Sridhar Siricilla | f87ff33 | 2019-09-12 17:18:20 +0530 | [diff] [blame] | 1 | /* SPDX-License-Identifier: GPL-2.0-only */ |
Sridhar Siricilla | f87ff33 | 2019-09-12 17:18:20 +0530 | [diff] [blame] | 2 | #include <bootstate.h> |
| 3 | #include <console/console.h> |
Rizwan Qureshi | ec32109 | 2019-09-06 20:28:43 +0530 | [diff] [blame] | 4 | #include <boot_device.h> |
| 5 | #include <cbfs.h> |
| 6 | #include <commonlib/cbfs.h> |
| 7 | #include <commonlib/region.h> |
| 8 | #include <fmap.h> |
Sridhar Siricilla | f87ff33 | 2019-09-12 17:18:20 +0530 | [diff] [blame] | 9 | #include <intelblocks/cse.h> |
| 10 | #include <security/vboot/vboot_common.h> |
Sridhar Siricilla | 87e36c4 | 2020-05-03 19:08:18 +0530 | [diff] [blame] | 11 | #include <security/vboot/misc.h> |
Rizwan Qureshi | ec32109 | 2019-09-06 20:28:43 +0530 | [diff] [blame] | 12 | #include <soc/intel/common/reset.h> |
| 13 | |
Sridhar Siricilla | f87ff33 | 2019-09-12 17:18:20 +0530 | [diff] [blame] | 14 | /* Converts bp index to boot partition string */ |
| 15 | #define GET_BP_STR(bp_index) (bp_index ? "RW" : "RO") |
| 16 | |
Rizwan Qureshi | ec32109 | 2019-09-06 20:28:43 +0530 | [diff] [blame] | 17 | /* CSE RW boot partition signature */ |
| 18 | #define CSE_RW_SIGNATURE 0x000055aa |
| 19 | |
| 20 | /* CSE RW boot partition signature size */ |
| 21 | #define CSE_RW_SIGN_SIZE sizeof(uint32_t) |
| 22 | |
Sridhar Siricilla | f87ff33 | 2019-09-12 17:18:20 +0530 | [diff] [blame] | 23 | /* |
Sridhar Siricilla | 99dbca3 | 2020-05-12 21:05:04 +0530 | [diff] [blame] | 24 | * CSE Firmware supports 3 boot partitions. For CSE Lite SKU, only 2 boot partitions are |
Sridhar Siricilla | f87ff33 | 2019-09-12 17:18:20 +0530 | [diff] [blame] | 25 | * used and 3rd boot partition is set to BP_STATUS_PARTITION_NOT_PRESENT. |
Sridhar Siricilla | 99dbca3 | 2020-05-12 21:05:04 +0530 | [diff] [blame] | 26 | * CSE Lite SKU Image Layout: |
Sridhar Siricilla | f87ff33 | 2019-09-12 17:18:20 +0530 | [diff] [blame] | 27 | * ------------- ------------------- --------------------- |
| 28 | * |CSE REGION | => | RO | RW | DATA | => | BP1 | BP2 | DATA | |
| 29 | * ------------- ------------------- --------------------- |
| 30 | */ |
| 31 | #define CSE_MAX_BOOT_PARTITIONS 3 |
| 32 | |
Sridhar Siricilla | 99dbca3 | 2020-05-12 21:05:04 +0530 | [diff] [blame] | 33 | /* CSE Lite SKU's valid bootable partition identifiers */ |
Sridhar Siricilla | f87ff33 | 2019-09-12 17:18:20 +0530 | [diff] [blame] | 34 | enum boot_partition_id { |
Rizwan Qureshi | ec32109 | 2019-09-06 20:28:43 +0530 | [diff] [blame] | 35 | /* RO(BP1) contains recovery/minimal boot firmware */ |
Sridhar Siricilla | f87ff33 | 2019-09-12 17:18:20 +0530 | [diff] [blame] | 36 | RO = 0, |
| 37 | |
Rizwan Qureshi | ec32109 | 2019-09-06 20:28:43 +0530 | [diff] [blame] | 38 | /* RW(BP2) contains fully functional CSE firmware */ |
Sridhar Siricilla | f87ff33 | 2019-09-12 17:18:20 +0530 | [diff] [blame] | 39 | RW = 1 |
| 40 | }; |
| 41 | |
Sridhar Siricilla | 87e36c4 | 2020-05-03 19:08:18 +0530 | [diff] [blame] | 42 | /* CSE recovery sub-error codes */ |
| 43 | enum csme_failure_reason { |
Sridhar Siricilla | 361e364 | 2020-10-18 20:14:07 +0530 | [diff] [blame] | 44 | |
| 45 | /* No error */ |
| 46 | CSE_LITE_SKU_NO_ERROR = 0, |
| 47 | |
Sridhar Siricilla | 87e36c4 | 2020-05-03 19:08:18 +0530 | [diff] [blame] | 48 | /* Unspecified error */ |
| 49 | CSE_LITE_SKU_UNSPECIFIED = 1, |
| 50 | |
| 51 | /* CSE fails to boot from RW */ |
| 52 | CSE_LITE_SKU_RW_JUMP_ERROR = 2, |
| 53 | |
| 54 | /* CSE RW boot partition access error */ |
| 55 | CSE_LITE_SKU_RW_ACCESS_ERROR = 3, |
| 56 | |
| 57 | /* Fails to set next boot partition as RW */ |
| 58 | CSE_LITE_SKU_RW_SWITCH_ERROR = 4, |
| 59 | |
| 60 | /* CSE firmware update failure */ |
| 61 | CSE_LITE_SKU_FW_UPDATE_ERROR = 5, |
| 62 | |
| 63 | /* Fails to communicate with CSE */ |
| 64 | CSE_LITE_SKU_COMMUNICATION_ERROR = 6, |
| 65 | |
| 66 | /* Fails to wipe CSE runtime data */ |
Sridhar Siricilla | 361e364 | 2020-10-18 20:14:07 +0530 | [diff] [blame] | 67 | CSE_LITE_SKU_DATA_WIPE_ERROR = 7, |
| 68 | |
| 69 | /* CSE RW is not found */ |
| 70 | CSE_LITE_SKU_RW_BLOB_NOT_FOUND = 8, |
| 71 | |
| 72 | /* CSE CBFS RW SHA-256 mismatch with the provided SHA */ |
| 73 | CSE_LITE_SKU_RW_BLOB_SHA256_MISMATCH = 9, |
| 74 | |
| 75 | /* CSE CBFS RW metadata is not found */ |
| 76 | CSE_LITE_SKU_RW_METADATA_NOT_FOUND = 10, |
Sridhar Siricilla | 87e36c4 | 2020-05-03 19:08:18 +0530 | [diff] [blame] | 77 | }; |
| 78 | |
Sridhar Siricilla | f87ff33 | 2019-09-12 17:18:20 +0530 | [diff] [blame] | 79 | /* |
| 80 | * Boot partition status. |
| 81 | * The status is returned in response to MKHI_BUP_COMMON_GET_BOOT_PARTITION_INFO cmd. |
| 82 | */ |
| 83 | enum bp_status { |
| 84 | /* This value is returned when a partition has no errors */ |
| 85 | BP_STATUS_SUCCESS = 0, |
| 86 | |
| 87 | /* |
| 88 | * This value is returned when a partition should be present based on layout, but it is |
| 89 | * not valid. |
| 90 | */ |
| 91 | BP_STATUS_GENERAL_FAILURE = 1, |
| 92 | |
| 93 | /* This value is returned when a partition is not present per initial image layout */ |
| 94 | BP_STATUS_PARTITION_NOT_PRESENT = 2, |
| 95 | |
Sridhar Siricilla | 2f6d555 | 2020-04-19 23:39:02 +0530 | [diff] [blame] | 96 | /* |
| 97 | * This value is returned when unexpected issues are detected in CSE Data area |
