xref: /rk3399_ARM-atf/include/services/rmmd_svc.h (revision f801fdc22ef4fce3cc24fd1cbccde5772c15b633)
177c27753SZelalem Aweke /*
2*f801fdc2STushar Khandelwal  * Copyright (c) 2021-2025, Arm Limited and Contributors. All rights reserved.
377c27753SZelalem Aweke  *
477c27753SZelalem Aweke  * SPDX-License-Identifier: BSD-3-Clause
577c27753SZelalem Aweke  */
677c27753SZelalem Aweke 
777c27753SZelalem Aweke #ifndef RMMD_SVC_H
877c27753SZelalem Aweke #define RMMD_SVC_H
977c27753SZelalem Aweke 
10e9529e46SRaghu Krishnamurthy #include <common/sha_common_macros.h>
11319fb084SSoby Mathew #include <lib/smccc.h>
12319fb084SSoby Mathew #include <lib/utils_def.h>
13319fb084SSoby Mathew 
14fb00dc4aSSubhasish Ghosh /* STD calls FNUM Min/Max ranges */
15319fb084SSoby Mathew #define RMI_FNUM_MIN_VALUE	U(0x150)
16319fb084SSoby Mathew #define RMI_FNUM_MAX_VALUE	U(0x18F)
17319fb084SSoby Mathew 
18fb00dc4aSSubhasish Ghosh /* Construct RMI fastcall std FID from offset */
19fb00dc4aSSubhasish Ghosh #define SMC64_RMI_FID(_offset)					  \
20fb00dc4aSSubhasish Ghosh 	((SMC_TYPE_FAST << FUNCID_TYPE_SHIFT)			| \
21fb00dc4aSSubhasish Ghosh 	 (SMC_64 << FUNCID_CC_SHIFT)				| \
22fb00dc4aSSubhasish Ghosh 	 (OEN_STD_START << FUNCID_OEN_SHIFT)			| \
23fb00dc4aSSubhasish Ghosh 	 (((RMI_FNUM_MIN_VALUE + (_offset)) & FUNCID_NUM_MASK)	  \
24fb00dc4aSSubhasish Ghosh 	  << FUNCID_NUM_SHIFT))
25fb00dc4aSSubhasish Ghosh 
26319fb084SSoby Mathew #define is_rmi_fid(fid) __extension__ ({		\
27319fb084SSoby Mathew 	__typeof__(fid) _fid = (fid);			\
28319fb084SSoby Mathew 	((GET_SMC_NUM(_fid) >= RMI_FNUM_MIN_VALUE) &&	\
29319fb084SSoby Mathew 	 (GET_SMC_NUM(_fid) <= RMI_FNUM_MAX_VALUE) &&	\
30319fb084SSoby Mathew 	 (GET_SMC_TYPE(_fid) == SMC_TYPE_FAST)	   &&	\
31319fb084SSoby Mathew 	 (GET_SMC_CC(_fid) == SMC_64)              &&	\
32319fb084SSoby Mathew 	 (GET_SMC_OEN(_fid) == OEN_STD_START)      &&	\
33319fb084SSoby Mathew 	 ((_fid & 0x00FE0000) == 0U)); })
34319fb084SSoby Mathew 
35319fb084SSoby Mathew /*
36fb00dc4aSSubhasish Ghosh  * RMI_FNUM_REQ_COMPLETE is the only function in the RMI range that originates
37319fb084SSoby Mathew  * from the Realm world and is handled by the RMMD. The RMI functions are
38319fb084SSoby Mathew  * always invoked by the Normal world, forwarded by RMMD and handled by the
39fb00dc4aSSubhasish Ghosh  * RMM.
40319fb084SSoby Mathew  */
41fb00dc4aSSubhasish Ghosh 					/* 0x18F */
42e50fedbcSJavier Almansa Sobrino #define RMM_RMI_REQ_COMPLETE		SMC64_RMI_FID(U(0x3F))
43319fb084SSoby Mathew 
448c980a4aSJavier Almansa Sobrino /* RMM_BOOT_COMPLETE arg0 error codes */
458c980a4aSJavier Almansa Sobrino #define E_RMM_BOOT_SUCCESS				(0)
468c980a4aSJavier Almansa Sobrino #define E_RMM_BOOT_UNKNOWN				(-1)
478c980a4aSJavier Almansa Sobrino #define E_RMM_BOOT_VERSION_MISMATCH			(-2)
488c980a4aSJavier Almansa Sobrino #define E_RMM_BOOT_CPUS_OUT_OF_RANGE			(-3)
498c980a4aSJavier Almansa Sobrino #define E_RMM_BOOT_CPU_ID_OUT_OF_RANGE			(-4)
508c980a4aSJavier Almansa Sobrino #define E_RMM_BOOT_INVALID_SHARED_BUFFER		(-5)
518c980a4aSJavier Almansa Sobrino #define E_RMM_BOOT_MANIFEST_VERSION_NOT_SUPPORTED	(-6)
528c980a4aSJavier Almansa Sobrino #define E_RMM_BOOT_MANIFEST_DATA_ERROR			(-7)
538c980a4aSJavier Almansa Sobrino 
548c980a4aSJavier Almansa Sobrino /* The SMC in the range 0x8400 0191 - 0x8400 01AF are reserved for RSIs.*/
55319fb084SSoby Mathew 
56319fb084SSoby Mathew /*
57319fb084SSoby Mathew  * EL3 - RMM SMCs used for requesting RMMD services. These SMCs originate in Realm
58319fb084SSoby Mathew  * world and return to Realm world.
59319fb084SSoby Mathew  *
60319fb084SSoby Mathew  * These are allocated from 0x8400 01B0 - 0x8400 01CF in the RMM Service range.
61319fb084SSoby Mathew  */
62319fb084SSoby Mathew #define RMMD_EL3_FNUM_MIN_VALUE		U(0x1B0)
63319fb084SSoby Mathew #define RMMD_EL3_FNUM_MAX_VALUE		U(0x1CF)
64319fb084SSoby Mathew 
65fb00dc4aSSubhasish Ghosh /* Construct RMM_EL3 fastcall std FID from offset */
66fb00dc4aSSubhasish Ghosh #define SMC64_RMMD_EL3_FID(_offset)					  \
67fb00dc4aSSubhasish Ghosh 	((SMC_TYPE_FAST << FUNCID_TYPE_SHIFT)				| \
68fb00dc4aSSubhasish Ghosh 	 (SMC_64 << FUNCID_CC_SHIFT)					| \
69fb00dc4aSSubhasish Ghosh 	 (OEN_STD_START << FUNCID_OEN_SHIFT)				| \
70fb00dc4aSSubhasish Ghosh 	 (((RMMD_EL3_FNUM_MIN_VALUE + (_offset)) & FUNCID_NUM_MASK)	  \
71fb00dc4aSSubhasish Ghosh 	  << FUNCID_NUM_SHIFT))
72fb00dc4aSSubhasish Ghosh 
73319fb084SSoby Mathew /* The macros below are used to identify GTSI calls from the SMC function ID */
74319fb084SSoby Mathew #define is_rmmd_el3_fid(fid) __extension__ ({		\
75319fb084SSoby Mathew 	__typeof__(fid) _fid = (fid);			\
76319fb084SSoby Mathew 	((GET_SMC_NUM(_fid) >= RMMD_EL3_FNUM_MIN_VALUE) &&\
77319fb084SSoby Mathew 	(GET_SMC_NUM(_fid) <= RMMD_EL3_FNUM_MAX_VALUE)  &&\
78319fb084SSoby Mathew 	(GET_SMC_TYPE(_fid) == SMC_TYPE_FAST)	    &&	\
79319fb084SSoby Mathew 	(GET_SMC_CC(_fid) == SMC_64)                &&	\
80319fb084SSoby Mathew 	(GET_SMC_OEN(_fid) == OEN_STD_START)        &&	\
81319fb084SSoby Mathew 	((_fid & 0x00FE0000) == 0U)); })
82319fb084SSoby Mathew 
83fb00dc4aSSubhasish Ghosh 					/* 0x1B0 - 0x1B1 */
84e50fedbcSJavier Almansa Sobrino #define RMM_GTSI_DELEGATE		SMC64_RMMD_EL3_FID(U(0))
85e50fedbcSJavier Almansa Sobrino #define RMM_GTSI_UNDELEGATE		SMC64_RMMD_EL3_FID(U(1))
86319fb084SSoby Mathew 
87319fb084SSoby Mathew /* Return error codes from RMM-EL3 SMCs */
88dc65ae46SJavier Almansa Sobrino #define E_RMM_OK			 0
89dc65ae46SJavier Almansa Sobrino #define E_RMM_UNK			-1
90dc65ae46SJavier Almansa Sobrino #define E_RMM_BAD_ADDR			-2
91dc65ae46SJavier Almansa Sobrino #define E_RMM_BAD_PAS			-3
92dc65ae46SJavier Almansa Sobrino #define E_RMM_NOMEM			-4
93dc65ae46SJavier Almansa Sobrino #define E_RMM_INVAL			-5
9442cf6026SJuan Pablo Conde #define E_RMM_AGAIN			-6
95319fb084SSoby Mathew 
96ade6000fSShruti Gupta /* Return error codes from RMI SMCs */
97ade6000fSShruti Gupta #define RMI_SUCCESS			0
98ade6000fSShruti Gupta #define RMI_ERROR_INPUT			1
99ade6000fSShruti Gupta 
100a0435105SSoby Mathew /*
101a0435105SSoby Mathew  * Retrieve Realm attestation key from EL3. Only P-384 ECC curve key is
102a0435105SSoby Mathew  * supported. The arguments to this SMC are :
103a0435105SSoby Mathew  *    arg0 - Function ID.
104a0435105SSoby Mathew  *    arg1 - Realm attestation key buffer Physical address.
105a0435105SSoby Mathew  *    arg2 - Realm attestation key buffer size (in bytes).
106a0435105SSoby Mathew  *    arg3 - The type of the elliptic curve to which the requested
107a0435105SSoby Mathew  *           attestation key belongs to. The value should be one of the
108a0435105SSoby Mathew  *           defined curve types.
109a0435105SSoby Mathew  * The return arguments are :
110a0435105SSoby Mathew  *    ret0 - Status / error.
111a0435105SSoby Mathew  *    ret1 - Size of the realm attestation key if successful.
112a0435105SSoby Mathew  */
113fb00dc4aSSubhasish Ghosh 					/* 0x1B2 */
114e50fedbcSJavier Almansa Sobrino #define RMM_ATTEST_GET_REALM_KEY	SMC64_RMMD_EL3_FID(U(2))
115fb00dc4aSSubhasish Ghosh 
116fb00dc4aSSubhasish Ghosh /*
117fb00dc4aSSubhasish Ghosh  * Retrieve Platform token from EL3.
118fb00dc4aSSubhasish Ghosh  * The arguments to this SMC are :
119fb00dc4aSSubhasish Ghosh  *    arg0 - Function ID.
120fb00dc4aSSubhasish Ghosh  *    arg1 - Platform attestation token buffer Physical address. (The challenge
121fb00dc4aSSubhasish Ghosh  *           object is passed in this buffer.)
122fb00dc4aSSubhasish Ghosh  *    arg2 - Platform attestation token buffer size (in bytes).
123fb00dc4aSSubhasish Ghosh  *    arg3 - Challenge object size (in bytes). It has to be one of the defined
124fb00dc4aSSubhasish Ghosh  *           SHA hash sizes.
125fb00dc4aSSubhasish Ghosh  * The return arguments are :
126fb00dc4aSSubhasish Ghosh  *    ret0 - Status / error.
127fb00dc4aSSubhasish Ghosh  *    ret1 - Size of the platform token if successful.
128fb00dc4aSSubhasish Ghosh  */
129fb00dc4aSSubhasish Ghosh 					/* 0x1B3 */
130e50fedbcSJavier Almansa Sobrino #define RMM_ATTEST_GET_PLAT_TOKEN	SMC64_RMMD_EL3_FID(U(3))
131a0435105SSoby Mathew 
1326a88ec8bSRaghu Krishnamurthy /* Starting RMM-EL3 interface version 0.4 */
1336a88ec8bSRaghu Krishnamurthy #define RMM_EL3_FEATURES				SMC64_RMMD_EL3_FID(U(4))
1346a88ec8bSRaghu Krishnamurthy #define RMM_EL3_FEAT_REG_0_IDX				U(0)
1356a88ec8bSRaghu Krishnamurthy /* Bit 0 of FEAT_REG_0 */
1366a88ec8bSRaghu Krishnamurthy /* 1 - the feature is present in EL3 , 0 - the feature is absent */
1376a88ec8bSRaghu Krishnamurthy #define RMM_EL3_FEAT_REG_0_EL3_TOKEN_SIGN_MASK		U(0x1)
1386a88ec8bSRaghu Krishnamurthy 
1396a88ec8bSRaghu Krishnamurthy /*
1406a88ec8bSRaghu Krishnamurthy  * Function codes to support attestation where EL3 is used to sign
1416a88ec8bSRaghu Krishnamurthy  * realm attestation tokens. In this model, the private key is not
1426a88ec8bSRaghu Krishnamurthy  * exposed to the RMM.
1436a88ec8bSRaghu Krishnamurthy  * The arguments to this SMC are:
1446a88ec8bSRaghu Krishnamurthy  *     arg0 - Function ID.
1456a88ec8bSRaghu Krishnamurthy  *     arg1 - Opcode, one of:
1466a88ec8bSRaghu Krishnamurthy  *               RMM_EL3_TOKEN_SIGN_PUSH_REQ_OP,
1476a88ec8bSRaghu Krishnamurthy  *               RMM_EL3_TOKEN_SIGN_PULL_RESP_OP,
1486a88ec8bSRaghu Krishnamurthy  *               RMM_EL3_TOKEN_SIGN_GET_RAK_PUB_OP
1496a88ec8bSRaghu Krishnamurthy  *     arg2 - Pointer to buffer with request/response structures,
1506a88ec8bSRaghu Krishnamurthy  *            which is in the RMM<->EL3 shared buffer.
1516a88ec8bSRaghu Krishnamurthy  *     arg3 - Buffer size of memory pointed by arg2.
1526a88ec8bSRaghu Krishnamurthy  *     arg4 - ECC Curve, when opcode is RMM_EL3_TOKEN_SIGN_GET_RAK_PUB_OP
1536a88ec8bSRaghu Krishnamurthy  * The return arguments are:
1546a88ec8bSRaghu Krishnamurthy  *     ret0 - Status/Error
1556a88ec8bSRaghu Krishnamurthy  *     ret1 - Size of public key if opcode is RMM_EL3_TOKEN_SIGN_GET_RAK_PUB_OP
1566a88ec8bSRaghu Krishnamurthy  */
1576a88ec8bSRaghu Krishnamurthy #define RMM_EL3_TOKEN_SIGN			SMC64_RMMD_EL3_FID(U(5))
1586a88ec8bSRaghu Krishnamurthy 
1596a88ec8bSRaghu Krishnamurthy /* Opcodes for RMM_EL3_TOKEN_SIGN  */
1606a88ec8bSRaghu Krishnamurthy #define RMM_EL3_TOKEN_SIGN_PUSH_REQ_OP          U(1)
1616a88ec8bSRaghu Krishnamurthy #define RMM_EL3_TOKEN_SIGN_PULL_RESP_OP         U(2)
1626a88ec8bSRaghu Krishnamurthy #define RMM_EL3_TOKEN_SIGN_GET_RAK_PUB_OP       U(3)
1636a88ec8bSRaghu Krishnamurthy 
164*f801fdc2STushar Khandelwal /* Starting RMM-EL3 interface version 0.5 */
165*f801fdc2STushar Khandelwal 
166*f801fdc2STushar Khandelwal /*
167*f801fdc2STushar Khandelwal  * Function code to support update of MEC keys.
168*f801fdc2STushar Khandelwal  * The arguments of this SMC are:
169*f801fdc2STushar Khandelwal  * 	arg0 - Function ID.
170*f801fdc2STushar Khandelwal  * 	arg1 - MECID
171*f801fdc2STushar Khandelwal  * The return arguments are:
172*f801fdc2STushar Khandelwal  * 	ret0 - Status/Error
173*f801fdc2STushar Khandelwal  */
174*f801fdc2STushar Khandelwal #define RMM_MECID_KEY_UPDATE			SMC64_RMMD_EL3_FID(U(6))
175*f801fdc2STushar Khandelwal 
176a0435105SSoby Mathew /* ECC Curve types for attest key generation */
1776a88ec8bSRaghu Krishnamurthy #define ATTEST_KEY_CURVE_ECC_SECP384R1		U(0)
1786a88ec8bSRaghu Krishnamurthy 
1796a88ec8bSRaghu Krishnamurthy /* Identifier for the hash algorithm used for attestation signing */
1806a88ec8bSRaghu Krishnamurthy #define EL3_TOKEN_SIGN_HASH_ALG_SHA384		U(1)
181a0435105SSoby Mathew 
1828c980a4aSJavier Almansa Sobrino /*
1838c980a4aSJavier Almansa Sobrino  * RMM_BOOT_COMPLETE originates on RMM when the boot finishes (either cold
1848c980a4aSJavier Almansa Sobrino  * or warm boot). This is handled by the RMM-EL3 interface SMC handler.
1858c980a4aSJavier Almansa Sobrino  *
1868c980a4aSJavier Almansa Sobrino  * RMM_BOOT_COMPLETE FID is located at the end of the available range.
1878c980a4aSJavier Almansa Sobrino  */
1888c980a4aSJavier Almansa Sobrino 					 /* 0x1CF */
1898c980a4aSJavier Almansa Sobrino #define RMM_BOOT_COMPLETE		SMC64_RMMD_EL3_FID(U(0x1F))
1908c980a4aSJavier Almansa Sobrino 
1918c980a4aSJavier Almansa Sobrino /*
1928c980a4aSJavier Almansa Sobrino  * The major version number of the RMM Boot Interface implementation.
1938c980a4aSJavier Almansa Sobrino  * Increase this whenever the semantics of the boot arguments change making it
1948c980a4aSJavier Almansa Sobrino  * backwards incompatible.
1958c980a4aSJavier Almansa Sobrino  */
1968c980a4aSJavier Almansa Sobrino #define RMM_EL3_IFC_VERSION_MAJOR	(U(0))
1978c980a4aSJavier Almansa Sobrino 
1988c980a4aSJavier Almansa Sobrino /*
1998c980a4aSJavier Almansa Sobrino  * The minor version number of the RMM Boot Interface implementation.
2008c980a4aSJavier Almansa Sobrino  * Increase this when a bug is fixed, or a feature is added without
2018c980a4aSJavier Almansa Sobrino  * breaking compatibility.
2028c980a4aSJavier Almansa Sobrino  */
203*f801fdc2STushar Khandelwal #define RMM_EL3_IFC_VERSION_MINOR	(U(5))
2048c980a4aSJavier Almansa Sobrino 
2058c980a4aSJavier Almansa Sobrino #define RMM_EL3_INTERFACE_VERSION				\
2068c980a4aSJavier Almansa Sobrino 	(((RMM_EL3_IFC_VERSION_MAJOR << 16) & 0x7FFFF) |	\
2078c980a4aSJavier Almansa Sobrino 		RMM_EL3_IFC_VERSION_MINOR)
2088c980a4aSJavier Almansa Sobrino 
2098c980a4aSJavier Almansa Sobrino #define RMM_EL3_IFC_VERSION_GET_MAJOR(_version) (((_version) >> 16) \
2108c980a4aSJavier Almansa Sobrino 								& 0x7FFF)
2118c980a4aSJavier Almansa Sobrino #define RMM_EL3_IFC_VERSION_GET_MAJOR_MINOR(_version) ((_version) & 0xFFFF)
212a0435105SSoby Mathew 
21377c27753SZelalem Aweke #ifndef __ASSEMBLER__
21477c27753SZelalem Aweke #include <stdint.h>
21577c27753SZelalem Aweke 
21677c27753SZelalem Aweke int rmmd_setup(void);
21777c27753SZelalem Aweke uint64_t rmmd_rmi_handler(uint32_t smc_fid,
21877c27753SZelalem Aweke 		uint64_t x1,
21977c27753SZelalem Aweke 		uint64_t x2,
22077c27753SZelalem Aweke 		uint64_t x3,
22177c27753SZelalem Aweke 		uint64_t x4,
22277c27753SZelalem Aweke 		void *cookie,
22377c27753SZelalem Aweke 		void *handle,
22477c27753SZelalem Aweke 		uint64_t flags);
22577c27753SZelalem Aweke 
226319fb084SSoby Mathew uint64_t rmmd_rmm_el3_handler(uint32_t smc_fid,
22777c27753SZelalem Aweke 		uint64_t x1,
22877c27753SZelalem Aweke 		uint64_t x2,
22977c27753SZelalem Aweke 		uint64_t x3,
23077c27753SZelalem Aweke 		uint64_t x4,
23177c27753SZelalem Aweke 		void *cookie,
23277c27753SZelalem Aweke 		void *handle,
23377c27753SZelalem Aweke 		uint64_t flags);
23477c27753SZelalem Aweke 
23577c27753SZelalem Aweke #endif /* __ASSEMBLER__ */
23677c27753SZelalem Aweke #endif /* RMMD_SVC_H */
237