* [PATCH v3 1/4] tpm_tis: Explicitly check for error code
2023-06-13 18:02 [PATCH v3 0/4] Recovery from data transfer errors for tpm_tis Alexander Steffen
@ 2023-06-13 18:02 ` Alexander Steffen
2023-07-10 16:58 ` Jarkko Sakkinen
2023-06-13 18:02 ` [PATCH v3 2/4] tpm_tis: Move CRC check to generic send routine Alexander Steffen
` (2 subsequent siblings)
3 siblings, 1 reply; 8+ messages in thread
From: Alexander Steffen @ 2023-06-13 18:02 UTC (permalink / raw)
To: jarkko, linux-integrity, linux-kernel; +Cc: Alexander Steffen, stable
recv_data either returns the number of received bytes, or a negative value
representing an error code. Adding the return value directly to the total
number of received bytes therefore looks a little weird, since it might add
a negative error code to a sum of bytes.
The following check for size < expected usually makes the function return
ETIME in that case, so it does not cause too many problems in practice. But
to make the code look cleaner and because the caller might still be
interested in the original error code, explicitly check for the presence of
an error code and pass that through.
Cc: stable@vger.kernel.org
Fixes: cb5354253af2 ("[PATCH] tpm: spacing cleanups 2")
Signed-off-by: Alexander Steffen <Alexander.Steffen@infineon.com>
---
drivers/char/tpm/tpm_tis_core.c | 9 +++++++--
1 file changed, 7 insertions(+), 2 deletions(-)
diff --git a/drivers/char/tpm/tpm_tis_core.c b/drivers/char/tpm/tpm_tis_core.c
index 558144fa707a..aaaa136044ae 100644
--- a/drivers/char/tpm/tpm_tis_core.c
+++ b/drivers/char/tpm/tpm_tis_core.c
@@ -363,8 +363,13 @@ static int tpm_tis_recv(struct tpm_chip *chip, u8 *buf, size_t count)
goto out;
}
- size += recv_data(chip, &buf[TPM_HEADER_SIZE],
- expected - TPM_HEADER_SIZE);
+ rc = recv_data(chip, &buf[TPM_HEADER_SIZE],
+ expected - TPM_HEADER_SIZE);
+ if (rc < 0) {
+ size = rc;
+ goto out;
+ }
+ size += rc;
if (size < expected) {
dev_err(&chip->dev, "Unable to read remainder of result\n");
size = -ETIME;
--
2.25.1
^ permalink raw reply [flat|nested] 8+ messages in thread* Re: [PATCH v3 1/4] tpm_tis: Explicitly check for error code
2023-06-13 18:02 ` [PATCH v3 1/4] tpm_tis: Explicitly check for error code Alexander Steffen
@ 2023-07-10 16:58 ` Jarkko Sakkinen
0 siblings, 0 replies; 8+ messages in thread
From: Jarkko Sakkinen @ 2023-07-10 16:58 UTC (permalink / raw)
To: Alexander Steffen, linux-integrity, linux-kernel; +Cc: stable
On Tue, 2023-06-13 at 20:02 +0200, Alexander Steffen wrote:
> recv_data either returns the number of received bytes, or a negative value
> representing an error code. Adding the return value directly to the total
> number of received bytes therefore looks a little weird, since it might add
> a negative error code to a sum of bytes.
>
> The following check for size < expected usually makes the function return
> ETIME in that case, so it does not cause too many problems in practice. But
> to make the code look cleaner and because the caller might still be
> interested in the original error code, explicitly check for the presence of
> an error code and pass that through.
