2016-08-17 23:08:22 +08:00
|
|
|
// Copyright 2015-2016 Espressif Systems (Shanghai) PTE LTD
|
|
|
|
//
|
|
|
|
// Licensed under the Apache License, Version 2.0 (the "License");
|
|
|
|
// you may not use this file except in compliance with the License.
|
|
|
|
// You may obtain a copy of the License at
|
|
|
|
|
|
|
|
// http://www.apache.org/licenses/LICENSE-2.0
|
|
|
|
//
|
|
|
|
// Unless required by applicable law or agreed to in writing, software
|
|
|
|
// distributed under the License is distributed on an "AS IS" BASIS,
|
|
|
|
// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
|
|
|
// See the License for the specific language governing permissions and
|
|
|
|
// limitations under the License.
|
|
|
|
|
|
|
|
#include <string.h>
|
|
|
|
|
|
|
|
#include "esp_attr.h"
|
|
|
|
#include "esp_types.h"
|
2016-09-15 00:53:33 +08:00
|
|
|
#include "esp_log.h"
|
2016-08-17 23:08:22 +08:00
|
|
|
|
|
|
|
#include "rom/cache.h"
|
|
|
|
#include "rom/ets_sys.h"
|
|
|
|
#include "rom/secure_boot.h"
|
|
|
|
|
|
|
|
#include "soc/dport_reg.h"
|
|
|
|
#include "soc/io_mux_reg.h"
|
|
|
|
#include "soc/efuse_reg.h"
|
|
|
|
#include "soc/rtc_cntl_reg.h"
|
|
|
|
|
|
|
|
#include "sdkconfig.h"
|
|
|
|
|
2016-11-02 10:41:58 +11:00
|
|
|
#include "bootloader_flash.h"
|
2016-11-11 17:00:34 +11:00
|
|
|
#include "bootloader_random.h"
|
2016-11-02 10:41:58 +11:00
|
|
|
#include "esp_image_format.h"
|
2016-11-02 17:54:47 +11:00
|
|
|
#include "esp_secure_boot.h"
|
2016-11-11 17:00:34 +11:00
|
|
|
#include "esp_flash_encrypt.h"
|
|
|
|
#include "esp_efuse.h"
|
2016-08-17 23:08:22 +08:00
|
|
|
|
2016-09-15 00:53:33 +08:00
|
|
|
static const char* TAG = "secure_boot";
|
|
|
|
|
2016-08-17 23:08:22 +08:00
|
|
|
/**
|
|
|
|
* @function : secure_boot_generate
|
2016-11-02 17:54:47 +11:00
|
|
|
* @description: generate boot digest (aka "abstract") & iv
|
2016-08-17 23:08:22 +08:00
|
|
|
*
|
2016-11-02 17:54:47 +11:00
|
|
|
* @inputs: image_len - length of image to calculate digest for
|
2016-08-17 23:08:22 +08:00
|
|
|
*/
|
2016-11-02 10:41:58 +11:00
|
|
|
static bool secure_boot_generate(uint32_t image_len){
|
2016-11-11 17:00:34 +11:00
|
|
|
esp_err_t err;
|
|
|
|
esp_secure_boot_iv_digest_t digest;
|
|
|
|
const uint32_t *image;
|
2016-11-02 10:41:58 +11:00
|
|
|
|
2016-11-02 17:54:47 +11:00
|
|
|
/* hardware secure boot engine only takes full blocks, so round up the
|
|
|
|
image length. The additional data should all be 0xFF.
