1 /* 2 * QTest TPM utilities 3 * 4 * Copyright (c) 2018 IBM Corporation 5 * Copyright (c) 2018 Red Hat, Inc. 6 * 7 * Authors: 8 * Stefan Berger <stefanb@linux.vnet.ibm.com> 9 * Marc-André Lureau <marcandre.lureau@redhat.com> 10 * 11 * This work is licensed under the terms of the GNU GPL, version 2 or later. 12 * See the COPYING file in the top-level directory. 13 */ 14 15 #include "qemu/osdep.h" 16 17 #include "hw/acpi/tpm.h" 18 #include "libqtest.h" 19 #include "tpm-util.h" 20 #include "qapi/qmp/qdict.h" 21 22 #define TIS_REG(LOCTY, REG) \ 23 (TPM_TIS_ADDR_BASE + ((LOCTY) << 12) + REG) 24 25 void tpm_util_crb_transfer(QTestState *s, 26 const unsigned char *req, size_t req_size, 27 unsigned char *rsp, size_t rsp_size) 28 { 29 uint64_t caddr = qtest_readq(s, TPM_CRB_ADDR_BASE + A_CRB_CTRL_CMD_LADDR); 30 uint64_t raddr = qtest_readq(s, TPM_CRB_ADDR_BASE + A_CRB_CTRL_RSP_ADDR); 31 32 qtest_writeb(s, TPM_CRB_ADDR_BASE + A_CRB_LOC_CTRL, 1); 33 34 qtest_memwrite(s, caddr, req, req_size); 35 36 uint32_t sts, start = 1; 37 uint64_t end_time = g_get_monotonic_time() + 5 * G_TIME_SPAN_SECOND; 38 qtest_writel(s, TPM_CRB_ADDR_BASE + A_CRB_CTRL_START, start); 39 while (true) { 40 start = qtest_readl(s, TPM_CRB_ADDR_BASE + A_CRB_CTRL_START); 41 if ((start & 1) == 0) { 42 break; 43 } 44 if (g_get_monotonic_time() >= end_time) { 45 break; 46 } 47 }; 48 start = qtest_readl(s, TPM_CRB_ADDR_BASE + A_CRB_CTRL_START); 49 g_assert_cmpint(start & 1, ==, 0); 50 sts = qtest_readl(s, TPM_CRB_ADDR_BASE + A_CRB_CTRL_STS); 51 g_assert_cmpint(sts & 1, ==, 0); 52 53 qtest_memread(s, raddr, rsp, rsp_size); 54 } 55 56 void tpm_util_tis_transfer(QTestState *s, 57 const unsigned char *req, size_t req_size, 58 unsigned char *rsp, size_t rsp_size) 59 { 60 uint32_t sts; 61 uint16_t bcount; 62 size_t i; 63 64 /* request use of locality 0 */ 65 qtest_writeb(s, TIS_REG(0, TPM_TIS_REG_ACCESS), TPM_TIS_ACCESS_REQUEST_USE); 66 qtest_writel(s, TIS_REG(0, TPM_TIS_REG_STS), TPM_TIS_STS_COMMAND_READY); 67 68 sts = qtest_readl(s, TIS_REG(0, TPM_TIS_REG_STS)); 69 bcount = (sts >> 8) & 0xffff; 70 g_assert_cmpint(bcount, >=, req_size); 71 72 /* transmit command */ 73 for (i = 0; i < req_size; i++) { 74 qtest_writeb(s, TIS_REG(0, TPM_TIS_REG_DATA_FIFO), req[i]); 75 } 76 77 /* start processing */ 78 qtest_writeb(s, TIS_REG(0, TPM_TIS_REG_STS), TPM_TIS_STS_TPM_GO); 79 80 uint64_t end_time = g_get_monotonic_time() + 50 * G_TIME_SPAN_SECOND; 81 do { 82 sts = qtest_readl(s, TIS_REG(0, TPM_TIS_REG_STS)); 83 if ((sts & TPM_TIS_STS_DATA_AVAILABLE) != 0) { 84 break; 85 } 86 } while (g_get_monotonic_time() < end_time); 87 88 sts = qtest_readl(s, TIS_REG(0, TPM_TIS_REG_STS)); 89 bcount = (sts >> 8) & 0xffff; 90 91 memset(rsp, 0, rsp_size); 