162306a36Sopenharmony_ci// SPDX-License-Identifier: GPL-2.0
262306a36Sopenharmony_ci/*
362306a36Sopenharmony_ci * Randomness driver for the ARM SMCCC TRNG Firmware Interface
462306a36Sopenharmony_ci * https://developer.arm.com/documentation/den0098/latest/
562306a36Sopenharmony_ci *
662306a36Sopenharmony_ci *  Copyright (C) 2020 Arm Ltd.
762306a36Sopenharmony_ci *
862306a36Sopenharmony_ci * The ARM TRNG firmware interface specifies a protocol to read entropy
962306a36Sopenharmony_ci * from a higher exception level, to abstract from any machine specific
1062306a36Sopenharmony_ci * implemenations and allow easier use in hypervisors.
1162306a36Sopenharmony_ci *
1262306a36Sopenharmony_ci * The firmware interface is realised using the SMCCC specification.
1362306a36Sopenharmony_ci */
1462306a36Sopenharmony_ci
1562306a36Sopenharmony_ci#include <linux/bits.h>
1662306a36Sopenharmony_ci#include <linux/device.h>
1762306a36Sopenharmony_ci#include <linux/hw_random.h>
1862306a36Sopenharmony_ci#include <linux/module.h>
1962306a36Sopenharmony_ci#include <linux/platform_device.h>
2062306a36Sopenharmony_ci#include <linux/arm-smccc.h>
2162306a36Sopenharmony_ci
2262306a36Sopenharmony_ci#ifdef CONFIG_ARM64
2362306a36Sopenharmony_ci#define ARM_SMCCC_TRNG_RND	ARM_SMCCC_TRNG_RND64
2462306a36Sopenharmony_ci#define MAX_BITS_PER_CALL	(3 * 64UL)
2562306a36Sopenharmony_ci#else
2662306a36Sopenharmony_ci#define ARM_SMCCC_TRNG_RND	ARM_SMCCC_TRNG_RND32
2762306a36Sopenharmony_ci#define MAX_BITS_PER_CALL	(3 * 32UL)
2862306a36Sopenharmony_ci#endif
2962306a36Sopenharmony_ci
3062306a36Sopenharmony_ci/* We don't want to allow the firmware to stall us forever. */
3162306a36Sopenharmony_ci#define SMCCC_TRNG_MAX_TRIES	20
3262306a36Sopenharmony_ci
3362306a36Sopenharmony_ci#define SMCCC_RET_TRNG_INVALID_PARAMETER	-2
3462306a36Sopenharmony_ci#define SMCCC_RET_TRNG_NO_ENTROPY		-3
3562306a36Sopenharmony_ci
3662306a36Sopenharmony_cistatic int copy_from_registers(char *buf, struct arm_smccc_res *res,
3762306a36Sopenharmony_ci			       size_t bytes)
3862306a36Sopenharmony_ci{
3962306a36Sopenharmony_ci	unsigned int chunk, copied;
4062306a36Sopenharmony_ci
4162306a36Sopenharmony_ci	if (bytes == 0)
4262306a36Sopenharmony_ci		return 0;
4362306a36Sopenharmony_ci
4462306a36Sopenharmony_ci	chunk = min(bytes, sizeof(long));
4562306a36Sopenharmony_ci	memcpy(buf, &res->a3, chunk);
4662306a36Sopenharmony_ci	copied = chunk;
4762306a36Sopenharmony_ci	if (copied >= bytes)
4862306a36Sopenharmony_ci		return copied;
4962306a36Sopenharmony_ci
5062306a36Sopenharmony_ci	chunk = min((bytes - copied), sizeof(long));
5162306a36Sopenharmony_ci	memcpy(&buf[copied], &res->a2, chunk);
5262306a36Sopenharmony_ci	copied += chunk;
5362306a36Sopenharmony_ci	if (copied >= bytes)
5462306a36Sopenharmony_ci		return copied;
5562306a36Sopenharmony_ci
5662306a36Sopenharmony_ci	chunk = min((bytes - copied), sizeof(long));
5762306a36Sopenharmony_ci	memcpy(&buf[copied], &res->a1, chunk);
