1bd5d9c74SNayna Jain // SPDX-License-Identifier: GPL-2.0+ 2bd5d9c74SNayna Jain /* 3bd5d9c74SNayna Jain * Copyright (C) 2019 IBM Corporation <nayna@linux.ibm.com> 4bd5d9c74SNayna Jain * 5bd5d9c74SNayna Jain * This code exposes secure variables to user via sysfs 6bd5d9c74SNayna Jain */ 7bd5d9c74SNayna Jain 8bd5d9c74SNayna Jain #define pr_fmt(fmt) "secvar-sysfs: "fmt 9bd5d9c74SNayna Jain 10bd5d9c74SNayna Jain #include <linux/slab.h> 11bd5d9c74SNayna Jain #include <linux/compat.h> 12bd5d9c74SNayna Jain #include <linux/string.h> 13bd5d9c74SNayna Jain #include <linux/of.h> 14bd5d9c74SNayna Jain #include <asm/secvar.h> 15bd5d9c74SNayna Jain 16bd5d9c74SNayna Jain #define NAME_MAX_SIZE 1024 17bd5d9c74SNayna Jain 18bd5d9c74SNayna Jain static struct kobject *secvar_kobj; 19bd5d9c74SNayna Jain static struct kset *secvar_kset; 20bd5d9c74SNayna Jain 21bd5d9c74SNayna Jain static ssize_t format_show(struct kobject *kobj, struct kobj_attribute *attr, 22bd5d9c74SNayna Jain char *buf) 23bd5d9c74SNayna Jain { 24ec2f40bdSRussell Currey char tmp[32]; 25ec2f40bdSRussell Currey ssize_t len = secvar_ops->format(tmp, sizeof(tmp)); 26bd5d9c74SNayna Jain 27ec2f40bdSRussell Currey if (len > 0) 28ec2f40bdSRussell Currey return sysfs_emit(buf, "%s\n", tmp); 29ec2f40bdSRussell Currey else if (len < 0) 30ec2f40bdSRussell Currey pr_err("Error %zd reading format string\n", len); 31ec2f40bdSRussell Currey else 32ec2f40bdSRussell Currey pr_err("Got empty format string from backend\n"); 33bd5d9c74SNayna Jain 34ec2f40bdSRussell Currey return -EIO; 35bd5d9c74SNayna Jain } 36bd5d9c74SNayna Jain 37bd5d9c74SNayna Jain 38bd5d9c74SNayna Jain static ssize_t size_show(struct kobject *kobj, struct kobj_attribute *attr, 39bd5d9c74SNayna Jain char *buf) 40bd5d9c74SNayna Jain { 4153cea34bSMichael Ellerman u64 dsize; 42bd5d9c74SNayna Jain int rc; 43bd5d9c74SNayna Jain 44bd5d9c74SNayna Jain rc = secvar_ops->get(kobj->name, strlen(kobj->name) + 1, NULL, &dsize); 45bd5d9c74SNayna Jain if (rc) { 46*c96db155SAndrew Donnellan if (rc != -ENOENT) 47*c96db155SAndrew Donnellan pr_err("Error retrieving %s variable size %d\n", kobj->name, rc); 48bd5d9c74SNayna Jain return rc; 49bd5d9c74SNayna Jain } 50bd5d9c74SNayna Jain 5116943a2fSRussell Currey return sysfs_emit(buf, "%llu\n", dsize); 52bd5d9c74SNayna Jain } 53bd5d9c74SNayna Jain 54bd5d9c74SNayna Jain static ssize_t data_read(struct file *filep, struct kobject *kobj, 55bd5d9c74SNayna Jain struct bin_attribute *attr, char *buf, loff_t off, 56bd5d9c74SNayna Jain size_t count) 57bd5d9c74SNayna Jain { 58bd5d9c74SNayna Jain char *data; 5953cea34bSMichael Ellerman u64 dsize; 60bd5d9c74SNayna Jain int rc; 61bd5d9c74SNayna Jain 62bd5d9c74SNayna Jain rc = secvar_ops->get(kobj->name, strlen(kobj->name) + 1, NULL, &dsize); 63bd5d9c74SNayna Jain if (rc) { 64*c96db155SAndrew Donnellan if (rc != -ENOENT) 65bd5d9c74SNayna Jain pr_err("Error getting %s variable size %d\n", kobj->name, rc); 66bd5d9c74SNayna Jain return rc; 67bd5d9c74SNayna Jain } 68bd5d9c74SNayna Jain pr_debug("dsize is %llu\n", dsize); 69bd5d9c74SNayna Jain 70bd5d9c74SNayna Jain data = kzalloc(dsize, GFP_KERNEL); 71bd5d9c74SNayna Jain if (!data) 72bd5d9c74SNayna Jain return -ENOMEM; 73bd5d9c74SNayna Jain 