xref: /rk3399_ARM-atf/bl1/bl1_main.c (revision 01df3c14677db0eab68f088f2721542f88ea4004)
14f6ad66aSAchin Gupta /*
2e83b0cadSDan Handley  * Copyright (c) 2013-2014, ARM Limited and Contributors. All rights reserved.
34f6ad66aSAchin Gupta  *
44f6ad66aSAchin Gupta  * Redistribution and use in source and binary forms, with or without
54f6ad66aSAchin Gupta  * modification, are permitted provided that the following conditions are met:
64f6ad66aSAchin Gupta  *
74f6ad66aSAchin Gupta  * Redistributions of source code must retain the above copyright notice, this
84f6ad66aSAchin Gupta  * list of conditions and the following disclaimer.
94f6ad66aSAchin Gupta  *
104f6ad66aSAchin Gupta  * Redistributions in binary form must reproduce the above copyright notice,
114f6ad66aSAchin Gupta  * this list of conditions and the following disclaimer in the documentation
124f6ad66aSAchin Gupta  * and/or other materials provided with the distribution.
134f6ad66aSAchin Gupta  *
144f6ad66aSAchin Gupta  * Neither the name of ARM nor the names of its contributors may be used
154f6ad66aSAchin Gupta  * to endorse or promote products derived from this software without specific
164f6ad66aSAchin Gupta  * prior written permission.
174f6ad66aSAchin Gupta  *
184f6ad66aSAchin Gupta  * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS"
194f6ad66aSAchin Gupta  * AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
204f6ad66aSAchin Gupta  * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
214f6ad66aSAchin Gupta  * ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT HOLDER OR CONTRIBUTORS BE
224f6ad66aSAchin Gupta  * LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
234f6ad66aSAchin Gupta  * CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
244f6ad66aSAchin Gupta  * SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
254f6ad66aSAchin Gupta  * INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN
264f6ad66aSAchin Gupta  * CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
274f6ad66aSAchin Gupta  * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE
284f6ad66aSAchin Gupta  * POSSIBILITY OF SUCH DAMAGE.
294f6ad66aSAchin Gupta  */
304f6ad66aSAchin Gupta 
3197043ac9SDan Handley #include <arch.h>
324f6ad66aSAchin Gupta #include <arch_helpers.h>
3397043ac9SDan Handley #include <assert.h>
34*01df3c14SJuan Castillo #include <auth.h>
3597043ac9SDan Handley #include <bl_common.h>
364112bfa0SVikram Kanigiri #include <debug.h>
3797043ac9SDan Handley #include <platform.h>
385f0cdb05SDan Handley #include <platform_def.h>
395b827a8fSDan Handley #include "bl1_private.h"
404f6ad66aSAchin Gupta 
414f6ad66aSAchin Gupta /*******************************************************************************
4229fb905dSVikram Kanigiri  * Runs BL2 from the given entry point. It results in dropping the
4329fb905dSVikram Kanigiri  * exception level
4429fb905dSVikram Kanigiri  ******************************************************************************/
454112bfa0SVikram Kanigiri static void __dead2 bl1_run_bl2(entry_point_info_t *bl2_ep)
4629fb905dSVikram Kanigiri {
4729fb905dSVikram Kanigiri 	bl1_arch_next_el_setup();
4829fb905dSVikram Kanigiri 
4929fb905dSVikram Kanigiri 	/* Tell next EL what we want done */
5029fb905dSVikram Kanigiri 	bl2_ep->args.arg0 = RUN_IMAGE;
5129fb905dSVikram Kanigiri 
524112bfa0SVikram Kanigiri 	if (GET_SECURITY_STATE(bl2_ep->h.attr) == NON_SECURE)
534112bfa0SVikram Kanigiri 		change_security_state(GET_SECURITY_STATE(bl2_ep->h.attr));
5429fb905dSVikram Kanigiri 
5529fb905dSVikram Kanigiri 	write_spsr_el3(bl2_ep->spsr);
564112bfa0SVikram Kanigiri 	write_elr_el3(bl2_ep->pc);
5729fb905dSVikram Kanigiri 
5829fb905dSVikram Kanigiri 	eret(bl2_ep->args.arg0,
5929fb905dSVikram Kanigiri 		bl2_ep->args.arg1,
6029fb905dSVikram Kanigiri 		bl2_ep->args.arg2,
6129fb905dSVikram Kanigiri 		bl2_ep->args.arg3,
6229fb905dSVikram Kanigiri 		bl2_ep->args.arg4,
6329fb905dSVikram Kanigiri 		bl2_ep->args.arg5,
6429fb905dSVikram Kanigiri 		bl2_ep->args.arg6,
6529fb905dSVikram Kanigiri 		bl2_ep->args.arg7);
6629fb905dSVikram Kanigiri }
6729fb905dSVikram Kanigiri 
688f55dfb4SSandrine Bailleux /*******************************************************************************
698f55dfb4SSandrine Bailleux  * The next function has a weak definition. Platform specific code can override
708f55dfb4SSandrine Bailleux  * it if it wishes to.
