1 /* 2 * Copyright 2017 Rockchip Electronics Co., Ltd 3 * Frank Wang <frank.wang@rock-chips.com> 4 * 5 * SPDX-License-Identifier: GPL-2.0+ 6 */ 7 8 #include <asm/io.h> 9 #include <android_avb/avb_ops_user.h> 10 #include <android_avb/rk_avb_ops_user.h> 11 #include <asm/arch/boot_mode.h> 12 #include <asm/arch/chip_info.h> 13 #include <asm/arch/rk_atags.h> 14 #include <write_keybox.h> 15 #include <linux/mtd/mtd.h> 16 #include <optee_include/OpteeClientInterface.h> 17 #include <mmc.h> 18 #include <stdlib.h> 19 #include <usbplug.h> 20 21 #ifdef CONFIG_ROCKCHIP_VENDOR_PARTITION 22 #include <asm/arch/vendor.h> 23 #endif 24 #include <rockusb.h> 25 26 #define ROCKUSB_INTERFACE_CLASS 0xff 27 #define ROCKUSB_INTERFACE_SUB_CLASS 0x06 28 #define ROCKUSB_INTERFACE_PROTOCOL 0x05 29 30 #define ROCKCHIP_FLASH_BLOCK_SIZE 1024 31 #define ROCKCHIP_FLASH_PAGE_SIZE 4 32 33 static struct usb_interface_descriptor rkusb_intf_desc = { 34 .bLength = USB_DT_INTERFACE_SIZE, 35 .bDescriptorType = USB_DT_INTERFACE, 36 .bInterfaceNumber = 0x00, 37 .bAlternateSetting = 0x00, 38 .bNumEndpoints = 0x02, 39 .bInterfaceClass = ROCKUSB_INTERFACE_CLASS, 40 .bInterfaceSubClass = ROCKUSB_INTERFACE_SUB_CLASS, 41 .bInterfaceProtocol = ROCKUSB_INTERFACE_PROTOCOL, 42 }; 43 44 static struct usb_descriptor_header *rkusb_fs_function[] = { 45 (struct usb_descriptor_header *)&rkusb_intf_desc, 46 (struct usb_descriptor_header *)&fsg_fs_bulk_in_desc, 47 (struct usb_descriptor_header *)&fsg_fs_bulk_out_desc, 48 NULL, 49 }; 50 51 static struct usb_descriptor_header *rkusb_hs_function[] = { 52 (struct usb_descriptor_header *)&rkusb_intf_desc, 53 (struct usb_descriptor_header *)&fsg_hs_bulk_in_desc, 54 (struct usb_descriptor_header *)&fsg_hs_bulk_out_desc, 55 NULL, 56 }; 57 58 static struct usb_descriptor_header *rkusb_ss_function[] = { 59 (struct usb_descriptor_header *)&rkusb_intf_desc, 60 (struct usb_descriptor_header *)&fsg_ss_bulk_in_desc, 61 (struct usb_descriptor_header *)&fsg_ss_bulk_in_comp_desc, 62 (struct usb_descriptor_header *)&fsg_ss_bulk_out_desc, 63 (struct usb_descriptor_header *)&fsg_ss_bulk_out_comp_desc, 64 NULL, 65 }; 66 67 struct rk_flash_info { 68 u32 flash_size; 69 u16 block_size; 70 u8 page_size; 71 u8 ecc_bits; 72 u8 access_time; 73 u8 manufacturer; 74 u8 flash_mask; 75 } __packed; 76 77 static int rkusb_rst_code; /* The subcode in reset command (0xFF) */ 78 79 int g_dnl_bind_fixup(struct usb_device_descriptor *dev, const char *name) 80 { 81 if (IS_RKUSB_UMS_DNL(name)) { 82 /* Fix to Rockchip's VID and PID */ 83 dev->idVendor = __constant_cpu_to_le16(0x2207); 84 dev->idProduct = __constant_cpu_to_le16(CONFIG_ROCKUSB_G_DNL_PID); 85 86 /* Enumerate as a loader device */ 87 #if defined(CONFIG_SUPPORT_USBPLUG) 88 dev->bcdUSB = cpu_to_le16(0x0200); 89 #else 90 dev->bcdUSB = cpu_to_le16(0x0201); 91 #endif 92 } else if (!strncmp(name, "usb_dnl_fastboot", 16)) { 93 /* Fix to Google's VID and PID */ 94 dev->idVendor = __constant_cpu_to_le16(0x18d1); 95 dev->idProduct = __constant_cpu_to_le16(0xd00d); 96 } else if (!strncmp(name, "usb_dnl_dfu", 11)) { 97 /* Fix to Rockchip's VID and PID for DFU */ 98 dev->idVendor = cpu_to_le16(0x2207); 99 dev->idProduct = cpu_to_le16(0x0107); 100 } else if (!strncmp(name, "usb_dnl_ums", 11)) { 101 dev->idVendor = cpu_to_le16(0x2207); 102 dev->idProduct = cpu_to_le16(0x0010); 103 } 104 105 return 0; 106 } 107 108 __maybe_unused 109 static inline void dump_cbw(struct fsg_bulk_cb_wrap *cbw) 110 { 111 assert(!cbw); 112 113 debug("%s:\n", __func__); 114 debug("Signature %x\n", cbw->Signature); 115 debug("Tag %x\n", cbw->Tag); 116 debug("DataTransferLength %x\n", cbw->DataTransferLength); 117 debug("Flags %x\n", cbw->Flags); 118 debug("LUN %x\n", cbw->Lun); 119 debug("Length %x\n", cbw->Length); 120 debug("OptionCode %x\n", cbw->CDB[0]); 121 debug("SubCode %x\n", cbw->CDB[1]); 122 debug("SectorAddr %x\n", get_unaligned_be32(&cbw->CDB[2])); 123 debug("BlkSectors %x\n\n", get_unaligned_be16(&cbw->CDB[7])); 124 } 125 126 static int rkusb_check_lun(struct fsg_common *common) 127 { 128 struct fsg_lun *curlun; 129 130 /* Check the LUN */ 131 if (common->lun >= 0 && common->lun < common->nluns) { 132 curlun = &common->luns[common->lun]; 133 if (common->cmnd[0] != SC_REQUEST_SENSE) { 134 curlun->sense_data = SS_NO_SENSE; 135 curlun->info_valid = 0; 136 } 137 } else { 138 curlun = NULL; 139 common->bad_lun_okay = 0; 140 141 /* 142 * INQUIRY and REQUEST SENSE commands are explicitly allowed 143 * to use unsupported LUNs; all others may not. 144 */ 145 if (common->cmnd[0] != SC_INQUIRY && 146 common->cmnd[0] != SC_REQUEST_SENSE) { 147 debug("unsupported LUN %d\n", common->lun); 148 return -EINVAL; 149 } 150 } 151 152 return 0; 153 } 154 155 static void __do_reset(struct usb_ep *ep, struct usb_request *req) 156 { 157 u32 boot_flag = BOOT_NORMAL; 158 159 if (rkusb_rst_code == 0x03) 160 boot_flag = BOOT_BROM_DOWNLOAD; 161 162 rkusb_rst_code = 0; /* restore to default */ 163 writel(boot_flag, (void *)CONFIG_ROCKCHIP_BOOT_MODE_REG); 164 165 do_reset(NULL, 0, 0, NULL); 166 } 167 168 static int rkusb_do_reset(struct fsg_common *common, 169 struct fsg_buffhd *bh) 170 { 171 common->data_size_from_cmnd = common->cmnd[4]; 172 common->residue = 0; 173 bh->inreq->complete = __do_reset; 174 bh->state = BUF_STATE_EMPTY; 175 176 rkusb_rst_code = !common->cmnd[1] ? 0xff : common->cmnd[1]; 177 return 0; 178 } 179 180 __weak bool rkusb_usb3_capable(void) 181 { 182 return false; 183 } 184 185 static int rkusb_do_switch_to_usb3(struct fsg_common *common, 186 struct fsg_buffhd *bh) 187 { 188 g_dnl_set_serialnumber((char *)&common->cmnd[1]); 189 rkusb_switch_to_usb3_enable(true); 190 bh->state = BUF_STATE_EMPTY; 191 192 return 0; 193 } 194 195 static int rkusb_do_test_unit_ready(struct fsg_common *common, 196 struct fsg_buffhd *bh) 197 { 198 struct blk_desc *desc = &ums[common->lun].block_dev; 199 200 if ((desc->if_type == IF_TYPE_MTD && desc->devnum == BLK_MTD_SPI_NOR) || 201 desc->if_type == IF_TYPE_SPINOR) 202 common->residue = 0x03 << 24; /* 128KB Max block xfer for SPI Nor */ 203 else 204 common->residue = 0x06 << 24; /* Max block xfer support from host */ 205 206 common->data_dir = DATA_DIR_NONE; 207 bh->state = BUF_STATE_EMPTY; 208 209 return 0; 210 } 211 212 static int rkusb_do_read_flash_id(struct fsg_common *common, 213 struct fsg_buffhd *bh) 214 { 215 u8 *buf = (u8 *)bh->buf; 216 u32 len = 5; 217 enum if_type type = ums[common->lun].block_dev.if_type; 218 u32 devnum = ums[common->lun].block_dev.devnum; 219 const char *str; 220 221 switch (type) { 222 case IF_TYPE_MMC: 223 str = "EMMC "; 224 break; 225 case IF_TYPE_RKNAND: 226 str = "NAND "; 227 break; 228 case IF_TYPE_MTD: 229 if (devnum == BLK_MTD_SPI_NAND) 230 str ="SNAND"; 231 else if (devnum == BLK_MTD_NAND) 232 str = "NAND "; 233 else 234 str = "NOR "; 235 break; 236 default: 237 str = "UNKN "; /* unknown */ 238 break; 239 } 240 241 memcpy((void *)&buf[0], str, len); 242 243 /* Set data xfer size */ 244 common->residue = common->data_size_from_cmnd = len; 245 common->data_size = len; 246 247 return len; 248 } 249 250 static int rkusb_do_test_bad_block(struct fsg_common *common, 251 struct fsg_buffhd *bh) 252 { 253 u8 *buf = (u8 *)bh->buf; 254 u32 len = 64; 255 256 memset((void *)&buf[0], 0, len); 257 258 /* Set data xfer size */ 259 common->residue = common->data_size_from_cmnd = len; 260 common->data_size = len; 261 262 return len; 263 } 264 265 static int rkusb_do_read_flash_info(struct fsg_common *common, 266 struct fsg_buffhd *bh) 267 { 268 struct blk_desc *desc = &ums[common->lun].block_dev; 269 u8 *buf = (u8 *)bh->buf; 270 u32 len = sizeof(struct rk_flash_info); 271 struct rk_flash_info finfo = { 272 .block_size = ROCKCHIP_FLASH_BLOCK_SIZE, 273 .ecc_bits = 0, 274 .page_size = ROCKCHIP_FLASH_PAGE_SIZE, 275 .access_time = 40, 276 .manufacturer = 0, 277 .flash_mask = 0 278 }; 279 280 finfo.flash_size = (u32)desc->lba; 281 282 if (desc->if_type == IF_TYPE_MTD && 283 (desc->devnum == BLK_MTD_NAND || 284 desc->devnum == BLK_MTD_SPI_NAND)) { 285 struct mtd_info *mtd = (struct mtd_info *)desc->bdev->priv; 286 287 if (mtd) { 288 finfo.block_size = mtd->erasesize >> 9; 289 finfo.page_size = mtd->writesize >> 9; 290 } 291 } 292 293 if (desc->if_type == IF_TYPE_MTD && desc->devnum == BLK_MTD_SPI_NOR) { 294 /* RV1126/RK3308 mtd spinor keep the former upgrade mode */ 295 #if !defined(CONFIG_ROCKCHIP_RV1126) && !defined(CONFIG_ROCKCHIP_RK3308) 296 finfo.block_size = 0x80; /* Aligned to 64KB */ 297 #else 298 finfo.block_size = ROCKCHIP_FLASH_BLOCK_SIZE; 299 #endif 300 } 301 302 debug("Flash info: block_size= %x page_size= %x\n", finfo.block_size, 303 finfo.page_size); 304 305 if (finfo.flash_size) 306 finfo.flash_mask = 1; 307 308 memset((void *)&buf[0], 0, len); 309 memcpy((void *)&buf[0], (void *)&finfo, len); 310 311 /* Set data xfer size */ 312 common->residue = common->data_size_from_cmnd = len; 313 /* legacy upgrade_tool does not set correct transfer size */ 314 common->data_size = len; 315 316 return len; 317 } 318 319 static int rkusb_do_get_chip_info(struct fsg_common *common, 320 struct fsg_buffhd *bh) 321 { 322 u8 *buf = (u8 *)bh->buf; 323 u32 len = common->data_size; 324 u32 chip_info[4]; 325 326 memset((void *)chip_info, 0, sizeof(chip_info)); 327 rockchip_rockusb_get_chip_info(chip_info); 328 329 memset((void *)&buf[0], 0, len); 330 memcpy((void *)&buf[0], (void *)chip_info, len); 331 332 /* Set data xfer size */ 333 common->residue = common->data_size_from_cmnd = len; 334 335 return len; 336 } 337 338 static int rkusb_do_lba_erase(struct fsg_common *common, 339 struct fsg_buffhd *bh) 340 { 341 struct fsg_lun *curlun = &common->luns[common->lun]; 342 u32 lba, amount; 343 loff_t file_offset; 344 int rc; 345 346 lba = get_unaligned_be32(&common->cmnd[2]); 347 if (lba >= curlun->num_sectors) { 348 curlun->sense_data = SS_LOGICAL_BLOCK_ADDRESS_OUT_OF_RANGE; 349 rc = -EINVAL; 350 goto out; 351 } 352 353 file_offset = ((loff_t) lba) << 9; 354 amount = get_unaligned_be16(&common->cmnd[7]) << 9; 355 if (unlikely(amount == 0)) { 356 curlun->sense_data = SS_INVALID_FIELD_IN_CDB; 357 rc = -EIO; 358 goto out; 359 } 360 361 /* Perform the erase */ 362 rc = ums[common->lun].erase_sector(&ums[common->lun], 363 file_offset / SECTOR_SIZE, 364 amount / SECTOR_SIZE); 365 if (!rc) { 366 curlun->sense_data = SS_MEDIUM_NOT_PRESENT; 367 rc = -EIO; 368 } 369 370 out: 371 common->data_dir = DATA_DIR_NONE; 372 bh->state = BUF_STATE_EMPTY; 373 374 return rc; 375 } 376 377 static int rkusb_do_erase_force(struct fsg_common *common, 378 struct fsg_buffhd *bh) 379 { 380 struct blk_desc *desc = &ums[common->lun].block_dev; 381 struct fsg_lun *curlun = &common->luns[common->lun]; 382 u16 block_size = ROCKCHIP_FLASH_BLOCK_SIZE; 383 u32 lba, amount; 384 loff_t file_offset; 385 int rc; 386 387 lba = get_unaligned_be32(&common->cmnd[2]); 388 if (lba >= curlun->num_sectors) { 389 curlun->sense_data = SS_LOGICAL_BLOCK_ADDRESS_OUT_OF_RANGE; 390 rc = -EINVAL; 391 goto out; 392 } 393 394 if (desc->if_type == IF_TYPE_MTD && 395 (desc->devnum == BLK_MTD_NAND || 396 desc->devnum == BLK_MTD_SPI_NAND)) { 397 struct mtd_info *mtd = (struct mtd_info *)desc->bdev->priv; 398 399 if (mtd) 400 block_size = mtd->erasesize >> 9; 401 } 402 403 file_offset = ((loff_t)lba) * block_size; 404 amount = get_unaligned_be16(&common->cmnd[7]) * block_size; 405 406 debug("%s lba= %x, nsec= %x\n", __func__, lba, 407 (u32)get_unaligned_be16(&common->cmnd[7])); 408 409 if (unlikely(amount == 0)) { 410 curlun->sense_data = SS_INVALID_FIELD_IN_CDB; 411 rc = -EIO; 412 goto out; 413 } 414 415 /* Perform the erase */ 416 rc = ums[common->lun].erase_sector(&ums[common->lun], 417 file_offset, 418 amount); 419 if (!rc) { 420 curlun->sense_data = SS_MEDIUM_NOT_PRESENT; 421 rc = -EIO; 422 } 423 424 out: 425 common->data_dir = DATA_DIR_NONE; 426 bh->state = BUF_STATE_EMPTY; 427 428 return rc; 429 } 430 431 #ifdef CONFIG_ROCKCHIP_VENDOR_PARTITION 432 static int rkusb_do_vs_write(struct fsg_common *common) 433 { 434 struct fsg_lun *curlun = &common->luns[common->lun]; 435 u16 type = get_unaligned_be16(&common->cmnd[4]); 436 struct vendor_item *vhead; 437 struct fsg_buffhd *bh; 438 void *data; 439 int rc; 440 441 if (common->data_size >= (u32)65536) { 442 /* _MUST_ small than 64K */ 443 curlun->sense_data = SS_LOGICAL_BLOCK_ADDRESS_OUT_OF_RANGE; 444 return -EINVAL; 445 } 446 447 common->residue = common->data_size; 448 common->usb_amount_left = common->data_size; 449 450 /* Carry out the file writes */ 451 if (unlikely(common->data_size == 0)) 452 return -EIO; /* No data to write */ 453 454 for (;;) { 455 if (common->usb_amount_left > 0) { 456 /* Wait for the next buffer to become available */ 457 bh = common->next_buffhd_to_fill; 458 if (bh->state != BUF_STATE_EMPTY) 459 goto wait; 460 461 /* Request the next buffer */ 462 common->usb_amount_left -= common->data_size; 463 bh->outreq->length = common->data_size; 464 bh->bulk_out_intended_length = common->data_size; 465 bh->outreq->short_not_ok = 1; 466 467 START_TRANSFER_OR(common, bulk_out, bh->outreq, 468 &bh->outreq_busy, &bh->state) 469 /* 470 * Don't know what to do if 471 * common->fsg is NULL 472 */ 473 return -EIO; 474 common->next_buffhd_to_fill = bh->next; 475 } else { 476 /* Then, wait for the data to become available */ 477 bh = common->next_buffhd_to_drain; 478 if (bh->state != BUF_STATE_FULL) 479 goto wait; 480 481 common->next_buffhd_to_drain = bh->next; 482 bh->state = BUF_STATE_EMPTY; 483 484 /* Did something go wrong with the transfer? */ 485 if (bh->outreq->status != 0) { 486 curlun->sense_data = SS_COMMUNICATION_FAILURE; 487 curlun->info_valid = 1; 488 break; 489 } 490 491 /* Perform the write */ 492 vhead = (struct vendor_item *)bh->buf; 493 data = bh->buf + sizeof(struct vendor_item); 494 495 if (!type) { 496 #ifndef CONFIG_SUPPORT_USBPLUG 497 if (vhead->id == HDCP_14_HDMI_ID || 498 vhead->id == HDCP_14_HDMIRX_ID || 499 vhead->id == HDCP_14_DP_ID) { 500 rc = vendor_handle_hdcp(vhead); 501 if (rc < 0) { 502 curlun->sense_data = SS_WRITE_ERROR; 503 return -EIO; 504 } 505 } 506 #endif 507 508 /* Vendor storage */ 509 rc = vendor_storage_write(vhead->id, 510 (char __user *)data, 511 vhead->size); 512 if (rc < 0) { 513 curlun->sense_data = SS_WRITE_ERROR; 514 return -EIO; 515 } 516 } else if (type == 1) { 517 /* RPMB */ 518 rc = 519 write_keybox_to_secure_storage((u8 *)data, 520 vhead->size); 521 if (rc < 0) { 522 curlun->sense_data = SS_WRITE_ERROR; 523 return -EIO; 524 } 525 } else if (type == 2) { 526 /* security storage */ 527 #ifdef CONFIG_RK_AVB_LIBAVB_USER 528 debug("%s call rk_avb_write_perm_attr %d, %d\n", 529 __func__, vhead->id, vhead->size); 530 rc = rk_avb_write_perm_attr(vhead->id, 531 (char __user *)data, 532 vhead->size); 533 if (rc < 0) { 534 curlun->sense_data = SS_WRITE_ERROR; 535 return -EIO; 536 } 537 #else 538 printf("Please enable CONFIG_RK_AVB_LIBAVB_USER\n"); 539 #endif 540 } else if (type == 3) { 541 /* efuse or otp*/ 542 #ifdef CONFIG_OPTEE_CLIENT 543 if (memcmp(data, "TAEK", 4) == 0) { 544 if (vhead->size - 8 != 32) { 545 printf("check ta encryption key size fail!\n"); 546 curlun->sense_data = SS_WRITE_ERROR; 547 return -EIO; 548 } 549 if (trusty_write_ta_encryption_key((uint32_t *)(data + 8), 8) != 0) { 550 printf("trusty_write_ta_encryption_key error!"); 551 curlun->sense_data = SS_WRITE_ERROR; 552 return -EIO; 553 } 554 } else if (memcmp(data, "EHUK", 4) == 0) { 555 if (vhead->size - 8 != 32) { 556 printf("check oem huk size fail!\n"); 557 curlun->sense_data = SS_WRITE_ERROR; 558 return -EIO; 559 } 560 if (trusty_write_oem_huk((uint32_t *)(data + 8), 8) != 0) { 561 printf("trusty_write_oem_huk error!"); 562 curlun->sense_data = SS_WRITE_ERROR; 563 return -EIO; 564 } 565 } else { 566 printf("Unknown tag\n"); 567 curlun->sense_data = SS_WRITE_ERROR; 568 return -EIO; 569 } 570 #else 571 printf("Please enable CONFIG_OPTEE_CLIENT\n"); 572 #endif 573 } else { 574 return -EINVAL; 575 } 576 577 common->residue -= common->data_size; 578 579 /* Did the host decide to stop early? */ 580 if (bh->outreq->actual != bh->outreq->length) 581 common->short_packet_received = 1; 582 break; /* Command done */ 583 } 584 wait: 585 /* Wait for something to happen */ 586 rc = sleep_thread(common); 587 if (rc) 588 return rc; 589 } 590 591 return -EIO; /* No default reply */ 592 } 593 594 static int rkusb_do_vs_read(struct fsg_common *common) 595 { 596 struct fsg_lun *curlun = &common->luns[common->lun]; 597 u16 type = get_unaligned_be16(&common->cmnd[4]); 598 struct vendor_item *vhead; 599 struct fsg_buffhd *bh; 600 void *data; 601 int rc; 602 603 if (common->data_size >= (u32)65536) { 604 /* _MUST_ small than 64K */ 605 curlun->sense_data = SS_LOGICAL_BLOCK_ADDRESS_OUT_OF_RANGE; 606 return -EINVAL; 607 } 608 609 common->residue = common->data_size; 610 common->usb_amount_left = common->data_size; 611 612 /* Carry out the file reads */ 613 if (unlikely(common->data_size == 0)) 614 return -EIO; /* No default reply */ 615 616 for (;;) { 617 /* Wait for the next buffer to become available */ 618 bh = common->next_buffhd_to_fill; 619 while (bh->state != BUF_STATE_EMPTY) { 620 rc = sleep_thread(common); 621 if (rc) 622 return rc; 623 } 624 625 memset(bh->buf, 0, FSG_BUFLEN); 626 vhead = (struct vendor_item *)bh->buf; 627 data = bh->buf + sizeof(struct vendor_item); 628 vhead->id = get_unaligned_be16(&common->cmnd[2]); 629 630 if (!type) { 631 /* Vendor storage */ 632 rc = vendor_storage_read(vhead->id, 633 (char __user *)data, 634 common->data_size); 635 if (!rc) { 636 curlun->sense_data = SS_UNRECOVERED_READ_ERROR; 637 return -EIO; 