blob: cf63ad97fab79c72500f07fd0257d75a9a569359 [file] [log] [blame]
Tom Rini10e47792018-05-06 17:58:06 -04001// SPDX-License-Identifier: GPL-2.0
Siva Durga Prasad Paladugub1acb652018-02-28 13:26:53 +05302/*
3 * (C) Copyright 2018 Xilinx, Inc.
4 * Siva Durga Prasad Paladugu <siva.durga.paladugu@xilinx.com>
Siva Durga Prasad Paladugub1acb652018-02-28 13:26:53 +05305 */
6
7#include <common.h>
Simon Glassed38aef2020-05-10 11:40:03 -06008#include <command.h>
Simon Glass1d91ba72019-11-14 12:57:37 -07009#include <cpu_func.h>
Simon Glass313112a2019-08-01 09:46:46 -060010#include <env.h>
Siva Durga Prasad Paladugub1acb652018-02-28 13:26:53 +053011#include <malloc.h>
Siva Durga Prasad Paladugu8b75ad62018-09-06 16:34:44 +053012#include <memalign.h>
Ibai Erkiagac8a3efa2019-09-27 11:37:01 +010013#include <zynqmp_firmware.h>
Siva Durga Prasad Paladugu48eaa0c2018-10-05 15:09:05 +053014#include <asm/arch/hardware.h>
Siva Durga Prasad Paladugub1acb652018-02-28 13:26:53 +053015#include <asm/arch/sys_proto.h>
16#include <asm/io.h>
17
Siva Durga Prasad Paladugu8b75ad62018-09-06 16:34:44 +053018struct aes {
19 u64 srcaddr;
20 u64 ivaddr;
21 u64 keyaddr;
22 u64 dstaddr;
23 u64 len;
24 u64 op;
25 u64 keysrc;
26};
27
Simon Glassed38aef2020-05-10 11:40:03 -060028static int do_zynqmp_verify_secure(struct cmd_tbl *cmdtp, int flag, int argc,
29 char *const argv[])
Siva Durga Prasad Paladugub1acb652018-02-28 13:26:53 +053030{
Vipul Kumar95a3f872018-07-11 15:18:28 +053031 u64 src_addr, addr;
32 u32 len, src_lo, src_hi;
33 u8 *key_ptr = NULL;
Siva Durga Prasad Paladugub1acb652018-02-28 13:26:53 +053034 int ret;
Siva Durga Prasad Paladugub1acb652018-02-28 13:26:53 +053035 u32 key_lo = 0;
36 u32 key_hi = 0;
37 u32 ret_payload[PAYLOAD_ARG_CNT];
Vipul Kumar95a3f872018-07-11 15:18:28 +053038
39 if (argc < 4)
40 return CMD_RET_USAGE;
Siva Durga Prasad Paladugub1acb652018-02-28 13:26:53 +053041
Vipul Kumar95a3f872018-07-11 15:18:28 +053042 src_addr = simple_strtoull(argv[2], NULL, 16);
43 len = simple_strtoul(argv[3], NULL, 16);
44
45 if (argc == 5)
46 key_ptr = (uint8_t *)(uintptr_t)simple_strtoull(argv[4],
47 NULL, 16);
48
49 if ((ulong)src_addr != ALIGN((ulong)src_addr,
50 CONFIG_SYS_CACHELINE_SIZE)) {
51 printf("Failed: source address not aligned:%lx\n",
52 (ulong)src_addr);
Siva Durga Prasad Paladugub1acb652018-02-28 13:26:53 +053053 return -EINVAL;
54 }
55
Vipul Kumar95a3f872018-07-11 15:18:28 +053056 src_lo = lower_32_bits((ulong)src_addr);
57 src_hi = upper_32_bits((ulong)src_addr);
58 flush_dcache_range((ulong)src_addr, (ulong)(src_addr + len));
Siva Durga Prasad Paladugub1acb652018-02-28 13:26:53 +053059
60 if (key_ptr) {
61 key_lo = lower_32_bits((ulong)key_ptr);
62 key_hi = upper_32_bits((ulong)key_ptr);
63 flush_dcache_range((ulong)key_ptr,
64 (ulong)(key_ptr + KEY_PTR_LEN));
65 }
66
Michal Simek4c3de372019-10-04 15:35:45 +020067 ret = xilinx_pm_request(PM_SECURE_IMAGE, src_lo, src_hi,