718f55dfb4SSandrine Bailleux  ******************************************************************************/
728f55dfb4SSandrine Bailleux #pragma weak bl1_init_bl2_mem_layout
738f55dfb4SSandrine Bailleux 
748f55dfb4SSandrine Bailleux /*******************************************************************************
758f55dfb4SSandrine Bailleux  * Function that takes a memory layout into which BL2 has been loaded and
768f55dfb4SSandrine Bailleux  * populates a new memory layout for BL2 that ensures that BL1's data sections
778f55dfb4SSandrine Bailleux  * resident in secure RAM are not visible to BL2.
788f55dfb4SSandrine Bailleux  ******************************************************************************/
798f55dfb4SSandrine Bailleux void bl1_init_bl2_mem_layout(const meminfo_t *bl1_mem_layout,
808f55dfb4SSandrine Bailleux 			     meminfo_t *bl2_mem_layout)
818f55dfb4SSandrine Bailleux {
828f55dfb4SSandrine Bailleux 	const size_t bl1_size = BL1_RAM_LIMIT - BL1_RAM_BASE;
838f55dfb4SSandrine Bailleux 
848f55dfb4SSandrine Bailleux 	assert(bl1_mem_layout != NULL);
858f55dfb4SSandrine Bailleux 	assert(bl2_mem_layout != NULL);
868f55dfb4SSandrine Bailleux 
878f55dfb4SSandrine Bailleux 	/* Check that BL1's memory is lying outside of the free memory */
888f55dfb4SSandrine Bailleux 	assert((BL1_RAM_LIMIT <= bl1_mem_layout->free_base) ||
898f55dfb4SSandrine Bailleux 	       (BL1_RAM_BASE >= bl1_mem_layout->free_base + bl1_mem_layout->free_size));
908f55dfb4SSandrine Bailleux 
918f55dfb4SSandrine Bailleux 	/* Remove BL1 RW data from the scope of memory visible to BL2 */
928f55dfb4SSandrine Bailleux 	*bl2_mem_layout = *bl1_mem_layout;
938f55dfb4SSandrine Bailleux 	reserve_mem(&bl2_mem_layout->total_base,
948f55dfb4SSandrine Bailleux 		    &bl2_mem_layout->total_size,
958f55dfb4SSandrine Bailleux 		    BL1_RAM_BASE,
968f55dfb4SSandrine Bailleux 		    bl1_size);
978f55dfb4SSandrine Bailleux 
988f55dfb4SSandrine Bailleux 	flush_dcache_range((unsigned long)bl2_mem_layout, sizeof(meminfo_t));
998f55dfb4SSandrine Bailleux }
10029fb905dSVikram Kanigiri 
10129fb905dSVikram Kanigiri /*******************************************************************************
1024f6ad66aSAchin Gupta  * Function to perform late architectural and platform specific initialization.
1034f6ad66aSAchin Gupta  * It also locates and loads the BL2 raw binary image in the trusted DRAM. Only
1044f6ad66aSAchin Gupta  * called by the primary cpu after a cold boot.
1054f6ad66aSAchin Gupta  * TODO: Add support for alternative image load mechanism e.g using virtio/elf
1064f6ad66aSAchin Gupta  * loader etc.
