xref: /qemu/backends/tpm/tpm_passthrough.c (revision 56a3c24ffc11955ddc7bb21362ca8069a3fc8c55)
14549a8b7SStefan Berger /*
24549a8b7SStefan Berger  *  passthrough TPM driver
34549a8b7SStefan Berger  *
44549a8b7SStefan Berger  *  Copyright (c) 2010 - 2013 IBM Corporation
54549a8b7SStefan Berger  *  Authors:
64549a8b7SStefan Berger  *    Stefan Berger <stefanb@us.ibm.com>
74549a8b7SStefan Berger  *
84549a8b7SStefan Berger  *  Copyright (C) 2011 IAIK, Graz University of Technology
94549a8b7SStefan Berger  *    Author: Andreas Niederl
104549a8b7SStefan Berger  *
114549a8b7SStefan Berger  * This library is free software; you can redistribute it and/or
124549a8b7SStefan Berger  * modify it under the terms of the GNU Lesser General Public
134549a8b7SStefan Berger  * License as published by the Free Software Foundation; either
144549a8b7SStefan Berger  * version 2 of the License, or (at your option) any later version.
154549a8b7SStefan Berger  *
164549a8b7SStefan Berger  * This library is distributed in the hope that it will be useful,
174549a8b7SStefan Berger  * but WITHOUT ANY WARRANTY; without even the implied warranty of
184549a8b7SStefan Berger  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU
194549a8b7SStefan Berger  * Lesser General Public License for more details.
204549a8b7SStefan Berger  *
214549a8b7SStefan Berger  * You should have received a copy of the GNU Lesser General Public
224549a8b7SStefan Berger  * License along with this library; if not, see <http://www.gnu.org/licenses/>
234549a8b7SStefan Berger  */
244549a8b7SStefan Berger 
2592dcc234SStefan Berger #include <dirent.h>
2692dcc234SStefan Berger 
274549a8b7SStefan Berger #include "qemu-common.h"
284549a8b7SStefan Berger #include "qapi/error.h"
294549a8b7SStefan Berger #include "qemu/sockets.h"
30dccfcd0eSPaolo Bonzini #include "sysemu/tpm_backend.h"
314549a8b7SStefan Berger #include "tpm_int.h"
324549a8b7SStefan Berger #include "hw/hw.h"
330d09e41aSPaolo Bonzini #include "hw/i386/pc.h"
34bdee56f5SPaolo Bonzini #include "sysemu/tpm_backend_int.h"
354549a8b7SStefan Berger #include "tpm_tis.h"
36*56a3c24fSStefan Berger #include "tpm_util.h"
374549a8b7SStefan Berger 
384d1ba9c4SStefan Berger #define DEBUG_TPM 0
394549a8b7SStefan Berger 
404d1ba9c4SStefan Berger #define DPRINTF(fmt, ...) do { \
414d1ba9c4SStefan Berger     if (DEBUG_TPM) { \
424d1ba9c4SStefan Berger         fprintf(stderr, fmt, ## __VA_ARGS__); \
434d1ba9c4SStefan Berger     } \
444d1ba9c4SStefan Berger } while (0);
454549a8b7SStefan Berger 
468f0605ccSStefan Berger #define TYPE_TPM_PASSTHROUGH "tpm-passthrough"
478f0605ccSStefan Berger #define TPM_PASSTHROUGH(obj) \
488f0605ccSStefan Berger     OBJECT_CHECK(TPMPassthruState, (obj), TYPE_TPM_PASSTHROUGH)
494549a8b7SStefan Berger 
50bdee56f5SPaolo Bonzini static const TPMDriverOps tpm_passthrough_driver;
51bdee56f5SPaolo Bonzini 
528f0605ccSStefan Berger /* data structures */
534549a8b7SStefan Berger typedef struct TPMPassthruThreadParams {
544549a8b7SStefan Berger     TPMState *tpm_state;
554549a8b7SStefan Berger 
564549a8b7SStefan Berger     TPMRecvDataCB *recv_data_callback;
574549a8b7SStefan Berger     TPMBackend *tb;
584549a8b7SStefan Berger } TPMPassthruThreadParams;
594549a8b7SStefan Berger 
604549a8b7SStefan Berger struct TPMPassthruState {
618f0605ccSStefan Berger     TPMBackend parent;
628f0605ccSStefan Berger 
634549a8b7SStefan Berger     TPMBackendThread tbt;
644549a8b7SStefan Berger 
654549a8b7SStefan Berger     TPMPassthruThreadParams tpm_thread_params;
664549a8b7SStefan Berger 
674549a8b7SStefan Berger     char *tpm_dev;
684549a8b7SStefan Berger     int tpm_fd;
6992dcc234SStefan Berger     bool tpm_executing;
7092dcc234SStefan Berger     bool tpm_op_canceled;
7192dcc234SStefan Berger     int cancel_fd;
724549a8b7SStefan Berger     bool had_startup_error;
