1 /* 2 * Copyright (C) 2004 IBM Corporation 3 * Authors: 4 * Leendert van Doorn <leendert@watson.ibm.com> 5 * Dave Safford <safford@watson.ibm.com> 6 * Reiner Sailer <sailer@watson.ibm.com> 7 * Kylene Hall <kjhall@us.ibm.com> 8 * 9 * Copyright (C) 2013 Obsidian Research Corp 10 * Jason Gunthorpe <jgunthorpe@obsidianresearch.com> 11 * 12 * Device file system interface to the TPM 13 * 14 * This program is free software; you can redistribute it and/or 15 * modify it under the terms of the GNU General Public License as 16 * published by the Free Software Foundation, version 2 of the 17 * License. 18 * 19 */ 20 #include <linux/slab.h> 21 #include <linux/uaccess.h> 22 #include "tpm.h" 23 #include "tpm-dev.h" 24 25 static void user_reader_timeout(struct timer_list *t) 26 { 27 struct file_priv *priv = from_timer(priv, t, user_read_timer); 28 29 pr_warn("TPM user space timeout is deprecated (pid=%d)\n", 30 task_tgid_nr(current)); 31 32 schedule_work(&priv->work); 33 } 34 35 static void timeout_work(struct work_struct *work) 36 { 37 struct file_priv *priv = container_of(work, struct file_priv, work); 38 39 mutex_lock(&priv->buffer_mutex); 40 atomic_set(&priv->data_pending, 0); 41 memset(priv->data_buffer, 0, sizeof(priv->data_buffer)); 42 mutex_unlock(&priv->buffer_mutex); 43 } 44 45 void tpm_common_open(struct file *file, struct tpm_chip *chip, 46 struct file_priv *priv) 47 { 48 priv->chip = chip; 49 atomic_set(&priv->data_pending, 0); 50 mutex_init(&priv->buffer_mutex); 51 timer_setup(&priv->user_read_timer, user_reader_timeout, 0); 52 INIT_WORK(&priv->work, timeout_work); 53 54 file->private_data = priv; 55 } 56 57 ssize_t tpm_common_read(struct file *file, char __user *buf, 58 size_t size, loff_t *off) 59 { 60 struct file_priv *priv = file->private_data; 61 ssize_t ret_size; 62 ssize_t orig_ret_size; 63 int rc; 64 65 del_singleshot_timer_sync(&priv->user_read_timer); 66 flush_work(&priv->work); 67 ret_size = atomic_read(&priv->data_pending); 68 if (ret_size > 0) { /* relay data */ 69 orig_ret_size = ret_size; 70 if (size < ret_size) 71 ret_size = size; 72 73 mutex_lock(&priv->buffer_mutex); 74 rc = copy_to_user(buf, priv->data_buffer, ret_size); 75 memset(priv->data_buffer, 0, orig_ret_size); 76 if (rc) 77 ret_size = -EFAULT; 78 79 mutex_unlock(&priv->buffer_mutex); 80 } 81 82 atomic_set(&priv->data_pending, 0); 83 84 return ret_size; 85 } 86 87 ssize_t tpm_common_write(struct file *file, const char __user *buf, 88 size_t size, loff_t *off, struct tpm_space *space) 89 { 90 struct file_priv *priv = file->private_data; 91 size_t in_size = size; 92 ssize_t out_size; 93 94 /* Cannot perform a write until the read has cleared either via 95 * tpm_read or a user_read_timer timeout. This also prevents split 96 * buffered writes from blocking here. 97 */ 98 if (atomic_read(&priv->data_pending) != 0) 99 return -EBUSY; 100 101 if (in_size > TPM_BUFSIZE) 102 return -E2BIG; 103 104 mutex_lock(&priv->buffer_mutex); 105 106 if (copy_from_user 107 (priv->data_buffer, (void __user *) buf, in_size)) { 108 mutex_unlock(&priv->buffer_mutex); 109 return -EFAULT; 110 } 111 112 if (in_size < 6 || 113 in_size < be32_to_cpu(*((__be32 *) (priv->data_buffer + 2)))) { 114 mutex_unlock(&priv->buffer_mutex); 115 return -EINVAL; 116 } 117 118 /* atomic tpm command send and result receive. We only hold the ops 119 * lock during this period so that the tpm can be unregistered even if 120 * the char dev is held open. 121 */ 122 if (tpm_try_get_ops(priv->chip)) { 123 mutex_unlock(&priv->buffer_mutex); 124 return -EPIPE; 125 } 126 out_size = tpm_transmit(priv->chip, space, priv->data_buffer, 127 sizeof(priv->data_buffer), 0); 128 129 tpm_put_ops(priv->chip); 130 if (out_size < 0) { 131 mutex_unlock(&priv->buffer_mutex); 132 return out_size; 133 } 134 135 atomic_set(&priv->data_pending, out_size); 136 mutex_unlock(&priv->buffer_mutex); 137 138 /* Set a timeout by which the reader must come claim the result */ 139 mod_timer(&priv->user_read_timer, jiffies + (120 * HZ)); 140 141 return in_size; 142 } 143 144 /* 145 * Called on file close 146 */ 147 void tpm_common_release(struct file *file, struct file_priv *priv) 148 { 149 del_singleshot_timer_sync(&priv->user_read_timer); 150 flush_work(&priv->work); 151 file->private_data = NULL; 152 atomic_set(&priv->data_pending, 0); 153 } 154