.gz
diff --git a/board/qemu/patches/arm-trusted-firmware/arm-trusted-firmware.hash b/board/qemu/patches/arm-trusted-firmware/arm-trusted-firmware.hash
index 74fe35c9bc733..0b99949745e7a 100644
--- a/board/qemu/patches/arm-trusted-firmware/arm-trusted-firmware.hash
+++ b/board/qemu/patches/arm-trusted-firmware/arm-trusted-firmware.hash
@@ -1,2 +1,2 @@ 
 # Locally computed:
-sha256  327c65b1bc231608a7a808b068b00c1a22310e9fc86158813cd10a9711d5725e  arm-trusted-firmware-v2.7.tar.gz
+sha256  c9f0d0bf967d690edbf34b621728a6271856f2e26ed46081a285b6d627a358c5  arm-trusted-firmware-v2.7-git4.tar.gz
diff --git a/board/stmicroelectronics/common/stm32mp157/patches/arm-trusted-firmware/arm-trusted-firmware.hash b/board/stmicroelectronics/common/stm32mp157/patches/arm-trusted-firmware/arm-trusted-firmware.hash
index 8b69a5a96453b..2bc5030cf2ff0 100644
--- a/board/stmicroelectronics/common/stm32mp157/patches/arm-trusted-firmware/arm-trusted-firmware.hash
+++ b/board/stmicroelectronics/common/stm32mp157/patches/arm-trusted-firmware/arm-trusted-firmware.hash
@@ -1,2 +1,2 @@ 
 # Locally calculated
-sha256  06d32acf42808b682859008292f0591d2d872f19aa1a8021bfcd1c1c626285e6  arm-trusted-firmware-v2.9.tar.gz
+sha256  72df0928138de111bf5e75fae47f88a4d1b4930ad52b7902e2b53e117be650c8  arm-trusted-firmware-v2.9-git4.tar.gz
diff --git a/board/ti/am62ax-sk/patches/arm-trusted-firmware/arm-trusted-firmware.hash b/board/ti/am62ax-sk/patches/arm-trusted-firmware/arm-trusted-firmware.hash
index 8f60864fbf67f..f0635a6652605 100644
--- a/board/ti/am62ax-sk/patches/arm-trusted-firmware/arm-trusted-firmware.hash
+++ b/board/ti/am62ax-sk/patches/arm-trusted-firmware/arm-trusted-firmware.hash
@@ -1,2 +1,2 @@ 
 # Locally computed:
-sha256  ba215404fe9db26e5f2cef3fdce17b7c8ed344a2a1d592dd01a5f1c5e72cfdbd  arm-trusted-firmware-lts-v2.10.4.tar.gz
+sha256  d7194687d13335f832a48c1b87ad4f15ffb983365ca2aba4afda57843fb01cb6  arm-trusted-firmware-lts-v2.10.4-git4.tar.gz
diff --git a/board/ti/am62x-sk/patches/arm-trusted-firmware/arm-trusted-firmware.hash b/board/ti/am62x-sk/patches/arm-trusted-firmware/arm-trusted-firmware.hash
index 7494e04ead5d0..d68ac4bd30db3 100644
--- a/board/ti/am62x-sk/patches/arm-trusted-firmware/arm-trusted-firmware.hash
+++ b/board/ti/am62x-sk/patches/arm-trusted-firmware/arm-trusted-firmware.hash
@@ -1,2 +1,2 @@ 
 # Locally calculated
-sha256  ba215404fe9db26e5f2cef3fdce17b7c8ed344a2a1d592dd01a5f1c5e72cfdbd  arm-trusted-firmware-lts-v2.10.4.tar.gz
+sha256  d7194687d13335f832a48c1b87ad4f15ffb983365ca2aba4afda57843fb01cb6  arm-trusted-firmware-lts-v2.10.4-git4.tar.gz
diff --git a/board/ti/am64x-sk/patches/arm-trusted-firmware/arm-trusted-firmware.hash b/board/ti/am64x-sk/patches/arm-trusted-firmware/arm-trusted-firmware.hash
index 7494e04ead5d0..d68ac4bd30db3 100644
--- a/board/ti/am64x-sk/patches/arm-trusted-firmware/arm-trusted-firmware.hash
+++ b/board/ti/am64x-sk/patches/arm-trusted-firmware/arm-trusted-firmware.hash
@@ -1,2 +1,2 @@ 
 # Locally calculated
-sha256  ba215404fe9db26e5f2cef3fdce17b7c8ed344a2a1d592dd01a5f1c5e72cfdbd  arm-trusted-firmware-lts-v2.10.4.tar.gz
+sha256  d7194687d13335f832a48c1b87ad4f15ffb983365ca2aba4afda57843fb01cb6  arm-trusted-firmware-lts-v2.10.4-git4.tar.gz
diff --git a/boot/arm-trusted-firmware/arm-trusted-firmware.hash b/boot/arm-trusted-firmware/arm-trusted-firmware.hash
index 73ab431b9fc97..660edb121edcc 100644
--- a/boot/arm-trusted-firmware/arm-trusted-firmware.hash
+++ b/boot/arm-trusted-firmware/arm-trusted-firmware.hash
@@ -1,4 +1,4 @@ 
 # Locally calculated
-sha256  2e18b881ada9198173238cca80086c787b1fa3f698944bde1743142823fc511c  arm-trusted-firmware-v2.10.tar.gz
-sha256  e55ae7105c996b60f748b2eb6adeaf5ac8946425e1d4294ecc1c56aebf435274  arm-trusted-firmware-lts-v2.8.13.tar.gz
+sha256  7efa89e1b4e4106ee05d68e876c8efbb146364d89cfd5d26bf4647b09c08f32b  arm-trusted-firmware-v2.10-git4.tar.gz
+sha256  695ae232fef6da931157e032b520f145b2c4cbe675d92b6a12222a332e960e89  arm-trusted-firmware-lts-v2.8.13-git4.tar.gz
 sha256  130d0c6e5159fa454b1e969fd281fa1d388819aefb203f65dd282544b5ab7ba9  docs/license.rst
diff --git a/boot/arm-trusted-firmware/arm-trusted-firmware.mk b/boot/arm-trusted-firmware/arm-trusted-firmware.mk
index abf917948eeee..1b2cc3a236e0a 100644
--- a/boot/arm-trusted-firmware/arm-trusted-firmware.mk
+++ b/boot/arm-trusted-firmware/arm-trusted-firmware.mk
@@ -16,7 +16,8 @@  ARM_TRUSTED_FIRMWARE_SITE = $(call qstrip,$(BR2_TARGET_ARM_TRUSTED_FIRMWARE_CUST
 ARM_TRUSTED_FIRMWARE_SITE_METHOD = git
 else
 # Handle stable official ATF versions
-ARM_TRUSTED_FIRMWARE_SITE = $(call github,ARM-software,arm-trusted-firmware,$(ARM_TRUSTED_FIRMWARE_VERSION))
+ARM_TRUSTED_FIRMWARE_SITE = https://git.trustedfirmware.org/TF-A/trusted-firmware-a.git
+ARM_TRUSTED_FIRMWARE_SITE_METHOD = git
 # The licensing of custom or from-git versions is unknown.
 # This is valid only for the latest (i.e. known) version.
 ifeq ($(BR2_TARGET_ARM_TRUSTED_FIRMWARE_LATEST_VERSION),y)