arch/arm64/boot/dts/renesas/rzt2h-n2h-evk-common.dtsi | 2 ++ 1 file changed, 2 insertions(+)
From: Lad Prabhakar <prabhakar.mahadev-lad.rj@bp.renesas.com>
Mark the BL2 and FIP partitions on XSPI1 as read-only to prevent them
from being modified through the MTD partition interface.
The corresponding boot partitions on XSPI0 are already marked
read-only.
Signed-off-by: Lad Prabhakar <prabhakar.mahadev-lad.rj@bp.renesas.com>
---
arch/arm64/boot/dts/renesas/rzt2h-n2h-evk-common.dtsi | 2 ++
1 file changed, 2 insertions(+)
diff --git a/arch/arm64/boot/dts/renesas/rzt2h-n2h-evk-common.dtsi b/arch/arm64/boot/dts/renesas/rzt2h-n2h-evk-common.dtsi
index 20d0b607ec62..395316c61f33 100644
--- a/arch/arm64/boot/dts/renesas/rzt2h-n2h-evk-common.dtsi
+++ b/arch/arm64/boot/dts/renesas/rzt2h-n2h-evk-common.dtsi
@@ -825,11 +825,13 @@ partitions {
partition@0 {
label = "bl2-1";
reg = <0x00000000 0x00060000>;
+ read-only;
};
partition@60000 {
label = "fip-1";
reg = <0x00060000 0x007a0000>;
+ read-only;
};
partition@800000 {
--
2.43.0
Hi Prabhakar,
On Wed, 26 Aug 2026 at 13:28, Prabhakar <prabhakar.csengg@gmail.com> wrote:
> From: Lad Prabhakar <prabhakar.mahadev-lad.rj@bp.renesas.com>
>
> Mark the BL2 and FIP partitions on XSPI1 as read-only to prevent them
> from being modified through the MTD partition interface.
>
> The corresponding boot partitions on XSPI0 are already marked
> read-only.
>
> Signed-off-by: Lad Prabhakar <prabhakar.mahadev-lad.rj@bp.renesas.com>
Thanks for your patch!
> --- a/arch/arm64/boot/dts/renesas/rzt2h-n2h-evk-common.dtsi
> +++ b/arch/arm64/boot/dts/renesas/rzt2h-n2h-evk-common.dtsi
> @@ -825,11 +825,13 @@ partitions {
> partition@0 {
> label = "bl2-1";
> reg = <0x00000000 0x00060000>;
> + read-only;
> };
>
> partition@60000 {
> label = "fip-1";
> reg = <0x00060000 0x007a0000>;
> + read-only;
> };
>
> partition@800000 {
Makes sense. However, what is the recommended interface to update
the bootloader in these partitions?
Gr{oetje,eeting}s,
Geert
--
Geert Uytterhoeven -- There's lots of Linux beyond ia32 -- geert@linux-m68k.org
In personal conversations with technical people, I call myself a hacker. But
when I'm talking to journalists I just say "programmer" or something like that.
-- Linus Torvalds
Hi Geert,
On Wed, Aug 26, 2026 at 2:47 PM Geert Uytterhoeven <geert@linux-m68k.org> wrote:
>
> Hi Prabhakar,
>
> On Wed, 26 Aug 2026 at 13:28, Prabhakar <prabhakar.csengg@gmail.com> wrote:
> > From: Lad Prabhakar <prabhakar.mahadev-lad.rj@bp.renesas.com>
> >
> > Mark the BL2 and FIP partitions on XSPI1 as read-only to prevent them
> > from being modified through the MTD partition interface.
> >
> > The corresponding boot partitions on XSPI0 are already marked
> > read-only.
> >
> > Signed-off-by: Lad Prabhakar <prabhakar.mahadev-lad.rj@bp.renesas.com>
>
> Thanks for your patch!
>
> > --- a/arch/arm64/boot/dts/renesas/rzt2h-n2h-evk-common.dtsi
> > +++ b/arch/arm64/boot/dts/renesas/rzt2h-n2h-evk-common.dtsi
> > @@ -825,11 +825,13 @@ partitions {
> > partition@0 {
> > label = "bl2-1";
> > reg = <0x00000000 0x00060000>;
> > + read-only;
> > };
> >
> > partition@60000 {
> > label = "fip-1";
> > reg = <0x00060000 0x007a0000>;
> > + read-only;
> > };
> >
> > partition@800000 {
>
> Makes sense. However, what is the recommended interface to update
> the bootloader in these partitions?
>
The BSP supports updates via the flashwriter tool; there is no
recommended way as such. Are you hinting to allow this to be done via
Linux?
Cheers,
Prabhakar
> Gr{oetje,eeting}s,
>
> Geert
>
> --
> Geert Uytterhoeven -- There's lots of Linux beyond ia32 -- geert@linux-m68k.org
>
> In personal conversations with technical people, I call myself a hacker. But
> when I'm talking to journalists I just say "programmer" or something like that.
> -- Linus Torvalds
Hi Prabhakar,
On Wed, 26 Aug 2026 at 19:29, Lad, Prabhakar <prabhakar.csengg@gmail.com> wrote:
> On Wed, Aug 26, 2026 at 2:47 PM Geert Uytterhoeven <geert@linux-m68k.org> wrote:
> > On Wed, 26 Aug 2026 at 13:28, Prabhakar <prabhakar.csengg@gmail.com> wrote:
> > > From: Lad Prabhakar <prabhakar.mahadev-lad.rj@bp.renesas.com>
> > >
> > > Mark the BL2 and FIP partitions on XSPI1 as read-only to prevent them
> > > from being modified through the MTD partition interface.
> > >
> > > The corresponding boot partitions on XSPI0 are already marked
> > > read-only.
> > >
> > > Signed-off-by: Lad Prabhakar <prabhakar.mahadev-lad.rj@bp.renesas.com>
> >
> > Thanks for your patch!
> >
> > > --- a/arch/arm64/boot/dts/renesas/rzt2h-n2h-evk-common.dtsi
> > > +++ b/arch/arm64/boot/dts/renesas/rzt2h-n2h-evk-common.dtsi
> > > @@ -825,11 +825,13 @@ partitions {
> > > partition@0 {
> > > label = "bl2-1";
> > > reg = <0x00000000 0x00060000>;
> > > + read-only;
> > > };
> > >
> > > partition@60000 {
> > > label = "fip-1";
> > > reg = <0x00060000 0x007a0000>;
> > > + read-only;
> > > };
> > >
> > > partition@800000 {
> >
> > Makes sense. However, what is the recommended interface to update
> > the bootloader in these partitions?
> >
> The BSP supports updates via the flashwriter tool; there is no
> recommended way as such. Are you hinting to allow this to be done via
> Linux?
Exactly. But as you recommend flashwriter, and the two XSPI instances
should be consistent, I'll just take the patch.
Reviewed-by: Geert Uytterhoeven <geert+renesas@glider.be>
i.e. will queue in renesas-devel for v7.4.
Gr{oetje,eeting}s,
Geert
--
Geert Uytterhoeven -- There's lots of Linux beyond ia32 -- geert@linux-m68k.org
In personal conversations with technical people, I call myself a hacker. But
when I'm talking to journalists I just say "programmer" or something like that.
-- Linus Torvalds
© 2016 - 2026 Red Hat, Inc.