18c2ecf20Sopenharmony_ci// SPDX-License-Identifier: GPL-2.0-only 28c2ecf20Sopenharmony_ci/* 38c2ecf20Sopenharmony_ci * Copyright (c) 2015-2016, Linaro Limited 48c2ecf20Sopenharmony_ci */ 58c2ecf20Sopenharmony_ci 68c2ecf20Sopenharmony_ci#define pr_fmt(fmt) KBUILD_MODNAME ": " fmt 78c2ecf20Sopenharmony_ci 88c2ecf20Sopenharmony_ci#include <linux/delay.h> 98c2ecf20Sopenharmony_ci#include <linux/device.h> 108c2ecf20Sopenharmony_ci#include <linux/i2c.h> 118c2ecf20Sopenharmony_ci#include <linux/slab.h> 128c2ecf20Sopenharmony_ci#include <linux/tee_drv.h> 138c2ecf20Sopenharmony_ci#include "optee_private.h" 148c2ecf20Sopenharmony_ci#include "optee_smc.h" 158c2ecf20Sopenharmony_ci 168c2ecf20Sopenharmony_cistruct wq_entry { 178c2ecf20Sopenharmony_ci struct list_head link; 188c2ecf20Sopenharmony_ci struct completion c; 198c2ecf20Sopenharmony_ci u32 key; 208c2ecf20Sopenharmony_ci}; 218c2ecf20Sopenharmony_ci 228c2ecf20Sopenharmony_civoid optee_wait_queue_init(struct optee_wait_queue *priv) 238c2ecf20Sopenharmony_ci{ 248c2ecf20Sopenharmony_ci mutex_init(&priv->mu); 258c2ecf20Sopenharmony_ci INIT_LIST_HEAD(&priv->db); 268c2ecf20Sopenharmony_ci} 278c2ecf20Sopenharmony_ci 288c2ecf20Sopenharmony_civoid optee_wait_queue_exit(struct optee_wait_queue *priv) 298c2ecf20Sopenharmony_ci{ 308c2ecf20Sopenharmony_ci mutex_destroy(&priv->mu); 318c2ecf20Sopenharmony_ci} 328c2ecf20Sopenharmony_ci 338c2ecf20Sopenharmony_cistatic void handle_rpc_func_cmd_get_time(struct optee_msg_arg *arg) 348c2ecf20Sopenharmony_ci{ 358c2ecf20Sopenharmony_ci struct timespec64 ts; 368c2ecf20Sopenharmony_ci 378c2ecf20Sopenharmony_ci if (arg->num_params != 1) 388c2ecf20Sopenharmony_ci goto bad; 398c2ecf20Sopenharmony_ci if ((arg->params[0].attr & OPTEE_MSG_ATTR_TYPE_MASK) != 408c2ecf20Sopenharmony_ci OPTEE_MSG_ATTR_TYPE_VALUE_OUTPUT) 418c2ecf20Sopenharmony_ci goto bad; 428c2ecf20Sopenharmony_ci 438c2ecf20Sopenharmony_ci ktime_get_real_ts64(&ts); 448c2ecf20Sopenharmony_ci arg->params[0].u.value.a = ts.tv_sec; 458c2ecf20Sopenharmony_ci arg->params[0].u.value.b = ts.tv_nsec; 468c2ecf20Sopenharmony_ci 478c2ecf20Sopenharmony_ci arg->ret = TEEC_SUCCESS; 488c2ecf20Sopenharmony_ci return; 498c2ecf20Sopenharmony_cibad: 508c2ecf20Sopenharmony_ci arg->ret = TEEC_ERROR_BAD_PARAMETERS; 518c2ecf20Sopenharmony_ci} 528c2ecf20Sopenharmony_ci 538c2ecf20Sopenharmony_ci#if IS_REACHABLE(CONFIG_I2C) 548c2ecf20Sopenharmony_cistatic void handle_rpc_func_cmd_i2c_transfer(struct tee_context *ctx, 558c2ecf20Sopenharmony_ci struct optee_msg_arg *arg) 568c2ecf20Sopenharmony_ci{ 578c2ecf20Sopenharmony_ci struct tee_param *params; 588c2ecf20Sopenharmony_ci struct i2c_adapter *adapter; 598c2ecf20Sopenharmony_ci struct i2c_msg msg = { }; 608c2ecf20Sopenharmony_ci size_t i; 618c2ecf20Sopenharmony_ci int ret = -EOPNOTSUPP; 628c2ecf20Sopenharmony_ci u8 attr[] = { 638c2ecf20Sopenharmony_ci TEE_IOCTL_PARAM_ATTR_TYPE_VALUE_INPUT, 648c2ecf20Sopenharmony_ci TEE_IOCTL_PARAM_ATTR_TYPE_VALUE_INPUT, 658c2ecf20Sopenharmony_ci TEE_IOCTL_PARAM_ATTR_TYPE_MEMREF_INOUT, 668c2ecf20Sopenharmony_ci TEE_IOCTL_PARAM_ATTR_TYPE_VALUE_OUTPUT, 678c2ecf20Sopenharmony_ci }; 688c2ecf20Sopenharmony_ci 698c2ecf20Sopenharmony_ci if (arg->num_params != ARRAY_SIZE(attr)) { 708c2ecf20Sopenharmony_ci arg->ret = TEEC_ERROR_BAD_PARAMETERS; 718c2ecf20Sopenharmony_ci