blob: bca4c3e3b7aae244b758c7e1f547f62d3058806f [file] [log] [blame]
Angel Pons986d50e2020-04-02 23:48:53 +02001/* SPDX-License-Identifier: GPL-2.0-only */
Aaron Durbin17200ad2015-05-01 16:48:54 -05002
3#include <cbfs.h>
4#include <console/console.h>
Aaron Durbinf7ce40b2016-08-24 14:58:12 -05005#include <ec/google/chromeec/ec.h>
Aaron Durbin09560fa2015-05-12 16:43:10 -05006#include <rmodule.h>
Philipp Deppenwiesefea24292017-10-17 17:02:29 +02007#include <security/vboot/misc.h>
8#include <security/vboot/symbols.h>
9#include <security/vboot/vboot_common.h>
Aaron Durbin17200ad2015-05-01 16:48:54 -050010
Julius Werner73d042b2017-03-17 16:54:48 -070011/* Ensure vboot configuration is valid: */
Julius Wernercd49cce2019-03-05 16:53:33 -080012_Static_assert(CONFIG(VBOOT_STARTS_IN_BOOTBLOCK) +
Martin Roth8a3a3c82020-05-04 10:13:45 -060013 CONFIG(VBOOT_STARTS_BEFORE_BOOTBLOCK) +
Julius Wernercd49cce2019-03-05 16:53:33 -080014 CONFIG(VBOOT_STARTS_IN_ROMSTAGE) == 1,
Martin Roth8a3a3c82020-05-04 10:13:45 -060015 "vboot must start in bootblock, PSP or romstage (but only one!)");
16_Static_assert(!CONFIG(VBOOT_SEPARATE_VERSTAGE) || CONFIG(VBOOT_STARTS_IN_BOOTBLOCK) ||
17 CONFIG(VBOOT_STARTS_BEFORE_BOOTBLOCK),
18 "stand-alone verstage must start in or before bootblock ");
Julius Wernercd49cce2019-03-05 16:53:33 -080019_Static_assert(!CONFIG(VBOOT_RETURN_FROM_VERSTAGE) ||
20 CONFIG(VBOOT_SEPARATE_VERSTAGE),
Julius Werner73d042b2017-03-17 16:54:48 -070021 "return from verstage only makes sense for separate verstages");
22
Arthur Heymans344e86b2019-11-20 19:47:10 +010023int vboot_executed;
Aaron Durbin6d720f32015-12-08 17:00:23 -060024
Wim Vervoorn1058dd82019-11-01 10:22:22 +010025void vboot_run_logic(void)
Aaron Durbin17200ad2015-05-01 16:48:54 -050026{
Paul Kocialkowski18117682016-05-14 15:30:52 +020027 if (verification_should_run()) {
Julius Werner58c39382017-02-13 17:53:29 -080028 /* Note: this path is not used for VBOOT_RETURN_FROM_VERSTAGE */
Aaron Durbin17200ad2015-05-01 16:48:54 -050029 verstage_main();
Arthur Heymans344e86b2019-11-20 19:47:10 +010030 vboot_executed = 1;
Aaron Durbin17200ad2015-05-01 16:48:54 -050031 } else if (verstage_should_load()) {
Aaron Durbin37a5d152015-09-17 16:09:30 -050032 struct cbfsf file;
Aaron Durbinac12c66c2015-05-20 12:08:55 -050033 struct prog verstage =
Aaron Durbin7e7a4df2015-12-08 14:34:35 -060034 PROG_INIT(PROG_VERSTAGE,
Aaron Durbinac12c66c2015-05-20 12:08:55 -050035 CONFIG_CBFS_PREFIX "/verstage");
Aaron Durbin17200ad2015-05-01 16:48:54 -050036
Aaron Durbince2c50d2015-05-13 13:33:27 -050037 printk(BIOS_DEBUG, "VBOOT: Loading verstage.\n");
38
Aaron Durbin17200ad2015-05-01 16:48:54 -050039 /* load verstage from RO */
Aaron Durbin37a5d152015-09-17 16:09:30 -050040 if (cbfs_boot_locate(&file, prog_name(&verstage), NULL))
41 die("failed to load verstage");
42
43 cbfs_file_data(prog_rdev(&verstage), &file);
44
45 if (cbfs_prog_stage_load(&verstage))
Aaron Durbin17200ad2015-05-01 16:48:54 -050046 die("failed to load verstage");
47
48 /* verify and select a slot */
49 prog_run(&verstage);
50
51 /* This is not actually possible to hit this condition at
52 * runtime, but this provides a hint to the compiler for dead
53 * code elimination below. */
Julius Wernercd49cce2019-03-05 16:53:33 -080054 if (!CONFIG(VBOOT_RETURN_FROM_VERSTAGE))
Aaron Durbin6d720f32015-12-08 17:00:23 -060055 return;
56
Arthur Heymans344e86b2019-11-20 19:47:10 +010057 vboot_executed = 1;
Aaron Durbin17200ad2015-05-01 16:48:54 -050058 }
Aaron Durbin17200ad2015-05-01 16:48:54 -050059}
60
Julius Werner815611e2019-12-05 22:29:07 -080061int vboot_locate_cbfs(struct region_device *rdev)
Aaron Durbin17200ad2015-05-01 16:48:54 -050062{
Julius Wernerf8e17642019-12-12 13:23:06 -080063 struct vb2_context *ctx;
Aaron Durbin899d13d2015-05-15 23:39:23 -050064
Aaron Durbin6d720f32015-12-08 17:00:23 -060065 /* Don't honor vboot results until the vboot logic has run. */
Joel Kitchingaf8471c2019-03-13 22:38:07 +080066 if (!vboot_logic_executed())
Aaron Durbinb6981c02015-05-15 15:57:51 -050067 return -1;
Aaron Durbin17200ad2015-05-01 16:48:54 -050068
Yu-Ping Wuaeb652a2019-11-14 15:42:25 +080069 ctx = vboot_get_context();
70
71 if (ctx->flags & VB2_CONTEXT_RECOVERY_MODE)
Aaron Durbin4e50cdd2015-05-15 23:25:46 -050072 return -1;
Aaron Durbinb6981c02015-05-15 15:57:51 -050073
Aaron Durbinfe338e22019-11-18 12:35:21 -070074 return vboot_locate_firmware(ctx, rdev);
Aaron Durbin17200ad2015-05-01 16:48:54 -050075}