All of lore.kernel.org
 help / color / mirror / Atom feed
From: Ilias Apalodimas <ilias.apalodimas@linaro.org>
To: Sughosh Ganu <sughosh.ganu@linaro.org>
Cc: u-boot@lists.denx.de, Heinrich Schuchardt <xypron.glpk@gmx.de>,
	Takahiro Akashi <takahiro.akashi@linaro.org>,
	Patrick Delaunay <patrick.delaunay@foss.st.com>,
	Patrice Chotard <patrice.chotard@foss.st.com>,
	Simon Glass <sjg@chromium.org>, Tom Rini <trini@konsulko.com>,
	Etienne Carriere <etienne.carriere@linaro.org>,
	Jassi Brar <jaswinder.singh@linaro.org>
Subject: Re: [PATCH v15 09/15] FWU: Add boot time checks as highlighted by the FWU specification
Date: Fri, 21 Oct 2022 18:08:29 +0300	[thread overview]
Message-ID: <Y1K17eaqDaEeH5xW@hera> (raw)
In-Reply-To: <20221021124608.681387-10-sughosh.ganu@linaro.org>

Hi Sughosh,

>  
>  #include <linux/errno.h>
>  #include <linux/types.h>
> @@ -44,6 +53,96 @@ static int fwu_get_dev_mdata(struct udevice **dev, struct fwu_mdata *mdata)
>  	return ret;
>  }
>  
> +static int trial_counter_update(u16 *trial_state_ctr)
> +{
> +	bool delete;
> +	u32 var_attr;
> +	efi_status_t status;
> +	efi_uintn_t var_size;
> +
> +	delete = !trial_state_ctr ? true : false;
> +	var_size = !trial_state_ctr ? 0 : (efi_uintn_t)sizeof(*trial_state_ctr);
> +	var_attr = !trial_state_ctr ? 0 : EFI_VARIABLE_NON_VOLATILE |
> +		EFI_VARIABLE_BOOTSERVICE_ACCESS;
> +	status = efi_set_variable_int(u"TrialStateCtr",
> +				      &efi_global_variable_guid,
> +				      var_attr,
> +				      var_size, trial_state_ctr, false);
> +
> +	if ((delete && (status != EFI_NOT_FOUND &&
> +			status != EFI_SUCCESS)) ||
> +	    (!delete && status != EFI_SUCCESS))
> +		return -1;
> +
> +	return 0;
> +}
> +
> +static int trial_counter_read(u16 *trial_state_ctr)
> +{
> +	efi_status_t status;
> +	efi_uintn_t var_size;
> +
> +	var_size = (efi_uintn_t)sizeof(trial_state_ctr);
> +	status = efi_get_variable_int(u"TrialStateCtr",
> +				      &efi_global_variable_guid,
> +				      NULL,
> +				      &var_size, trial_state_ctr,
> +				      NULL);
> +	if (status != EFI_SUCCESS) {
> +		log_err("Unable to read TrialStateCtr variable\n");
> +		return -1;
> +	}
> +
> +	return 0;
> +}
> +
> +static int fwu_trial_count_update(void)
> +{
> +	int ret;
> +	u16 trial_state_ctr;
> +
> +	ret = trial_counter_read(&trial_state_ctr);
> +	if (ret) {
> +		log_debug("Unable to read trial_state_ctr\n");
> +		goto out;
> +	}
> +
> +	++trial_state_ctr;
> +	if (trial_state_ctr > CONFIG_FWU_TRIAL_STATE_CNT) {
> +		log_info("Trial State count exceeded. Revert back to previous_active_index\n");
> +		ret = fwu_revert_boot_index();
> +		if (ret)
> +			log_err("Unable to revert active_index\n");
> +		ret = 1;
> +	} else {
> +		ret = trial_counter_update(&trial_state_ctr);
> +		if (ret)
> +			log_err("Unable to increment TrialStateCtr variable\n");
> +	}
> +
> +out:
> +	return ret;
> +}
> +
> +static int in_trial_state(struct fwu_mdata *mdata)
> +{
> +	u32 i, active_bank;
> +	struct fwu_image_entry *img_entry;
