1 /*
2  * Copyright (C) 2004 IBM Corporation
3  * Authors:
4  * Leendert van Doorn <leendert@watson.ibm.com>
5  * Dave Safford <safford@watson.ibm.com>
6  * Reiner Sailer <sailer@watson.ibm.com>
7  * Kylene Hall <kjhall@us.ibm.com>
8  *
9  * Copyright (C) 2013 Obsidian Research Corp
10  * Jason Gunthorpe <jgunthorpe@obsidianresearch.com>
11  *
12  * Device file system interface to the TPM
13  *
14  * This program is free software; you can redistribute it and/or
15  * modify it under the terms of the GNU General Public License as
16  * published by the Free Software Foundation, version 2 of the
17  * License.
18  *
19  */
20 #include <linux/slab.h>
21 #include <linux/uaccess.h>
22 #include "tpm.h"
23 #include "tpm-dev.h"
24 
25 static void user_reader_timeout(struct timer_list *t)
26 {
27 	struct file_priv *priv = from_timer(priv, t, user_read_timer);
28 
29 	pr_warn("TPM user space timeout is deprecated (pid=%d)\n",
30 		task_tgid_nr(current));
31 
32 	schedule_work(&priv->work);
33 }
34 
35 static void timeout_work(struct work_struct *work)
36 {
37 	struct file_priv *priv = container_of(work, struct file_priv, work);
38 
39 	mutex_lock(&priv->buffer_mutex);
40 	atomic_set(&priv->data_pending, 0);
41 	memset(priv->data_buffer, 0, sizeof(priv->data_buffer));
42 	mutex_unlock(&priv->buffer_mutex);
43 }
44 
45 void tpm_common_open(struct file *file, struct tpm_chip *chip,
46 		     struct file_priv *priv)
47 {
48 	priv->chip = chip;
49 	atomic_set(&priv->data_pending, 0);
50 	mutex_init(&priv->buffer_mutex);
51 	timer_setup(&priv->user_read_timer, user_reader_timeout, 0);
52 	INIT_WORK(&priv->work, timeout_work);
53 
54 	file->private_data = priv;
55 }
56 
57 ssize_t tpm_common_read(struct file *file, char __user *buf,
58 			size_t size, loff_t *off)
59 {
60 	struct file_priv *priv = file->private_data;
61 	ssize_t ret_size;
62 	ssize_t orig_ret_size;
63 	int rc;
64 
65 	del_singleshot_timer_sync(&priv->user_read_timer);
66 	flush_work(&priv->work);
67 	ret_size = atomic_read(&priv->data_pending);
68 	if (ret_size > 0) {	/* relay data */
69 		orig_ret_size = ret_size;
70 		if (size < ret_size)
71 			ret_size = size;
72 
73 		mutex_lock(&priv->buffer_mutex);
74 		rc = copy_to_user(buf, priv->data_buffer, ret_size);
75 		memset(priv->data_buffer, 0, orig_ret_size);
76 		if (rc)
77 			ret_size = -EFAULT;
78 
79 		mutex_unlock(&priv->buffer_mutex);
80 	}
81 
82 	atomic_set(&priv->data_pending, 0);
83 
84 	return ret_size;
85 }
86 
87 ssize_t tpm_common_write(struct file *file, const char __user *buf,
88 			 size_t size, loff_t *off, struct tpm_space *space)
89 {
90 	struct file_priv *priv = file->private_data;
91 	size_t in_size = size;
92 	ssize_t out_size;
93 
94 	/* Cannot perform a write until the read has cleared either via
95 	 * tpm_read or a user_read_timer timeout. This also prevents split
96 	 * buffered writes from blocking here.
97 	 */
98 	if (atomic_read(&priv->data_pending) != 0)
99 		return -EBUSY;
100 
101 	if (in_size > TPM_BUFSIZE)
102 		return -E2BIG;
103 
104 	mutex_lock(&priv->buffer_mutex);
105 
106 	if (copy_from_user
107 	    (priv->data_buffer, (void __user *) buf, in_size)) {
108 		mutex_unlock(&priv->buffer_mutex);
109 		return -EFAULT;
110 	}
111 
112 	if (in_size < 6 ||
113 	    in_size < be32_to_cpu(*((__be32 *) (priv->data_buffer + 2)))) {
114 		mutex_unlock(&priv->buffer_mutex);
115 		return -EINVAL;
116 	}
117 
118 	/* atomic tpm command send and result receive. We only hold the ops
119 	 * lock during this period so that the tpm can be unregistered even if
120 	 * the char dev is held open.
121 	 */
122 	if (tpm_try_get_ops(priv->chip)) {
123 		mutex_unlock(&priv->buffer_mutex);
124 		return -EPIPE;
125 	}
126 	out_size = tpm_transmit(priv->chip, space, priv->data_buffer,
127 				sizeof(priv->data_buffer), 0);
128 
129 	tpm_put_ops(priv->chip);
130 	if (out_size < 0) {
131 		mutex_unlock(&priv->buffer_mutex);
132 		return out_size;
133 	}
134 
135 	atomic_set(&priv->data_pending, out_size);
136 	mutex_unlock(&priv->buffer_mutex);
137 
138 	/* Set a timeout by which the reader must come claim the result */
139 	mod_timer(&priv->user_read_timer, jiffies + (120 * HZ));
140 
141 	return in_size;
142 }
143 
144 /*
145  * Called on file close
146  */
147 void tpm_common_release(struct file *file, struct file_priv *priv)
148 {
149 	del_singleshot_timer_sync(&priv->user_read_timer);
150 	flush_work(&priv->work);
151 	file->private_data = NULL;
152 	atomic_set(&priv->data_pending, 0);
153 }
154