1 /* 2 * Copyright (C) 2016 Google, Inc 3 * Written by Simon Glass <sjg@chromium.org> 4 * 5 * SPDX-License-Identifier: GPL-2.0+ 6 */ 7 8 #include <common.h> 9 #include <errno.h> 10 #include <image.h> 11 #include <linux/libfdt.h> 12 #include <spl.h> 13 #include <malloc.h> 14 #include <optee_include/OpteeClientInterface.h> 15 16 #ifndef CONFIG_SYS_BOOTM_LEN 17 #define CONFIG_SYS_BOOTM_LEN (64 << 20) 18 #endif 19 20 /** 21 * spl_fit_get_image_name(): By using the matching configuration subnode, 22 * retrieve the name of an image, specified by a property name and an index 23 * into that. 24 * @fit: Pointer to the FDT blob. 25 * @images: Offset of the /images subnode. 26 * @type: Name of the property within the configuration subnode. 27 * @index: Index into the list of strings in this property. 28 * @outname: Name of the image 29 * 30 * Return: 0 on success, or a negative error number 31 */ 32 static int spl_fit_get_image_name(const void *fit, int images, 33 const char *type, int index, 34 char **outname) 35 { 36 const char *name, *str; 37 __maybe_unused int node; 38 int conf_node; 39 int len, i; 40 41 conf_node = fit_find_config_node(fit); 42 if (conf_node < 0) { 43 #ifdef CONFIG_SPL_LIBCOMMON_SUPPORT 44 printf("No matching DT out of these options:\n"); 45 for (node = fdt_first_subnode(fit, conf_node); 46 node >= 0; 47 node = fdt_next_subnode(fit, node)) { 48 name = fdt_getprop(fit, node, "description", &len); 49 printf(" %s\n", name); 50 } 51 #endif 52 return conf_node; 53 } 54 55 name = fdt_getprop(fit, conf_node, type, &len); 56 if (!name) { 57 debug("cannot find property '%s': %d\n", type, len); 58 return -EINVAL; 59 } 60 61 str = name; 62 for (i = 0; i < index; i++) { 63 str = strchr(str, '\0') + 1; 64 if (!str || (str - name >= len)) { 65 debug("no string for index %d\n", index); 66 return -E2BIG; 67 } 68 } 69 70 *outname = (char *)str; 71 return 0; 72 } 73 74 /** 75 * spl_fit_get_image_node(): By using the matching configuration subnode, 76 * retrieve the name of an image, specified by a property name and an index 77 * into that. 78 * @fit: Pointer to the FDT blob. 79 * @images: Offset of the /images subnode. 80 * @type: Name of the property within the configuration subnode. 81 * @index: Index into the list of strings in this property. 82 * 83 * Return: the node offset of the respective image node or a negative 84 * error number. 85 */ 86 static int spl_fit_get_image_node(const void *fit, int images, 87 const char *type, int index) 88 { 89 char *str; 90 int err; 91 int node; 92 93 err = spl_fit_get_image_name(fit, images, type, index, &str); 94 if (err) 95 return err; 96 97 debug("%s: '%s'\n", type, str); 98 99 node = fdt_subnode_offset(fit, images, str); 100 if (node < 0) { 101 debug("cannot find image node '%s': %d\n", str, node); 102 return -EINVAL; 103 } 104 105 return node; 106 } 107 108 static int get_aligned_image_offset(struct spl_load_info *info, int offset) 109 { 110 /* 111 * If it is a FS read, get the first address before offset which is 112 * aligned to ARCH_DMA_MINALIGN. If it is raw read return the 113 * block number to which offset belongs. 114 */ 115 if (info->filename) 116 return offset & ~(ARCH_DMA_MINALIGN - 1); 117 118 return offset / info->bl_len; 119 } 120 121 static int get_aligned_image_overhead(struct spl_load_info *info, int offset) 122 { 123 /* 124 * If it is a FS read, get the difference between the offset and 125 * the first address before offset which is aligned to 126 * ARCH_DMA_MINALIGN. If it is raw read return the offset within the 127 * block. 128 */ 129 if (info->filename) 130 return offset & (ARCH_DMA_MINALIGN - 1); 131 132 return offset % info->bl_len; 133 } 134 135 static int get_aligned_image_size(struct spl_load_info *info, int data_size, 136 int offset) 137 { 138 data_size = data_size + get_aligned_image_overhead(info, offset); 139 140 if (info->filename) 141 return data_size; 142 143 return (data_size + info->bl_len - 1) / info->bl_len; 144 } 145 146 /** 147 * spl_load_fit_image(): load the image described in a certain FIT node 148 * @info: points to information about the device to load data from 149 * @sector: the start sector of the FIT image on the device 150 * @fit: points to the flattened device tree blob describing the FIT 151 * image 152 * @base_offset: the beginning of the data area containing the actual 153 * image data, relative to the beginning of the FIT 154 * @node: offset of the DT node describing the image to load (relative 155 * to @fit) 156 * @image_info: will be filled with information about the loaded image 157 * If the FIT node does not contain a "load" (address) property, 158 * the image gets loaded to the address pointed to by the 159 * load_addr member in this struct. 160 * 161 * Return: 0 on success or a negative error number. 162 */ 163 static int spl_load_fit_image(struct spl_load_info *info, ulong sector, 164 void *fit, ulong base_offset, int node, 165 struct spl_image_info *image_info) 166 { 167 int offset; 168 size_t length; 169 int len; 170 ulong size; 171 ulong load_addr, load_ptr; 172 void *src; 173 ulong overhead; 174 int nr_sectors; 175 int align_len = ARCH_DMA_MINALIGN - 1; 176 uint8_t image_comp = -1, type = -1; 177 const void *data; 178 bool external_data = false; 179 180 if (IS_ENABLED(CONFIG_SPL_OS_BOOT) && IS_ENABLED(CONFIG_SPL_GZIP)) { 181 if (fit_image_get_comp(fit, node, &image_comp)) 182 puts("Cannot get image compression format.\n"); 183 else 184 debug("%s ", genimg_get_comp_name(image_comp)); 185 186 if (fit_image_get_type(fit, node, &type)) 187 puts("Cannot get image type.\n"); 188 else 189 debug("%s ", genimg_get_type_name(type)); 190 } 191 192 if (fit_image_get_load(fit, node, &load_addr)) 193 load_addr = image_info->load_addr; 194 195 if (!fit_image_get_data_position(fit, node, &offset)) { 196 external_data = true; 197 } else if (!fit_image_get_data_offset(fit, node, &offset)) { 198 offset += base_offset; 199 external_data = true; 200 } 201 202 if (external_data) { 203 /* External data */ 204 if (fit_image_get_data_size(fit, node, &len)) 205 return -ENOENT; 206 207 load_ptr = (load_addr + align_len) & ~align_len; 208 #if defined(CONFIG_ARCH_ROCKCHIP) 209 if ((load_ptr < CONFIG_SYS_SDRAM_BASE) || 210 (load_ptr >= CONFIG_SYS_SDRAM_BASE + SDRAM_MAX_SIZE)) 211 load_ptr = (ulong)memalign(ARCH_DMA_MINALIGN, len); 212 #endif 213 length = len; 214 215 overhead = get_aligned_image_overhead(info, offset); 216 nr_sectors = get_aligned_image_size(info, length, offset); 217 218 if (info->read(info, 219 sector + get_aligned_image_offset(info, offset), 220 nr_sectors, (void *)load_ptr) != nr_sectors) 221 return -EIO; 222 223 debug("External data: dst=%lx, offset=%x, size=%lx\n", 224 load_ptr, offset, (unsigned long)length); 225 src = (void *)load_ptr + overhead; 226 } else { 227 /* Embedded data */ 228 if (fit_image_get_data(fit, node, &data, &length)) { 229 puts("Cannot get image data/size\n"); 230 return -ENOENT; 231 } 232 debug("Embedded data: dst=%lx, size=%lx\n", load_addr, 233 (unsigned long)length); 234 src = (void *)data; 235 } 236 237 /* Check hashes and signature */ 238 printf("## Checking %s ... ", 239 fit_get_name(fit, node, NULL)); 240 #ifdef CONFIG_FIT_SPL_PRINT 241 printf("\n"); 242 fit_image_print(fit, node, ""); 243 #endif 244 if (!fit_image_verify_with_data(fit, node, 245 src, length)) 246 return -EPERM; 247 puts("OK\n"); 248 249 #ifdef CONFIG_SPL_FIT_IMAGE_POST_PROCESS 250 board_fit_image_post_process(fit, node, (ulong *)&load_addr, 251 (ulong **)&src, &length); 252 #endif 253 254 if (IS_ENABLED(CONFIG_SPL_OS_BOOT) && 255 IS_ENABLED(CONFIG_SPL_GZIP) && 256 image_comp == IH_COMP_GZIP && 257 type == IH_TYPE_KERNEL) { 258 size = length; 259 if (gunzip((void *)load_addr, CONFIG_SYS_BOOTM_LEN, 260 src, &size)) { 261 puts("Uncompressing error\n"); 262 return -EIO; 263 } 264 length = size; 265 } else { 266 memcpy((void *)load_addr, src, length); 267 } 268 269 if (image_info) { 270 image_info->load_addr = load_addr; 271 image_info->size = length; 272 image_info->entry_point = fdt_getprop_u32(fit, node, "entry"); 273 } 274 275 return 0; 276 } 277 278 static int spl_fit_append_fdt(struct spl_image_info *spl_image, 279 struct spl_load_info *info, ulong sector, 280 void *fit, int images, ulong base_offset) 281 { 282 struct spl_image_info image_info; 283 int node, ret; 284 285 /* Figure out which device tree the board wants to use */ 286 node = spl_fit_get_image_node(fit, images, FIT_FDT_PROP, 0); 287 if (node < 0) { 288 debug("%s: cannot find FDT node\n", __func__); 289 return node; 290 } 291 292 /* 293 * Read the device tree and place it after the image. 294 * Align the destination address to ARCH_DMA_MINALIGN. 295 */ 296 image_info.load_addr = spl_image->load_addr + spl_image->size; 297 ret = spl_load_fit_image(info, sector, fit, base_offset, node, 298 &image_info); 299 300 if (ret < 0) 301 return ret; 302 303 /* Make the load-address of the FDT available for the SPL framework */ 304 spl_image->fdt_addr = (void *)image_info.load_addr; 305 #if !CONFIG_IS_ENABLED(FIT_IMAGE_TINY) 306 /* Try to make space, so we can inject details on the loadables */ 307 ret = fdt_shrink_to_minimum(spl_image->fdt_addr, 8192); 308 #endif 309 310 return ret; 311 } 312 313 static int spl_fit_record_loadable(const void *fit, int images, int index, 314 void *blob, struct spl_image_info *image) 315 { 316 int ret = 0; 317 #if !CONFIG_IS_ENABLED(FIT_IMAGE_TINY) 318 char *name; 319 int node; 320 321 ret = spl_fit_get_image_name(fit, images, "loadables", 322 index, &name); 323 if (ret < 0) 324 return ret; 325 326 node = spl_fit_get_image_node(fit, images, "loadables", index); 327 328 ret = fdt_record_loadable(blob, index, name, image->load_addr, 329 image->size, image->entry_point, 330 fdt_getprop(fit, node, "type", NULL), 331 fdt_getprop(fit, node, "os", NULL)); 332 #endif 333 return ret; 334 } 335 336 static int spl_fit_image_get_os(const void *fit, int noffset, uint8_t *os) 337 { 338 #if CONFIG_IS_ENABLED(FIT_IMAGE_TINY) 339 return -ENOTSUPP; 340 #else 341 return fit_image_get_os(fit, noffset, os); 342 #endif 343 } 344 345 __weak int spl_fit_standalone_release(uintptr_t entry_point) 346 { 347 return 0; 348 } 349 350 static void *spl_fit_load_blob(struct spl_load_info *info, 351 ulong sector, void *fit_header, 352 int *base_offset) 353 { 354 int align_len = ARCH_DMA_MINALIGN - 1; 355 ulong count; 356 ulong size; 357 int sectors; 358 void *fit; 359 360 /* 361 * For FIT with external data, figure out where the external images 362 * start. This is the base for the data-offset properties in each 363 * image. 364 */ 365 size = fdt_totalsize(fit_header); 366 size = FIT_ALIGN(size); 367 *base_offset = FIT_ALIGN(size); 368 369 /* 370 * So far we only have one block of data from the FIT. Read the entire 371 * thing, including that first block, placing it so it finishes before 372 * where we will load the image. 373 * 374 * Note that we will load the image such that its first byte will be 375 * at the load address. Since that byte may be part-way through a 376 * block, we may load the image up to one block before the load 377 * address. So take account of that here by subtracting an addition 378 * block length from the FIT start position. 379 * 380 * In fact the FIT has its own load address, but we assume it cannot 381 * be before CONFIG_SYS_TEXT_BASE. 382 * 383 * For FIT with data embedded, data is loaded as part of FIT image. 384 * For FIT with external data, data is not loaded in this step. 385 */ 386 fit = (void *)((CONFIG_SYS_TEXT_BASE - size - info->bl_len - 387 align_len) & ~align_len); 388 sectors = get_aligned_image_size(info, size, 0); 389 count = info->read(info, sector, sectors, fit); 390 debug("fit read sector %lx, sectors=%d, dst=%p, count=%lu\n", 391 sector, sectors, fit, count); 392 if (count == 0) 393 return NULL; 394 395 return fit; 396 } 397 398 static int spl_internal_load_simple_fit(struct spl_image_info *spl_image, 399 struct spl_load_info *info, 400 ulong sector, void *fit_header) 401 { 402 struct spl_image_info image_info; 403 int base_offset; 404 int images, ret; 405 int index = 0; 406 int node = -1; 407 void *fit; 408 409 fit = spl_fit_load_blob(info, sector, fit_header, &base_offset); 410 if (!fit) { 411 debug("%s: Cannot load blob\n", __func__); 412 return -1; 413 } 414 415 /* find the node holding the images information */ 416 images = fdt_path_offset(fit, FIT_IMAGES_PATH); 417 if (images < 0) { 418 debug("%s: Cannot find /images node: %d\n", __func__, images); 419 return -1; 420 } 421 422 /* if board sigs verify required, check self */ 423 if (fit_board_verify_required_sigs() && 424 !IS_ENABLED(CONFIG_SPL_FIT_SIGNATURE)) { 425 printf("Verified-boot requires CONFIG_SPL_FIT_SIGNATURE enabled\n"); 426 hang(); 427 } 428 429 /* verify the configure node by keys, if required */ 430 #ifdef CONFIG_SPL_FIT_SIGNATURE 431 int conf_noffset; 432 433 conf_noffset = fit_conf_get_node(fit, NULL); 434 if (conf_noffset <= 0) { 435 printf("No default config node\n"); 436 return -EINVAL; 437 } 438 439 ret = fit_config_verify(fit, conf_noffset); 440 if (ret) { 441 printf("fit verify configure failed, ret=%d\n", ret); 442 return ret; 443 } 444 printf("\n"); 445 446 #ifdef CONFIG_SPL_FIT_ROLLBACK_PROTECT 447 uint32_t this_index, min_index; 448 449 ret = fit_rollback_index_verify(fit, FIT_ROLLBACK_INDEX_SPL, 450 &this_index, &min_index); 451 if (ret) { 452 printf("fit failed to get rollback index, ret=%d\n", ret); 453 return ret; 454 } else if (this_index < min_index) { 455 printf("fit reject rollback: %d < %d(min)\n", 456 this_index, min_index); 457 return -EINVAL; 458 } 459 460 printf("rollback index: %d >= %d(min), OK\n", this_index, min_index); 461 #endif 462 #endif 463 464 /* 465 * If required to start the other core before load "loadables" 466 * firmwares, use the config "standalone" to load the other core's 467 * firmware, then start it. 468 * Normally, different cores' firmware is attach to the config 469 * "loadables" and load them together. 470 */ 471 if (node < 0) 472 node = spl_fit_get_image_node(fit, images, FIT_STANDALONE_PROP, 473 0); 474 if (node > 0) { 475 /* Load the image and set up the spl_image structure */ 476 ret = spl_load_fit_image(info, sector, fit, base_offset, node, 477 &image_info); 478 if (!ret) { 479 if (image_info.entry_point == FDT_ERROR) 480 image_info.entry_point = image_info.load_addr; 481 482 ret = spl_fit_standalone_release(image_info.entry_point); 483 if (ret) 484 printf("Start standalone fail, ret = %d\n", 485 ret); 486 } 487 488 node = -1; 489 } 490 491 /* 492 * Find the U-Boot image using the following search order: 493 * - start at 'firmware' (e.g. an ARM Trusted Firmware) 494 * - fall back 'kernel' (e.g. a Falcon-mode OS boot 495 * - fall back to using the first 'loadables' entry 496 */ 497 if (node < 0) 498 node = spl_fit_get_image_node(fit, images, FIT_FIRMWARE_PROP, 499 0); 500 #ifdef CONFIG_SPL_OS_BOOT 501 if (node < 0) 502 node = spl_fit_get_image_node(fit, images, FIT_KERNEL_PROP, 0); 503 #endif 504 if (node < 0) { 505 debug("could not find firmware image, trying loadables...\n"); 506 node = spl_fit_get_image_node(fit, images, "loadables", 0); 507 /* 508 * If we pick the U-Boot image from "loadables", start at 509 * the second image when later loading additional images. 510 */ 511 index = 1; 512 } 513 if (node < 0) { 514 debug("%s: Cannot find u-boot image node: %d\n", 515 __func__, node); 516 return -1; 517 } 518 519 /* Load the image and set up the spl_image structure */ 520 ret = spl_load_fit_image(info, sector, fit, base_offset, node, 521 spl_image); 522 if (ret) 523 return ret; 524 525 /* 526 * For backward compatibility, we treat the first node that is 527 * as a U-Boot image, if no OS-type has been declared. 528 */ 529 if (!spl_fit_image_get_os(fit, node, &spl_image->os)) 530 debug("Image OS is %s\n", genimg_get_os_name(spl_image->os)); 531 #if !defined(CONFIG_SPL_OS_BOOT) 532 else 533 spl_image->os = IH_OS_U_BOOT; 534 #endif 535 536 /* 537 * Booting a next-stage U-Boot may require us to append the FDT. 538 * We allow this to fail, as the U-Boot image might embed its FDT. 539 */ 540 if (spl_image->os == IH_OS_U_BOOT) 541 spl_fit_append_fdt(spl_image, info, sector, fit, 542 images, base_offset); 543 544 /* Now check if there are more images for us to load */ 545 for (; ; index++) { 546 uint8_t os_type = IH_OS_INVALID; 547 548 node = spl_fit_get_image_node(fit, images, "loadables", index); 549 if (node < 0) 550 break; 551 552 ret = spl_load_fit_image(info, sector, fit, base_offset, node, 553 &image_info); 554 if (ret < 0) 555 continue; 556 557 if (!spl_fit_image_get_os(fit, node, &os_type)) 558 debug("Loadable is %s\n", genimg_get_os_name(os_type)); 559 560 if (os_type == IH_OS_U_BOOT) { 561 spl_fit_append_fdt(&image_info, info, sector, 562 fit, images, base_offset); 563 spl_image->fdt_addr = image_info.fdt_addr; 564 } 565 566 /* 567 * If the "firmware" image did not provide an entry point, 568 * use the first valid entry point from the loadables. 569 */ 570 if (spl_image->entry_point == FDT_ERROR && 571 image_info.entry_point != FDT_ERROR) 572 spl_image->entry_point = image_info.entry_point; 573 574 /* Record our loadables into the FDT */ 575 if (spl_image->fdt_addr) 576 spl_fit_record_loadable(fit, images, index, 577 spl_image->fdt_addr, 578 &image_info); 579 } 580 581 /* 582 * If a platform does not provide CONFIG_SYS_UBOOT_START, U-Boot's 583 * Makefile will set it to 0 and it will end up as the entry point 584 * here. What it actually means is: use the load address. 585 */ 586 if (spl_image->entry_point == FDT_ERROR || spl_image->entry_point == 0) 587 spl_image->entry_point = spl_image->load_addr; 588 589 return 0; 590 } 591 592 int spl_load_simple_fit(struct spl_image_info *spl_image, 593 struct spl_load_info *info, ulong sector, void *fit) 594 { 595 ulong sector_offs = sector; 596 int i; 597 598 for (i = 0; i < CONFIG_SPL_FIT_IMAGE_MULTIPLE; i++) { 599 if (i > 0) { 600 sector_offs += 601 i * ((CONFIG_SPL_FIT_IMAGE_KB << 10) / info->bl_len); 602 printf("Trying fit image at 0x%lx sector\n", sector_offs); 603 if (info->read(info, sector_offs, 1, fit) != 1) { 604 printf("IO error\n"); 605 continue; 606 } 607 } 608 609 if (image_get_magic(fit) != FDT_MAGIC) { 610 printf("Bad fit magic\n"); 611 continue; 612 } 613 614 if (!spl_internal_load_simple_fit(spl_image, info, 615 sector_offs, fit)) 616 return 0; 617 } 618 619 return -EINVAL; 620 } 621 622