Angel Pons | 118a9c7 | 2020-04-02 23:48:34 +0200 | [diff] [blame] | 1 | /* SPDX-License-Identifier: GPL-2.0-only */ |
Aaron Durbin | 0424c95 | 2015-03-28 23:56:22 -0500 | [diff] [blame] | 2 | |
| 3 | #include <boot_device.h> |
Julius Werner | cefe89e | 2019-11-06 19:29:44 -0800 | [diff] [blame] | 4 | #include <cbmem.h> |
Aaron Durbin | 0424c95 | 2015-03-28 23:56:22 -0500 | [diff] [blame] | 5 | #include <console/console.h> |
| 6 | #include <fmap.h> |
Julius Werner | fdabf3f | 2020-05-06 17:06:35 -0700 | [diff] [blame] | 7 | #include <metadata_hash.h> |
Aaron Durbin | 0424c95 | 2015-03-28 23:56:22 -0500 | [diff] [blame] | 8 | #include <stddef.h> |
| 9 | #include <string.h> |
Julius Werner | cefe89e | 2019-11-06 19:29:44 -0800 | [diff] [blame] | 10 | #include <symbols.h> |
Krystian Hebel | 93f6b8a | 2020-09-30 18:23:14 +0200 | [diff] [blame] | 11 | #include <endian.h> |
Aaron Durbin | 0424c95 | 2015-03-28 23:56:22 -0500 | [diff] [blame] | 12 | |
Aaron Durbin | bf1e481 | 2016-05-10 15:12:08 -0500 | [diff] [blame] | 13 | #include "fmap_config.h" |
| 14 | |
Aaron Durbin | 0424c95 | 2015-03-28 23:56:22 -0500 | [diff] [blame] | 15 | /* |
| 16 | * See http://code.google.com/p/flashmap/ for more information on FMAP. |
| 17 | */ |
| 18 | |
Arthur Heymans | dba22d2 | 2019-11-20 19:57:49 +0100 | [diff] [blame] | 19 | static int fmap_print_once; |
Julius Werner | c893197 | 2021-04-16 16:48:32 -0700 | [diff] [blame] | 20 | static struct region_device fmap_cache; |
Duncan Laurie | bc2c0a3 | 2016-02-09 09:17:56 -0800 | [diff] [blame] | 21 | |
Julius Werner | cefe89e | 2019-11-06 19:29:44 -0800 | [diff] [blame] | 22 | #define print_once(...) do { \ |
Arthur Heymans | dba22d2 | 2019-11-20 19:57:49 +0100 | [diff] [blame] | 23 | if (!fmap_print_once) \ |
Julius Werner | cefe89e | 2019-11-06 19:29:44 -0800 | [diff] [blame] | 24 | printk(__VA_ARGS__); \ |
| 25 | } while (0) |
| 26 | |
Furquan Shaikh | b33a2b0 | 2019-09-26 23:51:46 -0700 | [diff] [blame] | 27 | uint64_t get_fmap_flash_offset(void) |
| 28 | { |
| 29 | return FMAP_OFFSET; |
| 30 | } |
| 31 | |
Julius Werner | fdabf3f | 2020-05-06 17:06:35 -0700 | [diff] [blame] | 32 | static int verify_fmap(const struct fmap *fmap) |
Julius Werner | cefe89e | 2019-11-06 19:29:44 -0800 | [diff] [blame] | 33 | { |
Julius Werner | fdabf3f | 2020-05-06 17:06:35 -0700 | [diff] [blame] | 34 | if (memcmp(fmap->signature, FMAP_SIGNATURE, sizeof(fmap->signature))) |
| 35 | return -1; |
| 36 | |
| 37 | static bool done = false; |
| 38 | if (!CONFIG(CBFS_VERIFICATION) || !ENV_INITIAL_STAGE || done) |
| 39 | return 0; /* Only need to check hash in first stage. */ |
| 40 | |
Julius Werner | 682cb3b | 2023-11-02 15:44:12 -0700 | [diff] [blame^] | 41 | /* On error we need to die right here, lest we risk a TOCTOU attack where the cache is |
| 42 | filled with a tampered FMAP but the later fallback path is fed a valid one. */ |