73*56a3c24fSStefan Berger 
74*56a3c24fSStefan Berger     TPMVersion tpm_version;
754549a8b7SStefan Berger };
764549a8b7SStefan Berger 
778f0605ccSStefan Berger typedef struct TPMPassthruState TPMPassthruState;
788f0605ccSStefan Berger 
794549a8b7SStefan Berger #define TPM_PASSTHROUGH_DEFAULT_DEVICE "/dev/tpm0"
804549a8b7SStefan Berger 
8192dcc234SStefan Berger /* functions */
8292dcc234SStefan Berger 
8392dcc234SStefan Berger static void tpm_passthrough_cancel_cmd(TPMBackend *tb);
8492dcc234SStefan Berger 
854549a8b7SStefan Berger static int tpm_passthrough_unix_write(int fd, const uint8_t *buf, uint32_t len)
864549a8b7SStefan Berger {
874549a8b7SStefan Berger     return send_all(fd, buf, len);
884549a8b7SStefan Berger }
894549a8b7SStefan Berger 
904549a8b7SStefan Berger static int tpm_passthrough_unix_read(int fd, uint8_t *buf, uint32_t len)
914549a8b7SStefan Berger {
924549a8b7SStefan Berger     return recv_all(fd, buf, len, true);
934549a8b7SStefan Berger }
944549a8b7SStefan Berger 
954549a8b7SStefan Berger static uint32_t tpm_passthrough_get_size_from_buffer(const uint8_t *buf)
964549a8b7SStefan Berger {
974549a8b7SStefan Berger     struct tpm_resp_hdr *resp = (struct tpm_resp_hdr *)buf;
984549a8b7SStefan Berger 
994549a8b7SStefan Berger     return be32_to_cpu(resp->len);
1004549a8b7SStefan Berger }
1014549a8b7SStefan Berger 
102bdee56f5SPaolo Bonzini /*
103bdee56f5SPaolo Bonzini  * Write an error message in the given output buffer.
104bdee56f5SPaolo Bonzini  */
105bdee56f5SPaolo Bonzini static void tpm_write_fatal_error_response(uint8_t *out, uint32_t out_len)
106bdee56f5SPaolo Bonzini {
107bdee56f5SPaolo Bonzini     if (out_len >= sizeof(struct tpm_resp_hdr)) {
108bdee56f5SPaolo Bonzini         struct tpm_resp_hdr *resp = (struct tpm_resp_hdr *)out;
109bdee56f5SPaolo Bonzini 
110bdee56f5SPaolo Bonzini         resp->tag = cpu_to_be16(TPM_TAG_RSP_COMMAND);
111bdee56f5SPaolo Bonzini         resp->len = cpu_to_be32(sizeof(struct tpm_resp_hdr));
112bdee56f5SPaolo Bonzini         resp->errcode = cpu_to_be32(TPM_FAIL);
113bdee56f5SPaolo Bonzini     }
114bdee56f5SPaolo Bonzini }
115bdee56f5SPaolo Bonzini 
116fd859081SStefan Berger static bool tpm_passthrough_is_selftest(const uint8_t *in, uint32_t in_len)
117fd859081SStefan Berger {
118fd859081SStefan Berger     struct tpm_req_hdr *hdr = (struct tpm_req_hdr *)in;
119fd859081SStefan Berger 
120fd859081SStefan Berger     if (in_len >= sizeof(*hdr)) {
121fd859081SStefan Berger         return (be32_to_cpu(hdr->ordinal) == TPM_ORD_ContinueSelfTest);
122fd859081SStefan Berger     }
123fd859081SStefan Berger 
124fd859081SStefan Berger     return false;
125fd859081SStefan Berger }
126fd859081SStefan Berger 
12792dcc234SStefan Berger static int tpm_passthrough_unix_tx_bufs(TPMPassthruState *tpm_pt,
1284549a8b7SStefan Berger                                         const uint8_t *in, uint32_t in_len,
129fd859081SStefan Berger                                         uint8_t *out, uint32_t out_len,
130fd859081SStefan Berger                                         bool *selftest_done)
1314549a8b7SStefan Berger {
1324549a8b7SStefan Berger     int ret;
133fd859081SStefan Berger     bool is_selftest;
134fd859081SStefan Berger     const struct tpm_resp_hdr *hdr;
1354549a8b7SStefan Berger 
13692dcc234SStefan Berger     tpm_pt->tpm_op_canceled = false;
13792dcc234SStefan Berger     tpm_pt->tpm_executing = true;
138fd859081SStefan Berger     *selftest_done = false;
139fd859081SStefan Berger 
140fd859081SStefan Berger     is_selftest = tpm_passthrough_is_selftest(in, in_len);
14192dcc234SStefan Berger 
14292dcc234SStefan Berger     ret = tpm_passthrough_unix_write(tpm_pt->tpm_fd, in, in_len);
1434549a8b7SStefan Berger     if (ret != in_len) {
14492dcc234SStefan Berger         if (!tpm_pt->tpm_op_canceled ||
