2022-02-13 00:09:46 +00:00
|
|
|
.TH MKIMAGE 1 "2022-02-07"
|
2010-06-16 01:38:24 +00:00
|
|
|
|
|
|
|
.SH NAME
|
|
|
|
mkimage \- Generate image for U-Boot
|
|
|
|
.SH SYNOPSIS
|
|
|
|
.B mkimage
|
2022-02-13 00:09:46 +00:00
|
|
|
.RB [ \-T " \fItype\fP] " \-l " [\fIuimage file name\fP]"
|
2013-06-13 22:10:03 +00:00
|
|
|
|
|
|
|
.B mkimage
|
|
|
|
.RB [\fIoptions\fP] " \-f [" "image tree source file" "]" " [" "uimage file name" "]"
|
|
|
|
|
2013-06-13 22:10:05 +00:00
|
|
|
.B mkimage
|
|
|
|
.RB [\fIoptions\fP] " \-F [" "uimage file name" "]"
|
|
|
|
|
2013-06-13 22:10:03 +00:00
|
|
|
.B mkimage
|
|
|
|
.RB [\fIoptions\fP] " (legacy mode)"
|
|
|
|
|
2010-06-16 01:38:24 +00:00
|
|
|
.SH "DESCRIPTION"
|
|
|
|
The
|
|
|
|
.B mkimage
|
|
|
|
command is used to create images for use with the U-Boot boot loader.
|
2011-12-21 04:31:23 +00:00
|
|
|
These images can contain the linux kernel, device tree blob, root file
|
2010-06-16 01:38:24 +00:00
|
|
|
system image, firmware images etc., either separate or combined.
|
|
|
|
|
|
|
|
.B mkimage
|
|
|
|
supports two different formats:
|
|
|
|
|
2011-12-21 04:31:23 +00:00
|
|
|
The old
|
2010-06-16 01:38:24 +00:00
|
|
|
.I legacy image
|
|
|
|
format concatenates the individual parts (for example, kernel image,
|
|
|
|
device tree blob and ramdisk image) and adds a 64 bytes header
|
|
|
|
containing information about target architecture, operating system,
|
|
|
|
image type, compression method, entry points, time stamp, checksums,
|
|
|
|
etc.
|
|
|
|
|
2011-12-21 04:31:23 +00:00
|
|
|
The new
|
2010-06-16 01:38:24 +00:00
|
|
|
.I FIT (Flattened Image Tree) format
|
2011-12-21 04:31:23 +00:00
|
|
|
allows for more flexibility in handling images of various types and also
|
2013-06-13 22:10:03 +00:00
|
|
|
enhances integrity protection of images with stronger checksums. It also
|
|
|
|
supports verified boot.
|
2010-06-16 01:38:24 +00:00
|
|
|
|
|
|
|
.SH "OPTIONS"
|
|
|
|
|
|
|
|
.B List image information:
|
|
|
|
|
|
|
|
.TP
|
|
|
|
.BI "\-l [" "uimage file name" "]"
|
|
|
|
mkimage lists the information contained in the header of an existing U-Boot image.
|
|
|
|
|
2022-02-13 00:09:46 +00:00
|
|
|
.TP
|
|
|
|
.BI "\-T [" "image type" "]"
|
|
|
|
Parse image file as type.
|
|
|
|
Pass \-h as the image to see the list of supported image type.
|
|
|
|
Without this option image type is autodetected.
|
|
|
|
|
2022-04-08 20:08:39 +00:00
|
|
|
.TP
|
|
|
|
.BI "\-q"
|
|
|
|
Quiet. Don't print the image header on successful verification.
|
|
|
|
|
2010-06-16 01:38:24 +00:00
|
|
|
.P
|
|
|
|
.B Create old legacy image:
|
|
|
|
|
|
|
|
.TP
|
|
|
|
.BI "\-A [" "architecture" "]"
|
2011-01-04 01:32:36 +00:00
|
|
|
Set architecture. Pass \-h as the architecture to see the list of supported architectures.
|
2010-06-16 01:38:24 +00:00
|
|
|
|
|
|
|
.TP
|
|
|
|
.BI "\-O [" "os" "]"
|
|
|
|
Set operating system. bootm command of u-boot changes boot method by os type.
