blob: 6c55ac805f3f1f28275991df4c0e583d55ad511b [file] [log] [blame]
Tamas Banf70ef8c2017-12-19 15:35:09 +00001/*
2 * Copyright (c) 2012-2014 Wind River Systems, Inc.
David Vincze225c58f2019-12-09 17:32:48 +01003 * Copyright (c) 2017-2020 Arm Limited.
Tamas Banf70ef8c2017-12-19 15:35:09 +00004 *
5 * Licensed under the Apache License, Version 2.0 (the "License");
6 * you may not use this file except in compliance with the License.
7 * You may obtain a copy of the License at
8 *
9 * http://www.apache.org/licenses/LICENSE-2.0
10 *
11 * Unless required by applicable law or agreed to in writing, software
12 * distributed under the License is distributed on an "AS IS" BASIS,
13 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
14 * See the License for the specific language governing permissions and
15 * limitations under the License.
16 */
17
18#include <assert.h>
Tamas Ban581034a2017-12-19 19:54:37 +000019#include "bl2_util.h"
Tamas Banf70ef8c2017-12-19 15:35:09 +000020#include "target.h"
Kevin Pengbc5e5aa2019-10-16 10:55:17 +080021#include "tfm_hal_device_header.h"
Tamas Banc3828852018-02-01 12:24:16 +000022#include "Driver_Flash.h"
Tamas Banbd3f7512018-01-26 15:45:03 +000023#include "mbedtls/memory_buffer_alloc.h"
Tamas Banf70ef8c2017-12-19 15:35:09 +000024#include "bootutil/bootutil_log.h"
25#include "bootutil/image.h"
26#include "bootutil/bootutil.h"
David Vincze225c58f2019-12-09 17:32:48 +010027#include "flash_map_backend/flash_map_backend.h"
28#include "boot_record.h"
David Vincze060968d2019-05-23 01:13:14 +020029#include "security_cnt.h"
David Vincze225c58f2019-12-09 17:32:48 +010030#include "boot_hal.h"
TTornblom83d96372019-11-19 12:53:16 +010031#include "region.h"
David Vincze99f1b362019-12-12 16:17:35 +010032#if MCUBOOT_LOG_LEVEL > MCUBOOT_LOG_LEVEL_OFF
David Vincze73dfbc52019-10-11 13:54:58 +020033#include "uart_stdout.h"
34#endif
Tamas Banf824e742019-10-25 21:22:26 +010035#if defined(CRYPTO_HW_ACCELERATOR) || \
36 defined(CRYPTO_HW_ACCELERATOR_OTP_PROVISIONING)
Raef Coles0e82adc2019-10-17 15:06:26 +010037#include "crypto_hw.h"
Tamas Banf824e742019-10-25 21:22:26 +010038#endif
Tamas Banf70ef8c2017-12-19 15:35:09 +000039
Tamas Ban581034a2017-12-19 19:54:37 +000040/* Avoids the semihosting issue */
41#if defined (__ARMCC_VERSION) && (__ARMCC_VERSION >= 6010050)
42__asm(" .global __ARM_use_no_argv\n");
43#endif
44
David Hu5cc9a3f2019-06-14 13:10:40 +080045#if defined(__ARM_ARCH_8M_MAIN__) || defined(__ARM_ARCH_8M_BASE__)
David Vinczee0a3c2f2019-05-15 16:45:14 +020046REGION_DECLARE(Image$$, ARM_LIB_STACK, $$ZI$$Base);
David Hu5cc9a3f2019-06-14 13:10:40 +080047#endif
David Vinczee0a3c2f2019-05-15 16:45:14 +020048
Tamas Banc3828852018-02-01 12:24:16 +000049/* Flash device name must be specified by target */
50extern ARM_DRIVER_FLASH FLASH_DEV_NAME;
Tamas Banf70ef8c2017-12-19 15:35:09 +000051
Tamas Banbd3f7512018-01-26 15:45:03 +000052#define BL2_MBEDTLS_MEM_BUF_LEN 0x2000
53/* Static buffer to be used by mbedtls for memory allocation */
54static uint8_t mbedtls_mem_buf[BL2_MBEDTLS_MEM_BUF_LEN];
Tamas Banf70ef8c2017-12-19 15:35:09 +000055
Tamas Banf70ef8c2017-12-19 15:35:09 +000056struct arm_vector_table {
57 uint32_t msp;
58 uint32_t reset;
59};
60
Tamas Band4bf3472019-09-06 12:59:56 +010061/*!
62 * \brief Chain-loading the next image in the boot sequence.
63 *
64 * This function calls the Reset_Handler of the next image in the boot sequence,
65 * usually it is the secure firmware. Before passing the execution to next image
66 * there is conditional rule to remove the secrets from the memory. This must be
67 * done if the following conditions are satisfied:
68 * - Memory is shared between SW components at different stages of the trusted
69 * boot process.
