1cb2c4f93SYing-Chun Liu (PaulLiu) /* 20d81b96eSHarrison Mutai * Copyright (c) 2022-2025, Arm Limited. All rights reserved. 3cb2c4f93SYing-Chun Liu (PaulLiu) * Copyright (c) 2022, Linaro. 4cb2c4f93SYing-Chun Liu (PaulLiu) * 5cb2c4f93SYing-Chun Liu (PaulLiu) * SPDX-License-Identifier: BSD-3-Clause 6cb2c4f93SYing-Chun Liu (PaulLiu) */ 7cb2c4f93SYing-Chun Liu (PaulLiu) 8cb2c4f93SYing-Chun Liu (PaulLiu) #include <string.h> 9cb2c4f93SYing-Chun Liu (PaulLiu) 10cb2c4f93SYing-Chun Liu (PaulLiu) #include <plat/arm/common/plat_arm.h> 11cb2c4f93SYing-Chun Liu (PaulLiu) 12*b67e9846SHarrison Mutai #include <drivers/auth/crypto_mod.h> 13*b67e9846SHarrison Mutai #include <drivers/measured_boot/metadata.h> 14*b67e9846SHarrison Mutai #include <event_measure.h> 15*b67e9846SHarrison Mutai #include <event_print.h> 16*b67e9846SHarrison Mutai 17*b67e9846SHarrison Mutai #include "./include/imx8m_measured_boot.h" 18*b67e9846SHarrison Mutai 19cb2c4f93SYing-Chun Liu (PaulLiu) /* Event Log data */ 20cb2c4f93SYing-Chun Liu (PaulLiu) static uint8_t event_log[PLAT_IMX_EVENT_LOG_MAX_SIZE]; 21*b67e9846SHarrison Mutai static const struct event_log_hash_info crypto_hash_info = { 22*b67e9846SHarrison Mutai .func = crypto_mod_calc_hash, 23*b67e9846SHarrison Mutai .ids = (const uint32_t[]){ CRYPTO_MD_ID }, 24*b67e9846SHarrison Mutai .count = 1U, 25*b67e9846SHarrison Mutai }; 26cb2c4f93SYing-Chun Liu (PaulLiu) 27cb2c4f93SYing-Chun Liu (PaulLiu) /* FVP table with platform specific image IDs, names and PCRs */ 28cb2c4f93SYing-Chun Liu (PaulLiu) static const event_log_metadata_t imx8m_event_log_metadata[] = { 29c6b204ccSTamas Ban { BL31_IMAGE_ID, MBOOT_BL31_IMAGE_STRING, PCR_0 }, 30c6b204ccSTamas Ban { BL32_IMAGE_ID, MBOOT_BL32_IMAGE_STRING, PCR_0 }, 31c6b204ccSTamas Ban { BL32_EXTRA1_IMAGE_ID, MBOOT_BL32_EXTRA1_IMAGE_STRING, PCR_0 }, 32c6b204ccSTamas Ban { BL32_EXTRA2_IMAGE_ID, MBOOT_BL32_EXTRA2_IMAGE_STRING, PCR_0 }, 33c6b204ccSTamas Ban { BL33_IMAGE_ID, MBOOT_BL33_IMAGE_STRING, PCR_0 }, 34cb2c4f93SYing-Chun Liu (PaulLiu) { EVLOG_INVALID_ID, NULL, (unsigned int)(-1) } /* Terminator */ 35cb2c4f93SYing-Chun Liu (PaulLiu) }; 36cb2c4f93SYing-Chun Liu (PaulLiu) 37cb2c4f93SYing-Chun Liu (PaulLiu) int plat_mboot_measure_image(unsigned int image_id, image_info_t *image_data) 38cb2c4f93SYing-Chun Liu (PaulLiu) { 39cb2c4f93SYing-Chun Liu (PaulLiu) /* Calculate image hash and record data in Event Log */ 40cb2c4f93SYing-Chun Liu (PaulLiu) int err = event_log_measure_and_record(image_data->image_base, 41cb2c4f93SYing-Chun Liu (PaulLiu) image_data->image_size, 42de10522aSManish V Badarkhe image_id, 43de10522aSManish V Badarkhe imx8m_event_log_metadata); 44cb2c4f93SYing-Chun Liu (PaulLiu) if (err != 0) { 45cb2c4f93SYing-Chun Liu (PaulLiu) ERROR("%s%s image id %u (%i)\n", 46cb2c4f93SYing-Chun Liu (PaulLiu) "Failed to ", "record", image_id, err); 47cb2c4f93SYing-Chun Liu (PaulLiu) return err; 48cb2c4f93SYing-Chun Liu (PaulLiu) } 49cb2c4f93SYing-Chun Liu (PaulLiu) 50cb2c4f93SYing-Chun Liu (PaulLiu) return 0; 51cb2c4f93SYing-Chun Liu (PaulLiu) } 52cb2c4f93SYing-Chun Liu (PaulLiu) 53cb2c4f93SYing-Chun Liu (PaulLiu) void bl2_plat_mboot_init(void) 54cb2c4f93SYing-Chun Liu (PaulLiu) { 55*b67e9846SHarrison Mutai int rc = event_log_init_and_reg( 56*b67e9846SHarrison Mutai event_log, event_log + sizeof(event_log), &crypto_hash_info); 57*b67e9846SHarrison Mutai if (rc < 0) { 58*b67e9846SHarrison Mutai ERROR("Failed to initialize event log (%d).