xref: /openbmc/u-boot/cmd/tpm_test.c (revision 9450ab2b)
183d290c5STom Rini // SPDX-License-Identifier: GPL-2.0+
22e192b24SSimon Glass /*
32e192b24SSimon Glass  * Copyright (c) 2015 Google, Inc
42e192b24SSimon Glass  */
52e192b24SSimon Glass 
62e192b24SSimon Glass #include <common.h>
72e192b24SSimon Glass #include <command.h>
82e192b24SSimon Glass #include <environment.h>
9d677bfe2SMiquel Raynal #include <tpm-v1.h>
10*abdc7b8aSSimon Glass #include "tpm-user-utils.h"
112e192b24SSimon Glass 
122e192b24SSimon Glass /* Prints error and returns on failure */
132e192b24SSimon Glass #define TPM_CHECK(tpm_command) do { \
142e192b24SSimon Glass 	uint32_t result; \
152e192b24SSimon Glass 	\
162e192b24SSimon Glass 	result = (tpm_command); \
172e192b24SSimon Glass 	if (result != TPM_SUCCESS) { \
182e192b24SSimon Glass 		printf("TEST FAILED: line %d: " #tpm_command ": 0x%x\n", \
192e192b24SSimon Glass 			__LINE__, result); \
202e192b24SSimon Glass 		return result; \
212e192b24SSimon Glass 	} \
222e192b24SSimon Glass } while (0)
232e192b24SSimon Glass 
242e192b24SSimon Glass #define INDEX0			0xda70
252e192b24SSimon Glass #define INDEX1			0xda71
262e192b24SSimon Glass #define INDEX2			0xda72
272e192b24SSimon Glass #define INDEX3			0xda73
282e192b24SSimon Glass #define INDEX_INITIALISED	0xda80
292e192b24SSimon Glass #define PHYS_PRESENCE		4
302e192b24SSimon Glass #define PRESENCE		8
312e192b24SSimon Glass 
TlclStartupIfNeeded(struct udevice * dev)32*abdc7b8aSSimon Glass static uint32_t TlclStartupIfNeeded(struct udevice *dev)
332e192b24SSimon Glass {
34*abdc7b8aSSimon Glass 	uint32_t result = tpm_startup(dev, TPM_ST_CLEAR);
352e192b24SSimon Glass 
362e192b24SSimon Glass 	return result == TPM_INVALID_POSTINIT ? TPM_SUCCESS : result;
372e192b24SSimon Glass }
382e192b24SSimon Glass 
test_timer(struct udevice * dev)39*abdc7b8aSSimon Glass static int test_timer(struct udevice *dev)
402e192b24SSimon Glass {
412e192b24SSimon Glass 	printf("get_timer(0) = %lu\n", get_timer(0));
422e192b24SSimon Glass 	return 0;
432e192b24SSimon Glass }
442e192b24SSimon Glass 
tpm_get_flags(struct udevice * dev,uint8_t * disable,uint8_t * deactivated,uint8_t * nvlocked)45*abdc7b8aSSimon Glass static uint32_t tpm_get_flags(struct udevice *dev, uint8_t *disable,
46*abdc7b8aSSimon Glass 			      uint8_t *deactivated, uint8_t *nvlocked)
472e192b24SSimon Glass {
482e192b24SSimon Glass 	struct tpm_permanent_flags pflags;
492e192b24SSimon Glass 	uint32_t result;
502e192b24SSimon Glass 
51*abdc7b8aSSimon Glass 	result = tpm_get_permanent_flags(dev, &pflags);
522e192b24SSimon Glass 	if (result)
532e192b24SSimon Glass 		return result;
542e192b24SSimon Glass 	if (disable)
552e192b24SSimon Glass 		*disable = pflags.disable;
562e192b24SSimon Glass 	if (deactivated)
572e192b24SSimon Glass 		*deactivated = pflags.deactivated;
582e192b24SSimon Glass 	if (nvlocked)
592e192b24SSimon Glass 		*nvlocked = pflags.nv_locked;
602e192b24SSimon Glass 	debug("TPM: Got flags disable=%d, deactivated=%d, nvlocked=%d\n",
612e192b24SSimon Glass 	      pflags.disable, pflags.deactivated, pflags.nv_locked);
622e192b24SSimon Glass 
632e192b24SSimon Glass 	return 0;
642e192b24SSimon Glass }
652e192b24SSimon Glass 
tpm_nv_write_value_lock(struct udevice * dev,uint32_t index)66*abdc7b8aSSimon Glass static uint32_t tpm_nv_write_value_lock(struct udevice *dev, uint32_t index)
672e192b24SSimon Glass {
682e192b24SSimon Glass 	debug("TPM: Write lock 0x%x\n", index);
692e192b24SSimon Glass 
70*abdc7b8aSSimon Glass 	return tpm_nv_write_value(dev, index, NULL, 0);
712e192b24SSimon Glass }
722e192b24SSimon Glass 
tpm_is_owned(struct udevice * dev)73*abdc7b8aSSimon Glass static int tpm_is_owned(struct udevice *dev)
742e192b24SSimon Glass {
752e192b24SSimon Glass 	uint8_t response[TPM_PUBEK_SIZE];
762e192b24SSimon Glass 	uint32_t result;
772e192b24SSimon Glass 
78*abdc7b8aSSimon Glass 	result = tpm_read_pubek(dev, response, sizeof(response));
792e192b24SSimon Glass 
