1 .\" SPDX-License-Identifier: GPL-2.0+
2 .\" Copyright (c) 2021, Linaro Limited
3 .\" written by AKASHI Takahiro <takahiro.akashi@linaro.org>
4 .TH MAEFICAPSULE 1 "May 2021"
7 mkeficapsule \- Generate EFI capsule file for U-Boot
11 .RI [ options ] " " [ image-blob ] " " capsule-file
16 command is used to create an EFI capsule file to be used by U-Boot for firmware
18 A capsule file may contain various types of firmware blobs which are to be
19 applied to the system.
20 If a capsule file is placed in the /EFI/CapusuleUpdate directory of the EFI
21 system partition, U-Boot will try to execute the update at the next reboot.
23 Optionally, a capsule file can be signed with a given private key.
24 In this case, the update will be authenticated by verifying the signature
27 Additionally, an empty capsule file can be generated to indicate the acceptance
28 or rejection of firmware images by a governing component like an operating
30 Empty capsules do not require an image-blob input file.
33 takes any type of image files when generating non empty capsules, including:
36 format is a single binary blob of any type of firmware.
39 .I FIT (Flattened Image Tree) image
40 format is the same as used in the new uImage format and allows for
41 multiple binary blobs in a single capsule file.
42 This type of image file can be generated by
48 .BI "-g\fR,\fB --guid " guid-string
49 Specify guid for image blob type. The format is:
50 xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx
52 The first three elements are in little endian, while the rest
53 is in big endian. The option must be specified for all non empty and
54 image acceptance capsules
57 .BI "-i\fR,\fB --index " index
58 Specify an image index
61 .BI "-I\fR,\fB --instance " instance
62 Specify a hardware instance
65 For generation of firmware accept empty capsule
69 .BI "-A\fR,\fB --fw-accept "
70 Generate a firmware acceptance empty capsule
73 .BI "-R\fR,\fB --fw-revert "
74 Generate a firmware revert empty capsule
77 .BI "-o\fR,\fB --capoemflag "
78 Capsule OEM flag, value between 0x0000 to 0xffff
86 .BR --private-key ", " --certificate " and " --monotonic-count
90 .BI "-p\fR,\fB --private-key " private-key-file
91 Specify signer's private key file in PEM
94 .BI "-c\fR,\fB --certificate " certificate-file
95 Specify signer's certificate file in EFI certificate list format
98 .BI "-m\fR,\fB --monotonic-count " count
99 Specify a monotonic count which is set to be monotonically incremented
100 at every firmware update.
103 .B "-d\fR,\fB --dump_sig"
104 Dump signature data into *.p7 file
109 .I /EFI/UpdateCapsule
110 The directory in which all capsule files be placed
116 Written by AKASHI Takahiro <takahiro.akashi@linaro.org>
119 http://www.denx.de/wiki/U-Boot/WebHome