| 98 | * and CSE TCB-SVN downgrade scenario. |
| 99 | */ |
| 100 | BP_STATUS_DATA_FAILURE = 3, |
Sridhar Siricilla | f87ff33 | 2019-09-12 17:18:20 +0530 | [diff] [blame] | 101 | }; |
| 102 | |
| 103 | /* |
| 104 | * Boot Partition Info Flags |
| 105 | * The flags are returned in response to MKHI_BUP_COMMON_GET_BOOT_PARTITION_INFO cmd. |
| 106 | */ |
| 107 | enum bp_info_flags { |
| 108 | |
| 109 | /* Redundancy Enabled: It indicates CSE supports RO(BP1) and RW(BP2) regions */ |
| 110 | BP_INFO_REDUNDANCY_EN = 1 << 0, |
| 111 | |
| 112 | /* It indicates RO(BP1) supports Minimal Recovery Mode */ |
| 113 | BP_INFO_MIN_RECOV_MODE_EN = 1 << 1, |
| 114 | |
| 115 | /* |
| 116 | * Read-only Config Enabled: It indicates HW protection to CSE RO region is enabled. |
| 117 | * The option is relevant only if the BP_INFO_MIN_RECOV_MODE_EN flag is enabled. |
| 118 | */ |
| 119 | BP_INFO_READ_ONLY_CFG = 1 << 2, |
| 120 | }; |
| 121 | |
Sridhar Siricilla | f87ff33 | 2019-09-12 17:18:20 +0530 | [diff] [blame] | 122 | /* CSE boot partition entry info */ |
| 123 | struct cse_bp_entry { |
| 124 | /* Boot partition version */ |
| 125 | struct fw_version fw_ver; |
| 126 | |
| 127 | /* Boot partition status */ |
| 128 | uint32_t status; |
| 129 | |
| 130 | /* Starting offset of the partition within CSE region */ |
| 131 | uint32_t start_offset; |
| 132 | |
| 133 | /* Ending offset of the partition within CSE region */ |
| 134 | uint32_t end_offset; |
| 135 | uint8_t reserved[12]; |
| 136 | } __packed; |
| 137 | |
| 138 | /* CSE boot partition info */ |
| 139 | struct cse_bp_info { |
| 140 | /* Number of boot partitions */ |
| 141 | uint8_t total_number_of_bp; |
| 142 | |
| 143 | /* Current boot partition */ |
| 144 | uint8_t current_bp; |
| 145 | |
| 146 | /* Next boot partition */ |
| 147 | uint8_t next_bp; |
| 148 | |
| 149 | /* Boot Partition Info Flags */ |
| 150 | uint8_t flags; |
| 151 | |
| 152 | /* Boot Partition Entry Info */ |
| 153 | struct cse_bp_entry bp_entries[CSE_MAX_BOOT_PARTITIONS]; |
| 154 | } __packed; |
| 155 | |
| 156 | struct get_bp_info_rsp { |
| 157 | struct mkhi_hdr hdr; |
| 158 | struct cse_bp_info bp_info; |
| 159 | } __packed; |
| 160 | |
Sridhar Siricilla | 33aa115 | 2020-06-26 14:29:40 +0530 | [diff] [blame] | 161 | static void cse_log_status_registers(void) |
| 162 | { |
| 163 | printk(BIOS_DEBUG, "cse_lite: CSE status registers: HFSTS1: 0x%x, HFSTS2: 0x%x " |
| 164 | "HFSTS3: 0x%x\n", me_read_config32(PCI_ME_HFSTS1), |
| 165 | me_read_config32(PCI_ME_HFSTS2), me_read_config32(PCI_ME_HFSTS3)); |
| 166 | } |
| 167 | |
Sridhar Siricilla | 87e36c4 | 2020-05-03 19:08:18 +0530 | [diff] [blame] | 168 | static void cse_trigger_recovery(uint8_t rec_sub_code) |
| 169 | { |
Sridhar Siricilla | 33aa115 | 2020-06-26 14:29:40 +0530 | [diff] [blame] | 170 | /* Log CSE Firmware Status Registers to help debugging */ |
| 171 | cse_log_status_registers(); |
Sridhar Siricilla | 87e36c4 | 2020-05-03 19:08:18 +0530 | [diff] [blame] | 172 | if (CONFIG(VBOOT)) { |
Subrata Banik | 754de4d | 2020-09-15 15:16:42 +0530 | [diff] [blame] | 173 | struct vb2_context *ctx = vboot_get_context(); |
| 174 | if (ctx == NULL) |
| 175 | goto failure; |
Sridhar Siricilla | 87e36c4 | 2020-05-03 19:08:18 +0530 | [diff] [blame] | 176 | vb2api_fail(ctx, VB2_RECOVERY_INTEL_CSE_LITE_SKU, rec_sub_code); |
| 177 | vboot_save_data(ctx); |
| 178 | vboot_reboot(); |
| 179 | } |
Subrata Banik | 754de4d | 2020-09-15 15:16:42 +0530 | [diff] [blame] | 180 | failure: |
Sridhar Siricilla | 87e36c4 | 2020-05-03 19:08:18 +0530 | [diff] [blame] | 181 | die("cse_lite: Failed to trigger recovery mode(recovery subcode:%d)\n", rec_sub_code); |
| 182 | } |
| 183 | |
Sridhar Siricilla | f87ff33 | 2019-09-12 17:18:20 +0530 | [diff] [blame] | 184 | static uint8_t cse_get_current_bp(const struct cse_bp_info *cse_bp_info) |
| 185 | { |
| 186 | return cse_bp_info->current_bp; |
| 187 | } |
| 188 | |
| 189 | static const struct cse_bp_entry *cse_get_bp_entry(enum boot_partition_id bp, |
| 190 | const struct cse_bp_info *cse_bp_info) |
| 191 | { |
| 192 | return &cse_bp_info->bp_entries[bp]; |
| 193 | } |
| 194 | |
| 195 | static void cse_print_boot_partition_info(const struct cse_bp_info *cse_bp_info) |
| 196 | { |
| 197 | const struct cse_bp_entry *cse_bp; |
| 198 | |
Sridhar Siricilla | 9f71b17 | 2020-06-01 14:50:52 +0530 | [diff] [blame] | 199 | printk(BIOS_DEBUG, "cse_lite: Number of partitions = %d\n", |
| 200 | cse_bp_info->total_number_of_bp); |
| 201 | printk(BIOS_DEBUG, "cse_lite: Current partition = %s\n", |
| 202 | GET_BP_STR(cse_bp_info->current_bp)); |
| 203 | printk(BIOS_DEBUG, "cse_lite: Next partition = %s\n", GET_BP_STR(cse_bp_info->next_bp)); |
| 204 | printk(BIOS_DEBUG, "cse_lite: Flags = 0x%x\n", cse_bp_info->flags); |
Sridhar Siricilla | f87ff33 | 2019-09-12 17:18:20 +0530 | [diff] [blame] | 205 | |
| 206 | /* Log version info of RO & RW partitions */ |
| 207 | cse_bp = cse_get_bp_entry(RO, cse_bp_info); |
Sridhar Siricilla | 9f71b17 | 2020-06-01 14:50:52 +0530 | [diff] [blame] | 208 | printk(BIOS_DEBUG, "cse_lite: %s version = %d.%d.%d.%d (Status=0x%x, Start=0x%x, End=0x%x)\n", |
Sridhar Siricilla | f87ff33 | 2019-09-12 17:18:20 +0530 | [diff] [blame] | 209 | GET_BP_STR(RO), cse_bp->fw_ver.major, cse_bp->fw_ver.minor, |
| 210 | cse_bp->fw_ver.hotfix, cse_bp->fw_ver.build, |
| 211 | cse_bp->status, cse_bp->start_offset, |
| 212 | cse_bp->end_offset); |