>
> Cc: stable@vger.kernel.org
> Fixes: cb5354253af2 ("[PATCH] tpm: spacing cleanups 2")
> Signed-off-by: Alexander Steffen <Alexander.Steffen@infineon.com>
> ---
> drivers/char/tpm/tpm_tis_core.c | 9 +++++++--
> 1 file changed, 7 insertions(+), 2 deletions(-)
>
> diff --git a/drivers/char/tpm/tpm_tis_core.c b/drivers/char/tpm/tpm_tis_core.c
> index 558144fa707a..aaaa136044ae 100644
> --- a/drivers/char/tpm/tpm_tis_core.c
> +++ b/drivers/char/tpm/tpm_tis_core.c
> @@ -363,8 +363,13 @@ static int tpm_tis_recv(struct tpm_chip *chip, u8 *buf, size_t count)
> goto out;
> }
>
> - size += recv_data(chip, &buf[TPM_HEADER_SIZE],
> - expected - TPM_HEADER_SIZE);
> + rc = recv_data(chip, &buf[TPM_HEADER_SIZE],
> + expected - TPM_HEADER_SIZE);
> + if (rc < 0) {
> + size = rc;
> + goto out;
> + }
> + size += rc;
> if (size < expected) {
> dev_err(&chip->dev, "Unable to read remainder of result\n");
> size = -ETIME;
Reviewed-by: Jarkko Sakkinen <jarkko@kernel.org>
BR, Jarkko
^ permalink raw reply [flat|nested] 8+ messages in thread
* [PATCH v3 2/4] tpm_tis: Move CRC check to generic send routine
2023-06-13 18:02 [PATCH v3 0/4] Recovery from data transfer errors for tpm_tis Alexander Steffen
2023-06-13 18:02 ` [PATCH v3 1/4] tpm_tis: Explicitly check for error code Alexander Steffen
@ 2023-06-13 18:02 ` Alexander Steffen
2023-06-13 18:02 ` [PATCH v3 3/4] tpm_tis: Use responseRetry to recover from data transfer errors Alexander Steffen
2023-06-13 18:02 ` [PATCH v3 4/4] tpm_tis: Resend command " Alexander Steffen
3 siblings, 0 replies; 8+ messages in thread
From: Alexander Steffen @ 2023-06-13 18:02 UTC (permalink / raw)
To: jarkko, linux-integrity, linux-kernel; +Cc: Alexander Steffen
The CRC functionality is initialized before tpm_tis_core, so it can be used
on all code paths within the module. Therefore, move the CRC check to the
generic send routine, that also contains all other checks for successful
command transmission, so that all those checks are in one place.
Also, this ensures that tpm_tis_ready is called when a CRC failure is
detected, to clear the invalid data from the TPM, which did not happen
previously.
Signed-off-by: Alexander Steffen <Alexander.Steffen@infineon.com>
Reviewed-by: Jarkko Sakkinen <jarkko@kernel.org>
---
drivers/char/tpm/tpm_tis_core.c | 12 ++++++------
1 file changed, 6 insertions(+), 6 deletions(-)
diff --git a/drivers/char/tpm/tpm_tis_core.c b/drivers/char/tpm/tpm_tis_core.c
index aaaa136044ae..5ddaf24518be 100644
--- a/drivers/char/tpm/tpm_tis_core.c
+++ b/drivers/char/tpm/tpm_tis_core.c
@@ -466,6 +466,12 @@ static int tpm_tis_send_data(struct tpm_chip *chip, const u8 *buf, size_t len)
goto out_err;
}
+ rc = tpm_tis_verify_crc(priv, len, buf);
+ if (rc < 0) {
+ dev_err(&chip->dev, "CRC mismatch for command.\n");
+ goto out_err;
+ }
+
return 0;
out_err:
@@ -510,12 +516,6 @@ static int tpm_tis_send_main(struct tpm_chip *chip, const u8 *buf, size_t len)
if (rc < 0)
return rc;
- rc = tpm_tis_verify_crc(priv, len, buf);
- if (rc < 0) {
- dev_err(&chip->dev, "CRC mismatch for command.\n");
- return rc;
- }
-
/* go and do it */
rc = tpm_tis_write8(priv, TPM_STS(priv->locality), TPM_STS_GO);
if (rc < 0)
--
2.25.1
^ permalink raw reply [flat|nested] 8+ messages in thread* [PATCH v3 3/4] tpm_tis: Use responseRetry to recover from data transfer errors
2023-06-13 18:02 [PATCH v3 0/4] Recovery from data transfer errors for tpm_tis Alexander Steffen
2023-06-13 18:02 ` [PATCH v3 1/4] tpm_tis: Explicitly check for error code Alexander Steffen
2023-06-13 18:02 ` [PATCH v3 2/4] tpm_tis: Move CRC check to generic send routine Alexander Steffen
@ 2023-06-13 18:02 ` Alexander Steffen
2023-07-10 16:59 ` Jarkko Sakkinen
2023-06-13 18:02 ` [PATCH v3 4/4] tpm_tis: Resend command " Alexander Steffen
3 siblings, 1 reply; 8+ messages in thread
From: Alexander Steffen @ 2023-06-13 18:02 UTC (permalink / raw)
To: jarkko, linux-integrity, linux-kernel; +Cc: Alexander Steffen
TPM responses may become damaged during transmission, for example due to
bit flips on the wire. Instead of aborting when detecting such issues, the
responseRetry functionality can be used to make the TPM retransmit its
response and receive it again without errors.
