xref: /arm-trusted-firmware/plat/brcm/common/brcm_io_storage.c (revision 91f16700b400a8c0651d24a598fc48ee2997a0d7)
1*91f16700Schasinglulu /*
2*91f16700Schasinglulu  * Copyright (c) 2019-2020, ARM Limited and Contributors. All rights reserved.
3*91f16700Schasinglulu  *
4*91f16700Schasinglulu  * SPDX-License-Identifier: BSD-3-Clause
5*91f16700Schasinglulu  */
6*91f16700Schasinglulu 
7*91f16700Schasinglulu #include <assert.h>
8*91f16700Schasinglulu #include <string.h>
9*91f16700Schasinglulu 
10*91f16700Schasinglulu #include <common/debug.h>
11*91f16700Schasinglulu #include <drivers/io/io_driver.h>
12*91f16700Schasinglulu #include <drivers/io/io_fip.h>
13*91f16700Schasinglulu #include <drivers/io/io_memmap.h>
14*91f16700Schasinglulu #include <drivers/io/io_storage.h>
15*91f16700Schasinglulu #include <tools_share/firmware_image_package.h>
16*91f16700Schasinglulu 
17*91f16700Schasinglulu #include <cmn_plat_def.h>
18*91f16700Schasinglulu #include <cmn_plat_util.h>
19*91f16700Schasinglulu #include <plat_brcm.h>
20*91f16700Schasinglulu #include <platform_def.h>
21*91f16700Schasinglulu 
22*91f16700Schasinglulu /* IO devices */
23*91f16700Schasinglulu static const io_dev_connector_t *fip_dev_con;
24*91f16700Schasinglulu static uintptr_t fip_dev_handle;
25*91f16700Schasinglulu static const io_dev_connector_t *memmap_dev_con;
26*91f16700Schasinglulu static uintptr_t memmap_dev_handle;
27*91f16700Schasinglulu 
28*91f16700Schasinglulu static const io_block_spec_t fip_block_spec = {
29*91f16700Schasinglulu 	.offset = PLAT_BRCM_FIP_BASE,
30*91f16700Schasinglulu 	.length = PLAT_BRCM_FIP_MAX_SIZE
31*91f16700Schasinglulu };
32*91f16700Schasinglulu 
33*91f16700Schasinglulu static const io_block_spec_t qspi_fip_block_spec = {
34*91f16700Schasinglulu 	.offset = PLAT_BRCM_FIP_QSPI_BASE,
35*91f16700Schasinglulu 	.length = PLAT_BRCM_FIP_MAX_SIZE
36*91f16700Schasinglulu };
37*91f16700Schasinglulu 
38*91f16700Schasinglulu static const io_block_spec_t nand_fip_block_spec = {
39*91f16700Schasinglulu 	.offset = PLAT_BRCM_FIP_NAND_BASE,
40*91f16700Schasinglulu 	.length = PLAT_BRCM_FIP_MAX_SIZE
41*91f16700Schasinglulu };
42*91f16700Schasinglulu 
43*91f16700Schasinglulu static const io_uuid_spec_t bl2_uuid_spec = {
44*91f16700Schasinglulu 	.uuid = UUID_TRUSTED_BOOT_FIRMWARE_BL2,
45*91f16700Schasinglulu };
46*91f16700Schasinglulu 
47*91f16700Schasinglulu static const io_uuid_spec_t scp_bl2_uuid_spec = {
48*91f16700Schasinglulu 	.uuid = UUID_SCP_FIRMWARE_SCP_BL2,
49*91f16700Schasinglulu };
50*91f16700Schasinglulu 
51*91f16700Schasinglulu static const io_uuid_spec_t bl31_uuid_spec = {
52*91f16700Schasinglulu 	.uuid = UUID_EL3_RUNTIME_FIRMWARE_BL31,
53*91f16700Schasinglulu };
54*91f16700Schasinglulu 
55*91f16700Schasinglulu static const io_uuid_spec_t bl32_uuid_spec = {
