1 // SPDX-License-Identifier: GPL-2.0+
3 * Copyright (c) 2015 Google, Inc
11 #include "tpm-user-utils.h"
14 /* Prints error and returns on failure */
15 #define TPM_CHECK(tpm_command) do { \
18 result = (tpm_command); \
19 if (result != TPM_SUCCESS) { \
20 printf("TEST FAILED: line %d: " #tpm_command ": 0x%x\n", \
30 #define INDEX_INITIALISED 0xda80
31 #define PHYS_PRESENCE 4
34 static uint32_t TlclStartupIfNeeded(struct udevice *dev)
36 uint32_t result = tpm_startup(dev, TPM_ST_CLEAR);
38 return result == TPM_INVALID_POSTINIT ? TPM_SUCCESS : result;
41 static int test_timer(struct udevice *dev)
43 printf("get_timer(0) = %lu\n", get_timer(0));
47 static uint32_t tpm_get_flags(struct udevice *dev, uint8_t *disable,
48 uint8_t *deactivated, uint8_t *nvlocked)
50 struct tpm_permanent_flags pflags;
53 result = tpm1_get_permanent_flags(dev, &pflags);
57 *disable = pflags.disable;
59 *deactivated = pflags.deactivated;
61 *nvlocked = pflags.nv_locked;
62 debug("TPM: Got flags disable=%d, deactivated=%d, nvlocked=%d\n",
63 pflags.disable, pflags.deactivated, pflags.nv_locked);
68 static uint32_t tpm_nv_write_value_lock(struct udevice *dev, uint32_t index)
70 debug("TPM: Write lock 0x%x\n", index);
72 return tpm_nv_write_value(dev, index, NULL, 0);
75 static int tpm_is_owned(struct udevice *dev)
77 uint8_t response[TPM_PUBEK_SIZE];
80 result = tpm_read_pubek(dev, response, sizeof(response));
82 return result != TPM_SUCCESS;
85 static int test_early_extend(struct udevice *dev)
88 uint8_t value_out[20];
90 printf("Testing earlyextend ...");
92 TPM_CHECK(tpm_startup(dev, TPM_ST_CLEAR));
93 TPM_CHECK(tpm_continue_self_test(dev));
94 TPM_CHECK(tpm_pcr_extend(dev, 1, value_in, sizeof(value_in), value_out,
100 static int test_early_nvram(struct udevice *dev)
104 printf("Testing earlynvram ...");
106 TPM_CHECK(tpm_startup(dev, TPM_ST_CLEAR));
107 TPM_CHECK(tpm_continue_self_test(dev));
108 TPM_CHECK(tpm_tsc_physical_presence(dev, PRESENCE));
109 TPM_CHECK(tpm_nv_read_value(dev, INDEX0, (uint8_t *)&x, sizeof(x)));
114 static int test_early_nvram2(struct udevice *dev)
118 printf("Testing earlynvram2 ...");
120 TPM_CHECK(tpm_startup(dev, TPM_ST_CLEAR));
121 TPM_CHECK(tpm_continue_self_test(dev));
122 TPM_CHECK(tpm_tsc_physical_presence(dev, PRESENCE));
123 TPM_CHECK(tpm_nv_write_value(dev, INDEX0, (uint8_t *)&x, sizeof(x)));
128 static int test_enable(struct udevice *dev)
130 uint8_t disable = 0, deactivated = 0;
132 printf("Testing enable ...\n");
134 TPM_CHECK(TlclStartupIfNeeded(dev));
135 TPM_CHECK(tpm_self_test_full(dev));
136 TPM_CHECK(tpm_tsc_physical_presence(dev, PRESENCE));
137 TPM_CHECK(tpm_get_flags(dev, &disable, &deactivated, NULL));
138 printf("\tdisable is %d, deactivated is %d\n", disable, deactivated);
139 TPM_CHECK(tpm_physical_enable(dev));
140 TPM_CHECK(tpm_physical_set_deactivated(dev, 0));
141 TPM_CHECK(tpm_get_flags(dev, &disable, &deactivated, NULL));
142 printf("\tdisable is %d, deactivated is %d\n", disable, deactivated);
143 if (disable == 1 || deactivated == 1)
144 printf("\tfailed to enable or activate\n");
149 #define reboot() do { \
150 printf("\trebooting...\n"); \
154 static int test_fast_enable(struct udevice *dev)
156 uint8_t disable = 0, deactivated = 0;
159 printf("Testing fastenable ...\n");
161 TPM_CHECK(TlclStartupIfNeeded(dev));
162 TPM_CHECK(tpm_self_test_full(dev));
163 TPM_CHECK(tpm_tsc_physical_presence(dev, PRESENCE));
164 TPM_CHECK(tpm_get_flags(dev, &disable, &deactivated, NULL));
165 printf("\tdisable is %d, deactivated is %d\n", disable, deactivated);
166 for (i = 0; i < 2; i++) {
167 TPM_CHECK(tpm_force_clear(dev));
168 TPM_CHECK(tpm_get_flags(dev, &disable, &deactivated, NULL));
169 printf("\tdisable is %d, deactivated is %d\n", disable,
171 assert(disable == 1 && deactivated == 1);
172 TPM_CHECK(tpm_physical_enable(dev));
173 TPM_CHECK(tpm_physical_set_deactivated(dev, 0));
174 TPM_CHECK(tpm_get_flags(dev, &disable, &deactivated, NULL));
175 printf("\tdisable is %d, deactivated is %d\n", disable,
177 assert(disable == 0 && deactivated == 0);
183 static int test_global_lock(struct udevice *dev)
189 printf("Testing globallock ...\n");
191 TPM_CHECK(TlclStartupIfNeeded(dev));
192 TPM_CHECK(tpm_self_test_full(dev));
193 TPM_CHECK(tpm_tsc_physical_presence(dev, PRESENCE));
194 TPM_CHECK(tpm_nv_read_value(dev, INDEX0, (uint8_t *)&x, sizeof(x)));
195 TPM_CHECK(tpm_nv_write_value(dev, INDEX0, (uint8_t *)&zero,
197 TPM_CHECK(tpm_nv_read_value(dev, INDEX1, (uint8_t *)&x, sizeof(x)));
198 TPM_CHECK(tpm_nv_write_value(dev, INDEX1, (uint8_t *)&zero,
200 TPM_CHECK(tpm_set_global_lock(dev));
201 /* Verifies that write to index0 fails */
203 result = tpm_nv_write_value(dev, INDEX0, (uint8_t *)&x, sizeof(x));
204 assert(result == TPM_AREA_LOCKED);
205 TPM_CHECK(tpm_nv_read_value(dev, INDEX0, (uint8_t *)&x, sizeof(x)));
207 /* Verifies that write to index1 is still possible */
209 TPM_CHECK(tpm_nv_write_value(dev, INDEX1, (uint8_t *)&x, sizeof(x)));
210 TPM_CHECK(tpm_nv_read_value(dev, INDEX1, (uint8_t *)&x, sizeof(x)));
213 tpm_tsc_physical_presence(dev, PHYS_PRESENCE);
214 /* Verifies that write to index1 fails */
216 result = tpm_nv_write_value(dev, INDEX1, (uint8_t *)&x, sizeof(x));
217 assert(result == TPM_BAD_PRESENCE);
218 TPM_CHECK(tpm_nv_read_value(dev, INDEX1, (uint8_t *)&x, sizeof(x)));
224 static int test_lock(struct udevice *dev)
226 printf("Testing lock ...\n");
228 tpm_startup(dev, TPM_ST_CLEAR);
229 tpm_self_test_full(dev);
230 tpm_tsc_physical_presence(dev, PRESENCE);
231 tpm_nv_write_value_lock(dev, INDEX0);
232 printf("\tLocked 0x%x\n", INDEX0);
237 static void initialise_spaces(struct udevice *dev)
240 uint32_t perm = TPM_NV_PER_WRITE_STCLEAR | TPM_NV_PER_PPWRITE;
242 printf("\tInitialising spaces\n");
243 tpm1_nv_set_locked(dev); /* useful only the first time */
244 tpm1_nv_define_space(dev, INDEX0, perm, 4);
245 tpm_nv_write_value(dev, INDEX0, (uint8_t *)&zero, 4);
246 tpm1_nv_define_space(dev, INDEX1, perm, 4);
247 tpm_nv_write_value(dev, INDEX1, (uint8_t *)&zero, 4);
248 tpm1_nv_define_space(dev, INDEX2, perm, 4);
249 tpm_nv_write_value(dev, INDEX2, (uint8_t *)&zero, 4);
250 tpm1_nv_define_space(dev, INDEX3, perm, 4);
251 tpm_nv_write_value(dev, INDEX3, (uint8_t *)&zero, 4);
252 perm = TPM_NV_PER_READ_STCLEAR | TPM_NV_PER_WRITE_STCLEAR |
254 tpm1_nv_define_space(dev, INDEX_INITIALISED, perm, 1);
257 static int test_readonly(struct udevice *dev)
260 uint32_t index_0, index_1, index_2, index_3;
261 int read0, read1, read2, read3;
263 printf("Testing readonly ...\n");
265 tpm_startup(dev, TPM_ST_CLEAR);
266 tpm_self_test_full(dev);
267 tpm_tsc_physical_presence(dev, PRESENCE);
269 * Checks if initialisation has completed by trying to read-lock a
270 * space that's created at the end of initialisation
272 if (tpm_nv_read_value(dev, INDEX_INITIALISED, &c, 0) == TPM_BADINDEX) {
273 /* The initialisation did not complete */
274 initialise_spaces(dev);
277 /* Checks if spaces are OK or messed up */
278 read0 = tpm_nv_read_value(dev, INDEX0, (uint8_t *)&index_0,
280 read1 = tpm_nv_read_value(dev, INDEX1, (uint8_t *)&index_1,
282 read2 = tpm_nv_read_value(dev, INDEX2, (uint8_t *)&index_2,
284 read3 = tpm_nv_read_value(dev, INDEX3, (uint8_t *)&index_3,
286 if (read0 || read1 || read2 || read3) {
287 printf("Invalid contents\n");
292 * Writes space, and locks it. Then attempts to write again.
293 * I really wish I could use the imperative.
296 if (tpm_nv_write_value(dev, INDEX0, (uint8_t *)&index_0,
299 pr_err("\tcould not write index 0\n");
301 tpm_nv_write_value_lock(dev, INDEX0);
302 if (tpm_nv_write_value(dev, INDEX0, (uint8_t *)&index_0,
305 pr_err("\tindex 0 is not locked\n");
311 static int test_redefine_unowned(struct udevice *dev)
317 printf("Testing redefine_unowned ...");
319 TPM_CHECK(TlclStartupIfNeeded(dev));
320 TPM_CHECK(tpm_self_test_full(dev));
321 TPM_CHECK(tpm_tsc_physical_presence(dev, PRESENCE));
322 assert(!tpm_is_owned(dev));
324 /* Ensures spaces exist. */
325 TPM_CHECK(tpm_nv_read_value(dev, INDEX0, (uint8_t *)&x, sizeof(x)));
326 TPM_CHECK(tpm_nv_read_value(dev, INDEX1, (uint8_t *)&x, sizeof(x)));
328 /* Redefines spaces a couple of times. */
329 perm = TPM_NV_PER_PPWRITE | TPM_NV_PER_GLOBALLOCK;
330 TPM_CHECK(tpm1_nv_define_space(dev, INDEX0, perm,
331 2 * sizeof(uint32_t)));
332 TPM_CHECK(tpm1_nv_define_space(dev, INDEX0, perm, sizeof(uint32_t)));
333 perm = TPM_NV_PER_PPWRITE;
334 TPM_CHECK(tpm1_nv_define_space(dev, INDEX1, perm,
335 2 * sizeof(uint32_t)));
336 TPM_CHECK(tpm1_nv_define_space(dev, INDEX1, perm, sizeof(uint32_t)));
338 /* Sets the global lock */
339 tpm_set_global_lock(dev);
341 /* Verifies that index0 cannot be redefined */
342 result = tpm1_nv_define_space(dev, INDEX0, perm, sizeof(uint32_t));
343 assert(result == TPM_AREA_LOCKED);
345 /* Checks that index1 can */
346 TPM_CHECK(tpm1_nv_define_space(dev, INDEX1, perm,
347 2 * sizeof(uint32_t)));
348 TPM_CHECK(tpm1_nv_define_space(dev, INDEX1, perm, sizeof(uint32_t)));
351 tpm_tsc_physical_presence(dev, PHYS_PRESENCE);
353 /* Verifies that neither index0 nor index1 can be redefined */
354 result = tpm1_nv_define_space(dev, INDEX0, perm, sizeof(uint32_t));
355 assert(result == TPM_BAD_PRESENCE);
356 result = tpm1_nv_define_space(dev, INDEX1, perm, sizeof(uint32_t));
357 assert(result == TPM_BAD_PRESENCE);
363 #define PERMPPGL (TPM_NV_PER_PPWRITE | TPM_NV_PER_GLOBALLOCK)
364 #define PERMPP TPM_NV_PER_PPWRITE
366 static int test_space_perm(struct udevice *dev)
370 printf("Testing spaceperm ...");
372 TPM_CHECK(TlclStartupIfNeeded(dev));
373 TPM_CHECK(tpm_continue_self_test(dev));
374 TPM_CHECK(tpm_tsc_physical_presence(dev, PRESENCE));
375 TPM_CHECK(tpm_get_permissions(dev, INDEX0, &perm));
376 assert((perm & PERMPPGL) == PERMPPGL);
377 TPM_CHECK(tpm_get_permissions(dev, INDEX1, &perm));
378 assert((perm & PERMPP) == PERMPP);
383 static int test_startup(struct udevice *dev)
387 printf("Testing startup ...\n");
390 result = tpm_startup(dev, TPM_ST_CLEAR);
391 if (result != 0 && result != TPM_INVALID_POSTINIT)
392 printf("\ttpm startup failed with 0x%x\n", result);
393 result = tpm_get_flags(dev, NULL, NULL, NULL);
395 printf("\ttpm getflags failed with 0x%x\n", result);
396 printf("\texecuting SelfTestFull\n");
397 tpm_self_test_full(dev);
398 result = tpm_get_flags(dev, NULL, NULL, NULL);
400 printf("\ttpm getflags failed with 0x%x\n", result);
406 * Runs [op] and ensures it returns success and doesn't run longer than
407 * [time_limit] in milliseconds.