5862306a36Sopenharmony_ci
5962306a36Sopenharmony_ci	return copied + chunk;
6062306a36Sopenharmony_ci}
6162306a36Sopenharmony_ci
6262306a36Sopenharmony_cistatic int smccc_trng_read(struct hwrng *rng, void *data, size_t max, bool wait)
6362306a36Sopenharmony_ci{
6462306a36Sopenharmony_ci	struct arm_smccc_res res;
6562306a36Sopenharmony_ci	u8 *buf = data;
6662306a36Sopenharmony_ci	unsigned int copied = 0;
6762306a36Sopenharmony_ci	int tries = 0;
6862306a36Sopenharmony_ci
6962306a36Sopenharmony_ci	while (copied < max) {
7062306a36Sopenharmony_ci		size_t bits = min_t(size_t, (max - copied) * BITS_PER_BYTE,
7162306a36Sopenharmony_ci				  MAX_BITS_PER_CALL);
7262306a36Sopenharmony_ci
7362306a36Sopenharmony_ci		arm_smccc_1_1_invoke(ARM_SMCCC_TRNG_RND, bits, &res);
7462306a36Sopenharmony_ci
7562306a36Sopenharmony_ci		switch ((int)res.a0) {
7662306a36Sopenharmony_ci		case SMCCC_RET_SUCCESS:
7762306a36Sopenharmony_ci			copied += copy_from_registers(buf + copied, &res,
7862306a36Sopenharmony_ci						      bits / BITS_PER_BYTE);
7962306a36Sopenharmony_ci			tries = 0;
8062306a36Sopenharmony_ci			break;
8162306a36Sopenharmony_ci		case SMCCC_RET_TRNG_NO_ENTROPY:
8262306a36Sopenharmony_ci			if (!wait)
8362306a36Sopenharmony_ci				return copied;
8462306a36Sopenharmony_ci			tries++;
8562306a36Sopenharmony_ci			if (tries >= SMCCC_TRNG_MAX_TRIES)
8662306a36Sopenharmony_ci				return copied;
8762306a36Sopenharmony_ci			cond_resched();
8862306a36Sopenharmony_ci			break;
8962306a36Sopenharmony_ci		default:
9062306a36Sopenharmony_ci			return -EIO;
9162306a36Sopenharmony_ci		}
9262306a36Sopenharmony_ci	}
9362306a36Sopenharmony_ci
9462306a36Sopenharmony_ci	return copied;
9562306a36Sopenharmony_ci}
9662306a36Sopenharmony_ci
9762306a36Sopenharmony_cistatic int smccc_trng_probe(struct platform_device *pdev)
9862306a36Sopenharmony_ci{
9962306a36Sopenharmony_ci	struct hwrng *trng;
10062306a36Sopenharmony_ci
10162306a36Sopenharmony_ci	trng = devm_kzalloc(&pdev->dev, sizeof(*trng), GFP_KERNEL);
10262306a36Sopenharmony_ci	if (!trng)
10362306a36Sopenharmony_ci		return -ENOMEM;
10462306a36Sopenharmony_ci
10562306a36Sopenharmony_ci	trng->name = "smccc_trng";
10662306a36Sopenharmony_ci	trng->read = smccc_trng_read;
10762306a36Sopenharmony_ci
10862306a36Sopenharmony_ci	return devm_hwrng_register(&pdev->dev, trng);
10962306a36Sopenharmony_ci}
11062306a36Sopenharmony_ci
11162306a36Sopenharmony_cistatic struct platform_driver smccc_trng_driver = {
11262306a36Sopenharmony_ci	.driver = {
11362306a36Sopenharmony_ci		.name		= "smccc_trng",
11462306a36Sopenharmony_ci	},
11562306a36Sopenharmony_ci	.probe		= smccc_trng_probe,
11662306a36Sopenharmony_ci};
11762306a36Sopenharmony_cimodule_platform_driver(smccc_trng_driver);
11862306a36Sopenharmony_ci
11962306a36Sopenharmony_ciMODULE_ALIAS("platform:smccc_trng");
12062306a36Sopenharmony_ciMODULE_AUTHOR("Andre Przywara");
12162306a36Sopenharmony_ciMODULE_LICENSE("GPL");
122