> +	struct fwu_image_bank_info *img_bank_info;
> +
> +	active_bank = mdata->active_index;
> +	img_entry = &mdata->img_entry[0];
> +	for (i = 0; i < CONFIG_FWU_NUM_IMAGES_PER_BANK; i++) {
> +		img_bank_info = &img_entry[i].img_bank_info[active_bank];
> +		if (!img_bank_info->accepted) {
> +			log_info("System booting in Trial State\n");
> +			return 1;
> +		}
> +	}
> +
> +	return 0;
> +}
> +
>  static int fwu_get_image_type_id(u8 *image_index, efi_guid_t *image_type_id)
>  {
>  	u8 index;
> @@ -499,3 +598,94 @@ __weak int fwu_plat_get_update_index(uint *update_idx)
>  
>  	return ret;
>  }
> +
> +/**
> + * fwu_update_checks_pass() - Check if FWU update can be done
> + *
> + * Check if the FWU update can be executed. The updates are
> + * allowed only when the platform is not in Trial State and
> + * the boot time checks have passed
> + *
> + * Return: 1 if OK, 0 if checks do not pass
> + *
> + */
> +u8 fwu_update_checks_pass(void)
> +{
> +	return !in_trial && boottime_check;
> +}
> +
> +/**
> + * fwu_empty_capsule_checks_pass() - Check if empty capsule can be processed
> + *
> + * Check if the empty capsule can be processed to either accept or revert
> + * an earlier executed update. The empty capsules need to be processed
> + * only when the platform is in Trial State and the boot time checks have
> + * passed
> + *
> + * Return: 1 if OK, 0 if not to be allowed
> + *
> + */
> +u8 fwu_empty_capsule_checks_pass(void)
> +{
> +	return in_trial && boottime_check;
> +}
> +
> +static int fwu_boottime_checks(void *ctx, struct event *event)
> +{
> +	int ret;
> +	u32 boot_idx, active_idx;
> +	struct udevice *dev;
> +	struct fwu_mdata mdata = { 0 };
> +
> +	ret = fwu_check_mdata_validity();
> +	if (ret)
> +		return 0;
> +
> +	/*
> +	 * Get the Boot Index, i.e. the bank from
> +	 * which the platform has booted. This value
> +	 * gets passed from the ealier stage bootloader
> +	 * which booted u-boot, e.g. tf-a. If the
> +	 * boot index is not the same as the
> +	 * active_index read from the FWU metadata,
> +	 * update the active_index.
> +	 */
> +	fwu_plat_get_bootidx(&boot_idx);
> +	if (boot_idx >= CONFIG_FWU_NUM_BANKS) {
> +		log_err("Received incorrect value of boot_index\n");
> +		return 0;
> +	}
> +
> +	ret = fwu_get_active_index(&active_idx);
> +	if (ret) {
> +		log_err("Unable to read active_index\n");
> +		return 0;
> +	}
> +
> +	if (boot_idx != active_idx) {
> +		log_info("Boot idx %u is not matching active idx %u, changing active_idx\n",
> +			 boot_idx, active_idx);
> +		ret = fwu_set_active_index(boot_idx);
> +		if (!ret)
> +			boottime_check = 1;
> +
> +		return 0;
> +	}
> +
> +	if (efi_init_obj_list() != EFI_SUCCESS)
> +		return 0;
> +
> +	ret = fwu_get_dev_mdata(&dev, &mdata);
> +	if (ret)
> +		return ret;
> +
> +	in_trial = in_trial_state(&mdata);
> +	if (!in_trial || (ret = fwu_trial_count_update()) > 0)

Why do we need to assign ret here?
if (!in_trial || !fwu_trial_count_update()) should be enough