74bd5d9c74SNayna Jain rc = secvar_ops->get(kobj->name, strlen(kobj->name) + 1, data, &dsize); 75bd5d9c74SNayna Jain if (rc) { 76bd5d9c74SNayna Jain pr_err("Error getting %s variable %d\n", kobj->name, rc); 77bd5d9c74SNayna Jain goto data_fail; 78bd5d9c74SNayna Jain } 79bd5d9c74SNayna Jain 80bd5d9c74SNayna Jain rc = memory_read_from_buffer(buf, count, &off, data, dsize); 81bd5d9c74SNayna Jain 82bd5d9c74SNayna Jain data_fail: 83bd5d9c74SNayna Jain kfree(data); 84bd5d9c74SNayna Jain return rc; 85bd5d9c74SNayna Jain } 86bd5d9c74SNayna Jain 87bd5d9c74SNayna Jain static ssize_t update_write(struct file *filep, struct kobject *kobj, 88bd5d9c74SNayna Jain struct bin_attribute *attr, char *buf, loff_t off, 89bd5d9c74SNayna Jain size_t count) 90bd5d9c74SNayna Jain { 91bd5d9c74SNayna Jain int rc; 92bd5d9c74SNayna Jain 93bd5d9c74SNayna Jain pr_debug("count is %ld\n", count); 94bd5d9c74SNayna Jain rc = secvar_ops->set(kobj->name, strlen(kobj->name) + 1, buf, count); 95bd5d9c74SNayna Jain if (rc) { 96bd5d9c74SNayna Jain pr_err("Error setting the %s variable %d\n", kobj->name, rc); 97bd5d9c74SNayna Jain return rc; 98bd5d9c74SNayna Jain } 99bd5d9c74SNayna Jain 100bd5d9c74SNayna Jain return count; 101bd5d9c74SNayna Jain } 102bd5d9c74SNayna Jain 103bd5d9c74SNayna Jain static struct kobj_attribute format_attr = __ATTR_RO(format); 104bd5d9c74SNayna Jain 105bd5d9c74SNayna Jain static struct kobj_attribute size_attr = __ATTR_RO(size); 106bd5d9c74SNayna Jain 107bd5d9c74SNayna Jain static struct bin_attribute data_attr = __BIN_ATTR_RO(data, 0); 108bd5d9c74SNayna Jain 109bd5d9c74SNayna Jain static struct bin_attribute update_attr = __BIN_ATTR_WO(update, 0); 110bd5d9c74SNayna Jain 111bd5d9c74SNayna Jain static struct bin_attribute *secvar_bin_attrs[] = { 112bd5d9c74SNayna Jain &data_attr, 113bd5d9c74SNayna Jain &update_attr, 114bd5d9c74SNayna Jain NULL, 115bd5d9c74SNayna Jain }; 116bd5d9c74SNayna Jain 117bd5d9c74SNayna Jain static struct attribute *secvar_attrs[] = { 118bd5d9c74SNayna Jain &size_attr.attr, 119bd5d9c74SNayna Jain NULL, 120bd5d9c74SNayna Jain }; 121bd5d9c74SNayna Jain 122bd5d9c74SNayna Jain static const struct attribute_group secvar_attr_group = { 123bd5d9c74SNayna Jain .attrs = secvar_attrs, 124bd5d9c74SNayna Jain .bin_attrs = secvar_bin_attrs, 125bd5d9c74SNayna Jain }; 126bd5d9c74SNayna Jain __ATTRIBUTE_GROUPS(secvar_attr); 127bd5d9c74SNayna Jain 128bd5d9c74SNayna Jain static struct kobj_type secvar_ktype = { 129bd5d9c74SNayna Jain .sysfs_ops = &kobj_sysfs_ops, 130bd5d9c74SNayna Jain .default_groups = secvar_attr_groups, 131bd5d9c74SNayna Jain }; 132bd5d9c74SNayna Jain 133bd5d9c74SNayna Jain static int update_kobj_size(void) 134bd5d9c74SNayna Jain { 135bd5d9c74SNayna Jain 136bd5d9c74SNayna Jain u64 varsize; 137e0240794SRussell Currey int rc = secvar_ops->max_size(&varsize); 138bd5d9c74SNayna Jain 139bd5d9c74SNayna Jain if (rc) 140e0240794SRussell Currey return rc; 141bd5d9c74SNayna Jain 142bd5d9c74SNayna Jain data_attr.size = varsize; 143bd5d9c74SNayna Jain update_attr.size = varsize; 144bd5d9c74SNayna Jain 145e0240794SRussell Currey return 0; 146bd5d9c74SNayna Jain } 147bd5d9c74SNayna Jain 14886b6c0aeSRussell Currey static int secvar_sysfs_config(struct kobject *kobj) 