From: "Lee, Chun-Yi" <joeyli.kernel@gmail.com>
To: linux-kernel@vger.kernel.org
Cc: linux-efi@vger.kernel.org, linux-pm@vger.kernel.org,
"Rafael J. Wysocki" <rjw@sisk.pl>,
Matthew Garrett <matthew.garrett@nebula.com>,
Len Brown <len.brown@intel.com>, Pavel Machek <pavel@ucw.cz>,
Josh Boyer <jwboyer@redhat.com>, Vojtech Pavlik <vojtech@suse.cz>,
Matt Fleming <matt.fleming@intel.com>,
Jiri Kosina <jkosina@suse.cz>, "H. Peter Anvin" <hpa@zytor.com>,
"Lee, Chun-Yi" <jlee@suse.com>
Subject: [RFC PATCH 09/16] PM / hibernate: Reserve swsusp key and earse footprints
Date: Thu, 16 Jul 2015 22:25:23 +0800 [thread overview]
Message-ID: <1437056730-15247-10-git-send-email-jlee@suse.com> (raw)
In-Reply-To: <1437056730-15247-1-git-send-email-jlee@suse.com>
Add handler to parse the setup data that carrying swsusp key, it
reserves swsusp key by memblock then copies key to a allocated page
in later initcall stage.
And for earsing footbprints, the codes in this patch remove setup
data that carried swsusp key, and clean the memory space that
reserved by memblock.
Signed-off-by: Lee, Chun-Yi <jlee@suse.com>
---
arch/x86/include/asm/suspend.h | 4 +++
arch/x86/kernel/setup.c | 21 ++++++++++-
arch/x86/power/Makefile | 1 +
arch/x86/power/hibernate_keys.c | 79 +++++++++++++++++++++++++++++++++++++++++
kernel/power/power.h | 5 +++
5 files changed, 109 insertions(+), 1 deletion(-)
create mode 100644 arch/x86/power/hibernate_keys.c
diff --git a/arch/x86/include/asm/suspend.h b/arch/x86/include/asm/suspend.h
index b0c3f68..bec87e3 100644
--- a/arch/x86/include/asm/suspend.h
+++ b/arch/x86/include/asm/suspend.h
@@ -7,8 +7,12 @@
#ifdef CONFIG_HIBERNATE_VERIFICATION
#include <linux/suspend.h>
+extern void parse_swsusp_keys(u64 phys_addr, u32 data_len);
+
struct swsusp_keys {
unsigned long skey_status;
u8 swsusp_key[SWSUSP_DIGEST_SIZE];
};
+#else
+static inline void parse_swsusp_keys(u64 phys_addr, u32 data_len) {}
#endif
diff --git a/arch/x86/kernel/setup.c b/arch/x86/kernel/setup.c
index 80f874b..5412be0 100644
--- a/arch/x86/kernel/setup.c
+++ b/arch/x86/kernel/setup.c
@@ -112,6 +112,8 @@
#include <asm/alternative.h>
#include <asm/prom.h>
+#include <asm/suspend.h>
+
/*
* max_low_pfn_mapped: highest direct mapped pfn under 4GB
* max_pfn_mapped: highest direct mapped pfn over 4GB
@@ -425,10 +427,22 @@ static void __init reserve_initrd(void)
}
#endif /* CONFIG_BLK_DEV_INITRD */
+static void __init remove_setup_data(u64 pa_prev, u64 pa_next)
+{
+ struct setup_data *data;
+
+ if (pa_prev) {
+ data = early_memremap(pa_prev, sizeof(*data));
+ data->next = pa_next;
+ early_iounmap(data, sizeof(*data));
+ } else
+ boot_params.hdr.setup_data = pa_next;
+}
+
static void __init parse_setup_data(void)
{
struct setup_data *data;
- u64 pa_data, pa_next;
+ u64 pa_data, pa_next, pa_prev = 0;
pa_data = boot_params.hdr.setup_data;
while (pa_data) {
@@ -450,9 +464,14 @@ static void __init parse_setup_data(void)
case SETUP_EFI:
parse_efi_setup(pa_data, data_len);
break;
+ case SETUP_SWSUSP_KEYS:
+ parse_swsusp_keys(pa_data, data_len);
+ remove_setup_data(pa_prev, pa_next);
+ break;
default:
break;
}
+ pa_prev = pa_data;
pa_data = pa_next;
}
}
diff --git a/arch/x86/power/Makefile b/arch/x86/power/Makefile
index a6a198c..ef8d550 100644
--- a/arch/x86/power/Makefile
+++ b/arch/x86/power/Makefile
@@ -5,3 +5,4 @@ CFLAGS_cpu.o := $(nostackp)
obj-$(CONFIG_PM_SLEEP) += cpu.o
obj-$(CONFIG_HIBERNATION) += hibernate_$(BITS).o hibernate_asm_$(BITS).o
+obj-$(CONFIG_HIBERNATE_VERIFICATION) += hibernate_keys.o
diff --git a/arch/x86/power/hibernate_keys.c b/arch/x86/power/hibernate_keys.c
new file mode 100644
index 0000000..4a68b86
--- /dev/null
+++ b/arch/x86/power/hibernate_keys.c
@@ -0,0 +1,79 @@
+/* Swsusp keys handler
+ *
+ * Copyright (C) 2015 SUSE Linux Products GmbH. All rights reserved.
