1*8617a60dSAndroid Build Coastguard Worker /* Copyright 2012 The ChromiumOS Authors
2*8617a60dSAndroid Build Coastguard Worker * Use of this source code is governed by a BSD-style license that can be
3*8617a60dSAndroid Build Coastguard Worker * found in the LICENSE file.
4*8617a60dSAndroid Build Coastguard Worker */
5*8617a60dSAndroid Build Coastguard Worker
6*8617a60dSAndroid Build Coastguard Worker #include <ctype.h>
7*8617a60dSAndroid Build Coastguard Worker #include <fcntl.h>
8*8617a60dSAndroid Build Coastguard Worker #include <stddef.h>
9*8617a60dSAndroid Build Coastguard Worker #include <stdio.h>
10*8617a60dSAndroid Build Coastguard Worker #include <string.h>
11*8617a60dSAndroid Build Coastguard Worker #include <sys/file.h>
12*8617a60dSAndroid Build Coastguard Worker #include <unistd.h>
13*8617a60dSAndroid Build Coastguard Worker
14*8617a60dSAndroid Build Coastguard Worker #include "2api.h"
15*8617a60dSAndroid Build Coastguard Worker #include "2common.h"
16*8617a60dSAndroid Build Coastguard Worker #include "2nvstorage.h"
17*8617a60dSAndroid Build Coastguard Worker #include "2sysincludes.h"
18*8617a60dSAndroid Build Coastguard Worker #include "chromeos_config.h"
19*8617a60dSAndroid Build Coastguard Worker #include "crossystem_arch.h"
20*8617a60dSAndroid Build Coastguard Worker #include "crossystem.h"
21*8617a60dSAndroid Build Coastguard Worker #include "crossystem_vbnv.h"
22*8617a60dSAndroid Build Coastguard Worker #include "host_common.h"
23*8617a60dSAndroid Build Coastguard Worker #include "flashrom.h"
24*8617a60dSAndroid Build Coastguard Worker #include "subprocess.h"
25*8617a60dSAndroid Build Coastguard Worker #include "vboot_struct.h"
26*8617a60dSAndroid Build Coastguard Worker
27*8617a60dSAndroid Build Coastguard Worker /* Filename for crossystem lock */
28*8617a60dSAndroid Build Coastguard Worker #define CROSSYSTEM_LOCK_PATH (CROSSYSTEM_LOCK_DIR "/crossystem.lock")
29*8617a60dSAndroid Build Coastguard Worker
30*8617a60dSAndroid Build Coastguard Worker /* Filename for kernel command line */
31*8617a60dSAndroid Build Coastguard Worker #define KERNEL_CMDLINE_PATH "/proc/cmdline"
32*8617a60dSAndroid Build Coastguard Worker
33*8617a60dSAndroid Build Coastguard Worker /* Filename for the tpm_clear_request executable. */
34*8617a60dSAndroid Build Coastguard Worker #define TPM_CLEAR_REQUEST_EXEC_NAME "/usr/sbin/tpm_clear_request"
35*8617a60dSAndroid Build Coastguard Worker
36*8617a60dSAndroid Build Coastguard Worker /* Fields that GetVdatString() can get */
37*8617a60dSAndroid Build Coastguard Worker typedef enum VdatStringField {
38*8617a60dSAndroid Build Coastguard Worker VDAT_STRING_DEPRECATED_TIMERS = 0, /* Timer values */
39*8617a60dSAndroid Build Coastguard Worker VDAT_STRING_LOAD_FIRMWARE_DEBUG, /* LoadFirmware() debug info */
40*8617a60dSAndroid Build Coastguard Worker VDAT_STRING_DEPRECATED_LOAD_KERNEL_DEBUG, /* vb2api_load_kernel()
41*8617a60dSAndroid Build Coastguard Worker debug info */
42*8617a60dSAndroid Build Coastguard Worker VDAT_STRING_MAINFW_ACT /* Active main firmware */
43*8617a60dSAndroid Build Coastguard Worker } VdatStringField;
44*8617a60dSAndroid Build Coastguard Worker
45*8617a60dSAndroid Build Coastguard Worker
46*8617a60dSAndroid Build Coastguard Worker /* Fields that GetVdatInt() can get */
47*8617a60dSAndroid Build Coastguard Worker typedef enum VdatIntField {
48*8617a60dSAndroid Build Coastguard Worker VDAT_INT_FLAGS = 0, /* Flags */
49*8617a60dSAndroid Build Coastguard Worker VDAT_INT_HEADER_VERSION, /* Header version for VbSharedData */
50*8617a60dSAndroid Build Coastguard Worker VDAT_INT_DEVSW_BOOT, /* Dev switch position at boot */
51*8617a60dSAndroid Build Coastguard Worker VDAT_INT_RECSW_BOOT, /* Recovery switch position at boot */
52*8617a60dSAndroid Build Coastguard Worker VDAT_INT_HW_WPSW_BOOT, /* Hardware WP switch position at boot */
53*8617a60dSAndroid Build Coastguard Worker
54*8617a60dSAndroid Build Coastguard Worker VDAT_INT_FW_VERSION_TPM, /* Current firmware version in TPM */
55*8617a60dSAndroid Build Coastguard Worker VDAT_INT_KERNEL_VERSION_TPM, /* Current kernel version in TPM */
56*8617a60dSAndroid Build Coastguard Worker VDAT_INT_KERNEL_KEY_VERIFIED, /* Kernel key verified using
57*8617a60dSAndroid Build Coastguard Worker * signature, not just hash */
58*8617a60dSAndroid Build Coastguard Worker VDAT_INT_RECOVERY_REASON, /* Recovery reason for current boot */
59*8617a60dSAndroid Build Coastguard Worker VDAT_INT_FW_BOOT2, /* Firmware selection by vboot2 */
60*8617a60dSAndroid Build Coastguard Worker VDAT_INT_FW_VERSION_ACT, /* Current active firmware version */
61*8617a60dSAndroid Build Coastguard Worker VDAT_INT_KERNEL_VERSION_ACT, /* Current active kernel version */
62*8617a60dSAndroid Build Coastguard Worker } VdatIntField;
63*8617a60dSAndroid Build Coastguard Worker
64*8617a60dSAndroid Build Coastguard Worker
65*8617a60dSAndroid Build Coastguard Worker /* Description of build options that may be specified on the
66*8617a60dSAndroid Build Coastguard Worker * kernel command line. */
67*8617a60dSAndroid Build Coastguard Worker typedef enum VbBuildOption {
68*8617a60dSAndroid Build Coastguard Worker VB_BUILD_OPTION_UNKNOWN,
69*8617a60dSAndroid Build Coastguard Worker VB_BUILD_OPTION_DEBUG,
70*8617a60dSAndroid Build Coastguard Worker VB_BUILD_OPTION_NODEBUG
71*8617a60dSAndroid Build Coastguard Worker } VbBuildOption;
72*8617a60dSAndroid Build Coastguard Worker
73*8617a60dSAndroid Build Coastguard Worker static const char *fw_results[] = {"unknown", "trying", "success", "failure"};
74*8617a60dSAndroid Build Coastguard Worker static const char *default_boot[] = {"disk", "usb", "altfw"};
75*8617a60dSAndroid Build Coastguard Worker
76*8617a60dSAndroid Build Coastguard Worker /* Masks for kern_nv usage by kernel. */
77*8617a60dSAndroid Build Coastguard Worker #define KERN_NV_FWUPDATE_TRIES_MASK 0x000F
78*8617a60dSAndroid Build Coastguard Worker #define KERN_NV_BLOCK_DEVMODE_FLAG 0x0010
79*8617a60dSAndroid Build Coastguard Worker #define KERN_NV_TPM_ATTACK_FLAG 0x0020
80*8617a60dSAndroid Build Coastguard Worker /* If you want to use the remaining currently-unused bits in kern_nv
81*8617a60dSAndroid Build Coastguard Worker * for something kernel-y, define a new field (the way we did for
82*8617a60dSAndroid Build Coastguard Worker * fwupdate_tries). Don't just modify kern_nv directly, because that
83*8617a60dSAndroid Build Coastguard Worker * makes it too easy to accidentally corrupt other sub-fields. */
84*8617a60dSAndroid Build Coastguard Worker #define KERN_NV_CURRENTLY_UNUSED 0xFFC0
85*8617a60dSAndroid Build Coastguard Worker
86*8617a60dSAndroid Build Coastguard Worker /* Return true if the FWID starts with the specified string. */
FwidStartsWith(const char * start)87*8617a60dSAndroid Build Coastguard Worker int FwidStartsWith(const char *start)
88*8617a60dSAndroid Build Coastguard Worker {
89*8617a60dSAndroid Build Coastguard Worker char fwid[VB_MAX_STRING_PROPERTY];
90*8617a60dSAndroid Build Coastguard Worker if (VbGetSystemPropertyString("fwid", fwid, sizeof(fwid)) != 0)
91*8617a60dSAndroid Build Coastguard Worker return 0;
92*8617a60dSAndroid Build Coastguard Worker
93*8617a60dSAndroid Build Coastguard Worker return 0 == strncmp(fwid, start, strlen(start));
94*8617a60dSAndroid Build Coastguard Worker }
95*8617a60dSAndroid Build Coastguard Worker
96*8617a60dSAndroid Build Coastguard Worker /* Acquire the lock for crossystem SetSystemProperty call. */
AcquireCrossystemLock(void)97*8617a60dSAndroid Build Coastguard Worker static int AcquireCrossystemLock(void)
98*8617a60dSAndroid Build Coastguard Worker {
99*8617a60dSAndroid Build Coastguard Worker int lock_fd;
100*8617a60dSAndroid Build Coastguard Worker
101*8617a60dSAndroid Build Coastguard Worker lock_fd = open(CROSSYSTEM_LOCK_PATH, O_RDWR | O_CREAT, 0600);
102*8617a60dSAndroid Build Coastguard Worker if (lock_fd < 0)
103*8617a60dSAndroid Build Coastguard Worker return -1;
104*8617a60dSAndroid Build Coastguard Worker
105*8617a60dSAndroid Build Coastguard Worker if (flock(lock_fd, LOCK_EX) < 0)
106*8617a60dSAndroid Build Coastguard Worker return -1;
107*8617a60dSAndroid Build Coastguard Worker
108*8617a60dSAndroid Build Coastguard Worker return lock_fd;
109*8617a60dSAndroid Build Coastguard Worker }
110*8617a60dSAndroid Build Coastguard Worker
111*8617a60dSAndroid Build Coastguard Worker /* Release the lock for crossystem SetSystemProperty call. */
ReleaseCrossystemLock(int lock_fd)112*8617a60dSAndroid Build Coastguard Worker static int ReleaseCrossystemLock(int lock_fd)
113*8617a60dSAndroid Build Coastguard Worker {
114*8617a60dSAndroid Build Coastguard Worker if (flock(lock_fd, F_UNLCK) < 0)
115*8617a60dSAndroid Build Coastguard Worker return -1;
116*8617a60dSAndroid Build Coastguard Worker
117*8617a60dSAndroid Build Coastguard Worker close(lock_fd);
118*8617a60dSAndroid Build Coastguard Worker
119*8617a60dSAndroid Build Coastguard Worker return 0;
120*8617a60dSAndroid Build Coastguard Worker }
121*8617a60dSAndroid Build Coastguard Worker
