1b0104773SPascal Brand /* 2b0104773SPascal Brand * Copyright (c) 2014, STMicroelectronics International N.V. 3b0104773SPascal Brand * All rights reserved. 4b0104773SPascal Brand * 5b0104773SPascal Brand * Redistribution and use in source and binary forms, with or without 6b0104773SPascal Brand * modification, are permitted provided that the following conditions are met: 7b0104773SPascal Brand * 8b0104773SPascal Brand * 1. Redistributions of source code must retain the above copyright notice, 9b0104773SPascal Brand * this list of conditions and the following disclaimer. 10b0104773SPascal Brand * 11b0104773SPascal Brand * 2. Redistributions in binary form must reproduce the above copyright notice, 12b0104773SPascal Brand * this list of conditions and the following disclaimer in the documentation 13b0104773SPascal Brand * and/or other materials provided with the distribution. 14b0104773SPascal Brand * 15b0104773SPascal Brand * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" 16b0104773SPascal Brand * AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE 17b0104773SPascal Brand * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE 18b0104773SPascal Brand * ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT HOLDER OR CONTRIBUTORS BE 19b0104773SPascal Brand * LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR 20b0104773SPascal Brand * CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF 21b0104773SPascal Brand * SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS 22b0104773SPascal Brand * INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN 23b0104773SPascal Brand * CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) 24b0104773SPascal Brand * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE 25b0104773SPascal Brand * POSSIBILITY OF SUCH DAMAGE. 26b0104773SPascal Brand */ 272eb765fcSJens Wiklander #include <util.h> 28b0104773SPascal Brand #include <kernel/tee_common_otp.h> 29b0104773SPascal Brand #include <kernel/tee_common.h> 30b0104773SPascal Brand #include <kernel/tee_compat.h> 31b0104773SPascal Brand #include <tee_api_types.h> 32b0104773SPascal Brand #include <kernel/tee_ta_manager.h> 33b0104773SPascal Brand #include <utee_types.h> 34b0104773SPascal Brand #include <tee/tee_svc.h> 35ffe04039SJerome Forissier #include <tee/tee_cryp_utl.h> 36177603c7SJens Wiklander #include <tee/abi.h> 37b0104773SPascal Brand #include <mm/tee_mmu.h> 38b0104773SPascal Brand #include <mm/tee_mm.h> 39b0104773SPascal Brand #include <kernel/tee_rpc.h> 40b0104773SPascal Brand #include <kernel/tee_rpc_types.h> 41b0104773SPascal Brand #include <kernel/tee_time.h> 42b0104773SPascal Brand 43b0104773SPascal Brand #include <user_ta_header.h> 444de4bebcSJens Wiklander #include <trace.h> 454de4bebcSJens Wiklander #include <kernel/trace_ta.h> 46b0104773SPascal Brand #include <kernel/chip_services.h> 47b0104773SPascal Brand 488a1e7b89SJerome Forissier #if (TRACE_LEVEL == TRACE_FLOW) && defined(CFG_TEE_CORE_TA_TRACE) 494de4bebcSJens Wiklander void tee_svc_trace_syscall(int num) 504de4bebcSJens Wiklander { 514de4bebcSJens Wiklander /* #0 is syscall return, not really interesting */ 524de4bebcSJens Wiklander if (num == 0) 534de4bebcSJens Wiklander return; 544de4bebcSJens Wiklander FMSG("syscall #%d", num); 554de4bebcSJens Wiklander } 564de4bebcSJens Wiklander #endif 574de4bebcSJens Wiklander 58453a5030SJerome Forissier void syscall_log(const void *buf __unused, size_t len __unused) 59b0104773SPascal Brand { 607c876f12SPascal Brand #ifdef CFG_TEE_CORE_TA_TRACE 61b0104773SPascal Brand char *kbuf; 62b0104773SPascal Brand 63b0104773SPascal Brand if (len == 0) 64b0104773SPascal Brand return; 65b0104773SPascal Brand 66b0104773SPascal Brand kbuf = malloc(len); 67b0104773SPascal Brand if (kbuf == NULL) 68b0104773SPascal Brand return; 69c0346845SJens Wiklander *kbuf = '\0'; 70b0104773SPascal Brand 71b0104773SPascal Brand /* log as Info/Raw traces */ 72b0104773SPascal Brand if (tee_svc_copy_from_user(NULL, kbuf, buf, len) == TEE_SUCCESS) 734de4bebcSJens Wiklander TAMSG_RAW("%.*s", (int)len, kbuf); 74b0104773SPascal Brand 75b0104773SPascal Brand free(kbuf); 767c876f12SPascal Brand #endif 77b0104773SPascal Brand } 78b0104773SPascal Brand 79453a5030SJerome Forissier TEE_Result syscall_reserved(void) 80b7fc217fSPascal Brand { 81b7fc217fSPascal Brand return TEE_ERROR_GENERIC; 82b7fc217fSPascal Brand } 83b7fc217fSPascal Brand 84453a5030SJerome Forissier TEE_Result syscall_not_supported(void) 85197d17e7SSY Chiu { 86197d17e7SSY Chiu return TEE_ERROR_NOT_SUPPORTED; 87197d17e7SSY Chiu } 88197d17e7SSY Chiu 89453a5030SJerome Forissier uint32_t syscall_dummy(uint32_t *a __unused) 90b0104773SPascal Brand { 91851aa858SJens Wiklander DMSG("tee_svc_sys_dummy: a 0x%" PRIxVA, (vaddr_t)a); 92b0104773SPascal Brand return 0; 93b0104773SPascal Brand } 94b0104773SPascal Brand 95453a5030SJerome Forissier uint32_t syscall_dummy_7args(uint32_t a1 __unused, uint32_t a2 __unused, 96cebdec51SJens Wiklander uint32_t a3 __unused, uint32_t a4 __unused, 97cebdec51SJens Wiklander uint32_t a5 __unused, uint32_t a6 __unused, 98cebdec51SJens Wiklander uint32_t a7 __unused) 99b0104773SPascal Brand { 100b0104773SPascal Brand DMSG("tee_svc_sys_dummy_7args: 0x%x, 0x%x, 0x%x, 0x%x, 0x%x, %x, %x\n", 101b0104773SPascal Brand a1, a2, a3, a4, a5, a6, a7); 102b0104773SPascal Brand return 0; 103b0104773SPascal Brand } 104b0104773SPascal Brand 105453a5030SJerome Forissier uint32_t syscall_nocall(void) 106b0104773SPascal Brand { 107b0104773SPascal Brand DMSG("No syscall"); 108b0104773SPascal Brand return 0x1; 109b0104773SPascal Brand } 110b0104773SPascal Brand 111ab35d7adSCedric Chaumont /* Configuration properties */ 112ab35d7adSCedric Chaumont /* API implementation version */ 113ab35d7adSCedric Chaumont static const char api_vers[] = TO_STR(CFG_TEE_API_VERSION); 114ab35d7adSCedric Chaumont 115ab35d7adSCedric Chaumont /* Implementation description (implementation-dependent) */ 116ab35d7adSCedric Chaumont static const char descr[] = TO_STR(CFG_TEE_IMPL_DESCR); 117ab35d7adSCedric Chaumont 118b0104773SPascal Brand /* 119ab35d7adSCedric Chaumont * TA persistent time protection level 120ab35d7adSCedric Chaumont * 100: Persistent time based on an REE-controlled real-time clock 121ab35d7adSCedric Chaumont * and on the TEE Trusted Storage for the storage of origins (default). 