xref: /arm-trusted-firmware/drivers/renesas/common/io/io_rcar.c (revision 91f16700b400a8c0651d24a598fc48ee2997a0d7)
1*91f16700Schasinglulu /*
2*91f16700Schasinglulu  * Copyright (c) 2015-2021, Renesas Electronics Corporation. All rights reserved.
3*91f16700Schasinglulu  *
4*91f16700Schasinglulu  * SPDX-License-Identifier: BSD-3-Clause
5*91f16700Schasinglulu  */
6*91f16700Schasinglulu 
7*91f16700Schasinglulu #include <errno.h>
8*91f16700Schasinglulu #include <stdint.h>
9*91f16700Schasinglulu #include <string.h>
10*91f16700Schasinglulu 
11*91f16700Schasinglulu #include <arch_helpers.h>
12*91f16700Schasinglulu #include <common/bl_common.h>
13*91f16700Schasinglulu #include <common/debug.h>
14*91f16700Schasinglulu #include <drivers/auth/auth_mod.h>
15*91f16700Schasinglulu #include <drivers/io/io_driver.h>
16*91f16700Schasinglulu #include <drivers/io/io_storage.h>
17*91f16700Schasinglulu #include <lib/mmio.h>
18*91f16700Schasinglulu #include <plat/common/platform.h>
19*91f16700Schasinglulu #include <tools_share/firmware_image_package.h>
20*91f16700Schasinglulu #include <tools_share/uuid.h>
21*91f16700Schasinglulu 
22*91f16700Schasinglulu #include "io_rcar.h"
23*91f16700Schasinglulu #include "io_common.h"
24*91f16700Schasinglulu #include "io_private.h"
25*91f16700Schasinglulu #include <platform_def.h>
26*91f16700Schasinglulu 
27*91f16700Schasinglulu extern int32_t plat_get_drv_source(uint32_t id, uintptr_t *dev,
28*91f16700Schasinglulu 				   uintptr_t *image_spec);
29*91f16700Schasinglulu 
30*91f16700Schasinglulu static int32_t rcar_dev_open(const uintptr_t dev_spec __attribute__ ((unused)),
31*91f16700Schasinglulu 			     io_dev_info_t **dev_info);
32*91f16700Schasinglulu static int32_t rcar_dev_close(io_dev_info_t *dev_info);
33*91f16700Schasinglulu 
34*91f16700Schasinglulu typedef struct {
35*91f16700Schasinglulu 	const int32_t name;
36*91f16700Schasinglulu 	const uint32_t offset;
37*91f16700Schasinglulu 	const uint32_t attr;
38*91f16700Schasinglulu } plat_rcar_name_offset_t;
39*91f16700Schasinglulu 
40*91f16700Schasinglulu typedef struct {
41*91f16700Schasinglulu 	/*
42*91f16700Schasinglulu 	 * Put position above the struct to allow {0} on static init.
43*91f16700Schasinglulu 	 * It is a workaround for a known bug in GCC
44*91f16700Schasinglulu 	 * http://gcc.gnu.org/bugzilla/show_bug.cgi?id=53119
45*91f16700Schasinglulu 	 */
46*91f16700Schasinglulu 	uint32_t position;
47*91f16700Schasinglulu 	uint32_t no_load;
48*91f16700Schasinglulu 	uintptr_t offset;
49*91f16700Schasinglulu 	uint32_t size;
50*91f16700Schasinglulu 	uintptr_t dst;
51*91f16700Schasinglulu 	uintptr_t partition;	/* for eMMC */
52*91f16700Schasinglulu 	/* RCAR_EMMC_PARTITION_BOOT_0 */
53*91f16700Schasinglulu 	/* RCAR_EMMC_PARTITION_BOOT_1 */
54*91f16700Schasinglulu 	/* RCAR_EMMC_PARTITION_USER   */
55*91f16700Schasinglulu } file_state_t;
56*91f16700Schasinglulu 
57*91f16700Schasinglulu #define RCAR_GET_FLASH_ADR(a, b)	((uint32_t)((0x40000U * (a)) + (b)))
58*91f16700Schasinglulu #define RCAR_ATTR_SET_CALCADDR(a)	((a) & 0xF)
59*91f16700Schasinglulu #define RCAR_ATTR_SET_ISNOLOAD(a)	(((a) & 0x1) << 16U)
60*91f16700Schasinglulu #define RCAR_ATTR_SET_CERTOFF(a)	(((a) & 0xF) << 8U)
61*91f16700Schasinglulu #define RCAR_ATTR_SET_ALL(a, b, c)	((uint32_t)(RCAR_ATTR_SET_CALCADDR(a) |\
62*91f16700Schasinglulu 					RCAR_ATTR_SET_ISNOLOAD(b) |\
63*91f16700Schasinglulu 					RCAR_ATTR_SET_CERTOFF(c)))
64*91f16700Schasinglulu 
65*91f16700Schasinglulu #define RCAR_ATTR_GET_CALCADDR(a)	((a) & 0xFU)
66*91f16700Schasinglulu #define RCAR_ATTR_GET_ISNOLOAD(a)	(((a) >> 16) & 0x1U)
67*91f16700Schasinglulu #define RCAR_ATTR_GET_CERTOFF(a)	((uint32_t)(((a) >> 8) & 0xFU))
68*91f16700Schasinglulu 
69*91f16700Schasinglulu #define RCAR_MAX_BL3X_IMAGE		(8U)
70*91f16700Schasinglulu #define RCAR_SECTOR6_CERT_OFFSET	(0x400U)
71*91f16700Schasinglulu #define RCAR_SDRAM_certESS		(0x43F00000U)
72*91f16700Schasinglulu #define RCAR_CERT_SIZE			(0x800U)
73*91f16700Schasinglulu #define RCAR_CERT_INFO_SIZE_OFFSET	(0x264U)
74*91f16700Schasinglulu #define RCAR_CERT_INFO_DST_OFFSET	(0x154U)
75*91f16700Schasinglulu #define RCAR_CERT_INFO_SIZE_OFFSET1	(0x364U)
76*91f16700Schasinglulu #define RCAR_CERT_INFO_DST_OFFSET1	(0x1D4U)
