From: Jonathan Derrick <jonathan.derrick@linux.dev>
To: gjoyce@linux.vnet.ibm.com, linux-block@vger.kernel.org
Cc: linuxppc-dev@lists.ozlabs.org, brking@linux.vnet.ibm.com,
msuchanek@suse.de, mpe@ellerman.id.au, nayna@linux.ibm.com,
axboe@kernel.dk, akpm@linux-foundation.org,
linux-efi@vger.kernel.org, keyrings@vger.kernel.org,
dhowells@redhat.com, jarkko@kernel.org
Subject: Re: [PATCH v4 2/3] powerpc/pseries: PLPKS SED Opal keystore support
Date: Fri, 7 Oct 2022 12:22:30 -0600 [thread overview]
Message-ID: <177ea4f0-93f7-85ac-5cad-9579ecfc5731@linux.dev> (raw)
In-Reply-To: <20220819223138.1457091-3-gjoyce@linux.vnet.ibm.com>
LGTM
Reviewed-by: Jonathan Derrick <jonathan.derrick@linux.dev>
On 8/19/2022 4:31 PM, gjoyce@linux.vnet.ibm.com wrote:
> From: Greg Joyce <gjoyce@linux.vnet.ibm.com>
>
> Define operations for SED Opal to read/write keys
> from POWER LPAR Platform KeyStore(PLPKS). This allows
> for non-volatile storage of SED Opal keys.
>
> Signed-off-by: Greg Joyce <gjoyce@linux.vnet.ibm.com>
> ---
> arch/powerpc/platforms/pseries/Makefile | 1 +
> .../powerpc/platforms/pseries/plpks_sed_ops.c | 124 ++++++++++++++++++
> 2 files changed, 125 insertions(+)
> create mode 100644 arch/powerpc/platforms/pseries/plpks_sed_ops.c
>
> diff --git a/arch/powerpc/platforms/pseries/Makefile b/arch/powerpc/platforms/pseries/Makefile
> index 14e143b946a3..b7fea9e48a58 100644
> --- a/arch/powerpc/platforms/pseries/Makefile
> +++ b/arch/powerpc/platforms/pseries/Makefile
> @@ -29,6 +29,7 @@ obj-$(CONFIG_PPC_SPLPAR) += vphn.o
> obj-$(CONFIG_PPC_SVM) += svm.o
> obj-$(CONFIG_FA_DUMP) += rtas-fadump.o
> obj-$(CONFIG_PSERIES_PLPKS) += plpks.o
> +obj-$(CONFIG_PSERIES_PLPKS) += plpks_sed_ops.o
>
> obj-$(CONFIG_SUSPEND) += suspend.o
> obj-$(CONFIG_PPC_VAS) += vas.o vas-sysfs.o
> diff --git a/arch/powerpc/platforms/pseries/plpks_sed_ops.c b/arch/powerpc/platforms/pseries/plpks_sed_ops.c
> new file mode 100644
> index 000000000000..833226738448
> --- /dev/null
> +++ b/arch/powerpc/platforms/pseries/plpks_sed_ops.c
> @@ -0,0 +1,124 @@
> +// SPDX-License-Identifier: GPL-2.0-only
> +/*
> + * POWER Platform specific code for non-volatile SED key access
> + * Copyright (C) 2022 IBM Corporation
> + *
> + * Define operations for SED Opal to read/write keys
> + * from POWER LPAR Platform KeyStore(PLPKS).
