xref: /rk3399_ARM-atf/drivers/fwu/fwu.c (revision d2566cfb896672ea07c31c37e7acd9ef77abc4fb)
10ec3ac60SManish V Badarkhe /*
2aae7c96dSSebastien Pasdeloup  * Copyright (c) 2021-2022, Arm Limited. All rights reserved.
30ec3ac60SManish V Badarkhe  *
40ec3ac60SManish V Badarkhe  * SPDX-License-Identifier: BSD-3-Clause
50ec3ac60SManish V Badarkhe  */
60ec3ac60SManish V Badarkhe 
70ec3ac60SManish V Badarkhe #include <assert.h>
80ec3ac60SManish V Badarkhe 
90ec3ac60SManish V Badarkhe #include <common/debug.h>
10c885d5c8SManish V Badarkhe #include <common/tf_crc32.h>
110ec3ac60SManish V Badarkhe #include <common/tbbr/tbbr_img_def.h>
120ec3ac60SManish V Badarkhe #include <drivers/fwu/fwu.h>
130ec3ac60SManish V Badarkhe #include <drivers/fwu/fwu_metadata.h>
140ec3ac60SManish V Badarkhe #include <drivers/io/io_storage.h>
150ec3ac60SManish V Badarkhe 
160ec3ac60SManish V Badarkhe #include <plat/common/platform.h>
170ec3ac60SManish V Badarkhe 
180ec3ac60SManish V Badarkhe /*
190ec3ac60SManish V Badarkhe  * Assert that crc_32 is the first member of fwu_metadata structure.
200ec3ac60SManish V Badarkhe  * It avoids accessing data outside of the metadata structure during
210ec3ac60SManish V Badarkhe  * CRC32 computation if the crc_32 field gets moved due the structure
220ec3ac60SManish V Badarkhe  * member(s) addition in the future.
230ec3ac60SManish V Badarkhe  */
240ec3ac60SManish V Badarkhe CASSERT((offsetof(struct fwu_metadata, crc_32) == 0),
250ec3ac60SManish V Badarkhe 	crc_32_must_be_first_member_of_structure);
260ec3ac60SManish V Badarkhe 
27*d2566cfbSSughosh Ganu /*
28*d2566cfbSSughosh Ganu  * Ensure that the NR_OF_FW_BANKS selected by the platform is not
29*d2566cfbSSughosh Ganu  * zero and not greater than the maximum number of banks allowed
30*d2566cfbSSughosh Ganu  * by the specification.
31*d2566cfbSSughosh Ganu  */
32*d2566cfbSSughosh Ganu CASSERT((NR_OF_FW_BANKS > 0) && (NR_OF_FW_BANKS <= NR_OF_MAX_FW_BANKS),
33*d2566cfbSSughosh Ganu 	assert_fwu_num_banks_invalid_value);
34*d2566cfbSSughosh Ganu 
35*d2566cfbSSughosh Ganu #define FWU_METADATA_VERSION		2U
36*d2566cfbSSughosh Ganu #define FWU_FW_STORE_DESC_OFFSET	0x20U
37*d2566cfbSSughosh Ganu 
380ec3ac60SManish V Badarkhe static struct fwu_metadata metadata;
39aae7c96dSSebastien Pasdeloup static bool is_metadata_initialized __unused;
400ec3ac60SManish V Badarkhe 
410ec3ac60SManish V Badarkhe /*******************************************************************************
420ec3ac60SManish V Badarkhe  * Compute CRC32 of the FWU metadata, and check it against the CRC32 value
430ec3ac60SManish V Badarkhe  * present in the FWU metadata.
440ec3ac60SManish V Badarkhe  *
450ec3ac60SManish V Badarkhe  * return -1 on error, otherwise 0
460ec3ac60SManish V Badarkhe  ******************************************************************************/
470ec3ac60SManish V Badarkhe static int fwu_metadata_crc_check(void)
480ec3ac60SManish V Badarkhe {
490ec3ac60SManish V Badarkhe 	unsigned char *data = (unsigned char *)&metadata;
500ec3ac60SManish V Badarkhe 
51c885d5c8SManish V Badarkhe 	uint32_t calc_crc = tf_crc32(0U, data + sizeof(metadata.crc_32),
520ec3ac60SManish V Badarkhe 				     (sizeof(metadata) -
530ec3ac60SManish V Badarkhe 				      sizeof(metadata.crc_32)));
540ec3ac60SManish V Badarkhe 
550ec3ac60SManish V Badarkhe 	if (metadata.crc_32 != calc_crc) {
560ec3ac60SManish V Badarkhe 		return -1;
570ec3ac60SManish V Badarkhe 	}
580ec3ac60SManish V Badarkhe 
590ec3ac60SManish V Badarkhe 	return 0;
600ec3ac60SManish V Badarkhe }
610ec3ac60SManish V Badarkhe 
620ec3ac60SManish V Badarkhe /*******************************************************************************
630ec3ac60SManish V Badarkhe  * Check the sanity of FWU metadata.
