From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.133.124]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id E56F536DA14 for ; Mon, 18 May 2026 15:17:59 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=170.10.133.124 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1779117484; cv=none; b=C+4cBZuh3+IHwbbM05AynnsbMfL336bZJL6BRXDPLcgmY/e+CglkPm/39a64pmSeqxEsn6PY4LoPmKcToYaPT8KMfnI12llaO+NXumVSoFvHx7y8hTGBC2X66OWGdsDfCANXQa5MohxJzzTCq9Q0xbJeTFAaPKl+7y21t/R/A7c= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1779117484; c=relaxed/simple; bh=GUOwjHTHp7F+veAyU1RHSAr7O3jNZOc2wq937tHgqSs=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=TJOJ2Udil1T9Q5rv6uXuRUWs+2YRujnqgLz3GiQDIS1yW4uzS7ddjpUoHWEO23yQhPEHTU5xHLp1+DhXwxQvtVfl69HchnZLJjfPrr2p3YULVkoyLk0xcDWK2YqwnrW/wKKGGMF5JcjBOWAymeF8j2P1I+dnSSiISToroAW47Ck= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com; spf=pass smtp.mailfrom=redhat.com; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b=hHiaVY8j; dkim=pass (2048-bit key) header.d=redhat.com header.i=@redhat.com header.b=KZleIkGM; arc=none smtp.client-ip=170.10.133.124 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=redhat.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b="hHiaVY8j"; dkim=pass (2048-bit key) header.d=redhat.com header.i=@redhat.com header.b="KZleIkGM" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1779117477; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=pe/iolypET0Kouxm0CjpcIMCpG/CgODFZgpYFH+mQ+E=; b=hHiaVY8jWAyES52eM4i1ZDzDlgmipQtrOkF55vo5w5/eoGvcPc/4G45xXukMpV7Vz9fWoz Iy1wy3Bal8Lc967ELWG6CZyiv2I9IRxSV3OLHfa+SxUlULv4y1o6LrCuqbFEPBi8jOjnmA zIrdYwU76OtpElMttKXyGMxqv389TyA= Received: from mail-pf1-f198.google.com (mail-pf1-f198.google.com [209.85.210.198]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-618-IcO0U3boNG2qDdJf-0Jx5A-1; Mon, 18 May 2026 11:17:55 -0400 X-MC-Unique: IcO0U3boNG2qDdJf-0Jx5A-1 X-Mimecast-MFC-AGG-ID: IcO0U3boNG2qDdJf-0Jx5A_1779117475 Received: by mail-pf1-f198.google.com with SMTP id d2e1a72fcca58-836d0184333so3348427b3a.0 for ; Mon, 18 May 2026 08:17:55 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=google; t=1779117475; x=1779722275; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to; bh=pe/iolypET0Kouxm0CjpcIMCpG/CgODFZgpYFH+mQ+E=; b=KZleIkGMFNWK4imHUQ3rJ+hlOxxxggfmMuVd+fE9tsOnEOGOhzZZsdOfFxEmD/dwAJ KLH6GC9i8TpXeG1+6h2mK4Vxqh9xES3JEeyOb5Bc1KhRnK9d26TTL77UPHHVjCN0XNiG 47fsbrKov110URKY7R7xzb1lUx4zlXO00xT8jeWbfL/aEED8CT3ZKW/RvGzMX0u3bh5o gqmmfN3N50JsTrsGDPnyrv5CWPVdiVxRuRq6X5nee+C5pES37FFZR1oCLpgdORzARkCo 1OdIy2cT8do6lTFQTNtvE/Fssv2nCyZATE9wEkSLviDFWVFxyNFRXxYMne6PohVX3df/ 8GXg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1779117475; x=1779722275; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to; bh=pe/iolypET0Kouxm0CjpcIMCpG/CgODFZgpYFH+mQ+E=; b=eCYgJidDfYP37E50J49wwcVtr+UOkkExnzNwMW1ai3giwVs/tAuLaAWFEjXbPaKbbx MDViUALT5HQVPuGGt3fXFLaRAGxJGLRfN0XBa1v/HAXT83jOWGESzQS5Gb1l5A+mcTd0 FKGU8Cq/mTb2/KYYkXVJz5fymQwMSAksS7ca6R12B48lFYNt6mAInc6V7CY1OtjwFxSv nwiJTfoKL62Q5MY0wTYhJNedH5pHUKM4uHCxbSpE4I2sVvnTdf52zf3c+XoDmvyjfUMp mcrvp0ePZOffunBhL9kBmDtUAtwMYEHoYnt2MrZqxB4ti8hAr5MhswnHMozP6pJ/1FO1 vUZQ== X-Gm-Message-State: AOJu0Ywbc471jIMT7qVMUYiGOo2Gfr4dkIzMo16H8eRwBDpMGw4swmtz 0z2qQPs7d2lVRp56lMgy6jr4IyUdLB4uMr5uvT+Poogk8EIL68ZuatMILyPsATIi4GucQDV/wcp G6+D5fGH5yuwM/uIgKT6KT+QljDqo7vzDu8vWrdlyHtbaMdyA/N7VgjmpxJjtOMaMtyHHk+dIMs