92 for (i = 0; i < bcount; i++) { 93 rsp[i] = qtest_readb(s, TIS_REG(0, TPM_TIS_REG_DATA_FIFO)); 94 } 95 96 /* relinquish use of locality 0 */ 97 qtest_writeb(s, TIS_REG(0, TPM_TIS_REG_ACCESS), 98 TPM_TIS_ACCESS_ACTIVE_LOCALITY); 99 } 100 101 void tpm_util_startup(QTestState *s, tx_func *tx) 102 { 103 unsigned char buffer[1024]; 104 unsigned char tpm_startup[] = 105 "\x80\x01\x00\x00\x00\x0c\x00\x00\x01\x44\x00\x00"; 106 unsigned char tpm_startup_resp[] = 107 "\x80\x01\x00\x00\x00\x0a\x00\x00\x00\x00"; 108 109 tx(s, tpm_startup, sizeof(tpm_startup), buffer, sizeof(buffer)); 110 111 g_assert_cmpmem(buffer, sizeof(tpm_startup_resp), 112 tpm_startup_resp, sizeof(tpm_startup_resp)); 113 } 114 115 void tpm_util_pcrextend(QTestState *s, tx_func *tx) 116 { 117 unsigned char buffer[1024]; 118 unsigned char tpm_pcrextend[] = 119 "\x80\x02\x00\x00\x00\x41\x00\x00\x01\x82\x00\x00\x00\x0a\x00\x00" 120 "\x00\x09\x40\x00\x00\x09\x00\x00\x00\x00\x00\x00\x00\x00\x01\x00" 121 "\x0b\x74\x65\x73\x74\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00" 122 "\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00" 123 "\x00"; 124 125 unsigned char tpm_pcrextend_resp[] = 126 "\x80\x02\x00\x00\x00\x13\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00" 127 "\x01\x00\x00"; 128 129 tx(s, tpm_pcrextend, sizeof(tpm_pcrextend), buffer, sizeof(buffer)); 130 131 g_assert_cmpmem(buffer, sizeof(tpm_pcrextend_resp), 132 tpm_pcrextend_resp, sizeof(tpm_pcrextend_resp)); 133 } 134 135 void tpm_util_pcrread(QTestState *s, tx_func *tx, 136 const unsigned char *exp_resp, size_t exp_resp_size) 137 { 138 unsigned char buffer[1024]; 139 unsigned char tpm_pcrread[] = 140 "\x80\x01\x00\x00\x00\x14\x00\x00\x01\x7e\x00\x00\x00\x01\x00\x0b" 141 "\x03\x00\x04\x00"; 142 143 tx(s, tpm_pcrread, sizeof(tpm_pcrread), buffer, sizeof(buffer)); 144 145 g_assert_cmpmem(buffer, exp_resp_size, exp_resp, exp_resp_size); 146 } 147 148 static gboolean tpm_util_swtpm_has_tpm2(void) 149 { 150 gint mystdout; 151 gboolean succ; 152 unsigned i; 153 char buffer[10240]; 154 ssize_t n; 155 gchar *swtpm_argv[] = { 156 g_strdup("swtpm"), g_strdup("socket"), g_strdup("--help"), NULL 157 }; 158 159 succ = g_spawn_async_with_pipes(NULL, swtpm_argv, NULL, 160 G_SPAWN_SEARCH_PATH, NULL, NULL, NULL, 161 NULL, &mystdout, NULL, NULL); 162 if (!succ) { 163 goto cleanup; 164 } 165 166 n = read(mystdout, buffer, sizeof(buffer) - 1); 167 if (n < 0) { 168 goto cleanup; 169 } 170 buffer[n] = 0; 171 if (!strstr(buffer, "--tpm2")) { 172 succ = false; 173 } 174 175 cleanup: 176 for (i = 0; swtpm_argv[i]; i++) { 177 g_free(swtpm_argv[i]); 178 } 179 180 return succ; 181 } 182 183 gboolean tpm_util_swtpm_start(const char *path, GPid *pid, 184 