return; 728c2ecf20Sopenharmony_ci } 738c2ecf20Sopenharmony_ci 748c2ecf20Sopenharmony_ci params = kmalloc_array(arg->num_params, sizeof(struct tee_param), 758c2ecf20Sopenharmony_ci GFP_KERNEL); 768c2ecf20Sopenharmony_ci if (!params) { 778c2ecf20Sopenharmony_ci arg->ret = TEEC_ERROR_OUT_OF_MEMORY; 788c2ecf20Sopenharmony_ci return; 798c2ecf20Sopenharmony_ci } 808c2ecf20Sopenharmony_ci 818c2ecf20Sopenharmony_ci if (optee_from_msg_param(params, arg->num_params, arg->params)) 828c2ecf20Sopenharmony_ci goto bad; 838c2ecf20Sopenharmony_ci 848c2ecf20Sopenharmony_ci for (i = 0; i < arg->num_params; i++) { 858c2ecf20Sopenharmony_ci if (params[i].attr != attr[i]) 868c2ecf20Sopenharmony_ci goto bad; 878c2ecf20Sopenharmony_ci } 888c2ecf20Sopenharmony_ci 898c2ecf20Sopenharmony_ci adapter = i2c_get_adapter(params[0].u.value.b); 908c2ecf20Sopenharmony_ci if (!adapter) 918c2ecf20Sopenharmony_ci goto bad; 928c2ecf20Sopenharmony_ci 938c2ecf20Sopenharmony_ci if (params[1].u.value.a & OPTEE_MSG_RPC_CMD_I2C_FLAGS_TEN_BIT) { 948c2ecf20Sopenharmony_ci if (!i2c_check_functionality(adapter, 958c2ecf20Sopenharmony_ci I2C_FUNC_10BIT_ADDR)) { 968c2ecf20Sopenharmony_ci i2c_put_adapter(adapter); 978c2ecf20Sopenharmony_ci goto bad; 988c2ecf20Sopenharmony_ci } 998c2ecf20Sopenharmony_ci 1008c2ecf20Sopenharmony_ci msg.flags = I2C_M_TEN; 1018c2ecf20Sopenharmony_ci } 1028c2ecf20Sopenharmony_ci 1038c2ecf20Sopenharmony_ci msg.addr = params[0].u.value.c; 1048c2ecf20Sopenharmony_ci msg.buf = params[2].u.memref.shm->kaddr; 1058c2ecf20Sopenharmony_ci msg.len = params[2].u.memref.size; 1068c2ecf20Sopenharmony_ci 1078c2ecf20Sopenharmony_ci switch (params[0].u.value.a) { 1088c2ecf20Sopenharmony_ci case OPTEE_MSG_RPC_CMD_I2C_TRANSFER_RD: 1098c2ecf20Sopenharmony_ci msg.flags |= I2C_M_RD; 1108c2ecf20Sopenharmony_ci break; 1118c2ecf20Sopenharmony_ci case OPTEE_MSG_RPC_CMD_I2C_TRANSFER_WR: 1128c2ecf20Sopenharmony_ci break; 1138c2ecf20Sopenharmony_ci default: 1148c2ecf20Sopenharmony_ci i2c_put_adapter(adapter); 1158c2ecf20Sopenharmony_ci goto bad; 1168c2ecf20Sopenharmony_ci } 1178c2ecf20Sopenharmony_ci 1188c2ecf20Sopenharmony_ci ret = i2c_transfer(adapter, &msg, 1); 1198c2ecf20Sopenharmony_ci 1208c2ecf20Sopenharmony_ci if (ret < 0) { 1218c2ecf20Sopenharmony_ci arg->ret = TEEC_ERROR_COMMUNICATION; 1228c2ecf20Sopenharmony_ci } else { 1238c2ecf20Sopenharmony_ci params[3].u.value.a = msg.len; 1248c2ecf20Sopenharmony_ci if (optee_to_msg_param(arg->params, arg->num_params, params)) 1258c2ecf20Sopenharmony_ci arg->ret = TEEC_ERROR_BAD_PARAMETERS; 1268c2ecf20Sopenharmony_ci else 1278c2ecf20Sopenharmony_ci arg->ret = TEEC_SUCCESS; 1288c2ecf20Sopenharmony_ci } 1298c2ecf20Sopenharmony_ci 1308c2ecf20Sopenharmony_ci i2c_put_adapter(adapter); 1318c2ecf20Sopenharmony_ci kfree(params); 1328c2ecf20Sopenharmony_ci return; 1338c2ecf20Sopenharmony_cibad: 1348c2ecf20Sopenharmony_ci kfree(params); 1358c2ecf20Sopenharmony_ci arg->ret = TEEC_ERROR_BAD_PARAMETERS; 1368c2ecf20Sopenharmony_ci} 1378c2ecf20Sopenharmony_ci#else 1388c2ecf20Sopenharmony_cistatic void handle_rpc_func_cmd_i2c_transfer(struct tee_context *ctx, 1398c2ecf20Sopenharmony_ci struct optee_msg_arg *arg) 1408c2ecf20Sopenharmony_ci{ 1418c2ecf20Sopenharmony_ci arg->ret = TEEC_ERROR_NOT_SUPPORTED; 1428c2ecf20Sopenharmony_ci} 1438c2ecf20Sopenharmony_ci#endif 