Received: by 2002:a25:8b12:0:0:0:0:0 with SMTP id i18csp1006515ybl; Wed, 21 Aug 2019 08:43:48 -0700 (PDT) X-Google-Smtp-Source: APXvYqyUVzCl+/WMOTUxKnq4by6If4wyDBMVaxrXtq+kc4xjw3UreRSH0QDRwDErC5o7538c2RlT X-Received: by 2002:a17:90a:8c0f:: with SMTP id a15mr609864pjo.112.1566402228552; Wed, 21 Aug 2019 08:43:48 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1566402228; cv=none; d=google.com; s=arc-20160816; b=Ee+A6kNh9kdruKuQcjbOCNBncblSKxZlnxTi5bRM52mQwlni8GksYg1+jE5AXNISAz BpCykxCP9vPNmgzA8txpvczVKClu/iFLLLPluZSM70cgUXhZUayT3P4VJ2zPbcX9TobQ kmRD13aFNo/Rmm4febpZwnR/sEXu2mJeBhwsjJuCpy9S4s9yrjNPcixPtQP5zi3x5qQU 5epGXEqr0KJkl1mbBVJge/lPmoSmx5o2ov9bkbrEruW+cALteUtbhAkZlBjwre3dYYJU VRzDTxx7mwyOurVrO02q3dpJrLgEkNRVVRphkZRsx7sODkTql/N1Y9oe306IriP3M0mU gFhw== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:sender:message-id:references:in-reply-to:date :subject:cc:to:from; bh=MX5JjWhjqmtMZ+zLRH85W1SWVXIQPt8Id8s6/MRzcdE=; b=EwoH1D9w4l3/V8+bw8Xos/OrOmOxGQI0vJ39ZpQONdHSoMuCJwmZeLsv3JWJ+KRnXp btzC1H5B3UAV7wENlo4KwV2fCG7tv0uWTMI636cm9zABcDt5rHQIjMhRCnV/S6WJWfrA 5YbQIOJGLnQ+I7qT0ANPvGIUMLnKv8GThOu5C8E0g4FAupA3I8PJ1ndMyakdL3SlvhHi aekTUYGbXAg6xgDzP0PAztAWC8Zo6M8SJ7nDqKjPByghMGcoVlj9lHwqsh5dBhTF52vn QwfCvpbIyGHCCTDAUNak1rx5YHsbkjWLiZ/vT7/B3PZfu0+vJE3K5hB2/b/z+p0GcSDA 2ANQ== ARC-Authentication-Results: i=1; mx.google.com; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=ibm.com Return-Path: Received: from vger.kernel.org (vger.kernel.org. [209.132.180.67]) by mx.google.com with ESMTP id 66si16179137pff.223.2019.08.21.08.43.33; Wed, 21 Aug 2019 08:43:48 -0700 (PDT) Received-SPF: pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) client-ip=209.132.180.67; Authentication-Results: mx.google.com; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=ibm.com Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1729830AbfHUPIw (ORCPT + 99 others); Wed, 21 Aug 2019 11:08:52 -0400 Received: from mx0a-001b2d01.pphosted.com ([148.163.156.1]:20976 "EHLO mx0a-001b2d01.pphosted.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1729811AbfHUPIu (ORCPT ); Wed, 21 Aug 2019 11:08:50 -0400 Received: from pps.filterd (m0098409.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.16.0.27/8.16.0.27) with SMTP id x7LF1Chf139072 for ; Wed, 21 Aug 2019 11:08:49 -0400 Received: from e06smtp01.uk.ibm.com (e06smtp01.uk.ibm.com [195.75.94.97]) by mx0a-001b2d01.pphosted.com with ESMTP id 2uh84rrv9w-1 (version=TLSv1.2 cipher=AES256-GCM-SHA384 bits=256 verify=NOT) for ; Wed, 21 Aug 2019 11:08:48 -0400 Received: from localhost by e06smtp01.uk.ibm.com with IBM ESMTP SMTP Gateway: Authorized Use Only! Violators will be prosecuted for from ; Wed, 21 Aug 2019 16:08:46 +0100 Received: from b06avi18626390.portsmouth.uk.ibm.com (9.149.26.192) by e06smtp01.uk.ibm.com (192.168.101.131) with IBM ESMTP SMTP Gateway: Authorized Use Only! Violators will be prosecuted; (version=TLSv1/SSLv3 cipher=AES256-GCM-SHA384 bits=256/256) Wed, 21 Aug 2019 16:08:41 +0100 Received: from d06av23.portsmouth.uk.ibm.com (d06av23.portsmouth.uk.ibm.com [9.149.105.59]) by b06avi18626390.portsmouth.uk.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id x7LF8JrV25559482 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Wed, 21 Aug 2019 15:08:19 GMT Received: from d06av23.portsmouth.uk.