19deb0eb7SJason Gunthorpe /* 29deb0eb7SJason Gunthorpe * Copyright (C) 2004 IBM Corporation 3afb5abc2SJarkko Sakkinen * Copyright (C) 2014 Intel Corporation 49deb0eb7SJason Gunthorpe * 59deb0eb7SJason Gunthorpe * Authors: 69deb0eb7SJason Gunthorpe * Leendert van Doorn <leendert@watson.ibm.com> 79deb0eb7SJason Gunthorpe * Dave Safford <safford@watson.ibm.com> 89deb0eb7SJason Gunthorpe * Reiner Sailer <sailer@watson.ibm.com> 99deb0eb7SJason Gunthorpe * Kylene Hall <kjhall@us.ibm.com> 109deb0eb7SJason Gunthorpe * 119deb0eb7SJason Gunthorpe * Maintained by: <tpmdd-devel@lists.sourceforge.net> 129deb0eb7SJason Gunthorpe * 139deb0eb7SJason Gunthorpe * Device driver for TCG/TCPA TPM (trusted platform module). 149deb0eb7SJason Gunthorpe * Specifications at www.trustedcomputinggroup.org 159deb0eb7SJason Gunthorpe * 169deb0eb7SJason Gunthorpe * This program is free software; you can redistribute it and/or 179deb0eb7SJason Gunthorpe * modify it under the terms of the GNU General Public License as 189deb0eb7SJason Gunthorpe * published by the Free Software Foundation, version 2 of the 199deb0eb7SJason Gunthorpe * License. 209deb0eb7SJason Gunthorpe * 219deb0eb7SJason Gunthorpe * Note, the TPM chip is not interrupt driven (only polling) 229deb0eb7SJason Gunthorpe * and can have very long timeouts (minutes!). Hence the unusual 239deb0eb7SJason Gunthorpe * calls to msleep. 249deb0eb7SJason Gunthorpe * 259deb0eb7SJason Gunthorpe */ 269deb0eb7SJason Gunthorpe 279deb0eb7SJason Gunthorpe #include <linux/poll.h> 289deb0eb7SJason Gunthorpe #include <linux/slab.h> 299deb0eb7SJason Gunthorpe #include <linux/mutex.h> 309deb0eb7SJason Gunthorpe #include <linux/spinlock.h> 319deb0eb7SJason Gunthorpe #include <linux/freezer.h> 32fd3ec366SThiebaud Weksteen #include <linux/tpm_eventlog.h> 339deb0eb7SJason Gunthorpe 349deb0eb7SJason Gunthorpe #include "tpm.h" 359deb0eb7SJason Gunthorpe 369deb0eb7SJason Gunthorpe #define TSC_MAX_ORDINAL 12 379deb0eb7SJason Gunthorpe #define TPM_PROTECTED_COMMAND 0x00 389deb0eb7SJason Gunthorpe #define TPM_CONNECTION_COMMAND 0x40 399deb0eb7SJason Gunthorpe 409deb0eb7SJason Gunthorpe /* 419deb0eb7SJason Gunthorpe * Bug workaround - some TPM's don't flush the most 429deb0eb7SJason Gunthorpe * recently changed pcr on suspend, so force the flush 439deb0eb7SJason Gunthorpe * with an extend to the selected _unused_ non-volatile pcr. 449deb0eb7SJason Gunthorpe */ 459deb0eb7SJason Gunthorpe static int tpm_suspend_pcr; 469deb0eb7SJason Gunthorpe module_param_named(suspend_pcr, tpm_suspend_pcr, uint, 0644); 479deb0eb7SJason Gunthorpe MODULE_PARM_DESC(suspend_pcr, 4839f5712bSDmitry Torokhov "PCR to use for dummy writes to facilitate flush on suspend."); 499deb0eb7SJason Gunthorpe 50d856c00fSTomas Winkler /** 51d856c00fSTomas Winkler * tpm_calc_ordinal_duration() - calculate the maximum command duration 52d856c00fSTomas Winkler * @chip: TPM chip to use. 53d856c00fSTomas Winkler * @ordinal: TPM command ordinal. 54d856c00fSTomas Winkler * 55d856c00fSTomas Winkler * The function returns the maximum amount of time the chip could take 56d856c00fSTomas Winkler * to return the result for a particular ordinal in jiffies. 57d856c00fSTomas Winkler * 58d856c00fSTomas Winkler * Return: A maximal duration time for an ordinal in jiffies. 59d856c00fSTomas Winkler */ 60d856c00fSTomas Winkler unsigned long tpm_calc_ordinal_duration(struct tpm_chip *chip, u32 ordinal) 61d856c00fSTomas Winkler { 62d856c00fSTomas Winkler if (chip->flags & TPM_CHIP_FLAG_TPM2) 63d856c00fSTomas Winkler return tpm2_calc_ordinal_duration(chip, ordinal); 64d856c00fSTomas Winkler else 65d856c00fSTomas Winkler return tpm1_calc_ordinal_duration(chip, ordinal); 66d856c00fSTomas Winkler } 67d856c00fSTomas Winkler EXPORT_SYMBOL_GPL(tpm_calc_ordinal_duration); 68d856c00fSTomas Winkler 69095531f8SJavier Martinez Canillas static int tpm_validate_command(struct tpm_chip *chip, 70745b361eSJarkko Sakkinen struct tpm_space *space, 71745b361eSJarkko Sakkinen const u8 *cmd, 7258472f5cSJarkko Sakkinen size_t len) 7358472f5cSJarkko Sakkinen { 7458472f5cSJarkko Sakkinen const struct tpm_input_header *header = (const void *)cmd; 7558472f5cSJarkko Sakkinen int i; 7658472f5cSJarkko Sakkinen u32 cc; 7758472f5cSJarkko Sakkinen u32 attrs; 7858472f5cSJarkko Sakkinen unsigned int nr_handles; 7958472f5cSJarkko Sakkinen 8058472f5cSJarkko Sakkinen if (len < TPM_HEADER_SIZE) 81095531f8SJavier Martinez Canillas return -EINVAL; 8258472f5cSJarkko Sakkinen 83745b361eSJarkko Sakkinen if (!space) 84095531f8SJavier Martinez Canillas return 0; 85745b361eSJarkko Sakkinen 8658472f5cSJarkko Sakkinen if (chip->flags & TPM_CHIP_FLAG_TPM2 && chip->nr_commands) { 8758472f5cSJarkko Sakkinen cc = be32_to_cpu(header->ordinal); 8858472f5cSJarkko Sakkinen 8958472f5cSJarkko Sakkinen i = tpm2_find_cc(chip, cc); 9058472f5cSJarkko Sakkinen if (i < 0) { 9158472f5cSJarkko Sakkinen dev_dbg(&chip->dev, "0x%04X is an invalid command\n", 9258472f5cSJarkko Sakkinen cc); 93095531f8SJavier Martinez Canillas return -EOPNOTSUPP; 9458472f5cSJarkko Sakkinen } 9558472f5cSJarkko Sakkinen 9658472f5cSJarkko Sakkinen attrs = chip->cc_attrs_tbl[i]; 9758472f5cSJarkko Sakkinen nr_handles = 9858472f5cSJarkko Sakkinen 4 * ((attrs >> TPM2_CC_ATTR_CHANDLES) & GENMASK(2, 0)); 9958472f5cSJarkko Sakkinen if (len < TPM_HEADER_SIZE + 4 * nr_handles) 10058472f5cSJarkko Sakkinen goto err_len; 10158472f5cSJarkko Sakkinen } 10258472f5cSJarkko Sakkinen 103095531f8SJavier Martinez Canillas return 0; 10458472f5cSJarkko Sakkinen err_len: 10558472f5cSJarkko Sakkinen dev_dbg(&chip->dev, 10658472f5cSJarkko Sakkinen "%s: insufficient command length %zu", __func__, len); 107095531f8SJavier Martinez Canillas return -EINVAL; 10858472f5cSJarkko Sakkinen } 10958472f5cSJarkko Sakkinen 110627448e8STomas Winkler static int tpm_request_locality(struct tpm_chip *chip, unsigned int flags) 111888d867dSTomas Winkler { 112888d867dSTomas Winkler int rc; 113888d867dSTomas Winkler 11458bac8ccSJarkko Sakkinen if (flags & TPM_TRANSMIT_NESTED) 115627448e8STomas Winkler return 0; 116627448e8STomas Winkler 117888d867dSTomas Winkler if (!chip->ops->request_locality) 118888d867dSTomas Winkler return 0; 119888d867dSTomas Winkler 120888d867dSTomas Winkler rc = chip->ops->request_locality(chip, 0); 121888d867dSTomas Winkler if (rc < 0) 122888d867dSTomas Winkler return rc; 123888d867dSTomas Winkler 124888d867dSTomas Winkler chip->locality = rc; 125888d867dSTomas Winkler 126888d867dSTomas Winkler return 0; 127888d867dSTomas Winkler } 128888d867dSTomas Winkler 129627448e8STomas Winkler static void tpm_relinquish_locality(struct tpm_chip *chip, unsigned int flags) 130888d867dSTomas Winkler { 131888d867dSTomas Winkler int rc; 132888d867dSTomas Winkler 13358bac8ccSJarkko Sakkinen if (flags & TPM_TRANSMIT_NESTED) 134627448e8STomas Winkler return; 135627448e8STomas Winkler 136888d867dSTomas Winkler if (!chip->ops->relinquish_locality) 137888d867dSTomas Winkler return; 138888d867dSTomas Winkler 139888d867dSTomas Winkler rc = chip->ops->relinquish_locality(chip, chip->locality); 140888d867dSTomas Winkler if (rc) 141888d867dSTomas Winkler dev_err(&chip->dev, "%s: : error %d\n", __func__, rc); 142888d867dSTomas Winkler 143888d867dSTomas Winkler chip->locality = -1; 144888d867dSTomas Winkler } 145888d867dSTomas Winkler 146627448e8STomas Winkler static int tpm_cmd_ready(struct tpm_chip *chip, unsigned int flags) 147627448e8STomas Winkler { 14858bac8ccSJarkko Sakkinen if (flags & TPM_TRANSMIT_NESTED) 149627448e8STomas Winkler return 0; 150627448e8STomas Winkler 151627448e8STomas Winkler if (!chip->ops->cmd_ready) 152627448e8STomas Winkler return 0; 153627448e8STomas Winkler 154627448e8STomas Winkler return chip->ops->cmd_ready(chip); 155627448e8STomas Winkler } 156627448e8STomas Winkler 157627448e8STomas Winkler static int tpm_go_idle(struct tpm_chip *chip, unsigned int flags) 158627448e8STomas Winkler { 15958bac8ccSJarkko Sakkinen if (flags & TPM_TRANSMIT_NESTED) 160627448e8STomas Winkler return 0; 161627448e8STomas Winkler 162627448e8STomas Winkler if (!chip->ops->go_idle) 163627448e8STomas Winkler return 0; 164627448e8STomas Winkler 165627448e8STomas Winkler return chip->ops->go_idle(chip); 166627448e8STomas Winkler } 167627448e8STomas Winkler 168e2fb992dSJames Bottomley static ssize_t tpm_try_transmit(struct tpm_chip *chip, 169e2fb992dSJames Bottomley struct tpm_space *space, 170e2fb992dSJames Bottomley u8 *buf, size_t bufsiz, 171e2fb992dSJames Bottomley unsigned int flags) 1729deb0eb7SJason Gunthorpe { 173745b361eSJarkko Sakkinen struct tpm_output_header *header = (void *)buf; 174745b361eSJarkko Sakkinen int rc; 175745b361eSJarkko Sakkinen ssize_t len = 0; 1769deb0eb7SJason Gunthorpe u32 count, ordinal; 1779deb0eb7SJason Gunthorpe unsigned long stop; 178877c57d0SJarkko Sakkinen bool need_locality; 1799deb0eb7SJason Gunthorpe 180095531f8SJavier Martinez Canillas rc = tpm_validate_command(chip, space, buf, bufsiz); 181095531f8SJavier Martinez Canillas if (rc == -EINVAL) 182095531f8SJavier Martinez Canillas return rc; 183095531f8SJavier Martinez Canillas /* 184095531f8SJavier Martinez Canillas * If the command is not implemented by the TPM, synthesize a 185095531f8SJavier Martinez Canillas * response with a TPM2_RC_COMMAND_CODE return for user-space. 186095531f8SJavier Martinez Canillas */ 187095531f8SJavier Martinez Canillas if (rc == -EOPNOTSUPP) { 188095531f8SJavier Martinez Canillas header->length = cpu_to_be32(sizeof(*header)); 189095531f8SJavier Martinez Canillas header->tag = cpu_to_be16(TPM2_ST_NO_SESSIONS); 190095531f8SJavier Martinez Canillas header->return_code = cpu_to_be32(TPM2_RC_COMMAND_CODE | 191095531f8SJavier Martinez Canillas TSS2_RESMGR_TPM_RC_LAYER); 19236a11029SRicardo Schwarzmeier return sizeof(*header); 193095531f8SJavier Martinez Canillas } 194ebfd7532SJarkko Sakkinen 1959deb0eb7SJason Gunthorpe if (bufsiz > TPM_BUFSIZE) 1969deb0eb7SJason Gunthorpe bufsiz = TPM_BUFSIZE; 1979deb0eb7SJason Gunthorpe 1989deb0eb7SJason Gunthorpe count = be32_to_cpu(*((__be32 *) (buf + 2))); 1999deb0eb7SJason Gunthorpe ordinal = be32_to_cpu(*((__be32 *) (buf + 6))); 2009deb0eb7SJason Gunthorpe if (count == 0) 2019deb0eb7SJason Gunthorpe return -ENODATA; 2029deb0eb7SJason Gunthorpe if (count > bufsiz) { 2038cfffc9dSJason Gunthorpe dev_err(&chip->dev, 2049deb0eb7SJason Gunthorpe "invalid count value %x %zx\n", count, bufsiz); 2059deb0eb7SJason Gunthorpe return -E2BIG; 2069deb0eb7SJason Gunthorpe } 2079deb0eb7SJason Gunthorpe 20858bac8ccSJarkko Sakkinen if (!