2023-03-07 10:46:59 +01:00
|
|
|
#![feature(async_fn_in_trait)]
|
|
|
|
#![allow(incomplete_features)]
|
2022-01-24 12:54:09 +01:00
|
|
|
#![no_std]
|
2022-08-30 13:07:35 +02:00
|
|
|
#![warn(missing_docs)]
|
2022-11-23 14:48:51 +01:00
|
|
|
#![doc = include_str!("../README.md")]
|
2022-01-24 12:54:09 +01:00
|
|
|
mod fmt;
|
|
|
|
|
2023-03-31 08:05:37 +02:00
|
|
|
mod boot_loader;
|
|
|
|
mod firmware_updater;
|
2023-04-04 21:09:30 +02:00
|
|
|
mod large_erase;
|
2023-04-03 15:33:20 +02:00
|
|
|
mod mem_flash;
|
2023-03-31 08:05:37 +02:00
|
|
|
mod partition;
|
2022-01-24 12:54:09 +01:00
|
|
|
|
2023-04-04 21:18:41 +02:00
|
|
|
pub use boot_loader::{BootError, BootFlash, BootLoader, FlashConfig, MultiFlashConfig, SingleFlashConfig};
|
2023-03-31 08:05:37 +02:00
|
|
|
pub use firmware_updater::{FirmwareUpdater, FirmwareUpdaterError};
|
|
|
|
pub use partition::Partition;
|
2022-04-20 13:49:59 +02:00
|
|
|
|
2023-03-31 08:05:37 +02:00
|
|
|
pub(crate) const BOOT_MAGIC: u8 = 0xD0;
|
|
|
|
pub(crate) const SWAP_MAGIC: u8 = 0xF0;
|
2022-01-24 12:54:09 +01:00
|
|
|
|
2022-08-30 13:07:35 +02:00
|
|
|
/// The state of the bootloader after running prepare.
|
|
|
|
#[derive(PartialEq, Eq, Debug)]
|
2022-01-24 12:54:09 +01:00
|
|
|
#[cfg_attr(feature = "defmt", derive(defmt::Format))]
|
|
|
|
pub enum State {
|
2022-08-30 13:07:35 +02:00
|
|
|
/// Bootloader is ready to boot the active partition.
|
2022-01-24 12:54:09 +01:00
|
|
|
Boot,
|
2022-08-30 13:07:35 +02:00
|
|
|
/// Bootloader has swapped the active partition with the dfu partition and will attempt boot.
|
2022-01-24 12:54:09 +01:00
|
|
|
Swap,
|
|
|
|
}
|
|
|
|
|
2022-08-30 13:07:35 +02:00
|
|
|
/// Buffer aligned to 32 byte boundary, largest known alignment requirement for embassy-boot.
|
|
|
|
#[repr(align(32))]
|
|
|
|
pub struct AlignedBuffer<const N: usize>(pub [u8; N]);
|
|
|
|
|
|
|
|
impl<const N: usize> AsRef<[u8]> for AlignedBuffer<N> {
|
|
|
|
fn as_ref(&self) -> &[u8] {
|
|
|
|
&self.0
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
impl<const N: usize> AsMut<[u8]> for AlignedBuffer<N> {
|
|
|
|
fn as_mut(&mut self) -> &mut [u8] {
|
|
|
|
&mut self.0
|
|
|
|
}
|
|
|
|
}
|
2022-04-19 14:42:38 +02:00
|
|
|
|
2022-01-24 12:54:09 +01:00
|
|
|
#[cfg(test)]
|
|
|
|
mod tests {
|
|
|
|
use futures::executor::block_on;
|
|
|
|
|
2022-06-12 22:15:44 +02:00
|
|
|
use super::*;
|
2023-04-04 21:09:30 +02:00
|
|
|
use crate::large_erase::LargeErase;
|
2023-04-03 15:33:20 +02:00
|
|
|
use crate::mem_flash::MemFlash;
|
2022-06-12 22:15:44 +02:00
|
|
|
|
2022-04-20 13:49:59 +02:00
|
|
|
/*
|
2022-01-24 12:54:09 +01:00
|
|
|
#[test]
|
|
|
|
fn test_bad_magic() {
|
|
|
|
let mut flash = MemFlash([0xff; 131072]);
|
