2nvstorage.c 9.8 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371
  1. /* Copyright (c) 2014 The Chromium OS Authors. All rights reserved.
  2. * Use of this source code is governed by a BSD-style license that can be
  3. * found in the LICENSE file.
  4. */
  5. /* Non-volatile storage routines */
  6. #include "2sysincludes.h"
  7. #include "2common.h"
  8. #include "2crc8.h"
  9. #include "2misc.h"
  10. #include "2nvstorage.h"
  11. #include "2nvstorage_fields.h"
  12. static void vb2_nv_regen_crc(struct vb2_context *ctx)
  13. {
  14. ctx->nvdata[VB2_NV_OFFS_CRC] = vb2_crc8(ctx->nvdata, VB2_NV_OFFS_CRC);
  15. ctx->flags |= VB2_CONTEXT_NVDATA_CHANGED;
  16. }
  17. /**
  18. * Check the CRC of the non-volatile storage context.
  19. *
  20. * Use this if reading from non-volatile storage may be flaky, and you want to
  21. * retry reading it several times.
  22. *
  23. * This may be called before vb2_context_init().
  24. *
  25. * @param ctx Context pointer
  26. * @return VB2_SUCCESS, or non-zero error code if error.
  27. */
  28. int vb2_nv_check_crc(const struct vb2_context *ctx)
  29. {
  30. const uint8_t *p = ctx->nvdata;
  31. /* Check header */
  32. if (VB2_NV_HEADER_SIGNATURE !=
  33. (p[VB2_NV_OFFS_HEADER] & VB2_NV_HEADER_MASK))
  34. return VB2_ERROR_NV_HEADER;
  35. /* Check CRC */
  36. if (vb2_crc8(p, VB2_NV_OFFS_CRC) != p[VB2_NV_OFFS_CRC])
  37. return VB2_ERROR_NV_CRC;
  38. return VB2_SUCCESS;
  39. }
  40. void vb2_nv_init(struct vb2_context *ctx)
  41. {
  42. struct vb2_shared_data *sd = vb2_get_sd(ctx);
  43. uint8_t *p = ctx->nvdata;
  44. /* Check data for consistency */
  45. if (vb2_nv_check_crc(ctx) != VB2_SUCCESS) {
  46. /* Data is inconsistent (bad CRC or header); reset defaults */
  47. memset(p, 0, VB2_NVDATA_SIZE);
  48. p[VB2_NV_OFFS_HEADER] = (VB2_NV_HEADER_SIGNATURE |
  49. VB2_NV_HEADER_FW_SETTINGS_RESET |
  50. VB2_NV_HEADER_KERNEL_SETTINGS_RESET);
  51. /* Regenerate CRC */
  52. vb2_nv_regen_crc(ctx);
  53. /* Set status flag */
  54. sd->status |= VB2_SD_STATUS_NV_REINIT;
  55. /* TODO: unit test for status flag being set */
  56. }
  57. sd->status |= VB2_SD_STATUS_NV_INIT;
  58. }
  59. /* Macro for vb2_nv_get() single-bit settings to reduce duplicate code. */
  60. #define GETBIT(offs, mask) (p[offs] & mask ? 1 : 0)
  61. uint32_t vb2_nv_get(struct vb2_context *ctx, enum vb2_nv_param param)
  62. {
  63. const uint8_t *p = ctx->nvdata;
  64. /*
  65. * TODO: We could reduce the binary size for this code by #ifdef'ing
  66. * out the params not used by firmware verification.
