emmc_rpmb.c 39 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273747576777879808182838485868788899091929394959697989910010110210310410510610710810911011111211311411511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414514614714814915015115215315415515615715815916016116216316416516616716816917017117217317417517617717817918018118218318418518618718818919019119219319419519619719819920020120220320420520620720820921021121221321421521621721821922022122222322422522622722822923023123223323423523623723823924024124224324424524624724824925025125225325425525625725825926026126226326426526626726826927027127227327427527627727827928028128228328428528628728828929029129229329429529629729829930030130230330430530630730830931031131231331431531631731831932032132232332432532632732832933033133233333433533633733833934034134234334434534634734834935035135235335435535635735835936036136236336436536636736836937037137237337437537637737837938038138238338438538638738838939039139239339439539639739839940040140240340440540640740840941041141241341441541641741841942042142242342442542642742842943043143243343443543643743843944044144244344444544644744844945045145245345445545645745845946046146246346446546646746846947047147247347447547647747847948048148248348448548648748848949049149249349449549649749849950050150250350450550650750850951051151251351451551651751851952052152252352452552652752852953053153253353453553653753853954054154254354454554654754854955055155255355455555655755855956056156256356456556656756856957057157257357457557657757857958058158258358458558658758858959059159259359459559659759859960060160260360460560660760860961061161261361461561661761861962062162262362462562662762862963063163263363463563663763863964064164264364464564664764864965065165265365465565665765865966066166266366466566666766866967067167267367467567667767867968068168268368468568668768868969069169269369469569669769869970070170270370470570670770870971071171271371471571671771871972072172272372472572672772872973073173273373473573673773873974074174274374474574674774874975075175275375475575675775875976076176276376476576676776876977077177277377477577677777877978078178278378478578678778878979079179279379479579679779879980080180280380480580680780880981081181281381481581681781881982082182282382482582682782882983083183283383483583683783883984084184284384484584684784884985085185285385485585685785885986086186286386486586686786886987087187287387487587687787887988088188288388488588688788888989089189289389489589689789889990090190290390490590690790890991091191291391491591691791891992092192292392492592692792892993093193293393493593693793893994094194294394494594694794894995095195295395495595695795895996096196296396496596696796896997097197297397497597697797897998098198298398498598698798898999099199299399499599699799899910001001100210031004100510061007100810091010101110121013101410151016101710181019102010211022102310241025102610271028102910301031103210331034103510361037103810391040104110421043104410451046104710481049105010511052105310541055105610571058105910601061106210631064106510661067106810691070107110721073107410751076107710781079108010811082108310841085108610871088108910901091109210931094109510961097109810991100110111021103110411051106110711081109111011111112111311141115111611171118111911201121112211231124112511261127112811291130113111321133113411351136113711381139114011411142114311441145114611471148114911501151115211531154115511561157115811591160116111621163116411651166116711681169117011711172117311741175117611771178117911801181118211831184118511861187118811891190119111921193119411951196119711981199120012011202120312041205120612071208120912101211121212131214121512161217121812191220122112221223122412251226122712281229123012311232123312341235123612371238123912401241124212431244124512461247124812491250125112521253125412551256125712581259126012611262126312641265126612671268126912701271127212731274127512761277127812791280128112821283128412851286128712881289129012911292129312941295129612971298129913001301130213031304130513061307130813091310131113121313131413151316131713181319132013211322132313241325132613271328132913301331133213331334133513361337133813391340134113421343134413451346134713481349135013511352135313541355135613571358135913601361136213631364136513661367136813691370137113721373137413751376137713781379138013811382138313841385138613871388138913901391139213931394139513961397139813991400140114021403140414051406140714081409141014111412141314141415141614171418141914201421142214231424142514261427142814291430143114321433143414351436143714381439144014411442144314441445144614471448144914501451145214531454145514561457145814591460146114621463146414651466146714681469147014711472147314741475147614771478147914801481148214831484148514861487148814891490149114921493149414951496149714981499150015011502150315041505150615071508150915101511151215131514151515161517151815191520152115221523152415251526152715281529153015311532153315341535153615371538153915401541154215431544154515461547154815491550155115521553155415551556155715581559156015611562156315641565156615671568156915701571157215731574157515761577157815791580158115821583158415851586158715881589159015911592159315941595159615971598159916001601160216031604160516061607160816091610161116121613161416151616161716181619162016211622162316241625162616271628162916301631163216331634163516361637163816391640164116421643164416451646164716481649165016511652
  1. /*
  2. * Copyright (C) 2015 MediaTek Inc.
  3. *
  4. * This program is free software: you can redistribute it and/or modify
  5. * it under the terms of the GNU General Public License version 2 as
  6. * published by the Free Software Foundation.
  7. *
  8. * This program is distributed in the hope that it will be useful,
  9. * but WITHOUT ANY WARRANTY; without even the implied warranty of
  10. * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
  11. * GNU General Public License for more details.
  12. */
  13. #include <linux/kernel.h>
  14. #include <linux/module.h>
  15. #include <linux/init.h>
  16. #include <linux/moduleparam.h>
  17. #include <linux/slab.h>
  18. #include <linux/unistd.h>
  19. #include <linux/sched.h>
  20. #include <linux/fs.h>
  21. #include <linux/uaccess.h>
  22. #include <linux/version.h>
  23. #include <linux/spinlock.h>
  24. #include <linux/semaphore.h>
  25. #include <linux/delay.h>
  26. #include <linux/kthread.h>
  27. #include <linux/errno.h>
  28. #include <linux/cdev.h>
  29. #include <linux/device.h>
  30. #include <linux/mutex.h>
  31. #include <linux/string.h>
  32. #include <linux/random.h>
  33. #include <linux/memory.h>
  34. #include <linux/io.h>
  35. #include <linux/proc_fs.h>
  36. #include <crypto/hash.h>
  37. #include <linux/scatterlist.h>
  38. #include <linux/mmc/card.h>
  39. #include <linux/mmc/host.h>
  40. #include <linux/mmc/mmc.h>
  41. #include <linux/mmc/core.h>
  42. #include <linux/mmc/sd.h>
  43. #include "drivers/mmc/card/queue.h"
  44. #include "drivers/mmc/core/core.h"
  45. #include "emmc_rpmb.h"
  46. #include "mt_sd.h"
  47. /* TEE usage */
  48. #ifdef CONFIG_TRUSTONIC_TEE_SUPPORT
  49. #include "mobicore_driver_api.h"
  50. #include "drrpmb_Api.h"
  51. #include "drrpmb_gp_Api.h"
  52. static struct mc_uuid_t rpmb_uuid = RPMB_UUID;
  53. static struct mc_session_handle rpmb_session = {0};
  54. static u32 rpmb_devid = MC_DEVICE_ID_DEFAULT;
  55. static dciMessage_t *rpmb_dci;
  56. static struct mc_uuid_t rpmb_gp_uuid = RPMB_GP_UUID;
  57. static struct mc_session_handle rpmb_gp_session = {0};
  58. static u32 rpmb_gp_devid = MC_DEVICE_ID_DEFAULT;
  59. static dciMessage_t *rpmb_gp_dci;
  60. #endif
  61. #define RPMB_NAME "emmcrpmb"
  62. #define DEFAULT_HANDLES_NUM (64)
  63. #define MAX_OPEN_SESSIONS (0xffffffff - 1)
  64. /* Debug message event */
  65. #define DBG_EVT_NONE (0) /* No event */
  66. #define DBG_EVT_CMD (1 << 0)/* SEC CMD related event */
  67. #define DBG_EVT_FUNC (1 << 1)/* SEC function event */
  68. #define DBG_EVT_INFO (1 << 2)/* SEC information event */
  69. #define DBG_EVT_WRN (1 << 30) /* Warning event */
  70. #define DBG_EVT_ERR (1 << 31) /* Error event */
  71. #define DBG_EVT_ALL (0xffffffff)
  72. #define DBG_EVT_MASK (DBG_EVT_ERR)
  73. #define MSG(evt, fmt, args...) \
  74. do {\
  75. if ((DBG_EVT_##evt) & DBG_EVT_MASK) { \
  76. pr_err("[%s] "fmt, RPMB_NAME, ##args); \
  77. } \
  78. } while (0)
  79. #if (defined(CONFIG_MICROTRUST_TZ_DRIVER))
  80. #define RPMB_DATA_BUFF_SIZE (1024 * 24)
  81. #define RPMB_ONE_FRAME_SIZE (512)
  82. static unsigned char *rpmb_buffer;
  83. #endif
  84. struct task_struct *open_th;
  85. struct task_struct *rpmbDci_th;
  86. struct task_struct *rpmb_gp_Dci_th;
  87. static struct cdev rpmb_dev;
  88. static struct class *rpmb_class;
  89. static DEFINE_MUTEX(rpmb_lock);
  90. /*
  91. * This is an alternative way to get mmc_card strcuture from mmc_host which set from msdc driver with
  92. * this callback function.
