Merge tag 'efi-2023-01-rc1-3' of https://source.denx.de/u-boot/custodians/u-boot-efi
[platform/kernel/u-boot.git] / cmd / tpm_test.c
1 // SPDX-License-Identifier: GPL-2.0+
2 /*
3  * Copyright (c) 2015 Google, Inc
4  */
5
6 #include <common.h>
7 #include <command.h>
8 #include <cpu_func.h>
9 #include <log.h>
10 #include <tpm-v1.h>
11 #include "tpm-user-utils.h"
12 #include <tpm_api.h>
13
14 /* Prints error and returns on failure */
15 #define TPM_CHECK(tpm_command) do { \
16         uint32_t result; \
17         \
18         result = (tpm_command); \
19         if (result != TPM_SUCCESS) { \
20                 printf("TEST FAILED: line %d: " #tpm_command ": 0x%x\n", \
21                         __LINE__, result); \
22                 return result; \
23         } \
24 } while (0)
25
26 #define INDEX0                  0xda70
27 #define INDEX1                  0xda71
28 #define INDEX2                  0xda72
29 #define INDEX3                  0xda73
30 #define INDEX_INITIALISED       0xda80
31 #define PHYS_PRESENCE           4
32 #define PRESENCE                8
33
34 static uint32_t TlclStartupIfNeeded(struct udevice *dev)
35 {
36         uint32_t result = tpm_startup(dev, TPM_ST_CLEAR);
37
38         return result == TPM_INVALID_POSTINIT ? TPM_SUCCESS : result;
39 }
40
41 static int test_timer(struct udevice *dev)
42 {
43         printf("get_timer(0) = %lu\n", get_timer(0));
44         return 0;
45 }
46
47 static uint32_t tpm_get_flags(struct udevice *dev, uint8_t *disable,
48                               uint8_t *deactivated, uint8_t *nvlocked)
49 {
50         struct tpm_permanent_flags pflags;
51         uint32_t result;
52
53         result = tpm1_get_permanent_flags(dev, &pflags);
54         if (result)
55                 return result;
56         if (disable)
57                 *disable = pflags.disable;
58         if (deactivated)
59                 *deactivated = pflags.deactivated;
60         if (nvlocked)
61                 *nvlocked = pflags.nv_locked;
62         debug("TPM: Got flags disable=%d, deactivated=%d, nvlocked=%d\n",
63               pflags.disable, pflags.deactivated, pflags.nv_locked);
64
65         return 0;
66 }
67
68 static uint32_t tpm_nv_write_value_lock(struct udevice *dev, uint32_t index)
69 {
70         debug("TPM: Write lock 0x%x\n", index);
71
72         return tpm_nv_write_value(dev, index, NULL, 0);
73 }
74
75 static int tpm_is_owned(struct udevice *dev)
76 {
77         uint8_t response[TPM_PUBEK_SIZE];
78         uint32_t result;
79
80         result = tpm_read_pubek(dev, response, sizeof(response));
81
82         return result != TPM_SUCCESS;
83 }
84
85 static int test_early_extend(struct udevice *dev)
86 {
87         uint8_t value_in[20];
88         uint8_t value_out[20];
89
90         printf("Testing earlyextend ...");
91         tpm_init(dev);
92         TPM_CHECK(tpm_startup(dev, TPM_ST_CLEAR));
93         TPM_CHECK(tpm_continue_self_test(dev));
94         TPM_CHECK(tpm_pcr_extend(dev, 1, value_in, sizeof(value_in), value_out,
95                                  "test"));
96         printf("done\n");
97         return 0;
98 }
99
100 static int test_early_nvram(struct udevice *dev)
101 {
102         uint32_t x;
103
104         printf("Testing earlynvram ...");
105         tpm_init(dev);
106         TPM_CHECK(tpm_startup(dev, TPM_ST_CLEAR));
107         TPM_CHECK(tpm_continue_self_test(dev));
108         TPM_CHECK(tpm_tsc_physical_presence(dev, PRESENCE));
109         TPM_CHECK(tpm_nv_read_value(dev, INDEX0, (uint8_t *)&x, sizeof(x)));
110         printf("done\n");
111         return 0;
112 }
113
114 static int test_early_nvram2(struct udevice *dev)
115 {
116         uint32_t x;
117
118         printf("Testing earlynvram2 ...");
119         tpm_init(dev);
120         TPM_CHECK(tpm_startup(dev, TPM_ST_CLEAR));
121         TPM_CHECK(tpm_continue_self_test(dev));
122         TPM_CHECK(tpm_tsc_physical_presence(dev, PRESENCE));
123         TPM_CHECK(tpm_nv_write_value(dev, INDEX0, (uint8_t *)&x, sizeof(x)));
124         printf("done\n");
125         return 0;
126 }
127
128 static int test_enable(struct udevice *dev)
129 {
130         uint8_t disable = 0, deactivated = 0;
131
132         printf("Testing enable ...\n");
133         tpm_init(dev);
134         TPM_CHECK(TlclStartupIfNeeded(dev));
135         TPM_CHECK(tpm_self_test_full(dev));
136         TPM_CHECK(tpm_tsc_physical_presence(dev, PRESENCE));
137         TPM_CHECK(tpm_get_flags(dev, &disable, &deactivated, NULL));
138         printf("\tdisable is %d, deactivated is %d\n", disable, deactivated);
139         TPM_CHECK(tpm_physical_enable(dev));
140         TPM_CHECK(tpm_physical_set_deactivated(dev, 0));
141         TPM_CHECK(tpm_get_flags(dev, &disable, &deactivated, NULL));
142         printf("\tdisable is %d, deactivated is %d\n", disable, deactivated);
143         if (disable == 1 || deactivated == 1)
144                 printf("\tfailed to enable or activate\n");
145         printf("\tdone\n");
146         return 0;
147 }
148
149 #define reboot() do { \
150         printf("\trebooting...\n"); \
151         reset_cpu(); \
152 } while (0)
153
154 static int test_fast_enable(struct udevice *dev)
155 {
156         uint8_t disable = 0, deactivated = 0;
157         int i;
158
159         printf("Testing fastenable ...\n");
160         tpm_init(dev);
161         TPM_CHECK(TlclStartupIfNeeded(dev));
162         TPM_CHECK(tpm_self_test_full(dev));
163         TPM_CHECK(tpm_tsc_physical_presence(dev, PRESENCE));
164         TPM_CHECK(tpm_get_flags(dev, &disable, &deactivated, NULL));
165         printf("\tdisable is %d, deactivated is %d\n", disable, deactivated);
166         for (i = 0; i < 2; i++) {
167                 TPM_CHECK(tpm_force_clear(dev));
168                 TPM_CHECK(tpm_get_flags(dev, &disable, &deactivated, NULL));
169                 printf("\tdisable is %d, deactivated is %d\n", disable,
170                        deactivated);
171                 assert(disable == 1 && deactivated == 1);
172                 TPM_CHECK(tpm_physical_enable(dev));
173                 TPM_CHECK(tpm_physical_set_deactivated(dev, 0));
174                 TPM_CHECK(tpm_get_flags(dev, &disable, &deactivated, NULL));
175                 printf("\tdisable is %d, deactivated is %d\n", disable,
176                        deactivated);
177                 assert(disable == 0 && deactivated == 0);
178         }
179         printf("\tdone\n");
180         return 0;
181 }
182
183 static int test_global_lock(struct udevice *dev)
184 {
185         uint32_t zero = 0;
186         uint32_t result;
187         uint32_t x;
188
189         printf("Testing globallock ...\n");
190         tpm_init(dev);
191         TPM_CHECK(TlclStartupIfNeeded(dev));
192         TPM_CHECK(tpm_self_test_full(dev));
193         TPM_CHECK(tpm_tsc_physical_presence(dev, PRESENCE));
194         TPM_CHECK(tpm_nv_read_value(dev, INDEX0, (uint8_t *)&x, sizeof(x)));
195         TPM_CHECK(tpm_nv_write_value(dev, INDEX0, (uint8_t *)&zero,
196                                      sizeof(uint32_t)));
197         TPM_CHECK(tpm_nv_read_value(dev, INDEX1, (uint8_t *)&x, sizeof(x)));
198         TPM_CHECK(tpm_nv_write_value(dev, INDEX1, (uint8_t *)&zero,
199                                      sizeof(uint32_t)));
200         TPM_CHECK(tpm_set_global_lock(dev));
201         /* Verifies that write to index0 fails */
202         x = 1;
203         result = tpm_nv_write_value(dev, INDEX0, (uint8_t *)&x, sizeof(x));
204         assert(result == TPM_AREA_LOCKED);