802e192b24SSimon Glass 	return result != TPM_SUCCESS;
812e192b24SSimon Glass }
822e192b24SSimon Glass 
test_early_extend(struct udevice * dev)83*abdc7b8aSSimon Glass static int test_early_extend(struct udevice *dev)
842e192b24SSimon Glass {
852e192b24SSimon Glass 	uint8_t value_in[20];
862e192b24SSimon Glass 	uint8_t value_out[20];
872e192b24SSimon Glass 
882e192b24SSimon Glass 	printf("Testing earlyextend ...");
89*abdc7b8aSSimon Glass 	tpm_init(dev);
90*abdc7b8aSSimon Glass 	TPM_CHECK(tpm_startup(dev, TPM_ST_CLEAR));
91*abdc7b8aSSimon Glass 	TPM_CHECK(tpm_continue_self_test(dev));
92*abdc7b8aSSimon Glass 	TPM_CHECK(tpm_extend(dev, 1, value_in, value_out));
932e192b24SSimon Glass 	printf("done\n");
942e192b24SSimon Glass 	return 0;
952e192b24SSimon Glass }
962e192b24SSimon Glass 
test_early_nvram(struct udevice * dev)97*abdc7b8aSSimon Glass static int test_early_nvram(struct udevice *dev)
982e192b24SSimon Glass {
992e192b24SSimon Glass 	uint32_t x;
1002e192b24SSimon Glass 
1012e192b24SSimon Glass 	printf("Testing earlynvram ...");
102*abdc7b8aSSimon Glass 	tpm_init(dev);
103*abdc7b8aSSimon Glass 	TPM_CHECK(tpm_startup(dev, TPM_ST_CLEAR));
104*abdc7b8aSSimon Glass 	TPM_CHECK(tpm_continue_self_test(dev));
105*abdc7b8aSSimon Glass 	TPM_CHECK(tpm_tsc_physical_presence(dev, PRESENCE));
106*abdc7b8aSSimon Glass 	TPM_CHECK(tpm_nv_read_value(dev, INDEX0, (uint8_t *)&x, sizeof(x)));
1072e192b24SSimon Glass 	printf("done\n");
1082e192b24SSimon Glass 	return 0;
1092e192b24SSimon Glass }
1102e192b24SSimon Glass 
test_early_nvram2(struct udevice * dev)111*abdc7b8aSSimon Glass static int test_early_nvram2(struct udevice *dev)
1122e192b24SSimon Glass {
1132e192b24SSimon Glass 	uint32_t x;
1142e192b24SSimon Glass 
1152e192b24SSimon Glass 	printf("Testing earlynvram2 ...");
116*abdc7b8aSSimon Glass 	tpm_init(dev);
117*abdc7b8aSSimon Glass 	TPM_CHECK(tpm_startup(dev, TPM_ST_CLEAR));
118*abdc7b8aSSimon Glass 	TPM_CHECK(tpm_continue_self_test(dev));
119*abdc7b8aSSimon Glass 	TPM_CHECK(tpm_tsc_physical_presence(dev, PRESENCE));
120*abdc7b8aSSimon Glass 	TPM_CHECK(tpm_nv_write_value(dev, INDEX0, (uint8_t *)&x, sizeof(x)));
1212e192b24SSimon Glass 	printf("done\n");
1222e192b24SSimon Glass 	return 0;
1232e192b24SSimon Glass }
1242e192b24SSimon Glass 
test_enable(struct udevice * dev)125*abdc7b8aSSimon Glass static int test_enable(struct udevice *dev)
1262e192b24SSimon Glass {
1272e192b24SSimon Glass 	uint8_t disable = 0, deactivated = 0;
1282e192b24SSimon Glass 
1292e192b24SSimon Glass 	printf("Testing enable ...\n");
130*abdc7b8aSSimon Glass 	tpm_init(dev);
131*abdc7b8aSSimon Glass 	TPM_CHECK(TlclStartupIfNeeded(dev));
132*abdc7b8aSSimon Glass 	TPM_CHECK(tpm_self_test_full(dev));
133*abdc7b8aSSimon Glass 	TPM_CHECK(tpm_tsc_physical_presence(dev, PRESENCE));
134*abdc7b8aSSimon Glass 	TPM_CHECK(tpm_get_flags(dev, &disable, &deactivated, NULL));
1352e192b24SSimon Glass 	printf("\tdisable is %d, deactivated is %d\n", disable, deactivated);
136*abdc7b8aSSimon Glass 	TPM_CHECK(tpm_physical_enable(dev));
137*abdc7b8aSSimon Glass 	TPM_CHECK(tpm_physical_set_deactivated(dev, 0));
138*abdc7b8aSSimon Glass 	TPM_CHECK(tpm_get_flags(dev, &disable, &deactivated, NULL));
1392e192b24SSimon Glass 	printf("\tdisable is %d, deactivated is %d\n", disable, deactivated);
1402e192b24SSimon Glass 	if (disable == 1 || deactivated == 1)
1412e192b24SSimon Glass 		printf("\tfailed to enable or activate\n");
1422e192b24SSimon Glass 	printf("\tdone\n");
1432e192b24SSimon Glass 	return 0;
1442e192b24SSimon Glass }
1452e192b24SSimon Glass 
1462e192b24SSimon Glass #define reboot() do { \
1472e192b24SSimon Glass 	printf("\trebooting...\n"); \
1482e192b24SSimon Glass 	reset_cpu(0); \
1492e192b24SSimon Glass } while (0)
1502e192b24SSimon Glass 
test_fast_enable(struct udevice * dev)151*abdc7b8aSSimon Glass static int test_fast_enable(struct udevice *dev)
1522e192b24SSimon Glass {
1532e192b24SSimon Glass 	uint8_t disable = 0, deactivated = 0;
1542e192b24SSimon Glass 	int i;
