1 // SPDX-License-Identifier: GPL-2.0-only
2 /* Copyright (c) 2010,2015,2019 The Linux Foundation. All rights reserved.
3 * Copyright (C) 2015 Linaro Ltd.
4 */
5
6 #include <linux/arm-smccc.h>
7 #include <linux/bitfield.h>
8 #include <linux/bits.h>
9 #include <linux/cleanup.h>
10 #include <linux/clk.h>
11 #include <linux/completion.h>
12 #include <linux/cpumask.h>
13 #include <linux/dma-mapping.h>
14 #include <linux/err.h>
15 #include <linux/export.h>
16 #include <linux/firmware/qcom/qcom_pas.h>
17 #include <linux/firmware/qcom/qcom_scm.h>
18 #include <linux/firmware/qcom/qcom_tzmem.h>
19 #include <linux/init.h>
20 #include <linux/interconnect.h>
21 #include <linux/interrupt.h>
22 #include <linux/kstrtox.h>
23 #include <linux/module.h>
24 #include <linux/of.h>
25 #include <linux/of_address.h>
26 #include <linux/of_irq.h>
27 #include <linux/of_platform.h>
28 #include <linux/of_reserved_mem.h>
29 #include <linux/platform_device.h>
30 #include <linux/reset-controller.h>
31 #include <linux/remoteproc.h>
32 #include <linux/sizes.h>
33 #include <linux/types.h>
34
35 #include <dt-bindings/interrupt-controller/arm-gic.h>
36
37 #include "qcom_pas.h"
38 #include "qcom_scm.h"
39 #include "qcom_tzmem.h"
40
41 static u32 download_mode;
42
43 #define GIC_SPI_BASE 32
44 #define GIC_MAX_SPI 1019 // SPIs in GICv3 spec range from 32..1019
45 #define GIC_ESPI_BASE 4096
46 #define GIC_MAX_ESPI 5119 // ESPIs in GICv3 spec range from 4096..5119
47
48 struct qcom_scm {
49 struct device *dev;
50 struct clk *core_clk;
51 struct clk *iface_clk;
52 struct clk *bus_clk;
53 struct icc_path *path;
54 struct completion *waitq_comps;
55 struct reset_controller_dev reset;
56
57 /* control access to the interconnect path */
58 struct mutex scm_bw_lock;
59 int scm_vote_count;
60
61 u64 dload_mode_addr;
62 void __iomem *minidump_sram;
63
64 struct qcom_tzmem_pool *mempool;
65 unsigned int wq_cnt;
66 };
67
68 struct qcom_scm_current_perm_info {
69 __le32 vmid;
70 __le32 perm;
71 __le64 ctx;
72 __le32 ctx_size;
73 __le32 unused;
74 };
75
76 struct qcom_scm_mem_map_info {
77 __le64 mem_addr;
78 __le64 mem_size;
79 };
80
81 /**
82 * struct qcom_scm_qseecom_resp - QSEECOM SCM call response.
83 * @result: Result or status of the SCM call. See &enum qcom_scm_qseecom_result.
84 * @resp_type: Type of the response. See &enum qcom_scm_qseecom_resp_type.
85 * @data: Response data. The type of this data is given in @resp_type.
86 */
87 struct qcom_scm_qseecom_resp {
88 u64 result;
89 u64 resp_type;
90 u64 data;
91 };
92
93 enum qcom_scm_qseecom_result {
94 QSEECOM_RESULT_SUCCESS = 0,
95 QSEECOM_RESULT_INCOMPLETE = 1,
96 QSEECOM_RESULT_BLOCKED_ON_LISTENER = 2,
97 QSEECOM_RESULT_FAILURE = 0xFFFFFFFF,
98 };
99
100 enum qcom_scm_qseecom_resp_type {
101 QSEECOM_SCM_RES_APP_ID = 0xEE01,
102 QSEECOM_SCM_RES_QSEOS_LISTENER_ID = 0xEE02,
103 };
104
105 enum qcom_scm_qseecom_tz_owner {
106 QSEECOM_TZ_OWNER_SIP = 2,
107 QSEECOM_TZ_OWNER_TZ_APPS = 48,
108 QSEECOM_TZ_OWNER_QSEE_OS = 50
109 };
110
111 enum qcom_scm_qseecom_tz_svc {
112 QSEECOM_TZ_SVC_APP_ID_PLACEHOLDER = 0,
113 QSEECOM_TZ_SVC_APP_MGR = 1,
114 QSEECOM_TZ_SVC_INFO = 6,
115 };
116
117 enum qcom_scm_qseecom_tz_cmd_app {
118 QSEECOM_TZ_CMD_APP_SEND = 1,
119 QSEECOM_TZ_CMD_APP_LOOKUP = 3,
120 };
121
122 enum qcom_scm_qseecom_tz_cmd_info {
123 QSEECOM_TZ_CMD_INFO_VERSION = 3,
124 };
125
126 #define RSCTABLE_BUFFER_NOT_SUFFICIENT 20
127
128 #define QSEECOM_MAX_APP_NAME_SIZE 64
129 #define SHMBRIDGE_RESULT_NOTSUPP 4
130
131 /* Each bit configures cold/warm boot address for one of the 4 CPUs */
132 static const u8 qcom_scm_cpu_cold_bits[QCOM_SCM_BOOT_MAX_CPUS] = {
133 0, BIT(0), BIT(3), BIT(5)
134 };
135 static const u8 qcom_scm_cpu_warm_bits[QCOM_SCM_BOOT_MAX_CPUS] = {
136 BIT(2), BIT(1), BIT(4), BIT(6)
137 };
138
