1 // SPDX-License-Identifier: GPL-2.0-only
3 * Copyright (C) 2004 IBM Corporation
4 * Copyright (C) 2014 Intel Corporation
15 * TPM chip management routines.
18 #include <linux/poll.h>
19 #include <linux/slab.h>
20 #include <linux/mutex.h>
21 #include <linux/spinlock.h>
22 #include <linux/freezer.h>
23 #include <linux/major.h>
24 #include <linux/tpm_eventlog.h>
25 #include <linux/hw_random.h>
28 DEFINE_IDR(dev_nums_idr);
29 static DEFINE_MUTEX(idr_lock);
31 const struct class tpm_class = {
33 .shutdown_pre = tpm_class_shutdown,
35 const struct class tpmrm_class = {
40 static int tpm_request_locality(struct tpm_chip *chip)
44 if (!chip->ops->request_locality)
47 rc = chip->ops->request_locality(chip, 0);
55 static void tpm_relinquish_locality(struct tpm_chip *chip)
59 if (!chip->ops->relinquish_locality)
62 rc = chip->ops->relinquish_locality(chip, chip->locality);
64 dev_err(&chip->dev, "%s: : error %d\n", __func__, rc);
69 static int tpm_cmd_ready(struct tpm_chip *chip)
71 if (!chip->ops->cmd_ready)
74 return chip->ops->cmd_ready(chip);
77 static int tpm_go_idle(struct tpm_chip *chip)
79 if (!chip->ops->go_idle)
82 return chip->ops->go_idle(chip);
85 static void tpm_clk_enable(struct tpm_chip *chip)
87 if (chip->ops->clk_enable)
88 chip->ops->clk_enable(chip, true);
91 static void tpm_clk_disable(struct tpm_chip *chip)
93 if (chip->ops->clk_enable)
94 chip->ops->clk_enable(chip, false);
98 * tpm_chip_start() - power on the TPM
99 * @chip: a TPM chip to use
102 * * The response length - OK
103 * * -errno - A system error
105 int tpm_chip_start(struct tpm_chip *chip)
109 tpm_clk_enable(chip);
111 if (chip->locality == -1) {
112 ret = tpm_request_locality(chip);
114 tpm_clk_disable(chip);
119 ret = tpm_cmd_ready(chip);
121 tpm_relinquish_locality(chip);
122 tpm_clk_disable(chip);
128 EXPORT_SYMBOL_GPL(tpm_chip_start);
131 * tpm_chip_stop() - power off the TPM
132 * @chip: a TPM chip to use
135 * * The response length - OK
136 * * -errno - A system error
138 void tpm_chip_stop(struct tpm_chip *chip)
141 tpm_relinquish_locality(chip);
142 tpm_clk_disable(chip);
144 EXPORT_SYMBOL_GPL(tpm_chip_stop);
147 * tpm_try_get_ops() - Get a ref to the tpm_chip
150 * The caller must already have some kind of locking to ensure that chip is
151 * valid. This function will lock the chip so that the ops member can be
152 * accessed safely. The locking prevents tpm_chip_unregister from
153 * completing, so it should not be held for long periods.
155 * Returns -ERRNO if the chip could not be got.
157 int tpm_try_get_ops(struct tpm_chip *chip)
161 get_device(&chip->dev);
163 down_read(&chip->ops_sem);
167 mutex_lock(&chip->tpm_mutex);
168 rc = tpm_chip_start(chip);
174 mutex_unlock(&chip->tpm_mutex);
176 up_read(&chip->ops_sem);
177 put_device(&chip->dev);
180 EXPORT_SYMBOL_GPL(tpm_try_get_ops);
183 * tpm_put_ops() - Release a ref to the tpm_chip
186 * This is the opposite pair to tpm_try_get_ops(). After this returns chip may
189 void tpm_put_ops(struct tpm_chip *chip)
192 mutex_unlock(&chip->tpm_mutex);
193 up_read(&chip->ops_sem);
194 put_device(&chip->dev);
196 EXPORT_SYMBOL_GPL(tpm_put_ops);
199 * tpm_default_chip() - find a TPM chip and get a reference to it
201 struct tpm_chip *tpm_default_chip(void)
203 struct tpm_chip *chip, *res = NULL;
207 mutex_lock(&idr_lock);
210 chip_prev = chip_num;
211 chip = idr_get_next(&dev_nums_idr, &chip_num);
213 get_device(&chip->dev);
217 } while (chip_prev != chip_num);
219 mutex_unlock(&idr_lock);
223 EXPORT_SYMBOL_GPL(tpm_default_chip);
226 * tpm_find_get_ops() - find and reserve a TPM chip
227 * @chip: a &struct tpm_chip instance, %NULL for the default chip
229 * Finds a TPM chip and reserves its class device and operations. The chip must
230 * be released with tpm_put_ops() after use.
