hw/arm: add authenticated A6 IMG3 boot lab
Model the A6 crypto, interrupt, USB, and platform blocks needed to boot SecureROM through iBSS into iBEC Recovery. Add local lab identity, IMG3, and APTicket tooling, patched macOS recovery utilities, UART and GDB access, and English end-user documentation.
This commit is contained in:
+133
-10
@@ -3,18 +3,78 @@ set -eu
|
||||
|
||||
script_dir=$(CDPATH= cd -- "$(dirname -- "$0")" && pwd)
|
||||
qemu_bin=${QEMU_BIN:-"$script_dir/build/qemu-system-arm"}
|
||||
rom_path=${ROM_PATH:-"$script_dir/firmware/s5l8950x-secure-rom.bin"}
|
||||
a6_lab_dir=${A6_LAB_DIR:-}
|
||||
if [ -n "$a6_lab_dir" ]; then
|
||||
a6_lab_dir=$(CDPATH= cd -- "$a6_lab_dir" && pwd)
|
||||
rom_path=${ROM_PATH:-"$a6_lab_dir/s5l8950x-secure-rom-lab.bin"}
|
||||
gid_key_path=${GID_KEY_PATH:-"$a6_lab_dir/gid-key.bin"}
|
||||
native_img3=${NATIVE_IMG3:-1}
|
||||
else
|
||||
rom_path=${ROM_PATH:-"$script_dir/firmware/s5l8950x-secure-rom.bin"}
|
||||
gid_key_path=${GID_KEY_PATH:-}
|
||||
native_img3=${NATIVE_IMG3:-0}
|
||||
fi
|
||||
dfu_image=${DFU_IMAGE:-}
|
||||
gdb_port=${GDB_PORT:-}
|
||||
paused=${PAUSED:-0}
|
||||
usb_bridge_port=${USB_BRIDGE_PORT:-26050}
|
||||
debug_uart=${DEBUG_UART:-1}
|
||||
|
||||
case $debug_uart in
|
||||
0|1) ;;
|
||||
*)
|
||||
echo "DEBUG_UART must be 0 or 1." >&2
|
||||
exit 1
|
||||
;;
|
||||
esac
|
||||
|
||||
case $native_img3 in
|
||||
0|1) ;;
|
||||
*)
|
||||
echo "NATIVE_IMG3 must be 0 or 1." >&2
|
||||
exit 1
|
||||
;;
|
||||
esac
|
||||
|
||||
case $gdb_port in
|
||||
''|*[!0-9]*)
|
||||
if [ -n "$gdb_port" ]; then
|
||||
echo "GDB_PORT must be an integer between 1 and 65535." >&2
|
||||
exit 1
|
||||
fi
|
||||
;;
|
||||
esac
|
||||
if [ -n "$gdb_port" ] &&
|
||||
{ [ "$gdb_port" -lt 1 ] || [ "$gdb_port" -gt 65535 ]; }; then
|
||||
echo "GDB_PORT must be between 1 and 65535." >&2
|
||||
exit 1
|
||||
fi
|
||||
if [ "$paused" != 0 ] && [ -z "$gdb_port" ]; then
|
||||
gdb_port=1234
|
||||
fi
|
||||
|
||||
case $usb_bridge_port in
|
||||
''|*[!0-9]*)
|
||||
echo "USB_BRIDGE_PORT must be an integer between 0 and 65535." >&2
|
||||
exit 1
|
||||
;;
|
||||
esac
|
||||
if [ "$usb_bridge_port" -gt 65535 ]; then
|
||||
echo "USB_BRIDGE_PORT must be between 0 and 65535." >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
if [ ! -x "$qemu_bin" ]; then
|
||||
echo "QEMU introuvable: $qemu_bin" >&2
|
||||
echo "Configurez ce dépôt avec --target-list=arm-softmmu puis compilez-le." >&2
|
||||
echo "QEMU not found: $qemu_bin" >&2
|
||||
echo "Configure this repository with --target-list=arm-softmmu," \
|
||||
"then build it." >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
if [ ! -f "$rom_path" ]; then
|
||||
echo "SecureROM introuvable: $rom_path" >&2
|
||||
echo "Placez votre dump A6 de 65536 octets dans firmware/s5l8950x-secure-rom.bin." >&2
|
||||
echo "SecureROM not found: $rom_path" >&2
|
||||
echo "Place your 65536-byte A6 dump at" \
|
||||
"firmware/s5l8950x-secure-rom.bin." >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
@@ -26,22 +86,85 @@ set -- \
|
||||
-display none \
|
||||
-serial mon:stdio