638 } 639 vhead->size = rc; 640 } else if (type == 1) { 641 /* RPMB */ 642 rc = 643 read_raw_data_from_secure_storage((u8 *)data, 644 common->data_size); 645 if (!rc) { 646 curlun->sense_data = SS_UNRECOVERED_READ_ERROR; 647 return -EIO; 648 } 649 vhead->size = rc; 650 } else if (type == 2) { 651 /* security storage */ 652 #ifdef CONFIG_RK_AVB_LIBAVB_USER 653 rc = rk_avb_read_perm_attr(vhead->id, 654 (char __user *)data, 655 vhead->size); 656 if (rc < 0) 657 return -EIO; 658 vhead->size = rc; 659 #else 660 printf("Please enable CONFIG_RK_AVB_LIBAVB_USER!\n"); 661 #endif 662 } else if (type == 3) { 663 /* efuse or otp*/ 664 #ifdef CONFIG_OPTEE_CLIENT 665 if (vhead->id == 120) { 666 u8 value; 667 char *written_str = "key is written!"; 668 char *not_written_str = "key is not written!"; 669 if (trusty_ta_encryption_key_is_written(&value) != 0) { 670 printf("trusty_ta_encryption_key_is_written error!"); 671 return -EIO; 672 } 673 if (value) { 674 memcpy(data, written_str, strlen(written_str)); 675 vhead->size = strlen(written_str); 676 } else { 677 memcpy(data, not_written_str, strlen(not_written_str)); 678 vhead->size = strlen(not_written_str); 679 } 680 } else { 681 printf("Unknown tag\n"); 682 return -EIO; 683 } 684 #else 685 printf("Please enable CONFIG_OPTEE_CLIENT\n"); 686 #endif 687 } else { 688 return -EINVAL; 689 } 690 691 common->residue -= common->data_size; 692 bh->inreq->length = common->data_size; 693 bh->state = BUF_STATE_FULL; 694 695 break; /* No more left to read */ 696 } 697 698 return -EIO; /* No default reply */ 699 } 700 #endif 701 702 static int rkusb_do_switch_storage(struct fsg_common *common) 703 { 704 enum if_type type, cur_type = ums[common->lun].block_dev.if_type; 705 int devnum, cur_devnum = ums[common->lun].block_dev.devnum; 706 struct blk_desc *block_dev; 707 u32 media = BOOT_TYPE_UNKNOWN; 708 709 media = 1 << common->cmnd[1]; 710 711 switch (media) { 712 #ifdef CONFIG_MMC 713 case BOOT_TYPE_EMMC: 714 type = IF_TYPE_MMC; 715 devnum = 0; 716 mmc_initialize(gd->bd); 717 break; 718 #endif 719 case BOOT_TYPE_MTD_BLK_NAND: 720 type = IF_TYPE_MTD; 721 devnum = 0; 722 break; 723 case BOOT_TYPE_MTD_BLK_SPI_NAND: 724 type = IF_TYPE_MTD; 725 devnum = 1; 726 break; 727 case BOOT_TYPE_MTD_BLK_SPI_NOR: 728 type = IF_TYPE_MTD; 729 devnum = 2; 730 break; 731 default: 732 printf("Bootdev 0x%x is not support\n", media); 733 return -ENODEV; 734 } 735 736 if (cur_type == type && cur_devnum == devnum) 737 return 0; 738 739 #if CONFIG_IS_ENABLED(SUPPORT_USBPLUG) 740 block_dev = usbplug_blk_get_devnum_by_type(type, devnum); 741 #else 742 block_dev = blk_get_devnum_by_type(type, devnum); 743 #endif 744 if (!block_dev) { 745 printf("Bootdev if_type=%d num=%d toggle fail\n", type, devnum); 746 return -ENODEV; 747 } 748 749 ums[common->lun].num_sectors = block_dev->lba; 750 ums[common->lun].block_dev = *block_dev; 751 752 printf("RKUSB: LUN %d, dev %d, hwpart %d, sector %#x, count %#x\n", 753 0, 754 ums[common->lun].block_dev.devnum, 755 ums[common->lun].block_dev.hwpart, 756 ums[common->lun].start_sector, 757 ums[common->lun].num_sectors); 758 759 return 0; 760 } 761 762 static int rkusb_do_get_storage_info(struct fsg_common *common, 763 struct fsg_buffhd *bh) 764 { 765 enum if_type type = ums[common->lun].block_dev.if_type; 766 int devnum = ums[common->lun].block_dev.devnum; 767 u32 media = BOOT_TYPE_UNKNOWN; 768 u32 len = common->data_size; 769 u8 *buf = (u8 *)bh->buf; 770 771 if (len > 4) 772 len = 4; 773 774 switch (type) { 775 case IF_TYPE_MMC: 