68 key_lo, key_hi, ret_payload);
Siva Durga Prasad Paladugub1acb652018-02-28 13:26:53 +053069 if (ret) {
70 printf("Failed: secure op status:0x%x\n", ret);
71 } else {
72 addr = (u64)ret_payload[1] << 32 | ret_payload[2];
73 printf("Verified image at 0x%llx\n", addr);
74 env_set_hex("zynqmp_verified_img_addr", addr);
75 }
76
77 return ret;
78}
79
Simon Glassed38aef2020-05-10 11:40:03 -060080static int do_zynqmp_mmio_read(struct cmd_tbl *cmdtp, int flag, int argc,
81 char *const argv[])
Vipul Kumar869ed8c2018-07-16 18:04:22 +053082{
83 u32 read_val, addr;
84 int ret;
85
86 if (argc != cmdtp->maxargs)
87 return CMD_RET_USAGE;
88
89 addr = simple_strtoul(argv[2], NULL, 16);
90
91 ret = zynqmp_mmio_read(addr, &read_val);
92 if (!ret)
93 printf("mmio read value at 0x%x = 0x%x\n",
94 addr, read_val);
95 else
96 printf("Failed: mmio read\n");
97
98 return ret;
99}
100
Simon Glassed38aef2020-05-10 11:40:03 -0600101static int do_zynqmp_mmio_write(struct cmd_tbl *cmdtp, int flag, int argc,
102 char *const argv[])
Vipul Kumar869ed8c2018-07-16 18:04:22 +0530103{
104 u32 addr, mask, val;
105 int ret;
106
107 if (argc != cmdtp->maxargs)
108 return CMD_RET_USAGE;
109
110 addr = simple_strtoul(argv[2], NULL, 16);
111 mask = simple_strtoul(argv[3], NULL, 16);
112 val = simple_strtoul(argv[4], NULL, 16);
113
114 ret = zynqmp_mmio_write(addr, mask, val);
115 if (ret != 0)
116 printf("Failed: mmio write\n");
117
118 return ret;
119}
120
Siva Durga Prasad Paladugu8b75ad62018-09-06 16:34:44 +0530121static int do_zynqmp_aes(struct cmd_tbl *cmdtp, int flag, int argc,
122 char * const argv[])
123{
124 ALLOC_CACHE_ALIGN_BUFFER(struct aes, aes, 1);
125 int ret;
126 u32 ret_payload[PAYLOAD_ARG_CNT];
127
128 if (zynqmp_firmware_version() <= PMUFW_V1_0) {
129 puts("ERR: PMUFW v1.0 or less is detected\n");
130 puts("ERR: Encrypt/Decrypt feature is not supported\n");
131 puts("ERR: Please upgrade PMUFW\n");
132 return CMD_RET_FAILURE;
133 }
134
135 if (argc < cmdtp->maxargs - 1)
136 return CMD_RET_USAGE;
137
138 aes->srcaddr = simple_strtoul(argv[2], NULL, 16);
139 aes->ivaddr = simple_strtoul(argv[3], NULL, 16);
140 aes->len = simple_strtoul(argv[4], NULL, 16);
141 aes->op = simple_strtoul(argv[5], NULL, 16);
142 aes->keysrc = simple_strtoul(argv[6], NULL, 16);
143 aes->dstaddr = simple_strtoul(argv[7], NULL, 16);
144
145 flush_dcache_range((ulong)aes, (ulong)(aes) +
146 roundup(sizeof(struct aes), ARCH_DMA_MINALIGN));
147
148 if (aes->srcaddr && aes->ivaddr && aes->dstaddr) {
149 flush_dcache_range(aes->srcaddr,
150 (aes->srcaddr +
151 roundup(aes->len, ARCH_DMA_MINALIGN)));
152 flush_dcache_range(aes->ivaddr,
153 (aes->ivaddr +
154 roundup(IV_SIZE, ARCH_DMA_MINALIGN)));
155 flush_dcache_range(aes->dstaddr,
156 (aes->dstaddr +
157 roundup(aes->len, ARCH_DMA_MINALIGN)));
158 }
159
160 if (aes->keysrc == 0) {
