blob: dc8ba3777b04779061b6a9f0eb122a3d06ee3815 [file] [log] [blame]
Angel Pons986d50e2020-04-02 23:48:53 +02001/* SPDX-License-Identifier: GPL-2.0-only */
Aaron Durbin17200ad2015-05-01 16:48:54 -05002
3#include <cbfs.h>
4#include <console/console.h>
Aaron Durbinf7ce40b2016-08-24 14:58:12 -05005#include <ec/google/chromeec/ec.h>
Aaron Durbin09560fa2015-05-12 16:43:10 -05006#include <rmodule.h>
Philipp Deppenwiesefea24292017-10-17 17:02:29 +02007#include <security/vboot/misc.h>
8#include <security/vboot/symbols.h>
9#include <security/vboot/vboot_common.h>
Aaron Durbin17200ad2015-05-01 16:48:54 -050010
Julius Werner73d042b2017-03-17 16:54:48 -070011/* Ensure vboot configuration is valid: */
Julius Wernercd49cce2019-03-05 16:53:33 -080012_Static_assert(CONFIG(VBOOT_STARTS_IN_BOOTBLOCK) +
13 CONFIG(VBOOT_STARTS_IN_ROMSTAGE) == 1,
Julius Werner73d042b2017-03-17 16:54:48 -070014 "vboot must either start in bootblock or romstage (not both!)");
Julius Wernercd49cce2019-03-05 16:53:33 -080015_Static_assert(!CONFIG(VBOOT_SEPARATE_VERSTAGE) ||
16 CONFIG(VBOOT_STARTS_IN_BOOTBLOCK),
Julius Werner73d042b2017-03-17 16:54:48 -070017 "stand-alone verstage must start in (i.e. after) bootblock");
Julius Wernercd49cce2019-03-05 16:53:33 -080018_Static_assert(!CONFIG(VBOOT_RETURN_FROM_VERSTAGE) ||
19 CONFIG(VBOOT_SEPARATE_VERSTAGE),
Julius Werner73d042b2017-03-17 16:54:48 -070020 "return from verstage only makes sense for separate verstages");
21
Arthur Heymans344e86b2019-11-20 19:47:10 +010022int vboot_executed;
Aaron Durbin6d720f32015-12-08 17:00:23 -060023
Wim Vervoorn1058dd82019-11-01 10:22:22 +010024void vboot_run_logic(void)
Aaron Durbin17200ad2015-05-01 16:48:54 -050025{
Paul Kocialkowski18117682016-05-14 15:30:52 +020026 if (verification_should_run()) {
Julius Werner58c39382017-02-13 17:53:29 -080027 /* Note: this path is not used for VBOOT_RETURN_FROM_VERSTAGE */
Aaron Durbin17200ad2015-05-01 16:48:54 -050028 verstage_main();
Arthur Heymans344e86b2019-11-20 19:47:10 +010029 vboot_executed = 1;
Aaron Durbin17200ad2015-05-01 16:48:54 -050030 } else if (verstage_should_load()) {
Aaron Durbin37a5d152015-09-17 16:09:30 -050031 struct cbfsf file;
Aaron Durbinac12c66c2015-05-20 12:08:55 -050032 struct prog verstage =
Aaron Durbin7e7a4df2015-12-08 14:34:35 -060033 PROG_INIT(PROG_VERSTAGE,
Aaron Durbinac12c66c2015-05-20 12:08:55 -050034 CONFIG_CBFS_PREFIX "/verstage");
Aaron Durbin17200ad2015-05-01 16:48:54 -050035
Aaron Durbince2c50d2015-05-13 13:33:27 -050036 printk(BIOS_DEBUG, "VBOOT: Loading verstage.\n");
37
Aaron Durbin17200ad2015-05-01 16:48:54 -050038 /* load verstage from RO */
Aaron Durbin37a5d152015-09-17 16:09:30 -050039 if (cbfs_boot_locate(&file, prog_name(&verstage), NULL))
40 die("failed to load verstage");
41
42 cbfs_file_data(prog_rdev(&verstage), &file);
43
44 if (cbfs_prog_stage_load(&verstage))
Aaron Durbin17200ad2015-05-01 16:48:54 -050045 die("failed to load verstage");
46
47 /* verify and select a slot */
48 prog_run(&verstage);
49
50 /* This is not actually possible to hit this condition at
51 * runtime, but this provides a hint to the compiler for dead
52 * code elimination below. */
Julius Wernercd49cce2019-03-05 16:53:33 -080053 if (!CONFIG(VBOOT_RETURN_FROM_VERSTAGE))
Aaron Durbin6d720f32015-12-08 17:00:23 -060054 return;
55
Arthur Heymans344e86b2019-11-20 19:47:10 +010056 vboot_executed = 1;
Aaron Durbin17200ad2015-05-01 16:48:54 -050057 }
Aaron Durbin17200ad2015-05-01 16:48:54 -050058}
59
Julius Werner815611e2019-12-05 22:29:07 -080060int vboot_locate_cbfs(struct region_device *rdev)
Aaron Durbin17200ad2015-05-01 16:48:54 -050061{
Julius Wernerf8e17642019-12-12 13:23:06 -080062 struct vb2_context *ctx;
Aaron Durbin899d13d2015-05-15 23:39:23 -050063
Aaron Durbin6d720f32015-12-08 17:00:23 -060064 /* Don't honor vboot results until the vboot logic has run. */
Joel Kitchingaf8471c2019-03-13 22:38:07 +080065 if (!vboot_logic_executed())
Aaron Durbinb6981c02015-05-15 15:57:51 -050066 return -1;
Aaron Durbin17200ad2015-05-01 16:48:54 -050067
Yu-Ping Wuaeb652a2019-11-14 15:42:25 +080068 ctx = vboot_get_context();
69
70 if (ctx->flags & VB2_CONTEXT_RECOVERY_MODE)
Aaron Durbin4e50cdd2015-05-15 23:25:46 -050071 return -1;
Aaron Durbinb6981c02015-05-15 15:57:51 -050072
Aaron Durbinfe338e22019-11-18 12:35:21 -070073 return vboot_locate_firmware(ctx, rdev);
Aaron Durbin17200ad2015-05-01 16:48:54 -050074}