xref: /rk3399_ARM-atf/lib/psa/measured_boot.c (revision 93d1f4bc749e157cdfbe060b7e10351f460dedef)
1 /*
2  * Copyright (c) 2022-2023, Arm Limited. All rights reserved.
3  *
4  * SPDX-License-Identifier: BSD-3-Clause
5  *
6  */
7 
8 #include <string.h>
9 
10 #include <common/debug.h>
11 #include <measured_boot.h>
12 #include <psa/client.h>
13 #include <psa_manifest/sid.h>
14 
15 #include "measured_boot_private.h"
16 
17 static void print_byte_array(const uint8_t *array __unused, size_t len __unused)
18 {
19 #if LOG_LEVEL >= LOG_LEVEL_INFO
20 	size_t i;
21 
22 	if (array == NULL || len == 0U) {
23 		(void)printf("\n");
24 	} else {
25 		for (i = 0U; i < len; ++i) {
26 			(void)printf(" %02x", array[i]);
27 			if ((i & U(0xF)) == U(0xF)) {
28 				(void)printf("\n");
29 				if (i < (len - 1U)) {
30 					INFO("\t\t:");
31 				}
32 			}
33 		}
34 	}
35 #endif
36 }
37 
38 static void log_measurement(uint8_t index,
39 			    const uint8_t *signer_id,
40 			    size_t signer_id_size,
41 			    const uint8_t *version,     /* string */
42 			    size_t version_size,
43 			    const uint8_t *sw_type,     /* string */
44 			    size_t sw_type_size,
45 			    uint32_t measurement_algo,
46 			    const uint8_t *measurement_value,
47 			    size_t measurement_value_size,
48 			    bool lock_measurement)
49 {
50 	INFO("Measured boot extend measurement:\n");
51 	INFO(" - slot        : %u\n", index);
52 	INFO(" - signer_id   :");
53 	print_byte_array(signer_id, signer_id_size);
54 	INFO(" - version     : %s\n",  version);
55 	INFO(" - version_size: %zu\n", version_size);
56 	INFO(" - sw_type     : %s\n",  sw_type);
57 	INFO(" - sw_type_size: %zu\n", sw_type_size);
58 	INFO(" - algorithm   : %x\n", measurement_algo);
59 	INFO(" - measurement :");
60 	print_byte_array(measurement_value, measurement_value_size);
61 	INFO(" - locking     : %s\n", lock_measurement ? "true" : "false");
62 }
63 
64 psa_status_t
65 rss_measured_boot_extend_measurement(uint8_t index,
66 				     const uint8_t *signer_id,
67 				     size_t signer_id_size,
68 				     const uint8_t *version,
69 				     size_t version_size,
70 				     uint32_t measurement_algo,
71 				     const uint8_t *sw_type,
72 				     size_t sw_type_size,
73 				     const uint8_t *measurement_value,
74 				     size_t measurement_value_size,
75 				     bool lock_measurement)
76 {
77 	struct measured_boot_extend_iovec_t extend_iov = {
78 		.index = index,
79 		.lock_measurement = lock_measurement,
80 		.measurement_algo = measurement_algo,
81 		.sw_type = {0},
82 		.sw_type_size = sw_type_size,
83 	};
84 
85 	if (version_size > VERSION_MAX_SIZE) {
86 		return PSA_ERROR_INVALID_ARGUMENT;
87 	}
88 
89 
90 	if (version_size > 0 && version[version_size - 1] == '\0') {
91 		version_size--;
92 	}
93 
94 	psa_invec in_vec[] = {
95 		{.base = &extend_iov,
96 			.len = sizeof(struct measured_boot_extend_iovec_t)},
97 		{.base = signer_id, .len = signer_id_size},
98 		{.base = version, .len = version_size },
99 		{.base = measurement_value, .len = measurement_value_size}
100 	};
101 
102 	if (sw_type != NULL) {
103 		if (extend_iov.sw_type_size > SW_TYPE_MAX_SIZE) {
104 			return PSA_ERROR_INVALID_ARGUMENT;
105 		}
106 		if (sw_type_size > 0 && sw_type[sw_type_size - 1] == '\0') {
107 			extend_iov.sw_type_size--;
108 		}
109 		memcpy(extend_iov.sw_type, sw_type, extend_iov.sw_type_size);
110 	}
111 
112 	log_measurement(index, signer_id, signer_id_size,
113 			version, version_size, sw_type, sw_type_size,
114 			measurement_algo, measurement_value,
115 			measurement_value_size, lock_measurement);
116 
117 	return psa_call(RSS_MEASURED_BOOT_HANDLE,
118 			RSS_MEASURED_BOOT_EXTEND,
119 			in_vec, IOVEC_LEN(in_vec),
120 			NULL, 0);
121 }
122 
123 psa_status_t rss_measured_boot_read_measurement(uint8_t index,
124 					uint8_t *signer_id,
125 					size_t signer_id_size,
126 					size_t *signer_id_len,
127 					uint8_t *version,
128 					size_t version_size,
129 					size_t *version_len,
130 					uint32_t *measurement_algo,
131 					uint8_t *sw_type,
132 					size_t sw_type_size,
133 					size_t *sw_type_len,
134 					uint8_t *measurement_value,
135 					size_t measurement_value_size,
136 					size_t *measurement_value_len,
137 					bool *is_locked)
138 {
139 	psa_status_t status;
140 	struct measured_boot_read_iovec_in_t read_iov_in = {
141 		.index = index,
142 		.sw_type_size = sw_type_size,
143 		.version_size = version_size,
144 	};
145 
146 	struct measured_boot_read_iovec_out_t read_iov_out;
147 
148 	psa_invec in_vec[] = {
149 		{.base = &read_iov_in,
150 		 .len = sizeof(struct measured_boot_read_iovec_in_t)},
151 	};
152 
153 	psa_outvec out_vec[] = {
154 		{.base = &read_iov_out,
155 		 .len = sizeof(struct measured_boot_read_iovec_out_t)},
156 		{.base = signer_id, .len = signer_id_size},
157 		{.base = measurement_value, .len = measurement_value_size}
158 	};
159 
160 	status = psa_call(RSS_MEASURED_BOOT_HANDLE, RSS_MEASURED_BOOT_READ,
161 					  in_vec, IOVEC_LEN(in_vec),
162 					  out_vec, IOVEC_LEN(out_vec));
163 
164 	if (status == PSA_SUCCESS) {
165 		*is_locked = read_iov_out.is_locked;
166 		*measurement_algo = read_iov_out.measurement_algo;
167 		*sw_type_len = read_iov_out.sw_type_len;
168 		*version_len = read_iov_out.version_len;
169 		memcpy(sw_type, read_iov_out.sw_type, read_iov_out.sw_type_len);
170 		memcpy(version, read_iov_out.version, read_iov_out.version_len);
171 		*signer_id_len = out_vec[1].len;
172 		*measurement_value_len = out_vec[2].len;
173 	}
174 
175 	return status;
176 }
177