xref: /openbmc/linux/arch/powerpc/kernel/secvar-sysfs.c (revision 53cea34b0a0a03568e189f8dfe2eb06f938986c8)
1bd5d9c74SNayna Jain // SPDX-License-Identifier: GPL-2.0+
2bd5d9c74SNayna Jain /*
3bd5d9c74SNayna Jain  * Copyright (C) 2019 IBM Corporation <nayna@linux.ibm.com>
4bd5d9c74SNayna Jain  *
5bd5d9c74SNayna Jain  * This code exposes secure variables to user via sysfs
6bd5d9c74SNayna Jain  */
7bd5d9c74SNayna Jain 
8bd5d9c74SNayna Jain #define pr_fmt(fmt) "secvar-sysfs: "fmt
9bd5d9c74SNayna Jain 
10bd5d9c74SNayna Jain #include <linux/slab.h>
11bd5d9c74SNayna Jain #include <linux/compat.h>
12bd5d9c74SNayna Jain #include <linux/string.h>
13bd5d9c74SNayna Jain #include <linux/of.h>
14bd5d9c74SNayna Jain #include <asm/secvar.h>
15bd5d9c74SNayna Jain 
16bd5d9c74SNayna Jain #define NAME_MAX_SIZE	   1024
17bd5d9c74SNayna Jain 
18bd5d9c74SNayna Jain static struct kobject *secvar_kobj;
19bd5d9c74SNayna Jain static struct kset *secvar_kset;
20bd5d9c74SNayna Jain 
21bd5d9c74SNayna Jain static ssize_t format_show(struct kobject *kobj, struct kobj_attribute *attr,
22bd5d9c74SNayna Jain 			   char *buf)
23bd5d9c74SNayna Jain {
24bd5d9c74SNayna Jain 	ssize_t rc = 0;
25bd5d9c74SNayna Jain 	struct device_node *node;
26bd5d9c74SNayna Jain 	const char *format;
27bd5d9c74SNayna Jain 
28bd5d9c74SNayna Jain 	node = of_find_compatible_node(NULL, NULL, "ibm,secvar-backend");
29d601fd24SHangyu Hua 	if (!of_device_is_available(node)) {
30d601fd24SHangyu Hua 		rc = -ENODEV;
31d601fd24SHangyu Hua 		goto out;
32d601fd24SHangyu Hua 	}
33bd5d9c74SNayna Jain 
34bd5d9c74SNayna Jain 	rc = of_property_read_string(node, "format", &format);
35bd5d9c74SNayna Jain 	if (rc)
36d601fd24SHangyu Hua 		goto out;
37bd5d9c74SNayna Jain 
38bd5d9c74SNayna Jain 	rc = sprintf(buf, "%s\n", format);
39bd5d9c74SNayna Jain 
40d601fd24SHangyu Hua out:
41bd5d9c74SNayna Jain 	of_node_put(node);
42bd5d9c74SNayna Jain 
43bd5d9c74SNayna Jain 	return rc;
44bd5d9c74SNayna Jain }
45bd5d9c74SNayna Jain 
46bd5d9c74SNayna Jain 
47bd5d9c74SNayna Jain static ssize_t size_show(struct kobject *kobj, struct kobj_attribute *attr,
48bd5d9c74SNayna Jain 			 char *buf)
49bd5d9c74SNayna Jain {
50*53cea34bSMichael Ellerman 	u64 dsize;
51bd5d9c74SNayna Jain 	int rc;
52bd5d9c74SNayna Jain 
53bd5d9c74SNayna Jain 	rc = secvar_ops->get(kobj->name, strlen(kobj->name) + 1, NULL, &dsize);
54bd5d9c74SNayna Jain 	if (rc) {
55bd5d9c74SNayna Jain 		pr_err("Error retrieving %s variable size %d\n", kobj->name,
56bd5d9c74SNayna Jain 		       rc);
57bd5d9c74SNayna Jain 		return rc;
58bd5d9c74SNayna Jain 	}
59bd5d9c74SNayna Jain 
60bd5d9c74SNayna Jain 	return sprintf(buf, "%llu\n", dsize);
61bd5d9c74SNayna Jain }
62bd5d9c74SNayna Jain 
