1 // SPDX-License-Identifier: GPL-2.0-only
3 * Qualcomm Peripheral Image Loader
5 * Copyright (C) 2016 Linaro Ltd
6 * Copyright (C) 2015 Sony Mobile Communications Inc
7 * Copyright (c) 2012-2013, The Linux Foundation. All rights reserved.
10 #include <linux/cleanup.h>
11 #include <linux/device.h>
12 #include <linux/elf.h>
13 #include <linux/firmware.h>
14 #include <linux/kernel.h>
15 #include <linux/module.h>
16 #include <linux/firmware/qcom/qcom_scm.h>
17 #include <linux/sizes.h>
18 #include <linux/slab.h>
19 #include <linux/soc/qcom/mdt_loader.h>
21 static bool mdt_phdr_valid(const struct elf32_phdr
*phdr
)
23 if (phdr
->p_type
!= PT_LOAD
)
26 if ((phdr
->p_flags
& QCOM_MDT_TYPE_MASK
) == QCOM_MDT_TYPE_HASH
)
35 static ssize_t
mdt_load_split_segment(void *ptr
, const struct elf32_phdr
*phdrs
,
36 unsigned int segment
, const char *fw_name
,
39 const struct elf32_phdr
*phdr
= &phdrs
[segment
];
40 const struct firmware
*seg_fw
;
43 if (strlen(fw_name
) < 4)
46 char *seg_name
__free(kfree
) = kstrdup(fw_name
, GFP_KERNEL
);
50 sprintf(seg_name
+ strlen(fw_name
) - 3, "b%02d", segment
);
51 ret
= request_firmware_into_buf(&seg_fw
, seg_name
, dev
,
54 dev_err(dev
, "error %zd loading %s\n", ret
, seg_name
);
58 if (seg_fw
->size
!= phdr
->p_filesz
) {
60 "failed to load segment %d from truncated file %s\n",
65 release_firmware(seg_fw
);
71 * qcom_mdt_get_size() - acquire size of the memory region needed to load mdt
72 * @fw: firmware object for the mdt file
74 * Returns size of the loaded firmware blob, or -EINVAL on failure.
76 ssize_t
qcom_mdt_get_size(const struct firmware
*fw
)
78 const struct elf32_phdr
*phdrs
;
79 const struct elf32_phdr
*phdr
;
80 const struct elf32_hdr
*ehdr
;
81 phys_addr_t min_addr
= PHYS_ADDR_MAX
;
82 phys_addr_t max_addr
= 0;
85 ehdr
= (struct elf32_hdr
*)fw
->data
;
86 phdrs
= (struct elf32_phdr
*)(ehdr
+ 1);
88 for (i
= 0; i
< ehdr
->e_phnum
; i
++) {
91 if (!mdt_phdr_valid(phdr
))
94 if (phdr
->p_paddr
< min_addr
)
95 min_addr
= phdr
->p_paddr
;
97 if (phdr
->p_paddr
+ phdr
->p_memsz
> max_addr
)
98 max_addr
= ALIGN(phdr
->p_paddr
+ phdr
->p_memsz
, SZ_4K
);
101 return min_addr
< max_addr
? max_addr
- min_addr
: -EINVAL
;
103 EXPORT_SYMBOL_GPL(qcom_mdt_get_size
);
106 * qcom_mdt_read_metadata() - read header and metadata from mdt or mbn
107 * @fw: firmware of mdt header or mbn
108 * @data_len: length of the read metadata blob
109 * @fw_name: name of the firmware, for construction of segment file names
110 * @dev: device handle to associate resources with
112 * The mechanism that performs the authentication of the loading firmware
113 * expects an ELF header directly followed by the segment of hashes, with no
114 * padding inbetween. This function allocates a chunk of memory for this pair
115 * and copy the two pieces into the buffer.
117 * In the case of split firmware the hash is found directly following the ELF
118 * header, rather than at p_offset described by the second program header.
120 * The caller is responsible to free (kfree()) the returned pointer.
