xref: /OK3568_Linux_fs/u-boot/common/image-android.c (revision 4882a59341e53eb6f0b4789bf948001014eff981)
1*4882a593Smuzhiyun /*
2*4882a593Smuzhiyun  * Copyright (c) 2011 Sebastian Andrzej Siewior <bigeasy@linutronix.de>
3*4882a593Smuzhiyun  *
4*4882a593Smuzhiyun  * SPDX-License-Identifier:	GPL-2.0+
5*4882a593Smuzhiyun  */
6*4882a593Smuzhiyun 
7*4882a593Smuzhiyun #include <common.h>
8*4882a593Smuzhiyun #include <image.h>
9*4882a593Smuzhiyun #include <android_ab.h>
10*4882a593Smuzhiyun #include <android_bootloader.h>
11*4882a593Smuzhiyun #include <android_image.h>
12*4882a593Smuzhiyun #include <malloc.h>
13*4882a593Smuzhiyun #include <mapmem.h>
14*4882a593Smuzhiyun #include <errno.h>
15*4882a593Smuzhiyun #include <boot_rkimg.h>
16*4882a593Smuzhiyun #include <crypto.h>
17*4882a593Smuzhiyun #include <sysmem.h>
18*4882a593Smuzhiyun #include <mp_boot.h>
19*4882a593Smuzhiyun #include <u-boot/sha1.h>
20*4882a593Smuzhiyun #ifdef CONFIG_RKIMG_BOOTLOADER
21*4882a593Smuzhiyun #include <asm/arch/resource_img.h>
22*4882a593Smuzhiyun #endif
23*4882a593Smuzhiyun #ifdef CONFIG_RK_AVB_LIBAVB_USER
24*4882a593Smuzhiyun #include <android_avb/avb_slot_verify.h>
25*4882a593Smuzhiyun #include <android_avb/avb_ops_user.h>
26*4882a593Smuzhiyun #include <android_avb/rk_avb_ops_user.h>
27*4882a593Smuzhiyun #endif
28*4882a593Smuzhiyun #include <optee_include/OpteeClientInterface.h>
29*4882a593Smuzhiyun 
30*4882a593Smuzhiyun DECLARE_GLOBAL_DATA_PTR;
31*4882a593Smuzhiyun 
32*4882a593Smuzhiyun #define ANDROID_IMAGE_DEFAULT_KERNEL_ADDR	0x10008000
33*4882a593Smuzhiyun #define ANDROID_PARTITION_VENDOR_BOOT		"vendor_boot"
34*4882a593Smuzhiyun #define ANDROID_PARTITION_INIT_BOOT		"init_boot"
35*4882a593Smuzhiyun 
36*4882a593Smuzhiyun #define BLK_CNT(_num_bytes, _block_size)	\
37*4882a593Smuzhiyun 		((_num_bytes + _block_size - 1) / _block_size)
38*4882a593Smuzhiyun 
39*4882a593Smuzhiyun static char andr_tmp_str[ANDR_BOOT_ARGS_SIZE + 1];
40*4882a593Smuzhiyun static u32 android_kernel_comp_type = IH_COMP_NONE;
41*4882a593Smuzhiyun 
android_version_init(void)42*4882a593Smuzhiyun static int android_version_init(void)
43*4882a593Smuzhiyun {
44*4882a593Smuzhiyun 	struct andr_img_hdr *hdr = NULL;
45*4882a593Smuzhiyun 	struct blk_desc *desc;
46*4882a593Smuzhiyun 	const char *part_name = PART_BOOT;
47*4882a593Smuzhiyun 	disk_partition_t part;
48*4882a593Smuzhiyun 	int os_version;
49*4882a593Smuzhiyun 
50*4882a593Smuzhiyun 	desc = rockchip_get_bootdev();
51*4882a593Smuzhiyun 	if (!desc) {
52*4882a593Smuzhiyun 		printf("No bootdev\n");
53*4882a593Smuzhiyun 		return -1;
54*4882a593Smuzhiyun 	}
55*4882a593Smuzhiyun 
56*4882a593Smuzhiyun #ifdef CONFIG_ANDROID_AB
57*4882a593Smuzhiyun 	part_name = ab_can_find_recovery_part() ? PART_RECOVERY : PART_BOOT;
58*4882a593Smuzhiyun #endif
59*4882a593Smuzhiyun 	if (part_get_info_by_name(desc, part_name, &part) < 0)
60*4882a593Smuzhiyun 		return -1;
61*4882a593Smuzhiyun 
62*4882a593Smuzhiyun 	hdr = populate_andr_img_hdr(desc, &part);
63*4882a593Smuzhiyun 	if (!hdr)
64*4882a593Smuzhiyun 		return -1;
65*4882a593Smuzhiyun 
66*4882a593Smuzhiyun 	os_version = hdr->os_version;
67*4882a593Smuzhiyun 	if (os_version)
68*4882a593Smuzhiyun 		printf("Android %u.%u, Build %u.%u, v%d\n",
69*4882a593Smuzhiyun 		       (os_version >> 25) & 0x7f, (os_version >> 18) & 0x7F,
70*4882a593Smuzhiyun 		       ((os_version >> 4) & 0x7f) + 2000, os_version & 0x0F,
71*4882a593Smuzhiyun 		       hdr->header_version);
72*4882a593Smuzhiyun 	free(hdr);
73*4882a593Smuzhiyun 
74*4882a593Smuzhiyun 	return (os_version >> 25) & 0x7f;
75*4882a593Smuzhiyun }
76*4882a593Smuzhiyun 
android_bcb_msg_sector_offset(void)77*4882a593Smuzhiyun u32 android_bcb_msg_sector_offset(void)
78*4882a593Smuzhiyun {
79*4882a593Smuzhiyun 	static int android_version = -1;	/* static */
80*4882a593Smuzhiyun 
81*4882a593Smuzhiyun 	/*
82*4882a593Smuzhiyun 	 * get android os version:
83*4882a593Smuzhiyun 	 *
84*4882a593Smuzhiyun 	 * There are two types of misc.img:
85*4882a593Smuzhiyun 	 *	Rockchip platforms defines BCB message at the 16KB offset of
86*4882a593Smuzhiyun 	 *	misc.img except for the Android version >= 10. Because Google
87*4882a593Smuzhiyun 	 *	defines it at 0x00 offset, and from Android-10 it becoms mandary
88*4882a593Smuzhiyun 	 *	on Google VTS.
89*4882a593Smuzhiyun 	 *
90*4882a593Smuzhiyun 	 * So we must get android 'os_version' to identify which type we
91*4882a593Smuzhiyun 	 * are using, then we could able to use rockchip_get_boot_mode()
92*4882a593Smuzhiyun 	 * which reads BCB from misc.img.
93*4882a593Smuzhiyun 	 */
94*4882a593Smuzhiyun #ifdef CONFIG_RKIMG_BOOTLOADER
95*4882a593Smuzhiyun 	if (android_version < 0)
96*4882a593Smuzhiyun 		android_version = android_version_init();
97*4882a593Smuzhiyun 
98*4882a593Smuzhiyun 	return (android_version >= 10) ? 0x00 : 0x20;
99*4882a593Smuzhiyun #else
100*4882a593Smuzhiyun 	return 0x00;
101*4882a593Smuzhiyun #endif
102*4882a593Smuzhiyun }
103*4882a593Smuzhiyun 
104*4882a593Smuzhiyun #ifdef CONFIG_ROCKCHIP_RESOURCE_IMAGE
android_image_init_resource(struct blk_desc * desc,disk_partition_t * out_part,ulong * out_blk_offset)105*4882a593Smuzhiyun int android_image_init_resource(struct blk_desc *desc,
106*4882a593Smuzhiyun 				disk_partition_t *out_part,
107*4882a593Smuzhiyun 				ulong *out_blk_offset)
108*4882a593Smuzhiyun {
109*4882a593Smuzhiyun 	struct andr_img_hdr *hdr = NULL;
110*4882a593Smuzhiyun 	const char *part_name = ANDROID_PARTITION_BOOT;
111*4882a593Smuzhiyun 	disk_partition_t part;
112*4882a593Smuzhiyun 	ulong offset;
113*4882a593Smuzhiyun 	int ret = 0;
114*4882a593Smuzhiyun 
115*4882a593Smuzhiyun 	if (!desc)
116*4882a593Smuzhiyun 		return -ENODEV;
117*4882a593Smuzhiyun 
118*4882a593Smuzhiyun #ifndef CONFIG_ANDROID_AB
119*4882a593Smuzhiyun 	if (rockchip_get_boot_mode() == BOOT_MODE_RECOVERY)
120*4882a593Smuzhiyun 		part_name = ANDROID_PARTITION_RECOVERY;
121*4882a593Smuzhiyun #endif
122*4882a593Smuzhiyun 	if (part_get_info_by_name(desc, part_name, &part) < 0)
123*4882a593Smuzhiyun 		return -ENOENT;
124*4882a593Smuzhiyun 
125*4882a593Smuzhiyun 	hdr = populate_andr_img_hdr(desc, &part);
126*4882a593Smuzhiyun 	if (!hdr)
127*4882a593Smuzhiyun 		return -EINVAL;
128*4882a593Smuzhiyun 
129*4882a593Smuzhiyun 	if (hdr->header_version >= 2 && hdr->dtb_size)
130*4882a593Smuzhiyun 		env_update("bootargs", "androidboot.dtb_idx=0");
131*4882a593Smuzhiyun 
132*4882a593Smuzhiyun 	if (hdr->header_version <= 2) {
133*4882a593Smuzhiyun 		offset = hdr->page_size +
134*4882a593Smuzhiyun 			ALIGN(hdr->kernel_size, hdr->page_size) +
135*4882a593Smuzhiyun 			ALIGN(hdr->ramdisk_size, hdr->page_size);
136*4882a593Smuzhiyun 		*out_part = part;
137*4882a593Smuzhiyun 		*out_blk_offset = DIV_ROUND_UP(offset, desc->blksz);
138*4882a593Smuzhiyun 	} else {
139*4882a593Smuzhiyun 		ret = -EINVAL;
140*4882a593Smuzhiyun 	}
141*4882a593Smuzhiyun 	free(hdr);
142*4882a593Smuzhiyun 
143*4882a593Smuzhiyun 	return ret;
144*4882a593Smuzhiyun }
145*4882a593Smuzhiyun #endif
146*4882a593Smuzhiyun 
android_image_get_kernel_addr(const struct andr_img_hdr * hdr)147*4882a593Smuzhiyun static ulong android_image_get_kernel_addr(const struct andr_img_hdr *hdr)
148*4882a593Smuzhiyun {
149*4882a593Smuzhiyun 	/*
150*4882a593Smuzhiyun 	 * All the Android tools that generate a boot.img use this
151*4882a593Smuzhiyun 	 * address as the default.
152*4882a593Smuzhiyun 	 *
153*4882a593Smuzhiyun 	 * Even though it doesn't really make a lot of sense, and it
154*4882a593Smuzhiyun 	 * might be valid on some platforms, we treat that address as
155*4882a593Smuzhiyun 	 * the default value for this field, and try to execute the
156*4882a593Smuzhiyun 	 * kernel in place in such a case.
157*4882a593Smuzhiyun 	 *
158*4882a593Smuzhiyun 	 * Otherwise, we will return the actual value set by the user.
159*4882a593Smuzhiyun 	 */
160*4882a593Smuzhiyun 	if (hdr->kernel_addr == ANDROID_IMAGE_DEFAULT_KERNEL_ADDR)
161*4882a593Smuzhiyun 		return (ulong)hdr + hdr->page_size;
162*4882a593Smuzhiyun 
163*4882a593Smuzhiyun #ifdef CONFIG_ARCH_ROCKCHIP
164*4882a593Smuzhiyun 	/*
165*4882a593Smuzhiyun 	 * If kernel is compressed, kernel_addr is set as decompressed address
166*4882a593Smuzhiyun 	 * after compressed being loaded to ram, so let's use it.
167*4882a593Smuzhiyun 	 */
168*4882a593Smuzhiyun 	if (android_kernel_comp_type != IH_COMP_NONE &&
169*4882a593Smuzhiyun 	    android_kernel_comp_type != IH_COMP_ZIMAGE)
170*4882a593Smuzhiyun 		return hdr->kernel_addr;
171*4882a593Smuzhiyun 
172*4882a593Smuzhiyun 	/*
173*4882a593Smuzhiyun 	 * Compatble with rockchip legacy packing with kernel/ramdisk/second
174*4882a593Smuzhiyun 	 * address base from 0x60000000(SDK versiont < 8.1), these are invalid
175*4882a593Smuzhiyun 	 * address, so we calc it by real size.
