blob: c4c2057d5c7affc3a5c25c77d3bf512a2f956aa1 [file] [log] [blame]
AKASHI Takahiro118a0ec2022-02-09 19:10:36 +09001.\" SPDX-License-Identifier: GPL-2.0+
2.\" Copyright (c) 2021, Linaro Limited
3.\" written by AKASHI Takahiro <takahiro.akashi@linaro.org>
4.TH MAEFICAPSULE 1 "May 2021"
5
6.SH NAME
7mkeficapsule \- Generate EFI capsule file for U-Boot
8
9.SH SYNOPSIS
10.B mkeficapsule
Sughosh Ganu6da92712022-10-21 18:16:06 +053011.RI [ options ] " " [ image-blob ] " " capsule-file
AKASHI Takahiro118a0ec2022-02-09 19:10:36 +090012
13.SH "DESCRIPTION"
Heinrich Schuchardta13b92a2023-01-22 11:27:10 +010014The
AKASHI Takahiro118a0ec2022-02-09 19:10:36 +090015.B mkeficapsule
Heinrich Schuchardta13b92a2023-01-22 11:27:10 +010016command is used to create an EFI capsule file to be used by U-Boot for firmware
17updates.
18A capsule file may contain various types of firmware blobs which are to be
19applied to the system.
20If a capsule file is placed in the /EFI/CapusuleUpdate directory of the EFI
21system partition, U-Boot will try to execute the update at the next reboot.
AKASHI Takahiro118a0ec2022-02-09 19:10:36 +090022
23Optionally, a capsule file can be signed with a given private key.
24In this case, the update will be authenticated by verifying the signature
25before applying.
26
Heinrich Schuchardta13b92a2023-01-22 11:27:10 +010027Additionally, an empty capsule file can be generated to indicate the acceptance
28or rejection of firmware images by a governing component like an operating
29system.
30Empty capsules do not require an image-blob input file.
Sughosh Ganu6da92712022-10-21 18:16:06 +053031
AKASHI Takahiro118a0ec2022-02-09 19:10:36 +090032.B mkeficapsule
Sughosh Ganu6da92712022-10-21 18:16:06 +053033takes any type of image files when generating non empty capsules, including:
AKASHI Takahiro118a0ec2022-02-09 19:10:36 +090034.TP
35.I raw image
36format is a single binary blob of any type of firmware.
37
38.TP
39.I FIT (Flattened Image Tree) image
40format is the same as used in the new uImage format and allows for
41multiple binary blobs in a single capsule file.
42This type of image file can be generated by
43.BR mkimage .
44
45.SH "OPTIONS"
Sughosh Ganu6da92712022-10-21 18:16:06 +053046
AKASHI Takahirod9612f42022-02-09 19:10:39 +090047.TP
48.BI "-g\fR,\fB --guid " guid-string
49Specify guid for image blob type. The format is:
50 xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx
51
52The first three elements are in little endian, while the rest
Sughosh Ganu6da92712022-10-21 18:16:06 +053053is in big endian. The option must be specified for all non empty and
54image acceptance capsules
AKASHI Takahiro118a0ec2022-02-09 19:10:36 +090055
56.TP
57.BI "-i\fR,\fB --index " index
58Specify an image index
59
60.TP
61.BI "-I\fR,\fB --instance " instance
62Specify a hardware instance
63
Sughosh Ganu6da92712022-10-21 18:16:06 +053064.PP
Masahisa Kojima000806f2023-06-07 14:41:56 +090065FMP Payload Header is inserted right before the payload if
66.BR --fw-version
67is specified
68
69
70.TP
71.BI "-v\fR,\fB --fw-version " firmware-version
72Specify a firmware version, 0 if omitted
73
74.PP
Sughosh Ganu6da92712022-10-21 18:16:06 +053075For generation of firmware accept empty capsule
76.BR --guid
77is mandatory
78.TP
79.BI "-A\fR,\fB --fw-accept "
80Generate a firmware acceptance empty capsule
81
82.TP
83.BI "-R\fR,\fB --fw-revert "
84Generate a firmware revert empty capsule
85
AKASHI Takahiro118a0ec2022-02-09 19:10:36 +090086.TP
Sughosh Ganuf65ee992022-10-21 18:16:07 +053087.BI "-o\fR,\fB --capoemflag "
88Capsule OEM flag, value between 0x0000 to 0xffff
89
90.TP
AKASHI Takahiro118a0ec2022-02-09 19:10:36 +090091.BR -h ", " --help
92Print a help message
93
94.PP
95With signing,
96.BR --private-key ", " --certificate " and " --monotonic-count
97are all mandatory.
98
99.TP
100.BI "-p\fR,\fB --private-key " private-key-file
101Specify signer's private key file in PEM
102
103.TP
104.BI "-c\fR,\fB --certificate " certificate-file
105Specify signer's certificate file in EFI certificate list format
106
107.TP
108.BI "-m\fR,\fB --monotonic-count " count
109Specify a monotonic count which is set to be monotonically incremented
110at every firmware update.
111
112.TP
113.B "-d\fR,\fB --dump_sig"
114Dump signature data into *.p7 file
115
116.PP
117.SH FILES
118.TP
119.I /EFI/UpdateCapsule
120The directory in which all capsule files be placed
121
122.SH SEE ALSO
123.BR mkimage (1)
124
125.SH AUTHORS
126Written by AKASHI Takahiro <takahiro.akashi@linaro.org>
127
128.SH HOMEPAGE
129http://www.denx.de/wiki/U-Boot/WebHome