162306a36Sopenharmony_ci// SPDX-License-Identifier: GPL-2.0-only
262306a36Sopenharmony_ci/*
362306a36Sopenharmony_ci * Copyright (c) 2015-2016, Linaro Limited
462306a36Sopenharmony_ci */
562306a36Sopenharmony_ci
662306a36Sopenharmony_ci#define pr_fmt(fmt) "%s: " fmt, __func__
762306a36Sopenharmony_ci
862306a36Sopenharmony_ci#include <linux/cdev.h>
962306a36Sopenharmony_ci#include <linux/cred.h>
1062306a36Sopenharmony_ci#include <linux/fs.h>
1162306a36Sopenharmony_ci#include <linux/idr.h>
1262306a36Sopenharmony_ci#include <linux/module.h>
1362306a36Sopenharmony_ci#include <linux/slab.h>
1462306a36Sopenharmony_ci#include <linux/tee_drv.h>
1562306a36Sopenharmony_ci#include <linux/uaccess.h>
1662306a36Sopenharmony_ci#include <crypto/hash.h>
1762306a36Sopenharmony_ci#include <crypto/sha1.h>
1862306a36Sopenharmony_ci#include "tee_private.h"
1962306a36Sopenharmony_ci
2062306a36Sopenharmony_ci#define TEE_NUM_DEVICES	32
2162306a36Sopenharmony_ci
2262306a36Sopenharmony_ci#define TEE_IOCTL_PARAM_SIZE(x) (sizeof(struct tee_param) * (x))
2362306a36Sopenharmony_ci
2462306a36Sopenharmony_ci#define TEE_UUID_NS_NAME_SIZE	128
2562306a36Sopenharmony_ci
2662306a36Sopenharmony_ci/*
2762306a36Sopenharmony_ci * TEE Client UUID name space identifier (UUIDv4)
2862306a36Sopenharmony_ci *
2962306a36Sopenharmony_ci * Value here is random UUID that is allocated as name space identifier for
3062306a36Sopenharmony_ci * forming Client UUID's for TEE environment using UUIDv5 scheme.
3162306a36Sopenharmony_ci */
3262306a36Sopenharmony_cistatic const uuid_t tee_client_uuid_ns = UUID_INIT(0x58ac9ca0, 0x2086, 0x4683,
3362306a36Sopenharmony_ci						   0xa1, 0xb8, 0xec, 0x4b,
3462306a36Sopenharmony_ci						   0xc0, 0x8e, 0x01, 0xb6);
3562306a36Sopenharmony_ci
3662306a36Sopenharmony_ci/*
3762306a36Sopenharmony_ci * Unprivileged devices in the lower half range and privileged devices in
3862306a36Sopenharmony_ci * the upper half range.
3962306a36Sopenharmony_ci */
4062306a36Sopenharmony_cistatic DECLARE_BITMAP(dev_mask, TEE_NUM_DEVICES);
4162306a36Sopenharmony_cistatic DEFINE_SPINLOCK(driver_lock);
4262306a36Sopenharmony_ci
4362306a36Sopenharmony_cistatic struct class *tee_class;
4462306a36Sopenharmony_cistatic dev_t tee_devt;
4562306a36Sopenharmony_ci
4662306a36Sopenharmony_cistruct tee_context *teedev_open(struct tee_device *teedev)
4762306a36Sopenharmony_ci{
4862306a36Sopenharmony_ci	int rc;
4962306a36Sopenharmony_ci	struct tee_context *ctx;
5062306a36Sopenharmony_ci
5162306a36Sopenharmony_ci	if (!tee_device_get(teedev))
5262306a36Sopenharmony_ci		return ERR_PTR(-EINVAL);
5362306a36Sopenharmony_ci
5462306a36Sopenharmony_ci	ctx = kzalloc(sizeof(*ctx), GFP_KERNEL);
5562306a36Sopenharmony_ci	if (!ctx) {
5662306a36Sopenharmony_ci		rc = -ENOMEM;
5762306a36Sopenharmony_ci		goto err;
5862306a36Sopenharmony_ci	}
5962306a36Sopenharmony_ci
6062306a36Sopenharmony_ci	kref_init(&ctx->refcount);
6162306a36Sopenharmony_ci	ctx->teedev = teedev;
6262306a36Sopenharmony_ci	rc = teedev->desc->ops->open(ctx);
6362306a36Sopenharmony_ci	if (rc)
6462306a36Sopenharmony_ci		goto err;
6562306a36Sopenharmony_ci
6662306a36Sopenharmony_ci	return ctx;
6762306a36Sopenharmony_cierr:
6862306a36Sopenharmony_ci	kfree(ctx);
6962306a36Sopenharmony_ci	tee_device_put(teedev);
7062306a36Sopenharmony_ci	return ERR_PTR(rc);
7162306a36Sopenharmony_ci
7262306a36Sopenharmony_ci}
7362306a36Sopenharmony_ciEXPORT_SYMBOL_GPL(teedev_open);
7462306a36Sopenharmony_ci
7562306a36Sopenharmony_civoid teedev_ctx_get(struct tee_context *ctx)
7662306a36Sopenharmony_ci{
7762306a36Sopenharmony_ci	if (ctx->releasing)
7862306a36Sopenharmony_ci		return;
7962306a36Sopenharmony_ci
8062306a36Sopenharmony_ci	kref_get(&ctx->refcount);
8162306a36Sopenharmony_ci}
8262306a36Sopenharmony_ci
8362306a36Sopenharmony_cistatic void teedev_ctx_release(struct kref *ref)
8462306a36Sopenharmony_ci{
8562306a36Sopenharmony_ci	struct tee_context *ctx = container_of(ref, struct tee_context,
8662306a36Sopenharmony_ci					       refcount);
8762306a36Sopenharmony_ci	ctx->releasing = true;
8862306a36Sopenharmony_ci	ctx->teedev->desc->ops->release(ctx);
8962306a36Sopenharmony_ci	kfree(ctx);
9062306a36Sopenharmony_ci}
9162306a36Sopenharmony_ci
9262306a36Sopenharmony_civoid teedev_ctx_put(struct tee_context *ctx)
9362306a36Sopenharmony_ci{
9462306a36Sopenharmony_ci	if (ctx->releasing)
9562306a36Sopenharmony_ci		return;
9662306a36Sopenharmony_ci
9762306a36Sopenharmony_ci	kref_put(&ctx->refcount, teedev_ctx_release);
9862306a36Sopenharmony_ci}
9962306a36Sopenharmony_ci
10062306a36Sopenharmony_civoid teedev_close_context(struct tee_context *ctx)
10162306a36Sopenharmony_ci{
10262306a36Sopenharmony_ci	struct tee_device *teedev = ctx->teedev;
10362306a36Sopenharmony_ci
10462306a36Sopenharmony_ci	teedev_ctx_put(ctx);
10562306a36Sopenharmony_ci	tee_device_put(teedev);
10662306a36Sopenharmony_ci}
10762306a36Sopenharmony_ciEXPORT_SYMBOL_GPL(teedev_close_context);
10862306a36Sopenharmony_ci
10962306a36Sopenharmony_cistatic int tee_open(struct inode *inode, struct file *filp)
11062306a36Sopenharmony_ci{
11162306a36Sopenharmony_ci	struct tee_context *ctx;
11262306a36Sopenharmony_ci
11362306a36Sopenharmony_ci	ctx = teedev_open(container_of(inode->i_cdev, struct tee_device, cdev));
11462306a36Sopenharmony_ci	if (IS_ERR(ctx))
11562306a36Sopenharmony_ci		return PTR_ERR(ctx);
11662306a36Sopenharmony_ci
11762306a36Sopenharmony_ci	/*
11862306a36Sopenharmony_ci	 * Default user-space behaviour is to wait for tee-supplicant
11962306a36Sopenharmony_ci	 * if not present for any requests in this context.
12062306a36Sopenharmony_ci	 */
12162306a36Sopenharmony_ci	ctx->supp_nowait = false;
12262306a36Sopenharmony_ci	filp->private_data = ctx;
12362306a36Sopenharmony_ci	return 0;
12462306a36Sopenharmony_ci}
12562306a36Sopenharmony_ci
12662306a36Sopenharmony_cistatic int tee_release(struct inode *inode, struct file *filp)
12762306a36Sopenharmony_ci{
12862306a36Sopenharmony_ci	teedev_close_context(filp->private_data);
12962306a36Sopenharmony_ci	return 0;
13062306a36Sopenharmony_ci}
13162306a36Sopenharmony_ci
13262306a36Sopenharmony_ci/**
13362306a36Sopenharmony_ci * uuid_v5() - Calculate UUIDv5
13462306a36Sopenharmony_ci * @uuid: Resulting UUID
13562306a36Sopenharmony_ci * @ns: Name space ID for UUIDv5 function
13662306a36Sopenharmony_ci * @name: Name for UUIDv5 function
13762306a36Sopenharmony_ci * @size: Size of name
13862306a36Sopenharmony_ci *
13962306a36Sopenharmony_ci * UUIDv5 is specific in RFC 4122.
