xref: /OK3568_Linux_fs/u-boot/drivers/mmc/rpmb.c (revision 4882a59341e53eb6f0b4789bf948001014eff981)
1*4882a593Smuzhiyun /*
2*4882a593Smuzhiyun  * Copyright 2014, Staubli Faverges
3*4882a593Smuzhiyun  * Pierre Aubert
4*4882a593Smuzhiyun  *
5*4882a593Smuzhiyun  * eMMC- Replay Protected Memory Block
6*4882a593Smuzhiyun  * According to JEDEC Standard No. 84-A441
7*4882a593Smuzhiyun  *
8*4882a593Smuzhiyun  * SPDX-License-Identifier:	GPL-2.0+
9*4882a593Smuzhiyun  */
10*4882a593Smuzhiyun 
11*4882a593Smuzhiyun #include <config.h>
12*4882a593Smuzhiyun #include <common.h>
13*4882a593Smuzhiyun #include <memalign.h>
14*4882a593Smuzhiyun #include <mmc.h>
15*4882a593Smuzhiyun #include <u-boot/sha256.h>
16*4882a593Smuzhiyun #include "mmc_private.h"
17*4882a593Smuzhiyun 
18*4882a593Smuzhiyun /* Request codes */
19*4882a593Smuzhiyun #define RPMB_REQ_KEY		1
20*4882a593Smuzhiyun #define RPMB_REQ_WCOUNTER	2
21*4882a593Smuzhiyun #define RPMB_REQ_WRITE_DATA	3
22*4882a593Smuzhiyun #define RPMB_REQ_READ_DATA	4
23*4882a593Smuzhiyun #define RPMB_REQ_STATUS		5
24*4882a593Smuzhiyun 
25*4882a593Smuzhiyun /* Response code */
26*4882a593Smuzhiyun #define RPMB_RESP_KEY		0x0100
27*4882a593Smuzhiyun #define RPMB_RESP_WCOUNTER	0x0200
28*4882a593Smuzhiyun #define RPMB_RESP_WRITE_DATA	0x0300
29*4882a593Smuzhiyun #define RPMB_RESP_READ_DATA	0x0400
30*4882a593Smuzhiyun 
31*4882a593Smuzhiyun /* Error codes */
32*4882a593Smuzhiyun #define RPMB_OK			0
33*4882a593Smuzhiyun #define RPMB_ERR_GENERAL	1
34*4882a593Smuzhiyun #define RPMB_ERR_AUTH	2
35*4882a593Smuzhiyun #define RPMB_ERR_COUNTER	3
36*4882a593Smuzhiyun #define RPMB_ERR_ADDRESS	4
37*4882a593Smuzhiyun #define RPMB_ERR_WRITE		5
38*4882a593Smuzhiyun #define RPMB_ERR_READ		6
39*4882a593Smuzhiyun #define RPMB_ERR_KEY		7
40*4882a593Smuzhiyun #define RPMB_ERR_CNT_EXPIRED	0x80
41*4882a593Smuzhiyun #define RPMB_ERR_MSK		0x7
42*4882a593Smuzhiyun 
43*4882a593Smuzhiyun #define SHA256_BLOCK_SIZE	64
44*4882a593Smuzhiyun 
45*4882a593Smuzhiyun /* Error messages */
46*4882a593Smuzhiyun static const char * const rpmb_err_msg[] = {
47*4882a593Smuzhiyun 	"",
48*4882a593Smuzhiyun 	"General failure",
49*4882a593Smuzhiyun 	"Authentication failure",
50*4882a593Smuzhiyun 	"Counter failure",
51*4882a593Smuzhiyun 	"Address failure",
52*4882a593Smuzhiyun 	"Write failure",
53*4882a593Smuzhiyun 	"Read failure",
54*4882a593Smuzhiyun 	"Authentication key not yet programmed",
55*4882a593Smuzhiyun };
56*4882a593Smuzhiyun 
mmc_set_blockcount(struct mmc * mmc,unsigned int blockcount,bool is_rel_write)57*4882a593Smuzhiyun static int mmc_set_blockcount(struct mmc *mmc, unsigned int blockcount,
