Andrew Walbran | 68a8c16 | 2022-03-07 15:38:42 +0000 | [diff] [blame] | 1 | // Copyright 2022, The Android Open Source Project |
| 2 | // |
| 3 | // Licensed under the Apache License, Version 2.0 (the "License"); |
| 4 | // you may not use this file except in compliance with the License. |
| 5 | // You may obtain a copy of the License at |
| 6 | // |
| 7 | // http://www.apache.org/licenses/LICENSE-2.0 |
| 8 | // |
| 9 | // Unless required by applicable law or agreed to in writing, software |
| 10 | // distributed under the License is distributed on an "AS IS" BASIS, |
| 11 | // WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. |
| 12 | // See the License for the specific language governing permissions and |
| 13 | // limitations under the License. |
| 14 | |
| 15 | //! pVM firmware. |
| 16 | |
| 17 | #![no_main] |
| 18 | #![no_std] |
| 19 | |
Pierre-Clément Tosi | db74cb1 | 2022-12-08 13:56:25 +0000 | [diff] [blame] | 20 | extern crate alloc; |
| 21 | |
Jiyong Park | c5d2ef2 | 2023-04-11 01:23:46 +0900 | [diff] [blame] | 22 | mod bootargs; |
Pierre-Clément Tosi | 20b6096 | 2022-10-17 13:35:27 +0100 | [diff] [blame] | 23 | mod config; |
Pierre-Clément Tosi | 90cd4f1 | 2023-02-17 11:19:56 +0000 | [diff] [blame] | 24 | mod crypto; |
Pierre-Clément Tosi | 4f4f5eb | 2022-12-08 14:31:42 +0000 | [diff] [blame] | 25 | mod dice; |
Pierre-Clément Tosi | 5bbfca5 | 2022-10-21 12:14:35 +0100 | [diff] [blame] | 26 | mod entry; |
Andrew Walbran | dfb7337 | 2022-04-21 10:52:27 +0000 | [diff] [blame] | 27 | mod exceptions; |
Pierre-Clément Tosi | a0934c1 | 2022-11-25 20:54:11 +0000 | [diff] [blame] | 28 | mod fdt; |
Pierre-Clément Tosi | 1cc5eb7 | 2023-02-02 11:09:18 +0000 | [diff] [blame] | 29 | mod gpt; |
Pierre-Clément Tosi | fc53115 | 2022-10-20 12:22:23 +0100 | [diff] [blame] | 30 | mod heap; |
Pierre-Clément Tosi | da4440a | 2022-08-22 18:06:32 +0100 | [diff] [blame] | 31 | mod helpers; |
Andrew Walbran | ba47d1d | 2022-12-14 15:21:44 +0000 | [diff] [blame] | 32 | mod hvc; |
Pierre-Clément Tosi | 1cc5eb7 | 2023-02-02 11:09:18 +0000 | [diff] [blame] | 33 | mod instance; |
Pierre-Clément Tosi | a0934c1 | 2022-11-25 20:54:11 +0000 | [diff] [blame] | 34 | mod memory; |
Pierre-Clément Tosi | a8a4a20 | 2022-11-03 14:16:46 +0000 | [diff] [blame] | 35 | mod mmu; |
Pierre-Clément Tosi | 90cd4f1 | 2023-02-17 11:19:56 +0000 | [diff] [blame] | 36 | mod rand; |
Andrew Walbran | 848decf | 2022-12-15 14:39:38 +0000 | [diff] [blame] | 37 | mod virtio; |
Andrew Walbran | 68a8c16 | 2022-03-07 15:38:42 +0000 | [diff] [blame] | 38 | |
Pierre-Clément Tosi | db74cb1 | 2022-12-08 13:56:25 +0000 | [diff] [blame] | 39 | use alloc::boxed::Box; |
Alan Stokes | d1ee63e | 2023-04-24 16:17:39 +0100 | [diff] [blame] | 40 | use alloc::string::ToString; |
Pierre-Clément Tosi | 97f5249 | 2023-04-04 15:52:17 +0100 | [diff] [blame^] | 41 | use core::ops::Range; |
Pierre-Clément Tosi | db74cb1 | 2022-12-08 13:56:25 +0000 | [diff] [blame] | 42 | |
Pierre-Clément Tosi | 4ba7966 | 2023-02-13 11:22:41 +0000 | [diff] [blame] | 43 | use crate::dice::PartialInputs; |
| 44 | use crate::entry::RebootReason; |
| 45 | use crate::fdt::modify_for_next_stage; |
| 46 | use crate::helpers::flush; |
