Skip to content

wolfBoot PolarFire SoC M-mode target with the Yocto RISC-V toolchain and ECC384 FIT signing - #181

Open
dgarske wants to merge 1 commit into
wolfSSL:masterfrom
dgarske:polarfire_mpfs
Open

dgarske wants to merge 1 commit into
wolfSSL:masterfrom
dgarske:polarfire_mpfs

Conversation

@dgarske

@dgarske dgarske commented Oct 2, 2026 •

Copy link
Copy Markdown
Member

Builds wolfBoot's standalone M-mode PolarFire SoC target (polarfire_mpfs250_m.config, which replaces the Hart Software Services (HSS)) with the BSP's riscv64 Linux toolchain, and signs the Microchip BSP FIT for it.

What it adds

  • wolfboot.inc - WOLFBOOT_GIT_URI / WOLFBOOT_GIT_BRANCH, so a fork or pre-merge branch can be selected from local.conf
  • wolfboot-signed-image.bb - WOLFBOOT_SIGN_ALGO / WOLFBOOT_HASH_ALGO (defaults unchanged: rsa4096 / sha3), and a version-independent image_signed.bin link in the deploy directory for wic layouts
  • wic/mpfs-wolfboot.wks - the BSP SD layout with the signed FIT raw in partition 1, where wolfBoot's disk loader reads it
  • README section for the PolarFire quick start (Libero config directory, ECC384 key pair, gzip FIT)

Changes to wolfboot_git.bb

  • Toolchain flags for the bootloader go into .config as CFLAGS_EXTRA / LDFLAGS_EXTRA instead of CC / LD on the make command line, which leaked the cross compiler into the sub-makes that build wolfBoot's host-side tools. A wolfBoot tree without the LDFLAGS_EXTRA consumer still gets the link flags through the LD override, so existing pins keep building.
  • -fno-pie / -no-pie / -Wl,--build-id=none: a default-PIE Linux toolchain otherwise produces a PIE and places a build-id note at the image base, ahead of the boot vector.
  • WOLFBOOT_NOSTDLIB for targets whose ABI the sysroot's libgcc does not match (M-mode is soft-float lp64 on an lp64d toolchain), plus empty gnu/stubs-<abi>.h for the ABI names glibc's stubs.h would otherwise fail to find.
  • Objects are cleared before make, so a re-run of do_compile with changed flags does not reuse objects from the previous configuration.

Needs the wolfBoot side of this change (LDFLAGS_EXTRA consumer, prebuilt KEYGEN_TOOL / SIGN_TOOL, libgcc-free FDT byte swaps): wolfSSL/wolfBoot#921.

Hardware / test status

PolarFire SoC Video Kit (MPFS250TS), meta-mchp linux4microchip+fpga-2025.10 (Scarthgap): wolfboot.elf programmed to eNVM with mpfsBootmodeProgrammer, the wic written to the SD card; wolfBoot verifies the ECC384-signed FIT and boots Linux 6.12 to the login prompt. The existing ZynqMP flow was not re-tested on hardware.

Scope

The Libero fpga_design_config directory and the signing key pair stay user-supplied paths. HSS payload generation for the S-mode (HSS-hosted) wolfBoot configuration is not covered.

@dgarske dgarske self-assigned this Oct 2, 2026
Copilot AI balanced review requested due to automatic review settings October 2, 2026 23:32

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The default wolfBoot revision lacks required linker support, and the Wic partition mapping conflicts with wolfBoot’s configured A/B slots.

Review effort: Balanced
Findings: 2 High severity

Open (2)
What changed in this PR

Adds PolarFire SoC M-mode wolfBoot builds and ECC384-signed FIT image generation using Yocto’s RISC-V toolchain.

Changes:

  • Adds configurable wolfBoot sources and signing algorithms.
  • Adds PolarFire-specific toolchain handling and documentation.
  • Adds a PolarFire SD-card Wic layout.
File Description
wic/​mpfs-wolfboot.wks Defines the PolarFire SD-card layout.
recipes-wolfssl/​wolfboot/​wolfboot.inc Makes wolfBoot repository and branch configurable.
recipes-wolfssl/​wolfboot/​wolfboot-signed-image.bb Supports configurable signing and stable artifact naming.
recipes-wolfssl/​wolfboot/​wolfboot_git.bb Adds RISC-V toolchain flags and native key-tool handling.
recipes-wolfssl/​wolfboot/​README.md Documents the PolarFire build and deployment flow.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread recipes-wolfssl/wolfboot/wolfboot_git.bb Outdated
Comment thread wic/mpfs-wolfboot.wks Outdated
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants