1 /* 2 * dfu.c -- DFU back-end routines 3 * 4 * Copyright (C) 2012 Samsung Electronics 5 * author: Lukasz Majewski <l.majewski@samsung.com> 6 * 7 * SPDX-License-Identifier: GPL-2.0+ 8 */ 9 10 #include <common.h> 11 #include <errno.h> 12 #include <malloc.h> 13 #include <mmc.h> 14 #include <fat.h> 15 #include <dfu.h> 16 #include <hash.h> 17 #include <linux/list.h> 18 #include <linux/compiler.h> 19 20 static LIST_HEAD(dfu_list); 21 static int dfu_alt_num; 22 static int alt_num_cnt; 23 static struct hash_algo *dfu_hash_algo; 24 25 /* 26 * The purpose of the dfu_usb_get_reset() function is to 27 * provide information if after USB_DETACH request 28 * being sent the dfu-util performed reset of USB 29 * bus. 30 * 31 * Described behaviour is the only way to distinct if 32 * user has typed -e (detach) or -R (reset) when invoking 33 * dfu-util command. 34 * 35 */ 36 __weak bool dfu_usb_get_reset(void) 37 { 38 #ifdef CONFIG_SPL_DFU_NO_RESET 39 return false; 40 #else 41 return true; 42 #endif 43 } 44 45 static int dfu_find_alt_num(const char *s) 46 { 47 int i = 0; 48 49 for (; *s; s++) 50 if (*s == ';') 51 i++; 52 53 return ++i; 54 } 55 56 int dfu_init_env_entities(char *interface, char *devstr) 57 { 58 const char *str_env; 59 char *env_bkp; 60 int ret; 61 62 #ifdef CONFIG_SET_DFU_ALT_INFO 63 set_dfu_alt_info(interface, devstr); 64 #endif 65 str_env = env_get("dfu_alt_info"); 66 if (!str_env) { 67 pr_err("\"dfu_alt_info\" env variable not defined!\n"); 68 return -EINVAL; 69 } 70 71 env_bkp = strdup(str_env); 72 ret = dfu_config_entities(env_bkp, interface, devstr); 73 if (ret) { 74 pr_err("DFU entities configuration failed!\n"); 75 return ret; 76 } 77 78 free(env_bkp); 79 return 0; 80 } 81 82 static unsigned char *dfu_buf; 83 static unsigned long dfu_buf_size; 84 85 unsigned char *dfu_free_buf(void) 86 { 87 free(dfu_buf); 88 dfu_buf = NULL; 89 return dfu_buf; 90 } 91 92 unsigned long dfu_get_buf_size(void) 93 { 94 return dfu_buf_size; 95 } 96 97 unsigned char *dfu_get_buf(struct dfu_entity *dfu) 98 { 99 char *s; 100 101 if (dfu_buf != NULL) 102 return dfu_buf; 103 104 s = env_get("dfu_bufsiz"); 105 if (s) 106 dfu_buf_size = (unsigned long)simple_strtol(s, NULL, 0); 107 108 if (!s || !dfu_buf_size) 109 dfu_buf_size = CONFIG_SYS_DFU_DATA_BUF_SIZE; 110 111 if (dfu->max_buf_size && dfu_buf_size > dfu->max_buf_size) 112 dfu_buf_size = dfu->max_buf_size; 113 114 dfu_buf = memalign(CONFIG_SYS_CACHELINE_SIZE, dfu_buf_size); 115 if (dfu_buf == NULL) 116 printf("%s: Could not memalign 0x%lx bytes\n", 117 __func__, dfu_buf_size); 118 119 return dfu_buf; 120 } 121 122 static char *dfu_get_hash_algo(void) 123 { 124 char *s; 125 126 s = env_get("dfu_hash_algo"); 127 if (!s) 128 return NULL; 129 130 if (!strcmp(s, "crc32")) { 131 debug("%s: DFU hash method: %s\n", __func__, s); 132 return s; 133 } 134 135 pr_err("DFU hash method: %s not supported!\n", s); 136 return NULL; 137 } 138 139 static int dfu_write_buffer_drain(struct dfu_entity *dfu) 140 { 141 long w_size; 142 int ret; 143 144 /* flush size? */ 145 w_size = dfu->i_buf - dfu->i_buf_start; 146 if (w_size == 0) 147 return 0; 148 149 if (dfu_hash_algo) 150 dfu_hash_algo->hash_update(dfu_hash_algo, &dfu->crc, 151 dfu->i_buf_start, w_size, 0); 152 153 ret = dfu->write_medium(dfu, dfu->offset, dfu->i_buf_start, &w_size); 154 if (ret) 155 debug("%s: Write error!\n", __func__); 156 157 /* point back */ 158 dfu->i_buf = dfu->i_buf_start; 159 160 /* update offset */ 161 dfu->offset += w_size; 162 163 puts("#"); 164 165 return ret; 166 } 167 168 void dfu_transaction_cleanup(struct dfu_entity *dfu) 169 { 170 /* clear everything */ 171 dfu->crc = 0; 172 dfu->offset = 0; 173 dfu->i_blk_seq_num = 0; 174 dfu->i_buf_start = dfu_get_buf(dfu); 175 dfu->i_buf_end = dfu->i_buf_start; 176 dfu->i_buf = dfu->i_buf_start; 177 dfu->r_left = 0; 178 dfu->b_left = 0; 179 dfu->bad_skip = 0; 180 181 dfu->inited = 0; 182 } 183 184 int dfu_transaction_initiate(struct dfu_entity *dfu, bool read) 185 { 186 int ret = 0; 187 188 if (dfu->inited) 189 return 0; 190 191 dfu_transaction_cleanup(dfu); 192 193 if (dfu->i_buf_start == NULL) 194 return -ENOMEM; 195 196 dfu->i_buf_end = dfu->i_buf_start + dfu_get_buf_size(); 197 198 if (read) { 199 ret = dfu->get_medium_size(dfu, &dfu->r_left); 200 if (ret < 0) 201 return ret; 202 debug("%s: %s %lld [B]\n", __func__, dfu->name, dfu->r_left); 203 } 204 205 dfu->inited = 1; 206 207 return 0; 208 } 209 210 int dfu_flush(struct dfu_entity *dfu, void *buf, int size, int blk_seq_num) 211 { 212 int ret = 0; 213 214 ret = dfu_write_buffer_drain(dfu); 215 if (ret) 216 return ret; 217 218 if (dfu->flush_medium) 219 ret = dfu->flush_medium(dfu); 220 221 if (dfu_hash_algo) 222 printf("\nDFU complete %s: 0x%08x\n", dfu_hash_algo->name, 223 dfu->crc); 224 225 dfu_transaction_cleanup(dfu); 226 227 return ret; 228 } 229 230 int dfu_write(struct dfu_entity *dfu, void *buf, int size, int blk_seq_num) 231 { 232 int ret; 233 234 debug("%s: name: %s buf: 0x%p size: 0x%x p_num: 0x%x offset: 0x%llx bufoffset: 0x%lx\n", 235 __func__, dfu->name, buf, size, blk_seq_num, dfu->offset, 236 (unsigned long)(dfu->i_buf - dfu->i_buf_start)); 237 238 ret = dfu_transaction_initiate(dfu, false); 239 if (ret < 0) 240 return ret; 241 242 if (dfu->i_blk_seq_num != blk_seq_num) { 243 printf("%s: Wrong sequence number! [%d] [%d]\n", 244 __func__, dfu->i_blk_seq_num, blk_seq_num); 245 dfu_transaction_cleanup(dfu); 246 return -1; 247 } 248 249 /* DFU 1.1 standard says: 250 * The wBlockNum field is a block sequence number. It increments each 251 * time a block is transferred, wrapping to zero from 65,535. It is used 252 * to provide useful context to the DFU loader in the device." 253 * 254 * This means that it's a 16 bit counter that roll-overs at 255 * 0xffff -> 0x0000. By having a typical 4K transfer block 256 * we roll-over at exactly 256MB. Not very fun to debug. 257 * 258 * Handling rollover, and having an inited variable, 259 * makes things work. 260 */ 261 262 /* handle rollover */ 263 dfu->i_blk_seq_num = (dfu->i_blk_seq_num + 1) & 0xffff; 264 265 /* flush buffer if overflow */ 266 if ((dfu->i_buf + size) > dfu->i_buf_end) { 267 ret = dfu_write_buffer_drain(dfu); 268 if (ret) { 269 dfu_transaction_cleanup(dfu); 270 return ret; 271 } 272 } 273 274 /* we should be in buffer now (if not then size too large) */ 275 if ((dfu->i_buf + size) > dfu->i_buf_end) { 276 pr_err("Buffer overflow! (0x%p + 0x%x > 0x%p)\n", dfu->i_buf, 277 size, dfu->i_buf_end); 278 dfu_transaction_cleanup(dfu); 279 return -1; 280 } 281 282 memcpy(dfu->i_buf, buf, size); 283 dfu->i_buf += size; 284 285 /* if end or if buffer full flush */ 286 if (size == 0 || (dfu->i_buf + size) > dfu->i_buf_end) { 287 ret = dfu_write_buffer_drain(dfu); 288 if (ret) { 289 dfu_transaction_cleanup(dfu); 290 return ret; 291 } 292 } 293 294 return 0; 295 } 296 297 static int dfu_read_buffer_fill(struct dfu_entity *dfu, void *buf, int size) 298 { 299 long chunk; 300 int ret, readn; 301 302 readn = 0; 