From patchwork Wed Jan 19 18:55:39 2022 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Sughosh Ganu X-Patchwork-Id: 533271 Delivered-To: patch@linaro.org Received: by 2002:ac0:f7d2:0:0:0:0:0 with SMTP id i18csp1130242imr; Wed, 19 Jan 2022 10:56:41 -0800 (PST) X-Google-Smtp-Source: ABdhPJy0fjaoM58OH9hQ0q0eBoyh6N5FQL5u+hs+qhgiIMKWIABLVjPBwyVdqqx3PIjkjHEe7FrE X-Received: by 2002:a17:906:4983:: with SMTP id p3mr25902811eju.589.1642618601095; Wed, 19 Jan 2022 10:56:41 -0800 (PST) ARC-Seal: i=1; a=rsa-sha256; t=1642618601; cv=none; d=google.com; s=arc-20160816; b=LmbSaIYJw4NuXuq9amBjpE8mbODt/2MQ6AYCwilW+A4McHE2BhS2jmTmX7udgdZIF5 a90TNREm7n0C0MFLig7awINFlZw6zHuBhdxgsrwICYYCiZhKl25mecex3wEySt8PjlL3 0/9yjmCLw+ufhOhf2EmXVmMmX1MxsnlcX51+P7S0Y/kQybwJRb7iHrNVHOv/qdcOeQem sLkp7VDBgoUPiBjfYiOSe3M+k/7IEPYm0WL9OcDe7sJ0KDXYXHy+FLqdujTG5+nhHhc+ SLRkQJlV8GTOpCvThXygi2+C5AngJISH/xQhO2e1Coh807idPXllsNznraSIobUiGNTK e7Lw== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=sender:errors-to:list-subscribe:list-help:list-post:list-archive :list-unsubscribe:list-id:precedence:message-id:date:subject:cc:to :from; bh=p4OYPVkTqAe/4Db3/RiIe3wmlnODnDav8HZ3I9lLX/E=; b=WXDGzy5nMUwr0BF4pbOaLu4b3GVtLNRw/5/cNq2gkfyn0eILCyYOhFkjUUvqjBmILP cV0pvElb17Ln+G+gBDLnM7e0sJhBXqCWtgK5MMvnh4dGSQe4KSO6+sgUdk68ALiz1n9T d+ig3uzdfiMrXcOKUpjwQG2np5AMFkCRlW0OBv8q8FESB38yZs8YZTLIRAMV32hgchde nwY9cTJ3iUZ0W6LUuDOWRgVGZ8PM0o8qMfMKldNqiDqLNG/ba0AWSEn0yI3BvaJz4apc W9LBHVT+a9bKkGHV2aL407VVvdXPdHk4idkeRIxK3Rj6WCFOq5tWMzQLWnoKFgeP/Mo6 KL2Q== ARC-Authentication-Results: i=1; mx.google.com; spf=pass (google.com: domain of u-boot-bounces@lists.denx.de designates 85.214.62.61 as permitted sender) smtp.mailfrom=u-boot-bounces@lists.denx.de; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=linaro.org Return-Path: Received: from phobos.denx.de (phobos.denx.de. [85.214.62.61]) by mx.google.com with ESMTPS id 6si306329ejc.71.2022.01.19.10.56.40 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 19 Jan 2022 10:56:41 -0800 (PST) Received-SPF: pass (google.com: domain of u-boot-bounces@lists.denx.de designates 85.214.62.61 as permitted sender) client-ip=85.214.62.61; Authentication-Results: mx.google.com; spf=pass (google.com: domain of u-boot-bounces@lists.denx.de designates 85.214.62.61 as permitted sender) smtp.mailfrom=u-boot-bounces@lists.denx.de; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=linaro.org Received: from h2850616.stratoserver.net (localhost [IPv6:::1]) by phobos.denx.de (Postfix) with ESMTP id 6C95A832CD; Wed, 19 Jan 2022 19:56:38 +0100 (CET) Authentication-Results: phobos.denx.de; dmarc=fail (p=none dis=none) header.from=linaro.org Authentication-Results: phobos.denx.de; spf=pass smtp.mailfrom=u-boot-bounces@lists.denx.de Received: by phobos.denx.de (Postfix, from userid 109) id 92C3083325; Wed, 19 Jan 2022 19:56:36 +0100 (CET) X-Spam-Checker-Version: SpamAssassin 3.4.2 (2018-09-13) on phobos.denx.de X-Spam-Level: X-Spam-Status: No, score=-1.2 required=5.0 tests=BAYES_00,LOTS_OF_MONEY, SPF_HELO_NONE,SPF_SOFTFAIL autolearn=no autolearn_force=no version=3.4.2 Received: from foss.arm.com (foss.arm.com [217.140.110.172]) by phobos.denx.de (Postfix) with ESMTP id 0C300831CA for ; Wed, 19 Jan 2022 19:56:33 +0100 (CET) Authentication-Results: phobos.denx.de; dmarc=fail (p=none dis=none) header.from=linaro.org Authentication-Results: phobos.denx.de; spf=fail smtp.mailfrom=sughosh.ganu@linaro.org Received: from usa-sjc-imap-foss1.foss.arm.com (unknown [10.121.207.14]) by usa-sjc-mx-foss1.foss.arm.com (Postfix) with ESMTP id 5001A1FB; Wed, 19 Jan 2022 10:56:32 -0800 (PST) Received: from a076522.blr.arm.com (a076522.blr.arm.com [10.162.16.44]) by usa-sjc-imap-foss1.foss.arm.com (Postfix) with ESMTPSA id 6E41D3F73D; Wed, 19 Jan 2022 10:56:27 -0800 (PST) From: Sughosh Ganu To: u-boot@lists.denx.de Cc: Masami Hiramatsu , Patrick Delaunay , Patrice Chotard , Heinrich Schuchardt , Alexander Graf , AKASHI Takahiro , Simon Glass , Bin Meng , Ilias Apalodimas , Jose Marinho , Grant Likely , Tom Rini , Etienne Carriere Subject: [RFC PATCH v3 0/9] FWU: Add support for FWU Multi Bank Update feature Date: Thu, 20 Jan 2022 00:25:39 +0530 Message-Id: <20220119185548.16730-1-sughosh.ganu@linaro.org> X-Mailer: git-send-email 2.17.1 X-BeenThere: u-boot@lists.denx.de X-Mailman-Version: 2.1.39 Precedence: list List-Id: U-Boot discussion List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: u-boot-bounces@lists.denx.de Sender: "U-Boot" X-Virus-Scanned: clamav-milter 0.103.2 at phobos.denx.de X-Virus-Status: Clean The patchset adds support for the FWU Multi Bank Update[1] feature. Certain aspects of the Dependable Boot[2] specification have also been implemented. The FWU multi bank update feature is used for supporting multiple sets(also called banks) of firmware image(s), allowing the platform to boot from a different bank, in case it fails to boot from the active bank. This functionality is supported by keeping the relevant information in a structure called metadata, which provides information on the images. Among other parameters, the metadata structure contains information on the currect active bank that is being used to boot image(s). Functionality is being added to work with the UEFI capsule driver in u-boot. The metadata is read to gather information on the update bank, which is the bank to which the firmware images would be flashed to. On a successful completion of the update of all components, the active bank field in the metadata is updated, to reflect the bank from which the platform will boot on the subsequent boots. Currently, the feature is being enabled on the STM32MP157C-DK2 board which boots a FIP image from a uSD card partitioned with the GPT partioning scheme. This also requires changes in the previous stage of bootloader, which parses the metadata and selects the bank to boot the image(s) from. Support is being added in tf-a(BL2 stage) for the STM32MP157C-DK2 board to boot the active bank images. These changes are under review currently[3]. These patches are based on top of the series from Takahiro to add Authentication support to mkeficapsule utility[4] [1] - https://developer.arm.com/documentation/den0118/a [2] - https://staging-git.codelinaro.org/linaro/firmware-dual-banked-updates/test [3] - https://review.trustedfirmware.org/c/TF-A/trusted-firmware-a/+/12566 [4] - https://patchwork.ozlabs.org/project/uboot/list/?series=281549 Changes since V2: * Use uint*_t types in fwu_mdata.h since the file is to be reused in other projects * Keep only the FWU metadata structures in fwu_mdata.h * Move all other function and macro declarations in fwu.h * Keep common implementations of fwu_update_active_index and fwu_revert_boot_index in fwu_mdata.c * Add a update_mdata function pointer in the fwu_mdata_ops structure * Move the function definition of fwu_verify_mdata to fwu_mdata.c to facilitate reuse * Remove the block device specific desc->devnum parameter for the fwu_plat_get_alt_num function call * Change the implementation of fwu_plat_get_alt_num to get the devnum in the function before calling gpt_plat_get_alt_num * Add logic to delete the TrialStateCtr variable if system is not in Trial State * Add logic to check if bit 15(OS Acceptance) of the Flags member in the capsule header is set * Add logic to set the accept bit of all images from a capsule if the OS Acceptance bit in the capsule header is not set * Include the log.h and stdio.h header files Sughosh Ganu (9): FWU: Add FWU metadata structure and functions for accessing metadata FWU: Add FWU metadata access functions for GPT partitioned block devices FWU: stm32mp1: Add helper functions for accessing FWU metadata FWU: STM32MP1: Add support to read boot index from backup register EFI: FMP: Add provision to update image's ImageTypeId in image descriptor FWU: Add boot time checks as highlighted by the FWU specification FWU: Add support for FWU Multi Bank Update feature FWU: cmd: Add a command to read FWU metadata mkeficapsule: Add support for generating empty capsules board/st/stm32mp1/stm32mp1.c | 183 ++++++++++ cmd/Kconfig | 7 + cmd/Makefile | 1 + cmd/fwu_mdata.c | 67 ++++ common/board_r.c | 6 + include/fwu.h | 81 +++++ include/fwu_mdata.h | 69 ++++ lib/Kconfig | 6 + lib/Makefile | 1 + lib/efi_loader/efi_capsule.c | 233 ++++++++++++- lib/efi_loader/efi_firmware.c | 90 ++++- lib/efi_loader/efi_setup.c | 3 +- lib/fwu_updates/Kconfig | 31 ++ lib/fwu_updates/Makefile | 11 + lib/fwu_updates/fwu.c | 198 +++++++++++ lib/fwu_updates/fwu_mdata.c | 358 +++++++++++++++++++ lib/fwu_updates/fwu_mdata_gpt_blk.c | 521 ++++++++++++++++++++++++++++ tools/eficapsule.h | 8 + tools/mkeficapsule.c | 102 +++++- 19 files changed, 1955 insertions(+), 21 deletions(-) create mode 100644 cmd/fwu_mdata.c create mode 100644 include/fwu.h create mode 100644 include/fwu_mdata.h create mode 100644 lib/fwu_updates/Kconfig create mode 100644 lib/fwu_updates/Makefile create mode 100644 lib/fwu_updates/fwu.c create mode 100644 lib/fwu_updates/fwu_mdata.c create mode 100644 lib/fwu_updates/fwu_mdata_gpt_blk.c