776 media = BOOT_TYPE_EMMC; 777 break; 778 779 case IF_TYPE_SD: 780 media = BOOT_TYPE_SD0; 781 break; 782 783 case IF_TYPE_MTD: 784 if (devnum == BLK_MTD_SPI_NAND) 785 media = BOOT_TYPE_MTD_BLK_SPI_NAND; 786 else if (devnum == BLK_MTD_NAND) 787 media = BOOT_TYPE_NAND; 788 else 789 media = BOOT_TYPE_MTD_BLK_SPI_NOR; 790 break; 791 792 case IF_TYPE_SCSI: 793 media = BOOT_TYPE_SATA; 794 break; 795 796 case IF_TYPE_RKNAND: 797 media = BOOT_TYPE_NAND; 798 break; 799 800 case IF_TYPE_NVME: 801 media = BOOT_TYPE_PCIE; 802 break; 803 804 default: 805 break; 806 } 807 808 memcpy((void *)&buf[0], (void *)&media, len); 809 common->residue = len; 810 common->data_size_from_cmnd = len; 811 812 return len; 813 } 814 815 static int rkusb_do_read_capacity(struct fsg_common *common, 816 struct fsg_buffhd *bh) 817 { 818 u8 *buf = (u8 *)bh->buf; 819 u32 len = common->data_size; 820 enum if_type type = ums[common->lun].block_dev.if_type; 821 int devnum = ums[common->lun].block_dev.devnum; 822 823 /* 824 * bit[0]: Direct LBA, 0: Disabled; 825 * bit[1]: Vendor Storage API, 0: Disabed (default); 826 * bit[2]: First 4M Access, 0: Disabled; 827 * bit[3]: Read LBA On, 0: Disabed (default); 828 * bit[4]: New Vendor Storage API, 0: Disabed; 829 * bit[5]: Read uart data from ram 830 * bit[6]: Read IDB config 831 * bit[7]: Read SecureMode 832 * bit[8]: New IDB feature 833 * bit[9]: Get storage media info 834 * bit[10:63}: Reserved. 835 */ 836 memset((void *)&buf[0], 0, len); 837 if (type == IF_TYPE_MMC || type == IF_TYPE_SD || type == IF_TYPE_NVME) 838 buf[0] = BIT(0) | BIT(2) | BIT(4); 839 else 840 buf[0] = BIT(0) | BIT(4); 841 842 if (type == IF_TYPE_MTD && 843 (devnum == BLK_MTD_NAND || 844 devnum == BLK_MTD_SPI_NAND)) 845 buf[0] |= (1 << 6); 846 847 #if !defined(CONFIG_ROCKCHIP_RV1126) && !defined(CONFIG_ROCKCHIP_RK3308) 848 if (type == IF_TYPE_MTD && devnum == BLK_MTD_SPI_NOR) 849 buf[0] |= (1 << 6); 850 #endif 851 852 #if defined(CONFIG_ROCKCHIP_NEW_IDB) 853 buf[1] = BIT(0); 854 #endif 855 buf[1] |= BIT(1); /* Switch Storage */ 856 buf[1] |= BIT(2); /* LBAwrite Parity */ 857 858 if (rkusb_usb3_capable() && !rkusb_force_usb2_enabled()) 859 buf[1] |= BIT(4); 860 else 861 buf[1] &= ~BIT(4); 862 863 /* Set data xfer size */ 864 common->residue = len; 865 common->data_size_from_cmnd = len; 866 867 return len; 868 } 869 870 static void rkusb_fixup_cbwcb(struct fsg_common *common, 871 struct fsg_buffhd *bh) 872 { 873 struct usb_request *req = bh->outreq; 874 struct fsg_bulk_cb_wrap *cbw = req->buf; 875 876 /* FIXME cbw.DataTransferLength was not set by Upgrade Tool */ 877 common->data_size = le32_to_cpu(cbw->DataTransferLength); 878 if (common->data_size == 0) { 879 common->data_size = 880 get_unaligned_be16(&common->cmnd[7]) << 9; 881 printf("Trasfer Length NOT set, please use new version tool\n"); 882 debug("%s %d, cmnd1 %x\n", __func__, 883 get_unaligned_be16(&common->cmnd[7]), 884 get_unaligned_be16(&common->cmnd[1])); 885 } 886 if (cbw->Flags & USB_BULK_IN_FLAG) 887 common->data_dir = DATA_DIR_TO_HOST; 888 else 889 common->data_dir = DATA_DIR_FROM_HOST; 890 891 /* Not support */ 892 common->cmnd[1] = 0; 893 } 894 895 static int rkusb_cmd_process(struct fsg_common *common, 896 struct fsg_buffhd *bh, int *reply) 897 { 898 struct usb_request *req = bh->outreq; 899 struct fsg_bulk_cb_wrap *cbw = req->buf; 900 int rc; 901 902 dump_cbw(cbw); 903 904 if (rkusb_check_lun(common)) { 905 *reply = -EINVAL; 906 return RKUSB_RC_ERROR; 907 } 908 909 switch (common->cmnd[0]) { 910 case