1074f6ad66aSAchin Gupta   ******************************************************************************/
1084f6ad66aSAchin Gupta void bl1_main(void)
1094f6ad66aSAchin Gupta {
1106ad2e461SDan Handley 	/* Announce our arrival */
1116ad2e461SDan Handley 	NOTICE(FIRMWARE_WELCOME_STR);
1126ad2e461SDan Handley 	NOTICE("BL1: %s\n", version_string);
1136ad2e461SDan Handley 	NOTICE("BL1: %s\n", build_message);
1146ad2e461SDan Handley 
1156ad2e461SDan Handley 	INFO("BL1: RAM 0x%lx - 0x%lx\n", BL1_RAM_BASE, BL1_RAM_LIMIT);
1166ad2e461SDan Handley 
11740a6f647SJames Morrissey #if DEBUG
1186ba0b6d6SVikram Kanigiri 	unsigned long sctlr_el3 = read_sctlr_el3();
11940a6f647SJames Morrissey #endif
1204112bfa0SVikram Kanigiri 	image_info_t bl2_image_info = { {0} };
1214112bfa0SVikram Kanigiri 	entry_point_info_t bl2_ep = { {0} };
122fb037bfbSDan Handley 	meminfo_t *bl1_tzram_layout;
123fb037bfbSDan Handley 	meminfo_t *bl2_tzram_layout = 0x0;
1244112bfa0SVikram Kanigiri 	int err;
1254f6ad66aSAchin Gupta 
1264f6ad66aSAchin Gupta 	/*
1274f6ad66aSAchin Gupta 	 * Ensure that MMU/Caches and coherency are turned on
1284f6ad66aSAchin Gupta 	 */
1294f6ad66aSAchin Gupta 	assert(sctlr_el3 | SCTLR_M_BIT);
1304f6ad66aSAchin Gupta 	assert(sctlr_el3 | SCTLR_C_BIT);
1314f6ad66aSAchin Gupta 	assert(sctlr_el3 | SCTLR_I_BIT);
1324f6ad66aSAchin Gupta 
1334f6ad66aSAchin Gupta 	/* Perform remaining generic architectural setup from EL3 */
1344f6ad66aSAchin Gupta 	bl1_arch_setup();
1354f6ad66aSAchin Gupta 
1364f6ad66aSAchin Gupta 	/* Perform platform setup in BL1. */
1374f6ad66aSAchin Gupta 	bl1_platform_setup();
1384f6ad66aSAchin Gupta 
1394112bfa0SVikram Kanigiri 	SET_PARAM_HEAD(&bl2_image_info, PARAM_IMAGE_BINARY, VERSION_1, 0);
1404112bfa0SVikram Kanigiri 	SET_PARAM_HEAD(&bl2_ep, PARAM_EP, VERSION_1, 0);
1414112bfa0SVikram Kanigiri 
1428f55dfb4SSandrine Bailleux 	/* Find out how much free trusted ram remains after BL1 load */
143ee12f6f7SSandrine Bailleux 	bl1_tzram_layout = bl1_plat_sec_mem_layout();
1448f55dfb4SSandrine Bailleux 
145*01df3c14SJuan Castillo #if TRUSTED_BOARD_BOOT
146*01df3c14SJuan Castillo 	/* Initialize authentication module */
147*01df3c14SJuan Castillo 	auth_init();
148*01df3c14SJuan Castillo 
149*01df3c14SJuan Castillo 	/*
150*01df3c14SJuan Castillo 	 * Load the BL2 certificate into the BL2 region. This region will be
151*01df3c14SJuan Castillo 	 * overwritten by the image, so the authentication module is responsible
152*01df3c14SJuan Castillo 	 * for storing the relevant data from the certificate (keys, hashes,
153*01df3c14SJuan Castillo 	 * etc.) so it can be used later.
154*01df3c14SJuan Castillo 	 */
155*01df3c14SJuan Castillo 	err = load_image(bl1_tzram_layout,
156*01df3c14SJuan Castillo 			 BL2_CERT_NAME,
157*01df3c14SJuan Castillo 			 BL2_BASE,
158*01df3c14SJuan Castillo 			 &bl2_image_info,
159*01df3c14SJuan Castillo 			 NULL);
160*01df3c14SJuan Castillo 	if (err) {
161*01df3c14SJuan Castillo 		ERROR("Failed to load BL2 certificate.\n");
162*01df3c14SJuan Castillo 		panic();
163*01df3c14SJuan Castillo 	}
164*01df3c14SJuan Castillo 
165*01df3c14SJuan Castillo 	err = auth_verify_obj(AUTH_BL2_IMG_CERT, bl2_image_info.image_base,
166*01df3c14SJuan Castillo 			bl2_image_info.image_size);
167*01df3c14SJuan Castillo 	if (err) {
168*01df3c14SJuan Castillo 		ERROR("Failed to validate BL2 certificate.\n");
169*01df3c14SJuan Castillo 		panic();
170*01df3c14SJuan Castillo 	}
171*01df3c14SJuan Castillo #endif /* TRUSTED_BOARD_BOOT */
172*01df3c14SJuan Castillo 
1738f55dfb4SSandrine Bailleux 	/* Load the BL2 image */
1744112bfa0SVikram Kanigiri 	err = load_image(bl1_tzram_layout,
1758f55dfb4SSandrine Bailleux 			 BL2_IMAGE_NAME,
1764112bfa0SVikram Kanigiri 			 BL2_BASE,
1774112bfa0SVikram Kanigiri 			 &bl2_image_info,
1784112bfa0SVikram Kanigiri 			 &bl2_ep);
1794112bfa0SVikram Kanigiri 	if (err) {
1804112bfa0SVikram Kanigiri 		/*
1814112bfa0SVikram Kanigiri 		 * TODO: print failure to load BL2 but also add a tzwdog timer
1824112bfa0SVikram Kanigiri 		 * which will reset the system eventually.