| 47 | use crate::helpers::GUEST_PAGE_SIZE; |
Pierre-Clément Tosi | 1cc5eb7 | 2023-02-02 11:09:18 +0000 | [diff] [blame] | 48 | use crate::instance::get_or_generate_instance_salt; |
Pierre-Clément Tosi | 4ba7966 | 2023-02-13 11:22:41 +0000 | [diff] [blame] | 49 | use crate::memory::MemoryTracker; |
| 50 | use crate::virtio::pci; |
Alan Stokes | d1ee63e | 2023-04-24 16:17:39 +0100 | [diff] [blame] | 51 | use ciborium::{de::from_reader, value::Value}; |
Pierre-Clément Tosi | 1cc5eb7 | 2023-02-02 11:09:18 +0000 | [diff] [blame] | 52 | use diced_open_dice::bcc_handover_main_flow; |
| 53 | use diced_open_dice::bcc_handover_parse; |
Pierre-Clément Tosi | 90cd4f1 | 2023-02-17 11:19:56 +0000 | [diff] [blame] | 54 | use diced_open_dice::DiceArtifacts; |
Andrew Walbran | 730375d | 2022-12-21 14:04:34 +0000 | [diff] [blame] | 55 | use fdtpci::{PciError, PciInfo}; |
Andrew Walbran | 1969063 | 2022-12-07 16:41:30 +0000 | [diff] [blame] | 56 | use libfdt::Fdt; |
Pierre-Clément Tosi | 8edf72e | 2022-12-06 16:02:57 +0000 | [diff] [blame] | 57 | use log::{debug, error, info, trace}; |
Pierre-Clément Tosi | 2d65298 | 2023-01-09 19:30:17 +0000 | [diff] [blame] | 58 | use pvmfw_avb::verify_payload; |
Jiyong Park | c5d2ef2 | 2023-04-11 01:23:46 +0900 | [diff] [blame] | 59 | use pvmfw_avb::DebugLevel; |
Alice Wang | 0aa3032 | 2023-01-31 11:00:10 +0000 | [diff] [blame] | 60 | use pvmfw_embedded_key::PUBLIC_KEY; |
Andrew Walbran | 68a8c16 | 2022-03-07 15:38:42 +0000 | [diff] [blame] | 61 | |
Pierre-Clément Tosi | 4f4f5eb | 2022-12-08 14:31:42 +0000 | [diff] [blame] | 62 | const NEXT_BCC_SIZE: usize = GUEST_PAGE_SIZE; |
| 63 | |
Alan Stokes | d1ee63e | 2023-04-24 16:17:39 +0100 | [diff] [blame] | 64 | type CiboriumError = ciborium::de::Error<ciborium_io::EndOfFile>; |
| 65 | |
| 66 | /// Decodes the provided binary CBOR-encoded value and returns a |
| 67 | /// ciborium::Value struct wrapped in Result. |
| 68 | fn value_from_bytes(mut bytes: &[u8]) -> Result<Value, CiboriumError> { |
| 69 | let value = from_reader(&mut bytes)?; |
| 70 | // Ciborium tries to read one Value, but doesn't care if there is trailing data. We do. |
| 71 | if !bytes.is_empty() { |
| 72 | return Err(CiboriumError::Semantic(Some(0), "unexpected trailing data".to_string())); |
| 73 | } |
| 74 | Ok(value) |
| 75 | } |
| 76 | |
Alice Wang | 28cbcf1 | 2022-12-01 07:58:28 +0000 | [diff] [blame] | 77 | fn main( |
Pierre-Clément Tosi | db74cb1 | 2022-12-08 13:56:25 +0000 | [diff] [blame] | 78 | fdt: &mut Fdt, |
Alice Wang | 28cbcf1 | 2022-12-01 07:58:28 +0000 | [diff] [blame] | 79 | signed_kernel: &[u8], |
| 80 | ramdisk: Option<&[u8]>, |
Alice Wang | 843d831 | 2023-02-15 09:47:06 +0000 | [diff] [blame] | 81 | current_bcc_handover: &[u8], |
Jiyong Park | c23426b | 2023-04-10 17:32:27 +0900 | [diff] [blame] | 82 | debug_policy: Option<&mut [u8]>, |
Andrew Walbran | 1969063 | 2022-12-07 16:41:30 +0000 | [diff] [blame] | 83 | memory: &mut MemoryTracker, |
Pierre-Clément Tosi | 97f5249 | 2023-04-04 15:52:17 +0100 | [diff] [blame^] | 84 | ) -> Result<Range<usize>, RebootReason> { |
Pierre-Clément Tosi | 37105a6 | 2022-10-18 12:21:48 +0100 | [diff] [blame] | 85 | info!("pVM firmware"); |