122 * Return: pointer to data, or ERR_PTR()
124 void *qcom_mdt_read_metadata(const struct firmware
*fw
, size_t *data_len
,
125 const char *fw_name
, struct device
*dev
)
127 const struct elf32_phdr
*phdrs
;
128 const struct elf32_hdr
*ehdr
;
129 unsigned int hash_segment
= 0;
137 ehdr
= (struct elf32_hdr
*)fw
->data
;
138 phdrs
= (struct elf32_phdr
*)(ehdr
+ 1);
140 if (ehdr
->e_phnum
< 2)
141 return ERR_PTR(-EINVAL
);
143 if (phdrs
[0].p_type
== PT_LOAD
)
144 return ERR_PTR(-EINVAL
);
146 for (i
= 1; i
< ehdr
->e_phnum
; i
++) {
147 if ((phdrs
[i
].p_flags
& QCOM_MDT_TYPE_MASK
) == QCOM_MDT_TYPE_HASH
) {
154 dev_err(dev
, "no hash segment found in %s\n", fw_name
);
155 return ERR_PTR(-EINVAL
);
158 ehdr_size
= phdrs
[0].p_filesz
;
159 hash_size
= phdrs
[hash_segment
].p_filesz
;
161 data
= kmalloc(ehdr_size
+ hash_size
, GFP_KERNEL
);
163 return ERR_PTR(-ENOMEM
);
165 /* Copy ELF header */
166 memcpy(data
, fw
->data
, ehdr_size
);
168 if (ehdr_size
+ hash_size
== fw
->size
) {
169 /* Firmware is split and hash is packed following the ELF header */
170 hash_offset
= phdrs
[0].p_filesz
;
171 memcpy(data
+ ehdr_size
, fw
->data
+ hash_offset
, hash_size
);
172 } else if (phdrs
[hash_segment
].p_offset
+ hash_size
<= fw
->size
) {
173 /* Hash is in its own segment, but within the loaded file */
174 hash_offset
= phdrs
[hash_segment
].p_offset
;
175 memcpy(data
+ ehdr_size
, fw
->data
+ hash_offset
, hash_size
);
177 /* Hash is in its own segment, beyond the loaded file */
178 ret
= mdt_load_split_segment(data
+ ehdr_size
, phdrs
, hash_segment
, fw_name
, dev
);
185 *data_len
= ehdr_size
+ hash_size
;
189 EXPORT_SYMBOL_GPL(qcom_mdt_read_metadata
);
192 * qcom_mdt_pas_init() - initialize PAS region for firmware loading
193 * @dev: device handle to associate resources with
194 * @fw: firmware object for the mdt file
195 * @fw_name: name of the firmware, for construction of segment file names
196 * @pas_id: PAS identifier
197 * @mem_phys: physical address of allocated memory region
198 * @ctx: PAS metadata context, to be released by caller
200 * Returns 0 on success, negative errno otherwise.
202 int qcom_mdt_pas_init(struct device
*dev
, const struct firmware
*fw
,
203 const char *fw_name
, int pas_id
, phys_addr_t mem_phys
,
204 struct qcom_scm_pas_metadata
*ctx
)
206 const struct elf32_phdr
*phdrs
;
207 const struct elf32_phdr
*phdr
;
208 const struct elf32_hdr
*ehdr
;
209 phys_addr_t min_addr
= PHYS_ADDR_MAX
;
210 phys_addr_t max_addr
= 0;
211 bool relocate
= false;
217 ehdr
= (struct elf32_hdr
*)fw
->data
;
218 phdrs
= (struct elf32_phdr
*)(ehdr
+ 1);
220 for (i
= 0; i
< ehdr
->e_phnum
; i
++) {
223 if (!mdt_phdr_valid(phdr
))
226 if (phdr
->p_flags
& QCOM_MDT_RELOCATABLE
)
229 if (phdr
->p_paddr
< min_addr
)
230 min_addr
= phdr
->p_paddr
;
232 if (phdr
->p_paddr
+ phdr
->p_memsz
> max_addr
)
233 max_addr
= ALIGN(phdr
->p_paddr
+ phdr
->p_memsz
, SZ_4K
);
236 metadata
= qcom_mdt_read_metadata(fw
, &metadata_len
, fw_name
, dev
);
237 if (IS_ERR(metadata
)) {
238 ret
= PTR_ERR(metadata
);
239 dev_err(dev
, "error %d reading firmware %s metadata\n", ret
, fw_name
);
243 ret
= qcom_scm_pas_init_image(pas_id
, metadata
, metadata_len
, ctx
);
246 /* Invalid firmware metadata */
247 dev_err(dev
, "error %d initializing firmware %s\n", ret
, fw_name
);
252 ret
= qcom_scm_pas_mem_setup(pas_id
, mem_phys
, max_addr
- min_addr
);
254 /* Unable to set up relocation */
255 dev_err(dev
, "error %d setting up firmware %s\n", ret
, fw_name
);
263 EXPORT_SYMBOL_GPL(qcom_mdt_pas_init
);
265 static bool qcom_mdt_bins_are_split(const struct firmware
*fw
, const char *fw_name
)
267 const struct elf32_phdr
*phdrs
;
268 const struct elf32_hdr
*ehdr
;
269 uint64_t seg_start
, seg_end
;
272 ehdr
= (struct elf32_hdr
*)fw
->data
;
273 phdrs
= (struct elf32_phdr
*)(ehdr
+ 1);
275 for (i
= 0; i
< ehdr
->e_phnum
; i
++) {
277 * The size of the MDT file is not padded to include any
278 * zero-sized segments at the end. Ignore these, as they should
279 * not affect the decision about image being split or not.