| 213 | |
| 214 | cse_bp = cse_get_bp_entry(RW, cse_bp_info); |
Sridhar Siricilla | 9f71b17 | 2020-06-01 14:50:52 +0530 | [diff] [blame] | 215 | printk(BIOS_DEBUG, "cse_lite: %s version = %d.%d.%d.%d (Status=0x%x, Start=0x%x, End=0x%x)\n", |
Sridhar Siricilla | f87ff33 | 2019-09-12 17:18:20 +0530 | [diff] [blame] | 216 | GET_BP_STR(RW), cse_bp->fw_ver.major, cse_bp->fw_ver.minor, |
| 217 | cse_bp->fw_ver.hotfix, cse_bp->fw_ver.build, |
| 218 | cse_bp->status, cse_bp->start_offset, |
| 219 | cse_bp->end_offset); |
| 220 | } |
| 221 | |
| 222 | /* |
| 223 | * Checks prerequisites for MKHI_BUP_COMMON_GET_BOOT_PARTITION_INFO and |
| 224 | * MKHI_BUP_COMMON_SET_BOOT_PARTITION_INFO HECI commands. |
| 225 | * It allows execution of the Boot Partition commands in below scenarios: |
| 226 | * - When CSE boots from RW partition (COM: Normal and CWS: Normal) |
| 227 | * - When CSE boots from RO partition (COM: Soft Temp Disable and CWS: Normal) |
| 228 | * - After HMRFPO_ENABLE command is issued to CSE (COM: SECOVER_MEI_MSG and CWS: Normal) |
Rizwan Qureshi | ec32109 | 2019-09-06 20:28:43 +0530 | [diff] [blame] | 229 | * The prerequisite check should be handled in cse_get_bp_info() and |
| 230 | * cse_set_next_boot_partition() since the CSE's current operation mode is changed between these |
| 231 | * cmd handler calls. |
Sridhar Siricilla | f87ff33 | 2019-09-12 17:18:20 +0530 | [diff] [blame] | 232 | */ |
| 233 | static bool cse_is_bp_cmd_info_possible(void) |
| 234 | { |
| 235 | if (cse_is_hfs1_cws_normal()) { |
| 236 | if (cse_is_hfs1_com_normal()) |
| 237 | return true; |
| 238 | if (cse_is_hfs1_com_secover_mei_msg()) |
| 239 | return true; |
| 240 | if (cse_is_hfs1_com_soft_temp_disable()) |
| 241 | return true; |
| 242 | } |
| 243 | return false; |
| 244 | } |
| 245 | |
| 246 | static bool cse_get_bp_info(struct get_bp_info_rsp *bp_info_rsp) |
| 247 | { |
| 248 | struct get_bp_info_req { |
| 249 | struct mkhi_hdr hdr; |
| 250 | uint8_t reserved[4]; |
| 251 | } __packed; |
| 252 | |
| 253 | struct get_bp_info_req info_req = { |
| 254 | .hdr.group_id = MKHI_GROUP_ID_BUP_COMMON, |
| 255 | .hdr.command = MKHI_BUP_COMMON_GET_BOOT_PARTITION_INFO, |
| 256 | .reserved = {0}, |
| 257 | }; |
| 258 | |
| 259 | if (!cse_is_bp_cmd_info_possible()) { |
Sridhar Siricilla | 9f71b17 | 2020-06-01 14:50:52 +0530 | [diff] [blame] | 260 | printk(BIOS_ERR, "cse_lite: CSE does not meet prerequisites\n"); |
Sridhar Siricilla | f87ff33 | 2019-09-12 17:18:20 +0530 | [diff] [blame] | 261 | return false; |
| 262 | } |
| 263 | |
| 264 | size_t resp_size = sizeof(struct get_bp_info_rsp); |
| 265 | |
| 266 | if (!heci_send_receive(&info_req, sizeof(info_req), bp_info_rsp, &resp_size)) { |
Sridhar Siricilla | 9f71b17 | 2020-06-01 14:50:52 +0530 | [diff] [blame] | 267 | printk(BIOS_ERR, "cse_lite: Could not get partition info\n"); |
Sridhar Siricilla | f87ff33 | 2019-09-12 17:18:20 +0530 | [diff] [blame] | 268 | return false; |
| 269 | } |
| 270 | |
| 271 | if (bp_info_rsp->hdr.result) { |
Sridhar Siricilla | 9f71b17 | 2020-06-01 14:50:52 +0530 | [diff] [blame] | 272 | printk(BIOS_ERR, "cse_lite: Get partition info resp failed: %d\n", |
Sridhar Siricilla | f87ff33 | 2019-09-12 17:18:20 +0530 | [diff] [blame] | 273 | bp_info_rsp->hdr.result); |
| 274 | return false; |
| 275 | } |
| 276 | |
| 277 | cse_print_boot_partition_info(&bp_info_rsp->bp_info); |
| 278 | |
| 279 | return true; |
| 280 | } |
| 281 | /* |
| 282 | * It sends HECI command to notify CSE about its next boot partition. When coreboot wants |
| 283 | * CSE to boot from certain partition (BP1 <RO> or BP2 <RW>), then this command can be used. |
| 284 | * The CSE's valid bootable partitions are BP1(RO) and BP2(RW). |
| 285 | * This function must be used before EOP. |
| 286 | * Returns false on failure and true on success. |
| 287 | */ |
| 288 | static bool cse_set_next_boot_partition(enum boot_partition_id bp) |
| 289 | { |
| 290 | struct set_boot_partition_info_req { |
| 291 | struct mkhi_hdr hdr; |
| 292 | uint8_t next_bp; |
| 293 | uint8_t reserved[3]; |
| 294 | } __packed; |
| 295 | |
| 296 | struct set_boot_partition_info_req switch_req = { |
| 297 | .hdr.group_id = MKHI_GROUP_ID_BUP_COMMON, |
| 298 | .hdr.command = MKHI_BUP_COMMON_SET_BOOT_PARTITION_INFO, |
| 299 | .next_bp = bp, |
| 300 | .reserved = {0}, |
| 301 | }; |
| 302 | |
| 303 | if (bp != RO && bp != RW) { |
Sridhar Siricilla | 9f71b17 | 2020-06-01 14:50:52 +0530 | [diff] [blame] | 304 | printk(BIOS_ERR, "cse_lite: Incorrect partition id(%d) is provided", bp); |
Sridhar Siricilla | f87ff33 | 2019-09-12 17:18:20 +0530 | [diff] [blame] | 305 | return false; |
| 306 | } |
| 307 | |
Sridhar Siricilla | 9f71b17 | 2020-06-01 14:50:52 +0530 | [diff] [blame] | 308 | printk(BIOS_INFO, "cse_lite: Set Boot Partition Info Command (%s)\n", GET_BP_STR(bp)); |
Sridhar Siricilla | f87ff33 | 2019-09-12 17:18:20 +0530 | [diff] [blame] | 309 | |
| 310 | if (!cse_is_bp_cmd_info_possible()) { |
Sridhar Siricilla | 9f71b17 | 2020-06-01 14:50:52 +0530 | [diff] [blame] | 311 | printk(BIOS_ERR, "cse_lite: CSE does not meet prerequisites\n"); |
Sridhar Siricilla | f87ff33 | 2019-09-12 17:18:20 +0530 | [diff] [blame] | 312 | return false; |
| 313 | } |
| 314 | |
| 315 | struct mkhi_hdr switch_resp; |
| 316 | size_t sw_resp_sz = sizeof(struct mkhi_hdr); |
| 317 | |
| 318 | if (!heci_send_receive(&switch_req, sizeof(switch_req), &switch_resp, &sw_resp_sz)) |