2022-08-30 13:07:35 +02:00
|
|
|
let mut flash = SingleFlashConfig::new(&mut flash);
|
2022-01-24 12:54:09 +01:00
|
|
|
|
|
|
|
let mut bootloader = BootLoader::<4096>::new(ACTIVE, DFU, STATE);
|
|
|
|
|
|
|
|
assert_eq!(
|
|
|
|
bootloader.prepare_boot(&mut flash),
|
|
|
|
Err(BootError::BadMagic)
|
|
|
|
);
|
|
|
|
}
|
2022-04-20 13:49:59 +02:00
|
|
|
*/
|
2022-01-24 12:54:09 +01:00
|
|
|
|
|
|
|
#[test]
|
|
|
|
fn test_boot_state() {
|
2022-04-28 10:38:25 +02:00
|
|
|
const STATE: Partition = Partition::new(0, 4096);
|
|
|
|
const ACTIVE: Partition = Partition::new(4096, 61440);
|
|
|
|
const DFU: Partition = Partition::new(61440, 122880);
|
|
|
|
|
2023-04-03 15:33:20 +02:00
|
|
|
let mut flash = MemFlash::<131072, 4096, 4>::default();
|
|
|
|
flash.mem[0..4].copy_from_slice(&[BOOT_MAGIC; 4]);
|
2022-08-30 13:07:35 +02:00
|
|
|
let mut flash = SingleFlashConfig::new(&mut flash);
|
2022-01-24 12:54:09 +01:00
|
|
|
|
2022-08-30 13:07:35 +02:00
|
|
|
let mut bootloader: BootLoader = BootLoader::new(ACTIVE, DFU, STATE);
|
2022-01-24 12:54:09 +01:00
|
|
|
|
2022-08-30 13:07:35 +02:00
|
|
|
let mut page = [0; 4096];
|
2023-04-04 20:25:55 +02:00
|
|
|
assert_eq!(State::Boot, bootloader.prepare_boot(&mut flash, &mut page).unwrap());
|
2022-01-24 12:54:09 +01:00
|
|
|
}
|
|
|
|
|
|
|
|
#[test]
|
2023-01-06 12:21:39 +01:00
|
|
|
#[cfg(not(feature = "_verify"))]
|
2022-01-24 12:54:09 +01:00
|
|
|
fn test_swap_state() {
|
2022-04-28 10:38:25 +02:00
|
|
|
const STATE: Partition = Partition::new(0, 4096);
|
|
|
|
const ACTIVE: Partition = Partition::new(4096, 61440);
|
|
|
|
const DFU: Partition = Partition::new(61440, 122880);
|
2023-04-04 07:18:29 +02:00
|
|
|
let mut flash = MemFlash::<131072, 4096, 4>::random();
|
2022-01-24 12:54:09 +01:00
|
|
|
|
|
|
|
let original: [u8; ACTIVE.len()] = [rand::random::<u8>(); ACTIVE.len()];
|
|
|
|
let update: [u8; DFU.len()] = [rand::random::<u8>(); DFU.len()];
|
2022-08-30 13:07:35 +02:00
|
|
|
let mut aligned = [0; 4];
|
2022-01-24 12:54:09 +01:00
|
|
|
|
|
|
|
for i in ACTIVE.from..ACTIVE.to {
|
2023-04-03 15:33:20 +02:00
|
|
|
flash.mem[i] = original[i - ACTIVE.from];
|
2022-01-24 12:54:09 +01:00
|
|
|
}
|
|
|
|
|
2022-08-30 13:07:35 +02:00
|
|
|
let mut bootloader: BootLoader = BootLoader::new(ACTIVE, DFU, STATE);
|
2022-01-24 12:54:09 +01:00
|
|
|
let mut updater = FirmwareUpdater::new(DFU, STATE);
|
2023-04-04 21:09:30 +02:00
|
|
|
block_on(updater.write_firmware(0, &update, &mut flash)).unwrap();
|
2022-08-30 13:07:35 +02:00
|
|
|
block_on(updater.mark_updated(&mut flash, &mut aligned)).unwrap();
|
2022-01-24 12:54:09 +01:00
|
|
|
|
2023-04-04 21:09:30 +02:00
|
|
|
let mut page = [0; 1024];
|
2022-04-20 13:49:59 +02:00
|
|
|
assert_eq!(
|