63bd5d9c74SNayna Jain static ssize_t data_read(struct file *filep, struct kobject *kobj,
64bd5d9c74SNayna Jain 			 struct bin_attribute *attr, char *buf, loff_t off,
65bd5d9c74SNayna Jain 			 size_t count)
66bd5d9c74SNayna Jain {
67bd5d9c74SNayna Jain 	char *data;
68*53cea34bSMichael Ellerman 	u64 dsize;
69bd5d9c74SNayna Jain 	int rc;
70bd5d9c74SNayna Jain 
71bd5d9c74SNayna Jain 	rc = secvar_ops->get(kobj->name, strlen(kobj->name) + 1, NULL, &dsize);
72bd5d9c74SNayna Jain 	if (rc) {
73bd5d9c74SNayna Jain 		pr_err("Error getting %s variable size %d\n", kobj->name, rc);
74bd5d9c74SNayna Jain 		return rc;
75bd5d9c74SNayna Jain 	}
76bd5d9c74SNayna Jain 	pr_debug("dsize is %llu\n", dsize);
77bd5d9c74SNayna Jain 
78bd5d9c74SNayna Jain 	data = kzalloc(dsize, GFP_KERNEL);
79bd5d9c74SNayna Jain 	if (!data)
80bd5d9c74SNayna Jain 		return -ENOMEM;
81bd5d9c74SNayna Jain 
82bd5d9c74SNayna Jain 	rc = secvar_ops->get(kobj->name, strlen(kobj->name) + 1, data, &dsize);
83bd5d9c74SNayna Jain 	if (rc) {
84bd5d9c74SNayna Jain 		pr_err("Error getting %s variable %d\n", kobj->name, rc);
85bd5d9c74SNayna Jain 		goto data_fail;
86bd5d9c74SNayna Jain 	}
87bd5d9c74SNayna Jain 
88bd5d9c74SNayna Jain 	rc = memory_read_from_buffer(buf, count, &off, data, dsize);
89bd5d9c74SNayna Jain 
90bd5d9c74SNayna Jain data_fail:
91bd5d9c74SNayna Jain 	kfree(data);
92bd5d9c74SNayna Jain 	return rc;
93bd5d9c74SNayna Jain }
94bd5d9c74SNayna Jain 
95bd5d9c74SNayna Jain static ssize_t update_write(struct file *filep, struct kobject *kobj,
96bd5d9c74SNayna Jain 			    struct bin_attribute *attr, char *buf, loff_t off,
97bd5d9c74SNayna Jain 			    size_t count)
98bd5d9c74SNayna Jain {
99bd5d9c74SNayna Jain 	int rc;
100bd5d9c74SNayna Jain 
101bd5d9c74SNayna Jain 	pr_debug("count is %ld\n", count);
102bd5d9c74SNayna Jain 	rc = secvar_ops->set(kobj->name, strlen(kobj->name) + 1, buf, count);
103bd5d9c74SNayna Jain 	if (rc) {
104bd5d9c74SNayna Jain 		pr_err("Error setting the %s variable %d\n", kobj->name, rc);
105bd5d9c74SNayna Jain 		return rc;
106bd5d9c74SNayna Jain 	}
107bd5d9c74SNayna Jain 
108bd5d9c74SNayna Jain 	return count;
109bd5d9c74SNayna Jain }
110bd5d9c74SNayna Jain 
111bd5d9c74SNayna Jain static struct kobj_attribute format_attr = __ATTR_RO(format);
112bd5d9c74SNayna Jain 
113bd5d9c74SNayna Jain static struct kobj_attribute size_attr = __ATTR_RO(size);
114bd5d9c74SNayna Jain 
115bd5d9c74SNayna Jain static struct bin_attribute data_attr = __BIN_ATTR_RO(data, 0);
116bd5d9c74SNayna Jain 
117bd5d9c74SNayna Jain static struct bin_attribute update_attr = __BIN_ATTR_WO(update, 0);
118bd5d9c74SNayna Jain 
119bd5d9c74SNayna Jain static struct bin_attribute *secvar_bin_attrs[] = {
120bd5d9c74SNayna Jain 	&data_attr,
