blob: 93b54bf8d7936862693d56d5b75343575f3e6293 [file] [log] [blame]
Tom Rini10e47792018-05-06 17:58:06 -04001// SPDX-License-Identifier: GPL-2.0+
Sebastian Siewior686d6672014-05-05 15:08:09 -05002/*
3 * Copyright (c) 2011 Sebastian Andrzej Siewior <bigeasy@linutronix.de>
Sebastian Siewior686d6672014-05-05 15:08:09 -05004 */
5
Simon Glass5e6201b2019-08-01 09:46:51 -06006#include <env.h>
Sebastian Siewior686d6672014-05-05 15:08:09 -05007#include <image.h>
Sam Protsenko4fabf402020-01-24 17:53:40 +02008#include <image-android-dt.h>
Sebastian Siewior686d6672014-05-05 15:08:09 -05009#include <android_image.h>
Ahmad Draidi9a1cb5d2014-10-23 20:50:07 +030010#include <malloc.h>
11#include <errno.h>
Eugeniu Rosca1403f392019-04-08 17:35:27 +020012#include <asm/unaligned.h>
Sam Protsenko4fabf402020-01-24 17:53:40 +020013#include <mapmem.h>
Simon Glass3ba929a2020-10-30 21:38:53 -060014#include <linux/libfdt.h>
Sebastian Siewior686d6672014-05-05 15:08:09 -050015
Maxime Ripard17ef1f52015-04-24 12:53:12 +020016#define ANDROID_IMAGE_DEFAULT_KERNEL_ADDR 0x10008000
Neil Armstrong04ba5572024-10-17 16:44:44 +020017#define ANDROID_IMAGE_DEFAULT_RAMDISK_ADDR 0x11000000
Maxime Ripard17ef1f52015-04-24 12:53:12 +020018
Sebastian Siewior686d6672014-05-05 15:08:09 -050019static char andr_tmp_str[ANDR_BOOT_ARGS_SIZE + 1];
20
Safae Ouajih313cc842023-02-06 00:50:18 +010021static ulong checksum(const unsigned char *buffer, ulong size)
22{
23 ulong sum = 0;
24
25 for (ulong i = 0; i < size; i++)
26 sum += buffer[i];
27 return sum;
28}
29
30static bool is_trailer_present(ulong bootconfig_end_addr)
31{
32 return !strncmp((char *)(bootconfig_end_addr - BOOTCONFIG_MAGIC_SIZE),
33 BOOTCONFIG_MAGIC, BOOTCONFIG_MAGIC_SIZE);
34}
35
36static ulong add_trailer(ulong bootconfig_start_addr, ulong bootconfig_size)
37{
38 ulong end;
39 ulong sum;
40
41 if (!bootconfig_start_addr)
42 return -1;
43 if (!bootconfig_size)
44 return 0;
45
46 end = bootconfig_start_addr + bootconfig_size;
47 if (is_trailer_present(end))
48 return 0;
49
50 memcpy((void *)(end), &bootconfig_size, BOOTCONFIG_SIZE_SIZE);
51 sum = checksum((unsigned char *)bootconfig_start_addr, bootconfig_size);
52 memcpy((void *)(end + BOOTCONFIG_SIZE_SIZE), &sum,
53 BOOTCONFIG_CHECKSUM_SIZE);
54 memcpy((void *)(end + BOOTCONFIG_SIZE_SIZE + BOOTCONFIG_CHECKSUM_SIZE),
55 BOOTCONFIG_MAGIC, BOOTCONFIG_MAGIC_SIZE);
56
57 return BOOTCONFIG_TRAILER_SIZE;
58}
59
Mattijs Korpershoek2b5c70a2024-07-10 10:40:02 +020060__weak ulong get_avendor_bootimg_addr(void)
61{
62 return -1;
63}
64
Safae Ouajih889005f2023-02-06 00:50:12 +010065static void android_boot_image_v3_v4_parse_hdr(const struct andr_boot_img_hdr_v3 *hdr,
66 struct andr_image_data *data)
67{
68 ulong end;
69
70 data->kcmdline = hdr->cmdline;
71 data->header_version = hdr->header_version;
72
73 /*
74 * The header takes a full page, the remaining components are aligned
75 * on page boundary.
76 */
77 end = (ulong)hdr;
78 end += ANDR_GKI_PAGE_SIZE;
79 data->kernel_ptr = end;
80 data->kernel_size = hdr->kernel_size;
81 end += ALIGN(hdr->kernel_size, ANDR_GKI_PAGE_SIZE);
Roman Stratiienko227b4fa2024-05-19 13:09:51 +000082 data->ramdisk_ptr = end;
Safae Ouajih889005f2023-02-06 00:50:12 +010083 data->ramdisk_size = hdr->ramdisk_size;
84 data->boot_ramdisk_size = hdr->ramdisk_size;
85 end += ALIGN(hdr->ramdisk_size, ANDR_GKI_PAGE_SIZE);
86
87 if (hdr->header_version > 3)
88 end += ALIGN(hdr->signature_size, ANDR_GKI_PAGE_SIZE);
89
90 data->boot_img_total_size = end - (ulong)hdr;
91}
92
93static void android_vendor_boot_image_v3_v4_parse_hdr(const struct andr_vnd_boot_img_hdr
94 *hdr, struct andr_image_data *data)
95{
96 ulong end;
97
98 /*
99 * The header takes a full page, the remaining components are aligned
100 * on page boundary.