58*4882a593Smuzhiyun 			      bool is_rel_write)
59*4882a593Smuzhiyun {
60*4882a593Smuzhiyun 	struct mmc_cmd cmd = {0};
61*4882a593Smuzhiyun 
62*4882a593Smuzhiyun 	cmd.cmdidx = MMC_CMD_SET_BLOCK_COUNT;
63*4882a593Smuzhiyun 	cmd.cmdarg = blockcount & 0x0000FFFF;
64*4882a593Smuzhiyun 	if (is_rel_write)
65*4882a593Smuzhiyun 		cmd.cmdarg |= 1 << 31;
66*4882a593Smuzhiyun 	cmd.resp_type = MMC_RSP_R1;
67*4882a593Smuzhiyun 
68*4882a593Smuzhiyun 	return mmc_send_cmd(mmc, &cmd, NULL);
69*4882a593Smuzhiyun }
mmc_rpmb_request(struct mmc * mmc,const void * s,unsigned int count,bool is_rel_write)70*4882a593Smuzhiyun static int mmc_rpmb_request(struct mmc *mmc, const void *s,
71*4882a593Smuzhiyun 			    unsigned int count, bool is_rel_write)
72*4882a593Smuzhiyun {
73*4882a593Smuzhiyun 	struct mmc_cmd cmd = {0};
74*4882a593Smuzhiyun 	struct mmc_data data;
75*4882a593Smuzhiyun 	int ret;
76*4882a593Smuzhiyun 
77*4882a593Smuzhiyun 	ret = mmc_set_blockcount(mmc, count, is_rel_write);
78*4882a593Smuzhiyun 	if (ret) {
79*4882a593Smuzhiyun #ifdef CONFIG_MMC_RPMB_TRACE
80*4882a593Smuzhiyun 		printf("%s:mmc_set_blockcount-> %d\n", __func__, ret);
81*4882a593Smuzhiyun #endif
82*4882a593Smuzhiyun 		return 1;
83*4882a593Smuzhiyun 	}
84*4882a593Smuzhiyun 
85*4882a593Smuzhiyun 	cmd.cmdidx = MMC_CMD_WRITE_MULTIPLE_BLOCK;
86*4882a593Smuzhiyun 	cmd.cmdarg = 0;
87*4882a593Smuzhiyun 	cmd.resp_type = MMC_RSP_R1;
88*4882a593Smuzhiyun 
89*4882a593Smuzhiyun 	data.src = (const char *)s;
90*4882a593Smuzhiyun 	data.blocks = count;
91*4882a593Smuzhiyun 	data.blocksize = MMC_MAX_BLOCK_LEN;
92*4882a593Smuzhiyun 	data.flags = MMC_DATA_WRITE;
93*4882a593Smuzhiyun 
94*4882a593Smuzhiyun 	ret = mmc_send_cmd(mmc, &cmd, &data);
95*4882a593Smuzhiyun 	if (ret) {
96*4882a593Smuzhiyun #ifdef CONFIG_MMC_RPMB_TRACE
97*4882a593Smuzhiyun 		printf("%s:mmc_send_cmd-> %d\n", __func__, ret);
98*4882a593Smuzhiyun #endif
99*4882a593Smuzhiyun 		return 1;
100*4882a593Smuzhiyun 	}
101*4882a593Smuzhiyun 	return 0;
102*4882a593Smuzhiyun }
mmc_rpmb_response(struct mmc * mmc,struct s_rpmb * s,unsigned short expected,unsigned short cnt)103*4882a593Smuzhiyun static int mmc_rpmb_response(struct mmc *mmc, struct s_rpmb *s,
104*4882a593Smuzhiyun 			     unsigned short expected, unsigned short cnt)
105*4882a593Smuzhiyun {
106*4882a593Smuzhiyun 	struct mmc_cmd cmd = {0};
107*4882a593Smuzhiyun 	struct mmc_data data;
108*4882a593Smuzhiyun 	int ret;
109*4882a593Smuzhiyun 
110*4882a593Smuzhiyun 	ret = mmc_set_blockcount(mmc, cnt, false);
