public inbox for u-boot@lists.denx.de
 help / color / mirror / Atom feed
From: Ilias Apalodimas <ilias.apalodimas@linaro.org>
To: Sughosh Ganu <sughosh.ganu@linaro.org>
Cc: u-boot@lists.denx.de, Heinrich Schuchardt <xypron.glpk@gmx.de>,
	Takahiro Akashi <takahiro.akashi@linaro.org>,
	Patrick Delaunay <patrick.delaunay@foss.st.com>,
	Patrice Chotard <patrice.chotard@foss.st.com>,
	Simon Glass <sjg@chromium.org>, Bin Meng <bmeng.cn@gmail.com>,
	Tom Rini <trini@konsulko.com>,
	Etienne Carriere <etienne.carriere@linaro.org>,
	Michal Simek <monstr@monstr.eu>,
	Jassi Brar <jaswinder.singh@linaro.org>
Subject: Re: [PATCH v14 09/15] FWU: Add boot time checks as highlighted by the FWU specification
Date: Thu, 20 Oct 2022 15:29:29 +0300	[thread overview]
Message-ID: <Y1E/Kd+L7aNuOUsC@hera> (raw)
In-Reply-To: <CADg8p96oVojjnBpRG0JvRJmXKureNqfP9cm9wj3LjJM=Z=spHA@mail.gmail.com>

Hi Sughosh, 

> > > +     }
> > > +
> > > +     return 0;
> > > +}
> > > +
> > > +static int fwu_trial_state_check(void)
> > > +{
> > > +     int ret;
> > > +     struct udevice *dev;
> > > +     efi_status_t status;
> > > +     efi_uintn_t var_size;
> > > +     u16 trial_state_ctr;
> > > +     struct fwu_mdata mdata = { 0 };
> > > +
> > > +     ret = fwu_get_dev_mdata(&dev, &mdata);
> > > +     if (ret)
> > > +             return ret;
> > > +
> > > +     trial_state = in_trial_state(&mdata);
> > > +     if (trial_state) {
> > > +             var_size = (efi_uintn_t)sizeof(trial_state_ctr);
> > > +             log_info("System booting in Trial State\n");
> > > +             status = efi_get_variable_int(u"TrialStateCtr",
> > > +                                           &efi_global_variable_guid,
> > > +                                           NULL,
> > > +                                           &var_size, &trial_state_ctr,
> > > +                                           NULL);
> > > +             if (status != EFI_SUCCESS) {
> > > +                     log_err("Unable to read TrialStateCtr variable\n");
> > > +                     ret = -1;
> > > +                     goto out;
> > > +             }
> > > +
> > > +             ++trial_state_ctr;
> > > +             if (trial_state_ctr > CONFIG_FWU_TRIAL_STATE_CNT) {
> > > +                     log_info("Trial State count exceeded. Revert back to previous_active_index\n");
> > > +                     ret = fwu_revert_boot_index();
> > > +                     if (ret) {
> > > +                             log_err("Unable to revert active_index\n");
> > > +                             goto out;
> > > +                     }
> > > +
> > > +                     /* Delete the TrialStateCtr variable */
> > > +                     ret = trial_counter_update(NULL);
> > > +                     if (ret) {
> > > +                             log_err("Unable to delete TrialStateCtr variable\n");
> > > +                             goto out;
> > > +                     }
> >
> > This is a bit confusing for me.  If the trial_state_ctr we need to goto out
> > anyway right?  So why don't we explicitly add a goto out at the end and get
> > rid of the else that's following ?
> 
> Actually, we don't need the goto statement above, as well as the one
> used below, in the else part. I can get rid of it. Personally I feel
> that this provides more clarity as to how the code flow is, but I can
> get rid of it if you so prefer. Thanks.
> 
> -sughosh

My previous reply wasn't that clear let me try again. 
Indeed the goto's aren't needed and that's the first confusing thing. On
top of that the fwu_trial_state_check() is a bit misleading as well, since
it does a lot more than checking. So that functions does
- check the trial state counter
- remove it if not on trial state
- bump the counter
- if the counter exceeds a threshold try to delete it
Also due to the fact that this runs from the event loop, the return codes
are a bit confusing

However this is only called from a fwu_boottime_checks() so we can break it
up in smaller pieces that would be easier to read. 
In fwu_trial_state_check() you only need the metadata to check whether you
are in trial state or not. 