77*91f16700Schasinglulu #define RCAR_CERT_INFO_SIZE_OFFSET2	(0x464U)
78*91f16700Schasinglulu #define RCAR_CERT_INFO_DST_OFFSET2	(0x254U)
79*91f16700Schasinglulu #define RCAR_CERT_LOAD			(1U)
80*91f16700Schasinglulu 
81*91f16700Schasinglulu #define RCAR_FLASH_CERT_HEADER		RCAR_GET_FLASH_ADR(6U, 0U)
82*91f16700Schasinglulu #define RCAR_EMMC_CERT_HEADER		(0x00030000U)
83*91f16700Schasinglulu 
84*91f16700Schasinglulu #define RCAR_COUNT_LOAD_BL33		(2U)
85*91f16700Schasinglulu #define RCAR_COUNT_LOAD_BL33X		(3U)
86*91f16700Schasinglulu 
87*91f16700Schasinglulu static const plat_rcar_name_offset_t name_offset[] = {
88*91f16700Schasinglulu 	{BL31_IMAGE_ID, 0U, RCAR_ATTR_SET_ALL(0, 0, 0)},
89*91f16700Schasinglulu 
90*91f16700Schasinglulu 	/* BL3-2 is optional in the platform */
91*91f16700Schasinglulu 	{BL32_IMAGE_ID, 0U, RCAR_ATTR_SET_ALL(1, 0, 1)},
92*91f16700Schasinglulu 	{BL33_IMAGE_ID, 0U, RCAR_ATTR_SET_ALL(2, 0, 2)},
93*91f16700Schasinglulu 	{BL332_IMAGE_ID, 0U, RCAR_ATTR_SET_ALL(3, 0, 3)},
94*91f16700Schasinglulu 	{BL333_IMAGE_ID, 0U, RCAR_ATTR_SET_ALL(4, 0, 4)},
95*91f16700Schasinglulu 	{BL334_IMAGE_ID, 0U, RCAR_ATTR_SET_ALL(5, 0, 5)},
96*91f16700Schasinglulu 	{BL335_IMAGE_ID, 0U, RCAR_ATTR_SET_ALL(6, 0, 6)},
97*91f16700Schasinglulu 	{BL336_IMAGE_ID, 0U, RCAR_ATTR_SET_ALL(7, 0, 7)},
98*91f16700Schasinglulu 	{BL337_IMAGE_ID, 0U, RCAR_ATTR_SET_ALL(8, 0, 8)},
99*91f16700Schasinglulu 	{BL338_IMAGE_ID, 0U, RCAR_ATTR_SET_ALL(9, 0, 9)},
100*91f16700Schasinglulu };
101*91f16700Schasinglulu 
102*91f16700Schasinglulu #if TRUSTED_BOARD_BOOT
103*91f16700Schasinglulu static const plat_rcar_name_offset_t cert_offset[] = {
104*91f16700Schasinglulu 	/* Certificates */
105*91f16700Schasinglulu 	{TRUSTED_KEY_CERT_ID, 0U, RCAR_ATTR_SET_ALL(0, 1, 0)},
106*91f16700Schasinglulu 	{SOC_FW_KEY_CERT_ID, 0U, RCAR_ATTR_SET_ALL(0, 1, 0)},
107*91f16700Schasinglulu 	{TRUSTED_OS_FW_KEY_CERT_ID, 0U, RCAR_ATTR_SET_ALL(0, 1, 0)},
108*91f16700Schasinglulu 	{NON_TRUSTED_FW_KEY_CERT_ID, 0U, RCAR_ATTR_SET_ALL(0, 1, 0)},
109*91f16700Schasinglulu 	{SOC_FW_CONTENT_CERT_ID, 0U, RCAR_ATTR_SET_ALL(0, 1, 0)},
110*91f16700Schasinglulu 	{TRUSTED_OS_FW_CONTENT_CERT_ID, 0U, RCAR_ATTR_SET_ALL(0, 1, 1)},
111*91f16700Schasinglulu 	{NON_TRUSTED_FW_CONTENT_CERT_ID, 0U, RCAR_ATTR_SET_ALL(0, 1, 2)},
112*91f16700Schasinglulu 	{BL332_CERT_ID, 0U, RCAR_ATTR_SET_ALL(0, 1, 3)},
113*91f16700Schasinglulu 	{BL333_CERT_ID, 0U, RCAR_ATTR_SET_ALL(0, 1, 4)},
114*91f16700Schasinglulu 	{BL334_CERT_ID, 0U, RCAR_ATTR_SET_ALL(0, 1, 5)},
115*91f16700Schasinglulu 	{BL335_CERT_ID, 0U, RCAR_ATTR_SET_ALL(0, 1, 6)},
116*91f16700Schasinglulu 	{BL336_CERT_ID, 0U, RCAR_ATTR_SET_ALL(0, 1, 7)},
117*91f16700Schasinglulu 	{BL337_CERT_ID, 0U, RCAR_ATTR_SET_ALL(0, 1, 8)},
118*91f16700Schasinglulu 	{BL338_CERT_ID, 0U, RCAR_ATTR_SET_ALL(0, 1, 9)},
119*91f16700Schasinglulu };
120*91f16700Schasinglulu #endif /* TRUSTED_BOARD_BOOT */
121*91f16700Schasinglulu 
122*91f16700Schasinglulu static file_state_t current_file = { 0 };
123*91f16700Schasinglulu 
124*91f16700Schasinglulu static uintptr_t rcar_handle, rcar_spec;
125*91f16700Schasinglulu static uint64_t rcar_image_header[RCAR_MAX_BL3X_IMAGE + 2U] = { 0U };
126*91f16700Schasinglulu static uint64_t rcar_image_header_prttn[RCAR_MAX_BL3X_IMAGE + 2U] = { 0U };
127*91f16700Schasinglulu static uint64_t rcar_image_number = { 0U };
128*91f16700Schasinglulu static uint32_t rcar_cert_load = { 0U };
129*91f16700Schasinglulu 
130*91f16700Schasinglulu static io_type_t device_type_rcar(void)
131*91f16700Schasinglulu {
132*91f16700Schasinglulu 	return IO_TYPE_FIRMWARE_IMAGE_PACKAGE;
133*91f16700Schasinglulu }
134*91f16700Schasinglulu 
135*91f16700Schasinglulu int32_t rcar_get_certificate(const int32_t name, uint32_t *cert)
136*91f16700Schasinglulu {
137*91f16700Schasinglulu #if TRUSTED_BOARD_BOOT
138*91f16700Schasinglulu 	int32_t i;
139*91f16700Schasinglulu 
140*91f16700Schasinglulu 	for (i = 0; i < ARRAY_SIZE(cert_offset); i++) {
141*91f16700Schasinglulu 		if (name != cert_offset[i].name) {
142*91f16700Schasinglulu 			continue;
143*91f16700Schasinglulu 		}
144*91f16700Schasinglulu 
145*91f16700Schasinglulu 		*cert = RCAR_CERT_SIZE;