111*4882a593Smuzhiyun 	if (ret) {
112*4882a593Smuzhiyun #ifdef CONFIG_MMC_RPMB_TRACE
113*4882a593Smuzhiyun 		printf("%s:mmc_set_blockcount-> %d\n", __func__, ret);
114*4882a593Smuzhiyun #endif
115*4882a593Smuzhiyun 		return -1;
116*4882a593Smuzhiyun 	}
117*4882a593Smuzhiyun 	cmd.cmdidx = MMC_CMD_READ_MULTIPLE_BLOCK;
118*4882a593Smuzhiyun 	cmd.cmdarg = 0;
119*4882a593Smuzhiyun 	cmd.resp_type = MMC_RSP_R1;
120*4882a593Smuzhiyun 
121*4882a593Smuzhiyun 	data.dest = (char *)s;
122*4882a593Smuzhiyun 	data.blocks = cnt;
123*4882a593Smuzhiyun 	data.blocksize = MMC_MAX_BLOCK_LEN;
124*4882a593Smuzhiyun 	data.flags = MMC_DATA_READ;
125*4882a593Smuzhiyun 
126*4882a593Smuzhiyun 	ret = mmc_send_cmd(mmc, &cmd, &data);
127*4882a593Smuzhiyun 	if (ret) {
128*4882a593Smuzhiyun #ifdef CONFIG_MMC_RPMB_TRACE
129*4882a593Smuzhiyun 		printf("%s:mmc_send_cmd-> %d\n", __func__, ret);
130*4882a593Smuzhiyun #endif
131*4882a593Smuzhiyun 		return -1;
132*4882a593Smuzhiyun 	}
133*4882a593Smuzhiyun 	/* Check the response and the status */
134*4882a593Smuzhiyun 	if (be16_to_cpu(s->request) != expected) {
135*4882a593Smuzhiyun #ifdef CONFIG_MMC_RPMB_TRACE
136*4882a593Smuzhiyun 		printf("%s:response= %x\n", __func__,
137*4882a593Smuzhiyun 		       be16_to_cpu(s->request));
138*4882a593Smuzhiyun #endif
139*4882a593Smuzhiyun 		return -1;
140*4882a593Smuzhiyun 	}
141*4882a593Smuzhiyun 	ret = be16_to_cpu(s->result);
142*4882a593Smuzhiyun 	if (ret) {
143*4882a593Smuzhiyun 		printf("%s %s\n", rpmb_err_msg[ret & RPMB_ERR_MSK],
144*4882a593Smuzhiyun 		       (ret & RPMB_ERR_CNT_EXPIRED) ?
145*4882a593Smuzhiyun 		       "Write counter has expired" : "");
146*4882a593Smuzhiyun 	}
147*4882a593Smuzhiyun 
148*4882a593Smuzhiyun 	/* Return the status of the command */
149*4882a593Smuzhiyun 	return ret;
150*4882a593Smuzhiyun }
mmc_rpmb_status(struct mmc * mmc,unsigned short expected)151*4882a593Smuzhiyun static int mmc_rpmb_status(struct mmc *mmc, unsigned short expected)
152*4882a593Smuzhiyun {
153*4882a593Smuzhiyun 	ALLOC_CACHE_ALIGN_BUFFER(struct s_rpmb, rpmb_frame, 1);
154*4882a593Smuzhiyun 
155*4882a593Smuzhiyun 	memset(rpmb_frame, 0, sizeof(struct s_rpmb));
156*4882a593Smuzhiyun 	rpmb_frame->request = cpu_to_be16(RPMB_REQ_STATUS);
157*4882a593Smuzhiyun 	if (mmc_rpmb_request(mmc, rpmb_frame, 1, false))
158*4882a593Smuzhiyun 		return -1;
159*4882a593Smuzhiyun 
160*4882a593Smuzhiyun 	/* Read the result */
161*4882a593Smuzhiyun 	return mmc_rpmb_response(mmc, rpmb_frame, expected, 1);
162*4882a593Smuzhiyun }