161 if (argc < cmdtp->maxargs)
162 return CMD_RET_USAGE;
163
164 aes->keyaddr = simple_strtoul(argv[8], NULL, 16);
165 if (aes->keyaddr)
166 flush_dcache_range(aes->keyaddr,
167 (aes->keyaddr +
168 roundup(KEY_PTR_LEN,
169 ARCH_DMA_MINALIGN)));
170 }
171
172 ret = xilinx_pm_request(PM_SECURE_AES, upper_32_bits((ulong)aes),
173 lower_32_bits((ulong)aes), 0, 0, ret_payload);
174 if (ret || ret_payload[1])
175 printf("Failed: AES op status:0x%x, errcode:0x%x\n",
176 ret, ret_payload[1]);
177
178 return ret;
179}
180
Siva Durga Prasad Paladugu48eaa0c2018-10-05 15:09:05 +0530181#ifdef CONFIG_DEFINE_TCM_OCM_MMAP
Simon Glassed38aef2020-05-10 11:40:03 -0600182static int do_zynqmp_tcm_init(struct cmd_tbl *cmdtp, int flag, int argc,
183 char *const argv[])
Siva Durga Prasad Paladugu48eaa0c2018-10-05 15:09:05 +0530184{
185 u8 mode;
186
187 if (argc != cmdtp->maxargs)
188 return CMD_RET_USAGE;
189
190 mode = simple_strtoul(argv[2], NULL, 16);
191 if (mode != TCM_LOCK && mode != TCM_SPLIT) {
192 printf("Mode should be either 0(lock)/1(split)\n");
193 return CMD_RET_FAILURE;
194 }
195
196 dcache_disable();
197 tcm_init(mode);
198 dcache_enable();
199
200 return CMD_RET_SUCCESS;
201}
202#endif
203
Michal Simekb0e4b232020-04-27 11:26:31 +0200204static int do_zynqmp_pmufw(struct cmd_tbl *cmdtp, int flag, int argc,
205 char * const argv[])
206{
207 u32 addr, size;
208
209 if (argc != cmdtp->maxargs)
210 return CMD_RET_USAGE;
211
212 addr = simple_strtoul(argv[2], NULL, 16);
213 size = simple_strtoul(argv[3], NULL, 16);
214 flush_dcache_range((ulong)addr, (ulong)(addr + size));
215
216 zynqmp_pmufw_load_config_object((const void *)(uintptr_t)addr,
217 (size_t)size);
218
219 return 0;
220}
221
T Karthik Reddy59ec6412019-01-07 17:05:10 +0530222static int do_zynqmp_rsa(struct cmd_tbl *cmdtp, int flag, int argc,
223 char * const argv[])
224{
225 u64 srcaddr, mod, exp;
226 u32 srclen, rsaop, size, ret_payload[PAYLOAD_ARG_CNT];
227 int ret;
228
229 if (argc != cmdtp->maxargs)
230 return CMD_RET_USAGE;
231
232 if (zynqmp_firmware_version() <= PMUFW_V1_0) {
233 puts("ERR: PMUFW v1.0 or less is detected\n");
234 puts("ERR: Encrypt/Decrypt feature is not supported\n");
235 puts("ERR: Please upgrade PMUFW\n");
236 return CMD_RET_FAILURE;
237 }
238
239 srcaddr = simple_strtoul(argv[2], NULL, 16);
240 srclen = simple_strtoul(argv[3], NULL, 16);
241 if (srclen != RSA_KEY_SIZE) {
242 puts("ERR: srclen should be equal to 0x200(512 bytes)\n");
243 return CMD_RET_USAGE;
244 }
245
246 mod = simple_strtoul(argv[4], NULL, 16);
247 exp = simple_strtoul(argv[5], NULL, 16);
248 rsaop = simple_strtoul(argv[6], NULL, 16);
249 if (!(rsaop == 0 || rsaop == 1)) {
250 puts("ERR: rsaop should be either 0 or 1\n");
251 return CMD_RET_USAGE;
252 }
253
254 memcpy((void *)srcaddr + srclen, (void *)mod, MODULUS_LEN);
255
256 /*
257 * For encryption we load public exponent (key size 4096-bits),