122*8617a60dSAndroid Build Coastguard Worker /* Check if system FW type is equivalent to a given name */
CheckFwType(const char * name)123*8617a60dSAndroid Build Coastguard Worker static bool CheckFwType(const char *name)
124*8617a60dSAndroid Build Coastguard Worker {
125*8617a60dSAndroid Build Coastguard Worker char fwtype_buf[VB_MAX_STRING_PROPERTY];
126*8617a60dSAndroid Build Coastguard Worker int fwtype_ret;
127*8617a60dSAndroid Build Coastguard Worker
128*8617a60dSAndroid Build Coastguard Worker fwtype_ret = VbGetSystemPropertyString("mainfw_type",
129*8617a60dSAndroid Build Coastguard Worker fwtype_buf, sizeof(fwtype_buf));
130*8617a60dSAndroid Build Coastguard Worker
131*8617a60dSAndroid Build Coastguard Worker if (fwtype_ret == 0 && !strcasecmp(fwtype_buf, name))
132*8617a60dSAndroid Build Coastguard Worker return true;
133*8617a60dSAndroid Build Coastguard Worker
134*8617a60dSAndroid Build Coastguard Worker return false;
135*8617a60dSAndroid Build Coastguard Worker }
136*8617a60dSAndroid Build Coastguard Worker
get_fake_context(void)137*8617a60dSAndroid Build Coastguard Worker static struct vb2_context *get_fake_context(void)
138*8617a60dSAndroid Build Coastguard Worker {
139*8617a60dSAndroid Build Coastguard Worker static uint8_t fake_workbuf[sizeof(struct vb2_shared_data) + 16]
140*8617a60dSAndroid Build Coastguard Worker __attribute__((aligned(VB2_WORKBUF_ALIGN)));
141*8617a60dSAndroid Build Coastguard Worker static struct vb2_context *fake_ctx;
142*8617a60dSAndroid Build Coastguard Worker
143*8617a60dSAndroid Build Coastguard Worker if (fake_ctx)
144*8617a60dSAndroid Build Coastguard Worker return fake_ctx;
145*8617a60dSAndroid Build Coastguard Worker
146*8617a60dSAndroid Build Coastguard Worker vb2api_init(fake_workbuf, sizeof(fake_workbuf), &fake_ctx);
147*8617a60dSAndroid Build Coastguard Worker
148*8617a60dSAndroid Build Coastguard Worker return fake_ctx;
149*8617a60dSAndroid Build Coastguard Worker }
150*8617a60dSAndroid Build Coastguard Worker
151*8617a60dSAndroid Build Coastguard Worker static int vnc_read;
152*8617a60dSAndroid Build Coastguard Worker
vb2_get_nv_storage(enum vb2_nv_param param)153*8617a60dSAndroid Build Coastguard Worker int vb2_get_nv_storage(enum vb2_nv_param param)
154*8617a60dSAndroid Build Coastguard Worker {
155*8617a60dSAndroid Build Coastguard Worker VbSharedDataHeader* sh = VbSharedDataRead();
156*8617a60dSAndroid Build Coastguard Worker struct vb2_context *ctx = get_fake_context();
157*8617a60dSAndroid Build Coastguard Worker
158*8617a60dSAndroid Build Coastguard Worker if (!sh)
159*8617a60dSAndroid Build Coastguard Worker return -1;
160*8617a60dSAndroid Build Coastguard Worker
161*8617a60dSAndroid Build Coastguard Worker /* TODO: locking around NV access */
162*8617a60dSAndroid Build Coastguard Worker if (!vnc_read) {
163*8617a60dSAndroid Build Coastguard Worker if (sh && sh->flags & VBSD_NVDATA_V2)
164*8617a60dSAndroid Build Coastguard Worker ctx->flags |= VB2_CONTEXT_NVDATA_V2;
165*8617a60dSAndroid Build Coastguard Worker if (0 != vb2_read_nv_storage(ctx)) {
166*8617a60dSAndroid Build Coastguard Worker free(sh);
167*8617a60dSAndroid Build Coastguard Worker return -1;
168*8617a60dSAndroid Build Coastguard Worker }
169*8617a60dSAndroid Build Coastguard Worker vb2_nv_init(ctx);
170*8617a60dSAndroid Build Coastguard Worker
171*8617a60dSAndroid Build Coastguard Worker /* TODO: If vnc.raw_changed, attempt to reopen NVRAM for write
172*8617a60dSAndroid Build Coastguard Worker * and save the new defaults. If we're able to, log. */
173*8617a60dSAndroid Build Coastguard Worker
174*8617a60dSAndroid Build Coastguard Worker vnc_read = 1;
175*8617a60dSAndroid Build Coastguard Worker }
176*8617a60dSAndroid Build Coastguard Worker
177*8617a60dSAndroid Build Coastguard Worker free(sh);
178*8617a60dSAndroid Build Coastguard Worker return (int)vb2_nv_get(ctx, param);
179*8617a60dSAndroid Build Coastguard Worker }
180*8617a60dSAndroid Build Coastguard Worker
vb2_set_nv_storage(enum vb2_nv_param param,int value)181*8617a60dSAndroid Build Coastguard Worker int vb2_set_nv_storage(enum vb2_nv_param param, int value)
182*8617a60dSAndroid Build Coastguard Worker {
183*8617a60dSAndroid Build Coastguard Worker VbSharedDataHeader* sh = VbSharedDataRead();
184*8617a60dSAndroid Build Coastguard Worker struct vb2_context *ctx = get_fake_context();
185*8617a60dSAndroid Build Coastguard Worker
186*8617a60dSAndroid Build Coastguard Worker if (!sh)
187*8617a60dSAndroid Build Coastguard Worker return -1;
188*8617a60dSAndroid Build Coastguard Worker
189*8617a60dSAndroid Build Coastguard Worker /* TODO: locking around NV access */
190*8617a60dSAndroid Build Coastguard Worker if (sh && sh->flags & VBSD_NVDATA_V2)
191*8617a60dSAndroid Build Coastguard Worker ctx->flags |= VB2_CONTEXT_NVDATA_V2;
192*8617a60dSAndroid Build Coastguard Worker if (0 != vb2_read_nv_storage(ctx)) {
193*8617a60dSAndroid Build Coastguard Worker free(sh);
194*8617a60dSAndroid Build Coastguard Worker return -1;
195*8617a60dSAndroid Build Coastguard Worker }
196*8617a60dSAndroid Build Coastguard Worker vb2_nv_init(ctx);
197*8617a60dSAndroid Build Coastguard Worker vb2_nv_set(ctx, param, (uint32_t)value);
198*8617a60dSAndroid Build Coastguard Worker
199*8617a60dSAndroid Build Coastguard Worker if (ctx->flags & VB2_CONTEXT_NVDATA_CHANGED) {
200*8617a60dSAndroid Build Coastguard Worker vnc_read = 0;
201*8617a60dSAndroid Build Coastguard Worker if (0 != vb2_write_nv_storage(ctx)) {
202*8617a60dSAndroid Build Coastguard Worker free(sh);
203*8617a60dSAndroid Build Coastguard Worker return -1;
204*8617a60dSAndroid Build Coastguard Worker }
205*8617a60dSAndroid Build Coastguard Worker ctx->flags &= ~VB2_CONTEXT_NVDATA_CHANGED;
206*8617a60dSAndroid Build Coastguard Worker }
207*8617a60dSAndroid Build Coastguard Worker
208*8617a60dSAndroid Build Coastguard Worker /* Success */
209*8617a60dSAndroid Build Coastguard Worker free(sh);
210*8617a60dSAndroid Build Coastguard Worker return 0;
211*8617a60dSAndroid Build Coastguard Worker }
212*8617a60dSAndroid Build Coastguard Worker
213*8617a60dSAndroid Build Coastguard Worker /*
214*8617a60dSAndroid Build Coastguard Worker * Set a param value, and try to flag it for persistent backup. It's okay if
215*8617a60dSAndroid Build Coastguard Worker * backup isn't supported (which it isn't, in current designs). It's
216*8617a60dSAndroid Build Coastguard Worker * best-effort only.
217*8617a60dSAndroid Build Coastguard Worker */
vb2_set_nv_storage_with_backup(enum vb2_nv_param param,int value)218*8617a60dSAndroid Build Coastguard Worker static int vb2_set_nv_storage_with_backup(enum vb2_nv_param param, int value)
219*8617a60dSAndroid Build Coastguard Worker {
220*8617a60dSAndroid Build Coastguard Worker int retval;
221*8617a60dSAndroid Build Coastguard Worker retval = vb2_set_nv_storage(param, value);
222*8617a60dSAndroid Build Coastguard Worker if (!retval)
223*8617a60dSAndroid Build Coastguard Worker vb2_set_nv_storage(VB2_NV_BACKUP_NVRAM_REQUEST, 1);
224*8617a60dSAndroid Build Coastguard Worker return retval;
225*8617a60dSAndroid Build Coastguard Worker }
226*8617a60dSAndroid Build Coastguard Worker
227*8617a60dSAndroid Build Coastguard Worker /* Find what build/debug status is specified on the kernel command
228*8617a60dSAndroid Build Coastguard Worker * line, if any. */
VbScanBuildOption(void)229*8617a60dSAndroid Build Coastguard Worker static VbBuildOption VbScanBuildOption(void)
230*8617a60dSAndroid Build Coastguard Worker {
231*8617a60dSAndroid Build Coastguard Worker FILE* f = NULL;
232*8617a60dSAndroid Build Coastguard Worker char buf[4096] = "";
233*8617a60dSAndroid Build Coastguard Worker char *t, *saveptr;
234*8617a60dSAndroid Build Coastguard Worker const char *delimiters = " \r\n";
235*8617a60dSAndroid Build Coastguard Worker
236*8617a60dSAndroid Build Coastguard Worker f = fopen(KERNEL_CMDLINE_PATH, "r");
237*8617a60dSAndroid Build Coastguard Worker if (NULL != f) {
238*8617a60dSAndroid Build Coastguard Worker if (NULL == fgets(buf, sizeof(buf), f))
239*8617a60dSAndroid Build Coastguard Worker buf[0] = 0;
240*8617a60dSAndroid Build Coastguard Worker fclose(f);
241*8617a60dSAndroid Build Coastguard Worker }
242*8617a60dSAndroid Build Coastguard Worker for (t = strtok_r(buf, delimiters, &saveptr); t;
243*8617a60dSAndroid Build Coastguard Worker t = strtok_r(NULL, delimiters, &saveptr)) {
244*8617a60dSAndroid Build Coastguard Worker if (0 == strcmp(t, "cros_debug"))
245*8617a60dSAndroid Build Coastguard Worker return VB_BUILD_OPTION_DEBUG;
246*8617a60dSAndroid Build Coastguard Worker else if (0 == strcmp(t, "cros_nodebug"))
247*8617a60dSAndroid Build Coastguard Worker return VB_BUILD_OPTION_NODEBUG;
248*8617a60dSAndroid Build Coastguard Worker }
249*8617a60dSAndroid Build Coastguard Worker
250*8617a60dSAndroid Build Coastguard Worker return VB_BUILD_OPTION_UNKNOWN;
251*8617a60dSAndroid Build Coastguard Worker }
252*8617a60dSAndroid Build Coastguard Worker
253*8617a60dSAndroid Build Coastguard Worker /* Determine whether the running OS image was built for debugging.