1552e192b24SSimon Glass 
1562e192b24SSimon Glass 	printf("Testing fastenable ...\n");
157*abdc7b8aSSimon Glass 	tpm_init(dev);
158*abdc7b8aSSimon Glass 	TPM_CHECK(TlclStartupIfNeeded(dev));
159*abdc7b8aSSimon Glass 	TPM_CHECK(tpm_self_test_full(dev));
160*abdc7b8aSSimon Glass 	TPM_CHECK(tpm_tsc_physical_presence(dev, PRESENCE));
161*abdc7b8aSSimon Glass 	TPM_CHECK(tpm_get_flags(dev, &disable, &deactivated, NULL));
1622e192b24SSimon Glass 	printf("\tdisable is %d, deactivated is %d\n", disable, deactivated);
1632e192b24SSimon Glass 	for (i = 0; i < 2; i++) {
164*abdc7b8aSSimon Glass 		TPM_CHECK(tpm_force_clear(dev));
165*abdc7b8aSSimon Glass 		TPM_CHECK(tpm_get_flags(dev, &disable, &deactivated, NULL));
1662e192b24SSimon Glass 		printf("\tdisable is %d, deactivated is %d\n", disable,
1672e192b24SSimon Glass 		       deactivated);
1682e192b24SSimon Glass 		assert(disable == 1 && deactivated == 1);
169*abdc7b8aSSimon Glass 		TPM_CHECK(tpm_physical_enable(dev));
170*abdc7b8aSSimon Glass 		TPM_CHECK(tpm_physical_set_deactivated(dev, 0));
171*abdc7b8aSSimon Glass 		TPM_CHECK(tpm_get_flags(dev, &disable, &deactivated, NULL));
1722e192b24SSimon Glass 		printf("\tdisable is %d, deactivated is %d\n", disable,
1732e192b24SSimon Glass 		       deactivated);
1742e192b24SSimon Glass 		assert(disable == 0 && deactivated == 0);
1752e192b24SSimon Glass 	}
1762e192b24SSimon Glass 	printf("\tdone\n");
1772e192b24SSimon Glass 	return 0;
1782e192b24SSimon Glass }
1792e192b24SSimon Glass 
test_global_lock(struct udevice * dev)180*abdc7b8aSSimon Glass static int test_global_lock(struct udevice *dev)
1812e192b24SSimon Glass {
1822e192b24SSimon Glass 	uint32_t zero = 0;
1832e192b24SSimon Glass 	uint32_t result;
1842e192b24SSimon Glass 	uint32_t x;
1852e192b24SSimon Glass 
1862e192b24SSimon Glass 	printf("Testing globallock ...\n");
187*abdc7b8aSSimon Glass 	tpm_init(dev);
188*abdc7b8aSSimon Glass 	TPM_CHECK(TlclStartupIfNeeded(dev));
189*abdc7b8aSSimon Glass 	TPM_CHECK(tpm_self_test_full(dev));
190*abdc7b8aSSimon Glass 	TPM_CHECK(tpm_tsc_physical_presence(dev, PRESENCE));
191*abdc7b8aSSimon Glass 	TPM_CHECK(tpm_nv_read_value(dev, INDEX0, (uint8_t *)&x, sizeof(x)));
192*abdc7b8aSSimon Glass 	TPM_CHECK(tpm_nv_write_value(dev, INDEX0, (uint8_t *)&zero,
1932e192b24SSimon Glass 				     sizeof(uint32_t)));
194*abdc7b8aSSimon Glass 	TPM_CHECK(tpm_nv_read_value(dev, INDEX1, (uint8_t *)&x, sizeof(x)));
195*abdc7b8aSSimon Glass 	TPM_CHECK(tpm_nv_write_value(dev, INDEX1, (uint8_t *)&zero,
1962e192b24SSimon Glass 				     sizeof(uint32_t)));
197*abdc7b8aSSimon Glass 	TPM_CHECK(tpm_set_global_lock(dev));
1982e192b24SSimon Glass 	/* Verifies that write to index0 fails */
1992e192b24SSimon Glass 	x = 1;
200*abdc7b8aSSimon Glass 	result = tpm_nv_write_value(dev, INDEX0, (uint8_t *)&x, sizeof(x));
2012e192b24SSimon Glass 	assert(result == TPM_AREA_LOCKED);
202*abdc7b8aSSimon Glass 	TPM_CHECK(tpm_nv_read_value(dev, INDEX0, (uint8_t *)&x, sizeof(x)));
2032e192b24SSimon Glass 	assert(x == 0);
2042e192b24SSimon Glass 	/* Verifies that write to index1 is still possible */
2052e192b24SSimon Glass 	x = 2;
206*abdc7b8aSSimon Glass 	TPM_CHECK(tpm_nv_write_value(dev, INDEX1, (uint8_t *)&x, sizeof(x)));
207*abdc7b8aSSimon Glass 	TPM_CHECK(tpm_nv_read_value(dev, INDEX1, (uint8_t *)&x, sizeof(x)));
2082e192b24SSimon Glass 	assert(x == 2);
2092e192b24SSimon Glass 	/* Turns off PP */
210*abdc7b8aSSimon Glass 	tpm_tsc_physical_presence(dev, PHYS_PRESENCE);
2112e192b24SSimon Glass 	/* Verifies that write to index1 fails */
2122e192b24SSimon Glass 	x = 3;
213*abdc7b8aSSimon Glass 	result = tpm_nv_write_value(dev, INDEX1, (uint8_t *)&x, sizeof(x));
2142e192b24SSimon Glass 	assert(result == TPM_BAD_PRESENCE);
215*abdc7b8aSSimon Glass 	TPM_CHECK(tpm_nv_read_value(dev, INDEX1, (uint8_t *)&x, sizeof(x)));
2162e192b24SSimon Glass 	assert(x == 2);
2172e192b24SSimon Glass 	printf("\tdone\n");
2182e192b24SSimon Glass 	return 0;
2192e192b24SSimon Glass }
2202e192b24SSimon Glass 
