Received: by 2002:ab2:7041:0:b0:1f4:bcc8:f211 with SMTP id x1csp10400lql; Fri, 12 Apr 2024 01:47:59 -0700 (PDT) X-Forwarded-Encrypted: i=3; AJvYcCX5X2efzw5+JCVJMbCmPFGJf681kVbUeRHlyK/8wtW1UZdB9xIEXqbmPnAM772ba/QnUgK+Oc+11uhYJuNs/595ilvSwF20qVNI7lXZOA== X-Google-Smtp-Source: AGHT+IHeoPvSeAGosB8sk2bnNvO0h8S5mxzDDd9iVEfh/vvy3341PySwSGYLEyt33nrp3GKlfEEL X-Received: by 2002:a05:6a20:3250:b0:1a3:8e1d:16b8 with SMTP id hm16-20020a056a20325000b001a38e1d16b8mr2044505pzc.28.1712911679364; Fri, 12 Apr 2024 01:47:59 -0700 (PDT) ARC-Seal: i=2; a=rsa-sha256; t=1712911679; cv=pass; d=google.com; s=arc-20160816; b=sC9o9/DVUpYywdv4ZaMn17E/z/3Q7oqUnpR/UvNfCx7wLh10F22lfyS9lABukgDdjT fUhoy2ht9VFoJaDQSoHEH85k/03MWdm0QKTudEjoVx/pj1gvCd3h42q/k5IF7OsJEU4S EPdnJBV07EW8ExY447VZj5FGTJAcoq26xO5MLVZiBtrcJyHinKOW3VLbziLWHdcyyRPZ I4ttHQwK+ChriUD7r8mMRPjK+/eO5aJ0TEAl1So8bfs7WWI3NDLyUa0rBZP7UORXzoE/ num/ksMnt0rO9l1cDFxH9YM0BYS0F5NUhsBeEqZF3ZrDX37O4o3bGJ99HOvhQUA68b6e vxNA== ARC-Message-Signature: i=2; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=content-transfer-encoding:mime-version:list-unsubscribe :list-subscribe:list-id:precedence:references:in-reply-to:message-id :date:subject:cc:to:from; bh=dZ7deQ1Z0/IVzjd0qeuWNxTAFM/oilBpz7/jozFMAW4=; fh=9AWGvCwMd4mMyxI7TJ92Wa86a643lV5Iw1qb3xmvBnY=; b=xf+xsvwBRDUvz8Vh0ou7iOV2c08G71ZODJhEqZfEAUTY9722jQYErGiF0y3NLimMIC wUt9ChQxq/WzVbKFGaTemc2+TkZ6e9SZA3KPad5Vh/NHayL0hnViydAGbLrYrlneSgg1 f01ZEejg5K2InXN3oBFg9+7TKGz8FUkWs+tW9aX+F0PrjyM4i5BJpXMirbArG/xRC4en HqrowpgjAs3NM0QWcXP8HhRWbiBO0+KeMKSv97fVEDZlKVkWMKrDpL5MJV6Q4zq0opOA 4LwalpZHlPZEzryaV07zpAxZXXkgFYEhnhhr1TX/Ah9lwSrsq/j3lVOi7HVL9LPYzwpP hvSw==; dara=google.com ARC-Authentication-Results: i=2; mx.google.com; arc=pass (i=1 spf=pass spfdomain=arm.com dmarc=pass fromdomain=arm.com); spf=pass (google.com: domain of linux-kernel+bounces-142266-linux.lists.archive=gmail.com@vger.kernel.org designates 2604:1380:45e3:2400::1 as permitted sender) smtp.mailfrom="linux-kernel+bounces-142266-linux.lists.archive=gmail.com@vger.kernel.org"; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=arm.com Return-Path: Received: from sv.mirrors.kernel.org (sv.mirrors.kernel.org. [2604:1380:45e3:2400::1]) by mx.google.com with ESMTPS id ng9-20020a17090b1a8900b002a29b882714si5244430pjb.187.2024.04.12.01.47.59 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 12 Apr 2024 01:47:59 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-kernel+bounces-142266-linux.lists.archive=gmail.com@vger.kernel.org designates 2604:1380:45e3:2400::1 as permitted sender) client-ip=2604:1380:45e3:2400::1; Authentication-Results: mx.google.com; arc=pass (i=1 spf=pass spfdomain=arm.com dmarc=pass fromdomain=arm.com); spf=pass (google.com: domain of linux-kernel+bounces-142266-linux.lists.archive=gmail.com@vger.kernel.org designates 2604:1380:45e3:2400::1 as permitted