19deb0eb7SJason Gunthorpe /* 29deb0eb7SJason Gunthorpe * Copyright (C) 2004 IBM Corporation 3afb5abc2SJarkko Sakkinen * Copyright (C) 2014 Intel Corporation 49deb0eb7SJason Gunthorpe * 59deb0eb7SJason Gunthorpe * Authors: 69deb0eb7SJason Gunthorpe * Leendert van Doorn <leendert@watson.ibm.com> 79deb0eb7SJason Gunthorpe * Dave Safford <safford@watson.ibm.com> 89deb0eb7SJason Gunthorpe * Reiner Sailer <sailer@watson.ibm.com> 99deb0eb7SJason Gunthorpe * Kylene Hall <kjhall@us.ibm.com> 109deb0eb7SJason Gunthorpe * 119deb0eb7SJason Gunthorpe * Maintained by: <tpmdd-devel@lists.sourceforge.net> 129deb0eb7SJason Gunthorpe * 139deb0eb7SJason Gunthorpe * Device driver for TCG/TCPA TPM (trusted platform module). 149deb0eb7SJason Gunthorpe * Specifications at www.trustedcomputinggroup.org 159deb0eb7SJason Gunthorpe * 169deb0eb7SJason Gunthorpe * This program is free software; you can redistribute it and/or 179deb0eb7SJason Gunthorpe * modify it under the terms of the GNU General Public License as 189deb0eb7SJason Gunthorpe * published by the Free Software Foundation, version 2 of the 199deb0eb7SJason Gunthorpe * License. 209deb0eb7SJason Gunthorpe * 219deb0eb7SJason Gunthorpe * Note, the TPM chip is not interrupt driven (only polling) 229deb0eb7SJason Gunthorpe * and can have very long timeouts (minutes!). Hence the unusual 239deb0eb7SJason Gunthorpe * calls to msleep. 249deb0eb7SJason Gunthorpe * 259deb0eb7SJason Gunthorpe */ 269deb0eb7SJason Gunthorpe 279deb0eb7SJason Gunthorpe #include <linux/poll.h> 289deb0eb7SJason Gunthorpe #include <linux/slab.h> 299deb0eb7SJason Gunthorpe #include <linux/mutex.h> 309deb0eb7SJason Gunthorpe #include <linux/spinlock.h> 319deb0eb7SJason Gunthorpe #include <linux/freezer.h> 32fd3ec366SThiebaud Weksteen #include <linux/tpm_eventlog.h> 339deb0eb7SJason Gunthorpe 349deb0eb7SJason Gunthorpe #include "tpm.h" 359deb0eb7SJason Gunthorpe 369deb0eb7SJason Gunthorpe #define TSC_MAX_ORDINAL 12 379deb0eb7SJason Gunthorpe #define TPM_PROTECTED_COMMAND 0x00 389deb0eb7SJason Gunthorpe #define TPM_CONNECTION_COMMAND 0x40 399deb0eb7SJason Gunthorpe 409deb0eb7SJason Gunthorpe /* 419deb0eb7SJason Gunthorpe * Bug workaround - some TPM's don't flush the most 429deb0eb7SJason Gunthorpe * recently changed pcr on suspend, so force the flush 439deb0eb7SJason Gunthorpe * with an extend to the selected _unused_ non-volatile pcr. 449deb0eb7SJason Gunthorpe */ 459deb0eb7SJason Gunthorpe static int tpm_suspend_pcr; 469deb0eb7SJason Gunthorpe module_param_named(suspend_pcr, tpm_suspend_pcr, uint, 0644); 479deb0eb7SJason Gunthorpe MODULE_PARM_DESC(suspend_pcr, 4839f5712bSDmitry Torokhov "PCR to use for dummy writes to facilitate flush on suspend."); 499deb0eb7SJason Gunthorpe 50*d856c00fSTomas Winkler /** 51*d856c00fSTomas Winkler * tpm_calc_ordinal_duration() - calculate the maximum command duration 52*d856c00fSTomas Winkler * @chip: TPM chip to use. 53*d856c00fSTomas Winkler * @ordinal: TPM command ordinal. 54*d856c00fSTomas Winkler * 55*d856c00fSTomas Winkler * The function returns the maximum amount of time the chip could take 56*d856c00fSTomas Winkler * to return the result for a particular ordinal in jiffies. 57*d856c00fSTomas Winkler * 58*d856c00fSTomas Winkler * Return: A maximal duration time for an ordinal in jiffies. 59*d856c00fSTomas Winkler */ 60*d856c00fSTomas Winkler unsigned long tpm_calc_ordinal_duration(struct tpm_chip *chip, u32 ordinal) 61*d856c00fSTomas Winkler { 62*d856c00fSTomas Winkler if (chip->flags & TPM_CHIP_FLAG_TPM2) 63*d856c00fSTomas Winkler return tpm2_calc_ordinal_duration(chip, ordinal); 64*d856c00fSTomas Winkler else 65*d856c00fSTomas Winkler return tpm1_calc_ordinal_duration(chip, ordinal); 66*d856c00fSTomas Winkler } 67*d856c00fSTomas Winkler EXPORT_SYMBOL_GPL(tpm_calc_ordinal_duration); 68*d856c00fSTomas Winkler 69095531f8SJavier Martinez Canillas static int tpm_validate_command(struct tpm_chip *chip, 70745b361eSJarkko Sakkinen struct tpm_space *space, 71745b361eSJarkko Sakkinen const u8 *cmd, 7258472f5cSJarkko Sakkinen size_t len) 7358472f5cSJarkko Sakkinen { 7458472f5cSJarkko Sakkinen const struct tpm_input_header *header = (const void *)cmd; 7558472f5cSJarkko Sakkinen int i; 7658472f5cSJarkko Sakkinen u32 cc; 7758472f5cSJarkko Sakkinen u32 attrs; 7858472f5cSJarkko Sakkinen unsigned int nr_handles; 7958472f5cSJarkko Sakkinen 8058472f5cSJarkko Sakkinen if (len < TPM_HEADER_SIZE) 81095531f8SJavier Martinez Canillas return -EINVAL; 8258472f5cSJarkko Sakkinen 83745b361eSJarkko Sakkinen if (!space) 84095531f8SJavier Martinez Canillas return 0; 85745b361eSJarkko Sakkinen 8658472f5cSJarkko Sakkinen if (chip->flags & TPM_CHIP_FLAG_TPM2 && chip->nr_commands) { 8758472f5cSJarkko Sakkinen cc = be32_to_cpu(header->ordinal); 8858472f5cSJarkko Sakkinen 8958472f5cSJarkko Sakkinen i = tpm2_find_cc(chip, cc); 9058472f5cSJarkko Sakkinen if (i < 0) { 9158472f5cSJarkko Sakkinen dev_dbg(&chip->dev, "0x%04X is an invalid command\n", 9258472f5cSJarkko Sakkinen cc); 93095531f8SJavier Martinez Canillas return -EOPNOTSUPP; 9458472f5cSJarkko Sakkinen } 9558472f5cSJarkko Sakkinen 9658472f5cSJarkko Sakkinen attrs = chip->cc_attrs_tbl[i]; 9758472f5cSJarkko Sakkinen nr_handles = 9858472f5cSJarkko Sakkinen 4 * ((attrs >> TPM2_CC_ATTR_CHANDLES) & GENMASK(2, 0)); 9958472f5cSJarkko Sakkinen if (len < TPM_HEADER_SIZE + 4 * nr_handles) 10058472f5cSJarkko Sakkinen goto err_len; 10158472f5cSJarkko Sakkinen } 10258472f5cSJarkko Sakkinen 103095531f8SJavier Martinez Canillas return 0; 10458472f5cSJarkko Sakkinen err_len: 10558472f5cSJarkko Sakkinen dev_dbg(&chip->dev, 10658472f5cSJarkko Sakkinen "%s: insufficient command length %zu", __func__, len); 107095531f8SJavier Martinez Canillas return -EINVAL; 10858472f5cSJarkko Sakkinen } 10958472f5cSJarkko Sakkinen 110627448e8STomas Winkler static int tpm_request_locality(struct tpm_chip *chip, unsigned int flags) 111888d867dSTomas Winkler { 112888d867dSTomas Winkler int rc; 113888d867dSTomas Winkler 11458bac8ccSJarkko Sakkinen if (flags & TPM_TRANSMIT_NESTED) 115627448e8STomas Winkler return 0; 116627448e8STomas Winkler 117888d867dSTomas Winkler if (!chip->ops->request_locality) 118888d867dSTomas Winkler return 0; 119888d867dSTomas Winkler 120888d867dSTomas Winkler rc = chip->ops->request_locality(chip, 0); 121888d867dSTomas Winkler if (rc < 0) 122888d867dSTomas Winkler return rc; 123888d867dSTomas Winkler 124888d867dSTomas Winkler chip->locality = rc; 125888d867dSTomas Winkler 126888d867dSTomas Winkler return 0; 127888d867dSTomas Winkler } 128888d867dSTomas Winkler 129627448e8STomas Winkler static void tpm_relinquish_locality(struct tpm_chip *chip, unsigned int flags) 130888d867dSTomas Winkler { 131888d867dSTomas Winkler int rc; 132888d867dSTomas Winkler 13358bac8ccSJarkko Sakkinen if (flags & TPM_TRANSMIT_NESTED) 134627448e8STomas Winkler return; 135627448e8STomas Winkler 136888d867dSTomas Winkler if (!chip->ops->relinquish_locality) 137888d867dSTomas Winkler return; 138888d867dSTomas Winkler 139888d867dSTomas Winkler rc = chip->ops->relinquish_locality(chip, chip->locality); 140888d867dSTomas Winkler if (rc) 141888d867dSTomas Winkler dev_err(&chip->dev, "%s: : error %d\n", __func__, rc); 142888d867dSTomas Winkler 143888d867dSTomas Winkler chip->locality = -1; 144888d867dSTomas Winkler } 145888d867dSTomas Winkler 146627448e8STomas Winkler static int tpm_cmd_ready(struct tpm_chip *chip, unsigned int flags) 147627448e8STomas Winkler { 14858bac8ccSJarkko Sakkinen if (flags & TPM_TRANSMIT_NESTED) 149627448e8STomas Winkler return 0; 150627448e8STomas Winkler 151627448e8STomas Winkler if (!chip->ops->cmd_ready) 152627448e8STomas Winkler return 0; 153627448e8STomas Winkler 154627448e8STomas Winkler return chip->ops->cmd_ready(chip); 155627448e8STomas Winkler } 