  67. */
  68. switch (param) {
  69. case VB2_NV_FIRMWARE_SETTINGS_RESET:
  70. return GETBIT(VB2_NV_OFFS_HEADER,
  71. VB2_NV_HEADER_FW_SETTINGS_RESET);
  72. case VB2_NV_KERNEL_SETTINGS_RESET:
  73. return GETBIT(VB2_NV_OFFS_HEADER,
  74. VB2_NV_HEADER_KERNEL_SETTINGS_RESET);
  75. case VB2_NV_DEBUG_RESET_MODE:
  76. return GETBIT(VB2_NV_OFFS_BOOT, VB2_NV_BOOT_DEBUG_RESET);
  77. case VB2_NV_TRY_NEXT:
  78. return GETBIT(VB2_NV_OFFS_BOOT2, VB2_NV_BOOT2_TRY_NEXT);
  79. case VB2_NV_TRY_COUNT:
  80. return p[VB2_NV_OFFS_BOOT] & VB2_NV_BOOT_TRY_COUNT_MASK;
  81. case VB2_NV_FW_TRIED:
  82. return GETBIT(VB2_NV_OFFS_BOOT2, VB2_NV_BOOT2_TRIED);
  83. case VB2_NV_FW_RESULT:
  84. return p[VB2_NV_OFFS_BOOT2] & VB2_NV_BOOT2_RESULT_MASK;
  85. case VB2_NV_FW_PREV_TRIED:
  86. return GETBIT(VB2_NV_OFFS_BOOT2, VB2_NV_BOOT2_PREV_TRIED);
  87. case VB2_NV_FW_PREV_RESULT:
  88. return (p[VB2_NV_OFFS_BOOT2] & VB2_NV_BOOT2_PREV_RESULT_MASK)
  89. >> VB2_NV_BOOT2_PREV_RESULT_SHIFT;
  90. case VB2_NV_RECOVERY_REQUEST:
  91. return p[VB2_NV_OFFS_RECOVERY];
  92. case VB2_NV_RECOVERY_SUBCODE:
  93. return p[VB2_NV_OFFS_RECOVERY_SUBCODE];
  94. case VB2_NV_LOCALIZATION_INDEX:
  95. return p[VB2_NV_OFFS_LOCALIZATION];
  96. case VB2_NV_KERNEL_FIELD:
  97. return (p[VB2_NV_OFFS_KERNEL]
  98. | (p[VB2_NV_OFFS_KERNEL + 1] << 8)
  99. | (p[VB2_NV_OFFS_KERNEL + 2] << 16)
  100. | (p[VB2_NV_OFFS_KERNEL + 3] << 24));
  101. case VB2_NV_DEV_BOOT_USB:
  102. return GETBIT(VB2_NV_OFFS_DEV, VB2_NV_DEV_FLAG_USB);
  103. case VB2_NV_DEV_BOOT_LEGACY:
  104. return GETBIT(VB2_NV_OFFS_DEV, VB2_NV_DEV_FLAG_LEGACY);
  105. case VB2_NV_DEV_BOOT_SIGNED_ONLY:
  106. return GETBIT(VB2_NV_OFFS_DEV, VB2_NV_DEV_FLAG_SIGNED_ONLY);
  107. case VB2_NV_DEV_BOOT_FASTBOOT_FULL_CAP:
  108. return GETBIT(VB2_NV_OFFS_DEV,
  109. VB2_NV_DEV_FLAG_FASTBOOT_FULL_CAP);
  110. case VB2_NV_DEV_DEFAULT_BOOT:
  111. return (p[VB2_NV_OFFS_DEV] & VB2_NV_DEV_FLAG_DEFAULT_BOOT)
  112. >> VB2_NV_DEV_DEFAULT_BOOT_SHIFT;
  113. case VB2_NV_DISABLE_DEV_REQUEST:
  114. return GETBIT(VB2_NV_OFFS_BOOT, VB2_NV_BOOT_DISABLE_DEV);
  115. case VB2_NV_OPROM_NEEDED:
  116. return GETBIT(VB2_NV_OFFS_BOOT, VB2_NV_BOOT_OPROM_NEEDED);
  117. case VB2_NV_BACKUP_NVRAM_REQUEST:
  118. return GETBIT(VB2_NV_OFFS_BOOT, VB2_NV_BOOT_BACKUP_NVRAM);
  119. case VB2_NV_CLEAR_TPM_OWNER_REQUEST:
  120. return GETBIT(VB2_NV_OFFS_TPM, VB2_NV_TPM_CLEAR_OWNER_REQUEST);
  121. case VB2_NV_CLEAR_TPM_OWNER_DONE:
  122. return GETBIT(VB2_NV_OFFS_TPM, VB2_NV_TPM_CLEAR_OWNER_DONE);
  123. case VB2_NV_TPM_REQUESTED_REBOOT:
  124. return GETBIT(VB2_NV_OFFS_TPM, VB2_NV_TPM_REBOOTED);
  125. case VB2_NV_REQ_WIPEOUT:
  126. return GETBIT(VB2_NV_OFFS_HEADER , VB2_NV_HEADER_WIPEOUT);
  127. case VB2_NV_FASTBOOT_UNLOCK_IN_FW:
  128. return GETBIT(VB2_NV_OFFS_MISC, VB2_NV_MISC_UNLOCK_FASTBOOT);
  129. case VB2_NV_BOOT_ON_AC_DETECT:
  130. return GETBIT(VB2_NV_OFFS_MISC, VB2_NV_MISC_BOOT_ON_AC_DETECT);
  131. case VB2_NV_TRY_RO_SYNC:
  132. return GETBIT(VB2_NV_OFFS_MISC, VB2_NV_MISC_TRY_RO_SYNC);
  133. case VB2_NV_BATTERY_CUTOFF_REQUEST:
  134. return GETBIT(VB2_NV_OFFS_MISC, VB2_NV_MISC_BATTERY_CUTOFF);
  135. }
  136. /*
  137. * Put default return outside the switch() instead of in default:, so
  138. * that adding a new param will cause a compiler warning.