test_lock(struct udevice * dev)221*abdc7b8aSSimon Glass static int test_lock(struct udevice *dev)
2222e192b24SSimon Glass {
2232e192b24SSimon Glass 	printf("Testing lock ...\n");
224*abdc7b8aSSimon Glass 	tpm_init(dev);
225*abdc7b8aSSimon Glass 	tpm_startup(dev, TPM_ST_CLEAR);
226*abdc7b8aSSimon Glass 	tpm_self_test_full(dev);
227*abdc7b8aSSimon Glass 	tpm_tsc_physical_presence(dev, PRESENCE);
228*abdc7b8aSSimon Glass 	tpm_nv_write_value_lock(dev, INDEX0);
2292e192b24SSimon Glass 	printf("\tLocked 0x%x\n", INDEX0);
2302e192b24SSimon Glass 	printf("\tdone\n");
2312e192b24SSimon Glass 	return 0;
2322e192b24SSimon Glass }
2332e192b24SSimon Glass 
initialise_spaces(struct udevice * dev)234*abdc7b8aSSimon Glass static void initialise_spaces(struct udevice *dev)
2352e192b24SSimon Glass {
2362e192b24SSimon Glass 	uint32_t zero = 0;
2372e192b24SSimon Glass 	uint32_t perm = TPM_NV_PER_WRITE_STCLEAR | TPM_NV_PER_PPWRITE;
2382e192b24SSimon Glass 
2392e192b24SSimon Glass 	printf("\tInitialising spaces\n");
240*abdc7b8aSSimon Glass 	tpm_nv_set_locked(dev);  /* useful only the first time */
241*abdc7b8aSSimon Glass 	tpm_nv_define_space(dev, INDEX0, perm, 4);
242*abdc7b8aSSimon Glass 	tpm_nv_write_value(dev, INDEX0, (uint8_t *)&zero, 4);
243*abdc7b8aSSimon Glass 	tpm_nv_define_space(dev, INDEX1, perm, 4);
244*abdc7b8aSSimon Glass 	tpm_nv_write_value(dev, INDEX1, (uint8_t *)&zero, 4);
245*abdc7b8aSSimon Glass 	tpm_nv_define_space(dev, INDEX2, perm, 4);
246*abdc7b8aSSimon Glass 	tpm_nv_write_value(dev, INDEX2, (uint8_t *)&zero, 4);
247*abdc7b8aSSimon Glass 	tpm_nv_define_space(dev, INDEX3, perm, 4);
248*abdc7b8aSSimon Glass 	tpm_nv_write_value(dev, INDEX3, (uint8_t *)&zero, 4);
2492e192b24SSimon Glass 	perm = TPM_NV_PER_READ_STCLEAR | TPM_NV_PER_WRITE_STCLEAR |
2502e192b24SSimon Glass 		TPM_NV_PER_PPWRITE;
251*abdc7b8aSSimon Glass 	tpm_nv_define_space(dev, INDEX_INITIALISED, perm, 1);
2522e192b24SSimon Glass }
2532e192b24SSimon Glass 
test_readonly(struct udevice * dev)254*abdc7b8aSSimon Glass static int test_readonly(struct udevice *dev)
2552e192b24SSimon Glass {
2562e192b24SSimon Glass 	uint8_t c;
2572e192b24SSimon Glass 	uint32_t index_0, index_1, index_2, index_3;
2582e192b24SSimon Glass 	int read0, read1, read2, read3;
2592e192b24SSimon Glass 
2602e192b24SSimon Glass 	printf("Testing readonly ...\n");
261*abdc7b8aSSimon Glass 	tpm_init(dev);
262*abdc7b8aSSimon Glass 	tpm_startup(dev, TPM_ST_CLEAR);
263*abdc7b8aSSimon Glass 	tpm_self_test_full(dev);
264*abdc7b8aSSimon Glass 	tpm_tsc_physical_presence(dev, PRESENCE);
2652e192b24SSimon Glass 	/*
2662e192b24SSimon Glass 	 * Checks if initialisation has completed by trying to read-lock a
2672e192b24SSimon Glass 	 * space that's created at the end of initialisation
2682e192b24SSimon Glass 	 */
269*abdc7b8aSSimon Glass 	if (tpm_nv_read_value(dev, INDEX_INITIALISED, &c, 0) == TPM_BADINDEX) {
2702e192b24SSimon Glass 		/* The initialisation did not complete */
271*abdc7b8aSSimon Glass 		initialise_spaces(dev);
2722e192b24SSimon Glass 	}
2732e192b24SSimon Glass 
2742e192b24SSimon Glass 	/* Checks if spaces are OK or messed up */
275*abdc7b8aSSimon Glass 	read0 = tpm_nv_read_value(dev, INDEX0, (uint8_t *)&index_0,
276*abdc7b8aSSimon Glass 				  sizeof(index_0));
277*abdc7b8aSSimon Glass 	read1 = tpm_nv_read_value(dev, INDEX1, (uint8_t *)&index_1,
278*abdc7b8aSSimon Glass 				  sizeof(index_1));
279*abdc7b8aSSimon Glass 	read2 = tpm_nv_read_value(dev, INDEX2, (uint8_t *)&index_2,
280*abdc7b8aSSimon Glass 				  sizeof(index_2));
281*abdc7b8aSSimon Glass 	read3 = tpm_nv_read_value(dev, INDEX3, (uint8_t *)&index_3,
282*abdc7b8aSSimon Glass 				  sizeof(index_3));
2832e192b24SSimon Glass 	if (read0 || read1 || read2 || read3) {
2842e192b24SSimon Glass 		printf("Invalid contents\n");
2852e192b24SSimon Glass 		return 0;
2862e192b24SSimon Glass 	}
2872e192b24SSimon Glass 
2882e192b24SSimon Glass 	/*
2892e192b24SSimon Glass 	 * Writes space, and locks it.  Then attempts to write again.