  93. * The strength is we don't have to extern msdc_host_host global variable, extern global is very bad...
  94. * The weakness is every platform driver needs to add this callback to give rpmb driver the mmc_host
  95. * structure and then we could know card.
  96. *
  97. * Finally, I decide to ignore its strength, because the weakness is more important.
  98. * If every projects have to add this callback, the operation is complicated.
  99. */
  100. #if 0
  101. struct mmc_host *emmc_rpmb_host;
  102. void emmc_rpmb_set_host(void *mmc_host)
  103. {
  104. emmc_rpmb_host = mmc_host;
  105. }
  106. #endif
  107. int hmac_sha256(const char *key, u32 klen, const char *str, u32 len, u8 *hmac)
  108. {
  109. struct shash_desc *shash;
  110. struct crypto_shash *hmacsha256 = crypto_alloc_shash("hmac(sha256)", 0, 0);
  111. u32 size = 0;
  112. int err = 0;
  113. if (IS_ERR(hmacsha256))
  114. return -1;
  115. size = sizeof(struct shash_desc) + crypto_shash_descsize(hmacsha256);
  116. shash = kmalloc(size, GFP_KERNEL);
  117. if (!shash) {
  118. err = -1;
  119. goto malloc_err;
  120. }
  121. shash->tfm = hmacsha256;
  122. shash->flags = 0x0;
  123. err = crypto_shash_setkey(hmacsha256, key, klen);
  124. if (err) {
  125. err = -1;
  126. goto hash_err;
  127. }
  128. err = crypto_shash_init(shash);
  129. if (err) {
  130. err = -1;
  131. goto hash_err;
  132. }
  133. crypto_shash_update(shash, str, len);
  134. err = crypto_shash_final(shash, hmac);
  135. hash_err:
  136. kfree(shash);
  137. malloc_err:
  138. crypto_free_shash(hmacsha256);
  139. return err;
  140. }
  141. /*
  142. * CHECK THIS!!! Copy from block.c mmc_blk_data structure.
  143. */
  144. struct emmc_rpmb_blk_data {
  145. spinlock_t lock;
  146. struct gendisk *disk;
  147. struct mmc_queue queue;
  148. struct list_head part;
  149. unsigned int flags;
  150. unsigned int usage;
  151. unsigned int read_only;
  152. unsigned int part_type;
  153. unsigned int name_idx;
  154. unsigned int reset_done;
  155. /*
  156. * Only set in main mmc_blk_data associated
  157. * with mmc_card with mmc_set_drvdata, and keeps
  158. * track of the current selected device partition.
  159. */
  160. unsigned int part_curr;
  161. struct device_attribute force_ro;
  162. struct device_attribute power_ro_lock;
  163. int area_type;
  164. };
  165. /*
  166. * CHECK THIS!!! Copy from block.c mmc_blk_part_switch.
  167. * Since it is static inline function, we cannot extern to use it.
  168. * For syncing block data, this is the only way.
  169. */
  170. int emmc_rpmb_switch(struct mmc_card *card, struct emmc_rpmb_blk_data *md)
  171. {
  172. int ret;
  173. struct emmc_rpmb_blk_data *main_md = mmc_get_drvdata(card);
  174. if (main_md->part_curr == md->part_type)
  175. return 0;
  176. if (mmc_card_mmc(card)) {
  177. u8 part_config = card->ext_csd.part_config;
  178. part_config &= ~EXT_CSD_PART_CONFIG_ACC_MASK;
  179. part_config |= md->part_type;
  180. ret = mmc_switch(card, EXT_CSD_CMD_SET_NORMAL,
  181. EXT_CSD_PART_CONFIG, part_config,
  182. card->ext_csd.part_time);
  183. if (ret)
  184. return ret;
  185. card->ext_csd.part_config = part_config;
  186. }
  187. main_md->part_curr = md->part_type;
  188. return 0;
  189. }
  190. static void emmc_rpmb_dump_frame(u8 *data_frame)
  191. {
  192. MSG(INFO, "mac, frame[196]=%x\n", data_frame[196]);
  193. MSG(INFO, "mac, frame[197]=%x\n", data_frame[197]);
  194. MSG(INFO, "mac, frame[198]=%x\n", data_frame[198]);
  195. MSG(INFO, "data,frame[228]=%x\n", data_frame[228]);
  196. MSG(INFO, "data,frame[229]=%x\n", data_frame[229]);
  197. MSG(INFO, "nonce, frame[484]=%x\n", data_frame[484]);
  198. MSG(INFO, "nonce, frame[485]=%x\n", data_frame[485]);
  199. MSG(INFO, "nonce, frame[486]=%x\n", data_frame[486]);
  200. MSG(INFO, "nonce, frame[487]=%x\n", data_frame[487]);
  201. MSG(INFO, "wc, frame[500]=%x\n", data_frame[500]);
  202. MSG(INFO, "wc, frame[501]=%x\n", data_frame[501]);
  203. MSG(INFO, "wc, frame[502]=%x\n", data_frame[502]);
  204. MSG(INFO, "wc, frame[503]=%x\n", data_frame[503]);
  205. MSG(INFO, "addr, frame[504]=%x\n", data_frame[504]);
  206. MSG(INFO, "addr, frame[505]=%x\n", data_frame[505]);
  207. MSG(INFO, "blkcnt,frame[506]=%x\n", data_frame[506]);
  208. MSG(INFO, "blkcnt,frame[507]=%x\n", data_frame[507]);
  209. MSG(INFO, "result, frame[508]=%x\n", data_frame[508]);
  210. MSG(INFO, "result, frame[509]=%x\n", data_frame[509]);
  211. MSG(INFO, "type, frame[510]=%x\n", data_frame[510]);
  212. MSG(INFO, "type, frame[511]=%x\n", data_frame[511]);
  213. }
  214. static int emmc_rpmb_send_command(
  215. struct mmc_card *card,
  216. u8 *buf,
  217. __u16 blks,
  218. __u16 type,
  219. u8 req_type
  220. )
  221. {
  222. struct mmc_request mrq = {NULL};
  223. struct mmc_command cmd = {0};
  224. struct mmc_command sbc = {0};
  225. struct mmc_data data = {0};
  226. struct scatterlist sg;
  227. u8 *transfer_buf = NULL;
  228. mrq.sbc = &sbc;
  229. mrq.cmd = &cmd;
  230. mrq.data = &data;
  231. mrq.stop = NULL;
  232. transfer_buf = kzalloc(512 * blks, GFP_KERNEL);
  233. if (!transfer_buf)
  234. return -ENOMEM;
  235. /*
  236. * set CMD23
  237. */
  238. sbc.opcode = MMC_SET_BLOCK_COUNT;
  239. sbc.arg = blks;
  240. if ((req_type == RPMB_REQ && type == RPMB_WRITE_DATA) || type == RPMB_PROGRAM_KEY)
  241. sbc.arg |= 1 << 31;
  242. sbc.flags = MMC_RSP_R1 | MMC_CMD_AC;
  243. /*
  244. * set CMD25/18
  245. */
  246. sg_init_one(&sg, transfer_buf, 512 * blks);
  247. if (req_type == RPMB_REQ) {
  248. cmd.opcode = MMC_WRITE_MULTIPLE_BLOCK;
  249. sg_copy_from_buffer(&sg, 1, buf, 512 * blks);
  250. data.flags |= MMC_DATA_WRITE;
  251. } else {
  252. cmd.opcode = MMC_READ_MULTIPLE_BLOCK;
  253. data.flags |= MMC_DATA_READ;
  254. }
  255. cmd.arg = 0;
  256. cmd.flags = MMC_RSP_R1 | MMC_CMD_ADTC;
  257. data.blksz = 512;
  258. data.blocks = blks;
  259. data.sg = &sg;
  260. data.sg_len = 1;
  261. mmc_set_data_timeout(&data, card);
  262. mmc_wait_for_req(card->host, &mrq);
  263. if (req_type != RPMB_REQ)
  264. sg_copy_to_buffer(&sg, 1, buf, 512 * blks);
  265. kfree(transfer_buf);
  266. if (cmd.error)
  267. return cmd.error;
  268. if (data.error)
  269. return data.error;
  270. return 0;
  271. }
  272. int emmc_rpmb_req_start(struct mmc_card *card, struct emmc_rpmb_req *req)
  273. {
  274. int err = 0;
  275. u16 blks = req->blk_cnt;
  276. u16 type = req->type;
  277. u8 *data_frame = req->data_frame;
  278. MSG(INFO, "%s, start\n", __func__);
  279. /*
  280. * STEP 1: send request to RPMB partition.