122ab35d7adSCedric Chaumont * 1000: Persistent time based on a TEE-controlled real-time clock 123ab35d7adSCedric Chaumont * and the TEE Trusted Storage. 124ab35d7adSCedric Chaumont * The real-time clock MUST be out of reach of software attacks 125ab35d7adSCedric Chaumont * from the REE. 126ab35d7adSCedric Chaumont */ 127b0104773SPascal Brand static const uint32_t ta_time_prot_lvl = 100; 128ab35d7adSCedric Chaumont 129ab35d7adSCedric Chaumont /* Elliptic Curve Cryptographic support (false by default) */ 130ab35d7adSCedric Chaumont static const bool crypto_ecc_en; 131ab35d7adSCedric Chaumont 132ab35d7adSCedric Chaumont /* 133ab35d7adSCedric Chaumont * Trusted storage anti rollback protection level 134ab35d7adSCedric Chaumont * 0 (or missing): No antirollback protection (default) 135ab35d7adSCedric Chaumont * 100: Antirollback enforced at REE level 136ab35d7adSCedric Chaumont * 1000: Antirollback TEE-controlled hardware 137ab35d7adSCedric Chaumont */ 138ab35d7adSCedric Chaumont static const uint32_t ts_antiroll_prot_lvl; 139ab35d7adSCedric Chaumont 140ab35d7adSCedric Chaumont /* Trusted OS implementation version */ 141ab35d7adSCedric Chaumont static const char trustedos_impl_version[] = TO_STR(CFG_TEE_IMPL_VERSION); 142ab35d7adSCedric Chaumont 143ab35d7adSCedric Chaumont /* Trusted OS implementation version (binary value) */ 144ab35d7adSCedric Chaumont static const uint32_t trustedos_impl_bin_version; /* 0 by default */ 145ab35d7adSCedric Chaumont 146ab35d7adSCedric Chaumont /* Trusted OS implementation manufacturer name */ 147ab35d7adSCedric Chaumont static const char trustedos_manufacturer[] = TO_STR(CFG_TEE_MANUFACTURER); 148ab35d7adSCedric Chaumont 149ab35d7adSCedric Chaumont /* Trusted firmware version */ 150ab35d7adSCedric Chaumont static const char fw_impl_version[] = TO_STR(CFG_TEE_FW_IMPL_VERSION); 151ab35d7adSCedric Chaumont 152ab35d7adSCedric Chaumont /* Trusted firmware version (binary value) */ 153ab35d7adSCedric Chaumont static const uint32_t fw_impl_bin_version; /* 0 by default */ 154ab35d7adSCedric Chaumont 155ab35d7adSCedric Chaumont /* Trusted firmware manufacturer name */ 156ab35d7adSCedric Chaumont static const char fw_manufacturer[] = TO_STR(CFG_TEE_FW_MANUFACTURER); 157ab35d7adSCedric Chaumont 158ab35d7adSCedric Chaumont struct tee_props { 159ab35d7adSCedric Chaumont const void *data; 160ab35d7adSCedric Chaumont const size_t len; 161ab35d7adSCedric Chaumont }; 162ab35d7adSCedric Chaumont 163ab35d7adSCedric Chaumont /* Consistent with enum utee_property */ 164ab35d7adSCedric Chaumont const struct tee_props tee_props_lut[] = { 165ab35d7adSCedric Chaumont {api_vers, sizeof(api_vers)}, 166ab35d7adSCedric Chaumont {descr, sizeof(descr)}, 167ab35d7adSCedric Chaumont {0, 0}, /* dev_id */ 1682cdaaacbSJerome Forissier {0, 0}, /* system time protection level */ 169ab35d7adSCedric Chaumont {&ta_time_prot_lvl, sizeof(ta_time_prot_lvl)}, 170ab35d7adSCedric Chaumont {&crypto_ecc_en, sizeof(crypto_ecc_en)}, 171ab35d7adSCedric Chaumont {&ts_antiroll_prot_lvl, sizeof(ts_antiroll_prot_lvl)}, 172ab35d7adSCedric Chaumont {trustedos_impl_version, sizeof(trustedos_impl_version)}, 173ab35d7adSCedric Chaumont {&trustedos_impl_bin_version, 174ab35d7adSCedric Chaumont sizeof(trustedos_impl_bin_version)}, 175ab35d7adSCedric Chaumont {trustedos_manufacturer, sizeof(trustedos_manufacturer)}, 176ab35d7adSCedric Chaumont {fw_impl_version, sizeof(fw_impl_version)}, 177ab35d7adSCedric Chaumont {&fw_impl_bin_version, sizeof(fw_impl_bin_version)}, 178ab35d7adSCedric Chaumont {fw_manufacturer, sizeof(fw_manufacturer)}, 179ab35d7adSCedric Chaumont {0, 0}, /* client_id */ 180ab35d7adSCedric Chaumont {0, 0}, /* ta_app_id */ 181ab35d7adSCedric Chaumont }; 182ab35d7adSCedric Chaumont 183453a5030SJerome Forissier TEE_Result syscall_get_property(uint32_t prop, tee_uaddr_t buf, size_t blen) 184ab35d7adSCedric Chaumont { 185b0104773SPascal Brand struct tee_ta_session *sess; 186b0104773SPascal Brand TEE_Result res; 187b0104773SPascal Brand 188ab35d7adSCedric Chaumont if (prop > ARRAY_SIZE(tee_props_lut)-1) 189ab35d7adSCedric Chaumont return TEE_ERROR_NOT_IMPLEMENTED; 190ab35d7adSCedric Chaumont 191b0104773SPascal Brand res = tee_ta_get_current_session(&sess); 192b0104773SPascal Brand if (res != TEE_SUCCESS) 193b0104773SPascal Brand return res; 194b0104773SPascal Brand 195b0104773SPascal Brand switch (prop) { 196b0104773SPascal Brand case UTEE_PROP_TEE_DEV_ID: 197b0104773SPascal Brand { 198b0104773SPascal Brand TEE_UUID uuid; 199ab35d7adSCedric Chaumont const size_t nslen = 5; 200ab35d7adSCedric Chaumont uint8_t data[5 + 201b0104773SPascal Brand FVR_DIE_ID_NUM_REGS * sizeof(uint32_t)] = { 202ab35d7adSCedric Chaumont 'O', 'P', 'T', 'E', 'E' }; 203b0104773SPascal Brand 204b0104773SPascal Brand if (blen < sizeof(uuid)) 205b0104773SPascal Brand return TEE_ERROR_SHORT_BUFFER; 206b0104773SPascal Brand 207b0104773SPascal Brand if (tee_otp_get_die_id 208b0104773SPascal Brand (data + nslen, sizeof(data) - nslen)) 209b0104773SPascal Brand return TEE_ERROR_BAD_STATE; 210b0104773SPascal Brand 211ffe04039SJerome Forissier res = tee_hash_createdigest(TEE_ALG_SHA256, data, 212ffe04039SJerome Forissier sizeof(data), 213ffe04039SJerome Forissier (uint8_t *)&uuid, 214ffe04039SJerome Forissier sizeof(uuid)); 215b0104773SPascal Brand if (res != TEE_SUCCESS) 216b0104773SPascal Brand return TEE_ERROR_BAD_STATE; 217b0104773SPascal Brand 218b0104773SPascal Brand /* 219b0104773SPascal Brand * Changes the random value into and UUID as specifiec 220b0104773SPascal Brand * in RFC 4122. The magic values are from the example 221b0104773SPascal Brand * code in the RFC. 222b0104773SPascal Brand * 223b0104773SPascal Brand * TEE_UUID is defined slightly different from the RFC, 224b0104773SPascal Brand * but close enough for our purpose. 225b0104773SPascal Brand */ 226b0104773SPascal Brand 227b0104773SPascal Brand uuid.timeHiAndVersion &= 0x0fff; 228b0104773SPascal Brand uuid.timeHiAndVersion |= 5 << 12; 229b0104773SPascal Brand 230b0104773SPascal Brand /* uuid.clock_seq_hi_and_reserved in the RFC */ 231b0104773SPascal Brand uuid.clockSeqAndNode[0] &= 0x3f; 232b0104773SPascal Brand uuid.clockSeqAndNode[0] |= 0x80; 233b0104773SPascal Brand 234b0104773SPascal Brand return tee_svc_copy_to_user(sess, (void *)buf, &uuid, 235b0104773SPascal Brand sizeof(TEE_UUID)); 236b0104773SPascal Brand } 237b0104773SPascal Brand 2382cdaaacbSJerome Forissier case UTEE_PROP_TEE_SYS_TIME_PROT_LEVEL: 2392cdaaacbSJerome Forissier { 2402cdaaacbSJerome Forissier uint32_t prot; 2412cdaaacbSJerome Forissier 2422cdaaacbSJerome Forissier if (blen < sizeof(prot)) 2432cdaaacbSJerome Forissier return TEE_ERROR_SHORT_BUFFER; 2442cdaaacbSJerome Forissier prot = tee_time_get_sys_time_protection_level(); 2452cdaaacbSJerome Forissier return tee_svc_copy_to_user(sess, (void *)buf, 2462cdaaacbSJerome Forissier &prot, sizeof(prot)); 2472cdaaacbSJerome Forissier } 2482cdaaacbSJerome Forissier 249b0104773SPascal Brand case UTEE_PROP_CLIENT_ID: 250b0104773SPascal Brand if (blen < sizeof(TEE_Identity)) 251b0104773SPascal Brand return TEE_ERROR_SHORT_BUFFER; 252b0104773SPascal Brand return tee_svc_copy_to_user(sess, (void *)buf, 253ab35d7adSCedric Chaumont &sess->clnt_id, 254ab35d7adSCedric Chaumont sizeof(TEE_Identity)); 25537d6ae92SPascal Brand 256b0104773SPascal Brand case UTEE_PROP_TA_APP_ID: 257b0104773SPascal Brand if (blen < sizeof(TEE_UUID)) 258b0104773SPascal Brand return TEE_ERROR_SHORT_BUFFER; 259b0104773SPascal Brand return tee_svc_copy_to_user(sess, (void *)buf, 260bc420748SJens Wiklander &sess->ctx->uuid, 261ab35d7adSCedric Chaumont sizeof(TEE_UUID)); 262b0104773SPascal Brand default: 263ab35d7adSCedric Chaumont if (blen < tee_props_lut[prop].len) 264ab35d7adSCedric Chaumont return TEE_ERROR_SHORT_BUFFER; 265ab35d7adSCedric Chaumont return tee_svc_copy_to_user(sess, (void *)buf, 266ab35d7adSCedric Chaumont tee_props_lut[prop].data, 267ab35d7adSCedric Chaumont tee_props_lut[prop].len); 268b0104773SPascal Brand } 269b0104773SPascal Brand } 270b0104773SPascal Brand 271b0104773SPascal Brand /* 272b0104773SPascal Brand * TA invokes some TA with parameter. 273b0104773SPascal Brand * If some parameters are memory references: 274b0104773SPascal Brand * - either the memref is inside TA private RAM: TA is not allowed to expose 275b0104773SPascal Brand * its private RAM: use a temporary memory buffer and copy the data. 276b0104773SPascal Brand * - or the memref is not in the TA private RAM: 277b0104773SPascal Brand * - if the memref was mapped to the TA, TA is allowed to expose it. 278b0104773SPascal Brand * - if so, converts memref virtual address into a physical address. 279b0104773SPascal Brand */ 280b0104773SPascal Brand static TEE_Result tee_svc_copy_param(struct tee_ta_session *sess, 281b0104773SPascal Brand struct tee_ta_session *called_sess, 282b0104773SPascal Brand uint32_t param_types, 283177603c7SJens Wiklander struct abi_user32_param *callee_params, 284b0104773SPascal Brand struct tee_ta_param *param, 285b0104773SPascal Brand tee_paddr_t tmp_buf_pa[TEE_NUM_PARAMS], 286b0104773SPascal Brand tee_mm_entry_t **mm) 287b0104773SPascal Brand { 288b0104773SPascal Brand size_t n; 289b0104773SPascal Brand TEE_Result res; 290b0104773SPascal Brand size_t req_mem = 0; 291b0104773SPascal Brand size_t s; 292b0104773SPascal Brand uint8_t *dst = 0; 293b0104773SPascal Brand tee_paddr_t dst_pa, src_pa = 0; 294b0104773SPascal Brand bool ta_private_memref[TEE_NUM_PARAMS]; 295b0104773SPascal Brand 296b7fc217fSPascal Brand /* fill 'param' input struct with caller params description buffer */ 297b0104773SPascal Brand param->types = param_types; 298b7fc217fSPascal Brand if (!callee_params) { 299b0104773SPascal Brand if (param->types != 0) 300b0104773SPascal Brand return TEE_ERROR_BAD_PARAMETERS; 301b0104773SPascal Brand memset(param->params, 0, sizeof(param->params)); 302b0104773SPascal Brand } else { 303177603c7SJens Wiklander res = tee_mmu_check_access_rights(sess->ctx, 304177603c7SJens Wiklander TEE_MEMORY_ACCESS_READ | TEE_MEMORY_ACCESS_ANY_OWNER, 305177603c7SJens Wiklander (tee_uaddr_t)callee_params, 306177603c7SJens Wiklander sizeof(struct abi_user32_param)); 307177603c7SJens Wiklander if (res != TEE_SUCCESS) 308177603c7SJens Wiklander return res; 309177603c7SJens Wiklander abi_user32_param_to_param(param->params, callee_params, 310177603c7SJens Wiklander param_types); 311b0104773SPascal Brand } 312b0104773SPascal Brand 313b0104773SPascal Brand if ((called_sess != NULL) && 314b0104773SPascal Brand (called_sess->ctx->static_ta == NULL) && 315b0104773SPascal Brand (called_sess->ctx->flags & TA_FLAG_USER_MODE) == 0) { 316b0104773SPascal Brand /* 317b0104773SPascal Brand * kernel TA, borrow the mapping of the calling 318b0104773SPascal Brand * during this call. 319b0104773SPascal Brand */ 320b0104773SPascal Brand called_sess->calling_sess = sess; 321b0104773SPascal Brand return TEE_SUCCESS; 322b0104773SPascal Brand } 323b0104773SPascal Brand 324b0104773SPascal Brand for (n = 0; n < TEE_NUM_PARAMS; n++) { 325b0104773SPascal Brand 326b0104773SPascal Brand ta_private_memref[n] = false; 327b0104773SPascal Brand 328b0104773SPascal Brand switch (TEE_PARAM_TYPE_GET(param->types, n)) { 329b0104773SPascal Brand case TEE_PARAM_TYPE_MEMREF_INPUT: 