1 /*
2 * Copyright (c) 2024, The ChromiumOS Authors. All rights reserved.
3 *
4 * SPDX-License-Identifier: BSD-3-Clause
5 */
6
7 #include <assert.h>
8 #include <stdint.h>
9 #include <string.h>
10
11 #include <common/debug.h>
12 #include <common/runtime_svc.h>
13 #include <lib/psci/psci.h>
14 #include <lib/xlat_tables/xlat_tables_v2.h>
15 #include <services/oem/chromeos/widevine_smc_handlers.h>
16 #include <tools_share/uuid.h>
17
18 #define CROS_OEM_TPM_AUTH_PK_MAX_LEN 128
19 #define CROS_OEM_HUK_LEN 32
20 #define CROS_OEM_ROT_LEN 32
21 #define CROS_OEM_GCK_LEN 32
22 #define CROS_OEM_DDK_LEN 32
23 #define CROS_OEM_STABLE_HUK_LEN 32
24
25 static uint8_t cros_oem_tpm_auth_pk_buffer[CROS_OEM_TPM_AUTH_PK_MAX_LEN];
26 static uint8_t cros_oem_huk_buffer[CROS_OEM_HUK_LEN];
27 static uint8_t cros_oem_rot_len_buffer[CROS_OEM_ROT_LEN];
28 static uint8_t cros_oem_gck_buffer[CROS_OEM_GCK_LEN];
29 static uint8_t cros_oem_ddk_buffer[CROS_OEM_DDK_LEN];
30 static uint8_t cros_oem_stable_huk_buffer[CROS_OEM_STABLE_HUK_LEN];
31
32 struct cros_oem_data cros_oem_tpm_auth_pk = {
33 .buffer = cros_oem_tpm_auth_pk_buffer,
34 .max_length = sizeof(cros_oem_tpm_auth_pk_buffer),
35 };
36
37 struct cros_oem_data cros_oem_huk = {
38 .buffer = cros_oem_huk_buffer,
39 .max_length = sizeof(cros_oem_huk_buffer),
40 };
41
42 struct cros_oem_data cros_oem_rot = {
43 .buffer = cros_oem_rot_len_buffer,
44 .max_length = sizeof(cros_oem_rot_len_buffer),
45 };
46
47 struct cros_oem_data cros_oem_gck = {
48 .buffer = cros_oem_gck_buffer,
49 .max_length = sizeof(cros_oem_gck_buffer),
50 };
51
52 struct cros_oem_data cros_oem_ddk = {
53 .buffer = cros_oem_ddk_buffer,
54 .max_length = sizeof(cros_oem_ddk_buffer),
55 };
56
57 struct cros_oem_data cros_oem_stable_huk = {
58 .buffer = cros_oem_stable_huk_buffer,
59 .max_length = sizeof(cros_oem_stable_huk_buffer),
60 };
61
cros_write_data(struct cros_oem_data * data,u_register_t length,u_register_t address,void * handle)62 static uintptr_t cros_write_data(struct cros_oem_data *data,
63 u_register_t length, u_register_t address,
64 void *handle)
65 {
66 uintptr_t aligned_address;
67 uintptr_t aligned_size;
68 int32_t rc;
69
70 if (data->length) {
71 SMC_RET1(handle, PSCI_E_ALREADY_ON);
72 }
73
74 if (length > data->max_length) {
75 SMC_RET1(handle, PSCI_E_INVALID_PARAMS);
76 }
77
78 aligned_address = page_align(address, DOWN);
79 aligned_size = page_align(length + (address - aligned_address), UP);
80
81 /*
82 * We do not validate the passed in address because we are trusting the
83 * non-secure world at this point still.
84 */
85 rc = mmap_add_dynamic_region(aligned_address, aligned_address,
86 aligned_size, MT_MEMORY | MT_RO | MT_NS);
87 if (rc != 0) {
88 SMC_RET1(handle, PSCI_E_INVALID_ADDRESS);
89 }
90
91 memcpy(data->buffer, (void *)address, length);
92 data->length = length;
93
94 mmap_remove_dynamic_region(aligned_address, aligned_size);
95 SMC_RET1(handle, SMC_OK);
96 }
97
98 /* Handler for servicing specific SMC calls. */
cros_oem_svc_smc_handler(uint32_t smc_fid,u_register_t x1,u_register_t x2,u_register_t x3,u_register_t x4,void * cookie,void * handle,u_register_t flags)99 static uintptr_t cros_oem_svc_smc_handler(uint32_t smc_fid, u_register_t x1,
100 u_register_t x2, u_register_t x3,
101 u_register_t x4, void *cookie,
102 void *handle, u_register_t flags)
103 {
104 switch (smc_fid) {
105 case CROS_OEM_SMC_DRM_SET_TPM_AUTH_PUB_FUNC_ID:
106 return cros_write_data(&cros_oem_tpm_auth_pk, x1, x2, handle);
107 case CROS_OEM_SMC_DRM_SET_HARDWARE_UNIQUE_KEY_FUNC_ID:
108 return cros_write_data(&cros_oem_huk, x1, x2, handle);
109 case CROS_OEM_SMC_DRM_SET_ROOT_OF_TRUST_FUNC_ID:
110 return cros_write_data(&cros_oem_rot, x1, x2, handle);
111 case CROS_OEM_SMC_DRM_SET_GSC_COUNTER_KEY_FUNC_ID:
112 return cros_write_data(&cros_oem_gck, x1, x2, handle);
113 case CROS_OEM_SMC_DRM_SET_DRM_DEVICE_KEY_FUNC_ID:
114 return cros_write_data(&cros_oem_ddk, x1, x2, handle);
115 case CROS_OEM_SMC_DRM_SET_STABLE_HARDWARE_UNIQUE_KEY_FUNC_ID:
116 return cros_write_data(&cros_oem_stable_huk, x1, x2, handle);
117 default:
118 WARN("Unimplemented OEM Call: 0x%x\n", smc_fid);
119 SMC_RET1(handle, SMC_UNK);
120 }
121 }
122
123 /* Register OEM Service Calls as runtime service */
124 DECLARE_RT_SVC(cros_oem_svc_smc_handler, OEN_OEM_START, OEN_OEM_END,
125 SMC_TYPE_FAST, NULL, cros_oem_svc_smc_handler);
126