  281. */
  282. if (type == RPMB_WRITE_DATA)
  283. err = emmc_rpmb_send_command(card, data_frame, blks, type, RPMB_REQ);
  284. else
  285. err = emmc_rpmb_send_command(card, data_frame, 1, type, RPMB_REQ);
  286. if (err) {
  287. MSG(ERR, "%s step 1, request failed (%d)\n", __func__, err);
  288. goto out;
  289. }
  290. /*
  291. * STEP 2: check write result. Only for WRITE_DATA or Program key.
  292. */
  293. memset(data_frame, 0, 512 * blks);
  294. if (type == RPMB_WRITE_DATA || type == RPMB_PROGRAM_KEY) {
  295. data_frame[RPMB_TYPE_BEG + 1] = RPMB_RESULT_READ;
  296. err = emmc_rpmb_send_command(card, data_frame, 1, RPMB_RESULT_READ, RPMB_REQ);
  297. if (err) {
  298. MSG(ERR, "%s step 2, request result failed (%d)\n", __func__, err);
  299. goto out;
  300. }
  301. }
  302. /*
  303. * STEP 3: get response from RPMB partition
  304. */
  305. data_frame[RPMB_TYPE_BEG] = 0;
  306. data_frame[RPMB_TYPE_BEG + 1] = type;
  307. if (type == RPMB_READ_DATA)
  308. err = emmc_rpmb_send_command(card, data_frame, blks, type, RPMB_RESP);
  309. else
  310. err = emmc_rpmb_send_command(card, data_frame, 1, type, RPMB_RESP);
  311. if (err)
  312. MSG(ERR, "%s step 3, response failed (%d)\n", __func__, err);
  313. MSG(INFO, "%s, end\n", __func__);
  314. out:
  315. return err;
  316. }
  317. int emmc_rpmb_req_handle(struct mmc_card *card, struct emmc_rpmb_req *rpmb_req)
  318. {
  319. struct emmc_rpmb_blk_data *md = NULL, *part_md;
  320. int ret;
  321. emmc_rpmb_dump_frame(rpmb_req->data_frame);
  322. md = mmc_get_drvdata(card);
  323. list_for_each_entry(part_md, &md->part, part) {
  324. if (part_md->part_type == EXT_CSD_PART_CONFIG_ACC_RPMB)
  325. break;
  326. }
  327. MSG(INFO, "%s start.\n", __func__);
  328. mmc_claim_host(card->host);
  329. /*
  330. * STEP1: Switch to RPMB partition.
  331. */
  332. ret = emmc_rpmb_switch(card, part_md);
  333. if (ret) {
  334. MSG(ERR, "%s emmc_rpmb_switch failed. (%x)\n", __func__, ret);
  335. goto error;
  336. }
  337. MSG(INFO, "%s, emmc_rpmb_switch success.\n", __func__);
  338. /*
  339. * STEP2: Start request. (CMD23, CMD25/18 procedure)
  340. */
  341. ret = emmc_rpmb_req_start(card, rpmb_req);
  342. if (ret) {
  343. MSG(ERR, "%s emmc_rpmb_req_start failed!! (%x)\n", __func__, ret);
  344. goto error;
  345. }
  346. MSG(INFO, "%s end.\n", __func__);
  347. error:
  348. mmc_release_host(card->host);
  349. emmc_rpmb_dump_frame(rpmb_req->data_frame);
  350. return ret;
  351. }
  352. /* ********************************************************************************
  353. *
  354. * Following are internal APIs. Stand-alone driver without TEE.
  355. *
  356. *
  357. **********************************************************************************/
  358. int emmc_rpmb_req_set_key(struct mmc_card *card, u8 *key)
  359. {
  360. struct emmc_rpmb_req rpmb_req;
  361. struct s_rpmb *rpmb_frame;
  362. int ret;
  363. MSG(INFO, "%s start!!!\n", __func__);
  364. rpmb_frame = kzalloc(sizeof(struct s_rpmb), 0);
  365. if (rpmb_frame == NULL)
  366. return RPMB_ALLOC_ERROR;
  367. memcpy(rpmb_frame->mac, key, RPMB_SZ_MAC);
  368. rpmb_req.type = RPMB_PROGRAM_KEY;
  369. rpmb_req.blk_cnt = 1;
  370. rpmb_req.data_frame = (u8 *)rpmb_frame;
  371. rpmb_frame->request = cpu_to_be16p(&rpmb_req.type);
  372. ret = emmc_rpmb_req_handle(card, &rpmb_req);
  373. if (ret) {
  374. MSG(ERR, "%s, emmc_rpmb_req_handle IO error!!!(%x)\n", __func__, ret);
  375. goto free;
  376. }
  377. if (rpmb_frame->result) {
  378. MSG(ERR, "%s, result error!!! (%x)\n", __func__, cpu_to_be16p(&rpmb_frame->result));
  379. ret = RPMB_RESULT_ERROR;
  380. }
  381. MSG(INFO, "%s end!!!\n", __func__);
  382. free:
  383. kfree(rpmb_frame);
  384. return ret;
  385. }
  386. int emmc_rpmb_req_get_wc(struct mmc_card *card, u8 *key, u32 *wc)
  387. {
  388. struct emmc_rpmb_req rpmb_req;
  389. struct s_rpmb *rpmb_frame;
  390. u8 nonce[RPMB_SZ_NONCE] = {0};
  391. u8 hmac[RPMB_SZ_MAC];
  392. int ret;
  393. MSG(INFO, "%s start!!!\n", __func__);
  394. do {
  395. rpmb_frame = kzalloc(sizeof(struct s_rpmb), 0);
  396. if (rpmb_frame == NULL)
  397. return RPMB_ALLOC_ERROR;
  398. get_random_bytes(nonce, RPMB_SZ_NONCE);
  399. /*
  400. * Prepare request. Get write counter.
  401. */
  402. rpmb_req.type = RPMB_GET_WRITE_COUNTER;
  403. rpmb_req.blk_cnt = 1;
  404. rpmb_req.data_frame = (u8 *)rpmb_frame;
  405. /*
  406. * Prepare get write counter frame. only need nonce.
  407. */
  408. rpmb_frame->request = cpu_to_be16p(&rpmb_req.type);
  409. memcpy(rpmb_frame->nonce, nonce, RPMB_SZ_NONCE);
  410. ret = emmc_rpmb_req_handle(card, &rpmb_req);
  411. if (ret) {
  412. MSG(ERR, "%s, emmc_rpmb_req_handle IO error!!!(%x)\n", __func__, ret);
  413. break;
  414. }
  415. /*
  416. * Authenticate response write counter frame.
  417. */
  418. hmac_sha256(key, 32, rpmb_frame->data, 284, hmac);
  419. if (memcmp(hmac, rpmb_frame->mac, RPMB_SZ_MAC) != 0) {
  420. MSG(ERR, "%s, hmac compare error!!!\n", __func__);
  421. ret = RPMB_HMAC_ERROR;
  422. break;
  423. }
  424. if (memcmp(nonce, rpmb_frame->nonce, RPMB_SZ_NONCE) != 0) {
  425. MSG(ERR, "%s, nonce compare error!!!\n", __func__);
  426. ret = RPMB_NONCE_ERROR;
  427. break;
  428. }
  429. if (rpmb_frame->result) {
  430. MSG(ERR, "%s, result error!!! (%x)\n", __func__, cpu_to_be16p(&rpmb_frame->result));
  431. ret = RPMB_RESULT_ERROR;
  432. break;
  433. }
  434. *wc = cpu_to_be32p(&rpmb_frame->write_counter);
  435. } while (0);
  436. MSG(INFO, "%s end!!!\n", __func__);
  437. kfree(rpmb_frame);
  438. return ret;
  439. }
  440. int emmc_rpmb_req_write_data(struct mmc_card *card, struct rpmb_ioc_param *param)
  441. {
  442. struct emmc_rpmb_req rpmb_req;
  443. struct s_rpmb *rpmb_frame;
  444. u32 tran_size, left_size = param->data_len;
  445. u32 wc = 0xFFFFFFFF;
  446. u16 iCnt, total_blkcnt, tran_blkcnt, left_blkcnt;
  447. u16 blkaddr;
  448. u8 hmac[RPMB_SZ_MAC];
  449. u8 *dataBuf, *dataBuf_start;
  450. int i, ret = 0;
  451. MSG(INFO, "%s start!!!\n", __func__);
  452. i = 0;
  453. tran_blkcnt = 0;
  454. dataBuf = NULL;
  455. dataBuf_start = NULL;
  456. left_blkcnt = total_blkcnt = ((param->data_len % RPMB_SZ_DATA) ?