330b0104773SPascal Brand case TEE_PARAM_TYPE_MEMREF_OUTPUT: 331b0104773SPascal Brand case TEE_PARAM_TYPE_MEMREF_INOUT: 332b0104773SPascal Brand if (param->params[n].memref.buffer == NULL) { 333b0104773SPascal Brand if (param->params[n].memref.size != 0) 334b0104773SPascal Brand return TEE_ERROR_BAD_PARAMETERS; 335b0104773SPascal Brand break; 336b0104773SPascal Brand } 337b0104773SPascal Brand /* uTA cannot expose its private memory */ 338b0104773SPascal Brand if (tee_mmu_is_vbuf_inside_ta_private(sess->ctx, 339106d8aa6SPascal Brand param->params[n].memref.buffer, 340b0104773SPascal Brand param->params[n].memref.size)) { 341b0104773SPascal Brand 342a17acc4cSSabrina Ni s = ROUNDUP(param->params[n].memref.size, 343b0104773SPascal Brand sizeof(uint32_t)); 344b0104773SPascal Brand /* Check overflow */ 345b0104773SPascal Brand if (req_mem + s < req_mem) 346b0104773SPascal Brand return TEE_ERROR_BAD_PARAMETERS; 347b0104773SPascal Brand req_mem += s; 348b0104773SPascal Brand ta_private_memref[n] = true; 349b0104773SPascal Brand break; 350b0104773SPascal Brand } 351106d8aa6SPascal Brand if (tee_mmu_is_vbuf_intersect_ta_private(sess->ctx, 352106d8aa6SPascal Brand param->params[n].memref.buffer, 353b0104773SPascal Brand param->params[n].memref.size)) 354b0104773SPascal Brand return TEE_ERROR_BAD_PARAMETERS; 355b0104773SPascal Brand 356b0104773SPascal Brand if (tee_mmu_user_va2pa(sess->ctx, 357b0104773SPascal Brand (void *)param->params[n].memref.buffer, 3580e692b78SJens Wiklander &src_pa) != TEE_SUCCESS) 359b0104773SPascal Brand return TEE_ERROR_BAD_PARAMETERS; 360b0104773SPascal Brand 361b0104773SPascal Brand param->param_attr[n] = tee_mmu_user_get_cache_attr( 362b0104773SPascal Brand sess->ctx, 363b0104773SPascal Brand (void *)param->params[n].memref.buffer); 364b0104773SPascal Brand 365b0104773SPascal Brand param->params[n].memref.buffer = (void *)src_pa; 366b0104773SPascal Brand break; 367b0104773SPascal Brand 368b0104773SPascal Brand default: 369b0104773SPascal Brand break; 370b0104773SPascal Brand } 371b0104773SPascal Brand } 372b0104773SPascal Brand 373b0104773SPascal Brand if (req_mem == 0) 374b0104773SPascal Brand return TEE_SUCCESS; 375b0104773SPascal Brand 376b0104773SPascal Brand /* Allocate section in secure DDR */ 377b0104773SPascal Brand *mm = tee_mm_alloc(&tee_mm_sec_ddr, req_mem); 378b0104773SPascal Brand if (*mm == NULL) { 379b0104773SPascal Brand DMSG("tee_mm_alloc TEE_ERROR_GENERIC"); 380b0104773SPascal Brand return TEE_ERROR_GENERIC; 381b0104773SPascal Brand } 382b0104773SPascal Brand 383b0104773SPascal Brand /* Get the virtual address for the section in secure DDR */ 384b0104773SPascal Brand res = tee_mmu_kmap(tee_mm_get_smem(*mm), req_mem, &dst); 385b0104773SPascal Brand if (res != TEE_SUCCESS) 386b0104773SPascal Brand return res; 387b0104773SPascal Brand dst_pa = tee_mm_get_smem(*mm); 388b0104773SPascal Brand 389b0104773SPascal Brand for (n = 0; n < 4; n++) { 390b0104773SPascal Brand 391b0104773SPascal Brand if (ta_private_memref[n] == false) 392b0104773SPascal Brand continue; 393b0104773SPascal Brand 394a17acc4cSSabrina Ni s = ROUNDUP(param->params[n].memref.size, sizeof(uint32_t)); 395b0104773SPascal Brand 396b0104773SPascal Brand switch (TEE_PARAM_TYPE_GET(param->types, n)) { 397b0104773SPascal Brand case TEE_PARAM_TYPE_MEMREF_INPUT: 398b0104773SPascal Brand case TEE_PARAM_TYPE_MEMREF_INOUT: 399b0104773SPascal Brand if (param->params[n].memref.buffer != NULL) { 400b0104773SPascal Brand res = tee_svc_copy_from_user(sess, dst, 401b7fc217fSPascal Brand param->params[n].memref.buffer, 402b7fc217fSPascal Brand param->params[n].memref.size); 403b0104773SPascal Brand if (res != TEE_SUCCESS) 404b0104773SPascal Brand return res; 405b0104773SPascal Brand param->param_attr[n] = 406b0104773SPascal Brand tee_mmu_kmap_get_cache_attr(dst); 407b0104773SPascal Brand param->params[n].memref.buffer = (void *)dst_pa; 408b0104773SPascal Brand tmp_buf_pa[n] = dst_pa; 409b0104773SPascal Brand dst += s; 410b0104773SPascal Brand dst_pa += s; 411b0104773SPascal Brand } 412b0104773SPascal Brand break; 413b0104773SPascal Brand 414b0104773SPascal Brand case TEE_PARAM_TYPE_MEMREF_OUTPUT: 415b0104773SPascal Brand if (param->params[n].memref.buffer != NULL) { 416b0104773SPascal Brand param->param_attr[n] = 417b0104773SPascal Brand tee_mmu_kmap_get_cache_attr(dst); 418b0104773SPascal Brand param->params[n].memref.buffer = (void *)dst_pa; 419b0104773SPascal Brand tmp_buf_pa[n] = dst_pa; 420b0104773SPascal Brand dst += s; 421b0104773SPascal Brand dst_pa += s; 422b0104773SPascal Brand } 423b0104773SPascal Brand break; 424b0104773SPascal Brand 425b0104773SPascal Brand default: 426b0104773SPascal Brand continue; 427b0104773SPascal Brand } 428b0104773SPascal Brand } 429b0104773SPascal Brand 430b0104773SPascal Brand tee_mmu_kunmap(dst, req_mem); 431b0104773SPascal Brand 432b0104773SPascal Brand return TEE_SUCCESS; 433b0104773SPascal Brand } 434b0104773SPascal Brand 435b0104773SPascal Brand /* 436b0104773SPascal Brand * Back from execution of service: update parameters passed from TA: 437b0104773SPascal Brand * If some parameters were memory references: 438b0104773SPascal Brand * - either the memref was temporary: copy back data and update size 439b0104773SPascal Brand * - or it was the original TA memref: update only the size value. 