Julius Werner | fdabf3f | 2020-05-06 17:06:35 -0700 | [diff] [blame] | 43 | if (metadata_hash_verify_fmap(fmap, FMAP_SIZE) != VB2_SUCCESS) |
Julius Werner | 682cb3b | 2023-11-02 15:44:12 -0700 | [diff] [blame^] | 44 | die("FMAP verification failure"); |
Julius Werner | fdabf3f | 2020-05-06 17:06:35 -0700 | [diff] [blame] | 45 | |
| 46 | done = true; |
| 47 | return 0; |
Julius Werner | cefe89e | 2019-11-06 19:29:44 -0800 | [diff] [blame] | 48 | } |
| 49 | |
| 50 | static void report(const struct fmap *fmap) |
| 51 | { |
| 52 | print_once(BIOS_DEBUG, "FMAP: Found \"%s\" version %d.%d at %#x.\n", |
| 53 | fmap->name, fmap->ver_major, fmap->ver_minor, FMAP_OFFSET); |
| 54 | print_once(BIOS_DEBUG, "FMAP: base = %#llx size = %#x #areas = %d\n", |
Krystian Hebel | 93f6b8a | 2020-09-30 18:23:14 +0200 | [diff] [blame] | 55 | (long long)le64toh(fmap->base), le32toh(fmap->size), |
| 56 | le16toh(fmap->nareas)); |
Arthur Heymans | dba22d2 | 2019-11-20 19:57:49 +0100 | [diff] [blame] | 57 | fmap_print_once = 1; |
Julius Werner | cefe89e | 2019-11-06 19:29:44 -0800 | [diff] [blame] | 58 | } |
| 59 | |
Julius Werner | c893197 | 2021-04-16 16:48:32 -0700 | [diff] [blame] | 60 | static void setup_preram_cache(struct region_device *cache_rdev) |
Julius Werner | cefe89e | 2019-11-06 19:29:44 -0800 | [diff] [blame] | 61 | { |
Julius Werner | 7fc9286 | 2019-11-18 13:01:06 -0800 | [diff] [blame] | 62 | if (CONFIG(NO_FMAP_CACHE)) |
| 63 | return; |
| 64 | |
Josie Nordrum | c3cc158 | 2020-09-09 12:57:13 -0600 | [diff] [blame] | 65 | /* No need to use FMAP cache in SMM */ |
| 66 | if (ENV_SMM) |
| 67 | return; |
| 68 | |
Julius Werner | cefe89e | 2019-11-06 19:29:44 -0800 | [diff] [blame] | 69 | if (!ENV_ROMSTAGE_OR_BEFORE) { |
| 70 | /* We get here if ramstage makes an FMAP access before calling |
| 71 | cbmem_initialize(). We should avoid letting it come to that, |
| 72 | so print a warning. */ |
| 73 | print_once(BIOS_WARNING, |
| 74 | "WARNING: Post-RAM FMAP access too early for cache!\n"); |
| 75 | return; |
| 76 | } |
| 77 | |
Julius Werner | cefe89e | 2019-11-06 19:29:44 -0800 | [diff] [blame] | 78 | struct fmap *fmap = (struct fmap *)_fmap_cache; |
Martin Roth | 1594e8f | 2020-07-15 13:57:54 -0600 | [diff] [blame] | 79 | if (!(ENV_INITIAL_STAGE)) { |
| 80 | /* NOTE: This assumes that the first stage will make |
Julius Werner | cefe89e | 2019-11-06 19:29:44 -0800 | [diff] [blame] | 81 | at least one FMAP access (usually from finding CBFS). */ |
Julius Werner | fdabf3f | 2020-05-06 17:06:35 -0700 | [diff] [blame] | 82 | if (!verify_fmap(fmap)) |
Julius Werner | cefe89e | 2019-11-06 19:29:44 -0800 | [diff] [blame] | 83 | goto register_cache; |
| 84 | |
Julius Werner | e966595 | 2022-01-21 17:06:20 -0800 | [diff] [blame] | 85 | printk(BIOS_ERR, "FMAP cache corrupted?!\n"); |