rpmb_hmac(unsigned char * key,unsigned char * buff,int len,unsigned char * output)163*4882a593Smuzhiyun static void rpmb_hmac(unsigned char *key, unsigned char *buff, int len,
164*4882a593Smuzhiyun 		      unsigned char *output)
165*4882a593Smuzhiyun {
166*4882a593Smuzhiyun 	sha256_context ctx;
167*4882a593Smuzhiyun 	int i;
168*4882a593Smuzhiyun 	unsigned char k_ipad[SHA256_BLOCK_SIZE];
169*4882a593Smuzhiyun 	unsigned char k_opad[SHA256_BLOCK_SIZE];
170*4882a593Smuzhiyun 
171*4882a593Smuzhiyun 	sha256_starts(&ctx);
172*4882a593Smuzhiyun 
173*4882a593Smuzhiyun 	/* According to RFC 4634, the HMAC transform looks like:
174*4882a593Smuzhiyun 	   SHA(K XOR opad, SHA(K XOR ipad, text))
175*4882a593Smuzhiyun 
176*4882a593Smuzhiyun 	   where K is an n byte key.
177*4882a593Smuzhiyun 	   ipad is the byte 0x36 repeated blocksize times
178*4882a593Smuzhiyun 	   opad is the byte 0x5c repeated blocksize times
179*4882a593Smuzhiyun 	   and text is the data being protected.
180*4882a593Smuzhiyun 	*/
181*4882a593Smuzhiyun 
182*4882a593Smuzhiyun 	for (i = 0; i < RPMB_SZ_MAC; i++) {
183*4882a593Smuzhiyun 		k_ipad[i] = key[i] ^ 0x36;
184*4882a593Smuzhiyun 		k_opad[i] = key[i] ^ 0x5c;
185*4882a593Smuzhiyun 	}
186*4882a593Smuzhiyun 	/* remaining pad bytes are '\0' XOR'd with ipad and opad values */
187*4882a593Smuzhiyun 	for ( ; i < SHA256_BLOCK_SIZE; i++) {
188*4882a593Smuzhiyun 		k_ipad[i] = 0x36;
189*4882a593Smuzhiyun 		k_opad[i] = 0x5c;
190*4882a593Smuzhiyun 	}
191*4882a593Smuzhiyun 	sha256_update(&ctx, k_ipad, SHA256_BLOCK_SIZE);
192*4882a593Smuzhiyun 	sha256_update(&ctx, buff, len);
193*4882a593Smuzhiyun 	sha256_finish(&ctx, output);
194*4882a593Smuzhiyun 
195*4882a593Smuzhiyun 	/* Init context for second pass */
196*4882a593Smuzhiyun 	sha256_starts(&ctx);
197*4882a593Smuzhiyun 
198*4882a593Smuzhiyun 	/* start with outer pad */
199*4882a593Smuzhiyun 	sha256_update(&ctx, k_opad, SHA256_BLOCK_SIZE);
200*4882a593Smuzhiyun 
201*4882a593Smuzhiyun 	/* then results of 1st hash */
202*4882a593Smuzhiyun 	sha256_update(&ctx, output, RPMB_SZ_MAC);
203*4882a593Smuzhiyun 
204*4882a593Smuzhiyun 	/* finish up 2nd pass */
205*4882a593Smuzhiyun 	sha256_finish(&ctx, output);
206*4882a593Smuzhiyun }
mmc_rpmb_get_counter(struct mmc * mmc,unsigned long * pcounter)207*4882a593Smuzhiyun int mmc_rpmb_get_counter(struct mmc *mmc, unsigned long *pcounter)
208*4882a593Smuzhiyun {
209*4882a593Smuzhiyun 	int ret;
210*4882a593Smuzhiyun 	ALLOC_CACHE_ALIGN_BUFFER(struct s_rpmb, rpmb_frame, 1);
211*4882a593Smuzhiyun 
212*4882a593Smuzhiyun 	/* Fill the request */