640ec3ac60SManish V Badarkhe  *
65*d2566cfbSSughosh Ganu  * return -EINVAL on error, otherwise 0
660ec3ac60SManish V Badarkhe  ******************************************************************************/
670ec3ac60SManish V Badarkhe static int fwu_metadata_sanity_check(void)
680ec3ac60SManish V Badarkhe {
69*d2566cfbSSughosh Ganu 	if (metadata.version != FWU_METADATA_VERSION) {
70*d2566cfbSSughosh Ganu 		WARN("Incorrect FWU Metadata version of %u\n",
71*d2566cfbSSughosh Ganu 		     metadata.version);
72*d2566cfbSSughosh Ganu 		return -EINVAL;
730ec3ac60SManish V Badarkhe 	}
740ec3ac60SManish V Badarkhe 
75*d2566cfbSSughosh Ganu 	if (metadata.active_index >= NR_OF_FW_BANKS) {
76*d2566cfbSSughosh Ganu 		WARN("Active Index value(%u) greater than the configured value(%d)",
77*d2566cfbSSughosh Ganu 		     metadata.active_index, NR_OF_FW_BANKS);
78*d2566cfbSSughosh Ganu 		return -EINVAL;
79*d2566cfbSSughosh Ganu 	}
80*d2566cfbSSughosh Ganu 
81*d2566cfbSSughosh Ganu 	if (metadata.previous_active_index >= NR_OF_FW_BANKS) {
82*d2566cfbSSughosh Ganu 		WARN("Previous Active Index value(%u) greater than the configured value(%d)",
83*d2566cfbSSughosh Ganu 		     metadata.previous_active_index, NR_OF_FW_BANKS);
84*d2566cfbSSughosh Ganu 		return -EINVAL;
85*d2566cfbSSughosh Ganu 	}
86*d2566cfbSSughosh Ganu 
87*d2566cfbSSughosh Ganu #if PSA_FWU_METADATA_FW_STORE_DESC
88*d2566cfbSSughosh Ganu 	if (metadata.fw_desc.num_banks != NR_OF_FW_BANKS) {
89*d2566cfbSSughosh Ganu 		WARN("Number of Banks(%u) in FWU Metadata different from the configured value(%d)",
90*d2566cfbSSughosh Ganu 		     metadata.fw_desc.num_banks, NR_OF_FW_BANKS);
91*d2566cfbSSughosh Ganu 		return -EINVAL;
92*d2566cfbSSughosh Ganu 	}
93*d2566cfbSSughosh Ganu 
94*d2566cfbSSughosh Ganu 	if (metadata.fw_desc.num_images != NR_OF_IMAGES_IN_FW_BANK) {
95*d2566cfbSSughosh Ganu 		WARN("Number of Images(%u) in FWU Metadata different from the configured value(%d)",
96*d2566cfbSSughosh Ganu 		     metadata.fw_desc.num_images, NR_OF_IMAGES_IN_FW_BANK);
97*d2566cfbSSughosh Ganu 		return -EINVAL;
98*d2566cfbSSughosh Ganu 	}
99*d2566cfbSSughosh Ganu 
100*d2566cfbSSughosh Ganu 	if (metadata.desc_offset != FWU_FW_STORE_DESC_OFFSET) {
101*d2566cfbSSughosh Ganu 		WARN("Descriptor Offset(0x%x) in the FWU Metadata not equal to 0x20\n",
102*d2566cfbSSughosh Ganu 		     metadata.desc_offset);
103*d2566cfbSSughosh Ganu 		return -EINVAL;
104*d2566cfbSSughosh Ganu 	}
105*d2566cfbSSughosh Ganu #else
106*d2566cfbSSughosh Ganu 	if (metadata.desc_offset != 0U) {
107*d2566cfbSSughosh Ganu 		WARN("Descriptor offset has non zero value of 0x%x\n",
108*d2566cfbSSughosh Ganu 		     metadata.desc_offset);
109*d2566cfbSSughosh Ganu 		return -EINVAL;
110*d2566cfbSSughosh Ganu 	}
111*d2566cfbSSughosh Ganu #endif
112*d2566cfbSSughosh Ganu 
1130ec3ac60SManish V Badarkhe 	return 0;
1140ec3ac60SManish V Badarkhe }
1150ec3ac60SManish V Badarkhe 
1160ec3ac60SManish V Badarkhe /*******************************************************************************
1170ec3ac60SManish V Badarkhe  * Verify and load specified FWU metadata image to local FWU metadata structure.
