1 /* 2 * Copyright (c) 2015-2022, ARM Limited and Contributors. All rights reserved. 3 * 4 * SPDX-License-Identifier: BSD-3-Clause 5 */ 6 7 #include <assert.h> 8 #include <errno.h> 9 #include <string.h> 10 11 #include <arch_helpers.h> 12 #include <common/bl_common.h> 13 #include <common/debug.h> 14 #include <common/desc_image_load.h> 15 #include <drivers/generic_delay_timer.h> 16 #include <drivers/mmc.h> 17 #include <drivers/st/bsec.h> 18 #include <drivers/st/regulator_fixed.h> 19 #include <drivers/st/stm32_iwdg.h> 20 #include <drivers/st/stm32_uart.h> 21 #include <drivers/st/stm32mp1_clk.h> 22 #include <drivers/st/stm32mp1_pwr.h> 23 #include <drivers/st/stm32mp1_ram.h> 24 #include <drivers/st/stm32mp_pmic.h> 25 #include <lib/fconf/fconf.h> 26 #include <lib/fconf/fconf_dyn_cfg_getter.h> 27 #include <lib/mmio.h> 28 #include <lib/optee_utils.h> 29 #include <lib/xlat_tables/xlat_tables_v2.h> 30 #include <plat/common/platform.h> 31 32 #include <platform_def.h> 33 #include <stm32mp_common.h> 34 #include <stm32mp1_dbgmcu.h> 35 36 #if DEBUG 37 static const char debug_msg[] = { 38 "***************************************************\n" 39 "** DEBUG ACCESS PORT IS OPEN! **\n" 40 "** This boot image is only for debugging purpose **\n" 41 "** and is unsafe for production use. **\n" 42 "** **\n" 43 "** If you see this message and you are not **\n" 44 "** debugging report this immediately to your **\n" 45 "** vendor! **\n" 46 "***************************************************\n" 47 }; 48 #endif 49 50 #if STM32MP15 51 static struct stm32mp_auth_ops stm32mp1_auth_ops; 52 #endif 53 54 static void print_reset_reason(void) 55 { 56 uint32_t rstsr = mmio_read_32(stm32mp_rcc_base() + RCC_MP_RSTSCLRR); 57 58 if (rstsr == 0U) { 59 WARN("Reset reason unknown\n"); 60 return; 61 } 62 63 INFO("Reset reason (0x%x):\n", rstsr); 64 65 if ((rstsr & RCC_MP_RSTSCLRR_PADRSTF) == 0U) { 66 if ((rstsr & RCC_MP_RSTSCLRR_STDBYRSTF) != 0U) { 67 INFO("System exits from STANDBY\n"); 68 return; 69 } 70 71 if ((rstsr & RCC_MP_RSTSCLRR_CSTDBYRSTF) != 0U) { 72 INFO("MPU exits from CSTANDBY\n"); 73 return; 74 } 75 } 76 77 if ((rstsr & RCC_MP_RSTSCLRR_PORRSTF) != 0U) { 78 INFO(" Power-on Reset (rst_por)\n"); 79 return; 80 } 81 82 if ((rstsr & RCC_MP_RSTSCLRR_BORRSTF) != 0U) { 83 INFO(" Brownout Reset (rst_bor)\n"); 84 return; 85 } 86 87 #if STM32MP15 88 if ((rstsr & RCC_MP_RSTSCLRR_MCSYSRSTF) != 0U) { 89 if ((rstsr & RCC_MP_RSTSCLRR_PADRSTF) != 0U) { 90 INFO(" System reset generated by MCU (MCSYSRST)\n"); 91 } else { 92 INFO(" Local reset generated by MCU (MCSYSRST)\n"); 93 } 94 return; 95 } 96 #endif 97 98 if ((rstsr & RCC_MP_RSTSCLRR_MPSYSRSTF) != 0U) { 99 INFO(" System reset generated by MPU (MPSYSRST)\n"); 100 return; 101 } 102 103 if ((rstsr & RCC_MP_RSTSCLRR_HCSSRSTF) != 0U) { 104 INFO(" Reset due