esp_image_format.c 5.7 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161
  1. // Copyright 2015-2016 Espressif Systems (Shanghai) PTE LTD
  2. //
  3. // Licensed under the Apache License, Version 2.0 (the "License");
  4. // you may not use this file except in compliance with the License.
  5. // You may obtain a copy of the License at
  6. // http://www.apache.org/licenses/LICENSE-2.0
  7. //
  8. // Unless required by applicable law or agreed to in writing, software
  9. // distributed under the License is distributed on an "AS IS" BASIS,
  10. // WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  11. // See the License for the specific language governing permissions and
  12. // limitations under the License.
  13. #include <string.h>
  14. #include <esp_image_format.h>
  15. #include <esp_log.h>
  16. #include <bootloader_flash.h>
  17. const static char *TAG = "esp_image";
  18. #define SIXTEEN_MB 0x1000000
  19. #define ESP_ROM_CHECKSUM_INITIAL 0xEF
  20. esp_err_t esp_image_load_header(uint32_t src_addr, esp_image_header_t *image_header)
  21. {
  22. esp_err_t err;
  23. ESP_LOGD(TAG, "reading image header @ 0x%x", src_addr);
  24. err = bootloader_flash_read(src_addr, image_header, sizeof(esp_image_header_t));
  25. if (err == ESP_OK) {
  26. if (image_header->magic != ESP_IMAGE_HEADER_MAGIC) {
  27. ESP_LOGE(TAG, "image at 0x%x has invalid magic byte", src_addr);
  28. err = ESP_ERR_IMAGE_INVALID;
  29. }
  30. if (image_header->spi_mode > ESP_IMAGE_SPI_MODE_SLOW_READ) {
  31. ESP_LOGW(TAG, "image at 0x%x has invalid SPI mode %d", src_addr, image_header->spi_mode);
  32. }
  33. if (image_header->spi_speed > ESP_IMAGE_SPI_SPEED_80M) {
  34. ESP_LOGW(TAG, "image at 0x%x has invalid SPI speed %d", src_addr, image_header->spi_speed);
  35. }
  36. if (image_header->spi_size > ESP_IMAGE_FLASH_SIZE_MAX) {
  37. ESP_LOGW(TAG, "image at 0x%x has invalid SPI size %d", src_addr, image_header->spi_size);
  38. }
  39. }
  40. if (err != ESP_OK) {
  41. bzero(image_header, sizeof(esp_image_header_t));
  42. }
  43. return err;
  44. }
  45. esp_err_t esp_image_load_segment_header(uint8_t index, uint32_t src_addr, const esp_image_header_t *image_header, esp_image_segment_header_t *segment_header, uint32_t *segment_data_offset)
  46. {
  47. esp_err_t err = ESP_OK;
  48. uint32_t next_addr = src_addr + sizeof(esp_image_header_t);
  49. if(index >= image_header->segment_count) {
  50. ESP_LOGE(TAG, "index %d higher than segment count %d", index, image_header->segment_count);
  51. return ESP_ERR_INVALID_ARG;
  52. }
  53. for(int i = 0; i <= index && err == ESP_OK; i++) {
  54. ESP_LOGV(TAG, "loading segment header %d at offset 0x%x", i, next_addr);
  55. err = bootloader_flash_read(next_addr, segment_header, sizeof(esp_image_segment_header_t));
  56. if (err == ESP_OK) {
  57. if ((segment_header->data_len & 3) != 0
  58. || segment_header->data_len >= SIXTEEN_MB) {
  59. ESP_LOGE(TAG, "invalid segment length 0x%x", segment_header->data_len);
  60. err = ESP_ERR_IMAGE_INVALID;
  61. }
  62. next_addr += sizeof(esp_image_segment_header_t);
  63. ESP_LOGV(TAG, "segment data length 0x%x data starts 0x%x", segment_header->data_len, next_addr);
  64. *segment_data_offset = next_addr;
  65. next_addr += segment_header->data_len;
  66. }
  67. }
  68. if (err != ESP_OK) {
  69. *segment_data_offset = 0;
  70. bzero(segment_header, sizeof(esp_image_segment_header_t));
  71. }
  72. return err;
  73. }
  74. esp_err_t esp_image_basic_verify(uint32_t src_addr, uint32_t *p_length)
  75. {
  76. esp_err_t err;
  77. uint8_t buf[16];
  78. uint8_t checksum = ESP_ROM_CHECKSUM_INITIAL;
  79. esp_image_header_t image_header;
  80. esp_image_segment_header_t segment_header = { 0 };
  81. uint32_t segment_data_offs = 0;
  82. const uint8_t *segment_data;
  83. uint32_t end_addr;
  84. uint32_t length;
  85. if (p_length != NULL) {
  86. *p_length = 0;
  87. }
  88. err = esp_image_load_header(src_addr, &image_header);
  89. if (err != ESP_OK) {
  90. return err;
  91. }
  92. ESP_LOGD(TAG, "reading %d image segments", image_header.segment_count);
  93. /* Checksum each segment's data */
  94. for (int i = 0; i < image_header.segment_count; i++) {
  95. err = esp_image_load_segment_header(i, src_addr, &image_header,
  96. &segment_header, &segment_data_offs);
  97. if (err != ESP_OK) {
  98. return err;
  99. }
  100. segment_data = bootloader_mmap(segment_data_offs, segment_header.data_len);
  101. if (segment_data == NULL) {
  102. ESP_LOGE(TAG, "bootloader_mmap(0x%x, 0x%x) failed", segment_data_offs, segment_header.data_len);
  103. return ESP_FAIL;
  104. }
  105. for(int i = 0; i < segment_header.data_len; i++) {
  106. checksum ^= segment_data[i];
  107. }
  108. bootloader_munmap(segment_data);
  109. }
  110. /* End of image, verify checksum */
  111. end_addr = segment_data_offs + segment_header.data_len;
  112. if (end_addr < src_addr) {
  113. ESP_LOGE(TAG, "image offset has wrapped");
  114. return ESP_ERR_IMAGE_INVALID;
  115. }
  116. length = end_addr - src_addr;
  117. if (length >= SIXTEEN_MB) {
  118. ESP_LOGE(TAG, "invalid total length 0x%x", length);
  119. return ESP_ERR_IMAGE_INVALID;
  120. }
  121. /* image padded to next full 16 byte block, with checksum byte at very end */
  122. ESP_LOGV(TAG, "unpadded image length 0x%x", length);
  123. length += 16; /* always pad by at least 1 byte */
  124. length = length - (length % 16);
  125. ESP_LOGV(TAG, "padded image length 0x%x", length);
  126. ESP_LOGD(TAG, "reading checksum block at 0x%x", src_addr + length - 16);
  127. bootloader_flash_read(src_addr + length - 16, buf, 16);
  128. if (checksum != buf[15]) {
  129. ESP_LOGE(TAG, "checksum failed. Calculated 0x%x read 0x%x",
  130. checksum, buf[15]);
  131. return ESP_ERR_IMAGE_INVALID;
  132. }
  133. if (p_length != NULL) {
  134. *p_length = length;
  135. }
  136. return ESP_OK;
  137. }