xref: /aosp_15_r20/external/vboot_reference/tests/vb2_secdata_firmware_tests.c (revision 8617a60d3594060b7ecbd21bc622a7c14f3cf2bc)
1 /* Copyright 2014 The ChromiumOS Authors
2  * Use of this source code is governed by a BSD-style license that can be
3  * found in the LICENSE file.
4  *
5  * Tests for firmware secure storage library.
6  */
7 
8 #include "2api.h"
9 #include "2common.h"
10 #include "2crc8.h"
11 #include "2misc.h"
12 #include "2secdata.h"
13 #include "2secdata_struct.h"
14 #include "2sysincludes.h"
15 #include "common/tests.h"
16 
17 static uint8_t workbuf[VB2_FIRMWARE_WORKBUF_RECOMMENDED_SIZE]
18 	__attribute__((aligned(VB2_WORKBUF_ALIGN)));
19 static struct vb2_context *ctx;
20 static struct vb2_shared_data *sd;
21 static struct vb2_secdata_firmware *sec;
22 
reset_common_data(void)23 static void reset_common_data(void)
24 {
25 	memset(workbuf, 0xaa, sizeof(workbuf));
26 	TEST_SUCC(vb2api_init(workbuf, sizeof(workbuf), &ctx),
27 		  "vb2api_init failed");
28 
29 	sd = vb2_get_sd(ctx);
30 
31 	/* Most tests assume we have passed fw_phase1() */
32 	sd->status |= VB2_SD_STATUS_RECOVERY_DECIDED;
33 
34 	sec = (struct vb2_secdata_firmware *)ctx->secdata_firmware;
35 }
36 
test_changed(struct vb2_context * c,int changed,const char * why)37 static void test_changed(struct vb2_context *c, int changed, const char *why)
38 {
39 	if (changed)
40 		TEST_NEQ(c->flags & VB2_CONTEXT_SECDATA_FIRMWARE_CHANGED,
41 			 0, why);
42 	else
43 		TEST_EQ(c->flags & VB2_CONTEXT_SECDATA_FIRMWARE_CHANGED,
44 			0, why);
45 
46 	c->flags &= ~VB2_CONTEXT_SECDATA_FIRMWARE_CHANGED;
47 };
48 
secdata_firmware_test(void)49 static void secdata_firmware_test(void)
50 {
51 	uint32_t v = 1;
52 	reset_common_data();
53 
54 	/* Check size constant */
55 	TEST_EQ(VB2_SECDATA_FIRMWARE_SIZE, sizeof(struct vb2_secdata_firmware),
56 		"Struct size constant");
57 
58 	/* Blank data is invalid */
59 	memset(&ctx->secdata_firmware, 0xa6, sizeof(ctx->secdata_firmware));
60 	TEST_EQ(vb2api_secdata_firmware_check(ctx),
61 		VB2_ERROR_SECDATA_FIRMWARE_CRC, "Check blank CRC");
62 	TEST_EQ(vb2_secdata_firmware_init(ctx),
63 		VB2_ERROR_SECDATA_FIRMWARE_CRC, "Init blank CRC");
64 
65 	/* Ensure zeroed buffers are invalid (coreboot relies on this) */
66 	memset(&ctx->secdata_firmware, 0, sizeof(ctx->secdata_firmware));
67 	TEST_EQ(vb2_secdata_firmware_init(ctx),
68 		VB2_ERROR_SECDATA_FIRMWARE_VERSION,
69 		"Zeroed buffer (invalid version)");
70 
71 	/* Try with bad version */
72 	TEST_EQ(vb2api_secdata_firmware_create(ctx), VB2_SECDATA_FIRMWARE_SIZE,
73 		"Create");
74 	sec->struct_version -= 1;
75 	sec->crc8 = vb2_crc8(sec, offsetof(struct vb2_secdata_firmware, crc8));
76 	TEST_EQ(vb2api_secdata_firmware_check(ctx),
77 		VB2_ERROR_SECDATA_FIRMWARE_VERSION, "Check invalid version");
78 	TEST_EQ(vb2_secdata_firmware_init(ctx),
79 		VB2_ERROR_SECDATA_FIRMWARE_VERSION, "Init invalid version");
80 
81 	/* Create good data */
82 	vb2api_secdata_firmware_create(ctx);
83 	TEST_SUCC(vb2api_secdata_firmware_check(ctx), "Check created CRC");
84 	TEST_SUCC(vb2_secdata_firmware_init(ctx), "Init created CRC");
85 	TEST_NEQ(sd->status & VB2_SD_STATUS_SECDATA_FIRMWARE_INIT, 0,
86 		 "Init set SD status");
87 	sd->status &= ~VB2_SD_STATUS_SECDATA_FIRMWARE_INIT;
88 	test_changed(ctx, 1, "Create changes data");
89 
90 	/* Now corrupt it */
91 	ctx->secdata_firmware[2]++;
92 	TEST_EQ(vb2api_secdata_firmware_check(ctx),