|
|
|
|
*/
|
2016-11-11 17:00:34 +11:00
|
|
|
if (image_len % sizeof(digest.iv) != 0) {
|
|
|
|
image_len = (image_len / sizeof(digest.iv) + 1) * sizeof(digest.iv);
|
2016-11-02 17:54:47 +11:00
|
|
|
}
|
|
|
|
ets_secure_boot_start();
|
2016-11-11 17:00:34 +11:00
|
|
|
ets_secure_boot_rd_iv((uint32_t *)digest.iv);
|
2016-11-02 17:54:47 +11:00
|
|
|
ets_secure_boot_hash(NULL);
|
|
|
|
/* iv stored in sec 0 */
|
2016-11-11 17:00:34 +11:00
|
|
|
err = bootloader_flash_erase_sector(0);
|
|
|
|
if (err != ESP_OK)
|
2016-11-02 17:54:47 +11:00
|
|
|
{
|
2016-11-11 17:00:34 +11:00
|
|
|
ESP_LOGE(TAG, "SPI erase failed: 0x%x", err);
|
2016-11-02 17:54:47 +11:00
|
|
|
return false;
|
|
|
|
}
|
|
|
|
|
|
|
|
/* generate digest from image contents */
|
2016-11-02 10:41:58 +11:00
|
|
|
image = bootloader_mmap(0x1000, image_len);
|
|
|
|
if (!image) {
|
|
|
|
ESP_LOGE(TAG, "bootloader_mmap(0x1000, 0x%x) failed", image_len);
|
|
|
|
return false;
|
|
|
|
}
|
2016-11-11 17:00:34 +11:00
|
|
|
for (int i = 0; i < image_len; i+= sizeof(digest.iv)) {
|
|
|
|
ets_secure_boot_hash(&image[i/sizeof(uint32_t)]);
|
2016-11-02 17:54:47 +11:00
|
|
|
}
|
2016-11-07 15:45:57 +11:00
|
|
|
bootloader_munmap(image);
|
2016-08-17 23:08:22 +08:00
|
|
|
|
2016-11-02 17:54:47 +11:00
|
|
|
ets_secure_boot_obtain();
|
2016-11-11 17:00:34 +11:00
|
|
|
ets_secure_boot_rd_abstract((uint32_t *)digest.digest);
|
2016-11-02 17:54:47 +11:00
|
|
|
ets_secure_boot_finish();
|
|
|
|
|
2016-11-11 17:00:34 +11:00
|
|
|
ESP_LOGD(TAG, "write iv+digest to flash");
|
|
|
|
err = bootloader_flash_write(FLASH_OFFS_SECURE_BOOT_IV_DIGEST, &digest,
|
|
|
|
sizeof(digest), esp_flash_encryption_enabled());
|
|
|
|
if (err != ESP_OK) {
|
|
|
|
ESP_LOGE(TAG, "SPI write failed: 0x%x", err);
|
2016-11-02 17:54:47 +11:00
|
|
|
return false;
|
|
|
|
}
|
|
|
|
Cache_Read_Enable(0);
|
|
|
|
return true;
|
2016-08-17 23:08:22 +08:00
|
|
|
}
|
|
|
|
|
2016-10-25 14:55:35 +11:00
|
|
|
/* Burn values written to the efuse write registers */
|
|
|
|
static inline void burn_efuses()
|
|
|
|
{
|
2016-11-07 15:45:26 +11:00
|
|
|
#ifdef CONFIG_SECURE_BOOT_TEST_MODE
|
2016-11-25 14:09:26 +11:00
|
|
|
ESP_LOGE(TAG, "SECURE BOOT TEST MODE. Not really burning any efuses! NOT SECURE");
|
2016-11-07 15:45:26 +11:00
|
|
|
#else
|
2016-11-11 17:00:34 +11:00
|
|
|
esp_efuse_burn_new_values();
|
2016-11-07 15:45:26 +11:00
|
|
|
#endif
|
2016-10-25 14:55:35 +11:00
|
|
|
}
|
2016-08-17 23:08:22 +08:00