sender) smtp.mailfrom="linux-kernel+bounces-142266-linux.lists.archive=gmail.com@vger.kernel.org"; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=arm.com Received: from smtp.subspace.kernel.org (wormhole.subspace.kernel.org [52.25.139.140]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by sv.mirrors.kernel.org (Postfix) with ESMTPS id B7E6D285B22 for ; Fri, 12 Apr 2024 08:46:57 +0000 (UTC) Received: from localhost.localdomain (localhost.localdomain [127.0.0.1]) by smtp.subspace.kernel.org (Postfix) with ESMTP id EE1CB59B48; Fri, 12 Apr 2024 08:42:55 +0000 (UTC) Received: from foss.arm.com (foss.arm.com [217.140.110.172]) by smtp.subspace.kernel.org (Postfix) with ESMTP id D05FD59144; Fri, 12 Apr 2024 08:42:52 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=217.140.110.172 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1712911375; cv=none; b=Fv5cjfWKM4hw/FpX5XM7bhBNSMJfvhaxJhsNZsBuq3ZOs+mz+W7j+nyjh5wZLqNvEL4PS4XRi55BU84MKb1wX5ATCHAzptHSPO49eJHCxPkIjnbU2gQ+Cstt94874oBbFJ+MBoscccJ3Xj4IuZoTFqAF0Idk8oskoMQ89z5yKyw= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1712911375; c=relaxed/simple; bh=Buv1HYJSYa+n1Zma6QisDz7cBN3yfD+mKL7KrmTpqYQ=; h=From:To:Cc:Subject:Date:Message-Id:In-Reply-To:References: MIME-Version; b=ACvzdr7Uwq34XK3V/f8T+PgUTlGEzBq1N64Ra5iHf9DmjsvY03Tl3n9xRqfjxdo/wMju1SPrxOxW19mMRNgO6xnGGQoqF6VQiC/WcfUzNGSXANOaDXhMmKbETIJfD5ZQ5BWMPa6V/CsvpYGhX1mmg08HSvdD6iyJfHXK+0gZHZs= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=arm.com; spf=pass smtp.mailfrom=arm.com; arc=none smtp.client-ip=217.140.110.172 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=arm.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=arm.com Received: from usa-sjc-imap-foss1.foss.arm.com (unknown [10.121.207.14]) by usa-sjc-mx-foss1.foss.arm.com (Postfix) with ESMTP id B016F339; Fri, 12 Apr 2024 01:43:21 -0700 (PDT) Received: from e112269-lin.cambridge.arm.com (e112269-lin.cambridge.arm.com [10.1.194.51]) by usa-sjc-imap-foss1.foss.arm.com (Postfix) with ESMTPSA id 3D1D13F6C4; Fri, 12 Apr 2024 01:42:50 -0700 (PDT) From: Steven Price To: kvm@vger.kernel.org, kvmarm@lists.linux.dev Cc: Sami Mujawar , Catalin Marinas , Marc Zyngier , Will Deacon , James Morse , Oliver Upton , Suzuki K Poulose , Zenghui Yu , linux-arm-kernel@lists.infradead.org, linux-kernel@vger.kernel.org, Joey Gouly , Alexandru Elisei , Christoffer Dall , Fuad Tabba , linux-coco@lists.linux.dev, Ganapatrao Kulkarni , Steven Price Subject: [PATCH v2 13/14] arm64: rsi: Interfaces to query attestation token Date: Fri, 12 Apr 2024 09:42:12 +0100 Message-Id: <20240412084213.1733764-14-steven.price@arm.com> X-Mailer: git-send-email 2.39.2 In-Reply-To: <20240412084213.1733764-1-steven.price@arm.com> References: <20240412084056.1733704-1-steven.price@arm.com> <20240412084213.1733764-1-steven.price@arm.