1*4882a593Smuzhiyun // SPDX-License-Identifier: GPL-2.0-or-later
2*4882a593Smuzhiyun /*
3*4882a593Smuzhiyun * Copyright (C) 2016 IBM Corporation
4*4882a593Smuzhiyun *
5*4882a593Smuzhiyun * Authors:
6*4882a593Smuzhiyun * Thiago Jung Bauermann <bauerman@linux.vnet.ibm.com>
7*4882a593Smuzhiyun */
8*4882a593Smuzhiyun
9*4882a593Smuzhiyun #include <linux/slab.h>
10*4882a593Smuzhiyun #include <linux/kexec.h>
11*4882a593Smuzhiyun #include <linux/of.h>
12*4882a593Smuzhiyun #include <linux/memblock.h>
13*4882a593Smuzhiyun #include <linux/libfdt.h>
14*4882a593Smuzhiyun
get_addr_size_cells(int * addr_cells,int * size_cells)15*4882a593Smuzhiyun static int get_addr_size_cells(int *addr_cells, int *size_cells)
16*4882a593Smuzhiyun {
17*4882a593Smuzhiyun struct device_node *root;
18*4882a593Smuzhiyun
19*4882a593Smuzhiyun root = of_find_node_by_path("/");
20*4882a593Smuzhiyun if (!root)
21*4882a593Smuzhiyun return -EINVAL;
22*4882a593Smuzhiyun
23*4882a593Smuzhiyun *addr_cells = of_n_addr_cells(root);
24*4882a593Smuzhiyun *size_cells = of_n_size_cells(root);
25*4882a593Smuzhiyun
26*4882a593Smuzhiyun of_node_put(root);
27*4882a593Smuzhiyun
28*4882a593Smuzhiyun return 0;
29*4882a593Smuzhiyun }
30*4882a593Smuzhiyun
do_get_kexec_buffer(const void * prop,int len,unsigned long * addr,size_t * size)31*4882a593Smuzhiyun static int do_get_kexec_buffer(const void *prop, int len, unsigned long *addr,
32*4882a593Smuzhiyun size_t *size)
33*4882a593Smuzhiyun {
34*4882a593Smuzhiyun int ret, addr_cells, size_cells;
35*4882a593Smuzhiyun
36*4882a593Smuzhiyun ret = get_addr_size_cells(&addr_cells, &size_cells);
37*4882a593Smuzhiyun if (ret)
38*4882a593Smuzhiyun return ret;
39*4882a593Smuzhiyun
40*4882a593Smuzhiyun if (len < 4 * (addr_cells + size_cells))
41*4882a593Smuzhiyun return -ENOENT;
42*4882a593Smuzhiyun
43*4882a593Smuzhiyun *addr = of_read_number(prop, addr_cells);
44*4882a593Smuzhiyun *size = of_read_number(prop + 4 * addr_cells, size_cells);
45*4882a593Smuzhiyun
46*4882a593Smuzhiyun return 0;
47*4882a593Smuzhiyun }
48*4882a593Smuzhiyun
49*4882a593Smuzhiyun /**
50*4882a593Smuzhiyun * ima_get_kexec_buffer - get IMA buffer from the previous kernel
51*4882a593Smuzhiyun * @addr: On successful return, set to point to the buffer contents.
52*4882a593Smuzhiyun * @size: On successful return, set to the buffer size.
53*4882a593Smuzhiyun *
54*4882a593Smuzhiyun * Return: 0 on success, negative errno on error.