SocketAddress **addr, GError **error) 185 { 186 char *swtpm_argv_tpmstate = g_strdup_printf("dir=%s", path); 187 char *swtpm_argv_ctrl = g_strdup_printf("type=unixio,path=%s/sock", 188 path); 189 gchar *swtpm_argv[] = { 190 g_strdup("swtpm"), g_strdup("socket"), 191 g_strdup("--tpmstate"), swtpm_argv_tpmstate, 192 g_strdup("--ctrl"), swtpm_argv_ctrl, 193 g_strdup("--tpm2"), 194 NULL 195 }; 196 gboolean succ; 197 unsigned i; 198 199 succ = tpm_util_swtpm_has_tpm2(); 200 if (!succ) { 201 goto cleanup; 202 } 203 204 *addr = g_new0(SocketAddress, 1); 205 (*addr)->type = SOCKET_ADDRESS_TYPE_UNIX; 206 (*addr)->u.q_unix.path = g_build_filename(path, "sock", NULL); 207 208 succ = g_spawn_async(NULL, swtpm_argv, NULL, G_SPAWN_SEARCH_PATH, 209 NULL, NULL, pid, error); 210 211 cleanup: 212 for (i = 0; swtpm_argv[i]; i++) { 213 g_free(swtpm_argv[i]); 214 } 215 216 return succ; 217 } 218 219 void tpm_util_swtpm_kill(GPid pid) 220 { 221 int n; 222 223 if (!pid) { 224 return; 225 } 226 227 g_spawn_close_pid(pid); 228 229 n = kill(pid, 0); 230 if (n < 0) { 231 return; 232 } 233 234 kill(pid, SIGKILL); 235 } 236 237 void tpm_util_migrate(QTestState *who, const char *uri) 238 { 239 QDict *rsp; 240 241 rsp = qtest_qmp(who, 242 "{ 'execute': 'migrate', 'arguments': { 'uri': %s } }", 243 uri); 244 g_assert(qdict_haskey(rsp, "return")); 245 qobject_unref(rsp); 246 } 247 248 void tpm_util_wait_for_migration_complete(QTestState *who) 249 { 250 while (true) { 251 QDict *rsp_return; 252 bool completed; 253 const char *status; 254 255 qtest_qmp_send(who, "{ 'execute': 'query-migrate' }"); 256 rsp_return = qtest_qmp_receive_success(who, NULL, NULL); 257 status = qdict_get_str(rsp_return, "status"); 258 completed = strcmp(status, "completed") == 0; 259 g_assert_cmpstr(status, !=, "failed"); 260 qobject_unref(rsp_return); 261 if (completed) { 262 return; 263 } 264 usleep(1000); 265 } 266 } 267 268 void tpm_util_migration_start_qemu(QTestState **src_qemu, 269 QTestState **dst_qemu, 270 SocketAddress *src_tpm_addr, 271 SocketAddress *dst_tpm_addr, 272 const char *miguri, 273 const char *ifmodel) 274 { 275 char *src_qemu_args, *dst_qemu_args; 276 277 src_qemu_args = g_strdup_printf( 278 "-chardev socket,id=chr,path=%s " 279 "-tpmdev emulator,id=dev,chardev=chr " 280 "-device %s,tpmdev=dev ", 281 src_tpm_addr->u.q_unix.path, ifmodel); 282 283 *src_qemu = qtest_init(src_qemu_args); 284 285 dst_qemu_args = g_strdup_printf( 286 "-chardev socket,id=chr,path=%s " 287 "-tpmdev emulator,id=dev,chardev=chr " 288 "-device %s,tpmdev=dev " 289 "-incoming %s", 290 dst_tpm_addr->u.q_unix.path, 291 ifmodel, miguri); 292 293 *dst_qemu = qtest_init(dst_qemu_args); 294 295 free(src_qemu_args); 296 free(dst_qemu_args); 297 } 298