Conversation
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
The default wolfBoot revision lacks required linker support, and the Wic partition mapping conflicts with wolfBoot’s configured A/B slots.
Review effort: Balanced
Findings: 2
Open (2)
What changed in this PR
Adds PolarFire SoC M-mode wolfBoot builds and ECC384-signed FIT image generation using Yocto’s RISC-V toolchain.
Changes:
- Adds configurable wolfBoot sources and signing algorithms.
- Adds PolarFire-specific toolchain handling and documentation.
- Adds a PolarFire SD-card Wic layout.
| File | Description |
|---|---|
wic/mpfs-wolfboot.wks |
Defines the PolarFire SD-card layout. |
recipes-wolfssl/wolfboot/wolfboot.inc |
Makes wolfBoot repository and branch configurable. |
recipes-wolfssl/wolfboot/wolfboot-signed-image.bb |
Supports configurable signing and stable artifact naming. |
recipes-wolfssl/wolfboot/wolfboot_git.bb |
Adds RISC-V toolchain flags and native key-tool handling. |
recipes-wolfssl/wolfboot/README.md |
Documents the PolarFire build and deployment flow. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
… toolchain and sign its FIT with ECC384
dgarske
force-pushed
the
polarfire_mpfs
branch
from
October 3, 2026 00:17
0c4fbb7 to
5161e43
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

Builds wolfBoot's standalone M-mode PolarFire SoC target (
polarfire_mpfs250_m.config, which replaces the Hart Software Services (HSS)) with the BSP's riscv64 Linux toolchain, and signs the Microchip BSP FIT for it.What it adds
wolfboot.inc-WOLFBOOT_GIT_URI/WOLFBOOT_GIT_BRANCH, so a fork or pre-merge branch can be selected from local.confwolfboot-signed-image.bb-WOLFBOOT_SIGN_ALGO/WOLFBOOT_HASH_ALGO(defaults unchanged: rsa4096 / sha3), and a version-independentimage_signed.binlink in the deploy directory for wic layoutswic/mpfs-wolfboot.wks- the BSP SD layout with the signed FIT raw in partition 1, where wolfBoot's disk loader reads itChanges to wolfboot_git.bb
.configasCFLAGS_EXTRA/LDFLAGS_EXTRAinstead ofCC/LDon the make command line, which leaked the cross compiler into the sub-makes that build wolfBoot's host-side tools. A wolfBoot tree without theLDFLAGS_EXTRAconsumer still gets the link flags through theLDoverride, so existing pins keep building.-fno-pie/-no-pie/-Wl,--build-id=none: a default-PIE Linux toolchain otherwise produces a PIE and places a build-id note at the image base, ahead of the boot vector.WOLFBOOT_NOSTDLIBfor targets whose ABI the sysroot's libgcc does not match (M-mode is soft-float lp64 on an lp64d toolchain), plus emptygnu/stubs-<abi>.hfor the ABI names glibc'sstubs.hwould otherwise fail to find.make, so a re-run of do_compile with changed flags does not reuse objects from the previous configuration.Needs the wolfBoot side of this change (LDFLAGS_EXTRA consumer, prebuilt KEYGEN_TOOL / SIGN_TOOL, libgcc-free FDT byte swaps): wolfSSL/wolfBoot#921.
Hardware / test status
PolarFire SoC Video Kit (MPFS250TS), meta-mchp linux4microchip+fpga-2025.10 (Scarthgap):
wolfboot.elfprogrammed to eNVM with mpfsBootmodeProgrammer, the wic written to the SD card; wolfBoot verifies the ECC384-signed FIT and boots Linux 6.12 to the login prompt. The existing ZynqMP flow was not re-tested on hardware.Scope
The Libero
fpga_design_configdirectory and the signing key pair stay user-supplied paths. HSS payload generation for the S-mode (HSS-hosted) wolfBoot configuration is not covered.