56*91f16700Schasinglulu 	.uuid = UUID_SECURE_PAYLOAD_BL32,
57*91f16700Schasinglulu };
58*91f16700Schasinglulu 
59*91f16700Schasinglulu static const io_uuid_spec_t bl32_extra1_uuid_spec = {
60*91f16700Schasinglulu 	.uuid = UUID_SECURE_PAYLOAD_BL32_EXTRA1,
61*91f16700Schasinglulu };
62*91f16700Schasinglulu 
63*91f16700Schasinglulu static const io_uuid_spec_t bl32_extra2_uuid_spec = {
64*91f16700Schasinglulu 	.uuid = UUID_SECURE_PAYLOAD_BL32_EXTRA2,
65*91f16700Schasinglulu };
66*91f16700Schasinglulu 
67*91f16700Schasinglulu static const io_uuid_spec_t bl33_uuid_spec = {
68*91f16700Schasinglulu 	.uuid = UUID_NON_TRUSTED_FIRMWARE_BL33,
69*91f16700Schasinglulu };
70*91f16700Schasinglulu 
71*91f16700Schasinglulu static const io_uuid_spec_t tb_fw_config_uuid_spec = {
72*91f16700Schasinglulu 	.uuid = UUID_TB_FW_CONFIG,
73*91f16700Schasinglulu };
74*91f16700Schasinglulu 
75*91f16700Schasinglulu static const io_uuid_spec_t hw_config_uuid_spec = {
76*91f16700Schasinglulu 	.uuid = UUID_HW_CONFIG,
77*91f16700Schasinglulu };
78*91f16700Schasinglulu 
79*91f16700Schasinglulu static const io_uuid_spec_t soc_fw_config_uuid_spec = {
80*91f16700Schasinglulu 	.uuid = UUID_SOC_FW_CONFIG,
81*91f16700Schasinglulu };
82*91f16700Schasinglulu 
83*91f16700Schasinglulu static const io_uuid_spec_t tos_fw_config_uuid_spec = {
84*91f16700Schasinglulu 	.uuid = UUID_TOS_FW_CONFIG,
85*91f16700Schasinglulu };
86*91f16700Schasinglulu 
87*91f16700Schasinglulu static const io_uuid_spec_t nt_fw_config_uuid_spec = {
88*91f16700Schasinglulu 	.uuid = UUID_NT_FW_CONFIG,
89*91f16700Schasinglulu };
90*91f16700Schasinglulu 
91*91f16700Schasinglulu #if TRUSTED_BOARD_BOOT
92*91f16700Schasinglulu static const io_uuid_spec_t tb_fw_cert_uuid_spec = {
93*91f16700Schasinglulu 	.uuid = UUID_TRUSTED_BOOT_FW_CERT,
94*91f16700Schasinglulu };
95*91f16700Schasinglulu 
96*91f16700Schasinglulu static const io_uuid_spec_t trusted_key_cert_uuid_spec = {
97*91f16700Schasinglulu 	.uuid = UUID_TRUSTED_KEY_CERT,
98*91f16700Schasinglulu };
99*91f16700Schasinglulu 
100*91f16700Schasinglulu static const io_uuid_spec_t scp_fw_key_cert_uuid_spec = {
101*91f16700Schasinglulu 	.uuid = UUID_SCP_FW_KEY_CERT,
102*91f16700Schasinglulu };
103*91f16700Schasinglulu 
104*91f16700Schasinglulu static const io_uuid_spec_t soc_fw_key_cert_uuid_spec = {
105*91f16700Schasinglulu 	.uuid = UUID_SOC_FW_KEY_CERT,
106*91f16700Schasinglulu };
107*91f16700Schasinglulu 
108*91f16700Schasinglulu static const io_uuid_spec_t tos_fw_key_cert_uuid_spec = {
109*91f16700Schasinglulu 	.uuid = UUID_TRUSTED_OS_FW_KEY_CERT,
110*91f16700Schasinglulu };
111*91f16700Schasinglulu 
112*91f16700Schasinglulu static const io_uuid_spec_t nt_fw_key_cert_uuid_spec = {
113*91f16700Schasinglulu 	.uuid = UUID_NON_TRUSTED_FW_KEY_CERT,