176*4882a593Smuzhiyun 	 */
177*4882a593Smuzhiyun 	return (ulong)hdr + hdr->page_size;
178*4882a593Smuzhiyun #else
179*4882a593Smuzhiyun 	return hdr->kernel_addr;
180*4882a593Smuzhiyun #endif
181*4882a593Smuzhiyun 
182*4882a593Smuzhiyun }
183*4882a593Smuzhiyun 
android_image_set_comp(struct andr_img_hdr * hdr,u32 comp)184*4882a593Smuzhiyun void android_image_set_comp(struct andr_img_hdr *hdr, u32 comp)
185*4882a593Smuzhiyun {
186*4882a593Smuzhiyun 	android_kernel_comp_type = comp;
187*4882a593Smuzhiyun }
188*4882a593Smuzhiyun 
android_image_get_comp(const struct andr_img_hdr * hdr)189*4882a593Smuzhiyun u32 android_image_get_comp(const struct andr_img_hdr *hdr)
190*4882a593Smuzhiyun {
191*4882a593Smuzhiyun 	return android_kernel_comp_type;
192*4882a593Smuzhiyun }
193*4882a593Smuzhiyun 
android_image_parse_kernel_comp(const struct andr_img_hdr * hdr)194*4882a593Smuzhiyun int android_image_parse_kernel_comp(const struct andr_img_hdr *hdr)
195*4882a593Smuzhiyun {
196*4882a593Smuzhiyun 	ulong kaddr = android_image_get_kernel_addr(hdr);
197*4882a593Smuzhiyun 	return bootm_parse_comp((const unsigned char *)kaddr);
198*4882a593Smuzhiyun }
199*4882a593Smuzhiyun 
200*4882a593Smuzhiyun /**
201*4882a593Smuzhiyun  * android_image_get_kernel() - processes kernel part of Android boot images
202*4882a593Smuzhiyun  * @hdr:	Pointer to image header, which is at the start
203*4882a593Smuzhiyun  *			of the image.
204*4882a593Smuzhiyun  * @verify:	Checksum verification flag. Currently unimplemented.
205*4882a593Smuzhiyun  * @os_data:	Pointer to a ulong variable, will hold os data start
206*4882a593Smuzhiyun  *			address.
207*4882a593Smuzhiyun  * @os_len:	Pointer to a ulong variable, will hold os data length.
208*4882a593Smuzhiyun  *
209*4882a593Smuzhiyun  * This function returns the os image's start address and length. Also,
210*4882a593Smuzhiyun  * it appends the kernel command line to the bootargs env variable.
211*4882a593Smuzhiyun  *
212*4882a593Smuzhiyun  * Return: Zero, os start address and length on success,
213*4882a593Smuzhiyun  *		otherwise on failure.
214*4882a593Smuzhiyun  */
android_image_get_kernel(const struct andr_img_hdr * hdr,int verify,ulong * os_data,ulong * os_len)215*4882a593Smuzhiyun int android_image_get_kernel(const struct andr_img_hdr *hdr, int verify,
216*4882a593Smuzhiyun 			     ulong *os_data, ulong *os_len)
217*4882a593Smuzhiyun {
218*4882a593Smuzhiyun 	u32 kernel_addr = android_image_get_kernel_addr(hdr);
219*4882a593Smuzhiyun 	const char *cmdline = hdr->header_version < 3 ?
220*4882a593Smuzhiyun 			      hdr->cmdline : hdr->total_cmdline;
221*4882a593Smuzhiyun 	/*
222*4882a593Smuzhiyun 	 * Not all Android tools use the id field for signing the image with
223*4882a593Smuzhiyun 	 * sha1 (or anything) so we don't check it. It is not obvious that the
224*4882a593Smuzhiyun 	 * string is null terminated so we take care of this.
225*4882a593Smuzhiyun 	 */
226*4882a593Smuzhiyun 	strncpy(andr_tmp_str, hdr->name, ANDR_BOOT_NAME_SIZE);
227*4882a593Smuzhiyun 	andr_tmp_str[ANDR_BOOT_NAME_SIZE] = '\0';
228*4882a593Smuzhiyun 	if (strlen(andr_tmp_str))
229*4882a593Smuzhiyun 		printf("Android's image name: %s\n", andr_tmp_str);
230*4882a593Smuzhiyun 
231*4882a593Smuzhiyun 	printf("Kernel: 0x%08x - 0x%08x (%u KiB)\n",
232*4882a593Smuzhiyun 	       kernel_addr, kernel_addr + hdr->kernel_size,
233*4882a593Smuzhiyun 	       DIV_ROUND_UP(hdr->kernel_size, 1024));
234*4882a593Smuzhiyun 
235*4882a593Smuzhiyun 	int len = 0;
236*4882a593Smuzhiyun 	if (cmdline) {
237*4882a593Smuzhiyun 		debug("Kernel command line: %s\n", cmdline);
238*4882a593Smuzhiyun 		len += strlen(cmdline);
239*4882a593Smuzhiyun 	}
240*4882a593Smuzhiyun 
241*4882a593Smuzhiyun 	char *bootargs = env_get("bootargs");
242*4882a593Smuzhiyun 	if (bootargs)
243*4882a593Smuzhiyun 		len += strlen(bootargs);
244*4882a593Smuzhiyun 
245*4882a593Smuzhiyun 	char *newbootargs = malloc(len + 2);
246*4882a593Smuzhiyun 	if (!newbootargs) {
247*4882a593Smuzhiyun 		puts("Error: malloc in android_image_get_kernel failed!\n");
248*4882a593Smuzhiyun 		return -ENOMEM;
249*4882a593Smuzhiyun 	}
250*4882a593Smuzhiyun 	*newbootargs = '\0';
251*4882a593Smuzhiyun 
252*4882a593Smuzhiyun 	if (bootargs) {
253*4882a593Smuzhiyun 		strcpy(newbootargs, bootargs);
254*4882a593Smuzhiyun 		strcat(newbootargs, " ");
255*4882a593Smuzhiyun 	}
256*4882a593Smuzhiyun 	if (cmdline)
257*4882a593Smuzhiyun 		strcat(newbootargs, cmdline);
258*4882a593Smuzhiyun 
259*4882a593Smuzhiyun 	env_set("bootargs", newbootargs);
260*4882a593Smuzhiyun 
261*4882a593Smuzhiyun 	if (os_data) {
262*4882a593Smuzhiyun 		*os_data = (ulong)hdr;
263*4882a593Smuzhiyun 		*os_data += hdr->page_size;
264*4882a593Smuzhiyun 	}
265*4882a593Smuzhiyun 	if (os_len)
266*4882a593Smuzhiyun 		*os_len = hdr->kernel_size;
267*4882a593Smuzhiyun 	return 0;
268*4882a593Smuzhiyun }
269*4882a593Smuzhiyun 
android_image_check_header(const struct andr_img_hdr * hdr)270*4882a593Smuzhiyun int android_image_check_header(const struct andr_img_hdr *hdr)
271*4882a593Smuzhiyun {
272*4882a593Smuzhiyun 	return memcmp(ANDR_BOOT_MAGIC, hdr->magic, ANDR_BOOT_MAGIC_SIZE);
273*4882a593Smuzhiyun }
274*4882a593Smuzhiyun 
android_image_get_end(const struct andr_img_hdr * hdr)275*4882a593Smuzhiyun ulong android_image_get_end(const struct andr_img_hdr *hdr)
276*4882a593Smuzhiyun {
277*4882a593Smuzhiyun 	ulong end;
278*4882a593Smuzhiyun 	/*
279*4882a593Smuzhiyun 	 * The header takes a full page, the remaining components are aligned
280*4882a593Smuzhiyun 	 * on page boundary
281*4882a593Smuzhiyun 	 */
282*4882a593Smuzhiyun 	end = (ulong)hdr;
283*4882a593Smuzhiyun 	if (hdr->header_version < 3) {
284*4882a593Smuzhiyun 		end += hdr->page_size;
285*4882a593Smuzhiyun 		end += ALIGN(hdr->kernel_size, hdr->page_size);
286*4882a593Smuzhiyun 		end += ALIGN(hdr->ramdisk_size, hdr->page_size);
287*4882a593Smuzhiyun 		end += ALIGN(hdr->second_size, hdr->page_size);
288*4882a593Smuzhiyun 		if (hdr->header_version == 1) {
289*4882a593Smuzhiyun 			end += ALIGN(hdr->recovery_dtbo_size, hdr->page_size);
290*4882a593Smuzhiyun 		} else if (hdr->header_version == 2) {
291*4882a593Smuzhiyun 			end += ALIGN(hdr->recovery_dtbo_size, hdr->page_size);
292*4882a593Smuzhiyun 			end += ALIGN(hdr->dtb_size, hdr->page_size);
293*4882a593Smuzhiyun 		}
294*4882a593Smuzhiyun 	} else {
295*4882a593Smuzhiyun 		/* boot_img_hdr_v34 */
296*4882a593Smuzhiyun 		end += hdr->page_size;
297*4882a593Smuzhiyun 		end += ALIGN(hdr->kernel_size, hdr->page_size);
298*4882a593Smuzhiyun 		end += ALIGN(hdr->ramdisk_size, hdr->page_size);
299*4882a593Smuzhiyun 	}
300*4882a593Smuzhiyun 
301*4882a593Smuzhiyun 	return end;
302*4882a593Smuzhiyun }
303*4882a593Smuzhiyun 
android_image_get_ksize(const struct andr_img_hdr * hdr)304*4882a593Smuzhiyun u32 android_image_get_ksize(const struct andr_img_hdr *hdr)
305*4882a593Smuzhiyun {
306*4882a593Smuzhiyun 	return hdr->kernel_size;
307*4882a593Smuzhiyun }
308*4882a593Smuzhiyun 
android_image_set_kload(struct andr_img_hdr * hdr,u32 load_address)309*4882a593Smuzhiyun void android_image_set_kload(struct andr_img_hdr *hdr, u32 load_address)
310*4882a593Smuzhiyun {
311*4882a593Smuzhiyun 	hdr->kernel_addr = load_address;
312*4882a593Smuzhiyun }
313*4882a593Smuzhiyun 
android_image_get_kload(const struct andr_img_hdr * hdr)314*4882a593Smuzhiyun ulong android_image_get_kload(const struct andr_img_hdr *hdr)
315*4882a593Smuzhiyun {
316*4882a593Smuzhiyun 	return android_image_get_kernel_addr(hdr);
317*4882a593Smuzhiyun }
318*4882a593Smuzhiyun 
android_image_get_ramdisk(const struct andr_img_hdr * hdr,ulong * rd_data,ulong * rd_len)319*4882a593Smuzhiyun int android_image_get_ramdisk(const struct andr_img_hdr *hdr,
320*4882a593Smuzhiyun 			      ulong *rd_data, ulong *rd_len)
321*4882a593Smuzhiyun {
322*4882a593Smuzhiyun 	ulong ramdisk_addr_r;
323*4882a593Smuzhiyun 	ulong start, end;
324*4882a593Smuzhiyun 
325*4882a593Smuzhiyun 	if (!hdr->ramdisk_size) {
326*4882a593Smuzhiyun 		*rd_data = *rd_len = 0;
327*4882a593Smuzhiyun 		return -1;
328*4882a593Smuzhiyun 	}
329*4882a593Smuzhiyun 
330*4882a593Smuzhiyun 	/* Have been loaded by android_image_load_separate() on ramdisk_addr_r */
331*4882a593Smuzhiyun 	ramdisk_addr_r = env_get_ulong("ramdisk_addr_r", 16, 0);
332*4882a593Smuzhiyun 	if (!ramdisk_addr_r) {
333*4882a593Smuzhiyun 		printf("No Found Ramdisk Load Address.\n");
334*4882a593Smuzhiyun 		return -1;
335*4882a593Smuzhiyun 	}
336*4882a593Smuzhiyun 
337*4882a593Smuzhiyun 	*rd_data = ramdisk_addr_r;
338*4882a593Smuzhiyun 	*rd_len = hdr->ramdisk_size;
339*4882a593Smuzhiyun 	if (hdr->header_version >= 3)
340*4882a593Smuzhiyun 		*rd_len += hdr->vendor_ramdisk_size;
341*4882a593Smuzhiyun 	if (hdr->header_version >= 4) {
342*4882a593Smuzhiyun 		 *rd_len += hdr->vendor_bootconfig_size +
343*4882a593Smuzhiyun 		  ANDROID_ADDITION_BOOTCONFIG_PARAMS_MAX_SIZE;
344*4882a593Smuzhiyun 	}
345*4882a593Smuzhiyun 
346*4882a593Smuzhiyun 	/* just for print msg */
347*4882a593Smuzhiyun 	start = ramdisk_addr_r;
348*4882a593Smuzhiyun 	if (hdr->header_version >= 3) {
349*4882a593Smuzhiyun 		end = start + (ulong)hdr->vendor_ramdisk_size;
350*4882a593Smuzhiyun 		printf("v-ramdisk:  0x%08lx - 0x%08lx (%u KiB)\n",
351*4882a593Smuzhiyun 		       start, end, DIV_ROUND_UP(hdr->vendor_ramdisk_size, 1024));
352*4882a593Smuzhiyun 		start = end;
353*4882a593Smuzhiyun 	}