70 * - There are secrets in the memory: KDF parameter, symmetric key,
71 * manufacturer sensitive code/data, etc.
72 */
73__attribute__((naked)) void boot_jump_to_next_image(uint32_t reset_handler_addr)
74{
75 __ASM volatile(
76 ".syntax unified \n"
77 "mov r7, r0 \n"
78 "bl boot_clear_bl2_ram_area \n" /* Clear RAM before jump */
79 "movs r0, #0 \n" /* Clear registers: R0-R12, */
80 "mov r1, r0 \n" /* except R7 */
81 "mov r2, r0 \n"
82 "mov r3, r0 \n"
83 "mov r4, r0 \n"
84 "mov r5, r0 \n"
85 "mov r6, r0 \n"
86 "mov r8, r0 \n"
87 "mov r9, r0 \n"
88 "mov r10, r0 \n"
89 "mov r11, r0 \n"
90 "mov r12, r0 \n"
91 "mov lr, r0 \n"
92 "bx r7 \n" /* Jump to Reset_handler */
93 );
94}
95
Tamas Banf70ef8c2017-12-19 15:35:09 +000096static void do_boot(struct boot_rsp *rsp)
97{
Tamas Ban581034a2017-12-19 19:54:37 +000098 /* Clang at O0, stores variables on the stack with SP relative addressing.
99 * When manually set the SP then the place of reset vector is lost.
100 * Static variables are stored in 'data' or 'bss' section, change of SP has
101 * no effect on them.
102 */
103 static struct arm_vector_table *vt;
Tamas Banf70ef8c2017-12-19 15:35:09 +0000104 uintptr_t flash_base;
105 int rc;
106
107 /* The beginning of the image is the ARM vector table, containing
108 * the initial stack pointer address and the reset vector
109 * consecutively. Manually set the stack pointer and jump into the
110 * reset vector
111 */
112 rc = flash_device_base(rsp->br_flash_dev_id, &flash_base);
113 assert(rc == 0);
114
Oliver Swedef9982442018-08-24 18:37:44 +0100115 if (rsp->br_hdr->ih_flags & IMAGE_F_RAM_LOAD) {
116 /* The image has been copied to SRAM, find the vector table
117 * at the load address instead of image's address in flash
118 */
119 vt = (struct arm_vector_table *)(rsp->br_hdr->ih_load_addr +
120 rsp->br_hdr->ih_hdr_size);
121 } else {
122 /* Using the flash address as not executing in SRAM */
123 vt = (struct arm_vector_table *)(flash_base +
124 rsp->br_image_off +
125 rsp->br_hdr->ih_hdr_size);
126 }
127
David Vinczeb57989f2018-09-24 10:59:04 +0200128 rc = FLASH_DEV_NAME.Uninitialize();
129 if(rc != ARM_DRIVER_OK) {
130 BOOT_LOG_ERR("Error while uninitializing Flash Interface");
131 }
132
David Vincze99f1b362019-12-12 16:17:35 +0100133#if MCUBOOT_LOG_LEVEL > MCUBOOT_LOG_LEVEL_OFF
David Vincze8da7f102018-09-24 10:53:46 +0200134 stdio_uninit();
David Vincze73dfbc52019-10-11 13:54:58 +0200135#endif
David Vincze8da7f102018-09-24 10:53:46 +0200136
David Hu5cc9a3f2019-06-14 13:10:40 +0800137#if defined(__ARM_ARCH_8M_MAIN__) || defined(__ARM_ARCH_8M_BASE__)
David Vinczee0a3c2f2019-05-15 16:45:14 +0200138 /* Restore the Main Stack Pointer Limit register's reset value
139 * before passing execution to runtime firmware to make the
140 * bootloader transparent to it.