205         TPM_CHECK(tpm_nv_read_value(dev, INDEX0, (uint8_t *)&x, sizeof(x)));
206         assert(x == 0);
207         /* Verifies that write to index1 is still possible */
208         x = 2;
209         TPM_CHECK(tpm_nv_write_value(dev, INDEX1, (uint8_t *)&x, sizeof(x)));
210         TPM_CHECK(tpm_nv_read_value(dev, INDEX1, (uint8_t *)&x, sizeof(x)));
211         assert(x == 2);
212         /* Turns off PP */
213         tpm_tsc_physical_presence(dev, PHYS_PRESENCE);
214         /* Verifies that write to index1 fails */
215         x = 3;
216         result = tpm_nv_write_value(dev, INDEX1, (uint8_t *)&x, sizeof(x));
217         assert(result == TPM_BAD_PRESENCE);
218         TPM_CHECK(tpm_nv_read_value(dev, INDEX1, (uint8_t *)&x, sizeof(x)));
219         assert(x == 2);
220         printf("\tdone\n");
221         return 0;
222 }
223
224 static int test_lock(struct udevice *dev)
225 {
226         printf("Testing lock ...\n");
227         tpm_init(dev);
228         tpm_startup(dev, TPM_ST_CLEAR);
229         tpm_self_test_full(dev);
230         tpm_tsc_physical_presence(dev, PRESENCE);
231         tpm_nv_write_value_lock(dev, INDEX0);
232         printf("\tLocked 0x%x\n", INDEX0);
233         printf("\tdone\n");
234         return 0;
235 }
236
237 static void initialise_spaces(struct udevice *dev)
238 {
239         uint32_t zero = 0;
240         uint32_t perm = TPM_NV_PER_WRITE_STCLEAR | TPM_NV_PER_PPWRITE;
241
242         printf("\tInitialising spaces\n");
243         tpm1_nv_set_locked(dev);  /* useful only the first time */
244         tpm1_nv_define_space(dev, INDEX0, perm, 4);
245         tpm_nv_write_value(dev, INDEX0, (uint8_t *)&zero, 4);
246         tpm1_nv_define_space(dev, INDEX1, perm, 4);
247         tpm_nv_write_value(dev, INDEX1, (uint8_t *)&zero, 4);
248         tpm1_nv_define_space(dev, INDEX2, perm, 4);
249         tpm_nv_write_value(dev, INDEX2, (uint8_t *)&zero, 4);
250         tpm1_nv_define_space(dev, INDEX3, perm, 4);
251         tpm_nv_write_value(dev, INDEX3, (uint8_t *)&zero, 4);
252         perm = TPM_NV_PER_READ_STCLEAR | TPM_NV_PER_WRITE_STCLEAR |
253                 TPM_NV_PER_PPWRITE;
254         tpm1_nv_define_space(dev, INDEX_INITIALISED, perm, 1);
255 }
256
257 static int test_readonly(struct udevice *dev)
258 {
259         uint8_t c;
260         uint32_t index_0, index_1, index_2, index_3;
261         int read0, read1, read2, read3;
262
263         printf("Testing readonly ...\n");
264         tpm_init(dev);
265         tpm_startup(dev, TPM_ST_CLEAR);
266         tpm_self_test_full(dev);
267         tpm_tsc_physical_presence(dev, PRESENCE);
268         /*
269          * Checks if initialisation has completed by trying to read-lock a
270          * space that's created at the end of initialisation
271          */
272         if (tpm_nv_read_value(dev, INDEX_INITIALISED, &c, 0) == TPM_BADINDEX) {
273                 /* The initialisation did not complete */
274                 initialise_spaces(dev);
275         }
276
277         /* Checks if spaces are OK or messed up */
278         read0 = tpm_nv_read_value(dev, INDEX0, (uint8_t *)&index_0,
279                                   sizeof(index_0));
280         read1 = tpm_nv_read_value(dev, INDEX1, (uint8_t *)&index_1,
281                                   sizeof(index_1));
282         read2 = tpm_nv_read_value(dev, INDEX2, (uint8_t *)&index_2,
283                                   sizeof(index_2));
284         read3 = tpm_nv_read_value(dev, INDEX3, (uint8_t *)&index_3,
285                                   sizeof(index_3));
286         if (read0 || read1 || read2 || read3) {
287                 printf("Invalid contents\n");
288                 return 0;
289         }
290
291         /*
292          * Writes space, and locks it.  Then attempts to write again.