156627448e8STomas Winkler 157627448e8STomas Winkler static int tpm_go_idle(struct tpm_chip *chip, unsigned int flags) 158627448e8STomas Winkler { 15958bac8ccSJarkko Sakkinen if (flags & TPM_TRANSMIT_NESTED) 160627448e8STomas Winkler return 0; 161627448e8STomas Winkler 162627448e8STomas Winkler if (!chip->ops->go_idle) 163627448e8STomas Winkler return 0; 164627448e8STomas Winkler 165627448e8STomas Winkler return chip->ops->go_idle(chip); 166627448e8STomas Winkler } 167627448e8STomas Winkler 168e2fb992dSJames Bottomley static ssize_t tpm_try_transmit(struct tpm_chip *chip, 169e2fb992dSJames Bottomley struct tpm_space *space, 170e2fb992dSJames Bottomley u8 *buf, size_t bufsiz, 171e2fb992dSJames Bottomley unsigned int flags) 1729deb0eb7SJason Gunthorpe { 173745b361eSJarkko Sakkinen struct tpm_output_header *header = (void *)buf; 174745b361eSJarkko Sakkinen int rc; 175745b361eSJarkko Sakkinen ssize_t len = 0; 1769deb0eb7SJason Gunthorpe u32 count, ordinal; 1779deb0eb7SJason Gunthorpe unsigned long stop; 178877c57d0SJarkko Sakkinen bool need_locality; 1799deb0eb7SJason Gunthorpe 180095531f8SJavier Martinez Canillas rc = tpm_validate_command(chip, space, buf, bufsiz); 181095531f8SJavier Martinez Canillas if (rc == -EINVAL) 182095531f8SJavier Martinez Canillas return rc; 183095531f8SJavier Martinez Canillas /* 184095531f8SJavier Martinez Canillas * If the command is not implemented by the TPM, synthesize a 185095531f8SJavier Martinez Canillas * response with a TPM2_RC_COMMAND_CODE return for user-space. 186095531f8SJavier Martinez Canillas */ 187095531f8SJavier Martinez Canillas if (rc == -EOPNOTSUPP) { 188095531f8SJavier Martinez Canillas header->length = cpu_to_be32(sizeof(*header)); 189095531f8SJavier Martinez Canillas header->tag = cpu_to_be16(TPM2_ST_NO_SESSIONS); 190095531f8SJavier Martinez Canillas header->return_code = cpu_to_be32(TPM2_RC_COMMAND_CODE | 191095531f8SJavier Martinez Canillas TSS2_RESMGR_TPM_RC_LAYER); 19236a11029SRicardo Schwarzmeier return sizeof(*header); 193095531f8SJavier Martinez Canillas } 194ebfd7532SJarkko Sakkinen 1959deb0eb7SJason Gunthorpe if (bufsiz > TPM_BUFSIZE) 1969deb0eb7SJason Gunthorpe bufsiz = TPM_BUFSIZE; 1979deb0eb7SJason Gunthorpe 1989deb0eb7SJason Gunthorpe count = be32_to_cpu(*((__be32 *) (buf + 2))); 1999deb0eb7SJason Gunthorpe ordinal = be32_to_cpu(*((__be32 *) (buf + 6))); 2009deb0eb7SJason Gunthorpe if (count == 0) 2019deb0eb7SJason Gunthorpe return -ENODATA; 2029deb0eb7SJason Gunthorpe if (count > bufsiz) { 2038cfffc9dSJason Gunthorpe dev_err(&chip->dev, 2049deb0eb7SJason Gunthorpe "invalid count value %x %zx\n", count, bufsiz); 2059deb0eb7SJason Gunthorpe return -E2BIG; 2069deb0eb7SJason Gunthorpe } 2079deb0eb7SJason Gunthorpe 20858bac8ccSJarkko Sakkinen if (!(flags & TPM_TRANSMIT_UNLOCKED) && !(flags & TPM_TRANSMIT_NESTED)) 2099deb0eb7SJason Gunthorpe mutex_lock(&chip->tpm_mutex); 2109deb0eb7SJason Gunthorpe 211b3e958ceSAzhar Shaikh if (chip->ops->clk_enable != NULL) 212b3e958ceSAzhar Shaikh chip->ops->clk_enable(chip, true); 213b3e958ceSAzhar Shaikh 214877c57d0SJarkko Sakkinen /* Store the decision as chip->locality will be changed. */ 215877c57d0SJarkko Sakkinen need_locality = chip->locality == -1; 216877c57d0SJarkko Sakkinen 217627448e8STomas Winkler if (need_locality) { 218627448e8STomas Winkler rc = tpm_request_locality(chip, flags); 219877c57d0SJarkko Sakkinen if (rc < 0) 220877c57d0SJarkko Sakkinen goto out_no_locality; 221877c57d0SJarkko Sakkinen } 222877c57d0SJarkko Sakkinen 223627448e8STomas Winkler rc = tpm_cmd_ready(chip, flags); 224627448e8STomas Winkler if (rc) 225627448e8STomas Winkler goto out; 226888d867dSTomas Winkler 227745b361eSJarkko Sakkinen rc = tpm2_prepare_space(chip, space, ordinal, buf); 228745b361eSJarkko Sakkinen if (rc) 229745b361eSJarkko Sakkinen goto out; 230745b361eSJarkko Sakkinen 23162c09e12SWinkler, Tomas rc = chip->ops->send(chip, buf, count); 2329deb0eb7SJason Gunthorpe if (rc < 0) { 233402149c6SStefan Berger if (rc != -EPIPE) 2348cfffc9dSJason Gunthorpe dev_err(&chip->dev, 235402149c6SStefan Berger "%s: tpm_send: error %d\n", __func__, rc); 2369deb0eb7SJason Gunthorpe goto out; 2379deb0eb7SJason Gunthorpe } 2389deb0eb7SJason Gunthorpe 239570a3609SChristophe Ricard if (chip->flags & TPM_CHIP_FLAG_IRQ) 2409deb0eb7SJason Gunthorpe goto out_recv; 2419deb0eb7SJason Gunthorpe 242*d856c00fSTomas Winkler stop = jiffies + tpm_calc_ordinal_duration(chip, ordinal); 2439deb0eb7SJason Gunthorpe do { 2445f82e9f0SJason Gunthorpe u8 status = chip->ops->status(chip); 2455f82e9f0SJason Gunthorpe if ((status & chip->ops->req_complete_mask) == 2465f82e9f0SJason Gunthorpe chip->ops->req_complete_val) 2479deb0eb7SJason Gunthorpe goto out_recv; 2489deb0eb7SJason Gunthorpe 2495f82e9f0SJason Gunthorpe if (chip->ops->req_canceled(chip, status)) { 2508cfffc9dSJason Gunthorpe dev_err(&chip->dev, "Operation Canceled\n"); 2519deb0eb7SJason Gunthorpe rc = -ECANCELED; 2529deb0eb7SJason Gunthorpe goto out; 2539deb0eb7SJason Gunthorpe } 2549deb0eb7SJason Gunthorpe 25559f5a6b0SNayna Jain tpm_msleep(TPM_TIMEOUT_POLL); 2569deb0eb7SJason Gunthorpe rmb(); 2579deb0eb7SJason Gunthorpe } while (time_before(jiffies, stop)); 2589deb0eb7SJason Gunthorpe 2595f82e9f0SJason Gunthorpe chip->ops->cancel(chip); 2608cfffc9dSJason Gunthorpe dev_err(&chip->dev, "Operation Timed out\n"); 2619deb0eb7SJason Gunthorpe rc = -ETIME; 2629deb0eb7SJason Gunthorpe goto out; 2639deb0eb7SJason Gunthorpe 2649deb0eb7SJason Gunthorpe out_recv: 26562c09e12SWinkler, Tomas len = chip->ops->recv(chip, buf, bufsiz); 266745b361eSJarkko Sakkinen if (len < 0) { 267745b361eSJarkko Sakkinen rc = len; 2688cfffc9dSJason Gunthorpe dev_err(&chip->dev, 269745b361eSJarkko Sakkinen "tpm_transmit: tpm_recv: error %d\n", rc); 270a147918eSJarkko Sakkinen goto out; 271745b361eSJarkko Sakkinen } else if (len < TPM_HEADER_SIZE) { 272a147918eSJarkko Sakkinen rc = -EFAULT; 273a147918eSJarkko Sakkinen goto out; 274a147918eSJarkko Sakkinen } 275a147918eSJarkko Sakkinen 276745b361eSJarkko Sakkinen if (len != be32_to_cpu(header->length)) { 277745b361eSJarkko Sakkinen rc = -EFAULT; 278a147918eSJarkko Sakkinen goto out; 279745b361eSJarkko Sakkinen } 280745b361eSJarkko Sakkinen 281745b361eSJarkko Sakkinen rc = tpm2_commit_space(chip, space, ordinal, buf, &len); 282627448e8STomas Winkler if (rc) 283627448e8STomas Winkler dev_err(&chip->dev, "tpm2_commit_space: error %d\n", rc); 284a147918eSJarkko Sakkinen 2859deb0eb7SJason Gunthorpe out: 286627448e8STomas Winkler rc = tpm_go_idle(chip, flags); 287627448e8STomas Winkler if (rc) 288627448e8STomas Winkler goto out; 289888d867dSTomas Winkler 290888d867dSTomas Winkler if (need_locality) 291627448e8STomas Winkler tpm_relinquish_locality(chip, flags); 292888d867dSTomas Winkler 293877c57d0SJarkko Sakkinen out_no_locality: 294b3e958ceSAzhar Shaikh if (chip->ops->clk_enable != NULL) 295b3e958ceSAzhar Shaikh chip->ops->clk_enable(chip, false); 296b3e958ceSAzhar Shaikh 29758bac8ccSJarkko Sakkinen if (!(flags & TPM_TRANSMIT_UNLOCKED) && !(flags & TPM_TRANSMIT_NESTED)) 2989deb0eb7SJason Gunthorpe mutex_unlock(&chip->tpm_mutex); 299745b361eSJarkko Sakkinen return rc ? rc : len; 3009deb0eb7SJason Gunthorpe } 3019deb0eb7SJason Gunthorpe 302f865c196SWinkler, Tomas /** 303e2fb992dSJames Bottomley * tpm_transmit - Internal kernel interface to transmit TPM commands. 