146*91f16700Schasinglulu 		*cert *= RCAR_ATTR_GET_CERTOFF(cert_offset[i].attr);
147*91f16700Schasinglulu 		*cert += RCAR_SDRAM_certESS;
148*91f16700Schasinglulu 		return 0;
149*91f16700Schasinglulu 	}
150*91f16700Schasinglulu #endif
151*91f16700Schasinglulu 	return -EINVAL;
152*91f16700Schasinglulu }
153*91f16700Schasinglulu 
154*91f16700Schasinglulu #define MFISBTSTSR			(0xE6260604U)
155*91f16700Schasinglulu #define MFISBTSTSR_BOOT_PARTITION	(0x00000010U)
156*91f16700Schasinglulu 
157*91f16700Schasinglulu static int32_t file_to_offset(const int32_t name, uintptr_t *offset,
158*91f16700Schasinglulu 			      uint32_t *cert, uint32_t *no_load,
159*91f16700Schasinglulu 			      uintptr_t *partition)
160*91f16700Schasinglulu {
161*91f16700Schasinglulu 	uint32_t addr;
162*91f16700Schasinglulu 	int32_t i;
163*91f16700Schasinglulu 
164*91f16700Schasinglulu 	for (i = 0; i < ARRAY_SIZE(name_offset); i++) {
165*91f16700Schasinglulu 		if (name != name_offset[i].name) {
166*91f16700Schasinglulu 			continue;
167*91f16700Schasinglulu 		}
168*91f16700Schasinglulu 
169*91f16700Schasinglulu 		addr = RCAR_ATTR_GET_CALCADDR(name_offset[i].attr);
170*91f16700Schasinglulu 		if (rcar_image_number + 2U < addr) {
171*91f16700Schasinglulu 			continue;
172*91f16700Schasinglulu 		}
173*91f16700Schasinglulu 
174*91f16700Schasinglulu 		*offset = rcar_image_header[addr];
175*91f16700Schasinglulu 
176*91f16700Schasinglulu 		if (mmio_read_32(MFISBTSTSR) & MFISBTSTSR_BOOT_PARTITION)
177*91f16700Schasinglulu 			*offset += 0x800000;
178*91f16700Schasinglulu 		*cert = RCAR_CERT_SIZE;
179*91f16700Schasinglulu 		*cert *= RCAR_ATTR_GET_CERTOFF(name_offset[i].attr);
180*91f16700Schasinglulu 		*cert += RCAR_SDRAM_certESS;
181*91f16700Schasinglulu 		*no_load = RCAR_ATTR_GET_ISNOLOAD(name_offset[i].attr);
182*91f16700Schasinglulu 		*partition = rcar_image_header_prttn[addr];
183*91f16700Schasinglulu 		return IO_SUCCESS;
184*91f16700Schasinglulu 	}
185*91f16700Schasinglulu 
186*91f16700Schasinglulu #if TRUSTED_BOARD_BOOT
187*91f16700Schasinglulu 	for (i = 0; i < ARRAY_SIZE(cert_offset); i++) {
188*91f16700Schasinglulu 		if (name != cert_offset[i].name) {
189*91f16700Schasinglulu 			continue;
190*91f16700Schasinglulu 		}
191*91f16700Schasinglulu 
192*91f16700Schasinglulu 		*no_load = RCAR_ATTR_GET_ISNOLOAD(cert_offset[i].attr);
193*91f16700Schasinglulu 		*partition = 0U;
194*91f16700Schasinglulu 		*offset = 0U;
195*91f16700Schasinglulu 		*cert = 0U;
196*91f16700Schasinglulu 		return IO_SUCCESS;
197*91f16700Schasinglulu 	}
198*91f16700Schasinglulu #endif
199*91f16700Schasinglulu 	return -EINVAL;
200*91f16700Schasinglulu }
201*91f16700Schasinglulu 
202*91f16700Schasinglulu #define RCAR_BOOT_KEY_CERT_NEW	(0xE6300F00U)
203*91f16700Schasinglulu #define	RCAR_CERT_MAGIC_NUM	(0xE291F358U)
204*91f16700Schasinglulu 
205*91f16700Schasinglulu void rcar_read_certificate(uint64_t cert, uint32_t *len, uintptr_t *dst)
206*91f16700Schasinglulu {
207*91f16700Schasinglulu 	uint32_t seed, val, info_1, info_2;
208*91f16700Schasinglulu 	uintptr_t size, dsth, dstl;
209*91f16700Schasinglulu 
210*91f16700Schasinglulu 	cert &= 0xFFFFFFFFU;
211*91f16700Schasinglulu 
212*91f16700Schasinglulu 	seed = mmio_read_32(RCAR_BOOT_KEY_CERT_NEW);
213*91f16700Schasinglulu 	val = mmio_read_32(RCAR_BOOT_KEY_CERT_NEW + 0xC);
214*91f16700Schasinglulu 	info_1 = (val >> 18) & 0x3U;
215*91f16700Schasinglulu 	val = mmio_read_32(cert + 0xC);
216*91f16700Schasinglulu 	info_2 = (val >> 21) & 0x3;
217*91f16700Schasinglulu 
218*91f16700Schasinglulu 	if (seed == RCAR_CERT_MAGIC_NUM) {
219*91f16700Schasinglulu 		if (info_1 != 1) {
220*91f16700Schasinglulu 			ERROR("BL2: Cert is invalid.\n");
221*91f16700Schasinglulu 			*dst = 0;
222*91f16700Schasinglulu 			*len = 0;
223*91f16700Schasinglulu 			return;
224*91f16700Schasinglulu 		}
225*91f16700Schasinglulu 
226*91f16700Schasinglulu 		if (info_2 > 2) {
227*91f16700Schasinglulu 			ERROR("BL2: Cert is invalid.\n");
228*91f16700Schasinglulu 			*dst = 0;
229*91f16700Schasinglulu 			*len = 0;
230*91f16700Schasinglulu 			return;
231*91f16700Schasinglulu 		}
232*91f16700Schasinglulu 
233*91f16700Schasinglulu 		switch (info_2) {
234*91f16700Schasinglulu 		case 2:
235*91f16700Schasinglulu 			size = cert + RCAR_CERT_INFO_SIZE_OFFSET2;