1180ec3ac60SManish V Badarkhe  *
1190ec3ac60SManish V Badarkhe  * @image_id: FWU metadata image id (either FWU_METADATA_IMAGE_ID or
1200ec3ac60SManish V Badarkhe  *				     BKUP_FWU_METADATA_IMAGE_ID)
1210ec3ac60SManish V Badarkhe  *
1220ec3ac60SManish V Badarkhe  * return a negative value on error, otherwise 0
1230ec3ac60SManish V Badarkhe  ******************************************************************************/
1240ec3ac60SManish V Badarkhe static int fwu_metadata_load(unsigned int image_id)
1250ec3ac60SManish V Badarkhe {
1260ec3ac60SManish V Badarkhe 	int result;
1270ec3ac60SManish V Badarkhe 	uintptr_t dev_handle, image_handle, image_spec;
1280ec3ac60SManish V Badarkhe 	size_t bytes_read;
1290ec3ac60SManish V Badarkhe 
1300ec3ac60SManish V Badarkhe 	assert((image_id == FWU_METADATA_IMAGE_ID) ||
1310ec3ac60SManish V Badarkhe 	       (image_id == BKUP_FWU_METADATA_IMAGE_ID));
1320ec3ac60SManish V Badarkhe 
1330ec3ac60SManish V Badarkhe 	result = plat_fwu_set_metadata_image_source(image_id,
1340ec3ac60SManish V Badarkhe 						    &dev_handle,
1350ec3ac60SManish V Badarkhe 						    &image_spec);
1360ec3ac60SManish V Badarkhe 	if (result != 0) {
1370ec3ac60SManish V Badarkhe 		WARN("Failed to set reference to image id=%u (%i)\n",
1380ec3ac60SManish V Badarkhe 		     image_id, result);
1390ec3ac60SManish V Badarkhe 		return result;
1400ec3ac60SManish V Badarkhe 	}
1410ec3ac60SManish V Badarkhe 
1420ec3ac60SManish V Badarkhe 	result = io_open(dev_handle, image_spec, &image_handle);
1430ec3ac60SManish V Badarkhe 	if (result != 0) {
1440ec3ac60SManish V Badarkhe 		WARN("Failed to load image id id=%u (%i)\n",
1450ec3ac60SManish V Badarkhe 		     image_id, result);
1460ec3ac60SManish V Badarkhe 		return result;
1470ec3ac60SManish V Badarkhe 	}
1480ec3ac60SManish V Badarkhe 
1490ec3ac60SManish V Badarkhe 	result = io_read(image_handle, (uintptr_t)&metadata,
1500ec3ac60SManish V Badarkhe 			 sizeof(struct fwu_metadata), &bytes_read);
1510ec3ac60SManish V Badarkhe 
1520ec3ac60SManish V Badarkhe 	if (result != 0) {
1530ec3ac60SManish V Badarkhe 		WARN("Failed to read image id=%u (%i)\n", image_id, result);
1540ec3ac60SManish V Badarkhe 		goto exit;
1550ec3ac60SManish V Badarkhe 	}
1560ec3ac60SManish V Badarkhe 
1570ec3ac60SManish V Badarkhe 	if (sizeof(struct fwu_metadata) != bytes_read) {
1580ec3ac60SManish V Badarkhe 		/* return -1 in case of partial/no read */
1590ec3ac60SManish V Badarkhe 		result = -1;
1600ec3ac60SManish V Badarkhe 		WARN("Read bytes (%zu) instead of expected (%zu) bytes\n",
1610ec3ac60SManish V Badarkhe 		     bytes_read, sizeof(struct fwu_metadata));
1620ec3ac60SManish V Badarkhe 		goto exit;
1630ec3ac60SManish V Badarkhe 	}
1640ec3ac60SManish V Badarkhe 
1650ec3ac60SManish V Badarkhe 	/* sanity check on loaded parameters */
1660ec3ac60SManish V Badarkhe 	result = fwu_metadata_sanity_check();
1670ec3ac60SManish V Badarkhe 	if (result != 0) {
1680ec3ac60SManish V Badarkhe 		WARN("Sanity %s\n", "check failed on FWU metadata");
1690ec3ac60SManish V Badarkhe 		goto exit;
1700ec3ac60SManish V Badarkhe 	}
1710ec3ac60SManish V Badarkhe 
1720ec3ac60SManish V Badarkhe 	/* CRC check on loaded parameters */
1730ec3ac60SManish V Badarkhe 	result = fwu_metadata_crc_check();
1740ec3ac60SManish V Badarkhe 	if (result != 0) {
1750ec3ac60SManish V Badarkhe 		WARN("CRC %s\n", "check failed on FWU metadata");
1760ec3ac60SManish V Badarkhe 	}
1770ec3ac60SManish V Badarkhe 
1780ec3ac60SManish V Badarkhe exit:
1790ec3ac60SManish V Badarkhe 	(void)io_close(image_handle);
1800ec3ac60SManish V Badarkhe 
1810ec3ac60SManish V Badarkhe 	return result;
1820ec3ac60SManish V Badarkhe }
1830ec3ac60SManish V Badarkhe 
1840ec3ac60SManish V Badarkhe /*******************************************************************************
18556724d09SSughosh Ganu  * The platform can be in one of Valid, Invalid or Accepted states.
