Received: by 2002:ab2:6d45:0:b0:1fb:d597:ff75 with SMTP id d5csp174834lqr; Wed, 5 Jun 2024 02:36:11 -0700 (PDT) X-Forwarded-Encrypted: i=3; AJvYcCU28Rzn+/6DBrSCDYBhQPXRBlyrvGsQJ9gIvoOqDSqUqAUPKOl+iogiNzrjDnt3YtaBz8/l/VnmklMpXMU4euhbRMICdiC6qLeQfaqySQ== X-Google-Smtp-Source: AGHT+IH1pYYoZQWFv0TH6XGu0RHA1W4CH1o/g7JiuOBjHuH3OD/2Y/vwBykDULzWDye965XwiWaq X-Received: by 2002:a17:906:b1c5:b0:a68:ff92:46f0 with SMTP id a640c23a62f3a-a699f34c052mr130077966b.10.1717580170913; Wed, 05 Jun 2024 02:36:10 -0700 (PDT) ARC-Seal: i=2; a=rsa-sha256; t=1717580170; cv=pass; d=google.com; s=arc-20160816; b=PgywaVx+IRlnlowC7TrnPkQGxrsLNiGxMIDdX4tEBtd2mm9cwGNXs0F6AKXzqPV5nF uv11hnvRz1W7GXGyiujmudeMEbPMLgU8h9/XxvVQyedFntAA0lHEjAjG45T9jgsB8jUt UF+X1dNzTSelEULybvkzKjmrqUv8hdmUnU9ve6X5ZuN1eyfGvxdzVZ+YO+hv0eEDbYUo shFca5Qbb5yp4gAbnvAsknCvlEhcwCx2ksGeOmDWzxSOXxh6zZDiTVit5wQnaEd2TaoD 5mZynxGYj/xby0pSipbD225b/YE6Vx6NCAS6Ek1kVfI9AOZqFurYv+9dASq04g2NMAQ9 CVog== ARC-Message-Signature: i=2; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=content-transfer-encoding:mime-version:list-unsubscribe :list-subscribe:list-id:precedence:references:in-reply-to:message-id :date:subject:cc:to:from; bh=F/rHeOkdsc9LvO9MaYietGBYwkL9mh8vq3UclBrGNaw=; fh=9AWGvCwMd4mMyxI7TJ92Wa86a643lV5Iw1qb3xmvBnY=; b=TvsGMAPJ4Sesd27s1TvKYZncsxxXv4R5hqdlsFdz3RqAndY1n8tO9SfxY6B2fOdXYk sdZ0Ja5nZpo+LeD8Kj/jI7Pngj+T9cafBtd4u0ARneKKBSnrq0JTdGoP2J2bJuv337eD HZ0oy2KBvvSvtlbjfXnv4Q4EWPHob+X2EOaqjs0Z3D94odbW/WhIM1VrMubhI2/n/ZOU kqY8wgIWtt/EdN9HhT0M4aw8ny4nRZzZl1c/Qfdzeao/+u1Lmf8Z5vfFsmkeuhckJs42 K6UyvgpOu4DRSjPEHk2W1KHYRuLycrksQndNiJ5Wl+uDvWs5HftT3UXFH1o1ovk1MvHY or1Q==; dara=google.com ARC-Authentication-Results: i=2; mx.google.com; arc=pass (i=1 spf=pass spfdomain=arm.com dmarc=pass fromdomain=arm.com); spf=pass (google.com: domain of linux-kernel+bounces-202112-linux.lists.archive=gmail.com@vger.kernel.org designates 2604:1380:4601:e00::3 as permitted sender) smtp.mailfrom="linux-kernel+bounces-202112-linux.lists.archive=gmail.com@vger.kernel.org"; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=arm.com Return-Path: Received: from am.mirrors.kernel.org (am.mirrors.kernel.org. [2604:1380:4601:e00::3]) by mx.google.com with ESMTPS id a640c23a62f3a-a68abd7d45fsi455850266b.89.2024.06.05.02.36.10 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 05 Jun 2024 02:36:10 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-kernel+bounces-202112-linux.lists.archive=gmail.com@vger.kernel.org designates 2604:1380:4601:e00::3 as permitted sender) client-ip=2604:1380:4601:e00::3; Authentication-Results: mx.google.com; arc=pass (i=1 spf=pass spfdomain=arm.com dmarc=pass fromdomain=arm.com); spf=pass (google.com: domain of linux-kernel+bounces-202112-linux.lists.archive=gmail.com@vger.kernel.org designates 2604:1380:4601:e00::3 as permitted