14062306a36Sopenharmony_ci *
14162306a36Sopenharmony_ci * This implements section (for SHA-1):
14262306a36Sopenharmony_ci * 4.3.  Algorithm for Creating a Name-Based UUID
14362306a36Sopenharmony_ci */
14462306a36Sopenharmony_cistatic int uuid_v5(uuid_t *uuid, const uuid_t *ns, const void *name,
14562306a36Sopenharmony_ci		   size_t size)
14662306a36Sopenharmony_ci{
14762306a36Sopenharmony_ci	unsigned char hash[SHA1_DIGEST_SIZE];
14862306a36Sopenharmony_ci	struct crypto_shash *shash = NULL;
14962306a36Sopenharmony_ci	struct shash_desc *desc = NULL;
15062306a36Sopenharmony_ci	int rc;
15162306a36Sopenharmony_ci
15262306a36Sopenharmony_ci	shash = crypto_alloc_shash("sha1", 0, 0);
15362306a36Sopenharmony_ci	if (IS_ERR(shash)) {
15462306a36Sopenharmony_ci		rc = PTR_ERR(shash);
15562306a36Sopenharmony_ci		pr_err("shash(sha1) allocation failed\n");
15662306a36Sopenharmony_ci		return rc;
15762306a36Sopenharmony_ci	}
15862306a36Sopenharmony_ci
15962306a36Sopenharmony_ci	desc = kzalloc(sizeof(*desc) + crypto_shash_descsize(shash),
16062306a36Sopenharmony_ci		       GFP_KERNEL);
16162306a36Sopenharmony_ci	if (!desc) {
16262306a36Sopenharmony_ci		rc = -ENOMEM;
16362306a36Sopenharmony_ci		goto out_free_shash;
16462306a36Sopenharmony_ci	}
16562306a36Sopenharmony_ci
16662306a36Sopenharmony_ci	desc->tfm = shash;
16762306a36Sopenharmony_ci
16862306a36Sopenharmony_ci	rc = crypto_shash_init(desc);
16962306a36Sopenharmony_ci	if (rc < 0)
17062306a36Sopenharmony_ci		goto out_free_desc;
17162306a36Sopenharmony_ci
17262306a36Sopenharmony_ci	rc = crypto_shash_update(desc, (const u8 *)ns, sizeof(*ns));
17362306a36Sopenharmony_ci	if (rc < 0)
17462306a36Sopenharmony_ci		goto out_free_desc;
17562306a36Sopenharmony_ci
17662306a36Sopenharmony_ci	rc = crypto_shash_update(desc, (const u8 *)name, size);
17762306a36Sopenharmony_ci	if (rc < 0)
17862306a36Sopenharmony_ci		goto out_free_desc;
17962306a36Sopenharmony_ci
18062306a36Sopenharmony_ci	rc = crypto_shash_final(desc, hash);
18162306a36Sopenharmony_ci	if (rc < 0)
18262306a36Sopenharmony_ci		goto out_free_desc;
18362306a36Sopenharmony_ci
18462306a36Sopenharmony_ci	memcpy(uuid->b, hash, UUID_SIZE);
18562306a36Sopenharmony_ci
18662306a36Sopenharmony_ci	/* Tag for version 5 */
18762306a36Sopenharmony_ci	uuid->b[6] = (hash[6] & 0x0F) | 0x50;
18862306a36Sopenharmony_ci	uuid->b[8] = (hash[8] & 0x3F) | 0x80;
18962306a36Sopenharmony_ci
19062306a36Sopenharmony_ciout_free_desc:
19162306a36Sopenharmony_ci	kfree(desc);
19262306a36Sopenharmony_ci
19362306a36Sopenharmony_ciout_free_shash:
19462306a36Sopenharmony_ci	crypto_free_shash(shash);
19562306a36Sopenharmony_ci	return rc;
19662306a36Sopenharmony_ci}
19762306a36Sopenharmony_ci
19862306a36Sopenharmony_ciint tee_session_calc_client_uuid(uuid_t *uuid, u32 connection_method,
19962306a36Sopenharmony_ci				 const u8 connection_data[TEE_IOCTL_UUID_LEN])
20062306a36Sopenharmony_ci{
20162306a36Sopenharmony_ci	gid_t ns_grp = (gid_t)-1;
20262306a36Sopenharmony_ci	kgid_t grp = INVALID_GID;
20362306a36Sopenharmony_ci	char *name = NULL;
20462306a36Sopenharmony_ci	int name_len;
20562306a36Sopenharmony_ci	int rc;
20662306a36Sopenharmony_ci
20762306a36Sopenharmony_ci	if (connection_method == TEE_IOCTL_LOGIN_PUBLIC ||
20862306a36Sopenharmony_ci	    connection_method == TEE_IOCTL_LOGIN_REE_KERNEL) {
20962306a36Sopenharmony_ci		/* Nil UUID to be passed to TEE environment */
21062306a36Sopenharmony_ci		uuid_copy(uuid, &uuid_null);
21162306a36Sopenharmony_ci		return 0;
21262306a36Sopenharmony_ci	}
21362306a36Sopenharmony_ci
21462306a36Sopenharmony_ci	/*
21562306a36Sopenharmony_ci	 * In Linux environment client UUID is based on UUIDv5.
21662306a36Sopenharmony_ci	 *
21762306a36Sopenharmony_ci	 * Determine client UUID with following semantics for 'name':
21862306a36Sopenharmony_ci	 *
21962306a36Sopenharmony_ci	 * For TEEC_LOGIN_USER:
22062306a36Sopenharmony_ci	 * uid=<uid>
22162306a36Sopenharmony_ci	 *
22262306a36Sopenharmony_ci	 * For TEEC_LOGIN_GROUP:
22362306a36Sopenharmony_ci	 * gid=<gid>
22462306a36Sopenharmony_ci	 *
22562306a36Sopenharmony_ci	 */
22662306a36Sopenharmony_ci
22762306a36Sopenharmony_ci	name = kzalloc(TEE_UUID_NS_NAME_SIZE, GFP_KERNEL);
22862306a36Sopenharmony_ci	if (!name)
22962306a36Sopenharmony_ci		return -ENOMEM;
23062306a36Sopenharmony_ci
23162306a36Sopenharmony_ci	switch (connection_method) {
23262306a36Sopenharmony_ci	case TEE_IOCTL_LOGIN_USER:
23362306a36Sopenharmony_ci		name_len = snprintf(name, TEE_UUID_NS_NAME_SIZE, "uid=%x",
23462306a36Sopenharmony_ci				    current_euid().val);
23562306a36Sopenharmony_ci		if (name_len >= TEE_UUID_NS_NAME_SIZE) {
23662306a36Sopenharmony_ci			rc = -E2BIG;
23762306a36Sopenharmony_ci			goto out_free_name;
23862306a36Sopenharmony_ci		}
23962306a36Sopenharmony_ci		break;
24062306a36Sopenharmony_ci
24162306a36Sopenharmony_ci	case TEE_IOCTL_LOGIN_GROUP:
24262306a36Sopenharmony_ci		memcpy(&ns_grp, connection_data, sizeof(gid_t));
24362306a36Sopenharmony_ci		grp = make_kgid(current_user_ns(), ns_grp);
24462306a36Sopenharmony_ci		if (!gid_valid(grp) || !in_egroup_p(grp)) {
24562306a36Sopenharmony_ci			rc = -EPERM;
24662306a36Sopenharmony_ci			goto out_free_name;
24762306a36Sopenharmony_ci		}
24862306a36Sopenharmony_ci
24962306a36Sopenharmony_ci		name_len = snprintf(name, TEE_UUID_NS_NAME_SIZE, "gid=%x",
25062306a36Sopenharmony_ci				    grp.val);
25162306a36Sopenharmony_ci		if (name_len >= TEE_UUID_NS_NAME_SIZE) {
25262306a36Sopenharmony_ci			rc = -E2BIG;
25362306a36Sopenharmony_ci			goto out_free_name;
25462306a36Sopenharmony_ci		}
25562306a36Sopenharmony_ci		break;
25662306a36Sopenharmony_ci
25762306a36Sopenharmony_ci	default:
25862306a36Sopenharmony_ci		rc = -EINVAL;
25962306a36Sopenharmony_ci		goto out_free_name;
26062306a36Sopenharmony_ci	}
26162306a36Sopenharmony_ci
26262306a36Sopenharmony_ci	rc = uuid_v5(uuid, &tee_client_uuid_ns, name, name_len);
26362306a36Sopenharmony_ciout_free_name:
26462306a36Sopenharmony_ci	kfree(name);
26562306a36Sopenharmony_ci
26662306a36Sopenharmony_ci	return rc;
26762306a36Sopenharmony_ci}
26862306a36Sopenharmony_ciEXPORT_SYMBOL_GPL(tee_session_calc_client_uuid);
26962306a36Sopenharmony_ci
27062306a36Sopenharmony_cistatic int tee_ioctl_version(struct tee_context *ctx,
27162306a36Sopenharmony_ci			     struct tee_ioctl_version_data __user *uvers)
27262306a36Sopenharmony_ci{
27362306a36Sopenharmony_ci	struct tee_ioctl_version_data vers;
27462306a36Sopenharmony_ci
27562306a36Sopenharmony_ci	ctx->teedev->desc->ops->get_version(ctx->teedev, &vers);
27662306a36Sopenharmony_ci
27762306a36Sopenharmony_ci	if (ctx->teedev->desc->flags & TEE_DESC_PRIVILEGED)
27862306a36Sopenharmony_ci		vers.gen_caps |= TEE_GEN_CAP_PRIVILEGED;
27962306a36Sopenharmony_ci
28062306a36Sopenharmony_ci	if (copy_to_user(uvers, &vers, sizeof(vers)))
28162306a36Sopenharmony_ci		return -EFAULT;
28262306a36Sopenharmony_ci
28362306a36Sopenharmony_ci	return 0;
28462306a36Sopenharmony_ci}
28562306a36Sopenharmony_ci
28662306a36Sopenharmony_cistatic int tee_ioctl_shm_alloc(struct tee_context *ctx,
28762306a36Sopenharmony_ci			       struct tee_ioctl_shm_alloc_data __user *udata)
28862306a36Sopenharmony_ci{
28962306a36Sopenharmony_ci	long ret;
29062306a36Sopenharmony_ci	struct tee_ioctl_shm_alloc_data data;
29162306a36Sopenharmony_ci	struct tee_shm *shm;
29262306a36Sopenharmony_ci
29362306a36Sopenharmony_ci	if (copy_from_user(&data, udata, sizeof(data)))
29462306a36Sopenharmony_ci		return -EFAULT;
29562306a36Sopenharmony_ci
29662306a36Sopenharmony_ci	/* Currently no input flags are supported */
29762306a36Sopenharmony_ci	if (data.flags)
29862306a36Sopenharmony_ci		return -EINVAL;
29962306a36Sopenharmony_ci
30062306a36Sopenharmony_ci	shm = tee_shm_alloc_user_buf(ctx, data.size);
30162306a36Sopenharmony_ci	if (IS_ERR(shm))
30262306a36Sopenharmony_ci		return PTR_ERR(shm);
30362306a36Sopenharmony_ci
30462306a36Sopenharmony_ci	data.id = shm->id;
30562306a36Sopenharmony_ci	data.size = shm->size;
30662306a36Sopenharmony_ci
30762306a36Sopenharmony_ci	if (copy_to_user(udata, &data, sizeof(data)))
30862306a36Sopenharmony_ci		ret = -EFAULT;
30962306a36Sopenharmony_ci	else
31062306a36Sopenharmony_ci		ret = tee_shm_get_fd(shm);
31162306a36Sopenharmony_ci
31262306a36Sopenharmony_ci	/*
31362306a36Sopenharmony_ci	 * When user space closes the file descriptor the shared memory
31462306a36Sopenharmony_ci	 * should be freed or if tee_shm_get_fd() failed then it will
31562306a36Sopenharmony_ci	 * be freed immediately.