114*91f16700Schasinglulu };
115*91f16700Schasinglulu 
116*91f16700Schasinglulu static const io_uuid_spec_t scp_fw_cert_uuid_spec = {
117*91f16700Schasinglulu 	.uuid = UUID_SCP_FW_CONTENT_CERT,
118*91f16700Schasinglulu };
119*91f16700Schasinglulu 
120*91f16700Schasinglulu static const io_uuid_spec_t soc_fw_cert_uuid_spec = {
121*91f16700Schasinglulu 	.uuid = UUID_SOC_FW_CONTENT_CERT,
122*91f16700Schasinglulu };
123*91f16700Schasinglulu 
124*91f16700Schasinglulu static const io_uuid_spec_t tos_fw_cert_uuid_spec = {
125*91f16700Schasinglulu 	.uuid = UUID_TRUSTED_OS_FW_CONTENT_CERT,
126*91f16700Schasinglulu };
127*91f16700Schasinglulu 
128*91f16700Schasinglulu static const io_uuid_spec_t nt_fw_cert_uuid_spec = {
129*91f16700Schasinglulu 	.uuid = UUID_NON_TRUSTED_FW_CONTENT_CERT,
130*91f16700Schasinglulu };
131*91f16700Schasinglulu #endif /* TRUSTED_BOARD_BOOT */
132*91f16700Schasinglulu 
133*91f16700Schasinglulu static int open_fip(const uintptr_t spec);
134*91f16700Schasinglulu static int open_memmap(const uintptr_t spec);
135*91f16700Schasinglulu static int open_qspi(const uintptr_t spec);
136*91f16700Schasinglulu static int open_nand(const uintptr_t spec);
137*91f16700Schasinglulu 
138*91f16700Schasinglulu struct plat_io_policy {
139*91f16700Schasinglulu 	uintptr_t *dev_handle;
140*91f16700Schasinglulu 	uintptr_t image_spec;
141*91f16700Schasinglulu 	int (*check)(const uintptr_t spec);
142*91f16700Schasinglulu };
143*91f16700Schasinglulu 
144*91f16700Schasinglulu /* By default, BRCM platforms load images from the FIP */
145*91f16700Schasinglulu static const struct plat_io_policy policies[] = {
146*91f16700Schasinglulu 	[FIP_IMAGE_ID] = {
147*91f16700Schasinglulu 		&memmap_dev_handle,
148*91f16700Schasinglulu 		(uintptr_t)&fip_block_spec,
149*91f16700Schasinglulu 		open_memmap
150*91f16700Schasinglulu 	},
151*91f16700Schasinglulu 	[BL2_IMAGE_ID] = {
152*91f16700Schasinglulu 		&fip_dev_handle,
153*91f16700Schasinglulu 		(uintptr_t)&bl2_uuid_spec,
154*91f16700Schasinglulu 		open_fip
155*91f16700Schasinglulu 	},
156*91f16700Schasinglulu 	[SCP_BL2_IMAGE_ID] = {
157*91f16700Schasinglulu 		&fip_dev_handle,
158*91f16700Schasinglulu 		(uintptr_t)&scp_bl2_uuid_spec,
159*91f16700Schasinglulu 		open_fip
160*91f16700Schasinglulu 	},
161*91f16700Schasinglulu 	[BL31_IMAGE_ID] = {
162*91f16700Schasinglulu 		&fip_dev_handle,
163*91f16700Schasinglulu 		(uintptr_t)&bl31_uuid_spec,
164*91f16700Schasinglulu 		open_fip
165*91f16700Schasinglulu 	},
166*91f16700Schasinglulu 	[BL32_IMAGE_ID] = {
167*91f16700Schasinglulu 		&fip_dev_handle,
168*91f16700Schasinglulu 		(uintptr_t)&bl32_uuid_spec,
169*91f16700Schasinglulu 		open_fip
170*91f16700Schasinglulu 	},
171*91f16700Schasinglulu 	[BL32_EXTRA1_IMAGE_ID] = {