  457. (param->data_len / RPMB_SZ_DATA + 1) :
  458. (param->data_len / RPMB_SZ_DATA));
  459. #ifdef RPMB_MULTI_BLOCK_ACCESS
  460. /*
  461. * For RPMB write data, the elements we need in the data frame is
  462. * 1. address.
  463. * 2. write counter.
  464. * 3. data.
  465. * 4. block count.
  466. * 5. MAC
  467. *
  468. */
  469. blkaddr = param->addr;
  470. while (left_blkcnt) {
  471. if (left_blkcnt >= MAX_RPMB_TRANSFER_BLK)
  472. tran_blkcnt = MAX_RPMB_TRANSFER_BLK;
  473. else
  474. tran_blkcnt = left_blkcnt;
  475. MSG(INFO, "%s, total_blkcnt=%x, tran_blkcnt=%x\n", __func__, left_blkcnt, tran_blkcnt);
  476. ret = emmc_rpmb_req_get_wc(card, param->key, &wc);
  477. if (ret) {
  478. MSG(ERR, "%s, emmc_rpmb_req_get_wc error!!!(%x)\n", __func__, ret);
  479. return ret;
  480. }
  481. rpmb_frame = kzalloc(tran_blkcnt * sizeof(struct s_rpmb) + tran_blkcnt * 512, 0);
  482. if (rpmb_frame == NULL)
  483. return RPMB_ALLOC_ERROR;
  484. dataBuf_start = dataBuf = (u8 *)(rpmb_frame + tran_blkcnt);
  485. /*
  486. * Prepare request. write data.
  487. */
  488. rpmb_req.type = RPMB_WRITE_DATA;
  489. rpmb_req.blk_cnt = tran_blkcnt;
  490. rpmb_req.data_frame = (u8 *)rpmb_frame;
  491. /*
  492. * STEP 3(data), prepare every data frame one by one and hook HMAC to the last.
  493. */
  494. for (iCnt = 0; iCnt < tran_blkcnt; iCnt++) {
  495. /*
  496. * Prepare write data frame. need addr, wc, blkcnt, data and mac.
  497. */
  498. rpmb_frame[iCnt].request = cpu_to_be16p(&rpmb_req.type);
  499. rpmb_frame[iCnt].address = cpu_to_be16p(&blkaddr);
  500. rpmb_frame[iCnt].write_counter = cpu_to_be32p(&wc);
  501. rpmb_frame[iCnt].block_count = cpu_to_be16p(&rpmb_req.blk_cnt);
  502. if (left_size >= RPMB_SZ_DATA)
  503. tran_size = RPMB_SZ_DATA;
  504. else
  505. tran_size = left_size;
  506. memcpy(rpmb_frame[iCnt].data,
  507. param->data + i * MAX_RPMB_TRANSFER_BLK * RPMB_SZ_DATA + (iCnt * RPMB_SZ_DATA),
  508. tran_size);
  509. left_size -= tran_size;
  510. memcpy(dataBuf, rpmb_frame[iCnt].data, 284);
  511. dataBuf += 284;
  512. }
  513. iCnt--;
  514. hmac_sha256(param->key, 32, dataBuf_start, 284 * tran_blkcnt, rpmb_frame[iCnt].mac);
  515. /*
  516. * STEP 4, send write data request.
  517. */
  518. ret = emmc_rpmb_req_handle(card, &rpmb_req);
  519. if (ret) {
  520. MSG(ERR, "%s, emmc_rpmb_req_handle IO error!!!(%x)\n", __func__, ret);
  521. break;
  522. }
  523. /*
  524. * STEP 5. authenticate write result response.
  525. * 1. authenticate hmac.
  526. * 2. check result.
  527. * 3. compare write counter is increamented.
  528. */
  529. hmac_sha256(param->key, 32, rpmb_frame->data, 284, hmac);
  530. if (memcmp(hmac, rpmb_frame->mac, RPMB_SZ_MAC) != 0) {
  531. MSG(ERR, "%s, hmac compare error!!!\n", __func__);
  532. ret = RPMB_HMAC_ERROR;
  533. break;
  534. }
  535. if (rpmb_frame->result) {
  536. MSG(ERR, "%s, result error!!! (%x)\n", __func__, cpu_to_be16p(&rpmb_frame->result));
  537. ret = RPMB_RESULT_ERROR;
  538. break;
  539. }
  540. if (cpu_to_be32p(&rpmb_frame->write_counter) != wc + 1) {
  541. MSG(ERR, "%s, write counter error!!! (%x)\n", __func__,
  542. cpu_to_be32p(&rpmb_frame->write_counter));
  543. ret = RPMB_WC_ERROR;
  544. break;
  545. }
  546. blkaddr += tran_blkcnt;
  547. left_blkcnt -= tran_blkcnt;
  548. i++;
  549. kfree(rpmb_frame);
  550. };
  551. if (ret)
  552. kfree(rpmb_frame);
  553. if (left_blkcnt || left_size) {
  554. MSG(ERR, "left_blkcnt or left_size is not empty!!!!!!\n");
  555. return RPMB_TRANSFER_NOT_COMPLETE;
  556. }
  557. #else
  558. rpmb_frame = kzalloc(sizeof(struct s_rpmb), 0);
  559. if (rpmb_frame == NULL)
  560. return RPMB_ALLOC_ERROR;
  561. blkaddr = param->addr;
  562. for (iCnt = 0; iCnt < total_blkcnt; iCnt++) {
  563. ret = emmc_rpmb_req_get_wc(card, param->key, &wc);
  564. if (ret)
  565. break;
  566. memset(rpmb_frame, 0, sizeof(struct s_rpmb));
  567. /*
  568. * Prepare request. write data.
  569. */
  570. rpmb_req.type = RPMB_WRITE_DATA;
  571. rpmb_req.blk_cnt = 1;
  572. rpmb_req.data_frame = (u8 *)rpmb_frame;
  573. /*
  574. * Prepare write data frame. need addr, wc, blkcnt, data and mac.
  575. */
  576. rpmb_frame->request = cpu_to_be16p(&rpmb_req.type);
  577. rpmb_frame->address = cpu_to_be16p(&blkaddr);
  578. rpmb_frame->write_counter = cpu_to_be32p(&wc);
  579. rpmb_frame->block_count = cpu_to_be16p(&rpmb_req.blk_cnt);
  580. if (left_size >= RPMB_SZ_DATA)
  581. tran_size = RPMB_SZ_DATA;
  582. else
  583. tran_size = left_size;
  584. memcpy(rpmb_frame->data, param->data + iCnt * RPMB_SZ_DATA, tran_size);
  585. hmac_sha256(param->key, 32, rpmb_frame->data, 284, rpmb_frame->mac);
  586. ret = emmc_rpmb_req_handle(card, &rpmb_req);
  587. if (ret) {
  588. MSG(ERR, "%s, emmc_rpmb_req_handle IO error!!!(%x)\n", __func__, ret);
  589. break;
  590. }
  591. /*
  592. * Authenticate response write data frame.
  593. */
  594. hmac_sha256(param->key, 32, rpmb_frame->data, 284, hmac);
  595. if (memcmp(hmac, rpmb_frame->mac, RPMB_SZ_MAC) != 0) {
  596. MSG(ERR, "%s, hmac compare error!!!\n", __func__);
  597. ret = RPMB_HMAC_ERROR;
  598. break;
  599. }
  600. if (rpmb_frame->result) {
  601. MSG(ERR, "%s, result error!!! (%x)\n", __func__, cpu_to_be16p(&rpmb_frame->result));
  602. ret = RPMB_RESULT_ERROR;
  603. break;
  604. }
  605. if (cpu_to_be32p(&rpmb_frame->write_counter) != wc + 1) {
  606. MSG(ERR, "%s, write counter error!!! (%x)\n", __func__,
  607. cpu_to_be32p(&rpmb_frame->write_counter));
  608. ret = RPMB_WC_ERROR;
  609. break;
  610. }
  611. left_size -= tran_size;
  612. blkaddr++;
  613. }
  614. kfree(rpmb_frame);
  615. #endif
  616. MSG(INFO, "%s end!!!\n", __func__);
  617. return ret;
  618. }
  619. int emmc_rpmb_req_read_data(struct mmc_card *card, struct rpmb_ioc_param *param)
  620. {
  621. struct emmc_rpmb_req rpmb_req;
  622. /* //if we put a large static buffer here, it will build fail.
  623. * rpmb_frame[MAX_RPMB_TRANSFER_BLK];
  624. * so I use dynamic alloc.