236*91f16700Schasinglulu 			dstl = cert + RCAR_CERT_INFO_DST_OFFSET2;
237*91f16700Schasinglulu 			break;
238*91f16700Schasinglulu 		case 1:
239*91f16700Schasinglulu 			size = cert + RCAR_CERT_INFO_SIZE_OFFSET1;
240*91f16700Schasinglulu 			dstl = cert + RCAR_CERT_INFO_DST_OFFSET1;
241*91f16700Schasinglulu 			break;
242*91f16700Schasinglulu 		case 0:
243*91f16700Schasinglulu 			size = cert + RCAR_CERT_INFO_SIZE_OFFSET;
244*91f16700Schasinglulu 			dstl = cert + RCAR_CERT_INFO_DST_OFFSET;
245*91f16700Schasinglulu 			break;
246*91f16700Schasinglulu 		}
247*91f16700Schasinglulu 
248*91f16700Schasinglulu 		*len = mmio_read_32(size) * 4U;
249*91f16700Schasinglulu 		dsth = dstl + 4U;
250*91f16700Schasinglulu 		*dst = ((uintptr_t) mmio_read_32(dsth) << 32) +
251*91f16700Schasinglulu 		    ((uintptr_t) mmio_read_32(dstl));
252*91f16700Schasinglulu 		return;
253*91f16700Schasinglulu 	}
254*91f16700Schasinglulu 
255*91f16700Schasinglulu 	size = cert + RCAR_CERT_INFO_SIZE_OFFSET;
256*91f16700Schasinglulu 	*len = mmio_read_32(size) * 4U;
257*91f16700Schasinglulu 	dstl = cert + RCAR_CERT_INFO_DST_OFFSET;
258*91f16700Schasinglulu 	dsth = dstl + 4U;
259*91f16700Schasinglulu 	*dst = ((uintptr_t) mmio_read_32(dsth) << 32) +
260*91f16700Schasinglulu 	    ((uintptr_t) mmio_read_32(dstl));
261*91f16700Schasinglulu }
262*91f16700Schasinglulu 
263*91f16700Schasinglulu static int32_t check_load_area(uintptr_t dst, uintptr_t len)
264*91f16700Schasinglulu {
265*91f16700Schasinglulu 	uint32_t legacy = dst + len <= UINT32_MAX - 1 ? 1 : 0;
266*91f16700Schasinglulu 	uintptr_t dram_start, dram_end;
267*91f16700Schasinglulu 	uintptr_t prot_start, prot_end;
268*91f16700Schasinglulu 	int32_t result = IO_SUCCESS;
269*91f16700Schasinglulu 
270*91f16700Schasinglulu 	dram_start = legacy ? DRAM1_BASE : DRAM_40BIT_BASE;
271*91f16700Schasinglulu 
272*91f16700Schasinglulu 	dram_end = legacy ? DRAM1_BASE + DRAM1_SIZE :
273*91f16700Schasinglulu 	    DRAM_40BIT_BASE + DRAM_40BIT_SIZE;
274*91f16700Schasinglulu 
275*91f16700Schasinglulu 	prot_start = legacy ? DRAM_PROTECTED_BASE : DRAM_40BIT_PROTECTED_BASE;
276*91f16700Schasinglulu 
277*91f16700Schasinglulu 	prot_end = prot_start + DRAM_PROTECTED_SIZE;
278*91f16700Schasinglulu 
279*91f16700Schasinglulu 	if (dst < dram_start || dst > dram_end - len) {
280*91f16700Schasinglulu 		ERROR("BL2: dst address is on the protected area.\n");
281*91f16700Schasinglulu 		result = IO_FAIL;
282*91f16700Schasinglulu 		goto done;
283*91f16700Schasinglulu 	}
284*91f16700Schasinglulu 
285*91f16700Schasinglulu 	/* load image is within SDRAM protected area */
286*91f16700Schasinglulu 	if (dst >= prot_start && dst < prot_end) {
287*91f16700Schasinglulu 		ERROR("BL2: dst address is on the protected area.\n");
288*91f16700Schasinglulu 		result = IO_FAIL;
289*91f16700Schasinglulu 	}
290*91f16700Schasinglulu 
291*91f16700Schasinglulu 	if (dst < prot_start && dst > prot_start - len) {
292*91f16700Schasinglulu 		ERROR("BL2: loaded data is on the protected area.\n");
293*91f16700Schasinglulu 		result = IO_FAIL;
294*91f16700Schasinglulu 	}
295*91f16700Schasinglulu done:
296*91f16700Schasinglulu 	if (result == IO_FAIL) {
297*91f16700Schasinglulu 		ERROR("BL2: Out of range : dst=0x%lx len=0x%lx\n", dst, len);
298*91f16700Schasinglulu 	}
299*91f16700Schasinglulu 
300*91f16700Schasinglulu 	return result;
301*91f16700Schasinglulu }
302*91f16700Schasinglulu 
303*91f16700Schasinglulu static int32_t load_bl33x(void)
304*91f16700Schasinglulu {
305*91f16700Schasinglulu 	static int32_t loaded = IO_NOT_SUPPORTED;
306*91f16700Schasinglulu 	uintptr_t dst, partition, handle;
307*91f16700Schasinglulu 	uint32_t noload, cert, len, i;
308*91f16700Schasinglulu 	uintptr_t offset;
309*91f16700Schasinglulu 	int32_t rc;
310*91f16700Schasinglulu 	size_t cnt;
311*91f16700Schasinglulu 	const int32_t img[] = {
312*91f16700Schasinglulu 		BL33_IMAGE_ID,
313*91f16700Schasinglulu 		BL332_IMAGE_ID,
314*91f16700Schasinglulu 		BL333_IMAGE_ID,
315*91f16700Schasinglulu 		BL334_IMAGE_ID,
316*91f16700Schasinglulu 		BL335_IMAGE_ID,
317*91f16700Schasinglulu 		BL336_IMAGE_ID,
318*91f16700Schasinglulu 		BL337_IMAGE_ID,
319*91f16700Schasinglulu 		BL338_IMAGE_ID
