1f7d7fcd9SEtienne Carriere // SPDX-License-Identifier: BSD-2-Clause 2f7d7fcd9SEtienne Carriere /* 3f7d7fcd9SEtienne Carriere * Copyright (c) 2018-2020, Linaro Limited 4f7d7fcd9SEtienne Carriere */ 5f7d7fcd9SEtienne Carriere 6f7d7fcd9SEtienne Carriere #include <pkcs11_ta.h> 7f7d7fcd9SEtienne Carriere #include <string.h> 8f7d7fcd9SEtienne Carriere #include <tee_internal_api.h> 9f7d7fcd9SEtienne Carriere #include <util.h> 10f7d7fcd9SEtienne Carriere 11f7d7fcd9SEtienne Carriere #include "pkcs11_helpers.h" 12f7d7fcd9SEtienne Carriere 13f7d7fcd9SEtienne Carriere static const char __maybe_unused unknown[] = "<unknown-identifier>"; 14f7d7fcd9SEtienne Carriere 15f7d7fcd9SEtienne Carriere struct any_id { 16f7d7fcd9SEtienne Carriere uint32_t id; 17f7d7fcd9SEtienne Carriere #if CFG_TEE_TA_LOG_LEVEL > 0 18f7d7fcd9SEtienne Carriere const char *string; 19f7d7fcd9SEtienne Carriere #endif 20f7d7fcd9SEtienne Carriere }; 21f7d7fcd9SEtienne Carriere 22f7d7fcd9SEtienne Carriere /* 23f7d7fcd9SEtienne Carriere * Macro PKCS11_ID() can be used to define cells in ID list arrays 24f7d7fcd9SEtienne Carriere * or ID/string conversion arrays. 25f7d7fcd9SEtienne Carriere */ 26f7d7fcd9SEtienne Carriere #if CFG_TEE_TA_LOG_LEVEL > 0 27f7d7fcd9SEtienne Carriere #define PKCS11_ID(_id) { .id = _id, .string = #_id } 28f7d7fcd9SEtienne Carriere #else 29f7d7fcd9SEtienne Carriere #define PKCS11_ID(_id) { .id = _id } 30f7d7fcd9SEtienne Carriere #endif 31f7d7fcd9SEtienne Carriere 32f7d7fcd9SEtienne Carriere #define ID2STR(id, table, prefix) \ 33f7d7fcd9SEtienne Carriere id2str(id, table, ARRAY_SIZE(table), prefix) 34f7d7fcd9SEtienne Carriere 3560290f69SEtienne Carriere #if CFG_TEE_TA_LOG_LEVEL > 0 36f7d7fcd9SEtienne Carriere /* Convert a PKCS11 ID into its label string */ 3760290f69SEtienne Carriere static const char *id2str(uint32_t id, const struct any_id *table, 38f7d7fcd9SEtienne Carriere size_t count, const char *prefix) 39f7d7fcd9SEtienne Carriere { 40f7d7fcd9SEtienne Carriere size_t n = 0; 41f7d7fcd9SEtienne Carriere const char *str = NULL; 42f7d7fcd9SEtienne Carriere 43f7d7fcd9SEtienne Carriere for (n = 0; n < count; n++) { 44f7d7fcd9SEtienne Carriere if (id != table[n].id) 45f7d7fcd9SEtienne Carriere continue; 46f7d7fcd9SEtienne Carriere 47f7d7fcd9SEtienne Carriere str = table[n].string; 48f7d7fcd9SEtienne Carriere 49f7d7fcd9SEtienne Carriere /* Skip prefix provided matches found */ 50f7d7fcd9SEtienne Carriere if (prefix && !TEE_MemCompare(str, prefix, strlen(prefix))) 51f7d7fcd9SEtienne