31662306a36Sopenharmony_ci	 */
31762306a36Sopenharmony_ci	tee_shm_put(shm);
31862306a36Sopenharmony_ci	return ret;
31962306a36Sopenharmony_ci}
32062306a36Sopenharmony_ci
32162306a36Sopenharmony_cistatic int
32262306a36Sopenharmony_citee_ioctl_shm_register(struct tee_context *ctx,
32362306a36Sopenharmony_ci		       struct tee_ioctl_shm_register_data __user *udata)
32462306a36Sopenharmony_ci{
32562306a36Sopenharmony_ci	long ret;
32662306a36Sopenharmony_ci	struct tee_ioctl_shm_register_data data;
32762306a36Sopenharmony_ci	struct tee_shm *shm;
32862306a36Sopenharmony_ci
32962306a36Sopenharmony_ci	if (copy_from_user(&data, udata, sizeof(data)))
33062306a36Sopenharmony_ci		return -EFAULT;
33162306a36Sopenharmony_ci
33262306a36Sopenharmony_ci	/* Currently no input flags are supported */
33362306a36Sopenharmony_ci	if (data.flags)
33462306a36Sopenharmony_ci		return -EINVAL;
33562306a36Sopenharmony_ci
33662306a36Sopenharmony_ci	shm = tee_shm_register_user_buf(ctx, data.addr, data.length);
33762306a36Sopenharmony_ci	if (IS_ERR(shm))
33862306a36Sopenharmony_ci		return PTR_ERR(shm);
33962306a36Sopenharmony_ci
34062306a36Sopenharmony_ci	data.id = shm->id;
34162306a36Sopenharmony_ci	data.length = shm->size;
34262306a36Sopenharmony_ci
34362306a36Sopenharmony_ci	if (copy_to_user(udata, &data, sizeof(data)))
34462306a36Sopenharmony_ci		ret = -EFAULT;
34562306a36Sopenharmony_ci	else
34662306a36Sopenharmony_ci		ret = tee_shm_get_fd(shm);
34762306a36Sopenharmony_ci	/*
34862306a36Sopenharmony_ci	 * When user space closes the file descriptor the shared memory
34962306a36Sopenharmony_ci	 * should be freed or if tee_shm_get_fd() failed then it will
35062306a36Sopenharmony_ci	 * be freed immediately.
35162306a36Sopenharmony_ci	 */
35262306a36Sopenharmony_ci	tee_shm_put(shm);
35362306a36Sopenharmony_ci	return ret;
35462306a36Sopenharmony_ci}
35562306a36Sopenharmony_ci
35662306a36Sopenharmony_cistatic int params_from_user(struct tee_context *ctx, struct tee_param *params,
35762306a36Sopenharmony_ci			    size_t num_params,
35862306a36Sopenharmony_ci			    struct tee_ioctl_param __user *uparams)
35962306a36Sopenharmony_ci{
36062306a36Sopenharmony_ci	size_t n;
36162306a36Sopenharmony_ci
36262306a36Sopenharmony_ci	for (n = 0; n < num_params; n++) {
36362306a36Sopenharmony_ci		struct tee_shm *shm;
36462306a36Sopenharmony_ci		struct tee_ioctl_param ip;
36562306a36Sopenharmony_ci
36662306a36Sopenharmony_ci		if (copy_from_user(&ip, uparams + n, sizeof(ip)))
36762306a36Sopenharmony_ci			return -EFAULT;
36862306a36Sopenharmony_ci
36962306a36Sopenharmony_ci		/* All unused attribute bits has to be zero */
37062306a36Sopenharmony_ci		if (ip.attr & ~TEE_IOCTL_PARAM_ATTR_MASK)
37162306a36Sopenharmony_ci			return -EINVAL;
37262306a36Sopenharmony_ci
37362306a36Sopenharmony_ci		params[n].attr = ip.attr;
37462306a36Sopenharmony_ci		switch (ip.attr & TEE_IOCTL_PARAM_ATTR_TYPE_MASK) {
37562306a36Sopenharmony_ci		case TEE_IOCTL_PARAM_ATTR_TYPE_NONE:
37662306a36Sopenharmony_ci		case TEE_IOCTL_PARAM_ATTR_TYPE_VALUE_OUTPUT:
37762306a36Sopenharmony_ci			break;
37862306a36Sopenharmony_ci		case TEE_IOCTL_PARAM_ATTR_TYPE_VALUE_INPUT:
37962306a36Sopenharmony_ci		case TEE_IOCTL_PARAM_ATTR_TYPE_VALUE_INOUT:
38062306a36Sopenharmony_ci			params[n].u.value.a = ip.a;
38162306a36Sopenharmony_ci			params[n].u.value.b = ip.b;
38262306a36Sopenharmony_ci			params[n].u.value.c = ip.c;
38362306a36Sopenharmony_ci			break;
38462306a36Sopenharmony_ci		case TEE_IOCTL_PARAM_ATTR_TYPE_MEMREF_INPUT:
38562306a36Sopenharmony_ci		case TEE_IOCTL_PARAM_ATTR_TYPE_MEMREF_OUTPUT:
38662306a36Sopenharmony_ci		case TEE_IOCTL_PARAM_ATTR_TYPE_MEMREF_INOUT:
38762306a36Sopenharmony_ci			/*
38862306a36Sopenharmony_ci			 * If a NULL pointer is passed to a TA in the TEE,
38962306a36Sopenharmony_ci			 * the ip.c IOCTL parameters is set to TEE_MEMREF_NULL
39062306a36Sopenharmony_ci			 * indicating a NULL memory reference.
39162306a36Sopenharmony_ci			 */
39262306a36Sopenharmony_ci			if (ip.c != TEE_MEMREF_NULL) {
39362306a36Sopenharmony_ci				/*
39462306a36Sopenharmony_ci				 * If we fail to get a pointer to a shared
39562306a36Sopenharmony_ci				 * memory object (and increase the ref count)
39662306a36Sopenharmony_ci				 * from an identifier we return an error. All
39762306a36Sopenharmony_ci				 * pointers that has been added in params have
39862306a36Sopenharmony_ci				 * an increased ref count. It's the callers
39962306a36Sopenharmony_ci				 * responibility to do tee_shm_put() on all
40062306a36Sopenharmony_ci				 * resolved pointers.
40162306a36Sopenharmony_ci				 */
40262306a36Sopenharmony_ci				shm = tee_shm_get_from_id(ctx, ip.c);
40362306a36Sopenharmony_ci				if (IS_ERR(shm))
40462306a36Sopenharmony_ci					return PTR_ERR(shm);
40562306a36Sopenharmony_ci
40662306a36Sopenharmony_ci				/*
40762306a36Sopenharmony_ci				 * Ensure offset + size does not overflow
40862306a36Sopenharmony_ci				 * offset and does not overflow the size of
40962306a36Sopenharmony_ci				 * the referred shared memory object.
41062306a36Sopenharmony_ci				 */
41162306a36Sopenharmony_ci				if ((ip.a + ip.b) < ip.a ||
41262306a36Sopenharmony_ci				    (ip.a + ip.b) > shm->size) {
41362306a36Sopenharmony_ci					tee_shm_put(shm);
41462306a36Sopenharmony_ci					return -EINVAL;
41562306a36Sopenharmony_ci				}
41662306a36Sopenharmony_ci			} else if (ctx->cap_memref_null) {
41762306a36Sopenharmony_ci				/* Pass NULL pointer to OP-TEE */
41862306a36Sopenharmony_ci				shm = NULL;
41962306a36Sopenharmony_ci			} else {
42062306a36Sopenharmony_ci				return -EINVAL;
42162306a36Sopenharmony_ci			}
42262306a36Sopenharmony_ci
42362306a36Sopenharmony_ci			params[n].u.memref.shm_offs = ip.a;
42462306a36Sopenharmony_ci			params[n].u.memref.size = ip.b;
42562306a36Sopenharmony_ci			params[n].u.memref.shm = shm;
42662306a36Sopenharmony_ci			break;
42762306a36Sopenharmony_ci		default:
42862306a36Sopenharmony_ci			/* Unknown attribute */
42962306a36Sopenharmony_ci			return -EINVAL;
43062306a36Sopenharmony_ci		}
43162306a36Sopenharmony_ci	}
43262306a36Sopenharmony_ci	return 0;
43362306a36Sopenharmony_ci}
43462306a36Sopenharmony_ci
43562306a36Sopenharmony_cistatic int params_to_user(struct tee_ioctl_param __user *uparams,
43662306a36Sopenharmony_ci			  size_t num_params, struct tee_param *params)
43762306a36Sopenharmony_ci{
43862306a36Sopenharmony_ci	size_t n;
43962306a36Sopenharmony_ci
44062306a36Sopenharmony_ci	for (n = 0; n < num_params; n++) {
44162306a36Sopenharmony_ci		struct tee_ioctl_param __user *up = uparams + n;
44262306a36Sopenharmony_ci		struct tee_param *p = params + n;
44362306a36Sopenharmony_ci
44462306a36Sopenharmony_ci		switch (p->attr) {
44562306a36Sopenharmony_ci		case TEE_IOCTL_PARAM_ATTR_TYPE_VALUE_OUTPUT:
44662306a36Sopenharmony_ci		case TEE_IOCTL_PARAM_ATTR_TYPE_VALUE_INOUT:
44762306a36Sopenharmony_ci			if (put_user(p->u.value.a, &up->a) ||
44862306a36Sopenharmony_ci			    put_user(p->u.value.b, &up->b) ||
44962306a36Sopenharmony_ci			    put_user(p->u.value.c, &up->c))
45062306a36Sopenharmony_ci				return -EFAULT;
45162306a36Sopenharmony_ci			break;
45262306a36Sopenharmony_ci		case TEE_IOCTL_PARAM_ATTR_TYPE_MEMREF_OUTPUT:
45362306a36Sopenharmony_ci		case TEE_IOCTL_PARAM_ATTR_TYPE_MEMREF_INOUT:
45462306a36Sopenharmony_ci			if (put_user((u64)p->u.memref.size, &up->b))
45562306a36Sopenharmony_ci				return -EFAULT;
45662306a36Sopenharmony_ci			break;
45762306a36Sopenharmony_ci		default:
45862306a36Sopenharmony_ci			break;
45962306a36Sopenharmony_ci		}
46062306a36Sopenharmony_ci	}
46162306a36Sopenharmony_ci	return 0;
46262306a36Sopenharmony_ci}
46362306a36Sopenharmony_ci
46462306a36Sopenharmony_cistatic int tee_ioctl_open_session(struct tee_context *ctx,
46562306a36Sopenharmony_ci				  struct tee_ioctl_buf_data __user *ubuf)
46662306a36Sopenharmony_ci{
46762306a36Sopenharmony_ci	int rc;
46862306a36Sopenharmony_ci	size_t n;
46962306a36Sopenharmony_ci	struct tee_ioctl_buf_data buf;
47062306a36Sopenharmony_ci	struct tee_ioctl_open_session_arg __user *uarg;
47162306a36Sopenharmony_ci	struct tee_ioctl_open_session_arg arg;
47262306a36Sopenharmony_ci	struct tee_ioctl_param __user *uparams = NULL;
47362306a36Sopenharmony_ci	struct tee_param *params = NULL;
47462306a36Sopenharmony_ci	bool have_session = false;
47562306a36Sopenharmony_ci
47662306a36Sopenharmony_ci	if (!ctx->teedev->desc->ops->open_session)
47762306a36Sopenharmony_ci		return -EINVAL;
47862306a36Sopenharmony_ci
47962306a36Sopenharmony_ci	if (copy_from_user(&buf, ubuf, sizeof(buf)))
48062306a36Sopenharmony_ci		return -EFAULT;
48162306a36Sopenharmony_ci
48262306a36Sopenharmony_ci	if (buf.buf_len > TEE_MAX_ARG_SIZE ||
48362306a36Sopenharmony_ci	    buf.buf_len < sizeof(struct tee_ioctl_open_session_arg))
48462306a36Sopenharmony_ci		return -EINVAL;
48562306a36Sopenharmony_ci
48662306a36Sopenharmony_ci	uarg = u64_to_user_ptr(buf.buf_ptr);
48762306a36Sopenharmony_ci	if (copy_from_user(&arg, uarg, sizeof(arg)))
48862306a36Sopenharmony_ci		return -EFAULT;
48962306a36Sopenharmony_ci
49062306a36Sopenharmony_ci	if (sizeof(arg) + TEE_IOCTL_PARAM_SIZE(arg.num_params) != buf.buf_len)
49162306a36Sopenharmony_ci		return -EINVAL;
49262306a36Sopenharmony_ci
49362306a36Sopenharmony_ci	if (arg.num_params) {
49462306a36Sopenharmony_ci		params = kcalloc(arg.num_params, sizeof(struct tee_param),
49562306a36Sopenharmony_ci				 GFP_KERNEL);
49662306a36Sopenharmony_ci		if (!params)
49762306a36Sopenharmony_ci			return -ENOMEM;
49862306a36Sopenharmony_ci		uparams = uarg->params;
49962306a36Sopenharmony_ci		rc = params_from_user(ctx, params, arg.num_params, uparams);
50062306a36Sopenharmony_ci		if (rc)
50162306a36Sopenharmony_ci			goto out;
50262306a36Sopenharmony_ci	}
50362306a36Sopenharmony_ci
50462306a36Sopenharmony_ci	if (arg.clnt_login >= TEE_IOCTL_LOGIN_REE_KERNEL_MIN &&
50562306a36Sopenharmony_ci	    arg.clnt_login <= TEE_IOCTL_LOGIN_REE_KERNEL_MAX) {
50662306a36Sopenharmony_ci		pr_debug("login method not allowed for user-space client\n");
50762306a36Sopenharmony_ci		rc = -EPERM;
50862306a36Sopenharmony_ci		goto out;
50962306a36Sopenharmony_ci	}
51062306a36Sopenharmony_ci
51162306a36Sopenharmony_ci	rc = ctx->teedev->desc->ops->open_session(ctx, &arg, params);
51262306a36Sopenharmony_ci	if (rc)
51362306a36Sopenharmony_ci		goto out;
51462306a36Sopenharmony_ci	have_session = true;
51562306a36Sopenharmony_ci
51662306a36Sopenharmony_ci	if (put_user(arg.session, &uarg->session) ||
51762306a36Sopenharmony_ci	    put_user(arg.ret, &uarg->ret) ||
51862306a36Sopenharmony_ci	    put_user(arg.ret_origin, &uarg->ret_origin)) {
51962306a36Sopenharmony_ci		rc = -EFAULT;
52062306a36Sopenharmony_ci		goto out;
52162306a36Sopenharmony_ci	}
52262306a36Sopenharmony_ci	rc = params_to_user(uparams, arg.num_params, params);
52362306a36Sopenharmony_ciout:
52462306a36Sopenharmony_ci	/*
52562306a36Sopenharmony_ci	 * If we've succeeded to open the session but failed to communicate
52662306a36Sopenharmony_ci	 * it back to user space, close the session again to avoid leakage.