172*91f16700Schasinglulu 		&fip_dev_handle,
173*91f16700Schasinglulu 		(uintptr_t)&bl32_extra1_uuid_spec,
174*91f16700Schasinglulu 		open_fip
175*91f16700Schasinglulu 	},
176*91f16700Schasinglulu 	[BL32_EXTRA2_IMAGE_ID] = {
177*91f16700Schasinglulu 		&fip_dev_handle,
178*91f16700Schasinglulu 		(uintptr_t)&bl32_extra2_uuid_spec,
179*91f16700Schasinglulu 		open_fip
180*91f16700Schasinglulu 	},
181*91f16700Schasinglulu 	[BL33_IMAGE_ID] = {
182*91f16700Schasinglulu 		&fip_dev_handle,
183*91f16700Schasinglulu 		(uintptr_t)&bl33_uuid_spec,
184*91f16700Schasinglulu 		open_fip
185*91f16700Schasinglulu 	},
186*91f16700Schasinglulu 	[TB_FW_CONFIG_ID] = {
187*91f16700Schasinglulu 		&fip_dev_handle,
188*91f16700Schasinglulu 		(uintptr_t)&tb_fw_config_uuid_spec,
189*91f16700Schasinglulu 		open_fip
190*91f16700Schasinglulu 	},
191*91f16700Schasinglulu 	[HW_CONFIG_ID] = {
192*91f16700Schasinglulu 		&fip_dev_handle,
193*91f16700Schasinglulu 		(uintptr_t)&hw_config_uuid_spec,
194*91f16700Schasinglulu 		open_fip
195*91f16700Schasinglulu 	},
196*91f16700Schasinglulu 	[SOC_FW_CONFIG_ID] = {
197*91f16700Schasinglulu 		&fip_dev_handle,
198*91f16700Schasinglulu 		(uintptr_t)&soc_fw_config_uuid_spec,
199*91f16700Schasinglulu 		open_fip
200*91f16700Schasinglulu 	},
201*91f16700Schasinglulu 	[TOS_FW_CONFIG_ID] = {
202*91f16700Schasinglulu 		&fip_dev_handle,
203*91f16700Schasinglulu 		(uintptr_t)&tos_fw_config_uuid_spec,
204*91f16700Schasinglulu 		open_fip
205*91f16700Schasinglulu 	},
206*91f16700Schasinglulu 	[NT_FW_CONFIG_ID] = {
207*91f16700Schasinglulu 		&fip_dev_handle,
208*91f16700Schasinglulu 		(uintptr_t)&nt_fw_config_uuid_spec,
209*91f16700Schasinglulu 		open_fip
210*91f16700Schasinglulu 	},
211*91f16700Schasinglulu #if TRUSTED_BOARD_BOOT
212*91f16700Schasinglulu 	[TRUSTED_BOOT_FW_CERT_ID] = {
213*91f16700Schasinglulu 		&fip_dev_handle,
214*91f16700Schasinglulu 		(uintptr_t)&tb_fw_cert_uuid_spec,
215*91f16700Schasinglulu 		open_fip
216*91f16700Schasinglulu 	},
217*91f16700Schasinglulu 	[TRUSTED_KEY_CERT_ID] = {
218*91f16700Schasinglulu 		&fip_dev_handle,
219*91f16700Schasinglulu 		(uintptr_t)&trusted_key_cert_uuid_spec,
220*91f16700Schasinglulu 		open_fip
221*91f16700Schasinglulu 	},
222*91f16700Schasinglulu 	[SCP_FW_KEY_CERT_ID] = {
223*91f16700Schasinglulu 		&fip_dev_handle,
224*91f16700Schasinglulu 		(uintptr_t)&scp_fw_key_cert_uuid_spec,
225*91f16700Schasinglulu 		open_fip
226*91f16700Schasinglulu 	},
227*91f16700Schasinglulu 	[SOC_FW_KEY_CERT_ID] = {
228*91f16700Schasinglulu 		&fip_dev_handle,
229*91f16700Schasinglulu 		(uintptr_t)&soc_fw_key_cert_uuid_spec,
230*91f16700Schasinglulu 		open_fip
231*91f16700Schasinglulu 	},
232*91f16700Schasinglulu 	[TRUSTED_OS_FW_KEY_CERT_ID] = {
233*91f16700Schasinglulu 		&fip_dev_handle,
