Add Supervise interrupts to allow to do privileged operations like flashing from application code.pull/25/head
parent
068f013bc6
commit
25e824aaa3
@ -0,0 +1,88 @@
|
||||
/*
|
||||
* This file is part of the TREZOR project, https://trezor.io/
|
||||
*
|
||||
* Copyright (C) 2018 Jochen Hoenicke <hoenicke@gmail.com>
|
||||
*
|
||||
* This library is free software: you can redistribute it and/or modify
|
||||
* it under the terms of the GNU Lesser General Public License as published by
|
||||
* the Free Software Foundation, either version 3 of the License, or
|
||||
* (at your option) any later version.
|
||||
*
|
||||
* This library is distributed in the hope that it will be useful,
|
||||
* but WITHOUT ANY WARRANTY; without even the implied warranty of
|
||||
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
||||
* GNU Lesser General Public License for more details.
|
||||
*
|
||||
* You should have received a copy of the GNU Lesser General Public License
|
||||
* along with this library. If not, see <http://www.gnu.org/licenses/>.
|
||||
*/
|
||||
|
||||
#include <libopencm3/stm32/flash.h>
|
||||
#include <stdint.h>
|
||||
#include "supervise.h"
|
||||
#include "memory.h"
|
||||
|
||||
static void svhandler_flash_unlock(void) {
|
||||
flash_clear_status_flags();
|
||||
flash_unlock();
|
||||
}
|
||||
|
||||
static void svhandler_flash_program(uint32_t psize) {
|
||||
/* Wait for any write operation to complete. */
|
||||
flash_wait_for_last_operation();
|
||||
/* check program size argument */
|
||||
if (psize != FLASH_CR_PROGRAM_X8
|
||||
&& psize != FLASH_CR_PROGRAM_X16
|
||||
&& psize != FLASH_CR_PROGRAM_X32
|
||||
&& psize != FLASH_CR_PROGRAM_X64)
|
||||
return;
|
||||
FLASH_CR = (FLASH_CR & ~(FLASH_CR_PROGRAM_MASK << FLASH_CR_PROGRAM_SHIFT))
|
||||
| (psize << FLASH_CR_PROGRAM_SHIFT);
|
||||
FLASH_CR |= FLASH_CR_PG;
|
||||
}
|
||||
|
||||
static void svhandler_flash_erase_sector(uint16_t sector) {
|
||||
/* we only allow erasing meta sectors 2 and 3. */
|
||||
if (sector < FLASH_META_SECTOR_FIRST ||
|
||||
sector > FLASH_META_SECTOR_LAST) {
|
||||
return;
|
||||
}
|
||||
flash_erase_sector(sector, FLASH_CR_PROGRAM_X32);
|
||||
}
|
||||
|
||||
static uint32_t svhandler_flash_lock(void) {
|
||||
/* Wait for any write operation to complete. */
|
||||
flash_wait_for_last_operation();
|
||||
/* Disable writes to flash. */
|
||||
FLASH_CR &= ~FLASH_CR_PG;
|
||||
/* lock flash register */
|
||||
FLASH_CR |= FLASH_CR_LOCK;
|
||||
/* return flash status register */
|
||||
return FLASH_SR;
|
||||
}
|
||||
|
||||
extern volatile uint32_t system_millis;
|
||||
|
||||
void svc_handler_main(uint32_t *stack) {
|
||||
uint8_t svc_number = ((uint8_t*) stack[6])[-2];
|
||||
switch (svc_number) {
|
||||
case SVC_FLASH_UNLOCK:
|
||||
svhandler_flash_unlock();
|
||||
break;
|
||||
case SVC_FLASH_PROGRAM:
|
||||
svhandler_flash_program(stack[0]);
|
||||
break;
|
||||
case SVC_FLASH_ERASE:
|
||||
svhandler_flash_erase_sector(stack[0]);
|
||||
break;
|
||||
case SVC_FLASH_LOCK:
|
||||
stack[0] = svhandler_flash_lock();
|
||||
break;
|
||||
case SVC_TIMER_MS:
|
||||
stack[0] = system_millis;
|
||||
break;
|
||||
default:
|
||||
stack[0] = 0xffffffff;
|
||||
break;
|
||||
}
|
||||
}
|
@ -0,0 +1,77 @@
|
||||
/*
|
||||
* This file is part of the TREZOR project, https://trezor.io/
|
||||
*
|
||||
* Copyright (C) 2018 Jochen Hoenicke <hoenicke@gmail.com>
|
||||
*
|
||||
* This library is free software: you can redistribute it and/or modify
|
||||
* it under the terms of the GNU Lesser General Public License as published by
|
||||
* the Free Software Foundation, either version 3 of the License, or
|
||||
* (at your option) any later version.
