2023-03-31 13:49:44 +00:00
|
|
|
#include <stdio.h>
|
2023-03-23 14:42:21 +00:00
|
|
|
#include <unistd.h>
|
|
|
|
|
2023-09-14 20:40:38 +00:00
|
|
|
#include TREZOR_BOARD
|
2023-03-31 13:49:44 +00:00
|
|
|
#include "bootui.h"
|
2024-08-16 10:11:38 +00:00
|
|
|
#include "bootutils.h"
|
2023-03-23 14:42:21 +00:00
|
|
|
#include "common.h"
|
|
|
|
#include "display.h"
|
|
|
|
#include "flash.h"
|
2023-11-01 12:40:50 +00:00
|
|
|
#include "flash_otp.h"
|
2023-06-30 10:12:55 +00:00
|
|
|
#include "model.h"
|
2023-03-23 14:42:21 +00:00
|
|
|
#include "rust_ui.h"
|
2023-09-14 12:55:03 +00:00
|
|
|
#ifdef USE_OPTIGA
|
|
|
|
#include "secret.h"
|
|
|
|
#endif
|
2023-03-23 14:42:21 +00:00
|
|
|
|
2023-06-30 10:12:55 +00:00
|
|
|
#include "emulator.h"
|
|
|
|
|
|
|
|
#undef FIRMWARE_START
|
|
|
|
|
2023-03-23 14:42:21 +00:00
|
|
|
uint8_t *FIRMWARE_START = 0;
|
2023-10-20 12:58:32 +00:00
|
|
|
|
2023-03-23 14:42:21 +00:00
|
|
|
void set_core_clock(int) {}
|
|
|
|
|
2024-07-10 22:55:52 +00:00
|
|
|
// used in fw emulator to raise python exception on exit
|
|
|
|
void __attribute__((noreturn)) main_clean_exit() { exit(3); }
|
|
|
|
|
2023-03-23 14:42:21 +00:00
|
|
|
int bootloader_main(void);
|
|
|
|
|
2023-06-28 08:51:30 +00:00
|
|
|
// assuming storage is single subarea
|
|
|
|
bool storage_empty(const flash_area_t *area) {
|
2023-10-16 20:01:36 +00:00
|
|
|
const uint8_t *storage = flash_area_get_address(area, 0, 0);
|
|
|
|
size_t storage_size = flash_area_get_size(area);
|
2023-03-31 13:49:44 +00:00
|
|
|
for (size_t i = 0; i < storage_size; i++) {
|
|
|
|
if (storage[i] != 0xFF) {
|
|
|
|
return false;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
return true;
|
|
|
|
}
|
|
|
|
|
2023-10-18 10:52:18 +00:00
|
|
|
void usage(void) {
|
|
|
|
printf("Usage: ./build/bootloader/bootloader_emu [options]\n");
|
|
|
|
printf("Options:\n");
|
|
|
|
printf(" -s stay in bootloader\n");
|
|
|
|
printf(" -e MESSAGE [TITLE [FOOTER]] display error screen and stop\n");
|
|
|
|
printf(" -c COLOR_VARIANT set color variant\n");
|
|
|
|
printf(" -b BITCOIN_ONLY set bitcoin only flag\n");
|
2023-10-26 08:47:24 +00:00
|
|
|
printf(
|
|
|
|
" -f FIRMWARE run interaction-less update for the specified image\n");
|
2023-10-18 10:52:18 +00:00
|
|
|
#ifdef USE_OPTIGA
|
|
|
|
printf(" -l lock bootloader\n");
|
|
|
|
#endif
|
|
|
|
printf(" -h show this help\n");
|
|
|
|
}
|
|
|
|
|
2023-10-31 11:38:11 +00:00
|
|
|
bool load_firmware(const char *filename, uint8_t *hash) {
|
2023-10-26 08:47:24 +00:00
|
|
|
// read the first 6 kB of firmware file into a buffer
|
|
|
|
FILE *file = fopen(filename, "rb");
|
|
|
|
if (!file) {
|
|
|
|
printf("Failed to open file '%s'\n", filename);
|
|
|
|
return false;