lnLZ4CB4EtN3hYAS7Km4P+l62bpl3tY0Khj9UFcSNf+jIdH1QH X-Gm-Gg: Acq92OHpXIfSjo8CGc744dtDHqlf1jhUVQTnXUasSevk8sHA/URk8aj7iHCiTf3HrJL /zHaN1i51rAEibCGWzxRRRZ9PsrQsui648uUacskyE4kRAa2E2mws3LVCVfdzAnTXNtcQo5T6aT xDuDUjhQ/rZP8gZPqxeFIDWQStqf2JJRBjJk+MQb4bEAUnSyfNXYSfhKqCn32FKMsfdnvBeTo80 bzBUkEY4iVehEeJjAF+IpRmyRVP5t6Z1o1kwr1S5nMYzbDwvcP68l/5m++Fg3NX6PWBvdbRBnpL 1IKRxP98KcCejrhElrcoQak8bsJkP+yXEYFBIOGAYJuOkH0YBevEQa7uWQekQrF/R49rhgea7jV QXwvHrEE/cvTZduhYw0XXYxnts40UpBjIn9XqBODPvcVeFMuCoXi0i0Oe+3+NoQ4= X-Received: by 2002:a05:6a00:a10:b0:83e:c8f8:cec7 with SMTP id d2e1a72fcca58-83f33dddb8cmr16057938b3a.35.1779117474490; Mon, 18 May 2026 08:17:54 -0700 (PDT) X-Received: by 2002:a05:6a00:a10:b0:83e:c8f8:cec7 with SMTP id d2e1a72fcca58-83f33dddb8cmr16057884b3a.35.1779117473762; Mon, 18 May 2026 08:17:53 -0700 (PDT) Received: from fedora.armenon-thinkpadp16vgen1.bengluru.csb ([49.36.104.172]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-83f197815cesm18181153b3a.24.2026.05.18.08.17.50 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 18 May 2026 08:17:52 -0700 (PDT) From: Arun Menon To: linux-kernel@vger.kernel.org Cc: Jarkko Sakkinen , linux-integrity@vger.kernel.org, Jason Gunthorpe , Peter Huewe , Arun Menon Subject: [PATCH v3 6/6] tpm_crb: Implement command and response chunking logic Date: Mon, 18 May 2026 20:47:24 +0530 Message-ID: <20260518151724.730443-7-armenon@redhat.com> X-Mailer: git-send-email 2.54.0 In-Reply-To: <20260518151724.730443-1-armenon@redhat.com> References: <20260518151724.730443-1-armenon@redhat.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit From: Arun Menon With the introduction of support for Post Quantum Cryptography algorithms in TPM, the commands and responses will grow in size. Some TPMs have a physical hardware memory window (MMIO) that is smaller than the commands we need to send. Therefore this commit implements the core logic of sending/receiving data in chunks. Instead of sending the whole command at once, the driver now sends it in small chunks. After each chunk, it signals the TPM using a nextChunk signal, and waits for the TPM to consume the data. Once the final piece is delivered, the driver signals the TPM to begin execution by toggling the start invoke bit. We use the same logic in reverse to read large responses from the TPM. This allows the driver to handle large payloads even when the hardware interface has limited memory. This kernel-side support corresponds to the backend implementation in QEMU [1]. QEMU reassembles the chunks before passing them to the TPM emulator. [1] https://lore.kernel.org/qemu-devel/20260506075813.120781-1-armenon@redhat.com/ Signed-off-by: Arun Menon --- drivers/char/tpm/tpm_crb.c | 215 +++++++++++++++++++++++++++++-------- 1 file changed, 173 insertions(+), 42 deletions(-) diff --git a/drivers/char/tpm/tpm_crb.c b/drivers/char/tpm/tpm_crb.c index 31f530744e90..8b2aaa109fc4 100644 --- a/drivers/char/tpm/tpm_crb.c +++ b/drivers/char/tpm/tpm_crb.c @@ -105,11 +105,13 @@ struct crb_priv { u8 __iomem *cmd; u8 __iomem *rsp; u32 cmd_size; + u32 rsp_size; u32 smc_func_id; u32 __iomem *pluton_start_addr; u32 __iomem *pluton_reply_addr; u8 ffa_flags; u8 ffa_attributes; + u32 intf_id; }; struct tpm2_crb_smc { @@ -369,38 +371,6 @@ static u8 crb_status(struct tpm_chip *chip) return sts; } -static int crb_recv(struct tpm_chip *chip, u8 *buf, size_t count) -{ - struct crb_priv *priv = dev_get_drvdata(&chip->dev); - unsigned