1bd5d9c74SNayna Jain // SPDX-License-Identifier: GPL-2.0+
2bd5d9c74SNayna Jain /*
3bd5d9c74SNayna Jain * Copyright (C) 2019 IBM Corporation <nayna@linux.ibm.com>
4bd5d9c74SNayna Jain *
5bd5d9c74SNayna Jain * This code exposes secure variables to user via sysfs
6bd5d9c74SNayna Jain */
7bd5d9c74SNayna Jain
8bd5d9c74SNayna Jain #define pr_fmt(fmt) "secvar-sysfs: "fmt
9bd5d9c74SNayna Jain
10bd5d9c74SNayna Jain #include <linux/slab.h>
11bd5d9c74SNayna Jain #include <linux/compat.h>
12bd5d9c74SNayna Jain #include <linux/string.h>
13bd5d9c74SNayna Jain #include <linux/of.h>
14bd5d9c74SNayna Jain #include <asm/secvar.h>
15bd5d9c74SNayna Jain
16bd5d9c74SNayna Jain #define NAME_MAX_SIZE 1024
17bd5d9c74SNayna Jain
18bd5d9c74SNayna Jain static struct kobject *secvar_kobj;
19bd5d9c74SNayna Jain static struct kset *secvar_kset;
20bd5d9c74SNayna Jain
format_show(struct kobject * kobj,struct kobj_attribute * attr,char * buf)21bd5d9c74SNayna Jain static ssize_t format_show(struct kobject *kobj, struct kobj_attribute *attr,
22bd5d9c74SNayna Jain char *buf)
23bd5d9c74SNayna Jain {
24ec2f40bdSRussell Currey char tmp[32];
25ec2f40bdSRussell Currey ssize_t len = secvar_ops->format(tmp, sizeof(tmp));
26bd5d9c74SNayna Jain
27ec2f40bdSRussell Currey if (len > 0)
28ec2f40bdSRussell Currey return sysfs_emit(buf, "%s\n", tmp);
29ec2f40bdSRussell Currey else if (len < 0)
30ec2f40bdSRussell Currey pr_err("Error %zd reading format string\n", len);
31ec2f40bdSRussell Currey else
32ec2f40bdSRussell Currey pr_err("Got empty format string from backend\n");
33bd5d9c74SNayna Jain
34ec2f40bdSRussell Currey return -EIO;
35bd5d9c74SNayna Jain }
36bd5d9c74SNayna Jain
37bd5d9c74SNayna Jain
size_show(struct kobject * kobj,struct kobj_attribute * attr,char * buf)38bd5d9c74SNayna Jain static ssize_t size_show(struct kobject *kobj, struct kobj_attribute *attr,
39bd5d9c74SNayna Jain char *buf)
40bd5d9c74SNayna Jain {
4153cea34bSMichael Ellerman u64 dsize;
42bd5d9c74SNayna Jain int rc;
43bd5d9c74SNayna Jain
44bd5d9c74SNayna Jain rc = secvar_ops->get(kobj->name, strlen(kobj->name) + 1, NULL, &dsize);
45bd5d9c74SNayna Jain if (rc) {
46*c96db155SAndrew Donnellan if (rc != -ENOENT)
47*c96db155SAndrew Donnellan pr_err("Error retrieving %s variable size %d\n", kobj->name, rc);
48bd5d9c74SNayna Jain return rc;
49bd5d9c74SNayna Jain }
50bd5d9c74SNayna Jain
5116943a2fSRussell Currey return sysfs_emit(buf, "%llu\n", dsize);
52bd5d9c74SNayna Jain }
53bd5d9c74SNayna Jain
data_read(struct file * filep,struct kobject * kobj,struct bin_attribute * attr,char * buf,loff_t off,size_t count)54bd5d9c74SNayna Jain static ssize_t data_read(struct file *filep, struct kobject *kobj,
55bd5d9c74SNayna Jain struct bin_attribute *attr, char *buf, loff_t off,
56bd5d9c74SNayna Jain size_t count)
57bd5d9c74SNayna Jain {
58bd5d9c74SNayna Jain char *data;
5953cea34bSMichael Ellerman u64 dsize;
60bd5d9c74SNayna Jain int rc;
61bd5d9c74SNayna Jain
62bd5d9c74SNayna Jain rc = secvar_ops->get(kobj->name, strlen(kobj->name) + 1, NULL, &dsize);
63bd5d9c74SNayna Jain if (rc) {
64*c96db155SAndrew Donnellan if (rc != -ENOENT)
65bd5d9c74SNayna Jain pr_err("Error getting %s variable size %d\n", kobj->name, rc);
66bd5d9c74SNayna Jain return rc;
67bd5d9c74SNayna Jain }
68bd5d9c74SNayna Jain pr_debug("dsize is %llu\n", dsize);
69bd5d9c74SNayna Jain
70bd5d9c74SNayna Jain data = kzalloc(dsize, GFP_KERNEL);