|
|
|
|
}
|
|
|
|
uint8_t buffer[6 * 1024];
|
|
|
|
size_t read = fread(buffer, 1, sizeof(buffer), file);
|
|
|
|
fclose(file);
|
|
|
|
if (read != sizeof(buffer)) {
|
2024-07-09 12:12:07 +00:00
|
|
|
printf("File '%s' does not contain a valid firmware image.\n", filename);
|
2023-10-26 08:47:24 +00:00
|
|
|
return false;
|
|
|
|
}
|
|
|
|
|
|
|
|
// read vendor and image header
|
|
|
|
vendor_header vhdr;
|
|
|
|
if (sectrue != read_vendor_header(buffer, &vhdr)) {
|
2024-07-09 12:12:07 +00:00
|
|
|
printf("File '%s' does not contain a valid vendor header.\n", filename);
|
2023-10-26 08:47:24 +00:00
|
|
|
return false;
|
|
|
|
}
|
|
|
|
const image_header *hdr = read_image_header(
|
|
|
|
buffer + vhdr.hdrlen, FIRMWARE_IMAGE_MAGIC, FIRMWARE_IMAGE_MAXSIZE);
|
|
|
|
if (hdr != (const image_header *)(buffer + vhdr.hdrlen)) {
|
2024-07-09 12:12:07 +00:00
|
|
|
printf("File '%s' does not contain a valid firmware image.\n", filename);
|
2023-10-26 08:47:24 +00:00
|
|
|
return false;
|
|
|
|
}
|
|
|
|
|
|
|
|
// hash it into boot_args
|
|
|
|
BLAKE2S_CTX ctx;
|
|
|
|
blake2s_Init(&ctx, BLAKE2S_DIGEST_LENGTH);
|
|
|
|
blake2s_Update(&ctx, buffer, vhdr.hdrlen + hdr->hdrlen);
|
2023-10-31 11:38:11 +00:00
|
|
|
blake2s_Final(&ctx, hash, BLAKE2S_DIGEST_LENGTH);
|
|
|
|
|
2023-10-26 08:47:24 +00:00
|
|
|
return true;
|
|
|
|
}
|
|
|
|
|
2023-03-31 13:49:44 +00:00
|
|
|
__attribute__((noreturn)) int main(int argc, char **argv) {
|
2024-05-31 13:16:35 +00:00
|
|
|
display_init(DISPLAY_RESET_CONTENT);
|
2023-03-23 14:42:21 +00:00
|
|
|
flash_init();
|
2023-11-01 12:40:50 +00:00
|
|
|
flash_otp_init();
|
|
|
|
|
2023-06-30 10:12:55 +00:00
|
|
|
FIRMWARE_START = (uint8_t *)flash_area_get_address(&FIRMWARE_AREA, 0, 0);
|
2023-03-23 14:42:21 +00:00
|
|
|
|
2023-03-31 13:49:44 +00:00
|
|
|
// simulate non-empty storage so that we know whether it was erased or not
|
2023-06-28 08:51:30 +00:00
|
|
|
if (storage_empty(&STORAGE_AREAS[0])) {
|
2023-06-30 10:12:55 +00:00
|
|
|
secbool ret = flash_area_write_word(&STORAGE_AREAS[0], 16, 0x12345678);
|
2023-03-31 13:49:44 +00:00
|
|
|
(void)ret;
|
|
|
|
}
|
|
|
|
|
2023-10-18 10:52:18 +00:00
|
|
|
int opt;
|
|
|
|
bool display_error = false;
|
|
|
|
uint8_t set_variant = 0xff;
|
|
|
|
uint8_t color_variant = 0;
|
|
|
|
uint8_t bitcoin_only = 0;
|
2023-10-26 08:47:24 +00:00
|
|
|
while ((opt = getopt(argc, argv, "hslec:b:f:")) != -1) {
|
2023-10-18 10:52:18 +00:00
|
|
|
switch (opt) {
|
|
|
|
case 's':
|
2023-10-31 11:38:11 +00:00
|
|
|
bootargs_set(BOOT_COMMAND_STOP_AND_WAIT, NULL, 0);
|
2023-10-18 10:52:18 +00:00
|
|
|
break;
|
|
|
|
case 'e':
|
|
|
|
display_error = true;
|
|
|
|
break;
|
|
|
|
case 'c':
|
|
|
|
set_variant = 1;
|
|
|