55*4882a593Smuzhiyun */
ima_get_kexec_buffer(void ** addr,size_t * size)56*4882a593Smuzhiyun int ima_get_kexec_buffer(void **addr, size_t *size)
57*4882a593Smuzhiyun {
58*4882a593Smuzhiyun int ret, len;
59*4882a593Smuzhiyun unsigned long tmp_addr;
60*4882a593Smuzhiyun size_t tmp_size;
61*4882a593Smuzhiyun const void *prop;
62*4882a593Smuzhiyun
63*4882a593Smuzhiyun prop = of_get_property(of_chosen, "linux,ima-kexec-buffer", &len);
64*4882a593Smuzhiyun if (!prop)
65*4882a593Smuzhiyun return -ENOENT;
66*4882a593Smuzhiyun
67*4882a593Smuzhiyun ret = do_get_kexec_buffer(prop, len, &tmp_addr, &tmp_size);
68*4882a593Smuzhiyun if (ret)
69*4882a593Smuzhiyun return ret;
70*4882a593Smuzhiyun
71*4882a593Smuzhiyun *addr = __va(tmp_addr);
72*4882a593Smuzhiyun *size = tmp_size;
73*4882a593Smuzhiyun
74*4882a593Smuzhiyun return 0;
75*4882a593Smuzhiyun }
76*4882a593Smuzhiyun
77*4882a593Smuzhiyun /**
78*4882a593Smuzhiyun * ima_free_kexec_buffer - free memory used by the IMA buffer
79*4882a593Smuzhiyun */
ima_free_kexec_buffer(void)80*4882a593Smuzhiyun int ima_free_kexec_buffer(void)
81*4882a593Smuzhiyun {
82*4882a593Smuzhiyun int ret;
83*4882a593Smuzhiyun unsigned long addr;
84*4882a593Smuzhiyun size_t size;
85*4882a593Smuzhiyun struct property *prop;
86*4882a593Smuzhiyun
87*4882a593Smuzhiyun prop = of_find_property(of_chosen, "linux,ima-kexec-buffer", NULL);
88*4882a593Smuzhiyun if (!prop)
89*4882a593Smuzhiyun return -ENOENT;
90*4882a593Smuzhiyun
91*4882a593Smuzhiyun ret = do_get_kexec_buffer(prop->value, prop->length, &addr, &size);
92*4882a593Smuzhiyun if (ret)
93*4882a593Smuzhiyun return ret;
94*4882a593Smuzhiyun
95*4882a593Smuzhiyun ret = of_remove_property(of_chosen, prop);
96*4882a593Smuzhiyun if (ret)
97*4882a593Smuzhiyun return ret;
98*4882a593Smuzhiyun
99*4882a593Smuzhiyun return memblock_free(addr, size);
100*4882a593Smuzhiyun
101*4882a593Smuzhiyun }
102*4882a593Smuzhiyun
103*4882a593Smuzhiyun /**
104*4882a593Smuzhiyun * remove_ima_buffer - remove the IMA buffer property and reservation from @fdt
105*4882a593Smuzhiyun *
106*4882a593Smuzhiyun * The IMA measurement buffer is of no use to a subsequent kernel, so we always
107*4882a593Smuzhiyun * remove it from the device tree.
108*4882a593Smuzhiyun */
remove_ima_buffer(void * fdt,int chosen_node)109*4882a593Smuzhiyun void remove_ima_buffer(void *fdt, int chosen_node)
110*4882a593Smuzhiyun {
111*4882a593Smuzhiyun int ret, len;
112*4882a593Smuzhiyun unsigned long addr;
113*4882a593Smuzhiyun size_t size;
114*4882a593Smuzhiyun const void *prop;
115*4882a593Smuzhiyun
116*4882a593Smuzhiyun prop = fdt_getprop(fdt, chosen_node, "linux,ima-kexec-buffer", &len);
117*4882a593Smuzhiyun if (!prop)
118*4882a593Smuzhiyun return;
119*4882a593Smuzhiyun
120*4882a593Smuzhiyun ret = do_get_kexec_buffer(prop, len, &addr, &size);
121*4882a593Smuzhiyun fdt_delprop(fdt, chosen_node, "linux,ima-kexec-buffer");
122*4882a593Smuzhiyun if (ret)
123*4882a593Smuzhiyun return;
124*4882a593Smuzhiyun
125*4882a593Smuzhiyun ret = delete_fdt_mem_rsv(fdt, addr, size);
126*4882a593Smuzhiyun if (!ret)
127*4882a593Smuzhiyun pr_debug("Removed old IMA buffer reservation.\n");
128*4882a593Smuzhiyun }
129*4882a593Smuzhiyun
130*4882a593Smuzhiyun #ifdef CONFIG_IMA_KEXEC
131*4882a593Smuzhiyun /**
132*4882a593Smuzhiyun * arch_ima_add_kexec_buffer - do arch-specific steps to add the IMA buffer
133*4882a593Smuzhiyun *
134*4882a593Smuzhiyun * Architectures should use this function to pass on the IMA buffer
135*4882a593Smuzhiyun * information to the next kernel.
136*4882a593Smuzhiyun *
137*4882a593Smuzhiyun * Return: 0 on success, negative errno on error.