14592dcc234SStefan Berger             (tpm_pt->tpm_op_canceled && errno != ECANCELED)) {
1464549a8b7SStefan Berger             error_report("tpm_passthrough: error while transmitting data "
14727215a22SGonglei                          "to TPM: %s (%i)",
1484549a8b7SStefan Berger                          strerror(errno), errno);
14992dcc234SStefan Berger         }
1504549a8b7SStefan Berger         goto err_exit;
1514549a8b7SStefan Berger     }
1524549a8b7SStefan Berger 
15392dcc234SStefan Berger     tpm_pt->tpm_executing = false;
15492dcc234SStefan Berger 
15592dcc234SStefan Berger     ret = tpm_passthrough_unix_read(tpm_pt->tpm_fd, out, out_len);
1564549a8b7SStefan Berger     if (ret < 0) {
15792dcc234SStefan Berger         if (!tpm_pt->tpm_op_canceled ||
15892dcc234SStefan Berger             (tpm_pt->tpm_op_canceled && errno != ECANCELED)) {
1594549a8b7SStefan Berger             error_report("tpm_passthrough: error while reading data from "
16027215a22SGonglei                          "TPM: %s (%i)",
1614549a8b7SStefan Berger                          strerror(errno), errno);
16292dcc234SStefan Berger         }
1634549a8b7SStefan Berger     } else if (ret < sizeof(struct tpm_resp_hdr) ||
1644549a8b7SStefan Berger                tpm_passthrough_get_size_from_buffer(out) != ret) {
1654549a8b7SStefan Berger         ret = -1;
1664549a8b7SStefan Berger         error_report("tpm_passthrough: received invalid response "
16727215a22SGonglei                      "packet from TPM");
1684549a8b7SStefan Berger     }
1694549a8b7SStefan Berger 
170fd859081SStefan Berger     if (is_selftest && (ret >= sizeof(struct tpm_resp_hdr))) {
171fd859081SStefan Berger         hdr = (struct tpm_resp_hdr *)out;
172fd859081SStefan Berger         *selftest_done = (be32_to_cpu(hdr->errcode) == 0);
173fd859081SStefan Berger     }
174fd859081SStefan Berger 
1754549a8b7SStefan Berger err_exit:
1764549a8b7SStefan Berger     if (ret < 0) {
1774549a8b7SStefan Berger         tpm_write_fatal_error_response(out, out_len);
1784549a8b7SStefan Berger     }
1794549a8b7SStefan Berger 
18092dcc234SStefan Berger     tpm_pt->tpm_executing = false;
18192dcc234SStefan Berger 
1824549a8b7SStefan Berger     return ret;
1834549a8b7SStefan Berger }
1844549a8b7SStefan Berger 
18592dcc234SStefan Berger static int tpm_passthrough_unix_transfer(TPMPassthruState *tpm_pt,
186fd859081SStefan Berger                                          const TPMLocality *locty_data,
187fd859081SStefan Berger                                          bool *selftest_done)
1884549a8b7SStefan Berger {
18992dcc234SStefan Berger     return tpm_passthrough_unix_tx_bufs(tpm_pt,
1904549a8b7SStefan Berger                                         locty_data->w_buffer.buffer,
1914549a8b7SStefan Berger                                         locty_data->w_offset,
1924549a8b7SStefan Berger                                         locty_data->r_buffer.buffer,
193fd859081SStefan Berger                                         locty_data->r_buffer.size,
194fd859081SStefan Berger                                         selftest_done);
1954549a8b7SStefan Berger }
1964549a8b7SStefan Berger 
1974549a8b7SStefan Berger static void tpm_passthrough_worker_thread(gpointer data,
1984549a8b7SStefan Berger                                           gpointer user_data)
1994549a8b7SStefan Berger {
2004549a8b7SStefan Berger     TPMPassthruThreadParams *thr_parms = user_data;
2018f0605ccSStefan Berger     TPMPassthruState *tpm_pt = TPM_PASSTHROUGH(thr_parms->tb);
2024549a8b7SStefan Berger     TPMBackendCmd cmd = (TPMBackendCmd)data;
203fd859081SStefan Berger     bool selftest_done = false;
2044549a8b7SStefan Berger 
2054549a8b7SStefan Berger     DPRINTF("tpm_passthrough: processing command type %d\n", cmd);