254*8617a60dSAndroid Build Coastguard Worker * Returns 1 if yes, 0 if no or indeterminate. */
VbGetDebugBuild(void)255*8617a60dSAndroid Build Coastguard Worker static vb2_error_t VbGetDebugBuild(void)
256*8617a60dSAndroid Build Coastguard Worker {
257*8617a60dSAndroid Build Coastguard Worker return VB_BUILD_OPTION_DEBUG == VbScanBuildOption();
258*8617a60dSAndroid Build Coastguard Worker }
259*8617a60dSAndroid Build Coastguard Worker
260*8617a60dSAndroid Build Coastguard Worker /* Determine whether OS-level debugging should be allowed.
261*8617a60dSAndroid Build Coastguard Worker * Returns 1 if yes, 0 if no or indeterminate. */
VbGetCrosDebug(void)262*8617a60dSAndroid Build Coastguard Worker static int VbGetCrosDebug(void)
263*8617a60dSAndroid Build Coastguard Worker {
264*8617a60dSAndroid Build Coastguard Worker /* If the currently running system specifies its debug status, use
265*8617a60dSAndroid Build Coastguard Worker * that in preference to other indicators. */
266*8617a60dSAndroid Build Coastguard Worker VbBuildOption option = VbScanBuildOption();
267*8617a60dSAndroid Build Coastguard Worker if (VB_BUILD_OPTION_DEBUG == option) {
268*8617a60dSAndroid Build Coastguard Worker return 1;
269*8617a60dSAndroid Build Coastguard Worker } else if (VB_BUILD_OPTION_NODEBUG == option) {
270*8617a60dSAndroid Build Coastguard Worker return 0;
271*8617a60dSAndroid Build Coastguard Worker }
272*8617a60dSAndroid Build Coastguard Worker
273*8617a60dSAndroid Build Coastguard Worker /* Command line is silent; allow debug if the dev switch is on. */
274*8617a60dSAndroid Build Coastguard Worker if (1 == VbGetSystemPropertyInt("devsw_boot"))
275*8617a60dSAndroid Build Coastguard Worker return 1;
276*8617a60dSAndroid Build Coastguard Worker
277*8617a60dSAndroid Build Coastguard Worker /* All other cases disallow debug. */
278*8617a60dSAndroid Build Coastguard Worker return 0;
279*8617a60dSAndroid Build Coastguard Worker }
280*8617a60dSAndroid Build Coastguard Worker
GetVdatLoadFirmwareDebug(char * dest,int size,const VbSharedDataHeader * sh)281*8617a60dSAndroid Build Coastguard Worker static int GetVdatLoadFirmwareDebug(char *dest, int size,
282*8617a60dSAndroid Build Coastguard Worker const VbSharedDataHeader *sh)
283*8617a60dSAndroid Build Coastguard Worker {
284*8617a60dSAndroid Build Coastguard Worker snprintf(dest, size,
285*8617a60dSAndroid Build Coastguard Worker "Check A result=%d\n"
286*8617a60dSAndroid Build Coastguard Worker "Check B result=%d\n"
287*8617a60dSAndroid Build Coastguard Worker "Firmware index booted=0x%02x\n"
288*8617a60dSAndroid Build Coastguard Worker "Active firmware version=0x%08x\n"
289*8617a60dSAndroid Build Coastguard Worker "Firmware version in TPM =0x%08x\n"
290*8617a60dSAndroid Build Coastguard Worker "Lowest combined version from firmware=0x%08x\n",
291*8617a60dSAndroid Build Coastguard Worker sh->check_fw_a_result,
292*8617a60dSAndroid Build Coastguard Worker sh->check_fw_b_result,
293*8617a60dSAndroid Build Coastguard Worker sh->firmware_index,
294*8617a60dSAndroid Build Coastguard Worker sh->fw_version_act,
295*8617a60dSAndroid Build Coastguard Worker sh->fw_version_tpm,
296*8617a60dSAndroid Build Coastguard Worker sh->fw_version_lowest);
297*8617a60dSAndroid Build Coastguard Worker return 0;
298*8617a60dSAndroid Build Coastguard Worker }
299*8617a60dSAndroid Build Coastguard Worker
GetVdatString(char * dest,int size,VdatStringField field)300*8617a60dSAndroid Build Coastguard Worker static int GetVdatString(char *dest, int size, VdatStringField field)
301*8617a60dSAndroid Build Coastguard Worker {
302*8617a60dSAndroid Build Coastguard Worker VbSharedDataHeader *sh = VbSharedDataRead();
303*8617a60dSAndroid Build Coastguard Worker int value = 0;
304*8617a60dSAndroid Build Coastguard Worker
305*8617a60dSAndroid Build Coastguard Worker if (!sh)
306*8617a60dSAndroid Build Coastguard Worker return -1;
307*8617a60dSAndroid Build Coastguard Worker
308*8617a60dSAndroid Build Coastguard Worker switch (field) {
309*8617a60dSAndroid Build Coastguard Worker case VDAT_STRING_LOAD_FIRMWARE_DEBUG:
310*8617a60dSAndroid Build Coastguard Worker value = GetVdatLoadFirmwareDebug(dest, size, sh);
311*8617a60dSAndroid Build Coastguard Worker break;
312*8617a60dSAndroid Build Coastguard Worker
313*8617a60dSAndroid Build Coastguard Worker case VDAT_STRING_MAINFW_ACT:
314*8617a60dSAndroid Build Coastguard Worker switch(sh->firmware_index) {
315*8617a60dSAndroid Build Coastguard Worker case 0:
316*8617a60dSAndroid Build Coastguard Worker StrCopy(dest, "A", size);
317*8617a60dSAndroid Build Coastguard Worker break;
318*8617a60dSAndroid Build Coastguard Worker case 1:
319*8617a60dSAndroid Build Coastguard Worker StrCopy(dest, "B", size);
320*8617a60dSAndroid Build Coastguard Worker break;
321*8617a60dSAndroid Build Coastguard Worker case 0xFF:
322*8617a60dSAndroid Build Coastguard Worker StrCopy(dest, "recovery", size);
323*8617a60dSAndroid Build Coastguard Worker break;
324*8617a60dSAndroid Build Coastguard Worker default:
325*8617a60dSAndroid Build Coastguard Worker value = -1;
326*8617a60dSAndroid Build Coastguard Worker }
327*8617a60dSAndroid Build Coastguard Worker break;
328*8617a60dSAndroid Build Coastguard Worker
329*8617a60dSAndroid Build Coastguard Worker default:
330*8617a60dSAndroid Build Coastguard Worker value = -1;
331*8617a60dSAndroid Build Coastguard Worker break;
332*8617a60dSAndroid Build Coastguard Worker }
333*8617a60dSAndroid Build Coastguard Worker
334*8617a60dSAndroid Build Coastguard Worker free(sh);
335*8617a60dSAndroid Build Coastguard Worker return value;
336*8617a60dSAndroid Build Coastguard Worker }
337*8617a60dSAndroid Build Coastguard Worker
FwidMajorVersion(void)338*8617a60dSAndroid Build Coastguard Worker static int FwidMajorVersion(void)
339*8617a60dSAndroid Build Coastguard Worker {
340*8617a60dSAndroid Build Coastguard Worker char fwid[VB_MAX_STRING_PROPERTY];
341*8617a60dSAndroid Build Coastguard Worker int version;
342*8617a60dSAndroid Build Coastguard Worker
343*8617a60dSAndroid Build Coastguard Worker if (VbGetSystemPropertyString("fwid", fwid, sizeof(fwid)) != 0)
344*8617a60dSAndroid Build Coastguard Worker return -1;
345*8617a60dSAndroid Build Coastguard Worker
346*8617a60dSAndroid Build Coastguard Worker if (sscanf(fwid, "%*[^.].%d", &version) != 1 || version <= 0) {
347*8617a60dSAndroid Build Coastguard Worker fprintf(stderr, "WARNING: Cannot parse major version from %s\n",
348*8617a60dSAndroid Build Coastguard Worker fwid);
349*8617a60dSAndroid Build Coastguard Worker return -1;
350*8617a60dSAndroid Build Coastguard Worker }
351*8617a60dSAndroid Build Coastguard Worker
352*8617a60dSAndroid Build Coastguard Worker return version;
353*8617a60dSAndroid Build Coastguard Worker }
354*8617a60dSAndroid Build Coastguard Worker
GetVdatInt(VdatIntField field)355*8617a60dSAndroid Build Coastguard Worker static int GetVdatInt(VdatIntField field)
356*8617a60dSAndroid Build Coastguard Worker {
357*8617a60dSAndroid Build Coastguard Worker VbSharedDataHeader* sh = VbSharedDataRead();
358*8617a60dSAndroid Build Coastguard Worker int value = -1;
359*8617a60dSAndroid Build Coastguard Worker
360*8617a60dSAndroid Build Coastguard Worker if (!sh)
361*8617a60dSAndroid Build Coastguard Worker return -1;
362*8617a60dSAndroid Build Coastguard Worker
363*8617a60dSAndroid Build Coastguard Worker /* Fields supported in version 1 */
364*8617a60dSAndroid Build Coastguard Worker switch (field) {
365*8617a60dSAndroid Build Coastguard Worker case VDAT_INT_FLAGS:
366*8617a60dSAndroid Build Coastguard Worker value = (int)sh->flags;
367*8617a60dSAndroid Build Coastguard Worker break;
368*8617a60dSAndroid Build Coastguard Worker case VDAT_INT_HEADER_VERSION:
369*8617a60dSAndroid Build Coastguard Worker value = sh->struct_version;
370*8617a60dSAndroid Build Coastguard Worker break;
371*8617a60dSAndroid Build Coastguard Worker case VDAT_INT_KERNEL_KEY_VERIFIED:
372*8617a60dSAndroid Build Coastguard Worker value = (sh->flags & VBSD_KERNEL_KEY_VERIFIED ? 1 : 0);
373*8617a60dSAndroid Build Coastguard Worker break;
374*8617a60dSAndroid Build Coastguard Worker case VDAT_INT_FW_VERSION_TPM:
375*8617a60dSAndroid Build Coastguard Worker /* b/269204332#comment5: Before CL:2054270 and CL:2056343,
376*8617a60dSAndroid Build Coastguard Worker fw_version_tpm was always 0. */
377*8617a60dSAndroid Build Coastguard Worker if (sh->struct_version <= 2 && FwidMajorVersion() < 12935)
378*8617a60dSAndroid Build Coastguard Worker value = (int)sh->fw_version_act;
379*8617a60dSAndroid Build Coastguard Worker else
380*8617a60dSAndroid Build Coastguard Worker value = (int)sh->fw_version_tpm;
381*8617a60dSAndroid Build Coastguard Worker break;
382*8617a60dSAndroid Build Coastguard Worker case VDAT_INT_KERNEL_VERSION_TPM:
383*8617a60dSAndroid Build Coastguard Worker value = (int)sh->kernel_version_tpm;
384*8617a60dSAndroid Build Coastguard Worker break;
385*8617a60dSAndroid Build Coastguard Worker case VDAT_INT_FW_BOOT2:
386*8617a60dSAndroid Build Coastguard Worker value = (sh->flags & VBSD_BOOT_FIRMWARE_VBOOT2 ? 1 : 0);