440b0104773SPascal Brand */ 441b0104773SPascal Brand static TEE_Result tee_svc_update_out_param( 442b0104773SPascal Brand struct tee_ta_session *sess, 443b0104773SPascal Brand struct tee_ta_session *called_sess, 444b0104773SPascal Brand struct tee_ta_param *param, 445b0104773SPascal Brand tee_paddr_t tmp_buf_pa[TEE_NUM_PARAMS], 446177603c7SJens Wiklander struct abi_user32_param *usr_param) 447b0104773SPascal Brand { 448b0104773SPascal Brand size_t n; 449177603c7SJens Wiklander TEE_Param callee_params[TEE_NUM_PARAMS]; 450b0104773SPascal Brand bool have_private_mem_map = (called_sess == NULL) || 451b0104773SPascal Brand (called_sess->ctx->static_ta != NULL) || 452b0104773SPascal Brand ((called_sess->ctx->flags & TA_FLAG_USER_MODE) != 0); 453b0104773SPascal Brand 454bc420748SJens Wiklander 455b0104773SPascal Brand tee_ta_set_current_session(sess); 456177603c7SJens Wiklander abi_user32_param_to_param(callee_params, usr_param, param->types); 457b0104773SPascal Brand 458b0104773SPascal Brand for (n = 0; n < TEE_NUM_PARAMS; n++) { 459b0104773SPascal Brand switch (TEE_PARAM_TYPE_GET(param->types, n)) { 460b0104773SPascal Brand case TEE_PARAM_TYPE_MEMREF_OUTPUT: 461b0104773SPascal Brand case TEE_PARAM_TYPE_MEMREF_INOUT: 462b0104773SPascal Brand 463b0104773SPascal Brand /* outside TA private => memref is valid, update size */ 464b0104773SPascal Brand if (!tee_mmu_is_vbuf_inside_ta_private(sess->ctx, 465106d8aa6SPascal Brand callee_params[n].memref.buffer, 466b0104773SPascal Brand param->params[n].memref.size)) { 467b7fc217fSPascal Brand callee_params[n].memref.size = 468b0104773SPascal Brand param->params[n].memref.size; 469b0104773SPascal Brand break; 470b0104773SPascal Brand } 471b0104773SPascal Brand 472b0104773SPascal Brand /* 473b0104773SPascal Brand * If we called a kernel TA the parameters are in shared 474b0104773SPascal Brand * memory and no copy is needed. 475b0104773SPascal Brand */ 476b0104773SPascal Brand if (have_private_mem_map && 477b0104773SPascal Brand param->params[n].memref.size <= 478b7fc217fSPascal Brand callee_params[n].memref.size) { 479b0104773SPascal Brand uint8_t *src = 0; 480b0104773SPascal Brand TEE_Result res; 481b0104773SPascal Brand 482b0104773SPascal Brand /* FIXME: TA_RAM is already mapped ! */ 483b0104773SPascal Brand res = tee_mmu_kmap(tmp_buf_pa[n], 484b0104773SPascal Brand param->params[n].memref.size, &src); 485b0104773SPascal Brand if (res != TEE_SUCCESS) 486b0104773SPascal Brand return TEE_ERROR_GENERIC; 487b0104773SPascal Brand 488b0104773SPascal Brand res = tee_svc_copy_to_user(sess, 489b7fc217fSPascal Brand callee_params[n].memref. 490b0104773SPascal Brand buffer, src, 491b0104773SPascal Brand param->params[n]. 492b0104773SPascal Brand memref.size); 493b0104773SPascal Brand if (res != TEE_SUCCESS) 494b0104773SPascal Brand return res; 495b0104773SPascal Brand tee_mmu_kunmap(src, 496b0104773SPascal Brand param->params[n].memref.size); 497b0104773SPascal Brand 498b0104773SPascal Brand } 499b7fc217fSPascal Brand callee_params[n].memref.size = param->params[n].memref.size; 500b0104773SPascal Brand break; 501b0104773SPascal Brand 502b0104773SPascal Brand case TEE_PARAM_TYPE_VALUE_OUTPUT: 503b0104773SPascal Brand case TEE_PARAM_TYPE_VALUE_INOUT: 504b7fc217fSPascal Brand callee_params[n].value = param->params[n].value; 505b0104773SPascal Brand break; 506b0104773SPascal Brand 507b0104773SPascal Brand default: 508b0104773SPascal Brand continue; 509b0104773SPascal Brand } 510b0104773SPascal Brand } 511b0104773SPascal Brand 512177603c7SJens Wiklander abi_param_to_user32_param(usr_param, callee_params, param->types); 513177603c7SJens Wiklander 514b0104773SPascal Brand return TEE_SUCCESS; 515b0104773SPascal Brand } 516b0104773SPascal Brand 517b0104773SPascal Brand /* Called when a TA calls an OpenSession on another TA */ 518453a5030SJerome Forissier TEE_Result syscall_open_ta_session(const TEE_UUID *dest, 519b0104773SPascal Brand uint32_t cancel_req_to, uint32_t param_types, 520177603c7SJens Wiklander struct abi_user32_param *usr_param, 521b0104773SPascal Brand TEE_TASessionHandle *ta_sess, 522b0104773SPascal Brand uint32_t *ret_orig) 523b0104773SPascal Brand { 524b0104773SPascal Brand TEE_Result res; 525b0104773SPascal Brand uint32_t ret_o = TEE_ORIGIN_TEE; 526b0104773SPascal Brand struct tee_ta_session *s = NULL; 527b0104773SPascal Brand struct tee_ta_session *sess; 528b0104773SPascal Brand tee_mm_entry_t *mm_param = NULL; 529b0104773SPascal Brand 530b0104773SPascal Brand TEE_UUID *uuid = malloc(sizeof(TEE_UUID)); 531b0104773SPascal Brand struct tee_ta_param *param = malloc(sizeof(struct tee_ta_param)); 532b0104773SPascal Brand TEE_Identity *clnt_id = malloc(sizeof(TEE_Identity)); 533b0104773SPascal Brand tee_paddr_t tmp_buf_pa[TEE_NUM_PARAMS]; 534b0104773SPascal Brand 535b0104773SPascal Brand if (uuid == NULL || param == NULL || clnt_id == NULL) { 536b0104773SPascal Brand res = TEE_ERROR_OUT_OF_MEMORY; 537b0104773SPascal Brand goto out_free_only; 538b0104773SPascal Brand } 539b0104773SPascal Brand 540b0104773SPascal Brand memset(param, 0, sizeof(struct tee_ta_param)); 541b0104773SPascal Brand 542b0104773SPascal Brand res = tee_ta_get_current_session(&sess); 543b0104773SPascal Brand if (res != TEE_SUCCESS) 544b0104773SPascal Brand goto out_free_only; 545b0104773SPascal Brand 546b0104773SPascal Brand res = tee_svc_copy_from_user(sess, uuid, dest, sizeof(TEE_UUID)); 547b0104773SPascal Brand if (res != TEE_SUCCESS) 548b0104773SPascal Brand goto function_exit; 549b0104773SPascal Brand 550b0104773SPascal Brand clnt_id->login = TEE_LOGIN_TRUSTED_APP; 551bc420748SJens Wiklander memcpy(&clnt_id->uuid, &sess->ctx->uuid, sizeof(TEE_UUID)); 552b0104773SPascal Brand 553177603c7SJens Wiklander res = tee_svc_copy_param(sess, NULL, param_types, usr_param, param, 554b0104773SPascal Brand tmp_buf_pa, &mm_param); 555b0104773SPascal Brand if (res != TEE_SUCCESS) 556b0104773SPascal Brand goto function_exit; 557b0104773SPascal Brand 558b0104773SPascal Brand /* 559b0104773SPascal Brand * Find session of a multi session TA or a static TA 560b0104773SPascal Brand * In such a case, there is no need to ask the supplicant for the TA 561b0104773SPascal Brand * code 562b0104773SPascal Brand */ 563b0104773SPascal Brand res = tee_ta_open_session(&ret_o, &s, &sess->ctx->open_sessions, uuid, 56427cbcc57SJens Wiklander clnt_id, cancel_req_to, param); 565c0346845SJens Wiklander if (res != TEE_SUCCESS) 566b0104773SPascal Brand goto function_exit; 567b0104773SPascal Brand 568177603c7SJens Wiklander res = tee_svc_update_out_param(sess, NULL, param, tmp_buf_pa, 569177603c7SJens Wiklander usr_param); 570b0104773SPascal Brand 571b0104773SPascal Brand function_exit: 572b0104773SPascal Brand tee_ta_set_current_session(sess); 573b0104773SPascal Brand 574b0104773SPascal Brand if (mm_param != NULL) { 575b0104773SPascal Brand TEE_Result res2; 576b0104773SPascal Brand void *va = 0; 577b0104773SPascal Brand 578b0104773SPascal Brand res2 = 579b0104773SPascal Brand tee_mmu_kmap_pa2va((void *)tee_mm_get_smem(mm_param), &va); 580b0104773SPascal Brand if (res2 == TEE_SUCCESS) 581b0104773SPascal Brand tee_mmu_kunmap(va, tee_mm_get_bytes(mm_param)); 582b0104773SPascal Brand } 583b0104773SPascal Brand tee_mm_free(mm_param); 5848707ec0fSJerome Forissier /* 5858707ec0fSJerome Forissier * We know that sizeof(TEE_TASessionHandle) in user mode (TA) is 4, 5868707ec0fSJerome Forissier * because we only support 32-bit TAs, so take care not to overflow it 5878707ec0fSJerome Forissier * if kernel addresses are 64-bit 5888707ec0fSJerome Forissier */ 5898707ec0fSJerome Forissier tee_svc_copy_kaddr_to_user32(sess, (uint32_t *)ta_sess, s); 590b0104773SPascal Brand tee_svc_copy_to_user(sess, ret_orig, &ret_o, sizeof(ret_o)); 591b0104773SPascal Brand 592b0104773SPascal Brand out_free_only: 593b0104773SPascal Brand free(param); 594b0104773SPascal Brand free(uuid); 595b0104773SPascal Brand free(clnt_id); 596b0104773SPascal Brand return res; 597b0104773SPascal Brand } 598b0104773SPascal Brand 599453a5030SJerome Forissier TEE_Result syscall_close_ta_session(TEE_TASessionHandle ta_sess) 600b0104773SPascal Brand { 601b0104773SPascal Brand TEE_Result res; 602b0104773SPascal Brand struct tee_ta_session *sess; 60360699957SPascal Brand TEE_Identity clnt_id; 604b0104773SPascal Brand 605b0104773SPascal Brand res = tee_ta_get_current_session(&sess); 606b0104773SPascal Brand if (res != TEE_SUCCESS) 607b0104773SPascal Brand return res; 608b0104773SPascal Brand 60960699957SPascal Brand clnt_id.login = TEE_LOGIN_TRUSTED_APP; 610bc420748SJens Wiklander memcpy(&clnt_id.uuid, &sess->ctx->uuid, sizeof(TEE_UUID)); 611b0104773SPascal Brand 61260699957SPascal Brand tee_ta_set_current_session(NULL); 613096cbcddSJean-Michel Delorme res = tee_ta_close_session((struct tee_ta_session *)ta_sess, 614096cbcddSJean-Michel Delorme &sess->ctx->open_sessions, 61560699957SPascal Brand &clnt_id); 616b0104773SPascal Brand tee_ta_set_current_session(sess); 617b0104773SPascal Brand return res; 618b0104773SPascal Brand } 619b0104773SPascal Brand 620453a5030SJerome Forissier TEE_Result syscall_invoke_ta_command(TEE_TASessionHandle ta_sess, 621b0104773SPascal Brand uint32_t cancel_req_to, uint32_t cmd_id, 622177603c7SJens Wiklander uint32_t param_types, 623177603c7SJens Wiklander struct abi_user32_param *usr_param, 624b0104773SPascal Brand uint32_t *ret_orig) 625b0104773SPascal Brand { 626b0104773SPascal Brand TEE_Result res; 627b0104773SPascal Brand uint32_t ret_o = TEE_ORIGIN_TEE; 628b0104773SPascal Brand struct tee_ta_param param = { 0 }; 62960699957SPascal Brand TEE_Identity clnt_id; 630b0104773SPascal Brand struct tee_ta_session *sess; 631*b666b6f2SJens Wiklander struct tee_ta_session *called_sess; 632b0104773SPascal Brand tee_mm_entry_t *mm_param = NULL; 633b0104773SPascal Brand tee_paddr_t tmp_buf_pa[TEE_NUM_PARAMS]; 634b0104773SPascal Brand 635b0104773SPascal Brand res = tee_ta_get_current_session(&sess); 636b0104773SPascal Brand if (res != TEE_SUCCESS) 637b0104773SPascal Brand return res; 638b0104773SPascal Brand 639*b666b6f2SJens Wiklander called_sess = tee_ta_get_session((vaddr_t)ta_sess, true, 640b0104773SPascal Brand &sess->ctx->open_sessions); 641*b666b6f2SJens Wiklander if (!called_sess) 642*b666b6f2SJens Wiklander return TEE_ERROR_BAD_PARAMETERS; 643b0104773SPascal Brand 64460699957SPascal Brand clnt_id.login = TEE_LOGIN_TRUSTED_APP; 645bc420748SJens Wiklander memcpy(&clnt_id.uuid, &sess->ctx->uuid, sizeof(TEE_UUID)); 64660699957SPascal Brand 647177603c7SJens Wiklander res = tee_svc_copy_param(sess, called_sess, param_types, usr_param, 648b0104773SPascal Brand ¶m, tmp_buf_pa, &mm_param); 649b0104773SPascal Brand if (res != TEE_SUCCESS) 650b0104773SPascal Brand goto function_exit; 651b0104773SPascal Brand 65260699957SPascal Brand res = tee_ta_invoke_command(&ret_o, called_sess, &clnt_id, 65360699957SPascal Brand cancel_req_to, cmd_id, ¶m); 65460699957SPascal Brand 655b0104773SPascal Brand if (res != TEE_SUCCESS) 656b0104773SPascal Brand goto function_exit; 657b0104773SPascal Brand 658b0104773SPascal Brand res = tee_svc_update_out_param(sess, called_sess, ¶m, tmp_buf_pa, 659177603c7SJens Wiklander usr_param); 660b0104773SPascal Brand if (res != TEE_SUCCESS) 661b0104773SPascal Brand goto function_exit; 662b0104773SPascal Brand 663b0104773SPascal Brand function_exit: 664b0104773SPascal Brand tee_ta_set_current_session(sess); 665b0104773SPascal Brand called_sess->calling_sess = NULL; /* clear eventual borrowed mapping */ 666*b666b6f2SJens Wiklander tee_ta_put_session(called_sess); 667b0104773SPascal Brand 668b0104773SPascal Brand if (mm_param != NULL) { 669b0104773SPascal Brand TEE_Result res2; 670b0104773SPascal Brand void *va = 0; 671b0104773SPascal Brand 672b0104773SPascal Brand res2 = 673b0104773SPascal Brand tee_mmu_kmap_pa2va((void *)tee_mm_get_smem(mm_param), &va); 674b0104773SPascal Brand if (res2 == TEE_SUCCESS) 675b0104773SPascal Brand tee_mmu_kunmap(va, tee_mm_get_bytes(mm_param)); 676b0104773SPascal Brand } 677b0104773SPascal Brand tee_mm_free(mm_param); 678b0104773SPascal Brand if (ret_orig) 679b0104773SPascal Brand tee_svc_copy_to_user(sess, ret_orig, &ret_o, sizeof(ret_o)); 680b0104773SPascal Brand return res; 681b0104773SPascal Brand } 682b0104773SPascal Brand 683453a5030SJerome Forissier