  139. */
  140. return 0;
  141. }
  142. #undef GETBIT
  143. /* Macro for vb2_nv_set() single-bit settings to reduce duplicate code. */
  144. #define SETBIT(offs, mask) \
  145. { if (value) p[offs] |= mask; else p[offs] &= ~mask; }
  146. void vb2_nv_set(struct vb2_context *ctx,
  147. enum vb2_nv_param param,
  148. uint32_t value)
  149. {
  150. uint8_t *p = ctx->nvdata;
  151. /* If not changing the value, don't regenerate the CRC. */
  152. if (vb2_nv_get(ctx, param) == value)
  153. return;
  154. /*
  155. * TODO: We could reduce the binary size for this code by #ifdef'ing
  156. * out the params not used by firmware verification.
  157. */
  158. switch (param) {
  159. case VB2_NV_FIRMWARE_SETTINGS_RESET:
  160. SETBIT(VB2_NV_OFFS_HEADER, VB2_NV_HEADER_FW_SETTINGS_RESET);
  161. break;
  162. case VB2_NV_KERNEL_SETTINGS_RESET:
  163. SETBIT(VB2_NV_OFFS_HEADER, VB2_NV_HEADER_KERNEL_SETTINGS_RESET);
  164. break;
  165. case VB2_NV_DEBUG_RESET_MODE:
  166. SETBIT(VB2_NV_OFFS_BOOT, VB2_NV_BOOT_DEBUG_RESET);
  167. break;
  168. case VB2_NV_TRY_NEXT:
  169. SETBIT(VB2_NV_OFFS_BOOT2, VB2_NV_BOOT2_TRY_NEXT);
  170. break;
  171. case VB2_NV_TRY_COUNT:
  172. /* Clip to valid range. */
  173. if (value > VB2_NV_BOOT_TRY_COUNT_MASK)
  174. value = VB2_NV_BOOT_TRY_COUNT_MASK;
  175. p[VB2_NV_OFFS_BOOT] &= ~VB2_NV_BOOT_TRY_COUNT_MASK;
  176. p[VB2_NV_OFFS_BOOT] |= (uint8_t)value;
  177. break;
  178. case VB2_NV_FW_TRIED:
  179. SETBIT(VB2_NV_OFFS_BOOT2, VB2_NV_BOOT2_TRIED);
  180. break;
  181. case VB2_NV_FW_RESULT:
  182. /* Map out of range values to unknown */
  183. if (value > VB2_NV_BOOT2_RESULT_MASK)
  184. value = VB2_FW_RESULT_UNKNOWN;
  185. p[VB2_NV_OFFS_BOOT2] &= ~VB2_NV_BOOT2_RESULT_MASK;
  186. p[VB2_NV_OFFS_BOOT2] |= (uint8_t)value;
  187. break;
  188. case VB2_NV_FW_PREV_TRIED:
  189. SETBIT(VB2_NV_OFFS_BOOT2, VB2_NV_BOOT2_PREV_TRIED);
  190. break;
  191. case VB2_NV_FW_PREV_RESULT:
  192. /* Map out of range values to unknown */
  193. if (value > VB2_NV_BOOT2_RESULT_MASK)
  194. value = VB2_FW_RESULT_UNKNOWN;
  195. p[VB2_NV_OFFS_BOOT2] &= ~VB2_NV_BOOT2_PREV_RESULT_MASK;
  196. p[VB2_NV_OFFS_BOOT2] |=
  197. (uint8_t)(value << VB2_NV_BOOT2_PREV_RESULT_SHIFT);
  198. break;
  199. case VB2_NV_RECOVERY_REQUEST:
  200. /*
  201. * Map values outside the valid range to the legacy reason,
  202. * since we can't determine if we're called from kernel or user
  203. * mode.