sender) smtp.mailfrom="linux-kernel+bounces-202112-linux.lists.archive=gmail.com@vger.kernel.org"; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=arm.com Received: from smtp.subspace.kernel.org (wormhole.subspace.kernel.org [52.25.139.140]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by am.mirrors.kernel.org (Postfix) with ESMTPS id 9973C1F2283F for ; Wed, 5 Jun 2024 09:36:10 +0000 (UTC) Received: from localhost.localdomain (localhost.localdomain [127.0.0.1]) by smtp.subspace.kernel.org (Postfix) with ESMTP id BA95B21C16F; Wed, 5 Jun 2024 09:31:11 +0000 (UTC) Received: from foss.arm.com (foss.arm.com [217.140.110.172]) by smtp.subspace.kernel.org (Postfix) with ESMTP id C3535199240; Wed, 5 Jun 2024 09:31:09 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=217.140.110.172 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1717579871; cv=none; b=G5HAzaXRoyy5M0VpYUuAxhjctIs1AQU3h2MIxKV2K6HXlyop8Ox6VALte4eJdCFHuunfVaeHmIdyH38/xy5gFDaOslmgDat//lCecOZjvbyJx6ZffGUiBN6koMFSt/p3vtXFWAAFP5iq6pEf0OehMYji4vvPr+mbT1uiDgLktdg= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1717579871; c=relaxed/simple; bh=cFWPoeb1yYKNg006l/xAGot1cV61wPsSLxGwON8u0Hc=; h=From:To:Cc:Subject:Date:Message-Id:In-Reply-To:References: MIME-Version; b=m/WEaRx0g9N+pynugOnUT+00orugTYX2IrEBkP3rlvm2rlvOFtZ+T+n1XVQWC0EVVB2ttRIi1mKC7C8TB87KRP3dZoXJVesN3hN+RkLVIC5JTExOGblGG8QTCeL6wgjnu4HB3D2NHfkK/vhd5F+XnJ+yCfZt0UAPJfiJV9PUpf8= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=arm.com; spf=pass smtp.mailfrom=arm.com; arc=none smtp.client-ip=217.140.110.172 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=arm.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=arm.com Received: from usa-sjc-imap-foss1.foss.arm.com (unknown [10.121.207.14]) by usa-sjc-mx-foss1.foss.arm.com (Postfix) with ESMTP id C3074DA7; Wed, 5 Jun 2024 02:31:33 -0700 (PDT) Received: from e122027.arm.com (unknown [10.57.39.129]) by usa-sjc-imap-foss1.foss.arm.com (Postfix) with ESMTPSA id 17F1D3F792; Wed, 5 Jun 2024 02:31:05 -0700 (PDT) From: Steven Price To: kvm@vger.kernel.org, kvmarm@lists.linux.dev Cc: Sami Mujawar , Catalin Marinas , Marc Zyngier , Will Deacon , James Morse , Oliver Upton , Suzuki K Poulose , Zenghui Yu , linux-arm-kernel@lists.infradead.org, linux-kernel@vger.kernel.org, Joey Gouly , Alexandru Elisei , Christoffer Dall , Fuad Tabba , linux-coco@lists.linux.dev, Ganapatrao Kulkarni , Steven Price Subject: [PATCH v3 13/14] arm64: rsi: Interfaces to query attestation token Date: Wed, 5 Jun 2024 10:30:05 +0100 Message-Id: <20240605093006.145492-14-steven.price@arm.com> X-Mailer: git-send-email 2.34.1 In-Reply-To: <20240605093006.145492-1-steven.price@arm.com> References: <20240605093006.145492-1-steven.price@arm.