1448c2ecf20Sopenharmony_ci 1458c2ecf20Sopenharmony_cistatic struct wq_entry *wq_entry_get(struct optee_wait_queue *wq, u32 key) 1468c2ecf20Sopenharmony_ci{ 1478c2ecf20Sopenharmony_ci struct wq_entry *w; 1488c2ecf20Sopenharmony_ci 1498c2ecf20Sopenharmony_ci mutex_lock(&wq->mu); 1508c2ecf20Sopenharmony_ci 1518c2ecf20Sopenharmony_ci list_for_each_entry(w, &wq->db, link) 1528c2ecf20Sopenharmony_ci if (w->key == key) 1538c2ecf20Sopenharmony_ci goto out; 1548c2ecf20Sopenharmony_ci 1558c2ecf20Sopenharmony_ci w = kmalloc(sizeof(*w), GFP_KERNEL); 1568c2ecf20Sopenharmony_ci if (w) { 1578c2ecf20Sopenharmony_ci init_completion(&w->c); 1588c2ecf20Sopenharmony_ci w->key = key; 1598c2ecf20Sopenharmony_ci list_add_tail(&w->link, &wq->db); 1608c2ecf20Sopenharmony_ci } 1618c2ecf20Sopenharmony_ciout: 1628c2ecf20Sopenharmony_ci mutex_unlock(&wq->mu); 1638c2ecf20Sopenharmony_ci return w; 1648c2ecf20Sopenharmony_ci} 1658c2ecf20Sopenharmony_ci 1668c2ecf20Sopenharmony_cistatic void wq_sleep(struct optee_wait_queue *wq, u32 key) 1678c2ecf20Sopenharmony_ci{ 1688c2ecf20Sopenharmony_ci struct wq_entry *w = wq_entry_get(wq, key); 1698c2ecf20Sopenharmony_ci 1708c2ecf20Sopenharmony_ci if (w) { 1718c2ecf20Sopenharmony_ci wait_for_completion(&w->c); 1728c2ecf20Sopenharmony_ci mutex_lock(&wq->mu); 1738c2ecf20Sopenharmony_ci list_del(&w->link); 1748c2ecf20Sopenharmony_ci mutex_unlock(&wq->mu); 1758c2ecf20Sopenharmony_ci kfree(w); 1768c2ecf20Sopenharmony_ci } 1778c2ecf20Sopenharmony_ci} 1788c2ecf20Sopenharmony_ci 1798c2ecf20Sopenharmony_cistatic void wq_wakeup(struct optee_wait_queue *wq, u32 key) 1808c2ecf20Sopenharmony_ci{ 1818c2ecf20Sopenharmony_ci struct wq_entry *w = wq_entry_get(wq, key); 1828c2ecf20Sopenharmony_ci 1838c2ecf20Sopenharmony_ci if (w) 1848c2ecf20Sopenharmony_ci complete(&w->c); 1858c2ecf20Sopenharmony_ci} 1868c2ecf20Sopenharmony_ci 1878c2ecf20Sopenharmony_cistatic void handle_rpc_func_cmd_wq(struct optee *optee, 1888c2ecf20Sopenharmony_ci struct optee_msg_arg *arg) 1898c2ecf20Sopenharmony_ci{ 1908c2ecf20Sopenharmony_ci if (arg->num_params != 1) 1918c2ecf20Sopenharmony_ci goto bad; 1928c2ecf20Sopenharmony_ci 1938c2ecf20Sopenharmony_ci if ((arg->params[0].attr & OPTEE_MSG_ATTR_TYPE_MASK) != 1948c2ecf20Sopenharmony_ci OPTEE_MSG_ATTR_TYPE_VALUE_INPUT) 1958c2ecf20Sopenharmony_ci goto bad; 1968c2ecf20Sopenharmony_ci 1978c2ecf20Sopenharmony_ci switch (arg->params[0].u.value.a) { 1988c2ecf20Sopenharmony_ci case OPTEE_MSG_RPC_WAIT_QUEUE_SLEEP: 1998c2ecf20Sopenharmony_ci wq_sleep(&optee->wait_queue, arg->params[0].u.value.b); 2008c2ecf20Sopenharmony_ci break; 2018c2ecf20Sopenharmony_ci case OPTEE_MSG_RPC_WAIT_QUEUE_WAKEUP: 2028c2ecf20Sopenharmony_ci wq_wakeup(&optee->wait_queue, arg->params[0].u.value.b); 2038c2ecf20Sopenharmony_ci break; 2048c2ecf20Sopenharmony_ci default: 2058c2ecf20Sopenharmony_ci goto bad; 2068c2ecf20Sopenharmony_ci } 2078c2ecf20Sopenharmony_ci 2088c2ecf20Sopenharmony_ci arg->ret = TEEC_SUCCESS; 2098c2ecf20Sopenharmony_ci return; 2108c2ecf20Sopenharmony_cibad: 2118c2ecf20Sopenharmony_ci arg->ret = TEEC_ERROR_BAD_PARAMETERS; 2128c2ecf20Sopenharmony_ci} 2138c2ecf20Sopenharmony_ci 2148c2ecf20Sopenharmony_cistatic void handle_rpc_func_cmd_wait(struct optee_msg_arg *arg) 2158c2ecf20Sopenharmony_ci{ 2168c2ecf20Sopenharmony_ci u32 msec_to_wait; 