|
2011-01-04 01:32:36 +00:00
|
|
|
Pass \-h as the OS to see the list of supported OS.
|
2010-06-16 01:38:24 +00:00
|
|
|
|
|
|
|
.TP
|
|
|
|
.BI "\-T [" "image type" "]"
|
|
|
|
Set image type.
|
2011-01-04 01:32:36 +00:00
|
|
|
Pass \-h as the image to see the list of supported image type.
|
2010-06-16 01:38:24 +00:00
|
|
|
|
|
|
|
.TP
|
|
|
|
.BI "\-C [" "compression type" "]"
|
|
|
|
Set compression type.
|
2011-01-04 01:32:36 +00:00
|
|
|
Pass \-h as the compression to see the list of supported compression type.
|
2010-06-16 01:38:24 +00:00
|
|
|
|
|
|
|
.TP
|
2016-09-14 19:54:53 +00:00
|
|
|
.BI "\-a [" "load address" "]"
|
2010-06-16 01:38:24 +00:00
|
|
|
Set load address with a hex number.
|
|
|
|
|
|
|
|
.TP
|
|
|
|
.BI "\-e [" "entry point" "]"
|
|
|
|
Set entry point with a hex number.
|
|
|
|
|
2013-06-13 22:10:03 +00:00
|
|
|
.TP
|
|
|
|
.BI "\-l"
|
|
|
|
List the contents of an image.
|
|
|
|
|
2010-06-16 01:38:24 +00:00
|
|
|
.TP
|
|
|
|
.BI "\-n [" "image name" "]"
|
|
|
|
Set image name to 'image name'.
|
|
|
|
|
2022-04-08 20:08:39 +00:00
|
|
|
.TP
|
|
|
|
.BI "\-R [" "secondary image name" "]"
|
|
|
|
Some image types support a second image for additional data. For these types,
|
|
|
|
use \-R to specify this second image.
|
2022-05-16 20:11:07 +00:00
|
|
|
.TS
|
|
|
|
allbox;
|
|
|
|
lb lbx
|
|
|
|
l l.
|
|
|
|
Image Type Secondary Image Description
|
|
|
|
pblimage Additional RCW-style header, typically used for PBI commands.
|
|
|
|
zynqimage, zynqmpimage T{
|
|
|
|
Initialization parameters, one per line. Each parameter has the form
|
|
|
|
.sp
|
|
|
|
.ti 4
|
|
|
|
.I address data
|
|
|
|
.sp
|
|
|
|
where
|
|
|
|
.I address
|
|
|
|
and
|
|
|
|
.I data
|
|
|
|
are hexadecimal integers. The boot ROM will write each
|
|
|
|
.I data
|
|
|
|
to
|
|
|
|
.I address
|
|
|
|
when loading the image. At most 256 parameters may be specified in this
|
|
|
|
manner.
|
|
|
|
T}
|
|
|
|
.TE
|
2022-04-08 20:08:39 +00:00
|
|
|
|
2010-06-16 01:38:24 +00:00
|
|
|
.TP
|
|
|
|
.BI "\-d [" "image data file" "]"
|
|
|
|
Use image data from 'image data file'.
|
|
|
|
|
|
|
|
.TP
|
|
|
|
.BI "\-x"
|
|
|
|
Set XIP (execute in place) flag.
|
|
|
|
|
2022-04-08 20:08:39 +00:00
|
|
|
.TP
|
|
|
|
.BI "\-s"
|
2022-05-16 20:11:07 +00:00
|
|
|
Don't copy in the image data. Depending on the image type, this may create
|
|
|
|
just the header, everything but the image data, or nothing at all.
|
2022-04-08 20:08:39 +00:00
|
|
|
|
|
|
|
.TP
|
|
|
|
.BI "\-v"
|
|
|
|
Verbose. Print file names as they are added to the image.
|
|
|
|
|
2010-06-16 01:38:24 +00:00
|
|
|
.P
|
|
|
|
.B Create FIT image:
|
|
|
|
|
2016-02-23 05:55:52 +00:00
|
|
|
.TP
|
2016-05-01 01:01:27 +00:00
|
|
|
.BI "\-b [" "device tree file" "]
|
|
|
|
Appends the device tree binary file (.dtb) to the FIT.