231 * This function is for internal use only. It supports existing TPM callers
232 * by accepting NULL, but those callers should be converted to pass in a chip
236 * A reserved &struct tpm_chip instance.
237 * %NULL if a chip is not found.
238 * %NULL if the chip is not available.
240 struct tpm_chip *tpm_find_get_ops(struct tpm_chip *chip)
245 if (!tpm_try_get_ops(chip))
250 chip = tpm_default_chip();
253 rc = tpm_try_get_ops(chip);
254 /* release additional reference we got from tpm_default_chip() */
255 put_device(&chip->dev);
262 * tpm_dev_release() - free chip memory and the device number
263 * @dev: the character device for the TPM chip
265 * This is used as the release function for the character device.
267 static void tpm_dev_release(struct device *dev)
269 struct tpm_chip *chip = container_of(dev, struct tpm_chip, dev);
271 mutex_lock(&idr_lock);
272 idr_remove(&dev_nums_idr, chip->dev_num);
273 mutex_unlock(&idr_lock);
275 kfree(chip->work_space.context_buf);
276 kfree(chip->work_space.session_buf);
277 kfree(chip->allocated_banks);
282 * tpm_class_shutdown() - prepare the TPM device for loss of power.
283 * @dev: device to which the chip is associated.
285 * Issues a TPM2_Shutdown command prior to loss of power, as required by the
286 * TPM 2.0 spec. Then, calls bus- and device- specific shutdown code.
288 * Return: always 0 (i.e. success)
290 int tpm_class_shutdown(struct device *dev)
292 struct tpm_chip *chip = container_of(dev, struct tpm_chip, dev);
294 down_write(&chip->ops_sem);
295 if (chip->flags & TPM_CHIP_FLAG_TPM2) {
296 if (!tpm_chip_start(chip)) {
297 tpm2_shutdown(chip, TPM2_SU_CLEAR);
302 up_write(&chip->ops_sem);
308 * tpm_chip_alloc() - allocate a new struct tpm_chip instance
309 * @pdev: device to which the chip is associated
310 * At this point pdev mst be initialized, but does not have to
312 * @ops: struct tpm_class_ops instance
314 * Allocates a new struct tpm_chip instance and assigns a free
315 * device number for it. Must be paired with put_device(&chip->dev).
317 struct tpm_chip *tpm_chip_alloc(struct device *pdev,
318 const struct tpm_class_ops *ops)
320 struct tpm_chip *chip;
323 chip = kzalloc(sizeof(*chip), GFP_KERNEL);
325 return ERR_PTR(-ENOMEM);
327 mutex_init(&chip->tpm_mutex);
328 init_rwsem(&chip->ops_sem);
332 mutex_lock(&idr_lock);
333 rc = idr_alloc(&dev_nums_idr, NULL, 0, TPM_NUM_DEVICES, GFP_KERNEL);
334 mutex_unlock(&idr_lock);
336 dev_err(pdev, "No available tpm device numbers\n");
342 device_initialize(&chip->dev);
344 chip->dev.class = &tpm_class;
345 chip->dev.release = tpm_dev_release;
346 chip->dev.parent = pdev;
347 chip->dev.groups = chip->groups;
349 if (chip->dev_num == 0)
350 chip->dev.devt = MKDEV(MISC_MAJOR, TPM_MINOR);