to a clock failure on HSE\n"); 105 return; 106 } 107 108 if ((rstsr & RCC_MP_RSTSCLRR_IWDG1RSTF) != 0U) { 109 INFO(" IWDG1 Reset (rst_iwdg1)\n"); 110 return; 111 } 112 113 if ((rstsr & RCC_MP_RSTSCLRR_IWDG2RSTF) != 0U) { 114 INFO(" IWDG2 Reset (rst_iwdg2)\n"); 115 return; 116 } 117 118 if ((rstsr & RCC_MP_RSTSCLRR_MPUP0RSTF) != 0U) { 119 INFO(" MPU Processor 0 Reset\n"); 120 return; 121 } 122 123 #if STM32MP15 124 if ((rstsr & RCC_MP_RSTSCLRR_MPUP1RSTF) != 0U) { 125 INFO(" MPU Processor 1 Reset\n"); 126 return; 127 } 128 #endif 129 130 if ((rstsr & RCC_MP_RSTSCLRR_PADRSTF) != 0U) { 131 INFO(" Pad Reset from NRST\n"); 132 return; 133 } 134 135 if ((rstsr & RCC_MP_RSTSCLRR_VCORERSTF) != 0U) { 136 INFO(" Reset due to a failure of VDD_CORE\n"); 137 return; 138 } 139 140 ERROR(" Unidentified reset reason\n"); 141 } 142 143 void bl2_el3_early_platform_setup(u_register_t arg0, 144 u_register_t arg1 __unused, 145 u_register_t arg2 __unused, 146 u_register_t arg3 __unused) 147 { 148 stm32mp_setup_early_console(); 149 150 stm32mp_save_boot_ctx_address(arg0); 151 } 152 153 void bl2_platform_setup(void) 154 { 155 int ret; 156 157 ret = stm32mp1_ddr_probe(); 158 if (ret < 0) { 159 ERROR("Invalid DDR init: error %d\n", ret); 160 panic(); 161 } 162 163 /* Map DDR for binary load, now with cacheable attribute */ 164 ret = mmap_add_dynamic_region(STM32MP_DDR_BASE, STM32MP_DDR_BASE, 165 STM32MP_DDR_MAX_SIZE, MT_MEMORY | MT_RW | MT_SECURE); 166 if (ret < 0) { 167 ERROR("DDR mapping: error %d\n", ret); 168 panic(); 169 } 170 171 #if STM32MP_USE_STM32IMAGE 172 #ifdef AARCH32_SP_OPTEE 173 INFO("BL2 runs OP-TEE setup\n"); 174 #else 175 INFO("BL2 runs SP_MIN setup\n"); 176 #endif 177 #endif /* STM32MP_USE_STM32IMAGE */ 178 } 179 180 #if STM32MP15 181 static void update_monotonic_counter(void) 182 { 183 uint32_t version; 184 uint32_t otp; 185 186 CASSERT(STM32_TF_VERSION <= MAX_MONOTONIC_VALUE, 187 assert_stm32mp1_monotonic_counter_reach_max); 188 189 /* Check if monotonic counter needs to be incremented */ 190 if (stm32_get_otp_index(MONOTONIC_OTP, &otp, NULL) != 0) { 191 panic(); 192 } 193 194 if (stm32_get_otp_value_from_idx(otp, &version) != 0) { 195 panic(); 196 } 197 198 if ((version + 1U) < BIT(STM32_TF_VERSION)) { 199 uint32_t result; 200 201 /* Need to increment the monotonic counter. */ 202 version = BIT(STM32_TF_VERSION) - 1U; 203 204 result = bsec_program_otp(version, otp); 205 if (result != BSEC_OK) { 206 ERROR("BSEC: MONOTONIC_OTP program Error %u\n", 207 result); 208 panic(); 209 } 210 INFO("Monotonic counter has been incremented (value 0x%x)\n", 211 version); 212 } 213 } 214 #endif 215 216 void bl2_el3_plat_arch_setup(void) 217 { 218 const char *board_model; 219 boot_api_context_t *boot_context = 220 (boot_api_context_t *)stm32mp_get_boot_ctx_address(); 221 uintptr_t