304e2fb992dSJames Bottomley * 305e2fb992dSJames Bottomley * @chip: TPM chip to use 306e2fb992dSJames Bottomley * @space: tpm space 307e2fb992dSJames Bottomley * @buf: TPM command buffer 308e2fb992dSJames Bottomley * @bufsiz: length of the TPM command buffer 309e2fb992dSJames Bottomley * @flags: tpm transmit flags - bitmap 310e2fb992dSJames Bottomley * 311e2fb992dSJames Bottomley * A wrapper around tpm_try_transmit that handles TPM2_RC_RETRY 312e2fb992dSJames Bottomley * returns from the TPM and retransmits the command after a delay up 313e2fb992dSJames Bottomley * to a maximum wait of TPM2_DURATION_LONG. 314e2fb992dSJames Bottomley * 315e2fb992dSJames Bottomley * Note: TPM1 never returns TPM2_RC_RETRY so the retry logic is TPM2 316e2fb992dSJames Bottomley * only 317e2fb992dSJames Bottomley * 318e2fb992dSJames Bottomley * Return: 319e2fb992dSJames Bottomley * the length of the return when the operation is successful. 320e2fb992dSJames Bottomley * A negative number for system errors (errno). 321e2fb992dSJames Bottomley */ 322e2fb992dSJames Bottomley ssize_t tpm_transmit(struct tpm_chip *chip, struct tpm_space *space, 323e2fb992dSJames Bottomley u8 *buf, size_t bufsiz, unsigned int flags) 324e2fb992dSJames Bottomley { 325e2fb992dSJames Bottomley struct tpm_output_header *header = (struct tpm_output_header *)buf; 326e2fb992dSJames Bottomley /* space for header and handles */ 327e2fb992dSJames Bottomley u8 save[TPM_HEADER_SIZE + 3*sizeof(u32)]; 328e2fb992dSJames Bottomley unsigned int delay_msec = TPM2_DURATION_SHORT; 329e2fb992dSJames Bottomley u32 rc = 0; 330e2fb992dSJames Bottomley ssize_t ret; 331e2fb992dSJames Bottomley const size_t save_size = min(space ? sizeof(save) : TPM_HEADER_SIZE, 332e2fb992dSJames Bottomley bufsiz); 3332be8ffedSJames Bottomley /* the command code is where the return code will be */ 3342be8ffedSJames Bottomley u32 cc = be32_to_cpu(header->return_code); 335e2fb992dSJames Bottomley 336e2fb992dSJames Bottomley /* 337e2fb992dSJames Bottomley * Subtlety here: if we have a space, the handles will be 338e2fb992dSJames Bottomley * transformed, so when we restore the header we also have to 339e2fb992dSJames Bottomley * restore the handles. 340e2fb992dSJames Bottomley */ 341e2fb992dSJames Bottomley memcpy(save, buf, save_size); 342e2fb992dSJames Bottomley 343e2fb992dSJames Bottomley for (;;) { 344e2fb992dSJames Bottomley ret = tpm_try_transmit(chip, space, buf, bufsiz, flags); 345e2fb992dSJames Bottomley if (ret < 0) 346e2fb992dSJames Bottomley break; 347e2fb992dSJames Bottomley rc = be32_to_cpu(header->return_code); 3482be8ffedSJames Bottomley if (rc != TPM2_RC_RETRY && rc != TPM2_RC_TESTING) 3492be8ffedSJames Bottomley break; 3502be8ffedSJames Bottomley /* 3512be8ffedSJames Bottomley * return immediately if self test returns test 3522be8ffedSJames Bottomley * still running to shorten boot time. 3532be8ffedSJames Bottomley */ 3542be8ffedSJames Bottomley if (rc == TPM2_RC_TESTING && cc == TPM2_CC_SELF_TEST) 355e2fb992dSJames Bottomley break; 35692980756SNayna Jain 357e2fb992dSJames Bottomley if (delay_msec > TPM2_DURATION_LONG) { 3582be8ffedSJames Bottomley if (rc == TPM2_RC_RETRY) 3592be8ffedSJames Bottomley dev_err(&chip->dev, "in retry loop\n"); 3602be8ffedSJames Bottomley else 3612be8ffedSJames Bottomley dev_err(&chip->dev, 3622be8ffedSJames Bottomley "self test is still running\n"); 363e2fb992dSJames Bottomley break; 364e2fb992dSJames Bottomley } 365e2fb992dSJames Bottomley tpm_msleep(delay_msec); 36692980756SNayna Jain delay_msec *= 2; 367e2fb992dSJames Bottomley memcpy(buf, save, save_size); 368e2fb992dSJames Bottomley } 369e2fb992dSJames Bottomley return ret; 370e2fb992dSJames Bottomley } 371e2fb992dSJames Bottomley /** 37265520d46SWinkler, Tomas * tpm_transmit_cmd - send a tpm command to the device 373f865c196SWinkler, Tomas * The function extracts tpm out header return code 374f865c196SWinkler, Tomas * 375f865c196SWinkler, Tomas * @chip: TPM chip to use 37665520d46SWinkler, Tomas * @space: tpm space 377c659af78SStefan Berger * @buf: TPM command buffer 378c659af78SStefan Berger * @bufsiz: length of the buffer 379c659af78SStefan Berger * @min_rsp_body_length: minimum expected length of response body 380f865c196SWinkler, Tomas * @flags: tpm transmit flags - bitmap 381f865c196SWinkler, Tomas * @desc: command description used in the error message 382f865c196SWinkler, Tomas * 383f865c196SWinkler, Tomas * Return: 384f865c196SWinkler, Tomas * 0 when the operation is successful. 385f865c196SWinkler, Tomas * A negative number for system errors (errno). 386f865c196SWinkler, Tomas * A positive number for a TPM error. 387f865c196SWinkler, Tomas */ 388745b361eSJarkko Sakkinen ssize_t tpm_transmit_cmd(struct tpm_chip *chip, struct tpm_space *space, 38962c09e12SWinkler, Tomas void *buf, size_t bufsiz, 390745b361eSJarkko Sakkinen size_t min_rsp_body_length, unsigned int flags, 391745b361eSJarkko Sakkinen const char *desc) 3929deb0eb7SJason Gunthorpe { 393a147918eSJarkko Sakkinen const struct tpm_output_header *header = buf; 3949deb0eb7SJason Gunthorpe int err; 395c659af78SStefan Berger ssize_t len; 3969deb0eb7SJason Gunthorpe 39762c09e12SWinkler, Tomas len = tpm_transmit(chip, space, buf, bufsiz, flags); 3989deb0eb7SJason Gunthorpe if (len < 0) 3999deb0eb7SJason Gunthorpe return len; 40087155b73SJarkko Sakkinen 40187155b73SJarkko Sakkinen err = be32_to_cpu(header->return_code); 4020d6d0d62SJavier Martinez Canillas if (err != 0 && err != TPM_ERR_DISABLED && err != TPM_ERR_DEACTIVATED 4030d6d0d62SJavier Martinez Canillas && desc) 4048cfffc9dSJason Gunthorpe dev_err(&chip->dev, "A TPM error (%d) occurred %s\n", err, 40571ed848fSJarkko Sakkinen desc); 406c659af78SStefan Berger if (err) 4079deb0eb7SJason Gunthorpe return err; 408c659af78SStefan Berger 409c659af78SStefan Berger if (len < min_rsp_body_length + TPM_HEADER_SIZE) 410c659af78SStefan Berger return -EFAULT; 411c659af78SStefan Berger 412c659af78SStefan Berger return 0; 4139deb0eb7SJason Gunthorpe } 414be4c9acfSStefan Berger EXPORT_SYMBOL_GPL(tpm_transmit_cmd); 4159deb0eb7SJason Gunthorpe 41619cbe4f6SJarkko Sakkinen #define TPM_ORD_STARTUP 153 41719cbe4f6SJarkko Sakkinen #define TPM_ST_CLEAR 1 41819cbe4f6SJarkko Sakkinen 41919cbe4f6SJarkko Sakkinen /** 42019cbe4f6SJarkko Sakkinen * tpm_startup - turn on the TPM 42119cbe4f6SJarkko Sakkinen * @chip: TPM chip to use 42219cbe4f6SJarkko Sakkinen * 42319cbe4f6SJarkko Sakkinen * Normally the firmware should start the TPM. This function is provided as a 42419cbe4f6SJarkko Sakkinen * workaround if this does not happen. A legal case for this could be for 42519cbe4f6SJarkko Sakkinen * example when a TPM emulator is used. 42619cbe4f6SJarkko Sakkinen * 42719cbe4f6SJarkko Sakkinen * Return: same as tpm_transmit_cmd() 42819cbe4f6SJarkko Sakkinen */ 42919cbe4f6SJarkko Sakkinen int tpm_startup(struct tpm_chip *chip) 43019cbe4f6SJarkko Sakkinen { 43119cbe4f6SJarkko Sakkinen struct tpm_buf buf; 43219cbe4f6SJarkko Sakkinen int rc; 43319cbe4f6SJarkko Sakkinen 43419cbe4f6SJarkko Sakkinen dev_info(&chip->dev, "starting up the TPM manually\n"); 43519cbe4f6SJarkko Sakkinen 43619cbe4f6SJarkko Sakkinen if (chip->flags & TPM_CHIP_FLAG_TPM2) { 43719cbe4f6SJarkko Sakkinen rc = tpm_buf_init(&buf, TPM2_ST_NO_SESSIONS, TPM2_CC_STARTUP); 43819cbe4f6SJarkko Sakkinen if (rc < 0) 43919cbe4f6SJarkko Sakkinen return rc; 44019cbe4f6SJarkko Sakkinen 44119cbe4f6SJarkko Sakkinen tpm_buf_append_u16(&buf, TPM2_SU_CLEAR); 44219cbe4f6SJarkko Sakkinen } else { 44319cbe4f6SJarkko Sakkinen rc = tpm_buf_init(&buf, TPM_TAG_RQU_COMMAND, TPM_ORD_STARTUP); 44419cbe4f6SJarkko Sakkinen if (rc < 0) 44519cbe4f6SJarkko Sakkinen return rc; 44619cbe4f6SJarkko Sakkinen 44719cbe4f6SJarkko Sakkinen tpm_buf_append_u16(&buf, TPM_ST_CLEAR); 44819cbe4f6SJarkko Sakkinen } 44919cbe4f6SJarkko Sakkinen 45019cbe4f6SJarkko Sakkinen rc = tpm_transmit_cmd(chip, NULL, buf.data, PAGE_SIZE, 0, 0, 45119cbe4f6SJarkko Sakkinen "attempting to start the TPM"); 45219cbe4f6SJarkko Sakkinen 45319cbe4f6SJarkko Sakkinen tpm_buf_destroy(&buf); 45419cbe4f6SJarkko Sakkinen return rc; 45519cbe4f6SJarkko Sakkinen } 45619cbe4f6SJarkko Sakkinen 457f865c196SWinkler, Tomas #define TPM_DIGEST_SIZE 