(flags & TPM_TRANSMIT_UNLOCKED) && !(flags & TPM_TRANSMIT_NESTED)) 2099deb0eb7SJason Gunthorpe mutex_lock(&chip->tpm_mutex); 2109deb0eb7SJason Gunthorpe 211b3e958ceSAzhar Shaikh if (chip->ops->clk_enable != NULL) 212b3e958ceSAzhar Shaikh chip->ops->clk_enable(chip, true); 213b3e958ceSAzhar Shaikh 214877c57d0SJarkko Sakkinen /* Store the decision as chip->locality will be changed. */ 215877c57d0SJarkko Sakkinen need_locality = chip->locality == -1; 216877c57d0SJarkko Sakkinen 217627448e8STomas Winkler if (need_locality) { 218627448e8STomas Winkler rc = tpm_request_locality(chip, flags); 219877c57d0SJarkko Sakkinen if (rc < 0) 220877c57d0SJarkko Sakkinen goto out_no_locality; 221877c57d0SJarkko Sakkinen } 222877c57d0SJarkko Sakkinen 223627448e8STomas Winkler rc = tpm_cmd_ready(chip, flags); 224627448e8STomas Winkler if (rc) 225627448e8STomas Winkler goto out; 226888d867dSTomas Winkler 227745b361eSJarkko Sakkinen rc = tpm2_prepare_space(chip, space, ordinal, buf); 228745b361eSJarkko Sakkinen if (rc) 229745b361eSJarkko Sakkinen goto out; 230745b361eSJarkko Sakkinen 23162c09e12SWinkler, Tomas rc = chip->ops->send(chip, buf, count); 2329deb0eb7SJason Gunthorpe if (rc < 0) { 233402149c6SStefan Berger if (rc != -EPIPE) 2348cfffc9dSJason Gunthorpe dev_err(&chip->dev, 235402149c6SStefan Berger "%s: tpm_send: error %d\n", __func__, rc); 2369deb0eb7SJason Gunthorpe goto out; 2379deb0eb7SJason Gunthorpe } 2389deb0eb7SJason Gunthorpe 239570a3609SChristophe Ricard if (chip->flags & TPM_CHIP_FLAG_IRQ) 2409deb0eb7SJason Gunthorpe goto out_recv; 2419deb0eb7SJason Gunthorpe 242d856c00fSTomas Winkler stop = jiffies + tpm_calc_ordinal_duration(chip, ordinal); 2439deb0eb7SJason Gunthorpe do { 2445f82e9f0SJason Gunthorpe u8 status = chip->ops->status(chip); 2455f82e9f0SJason Gunthorpe if ((status & chip->ops->req_complete_mask) == 2465f82e9f0SJason Gunthorpe chip->ops->req_complete_val) 2479deb0eb7SJason Gunthorpe goto out_recv; 2489deb0eb7SJason Gunthorpe 2495f82e9f0SJason Gunthorpe if (chip->ops->req_canceled(chip, status)) { 2508cfffc9dSJason Gunthorpe dev_err(&chip->dev, "Operation Canceled\n"); 2519deb0eb7SJason Gunthorpe rc = -ECANCELED; 2529deb0eb7SJason Gunthorpe goto out; 2539deb0eb7SJason Gunthorpe } 2549deb0eb7SJason Gunthorpe 25559f5a6b0SNayna Jain tpm_msleep(TPM_TIMEOUT_POLL); 2569deb0eb7SJason Gunthorpe rmb(); 2579deb0eb7SJason Gunthorpe } while (time_before(jiffies, stop)); 2589deb0eb7SJason Gunthorpe 2595f82e9f0SJason Gunthorpe chip->ops->cancel(chip); 2608cfffc9dSJason Gunthorpe dev_err(&chip->dev, "Operation Timed out\n"); 2619deb0eb7SJason Gunthorpe rc = -ETIME; 2629deb0eb7SJason Gunthorpe goto out; 2639deb0eb7SJason Gunthorpe 2649deb0eb7SJason Gunthorpe out_recv: 26562c09e12SWinkler, Tomas len = chip->ops->recv(chip, buf, bufsiz); 266745b361eSJarkko Sakkinen if (len < 0) { 267745b361eSJarkko Sakkinen rc = len; 2688cfffc9dSJason Gunthorpe dev_err(&chip->dev, 269745b361eSJarkko Sakkinen "tpm_transmit: tpm_recv: error %d\n", rc); 270a147918eSJarkko Sakkinen goto out; 271745b361eSJarkko Sakkinen } else if (len < TPM_HEADER_SIZE) { 272a147918eSJarkko Sakkinen rc = -EFAULT; 273a147918eSJarkko Sakkinen goto out; 274a147918eSJarkko Sakkinen } 275a147918eSJarkko Sakkinen 276745b361eSJarkko Sakkinen if (len != be32_to_cpu(header->length)) { 277745b361eSJarkko Sakkinen rc = -EFAULT; 278a147918eSJarkko Sakkinen goto out; 279745b361eSJarkko Sakkinen } 280745b361eSJarkko Sakkinen 281745b361eSJarkko Sakkinen rc = tpm2_commit_space(chip, space, ordinal, buf, &len); 282627448e8STomas Winkler if (rc) 283627448e8STomas Winkler dev_err(&chip->dev, "tpm2_commit_space: error %d\n", rc); 284a147918eSJarkko Sakkinen 2859deb0eb7SJason Gunthorpe out: 286627448e8STomas Winkler rc = tpm_go_idle(chip, flags); 287627448e8STomas Winkler if (rc) 288627448e8STomas Winkler goto out; 289888d867dSTomas Winkler 290888d867dSTomas Winkler if (need_locality) 291627448e8STomas Winkler tpm_relinquish_locality(chip, flags); 292888d867dSTomas Winkler 293877c57d0SJarkko Sakkinen out_no_locality: 294b3e958ceSAzhar Shaikh if (chip->ops->clk_enable != NULL) 295b3e958ceSAzhar Shaikh chip->ops->clk_enable(chip, false); 296b3e958ceSAzhar Shaikh 29758bac8ccSJarkko Sakkinen if (!(flags & TPM_TRANSMIT_UNLOCKED) && !(flags & TPM_TRANSMIT_NESTED)) 2989deb0eb7SJason Gunthorpe mutex_unlock(&chip->tpm_mutex); 299745b361eSJarkko Sakkinen return rc ? rc : len; 3009deb0eb7SJason Gunthorpe } 3019deb0eb7SJason Gunthorpe 302f865c196SWinkler, Tomas /** 303e2fb992dSJames Bottomley * tpm_transmit - Internal kernel interface to transmit TPM commands. 