| 319 | return false; |
| 320 | |
| 321 | if (switch_resp.result) { |
Sridhar Siricilla | 9f71b17 | 2020-06-01 14:50:52 +0530 | [diff] [blame] | 322 | printk(BIOS_ERR, "cse_lite: Set Boot Partition Info Response Failed: %d\n", |
Sridhar Siricilla | f87ff33 | 2019-09-12 17:18:20 +0530 | [diff] [blame] | 323 | switch_resp.result); |
| 324 | return false; |
| 325 | } |
| 326 | |
| 327 | return true; |
| 328 | } |
| 329 | |
V Sowmya | f990552 | 2020-11-12 20:19:04 +0530 | [diff] [blame] | 330 | static bool cse_data_clear_request(const struct cse_bp_info *cse_bp_info) |
| 331 | { |
| 332 | struct data_clr_request { |
| 333 | struct mkhi_hdr hdr; |
| 334 | uint8_t reserved[4]; |
| 335 | } __packed; |
| 336 | |
| 337 | struct data_clr_request data_clr_rq = { |
| 338 | .hdr.group_id = MKHI_GROUP_ID_BUP_COMMON, |
| 339 | .hdr.command = MKHI_BUP_COMMON_DATA_CLEAR, |
| 340 | .reserved = {0}, |
| 341 | }; |
| 342 | |
| 343 | if (!cse_is_hfs1_cws_normal() || !cse_is_hfs1_com_soft_temp_disable() || |
| 344 | cse_get_current_bp(cse_bp_info) != RO) { |
| 345 | printk(BIOS_ERR, "cse_lite: CSE doesn't meet DATA CLEAR cmd prerequisites\n"); |
| 346 | return false; |
| 347 | } |
| 348 | |
| 349 | printk(BIOS_DEBUG, "cse_lite: Sending DATA CLEAR HECI command\n"); |
| 350 | |
| 351 | struct mkhi_hdr data_clr_rsp; |
| 352 | size_t data_clr_rsp_sz = sizeof(data_clr_rsp); |
| 353 | |
| 354 | if (!heci_send_receive(&data_clr_rq, sizeof(data_clr_rq), &data_clr_rsp, |
Sridhar Siricilla | 361e364 | 2020-10-18 20:14:07 +0530 | [diff] [blame] | 355 | &data_clr_rsp_sz)) { |
V Sowmya | f990552 | 2020-11-12 20:19:04 +0530 | [diff] [blame] | 356 | return false; |
| 357 | } |
| 358 | |
| 359 | if (data_clr_rsp.result) { |
| 360 | printk(BIOS_ERR, "cse_lite: CSE DATA CLEAR command response failed: %d\n", |
| 361 | data_clr_rsp.result); |
| 362 | return false; |
| 363 | } |
| 364 | |
| 365 | return true; |
| 366 | } |
Sridhar Siricilla | 361e364 | 2020-10-18 20:14:07 +0530 | [diff] [blame] | 367 | |
Karthikeyan Ramasubramanian | f9cc637 | 2020-08-04 16:38:58 -0600 | [diff] [blame] | 368 | __weak void cse_board_reset(void) |
| 369 | { |
| 370 | /* Default weak implementation, does nothing. */ |
| 371 | } |
| 372 | |
Rizwan Qureshi | ec32109 | 2019-09-06 20:28:43 +0530 | [diff] [blame] | 373 | /* Set the CSE's next boot partition and issues system reset */ |
| 374 | static bool cse_set_and_boot_from_next_bp(enum boot_partition_id bp) |
Sridhar Siricilla | f87ff33 | 2019-09-12 17:18:20 +0530 | [diff] [blame] | 375 | { |
Rizwan Qureshi | ec32109 | 2019-09-06 20:28:43 +0530 | [diff] [blame] | 376 | if (!cse_set_next_boot_partition(bp)) |
Sridhar Siricilla | f87ff33 | 2019-09-12 17:18:20 +0530 | [diff] [blame] | 377 | return false; |
| 378 | |
Karthikeyan Ramasubramanian | f9cc637 | 2020-08-04 16:38:58 -0600 | [diff] [blame] | 379 | /* Allow the board to perform a reset for CSE RO<->RW jump */ |
| 380 | cse_board_reset(); |
| 381 | |
| 382 | /* If board does not perform the reset, then perform global_reset */ |
Furquan Shaikh | b13bd1e | 2020-09-21 22:44:27 +0000 | [diff] [blame] | 383 | do_global_reset(); |
Sridhar Siricilla | f87ff33 | 2019-09-12 17:18:20 +0530 | [diff] [blame] | 384 | |
Rizwan Qureshi | ec32109 | 2019-09-06 20:28:43 +0530 | [diff] [blame] | 385 | die("cse_lite: Failed to reset the system\n"); |
Sridhar Siricilla | f87ff33 | 2019-09-12 17:18:20 +0530 | [diff] [blame] | 386 | |
| 387 | /* Control never reaches here */ |
| 388 | return false; |
| 389 | } |
| 390 | |
Rizwan Qureshi | ec32109 | 2019-09-06 20:28:43 +0530 | [diff] [blame] | 391 | static bool cse_boot_to_rw(const struct cse_bp_info *cse_bp_info) |
Sridhar Siricilla | f87ff33 | 2019-09-12 17:18:20 +0530 | [diff] [blame] | 392 | { |
Rizwan Qureshi | ec32109 | 2019-09-06 20:28:43 +0530 | [diff] [blame] | 393 | if (cse_get_current_bp(cse_bp_info) == RW) |
| 394 | return true; |
Sridhar Siricilla | f87ff33 | 2019-09-12 17:18:20 +0530 | [diff] [blame] | 395 | |
Rizwan Qureshi | ec32109 | 2019-09-06 20:28:43 +0530 | [diff] [blame] | 396 | return cse_set_and_boot_from_next_bp(RW); |
| 397 | } |
Sridhar Siricilla | f87ff33 | 2019-09-12 17:18:20 +0530 | [diff] [blame] | 398 | |
V Sowmya | f990552 | 2020-11-12 20:19:04 +0530 | [diff] [blame] | 399 | /* Check if CSE RW data partition is valid or not */ |
| 400 | static bool cse_is_rw_dp_valid(const struct cse_bp_info *cse_bp_info) |
| 401 | { |
| 402 | const struct cse_bp_entry *rw_bp; |
| 403 | |
| 404 | rw_bp = cse_get_bp_entry(RW, cse_bp_info); |
| 405 | return rw_bp->status != BP_STATUS_DATA_FAILURE; |
| 406 | } |
| 407 | |
| 408 | /* |
| 409 | * It returns true if RW partition doesn't indicate BP_STATUS_DATA_FAILURE |
| 410 | * otherwise false if any operation fails. |
| 411 | */ |
| 412 | static bool cse_fix_data_failure_err(const struct cse_bp_info *cse_bp_info) |
| 413 | { |
| 414 | /* |
| 415 | * If RW partition status indicates BP_STATUS_DATA_FAILURE, |
| 416 | * - Send DATA CLEAR HECI command to CSE |
| 417 | * - Send SET BOOT PARTITION INFO(RW) command to set CSE's next partition |
| 418 | * - Issue GLOBAL RESET HECI command. |
| 419 | */ |
| 420 | if (cse_is_rw_dp_valid(cse_bp_info)) |
| 421 | return true; |
| 422 | |
| 423 | if (!cse_data_clear_request(cse_bp_info)) |
| 424 | return false; |
| 425 | |
| 426 | return cse_boot_to_rw(cse_bp_info); |
