From: Christophe Ricard <christophe.ricard@gmail.com>
To: u-boot@lists.denx.de
Subject: [U-Boot] [PATCH v2 25/28] tpm: Add functions to access flags and permissions
Date: Mon, 24 Aug 2015 22:23:22 +0200 [thread overview]
Message-ID: <55DB7D3A.4050105@gmail.com> (raw)
In-Reply-To: <1440289904-31280-26-git-send-email-sjg@chromium.org>
Acked-by: Christophe Ricard<christophe-h.ricard@st.com>
On 23/08/2015 02:31, Simon Glass wrote:
> Add a few new functions which will be used by the test command in a future
> patch.
>
> Signed-off-by: Simon Glass <sjg@chromium.org>
> ---
>
> Changes in v2:
> - Add new patch with functions to access flags and permissions
>
> include/tpm.h | 49 +++++++++++++++++++++++++++++++++++++++++++++++++
> lib/tpm.c | 51 ++++++++++++++++++++++++++++++++++++++++++++++++++-
> 2 files changed, 99 insertions(+), 1 deletion(-)
>
> diff --git a/include/tpm.h b/include/tpm.h
> index 445952b..086b672 100644
> --- a/include/tpm.h
> +++ b/include/tpm.h
> @@ -49,6 +49,15 @@ enum tpm_nv_index {
> TPM_NV_INDEX_DIR = 0x10000001,
> };
>
> +#define TPM_NV_PER_GLOBALLOCK (1U << 15)
> +#define TPM_NV_PER_PPWRITE (1U << 0)
> +#define TPM_NV_PER_READ_STCLEAR (1U << 31)
> +#define TPM_NV_PER_WRITE_STCLEAR (1U << 14)
> +
> +enum {
> + TPM_PUBEK_SIZE = 256,
> +};
> +
> /**
> * TPM return codes as defined in the TCG Main specification
> * (TPM Main Part 2 Structures; Specification version 1.2)
> @@ -163,6 +172,30 @@ enum tpm_return_code {
> TPM_DEFEND_LOCK_RUNNING = TPM_BASE + TPM_NON_FATAL + 3,
> };
>
> +struct tpm_permanent_flags {
> + __be16 tag;
> + u8 disable;
> + u8 ownership;
> + u8 deactivated;
> + u8 read_pubek;
> + u8 disable_owner_clear;
> + u8 allow_maintenance;
> + u8 physical_presence_lifetime_lock;
> + u8 physical_presence_hw_enable;
> + u8 physical_presence_cmd_enable;
> + u8 cekp_used;
> + u8 tpm_post;
> + u8 tpm_post_lock;
> + u8 fips;
> + u8 operator;
> + u8 enable_revoke_ek;
> + u8 nv_locked;
> + u8 read_srk_pub;
> + u8 tpm_established;
> + u8 maintenance_done;
> + u8 disable_full_da_logic_info;
> +} __packed;
> +
> #ifdef CONFIG_DM_TPM
>
> /* Max buffer size supported by our tpm */
> @@ -551,4 +584,20 @@ uint32_t tpm_load_key2_oiap(uint32_t parent_handle,
> uint32_t tpm_get_pub_key_oiap(uint32_t key_handle, const void *usage_auth,
> void *pubkey, size_t *pubkey_len);
>
> +/**
> + * Get the TPM permanent flags value
> + *
> + * @param pflags Place to put permanent flags
> + * @return return code of the operation
> + */
> +uint32_t tpm_get_permanent_flags(struct tpm_permanent_flags *pflags);
> +
> +/**
> + * Get the TPM permissions
> + *
> + * @param perm Returns permissions value
> + * @return return code of the operation
> + */
> +uint32_t tpm_get_permissions(uint32_t index, uint32_t *perm);
> +
> #endif /* __TPM_H */
> diff --git a/lib/tpm.c b/lib/tpm.c
> index 19bf0b5..5d5f707 100644
> --- a/lib/tpm.c
> +++ b/lib/tpm.c
> @@ -18,7 +18,6 @@
> /* Useful constants */
> enum {
> COMMAND_BUFFER_SIZE = 256,
> - TPM_PUBEK_SIZE = 256,
> TPM_REQUEST_HEADER_LENGTH = 10,
> TPM_RESPONSE_HEADER_LENGTH = 10,
> PCR_DIGEST_LENGTH = 20,
> @@ -610,6 +609,56 @@ uint32_t tpm_get_capability(uint32_t cap_area, uint32_t sub_cap,
> return 0;
> }
>
> +uint32_t tpm_get_permanent_flags(struct tpm_permanent_flags *pflags)
> +{
> + const uint8_t command[22] = {
> + 0x0, 0xc1, /* TPM_TAG */
> + 0x0, 0x0, 0x0, 0x16, /* parameter size */
> + 0x0, 0x0, 0x0, 0x65, /* TPM_COMMAND_CODE */
> + 0x0, 0x0, 0x0, 0x4, /* TPM_CAP_FLAG_PERM */
> + 0x0, 0x0, 0x0, 0x4, /* subcap size */
> + 0x0, 0x0, 0x1, 0x8, /* subcap value */
> + };
> + uint8_t response[COMMAND_BUFFER_SIZE];
> + size_t response_length = sizeof(response);
> + uint32_t err;
> +
> + err = tpm_sendrecv_command(command, response, &response_length);
> + if (err)
> + return err;
> + memcpy(pflags, response + TPM_HEADER_SIZE, sizeof(*pflags));
> +
> + return 0;
> +}
> +
> +uint32_t tpm_get_permissions(uint32_t index, uint32_t *perm)
> +{
> + const uint8_t command[22] = {
> + 0x0, 0xc1, /* TPM_TAG */
> + 0x0, 0x0, 0x0, 0x16, /* parameter size */
> + 0x0, 0x0, 0x0, 0x65, /* TPM_COMMAND_CODE */
> + 0x0, 0x0, 0x0, 0x11,
> + 0x0, 0x0, 0x0, 0x4,
> + };
> + const size_t index_offset = 18;
> + const size_t perm_offset = 60;
> + uint8_t buf[COMMAND_BUFFER_SIZE], response[COMMAND_BUFFER_SIZE];
> + size_t response_length = sizeof(response);
> + uint32_t err;
> +
> + if (pack_byte_string(buf, sizeof(buf), "d", 0, command, sizeof(command),
> + index_offset, index))
> + return TPM_LIB_ERROR;
> + err = tpm_sendrecv_command(buf, response, &response_length);
> + if (err)
> + return err;
> + if (unpack_byte_string(response, response_length, "d",
> + perm_offset, perm))
> + return TPM_LIB_ERROR;
> +
> + return 0;
> +}
> +
> #ifdef CONFIG_TPM_AUTH_SESSIONS
>
> /**
next prev parent reply other threads:[~2015-08-24 20:23 UTC|newest]
Thread overview: 81+ messages / expand[flat|nested] mbox.gz Atom feed top
2015-08-23 0:31 [U-Boot] [PATCH v2 00/28] dm: Convert TPM drivers to driver model Simon Glass
2015-08-23 0:31 ` [U-Boot] [PATCH v2 01/28] tpm: Remove old pre-driver-model I2C code Simon Glass
2015-08-24 4:50 ` Heiko Schocher
2015-08-24 4:52 ` Simon Glass
2015-08-24 5:15 ` Heiko Schocher
2015-08-30 22:42 ` Simon Glass
2015-08-23 0:31 ` [U-Boot] [PATCH v2 02/28] tpm: Drop two unused options Simon Glass
2015-08-30 22:42 ` Simon Glass
2015-08-23 0:31 ` [U-Boot] [PATCH v2 03/28] tpm: Add Kconfig options for TPMs Simon Glass
2015-08-24 20:24 ` Christophe Ricard
2015-08-30 22:42 ` Simon Glass
2015-08-23 0:31 ` [U-Boot] [PATCH v2 04/28] tpm: Convert board config TPM options to Kconfig Simon Glass
2015-08-24 20:20 ` Christophe Ricard
2015-08-30 22:43 ` Simon Glass
2015-08-23 0:31 ` [U-Boot] [PATCH v2 05/28] tpm: Convert drivers to use SPDX Simon Glass
2015-08-30 22:43 ` Simon Glass
2015-08-23 0:31 ` [U-Boot] [PATCH v2 06/28] tpm: Move the I2C TPM code into one file Simon Glass
2015-08-24 20:24 ` Christophe Ricard
2015-08-25 4:13 ` Simon Glass
2015-08-25 18:38 ` Christophe Ricard
2015-08-30 22:43 ` Simon Glass
2015-08-23 0:31 ` [U-Boot] [PATCH v2 07/28] tpm: tpm_tis_i2c: Drop unnecessary methods Simon Glass
2015-08-30 22:43 ` Simon Glass
2015-08-23 0:31 ` [U-Boot] [PATCH v2 08/28] tpm: tpm_tis_i2c: Drop struct tpm_vendor_specific Simon Glass
2015-08-30 22:43 ` Simon Glass
2015-08-23 0:31 ` [U-Boot] [PATCH v2 09/28] tpm: tpm_tis_i2c: Merge struct tpm_dev into tpm_chip Simon Glass
2015-08-30 22:43 ` Simon Glass
2015-08-23 0:31 ` [U-Boot] [PATCH v2 10/28] tpm: tpm_tis_i2c: Merge struct tpm " Simon Glass
2015-08-30 22:43 ` Simon Glass