TEE_Result syscall_check_access_rights(uint32_t flags, const void *buf, 684b0104773SPascal Brand size_t len) 685b0104773SPascal Brand { 686b0104773SPascal Brand TEE_Result res; 687b0104773SPascal Brand struct tee_ta_session *s; 688b0104773SPascal Brand 689b0104773SPascal Brand res = tee_ta_get_current_session(&s); 690b0104773SPascal Brand if (res != TEE_SUCCESS) 691b0104773SPascal Brand return res; 692b0104773SPascal Brand 693b0104773SPascal Brand return tee_mmu_check_access_rights(s->ctx, flags, (tee_uaddr_t)buf, 694b0104773SPascal Brand len); 695b0104773SPascal Brand } 696b0104773SPascal Brand 697b0104773SPascal Brand TEE_Result tee_svc_copy_from_user(struct tee_ta_session *sess, void *kaddr, 698b0104773SPascal Brand const void *uaddr, size_t len) 699b0104773SPascal Brand { 700b0104773SPascal Brand TEE_Result res; 701b0104773SPascal Brand struct tee_ta_session *s; 702b0104773SPascal Brand 703b0104773SPascal Brand if (sess == NULL) { 704b0104773SPascal Brand res = tee_ta_get_current_session(&s); 705b0104773SPascal Brand if (res != TEE_SUCCESS) 706b0104773SPascal Brand return res; 707b0104773SPascal Brand } else { 708b0104773SPascal Brand s = sess; 709b0104773SPascal Brand tee_ta_set_current_session(s); 710b0104773SPascal Brand } 711b0104773SPascal Brand res = 712b0104773SPascal Brand tee_mmu_check_access_rights(s->ctx, 713b0104773SPascal Brand TEE_MEMORY_ACCESS_READ | 714b0104773SPascal Brand TEE_MEMORY_ACCESS_ANY_OWNER, 715b0104773SPascal Brand (tee_uaddr_t)uaddr, len); 716b0104773SPascal Brand if (res != TEE_SUCCESS) 717b0104773SPascal Brand return res; 718b0104773SPascal Brand 719b0104773SPascal Brand memcpy(kaddr, uaddr, len); 720b0104773SPascal Brand return TEE_SUCCESS; 721b0104773SPascal Brand } 722b0104773SPascal Brand 723b0104773SPascal Brand TEE_Result tee_svc_copy_to_user(struct tee_ta_session *sess, void *uaddr, 724b0104773SPascal Brand const void *kaddr, size_t len) 725b0104773SPascal Brand { 726b0104773SPascal Brand TEE_Result res; 727b0104773SPascal Brand struct tee_ta_session *s; 728b0104773SPascal Brand 729b0104773SPascal Brand if (sess == NULL) { 730b0104773SPascal Brand res = tee_ta_get_current_session(&s); 731b0104773SPascal Brand if (res != TEE_SUCCESS) 732b0104773SPascal Brand return res; 733b0104773SPascal Brand } else { 734b0104773SPascal Brand s = sess; 735b0104773SPascal Brand tee_ta_set_current_session(s); 736b0104773SPascal Brand } 737b0104773SPascal Brand 738b0104773SPascal Brand res = 739b0104773SPascal Brand tee_mmu_check_access_rights(s->ctx, 740b0104773SPascal Brand TEE_MEMORY_ACCESS_WRITE | 741b0104773SPascal Brand TEE_MEMORY_ACCESS_ANY_OWNER, 742b0104773SPascal Brand (tee_uaddr_t)uaddr, len); 743b0104773SPascal Brand if (res != TEE_SUCCESS) 744b0104773SPascal Brand return res; 745b0104773SPascal Brand 746b0104773SPascal Brand memcpy(uaddr, kaddr, len); 747b0104773SPascal Brand return TEE_SUCCESS; 748b0104773SPascal Brand } 749b0104773SPascal Brand 7508707ec0fSJerome Forissier /* 7518707ec0fSJerome Forissier * Copy a kernel address into a 32-bit user buffer. In 64-bit mode, this will 7528707ec0fSJerome Forissier * fail if the address is not in the lower 4 GiB. 7538707ec0fSJerome Forissier */ 7548707ec0fSJerome Forissier TEE_Result tee_svc_copy_kaddr_to_user32(struct tee_ta_session *sess, 7558707ec0fSJerome Forissier uint32_t *uaddr, const void *kaddr) 7568707ec0fSJerome Forissier { 7578707ec0fSJerome Forissier uint32_t lo = (long)kaddr & 0xFFFFFFFF; 7588707ec0fSJerome Forissier 7598707ec0fSJerome Forissier if ((long)lo != (long)kaddr) { 7608707ec0fSJerome Forissier EMSG("Unexpected high kernel address\n"); 7618707ec0fSJerome Forissier return TEE_ERROR_GENERIC; 7628707ec0fSJerome Forissier } 7638707ec0fSJerome Forissier return tee_svc_copy_to_user(sess, uaddr, &lo, sizeof(lo)); 7648707ec0fSJerome Forissier } 7658707ec0fSJerome Forissier 766b0104773SPascal Brand static bool session_is_cancelled(struct tee_ta_session *s, TEE_Time *curr_time) 767b0104773SPascal Brand { 768b0104773SPascal Brand TEE_Time current_time; 769b0104773SPascal Brand 770b0104773SPascal Brand if (s->cancel_mask) 771b0104773SPascal Brand return false; 772b0104773SPascal Brand 773b0104773SPascal Brand if (s->cancel) 774b0104773SPascal Brand return true; 775b0104773SPascal Brand 776b0104773SPascal Brand if (s->cancel_time.seconds == UINT32_MAX) 777b0104773SPascal Brand return false; 778b0104773SPascal Brand 779b0104773SPascal Brand if (curr_time != NULL) 780b0104773SPascal Brand current_time = *curr_time; 781b0104773SPascal Brand else if (tee_time_get_sys_time(¤t_time) != TEE_SUCCESS) 782b0104773SPascal Brand return false; 783b0104773SPascal Brand 784b0104773SPascal Brand if (current_time.seconds > s->cancel_time.seconds || 785b0104773SPascal Brand (current_time.seconds == s->cancel_time.seconds && 786b0104773SPascal Brand current_time.millis >= s->cancel_time.millis)) { 787b0104773SPascal Brand return true; 788b0104773SPascal Brand } 789b0104773SPascal Brand 790b0104773SPascal Brand return false; 791b0104773SPascal Brand } 792b0104773SPascal Brand 793453a5030SJerome Forissier TEE_Result syscall_get_cancellation_flag(bool *cancel) 794b0104773SPascal Brand { 795b0104773SPascal Brand TEE_Result res; 796b0104773SPascal Brand struct tee_ta_session *s = NULL; 797b0104773SPascal Brand bool c; 798b0104773SPascal Brand 799b0104773SPascal Brand res = tee_ta_get_current_session(&s); 800b0104773SPascal Brand if (res != TEE_SUCCESS) 801b0104773SPascal Brand return res; 802b0104773SPascal Brand 803b0104773SPascal Brand c = session_is_cancelled(s, NULL); 804b0104773SPascal Brand 805b0104773SPascal Brand return tee_svc_copy_to_user(s, cancel, &c, sizeof(c)); 806b0104773SPascal Brand } 807b0104773SPascal Brand 808453a5030SJerome Forissier TEE_Result syscall_unmask_cancellation(bool *old_mask) 809b0104773SPascal Brand { 810b0104773SPascal Brand TEE_Result