+ * Written by Chun-Yi Lee (jlee@suse.com)
+ *
+ * This program is free software; you can redistribute it and/or
+ * modify it under the terms of the GNU General Public Licence
+ * as published by the Free Software Foundation; either version
+ * 2 of the Licence, or (at your option) any later version.
+ */
+
+#include <linux/bootmem.h>
+#include <linux/memblock.h>
+#include <linux/suspend.h>
+#include <asm/suspend.h>
+
+/* physical address of swsusp keys from boot params */
+static u64 keys_phys_addr;
+
+/* A page used to keep swsusp keys */
+static struct swsusp_keys *swsusp_keys;
+
+void __init parse_swsusp_keys(u64 phys_addr, u32 data_len)
+{
+ struct setup_data *swsusp_setup_data;
+
+ /* Reserve keys memory, will copy and earse in init_hibernate_keys() */
+ keys_phys_addr = phys_addr + sizeof(struct setup_data);
+ memblock_reserve(keys_phys_addr, sizeof(struct swsusp_keys));
+
+ /* clear setup_data */
+ swsusp_setup_data = early_memremap(phys_addr, data_len);
+ if (!swsusp_setup_data)
+ return;
+
+ memset(swsusp_setup_data, 0, sizeof(struct setup_data));
+ early_memunmap(swsusp_setup_data, data_len);
+}
+
+int get_swsusp_key(u8 **skey)
+{
+ if (!swsusp_keys)
+ return -ENODEV;
+
+ if (!swsusp_keys->skey_status)
+ *skey = swsusp_keys->swsusp_key;
+
+ return swsusp_keys->skey_status;
+}
+
+static int __init init_hibernate_keys(void)
+{
+ struct swsusp_keys *keys;
+ int ret = 0;
+
+ if (!keys_phys_addr)
+ return -ENODEV;
+
+ keys = early_memremap(keys_phys_addr, sizeof(struct swsusp_keys));
+
+ /* Copy swsusp keys to a allocated page */
+ swsusp_keys = (struct swsusp_keys *)get_zeroed_page(GFP_KERNEL);
+ if (swsusp_keys) {
+ *swsusp_keys = *keys;
+ } else {
+ pr_err("PM: Allocate swsusp keys page failed\n");
+ ret = -ENOMEM;
+ }
+
+ /* Earse keys data no matter copy success or failed */
+ memset(keys, 0, sizeof(struct swsusp_keys));
+ early_memunmap(keys, sizeof(struct swsusp_keys));
+ memblock_free(keys_phys_addr, sizeof(struct swsusp_keys));
+ keys_phys_addr = 0;
+
+ return ret;
+}
+
+late_initcall(init_hibernate_keys);
diff --git a/kernel/power/power.h b/kernel/power/power.h
index f65fcf7..b8020e9 100644
--- a/kernel/power/power.h
+++ b/kernel/power/power.h
@@ -16,6 +16,11 @@ struct swsusp_info {
} __aligned(PAGE_SIZE);
#ifdef CONFIG_HIBERNATION
+#ifdef CONFIG_HIBERNATE_VERIFICATION
+/* arch/x86/power/hibernate_keys.c */
+extern int get_swsusp_key(u8 **skey);
+#endif
+
/* kernel/power/snapshot.c */
extern void __init hibernate_reserved_size_init(void);
extern void __init hibernate_image_size_init(void);
--
1.8.4.5
next prev parent reply other threads:[~2015-07-16 14:29 UTC|newest]
Thread overview: 52+ messages / expand[flat|nested] mbox.gz Atom feed top
2015-07-16 14:25 [RFC PATCH 00/16] Signature verification of hibernate snapshot Lee, Chun-Yi
2015-07-16 14:25 ` [RFC PATCH 01/16] PM / hibernate: define HMAC algorithm and digest size of swsusp Lee, Chun-Yi
2015-07-28 12:01 ` Pavel Machek
2015-07-31 10:08 ` joeyli
2015-07-31 12:49 ` Pavel Machek
2015-07-31 15:46 ` joeyli