Julius Werner | fdabf3f | 2020-05-06 17:06:35 -0700 | [diff] [blame] | 86 | if (CONFIG(TOCTOU_SAFETY)) |
| 87 | die("TOCTOU safety relies on FMAP cache"); |
Julius Werner | cefe89e | 2019-11-06 19:29:44 -0800 | [diff] [blame] | 88 | } |
| 89 | |
| 90 | /* In case we fail below, make sure the cache is invalid. */ |
| 91 | memset(fmap->signature, 0, sizeof(fmap->signature)); |
| 92 | |
| 93 | boot_device_init(); |
| 94 | const struct region_device *boot_rdev = boot_device_ro(); |
| 95 | if (!boot_rdev) |
| 96 | return; |
| 97 | |
| 98 | /* memlayout statically guarantees that the FMAP_CACHE is big enough. */ |
| 99 | if (rdev_readat(boot_rdev, fmap, FMAP_OFFSET, FMAP_SIZE) != FMAP_SIZE) |
| 100 | return; |
Julius Werner | fdabf3f | 2020-05-06 17:06:35 -0700 | [diff] [blame] | 101 | if (verify_fmap(fmap)) |
Julius Werner | cefe89e | 2019-11-06 19:29:44 -0800 | [diff] [blame] | 102 | return; |
| 103 | report(fmap); |
| 104 | |
| 105 | register_cache: |
Julius Werner | c893197 | 2021-04-16 16:48:32 -0700 | [diff] [blame] | 106 | rdev_chain_mem(cache_rdev, fmap, FMAP_SIZE); |
Julius Werner | cefe89e | 2019-11-06 19:29:44 -0800 | [diff] [blame] | 107 | } |
| 108 | |
Furquan Shaikh | b33a2b0 | 2019-09-26 23:51:46 -0700 | [diff] [blame] | 109 | static int find_fmap_directory(struct region_device *fmrd) |
Aaron Durbin | 0424c95 | 2015-03-28 23:56:22 -0500 | [diff] [blame] | 110 | { |
| 111 | const struct region_device *boot; |
| 112 | struct fmap *fmap; |
Aaron Durbin | bf1e481 | 2016-05-10 15:12:08 -0500 | [diff] [blame] | 113 | size_t offset = FMAP_OFFSET; |
Aaron Durbin | 0424c95 | 2015-03-28 23:56:22 -0500 | [diff] [blame] | 114 | |
Julius Werner | cefe89e | 2019-11-06 19:29:44 -0800 | [diff] [blame] | 115 | /* Try FMAP cache first */ |
Julius Werner | c893197 | 2021-04-16 16:48:32 -0700 | [diff] [blame] | 116 | if (!region_device_sz(&fmap_cache)) |
Arthur Heymans | dba22d2 | 2019-11-20 19:57:49 +0100 | [diff] [blame] | 117 | setup_preram_cache(&fmap_cache); |
Julius Werner | c893197 | 2021-04-16 16:48:32 -0700 | [diff] [blame] | 118 | if (region_device_sz(&fmap_cache)) |
| 119 | return rdev_chain_full(fmrd, &fmap_cache); |
Patrick Rudolph | 6d787c2 | 2019-09-12 13:21:37 +0200 | [diff] [blame] | 120 | |
Aaron Durbin | 0424c95 | 2015-03-28 23:56:22 -0500 | [diff] [blame] | 121 | boot_device_init(); |
| 122 | boot = boot_device_ro(); |
| 123 | |
| 124 | if (boot == NULL) |
| 125 | return -1; |
| 126 | |
Julius Werner | 5bc5b1d | 2023-11-06 16:51:27 -0800 | [diff] [blame] | 127 | fmap = rdev_mmap(boot, offset, FMAP_SIZE); |
Aaron Durbin | 0424c95 | 2015-03-28 23:56:22 -0500 | [diff] [blame] | 128 | |
| 129 | if (fmap == NULL) |
| 130 | return -1; |
| 131 | |
Julius Werner | fdabf3f | 2020-05-06 17:06:35 -0700 | [diff] [blame] | 132 | if (verify_fmap(fmap)) { |
| 133 | printk(BIOS_ERR, "FMAP missing or corrupted at offset 0x%zx!\n", |