|
|
|
|
2016-11-02 17:54:47 +11:00
|
|
|
esp_err_t esp_secure_boot_permanently_enable(void) {
|
2016-11-02 10:41:58 +11:00
|
|
|
esp_err_t err;
|
|
|
|
uint32_t image_len = 0;
|
2016-11-02 17:54:47 +11:00
|
|
|
if (esp_secure_boot_enabled())
|
2016-10-25 14:55:35 +11:00
|
|
|
{
|
|
|
|
ESP_LOGI(TAG, "bootloader secure boot is already enabled, continuing..");
|
2016-11-02 17:54:47 +11:00
|
|
|
return ESP_OK;
|
2016-10-25 14:55:35 +11:00
|
|
|
}
|
|
|
|
|
2016-11-11 17:00:34 +11:00
|
|
|
err = esp_image_basic_verify(0x1000, true, &image_len);
|
2016-11-02 10:41:58 +11:00
|
|
|
if (err != ESP_OK) {
|
|
|
|
ESP_LOGE(TAG, "bootloader image appears invalid! error %d", err);
|
2016-11-02 17:54:47 +11:00
|
|
|
return err;
|
2016-10-25 14:55:35 +11:00
|
|
|
}
|
|
|
|
|
|
|
|
uint32_t dis_reg = REG_READ(EFUSE_BLK0_RDATA0_REG);
|
|
|
|
bool efuse_key_read_protected = dis_reg & EFUSE_RD_DIS_BLK2;
|
|
|
|
bool efuse_key_write_protected = dis_reg & EFUSE_WR_DIS_BLK2;
|
|
|
|
if (efuse_key_read_protected == false
|
|
|
|
&& efuse_key_write_protected == false
|
|
|
|
&& REG_READ(EFUSE_BLK2_RDATA0_REG) == 0
|
|
|
|
&& REG_READ(EFUSE_BLK2_RDATA1_REG) == 0
|
|
|
|
&& REG_READ(EFUSE_BLK2_RDATA2_REG) == 0
|
|
|
|
&& REG_READ(EFUSE_BLK2_RDATA3_REG) == 0
|
|
|
|
&& REG_READ(EFUSE_BLK2_RDATA4_REG) == 0
|
|
|
|
&& REG_READ(EFUSE_BLK2_RDATA5_REG) == 0
|
|
|
|
&& REG_READ(EFUSE_BLK2_RDATA6_REG) == 0
|
|
|
|
&& REG_READ(EFUSE_BLK2_RDATA7_REG) == 0) {
|
|
|
|
|
2016-12-01 23:16:34 -08:00
|
|
|
/* On-device key generation is temporarily disabled, until
|
|
|
|
* RNG operation during bootloader is qualified.
|
|
|
|
* See docs/security/secure-boot.rst for details. */
|
|
|
|
ESP_LOGE(TAG, "On-device key generation is not yet available.");
|
|
|
|
return ESP_ERR_NOT_SUPPORTED;
|
2016-10-25 14:55:35 +11:00
|
|
|
} else {
|
|
|
|
ESP_LOGW(TAG, "Using pre-loaded secure boot key in EFUSE block 2");
|
|
|
|
}
|
|
|
|
|
|
|
|
ESP_LOGI(TAG, "Generating secure boot digest...");
|
2016-11-02 10:41:58 +11:00
|
|
|
if (false == secure_boot_generate(image_len)){
|
2016-10-25 14:55:35 +11:00
|
|
|
ESP_LOGE(TAG, "secure boot generation failed");
|
2016-11-02 17:54:47 +11:00
|
|
|
return ESP_FAIL;
|
2016-10-25 14:55:35 +11:00
|
|
|
}
|
|
|
|
ESP_LOGI(TAG, "Digest generation complete.");
|
|
|
|
|
2016-11-25 14:09:26 +11:00
|
|
|
#ifndef CONFIG_SECURE_BOOT_TEST_MODE
|
2016-10-25 14:55:35 +11:00
|
|
|
if (!efuse_key_read_protected) {