|
color_variant = atoi(optarg);
|
|
|
|
break;
|
|
|
|
case 'b':
|
|
|
|
set_variant = 1;
|
|
|
|
bitcoin_only = atoi(optarg);
|
|
|
|
break;
|
2023-10-26 08:47:24 +00:00
|
|
|
case 'f':
|
2023-10-31 11:38:11 +00:00
|
|
|
uint8_t hash[BLAKE2S_DIGEST_LENGTH];
|
|
|
|
if (!load_firmware(optarg, hash)) {
|
2023-10-26 08:47:24 +00:00
|
|
|
exit(1);
|
|
|
|
}
|
2023-10-31 11:38:11 +00:00
|
|
|
bootargs_set(BOOT_COMMAND_INSTALL_UPGRADE, hash, sizeof(hash));
|
2023-10-26 08:47:24 +00:00
|
|
|
break;
|
2023-09-14 12:55:03 +00:00
|
|
|
#ifdef USE_OPTIGA
|
2023-10-18 10:52:18 +00:00
|
|
|
case 'l':
|
|
|
|
// write bootloader-lock secret
|
|
|
|
secret_write_header();
|
|
|
|
break;
|
2023-09-14 12:55:03 +00:00
|
|
|
#endif
|
2023-10-18 10:52:18 +00:00
|
|
|
default:
|
|
|
|
usage();
|
|
|
|
exit(1);
|
|
|
|
}
|
2023-03-23 14:42:21 +00:00
|
|
|
}
|
|
|
|
|
2023-10-18 10:52:18 +00:00
|
|
|
if (display_error) {
|
|
|
|
const char *message, *title = NULL, *footer = NULL;
|
|
|
|
if (optind < argc) {
|
|
|
|
message = argv[optind++];
|
|
|
|
if (optind < argc) {
|
|
|
|
title = argv[optind++];
|
|
|
|
if (optind < argc) {
|
|
|
|
footer = argv[optind++];
|
|
|
|
}
|
|
|
|
}
|
|
|
|
} else {
|
|
|
|
message = "No message specified";
|
|
|
|
}
|
2024-06-10 14:57:59 +00:00
|
|
|
error_shutdown_ex(title, message, footer);
|
2023-10-18 10:52:18 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
// write variant to OTP
|
|
|
|
const uint8_t otp_data[] = {set_variant, color_variant, bitcoin_only};
|
|
|
|
(void)!flash_otp_write(FLASH_OTP_BLOCK_DEVICE_VARIANT, 0, otp_data,
|
|
|
|
sizeof(otp_data));
|
|
|
|
|
2023-03-31 13:49:44 +00:00
|
|
|
bootloader_main();
|
2023-03-23 14:42:21 +00:00
|
|
|
hal_delay(3000);
|
2024-07-10 13:18:21 +00:00
|
|
|
jump_to(0);
|
2023-03-23 14:42:21 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
void mpu_config_bootloader(void) {}
|
|
|
|
|
|
|
|
void mpu_config_off(void) {}
|
|
|
|
|
2024-07-10 13:18:21 +00:00
|
|
|
__attribute__((noreturn)) void jump_to(uint32_t address) {
|
2023-06-30 10:12:55 +00:00
|
|
|
bool storage_is_erased =
|
2023-06-28 08:51:30 +00:00
|
|
|
storage_empty(&STORAGE_AREAS[0]) && storage_empty(&STORAGE_AREAS[1]);
|
2023-03-31 13:49:44 +00:00
|
|
|
|
|
|
|
if (storage_is_erased) {
|
|
|
|
printf("STORAGE WAS ERASED\n");
|
2024-06-10 14:57:59 +00:00
|
|
|
error_shutdown_ex("BOOTLOADER EXIT", "Jumped to firmware",
|
|
|
|
"STORAGE WAS ERASED");
|
2023-03-31 13:49:44 +00:00
|
|
|
} else {
|
|
|
|
printf("storage was retained\n");
|
2024-06-10 14:57:59 +00:00
|
|
|
error_shutdown_ex("BOOTLOADER EXIT", "Jumped to firmware",
|
|
|
|
"STORAGE WAS RETAINED");
|
2023-03-31 13:49:44 +00:00
|
|
|
}
|
2023-03-23 14:42:21 +00:00
|
|
|
}
|