> +		ret = trial_counter_update(NULL);
> +
> +	if (!ret)
> +		boottime_check = 1;
> +
> +	return 0;
> +}
> +EVENT_SPY(EVT_MAIN_LOOP, fwu_boottime_checks);
> -- 
> 2.34.1
> 

With that
Acked-by: Ilias Apalodimas <ilias.apalodimas@linaro.org>


  reply	other threads:[~2022-10-21 15:08 UTC|newest]

Thread overview: 27+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2022-10-21 12:45 [PATCH v15 00/15] FWU: Add FWU Multi Bank Update feature support Sughosh Ganu
2022-10-21 12:45 ` [PATCH v15 01/15] dt/bindings: Add bindings for GPT based FWU Metadata storage device Sughosh Ganu
2022-11-01 14:34   ` Tom Rini
2022-10-21 12:45 ` [PATCH v15 02/15] FWU: Add FWU metadata structure and driver for accessing metadata Sughosh Ganu
2022-10-21 12:45 ` [PATCH v15 03/15] FWU: Add FWU metadata access driver for GPT partitioned block devices Sughosh Ganu
2022-10-21 15:03   ` Ilias Apalodimas
2022-10-21 16:27     ` Sughosh Ganu
2022-10-21 16:38       ` Ilias Apalodimas
2022-10-21 12:45 ` [PATCH v15 04/15] stm32mp1: Add a node for the FWU metadata device Sughosh Ganu
2022-10-21 12:45 ` [PATCH v15 05/15] stm32mp1: Add image information for capsule updates Sughosh Ganu
2022-10-21 12:45 ` [PATCH v15 06/15] FWU: Add helper functions for accessing FWU metadata Sughosh Ganu
2022-10-21 12:46 ` [PATCH v15 07/15] FWU: STM32MP1: Add support to read boot index from backup register Sughosh Ganu
2022-10-21 12:46 ` [PATCH v15 08/15] event: Add an event for main_loop Sughosh Ganu
2022-10-21 12:46 ` [PATCH v15 09/15] FWU: Add boot time checks as highlighted by the FWU specification Sughosh Ganu
2022-10-21 15:08   ` Ilias Apalodimas [this message]
2022-10-21 16:30     ` Sughosh Ganu
2022-10-21 12:46 ` [PATCH v15 10/15] FWU: Add support for the FWU Multi Bank Update feature Sughosh Ganu
2022-10-31 17:59   ` Ilias Apalodimas
2022-11-01 13:31     ` Tom Rini
2022-11-01 19:36       ` Simon Glass
2022-10-21 12:46 ` [PATCH v15 11/15] FWU: cmd: Add a command to read FWU metadata Sughosh Ganu
2022-10-21 12:46 ` [PATCH v15 12/15] test: dm: Add test cases for FWU Metadata uclass Sughosh Ganu
2022-10-21 12:46 ` [PATCH v15 13/15] mkeficapsule: Add support for generating empty capsules Sughosh Ganu
2022-10-21 12:46 ` [PATCH v15 14/15] mkeficapsule: Add support for setting OEM flags in capsule header Sughosh Ganu
2022-10-25 13:56   ` Etienne Carriere
2022-10-21 12:46 ` [PATCH v15 15/15] FWU: doc: Add documentation for the FWU feature Sughosh Ganu
2022-10-21 13:33   ` Ilias Apalodimas

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=Y1K17eaqDaEeH5xW@hera \
    --to=ilias.apalodimas@linaro.org \
    --cc=etienne.carriere@linaro.org \
    --cc=jaswinder.singh@linaro.org \
    --cc=patrice.chotard@foss.st.com \
    --cc=patrick.delaunay@foss.st.com \
    --cc=sjg@chromium.org \
    --cc=sughosh.ganu@linaro.org \
    --cc=takahiro.akashi@linaro.org \
    --cc=trini@konsulko.com \
    --cc=u-boot@lists.denx.de \
    --cc=xypron.glpk@gmx.de \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.