pwr_base; 222 uintptr_t rcc_base; 223 224 if (bsec_probe() != 0U) { 225 panic(); 226 } 227 228 mmap_add_region(BL_CODE_BASE, BL_CODE_BASE, 229 BL_CODE_END - BL_CODE_BASE, 230 MT_CODE | MT_SECURE); 231 232 #if STM32MP_USE_STM32IMAGE 233 #ifdef AARCH32_SP_OPTEE 234 mmap_add_region(STM32MP_OPTEE_BASE, STM32MP_OPTEE_BASE, 235 STM32MP_OPTEE_SIZE, 236 MT_MEMORY | MT_RW | MT_SECURE); 237 #else 238 /* Prevent corruption of preloaded BL32 */ 239 mmap_add_region(BL32_BASE, BL32_BASE, 240 BL32_LIMIT - BL32_BASE, 241 MT_RO_DATA | MT_SECURE); 242 #endif 243 #endif /* STM32MP_USE_STM32IMAGE */ 244 245 /* Prevent corruption of preloaded Device Tree */ 246 mmap_add_region(DTB_BASE, DTB_BASE, 247 DTB_LIMIT - DTB_BASE, 248 MT_RO_DATA | MT_SECURE); 249 250 configure_mmu(); 251 252 if (dt_open_and_check(STM32MP_DTB_BASE) < 0) { 253 panic(); 254 } 255 256 pwr_base = stm32mp_pwr_base(); 257 rcc_base = stm32mp_rcc_base(); 258 259 /* 260 * Disable the backup domain write protection. 261 * The protection is enable at each reset by hardware 262 * and must be disabled by software. 263 */ 264 mmio_setbits_32(pwr_base + PWR_CR1, PWR_CR1_DBP); 265 266 while ((mmio_read_32(pwr_base + PWR_CR1) & PWR_CR1_DBP) == 0U) { 267 ; 268 } 269 270 /* Reset backup domain on cold boot cases */ 271 if ((mmio_read_32(rcc_base + RCC_BDCR) & RCC_BDCR_RTCSRC_MASK) == 0U) { 272 mmio_setbits_32(rcc_base + RCC_BDCR, RCC_BDCR_VSWRST); 273 274 while ((mmio_read_32(rcc_base + RCC_BDCR) & RCC_BDCR_VSWRST) == 275 0U) { 276 ; 277 } 278 279 mmio_clrbits_32(rcc_base + RCC_BDCR, RCC_BDCR_VSWRST); 280 } 281 282 #if STM32MP15 283 /* Disable MCKPROT */ 284 mmio_clrbits_32(rcc_base + RCC_TZCR, RCC_TZCR_MCKPROT); 285 #endif 286 287 /* 288 * Set minimum reset pulse duration to 31ms for discrete power 289 * supplied boards. 290 */ 291 if (dt_pmic_status() <= 0) { 292 mmio_clrsetbits_32(rcc_base + RCC_RDLSICR, 293 RCC_RDLSICR_MRD_MASK, 294 31U << RCC_RDLSICR_MRD_SHIFT); 295 } 296 297 generic_delay_timer_init(); 298 299 #if STM32MP_UART_PROGRAMMER 300 /* Disable programmer UART before changing clock tree */ 301 if (boot_context->boot_interface_selected == 302 BOOT_API_CTX_BOOT_INTERFACE_SEL_SERIAL_UART) { 303 uintptr_t uart_prog_addr = 304 get_uart_address(boot_context->boot_interface_instance); 305 306 stm32_uart_stop(uart_prog_addr); 307 } 308 #endif 309 if (stm32mp1_clk_probe() < 0) { 310 panic(); 311 } 312 313 if (stm32mp1_clk_init() < 0) { 314 panic(); 315 } 316 317 stm32_save_boot_interface(boot_context->boot_interface_selected, 318 boot_context->boot_interface_instance); 319 stm32_save_boot_auth(boot_context->auth_status, 320 boot_context->boot_partition_used_toboot); 321 322 #if STM32MP_USB_PROGRAMMER && STM32MP15 323 /* Deconfigure all UART RX pins configured by ROM code */ 324 stm32mp1_deconfigure_uart_pins(); 325 #endif 