2064549a8b7SStefan Berger 
2074549a8b7SStefan Berger     switch (cmd) {
2084549a8b7SStefan Berger     case TPM_BACKEND_CMD_PROCESS_CMD:
20992dcc234SStefan Berger         tpm_passthrough_unix_transfer(tpm_pt,
210fd859081SStefan Berger                                       thr_parms->tpm_state->locty_data,
211fd859081SStefan Berger                                       &selftest_done);
2124549a8b7SStefan Berger 
2134549a8b7SStefan Berger         thr_parms->recv_data_callback(thr_parms->tpm_state,
214fd859081SStefan Berger                                       thr_parms->tpm_state->locty_number,
215fd859081SStefan Berger                                       selftest_done);
2164549a8b7SStefan Berger         break;
2174549a8b7SStefan Berger     case TPM_BACKEND_CMD_INIT:
2184549a8b7SStefan Berger     case TPM_BACKEND_CMD_END:
2194549a8b7SStefan Berger     case TPM_BACKEND_CMD_TPM_RESET:
2204549a8b7SStefan Berger         /* nothing to do */
2214549a8b7SStefan Berger         break;
2224549a8b7SStefan Berger     }
2234549a8b7SStefan Berger }
2244549a8b7SStefan Berger 
2254549a8b7SStefan Berger /*
2264549a8b7SStefan Berger  * Start the TPM (thread). If it had been started before, then terminate
2274549a8b7SStefan Berger  * and start it again.
2284549a8b7SStefan Berger  */
2294549a8b7SStefan Berger static int tpm_passthrough_startup_tpm(TPMBackend *tb)
2304549a8b7SStefan Berger {
2318f0605ccSStefan Berger     TPMPassthruState *tpm_pt = TPM_PASSTHROUGH(tb);
2324549a8b7SStefan Berger 
2334549a8b7SStefan Berger     /* terminate a running TPM */
2344549a8b7SStefan Berger     tpm_backend_thread_end(&tpm_pt->tbt);
2354549a8b7SStefan Berger 
2364549a8b7SStefan Berger     tpm_backend_thread_create(&tpm_pt->tbt,
2374549a8b7SStefan Berger                               tpm_passthrough_worker_thread,
2388f0605ccSStefan Berger                               &tpm_pt->tpm_thread_params);
2394549a8b7SStefan Berger 
2404549a8b7SStefan Berger     return 0;
2414549a8b7SStefan Berger }
2424549a8b7SStefan Berger 
2434549a8b7SStefan Berger static void tpm_passthrough_reset(TPMBackend *tb)
2444549a8b7SStefan Berger {
2458f0605ccSStefan Berger     TPMPassthruState *tpm_pt = TPM_PASSTHROUGH(tb);
2464549a8b7SStefan Berger 
2474549a8b7SStefan Berger     DPRINTF("tpm_passthrough: CALL TO TPM_RESET!\n");
2484549a8b7SStefan Berger 
24992dcc234SStefan Berger     tpm_passthrough_cancel_cmd(tb);
25092dcc234SStefan Berger 
2514549a8b7SStefan Berger     tpm_backend_thread_end(&tpm_pt->tbt);
2524549a8b7SStefan Berger 
2534549a8b7SStefan Berger     tpm_pt->had_startup_error = false;
2544549a8b7SStefan Berger }
2554549a8b7SStefan Berger 
2564549a8b7SStefan Berger static int tpm_passthrough_init(TPMBackend *tb, TPMState *s,
2574549a8b7SStefan Berger                                 TPMRecvDataCB *recv_data_cb)
2584549a8b7SStefan Berger {
2598f0605ccSStefan Berger     TPMPassthruState *tpm_pt = TPM_PASSTHROUGH(tb);
2604549a8b7SStefan Berger 
2614549a8b7SStefan Berger     tpm_pt->tpm_thread_params.tpm_state = s;
2624549a8b7SStefan Berger     tpm_pt->tpm_thread_params.recv_data_callback = recv_data_cb;
2634549a8b7SStefan Berger     tpm_pt->tpm_thread_params.tb = tb;
2644549a8b7SStefan Berger 
2654549a8b7SStefan Berger     return 0;
2664549a8b7SStefan Berger }
2674549a8b7SStefan Berger 
2684549a8b7SStefan Berger static bool tpm_passthrough_get_tpm_established_flag(TPMBackend *tb)
2694549a8b7SStefan Berger {
2704549a8b7SStefan Berger     return false;
2714549a8b7SStefan Berger }
2724549a8b7SStefan Berger 
273116694c3SStefan Berger static int tpm_passthrough_reset_tpm_established_flag(TPMBackend *tb,
274116694c3SStefan Berger                                                       uint8_t locty)
275116694c3SStefan Berger {
276116694c3SStefan Berger     /* only a TPM 2.0 will support this */