|
2016-02-23 05:55:52 +00:00
|
|
|
|
2013-06-13 22:10:06 +00:00
|
|
|
.TP
|
|
|
|
.BI "\-c [" "comment" "]"
|
|
|
|
Specifies a comment to be added when signing. This is typically a useful
|
|
|
|
message which describes how the image was signed or some other useful
|
|
|
|
information.
|
|
|
|
|
2010-06-16 01:38:24 +00:00
|
|
|
.TP
|
2011-12-23 05:40:20 +00:00
|
|
|
.BI "\-D [" "dtc options" "]"
|
2010-06-16 01:38:24 +00:00
|
|
|
Provide special options to the device tree compiler that is used to
|
|
|
|
create the image.
|
|
|
|
|
2016-02-23 05:55:53 +00:00
|
|
|
.TP
|
|
|
|
.BI "\-E
|
|
|
|
After processing, move the image data outside the FIT and store a data offset
|
|
|
|
in the FIT. Images will be placed one after the other immediately after the
|
|
|
|
FIT, with each one aligned to a 4-byte boundary. The existing 'data' property
|
|
|
|
in each image will be replaced with 'data-offset' and 'data-size' properties.
|
|
|
|
A 'data-offset' of 0 indicates that it starts in the first (4-byte aligned)
|
|
|
|
byte after the FIT.
|
|
|
|
|
2022-04-08 20:08:39 +00:00
|
|
|
.TP
|
|
|
|
.BI "\-B [" "alignment" "]"
|
|
|
|
The alignment, in hexadecimal, that external data will be aligned to. This
|
|
|
|
option only has an effect when \-E is specified.
|
|
|
|
|
2010-06-16 01:38:24 +00:00
|
|
|
.TP
|
2016-02-23 05:55:51 +00:00
|
|
|
.BI "\-f [" "image tree source file" " | " "auto" "]"
|
2011-12-21 04:31:23 +00:00
|
|
|
Image tree source file that describes the structure and contents of the
|
2010-06-16 01:38:24 +00:00
|
|
|
FIT image.
|
|
|
|
|
2016-02-23 05:55:51 +00:00
|
|
|
This can be automatically generated for some simple cases.
|
|
|
|
Use "-f auto" for this. In that case the arguments -d, -A, -O, -T, -C, -a
|
|
|
|
and -e are used to specify the image to include in the FIT and its attributes.
|
|
|
|
No .its file is required.
|
|
|
|
|
2013-06-13 22:10:05 +00:00
|
|
|
.TP
|
|
|
|
.BI "\-F"
|
|
|
|
Indicates that an existing FIT image should be modified. No dtc
|
2014-11-02 01:09:01 +00:00
|
|
|
compilation is performed and the \-f flag should not be given.
|
2013-06-13 22:10:05 +00:00
|
|
|
This can be used to sign images with additional keys after initial image
|
|
|
|
creation.
|
|
|
|
|
2016-11-04 13:22:15 +00:00
|
|
|
.TP
|
|
|
|
.BI "\-i [" "ramdisk_file" "]"
|
|
|
|
Appends the ramdisk file to the FIT.
|
|
|
|
|
2013-06-13 22:10:03 +00:00
|
|
|
.TP
|
|
|
|
.BI "\-k [" "key_directory" "]"
|
|
|
|
Specifies the directory containing keys to use for signing. This directory
|
|
|
|
should contain a private key file <name>.key for use with signing and a
|
|
|
|
certificate <name>.crt (containing the public key) for use with verification.
|
|
|
|
|
2022-05-16 20:11:07 +00:00
|
|
|
.TP
|
|
|
|
.BI "\-G [" "key_file" "]"
|
|
|
|
Specifies the private key file to use when signing. This option may be used
|
|
|
|
instead of \-k.
|
|
|
|
|
2013-06-13 22:10:04 +00:00
|
|
|
.TP
|
|
|
|
.BI "\-K [" "key_destination" "]"
|
|
|
|
Specifies a compiled device tree binary file (typically .dtb) to write
|
|
|
|
public key information into. When a private key is used to sign an image,
|
|
|
|
the corresponding public key is written into this file for for run-time
|
|
|
|
verification. Typically the file here is the device tree binary used by
|
|
|
|
CONFIG_OF_CONTROL in U-Boot.