| 427 | } |
| 428 | |
| 429 | #if CONFIG(SOC_INTEL_CSE_RW_UPDATE) |
| 430 | static const struct fw_version *cse_get_bp_entry_version(enum boot_partition_id bp, |
Sridhar Siricilla | 361e364 | 2020-10-18 20:14:07 +0530 | [diff] [blame] | 431 | const struct cse_bp_info *bp_info) |
V Sowmya | f990552 | 2020-11-12 20:19:04 +0530 | [diff] [blame] | 432 | { |
| 433 | const struct cse_bp_entry *cse_bp; |
| 434 | |
| 435 | cse_bp = cse_get_bp_entry(bp, bp_info); |
| 436 | return &cse_bp->fw_ver; |
| 437 | } |
| 438 | |
| 439 | static const struct fw_version *cse_get_rw_version(const struct cse_bp_info *cse_bp_info) |
| 440 | { |
| 441 | return cse_get_bp_entry_version(RW, cse_bp_info); |
| 442 | } |
| 443 | |
| 444 | static void cse_get_bp_entry_range(const struct cse_bp_info *cse_bp_info, |
Sridhar Siricilla | 361e364 | 2020-10-18 20:14:07 +0530 | [diff] [blame] | 445 | enum boot_partition_id bp, uint32_t *start_offset, uint32_t *end_offset) |
V Sowmya | f990552 | 2020-11-12 20:19:04 +0530 | [diff] [blame] | 446 | { |
| 447 | const struct cse_bp_entry *cse_bp; |
| 448 | |
| 449 | cse_bp = cse_get_bp_entry(bp, cse_bp_info); |
| 450 | |
| 451 | if (start_offset) |
| 452 | *start_offset = cse_bp->start_offset; |
| 453 | |
| 454 | if (end_offset) |
| 455 | *end_offset = cse_bp->end_offset; |
| 456 | |
| 457 | } |
| 458 | |
| 459 | static bool cse_is_rw_bp_status_valid(const struct cse_bp_info *cse_bp_info) |
| 460 | { |
| 461 | const struct cse_bp_entry *rw_bp; |
| 462 | |
| 463 | rw_bp = cse_get_bp_entry(RW, cse_bp_info); |
| 464 | |
| 465 | if (rw_bp->status == BP_STATUS_PARTITION_NOT_PRESENT || |
| 466 | rw_bp->status == BP_STATUS_GENERAL_FAILURE) { |
| 467 | printk(BIOS_ERR, "cse_lite: RW BP (status:%u) is not valid\n", rw_bp->status); |
| 468 | return false; |
| 469 | } |
| 470 | return true; |
| 471 | } |
| 472 | |
Rizwan Qureshi | ec32109 | 2019-09-06 20:28:43 +0530 | [diff] [blame] | 473 | static bool cse_boot_to_ro(const struct cse_bp_info *cse_bp_info) |
| 474 | { |
| 475 | if (cse_get_current_bp(cse_bp_info) == RO) |
| 476 | return true; |
| 477 | |
| 478 | return cse_set_and_boot_from_next_bp(RO); |
| 479 | } |
| 480 | |
| 481 | static bool cse_get_rw_rdev(struct region_device *rdev) |
| 482 | { |
| 483 | if (fmap_locate_area_as_rdev_rw(CONFIG_SOC_INTEL_CSE_FMAP_NAME, rdev) < 0) { |
| 484 | printk(BIOS_ERR, "cse_lite: Failed to locate %s in FMAP\n", |
Sridhar Siricilla | 361e364 | 2020-10-18 20:14:07 +0530 | [diff] [blame] | 485 | CONFIG_SOC_INTEL_CSE_FMAP_NAME); |
Rizwan Qureshi | ec32109 | 2019-09-06 20:28:43 +0530 | [diff] [blame] | 486 | return false; |
| 487 | } |
| 488 | |
| 489 | return true; |
| 490 | } |
| 491 | |
Rizwan Qureshi | ec32109 | 2019-09-06 20:28:43 +0530 | [diff] [blame] | 492 | static bool cse_is_rw_bp_sign_valid(const struct region_device *target_rdev) |
| 493 | { |
| 494 | uint32_t cse_bp_sign; |
| 495 | |
| 496 | if (rdev_readat(target_rdev, &cse_bp_sign, 0, CSE_RW_SIGN_SIZE) != CSE_RW_SIGN_SIZE) { |
| 497 | printk(BIOS_ERR, "cse_lite: Failed to read RW boot partition signature\n"); |
| 498 | return false; |
| 499 | } |
| 500 | |
| 501 | return cse_bp_sign == CSE_RW_SIGNATURE; |
| 502 | } |
| 503 | |
| 504 | static bool cse_get_target_rdev(const struct cse_bp_info *cse_bp_info, |
| 505 | struct region_device *target_rdev) |
| 506 | { |
| 507 | struct region_device cse_region_rdev; |
| 508 | size_t size; |
| 509 | uint32_t start_offset; |
| 510 | uint32_t end_offset; |
| 511 | |
| 512 | if (!cse_get_rw_rdev(&cse_region_rdev)) |
| 513 | return false; |
| 514 | |
| 515 | cse_get_bp_entry_range(cse_bp_info, RW, &start_offset, &end_offset); |
| 516 | size = end_offset + 1 - start_offset; |
| 517 | |
| 518 | if (rdev_chain(target_rdev, &cse_region_rdev, start_offset, size)) |
| 519 | return false; |
| 520 | |
| 521 | printk(BIOS_DEBUG, "cse_lite: CSE RW partition: offset = 0x%x, size = 0x%x\n", |
| 522 | (uint32_t)start_offset, (uint32_t) size); |
| 523 | |
| 524 | return true; |
| 525 | } |
| 526 | |
Sridhar Siricilla | 361e364 | 2020-10-18 20:14:07 +0530 | [diff] [blame] | 527 | static const char *cse_get_source_rdev_fmap(void) |
Rizwan Qureshi | ec32109 | 2019-09-06 20:28:43 +0530 | [diff] [blame] | 528 | { |
Sridhar Siricilla | 361e364 | 2020-10-18 20:14:07 +0530 | [diff] [blame] | 529 | struct vb2_context *ctx = vboot_get_context(); |
| 530 | if (ctx == NULL) |
| 531 | return NULL; |
Rizwan Qureshi | ec32109 | 2019-09-06 20:28:43 +0530 | [diff] [blame] | 532 | |
Sridhar Siricilla | 361e364 | 2020-10-18 20:14:07 +0530 | [diff] [blame] | 533 | if (vboot_is_firmware_slot_a(ctx)) |
| 534 | return CONFIG_SOC_INTEL_CSE_RW_A_FMAP_NAME; |
| 535 | |
| 536 | return CONFIG_SOC_INTEL_CSE_RW_B_FMAP_NAME; |
| 537 | } |
| 538 | |
| 539 | static bool cse_get_source_rdev(struct region_device *rdev) |
| 540 | { |
| 541 | const char *reg_name; |
| 542 | uint32_t cbfs_type = CBFS_TYPE_RAW; |
| 543 | struct cbfsf fh; |
| 544 | |
| 545 | reg_name = cse_get_source_rdev_fmap(); |
| 546 | |
| 547 | if (reg_name == NULL) |
Sridhar Siricilla | f87ff33 | 2019-09-12 17:18:20 +0530 | [diff] [blame] | 548 | return false; |
Sridhar Siricilla | 361e364 | 2020-10-18 20:14:07 +0530 | [diff] [blame] | 549 | |
| 550 | if (cbfs_locate_file_in_region(&fh, reg_name, CONFIG_SOC_INTEL_CSE_RW_CBFS_NAME, |
| 551 | &cbfs_type) < 0) |
| 552 | return false; |
| 553 | |
| 554 | cbfs_file_data(rdev, &fh); |
| 555 | |
Sridhar Siricilla | f87ff33 | 2019-09-12 17:18:20 +0530 | [diff] [blame] | 556 | return true; |
| 557 | } |
| 558 | |
Rizwan Qureshi | ec32109 | 2019-09-06 20:28:43 +0530 | [diff] [blame] | 559 | /* |
| 560 | * Compare versions of CSE CBFS RW and CSE RW partition |
| 561 | * If ver_cmp_status = 0, no update is required |
| 562 | * If ver_cmp_status < 0, coreboot downgrades CSE RW region |
| 563 | * If ver_cmp_status > 0, coreboot upgrades CSE RW region |
| 564 | */ |
| 565 | static int cse_check_version_mismatch(const struct cse_bp_info *cse_bp_info, |
Sridhar Siricilla | 361e364 | 2020-10-18 20:14:07 +0530 | [diff] [blame] | 566 | const struct cse_rw_metadata *source_metadata) |
Sridhar Siricilla | f87ff33 | 2019-09-12 17:18:20 +0530 | [diff] [blame] | 567 | { |
Rizwan Qureshi | ec32109 | 2019-09-06 20:28:43 +0530 | [diff] [blame] | 568 | const struct fw_version *cse_rw_ver; |
| 569 | |
Rizwan Qureshi | ec32109 | 2019-09-06 20:28:43 +0530 | [diff] [blame] | 570 | printk(BIOS_DEBUG, "cse_lite: CSE CBFS RW version : %d.%d.%d.%d\n", |
Sridhar Siricilla | 361e364 | 2020-10-18 20:14:07 +0530 | [diff] [blame] | 571 | source_metadata->version.major, |
| 572 | source_metadata->version.minor, |
| 573 | source_metadata->version.hotfix, |
| 574 | source_metadata->version.build); |
Rizwan Qureshi | ec32109 | 2019-09-06 20:28:43 +0530 | [diff] [blame] | 575 | |
| 576 | cse_rw_ver = cse_get_rw_version(cse_bp_info); |
| 577 | |
Sridhar Siricilla | 361e364 | 2020-10-18 20:14:07 +0530 | [diff] [blame] | 578 | if (source_metadata->version.major != cse_rw_ver->major) |
| 579 | return source_metadata->version.major - cse_rw_ver->major; |
| 580 | else if (source_metadata->version.minor != cse_rw_ver->minor) |
| 581 | return source_metadata->version.minor - cse_rw_ver->minor; |
| 582 | else if (source_metadata->version.hotfix != cse_rw_ver->hotfix) |
| 583 | return source_metadata->version.hotfix - cse_rw_ver->hotfix; |
Rizwan Qureshi | ec32109 | 2019-09-06 20:28:43 +0530 | [diff] [blame] | 584 | else |
Sridhar Siricilla | 361e364 | 2020-10-18 20:14:07 +0530 | [diff] [blame] | 585 | return source_metadata->version.build - cse_rw_ver->build; |
| 586 | } |
| 587 | |
| 588 | /* The function calculates SHA-256 of CSE RW blob and compares it with the provided SHA value */ |
| 589 | static bool cse_verify_cbfs_rw_sha256(const uint8_t *expected_rw_blob_sha, |
| 590 | const void *rw_blob, const size_t rw_blob_sz) |
| 591 | |
| 592 | { |
| 593 | uint8_t rw_comp_sha[VB2_SHA256_DIGEST_SIZE]; |
| 594 | |
| 595 | if (vb2_digest_buffer(rw_blob, rw_blob_sz, VB2_HASH_SHA256, rw_comp_sha, |
| 596 | VB2_SHA256_DIGEST_SIZE)) { |
| 597 | printk(BIOS_ERR, "cse_lite: CSE CBFS RW's SHA-256 calculation has failed\n"); |
| 598 | return false; |
| 599 | } |
| 600 | |
| 601 | if (memcmp(expected_rw_blob_sha, rw_comp_sha, VB2_SHA256_DIGEST_SIZE)) { |
| 602 | printk(BIOS_ERR, "cse_lite: Computed CBFS RW's SHA-256 does not match with" |
| 603 | "the provided SHA in the metadata\n"); |
| 604 | return false; |
| 605 | } |
| 606 | printk(BIOS_SPEW, "cse_lite: Computed SHA of CSE CBFS RW Image matches the" |
| 607 | " provided hash in the metadata\n"); |
| 608 | return true; |
Rizwan Qureshi | ec32109 | 2019-09-06 20:28:43 +0530 | [diff] [blame] | 609 | } |
| 610 | |
| 611 | static bool cse_erase_rw_region(const struct region_device *target_rdev) |
| 612 | { |
Rizwan Qureshi | ec32109 | 2019-09-06 20:28:43 +0530 | [diff] [blame] | 613 | if (rdev_eraseat(target_rdev, 0, region_device_sz(target_rdev)) < 0) { |
| 614 | printk(BIOS_ERR, "cse_lite: CSE RW partition could not be erased\n"); |
| 615 | return false; |
| 616 | } |
| 617 | return true; |
| 618 | } |
| 619 | |
Sridhar Siricilla | 361e364 | 2020-10-18 20:14:07 +0530 | [diff] [blame] | 620 | static bool cse_copy_rw(const struct region_device *target_rdev, const void *buf, |
| 621 | size_t offset, size_t size) |
Rizwan Qureshi | ec32109 | 2019-09-06 20:28:43 +0530 | [diff] [blame] | 622 | { |
| 623 | if (rdev_writeat(target_rdev, buf, offset, size) < 0) { |
| 624 | printk(BIOS_ERR, "cse_lite: Failed to update CSE firmware\n"); |
| 625 | return false; |
| 626 | } |
| 627 | |
| 628 | return true; |
| 629 | } |
| 630 | |
| 631 | static bool cse_is_rw_version_latest(const struct cse_bp_info *cse_bp_info, |
Sridhar Siricilla | 361e364 | 2020-10-18 20:14:07 +0530 | [diff] [blame] | 632 | const struct cse_rw_metadata *source_metadata) |
Rizwan Qureshi | ec32109 | 2019-09-06 20:28:43 +0530 | [diff] [blame] | 633 | { |
Sridhar Siricilla | 361e364 | 2020-10-18 20:14:07 +0530 | [diff] [blame] | 634 | return !cse_check_version_mismatch(cse_bp_info, source_metadata); |
Rizwan Qureshi | ec32109 | 2019-09-06 20:28:43 +0530 | [diff] [blame] | 635 | } |
| 636 | |
Sridhar Siricilla | 2f6d555 | 2020-04-19 23:39:02 +0530 | [diff] [blame] | 637 | static bool cse_is_downgrade_instance(const struct cse_bp_info *cse_bp_info, |
Sridhar Siricilla | 361e364 | 2020-10-18 20:14:07 +0530 | [diff] [blame] | 638 | const struct cse_rw_metadata *source_metadata) |
Sridhar Siricilla | 2f6d555 | 2020-04-19 23:39:02 +0530 | [diff] [blame] | 639 | { |
Sridhar Siricilla | 361e364 | 2020-10-18 20:14:07 +0530 | [diff] [blame] | 640 | return cse_check_version_mismatch(cse_bp_info, source_metadata) < 0; |
Sridhar Siricilla | 2f6d555 | 2020-04-19 23:39:02 +0530 | [diff] [blame] | 641 | } |
| 642 | |