277116694c3SStefan Berger     return 0;
278116694c3SStefan Berger }
279116694c3SStefan Berger 
2804549a8b7SStefan Berger static bool tpm_passthrough_get_startup_error(TPMBackend *tb)
2814549a8b7SStefan Berger {
2828f0605ccSStefan Berger     TPMPassthruState *tpm_pt = TPM_PASSTHROUGH(tb);
2834549a8b7SStefan Berger 
2844549a8b7SStefan Berger     return tpm_pt->had_startup_error;
2854549a8b7SStefan Berger }
2864549a8b7SStefan Berger 
2874549a8b7SStefan Berger static size_t tpm_passthrough_realloc_buffer(TPMSizedBuffer *sb)
2884549a8b7SStefan Berger {
2894549a8b7SStefan Berger     size_t wanted_size = 4096; /* Linux tpm.c buffer size */
2904549a8b7SStefan Berger 
2914549a8b7SStefan Berger     if (sb->size != wanted_size) {
2924549a8b7SStefan Berger         sb->buffer = g_realloc(sb->buffer, wanted_size);
2934549a8b7SStefan Berger         sb->size = wanted_size;
2944549a8b7SStefan Berger     }
2954549a8b7SStefan Berger     return sb->size;
2964549a8b7SStefan Berger }
2974549a8b7SStefan Berger 
2984549a8b7SStefan Berger static void tpm_passthrough_deliver_request(TPMBackend *tb)
2994549a8b7SStefan Berger {
3008f0605ccSStefan Berger     TPMPassthruState *tpm_pt = TPM_PASSTHROUGH(tb);
3014549a8b7SStefan Berger 
3024549a8b7SStefan Berger     tpm_backend_thread_deliver_request(&tpm_pt->tbt);
3034549a8b7SStefan Berger }
3044549a8b7SStefan Berger 
3054549a8b7SStefan Berger static void tpm_passthrough_cancel_cmd(TPMBackend *tb)
3064549a8b7SStefan Berger {
3078f0605ccSStefan Berger     TPMPassthruState *tpm_pt = TPM_PASSTHROUGH(tb);
30892dcc234SStefan Berger     int n;
30992dcc234SStefan Berger 
31092dcc234SStefan Berger     /*
31192dcc234SStefan Berger      * As of Linux 3.7 the tpm_tis driver does not properly cancel
31292dcc234SStefan Berger      * commands on all TPM manufacturers' TPMs.
31392dcc234SStefan Berger      * Only cancel if we're busy so we don't cancel someone else's
31492dcc234SStefan Berger      * command, e.g., a command executed on the host.
31592dcc234SStefan Berger      */
31692dcc234SStefan Berger     if (tpm_pt->tpm_executing) {
31792dcc234SStefan Berger         if (tpm_pt->cancel_fd >= 0) {
31892dcc234SStefan Berger             n = write(tpm_pt->cancel_fd, "-", 1);
31992dcc234SStefan Berger             if (n != 1) {
32027215a22SGonglei                 error_report("Canceling TPM command failed: %s",
32192dcc234SStefan Berger                              strerror(errno));
32292dcc234SStefan Berger             } else {
32392dcc234SStefan Berger                 tpm_pt->tpm_op_canceled = true;
32492dcc234SStefan Berger             }
32592dcc234SStefan Berger         } else {
32692dcc234SStefan Berger             error_report("Cannot cancel TPM command due to missing "
32792dcc234SStefan Berger                          "TPM sysfs cancel entry");
32892dcc234SStefan Berger         }
32992dcc234SStefan Berger     }
3304549a8b7SStefan Berger }
3314549a8b7SStefan Berger 
3324549a8b7SStefan Berger static const char *tpm_passthrough_create_desc(void)
3334549a8b7SStefan Berger {
3344549a8b7SStefan Berger     return "Passthrough TPM backend driver";
3354549a8b7SStefan Berger }
3364549a8b7SStefan Berger 
337116694c3SStefan Berger static TPMVersion tpm_passthrough_get_tpm_version(TPMBackend *tb)
338116694c3SStefan Berger {
339*56a3c24fSStefan Berger     TPMPassthruState *tpm_pt = TPM_PASSTHROUGH(tb);
340116694c3SStefan Berger 
341*56a3c24fSStefan Berger     return tpm_pt->tpm_version;
3424549a8b7SStefan Berger }
3434549a8b7SStefan Berger 
34492dcc234SStefan Berger /*
34592dcc234SStefan Berger  * Unless path or file descriptor set has been provided by user,
34692dcc234SStefan Berger  * determine the sysfs cancel file following kernel documentation
34792dcc234SStefan Berger  * in Documentation/ABI/stable/sysfs-class-tpm.