303 while (size > 0) { 304 /* get chunk that can be read */ 305 chunk = min((long)size, dfu->b_left); 306 /* consume */ 307 if (chunk > 0) { 308 memcpy(buf, dfu->i_buf, chunk); 309 if (dfu_hash_algo) 310 dfu_hash_algo->hash_update(dfu_hash_algo, 311 &dfu->crc, buf, 312 chunk, 0); 313 314 dfu->i_buf += chunk; 315 dfu->b_left -= chunk; 316 size -= chunk; 317 buf += chunk; 318 readn += chunk; 319 } 320 321 /* all done */ 322 if (size > 0) { 323 /* no more to read */ 324 if (dfu->r_left == 0) 325 break; 326 327 dfu->i_buf = dfu->i_buf_start; 328 dfu->b_left = dfu->i_buf_end - dfu->i_buf_start; 329 330 /* got to read, but buffer is empty */ 331 if (dfu->b_left > dfu->r_left) 332 dfu->b_left = dfu->r_left; 333 ret = dfu->read_medium(dfu, dfu->offset, dfu->i_buf, 334 &dfu->b_left); 335 if (ret != 0) { 336 debug("%s: Read error!\n", __func__); 337 return ret; 338 } 339 dfu->offset += dfu->b_left; 340 dfu->r_left -= dfu->b_left; 341 342 puts("#"); 343 } 344 } 345 346 return readn; 347 } 348 349 int dfu_read(struct dfu_entity *dfu, void *buf, int size, int blk_seq_num) 350 { 351 int ret = 0; 352 353 debug("%s: name: %s buf: 0x%p size: 0x%x p_num: 0x%x i_buf: 0x%p\n", 354 __func__, dfu->name, buf, size, blk_seq_num, dfu->i_buf); 355 356 ret = dfu_transaction_initiate(dfu, true); 357 if (ret < 0) 358 return ret; 359 360 if (dfu->i_blk_seq_num != blk_seq_num) { 361 printf("%s: Wrong sequence number! [%d] [%d]\n", 362 __func__, dfu->i_blk_seq_num, blk_seq_num); 363 return -1; 364 } 365 /* handle rollover */ 366 dfu->i_blk_seq_num = (dfu->i_blk_seq_num + 1) & 0xffff; 367 368 ret = dfu_read_buffer_fill(dfu, buf, size); 369 if (ret < 0) { 370 printf("%s: Failed to fill buffer\n", __func__); 371 return -1; 372 } 373 374 if (ret < size) { 375 if (dfu_hash_algo) 376 debug("%s: %s %s: 0x%x\n", __func__, dfu->name, 377 dfu_hash_algo->name, dfu->crc); 378 puts("\nUPLOAD ... done\nCtrl+C to exit ...\n"); 379 380 dfu_transaction_cleanup(dfu); 381 } 382 383 return ret; 384 } 385 386 static int dfu_fill_entity(struct dfu_entity *dfu, char *s, int alt, 387 char *interface, char *devstr) 388 { 389 char *st; 390 391 debug("%s: %s interface: %s dev: %s\n", __func__, s, interface, devstr); 392 st = strsep(&s, " "); 393 strcpy(dfu->name, st); 394 395 dfu->alt = alt; 396 dfu->max_buf_size = 0; 397 dfu->free_entity = NULL; 398 399 /* Specific for mmc device */ 400 if (strcmp(interface, "mmc") == 0) { 401 if (dfu_fill_entity_mmc(dfu, devstr, s)) 402 return -1; 403 } else if (strcmp(interface, "mtd") == 0) { 404 if (dfu_fill_entity_mtd(dfu, devstr, s)) 405 return -1; 406 } else if (strcmp(interface, "nand") == 0) { 407 if (dfu_fill_entity_nand(dfu, devstr, s)) 408 return -1; 409 } else if (strcmp(interface, "ram") == 0) { 410 if (dfu_fill_entity_ram(dfu, devstr, s)) 411 return -1; 412 } else if (strcmp(interface, "sf") == 0) { 413 if (dfu_fill_entity_sf(dfu, devstr, s)) 414 return -1; 415 } else { 416 printf("%s: Device %s not (yet) supported!\n", 417 __func__, interface); 418 return -1; 419 } 420 dfu_get_buf(dfu); 421 422 return 0; 423 } 424 425 void dfu_free_entities(void) 426 { 427 struct dfu_entity *dfu, *p, *t = NULL; 428 429 dfu_free_buf(); 430 list_for_each_entry_safe_reverse(dfu, p, &dfu_list, list) { 431 list_del(&dfu->list); 432 if (dfu->free_entity) 433 dfu->free_entity(dfu); 434 t = dfu; 435 } 436 if (t) 437 free(t); 438 INIT_LIST_HEAD(&dfu_list); 439 440 alt_num_cnt = 0; 441 } 442 443 int dfu_config_entities(char *env, char *interface, char *devstr) 