Pierre-Clément Tosi | 8036b4f | 2023-02-17 10:31:31 +0000 | [diff] [blame] | 86 | debug!("FDT: {:?}", fdt.as_ptr()); |
Pierre-Clément Tosi | a0934c1 | 2022-11-25 20:54:11 +0000 | [diff] [blame] | 87 | debug!("Signed kernel: {:?} ({:#x} bytes)", signed_kernel.as_ptr(), signed_kernel.len()); |
Alice Wang | a78279c | 2022-12-16 12:41:19 +0000 | [diff] [blame] | 88 | debug!("AVB public key: addr={:?}, size={:#x} ({1})", PUBLIC_KEY.as_ptr(), PUBLIC_KEY.len()); |
Pierre-Clément Tosi | a0934c1 | 2022-11-25 20:54:11 +0000 | [diff] [blame] | 89 | if let Some(rd) = ramdisk { |
| 90 | debug!("Ramdisk: {:?} ({:#x} bytes)", rd.as_ptr(), rd.len()); |
| 91 | } else { |
| 92 | debug!("Ramdisk: None"); |
| 93 | } |
Alice Wang | 843d831 | 2023-02-15 09:47:06 +0000 | [diff] [blame] | 94 | let bcc_handover = bcc_handover_parse(current_bcc_handover).map_err(|e| { |
| 95 | error!("Invalid BCC Handover: {e:?}"); |
| 96 | RebootReason::InvalidBcc |
| 97 | })?; |
| 98 | trace!("BCC: {bcc_handover:x?}"); |
Andrew Walbran | 1969063 | 2022-12-07 16:41:30 +0000 | [diff] [blame] | 99 | |
Alan Stokes | d1ee63e | 2023-04-24 16:17:39 +0100 | [diff] [blame] | 100 | // Minimal BCC verification - check the BCC exists & is valid CBOR. |
| 101 | // TODO(alanstokes): Do something more useful. |
| 102 | if let Some(bytes) = bcc_handover.bcc() { |
| 103 | let _ = value_from_bytes(bytes).map_err(|e| { |
| 104 | error!("Invalid BCC: {e:?}"); |
| 105 | RebootReason::InvalidBcc |
| 106 | })?; |
| 107 | } else { |
| 108 | error!("Missing BCC"); |
| 109 | return Err(RebootReason::InvalidBcc); |
| 110 | } |
| 111 | |
Andrew Walbran | 1969063 | 2022-12-07 16:41:30 +0000 | [diff] [blame] | 112 | // Set up PCI bus for VirtIO devices. |
Andrew Walbran | d1d0318 | 2022-12-09 18:20:01 +0000 | [diff] [blame] | 113 | let pci_info = PciInfo::from_fdt(fdt).map_err(handle_pci_error)?; |
| 114 | debug!("PCI: {:#x?}", pci_info); |
Andrew Walbran | b398fc8 | 2023-01-24 14:45:46 +0000 | [diff] [blame] | 115 | let mut pci_root = pci::initialise(pci_info, memory)?; |
Andrew Walbran | 1969063 | 2022-12-07 16:41:30 +0000 | [diff] [blame] | 116 | |
Alice Wang | 1f0add0 | 2023-01-23 16:22:53 +0000 | [diff] [blame] | 117 | let verified_boot_data = verify_payload(signed_kernel, ramdisk, PUBLIC_KEY).map_err(|e| { |
Pierre-Clément Tosi | 2d65298 | 2023-01-09 19:30:17 +0000 | [diff] [blame] | 118 | error!("Failed to verify the payload: {e}"); |
| 119 | RebootReason::PayloadVerificationError |
| 120 | })?; |
| 121 | |
Pierre-Clément Tosi | db74cb1 | 2022-12-08 13:56:25 +0000 | [diff] [blame] | 122 | let next_bcc = heap::aligned_boxed_slice(NEXT_BCC_SIZE, GUEST_PAGE_SIZE).ok_or_else(|| { |
| 123 | error!("Failed to allocate the next-stage BCC"); |
| 124 | RebootReason::InternalError |
| 125 | })?; |
| 126 | // By leaking the slice, its content will be left behind for the next stage. |
| 127 | let next_bcc = Box::leak(next_bcc); |
Pierre-Clément Tosi | 4f4f5eb | 2022-12-08 14:31:42 +0000 | [diff] [blame] | 128 | |
Pierre-Clément Tosi | f58f3a3 | 2023-02-02 16:24:23 +0000 | [diff] [blame] | 129 | let dice_inputs = PartialInputs::new(&verified_boot_data).map_err(|e| { |
| 130 | error!("Failed to compute partial DICE inputs: {e:?}"); |