| 134 | offset); |
Aaron Durbin | 0424c95 | 2015-03-28 23:56:22 -0500 | [diff] [blame] | 135 | rdev_munmap(boot, fmap); |
| 136 | return -1; |
| 137 | } |
| 138 | |
Julius Werner | cefe89e | 2019-11-06 19:29:44 -0800 | [diff] [blame] | 139 | report(fmap); |
Aaron Durbin | 0424c95 | 2015-03-28 23:56:22 -0500 | [diff] [blame] | 140 | |
| 141 | rdev_munmap(boot, fmap); |
| 142 | |
Julius Werner | cefe89e | 2019-11-06 19:29:44 -0800 | [diff] [blame] | 143 | return rdev_chain(fmrd, boot, offset, FMAP_SIZE); |
Aaron Durbin | 0424c95 | 2015-03-28 23:56:22 -0500 | [diff] [blame] | 144 | } |
| 145 | |
| 146 | int fmap_locate_area_as_rdev(const char *name, struct region_device *area) |
| 147 | { |
| 148 | struct region ar; |
| 149 | |
| 150 | if (fmap_locate_area(name, &ar)) |
| 151 | return -1; |
| 152 | |
| 153 | return boot_device_ro_subregion(&ar, area); |
| 154 | } |
| 155 | |
Aaron Durbin | bccaab8 | 2016-08-12 12:42:04 -0500 | [diff] [blame] | 156 | int fmap_locate_area_as_rdev_rw(const char *name, struct region_device *area) |
| 157 | { |
| 158 | struct region ar; |
| 159 | |
| 160 | if (fmap_locate_area(name, &ar)) |
| 161 | return -1; |
| 162 | |
| 163 | return boot_device_rw_subregion(&ar, area); |
| 164 | } |
| 165 | |
Aaron Durbin | 0424c95 | 2015-03-28 23:56:22 -0500 | [diff] [blame] | 166 | int fmap_locate_area(const char *name, struct region *ar) |
| 167 | { |
| 168 | struct region_device fmrd; |
| 169 | size_t offset; |
| 170 | |
Jakub Czapiga | 5446bdb | 2020-12-10 12:21:52 +0100 | [diff] [blame] | 171 | if (name == NULL || ar == NULL) |
| 172 | return -1; |
| 173 | |
Aaron Durbin | 0424c95 | 2015-03-28 23:56:22 -0500 | [diff] [blame] | 174 | if (find_fmap_directory(&fmrd)) |
| 175 | return -1; |
| 176 | |
| 177 | /* Start reading the areas just after fmap header. */ |
| 178 | offset = sizeof(struct fmap); |
| 179 | |
| 180 | while (1) { |
| 181 | struct fmap_area *area; |
| 182 | |
| 183 | area = rdev_mmap(&fmrd, offset, sizeof(*area)); |
| 184 | |
| 185 | if (area == NULL) |
| 186 | return -1; |
| 187 | |
| 188 | if (strcmp((const char *)area->name, name)) { |
| 189 | rdev_munmap(&fmrd, area); |
| 190 | offset += sizeof(struct fmap_area); |
| 191 | continue; |
| 192 | } |
| 193 | |
Duncan Laurie | bc2c0a3 | 2016-02-09 09:17:56 -0800 | [diff] [blame] | 194 | printk(BIOS_DEBUG, "FMAP: area %s found @ %x (%d bytes)\n", |
Krystian Hebel | 93f6b8a | 2020-09-30 18:23:14 +0200 | [diff] [blame] | 195 | name, le32toh(area->offset), le32toh(area->size)); |
Aaron Durbin | 0424c95 | 2015-03-28 23:56:22 -0500 | [diff] [blame] | 196 | |
Krystian Hebel | 93f6b8a | 2020-09-30 18:23:14 +0200 | [diff] [blame] | 197 | ar->offset = le32toh(area->offset); |
| 198 | ar->size = le32toh(area->size); |
Aaron Durbin | 0424c95 | 2015-03-28 23:56:22 -0500 | [diff] [blame] | 199 | |
| 200 | rdev_munmap(&fmrd, area); |