2178c2ecf20Sopenharmony_ci 2188c2ecf20Sopenharmony_ci if (arg->num_params != 1) 2198c2ecf20Sopenharmony_ci goto bad; 2208c2ecf20Sopenharmony_ci 2218c2ecf20Sopenharmony_ci if ((arg->params[0].attr & OPTEE_MSG_ATTR_TYPE_MASK) != 2228c2ecf20Sopenharmony_ci OPTEE_MSG_ATTR_TYPE_VALUE_INPUT) 2238c2ecf20Sopenharmony_ci goto bad; 2248c2ecf20Sopenharmony_ci 2258c2ecf20Sopenharmony_ci msec_to_wait = arg->params[0].u.value.a; 2268c2ecf20Sopenharmony_ci 2278c2ecf20Sopenharmony_ci /* Go to interruptible sleep */ 2288c2ecf20Sopenharmony_ci msleep_interruptible(msec_to_wait); 2298c2ecf20Sopenharmony_ci 2308c2ecf20Sopenharmony_ci arg->ret = TEEC_SUCCESS; 2318c2ecf20Sopenharmony_ci return; 2328c2ecf20Sopenharmony_cibad: 2338c2ecf20Sopenharmony_ci arg->ret = TEEC_ERROR_BAD_PARAMETERS; 2348c2ecf20Sopenharmony_ci} 2358c2ecf20Sopenharmony_ci 2368c2ecf20Sopenharmony_cistatic void handle_rpc_supp_cmd(struct tee_context *ctx, 2378c2ecf20Sopenharmony_ci struct optee_msg_arg *arg) 2388c2ecf20Sopenharmony_ci{ 2398c2ecf20Sopenharmony_ci struct tee_param *params; 2408c2ecf20Sopenharmony_ci 2418c2ecf20Sopenharmony_ci arg->ret_origin = TEEC_ORIGIN_COMMS; 2428c2ecf20Sopenharmony_ci 2438c2ecf20Sopenharmony_ci params = kmalloc_array(arg->num_params, sizeof(struct tee_param), 2448c2ecf20Sopenharmony_ci GFP_KERNEL); 2458c2ecf20Sopenharmony_ci if (!params) { 2468c2ecf20Sopenharmony_ci arg->ret = TEEC_ERROR_OUT_OF_MEMORY; 2478c2ecf20Sopenharmony_ci return; 2488c2ecf20Sopenharmony_ci } 2498c2ecf20Sopenharmony_ci 2508c2ecf20Sopenharmony_ci if (optee_from_msg_param(params, arg->num_params, arg->params)) { 2518c2ecf20Sopenharmony_ci arg->ret = TEEC_ERROR_BAD_PARAMETERS; 2528c2ecf20Sopenharmony_ci goto out; 2538c2ecf20Sopenharmony_ci } 2548c2ecf20Sopenharmony_ci 2558c2ecf20Sopenharmony_ci arg->ret = optee_supp_thrd_req(ctx, arg->cmd, arg->num_params, params); 2568c2ecf20Sopenharmony_ci 2578c2ecf20Sopenharmony_ci if (optee_to_msg_param(arg->params, arg->num_params, params)) 2588c2ecf20Sopenharmony_ci arg->ret = TEEC_ERROR_BAD_PARAMETERS; 2598c2ecf20Sopenharmony_ciout: 2608c2ecf20Sopenharmony_ci kfree(params); 2618c2ecf20Sopenharmony_ci} 2628c2ecf20Sopenharmony_ci 2638c2ecf20Sopenharmony_cistatic struct tee_shm *cmd_alloc_suppl(struct tee_context *ctx, size_t sz) 2648c2ecf20Sopenharmony_ci{ 2658c2ecf20Sopenharmony_ci u32 ret; 2668c2ecf20Sopenharmony_ci struct tee_param param; 2678c2ecf20Sopenharmony_ci struct optee *optee = tee_get_drvdata(ctx->teedev); 2688c2ecf20Sopenharmony_ci struct tee_shm *shm; 2698c2ecf20Sopenharmony_ci 2708c2ecf20Sopenharmony_ci param.attr = TEE_IOCTL_PARAM_ATTR_TYPE_VALUE_INOUT; 2718c2ecf20Sopenharmony_ci param.u.value.a = OPTEE_MSG_RPC_SHM_TYPE_APPL; 2728c2ecf20Sopenharmony_ci param.u.value.b = sz; 2738c2ecf20Sopenharmony_ci param.u.value.c = 0; 2748c2ecf20Sopenharmony_ci 2758c2ecf20Sopenharmony_ci ret = optee_supp_thrd_req(ctx, OPTEE_MSG_RPC_CMD_SHM_ALLOC, 1, ¶m); 2768c2ecf20Sopenharmony_ci if (ret) 2778c2ecf20Sopenharmony_ci return ERR_PTR(-ENOMEM); 2788c2ecf20Sopenharmony_ci 2798c2ecf20Sopenharmony_ci mutex_lock(&optee->supp.mutex); 2808c2ecf20Sopenharmony_ci /* Increases count as secure world doesn't have a reference */ 2818c2ecf20Sopenharmony_ci shm = tee_shm_get_from_id(optee->supp.ctx, param.u.value.c); 2828c2ecf20Sopenharmony_ci mutex_unlock(&optee->supp.mutex); 