352 chip->dev.devt = MKDEV(MAJOR(tpm_devt), chip->dev_num);
354 rc = dev_set_name(&chip->dev, "tpm%d", chip->dev_num);
359 chip->flags |= TPM_CHIP_FLAG_VIRTUAL;
361 cdev_init(&chip->cdev, &tpm_fops);
362 chip->cdev.owner = THIS_MODULE;
364 rc = tpm2_init_space(&chip->work_space, TPM2_SPACE_BUFFER_SIZE);
374 put_device(&chip->dev);
377 EXPORT_SYMBOL_GPL(tpm_chip_alloc);
379 static void tpm_put_device(void *dev)
385 * tpmm_chip_alloc() - allocate a new struct tpm_chip instance
386 * @pdev: parent device to which the chip is associated
387 * @ops: struct tpm_class_ops instance
389 * Same as tpm_chip_alloc except devm is used to do the put_device
391 struct tpm_chip *tpmm_chip_alloc(struct device *pdev,
392 const struct tpm_class_ops *ops)
394 struct tpm_chip *chip;
397 chip = tpm_chip_alloc(pdev, ops);
401 rc = devm_add_action_or_reset(pdev,
407 dev_set_drvdata(pdev, chip);
411 EXPORT_SYMBOL_GPL(tpmm_chip_alloc);
413 static int tpm_add_char_device(struct tpm_chip *chip)
417 rc = cdev_device_add(&chip->cdev, &chip->dev);
420 "unable to cdev_device_add() %s, major %d, minor %d, err=%d\n",
421 dev_name(&chip->dev), MAJOR(chip->dev.devt),
422 MINOR(chip->dev.devt), rc);
426 if (chip->flags & TPM_CHIP_FLAG_TPM2 && !tpm_is_firmware_upgrade(chip)) {
427 rc = tpm_devs_add(chip);
432 /* Make the chip available. */
433 mutex_lock(&idr_lock);
434 idr_replace(&dev_nums_idr, chip, chip->dev_num);
435 mutex_unlock(&idr_lock);
440 cdev_device_del(&chip->cdev, &chip->dev);
444 static void tpm_del_char_device(struct tpm_chip *chip)
446 cdev_device_del(&chip->cdev, &chip->dev);
448 /* Make the chip unavailable. */
449 mutex_lock(&idr_lock);
450 idr_replace(&dev_nums_idr, NULL, chip->dev_num);
451 mutex_unlock(&idr_lock);
453 /* Make the driver uncallable. */
454 down_write(&chip->ops_sem);
457 * Check if chip->ops is still valid: In case that the controller
458 * drivers shutdown handler unregisters the controller in its
459 * shutdown handler we are called twice and chip->ops to NULL.
462 if (chip->flags & TPM_CHIP_FLAG_TPM2) {
463 if (!tpm_chip_start(chip)) {
464 tpm2_shutdown(chip, TPM2_SU_CLEAR);
470 up_write(&chip->ops_sem);
473 static void tpm_del_legacy_sysfs(struct tpm_chip *chip)
475 struct attribute **i;
477 if (chip->flags & (TPM_CHIP_FLAG_TPM2 | TPM_CHIP_FLAG_VIRTUAL) ||
478 tpm_is_firmware_upgrade(chip))
481 sysfs_remove_link(&chip->dev.parent->kobj, "ppi");
483 for (i = chip->groups[0]->attrs; *i != NULL; ++i)
484 sysfs_remove_link(&chip->dev.parent->kobj, (*i)->name);
487 /* For compatibility with legacy sysfs paths we provide symlinks from the
488 * parent dev directory to selected names within the tpm chip directory. Old
489 * kernel versions created these files directly under the parent.
