tpm.h 9.98 KB
Newer Older
Linus Torvalds's avatar
Linus Torvalds committed
1 2 3 4 5 6 7 8 9
/*
 * Copyright (C) 2004 IBM Corporation
 *
 * Authors:
 * Leendert van Doorn <leendert@watson.ibm.com>
 * Dave Safford <safford@watson.ibm.com>
 * Reiner Sailer <sailer@watson.ibm.com>
 * Kylene Hall <kjhall@us.ibm.com>
 *
Kent Yoder's avatar
Kent Yoder committed
10
 * Maintained by: <tpmdd-devel@lists.sourceforge.net>
Linus Torvalds's avatar
Linus Torvalds committed
11 12
 *
 * Device driver for TCG/TCPA TPM (trusted platform module).
13
 * Specifications at www.trustedcomputinggroup.org
Linus Torvalds's avatar
Linus Torvalds committed
14 15 16 17 18
 *
 * This program is free software; you can redistribute it and/or
 * modify it under the terms of the GNU General Public License as
 * published by the Free Software Foundation, version 2 of the
 * License.
19
 *
Linus Torvalds's avatar
Linus Torvalds committed
20 21 22 23
 */
#include <linux/module.h>
#include <linux/delay.h>
#include <linux/fs.h>
24
#include <linux/mutex.h>
25
#include <linux/sched.h>
26
#include <linux/platform_device.h>
27
#include <linux/io.h>
Rajiv Andrade's avatar
Rajiv Andrade committed
28
#include <linux/tpm.h>
29
#include <linux/acpi.h>
Jarkko Sakkinen's avatar
Jarkko Sakkinen committed
30
#include <linux/cdev.h>
Linus Torvalds's avatar
Linus Torvalds committed
31

32 33 34 35
enum tpm_const {
	TPM_MINOR = 224,	/* officially assigned */
	TPM_BUFSIZE = 4096,
	TPM_NUM_DEVICES = 256,
36
	TPM_RETRY = 50,		/* 5 seconds */
37 38
};

39 40
enum tpm_timeout {
	TPM_TIMEOUT = 5,	/* msecs */
41
	TPM_TIMEOUT_RETRY = 100 /* msecs */
42
};
Linus Torvalds's avatar
Linus Torvalds committed
43 44

/* TPM addresses */
45
enum tpm_addr {
46
	TPM_SUPERIO_ADDR = 0x2E,
47 48 49
	TPM_ADDR = 0x4E,
};

50 51 52 53 54 55 56 57
/* Indexes the duration array */
enum tpm_duration {
	TPM_SHORT = 0,
	TPM_MEDIUM = 1,
	TPM_LONG = 2,
	TPM_UNDEFINED,
};

58
#define TPM_WARN_RETRY          0x800
59
#define TPM_WARN_DOING_SELFTEST 0x802
60 61
#define TPM_ERR_DEACTIVATED     0x6
#define TPM_ERR_DISABLED        0x7
62
#define TPM_ERR_INVALID_POSTINIT 38
63

64
#define TPM_HEADER_SIZE		10
65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117

enum tpm2_const {
	TPM2_PLATFORM_PCR	= 24,
	TPM2_PCR_SELECT_MIN	= ((TPM2_PLATFORM_PCR + 7) / 8),
	TPM2_TIMEOUT_A		= 750,
	TPM2_TIMEOUT_B		= 2000,
	TPM2_TIMEOUT_C		= 200,
	TPM2_TIMEOUT_D		= 30,
	TPM2_DURATION_SHORT	= 20,
	TPM2_DURATION_MEDIUM	= 750,
	TPM2_DURATION_LONG	= 2000,
};

enum tpm2_structures {
	TPM2_ST_NO_SESSIONS	= 0x8001,
	TPM2_ST_SESSIONS	= 0x8002,
};

enum tpm2_return_codes {
	TPM2_RC_INITIALIZE	= 0x0100,
	TPM2_RC_TESTING		= 0x090A,
	TPM2_RC_DISABLED	= 0x0120,
};

enum tpm2_algorithms {
	TPM2_ALG_SHA1		= 0x0004,
};

enum tpm2_command_codes {
	TPM2_CC_FIRST		= 0x011F,
	TPM2_CC_SELF_TEST	= 0x0143,
	TPM2_CC_STARTUP		= 0x0144,
	TPM2_CC_SHUTDOWN	= 0x0145,
	TPM2_CC_GET_CAPABILITY	= 0x017A,
	TPM2_CC_GET_RANDOM	= 0x017B,
	TPM2_CC_PCR_READ	= 0x017E,
	TPM2_CC_PCR_EXTEND	= 0x0182,
	TPM2_CC_LAST		= 0x018F,
};

enum tpm2_permanent_handles {
	TPM2_RS_PW		= 0x40000009,
};

enum tpm2_capabilities {
	TPM2_CAP_TPM_PROPERTIES = 6,
};

enum tpm2_startup_types {
	TPM2_SU_CLEAR	= 0x0000,
	TPM2_SU_STATE	= 0x0001,
};