139 #define QCOM_SMC_WAITQ_FLAG_WAKE_ONE BIT(0)
140
141 #define QCOM_DLOAD_MASK GENMASK(5, 4)
142 #define QCOM_DLOAD_NODUMP 0
143 #define QCOM_DLOAD_FULLDUMP 1
144 #define QCOM_DLOAD_MINIDUMP 2
145 #define QCOM_DLOAD_BOTHDUMP 3
146
147 /* Minidump destination values written to always-on SRAM for boot firmware */
148 #define QCOM_MINIDUMP_DEST_USB 0x0
149 #define QCOM_MINIDUMP_DEST_STORAGE 0x2
150
151 static u32 minidump_dest = QCOM_MINIDUMP_DEST_USB;
152
153 static const struct {
154 const char *name;
155 u32 val;
156 } minidump_dest_map[] = {
157 { "usb", QCOM_MINIDUMP_DEST_USB },
158 { "storage", QCOM_MINIDUMP_DEST_STORAGE },
159 };
160
161 #define QCOM_SCM_DEFAULT_WAITQ_COUNT 1
162
163 static const char * const qcom_scm_convention_names[] = {
164 [SMC_CONVENTION_UNKNOWN] = "unknown",
165 [SMC_CONVENTION_ARM_32] = "smc arm 32",
166 [SMC_CONVENTION_ARM_64] = "smc arm 64",
167 [SMC_CONVENTION_LEGACY] = "smc legacy",
168 };
169
170 static const char * const download_mode_name[] = {
171 [QCOM_DLOAD_NODUMP] = "off",
172 [QCOM_DLOAD_FULLDUMP] = "full",
173 [QCOM_DLOAD_MINIDUMP] = "mini",
174 [QCOM_DLOAD_BOTHDUMP] = "full,mini",
175 };
176
177 static struct qcom_scm *__scm;
178
qcom_scm_clk_enable(void)179 static int qcom_scm_clk_enable(void)
180 {
181 int ret;
182
183 ret = clk_prepare_enable(__scm->core_clk);
184 if (ret)
185 goto bail;
186
187 ret = clk_prepare_enable(__scm->iface_clk);
188 if (ret)
189 goto disable_core;
190
191 ret = clk_prepare_enable(__scm->bus_clk);
192 if (ret)
193 goto disable_iface;
194
195 return 0;
196
197 disable_iface:
198 clk_disable_unprepare(__scm->iface_clk);
199 disable_core:
200 clk_disable_unprepare(__scm->core_clk);
201 bail:
202 return ret;
203 }
204
qcom_scm_clk_disable(void)205 static void qcom_scm_clk_disable(void)
206 {
207 clk_disable_unprepare(__scm->core_clk);
208 clk_disable_unprepare(__scm->iface_clk);
209 clk_disable_unprepare(__scm->bus_clk);
210 }
211
qcom_scm_bw_enable(void)212 static int qcom_scm_bw_enable(void)
213 {
214 int ret = 0;
215
216 if (!__scm->path)
217 return 0;
218
219 guard(mutex)(&__scm->scm_bw_lock);
220
221 if (!__scm->scm_vote_count) {
222 ret = icc_set_bw(__scm->path, 0, UINT_MAX);
223 if (ret < 0) {
224 dev_err(__scm->dev, "failed to set bandwidth request\n");
225 return ret;
226 }
227 }
228 __scm->scm_vote_count++;
229
230 return 0;
231 }
232
qcom_scm_bw_disable(void)233 static void qcom_scm_bw_disable(void)
234 {
235 if (!__scm->path)
236 return;
237
238 mutex_lock(&__scm->scm_bw_lock);
239 if (__scm->scm_vote_count-- == 1)
240 icc_set_bw(__scm->path, 0, 0);
241 mutex_unlock(&__scm->scm_bw_lock);
242 }
243
244 enum qcom_scm_convention qcom_scm_convention = SMC_CONVENTION_UNKNOWN;
245 static DEFINE_SPINLOCK(scm_query_lock);
246
qcom_scm_get_tzmem_pool(void)247 struct qcom_tzmem_pool *qcom_scm_get_tzmem_pool(void)
248 {
249 if (!qcom_scm_is_available())
250 return NULL;
251
252 return __scm->mempool;
253 }
254
__get_convention(void)255 static enum qcom_scm_convention __get_convention(void)
256 {
257 unsigned long flags;
258 struct qcom_scm_desc desc = {
259 .svc = QCOM_SCM_SVC_INFO,
260 .cmd = QCOM_SCM_INFO_IS_CALL_AVAIL,
261 .args[0] = SCM_SMC_FNID(QCOM_SCM_SVC_INFO,
262 QCOM_SCM_INFO_IS_CALL_AVAIL) |
263 (ARM_SMCCC_OWNER_SIP << ARM_SMCCC_OWNER_SHIFT),
264 .arginfo = QCOM_SCM_ARGS(1),
265 .owner = ARM_SMCCC_OWNER_SIP,
266 };
267 struct qcom_scm_res res;
268 enum qcom_scm_convention probed_convention;
269 int ret;
270 bool forced = false;
271
272 if (likely(qcom_scm_convention != SMC_CONVENTION_UNKNOWN))
273 return qcom_scm_convention;
274
275 /*
276 * Per the "SMC calling convention specification", the 64-bit calling
277 * convention can only be used when the client is 64-bit, otherwise
278 * system will encounter the undefined behaviour.