293          * I really wish I could use the imperative.
294          */
295         index_0 += 1;
296         if (tpm_nv_write_value(dev, INDEX0, (uint8_t *)&index_0,
297                                sizeof(index_0) !=
298                 TPM_SUCCESS)) {
299                 pr_err("\tcould not write index 0\n");
300         }
301         tpm_nv_write_value_lock(dev, INDEX0);
302         if (tpm_nv_write_value(dev, INDEX0, (uint8_t *)&index_0,
303                                sizeof(index_0)) ==
304                         TPM_SUCCESS)
305                 pr_err("\tindex 0 is not locked\n");
306
307         printf("\tdone\n");
308         return 0;
309 }
310
311 static int test_redefine_unowned(struct udevice *dev)
312 {
313         uint32_t perm;
314         uint32_t result;
315         uint32_t x;
316
317         printf("Testing redefine_unowned ...");
318         tpm_init(dev);
319         TPM_CHECK(TlclStartupIfNeeded(dev));
320         TPM_CHECK(tpm_self_test_full(dev));
321         TPM_CHECK(tpm_tsc_physical_presence(dev, PRESENCE));
322         assert(!tpm_is_owned(dev));
323
324         /* Ensures spaces exist. */
325         TPM_CHECK(tpm_nv_read_value(dev, INDEX0, (uint8_t *)&x, sizeof(x)));
326         TPM_CHECK(tpm_nv_read_value(dev, INDEX1, (uint8_t *)&x, sizeof(x)));
327
328         /* Redefines spaces a couple of times. */
329         perm = TPM_NV_PER_PPWRITE | TPM_NV_PER_GLOBALLOCK;
330         TPM_CHECK(tpm1_nv_define_space(dev, INDEX0, perm,
331                                        2 * sizeof(uint32_t)));
332         TPM_CHECK(tpm1_nv_define_space(dev, INDEX0, perm, sizeof(uint32_t)));
333         perm = TPM_NV_PER_PPWRITE;
334         TPM_CHECK(tpm1_nv_define_space(dev, INDEX1, perm,
335                                        2 * sizeof(uint32_t)));
336         TPM_CHECK(tpm1_nv_define_space(dev, INDEX1, perm, sizeof(uint32_t)));
337
338         /* Sets the global lock */
339         tpm_set_global_lock(dev);
340
341         /* Verifies that index0 cannot be redefined */
342         result = tpm1_nv_define_space(dev, INDEX0, perm, sizeof(uint32_t));
343         assert(result == TPM_AREA_LOCKED);
344
345         /* Checks that index1 can */
346         TPM_CHECK(tpm1_nv_define_space(dev, INDEX1, perm,
347                                        2 * sizeof(uint32_t)));
348         TPM_CHECK(tpm1_nv_define_space(dev, INDEX1, perm, sizeof(uint32_t)));
349
350         /* Turns off PP */
351         tpm_tsc_physical_presence(dev, PHYS_PRESENCE);
352
353         /* Verifies that neither index0 nor index1 can be redefined */
354         result = tpm1_nv_define_space(dev, INDEX0, perm, sizeof(uint32_t));
355         assert(result == TPM_BAD_PRESENCE);
356         result = tpm1_nv_define_space(dev, INDEX1, perm, sizeof(uint32_t));
357         assert(result == TPM_BAD_PRESENCE);
358
359         printf("done\n");
360         return 0;
361 }
362
363 #define PERMPPGL (TPM_NV_PER_PPWRITE | TPM_NV_PER_GLOBALLOCK)
364 #define PERMPP TPM_NV_PER_PPWRITE
365
366 static int test_space_perm(struct udevice *dev)
367 {
368         uint32_t perm;
369
370         printf("Testing spaceperm ...");
371         tpm_init(dev);
372         TPM_CHECK(TlclStartupIfNeeded(dev));
373         TPM_CHECK(tpm_continue_self_test(dev));
374         TPM_CHECK(tpm_tsc_physical_presence(dev, PRESENCE));