Rizwan Qureshi | ec32109 | 2019-09-06 20:28:43 +0530 | [diff] [blame] | 643 | static bool cse_is_update_required(const struct cse_bp_info *cse_bp_info, |
Sridhar Siricilla | 361e364 | 2020-10-18 20:14:07 +0530 | [diff] [blame] | 644 | const struct cse_rw_metadata *source_metadata, |
| 645 | struct region_device *target_rdev) |
Rizwan Qureshi | ec32109 | 2019-09-06 20:28:43 +0530 | [diff] [blame] | 646 | { |
| 647 | return (!cse_is_rw_bp_sign_valid(target_rdev) || |
Sridhar Siricilla | 361e364 | 2020-10-18 20:14:07 +0530 | [diff] [blame] | 648 | !cse_is_rw_version_latest(cse_bp_info, source_metadata)); |
Rizwan Qureshi | ec32109 | 2019-09-06 20:28:43 +0530 | [diff] [blame] | 649 | } |
| 650 | |
| 651 | static bool cse_write_rw_region(const struct region_device *target_rdev, |
Sridhar Siricilla | 361e364 | 2020-10-18 20:14:07 +0530 | [diff] [blame] | 652 | const void *cse_cbfs_rw, const size_t cse_cbfs_rw_sz) |
Rizwan Qureshi | ec32109 | 2019-09-06 20:28:43 +0530 | [diff] [blame] | 653 | { |
Rizwan Qureshi | ec32109 | 2019-09-06 20:28:43 +0530 | [diff] [blame] | 654 | /* Points to CSE CBFS RW image after boot partition signature */ |
| 655 | uint8_t *cse_cbfs_rw_wo_sign = (uint8_t *)cse_cbfs_rw + CSE_RW_SIGN_SIZE; |
| 656 | |
| 657 | /* Size of CSE CBFS RW image without boot partition signature */ |
Sridhar Siricilla | 361e364 | 2020-10-18 20:14:07 +0530 | [diff] [blame] | 658 | uint32_t cse_cbfs_rw_wo_sign_sz = cse_cbfs_rw_sz - CSE_RW_SIGN_SIZE; |
Rizwan Qureshi | ec32109 | 2019-09-06 20:28:43 +0530 | [diff] [blame] | 659 | |
| 660 | /* Update except CSE RW signature */ |
| 661 | if (!cse_copy_rw(target_rdev, cse_cbfs_rw_wo_sign, CSE_RW_SIGN_SIZE, |
| 662 | cse_cbfs_rw_wo_sign_sz)) |
Sridhar Siricilla | 361e364 | 2020-10-18 20:14:07 +0530 | [diff] [blame] | 663 | return false; |
Rizwan Qureshi | ec32109 | 2019-09-06 20:28:43 +0530 | [diff] [blame] | 664 | |
| 665 | /* Update CSE RW signature to indicate update is complete */ |
| 666 | if (!cse_copy_rw(target_rdev, (void *)cse_cbfs_rw, 0, CSE_RW_SIGN_SIZE)) |
Rizwan Qureshi | ec32109 | 2019-09-06 20:28:43 +0530 | [diff] [blame] | 667 | return false; |
| 668 | |
| 669 | printk(BIOS_INFO, "cse_lite: CSE RW Update Successful\n"); |
| 670 | return true; |
| 671 | } |
| 672 | |
Sridhar Siricilla | 361e364 | 2020-10-18 20:14:07 +0530 | [diff] [blame] | 673 | static enum csme_failure_reason cse_update_rw(const struct cse_bp_info *cse_bp_info, |
| 674 | const void *cse_cbfs_rw, const size_t cse_blob_sz, |
| 675 | struct region_device *target_rdev) |
| 676 | { |
| 677 | |
| 678 | if (!cse_erase_rw_region(target_rdev)) |
| 679 | return CSE_LITE_SKU_FW_UPDATE_ERROR; |
| 680 | |
| 681 | if (!cse_write_rw_region(target_rdev, cse_cbfs_rw, cse_blob_sz)) |
| 682 | return CSE_LITE_SKU_FW_UPDATE_ERROR; |
| 683 | |
| 684 | return CSE_LITE_SKU_NO_ERROR; |
| 685 | } |
| 686 | |
Sridhar Siricilla | 2f6d555 | 2020-04-19 23:39:02 +0530 | [diff] [blame] | 687 | static bool cse_prep_for_rw_update(const struct cse_bp_info *cse_bp_info, |
Sridhar Siricilla | 361e364 | 2020-10-18 20:14:07 +0530 | [diff] [blame] | 688 | const struct cse_rw_metadata *source_metadata) |
Rizwan Qureshi | ec32109 | 2019-09-06 20:28:43 +0530 | [diff] [blame] | 689 | { |
| 690 | /* |
| 691 | * To set CSE's operation mode to HMRFPO mode: |
| 692 | * 1. Ensure CSE to boot from RO(BP1) |
| 693 | * 2. Send HMRFPO_ENABLE command to CSE |
| 694 | */ |
| 695 | if (!cse_boot_to_ro(cse_bp_info)) |
| 696 | return false; |
| 697 | |
Sridhar Siricilla | 361e364 | 2020-10-18 20:14:07 +0530 | [diff] [blame] | 698 | if (cse_is_downgrade_instance(cse_bp_info, source_metadata) && |
Sridhar Siricilla | 2f6d555 | 2020-04-19 23:39:02 +0530 | [diff] [blame] | 699 | !cse_data_clear_request(cse_bp_info)) { |
| 700 | printk(BIOS_ERR, "cse_lite: CSE FW downgrade is aborted\n"); |
| 701 | return false; |
| 702 | } |
| 703 | |
Rizwan Qureshi | ec32109 | 2019-09-06 20:28:43 +0530 | [diff] [blame] | 704 | return cse_hmrfpo_enable(); |
| 705 | } |
| 706 | |
Sridhar Siricilla | 361e364 | 2020-10-18 20:14:07 +0530 | [diff] [blame] | 707 | static enum csme_failure_reason cse_trigger_fw_update(const struct cse_bp_info *cse_bp_info, |
| 708 | const struct cse_rw_metadata *source_metadata, |
| 709 | struct region_device *target_rdev) |
Rizwan Qureshi | ec32109 | 2019-09-06 20:28:43 +0530 | [diff] [blame] | 710 | { |
Sridhar Siricilla | 361e364 | 2020-10-18 20:14:07 +0530 | [diff] [blame] | 711 | struct region_device source_rdev; |
| 712 | enum csme_failure_reason rv; |
Rizwan Qureshi | ec32109 | 2019-09-06 20:28:43 +0530 | [diff] [blame] | 713 | |
Sridhar Siricilla | 361e364 | 2020-10-18 20:14:07 +0530 | [diff] [blame] | 714 | if (!cse_get_source_rdev(&source_rdev)) |
| 715 | return CSE_LITE_SKU_RW_BLOB_NOT_FOUND; |
Rizwan Qureshi | ec32109 | 2019-09-06 20:28:43 +0530 | [diff] [blame] | 716 | |
Sridhar Siricilla | 361e364 | 2020-10-18 20:14:07 +0530 | [diff] [blame] | 717 | void *cse_cbfs_rw = rdev_mmap_full(&source_rdev); |
| 718 | |
| 719 | if (!cse_cbfs_rw) { |
| 720 | printk(BIOS_ERR, "cse_lite: CSE CBFS RW blob could not be mapped\n"); |
| 721 | return CSE_LITE_SKU_RW_BLOB_NOT_FOUND; |
| 722 | } |
| 723 | |
| 724 | if (!cse_verify_cbfs_rw_sha256(source_metadata->sha256, cse_cbfs_rw, |
| 725 | region_device_sz(&source_rdev))) { |
| 726 | rv = CSE_LITE_SKU_RW_BLOB_SHA256_MISMATCH; |
| 727 | goto error_exit; |
| 728 | } |
| 729 | |