354*4882a593Smuzhiyun 	{
355*4882a593Smuzhiyun 		end = start + (ulong)hdr->ramdisk_size;
356*4882a593Smuzhiyun 		printf("ramdisk:    0x%08lx - 0x%08lx (%u KiB)\n",
357*4882a593Smuzhiyun 		       start, end, DIV_ROUND_UP(hdr->ramdisk_size, 1024));
358*4882a593Smuzhiyun 		start = end;
359*4882a593Smuzhiyun 	}
360*4882a593Smuzhiyun 	if (hdr->header_version >= 4) {
361*4882a593Smuzhiyun 		end = start + (ulong)hdr->vendor_bootconfig_size;
362*4882a593Smuzhiyun 		printf("bootconfig: 0x%08lx - 0x%08lx (%u KiB)\n",
363*4882a593Smuzhiyun 		       start, end, DIV_ROUND_UP(hdr->vendor_bootconfig_size, 1024));
364*4882a593Smuzhiyun 		start = end;
365*4882a593Smuzhiyun 		end = start + ANDROID_ADDITION_BOOTCONFIG_PARAMS_MAX_SIZE;
366*4882a593Smuzhiyun 		printf("bootparams: 0x%08lx - 0x%08lx\n", start, end);
367*4882a593Smuzhiyun 	}
368*4882a593Smuzhiyun 
369*4882a593Smuzhiyun 	return 0;
370*4882a593Smuzhiyun }
371*4882a593Smuzhiyun 
android_image_get_fdt(const struct andr_img_hdr * hdr,ulong * rd_data)372*4882a593Smuzhiyun int android_image_get_fdt(const struct andr_img_hdr *hdr,
373*4882a593Smuzhiyun 			      ulong *rd_data)
374*4882a593Smuzhiyun {
375*4882a593Smuzhiyun 	ulong fdt_addr_r;
376*4882a593Smuzhiyun 
377*4882a593Smuzhiyun 	if (!hdr->second_size) {
378*4882a593Smuzhiyun 		*rd_data = 0;
379*4882a593Smuzhiyun 		return -1;
380*4882a593Smuzhiyun 	}
381*4882a593Smuzhiyun 
382*4882a593Smuzhiyun 	/* Have been loaded by android_image_load_separate() on fdt_addr_r */
383*4882a593Smuzhiyun 	fdt_addr_r = env_get_ulong("fdt_addr_r", 16, 0);
384*4882a593Smuzhiyun 	if (!fdt_addr_r) {
385*4882a593Smuzhiyun 		printf("No Found FDT Load Address.\n");
386*4882a593Smuzhiyun 		return -1;
387*4882a593Smuzhiyun 	}
388*4882a593Smuzhiyun 
389*4882a593Smuzhiyun 	*rd_data = fdt_addr_r;
390*4882a593Smuzhiyun 
391*4882a593Smuzhiyun 	debug("FDT load addr 0x%08x size %u KiB\n",
392*4882a593Smuzhiyun 	      hdr->second_addr, DIV_ROUND_UP(hdr->second_size, 1024));
393*4882a593Smuzhiyun 
394*4882a593Smuzhiyun 	return 0;
395*4882a593Smuzhiyun }
396*4882a593Smuzhiyun 
397*4882a593Smuzhiyun #ifdef CONFIG_ANDROID_BOOT_IMAGE_HASH
print_hash(const char * label,u8 * hash,int len)398*4882a593Smuzhiyun static void print_hash(const char *label, u8 *hash, int len)
399*4882a593Smuzhiyun {
400*4882a593Smuzhiyun 	int i;
401*4882a593Smuzhiyun 
402*4882a593Smuzhiyun 	printf("%s:\n    0x", label ? : "Hash");
403*4882a593Smuzhiyun 	for (i = 0; i < len; i++)
404*4882a593Smuzhiyun 		printf("%02x", hash[i]);
405*4882a593Smuzhiyun 	printf("\n");
406*4882a593Smuzhiyun }
407*4882a593Smuzhiyun #endif
408*4882a593Smuzhiyun 
409*4882a593Smuzhiyun typedef enum {
410*4882a593Smuzhiyun 	IMG_KERNEL,
411*4882a593Smuzhiyun 	IMG_RAMDISK,	/* within boot.img or init_boot.img(Android-13 or later) */
412*4882a593Smuzhiyun 	IMG_SECOND,
413*4882a593Smuzhiyun 	IMG_RECOVERY_DTBO,
414*4882a593Smuzhiyun 	IMG_RK_DTB,	/* within resource.img in second position */
415*4882a593Smuzhiyun 	IMG_DTB,
416*4882a593Smuzhiyun 	IMG_VENDOR_RAMDISK,
417*4882a593Smuzhiyun 	IMG_BOOTCONFIG,
418*4882a593Smuzhiyun 	IMG_MAX,
419*4882a593Smuzhiyun } img_t;
420*4882a593Smuzhiyun 
421*4882a593Smuzhiyun #if defined(CONFIG_ANDROID_BOOT_IMAGE_HASH) && !defined(CONFIG_DM_CRYPTO)
422*4882a593Smuzhiyun static sha1_context sha1_ctx;
423*4882a593Smuzhiyun #endif
424*4882a593Smuzhiyun 
image_load(img_t img,struct andr_img_hdr * hdr,ulong blkstart,void * ram_base,struct udevice * crypto)425*4882a593Smuzhiyun static int image_load(img_t img, struct andr_img_hdr *hdr,
426*4882a593Smuzhiyun 		      ulong blkstart, void *ram_base,
427*4882a593Smuzhiyun 		      struct udevice *crypto)
428*4882a593Smuzhiyun {
429*4882a593Smuzhiyun 	struct blk_desc *desc = rockchip_get_bootdev();
430*4882a593Smuzhiyun 	disk_partition_t part_vendor_boot;
431*4882a593Smuzhiyun 	disk_partition_t part_init_boot;
432*4882a593Smuzhiyun 	__maybe_unused u32 typesz;
433*4882a593Smuzhiyun 	u32 andr_version = (hdr->os_version >> 25) & 0x7f;
434*4882a593Smuzhiyun 	ulong pgsz = hdr->page_size;
435*4882a593Smuzhiyun 	ulong blksz = desc->blksz;
436*4882a593Smuzhiyun 	ulong blkcnt, blkoff;
437*4882a593Smuzhiyun 	ulong memmove_dst = 0;
438*4882a593Smuzhiyun 	ulong bsoffs = 0;
439*4882a593Smuzhiyun 	ulong extra = 0;
440*4882a593Smuzhiyun 	ulong length;
441*4882a593Smuzhiyun 	void *buffer;
442*4882a593Smuzhiyun 	void *tmp = NULL;
443*4882a593Smuzhiyun 	int ret = 0;
444*4882a593Smuzhiyun 
445*4882a593Smuzhiyun 	switch (img) {
446*4882a593Smuzhiyun 	case IMG_KERNEL:
447*4882a593Smuzhiyun 		bsoffs = 0; /* include a page_size(image header) */
448*4882a593Smuzhiyun 		length = hdr->kernel_size + pgsz;
449*4882a593Smuzhiyun 		buffer = (void *)env_get_ulong("android_addr_r", 16, 0);
450*4882a593Smuzhiyun 		blkcnt = DIV_ROUND_UP(hdr->kernel_size + pgsz, blksz);
451*4882a593Smuzhiyun 		typesz = sizeof(hdr->kernel_size);
452*4882a593Smuzhiyun 		if (!sysmem_alloc_base(MEM_KERNEL,
453*4882a593Smuzhiyun 			(phys_addr_t)buffer, blkcnt * blksz))
454*4882a593Smuzhiyun 			return -ENOMEM;
455*4882a593Smuzhiyun 		break;
456*4882a593Smuzhiyun 	case IMG_VENDOR_RAMDISK:
457*4882a593Smuzhiyun 		if (hdr->vendor_boot_buf) {
458*4882a593Smuzhiyun 			ram_base = hdr->vendor_boot_buf;
459*4882a593Smuzhiyun 		} else {
460*4882a593Smuzhiyun 			if (part_get_info_by_name(desc,
461*4882a593Smuzhiyun 						  ANDROID_PARTITION_VENDOR_BOOT,
462*4882a593Smuzhiyun 						  &part_vendor_boot) < 0) {
463*4882a593Smuzhiyun 				printf("No vendor boot partition\n");
464*4882a593Smuzhiyun 				return -ENOENT;
465*4882a593Smuzhiyun 			}
466*4882a593Smuzhiyun 			ram_base = 0;
467*4882a593Smuzhiyun 		}
468*4882a593Smuzhiyun 
469*4882a593Smuzhiyun 		blkstart = part_vendor_boot.start;
470*4882a593Smuzhiyun 		pgsz = hdr->vendor_page_size;
471*4882a593Smuzhiyun 		bsoffs = ALIGN(VENDOR_BOOT_HDRv3_SIZE, pgsz);
472*4882a593Smuzhiyun 		length = hdr->vendor_ramdisk_size;
473*4882a593Smuzhiyun 		buffer = (void *)env_get_ulong("ramdisk_addr_r", 16, 0);
474*4882a593Smuzhiyun 		blkcnt = DIV_ROUND_UP(hdr->vendor_ramdisk_size, blksz);
475*4882a593Smuzhiyun 		typesz = sizeof(hdr->vendor_ramdisk_size);
476*4882a593Smuzhiyun 		/*
477*4882a593Smuzhiyun 		 * Add extra memory for generic ramdisk space.
478*4882a593Smuzhiyun 		 *
479*4882a593Smuzhiyun 		 * In case of unaligned vendor ramdisk size, reserve
480*4882a593Smuzhiyun 		 * 1 more blksz.
481*4882a593Smuzhiyun 		 *
482*4882a593Smuzhiyun 		 * Reserve 8KB for bootloader cmdline.
483*4882a593Smuzhiyun 		 */
484*4882a593Smuzhiyun 		if (hdr->header_version >= 3)
485*4882a593Smuzhiyun 			extra += ALIGN(hdr->ramdisk_size, blksz) + blksz;
486*4882a593Smuzhiyun 		if (hdr->header_version >= 4)
487*4882a593Smuzhiyun 			extra += ALIGN(hdr->vendor_bootconfig_size, blksz) +
488*4882a593Smuzhiyun 				 ANDROID_ADDITION_BOOTCONFIG_PARAMS_MAX_SIZE;
489*4882a593Smuzhiyun 		if (length && !sysmem_alloc_base(MEM_RAMDISK,
490*4882a593Smuzhiyun 			(phys_addr_t)buffer, blkcnt * blksz + extra))
491*4882a593Smuzhiyun 			return -ENOMEM;
492*4882a593Smuzhiyun 		break;
493*4882a593Smuzhiyun 	case IMG_RAMDISK:
494*4882a593Smuzhiyun 		/* get ramdisk from init_boot.img ? */
495*4882a593Smuzhiyun 		if (hdr->header_version >= 4 && andr_version >= 13) {
496*4882a593Smuzhiyun 			if (hdr->init_boot_buf) {
497*4882a593Smuzhiyun 				ram_base = hdr->init_boot_buf;
498*4882a593Smuzhiyun 			} else {
499*4882a593Smuzhiyun 				if (part_get_info_by_name(desc,
500*4882a593Smuzhiyun 				    ANDROID_PARTITION_INIT_BOOT, &part_init_boot) < 0) {
501*4882a593Smuzhiyun 					printf("No init boot partition\n");
502*4882a593Smuzhiyun 					return -ENOENT;
503*4882a593Smuzhiyun 				}
504*4882a593Smuzhiyun 				blkstart = part_init_boot.start;
505*4882a593Smuzhiyun 				ram_base = 0;
506*4882a593Smuzhiyun 			}
507*4882a593Smuzhiyun 			bsoffs = pgsz;
508*4882a593Smuzhiyun 		} else {
509*4882a593Smuzhiyun 			/* get ramdisk from generic boot.img */
510*4882a593Smuzhiyun 			bsoffs = pgsz + ALIGN(hdr->kernel_size, pgsz);
511*4882a593Smuzhiyun 		}
512*4882a593Smuzhiyun 
513*4882a593Smuzhiyun 		length = hdr->ramdisk_size;
514*4882a593Smuzhiyun 		buffer = (void *)env_get_ulong("ramdisk_addr_r", 16, 0);
515*4882a593Smuzhiyun 		blkcnt = DIV_ROUND_UP(hdr->ramdisk_size, blksz);
516*4882a593Smuzhiyun 		typesz = sizeof(hdr->ramdisk_size);
517*4882a593Smuzhiyun 
518*4882a593Smuzhiyun 		/*
519*4882a593Smuzhiyun 		 * ramdisk_addr_r v012:
520*4882a593Smuzhiyun 		 *	|----------------|
521*4882a593Smuzhiyun 		 *	|    ramdisk     |
522*4882a593Smuzhiyun 		 *	|----------------|
523*4882a593Smuzhiyun 		 *
524*4882a593Smuzhiyun 		 * ramdisk_addr_r v3 (Android-11 and later):
525*4882a593Smuzhiyun 		 *	|----------------|---------|
526*4882a593Smuzhiyun 		 *	| vendor-ramdisk | ramdisk |
527*4882a593Smuzhiyun 		 *	|----------------|---------|
528*4882a593Smuzhiyun 		 *
529*4882a593Smuzhiyun 		 * ramdisk_addr_r v4 (Android-12 and later):
530*4882a593Smuzhiyun 		 *	|----------------|---------|------------|------------|
531*4882a593Smuzhiyun 		 *	| vendor-ramdisk | ramdisk | bootconfig | bootparams |
532*4882a593Smuzhiyun 		 *	|----------------|---------|------------|------------|
533*4882a593Smuzhiyun 		 *
534*4882a593Smuzhiyun 		 * ramdisk_addr_r v4 + init_boot(Android-13 and later):
535*4882a593Smuzhiyun 		 *	|----------------|----------------|------------|------------|
