1 /* SPDX-License-Identifier: GPL-2.0 WITH Linux-syscall-note */
3 * Copyright © 2016 Intel Corporation
10 #ifndef _UAPI_SED_OPAL_H
11 #define _UAPI_SED_OPAL_H
13 #include <linux/types.h>
15 #define OPAL_KEY_MAX 256
16 #define OPAL_MAX_LRS 9
19 OPAL_MBR_ENABLE = 0x0,
20 OPAL_MBR_DISABLE = 0x01,
23 enum opal_mbr_done_flag {
24 OPAL_MBR_NOT_DONE = 0x0,
41 enum opal_lock_state {
42 OPAL_RO = 0x01, /* 0001 */
43 OPAL_RW = 0x02, /* 0010 */
44 OPAL_LK = 0x04, /* 0100 */
47 enum opal_lock_flags {
48 /* IOC_OPAL_SAVE will also store the provided key for locking */
49 OPAL_SAVE_FOR_LOCK = 0x01,
56 __u8 key[OPAL_KEY_MAX];
63 __u8 lr[OPAL_MAX_LRS];
64 __u8 align[2]; /* Align to 8 byte boundary */
67 struct opal_session_info {
70 struct opal_key opal_key;
73 struct opal_user_lr_setup {
76 __u32 RLE; /* Read Lock enabled */
77 __u32 WLE; /* Write Lock Enabled */
78 struct opal_session_info session;
81 struct opal_lock_unlock {
82 struct opal_session_info session;
89 struct opal_session_info session;
91 /* When we're not operating in sum, and we first set
92 * passwords we need to set them via ADMIN authority.
93 * After passwords are changed, we can set them via,
95 * Because of this restriction we need to know about
96 * Two different users. One in 'session' which we will use
97 * to start the session and new_userr_pw as the user we're
100 struct opal_session_info new_user_pw;
103 struct opal_mbr_data {
109 struct opal_mbr_done {
115 struct opal_shadow_mbr {
122 /* Opal table operations */
123 enum opal_table_ops {
128 #define OPAL_UID_LENGTH 8
129 struct opal_read_write_table {
132 const __u8 table_uid[OPAL_UID_LENGTH];
135 #define OPAL_TABLE_READ (1 << OPAL_READ_TABLE)
136 #define OPAL_TABLE_WRITE (1 << OPAL_WRITE_TABLE)
141 #define OPAL_FL_SUPPORTED 0x00000001
142 #define OPAL_FL_LOCKING_SUPPORTED 0x00000002
143 #define OPAL_FL_LOCKING_ENABLED 0x00000004
144 #define OPAL_FL_LOCKED 0x00000008
145 #define OPAL_FL_MBR_ENABLED 0x00000010
146 #define OPAL_FL_MBR_DONE 0x00000020
153 #define IOC_OPAL_SAVE _IOW('p', 220, struct opal_lock_unlock)
154 #define IOC_OPAL_LOCK_UNLOCK _IOW('p', 221, struct opal_lock_unlock)
155 #define IOC_OPAL_TAKE_OWNERSHIP _IOW('p', 222, struct opal_key)
156 #define IOC_OPAL_ACTIVATE_LSP _IOW('p', 223, struct opal_lr_act)
157 #define IOC_OPAL_SET_PW _IOW('p', 224, struct opal_new_pw)
158 #define IOC_OPAL_ACTIVATE_USR _IOW('p', 225, struct opal_session_info)
159 #define IOC_OPAL_REVERT_TPR _IOW('p', 226, struct opal_key)
160 #define IOC_OPAL_LR_SETUP _IOW('p', 227, struct opal_user_lr_setup)
161 #define IOC_OPAL_ADD_USR_TO_LR _IOW('p', 228, struct opal_lock_unlock)
162 #define IOC_OPAL_ENABLE_DISABLE_MBR _IOW('p', 229, struct opal_mbr_data)
163 #define IOC_OPAL_ERASE_LR _IOW('p', 230, struct opal_session_info)
164 #define IOC_OPAL_SECURE_ERASE_LR _IOW('p', 231, struct opal_session_info)
165 #define IOC_OPAL_PSID_REVERT_TPR _IOW('p', 232, struct opal_key)
166 #define IOC_OPAL_MBR_DONE _IOW('p', 233, struct opal_mbr_done)
167 #define IOC_OPAL_WRITE_SHADOW_MBR _IOW('p', 234, struct opal_shadow_mbr)
168 #define IOC_OPAL_GENERIC_TABLE_RW _IOW('p', 235, struct opal_read_write_table)
169 #define IOC_OPAL_GET_STATUS _IOR('p', 236, struct opal_status)
171 #endif /* _UAPI_SED_OPAL_H */