258 * for decryption we load private exponent (32-bits)
259 */
260 if (rsaop) {
261 memcpy((void *)srcaddr + srclen + MODULUS_LEN,
262 (void *)exp, PUB_EXPO_LEN);
263 size = srclen + MODULUS_LEN + PUB_EXPO_LEN;
264 } else {
265 memcpy((void *)srcaddr + srclen + MODULUS_LEN,
266 (void *)exp, PRIV_EXPO_LEN);
267 size = srclen + MODULUS_LEN + PRIV_EXPO_LEN;
268 }
269
270 flush_dcache_range((ulong)srcaddr,
271 (ulong)(srcaddr) + roundup(size, ARCH_DMA_MINALIGN));
272
273 ret = xilinx_pm_request(PM_SECURE_RSA, upper_32_bits((ulong)srcaddr),
274 lower_32_bits((ulong)srcaddr), srclen, rsaop,
275 ret_payload);
276 if (ret || ret_payload[1]) {
277 printf("Failed: RSA status:0x%x, errcode:0x%x\n",
278 ret, ret_payload[1]);
279 return CMD_RET_FAILURE;
280 }
281
282 return CMD_RET_SUCCESS;
283}
284
T Karthik Reddy89cbce92019-01-07 17:05:11 +0530285static int do_zynqmp_sha3(struct cmd_tbl *cmdtp, int flag,
286 int argc, char * const argv[])
287{
Michal Simekd5c37472020-10-20 08:29:25 +0200288 u64 srcaddr, hashaddr;
T Karthik Reddy89cbce92019-01-07 17:05:11 +0530289 u32 srclen, ret_payload[PAYLOAD_ARG_CNT];
290 int ret;
291
Michal Simekd5c37472020-10-20 08:29:25 +0200292 if (argc > cmdtp->maxargs || argc < (cmdtp->maxargs - 1))
T Karthik Reddy89cbce92019-01-07 17:05:11 +0530293 return CMD_RET_USAGE;
294
295 if (zynqmp_firmware_version() <= PMUFW_V1_0) {
296 puts("ERR: PMUFW v1.0 or less is detected\n");
297 puts("ERR: Encrypt/Decrypt feature is not supported\n");
298 puts("ERR: Please upgrade PMUFW\n");
299 return CMD_RET_FAILURE;
300 }
301
302 srcaddr = simple_strtoul(argv[2], NULL, 16);
303 srclen = simple_strtoul(argv[3], NULL, 16);
304
Michal Simekd5c37472020-10-20 08:29:25 +0200305 if (argc == 5) {
306 hashaddr = simple_strtoul(argv[4], NULL, 16);
307 flush_dcache_range(hashaddr,
308 hashaddr + roundup(ZYNQMP_SHA3_SIZE,
309 ARCH_DMA_MINALIGN));
310 } else {
311 hashaddr = srcaddr;
312 }
313
T Karthik Reddy89cbce92019-01-07 17:05:11 +0530314 /* Check srcaddr or srclen != 0 */
315 if (!srcaddr || !srclen) {
316 puts("ERR: srcaddr & srclen should not be 0\n");
317 return CMD_RET_USAGE;
318 }
319
320 flush_dcache_range(srcaddr,
321 srcaddr + roundup(srclen, ARCH_DMA_MINALIGN));
322
323 ret = xilinx_pm_request(PM_SECURE_SHA, 0, 0, 0,
324 ZYNQMP_SHA3_INIT, ret_payload);
325 if (ret || ret_payload[1]) {
326 printf("Failed: SHA INIT status:0x%x, errcode:0x%x\n",
327 ret, ret_payload[1]);
328 return CMD_RET_FAILURE;
329 }
330
331 ret = xilinx_pm_request(PM_SECURE_SHA, upper_32_bits((ulong)srcaddr),
332 lower_32_bits((ulong)srcaddr),
333 srclen, ZYNQMP_SHA3_UPDATE, ret_payload);
334 if (ret || ret_payload[1]) {
335 printf("Failed: SHA UPDATE status:0x%x, errcode:0x%x\n",
336 ret, ret_payload[1]);
337 return CMD_RET_FAILURE;
338 }
339
Michal Simekd5c37472020-10-20 08:29:25 +0200340 ret = xilinx_pm_request(PM_SECURE_SHA, upper_32_bits((ulong)hashaddr),