2838c2ecf20Sopenharmony_ci return shm; 2848c2ecf20Sopenharmony_ci} 2858c2ecf20Sopenharmony_ci 2868c2ecf20Sopenharmony_cistatic void handle_rpc_func_cmd_shm_alloc(struct tee_context *ctx, 2878c2ecf20Sopenharmony_ci struct optee *optee, 2888c2ecf20Sopenharmony_ci struct optee_msg_arg *arg, 2898c2ecf20Sopenharmony_ci struct optee_call_ctx *call_ctx) 2908c2ecf20Sopenharmony_ci{ 2918c2ecf20Sopenharmony_ci phys_addr_t pa; 2928c2ecf20Sopenharmony_ci struct tee_shm *shm; 2938c2ecf20Sopenharmony_ci size_t sz; 2948c2ecf20Sopenharmony_ci size_t n; 2958c2ecf20Sopenharmony_ci 2968c2ecf20Sopenharmony_ci arg->ret_origin = TEEC_ORIGIN_COMMS; 2978c2ecf20Sopenharmony_ci 2988c2ecf20Sopenharmony_ci if (!arg->num_params || 2998c2ecf20Sopenharmony_ci arg->params[0].attr != OPTEE_MSG_ATTR_TYPE_VALUE_INPUT) { 3008c2ecf20Sopenharmony_ci arg->ret = TEEC_ERROR_BAD_PARAMETERS; 3018c2ecf20Sopenharmony_ci return; 3028c2ecf20Sopenharmony_ci } 3038c2ecf20Sopenharmony_ci 3048c2ecf20Sopenharmony_ci for (n = 1; n < arg->num_params; n++) { 3058c2ecf20Sopenharmony_ci if (arg->params[n].attr != OPTEE_MSG_ATTR_TYPE_NONE) { 3068c2ecf20Sopenharmony_ci arg->ret = TEEC_ERROR_BAD_PARAMETERS; 3078c2ecf20Sopenharmony_ci return; 3088c2ecf20Sopenharmony_ci } 3098c2ecf20Sopenharmony_ci } 3108c2ecf20Sopenharmony_ci 3118c2ecf20Sopenharmony_ci sz = arg->params[0].u.value.b; 3128c2ecf20Sopenharmony_ci switch (arg->params[0].u.value.a) { 3138c2ecf20Sopenharmony_ci case OPTEE_MSG_RPC_SHM_TYPE_APPL: 3148c2ecf20Sopenharmony_ci shm = cmd_alloc_suppl(ctx, sz); 3158c2ecf20Sopenharmony_ci break; 3168c2ecf20Sopenharmony_ci case OPTEE_MSG_RPC_SHM_TYPE_KERNEL: 3178c2ecf20Sopenharmony_ci shm = tee_shm_alloc(optee->ctx, sz, 3188c2ecf20Sopenharmony_ci TEE_SHM_MAPPED | TEE_SHM_PRIV); 3198c2ecf20Sopenharmony_ci break; 3208c2ecf20Sopenharmony_ci default: 3218c2ecf20Sopenharmony_ci arg->ret = TEEC_ERROR_BAD_PARAMETERS; 3228c2ecf20Sopenharmony_ci return; 3238c2ecf20Sopenharmony_ci } 3248c2ecf20Sopenharmony_ci 3258c2ecf20Sopenharmony_ci if (IS_ERR(shm)) { 3268c2ecf20Sopenharmony_ci arg->ret = TEEC_ERROR_OUT_OF_MEMORY; 3278c2ecf20Sopenharmony_ci return; 3288c2ecf20Sopenharmony_ci } 3298c2ecf20Sopenharmony_ci 3308c2ecf20Sopenharmony_ci if (tee_shm_get_pa(shm, 0, &pa)) { 3318c2ecf20Sopenharmony_ci arg->ret = TEEC_ERROR_BAD_PARAMETERS; 3328c2ecf20Sopenharmony_ci goto bad; 3338c2ecf20Sopenharmony_ci } 3348c2ecf20Sopenharmony_ci 3358c2ecf20Sopenharmony_ci sz = tee_shm_get_size(shm); 3368c2ecf20Sopenharmony_ci 3378c2ecf20Sopenharmony_ci if (tee_shm_is_registered(shm)) { 3388c2ecf20Sopenharmony_ci struct page **pages; 3398c2ecf20Sopenharmony_ci u64 *pages_list; 3408c2ecf20Sopenharmony_ci size_t page_num; 3418c2ecf20Sopenharmony_ci 3428c2ecf20Sopenharmony_ci pages = tee_shm_get_pages(shm, &page_num); 3438c2ecf20Sopenharmony_ci if (!pages || !page_num) { 3448c2ecf20Sopenharmony_ci arg->ret = TEEC_ERROR_OUT_OF_MEMORY; 3458c2ecf20Sopenharmony_ci goto bad; 3468c2ecf20Sopenharmony_ci } 3478c2ecf20Sopenharmony_ci 3488c2ecf20Sopenharmony_ci pages_list = optee_allocate_pages_list(page_num); 3498c2ecf20Sopenharmony_ci if (!pages_list) { 3508c2ecf20Sopenharmony_ci arg->ret = TEEC_ERROR_OUT_OF_MEMORY; 3518c2ecf20Sopenharmony_ci goto bad; 3528c2ecf20Sopenharmony_ci } 3538c2ecf20Sopenharmony_ci 3548c2ecf20Sopenharmony_ci