tpm.h 12.7 KB
Newer Older
L
Linus Torvalds 已提交
1 2
/*
 * Copyright (C) 2004 IBM Corporation
J
Jarkko Sakkinen 已提交
3
 * Copyright (C) 2015 Intel Corporation
L
Linus Torvalds 已提交
4 5 6 7 8 9 10
 *
 * Authors:
 * Leendert van Doorn <leendert@watson.ibm.com>
 * Dave Safford <safford@watson.ibm.com>
 * Reiner Sailer <sailer@watson.ibm.com>
 * Kylene Hall <kjhall@us.ibm.com>
 *
K
Kent Yoder 已提交
11
 * Maintained by: <tpmdd-devel@lists.sourceforge.net>
L
Linus Torvalds 已提交
12 13
 *
 * Device driver for TCG/TCPA TPM (trusted platform module).
14
 * Specifications at www.trustedcomputinggroup.org
L
Linus Torvalds 已提交
15 16 17 18 19
 *
 * This program is free software; you can redistribute it and/or
 * modify it under the terms of the GNU General Public License as
 * published by the Free Software Foundation, version 2 of the
 * License.
20
 *
L
Linus Torvalds 已提交
21 22 23 24
 */
#include <linux/module.h>
#include <linux/delay.h>
#include <linux/fs.h>
25
#include <linux/mutex.h>
26
#include <linux/sched.h>
27
#include <linux/platform_device.h>
A
Andrew Morton 已提交
28
#include <linux/io.h>
R
Rajiv Andrade 已提交
29
#include <linux/tpm.h>
30
#include <linux/acpi.h>
J
Jarkko Sakkinen 已提交
31
#include <linux/cdev.h>
J
Jarkko Sakkinen 已提交
32
#include <linux/highmem.h>
L
Linus Torvalds 已提交
33

34 35 36 37
enum tpm_const {
	TPM_MINOR = 224,	/* officially assigned */
	TPM_BUFSIZE = 4096,
	TPM_NUM_DEVICES = 256,
38
	TPM_RETRY = 50,		/* 5 seconds */
39 40
};

41 42
enum tpm_timeout {
	TPM_TIMEOUT = 5,	/* msecs */
43
	TPM_TIMEOUT_RETRY = 100 /* msecs */
44
};
L
Linus Torvalds 已提交
45 46

/* TPM addresses */
47
enum tpm_addr {
48
	TPM_SUPERIO_ADDR = 0x2E,
49 50 51
	TPM_ADDR = 0x4E,
};

52 53 54 55 56 57 58 59
/* Indexes the duration array */
enum tpm_duration {
	TPM_SHORT = 0,
	TPM_MEDIUM = 1,
	TPM_LONG = 2,
	TPM_UNDEFINED,
};

60
#define TPM_WARN_RETRY          0x800
61
#define TPM_WARN_DOING_SELFTEST 0x802
62 63
#define TPM_ERR_DEACTIVATED     0x6
#define TPM_ERR_DISABLED        0x7
64
#define TPM_ERR_INVALID_POSTINIT 38
65

R
Rajiv Andrade 已提交
66
#define TPM_HEADER_SIZE		10
J
Jarkko Sakkinen 已提交
67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85

enum tpm2_const {
	TPM2_PLATFORM_PCR	= 24,
	TPM2_PCR_SELECT_MIN	= ((TPM2_PLATFORM_PCR + 7) / 8),
	TPM2_TIMEOUT_A		= 750,
	TPM2_TIMEOUT_B		= 2000,
	TPM2_TIMEOUT_C		= 200,
	TPM2_TIMEOUT_D		= 30,
	TPM2_DURATION_SHORT	= 20,
	TPM2_DURATION_MEDIUM	= 750,
	TPM2_DURATION_LONG	= 2000,
};

enum tpm2_structures {
	TPM2_ST_NO_SESSIONS	= 0x8001,
	TPM2_ST_SESSIONS	= 0x8002,
};