444 { 445 struct dfu_entity *dfu; 446 int i, ret; 447 char *s; 448 449 dfu_alt_num = dfu_find_alt_num(env); 450 debug("%s: dfu_alt_num=%d\n", __func__, dfu_alt_num); 451 452 dfu_hash_algo = NULL; 453 s = dfu_get_hash_algo(); 454 if (s) { 455 ret = hash_lookup_algo(s, &dfu_hash_algo); 456 if (ret) 457 pr_err("Hash algorithm %s not supported\n", s); 458 } 459 460 dfu = calloc(sizeof(*dfu), dfu_alt_num); 461 if (!dfu) 462 return -1; 463 for (i = 0; i < dfu_alt_num; i++) { 464 465 s = strsep(&env, ";"); 466 ret = dfu_fill_entity(&dfu[i], s, alt_num_cnt, interface, 467 devstr); 468 if (ret) { 469 free(dfu); 470 return -1; 471 } 472 473 list_add_tail(&dfu[i].list, &dfu_list); 474 alt_num_cnt++; 475 } 476 477 return 0; 478 } 479 480 const char *dfu_get_dev_type(enum dfu_device_type t) 481 { 482 const char *dev_t[] = {NULL, "eMMC", "OneNAND", "NAND", "RAM", "SF" }; 483 return dev_t[t]; 484 } 485 486 const char *dfu_get_layout(enum dfu_layout l) 487 { 488 const char *dfu_layout[] = {NULL, "RAW_ADDR", "FAT", "EXT2", 489 "EXT3", "EXT4", "RAM_ADDR" }; 490 return dfu_layout[l]; 491 } 492 493 void dfu_show_entities(void) 494 { 495 struct dfu_entity *dfu; 496 497 puts("DFU alt settings list:\n"); 498 499 list_for_each_entry(dfu, &dfu_list, list) { 500 printf("dev: %s alt: %d name: %s layout: %s\n", 501 dfu_get_dev_type(dfu->dev_type), dfu->alt, 502 dfu->name, dfu_get_layout(dfu->layout)); 503 } 504 } 505 506 int dfu_get_alt_number(void) 507 { 508 return dfu_alt_num; 509 } 510 511 struct dfu_entity *dfu_get_entity(int alt) 512 { 513 struct dfu_entity *dfu; 514 515 list_for_each_entry(dfu, &dfu_list, list) { 516 if (dfu->alt == alt) 517 return dfu; 518 } 519 520 return NULL; 521 } 522 523 int dfu_get_alt(char *name) 524 { 525 struct dfu_entity *dfu; 526 char *str; 527 528 list_for_each_entry(dfu, &dfu_list, list) { 529 if (dfu->name[0] != '/') { 530 if (!strncmp(dfu->name, name, strlen(dfu->name))) 531 return dfu->alt; 532 } else { 533 /* 534 * One must also consider absolute path 535 * (/boot/bin/uImage) available at dfu->name when 536 * compared "plain" file name (uImage) 537 * 538 * It is the case for e.g. thor gadget where lthor SW 539 * sends only the file name, so only the very last part 540 * of path must be checked for equality 541 */ 542 543 str = strstr(dfu->name, name); 544 if (!str) 545 continue; 546 547 /* 548 * Check if matching substring is the last element of 549 * dfu->name (uImage) 550 */ 551 if (strlen(dfu->name) == 552 ((str - dfu->name) + strlen(name))) 553 return dfu->alt; 554 } 555 } 556 557 return -ENODEV; 558 } 559 560 int dfu_write_from_mem_addr(struct dfu_entity *dfu, void *buf, int size) 561 { 562 unsigned long dfu_buf_size, write, left = size; 563 int i, ret = 0; 564 void *dp = buf; 565 566 /* 567 * Here we must call dfu_get_buf(dfu) first to be sure that dfu_buf_size 568 * has been properly initialized - e.g. if "dfu_bufsiz" has been taken 569 * into account. 570 */ 571 dfu_get_buf(dfu); 572 dfu_buf_size = dfu_get_buf_size(); 573 debug("%s: dfu buf size: %lu\n", __func__, dfu_buf_size); 574 575 for (i = 0; left > 0; i++) { 576 write = min(dfu_buf_size, left); 577 578 debug("%s: dp: 0x%p left: %lu write: %lu\n", __func__, 579 dp, left, write); 580 ret = dfu_write(dfu, dp, write, i); 581 if (ret) { 582 pr_err("DFU write failed\n"); 583 return ret; 584 } 585 586 dp += write; 587 left -= write; 588 } 589 590 ret = dfu_flush(dfu, NULL, 0, i); 591 if (ret) 592 pr_err("DFU flush failed!"); 593 594 return ret; 595 } 596