536*4882a593Smuzhiyun 		 *	| vendor-ramdisk | (init_)ramdisk | bootconfig | bootparams |
537*4882a593Smuzhiyun 		 *	|----------------|----------------|------------|------------|
538*4882a593Smuzhiyun 		 */
539*4882a593Smuzhiyun 		if (hdr->header_version >= 3) {
540*4882a593Smuzhiyun 			buffer += hdr->vendor_ramdisk_size;
541*4882a593Smuzhiyun 			if (!IS_ALIGNED((ulong)buffer, blksz)) {
542*4882a593Smuzhiyun 				memmove_dst = (ulong)buffer;
543*4882a593Smuzhiyun 				buffer = (void *)ALIGN(memmove_dst, blksz);
544*4882a593Smuzhiyun 			}
545*4882a593Smuzhiyun 		}
546*4882a593Smuzhiyun 		/* sysmem has been alloced by vendor ramdisk */
547*4882a593Smuzhiyun 		if (hdr->header_version < 3) {
548*4882a593Smuzhiyun 			if (length && !sysmem_alloc_base(MEM_RAMDISK,
549*4882a593Smuzhiyun 				(phys_addr_t)buffer, blkcnt * blksz))
550*4882a593Smuzhiyun 				return -ENOMEM;
551*4882a593Smuzhiyun 		}
552*4882a593Smuzhiyun 		break;
553*4882a593Smuzhiyun 	case IMG_BOOTCONFIG:
554*4882a593Smuzhiyun 		if (hdr->header_version < 4)
555*4882a593Smuzhiyun 			return 0;
556*4882a593Smuzhiyun 
557*4882a593Smuzhiyun 		if (hdr->vendor_boot_buf) {
558*4882a593Smuzhiyun 			ram_base = hdr->vendor_boot_buf;
559*4882a593Smuzhiyun 		} else {
560*4882a593Smuzhiyun 			if (part_get_info_by_name(desc,
561*4882a593Smuzhiyun 						  ANDROID_PARTITION_VENDOR_BOOT,
562*4882a593Smuzhiyun 						  &part_vendor_boot) < 0) {
563*4882a593Smuzhiyun 				printf("No vendor boot partition\n");
564*4882a593Smuzhiyun 				return -ENOENT;
565*4882a593Smuzhiyun 			}
566*4882a593Smuzhiyun 			ram_base = 0;
567*4882a593Smuzhiyun 		}
568*4882a593Smuzhiyun 		blkstart = part_vendor_boot.start;
569*4882a593Smuzhiyun 		pgsz = hdr->vendor_page_size;
570*4882a593Smuzhiyun 		bsoffs = ALIGN(VENDOR_BOOT_HDRv4_SIZE, pgsz) +
571*4882a593Smuzhiyun 			 ALIGN(hdr->vendor_ramdisk_size, pgsz) +
572*4882a593Smuzhiyun 			 ALIGN(hdr->dtb_size, pgsz) +
573*4882a593Smuzhiyun 			 ALIGN(hdr->vendor_ramdisk_table_size, pgsz);
574*4882a593Smuzhiyun 		length = hdr->vendor_bootconfig_size;
575*4882a593Smuzhiyun 		buffer = (void *)env_get_ulong("ramdisk_addr_r", 16, 0);
576*4882a593Smuzhiyun 		blkcnt = DIV_ROUND_UP(hdr->vendor_bootconfig_size, blksz);
577*4882a593Smuzhiyun 		typesz = sizeof(hdr->vendor_bootconfig_size);
578*4882a593Smuzhiyun 
579*4882a593Smuzhiyun 		buffer += hdr->vendor_ramdisk_size + hdr->ramdisk_size;
580*4882a593Smuzhiyun 		if (!IS_ALIGNED((ulong)buffer, blksz)) {
581*4882a593Smuzhiyun 			memmove_dst = (ulong)buffer;
582*4882a593Smuzhiyun 			buffer = (void *)ALIGN(memmove_dst, blksz);
583*4882a593Smuzhiyun 		}
584*4882a593Smuzhiyun 		break;
585*4882a593Smuzhiyun 	case IMG_SECOND:
586*4882a593Smuzhiyun 		bsoffs = pgsz +
587*4882a593Smuzhiyun 			 ALIGN(hdr->kernel_size, pgsz) +
588*4882a593Smuzhiyun 			 ALIGN(hdr->ramdisk_size, pgsz);
589*4882a593Smuzhiyun 		length = hdr->second_size;
590*4882a593Smuzhiyun 		blkcnt = DIV_ROUND_UP(hdr->second_size, blksz);
591*4882a593Smuzhiyun 		buffer = tmp = malloc(blkcnt * blksz);
592*4882a593Smuzhiyun 		typesz = sizeof(hdr->second_size);
593*4882a593Smuzhiyun 		break;
594*4882a593Smuzhiyun 	case IMG_RECOVERY_DTBO:
595*4882a593Smuzhiyun 		bsoffs = pgsz +
596*4882a593Smuzhiyun 			 ALIGN(hdr->kernel_size, pgsz) +
597*4882a593Smuzhiyun 			 ALIGN(hdr->ramdisk_size, pgsz) +
598*4882a593Smuzhiyun 			 ALIGN(hdr->second_size, pgsz);
599*4882a593Smuzhiyun 		length = hdr->recovery_dtbo_size;
600*4882a593Smuzhiyun 		blkcnt = DIV_ROUND_UP(hdr->recovery_dtbo_size, blksz);
601*4882a593Smuzhiyun 		buffer = tmp = malloc(blkcnt * blksz);
602*4882a593Smuzhiyun 		typesz = sizeof(hdr->recovery_dtbo_size);
603*4882a593Smuzhiyun 		break;
604*4882a593Smuzhiyun 	case IMG_DTB:
605*4882a593Smuzhiyun 		bsoffs = pgsz +
606*4882a593Smuzhiyun 			 ALIGN(hdr->kernel_size, pgsz) +
607*4882a593Smuzhiyun 			 ALIGN(hdr->ramdisk_size, pgsz) +
608*4882a593Smuzhiyun 			 ALIGN(hdr->second_size, pgsz) +
609*4882a593Smuzhiyun 			 ALIGN(hdr->recovery_dtbo_size, pgsz);
610*4882a593Smuzhiyun 		length = hdr->dtb_size;
611*4882a593Smuzhiyun 		blkcnt = DIV_ROUND_UP(hdr->dtb_size, blksz);
612*4882a593Smuzhiyun 		buffer = tmp = malloc(blkcnt * blksz);
613*4882a593Smuzhiyun 		typesz = sizeof(hdr->dtb_size);
614*4882a593Smuzhiyun 		break;
615*4882a593Smuzhiyun 	case IMG_RK_DTB:
616*4882a593Smuzhiyun #ifdef CONFIG_RKIMG_BOOTLOADER
617*4882a593Smuzhiyun 		/* No going further, it handles DTBO, HW-ID, etc */
618*4882a593Smuzhiyun 		buffer = (void *)env_get_ulong("fdt_addr_r", 16, 0);
619*4882a593Smuzhiyun 		if (gd->fdt_blob != (void *)buffer)
620*4882a593Smuzhiyun 			ret = rockchip_read_dtb_file(buffer);
621*4882a593Smuzhiyun #endif
622*4882a593Smuzhiyun 		return ret < 0 ? ret : 0;
623*4882a593Smuzhiyun 	default:
624*4882a593Smuzhiyun 		return -EINVAL;
625*4882a593Smuzhiyun 	}
626*4882a593Smuzhiyun 
627*4882a593Smuzhiyun 	if (!buffer) {
628*4882a593Smuzhiyun 		printf("No memory for image(%d)\n", img);
629*4882a593Smuzhiyun 		return -ENOMEM;
630*4882a593Smuzhiyun 	}
631*4882a593Smuzhiyun 
632*4882a593Smuzhiyun 	if (!blksz || !length)
633*4882a593Smuzhiyun 		goto crypto_calc;
634*4882a593Smuzhiyun 
635*4882a593Smuzhiyun 	/* load */
636*4882a593Smuzhiyun 	if (ram_base) {
637*4882a593Smuzhiyun 		memcpy(buffer, (char *)((ulong)ram_base + bsoffs), length);
638*4882a593Smuzhiyun 	} else {
639*4882a593Smuzhiyun 		blkoff = DIV_ROUND_UP(bsoffs, blksz);
640*4882a593Smuzhiyun 		ret = blk_dread(desc, blkstart + blkoff, blkcnt, buffer);
641*4882a593Smuzhiyun 		if (ret != blkcnt) {
642*4882a593Smuzhiyun 			printf("Failed to read img(%d), ret=%d\n", img, ret);
643*4882a593Smuzhiyun 			return -EIO;
644*4882a593Smuzhiyun 		}
645*4882a593Smuzhiyun 	}
646*4882a593Smuzhiyun 
647*4882a593Smuzhiyun 	if (memmove_dst)
648*4882a593Smuzhiyun 		memmove((char *)memmove_dst, buffer, length);
649*4882a593Smuzhiyun 
650*4882a593Smuzhiyun crypto_calc:
651*4882a593Smuzhiyun 	if (img == IMG_KERNEL) {
652*4882a593Smuzhiyun 		buffer += pgsz;
653*4882a593Smuzhiyun 		length -= pgsz;
654*4882a593Smuzhiyun 	}
655*4882a593Smuzhiyun 
656*4882a593Smuzhiyun 	/* sha1 */
657*4882a593Smuzhiyun 	if (hdr->header_version < 3) {
658*4882a593Smuzhiyun #ifdef CONFIG_ANDROID_BOOT_IMAGE_HASH
659*4882a593Smuzhiyun #ifdef CONFIG_DM_CRYPTO
660*4882a593Smuzhiyun 		if (crypto) {
661*4882a593Smuzhiyun 			crypto_sha_update(crypto, (u32 *)buffer, length);
662*4882a593Smuzhiyun 			crypto_sha_update(crypto, (u32 *)&length, typesz);
663*4882a593Smuzhiyun 		}
664*4882a593Smuzhiyun #else
665*4882a593Smuzhiyun 		sha1_update(&sha1_ctx, (void *)buffer, length);
666*4882a593Smuzhiyun 		sha1_update(&sha1_ctx, (void *)&length, typesz);
667*4882a593Smuzhiyun #endif
668*4882a593Smuzhiyun #endif
669*4882a593Smuzhiyun 	}
670*4882a593Smuzhiyun 
671*4882a593Smuzhiyun 	if (tmp)
672*4882a593Smuzhiyun 		free(tmp);
673*4882a593Smuzhiyun 
674*4882a593Smuzhiyun 	return 0;
675*4882a593Smuzhiyun }
676*4882a593Smuzhiyun 
images_load_verify(struct andr_img_hdr * hdr,ulong part_start,void * ram_base,struct udevice * crypto)677*4882a593Smuzhiyun static int images_load_verify(struct andr_img_hdr *hdr, ulong part_start,
678*4882a593Smuzhiyun 			      void *ram_base, struct udevice *crypto)
679*4882a593Smuzhiyun {
680*4882a593Smuzhiyun 	/* load, never change order ! */
681*4882a593Smuzhiyun 	if (image_load(IMG_KERNEL, hdr, part_start, ram_base, crypto))
682*4882a593Smuzhiyun 		return -1;
683*4882a593Smuzhiyun 	if (image_load(IMG_RAMDISK, hdr, part_start, ram_base, crypto))
684*4882a593Smuzhiyun 		return -1;
685*4882a593Smuzhiyun 	if (image_load(IMG_SECOND, hdr, part_start, ram_base, crypto))
686*4882a593Smuzhiyun 		return -1;
687*4882a593Smuzhiyun 	if (hdr->header_version > 0) {
688*4882a593Smuzhiyun 		if (image_load(IMG_RECOVERY_DTBO, hdr, part_start,
689*4882a593Smuzhiyun 			       ram_base, crypto))
690*4882a593Smuzhiyun 			return -1;
691*4882a593Smuzhiyun 	}
692*4882a593Smuzhiyun 	if (hdr->header_version > 1) {
693*4882a593Smuzhiyun 		if (image_load(IMG_DTB, hdr, part_start, ram_base, crypto))
694*4882a593Smuzhiyun 			return -1;
695*4882a593Smuzhiyun 	}
696*4882a593Smuzhiyun 
697*4882a593Smuzhiyun 	return 0;
698*4882a593Smuzhiyun }
699*4882a593Smuzhiyun 
700*4882a593Smuzhiyun /*
701*4882a593Smuzhiyun  * @ram_base: !NULL means require memcpy for an exist full android image.
702*4882a593Smuzhiyun  */
android_image_separate(struct andr_img_hdr * hdr,const disk_partition_t * part,void * load_address,void * ram_base)703*4882a593Smuzhiyun static int android_image_separate(struct andr_img_hdr *hdr,
704*4882a593Smuzhiyun 				  const disk_partition_t *part,
705*4882a593Smuzhiyun 				  void *load_address,
706*4882a593Smuzhiyun 				  void *ram_base)
707*4882a593Smuzhiyun {
708*4882a593Smuzhiyun 	ulong bstart;
709*4882a593Smuzhiyun 	int ret;
710*4882a593Smuzhiyun 
711*4882a593Smuzhiyun 	if (android_image_check_header(hdr)) {
712*4882a593Smuzhiyun 		printf("Bad android image header\n");
713*4882a593Smuzhiyun 		return -EINVAL;
714*4882a593Smuzhiyun 	}
715*4882a593Smuzhiyun 
716*4882a593Smuzhiyun 	/* set for image_load(IMG_KERNEL, ...) */
717*4882a593Smuzhiyun 	env_set_hex("android_addr_r", (ulong)load_address);
718*4882a593Smuzhiyun 	bstart = part ? part->start : 0;
719*4882a593Smuzhiyun 
720*4882a593Smuzhiyun 	/*
721*4882a593Smuzhiyun 	 * 1. Load images to their individual target ram position
722*4882a593Smuzhiyun 	 *    in order to disable fdt/ramdisk relocation.