20 458f865c196SWinkler, Tomas #define TPM_RET_CODE_IDX 6 4599deb0eb7SJason Gunthorpe #define TPM_INTERNAL_RESULT_SIZE 200 460a69faebfSRoberto Sassu #define TPM_ORD_GET_CAP 101 461a69faebfSRoberto Sassu #define TPM_ORD_GET_RANDOM 70 4629deb0eb7SJason Gunthorpe 4639deb0eb7SJason Gunthorpe static const struct tpm_input_header tpm_getcap_header = { 46406e93279SRoberto Sassu .tag = cpu_to_be16(TPM_TAG_RQU_COMMAND), 4659deb0eb7SJason Gunthorpe .length = cpu_to_be32(22), 466a69faebfSRoberto Sassu .ordinal = cpu_to_be32(TPM_ORD_GET_CAP) 4679deb0eb7SJason Gunthorpe }; 4689deb0eb7SJason Gunthorpe 46984fda152SJarkko Sakkinen ssize_t tpm_getcap(struct tpm_chip *chip, u32 subcap_id, cap_t *cap, 470c659af78SStefan Berger const char *desc, size_t min_cap_length) 4719deb0eb7SJason Gunthorpe { 472124bdcf4SJarkko Sakkinen struct tpm_buf buf; 4739deb0eb7SJason Gunthorpe int rc; 4749deb0eb7SJason Gunthorpe 475124bdcf4SJarkko Sakkinen rc = tpm_buf_init(&buf, TPM_TAG_RQU_COMMAND, TPM_ORD_GET_CAP); 476124bdcf4SJarkko Sakkinen if (rc) 477124bdcf4SJarkko Sakkinen return rc; 478124bdcf4SJarkko Sakkinen 47984fda152SJarkko Sakkinen if (subcap_id == TPM_CAP_VERSION_1_1 || 48084fda152SJarkko Sakkinen subcap_id == TPM_CAP_VERSION_1_2) { 481124bdcf4SJarkko Sakkinen tpm_buf_append_u32(&buf, subcap_id); 482124bdcf4SJarkko Sakkinen tpm_buf_append_u32(&buf, 0); 4839deb0eb7SJason Gunthorpe } else { 4849deb0eb7SJason Gunthorpe if (subcap_id == TPM_CAP_FLAG_PERM || 4859deb0eb7SJason Gunthorpe subcap_id == TPM_CAP_FLAG_VOL) 486124bdcf4SJarkko Sakkinen tpm_buf_append_u32(&buf, TPM_CAP_FLAG); 4879deb0eb7SJason Gunthorpe else 488124bdcf4SJarkko Sakkinen tpm_buf_append_u32(&buf, TPM_CAP_PROP); 489124bdcf4SJarkko Sakkinen 490124bdcf4SJarkko Sakkinen tpm_buf_append_u32(&buf, 4); 491124bdcf4SJarkko Sakkinen tpm_buf_append_u32(&buf, subcap_id); 4929deb0eb7SJason Gunthorpe } 493124bdcf4SJarkko Sakkinen rc = tpm_transmit_cmd(chip, NULL, buf.data, PAGE_SIZE, 494c659af78SStefan Berger min_cap_length, 0, desc); 4959deb0eb7SJason Gunthorpe if (!rc) 496124bdcf4SJarkko Sakkinen *cap = *(cap_t *)&buf.data[TPM_HEADER_SIZE + 4]; 497124bdcf4SJarkko Sakkinen 498124bdcf4SJarkko Sakkinen tpm_buf_destroy(&buf); 4999deb0eb7SJason Gunthorpe return rc; 5009deb0eb7SJason Gunthorpe } 501eb5854e7SJarkko Sakkinen EXPORT_SYMBOL_GPL(tpm_getcap); 5029deb0eb7SJason Gunthorpe 5039deb0eb7SJason Gunthorpe int tpm_get_timeouts(struct tpm_chip *chip) 5049deb0eb7SJason Gunthorpe { 505aaa6f7f6SEd Swierk cap_t cap; 5061d70fe9dSMaciej S. Szmigiero unsigned long timeout_old[4], timeout_chip[4], timeout_eff[4]; 5079deb0eb7SJason Gunthorpe ssize_t rc; 5089deb0eb7SJason Gunthorpe 509d1d253cfSJason Gunthorpe if (chip->flags & TPM_CHIP_FLAG_HAVE_TIMEOUTS) 510d1d253cfSJason Gunthorpe return 0; 511d1d253cfSJason Gunthorpe 51225112048SJason Gunthorpe if (chip->flags & TPM_CHIP_FLAG_TPM2) { 51325112048SJason Gunthorpe /* Fixed timeouts for TPM2 */ 514af782f33SChristophe Ricard chip->timeout_a = msecs_to_jiffies(TPM2_TIMEOUT_A); 515af782f33SChristophe Ricard chip->timeout_b = msecs_to_jiffies(TPM2_TIMEOUT_B); 516af782f33SChristophe Ricard chip->timeout_c = msecs_to_jiffies(TPM2_TIMEOUT_C); 517af782f33SChristophe Ricard chip->timeout_d = msecs_to_jiffies(TPM2_TIMEOUT_D); 518af782f33SChristophe Ricard chip->duration[TPM_SHORT] = 51925112048SJason Gunthorpe msecs_to_jiffies(TPM2_DURATION_SHORT); 520af782f33SChristophe Ricard chip->duration[TPM_MEDIUM] = 52125112048SJason Gunthorpe msecs_to_jiffies(TPM2_DURATION_MEDIUM); 522af782f33SChristophe Ricard chip->duration[TPM_LONG] = 52325112048SJason Gunthorpe msecs_to_jiffies(TPM2_DURATION_LONG); 524076d3564STomas Winkler chip->duration[TPM_LONG_LONG] = 525076d3564STomas Winkler msecs_to_jiffies(TPM2_DURATION_LONG_LONG); 526d1d253cfSJason Gunthorpe 527d1d253cfSJason Gunthorpe chip->flags |= TPM_CHIP_FLAG_HAVE_TIMEOUTS; 52825112048SJason Gunthorpe return 0; 52925112048SJason Gunthorpe } 53025112048SJason Gunthorpe 531c659af78SStefan Berger rc = tpm_getcap(chip, TPM_CAP_PROP_TIS_TIMEOUT, &cap, NULL, 532c659af78SStefan Berger sizeof(cap.timeout)); 5339deb0eb7SJason Gunthorpe if (rc == TPM_ERR_INVALID_POSTINIT) { 53419cbe4f6SJarkko Sakkinen if (tpm_startup(chip)) 5359deb0eb7SJason Gunthorpe return rc; 5369deb0eb7SJason Gunthorpe 537aaa6f7f6SEd Swierk rc = tpm_getcap(chip, TPM_CAP_PROP_TIS_TIMEOUT, &cap, 538c659af78SStefan Berger "attempting to determine the timeouts", 539c659af78SStefan Berger sizeof(cap.timeout)); 5409deb0eb7SJason Gunthorpe } 541c659af78SStefan Berger 54262bfdacbSJason Gunthorpe if (rc) { 54362bfdacbSJason Gunthorpe dev_err(&chip->dev, 54462bfdacbSJason Gunthorpe "A TPM error (%zd) occurred attempting to determine the timeouts\n", 54562bfdacbSJason Gunthorpe rc); 546aaa6f7f6SEd Swierk return rc; 54762bfdacbSJason Gunthorpe } 5489deb0eb7SJason Gunthorpe 5491d70fe9dSMaciej S. Szmigiero timeout_old[0] = jiffies_to_usecs(chip->timeout_a); 5501d70fe9dSMaciej S. Szmigiero timeout_old[1] = jiffies_to_usecs(chip->timeout_b); 5511d70fe9dSMaciej S. Szmigiero timeout_old[2] = jiffies_to_usecs(chip->timeout_c); 5521d70fe9dSMaciej S. Szmigiero timeout_old[3] = jiffies_to_usecs(chip->timeout_d); 5531d70fe9dSMaciej S. Szmigiero timeout_chip[0] = be32_to_cpu(cap.timeout.a); 5541d70fe9dSMaciej S. Szmigiero timeout_chip[1] = be32_to_cpu(cap.timeout.b); 5551d70fe9dSMaciej S. Szmigiero timeout_chip[2] = be32_to_cpu(cap.timeout.c); 5561d70fe9dSMaciej S. Szmigiero timeout_chip[3] = be32_to_cpu(cap.timeout.d); 5571d70fe9dSMaciej S. Szmigiero memcpy(timeout_eff, timeout_chip, sizeof(timeout_eff)); 5588e54caf4SJason Gunthorpe 5598e54caf4SJason Gunthorpe /* 5608e54caf4SJason Gunthorpe * Provide ability for vendor overrides of timeout values in case 5618e54caf4SJason Gunthorpe * of misreporting. 5628e54caf4SJason Gunthorpe */ 5638e54caf4SJason Gunthorpe if (chip->ops->update_timeouts != NULL) 564af782f33SChristophe Ricard chip->timeout_adjusted = 5651d70fe9dSMaciej S. Szmigiero chip->ops->update_timeouts(chip, timeout_eff); 5668e54caf4SJason Gunthorpe 567af782f33SChristophe Ricard if (!chip->timeout_adjusted) { 5681d70fe9dSMaciej S. Szmigiero /* Restore default if chip reported 0 */ 5698e54caf4SJason Gunthorpe int i; 5708e54caf4SJason Gunthorpe 5711d70fe9dSMaciej S. Szmigiero for (i = 0; i < ARRAY_SIZE(timeout_eff); i++) { 5721d70fe9dSMaciej S. Szmigiero if (timeout_eff[i]) 5731d70fe9dSMaciej S. Szmigiero continue; 5741d70fe9dSMaciej S. Szmigiero 5751d70fe9dSMaciej S. Szmigiero timeout_eff[i] = timeout_old[i]; 5761d70fe9dSMaciej S. Szmigiero chip->timeout_adjusted = true; 5771d70fe9dSMaciej S. Szmigiero } 5781d70fe9dSMaciej S. Szmigiero 5791d70fe9dSMaciej S. Szmigiero if (timeout_eff[0] != 0 && timeout_eff[0] < 1000) { 5809deb0eb7SJason Gunthorpe /* timeouts in msec rather usec */ 5811d70fe9dSMaciej S. Szmigiero for (i = 0; i != ARRAY_SIZE(timeout_eff); i++) 5821d70fe9dSMaciej S. Szmigiero timeout_eff[i] *= 1000; 583af782f33SChristophe Ricard chip->timeout_adjusted = true; 5849deb0eb7SJason Gunthorpe } 5858e54caf4SJason Gunthorpe } 5868e54caf4SJason Gunthorpe 5878e54caf4SJason Gunthorpe /* Report adjusted timeouts */ 588af782f33SChristophe Ricard if (chip->timeout_adjusted) { 5898cfffc9dSJason Gunthorpe dev_info(&chip->dev, 5908e54caf4SJason Gunthorpe HW_ERR "Adjusting reported timeouts: A %lu->%luus B %lu->%luus C %lu->%luus D %lu->%luus\n", 5911d70fe9dSMaciej S. Szmigiero timeout_chip[0], timeout_eff[0], 5921d70fe9dSMaciej S. Szmigiero timeout_chip[1], timeout_eff[1], 5931d70fe9dSMaciej S. Szmigiero timeout_chip[2], timeout_eff[2], 5941d70fe9dSMaciej S. Szmigiero timeout_chip[3], timeout_eff[3]); 5958e54caf4SJason Gunthorpe } 5968e54caf4SJason Gunthorpe 5971d70fe9dSMaciej S. Szmigiero chip->timeout_a = usecs_to_jiffies(timeout_eff[0]); 5981d70fe9dSMaciej