Carriere str += strlen(prefix); 52f7d7fcd9SEtienne Carriere 53f7d7fcd9SEtienne Carriere return str; 54f7d7fcd9SEtienne Carriere } 55f7d7fcd9SEtienne Carriere 56f7d7fcd9SEtienne Carriere return unknown; 57f7d7fcd9SEtienne Carriere } 5860290f69SEtienne Carriere #endif /* CFG_TEE_TA_LOG_LEVEL > 0 */ 59f7d7fcd9SEtienne Carriere 60f7d7fcd9SEtienne Carriere /* 61f7d7fcd9SEtienne Carriere * TA command IDs: used only as ID/string conversion for debug trace support 62f7d7fcd9SEtienne Carriere */ 63f7d7fcd9SEtienne Carriere static const struct any_id __maybe_unused string_ta_cmd[] = { 64f7d7fcd9SEtienne Carriere PKCS11_ID(PKCS11_CMD_PING), 65a67dc424SEtienne Carriere PKCS11_ID(PKCS11_CMD_SLOT_LIST), 66a67dc424SEtienne Carriere PKCS11_ID(PKCS11_CMD_SLOT_INFO), 67a67dc424SEtienne Carriere PKCS11_ID(PKCS11_CMD_TOKEN_INFO), 68d21ec5f4SEtienne Carriere PKCS11_ID(PKCS11_CMD_MECHANISM_IDS), 69d21ec5f4SEtienne Carriere PKCS11_ID(PKCS11_CMD_MECHANISM_INFO), 70d21ec5f4SEtienne Carriere PKCS11_ID(PKCS11_CMD_OPEN_SESSION), 71d21ec5f4SEtienne Carriere PKCS11_ID(PKCS11_CMD_SESSION_INFO), 72d21ec5f4SEtienne Carriere PKCS11_ID(PKCS11_CMD_CLOSE_SESSION), 73d21ec5f4SEtienne Carriere PKCS11_ID(PKCS11_CMD_CLOSE_ALL_SESSIONS), 74a67dc424SEtienne Carriere }; 75a67dc424SEtienne Carriere 76a67dc424SEtienne Carriere static const struct any_id __maybe_unused string_slot_flags[] = { 77a67dc424SEtienne Carriere PKCS11_ID(PKCS11_CKFS_TOKEN_PRESENT), 78a67dc424SEtienne Carriere PKCS11_ID(PKCS11_CKFS_REMOVABLE_DEVICE), 79a67dc424SEtienne Carriere PKCS11_ID(PKCS11_CKFS_HW_SLOT), 80a67dc424SEtienne Carriere }; 81a67dc424SEtienne Carriere 82a67dc424SEtienne Carriere static const struct any_id __maybe_unused string_token_flags[] = { 83a67dc424SEtienne Carriere PKCS11_ID(PKCS11_CKFT_RNG), 84a67dc424SEtienne Carriere PKCS11_ID(PKCS11_CKFT_WRITE_PROTECTED), 85a67dc424SEtienne Carriere PKCS11_ID(PKCS11_CKFT_LOGIN_REQUIRED), 86a67dc424SEtienne Carriere PKCS11_ID(PKCS11_CKFT_USER_PIN_INITIALIZED), 87a67dc424SEtienne Carriere PKCS11_ID(PKCS11_CKFT_RESTORE_KEY_NOT_NEEDED), 88a67dc424SEtienne Carriere PKCS11_ID(PKCS11_CKFT_CLOCK_ON_TOKEN), 89a67dc424SEtienne Carriere PKCS11_ID(PKCS11_CKFT_PROTECTED_AUTHENTICATION_PATH), 90a67dc424SEtienne Carriere PKCS11_ID(PKCS11_CKFT_DUAL_CRYPTO_OPERATIONS), 91a67dc424SEtienne Carriere PKCS11_ID(PKCS11_CKFT_TOKEN_INITIALIZED), 92a67dc424SEtienne Carriere PKCS11_ID(PKCS11_CKFT_USER_PIN_COUNT_LOW), 93a67dc424SEtienne Carriere PKCS11_ID(PKCS11_CKFT_USER_PIN_FINAL_TRY), 