3488e36d6caSStefan Berger  * From /dev/tpm0 create /sys/class/misc/tpm0/device/cancel
34992dcc234SStefan Berger  */
35092dcc234SStefan Berger static int tpm_passthrough_open_sysfs_cancel(TPMBackend *tb)
35192dcc234SStefan Berger {
3528e36d6caSStefan Berger     TPMPassthruState *tpm_pt = TPM_PASSTHROUGH(tb);
35392dcc234SStefan Berger     int fd = -1;
3548e36d6caSStefan Berger     char *dev;
35592dcc234SStefan Berger     char path[PATH_MAX];
35692dcc234SStefan Berger 
35792dcc234SStefan Berger     if (tb->cancel_path) {
35892dcc234SStefan Berger         fd = qemu_open(tb->cancel_path, O_WRONLY);
35992dcc234SStefan Berger         if (fd < 0) {
36092dcc234SStefan Berger             error_report("Could not open TPM cancel path : %s",
36192dcc234SStefan Berger                          strerror(errno));
36292dcc234SStefan Berger         }
36392dcc234SStefan Berger         return fd;
36492dcc234SStefan Berger     }
36592dcc234SStefan Berger 
3668e36d6caSStefan Berger     dev = strrchr(tpm_pt->tpm_dev, '/');
3678e36d6caSStefan Berger     if (dev) {
3688e36d6caSStefan Berger         dev++;
3698e36d6caSStefan Berger         if (snprintf(path, sizeof(path), "/sys/class/misc/%s/device/cancel",
3708e36d6caSStefan Berger                      dev) < sizeof(path)) {
37192dcc234SStefan Berger             fd = qemu_open(path, O_WRONLY);
37292dcc234SStefan Berger             if (fd >= 0) {
37392dcc234SStefan Berger                 tb->cancel_path = g_strdup(path);
3748e36d6caSStefan Berger             } else {
3758e36d6caSStefan Berger                 error_report("tpm_passthrough: Could not open TPM cancel "
3768e36d6caSStefan Berger                              "path %s : %s", path, strerror(errno));
3778e36d6caSStefan Berger             }
3788e36d6caSStefan Berger         }
3798e36d6caSStefan Berger     } else {
3808e36d6caSStefan Berger        error_report("tpm_passthrough: Bad TPM device path %s",
3818e36d6caSStefan Berger                     tpm_pt->tpm_dev);
38292dcc234SStefan Berger     }
38392dcc234SStefan Berger 
38492dcc234SStefan Berger     return fd;
38592dcc234SStefan Berger }
38692dcc234SStefan Berger 
3874549a8b7SStefan Berger static int tpm_passthrough_handle_device_opts(QemuOpts *opts, TPMBackend *tb)
3884549a8b7SStefan Berger {
3898f0605ccSStefan Berger     TPMPassthruState *tpm_pt = TPM_PASSTHROUGH(tb);
3904549a8b7SStefan Berger     const char *value;
3914549a8b7SStefan Berger 
39292dcc234SStefan Berger     value = qemu_opt_get(opts, "cancel-path");
39392dcc234SStefan Berger     tb->cancel_path = g_strdup(value);
39492dcc234SStefan Berger 
3954549a8b7SStefan Berger     value = qemu_opt_get(opts, "path");
3964549a8b7SStefan Berger     if (!value) {
3974549a8b7SStefan Berger         value = TPM_PASSTHROUGH_DEFAULT_DEVICE;
3984549a8b7SStefan Berger     }
3994549a8b7SStefan Berger 
4008f0605ccSStefan Berger     tpm_pt->tpm_dev = g_strdup(value);
4014549a8b7SStefan Berger 
4028f0605ccSStefan Berger     tb->path = g_strdup(tpm_pt->tpm_dev);
4034549a8b7SStefan Berger 
4048f0605ccSStefan Berger     tpm_pt->tpm_fd = qemu_open(tpm_pt->tpm_dev, O_RDWR);
4058f0605ccSStefan Berger     if (tpm_pt->tpm_fd < 0) {
40627215a22SGonglei         error_report("Cannot access TPM device using '%s': %s",
4078f0605ccSStefan Berger                      tpm_pt->tpm_dev, strerror(errno));
4084549a8b7SStefan Berger         goto err_free_parameters;
4094549a8b7SStefan Berger     }
4104549a8b7SStefan Berger 