320*91f16700Schasinglulu 	};
321*91f16700Schasinglulu 
322*91f16700Schasinglulu 	if (loaded != IO_NOT_SUPPORTED) {
323*91f16700Schasinglulu 		return loaded;
324*91f16700Schasinglulu 	}
325*91f16700Schasinglulu 
326*91f16700Schasinglulu 	for (i = 1; i < rcar_image_number; i++) {
327*91f16700Schasinglulu 		rc = file_to_offset(img[i], &offset, &cert, &noload,
328*91f16700Schasinglulu 				    &partition);
329*91f16700Schasinglulu 		if (rc != IO_SUCCESS) {
330*91f16700Schasinglulu 			WARN("%s: failed to get offset\n", __func__);
331*91f16700Schasinglulu 			loaded = IO_FAIL;
332*91f16700Schasinglulu 			return loaded;
333*91f16700Schasinglulu 		}
334*91f16700Schasinglulu 
335*91f16700Schasinglulu 		rcar_read_certificate((uint64_t) cert, &len, &dst);
336*91f16700Schasinglulu 		((io_drv_spec_t *) rcar_spec)->partition = partition;
337*91f16700Schasinglulu 
338*91f16700Schasinglulu 		rc = io_open(rcar_handle, rcar_spec, &handle);
339*91f16700Schasinglulu 		if (rc != IO_SUCCESS) {
340*91f16700Schasinglulu 			WARN("%s: Failed to open FIP (%i)\n", __func__, rc);
341*91f16700Schasinglulu 			loaded = IO_FAIL;
342*91f16700Schasinglulu 			return loaded;
343*91f16700Schasinglulu 		}
344*91f16700Schasinglulu 
345*91f16700Schasinglulu 		rc = io_seek(handle, IO_SEEK_SET, offset);
346*91f16700Schasinglulu 		if (rc != IO_SUCCESS) {
347*91f16700Schasinglulu 			WARN("%s: failed to seek\n", __func__);
348*91f16700Schasinglulu 			loaded = IO_FAIL;
349*91f16700Schasinglulu 			return loaded;
350*91f16700Schasinglulu 		}
351*91f16700Schasinglulu 
352*91f16700Schasinglulu 		rc = check_load_area(dst, len);
353*91f16700Schasinglulu 		if (rc != IO_SUCCESS) {
354*91f16700Schasinglulu 			WARN("%s: check load area\n", __func__);
355*91f16700Schasinglulu 			loaded = IO_FAIL;
356*91f16700Schasinglulu 			return loaded;
357*91f16700Schasinglulu 		}
358*91f16700Schasinglulu 
359*91f16700Schasinglulu 		rc = io_read(handle, dst, len, &cnt);
360*91f16700Schasinglulu 		if (rc != IO_SUCCESS) {
361*91f16700Schasinglulu 			WARN("%s: failed to read\n", __func__);
362*91f16700Schasinglulu 			loaded = IO_FAIL;
363*91f16700Schasinglulu 			return loaded;
364*91f16700Schasinglulu 		}
365*91f16700Schasinglulu #if TRUSTED_BOARD_BOOT
366*91f16700Schasinglulu 		rc = auth_mod_verify_img(img[i], (void *)dst, len);
367*91f16700Schasinglulu 		if (rc != 0) {
368*91f16700Schasinglulu 			memset((void *)dst, 0x00, len);
369*91f16700Schasinglulu 			loaded = IO_FAIL;
370*91f16700Schasinglulu 			return loaded;
371*91f16700Schasinglulu 		}
372*91f16700Schasinglulu #endif
373*91f16700Schasinglulu 		io_close(handle);
374*91f16700Schasinglulu 	}
375*91f16700Schasinglulu 
376*91f16700Schasinglulu 	loaded = IO_SUCCESS;
377*91f16700Schasinglulu 
378*91f16700Schasinglulu 	return loaded;
379*91f16700Schasinglulu }
380*91f16700Schasinglulu 
381*91f16700Schasinglulu static int32_t rcar_dev_init(io_dev_info_t *dev_info, const uintptr_t name)
382*91f16700Schasinglulu {
383*91f16700Schasinglulu 	static uint64_t header[64] __aligned(FLASH_TRANS_SIZE_UNIT) = {0UL};
384*91f16700Schasinglulu 	uintptr_t handle;
385*91f16700Schasinglulu 	ssize_t offset;
386*91f16700Schasinglulu 	uint32_t i;
387*91f16700Schasinglulu 	int32_t rc;
388*91f16700Schasinglulu 	size_t cnt;
389*91f16700Schasinglulu 
390*91f16700Schasinglulu 	/* Obtain a reference to the image by querying the platform layer */
391*91f16700Schasinglulu 	rc = plat_get_drv_source(name, &rcar_handle, &rcar_spec);
392*91f16700Schasinglulu 	if (rc != IO_SUCCESS) {
393*91f16700Schasinglulu 		WARN("Failed to obtain reference to img %ld (%i)\n", name, rc);
394*91f16700Schasinglulu 		return IO_FAIL;
395*91f16700Schasinglulu 	}
396*91f16700Schasinglulu 
397*91f16700Schasinglulu 	if (rcar_cert_load == RCAR_CERT_LOAD) {
398*91f16700Schasinglulu 		return IO_SUCCESS;
399*91f16700Schasinglulu 	}
400*91f16700Schasinglulu 
401*91f16700Schasinglulu 	rc = io_open(rcar_handle, rcar_spec, &handle);
402*91f16700Schasinglulu 	if (rc != IO_SUCCESS) {
403*91f16700Schasinglulu 		WARN("Failed to access img %ld (%i)\n", name, rc);
404*91f16700Schasinglulu 		return IO_FAIL;
405*91f16700Schasinglulu 	}
406*91f16700Schasinglulu 
407*91f16700Schasinglulu 	/*
408*91f16700Schasinglulu 	 * get start address list