101 */
Safae Ouajih6665296e2023-02-06 00:50:14 +0100102 data->kcmdline_extra = hdr->cmdline;
Safae Ouajih889005f2023-02-06 00:50:12 +0100103 data->tags_addr = hdr->tags_addr;
104 data->image_name = hdr->name;
105 data->kernel_addr = hdr->kernel_addr;
106 data->ramdisk_addr = hdr->ramdisk_addr;
107 data->dtb_load_addr = hdr->dtb_addr;
Safae Ouajih313cc842023-02-06 00:50:18 +0100108 data->bootconfig_size = hdr->bootconfig_size;
Safae Ouajih889005f2023-02-06 00:50:12 +0100109 end = (ulong)hdr;
110 end += hdr->page_size;
111 if (hdr->vendor_ramdisk_size) {
112 data->vendor_ramdisk_ptr = end;
113 data->vendor_ramdisk_size = hdr->vendor_ramdisk_size;
114 data->ramdisk_size += hdr->vendor_ramdisk_size;
115 end += ALIGN(hdr->vendor_ramdisk_size, hdr->page_size);
116 }
117
118 data->dtb_ptr = end;
119 data->dtb_size = hdr->dtb_size;
120
121 end += ALIGN(hdr->dtb_size, hdr->page_size);
122 end += ALIGN(hdr->vendor_ramdisk_table_size, hdr->page_size);
Safae Ouajih313cc842023-02-06 00:50:18 +0100123 data->bootconfig_addr = end;
124 if (hdr->bootconfig_size) {
125 data->bootconfig_size += add_trailer(data->bootconfig_addr,
126 data->bootconfig_size);
127 data->ramdisk_size += data->bootconfig_size;
128 }
129 end += ALIGN(data->bootconfig_size, hdr->page_size);
Safae Ouajih889005f2023-02-06 00:50:12 +0100130 data->vendor_boot_img_total_size = end - (ulong)hdr;
131}
132
Safae Ouajih027191d2023-02-06 00:50:07 +0100133static void android_boot_image_v0_v1_v2_parse_hdr(const struct andr_boot_img_hdr_v0 *hdr,
134 struct andr_image_data *data)
135{
136 ulong end;
137
138 data->image_name = hdr->name;
139 data->kcmdline = hdr->cmdline;
140 data->kernel_addr = hdr->kernel_addr;
141 data->ramdisk_addr = hdr->ramdisk_addr;
142 data->header_version = hdr->header_version;
143 data->dtb_load_addr = hdr->dtb_addr;
144
145 end = (ulong)hdr;
146
147 /*
148 * The header takes a full page, the remaining components are aligned
149 * on page boundary
150 */
151
152 end += hdr->page_size;
153
154 data->kernel_ptr = end;
155 data->kernel_size = hdr->kernel_size;
156 end += ALIGN(hdr->kernel_size, hdr->page_size);
157
158 data->ramdisk_ptr = end;
159 data->ramdisk_size = hdr->ramdisk_size;
160 end += ALIGN(hdr->ramdisk_size, hdr->page_size);
161
162 data->second_ptr = end;
163 data->second_size = hdr->second_size;
164 end += ALIGN(hdr->second_size, hdr->page_size);
165
166 if (hdr->header_version >= 1) {
167 data->recovery_dtbo_ptr = end;
168 data->recovery_dtbo_size = hdr->recovery_dtbo_size;
169 end += ALIGN(hdr->recovery_dtbo_size, hdr->page_size);
170 }
171
172 if (hdr->header_version >= 2) {
173 data->dtb_ptr = end;
174 data->dtb_size = hdr->dtb_size;
175 end += ALIGN(hdr->dtb_size, hdr->page_size);
176 }
177
178 data->boot_img_total_size = end - (ulong)hdr;
179}
180
Julien Massonb238dee2024-11-21 11:59:55 +0100181bool android_image_get_bootimg_size(const void *hdr, u32 *boot_img_size)
182{
183 struct andr_image_data data;
184
185 if (!hdr || !boot_img_size) {
186 printf("hdr or boot_img_size can't be NULL\n");
187 return false;
188 }
189
190 if (!is_android_boot_image_header(hdr)) {
191 printf("Incorrect boot image header\n");
192 return false;
193 }
194
195 if (((struct andr_boot_img_hdr_v0 *)hdr)->header_version <= 2)
196 android_boot_image_v0_v1_v2_parse_hdr(hdr, &data);
197 else
198 android_boot_image_v3_v4_parse_hdr(hdr, &data);
199
200 *boot_img_size = data.boot_img_total_size;
201
202 return true;
203}
204
205bool android_image_get_vendor_bootimg_size(const void *hdr, u32 *vendor_boot_img_size)
206{
207 struct andr_image_data data;
208
209 if (!hdr || !vendor_boot_img_size) {
210 printf("hdr or vendor_boot_img_size can't be NULL\n");
211 return false;
212 }
213
214 if (!is_android_vendor_boot_image_header(hdr)) {
215 printf("Incorrect vendor boot image header\n");
216 return false;
217 }
218
219 android_vendor_boot_image_v3_v4_parse_hdr(hdr, &data);
220
221 *vendor_boot_img_size = data.vendor_boot_img_total_size;
222
223 return true;
224}
225
Safae Ouajihc60ae102023-02-06 00:50:11 +0100226bool android_image_get_data(const void *boot_hdr, const void *vendor_boot_hdr,
227 struct andr_image_data *data)
Safae Ouajih027191d2023-02-06 00:50:07 +0100228{
229 if (!boot_hdr || !data) {
230 printf("boot_hdr or data params can't be NULL\n");
231 return false;
232 }
233
234 if (!is_android_boot_image_header(boot_hdr)) {
235 printf("Incorrect boot image header\n");
236 return false;
237 }
238
Safae Ouajih889005f2023-02-06 00:50:12 +0100239 if (((struct andr_boot_img_hdr_v0 *)boot_hdr)->header_version > 2) {
240 if (!vendor_boot_hdr) {
241 printf("For boot header v3+ vendor boot image has to be provided\n");
242 return false;
243 }
244 if (!is_android_vendor_boot_image_header(vendor_boot_hdr)) {
245 printf("Incorrect vendor boot image header\n");
246 return false;
247 }
248 android_boot_image_v3_v4_parse_hdr(boot_hdr, data);
249 android_vendor_boot_image_v3_v4_parse_hdr(vendor_boot_hdr, data);
250 } else {
Safae Ouajih027191d2023-02-06 00:50:07 +0100251 android_boot_image_v0_v1_v2_parse_hdr(boot_hdr, data);
Safae Ouajih889005f2023-02-06 00:50:12 +0100252 }
Safae Ouajih027191d2023-02-06 00:50:07 +0100253
254 return true;
255}
256
Neil Armstrong7cb867d2024-10-17 16:44:43 +0200257static ulong android_image_get_kernel_addr(struct andr_image_data *img_data,
258 ulong comp)
Maxime Ripard17ef1f52015-04-24 12:53:12 +0200259{
260 /*
261 * All the Android tools that generate a boot.img use this
262 * address as the default.
263 *
264 * Even though it doesn't really make a lot of sense, and it
265 * might be valid on some platforms, we treat that adress as
266 * the default value for this field, and try to execute the
267 * kernel in place in such a case.