2015-08-23 0:31 ` [U-Boot] [PATCH v2 11/28] tpm: tpm_tis_i2c: Move definitions into the header file Simon Glass
2015-08-30 22:43 ` Simon Glass
2015-08-23 0:31 ` [U-Boot] [PATCH v2 12/28] tpm: tpm_tis_i2c: Simplify init code Simon Glass
2015-08-24 20:20 ` Christophe Ricard
2015-08-30 22:43 ` Simon Glass
2015-08-23 0:31 ` [U-Boot] [PATCH v2 13/28] tpm: tpm_tis_i2c: Use a consistent tpm_tis_i2c_ prefix Simon Glass
2015-08-30 22:43 ` Simon Glass
2015-08-23 0:31 ` [U-Boot] [PATCH v2 14/28] tpm: tpm_tis_i2c: Tidy up delays Simon Glass
2015-08-30 22:43 ` Simon Glass
2015-08-23 0:31 ` [U-Boot] [PATCH v2 15/28] dm: tpm: Add a uclass for Trusted Platform Modules Simon Glass
2015-08-24 20:21 ` Christophe Ricard
2015-08-30 22:43 ` Simon Glass
2015-08-23 0:31 ` [U-Boot] [PATCH v2 16/28] dm: tpm: Convert the TPM command and library to driver model Simon Glass
2015-08-24 20:21 ` Christophe Ricard
2015-08-30 22:43 ` Simon Glass
2015-08-23 0:31 ` [U-Boot] [PATCH v2 17/28] dm: i2c: Add a command to adjust the offset length Simon Glass
2015-08-24 20:21 ` Christophe Ricard
2015-08-30 22:43 ` Simon Glass
2015-08-23 0:31 ` [U-Boot] [PATCH v2 18/28] tpm: Report tpm errors on the command line Simon Glass
2015-08-24 20:21 ` Christophe Ricard
2015-08-30 22:43 ` Simon Glass
2015-08-23 0:31 ` [U-Boot] [PATCH v2 19/28] dm: tpm: sandbox: Convert TPM driver to driver model Simon Glass
2015-08-30 22:43 ` Simon Glass
2015-08-23 0:31 ` [U-Boot] [PATCH v2 20/28] tpm: Check that parse_byte_string() has data to parse Simon Glass
2015-08-24 20:22 ` Christophe Ricard
2015-08-25 4:13 ` Simon Glass
2015-08-25 18:40 ` Christophe Ricard
2015-08-30 22:43 ` Simon Glass
2015-08-23 0:31 ` [U-Boot] [PATCH v2 21/28] exynos: x86: dts: Add tpm nodes to the device tree for Chrome OS devices Simon Glass
2015-08-24 20:22 ` Christophe Ricard
2015-08-30 22:43 ` Simon Glass
2015-08-23 0:31 ` [U-Boot] [PATCH v2 22/28] dm: tpm: Convert I2C driver to driver model Simon Glass
2015-08-24 20:22 ` Christophe Ricard
2015-08-30 22:44 ` Simon Glass
2015-08-23 0:31 ` [U-Boot] [PATCH v2 23/28] dm: tpm: Convert LPC " Simon Glass
2015-08-24 20:23 ` Christophe Ricard
2015-08-30 22:44 ` Simon Glass
2015-08-23 0:31 ` [U-Boot] [PATCH v2 24/28] tpm: Add a 'tpm info' command Simon Glass
2015-08-30 22:44 ` Simon Glass
2015-08-23 0:31 ` [U-Boot] [PATCH v2 25/28] tpm: Add functions to access flags and permissions Simon Glass
2015-08-24 20:23 ` Christophe Ricard [this message]
2015-08-30 22:44 ` Simon Glass
2015-08-23 0:31 ` [U-Boot] [PATCH v2 26/28] dm: tpm: Add a 'tpmtest' command Simon Glass
2015-08-24 20:23 ` Christophe Ricard
2015-08-30 22:44 ` Simon Glass
2015-08-23 0:31 ` [U-Boot] [PATCH v2 27/28] tpm: Enable 'tpmtest' command for Chrome OS boards with TPMs Simon Glass
2015-08-24 20:23 ` Christophe Ricard
2015-08-30 22:44 ` Simon Glass
2015-08-23 0:31 ` [U-Boot] [PATCH v2 28/28] tegra: nyan: Enable TPM command and driver Simon Glass
2015-08-30 22:44 ` Simon Glass
2015-08-24 20:20 ` [U-Boot] [PATCH v2 00/28] dm: Convert TPM drivers to driver model Christophe Ricard
2015-08-25 4:13 ` Simon Glass
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=55DB7D3A.4050105@gmail.com \
--to=christophe.ricard@gmail.com \
--cc=u-boot@lists.denx.de \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.