387*8617a60dSAndroid Build Coastguard Worker break;
388*8617a60dSAndroid Build Coastguard Worker case VDAT_INT_FW_VERSION_ACT:
389*8617a60dSAndroid Build Coastguard Worker value = (int)sh->fw_version_act;
390*8617a60dSAndroid Build Coastguard Worker break;
391*8617a60dSAndroid Build Coastguard Worker default:
392*8617a60dSAndroid Build Coastguard Worker break;
393*8617a60dSAndroid Build Coastguard Worker }
394*8617a60dSAndroid Build Coastguard Worker
395*8617a60dSAndroid Build Coastguard Worker /* Fields added in struct version 2 */
396*8617a60dSAndroid Build Coastguard Worker if (sh->struct_version >= 2) {
397*8617a60dSAndroid Build Coastguard Worker switch(field) {
398*8617a60dSAndroid Build Coastguard Worker case VDAT_INT_DEVSW_BOOT:
399*8617a60dSAndroid Build Coastguard Worker value = (sh->flags &
400*8617a60dSAndroid Build Coastguard Worker VBSD_BOOT_DEV_SWITCH_ON ? 1 : 0);
401*8617a60dSAndroid Build Coastguard Worker break;
402*8617a60dSAndroid Build Coastguard Worker case VDAT_INT_RECSW_BOOT:
403*8617a60dSAndroid Build Coastguard Worker value = (sh->flags &
404*8617a60dSAndroid Build Coastguard Worker VBSD_BOOT_REC_SWITCH_ON ? 1 : 0);
405*8617a60dSAndroid Build Coastguard Worker break;
406*8617a60dSAndroid Build Coastguard Worker case VDAT_INT_HW_WPSW_BOOT:
407*8617a60dSAndroid Build Coastguard Worker value = (sh->flags &
408*8617a60dSAndroid Build Coastguard Worker VBSD_BOOT_FIRMWARE_WP_ENABLED ? 1 : 0);
409*8617a60dSAndroid Build Coastguard Worker break;
410*8617a60dSAndroid Build Coastguard Worker case VDAT_INT_RECOVERY_REASON:
411*8617a60dSAndroid Build Coastguard Worker value = sh->recovery_reason;
412*8617a60dSAndroid Build Coastguard Worker break;
413*8617a60dSAndroid Build Coastguard Worker default:
414*8617a60dSAndroid Build Coastguard Worker break;
415*8617a60dSAndroid Build Coastguard Worker }
416*8617a60dSAndroid Build Coastguard Worker }
417*8617a60dSAndroid Build Coastguard Worker
418*8617a60dSAndroid Build Coastguard Worker /* Fields added in struct version 3 */
419*8617a60dSAndroid Build Coastguard Worker if (sh->struct_version >= 3) {
420*8617a60dSAndroid Build Coastguard Worker switch(field) {
421*8617a60dSAndroid Build Coastguard Worker case VDAT_INT_KERNEL_VERSION_ACT:
422*8617a60dSAndroid Build Coastguard Worker value = (int)sh->kernel_version_act;
423*8617a60dSAndroid Build Coastguard Worker break;
424*8617a60dSAndroid Build Coastguard Worker default:
425*8617a60dSAndroid Build Coastguard Worker break;
426*8617a60dSAndroid Build Coastguard Worker }
427*8617a60dSAndroid Build Coastguard Worker }
428*8617a60dSAndroid Build Coastguard Worker
429*8617a60dSAndroid Build Coastguard Worker free(sh);
430*8617a60dSAndroid Build Coastguard Worker return value;
431*8617a60dSAndroid Build Coastguard Worker }
432*8617a60dSAndroid Build Coastguard Worker
433*8617a60dSAndroid Build Coastguard Worker /* Return version of VbSharedData struct or -1 if not found. */
VbSharedDataVersion(void)434*8617a60dSAndroid Build Coastguard Worker int VbSharedDataVersion(void)
435*8617a60dSAndroid Build Coastguard Worker {
436*8617a60dSAndroid Build Coastguard Worker return GetVdatInt(VDAT_INT_HEADER_VERSION);
437*8617a60dSAndroid Build Coastguard Worker }
438*8617a60dSAndroid Build Coastguard Worker
VbGetSystemPropertyInt(const char * name)439*8617a60dSAndroid Build Coastguard Worker int VbGetSystemPropertyInt(const char *name)
440*8617a60dSAndroid Build Coastguard Worker {
441*8617a60dSAndroid Build Coastguard Worker int value = -1;
442*8617a60dSAndroid Build Coastguard Worker
443*8617a60dSAndroid Build Coastguard Worker /* Check architecture-dependent properties first */
444*8617a60dSAndroid Build Coastguard Worker value = VbGetArchPropertyInt(name);
445*8617a60dSAndroid Build Coastguard Worker if (-1 != value)
446*8617a60dSAndroid Build Coastguard Worker return value;
447*8617a60dSAndroid Build Coastguard Worker
448*8617a60dSAndroid Build Coastguard Worker /* NV storage values */
449*8617a60dSAndroid Build Coastguard Worker else if (!strcasecmp(name,"kern_nv")) {
450*8617a60dSAndroid Build Coastguard Worker value = vb2_get_nv_storage(VB2_NV_KERNEL_FIELD);
451*8617a60dSAndroid Build Coastguard Worker } else if (!strcasecmp(name,"nvram_cleared")) {
452*8617a60dSAndroid Build Coastguard Worker value = vb2_get_nv_storage(VB2_NV_KERNEL_SETTINGS_RESET);
453*8617a60dSAndroid Build Coastguard Worker } else if (!strcasecmp(name,"recovery_request")) {
454*8617a60dSAndroid Build Coastguard Worker value = vb2_get_nv_storage(VB2_NV_RECOVERY_REQUEST);
455*8617a60dSAndroid Build Coastguard Worker } else if (!strcasecmp(name,"diagnostic_request")) {
456*8617a60dSAndroid Build Coastguard Worker value = vb2_get_nv_storage(VB2_NV_DIAG_REQUEST);
457*8617a60dSAndroid Build Coastguard Worker } else if (!strcasecmp(name,"dbg_reset")) {
458*8617a60dSAndroid Build Coastguard Worker value = vb2_get_nv_storage(VB2_NV_DEBUG_RESET_MODE);
459*8617a60dSAndroid Build Coastguard Worker } else if (!strcasecmp(name,"disable_dev_request")) {
460*8617a60dSAndroid Build Coastguard Worker value = vb2_get_nv_storage(VB2_NV_DISABLE_DEV_REQUEST);
461*8617a60dSAndroid Build Coastguard Worker } else if (!strcasecmp(name,"clear_tpm_owner_request")) {
462*8617a60dSAndroid Build Coastguard Worker if (EXTERNAL_TPM_CLEAR_REQUEST && CheckFwType("nonchrome")) {
463*8617a60dSAndroid Build Coastguard Worker const char *const argv[] = {
464*8617a60dSAndroid Build Coastguard Worker TPM_CLEAR_REQUEST_EXEC_NAME,
465*8617a60dSAndroid Build Coastguard Worker NULL,
466*8617a60dSAndroid Build Coastguard Worker };
467*8617a60dSAndroid Build Coastguard Worker value = subprocess_run(argv, &subprocess_null, &subprocess_null,
468*8617a60dSAndroid Build Coastguard Worker &subprocess_null);
469*8617a60dSAndroid Build Coastguard Worker } else {
470*8617a60dSAndroid Build Coastguard Worker value = vb2_get_nv_storage(VB2_NV_CLEAR_TPM_OWNER_REQUEST);
471*8617a60dSAndroid Build Coastguard Worker }
472*8617a60dSAndroid Build Coastguard Worker } else if (!strcasecmp(name,"clear_tpm_owner_done")) {
473*8617a60dSAndroid Build Coastguard Worker value = vb2_get_nv_storage(VB2_NV_CLEAR_TPM_OWNER_DONE);
474*8617a60dSAndroid Build Coastguard Worker } else if (!strcasecmp(name,"tpm_rebooted")) {
475*8617a60dSAndroid Build Coastguard Worker value = vb2_get_nv_storage(VB2_NV_TPM_REQUESTED_REBOOT);
476*8617a60dSAndroid Build Coastguard Worker } else if (!strcasecmp(name,"fw_try_count")) {
477*8617a60dSAndroid Build Coastguard Worker value = vb2_get_nv_storage(VB2_NV_TRY_COUNT);
478*8617a60dSAndroid Build Coastguard Worker } else if (!strcasecmp(name,"fw_vboot2")) {
479*8617a60dSAndroid Build Coastguard Worker value = GetVdatInt(VDAT_INT_FW_BOOT2);
480*8617a60dSAndroid Build Coastguard Worker } else if (!strcasecmp(name,"fwupdate_tries")) {
481*8617a60dSAndroid Build Coastguard Worker value = vb2_get_nv_storage(VB2_NV_KERNEL_FIELD);
482*8617a60dSAndroid Build Coastguard Worker if (value != -1)
483*8617a60dSAndroid Build Coastguard Worker value &= KERN_NV_FWUPDATE_TRIES_MASK;
484*8617a60dSAndroid Build Coastguard Worker } else if (!strcasecmp(name,"block_devmode")) {
485*8617a60dSAndroid Build Coastguard Worker value = vb2_get_nv_storage(VB2_NV_KERNEL_FIELD);
486*8617a60dSAndroid Build Coastguard Worker if (value != -1) {
487*8617a60dSAndroid Build Coastguard Worker value &= KERN_NV_BLOCK_DEVMODE_FLAG;
488*8617a60dSAndroid Build Coastguard Worker value = !!value;
489*8617a60dSAndroid Build Coastguard Worker }
490*8617a60dSAndroid Build Coastguard Worker } else if (!strcasecmp(name,"tpm_attack")) {
491*8617a60dSAndroid Build Coastguard Worker value = vb2_get_nv_storage(VB2_NV_KERNEL_FIELD);
492*8617a60dSAndroid Build Coastguard Worker if (value != -1) {
493*8617a60dSAndroid Build Coastguard Worker value &= KERN_NV_TPM_ATTACK_FLAG;
494*8617a60dSAndroid Build Coastguard Worker value = !!value;
495*8617a60dSAndroid Build Coastguard Worker }
496*8617a60dSAndroid Build Coastguard Worker } else if (!strcasecmp(name,"loc_idx")) {
497*8617a60dSAndroid Build Coastguard Worker value = vb2_get_nv_storage(VB2_NV_LOCALIZATION_INDEX);
498*8617a60dSAndroid Build Coastguard Worker } else if (!strcasecmp(name,"backup_nvram_request")) {
499*8617a60dSAndroid Build Coastguard Worker value = vb2_get_nv_storage(VB2_NV_BACKUP_NVRAM_REQUEST);
500*8617a60dSAndroid Build Coastguard Worker } else if (!strcasecmp(name,"dev_boot_usb")) {
501*8617a60dSAndroid Build Coastguard Worker value = vb2_get_nv_storage(VB2_NV_DEV_BOOT_EXTERNAL);
502*8617a60dSAndroid Build Coastguard Worker } else if (!strcasecmp(name,"dev_boot_altfw") ||
503*8617a60dSAndroid Build Coastguard Worker !strcasecmp(name,"dev_boot_legacy")) {
504*8617a60dSAndroid Build Coastguard Worker value = vb2_get_nv_storage(VB2_NV_DEV_BOOT_ALTFW);
505*8617a60dSAndroid Build Coastguard Worker } else if (!strcasecmp(name,"dev_boot_signed_only")) {
506*8617a60dSAndroid Build Coastguard Worker value = vb2_get_nv_storage(VB2_NV_DEV_BOOT_SIGNED_ONLY);
507*8617a60dSAndroid Build Coastguard Worker } else if (!strcasecmp(name,"dev_enable_udc")) {