52762306a36Sopenharmony_ci	 */
52862306a36Sopenharmony_ci	if (rc && have_session && ctx->teedev->desc->ops->close_session)
52962306a36Sopenharmony_ci		ctx->teedev->desc->ops->close_session(ctx, arg.session);
53062306a36Sopenharmony_ci
53162306a36Sopenharmony_ci	if (params) {
53262306a36Sopenharmony_ci		/* Decrease ref count for all valid shared memory pointers */
53362306a36Sopenharmony_ci		for (n = 0; n < arg.num_params; n++)
53462306a36Sopenharmony_ci			if (tee_param_is_memref(params + n) &&
53562306a36Sopenharmony_ci			    params[n].u.memref.shm)
53662306a36Sopenharmony_ci				tee_shm_put(params[n].u.memref.shm);
53762306a36Sopenharmony_ci		kfree(params);
53862306a36Sopenharmony_ci	}
53962306a36Sopenharmony_ci
54062306a36Sopenharmony_ci	return rc;
54162306a36Sopenharmony_ci}
54262306a36Sopenharmony_ci
54362306a36Sopenharmony_cistatic int tee_ioctl_invoke(struct tee_context *ctx,
54462306a36Sopenharmony_ci			    struct tee_ioctl_buf_data __user *ubuf)
54562306a36Sopenharmony_ci{
54662306a36Sopenharmony_ci	int rc;
54762306a36Sopenharmony_ci	size_t n;
54862306a36Sopenharmony_ci	struct tee_ioctl_buf_data buf;
54962306a36Sopenharmony_ci	struct tee_ioctl_invoke_arg __user *uarg;
55062306a36Sopenharmony_ci	struct tee_ioctl_invoke_arg arg;
55162306a36Sopenharmony_ci	struct tee_ioctl_param __user *uparams = NULL;
55262306a36Sopenharmony_ci	struct tee_param *params = NULL;
55362306a36Sopenharmony_ci
55462306a36Sopenharmony_ci	if (!ctx->teedev->desc->ops->invoke_func)
55562306a36Sopenharmony_ci		return -EINVAL;
55662306a36Sopenharmony_ci
55762306a36Sopenharmony_ci	if (copy_from_user(&buf, ubuf, sizeof(buf)))
55862306a36Sopenharmony_ci		return -EFAULT;
55962306a36Sopenharmony_ci
56062306a36Sopenharmony_ci	if (buf.buf_len > TEE_MAX_ARG_SIZE ||
56162306a36Sopenharmony_ci	    buf.buf_len < sizeof(struct tee_ioctl_invoke_arg))
56262306a36Sopenharmony_ci		return -EINVAL;
56362306a36Sopenharmony_ci
56462306a36Sopenharmony_ci	uarg = u64_to_user_ptr(buf.buf_ptr);
56562306a36Sopenharmony_ci	if (copy_from_user(&arg, uarg, sizeof(arg)))
56662306a36Sopenharmony_ci		return -EFAULT;
56762306a36Sopenharmony_ci
56862306a36Sopenharmony_ci	if (sizeof(arg) + TEE_IOCTL_PARAM_SIZE(arg.num_params) != buf.buf_len)
56962306a36Sopenharmony_ci		return -EINVAL;
57062306a36Sopenharmony_ci
57162306a36Sopenharmony_ci	if (arg.num_params) {
57262306a36Sopenharmony_ci		params = kcalloc(arg.num_params, sizeof(struct tee_param),
57362306a36Sopenharmony_ci				 GFP_KERNEL);
57462306a36Sopenharmony_ci		if (!params)
57562306a36Sopenharmony_ci			return -ENOMEM;
57662306a36Sopenharmony_ci		uparams = uarg->params;
57762306a36Sopenharmony_ci		rc = params_from_user(ctx, params, arg.num_params, uparams);
57862306a36Sopenharmony_ci		if (rc)
57962306a36Sopenharmony_ci			goto out;
58062306a36Sopenharmony_ci	}
58162306a36Sopenharmony_ci
58262306a36Sopenharmony_ci	rc = ctx->teedev->desc->ops->invoke_func(ctx, &arg, params);
58362306a36Sopenharmony_ci	if (rc)
58462306a36Sopenharmony_ci		goto out;
58562306a36Sopenharmony_ci
58662306a36Sopenharmony_ci	if (put_user(arg.ret, &uarg->ret) ||
58762306a36Sopenharmony_ci	    put_user(arg.ret_origin, &uarg->ret_origin)) {
58862306a36Sopenharmony_ci		rc = -EFAULT;
58962306a36Sopenharmony_ci		goto out;
59062306a36Sopenharmony_ci	}
59162306a36Sopenharmony_ci	rc = params_to_user(uparams, arg.num_params, params);
59262306a36Sopenharmony_ciout:
59362306a36Sopenharmony_ci	if (params) {
59462306a36Sopenharmony_ci		/* Decrease ref count for all valid shared memory pointers */
59562306a36Sopenharmony_ci		for (n = 0; n < arg.num_params; n++)
59662306a36Sopenharmony_ci			if (tee_param_is_memref(params + n) &&
59762306a36Sopenharmony_ci			    params[n].u.memref.shm)
59862306a36Sopenharmony_ci				tee_shm_put(params[n].u.memref.shm);
59962306a36Sopenharmony_ci		kfree(params);
60062306a36Sopenharmony_ci	}
60162306a36Sopenharmony_ci	return rc;
60262306a36Sopenharmony_ci}
60362306a36Sopenharmony_ci
60462306a36Sopenharmony_cistatic int tee_ioctl_cancel(struct tee_context *ctx,
60562306a36Sopenharmony_ci			    struct tee_ioctl_cancel_arg __user *uarg)
60662306a36Sopenharmony_ci{
60762306a36Sopenharmony_ci	struct tee_ioctl_cancel_arg arg;
60862306a36Sopenharmony_ci
60962306a36Sopenharmony_ci	if (!ctx->teedev->desc->ops->cancel_req)
61062306a36Sopenharmony_ci		return -EINVAL;
61162306a36Sopenharmony_ci
61262306a36Sopenharmony_ci	if (copy_from_user(&arg, uarg, sizeof(arg)))
61362306a36Sopenharmony_ci		return -EFAULT;
61462306a36Sopenharmony_ci
61562306a36Sopenharmony_ci	return ctx->teedev->desc->ops->cancel_req(ctx, arg.cancel_id,
61662306a36Sopenharmony_ci						  arg.session);
61762306a36Sopenharmony_ci}
61862306a36Sopenharmony_ci
61962306a36Sopenharmony_cistatic int
62062306a36Sopenharmony_citee_ioctl_close_session(struct tee_context *ctx,
62162306a36Sopenharmony_ci			struct tee_ioctl_close_session_arg __user *uarg)
62262306a36Sopenharmony_ci{
62362306a36Sopenharmony_ci	struct tee_ioctl_close_session_arg arg;
62462306a36Sopenharmony_ci
62562306a36Sopenharmony_ci	if (!ctx->teedev->desc->ops->close_session)
62662306a36Sopenharmony_ci		return -EINVAL;
62762306a36Sopenharmony_ci
62862306a36Sopenharmony_ci	if (copy_from_user(&arg, uarg, sizeof(arg)))
62962306a36Sopenharmony_ci		return -EFAULT;
63062306a36Sopenharmony_ci
63162306a36Sopenharmony_ci	return ctx->teedev->desc->ops->close_session(ctx, arg.session);
63262306a36Sopenharmony_ci}
63362306a36Sopenharmony_ci
63462306a36Sopenharmony_cistatic int params_to_supp(struct tee_context *ctx,
63562306a36Sopenharmony_ci			  struct tee_ioctl_param __user *uparams,
63662306a36Sopenharmony_ci			  size_t num_params, struct tee_param *params)
63762306a36Sopenharmony_ci{
63862306a36Sopenharmony_ci	size_t n;
63962306a36Sopenharmony_ci
64062306a36Sopenharmony_ci	for (n = 0; n < num_params; n++) {
64162306a36Sopenharmony_ci		struct tee_ioctl_param ip;
64262306a36Sopenharmony_ci		struct tee_param *p = params + n;
64362306a36Sopenharmony_ci
64462306a36Sopenharmony_ci		ip.attr = p->attr;