  625. */
  626. struct s_rpmb *rpmb_frame;
  627. u32 tran_size, left_size = param->data_len;
  628. u16 iCnt, total_blkcnt, tran_blkcnt, left_blkcnt;
  629. u16 blkaddr;
  630. u8 nonce[RPMB_SZ_NONCE] = {0};
  631. u8 hmac[RPMB_SZ_MAC];
  632. u8 *dataBuf, *dataBuf_start;
  633. int i, ret = 0;
  634. MSG(INFO, "%s start!!!\n", __func__);
  635. i = 0;
  636. tran_blkcnt = 0;
  637. dataBuf = NULL;
  638. dataBuf_start = NULL;
  639. left_blkcnt = total_blkcnt = ((param->data_len % RPMB_SZ_DATA) ?
  640. (param->data_len / RPMB_SZ_DATA + 1) :
  641. (param->data_len / RPMB_SZ_DATA));
  642. #ifdef RPMB_MULTI_BLOCK_ACCESS
  643. blkaddr = param->addr;
  644. while (left_blkcnt) {
  645. if (left_blkcnt >= MAX_RPMB_TRANSFER_BLK)
  646. tran_blkcnt = MAX_RPMB_TRANSFER_BLK;
  647. else
  648. tran_blkcnt = left_blkcnt;
  649. MSG(INFO, "%s, left_blkcnt=%x, tran_blkcnt=%x\n", __func__, left_blkcnt, tran_blkcnt);
  650. /*
  651. * initial buffer. (since HMAC computation of multi block needs multi buffer, pre-alloced it)
  652. */
  653. rpmb_frame = kzalloc(tran_blkcnt * sizeof(struct s_rpmb) + tran_blkcnt * 512, 0);
  654. if (rpmb_frame == NULL)
  655. return RPMB_ALLOC_ERROR;
  656. dataBuf_start = dataBuf = (u8 *)(rpmb_frame + tran_blkcnt);
  657. get_random_bytes(nonce, RPMB_SZ_NONCE);
  658. /*
  659. * Prepare request.
  660. */
  661. rpmb_req.type = RPMB_READ_DATA;
  662. rpmb_req.blk_cnt = tran_blkcnt;
  663. rpmb_req.data_frame = (u8 *)rpmb_frame;
  664. /*
  665. * Prepare request read data frame. only need addr and nonce.
  666. */
  667. rpmb_frame->request = cpu_to_be16p(&rpmb_req.type);
  668. rpmb_frame->address = cpu_to_be16p(&blkaddr);
  669. memcpy(rpmb_frame->nonce, nonce, RPMB_SZ_NONCE);
  670. ret = emmc_rpmb_req_handle(card, &rpmb_req);
  671. if (ret) {
  672. MSG(ERR, "%s, emmc_rpmb_req_handle IO error!!!(%x)\n", __func__, ret);
  673. break;
  674. }
  675. /*
  676. * STEP 3, retrieve every data frame one by one.
  677. */
  678. for (iCnt = 0; iCnt < tran_blkcnt; iCnt++) {
  679. if (left_size >= RPMB_SZ_DATA)
  680. tran_size = RPMB_SZ_DATA;
  681. else
  682. tran_size = left_size;
  683. /*
  684. * dataBuf used for hmac calculation. we need to aggregate each block's data till to type field.
  685. * each block has 284 bytes need to aggregate.
  686. */
  687. memcpy(dataBuf, rpmb_frame[iCnt].data, 284);
  688. dataBuf = dataBuf + 284;
  689. /*
  690. * sorry, I shouldn't copy read data to user's buffer now, it should be later
  691. * after checking no problem,
  692. * but for convenience...you know...
  693. */
  694. memcpy(param->data + i * MAX_RPMB_TRANSFER_BLK * RPMB_SZ_DATA + (iCnt * RPMB_SZ_DATA),
  695. rpmb_frame[iCnt].data,
  696. tran_size);
  697. left_size -= tran_size;
  698. }
  699. iCnt--;
  700. /*
  701. * Authenticate response read data frame.
  702. */
  703. hmac_sha256(param->key, 32, dataBuf_start, 284 * tran_blkcnt, hmac);
  704. if (memcmp(hmac, rpmb_frame[iCnt].mac, RPMB_SZ_MAC) != 0) {
  705. MSG(ERR, "%s, hmac compare error!!!\n", __func__);
  706. ret = RPMB_HMAC_ERROR;
  707. break;
  708. }
  709. if (memcmp(nonce, rpmb_frame[iCnt].nonce, RPMB_SZ_NONCE) != 0) {
  710. MSG(ERR, "%s, nonce compare error!!!\n", __func__);
  711. ret = RPMB_NONCE_ERROR;
  712. break;
  713. }
  714. if (rpmb_frame[iCnt].result) {
  715. MSG(ERR, "%s, result error!!! (%x)\n", __func__, cpu_to_be16p(&rpmb_frame[iCnt].result));
  716. ret = RPMB_RESULT_ERROR;
  717. break;
  718. }
  719. blkaddr += tran_blkcnt;
  720. left_blkcnt -= tran_blkcnt;
  721. i++;
  722. kfree(rpmb_frame);
  723. };
  724. if (ret)
  725. kfree(rpmb_frame);
  726. if (left_blkcnt || left_size) {
  727. MSG(ERR, "left_blkcnt or left_size is not empty!!!!!!\n");
  728. return RPMB_TRANSFER_NOT_COMPLETE;
  729. }
  730. #else
  731. rpmb_frame = kzalloc(sizeof(struct s_rpmb), 0);
  732. if (rpmb_frame == NULL)
  733. return RPMB_ALLOC_ERROR;
  734. blkaddr = param->addr;
  735. for (iCnt = 0; iCnt < total_blkcnt; iCnt++) {
  736. memset(rpmb_frame, 0, sizeof(struct s_rpmb));
  737. get_random_bytes(nonce, RPMB_SZ_NONCE);
  738. /*
  739. * Prepare request.
  740. */
  741. rpmb_req.type = RPMB_READ_DATA;
  742. rpmb_req.blk_cnt = 1;
  743. rpmb_req.data_frame = (u8 *)rpmb_frame;
  744. /*
  745. * Prepare request read data frame. only need addr and nonce.
  746. */
  747. rpmb_frame->request = cpu_to_be16p(&rpmb_req.type);
  748. rpmb_frame->address = cpu_to_be16p(&blkaddr);
  749. memcpy(rpmb_frame->nonce, nonce, RPMB_SZ_NONCE);
  750. ret = emmc_rpmb_req_handle(card, &rpmb_req);
  751. if (ret) {
  752. MSG(ERR, "%s, emmc_rpmb_req_handle IO error!!!(%x)\n", __func__, ret);
  753. break;
  754. }
  755. /*
  756. * Authenticate response read data frame.
  757. */
  758. hmac_sha256(param->key, 32, rpmb_frame->data, 284, hmac);
  759. if (memcmp(hmac, rpmb_frame->mac, RPMB_SZ_MAC) != 0) {
  760. MSG(ERR, "%s, hmac compare error!!!\n", __func__);
  761. ret = RPMB_HMAC_ERROR;
  762. break;
  763. }
  764. if (memcmp(nonce, rpmb_frame->nonce, RPMB_SZ_NONCE) != 0) {
  765. MSG(ERR, "%s, nonce compare error!!!\n", __func__);
  766. ret = RPMB_NONCE_ERROR;
  767. break;
  768. }
  769. if (rpmb_frame->result) {
  770. MSG(ERR, "%s, result error!!! (%x)\n", __func__, cpu_to_be16p(&rpmb_frame->result));
  771. ret = RPMB_RESULT_ERROR;
  772. break;
  773. }
  774. if (left_size >= RPMB_SZ_DATA)
  775. tran_size = RPMB_SZ_DATA;
  776. else
  777. tran_size = left_size;
  778. memcpy(param->data + RPMB_SZ_DATA * iCnt, rpmb_frame->data, tran_size);
  779. left_size -= tran_size;
  780. blkaddr++;
  781. }
  782. kfree(rpmb_frame);
  783. #endif
  784. MSG(INFO, "%s end!!!\n", __func__);
  785. return ret;
  786. }
  787. #if (defined(CONFIG_MICROTRUST_TZ_DRIVER))
  788. int neu_rpmb_req_get_wc(struct mmc_card *card, unsigned int *wc)
  789. {
  790. struct emmc_rpmb_req rpmb_req;
  791. struct s_rpmb rpmb_frame;
  792. u8 nonce[RPMB_SZ_NONCE] = {0};
  793. int ret;
  794. memset(&rpmb_frame, 0, sizeof(rpmb_frame));
  795. get_random_bytes(nonce, RPMB_SZ_NONCE);
  796. /*
  797. * Prepare request. Get write counter.
  798. */
  799. rpmb_req.type = RPMB_GET_WRITE_COUNTER;
  800. rpmb_req.blk_cnt = 1;
  801. rpmb_req.data_frame = (u8 *)&rpmb_frame;
  802. /*
  803. * Prepare get write counter frame. only need nonce.