268 *
269 * Otherwise, we will return the actual value set by the user.
270 */
Neil Armstrong7cb867d2024-10-17 16:44:43 +0200271 if (img_data->kernel_addr == ANDROID_IMAGE_DEFAULT_KERNEL_ADDR) {
272 if (comp == IH_COMP_NONE)
273 return img_data->kernel_ptr;
274 return env_get_ulong("kernel_addr_r", 16, 0);
275 }
Maxime Ripard17ef1f52015-04-24 12:53:12 +0200276
Christian Gmeiner3fabf862020-05-29 17:53:45 +0200277 /*
278 * abootimg creates images where all load addresses are 0
279 * and we need to fix them.
280 */
Safae Ouajihbced1042023-02-06 00:50:08 +0100281 if (img_data->kernel_addr == 0 && img_data->ramdisk_addr == 0)
Christian Gmeiner3fabf862020-05-29 17:53:45 +0200282 return env_get_ulong("kernel_addr_r", 16, 0);
283
Safae Ouajihbced1042023-02-06 00:50:08 +0100284 return img_data->kernel_addr;
Maxime Ripard17ef1f52015-04-24 12:53:12 +0200285}
286
Ahmad Draidi9a1cb5d2014-10-23 20:50:07 +0300287/**
288 * android_image_get_kernel() - processes kernel part of Android boot images
Safae Ouajihc60ae102023-02-06 00:50:11 +0100289 * @hdr: Pointer to boot image header, which is at the start
Ahmad Draidi9a1cb5d2014-10-23 20:50:07 +0300290 * of the image.
Safae Ouajihc60ae102023-02-06 00:50:11 +0100291 * @vendor_boot_img: Pointer to vendor boot image header, which is at the
292 * start of the image.
Ahmad Draidi9a1cb5d2014-10-23 20:50:07 +0300293 * @verify: Checksum verification flag. Currently unimplemented.
294 * @os_data: Pointer to a ulong variable, will hold os data start
295 * address.
296 * @os_len: Pointer to a ulong variable, will hold os data length.
297 *
298 * This function returns the os image's start address and length. Also,
299 * it appends the kernel command line to the bootargs env variable.
300 *
301 * Return: Zero, os start address and length on success,
302 * otherwise on failure.
303 */
Safae Ouajih51c981b2023-02-06 00:50:17 +0100304int android_image_get_kernel(const void *hdr,
Safae Ouajihc60ae102023-02-06 00:50:11 +0100305 const void *vendor_boot_img, int verify,
Sebastian Siewior686d6672014-05-05 15:08:09 -0500306 ulong *os_data, ulong *os_len)
307{
Safae Ouajihbced1042023-02-06 00:50:08 +0100308 struct andr_image_data img_data = {0};
Neil Armstrongfd0318b2024-10-17 16:44:42 +0200309 ulong kernel_addr;
Safae Ouajihbced1042023-02-06 00:50:08 +0100310 const struct legacy_img_hdr *ihdr;
Neil Armstrong7cb867d2024-10-17 16:44:43 +0200311 ulong comp;
Safae Ouajihbced1042023-02-06 00:50:08 +0100312
Safae Ouajihc60ae102023-02-06 00:50:11 +0100313 if (!android_image_get_data(hdr, vendor_boot_img, &img_data))
Safae Ouajihbced1042023-02-06 00:50:08 +0100314 return -EINVAL;
315
Neil Armstrong7cb867d2024-10-17 16:44:43 +0200316 comp = android_image_get_kcomp(hdr, vendor_boot_img);
317
318 kernel_addr = android_image_get_kernel_addr(&img_data, comp);
Safae Ouajihbced1042023-02-06 00:50:08 +0100319 ihdr = (const struct legacy_img_hdr *)img_data.kernel_ptr;
Maxime Ripard17ef1f52015-04-24 12:53:12 +0200320
Sebastian Siewior686d6672014-05-05 15:08:09 -0500321 /*
322 * Not all Android tools use the id field for signing the image with
323 * sha1 (or anything) so we don't check it. It is not obvious that the
324 * string is null terminated so we take care of this.
325 */
Safae Ouajihbced1042023-02-06 00:50:08 +0100326 strlcpy(andr_tmp_str, img_data.image_name, ANDR_BOOT_NAME_SIZE);
Sebastian Siewior686d6672014-05-05 15:08:09 -0500327 andr_tmp_str[ANDR_BOOT_NAME_SIZE] = '\0';
328 if (strlen(andr_tmp_str))
329 printf("Android's image name: %s\n", andr_tmp_str);
330
Neil Armstrongfd0318b2024-10-17 16:44:42 +0200331 printf("Kernel load addr 0x%08lx size %u KiB\n",
Safae Ouajihbced1042023-02-06 00:50:08 +0100332 kernel_addr, DIV_ROUND_UP(img_data.kernel_size, 1024));
Ahmad Draidi9a1cb5d2014-10-23 20:50:07 +0300333
334 int len = 0;
Safae Ouajihbced1042023-02-06 00:50:08 +0100335 if (*img_data.kcmdline) {
336 printf("Kernel command line: %s\n", img_data.kcmdline);
337 len += strlen(img_data.kcmdline);
Sebastian Siewior686d6672014-05-05 15:08:09 -0500338 }
Ahmad Draidi9a1cb5d2014-10-23 20:50:07 +0300339
Safae Ouajih6665296e2023-02-06 00:50:14 +0100340 if (img_data.kcmdline_extra) {
341 printf("Kernel extra command line: %s\n", img_data.kcmdline_extra);
342 len += strlen(img_data.kcmdline_extra);
343 }
344
Simon Glass64b723f2017-08-03 12:22:12 -0600345 char *bootargs = env_get("bootargs");
Ahmad Draidi9a1cb5d2014-10-23 20:50:07 +0300346 if (bootargs)
347 len += strlen(bootargs);
348
349 char *newbootargs = malloc(len + 2);
350 if (!newbootargs) {
351 puts("Error: malloc in android_image_get_kernel failed!\n");
352 return -ENOMEM;
353 }
354 *newbootargs = '\0';
355
356 if (bootargs) {
357 strcpy(newbootargs, bootargs);
358 strcat(newbootargs, " ");
359 }
Safae Ouajihbced1042023-02-06 00:50:08 +0100360
361 if (*img_data.kcmdline)
362 strcat(newbootargs, img_data.kcmdline);
Ahmad Draidi9a1cb5d2014-10-23 20:50:07 +0300363
Safae Ouajih6665296e2023-02-06 00:50:14 +0100364 if (img_data.kcmdline_extra) {
365 strcat(newbootargs, " ");
366 strcat(newbootargs, img_data.kcmdline_extra);
367 }
368
Simon Glass6a38e412017-08-03 12:22:09 -0600369 env_set("bootargs", newbootargs);