64562306a36Sopenharmony_ci		switch (p->attr & TEE_IOCTL_PARAM_ATTR_TYPE_MASK) {
64662306a36Sopenharmony_ci		case TEE_IOCTL_PARAM_ATTR_TYPE_VALUE_INPUT:
64762306a36Sopenharmony_ci		case TEE_IOCTL_PARAM_ATTR_TYPE_VALUE_INOUT:
64862306a36Sopenharmony_ci			ip.a = p->u.value.a;
64962306a36Sopenharmony_ci			ip.b = p->u.value.b;
65062306a36Sopenharmony_ci			ip.c = p->u.value.c;
65162306a36Sopenharmony_ci			break;
65262306a36Sopenharmony_ci		case TEE_IOCTL_PARAM_ATTR_TYPE_MEMREF_INPUT:
65362306a36Sopenharmony_ci		case TEE_IOCTL_PARAM_ATTR_TYPE_MEMREF_OUTPUT:
65462306a36Sopenharmony_ci		case TEE_IOCTL_PARAM_ATTR_TYPE_MEMREF_INOUT:
65562306a36Sopenharmony_ci			ip.b = p->u.memref.size;
65662306a36Sopenharmony_ci			if (!p->u.memref.shm) {
65762306a36Sopenharmony_ci				ip.a = 0;
65862306a36Sopenharmony_ci				ip.c = (u64)-1; /* invalid shm id */
65962306a36Sopenharmony_ci				break;
66062306a36Sopenharmony_ci			}
66162306a36Sopenharmony_ci			ip.a = p->u.memref.shm_offs;
66262306a36Sopenharmony_ci			ip.c = p->u.memref.shm->id;
66362306a36Sopenharmony_ci			break;
66462306a36Sopenharmony_ci		default:
66562306a36Sopenharmony_ci			ip.a = 0;
66662306a36Sopenharmony_ci			ip.b = 0;
66762306a36Sopenharmony_ci			ip.c = 0;
66862306a36Sopenharmony_ci			break;
66962306a36Sopenharmony_ci		}
67062306a36Sopenharmony_ci
67162306a36Sopenharmony_ci		if (copy_to_user(uparams + n, &ip, sizeof(ip)))
67262306a36Sopenharmony_ci			return -EFAULT;
67362306a36Sopenharmony_ci	}
67462306a36Sopenharmony_ci
67562306a36Sopenharmony_ci	return 0;
67662306a36Sopenharmony_ci}
67762306a36Sopenharmony_ci
67862306a36Sopenharmony_cistatic int tee_ioctl_supp_recv(struct tee_context *ctx,
67962306a36Sopenharmony_ci			       struct tee_ioctl_buf_data __user *ubuf)
68062306a36Sopenharmony_ci{
68162306a36Sopenharmony_ci	int rc;
68262306a36Sopenharmony_ci	struct tee_ioctl_buf_data buf;
68362306a36Sopenharmony_ci	struct tee_iocl_supp_recv_arg __user *uarg;
68462306a36Sopenharmony_ci	struct tee_param *params;
68562306a36Sopenharmony_ci	u32 num_params;
68662306a36Sopenharmony_ci	u32 func;
68762306a36Sopenharmony_ci
68862306a36Sopenharmony_ci	if (!ctx->teedev->desc->ops->supp_recv)
68962306a36Sopenharmony_ci		return -EINVAL;
69062306a36Sopenharmony_ci
69162306a36Sopenharmony_ci	if (copy_from_user(&buf, ubuf, sizeof(buf)))
69262306a36Sopenharmony_ci		return -EFAULT;
69362306a36Sopenharmony_ci
69462306a36Sopenharmony_ci	if (buf.buf_len > TEE_MAX_ARG_SIZE ||
69562306a36Sopenharmony_ci	    buf.buf_len < sizeof(struct tee_iocl_supp_recv_arg))
69662306a36Sopenharmony_ci		return -EINVAL;
69762306a36Sopenharmony_ci
69862306a36Sopenharmony_ci	uarg = u64_to_user_ptr(buf.buf_ptr);
69962306a36Sopenharmony_ci	if (get_user(num_params, &uarg->num_params))
70062306a36Sopenharmony_ci		return -EFAULT;
70162306a36Sopenharmony_ci
70262306a36Sopenharmony_ci	if (sizeof(*uarg) + TEE_IOCTL_PARAM_SIZE(num_params) != buf.buf_len)
70362306a36Sopenharmony_ci		return -EINVAL;
70462306a36Sopenharmony_ci
70562306a36Sopenharmony_ci	params = kcalloc(num_params, sizeof(struct tee_param), GFP_KERNEL);
70662306a36Sopenharmony_ci	if (!params)
70762306a36Sopenharmony_ci		return -ENOMEM;
70862306a36Sopenharmony_ci
70962306a36Sopenharmony_ci	rc = params_from_user(ctx, params, num_params, uarg->params);
71062306a36Sopenharmony_ci	if (rc)
71162306a36Sopenharmony_ci		goto out;
71262306a36Sopenharmony_ci
71362306a36Sopenharmony_ci	rc = ctx->teedev->desc->ops->supp_recv(ctx, &func, &num_params, params);
71462306a36Sopenharmony_ci	if (rc)
71562306a36Sopenharmony_ci		goto out;
71662306a36Sopenharmony_ci
71762306a36Sopenharmony_ci	if (put_user(func, &uarg->func) ||
71862306a36Sopenharmony_ci	    put_user(num_params, &uarg->num_params)) {
71962306a36Sopenharmony_ci		rc = -EFAULT;
72062306a36Sopenharmony_ci		goto out;
72162306a36Sopenharmony_ci	}
72262306a36Sopenharmony_ci
72362306a36Sopenharmony_ci	rc = params_to_supp(ctx, uarg->params, num_params, params);
72462306a36Sopenharmony_ciout:
72562306a36Sopenharmony_ci	kfree(params);
72662306a36Sopenharmony_ci	return rc;
72762306a36Sopenharmony_ci}
72862306a36Sopenharmony_ci
72962306a36Sopenharmony_cistatic int params_from_supp(struct tee_param *params, size_t num_params,
73062306a36Sopenharmony_ci			    struct tee_ioctl_param __user *uparams)
73162306a36Sopenharmony_ci{
73262306a36Sopenharmony_ci	size_t n;
73362306a36Sopenharmony_ci
73462306a36Sopenharmony_ci	for (n = 0; n < num_params; n++) {
73562306a36Sopenharmony_ci		struct tee_param *p = params + n;
73662306a36Sopenharmony_ci		struct tee_ioctl_param ip;
73762306a36Sopenharmony_ci
73862306a36Sopenharmony_ci		if (copy_from_user(&ip, uparams + n, sizeof(ip)))
73962306a36Sopenharmony_ci			return -EFAULT;
74062306a36Sopenharmony_ci
74162306a36Sopenharmony_ci		/* All unused attribute bits has to be zero */
74262306a36Sopenharmony_ci		if (ip.attr & ~TEE_IOCTL_PARAM_ATTR_MASK)
74362306a36Sopenharmony_ci			return -EINVAL;
74462306a36Sopenharmony_ci
74562306a36Sopenharmony_ci		p->attr = ip.attr;
74662306a36Sopenharmony_ci		switch (ip.attr & TEE_IOCTL_PARAM_ATTR_TYPE_MASK) {
74762306a36Sopenharmony_ci		case TEE_IOCTL_PARAM_ATTR_TYPE_VALUE_OUTPUT:
74862306a36Sopenharmony_ci		case TEE_IOCTL_PARAM_ATTR_TYPE_VALUE_INOUT:
74962306a36Sopenharmony_ci			/* Only out and in/out values can be updated */
75062306a36Sopenharmony_ci			p->u.value.a = ip.a;
75162306a36Sopenharmony_ci			p->u.value.b = ip.b;
75262306a36Sopenharmony_ci			p->u.value.c = ip.c;
75362306a36Sopenharmony_ci			break;
75462306a36Sopenharmony_ci		case TEE_IOCTL_PARAM_ATTR_TYPE_MEMREF_OUTPUT:
75562306a36Sopenharmony_ci		case TEE_IOCTL_PARAM_ATTR_TYPE_MEMREF_INOUT:
75662306a36Sopenharmony_ci			/*
75762306a36Sopenharmony_ci			 * Only the size of the memref can be updated.
75862306a36Sopenharmony_ci			 * Since we don't have access to the original
75962306a36Sopenharmony_ci			 * parameters here, only store the supplied size.
76062306a36Sopenharmony_ci			 * The driver will copy the updated size into the
76162306a36Sopenharmony_ci			 * original parameters.