  804. */
  805. rpmb_frame.request = cpu_to_be16p(&rpmb_req.type);
  806. memcpy(rpmb_frame.nonce, nonce, RPMB_SZ_NONCE);
  807. ret = emmc_rpmb_req_handle(card, &rpmb_req);
  808. if (ret) {
  809. MSG(ERR, "%s, emmc_rpmb_req_handle IO error!!!(%x)\n", __func__, ret);
  810. return ret;
  811. }
  812. if (memcmp(nonce, rpmb_frame.nonce, RPMB_SZ_NONCE) != 0) {
  813. MSG(ERR, "%s, nonce compare error!!!\n", __func__);
  814. ret = RPMB_NONCE_ERROR;
  815. return ret;
  816. }
  817. if (rpmb_frame.result) {
  818. MSG(ERR, "%s, result error!!! (%x)\n", __func__, cpu_to_be16p(&rpmb_frame.result));
  819. ret = RPMB_RESULT_ERROR;
  820. return cpu_to_be16p(&rpmb_frame.result);
  821. }
  822. *wc = cpu_to_be32p(&rpmb_frame.write_counter);
  823. return ret;
  824. }
  825. EXPORT_SYMBOL(neu_rpmb_req_get_wc);
  826. int neu_rpmb_req_read_data(struct mmc_card *card, struct s_rpmb *param, u32 blk_cnt)/*struct mmc_card *card, */
  827. {
  828. struct emmc_rpmb_req rpmb_req;
  829. int ret;
  830. rpmb_req.type = RPMB_READ_DATA;
  831. rpmb_req.blk_cnt = blk_cnt;
  832. rpmb_req.data_frame = (u8 *)param;
  833. ret = emmc_rpmb_req_handle(card, &rpmb_req);
  834. if (ret)
  835. MSG(ERR, "%s, emmc_rpmb_req_handle IO error!!!(%x)\n", __func__, ret);
  836. return ret;
  837. }
  838. EXPORT_SYMBOL(neu_rpmb_req_read_data);
  839. int neu_rpmb_req_write_data(struct mmc_card *card, struct s_rpmb *param, u32 blk_cnt)/*struct mmc_card *card, */
  840. {
  841. struct emmc_rpmb_req rpmb_req;
  842. int ret;
  843. rpmb_req.type = RPMB_WRITE_DATA;
  844. rpmb_req.blk_cnt = blk_cnt;
  845. rpmb_req.data_frame = (u8 *)param;
  846. ret = emmc_rpmb_req_handle(card, &rpmb_req);
  847. if (ret)
  848. MSG(ERR, "%s, emmc_rpmb_req_handle IO error!!!(%x)\n", __func__, ret);
  849. return ret;
  850. }
  851. EXPORT_SYMBOL(neu_rpmb_req_write_data);
  852. #endif
  853. /*
  854. * End of above.
  855. *
  856. **********************************************************************************/
  857. #ifdef CONFIG_TRUSTONIC_TEE_SUPPORT
  858. static int emmc_rpmb_execute(u32 cmdId)
  859. {
  860. int ret;
  861. struct mmc_card *card = mtk_msdc_host[0]->mmc->card;
  862. struct emmc_rpmb_req rpmb_req;
  863. switch (cmdId) {
  864. case DCI_RPMB_CMD_READ_DATA:
  865. MSG(INFO, "%s: DCI_RPMB_CMD_READ_DATA.\n", __func__);
  866. rpmb_req.type = RPMB_READ_DATA;
  867. rpmb_req.blk_cnt = rpmb_dci->request.blks;
  868. rpmb_req.addr = rpmb_dci->request.addr;
  869. rpmb_req.data_frame = rpmb_dci->request.frame;
  870. ret = emmc_rpmb_req_handle(card, &rpmb_req);
  871. if (ret)
  872. MSG(ERR, "%s, emmc_rpmb_req_read_data failed!!(%x)\n", __func__, ret);
  873. break;
  874. case DCI_RPMB_CMD_GET_WCNT:
  875. MSG(INFO, "%s: DCI_RPMB_CMD_GET_WCNT.\n", __func__);
  876. rpmb_req.type = RPMB_GET_WRITE_COUNTER;
  877. rpmb_req.blk_cnt = rpmb_dci->request.blks;
  878. rpmb_req.addr = rpmb_dci->request.addr;
  879. rpmb_req.data_frame = rpmb_dci->request.frame;
  880. ret = emmc_rpmb_req_handle(card, &rpmb_req);
  881. if (ret)
  882. MSG(ERR, "%s, emmc_rpmb_req_handle failed!!(%x)\n", __func__, ret);
  883. break;
  884. case DCI_RPMB_CMD_WRITE_DATA:
  885. MSG(INFO, "%s: DCI_RPMB_CMD_WRITE_DATA.\n", __func__);
  886. rpmb_req.type = RPMB_WRITE_DATA;
  887. rpmb_req.blk_cnt = rpmb_dci->request.blks;
  888. rpmb_req.addr = rpmb_dci->request.addr;
  889. rpmb_req.data_frame = rpmb_dci->request.frame;
  890. ret = emmc_rpmb_req_handle(card, &rpmb_req);
  891. if (ret)
  892. MSG(ERR, "%s, emmc_rpmb_req_handle failed!!(%x)\n", __func__, ret);
  893. break;
  894. default:
  895. MSG(ERR, "%s: receive an unknown command id(%d).\n", __func__, cmdId);
  896. break;
  897. }
  898. return 0;
  899. }
  900. int emmc_rpmb_listenDci(void *data)
  901. {
  902. enum mc_result mc_ret;
  903. u32 cmdId;
  904. MSG(INFO, "%s: DCI listener.\n", __func__);
  905. for (;;) {
  906. MSG(INFO, "%s: Waiting for notification\n", __func__);
  907. /* Wait for notification from SWd */
  908. mc_ret = mc_wait_notification(&rpmb_session, MC_INFINITE_TIMEOUT);
  909. if (mc_ret != MC_DRV_OK) {
  910. MSG(ERR, "%s: mcWaitNotification failed, mc_ret=%d\n", __func__, mc_ret);
  911. break;
  912. }
  913. cmdId = rpmb_dci->command.header.commandId;
  914. MSG(INFO, "%s: wait notification done!! cmdId = %x\n", __func__, cmdId);
  915. /* Received exception. */
  916. mc_ret = emmc_rpmb_execute(cmdId);
  917. /* Notify the STH*/
  918. mc_ret = mc_notify(&rpmb_session);
  919. if (mc_ret != MC_DRV_OK) {
  920. MSG(ERR, "%s: mcNotify returned: %d\n", __func__, mc_ret);
  921. break;
  922. }
  923. }
  924. return 0;
  925. }
  926. static int emmc_rpmb_open_session(void)
  927. {
  928. int cnt = 0;
  929. enum mc_result mc_ret = MC_DRV_ERR_UNKNOWN;
  930. MSG(INFO, "%s start\n", __func__);
  931. do {
  932. msleep(2000);
  933. /* open device */
  934. mc_ret = mc_open_device(rpmb_devid);
  935. if (mc_ret != MC_DRV_OK) {
  936. MSG(ERR, "%s, mc_open_device failed: %d\n", __func__, mc_ret);
  937. cnt++;
  938. continue;
  939. }
  940. MSG(INFO, "%s, mc_open_device success.\n", __func__);
  941. /* allocating WSM for DCI */
  942. mc_ret = mc_malloc_wsm(rpmb_devid, 0, sizeof(dciMessage_t), (uint8_t **)&rpmb_dci, 0);
  943. if (mc_ret != MC_DRV_OK) {
  944. mc_close_device(rpmb_devid);
  945. MSG(ERR, "%s, mc_malloc_wsm failed: %d\n", __func__, mc_ret);
  946. cnt++;
  947. continue;
  948. }
  949. MSG(INFO, "%s, mc_malloc_wsm success.\n", __func__);
  950. MSG(INFO, "uuid[0]=%d, uuid[1]=%d, uuid[2]=%d, uuid[3]=%d\n",
  951. rpmb_uuid.value[0], rpmb_uuid.value[1], rpmb_uuid.value[2], rpmb_uuid.value[3]);
  952. rpmb_session.device_id = rpmb_devid;
  953. /* open session */
  954. mc_ret = mc_open_session(&rpmb_session,
  955. &rpmb_uuid,
  956. (uint8_t *) rpmb_dci,
  957. sizeof(dciMessage_t));
  958. if (mc_ret != MC_DRV_OK) {
  959. MSG(ERR, "%s, mc_open_session failed.(%d)\n", __func__, cnt);
  960. mc_ret = mc_free_wsm(rpmb_devid, (uint8_t *)rpmb_dci);