|
|
|
State::Swap,
|
|
|
|
bootloader
|
2023-04-04 20:25:55 +02:00
|
|
|
.prepare_boot(&mut SingleFlashConfig::new(&mut flash), &mut page)
|
2022-04-20 13:49:59 +02:00
|
|
|
.unwrap()
|
|
|
|
);
|
2022-01-24 12:54:09 +01:00
|
|
|
|
|
|
|
for i in ACTIVE.from..ACTIVE.to {
|
2023-04-03 15:33:20 +02:00
|
|
|
assert_eq!(flash.mem[i], update[i - ACTIVE.from], "Index {}", i);
|
2022-01-24 12:54:09 +01:00
|
|
|
}
|
|
|
|
|
|
|
|
// First DFU page is untouched
|
|
|
|
for i in DFU.from + 4096..DFU.to {
|
2023-04-03 15:33:20 +02:00
|
|
|
assert_eq!(flash.mem[i], original[i - DFU.from - 4096], "Index {}", i);
|
2022-01-24 12:54:09 +01:00
|
|
|
}
|
|
|
|
|
|
|
|
// Running again should cause a revert
|
2022-04-20 13:49:59 +02:00
|
|
|
assert_eq!(
|
|
|
|
State::Swap,
|
|
|
|
bootloader
|
2023-04-04 20:25:55 +02:00
|
|
|
.prepare_boot(&mut SingleFlashConfig::new(&mut flash), &mut page)
|
2022-04-20 13:49:59 +02:00
|
|
|
.unwrap()
|
|
|
|
);
|
2022-01-24 12:54:09 +01:00
|
|
|
|
|
|
|
for i in ACTIVE.from..ACTIVE.to {
|
2023-04-03 15:33:20 +02:00
|
|
|
assert_eq!(flash.mem[i], original[i - ACTIVE.from], "Index {}", i);
|
2022-01-24 12:54:09 +01:00
|
|
|
}
|
|
|
|
|
|
|
|
// Last page is untouched
|
|
|
|
for i in DFU.from..DFU.to - 4096 {
|
2023-04-03 15:33:20 +02:00
|
|
|
assert_eq!(flash.mem[i], update[i - DFU.from], "Index {}", i);
|
2022-01-24 12:54:09 +01:00
|
|
|
}
|
|
|
|
|
|
|
|
// Mark as booted
|
2022-08-30 13:07:35 +02:00
|
|
|
block_on(updater.mark_booted(&mut flash, &mut aligned)).unwrap();
|
2022-04-20 13:49:59 +02:00
|
|
|
assert_eq!(
|
|
|
|
State::Boot,
|
|
|
|
bootloader
|
2023-04-04 20:25:55 +02:00
|
|
|
.prepare_boot(&mut SingleFlashConfig::new(&mut flash), &mut page)
|
2022-04-20 13:49:59 +02:00
|
|
|
.unwrap()
|
|
|
|
);
|
2022-01-24 12:54:09 +01:00
|
|
|
}
|
|
|
|
|
2022-04-28 10:38:25 +02:00
|
|
|
#[test]
|
2023-01-06 12:21:39 +01:00
|
|
|
#[cfg(not(feature = "_verify"))]
|
2022-04-28 10:38:25 +02:00
|
|
|
fn test_separate_flash_active_page_biggest() {
|
|
|
|
const STATE: Partition = Partition::new(2048, 4096);
|
|
|
|
const ACTIVE: Partition = Partition::new(4096, 16384);
|
|
|
|
const DFU: Partition = Partition::new(0, 16384);
|
|
|
|
|
2023-04-03 15:33:20 +02:00
|
|
|
let mut active = MemFlash::<16384, 4096, 8>::random();
|
2023-04-04 21:09:30 +02:00
|
|
|
let mut dfu = LargeErase::<_, 4096>::new(MemFlash::<16384, 2048, 8>::random());
|
2023-04-04 07:18:29 +02:00
|
|
|
let mut state = MemFlash::<4096, 128, 4>::random();
|
2022-08-30 13:07:35 +02:00
|
|
|
let mut aligned = [0; 4];
|
2022-04-28 10:38:25 +02:00
|
|
|
|
|
|
|
let original: [u8; ACTIVE.len()] = [rand::random::<u8>(); ACTIVE.len()];
|
|
|
|
let update: [u8; DFU.len()] = [rand::random::<u8>(); DFU.len()];