  204. */
  205. if (value > 0xff)
  206. value = VB2_RECOVERY_LEGACY;
  207. p[VB2_NV_OFFS_RECOVERY] = (uint8_t)value;
  208. break;
  209. case VB2_NV_RECOVERY_SUBCODE:
  210. p[VB2_NV_OFFS_RECOVERY_SUBCODE] = (uint8_t)value;
  211. break;
  212. case VB2_NV_LOCALIZATION_INDEX:
  213. /* Map values outside the valid range to the default index. */
  214. if (value > 0xFF)
  215. value = 0;
  216. p[VB2_NV_OFFS_LOCALIZATION] = (uint8_t)value;
  217. break;
  218. case VB2_NV_KERNEL_FIELD:
  219. p[VB2_NV_OFFS_KERNEL] = (uint8_t)(value);
  220. p[VB2_NV_OFFS_KERNEL + 1] = (uint8_t)(value >> 8);
  221. p[VB2_NV_OFFS_KERNEL + 2] = (uint8_t)(value >> 16);
  222. p[VB2_NV_OFFS_KERNEL + 3] = (uint8_t)(value >> 24);
  223. break;
  224. case VB2_NV_DEV_BOOT_USB:
  225. SETBIT(VB2_NV_OFFS_DEV, VB2_NV_DEV_FLAG_USB);
  226. break;
  227. case VB2_NV_DEV_BOOT_LEGACY:
  228. SETBIT(VB2_NV_OFFS_DEV, VB2_NV_DEV_FLAG_LEGACY);
  229. break;
  230. case VB2_NV_DEV_BOOT_SIGNED_ONLY:
  231. SETBIT(VB2_NV_OFFS_DEV, VB2_NV_DEV_FLAG_SIGNED_ONLY);
  232. break;
  233. case VB2_NV_DEV_BOOT_FASTBOOT_FULL_CAP:
  234. SETBIT(VB2_NV_OFFS_DEV, VB2_NV_DEV_FLAG_FASTBOOT_FULL_CAP);
  235. break;
  236. case VB2_NV_DEV_DEFAULT_BOOT:
  237. /* Map out of range values to disk */
  238. if (value > (VB2_NV_DEV_FLAG_DEFAULT_BOOT >>
  239. VB2_NV_DEV_DEFAULT_BOOT_SHIFT))
  240. value = VB2_DEV_DEFAULT_BOOT_DISK;
  241. p[VB2_NV_OFFS_DEV] &= ~VB2_NV_DEV_FLAG_DEFAULT_BOOT;
  242. p[VB2_NV_OFFS_DEV] |=
  243. (uint8_t)(value << VB2_NV_DEV_DEFAULT_BOOT_SHIFT);
  244. break;
  245. case VB2_NV_DISABLE_DEV_REQUEST:
  246. SETBIT(VB2_NV_OFFS_BOOT, VB2_NV_BOOT_DISABLE_DEV);
  247. break;
  248. case VB2_NV_OPROM_NEEDED:
  249. SETBIT(VB2_NV_OFFS_BOOT, VB2_NV_BOOT_OPROM_NEEDED);
  250. break;
  251. case VB2_NV_BACKUP_NVRAM_REQUEST:
  252. SETBIT(VB2_NV_OFFS_BOOT, VB2_NV_BOOT_BACKUP_NVRAM);
  253. break;
  254. case VB2_NV_CLEAR_TPM_OWNER_REQUEST:
  255. SETBIT(VB2_NV_OFFS_TPM, VB2_NV_TPM_CLEAR_OWNER_REQUEST);
  256. break;
  257. case VB2_NV_CLEAR_TPM_OWNER_DONE:
  258. SETBIT(VB2_NV_OFFS_TPM, VB2_NV_TPM_CLEAR_OWNER_DONE);
  259. break;
  260. case VB2_NV_TPM_REQUESTED_REBOOT:
  261. SETBIT(VB2_NV_OFFS_TPM, VB2_NV_TPM_REBOOTED);
  262. break;
  263. case VB2_NV_REQ_WIPEOUT:
  264. SETBIT(VB2_NV_OFFS_HEADER , VB2_NV_HEADER_WIPEOUT);
  265. break;
  266. case VB2_NV_FASTBOOT_UNLOCK_IN_FW:
  267. SETBIT(VB2_NV_OFFS_MISC, VB2_NV_MISC_UNLOCK_FASTBOOT);
  268. break;
  269. case VB2_NV_BOOT_ON_AC_DETECT:
  270. SETBIT(VB2_NV_OFFS_MISC, VB2_NV_MISC_BOOT_ON_AC_DETECT);
  271. break;
  272. case VB2_NV_TRY_RO_SYNC:
  273. SETBIT(VB2_NV_OFFS_MISC, VB2_NV_MISC_TRY_RO_SYNC);
  274. break;
  275. case VB2_NV_BATTERY_CUTOFF_REQUEST:
  276. SETBIT(VB2_NV_OFFS_MISC, VB2_NV_MISC_BATTERY_CUTOFF);
  277. break;
  278. }
  279. /*
  280. * Note there is no default case. This causes a compiler warning if
  281. * a new param is added to the enum without adding support here.
  282. */
  283. /* Need to regenerate CRC, since the value changed. */
  284. vb2_nv_regen_crc(ctx);
  285. }
  286. #undef SETBIT