2902e192b24SSimon Glass 	 * I really wish I could use the imperative.
2912e192b24SSimon Glass 	 */
2922e192b24SSimon Glass 	index_0 += 1;
293*abdc7b8aSSimon Glass 	if (tpm_nv_write_value(dev, INDEX0, (uint8_t *)&index_0,
294*abdc7b8aSSimon Glass 			       sizeof(index_0) !=
2952e192b24SSimon Glass 		TPM_SUCCESS)) {
2969b643e31SMasahiro Yamada 		pr_err("\tcould not write index 0\n");
2972e192b24SSimon Glass 	}
298*abdc7b8aSSimon Glass 	tpm_nv_write_value_lock(dev, INDEX0);
299*abdc7b8aSSimon Glass 	if (tpm_nv_write_value(dev, INDEX0, (uint8_t *)&index_0,
300*abdc7b8aSSimon Glass 			       sizeof(index_0)) ==
3012e192b24SSimon Glass 			TPM_SUCCESS)
3029b643e31SMasahiro Yamada 		pr_err("\tindex 0 is not locked\n");
3032e192b24SSimon Glass 
3042e192b24SSimon Glass 	printf("\tdone\n");
3052e192b24SSimon Glass 	return 0;
3062e192b24SSimon Glass }
3072e192b24SSimon Glass 
test_redefine_unowned(struct udevice * dev)308*abdc7b8aSSimon Glass static int test_redefine_unowned(struct udevice *dev)
3092e192b24SSimon Glass {
3102e192b24SSimon Glass 	uint32_t perm;
3112e192b24SSimon Glass 	uint32_t result;
3122e192b24SSimon Glass 	uint32_t x;
3132e192b24SSimon Glass 
3142e192b24SSimon Glass 	printf("Testing redefine_unowned ...");
315*abdc7b8aSSimon Glass 	tpm_init(dev);
316*abdc7b8aSSimon Glass 	TPM_CHECK(TlclStartupIfNeeded(dev));
317*abdc7b8aSSimon Glass 	TPM_CHECK(tpm_self_test_full(dev));
318*abdc7b8aSSimon Glass 	TPM_CHECK(tpm_tsc_physical_presence(dev, PRESENCE));
319*abdc7b8aSSimon Glass 	assert(!tpm_is_owned(dev));
3202e192b24SSimon Glass 
3212e192b24SSimon Glass 	/* Ensures spaces exist. */
322*abdc7b8aSSimon Glass 	TPM_CHECK(tpm_nv_read_value(dev, INDEX0, (uint8_t *)&x, sizeof(x)));
323*abdc7b8aSSimon Glass 	TPM_CHECK(tpm_nv_read_value(dev, INDEX1, (uint8_t *)&x, sizeof(x)));
3242e192b24SSimon Glass 
3252e192b24SSimon Glass 	/* Redefines spaces a couple of times. */
3262e192b24SSimon Glass 	perm = TPM_NV_PER_PPWRITE | TPM_NV_PER_GLOBALLOCK;
327*abdc7b8aSSimon Glass 	TPM_CHECK(tpm_nv_define_space(dev, INDEX0, perm, 2 * sizeof(uint32_t)));
328*abdc7b8aSSimon Glass 	TPM_CHECK(tpm_nv_define_space(dev, INDEX0, perm, sizeof(uint32_t)));
3292e192b24SSimon Glass 	perm = TPM_NV_PER_PPWRITE;
330*abdc7b8aSSimon Glass 	TPM_CHECK(tpm_nv_define_space(dev, INDEX1, perm, 2 * sizeof(uint32_t)));
331*abdc7b8aSSimon Glass 	TPM_CHECK(tpm_nv_define_space(dev, INDEX1, perm, sizeof(uint32_t)));
3322e192b24SSimon Glass 
3332e192b24SSimon Glass 	/* Sets the global lock */
334*abdc7b8aSSimon Glass 	tpm_set_global_lock(dev);
3352e192b24SSimon Glass 
3362e192b24SSimon Glass 	/* Verifies that index0 cannot be redefined */
337*abdc7b8aSSimon Glass 	result = tpm_nv_define_space(dev, INDEX0, perm, sizeof(uint32_t));
3382e192b24SSimon Glass 	assert(result == TPM_AREA_LOCKED);
3392e192b24SSimon Glass 
3402e192b24SSimon Glass 	/* Checks that index1 can */
341*abdc7b8aSSimon Glass 	TPM_CHECK(tpm_nv_define_space(dev, INDEX1, perm, 2 * sizeof(uint32_t)));
342*abdc7b8aSSimon Glass 	TPM_CHECK(tpm_nv_define_space(dev, INDEX1, perm, sizeof(uint32_t)));
3432e192b24SSimon Glass 
3442e192b24SSimon Glass 	/* Turns off PP */
