2019-06-01 10:08:55 +02:00
// SPDX-License-Identifier: GPL-2.0-only
2005-04-16 15:20:36 -07:00
/*
* Copyright ( C ) 2004 IBM Corporation
2014-12-12 11:46:34 -08:00
* Copyright ( C ) 2014 Intel Corporation
2005-04-16 15:20:36 -07:00
*
* Authors :
* Leendert van Doorn < leendert @ watson . ibm . com >
* Dave Safford < safford @ watson . ibm . com >
* Reiner Sailer < sailer @ watson . ibm . com >
* Kylene Hall < kjhall @ us . ibm . com >
*
2007-08-22 14:01:04 -07:00
* Maintained by : < tpmdd - devel @ lists . sourceforge . net >
2005-04-16 15:20:36 -07:00
*
* Device driver for TCG / TCPA TPM ( trusted platform module ) .
tpm: cleanup checkpatch warnings
before we rename the file it might be a good idea to cleanup the long
persisting checkpatch warnings.
Since everything is really trivial, splitting the patch up would only
result in noise.
For the interested reader - here the checkpatch warnings:
(regrouped for easer readability)
ERROR: trailing whitespace
+ * Specifications at www.trustedcomputinggroup.org^I $
+ * $
+^I/* $
+^I parameters (RSA 12->bytes: keybit, #primes, expbit) $
WARNING: unnecessary whitespace before a quoted newline
+ "invalid count value %x %zx \n", count, bufsiz);
ERROR: do not use assignment in if condition
+ if ((rc = chip->vendor.send(chip, (u8 *) buf, count)) < 0) {
ERROR: space required after that ',' (ctx:VxV)
+ len = tpm_transmit(chip,(u8 *) cmd, len);
^
ERROR: "foo * bar" should be "foo *bar"
+ssize_t tpm_show_enabled(struct device * dev, struct device_attribute * attr,
+ssize_t tpm_show_enabled(struct device * dev, struct device_attribute * attr,
+ssize_t tpm_show_active(struct device * dev, struct device_attribute * attr,
+ssize_t tpm_show_active(struct device * dev, struct device_attribute * attr,
+ssize_t tpm_show_owned(struct device * dev, struct device_attribute * attr,
+ssize_t tpm_show_owned(struct device * dev, struct device_attribute * attr,
+ssize_t tpm_show_temp_deactivated(struct device * dev,
+ struct device_attribute * attr, char *buf)
WARNING: please, no space before tabs
+ * @chip_num: ^Itpm idx # or ANY$
+ * @res_buf: ^ITPM_PCR value$
+ * ^I^Isize of res_buf is 20 bytes (or NULL if you don't care)$
+ * @chip_num: ^Itpm idx # or AN&$
+ * @hash: ^Ihash value used to extend pcr value$
ERROR: code indent should use tabs where possible
+^I TPM_ORD_CONTINUE_SELFTEST);$
WARNING: line over 80 characters
+static bool wait_for_tpm_stat_cond(struct tpm_chip *chip, u8 mask, bool check_cancel,
ERROR: trailing whitespace
+ * Called from tpm_<specific>.c probe function only for devices $
total: 16 errors, 7 warnings, 1554 lines checked
Signed-off-by: Peter Huewe <peterhuewe@gmx.de>
2013-10-22 00:29:14 +02:00
* Specifications at www . trustedcomputinggroup . org
2005-04-16 15:20:36 -07:00
*
* Note , the TPM chip is not interrupt driven ( only polling )
* and can have very long timeouts ( minutes ! ) . Hence the unusual
2005-06-23 22:01:47 -07:00
* calls to msleep .
2005-04-16 15:20:36 -07:00
*/
# include <linux/poll.h>
include cleanup: Update gfp.h and slab.h includes to prepare for breaking implicit slab.h inclusion from percpu.h
percpu.h is included by sched.h and module.h and thus ends up being
included when building most .c files. percpu.h includes slab.h which
in turn includes gfp.h making everything defined by the two files
universally available and complicating inclusion dependencies.
percpu.h -> slab.h dependency is about to be removed. Prepare for
this change by updating users of gfp and slab facilities include those
headers directly instead of assuming availability. As this conversion
needs to touch large number of source files, the following script is
used as the basis of conversion.
http://userweb.kernel.org/~tj/misc/slabh-sweep.py
The script does the followings.
* Scan files for gfp and slab usages and update includes such that
only the necessary includes are there. ie. if only gfp is used,
gfp.h, if slab is used, slab.h.
* When the script inserts a new include, it looks at the include
blocks and try to put the new include such that its order conforms
to its surrounding. It's put in the include block which contains
core kernel includes, in the same order that the rest are ordered -
alphabetical, Christmas tree, rev-Xmas-tree or at the end if there
doesn't seem to be any matching order.
* If the script can't find a place to put a new include (mostly
because the file doesn't have fitting include block), it prints out
an error message indicating which .h file needs to be added to the
file.
The conversion was done in the following steps.
1. The initial automatic conversion of all .c files updated slightly
over 4000 files, deleting around 700 includes and adding ~480 gfp.h
and ~3000 slab.h inclusions. The script emitted errors for ~400
files.
2. Each error was manually checked. Some didn't need the inclusion,
some needed manual addition while adding it to implementation .h or
embedding .c file was more appropriate for others. This step added
inclusions to around 150 files.
3. The script was run again and the output was compared to the edits
from #2 to make sure no file was left behind.
4. Several build tests were done and a couple of problems were fixed.
e.g. lib/decompress_*.c used malloc/free() wrappers around slab
APIs requiring slab.h to be added manually.
5. The script was run on all .h files but without automatically
editing them as sprinkling gfp.h and slab.h inclusions around .h
files could easily lead to inclusion dependency hell. Most gfp.h
inclusion directives were ignored as stuff from gfp.h was usually
wildly available and often used in preprocessor macros. Each
slab.h inclusion directive was examined and added manually as
necessary.
6. percpu.h was updated not to include slab.h.
7. Build test were done on the following configurations and failures
were fixed. CONFIG_GCOV_KERNEL was turned off for all tests (as my
distributed build env didn't work with gcov compiles) and a few
more options had to be turned off depending on archs to make things
build (like ipr on powerpc/64 which failed due to missing writeq).
* x86 and x86_64 UP and SMP allmodconfig and a custom test config.
* powerpc and powerpc64 SMP allmodconfig
* sparc and sparc64 SMP allmodconfig
* ia64 SMP allmodconfig
* s390 SMP allmodconfig
* alpha SMP allmodconfig
* um on x86_64 SMP allmodconfig
8. percpu.h modifications were reverted so that it could be applied as
a separate patch and serve as bisection point.
Given the fact that I had only a couple of failures from tests on step
6, I'm fairly confident about the coverage of this conversion patch.
If there is a breakage, it's likely to be something in one of the arch
headers which should be easily discoverable easily on most builds of
the specific arch.
Signed-off-by: Tejun Heo <tj@kernel.org>
Guess-its-ok-by: Christoph Lameter <cl@linux-foundation.org>
Cc: Ingo Molnar <mingo@redhat.com>
Cc: Lee Schermerhorn <Lee.Schermerhorn@hp.com>
2010-03-24 17:04:11 +09:00
# include <linux/slab.h>
2007-05-08 00:32:02 -07:00
# include <linux/mutex.h>
2005-04-16 15:20:36 -07:00
# include <linux/spinlock.h>
2019-09-20 11:32:36 -07:00
# include <linux/suspend.h>
2011-09-16 14:39:40 -03:00
# include <linux/freezer.h>
2017-09-20 10:13:36 +02:00
# include <linux/tpm_eventlog.h>
2007-05-08 00:32:02 -07:00
2005-04-16 15:20:36 -07:00
# include "tpm.h"
2010-10-01 14:16:39 -07:00
/*
* Bug workaround - some TPM ' s don ' t flush the most
* recently changed pcr on suspend , so force the flush
* with an extend to the selected _unused_ non - volatile pcr .
*/
2018-10-19 21:23:07 +03:00
static u32 tpm_suspend_pcr ;
2010-10-01 14:16:39 -07:00
module_param_named ( suspend_pcr , tpm_suspend_pcr , uint , 0644 ) ;
MODULE_PARM_DESC ( suspend_pcr ,
2017-02-05 20:47:18 -08:00
" PCR to use for dummy writes to facilitate flush on suspend. " ) ;
2010-10-01 14:16:39 -07:00
2018-10-19 21:22:51 +03:00
/**
* tpm_calc_ordinal_duration ( ) - calculate the maximum command duration
* @ chip : TPM chip to use .
* @ ordinal : TPM command ordinal .
*
* The function returns the maximum amount of time the chip could take
* to return the result for a particular ordinal in jiffies .
*
* Return : A maximal duration time for an ordinal in jiffies .
*/
unsigned long tpm_calc_ordinal_duration ( struct tpm_chip * chip , u32 ordinal )
{
if ( chip - > flags & TPM_CHIP_FLAG_TPM2 )
return tpm2_calc_ordinal_duration ( chip , ordinal ) ;
else
return tpm1_calc_ordinal_duration ( chip , ordinal ) ;
}
EXPORT_SYMBOL_GPL ( tpm_calc_ordinal_duration ) ;
2018-11-05 03:02:38 +02:00
static ssize_t tpm_try_transmit ( struct tpm_chip * chip , void * buf , size_t bufsiz )
2005-04-16 15:20:36 -07:00
{
2018-11-06 19:04:30 +02:00
struct tpm_header * header = buf ;
2017-01-06 14:03:45 +02:00
int rc ;
ssize_t len = 0 ;
2006-04-22 02:37:38 -07:00
u32 count , ordinal ;
2005-06-23 22:01:47 -07:00
unsigned long stop ;
2005-04-16 15:20:36 -07:00
2018-11-03 03:04:56 +02:00
if ( bufsiz < TPM_HEADER_SIZE )
return - EINVAL ;
2016-09-12 13:43:30 +03:00
2011-09-15 14:37:43 -03:00
if ( bufsiz > TPM_BUFSIZE )
bufsiz = TPM_BUFSIZE ;
2018-11-03 02:31:07 +02:00
count = be32_to_cpu ( header - > length ) ;
ordinal = be32_to_cpu ( header - > ordinal ) ;
2005-04-16 15:20:36 -07:00
if ( count = = 0 )
return - ENODATA ;
if ( count > bufsiz ) {
2016-02-29 12:29:47 -05:00
dev_err ( & chip - > dev ,
tpm: cleanup checkpatch warnings
before we rename the file it might be a good idea to cleanup the long
persisting checkpatch warnings.
Since everything is really trivial, splitting the patch up would only
result in noise.
For the interested reader - here the checkpatch warnings:
(regrouped for easer readability)
ERROR: trailing whitespace
+ * Specifications at www.trustedcomputinggroup.org^I $
+ * $
+^I/* $
+^I parameters (RSA 12->bytes: keybit, #primes, expbit) $
WARNING: unnecessary whitespace before a quoted newline
+ "invalid count value %x %zx \n", count, bufsiz);
ERROR: do not use assignment in if condition
+ if ((rc = chip->vendor.send(chip, (u8 *) buf, count)) < 0) {
ERROR: space required after that ',' (ctx:VxV)
+ len = tpm_transmit(chip,(u8 *) cmd, len);
^
ERROR: "foo * bar" should be "foo *bar"
+ssize_t tpm_show_enabled(struct device * dev, struct device_attribute * attr,
+ssize_t tpm_show_enabled(struct device * dev, struct device_attribute * attr,
+ssize_t tpm_show_active(struct device * dev, struct device_attribute * attr,
+ssize_t tpm_show_active(struct device * dev, struct device_attribute * attr,
+ssize_t tpm_show_owned(struct device * dev, struct device_attribute * attr,
+ssize_t tpm_show_owned(struct device * dev, struct device_attribute * attr,
+ssize_t tpm_show_temp_deactivated(struct device * dev,
+ struct device_attribute * attr, char *buf)
WARNING: please, no space before tabs
+ * @chip_num: ^Itpm idx # or ANY$
+ * @res_buf: ^ITPM_PCR value$
+ * ^I^Isize of res_buf is 20 bytes (or NULL if you don't care)$
+ * @chip_num: ^Itpm idx # or AN&$
+ * @hash: ^Ihash value used to extend pcr value$
ERROR: code indent should use tabs where possible
+^I TPM_ORD_CONTINUE_SELFTEST);$
WARNING: line over 80 characters
+static bool wait_for_tpm_stat_cond(struct tpm_chip *chip, u8 mask, bool check_cancel,
ERROR: trailing whitespace
+ * Called from tpm_<specific>.c probe function only for devices $
total: 16 errors, 7 warnings, 1554 lines checked
Signed-off-by: Peter Huewe <peterhuewe@gmx.de>
2013-10-22 00:29:14 +02:00
" invalid count value %x %zx \n " , count , bufsiz ) ;
2005-04-16 15:20:36 -07:00
return - E2BIG ;
}
2018-03-05 14:48:26 +02:00
rc = chip - > ops - > send ( chip , buf , count ) ;
tpm: cleanup checkpatch warnings
before we rename the file it might be a good idea to cleanup the long
persisting checkpatch warnings.
Since everything is really trivial, splitting the patch up would only
result in noise.
For the interested reader - here the checkpatch warnings:
(regrouped for easer readability)
ERROR: trailing whitespace
+ * Specifications at www.trustedcomputinggroup.org^I $
+ * $
+^I/* $
+^I parameters (RSA 12->bytes: keybit, #primes, expbit) $
WARNING: unnecessary whitespace before a quoted newline
+ "invalid count value %x %zx \n", count, bufsiz);
ERROR: do not use assignment in if condition
+ if ((rc = chip->vendor.send(chip, (u8 *) buf, count)) < 0) {
ERROR: space required after that ',' (ctx:VxV)
+ len = tpm_transmit(chip,(u8 *) cmd, len);
^
ERROR: "foo * bar" should be "foo *bar"
+ssize_t tpm_show_enabled(struct device * dev, struct device_attribute * attr,
+ssize_t tpm_show_enabled(struct device * dev, struct device_attribute * attr,
+ssize_t tpm_show_active(struct device * dev, struct device_attribute * attr,
+ssize_t tpm_show_active(struct device * dev, struct device_attribute * attr,
+ssize_t tpm_show_owned(struct device * dev, struct device_attribute * attr,
+ssize_t tpm_show_owned(struct device * dev, struct device_attribute * attr,
+ssize_t tpm_show_temp_deactivated(struct device * dev,
+ struct device_attribute * attr, char *buf)
WARNING: please, no space before tabs
+ * @chip_num: ^Itpm idx # or ANY$
+ * @res_buf: ^ITPM_PCR value$
+ * ^I^Isize of res_buf is 20 bytes (or NULL if you don't care)$
+ * @chip_num: ^Itpm idx # or AN&$
+ * @hash: ^Ihash value used to extend pcr value$
ERROR: code indent should use tabs where possible
+^I TPM_ORD_CONTINUE_SELFTEST);$
WARNING: line over 80 characters
+static bool wait_for_tpm_stat_cond(struct tpm_chip *chip, u8 mask, bool check_cancel,
ERROR: trailing whitespace
+ * Called from tpm_<specific>.c probe function only for devices $
total: 16 errors, 7 warnings, 1554 lines checked
Signed-off-by: Peter Huewe <peterhuewe@gmx.de>
2013-10-22 00:29:14 +02:00
if ( rc < 0 ) {
2017-05-25 18:29:13 -04:00
if ( rc ! = - EPIPE )
dev_err ( & chip - > dev ,
2019-02-08 18:30:58 +02:00
" %s: send(): error %d \n " , __func__ , rc ) ;
2018-11-03 05:22:36 +02:00
return rc ;
2005-04-16 15:20:36 -07:00
}
2019-02-08 18:30:58 +02:00
/* A sanity check. send() should just return zero on success e.g.
* not the command length .
*/
if ( rc > 0 ) {
dev_warn ( & chip - > dev ,
" %s: send(): invalid value %d \n " , __func__ , rc ) ;
rc = 0 ;
}
2016-03-31 22:56:56 +02:00
if ( chip - > flags & TPM_CHIP_FLAG_IRQ )
2006-04-22 02:38:03 -07:00
goto out_recv ;
2018-10-19 21:22:51 +03:00
stop = jiffies + tpm_calc_ordinal_duration ( chip , ordinal ) ;
2005-04-16 15:20:36 -07:00
do {
2013-11-26 13:30:44 -07:00
u8 status = chip - > ops - > status ( chip ) ;
if ( ( status & chip - > ops - > req_complete_mask ) = =
chip - > ops - > req_complete_val )
2005-04-16 15:20:36 -07:00
goto out_recv ;
2005-06-23 22:02:02 -07:00
2013-11-26 13:30:44 -07:00
if ( chip - > ops - > req_canceled ( chip , status ) ) {
2016-02-29 12:29:47 -05:00
dev_err ( & chip - > dev , " Operation Canceled \n " ) ;
2018-11-03 05:22:36 +02:00
return - ECANCELED ;
2005-06-23 22:02:02 -07:00
}
2018-05-07 12:07:32 -04:00
tpm_msleep ( TPM_TIMEOUT_POLL ) ;
2005-04-16 15:20:36 -07:00
rmb ( ) ;
2005-06-23 22:01:47 -07:00
} while ( time_before ( jiffies , stop ) ) ;
2005-04-16 15:20:36 -07:00
2013-11-26 13:30:44 -07:00
chip - > ops - > cancel ( chip ) ;
2016-02-29 12:29:47 -05:00
dev_err ( & chip - > dev , " Operation Timed out \n " ) ;
2018-11-03 05:22:36 +02:00
return - ETIME ;
2005-04-16 15:20:36 -07:00
out_recv :
2018-03-05 14:48:26 +02:00
len = chip - > ops - > recv ( chip , buf , bufsiz ) ;
2017-01-06 14:03:45 +02:00
if ( len < 0 ) {
rc = len ;
2018-11-04 16:15:49 +02:00
dev_err ( & chip - > dev , " tpm_transmit: tpm_recv: error %d \n " , rc ) ;
} else if ( len < TPM_HEADER_SIZE | | len ! = be32_to_cpu ( header - > length ) )
2017-02-14 21:57:42 +02:00
rc = - EFAULT ;
2017-01-06 14:03:45 +02:00
return rc ? rc : len ;
2005-04-16 15:20:36 -07:00
}
2018-03-21 11:43:48 -07:00
/**
* tpm_transmit - Internal kernel interface to transmit TPM commands .
2018-10-26 14:34:22 +01:00
* @ chip : a TPM chip to use
* @ buf : a TPM command buffer
* @ bufsiz : length of the TPM command buffer
2018-03-21 11:43:48 -07:00
*
2018-10-26 14:34:22 +01:00
* A wrapper around tpm_try_transmit ( ) that handles TPM2_RC_RETRY returns from
* the TPM and retransmits the command after a delay up to a maximum wait of
* TPM2_DURATION_LONG .
2018-03-21 11:43:48 -07:00
*
2018-10-26 14:34:22 +01:00
* Note that TPM 1. x never returns TPM2_RC_RETRY so the retry logic is TPM 2.0
* only .
2018-03-21 11:43:48 -07:00
*
* Return :
2018-10-26 14:34:22 +01:00
* * The response length - OK
* * - errno - A system error
2018-03-21 11:43:48 -07:00
*/
2018-11-05 03:02:38 +02:00
ssize_t tpm_transmit ( struct tpm_chip * chip , u8 * buf , size_t bufsiz )
2018-03-21 11:43:48 -07:00
{
2018-11-06 19:04:30 +02:00
struct tpm_header * header = ( struct tpm_header * ) buf ;
2018-03-21 11:43:48 -07:00
/* space for header and handles */
u8 save [ TPM_HEADER_SIZE + 3 * sizeof ( u32 ) ] ;
unsigned int delay_msec = TPM2_DURATION_SHORT ;
u32 rc = 0 ;
ssize_t ret ;
2018-11-03 15:15:07 +02:00
const size_t save_size = min ( sizeof ( save ) , bufsiz ) ;
2018-03-22 17:32:20 +02:00
/* the command code is where the return code will be */
u32 cc = be32_to_cpu ( header - > return_code ) ;
2018-03-21 11:43:48 -07:00
/*
* Subtlety here : if we have a space , the handles will be
* transformed , so when we restore the header we also have to
* restore the handles .
*/
memcpy ( save , buf , save_size ) ;
for ( ; ; ) {
2018-11-05 03:02:38 +02:00
ret = tpm_try_transmit ( chip , buf , bufsiz ) ;
2018-03-21 11:43:48 -07:00
if ( ret < 0 )
break ;
rc = be32_to_cpu ( header - > return_code ) ;
2018-03-22 17:32:20 +02:00
if ( rc ! = TPM2_RC_RETRY & & rc ! = TPM2_RC_TESTING )
break ;
/*
* return immediately if self test returns test
* still running to shorten boot time .
*/
if ( rc = = TPM2_RC_TESTING & & cc = = TPM2_CC_SELF_TEST )
2018-03-21 11:43:48 -07:00
break ;
2018-04-02 21:50:06 +05:30
2018-03-21 11:43:48 -07:00
if ( delay_msec > TPM2_DURATION_LONG ) {
2018-03-22 17:32:20 +02:00
if ( rc = = TPM2_RC_RETRY )
dev_err ( & chip - > dev , " in retry loop \n " ) ;
else
dev_err ( & chip - > dev ,
" self test is still running \n " ) ;
2018-03-21 11:43:48 -07:00
break ;
}
tpm_msleep ( delay_msec ) ;
2018-04-02 21:50:06 +05:30
delay_msec * = 2 ;
2018-03-21 11:43:48 -07:00
memcpy ( buf , save , save_size ) ;
}
return ret ;
}
2018-10-26 14:34:22 +01:00
2016-11-23 12:04:11 +02:00
/**
2018-03-05 14:48:25 +02:00
* tpm_transmit_cmd - send a tpm command to the device
2018-10-26 14:34:22 +01:00
* @ chip : a TPM chip to use
* @ buf : a TPM command buffer
* @ min_rsp_body_length : minimum expected length of response body
* @ desc : command description used in the error message
2016-11-23 12:04:11 +02:00
*
* Return :
2018-10-26 14:34:22 +01:00
* * 0 - OK
* * - errno - A system error
* * TPM_RC - A TPM error
2016-11-23 12:04:11 +02:00
*/
2018-11-03 15:15:07 +02:00
ssize_t tpm_transmit_cmd ( struct tpm_chip * chip , struct tpm_buf * buf ,
2018-11-05 03:02:38 +02:00
size_t min_rsp_body_length , const char * desc )
2006-04-22 02:37:05 -07:00
{
2018-11-06 19:04:30 +02:00
const struct tpm_header * header = ( struct tpm_header * ) buf - > data ;
2006-04-22 02:37:05 -07:00
int err ;
2017-01-19 07:19:12 -05:00
ssize_t len ;
2006-04-22 02:37:05 -07:00
2018-11-05 03:02:38 +02:00
len = tpm_transmit ( chip , buf - > data , PAGE_SIZE ) ;
2006-04-22 02:37:05 -07:00
if ( len < 0 )
return len ;
2014-12-12 11:46:33 -08:00
err = be32_to_cpu ( header - > return_code ) ;
tpm: suppress transmit cmd error logs when TPM 1.2 is disabled/deactivated
For TPM 1.2 chips the system setup utility allows to set the TPM device in
one of the following states:
* Active: Security chip is functional
* Inactive: Security chip is visible, but is not functional
* Disabled: Security chip is hidden and is not functional
When choosing the "Inactive" state, the TPM 1.2 device is enumerated and
registered, but sending TPM commands fail with either TPM_DEACTIVATED or
TPM_DISABLED depending if the firmware deactivated or disabled the TPM.
Since these TPM 1.2 error codes don't have special treatment, inactivating
the TPM leads to a very noisy kernel log buffer that shows messages like
the following:
tpm_tis 00:05: 1.2 TPM (device-id 0x0, rev-id 78)
tpm tpm0: A TPM error (6) occurred attempting to read a pcr value
tpm tpm0: TPM is disabled/deactivated (0x6)
tpm tpm0: A TPM error (6) occurred attempting get random
tpm tpm0: A TPM error (6) occurred attempting to read a pcr value
ima: No TPM chip found, activating TPM-bypass! (rc=6)
tpm tpm0: A TPM error (6) occurred attempting get random
tpm tpm0: A TPM error (6) occurred attempting get random
tpm tpm0: A TPM error (6) occurred attempting get random
tpm tpm0: A TPM error (6) occurred attempting get random
Let's just suppress error log messages for the TPM_{DEACTIVATED,DISABLED}
return codes, since this is expected when the TPM 1.2 is set to Inactive.
In that case the kernel log is cleaner and less confusing for users, i.e:
tpm_tis 00:05: 1.2 TPM (device-id 0x0, rev-id 78)
tpm tpm0: TPM is disabled/deactivated (0x6)
ima: No TPM chip found, activating TPM-bypass! (rc=6)
Reported-by: Hans de Goede <hdegoede@redhat.com>
Signed-off-by: Javier Martinez Canillas <javierm@redhat.com>
Reviewed-by: Jarkko Sakkinen <jarkko.sakkinen@linux.intel.com>
Signed-off-by: Jarkko Sakkinen <jarkko.sakkinen@linux.intel.com>
2018-08-30 16:40:05 +02:00
if ( err ! = 0 & & err ! = TPM_ERR_DISABLED & & err ! = TPM_ERR_DEACTIVATED
2019-01-29 11:59:11 -07:00
& & err ! = TPM2_RC_TESTING & & desc )
2016-02-29 12:29:47 -05:00
dev_err ( & chip - > dev , " A TPM error (%d) occurred %s \n " , err ,
2014-12-12 11:46:36 -08:00
desc ) ;
2017-01-19 07:19:12 -05:00
if ( err )
return err ;
if ( len < min_rsp_body_length + TPM_HEADER_SIZE )
return - EFAULT ;
2011-11-01 17:00:52 -02:00
2017-01-19 07:19:12 -05:00
return 0 ;
2006-04-22 02:37:05 -07:00
}
2017-05-24 17:39:40 -04:00
EXPORT_SYMBOL_GPL ( tpm_transmit_cmd ) ;
2006-04-22 02:37:05 -07:00
2011-11-11 12:57:02 -05:00
int tpm_get_timeouts ( struct tpm_chip * chip )
2006-04-22 02:37:50 -07:00
{
2016-10-26 16:28:44 -06:00
if ( chip - > flags & TPM_CHIP_FLAG_HAVE_TIMEOUTS )
return 0 ;
2018-10-19 21:22:52 +03:00
if ( chip - > flags & TPM_CHIP_FLAG_TPM2 )
return tpm2_get_timeouts ( chip ) ;
else
return tpm1_get_timeouts ( chip ) ;
2006-04-22 02:37:50 -07:00
}
EXPORT_SYMBOL_GPL ( tpm_get_timeouts ) ;
2015-05-30 08:09:04 +03:00
/**
2017-11-05 13:16:26 +02:00
* tpm_is_tpm2 - do we a have a TPM2 chip ?
* @ chip : a & struct tpm_chip instance , % NULL for the default chip
2015-05-30 08:09:04 +03:00
*
2017-11-05 13:16:26 +02:00
* Return :
* 1 if we have a TPM2 chip .
* 0 if we don ' t have a TPM2 chip .
* A negative number for system errors ( errno ) .
2015-05-30 08:09:04 +03:00
*/
2017-11-05 13:16:26 +02:00
int tpm_is_tpm2 ( struct tpm_chip * chip )
2015-05-30 08:09:04 +03:00
{
int rc ;
2018-06-26 07:06:15 -04:00
chip = tpm_find_get_ops ( chip ) ;
2017-11-05 13:16:26 +02:00
if ( ! chip )
2015-05-30 08:09:04 +03:00
return - ENODEV ;
rc = ( chip - > flags & TPM_CHIP_FLAG_TPM2 ) ! = 0 ;
2016-02-12 20:29:53 -07:00
tpm_put_ops ( chip ) ;
2015-05-30 08:09:04 +03:00
return rc ;
}
EXPORT_SYMBOL_GPL ( tpm_is_tpm2 ) ;
2009-02-02 15:23:44 -02:00
/**
2017-11-05 13:16:26 +02:00
* tpm_pcr_read - read a PCR value from SHA1 bank
* @ chip : a & struct tpm_chip instance , % NULL for the default chip
* @ pcr_idx : the PCR to be retrieved
tpm: retrieve digest size of unknown algorithms with PCR read
Currently, the TPM driver retrieves the digest size from a table mapping
TPM algorithms identifiers to identifiers defined by the crypto subsystem.
If the algorithm is not defined by the latter, the digest size can be
retrieved from the output of the PCR read command.
The patch modifies the definition of tpm_pcr_read() and tpm2_pcr_read() to
pass the desired hash algorithm and obtain the digest size at TPM startup.
Algorithms and corresponding digest sizes are stored in the new structure
tpm_bank_info, member of tpm_chip, so that the information can be used by
other kernel subsystems.
tpm_bank_info contains: the TPM algorithm identifier, necessary to generate
the event log as defined by Trusted Computing Group (TCG); the digest size,
to pad/truncate a digest calculated with a different algorithm; the crypto
subsystem identifier, to calculate the digest of event data.
This patch also protects against data corruption that could happen in the
bus, by checking that the digest size returned by the TPM during a PCR read
matches the size of the algorithm passed to tpm2_pcr_read().
For the initial PCR read, when digest sizes are not yet available, this
patch ensures that the amount of data copied from the output returned by
the TPM does not exceed the size of the array data are copied to.
Signed-off-by: Roberto Sassu <roberto.sassu@huawei.com>
Reviewed-by: Jarkko Sakkinen <jarkko.sakkinen@linux.intel.com>
Tested-by: Jarkko Sakkinen <jarkko.sakkinen@linux.intel.com>
Acked-by: Mimi Zohar <zohar@linux.ibm.com>
Signed-off-by: Jarkko Sakkinen <jarkko.sakkinen@linux.intel.com>
2019-02-06 17:24:49 +01:00
* @ digest : the PCR bank and buffer current PCR value is written to
2009-02-02 15:23:44 -02:00
*
2017-11-05 13:16:26 +02:00
* Return : same as with tpm_transmit_cmd ( )
2009-02-02 15:23:44 -02:00
*/
tpm: retrieve digest size of unknown algorithms with PCR read
Currently, the TPM driver retrieves the digest size from a table mapping
TPM algorithms identifiers to identifiers defined by the crypto subsystem.
If the algorithm is not defined by the latter, the digest size can be
retrieved from the output of the PCR read command.
The patch modifies the definition of tpm_pcr_read() and tpm2_pcr_read() to
pass the desired hash algorithm and obtain the digest size at TPM startup.
Algorithms and corresponding digest sizes are stored in the new structure
tpm_bank_info, member of tpm_chip, so that the information can be used by
other kernel subsystems.
tpm_bank_info contains: the TPM algorithm identifier, necessary to generate
the event log as defined by Trusted Computing Group (TCG); the digest size,
to pad/truncate a digest calculated with a different algorithm; the crypto
subsystem identifier, to calculate the digest of event data.
This patch also protects against data corruption that could happen in the
bus, by checking that the digest size returned by the TPM during a PCR read
matches the size of the algorithm passed to tpm2_pcr_read().
For the initial PCR read, when digest sizes are not yet available, this
patch ensures that the amount of data copied from the output returned by
the TPM does not exceed the size of the array data are copied to.
Signed-off-by: Roberto Sassu <roberto.sassu@huawei.com>
Reviewed-by: Jarkko Sakkinen <jarkko.sakkinen@linux.intel.com>
Tested-by: Jarkko Sakkinen <jarkko.sakkinen@linux.intel.com>
Acked-by: Mimi Zohar <zohar@linux.ibm.com>
Signed-off-by: Jarkko Sakkinen <jarkko.sakkinen@linux.intel.com>
2019-02-06 17:24:49 +01:00
int tpm_pcr_read ( struct tpm_chip * chip , u32 pcr_idx ,
struct tpm_digest * digest )
2009-02-02 15:23:44 -02:00
{
int rc ;
2018-06-26 07:06:15 -04:00
chip = tpm_find_get_ops ( chip ) ;
2017-11-05 13:16:26 +02:00
if ( ! chip )
2009-02-02 15:23:44 -02:00
return - ENODEV ;
2018-10-19 21:22:56 +03:00
2014-12-12 11:46:38 -08:00
if ( chip - > flags & TPM_CHIP_FLAG_TPM2 )
tpm: retrieve digest size of unknown algorithms with PCR read
Currently, the TPM driver retrieves the digest size from a table mapping
TPM algorithms identifiers to identifiers defined by the crypto subsystem.
If the algorithm is not defined by the latter, the digest size can be
retrieved from the output of the PCR read command.
The patch modifies the definition of tpm_pcr_read() and tpm2_pcr_read() to
pass the desired hash algorithm and obtain the digest size at TPM startup.
Algorithms and corresponding digest sizes are stored in the new structure
tpm_bank_info, member of tpm_chip, so that the information can be used by
other kernel subsystems.
tpm_bank_info contains: the TPM algorithm identifier, necessary to generate
the event log as defined by Trusted Computing Group (TCG); the digest size,
to pad/truncate a digest calculated with a different algorithm; the crypto
subsystem identifier, to calculate the digest of event data.
This patch also protects against data corruption that could happen in the
bus, by checking that the digest size returned by the TPM during a PCR read
matches the size of the algorithm passed to tpm2_pcr_read().
For the initial PCR read, when digest sizes are not yet available, this
patch ensures that the amount of data copied from the output returned by
the TPM does not exceed the size of the array data are copied to.
Signed-off-by: Roberto Sassu <roberto.sassu@huawei.com>
Reviewed-by: Jarkko Sakkinen <jarkko.sakkinen@linux.intel.com>
Tested-by: Jarkko Sakkinen <jarkko.sakkinen@linux.intel.com>
Acked-by: Mimi Zohar <zohar@linux.ibm.com>
Signed-off-by: Jarkko Sakkinen <jarkko.sakkinen@linux.intel.com>
2019-02-06 17:24:49 +01:00
rc = tpm2_pcr_read ( chip , pcr_idx , digest , NULL ) ;
2014-12-12 11:46:38 -08:00
else
tpm: retrieve digest size of unknown algorithms with PCR read
Currently, the TPM driver retrieves the digest size from a table mapping
TPM algorithms identifiers to identifiers defined by the crypto subsystem.
If the algorithm is not defined by the latter, the digest size can be
retrieved from the output of the PCR read command.
The patch modifies the definition of tpm_pcr_read() and tpm2_pcr_read() to
pass the desired hash algorithm and obtain the digest size at TPM startup.
Algorithms and corresponding digest sizes are stored in the new structure
tpm_bank_info, member of tpm_chip, so that the information can be used by
other kernel subsystems.
tpm_bank_info contains: the TPM algorithm identifier, necessary to generate
the event log as defined by Trusted Computing Group (TCG); the digest size,
to pad/truncate a digest calculated with a different algorithm; the crypto
subsystem identifier, to calculate the digest of event data.
This patch also protects against data corruption that could happen in the
bus, by checking that the digest size returned by the TPM during a PCR read
matches the size of the algorithm passed to tpm2_pcr_read().
For the initial PCR read, when digest sizes are not yet available, this
patch ensures that the amount of data copied from the output returned by
the TPM does not exceed the size of the array data are copied to.
Signed-off-by: Roberto Sassu <roberto.sassu@huawei.com>
Reviewed-by: Jarkko Sakkinen <jarkko.sakkinen@linux.intel.com>
Tested-by: Jarkko Sakkinen <jarkko.sakkinen@linux.intel.com>
Acked-by: Mimi Zohar <zohar@linux.ibm.com>
Signed-off-by: Jarkko Sakkinen <jarkko.sakkinen@linux.intel.com>
2019-02-06 17:24:49 +01:00
rc = tpm1_pcr_read ( chip , pcr_idx , digest - > digest ) ;
2018-10-19 21:22:56 +03:00
2016-02-12 20:29:53 -07:00
tpm_put_ops ( chip ) ;
2009-02-02 15:23:44 -02:00
return rc ;
}
EXPORT_SYMBOL_GPL ( tpm_pcr_read ) ;
/**
2017-11-05 13:16:26 +02:00
* tpm_pcr_extend - extend a PCR value in SHA1 bank .
* @ chip : a & struct tpm_chip instance , % NULL for the default chip
* @ pcr_idx : the PCR to be retrieved
2019-02-06 17:24:52 +01:00
* @ digests : array of tpm_digest structures used to extend PCRs
2009-02-02 15:23:44 -02:00
*
2019-02-06 17:24:52 +01:00
* Note : callers must pass a digest for every allocated PCR bank , in the same
* order of the banks in chip - > allocated_banks .
2017-11-05 13:16:26 +02:00
*
* Return : same as with tpm_transmit_cmd ( )
2009-02-02 15:23:44 -02:00
*/
2019-02-06 17:24:52 +01:00
int tpm_pcr_extend ( struct tpm_chip * chip , u32 pcr_idx ,
struct tpm_digest * digests )
2009-02-02 15:23:44 -02:00
{
int rc ;
2017-01-30 04:59:41 -05:00
int i ;
2009-02-02 15:23:44 -02:00
2018-06-26 07:06:15 -04:00
chip = tpm_find_get_ops ( chip ) ;
2017-11-05 13:16:26 +02:00
if ( ! chip )
2009-02-02 15:23:44 -02:00
return - ENODEV ;
2019-09-13 20:51:36 +02:00
for ( i = 0 ; i < chip - > nr_allocated_banks ; i + + ) {
if ( digests [ i ] . alg_id ! = chip - > allocated_banks [ i ] . alg_id ) {
rc = EINVAL ;
goto out ;
}
}
2017-01-30 04:59:41 -05:00
2019-02-06 17:24:52 +01:00
if ( chip - > flags & TPM_CHIP_FLAG_TPM2 ) {
rc = tpm2_pcr_extend ( chip , pcr_idx , digests ) ;
2019-09-13 20:51:36 +02:00
goto out ;
2014-12-12 11:46:38 -08:00
}
2019-02-06 17:24:52 +01:00
rc = tpm1_pcr_extend ( chip , pcr_idx , digests [ 0 ] . digest ,
2017-05-04 13:16:47 +02:00
" attempting extend a PCR value " ) ;
2019-09-13 20:51:36 +02:00
out :
2016-02-12 20:29:53 -07:00
tpm_put_ops ( chip ) ;
2009-02-02 15:23:44 -02:00
return rc ;
}
EXPORT_SYMBOL_GPL ( tpm_pcr_extend ) ;
2017-11-05 13:16:26 +02:00
/**
* tpm_send - send a TPM command
* @ chip : a & struct tpm_chip instance , % NULL for the default chip
* @ cmd : a TPM command buffer
* @ buflen : the length of the TPM command buffer
*
* Return : same as with tpm_transmit_cmd ( )
*/
int tpm_send ( struct tpm_chip * chip , void * cmd , size_t buflen )
2010-11-23 18:54:16 -05:00
{
2018-10-26 14:34:22 +01:00
struct tpm_buf buf ;
2010-11-23 18:54:16 -05:00
int rc ;
2018-06-26 07:06:15 -04:00
chip = tpm_find_get_ops ( chip ) ;
2017-11-05 13:16:26 +02:00
if ( ! chip )
2010-11-23 18:54:16 -05:00
return - ENODEV ;
2019-09-16 11:38:34 +03:00
buf . data = cmd ;
2018-11-05 03:02:38 +02:00
rc = tpm_transmit_cmd ( chip , & buf , 0 , " attempting to a send a command " ) ;
2019-09-16 11:38:34 +03:00
2016-02-12 20:29:53 -07:00
tpm_put_ops ( chip ) ;
2010-11-23 18:54:16 -05:00
return rc ;
}
EXPORT_SYMBOL_GPL ( tpm_send ) ;
2018-10-19 21:22:59 +03:00
int tpm_auto_startup ( struct tpm_chip * chip )
{
int rc ;
if ( ! ( chip - > ops - > flags & TPM_OPS_AUTO_STARTUP ) )
return 0 ;
if ( chip - > flags & TPM_CHIP_FLAG_TPM2 )
rc = tpm2_auto_startup ( chip ) ;
else
rc = tpm1_auto_startup ( chip ) ;
return rc ;
}
2005-04-16 15:20:36 -07:00
/*
* We are about to suspend . Save the TPM state
* so that it can be restored .
*/
2012-07-06 19:09:01 +02:00
int tpm_pm_suspend ( struct device * dev )
2005-04-16 15:20:36 -07:00
{
2016-05-11 11:28:27 -04:00
struct tpm_chip * chip = dev_get_drvdata ( dev ) ;
2018-10-19 21:22:57 +03:00
int rc = 0 ;
2008-01-14 00:55:12 -08:00
2018-10-19 21:22:57 +03:00
if ( ! chip )
2005-04-16 15:20:36 -07:00
return - ENODEV ;
2017-06-27 12:27:24 +02:00
if ( chip - > flags & TPM_CHIP_FLAG_ALWAYS_POWERED )
2019-09-20 11:32:36 -07:00
goto suspended ;
if ( ( chip - > flags & TPM_CHIP_FLAG_FIRMWARE_POWER_MANAGED ) & &
! pm_suspend_via_firmware ( ) )
goto suspended ;
2017-06-27 12:27:24 +02:00
2019-03-22 12:51:20 +02:00
if ( ! tpm_chip_start ( chip ) ) {
if ( chip - > flags & TPM_CHIP_FLAG_TPM2 )
2018-11-05 02:07:56 +02:00
tpm2_shutdown ( chip , TPM2_SU_STATE ) ;
2019-03-22 12:51:20 +02:00
else
rc = tpm1_pm_suspend ( chip , tpm_suspend_pcr ) ;
tpm_chip_stop ( chip ) ;
2018-11-05 02:07:56 +02:00
}
2013-03-17 14:56:39 -07:00
2019-09-20 11:32:36 -07:00
suspended :
2010-03-25 00:55:32 -03:00
return rc ;
2005-04-16 15:20:36 -07:00
}
EXPORT_SYMBOL_GPL ( tpm_pm_suspend ) ;
/*
* Resume from a power safe . The BIOS already restored
* the TPM state .
*/
2005-10-30 15:03:25 -08:00
int tpm_pm_resume ( struct device * dev )
2005-04-16 15:20:36 -07:00
{
2016-05-11 11:28:27 -04:00
struct tpm_chip * chip = dev_get_drvdata ( dev ) ;
2005-04-16 15:20:36 -07:00
if ( chip = = NULL )
return - ENODEV ;
return 0 ;
}
EXPORT_SYMBOL_GPL ( tpm_pm_resume ) ;
2012-06-07 13:47:14 -05:00
/**
2017-11-05 13:16:26 +02:00
* tpm_get_random ( ) - get random bytes from the TPM ' s RNG
* @ chip : a & struct tpm_chip instance , % NULL for the default chip
* @ out : destination buffer for the random bytes
* @ max : the max number of bytes to write to @ out
2012-06-07 13:47:14 -05:00
*
2018-10-19 21:23:02 +03:00
* Return : number of random bytes read or a negative error value .
2012-06-07 13:47:14 -05:00
*/
2017-11-05 13:16:26 +02:00
int tpm_get_random ( struct tpm_chip * chip , u8 * out , size_t max )
2012-06-07 13:47:14 -05:00
{
2018-10-19 21:22:55 +03:00
int rc ;
2012-06-07 13:47:14 -05:00
2018-10-19 21:22:55 +03:00
if ( ! out | | max > TPM_MAX_RNG_DATA )
2014-05-09 14:23:10 +03:00
return - EINVAL ;
2018-06-26 07:06:15 -04:00
chip = tpm_find_get_ops ( chip ) ;
2017-11-05 13:16:26 +02:00
if ( ! chip )
2012-06-07 13:47:14 -05:00
return - ENODEV ;
2018-10-19 21:22:55 +03:00
if ( chip - > flags & TPM_CHIP_FLAG_TPM2 )
rc = tpm2_get_random ( chip , out , max ) ;
else
rc = tpm1_get_random ( chip , out , max ) ;
2012-06-07 13:47:14 -05:00
2016-02-12 20:29:53 -07:00
tpm_put_ops ( chip ) ;
2018-10-19 21:22:55 +03:00
return rc ;
2012-06-07 13:47:14 -05:00
}
EXPORT_SYMBOL_GPL ( tpm_get_random ) ;
2014-12-12 11:46:37 -08:00
static int __init tpm_init ( void )
{
int rc ;
tpm_class = class_create ( THIS_MODULE , " tpm " ) ;
if ( IS_ERR ( tpm_class ) ) {
pr_err ( " couldn't create tpm class \n " ) ;
return PTR_ERR ( tpm_class ) ;
}
2017-01-03 09:07:32 -08:00
tpmrm_class = class_create ( THIS_MODULE , " tpmrm " ) ;
if ( IS_ERR ( tpmrm_class ) ) {
pr_err ( " couldn't create tpmrm class \n " ) ;
2018-09-10 10:18:33 -07:00
rc = PTR_ERR ( tpmrm_class ) ;
goto out_destroy_tpm_class ;
2017-01-03 09:07:32 -08:00
}
rc = alloc_chrdev_region ( & tpm_devt , 0 , 2 * TPM_NUM_DEVICES , " tpm " ) ;
2014-12-12 11:46:37 -08:00
if ( rc < 0 ) {
pr_err ( " tpm: failed to allocate char dev region \n " ) ;
2018-09-10 10:18:33 -07:00
goto out_destroy_tpmrm_class ;
}
rc = tpm_dev_common_init ( ) ;
if ( rc ) {
pr_err ( " tpm: failed to allocate char dev region \n " ) ;
goto out_unreg_chrdev ;
2014-12-12 11:46:37 -08:00
}
return 0 ;
2018-09-10 10:18:33 -07:00
out_unreg_chrdev :
unregister_chrdev_region ( tpm_devt , 2 * TPM_NUM_DEVICES ) ;
out_destroy_tpmrm_class :
class_destroy ( tpmrm_class ) ;
out_destroy_tpm_class :
class_destroy ( tpm_class ) ;
return rc ;
2014-12-12 11:46:37 -08:00
}
static void __exit tpm_exit ( void )
{
2016-02-29 08:53:02 -05:00
idr_destroy ( & dev_nums_idr ) ;
2014-12-12 11:46:37 -08:00
class_destroy ( tpm_class ) ;
2017-01-03 09:07:32 -08:00
class_destroy ( tpmrm_class ) ;
unregister_chrdev_region ( tpm_devt , 2 * TPM_NUM_DEVICES ) ;
2018-09-10 10:18:33 -07:00
tpm_dev_common_exit ( ) ;
2014-12-12 11:46:37 -08:00
}
subsys_initcall ( tpm_init ) ;
module_exit ( tpm_exit ) ;
2005-04-16 15:20:36 -07:00
MODULE_AUTHOR ( " Leendert van Doorn (leendert@watson.ibm.com) " ) ;
MODULE_DESCRIPTION ( " TPM Driver " ) ;
MODULE_VERSION ( " 2.0 " ) ;
MODULE_LICENSE ( " GPL " ) ;