Sebastian Siewior686d6672014-05-05 15:08:09 -0500370
371 if (os_data) {
Roman Stratiienko73268582019-06-03 15:38:13 +0300372 if (image_get_magic(ihdr) == IH_MAGIC) {
373 *os_data = image_get_data(ihdr);
374 } else {
Safae Ouajihbced1042023-02-06 00:50:08 +0100375 *os_data = img_data.kernel_ptr;
Roman Stratiienko73268582019-06-03 15:38:13 +0300376 }
Sebastian Siewior686d6672014-05-05 15:08:09 -0500377 }
Roman Stratiienko73268582019-06-03 15:38:13 +0300378 if (os_len) {
379 if (image_get_magic(ihdr) == IH_MAGIC)
380 *os_len = image_get_data_size(ihdr);
381 else
Safae Ouajihbced1042023-02-06 00:50:08 +0100382 *os_len = img_data.kernel_size;
Roman Stratiienko73268582019-06-03 15:38:13 +0300383 }
Sebastian Siewior686d6672014-05-05 15:08:09 -0500384 return 0;
385}
386
Safae Ouajih889005f2023-02-06 00:50:12 +0100387bool is_android_vendor_boot_image_header(const void *vendor_boot_img)
388{
389 return !memcmp(VENDOR_BOOT_MAGIC, vendor_boot_img, ANDR_VENDOR_BOOT_MAGIC_SIZE);
390}
391
Safae Ouajih51c981b2023-02-06 00:50:17 +0100392bool is_android_boot_image_header(const void *hdr)
Sebastian Siewior686d6672014-05-05 15:08:09 -0500393{
Safae Ouajih88ad0c12023-02-06 00:50:05 +0100394 return !memcmp(ANDR_BOOT_MAGIC, hdr, ANDR_BOOT_MAGIC_SIZE);
Sebastian Siewior686d6672014-05-05 15:08:09 -0500395}
396
Safae Ouajihc60ae102023-02-06 00:50:11 +0100397ulong android_image_get_end(const struct andr_boot_img_hdr_v0 *hdr,
398 const void *vendor_boot_img)
Sebastian Siewior686d6672014-05-05 15:08:09 -0500399{
Safae Ouajihbced1042023-02-06 00:50:08 +0100400 struct andr_image_data img_data;
Sebastian Siewior686d6672014-05-05 15:08:09 -0500401
Safae Ouajihc60ae102023-02-06 00:50:11 +0100402 if (!android_image_get_data(hdr, vendor_boot_img, &img_data))
Safae Ouajihbced1042023-02-06 00:50:08 +0100403 return -EINVAL;
Sam Protsenko9e4982c2019-08-15 20:25:07 +0300404
Safae Ouajihbced1042023-02-06 00:50:08 +0100405 if (img_data.header_version > 2)
406 return 0;
Sam Protsenko9e4982c2019-08-15 20:25:07 +0300407
Safae Ouajihbced1042023-02-06 00:50:08 +0100408 return img_data.boot_img_total_size;
Sebastian Siewior686d6672014-05-05 15:08:09 -0500409}
410
Safae Ouajih51c981b2023-02-06 00:50:17 +0100411ulong android_image_get_kload(const void *hdr,
Safae Ouajihc60ae102023-02-06 00:50:11 +0100412 const void *vendor_boot_img)
Sebastian Siewior686d6672014-05-05 15:08:09 -0500413{
Safae Ouajihbced1042023-02-06 00:50:08 +0100414 struct andr_image_data img_data;
Neil Armstrong7cb867d2024-10-17 16:44:43 +0200415 ulong comp;
Safae Ouajihbced1042023-02-06 00:50:08 +0100416
Safae Ouajihc60ae102023-02-06 00:50:11 +0100417 if (!android_image_get_data(hdr, vendor_boot_img, &img_data))
Safae Ouajihbced1042023-02-06 00:50:08 +0100418 return -EINVAL;
419
Neil Armstrong7cb867d2024-10-17 16:44:43 +0200420 comp = android_image_get_kcomp(hdr, vendor_boot_img);
421
422 return android_image_get_kernel_addr(&img_data, comp);
Sebastian Siewior686d6672014-05-05 15:08:09 -0500423}
424
Safae Ouajih51c981b2023-02-06 00:50:17 +0100425ulong android_image_get_kcomp(const void *hdr,
Safae Ouajihc60ae102023-02-06 00:50:11 +0100426 const void *vendor_boot_img)
Eugeniu Rosca1403f392019-04-08 17:35:27 +0200427{
Safae Ouajih027191d2023-02-06 00:50:07 +0100428 struct andr_image_data img_data;
429 const void *p;
430
Safae Ouajihc60ae102023-02-06 00:50:11 +0100431 if (!android_image_get_data(hdr, vendor_boot_img, &img_data))
Safae Ouajih027191d2023-02-06 00:50:07 +0100432 return -EINVAL;
Eugeniu Rosca1403f392019-04-08 17:35:27 +0200433
Safae Ouajih027191d2023-02-06 00:50:07 +0100434 p = (const void *)img_data.kernel_ptr;
Simon Glassbb7d3bb2022-09-06 20:26:52 -0600435 if (image_get_magic((struct legacy_img_hdr *)p) == IH_MAGIC)
436 return image_get_comp((struct legacy_img_hdr *)p);
Roman Stratiienko73268582019-06-03 15:38:13 +0300437 else if (get_unaligned_le32(p) == LZ4F_MAGIC)
Eugeniu Rosca1403f392019-04-08 17:35:27 +0200438 return IH_COMP_LZ4;
439 else
Stephan Gerhold9e5111d2021-07-01 20:33:16 +0200440 return image_decomp_type(p, sizeof(u32));
Eugeniu Rosca1403f392019-04-08 17:35:27 +0200441}
442
Safae Ouajih5b01a882023-02-06 00:50:13 +0100443int android_image_get_ramdisk(const void *hdr, const void *vendor_boot_img,
444 ulong *rd_data, ulong *rd_len)
Sebastian Siewior686d6672014-05-05 15:08:09 -0500445{
Safae Ouajihbced1042023-02-06 00:50:08 +0100446 struct andr_image_data img_data = {0};
Safae Ouajih5b01a882023-02-06 00:50:13 +0100447 ulong ramdisk_ptr;
Safae Ouajihbced1042023-02-06 00:50:08 +0100448
Safae Ouajihc60ae102023-02-06 00:50:11 +0100449 if (!android_image_get_data(hdr, vendor_boot_img, &img_data))
Safae Ouajihbced1042023-02-06 00:50:08 +0100450 return -EINVAL;
451
Michael Walle955415b2024-07-29 23:36:57 +0200452 if (!img_data.ramdisk_size)
453 return -ENOENT;
Neil Armstrong04ba5572024-10-17 16:44:44 +0200454 /*
455 * Android tools can generate a boot.img with default load address
456 * or 0, even though it doesn't really make a lot of sense, and it
457 * might be valid on some platforms, we treat that address as
458 * the default value for this field, and try to pass ramdisk
459 * in place if possible.