375         TPM_CHECK(tpm_get_permissions(dev, INDEX0, &perm));
376         assert((perm & PERMPPGL) == PERMPPGL);
377         TPM_CHECK(tpm_get_permissions(dev, INDEX1, &perm));
378         assert((perm & PERMPP) == PERMPP);
379         printf("done\n");
380         return 0;
381 }
382
383 static int test_startup(struct udevice *dev)
384 {
385         uint32_t result;
386
387         printf("Testing startup ...\n");
388
389         tpm_init(dev);
390         result = tpm_startup(dev, TPM_ST_CLEAR);
391         if (result != 0 && result != TPM_INVALID_POSTINIT)
392                 printf("\ttpm startup failed with 0x%x\n", result);
393         result = tpm_get_flags(dev, NULL, NULL, NULL);
394         if (result != 0)
395                 printf("\ttpm getflags failed with 0x%x\n", result);
396         printf("\texecuting SelfTestFull\n");
397         tpm_self_test_full(dev);
398         result = tpm_get_flags(dev, NULL, NULL, NULL);
399         if (result != 0)
400                 printf("\ttpm getflags failed with 0x%x\n", result);
401         printf("\tdone\n");
402         return 0;
403 }
404
405 /*
406  * Runs [op] and ensures it returns success and doesn't run longer than
407  * [time_limit] in milliseconds.
408  */
409 #define TTPM_CHECK(op, time_limit) do { \
410         ulong start, time; \
411         uint32_t __result; \
412         \
413         start = get_timer(0); \
414         __result = op; \
415         if (__result != TPM_SUCCESS) { \
416                 printf("\t" #op ": error 0x%x\n", __result); \
417                 return -1; \
418         } \
419         time = get_timer(start); \
420         printf("\t" #op ": %lu ms\n", time); \
421         if (time > (ulong)time_limit) { \
422                 printf("\t" #op " exceeded " #time_limit " ms\n"); \
423         } \
424 } while (0)
425
426
427 static int test_timing(struct udevice *dev)
428 {
429         uint8_t in[20], out[20];
430         uint32_t x;
431
432         printf("Testing timing ...");
433         tpm_init(dev);
434         TTPM_CHECK(TlclStartupIfNeeded(dev), 50);
435         TTPM_CHECK(tpm_continue_self_test(dev), 100);
436         TTPM_CHECK(tpm_self_test_full(dev), 1000);
437         TTPM_CHECK(tpm_tsc_physical_presence(dev, PRESENCE), 100);
438         TTPM_CHECK(tpm_nv_write_value(dev, INDEX0, (uint8_t *)&x, sizeof(x)),
439                    100);
440         TTPM_CHECK(tpm_nv_read_value(dev, INDEX0, (uint8_t *)&x, sizeof(x)),
441                    100);
442         TTPM_CHECK(tpm_pcr_extend(dev, 0, in, sizeof(in), out, "test"), 200);
443         TTPM_CHECK(tpm_set_global_lock(dev), 50);
444         TTPM_CHECK(tpm_tsc_physical_presence(dev, PHYS_PRESENCE), 100);
445         printf("done\n");
446         return 0;
447 }
448
449 #define TPM_MAX_NV_WRITES_NOOWNER 64
450
451 static int test_write_limit(struct udevice *dev)
452 {
453         uint32_t result;
454         int i;
455
456         printf("Testing writelimit ...\n");
457         tpm_init(dev);
458         TPM_CHECK(TlclStartupIfNeeded(dev));
459         TPM_CHECK(tpm_self_test_full(dev));
460         TPM_CHECK(tpm_tsc_physical_presence(dev, PRESENCE));
461         TPM_CHECK(tpm_force_clear(dev));
462         TPM_CHECK(tpm_physical_enable(dev));
463         TPM_CHECK(tpm_physical_set_deactivated(dev, 0));
464
465         for (i = 0; i < TPM_MAX_NV_WRITES_NOOWNER + 2; i++) {