94a67dc424SEtienne Carriere PKCS11_ID(PKCS11_CKFT_USER_PIN_LOCKED), 95a67dc424SEtienne Carriere PKCS11_ID(PKCS11_CKFT_USER_PIN_TO_BE_CHANGED), 96a67dc424SEtienne Carriere PKCS11_ID(PKCS11_CKFT_SO_PIN_COUNT_LOW), 97a67dc424SEtienne Carriere PKCS11_ID(PKCS11_CKFT_SO_PIN_FINAL_TRY), 98a67dc424SEtienne Carriere PKCS11_ID(PKCS11_CKFT_SO_PIN_LOCKED), 99a67dc424SEtienne Carriere PKCS11_ID(PKCS11_CKFT_SO_PIN_TO_BE_CHANGED), 100a67dc424SEtienne Carriere PKCS11_ID(PKCS11_CKFT_ERROR_STATE), 101f7d7fcd9SEtienne Carriere }; 102f7d7fcd9SEtienne Carriere 103d21ec5f4SEtienne Carriere static const struct any_id __maybe_unused string_session_flags[] = { 104d21ec5f4SEtienne Carriere PKCS11_ID(PKCS11_CKFSS_RW_SESSION), 105d21ec5f4SEtienne Carriere PKCS11_ID(PKCS11_CKFSS_SERIAL_SESSION), 106d21ec5f4SEtienne Carriere }; 107d21ec5f4SEtienne Carriere 108d21ec5f4SEtienne Carriere static const struct any_id __maybe_unused string_session_state[] = { 109d21ec5f4SEtienne Carriere PKCS11_ID(PKCS11_CKS_RO_PUBLIC_SESSION), 110d21ec5f4SEtienne Carriere PKCS11_ID(PKCS11_CKS_RO_USER_FUNCTIONS), 111d21ec5f4SEtienne Carriere PKCS11_ID(PKCS11_CKS_RW_PUBLIC_SESSION), 112d21ec5f4SEtienne Carriere PKCS11_ID(PKCS11_CKS_RW_USER_FUNCTIONS), 113d21ec5f4SEtienne Carriere PKCS11_ID(PKCS11_CKS_RW_SO_FUNCTIONS), 114d21ec5f4SEtienne Carriere }; 115d21ec5f4SEtienne Carriere 116d34f3266SEtienne Carriere static const struct any_id __maybe_unused string_rc[] = { 117d34f3266SEtienne Carriere PKCS11_ID(PKCS11_CKR_OK), 118d34f3266SEtienne Carriere PKCS11_ID(PKCS11_CKR_GENERAL_ERROR), 119d34f3266SEtienne Carriere PKCS11_ID(PKCS11_CKR_DEVICE_MEMORY), 120d34f3266SEtienne Carriere PKCS11_ID(PKCS11_CKR_ARGUMENTS_BAD), 121d34f3266SEtienne Carriere PKCS11_ID(PKCS11_CKR_BUFFER_TOO_SMALL), 122d34f3266SEtienne Carriere PKCS11_ID(PKCS11_CKR_FUNCTION_FAILED), 123d34f3266SEtienne Carriere PKCS11_ID(PKCS11_CKR_SIGNATURE_INVALID), 124d34f3266SEtienne Carriere PKCS11_ID(PKCS11_CKR_ATTRIBUTE_TYPE_INVALID), 125d34f3266SEtienne Carriere PKCS11_ID(PKCS11_CKR_ATTRIBUTE_VALUE_INVALID), 126d34f3266SEtienne Carriere PKCS11_ID(PKCS11_CKR_OBJECT_HANDLE_INVALID), 127d34f3266SEtienne Carriere PKCS11_ID(PKCS11_CKR_KEY_HANDLE_INVALID), 128d34f3266SEtienne Carriere PKCS11_ID(PKCS11_CKR_MECHANISM_INVALID), 129d34f3266SEtienne Carriere PKCS11_ID(PKCS11_CKR_SESSION_HANDLE_INVALID), 130d34f3266SEtienne Carriere PKCS11_ID(PKCS11_CKR_SLOT_ID_INVALID), 131d34f3266SEtienne Carriere PKCS11_ID(PKCS11_CKR_MECHANISM_PARAM_INVALID), 132d34f3266SEtienne