|
|
|
|
ESP_LOGE(TAG, "Pre-loaded key is not read protected. Refusing to blow secure boot efuse.");
|
2016-11-02 17:54:47 +11:00
|
|
|
return ESP_ERR_INVALID_STATE;
|
2016-10-25 14:55:35 +11:00
|
|
|
}
|
|
|
|
if (!efuse_key_write_protected) {
|
|
|
|
ESP_LOGE(TAG, "Pre-loaded key is not write protected. Refusing to blow secure boot efuse.");
|
2016-11-02 17:54:47 +11:00
|
|
|
return ESP_ERR_INVALID_STATE;
|
2016-10-25 14:55:35 +11:00
|
|
|
}
|
2016-11-25 14:09:26 +11:00
|
|
|
#endif
|
2016-08-17 23:08:22 +08:00
|
|
|
|
2016-11-07 15:45:26 +11:00
|
|
|
ESP_LOGI(TAG, "blowing secure boot efuse...");
|
2016-10-25 14:55:35 +11:00
|
|
|
ESP_LOGD(TAG, "before updating, EFUSE_BLK0_RDATA6 %x", REG_READ(EFUSE_BLK0_RDATA6_REG));
|
2016-11-07 15:45:26 +11:00
|
|
|
|
|
|
|
uint32_t new_wdata6 = EFUSE_RD_ABS_DONE_0;
|
|
|
|
|
2016-11-25 14:09:26 +11:00
|
|
|
#ifndef CONFIG_SECURE_BOOT_ALLOW_JTAG
|
|
|
|
ESP_LOGI(TAG, "Disable JTAG...");
|
2016-11-07 15:45:26 +11:00
|
|
|
new_wdata6 |= EFUSE_RD_DISABLE_JTAG;
|
2016-11-25 14:09:26 +11:00
|
|
|
#else
|
|
|
|
ESP_LOGW(TAG, "Not disabling JTAG - SECURITY COMPROMISED");
|
|
|
|
#endif
|
2016-11-07 15:45:26 +11:00
|
|
|
|
2016-11-25 14:09:26 +11:00
|
|
|
#ifndef CONFIG_SECURE_BOOT_ALLOW_ROM_BASIC
|
|
|
|
ESP_LOGI(TAG, "Disable ROM BASIC interpreter fallback...");
|
|
|
|
new_wdata6 |= EFUSE_RD_CONSOLE_DEBUG_DISABLE;
|
|
|
|
#else
|
|
|
|
ESP_LOGW(TAG, "Not disabling ROM BASIC fallback - SECURITY COMPROMISED");
|
|
|
|
#endif
|
2016-11-07 15:45:26 +11:00
|
|
|
|
|
|
|
REG_WRITE(EFUSE_BLK0_WDATA6_REG, new_wdata6);
|
2016-10-25 14:55:35 +11:00
|
|
|
burn_efuses();
|
|
|
|
uint32_t after = REG_READ(EFUSE_BLK0_RDATA6_REG);
|
|
|
|
ESP_LOGD(TAG, "after updating, EFUSE_BLK0_RDATA6 %x", after);
|
|
|
|
if (after & EFUSE_RD_ABS_DONE_0) {
|
|
|
|
ESP_LOGI(TAG, "secure boot is now enabled for bootloader image");
|
2016-11-02 17:54:47 +11:00
|
|
|
return ESP_OK;
|
2016-10-25 14:55:35 +11:00
|
|
|
} else {
|
2016-11-07 15:45:26 +11:00
|
|
|
#ifdef CONFIG_SECURE_BOOT_TEST_MODE
|
|
|
|
ESP_LOGE(TAG, "secure boot not enabled due to test mode");
|
|
|
|
#else
|
2016-10-25 14:55:35 +11:00
|
|
|
ESP_LOGE(TAG, "secure boot not enabled for bootloader image, EFUSE_RD_ABS_DONE_0 is probably write protected!");
|
2016-11-07 15:45:26 +11:00
|
|
|
#endif
|
2016-11-02 17:54:47 +11:00
|
|
|
return ESP_ERR_INVALID_STATE;
|
2016-10-25 14:55:35 +11:00
|
|
|
}
|
2016-08-17 23:08:22 +08:00
|
|
|
}
|