11bb92983SJerome Forissier /* SPDX-License-Identifier: BSD-2-Clause */ 2b0104773SPascal Brand /* 3b0104773SPascal Brand * Copyright (c) 2014, STMicroelectronics International N.V. 4387b0ee3SEtienne Carriere * Copyright (c) 2018, Linaro Limited. 5b0104773SPascal Brand */ 6b0104773SPascal Brand 7b0104773SPascal Brand #ifndef USER_TA_HEADER_H 8b0104773SPascal Brand #define USER_TA_HEADER_H 9b0104773SPascal Brand 10b0104773SPascal Brand #include <tee_api_types.h> 11387b0ee3SEtienne Carriere #include <util.h> 12b0104773SPascal Brand 13138c5102SJens Wiklander #define TA_FLAG_USER_MODE 0 /* Deprecated, was BIT32(0) */ 14138c5102SJens Wiklander #define TA_FLAG_EXEC_DDR 0 /* Deprecated, was BIT32(1) */ 15138c5102SJens Wiklander #define TA_FLAG_SINGLE_INSTANCE BIT32(2) 16138c5102SJens Wiklander #define TA_FLAG_MULTI_SESSION BIT32(3) 17138c5102SJens Wiklander #define TA_FLAG_INSTANCE_KEEP_ALIVE BIT32(4) /* remains after last close */ 18138c5102SJens Wiklander #define TA_FLAG_SECURE_DATA_PATH BIT32(5) /* accesses SDP memory */ 19138c5102SJens Wiklander #define TA_FLAG_REMAP_SUPPORT 0 /* Deprecated, was BIT32(6) */ 20138c5102SJens Wiklander #define TA_FLAG_CACHE_MAINTENANCE BIT32(7) /* use cache flush syscall */ 21c7c4b6e3SJens Wiklander /* 22c7c4b6e3SJens Wiklander * TA instance can execute multiple sessions concurrently 23c7c4b6e3SJens Wiklander * (pseudo-TAs only). 24c7c4b6e3SJens Wiklander */ 25138c5102SJens Wiklander #define TA_FLAG_CONCURRENT BIT32(8) 26bc5921cdSMaxim Uvarov /* 27a96033caSJens Wiklander * Device enumeration is initiated at multiple stages by the normal 28a96033caSJens Wiklander * world: 29a96033caSJens Wiklander * 1. First when the kernel driver has initialized 30a96033caSJens Wiklander * 2. When RPMB is available via inkernel RPMB routing 31a96033caSJens Wiklander * 3. When the tee-supplicant is started 32a96033caSJens Wiklander * 33a96033caSJens Wiklander * The flags below control at which stage a TA will be enumerated: 34a96033caSJens Wiklander * TA_FLAG_DEVICE_ENUM - at stage 1 35a96033caSJens Wiklander * TA_FLAG_DEVICE_ENUM_TEE_STORAGE_PRIVATE - 36a96033caSJens Wiklander * when secure storage is available, at stage 2 or 3 depending 37a96033caSJens Wiklander * on whether TEE_STORAGE_PRIVATE is using RPMB FS 38a96033caSJens Wiklander * (CFG_REE_FS=n CFG_RPMB_FS=y) or REE FS (CFG_REE_FS=y). The 39a96033caSJens Wiklander * former utilizes in kernel RPMB routing, and the latter 40a96033caSJens Wiklander * depends on tee-supplicant to access secure storage. 41a96033caSJens Wiklander * TA_FLAG_DEVICE_ENUM_SUPP - at stage 3 42a96033caSJens Wiklander * 43a96033caSJens Wiklander * The TA is enumerated at stage 2 if 44a96033caSJens Wiklander * TA_FLAG_DEVICE_ENUM_TEE_STORAGE_PRIVATE is set and 45a96033caSJens Wiklander * TEE_STORAGE_PRIVATE is using RPMB FS, or if it's using REE FS it 46a96033caSJens Wiklander * will be enumerated at stage 3. 47bc5921cdSMaxim Uvarov */ 48138c5102SJens Wiklander #define TA_FLAG_DEVICE_ENUM BIT32(9) /* without tee-supplicant */ 49138c5102SJens Wiklander #define TA_FLAG_DEVICE_ENUM_SUPP BIT32(10) /* with tee-supplicant */ 50138c5102SJens Wiklander /* See also "gpd.ta.doesNotCloseHandleOnCorruptObject" */ 51138c5102SJens Wiklander #define TA_FLAG_DONT_CLOSE_HANDLE_ON_CORRUPT_OBJECT \ 52138c5102SJens Wiklander BIT32(11) 53a96033caSJens Wiklander #define TA_FLAG_DEVICE_ENUM_TEE_STORAGE_PRIVATE \ 54a96033caSJens Wiklander BIT32(12) /* with TEE_STORAGE_PRIVATE */ 55*941a58d7SJens Wiklander /* 56*941a58d7SJens Wiklander * Don't restart a TA with TA_FLAG_INSTANCE_KEEP_ALIVE set if it has 57*941a58d7SJens Wiklander * crashed. 