118 119 120 121 122 123 124
enum tpm2_start_method {
	TPM2_START_ACPI = 2,
	TPM2_START_FIFO = 6,
	TPM2_START_CRB = 7,
	TPM2_START_CRB_WITH_ACPI = 8,
};

Linus Torvalds's avatar
Linus Torvalds committed
125 126 127
struct tpm_chip;

struct tpm_vendor_specific {
128 129 130
	void __iomem *iobase;		/* ioremapped address */
	unsigned long base;		/* TPM base address */

131
	int irq;
132
	int probed_irq;
133

134 135
	int region_size;
	int have_region;
Linus Torvalds's avatar
Linus Torvalds committed
136

137 138
	struct list_head list;
	int locality;
139
	unsigned long timeout_a, timeout_b, timeout_c, timeout_d; /* jiffies */
140
	bool timeout_adjusted;
141
	unsigned long duration[3]; /* jiffies */
142
	bool duration_adjusted;
143
	void *priv;
144 145 146

	wait_queue_head_t read_queue;
	wait_queue_head_t int_queue;
Stefan Berger's avatar
Stefan Berger committed
147 148

	u16 manufacturer_id;
Linus Torvalds's avatar
Linus Torvalds committed
149 150
};

151
#define TPM_VPRIV(c)     ((c)->vendor.priv)
152

Stefan Berger's avatar
Stefan Berger committed
153
#define TPM_VID_INTEL    0x8086
154 155
#define TPM_VID_WINBOND  0x1050
#define TPM_VID_STM      0x104A
Stefan Berger's avatar
Stefan Berger committed
156

157 158
#define TPM_PPI_VERSION_LEN		3

159 160
enum tpm_chip_flags {
	TPM_CHIP_FLAG_REGISTERED	= BIT(0),
161
	TPM_CHIP_FLAG_PPI		= BIT(1),
162
	TPM_CHIP_FLAG_TPM2		= BIT(2),
163 164
};

Linus Torvalds's avatar
Linus Torvalds committed
165
struct tpm_chip {
166
	struct device *pdev;	/* Device stuff */
Jarkko Sakkinen's avatar
Jarkko Sakkinen committed
167 168 169
	struct device dev;
	struct cdev cdev;

170
	const struct tpm_class_ops *ops;
171
	unsigned int flags;
Linus Torvalds's avatar
Linus Torvalds committed
172 173

	int dev_num;		/* /dev/tpm# */
174
	char devname[7];
175
	unsigned long is_open;	/* only one allowed */
Linus Torvalds's avatar
Linus Torvalds committed
176 177
	int time_expired;

178
	struct mutex tpm_mutex;	/* tpm is processing */
Linus Torvalds's avatar
Linus Torvalds committed
179

180
	struct tpm_vendor_specific vendor;
Linus Torvalds's avatar
Linus Torvalds committed
181

182 183
	struct dentry **bios_dir;

184 185 186 187 188
#ifdef CONFIG_ACPI
	acpi_handle acpi_dev_handle;
	char ppi_version[TPM_PPI_VERSION_LEN + 1];
#endif /* CONFIG_ACPI */

Linus Torvalds's avatar
Linus Torvalds committed
189 190 191
	struct list_head list;
};

192 193
#define to_tpm_chip(n) container_of(n, struct tpm_chip, vendor)

Mimi Zohar's avatar
Mimi Zohar committed
194 195
static inline void tpm_chip_put(struct tpm_chip *chip)
{
196
	module_put(chip->pdev->driver->owner);
Mimi Zohar's avatar
Mimi Zohar committed
197 198
}

199
static inline int tpm_read_index(int base, int index)
Linus Torvalds's avatar
Linus Torvalds committed
200
{
201 202
	outb(index, base);
	return inb(base+1) & 0xFF;
Linus Torvalds's avatar
Linus Torvalds committed
203 204
}

205
static inline void tpm_write_index(int base, int index, int value)
Linus Torvalds's avatar
Linus Torvalds committed
206
{
207 208
	outb(index, base);
	outb(value & 0xFF, base+1);
Linus Torvalds's avatar
Linus Torvalds committed
209
}
210 211 212 213
struct tpm_input_header {
	__be16	tag;
	__be32	length;
	__be32	ordinal;
214
} __packed;
215 216 217 218 219

struct tpm_output_header {
	__be16	tag;
	__be32	length;
	__be32	return_code;
220
} __packed;
221

222 223
#define TPM_TAG_RQU_COMMAND cpu_to_be16(193)