345*abdc7b8aSSimon Glass 	tpm_tsc_physical_presence(dev, PHYS_PRESENCE);
3462e192b24SSimon Glass 
3472e192b24SSimon Glass 	/* Verifies that neither index0 nor index1 can be redefined */
348*abdc7b8aSSimon Glass 	result = tpm_nv_define_space(dev, INDEX0, perm, sizeof(uint32_t));
3492e192b24SSimon Glass 	assert(result == TPM_BAD_PRESENCE);
350*abdc7b8aSSimon Glass 	result = tpm_nv_define_space(dev, INDEX1, perm, sizeof(uint32_t));
3512e192b24SSimon Glass 	assert(result == TPM_BAD_PRESENCE);
3522e192b24SSimon Glass 
3532e192b24SSimon Glass 	printf("done\n");
3542e192b24SSimon Glass 	return 0;
3552e192b24SSimon Glass }
3562e192b24SSimon Glass 
3572e192b24SSimon Glass #define PERMPPGL (TPM_NV_PER_PPWRITE | TPM_NV_PER_GLOBALLOCK)
3582e192b24SSimon Glass #define PERMPP TPM_NV_PER_PPWRITE
3592e192b24SSimon Glass 
test_space_perm(struct udevice * dev)360*abdc7b8aSSimon Glass static int test_space_perm(struct udevice *dev)
3612e192b24SSimon Glass {
3622e192b24SSimon Glass 	uint32_t perm;
3632e192b24SSimon Glass 
3642e192b24SSimon Glass 	printf("Testing spaceperm ...");
365*abdc7b8aSSimon Glass 	tpm_init(dev);
366*abdc7b8aSSimon Glass 	TPM_CHECK(TlclStartupIfNeeded(dev));
367*abdc7b8aSSimon Glass 	TPM_CHECK(tpm_continue_self_test(dev));
368*abdc7b8aSSimon Glass 	TPM_CHECK(tpm_tsc_physical_presence(dev, PRESENCE));
369*abdc7b8aSSimon Glass 	TPM_CHECK(tpm_get_permissions(dev, INDEX0, &perm));
3702e192b24SSimon Glass 	assert((perm & PERMPPGL) == PERMPPGL);
371*abdc7b8aSSimon Glass 	TPM_CHECK(tpm_get_permissions(dev, INDEX1, &perm));
3722e192b24SSimon Glass 	assert((perm & PERMPP) == PERMPP);
3732e192b24SSimon Glass 	printf("done\n");
3742e192b24SSimon Glass 	return 0;
3752e192b24SSimon Glass }
3762e192b24SSimon Glass 
test_startup(struct udevice * dev)377*abdc7b8aSSimon Glass static int test_startup(struct udevice *dev)
3782e192b24SSimon Glass {
3792e192b24SSimon Glass 	uint32_t result;
380*abdc7b8aSSimon Glass 
3812e192b24SSimon Glass 	printf("Testing startup ...\n");
3822e192b24SSimon Glass 
383*abdc7b8aSSimon Glass 	tpm_init(dev);
384*abdc7b8aSSimon Glass 	result = tpm_startup(dev, TPM_ST_CLEAR);
3852e192b24SSimon Glass 	if (result != 0 && result != TPM_INVALID_POSTINIT)
3862e192b24SSimon Glass 		printf("\ttpm startup failed with 0x%x\n", result);
387*abdc7b8aSSimon Glass 	result = tpm_get_flags(dev, NULL, NULL, NULL);
3882e192b24SSimon Glass 	if (result != 0)
3892e192b24SSimon Glass 		printf("\ttpm getflags failed with 0x%x\n", result);
3902e192b24SSimon Glass 	printf("\texecuting SelfTestFull\n");
391*abdc7b8aSSimon Glass 	tpm_self_test_full(dev);
392*abdc7b8aSSimon Glass 	result = tpm_get_flags(dev, NULL, NULL, NULL);
3932e192b24SSimon Glass 	if (result != 0)
3942e192b24SSimon Glass 		printf("\ttpm getflags failed with 0x%x\n", result);
3952e192b24SSimon Glass 	printf("\tdone\n");
3962e192b24SSimon Glass 	return 0;
3972e192b24SSimon Glass }
3982e192b24SSimon Glass 
3992e192b24SSimon Glass /*
4002e192b24SSimon Glass  * Runs [op] and ensures it returns success and doesn't run longer than
4012e192b24SSimon Glass  * [time_limit] in milliseconds.