Carriere PKCS11_ID(PKCS11_CKR_TEMPLATE_INCONSISTENT), 133d34f3266SEtienne Carriere PKCS11_ID(PKCS11_CKR_TEMPLATE_INCOMPLETE), 134d34f3266SEtienne Carriere PKCS11_ID(PKCS11_CKR_PIN_INCORRECT), 135d34f3266SEtienne Carriere PKCS11_ID(PKCS11_CKR_PIN_LOCKED), 136d34f3266SEtienne Carriere PKCS11_ID(PKCS11_CKR_PIN_EXPIRED), 137d34f3266SEtienne Carriere PKCS11_ID(PKCS11_CKR_PIN_INVALID), 138d34f3266SEtienne Carriere PKCS11_ID(PKCS11_CKR_PIN_LEN_RANGE), 139d34f3266SEtienne Carriere PKCS11_ID(PKCS11_CKR_SESSION_EXISTS), 140d34f3266SEtienne Carriere PKCS11_ID(PKCS11_CKR_SESSION_READ_ONLY), 141d34f3266SEtienne Carriere PKCS11_ID(PKCS11_CKR_SESSION_READ_WRITE_SO_EXISTS), 142d34f3266SEtienne Carriere PKCS11_ID(PKCS11_CKR_OPERATION_ACTIVE), 143d34f3266SEtienne Carriere PKCS11_ID(PKCS11_CKR_KEY_FUNCTION_NOT_PERMITTED), 144d34f3266SEtienne Carriere PKCS11_ID(PKCS11_CKR_OPERATION_NOT_INITIALIZED), 145d34f3266SEtienne Carriere PKCS11_ID(PKCS11_CKR_TOKEN_WRITE_PROTECTED), 146d34f3266SEtienne Carriere PKCS11_ID(PKCS11_CKR_TOKEN_NOT_PRESENT), 147d34f3266SEtienne Carriere PKCS11_ID(PKCS11_CKR_TOKEN_NOT_RECOGNIZED), 148d34f3266SEtienne Carriere PKCS11_ID(PKCS11_CKR_ACTION_PROHIBITED), 149d34f3266SEtienne Carriere PKCS11_ID(PKCS11_CKR_ATTRIBUTE_READ_ONLY), 150d34f3266SEtienne Carriere PKCS11_ID(PKCS11_CKR_PIN_TOO_WEAK), 151d34f3266SEtienne Carriere PKCS11_ID(PKCS11_CKR_CURVE_NOT_SUPPORTED), 152d34f3266SEtienne Carriere PKCS11_ID(PKCS11_CKR_DOMAIN_PARAMS_INVALID), 153d34f3266SEtienne Carriere PKCS11_ID(PKCS11_CKR_USER_ALREADY_LOGGED_IN), 154d34f3266SEtienne Carriere PKCS11_ID(PKCS11_CKR_USER_ANOTHER_ALREADY_LOGGED_IN), 155d34f3266SEtienne Carriere PKCS11_ID(PKCS11_CKR_USER_NOT_LOGGED_IN), 156d34f3266SEtienne Carriere PKCS11_ID(PKCS11_CKR_USER_PIN_NOT_INITIALIZED), 157d34f3266SEtienne Carriere PKCS11_ID(PKCS11_CKR_USER_TOO_MANY_TYPES), 158d34f3266SEtienne Carriere PKCS11_ID(PKCS11_CKR_USER_TYPE_INVALID), 159d34f3266SEtienne Carriere PKCS11_ID(PKCS11_CKR_SESSION_READ_ONLY_EXISTS), 160d34f3266SEtienne Carriere PKCS11_ID(PKCS11_RV_NOT_FOUND), 161d34f3266SEtienne Carriere PKCS11_ID(PKCS11_RV_NOT_IMPLEMENTED), 162d34f3266SEtienne Carriere }; 163d34f3266SEtienne Carriere 164*8e03579eSJens Wiklander /* 165*8e03579eSJens Wiklander * Conversion between PKCS11 TA and GPD TEE return codes 166*8e03579eSJens Wiklander */ 167*8e03579eSJens Wiklander enum pkcs11_rc tee2pkcs_error(TEE_Result res) 168*8e03579eSJens Wiklander { 169*8e03579eSJens Wiklander switch (res) { 170*8e03579eSJens Wiklander case TEE_SUCCESS: 171*8e03579eSJens Wiklander return PKCS11_CKR_OK; 172*8e03579eSJens Wiklander 173*8e03579eSJens Wiklander case TEE_ERROR_BAD_PARAMETERS: 174*8e03579eSJens Wiklander return PKCS11_CKR_ARGUMENTS_BAD; 175*8e03579eSJens Wiklander 176*8e03579eSJens Wiklander case TEE_ERROR_OUT_OF_MEMORY: 177*8e03579eSJens Wiklander return PKCS11_CKR_DEVICE_MEMORY; 178*8e03579eSJens Wiklander 179*8e03579eSJens Wiklander case TEE_ERROR_SHORT_BUFFER: 180*8e03579eSJens Wiklander return PKCS11_CKR_BUFFER_TOO_SMALL; 181*8e03579eSJens Wiklander 182*8e03579eSJens Wiklander case TEE_ERROR_MAC_INVALID: 183*8e03579eSJens Wiklander case TEE_ERROR_SIGNATURE_INVALID: 184*8e03579eSJens Wiklander return PKCS11_CKR_SIGNATURE_INVALID; 185*8e03579eSJens Wiklander 186*8e03579eSJens Wiklander default: 187*8e03579eSJens Wiklander return PKCS11_CKR_GENERAL_ERROR; 188*8e03579eSJens Wiklander } 189*8e03579eSJens Wiklander } 190*8e03579eSJens Wiklander 191f7d7fcd9SEtienne Carriere #if CFG_TEE_TA_LOG_LEVEL > 0 192d34f3266SEtienne Carriere const char *id2str_rc(uint32_t id) 193d34f3266SEtienne Carriere { 194d34f3266SEtienne Carriere return ID2STR(id, string_rc, "PKCS11_CKR_"); 195d34f3266SEtienne Carriere } 196d34f3266SEtienne Carriere 197f7d7fcd9SEtienne Carriere const char *id2str_ta_cmd(uint32_t id) 198f7d7fcd9SEtienne Carriere { 199f7d7fcd9SEtienne Carriere return ID2STR(id, string_ta_cmd, NULL); 200f7d7fcd9SEtienne Carriere } 201a67dc424SEtienne Carriere 202a67dc424SEtienne Carriere const char *id2str_slot_flag(uint32_t id) 203a67dc424SEtienne Carriere { 204a67dc424SEtienne Carriere return ID2STR(id, string_slot_flags, "PKCS11_CKFS_"); 205a67dc424SEtienne Carriere } 206a67dc424SEtienne Carriere 207a67dc424SEtienne Carriere const char *id2str_token_flag(uint32_t id) 208a67dc424SEtienne Carriere { 209a67dc424SEtienne Carriere return ID2STR(id, string_token_flags, "PKCS11_CKFT_"); 210a67dc424SEtienne Carriere } 211d21ec5f4SEtienne Carriere 212d21ec5f4SEtienne Carriere const char *id2str_session_flag(uint32_t id) 213d21ec5f4SEtienne Carriere { 214d21ec5f4SEtienne Carriere return ID2STR(id, string_session_flags, "PKCS11_CKFSS_"); 215d21ec5f4SEtienne Carriere } 216d21ec5f4SEtienne Carriere 217d21ec5f4SEtienne Carriere const char *id2str_session_state(uint32_t id) 218d21ec5f4SEtienne Carriere { 219d21ec5f4SEtienne Carriere return ID2STR(id, string_session_state, "PKCS11_CKS_"); 220d21ec5f4SEtienne Carriere } 221f7d7fcd9SEtienne Carriere #endif /*CFG_TEE_TA_LOG_LEVEL*/ 222