1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215 216 217 218 219 220 221 222 223 224 225 226 227 228 229 230 231 232 233 234 235 236 237 238 239 240 241 242 243 244 245 246 247 248 249 250 251 252 253 254 255 256 257 258 259 260 261 262 263 264 265 266 267 268 269 270 271 272 273 274 275 276 277 278 279 280 281 282 283 284 285 286 287 288 289 290 291 292 293 294 295 296 297 298 299 300 301 302 303 304 305 306 307 308 309 310 311
|
// SPDX-License-Identifier: GPL-2.0-only
/*
* AMD Secure Processor Seamless Firmware Servicing support.
*
* Copyright (C) 2025 Advanced Micro Devices, Inc.
*
* Author: Ashish Kalra <ashish.kalra@amd.com>
*/
#include <linux/firmware.h>
#include "sfs.h"
#include "sev-dev.h"
#define SFS_DEFAULT_TIMEOUT (10 * MSEC_PER_SEC)
#define SFS_MAX_PAYLOAD_SIZE (2 * 1024 * 1024)
#define SFS_NUM_2MB_PAGES_CMDBUF (SFS_MAX_PAYLOAD_SIZE / PMD_SIZE)
#define SFS_NUM_PAGES_CMDBUF (SFS_MAX_PAYLOAD_SIZE / PAGE_SIZE)
static DEFINE_MUTEX(sfs_ioctl_mutex);
static struct sfs_misc_dev *misc_dev;
static int send_sfs_cmd(struct sfs_device *sfs_dev, int msg)
{
int ret;
sfs_dev->command_buf->hdr.status = 0;
sfs_dev->command_buf->hdr.sub_cmd_id = msg;
ret = psp_extended_mailbox_cmd(sfs_dev->psp,
SFS_DEFAULT_TIMEOUT,
(struct psp_ext_request *)sfs_dev->command_buf);
if (ret == -EIO) {
dev_dbg(sfs_dev->dev,
"msg 0x%x failed with PSP error: 0x%x, extended status: 0x%x\n",
msg, sfs_dev->command_buf->hdr.status,
*(u32 *)sfs_dev->command_buf->buf);
}
return ret;
}
static int send_sfs_get_fw_versions(struct sfs_device *sfs_dev)
{
/*
* SFS_GET_FW_VERSIONS command needs the output buffer to be
* initialized to 0xC7 in every byte.
*/
memset(sfs_dev->command_buf->sfs_buffer, 0xc7, PAGE_SIZE);
sfs_dev->command_buf->hdr.payload_size = 2 * PAGE_SIZE;
return send_sfs_cmd(sfs_dev, PSP_SFS_GET_FW_VERSIONS);
}
static int send_sfs_update_package(struct sfs_device *sfs_dev, const char *payload_name)
{
char payload_path[PAYLOAD_NAME_SIZE + sizeof("amd/")];
const struct firmware *firmware;
unsigned long package_size;
int ret;
/* Sanitize userspace provided payload name */
if (!strnchr(payload_name, PAYLOAD_NAME_SIZE, '\0'))
return -EINVAL;
snprintf(payload_path, sizeof(payload_path), "amd/%s", payload_name);
ret = firmware_request_nowarn(&firmware, payload_path, sfs_dev->dev);
if (ret < 0) {
dev_warn_ratelimited(sfs_dev->dev, "firmware request failed for %s (%d)\n",
payload_path, ret);
return -ENOENT;
}
/*
* SFS Update Package command's input buffer contains TEE_EXT_CMD_BUFFER
* followed by the Update Package and it should be 64KB aligned.
*/
package_size = ALIGN(firmware->size + PAGE_SIZE, 0x10000U);
/*
* SFS command buffer is a pre-allocated 2MB buffer, fail update package
* if SFS payload is larger than the pre-allocated command buffer.
*/
if (package_size > SFS_MAX_PAYLOAD_SIZE) {
dev_warn_ratelimited(sfs_dev->dev,
"SFS payload size %ld larger than maximum supported payload size of %u\n",
package_size, SFS_MAX_PAYLOAD_SIZE);
release_firmware(firmware);
return -E2BIG;
}
/*
* Copy firmware data to a HV_Fixed memory region.
*/
memcpy(sfs_dev->command_buf->sfs_buffer, firmware->data, firmware->size);
sfs_dev->command_buf->hdr.payload_size = package_size;
release_firmware(firmware);
return send_sfs_cmd(sfs_dev, PSP_SFS_UPDATE);
}
static long sfs_ioctl(struct file *filp, unsigned int cmd, unsigned long arg)
{
struct sfs_user_get_fw_versions __user *sfs_get_fw_versions;
struct sfs_user_update_package __user *sfs_update_package;
struct psp_device *psp_master = psp_get_master_device();
char payload_name[PAYLOAD_NAME_SIZE];
struct sfs_device *sfs_dev;
int ret = 0;
if (!psp_master || !psp_master->sfs_data)
return -ENODEV;
sfs_dev = psp_master->sfs_data;
guard(mutex)(&sfs_ioctl_mutex);
switch (cmd) {
case SFSIOCFWVERS:
dev_dbg(sfs_dev->dev, "in SFSIOCFWVERS\n");
sfs_get_fw_versions = (struct sfs_user_get_fw_versions __user *)arg;
ret = send_sfs_get_fw_versions(sfs_dev);
if (ret && ret != -EIO)
return ret;
/*
* Return SFS status and extended status back to userspace
* if PSP status indicated success or command error.