224 225 226 227 228 229 230
struct	stclear_flags_t {
	__be16	tag;
	u8	deactivated;
	u8	disableForceClear;
	u8	physicalPresence;
	u8	physicalPresenceLock;
	u8	bGlobalLock;
231
} __packed;
232 233 234 235 236 237

struct	tpm_version_t {
	u8	Major;
	u8	Minor;
	u8	revMajor;
	u8	revMinor;
238
} __packed;
239 240 241 242 243 244 245

struct	tpm_version_1_2_t {
	__be16	tag;
	u8	Major;
	u8	Minor;
	u8	revMajor;
	u8	revMinor;
246
} __packed;
247 248 249 250 251 252

struct	timeout_t {
	__be32	a;
	__be32	b;
	__be32	c;
	__be32	d;
253
} __packed;
254 255 256 257 258

struct duration_t {
	__be32	tpm_short;
	__be32	tpm_medium;
	__be32	tpm_long;
259
} __packed;
260 261 262 263 264 265 266 267 268 269 270 271 272 273 274 275 276 277 278 279 280 281 282

struct permanent_flags_t {
	__be16	tag;
	u8	disable;
	u8	ownership;
	u8	deactivated;
	u8	readPubek;
	u8	disableOwnerClear;
	u8	allowMaintenance;
	u8	physicalPresenceLifetimeLock;
	u8	physicalPresenceHWEnable;
	u8	physicalPresenceCMDEnable;
	u8	CEKPUsed;
	u8	TPMpost;
	u8	TPMpostLock;
	u8	FIPS;
	u8	operator;
	u8	enableRevokeEK;
	u8	nvLocked;
	u8	readSRKPub;
	u8	tpmEstablished;
	u8	maintenanceDone;
	u8	disableFullDALogicInfo;
283
} __packed;
284 285 286 287 288 289 290 291 292 293 294 295 296

typedef union {
	struct	permanent_flags_t perm_flags;
	struct	stclear_flags_t	stclear_flags;
	bool	owned;
	__be32	num_pcrs;
	struct	tpm_version_t	tpm_version;
	struct	tpm_version_1_2_t tpm_version_1_2;
	__be32	manufacturer_id;
	struct timeout_t  timeout;
	struct duration_t duration;
} cap_t;

297 298 299 300 301 302 303 304 305 306 307 308 309 310 311 312 313 314
enum tpm_capabilities {
	TPM_CAP_FLAG = cpu_to_be32(4),
	TPM_CAP_PROP = cpu_to_be32(5),
	CAP_VERSION_1_1 = cpu_to_be32(0x06),
	CAP_VERSION_1_2 = cpu_to_be32(0x1A)
};

enum tpm_sub_capabilities {
	TPM_CAP_PROP_PCR = cpu_to_be32(0x101),
	TPM_CAP_PROP_MANUFACTURER = cpu_to_be32(0x103),
	TPM_CAP_FLAG_PERM = cpu_to_be32(0x108),
	TPM_CAP_FLAG_VOL = cpu_to_be32(0x109),
	TPM_CAP_PROP_OWNER = cpu_to_be32(0x111),
	TPM_CAP_PROP_TIS_TIMEOUT = cpu_to_be32(0x115),
	TPM_CAP_PROP_TIS_DURATION = cpu_to_be32(0x120),

};

315 316 317 318
struct	tpm_getcap_params_in {
	__be32	cap;
	__be32	subcap_size;
	__be32	subcap;
319
} __packed;
320 321 322 323

struct	tpm_getcap_params_out {
	__be32	cap_size;
	cap_t	cap;
324
} __packed;
325 326 327 328 329

struct	tpm_readpubek_params_out {
	u8	algorithm[4];
	u8	encscheme[2];
	u8	sigscheme[2];
330
	__be32	paramsize;
331 332 333 334
	u8	parameters[12]; /*assuming RSA*/
	__be32	keysize;
	u8	modulus[256];
	u8	checksum[20];
335
} __packed;
336 337 338 339 340 341

typedef union {
	struct	tpm_input_header in;
	struct	tpm_output_header out;
} tpm_cmd_header;

Rajiv Andrade's avatar
Rajiv Andrade committed
342 343
struct tpm_pcrread_out {
	u8	pcr_result[TPM_DIGEST_SIZE];
344
} __packed;
Rajiv Andrade's avatar
Rajiv Andrade committed
345 346 347

struct tpm_pcrread_in {
	__be32	pcr_idx;
348
} __packed;
Rajiv Andrade's avatar
Rajiv Andrade committed
349 350 351 352

struct tpm_pcrextend_in {
	__be32	pcr_idx;
	u8	hash[TPM_DIGEST_SIZE];
353
} __packed;
Rajiv Andrade's avatar
Rajiv Andrade committed
354