723*4882a593Smuzhiyun 	 */
724*4882a593Smuzhiyun 
725*4882a593Smuzhiyun 	/* load rk-kernel.dtb alone */
726*4882a593Smuzhiyun 	if (image_load(IMG_RK_DTB, hdr, bstart, ram_base, NULL))
727*4882a593Smuzhiyun 		return -1;
728*4882a593Smuzhiyun 
729*4882a593Smuzhiyun #ifdef CONFIG_ANDROID_BOOT_IMAGE_HASH
730*4882a593Smuzhiyun 	int verify = 1;
731*4882a593Smuzhiyun 
732*4882a593Smuzhiyun #ifdef CONFIG_MP_BOOT
733*4882a593Smuzhiyun 	verify = mpb_post(3);
734*4882a593Smuzhiyun #endif
735*4882a593Smuzhiyun 	if (hdr->header_version < 3 && verify) {
736*4882a593Smuzhiyun 		struct udevice *dev = NULL;
737*4882a593Smuzhiyun 		uchar hash[20];
738*4882a593Smuzhiyun #ifdef CONFIG_DM_CRYPTO
739*4882a593Smuzhiyun 		sha_context ctx;
740*4882a593Smuzhiyun 
741*4882a593Smuzhiyun 		ctx.length = 0;
742*4882a593Smuzhiyun 		ctx.algo = CRYPTO_SHA1;
743*4882a593Smuzhiyun 		dev = crypto_get_device(ctx.algo);
744*4882a593Smuzhiyun 		if (!dev) {
745*4882a593Smuzhiyun 			printf("Can't find crypto device for SHA1\n");
746*4882a593Smuzhiyun 			return -ENODEV;
747*4882a593Smuzhiyun 		}
748*4882a593Smuzhiyun 
749*4882a593Smuzhiyun 		/* v1 & v2: requires total length before sha init */
750*4882a593Smuzhiyun 		ctx.length += hdr->kernel_size + sizeof(hdr->kernel_size) +
751*4882a593Smuzhiyun 			      hdr->ramdisk_size + sizeof(hdr->ramdisk_size) +
752*4882a593Smuzhiyun 			      hdr->second_size + sizeof(hdr->second_size);
753*4882a593Smuzhiyun 		if (hdr->header_version > 0)
754*4882a593Smuzhiyun 			ctx.length += hdr->recovery_dtbo_size +
755*4882a593Smuzhiyun 						sizeof(hdr->recovery_dtbo_size);
756*4882a593Smuzhiyun 		if (hdr->header_version > 1)
757*4882a593Smuzhiyun 			ctx.length += hdr->dtb_size + sizeof(hdr->dtb_size);
758*4882a593Smuzhiyun 		crypto_sha_init(dev, &ctx);
759*4882a593Smuzhiyun #else
760*4882a593Smuzhiyun 		sha1_starts(&sha1_ctx);
761*4882a593Smuzhiyun #endif
762*4882a593Smuzhiyun 		ret = images_load_verify(hdr, bstart, ram_base, dev);
763*4882a593Smuzhiyun 		if (ret)
764*4882a593Smuzhiyun 			return ret;
765*4882a593Smuzhiyun 
766*4882a593Smuzhiyun #ifdef CONFIG_DM_CRYPTO
767*4882a593Smuzhiyun 		crypto_sha_final(dev, &ctx, hash);
768*4882a593Smuzhiyun #else
769*4882a593Smuzhiyun 		sha1_finish(&sha1_ctx, hash);
770*4882a593Smuzhiyun #endif
771*4882a593Smuzhiyun 		if (memcmp(hash, hdr->id, 20)) {
772*4882a593Smuzhiyun 			print_hash("Hash from header", (u8 *)hdr->id, 20);
773*4882a593Smuzhiyun 			print_hash("Hash real", (u8 *)hash, 20);
774*4882a593Smuzhiyun 			return -EBADFD;
775*4882a593Smuzhiyun 		} else {
776*4882a593Smuzhiyun 			printf("ANDROID: Hash OK\n");
777*4882a593Smuzhiyun 		}
778*4882a593Smuzhiyun 	} else
779*4882a593Smuzhiyun #endif
780*4882a593Smuzhiyun 	{
781*4882a593Smuzhiyun 		ret = images_load_verify(hdr, bstart, ram_base, NULL);
782*4882a593Smuzhiyun 		if (ret)
783*4882a593Smuzhiyun 			return ret;
784*4882a593Smuzhiyun 	}
785*4882a593Smuzhiyun 
786*4882a593Smuzhiyun 	/* 2. Disable fdt/ramdisk relocation, it saves boot time */
787*4882a593Smuzhiyun 	env_set("bootm-no-reloc", "y");
788*4882a593Smuzhiyun 
789*4882a593Smuzhiyun 	return 0;
790*4882a593Smuzhiyun }
791*4882a593Smuzhiyun 
android_image_separate_v34(struct andr_img_hdr * hdr,const disk_partition_t * part,void * load_address,void * ram_base)792*4882a593Smuzhiyun static int android_image_separate_v34(struct andr_img_hdr *hdr,
793*4882a593Smuzhiyun 				      const disk_partition_t *part,
794*4882a593Smuzhiyun 				      void *load_address, void *ram_base)
795*4882a593Smuzhiyun {
796*4882a593Smuzhiyun 	ulong bstart;
797*4882a593Smuzhiyun 
798*4882a593Smuzhiyun 	if (android_image_check_header(hdr)) {
799*4882a593Smuzhiyun 		printf("Bad android image header\n");
800*4882a593Smuzhiyun 		return -EINVAL;
801*4882a593Smuzhiyun 	}
802*4882a593Smuzhiyun 
803*4882a593Smuzhiyun 	/* set for image_load(IMG_KERNEL, ...) */
804*4882a593Smuzhiyun 	env_set_hex("android_addr_r", (ulong)load_address);
805*4882a593Smuzhiyun 	bstart = part ? part->start : 0;
806*4882a593Smuzhiyun 
807*4882a593Smuzhiyun 	/*
808*4882a593Smuzhiyun 	 * 1. Load images to their individual target ram position
809*4882a593Smuzhiyun 	 *    in order to disable fdt/ramdisk relocation.
810*4882a593Smuzhiyun 	 */
811*4882a593Smuzhiyun 	if (image_load(IMG_RK_DTB,  hdr, bstart, ram_base, NULL))
812*4882a593Smuzhiyun 		return -1;
813*4882a593Smuzhiyun 	if (image_load(IMG_KERNEL,  hdr, bstart, ram_base, NULL))
814*4882a593Smuzhiyun 		return -1;
815*4882a593Smuzhiyun 	if (image_load(IMG_VENDOR_RAMDISK, hdr, bstart, ram_base, NULL))
816*4882a593Smuzhiyun 		return -1;
817*4882a593Smuzhiyun 	if (image_load(IMG_RAMDISK, hdr, bstart, ram_base, NULL))
818*4882a593Smuzhiyun 		return -1;
819*4882a593Smuzhiyun 	if (image_load(IMG_BOOTCONFIG, hdr, bstart, ram_base, NULL))
820*4882a593Smuzhiyun 		return -1;
821*4882a593Smuzhiyun 	/*
822*4882a593Smuzhiyun 	 * Copy the populated hdr to load address after image_load(IMG_KERNEL)
823*4882a593Smuzhiyun 	 *
824*4882a593Smuzhiyun 	 * The image_load(IMG_KERNEL) only reads boot_img_hdr_v34 while
825*4882a593Smuzhiyun 	 * vendor_boot_img_hdr_v34 is not included, so fix it here.
826*4882a593Smuzhiyun 	 */
827*4882a593Smuzhiyun 	memcpy((char *)load_address, hdr, hdr->page_size);
828*4882a593Smuzhiyun 
829*4882a593Smuzhiyun 	/* 2. Disable fdt/ramdisk relocation, it saves boot time */
830*4882a593Smuzhiyun 	env_set("bootm-no-reloc", "y");
831*4882a593Smuzhiyun 
832*4882a593Smuzhiyun 	return 0;
833*4882a593Smuzhiyun }
834*4882a593Smuzhiyun 
android_image_get_comp_addr(struct andr_img_hdr * hdr,int comp)835*4882a593Smuzhiyun static ulong android_image_get_comp_addr(struct andr_img_hdr *hdr, int comp)
836*4882a593Smuzhiyun {
837*4882a593Smuzhiyun 	ulong kernel_addr_c;
838*4882a593Smuzhiyun 	ulong load_addr = 0;
839*4882a593Smuzhiyun 
840*4882a593Smuzhiyun 	kernel_addr_c = env_get_ulong("kernel_addr_c", 16, 0);
841*4882a593Smuzhiyun 
842*4882a593Smuzhiyun #ifdef CONFIG_ARM64
843*4882a593Smuzhiyun 	/*
844*4882a593Smuzhiyun 	 * On 64-bit kernel, assuming use IMAGE by default.
845*4882a593Smuzhiyun 	 *
846*4882a593Smuzhiyun 	 * kernel_addr_c is for LZ4-IMAGE but maybe not defined.
847*4882a593Smuzhiyun 	 * kernel_addr_r is for IMAGE.
848*4882a593Smuzhiyun 	 */
849*4882a593Smuzhiyun 	if (comp != IH_COMP_NONE) {
850*4882a593Smuzhiyun 		ulong comp_addr;
851*4882a593Smuzhiyun 
852*4882a593Smuzhiyun 		if (kernel_addr_c) {
853*4882a593Smuzhiyun 			comp_addr = kernel_addr_c;
854*4882a593Smuzhiyun 		} else {
855*4882a593Smuzhiyun 			printf("Warn: No \"kernel_addr_c\"\n");
856*4882a593Smuzhiyun 			comp_addr = CONFIG_SYS_SDRAM_BASE + 0x2000000;/* 32M */
857*4882a593Smuzhiyun 			env_set_hex("kernel_addr_c", comp_addr);
858*4882a593Smuzhiyun 		}
859*4882a593Smuzhiyun 
860*4882a593Smuzhiyun 		load_addr = comp_addr - hdr->page_size;
861*4882a593Smuzhiyun 	}
862*4882a593Smuzhiyun #else
863*4882a593Smuzhiyun 	/*
864*4882a593Smuzhiyun 	 * On 32-bit kernel:
865*4882a593Smuzhiyun 	 *
866*4882a593Smuzhiyun 	 * The input load_addr is from env value: "kernel_addr_r", it has
867*4882a593Smuzhiyun 	 * different role depends on whether kernel_addr_c is defined:
868*4882a593Smuzhiyun 	 *
869*4882a593Smuzhiyun 	 * - kernel_addr_r is for lz4/zImage if kernel_addr_c if [not] defined.
870*4882a593Smuzhiyun 	 * - kernel_addr_r is for IMAGE if kernel_addr_c is defined.
871*4882a593Smuzhiyun 	 */
872*4882a593Smuzhiyun 	if (comp == IH_COMP_NONE) {
873*4882a593Smuzhiyun 		if (kernel_addr_c) {
874*4882a593Smuzhiyun 			/* input load_addr is for Image, nothing to do */
875*4882a593Smuzhiyun 		} else {
876*4882a593Smuzhiyun 			/* input load_addr is for lz4/zImage, set default addr for Image */
877*4882a593Smuzhiyun 			load_addr = CONFIG_SYS_SDRAM_BASE + 0x8000;
878*4882a593Smuzhiyun 			env_set_hex("kernel_addr_r", load_addr);
879*4882a593Smuzhiyun 
880*4882a593Smuzhiyun 			load_addr -= hdr->page_size;
881*4882a593Smuzhiyun 		}
882*4882a593Smuzhiyun 	} else {
883*4882a593Smuzhiyun 		if (kernel_addr_c) {
884*4882a593Smuzhiyun 			/* input load_addr is for Image, so use another for lz4/zImage */
885*4882a593Smuzhiyun 			load_addr = kernel_addr_c - hdr->page_size;
886*4882a593Smuzhiyun 		} else {
887*4882a593Smuzhiyun 			/* input load_addr is for lz4/zImage, nothing to do */
888*4882a593Smuzhiyun 		}
889*4882a593Smuzhiyun 	}
890*4882a593Smuzhiyun #endif
891*4882a593Smuzhiyun 
892*4882a593Smuzhiyun 	return load_addr;
893*4882a593Smuzhiyun }
894*4882a593Smuzhiyun 
android_image_set_decomp(struct andr_img_hdr * hdr,int comp)895*4882a593Smuzhiyun void android_image_set_decomp(struct andr_img_hdr *hdr, int comp)
896*4882a593Smuzhiyun {
897*4882a593Smuzhiyun 	ulong kernel_addr_r;
898*4882a593Smuzhiyun 
899*4882a593Smuzhiyun 	env_set_ulong("os_comp", comp);
900*4882a593Smuzhiyun 
901*4882a593Smuzhiyun 	/* zImage handles decompress itself */
902*4882a593Smuzhiyun 	if (comp != IH_COMP_NONE && comp != IH_COMP_ZIMAGE) {
903*4882a593Smuzhiyun 		kernel_addr_r = env_get_ulong("kernel_addr_r", 16, 0x02080000);
904*4882a593Smuzhiyun 		android_image_set_kload(hdr, kernel_addr_r);
905*4882a593Smuzhiyun 		android_image_set_comp(hdr, comp);
906*4882a593Smuzhiyun 	} else {
907*4882a593Smuzhiyun 		android_image_set_comp(hdr, IH_COMP_NONE);
908*4882a593Smuzhiyun 	}
909*4882a593Smuzhiyun }
910*4882a593Smuzhiyun 
android_image_load_separate(struct andr_img_hdr * hdr,const disk_partition_t * part,void * load_addr)911*4882a593Smuzhiyun static int android_image_load_separate(struct andr_img_hdr *hdr,
912*4882a593Smuzhiyun 				       const disk_partition_t *part,
913*4882a593Smuzhiyun 				       void *load_addr)
914*4882a593Smuzhiyun {
915*4882a593Smuzhiyun 	if (hdr->header_version < 3)
916*4882a593Smuzhiyun 		return android_image_separate(hdr, part, load_addr, NULL);
917*4882a593Smuzhiyun 	else
918*4882a593Smuzhiyun 		return android_image_separate_v34(hdr, part, load_addr, NULL);
919*4882a593Smuzhiyun }
920*4882a593Smuzhiyun 
android_image_memcpy_separate(struct andr_img_hdr * hdr,ulong * load_addr)921*4882a593Smuzhiyun int android_image_memcpy_separate(struct andr_img_hdr *hdr, ulong *load_addr)
922*4882a593Smuzhiyun {
923*4882a593Smuzhiyun 	ulong comp_addr;
924*4882a593Smuzhiyun 	int comp;
925*4882a593Smuzhiyun 
926*4882a593Smuzhiyun 	comp = bootm_parse_comp((void *)(ulong)hdr + hdr->page_size);
927*4882a593Smuzhiyun 	comp_addr = android_image_get_comp_addr(hdr, comp);
928*4882a593Smuzhiyun 
929*4882a593Smuzhiyun 	/* non-compressed image: already in-place */
930*4882a593Smuzhiyun 	if ((ulong)hdr == *load_addr)
931*4882a593Smuzhiyun 		return 0;
932*4882a593Smuzhiyun 
933*4882a593Smuzhiyun 	/* compressed image */
934*4882a593Smuzhiyun 	if (comp_addr) {
935*4882a593Smuzhiyun 		*load_addr = comp_addr;
936*4882a593Smuzhiyun 		if ((ulong)hdr == comp_addr)	/* already in-place */
937*4882a593Smuzhiyun 			return 0;
938*4882a593Smuzhiyun 	}
939*4882a593Smuzhiyun 
940*4882a593Smuzhiyun 	/*
941*4882a593Smuzhiyun 	 * The most possible reason to arrive here is:
942*4882a593Smuzhiyun 	 *
943*4882a593Smuzhiyun 	 * VBoot=1 and AVB load full partition to a temp memory buffer, now we
944*4882a593Smuzhiyun 	 * separate(memcpy) subimages from boot.img to where they should be.
945*4882a593Smuzhiyun 	 */
946*4882a593Smuzhiyun 	if (hdr->header_version < 3) {
947*4882a593Smuzhiyun 		if (android_image_separate(hdr, NULL, (void *)(*load_addr), hdr))
948*4882a593Smuzhiyun 			return -1;
949*4882a593Smuzhiyun 	} else {
950*4882a593Smuzhiyun 		if (android_image_separate_v34(hdr, NULL, (void *)(*load_addr), hdr))
951*4882a593Smuzhiyun 			return -1;
952*4882a593Smuzhiyun 	}
953*4882a593Smuzhiyun 
954*4882a593Smuzhiyun 	android_image_set_decomp((void *)(*load_addr), comp);
955*4882a593Smuzhiyun 
956*4882a593Smuzhiyun 	return 0;
957*4882a593Smuzhiyun }
958*4882a593Smuzhiyun 
android_image_load(struct blk_desc * dev_desc,const disk_partition_t * part_info,unsigned long load_address,unsigned long max_size)959*4882a593Smuzhiyun long android_image_load(struct blk_desc *dev_desc,
960*4882a593Smuzhiyun 			const disk_partition_t *part_info,
961*4882a593Smuzhiyun 			unsigned long load_address,
962*4882a593Smuzhiyun 			unsigned long max_size) {
963*4882a593Smuzhiyun 	struct andr_img_hdr *hdr;
964*4882a593Smuzhiyun 	ulong comp_addr;
965*4882a593Smuzhiyun 	int comp, ret;
966*4882a593Smuzhiyun 	int blk_off;
967*4882a593Smuzhiyun 
968*4882a593Smuzhiyun 	if (max_size < part_info->blksz)
969*4882a593Smuzhiyun 		return -1;
970*4882a593Smuzhiyun 
971*4882a593Smuzhiyun 	hdr = populate_andr_img_hdr(dev_desc, (disk_partition_t *)part_info);
972*4882a593Smuzhiyun 	if (!hdr) {
973*4882a593Smuzhiyun 		printf("No valid android hdr\n");
974*4882a593Smuzhiyun 		return -1;
975*4882a593Smuzhiyun 	}
976*4882a593Smuzhiyun 
977*4882a593Smuzhiyun 	/*
978*4882a593Smuzhiyun 	 * create the layout:
979*4882a593Smuzhiyun 	 *
980*4882a593Smuzhiyun 	 * |<- page_size ->|1-blk |
981*4882a593Smuzhiyun 	 * |-----|---------|------|-----|
982*4882a593Smuzhiyun 	 * | hdr |   ...   |   kernel   |
983*4882a593Smuzhiyun 	 * |-----|----- ---|------------|
984*4882a593Smuzhiyun 	 *
985*4882a593Smuzhiyun 	 * Alloc page_size and 1 more blk for reading kernel image to
986*4882a593Smuzhiyun 	 * get it's compression type, then fill the android hdr what
987*4882a593Smuzhiyun 	 * we have populated before.
988*4882a593Smuzhiyun 	 *
989*4882a593Smuzhiyun 	 * Why? see: android_image_get_kernel_addr().
990*4882a593Smuzhiyun 	 */
991*4882a593Smuzhiyun 	blk_off = BLK_CNT(hdr->page_size, dev_desc->blksz);
992*4882a593Smuzhiyun 	hdr = (struct andr_img_hdr *)
993*4882a593Smuzhiyun 			realloc(hdr, (blk_off + 1) * dev_desc->blksz);
994*4882a593Smuzhiyun 	if (!hdr)
995*4882a593Smuzhiyun 		return -1;
996*4882a593Smuzhiyun 
997*4882a593Smuzhiyun 	if (blk_dread(dev_desc, part_info->start + blk_off, 1,
998*4882a593Smuzhiyun 		      (char *)hdr + hdr->page_size) != 1) {
999*4882a593Smuzhiyun 		free(hdr);
1000*4882a593Smuzhiyun 		return -1;
1001*4882a593Smuzhiyun 	}
1002*4882a593Smuzhiyun 
1003*4882a593Smuzhiyun 	/* Changed to compressed address ? */
1004*4882a593Smuzhiyun 	comp = bootm_parse_comp((void *)(ulong)hdr + hdr->page_size);
1005*4882a593Smuzhiyun 	comp_addr = android_image_get_comp_addr(hdr, comp);
1006*4882a593Smuzhiyun 	if (comp_addr)
1007*4882a593Smuzhiyun 		load_address = comp_addr;
1008*4882a593Smuzhiyun 	else
1009*4882a593Smuzhiyun 		load_address -= hdr->page_size;
1010*4882a593Smuzhiyun 
1011*4882a593Smuzhiyun 	ret = android_image_load_separate(hdr, part_info, (void *)load_address);
1012*4882a593Smuzhiyun 	if (ret) {
1013*4882a593Smuzhiyun 		printf("Failed to load android image\n");
1014*4882a593Smuzhiyun 		goto fail;
1015*4882a593Smuzhiyun 	}
1016*4882a593Smuzhiyun 	android_image_set_decomp((void *)load_address, comp);
1017*4882a593Smuzhiyun 
1018*4882a593Smuzhiyun 	debug("Loading Android Image to 0x%08lx\n", load_address);
1019*4882a593Smuzhiyun 
1020*4882a593Smuzhiyun 	free(hdr);
1021*4882a593Smuzhiyun 	return load_address;
1022*4882a593Smuzhiyun 
1023*4882a593Smuzhiyun fail:
1024*4882a593Smuzhiyun 	free(hdr);
1025*4882a593Smuzhiyun 	return -1;
1026*4882a593Smuzhiyun }
1027*4882a593Smuzhiyun 
1028*4882a593Smuzhiyun static struct andr_img_hdr *
extract_boot_image_v012_header(struct blk_desc * dev_desc,const disk_partition_t * boot_img)1029*4882a593Smuzhiyun extract_boot_image_v012_header(struct blk_desc *dev_desc,
1030*4882a593Smuzhiyun 			       const disk_partition_t *boot_img)
1031*4882a593Smuzhiyun {
1032*4882a593Smuzhiyun 	struct andr_img_hdr *hdr;
1033*4882a593Smuzhiyun 	long blk_cnt, blks_read;
1034*4882a593Smuzhiyun 
1035*4882a593Smuzhiyun 	blk_cnt = BLK_CNT(sizeof(struct andr_img_hdr), dev_desc->blksz);
1036*4882a593Smuzhiyun 	hdr = (struct andr_img_hdr *)malloc(blk_cnt * dev_desc->blksz);
1037*4882a593Smuzhiyun 
1038*4882a593Smuzhiyun 	if (!blk_cnt || !hdr)
1039*4882a593Smuzhiyun 		return NULL;
1040*4882a593Smuzhiyun 
1041*4882a593Smuzhiyun 	blks_read = blk_dread(dev_desc, boot_img->start, blk_cnt, hdr);
1042*4882a593Smuzhiyun 	if (blks_read != blk_cnt) {
1043*4882a593Smuzhiyun 		debug("boot img header blk cnt is %ld and blks read is %ld\n",
1044*4882a593Smuzhiyun 		      blk_cnt, blks_read);
1045*4882a593Smuzhiyun 		return NULL;
1046*4882a593Smuzhiyun 	}
1047*4882a593Smuzhiyun 
1048*4882a593Smuzhiyun 	if (android_image_check_header((void *)hdr)) {
1049*4882a593Smuzhiyun 		printf("boot header magic is invalid.\n");
1050*4882a593Smuzhiyun 		return NULL;
1051*4882a593Smuzhiyun 	}
1052*4882a593Smuzhiyun 
1053*4882a593Smuzhiyun 	if (hdr->page_size < sizeof(*hdr)) {
1054*4882a593Smuzhiyun 		printf("android hdr is over size\n");
1055*4882a593Smuzhiyun 		return NULL;
1056*4882a593Smuzhiyun 	}
1057*4882a593Smuzhiyun 
1058*4882a593Smuzhiyun 	return hdr;
1059*4882a593Smuzhiyun }
1060*4882a593Smuzhiyun 
1061*4882a593Smuzhiyun static struct boot_img_hdr_v34 *
extract_boot_image_v34_header(struct blk_desc * dev_desc,const disk_partition_t * boot_img)1062*4882a593Smuzhiyun extract_boot_image_v34_header(struct blk_desc *dev_desc,
1063*4882a593Smuzhiyun 			      const disk_partition_t *boot_img)
1064*4882a593Smuzhiyun {
1065*4882a593Smuzhiyun 	struct boot_img_hdr_v34 *boot_hdr;
1066*4882a593Smuzhiyun 	disk_partition_t part;
1067*4882a593Smuzhiyun 	long blk_cnt, blks_read;
1068*4882a593Smuzhiyun 
1069*4882a593Smuzhiyun 	blk_cnt = BLK_CNT(sizeof(struct boot_img_hdr_v34), dev_desc->blksz);
1070*4882a593Smuzhiyun 	boot_hdr = (struct boot_img_hdr_v34 *)malloc(blk_cnt * dev_desc->blksz);
1071*4882a593Smuzhiyun 
1072*4882a593Smuzhiyun 	if (!blk_cnt || !boot_hdr)
1073*4882a593Smuzhiyun 		return NULL;
1074*4882a593Smuzhiyun 
1075*4882a593Smuzhiyun 	blks_read = blk_dread(dev_desc, boot_img->start, blk_cnt, boot_hdr);
1076*4882a593Smuzhiyun 	if (blks_read != blk_cnt) {
1077*4882a593Smuzhiyun 		debug("boot img header blk cnt is %ld and blks read is %ld\n",
1078*4882a593Smuzhiyun 		      blk_cnt, blks_read);
1079*4882a593Smuzhiyun 		return NULL;
1080*4882a593Smuzhiyun 	}
1081*4882a593Smuzhiyun 
1082*4882a593Smuzhiyun 	if (android_image_check_header((void *)boot_hdr)) {
1083*4882a593Smuzhiyun 		printf("boot header magic is invalid.\n");
1084*4882a593Smuzhiyun 		return NULL;
1085*4882a593Smuzhiyun 	}
1086*4882a593Smuzhiyun 
1087*4882a593Smuzhiyun 	if (boot_hdr->header_version < 3) {
1088*4882a593Smuzhiyun 		printf("boot header %d, is not >= v3.\n",
1089*4882a593Smuzhiyun 		       boot_hdr->header_version);
1090*4882a593Smuzhiyun 		return NULL;
1091*4882a593Smuzhiyun 	}
1092*4882a593Smuzhiyun 
1093*4882a593Smuzhiyun 	/* Start from android-13 GKI, it doesn't assign 'os_version' */
1094*4882a593Smuzhiyun 	if (boot_hdr->header_version >= 4 && boot_hdr->os_version == 0) {
1095*4882a593Smuzhiyun 		if (part_get_info_by_name(dev_desc,
1096*4882a593Smuzhiyun 				ANDROID_PARTITION_INIT_BOOT, &part) > 0)
1097*4882a593Smuzhiyun 			boot_hdr->os_version = 13 << 25;
1098*4882a593Smuzhiyun 	}
1099*4882a593Smuzhiyun 
1100*4882a593Smuzhiyun 	return boot_hdr;
1101*4882a593Smuzhiyun }
1102*4882a593Smuzhiyun 
1103*4882a593Smuzhiyun static struct vendor_boot_img_hdr_v34 *
extract_vendor_boot_image_v34_header(struct blk_desc * dev_desc,const disk_partition_t * part_vendor_boot)1104*4882a593Smuzhiyun extract_vendor_boot_image_v34_header(struct blk_desc *dev_desc,
1105*4882a593Smuzhiyun 				     const disk_partition_t *part_vendor_boot)
1106*4882a593Smuzhiyun {
1107*4882a593Smuzhiyun 	struct vendor_boot_img_hdr_v34 *vboot_hdr;
1108*4882a593Smuzhiyun 	long blk_cnt, blks_read;
1109*4882a593Smuzhiyun 
1110*4882a593Smuzhiyun 	blk_cnt = BLK_CNT(sizeof(struct vendor_boot_img_hdr_v34),
1111*4882a593Smuzhiyun 				part_vendor_boot->blksz);
1112*4882a593Smuzhiyun 	vboot_hdr = (struct vendor_boot_img_hdr_v34 *)
1113*4882a593Smuzhiyun 				malloc(blk_cnt * part_vendor_boot->blksz);
1114*4882a593Smuzhiyun 
1115*4882a593Smuzhiyun 	if (!blk_cnt || !vboot_hdr)
1116*4882a593Smuzhiyun 		return NULL;
1117*4882a593Smuzhiyun 
1118*4882a593Smuzhiyun 	blks_read = blk_dread(dev_desc, part_vendor_boot->start,
1119*4882a593Smuzhiyun 			      blk_cnt, vboot_hdr);
1120*4882a593Smuzhiyun 	if (blks_read != blk_cnt) {
1121*4882a593Smuzhiyun 		debug("vboot img header blk cnt is %ld and blks read is %ld\n",
1122*4882a593Smuzhiyun 		      blk_cnt, blks_read);
1123*4882a593Smuzhiyun 		return NULL;
1124*4882a593Smuzhiyun 	}
1125*4882a593Smuzhiyun 
1126*4882a593Smuzhiyun 	if (strncmp(VENDOR_BOOT_MAGIC, (void *)vboot_hdr->magic,
1127*4882a593Smuzhiyun 		    VENDOR_BOOT_MAGIC_SIZE)) {
1128*4882a593Smuzhiyun 		printf("vendor boot header is invalid.\n");
1129*4882a593Smuzhiyun 		return NULL;
1130*4882a593Smuzhiyun 	}
1131*4882a593Smuzhiyun 
1132*4882a593Smuzhiyun 	if (vboot_hdr->header_version < 3) {
1133*4882a593Smuzhiyun 		printf("vendor boot header %d, is not >= v3.\n",
1134*4882a593Smuzhiyun 		       vboot_hdr->header_version);
1135*4882a593Smuzhiyun 		return NULL;
1136*4882a593Smuzhiyun 	}
1137*4882a593Smuzhiyun 
1138*4882a593Smuzhiyun 	return vboot_hdr;
1139*4882a593Smuzhiyun }
1140*4882a593Smuzhiyun 
populate_boot_info(const struct boot_img_hdr_v34 * boot_hdr,const struct vendor_boot_img_hdr_v34 * vendor_boot_hdr,const struct boot_img_hdr_v34 * init_boot_hdr,struct andr_img_hdr * hdr,bool save_hdr)1141*4882a593Smuzhiyun int populate_boot_info(const struct boot_img_hdr_v34 *boot_hdr,
1142*4882a593Smuzhiyun 		       const struct vendor_boot_img_hdr_v34 *vendor_boot_hdr,
1143*4882a593Smuzhiyun 		       const struct boot_img_hdr_v34 *init_boot_hdr,
1144*4882a593Smuzhiyun 		       struct andr_img_hdr *hdr, bool save_hdr)
1145*4882a593Smuzhiyun {
1146*4882a593Smuzhiyun 	memset(hdr->magic, 0, ANDR_BOOT_MAGIC_SIZE);
1147*4882a593Smuzhiyun 	memcpy(hdr->magic, boot_hdr->magic, ANDR_BOOT_MAGIC_SIZE);
1148*4882a593Smuzhiyun 
1149*4882a593Smuzhiyun 	hdr->kernel_size = boot_hdr->kernel_size;
1150*4882a593Smuzhiyun 	/* don't use vendor_boot_hdr->kernel_addr, we prefer "hdr + hdr->page_size" */
1151*4882a593Smuzhiyun 	hdr->kernel_addr = ANDROID_IMAGE_DEFAULT_KERNEL_ADDR;
1152*4882a593Smuzhiyun 
1153*4882a593Smuzhiyun 	/*
1154*4882a593Smuzhiyun 	 * generic ramdisk: immediately following the vendor ramdisk.
1155*4882a593Smuzhiyun 	 * It can be from init_boot.img or boot.img.
1156*4882a593Smuzhiyun 	 */
1157*4882a593Smuzhiyun 	if (init_boot_hdr)
1158*4882a593Smuzhiyun 		hdr->ramdisk_size = init_boot_hdr->ramdisk_size;
1159*4882a593Smuzhiyun 	else
1160*4882a593Smuzhiyun 		hdr->ramdisk_size = boot_hdr->ramdisk_size;
1161*4882a593Smuzhiyun 
1162*4882a593Smuzhiyun 	/* actually, useless */
1163*4882a593Smuzhiyun 	hdr->ramdisk_addr = env_get_ulong("ramdisk_addr_r", 16, 0);
1164*4882a593Smuzhiyun 
1165*4882a593Smuzhiyun 	/* removed in v3 */
1166*4882a593Smuzhiyun 	hdr->second_size = 0;
1167*4882a593Smuzhiyun 	hdr->second_addr = 0;
1168*4882a593Smuzhiyun 
1169*4882a593Smuzhiyun 	hdr->tags_addr = vendor_boot_hdr->tags_addr;
1170*4882a593Smuzhiyun 
1171*4882a593Smuzhiyun 	/* fixed in v3 */
1172*4882a593Smuzhiyun 	hdr->page_size = 4096;
1173*4882a593Smuzhiyun 	hdr->header_version = boot_hdr->header_version;
1174*4882a593Smuzhiyun 	hdr->os_version = boot_hdr->os_version;
1175*4882a593Smuzhiyun 
1176*4882a593Smuzhiyun 	memset(hdr->name, 0, ANDR_BOOT_NAME_SIZE);
1177*4882a593Smuzhiyun 	strncpy(hdr->name, (const char *)vendor_boot_hdr->name, ANDR_BOOT_NAME_SIZE);
1178*4882a593Smuzhiyun 
1179*4882a593Smuzhiyun 	/* removed in v3 */
1180*4882a593Smuzhiyun 	memset(hdr->cmdline, 0, ANDR_BOOT_ARGS_SIZE);
1181*4882a593Smuzhiyun 	memset(hdr->id, 0, 32);
1182*4882a593Smuzhiyun 	memset(hdr->extra_cmdline, 0, ANDR_BOOT_EXTRA_ARGS_SIZE);
1183*4882a593Smuzhiyun 	hdr->recovery_dtbo_size = 0;
1184*4882a593Smuzhiyun 	hdr->recovery_dtbo_offset = 0;
1185*4882a593Smuzhiyun 
1186*4882a593Smuzhiyun 	hdr->header_size = boot_hdr->header_size;
1187*4882a593Smuzhiyun 	hdr->dtb_size = vendor_boot_hdr->dtb_size;
1188*4882a593Smuzhiyun 	hdr->dtb_addr = vendor_boot_hdr->dtb_addr;
1189*4882a593Smuzhiyun 
1190*4882a593Smuzhiyun 	/* boot_img_hdr_v34 fields */
1191*4882a593Smuzhiyun 	hdr->vendor_ramdisk_size = vendor_boot_hdr->vendor_ramdisk_size;
1192*4882a593Smuzhiyun 	hdr->vendor_page_size = vendor_boot_hdr->page_size;
1193*4882a593Smuzhiyun 	hdr->vendor_header_version = vendor_boot_hdr->header_version;
1194*4882a593Smuzhiyun 	hdr->vendor_header_size = vendor_boot_hdr->header_size;
1195*4882a593Smuzhiyun 
1196*4882a593Smuzhiyun 	hdr->total_cmdline = calloc(1, TOTAL_BOOT_ARGS_SIZE);
1197*4882a593Smuzhiyun 	if (!hdr->total_cmdline)
1198*4882a593Smuzhiyun 		return -ENOMEM;
1199*4882a593Smuzhiyun 	strncpy(hdr->total_cmdline, (const char *)boot_hdr->cmdline,
1200*4882a593Smuzhiyun 		sizeof(boot_hdr->cmdline));
1201*4882a593Smuzhiyun 	strncat(hdr->total_cmdline, " ", 1);
1202*4882a593Smuzhiyun 	strncat(hdr->total_cmdline, (const char *)vendor_boot_hdr->cmdline,
1203*4882a593Smuzhiyun 		sizeof(vendor_boot_hdr->cmdline));
1204*4882a593Smuzhiyun 
1205*4882a593Smuzhiyun 	/* new for header v4 */
1206*4882a593Smuzhiyun 	if (vendor_boot_hdr->header_version >= 4) {
1207*4882a593Smuzhiyun 		hdr->vendor_ramdisk_table_size =
1208*4882a593Smuzhiyun 				vendor_boot_hdr->vendor_ramdisk_table_size;
1209*4882a593Smuzhiyun 		hdr->vendor_ramdisk_table_entry_num =
1210*4882a593Smuzhiyun 				vendor_boot_hdr->vendor_ramdisk_table_entry_num;
1211*4882a593Smuzhiyun 		hdr->vendor_ramdisk_table_entry_size =
1212*4882a593Smuzhiyun 				vendor_boot_hdr->vendor_ramdisk_table_entry_size;
1213*4882a593Smuzhiyun 		/*
1214*4882a593Smuzhiyun 		 * If we place additional "androidboot.xxx" parameters after
1215*4882a593Smuzhiyun 		 * bootconfig, this field value should be increased,
1216*4882a593Smuzhiyun 		 * but not over than ANDROID_ADDITION_BOOTCONFIG_PARAMS_MAX_SIZE.