76262306a36Sopenharmony_ci			 */
76362306a36Sopenharmony_ci			p->u.memref.shm = NULL;
76462306a36Sopenharmony_ci			p->u.memref.shm_offs = 0;
76562306a36Sopenharmony_ci			p->u.memref.size = ip.b;
76662306a36Sopenharmony_ci			break;
76762306a36Sopenharmony_ci		default:
76862306a36Sopenharmony_ci			memset(&p->u, 0, sizeof(p->u));
76962306a36Sopenharmony_ci			break;
77062306a36Sopenharmony_ci		}
77162306a36Sopenharmony_ci	}
77262306a36Sopenharmony_ci	return 0;
77362306a36Sopenharmony_ci}
77462306a36Sopenharmony_ci
77562306a36Sopenharmony_cistatic int tee_ioctl_supp_send(struct tee_context *ctx,
77662306a36Sopenharmony_ci			       struct tee_ioctl_buf_data __user *ubuf)
77762306a36Sopenharmony_ci{
77862306a36Sopenharmony_ci	long rc;
77962306a36Sopenharmony_ci	struct tee_ioctl_buf_data buf;
78062306a36Sopenharmony_ci	struct tee_iocl_supp_send_arg __user *uarg;
78162306a36Sopenharmony_ci	struct tee_param *params;
78262306a36Sopenharmony_ci	u32 num_params;
78362306a36Sopenharmony_ci	u32 ret;
78462306a36Sopenharmony_ci
78562306a36Sopenharmony_ci	/* Not valid for this driver */
78662306a36Sopenharmony_ci	if (!ctx->teedev->desc->ops->supp_send)
78762306a36Sopenharmony_ci		return -EINVAL;
78862306a36Sopenharmony_ci
78962306a36Sopenharmony_ci	if (copy_from_user(&buf, ubuf, sizeof(buf)))
79062306a36Sopenharmony_ci		return -EFAULT;
79162306a36Sopenharmony_ci
79262306a36Sopenharmony_ci	if (buf.buf_len > TEE_MAX_ARG_SIZE ||
79362306a36Sopenharmony_ci	    buf.buf_len < sizeof(struct tee_iocl_supp_send_arg))
79462306a36Sopenharmony_ci		return -EINVAL;
79562306a36Sopenharmony_ci
79662306a36Sopenharmony_ci	uarg = u64_to_user_ptr(buf.buf_ptr);
79762306a36Sopenharmony_ci	if (get_user(ret, &uarg->ret) ||
79862306a36Sopenharmony_ci	    get_user(num_params, &uarg->num_params))
79962306a36Sopenharmony_ci		return -EFAULT;
80062306a36Sopenharmony_ci
80162306a36Sopenharmony_ci	if (sizeof(*uarg) + TEE_IOCTL_PARAM_SIZE(num_params) > buf.buf_len)
80262306a36Sopenharmony_ci		return -EINVAL;
80362306a36Sopenharmony_ci
80462306a36Sopenharmony_ci	params = kcalloc(num_params, sizeof(struct tee_param), GFP_KERNEL);
80562306a36Sopenharmony_ci	if (!params)
80662306a36Sopenharmony_ci		return -ENOMEM;
80762306a36Sopenharmony_ci
80862306a36Sopenharmony_ci	rc = params_from_supp(params, num_params, uarg->params);
80962306a36Sopenharmony_ci	if (rc)
81062306a36Sopenharmony_ci		goto out;
81162306a36Sopenharmony_ci
81262306a36Sopenharmony_ci	rc = ctx->teedev->desc->ops->supp_send(ctx, ret, num_params, params);
81362306a36Sopenharmony_ciout:
81462306a36Sopenharmony_ci	kfree(params);
81562306a36Sopenharmony_ci	return rc;
81662306a36Sopenharmony_ci}
81762306a36Sopenharmony_ci
81862306a36Sopenharmony_cistatic long tee_ioctl(struct file *filp, unsigned int cmd, unsigned long arg)
81962306a36Sopenharmony_ci{
82062306a36Sopenharmony_ci	struct tee_context *ctx = filp->private_data;
82162306a36Sopenharmony_ci	void __user *uarg = (void __user *)arg;
82262306a36Sopenharmony_ci
82362306a36Sopenharmony_ci	switch (cmd) {
82462306a36Sopenharmony_ci	case TEE_IOC_VERSION:
82562306a36Sopenharmony_ci		return tee_ioctl_version(ctx, uarg);
82662306a36Sopenharmony_ci	case TEE_IOC_SHM_ALLOC:
82762306a36Sopenharmony_ci		return tee_ioctl_shm_alloc(ctx, uarg);
82862306a36Sopenharmony_ci	case TEE_IOC_SHM_REGISTER:
82962306a36Sopenharmony_ci		return tee_ioctl_shm_register(ctx, uarg);
83062306a36Sopenharmony_ci	case TEE_IOC_OPEN_SESSION:
83162306a36Sopenharmony_ci		return tee_ioctl_open_session(ctx, uarg);
83262306a36Sopenharmony_ci	case TEE_IOC_INVOKE:
83362306a36Sopenharmony_ci		return tee_ioctl_invoke(ctx, uarg);
83462306a36Sopenharmony_ci	case TEE_IOC_CANCEL:
83562306a36Sopenharmony_ci		return tee_ioctl_cancel(ctx, uarg);
83662306a36Sopenharmony_ci	case TEE_IOC_CLOSE_SESSION:
83762306a36Sopenharmony_ci		return tee_ioctl_close_session(ctx, uarg);
83862306a36Sopenharmony_ci	case TEE_IOC_SUPPL_RECV:
83962306a36Sopenharmony_ci		return tee_ioctl_supp_recv(ctx, uarg);
84062306a36Sopenharmony_ci	case TEE_IOC_SUPPL_SEND:
84162306a36Sopenharmony_ci		return tee_ioctl_supp_send(ctx, uarg);
84262306a36Sopenharmony_ci	default:
84362306a36Sopenharmony_ci		return -EINVAL;
84462306a36Sopenharmony_ci	}
84562306a36Sopenharmony_ci}
84662306a36Sopenharmony_ci
84762306a36Sopenharmony_cistatic const struct file_operations tee_fops = {
84862306a36Sopenharmony_ci	.owner = THIS_MODULE,
84962306a36Sopenharmony_ci	.open = tee_open,
85062306a36Sopenharmony_ci	.release = tee_release,
85162306a36Sopenharmony_ci	.unlocked_ioctl = tee_ioctl,
85262306a36Sopenharmony_ci	.compat_ioctl = compat_ptr_ioctl,
85362306a36Sopenharmony_ci};
85462306a36Sopenharmony_ci
85562306a36Sopenharmony_cistatic void tee_release_device(struct device *dev)
85662306a36Sopenharmony_ci{
85762306a36Sopenharmony_ci	struct tee_device *teedev = container_of(dev, struct tee_device, dev);
85862306a36Sopenharmony_ci
85962306a36Sopenharmony_ci	spin_lock(&driver_lock);
86062306a36Sopenharmony_ci	clear_bit(teedev->id, dev_mask);
86162306a36Sopenharmony_ci	spin_unlock(&driver_lock);
86262306a36Sopenharmony_ci	mutex_destroy(&teedev->mutex);
86362306a36Sopenharmony_ci	idr_destroy(&teedev->idr);
86462306a36Sopenharmony_ci	kfree(teedev);
86562306a36Sopenharmony_ci}
86662306a36Sopenharmony_ci
86762306a36Sopenharmony_ci/**
86862306a36Sopenharmony_ci * tee_device_alloc() - Allocate a new struct tee_device instance
86962306a36Sopenharmony_ci * @teedesc:	Descriptor for this driver
87062306a36Sopenharmony_ci * @dev:	Parent device for this device
87162306a36Sopenharmony_ci * @pool:	Shared memory pool, NULL if not used
87262306a36Sopenharmony_ci * @driver_data: Private driver data for this device
87362306a36Sopenharmony_ci *
87462306a36Sopenharmony_ci * Allocates a new struct tee_device instance. The device is
87562306a36Sopenharmony_ci * removed by tee_device_unregister().
87662306a36Sopenharmony_ci *
87762306a36Sopenharmony_ci * @returns a pointer to a 'struct tee_device' or an ERR_PTR on failure
87862306a36Sopenharmony_ci */
87962306a36Sopenharmony_cistruct tee_device *tee_device_alloc(const struct tee_desc *teedesc,
88062306a36Sopenharmony_ci				    struct device *dev,
88162306a36Sopenharmony_ci				    struct tee_shm_pool *pool,
88262306a36Sopenharmony_ci				    void *driver_data)
88362306a36Sopenharmony_ci{
88462306a36Sopenharmony_ci	struct tee_device *teedev;
88562306a36Sopenharmony_ci	void *ret;
88662306a36Sopenharmony_ci	int rc, max_id;
88762306a36Sopenharmony_ci	int offs = 0;
88862306a36Sopenharmony_ci
88962306a36Sopenharmony_ci	if (!teedesc || !teedesc->name || !teedesc->ops ||
89062306a36Sopenharmony_ci	    !teedesc->ops->get_version || !teedesc->ops->open ||
89162306a36Sopenharmony_ci	    !teedesc->ops->release || !pool)
89262306a36Sopenharmony_ci		return ERR_PTR(-EINVAL);
89362306a36Sopenharmony_ci
89462306a36Sopenharmony_ci	teedev = kzalloc(sizeof(*teedev), GFP_KERNEL);
89562306a36Sopenharmony_ci	if (!teedev) {
89662306a36Sopenharmony_ci		ret = ERR_PTR(-ENOMEM);
89762306a36Sopenharmony_ci		goto err;
89862306a36Sopenharmony_ci	}
89962306a36Sopenharmony_ci
90062306a36Sopenharmony_ci	max_id = TEE_NUM_DEVICES / 2;
90162306a36Sopenharmony_ci
90262306a36Sopenharmony_ci	if (teedesc->flags & TEE_DESC_PRIVILEGED) {
90362306a36Sopenharmony_ci		offs = TEE_NUM_DEVICES / 2;
90462306a36Sopenharmony_ci		max_id = TEE_NUM_DEVICES;
90562306a36Sopenharmony_ci	}
90662306a36Sopenharmony_ci
90762306a36Sopenharmony_ci	spin_lock(&driver_lock);
90862306a36Sopenharmony_ci	teedev->id = find_next_zero_bit(dev_mask, max_id, offs);
90962306a36Sopenharmony_ci	if (teedev->id < max_id)
91062306a36Sopenharmony_ci		set_bit(teedev->id, dev_mask);
91162306a36Sopenharmony_ci	spin_unlock(&driver_lock);
91262306a36Sopenharmony_ci
91362306a36Sopenharmony_ci	if (teedev->id >= max_id) {
91462306a36Sopenharmony_ci		ret = ERR_PTR(-ENOMEM);
91562306a36Sopenharmony_ci		goto err;
91662306a36Sopenharmony_ci	}
91762306a36Sopenharmony_ci
91862306a36Sopenharmony_ci	snprintf(teedev->name, sizeof(teedev->name), "tee%s%d",
91962306a36Sopenharmony_ci		 teedesc->flags & TEE_DESC_PRIVILEGED ? "priv" : "",
92062306a36Sopenharmony_ci		 teedev->id - offs);
92162306a36Sopenharmony_ci
92262306a36Sopenharmony_ci	teedev->dev.class = tee_class;
92362306a36Sopenharmony_ci	teedev->dev.release = tee_release_device;
92462306a36Sopenharmony_ci	teedev->dev.parent = dev;
92562306a36Sopenharmony_ci
92662306a36Sopenharmony_ci	teedev->dev.devt = MKDEV(MAJOR(tee_devt), teedev->id);
92762306a36Sopenharmony_ci
92862306a36Sopenharmony_ci	rc = dev_set_name(&teedev->dev, "%s", teedev->name);
92962306a36Sopenharmony_ci	if (rc) {
93062306a36Sopenharmony_ci		ret = ERR_PTR(rc);
93162306a36Sopenharmony_ci		goto err_devt;
93262306a36Sopenharmony_ci	}
93362306a36Sopenharmony_ci
93462306a36Sopenharmony_ci	cdev_init(&teedev->cdev, &tee_fops);
93562306a36Sopenharmony_ci	teedev->cdev.owner = teedesc->owner;
93662306a36Sopenharmony_ci
93762306a36Sopenharmony_ci	dev_set_drvdata(&teedev->dev, driver_data);
93862306a36Sopenharmony_ci	device_initialize(&teedev->dev);
93962306a36Sopenharmony_ci
94062306a36Sopenharmony_ci	/* 1 as tee_device_unregister() does one final tee_device_put() */
94162306a36Sopenharmony_ci	teedev->num_users = 1;
94262306a36Sopenharmony_ci	init_completion(&teedev->c_no_users);
94362306a36Sopenharmony_ci	mutex_init(&teedev->mutex);
94462306a36Sopenharmony_ci	idr_init(&teedev->idr);
94562306a36Sopenharmony_ci
94662306a36Sopenharmony_ci	teedev->desc = teedesc;
94762306a36Sopenharmony_ci	teedev->pool = pool;
94862306a36Sopenharmony_ci
94962306a36Sopenharmony_ci	return teedev;
95062306a36Sopenharmony_cierr_devt:
95162306a36Sopenharmony_ci	unregister_chrdev_region(teedev->dev.devt, 1);
95262306a36Sopenharmony_cierr:
95362306a36Sopenharmony_ci	pr_err("could not register %s driver\n",
95462306a36Sopenharmony_ci	       teedesc->flags & TEE_DESC_PRIVILEGED ? "privileged" : "client");
95562306a36Sopenharmony_ci	if (teedev && teedev->id < TEE_NUM_DEVICES) {
95662306a36Sopenharmony_ci		spin_lock(&driver_lock);
95762306a36Sopenharmony_ci		clear_bit(teedev->id, dev_mask);
95862306a36Sopenharmony_ci		spin_unlock(&driver_lock);
95962306a36Sopenharmony_ci	}
96062306a36Sopenharmony_ci	kfree(teedev);
96162306a36Sopenharmony_ci	return ret;
96262306a36Sopenharmony_ci}
96362306a36Sopenharmony_ciEXPORT_SYMBOL_GPL(tee_device_alloc);
96462306a36Sopenharmony_ci
96562306a36Sopenharmony_cistatic ssize_t implementation_id_show(struct device *dev,
96662306a36Sopenharmony_ci				      struct device_attribute *attr, char *buf)
96762306a36Sopenharmony_ci{
96862306a36Sopenharmony_ci	struct tee_device *teedev = container_of(dev, struct tee_device, dev);
96962306a36Sopenharmony_ci	struct tee_ioctl_version_data vers;
97062306a36Sopenharmony_ci
97162306a36Sopenharmony_ci	teedev->desc->ops->get_version(teedev, &vers);
97262306a36Sopenharmony_ci	return scnprintf(buf, PAGE_SIZE, "%d\n", vers.impl_id);
97362306a36Sopenharmony_ci}
97462306a36Sopenharmony_cistatic DEVICE_ATTR_RO(implementation_id);
97562306a36Sopenharmony_ci
97662306a36Sopenharmony_cistatic struct attribute *tee_dev_attrs[] = {
97762306a36Sopenharmony_ci	&dev_attr_implementation_id.attr,
97862306a36Sopenharmony_ci	NULL
97962306a36Sopenharmony_ci};
98062306a36Sopenharmony_ci
98162306a36Sopenharmony_ciATTRIBUTE_GROUPS(tee_dev);
98262306a36Sopenharmony_ci
98362306a36Sopenharmony_ci/**
98462306a36Sopenharmony_ci * tee_device_register() - Registers a TEE device
98562306a36Sopenharmony_ci * @teedev:	Device to register
98662306a36Sopenharmony_ci *
98762306a36Sopenharmony_ci * tee_device_unregister() need to be called to remove the @teedev if
98862306a36Sopenharmony_ci * this function fails.