|
||||
*
|
||||
* This library is distributed in the hope that it will be useful,
|
||||
* but WITHOUT ANY WARRANTY; without even the implied warranty of
|
||||
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
||||
* GNU Lesser General Public License for more details.
|
||||
*
|
||||
* You should have received a copy of the GNU Lesser General Public License
|
||||
* along with this library. If not, see <http://www.gnu.org/licenses/>.
|
||||
*/
|
||||
|
||||
#ifndef __SUPERVISE_H__
|
||||
#define __SUPERVISE_H__
|
||||
|
||||
#define SVC_FLASH_UNLOCK 0
|
||||
#define SVC_FLASH_ERASE 1
|
||||
#define SVC_FLASH_PROGRAM 2
|
||||
#define SVC_FLASH_LOCK 3
|
||||
#define SVC_TIMER_MS 4
|
||||
|
||||
/* Unlocks flash. This function needs to be called before programming
|
||||
* or erasing. Multiple calls of flash_program and flash_erase can
|
||||
* follow and should be completed with flash_lock().
|
||||
*/
|
||||
inline void svc_flash_unlock(void) {
|
||||
__asm__ __volatile__ ("svc %0" :: "i" (SVC_FLASH_UNLOCK) : "memory");
|
||||
}
|
||||
|
||||
/* Enable flash write operations.
|
||||
* @param program_size (8-bit, 16-bit, 32-bit or 64-bit)
|
||||
* should be one of the FLASH_CR_PROGRAM_X.. constants
|
||||
*/
|
||||
inline void svc_flash_program(uint32_t program_size) {
|
||||
register uint32_t r0 __asm__("r0") = program_size;
|
||||
__asm__ __volatile__ ("svc %0" :: "i" (SVC_FLASH_PROGRAM), "r" (r0) : "memory");
|
||||
}
|
||||
|
||||
/* Erase a flash sector.
|
||||
* @param sector sector number 0..11
|
||||
* (this only allows erasing meta sectors 2 and 3 though).
|
||||
*/
|
||||
inline void svc_flash_erase_sector(uint8_t sector) {
|
||||
register uint32_t r0 __asm__("r0") = sector;
|
||||
__asm__ __volatile__ ("svc %0" :: "i" (SVC_FLASH_ERASE), "r" (r0) : "memory");
|
||||
}
|
||||
|
||||
/* Lock flash after programming or erasing.
|
||||
* @return flash status register (FLASH_SR)
|
||||
*/
|
||||
inline uint32_t svc_flash_lock(void) {
|
||||
register uint32_t r0 __asm__("r0");
|
||||
__asm__ __volatile__ ("svc %1" : "=r" (r0) : "i" (SVC_FLASH_LOCK) : "memory");
|
||||
return r0;
|
||||
}
|
||||
|
||||
inline uint32_t svc_timer_ms(void) {
|
||||
register uint32_t r0 __asm__("r0");
|
||||
__asm__ __volatile__ ("svc %1" : "=r" (r0) : "i" (SVC_TIMER_MS) : "memory");
|
||||
return r0;
|
||||
}
|
||||
|
||||
inline void flash_write32(uint32_t addr, uint32_t word) {
|
||||
*((volatile uint32_t *) addr) = word;
|
||||
}
|
||||
inline void flash_write8(uint32_t addr, uint8_t byte) {
|
||||
*((volatile uint8_t *) addr) = byte;
|
||||
}
|
||||
|
||||
#endif
|
Loading…
Reference in new issue