* Asks the EC to protect or unprotect the specified flash region. */
| 187 | * Asks the EC to protect or unprotect the specified flash region. |
| 188 | */ |
| 189 | static vb2_error_t ec_protect_flash(int enable) |
| 190 | { |
| 191 | struct ec_response_flash_protect resp; |
| 192 | uint32_t protected_region = EC_FLASH_PROTECT_ALL_NOW; |
| 193 | const uint32_t mask = EC_FLASH_PROTECT_ALL_NOW | EC_FLASH_PROTECT_ALL_AT_BOOT; |
| 194 | |
| 195 | if (google_chromeec_flash_protect(mask, enable ? mask : 0, &resp) != 0) |
| 196 | return VB2_ERROR_UNKNOWN; |
| 197 | |
| 198 | if (!enable) { |
| 199 | /* If protection is still enabled, need reboot */ |
| 200 | if (resp.flags & protected_region) |
| 201 | return VB2_REQUEST_REBOOT_EC_TO_RO; |
| 202 | |
| 203 | return VB2_SUCCESS; |
| 204 | } |
| 205 | |
| 206 | /* |
| 207 | * If write protect and ro-at-boot aren't both asserted, don't expect |
| 208 | * protection enabled. |
| 209 | */ |
| 210 | if ((~resp.flags) & (EC_FLASH_PROTECT_GPIO_ASSERTED | |
| 211 | EC_FLASH_PROTECT_RO_AT_BOOT)) |
| 212 | return VB2_SUCCESS; |
| 213 | |
| 214 | /* If flash is protected now, success */ |
| 215 | if (resp.flags & EC_FLASH_PROTECT_ALL_NOW) |
| 216 | return VB2_SUCCESS; |
| 217 | |
| 218 | /* If RW will be protected at boot but not now, need a reboot */ |
| 219 | if (resp.flags & EC_FLASH_PROTECT_ALL_AT_BOOT) |
| 220 | return VB2_REQUEST_REBOOT_EC_TO_RO; |
| 221 | |
| 222 | /* Otherwise, it's an error */ |
| 223 | return VB2_ERROR_UNKNOWN; |
| 224 | } |
| 225 | |
| 226 | /* Convert a firmware image type to an EC flash region */ |
| 227 | static enum ec_flash_region vboot_to_ec_region(enum vb2_firmware_selection select) |
no test coverage detected