1834112bfa0SVikram Kanigiri 		 */
1846ad2e461SDan Handley 		ERROR("Failed to load BL2 firmware.\n");
1854112bfa0SVikram Kanigiri 		panic();
1864112bfa0SVikram Kanigiri 	}
187*01df3c14SJuan Castillo 
188*01df3c14SJuan Castillo #if TRUSTED_BOARD_BOOT
189*01df3c14SJuan Castillo 	err = auth_verify_obj(AUTH_BL2_IMG, bl2_image_info.image_base,
190*01df3c14SJuan Castillo 				bl2_image_info.image_size);
191*01df3c14SJuan Castillo 	if (err) {
192*01df3c14SJuan Castillo 		ERROR("Failed to validate BL2 image.\n");
193*01df3c14SJuan Castillo 		panic();
194*01df3c14SJuan Castillo 	}
195*01df3c14SJuan Castillo 
196*01df3c14SJuan Castillo 	/* After working with data, invalidate the data cache */
197*01df3c14SJuan Castillo 	inv_dcache_range(bl2_image_info.image_base,
198*01df3c14SJuan Castillo 			(size_t)bl2_image_info.image_size);
199*01df3c14SJuan Castillo #endif /* TRUSTED_BOARD_BOOT */
200*01df3c14SJuan Castillo 
2014f6ad66aSAchin Gupta 	/*
2024f6ad66aSAchin Gupta 	 * Create a new layout of memory for BL2 as seen by BL1 i.e.
2034f6ad66aSAchin Gupta 	 * tell it the amount of total and free memory available.
2044f6ad66aSAchin Gupta 	 * This layout is created at the first free address visible
2054f6ad66aSAchin Gupta 	 * to BL2. BL2 will read the memory layout before using its
2064f6ad66aSAchin Gupta 	 * memory for other purposes.
2074f6ad66aSAchin Gupta 	 */
208fb037bfbSDan Handley 	bl2_tzram_layout = (meminfo_t *) bl1_tzram_layout->free_base;
2098f55dfb4SSandrine Bailleux 	bl1_init_bl2_mem_layout(bl1_tzram_layout, bl2_tzram_layout);
2104f6ad66aSAchin Gupta 
2114112bfa0SVikram Kanigiri 	bl1_plat_set_bl2_ep_info(&bl2_image_info, &bl2_ep);
21229fb905dSVikram Kanigiri 	bl2_ep.args.arg1 = (unsigned long)bl2_tzram_layout;
2136ad2e461SDan Handley 	NOTICE("BL1: Booting BL2\n");
2146ad2e461SDan Handley 	INFO("BL1: BL2 address = 0x%llx\n",
2154112bfa0SVikram Kanigiri 		(unsigned long long) bl2_ep.pc);
2166ad2e461SDan Handley 	INFO("BL1: BL2 spsr = 0x%x\n", bl2_ep.spsr);
2176ad2e461SDan Handley 	VERBOSE("BL1: BL2 memory layout address = 0x%llx\n",
2184f6ad66aSAchin Gupta 		(unsigned long long) bl2_tzram_layout);
2196ad2e461SDan Handley 
22029fb905dSVikram Kanigiri 	bl1_run_bl2(&bl2_ep);
2214f6ad66aSAchin Gupta 
2224f6ad66aSAchin Gupta 	return;
2234f6ad66aSAchin Gupta }
2244f6ad66aSAchin Gupta 
2254f6ad66aSAchin Gupta /*******************************************************************************
2264f6ad66aSAchin Gupta  * Temporary function to print the fact that BL2 has done its job and BL31 is
2274f6ad66aSAchin Gupta  * about to be loaded. This is needed as long as printfs cannot be used
2284f6ad66aSAchin Gupta  ******************************************************************************/
2294112bfa0SVikram Kanigiri void display_boot_progress(entry_point_info_t *bl31_ep_info)
2304f6ad66aSAchin Gupta {
2316ad2e461SDan Handley 	NOTICE("BL1: Booting BL3-1\n");
2326ad2e461SDan Handley 	INFO("BL1: BL3-1 address = 0x%llx\n",
2336ad2e461SDan Handley 		(unsigned long long)bl31_ep_info->pc);
2346ad2e461SDan Handley 	INFO("BL1: BL3-1 spsr = 0x%llx\n",
2356ad2e461SDan Handley 		(unsigned long long)bl31_ep_info->spsr);
2366ad2e461SDan Handley 	INFO("BL1: BL3-1 params address = 0x%llx\n",
23729fb905dSVikram Kanigiri 		(unsigned long long)bl31_ep_info->args.arg0);
2386ad2e461SDan Handley 	INFO("BL1: BL3-1 plat params address = 0x%llx\n",
2394112bfa0SVikram Kanigiri 		(unsigned long long)bl31_ep_info->args.arg1);
2404f6ad66aSAchin Gupta }
241