93 		VB2_ERROR_SECDATA_FIRMWARE_CRC, "Check invalid CRC");
94 	TEST_EQ(vb2_secdata_firmware_init(ctx),
95 		VB2_ERROR_SECDATA_FIRMWARE_CRC, "Init invalid CRC");
96 
97 	/* Read/write flags */
98 	vb2api_secdata_firmware_create(ctx);
99 	vb2_secdata_firmware_init(ctx);
100 	ctx->flags = 0;
101 	v = vb2_secdata_firmware_get(ctx, VB2_SECDATA_FIRMWARE_FLAGS);
102 	TEST_EQ(v, 0, "Flags created 0");
103 	test_changed(ctx, 0, "Get doesn't change data");
104 	vb2_secdata_firmware_set(ctx, VB2_SECDATA_FIRMWARE_FLAGS, 0x12);
105 	test_changed(ctx, 1, "Set changes data");
106 	vb2_secdata_firmware_set(ctx, VB2_SECDATA_FIRMWARE_FLAGS, 0x12);
107 	test_changed(ctx, 0, "Set again doesn't change data");
108 	v = vb2_secdata_firmware_get(ctx, VB2_SECDATA_FIRMWARE_FLAGS);
109 	TEST_EQ(v, 0x12, "Flags changed");
110 	TEST_ABORT(vb2_secdata_firmware_set(ctx, VB2_SECDATA_FIRMWARE_FLAGS,
111 					    0x100),
112 		   "Bad flags");
113 
114 	/* Read/write versions */
115 	v = vb2_secdata_firmware_get(ctx, VB2_SECDATA_FIRMWARE_VERSIONS);
116 	TEST_EQ(v, 0, "Versions created 0");
117 	test_changed(ctx, 0, "Get doesn't change data");
118 	vb2_secdata_firmware_set(ctx, VB2_SECDATA_FIRMWARE_VERSIONS,
119 				 0x123456ff);
120 	test_changed(ctx, 1, "Set changes data");
121 	vb2_secdata_firmware_set(ctx, VB2_SECDATA_FIRMWARE_VERSIONS,
122 				 0x123456ff);
123 	test_changed(ctx, 0, "Set again doesn't change data");
124 	v = vb2_secdata_firmware_get(ctx, VB2_SECDATA_FIRMWARE_VERSIONS);
125 	TEST_EQ(v, 0x123456ff, "Versions changed");
126 
127 	/* Invalid field fails */
128 	TEST_ABORT(vb2_secdata_firmware_get(ctx, -1), "Get invalid");
129 	TEST_ABORT(vb2_secdata_firmware_set(ctx, -1, 456), "Set invalid");
130 	test_changed(ctx, 0, "Set invalid field doesn't change data");
131 
132 	/* Read/write uninitialized data fails */
133 	sd->status &= ~VB2_SD_STATUS_SECDATA_FIRMWARE_INIT;
134 	TEST_ABORT(vb2_secdata_firmware_get(ctx,
135 					    VB2_SECDATA_FIRMWARE_VERSIONS),
136 		   "Get uninitialized");
137 	test_changed(ctx, 0, "Get uninitialized doesn't change data");
138 	TEST_ABORT(vb2_secdata_firmware_set(ctx, VB2_SECDATA_FIRMWARE_VERSIONS,
139 					    0x123456ff),
140 		   "Set uninitialized");
141 	test_changed(ctx, 0, "Set uninitialized doesn't change data");
142 
143 	/* Read/write uninitialized in recovery mode */
144 	ctx->flags |= VB2_CONTEXT_RECOVERY_MODE;
145 	TEST_EQ(vb2_secdata_firmware_get(ctx, VB2_SECDATA_FIRMWARE_VERSIONS), 0,
146 		"Get uninitialized (recmode)");
147 	test_changed(ctx, 0, "Get uninitialized (recmode) doesn't change data");
148 	vb2_secdata_firmware_set(ctx, VB2_SECDATA_FIRMWARE_VERSIONS,
149 				 0x123456ff);
150 	test_changed(ctx, 0, "Set uninitialized (recmode) doesn't change data");
151 
152 	/* Read/write early in fw_phase1 */
153 	ctx->flags &= ~VB2_CONTEXT_RECOVERY_MODE;
154 	sd->status &= ~VB2_SD_STATUS_RECOVERY_DECIDED;
155 	TEST_EQ(vb2_secdata_firmware_get(ctx, VB2_SECDATA_FIRMWARE_VERSIONS), 0,
156 		"Get uninitialized (phase1)");
157 	test_changed(ctx, 0, "Get uninitialized (phase1) doesn't change data");
158 	vb2_secdata_firmware_set(ctx, VB2_SECDATA_FIRMWARE_VERSIONS,
159 				 0x123456ff);
160 	test_changed(ctx, 0, "Set uninitialized (phase1) doesn't change data");
161 }
162 
main(int argc,char * argv[])163 int main(int argc, char* argv[])
164 {
165 	secdata_firmware_test();
166 
167 	return gTestSuccess ? 0 : 255;
168 }
169