|
|
|
|
|
|
|
|
for i in ACTIVE.from..ACTIVE.to {
|
2023-04-03 15:33:20 +02:00
|
|
|
active.mem[i] = original[i - ACTIVE.from];
|
2022-04-28 10:38:25 +02:00
|
|
|
}
|
|
|
|
|
|
|
|
let mut updater = FirmwareUpdater::new(DFU, STATE);
|
|
|
|
|
2023-04-04 21:09:30 +02:00
|
|
|
block_on(updater.write_firmware(0, &update, &mut dfu)).unwrap();
|
2022-08-30 13:07:35 +02:00
|
|
|
block_on(updater.mark_updated(&mut state, &mut aligned)).unwrap();
|
|
|
|
|
|
|
|
let mut bootloader: BootLoader = BootLoader::new(ACTIVE, DFU, STATE);
|
|
|
|
let mut page = [0; 4096];
|
2022-04-28 10:38:25 +02:00
|
|
|
|
|
|
|
assert_eq!(
|
|
|
|
State::Swap,
|
|
|
|
bootloader
|
2023-04-04 20:25:55 +02:00
|
|
|
.prepare_boot(&mut MultiFlashConfig::new(&mut active, &mut state, &mut dfu), &mut page)
|
2022-04-28 10:38:25 +02:00
|
|
|
.unwrap()
|
|
|
|
);
|
|
|
|
|
|
|
|
for i in ACTIVE.from..ACTIVE.to {
|
2023-04-03 15:33:20 +02:00
|
|
|
assert_eq!(active.mem[i], update[i - ACTIVE.from], "Index {}", i);
|
2022-04-28 10:38:25 +02:00
|
|
|
}
|
|
|
|
|
|
|
|
// First DFU page is untouched
|
|
|
|
for i in DFU.from + 4096..DFU.to {
|
2023-04-04 21:09:30 +02:00
|
|
|
assert_eq!(dfu.0.mem[i], original[i - DFU.from - 4096], "Index {}", i);
|
2022-04-28 10:38:25 +02:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
#[test]
|
2023-01-06 12:21:39 +01:00
|
|
|
#[cfg(not(feature = "_verify"))]
|
2022-04-28 10:38:25 +02:00
|
|
|
fn test_separate_flash_dfu_page_biggest() {
|
|
|
|
const STATE: Partition = Partition::new(2048, 4096);
|
|
|
|
const ACTIVE: Partition = Partition::new(4096, 16384);
|
|
|
|
const DFU: Partition = Partition::new(0, 16384);
|
|
|
|
|
2022-08-30 13:07:35 +02:00
|
|
|
let mut aligned = [0; 4];
|
2023-04-04 21:09:30 +02:00
|
|
|
let mut active = LargeErase::<_, 4096>::new(MemFlash::<16384, 2048, 4>::random());
|
2023-04-03 15:33:20 +02:00
|
|
|
let mut dfu = MemFlash::<16384, 4096, 8>::random();
|
2023-04-04 07:18:29 +02:00
|
|
|
let mut state = MemFlash::<4096, 128, 4>::random();
|
2022-04-28 10:38:25 +02:00
|
|
|
|
|
|
|
let original: [u8; ACTIVE.len()] = [rand::random::<u8>(); ACTIVE.len()];
|
|
|
|
let update: [u8; DFU.len()] = [rand::random::<u8>(); DFU.len()];
|
2022-01-24 12:54:09 +01:00
|
|
|
|
2022-04-28 10:38:25 +02:00
|
|
|
for i in ACTIVE.from..ACTIVE.to {
|
2023-04-04 21:09:30 +02:00
|
|
|
active.0.mem[i] = original[i - ACTIVE.from];
|
2022-04-28 10:38:25 +02:00
|
|
|
}
|
|
|
|
|
|
|
|
let mut updater = FirmwareUpdater::new(DFU, STATE);
|
|
|
|
|
2023-04-04 21:09:30 +02:00
|
|
|
block_on(updater.write_firmware(0, &update, &mut dfu)).unwrap();
|
2022-08-30 13:07:35 +02:00
|
|
|
block_on(updater.mark_updated(&mut state, &mut aligned)).unwrap();
|
2022-04-28 10:38:25 +02:00