326 327 if (stm32mp_uart_console_setup() != 0) { 328 goto skip_console_init; 329 } 330 331 stm32mp_print_cpuinfo(); 332 333 board_model = dt_get_board_model(); 334 if (board_model != NULL) { 335 NOTICE("Model: %s\n", board_model); 336 } 337 338 stm32mp_print_boardinfo(); 339 340 if (boot_context->auth_status != BOOT_API_CTX_AUTH_NO) { 341 NOTICE("Bootrom authentication %s\n", 342 (boot_context->auth_status == BOOT_API_CTX_AUTH_FAILED) ? 343 "failed" : "succeeded"); 344 } 345 346 skip_console_init: 347 if (fixed_regulator_register() != 0) { 348 panic(); 349 } 350 351 if (dt_pmic_status() > 0) { 352 initialize_pmic(); 353 if (pmic_voltages_init() != 0) { 354 ERROR("PMIC voltages init failed\n"); 355 panic(); 356 } 357 print_pmic_info_and_debug(); 358 } 359 360 stm32mp1_syscfg_init(); 361 362 if (stm32_iwdg_init() < 0) { 363 panic(); 364 } 365 366 stm32_iwdg_refresh(); 367 368 if (bsec_read_debug_conf() != 0U) { 369 if (stm32mp_is_closed_device()) { 370 #if DEBUG 371 WARN("\n%s", debug_msg); 372 #else 373 ERROR("***Debug opened on closed chip***\n"); 374 #endif 375 } 376 } 377 378 #if STM32MP15 379 if (stm32mp_is_auth_supported()) { 380 stm32mp1_auth_ops.check_key = 381 boot_context->bootrom_ecdsa_check_key; 382 stm32mp1_auth_ops.verify_signature = 383 boot_context->bootrom_ecdsa_verify_signature; 384 385 stm32mp_init_auth(&stm32mp1_auth_ops); 386 } 387 #endif 388 389 stm32mp1_arch_security_setup(); 390 391 print_reset_reason(); 392 393 #if STM32MP15 394 update_monotonic_counter(); 395 #endif 396 397 stm32mp1_syscfg_enable_io_compensation_finish(); 398 399 #if !STM32MP_USE_STM32IMAGE 400 fconf_populate("TB_FW", STM32MP_DTB_BASE); 401 #endif /* !STM32MP_USE_STM32IMAGE */ 402 403 stm32mp_io_setup(); 404 } 405 406 /******************************************************************************* 407 * This function can be used by the platforms to update/use image 408 * information for given `image_id`. 409 ******************************************************************************/ 410 int bl2_plat_handle_post_image_load(unsigned int image_id) 411 { 412 int err = 0; 413 bl_mem_params_node_t *bl_mem_params = get_bl_mem_params_node(image_id); 414 bl_mem_params_node_t *bl32_mem_params; 415 bl_mem_params_node_t *pager_mem_params __unused; 416 bl_mem_params_node_t *paged_mem_params __unused; 417 #if !STM32MP_USE_STM32IMAGE 418 const struct dyn_cfg_dtb_info_t *config_info; 419 bl_mem_params_node_t *tos_fw_mem_params; 420 unsigned int i; 421 unsigned int idx; 422 unsigned long long ddr_top __unused; 423 const unsigned int image_ids[] = { 424 BL32_IMAGE_ID, 425 BL33_IMAGE_ID, 426 HW_CONFIG_ID, 427 TOS_FW_CONFIG_ID, 428 }; 429 #endif /* !STM32MP_USE_STM32IMAGE */ 430 431 assert(bl_mem_params != NULL); 432 433 switch (image_id) { 434 #if !STM32MP_USE_STM32IMAGE 435 case