58*941a58d7SJens Wiklander */ 59*941a58d7SJens Wiklander #define TA_FLAG_INSTANCE_KEEP_CRASHED BIT32(13) 6055d3ebe9SPascal Brand 61*941a58d7SJens Wiklander #define TA_FLAGS_MASK GENMASK_32(13, 0) 62387b0ee3SEtienne Carriere 63bc420748SJens Wiklander struct ta_head { 64bc420748SJens Wiklander TEE_UUID uuid; 65bc420748SJens Wiklander uint32_t stack_size; 66bc420748SJens Wiklander uint32_t flags; 67a73b5878SJens Wiklander uint64_t depr_entry; 68bc420748SJens Wiklander }; 69bc420748SJens Wiklander 70099918f6SSumit Garg #if defined(CFG_FTRACE_SUPPORT) 71b02ae382SSumit Garg #define FTRACE_RETFUNC_DEPTH 50 72c96d7091SSumit Garg union compat_ptr { 73c96d7091SSumit Garg uint64_t ptr64; 74c96d7091SSumit Garg struct { 75c96d7091SSumit Garg uint32_t lo; 76c96d7091SSumit Garg uint32_t hi; 77c96d7091SSumit Garg } ptr32; 78c96d7091SSumit Garg }; 79c96d7091SSumit Garg 80b02ae382SSumit Garg struct __ftrace_info { 81c96d7091SSumit Garg union compat_ptr buf_start; 82c96d7091SSumit Garg union compat_ptr buf_end; 83c96d7091SSumit Garg union compat_ptr ret_ptr; 84b02ae382SSumit Garg }; 85b02ae382SSumit Garg 86b02ae382SSumit Garg struct ftrace_buf { 87b02ae382SSumit Garg uint64_t ret_func_ptr; /* __ftrace_return pointer */ 88b02ae382SSumit Garg uint64_t ret_stack[FTRACE_RETFUNC_DEPTH]; /* Return stack */ 89b02ae382SSumit Garg uint32_t ret_idx; /* Return stack index */ 90b02ae382SSumit Garg uint32_t lr_idx; /* lr index used for stack unwinding */ 91f5df167cSSumit Garg uint64_t begin_time[FTRACE_RETFUNC_DEPTH]; /* Timestamp */ 92f5df167cSSumit Garg uint64_t suspend_time; /* Suspend timestamp */ 935c2c0fb3SJerome Forissier uint32_t curr_idx; /* Current entry in the (circular) buffer */ 94b02ae382SSumit Garg uint32_t max_size; /* Max allowed size of ftrace buffer */ 95b02ae382SSumit Garg uint32_t head_off; /* Ftrace buffer header offset */ 96b02ae382SSumit Garg uint32_t buf_off; /* Ftrace buffer offset */ 97099918f6SSumit Garg bool syscall_trace_enabled; /* Some syscalls are never traced */ 98099918f6SSumit Garg bool syscall_trace_suspended; /* By foreign interrupt or RPC */ 995c2c0fb3SJerome Forissier bool overflow; /* Circular buffer has wrapped */ 100b02ae382SSumit Garg }; 101b02ae382SSumit Garg 102b02ae382SSumit Garg /* Defined by the linker script */ 103b02ae382SSumit Garg extern struct ftrace_buf __ftrace_buf_start; 104b02ae382SSumit Garg extern uint8_t __ftrace_buf_end[]; 105b02ae382SSumit Garg 106b02ae382SSumit Garg unsigned long ftrace_return(void); 107b02ae382SSumit Garg void __ftrace_return(void); 108b02ae382SSumit Garg #endif 109b02ae382SSumit Garg 110dd655cb9SJerome Forissier void __utee_call_elf_init_fn(void); 111dd655cb9SJerome Forissier void __utee_call_elf_fini_fn(void); 112dd655cb9SJerome Forissier 1139d224046SJerome Forissier void __utee_tcb_init(void); 1149d224046SJerome Forissier 1159d224046SJerome Forissier /* 1169d224046SJerome Forissier * Information about the ELF objects loaded by the application 1179d224046SJerome Forissier */ 1189d224046SJerome Forissier 1199d224046SJerome Forissier struct __elf_phdr_info { 1209d224046SJerome Forissier uint32_t reserved; 