341 lower_32_bits((ulong)hashaddr),
342 ZYNQMP_SHA3_SIZE, ZYNQMP_SHA3_FINAL,
343 ret_payload);
T Karthik Reddy89cbce92019-01-07 17:05:11 +0530344 if (ret || ret_payload[1]) {
345 printf("Failed: SHA FINAL status:0x%x, errcode:0x%x\n",
346 ret, ret_payload[1]);
347 return CMD_RET_FAILURE;
348 }
349
350 return CMD_RET_SUCCESS;
351}
352
Simon Glassed38aef2020-05-10 11:40:03 -0600353static struct cmd_tbl cmd_zynqmp_sub[] = {
Vipul Kumar95a3f872018-07-11 15:18:28 +0530354 U_BOOT_CMD_MKENT(secure, 5, 0, do_zynqmp_verify_secure, "", ""),
Michal Simekb0e4b232020-04-27 11:26:31 +0200355 U_BOOT_CMD_MKENT(pmufw, 4, 0, do_zynqmp_pmufw, "", ""),
Vipul Kumar869ed8c2018-07-16 18:04:22 +0530356 U_BOOT_CMD_MKENT(mmio_read, 3, 0, do_zynqmp_mmio_read, "", ""),
357 U_BOOT_CMD_MKENT(mmio_write, 5, 0, do_zynqmp_mmio_write, "", ""),
Siva Durga Prasad Paladugu8b75ad62018-09-06 16:34:44 +0530358 U_BOOT_CMD_MKENT(aes, 9, 0, do_zynqmp_aes, "", ""),
T Karthik Reddy59ec6412019-01-07 17:05:10 +0530359 U_BOOT_CMD_MKENT(rsa, 7, 0, do_zynqmp_rsa, "", ""),
Michal Simekd5c37472020-10-20 08:29:25 +0200360 U_BOOT_CMD_MKENT(sha3, 5, 0, do_zynqmp_sha3, "", ""),
Siva Durga Prasad Paladugu48eaa0c2018-10-05 15:09:05 +0530361#ifdef CONFIG_DEFINE_TCM_OCM_MMAP
362 U_BOOT_CMD_MKENT(tcminit, 3, 0, do_zynqmp_tcm_init, "", ""),
363#endif
Vipul Kumar95a3f872018-07-11 15:18:28 +0530364};
365
Siva Durga Prasad Paladugub1acb652018-02-28 13:26:53 +0530366/**
367 * do_zynqmp - Handle the "zynqmp" command-line command
368 * @cmdtp: Command data struct pointer
369 * @flag: Command flag
370 * @argc: Command-line argument count
371 * @argv: Array of command-line arguments
372 *
373 * Processes the zynqmp specific commands
374 *
375 * Return: return 0 on success and CMD_RET_USAGE incase of misuse and error
376 */
Simon Glassed38aef2020-05-10 11:40:03 -0600377static int do_zynqmp(struct cmd_tbl *cmdtp, int flag, int argc,
Siva Durga Prasad Paladugub1acb652018-02-28 13:26:53 +0530378 char *const argv[])
379{
Simon Glassed38aef2020-05-10 11:40:03 -0600380 struct cmd_tbl *c;
Siva Durga Prasad Paladugub1acb652018-02-28 13:26:53 +0530381
Vipul Kumar95a3f872018-07-11 15:18:28 +0530382 if (argc < 2)
Siva Durga Prasad Paladugub1acb652018-02-28 13:26:53 +0530383 return CMD_RET_USAGE;
384
Vipul Kumar95a3f872018-07-11 15:18:28 +0530385 c = find_cmd_tbl(argv[1], &cmd_zynqmp_sub[0],
386 ARRAY_SIZE(cmd_zynqmp_sub));
Siva Durga Prasad Paladugub1acb652018-02-28 13:26:53 +0530387
Vipul Kumar95a3f872018-07-11 15:18:28 +0530388 if (c)
389 return c->cmd(c, flag, argc, argv);
390 else
391 return CMD_RET_USAGE;
Siva Durga Prasad Paladugub1acb652018-02-28 13:26:53 +0530392}
393
394/***************************************************/
395#ifdef CONFIG_SYS_LONGHELP
396static char zynqmp_help_text[] =
397 "secure src len [key_addr] - verifies secure images of $len bytes\n"