call_ctx->pages_list = pages_list; 3558c2ecf20Sopenharmony_ci call_ctx->num_entries = page_num; 3568c2ecf20Sopenharmony_ci 3578c2ecf20Sopenharmony_ci arg->params[0].attr = OPTEE_MSG_ATTR_TYPE_TMEM_OUTPUT | 3588c2ecf20Sopenharmony_ci OPTEE_MSG_ATTR_NONCONTIG; 3598c2ecf20Sopenharmony_ci /* 3608c2ecf20Sopenharmony_ci * In the least bits of u.tmem.buf_ptr we store buffer offset 3618c2ecf20Sopenharmony_ci * from 4k page, as described in OP-TEE ABI. 3628c2ecf20Sopenharmony_ci */ 3638c2ecf20Sopenharmony_ci arg->params[0].u.tmem.buf_ptr = virt_to_phys(pages_list) | 3648c2ecf20Sopenharmony_ci (tee_shm_get_page_offset(shm) & 3658c2ecf20Sopenharmony_ci (OPTEE_MSG_NONCONTIG_PAGE_SIZE - 1)); 3668c2ecf20Sopenharmony_ci arg->params[0].u.tmem.size = tee_shm_get_size(shm); 3678c2ecf20Sopenharmony_ci arg->params[0].u.tmem.shm_ref = (unsigned long)shm; 3688c2ecf20Sopenharmony_ci 3698c2ecf20Sopenharmony_ci optee_fill_pages_list(pages_list, pages, page_num, 3708c2ecf20Sopenharmony_ci tee_shm_get_page_offset(shm)); 3718c2ecf20Sopenharmony_ci } else { 3728c2ecf20Sopenharmony_ci arg->params[0].attr = OPTEE_MSG_ATTR_TYPE_TMEM_OUTPUT; 3738c2ecf20Sopenharmony_ci arg->params[0].u.tmem.buf_ptr = pa; 3748c2ecf20Sopenharmony_ci arg->params[0].u.tmem.size = sz; 3758c2ecf20Sopenharmony_ci arg->params[0].u.tmem.shm_ref = (unsigned long)shm; 3768c2ecf20Sopenharmony_ci } 3778c2ecf20Sopenharmony_ci 3788c2ecf20Sopenharmony_ci arg->ret = TEEC_SUCCESS; 3798c2ecf20Sopenharmony_ci return; 3808c2ecf20Sopenharmony_cibad: 3818c2ecf20Sopenharmony_ci tee_shm_free(shm); 3828c2ecf20Sopenharmony_ci} 3838c2ecf20Sopenharmony_ci 3848c2ecf20Sopenharmony_cistatic void cmd_free_suppl(struct tee_context *ctx, struct tee_shm *shm) 3858c2ecf20Sopenharmony_ci{ 3868c2ecf20Sopenharmony_ci struct tee_param param; 3878c2ecf20Sopenharmony_ci 3888c2ecf20Sopenharmony_ci param.attr = TEE_IOCTL_PARAM_ATTR_TYPE_VALUE_INOUT; 3898c2ecf20Sopenharmony_ci param.u.value.a = OPTEE_MSG_RPC_SHM_TYPE_APPL; 3908c2ecf20Sopenharmony_ci param.u.value.b = tee_shm_get_id(shm); 3918c2ecf20Sopenharmony_ci param.u.value.c = 0; 3928c2ecf20Sopenharmony_ci 3938c2ecf20Sopenharmony_ci /* 3948c2ecf20Sopenharmony_ci * Match the tee_shm_get_from_id() in cmd_alloc_suppl() as secure 3958c2ecf20Sopenharmony_ci * world has released its reference. 3968c2ecf20Sopenharmony_ci * 3978c2ecf20Sopenharmony_ci * It's better to do this before sending the request to supplicant 3988c2ecf20Sopenharmony_ci * as we'd like to let the process doing the initial allocation to 3998c2ecf20Sopenharmony_ci * do release the last reference too in order to avoid stacking 4008c2ecf20Sopenharmony_ci * many pending fput() on the client process. This could otherwise 4018c2ecf20Sopenharmony_ci * happen if secure world does many allocate and free in a single 4028c2ecf20Sopenharmony_ci * invoke. 