S. Szmigiero chip->timeout_b = usecs_to_jiffies(timeout_eff[1]); 5991d70fe9dSMaciej S. Szmigiero chip->timeout_c = usecs_to_jiffies(timeout_eff[2]); 6001d70fe9dSMaciej S. Szmigiero chip->timeout_d = usecs_to_jiffies(timeout_eff[3]); 6019deb0eb7SJason Gunthorpe 602aaa6f7f6SEd Swierk rc = tpm_getcap(chip, TPM_CAP_PROP_TIS_DURATION, &cap, 603c659af78SStefan Berger "attempting to determine the durations", 604c659af78SStefan Berger sizeof(cap.duration)); 6059deb0eb7SJason Gunthorpe if (rc) 6069deb0eb7SJason Gunthorpe return rc; 6079deb0eb7SJason Gunthorpe 608af782f33SChristophe Ricard chip->duration[TPM_SHORT] = 609aaa6f7f6SEd Swierk usecs_to_jiffies(be32_to_cpu(cap.duration.tpm_short)); 610af782f33SChristophe Ricard chip->duration[TPM_MEDIUM] = 611aaa6f7f6SEd Swierk usecs_to_jiffies(be32_to_cpu(cap.duration.tpm_medium)); 612af782f33SChristophe Ricard chip->duration[TPM_LONG] = 613aaa6f7f6SEd Swierk usecs_to_jiffies(be32_to_cpu(cap.duration.tpm_long)); 614076d3564STomas Winkler chip->duration[TPM_LONG_LONG] = 0; /* not used under 1.2 */ 6159deb0eb7SJason Gunthorpe 6169deb0eb7SJason Gunthorpe /* The Broadcom BCM0102 chipset in a Dell Latitude D820 gets the above 6179deb0eb7SJason Gunthorpe * value wrong and apparently reports msecs rather than usecs. So we 6189deb0eb7SJason Gunthorpe * fix up the resulting too-small TPM_SHORT value to make things work. 6199deb0eb7SJason Gunthorpe * We also scale the TPM_MEDIUM and -_LONG values by 1000. 6209deb0eb7SJason Gunthorpe */ 621af782f33SChristophe Ricard if (chip->duration[TPM_SHORT] < (HZ / 100)) { 622af782f33SChristophe Ricard chip->duration[TPM_SHORT] = HZ; 623af782f33SChristophe Ricard chip->duration[TPM_MEDIUM] *= 1000; 624af782f33SChristophe Ricard chip->duration[TPM_LONG] *= 1000; 625af782f33SChristophe Ricard chip->duration_adjusted = true; 6268cfffc9dSJason Gunthorpe dev_info(&chip->dev, "Adjusting TPM timeout parameters."); 6279deb0eb7SJason Gunthorpe } 628d1d253cfSJason Gunthorpe 629d1d253cfSJason Gunthorpe chip->flags |= TPM_CHIP_FLAG_HAVE_TIMEOUTS; 6309deb0eb7SJason Gunthorpe return 0; 6319deb0eb7SJason Gunthorpe } 6329deb0eb7SJason Gunthorpe EXPORT_SYMBOL_GPL(tpm_get_timeouts); 6339deb0eb7SJason Gunthorpe 6349deb0eb7SJason Gunthorpe #define TPM_ORD_CONTINUE_SELFTEST 83 6359deb0eb7SJason Gunthorpe #define CONTINUE_SELFTEST_RESULT_SIZE 10 6369deb0eb7SJason Gunthorpe 6370014777fSJulia Lawall static const struct tpm_input_header continue_selftest_header = { 63806e93279SRoberto Sassu .tag = cpu_to_be16(TPM_TAG_RQU_COMMAND), 6399deb0eb7SJason Gunthorpe .length = cpu_to_be32(10), 6409deb0eb7SJason Gunthorpe .ordinal = cpu_to_be32(TPM_ORD_CONTINUE_SELFTEST), 6419deb0eb7SJason Gunthorpe }; 6429deb0eb7SJason Gunthorpe 6439deb0eb7SJason Gunthorpe /** 6449deb0eb7SJason Gunthorpe * tpm_continue_selftest -- run TPM's selftest 6459deb0eb7SJason Gunthorpe * @chip: TPM chip to use 6469deb0eb7SJason Gunthorpe * 6479deb0eb7SJason Gunthorpe * Returns 0 on success, < 0 in case of fatal error or a value > 0 representing 6489deb0eb7SJason Gunthorpe * a TPM error code. 6499deb0eb7SJason Gunthorpe */ 6509deb0eb7SJason Gunthorpe static int tpm_continue_selftest(struct tpm_chip *chip) 6519deb0eb7SJason Gunthorpe { 6529deb0eb7SJason Gunthorpe int rc; 6539deb0eb7SJason Gunthorpe struct tpm_cmd_t cmd; 6549deb0eb7SJason Gunthorpe 6559deb0eb7SJason Gunthorpe cmd.header.in = continue_selftest_header; 656745b361eSJarkko Sakkinen rc = tpm_transmit_cmd(chip, NULL, &cmd, CONTINUE_SELFTEST_RESULT_SIZE, 657745b361eSJarkko Sakkinen 0, 0, "continue selftest"); 6589deb0eb7SJason Gunthorpe return rc; 6599deb0eb7SJason Gunthorpe } 6609deb0eb7SJason Gunthorpe 661a69faebfSRoberto Sassu #define TPM_ORDINAL_PCRREAD 21 6629deb0eb7SJason Gunthorpe #define READ_PCR_RESULT_SIZE 30 663c659af78SStefan Berger #define READ_PCR_RESULT_BODY_SIZE 20 6640014777fSJulia Lawall static const struct tpm_input_header pcrread_header = { 66506e93279SRoberto Sassu .tag = cpu_to_be16(TPM_TAG_RQU_COMMAND), 6669deb0eb7SJason Gunthorpe .length = cpu_to_be32(14), 667a69faebfSRoberto Sassu .ordinal = cpu_to_be32(TPM_ORDINAL_PCRREAD) 6689deb0eb7SJason Gunthorpe }; 6699deb0eb7SJason Gunthorpe 670000a07b0SJason Gunthorpe int tpm_pcr_read_dev(struct tpm_chip *chip, int pcr_idx, u8 *res_buf) 6719deb0eb7SJason Gunthorpe { 6729deb0eb7SJason Gunthorpe int rc; 6739deb0eb7SJason Gunthorpe struct tpm_cmd_t cmd; 6749deb0eb7SJason Gunthorpe 6759deb0eb7SJason Gunthorpe cmd.header.in = pcrread_header; 6769deb0eb7SJason Gunthorpe cmd.params.pcrread_in.pcr_idx = cpu_to_be32(pcr_idx); 677745b361eSJarkko Sakkinen rc = tpm_transmit_cmd(chip, NULL, &cmd, READ_PCR_RESULT_SIZE, 678c659af78SStefan Berger READ_PCR_RESULT_BODY_SIZE, 0, 6799deb0eb7SJason Gunthorpe "attempting to read a pcr value"); 6809deb0eb7SJason Gunthorpe 6819deb0eb7SJason Gunthorpe if (rc == 0) 6829deb0eb7SJason Gunthorpe memcpy(res_buf, cmd.params.pcrread_out.pcr_result, 6839deb0eb7SJason Gunthorpe TPM_DIGEST_SIZE); 6849deb0eb7SJason Gunthorpe return rc; 6859deb0eb7SJason Gunthorpe } 6869deb0eb7SJason Gunthorpe 6879deb0eb7SJason Gunthorpe /** 688aad887f6SJarkko Sakkinen * tpm_is_tpm2 - do we a have a TPM2 chip? 689aad887f6SJarkko Sakkinen * @chip: a &struct tpm_chip instance, %NULL for the default chip 690954650efSJarkko Sakkinen * 691aad887f6SJarkko Sakkinen * Return: 692aad887f6SJarkko Sakkinen * 1 if we have a TPM2 chip. 693aad887f6SJarkko Sakkinen * 0 if we don't have a TPM2 chip. 694aad887f6SJarkko Sakkinen * A negative number for system errors (errno). 695954650efSJarkko Sakkinen */ 696aad887f6SJarkko Sakkinen int tpm_is_tpm2(struct tpm_chip *chip) 697954650efSJarkko Sakkinen { 698954650efSJarkko Sakkinen int rc; 699954650efSJarkko Sakkinen 700fc1d52b7SStefan Berger chip = tpm_find_get_ops(chip); 701aad887f6SJarkko Sakkinen if (!chip) 702954650efSJarkko Sakkinen return -ENODEV; 703954650efSJarkko Sakkinen 704954650efSJarkko Sakkinen rc = (chip->flags & TPM_CHIP_FLAG_TPM2) != 0; 705954650efSJarkko Sakkinen 7064e26195fSJason Gunthorpe tpm_put_ops(chip); 707954650efSJarkko Sakkinen 708954650efSJarkko Sakkinen return rc; 709954650efSJarkko Sakkinen } 710954650efSJarkko Sakkinen EXPORT_SYMBOL_GPL(tpm_is_tpm2); 711954650efSJarkko Sakkinen 712954650efSJarkko Sakkinen /** 713aad887f6SJarkko Sakkinen * tpm_pcr_read - read a PCR value from SHA1 bank 714aad887f6SJarkko Sakkinen * @chip: a &struct tpm_chip instance, %NULL for the default chip 715aad887f6SJarkko Sakkinen * @pcr_idx: the PCR to be retrieved 716aad887f6SJarkko Sakkinen * @res_buf: the value of the PCR 7179deb0eb7SJason Gunthorpe * 718aad887f6SJarkko Sakkinen * Return: same as with tpm_transmit_cmd() 7199deb0eb7SJason Gunthorpe */ 720aad887f6SJarkko Sakkinen int tpm_pcr_read(struct tpm_chip *chip, int pcr_idx, u8 *res_buf) 7219deb0eb7SJason Gunthorpe { 7229deb0eb7SJason Gunthorpe int rc; 7239deb0eb7SJason Gunthorpe 724fc1d52b7SStefan Berger chip = tpm_find_get_ops(chip); 725aad887f6SJarkko Sakkinen if (!chip) 7269deb0eb7SJason Gunthorpe return -ENODEV; 7277a1d7e6dSJarkko Sakkinen if (chip->flags & TPM_CHIP_FLAG_TPM2) 7287a1d7e6dSJarkko Sakkinen rc = tpm2_pcr_read(chip, pcr_idx, res_buf); 7297a1d7e6dSJarkko Sakkinen else 730000a07b0SJason Gunthorpe rc = tpm_pcr_read_dev(chip, pcr_idx, res_buf); 7314e26195fSJason Gunthorpe tpm_put_ops(chip); 7329deb0eb7SJason Gunthorpe return rc; 7339deb0eb7SJason Gunthorpe } 7349deb0eb7SJason Gunthorpe EXPORT_SYMBOL_GPL(tpm_pcr_read); 7359deb0eb7SJason Gunthorpe 736a69faebfSRoberto Sassu #define TPM_ORD_PCR_EXTEND 20 737ca6d4580SWinkler, Tomas #define EXTEND_PCR_RESULT_SIZE 34 73851b0be64SStefan Berger #define EXTEND_PCR_RESULT_BODY_SIZE 20 739ca6d4580SWinkler, Tomas static const struct tpm_input_header pcrextend_header = { 74006e93279SRoberto Sassu .tag = cpu_to_be16(TPM_TAG_RQU_COMMAND), 