| 131 | RebootReason::InternalError |
| 132 | })?; |
Pierre-Clément Tosi | 90cd4f1 | 2023-02-17 11:19:56 +0000 | [diff] [blame] | 133 | let cdi_seal = DiceArtifacts::cdi_seal(&bcc_handover); |
| 134 | let (new_instance, salt) = get_or_generate_instance_salt(&mut pci_root, &dice_inputs, cdi_seal) |
| 135 | .map_err(|e| { |
Pierre-Clément Tosi | 1cc5eb7 | 2023-02-02 11:09:18 +0000 | [diff] [blame] | 136 | error!("Failed to get instance.img salt: {e}"); |
| 137 | RebootReason::InternalError |
| 138 | })?; |
| 139 | trace!("Got salt from instance.img: {salt:x?}"); |
| 140 | |
Pierre-Clément Tosi | f58f3a3 | 2023-02-02 16:24:23 +0000 | [diff] [blame] | 141 | let dice_inputs = dice_inputs.into_input_values(&salt).map_err(|e| { |
| 142 | error!("Failed to generate DICE inputs: {e:?}"); |
| 143 | RebootReason::InternalError |
| 144 | })?; |
Alice Wang | 843d831 | 2023-02-15 09:47:06 +0000 | [diff] [blame] | 145 | let _ = bcc_handover_main_flow(current_bcc_handover, &dice_inputs, next_bcc).map_err(|e| { |
Pierre-Clément Tosi | f58f3a3 | 2023-02-02 16:24:23 +0000 | [diff] [blame] | 146 | error!("Failed to derive next-stage DICE secrets: {e:?}"); |
| 147 | RebootReason::SecretDerivationError |
| 148 | })?; |
Pierre-Clément Tosi | db74cb1 | 2022-12-08 13:56:25 +0000 | [diff] [blame] | 149 | flush(next_bcc); |
| 150 | |
Pierre-Clément Tosi | b2d8aa7 | 2023-02-17 15:22:50 +0000 | [diff] [blame] | 151 | let strict_boot = true; |
Jiyong Park | c5d2ef2 | 2023-04-11 01:23:46 +0900 | [diff] [blame] | 152 | let debuggable = verified_boot_data.debug_level != DebugLevel::None; |
| 153 | modify_for_next_stage(fdt, next_bcc, new_instance, strict_boot, debug_policy, debuggable) |
| 154 | .map_err(|e| { |
| 155 | error!("Failed to configure device tree: {e}"); |
| 156 | RebootReason::InternalError |
| 157 | })?; |
Pierre-Clément Tosi | db74cb1 | 2022-12-08 13:56:25 +0000 | [diff] [blame] | 158 | |
Alice Wang | 4379c83 | 2022-12-05 15:50:20 +0000 | [diff] [blame] | 159 | info!("Starting payload..."); |
Pierre-Clément Tosi | 97f5249 | 2023-04-04 15:52:17 +0100 | [diff] [blame^] | 160 | |
| 161 | let bcc_range = { |
| 162 | let r = next_bcc.as_ptr_range(); |
| 163 | (r.start as usize)..(r.end as usize) |
| 164 | }; |
| 165 | |
| 166 | Ok(bcc_range) |
Pierre-Clément Tosi | 263ffd5 | 2022-10-05 20:27:50 +0100 | [diff] [blame] | 167 | } |
Andrew Walbran | d1d0318 | 2022-12-09 18:20:01 +0000 | [diff] [blame] | 168 | |
| 169 | /// Logs the given PCI error and returns the appropriate `RebootReason`. |
| 170 | fn handle_pci_error(e: PciError) -> RebootReason { |
| 171 | error!("{}", e); |
| 172 | match e { |
| 173 | PciError::FdtErrorPci(_) |
| 174 | | PciError::FdtNoPci |
| 175 | | PciError::FdtErrorReg(_) |
| 176 | | PciError::FdtMissingReg |
| 177 | | PciError::FdtRegEmpty |
| 178 | | PciError::FdtRegMissingSize |
| 179 | | PciError::CamWrongSize(_) |
| 180 | | PciError::FdtErrorRanges(_) |
| 181 | | PciError::FdtMissingRanges |
| 182 | | PciError::RangeAddressMismatch { .. } |
| 183 | | PciError::NoSuitableRange => RebootReason::InvalidFdt, |
Andrew Walbran | d1d0318 | 2022-12-09 18:20:01 +0000 | [diff] [blame] | 184 | } |
| 185 | } |