|
|
|
|
2022-08-30 13:07:35 +02:00
|
|
|
let mut bootloader: BootLoader = BootLoader::new(ACTIVE, DFU, STATE);
|
|
|
|
let mut page = [0; 4096];
|
2022-04-28 10:38:25 +02:00
|
|
|
assert_eq!(
|
|
|
|
State::Swap,
|
|
|
|
bootloader
|
2022-08-30 13:07:35 +02:00
|
|
|
.prepare_boot(
|
|
|
|
&mut MultiFlashConfig::new(&mut active, &mut state, &mut dfu,),
|
|
|
|
&mut page
|
|
|
|
)
|
2022-04-28 10:38:25 +02:00
|
|
|
.unwrap()
|
|
|
|
);
|
|
|
|
|
|
|
|
for i in ACTIVE.from..ACTIVE.to {
|
2023-04-04 21:09:30 +02:00
|
|
|
assert_eq!(active.0.mem[i], update[i - ACTIVE.from], "Index {}", i);
|
2022-04-28 10:38:25 +02:00
|
|
|
}
|
|
|
|
|
|
|
|
// First DFU page is untouched
|
|
|
|
for i in DFU.from + 4096..DFU.to {
|
2023-04-03 15:33:20 +02:00
|
|
|
assert_eq!(dfu.mem[i], original[i - DFU.from - 4096], "Index {}", i);
|
2022-04-28 10:38:25 +02:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2023-01-06 12:21:39 +01:00
|
|
|
#[test]
|
|
|
|
#[cfg(feature = "_verify")]
|
|
|
|
fn test_verify() {
|
|
|
|
// The following key setup is based on:
|
|
|
|
// https://docs.rs/ed25519-dalek/latest/ed25519_dalek/#example
|
|
|
|
|
|
|
|
use ed25519_dalek::Keypair;
|
|
|
|
use rand::rngs::OsRng;
|
|
|
|
|
|
|
|
let mut csprng = OsRng {};
|
|
|
|
let keypair: Keypair = Keypair::generate(&mut csprng);
|
|
|
|
|
|
|
|
use ed25519_dalek::{Digest, Sha512, Signature, Signer};
|
|
|
|
let firmware: &[u8] = b"This are bytes that would otherwise be firmware bytes for DFU.";
|
|
|
|
let mut digest = Sha512::new();
|
|
|
|
digest.update(&firmware);
|
|
|
|
let message = digest.finalize();
|
|
|
|
let signature: Signature = keypair.sign(&message);
|
|
|
|
|
|
|
|
use ed25519_dalek::PublicKey;
|
|
|
|
let public_key: PublicKey = keypair.public;
|
|
|
|
|
|
|
|
// Setup flash
|
|
|
|
|
|
|
|
const STATE: Partition = Partition::new(0, 4096);
|
|
|
|
const DFU: Partition = Partition::new(4096, 8192);
|
2023-04-04 12:36:50 +02:00
|
|
|
let mut flash = MemFlash::<8192, 4096, 4>::default();
|
2023-01-06 12:21:39 +01:00
|
|
|
|
|
|
|
let firmware_len = firmware.len();
|
|
|
|
|
|
|
|
let mut write_buf = [0; 4096];
|
|
|
|
write_buf[0..firmware_len].copy_from_slice(firmware);
|
2023-04-04 12:36:50 +02:00
|
|
|
DFU.write_blocking(&mut flash, 0, &write_buf).unwrap();
|
2023-01-06 12:21:39 +01:00
|
|
|
|
|
|
|
// On with the test
|
|
|
|
|
|
|
|
let mut updater = FirmwareUpdater::new(DFU, STATE);
|
|
|
|
|
|
|
|
let mut aligned = [0; 4];
|
|
|
|
|
|
|
|
assert!(block_on(updater.verify_and_mark_updated(
|
|
|
|
&mut flash,
|
|
|
|
&public_key.to_bytes(),
|
|
|
|
&signature.to_bytes(),
|
|
|
|
firmware_len,
|
|
|
|
&mut aligned,
|
|
|
|
))
|
|
|
|
.is_ok());
|
|
|
|
}
|
2022-01-24 12:54:09 +01:00
|
|
|
}
|