| 201 | |
| 202 | return 0; |
| 203 | } |
| 204 | |
| 205 | printk(BIOS_DEBUG, "FMAP: area %s not found\n", name); |
| 206 | |
| 207 | return -1; |
| 208 | } |
Patrick Georgi | 9952690 | 2015-07-09 11:27:44 +0200 | [diff] [blame] | 209 | |
| 210 | int fmap_find_region_name(const struct region * const ar, |
| 211 | char name[FMAP_STRLEN]) |
| 212 | { |
| 213 | struct region_device fmrd; |
| 214 | size_t offset; |
| 215 | |
Jakub Czapiga | 5446bdb | 2020-12-10 12:21:52 +0100 | [diff] [blame] | 216 | if (name == NULL || ar == NULL) |
| 217 | return -1; |
| 218 | |
Patrick Georgi | 9952690 | 2015-07-09 11:27:44 +0200 | [diff] [blame] | 219 | if (find_fmap_directory(&fmrd)) |
| 220 | return -1; |
| 221 | |
| 222 | /* Start reading the areas just after fmap header. */ |
| 223 | offset = sizeof(struct fmap); |
| 224 | |
| 225 | while (1) { |
| 226 | struct fmap_area *area; |
| 227 | |
| 228 | area = rdev_mmap(&fmrd, offset, sizeof(*area)); |
| 229 | |
| 230 | if (area == NULL) |
| 231 | return -1; |
| 232 | |
Krystian Hebel | 93f6b8a | 2020-09-30 18:23:14 +0200 | [diff] [blame] | 233 | if ((ar->offset != le32toh(area->offset)) || |
| 234 | (ar->size != le32toh(area->size))) { |
Patrick Georgi | 9952690 | 2015-07-09 11:27:44 +0200 | [diff] [blame] | 235 | rdev_munmap(&fmrd, area); |
| 236 | offset += sizeof(struct fmap_area); |
| 237 | continue; |
| 238 | } |
| 239 | |
| 240 | printk(BIOS_DEBUG, "FMAP: area (%zx, %zx) found, named %s\n", |
| 241 | ar->offset, ar->size, area->name); |
| 242 | |
| 243 | memcpy(name, area->name, FMAP_STRLEN); |
| 244 | |
| 245 | rdev_munmap(&fmrd, area); |
| 246 | |
| 247 | return 0; |
| 248 | } |
| 249 | |
| 250 | printk(BIOS_DEBUG, "FMAP: area (%zx, %zx) not found\n", |
| 251 | ar->offset, ar->size); |
| 252 | |
| 253 | return -1; |
| 254 | } |
T Michael Turney | 19fcc89 | 2019-03-20 14:37:34 -0700 | [diff] [blame] | 255 | |
| 256 | ssize_t fmap_read_area(const char *name, void *buffer, size_t size) |
| 257 | { |
| 258 | struct region_device rdev; |
| 259 | if (fmap_locate_area_as_rdev(name, &rdev)) |
| 260 | return -1; |
| 261 | return rdev_readat(&rdev, buffer, 0, |
| 262 | MIN(size, region_device_sz(&rdev))); |
| 263 | } |
| 264 | |
| 265 | ssize_t fmap_overwrite_area(const char *name, const void *buffer, size_t size) |
| 266 | { |
| 267 | struct region_device rdev; |
| 268 | |
| 269 | if (fmap_locate_area_as_rdev_rw(name, &rdev)) |
| 270 | return -1; |
| 271 | if (size > region_device_sz(&rdev)) |
| 272 | return -1; |
| 273 | if (rdev_eraseat(&rdev, 0, region_device_sz(&rdev)) < 0) |
| 274 | return -1; |
| 275 | return rdev_writeat(&rdev, buffer, 0, size); |
| 276 | } |
Patrick Rudolph | 6d787c2 | 2019-09-12 13:21:37 +0200 | [diff] [blame] | 277 | |
Kyösti Mälkki | 845f232 | 2022-04-06 10:53:17 +0300 | [diff] [blame] | 278 | static void fmap_register_cbmem_cache(void) |