281 if (!phdrs
[i
].p_filesz
)
284 seg_start
= phdrs
[i
].p_offset
;
285 seg_end
= phdrs
[i
].p_offset
+ phdrs
[i
].p_filesz
;
286 if (seg_start
> fw
->size
|| seg_end
> fw
->size
)
293 static int __qcom_mdt_load(struct device
*dev
, const struct firmware
*fw
,
294 const char *fw_name
, int pas_id
, void *mem_region
,
295 phys_addr_t mem_phys
, size_t mem_size
,
296 phys_addr_t
*reloc_base
, bool pas_init
)
298 const struct elf32_phdr
*phdrs
;
299 const struct elf32_phdr
*phdr
;
300 const struct elf32_hdr
*ehdr
;
301 phys_addr_t mem_reloc
;
302 phys_addr_t min_addr
= PHYS_ADDR_MAX
;
304 bool relocate
= false;
310 if (!fw
|| !mem_region
|| !mem_phys
|| !mem_size
)
313 is_split
= qcom_mdt_bins_are_split(fw
, fw_name
);
314 ehdr
= (struct elf32_hdr
*)fw
->data
;
315 phdrs
= (struct elf32_phdr
*)(ehdr
+ 1);
317 for (i
= 0; i
< ehdr
->e_phnum
; i
++) {
320 if (!mdt_phdr_valid(phdr
))
323 if (phdr
->p_flags
& QCOM_MDT_RELOCATABLE
)
326 if (phdr
->p_paddr
< min_addr
)
327 min_addr
= phdr
->p_paddr
;
332 * The image is relocatable, so offset each segment based on
333 * the lowest segment address.
335 mem_reloc
= min_addr
;
338 * Image is not relocatable, so offset each segment based on
339 * the allocated physical chunk of memory.
341 mem_reloc
= mem_phys
;
344 for (i
= 0; i
< ehdr
->e_phnum
; i
++) {
347 if (!mdt_phdr_valid(phdr
))
350 offset
= phdr
->p_paddr
- mem_reloc
;
351 if (offset
< 0 || offset
+ phdr
->p_memsz
> mem_size
) {
352 dev_err(dev
, "segment outside memory range\n");
357 if (phdr
->p_filesz
> phdr
->p_memsz
) {
359 "refusing to load segment %d with p_filesz > p_memsz\n",
365 ptr
= mem_region
+ offset
;
367 if (phdr
->p_filesz
&& !is_split
) {
368 /* Firmware is large enough to be non-split */
369 if (phdr
->p_offset
+ phdr
->p_filesz
> fw
->size
) {
370 dev_err(dev
, "file %s segment %d would be truncated\n",
376 memcpy(ptr
, fw
->data
+ phdr
->p_offset
, phdr
->p_filesz
);
377 } else if (phdr
->p_filesz
) {
378 /* Firmware not large enough, load split-out segments */
379 ret
= mdt_load_split_segment(ptr
, phdrs
, i
, fw_name
, dev
);
384 if (phdr
->p_memsz
> phdr
->p_filesz
)
385 memset(ptr
+ phdr
->p_filesz
, 0, phdr
->p_memsz
- phdr
->p_filesz
);
389 *reloc_base
= mem_reloc
;
395 * qcom_mdt_load() - load the firmware which header is loaded as fw
396 * @dev: device handle to associate resources with
397 * @fw: firmware object for the mdt file
398 * @firmware: name of the firmware, for construction of segment file names
399 * @pas_id: PAS identifier
400 * @mem_region: allocated memory region to load firmware into
401 * @mem_phys: physical address of allocated memory region
402 * @mem_size: size of the allocated memory region
403 * @reloc_base: adjusted physical address after relocation
405 * Returns 0 on success, negative errno otherwise.
407 int qcom_mdt_load(struct device
*dev
, const struct firmware
*fw
,
408 const char *firmware
, int pas_id
, void *mem_region
,
409 phys_addr_t mem_phys
, size_t mem_size
,
410 phys_addr_t
*reloc_base
)
414 ret
= qcom_mdt_pas_init(dev
, fw
, firmware
, pas_id
, mem_phys
, NULL
);
418 return __qcom_mdt_load(dev
, fw
, firmware
, pas_id
, mem_region
, mem_phys
,
419 mem_size
, reloc_base
, true);
421 EXPORT_SYMBOL_GPL(qcom_mdt_load
);
424 * qcom_mdt_load_no_init() - load the firmware which header is loaded as fw
425 * @dev: device handle to associate resources with
426 * @fw: firmware object for the mdt file
427 * @firmware: name of the firmware, for construction of segment file names
428 * @pas_id: PAS identifier
429 * @mem_region: allocated memory region to load firmware into
430 * @mem_phys: physical address of allocated memory region
431 * @mem_size: size of the allocated memory region
432 * @reloc_base: adjusted physical address after relocation
434 * Returns 0 on success, negative errno otherwise.
436 int qcom_mdt_load_no_init(struct device
*dev
, const struct firmware
*fw
,
437 const char *firmware
, int pas_id
,
438 void *mem_region
, phys_addr_t mem_phys
,
439 size_t mem_size
, phys_addr_t
*reloc_base
)
441 return __qcom_mdt_load(dev
, fw
, firmware
, pas_id
, mem_region
, mem_phys
,
442 mem_size
, reloc_base
, false);
444 EXPORT_SYMBOL_GPL(qcom_mdt_load_no_init
);
446 MODULE_DESCRIPTION("Firmware parser for Qualcomm MDT format");
447 MODULE_LICENSE("GPL v2");