355 356 357 358 359 360 361 362 363
/* 128 bytes is an arbitrary cap. This could be as large as TPM_BUFSIZE - 18
 * bytes, but 128 is still a relatively large number of random bytes and
 * anything much bigger causes users of struct tpm_cmd_t to start getting
 * compiler warnings about stack frame size. */
#define TPM_MAX_RNG_DATA	128

struct tpm_getrandom_out {
	__be32 rng_data_len;
	u8     rng_data[TPM_MAX_RNG_DATA];
364
} __packed;
365 366 367

struct tpm_getrandom_in {
	__be32 num_bytes;
368
} __packed;
369

370 371 372 373
struct tpm_startup_in {
	__be16	startup_type;
} __packed;

374 375 376 377 378
typedef union {
	struct	tpm_getcap_params_out getcap_out;
	struct	tpm_readpubek_params_out readpubek_out;
	u8	readpubek_out_buffer[sizeof(struct tpm_readpubek_params_out)];
	struct	tpm_getcap_params_in getcap_in;
Rajiv Andrade's avatar
Rajiv Andrade committed
379 380 381
	struct	tpm_pcrread_in	pcrread_in;
	struct	tpm_pcrread_out	pcrread_out;
	struct	tpm_pcrextend_in pcrextend_in;
382 383
	struct	tpm_getrandom_in getrandom_in;
	struct	tpm_getrandom_out getrandom_out;
384
	struct tpm_startup_in startup_in;
385 386 387 388 389
} tpm_cmd_params;

struct tpm_cmd_t {
	tpm_cmd_header	header;
	tpm_cmd_params	params;
390
} __packed;
391

Jarkko Sakkinen's avatar
Jarkko Sakkinen committed
392 393 394 395
extern struct class *tpm_class;
extern dev_t tpm_devt;
extern const struct file_operations tpm_fops;

396
ssize_t	tpm_getcap(struct device *, __be32, cap_t *, const char *);
397 398
ssize_t tpm_transmit(struct tpm_chip *chip, const char *buf,
		     size_t bufsiz);
399 400
ssize_t tpm_transmit_cmd(struct tpm_chip *chip, void *cmd, int len,
			 const char *desc);
401
extern int tpm_get_timeouts(struct tpm_chip *);
402
extern void tpm_gen_interrupt(struct tpm_chip *);
403
extern int tpm_do_selftest(struct tpm_chip *);
404
extern unsigned long tpm_calc_ordinal_duration(struct tpm_chip *, u32);
405
extern int tpm_pm_suspend(struct device *);
406
extern int tpm_pm_resume(struct device *);
407
extern int wait_for_tpm_stat(struct tpm_chip *, u8, unsigned long,
408
			     wait_queue_head_t *, bool);
409

410 411 412 413 414 415
struct tpm_chip *tpm_chip_find_get(int chip_num);
extern struct tpm_chip *tpmm_chip_alloc(struct device *dev,
				       const struct tpm_class_ops *ops);
extern int tpm_chip_register(struct tpm_chip *chip);
extern void tpm_chip_unregister(struct tpm_chip *chip);

416 417
int tpm_sysfs_add_device(struct tpm_chip *chip);
void tpm_sysfs_del_device(struct tpm_chip *chip);
418

419 420
int tpm_pcr_read_dev(struct tpm_chip *chip, int pcr_idx, u8 *res_buf);

421
#ifdef CONFIG_ACPI
422 423
extern int tpm_add_ppi(struct tpm_chip *chip);
extern void tpm_remove_ppi(struct tpm_chip *chip);
424
#else
425
static inline int tpm_add_ppi(struct tpm_chip *chip)
426 427 428
{
	return 0;
}
429

430
static inline void tpm_remove_ppi(struct tpm_chip *chip)
431 432
{
}
433
#endif
434 435 436 437 438 439 440 441

int tpm2_pcr_read(struct tpm_chip *chip, int pcr_idx, u8 *res_buf);
int tpm2_pcr_extend(struct tpm_chip *chip, int pcr_idx, const u8 *hash);
int tpm2_get_random(struct tpm_chip *chip, u8 *out, size_t max);
ssize_t tpm2_get_tpm_pt(struct tpm_chip *chip, u32 property_id,
			u32 *value, const char *desc);

extern int tpm2_startup(struct tpm_chip *chip, u16 startup_type);
442
extern void tpm2_shutdown(struct tpm_chip *chip, u16 shutdown_type);
443 444
extern unsigned long tpm2_calc_ordinal_duration(struct tpm_chip *, u32);
extern int tpm2_do_selftest(struct tpm_chip *chip);
445 446
extern int tpm2_gen_interrupt(struct tpm_chip *chip);
extern int tpm2_probe(struct tpm_chip *chip);