xref: /arm-trusted-firmware/plat/imx/imx8m/imx8m_measured_boot.c (revision 91f16700b400a8c0651d24a598fc48ee2997a0d7)
1*91f16700Schasinglulu /*
2*91f16700Schasinglulu  * Copyright (c) 2022-2023, Arm Limited. All rights reserved.
3*91f16700Schasinglulu  * Copyright (c) 2022, Linaro.
4*91f16700Schasinglulu  *
5*91f16700Schasinglulu  * SPDX-License-Identifier: BSD-3-Clause
6*91f16700Schasinglulu  */
7*91f16700Schasinglulu 
8*91f16700Schasinglulu #include <string.h>
9*91f16700Schasinglulu 
10*91f16700Schasinglulu #include "./include/imx8m_measured_boot.h"
11*91f16700Schasinglulu #include <drivers/measured_boot/event_log/event_log.h>
12*91f16700Schasinglulu #include <plat/arm/common/plat_arm.h>
13*91f16700Schasinglulu 
14*91f16700Schasinglulu /* Event Log data */
15*91f16700Schasinglulu static uint8_t event_log[PLAT_IMX_EVENT_LOG_MAX_SIZE];
16*91f16700Schasinglulu 
17*91f16700Schasinglulu /* FVP table with platform specific image IDs, names and PCRs */
18*91f16700Schasinglulu static const event_log_metadata_t imx8m_event_log_metadata[] = {
19*91f16700Schasinglulu 	{ BL31_IMAGE_ID, EVLOG_BL31_STRING, PCR_0 },
20*91f16700Schasinglulu 	{ BL32_IMAGE_ID, EVLOG_BL32_STRING, PCR_0 },
21*91f16700Schasinglulu 	{ BL32_EXTRA1_IMAGE_ID, EVLOG_BL32_EXTRA1_STRING, PCR_0 },
22*91f16700Schasinglulu 	{ BL32_EXTRA2_IMAGE_ID, EVLOG_BL32_EXTRA2_STRING, PCR_0 },
23*91f16700Schasinglulu 	{ BL33_IMAGE_ID, EVLOG_BL33_STRING, PCR_0 },
24*91f16700Schasinglulu 	{ EVLOG_INVALID_ID, NULL, (unsigned int)(-1) }	/* Terminator */
25*91f16700Schasinglulu };
26*91f16700Schasinglulu 
27*91f16700Schasinglulu int plat_mboot_measure_image(unsigned int image_id, image_info_t *image_data)
28*91f16700Schasinglulu {
29*91f16700Schasinglulu 	/* Calculate image hash and record data in Event Log */
30*91f16700Schasinglulu 	int err = event_log_measure_and_record(image_data->image_base,
31*91f16700Schasinglulu 					       image_data->image_size,
32*91f16700Schasinglulu 					       image_id,
33*91f16700Schasinglulu 					       imx8m_event_log_metadata);
34*91f16700Schasinglulu 	if (err != 0) {
35*91f16700Schasinglulu 		ERROR("%s%s image id %u (%i)\n",
36*91f16700Schasinglulu 		      "Failed to ", "record", image_id, err);
37*91f16700Schasinglulu 		return err;
38*91f16700Schasinglulu 	}
39*91f16700Schasinglulu 
40*91f16700Schasinglulu 	return 0;
41*91f16700Schasinglulu }
42*91f16700Schasinglulu 
43*91f16700Schasinglulu void bl2_plat_mboot_init(void)
44*91f16700Schasinglulu {
45*91f16700Schasinglulu 	event_log_init(event_log, event_log + sizeof(event_log));
46*91f16700Schasinglulu 	event_log_write_header();
47*91f16700Schasinglulu }
48*91f16700Schasinglulu 
49*91f16700Schasinglulu void bl2_plat_mboot_finish(void)
50*91f16700Schasinglulu {
51*91f16700Schasinglulu 	int rc = 0;
52*91f16700Schasinglulu 
53*91f16700Schasinglulu 	/* Event Log address in Non-Secure memory */
54*91f16700Schasinglulu 	uintptr_t ns_log_addr;
55*91f16700Schasinglulu 
56*91f16700Schasinglulu 	/* Event Log filled size */
57*91f16700Schasinglulu 	size_t event_log_cur_size;
58*91f16700Schasinglulu 
59*91f16700Schasinglulu 	event_log_cur_size = event_log_get_cur_size(event_log);
60*91f16700Schasinglulu 
61*91f16700Schasinglulu 	rc = imx8m_set_nt_fw_info(event_log_cur_size, &ns_log_addr);
62*91f16700Schasinglulu 	if (rc != 0) {
63*91f16700Schasinglulu 		ERROR("%s(): Unable to update %s_FW_CONFIG\n",
64*91f16700Schasinglulu 		      __func__, "NT");
65*91f16700Schasinglulu 		/*
66*91f16700Schasinglulu 		 * It is a fatal error because on i.MX U-boot assumes that
67*91f16700Schasinglulu 		 * a valid event log exists and will use it to record the
68*91f16700Schasinglulu 		 * measurements into the fTPM.
69*91f16700Schasinglulu 		 */
70*91f16700Schasinglulu 		panic();
71*91f16700Schasinglulu 	}
72*91f16700Schasinglulu 
73*91f16700Schasinglulu 	/* Copy Event Log to Non-secure memory */
74*91f16700Schasinglulu 	(void)memcpy((void *)ns_log_addr, (const void *)event_log,
75*91f16700Schasinglulu 		     event_log_cur_size);
76*91f16700Schasinglulu 
77*91f16700Schasinglulu 	/* Ensure that the Event Log is visible in Non-secure memory */
78*91f16700Schasinglulu 	flush_dcache_range(ns_log_addr, event_log_cur_size);
79*91f16700Schasinglulu 
80*91f16700Schasinglulu 	dump_event_log((uint8_t *)event_log, event_log_cur_size);
81*91f16700Schasinglulu }
82*91f16700Schasinglulu 
83*91f16700Schasinglulu int plat_mboot_measure_key(const void *pk_oid, const void *pk_ptr,
84*91f16700Schasinglulu 			   size_t pk_len)
85*91f16700Schasinglulu {
86*91f16700Schasinglulu 	return 0;
87*91f16700Schasinglulu }
88