398 " long at address $src. Optional key_addr\n"
399 " can be specified if user key needs to\n"
Vipul Kumar869ed8c2018-07-16 18:04:22 +0530400 " be used for decryption\n"
401 "zynqmp mmio_read address - read from address\n"
402 "zynqmp mmio_write address mask value - write value after masking to\n"
Siva Durga Prasad Paladugu48eaa0c2018-10-05 15:09:05 +0530403 " address\n"
Siva Durga Prasad Paladugu8b75ad62018-09-06 16:34:44 +0530404 "zynqmp aes srcaddr ivaddr len aesop keysrc dstaddr [keyaddr] -\n"
405 " Encrypts or decrypts blob of data at src address and puts it\n"
406 " back to dstaddr using key and iv at keyaddr and ivaddr\n"
407 " respectively. keysrc value specifies from which source key\n"
408 " has to be used, it can be User/Device/PUF key. A value of 0\n"
409 " for KUP(user key),1 for DeviceKey and 2 for PUF key. The\n"
410 " aesop value specifies the operation which can be 0 for\n"
411 " decrypt and 1 for encrypt operation\n"
Siva Durga Prasad Paladugu48eaa0c2018-10-05 15:09:05 +0530412#ifdef CONFIG_DEFINE_TCM_OCM_MMAP
Michal Simek3a5642d2018-11-21 07:49:18 +0100413 "zynqmp tcminit mode - Initialize the TCM with zeros. TCM needs to be\n"
414 " initialized before accessing to avoid ECC\n"
415 " errors. mode specifies in which mode TCM has\n"
416 " to be initialized. Supported modes will be\n"
417 " lock(0)/split(1)\n"
Siva Durga Prasad Paladugu48eaa0c2018-10-05 15:09:05 +0530418#endif
Michal Simekb0e4b232020-04-27 11:26:31 +0200419 "zynqmp pmufw address size - load PMU FW configuration object\n"
T Karthik Reddy59ec6412019-01-07 17:05:10 +0530420 "zynqmp rsa srcaddr srclen mod exp rsaop -\n"
421 " Performs RSA encryption and RSA decryption on blob of data\n"
422 " at srcaddr and puts it back in srcaddr using modulus and\n"
423 " public or private exponent\n"
424 " srclen : must be key size(4096 bits)\n"
425 " exp : private key exponent for RSA decryption(4096 bits)\n"
426 " public key exponent for RSA encryption(32 bits)\n"
427 " rsaop : 0 for RSA Decryption, 1 for RSA Encryption\n"
Michal Simekd5c37472020-10-20 08:29:25 +0200428 "zynqmp sha3 srcaddr srclen [key_addr] -\n"
T Karthik Reddy89cbce92019-01-07 17:05:11 +0530429 " Generates sha3 hash value for data blob at srcaddr and puts\n"
430 " 48 bytes hash value into srcaddr\n"
Michal Simekd5c37472020-10-20 08:29:25 +0200431 " Optional key_addr can be specified for saving sha3 hash value\n"
T Karthik Reddy89cbce92019-01-07 17:05:11 +0530432 " Note: srcaddr/srclen should not be 0\n"
Siva Durga Prasad Paladugu48eaa0c2018-10-05 15:09:05 +0530433 ;
Siva Durga Prasad Paladugub1acb652018-02-28 13:26:53 +0530434#endif
435
436U_BOOT_CMD(
Siva Durga Prasad Paladugu8b75ad62018-09-06 16:34:44 +0530437 zynqmp, 9, 1, do_zynqmp,
Vipul Kumar95a3f872018-07-11 15:18:28 +0530438 "ZynqMP sub-system",
Siva Durga Prasad Paladugub1acb652018-02-28 13:26:53 +0530439 zynqmp_help_text
440)