So I would suggest 
1. Create a trial_counter_read() which only reads the EFI variable
2. move the metadata code in fwu_boottime_checks()a instead of
   fwu_trial_state_check()
3. rename fwu_trial_state_check() -> fwu_try_update_cnt()


static u8 trial_state; -> s/trial_state/in_trial/

static int fwu_boottime_checks(void *ctx, struct event *event)
{
	.....

	ret = fwu_get_dev_mdata(&dev, &mdata);
	if (ret)
		return ret;(NULL);
	
	in_trial = in_trial_state(&mdata) + 1;
	cnt = trial_counter_read();

	if (in_trial && cnt < CONFIG_FWU_TRIAL_STATE_CNT)
		ret = fwu_try_update_cnt()
		if (fail)
			trial_counter_update
	else
		trial_counter_update(NULL);
		
There will be an extra GetVariable call since we unconditionally read the
counter now, but we can add if (in_trial), although it doesn't matter that
much.
		
		
Can you give it a shot and see if that works for you?

Thanks
/Ilias

> 
> >
> > > +             } else {
> > > +                     ret = trial_counter_update(&trial_state_ctr);
> > > +                     if (ret) {
> > > +                             log_err("Unable to increment TrialStateCtr variable\n");
> > > +                             goto out;
> > > +                     }
> > > +             }
> > > +     } else {
> > > +             /* Delete the variable */
> > > +             ret = trial_counter_update(NULL);
> > > +             if (ret) {
> > > +                     log_err("Unable to delete TrialStateCtr variable\n");
> > > +             }
> > > +     }
> > > +
> > > +out:
> > > +     return ret;
> > > +}
> > > +
> > >  static int fwu_get_image_type_id(u8 *image_index, efi_guid_t *image_type_id)
> > >  {
> > >       u8 index;
> > > @@ -494,3 +607,69 @@ __weak int fwu_plat_get_update_index(uint *update_idx)
> > >
> > >       return ret;
> > >  }
> > > +
> > > +/**
> > > + * fwu_update_checks_pass() - Check if FWU update can be done
> > > + *
> > > + * Check if the FWU update can be executed. The updates are
> > > + * allowed only when the platform is not in Trial State and
> > > + * the boot time checks have passed
> > > + *
> > > + * Return: 1 if OK, 0 on error
> > > + *
> > > + */
> > > +u8 fwu_update_checks_pass(void)
> > > +{
> > > +     return !trial_state && boottime_check;
> > > +}
> > > +
> > > +static int fwu_boottime_checks(void *ctx, struct event *event)
> > > +{
> > > +     int ret;
> > > +     u32 boot_idx, active_idx;
> > > +
> > > +     ret = fwu_check_mdata_validity();
> > > +     if (ret)
> > > +             return 0;
> > > +
> > > +     /*
> > > +      * Get the Boot Index, i.e. the bank from
> > > +      * which the platform has booted. This value
> > > +      * gets passed from the ealier stage bootloader
> > > +      * which booted u-boot, e.g. tf-a. If the
> > > +      * boot index is not the same as the
> > > +      * active_index read from the FWU metadata,
> > > +      * update the active_index.
> > > +      */
> > > +     fwu_plat_get_bootidx(&boot_idx);
> > > +     if (boot_idx >= CONFIG_FWU_NUM_BANKS) {
> > > +             log_err("Received incorrect value of boot_index\n");
> > > +             return 0;
> > > +     }
> > > +
> > > +     ret = fwu_get_active_index(&active_idx);
> > > +     if (ret) {
> > > +             log_err("Unable to read active_index\n");
> > > +             return 0;
> > > +     }
> > > +
> > > +     if (boot_idx != active_idx) {
> > > +             log_info("Boot idx %u is not matching active idx %u, changing active_idx\n",
> > > +                      boot_idx, active_idx);
> > > +             ret = fwu_set_active_index(boot_idx);
> > > +             if (!ret)
> > > +                     boottime_check = 1;
> > > +
> > > +             return 0;
> > > +     }
> > > +
> > > +     if (efi_init_obj_list() != EFI_SUCCESS)
> > > +             return 0;
> > > +
> > > +     ret = fwu_trial_state_check();
> > > +     if (!ret)
> > > +             boottime_check = 1;
> > > +
> > > +     return 0;
> > > +}
> > > +EVENT_SPY(EVT_MAIN_LOOP, fwu_boottime_checks);
> > > --
> > > 2.34.1
> > >
> >
> > Thanks
> > /Ilias

  parent reply	other threads:[~2022-10-20 12:29 UTC|newest]