2015-07-16 14:25 ` [RFC PATCH 02/16] x86/efi: Add get and set variable to EFI services pointer table Lee, Chun-Yi
2015-07-30 15:19 ` Matt Fleming
2015-07-31 10:14 ` joeyli
2015-07-16 14:25 ` [RFC PATCH 03/16] x86/boot: Public getting random boot function Lee, Chun-Yi
2015-07-28 12:21 ` Pavel Machek
2015-07-31 10:52 ` joeyli
2015-07-31 12:50 ` Pavel Machek
2015-07-16 14:25 ` [RFC PATCH 04/16] x86/efi: Generating random number in EFI stub Lee, Chun-Yi
2015-07-28 12:01 ` Pavel Machek
2015-07-31 9:06 ` joeyli
2015-07-30 15:37 ` Matt Fleming
2015-07-31 9:12 ` joeyli
2015-07-16 14:25 ` [RFC PATCH 05/16] x86/efi: Get entropy through EFI random number generator protocol Lee, Chun-Yi
2015-07-28 12:28 ` Pavel Machek
2015-07-31 9:58 ` joeyli
2015-07-31 12:01 ` Matt Fleming
2015-07-31 16:05 ` joeyli
2015-07-30 16:11 ` Matt Fleming
2015-07-31 14:59 ` joeyli
2015-07-31 15:01 ` joeyli
2015-07-16 14:25 ` [RFC PATCH 06/16] x86/efi: Generating random HMAC key for siging hibernate image Lee, Chun-Yi
2015-07-28 12:30 ` Pavel Machek
2015-07-31 10:56 ` joeyli
2015-07-30 16:20 ` Matt Fleming
2015-07-31 15:09 ` joeyli
2015-07-16 14:25 ` [RFC PATCH 07/16] efi: Public the function of transferring EFI status to kernel error Lee, Chun-Yi
2015-07-30 16:23 ` Matt Fleming
2015-07-31 15:11 ` joeyli
2015-08-02 0:23 ` Valdis.Kletnieks
2015-07-16 14:25 ` [RFC PATCH 08/16] x86/efi: Carrying swsusp key by setup data Lee, Chun-Yi
2015-07-30 16:30 ` Matt Fleming
2015-07-31 15:31 ` joeyli
2015-07-16 14:25 ` Lee, Chun-Yi [this message]
2015-07-28 12:35 ` [RFC PATCH 09/16] PM / hibernate: Reserve swsusp key and earse footprints Pavel Machek
2015-07-31 15:43 ` joeyli
2015-07-16 14:25 ` [RFC PATCH 10/16] PM / hibernate: Generate and verify signature of hibernate snapshot Lee, Chun-Yi
2015-07-16 14:25 ` [RFC PATCH 11/16] PM / hibernate: Avoid including swsusp key to hibernate image Lee, Chun-Yi
2015-07-16 14:25 ` [RFC PATCH 12/16] PM / hibernate: Forward signature verifying result and key to image kernel Lee, Chun-Yi
2015-07-16 14:25 ` [RFC PATCH 13/16] PM / hibernate: Add configuration to enforce signature verification Lee, Chun-Yi
2015-07-16 14:25 ` [RFC PATCH 14/16] PM / hibernate: Allow user trigger swsusp key re-generating Lee, Chun-Yi
2015-07-16 14:25 ` [RFC PATCH 15/16] PM / hibernate: Bypass verification logic on legacy BIOS Lee, Chun-Yi
2015-07-16 14:25 ` [RFC PATCH 16/16] PM / hibernate: Document signature verification of hibernate snapshot Lee, Chun-Yi
2015-07-24 17:08 ` [RFC PATCH 00/16] Signature " Jiri Kosina
2015-07-24 20:08 ` Rafael J. Wysocki
2015-07-28 12:09 ` Matt Fleming
2015-07-25 14:32 ` joeyli
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=1437056730-15247-10-git-send-email-jlee@suse.com \
--to=joeyli.kernel@gmail.com \
--cc=hpa@zytor.com \
--cc=jkosina@suse.cz \
--cc=jlee@suse.com \
--cc=jwboyer@redhat.com \
--cc=len.brown@intel.com \
--cc=linux-efi@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-pm@vger.kernel.org \
--cc=matt.fleming@intel.com \
--cc=matthew.garrett@nebula.com \
--cc=pavel@ucw.cz \
--cc=rjw@sisk.pl \
--cc=vojtech@suse.cz \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®