411*56a3c24fSStefan Berger     if (tpm_util_test_tpmdev(tpm_pt->tpm_fd, &tpm_pt->tpm_version)) {
41227215a22SGonglei         error_report("'%s' is not a TPM device.",
4138f0605ccSStefan Berger                      tpm_pt->tpm_dev);
4144549a8b7SStefan Berger         goto err_close_tpmdev;
4154549a8b7SStefan Berger     }
4164549a8b7SStefan Berger 
4174549a8b7SStefan Berger     return 0;
4184549a8b7SStefan Berger 
4194549a8b7SStefan Berger  err_close_tpmdev:
4208f0605ccSStefan Berger     qemu_close(tpm_pt->tpm_fd);
4218f0605ccSStefan Berger     tpm_pt->tpm_fd = -1;
4224549a8b7SStefan Berger 
4234549a8b7SStefan Berger  err_free_parameters:
4244549a8b7SStefan Berger     g_free(tb->path);
4254549a8b7SStefan Berger     tb->path = NULL;
4264549a8b7SStefan Berger 
4278f0605ccSStefan Berger     g_free(tpm_pt->tpm_dev);
4288f0605ccSStefan Berger     tpm_pt->tpm_dev = NULL;
4294549a8b7SStefan Berger 
4304549a8b7SStefan Berger     return 1;
4314549a8b7SStefan Berger }
4324549a8b7SStefan Berger 
4334549a8b7SStefan Berger static TPMBackend *tpm_passthrough_create(QemuOpts *opts, const char *id)
4344549a8b7SStefan Berger {
4358f0605ccSStefan Berger     Object *obj = object_new(TYPE_TPM_PASSTHROUGH);
4368f0605ccSStefan Berger     TPMBackend *tb = TPM_BACKEND(obj);
4378f0605ccSStefan Berger     TPMPassthruState *tpm_pt = TPM_PASSTHROUGH(tb);
4384549a8b7SStefan Berger 
4394549a8b7SStefan Berger     tb->id = g_strdup(id);
4404549a8b7SStefan Berger     /* let frontend set the fe_model to proper value */
4414549a8b7SStefan Berger     tb->fe_model = -1;
4424549a8b7SStefan Berger 
4434549a8b7SStefan Berger     tb->ops = &tpm_passthrough_driver;
4444549a8b7SStefan Berger 
4454549a8b7SStefan Berger     if (tpm_passthrough_handle_device_opts(opts, tb)) {
4464549a8b7SStefan Berger         goto err_exit;
4474549a8b7SStefan Berger     }
4484549a8b7SStefan Berger 
4498f0605ccSStefan Berger     tpm_pt->cancel_fd = tpm_passthrough_open_sysfs_cancel(tb);
4508f0605ccSStefan Berger     if (tpm_pt->cancel_fd < 0) {
45192dcc234SStefan Berger         goto err_exit;
45292dcc234SStefan Berger     }
45392dcc234SStefan Berger 
4544549a8b7SStefan Berger     return tb;
4554549a8b7SStefan Berger 
4564549a8b7SStefan Berger err_exit:
4574549a8b7SStefan Berger     g_free(tb->id);
4584549a8b7SStefan Berger 
4594549a8b7SStefan Berger     return NULL;
4604549a8b7SStefan Berger }
4614549a8b7SStefan Berger 
4624549a8b7SStefan Berger static void tpm_passthrough_destroy(TPMBackend *tb)
4634549a8b7SStefan Berger {
4648f0605ccSStefan Berger     TPMPassthruState *tpm_pt = TPM_PASSTHROUGH(tb);
4654549a8b7SStefan Berger 
46692dcc234SStefan Berger     tpm_passthrough_cancel_cmd(tb);
46792dcc234SStefan Berger 
4684549a8b7SStefan Berger     tpm_backend_thread_end(&tpm_pt->tbt);
4694549a8b7SStefan Berger 
4704549a8b7SStefan Berger     qemu_close(tpm_pt->tpm_fd);
4718f0605ccSStefan Berger     qemu_close(tpm_pt->cancel_fd);
4724549a8b7SStefan Berger 
4734549a8b7SStefan Berger     g_free(tb->id);
4744549a8b7SStefan Berger     g_free(tb->path);
47592dcc234SStefan Berger     g_free(tb->cancel_path);
4768f0605ccSStefan Berger     g_free(tpm_pt->tpm_dev);
4774549a8b7SStefan Berger }
4784549a8b7SStefan Berger 
479bb716238SStefan Berger static const QemuOptDesc tpm_passthrough_cmdline_opts[] = {
480bb716238SStefan Berger     TPM_STANDARD_CMDLINE_OPTS,
481bb716238SStefan Berger     {
482bb716238SStefan Berger         .name = "cancel-path",
483bb716238SStefan Berger         .type = QEMU_OPT_STRING,
484bb716238SStefan Berger         .help = "Sysfs file entry for canceling TPM commands",