*/
if (copy_to_user(&sfs_get_fw_versions->blob, sfs_dev->command_buf->sfs_buffer,
PAGE_SIZE))
return -EFAULT;
if (copy_to_user(&sfs_get_fw_versions->sfs_status,
&sfs_dev->command_buf->hdr.status,
sizeof(sfs_get_fw_versions->sfs_status)))
return -EFAULT;
if (copy_to_user(&sfs_get_fw_versions->sfs_extended_status,
&sfs_dev->command_buf->buf,
sizeof(sfs_get_fw_versions->sfs_extended_status)))
return -EFAULT;
break;
case SFSIOCUPDATEPKG:
dev_dbg(sfs_dev->dev, "in SFSIOCUPDATEPKG\n");
sfs_update_package = (struct sfs_user_update_package __user *)arg;
if (copy_from_user(payload_name, sfs_update_package->payload_name,
PAYLOAD_NAME_SIZE))
return -EFAULT;
ret = send_sfs_update_package(sfs_dev, payload_name);
if (ret && ret != -EIO)
return ret;
/*
* Return SFS status and extended status back to userspace
* if PSP status indicated success or command error.
*/
if (copy_to_user(&sfs_update_package->sfs_status,
&sfs_dev->command_buf->hdr.status,
sizeof(sfs_update_package->sfs_status)))
return -EFAULT;
if (copy_to_user(&sfs_update_package->sfs_extended_status,
&sfs_dev->command_buf->buf,
sizeof(sfs_update_package->sfs_extended_status)))
return -EFAULT;
break;
default:
ret = -EINVAL;
}
return ret;
}
static const struct file_operations sfs_fops = {
.owner = THIS_MODULE,
.unlocked_ioctl = sfs_ioctl,
};
static void sfs_exit(struct kref *ref)
{
misc_deregister(&misc_dev->misc);
kfree(misc_dev);
misc_dev = NULL;
}
void sfs_dev_destroy(struct psp_device *psp)
{
struct sfs_device *sfs_dev = psp->sfs_data;
if (!sfs_dev)
return;
/*
* Change SFS command buffer back to the default "Write-Back" type.
*/
set_memory_wb((unsigned long)sfs_dev->command_buf, SFS_NUM_PAGES_CMDBUF);
snp_free_hv_fixed_pages(sfs_dev->page);
if (sfs_dev->misc)
kref_put(&misc_dev->refcount, sfs_exit);
psp->sfs_data = NULL;
}
/* Based on sev_misc_init() */
static int sfs_misc_init(struct sfs_device *sfs)
{
struct device *dev = sfs->dev;
int ret;
/*
* SFS feature support can be detected on multiple devices but the SFS
* FW commands must be issued on the master. During probe, we do not
* know the master hence we create /dev/sfs on the first device probe.
*/
if (!misc_dev) {
struct miscdevice *misc;
misc_dev = kzalloc(sizeof(*misc_dev), GFP_KERNEL);
if (!misc_dev)
return -ENOMEM;
misc = &misc_dev->misc;
misc->minor = MISC_DYNAMIC_MINOR;
misc->name = "sfs";
misc->fops = &sfs_fops;
misc->mode = 0600;
ret = misc_register(misc);
if (ret)
return ret;
kref_init(&misc_dev->refcount);
} else {
kref_get(&misc_dev->refcount);
}
sfs->misc = misc_dev;
dev_dbg(dev, "registered SFS device\n");
return 0;
}
int sfs_dev_init(struct psp_device *psp)
{
struct device *dev = psp->dev;
struct sfs_device *sfs_dev;
struct page *page;
int ret = -ENOMEM;
sfs_dev = devm_kzalloc(dev, sizeof(*sfs_dev), GFP_KERNEL);
if (!sfs_dev)
return -ENOMEM;
/*
* Pre-allocate 2MB command buffer for all SFS commands using
* SNP HV_Fixed page allocator which also transitions the
* SFS command buffer to HV_Fixed page state if SNP is enabled.
*/
page = snp_alloc_hv_fixed_pages(SFS_NUM_2MB_PAGES_CMDBUF);
if (!page) {
dev_dbg(dev, "Command Buffer HV-Fixed page allocation failed\n");
goto cleanup_dev;
}
sfs_dev->page = page;
sfs_dev->command_buf = page_address(page);
dev_dbg(dev, "Command buffer 0x%px to be marked as HV_Fixed\n", sfs_dev->command_buf);
/*
* SFS command buffer must be mapped as non-cacheable.
*/
ret = set_memory_uc((unsigned long)sfs_dev->command_buf, SFS_NUM_PAGES_CMDBUF);
if (ret) {
dev_dbg(dev, "Set memory uc failed\n");
goto cleanup_cmd_buf;
}
dev_dbg(dev, "Command buffer 0x%px marked uncacheable\n", sfs_dev->command_buf);
psp->sfs_data = sfs_dev;
sfs_dev->dev = dev;
sfs_dev->psp = psp;
ret = sfs_misc_init(sfs_dev);
if (ret)
goto cleanup_mem_attr;
dev_notice(sfs_dev->dev, "SFS support is available\n");
return 0;
cleanup_mem_attr:
set_memory_wb((unsigned long)sfs_dev->command_buf, SFS_NUM_PAGES_CMDBUF);
cleanup_cmd_buf:
snp_free_hv_fixed_pages(page);
cleanup_dev:
psp->sfs_data = NULL;
devm_kfree(dev, sfs_dev);
return ret;
}
|