304e2fb992dSJames Bottomley * 305e2fb992dSJames Bottomley * @chip: TPM chip to use 306e2fb992dSJames Bottomley * @space: tpm space 307e2fb992dSJames Bottomley * @buf: TPM command buffer 308e2fb992dSJames Bottomley * @bufsiz: length of the TPM command buffer 309e2fb992dSJames Bottomley * @flags: tpm transmit flags - bitmap 310e2fb992dSJames Bottomley * 311e2fb992dSJames Bottomley * A wrapper around tpm_try_transmit that handles TPM2_RC_RETRY 312e2fb992dSJames Bottomley * returns from the TPM and retransmits the command after a delay up 313e2fb992dSJames Bottomley * to a maximum wait of TPM2_DURATION_LONG. 314e2fb992dSJames Bottomley * 315e2fb992dSJames Bottomley * Note: TPM1 never returns TPM2_RC_RETRY so the retry logic is TPM2 316e2fb992dSJames Bottomley * only 317e2fb992dSJames Bottomley * 318e2fb992dSJames Bottomley * Return: 319e2fb992dSJames Bottomley * the length of the return when the operation is successful. 320e2fb992dSJames Bottomley * A negative number for system errors (errno). 321e2fb992dSJames Bottomley */ 322e2fb992dSJames Bottomley ssize_t tpm_transmit(struct tpm_chip *chip, struct tpm_space *space, 323e2fb992dSJames Bottomley u8 *buf, size_t bufsiz, unsigned int flags) 324e2fb992dSJames Bottomley { 325e2fb992dSJames Bottomley struct tpm_output_header *header = (struct tpm_output_header *)buf; 326e2fb992dSJames Bottomley /* space for header and handles */ 327e2fb992dSJames Bottomley u8 save[TPM_HEADER_SIZE + 3*sizeof(u32)]; 328e2fb992dSJames Bottomley unsigned int delay_msec = TPM2_DURATION_SHORT; 329e2fb992dSJames Bottomley u32 rc = 0; 330e2fb992dSJames Bottomley ssize_t ret; 331e2fb992dSJames Bottomley const size_t save_size = min(space ? sizeof(save) : TPM_HEADER_SIZE, 332e2fb992dSJames Bottomley bufsiz); 3332be8ffedSJames Bottomley /* the command code is where the return code will be */ 3342be8ffedSJames Bottomley u32 cc = be32_to_cpu(header->return_code); 335e2fb992dSJames Bottomley 336e2fb992dSJames Bottomley /* 337e2fb992dSJames Bottomley * Subtlety here: if we have a space, the handles will be 338e2fb992dSJames Bottomley * transformed, so when we restore the header we also have to 339e2fb992dSJames Bottomley * restore the handles. 340e2fb992dSJames Bottomley */ 341e2fb992dSJames Bottomley memcpy(save, buf, save_size); 342e2fb992dSJames Bottomley 343e2fb992dSJames Bottomley for (;;) { 344e2fb992dSJames Bottomley ret = tpm_try_transmit(chip, space, buf, bufsiz, flags); 345e2fb992dSJames Bottomley if (ret < 0) 346e2fb992dSJames Bottomley break; 347e2fb992dSJames Bottomley rc = be32_to_cpu(header->return_code); 3482be8ffedSJames Bottomley if (rc != TPM2_RC_RETRY && rc != TPM2_RC_TESTING) 3492be8ffedSJames Bottomley break; 3502be8ffedSJames Bottomley /* 3512be8ffedSJames Bottomley * return immediately if self test returns test 3522be8ffedSJames Bottomley * still running to shorten boot time. 3532be8ffedSJames Bottomley */ 3542be8ffedSJames Bottomley if (rc == TPM2_RC_TESTING && cc == TPM2_CC_SELF_TEST) 355e2fb992dSJames Bottomley break; 35692980756SNayna Jain 357e2fb992dSJames Bottomley if (delay_msec > TPM2_DURATION_LONG) { 3582be8ffedSJames Bottomley if (rc == TPM2_RC_RETRY) 3592be8ffedSJames Bottomley dev_err(&chip->dev, "in retry loop\n"); 3602be8ffedSJames Bottomley else 3612be8ffedSJames Bottomley dev_err(&chip->dev, 3622be8ffedSJames Bottomley "self test is still running\n"); 363e2fb992dSJames Bottomley break; 364e2fb992dSJames Bottomley } 365e2fb992dSJames Bottomley tpm_msleep(delay_msec); 36692980756SNayna Jain delay_msec *= 2; 367e2fb992dSJames Bottomley memcpy(buf, save, save_size); 368e2fb992dSJames Bottomley } 369e2fb992dSJames Bottomley return ret; 370e2fb992dSJames Bottomley } 371e2fb992dSJames Bottomley /** 37265520d46SWinkler, Tomas * tpm_transmit_cmd - send a tpm command to the device 373f865c196SWinkler, Tomas * The function extracts tpm out header return code 374f865c196SWinkler, Tomas * 375f865c196SWinkler, Tomas * @chip: TPM chip to use 37665520d46SWinkler, Tomas * @space: tpm space 377c659af78SStefan Berger * @buf: TPM command buffer 378c659af78SStefan Berger * @bufsiz: length of the buffer 379c659af78SStefan Berger * @min_rsp_body_length: minimum expected length of response body 380f865c196SWinkler, Tomas * @flags: tpm transmit flags - bitmap 381f865c196SWinkler, Tomas * @desc: command description used in the error message 382f865c196SWinkler, Tomas * 383f865c196SWinkler, Tomas * Return: 384f865c196SWinkler, Tomas * 0 when the operation is successful. 385f865c196SWinkler, Tomas * A negative number for system errors (errno). 386f865c196SWinkler, Tomas * A positive number for a TPM error. 387f865c196SWinkler, Tomas */ 388745b361eSJarkko Sakkinen ssize_t tpm_transmit_cmd(struct tpm_chip *chip, struct tpm_space *space, 38962c09e12SWinkler, Tomas void *buf, size_t bufsiz, 390745b361eSJarkko Sakkinen size_t min_rsp_body_length, unsigned int flags, 391745b361eSJarkko Sakkinen const char *desc) 3929deb0eb7SJason Gunthorpe { 393a147918eSJarkko Sakkinen const struct tpm_output_header *header = buf; 3949deb0eb7SJason Gunthorpe int err; 395c659af78SStefan Berger ssize_t len; 3969deb0eb7SJason Gunthorpe 39762c09e12SWinkler, Tomas len = tpm_transmit(chip, space, buf, bufsiz, flags); 3989deb0eb7SJason Gunthorpe if (len < 0) 3999deb0eb7SJason Gunthorpe return len; 40087155b73SJarkko Sakkinen 40187155b73SJarkko Sakkinen err = be32_to_cpu(header->return_code); 4020d6d0d62SJavier Martinez Canillas if (err != 0 && err != TPM_ERR_DISABLED && err != TPM_ERR_DEACTIVATED 4030d6d0d62SJavier Martinez Canillas && desc) 4048cfffc9dSJason Gunthorpe dev_err(&chip->dev, "A TPM