71bd5d9c74SNayna Jain if (!data)
72bd5d9c74SNayna Jain return -ENOMEM;
73bd5d9c74SNayna Jain
74bd5d9c74SNayna Jain rc = secvar_ops->get(kobj->name, strlen(kobj->name) + 1, data, &dsize);
75bd5d9c74SNayna Jain if (rc) {
76bd5d9c74SNayna Jain pr_err("Error getting %s variable %d\n", kobj->name, rc);
77bd5d9c74SNayna Jain goto data_fail;
78bd5d9c74SNayna Jain }
79bd5d9c74SNayna Jain
80bd5d9c74SNayna Jain rc = memory_read_from_buffer(buf, count, &off, data, dsize);
81bd5d9c74SNayna Jain
82bd5d9c74SNayna Jain data_fail:
83bd5d9c74SNayna Jain kfree(data);
84bd5d9c74SNayna Jain return rc;
85bd5d9c74SNayna Jain }
86bd5d9c74SNayna Jain
update_write(struct file * filep,struct kobject * kobj,struct bin_attribute * attr,char * buf,loff_t off,size_t count)87bd5d9c74SNayna Jain static ssize_t update_write(struct file *filep, struct kobject *kobj,
88bd5d9c74SNayna Jain struct bin_attribute *attr, char *buf, loff_t off,
89bd5d9c74SNayna Jain size_t count)
90bd5d9c74SNayna Jain {
91bd5d9c74SNayna Jain int rc;
92bd5d9c74SNayna Jain
93bd5d9c74SNayna Jain pr_debug("count is %ld\n", count);
94bd5d9c74SNayna Jain rc = secvar_ops->set(kobj->name, strlen(kobj->name) + 1, buf, count);
95bd5d9c74SNayna Jain if (rc) {
96bd5d9c74SNayna Jain pr_err("Error setting the %s variable %d\n", kobj->name, rc);
97bd5d9c74SNayna Jain return rc;
98bd5d9c74SNayna Jain }
99bd5d9c74SNayna Jain
100bd5d9c74SNayna Jain return count;
101bd5d9c74SNayna Jain }
102bd5d9c74SNayna Jain
103bd5d9c74SNayna Jain static struct kobj_attribute format_attr = __ATTR_RO(format);
104bd5d9c74SNayna Jain
105bd5d9c74SNayna Jain static struct kobj_attribute size_attr = __ATTR_RO(size);
106bd5d9c74SNayna Jain
107bd5d9c74SNayna Jain static struct bin_attribute data_attr = __BIN_ATTR_RO(data, 0);
108bd5d9c74SNayna Jain
109bd5d9c74SNayna Jain static struct bin_attribute update_attr = __BIN_ATTR_WO(update, 0);
110bd5d9c74SNayna Jain
111bd5d9c74SNayna Jain static struct bin_attribute *secvar_bin_attrs[] = {
112bd5d9c74SNayna Jain &data_attr,
113bd5d9c74SNayna Jain &update_attr,
114bd5d9c74SNayna Jain NULL,
115bd5d9c74SNayna Jain };
116bd5d9c74SNayna Jain
117bd5d9c74SNayna Jain static struct attribute *secvar_attrs[] = {
118bd5d9c74SNayna Jain &size_attr.attr,
119bd5d9c74SNayna Jain NULL,
120bd5d9c74SNayna Jain };
121bd5d9c74SNayna Jain
122bd5d9c74SNayna Jain static const struct attribute_group secvar_attr_group = {
123bd5d9c74SNayna Jain .attrs = secvar_attrs,
124bd5d9c74SNayna Jain .bin_attrs = secvar_bin_attrs,
125bd5d9c74SNayna Jain };
126bd5d9c74SNayna Jain __ATTRIBUTE_GROUPS(secvar_attr);
127bd5d9c74SNayna Jain
128bd5d9c74SNayna Jain static struct kobj_type secvar_ktype = {
129bd5d9c74SNayna Jain .sysfs_ops = &kobj_sysfs_ops,
130bd5d9c74SNayna Jain .default_groups = secvar_attr_groups,
131bd5d9c74SNayna Jain };
132bd5d9c74SNayna Jain
update_kobj_size(void)133bd5d9c74SNayna Jain static int update_kobj_size(void)
134bd5d9c74SNayna Jain {
135bd5d9c74SNayna Jain
136bd5d9c74SNayna Jain u64 varsize;
137e0240794SRussell Currey int rc = secvar_ops->max_size(&varsize);
138bd5d9c74SNayna Jain
139bd5d9c74SNayna Jain if (rc)
140e0240794SRussell Currey return rc;
141bd5d9c74SNayna Jain
142bd5d9c74SNayna Jain data_attr.size = varsize;
143bd5d9c74SNayna Jain update_attr.size = varsize;
144bd5d9c74SNayna Jain
145e0240794SRussell Currey return 0;