int expected; - - /* A sanity check that the upper layer wants to get at least the header - * as that is the minimum size for any TPM response. - */ - if (count < TPM_HEADER_SIZE) - return -EIO; - - /* If this bit is set, according to the spec, the TPM is in - * unrecoverable condition. - */ - if (ioread32(&priv->regs_t->ctrl_sts) & CRB_CTRL_STS_ERROR) - return -EIO; - - /* Read the first 8 bytes in order to get the length of the response. - * We read exactly a quad word in order to make sure that the remaining - * reads will be aligned. - */ - memcpy_fromio(buf, priv->rsp, 8); - - expected = be32_to_cpup((__be32 *)&buf[2]); - if (expected > count || expected < TPM_HEADER_SIZE) - return -EIO; - - memcpy_fromio(&buf[8], &priv->rsp[8], expected - 8); - - return expected; -} - static int crb_do_acpi_start(struct tpm_chip *chip) { union acpi_object *obj; @@ -472,17 +442,71 @@ static int tpm_crb_start(struct tpm_chip *chip, u32 start_cmd) return rc; } +static int tpm_crb_send_no_chunks(struct tpm_chip *chip, u8 *buf, size_t len) +{ + struct crb_priv *priv = dev_get_drvdata(&chip->dev); + int rc; + + memcpy_toio(priv->cmd, buf, len); + + /* Make sure that cmd is populated before issuing start. */ + wmb(); + + rc = tpm_crb_start(chip, CRB_START_INVOKE); + if (rc) + return rc; + + return crb_try_pluton_doorbell(priv, false); +} + +static int tpm_crb_send_chunks(struct tpm_chip *chip, u8 *buf, size_t len) +{ + struct crb_priv *priv = dev_get_drvdata(&chip->dev); + size_t offset = 0; + size_t chunk_size; + int rc; + + while (offset < len) { + chunk_size = min_t(size_t, len - offset, priv->cmd_size); + + if (chunk_size == 0) + break; + + memcpy_toio(priv->cmd, buf + offset, chunk_size); + offset += chunk_size; + + /* Make sure that cmd is populated before issuing start. */ + wmb(); + if (offset < len) { + rc = tpm_crb_start(chip, CRB_START_NEXT_CHUNK); + if (rc) + return rc; + if (!crb_wait_for_reg_32(&priv->regs_t->ctrl_start, + CRB_START_NEXT_CHUNK, 0, + TPM2_TIMEOUT_C)) { + dev_err(&chip->dev, + "Timeout waiting for backend to consume chunk\n"); + return -ETIME; + } + } else { + rc = tpm_crb_start(chip, CRB_START_INVOKE); + if (rc) + return rc; + } + } + + return crb_try_pluton_doorbell(priv, false); +} static int crb_send(struct tpm_chip *chip, u8 *buf, size_t bufsiz, size_t len) { struct crb_priv *priv = dev_get_drvdata(&chip->dev); - int rc = 0; /* Zero the cancel register so that the next command will not get * canceled. */ iowrite32(0, &priv->regs_t->ctrl_cancel); - if (len > priv->cmd_size) { + if (len > priv->cmd_size && !(priv->intf_id & CRB_INTF_CAP_CRB_CHUNK)) { dev_err(&chip->dev, "invalid command count value %zd %d\n", len, priv->cmd_size); return -E2BIG; @@ -492,16 +516,115 @@ static int crb_send(struct tpm_chip *chip, u8 *buf, size_t bufsiz, size_t len) if (priv->sm == ACPI_TPM2_COMMAND_BUFFER_WITH_PLUTON) __crb_cmd_ready(&chip->dev, priv, chip->locality); - memcpy_toio(priv->cmd, buf, len); + if (len <= priv->cmd_size) + return tpm_crb_send_no_chunks(chip, buf, len); - /* Make sure that cmd is populated before issuing start. */ - wmb(); + return tpm_crb_send_chunks(chip, buf, len); +} - rc = tpm_crb_start(chip, CRB_START_INVOKE); - if (rc) - return rc; +static int tpm_crb_recv_no_chunks(struct tpm_chip *chip, u8 *buf, size_t count) +{ + struct crb_priv *priv = dev_get_drvdata(&chip->dev); + unsigned int expected; - return