14986b6c0aeSRussell Currey { 15086b6c0aeSRussell Currey struct attribute_group config_group = { 15186b6c0aeSRussell Currey .name = "config", 15286b6c0aeSRussell Currey .attrs = (struct attribute **)secvar_ops->config_attrs, 15386b6c0aeSRussell Currey }; 15486b6c0aeSRussell Currey 15586b6c0aeSRussell Currey if (secvar_ops->config_attrs) 15686b6c0aeSRussell Currey return sysfs_create_group(kobj, &config_group); 15786b6c0aeSRussell Currey 15886b6c0aeSRussell Currey return 0; 15986b6c0aeSRussell Currey } 16086b6c0aeSRussell Currey 16150a466bfSAndrew Donnellan static int add_var(const char *name) 162bd5d9c74SNayna Jain { 163bd5d9c74SNayna Jain struct kobject *kobj; 16450a466bfSAndrew Donnellan int rc; 16550a466bfSAndrew Donnellan 16650a466bfSAndrew Donnellan kobj = kzalloc(sizeof(*kobj), GFP_KERNEL); 16750a466bfSAndrew Donnellan if (!kobj) 16850a466bfSAndrew Donnellan return -ENOMEM; 16950a466bfSAndrew Donnellan 17050a466bfSAndrew Donnellan kobject_init(kobj, &secvar_ktype); 17150a466bfSAndrew Donnellan 17250a466bfSAndrew Donnellan rc = kobject_add(kobj, &secvar_kset->kobj, "%s", name); 17350a466bfSAndrew Donnellan if (rc) { 17450a466bfSAndrew Donnellan pr_warn("kobject_add error %d for attribute: %s\n", rc, 17550a466bfSAndrew Donnellan name); 17650a466bfSAndrew Donnellan kobject_put(kobj); 17750a466bfSAndrew Donnellan return rc; 17850a466bfSAndrew Donnellan } 17950a466bfSAndrew Donnellan 18050a466bfSAndrew Donnellan kobject_uevent(kobj, KOBJ_ADD); 18150a466bfSAndrew Donnellan return 0; 18250a466bfSAndrew Donnellan } 18350a466bfSAndrew Donnellan 18450a466bfSAndrew Donnellan static int secvar_sysfs_load(void) 18550a466bfSAndrew Donnellan { 18653cea34bSMichael Ellerman u64 namesize = 0; 18753cea34bSMichael Ellerman char *name; 188bd5d9c74SNayna Jain int rc; 189bd5d9c74SNayna Jain 190bd5d9c74SNayna Jain name = kzalloc(NAME_MAX_SIZE, GFP_KERNEL); 191bd5d9c74SNayna Jain if (!name) 192bd5d9c74SNayna Jain return -ENOMEM; 193bd5d9c74SNayna Jain 194bd5d9c74SNayna Jain do { 195bd5d9c74SNayna Jain rc = secvar_ops->get_next(name, &namesize, NAME_MAX_SIZE); 196bd5d9c74SNayna Jain if (rc) { 197bd5d9c74SNayna Jain if (rc != -ENOENT) 198c9fd2952SRussell Currey pr_err("error getting secvar from firmware %d\n", rc); 199c9fd2952SRussell Currey else 200c9fd2952SRussell Currey rc = 0; 201c9fd2952SRussell Currey 202bd5d9c74SNayna Jain break; 203bd5d9c74SNayna Jain } 204bd5d9c74SNayna Jain 20550a466bfSAndrew Donnellan rc = add_var(name); 206bd5d9c74SNayna Jain } while (!rc); 207bd5d9c74SNayna Jain 208bd5d9c74SNayna Jain kfree(name); 209bd5d9c74SNayna Jain return rc; 210bd5d9c74SNayna Jain } 211bd5d9c74SNayna Jain 21250a466bfSAndrew Donnellan static int secvar_sysfs_load_static(void) 21350a466bfSAndrew Donnellan { 21450a466bfSAndrew Donnellan const char * const *name_ptr = secvar_ops->var_names; 21550a466bfSAndrew Donnellan int rc; 21650a466bfSAndrew Donnellan 21750a466bfSAndrew Donnellan while (*name_ptr) { 21850a466bfSAndrew Donnellan rc = add_var(*name_ptr); 21950a466bfSAndrew Donnellan if (rc) 22050a466bfSAndrew Donnellan return rc; 22150a466bfSAndrew Donnellan name_ptr++; 22250a466bfSAndrew Donnellan } 22350a466bfSAndrew Donnellan 22450a466bfSAndrew Donnellan return 0; 