error (%d) occurred %s\n", err, 40571ed848fSJarkko Sakkinen desc); 406c659af78SStefan Berger if (err) 4079deb0eb7SJason Gunthorpe return err; 408c659af78SStefan Berger 409c659af78SStefan Berger if (len < min_rsp_body_length + TPM_HEADER_SIZE) 410c659af78SStefan Berger return -EFAULT; 411c659af78SStefan Berger 412c659af78SStefan Berger return 0; 4139deb0eb7SJason Gunthorpe } 414be4c9acfSStefan Berger EXPORT_SYMBOL_GPL(tpm_transmit_cmd); 4159deb0eb7SJason Gunthorpe 41619cbe4f6SJarkko Sakkinen #define TPM_ORD_STARTUP 153 41719cbe4f6SJarkko Sakkinen #define TPM_ST_CLEAR 1 41819cbe4f6SJarkko Sakkinen 41919cbe4f6SJarkko Sakkinen /** 42019cbe4f6SJarkko Sakkinen * tpm_startup - turn on the TPM 42119cbe4f6SJarkko Sakkinen * @chip: TPM chip to use 42219cbe4f6SJarkko Sakkinen * 42319cbe4f6SJarkko Sakkinen * Normally the firmware should start the TPM. This function is provided as a 42419cbe4f6SJarkko Sakkinen * workaround if this does not happen. A legal case for this could be for 42519cbe4f6SJarkko Sakkinen * example when a TPM emulator is used. 42619cbe4f6SJarkko Sakkinen * 42719cbe4f6SJarkko Sakkinen * Return: same as tpm_transmit_cmd() 42819cbe4f6SJarkko Sakkinen */ 42919cbe4f6SJarkko Sakkinen int tpm_startup(struct tpm_chip *chip) 43019cbe4f6SJarkko Sakkinen { 43119cbe4f6SJarkko Sakkinen struct tpm_buf buf; 43219cbe4f6SJarkko Sakkinen int rc; 43319cbe4f6SJarkko Sakkinen 43419cbe4f6SJarkko Sakkinen dev_info(&chip->dev, "starting up the TPM manually\n"); 43519cbe4f6SJarkko Sakkinen 43619cbe4f6SJarkko Sakkinen if (chip->flags & TPM_CHIP_FLAG_TPM2) { 43719cbe4f6SJarkko Sakkinen rc = tpm_buf_init(&buf, TPM2_ST_NO_SESSIONS, TPM2_CC_STARTUP); 43819cbe4f6SJarkko Sakkinen if (rc < 0) 43919cbe4f6SJarkko Sakkinen return rc; 44019cbe4f6SJarkko Sakkinen 44119cbe4f6SJarkko Sakkinen tpm_buf_append_u16(&buf, TPM2_SU_CLEAR); 44219cbe4f6SJarkko Sakkinen } else { 44319cbe4f6SJarkko Sakkinen rc = tpm_buf_init(&buf, TPM_TAG_RQU_COMMAND, TPM_ORD_STARTUP); 44419cbe4f6SJarkko Sakkinen if (rc < 0) 44519cbe4f6SJarkko Sakkinen return rc; 44619cbe4f6SJarkko Sakkinen 44719cbe4f6SJarkko Sakkinen tpm_buf_append_u16(&buf, TPM_ST_CLEAR); 44819cbe4f6SJarkko Sakkinen } 44919cbe4f6SJarkko Sakkinen 45019cbe4f6SJarkko Sakkinen rc = tpm_transmit_cmd(chip, NULL, buf.data, PAGE_SIZE, 0, 0, 45119cbe4f6SJarkko Sakkinen "attempting to start the TPM"); 45219cbe4f6SJarkko Sakkinen 45319cbe4f6SJarkko Sakkinen tpm_buf_destroy(&buf); 45419cbe4f6SJarkko Sakkinen return rc; 45519cbe4f6SJarkko Sakkinen } 45619cbe4f6SJarkko Sakkinen 4579deb0eb7SJason Gunthorpe int tpm_get_timeouts(struct tpm_chip *chip) 4589deb0eb7SJason Gunthorpe { 459d1d253cfSJason Gunthorpe if (chip->flags & TPM_CHIP_FLAG_HAVE_TIMEOUTS) 460d1d253cfSJason Gunthorpe return 0; 461d1d253cfSJason Gunthorpe 46270a3199aSTomas Winkler if (chip->flags & TPM_CHIP_FLAG_TPM2) 46370a3199aSTomas Winkler return tpm2_get_timeouts(chip); 46470a3199aSTomas Winkler else 46570a3199aSTomas Winkler return tpm1_get_timeouts(chip); 4669deb0eb7SJason Gunthorpe } 4679deb0eb7SJason Gunthorpe EXPORT_SYMBOL_GPL(tpm_get_timeouts); 4689deb0eb7SJason Gunthorpe 4699deb0eb7SJason Gunthorpe /** 470aad887f6SJarkko Sakkinen * tpm_is_tpm2 - do we a have a TPM2 chip? 471aad887f6SJarkko Sakkinen * @chip: a &struct tpm_chip instance, %NULL for the default chip 472954650efSJarkko Sakkinen * 473aad887f6SJarkko Sakkinen * Return: 474aad887f6SJarkko Sakkinen * 1 if we have a TPM2 chip. 475aad887f6SJarkko Sakkinen * 0 if we don't have a TPM2 chip. 476aad887f6SJarkko Sakkinen * A negative number for system errors (errno). 477954650efSJarkko Sakkinen */ 478aad887f6SJarkko Sakkinen int tpm_is_tpm2(struct tpm_chip *chip) 479954650efSJarkko Sakkinen { 480954650efSJarkko Sakkinen int rc; 481954650efSJarkko Sakkinen 482fc1d52b7SStefan Berger chip = tpm_find_get_ops(chip); 483aad887f6SJarkko Sakkinen if (!chip) 484954650efSJarkko Sakkinen return -ENODEV; 485954650efSJarkko Sakkinen 486954650efSJarkko Sakkinen rc = (chip->flags & TPM_CHIP_FLAG_TPM2) != 0; 487954650efSJarkko Sakkinen 4884e26195fSJason Gunthorpe tpm_put_ops(chip); 489954650efSJarkko Sakkinen 490954650efSJarkko Sakkinen return rc; 491954650efSJarkko Sakkinen } 492954650efSJarkko Sakkinen EXPORT_SYMBOL_GPL(tpm_is_tpm2); 493954650efSJarkko Sakkinen 494954650efSJarkko Sakkinen /** 495aad887f6SJarkko Sakkinen * tpm_pcr_read - read a PCR value from SHA1 bank 496aad887f6SJarkko Sakkinen * @chip: a &struct tpm_chip instance, %NULL for the default chip 497aad887f6SJarkko Sakkinen * @pcr_idx: the PCR to be retrieved 498aad887f6SJarkko Sakkinen * @res_buf: the value of the PCR 4999deb0eb7SJason Gunthorpe * 500aad887f6SJarkko Sakkinen * Return: same as with tpm_transmit_cmd() 5019deb0eb7SJason Gunthorpe */ 502aad887f6SJarkko Sakkinen int tpm_pcr_read(struct tpm_chip *chip, int pcr_idx, u8 *res_buf) 5039deb0eb7SJason Gunthorpe { 5049deb0eb7SJason Gunthorpe int rc; 5059deb0eb7SJason Gunthorpe 506fc1d52b7SStefan Berger chip = tpm_find_get_ops(chip); 507aad887f6SJarkko Sakkinen if (!chip) 5089deb0eb7SJason Gunthorpe return -ENODEV; 509*d4a31756STomas Winkler 5107a1d7e6dSJarkko Sakkinen if (chip->flags & TPM_CHIP_FLAG_TPM2) 5117a1d7e6dSJarkko Sakkinen rc = tpm2_pcr_read(chip, pcr_idx, res_buf); 5127a1d7e6dSJarkko Sakkinen else 513*d4a31756STomas Winkler rc = tpm1_pcr_read_dev(chip, pcr_idx, res_buf); 514*d4a31756STomas Winkler 5154e26195fSJason Gunthorpe tpm_put_ops(chip); 5169deb0eb7SJason Gunthorpe return rc; 5179deb0eb7SJason Gunthorpe } 5189deb0eb7SJason Gunthorpe EXPORT_SYMBOL_GPL(tpm_pcr_read); 5199deb0eb7SJason Gunthorpe 5209deb0eb7SJason Gunthorpe /** 521aad887f6SJarkko Sakkinen * tpm_pcr_extend - extend a PCR value in SHA1 bank. 522aad887f6SJarkko Sakkinen * @chip: a &struct tpm_chip instance, %NULL for the default chip 523aad887f6SJarkko Sakkinen * @pcr_idx: the PCR to be retrieved 524aad887f6SJarkko Sakkinen * @hash: the hash value used to extend the PCR value 5259deb0eb7SJason Gunthorpe * 526aad887f6SJarkko Sakkinen * Note: with TPM 2.0 extends also those banks with a known digest size to the 527aad887f6SJarkko Sakkinen * cryto subsystem in order to prevent malicious use of those PCR banks. In the 528aad887f6SJarkko Sakkinen * future we should dynamically determine digest sizes. 529aad887f6SJarkko Sakkinen * 530aad887f6SJarkko Sakkinen * Return: same as with tpm_transmit_cmd() 5319deb0eb7SJason Gunthorpe */ 532aad887f6SJarkko Sakkinen int tpm_pcr_extend(struct tpm_chip *chip, int pcr_idx, const u8 *hash) 5339deb0eb7SJason Gunthorpe { 5349deb0eb7SJason Gunthorpe int rc; 535c1f92b4bSNayna Jain struct tpm2_digest digest_list[ARRAY_SIZE(chip->active_banks)]; 536c1f92b4bSNayna Jain u32 count = 0; 537c1f92b4bSNayna Jain int i; 5389deb0eb7SJason Gunthorpe 539fc1d52b7SStefan Berger chip = tpm_find_get_ops(chip); 540aad887f6SJarkko Sakkinen if (!chip) 5419deb0eb7SJason Gunthorpe return -ENODEV; 5429deb0eb7SJason Gunthorpe 5437a1d7e6dSJarkko Sakkinen if (chip->flags & TPM_CHIP_FLAG_TPM2) { 544c1f92b4bSNayna Jain memset(digest_list, 0, sizeof(digest_list)); 545c1f92b4bSNayna Jain 54670ea1636SDan Carpenter for (i = 0; i < ARRAY_SIZE(chip->active_banks) && 54770ea1636SDan Carpenter chip->active_banks[i] != TPM2_ALG_ERROR; i++) { 548c1f92b4bSNayna Jain digest_list[i].alg_id = chip->active_banks[i]; 549c1f92b4bSNayna Jain memcpy(digest_list[i].digest, hash, TPM_DIGEST_SIZE); 550c1f92b4bSNayna Jain count++; 551c1f92b4bSNayna Jain } 552c1f92b4bSNayna Jain 553c1f92b4bSNayna Jain rc = tpm2_pcr_extend(chip, pcr_idx, count, digest_list); 5544e26195fSJason Gunthorpe tpm_put_ops(chip); 5557a1d7e6dSJarkko Sakkinen return rc; 5567a1d7e6dSJarkko Sakkinen } 5577a1d7e6dSJarkko Sakkinen 558175d5b2aSRoberto Sassu rc = tpm1_pcr_extend(chip, pcr_idx, hash, 5599deb0eb7SJason Gunthorpe "attempting extend a PCR value"); 5604e26195fSJason Gunthorpe tpm_put_ops(chip); 5619deb0eb7SJason Gunthorpe return rc; 5629deb0eb7SJason Gunthorpe } 5639deb0eb7SJason Gunthorpe EXPORT_SYMBOL_GPL(tpm_pcr_extend); 5649deb0eb7SJason Gunthorpe 5659deb0eb7SJason Gunthorpe /** 566aad887f6SJarkko Sakkinen * tpm_send - send a TPM command 567aad887f6SJarkko Sakkinen * @chip: a &struct tpm_chip instance, %NULL for the default chip 568aad887f6SJarkko Sakkinen * @cmd: a TPM command buffer 569aad887f6SJarkko Sakkinen * @buflen: the length of the TPM command buffer 570aad887f6SJarkko Sakkinen * 571aad887f6SJarkko Sakkinen * Return: same as with tpm_transmit_cmd() 572aad887f6SJarkko Sakkinen */ 573aad887f6SJarkko Sakkinen int tpm_send(struct tpm_chip *chip, void *cmd, size_t buflen) 5749deb0eb7SJason Gunthorpe { 5759deb0eb7SJason Gunthorpe int rc; 5769deb0eb7SJason Gunthorpe 577fc1d52b7SStefan Berger chip = tpm_find_get_ops(chip); 578aad887f6SJarkko Sakkinen if (!chip) 5799deb0eb7SJason Gunthorpe return -ENODEV; 5809deb0eb7SJason Gunthorpe 581745b361eSJarkko Sakkinen rc = tpm_transmit_cmd(chip, NULL, cmd, buflen, 0, 0, 582aad887f6SJarkko Sakkinen "attempting to a send a command"); 5834e26195fSJason Gunthorpe tpm_put_ops(chip); 5849deb0eb7SJason Gunthorpe return rc; 5859deb0eb7SJason Gunthorpe } 5869deb0eb7SJason Gunthorpe EXPORT_SYMBOL_GPL(tpm_send); 5879deb0eb7SJason Gunthorpe 588a69faebfSRoberto Sassu #define TPM_ORD_SAVESTATE 152 5899deb0eb7SJason Gunthorpe #define SAVESTATE_RESULT_SIZE 10 5909deb0eb7SJason Gunthorpe 5910014777fSJulia Lawall static const struct tpm_input_header savestate_header = { 59206e93279SRoberto Sassu .tag = cpu_to_be16(TPM_TAG_RQU_COMMAND), 5939deb0eb7SJason Gunthorpe .length = cpu_to_be32(10), 594a69faebfSRoberto Sassu .ordinal = cpu_to_be32(TPM_ORD_SAVESTATE) 5959deb0eb7SJason Gunthorpe }; 5969deb0eb7SJason Gunthorpe 5979deb0eb7SJason Gunthorpe /* 5989deb0eb7SJason Gunthorpe * We are about to suspend. Save the TPM state 5999deb0eb7SJason Gunthorpe * so that it can be restored. 