508*8617a60dSAndroid Build Coastguard Worker value = vb2_get_nv_storage(VB2_NV_DEV_ENABLE_UDC);
509*8617a60dSAndroid Build Coastguard Worker } else if (!strcasecmp(name,"display_request")) {
510*8617a60dSAndroid Build Coastguard Worker value = vb2_get_nv_storage(VB2_NV_DISPLAY_REQUEST);
511*8617a60dSAndroid Build Coastguard Worker } else if (!strcasecmp(name,"recovery_subcode")) {
512*8617a60dSAndroid Build Coastguard Worker value = vb2_get_nv_storage(VB2_NV_RECOVERY_SUBCODE);
513*8617a60dSAndroid Build Coastguard Worker } else if (!strcasecmp(name,"wipeout_request")) {
514*8617a60dSAndroid Build Coastguard Worker value = vb2_get_nv_storage(VB2_NV_REQ_WIPEOUT);
515*8617a60dSAndroid Build Coastguard Worker } else if (!strcasecmp(name,"kernel_max_rollforward")) {
516*8617a60dSAndroid Build Coastguard Worker value = vb2_get_nv_storage(VB2_NV_KERNEL_MAX_ROLLFORWARD);
517*8617a60dSAndroid Build Coastguard Worker }
518*8617a60dSAndroid Build Coastguard Worker /* Other parameters */
519*8617a60dSAndroid Build Coastguard Worker else if (!strcasecmp(name,"cros_debug")) {
520*8617a60dSAndroid Build Coastguard Worker value = VbGetCrosDebug();
521*8617a60dSAndroid Build Coastguard Worker } else if (!strcasecmp(name,"debug_build")) {
522*8617a60dSAndroid Build Coastguard Worker value = VbGetDebugBuild();
523*8617a60dSAndroid Build Coastguard Worker } else if (!strcasecmp(name,"devsw_boot")) {
524*8617a60dSAndroid Build Coastguard Worker value = GetVdatInt(VDAT_INT_DEVSW_BOOT);
525*8617a60dSAndroid Build Coastguard Worker } else if (!strcasecmp(name, "recoverysw_boot")) {
526*8617a60dSAndroid Build Coastguard Worker value = GetVdatInt(VDAT_INT_RECSW_BOOT);
527*8617a60dSAndroid Build Coastguard Worker } else if (!strcasecmp(name, "wpsw_cur")) {
528*8617a60dSAndroid Build Coastguard Worker /* Use "write-protect at boot" as a fallback value. */
529*8617a60dSAndroid Build Coastguard Worker value = GetVdatInt(VDAT_INT_HW_WPSW_BOOT);
530*8617a60dSAndroid Build Coastguard Worker fprintf(stderr,
531*8617a60dSAndroid Build Coastguard Worker "Fallback to WPSW_BOOT (%d), which may be invalid\n",
532*8617a60dSAndroid Build Coastguard Worker value);
533*8617a60dSAndroid Build Coastguard Worker } else if (!strcasecmp(name,"vdat_flags")) {
534*8617a60dSAndroid Build Coastguard Worker value = GetVdatInt(VDAT_INT_FLAGS);
535*8617a60dSAndroid Build Coastguard Worker } else if (!strcasecmp(name,"tpm_fwver")) {
536*8617a60dSAndroid Build Coastguard Worker value = GetVdatInt(VDAT_INT_FW_VERSION_TPM);
537*8617a60dSAndroid Build Coastguard Worker } else if (!strcasecmp(name,"tpm_kernver")) {
538*8617a60dSAndroid Build Coastguard Worker value = GetVdatInt(VDAT_INT_KERNEL_VERSION_TPM);
539*8617a60dSAndroid Build Coastguard Worker } else if (!strcasecmp(name,"act_fwver")) {
540*8617a60dSAndroid Build Coastguard Worker value = GetVdatInt(VDAT_INT_FW_VERSION_ACT);
541*8617a60dSAndroid Build Coastguard Worker } else if (!strcasecmp(name,"act_kernver")) {
542*8617a60dSAndroid Build Coastguard Worker value = GetVdatInt(VDAT_INT_KERNEL_VERSION_ACT);
543*8617a60dSAndroid Build Coastguard Worker } else if (!strcasecmp(name,"recovery_reason")) {
544*8617a60dSAndroid Build Coastguard Worker value = GetVdatInt(VDAT_INT_RECOVERY_REASON);
545*8617a60dSAndroid Build Coastguard Worker } else if (!strcasecmp(name, "boot_on_ac_detect")) {
546*8617a60dSAndroid Build Coastguard Worker value = vb2_get_nv_storage(VB2_NV_BOOT_ON_AC_DETECT);
547*8617a60dSAndroid Build Coastguard Worker } else if (!strcasecmp(name, "try_ro_sync")) {
548*8617a60dSAndroid Build Coastguard Worker value = vb2_get_nv_storage(VB2_NV_TRY_RO_SYNC);
549*8617a60dSAndroid Build Coastguard Worker } else if (!strcasecmp(name, "battery_cutoff_request")) {
550*8617a60dSAndroid Build Coastguard Worker value = vb2_get_nv_storage(VB2_NV_BATTERY_CUTOFF_REQUEST);
551*8617a60dSAndroid Build Coastguard Worker } else if (!strcasecmp(name, "inside_vm")) {
552*8617a60dSAndroid Build Coastguard Worker /* Detect if the host is a VM. If there is no HWID and the
553*8617a60dSAndroid Build Coastguard Worker * firmware type is "nonchrome", then assume it is a VM. If
554*8617a60dSAndroid Build Coastguard Worker * HWID is present, it is a baremetal Chrome OS machine. Other
555*8617a60dSAndroid Build Coastguard Worker * cases are errors. */
556*8617a60dSAndroid Build Coastguard Worker char hwid[VB_MAX_STRING_PROPERTY];
557*8617a60dSAndroid Build Coastguard Worker if (VbGetSystemPropertyString("hwid", hwid,
558*8617a60dSAndroid Build Coastguard Worker sizeof(hwid)) != 0) {
559*8617a60dSAndroid Build Coastguard Worker char fwtype_buf[VB_MAX_STRING_PROPERTY];
560*8617a60dSAndroid Build Coastguard Worker int fwtype_ret = VbGetSystemPropertyString(
561*8617a60dSAndroid Build Coastguard Worker "mainfw_type", fwtype_buf, sizeof(fwtype_buf));
562*8617a60dSAndroid Build Coastguard Worker if (fwtype_ret == 0 &&
563*8617a60dSAndroid Build Coastguard Worker !strcasecmp(fwtype_buf, "nonchrome")) {
564*8617a60dSAndroid Build Coastguard Worker value = 1;
565*8617a60dSAndroid Build Coastguard Worker }
566*8617a60dSAndroid Build Coastguard Worker } else {
567*8617a60dSAndroid Build Coastguard Worker value = 0;
568*8617a60dSAndroid Build Coastguard Worker }
569*8617a60dSAndroid Build Coastguard Worker } else if (!strcasecmp(name, "post_ec_sync_delay")) {
570*8617a60dSAndroid Build Coastguard Worker value = vb2_get_nv_storage(VB2_NV_POST_EC_SYNC_DELAY);
571*8617a60dSAndroid Build Coastguard Worker }
572*8617a60dSAndroid Build Coastguard Worker
573*8617a60dSAndroid Build Coastguard Worker return value;
574*8617a60dSAndroid Build Coastguard Worker }
575*8617a60dSAndroid Build Coastguard Worker
VbGetSystemPropertyString(const char * name,char * dest,size_t size)576*8617a60dSAndroid Build Coastguard Worker int VbGetSystemPropertyString(const char *name, char *dest, size_t size)
577*8617a60dSAndroid Build Coastguard Worker {
578*8617a60dSAndroid Build Coastguard Worker if (dest == NULL || size == 0)
579*8617a60dSAndroid Build Coastguard Worker {
580*8617a60dSAndroid Build Coastguard Worker fprintf(stderr, "invalid dest buffer\n");
581*8617a60dSAndroid Build Coastguard Worker return -1;
582*8617a60dSAndroid Build Coastguard Worker }
583*8617a60dSAndroid Build Coastguard Worker /* Check for HWID override via cros_config */
584*8617a60dSAndroid Build Coastguard Worker if (!strcasecmp(name, "hwid")) {
585*8617a60dSAndroid Build Coastguard Worker char *hwid_override;
586*8617a60dSAndroid Build Coastguard Worker
587*8617a60dSAndroid Build Coastguard Worker if (chromeos_config_get_string("/", "hwid-override",
588*8617a60dSAndroid Build Coastguard Worker &hwid_override) == VB2_SUCCESS) {
589*8617a60dSAndroid Build Coastguard Worker StrCopy(dest, hwid_override, size);
590*8617a60dSAndroid Build Coastguard Worker free(hwid_override);
591*8617a60dSAndroid Build Coastguard Worker return 0;
592*8617a60dSAndroid Build Coastguard Worker }
593*8617a60dSAndroid Build Coastguard Worker }
594*8617a60dSAndroid Build Coastguard Worker
595*8617a60dSAndroid Build Coastguard Worker /* Check architecture-dependent properties */
596*8617a60dSAndroid Build Coastguard Worker if (VbGetArchPropertyString(name, dest, size))
597*8617a60dSAndroid Build Coastguard Worker return 0;
598*8617a60dSAndroid Build Coastguard Worker
599*8617a60dSAndroid Build Coastguard Worker if (!strcasecmp(name,"kernkey_vfy")) {
600*8617a60dSAndroid Build Coastguard Worker switch(GetVdatInt(VDAT_INT_KERNEL_KEY_VERIFIED)) {
601*8617a60dSAndroid Build Coastguard Worker case 0:
602*8617a60dSAndroid Build Coastguard Worker StrCopy(dest, "hash", size);
603*8617a60dSAndroid Build Coastguard Worker return 0;
604*8617a60dSAndroid Build Coastguard Worker case 1:
605*8617a60dSAndroid Build Coastguard Worker StrCopy(dest, "sig", size);
606*8617a60dSAndroid Build Coastguard Worker return 0;
607*8617a60dSAndroid Build Coastguard Worker default:
608*8617a60dSAndroid Build Coastguard Worker return -1;
609*8617a60dSAndroid Build Coastguard Worker }
610*8617a60dSAndroid Build Coastguard Worker } else if (!strcasecmp(name, "mainfw_act")) {
611*8617a60dSAndroid Build Coastguard Worker return GetVdatString(dest, size, VDAT_STRING_MAINFW_ACT);
612*8617a60dSAndroid Build Coastguard Worker } else if (!strcasecmp(name, "vdat_lfdebug")) {
613*8617a60dSAndroid Build Coastguard Worker return GetVdatString(dest, size,
614*8617a60dSAndroid Build Coastguard Worker VDAT_STRING_LOAD_FIRMWARE_DEBUG);
615*8617a60dSAndroid Build Coastguard Worker } else if (!strcasecmp(name, "fw_try_next")) {
616*8617a60dSAndroid Build Coastguard Worker StrCopy(dest,
617*8617a60dSAndroid Build Coastguard Worker vb2_get_nv_storage(VB2_NV_TRY_NEXT) ? "B" : "A",
618*8617a60dSAndroid Build Coastguard Worker size);
619*8617a60dSAndroid Build Coastguard Worker return 0;
620*8617a60dSAndroid Build Coastguard Worker } else if (!strcasecmp(name, "fw_tried")) {
621*8617a60dSAndroid Build Coastguard Worker StrCopy(dest,
622*8617a60dSAndroid Build Coastguard Worker vb2_get_nv_storage(VB2_NV_FW_TRIED) ? "B" : "A",