| 730 | if (!cse_prep_for_rw_update(cse_bp_info, source_metadata)) { |
| 731 | rv = CSE_LITE_SKU_COMMUNICATION_ERROR; |
| 732 | goto error_exit; |
| 733 | } |
| 734 | |
| 735 | rv = cse_update_rw(cse_bp_info, cse_cbfs_rw, region_device_sz(&source_rdev), |
| 736 | target_rdev); |
| 737 | |
| 738 | error_exit: |
| 739 | rdev_munmap(&source_rdev, cse_cbfs_rw); |
| 740 | return rv; |
Rizwan Qureshi | ec32109 | 2019-09-06 20:28:43 +0530 | [diff] [blame] | 741 | } |
| 742 | |
Sridhar Siricilla | 361e364 | 2020-10-18 20:14:07 +0530 | [diff] [blame] | 743 | static uint8_t cse_fw_update(const struct cse_bp_info *cse_bp_info) |
Rizwan Qureshi | ec32109 | 2019-09-06 20:28:43 +0530 | [diff] [blame] | 744 | { |
| 745 | struct region_device target_rdev; |
Sridhar Siricilla | 361e364 | 2020-10-18 20:14:07 +0530 | [diff] [blame] | 746 | struct cse_rw_metadata source_metadata; |
| 747 | |
| 748 | /* Read CSE CBFS RW metadata */ |
| 749 | if (cbfs_boot_load_file(CONFIG_SOC_INTEL_CSE_RW_METADATA_CBFS_NAME, &source_metadata, |
| 750 | sizeof(source_metadata), CBFS_TYPE_RAW) != sizeof(source_metadata)) { |
| 751 | printk(BIOS_ERR, "cse_lite: Failed to get CSE CBFS RW metadata\n"); |
| 752 | return CSE_LITE_SKU_RW_METADATA_NOT_FOUND; |
| 753 | } |
Rizwan Qureshi | ec32109 | 2019-09-06 20:28:43 +0530 | [diff] [blame] | 754 | |
| 755 | if (!cse_get_target_rdev(cse_bp_info, &target_rdev)) { |
| 756 | printk(BIOS_ERR, "cse_lite: Failed to get CSE RW Partition\n"); |
| 757 | return CSE_LITE_SKU_RW_ACCESS_ERROR; |
| 758 | } |
| 759 | |
Sridhar Siricilla | 361e364 | 2020-10-18 20:14:07 +0530 | [diff] [blame] | 760 | if (cse_is_update_required(cse_bp_info, &source_metadata, &target_rdev)) { |
Rizwan Qureshi | ec32109 | 2019-09-06 20:28:43 +0530 | [diff] [blame] | 761 | printk(BIOS_DEBUG, "cse_lite: CSE RW update is initiated\n"); |
Sridhar Siricilla | 361e364 | 2020-10-18 20:14:07 +0530 | [diff] [blame] | 762 | return cse_trigger_fw_update(cse_bp_info, &source_metadata, &target_rdev); |
Rizwan Qureshi | ec32109 | 2019-09-06 20:28:43 +0530 | [diff] [blame] | 763 | } |
| 764 | |
| 765 | if (!cse_is_rw_bp_status_valid(cse_bp_info)) |
| 766 | return CSE_LITE_SKU_RW_JUMP_ERROR; |
| 767 | |
| 768 | return 0; |
Sridhar Siricilla | f87ff33 | 2019-09-12 17:18:20 +0530 | [diff] [blame] | 769 | } |
V Sowmya | f990552 | 2020-11-12 20:19:04 +0530 | [diff] [blame] | 770 | #endif |
Sridhar Siricilla | f87ff33 | 2019-09-12 17:18:20 +0530 | [diff] [blame] | 771 | |
| 772 | void cse_fw_sync(void *unused) |
| 773 | { |
| 774 | static struct get_bp_info_rsp cse_bp_info; |
| 775 | |
| 776 | if (vboot_recovery_mode_enabled()) { |
Sridhar Siricilla | 9f71b17 | 2020-06-01 14:50:52 +0530 | [diff] [blame] | 777 | printk(BIOS_DEBUG, "cse_lite: Skip switching to RW in the recovery path\n"); |
Sridhar Siricilla | f87ff33 | 2019-09-12 17:18:20 +0530 | [diff] [blame] | 778 | return; |
| 779 | } |
| 780 | |
Sridhar Siricilla | 99dbca3 | 2020-05-12 21:05:04 +0530 | [diff] [blame] | 781 | /* If CSE SKU type is not Lite, skip enabling CSE Lite SKU */ |
| 782 | if (!cse_is_hfs3_fw_sku_lite()) { |
Sridhar Siricilla | 9f71b17 | 2020-06-01 14:50:52 +0530 | [diff] [blame] | 783 | printk(BIOS_ERR, "cse_lite: Not a CSE Lite SKU\n"); |
Sridhar Siricilla | f87ff33 | 2019-09-12 17:18:20 +0530 | [diff] [blame] | 784 | return; |
| 785 | } |
| 786 | |
| 787 | if (!cse_get_bp_info(&cse_bp_info)) { |
Sridhar Siricilla | 9f71b17 | 2020-06-01 14:50:52 +0530 | [diff] [blame] | 788 | printk(BIOS_ERR, "cse_lite: Failed to get CSE boot partition info\n"); |
Sridhar Siricilla | 87e36c4 | 2020-05-03 19:08:18 +0530 | [diff] [blame] | 789 | cse_trigger_recovery(CSE_LITE_SKU_COMMUNICATION_ERROR); |
Sridhar Siricilla | f87ff33 | 2019-09-12 17:18:20 +0530 | [diff] [blame] | 790 | } |
| 791 | |
Sridhar Siricilla | 2f6d555 | 2020-04-19 23:39:02 +0530 | [diff] [blame] | 792 | if (!cse_fix_data_failure_err(&cse_bp_info.bp_info)) |
| 793 | cse_trigger_recovery(CSE_LITE_SKU_DATA_WIPE_ERROR); |
| 794 | |
Sridhar Siricilla | 361e364 | 2020-10-18 20:14:07 +0530 | [diff] [blame] | 795 | /* |
| 796 | * If SOC_INTEL_CSE_RW_UPDATE is defined , then trigger CSE firmware update. The driver |
| 797 | * triggers recovery if CSE CBFS RW metadata or CSE CBFS RW blob is not available. |
| 798 | */ |
V Sowmya | f990552 | 2020-11-12 20:19:04 +0530 | [diff] [blame] | 799 | #if CONFIG(SOC_INTEL_CSE_RW_UPDATE) |
Rizwan Qureshi | ec32109 | 2019-09-06 20:28:43 +0530 | [diff] [blame] | 800 | uint8_t rv; |
Sridhar Siricilla | 361e364 | 2020-10-18 20:14:07 +0530 | [diff] [blame] | 801 | rv = cse_fw_update(&cse_bp_info.bp_info); |
| 802 | if (rv) |
| 803 | cse_trigger_recovery(rv); |
V Sowmya | f990552 | 2020-11-12 20:19:04 +0530 | [diff] [blame] | 804 | #endif |
Sridhar Siricilla | f87ff33 | 2019-09-12 17:18:20 +0530 | [diff] [blame] | 805 | |
| 806 | if (!cse_boot_to_rw(&cse_bp_info.bp_info)) { |
Sridhar Siricilla | 9f71b17 | 2020-06-01 14:50:52 +0530 | [diff] [blame] | 807 | printk(BIOS_ERR, "cse_lite: Failed to switch to RW\n"); |
Sridhar Siricilla | 87e36c4 | 2020-05-03 19:08:18 +0530 | [diff] [blame] | 808 | cse_trigger_recovery(CSE_LITE_SKU_RW_SWITCH_ERROR); |
Sridhar Siricilla | f87ff33 | 2019-09-12 17:18:20 +0530 | [diff] [blame] | 809 | } |
Sridhar Siricilla | f87ff33 | 2019-09-12 17:18:20 +0530 | [diff] [blame] | 810 | } |
| 811 | |
| 812 | BOOT_STATE_INIT_ENTRY(BS_PRE_DEVICE, BS_ON_ENTRY, cse_fw_sync, NULL); |