  961. MSG(ERR, "%s, free wsm result (%d)\n", __func__, mc_ret);
  962. mc_ret = mc_close_device(rpmb_devid);
  963. MSG(ERR, "%s, try free wsm and close device\n", __func__);
  964. cnt++;
  965. continue;
  966. }
  967. /* create a thread for listening DCI signals */
  968. rpmbDci_th = kthread_run(emmc_rpmb_listenDci, NULL, "rpmb_Dci");
  969. if (IS_ERR(rpmbDci_th))
  970. MSG(ERR, "%s, init kthread_run failed!\n", __func__);
  971. else
  972. break;
  973. } while (cnt < 30);
  974. if (cnt >= 30)
  975. MSG(ERR, "%s, open session failed!!!\n", __func__);
  976. MSG(INFO, "%s end, mc_ret = %x\n", __func__, mc_ret);
  977. return mc_ret;
  978. }
  979. static int emmc_rpmb_gp_execute(u32 cmdId)
  980. {
  981. int ret;
  982. struct mmc_card *card = mtk_msdc_host[0]->mmc->card;
  983. struct emmc_rpmb_req rpmb_req;
  984. switch (cmdId) {
  985. case DCI_RPMB_CMD_READ_DATA:
  986. MSG(INFO, "%s: DCI_RPMB_CMD_READ_DATA.\n", __func__);
  987. rpmb_req.type = RPMB_READ_DATA;
  988. rpmb_req.blk_cnt = rpmb_gp_dci->request.blks;
  989. rpmb_req.addr = rpmb_gp_dci->request.addr;
  990. rpmb_req.data_frame = rpmb_gp_dci->request.frame;
  991. ret = emmc_rpmb_req_handle(card, &rpmb_req);
  992. if (ret)
  993. MSG(ERR, "%s, emmc_rpmb_req_read_data failed!!(%x)\n", __func__, ret);
  994. break;
  995. case DCI_RPMB_CMD_GET_WCNT:
  996. MSG(INFO, "%s: DCI_RPMB_CMD_GET_WCNT.\n", __func__);
  997. rpmb_req.type = RPMB_GET_WRITE_COUNTER;
  998. rpmb_req.blk_cnt = rpmb_gp_dci->request.blks;
  999. rpmb_req.addr = rpmb_gp_dci->request.addr;
  1000. rpmb_req.data_frame = rpmb_gp_dci->request.frame;
  1001. ret = emmc_rpmb_req_handle(card, &rpmb_req);
  1002. if (ret)
  1003. MSG(ERR, "%s, emmc_rpmb_req_handle failed!!(%x)\n", __func__, ret);
  1004. break;
  1005. case DCI_RPMB_CMD_WRITE_DATA:
  1006. MSG(INFO, "%s: DCI_RPMB_CMD_WRITE_DATA.\n", __func__);
  1007. rpmb_req.type = RPMB_WRITE_DATA;
  1008. rpmb_req.blk_cnt = rpmb_gp_dci->request.blks;
  1009. rpmb_req.addr = rpmb_gp_dci->request.addr;
  1010. rpmb_req.data_frame = rpmb_gp_dci->request.frame;
  1011. ret = emmc_rpmb_req_handle(card, &rpmb_req);
  1012. if (ret)
  1013. MSG(ERR, "%s, emmc_rpmb_req_handle failed!!(%x)\n", __func__, ret);
  1014. break;
  1015. default:
  1016. MSG(ERR, "%s: receive an unknown command id(%d).\n", __func__, cmdId);
  1017. break;
  1018. }
  1019. return 0;
  1020. }
  1021. int emmc_rpmb_gp_listenDci(void *data)
  1022. {
  1023. enum mc_result mc_ret;
  1024. u32 cmdId;
  1025. MSG(INFO, "%s: DCI listener.\n", __func__);
  1026. for (;;) {
  1027. MSG(INFO, "%s: Waiting for notification\n", __func__);
  1028. /* Wait for notification from SWd */
  1029. mc_ret = mc_wait_notification(&rpmb_gp_session, MC_INFINITE_TIMEOUT);
  1030. if (mc_ret != MC_DRV_OK) {
  1031. MSG(ERR, "%s: mcWaitNotification failed, mc_ret=%d\n", __func__, mc_ret);
  1032. break;
  1033. }
  1034. cmdId = rpmb_gp_dci->command.header.commandId;
  1035. MSG(INFO, "%s: wait notification done!! cmdId = %x\n", __func__, cmdId);
  1036. /* Received exception. */
  1037. mc_ret = emmc_rpmb_gp_execute(cmdId);
  1038. /* Notify the STH*/
  1039. mc_ret = mc_notify(&rpmb_gp_session);
  1040. if (mc_ret != MC_DRV_OK) {
  1041. MSG(ERR, "%s: mcNotify returned: %d\n", __func__, mc_ret);
  1042. break;
  1043. }
  1044. }
  1045. return 0;
  1046. }
  1047. static int emmc_rpmb_gp_open_session(void)
  1048. {
  1049. int cnt = 0;
  1050. enum mc_result mc_ret = MC_DRV_ERR_UNKNOWN;
  1051. MSG(INFO, "%s start\n", __func__);
  1052. do {
  1053. msleep(2000);
  1054. /* open device */
  1055. mc_ret = mc_open_device(rpmb_gp_devid);
  1056. if (mc_ret != MC_DRV_OK) {
  1057. MSG(ERR, "%s, mc_open_device failed: %d\n", __func__, mc_ret);
  1058. cnt++;
  1059. continue;
  1060. }
  1061. MSG(INFO, "%s, mc_open_device success.\n", __func__);
  1062. /* allocating WSM for DCI */
  1063. mc_ret = mc_malloc_wsm(rpmb_gp_devid, 0, sizeof(dciMessage_t), (uint8_t **)&rpmb_gp_dci, 0);
  1064. if (mc_ret != MC_DRV_OK) {
  1065. mc_close_device(rpmb_gp_devid);
  1066. MSG(ERR, "%s, mc_malloc_wsm failed: %d\n", __func__, mc_ret);
  1067. cnt++;
  1068. continue;
  1069. }
  1070. MSG(INFO, "%s, mc_malloc_wsm success.\n", __func__);
  1071. MSG(INFO, "uuid[0]=%d, uuid[1]=%d, uuid[2]=%d, uuid[3]=%d\n",
  1072. rpmb_gp_uuid.value[0],
  1073. rpmb_gp_uuid.value[1],
  1074. rpmb_gp_uuid.value[2],
  1075. rpmb_gp_uuid.value[3]
  1076. );
  1077. rpmb_gp_session.device_id = rpmb_gp_devid;
  1078. /* open session */
  1079. mc_ret = mc_open_session(&rpmb_gp_session,
  1080. &rpmb_gp_uuid,
  1081. (uint8_t *) rpmb_gp_dci,
  1082. sizeof(dciMessage_t));
  1083. if (mc_ret != MC_DRV_OK) {
  1084. MSG(ERR, "%s, mc_open_session failed.(%d)\n", __func__, cnt);
  1085. mc_ret = mc_free_wsm(rpmb_gp_devid, (uint8_t *)rpmb_gp_dci);
  1086. MSG(ERR, "%s, free wsm result (%d)\n", __func__, mc_ret);
  1087. mc_ret = mc_close_device(rpmb_gp_devid);
  1088. MSG(ERR, "%s, try free wsm and close device\n", __func__);
  1089. cnt++;
  1090. continue;
  1091. }
  1092. /* create a thread for listening DCI signals */
  1093. rpmb_gp_Dci_th = kthread_run(emmc_rpmb_gp_listenDci, NULL, "rpmb_gp_Dci");
  1094. if (IS_ERR(rpmb_gp_Dci_th))
  1095. MSG(ERR, "%s, init kthread_run failed!\n", __func__);
  1096. else
  1097. break;
  1098. } while (cnt < 30);
  1099. if (cnt >= 30)
  1100. MSG(ERR, "%s, open session failed!!!\n", __func__);
  1101. MSG(ERR, "%s end, mc_ret = %x\n", __func__, mc_ret);
  1102. return mc_ret;
  1103. }
  1104. static int emmc_rpmb_thread(void *context)
  1105. {
  1106. int ret;
  1107. MSG(INFO, "%s start\n", __func__);
  1108. ret = emmc_rpmb_open_session();
  1109. MSG(INFO, "%s emmc_rpmb_open_session, ret = %x\n", __func__, ret);
  1110. ret = emmc_rpmb_gp_open_session();
  1111. MSG(INFO, "%s emmc_rpmb_gp_open_session, ret = %x\n", __func__, ret);
  1112. return 0;
  1113. }
  1114. #endif
  1115. static int emmc_rpmb_open(struct inode *inode, struct file *file)