FW_CONFIG_ID: 436 /* Set global DTB info for fixed fw_config information */ 437 set_config_info(STM32MP_FW_CONFIG_BASE, ~0UL, STM32MP_FW_CONFIG_MAX_SIZE, 438 FW_CONFIG_ID); 439 fconf_populate("FW_CONFIG", STM32MP_FW_CONFIG_BASE); 440 441 idx = dyn_cfg_dtb_info_get_index(TOS_FW_CONFIG_ID); 442 443 /* Iterate through all the fw config IDs */ 444 for (i = 0U; i < ARRAY_SIZE(image_ids); i++) { 445 if ((image_ids[i] == TOS_FW_CONFIG_ID) && (idx == FCONF_INVALID_IDX)) { 446 continue; 447 } 448 449 bl_mem_params = get_bl_mem_params_node(image_ids[i]); 450 assert(bl_mem_params != NULL); 451 452 config_info = FCONF_GET_PROPERTY(dyn_cfg, dtb, image_ids[i]); 453 if (config_info == NULL) { 454 continue; 455 } 456 457 bl_mem_params->image_info.image_base = config_info->config_addr; 458 bl_mem_params->image_info.image_max_size = config_info->config_max_size; 459 460 bl_mem_params->image_info.h.attr &= ~IMAGE_ATTRIB_SKIP_LOADING; 461 462 switch (image_ids[i]) { 463 case BL32_IMAGE_ID: 464 bl_mem_params->ep_info.pc = config_info->config_addr; 465 466 /* In case of OPTEE, initialize address space with tos_fw addr */ 467 pager_mem_params = get_bl_mem_params_node(BL32_EXTRA1_IMAGE_ID); 468 assert(pager_mem_params != NULL); 469 pager_mem_params->image_info.image_base = config_info->config_addr; 470 pager_mem_params->image_info.image_max_size = 471 config_info->config_max_size; 472 473 /* Init base and size for pager if exist */ 474 paged_mem_params = get_bl_mem_params_node(BL32_EXTRA2_IMAGE_ID); 475 if (paged_mem_params != NULL) { 476 paged_mem_params->image_info.image_base = STM32MP_DDR_BASE + 477 (dt_get_ddr_size() - STM32MP_DDR_S_SIZE - 478 STM32MP_DDR_SHMEM_SIZE); 479 paged_mem_params->image_info.image_max_size = 480 STM32MP_DDR_S_SIZE; 481 } 482 break; 483 484 case BL33_IMAGE_ID: 485 bl_mem_params->ep_info.pc = config_info->config_addr; 486 break; 487 488 case HW_CONFIG_ID: 489 case TOS_FW_CONFIG_ID: 490 break; 491 492 default: 493 return -EINVAL; 494 } 495 } 496 break; 497 #endif /* !STM32MP_USE_STM32IMAGE */ 498 499 case BL32_IMAGE_ID: 500 if (optee_header_is_valid(bl_mem_params->image_info.image_base)) { 501 image_info_t *paged_image_info = NULL; 502 503 /* BL32 is OP-TEE header */ 504 bl_mem_params->ep_info.pc = bl_mem_params->image_info.image_base; 505 pager_mem_params = get_bl_mem_params_node(BL32_EXTRA1_IMAGE_ID); 506 assert(pager_mem_params != NULL); 507 508 paged_mem_params = get_bl_mem_params_node(BL32_EXTRA2_IMAGE_ID); 509 if (paged_mem_params != NULL) { 510 paged_image_info = &paged_mem_params->image_info; 511 } 512 513 #if STM32MP_USE_STM32IMAGE && defined(AARCH32_SP_OPTEE) 514 /* Set OP-TEE extra image load areas at run-time */ 515 pager_mem_params->image_info.image_base = STM32MP_OPTEE_BASE; 516 pager_mem_params->image_info.image_max_size = STM32MP_OPTEE_SIZE; 