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit From: Sami Mujawar Add interfaces to query the attestation token using the RSI calls. Signed-off-by: Sami Mujawar Signed-off-by: Suzuki K Poulose Signed-off-by: Steven Price --- arch/arm64/include/asm/rsi_cmds.h | 74 +++++++++++++++++++++++++++++++ 1 file changed, 74 insertions(+) diff --git a/arch/arm64/include/asm/rsi_cmds.h b/arch/arm64/include/asm/rsi_cmds.h index b4cbeafa2f41..c1850aefe54e 100644 --- a/arch/arm64/include/asm/rsi_cmds.h +++ b/arch/arm64/include/asm/rsi_cmds.h @@ -10,6 +10,9 @@ #include +#define GRANULE_SHIFT 12 +#define GRANULE_SIZE (_AC(1, UL) << GRANULE_SHIFT) + enum ripas { RSI_RIPAS_EMPTY, RSI_RIPAS_RAM, @@ -66,4 +69,75 @@ static inline unsigned long rsi_set_addr_range_state(phys_addr_t start, return res.a0; } +/** + * rsi_attestation_token_init - Initialise the operation to retrieve an + * attestation token. + * + * @challenge: The challenge data to be used in the attestation token + * generation. + * @size: Size of the challenge data in bytes. + * + * Initialises the attestation token generation and returns an upper bound + * on the attestation token size that can be used to allocate an adequate + * buffer. The caller is expected to subsequently call + * rsi_attestation_token_continue() to retrieve the attestation token data on + * the same CPU. + * + * Returns: + * On success, returns the upper limit of the attestation report size. + * Otherwise, -EINVAL + */ +static inline unsigned long +rsi_attestation_token_init(const u8 *challenge, unsigned long size) +{ + struct arm_smccc_1_2_regs regs = { 0 }; + + /* The challenge must be at least 32bytes and at most 64bytes */ + if (!challenge || size < 32 || size > 64) + return -EINVAL; + + regs.a0 = SMC_RSI_ATTESTATION_TOKEN_INIT; + memcpy(®s.a1, challenge, size); + arm_smccc_1_2_smc(®s, ®s); + + if (regs.a0 == RSI_SUCCESS) + return regs.a1; + + return -EINVAL; +} + +/** + * rsi_attestation_token_continue - Continue the operation to retrieve an + * attestation token. + * + * @granule: {I}PA of the Granule to which the token will be written. + * @offset: Offset within Granule to start of buffer in bytes. + * @size: The size of the buffer. + * @len: The number of bytes written to the buffer. + * + * Retrieves up to a GRANULE_SIZE worth of token data per call. The caller is + * expected to call rsi_attestation_token_init() before calling this function + * to retrieve the attestation token. + * + * Return: + * * %RSI_SUCCESS - Attestation token retrieved successfully. + * * %RSI_INCOMPLETE - Token generation is not complete. + * * %RSI_ERROR_INPUT - A parameter was not valid. + * * %RSI_ERROR_STATE - Attestation not in progress. + */ +static inline int rsi_attestation_token_continue(phys_addr_t granule, + unsigned long offset, + unsigned long size, + unsigned long *len) +{ + struct arm_smccc_res res; + + arm_smccc_1_1_invoke(SMC_RSI_ATTESTATION_TOKEN_CONTINUE, + granule, offset, size, 0, &res); + + if (len) + *len = res.a1; + return res.a0; +} + #endif -- 2.34.1