1860ec3ac60SManish V Badarkhe  *
18756724d09SSughosh Ganu  * Invalid - One or more images in the bank are corrupted, or partially
18856724d09SSughosh Ganu  *           overwritten. The bank is not to be used for booting.
18956724d09SSughosh Ganu  *
19056724d09SSughosh Ganu  * Valid - All images of the bank are valid but at least one image has not
19156724d09SSughosh Ganu  *         been accepted. This implies that the platform is in Trial State.
19256724d09SSughosh Ganu  *
19356724d09SSughosh Ganu  * Accepted - All images of the bank are valid and accepted.
19456724d09SSughosh Ganu  *
19556724d09SSughosh Ganu  * Returns the state of the current active bank
1960ec3ac60SManish V Badarkhe  ******************************************************************************/
19756724d09SSughosh Ganu uint32_t fwu_get_active_bank_state(void)
1980ec3ac60SManish V Badarkhe {
199aae7c96dSSebastien Pasdeloup 	assert(is_metadata_initialized);
2000ec3ac60SManish V Badarkhe 
20156724d09SSughosh Ganu 	return metadata.bank_state[metadata.active_index];
2020ec3ac60SManish V Badarkhe }
2030ec3ac60SManish V Badarkhe 
2049adce87eSSughosh Ganu const struct fwu_metadata *fwu_get_metadata(void)
2059adce87eSSughosh Ganu {
206aae7c96dSSebastien Pasdeloup 	assert(is_metadata_initialized);
2079adce87eSSughosh Ganu 
2089adce87eSSughosh Ganu 	return &metadata;
2099adce87eSSughosh Ganu }
2109adce87eSSughosh Ganu 
2110ec3ac60SManish V Badarkhe /*******************************************************************************
2120ec3ac60SManish V Badarkhe  * Load verified copy of FWU metadata image kept in the platform NV storage
2130ec3ac60SManish V Badarkhe  * into local FWU metadata structure.
2140ec3ac60SManish V Badarkhe  * Also, update platform I/O policies with the offset address and length of
2150ec3ac60SManish V Badarkhe  * firmware-updated images kept in the platform NV storage.
2160ec3ac60SManish V Badarkhe  ******************************************************************************/
2170ec3ac60SManish V Badarkhe void fwu_init(void)
2180ec3ac60SManish V Badarkhe {
2190ec3ac60SManish V Badarkhe 	/* Load FWU metadata which will be used to load the images in the
2200ec3ac60SManish V Badarkhe 	 * active bank as per PSA FWU specification
2210ec3ac60SManish V Badarkhe 	 */
2220ec3ac60SManish V Badarkhe 	int result = fwu_metadata_load(FWU_METADATA_IMAGE_ID);
2230ec3ac60SManish V Badarkhe 
2240ec3ac60SManish V Badarkhe 	if (result != 0) {
2250ec3ac60SManish V Badarkhe 		WARN("loading of FWU-Metadata failed, "
2260ec3ac60SManish V Badarkhe 		     "using Bkup-FWU-Metadata\n");
2270ec3ac60SManish V Badarkhe 
2280ec3ac60SManish V Badarkhe 		result = fwu_metadata_load(BKUP_FWU_METADATA_IMAGE_ID);
2290ec3ac60SManish V Badarkhe 		if (result != 0) {
2300ec3ac60SManish V Badarkhe 			ERROR("loading of Bkup-FWU-Metadata failed\n");
2310ec3ac60SManish V Badarkhe 			panic();
2320ec3ac60SManish V Badarkhe 		}
2330ec3ac60SManish V Badarkhe 	}
2340ec3ac60SManish V Badarkhe 
235aae7c96dSSebastien Pasdeloup 	is_metadata_initialized = true;
2360ec3ac60SManish V Badarkhe 
237aae7c96dSSebastien Pasdeloup 	plat_fwu_set_images_source(&metadata);
2380ec3ac60SManish V Badarkhe }
239