This should not make any functional difference, and downstream boards that already override the keyfile property via an explicit .dtsi fragment for each node will continue to have precedence over the value coming from the template. But this makes it much more ergonomic to have the keyfile and distinguished-name have consistent values throughout, because one only has to override the values in the templates and not each and every individual node.
Reviewed-by: Simon Glass <[email protected]> Signed-off-by: Rasmus Villemoes <[email protected]> --- arch/arm/dts/k3-binman.dtsi | 21 ++++++++++----------- 1 file changed, 10 insertions(+), 11 deletions(-) diff --git a/arch/arm/dts/k3-binman.dtsi b/arch/arm/dts/k3-binman.dtsi index 2c9e5b619b7..797c271bdeb 100644 --- a/arch/arm/dts/k3-binman.dtsi +++ b/arch/arm/dts/k3-binman.dtsi @@ -150,8 +150,8 @@ arch = "arm"; compression = "none"; ti-secure { + insert-template = <&keyfile_template>, <&distinguished_name_template>; content = <&board_cfg>; - keyfile = "custMpk.pem"; }; board_cfg: board-cfg { filename = "board-cfg.bin"; @@ -165,8 +165,8 @@ arch = "arm"; compression = "none"; ti-secure { + insert-template = <&keyfile_template>, <&distinguished_name_template>; content = <&pm_cfg>; - keyfile = "custMpk.pem"; }; pm_cfg: pm-cfg { filename = "pm-cfg.bin"; @@ -179,8 +179,8 @@ arch = "arm"; compression = "none"; ti-secure { + insert-template = <&keyfile_template>, <&distinguished_name_template>; content = <&rm_cfg>; - keyfile = "custMpk.pem"; }; rm_cfg: rm-cfg { filename = "rm-cfg.bin"; @@ -193,8 +193,8 @@ arch = "arm"; compression = "none"; ti-secure { + insert-template = <&keyfile_template>, <&distinguished_name_template>; content = <&sec_cfg>; - keyfile = "custMpk.pem"; }; sec_cfg: sec-cfg { filename = "sec-cfg.bin"; @@ -287,8 +287,8 @@ load = <CONFIG_K3_ATF_LOAD_ADDR>; entry = <CONFIG_K3_ATF_LOAD_ADDR>; ti-secure { + insert-template = <&keyfile_template>, <&distinguished_name_template>; content = <&atf>; - keyfile = "custMpk.pem"; }; atf: atf-bl31 { }; @@ -303,8 +303,8 @@ load = <CONFIG_K3_OPTEE_LOAD_ADDR>; entry = <CONFIG_K3_OPTEE_LOAD_ADDR>; ti-secure { + insert-template = <&keyfile_template>, <&distinguished_name_template>; content = <&tee>; - keyfile = "custMpk.pem"; }; tee: tee-os { optional; @@ -330,9 +330,8 @@ load = <CONFIG_SPL_TEXT_BASE>; entry = <CONFIG_SPL_TEXT_BASE>; ti-secure { + insert-template = <&keyfile_template>, <&distinguished_name_template>; content = <&u_boot_spl_nodtb>; - keyfile = "custMpk.pem"; - }; u_boot_spl_nodtb: blob-ext { filename = "spl/u-boot-spl-nodtb.bin"; @@ -419,8 +418,8 @@ compression = "none"; load = <CONFIG_TEXT_BASE>; ti-secure { + insert-template = <&keyfile_template>, <&distinguished_name_template>; content = <&u_boot_nodtb>; - keyfile = "custMpk.pem"; }; u_boot_nodtb: u-boot-nodtb { }; @@ -521,8 +520,8 @@ load = <CONFIG_K3_ATF_LOAD_ADDR>; entry = <CONFIG_K3_ATF_LOAD_ADDR>; ti-secure { + insert-template = <&keyfile_template>, <&distinguished_name_template>; content = <&atf_falcon>; - keyfile = "custMpk.pem"; }; atf_falcon: atf-bl31 { }; @@ -536,8 +535,8 @@ load = <CONFIG_K3_OPTEE_LOAD_ADDR>; entry = <CONFIG_K3_OPTEE_LOAD_ADDR>; ti-secure { + insert-template = <&keyfile_template>, <&distinguished_name_template>; content = <&tee_falcon>; - keyfile = "custMpk.pem"; }; tee_falcon: tee-os { optional; -- 2.55.0