6009deb0eb7SJason Gunthorpe */ 6019deb0eb7SJason Gunthorpe int tpm_pm_suspend(struct device *dev) 6029deb0eb7SJason Gunthorpe { 603ec03c50bSStefan Berger struct tpm_chip *chip = dev_get_drvdata(dev); 6049deb0eb7SJason Gunthorpe struct tpm_cmd_t cmd; 6059deb0eb7SJason Gunthorpe int rc, try; 6069deb0eb7SJason Gunthorpe 6079deb0eb7SJason Gunthorpe u8 dummy_hash[TPM_DIGEST_SIZE] = { 0 }; 6089deb0eb7SJason Gunthorpe 6099deb0eb7SJason Gunthorpe if (chip == NULL) 6109deb0eb7SJason Gunthorpe return -ENODEV; 6119deb0eb7SJason Gunthorpe 612b5d0ebc9SEnric Balletbo i Serra if (chip->flags & TPM_CHIP_FLAG_ALWAYS_POWERED) 613b5d0ebc9SEnric Balletbo i Serra return 0; 614b5d0ebc9SEnric Balletbo i Serra 61574d6b3ceSJarkko Sakkinen if (chip->flags & TPM_CHIP_FLAG_TPM2) { 61674d6b3ceSJarkko Sakkinen tpm2_shutdown(chip, TPM2_SU_STATE); 61774d6b3ceSJarkko Sakkinen return 0; 61874d6b3ceSJarkko Sakkinen } 61930fc8d13SJarkko Sakkinen 6209deb0eb7SJason Gunthorpe /* for buggy tpm, flush pcrs with extend to selected dummy */ 621175d5b2aSRoberto Sassu if (tpm_suspend_pcr) 622175d5b2aSRoberto Sassu rc = tpm1_pcr_extend(chip, tpm_suspend_pcr, dummy_hash, 6239deb0eb7SJason Gunthorpe "extending dummy pcr before suspend"); 6249deb0eb7SJason Gunthorpe 6259deb0eb7SJason Gunthorpe /* now do the actual savestate */ 6269deb0eb7SJason Gunthorpe for (try = 0; try < TPM_RETRY; try++) { 6279deb0eb7SJason Gunthorpe cmd.header.in = savestate_header; 628745b361eSJarkko Sakkinen rc = tpm_transmit_cmd(chip, NULL, &cmd, SAVESTATE_RESULT_SIZE, 629745b361eSJarkko Sakkinen 0, 0, NULL); 6309deb0eb7SJason Gunthorpe 6319deb0eb7SJason Gunthorpe /* 6329deb0eb7SJason Gunthorpe * If the TPM indicates that it is too busy to respond to 6339deb0eb7SJason Gunthorpe * this command then retry before giving up. It can take 6349deb0eb7SJason Gunthorpe * several seconds for this TPM to be ready. 6359deb0eb7SJason Gunthorpe * 6369deb0eb7SJason Gunthorpe * This can happen if the TPM has already been sent the 6379deb0eb7SJason Gunthorpe * SaveState command before the driver has loaded. TCG 1.2 6389deb0eb7SJason Gunthorpe * specification states that any communication after SaveState 6399deb0eb7SJason Gunthorpe * may cause the TPM to invalidate previously saved state. 6409deb0eb7SJason Gunthorpe */ 6419deb0eb7SJason Gunthorpe if (rc != TPM_WARN_RETRY) 6429deb0eb7SJason Gunthorpe break; 6439f3fc7bcSHamza Attak tpm_msleep(TPM_TIMEOUT_RETRY); 6449deb0eb7SJason Gunthorpe } 6459deb0eb7SJason Gunthorpe 6469deb0eb7SJason Gunthorpe if (rc) 6478cfffc9dSJason Gunthorpe dev_err(&chip->dev, 6489deb0eb7SJason Gunthorpe "Error (%d) sending savestate before suspend\n", rc); 6499deb0eb7SJason Gunthorpe else if (try > 0) 6508cfffc9dSJason Gunthorpe dev_warn(&chip->dev, "TPM savestate took %dms\n", 6519deb0eb7SJason Gunthorpe try * TPM_TIMEOUT_RETRY); 6529deb0eb7SJason Gunthorpe 6539deb0eb7SJason Gunthorpe return rc; 6549deb0eb7SJason Gunthorpe } 6559deb0eb7SJason Gunthorpe EXPORT_SYMBOL_GPL(tpm_pm_suspend); 6569deb0eb7SJason Gunthorpe 6579deb0eb7SJason Gunthorpe /* 6589deb0eb7SJason Gunthorpe * Resume from a power safe. The BIOS already restored 6599deb0eb7SJason Gunthorpe * the TPM state. 6609deb0eb7SJason Gunthorpe */ 6619deb0eb7SJason Gunthorpe int tpm_pm_resume(struct device *dev) 6629deb0eb7SJason Gunthorpe { 663ec03c50bSStefan Berger struct tpm_chip *chip = dev_get_drvdata(dev); 6649deb0eb7SJason Gunthorpe 6659deb0eb7SJason Gunthorpe if (chip == NULL) 6669deb0eb7SJason Gunthorpe return -ENODEV; 6679deb0eb7SJason Gunthorpe 6689deb0eb7SJason Gunthorpe return 0; 6699deb0eb7SJason Gunthorpe } 6709deb0eb7SJason Gunthorpe EXPORT_SYMBOL_GPL(tpm_pm_resume); 6719deb0eb7SJason Gunthorpe 6729deb0eb7SJason Gunthorpe /** 673aad887f6SJarkko Sakkinen * tpm_get_random() - get random bytes from the TPM's RNG 674aad887f6SJarkko Sakkinen * @chip: a &struct tpm_chip instance, %NULL for the default chip 6759deb0eb7SJason Gunthorpe * @out: destination buffer for the random bytes 6769deb0eb7SJason Gunthorpe * @max: the max number of bytes to write to @out 6779deb0eb7SJason Gunthorpe * 678aad887f6SJarkko Sakkinen * Return: same as with tpm_transmit_cmd() 6799deb0eb7SJason Gunthorpe */ 680aad887f6SJarkko Sakkinen int tpm_get_random(struct tpm_chip *chip, u8 *out, size_t max) 6819deb0eb7SJason Gunthorpe { 682433d390fSTomas Winkler int rc; 6839deb0eb7SJason Gunthorpe 684433d390fSTomas Winkler if (!out || max > TPM_MAX_RNG_DATA) 6853e14d83eSJarkko Sakkinen return -EINVAL; 6863e14d83eSJarkko Sakkinen 687fc1d52b7SStefan Berger chip = tpm_find_get_ops(chip); 688aad887f6SJarkko Sakkinen if (!chip) 6899deb0eb7SJason Gunthorpe return -ENODEV; 6909deb0eb7SJason Gunthorpe 691433d390fSTomas Winkler if (chip->flags & TPM_CHIP_FLAG_TPM2) 692433d390fSTomas Winkler rc = tpm2_get_random(chip, out, max); 693433d390fSTomas Winkler else 694433d390fSTomas Winkler rc = tpm1_get_random(chip, out, max); 6959deb0eb7SJason Gunthorpe 6964e26195fSJason Gunthorpe tpm_put_ops(chip); 697433d390fSTomas Winkler return rc; 6989deb0eb7SJason Gunthorpe } 6999deb0eb7SJason Gunthorpe EXPORT_SYMBOL_GPL(tpm_get_random); 7009deb0eb7SJason Gunthorpe 701954650efSJarkko Sakkinen /** 702aad887f6SJarkko Sakkinen * tpm_seal_trusted() - seal a trusted key payload 703aad887f6SJarkko Sakkinen * @chip: a &struct tpm_chip instance, %NULL for the default chip 704954650efSJarkko Sakkinen * @options: authentication values and other options 705954650efSJarkko Sakkinen * @payload: the key data in clear and encrypted form 706954650efSJarkko Sakkinen * 707aad887f6SJarkko Sakkinen * Note: only TPM 2.0 chip are supported. TPM 1.x implementation is located in 708aad887f6SJarkko Sakkinen * the keyring subsystem. 