138*4882a593Smuzhiyun */
arch_ima_add_kexec_buffer(struct kimage * image,unsigned long load_addr,size_t size)139*4882a593Smuzhiyun int arch_ima_add_kexec_buffer(struct kimage *image, unsigned long load_addr,
140*4882a593Smuzhiyun size_t size)
141*4882a593Smuzhiyun {
142*4882a593Smuzhiyun image->arch.ima_buffer_addr = load_addr;
143*4882a593Smuzhiyun image->arch.ima_buffer_size = size;
144*4882a593Smuzhiyun
145*4882a593Smuzhiyun return 0;
146*4882a593Smuzhiyun }
147*4882a593Smuzhiyun
write_number(void * p,u64 value,int cells)148*4882a593Smuzhiyun static int write_number(void *p, u64 value, int cells)
149*4882a593Smuzhiyun {
150*4882a593Smuzhiyun if (cells == 1) {
151*4882a593Smuzhiyun u32 tmp;
152*4882a593Smuzhiyun
153*4882a593Smuzhiyun if (value > U32_MAX)
154*4882a593Smuzhiyun return -EINVAL;
155*4882a593Smuzhiyun
156*4882a593Smuzhiyun tmp = cpu_to_be32(value);
157*4882a593Smuzhiyun memcpy(p, &tmp, sizeof(tmp));
158*4882a593Smuzhiyun } else if (cells == 2) {
159*4882a593Smuzhiyun u64 tmp;
160*4882a593Smuzhiyun
161*4882a593Smuzhiyun tmp = cpu_to_be64(value);
162*4882a593Smuzhiyun memcpy(p, &tmp, sizeof(tmp));
163*4882a593Smuzhiyun } else
164*4882a593Smuzhiyun return -EINVAL;
165*4882a593Smuzhiyun
166*4882a593Smuzhiyun return 0;
167*4882a593Smuzhiyun }
168*4882a593Smuzhiyun
169*4882a593Smuzhiyun /**
170*4882a593Smuzhiyun * setup_ima_buffer - add IMA buffer information to the fdt
171*4882a593Smuzhiyun * @image: kexec image being loaded.
172*4882a593Smuzhiyun * @fdt: Flattened device tree for the next kernel.
173*4882a593Smuzhiyun * @chosen_node: Offset to the chosen node.
174*4882a593Smuzhiyun *
175*4882a593Smuzhiyun * Return: 0 on success, or negative errno on error.
176*4882a593Smuzhiyun */
setup_ima_buffer(const struct kimage * image,void * fdt,int chosen_node)177*4882a593Smuzhiyun int setup_ima_buffer(const struct kimage *image, void *fdt, int chosen_node)
178*4882a593Smuzhiyun {
179*4882a593Smuzhiyun int ret, addr_cells, size_cells, entry_size;
180*4882a593Smuzhiyun u8 value[16];
181*4882a593Smuzhiyun
182*4882a593Smuzhiyun remove_ima_buffer(fdt, chosen_node);
183*4882a593Smuzhiyun if (!image->arch.ima_buffer_size)
184*4882a593Smuzhiyun return 0;
185*4882a593Smuzhiyun
186*4882a593Smuzhiyun ret = get_addr_size_cells(&addr_cells, &size_cells);
187*4882a593Smuzhiyun if (ret)
188*4882a593Smuzhiyun return ret;
189*4882a593Smuzhiyun
190*4882a593Smuzhiyun entry_size = 4 * (addr_cells + size_cells);
191*4882a593Smuzhiyun
192*4882a593Smuzhiyun if (entry_size > sizeof(value))
193*4882a593Smuzhiyun return -EINVAL;
194*4882a593Smuzhiyun
195*4882a593Smuzhiyun ret = write_number(value, image->arch.ima_buffer_addr, addr_cells);
196*4882a593Smuzhiyun if (ret)
197*4882a593Smuzhiyun return ret;
198*4882a593Smuzhiyun
199*4882a593Smuzhiyun ret = write_number(value + 4 * addr_cells, image->arch.ima_buffer_size,
200*4882a593Smuzhiyun size_cells);
201*4882a593Smuzhiyun if (ret)
202*4882a593Smuzhiyun return ret;
203*4882a593Smuzhiyun
204*4882a593Smuzhiyun ret = fdt_setprop(fdt, chosen_node, "linux,ima-kexec-buffer", value,
205*4882a593Smuzhiyun entry_size);
206*4882a593Smuzhiyun if (ret < 0)
207*4882a593Smuzhiyun return -EINVAL;
208*4882a593Smuzhiyun
209*4882a593Smuzhiyun ret = fdt_add_mem_rsv(fdt, image->arch.ima_buffer_addr,
210*4882a593Smuzhiyun image->arch.ima_buffer_size);
211*4882a593Smuzhiyun if (ret)
212*4882a593Smuzhiyun return -EINVAL;
213*4882a593Smuzhiyun
214*4882a593Smuzhiyun pr_debug("IMA buffer at 0x%llx, size = 0x%zx\n",
215*4882a593Smuzhiyun image->arch.ima_buffer_addr, image->arch.ima_buffer_size);
216*4882a593Smuzhiyun
217*4882a593Smuzhiyun return 0;
218*4882a593Smuzhiyun }
219*4882a593Smuzhiyun #endif /* CONFIG_IMA_KEXEC */
220