xref: /aosp_15_r20/external/arm-trusted-firmware/drivers/brcm/scp.c (revision 54fd6939e177f8ff529b10183254802c76df6d08)
1*54fd6939SJiyong Park /*
2*54fd6939SJiyong Park  * Copyright (c) 2017 - 2020, Broadcom
3*54fd6939SJiyong Park  *
4*54fd6939SJiyong Park  * SPDX-License-Identifier: BSD-3-Clause
5*54fd6939SJiyong Park  */
6*54fd6939SJiyong Park 
7*54fd6939SJiyong Park #include <string.h>
8*54fd6939SJiyong Park 
9*54fd6939SJiyong Park #include <arch_helpers.h>
10*54fd6939SJiyong Park #include <common/debug.h>
11*54fd6939SJiyong Park 
12*54fd6939SJiyong Park /* MCU binary image structure: <header> <data>
13*54fd6939SJiyong Park  *
14*54fd6939SJiyong Park  * Header structure:
15*54fd6939SJiyong Park  * <magic-start>
16*54fd6939SJiyong Park  * <num-sections>
17*54fd6939SJiyong Park  * {<src-offset> <src-size> <dst-addr>}*
18*54fd6939SJiyong Park  * <magic-end>
19*54fd6939SJiyong Park  *
20*54fd6939SJiyong Park  * MCU data (<data>) consists of several sections of code/data, to be
21*54fd6939SJiyong Park  *             installed (copied) into MCU memories.
22*54fd6939SJiyong Park  * Header (<header>) gives information about sections contained in <data>.
23*54fd6939SJiyong Park  *
24*54fd6939SJiyong Park  * The installer code iterates over sections in MCU binary.
25*54fd6939SJiyong Park  * For each section, it copies the section into MCU memory.
26*54fd6939SJiyong Park  *
27*54fd6939SJiyong Park  * The header contains:
28*54fd6939SJiyong Park  *	 - <magic-start> - 32-bit magic number to mark header start
29*54fd6939SJiyong Park  *	 - <num-sections> - number of sections in <data>
30*54fd6939SJiyong Park  *	 - <num-sections> tuples. Each tuple describes a section.
31*54fd6939SJiyong Park  *			 A tuple contains three 32-bit words.
32*54fd6939SJiyong Park  *	 - <magic-end> - 32-bit magic number to mark header end
33*54fd6939SJiyong Park  *
34*54fd6939SJiyong Park  * Each section is describes by a tuple, consisting of three 32-bit words:
35*54fd6939SJiyong Park  *	 - offset of section within MCU binary (relative to beginning of <data>)
36*54fd6939SJiyong Park  *	 - section size (in bytes) in MCU binary
37*54fd6939SJiyong Park  *	 - target address (in MCU memory). Section is copied to this location.
38*54fd6939SJiyong Park  *
39*54fd6939SJiyong Park  * All fields are 32-bit unsigned integers in little endian format.
40*54fd6939SJiyong Park  * All sizes are assumed to be 32-bit aligned.
41*54fd6939SJiyong Park  */
42*54fd6939SJiyong Park 
43*54fd6939SJiyong Park #define SCP_BIN_HEADER_MAGIC_START 0xfa587D01
44*54fd6939SJiyong Park #define SCP_BIN_HEADER_MAGIC_END 0xf3e06a85
45*54fd6939SJiyong Park 
download_scp_patch(void * image,unsigned int image_size)46*54fd6939SJiyong Park int download_scp_patch(void *image, unsigned int image_size)
47*54fd6939SJiyong Park {
48*54fd6939SJiyong Park 	unsigned int *pheader = (unsigned int *)(image);
49*54fd6939SJiyong Park 	unsigned int header_size;
50*54fd6939SJiyong Park 	unsigned char *pdata;
51*54fd6939SJiyong Park 	void *dest;
52*54fd6939SJiyong Park 	unsigned int num_sections;
53*54fd6939SJiyong Park 	unsigned int section_src_offset;
54*54fd6939SJiyong Park 	unsigned int section_size;
55*54fd6939SJiyong Park 
56*54fd6939SJiyong Park 	if (pheader && (pheader[0] != SCP_BIN_HEADER_MAGIC_START)) {
57*54fd6939SJiyong Park 		ERROR("SCP: Could not find SCP header.\n");
58*54fd6939SJiyong Park 		return -1;
59*54fd6939SJiyong Park 	}
60*54fd6939SJiyong Park 
61*54fd6939SJiyong Park 	num_sections = pheader[1];
62*54fd6939SJiyong Park 	INFO("...Number of sections: %d\n", num_sections);
63*54fd6939SJiyong Park 	header_size = 4 * (1 + 1 + 3 * num_sections + 1);
64*54fd6939SJiyong Park 
65*54fd6939SJiyong Park 	if (image_size < header_size) {
66*54fd6939SJiyong Park 		ERROR("SCP: Wrong size.\n");
67*54fd6939SJiyong Park 		return -1;
68*54fd6939SJiyong Park 	}
69*54fd6939SJiyong Park 
70*54fd6939SJiyong Park 	if (*(pheader + header_size/4 - 1) != SCP_BIN_HEADER_MAGIC_END) {
71*54fd6939SJiyong Park 		ERROR("SCP: Could not find SCP footer.\n");
72*54fd6939SJiyong Park 		return -1;
73*54fd6939SJiyong Park 	}
74*54fd6939SJiyong Park 
75*54fd6939SJiyong Park 	VERBOSE("SCP image header validated successfully\n");
76*54fd6939SJiyong Park 	pdata = (unsigned char *)pheader + header_size;
77*54fd6939SJiyong Park 
78*54fd6939SJiyong Park 	for (pheader += 2; num_sections > 0; num_sections--) {
79*54fd6939SJiyong Park 
80*54fd6939SJiyong Park 		section_src_offset = pheader[0];
81*54fd6939SJiyong Park 		section_size = pheader[1];
82*54fd6939SJiyong Park 		dest = (void *)(unsigned long)pheader[2];
83*54fd6939SJiyong Park 
84*54fd6939SJiyong Park 		INFO("section: src:0x%x, size:%d, dst:0x%x\n",
85*54fd6939SJiyong Park 				section_src_offset, section_size, pheader[2]);
86*54fd6939SJiyong Park 
87*54fd6939SJiyong Park 		if ((section_src_offset + section_size) > image_size) {
88*54fd6939SJiyong Park 			ERROR("SCP: Section points to outside of patch.\n");
89*54fd6939SJiyong Park 			return -1;
90*54fd6939SJiyong Park 		}
91*54fd6939SJiyong Park 
92*54fd6939SJiyong Park 		/* copy from source to target section */
93*54fd6939SJiyong Park 		memcpy(dest, pdata + section_src_offset, section_size);
94*54fd6939SJiyong Park 		flush_dcache_range((uintptr_t)dest, section_size);
95*54fd6939SJiyong Park 
96*54fd6939SJiyong Park 		/* next section */
97*54fd6939SJiyong Park 		pheader += 3;
98*54fd6939SJiyong Park 	}
99*54fd6939SJiyong Park 	return 0;
100*54fd6939SJiyong Park }
101