> + *
> + * Self Encrypting Drives(SED) key storage using PLPKS
> + */
> +
> +#include <linux/kernel.h>
> +#include <linux/slab.h>
> +#include <linux/string.h>
> +#include <linux/ioctl.h>
> +#include <linux/sed-opal-key.h>
> +#include "plpks.h"
> +
> +/*
> + * structure that contains all SED data
> + */
> +struct plpks_sed_object_data {
> + u_char version;
> + u_char pad1[7];
> + u_long authority;
> + u_long range;
> + u_int key_len;
> + u_char key[32];
> +};
> +
> +#define PLPKS_PLATVAR_POLICY WORLDREADABLE
> +#define PLPKS_PLATVAR_OS_COMMON 4
> +
> +#define PLPKS_SED_OBJECT_DATA_V0 0
> +#define PLPKS_SED_MANGLED_LABEL "/default/pri"
> +#define PLPKS_SED_COMPONENT "sed-opal"
> +#define PLPKS_SED_KEY "opal-boot-pin"
> +
> +/*
> + * authority is admin1 and range is global
> + */
> +#define PLPKS_SED_AUTHORITY 0x0000000900010001
> +#define PLPKS_SED_RANGE 0x0000080200000001
> +
> +void plpks_init_var(struct plpks_var *var, char *keyname)
> +{
> + var->name = keyname;
> + var->namelen = strlen(keyname);
> + if (strcmp(PLPKS_SED_KEY, keyname) == 0) {
> + var->name = PLPKS_SED_MANGLED_LABEL;
> + var->namelen = strlen(keyname);
> + }
> + var->policy = PLPKS_PLATVAR_POLICY;
> + var->os = PLPKS_PLATVAR_OS_COMMON;
> + var->data = NULL;
> + var->datalen = 0;
> + var->component = PLPKS_SED_COMPONENT;
> +}
> +
> +/*
> + * Read the SED Opal key from PLPKS given the label
> + */
> +int sed_read_key(char *keyname, char *key, u_int *keylen)
> +{
> + struct plpks_var var;
> + struct plpks_sed_object_data *data;
> + u_int offset = 0;
> + int ret;
> +
> + plpks_init_var(&var, keyname);
> +
> + offset = offsetof(struct plpks_sed_object_data, key);
> +
> + ret = plpks_read_os_var(&var);
> + if (ret != 0)
> + return ret;
> +
> + if (offset > var.datalen)
> + offset = 0;
> +
> + data = (struct plpks_sed_object_data *)var.data;
> + *keylen = be32_to_cpu(data->key_len);
> +
> + if (var.data) {
> + memcpy(key, var.data + offset, var.datalen - offset)> + key[*keylen] = '\0';
> + kfree(var.data);
> + }
> +
> + return 0;
> +}
> +
> +/*
> + * Write the SED Opal key to PLPKS given the label
> + */
> +int sed_write_key(char *keyname, char *key, u_int keylen)
> +{
> + struct plpks_var var;
> + struct plpks_sed_object_data data;
> + struct plpks_var_name vname;
> +
> + plpks_init_var(&var, keyname);
> +
> + var.datalen = sizeof(struct plpks_sed_object_data);
> + var.data = (u8 *)&data;
> +
> + /* initialize SED object */
> + data.version = PLPKS_SED_OBJECT_DATA_V0;
> + data.authority = cpu_to_be64(PLPKS_SED_AUTHORITY);
> + data.range = cpu_to_be64(PLPKS_SED_RANGE);
> + memset(&data.pad1, '\0', sizeof(data.pad1));
> + data.key_len = cpu_to_be32(keylen);
> + memcpy(data.key, (char *)key, keylen);
> +
> + /*
> + * Key update requires remove first. The return value
> + * is ignored since it's okay if the key doesn't exist.
> + */
> + vname.namelen = var.namelen;
> + vname.name = var.name;
> + plpks_remove_var(var.component, var.os, vname);
> +
> + return plpks_write_var(var);
> +}
next prev parent reply other threads:[~2022-10-07 18:22 UTC|newest]
Thread overview: 10+ messages / expand[flat|nested] mbox.gz Atom feed top
2022-08-19 22:31 [PATCH v4 0/3] generic and PowerPC SED Opal keystore gjoyce
2022-08-19 22:31 ` [PATCH v4 1/3] block: sed-opal: " gjoyce
2022-10-07 18:23 ` Jonathan Derrick
2022-08-19 22:31 ` [PATCH v4 2/3] powerpc/pseries: PLPKS SED Opal keystore support gjoyce
2022-10-07 18:22 ` Jonathan Derrick [this message]
2022-10-07 19:09 ` Elliott, Robert (Servers)
2022-11-16 23:44 ` Greg Joyce
2022-08-19 22:31 ` [PATCH v4 3/3] block: sed-opal: keystore access for SED Opal keys gjoyce
2022-10-07 18:21 ` Jonathan Derrick
2022-11-16 23:16 ` Greg Joyce
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=177ea4f0-93f7-85ac-5cad-9579ecfc5731@linux.dev \
--to=jonathan.derrick@linux.dev \
--cc=akpm@linux-foundation.org \
--cc=axboe@kernel.dk \
--cc=brking@linux.vnet.ibm.com \
--cc=dhowells@redhat.com \
--cc=gjoyce@linux.vnet.ibm.com \
--cc=jarkko@kernel.org \
--cc=keyrings@vger.kernel.org \
--cc=linux-block@vger.kernel.org \
--cc=linux-efi@vger.kernel.org \
--cc=linuxppc-dev@lists.ozlabs.org \
--cc=mpe@ellerman.id.au \
--cc=msuchanek@suse.de \
--cc=nayna@linux.ibm.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).