4038c2ecf20Sopenharmony_ci */ 4048c2ecf20Sopenharmony_ci tee_shm_put(shm); 4058c2ecf20Sopenharmony_ci 4068c2ecf20Sopenharmony_ci optee_supp_thrd_req(ctx, OPTEE_MSG_RPC_CMD_SHM_FREE, 1, ¶m); 4078c2ecf20Sopenharmony_ci} 4088c2ecf20Sopenharmony_ci 4098c2ecf20Sopenharmony_cistatic void handle_rpc_func_cmd_shm_free(struct tee_context *ctx, 4108c2ecf20Sopenharmony_ci struct optee_msg_arg *arg) 4118c2ecf20Sopenharmony_ci{ 4128c2ecf20Sopenharmony_ci struct tee_shm *shm; 4138c2ecf20Sopenharmony_ci 4148c2ecf20Sopenharmony_ci arg->ret_origin = TEEC_ORIGIN_COMMS; 4158c2ecf20Sopenharmony_ci 4168c2ecf20Sopenharmony_ci if (arg->num_params != 1 || 4178c2ecf20Sopenharmony_ci arg->params[0].attr != OPTEE_MSG_ATTR_TYPE_VALUE_INPUT) { 4188c2ecf20Sopenharmony_ci arg->ret = TEEC_ERROR_BAD_PARAMETERS; 4198c2ecf20Sopenharmony_ci return; 4208c2ecf20Sopenharmony_ci } 4218c2ecf20Sopenharmony_ci 4228c2ecf20Sopenharmony_ci shm = (struct tee_shm *)(unsigned long)arg->params[0].u.value.b; 4238c2ecf20Sopenharmony_ci switch (arg->params[0].u.value.a) { 4248c2ecf20Sopenharmony_ci case OPTEE_MSG_RPC_SHM_TYPE_APPL: 4258c2ecf20Sopenharmony_ci cmd_free_suppl(ctx, shm); 4268c2ecf20Sopenharmony_ci break; 4278c2ecf20Sopenharmony_ci case OPTEE_MSG_RPC_SHM_TYPE_KERNEL: 4288c2ecf20Sopenharmony_ci tee_shm_free(shm); 4298c2ecf20Sopenharmony_ci break; 4308c2ecf20Sopenharmony_ci default: 4318c2ecf20Sopenharmony_ci arg->ret = TEEC_ERROR_BAD_PARAMETERS; 4328c2ecf20Sopenharmony_ci } 4338c2ecf20Sopenharmony_ci arg->ret = TEEC_SUCCESS; 4348c2ecf20Sopenharmony_ci} 4358c2ecf20Sopenharmony_ci 4368c2ecf20Sopenharmony_cistatic void free_pages_list(struct optee_call_ctx *call_ctx) 4378c2ecf20Sopenharmony_ci{ 4388c2ecf20Sopenharmony_ci if (call_ctx->pages_list) { 4398c2ecf20Sopenharmony_ci optee_free_pages_list(call_ctx->pages_list, 4408c2ecf20Sopenharmony_ci call_ctx->num_entries); 4418c2ecf20Sopenharmony_ci call_ctx->pages_list = NULL; 4428c2ecf20Sopenharmony_ci call_ctx->num_entries = 0; 4438c2ecf20Sopenharmony_ci } 4448c2ecf20Sopenharmony_ci} 4458c2ecf20Sopenharmony_ci 4468c2ecf20Sopenharmony_civoid optee_rpc_finalize_call(struct optee_call_ctx *call_ctx) 4478c2ecf20Sopenharmony_ci{ 4488c2ecf20Sopenharmony_ci free_pages_list(call_ctx); 4498c2ecf20Sopenharmony_ci} 4508c2ecf20Sopenharmony_ci 4518c2ecf20Sopenharmony_cistatic void handle_rpc_func_cmd(struct tee_context *ctx, struct optee *optee, 4528c2ecf20Sopenharmony_ci struct tee_shm *shm, 4538c2ecf20Sopenharmony_ci struct optee_call_ctx *call_ctx) 4548c2ecf20Sopenharmony_ci{ 4558c2ecf20Sopenharmony_ci struct optee_msg_arg *arg; 4568c2ecf20Sopenharmony_ci 4578c2ecf20Sopenharmony_ci arg = tee_shm_get_va(shm, 0); 4588c2ecf20Sopenharmony_ci if (IS_ERR(arg)) { 4598c2ecf20Sopenharmony_ci pr_err("%s: tee_shm_get_va %p failed\n", __func__, shm); 4608c2ecf20Sopenharmony_ci return; 4618c2ecf20Sopenharmony_ci } 4628c2ecf20Sopenharmony_ci 4638c2ecf20Sopenharmony_ci switch (arg->cmd) { 4648c2ecf20Sopenharmony_ci case OPTEE_MSG_RPC_CMD_GET_TIME: 4658c2ecf20Sopenharmony_ci handle_rpc_func_cmd_get_time(arg); 4668c2ecf20Sopenharmony_ci break; 4678c2ecf20Sopenharmony_ci case OPTEE_MSG_RPC_CMD_WAIT_QUEUE: 4688c2ecf20Sopenharmony_ci handle_rpc_func_cmd_wq(optee, arg); 4698c2ecf20Sopenharmony_ci break; 4708c2ecf20Sopenharmony_ci case OPTEE_MSG_RPC_CMD_SUSPEND: 4718c2ecf20Sopenharmony_ci handle_rpc_func_cmd_wait(arg); 4728c2ecf20Sopenharmony_ci break; 4738c2ecf20Sopenharmony_ci case OPTEE_MSG_RPC_CMD_SHM_ALLOC: 4748c2ecf20Sopenharmony_ci free_pages_list(call_ctx); 4758c2ecf20Sopenharmony_ci handle_rpc_func_cmd_shm_alloc(ctx, optee, arg, call_ctx); 4768c2ecf20Sopenharmony_ci break; 4778c2ecf20Sopenharmony_ci case OPTEE_MSG_RPC_CMD_SHM_FREE: 4788c2ecf20Sopenharmony_ci handle_rpc_func_cmd_shm_free(ctx, arg); 4798c2ecf20Sopenharmony_ci break; 