623*8617a60dSAndroid Build Coastguard Worker size);
624*8617a60dSAndroid Build Coastguard Worker return 0;
625*8617a60dSAndroid Build Coastguard Worker } else if (!strcasecmp(name, "fw_result")) {
626*8617a60dSAndroid Build Coastguard Worker int v = vb2_get_nv_storage(VB2_NV_FW_RESULT);
627*8617a60dSAndroid Build Coastguard Worker if (v < ARRAY_SIZE(fw_results))
628*8617a60dSAndroid Build Coastguard Worker StrCopy(dest, fw_results[v], size);
629*8617a60dSAndroid Build Coastguard Worker else
630*8617a60dSAndroid Build Coastguard Worker StrCopy(dest, "unknown", size);
631*8617a60dSAndroid Build Coastguard Worker return 0;
632*8617a60dSAndroid Build Coastguard Worker } else if (!strcasecmp(name, "fw_prev_tried")) {
633*8617a60dSAndroid Build Coastguard Worker StrCopy(dest,
634*8617a60dSAndroid Build Coastguard Worker vb2_get_nv_storage(VB2_NV_FW_PREV_TRIED) ? "B" : "A",
635*8617a60dSAndroid Build Coastguard Worker size);
636*8617a60dSAndroid Build Coastguard Worker return 0;
637*8617a60dSAndroid Build Coastguard Worker } else if (!strcasecmp(name, "fw_prev_result")) {
638*8617a60dSAndroid Build Coastguard Worker int v = vb2_get_nv_storage(VB2_NV_FW_PREV_RESULT);
639*8617a60dSAndroid Build Coastguard Worker if (v < ARRAY_SIZE(fw_results))
640*8617a60dSAndroid Build Coastguard Worker StrCopy(dest, fw_results[v], size);
641*8617a60dSAndroid Build Coastguard Worker else
642*8617a60dSAndroid Build Coastguard Worker StrCopy(dest, "unknown", size);
643*8617a60dSAndroid Build Coastguard Worker return 0;
644*8617a60dSAndroid Build Coastguard Worker } else if (!strcasecmp(name,"dev_default_boot")) {
645*8617a60dSAndroid Build Coastguard Worker int v = vb2_get_nv_storage(VB2_NV_DEV_DEFAULT_BOOT);
646*8617a60dSAndroid Build Coastguard Worker if (v < ARRAY_SIZE(default_boot))
647*8617a60dSAndroid Build Coastguard Worker StrCopy(dest, default_boot[v], size);
648*8617a60dSAndroid Build Coastguard Worker else
649*8617a60dSAndroid Build Coastguard Worker StrCopy(dest, "unknown", size);
650*8617a60dSAndroid Build Coastguard Worker return 0;
651*8617a60dSAndroid Build Coastguard Worker } else if (!strcasecmp(name, "minios_priority")) {
652*8617a60dSAndroid Build Coastguard Worker StrCopy(dest,
653*8617a60dSAndroid Build Coastguard Worker vb2_get_nv_storage(VB2_NV_MINIOS_PRIORITY) ?"B" : "A",
654*8617a60dSAndroid Build Coastguard Worker size);
655*8617a60dSAndroid Build Coastguard Worker return 0;
656*8617a60dSAndroid Build Coastguard Worker }
657*8617a60dSAndroid Build Coastguard Worker
658*8617a60dSAndroid Build Coastguard Worker return -1;
659*8617a60dSAndroid Build Coastguard Worker }
660*8617a60dSAndroid Build Coastguard Worker
VbSetSystemPropertyIntInternal(const char * name,int value)661*8617a60dSAndroid Build Coastguard Worker static int VbSetSystemPropertyIntInternal(const char *name, int value)
662*8617a60dSAndroid Build Coastguard Worker {
663*8617a60dSAndroid Build Coastguard Worker /* Check architecture-dependent properties first */
664*8617a60dSAndroid Build Coastguard Worker
665*8617a60dSAndroid Build Coastguard Worker if (0 == VbSetArchPropertyInt(name, value))
666*8617a60dSAndroid Build Coastguard Worker return 0;
667*8617a60dSAndroid Build Coastguard Worker
668*8617a60dSAndroid Build Coastguard Worker /* NV storage values */
669*8617a60dSAndroid Build Coastguard Worker if (!strcasecmp(name,"nvram_cleared")) {
670*8617a60dSAndroid Build Coastguard Worker /* Can only clear this flag; it's set inside the NV storage
671*8617a60dSAndroid Build Coastguard Worker * library. */
672*8617a60dSAndroid Build Coastguard Worker return vb2_set_nv_storage(VB2_NV_KERNEL_SETTINGS_RESET, 0);
673*8617a60dSAndroid Build Coastguard Worker } else if (!strcasecmp(name,"recovery_request")) {
674*8617a60dSAndroid Build Coastguard Worker return vb2_set_nv_storage(VB2_NV_RECOVERY_REQUEST, value);
675*8617a60dSAndroid Build Coastguard Worker } else if (!strcasecmp(name,"diagnostic_request")) {
676*8617a60dSAndroid Build Coastguard Worker return vb2_set_nv_storage(VB2_NV_DIAG_REQUEST, value);
677*8617a60dSAndroid Build Coastguard Worker } else if (!strcasecmp(name,"recovery_subcode")) {
678*8617a60dSAndroid Build Coastguard Worker return vb2_set_nv_storage(VB2_NV_RECOVERY_SUBCODE, value);
679*8617a60dSAndroid Build Coastguard Worker } else if (!strcasecmp(name,"dbg_reset")) {
680*8617a60dSAndroid Build Coastguard Worker return vb2_set_nv_storage(VB2_NV_DEBUG_RESET_MODE, value);
681*8617a60dSAndroid Build Coastguard Worker } else if (!strcasecmp(name,"disable_dev_request")) {
682*8617a60dSAndroid Build Coastguard Worker return vb2_set_nv_storage(VB2_NV_DISABLE_DEV_REQUEST, value);
683*8617a60dSAndroid Build Coastguard Worker } else if (!strcasecmp(name,"clear_tpm_owner_request")) {
684*8617a60dSAndroid Build Coastguard Worker if (EXTERNAL_TPM_CLEAR_REQUEST && CheckFwType("nonchrome")) {
685*8617a60dSAndroid Build Coastguard Worker const char *const argv[] = {
686*8617a60dSAndroid Build Coastguard Worker TPM_CLEAR_REQUEST_EXEC_NAME,
687*8617a60dSAndroid Build Coastguard Worker value ? "1" : "0",
688*8617a60dSAndroid Build Coastguard Worker NULL,
689*8617a60dSAndroid Build Coastguard Worker };
690*8617a60dSAndroid Build Coastguard Worker return subprocess_run(argv, &subprocess_null, &subprocess_null,
691*8617a60dSAndroid Build Coastguard Worker &subprocess_null);
692*8617a60dSAndroid Build Coastguard Worker } else {
693*8617a60dSAndroid Build Coastguard Worker return vb2_set_nv_storage(
694*8617a60dSAndroid Build Coastguard Worker VB2_NV_CLEAR_TPM_OWNER_REQUEST, value);
695*8617a60dSAndroid Build Coastguard Worker }
696*8617a60dSAndroid Build Coastguard Worker } else if (!strcasecmp(name,"clear_tpm_owner_done")) {
697*8617a60dSAndroid Build Coastguard Worker /* Can only clear this flag; it's set by firmware. */
698*8617a60dSAndroid Build Coastguard Worker return vb2_set_nv_storage(VB2_NV_CLEAR_TPM_OWNER_DONE, 0);
699*8617a60dSAndroid Build Coastguard Worker } else if (!strcasecmp(name,"fw_try_count")) {
700*8617a60dSAndroid Build Coastguard Worker return vb2_set_nv_storage(VB2_NV_TRY_COUNT, value);
701*8617a60dSAndroid Build Coastguard Worker } else if (!strcasecmp(name,"display_request")) {
702*8617a60dSAndroid Build Coastguard Worker return vb2_set_nv_storage(VB2_NV_DISPLAY_REQUEST, value);
703*8617a60dSAndroid Build Coastguard Worker } else if (!strcasecmp(name,"wipeout_request")) {
704*8617a60dSAndroid Build Coastguard Worker /* Can only clear this flag, set only by firmware. */
705*8617a60dSAndroid Build Coastguard Worker return vb2_set_nv_storage(VB2_NV_REQ_WIPEOUT, 0);
706*8617a60dSAndroid Build Coastguard Worker } else if (!strcasecmp(name,"backup_nvram_request")) {
707*8617a60dSAndroid Build Coastguard Worker /* Best-effort only, since it requires firmware and TPM
708*8617a60dSAndroid Build Coastguard Worker * support. */
709*8617a60dSAndroid Build Coastguard Worker return vb2_set_nv_storage(VB2_NV_BACKUP_NVRAM_REQUEST, value);
710*8617a60dSAndroid Build Coastguard Worker } else if (!strcasecmp(name,"fwupdate_tries")) {
711*8617a60dSAndroid Build Coastguard Worker int kern_nv = vb2_get_nv_storage(VB2_NV_KERNEL_FIELD);
712*8617a60dSAndroid Build Coastguard Worker if (kern_nv == -1)
713*8617a60dSAndroid Build Coastguard Worker return -1;
714*8617a60dSAndroid Build Coastguard Worker kern_nv &= ~KERN_NV_FWUPDATE_TRIES_MASK;
715*8617a60dSAndroid Build Coastguard Worker kern_nv |= (value & KERN_NV_FWUPDATE_TRIES_MASK);
716*8617a60dSAndroid Build Coastguard Worker return vb2_set_nv_storage_with_backup(
717*8617a60dSAndroid Build Coastguard Worker VB2_NV_KERNEL_FIELD, kern_nv);
718*8617a60dSAndroid Build Coastguard Worker } else if (!strcasecmp(name,"block_devmode")) {
719*8617a60dSAndroid Build Coastguard Worker int kern_nv = vb2_get_nv_storage(VB2_NV_KERNEL_FIELD);
720*8617a60dSAndroid Build Coastguard Worker if (kern_nv == -1)
721*8617a60dSAndroid Build Coastguard Worker return -1;
722*8617a60dSAndroid Build Coastguard Worker kern_nv &= ~KERN_NV_BLOCK_DEVMODE_FLAG;
723*8617a60dSAndroid Build Coastguard Worker if (value)
724*8617a60dSAndroid Build Coastguard Worker kern_nv |= KERN_NV_BLOCK_DEVMODE_FLAG;
725*8617a60dSAndroid Build Coastguard Worker return vb2_set_nv_storage_with_backup(
726*8617a60dSAndroid Build Coastguard Worker VB2_NV_KERNEL_FIELD, kern_nv);
727*8617a60dSAndroid Build Coastguard Worker } else if (!strcasecmp(name,"tpm_attack")) {
728*8617a60dSAndroid Build Coastguard Worker /* This value should only be read and cleared, but we allow
729*8617a60dSAndroid Build Coastguard Worker * setting it to 1 for testing. */
730*8617a60dSAndroid Build Coastguard Worker int kern_nv = vb2_get_nv_storage(VB2_NV_KERNEL_FIELD);
731*8617a60dSAndroid Build Coastguard Worker if (kern_nv == -1)
732*8617a60dSAndroid Build Coastguard Worker return -1;
733*8617a60dSAndroid Build Coastguard Worker kern_nv &= ~KERN_NV_TPM_ATTACK_FLAG;
734*8617a60dSAndroid Build Coastguard Worker if (value)
735*8617a60dSAndroid Build Coastguard Worker kern_nv |= KERN_NV_TPM_ATTACK_FLAG;
736*8617a60dSAndroid Build Coastguard Worker return vb2_set_nv_storage_with_backup(