741ca6d4580SWinkler, Tomas .length = cpu_to_be32(34), 742a69faebfSRoberto Sassu .ordinal = cpu_to_be32(TPM_ORD_PCR_EXTEND) 743ca6d4580SWinkler, Tomas }; 744ca6d4580SWinkler, Tomas 745175d5b2aSRoberto Sassu static int tpm1_pcr_extend(struct tpm_chip *chip, int pcr_idx, const u8 *hash, 746175d5b2aSRoberto Sassu char *log_msg) 747175d5b2aSRoberto Sassu { 748175d5b2aSRoberto Sassu struct tpm_buf buf; 749175d5b2aSRoberto Sassu int rc; 750175d5b2aSRoberto Sassu 751175d5b2aSRoberto Sassu rc = tpm_buf_init(&buf, TPM_TAG_RQU_COMMAND, TPM_ORD_PCR_EXTEND); 752175d5b2aSRoberto Sassu if (rc) 753175d5b2aSRoberto Sassu return rc; 754175d5b2aSRoberto Sassu 755175d5b2aSRoberto Sassu tpm_buf_append_u32(&buf, pcr_idx); 756175d5b2aSRoberto Sassu tpm_buf_append(&buf, hash, TPM_DIGEST_SIZE); 757175d5b2aSRoberto Sassu 758175d5b2aSRoberto Sassu rc = tpm_transmit_cmd(chip, NULL, buf.data, EXTEND_PCR_RESULT_SIZE, 759175d5b2aSRoberto Sassu EXTEND_PCR_RESULT_BODY_SIZE, 0, log_msg); 760175d5b2aSRoberto Sassu tpm_buf_destroy(&buf); 761175d5b2aSRoberto Sassu return rc; 762175d5b2aSRoberto Sassu } 763175d5b2aSRoberto Sassu 7649deb0eb7SJason Gunthorpe /** 765aad887f6SJarkko Sakkinen * tpm_pcr_extend - extend a PCR value in SHA1 bank. 766aad887f6SJarkko Sakkinen * @chip: a &struct tpm_chip instance, %NULL for the default chip 767aad887f6SJarkko Sakkinen * @pcr_idx: the PCR to be retrieved 768aad887f6SJarkko Sakkinen * @hash: the hash value used to extend the PCR value 7699deb0eb7SJason Gunthorpe * 770aad887f6SJarkko Sakkinen * Note: with TPM 2.0 extends also those banks with a known digest size to the 771aad887f6SJarkko Sakkinen * cryto subsystem in order to prevent malicious use of those PCR banks. In the 772aad887f6SJarkko Sakkinen * future we should dynamically determine digest sizes. 773aad887f6SJarkko Sakkinen * 774aad887f6SJarkko Sakkinen * Return: same as with tpm_transmit_cmd() 7759deb0eb7SJason Gunthorpe */ 776aad887f6SJarkko Sakkinen int tpm_pcr_extend(struct tpm_chip *chip, int pcr_idx, const u8 *hash) 7779deb0eb7SJason Gunthorpe { 7789deb0eb7SJason Gunthorpe int rc; 779c1f92b4bSNayna Jain struct tpm2_digest digest_list[ARRAY_SIZE(chip->active_banks)]; 780c1f92b4bSNayna Jain u32 count = 0; 781c1f92b4bSNayna Jain int i; 7829deb0eb7SJason Gunthorpe 783fc1d52b7SStefan Berger chip = tpm_find_get_ops(chip); 784aad887f6SJarkko Sakkinen if (!chip) 7859deb0eb7SJason Gunthorpe return -ENODEV; 7869deb0eb7SJason Gunthorpe 7877a1d7e6dSJarkko Sakkinen if (chip->flags & TPM_CHIP_FLAG_TPM2) { 788c1f92b4bSNayna Jain memset(digest_list, 0, sizeof(digest_list)); 789c1f92b4bSNayna Jain 79070ea1636SDan Carpenter for (i = 0; i < ARRAY_SIZE(chip->active_banks) && 79170ea1636SDan Carpenter chip->active_banks[i] != TPM2_ALG_ERROR; i++) { 792c1f92b4bSNayna Jain digest_list[i].alg_id = chip->active_banks[i]; 793c1f92b4bSNayna Jain memcpy(digest_list[i].digest, hash, TPM_DIGEST_SIZE); 794c1f92b4bSNayna Jain count++; 795c1f92b4bSNayna Jain } 796c1f92b4bSNayna Jain 797c1f92b4bSNayna Jain rc = tpm2_pcr_extend(chip, pcr_idx, count, digest_list); 7984e26195fSJason Gunthorpe tpm_put_ops(chip); 7997a1d7e6dSJarkko Sakkinen return rc; 8007a1d7e6dSJarkko Sakkinen } 8017a1d7e6dSJarkko Sakkinen 802175d5b2aSRoberto Sassu rc = tpm1_pcr_extend(chip, pcr_idx, hash, 8039deb0eb7SJason Gunthorpe "attempting extend a PCR value"); 8044e26195fSJason Gunthorpe tpm_put_ops(chip); 8059deb0eb7SJason Gunthorpe return rc; 8069deb0eb7SJason Gunthorpe } 8079deb0eb7SJason Gunthorpe EXPORT_SYMBOL_GPL(tpm_pcr_extend); 8089deb0eb7SJason Gunthorpe 8099deb0eb7SJason Gunthorpe /** 8109deb0eb7SJason Gunthorpe * tpm_do_selftest - have the TPM continue its selftest and wait until it 8119deb0eb7SJason Gunthorpe * can receive further commands 8129deb0eb7SJason Gunthorpe * @chip: TPM chip to use 8139deb0eb7SJason Gunthorpe * 8149deb0eb7SJason Gunthorpe * Returns 0 on success, < 0 in case of fatal error or a value > 0 representing 8159deb0eb7SJason Gunthorpe * a TPM error code. 8169deb0eb7SJason Gunthorpe */ 8179deb0eb7SJason Gunthorpe int tpm_do_selftest(struct tpm_chip *chip) 8189deb0eb7SJason Gunthorpe { 8199deb0eb7SJason Gunthorpe int rc; 8209deb0eb7SJason Gunthorpe unsigned int loops; 8219deb0eb7SJason Gunthorpe unsigned int delay_msec = 100; 8229deb0eb7SJason Gunthorpe unsigned long duration; 8230c541332SJarkko Sakkinen u8 dummy[TPM_DIGEST_SIZE]; 8249deb0eb7SJason Gunthorpe 825b2d6e6deSTomas Winkler duration = tpm1_calc_ordinal_duration(chip, TPM_ORD_CONTINUE_SELFTEST); 8269deb0eb7SJason Gunthorpe 8279deb0eb7SJason Gunthorpe loops = jiffies_to_msecs(duration) / delay_msec; 8289deb0eb7SJason Gunthorpe 8299deb0eb7SJason Gunthorpe rc = tpm_continue_selftest(chip); 8300803d7beSChris Chiu if (rc == TPM_ERR_INVALID_POSTINIT) { 8310803d7beSChris Chiu chip->flags |= TPM_CHIP_FLAG_ALWAYS_POWERED; 8320803d7beSChris Chiu dev_info(&chip->dev, "TPM not ready (%d)\n", rc); 8330803d7beSChris Chiu } 8349deb0eb7SJason Gunthorpe /* This may fail if there was no TPM driver during a suspend/resume 8359deb0eb7SJason Gunthorpe * cycle; some may return 10 (BAD_ORDINAL), others 28 (FAILEDSELFTEST) 8369deb0eb7SJason Gunthorpe */ 8379deb0eb7SJason Gunthorpe if (rc) 8389deb0eb7SJason Gunthorpe return rc; 8399deb0eb7SJason Gunthorpe 8409deb0eb7SJason Gunthorpe do { 8419deb0eb7SJason Gunthorpe /* Attempt to read a PCR value */ 8420c541332SJarkko Sakkinen rc = tpm_pcr_read_dev(chip, 0, dummy); 8430c541332SJarkko Sakkinen 8449deb0eb7SJason Gunthorpe /* Some buggy TPMs will not respond to tpm_tis_ready() for 8459deb0eb7SJason Gunthorpe * around 300ms while the self test is ongoing, keep trying 8469deb0eb7SJason Gunthorpe * until the self test duration expires. */ 8479deb0eb7SJason Gunthorpe if (rc == -ETIME) { 8488cfffc9dSJason Gunthorpe dev_info( 8498cfffc9dSJason Gunthorpe &chip->dev, HW_ERR 8508cfffc9dSJason Gunthorpe "TPM command timed out during continue self test"); 8519f3fc7bcSHamza Attak tpm_msleep(delay_msec); 8529deb0eb7SJason Gunthorpe continue; 8539deb0eb7SJason Gunthorpe } 8549deb0eb7SJason Gunthorpe 8559deb0eb7SJason Gunthorpe if (rc == TPM_ERR_DISABLED || rc == TPM_ERR_DEACTIVATED) { 8568cfffc9dSJason Gunthorpe dev_info(&chip->dev, 8579deb0eb7SJason Gunthorpe "TPM is disabled/deactivated (0x%X)\n", rc); 8589deb0eb7SJason Gunthorpe /* TPM is disabled and/or deactivated; driver can 8599deb0eb7SJason Gunthorpe * proceed and TPM does handle commands for 8609deb0eb7SJason Gunthorpe * suspend/resume correctly 8619deb0eb7SJason Gunthorpe */ 8629deb0eb7SJason Gunthorpe return 0; 8639deb0eb7SJason Gunthorpe } 8649deb0eb7SJason Gunthorpe if (rc != TPM_WARN_DOING_SELFTEST) 8659deb0eb7SJason Gunthorpe return rc; 8669f3fc7bcSHamza Attak tpm_msleep(delay_msec); 8679deb0eb7SJason Gunthorpe } while (--loops > 0); 8689deb0eb7SJason Gunthorpe 8699deb0eb7SJason Gunthorpe return rc; 8709deb0eb7SJason Gunthorpe } 8719deb0eb7SJason Gunthorpe EXPORT_SYMBOL_GPL(tpm_do_selftest); 8729deb0eb7SJason Gunthorpe 873cae8b441SJason Gunthorpe /** 874cae8b441SJason Gunthorpe * tpm1_auto_startup - Perform the standard automatic TPM initialization 875cae8b441SJason Gunthorpe * sequence 876cae8b441SJason Gunthorpe * @chip: TPM chip to use 877cae8b441SJason Gunthorpe * 878cae8b441SJason Gunthorpe * Returns 0 on success, < 0 in case of fatal error. 