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 7FF0AA406E; Wed, 21 Aug 2019 15:08:39 +0000 (GMT) Received: from d06av23.portsmouth.uk.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 094CEA4040; Wed, 21 Aug 2019 15:08:37 +0000 (GMT) Received: from swastik.ibm.com (unknown [9.85.158.102]) by d06av23.portsmouth.uk.ibm.com (Postfix) with ESMTP; Wed, 21 Aug 2019 15:08:36 +0000 (GMT) From: Nayna Jain To: linuxppc-dev@ozlabs.org, linux-efi@vger.kernel.org, linux-integrity@vger.kernel.org Cc: linux-kernel@vger.kernel.org, Michael Ellerman , Benjamin Herrenschmidt , Paul Mackerras , Ard Biesheuvel , Jeremy Kerr , Matthew Garret , Mimi Zohar , Greg Kroah-Hartman , Claudio Carvalho , George Wilson , Elaine Palmer , Eric Ricther , "Oliver O'Halloran" , Nayna Jain Subject: [PATCH v2 2/4] powerpc: expose secure variables to userspace via sysfs Date: Wed, 21 Aug 2019 11:08:21 -0400 X-Mailer: git-send-email 1.8.3.1 In-Reply-To: <1566400103-18201-1-git-send-email-nayna@linux.ibm.com> References: <1566400103-18201-1-git-send-email-nayna@linux.ibm.com> X-TM-AS-GCONF: 00 x-cbid: 19082115-4275-0000-0000-0000035B8B0A X-IBM-AV-DETECTION: SAVI=unused REMOTE=unused XFE=unused x-cbparentid: 19082115-4276-0000-0000-0000386DAEA1 Message-Id: <1566400103-18201-3-git-send-email-nayna@linux.ibm.com> X-Proofpoint-Virus-Version: vendor=fsecure engine=2.50.10434:,, definitions=2019-08-21_05:,, signatures=0 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 priorityscore=1501 malwarescore=0 suspectscore=0 phishscore=0 bulkscore=0 spamscore=0 clxscore=1015 lowpriorityscore=0 mlxscore=0 impostorscore=0 mlxlogscore=999 adultscore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.0.1-1906280000 definitions=main-1908210160 Sender: linux-kernel-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org PowerNV secure variables, which store the keys used for OS kernel verification, are managed by the firmware. These secure variables need to be accessed by the userspace for addition/deletion of the certificates. This patch adds the sysfs interface to expose secure variables for PowerNV secureboot. The users shall use this interface for manipulating the keys stored in the secure variables. Signed-off-by: Nayna Jain --- Documentation/ABI/testing/sysfs-secvar | 27 ++++ arch/powerpc/Kconfig | 9 ++ arch/powerpc/kernel/Makefile | 1 + arch/powerpc/kernel/secvar-sysfs.c | 210 +++++++++++++++++++++++++ 4 files changed, 247 insertions(+) create mode 100644 Documentation/ABI/testing/sysfs-secvar create mode 100644 arch/powerpc/kernel/secvar-sysfs.c diff --git a/Documentation/ABI/testing/sysfs-secvar b/Documentation/ABI/testing/sysfs-secvar new file mode 100644 index 000000000000..68f0e03d873d --- /dev/null +++ b/Documentation/ABI/testing/sysfs-secvar @@ -0,0 +1,27 @@ +What: /sys/firmware/secvar +Date: August 2019 +Contact: Nayna Jain +Description: + This directory exposes interfaces for interacting with + the secure variables managed by OPAL firmware. + + This is only for the powerpc/powernv platform. + + Directory: + vars: This directory lists all the variables that + are supported by the OPAL. The variables are + represented in the form of directories with + their variable names. The variable name is + unique and is in ASCII representation. The data + and size can be determined by reading their + respective attribute files. + + Each variable directory has the following files: + name: An ASCII representation of the variable name + data: A read-only file containing the value of the + variable + size: An integer representation of the size of the + content of the variable. In other works, it + represents the size of the data + update: A write-only file that is used to submit the new + value for the variable. diff --git a/arch/powerpc/Kconfig b/arch/powerpc/Kconfig index 42109682b727..b4bdf77837b2 100644 --- a/arch/powerpc/Kconfig +++ b/arch/powerpc/Kconfig @@ -925,6 +925,15 @@ config PPC_SECURE_BOOT allows user to enable OS Secure Boot on PowerPC systems that have firmware secure boot support. +config SECVAR_SYSFS + tristate "Enable sysfs interface for POWER secure variables" + depends on PPC_SECURE_BOOT + help + POWER secure variables are managed and controlled by firmware. + These variables are exposed to userspace via sysfs to enable + read/write operations on these variables. Say Y if you have + secure boot enabled and want to expose variables to userspace. + endmenu config ISA_DMA_API diff --git a/arch/powerpc/kernel/Makefile b/arch/powerpc/kernel/Makefile index 9041563f1c74..4ea7b738c3a3 100644 --- a/arch/powerpc/kernel/Makefile +++ b/arch/powerpc/kernel/Makefile @@ -158,6 +158,7 @@ obj-$(CONFIG_EPAPR_PARAVIRT) += epapr_paravirt.o epapr_hcalls.o obj-$(CONFIG_KVM_GUEST) += kvm.o kvm_emul.o obj-$(CONFIG_PPC_SECURE_BOOT) += secboot.o ima_arch.o secvar-ops.o +obj-$(CONFIG_SECVAR_SYSFS) += secvar-sysfs.o # Disable GCOV, KCOV & sanitizers in odd or sensitive code GCOV_PROFILE_prom_init.o := n diff --git a/arch/powerpc/kernel/secvar-sysfs.c b/arch/powerpc/kernel/secvar-sysfs.c new file mode 100644 index 000000000000..e46986bb29a0 --- /dev/null +++ b/arch/powerpc/kernel/secvar-sysfs.c @@ -0,0 +1,210 @@ +// SPDX-License-Identifier: GPL-2.0+ +/* + * Copyright (C) 2019 IBM Corporation + * + * This code exposes secure variables to user via sysfs + */ + +#include +#include +#include +#include +#include +#include + +//Approximating it for now, it is bound to change. +#define VARIABLE_MAX_SIZE 32000 + +static struct kobject *powerpc_kobj; +static struct secvar_operations *secvarops; +struct kset *secvar_kset; + +static ssize_t name_show(struct kobject *kobj, struct kobj_attribute *attr, + char *buf) +{ + return sprintf(buf, "%s", kobj->name); +} + +static ssize_t size_show(struct kobject *kobj, struct kobj_attribute *attr, + char *buf) +{ + unsigned long dsize; + int rc; + + rc = secvarops->get_variable(kobj->name, strlen(kobj->name) + 1, NULL, + &dsize); + if (rc) { + pr_err("Error retrieving variable size %d\n", rc); + return rc; + } + + rc = sprintf(buf, "%ld", dsize); + + return rc; +} + +static ssize_t data_read(struct file *filep, struct kobject *kobj, + struct bin_attribute *attr, char *buf, loff_t off, + size_t count) +{ + unsigned long dsize; + int rc; + char *data; + + rc = secvarops->get_variable(kobj->name, strlen(kobj->name) + 1, NULL, + &dsize); + if (rc) { + pr_err("Error getting variable size %d\n", rc); + return