517 518 paged_mem_params->image_info.image_base = STM32MP_DDR_BASE + 519 dt_get_ddr_size() - 520 STM32MP_DDR_S_SIZE - 521 STM32MP_DDR_SHMEM_SIZE; 522 paged_mem_params->image_info.image_max_size = STM32MP_DDR_S_SIZE; 523 #endif /* STM32MP_USE_STM32IMAGE && defined(AARCH32_SP_OPTEE) */ 524 525 err = parse_optee_header(&bl_mem_params->ep_info, 526 &pager_mem_params->image_info, 527 paged_image_info); 528 if (err != 0) { 529 ERROR("OPTEE header parse error.\n"); 530 panic(); 531 } 532 533 /* Set optee boot info from parsed header data */ 534 if (paged_mem_params != NULL) { 535 bl_mem_params->ep_info.args.arg0 = 536 paged_mem_params->image_info.image_base; 537 } else { 538 bl_mem_params->ep_info.args.arg0 = 0U; 539 } 540 541 bl_mem_params->ep_info.args.arg1 = 0U; /* Unused */ 542 bl_mem_params->ep_info.args.arg2 = 0U; /* No DT supported */ 543 } else { 544 #if !STM32MP_USE_STM32IMAGE 545 bl_mem_params->ep_info.pc = bl_mem_params->image_info.image_base; 546 tos_fw_mem_params = get_bl_mem_params_node(TOS_FW_CONFIG_ID); 547 assert(tos_fw_mem_params != NULL); 548 bl_mem_params->image_info.image_max_size += 549 tos_fw_mem_params->image_info.image_max_size; 550 #endif /* !STM32MP_USE_STM32IMAGE */ 551 bl_mem_params->ep_info.args.arg0 = 0; 552 } 553 break; 554 555 case BL33_IMAGE_ID: 556 bl32_mem_params = get_bl_mem_params_node(BL32_IMAGE_ID); 557 assert(bl32_mem_params != NULL); 558 bl32_mem_params->ep_info.lr_svc = bl_mem_params->ep_info.pc; 559 #if !STM32MP_USE_STM32IMAGE && PSA_FWU_SUPPORT 560 stm32mp1_fwu_set_boot_idx(); 561 #endif /* !STM32MP_USE_STM32IMAGE && PSA_FWU_SUPPORT */ 562 break; 563 564 default: 565 /* Do nothing in default case */ 566 break; 567 } 568 569 #if STM32MP_SDMMC || STM32MP_EMMC 570 /* 571 * Invalidate remaining data read from MMC but not flushed by load_image_flush(). 572 * We take the worst case which is 2 MMC blocks. 573 */ 574 if ((image_id != FW_CONFIG_ID) && 575 ((bl_mem_params->image_info.h.attr & IMAGE_ATTRIB_SKIP_LOADING) == 0U)) { 576 inv_dcache_range(bl_mem_params->image_info.image_base + 577 bl_mem_params->image_info.image_size, 578 2U * MMC_BLOCK_SIZE); 579 } 580 #endif /* STM32MP_SDMMC || STM32MP_EMMC */ 581 582 return err; 583 } 584 585 void bl2_el3_plat_prepare_exit(void) 586 { 587 uint16_t boot_itf = stm32mp_get_boot_itf_selected(); 588 589 switch (boot_itf) { 590 #if STM32MP_UART_PROGRAMMER || STM32MP_USB_PROGRAMMER 591 case BOOT_API_CTX_BOOT_INTERFACE_SEL_SERIAL_UART: 592 case BOOT_API_CTX_BOOT_INTERFACE_SEL_SERIAL_USB: 593 /* Invalidate the downloaded buffer used with io_memmap */ 594 inv_dcache_range(DWL_BUFFER_BASE, DWL_BUFFER_SIZE); 595 break; 596 #endif /* STM32MP_UART_PROGRAMMER || STM32MP_USB_PROGRAMMER */ 597 default: 598 /* Do nothing in default case */ 599 break; 600 } 601 602 stm32mp1_security_setup(); 603 } 604