466                 printf("\twriting %d\n", i);
467                 result = tpm_nv_write_value(dev, INDEX0, (uint8_t *)&i,
468                                             sizeof(i));
469                 switch (result) {
470                 case TPM_SUCCESS:
471                         break;
472                 case TPM_MAXNVWRITES:
473                         assert(i >= TPM_MAX_NV_WRITES_NOOWNER);
474                 default:
475                         pr_err("\tunexpected error code %d (0x%x)\n",
476                               result, result);
477                 }
478         }
479
480         /* Reset write count */
481         TPM_CHECK(tpm_force_clear(dev));
482         TPM_CHECK(tpm_physical_enable(dev));
483         TPM_CHECK(tpm_physical_set_deactivated(dev, 0));
484
485         /* Try writing again. */
486         TPM_CHECK(tpm_nv_write_value(dev, INDEX0, (uint8_t *)&i, sizeof(i)));
487         printf("\tdone\n");
488         return 0;
489 }
490
491 #define VOIDTEST(XFUNC) \
492         int do_test_##XFUNC(struct cmd_tbl *cmd_tbl, int flag, int argc, \
493         char *const argv[]) \
494         { \
495                 struct udevice *dev; \
496                 int ret; \
497 \
498                 ret = get_tpm(&dev); \
499                 if (ret) \
500                         return ret; \
501                 return test_##XFUNC(dev); \
502         }
503
504 #define VOIDENT(XNAME) \
505         U_BOOT_CMD_MKENT(XNAME, 0, 1, do_test_##XNAME, "", ""),
506
507 VOIDTEST(early_extend)
508 VOIDTEST(early_nvram)
509 VOIDTEST(early_nvram2)
510 VOIDTEST(enable)
511 VOIDTEST(fast_enable)
512 VOIDTEST(global_lock)
513 VOIDTEST(lock)
514 VOIDTEST(readonly)
515 VOIDTEST(redefine_unowned)
516 VOIDTEST(space_perm)
517 VOIDTEST(startup)
518 VOIDTEST(timing)
519 VOIDTEST(write_limit)
520 VOIDTEST(timer)
521
522 static struct cmd_tbl cmd_cros_tpm_sub[] = {
523         VOIDENT(early_extend)
524         VOIDENT(early_nvram)
525         VOIDENT(early_nvram2)
526         VOIDENT(enable)
527         VOIDENT(fast_enable)
528         VOIDENT(global_lock)
529         VOIDENT(lock)
530         VOIDENT(readonly)
531         VOIDENT(redefine_unowned)
532         VOIDENT(space_perm)
533         VOIDENT(startup)
534         VOIDENT(timing)
535         VOIDENT(write_limit)
536         VOIDENT(timer)
537 };
538
539 static int do_tpmtest(struct cmd_tbl *cmdtp, int flag, int argc,
540                       char *const argv[])
541 {
542         struct cmd_tbl *c;
543         int i;
544
545         printf("argc = %d, argv = ", argc);
546
547         for (i = 0; i < argc; i++)
548                 printf(" %s", argv[i]);
549
550         printf("\n------\n");
551
552         argc--;
553         argv++;
554         c = find_cmd_tbl(argv[0], cmd_cros_tpm_sub,
555                          ARRAY_SIZE(cmd_cros_tpm_sub));
556         return c ? c->cmd(cmdtp, flag, argc, argv) : cmd_usage(cmdtp);
557 }
558
559 U_BOOT_CMD(tpmtest, 2, 1, do_tpmtest, "TPM tests",
560         "\n\tearly_extend\n"
561         "\tearly_nvram\n"
562         "\tearly_nvram2\n"
563         "\tenable\n"
564         "\tfast_enable\n"
565         "\tglobal_lock\n"
566         "\tlock\n"
567         "\treadonly\n"
568         "\tredefine_unowned\n"
569         "\tspace_perm\n"
570         "\tstartup\n"
571         "\ttiming\n"
572         "\twrite_limit\n");