409*91f16700Schasinglulu 	 * [0] address num
410*91f16700Schasinglulu 	 * [1] BL33-1 image address
411*91f16700Schasinglulu 	 * [2] BL33-2 image address
412*91f16700Schasinglulu 	 * [3] BL33-3 image address
413*91f16700Schasinglulu 	 * [4] BL33-4 image address
414*91f16700Schasinglulu 	 * [5] BL33-5 image address
415*91f16700Schasinglulu 	 * [6] BL33-6 image address
416*91f16700Schasinglulu 	 * [7] BL33-7 image address
417*91f16700Schasinglulu 	 * [8] BL33-8 image address
418*91f16700Schasinglulu 	 */
419*91f16700Schasinglulu 	offset = name == EMMC_DEV_ID ? RCAR_EMMC_CERT_HEADER :
420*91f16700Schasinglulu 	    RCAR_FLASH_CERT_HEADER;
421*91f16700Schasinglulu 	rc = io_seek(handle, IO_SEEK_SET, offset);
422*91f16700Schasinglulu 	if (rc != IO_SUCCESS) {
423*91f16700Schasinglulu 		WARN("Firmware Image Package header failed to seek\n");
424*91f16700Schasinglulu 		goto error;
425*91f16700Schasinglulu 	}
426*91f16700Schasinglulu 
427*91f16700Schasinglulu 	rc = io_read(handle, (uintptr_t) &header, sizeof(header), &cnt);
428*91f16700Schasinglulu 	if (rc != IO_SUCCESS) {
429*91f16700Schasinglulu 		WARN("Firmware Image Package header failed to read\n");
430*91f16700Schasinglulu 		goto error;
431*91f16700Schasinglulu 	}
432*91f16700Schasinglulu 
433*91f16700Schasinglulu #if RCAR_BL2_DCACHE == 1
434*91f16700Schasinglulu 	inv_dcache_range((uint64_t) header, sizeof(header));
435*91f16700Schasinglulu #endif
436*91f16700Schasinglulu 
437*91f16700Schasinglulu 	rcar_image_number = header[0];
438*91f16700Schasinglulu 	for (i = 0; i < rcar_image_number + 2; i++) {
439*91f16700Schasinglulu 		rcar_image_header[i] = header[i * 2 + 1];
440*91f16700Schasinglulu 		rcar_image_header_prttn[i] = header[i * 2 + 2];
441*91f16700Schasinglulu 	}
442*91f16700Schasinglulu 
443*91f16700Schasinglulu 	if (rcar_image_number == 0 || rcar_image_number > RCAR_MAX_BL3X_IMAGE) {
444*91f16700Schasinglulu 		WARN("Firmware Image Package header check failed.\n");
445*91f16700Schasinglulu 		rc = IO_FAIL;
446*91f16700Schasinglulu 		goto error;
447*91f16700Schasinglulu 	}
448*91f16700Schasinglulu 
449*91f16700Schasinglulu 	rc = io_seek(handle, IO_SEEK_SET, offset + RCAR_SECTOR6_CERT_OFFSET);
450*91f16700Schasinglulu 	if (rc != IO_SUCCESS) {
451*91f16700Schasinglulu 		WARN("Firmware Image Package header failed to seek cert\n");
452*91f16700Schasinglulu 		goto error;
453*91f16700Schasinglulu 	}
454*91f16700Schasinglulu 
455*91f16700Schasinglulu 	rc = io_read(handle, RCAR_SDRAM_certESS,
456*91f16700Schasinglulu 		     RCAR_CERT_SIZE * (2 + rcar_image_number), &cnt);
457*91f16700Schasinglulu 	if (rc != IO_SUCCESS) {
458*91f16700Schasinglulu 		WARN("cert file read error.\n");
459*91f16700Schasinglulu 		goto error;
460*91f16700Schasinglulu 	}
461*91f16700Schasinglulu 
462*91f16700Schasinglulu #if RCAR_BL2_DCACHE == 1
463*91f16700Schasinglulu 	inv_dcache_range(RCAR_SDRAM_certESS,
464*91f16700Schasinglulu 			 RCAR_CERT_SIZE * (2 + rcar_image_number));
465*91f16700Schasinglulu #endif
466*91f16700Schasinglulu 
467*91f16700Schasinglulu 	rcar_cert_load = RCAR_CERT_LOAD;
468*91f16700Schasinglulu error:
469*91f16700Schasinglulu 
470*91f16700Schasinglulu 	if (rc != IO_SUCCESS) {
471*91f16700Schasinglulu 		rc = IO_FAIL;
472*91f16700Schasinglulu 	}
473*91f16700Schasinglulu 
474*91f16700Schasinglulu 	io_close(handle);
475*91f16700Schasinglulu 
476*91f16700Schasinglulu 	return rc;
477*91f16700Schasinglulu 
478*91f16700Schasinglulu }
479*91f16700Schasinglulu 
480*91f16700Schasinglulu static int32_t rcar_file_open(io_dev_info_t *info, const uintptr_t file_spec,
481*91f16700Schasinglulu 			      io_entity_t *entity)
482*91f16700Schasinglulu {
483*91f16700Schasinglulu 	const io_drv_spec_t *spec = (io_drv_spec_t *) file_spec;
484*91f16700Schasinglulu 	uintptr_t partition, offset, dst;
485*91f16700Schasinglulu 	uint32_t noload, cert, len;
486*91f16700Schasinglulu 	int32_t rc;
487*91f16700Schasinglulu 
488*91f16700Schasinglulu 	/*
489*91f16700Schasinglulu 	 * Only one file open at a time. We need to  track state (ie, file
490*91f16700Schasinglulu 	 * cursor position). Since the header lives at offset zero, this entry
491*91f16700Schasinglulu 	 * should never be zero in an active file.