1217*4882a593Smuzhiyun 		 */
1218*4882a593Smuzhiyun 		hdr->vendor_bootconfig_size =
1219*4882a593Smuzhiyun 				vendor_boot_hdr->vendor_bootconfig_size;
1220*4882a593Smuzhiyun 	} else {
1221*4882a593Smuzhiyun 		hdr->vendor_ramdisk_table_size = 0;
1222*4882a593Smuzhiyun 		hdr->vendor_ramdisk_table_entry_num = 0;
1223*4882a593Smuzhiyun 		hdr->vendor_ramdisk_table_entry_size = 0;
1224*4882a593Smuzhiyun 		hdr->vendor_bootconfig_size = 0;
1225*4882a593Smuzhiyun 	}
1226*4882a593Smuzhiyun 
1227*4882a593Smuzhiyun 	hdr->init_boot_buf = save_hdr ? (void *)init_boot_hdr : 0;
1228*4882a593Smuzhiyun 	hdr->vendor_boot_buf = save_hdr ? (void *)vendor_boot_hdr : 0;
1229*4882a593Smuzhiyun 
1230*4882a593Smuzhiyun 	if (hdr->page_size < sizeof(*hdr)) {
1231*4882a593Smuzhiyun 		printf("android hdr is over size\n");
1232*4882a593Smuzhiyun 		return -EINVAL;
1233*4882a593Smuzhiyun 	}
1234*4882a593Smuzhiyun 
1235*4882a593Smuzhiyun 	return 0;
1236*4882a593Smuzhiyun }
1237*4882a593Smuzhiyun 
1238*4882a593Smuzhiyun /*
1239*4882a593Smuzhiyun  * The possible cases of boot.img + recovery.img:
1240*4882a593Smuzhiyun  *
1241*4882a593Smuzhiyun  * [N]: 0, 1, 2
1242*4882a593Smuzhiyun  * [M]: 0, 1, 2, 3, 4
1243*4882a593Smuzhiyun  *
1244*4882a593Smuzhiyun  * |--------------------|---------------------|
1245*4882a593Smuzhiyun  * |   boot.img         |    recovery.img     |
1246*4882a593Smuzhiyun  * |--------------------|---------------------|
1247*4882a593Smuzhiyun  * | boot_img_hdr_v[N]  |  boot_img_hdr_v[N]  | <= if A/B is not required
1248*4882a593Smuzhiyun  * |--------------------|---------------------|
1249*4882a593Smuzhiyun  * | boot_img_hdr_v34   |  boot_img_hdr_v2    | <= if A/B is not required
1250*4882a593Smuzhiyun  * |------------------------------------------|
1251*4882a593Smuzhiyun  * | boot_img_hdr_v[M], no recovery.img       | <= if A/B is required
1252*4882a593Smuzhiyun  * |------------------------------------------|
1253*4882a593Smuzhiyun  */
populate_andr_img_hdr(struct blk_desc * dev_desc,disk_partition_t * part_boot)1254*4882a593Smuzhiyun struct andr_img_hdr *populate_andr_img_hdr(struct blk_desc *dev_desc,
1255*4882a593Smuzhiyun 					   disk_partition_t *part_boot)
1256*4882a593Smuzhiyun {
1257*4882a593Smuzhiyun 	disk_partition_t part_vendor_boot;
1258*4882a593Smuzhiyun 	disk_partition_t part_init_boot;
1259*4882a593Smuzhiyun 	struct vendor_boot_img_hdr_v34 *vboot_hdr = NULL;
1260*4882a593Smuzhiyun 	struct boot_img_hdr_v34 *iboot_hdr = NULL;
1261*4882a593Smuzhiyun 	struct boot_img_hdr_v34 *boot_hdr = NULL;
1262*4882a593Smuzhiyun 	struct andr_img_hdr *andr_hdr = NULL;
1263*4882a593Smuzhiyun 	int header_version;
1264*4882a593Smuzhiyun 	int andr_version;
1265*4882a593Smuzhiyun 
1266*4882a593Smuzhiyun 	if (!dev_desc || !part_boot)
1267*4882a593Smuzhiyun 		return NULL;
1268*4882a593Smuzhiyun 
1269*4882a593Smuzhiyun 	andr_hdr = (struct andr_img_hdr *)malloc(1 * dev_desc->blksz);
1270*4882a593Smuzhiyun 	if (!andr_hdr)
1271*4882a593Smuzhiyun 		return NULL;
1272*4882a593Smuzhiyun 
1273*4882a593Smuzhiyun 	if (blk_dread(dev_desc, part_boot->start, 1, andr_hdr) != 1) {
1274*4882a593Smuzhiyun 		free(andr_hdr);
1275*4882a593Smuzhiyun 		return NULL;
1276*4882a593Smuzhiyun 	}
1277*4882a593Smuzhiyun 
1278*4882a593Smuzhiyun 	if (android_image_check_header(andr_hdr)) {
1279*4882a593Smuzhiyun 		free(andr_hdr);
1280*4882a593Smuzhiyun 		return NULL;
1281*4882a593Smuzhiyun 	}
1282*4882a593Smuzhiyun 
1283*4882a593Smuzhiyun 	header_version = andr_hdr->header_version;
1284*4882a593Smuzhiyun 	free(andr_hdr);
1285*4882a593Smuzhiyun 	andr_hdr = NULL;
1286*4882a593Smuzhiyun 
1287*4882a593Smuzhiyun 	if (header_version < 3) {
1288*4882a593Smuzhiyun 		return extract_boot_image_v012_header(dev_desc, part_boot);
1289*4882a593Smuzhiyun 	} else {
1290*4882a593Smuzhiyun 		if (part_get_info_by_name(dev_desc,
1291*4882a593Smuzhiyun 					  ANDROID_PARTITION_VENDOR_BOOT,
1292*4882a593Smuzhiyun 					  &part_vendor_boot) < 0) {
1293*4882a593Smuzhiyun 			printf("No vendor boot partition\n");
1294*4882a593Smuzhiyun 			return NULL;
1295*4882a593Smuzhiyun 		}
1296*4882a593Smuzhiyun 		boot_hdr = extract_boot_image_v34_header(dev_desc, part_boot);
1297*4882a593Smuzhiyun 		vboot_hdr = extract_vendor_boot_image_v34_header(dev_desc,
1298*4882a593Smuzhiyun 							&part_vendor_boot);
1299*4882a593Smuzhiyun 		if (!boot_hdr || !vboot_hdr)
1300*4882a593Smuzhiyun 			goto image_load_exit;
1301*4882a593Smuzhiyun 
1302*4882a593Smuzhiyun 		andr_version = (boot_hdr->os_version >> 25) & 0x7f;
1303*4882a593Smuzhiyun 		if (header_version >= 4 && andr_version >= 13) {
1304*4882a593Smuzhiyun 			if (part_get_info_by_name(dev_desc,
1305*4882a593Smuzhiyun 						  ANDROID_PARTITION_INIT_BOOT,
1306*4882a593Smuzhiyun 						  &part_init_boot) < 0) {
1307*4882a593Smuzhiyun 				printf("No init boot partition\n");
1308*4882a593Smuzhiyun 				return NULL;
1309*4882a593Smuzhiyun 			}
1310*4882a593Smuzhiyun 			iboot_hdr = extract_boot_image_v34_header(dev_desc, &part_init_boot);
1311*4882a593Smuzhiyun 			if (!iboot_hdr)
1312*4882a593Smuzhiyun 				goto image_load_exit;
1313*4882a593Smuzhiyun 			if (!iboot_hdr->ramdisk_size) {
1314*4882a593Smuzhiyun 				printf("No ramdisk in init boot partition\n");
1315*4882a593Smuzhiyun 				goto image_load_exit;
1316*4882a593Smuzhiyun 			}
1317*4882a593Smuzhiyun 		}
1318*4882a593Smuzhiyun 
1319*4882a593Smuzhiyun 		andr_hdr = (struct andr_img_hdr *)
1320*4882a593Smuzhiyun 				malloc(sizeof(struct andr_img_hdr));
1321*4882a593Smuzhiyun 		if (!andr_hdr) {
1322*4882a593Smuzhiyun 			printf("No memory for andr hdr\n");
1323*4882a593Smuzhiyun 			goto image_load_exit;
1324*4882a593Smuzhiyun 		}
1325*4882a593Smuzhiyun 
1326*4882a593Smuzhiyun 		if (populate_boot_info(boot_hdr, vboot_hdr,
1327*4882a593Smuzhiyun 				       iboot_hdr, andr_hdr, false)) {
1328*4882a593Smuzhiyun 			printf("populate boot info failed\n");
1329*4882a593Smuzhiyun 			goto image_load_exit;
1330*4882a593Smuzhiyun 		}
1331*4882a593Smuzhiyun 
1332*4882a593Smuzhiyun image_load_exit:
1333*4882a593Smuzhiyun 		if (boot_hdr)
1334*4882a593Smuzhiyun 			free(boot_hdr);
1335*4882a593Smuzhiyun 		if (iboot_hdr)
1336*4882a593Smuzhiyun 			free(iboot_hdr);
1337*4882a593Smuzhiyun 		if (vboot_hdr)
1338*4882a593Smuzhiyun 			free(vboot_hdr);
1339*4882a593Smuzhiyun 
1340*4882a593Smuzhiyun 		return andr_hdr;
1341*4882a593Smuzhiyun 	}
1342*4882a593Smuzhiyun 
1343*4882a593Smuzhiyun 	return NULL;
1344*4882a593Smuzhiyun }
1345*4882a593Smuzhiyun 
1346*4882a593Smuzhiyun #if !defined(CONFIG_SPL_BUILD)
1347*4882a593Smuzhiyun /**
1348*4882a593Smuzhiyun  * android_print_contents - prints out the contents of the Android format image
1349*4882a593Smuzhiyun  * @hdr: pointer to the Android format image header
1350*4882a593Smuzhiyun  *
1351*4882a593Smuzhiyun  * android_print_contents() formats a multi line Android image contents
1352*4882a593Smuzhiyun  * description.
1353*4882a593Smuzhiyun  * The routine prints out Android image properties
1354*4882a593Smuzhiyun  *
1355*4882a593Smuzhiyun  * returns:
1356*4882a593Smuzhiyun  *     no returned results
1357*4882a593Smuzhiyun  */
android_print_contents(const struct andr_img_hdr * hdr)1358*4882a593Smuzhiyun void android_print_contents(const struct andr_img_hdr *hdr)
1359*4882a593Smuzhiyun {
1360*4882a593Smuzhiyun 	const char * const p = IMAGE_INDENT_STRING;
1361*4882a593Smuzhiyun 	/* os_version = ver << 11 | lvl */
1362*4882a593Smuzhiyun 	u32 os_ver = hdr->os_version >> 11;
1363*4882a593Smuzhiyun 	u32 os_lvl = hdr->os_version & ((1U << 11) - 1);
1364*4882a593Smuzhiyun 	u32 header_version = hdr->header_version;
1365*4882a593Smuzhiyun 
1366*4882a593Smuzhiyun 	printf("%skernel size:      %x\n", p, hdr->kernel_size);
1367*4882a593Smuzhiyun 	printf("%skernel address:   %x\n", p, hdr->kernel_addr);
1368*4882a593Smuzhiyun 	printf("%sramdisk size:     %x\n", p, hdr->ramdisk_size);
1369*4882a593Smuzhiyun 	printf("%sramdisk address: %x\n", p, hdr->ramdisk_addr);
1370*4882a593Smuzhiyun 	printf("%ssecond size:      %x\n", p, hdr->second_size);
1371*4882a593Smuzhiyun 	printf("%ssecond address:   %x\n", p, hdr->second_addr);
1372*4882a593Smuzhiyun 	printf("%stags address:     %x\n", p, hdr->tags_addr);
1373*4882a593Smuzhiyun 	printf("%spage size:        %x\n", p, hdr->page_size);
1374*4882a593Smuzhiyun 	printf("%sheader_version:   %x\n", p, header_version);
1375*4882a593Smuzhiyun 	/* ver = A << 14 | B << 7 | C         (7 bits for each of A, B, C)
1376*4882a593Smuzhiyun 	 * lvl = ((Y - 2000) & 127) << 4 | M  (7 bits for Y, 4 bits for M) */
1377*4882a593Smuzhiyun 	printf("%sos_version:       %x (ver: %u.%u.%u, level: %u.%u)\n",
1378*4882a593Smuzhiyun 	       p, hdr->os_version,
1379*4882a593Smuzhiyun 	       (os_ver >> 7) & 0x7F, (os_ver >> 14) & 0x7F, os_ver & 0x7F,
1380*4882a593Smuzhiyun 	       (os_lvl >> 4) + 2000, os_lvl & 0x0F);
1381*4882a593Smuzhiyun 	printf("%sname:             %s\n", p, hdr->name);
1382*4882a593Smuzhiyun 	printf("%scmdline:          %s\n", p, hdr->cmdline);
1383*4882a593Smuzhiyun 
1384*4882a593Smuzhiyun 	if (header_version == 1 || header_version == 2) {
1385*4882a593Smuzhiyun 		printf("%srecovery dtbo size:    %x\n", p, hdr->recovery_dtbo_size);
1386*4882a593Smuzhiyun 		printf("%srecovery dtbo offset:  %llx\n", p, hdr->recovery_dtbo_offset);
1387*4882a593Smuzhiyun 		printf("%sheader size:           %x\n", p, hdr->header_size);
1388*4882a593Smuzhiyun 	}
1389*4882a593Smuzhiyun 
1390*4882a593Smuzhiyun 	if (header_version == 2 || header_version == 3) {
1391*4882a593Smuzhiyun 		printf("%sdtb size:              %x\n", p, hdr->dtb_size);
1392*4882a593Smuzhiyun 		printf("%sdtb addr:              %llx\n", p, hdr->dtb_addr);
1393*4882a593Smuzhiyun 	}
1394*4882a593Smuzhiyun 
1395*4882a593Smuzhiyun 	if (header_version >= 3) {
1396*4882a593Smuzhiyun 		printf("%scmdline:               %s\n", p, hdr->total_cmdline);
1397*4882a593Smuzhiyun 		printf("%svendor ramdisk size:   %x\n", p, hdr->vendor_ramdisk_size);
1398*4882a593Smuzhiyun 		printf("%svendor page size:      %x\n", p, hdr->vendor_page_size);
1399*4882a593Smuzhiyun 		printf("%svendor header version: %d\n", p, hdr->vendor_header_version);
1400*4882a593Smuzhiyun 		printf("%svendor header size:    %x\n", p, hdr->vendor_header_size);
1401*4882a593Smuzhiyun 	}
1402*4882a593Smuzhiyun 
1403*4882a593Smuzhiyun 	if (header_version >= 4) {
1404*4882a593Smuzhiyun 		printf("%svendor ramdisk table size:        %x\n",
1405*4882a593Smuzhiyun 		       p, hdr->vendor_ramdisk_table_size);
1406*4882a593Smuzhiyun 		printf("%svendor ramdisk table entry num:   %x\n",
1407*4882a593Smuzhiyun 		       p, hdr->vendor_ramdisk_table_entry_num);
1408*4882a593Smuzhiyun 		printf("%svendor ramdisk table entry size:  %x\n",
1409*4882a593Smuzhiyun 		       p, hdr->vendor_ramdisk_table_entry_size);
1410*4882a593Smuzhiyun 		printf("%svendor bootconfig size:           %d\n",
1411*4882a593Smuzhiyun 		       p, hdr->vendor_bootconfig_size);
1412*4882a593Smuzhiyun 	}
1413*4882a593Smuzhiyun }
1414*4882a593Smuzhiyun #endif
1415