879cae8b441SJason Gunthorpe */ 880cae8b441SJason Gunthorpe int tpm1_auto_startup(struct tpm_chip *chip) 881cae8b441SJason Gunthorpe { 882cae8b441SJason Gunthorpe int rc; 883cae8b441SJason Gunthorpe 884cae8b441SJason Gunthorpe rc = tpm_get_timeouts(chip); 885cae8b441SJason Gunthorpe if (rc) 886cae8b441SJason Gunthorpe goto out; 887cae8b441SJason Gunthorpe rc = tpm_do_selftest(chip); 888cae8b441SJason Gunthorpe if (rc) { 889cae8b441SJason Gunthorpe dev_err(&chip->dev, "TPM self test failed\n"); 890cae8b441SJason Gunthorpe goto out; 891cae8b441SJason Gunthorpe } 892cae8b441SJason Gunthorpe 893cae8b441SJason Gunthorpe return rc; 894cae8b441SJason Gunthorpe out: 895cae8b441SJason Gunthorpe if (rc > 0) 896cae8b441SJason Gunthorpe rc = -ENODEV; 897cae8b441SJason Gunthorpe return rc; 898cae8b441SJason Gunthorpe } 899cae8b441SJason Gunthorpe 900aad887f6SJarkko Sakkinen /** 901aad887f6SJarkko Sakkinen * tpm_send - send a TPM command 902aad887f6SJarkko Sakkinen * @chip: a &struct tpm_chip instance, %NULL for the default chip 903aad887f6SJarkko Sakkinen * @cmd: a TPM command buffer 904aad887f6SJarkko Sakkinen * @buflen: the length of the TPM command buffer 905aad887f6SJarkko Sakkinen * 906aad887f6SJarkko Sakkinen * Return: same as with tpm_transmit_cmd() 907aad887f6SJarkko Sakkinen */ 908aad887f6SJarkko Sakkinen int tpm_send(struct tpm_chip *chip, void *cmd, size_t buflen) 9099deb0eb7SJason Gunthorpe { 9109deb0eb7SJason Gunthorpe int rc; 9119deb0eb7SJason Gunthorpe 912fc1d52b7SStefan Berger chip = tpm_find_get_ops(chip); 913aad887f6SJarkko Sakkinen if (!chip) 9149deb0eb7SJason Gunthorpe return -ENODEV; 9159deb0eb7SJason Gunthorpe 916745b361eSJarkko Sakkinen rc = tpm_transmit_cmd(chip, NULL, cmd, buflen, 0, 0, 917aad887f6SJarkko Sakkinen "attempting to a send a command"); 9184e26195fSJason Gunthorpe tpm_put_ops(chip); 9199deb0eb7SJason Gunthorpe return rc; 9209deb0eb7SJason Gunthorpe } 9219deb0eb7SJason Gunthorpe EXPORT_SYMBOL_GPL(tpm_send); 9229deb0eb7SJason Gunthorpe 923a69faebfSRoberto Sassu #define TPM_ORD_SAVESTATE 152 9249deb0eb7SJason Gunthorpe #define SAVESTATE_RESULT_SIZE 10 9259deb0eb7SJason Gunthorpe 9260014777fSJulia Lawall static const struct tpm_input_header savestate_header = { 92706e93279SRoberto Sassu .tag = cpu_to_be16(TPM_TAG_RQU_COMMAND), 9289deb0eb7SJason Gunthorpe .length = cpu_to_be32(10), 929a69faebfSRoberto Sassu .ordinal = cpu_to_be32(TPM_ORD_SAVESTATE) 9309deb0eb7SJason Gunthorpe }; 9319deb0eb7SJason Gunthorpe 9329deb0eb7SJason Gunthorpe /* 9339deb0eb7SJason Gunthorpe * We are about to suspend. Save the TPM state 9349deb0eb7SJason Gunthorpe * so that it can be restored. 9359deb0eb7SJason Gunthorpe */ 9369deb0eb7SJason Gunthorpe int tpm_pm_suspend(struct device *dev) 9379deb0eb7SJason Gunthorpe { 938ec03c50bSStefan Berger struct tpm_chip *chip = dev_get_drvdata(dev); 9399deb0eb7SJason Gunthorpe struct tpm_cmd_t cmd; 9409deb0eb7SJason Gunthorpe int rc, try; 9419deb0eb7SJason Gunthorpe 9429deb0eb7SJason Gunthorpe u8 dummy_hash[TPM_DIGEST_SIZE] = { 0 }; 9439deb0eb7SJason Gunthorpe 9449deb0eb7SJason Gunthorpe if (chip == NULL) 9459deb0eb7SJason Gunthorpe return -ENODEV; 9469deb0eb7SJason Gunthorpe 947b5d0ebc9SEnric Balletbo i Serra if (chip->flags & TPM_CHIP_FLAG_ALWAYS_POWERED) 948b5d0ebc9SEnric Balletbo i Serra return 0; 949b5d0ebc9SEnric Balletbo i Serra 95074d6b3ceSJarkko Sakkinen if (chip->flags & TPM_CHIP_FLAG_TPM2) { 95174d6b3ceSJarkko Sakkinen tpm2_shutdown(chip, TPM2_SU_STATE); 95274d6b3ceSJarkko Sakkinen return 0; 95374d6b3ceSJarkko Sakkinen } 95430fc8d13SJarkko Sakkinen 9559deb0eb7SJason Gunthorpe /* for buggy tpm, flush pcrs with extend to selected dummy */ 956175d5b2aSRoberto Sassu if (tpm_suspend_pcr) 957175d5b2aSRoberto Sassu rc = tpm1_pcr_extend(chip, tpm_suspend_pcr, dummy_hash, 9589deb0eb7SJason Gunthorpe "extending dummy pcr before suspend"); 9599deb0eb7SJason Gunthorpe 9609deb0eb7SJason Gunthorpe /* now do the actual savestate */ 9619deb0eb7SJason Gunthorpe for (try = 0; try < TPM_RETRY; try++) { 9629deb0eb7SJason Gunthorpe cmd.header.in = savestate_header; 963745b361eSJarkko Sakkinen rc = tpm_transmit_cmd(chip, NULL, &cmd, SAVESTATE_RESULT_SIZE, 964745b361eSJarkko Sakkinen 0, 0, NULL); 9659deb0eb7SJason Gunthorpe 9669deb0eb7SJason Gunthorpe /* 9679deb0eb7SJason Gunthorpe * If the TPM indicates that it is too busy to respond to 9689deb0eb7SJason Gunthorpe * this command then retry before giving up. It can take 9699deb0eb7SJason Gunthorpe * several seconds for this TPM to be ready. 9709deb0eb7SJason Gunthorpe * 9719deb0eb7SJason Gunthorpe * This can happen if the TPM has already been sent the 9729deb0eb7SJason Gunthorpe * SaveState command before the driver has loaded. TCG 1.2 9739deb0eb7SJason Gunthorpe * specification states that any communication after SaveState 9749deb0eb7SJason Gunthorpe * may cause the TPM to invalidate previously saved state. 9759deb0eb7SJason Gunthorpe */ 9769deb0eb7SJason Gunthorpe if (rc != TPM_WARN_RETRY) 9779deb0eb7SJason Gunthorpe break; 9789f3fc7bcSHamza Attak tpm_msleep(TPM_TIMEOUT_RETRY); 9799deb0eb7SJason Gunthorpe } 9809deb0eb7SJason Gunthorpe 9819deb0eb7SJason Gunthorpe if (rc) 9828cfffc9dSJason Gunthorpe dev_err(&chip->dev, 9839deb0eb7SJason Gunthorpe "Error (%d) sending savestate before suspend\n", rc); 9849deb0eb7SJason Gunthorpe else if (try > 0) 9858cfffc9dSJason Gunthorpe dev_warn(&chip->dev, "TPM savestate took %dms\n", 9869deb0eb7SJason Gunthorpe try * TPM_TIMEOUT_RETRY); 9879deb0eb7SJason Gunthorpe 9889deb0eb7SJason Gunthorpe return rc; 9899deb0eb7SJason Gunthorpe } 9909deb0eb7SJason Gunthorpe EXPORT_SYMBOL_GPL(tpm_pm_suspend); 9919deb0eb7SJason Gunthorpe 9929deb0eb7SJason Gunthorpe /* 9939deb0eb7SJason Gunthorpe * Resume from a power safe. The BIOS already restored 9949deb0eb7SJason Gunthorpe * the TPM state. 9959deb0eb7SJason Gunthorpe */ 9969deb0eb7SJason Gunthorpe int tpm_pm_resume(struct device *dev) 9979deb0eb7SJason Gunthorpe { 998ec03c50bSStefan Berger struct tpm_chip *chip = dev_get_drvdata(dev); 9999deb0eb7SJason Gunthorpe 10009deb0eb7SJason Gunthorpe if (chip == NULL) 10019deb0eb7SJason Gunthorpe return -ENODEV; 10029deb0eb7SJason Gunthorpe 10039deb0eb7SJason Gunthorpe return 0; 10049deb0eb7SJason Gunthorpe } 10059deb0eb7SJason Gunthorpe EXPORT_SYMBOL_GPL(tpm_pm_resume); 10069deb0eb7SJason Gunthorpe 10079deb0eb7SJason Gunthorpe #define TPM_GETRANDOM_RESULT_SIZE 18 10080014777fSJulia Lawall static const struct tpm_input_header tpm_getrandom_header = { 100906e93279SRoberto Sassu .tag = cpu_to_be16(TPM_TAG_RQU_COMMAND), 10109deb0eb7SJason Gunthorpe .length = cpu_to_be32(14), 1011a69faebfSRoberto Sassu .ordinal = cpu_to_be32(TPM_ORD_GET_RANDOM) 10129deb0eb7SJason Gunthorpe }; 10139deb0eb7SJason Gunthorpe 10149deb0eb7SJason Gunthorpe /** 1015aad887f6SJarkko Sakkinen * tpm_get_random() - get random bytes from the TPM's RNG 1016aad887f6SJarkko Sakkinen * @chip: a &struct tpm_chip instance, %NULL for the default chip 10179deb0eb7SJason Gunthorpe * @out: destination buffer for the random bytes 10189deb0eb7SJason Gunthorpe * @max: the max number of bytes to write to @out 10199deb0eb7SJason Gunthorpe * 1020aad887f6SJarkko Sakkinen * Return: same as with tpm_transmit_cmd() 10219deb0eb7SJason Gunthorpe */ 1022aad887f6SJarkko Sakkinen int tpm_get_random(struct tpm_chip *chip, u8 *out, size_t max) 10239deb0eb7SJason Gunthorpe { 10249deb0eb7SJason Gunthorpe struct tpm_cmd_t tpm_cmd; 1025c659af78SStefan Berger u32 recd, num_bytes = min_t(u32, max, TPM_MAX_RNG_DATA), rlength; 10269deb0eb7SJason Gunthorpe int err, total = 0, retries = 5; 10279deb0eb7SJason Gunthorpe u8 *dest = out; 10289deb0eb7SJason Gunthorpe 10293e14d83eSJarkko Sakkinen if (!out || !num_bytes || max > TPM_MAX_RNG_DATA) 10303e14d83eSJarkko Sakkinen return -EINVAL; 10313e14d83eSJarkko Sakkinen 1032fc1d52b7SStefan Berger chip = tpm_find_get_ops(chip); 1033aad887f6SJarkko Sakkinen if (!chip) 10349deb0eb7SJason Gunthorpe return -ENODEV; 10359deb0eb7SJason Gunthorpe 10367a1d7e6dSJarkko Sakkinen if (chip->flags & TPM_CHIP_FLAG_TPM2) { 10377a1d7e6dSJarkko Sakkinen err = tpm2_get_random(chip, out, max); 10384e26195fSJason Gunthorpe tpm_put_ops(chip); 10397a1d7e6dSJarkko Sakkinen return err; 10407a1d7e6dSJarkko Sakkinen } 10417a1d7e6dSJarkko Sakkinen 