146bd5d9c74SNayna Jain }
147bd5d9c74SNayna Jain
secvar_sysfs_config(struct kobject * kobj)14886b6c0aeSRussell Currey static int secvar_sysfs_config(struct kobject *kobj)
14986b6c0aeSRussell Currey {
15086b6c0aeSRussell Currey struct attribute_group config_group = {
15186b6c0aeSRussell Currey .name = "config",
15286b6c0aeSRussell Currey .attrs = (struct attribute **)secvar_ops->config_attrs,
15386b6c0aeSRussell Currey };
15486b6c0aeSRussell Currey
15586b6c0aeSRussell Currey if (secvar_ops->config_attrs)
15686b6c0aeSRussell Currey return sysfs_create_group(kobj, &config_group);
15786b6c0aeSRussell Currey
15886b6c0aeSRussell Currey return 0;
15986b6c0aeSRussell Currey }
16086b6c0aeSRussell Currey
add_var(const char * name)16150a466bfSAndrew Donnellan static int add_var(const char *name)
162bd5d9c74SNayna Jain {
163bd5d9c74SNayna Jain struct kobject *kobj;
16450a466bfSAndrew Donnellan int rc;
16550a466bfSAndrew Donnellan
16650a466bfSAndrew Donnellan kobj = kzalloc(sizeof(*kobj), GFP_KERNEL);
16750a466bfSAndrew Donnellan if (!kobj)
16850a466bfSAndrew Donnellan return -ENOMEM;
16950a466bfSAndrew Donnellan
17050a466bfSAndrew Donnellan kobject_init(kobj, &secvar_ktype);
17150a466bfSAndrew Donnellan
17250a466bfSAndrew Donnellan rc = kobject_add(kobj, &secvar_kset->kobj, "%s", name);
17350a466bfSAndrew Donnellan if (rc) {
17450a466bfSAndrew Donnellan pr_warn("kobject_add error %d for attribute: %s\n", rc,
17550a466bfSAndrew Donnellan name);
17650a466bfSAndrew Donnellan kobject_put(kobj);
17750a466bfSAndrew Donnellan return rc;
17850a466bfSAndrew Donnellan }
17950a466bfSAndrew Donnellan
18050a466bfSAndrew Donnellan kobject_uevent(kobj, KOBJ_ADD);
18150a466bfSAndrew Donnellan return 0;
18250a466bfSAndrew Donnellan }
18350a466bfSAndrew Donnellan
secvar_sysfs_load(void)18450a466bfSAndrew Donnellan static int secvar_sysfs_load(void)
18550a466bfSAndrew Donnellan {
18653cea34bSMichael Ellerman u64 namesize = 0;
18753cea34bSMichael Ellerman char *name;
188bd5d9c74SNayna Jain int rc;
189bd5d9c74SNayna Jain
190bd5d9c74SNayna Jain name = kzalloc(NAME_MAX_SIZE, GFP_KERNEL);
191bd5d9c74SNayna Jain if (!name)
192bd5d9c74SNayna Jain return -ENOMEM;
193bd5d9c74SNayna Jain
194bd5d9c74SNayna Jain do {
195bd5d9c74SNayna Jain rc = secvar_ops->get_next(name, &namesize, NAME_MAX_SIZE);
196bd5d9c74SNayna Jain if (rc) {
197bd5d9c74SNayna Jain if (rc != -ENOENT)
198c9fd2952SRussell Currey pr_err("error getting secvar from firmware %d\n", rc);
199c9fd2952SRussell Currey else
200c9fd2952SRussell Currey rc = 0;
201c9fd2952SRussell Currey
202bd5d9c74SNayna Jain break;
203bd5d9c74SNayna Jain }
204bd5d9c74SNayna Jain
20550a466bfSAndrew Donnellan rc = add_var(name);
206bd5d9c74SNayna Jain } while (!rc);
207bd5d9c74SNayna Jain
208bd5d9c74SNayna Jain kfree(name);
209bd5d9c74SNayna Jain return rc;
210bd5d9c74SNayna Jain }
211bd5d9c74SNayna Jain
secvar_sysfs_load_static(void)21250a466bfSAndrew Donnellan static int secvar_sysfs_load_static(void)
21350a466bfSAndrew Donnellan {
21450a466bfSAndrew Donnellan const char * const *name_ptr = secvar_ops->var_names;
21550a466bfSAndrew Donnellan int rc;
21650a466bfSAndrew Donnellan
21750a466bfSAndrew Donnellan while (*name_ptr) {
21850a466bfSAndrew Donnellan rc = add_var(*name_ptr);
21950a466bfSAndrew Donnellan if (rc)
22050a466bfSAndrew Donnellan return rc;
22150a466bfSAndrew Donnellan name_ptr++;