234*91f16700Schasinglulu 		(uintptr_t)&tos_fw_key_cert_uuid_spec,
235*91f16700Schasinglulu 		open_fip
236*91f16700Schasinglulu 	},
237*91f16700Schasinglulu 	[NON_TRUSTED_FW_KEY_CERT_ID] = {
238*91f16700Schasinglulu 		&fip_dev_handle,
239*91f16700Schasinglulu 		(uintptr_t)&nt_fw_key_cert_uuid_spec,
240*91f16700Schasinglulu 		open_fip
241*91f16700Schasinglulu 	},
242*91f16700Schasinglulu 	[SCP_FW_CONTENT_CERT_ID] = {
243*91f16700Schasinglulu 		&fip_dev_handle,
244*91f16700Schasinglulu 		(uintptr_t)&scp_fw_cert_uuid_spec,
245*91f16700Schasinglulu 		open_fip
246*91f16700Schasinglulu 	},
247*91f16700Schasinglulu 	[SOC_FW_CONTENT_CERT_ID] = {
248*91f16700Schasinglulu 		&fip_dev_handle,
249*91f16700Schasinglulu 		(uintptr_t)&soc_fw_cert_uuid_spec,
250*91f16700Schasinglulu 		open_fip
251*91f16700Schasinglulu 	},
252*91f16700Schasinglulu 	[TRUSTED_OS_FW_CONTENT_CERT_ID] = {
253*91f16700Schasinglulu 		&fip_dev_handle,
254*91f16700Schasinglulu 		(uintptr_t)&tos_fw_cert_uuid_spec,
255*91f16700Schasinglulu 		open_fip
256*91f16700Schasinglulu 	},
257*91f16700Schasinglulu 	[NON_TRUSTED_FW_CONTENT_CERT_ID] = {
258*91f16700Schasinglulu 		&fip_dev_handle,
259*91f16700Schasinglulu 		(uintptr_t)&nt_fw_cert_uuid_spec,
260*91f16700Schasinglulu 		open_fip
261*91f16700Schasinglulu 	},
262*91f16700Schasinglulu #endif /* TRUSTED_BOARD_BOOT */
263*91f16700Schasinglulu };
264*91f16700Schasinglulu 
265*91f16700Schasinglulu /* By default, BRCM platforms load images from the FIP */
266*91f16700Schasinglulu static const struct plat_io_policy boot_source_policies[] = {
267*91f16700Schasinglulu 	[BOOT_SOURCE_QSPI] = {
268*91f16700Schasinglulu 		&memmap_dev_handle,
269*91f16700Schasinglulu 		(uintptr_t)&qspi_fip_block_spec,
270*91f16700Schasinglulu 		open_qspi
271*91f16700Schasinglulu 	},
272*91f16700Schasinglulu 	[BOOT_SOURCE_NAND] = {
273*91f16700Schasinglulu 		&memmap_dev_handle,
274*91f16700Schasinglulu 		(uintptr_t)&nand_fip_block_spec,
275*91f16700Schasinglulu 		open_nand
276*91f16700Schasinglulu 	},
277*91f16700Schasinglulu };
278*91f16700Schasinglulu 
279*91f16700Schasinglulu /* Weak definitions may be overridden in specific brcm platform */
280*91f16700Schasinglulu #pragma weak plat_brcm_io_setup
281*91f16700Schasinglulu #pragma weak plat_brcm_process_flags
282*91f16700Schasinglulu 
283*91f16700Schasinglulu static int open_fip(const uintptr_t spec)
284*91f16700Schasinglulu {
285*91f16700Schasinglulu 	int result;
286*91f16700Schasinglulu 	uintptr_t local_image_handle;
287*91f16700Schasinglulu 
288*91f16700Schasinglulu 	/* See if a Firmware Image Package is available */
289*91f16700Schasinglulu 	result = io_dev_init(fip_dev_handle, (uintptr_t)FIP_IMAGE_ID);
290*91f16700Schasinglulu 	if (result == 0) {