485bb716238SStefan Berger     },
486bb716238SStefan Berger     {
487bb716238SStefan Berger         .name = "path",
488bb716238SStefan Berger         .type = QEMU_OPT_STRING,
489bb716238SStefan Berger         .help = "Path to TPM device on the host",
490bb716238SStefan Berger     },
491bb716238SStefan Berger     { /* end of list */ },
492bb716238SStefan Berger };
493bb716238SStefan Berger 
494bdee56f5SPaolo Bonzini static const TPMDriverOps tpm_passthrough_driver = {
4954549a8b7SStefan Berger     .type                     = TPM_TYPE_PASSTHROUGH,
496bb716238SStefan Berger     .opts                     = tpm_passthrough_cmdline_opts,
4974549a8b7SStefan Berger     .desc                     = tpm_passthrough_create_desc,
4984549a8b7SStefan Berger     .create                   = tpm_passthrough_create,
4994549a8b7SStefan Berger     .destroy                  = tpm_passthrough_destroy,
5004549a8b7SStefan Berger     .init                     = tpm_passthrough_init,
5014549a8b7SStefan Berger     .startup_tpm              = tpm_passthrough_startup_tpm,
5024549a8b7SStefan Berger     .realloc_buffer           = tpm_passthrough_realloc_buffer,
5034549a8b7SStefan Berger     .reset                    = tpm_passthrough_reset,
5044549a8b7SStefan Berger     .had_startup_error        = tpm_passthrough_get_startup_error,
5054549a8b7SStefan Berger     .deliver_request          = tpm_passthrough_deliver_request,
5064549a8b7SStefan Berger     .cancel_cmd               = tpm_passthrough_cancel_cmd,
5074549a8b7SStefan Berger     .get_tpm_established_flag = tpm_passthrough_get_tpm_established_flag,
508116694c3SStefan Berger     .reset_tpm_established_flag = tpm_passthrough_reset_tpm_established_flag,
509116694c3SStefan Berger     .get_tpm_version          = tpm_passthrough_get_tpm_version,
5104549a8b7SStefan Berger };
5114549a8b7SStefan Berger 
5128f0605ccSStefan Berger static void tpm_passthrough_inst_init(Object *obj)
5138f0605ccSStefan Berger {
5148f0605ccSStefan Berger }
5158f0605ccSStefan Berger 
5168f0605ccSStefan Berger static void tpm_passthrough_inst_finalize(Object *obj)
5178f0605ccSStefan Berger {
5188f0605ccSStefan Berger }
5198f0605ccSStefan Berger 
5208f0605ccSStefan Berger static void tpm_passthrough_class_init(ObjectClass *klass, void *data)
5218f0605ccSStefan Berger {
5228f0605ccSStefan Berger     TPMBackendClass *tbc = TPM_BACKEND_CLASS(klass);
5238f0605ccSStefan Berger 
5248f0605ccSStefan Berger     tbc->ops = &tpm_passthrough_driver;
5258f0605ccSStefan Berger }
5268f0605ccSStefan Berger 
5278f0605ccSStefan Berger static const TypeInfo tpm_passthrough_info = {
5288f0605ccSStefan Berger     .name = TYPE_TPM_PASSTHROUGH,
5298f0605ccSStefan Berger     .parent = TYPE_TPM_BACKEND,
5308f0605ccSStefan Berger     .instance_size = sizeof(TPMPassthruState),
5318f0605ccSStefan Berger     .class_init = tpm_passthrough_class_init,
5328f0605ccSStefan Berger     .instance_init = tpm_passthrough_inst_init,
5338f0605ccSStefan Berger     .instance_finalize = tpm_passthrough_inst_finalize,
5348f0605ccSStefan Berger };
5358f0605ccSStefan Berger 
5364549a8b7SStefan Berger static void tpm_passthrough_register(void)
5374549a8b7SStefan Berger {
5388f0605ccSStefan Berger     type_register_static(&tpm_passthrough_info);
5394549a8b7SStefan Berger     tpm_register_driver(&tpm_passthrough_driver);
5404549a8b7SStefan Berger }
5414549a8b7SStefan Berger 
5424549a8b7SStefan Berger type_init(tpm_passthrough_register)
543