4022e192b24SSimon Glass  */
4032e192b24SSimon Glass #define TTPM_CHECK(op, time_limit) do { \
4042e192b24SSimon Glass 	ulong start, time; \
4052e192b24SSimon Glass 	uint32_t __result; \
4062e192b24SSimon Glass 	\
4072e192b24SSimon Glass 	start = get_timer(0); \
4082e192b24SSimon Glass 	__result = op; \
4092e192b24SSimon Glass 	if (__result != TPM_SUCCESS) { \
4102e192b24SSimon Glass 		printf("\t" #op ": error 0x%x\n", __result); \
4112e192b24SSimon Glass 		return -1; \
4122e192b24SSimon Glass 	} \
4132e192b24SSimon Glass 	time = get_timer(start); \
4142e192b24SSimon Glass 	printf("\t" #op ": %lu ms\n", time); \
4152e192b24SSimon Glass 	if (time > (ulong)time_limit) { \
4162e192b24SSimon Glass 		printf("\t" #op " exceeded " #time_limit " ms\n"); \
4172e192b24SSimon Glass 	} \
4182e192b24SSimon Glass } while (0)
4192e192b24SSimon Glass 
4202e192b24SSimon Glass 
test_timing(struct udevice * dev)421*abdc7b8aSSimon Glass static int test_timing(struct udevice *dev)
4222e192b24SSimon Glass {
4232e192b24SSimon Glass 	uint8_t in[20], out[20];
424*abdc7b8aSSimon Glass 	uint32_t x;
4252e192b24SSimon Glass 
4262e192b24SSimon Glass 	printf("Testing timing ...");
427*abdc7b8aSSimon Glass 	tpm_init(dev);
428*abdc7b8aSSimon Glass 	TTPM_CHECK(TlclStartupIfNeeded(dev), 50);
429*abdc7b8aSSimon Glass 	TTPM_CHECK(tpm_continue_self_test(dev), 100);
430*abdc7b8aSSimon Glass 	TTPM_CHECK(tpm_self_test_full(dev), 1000);
431*abdc7b8aSSimon Glass 	TTPM_CHECK(tpm_tsc_physical_presence(dev, PRESENCE), 100);
432*abdc7b8aSSimon Glass 	TTPM_CHECK(tpm_nv_write_value(dev, INDEX0, (uint8_t *)&x, sizeof(x)),
433*abdc7b8aSSimon Glass 		   100);
434*abdc7b8aSSimon Glass 	TTPM_CHECK(tpm_nv_read_value(dev, INDEX0, (uint8_t *)&x, sizeof(x)),
435*abdc7b8aSSimon Glass 		   100);
436*abdc7b8aSSimon Glass 	TTPM_CHECK(tpm_extend(dev, 0, in, out), 200);
437*abdc7b8aSSimon Glass 	TTPM_CHECK(tpm_set_global_lock(dev), 50);
438*abdc7b8aSSimon Glass 	TTPM_CHECK(tpm_tsc_physical_presence(dev, PHYS_PRESENCE), 100);
4392e192b24SSimon Glass 	printf("done\n");
4402e192b24SSimon Glass 	return 0;
4412e192b24SSimon Glass }
4422e192b24SSimon Glass 
4432e192b24SSimon Glass #define TPM_MAX_NV_WRITES_NOOWNER 64
4442e192b24SSimon Glass 
test_write_limit(struct udevice * dev)445*abdc7b8aSSimon Glass static int test_write_limit(struct udevice *dev)
4462e192b24SSimon Glass {
4472e192b24SSimon Glass 	uint32_t result;
448*abdc7b8aSSimon Glass 	int i;
4492e192b24SSimon Glass 
450*abdc7b8aSSimon Glass 	printf("Testing writelimit ...\n");
451*abdc7b8aSSimon Glass 	tpm_init(dev);
452*abdc7b8aSSimon Glass 	TPM_CHECK(TlclStartupIfNeeded(dev));
453*abdc7b8aSSimon Glass 	TPM_CHECK(tpm_self_test_full(dev));
454*abdc7b8aSSimon Glass 	TPM_CHECK(tpm_tsc_physical_presence(dev, PRESENCE));
455*abdc7b8aSSimon Glass 	TPM_CHECK(tpm_force_clear(dev));
456*abdc7b8aSSimon Glass 	TPM_CHECK(tpm_physical_enable(dev));
457*abdc7b8aSSimon Glass 	TPM_CHECK(tpm_physical_set_deactivated(dev, 0));
4582e192b24SSimon Glass 
4592e192b24SSimon Glass 	for (i = 0; i < TPM_MAX_NV_WRITES_NOOWNER + 2; i++) {
4602e192b24SSimon Glass 		printf("\twriting %d\n", i);
461*abdc7b8aSSimon Glass 		result = tpm_nv_write_value(dev, INDEX0, (uint8_t *)&i,
462*abdc7b8aSSimon Glass 					    sizeof(i));
4632e192b24SSimon Glass 		switch (result) {
4642e192b24SSimon Glass 		case TPM_SUCCESS:
4652e192b24SSimon Glass 			break;
4662e192b24SSimon Glass 		case TPM_MAXNVWRITES:
4672e192b24SSimon Glass 			assert(i >= TPM_MAX_NV_WRITES_NOOWNER);
4682e192b24SSimon Glass 		default:
4699b643e31SMasahiro Yamada 			pr_err("\tunexpected error code %d (0x%x)\n",
4702e192b24SSimon Glass 			      result, result);
4712e192b24SSimon Glass 		}
4722e192b24SSimon Glass 	}
4732e192b24SSimon Glass 
4742e192b24SSimon Glass 	/* Reset write count */
475*abdc7b8aSSimon Glass 	TPM_CHECK(tpm_force_clear(dev));
476*abdc7b8aSSimon Glass 	TPM_CHECK(tpm_physical_enable(dev));
477*abdc7b8aSSimon Glass 	TPM_CHECK(tpm_physical_set_deactivated(dev, 0));