4808c2ecf20Sopenharmony_ci case OPTEE_MSG_RPC_CMD_I2C_TRANSFER: 4818c2ecf20Sopenharmony_ci handle_rpc_func_cmd_i2c_transfer(ctx, arg); 4828c2ecf20Sopenharmony_ci break; 4838c2ecf20Sopenharmony_ci default: 4848c2ecf20Sopenharmony_ci handle_rpc_supp_cmd(ctx, arg); 4858c2ecf20Sopenharmony_ci } 4868c2ecf20Sopenharmony_ci} 4878c2ecf20Sopenharmony_ci 4888c2ecf20Sopenharmony_ci/** 4898c2ecf20Sopenharmony_ci * optee_handle_rpc() - handle RPC from secure world 4908c2ecf20Sopenharmony_ci * @ctx: context doing the RPC 4918c2ecf20Sopenharmony_ci * @param: value of registers for the RPC 4928c2ecf20Sopenharmony_ci * @call_ctx: call context. Preserved during one OP-TEE invocation 4938c2ecf20Sopenharmony_ci * 4948c2ecf20Sopenharmony_ci * Result of RPC is written back into @param. 4958c2ecf20Sopenharmony_ci */ 4968c2ecf20Sopenharmony_civoid optee_handle_rpc(struct tee_context *ctx, struct optee_rpc_param *param, 4978c2ecf20Sopenharmony_ci struct optee_call_ctx *call_ctx) 4988c2ecf20Sopenharmony_ci{ 4998c2ecf20Sopenharmony_ci struct tee_device *teedev = ctx->teedev; 5008c2ecf20Sopenharmony_ci struct optee *optee = tee_get_drvdata(teedev); 5018c2ecf20Sopenharmony_ci struct tee_shm *shm; 5028c2ecf20Sopenharmony_ci phys_addr_t pa; 5038c2ecf20Sopenharmony_ci 5048c2ecf20Sopenharmony_ci switch (OPTEE_SMC_RETURN_GET_RPC_FUNC(param->a0)) { 5058c2ecf20Sopenharmony_ci case OPTEE_SMC_RPC_FUNC_ALLOC: 5068c2ecf20Sopenharmony_ci shm = tee_shm_alloc(optee->ctx, param->a1, 5078c2ecf20Sopenharmony_ci TEE_SHM_MAPPED | TEE_SHM_PRIV); 5088c2ecf20Sopenharmony_ci if (!IS_ERR(shm) && !tee_shm_get_pa(shm, 0, &pa)) { 5098c2ecf20Sopenharmony_ci reg_pair_from_64(¶m->a1, ¶m->a2, pa); 5108c2ecf20Sopenharmony_ci reg_pair_from_64(¶m->a4, ¶m->a5, 5118c2ecf20Sopenharmony_ci (unsigned long)shm); 5128c2ecf20Sopenharmony_ci } else { 5138c2ecf20Sopenharmony_ci param->a1 = 0; 5148c2ecf20Sopenharmony_ci param->a2 = 0; 5158c2ecf20Sopenharmony_ci param->a4 = 0; 5168c2ecf20Sopenharmony_ci param->a5 = 0; 5178c2ecf20Sopenharmony_ci } 5188c2ecf20Sopenharmony_ci break; 5198c2ecf20Sopenharmony_ci case OPTEE_SMC_RPC_FUNC_FREE: 5208c2ecf20Sopenharmony_ci shm = reg_pair_to_ptr(param->a1, param->a2); 5218c2ecf20Sopenharmony_ci tee_shm_free(shm); 5228c2ecf20Sopenharmony_ci break; 5238c2ecf20Sopenharmony_ci case OPTEE_SMC_RPC_FUNC_FOREIGN_INTR: 5248c2ecf20Sopenharmony_ci /* 5258c2ecf20Sopenharmony_ci * A foreign interrupt was raised while secure world was 5268c2ecf20Sopenharmony_ci * executing, since they are handled in Linux a dummy RPC is 5278c2ecf20Sopenharmony_ci * performed to let Linux take the interrupt through the normal 5288c2ecf20Sopenharmony_ci * vector. 5298c2ecf20Sopenharmony_ci */ 5308c2ecf20Sopenharmony_ci break; 5318c2ecf20Sopenharmony_ci case OPTEE_SMC_RPC_FUNC_CMD: 5328c2ecf20Sopenharmony_ci shm = reg_pair_to_ptr(param->a1, param->a2); 5338c2ecf20Sopenharmony_ci handle_rpc_func_cmd(ctx, optee, shm, call_ctx); 5348c2ecf20Sopenharmony_ci break; 5358c2ecf20Sopenharmony_ci default: 5368c2ecf20Sopenharmony_ci pr_warn("Unknown RPC func 0x%x\n", 5378c2ecf20Sopenharmony_ci (u32)OPTEE_SMC_RETURN_GET_RPC_FUNC(param->a0)); 5388c2ecf20Sopenharmony_ci break; 5398c2ecf20Sopenharmony_ci } 5408c2ecf20Sopenharmony_ci 5418c2ecf20Sopenharmony_ci param->a0 = OPTEE_SMC_CALL_RETURN_FROM_RPC; 5428c2ecf20Sopenharmony_ci} 543