1 // SPDX-License-Identifier: MIT
3 * AMD Trusted Execution Environment (TEE) interface
8 * Copyright (C) 2019,2021 Advanced Micro Devices, Inc.
11 #include <linux/bitfield.h>
12 #include <linux/types.h>
13 #include <linux/mutex.h>
14 #include <linux/delay.h>
15 #include <linux/slab.h>
16 #include <linux/gfp.h>
17 #include <linux/psp.h>
18 #include <linux/psp-tee.h>
25 static int tee_alloc_ring(struct psp_tee_device *tee, int ring_size)
27 struct ring_buf_manager *rb_mgr = &tee->rb_mgr;
33 /* We need actual physical address instead of DMA address, since
34 * Trusted OS running on AMD Secure Processor will map this region
36 start_addr = (void *)__get_free_pages(GFP_KERNEL, get_order(ring_size));
40 memset(start_addr, 0x0, ring_size);
41 rb_mgr->ring_start = start_addr;
42 rb_mgr->ring_size = ring_size;
43 rb_mgr->ring_pa = __psp_pa(start_addr);
44 mutex_init(&rb_mgr->mutex);
49 static void tee_free_ring(struct psp_tee_device *tee)
51 struct ring_buf_manager *rb_mgr = &tee->rb_mgr;
53 if (!rb_mgr->ring_start)
56 free_pages((unsigned long)rb_mgr->ring_start,
57 get_order(rb_mgr->ring_size));
59 rb_mgr->ring_start = NULL;
60 rb_mgr->ring_size = 0;
62 mutex_destroy(&rb_mgr->mutex);
65 static int tee_wait_cmd_poll(struct psp_tee_device *tee, unsigned int timeout,
68 /* ~10ms sleep per loop => nloop = timeout * 100 */
69 int nloop = timeout * 100;
72 *reg = ioread32(tee->io_regs + tee->vdata->cmdresp_reg);
73 if (FIELD_GET(PSP_CMDRESP_RESP, *reg))
76 usleep_range(10000, 10100);
79 dev_err(tee->dev, "tee: command timed out, disabling PSP\n");
86 struct tee_init_ring_cmd *tee_alloc_cmd_buffer(struct psp_tee_device *tee)
88 struct tee_init_ring_cmd *cmd;
90 cmd = kzalloc(sizeof(*cmd), GFP_KERNEL);
94 cmd->hi_addr = upper_32_bits(tee->rb_mgr.ring_pa);
95 cmd->low_addr = lower_32_bits(tee->rb_mgr.ring_pa);
96 cmd->size = tee->rb_mgr.ring_size;
98 dev_dbg(tee->dev, "tee: ring address: high = 0x%x low = 0x%x size = %u\n",
99 cmd->hi_addr, cmd->low_addr, cmd->size);
104 static inline void tee_free_cmd_buffer(struct tee_init_ring_cmd *cmd)
109 static int tee_init_ring(struct psp_tee_device *tee)
111 int ring_size = MAX_RING_BUFFER_ENTRIES * sizeof(struct tee_ring_cmd);
112 struct tee_init_ring_cmd *cmd;
113 phys_addr_t cmd_buffer;
117 BUILD_BUG_ON(sizeof(struct tee_ring_cmd) != 1024);
119 ret = tee_alloc_ring(tee, ring_size);
121 dev_err(tee->dev, "tee: ring allocation failed %d\n", ret);
125 tee->rb_mgr.wptr = 0;
127 cmd = tee_alloc_cmd_buffer(tee);
133 cmd_buffer = __psp_pa((void *)cmd);
135 /* Send command buffer details to Trusted OS by writing to
136 * CPU-PSP message registers
139 iowrite32(lower_32_bits(cmd_buffer),
140 tee->io_regs + tee->vdata->cmdbuff_addr_lo_reg);
141 iowrite32(upper_32_bits(cmd_buffer),
142 tee->io_regs + tee->vdata->cmdbuff_addr_hi_reg);
143 iowrite32(TEE_RING_INIT_CMD,
144 tee->io_regs + tee->vdata->cmdresp_reg);
146 ret = tee_wait_cmd_poll(tee, TEE_DEFAULT_TIMEOUT, ®);
148 dev_err(tee->dev, "tee: ring init command timed out\n");
153 if (FIELD_GET(PSP_CMDRESP_STS, reg)) {
154 dev_err(tee->dev, "tee: ring init command failed (%#010lx)\n",
155 FIELD_GET(PSP_CMDRESP_STS, reg));
161 tee_free_cmd_buffer(cmd);
166 static void tee_destroy_ring(struct psp_tee_device *tee)
171 if (!tee->rb_mgr.ring_start)
177 iowrite32(TEE_RING_DESTROY_CMD,
178 tee->io_regs + tee->vdata->cmdresp_reg);
180 ret = tee_wait_cmd_poll(tee, TEE_DEFAULT_TIMEOUT, ®);
182 dev_err(tee->dev, "tee: ring destroy command timed out\n");
183 } else if (FIELD_GET(PSP_CMDRESP_STS, reg)) {
184 dev_err(tee->dev, "tee: ring destroy command failed (%#010lx)\n",
185 FIELD_GET(PSP_CMDRESP_STS, reg));
192 int tee_dev_init(struct psp_device *psp)
194 struct device *dev = psp->dev;