enum tpm2_return_codes {
86 87
	TPM2_RC_HASH		= 0x0083, /* RC_FMT1 */
	TPM2_RC_INITIALIZE	= 0x0100, /* RC_VER1 */
J
Jarkko Sakkinen 已提交
88
	TPM2_RC_DISABLED	= 0x0120,
89
	TPM2_RC_TESTING		= 0x090A, /* RC_WARN */
J
Jarkko Sakkinen 已提交
90 91 92 93
};

enum tpm2_algorithms {
	TPM2_ALG_SHA1		= 0x0004,
J
Jarkko Sakkinen 已提交
94 95
	TPM2_ALG_KEYEDHASH	= 0x0008,
	TPM2_ALG_SHA256		= 0x000B,
96 97 98 99
	TPM2_ALG_SHA384		= 0x000C,
	TPM2_ALG_SHA512		= 0x000D,
	TPM2_ALG_NULL		= 0x0010,
	TPM2_ALG_SM3_256	= 0x0012,
J
Jarkko Sakkinen 已提交
100 101 102 103 104 105 106
};

enum tpm2_command_codes {
	TPM2_CC_FIRST		= 0x011F,
	TPM2_CC_SELF_TEST	= 0x0143,
	TPM2_CC_STARTUP		= 0x0144,
	TPM2_CC_SHUTDOWN	= 0x0145,
J
Jarkko Sakkinen 已提交
107 108 109 110
	TPM2_CC_CREATE		= 0x0153,
	TPM2_CC_LOAD		= 0x0157,
	TPM2_CC_UNSEAL		= 0x015E,
	TPM2_CC_FLUSH_CONTEXT	= 0x0165,
J
Jarkko Sakkinen 已提交
111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130
	TPM2_CC_GET_CAPABILITY	= 0x017A,
	TPM2_CC_GET_RANDOM	= 0x017B,
	TPM2_CC_PCR_READ	= 0x017E,
	TPM2_CC_PCR_EXTEND	= 0x0182,
	TPM2_CC_LAST		= 0x018F,
};

enum tpm2_permanent_handles {
	TPM2_RS_PW		= 0x40000009,
};

enum tpm2_capabilities {
	TPM2_CAP_TPM_PROPERTIES = 6,
};

enum tpm2_startup_types {
	TPM2_SU_CLEAR	= 0x0000,
	TPM2_SU_STATE	= 0x0001,
};

131 132 133 134 135 136 137
enum tpm2_start_method {
	TPM2_START_ACPI = 2,
	TPM2_START_FIFO = 6,
	TPM2_START_CRB = 7,
	TPM2_START_CRB_WITH_ACPI = 8,
};

L
Linus Torvalds 已提交
138 139 140
struct tpm_chip;

struct tpm_vendor_specific {
141 142 143
	void __iomem *iobase;		/* ioremapped address */
	unsigned long base;		/* TPM base address */

144 145
	int irq;

146 147
	int region_size;
	int have_region;
L
Linus Torvalds 已提交
148

149 150
	struct list_head list;
	int locality;
151
	unsigned long timeout_a, timeout_b, timeout_c, timeout_d; /* jiffies */
152
	bool timeout_adjusted;
153
	unsigned long duration[3]; /* jiffies */
154
	bool duration_adjusted;
155
	void *priv;
156 157 158

	wait_queue_head_t read_queue;
	wait_queue_head_t int_queue;
S
Stefan Berger 已提交
159 160

	u16 manufacturer_id;
L
Linus Torvalds 已提交
161 162
};

163
#define TPM_VPRIV(c)     ((c)->vendor.priv)
164

S
Stefan Berger 已提交
165
#define TPM_VID_INTEL    0x8086
166 167
#define TPM_VID_WINBOND  0x1050
#define TPM_VID_STM      0x104A
S
Stefan Berger 已提交
168