213*4882a593Smuzhiyun 	memset(rpmb_frame, 0, sizeof(struct s_rpmb));
214*4882a593Smuzhiyun 	rpmb_frame->request = cpu_to_be16(RPMB_REQ_WCOUNTER);
215*4882a593Smuzhiyun 	if (mmc_rpmb_request(mmc, rpmb_frame, 1, false))
216*4882a593Smuzhiyun 		return -1;
217*4882a593Smuzhiyun 
218*4882a593Smuzhiyun 	/* Read the result */
219*4882a593Smuzhiyun 	ret = mmc_rpmb_response(mmc, rpmb_frame, RPMB_RESP_WCOUNTER, 1);
220*4882a593Smuzhiyun 	if (ret)
221*4882a593Smuzhiyun 		return ret;
222*4882a593Smuzhiyun 
223*4882a593Smuzhiyun 	*pcounter = be32_to_cpu(rpmb_frame->write_counter);
224*4882a593Smuzhiyun 	return 0;
225*4882a593Smuzhiyun }
mmc_rpmb_set_key(struct mmc * mmc,void * key)226*4882a593Smuzhiyun int mmc_rpmb_set_key(struct mmc *mmc, void *key)
227*4882a593Smuzhiyun {
228*4882a593Smuzhiyun 	ALLOC_CACHE_ALIGN_BUFFER(struct s_rpmb, rpmb_frame, 1);
229*4882a593Smuzhiyun 	/* Fill the request */
230*4882a593Smuzhiyun 	memset(rpmb_frame, 0, sizeof(struct s_rpmb));
231*4882a593Smuzhiyun 	rpmb_frame->request = cpu_to_be16(RPMB_REQ_KEY);
232*4882a593Smuzhiyun 	memcpy(rpmb_frame->mac, key, RPMB_SZ_MAC);
233*4882a593Smuzhiyun 
234*4882a593Smuzhiyun 	if (mmc_rpmb_request(mmc, rpmb_frame, 1, true))
235*4882a593Smuzhiyun 		return -1;
236*4882a593Smuzhiyun 
237*4882a593Smuzhiyun 	/* read the operation status */
238*4882a593Smuzhiyun 	return mmc_rpmb_status(mmc, RPMB_RESP_KEY);
239*4882a593Smuzhiyun }
mmc_rpmb_read(struct mmc * mmc,void * addr,unsigned short blk,unsigned short cnt,unsigned char * key)240*4882a593Smuzhiyun int mmc_rpmb_read(struct mmc *mmc, void *addr, unsigned short blk,
241*4882a593Smuzhiyun 		  unsigned short cnt, unsigned char *key)
242*4882a593Smuzhiyun {
243*4882a593Smuzhiyun 	ALLOC_CACHE_ALIGN_BUFFER
244*4882a593Smuzhiyun 		(char, rpmb_frame_data,
245*4882a593Smuzhiyun 		sizeof(struct s_rpmb) * cnt);
246*4882a593Smuzhiyun 	ALLOC_CACHE_ALIGN_BUFFER
247*4882a593Smuzhiyun 		(char, rpmb_frame_data_verify,
248*4882a593Smuzhiyun 		sizeof(struct s_rpmb_verify) * cnt);
249*4882a593Smuzhiyun 	struct s_rpmb *rpmb_frame;
250*4882a593Smuzhiyun 	struct s_rpmb_verify *rpmb_frame_vrify;
251*4882a593Smuzhiyun 	int i;
252*4882a593Smuzhiyun 
253*4882a593Smuzhiyun 	memset(rpmb_frame_data, 0, sizeof(struct s_rpmb) * cnt);
254*4882a593Smuzhiyun 	memset(rpmb_frame_data_verify, 0, sizeof(struct s_rpmb_verify) * cnt);
255*4882a593Smuzhiyun 	rpmb_frame = (struct s_rpmb *)rpmb_frame_data;
256*4882a593Smuzhiyun 	rpmb_frame->address = cpu_to_be16(blk);
257*4882a593Smuzhiyun 	rpmb_frame->request = cpu_to_be16(RPMB_REQ_READ_DATA);
258*4882a593Smuzhiyun 	if (mmc_rpmb_request(mmc, rpmb_frame, 1, false)) {
259*4882a593Smuzhiyun 		printf("mmc_rpmb_read request error\n");
260*4882a593Smuzhiyun 		return -1;
261*4882a593Smuzhiyun 	}
262*4882a593Smuzhiyun 
263*4882a593Smuzhiyun 	if (mmc_rpmb_response
264*4882a593Smuzhiyun 			(mmc,
265*4882a593Smuzhiyun 			(struct s_rpmb *)rpmb_frame_data,
266*4882a593Smuzhiyun 			RPMB_RESP_READ_DATA, cnt)) {
267*4882a593Smuzhiyun 		printf("mmc_rpmb_read response error\n");
268*4882a593Smuzhiyun 		return -1;
269*4882a593Smuzhiyun 	}
270*4882a593Smuzhiyun 
271*4882a593Smuzhiyun 	for (i = 0; i < cnt; i++) {
272*4882a593Smuzhiyun 		rpmb_frame = (struct s_rpmb *)
273*4882a593Smuzhiyun 					(rpmb_frame_data +
274*4882a593Smuzhiyun 					i * sizeof(struct s_rpmb));
275*4882a593Smuzhiyun 
276*4882a593Smuzhiyun 		rpmb_frame_vrify = (struct s_rpmb_verify *)
277*4882a593Smuzhiyun 					(rpmb_frame_data_verify +
278*4882a593Smuzhiyun 					i * sizeof(struct s_rpmb_verify));
279*4882a593Smuzhiyun 		memcpy(addr + i * RPMB_SZ_DATA, rpmb_frame->data, RPMB_SZ_DATA);
280*4882a593Smuzhiyun 		memcpy(rpmb_frame_vrify->data, rpmb_frame->data, 284);
281*4882a593Smuzhiyun 	}
282*4882a593Smuzhiyun 
283*4882a593Smuzhiyun 	if (key) {
284*4882a593Smuzhiyun 		unsigned char ret_hmac[RPMB_SZ_MAC];
285*4882a593Smuzhiyun 		rpmb_hmac
286*4882a593Smuzhiyun 			(key, (unsigned char *)rpmb_frame_data_verify,
287*4882a593Smuzhiyun 			284 * cnt, ret_hmac);
288*4882a593Smuzhiyun 		if (memcmp(ret_hmac, rpmb_frame->mac, RPMB_SZ_MAC)) {
289*4882a593Smuzhiyun 			printf("MAC error on block #%d\n", i);
290*4882a593Smuzhiyun 			return -1;
291*4882a593Smuzhiyun 		}
292*4882a593Smuzhiyun 	}
293*4882a593Smuzhiyun 
294*4882a593Smuzhiyun 	return cnt;
295*4882a593Smuzhiyun }
mmc_rpmb_write(struct mmc * mmc,void * addr,unsigned short blk,unsigned short cnt,unsigned char * key)296*4882a593Smuzhiyun int mmc_rpmb_write(struct mmc *mmc, void *addr, unsigned short blk,
297*4882a593Smuzhiyun 		  unsigned short cnt, unsigned char *key)
298*4882a593Smuzhiyun {
299*4882a593Smuzhiyun 	struct s_rpmb *rpmb_frame;
300*4882a593Smuzhiyun 	struct s_rpmb_verify *rpmb_frame_vrify;
301*4882a593Smuzhiyun 	ALLOC_CACHE_ALIGN_BUFFER
302*4882a593Smuzhiyun 		(char, rpmb_frame_data,
303*4882a593Smuzhiyun 		sizeof(struct s_rpmb) * cnt);
304*4882a593Smuzhiyun 	ALLOC_CACHE_ALIGN_BUFFER
305*4882a593Smuzhiyun 		(char, rpmb_frame_data_verify,
306*4882a593Smuzhiyun 		sizeof(struct s_rpmb_verify) * cnt);
307*4882a593Smuzhiyun 
308*4882a593Smuzhiyun 	unsigned long wcount;
309*4882a593Smuzhiyun 	unsigned short i;
