1 // SPDX-License-Identifier: GPL-2.0+
3 * Copyright (c) 2015 Google, Inc
9 #include "tpm-user-utils.h"
11 /* Prints error and returns on failure */
12 #define TPM_CHECK(tpm_command) do { \
15 result = (tpm_command); \
16 if (result != TPM_SUCCESS) { \
17 printf("TEST FAILED: line %d: " #tpm_command ": 0x%x\n", \
27 #define INDEX_INITIALISED 0xda80
28 #define PHYS_PRESENCE 4
31 static uint32_t TlclStartupIfNeeded(struct udevice *dev)
33 uint32_t result = tpm_startup(dev, TPM_ST_CLEAR);
35 return result == TPM_INVALID_POSTINIT ? TPM_SUCCESS : result;
38 static int test_timer(struct udevice *dev)
40 printf("get_timer(0) = %lu\n", get_timer(0));
44 static uint32_t tpm_get_flags(struct udevice *dev, uint8_t *disable,
45 uint8_t *deactivated, uint8_t *nvlocked)
47 struct tpm_permanent_flags pflags;
50 result = tpm_get_permanent_flags(dev, &pflags);
54 *disable = pflags.disable;
56 *deactivated = pflags.deactivated;
58 *nvlocked = pflags.nv_locked;
59 debug("TPM: Got flags disable=%d, deactivated=%d, nvlocked=%d\n",
60 pflags.disable, pflags.deactivated, pflags.nv_locked);
65 static uint32_t tpm_nv_write_value_lock(struct udevice *dev, uint32_t index)
67 debug("TPM: Write lock 0x%x\n", index);
69 return tpm_nv_write_value(dev, index, NULL, 0);
72 static int tpm_is_owned(struct udevice *dev)
74 uint8_t response[TPM_PUBEK_SIZE];
77 result = tpm_read_pubek(dev, response, sizeof(response));
79 return result != TPM_SUCCESS;
82 static int test_early_extend(struct udevice *dev)
85 uint8_t value_out[20];
87 printf("Testing earlyextend ...");
89 TPM_CHECK(tpm_startup(dev, TPM_ST_CLEAR));
90 TPM_CHECK(tpm_continue_self_test(dev));
91 TPM_CHECK(tpm_extend(dev, 1, value_in, value_out));
96 static int test_early_nvram(struct udevice *dev)
100 printf("Testing earlynvram ...");
102 TPM_CHECK(tpm_startup(dev, TPM_ST_CLEAR));
103 TPM_CHECK(tpm_continue_self_test(dev));
104 TPM_CHECK(tpm_tsc_physical_presence(dev, PRESENCE));
105 TPM_CHECK(tpm_nv_read_value(dev, INDEX0, (uint8_t *)&x, sizeof(x)));
110 static int test_early_nvram2(struct udevice *dev)
114 printf("Testing earlynvram2 ...");
116 TPM_CHECK(tpm_startup(dev, TPM_ST_CLEAR));
117 TPM_CHECK(tpm_continue_self_test(dev));
118 TPM_CHECK(tpm_tsc_physical_presence(dev, PRESENCE));
119 TPM_CHECK(tpm_nv_write_value(dev, INDEX0, (uint8_t *)&x, sizeof(x)));
124 static int test_enable(struct udevice *dev)
126 uint8_t disable = 0, deactivated = 0;
128 printf("Testing enable ...\n");
130 TPM_CHECK(TlclStartupIfNeeded(dev));
131 TPM_CHECK(tpm_self_test_full(dev));
132 TPM_CHECK(tpm_tsc_physical_presence(dev, PRESENCE));
133 TPM_CHECK(tpm_get_flags(dev, &disable, &deactivated, NULL));
134 printf("\tdisable is %d, deactivated is %d\n", disable, deactivated);
135 TPM_CHECK(tpm_physical_enable(dev));
136 TPM_CHECK(tpm_physical_set_deactivated(dev, 0));
137 TPM_CHECK(tpm_get_flags(dev, &disable, &deactivated, NULL));
138 printf("\tdisable is %d, deactivated is %d\n", disable, deactivated);
139 if (disable == 1 || deactivated == 1)
140 printf("\tfailed to enable or activate\n");
145 #define reboot() do { \
146 printf("\trebooting...\n"); \
150 static int test_fast_enable(struct udevice *dev)
152 uint8_t disable = 0, deactivated = 0;
155 printf("Testing fastenable ...\n");
157 TPM_CHECK(TlclStartupIfNeeded(dev));
158 TPM_CHECK(tpm_self_test_full(dev));
159 TPM_CHECK(tpm_tsc_physical_presence(dev, PRESENCE));
160 TPM_CHECK(tpm_get_flags(dev, &disable, &deactivated, NULL));
161 printf("\tdisable is %d, deactivated is %d\n", disable, deactivated);
162 for (i = 0; i < 2; i++) {
163 TPM_CHECK(tpm_force_clear(dev));
164 TPM_CHECK(tpm_get_flags(dev, &disable, &deactivated, NULL));
