/* SPDX-License-Identifier: BSD-2-Clause */ /* * Copyright (c) 2018-2020, Linaro Limited */ #ifndef PKCS11_TA_H #define PKCS11_TA_H #include #include #define PKCS11_TA_UUID { 0xfd02c9da, 0x306c, 0x48c7, \ { 0xa4, 0x9c, 0xbb, 0xd8, 0x27, 0xae, 0x86, 0xee } } /* PKCS11 trusted application version information */ #define PKCS11_TA_VERSION_MAJOR 0 #define PKCS11_TA_VERSION_MINOR 1 #define PKCS11_TA_VERSION_PATCH 0 /* Attribute specific values */ #define PKCS11_UNAVAILABLE_INFORMATION UINT32_C(0xFFFFFFFF) #define PKCS11_UNDEFINED_ID PKCS11_UNAVAILABLE_INFORMATION #define PKCS11_FALSE false #define PKCS11_TRUE true /* * Note on PKCS#11 TA commands ABI * * For evolution of the TA API and to not mess with the GPD TEE 4 parameters * constraint, all the PKCS11 TA invocation commands use a subset of available * the GPD TEE invocation parameter types. * * Param#0 is used for the so-called control arguments of the invoked command * and for providing a PKCS#11 compliant status code for the request command. * Param#0 is an in/out memory reference (aka memref[0]). The input buffer * stores serialized arguments for the command. The output buffer store the * 32bit TA return code for the command. As a consequence, param#0 shall * always be an input/output memory reference of at least 32bit, more if * the command expects more input arguments. * * When the TA returns with TEE_SUCCESS result, client shall always get the * 32bit value stored in param#0 output buffer and use the value as TA * return code for the invoked command. * * Param#1 can be used for input data arguments of the invoked command. * It is unused or is a input memory reference, aka memref[1]. * Evolution of the API may use memref[1] for output data as well. * * Param#2 is mostly used for output data arguments of the invoked command * and for output handles generated from invoked commands. * Few commands uses it for a secondary input data buffer argument. * It is unused or is a input/output/in-out memory reference, aka memref[2]. * * Param#3 is currently unused and reserved for evolution of the API. */ /* * PKCS11_CMD_PING Acknowledge TA presence and return version info * * [in] memref[0] = 32bit, unused, must be 0 * [out] memref[0] = 32bit return code, enum pkcs11_rc * [out] memref[2] = [ * 32bit version major value, * 32bit version minor value * 32bit version patch value * ] */ #define PKCS11_CMD_PING 0 /* * Command return codes * PKCS11_ relates CryptoKi client API CKR_ */ enum pkcs11_rc { PKCS11_CKR_OK = 0, PKCS11_CKR_CANCEL = 0x0001, PKCS11_CKR_SLOT_ID_INVALID = 