310*4882a593Smuzhiyun 	unsigned short temp;
311*4882a593Smuzhiyun 
312*4882a593Smuzhiyun 	temp = cnt - 1;
313*4882a593Smuzhiyun 	memset(rpmb_frame_data, 0, sizeof(struct s_rpmb) * cnt);
314*4882a593Smuzhiyun 	memset(rpmb_frame_data_verify, 0, sizeof(struct s_rpmb_verify) * cnt);
315*4882a593Smuzhiyun 	for (i = 0; i < cnt; i++) {
316*4882a593Smuzhiyun 		if (i == 0) {
317*4882a593Smuzhiyun 			if (mmc_rpmb_get_counter(mmc, &wcount)) {
318*4882a593Smuzhiyun 				printf("Cannot read RPMB write counter\n");
319*4882a593Smuzhiyun 				break;
320*4882a593Smuzhiyun 			}
321*4882a593Smuzhiyun 		}
322*4882a593Smuzhiyun 
323*4882a593Smuzhiyun 		rpmb_frame = (struct s_rpmb *)
324*4882a593Smuzhiyun 			(rpmb_frame_data +
325*4882a593Smuzhiyun 			i * sizeof(struct s_rpmb));
326*4882a593Smuzhiyun 		rpmb_frame_vrify = (struct s_rpmb_verify *)
327*4882a593Smuzhiyun 			(rpmb_frame_data_verify +
328*4882a593Smuzhiyun 			i * sizeof(struct s_rpmb_verify));
329*4882a593Smuzhiyun 		memcpy(rpmb_frame->data, addr + i * RPMB_SZ_DATA, RPMB_SZ_DATA);
330*4882a593Smuzhiyun 		memcpy(rpmb_frame_vrify->data, addr +
331*4882a593Smuzhiyun 			i * RPMB_SZ_DATA, RPMB_SZ_DATA);
332*4882a593Smuzhiyun 		rpmb_frame->address = cpu_to_be16(blk);
333*4882a593Smuzhiyun 		rpmb_frame_vrify->address = cpu_to_be16(blk);
334*4882a593Smuzhiyun 		rpmb_frame->block_count = cpu_to_be16(cnt);
335*4882a593Smuzhiyun 		rpmb_frame_vrify->block_count = cpu_to_be16(cnt);
336*4882a593Smuzhiyun 		rpmb_frame->write_counter = cpu_to_be32(wcount);
337*4882a593Smuzhiyun 		rpmb_frame_vrify->write_counter = cpu_to_be32(wcount);
338*4882a593Smuzhiyun 		rpmb_frame->request = cpu_to_be16(RPMB_REQ_WRITE_DATA);
339*4882a593Smuzhiyun 		rpmb_frame_vrify->request = cpu_to_be16(RPMB_REQ_WRITE_DATA);
340*4882a593Smuzhiyun 		if (i == temp) {
341*4882a593Smuzhiyun 			rpmb_hmac
342*4882a593Smuzhiyun 				(key, (unsigned char *)rpmb_frame_data_verify,
343*4882a593Smuzhiyun 				284 * cnt, rpmb_frame->mac);
344*4882a593Smuzhiyun 		}
345*4882a593Smuzhiyun 	}
346*4882a593Smuzhiyun 	if (mmc_rpmb_request(mmc, rpmb_frame_data, cnt, true))
347*4882a593Smuzhiyun 		return -1;
348*4882a593Smuzhiyun 
349*4882a593Smuzhiyun 	if (mmc_rpmb_status(mmc, RPMB_RESP_WRITE_DATA))
350*4882a593Smuzhiyun 		return -1;
351*4882a593Smuzhiyun 	return cnt;
352*4882a593Smuzhiyun }
353*4882a593Smuzhiyun 
read_counter(struct mmc * mmc,struct s_rpmb * requestpackets)354*4882a593Smuzhiyun int read_counter(struct mmc *mmc, struct s_rpmb *requestpackets)
355*4882a593Smuzhiyun {