  1116. {
  1117. MSG(INFO, "%s, !!!!!!!!!!!!\n", __func__);
  1118. #if (defined(CONFIG_MICROTRUST_TZ_DRIVER))
  1119. rpmb_buffer = kzalloc(RPMB_DATA_BUFF_SIZE, 0);
  1120. if (rpmb_buffer == NULL) {
  1121. MSG(ERR, "%s, rpmb kzalloc memory fail!!!\n", __func__);
  1122. return -1;
  1123. }
  1124. MSG(INFO, "%s, rpmb kzalloc memory done!!!\n", __func__);
  1125. #endif
  1126. return 0;
  1127. }
  1128. static long emmc_rpmb_ioctl(struct file *file, unsigned int cmd, unsigned long arg)
  1129. {
  1130. int err = 0;
  1131. struct mmc_card *card = mtk_msdc_host[0]->mmc->card;
  1132. struct rpmb_ioc_param param;
  1133. int ret;
  1134. #if (defined(CONFIG_MICROTRUST_TZ_DRIVER))
  1135. u32 rpmb_size = 0;
  1136. struct rpmb_infor rpmbinfor;
  1137. memset(&rpmbinfor, 0, sizeof(struct rpmb_infor));
  1138. #endif
  1139. MSG(INFO, "%s, !!!!!!!!!!!!\n", __func__);
  1140. err = copy_from_user(&param, (void *)arg, sizeof(param));
  1141. if (err < 0) {
  1142. MSG(ERR, "%s, err=%x\n", __func__, err);
  1143. return -1;
  1144. }
  1145. #if (defined(CONFIG_MICROTRUST_TZ_DRIVER))
  1146. if ((cmd == RPMB_IOCTL_SOTER_WRITE_DATA) || (cmd == RPMB_IOCTL_SOTER_READ_DATA)) {
  1147. if (rpmb_buffer == NULL) {
  1148. MSG(ERR, "%s, rpmb_buffer is NULL!\n", __func__);
  1149. return -1;
  1150. }
  1151. err = copy_from_user(&rpmb_size, (void *)arg, 4);
  1152. if (err < 0) {
  1153. MSG(ERR, "%s, err=%x\n", __func__, err);
  1154. return -1;
  1155. }
  1156. rpmbinfor.size = *(unsigned char *)&rpmb_size | (*((unsigned char *)&rpmb_size + 1) << 8);
  1157. rpmbinfor.size |= (*((unsigned char *)&rpmb_size+2) << 16) | (*((unsigned char *)&rpmb_size+3) << 24);
  1158. if (rpmbinfor.size <= (RPMB_DATA_BUFF_SIZE-4)) {
  1159. MSG(INFO, "%s, rpmbinfor.size is %d!\n", __func__, rpmbinfor.size);
  1160. err = copy_from_user(rpmb_buffer, (void *)arg, 4 + rpmbinfor.size);
  1161. if (err < 0) {
  1162. MSG(ERR, "%s, err=%x\n", __func__, err);
  1163. return -1;
  1164. }
  1165. rpmbinfor.data_frame = (rpmb_buffer + 4);
  1166. } else {
  1167. MSG(ERR, "%s, rpmbinfor.size(%d+4) is overflow (%d)!\n",
  1168. __func__, rpmbinfor.size, RPMB_DATA_BUFF_SIZE);
  1169. return -1;
  1170. }
  1171. if (cmd == RPMB_IOCTL_SOTER_WRITE_DATA) {
  1172. ret = neu_rpmb_req_write_data(card,
  1173. (struct s_rpmb *)(rpmbinfor.data_frame), rpmbinfor.size/RPMB_ONE_FRAME_SIZE);
  1174. if (ret)
  1175. MSG(ERR, "%s, emmc_rpmb_req_handle IO error!!!(%x)\n", __func__, ret);
  1176. err = copy_to_user((void *)arg, rpmb_buffer, 4 + rpmbinfor.size);
  1177. } else if (cmd == RPMB_IOCTL_SOTER_READ_DATA) {
  1178. ret = neu_rpmb_req_read_data(card,
  1179. (struct s_rpmb *)(rpmbinfor.data_frame), rpmbinfor.size/RPMB_ONE_FRAME_SIZE);
  1180. if (ret)
  1181. MSG(ERR, "%s, emmc_rpmb_req_handle IO error!!!(%x)\n", __func__, ret);
  1182. err = copy_to_user((void *)arg, rpmb_buffer, 4 + rpmbinfor.size);
  1183. }
  1184. }
  1185. #endif
  1186. switch (cmd) {
  1187. case RPMB_IOCTL_PROGRAM_KEY:
  1188. MSG(INFO, "%s, cmd = RPMB_IOCTL_PROGRAM_KEY!!!!!!!!!!!!!!\n", __func__);
  1189. ret = emmc_rpmb_req_set_key(card, param.key);
  1190. break;
  1191. case RPMB_IOCTL_READ_DATA:
  1192. MSG(INFO, "%s, cmd = RPMB_IOCTL_READ_DATA!!!!!!!!!!!!!!\n", __func__);
  1193. ret = emmc_rpmb_req_read_data(card, &param);
  1194. err = copy_to_user((void *)arg, &param, sizeof(param));
  1195. if (err < 0) {
  1196. MSG(ERR, "%s, err=%x\n", __func__, err);
  1197. return -1;
  1198. }
  1199. break;
  1200. case RPMB_IOCTL_WRITE_DATA:
  1201. MSG(INFO, "%s, cmd = RPMB_IOCTL_WRITE_DATA!!!!!!!!!!!!!!\n", __func__);
  1202. ret = emmc_rpmb_req_write_data(card, &param);
  1203. break;
  1204. #if (defined(CONFIG_MICROTRUST_TZ_DRIVER))
  1205. case RPMB_IOCTL_SOTER_GET_CNT:
  1206. ret = neu_rpmb_req_get_wc(card, (unsigned int *)arg);
  1207. break;
  1208. #endif
  1209. default:
  1210. MSG(ERR, "%s, wrong ioctl code (%d)!!!\n", __func__, cmd);
  1211. return -ENOTTY;
  1212. }
  1213. return ret;
  1214. }
  1215. static int emmc_rpmb_close(struct inode *inode, struct file *file)
  1216. {
  1217. int ret = 0;
  1218. MSG(INFO, "%s, !!!!!!!!!!!!\n", __func__);
  1219. #if (defined(CONFIG_MICROTRUST_TZ_DRIVER))
  1220. kfree(rpmb_buffer);
  1221. MSG(INFO, "%s, rpmb free memory done!!!\n", __func__);
  1222. #endif
  1223. return ret;
  1224. }
  1225. static const struct file_operations emmc_rpmb_fops = {
  1226. .owner = THIS_MODULE,
  1227. .open = emmc_rpmb_open,
  1228. .release = emmc_rpmb_close,
  1229. .unlocked_ioctl = emmc_rpmb_ioctl,
  1230. .write = NULL,
  1231. .read = NULL,
  1232. };
  1233. static int __init emmc_rpmb_init(void)
  1234. {
  1235. int alloc_ret = -1;
  1236. int cdev_ret = -1;
  1237. int major;
  1238. dev_t dev;
  1239. struct device *device = NULL;
  1240. MSG(INFO, "%s start\n", __func__);
  1241. alloc_ret = alloc_chrdev_region(&dev, 0, 1, RPMB_NAME);
  1242. if (alloc_ret)
  1243. goto error;
  1244. major = MAJOR(dev);
  1245. cdev_init(&rpmb_dev, &emmc_rpmb_fops);
  1246. rpmb_dev.owner = THIS_MODULE;
  1247. cdev_ret = cdev_add(&rpmb_dev, MKDEV(major, 0), 1);
  1248. if (cdev_ret)
  1249. goto error;
  1250. rpmb_class = class_create(THIS_MODULE, RPMB_NAME);
  1251. if (IS_ERR(rpmb_class))
  1252. goto error;
  1253. device = device_create(rpmb_class, NULL, MKDEV(major, 0), NULL,
  1254. RPMB_NAME "%d", 0);
  1255. if (IS_ERR(device))
  1256. goto error;
  1257. #ifdef CONFIG_TRUSTONIC_TEE_SUPPORT
  1258. open_th = kthread_run(emmc_rpmb_thread, NULL, "rpmb_open");
  1259. if (IS_ERR(open_th))
  1260. MSG(ERR, "%s, init kthread_run failed!\n", __func__);
  1261. #endif
  1262. MSG(INFO, "emmc_rpmb_init end!!!!\n");
  1263. return 0;
  1264. error:
  1265. if (rpmb_class)
  1266. class_destroy(rpmb_class);
  1267. if (cdev_ret == 0)
  1268. cdev_del(&rpmb_dev);
  1269. if (alloc_ret == 0)
  1270. unregister_chrdev_region(dev, 1);
  1271. return -1;
  1272. }
  1273. late_initcall(emmc_rpmb_init);