Signed-off-by: Alexander Steffen <Alexander.Steffen@infineon.com>
---
drivers/char/tpm/tpm_tis_core.c | 37 ++++++++++++++++++++++++++-------
drivers/char/tpm/tpm_tis_core.h | 1 +
2 files changed, 30 insertions(+), 8 deletions(-)
diff --git a/drivers/char/tpm/tpm_tis_core.c b/drivers/char/tpm/tpm_tis_core.c
index 5ddaf24518be..a6d1396413a7 100644
--- a/drivers/char/tpm/tpm_tis_core.c
+++ b/drivers/char/tpm/tpm_tis_core.c
@@ -337,7 +337,7 @@ static int recv_data(struct tpm_chip *chip, u8 *buf, size_t count)
return size;
}
-static int tpm_tis_recv(struct tpm_chip *chip, u8 *buf, size_t count)
+static int tpm_tis_try_recv(struct tpm_chip *chip, u8 *buf, size_t count)
{
struct tpm_tis_data *priv = dev_get_drvdata(&chip->dev);
int size = 0;
@@ -345,11 +345,6 @@ static int tpm_tis_recv(struct tpm_chip *chip, u8 *buf, size_t count)
u32 expected;
int rc;
- if (count < TPM_HEADER_SIZE) {
- size = -EIO;
- goto out;
- }
-
size = recv_data(chip, buf, TPM_HEADER_SIZE);
/* read first 10 bytes, including tag, paramsize, and result */
if (size < TPM_HEADER_SIZE) {
@@ -382,7 +377,7 @@ static int tpm_tis_recv(struct tpm_chip *chip, u8 *buf, size_t count)
goto out;
}
status = tpm_tis_status(chip);
- if (status & TPM_STS_DATA_AVAIL) { /* retry? */
+ if (status & TPM_STS_DATA_AVAIL) {
dev_err(&chip->dev, "Error left over data\n");
size = -EIO;
goto out;
@@ -396,10 +391,36 @@ static int tpm_tis_recv(struct tpm_chip *chip, u8 *buf, size_t count)
}
out:
- tpm_tis_ready(chip);
return size;
}
+static int tpm_tis_recv(struct tpm_chip *chip, u8 *buf, size_t count)
+{
+ struct tpm_tis_data *priv = dev_get_drvdata(&chip->dev);
+ unsigned int try;
+ int rc = 0;
+
+ if (count < TPM_HEADER_SIZE)
+ return -EIO;
+
+ for (try = 0; try < TPM_RETRY; try++) {
+ rc = tpm_tis_try_recv(chip, buf, count);
+
+ if (rc == -EIO)
+ /* Data transfer errors, indicated by EIO, can be
+ * recovered by rereading the response.
+ */
+ tpm_tis_write8(priv, TPM_STS(priv->locality),
+ TPM_STS_RESPONSE_RETRY);
+ else
+ break;
+ }
+
+ tpm_tis_ready(chip);
+
+ return rc;
+}
+
/*
* If interrupts are used (signaled by an irq set in the vendor structure)
* tpm.c can skip polling for the data to be available as the interrupt is
diff --git a/drivers/char/tpm/tpm_tis_core.h b/drivers/char/tpm/tpm_tis_core.h
index 610bfadb6acf..3a6b600d22ba 100644
--- a/drivers/char/tpm/tpm_tis_core.h
+++ b/drivers/char/tpm/tpm_tis_core.h
@@ -34,6 +34,7 @@ enum tis_status {
TPM_STS_GO = 0x20,
TPM_STS_DATA_AVAIL = 0x10,
TPM_STS_DATA_EXPECT = 0x08,
+ TPM_STS_RESPONSE_RETRY = 0x02,
TPM_STS_READ_ZERO = 0x23, /* bits that must be zero on read */
};
--
2.25.1
^ permalink raw reply [flat|nested] 8+ messages in thread* Re: [PATCH v3 3/4] tpm_tis: Use responseRetry to recover from data transfer errors
2023-06-13 18:02 ` [PATCH v3 3/4] tpm_tis: Use responseRetry to recover from data transfer errors Alexander Steffen
@ 2023-07-10 16:59 ` Jarkko Sakkinen
0 siblings, 0 replies; 8+ messages in thread
From: Jarkko Sakkinen @ 2023-07-10 16:59 UTC (permalink / raw)
To: Alexander Steffen, linux-integrity, linux-kernel
On Tue, 2023-06-13 at 20:02 +0200, Alexander Steffen wrote:
> TPM responses may become damaged during transmission, for example due to
> bit flips on the wire. Instead of aborting when detecting such issues, the
> responseRetry functionality can be used to make the TPM retransmit its
> response and receive it again without errors.
>
> Signed-off-by: Alexander Steffen <Alexander.Steffen@infineon.com>
> ---
> drivers/char/tpm/tpm_tis_core.c | 37 ++++++++++++++++++++++++++-------
> drivers/char/tpm/tpm_tis_core.h | 1 +
> 2 files changed, 30 insertions(+), 8 deletions(-)
>
> diff --git a/drivers/char/tpm/tpm_tis_core.c b/drivers/char/tpm/tpm_tis_core.c
> index 5ddaf24518be..a6d1396413a7 100644
> --- a/drivers/char/tpm/tpm_tis_core.c
> +++ b/drivers/char/tpm/tpm_tis_core.c
> @@ -337,7 +337,7 @@ static int recv_data(struct tpm_chip *chip, u8 *buf, size_t count)
> return size;
> }
>
> -static int tpm_tis_recv(struct tpm_chip *chip, u8 *buf, size_t count)
> +static int tpm_tis_try_recv(struct tpm_chip *chip, u8 *buf, size_t count)
> {
> struct tpm_tis_data *priv = dev_get_drvdata(&chip->dev);
> int size = 0;
> @@ -345,11 +345,6 @@ static int tpm_tis_recv(struct tpm_chip *chip, u8 *buf, size_t count)
> u32 expected;
> int rc;
>
> - if (count < TPM_HEADER_SIZE) {
> - size = -EIO;
> - goto out;
> - }
> -
> size = recv_data(chip, buf, TPM_HEADER_SIZE);
> /* read first 10 bytes, including tag, paramsize, and result */
> if (size < TPM_HEADER_SIZE) {
> @@ -382,7 +377,7 @@ static int tpm_tis_recv(struct tpm_chip *chip, u8 *buf, size_t count)
> goto out;
> }
> status = tpm_tis_status(chip);
> - if (status & TPM_STS_DATA_AVAIL) { /* retry? */
> + if (status & TPM_STS_DATA_AVAIL) {
> dev_err(&chip->dev, "Error left over data\n");
> size = -EIO;
> goto out;
> @@ -396,10 +391,36 @@ static int tpm_tis_recv(struct tpm_chip *chip, u8 *buf, size_t count)
> }
>
> out:
> - tpm_tis_ready(chip);
> return size;
> }
>
> +static int tpm_tis_recv(struct tpm_chip *chip, u8 *buf, size_t count)
> +{
> + struct tpm_tis_data *priv = dev_get_drvdata(&chip->dev);
> + unsigned int try;
> + int rc = 0;
> +
> + if (count < TPM_HEADER_SIZE)
> + return -EIO;
> +
> + for (try = 0; try < TPM_RETRY; try++) {
> + rc = tpm_tis_try_recv(chip, buf, count);
> +
> + if (rc == -EIO)
> + /* Data transfer errors, indicated by EIO, can be
> + * recovered by rereading the response.
> + */
> + tpm_tis_write8(priv, TPM_STS(priv->locality),
> + TPM_STS_RESPONSE_RETRY);
> + else
> + break;
> + }
> +
> + tpm_tis_ready(chip);
> +
> + return rc;
> +}
> +
> /*
> * If interrupts are used (signaled by an irq set in the vendor structure)
> * tpm.c can skip polling for the data to be available as the interrupt is
> diff --git a/drivers/char/tpm/tpm_tis_core.h b/drivers/char/tpm/tpm_tis_core.h
> index 610bfadb6acf..3a6b600d22ba 100644
> --- a/drivers/char/tpm/tpm_tis_core.h
> +++ b/drivers/char/tpm/tpm_tis_core.h
> @@ -34,6 +34,7 @@ enum tis_status {
> TPM_STS_GO = 0x20,
> TPM_STS_DATA_AVAIL = 0x10,
> TPM_STS_DATA_EXPECT = 0x08,
> + TPM_STS_RESPONSE_RETRY = 0x02,
> TPM_STS_READ_ZERO = 0x23, /* bits that must be zero on read */
> };
>
Reviewed-by: Jarkko Sakkinen <jarkko@kernel.org>
BR, Jarkko
^ permalink raw reply [flat|nested] 8+ messages in thread
* [PATCH v3 4/4] tpm_tis: Resend command to recover from data transfer errors
2023-06-13 18:02 [PATCH v3 0/4] Recovery from data transfer errors for tpm_tis Alexander Steffen
` (2 preceding siblings ...)