98962306a36Sopenharmony_ci *
99062306a36Sopenharmony_ci * @returns < 0 on failure
99162306a36Sopenharmony_ci */
99262306a36Sopenharmony_ciint tee_device_register(struct tee_device *teedev)
99362306a36Sopenharmony_ci{
99462306a36Sopenharmony_ci	int rc;
99562306a36Sopenharmony_ci
99662306a36Sopenharmony_ci	if (teedev->flags & TEE_DEVICE_FLAG_REGISTERED) {
99762306a36Sopenharmony_ci		dev_err(&teedev->dev, "attempt to register twice\n");
99862306a36Sopenharmony_ci		return -EINVAL;
99962306a36Sopenharmony_ci	}
100062306a36Sopenharmony_ci
100162306a36Sopenharmony_ci	teedev->dev.groups = tee_dev_groups;
100262306a36Sopenharmony_ci
100362306a36Sopenharmony_ci	rc = cdev_device_add(&teedev->cdev, &teedev->dev);
100462306a36Sopenharmony_ci	if (rc) {
100562306a36Sopenharmony_ci		dev_err(&teedev->dev,
100662306a36Sopenharmony_ci			"unable to cdev_device_add() %s, major %d, minor %d, err=%d\n",
100762306a36Sopenharmony_ci			teedev->name, MAJOR(teedev->dev.devt),
100862306a36Sopenharmony_ci			MINOR(teedev->dev.devt), rc);
100962306a36Sopenharmony_ci		return rc;
101062306a36Sopenharmony_ci	}
101162306a36Sopenharmony_ci
101262306a36Sopenharmony_ci	teedev->flags |= TEE_DEVICE_FLAG_REGISTERED;
101362306a36Sopenharmony_ci	return 0;
101462306a36Sopenharmony_ci}
101562306a36Sopenharmony_ciEXPORT_SYMBOL_GPL(tee_device_register);
101662306a36Sopenharmony_ci
101762306a36Sopenharmony_civoid tee_device_put(struct tee_device *teedev)
101862306a36Sopenharmony_ci{
101962306a36Sopenharmony_ci	mutex_lock(&teedev->mutex);
102062306a36Sopenharmony_ci	/* Shouldn't put in this state */
102162306a36Sopenharmony_ci	if (!WARN_ON(!teedev->desc)) {
102262306a36Sopenharmony_ci		teedev->num_users--;
102362306a36Sopenharmony_ci		if (!teedev->num_users) {
102462306a36Sopenharmony_ci			teedev->desc = NULL;
102562306a36Sopenharmony_ci			complete(&teedev->c_no_users);
102662306a36Sopenharmony_ci		}
102762306a36Sopenharmony_ci	}
102862306a36Sopenharmony_ci	mutex_unlock(&teedev->mutex);
102962306a36Sopenharmony_ci}
103062306a36Sopenharmony_ci
103162306a36Sopenharmony_cibool tee_device_get(struct tee_device *teedev)
103262306a36Sopenharmony_ci{
103362306a36Sopenharmony_ci	mutex_lock(&teedev->mutex);
103462306a36Sopenharmony_ci	if (!teedev->desc) {
103562306a36Sopenharmony_ci		mutex_unlock(&teedev->mutex);
103662306a36Sopenharmony_ci		return false;
103762306a36Sopenharmony_ci	}
103862306a36Sopenharmony_ci	teedev->num_users++;
103962306a36Sopenharmony_ci	mutex_unlock(&teedev->mutex);
104062306a36Sopenharmony_ci	return true;
104162306a36Sopenharmony_ci}
104262306a36Sopenharmony_ci
104362306a36Sopenharmony_ci/**
104462306a36Sopenharmony_ci * tee_device_unregister() - Removes a TEE device
104562306a36Sopenharmony_ci * @teedev:	Device to unregister
104662306a36Sopenharmony_ci *
104762306a36Sopenharmony_ci * This function should be called to remove the @teedev even if
104862306a36Sopenharmony_ci * tee_device_register() hasn't been called yet. Does nothing if
104962306a36Sopenharmony_ci * @teedev is NULL.
105062306a36Sopenharmony_ci */
105162306a36Sopenharmony_civoid tee_device_unregister(struct tee_device *teedev)
105262306a36Sopenharmony_ci{
105362306a36Sopenharmony_ci	if (!teedev)
105462306a36Sopenharmony_ci		return;
105562306a36Sopenharmony_ci
105662306a36Sopenharmony_ci	if (teedev->flags & TEE_DEVICE_FLAG_REGISTERED)
105762306a36Sopenharmony_ci		cdev_device_del(&teedev->cdev, &teedev->dev);
105862306a36Sopenharmony_ci
105962306a36Sopenharmony_ci	tee_device_put(teedev);
106062306a36Sopenharmony_ci	wait_for_completion(&teedev->c_no_users);
106162306a36Sopenharmony_ci
106262306a36Sopenharmony_ci	/*
106362306a36Sopenharmony_ci	 * No need to take a mutex any longer now since teedev->desc was
106462306a36Sopenharmony_ci	 * set to NULL before teedev->c_no_users was completed.
106562306a36Sopenharmony_ci	 */
106662306a36Sopenharmony_ci
106762306a36Sopenharmony_ci	teedev->pool = NULL;
106862306a36Sopenharmony_ci
106962306a36Sopenharmony_ci	put_device(&teedev->dev);
107062306a36Sopenharmony_ci}
107162306a36Sopenharmony_ciEXPORT_SYMBOL_GPL(tee_device_unregister);
107262306a36Sopenharmony_ci
107362306a36Sopenharmony_ci/**
107462306a36Sopenharmony_ci * tee_get_drvdata() - Return driver_data pointer
107562306a36Sopenharmony_ci * @teedev:	Device containing the driver_data pointer
107662306a36Sopenharmony_ci * @returns the driver_data pointer supplied to tee_device_alloc().
107762306a36Sopenharmony_ci */
107862306a36Sopenharmony_civoid *tee_get_drvdata(struct tee_device *teedev)
107962306a36Sopenharmony_ci{
108062306a36Sopenharmony_ci	return dev_get_drvdata(&teedev->dev);
108162306a36Sopenharmony_ci}
108262306a36Sopenharmony_ciEXPORT_SYMBOL_GPL(tee_get_drvdata);
108362306a36Sopenharmony_ci
108462306a36Sopenharmony_cistruct match_dev_data {
108562306a36Sopenharmony_ci	struct tee_ioctl_version_data *vers;
108662306a36Sopenharmony_ci	const void *data;
108762306a36Sopenharmony_ci	int (*match)(struct tee_ioctl_version_data *, const void *);
108862306a36Sopenharmony_ci};
108962306a36Sopenharmony_ci
109062306a36Sopenharmony_cistatic int match_dev(struct device *dev, const void *data)
109162306a36Sopenharmony_ci{
109262306a36Sopenharmony_ci	const struct match_dev_data *match_data = data;
109362306a36Sopenharmony_ci	struct tee_device *teedev = container_of(dev, struct tee_device, dev);
109462306a36Sopenharmony_ci
109562306a36Sopenharmony_ci	teedev->desc->ops->get_version(teedev, match_data->vers);
109662306a36Sopenharmony_ci	return match_data->match(match_data->vers, match_data->data);
109762306a36Sopenharmony_ci}
109862306a36Sopenharmony_ci
109962306a36Sopenharmony_cistruct tee_context *
110062306a36Sopenharmony_citee_client_open_context(struct tee_context *start,
110162306a36Sopenharmony_ci			int (*match)(struct tee_ioctl_version_data *,
110262306a36Sopenharmony_ci				     const void *),
110362306a36Sopenharmony_ci			const void *data, struct tee_ioctl_version_data *vers)
110462306a36Sopenharmony_ci{
110562306a36Sopenharmony_ci	struct device *dev = NULL;
110662306a36Sopenharmony_ci	struct device *put_dev = NULL;
110762306a36Sopenharmony_ci	struct tee_context *ctx = NULL;
110862306a36Sopenharmony_ci	struct tee_ioctl_version_data v;
110962306a36Sopenharmony_ci	struct match_dev_data match_data = { vers ? vers : &v, data, match };
111062306a36Sopenharmony_ci
111162306a36Sopenharmony_ci	if (start)
111262306a36Sopenharmony_ci		dev = &start->teedev->dev;
111362306a36Sopenharmony_ci
111462306a36Sopenharmony_ci	do {
111562306a36Sopenharmony_ci		dev = class_find_device(tee_class, dev, &match_data, match_dev);
111662306a36Sopenharmony_ci		if (!dev) {
111762306a36Sopenharmony_ci			ctx = ERR_PTR(-ENOENT);
111862306a36Sopenharmony_ci			break;
111962306a36Sopenharmony_ci		}
112062306a36Sopenharmony_ci
112162306a36Sopenharmony_ci		put_device(put_dev);
112262306a36Sopenharmony_ci		put_dev = dev;
112362306a36Sopenharmony_ci
112462306a36Sopenharmony_ci		ctx = teedev_open(container_of(dev, struct tee_device, dev));
112562306a36Sopenharmony_ci	} while (IS_ERR(ctx) && PTR_ERR(ctx) != -ENOMEM);
112662306a36Sopenharmony_ci
112762306a36Sopenharmony_ci	put_device(put_dev);
112862306a36Sopenharmony_ci	/*
112962306a36Sopenharmony_ci	 * Default behaviour for in kernel client is to not wait for
113062306a36Sopenharmony_ci	 * tee-supplicant if not present for any requests in this context.