291*91f16700Schasinglulu 		result = io_open(fip_dev_handle, spec, &local_image_handle);
292*91f16700Schasinglulu 		if (result == 0) {
293*91f16700Schasinglulu 			VERBOSE("Using FIP\n");
294*91f16700Schasinglulu 			io_close(local_image_handle);
295*91f16700Schasinglulu 		}
296*91f16700Schasinglulu 	}
297*91f16700Schasinglulu 	return result;
298*91f16700Schasinglulu }
299*91f16700Schasinglulu 
300*91f16700Schasinglulu 
301*91f16700Schasinglulu static int open_memmap(const uintptr_t spec)
302*91f16700Schasinglulu {
303*91f16700Schasinglulu 	int result;
304*91f16700Schasinglulu 	uintptr_t local_image_handle;
305*91f16700Schasinglulu 
306*91f16700Schasinglulu 	result = io_dev_init(memmap_dev_handle, (uintptr_t)NULL);
307*91f16700Schasinglulu 	if (result == 0) {
308*91f16700Schasinglulu 		result = io_open(memmap_dev_handle, spec, &local_image_handle);
309*91f16700Schasinglulu 		if (result == 0) {
310*91f16700Schasinglulu 			VERBOSE("Using Memmap\n");
311*91f16700Schasinglulu 			io_close(local_image_handle);
312*91f16700Schasinglulu 		}
313*91f16700Schasinglulu 	}
314*91f16700Schasinglulu 	return result;
315*91f16700Schasinglulu }
316*91f16700Schasinglulu 
317*91f16700Schasinglulu static int open_qspi(const uintptr_t spec)
318*91f16700Schasinglulu {
319*91f16700Schasinglulu 	return open_memmap(spec);
320*91f16700Schasinglulu }
321*91f16700Schasinglulu 
322*91f16700Schasinglulu static int open_nand(const uintptr_t spec)
323*91f16700Schasinglulu {
324*91f16700Schasinglulu 	return open_memmap(spec);
325*91f16700Schasinglulu }
326*91f16700Schasinglulu 
327*91f16700Schasinglulu 
328*91f16700Schasinglulu void brcm_io_setup(void)
329*91f16700Schasinglulu {
330*91f16700Schasinglulu 	int io_result;
331*91f16700Schasinglulu 	uint32_t boot_source;
332*91f16700Schasinglulu 
333*91f16700Schasinglulu 	io_result = register_io_dev_fip(&fip_dev_con);
334*91f16700Schasinglulu 	assert(io_result == 0);
335*91f16700Schasinglulu 
336*91f16700Schasinglulu 	io_result = register_io_dev_memmap(&memmap_dev_con);
337*91f16700Schasinglulu 	assert(io_result == 0);
338*91f16700Schasinglulu 
339*91f16700Schasinglulu 	/* Open connections to devices and cache the handles */
340*91f16700Schasinglulu 	io_result = io_dev_open(fip_dev_con, (uintptr_t)NULL,
341*91f16700Schasinglulu 				&fip_dev_handle);
342*91f16700Schasinglulu 	assert(io_result == 0);
343*91f16700Schasinglulu 
344*91f16700Schasinglulu 	boot_source = boot_source_get();
345*91f16700Schasinglulu 	switch (boot_source) {
346*91f16700Schasinglulu 	case BOOT_SOURCE_QSPI:
347*91f16700Schasinglulu 	case BOOT_SOURCE_NAND:
348*91f16700Schasinglulu 	default:
349*91f16700Schasinglulu 		io_result = io_dev_open(memmap_dev_con, (uintptr_t)NULL,
350*91f16700Schasinglulu 					&memmap_dev_handle);
351*91f16700Schasinglulu 		break;
352*91f16700Schasinglulu 	}