165 printf("\tdisable is %d, deactivated is %d\n", disable,
167 assert(disable == 1 && deactivated == 1);
168 TPM_CHECK(tpm_physical_enable(dev));
169 TPM_CHECK(tpm_physical_set_deactivated(dev, 0));
170 TPM_CHECK(tpm_get_flags(dev, &disable, &deactivated, NULL));
171 printf("\tdisable is %d, deactivated is %d\n", disable,
173 assert(disable == 0 && deactivated == 0);
179 static int test_global_lock(struct udevice *dev)
185 printf("Testing globallock ...\n");
187 TPM_CHECK(TlclStartupIfNeeded(dev));
188 TPM_CHECK(tpm_self_test_full(dev));
189 TPM_CHECK(tpm_tsc_physical_presence(dev, PRESENCE));
190 TPM_CHECK(tpm_nv_read_value(dev, INDEX0, (uint8_t *)&x, sizeof(x)));
191 TPM_CHECK(tpm_nv_write_value(dev, INDEX0, (uint8_t *)&zero,
193 TPM_CHECK(tpm_nv_read_value(dev, INDEX1, (uint8_t *)&x, sizeof(x)));
194 TPM_CHECK(tpm_nv_write_value(dev, INDEX1, (uint8_t *)&zero,
196 TPM_CHECK(tpm_set_global_lock(dev));
197 /* Verifies that write to index0 fails */
199 result = tpm_nv_write_value(dev, INDEX0, (uint8_t *)&x, sizeof(x));
200 assert(result == TPM_AREA_LOCKED);
201 TPM_CHECK(tpm_nv_read_value(dev, INDEX0, (uint8_t *)&x, sizeof(x)));
203 /* Verifies that write to index1 is still possible */
205 TPM_CHECK(tpm_nv_write_value(dev, INDEX1, (uint8_t *)&x, sizeof(x)));
206 TPM_CHECK(tpm_nv_read_value(dev, INDEX1, (uint8_t *)&x, sizeof(x)));
209 tpm_tsc_physical_presence(dev, PHYS_PRESENCE);
210 /* Verifies that write to index1 fails */
212 result = tpm_nv_write_value(dev, INDEX1, (uint8_t *)&x, sizeof(x));
213 assert(result == TPM_BAD_PRESENCE);
214 TPM_CHECK(tpm_nv_read_value(dev, INDEX1, (uint8_t *)&x, sizeof(x)));
220 static int test_lock(struct udevice *dev)
222 printf("Testing lock ...\n");
224 tpm_startup(dev, TPM_ST_CLEAR);
225 tpm_self_test_full(dev);
226 tpm_tsc_physical_presence(dev, PRESENCE);
227 tpm_nv_write_value_lock(dev, INDEX0);
228 printf("\tLocked 0x%x\n", INDEX0);
233 static void initialise_spaces(struct udevice *dev)
236 uint32_t perm = TPM_NV_PER_WRITE_STCLEAR | TPM_NV_PER_PPWRITE;
238 printf("\tInitialising spaces\n");
239 tpm_nv_set_locked(dev); /* useful only the first time */
240 tpm_nv_define_space(dev, INDEX0, perm, 4);
241 tpm_nv_write_value(dev, INDEX0, (uint8_t *)&zero, 4);
242 tpm_nv_define_space(dev, INDEX1, perm, 4);
243 tpm_nv_write_value(dev, INDEX1, (uint8_t *)&zero, 4);
244 tpm_nv_define_space(dev, INDEX2, perm, 4);
245 tpm_nv_write_value(dev, INDEX2, (uint8_t *)&zero, 4);
246 tpm_nv_define_space(dev, INDEX3, perm, 4);
247 tpm_nv_write_value(dev, INDEX3, (uint8_t *)&zero, 4);
248 perm = TPM_NV_PER_READ_STCLEAR | TPM_NV_PER_WRITE_STCLEAR |
250 tpm_nv_define_space(dev, INDEX_INITIALISED, perm, 1);
253 static int test_readonly(struct udevice *dev)
256 uint32_t index_0, index_1, index_2, index_3;
257 int read0, read1, read2, read3;
259 printf("Testing readonly ...\n");
261 tpm_startup(dev, TPM_ST_CLEAR);
262 tpm_self_test_full(dev);
263 tpm_tsc_physical_presence(dev, PRESENCE);
265 * Checks if initialisation has completed by trying to read-lock a
266 * space that's created at the end of initialisation
268 if (tpm_nv_read_value(dev, INDEX_INITIALISED, &c, 0) == TPM_BADINDEX) {
269 /* The initialisation did not complete */
270 initialise_spaces(dev);
273 /* Checks if spaces are OK or messed up */
274 read0 = tpm_nv_read_value(dev, INDEX0, (uint8_t *)&index_0,
276 read1 = tpm_nv_read_value(dev, INDEX1, (uint8_t *)&index_1,
278 read2 = tpm_nv_read_value(dev, INDEX2, (uint8_t *)&index_2,
280 read3 = tpm_nv_read_value(dev, INDEX3, (uint8_t *)&index_3,
282 if (read0 || read1 || read2 || read3) {
283 printf("Invalid contents\n");
288 * Writes space, and locks it. Then attempts to write again.