460 */
Safae Ouajih5b01a882023-02-06 00:50:13 +0100461 if (img_data.header_version > 2) {
Neil Armstrong04ba5572024-10-17 16:44:44 +0200462 /* Ramdisk can't be used in-place, copy it to ramdisk_addr_r */
463 if (img_data.ramdisk_addr == ANDROID_IMAGE_DEFAULT_RAMDISK_ADDR) {
464 ramdisk_ptr = env_get_ulong("ramdisk_addr_r", 16, 0);
465 if (!ramdisk_ptr) {
466 printf("Invalid ramdisk_addr_r to copy ramdisk into\n");
467 return -EINVAL;
468 }
469 } else {
470 ramdisk_ptr = img_data.ramdisk_addr;
471 }
472 *rd_data = ramdisk_ptr;
Safae Ouajih5b01a882023-02-06 00:50:13 +0100473 memcpy((void *)(ramdisk_ptr), (void *)img_data.vendor_ramdisk_ptr,
474 img_data.vendor_ramdisk_size);
Roman Stratiienko227b4fa2024-05-19 13:09:51 +0000475 ramdisk_ptr += img_data.vendor_ramdisk_size;
476 memcpy((void *)(ramdisk_ptr), (void *)img_data.ramdisk_ptr,
Safae Ouajih313cc842023-02-06 00:50:18 +0100477 img_data.boot_ramdisk_size);
Roman Stratiienko227b4fa2024-05-19 13:09:51 +0000478 ramdisk_ptr += img_data.boot_ramdisk_size;
Safae Ouajih313cc842023-02-06 00:50:18 +0100479 if (img_data.bootconfig_size) {
480 memcpy((void *)
Roman Stratiienko227b4fa2024-05-19 13:09:51 +0000481 (ramdisk_ptr), (void *)img_data.bootconfig_addr,
Safae Ouajih313cc842023-02-06 00:50:18 +0100482 img_data.bootconfig_size);
483 }
Mattijs Korpershoek91359972024-10-03 14:42:39 +0200484 } else {
Neil Armstrong04ba5572024-10-17 16:44:44 +0200485 /* Ramdisk can be used in-place, use current ptr */
486 if (img_data.ramdisk_addr == 0 ||
487 img_data.ramdisk_addr == ANDROID_IMAGE_DEFAULT_RAMDISK_ADDR) {
488 *rd_data = img_data.ramdisk_ptr;
489 } else {
490 ramdisk_ptr = img_data.ramdisk_addr;
491 *rd_data = ramdisk_ptr;
492 memcpy((void *)(ramdisk_ptr), (void *)img_data.ramdisk_ptr,
493 img_data.ramdisk_size);
494 }
Safae Ouajih5b01a882023-02-06 00:50:13 +0100495 }
Ahmad Draidi9a1cb5d2014-10-23 20:50:07 +0300496
Safae Ouajihbced1042023-02-06 00:50:08 +0100497 printf("RAM disk load addr 0x%08lx size %u KiB\n",
Neil Armstrong04ba5572024-10-17 16:44:44 +0200498 *rd_data, DIV_ROUND_UP(img_data.ramdisk_size, 1024));
Sebastian Siewior686d6672014-05-05 15:08:09 -0500499
Safae Ouajihbced1042023-02-06 00:50:08 +0100500 *rd_len = img_data.ramdisk_size;
Sebastian Siewior686d6672014-05-05 15:08:09 -0500501 return 0;
502}
Michael Trimarchi44af20b2016-06-10 19:54:37 +0200503
Safae Ouajih51c981b2023-02-06 00:50:17 +0100504int android_image_get_second(const void *hdr, ulong *second_data, ulong *second_len)
Bin Chen909f1402018-01-27 16:59:08 +1100505{
Safae Ouajihbced1042023-02-06 00:50:08 +0100506 struct andr_image_data img_data;
507
Safae Ouajihc60ae102023-02-06 00:50:11 +0100508 if (!android_image_get_data(hdr, NULL, &img_data))
Safae Ouajihbced1042023-02-06 00:50:08 +0100509 return -EINVAL;
510
Safae Ouajih51c981b2023-02-06 00:50:17 +0100511 if (img_data.header_version > 2) {
512 printf("Second stage bootloader is only supported for boot image version <= 2\n");
513 return -EOPNOTSUPP;
514 }
515
Safae Ouajihbced1042023-02-06 00:50:08 +0100516 if (!img_data.second_size) {
Bin Chen909f1402018-01-27 16:59:08 +1100517 *second_data = *second_len = 0;
518 return -1;
519 }
520
Safae Ouajihbced1042023-02-06 00:50:08 +0100521 *second_data = img_data.second_ptr;
Bin Chen909f1402018-01-27 16:59:08 +1100522
523 printf("second address is 0x%lx\n",*second_data);
524
Safae Ouajihbced1042023-02-06 00:50:08 +0100525 *second_len = img_data.second_size;
Bin Chen909f1402018-01-27 16:59:08 +1100526 return 0;
527}
528
Sam Protsenko4fabf402020-01-24 17:53:40 +0200529/**
Sam Protsenko2666a1a2020-01-24 17:53:41 +0200530 * android_image_get_dtbo() - Get address and size of recovery DTBO image.