353*91f16700Schasinglulu 	assert(io_result == 0);
354*91f16700Schasinglulu 
355*91f16700Schasinglulu 	/* Ignore improbable errors in release builds */
356*91f16700Schasinglulu 	(void)io_result;
357*91f16700Schasinglulu }
358*91f16700Schasinglulu 
359*91f16700Schasinglulu void plat_brcm_io_setup(void)
360*91f16700Schasinglulu {
361*91f16700Schasinglulu 	brcm_io_setup();
362*91f16700Schasinglulu }
363*91f16700Schasinglulu 
364*91f16700Schasinglulu void plat_brcm_process_flags(uint16_t plat_toc_flags __unused)
365*91f16700Schasinglulu {
366*91f16700Schasinglulu 	WARN("%s not implemented\n", __func__);
367*91f16700Schasinglulu }
368*91f16700Schasinglulu 
369*91f16700Schasinglulu /*
370*91f16700Schasinglulu  * Return an IO device handle and specification which can be used to access
371*91f16700Schasinglulu  * an image. Use this to enforce platform load policy
372*91f16700Schasinglulu  */
373*91f16700Schasinglulu int plat_get_image_source(unsigned int image_id, uintptr_t *dev_handle,
374*91f16700Schasinglulu 			  uintptr_t *image_spec)
375*91f16700Schasinglulu {
376*91f16700Schasinglulu 	int result;
377*91f16700Schasinglulu 	const struct plat_io_policy *policy;
378*91f16700Schasinglulu 	uint32_t boot_source;
379*91f16700Schasinglulu 	uint16_t lcl_plat_toc_flg;
380*91f16700Schasinglulu 
381*91f16700Schasinglulu 	assert(image_id < ARRAY_SIZE(policies));
382*91f16700Schasinglulu 
383*91f16700Schasinglulu 	boot_source = boot_source_get();
384*91f16700Schasinglulu 	if (image_id == FIP_IMAGE_ID)
385*91f16700Schasinglulu 		policy = &boot_source_policies[boot_source];
386*91f16700Schasinglulu 	else
387*91f16700Schasinglulu 		policy = &policies[image_id];
388*91f16700Schasinglulu 
389*91f16700Schasinglulu 	result = policy->check(policy->image_spec);
390*91f16700Schasinglulu 	if (result == 0) {
391*91f16700Schasinglulu 		*image_spec = policy->image_spec;
392*91f16700Schasinglulu 		*dev_handle = *(policy->dev_handle);
393*91f16700Schasinglulu 
394*91f16700Schasinglulu 		if (image_id == TRUSTED_BOOT_FW_CERT_ID) {
395*91f16700Schasinglulu 			/*
396*91f16700Schasinglulu 			 * Process the header flags to perform
397*91f16700Schasinglulu 			 * such custom actions as speeding up PLL.
398*91f16700Schasinglulu 			 * CERT seems to be the first image accessed
399*91f16700Schasinglulu 			 * by BL1 so this is where we process the flags.
400*91f16700Schasinglulu 			 */
401*91f16700Schasinglulu 			fip_dev_get_plat_toc_flag((io_dev_info_t *)fip_dev_handle,
402*91f16700Schasinglulu 						  &lcl_plat_toc_flg);
403*91f16700Schasinglulu 			plat_brcm_process_flags(lcl_plat_toc_flg);
404*91f16700Schasinglulu 		}
405*91f16700Schasinglulu 	}
406*91f16700Schasinglulu 
407*91f16700Schasinglulu 	return result;
408*91f16700Schasinglulu }
409