22250a466bfSAndrew Donnellan }
22350a466bfSAndrew Donnellan
22450a466bfSAndrew Donnellan return 0;
22550a466bfSAndrew Donnellan }
22650a466bfSAndrew Donnellan
secvar_sysfs_init(void)227bd5d9c74SNayna Jain static int secvar_sysfs_init(void)
228bd5d9c74SNayna Jain {
2296d64c497SAndrew Donnellan u64 max_size;
230bd5d9c74SNayna Jain int rc;
231bd5d9c74SNayna Jain
232bd5d9c74SNayna Jain if (!secvar_ops) {
233caefd3b7SAndrew Donnellan pr_warn("Failed to retrieve secvar operations\n");
234bd5d9c74SNayna Jain return -ENODEV;
235bd5d9c74SNayna Jain }
236bd5d9c74SNayna Jain
237bd5d9c74SNayna Jain secvar_kobj = kobject_create_and_add("secvar", firmware_kobj);
238bd5d9c74SNayna Jain if (!secvar_kobj) {
239caefd3b7SAndrew Donnellan pr_err("Failed to create firmware kobj\n");
240bd5d9c74SNayna Jain return -ENOMEM;
241bd5d9c74SNayna Jain }
242bd5d9c74SNayna Jain
243bd5d9c74SNayna Jain rc = sysfs_create_file(secvar_kobj, &format_attr.attr);
244bd5d9c74SNayna Jain if (rc) {
24586b6c0aeSRussell Currey pr_err("Failed to create format object\n");
24686b6c0aeSRussell Currey rc = -ENOMEM;
24786b6c0aeSRussell Currey goto err;
248bd5d9c74SNayna Jain }
249bd5d9c74SNayna Jain
250bd5d9c74SNayna Jain secvar_kset = kset_create_and_add("vars", NULL, secvar_kobj);
251bd5d9c74SNayna Jain if (!secvar_kset) {
252caefd3b7SAndrew Donnellan pr_err("sysfs kobject registration failed\n");
25386b6c0aeSRussell Currey rc = -ENOMEM;
25486b6c0aeSRussell Currey goto err;
255bd5d9c74SNayna Jain }
256bd5d9c74SNayna Jain
257bd5d9c74SNayna Jain rc = update_kobj_size();
258bd5d9c74SNayna Jain if (rc) {
259bd5d9c74SNayna Jain pr_err("Cannot read the size of the attribute\n");
26086b6c0aeSRussell Currey goto err;
26186b6c0aeSRussell Currey }
26286b6c0aeSRussell Currey
26386b6c0aeSRussell Currey rc = secvar_sysfs_config(secvar_kobj);
26486b6c0aeSRussell Currey if (rc) {
26586b6c0aeSRussell Currey pr_err("Failed to create config directory\n");
26686b6c0aeSRussell Currey goto err;
267bd5d9c74SNayna Jain }
268bd5d9c74SNayna Jain
26950a466bfSAndrew Donnellan if (secvar_ops->get_next)
27050a466bfSAndrew Donnellan rc = secvar_sysfs_load();
27150a466bfSAndrew Donnellan else
27250a466bfSAndrew Donnellan rc = secvar_sysfs_load_static();
27350a466bfSAndrew Donnellan
27450a466bfSAndrew Donnellan if (rc) {
27550a466bfSAndrew Donnellan pr_err("Failed to create variable attributes\n");
27650a466bfSAndrew Donnellan goto err;
27750a466bfSAndrew Donnellan }
278bd5d9c74SNayna Jain
2796d64c497SAndrew Donnellan // Due to sysfs limitations, we will only ever get a write buffer of
2806d64c497SAndrew Donnellan // up to 1 page in size. Print a warning if this is potentially going
2816d64c497SAndrew Donnellan // to cause problems, so that the user is aware.
2826d64c497SAndrew Donnellan secvar_ops->max_size(&max_size);
2836d64c497SAndrew Donnellan if (max_size > PAGE_SIZE)
2846d64c497SAndrew Donnellan pr_warn_ratelimited("PAGE_SIZE (%lu) is smaller than maximum object size (%llu), writes are limited to PAGE_SIZE\n",
2856d64c497SAndrew Donnellan PAGE_SIZE, max_size);
2866d64c497SAndrew Donnellan
287bd5d9c74SNayna Jain return 0;
28886b6c0aeSRussell Currey err:
28986b6c0aeSRussell Currey kobject_put(secvar_kobj);
29086b6c0aeSRussell Currey return rc;
291bd5d9c74SNayna Jain }
292bd5d9c74SNayna Jain
293bd5d9c74SNayna Jain late_initcall(secvar_sysfs_init);
294