|
||||
|
||||
if [ "$debug_uart" = 1 ]; then
|
||||
set -- "$@" \
|
||||
-global s5l8950x-usb-otg.force-debug-uarts=on \
|
||||
-global s5l8950x-aes.force-debug-uarts=on
|
||||
fi
|
||||
|
||||
if [ -n "$gid_key_path" ]; then
|
||||
if [ ! -f "$gid_key_path" ]; then
|
||||
echo "Lab GID key not found: $gid_key_path" >&2
|
||||
exit 1
|
||||
fi
|
||||
set -- "$@" -global "s5l8950x-aes.gid-key-file=$gid_key_path"
|
||||
fi
|
||||
|
||||
if [ "$native_img3" = 1 ]; then
|
||||
set -- "$@" \
|
||||
-global s5l8950x-usb-otg.native-img3-handoff=on \
|
||||
-global s5l8950x-aes.authenticated-ibec-handoff=on
|
||||
fi
|
||||
|
||||
if [ -n "$dfu_image" ]; then
|
||||
if [ ! -f "$dfu_image" ]; then
|
||||
echo "Image DFU introuvable: $dfu_image" >&2
|
||||
echo "DFU image not found: $dfu_image" >&2
|
||||
exit 1
|
||||
fi
|
||||
set -- "$@" -global "s5l8950x-usb-otg.dfu-image=$dfu_image"
|
||||
fi
|
||||
|
||||
if [ "$usb_bridge_port" -ne 0 ]; then
|
||||
usb_chardev="socket,id=a6usb,host=127.0.0.1,port=$usb_bridge_port"
|
||||
usb_chardev="$usb_chardev,server=on,wait=off"
|
||||
set -- "$@" \
|
||||
-chardev "$usb_chardev" \
|
||||
-global "s5l8950x-usb-otg.usb-bridge=a6usb"
|
||||
fi
|
||||
|
||||
if [ -n "$gdb_port" ]; then
|
||||
set -- "$@" -gdb "tcp:127.0.0.1:$gdb_port"
|
||||
fi
|
||||
if [ "$paused" != 0 ]; then
|
||||
set -- "$@" -S
|
||||
fi
|
||||
|
||||
echo "QEMU macOS : $qemu_bin"
|
||||
echo "SecureROM : $rom_path"
|
||||
if [ -n "$dfu_image" ]; then
|
||||
echo "Image DFU : $dfu_image"
|
||||
echo "Injection DFU interne active."
|
||||
echo "DFU image : $dfu_image"
|
||||
echo "Internal DFU injection is enabled."
|
||||
else
|
||||
echo "La SecureROM attend en dfuIDLE."
|
||||
echo "SecureROM is waiting in dfuIDLE."
|
||||
fi
|
||||
echo "A6 UART : this console (Ctrl+A C = monitor, Ctrl+A X = quit)"
|
||||
if [ -n "$gid_key_path" ]; then
|
||||
echo "AES GID : lab identity active (private key is not displayed)"
|
||||
else
|
||||
echo "AES GID : no lab GID slot configured"
|
||||
fi
|
||||
if [ "$native_img3" = 1 ]; then
|
||||
echo "IMG3 handoff: authenticated iBEC transfer to 0xbff00000"
|
||||
else
|
||||
echo "IMG3 handoff: synthetic USB bridge compatibility mode"
|
||||
fi
|
||||
if [ "$debug_uart" = 1 ]; then
|
||||
echo "debug-uarts: forced to 3 in iBSS/iBEC after IMG3 validation"
|
||||
else
|
||||
echo "debug-uarts: native firmware behavior (DEBUG_UART=0)"
|
||||
fi
|
||||
if [ "$usb_bridge_port" -ne 0 ]; then
|
||||
echo "USB tools : QEMU at 127.0.0.1:$usb_bridge_port"
|
||||
echo "irecovery : scripts/irecovery-qemu -q"
|
||||
else
|
||||
echo "USB tools : disabled (USB_BRIDGE_PORT=0)"
|
||||
fi
|
||||
if [ -n "$gdb_port" ]; then
|
||||
echo "Debugger : remote GDB at 127.0.0.1:$gdb_port"
|
||||
echo "LLDB : lldb -o 'gdb-remote 127.0.0.1:$gdb_port'"
|
||||
fi
|
||||
if [ "$paused" != 0 ]; then
|
||||
echo "CPU : paused until the debugger issues continue"
|
||||
fi
|
||||
echo "UART A6 : cette console (Ctrl+A C = moniteur, Ctrl+A X = quitter)"
|
||||
|
||||
exec "$qemu_bin" "$@"
|
||||
|
||||
Reference in New Issue
Block a user