4782e192b24SSimon Glass 
4792e192b24SSimon Glass 	/* Try writing again. */
480*abdc7b8aSSimon Glass 	TPM_CHECK(tpm_nv_write_value(dev, INDEX0, (uint8_t *)&i, sizeof(i)));
4812e192b24SSimon Glass 	printf("\tdone\n");
4822e192b24SSimon Glass 	return 0;
4832e192b24SSimon Glass }
4842e192b24SSimon Glass 
4852e192b24SSimon Glass #define VOIDTEST(XFUNC) \
4862e192b24SSimon Glass 	int do_test_##XFUNC(cmd_tbl_t *cmd_tbl, int flag, int argc, \
4872e192b24SSimon Glass 	char * const argv[]) \
4882e192b24SSimon Glass 	{ \
489*abdc7b8aSSimon Glass 		struct udevice *dev; \
490*abdc7b8aSSimon Glass 		int ret; \
491*abdc7b8aSSimon Glass \
492*abdc7b8aSSimon Glass 		ret = get_tpm(&dev); \
493*abdc7b8aSSimon Glass 		if (ret) \
494*abdc7b8aSSimon Glass 			return ret; \
495*abdc7b8aSSimon Glass 		return test_##XFUNC(dev); \
4962e192b24SSimon Glass 	}
4972e192b24SSimon Glass 
4982e192b24SSimon Glass #define VOIDENT(XNAME) \
4992e192b24SSimon Glass 	U_BOOT_CMD_MKENT(XNAME, 0, 1, do_test_##XNAME, "", ""),
5002e192b24SSimon Glass 
5012e192b24SSimon Glass VOIDTEST(early_extend)
5022e192b24SSimon Glass VOIDTEST(early_nvram)
5032e192b24SSimon Glass VOIDTEST(early_nvram2)
5042e192b24SSimon Glass VOIDTEST(enable)
5052e192b24SSimon Glass VOIDTEST(fast_enable)
5062e192b24SSimon Glass VOIDTEST(global_lock)
5072e192b24SSimon Glass VOIDTEST(lock)
5082e192b24SSimon Glass VOIDTEST(readonly)
5092e192b24SSimon Glass VOIDTEST(redefine_unowned)
5102e192b24SSimon Glass VOIDTEST(space_perm)
5112e192b24SSimon Glass VOIDTEST(startup)
5122e192b24SSimon Glass VOIDTEST(timing)
5132e192b24SSimon Glass VOIDTEST(write_limit)
5142e192b24SSimon Glass VOIDTEST(timer)
5152e192b24SSimon Glass 
5162e192b24SSimon Glass static cmd_tbl_t cmd_cros_tpm_sub[] = {
5172e192b24SSimon Glass 	VOIDENT(early_extend)
5182e192b24SSimon Glass 	VOIDENT(early_nvram)
5192e192b24SSimon Glass 	VOIDENT(early_nvram2)
5202e192b24SSimon Glass 	VOIDENT(enable)
5212e192b24SSimon Glass 	VOIDENT(fast_enable)
5222e192b24SSimon Glass 	VOIDENT(global_lock)
5232e192b24SSimon Glass 	VOIDENT(lock)
5242e192b24SSimon Glass 	VOIDENT(readonly)
5252e192b24SSimon Glass 	VOIDENT(redefine_unowned)
5262e192b24SSimon Glass 	VOIDENT(space_perm)
5272e192b24SSimon Glass 	VOIDENT(startup)
5282e192b24SSimon Glass 	VOIDENT(timing)
5292e192b24SSimon Glass 	VOIDENT(write_limit)
5302e192b24SSimon Glass 	VOIDENT(timer)
5312e192b24SSimon Glass };
5322e192b24SSimon Glass 
do_tpmtest(cmd_tbl_t * cmdtp,int flag,int argc,char * const argv[])5332e192b24SSimon Glass static int do_tpmtest(cmd_tbl_t *cmdtp, int flag, int argc, char * const argv[])
5342e192b24SSimon Glass {
5352e192b24SSimon Glass 	cmd_tbl_t *c;
5360427b9c5SStefan Brüns 	int i;
5372e192b24SSimon Glass 
5382e192b24SSimon Glass 	printf("argc = %d, argv = ", argc);
5392e192b24SSimon Glass 
5402e192b24SSimon Glass 	for (i = 0; i < argc; i++)
5412e192b24SSimon Glass 		printf(" %s", argv[i]);
5420427b9c5SStefan Brüns 
5432e192b24SSimon Glass 	printf("\n------\n");
5440427b9c5SStefan Brüns 
5452e192b24SSimon Glass 	argc--;
5462e192b24SSimon Glass 	argv++;
5472e192b24SSimon Glass 	c = find_cmd_tbl(argv[0], cmd_cros_tpm_sub,
5482e192b24SSimon Glass 			 ARRAY_SIZE(cmd_cros_tpm_sub));
5492e192b24SSimon Glass 	return c ? c->cmd(cmdtp, flag, argc, argv) : cmd_usage(cmdtp);
5502e192b24SSimon Glass }
5512e192b24SSimon Glass 
5522e192b24SSimon Glass U_BOOT_CMD(tpmtest, 2, 1, do_tpmtest, "TPM tests",
5532e192b24SSimon Glass 	"\n\tearly_extend\n"
5542e192b24SSimon Glass 	"\tearly_nvram\n"
5552e192b24SSimon Glass 	"\tearly_nvram2\n"
5562e192b24SSimon Glass 	"\tenable\n"
5572e192b24SSimon Glass 	"\tfast_enable\n"
5582e192b24SSimon Glass 	"\tglobal_lock\n"
5592e192b24SSimon Glass 	"\tlock\n"
5602e192b24SSimon Glass 	"\treadonly\n"
5612e192b24SSimon Glass 	"\tredefine_unowned\n"
5622e192b24SSimon Glass 	"\tspace_perm\n"
5632e192b24SSimon Glass 	"\tstartup\n"
5642e192b24SSimon Glass 	"\ttiming\n"
5652e192b24SSimon Glass 	"\twrite_limit\n");
566