RKUSB_TEST_UNIT_READY: 911 *reply = rkusb_do_test_unit_ready(common, bh); 912 rc = RKUSB_RC_FINISHED; 913 break; 914 915 case RKUSB_READ_FLASH_ID: 916 *reply = rkusb_do_read_flash_id(common, bh); 917 rc = RKUSB_RC_FINISHED; 918 break; 919 920 case RKUSB_TEST_BAD_BLOCK: 921 *reply = rkusb_do_test_bad_block(common, bh); 922 rc = RKUSB_RC_FINISHED; 923 break; 924 925 case RKUSB_ERASE_10_FORCE: 926 *reply = rkusb_do_erase_force(common, bh); 927 rc = RKUSB_RC_FINISHED; 928 break; 929 930 case RKUSB_LBA_READ_10: 931 rkusb_fixup_cbwcb(common, bh); 932 common->cmnd[0] = SC_READ_10; 933 common->cmnd[1] = 0; /* Not support */ 934 rc = RKUSB_RC_CONTINUE; 935 break; 936 937 case RKUSB_LBA_WRITE_10: 938 rkusb_fixup_cbwcb(common, bh); 939 common->cmnd[0] = SC_WRITE_10; 940 common->cmnd[1] = 0; /* Not support */ 941 rc = RKUSB_RC_CONTINUE; 942 break; 943 944 case RKUSB_READ_FLASH_INFO: 945 *reply = rkusb_do_read_flash_info(common, bh); 946 rc = RKUSB_RC_FINISHED; 947 break; 948 949 case RKUSB_GET_CHIP_VER: 950 *reply = rkusb_do_get_chip_info(common, bh); 951 rc = RKUSB_RC_FINISHED; 952 break; 953 954 case RKUSB_LBA_ERASE: 955 *reply = rkusb_do_lba_erase(common, bh); 956 rc = RKUSB_RC_FINISHED; 957 break; 958 959 #ifdef CONFIG_ROCKCHIP_VENDOR_PARTITION 960 case RKUSB_VS_WRITE: 961 *reply = rkusb_do_vs_write(common); 962 rc = RKUSB_RC_FINISHED; 963 break; 964 965 case RKUSB_VS_READ: 966 *reply = rkusb_do_vs_read(common); 967 rc = RKUSB_RC_FINISHED; 968 break; 969 #endif 970 case RKUSB_SWITCH_STORAGE: 971 *reply = rkusb_do_switch_storage(common); 972 rc = RKUSB_RC_FINISHED; 973 break; 974 case RKUSB_GET_STORAGE_MEDIA: 975 *reply = rkusb_do_get_storage_info(common, bh); 976 rc = RKUSB_RC_FINISHED; 977 break; 978 979 case RKUSB_READ_CAPACITY: 980 *reply = rkusb_do_read_capacity(common, bh); 981 rc = RKUSB_RC_FINISHED; 982 break; 983 984 case RKUSB_SWITCH_USB3: 985 *reply = rkusb_do_switch_to_usb3(common, bh); 986 rc = RKUSB_RC_FINISHED; 987 break; 988 989 case RKUSB_RESET: 990 *reply = rkusb_do_reset(common, bh); 991 rc = RKUSB_RC_FINISHED; 992 break; 993 994 case RKUSB_READ_10: 995 case RKUSB_WRITE_10: 996 printf("CMD Not support, pls use new version Tool\n"); 997 case RKUSB_SET_DEVICE_ID: 998 case RKUSB_ERASE_10: 999 case RKUSB_WRITE_SPARE: 1000 case RKUSB_READ_SPARE: 1001 case RKUSB_GET_VERSION: 1002 case RKUSB_ERASE_SYS_DISK: 1003 case RKUSB_SDRAM_READ_10: 1004 case RKUSB_SDRAM_WRITE_10: 1005 case RKUSB_SDRAM_EXECUTE: 1006 case RKUSB_LOW_FORMAT: 1007 case RKUSB_SET_RESET_FLAG: 1008 case RKUSB_SPI_READ_10: 1009 case RKUSB_SPI_WRITE_10: 1010 case RKUSB_SESSION: 1011 /* Fall through */ 1012 default: 1013 rc = RKUSB_RC_UNKNOWN_CMND; 1014 break; 1015 } 1016 1017 return rc; 1018 } 1019 1020 int rkusb_do_check_parity(struct fsg_common *common) 1021 { 1022 int ret = 0, rc; 1023 u32 parity, i, usb_parity, lba, len; 1024 static u32 usb_check_buffer[1024 * 256]; 1025 1026 usb_parity = common->cmnd[9] | (common->cmnd[10] << 8) | 1027 (common->cmnd[11] << 16) | (common->cmnd[12] << 24); 1028 1029 if (common->cmnd[0] == SC_WRITE_10 && (usb_parity)) { 1030 lba = get_unaligned_be32(&common->cmnd[2]); 1031 len = common->data_size_from_cmnd >> 9; 1032 rc = blk_dread(&ums[common->lun].block_dev, lba, len, usb_check_buffer); 1033 parity = 0x000055aa; 1034 for (i = 0; i < len * 128; i++) 1035 parity += usb_check_buffer[i]; 1036 if (!rc || parity != usb_parity) 1037 common->phase_error = 1; 1038 } 1039 1040 return ret; 1041 } 1042 1043 DECLARE_GADGET_BIND_CALLBACK(rkusb_ums_dnl, fsg_add); 1044