121bd5d9c74SNayna Jain 	&update_attr,
122bd5d9c74SNayna Jain 	NULL,
123bd5d9c74SNayna Jain };
124bd5d9c74SNayna Jain 
125bd5d9c74SNayna Jain static struct attribute *secvar_attrs[] = {
126bd5d9c74SNayna Jain 	&size_attr.attr,
127bd5d9c74SNayna Jain 	NULL,
128bd5d9c74SNayna Jain };
129bd5d9c74SNayna Jain 
130bd5d9c74SNayna Jain static const struct attribute_group secvar_attr_group = {
131bd5d9c74SNayna Jain 	.attrs = secvar_attrs,
132bd5d9c74SNayna Jain 	.bin_attrs = secvar_bin_attrs,
133bd5d9c74SNayna Jain };
134bd5d9c74SNayna Jain __ATTRIBUTE_GROUPS(secvar_attr);
135bd5d9c74SNayna Jain 
136bd5d9c74SNayna Jain static struct kobj_type secvar_ktype = {
137bd5d9c74SNayna Jain 	.sysfs_ops	= &kobj_sysfs_ops,
138bd5d9c74SNayna Jain 	.default_groups = secvar_attr_groups,
139bd5d9c74SNayna Jain };
140bd5d9c74SNayna Jain 
141bd5d9c74SNayna Jain static int update_kobj_size(void)
142bd5d9c74SNayna Jain {
143bd5d9c74SNayna Jain 
144bd5d9c74SNayna Jain 	struct device_node *node;
145bd5d9c74SNayna Jain 	u64 varsize;
146bd5d9c74SNayna Jain 	int rc = 0;
147bd5d9c74SNayna Jain 
148bd5d9c74SNayna Jain 	node = of_find_compatible_node(NULL, NULL, "ibm,secvar-backend");
149bd5d9c74SNayna Jain 	if (!of_device_is_available(node)) {
150bd5d9c74SNayna Jain 		rc = -ENODEV;
151bd5d9c74SNayna Jain 		goto out;
152bd5d9c74SNayna Jain 	}
153bd5d9c74SNayna Jain 
154bd5d9c74SNayna Jain 	rc = of_property_read_u64(node, "max-var-size", &varsize);
155bd5d9c74SNayna Jain 	if (rc)
156bd5d9c74SNayna Jain 		goto out;
157bd5d9c74SNayna Jain 
158bd5d9c74SNayna Jain 	data_attr.size = varsize;
159bd5d9c74SNayna Jain 	update_attr.size = varsize;
160bd5d9c74SNayna Jain 
161bd5d9c74SNayna Jain out:
162bd5d9c74SNayna Jain 	of_node_put(node);
163bd5d9c74SNayna Jain 
164bd5d9c74SNayna Jain 	return rc;
165bd5d9c74SNayna Jain }
166bd5d9c74SNayna Jain 
167bd5d9c74SNayna Jain static int secvar_sysfs_load(void)
168bd5d9c74SNayna Jain {
169bd5d9c74SNayna Jain 	struct kobject *kobj;
170*53cea34bSMichael Ellerman 	u64 namesize = 0;
171*53cea34bSMichael Ellerman 	char *name;
172bd5d9c74SNayna Jain 	int rc;
173bd5d9c74SNayna Jain 
174bd5d9c74SNayna Jain 	name = kzalloc(NAME_MAX_SIZE, GFP_KERNEL);
175bd5d9c74SNayna Jain 	if (!name)
176bd5d9c74SNayna Jain 		return -ENOMEM;
177bd5d9c74SNayna Jain 
178bd5d9c74SNayna Jain 	do {
179bd5d9c74SNayna Jain 		rc = secvar_ops->get_next(name, &namesize, NAME_MAX_SIZE);
180bd5d9c74SNayna Jain 		if (rc) {
181bd5d9c74SNayna Jain 			if (rc != -ENOENT)
182c9fd2952SRussell Currey 				pr_err("error getting secvar from firmware %d\n", rc);
183c9fd2952SRussell Currey 			else
184c9fd2952SRussell Currey 				rc = 0;
185c9fd2952SRussell Currey 
186bd5d9c74SNayna Jain 			break;
187bd5d9c74SNayna Jain 		}
188bd5d9c74SNayna Jain 