|
|
|
|
|
2022-04-08 20:08:39 +00:00
|
|
|
.TP
|
|
|
|
.BI "\-G [" "key_file" "]"
|
|
|
|
Specifies the private key file to use when signing. This option may be used
|
|
|
|
instead of \-k.
|
|
|
|
|
2022-05-16 20:11:08 +00:00
|
|
|
.TP
|
|
|
|
.BI "\-g [" "key_name_hint" "]"
|
|
|
|
Sets the key-name-hint property when used with \-f auto. This is the <name>
|
|
|
|
part of the key. The directory part is set by \-k. This option also indicates
|
|
|
|
that the images included in the FIT should be signed. If this option is
|
|
|
|
specified, \-o must be specified as well.
|
|
|
|
|
2022-01-14 09:21:19 +00:00
|
|
|
.TP
|
|
|
|
.BI "\-o [" "signing algorithm" "]"
|
|
|
|
Specifies the algorithm to be used for signing a FIT image. The default is
|
2022-02-05 12:19:36 +00:00
|
|
|
taken from the signature node's 'algo' property.
|
2022-01-14 09:21:19 +00:00
|
|
|
|
2016-06-10 02:38:02 +00:00
|
|
|
.TP
|
|
|
|
.BI "\-p [" "external position" "]"
|
|
|
|
Place external data at a static external position. See \-E. Instead of writing
|
|
|
|
a 'data-offset' property defining the offset from the end of the FIT, \-p will
|
|
|
|
use 'data-position' as the absolute position from the base of the FIT.
|
|
|
|
|
2013-06-13 22:10:07 +00:00
|
|
|
.TP
|
2022-04-08 20:08:39 +00:00
|
|
|
.BI "\-r"
|
2013-06-13 22:10:07 +00:00
|
|
|
Specifies that keys used to sign the FIT are required. This means that they
|
|
|
|
must be verified for the image to boot. Without this option, the verification
|
|
|
|
will be optional (useful for testing but not for release).
|
|
|
|
|
2022-04-08 20:08:39 +00:00
|
|
|
.TP
|
|
|
|
.BI "\-N [" "engine" "]"
|
|
|
|
The openssl engine to use when signing and verifying the image. For a complete list of
|
|
|
|
available engines, refer to
|
|
|
|
.BR engine (1).
|
|
|
|
|
2020-07-10 00:39:43 +00:00
|
|
|
.TP
|
|
|
|
.BI "\-t
|
|
|
|
Update the timestamp in the FIT.
|
|
|
|
|
|
|
|
Normally the FIT timestamp is created the first time mkimage is run on a FIT,
|
|
|
|
when converting the source .its to the binary .fit file. This corresponds to
|
|
|
|
using the -f flag. But if the original input to mkimage is a binary file
|
|
|
|
(already compiled) then the timestamp is assumed to have been set previously.
|
|
|
|
|
2011-12-21 04:31:23 +00:00
|
|
|
.SH EXAMPLES
|
2010-06-16 01:38:24 +00:00
|
|
|
|
|
|
|
List image information:
|
|
|
|
.nf
|
|
|
|
.B mkimage -l uImage
|
|
|
|
.fi
|
|
|
|
.P
|
|
|
|
Create legacy image with compressed PowerPC Linux kernel:
|
|
|
|
.nf
|
|
|
|
.B mkimage -A powerpc -O linux -T kernel -C gzip \\\\
|
|
|
|
.br
|
|
|
|
.B -a 0 -e 0 -n Linux -d vmlinux.gz uImage
|
|
|
|
.fi
|
|
|
|
.P
|
|
|
|
Create FIT image with compressed PowerPC Linux kernel:
|
|
|
|
.nf
|
|
|
|
.B mkimage -f kernel.its kernel.itb
|
|
|
|
.fi
|
2013-06-13 22:10:04 +00:00
|
|
|
.P
|
|
|
|
Create FIT image with compressed kernel and sign it with keys in the
|
|
|
|
/public/signing-keys directory. Add corresponding public keys into u-boot.dtb,
|
|
|
|
skipping those for which keys cannot be found. Also add a comment.