531 * @hdr_addr: Boot image header address
532 * @addr: If not NULL, will contain address of recovery DTBO image
533 * @size: If not NULL, will contain size of recovery DTBO image
534 *
535 * Get the address and size of DTBO image in "Recovery DTBO" area of Android
536 * Boot Image in RAM. The format of this image is Android DTBO (see
537 * corresponding "DTB/DTBO Partitions" AOSP documentation for details). Once
538 * the address is obtained from this function, one can use 'adtimg' U-Boot
539 * command or android_dt_*() functions to extract desired DTBO blob.
540 *
541 * This DTBO (included in boot image) is only needed for non-A/B devices, and it
542 * only can be found in recovery image. On A/B devices we can always rely on
543 * "dtbo" partition. See "Including DTBO in Recovery for Non-A/B Devices" in
544 * AOSP documentation for details.
545 *
546 * Return: true on success or false on error.
547 */
548bool android_image_get_dtbo(ulong hdr_addr, ulong *addr, u32 *size)
549{
Safae Ouajih8656e382023-02-06 00:50:03 +0100550 const struct andr_boot_img_hdr_v0 *hdr;
Sam Protsenko2666a1a2020-01-24 17:53:41 +0200551 ulong dtbo_img_addr;
552 bool ret = true;
553
554 hdr = map_sysmem(hdr_addr, sizeof(*hdr));
Safae Ouajih88ad0c12023-02-06 00:50:05 +0100555 if (!is_android_boot_image_header(hdr)) {
Sam Protsenko2666a1a2020-01-24 17:53:41 +0200556 printf("Error: Boot Image header is incorrect\n");
557 ret = false;
558 goto exit;
559 }
560
Safae Ouajih8d351582023-02-06 00:50:10 +0100561 if (hdr->header_version != 1 && hdr->header_version != 2) {
562 printf("Error: header version must be >= 1 and <= 2 to get dtbo\n");
Sam Protsenko2666a1a2020-01-24 17:53:41 +0200563 ret = false;
564 goto exit;
565 }
566
567 if (hdr->recovery_dtbo_size == 0) {
568 printf("Error: recovery_dtbo_size is 0\n");
569 ret = false;
570 goto exit;
571 }
572
573 /* Calculate the address of DTB area in boot image */
574 dtbo_img_addr = hdr_addr;
575 dtbo_img_addr += hdr->page_size;
576 dtbo_img_addr += ALIGN(hdr->kernel_size, hdr->page_size);
577 dtbo_img_addr += ALIGN(hdr->ramdisk_size, hdr->page_size);
578 dtbo_img_addr += ALIGN(hdr->second_size, hdr->page_size);
579
580 if (addr)
581 *addr = dtbo_img_addr;
582 if (size)
583 *size = hdr->recovery_dtbo_size;
584
585exit:
586 unmap_sysmem(hdr);
587 return ret;
588}
589
590/**
Sam Protsenko4fabf402020-01-24 17:53:40 +0200591 * android_image_get_dtb_img_addr() - Get the address of DTB area in boot image.
592 * @hdr_addr: Boot image header address
Safae Ouajihc60ae102023-02-06 00:50:11 +0100593 * @vhdr_addr: Vendor Boot image header address
Sam Protsenko4fabf402020-01-24 17:53:40 +0200594 * @addr: Will contain the address of DTB area in boot image
595 *
596 * Return: true on success or false on fail.
597 */
Safae Ouajihc60ae102023-02-06 00:50:11 +0100598static bool android_image_get_dtb_img_addr(ulong hdr_addr, ulong vhdr_addr, ulong *addr)
Sam Protsenko4fabf402020-01-24 17:53:40 +0200599{
Safae Ouajih8656e382023-02-06 00:50:03 +0100600 const struct andr_boot_img_hdr_v0 *hdr;
Safae Ouajih9a5cc7f2023-02-06 00:50:15 +0100601 const struct andr_vnd_boot_img_hdr *v_hdr;
Sam Protsenko4fabf402020-01-24 17:53:40 +0200602 ulong dtb_img_addr;
603 bool ret = true;
604
605 hdr = map_sysmem(hdr_addr, sizeof(*hdr));
Safae Ouajih88ad0c12023-02-06 00:50:05 +0100606 if (!is_android_boot_image_header(hdr)) {
Sam Protsenko4fabf402020-01-24 17:53:40 +0200607 printf("Error: Boot Image header is incorrect\n");
608 ret = false;
609 goto exit;
610 }
611
612 if (hdr->header_version < 2) {
613 printf("Error: header_version must be >= 2 to get dtb\n");
614 ret = false;
615 goto exit;
616 }
617
Safae Ouajih9a5cc7f2023-02-06 00:50:15 +0100618 if (hdr->header_version == 2) {
619 if (!hdr->dtb_size) {
620 printf("Error: dtb_size is 0\n");
621 ret = false;
622 goto exit;
623 }
624 /* Calculate the address of DTB area in boot image */
625 dtb_img_addr = hdr_addr;
626 dtb_img_addr += hdr->page_size;
627 dtb_img_addr += ALIGN(hdr->kernel_size, hdr->page_size);
628 dtb_img_addr += ALIGN(hdr->ramdisk_size, hdr->page_size);
629 dtb_img_addr += ALIGN(hdr->second_size, hdr->page_size);
630 dtb_img_addr += ALIGN(hdr->recovery_dtbo_size, hdr->page_size);
Sam Protsenko4fabf402020-01-24 17:53:40 +0200631
Safae Ouajih9a5cc7f2023-02-06 00:50:15 +0100632 *addr = dtb_img_addr;
633 }
Sam Protsenko4fabf402020-01-24 17:53:40 +0200634
Safae Ouajih9a5cc7f2023-02-06 00:50:15 +0100635 if (hdr->header_version > 2) {
636 v_hdr = map_sysmem(vhdr_addr, sizeof(*v_hdr));
637 if (!v_hdr->dtb_size) {
638 printf("Error: dtb_size is 0\n");
639 ret = false;
640 unmap_sysmem(v_hdr);
641 goto exit;
642 }
643 /* Calculate the address of DTB area in boot image */
644 dtb_img_addr = vhdr_addr;
645 dtb_img_addr += v_hdr->page_size;
646 if (v_hdr->vendor_ramdisk_size)
647 dtb_img_addr += ALIGN(v_hdr->vendor_ramdisk_size, v_hdr->page_size);
648 *addr = dtb_img_addr;
649 unmap_sysmem(v_hdr);
650 goto exit;
651 }
Sam Protsenko4fabf402020-01-24 17:53:40 +0200652exit:
653 unmap_sysmem(hdr);
654 return ret;
655}
656
657/**
658 * android_image_get_dtb_by_index() - Get address and size of blob in DTB area.