356*4882a593Smuzhiyun 	if (mmc_rpmb_request(mmc, requestpackets, 1, false))
357*4882a593Smuzhiyun 		return -1;
358*4882a593Smuzhiyun 
359*4882a593Smuzhiyun 	if (mmc_rpmb_response(mmc, requestpackets, RPMB_RESP_WCOUNTER, 1))
360*4882a593Smuzhiyun 		return -1;
361*4882a593Smuzhiyun 
362*4882a593Smuzhiyun 	return 0;
363*4882a593Smuzhiyun }
364*4882a593Smuzhiyun 
program_key(struct mmc * mmc,struct s_rpmb * requestpackets)365*4882a593Smuzhiyun int program_key(struct mmc *mmc, struct s_rpmb *requestpackets)
366*4882a593Smuzhiyun {
367*4882a593Smuzhiyun 	if (mmc_rpmb_request(mmc, requestpackets, 1, true))
368*4882a593Smuzhiyun 		return -1;
369*4882a593Smuzhiyun 
370*4882a593Smuzhiyun 	memset(requestpackets, 0, sizeof(struct s_rpmb));
371*4882a593Smuzhiyun 
372*4882a593Smuzhiyun 	requestpackets->request = cpu_to_be16(RPMB_REQ_STATUS);
373*4882a593Smuzhiyun 
374*4882a593Smuzhiyun 	if (mmc_rpmb_request(mmc, requestpackets, 1, false))
375*4882a593Smuzhiyun 		return -1;
376*4882a593Smuzhiyun 
377*4882a593Smuzhiyun 	return mmc_rpmb_response(mmc, requestpackets, RPMB_RESP_KEY, 1);
378*4882a593Smuzhiyun }
379*4882a593Smuzhiyun 
authenticated_read(struct mmc * mmc,struct s_rpmb * requestpackets,uint16_t block_count)380*4882a593Smuzhiyun int authenticated_read(struct mmc *mmc,
381*4882a593Smuzhiyun 	struct s_rpmb *requestpackets, uint16_t block_count)
382*4882a593Smuzhiyun {
383*4882a593Smuzhiyun 	if (mmc_rpmb_request(mmc, requestpackets, 1, false))
384*4882a593Smuzhiyun 		return -1;
385*4882a593Smuzhiyun 
386*4882a593Smuzhiyun 	if (mmc_rpmb_response
387*4882a593Smuzhiyun 		(mmc, requestpackets, RPMB_RESP_READ_DATA, block_count))
388*4882a593Smuzhiyun 		return -1;
389*4882a593Smuzhiyun 
390*4882a593Smuzhiyun 	return 0;
391*4882a593Smuzhiyun }
392*4882a593Smuzhiyun 
authenticated_write(struct mmc * mmc,struct s_rpmb * requestpackets)393*4882a593Smuzhiyun int authenticated_write(struct mmc *mmc, struct s_rpmb *requestpackets)
394*4882a593Smuzhiyun {
395*4882a593Smuzhiyun 	if (mmc_rpmb_request(mmc, requestpackets, 1, true))
396*4882a593Smuzhiyun 		return -1;
397*4882a593Smuzhiyun 
398*4882a593Smuzhiyun 	memset(requestpackets, 0, sizeof(struct s_rpmb));
399*4882a593Smuzhiyun 
400*4882a593Smuzhiyun 	requestpackets->request = cpu_to_be16(RPMB_REQ_STATUS);
401*4882a593Smuzhiyun 
402*4882a593Smuzhiyun 	if (mmc_rpmb_request(mmc, requestpackets, 1, false))
403*4882a593Smuzhiyun 		return -1;
404*4882a593Smuzhiyun 
405*4882a593Smuzhiyun 	return mmc_rpmb_response(mmc, requestpackets, RPMB_RESP_WRITE_DATA, 1);
406*4882a593Smuzhiyun }
407*4882a593Smuzhiyun 
408