\n", rc); 59*b67e9846SHarrison Mutai panic(); 60*b67e9846SHarrison Mutai } 61*b67e9846SHarrison Mutai 62*b67e9846SHarrison Mutai rc = event_log_write_header(); 63*b67e9846SHarrison Mutai if (rc < 0) { 64*b67e9846SHarrison Mutai ERROR("Failed to write event log header (%d).\n", rc); 65*b67e9846SHarrison Mutai panic(); 66*b67e9846SHarrison Mutai } 67cb2c4f93SYing-Chun Liu (PaulLiu) } 68cb2c4f93SYing-Chun Liu (PaulLiu) 69cb2c4f93SYing-Chun Liu (PaulLiu) void bl2_plat_mboot_finish(void) 70cb2c4f93SYing-Chun Liu (PaulLiu) { 71cb2c4f93SYing-Chun Liu (PaulLiu) int rc = 0; 72cb2c4f93SYing-Chun Liu (PaulLiu) 73cb2c4f93SYing-Chun Liu (PaulLiu) /* Event Log address in Non-Secure memory */ 74cb2c4f93SYing-Chun Liu (PaulLiu) uintptr_t ns_log_addr; 75cb2c4f93SYing-Chun Liu (PaulLiu) 76cb2c4f93SYing-Chun Liu (PaulLiu) /* Event Log filled size */ 77cb2c4f93SYing-Chun Liu (PaulLiu) size_t event_log_cur_size; 78cb2c4f93SYing-Chun Liu (PaulLiu) 79cb2c4f93SYing-Chun Liu (PaulLiu) event_log_cur_size = event_log_get_cur_size(event_log); 80cb2c4f93SYing-Chun Liu (PaulLiu) 81cb2c4f93SYing-Chun Liu (PaulLiu) rc = imx8m_set_nt_fw_info(event_log_cur_size, &ns_log_addr); 82cb2c4f93SYing-Chun Liu (PaulLiu) if (rc != 0) { 83cb2c4f93SYing-Chun Liu (PaulLiu) ERROR("%s(): Unable to update %s_FW_CONFIG\n", 84cb2c4f93SYing-Chun Liu (PaulLiu) __func__, "NT"); 85cb2c4f93SYing-Chun Liu (PaulLiu) /* 86cb2c4f93SYing-Chun Liu (PaulLiu) * It is a fatal error because on i.MX U-boot assumes that 87cb2c4f93SYing-Chun Liu (PaulLiu) * a valid event log exists and will use it to record the 88cb2c4f93SYing-Chun Liu (PaulLiu) * measurements into the fTPM. 89cb2c4f93SYing-Chun Liu (PaulLiu) */ 90cb2c4f93SYing-Chun Liu (PaulLiu) panic(); 91cb2c4f93SYing-Chun Liu (PaulLiu) } 92cb2c4f93SYing-Chun Liu (PaulLiu) 93cb2c4f93SYing-Chun Liu (PaulLiu) /* Copy Event Log to Non-secure memory */ 94cb2c4f93SYing-Chun Liu (PaulLiu) (void)memcpy((void *)ns_log_addr, (const void *)event_log, 95cb2c4f93SYing-Chun Liu (PaulLiu) event_log_cur_size); 96cb2c4f93SYing-Chun Liu (PaulLiu) 97cb2c4f93SYing-Chun Liu (PaulLiu) /* Ensure that the Event Log is visible in Non-secure memory */ 98cb2c4f93SYing-Chun Liu (PaulLiu) flush_dcache_range(ns_log_addr, event_log_cur_size); 99cb2c4f93SYing-Chun Liu (PaulLiu) 1000d81b96eSHarrison Mutai event_log_dump((uint8_t *)event_log, event_log_cur_size); 101cb2c4f93SYing-Chun Liu (PaulLiu) } 102b9bceef8SManish V Badarkhe 103b9bceef8SManish V Badarkhe int plat_mboot_measure_key(const void *pk_oid, const void *pk_ptr, 104b9bceef8SManish V Badarkhe size_t pk_len) 105b9bceef8SManish V Badarkhe { 106b9bceef8SManish V Badarkhe return 0; 107b9bceef8SManish V Badarkhe } 108