rc; + } + pr_debug("dsize is %ld\n", dsize); + + data = kzalloc(dsize, GFP_KERNEL); + if (!data) + return -ENOMEM; + + rc = secvarops->get_variable(kobj->name, strlen(kobj->name)+1, data, + &dsize); + if (rc) { + pr_err("Error getting variable %d\n", rc); + goto data_fail; + } + + rc = memory_read_from_buffer(buf, count, &off, data, dsize); + +data_fail: + kfree(data); + return rc; +} + +static ssize_t update_write(struct file *filep, struct kobject *kobj, + struct bin_attribute *attr, char *buf, loff_t off, + size_t count) +{ + int rc; + + pr_debug("count is %ld\n", count); + rc = secvarops->set_variable(kobj->name, strlen(kobj->name)+1, buf, + count); + if (rc) { + pr_err("Error setting the variable %s\n", kobj->name); + return rc; + } + + return count; +} + +static struct kobj_attribute name_attr = +__ATTR(name, 0444, name_show, NULL); + +static struct kobj_attribute size_attr = +__ATTR(size, 0444, size_show, NULL); + +static struct bin_attribute data_attr = { + .attr = {.name = "data", .mode = 0444}, + .size = VARIABLE_MAX_SIZE, + .read = data_read, +}; + + +static struct bin_attribute update_attr = { + .attr = {.name = "update", .mode = 0200}, + .size = VARIABLE_MAX_SIZE, + .write = update_write, +}; + +static struct bin_attribute *secvar_bin_attrs[] = { + &data_attr, + &update_attr, + NULL, +}; + +static struct attribute *secvar_attrs[] = { + &name_attr.attr, + &size_attr.attr, + NULL, +}; + +const struct attribute_group secvar_attr_group = { + .attrs = secvar_attrs, + .bin_attrs = secvar_bin_attrs, +}; + +int secvar_sysfs_load(void) +{ + + char *name; + unsigned long namesize; + struct kobject *kobj; + int status; + int rc = 0; + + name = kzalloc(1024, GFP_KERNEL); + if (!name) + return -ENOMEM; + + do { + + status = secvarops->get_next_variable(name, &namesize, 1024); + if (status != OPAL_SUCCESS) + break; + + pr_info("name is %s\n", name); + kobj = kobject_create_and_add(name, &(secvar_kset->kobj)); + if (kobj) { + rc = sysfs_create_group(kobj, &secvar_attr_group); + if (rc) + pr_err("Error creating attributes for %s variable\n", + name); + } else { + pr_err("Error creating sysfs entry for %s variable\n", + name); + rc = -EINVAL; + } + + } while ((status == OPAL_SUCCESS) && (rc == 0)); + + kfree(name); + return rc; +} + +int secvar_sysfs_init(void) +{ + powerpc_kobj = kobject_create_and_add("secvar", firmware_kobj); + if (!powerpc_kobj) { + pr_err("secvar: Failed to create firmware kobj\n"); + return -ENODEV; + } + + secvar_kset = kset_create_and_add("vars", NULL, powerpc_kobj); + if (!secvar_kset) { + pr_err("secvar: sysfs kobject registration failed.\n"); + return -ENODEV; + } + + secvarops = get_secvar_ops(); + if (!secvarops) { + kobject_put(powerpc_kobj); + pr_err("secvar: failed to retrieve secvar operations.\n"); + return -ENODEV; + } + + secvar_sysfs_load(); + pr_info("Secure variables sysfs initialized"); + + return 0; +} +EXPORT_SYMBOL_GPL(secvar_sysfs_init); + +static void secvar_sysfs_exit(void) +{ + kobject_put(powerpc_kobj); +} +EXPORT_SYMBOL_GPL(secvar_sysfs_exit); + +module_init(secvar_sysfs_init); +module_exit(secvar_sysfs_exit); + +MODULE_AUTHOR("Nayna Jain"); +MODULE_DESCRIPTION("sysfs interface to POWER secure variables"); +MODULE_LICENSE("GPL"); -- 2.20.1