113162306a36Sopenharmony_ci	 * Also this flag could be configured again before call to
113262306a36Sopenharmony_ci	 * tee_client_open_session() if any in kernel client requires
113362306a36Sopenharmony_ci	 * different behaviour.
113462306a36Sopenharmony_ci	 */
113562306a36Sopenharmony_ci	if (!IS_ERR(ctx))
113662306a36Sopenharmony_ci		ctx->supp_nowait = true;
113762306a36Sopenharmony_ci
113862306a36Sopenharmony_ci	return ctx;
113962306a36Sopenharmony_ci}
114062306a36Sopenharmony_ciEXPORT_SYMBOL_GPL(tee_client_open_context);
114162306a36Sopenharmony_ci
114262306a36Sopenharmony_civoid tee_client_close_context(struct tee_context *ctx)
114362306a36Sopenharmony_ci{
114462306a36Sopenharmony_ci	teedev_close_context(ctx);
114562306a36Sopenharmony_ci}
114662306a36Sopenharmony_ciEXPORT_SYMBOL_GPL(tee_client_close_context);
114762306a36Sopenharmony_ci
114862306a36Sopenharmony_civoid tee_client_get_version(struct tee_context *ctx,
114962306a36Sopenharmony_ci			    struct tee_ioctl_version_data *vers)
115062306a36Sopenharmony_ci{
115162306a36Sopenharmony_ci	ctx->teedev->desc->ops->get_version(ctx->teedev, vers);
115262306a36Sopenharmony_ci}
115362306a36Sopenharmony_ciEXPORT_SYMBOL_GPL(tee_client_get_version);
115462306a36Sopenharmony_ci
115562306a36Sopenharmony_ciint tee_client_open_session(struct tee_context *ctx,
115662306a36Sopenharmony_ci			    struct tee_ioctl_open_session_arg *arg,
115762306a36Sopenharmony_ci			    struct tee_param *param)
115862306a36Sopenharmony_ci{
115962306a36Sopenharmony_ci	if (!ctx->teedev->desc->ops->open_session)
116062306a36Sopenharmony_ci		return -EINVAL;
116162306a36Sopenharmony_ci	return ctx->teedev->desc->ops->open_session(ctx, arg, param);
116262306a36Sopenharmony_ci}
116362306a36Sopenharmony_ciEXPORT_SYMBOL_GPL(tee_client_open_session);
116462306a36Sopenharmony_ci
116562306a36Sopenharmony_ciint tee_client_close_session(struct tee_context *ctx, u32 session)
116662306a36Sopenharmony_ci{
116762306a36Sopenharmony_ci	if (!ctx->teedev->desc->ops->close_session)
116862306a36Sopenharmony_ci		return -EINVAL;
116962306a36Sopenharmony_ci	return ctx->teedev->desc->ops->close_session(ctx, session);
117062306a36Sopenharmony_ci}
117162306a36Sopenharmony_ciEXPORT_SYMBOL_GPL(tee_client_close_session);
117262306a36Sopenharmony_ci
117362306a36Sopenharmony_ciint tee_client_invoke_func(struct tee_context *ctx,
117462306a36Sopenharmony_ci			   struct tee_ioctl_invoke_arg *arg,
117562306a36Sopenharmony_ci			   struct tee_param *param)
117662306a36Sopenharmony_ci{
117762306a36Sopenharmony_ci	if (!ctx->teedev->desc->ops->invoke_func)
117862306a36Sopenharmony_ci		return -EINVAL;
117962306a36Sopenharmony_ci	return ctx->teedev->desc->ops->invoke_func(ctx, arg, param);
118062306a36Sopenharmony_ci}
118162306a36Sopenharmony_ciEXPORT_SYMBOL_GPL(tee_client_invoke_func);
118262306a36Sopenharmony_ci
118362306a36Sopenharmony_ciint tee_client_cancel_req(struct tee_context *ctx,
118462306a36Sopenharmony_ci			  struct tee_ioctl_cancel_arg *arg)
118562306a36Sopenharmony_ci{
118662306a36Sopenharmony_ci	if (!ctx->teedev->desc->ops->cancel_req)
118762306a36Sopenharmony_ci		return -EINVAL;
118862306a36Sopenharmony_ci	return ctx->teedev->desc->ops->cancel_req(ctx, arg->cancel_id,
118962306a36Sopenharmony_ci						  arg->session);
119062306a36Sopenharmony_ci}
119162306a36Sopenharmony_ci
119262306a36Sopenharmony_cistatic int tee_client_device_match(struct device *dev,
119362306a36Sopenharmony_ci				   struct device_driver *drv)
119462306a36Sopenharmony_ci{
119562306a36Sopenharmony_ci	const struct tee_client_device_id *id_table;
119662306a36Sopenharmony_ci	struct tee_client_device *tee_device;
119762306a36Sopenharmony_ci
119862306a36Sopenharmony_ci	id_table = to_tee_client_driver(drv)->id_table;
119962306a36Sopenharmony_ci	tee_device = to_tee_client_device(dev);
120062306a36Sopenharmony_ci
120162306a36Sopenharmony_ci	while (!uuid_is_null(&id_table->uuid)) {
120262306a36Sopenharmony_ci		if (uuid_equal(&tee_device->id.uuid, &id_table->uuid))
120362306a36Sopenharmony_ci			return 1;
120462306a36Sopenharmony_ci		id_table++;
120562306a36Sopenharmony_ci	}
120662306a36Sopenharmony_ci
120762306a36Sopenharmony_ci	return 0;
120862306a36Sopenharmony_ci}
120962306a36Sopenharmony_ci
121062306a36Sopenharmony_cistatic int tee_client_device_uevent(const struct device *dev,
121162306a36Sopenharmony_ci				    struct kobj_uevent_env *env)
121262306a36Sopenharmony_ci{
121362306a36Sopenharmony_ci	uuid_t *dev_id = &to_tee_client_device(dev)->id.uuid;
121462306a36Sopenharmony_ci
121562306a36Sopenharmony_ci	return add_uevent_var(env, "MODALIAS=tee:%pUb", dev_id);
121662306a36Sopenharmony_ci}
121762306a36Sopenharmony_ci
121862306a36Sopenharmony_cistruct bus_type tee_bus_type = {
121962306a36Sopenharmony_ci	.name		= "tee",
122062306a36Sopenharmony_ci	.match		= tee_client_device_match,
122162306a36Sopenharmony_ci	.uevent		= tee_client_device_uevent,
122262306a36Sopenharmony_ci};
122362306a36Sopenharmony_ciEXPORT_SYMBOL_GPL(tee_bus_type);
122462306a36Sopenharmony_ci
122562306a36Sopenharmony_cistatic int __init tee_init(void)
122662306a36Sopenharmony_ci{
122762306a36Sopenharmony_ci	int rc;
122862306a36Sopenharmony_ci
122962306a36Sopenharmony_ci	tee_class = class_create("tee");
123062306a36Sopenharmony_ci	if (IS_ERR(tee_class)) {
123162306a36Sopenharmony_ci		pr_err("couldn't create class\n");
123262306a36Sopenharmony_ci		return PTR_ERR(tee_class);
123362306a36Sopenharmony_ci	}
123462306a36Sopenharmony_ci
123562306a36Sopenharmony_ci	rc = alloc_chrdev_region(&tee_devt, 0, TEE_NUM_DEVICES, "tee");
123662306a36Sopenharmony_ci	if (rc) {
123762306a36Sopenharmony_ci		pr_err("failed to allocate char dev region\n");
123862306a36Sopenharmony_ci		goto out_unreg_class;
123962306a36Sopenharmony_ci	}
124062306a36Sopenharmony_ci
124162306a36Sopenharmony_ci	rc = bus_register(&tee_bus_type);
124262306a36Sopenharmony_ci	if (rc) {
124362306a36Sopenharmony_ci		pr_err("failed to register tee bus\n");
124462306a36Sopenharmony_ci		goto out_unreg_chrdev;
124562306a36Sopenharmony_ci	}
124662306a36Sopenharmony_ci
124762306a36Sopenharmony_ci	return 0;
124862306a36Sopenharmony_ci
124962306a36Sopenharmony_ciout_unreg_chrdev:
125062306a36Sopenharmony_ci	unregister_chrdev_region(tee_devt, TEE_NUM_DEVICES);
125162306a36Sopenharmony_ciout_unreg_class:
125262306a36Sopenharmony_ci	class_destroy(tee_class);
125362306a36Sopenharmony_ci	tee_class = NULL;
125462306a36Sopenharmony_ci
125562306a36Sopenharmony_ci	return rc;
125662306a36Sopenharmony_ci}
125762306a36Sopenharmony_ci
125862306a36Sopenharmony_cistatic void __exit tee_exit(void)
125962306a36Sopenharmony_ci{
126062306a36Sopenharmony_ci	bus_unregister(&tee_bus_type);
126162306a36Sopenharmony_ci	unregister_chrdev_region(tee_devt, TEE_NUM_DEVICES);
126262306a36Sopenharmony_ci	class_destroy(tee_class);
126362306a36Sopenharmony_ci	tee_class = NULL;
126462306a36Sopenharmony_ci}
126562306a36Sopenharmony_ci
126662306a36Sopenharmony_cisubsys_initcall(tee_init);
126762306a36Sopenharmony_cimodule_exit(tee_exit);
126862306a36Sopenharmony_ci
126962306a36Sopenharmony_ciMODULE_AUTHOR("Linaro");
127062306a36Sopenharmony_ciMODULE_DESCRIPTION("TEE Driver");
127162306a36Sopenharmony_ciMODULE_VERSION("1.0");
127262306a36Sopenharmony_ciMODULE_LICENSE("GPL v2");
1273