195 struct psp_tee_device *tee;
199 tee = devm_kzalloc(dev, sizeof(*tee), GFP_KERNEL);
208 tee->io_regs = psp->io_regs;
210 tee->vdata = (struct tee_vdata *)psp->vdata->tee;
213 dev_err(dev, "tee: missing driver data\n");
217 ret = tee_init_ring(tee);
219 dev_err(dev, "tee: failed to init ring buffer\n");
223 dev_notice(dev, "tee enabled\n");
228 psp->tee_data = NULL;
230 dev_notice(dev, "tee initialization failed\n");
235 void tee_dev_destroy(struct psp_device *psp)
237 struct psp_tee_device *tee = psp->tee_data;
242 tee_destroy_ring(tee);
245 static int tee_submit_cmd(struct psp_tee_device *tee, enum tee_cmd_id cmd_id,
246 void *buf, size_t len, struct tee_ring_cmd **resp)
248 struct tee_ring_cmd *cmd;
249 int nloop = 1000, ret = 0;
254 mutex_lock(&tee->rb_mgr.mutex);
256 /* Loop until empty entry found in ring buffer */
258 /* Get pointer to ring buffer command entry */
259 cmd = (struct tee_ring_cmd *)
260 (tee->rb_mgr.ring_start + tee->rb_mgr.wptr);
262 rptr = ioread32(tee->io_regs + tee->vdata->ring_rptr_reg);
264 /* Check if ring buffer is full or command entry is waiting
265 * for response from TEE
267 if (!(tee->rb_mgr.wptr + sizeof(struct tee_ring_cmd) == rptr ||
268 cmd->flag == CMD_WAITING_FOR_RESPONSE))
271 dev_dbg(tee->dev, "tee: ring buffer full. rptr = %u wptr = %u\n",
272 rptr, tee->rb_mgr.wptr);
274 /* Wait if ring buffer is full or TEE is processing data */
275 mutex_unlock(&tee->rb_mgr.mutex);
276 schedule_timeout_interruptible(msecs_to_jiffies(10));
277 mutex_lock(&tee->rb_mgr.mutex);
282 (tee->rb_mgr.wptr + sizeof(struct tee_ring_cmd) == rptr ||
283 cmd->flag == CMD_WAITING_FOR_RESPONSE)) {
284 dev_err(tee->dev, "tee: ring buffer full. rptr = %u wptr = %u response flag %u\n",
285 rptr, tee->rb_mgr.wptr, cmd->flag);
290 /* Do not submit command if PSP got disabled while processing any
291 * command in another thread
298 /* Write command data into ring buffer */
299 cmd->cmd_id = cmd_id;
300 cmd->cmd_state = TEE_CMD_STATE_INIT;
301 memset(&cmd->buf[0], 0, sizeof(cmd->buf));
302 memcpy(&cmd->buf[0], buf, len);
304 /* Indicate driver is waiting for response */
305 cmd->flag = CMD_WAITING_FOR_RESPONSE;
307 /* Update local copy of write pointer */
308 tee->rb_mgr.wptr += sizeof(struct tee_ring_cmd);
309 if (tee->rb_mgr.wptr >= tee->rb_mgr.ring_size)
310 tee->rb_mgr.wptr = 0;
312 /* Trigger interrupt to Trusted OS */
313 iowrite32(tee->rb_mgr.wptr, tee->io_regs + tee->vdata->ring_wptr_reg);
315 /* The response is provided by Trusted OS in same
316 * location as submitted data entry within ring buffer.
321 mutex_unlock(&tee->rb_mgr.mutex);
326 static int tee_wait_cmd_completion(struct psp_tee_device *tee,
327 struct tee_ring_cmd *resp,
328 unsigned int timeout)
330 /* ~1ms sleep per loop => nloop = timeout * 1000 */
331 int nloop = timeout * 1000;
334 if (resp->cmd_state == TEE_CMD_STATE_COMPLETED)
337 usleep_range(1000, 1100);
340 dev_err(tee->dev, "tee: command 0x%x timed out, disabling PSP\n",
348 int psp_tee_process_cmd(enum tee_cmd_id cmd_id, void *buf, size_t len,
351 struct psp_device *psp = psp_get_master_device();
352 struct psp_tee_device *tee;
353 struct tee_ring_cmd *resp;
356 if (!buf || !status || !len || len > sizeof(resp->buf))
361 if (!psp || !psp->tee_data)
369 ret = tee_submit_cmd(tee, cmd_id, buf, len, &resp);
373 ret = tee_wait_cmd_completion(tee, resp, TEE_DEFAULT_TIMEOUT);
375 resp->flag = CMD_RESPONSE_TIMEDOUT;
379 memcpy(buf, &resp->buf[0], len);
380 *status = resp->status;
382 resp->flag = CMD_RESPONSE_COPIED;
386 EXPORT_SYMBOL(psp_tee_process_cmd);
388 int psp_check_tee_status(void)
390 struct psp_device *psp = psp_get_master_device();
392 if (!psp || !psp->tee_data)
397 EXPORT_SYMBOL(psp_check_tee_status);