289 * I really wish I could use the imperative.
292 if (tpm_nv_write_value(dev, INDEX0, (uint8_t *)&index_0,
295 pr_err("\tcould not write index 0\n");
297 tpm_nv_write_value_lock(dev, INDEX0);
298 if (tpm_nv_write_value(dev, INDEX0, (uint8_t *)&index_0,
301 pr_err("\tindex 0 is not locked\n");
307 static int test_redefine_unowned(struct udevice *dev)
313 printf("Testing redefine_unowned ...");
315 TPM_CHECK(TlclStartupIfNeeded(dev));
316 TPM_CHECK(tpm_self_test_full(dev));
317 TPM_CHECK(tpm_tsc_physical_presence(dev, PRESENCE));
318 assert(!tpm_is_owned(dev));
320 /* Ensures spaces exist. */
321 TPM_CHECK(tpm_nv_read_value(dev, INDEX0, (uint8_t *)&x, sizeof(x)));
322 TPM_CHECK(tpm_nv_read_value(dev, INDEX1, (uint8_t *)&x, sizeof(x)));
324 /* Redefines spaces a couple of times. */
325 perm = TPM_NV_PER_PPWRITE | TPM_NV_PER_GLOBALLOCK;
326 TPM_CHECK(tpm_nv_define_space(dev, INDEX0, perm, 2 * sizeof(uint32_t)));
327 TPM_CHECK(tpm_nv_define_space(dev, INDEX0, perm, sizeof(uint32_t)));
328 perm = TPM_NV_PER_PPWRITE;
329 TPM_CHECK(tpm_nv_define_space(dev, INDEX1, perm, 2 * sizeof(uint32_t)));
330 TPM_CHECK(tpm_nv_define_space(dev, INDEX1, perm, sizeof(uint32_t)));
332 /* Sets the global lock */
333 tpm_set_global_lock(dev);
335 /* Verifies that index0 cannot be redefined */
336 result = tpm_nv_define_space(dev, INDEX0, perm, sizeof(uint32_t));
337 assert(result == TPM_AREA_LOCKED);
339 /* Checks that index1 can */
340 TPM_CHECK(tpm_nv_define_space(dev, INDEX1, perm, 2 * sizeof(uint32_t)));
341 TPM_CHECK(tpm_nv_define_space(dev, INDEX1, perm, sizeof(uint32_t)));
344 tpm_tsc_physical_presence(dev, PHYS_PRESENCE);
346 /* Verifies that neither index0 nor index1 can be redefined */
347 result = tpm_nv_define_space(dev, INDEX0, perm, sizeof(uint32_t));
348 assert(result == TPM_BAD_PRESENCE);
349 result = tpm_nv_define_space(dev, INDEX1, perm, sizeof(uint32_t));
350 assert(result == TPM_BAD_PRESENCE);
356 #define PERMPPGL (TPM_NV_PER_PPWRITE | TPM_NV_PER_GLOBALLOCK)
357 #define PERMPP TPM_NV_PER_PPWRITE
359 static int test_space_perm(struct udevice *dev)
363 printf("Testing spaceperm ...");
365 TPM_CHECK(TlclStartupIfNeeded(dev));
366 TPM_CHECK(tpm_continue_self_test(dev));
367 TPM_CHECK(tpm_tsc_physical_presence(dev, PRESENCE));
368 TPM_CHECK(tpm_get_permissions(dev, INDEX0, &perm));
369 assert((perm & PERMPPGL) == PERMPPGL);
370 TPM_CHECK(tpm_get_permissions(dev, INDEX1, &perm));
371 assert((perm & PERMPP) == PERMPP);
376 static int test_startup(struct udevice *dev)
380 printf("Testing startup ...\n");
383 result = tpm_startup(dev, TPM_ST_CLEAR);
384 if (result != 0 && result != TPM_INVALID_POSTINIT)
385 printf("\ttpm startup failed with 0x%x\n", result);
386 result = tpm_get_flags(dev, NULL, NULL, NULL);
388 printf("\ttpm getflags failed with 0x%x\n", result);
389 printf("\texecuting SelfTestFull\n");
390 tpm_self_test_full(dev);
391 result = tpm_get_flags(dev, NULL, NULL, NULL);
393 printf("\ttpm getflags failed with 0x%x\n", result);
399 * Runs [op] and ensures it returns success and doesn't run longer than
400 * [time_limit] in milliseconds.