res; 811b0104773SPascal Brand struct tee_ta_session *s = NULL; 812b0104773SPascal Brand bool m; 813b0104773SPascal Brand 814b0104773SPascal Brand res = tee_ta_get_current_session(&s); 815b0104773SPascal Brand if (res != TEE_SUCCESS) 816b0104773SPascal Brand return res; 817b0104773SPascal Brand 818b0104773SPascal Brand m = s->cancel_mask; 819b0104773SPascal Brand s->cancel_mask = false; 820b0104773SPascal Brand return tee_svc_copy_to_user(s, old_mask, &m, sizeof(m)); 821b0104773SPascal Brand } 822b0104773SPascal Brand 823453a5030SJerome Forissier TEE_Result syscall_mask_cancellation(bool *old_mask) 824b0104773SPascal Brand { 825b0104773SPascal Brand TEE_Result res; 826b0104773SPascal Brand struct tee_ta_session *s = NULL; 827b0104773SPascal Brand bool m; 828b0104773SPascal Brand 829b0104773SPascal Brand res = tee_ta_get_current_session(&s); 830b0104773SPascal Brand if (res != TEE_SUCCESS) 831b0104773SPascal Brand return res; 832b0104773SPascal Brand 833b0104773SPascal Brand m = s->cancel_mask; 834b0104773SPascal Brand s->cancel_mask = true; 835b0104773SPascal Brand return tee_svc_copy_to_user(s, old_mask, &m, sizeof(m)); 836b0104773SPascal Brand } 837b0104773SPascal Brand 838453a5030SJerome Forissier TEE_Result syscall_wait(uint32_t timeout) 839b0104773SPascal Brand { 840b0104773SPascal Brand TEE_Result res = TEE_SUCCESS; 841b0104773SPascal Brand uint32_t mytime = 0; 842b0104773SPascal Brand struct tee_ta_session *s; 843b0104773SPascal Brand TEE_Time base_time; 844b0104773SPascal Brand TEE_Time current_time; 845b0104773SPascal Brand 846b0104773SPascal Brand res = tee_ta_get_current_session(&s); 847b0104773SPascal Brand if (res != TEE_SUCCESS) 848b0104773SPascal Brand return res; 849b0104773SPascal Brand 850b0104773SPascal Brand res = tee_time_get_sys_time(&base_time); 851b0104773SPascal Brand if (res != TEE_SUCCESS) 852b0104773SPascal Brand return res; 853b0104773SPascal Brand 854b0104773SPascal Brand while (true) { 855b0104773SPascal Brand res = tee_time_get_sys_time(¤t_time); 856b0104773SPascal Brand if (res != TEE_SUCCESS) 857b0104773SPascal Brand return res; 858b0104773SPascal Brand 859b0104773SPascal Brand if (session_is_cancelled(s, ¤t_time)) 860b0104773SPascal Brand return TEE_ERROR_CANCEL; 861b0104773SPascal Brand 862b0104773SPascal Brand mytime = (current_time.seconds - base_time.seconds) * 1000 + 863b0104773SPascal Brand (int)current_time.millis - (int)base_time.millis; 864b0104773SPascal Brand if (mytime >= timeout) 865b0104773SPascal Brand return TEE_SUCCESS; 866b0104773SPascal Brand 867d1aea08fSSY Chiu tee_time_wait(timeout - mytime); 868b0104773SPascal Brand } 869b0104773SPascal Brand 870b0104773SPascal Brand return res; 871b0104773SPascal Brand } 872b0104773SPascal Brand 873453a5030SJerome Forissier TEE_Result syscall_get_time(enum utee_time_category cat, TEE_Time *mytime) 874b0104773SPascal Brand { 875b0104773SPascal Brand TEE_Result res, res2; 876b0104773SPascal Brand struct tee_ta_session *s = NULL; 877b0104773SPascal Brand TEE_Time t; 878b0104773SPascal Brand 879b0104773SPascal Brand res = tee_ta_get_current_session(&s); 880b0104773SPascal Brand if (res != TEE_SUCCESS) 881b0104773SPascal Brand return res; 882b0104773SPascal Brand 883b0104773SPascal Brand switch (cat) { 884b0104773SPascal Brand case UTEE_TIME_CAT_SYSTEM: 885b0104773SPascal Brand res = tee_time_get_sys_time(&t); 886b0104773SPascal Brand break; 887b0104773SPascal Brand case UTEE_TIME_CAT_TA_PERSISTENT: 888bc420748SJens Wiklander res = tee_time_get_ta_time((const void *)&s->ctx->uuid, &t); 889b0104773SPascal Brand break; 890b0104773SPascal Brand case UTEE_TIME_CAT_REE: 891b0104773SPascal Brand res = tee_time_get_ree_time(&t); 892b0104773SPascal Brand break; 893b0104773SPascal Brand default: 894b0104773SPascal Brand res = TEE_ERROR_BAD_PARAMETERS; 895b0104773SPascal Brand break; 896b0104773SPascal Brand } 897b0104773SPascal Brand 898b0104773SPascal Brand if (res == TEE_SUCCESS || res == TEE_ERROR_OVERFLOW) { 899b0104773SPascal Brand res2 = tee_svc_copy_to_user(s, mytime, &t, sizeof(t)); 900b0104773SPascal Brand if (res2 != TEE_SUCCESS) 901b0104773SPascal Brand res = res2; 902b0104773SPascal Brand } 903b0104773SPascal Brand 904b0104773SPascal Brand return res; 905b0104773SPascal Brand } 906b0104773SPascal Brand 907453a5030SJerome Forissier TEE_Result syscall_set_ta_time(const TEE_Time *mytime) 908b0104773SPascal Brand { 909b0104773SPascal Brand TEE_Result res; 910b0104773SPascal Brand struct tee_ta_session *s = NULL; 911b0104773SPascal Brand TEE_Time t; 912b0104773SPascal Brand 913b0104773SPascal Brand res = tee_ta_get_current_session(&s); 914b0104773SPascal Brand if (res != TEE_SUCCESS) 915b0104773SPascal Brand return res; 916b0104773SPascal Brand 917b0104773SPascal Brand res = tee_svc_copy_from_user(s, &t, mytime, sizeof(t)); 918b0104773SPascal Brand if (res != TEE_SUCCESS) 919b0104773SPascal Brand return res; 920b0104773SPascal Brand 921bc420748SJens Wiklander return tee_time_set_ta_time((const void *)&s->ctx->uuid, &t); 922b0104773SPascal Brand } 923fa530828SPascal Brand 924fa530828SPascal Brand #ifdef CFG_CACHE_API 925453a5030SJerome Forissier TEE_Result syscall_cache_operation(void *va, size_t len, 926fa530828SPascal Brand enum utee_cache_operation op) 927fa530828SPascal Brand { 928fa530828SPascal Brand TEE_Result res; 929fa530828SPascal Brand struct tee_ta_session *s = NULL; 930fa530828SPascal Brand 931fa530828SPascal Brand res = tee_ta_get_current_session(&s); 932fa530828SPascal Brand if (res != TEE_SUCCESS) 933fa530828SPascal Brand return res; 934fa530828SPascal Brand 935fa530828SPascal Brand if ((s->ctx->flags & TA_FLAG_CACHE_MAINTENANCE) == 0) 936fa530828SPascal Brand return TEE_ERROR_NOT_SUPPORTED; 937fa530828SPascal Brand 938fa530828SPascal Brand return tee_uta_cache_operation(s, op, va, len); 939fa530828SPascal Brand } 940fa530828SPascal Brand #endif 941