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit From: Sami Mujawar Add interfaces to query the attestation token using the RSI calls. Signed-off-by: Sami Mujawar Signed-off-by: Suzuki K Poulose Signed-off-by: Steven Price --- v3: Prefix GRANULE_xxx defines with RSI_. --- arch/arm64/include/asm/rsi_cmds.h | 74 +++++++++++++++++++++++++++++++ 1 file changed, 74 insertions(+) diff --git a/arch/arm64/include/asm/rsi_cmds.h b/arch/arm64/include/asm/rsi_cmds.h index ab8ad435f10e..ca0ea5929ecc 100644 --- a/arch/arm64/include/asm/rsi_cmds.h +++ b/arch/arm64/include/asm/rsi_cmds.h @@ -10,6 +10,9 @@ #include +#define RSI_GRANULE_SHIFT 12 +#define RSI_GRANULE_SIZE (_AC(1, UL) << RSI_GRANULE_SHIFT) + enum ripas { RSI_RIPAS_EMPTY, RSI_RIPAS_RAM, @@ -66,4 +69,75 @@ static inline unsigned long rsi_set_addr_range_state(phys_addr_t start, return res.a0; } +/** + * rsi_attestation_token_init - Initialise the operation to retrieve an + * attestation token. + * + * @challenge: The challenge data to be used in the attestation token + * generation. + * @size: Size of the challenge data in bytes. + * + * Initialises the attestation token generation and returns an upper bound + * on the attestation token size that can be used to allocate an adequate + * buffer. The caller is expected to subsequently call + * rsi_attestation_token_continue() to retrieve the attestation token data on + * the same CPU. + * + * Returns: + * On success, returns the upper limit of the attestation report size. + * Otherwise, -EINVAL + */ +static inline unsigned long +rsi_attestation_token_init(const u8 *challenge, unsigned long size) +{ + struct arm_smccc_1_2_regs regs = { 0 }; + + /* The challenge must be at least 32bytes and at most 64bytes */ + if (!challenge || size < 32 || size > 64) + return -EINVAL; + + regs.a0 = SMC_RSI_ATTESTATION_TOKEN_INIT; + memcpy(®s.a1, challenge, size); + arm_smccc_1_2_smc(®s, ®s); + + if (regs.a0 == RSI_SUCCESS) + return regs.a1; + + return -EINVAL; +} + +/** + * rsi_attestation_token_continue - Continue the operation to retrieve an + * attestation token. + * + * @granule: {I}PA of the Granule to which the token will be written. + * @offset: Offset within Granule to start of buffer in bytes. + * @size: The size of the buffer. + * @len: The number of bytes written to the buffer. + * + * Retrieves up to a RSI_GRANULE_SIZE worth of token data per call. The caller + * is expected to call rsi_attestation_token_init() before calling this + * function to retrieve the attestation token. + * + * Return: + * * %RSI_SUCCESS - Attestation token retrieved successfully. + * * %RSI_INCOMPLETE - Token generation is not complete. + * * %RSI_ERROR_INPUT - A parameter was not valid. + * * %RSI_ERROR_STATE - Attestation not in progress. + */ +static inline int rsi_attestation_token_continue(phys_addr_t granule, + unsigned long offset, + unsigned long size, + unsigned long *len) +{ + struct arm_smccc_res res; + + arm_smccc_1_1_invoke(SMC_RSI_ATTESTATION_TOKEN_CONTINUE, + granule, offset, size, 0, &res); + + if (len) + *len = res.a1; + return res.a0; +} + #endif -- 2.34.1