492*91f16700Schasinglulu 	 * Once the system supports dynamic memory allocation we will allow more
493*91f16700Schasinglulu 	 * than one open file at a time.
494*91f16700Schasinglulu 	 */
495*91f16700Schasinglulu 	if (current_file.offset != 0U) {
496*91f16700Schasinglulu 		WARN("%s: Only one open file at a time.\n", __func__);
497*91f16700Schasinglulu 		return IO_RESOURCES_EXHAUSTED;
498*91f16700Schasinglulu 	}
499*91f16700Schasinglulu 
500*91f16700Schasinglulu 	rc = file_to_offset(spec->offset, &offset, &cert, &noload, &partition);
501*91f16700Schasinglulu 	if (rc != IO_SUCCESS) {
502*91f16700Schasinglulu 		WARN("Failed to open file name %ld (%i)\n", spec->offset, rc);
503*91f16700Schasinglulu 		return IO_FAIL;
504*91f16700Schasinglulu 	}
505*91f16700Schasinglulu 
506*91f16700Schasinglulu 	if (noload != 0U) {
507*91f16700Schasinglulu 		current_file.offset = 1;
508*91f16700Schasinglulu 		current_file.dst = 0;
509*91f16700Schasinglulu 		current_file.size = 1;
510*91f16700Schasinglulu 		current_file.position = 0;
511*91f16700Schasinglulu 		current_file.no_load = noload;
512*91f16700Schasinglulu 		current_file.partition = 0;
513*91f16700Schasinglulu 		entity->info = (uintptr_t) &current_file;
514*91f16700Schasinglulu 
515*91f16700Schasinglulu 		return IO_SUCCESS;
516*91f16700Schasinglulu 	}
517*91f16700Schasinglulu 
518*91f16700Schasinglulu 	rcar_read_certificate((uint64_t) cert, &len, &dst);
519*91f16700Schasinglulu 
520*91f16700Schasinglulu 	/* Baylibre: HACK */
521*91f16700Schasinglulu 	if (spec->offset == BL31_IMAGE_ID && len < RCAR_TRUSTED_SRAM_SIZE) {
522*91f16700Schasinglulu 		WARN("%s,%s\n", "r-car ignoring the BL31 size from certificate",
523*91f16700Schasinglulu 		     "using RCAR_TRUSTED_SRAM_SIZE instead");
524*91f16700Schasinglulu 		len = RCAR_TRUSTED_SRAM_SIZE;
525*91f16700Schasinglulu 	}
526*91f16700Schasinglulu 
527*91f16700Schasinglulu 	current_file.partition = partition;
528*91f16700Schasinglulu 	current_file.no_load = noload;
529*91f16700Schasinglulu 	current_file.offset = offset;
530*91f16700Schasinglulu 	current_file.position = 0;
531*91f16700Schasinglulu 	current_file.size = len;
532*91f16700Schasinglulu 	current_file.dst = dst;
533*91f16700Schasinglulu 	entity->info = (uintptr_t) &current_file;
534*91f16700Schasinglulu 
535*91f16700Schasinglulu 	return IO_SUCCESS;
536*91f16700Schasinglulu }
537*91f16700Schasinglulu 
538*91f16700Schasinglulu static int32_t rcar_file_len(io_entity_t *entity, size_t *length)
539*91f16700Schasinglulu {
540*91f16700Schasinglulu 	*length = ((file_state_t *) entity->info)->size;
541*91f16700Schasinglulu 
542*91f16700Schasinglulu 	NOTICE("%s: len: 0x%08lx\n", __func__, *length);
543*91f16700Schasinglulu 
544*91f16700Schasinglulu 	return IO_SUCCESS;
545*91f16700Schasinglulu }
546*91f16700Schasinglulu 
547*91f16700Schasinglulu static int32_t rcar_file_read(io_entity_t *entity, uintptr_t buffer,
548*91f16700Schasinglulu 			      size_t length, size_t *cnt)
549*91f16700Schasinglulu {
550*91f16700Schasinglulu 	file_state_t *fp = (file_state_t *) entity->info;
551*91f16700Schasinglulu 	ssize_t offset = fp->offset + fp->position;
552*91f16700Schasinglulu 	uintptr_t handle;
553*91f16700Schasinglulu 	int32_t rc;
554*91f16700Schasinglulu 
555*91f16700Schasinglulu #ifdef SPD_NONE
556*91f16700Schasinglulu 	static uint32_t load_bl33x_counter = 1;
557*91f16700Schasinglulu #else
558*91f16700Schasinglulu 	static uint32_t load_bl33x_counter;
559*91f16700Schasinglulu #endif
560*91f16700Schasinglulu 	if (current_file.no_load != 0U) {
561*91f16700Schasinglulu 		*cnt = length;
562*91f16700Schasinglulu 		return IO_SUCCESS;
563*91f16700Schasinglulu 	}
564*91f16700Schasinglulu 
565*91f16700Schasinglulu 	((io_drv_spec_t *) rcar_spec)->partition = fp->partition;
566*91f16700Schasinglulu 
567*91f16700Schasinglulu 	rc = io_open(rcar_handle, rcar_spec, &handle);
568*91f16700Schasinglulu 	if (rc != IO_SUCCESS) {
569*91f16700Schasinglulu 		WARN("Failed to open FIP (%i)\n", rc);
570*91f16700Schasinglulu 		return IO_FAIL;
571*91f16700Schasinglulu 	}
572*91f16700Schasinglulu 
573*91f16700Schasinglulu 	rc = io_seek(handle, IO_SEEK_SET, offset);