737*8617a60dSAndroid Build Coastguard Worker VB2_NV_KERNEL_FIELD, kern_nv);
738*8617a60dSAndroid Build Coastguard Worker } else if (!strcasecmp(name,"loc_idx")) {
739*8617a60dSAndroid Build Coastguard Worker return vb2_set_nv_storage_with_backup(
740*8617a60dSAndroid Build Coastguard Worker VB2_NV_LOCALIZATION_INDEX, value);
741*8617a60dSAndroid Build Coastguard Worker } else if (!strcasecmp(name,"dev_boot_usb")) {
742*8617a60dSAndroid Build Coastguard Worker return vb2_set_nv_storage_with_backup(
743*8617a60dSAndroid Build Coastguard Worker VB2_NV_DEV_BOOT_EXTERNAL, value);
744*8617a60dSAndroid Build Coastguard Worker } else if (!strcasecmp(name,"dev_boot_altfw") ||
745*8617a60dSAndroid Build Coastguard Worker !strcasecmp(name,"dev_boot_legacy")) {
746*8617a60dSAndroid Build Coastguard Worker return vb2_set_nv_storage_with_backup(
747*8617a60dSAndroid Build Coastguard Worker VB2_NV_DEV_BOOT_ALTFW, value);
748*8617a60dSAndroid Build Coastguard Worker } else if (!strcasecmp(name,"dev_boot_signed_only")) {
749*8617a60dSAndroid Build Coastguard Worker return vb2_set_nv_storage_with_backup(
750*8617a60dSAndroid Build Coastguard Worker VB2_NV_DEV_BOOT_SIGNED_ONLY, value);
751*8617a60dSAndroid Build Coastguard Worker } else if (!strcasecmp(name, "dev_enable_udc")) {
752*8617a60dSAndroid Build Coastguard Worker return vb2_set_nv_storage_with_backup(
753*8617a60dSAndroid Build Coastguard Worker VB2_NV_DEV_ENABLE_UDC, value);
754*8617a60dSAndroid Build Coastguard Worker } else if (!strcasecmp(name, "boot_on_ac_detect")) {
755*8617a60dSAndroid Build Coastguard Worker return vb2_set_nv_storage_with_backup(
756*8617a60dSAndroid Build Coastguard Worker VB2_NV_BOOT_ON_AC_DETECT, value);
757*8617a60dSAndroid Build Coastguard Worker } else if (!strcasecmp(name, "try_ro_sync")) {
758*8617a60dSAndroid Build Coastguard Worker return vb2_set_nv_storage_with_backup(
759*8617a60dSAndroid Build Coastguard Worker VB2_NV_TRY_RO_SYNC, value);
760*8617a60dSAndroid Build Coastguard Worker } else if (!strcasecmp(name, "battery_cutoff_request")) {
761*8617a60dSAndroid Build Coastguard Worker return vb2_set_nv_storage(VB2_NV_BATTERY_CUTOFF_REQUEST, value);
762*8617a60dSAndroid Build Coastguard Worker } else if (!strcasecmp(name,"kernel_max_rollforward")) {
763*8617a60dSAndroid Build Coastguard Worker return vb2_set_nv_storage(VB2_NV_KERNEL_MAX_ROLLFORWARD, value);
764*8617a60dSAndroid Build Coastguard Worker } else if (!strcasecmp(name, "post_ec_sync_delay")) {
765*8617a60dSAndroid Build Coastguard Worker return vb2_set_nv_storage(VB2_NV_POST_EC_SYNC_DELAY, value);
766*8617a60dSAndroid Build Coastguard Worker }
767*8617a60dSAndroid Build Coastguard Worker
768*8617a60dSAndroid Build Coastguard Worker return -1;
769*8617a60dSAndroid Build Coastguard Worker }
770*8617a60dSAndroid Build Coastguard Worker
VbSetSystemPropertyInt(const char * name,int value)771*8617a60dSAndroid Build Coastguard Worker int VbSetSystemPropertyInt(const char *name, int value)
772*8617a60dSAndroid Build Coastguard Worker {
773*8617a60dSAndroid Build Coastguard Worker int result = -1;
774*8617a60dSAndroid Build Coastguard Worker int lock_fd;
775*8617a60dSAndroid Build Coastguard Worker
776*8617a60dSAndroid Build Coastguard Worker lock_fd = AcquireCrossystemLock();
777*8617a60dSAndroid Build Coastguard Worker if (lock_fd < 0)
778*8617a60dSAndroid Build Coastguard Worker return -1;
779*8617a60dSAndroid Build Coastguard Worker
780*8617a60dSAndroid Build Coastguard Worker result = VbSetSystemPropertyIntInternal(name, value);
781*8617a60dSAndroid Build Coastguard Worker
782*8617a60dSAndroid Build Coastguard Worker if (ReleaseCrossystemLock(lock_fd) < 0)
783*8617a60dSAndroid Build Coastguard Worker return -1;
784*8617a60dSAndroid Build Coastguard Worker
785*8617a60dSAndroid Build Coastguard Worker return result;
786*8617a60dSAndroid Build Coastguard Worker }
787*8617a60dSAndroid Build Coastguard Worker
VbSetSystemPropertyStringInternal(const char * name,const char * value)788*8617a60dSAndroid Build Coastguard Worker static int VbSetSystemPropertyStringInternal(const char *name,
789*8617a60dSAndroid Build Coastguard Worker const char *value)
790*8617a60dSAndroid Build Coastguard Worker {
791*8617a60dSAndroid Build Coastguard Worker /* Chain to architecture-dependent properties */
792*8617a60dSAndroid Build Coastguard Worker if (0 == VbSetArchPropertyString(name, value))
793*8617a60dSAndroid Build Coastguard Worker return 0;
794*8617a60dSAndroid Build Coastguard Worker
795*8617a60dSAndroid Build Coastguard Worker if (!strcasecmp(name, "fw_try_next")) {
796*8617a60dSAndroid Build Coastguard Worker if (!strcasecmp(value, "A"))
797*8617a60dSAndroid Build Coastguard Worker return vb2_set_nv_storage(VB2_NV_TRY_NEXT, 0);
798*8617a60dSAndroid Build Coastguard Worker else if (!strcasecmp(value, "B"))
799*8617a60dSAndroid Build Coastguard Worker return vb2_set_nv_storage(VB2_NV_TRY_NEXT, 1);
800*8617a60dSAndroid Build Coastguard Worker else
801*8617a60dSAndroid Build Coastguard Worker return -1;
802*8617a60dSAndroid Build Coastguard Worker } else if (!strcasecmp(name, "minios_priority")) {
803*8617a60dSAndroid Build Coastguard Worker if (!strcasecmp(value, "A"))
804*8617a60dSAndroid Build Coastguard Worker return vb2_set_nv_storage(VB2_NV_MINIOS_PRIORITY, 0);
805*8617a60dSAndroid Build Coastguard Worker else if (!strcasecmp(value, "B"))
806*8617a60dSAndroid Build Coastguard Worker return vb2_set_nv_storage(VB2_NV_MINIOS_PRIORITY, 1);
807*8617a60dSAndroid Build Coastguard Worker else
808*8617a60dSAndroid Build Coastguard Worker return -1;
809*8617a60dSAndroid Build Coastguard Worker } else if (!strcasecmp(name, "fw_result")) {
810*8617a60dSAndroid Build Coastguard Worker int i;
811*8617a60dSAndroid Build Coastguard Worker
812*8617a60dSAndroid Build Coastguard Worker for (i = 0; i < ARRAY_SIZE(fw_results); i++) {
813*8617a60dSAndroid Build Coastguard Worker if (!strcasecmp(value, fw_results[i]))
814*8617a60dSAndroid Build Coastguard Worker return vb2_set_nv_storage(VB2_NV_FW_RESULT, i);
815*8617a60dSAndroid Build Coastguard Worker }
816*8617a60dSAndroid Build Coastguard Worker return -1;
817*8617a60dSAndroid Build Coastguard Worker } else if (!strcasecmp(name, "dev_default_boot")) {
818*8617a60dSAndroid Build Coastguard Worker int i;
819*8617a60dSAndroid Build Coastguard Worker
820*8617a60dSAndroid Build Coastguard Worker /* "legacy" term deprecated in favour of "altfw"
821*8617a60dSAndroid Build Coastguard Worker (see: b/179458327) */
822*8617a60dSAndroid Build Coastguard Worker if (!strcasecmp(value, "legacy")) {
823*8617a60dSAndroid Build Coastguard Worker fprintf(stderr,
824*8617a60dSAndroid Build Coastguard Worker "!!!\n"
825*8617a60dSAndroid Build Coastguard Worker "!!! PLEASE USE 'altfw' INSTEAD OF 'legacy'\n"
826*8617a60dSAndroid Build Coastguard Worker "!!!\n");
827*8617a60dSAndroid Build Coastguard Worker value = "altfw";
828*8617a60dSAndroid Build Coastguard Worker }
829*8617a60dSAndroid Build Coastguard Worker
830*8617a60dSAndroid Build Coastguard Worker for (i = 0; i < ARRAY_SIZE(default_boot); i++) {
831*8617a60dSAndroid Build Coastguard Worker if (!strcasecmp(value, default_boot[i]))
832*8617a60dSAndroid Build Coastguard Worker return vb2_set_nv_storage(
833*8617a60dSAndroid Build Coastguard Worker VB2_NV_DEV_DEFAULT_BOOT, i);
834*8617a60dSAndroid Build Coastguard Worker }
835*8617a60dSAndroid Build Coastguard Worker return -1;
836*8617a60dSAndroid Build Coastguard Worker }
837*8617a60dSAndroid Build Coastguard Worker
838*8617a60dSAndroid Build Coastguard Worker return -1;
839*8617a60dSAndroid Build Coastguard Worker }
840*8617a60dSAndroid Build Coastguard Worker
VbSetSystemPropertyString(const char * name,const char * value)841*8617a60dSAndroid Build Coastguard Worker int VbSetSystemPropertyString(const char *name, const char *value)
842*8617a60dSAndroid Build Coastguard Worker {
843*8617a60dSAndroid Build Coastguard Worker int result = -1;
844*8617a60dSAndroid Build Coastguard Worker int lock_fd;
845*8617a60dSAndroid Build Coastguard Worker
846*8617a60dSAndroid Build Coastguard Worker lock_fd = AcquireCrossystemLock();
847*8617a60dSAndroid Build Coastguard Worker if (lock_fd < 0)
848*8617a60dSAndroid Build Coastguard Worker return -1;
849*8617a60dSAndroid Build Coastguard Worker
850*8617a60dSAndroid Build Coastguard Worker result = VbSetSystemPropertyStringInternal(name, value);
851*8617a60dSAndroid Build Coastguard Worker
852*8617a60dSAndroid Build Coastguard Worker if (ReleaseCrossystemLock(lock_fd) < 0)
853*8617a60dSAndroid Build Coastguard Worker return -1;
854*8617a60dSAndroid Build Coastguard Worker
855*8617a60dSAndroid Build Coastguard Worker return result;
856*8617a60dSAndroid Build Coastguard Worker }
857*8617a60dSAndroid Build Coastguard Worker
858*8617a60dSAndroid Build Coastguard Worker /**
859*8617a60dSAndroid Build Coastguard Worker * Get index of the last valid VBNV entry.
860*8617a60dSAndroid Build Coastguard Worker *
861*8617a60dSAndroid Build Coastguard Worker * @param buf Pointer to the buffer containing VBNV entries.