659 * @hdr_addr: Boot image header address
Safae Ouajihc60ae102023-02-06 00:50:11 +0100660 * @vendor_boot_img: Pointer to vendor boot image header, which is at the start of the image.
Sam Protsenko4fabf402020-01-24 17:53:40 +0200661 * @index: Index of desired DTB in DTB area (starting from 0)
662 * @addr: If not NULL, will contain address to specified DTB
663 * @size: If not NULL, will contain size of specified DTB
664 *
665 * Get the address and size of DTB blob by its index in DTB area of Android
666 * Boot Image in RAM.
667 *
668 * Return: true on success or false on error.
669 */
Safae Ouajihc60ae102023-02-06 00:50:11 +0100670bool android_image_get_dtb_by_index(ulong hdr_addr, ulong vendor_boot_img,
671 u32 index, ulong *addr, u32 *size)
Sam Protsenko4fabf402020-01-24 17:53:40 +0200672{
Safae Ouajihbced1042023-02-06 00:50:08 +0100673 struct andr_image_data img_data;
Safae Ouajih8656e382023-02-06 00:50:03 +0100674 const struct andr_boot_img_hdr_v0 *hdr;
Safae Ouajihc60ae102023-02-06 00:50:11 +0100675 const struct andr_vnd_boot_img_hdr *vhdr;
Safae Ouajihbced1042023-02-06 00:50:08 +0100676
677 hdr = map_sysmem(hdr_addr, sizeof(*hdr));
Safae Ouajihc60ae102023-02-06 00:50:11 +0100678 if (vendor_boot_img != -1)
679 vhdr = map_sysmem(vendor_boot_img, sizeof(*vhdr));
680 if (!android_image_get_data(hdr, vhdr, &img_data)) {
681 if (vendor_boot_img != -1)
682 unmap_sysmem(vhdr);
Safae Ouajihbced1042023-02-06 00:50:08 +0100683 unmap_sysmem(hdr);
684 return false;
685 }
Safae Ouajihc60ae102023-02-06 00:50:11 +0100686 if (vendor_boot_img != -1)
687 unmap_sysmem(vhdr);
Safae Ouajihbced1042023-02-06 00:50:08 +0100688 unmap_sysmem(hdr);
689
Sam Protsenko4fabf402020-01-24 17:53:40 +0200690 ulong dtb_img_addr; /* address of DTB part in boot image */
691 u32 dtb_img_size; /* size of DTB payload in boot image */
692 ulong dtb_addr; /* address of DTB blob with specified index */
693 u32 i; /* index iterator */
694
Safae Ouajihc60ae102023-02-06 00:50:11 +0100695 android_image_get_dtb_img_addr(hdr_addr, vendor_boot_img, &dtb_img_addr);
Sam Protsenko4fabf402020-01-24 17:53:40 +0200696 /* Check if DTB area of boot image is in DTBO format */
697 if (android_dt_check_header(dtb_img_addr)) {
698 return android_dt_get_fdt_by_index(dtb_img_addr, index, addr,
699 size);
700 }
701
702 /* Find out the address of DTB with specified index in concat blobs */
Safae Ouajihbced1042023-02-06 00:50:08 +0100703 dtb_img_size = img_data.dtb_size;
Sam Protsenko4fabf402020-01-24 17:53:40 +0200704 i = 0;
705 dtb_addr = dtb_img_addr;
706 while (dtb_addr < dtb_img_addr + dtb_img_size) {
707 const struct fdt_header *fdt;
708 u32 dtb_size;
709
710 fdt = map_sysmem(dtb_addr, sizeof(*fdt));
711 if (fdt_check_header(fdt) != 0) {
712 unmap_sysmem(fdt);
713 printf("Error: Invalid FDT header for index %u\n", i);
714 return false;
715 }
716
717 dtb_size = fdt_totalsize(fdt);
718 unmap_sysmem(fdt);
719
720 if (i == index) {
721 if (size)
722 *size = dtb_size;
723 if (addr)
724 *addr = dtb_addr;
725 return true;
726 }
727
728 dtb_addr += dtb_size;
729 ++i;
730 }
731
732 printf("Error: Index is out of bounds (%u/%u)\n", index, i);
733 return false;
734}
735
Simon Glass0e84d962024-09-29 19:49:50 -0600736#if !defined(CONFIG_XPL_BUILD)
Michael Trimarchi44af20b2016-06-10 19:54:37 +0200737/**
738 * android_print_contents - prints out the contents of the Android format image
739 * @hdr: pointer to the Android format image header
740 *
741 * android_print_contents() formats a multi line Android image contents
742 * description.