709aad887f6SJarkko Sakkinen * 710aad887f6SJarkko Sakkinen * Return: same as with tpm_transmit_cmd() 711954650efSJarkko Sakkinen */ 712aad887f6SJarkko Sakkinen int tpm_seal_trusted(struct tpm_chip *chip, struct trusted_key_payload *payload, 713954650efSJarkko Sakkinen struct trusted_key_options *options) 714954650efSJarkko Sakkinen { 715954650efSJarkko Sakkinen int rc; 716954650efSJarkko Sakkinen 717fc1d52b7SStefan Berger chip = tpm_find_get_ops(chip); 718aad887f6SJarkko Sakkinen if (!chip || !(chip->flags & TPM_CHIP_FLAG_TPM2)) 719954650efSJarkko Sakkinen return -ENODEV; 720954650efSJarkko Sakkinen 721954650efSJarkko Sakkinen rc = tpm2_seal_trusted(chip, payload, options); 722954650efSJarkko Sakkinen 7234e26195fSJason Gunthorpe tpm_put_ops(chip); 724954650efSJarkko Sakkinen return rc; 725954650efSJarkko Sakkinen } 726954650efSJarkko Sakkinen EXPORT_SYMBOL_GPL(tpm_seal_trusted); 727954650efSJarkko Sakkinen 728954650efSJarkko Sakkinen /** 729954650efSJarkko Sakkinen * tpm_unseal_trusted() - unseal a trusted key 730aad887f6SJarkko Sakkinen * @chip: a &struct tpm_chip instance, %NULL for the default chip 731954650efSJarkko Sakkinen * @options: authentication values and other options 732954650efSJarkko Sakkinen * @payload: the key data in clear and encrypted form 733954650efSJarkko Sakkinen * 734aad887f6SJarkko Sakkinen * Note: only TPM 2.0 chip are supported. TPM 1.x implementation is located in 735aad887f6SJarkko Sakkinen * the keyring subsystem. 736aad887f6SJarkko Sakkinen * 737aad887f6SJarkko Sakkinen * Return: same as with tpm_transmit_cmd() 738954650efSJarkko Sakkinen */ 739aad887f6SJarkko Sakkinen int tpm_unseal_trusted(struct tpm_chip *chip, 740aad887f6SJarkko Sakkinen struct trusted_key_payload *payload, 741954650efSJarkko Sakkinen struct trusted_key_options *options) 742954650efSJarkko Sakkinen { 743954650efSJarkko Sakkinen int rc; 744954650efSJarkko Sakkinen 745fc1d52b7SStefan Berger chip = tpm_find_get_ops(chip); 746aad887f6SJarkko Sakkinen if (!chip || !(chip->flags & TPM_CHIP_FLAG_TPM2)) 747954650efSJarkko Sakkinen return -ENODEV; 748954650efSJarkko Sakkinen 749954650efSJarkko Sakkinen rc = tpm2_unseal_trusted(chip, payload, options); 750954650efSJarkko Sakkinen 7514e26195fSJason Gunthorpe tpm_put_ops(chip); 7524e26195fSJason Gunthorpe 753954650efSJarkko Sakkinen return rc; 754954650efSJarkko Sakkinen } 755954650efSJarkko Sakkinen EXPORT_SYMBOL_GPL(tpm_unseal_trusted); 756954650efSJarkko Sakkinen 757313d21eeSJarkko Sakkinen static int __init tpm_init(void) 758313d21eeSJarkko Sakkinen { 759313d21eeSJarkko Sakkinen int rc; 760313d21eeSJarkko Sakkinen 761313d21eeSJarkko Sakkinen tpm_class = class_create(THIS_MODULE, "tpm"); 762313d21eeSJarkko Sakkinen if (IS_ERR(tpm_class)) { 763313d21eeSJarkko Sakkinen pr_err("couldn't create tpm class\n"); 764313d21eeSJarkko Sakkinen return PTR_ERR(tpm_class); 765313d21eeSJarkko Sakkinen } 766313d21eeSJarkko Sakkinen 767fdc915f7SJames Bottomley tpmrm_class = class_create(THIS_MODULE, "tpmrm"); 768fdc915f7SJames Bottomley if (IS_ERR(tpmrm_class)) { 769fdc915f7SJames Bottomley pr_err("couldn't create tpmrm class\n"); 7709e1b74a6STadeusz Struk rc = PTR_ERR(tpmrm_class); 7719e1b74a6STadeusz Struk goto out_destroy_tpm_class; 772fdc915f7SJames Bottomley } 773fdc915f7SJames Bottomley 774fdc915f7SJames Bottomley rc = alloc_chrdev_region(&tpm_devt, 0, 2*TPM_NUM_DEVICES, "tpm"); 775313d21eeSJarkko Sakkinen if (rc < 0) { 776313d21eeSJarkko Sakkinen pr_err("tpm: failed to allocate char dev region\n"); 7779e1b74a6STadeusz Struk goto out_destroy_tpmrm_class; 7789e1b74a6STadeusz Struk } 7799e1b74a6STadeusz Struk 7809e1b74a6STadeusz Struk rc = tpm_dev_common_init(); 7819e1b74a6STadeusz Struk if (rc) { 7829e1b74a6STadeusz Struk pr_err("tpm: failed to allocate char dev region\n"); 7839e1b74a6STadeusz Struk goto out_unreg_chrdev; 784313d21eeSJarkko Sakkinen } 785313d21eeSJarkko Sakkinen 786313d21eeSJarkko Sakkinen return 0; 7879e1b74a6STadeusz Struk 7889e1b74a6STadeusz Struk out_unreg_chrdev: 7899e1b74a6STadeusz Struk unregister_chrdev_region(tpm_devt, 2 * TPM_NUM_DEVICES); 7909e1b74a6STadeusz Struk out_destroy_tpmrm_class: 7919e1b74a6STadeusz Struk class_destroy(tpmrm_class); 7929e1b74a6STadeusz Struk out_destroy_tpm_class: 7939e1b74a6STadeusz Struk class_destroy(tpm_class); 7949e1b74a6STadeusz Struk 7959e1b74a6STadeusz Struk return rc; 796313d21eeSJarkko Sakkinen } 797313d21eeSJarkko Sakkinen 798313d21eeSJarkko Sakkinen static void __exit tpm_exit(void) 799313d21eeSJarkko Sakkinen { 80015516788SStefan Berger idr_destroy(&dev_nums_idr); 801313d21eeSJarkko Sakkinen class_destroy(tpm_class); 802fdc915f7SJames Bottomley class_destroy(tpmrm_class); 803fdc915f7SJames Bottomley unregister_chrdev_region(tpm_devt, 2*TPM_NUM_DEVICES); 8049e1b74a6STadeusz Struk tpm_dev_common_exit(); 805313d21eeSJarkko Sakkinen } 806313d21eeSJarkko Sakkinen 807313d21eeSJarkko Sakkinen subsys_initcall(tpm_init); 808313d21eeSJarkko Sakkinen module_exit(tpm_exit); 809313d21eeSJarkko Sakkinen 8109deb0eb7SJason Gunthorpe MODULE_AUTHOR("Leendert van Doorn (leendert@watson.ibm.com)"); 8119deb0eb7SJason Gunthorpe MODULE_DESCRIPTION("TPM Driver"); 8129deb0eb7SJason Gunthorpe MODULE_VERSION("2.0"); 8139deb0eb7SJason Gunthorpe MODULE_LICENSE("GPL"); 814