169 170
#define TPM_PPI_VERSION_LEN		3

171 172
enum tpm_chip_flags {
	TPM_CHIP_FLAG_REGISTERED	= BIT(0),
173
	TPM_CHIP_FLAG_TPM2		= BIT(1),
174 175
};

L
Linus Torvalds 已提交
176
struct tpm_chip {
177
	struct device *pdev;	/* Device stuff */
J
Jarkko Sakkinen 已提交
178 179 180
	struct device dev;
	struct cdev cdev;

181
	const struct tpm_class_ops *ops;
182
	unsigned int flags;
L
Linus Torvalds 已提交
183 184

	int dev_num;		/* /dev/tpm# */
185
	char devname[7];
186
	unsigned long is_open;	/* only one allowed */
L
Linus Torvalds 已提交
187 188
	int time_expired;

189
	struct mutex tpm_mutex;	/* tpm is processing */
L
Linus Torvalds 已提交
190

K
Kylene Jo Hall 已提交
191
	struct tpm_vendor_specific vendor;
L
Linus Torvalds 已提交
192

193 194
	struct dentry **bios_dir;

195
#ifdef CONFIG_ACPI
196 197
	const struct attribute_group *groups[2];
	unsigned int groups_cnt;
198 199 200 201
	acpi_handle acpi_dev_handle;
	char ppi_version[TPM_PPI_VERSION_LEN + 1];
#endif /* CONFIG_ACPI */

L
Linus Torvalds 已提交
202 203 204
	struct list_head list;
};

205
#define to_tpm_chip(d) container_of(d, struct tpm_chip, dev)
206

M
Mimi Zohar 已提交
207 208
static inline void tpm_chip_put(struct tpm_chip *chip)
{
209
	module_put(chip->pdev->driver->owner);
M
Mimi Zohar 已提交
210 211
}

212
static inline int tpm_read_index(int base, int index)
L
Linus Torvalds 已提交
213
{
214 215
	outb(index, base);
	return inb(base+1) & 0xFF;
L
Linus Torvalds 已提交
216 217
}

218
static inline void tpm_write_index(int base, int index, int value)
L
Linus Torvalds 已提交
219
{
220 221
	outb(index, base);
	outb(value & 0xFF, base+1);
L
Linus Torvalds 已提交
222
}
223 224 225 226
struct tpm_input_header {
	__be16	tag;
	__be32	length;
	__be32	ordinal;
227
} __packed;
228 229 230 231 232

struct tpm_output_header {
	__be16	tag;
	__be32	length;
	__be32	return_code;
233
} __packed;
234

235 236
#define TPM_TAG_RQU_COMMAND cpu_to_be16(193)

237 238 239 240 241 242 243
struct	stclear_flags_t {
	__be16	tag;
	u8	deactivated;
	u8	disableForceClear;
	u8	physicalPresence;
	u8	physicalPresenceLock;
	u8	bGlobalLock;
244
} __packed;
245 246 247 248 249 250

struct	tpm_version_t {
	u8	Major;
	u8	Minor;
	u8	revMajor;
	u8	revMinor;
251
} __packed;
252 253 254 255 256 257 258

struct	tpm_version_1_2_t {
	__be16	tag;
	u8	Major;
	u8	Minor;
	u8	revMajor;
	u8	revMinor;
259
} __packed;
260 261 262 263 264 265

struct	timeout_t {
	__be32	a;
	__be32	b;
	__be32	c;
	__be32	d;
266
} __packed;
267 268 269 270 271

struct duration_t {
	__be32	tpm_short;
	__be32	tpm_medium;
	__be32	tpm_long;
272
} __packed;
273 274 275 276 277 278 279 280 281 282 283 284 285 286 287 288 289 290 291 292 293 294 295

struct permanent_flags_t {
	__be16	tag;
	u8	disable;
	u8	ownership;
	u8	deactivated;
	u8	readPubek;
	u8	disableOwnerClear;
	u8	allowMaintenance;
	u8	physicalPresenceLifetimeLock;
	u8	physicalPresenceHWEnable;
	u8	physicalPresenceCMDEnable;
	u8	CEKPUsed;
	u8	TPMpost;
	u8	TPMpostLock;
	u8	FIPS;
	u8	operator;
	u8	enableRevokeEK;
	u8	nvLocked;
	u8	readSRKPub;
	u8	tpmEstablished;
	u8	maintenanceDone;
	u8	disableFullDALogicInfo;
296
} __packed;
297 298 299 300 301 302 303 304 305 306 307 308 309

typedef union {
	struct	permanent_flags_t perm_flags;
	struct	stclear_flags_t	stclear_flags;
	bool	owned;
	__be32	num_pcrs;
	struct	tpm_version_t	tpm_version;
	struct	tpm_version_1_2_t tpm_version_1_2;
	__be32	manufacturer_id;
	struct timeout_t  timeout;
	struct duration_t duration;
} cap_t;

310 311 312 313 314 315 316 317 318 319 320 321 322 323 324 325 326 327
enum tpm_capabilities {
	TPM_CAP_FLAG = cpu_to_be32(4),
	TPM_CAP_PROP = cpu_to_be32(5),
	CAP_VERSION_1_1 = cpu_to_be32(0x06),
	CAP_VERSION_1_2 = cpu_to_be32(0x1A)
};

enum tpm_sub_capabilities {
	TPM_CAP_PROP_PCR = cpu_to_be32(0x101),
	TPM_CAP_PROP_MANUFACTURER = cpu_to_be32(0x103),
	TPM_CAP_FLAG_PERM = cpu_to_be32(0x108),
	TPM_CAP_FLAG_VOL = cpu_to_be32(0x109),
	TPM_CAP_PROP_OWNER = cpu_to_be32(0x111),
	TPM_CAP_PROP_TIS_TIMEOUT = cpu_to_be32(0x115),
	TPM_CAP_PROP_TIS_DURATION = cpu_to_be32(0x120),

};

328 329 330 331
struct	tpm_getcap_params_in {
	__be32	cap;
	__be32	subcap_size;
	__be32	subcap;
332
} __packed;
333 334 335 336

struct	tpm_getcap_params_out {
	__be32	cap_size;
	cap_t	cap;
337
} __packed;
338 339 340 341 342

struct	tpm_readpubek_params_out {
	u8	algorithm[4];
	u8	encscheme[2];
	u8	sigscheme[2];
R
Rajiv Andrade 已提交
343
	__be32	paramsize;
344 345 346 347
	u8	parameters[12]; /*assuming RSA*/
	__be32	keysize;
	u8	modulus[256];
	u8	checksum[20];
348
} __packed;
349 350 351 352 353 354

typedef union {
	struct	tpm_input_header in;
	struct	tpm_output_header out;
} tpm_cmd_header;

R
Rajiv Andrade 已提交
355 356
struct tpm_pcrread_out {
	u8	pcr_result[TPM_DIGEST_SIZE];
357
} __packed;
R
Rajiv Andrade 已提交
358 359 360

struct tpm_pcrread_in {
	__be32	pcr_idx;
361
} __packed;
R
Rajiv Andrade 已提交
362 363 364 365

struct tpm_pcrextend_in {
	__be32	pcr_idx;
	u8	hash[TPM_DIGEST_SIZE];
366
} __packed;
R
Rajiv Andrade 已提交
367

368 369 370 371 372 373 374 375 376
/* 128 bytes is an arbitrary cap. This could be as large as TPM_BUFSIZE - 18
 * bytes, but 128 is still a relatively large number of random bytes and
 * anything much bigger causes users of struct tpm_cmd_t to start getting
 * compiler warnings about stack frame size. */
#define TPM_MAX_RNG_DATA	128

struct tpm_getrandom_out {
	__be32 rng_data_len;
	u8     rng_data[TPM_MAX_RNG_DATA];
377
} __packed;
378 379 380

struct tpm_getrandom_in {
	__be32 num_bytes;
381
} __packed;
382

383 384 385 386
struct tpm_startup_in {
	__be16	startup_type;
} __packed;

387 388 389 390 391
typedef union {
	struct	tpm_getcap_params_out getcap_out;
	struct	tpm_readpubek_params_out readpubek_out;
	u8	readpubek_out_buffer[sizeof(struct tpm_readpubek_params_out)];
	struct	tpm_getcap_params_in getcap_in;
R
Rajiv Andrade 已提交
392 393 394
	struct	tpm_pcrread_in	pcrread_in;
	struct	tpm_pcrread_out	pcrread_out;
	struct	tpm_pcrextend_in pcrextend_in;
395 396
	struct	tpm_getrandom_in getrandom_in;
	struct	tpm_getrandom_out getrandom_out;
397
	struct tpm_startup_in startup_in;
398 399 400 401 402
} tpm_cmd_params;

struct tpm_cmd_t {
	tpm_cmd_header	header;
	tpm_cmd_params	params;
403
} __packed;
404

J
Jarkko Sakkinen 已提交
405 406 407 408 409 410 411 412 413 414 415 416 417 418 419
/* A string buffer type for constructing TPM commands. This is based on the
 * ideas of string buffer code in security/keys/trusted.h but is heap based
 * in order to keep the stack usage minimal.
 */

enum tpm_buf_flags {
	TPM_BUF_OVERFLOW	= BIT(0),
};

struct tpm_buf {
	struct page *data_page;
	unsigned int flags;
	u8 *data;
};

J
Jarkko Sakkinen 已提交
420
static inline int tpm_buf_init(struct tpm_buf *buf, u16 tag, u32 ordinal)
J
Jarkko Sakkinen 已提交
421 422 423 424 425 426 427 428 429 430 431 432 433 434 435 436 437 438 439 440 441 442 443 444 445 446 447 448 449 450 451 452 453 454 455 456 457 458 459 460 461 462 463 464 465 466 467 468 469 470 471 472 473 474 475 476 477 478 479 480 481 482 483 484 485 486 487 488 489 490 491 492 493 494 495 496 497 498 499
{
	struct tpm_input_header *head;

	buf->data_page = alloc_page(GFP_HIGHUSER);
	if (!buf->data_page)
		return -ENOMEM;

	buf->flags = 0;
	buf->data = kmap(buf->data_page);

	head = (struct tpm_input_header *) buf->data;

	head->tag = cpu_to_be16(tag);
	head->length = cpu_to_be32(sizeof(*head));
	head->ordinal = cpu_to_be32(ordinal);

	return 0;
}

static inline void tpm_buf_destroy(struct tpm_buf *buf)
{
	kunmap(buf->data_page);
	__free_page(buf->data_page);
}

static inline u32 tpm_buf_length(struct tpm_buf *buf)
{
	struct tpm_input_header *head = (struct tpm_input_header *) buf->data;

	return be32_to_cpu(head->length);
}

static inline u16 tpm_buf_tag(struct tpm_buf *buf)
{
	struct tpm_input_header *head = (struct tpm_input_header *) buf->data;

	return be16_to_cpu(head->tag);
}

static inline void tpm_buf_append(struct tpm_buf *buf,
				  const unsigned char *new_data,
				  unsigned int new_len)
{
	struct tpm_input_header *head = (struct tpm_input_header *) buf->data;
	u32 len = tpm_buf_length(buf);

	/* Return silently if overflow has already happened. */
	if (buf->flags & TPM_BUF_OVERFLOW)
		return;

	if ((len + new_len) > PAGE_SIZE) {
		WARN(1, "tpm_buf: overflow\n");
		buf->flags |= TPM_BUF_OVERFLOW;
		return;
	}

	memcpy(&buf->data[len], new_data, new_len);
	head->length = cpu_to_be32(len + new_len);
}

static inline void tpm_buf_append_u8(struct tpm_buf *buf, const u8 value)
{
	tpm_buf_append(buf, &value, 1);
}

static inline void tpm_buf_append_u16(struct tpm_buf *buf, const u16 value)
{
	__be16 value2 = cpu_to_be16(value);

	tpm_buf_append(buf, (u8 *) &value2, 2);
}

static inline void tpm_buf_append_u32(struct tpm_buf *buf, const u32 value)
{
	__be32 value2 = cpu_to_be32(value);

	tpm_buf_append(buf, (u8 *) &value2, 4);
}

J
Jarkko Sakkinen 已提交
500 501 502 503
extern struct class *tpm_class;
extern dev_t tpm_devt;
extern const struct file_operations tpm_fops;

504
ssize_t	tpm_getcap(struct device *, __be32, cap_t *, const char *);
505 506
ssize_t tpm_transmit(struct tpm_chip *chip, const char *buf,
		     size_t bufsiz);
507 508
ssize_t tpm_transmit_cmd(struct tpm_chip *chip, void *cmd, int len,
			 const char *desc);
509
extern int tpm_get_timeouts(struct tpm_chip *);
510
extern void tpm_gen_interrupt(struct tpm_chip *);
511
extern int tpm_do_selftest(struct tpm_chip *);
512
extern unsigned long tpm_calc_ordinal_duration(struct tpm_chip *, u32);
513
extern int tpm_pm_suspend(struct device *);
514
extern int tpm_pm_resume(struct device *);
515
extern int wait_for_tpm_stat(struct tpm_chip *, u8, unsigned long,
516
			     wait_queue_head_t *, bool);
517

518 519 520 521 522 523
struct tpm_chip *tpm_chip_find_get(int chip_num);
extern struct tpm_chip *tpmm_chip_alloc(struct device *dev,
				       const struct tpm_class_ops *ops);
extern int tpm_chip_register(struct tpm_chip *chip);
extern void tpm_chip_unregister(struct tpm_chip *chip);

524 525
int tpm_sysfs_add_device(struct tpm_chip *chip);
void tpm_sysfs_del_device(struct tpm_chip *chip);
526

527 528
int tpm_pcr_read_dev(struct tpm_chip *chip, int pcr_idx, u8 *res_buf);

529
#ifdef CONFIG_ACPI
530
extern void tpm_add_ppi(struct tpm_chip *chip);
531
#else
532
static inline void tpm_add_ppi(struct tpm_chip *chip)
533 534
{
}
535
#endif
J
Jarkko Sakkinen 已提交
536 537 538 539

int tpm2_pcr_read(struct tpm_chip *chip, int pcr_idx, u8 *res_buf);
int tpm2_pcr_extend(struct tpm_chip *chip, int pcr_idx, const u8 *hash);
int tpm2_get_random(struct tpm_chip *chip, u8 *out, size_t max);
J
Jarkko Sakkinen 已提交
540 541 542 543 544 545
int tpm2_seal_trusted(struct tpm_chip *chip,
		      struct trusted_key_payload *payload,
		      struct trusted_key_options *options);
int tpm2_unseal_trusted(struct tpm_chip *chip,
			struct trusted_key_payload *payload,
			struct trusted_key_options *options);
J
Jarkko Sakkinen 已提交
546 547 548 549
ssize_t tpm2_get_tpm_pt(struct tpm_chip *chip, u32 property_id,
			u32 *value, const char *desc);

extern int tpm2_startup(struct tpm_chip *chip, u16 startup_type);
550
extern void tpm2_shutdown(struct tpm_chip *chip, u16 shutdown_type);
J
Jarkko Sakkinen 已提交
551 552
extern unsigned long tpm2_calc_ordinal_duration(struct tpm_chip *, u32);
extern int tpm2_do_selftest(struct tpm_chip *chip);
553 554
extern int tpm2_gen_interrupt(struct tpm_chip *chip);
extern int tpm2_probe(struct tpm_chip *chip);