22550a466bfSAndrew Donnellan } 22650a466bfSAndrew Donnellan 227bd5d9c74SNayna Jain static int secvar_sysfs_init(void) 228bd5d9c74SNayna Jain { 2296d64c497SAndrew Donnellan u64 max_size; 230bd5d9c74SNayna Jain int rc; 231bd5d9c74SNayna Jain 232bd5d9c74SNayna Jain if (!secvar_ops) { 233caefd3b7SAndrew Donnellan pr_warn("Failed to retrieve secvar operations\n"); 234bd5d9c74SNayna Jain return -ENODEV; 235bd5d9c74SNayna Jain } 236bd5d9c74SNayna Jain 237bd5d9c74SNayna Jain secvar_kobj = kobject_create_and_add("secvar", firmware_kobj); 238bd5d9c74SNayna Jain if (!secvar_kobj) { 239caefd3b7SAndrew Donnellan pr_err("Failed to create firmware kobj\n"); 240bd5d9c74SNayna Jain return -ENOMEM; 241bd5d9c74SNayna Jain } 242bd5d9c74SNayna Jain 243bd5d9c74SNayna Jain rc = sysfs_create_file(secvar_kobj, &format_attr.attr); 244bd5d9c74SNayna Jain if (rc) { 24586b6c0aeSRussell Currey pr_err("Failed to create format object\n"); 24686b6c0aeSRussell Currey rc = -ENOMEM; 24786b6c0aeSRussell Currey goto err; 248bd5d9c74SNayna Jain } 249bd5d9c74SNayna Jain 250bd5d9c74SNayna Jain secvar_kset = kset_create_and_add("vars", NULL, secvar_kobj); 251bd5d9c74SNayna Jain if (!secvar_kset) { 252caefd3b7SAndrew Donnellan pr_err("sysfs kobject registration failed\n"); 25386b6c0aeSRussell Currey rc = -ENOMEM; 25486b6c0aeSRussell Currey goto err; 255bd5d9c74SNayna Jain } 256bd5d9c74SNayna Jain 257bd5d9c74SNayna Jain rc = update_kobj_size(); 258bd5d9c74SNayna Jain if (rc) { 259bd5d9c74SNayna Jain pr_err("Cannot read the size of the attribute\n"); 26086b6c0aeSRussell Currey goto err; 26186b6c0aeSRussell Currey } 26286b6c0aeSRussell Currey 26386b6c0aeSRussell Currey rc = secvar_sysfs_config(secvar_kobj); 26486b6c0aeSRussell Currey if (rc) { 26586b6c0aeSRussell Currey pr_err("Failed to create config directory\n"); 26686b6c0aeSRussell Currey goto err; 267bd5d9c74SNayna Jain } 268bd5d9c74SNayna Jain 26950a466bfSAndrew Donnellan if (secvar_ops->get_next) 27050a466bfSAndrew Donnellan rc = secvar_sysfs_load(); 27150a466bfSAndrew Donnellan else 27250a466bfSAndrew Donnellan rc = secvar_sysfs_load_static(); 27350a466bfSAndrew Donnellan 27450a466bfSAndrew Donnellan if (rc) { 27550a466bfSAndrew Donnellan pr_err("Failed to create variable attributes\n"); 27650a466bfSAndrew Donnellan goto err; 27750a466bfSAndrew Donnellan } 278bd5d9c74SNayna Jain 2796d64c497SAndrew Donnellan // Due to sysfs limitations, we will only ever get a write buffer of 2806d64c497SAndrew Donnellan // up to 1 page in size. Print a warning if this is potentially going 2816d64c497SAndrew Donnellan // to cause problems, so that the user is aware. 2826d64c497SAndrew Donnellan secvar_ops->max_size(&max_size); 2836d64c497SAndrew Donnellan if (max_size > PAGE_SIZE) 2846d64c497SAndrew Donnellan pr_warn_ratelimited("PAGE_SIZE (%lu) is smaller than maximum object size (%llu), writes are limited to PAGE_SIZE\n", 2856d64c497SAndrew Donnellan PAGE_SIZE, max_size); 2866d64c497SAndrew Donnellan 287bd5d9c74SNayna Jain return 0; 28886b6c0aeSRussell Currey err: 28986b6c0aeSRussell Currey kobject_put(secvar_kobj); 29086b6c0aeSRussell Currey return rc; 291bd5d9c74SNayna Jain } 292bd5d9c74SNayna Jain 293bd5d9c74SNayna Jain late_initcall(secvar_sysfs_init); 294