574*91f16700Schasinglulu 	if (rc != IO_SUCCESS) {
575*91f16700Schasinglulu 		WARN("%s: failed to seek\n", __func__);
576*91f16700Schasinglulu 		goto error;
577*91f16700Schasinglulu 	}
578*91f16700Schasinglulu 
579*91f16700Schasinglulu 	if (load_bl33x_counter == RCAR_COUNT_LOAD_BL33) {
580*91f16700Schasinglulu 		rc = check_load_area(buffer, length);
581*91f16700Schasinglulu 		if (rc != IO_SUCCESS) {
582*91f16700Schasinglulu 			WARN("%s: load area err\n", __func__);
583*91f16700Schasinglulu 			goto error;
584*91f16700Schasinglulu 		}
585*91f16700Schasinglulu 	}
586*91f16700Schasinglulu 
587*91f16700Schasinglulu 	rc = io_read(handle, buffer, length, cnt);
588*91f16700Schasinglulu 	if (rc != IO_SUCCESS) {
589*91f16700Schasinglulu 		WARN("Failed to read payload (%i)\n", rc);
590*91f16700Schasinglulu 		goto error;
591*91f16700Schasinglulu 	}
592*91f16700Schasinglulu 
593*91f16700Schasinglulu 	fp->position += *cnt;
594*91f16700Schasinglulu 	io_close(handle);
595*91f16700Schasinglulu 
596*91f16700Schasinglulu 	load_bl33x_counter += 1;
597*91f16700Schasinglulu 	if (load_bl33x_counter == RCAR_COUNT_LOAD_BL33X) {
598*91f16700Schasinglulu 		return load_bl33x();
599*91f16700Schasinglulu 	}
600*91f16700Schasinglulu 
601*91f16700Schasinglulu 	return IO_SUCCESS;
602*91f16700Schasinglulu error:
603*91f16700Schasinglulu 	io_close(handle);
604*91f16700Schasinglulu 	return IO_FAIL;
605*91f16700Schasinglulu }
606*91f16700Schasinglulu 
607*91f16700Schasinglulu static int32_t rcar_file_close(io_entity_t *entity)
608*91f16700Schasinglulu {
609*91f16700Schasinglulu 	if (current_file.offset != 0U) {
610*91f16700Schasinglulu 		memset(&current_file, 0, sizeof(current_file));
611*91f16700Schasinglulu 	}
612*91f16700Schasinglulu 
613*91f16700Schasinglulu 	entity->info = 0U;
614*91f16700Schasinglulu 
615*91f16700Schasinglulu 	return IO_SUCCESS;
616*91f16700Schasinglulu }
617*91f16700Schasinglulu 
618*91f16700Schasinglulu static const io_dev_funcs_t rcar_dev_funcs = {
619*91f16700Schasinglulu 	.type = &device_type_rcar,
620*91f16700Schasinglulu 	.open = &rcar_file_open,
621*91f16700Schasinglulu 	.seek = NULL,
622*91f16700Schasinglulu 	.size = &rcar_file_len,
623*91f16700Schasinglulu 	.read = &rcar_file_read,
624*91f16700Schasinglulu 	.write = NULL,
625*91f16700Schasinglulu 	.close = &rcar_file_close,
626*91f16700Schasinglulu 	.dev_init = &rcar_dev_init,
627*91f16700Schasinglulu 	.dev_close = &rcar_dev_close,
628*91f16700Schasinglulu };
629*91f16700Schasinglulu 
630*91f16700Schasinglulu static const io_dev_info_t rcar_dev_info = {
631*91f16700Schasinglulu 	.funcs = &rcar_dev_funcs,
632*91f16700Schasinglulu 	.info = (uintptr_t) 0
633*91f16700Schasinglulu };
634*91f16700Schasinglulu 
635*91f16700Schasinglulu static const io_dev_connector_t rcar_dev_connector = {
636*91f16700Schasinglulu 	.dev_open = &rcar_dev_open
637*91f16700Schasinglulu };
638*91f16700Schasinglulu 
639*91f16700Schasinglulu static int32_t rcar_dev_open(const uintptr_t dev_spec __attribute__ ((unused)),
640*91f16700Schasinglulu 			     io_dev_info_t **dev_info)
641*91f16700Schasinglulu {
642*91f16700Schasinglulu 	*dev_info = (io_dev_info_t *) &rcar_dev_info;
643*91f16700Schasinglulu 
644*91f16700Schasinglulu 	return IO_SUCCESS;
645*91f16700Schasinglulu }
646*91f16700Schasinglulu 
647*91f16700Schasinglulu static int32_t rcar_dev_close(io_dev_info_t *dev_info)
648*91f16700Schasinglulu {
649*91f16700Schasinglulu 	rcar_handle = 0;
650*91f16700Schasinglulu 	rcar_spec = 0;
651*91f16700Schasinglulu 
652*91f16700Schasinglulu 	return IO_SUCCESS;
653*91f16700Schasinglulu }
654*91f16700Schasinglulu 
655*91f16700Schasinglulu int32_t rcar_register_io_dev(const io_dev_connector_t **dev_con)
656*91f16700Schasinglulu {
657*91f16700Schasinglulu 	int32_t result;
658*91f16700Schasinglulu 
659*91f16700Schasinglulu 	result = io_register_device(&rcar_dev_info);
660*91f16700Schasinglulu 	if (result == IO_SUCCESS) {
661*91f16700Schasinglulu 		*dev_con = &rcar_dev_connector;
662*91f16700Schasinglulu 	}
663*91f16700Schasinglulu 
664*91f16700Schasinglulu 	return result;
665*91f16700Schasinglulu }
666