10429deb0eb7SJason Gunthorpe do { 10439deb0eb7SJason Gunthorpe tpm_cmd.header.in = tpm_getrandom_header; 10449deb0eb7SJason Gunthorpe tpm_cmd.params.getrandom_in.num_bytes = cpu_to_be32(num_bytes); 10459deb0eb7SJason Gunthorpe 1046745b361eSJarkko Sakkinen err = tpm_transmit_cmd(chip, NULL, &tpm_cmd, 10479deb0eb7SJason Gunthorpe TPM_GETRANDOM_RESULT_SIZE + num_bytes, 1048c659af78SStefan Berger offsetof(struct tpm_getrandom_out, 1049c659af78SStefan Berger rng_data), 1050d4816edfSJarkko Sakkinen 0, "attempting get random"); 10519deb0eb7SJason Gunthorpe if (err) 10529deb0eb7SJason Gunthorpe break; 10539deb0eb7SJason Gunthorpe 10549deb0eb7SJason Gunthorpe recd = be32_to_cpu(tpm_cmd.params.getrandom_out.rng_data_len); 10553be23274SJeremy Boone if (recd > num_bytes) { 10563be23274SJeremy Boone total = -EFAULT; 10573be23274SJeremy Boone break; 10583be23274SJeremy Boone } 1059c659af78SStefan Berger 1060c659af78SStefan Berger rlength = be32_to_cpu(tpm_cmd.header.out.length); 106184b59f64SJarkko Sakkinen if (rlength < TPM_HEADER_SIZE + 106284b59f64SJarkko Sakkinen offsetof(struct tpm_getrandom_out, rng_data) + 1063c659af78SStefan Berger recd) { 1064c659af78SStefan Berger total = -EFAULT; 1065c659af78SStefan Berger break; 1066c659af78SStefan Berger } 10679deb0eb7SJason Gunthorpe memcpy(dest, tpm_cmd.params.getrandom_out.rng_data, recd); 10689deb0eb7SJason Gunthorpe 10699deb0eb7SJason Gunthorpe dest += recd; 10709deb0eb7SJason Gunthorpe total += recd; 10719deb0eb7SJason Gunthorpe num_bytes -= recd; 10729deb0eb7SJason Gunthorpe } while (retries-- && total < max); 10739deb0eb7SJason Gunthorpe 10744e26195fSJason Gunthorpe tpm_put_ops(chip); 10759deb0eb7SJason Gunthorpe return total ? total : -EIO; 10769deb0eb7SJason Gunthorpe } 10779deb0eb7SJason Gunthorpe EXPORT_SYMBOL_GPL(tpm_get_random); 10789deb0eb7SJason Gunthorpe 1079954650efSJarkko Sakkinen /** 1080aad887f6SJarkko Sakkinen * tpm_seal_trusted() - seal a trusted key payload 1081aad887f6SJarkko Sakkinen * @chip: a &struct tpm_chip instance, %NULL for the default chip 1082954650efSJarkko Sakkinen * @options: authentication values and other options 1083954650efSJarkko Sakkinen * @payload: the key data in clear and encrypted form 1084954650efSJarkko Sakkinen * 1085aad887f6SJarkko Sakkinen * Note: only TPM 2.0 chip are supported. TPM 1.x implementation is located in 1086aad887f6SJarkko Sakkinen * the keyring subsystem. 1087aad887f6SJarkko Sakkinen * 1088aad887f6SJarkko Sakkinen * Return: same as with tpm_transmit_cmd() 1089954650efSJarkko Sakkinen */ 1090aad887f6SJarkko Sakkinen int tpm_seal_trusted(struct tpm_chip *chip, struct trusted_key_payload *payload, 1091954650efSJarkko Sakkinen struct trusted_key_options *options) 1092954650efSJarkko Sakkinen { 1093954650efSJarkko Sakkinen int rc; 1094954650efSJarkko Sakkinen 1095fc1d52b7SStefan Berger chip = tpm_find_get_ops(chip); 1096aad887f6SJarkko Sakkinen if (!chip || !(chip->flags & TPM_CHIP_FLAG_TPM2)) 1097954650efSJarkko Sakkinen return -ENODEV; 1098954650efSJarkko Sakkinen 1099954650efSJarkko Sakkinen rc = tpm2_seal_trusted(chip, payload, options); 1100954650efSJarkko Sakkinen 11014e26195fSJason Gunthorpe tpm_put_ops(chip); 1102954650efSJarkko Sakkinen return rc; 1103954650efSJarkko Sakkinen } 1104954650efSJarkko Sakkinen EXPORT_SYMBOL_GPL(tpm_seal_trusted); 1105954650efSJarkko Sakkinen 1106954650efSJarkko Sakkinen /** 1107954650efSJarkko Sakkinen * tpm_unseal_trusted() - unseal a trusted key 1108aad887f6SJarkko Sakkinen * @chip: a &struct tpm_chip instance, %NULL for the default chip 1109954650efSJarkko Sakkinen * @options: authentication values and other options 1110954650efSJarkko Sakkinen * @payload: the key data in clear and encrypted form 1111954650efSJarkko Sakkinen * 1112aad887f6SJarkko Sakkinen * Note: only TPM 2.0 chip are supported. TPM 1.x implementation is located in 1113aad887f6SJarkko Sakkinen * the keyring subsystem. 1114aad887f6SJarkko Sakkinen * 1115aad887f6SJarkko Sakkinen * Return: same as with tpm_transmit_cmd() 1116954650efSJarkko Sakkinen */ 1117aad887f6SJarkko Sakkinen int tpm_unseal_trusted(struct tpm_chip *chip, 1118aad887f6SJarkko Sakkinen struct trusted_key_payload *payload, 1119954650efSJarkko Sakkinen struct trusted_key_options *options) 1120954650efSJarkko Sakkinen { 1121954650efSJarkko Sakkinen int rc; 1122954650efSJarkko Sakkinen 1123fc1d52b7SStefan Berger chip = tpm_find_get_ops(chip); 1124aad887f6SJarkko Sakkinen if (!chip || !(chip->flags & TPM_CHIP_FLAG_TPM2)) 1125954650efSJarkko Sakkinen return -ENODEV; 1126954650efSJarkko Sakkinen 1127954650efSJarkko Sakkinen rc = tpm2_unseal_trusted(chip, payload, options); 1128954650efSJarkko Sakkinen 11294e26195fSJason Gunthorpe tpm_put_ops(chip); 11304e26195fSJason Gunthorpe 1131954650efSJarkko Sakkinen return rc; 1132954650efSJarkko Sakkinen } 1133954650efSJarkko Sakkinen EXPORT_SYMBOL_GPL(tpm_unseal_trusted); 1134954650efSJarkko Sakkinen 1135313d21eeSJarkko Sakkinen static int __init tpm_init(void) 1136313d21eeSJarkko Sakkinen { 1137313d21eeSJarkko Sakkinen int rc; 1138313d21eeSJarkko Sakkinen 1139313d21eeSJarkko Sakkinen tpm_class = class_create(THIS_MODULE, "tpm"); 1140313d21eeSJarkko Sakkinen if (IS_ERR(tpm_class)) { 1141313d21eeSJarkko Sakkinen pr_err("couldn't create tpm class\n"); 1142313d21eeSJarkko Sakkinen return PTR_ERR(tpm_class); 1143313d21eeSJarkko Sakkinen } 1144313d21eeSJarkko Sakkinen 1145fdc915f7SJames Bottomley tpmrm_class = class_create(THIS_MODULE, "tpmrm"); 1146fdc915f7SJames Bottomley if (IS_ERR(tpmrm_class)) { 1147fdc915f7SJames Bottomley pr_err("couldn't create tpmrm class\n"); 11489e1b74a6STadeusz Struk rc = PTR_ERR(tpmrm_class); 11499e1b74a6STadeusz Struk goto out_destroy_tpm_class; 1150fdc915f7SJames Bottomley } 1151fdc915f7SJames Bottomley 1152fdc915f7SJames Bottomley rc = alloc_chrdev_region(&tpm_devt, 0, 2*TPM_NUM_DEVICES, "tpm"); 1153313d21eeSJarkko Sakkinen if (rc < 0) { 1154313d21eeSJarkko Sakkinen pr_err("tpm: failed to allocate char dev region\n"); 11559e1b74a6STadeusz Struk goto out_destroy_tpmrm_class; 11569e1b74a6STadeusz Struk } 11579e1b74a6STadeusz Struk 11589e1b74a6STadeusz Struk rc = tpm_dev_common_init(); 11599e1b74a6STadeusz Struk if (rc) { 11609e1b74a6STadeusz Struk pr_err("tpm: failed to allocate char dev region\n"); 11619e1b74a6STadeusz Struk goto out_unreg_chrdev; 1162313d21eeSJarkko Sakkinen } 1163313d21eeSJarkko Sakkinen 1164313d21eeSJarkko Sakkinen return 0; 11659e1b74a6STadeusz Struk 11669e1b74a6STadeusz Struk out_unreg_chrdev: 11679e1b74a6STadeusz Struk unregister_chrdev_region(tpm_devt, 2 * TPM_NUM_DEVICES); 11689e1b74a6STadeusz Struk out_destroy_tpmrm_class: 11699e1b74a6STadeusz Struk class_destroy(tpmrm_class); 11709e1b74a6STadeusz Struk out_destroy_tpm_class: 11719e1b74a6STadeusz Struk class_destroy(tpm_class); 11729e1b74a6STadeusz Struk 11739e1b74a6STadeusz Struk return rc; 1174313d21eeSJarkko Sakkinen } 1175313d21eeSJarkko Sakkinen 1176313d21eeSJarkko Sakkinen static void __exit tpm_exit(void) 1177313d21eeSJarkko Sakkinen { 117815516788SStefan Berger idr_destroy(&dev_nums_idr); 1179313d21eeSJarkko Sakkinen class_destroy(tpm_class); 1180fdc915f7SJames Bottomley class_destroy(tpmrm_class); 1181fdc915f7SJames Bottomley unregister_chrdev_region(tpm_devt, 2*TPM_NUM_DEVICES); 11829e1b74a6STadeusz Struk tpm_dev_common_exit(); 1183313d21eeSJarkko Sakkinen } 1184313d21eeSJarkko Sakkinen 1185313d21eeSJarkko Sakkinen subsys_initcall(tpm_init); 1186313d21eeSJarkko Sakkinen module_exit(tpm_exit); 1187313d21eeSJarkko Sakkinen 11889deb0eb7SJason Gunthorpe MODULE_AUTHOR("Leendert van Doorn (leendert@watson.ibm.com)"); 11899deb0eb7SJason Gunthorpe MODULE_DESCRIPTION("TPM Driver"); 11909deb0eb7SJason Gunthorpe MODULE_VERSION("2.0"); 11919deb0eb7SJason Gunthorpe MODULE_LICENSE("GPL"); 1192