|
|
|
|
.nf
|
|
|
|
.B mkimage -f kernel.its -k /public/signing-keys -K u-boot.dtb \\\\
|
2014-11-02 01:09:01 +00:00
|
|
|
.br
|
2016-02-23 05:55:49 +00:00
|
|
|
.B -c """Kernel 3.8 image for production devices""" kernel.itb
|
2013-06-13 22:10:04 +00:00
|
|
|
.fi
|
2010-06-16 01:38:24 +00:00
|
|
|
|
2022-05-16 20:11:08 +00:00
|
|
|
.P
|
|
|
|
Add public keys to u-boot.dtb without needing a FIT to sign. This will also
|
|
|
|
create a FIT containing an images node with no data named unused.itb.
|
|
|
|
.nf
|
|
|
|
.B mkimage -f auto -d /dev/null -k /public/signing-keys -g dev \\\\
|
|
|
|
.br
|
|
|
|
.B -o sha256,rsa2048 -K u-boot.dtb unused.itb
|
|
|
|
.fi
|
|
|
|
|
2013-06-13 22:10:05 +00:00
|
|
|
.P
|
|
|
|
Update an existing FIT image, signing it with additional keys.
|
|
|
|
Add corresponding public keys into u-boot.dtb. This will resign all images
|
|
|
|
with keys that are available in the new directory. Images that request signing
|
|
|
|
with unavailable keys are skipped.
|
|
|
|
.nf
|
|
|
|
.B mkimage -F -k /secret/signing-keys -K u-boot.dtb \\\\
|
2014-11-02 01:09:01 +00:00
|
|
|
.br
|
2016-02-23 05:55:49 +00:00
|
|
|
.B -c """Kernel 3.8 image for production devices""" kernel.itb
|
2013-06-13 22:10:05 +00:00
|
|
|
.fi
|
|
|
|
|
2016-02-23 05:55:51 +00:00
|
|
|
.P
|
|
|
|
Create a FIT image containing a kernel, using automatic mode. No .its file
|
|
|
|
is required.
|
|
|
|
.nf
|
|
|
|
.B mkimage -f auto -A arm -O linux -T kernel -C none -a 43e00000 -e 0 \\\\
|
|
|
|
.br
|
|
|
|
.B -c """Kernel 4.4 image for production devices""" -d vmlinuz kernel.itb
|
|
|
|
.fi
|
2016-02-23 05:55:52 +00:00
|
|
|
.P
|
|
|
|
Create a FIT image containing a kernel and some device tree files, using
|
|
|
|
automatic mode. No .its file is required.
|
|
|
|
.nf
|
|
|
|
.B mkimage -f auto -A arm -O linux -T kernel -C none -a 43e00000 -e 0 \\\\
|
|
|
|
.br
|
|
|
|
.B -c """Kernel 4.4 image for production devices""" -d vmlinuz \\\\
|
2016-05-01 01:01:27 +00:00
|
|
|
.B -b /path/to/rk3288-firefly.dtb -b /path/to/rk3288-jerry.dtb kernel.itb
|
2016-02-23 05:55:52 +00:00
|
|
|
.fi
|
2022-05-16 20:11:08 +00:00
|
|
|
.P
|
|
|
|
Create a FIT image containing a signed kernel, using automatic mode. No .its
|
|
|
|
file is required.
|
|
|
|
.nf
|
|
|
|
.B mkimage -f auto -A arm -O linux -T kernel -C none -a 43e00000 -e 0 \\\\
|
|
|
|
.br
|
|
|
|
.B -d vmlinuz -k /secret/signing-keys -g dev -o sha256,rsa2048 kernel.itb
|
|
|
|
.fi
|
2016-02-23 05:55:51 +00:00
|
|
|
|
2010-06-16 01:38:24 +00:00
|
|
|
.SH HOMEPAGE
|
|
|
|
http://www.denx.de/wiki/U-Boot/WebHome
|
|
|
|
.PP
|
|
|
|
.SH AUTHOR
|
|
|
|
This manual page was written by Nobuhiro Iwamatsu <iwamatsu@nigauri.org>
|
2013-06-13 22:10:03 +00:00
|
|
|
and Wolfgang Denk <wd@denx.de>. It was updated for image signing by
|
|
|
|
Simon Glass <sjg@chromium.org>.
|