402 #define TTPM_CHECK(op, time_limit) do { \
406 start = get_timer(0); \
408 if (__result != TPM_SUCCESS) { \
409 printf("\t" #op ": error 0x%x\n", __result); \
412 time = get_timer(start); \
413 printf("\t" #op ": %lu ms\n", time); \
414 if (time > (ulong)time_limit) { \
415 printf("\t" #op " exceeded " #time_limit " ms\n"); \
420 static int test_timing(struct udevice *dev)
422 uint8_t in[20], out[20];
425 printf("Testing timing ...");
427 TTPM_CHECK(TlclStartupIfNeeded(dev), 50);
428 TTPM_CHECK(tpm_continue_self_test(dev), 100);
429 TTPM_CHECK(tpm_self_test_full(dev), 1000);
430 TTPM_CHECK(tpm_tsc_physical_presence(dev, PRESENCE), 100);
431 TTPM_CHECK(tpm_nv_write_value(dev, INDEX0, (uint8_t *)&x, sizeof(x)),
433 TTPM_CHECK(tpm_nv_read_value(dev, INDEX0, (uint8_t *)&x, sizeof(x)),
435 TTPM_CHECK(tpm_extend(dev, 0, in, out), 200);
436 TTPM_CHECK(tpm_set_global_lock(dev), 50);
437 TTPM_CHECK(tpm_tsc_physical_presence(dev, PHYS_PRESENCE), 100);
442 #define TPM_MAX_NV_WRITES_NOOWNER 64
444 static int test_write_limit(struct udevice *dev)
449 printf("Testing writelimit ...\n");
451 TPM_CHECK(TlclStartupIfNeeded(dev));
452 TPM_CHECK(tpm_self_test_full(dev));
453 TPM_CHECK(tpm_tsc_physical_presence(dev, PRESENCE));
454 TPM_CHECK(tpm_force_clear(dev));
455 TPM_CHECK(tpm_physical_enable(dev));
456 TPM_CHECK(tpm_physical_set_deactivated(dev, 0));
458 for (i = 0; i < TPM_MAX_NV_WRITES_NOOWNER + 2; i++) {
459 printf("\twriting %d\n", i);
460 result = tpm_nv_write_value(dev, INDEX0, (uint8_t *)&i,
465 case TPM_MAXNVWRITES:
466 assert(i >= TPM_MAX_NV_WRITES_NOOWNER);
468 pr_err("\tunexpected error code %d (0x%x)\n",
473 /* Reset write count */
474 TPM_CHECK(tpm_force_clear(dev));
475 TPM_CHECK(tpm_physical_enable(dev));
476 TPM_CHECK(tpm_physical_set_deactivated(dev, 0));
478 /* Try writing again. */
479 TPM_CHECK(tpm_nv_write_value(dev, INDEX0, (uint8_t *)&i, sizeof(i)));
484 #define VOIDTEST(XFUNC) \
485 int do_test_##XFUNC(cmd_tbl_t *cmd_tbl, int flag, int argc, \
486 char * const argv[]) \
488 struct udevice *dev; \
491 ret = get_tpm(&dev); \
494 return test_##XFUNC(dev); \
497 #define VOIDENT(XNAME) \
498 U_BOOT_CMD_MKENT(XNAME, 0, 1, do_test_##XNAME, "", ""),
500 VOIDTEST(early_extend)
501 VOIDTEST(early_nvram)
502 VOIDTEST(early_nvram2)
504 VOIDTEST(fast_enable)
505 VOIDTEST(global_lock)
508 VOIDTEST(redefine_unowned)
512 VOIDTEST(write_limit)
515 static cmd_tbl_t cmd_cros_tpm_sub[] = {
516 VOIDENT(early_extend)
518 VOIDENT(early_nvram2)
524 VOIDENT(redefine_unowned)
532 static int do_tpmtest(cmd_tbl_t *cmdtp, int flag, int argc, char * const argv[])
537 printf("argc = %d, argv = ", argc);
539 for (i = 0; i < argc; i++)
540 printf(" %s", argv[i]);
542 printf("\n------\n");
546 c = find_cmd_tbl(argv[0], cmd_cros_tpm_sub,
547 ARRAY_SIZE(cmd_cros_tpm_sub));
548 return c ? c->cmd(cmdtp, flag, argc, argv) : cmd_usage(cmdtp);
551 U_BOOT_CMD(tpmtest, 2, 1, do_tpmtest, "TPM tests",
560 "\tredefine_unowned\n"