2023-06-13 18:02 ` [PATCH v3 3/4] tpm_tis: Use responseRetry to recover from data transfer errors Alexander Steffen
@ 2023-06-13 18:02 ` Alexander Steffen
2023-07-10 17:00 ` Jarkko Sakkinen
3 siblings, 1 reply; 8+ messages in thread
From: Alexander Steffen @ 2023-06-13 18:02 UTC (permalink / raw)
To: jarkko, linux-integrity, linux-kernel; +Cc: Alexander Steffen
Similar to the transmission of TPM responses, also the transmission of TPM
commands may become corrupted. Instead of aborting when detecting such
issues, try resending the command again.
Signed-off-by: Alexander Steffen <Alexander.Steffen@infineon.com>
---
drivers/char/tpm/tpm_tis_core.c | 13 ++++++++++---
1 file changed, 10 insertions(+), 3 deletions(-)
diff --git a/drivers/char/tpm/tpm_tis_core.c b/drivers/char/tpm/tpm_tis_core.c
index a6d1396413a7..7b13ad4bd6dd 100644
--- a/drivers/char/tpm/tpm_tis_core.c
+++ b/drivers/char/tpm/tpm_tis_core.c
@@ -532,10 +532,17 @@ static int tpm_tis_send_main(struct tpm_chip *chip, const u8 *buf, size_t len)
int rc;
u32 ordinal;
unsigned long dur;
+ unsigned int try;
- rc = tpm_tis_send_data(chip, buf, len);
- if (rc < 0)
- return rc;
+ for (try = 0; try < TPM_RETRY; try++) {
+ rc = tpm_tis_send_data(chip, buf, len);
+ if (rc >= 0)
+ /* Data transfer done successfully */
+ break;
+ else if (rc != -EIO)
+ /* Data transfer failed, not recoverable */
+ return rc;
+ }
/* go and do it */
rc = tpm_tis_write8(priv, TPM_STS(priv->locality), TPM_STS_GO);
--
2.25.1
^ permalink raw reply [flat|nested] 8+ messages in thread* Re: [PATCH v3 4/4] tpm_tis: Resend command to recover from data transfer errors
2023-06-13 18:02 ` [PATCH v3 4/4] tpm_tis: Resend command " Alexander Steffen
@ 2023-07-10 17:00 ` Jarkko Sakkinen
0 siblings, 0 replies; 8+ messages in thread
From: Jarkko Sakkinen @ 2023-07-10 17:00 UTC (permalink / raw)
To: Alexander Steffen, linux-integrity, linux-kernel
On Tue, 2023-06-13 at 20:02 +0200, Alexander Steffen wrote:
> Similar to the transmission of TPM responses, also the transmission of TPM
> commands may become corrupted. Instead of aborting when detecting such
> issues, try resending the command again.
>
> Signed-off-by: Alexander Steffen <Alexander.Steffen@infineon.com>
> ---
> drivers/char/tpm/tpm_tis_core.c | 13 ++++++++++---
> 1 file changed, 10 insertions(+), 3 deletions(-)
>
> diff --git a/drivers/char/tpm/tpm_tis_core.c b/drivers/char/tpm/tpm_tis_core.c
> index a6d1396413a7..7b13ad4bd6dd 100644
> --- a/drivers/char/tpm/tpm_tis_core.c
> +++ b/drivers/char/tpm/tpm_tis_core.c
> @@ -532,10 +532,17 @@ static int tpm_tis_send_main(struct tpm_chip *chip, const u8 *buf, size_t len)
> int rc;
> u32 ordinal;
> unsigned long dur;
> + unsigned int try;
>
> - rc = tpm_tis_send_data(chip, buf, len);
> - if (rc < 0)
> - return rc;
> + for (try = 0; try < TPM_RETRY; try++) {
> + rc = tpm_tis_send_data(chip, buf, len);
> + if (rc >= 0)
> + /* Data transfer done successfully */
> + break;
> + else if (rc != -EIO)
> + /* Data transfer failed, not recoverable */
> + return rc;
> + }
>
> /* go and do it */
> rc = tpm_tis_write8(priv, TPM_STS(priv->locality), TPM_STS_GO);
Reviewed-by: Jarkko Sakkinen <jarkko@kernel.org>
BR, Jarkko
^ permalink raw reply [flat|nested] 8+ messages in thread