409 #define TTPM_CHECK(op, time_limit) do { \
413 start = get_timer(0); \
415 if (__result != TPM_SUCCESS) { \
416 printf("\t" #op ": error 0x%x\n", __result); \
419 time = get_timer(start); \
420 printf("\t" #op ": %lu ms\n", time); \
421 if (time > (ulong)time_limit) { \
422 printf("\t" #op " exceeded " #time_limit " ms\n"); \
427 static int test_timing(struct udevice *dev)
429 uint8_t in[20], out[20];
432 printf("Testing timing ...");
434 TTPM_CHECK(TlclStartupIfNeeded(dev), 50);
435 TTPM_CHECK(tpm_continue_self_test(dev), 100);
436 TTPM_CHECK(tpm_self_test_full(dev), 1000);
437 TTPM_CHECK(tpm_tsc_physical_presence(dev, PRESENCE), 100);
438 TTPM_CHECK(tpm_nv_write_value(dev, INDEX0, (uint8_t *)&x, sizeof(x)),
440 TTPM_CHECK(tpm_nv_read_value(dev, INDEX0, (uint8_t *)&x, sizeof(x)),
442 TTPM_CHECK(tpm_pcr_extend(dev, 0, in, sizeof(in), out, "test"), 200);
443 TTPM_CHECK(tpm_set_global_lock(dev), 50);
444 TTPM_CHECK(tpm_tsc_physical_presence(dev, PHYS_PRESENCE), 100);
449 #define TPM_MAX_NV_WRITES_NOOWNER 64
451 static int test_write_limit(struct udevice *dev)
456 printf("Testing writelimit ...\n");
458 TPM_CHECK(TlclStartupIfNeeded(dev));
459 TPM_CHECK(tpm_self_test_full(dev));
460 TPM_CHECK(tpm_tsc_physical_presence(dev, PRESENCE));
461 TPM_CHECK(tpm_force_clear(dev));
462 TPM_CHECK(tpm_physical_enable(dev));
463 TPM_CHECK(tpm_physical_set_deactivated(dev, 0));
465 for (i = 0; i < TPM_MAX_NV_WRITES_NOOWNER + 2; i++) {
466 printf("\twriting %d\n", i);
467 result = tpm_nv_write_value(dev, INDEX0, (uint8_t *)&i,
472 case TPM_MAXNVWRITES:
473 assert(i >= TPM_MAX_NV_WRITES_NOOWNER);
475 pr_err("\tunexpected error code %d (0x%x)\n",
480 /* Reset write count */
481 TPM_CHECK(tpm_force_clear(dev));
482 TPM_CHECK(tpm_physical_enable(dev));
483 TPM_CHECK(tpm_physical_set_deactivated(dev, 0));
485 /* Try writing again. */
486 TPM_CHECK(tpm_nv_write_value(dev, INDEX0, (uint8_t *)&i, sizeof(i)));
491 #define VOIDTEST(XFUNC) \
492 int do_test_##XFUNC(struct cmd_tbl *cmd_tbl, int flag, int argc, \
493 char *const argv[]) \
495 struct udevice *dev; \
498 ret = get_tpm(&dev); \
501 return test_##XFUNC(dev); \
504 #define VOIDENT(XNAME) \
505 U_BOOT_CMD_MKENT(XNAME, 0, 1, do_test_##XNAME, "", ""),
507 VOIDTEST(early_extend)
508 VOIDTEST(early_nvram)
509 VOIDTEST(early_nvram2)
511 VOIDTEST(fast_enable)
512 VOIDTEST(global_lock)
515 VOIDTEST(redefine_unowned)
519 VOIDTEST(write_limit)
522 static struct cmd_tbl cmd_cros_tpm_sub[] = {
523 VOIDENT(early_extend)
525 VOIDENT(early_nvram2)
531 VOIDENT(redefine_unowned)
539 static int do_tpmtest(struct cmd_tbl *cmdtp, int flag, int argc,
545 printf("argc = %d, argv = ", argc);
547 for (i = 0; i < argc; i++)
548 printf(" %s", argv[i]);
550 printf("\n------\n");
554 c = find_cmd_tbl(argv[0], cmd_cros_tpm_sub,
555 ARRAY_SIZE(cmd_cros_tpm_sub));
556 return c ? c->cmd(cmdtp, flag, argc, argv) : cmd_usage(cmdtp);
559 U_BOOT_CMD(tpmtest, 2, 1, do_tpmtest, "TPM tests",
568 "\tredefine_unowned\n"