0x0003, PKCS11_CKR_GENERAL_ERROR = 0x0005, PKCS11_CKR_FUNCTION_FAILED = 0x0006, PKCS11_CKR_ARGUMENTS_BAD = 0x0007, PKCS11_CKR_ATTRIBUTE_READ_ONLY = 0x0010, PKCS11_CKR_ATTRIBUTE_SENSITIVE = 0x0011, PKCS11_CKR_ATTRIBUTE_TYPE_INVALID = 0x0012, PKCS11_CKR_ATTRIBUTE_VALUE_INVALID = 0x0013, PKCS11_CKR_ACTION_PROHIBITED = 0x001b, PKCS11_CKR_DATA_INVALID = 0x0020, PKCS11_CKR_DATA_LEN_RANGE = 0x0021, PKCS11_CKR_DEVICE_ERROR = 0x0030, PKCS11_CKR_DEVICE_MEMORY = 0x0031, PKCS11_CKR_DEVICE_REMOVED = 0x0032, PKCS11_CKR_ENCRYPTED_DATA_INVALID = 0x0040, PKCS11_CKR_ENCRYPTED_DATA_LEN_RANGE = 0x0041, PKCS11_CKR_KEY_HANDLE_INVALID = 0x0060, PKCS11_CKR_KEY_SIZE_RANGE = 0x0062, PKCS11_CKR_KEY_TYPE_INCONSISTENT = 0x0063, PKCS11_CKR_KEY_FUNCTION_NOT_PERMITTED = 0x0068, PKCS11_CKR_KEY_NOT_WRAPPABLE = 0x0069, PKCS11_CKR_KEY_UNEXTRACTABLE = 0x006a, PKCS11_CKR_MECHANISM_INVALID = 0x0070, PKCS11_CKR_MECHANISM_PARAM_INVALID = 0x0071, PKCS11_CKR_OBJECT_HANDLE_INVALID = 0x0082, PKCS11_CKR_OPERATION_ACTIVE = 0x0090, PKCS11_CKR_OPERATION_NOT_INITIALIZED = 0x0091, PKCS11_CKR_PIN_INCORRECT = 0x00a0, PKCS11_CKR_PIN_INVALID = 0x00a1, PKCS11_CKR_PIN_LEN_RANGE = 0x00a2, PKCS11_CKR_PIN_EXPIRED = 0x00a3, PKCS11_CKR_PIN_LOCKED = 0x00a4, PKCS11_CKR_SESSION_CLOSED = 0x00b0, PKCS11_CKR_SESSION_COUNT = 0x00b1, PKCS11_CKR_SESSION_HANDLE_INVALID = 0x00b3, PKCS11_CKR_SESSION_READ_ONLY = 0x00b5, PKCS11_CKR_SESSION_EXISTS = 0x00b6, PKCS11_CKR_SESSION_READ_ONLY_EXISTS = 0x00b7, PKCS11_CKR_SESSION_READ_WRITE_SO_EXISTS = 0x00b8, PKCS11_CKR_SIGNATURE_INVALID = 0x00c0, PKCS11_CKR_SIGNATURE_LEN_RANGE = 0x00c1, PKCS11_CKR_TEMPLATE_INCOMPLETE = 0x00d0, PKCS11_CKR_TEMPLATE_INCONSISTENT = 0x00d1, PKCS11_CKR_TOKEN_NOT_PRESENT = 0x00e0, PKCS11_CKR_TOKEN_NOT_RECOGNIZED = 0x00e1, PKCS11_CKR_TOKEN_WRITE_PROTECTED = 0x00e2, PKCS11_CKR_USER_ALREADY_LOGGED_IN = 0x0100, PKCS11_CKR_USER_NOT_LOGGED_IN = 0x0101, PKCS11_CKR_USER_PIN_NOT_INITIALIZED = 0x0102, PKCS11_CKR_USER_TYPE_INVALID = 0x0103, PKCS11_CKR_USER_ANOTHER_ALREADY_LOGGED_IN = 0x0104, PKCS11_CKR_USER_TOO_MANY_TYPES = 0x0105, PKCS11_CKR_DOMAIN_PARAMS_INVALID = 0x0130, PKCS11_CKR_CURVE_NOT_SUPPORTED = 0x0140, PKCS11_CKR_BUFFER_TOO_SMALL = 0x0150, PKCS11_CKR_SAVED_STATE_INVALID = 0x0160, PKCS11_CKR_INFORMATION_SENSITIVE = 0x0170, PKCS11_CKR_STATE_UNSAVEABLE = 0x0180, PKCS11_CKR_PIN_TOO_WEAK = 0x01b8, PKCS11_CKR_PUBLIC_KEY_INVALID = 0x01b9, PKCS11_CKR_FUNCTION_REJECTED = 0x0200, /* Vendor specific IDs not returned to client */ PKCS11_RV_NOT_FOUND = 0x80000000, PKCS11_RV_NOT_IMPLEMENTED = 0x80000001, }; #endif /*PKCS11_TA_H*/