1219d224046SJerome Forissier uint16_t count; 1229d224046SJerome Forissier uint8_t reserved2; 1239d224046SJerome Forissier char zero; 1249d224046SJerome Forissier struct dl_phdr_info *dlpi; /* @count entries */ 1259d224046SJerome Forissier }; 1269d224046SJerome Forissier 1279d224046SJerome Forissier /* 32-bit variant for a 64-bit ldelf to access a 32-bit TA */ 1289d224046SJerome Forissier struct __elf_phdr_info32 { 1299d224046SJerome Forissier uint32_t reserved; 1309d224046SJerome Forissier uint16_t count; 1319d224046SJerome Forissier uint8_t reserved2; 1329d224046SJerome Forissier char zero; 1339d224046SJerome Forissier uint32_t dlpi; 1349d224046SJerome Forissier }; 1359d224046SJerome Forissier 1369d224046SJerome Forissier extern struct __elf_phdr_info __elf_phdr_info; 1379d224046SJerome Forissier 13855d3ebe9SPascal Brand #define TA_PROP_STR_SINGLE_INSTANCE "gpd.ta.singleInstance" 13955d3ebe9SPascal Brand #define TA_PROP_STR_MULTI_SESSION "gpd.ta.multiSession" 14055d3ebe9SPascal Brand #define TA_PROP_STR_KEEP_ALIVE "gpd.ta.instanceKeepAlive" 141*941a58d7SJens Wiklander #define TA_PROP_STR_KEEP_CRASHED "optee.ta.instanceKeepCrashed" 14255d3ebe9SPascal Brand #define TA_PROP_STR_DATA_SIZE "gpd.ta.dataSize" 14355d3ebe9SPascal Brand #define TA_PROP_STR_STACK_SIZE "gpd.ta.stackSize" 144d71d2857SCedric Chaumont #define TA_PROP_STR_VERSION "gpd.ta.version" 145d71d2857SCedric Chaumont #define TA_PROP_STR_DESCRIPTION "gpd.ta.description" 146d3efff0bSJens Wiklander #define TA_PROP_STR_ENDIAN "gpd.ta.endian" 147138c5102SJens Wiklander #define TA_PROP_STR_DOES_NOT_CLOSE_HANDLE_ON_CORRUPT_OBJECT \ 148138c5102SJens Wiklander "gpd.ta.doesNotCloseHandleOnCorruptObject" 149b0104773SPascal Brand 150b0104773SPascal Brand enum user_ta_prop_type { 151b0104773SPascal Brand USER_TA_PROP_TYPE_BOOL, /* bool */ 152b0104773SPascal Brand USER_TA_PROP_TYPE_U32, /* uint32_t */ 153b0104773SPascal Brand USER_TA_PROP_TYPE_UUID, /* TEE_UUID */ 154b0104773SPascal Brand USER_TA_PROP_TYPE_IDENTITY, /* TEE_Identity */ 155b0104773SPascal Brand USER_TA_PROP_TYPE_STRING, /* zero terminated string of char */ 156b0104773SPascal Brand USER_TA_PROP_TYPE_BINARY_BLOCK, /* zero terminated base64 coded string */ 1576551d565SJens Wiklander USER_TA_PROP_TYPE_U64, /* uint64_t */ 158a1f2c430SClement Faure USER_TA_PROP_TYPE_INVALID, /* invalid value */ 159b0104773SPascal Brand }; 160b0104773SPascal Brand 161b0104773SPascal Brand struct user_ta_property { 162b0104773SPascal Brand const char *name; 163b0104773SPascal Brand enum user_ta_prop_type type; 164b0104773SPascal Brand const void *value; 165b0104773SPascal Brand }; 166b0104773SPascal Brand 167b0104773SPascal Brand extern const struct user_ta_property ta_props[]; 168b0104773SPascal Brand extern const size_t ta_num_props; 169b0104773SPascal Brand 170e64b7b2eSJens Wiklander extern uint8_t __ta_no_share_heap[]; 171e64b7b2eSJens Wiklander extern const size_t __ta_no_share_heap_size; 172b0104773SPascal Brand /* Needed by TEE_CheckMemoryAccessRights() */ 173b0104773SPascal Brand extern uint32_t ta_param_types; 17468540524SIgor Opaniuk extern TEE_Param ta_params[TEE_NUM_PARAMS]; 175e64b7b2eSJens Wiklander extern struct malloc_ctx *__ta_no_share_malloc_ctx; 176b0104773SPascal Brand 177b0104773SPascal Brand int tahead_get_trace_level(void); 178b0104773SPascal Brand 179b0104773SPascal Brand #endif /* USER_TA_HEADER_H */ 180