743 * The routine prints out Android image properties
744 *
745 * returns:
746 * no returned results
747 */
Safae Ouajih8656e382023-02-06 00:50:03 +0100748void android_print_contents(const struct andr_boot_img_hdr_v0 *hdr)
Michael Trimarchi44af20b2016-06-10 19:54:37 +0200749{
Safae Ouajiha148a822023-02-06 00:50:09 +0100750 if (hdr->header_version >= 3) {
751 printf("Content print is not supported for boot image header version > 2");
752 return;
753 }
Michael Trimarchi44af20b2016-06-10 19:54:37 +0200754 const char * const p = IMAGE_INDENT_STRING;
Alex Deymo41f513a2017-04-02 01:49:47 -0700755 /* os_version = ver << 11 | lvl */
756 u32 os_ver = hdr->os_version >> 11;
757 u32 os_lvl = hdr->os_version & ((1U << 11) - 1);
Michael Trimarchi44af20b2016-06-10 19:54:37 +0200758
Sam Protsenko9e4982c2019-08-15 20:25:07 +0300759 printf("%skernel size: %x\n", p, hdr->kernel_size);
760 printf("%skernel address: %x\n", p, hdr->kernel_addr);
761 printf("%sramdisk size: %x\n", p, hdr->ramdisk_size);
762 printf("%sramdisk address: %x\n", p, hdr->ramdisk_addr);
763 printf("%ssecond size: %x\n", p, hdr->second_size);
764 printf("%ssecond address: %x\n", p, hdr->second_addr);
765 printf("%stags address: %x\n", p, hdr->tags_addr);
766 printf("%spage size: %x\n", p, hdr->page_size);
Alex Deymo41f513a2017-04-02 01:49:47 -0700767 /* ver = A << 14 | B << 7 | C (7 bits for each of A, B, C)
768 * lvl = ((Y - 2000) & 127) << 4 | M (7 bits for Y, 4 bits for M) */
Sam Protsenko9e4982c2019-08-15 20:25:07 +0300769 printf("%sos_version: %x (ver: %u.%u.%u, level: %u.%u)\n",
Alex Deymo41f513a2017-04-02 01:49:47 -0700770 p, hdr->os_version,
771 (os_ver >> 7) & 0x7F, (os_ver >> 14) & 0x7F, os_ver & 0x7F,
772 (os_lvl >> 4) + 2000, os_lvl & 0x0F);
Sam Protsenko9e4982c2019-08-15 20:25:07 +0300773 printf("%sname: %s\n", p, hdr->name);
774 printf("%scmdline: %s\n", p, hdr->cmdline);
775 printf("%sheader_version: %d\n", p, hdr->header_version);
776
777 if (hdr->header_version >= 1) {
778 printf("%srecovery dtbo size: %x\n", p,
779 hdr->recovery_dtbo_size);
780 printf("%srecovery dtbo offset: %llx\n", p,
781 hdr->recovery_dtbo_offset);
782 printf("%sheader size: %x\n", p,
783 hdr->header_size);
784 }
785
Safae Ouajiha148a822023-02-06 00:50:09 +0100786 if (hdr->header_version == 2) {
Sam Protsenko9e4982c2019-08-15 20:25:07 +0300787 printf("%sdtb size: %x\n", p, hdr->dtb_size);
788 printf("%sdtb addr: %llx\n", p, hdr->dtb_addr);
789 }
Sam Protsenko4fabf402020-01-24 17:53:40 +0200790}
791
792/**
793 * android_image_print_dtb_info - Print info for one DTB blob in DTB area.
794 * @fdt: DTB header
795 * @index: Number of DTB blob in DTB area.
796 *
797 * Return: true on success or false on error.
798 */
799static bool android_image_print_dtb_info(const struct fdt_header *fdt,
800 u32 index)
801{
802 int root_node_off;
803 u32 fdt_size;
804 const char *model;
805 const char *compatible;
806
807 root_node_off = fdt_path_offset(fdt, "/");
808 if (root_node_off < 0) {
809 printf("Error: Root node not found\n");
810 return false;
811 }
812
813 fdt_size = fdt_totalsize(fdt);
814 compatible = fdt_getprop(fdt, root_node_off, "compatible",
815 NULL);
816 model = fdt_getprop(fdt, root_node_off, "model", NULL);
817
818 printf(" - DTB #%u:\n", index);
819 printf(" (DTB)size = %d\n", fdt_size);
820 printf(" (DTB)model = %s\n", model ? model : "(unknown)");
821 printf(" (DTB)compatible = %s\n",
822 compatible ? compatible : "(unknown)");
823
824 return true;
825}
826
827/**
828 * android_image_print_dtb_contents() - Print info for DTB blobs in DTB area.
829 * @hdr_addr: Boot image header address
830 *
831 * DTB payload in Android Boot Image v2+ can be in one of following formats:
832 * 1. Concatenated DTB blobs
833 * 2. Android DTBO format (see CONFIG_CMD_ADTIMG for details)
834 *
835 * This function does next:
836 * 1. Prints out the format used in DTB area
837 * 2. Iterates over all DTB blobs in DTB area and prints out the info for
838 * each blob.
839 *
840 * Return: true on success or false on error.
841 */
842bool android_image_print_dtb_contents(ulong hdr_addr)
843{
Safae Ouajih8656e382023-02-06 00:50:03 +0100844 const struct andr_boot_img_hdr_v0 *hdr;
Sam Protsenko4fabf402020-01-24 17:53:40 +0200845 bool res;
846 ulong dtb_img_addr; /* address of DTB part in boot image */
847 u32 dtb_img_size; /* size of DTB payload in boot image */
848 ulong dtb_addr; /* address of DTB blob with specified index */
849 u32 i; /* index iterator */
850
Safae Ouajihc60ae102023-02-06 00:50:11 +0100851 res = android_image_get_dtb_img_addr(hdr_addr, 0, &dtb_img_addr);
Sam Protsenko4fabf402020-01-24 17:53:40 +0200852 if (!res)
853 return false;
854
855 /* Check if DTB area of boot image is in DTBO format */
856 if (android_dt_check_header(dtb_img_addr)) {
857 printf("## DTB area contents (DTBO format):\n");
858 android_dt_print_contents(dtb_img_addr);
859 return true;
860 }
861
862 printf("## DTB area contents (concat format):\n");
863
864 /* Iterate over concatenated DTB blobs */
865 hdr = map_sysmem(hdr_addr, sizeof(*hdr));
866 dtb_img_size = hdr->dtb_size;
867 unmap_sysmem(hdr);
868 i = 0;
869 dtb_addr = dtb_img_addr;
870 while (dtb_addr < dtb_img_addr + dtb_img_size) {
871 const struct fdt_header *fdt;
872 u32 dtb_size;
873
874 fdt = map_sysmem(dtb_addr, sizeof(*fdt));
875 if (fdt_check_header(fdt) != 0) {
876 unmap_sysmem(fdt);
877 printf("Error: Invalid FDT header for index %u\n", i);
878 return false;
879 }
880
881 res = android_image_print_dtb_info(fdt, i);
882 if (!res) {
883 unmap_sysmem(fdt);
884 return false;
885 }
886
887 dtb_size = fdt_totalsize(fdt);
888 unmap_sysmem(fdt);
889 dtb_addr += dtb_size;
890 ++i;
891 }
892
893 return true;
Michael Trimarchi44af20b2016-06-10 19:54:37 +0200894}
895#endif