• Home
  • Line#
  • Scopes#
  • Navigate#
  • Raw
  • Download
1 /*
2  * Copyright (C) 2005, 2012 IBM Corporation
3  *
4  * Authors:
5  *	Kent Yoder <key@linux.vnet.ibm.com>
6  *	Seiji Munetoh <munetoh@jp.ibm.com>
7  *	Stefan Berger <stefanb@us.ibm.com>
8  *	Reiner Sailer <sailer@watson.ibm.com>
9  *	Kylene Hall <kjhall@us.ibm.com>
10  *	Nayna Jain <nayna@linux.vnet.ibm.com>
11  *
12  * Access to the event log created by a system's firmware / BIOS
13  *
14  * This program is free software; you can redistribute it and/or
15  * modify it under the terms of the GNU General Public License
16  * as published by the Free Software Foundation; either version
17  * 2 of the License, or (at your option) any later version.
18  *
19  */
20 
21 #include <linux/seq_file.h>
22 #include <linux/fs.h>
23 #include <linux/security.h>
24 #include <linux/module.h>
25 #include <linux/tpm_eventlog.h>
26 
27 #include "../tpm.h"
28 #include "common.h"
29 
tpm_bios_measurements_open(struct inode * inode,struct file * file)30 static int tpm_bios_measurements_open(struct inode *inode,
31 					    struct file *file)
32 {
33 	int err;
34 	struct seq_file *seq;
35 	struct tpm_chip_seqops *chip_seqops;
36 	const struct seq_operations *seqops;
37 	struct tpm_chip *chip;
38 
39 	inode_lock(inode);
40 	if (!inode->i_private) {
41 		inode_unlock(inode);
42 		return -ENODEV;
43 	}
44 	chip_seqops = (struct tpm_chip_seqops *)inode->i_private;
45 	seqops = chip_seqops->seqops;
46 	chip = chip_seqops->chip;
47 	get_device(&chip->dev);
48 	inode_unlock(inode);
49 
50 	/* now register seq file */
51 	err = seq_open(file, seqops);
52 	if (!err) {
53 		seq = file->private_data;
54 		seq->private = chip;
55 	}
56 
57 	return err;
58 }
59 
tpm_bios_measurements_release(struct inode * inode,struct file * file)60 static int tpm_bios_measurements_release(struct inode *inode,
61 					 struct file *file)
62 {
63 	struct seq_file *seq = (struct seq_file *)file->private_data;
64 	struct tpm_chip *chip = (struct tpm_chip *)seq->private;
65 
66 	put_device(&chip->dev);
67 
68 	return seq_release(inode, file);
69 }
70 
71 static const struct file_operations tpm_bios_measurements_ops = {
72 	.owner = THIS_MODULE,
73 	.open = tpm_bios_measurements_open,
74 	.read = seq_read,
75 	.llseek = seq_lseek,
76 	.release = tpm_bios_measurements_release,
77 };
78 
tpm_read_log(struct tpm_chip * chip)79 static int tpm_read_log(struct tpm_chip *chip)
80 {
81 	int rc;
82 
83 	if (chip->log.bios_event_log != NULL) {
84 		dev_dbg(&chip->dev,
85 			"%s: ERROR - event log already initialized\n",
86 			__func__);
87 		return -EFAULT;
88 	}
89 
90 	rc = tpm_read_log_acpi(chip);
91 	if (rc != -ENODEV)
92 		return rc;
93 
94 	rc = tpm_read_log_efi(chip);
95 	if (rc != -ENODEV)
96 		return rc;
97 
98 	return tpm_read_log_of(chip);
99 }
100 
101 /*
102  * tpm_bios_log_setup() - Read the event log from the firmware
103  * @chip: TPM chip to use.
104  *
105  * If an event log is found then the securityfs files are setup to
106  * export it to userspace, otherwise nothing is done.
107  */
tpm_bios_log_setup(struct tpm_chip * chip)108 void tpm_bios_log_setup(struct tpm_chip *chip)
109 {
110 	const char *name = dev_name(&chip->dev);
111 	unsigned int cnt;
112 	int log_version;
113 	int rc = 0;
114 
115 	rc = tpm_read_log(chip);
116 	if (rc < 0)
117 		return;
118 	log_version = rc;
119 
120 	cnt = 0;
121 	chip->bios_dir[cnt] = securityfs_create_dir(name, NULL);
122 	/* NOTE: securityfs_create_dir can return ENODEV if securityfs is
123 	 * compiled out. The caller should ignore the ENODEV return code.
124 	 */
125 	if (IS_ERR(chip->bios_dir[cnt]))
126 		goto err;
127 	cnt++;
128 
129 	chip->bin_log_seqops.chip = chip;
130 	if (log_version == EFI_TCG2_EVENT_LOG_FORMAT_TCG_2)
131 		chip->bin_log_seqops.seqops =
132 			&tpm2_binary_b_measurements_seqops;
133 	else
134 		chip->bin_log_seqops.seqops =
135 			&tpm1_binary_b_measurements_seqops;
136 
137 
138 	chip->bios_dir[cnt] =
139 	    securityfs_create_file("binary_bios_measurements",
140 				   0440, chip->bios_dir[0],
141 				   (void *)&chip->bin_log_seqops,
142 				   &tpm_bios_measurements_ops);
143 	if (IS_ERR(chip->bios_dir[cnt]))
144 		goto err;
145 	cnt++;
146 
147 	if (!(chip->flags & TPM_CHIP_FLAG_TPM2)) {
148 
149 		chip->ascii_log_seqops.chip = chip;
150 		chip->ascii_log_seqops.seqops =
151 			&tpm1_ascii_b_measurements_seqops;
152 
153 		chip->bios_dir[cnt] =
154 			securityfs_create_file("ascii_bios_measurements",
155 					       0440, chip->bios_dir[0],
156 					       (void *)&chip->ascii_log_seqops,
157 					       &tpm_bios_measurements_ops);
158 		if (IS_ERR(chip->bios_dir[cnt]))
159 			goto err;
160 		cnt++;
161 	}
162 
163 	return;
164 
165 err:
166 	chip->bios_dir[cnt] = NULL;
167 	tpm_bios_log_teardown(chip);
168 	return;
169 }
170 
tpm_bios_log_teardown(struct tpm_chip * chip)171 void tpm_bios_log_teardown(struct tpm_chip *chip)
172 {
173 	int i;
174 	struct inode *inode;
175 
176 	/* securityfs_remove currently doesn't take care of handling sync
177 	 * between removal and opening of pseudo files. To handle this, a
178 	 * workaround is added by making i_private = NULL here during removal
179 	 * and to check it during open(), both within inode_lock()/unlock().
180 	 * This design ensures that open() either safely gets kref or fails.
181 	 */
182 	for (i = (TPM_NUM_EVENT_LOG_FILES - 1); i >= 0; i--) {
183 		if (chip->bios_dir[i]) {
184 			inode = d_inode(chip->bios_dir[i]);
185 			inode_lock(inode);
186 			inode->i_private = NULL;
187 			inode_unlock(inode);
188 			securityfs_remove(chip->bios_dir[i]);
189 		}
190 	}
191 }
192