Patrick Rudolph | 6d787c2 | 2019-09-12 13:21:37 +0200 | [diff] [blame] | 279 | { |
| 280 | const struct cbmem_entry *e; |
Patrick Rudolph | 6d787c2 | 2019-09-12 13:21:37 +0200 | [diff] [blame] | 281 | |
| 282 | /* Find the FMAP cache installed by previous stage */ |
| 283 | e = cbmem_entry_find(CBMEM_ID_FMAP); |
| 284 | /* Don't set fmap_cache so that find_fmap_directory will use regular path */ |
| 285 | if (!e) |
| 286 | return; |
| 287 | |
Julius Werner | c893197 | 2021-04-16 16:48:32 -0700 | [diff] [blame] | 288 | rdev_chain_mem(&fmap_cache, cbmem_entry_start(e), cbmem_entry_size(e)); |
Patrick Rudolph | 6d787c2 | 2019-09-12 13:21:37 +0200 | [diff] [blame] | 289 | } |
| 290 | |
| 291 | /* |
| 292 | * The main reason to copy the FMAP into CBMEM is to make it available to the |
| 293 | * OS on every architecture. As side effect use the CBMEM copy as cache. |
| 294 | */ |
Kyösti Mälkki | 845f232 | 2022-04-06 10:53:17 +0300 | [diff] [blame] | 295 | static void fmap_add_cbmem_cache(void) |
Patrick Rudolph | 6d787c2 | 2019-09-12 13:21:37 +0200 | [diff] [blame] | 296 | { |
| 297 | struct region_device fmrd; |
| 298 | |
| 299 | if (find_fmap_directory(&fmrd)) |
| 300 | return; |
| 301 | |
| 302 | /* Reloads the FMAP even on ACPI S3 resume */ |
| 303 | const size_t s = region_device_sz(&fmrd); |
| 304 | struct fmap *fmap = cbmem_add(CBMEM_ID_FMAP, s); |
| 305 | if (!fmap) { |
Julius Werner | e966595 | 2022-01-21 17:06:20 -0800 | [diff] [blame] | 306 | printk(BIOS_ERR, "Failed to allocate CBMEM\n"); |
Patrick Rudolph | 6d787c2 | 2019-09-12 13:21:37 +0200 | [diff] [blame] | 307 | return; |
| 308 | } |
| 309 | |
| 310 | const ssize_t ret = rdev_readat(&fmrd, fmap, 0, s); |
| 311 | if (ret != s) { |
Julius Werner | e966595 | 2022-01-21 17:06:20 -0800 | [diff] [blame] | 312 | printk(BIOS_ERR, "Failed to read FMAP into CBMEM\n"); |
Patrick Rudolph | 6d787c2 | 2019-09-12 13:21:37 +0200 | [diff] [blame] | 313 | cbmem_entry_remove(cbmem_entry_find(CBMEM_ID_FMAP)); |
| 314 | return; |
| 315 | } |
Kyösti Mälkki | 845f232 | 2022-04-06 10:53:17 +0300 | [diff] [blame] | 316 | } |
| 317 | |
| 318 | static void fmap_setup_cbmem_cache(int unused) |
| 319 | { |
Kyösti Mälkki | fa3bc04 | 2022-03-31 07:40:10 +0300 | [diff] [blame] | 320 | if (ENV_CREATES_CBMEM) |
Kyösti Mälkki | 845f232 | 2022-04-06 10:53:17 +0300 | [diff] [blame] | 321 | fmap_add_cbmem_cache(); |
Patrick Rudolph | 6d787c2 | 2019-09-12 13:21:37 +0200 | [diff] [blame] | 322 | |
| 323 | /* Finally advertise the cache for the current stage */ |
Kyösti Mälkki | 845f232 | 2022-04-06 10:53:17 +0300 | [diff] [blame] | 324 | fmap_register_cbmem_cache(); |
Patrick Rudolph | 6d787c2 | 2019-09-12 13:21:37 +0200 | [diff] [blame] | 325 | } |
| 326 | |
Kyösti Mälkki | fa3bc04 | 2022-03-31 07:40:10 +0300 | [diff] [blame] | 327 | CBMEM_READY_HOOK(fmap_setup_cbmem_cache); |