491 static int tpm_add_legacy_sysfs(struct tpm_chip *chip)
493 struct attribute **i;
496 if (chip->flags & (TPM_CHIP_FLAG_TPM2 | TPM_CHIP_FLAG_VIRTUAL) ||
497 tpm_is_firmware_upgrade(chip))
500 rc = compat_only_sysfs_link_entry_to_kobj(
501 &chip->dev.parent->kobj, &chip->dev.kobj, "ppi", NULL);
502 if (rc && rc != -ENOENT)
505 /* All the names from tpm-sysfs */
506 for (i = chip->groups[0]->attrs; *i != NULL; ++i) {
507 rc = compat_only_sysfs_link_entry_to_kobj(
508 &chip->dev.parent->kobj, &chip->dev.kobj, (*i)->name, NULL);
510 tpm_del_legacy_sysfs(chip);
518 static int tpm_hwrng_read(struct hwrng *rng, void *data, size_t max, bool wait)
520 struct tpm_chip *chip = container_of(rng, struct tpm_chip, hwrng);
522 /* Give back zero bytes, as TPM chip has not yet fully resumed: */
523 if (chip->flags & TPM_CHIP_FLAG_SUSPENDED)
526 return tpm_get_random(chip, data, max);
529 static bool tpm_is_hwrng_enabled(struct tpm_chip *chip)
531 if (!IS_ENABLED(CONFIG_HW_RANDOM_TPM))
533 if (tpm_is_firmware_upgrade(chip))
535 if (chip->flags & TPM_CHIP_FLAG_HWRNG_DISABLED)
540 static int tpm_add_hwrng(struct tpm_chip *chip)
542 if (!tpm_is_hwrng_enabled(chip))
545 snprintf(chip->hwrng_name, sizeof(chip->hwrng_name),
546 "tpm-rng-%d", chip->dev_num);
547 chip->hwrng.name = chip->hwrng_name;
548 chip->hwrng.read = tpm_hwrng_read;
549 return hwrng_register(&chip->hwrng);
552 static int tpm_get_pcr_allocation(struct tpm_chip *chip)
556 if (tpm_is_firmware_upgrade(chip))
559 rc = (chip->flags & TPM_CHIP_FLAG_TPM2) ?
560 tpm2_get_pcr_allocation(chip) :
561 tpm1_get_pcr_allocation(chip);
570 * tpm_chip_bootstrap() - Boostrap TPM chip after power on
571 * @chip: TPM chip to use.
573 * Initialize TPM chip after power on. This a one-shot function: subsequent
574 * calls will have no effect.
576 int tpm_chip_bootstrap(struct tpm_chip *chip)
580 if (chip->flags & TPM_CHIP_FLAG_BOOTSTRAPPED)
583 rc = tpm_chip_start(chip);
587 rc = tpm_auto_startup(chip);
591 rc = tpm_get_pcr_allocation(chip);
596 * Unconditionally set, as driver initialization should cease, when the
597 * boostrapping process fails.
599 chip->flags |= TPM_CHIP_FLAG_BOOTSTRAPPED;
603 EXPORT_SYMBOL_GPL(tpm_chip_bootstrap);
606 * tpm_chip_register() - create a character device for the TPM chip
607 * @chip: TPM chip to use.
609 * Creates a character device for the TPM chip and adds sysfs attributes for
610 * the device. As the last step this function adds the chip to the list of TPM
611 * chips available for in-kernel use.
613 * This function should be only called after the chip initialization is
616 int tpm_chip_register(struct tpm_chip *chip)
620 rc = tpm_chip_bootstrap(chip);
624 tpm_sysfs_add_device(chip);
626 tpm_bios_log_setup(chip);
630 rc = tpm_add_hwrng(chip);
634 rc = tpm_add_char_device(chip);
638 rc = tpm_add_legacy_sysfs(chip);
640 tpm_chip_unregister(chip);
647 if (tpm_is_hwrng_enabled(chip))
648 hwrng_unregister(&chip->hwrng);
650 tpm_bios_log_teardown(chip);
654 EXPORT_SYMBOL_GPL(tpm_chip_register);
657 * tpm_chip_unregister() - release the TPM driver
658 * @chip: TPM chip to use.
660 * Takes the chip first away from the list of available TPM chips and then
661 * cleans up all the resources reserved by tpm_chip_register().
663 * Once this function returns the driver call backs in 'op's will not be
664 * running and will no longer start.
666 * NOTE: This function should be only called before deinitializing chip
669 void tpm_chip_unregister(struct tpm_chip *chip)
671 tpm_del_legacy_sysfs(chip);
672 if (tpm_is_hwrng_enabled(chip))
673 hwrng_unregister(&chip->hwrng);
674 tpm_bios_log_teardown(chip);
675 if (chip->flags & TPM_CHIP_FLAG_TPM2 && !tpm_is_firmware_upgrade(chip))
676 tpm_devs_remove(chip);
677 tpm_del_char_device(chip);
679 EXPORT_SYMBOL_GPL(tpm_chip_unregister);