189bd5d9c74SNayna Jain 		kobj = kzalloc(sizeof(*kobj), GFP_KERNEL);
190bd5d9c74SNayna Jain 		if (!kobj) {
191bd5d9c74SNayna Jain 			rc = -ENOMEM;
192bd5d9c74SNayna Jain 			break;
193bd5d9c74SNayna Jain 		}
194bd5d9c74SNayna Jain 
195bd5d9c74SNayna Jain 		kobject_init(kobj, &secvar_ktype);
196bd5d9c74SNayna Jain 
197bd5d9c74SNayna Jain 		rc = kobject_add(kobj, &secvar_kset->kobj, "%s", name);
198bd5d9c74SNayna Jain 		if (rc) {
199bd5d9c74SNayna Jain 			pr_warn("kobject_add error %d for attribute: %s\n", rc,
200bd5d9c74SNayna Jain 				name);
201bd5d9c74SNayna Jain 			kobject_put(kobj);
202bd5d9c74SNayna Jain 			kobj = NULL;
203bd5d9c74SNayna Jain 		}
204bd5d9c74SNayna Jain 
205bd5d9c74SNayna Jain 		if (kobj)
206bd5d9c74SNayna Jain 			kobject_uevent(kobj, KOBJ_ADD);
207bd5d9c74SNayna Jain 
208bd5d9c74SNayna Jain 	} while (!rc);
209bd5d9c74SNayna Jain 
210bd5d9c74SNayna Jain 	kfree(name);
211bd5d9c74SNayna Jain 	return rc;
212bd5d9c74SNayna Jain }
213bd5d9c74SNayna Jain 
214bd5d9c74SNayna Jain static int secvar_sysfs_init(void)
215bd5d9c74SNayna Jain {
216bd5d9c74SNayna Jain 	int rc;
217bd5d9c74SNayna Jain 
218bd5d9c74SNayna Jain 	if (!secvar_ops) {
219bd5d9c74SNayna Jain 		pr_warn("secvar: failed to retrieve secvar operations.\n");
220bd5d9c74SNayna Jain 		return -ENODEV;
221bd5d9c74SNayna Jain 	}
222bd5d9c74SNayna Jain 
223bd5d9c74SNayna Jain 	secvar_kobj = kobject_create_and_add("secvar", firmware_kobj);
224bd5d9c74SNayna Jain 	if (!secvar_kobj) {
225bd5d9c74SNayna Jain 		pr_err("secvar: Failed to create firmware kobj\n");
226bd5d9c74SNayna Jain 		return -ENOMEM;
227bd5d9c74SNayna Jain 	}
228bd5d9c74SNayna Jain 
229bd5d9c74SNayna Jain 	rc = sysfs_create_file(secvar_kobj, &format_attr.attr);
230bd5d9c74SNayna Jain 	if (rc) {
231bd5d9c74SNayna Jain 		kobject_put(secvar_kobj);
232bd5d9c74SNayna Jain 		return -ENOMEM;
233bd5d9c74SNayna Jain 	}
234bd5d9c74SNayna Jain 
235bd5d9c74SNayna Jain 	secvar_kset = kset_create_and_add("vars", NULL, secvar_kobj);
236bd5d9c74SNayna Jain 	if (!secvar_kset) {
237bd5d9c74SNayna Jain 		pr_err("secvar: sysfs kobject registration failed.\n");
238bd5d9c74SNayna Jain 		kobject_put(secvar_kobj);
239bd5d9c74SNayna Jain 		return -ENOMEM;
240bd5d9c74SNayna Jain 	}
241bd5d9c74SNayna Jain 
242bd5d9c74SNayna Jain 	rc = update_kobj_size();
243bd5d9c74SNayna Jain 	if (rc) {
244bd5d9c74SNayna Jain 		pr_err("Cannot read the size of the attribute\n");
245bd5d9c74SNayna Jain 		return rc;
246bd5d9c74SNayna Jain 	}
247bd5d9c74SNayna Jain 
248bd5d9c74SNayna Jain 	secvar_sysfs_load();
249bd5d9c74SNayna Jain 
250bd5d9c74SNayna Jain 	return 0;
251bd5d9c74SNayna Jain }
252bd5d9c74SNayna Jain 
253bd5d9c74SNayna Jain late_initcall(secvar_sysfs_init);
254