crb_try_pluton_doorbell(priv, false); + /* Read the first 8 bytes in order to get the length of the response. + * We read exactly a quad word in order to make sure that the remaining + * reads will be aligned. + */ + memcpy_fromio(buf, priv->rsp, 8); + + expected = be32_to_cpup((__be32 *)&buf[2]); + if (expected > count || expected < TPM_HEADER_SIZE) + return -EIO; + + memcpy_fromio(&buf[8], &priv->rsp[8], expected - 8); + + return expected; +} + +static int tpm_crb_recv_chunks(struct tpm_chip *chip, u8 *buf, size_t count, + unsigned int expected) +{ + struct crb_priv *priv = dev_get_drvdata(&chip->dev); + size_t offset = 0; + size_t chunk_size; + size_t first_read; + int rc; + + if (expected > count) + return -EIO; + /* + * Set chunk_size by comparing the size of the buffer that the upper + * layer has allocated (count) to the hardware tpm limit (priv->rsp_size). + * This is to prevent buffer overflow while writing to buf. + */ + chunk_size = min_t(size_t, count, priv->rsp_size); + if (chunk_size < 8) + return -EIO; + + memcpy_fromio(buf, priv->rsp, 8); + + /* + * Compare the actual size of the response we found in + * the header to the chunk size + */ + first_read = min_t(size_t, expected, chunk_size); + + memcpy_fromio(&buf[8], &priv->rsp[8], first_read - 8); + offset = first_read; + + while (offset < expected) { + rc = tpm_crb_start(chip, CRB_START_NEXT_CHUNK); + if (rc) + return rc; + + if (!crb_wait_for_reg_32(&priv->regs_t->ctrl_start, + CRB_START_NEXT_CHUNK, 0, + TPM2_TIMEOUT_C)) { + dev_err(&chip->dev, "Timeout waiting for backend response\n"); + return -ETIME; + } + + chunk_size = min_t(size_t, expected - offset, priv->rsp_size); + memcpy_fromio(buf + offset, priv->rsp, chunk_size); + offset += chunk_size; + } + + return expected; +} + +static int crb_recv(struct tpm_chip *chip, u8 *buf, size_t count) +{ + struct crb_priv *priv = dev_get_drvdata(&chip->dev); + unsigned int expected; + + /* A sanity check that the upper layer wants to get at least the header + * as that is the minimum size for any TPM response. + */ + if (count < TPM_HEADER_SIZE) + return -EIO; + + /* If this bit is set, according to the spec, the TPM is in + * unrecoverable condition. + */ + if (ioread32(&priv->regs_t->ctrl_sts) & CRB_CTRL_STS_ERROR) + return -EIO; + + /* + * Peek at the first 8 bytes to determine the response size + */ + expected = be32_to_cpup((__be32 *)&priv->rsp[2]); + + if (expected <= priv->rsp_size) + return tpm_crb_recv_no_chunks(chip, buf, count); + + if (!(priv->intf_id & CRB_INTF_CAP_CRB_CHUNK)) { + dev_err(&chip->dev, + "Response larger than MMIO and chunking not supported\n"); + return -EIO; + } + + return tpm_crb_recv_chunks(chip, buf, count, expected); } static void crb_cancel(struct tpm_chip *chip) @@ -728,6 +851,12 @@ static int crb_map_io(struct device *dev, struct crb_priv *priv, goto out; } + if (priv->regs_h) + priv->intf_id = ioread32((u32 __iomem *)&priv->regs_h->intf_id); + + if (priv->intf_id & CRB_INTF_CAP_CRB_CHUNK) + dev_info(dev, "CRB Chunking is supported by backend\n"); + memcpy_fromio(&__rsp_pa, &priv->regs_t->ctrl_rsp_pa, 8); rsp_pa = le64_to_cpu(__rsp_pa); rsp_size = ioread32(&priv->regs_t->ctrl_rsp_size); @@ -765,8 +894,10 @@ static int crb_map_io(struct device *dev, struct crb_priv *priv, priv->rsp = priv->cmd; out: - if (!ret) + if (!ret) { priv->cmd_size = cmd_size; + priv->rsp_size = rsp_size; + } __crb_go_idle(dev, priv, 0); -- 2.54.0