141 */
142 __set_MSPLIM(0);
David Hu5cc9a3f2019-06-14 13:10:40 +0800143#endif
David Vinczee0a3c2f2019-05-15 16:45:14 +0200144
Tamas Ban581034a2017-12-19 19:54:37 +0000145 __set_MSP(vt->msp);
146 __DSB();
147 __ISB();
148
Tamas Band4bf3472019-09-06 12:59:56 +0100149 boot_jump_to_next_image(vt->reset);
Tamas Banf70ef8c2017-12-19 15:35:09 +0000150}
Tamas Banf70ef8c2017-12-19 15:35:09 +0000151
Tamas Ban581034a2017-12-19 19:54:37 +0000152int main(void)
Tamas Banf70ef8c2017-12-19 15:35:09 +0000153{
David Hu5cc9a3f2019-06-14 13:10:40 +0800154#if defined(__ARM_ARCH_8M_MAIN__) || defined(__ARM_ARCH_8M_BASE__)
David Vinczee0a3c2f2019-05-15 16:45:14 +0200155 uint32_t msp_stack_bottom =
156 (uint32_t)&REGION_NAME(Image$$, ARM_LIB_STACK, $$ZI$$Base);
David Hu5cc9a3f2019-06-14 13:10:40 +0800157#endif
Tamas Banf70ef8c2017-12-19 15:35:09 +0000158 struct boot_rsp rsp;
159 int rc;
160
David Hu5cc9a3f2019-06-14 13:10:40 +0800161#if defined(__ARM_ARCH_8M_MAIN__) || defined(__ARM_ARCH_8M_BASE__)
David Vinczee0a3c2f2019-05-15 16:45:14 +0200162 __set_MSPLIM(msp_stack_bottom);
David Hu5cc9a3f2019-06-14 13:10:40 +0800163#endif
David Vinczee0a3c2f2019-05-15 16:45:14 +0200164
Andrei Narkevitchb0be4612020-01-27 17:26:19 -0800165 /* Perform platform specific initialization */
166 if (boot_platform_init() != 0) {
167 while (1)
168 ;
169 }
170
David Vincze99f1b362019-12-12 16:17:35 +0100171#if MCUBOOT_LOG_LEVEL > MCUBOOT_LOG_LEVEL_OFF
Gabor Kerteszeb953f52018-07-17 13:36:28 +0200172 stdio_init();
David Vincze73dfbc52019-10-11 13:54:58 +0200173#endif
Tamas Ban581034a2017-12-19 19:54:37 +0000174
Tamas Banf70ef8c2017-12-19 15:35:09 +0000175 BOOT_LOG_INF("Starting bootloader");
176
Tamas Banbd3f7512018-01-26 15:45:03 +0000177 /* Initialise the mbedtls static memory allocator so that mbedtls allocates
178 * memory from the provided static buffer instead of from the heap.
179 */
180 mbedtls_memory_buffer_alloc_init(mbedtls_mem_buf, BL2_MBEDTLS_MEM_BUF_LEN);
Tamas Banf70ef8c2017-12-19 15:35:09 +0000181
Raef Coles0e82adc2019-10-17 15:06:26 +0100182#ifdef CRYPTO_HW_ACCELERATOR
183 rc = crypto_hw_accelerator_init();
184 if (rc) {
185 BOOT_LOG_ERR("Error while initializing cryptographic accelerator.");
186 while (1);
187 }
188#endif /* CRYPTO_HW_ACCELERATOR */
189
David Vinczec3e313a2020-01-06 17:31:11 +0100190#ifndef MCUBOOT_USE_UPSTREAM
David Vincze060968d2019-05-23 01:13:14 +0200191 rc = boot_nv_security_counter_init();
192 if (rc != 0) {
193 BOOT_LOG_ERR("Error while initializing the security counter");
194 while (1)
195 ;
196 }
David Vinczec3e313a2020-01-06 17:31:11 +0100197#endif /* !MCUBOOT_USE_UPSTREAM */
David Vincze060968d2019-05-23 01:13:14 +0200198
Tamas Banf70ef8c2017-12-19 15:35:09 +0000199 rc = boot_go(&rsp);
200 if (rc != 0) {
201 BOOT_LOG_ERR("Unable to find bootable image");
202 while (1)
203 ;
204 }
205
Raef Coles0e82adc2019-10-17 15:06:26 +0100206#ifdef CRYPTO_HW_ACCELERATOR
207 rc = crypto_hw_accelerator_finish();
208 if (rc) {
209 BOOT_LOG_ERR("Error while uninitializing cryptographic accelerator.");
210 while (1);
211 }
212#endif /* CRYPTO_HW_ACCELERATOR */
213
Tamas Banf824e742019-10-25 21:22:26 +0100214/* This is a workaround to program the TF-M related cryptographic keys
215 * to CC312 OTP memory. This functionality is independent from secure boot,
216 * this is usually done in the factory floor during chip manufacturing.
217 */
218#ifdef CRYPTO_HW_ACCELERATOR_OTP_PROVISIONING
219 BOOT_LOG_INF("OTP provisioning started.");
220 rc = crypto_hw_accelerator_otp_provisioning();
221 if (rc) {
222 BOOT_LOG_ERR("OTP provisioning FAILED: 0x%X", rc);
223 while (1);
224 } else {
225 BOOT_LOG_INF("OTP provisioning succeeded. TF-M won't be loaded.");
226
227 /* We don't need to boot - the only aim is provisioning. */
228 while (1);
229 }
230#endif /* CRYPTO_HW_ACCELERATOR_OTP_PROVISIONING */
231
Tamas Banf70ef8c2017-12-19 15:35:09 +0000232 BOOT_LOG_INF("Bootloader chainload address offset: 0x%x",
233 rsp.br_image_off);
Tamas Banf70ef8c2017-12-19 15:35:09 +0000234 BOOT_LOG_INF("Jumping to the first image slot");
235 do_boot(&rsp);
236
237 BOOT_LOG_ERR("Never should get here");
238 while (1)
239 ;
240}