Thread overview: 39+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2022-10-18 11:43 [PATCH v14 00/15] FWU: Add FWU Multi Bank Update feature support Sughosh Ganu
2022-10-18 11:43 ` [PATCH v14 01/15] dt/bindings: Add bindings for GPT based FWU Metadata storage device Sughosh Ganu
2022-10-18 11:43 ` [PATCH v14 02/15] FWU: Add FWU metadata structure and driver for accessing metadata Sughosh Ganu
2022-10-19 19:56   ` Ilias Apalodimas
2022-10-19 21:13     ` Etienne Carriere
2022-10-20  4:45     ` Sughosh Ganu
2022-10-20  6:39       ` Ilias Apalodimas
2022-10-18 11:43 ` [PATCH v14 03/15] FWU: Add FWU metadata access driver for GPT partitioned block devices Sughosh Ganu
2022-10-18 15:08   ` Ilias Apalodimas
2022-10-19  5:02     ` Sughosh Ganu
2022-10-18 11:43 ` [PATCH v14 04/15] stm32mp1: Add a node for the FWU metadata device Sughosh Ganu
2022-10-18 11:43 ` [PATCH v14 05/15] stm32mp1: Add image information for capsule updates Sughosh Ganu
2022-10-18 11:43 ` [PATCH v14 06/15] FWU: Add helper functions for accessing FWU metadata Sughosh Ganu
2022-10-18 11:43 ` [PATCH v14 07/15] FWU: STM32MP1: Add support to read boot index from backup register Sughosh Ganu
2022-10-20 14:17   ` Etienne Carriere
2022-10-18 11:43 ` [PATCH v14 08/15] event: Add an event for main_loop Sughosh Ganu
2022-10-20 14:18   ` Etienne Carriere
2022-10-18 11:43 ` [PATCH v14 09/15] FWU: Add boot time checks as highlighted by the FWU specification Sughosh Ganu
2022-10-19 20:01   ` Ilias Apalodimas
2022-10-20  4:35     ` Sughosh Ganu
2022-10-20  6:30       ` Ilias Apalodimas
2022-10-20 12:29       ` Ilias Apalodimas [this message]
2022-10-18 11:43 ` [PATCH v14 10/15] FWU: Add support for the FWU Multi Bank Update feature Sughosh Ganu
2022-10-19  7:36   ` Ilias Apalodimas
2022-10-18 11:43 ` [PATCH v14 11/15] FWU: cmd: Add a command to read FWU metadata Sughosh Ganu
2022-10-18 11:43 ` [PATCH v14 12/15] test: dm: Add test cases for FWU Metadata uclass Sughosh Ganu
2022-10-18 13:41   ` Ilias Apalodimas
2022-10-18 16:59   ` Simon Glass
2022-10-19  4:51     ` Sughosh Ganu
2022-10-18 11:43 ` [PATCH v14 13/15] mkeficapsule: Add support for generating empty capsules Sughosh Ganu
2022-10-20 14:11   ` Etienne Carriere
2022-10-18 11:43 ` [PATCH v14 14/15] mkeficapsule: Add support for setting OEM flags in capsule header Sughosh Ganu
2022-10-20 13:55   ` Etienne Carriere
2022-10-20 14:10     ` Sughosh Ganu
2022-10-20 14:23       ` Etienne Carriere
2022-10-18 11:43 ` [PATCH v14 15/15] FWU: doc: Add documentation for the FWU feature Sughosh Ganu
2022-10-18 14:26   ` Ilias Apalodimas
2022-10-20 14:04     ` Etienne Carriere
2022-10-20 14:28   ` Etienne Carriere

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=Y1E/Kd+L7aNuOUsC@hera \
    --to=ilias.apalodimas@linaro.org \
    --cc=bmeng.cn@gmail.com \
    --cc=etienne.carriere@linaro.org \
    --cc=jaswinder.singh@linaro.org \
    --cc=monstr@monstr.eu \
    --cc=patrice.chotard@foss.st.com \
    --cc=patrick.delaunay@foss.st.com \
    --cc=sjg@chromium.org \
    --cc=sughosh.ganu@linaro.org \
    --cc=takahiro.akashi@linaro.org \
    --cc=trini@konsulko.com \
    --cc=u-boot@lists.denx.de \
    --cc=xypron.glpk@gmx.de \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox