177c27753SZelalem Aweke /* 2*f801fdc2STushar Khandelwal * Copyright (c) 2021-2025, Arm Limited and Contributors. All rights reserved. 377c27753SZelalem Aweke * 477c27753SZelalem Aweke * SPDX-License-Identifier: BSD-3-Clause 577c27753SZelalem Aweke */ 677c27753SZelalem Aweke 777c27753SZelalem Aweke #ifndef RMMD_SVC_H 877c27753SZelalem Aweke #define RMMD_SVC_H 977c27753SZelalem Aweke 10e9529e46SRaghu Krishnamurthy #include <common/sha_common_macros.h> 11319fb084SSoby Mathew #include <lib/smccc.h> 12319fb084SSoby Mathew #include <lib/utils_def.h> 13319fb084SSoby Mathew 14fb00dc4aSSubhasish Ghosh /* STD calls FNUM Min/Max ranges */ 15319fb084SSoby Mathew #define RMI_FNUM_MIN_VALUE U(0x150) 16319fb084SSoby Mathew #define RMI_FNUM_MAX_VALUE U(0x18F) 17319fb084SSoby Mathew 18fb00dc4aSSubhasish Ghosh /* Construct RMI fastcall std FID from offset */ 19fb00dc4aSSubhasish Ghosh #define SMC64_RMI_FID(_offset) \ 20fb00dc4aSSubhasish Ghosh ((SMC_TYPE_FAST << FUNCID_TYPE_SHIFT) | \ 21fb00dc4aSSubhasish Ghosh (SMC_64 << FUNCID_CC_SHIFT) | \ 22fb00dc4aSSubhasish Ghosh (OEN_STD_START << FUNCID_OEN_SHIFT) | \ 23fb00dc4aSSubhasish Ghosh (((RMI_FNUM_MIN_VALUE + (_offset)) & FUNCID_NUM_MASK) \ 24fb00dc4aSSubhasish Ghosh << FUNCID_NUM_SHIFT)) 25fb00dc4aSSubhasish Ghosh 26319fb084SSoby Mathew #define is_rmi_fid(fid) __extension__ ({ \ 27319fb084SSoby Mathew __typeof__(fid) _fid = (fid); \ 28319fb084SSoby Mathew ((GET_SMC_NUM(_fid) >= RMI_FNUM_MIN_VALUE) && \ 29319fb084SSoby Mathew (GET_SMC_NUM(_fid) <= RMI_FNUM_MAX_VALUE) && \ 30319fb084SSoby Mathew (GET_SMC_TYPE(_fid) == SMC_TYPE_FAST) && \ 31319fb084SSoby Mathew (GET_SMC_CC(_fid) == SMC_64) && \ 32319fb084SSoby Mathew (GET_SMC_OEN(_fid) == OEN_STD_START) && \ 33319fb084SSoby Mathew ((_fid & 0x00FE0000) == 0U)); }) 34319fb084SSoby Mathew 35319fb084SSoby Mathew /* 36fb00dc4aSSubhasish Ghosh * RMI_FNUM_REQ_COMPLETE is the only function in the RMI range that originates 37319fb084SSoby Mathew * from the Realm world and is handled by the RMMD. The RMI functions are 38319fb084SSoby Mathew * always invoked by the Normal world, forwarded by RMMD and handled by the 39fb00dc4aSSubhasish Ghosh * RMM. 40319fb084SSoby Mathew */ 41fb00dc4aSSubhasish Ghosh /* 0x18F */ 42e50fedbcSJavier Almansa Sobrino #define RMM_RMI_REQ_COMPLETE SMC64_RMI_FID(U(0x3F)) 43319fb084SSoby Mathew 448c980a4aSJavier Almansa Sobrino /* RMM_BOOT_COMPLETE arg0 error codes */ 458c980a4aSJavier Almansa Sobrino #define E_RMM_BOOT_SUCCESS (0) 468c980a4aSJavier Almansa Sobrino #define E_RMM_BOOT_UNKNOWN (-1) 478c980a4aSJavier Almansa Sobrino #define E_RMM_BOOT_VERSION_MISMATCH (-2) 488c980a4aSJavier Almansa Sobrino #define E_RMM_BOOT_CPUS_OUT_OF_RANGE (-3) 498c980a4aSJavier Almansa Sobrino #define E_RMM_BOOT_CPU_ID_OUT_OF_RANGE (-4) 508c980a4aSJavier Almansa Sobrino #define E_RMM_BOOT_INVALID_SHARED_BUFFER (-5) 518c980a4aSJavier Almansa Sobrino #define E_RMM_BOOT_MANIFEST_VERSION_NOT_SUPPORTED (-6) 528c980a4aSJavier Almansa Sobrino #define E_RMM_BOOT_MANIFEST_DATA_ERROR (-7) 538c980a4aSJavier Almansa Sobrino 548c980a4aSJavier Almansa Sobrino /* The SMC in the range 0x8400 0191 - 0x8400 01AF are reserved for RSIs.*/ 55319fb084SSoby Mathew 56319fb084SSoby Mathew /* 57319fb084SSoby Mathew * EL3 - RMM SMCs used for requesting RMMD services. These SMCs originate in Realm 58319fb084SSoby Mathew * world and return to Realm world. 59319fb084SSoby Mathew * 60319fb084SSoby Mathew * These are allocated from 0x8400 01B0 - 0x8400 01CF in the RMM Service range. 61319fb084SSoby Mathew */ 62319fb084SSoby Mathew #define RMMD_EL3_FNUM_MIN_VALUE U(0x1B0) 63319fb084SSoby Mathew #define RMMD_EL3_FNUM_MAX_VALUE U(0x1CF) 64319fb084SSoby Mathew 65fb00dc4aSSubhasish Ghosh /* Construct RMM_EL3 fastcall std FID from offset */ 66fb00dc4aSSubhasish Ghosh #define SMC64_RMMD_EL3_FID(_offset) \ 67fb00dc4aSSubhasish Ghosh ((SMC_TYPE_FAST << FUNCID_TYPE_SHIFT) | \ 68fb00dc4aSSubhasish Ghosh (SMC_64 << FUNCID_CC_SHIFT) | \ 69fb00dc4aSSubhasish Ghosh (OEN_STD_START << FUNCID_OEN_SHIFT) | \ 70fb00dc4aSSubhasish Ghosh (((RMMD_EL3_FNUM_MIN_VALUE + (_offset)) & FUNCID_NUM_MASK) \ 71fb00dc4aSSubhasish Ghosh << FUNCID_NUM_SHIFT)) 72fb00dc4aSSubhasish Ghosh 73319fb084SSoby Mathew /* The macros below are used to identify GTSI calls from the SMC function ID */ 74319fb084SSoby Mathew #define is_rmmd_el3_fid(fid) __extension__ ({ \ 75319fb084SSoby Mathew __typeof__(fid) _fid = (fid); \ 76319fb084SSoby Mathew ((GET_SMC_NUM(_fid) >= RMMD_EL3_FNUM_MIN_VALUE) &&\ 77319fb084SSoby Mathew (GET_SMC_NUM(_fid) <= RMMD_EL3_FNUM_MAX_VALUE) &&\ 78319fb084SSoby Mathew (GET_SMC_TYPE(_fid) == SMC_TYPE_FAST) && \ 79319fb084SSoby Mathew (GET_SMC_CC(_fid) == SMC_64) && \ 80319fb084SSoby Mathew (GET_SMC_OEN(_fid) == OEN_STD_START) && \ 81319fb084SSoby Mathew ((_fid & 0x00FE0000) == 0U)); }) 82319fb084SSoby Mathew 83fb00dc4aSSubhasish Ghosh /* 0x1B0 - 0x1B1 */ 84e50fedbcSJavier Almansa Sobrino #define RMM_GTSI_DELEGATE SMC64_RMMD_EL3_FID(U(0)) 85e50fedbcSJavier Almansa Sobrino #define RMM_GTSI_UNDELEGATE SMC64_RMMD_EL3_FID(U(1)) 86319fb084SSoby Mathew 87319fb084SSoby Mathew /* Return error codes from RMM-EL3 SMCs */ 88dc65ae46SJavier Almansa Sobrino #define E_RMM_OK 0 89dc65ae46SJavier Almansa Sobrino #define E_RMM_UNK -1 90dc65ae46SJavier Almansa Sobrino #define E_RMM_BAD_ADDR -2 91dc65ae46SJavier Almansa Sobrino #define E_RMM_BAD_PAS -3 92dc65ae46SJavier Almansa Sobrino #define E_RMM_NOMEM -4 93dc65ae46SJavier Almansa Sobrino #define E_RMM_INVAL -5 9442cf6026SJuan Pablo Conde #define E_RMM_AGAIN -6 95319fb084SSoby Mathew 96ade6000fSShruti Gupta /* Return error codes from RMI SMCs */ 97ade6000fSShruti Gupta #define RMI_SUCCESS 0 98ade6000fSShruti Gupta #define RMI_ERROR_INPUT 1 99ade6000fSShruti Gupta 100a0435105SSoby Mathew /* 101a0435105SSoby Mathew * Retrieve Realm attestation key from EL3. Only P-384 ECC curve key is 102a0435105SSoby Mathew * supported. The arguments to this SMC are : 103a0435105SSoby Mathew * arg0 - Function ID. 104a0435105SSoby Mathew * arg1 - Realm attestation key buffer Physical address. 105a0435105SSoby Mathew * arg2 - Realm attestation key buffer size (in bytes). 106a0435105SSoby Mathew * arg3 - The type of the elliptic curve to which the requested 107a0435105SSoby Mathew * attestation key belongs to. The value should be one of the 108a0435105SSoby Mathew * defined curve types. 109a0435105SSoby Mathew * The return arguments are : 110a0435105SSoby Mathew * ret0 - Status / error. 111a0435105SSoby Mathew * ret1 - Size of the realm attestation key if successful. 112a0435105SSoby Mathew */ 113fb00dc4aSSubhasish Ghosh /* 0x1B2 */ 114e50fedbcSJavier Almansa Sobrino #define RMM_ATTEST_GET_REALM_KEY SMC64_RMMD_EL3_FID(U(2)) 115fb00dc4aSSubhasish Ghosh 116fb00dc4aSSubhasish Ghosh /* 117fb00dc4aSSubhasish Ghosh * Retrieve Platform token from EL3. 118fb00dc4aSSubhasish Ghosh * The arguments to this SMC are : 119fb00dc4aSSubhasish Ghosh * arg0 - Function ID. 120fb00dc4aSSubhasish Ghosh * arg1 - Platform attestation token buffer Physical address. (The challenge 121fb00dc4aSSubhasish Ghosh * object is passed in this buffer.) 122fb00dc4aSSubhasish Ghosh * arg2 - Platform attestation token buffer size (in bytes). 123fb00dc4aSSubhasish Ghosh * arg3 - Challenge object size (in bytes). It has to be one of the defined 124fb00dc4aSSubhasish Ghosh * SHA hash sizes. 125fb00dc4aSSubhasish Ghosh * The return arguments are : 126fb00dc4aSSubhasish Ghosh * ret0 - Status / error. 127fb00dc4aSSubhasish Ghosh * ret1 - Size of the platform token if successful. 128fb00dc4aSSubhasish Ghosh */ 129fb00dc4aSSubhasish Ghosh /* 0x1B3 */ 130e50fedbcSJavier Almansa Sobrino #define RMM_ATTEST_GET_PLAT_TOKEN SMC64_RMMD_EL3_FID(U(3)) 131a0435105SSoby Mathew 1326a88ec8bSRaghu Krishnamurthy /* Starting RMM-EL3 interface version 0.4 */ 1336a88ec8bSRaghu Krishnamurthy #define RMM_EL3_FEATURES SMC64_RMMD_EL3_FID(U(4)) 1346a88ec8bSRaghu Krishnamurthy #define RMM_EL3_FEAT_REG_0_IDX U(0) 1356a88ec8bSRaghu Krishnamurthy /* Bit 0 of FEAT_REG_0 */ 1366a88ec8bSRaghu Krishnamurthy /* 1 - the feature is present in EL3 , 0 - the feature is absent */ 1376a88ec8bSRaghu Krishnamurthy #define RMM_EL3_FEAT_REG_0_EL3_TOKEN_SIGN_MASK U(0x1) 1386a88ec8bSRaghu Krishnamurthy 1396a88ec8bSRaghu Krishnamurthy /* 1406a88ec8bSRaghu Krishnamurthy * Function codes to support attestation where EL3 is used to sign 1416a88ec8bSRaghu Krishnamurthy * realm attestation tokens. In this model, the private key is not 1426a88ec8bSRaghu Krishnamurthy * exposed to the RMM. 1436a88ec8bSRaghu Krishnamurthy * The arguments to this SMC are: 1446a88ec8bSRaghu Krishnamurthy * arg0 - Function ID. 1456a88ec8bSRaghu Krishnamurthy * arg1 - Opcode, one of: 1466a88ec8bSRaghu Krishnamurthy * RMM_EL3_TOKEN_SIGN_PUSH_REQ_OP, 1476a88ec8bSRaghu Krishnamurthy * RMM_EL3_TOKEN_SIGN_PULL_RESP_OP, 1486a88ec8bSRaghu Krishnamurthy * RMM_EL3_TOKEN_SIGN_GET_RAK_PUB_OP 1496a88ec8bSRaghu Krishnamurthy * arg2 - Pointer to buffer with request/response structures, 1506a88ec8bSRaghu Krishnamurthy * which is in the RMM<->EL3 shared buffer. 1516a88ec8bSRaghu Krishnamurthy * arg3 - Buffer size of memory pointed by arg2. 1526a88ec8bSRaghu Krishnamurthy * arg4 - ECC Curve, when opcode is RMM_EL3_TOKEN_SIGN_GET_RAK_PUB_OP 1536a88ec8bSRaghu Krishnamurthy * The return arguments are: 1546a88ec8bSRaghu Krishnamurthy * ret0 - Status/Error 1556a88ec8bSRaghu Krishnamurthy * ret1 - Size of public key if opcode is RMM_EL3_TOKEN_SIGN_GET_RAK_PUB_OP 1566a88ec8bSRaghu Krishnamurthy */ 1576a88ec8bSRaghu Krishnamurthy #define RMM_EL3_TOKEN_SIGN SMC64_RMMD_EL3_FID(U(5)) 1586a88ec8bSRaghu Krishnamurthy 1596a88ec8bSRaghu Krishnamurthy /* Opcodes for RMM_EL3_TOKEN_SIGN */ 1606a88ec8bSRaghu Krishnamurthy #define RMM_EL3_TOKEN_SIGN_PUSH_REQ_OP U(1) 1616a88ec8bSRaghu Krishnamurthy #define RMM_EL3_TOKEN_SIGN_PULL_RESP_OP U(2) 1626a88ec8bSRaghu Krishnamurthy #define RMM_EL3_TOKEN_SIGN_GET_RAK_PUB_OP U(3) 1636a88ec8bSRaghu Krishnamurthy 164*f801fdc2STushar Khandelwal /* Starting RMM-EL3 interface version 0.5 */ 165*f801fdc2STushar Khandelwal 166*f801fdc2STushar Khandelwal /* 167*f801fdc2STushar Khandelwal * Function code to support update of MEC keys. 168*f801fdc2STushar Khandelwal * The arguments of this SMC are: 169*f801fdc2STushar Khandelwal * arg0 - Function ID. 170*f801fdc2STushar Khandelwal * arg1 - MECID 171*f801fdc2STushar Khandelwal * The return arguments are: 172*f801fdc2STushar Khandelwal * ret0 - Status/Error 173*f801fdc2STushar Khandelwal */ 174*f801fdc2STushar Khandelwal #define RMM_MECID_KEY_UPDATE SMC64_RMMD_EL3_FID(U(6)) 175*f801fdc2STushar Khandelwal 176a0435105SSoby Mathew /* ECC Curve types for attest key generation */ 1776a88ec8bSRaghu Krishnamurthy #define ATTEST_KEY_CURVE_ECC_SECP384R1 U(0) 1786a88ec8bSRaghu Krishnamurthy 1796a88ec8bSRaghu Krishnamurthy /* Identifier for the hash algorithm used for attestation signing */ 1806a88ec8bSRaghu Krishnamurthy #define EL3_TOKEN_SIGN_HASH_ALG_SHA384 U(1) 181a0435105SSoby Mathew 1828c980a4aSJavier Almansa Sobrino /* 1838c980a4aSJavier Almansa Sobrino * RMM_BOOT_COMPLETE originates on RMM when the boot finishes (either cold 1848c980a4aSJavier Almansa Sobrino * or warm boot). This is handled by the RMM-EL3 interface SMC handler. 1858c980a4aSJavier Almansa Sobrino * 1868c980a4aSJavier Almansa Sobrino * RMM_BOOT_COMPLETE FID is located at the end of the available range. 1878c980a4aSJavier Almansa Sobrino */ 1888c980a4aSJavier Almansa Sobrino /* 0x1CF */ 1898c980a4aSJavier Almansa Sobrino #define RMM_BOOT_COMPLETE SMC64_RMMD_EL3_FID(U(0x1F)) 1908c980a4aSJavier Almansa Sobrino 1918c980a4aSJavier Almansa Sobrino /* 1928c980a4aSJavier Almansa Sobrino * The major version number of the RMM Boot Interface implementation. 1938c980a4aSJavier Almansa Sobrino * Increase this whenever the semantics of the boot arguments change making it 1948c980a4aSJavier Almansa Sobrino * backwards incompatible. 1958c980a4aSJavier Almansa Sobrino */ 1968c980a4aSJavier Almansa Sobrino #define RMM_EL3_IFC_VERSION_MAJOR (U(0)) 1978c980a4aSJavier Almansa Sobrino 1988c980a4aSJavier Almansa Sobrino /* 1998c980a4aSJavier Almansa Sobrino * The minor version number of the RMM Boot Interface implementation. 2008c980a4aSJavier Almansa Sobrino * Increase this when a bug is fixed, or a feature is added without 2018c980a4aSJavier Almansa Sobrino * breaking compatibility. 2028c980a4aSJavier Almansa Sobrino */ 203*f801fdc2STushar Khandelwal #define RMM_EL3_IFC_VERSION_MINOR (U(5)) 2048c980a4aSJavier Almansa Sobrino 2058c980a4aSJavier Almansa Sobrino #define RMM_EL3_INTERFACE_VERSION \ 2068c980a4aSJavier Almansa Sobrino (((RMM_EL3_IFC_VERSION_MAJOR << 16) & 0x7FFFF) | \ 2078c980a4aSJavier Almansa Sobrino RMM_EL3_IFC_VERSION_MINOR) 2088c980a4aSJavier Almansa Sobrino 2098c980a4aSJavier Almansa Sobrino #define RMM_EL3_IFC_VERSION_GET_MAJOR(_version) (((_version) >> 16) \ 2108c980a4aSJavier Almansa Sobrino & 0x7FFF) 2118c980a4aSJavier Almansa Sobrino #define RMM_EL3_IFC_VERSION_GET_MAJOR_MINOR(_version) ((_version) & 0xFFFF) 212a0435105SSoby Mathew 21377c27753SZelalem Aweke #ifndef __ASSEMBLER__ 21477c27753SZelalem Aweke #include <stdint.h> 21577c27753SZelalem Aweke 21677c27753SZelalem Aweke int rmmd_setup(void); 21777c27753SZelalem Aweke uint64_t rmmd_rmi_handler(uint32_t smc_fid, 21877c27753SZelalem Aweke uint64_t x1, 21977c27753SZelalem Aweke uint64_t x2, 22077c27753SZelalem Aweke uint64_t x3, 22177c27753SZelalem Aweke uint64_t x4, 22277c27753SZelalem Aweke void *cookie, 22377c27753SZelalem Aweke void *handle, 22477c27753SZelalem Aweke uint64_t flags); 22577c27753SZelalem Aweke 226319fb084SSoby Mathew uint64_t rmmd_rmm_el3_handler(uint32_t smc_fid, 22777c27753SZelalem Aweke uint64_t x1, 22877c27753SZelalem Aweke uint64_t x2, 22977c27753SZelalem Aweke uint64_t x3, 23077c27753SZelalem Aweke uint64_t x4, 23177c27753SZelalem Aweke void *cookie, 23277c27753SZelalem Aweke void *handle, 23377c27753SZelalem Aweke uint64_t flags); 23477c27753SZelalem Aweke 23577c27753SZelalem Aweke #endif /* __ASSEMBLER__ */ 23677c27753SZelalem Aweke #endif /* RMMD_SVC_H */ 237