862*8617a60dSAndroid Build Coastguard Worker * @param buf_sz Size of the buffer.
863*8617a60dSAndroid Build Coastguard Worker * @param vbnv_size The size of a single VBNV entry for this device.
864*8617a60dSAndroid Build Coastguard Worker *
865*8617a60dSAndroid Build Coastguard Worker * @return The index of the last valid VBNV entry found by binary search,
866*8617a60dSAndroid Build Coastguard Worker * or -1 if not found. When the FMAP region is corrupted (used entries occurring
867*8617a60dSAndroid Build Coastguard Worker * after blank ones), the returned index may not point to the last VBNV
868*8617a60dSAndroid Build Coastguard Worker * entry.
869*8617a60dSAndroid Build Coastguard Worker */
vb2_nv_index(const uint8_t * buf,uint32_t buf_sz,int vbnv_size)870*8617a60dSAndroid Build Coastguard Worker static int vb2_nv_index(const uint8_t *buf, uint32_t buf_sz, int vbnv_size)
871*8617a60dSAndroid Build Coastguard Worker {
872*8617a60dSAndroid Build Coastguard Worker int used_below, blank_above;
873*8617a60dSAndroid Build Coastguard Worker uint8_t blank[VB2_NVDATA_SIZE_V2];
874*8617a60dSAndroid Build Coastguard Worker
875*8617a60dSAndroid Build Coastguard Worker /* The size of the buffer should be an even multiple of the
876*8617a60dSAndroid Build Coastguard Worker VBNV size. */
877*8617a60dSAndroid Build Coastguard Worker if (buf_sz % vbnv_size != 0) {
878*8617a60dSAndroid Build Coastguard Worker VB2_DIE("The VBNV in flash (%u bytes) is not an even multiple "
879*8617a60dSAndroid Build Coastguard Worker "of the VBNV size (%u bytes). This is likely a "
880*8617a60dSAndroid Build Coastguard Worker "firmware bug.\n", buf_sz, vbnv_size);
881*8617a60dSAndroid Build Coastguard Worker }
882*8617a60dSAndroid Build Coastguard Worker
883*8617a60dSAndroid Build Coastguard Worker memset(blank, 0xff, sizeof(blank));
884*8617a60dSAndroid Build Coastguard Worker
885*8617a60dSAndroid Build Coastguard Worker /* To match the searching algorithm in firmware, perform binary search
886*8617a60dSAndroid Build Coastguard Worker instead of linear search to find the last used index. */
887*8617a60dSAndroid Build Coastguard Worker used_below = 0;
888*8617a60dSAndroid Build Coastguard Worker blank_above = buf_sz / vbnv_size;
889*8617a60dSAndroid Build Coastguard Worker while (used_below + 1 < blank_above) {
890*8617a60dSAndroid Build Coastguard Worker int mid = (used_below + blank_above) / 2;
891*8617a60dSAndroid Build Coastguard Worker if (!memcmp(blank, &buf[mid * vbnv_size], vbnv_size))
892*8617a60dSAndroid Build Coastguard Worker blank_above = mid;
893*8617a60dSAndroid Build Coastguard Worker else
894*8617a60dSAndroid Build Coastguard Worker used_below = mid;
895*8617a60dSAndroid Build Coastguard Worker }
896*8617a60dSAndroid Build Coastguard Worker
897*8617a60dSAndroid Build Coastguard Worker /* Check the all blank case. */
898*8617a60dSAndroid Build Coastguard Worker if (used_below == 0 &&
899*8617a60dSAndroid Build Coastguard Worker !memcmp(blank, &buf[used_below * vbnv_size], vbnv_size)) {
900*8617a60dSAndroid Build Coastguard Worker fprintf(stderr, "VBNV is uninitialized.\n");
901*8617a60dSAndroid Build Coastguard Worker return -1;
902*8617a60dSAndroid Build Coastguard Worker }
903*8617a60dSAndroid Build Coastguard Worker
904*8617a60dSAndroid Build Coastguard Worker return used_below;
905*8617a60dSAndroid Build Coastguard Worker }
906*8617a60dSAndroid Build Coastguard Worker
907*8617a60dSAndroid Build Coastguard Worker /**
908*8617a60dSAndroid Build Coastguard Worker * Check whether the VBNV entries are corrupted.
909*8617a60dSAndroid Build Coastguard Worker *
910*8617a60dSAndroid Build Coastguard Worker * @param buf Pointer to the buffer containing VBNV entries.
911*8617a60dSAndroid Build Coastguard Worker * @param buf_sz Size of the buffer.
912*8617a60dSAndroid Build Coastguard Worker * @param vbnv_size The size of a single VBNV entry for this device.
913*8617a60dSAndroid Build Coastguard Worker *
914*8617a60dSAndroid Build Coastguard Worker * @return True if there are used entries occurring after blank ones, or false
915*8617a60dSAndroid Build Coastguard Worker * otherwise.
916*8617a60dSAndroid Build Coastguard Worker */
is_corrupted(const uint8_t * buf,uint32_t buf_sz,int vbnv_size)917*8617a60dSAndroid Build Coastguard Worker static bool is_corrupted(const uint8_t *buf, uint32_t buf_sz, int vbnv_size)
918*8617a60dSAndroid Build Coastguard Worker {
919*8617a60dSAndroid Build Coastguard Worker uint8_t blank[VB2_NVDATA_SIZE_V2];
920*8617a60dSAndroid Build Coastguard Worker bool found_blank = false;
921*8617a60dSAndroid Build Coastguard Worker
922*8617a60dSAndroid Build Coastguard Worker memset(blank, 0xff, sizeof(blank));
923*8617a60dSAndroid Build Coastguard Worker
924*8617a60dSAndroid Build Coastguard Worker for (int i = 0; i < buf_sz / vbnv_size; i++) {
925*8617a60dSAndroid Build Coastguard Worker if (!memcmp(blank, &buf[i * vbnv_size], vbnv_size))
926*8617a60dSAndroid Build Coastguard Worker found_blank = true;
927*8617a60dSAndroid Build Coastguard Worker else if (found_blank)
928*8617a60dSAndroid Build Coastguard Worker return true;
929*8617a60dSAndroid Build Coastguard Worker }
930*8617a60dSAndroid Build Coastguard Worker
931*8617a60dSAndroid Build Coastguard Worker return false;
932*8617a60dSAndroid Build Coastguard Worker }
933*8617a60dSAndroid Build Coastguard Worker
934*8617a60dSAndroid Build Coastguard Worker #define VBNV_FMAP_REGION "RW_NVRAM"
935*8617a60dSAndroid Build Coastguard Worker
vb2_read_nv_storage_flashrom(struct vb2_context * ctx)936*8617a60dSAndroid Build Coastguard Worker int vb2_read_nv_storage_flashrom(struct vb2_context *ctx)
937*8617a60dSAndroid Build Coastguard Worker {
938*8617a60dSAndroid Build Coastguard Worker int index;
939*8617a60dSAndroid Build Coastguard Worker int vbnv_size = vb2_nv_get_size(ctx);
940*8617a60dSAndroid Build Coastguard Worker
941*8617a60dSAndroid Build Coastguard Worker struct firmware_image image = {
942*8617a60dSAndroid Build Coastguard Worker .programmer = FLASHROM_PROGRAMMER_INTERNAL_AP,
943*8617a60dSAndroid Build Coastguard Worker };
944*8617a60dSAndroid Build Coastguard Worker if (flashrom_read(&image, VBNV_FMAP_REGION))
945*8617a60dSAndroid Build Coastguard Worker return -1;
946*8617a60dSAndroid Build Coastguard Worker
947*8617a60dSAndroid Build Coastguard Worker index = vb2_nv_index(image.data, image.size, vbnv_size);
948*8617a60dSAndroid Build Coastguard Worker if (index < 0) {
949*8617a60dSAndroid Build Coastguard Worker free(image.data);
950*8617a60dSAndroid Build Coastguard Worker return -1;
951*8617a60dSAndroid Build Coastguard Worker }
952*8617a60dSAndroid Build Coastguard Worker
953*8617a60dSAndroid Build Coastguard Worker memcpy(ctx->nvdata, &image.data[index * vbnv_size], vbnv_size);
954*8617a60dSAndroid Build Coastguard Worker free(image.data);
955*8617a60dSAndroid Build Coastguard Worker return 0;
956*8617a60dSAndroid Build Coastguard Worker }
957*8617a60dSAndroid Build Coastguard Worker
vb2_write_nv_storage_flashrom(struct vb2_context * ctx)958*8617a60dSAndroid Build Coastguard Worker int vb2_write_nv_storage_flashrom(struct vb2_context *ctx)
959*8617a60dSAndroid Build Coastguard Worker {
960*8617a60dSAndroid Build Coastguard Worker int rv = 0;
961*8617a60dSAndroid Build Coastguard Worker int index;
962*8617a60dSAndroid Build Coastguard Worker bool corrupted;
963*8617a60dSAndroid Build Coastguard Worker int vbnv_size = vb2_nv_get_size(ctx);
964*8617a60dSAndroid Build Coastguard Worker
965*8617a60dSAndroid Build Coastguard Worker struct firmware_image image = {
966*8617a60dSAndroid Build Coastguard Worker .programmer = FLASHROM_PROGRAMMER_INTERNAL_AP,
967*8617a60dSAndroid Build Coastguard Worker };
968*8617a60dSAndroid Build Coastguard Worker if (flashrom_read(&image, VBNV_FMAP_REGION))
969*8617a60dSAndroid Build Coastguard Worker return -1;
970*8617a60dSAndroid Build Coastguard Worker
971*8617a60dSAndroid Build Coastguard Worker index = vb2_nv_index(image.data, image.size, vbnv_size) + 1;
972*8617a60dSAndroid Build Coastguard Worker corrupted = is_corrupted(image.data, image.size, vbnv_size);
973*8617a60dSAndroid Build Coastguard Worker
974*8617a60dSAndroid Build Coastguard Worker if (corrupted || index * vbnv_size == image.size) {
975*8617a60dSAndroid Build Coastguard Worker /* VBNV is corrupted or full. Erase and write at beginning. */
976*8617a60dSAndroid Build Coastguard Worker if (corrupted)
977*8617a60dSAndroid Build Coastguard Worker fprintf(stderr, "VBNV is corrupted; erasing %s\n",
978*8617a60dSAndroid Build Coastguard Worker VBNV_FMAP_REGION);
979*8617a60dSAndroid Build Coastguard Worker memset(image.data, 0xff, image.size);
980*8617a60dSAndroid Build Coastguard Worker index = 0;
981*8617a60dSAndroid Build Coastguard Worker }
982*8617a60dSAndroid Build Coastguard Worker
983*8617a60dSAndroid Build Coastguard Worker memcpy(&image.data[index * vbnv_size], ctx->nvdata, vbnv_size);
984*8617a60dSAndroid Build Coastguard Worker if (flashrom_write(&image, VBNV_FMAP_REGION)) {
985*8617a60dSAndroid Build Coastguard Worker rv = -1;
986*8617a60dSAndroid Build Coastguard Worker goto exit;
987*8617a60dSAndroid Build Coastguard Worker }
988*8617a60dSAndroid Build Coastguard Worker
989*8617a60dSAndroid Build Coastguard Worker exit:
990*8617a60dSAndroid Build Coastguard Worker free(image.data);
991*8617a60dSAndroid Build Coastguard Worker return rv;
992*8617a60dSAndroid Build Coastguard Worker }
993