279 */
280 #if IS_ENABLED(CONFIG_ARM64)
281 /*
282 * Device isn't required as there is only one argument - no device
283 * needed to dma_map_single to secure world
284 */
285 probed_convention = SMC_CONVENTION_ARM_64;
286 ret = __scm_smc_call(NULL, &desc, probed_convention, &res, true);
287 if (!ret && res.result[0] == 1)
288 goto found;
289
290 /*
291 * Some SC7180 firmwares didn't implement the
292 * QCOM_SCM_INFO_IS_CALL_AVAIL call, so we fallback to forcing ARM_64
293 * calling conventions on these firmwares. Luckily we don't make any
294 * early calls into the firmware on these SoCs so the device pointer
295 * will be valid here to check if the compatible matches.
296 */
297 if (of_device_is_compatible(__scm ? __scm->dev->of_node : NULL, "qcom,scm-sc7180")) {
298 forced = true;
299 goto found;
300 }
301 #endif
302
303 probed_convention = SMC_CONVENTION_ARM_32;
304 ret = __scm_smc_call(NULL, &desc, probed_convention, &res, true);
305 if (!ret && res.result[0] == 1)
306 goto found;
307
308 probed_convention = SMC_CONVENTION_LEGACY;
309 found:
310 spin_lock_irqsave(&scm_query_lock, flags);
311 if (probed_convention != qcom_scm_convention) {
312 qcom_scm_convention = probed_convention;
313 pr_info("qcom_scm: convention: %s%s\n",
314 qcom_scm_convention_names[qcom_scm_convention],
315 forced ? " (forced)" : "");
316 }
317 spin_unlock_irqrestore(&scm_query_lock, flags);
318
319 return qcom_scm_convention;
320 }
321
322 /**
323 * qcom_scm_call() - Invoke a syscall in the secure world
324 * @dev: device
325 * @desc: Descriptor structure containing arguments and return values
326 * @res: Structure containing results from SMC/HVC call
327 *
328 * Sends a command to the SCM and waits for the command to finish processing.
329 * This should *only* be called in pre-emptible context.
330 */
qcom_scm_call(struct device * dev,const struct qcom_scm_desc * desc,struct qcom_scm_res * res)331 static int qcom_scm_call(struct device *dev, const struct qcom_scm_desc *desc,
332 struct qcom_scm_res *res)
333 {
334 might_sleep();
335 switch (__get_convention()) {
336 case SMC_CONVENTION_ARM_32:
337 case SMC_CONVENTION_ARM_64:
338 return scm_smc_call(dev, desc, res, false);
339 case SMC_CONVENTION_LEGACY:
340 return scm_legacy_call(dev, desc, res);
341 default:
342 pr_err("Unknown current SCM calling convention.\n");
343 return -EINVAL;
344 }
345 }
346
347 /**
348 * qcom_scm_call_atomic() - atomic variation of qcom_scm_call()
349 * @dev: device
350 * @desc: Descriptor structure containing arguments and return values
351 * @res: Structure containing results from SMC/HVC call
352 *
353 * Sends a command to the SCM and waits for the command to finish processing.
354 * This can be called in atomic context.
355 */
qcom_scm_call_atomic(struct device * dev,const struct qcom_scm_desc * desc,struct qcom_scm_res * res)356 static int qcom_scm_call_atomic(struct device *dev,
357 const struct qcom_scm_desc *desc,
358 struct qcom_scm_res *res)
359 {
360 switch (__get_convention()) {
361 case SMC_CONVENTION_ARM_32:
362 case SMC_CONVENTION_ARM_64:
363 return scm_smc_call(dev, desc, res, true);
364 case SMC_CONVENTION_LEGACY:
365 return scm_legacy_call_atomic(dev, desc, res);
366 default:
367 pr_err("Unknown current SCM calling convention.\n");
368 return -EINVAL;
369 }
370 }
371
__qcom_scm_is_call_available(struct device * dev,u32 svc_id,u32 cmd_id)372 static bool __qcom_scm_is_call_available(struct device *dev, u32 svc_id,
373 u32 cmd_id)
374 {
375 int ret;
376 struct qcom_scm_desc desc = {
377 .svc = QCOM_SCM_SVC_INFO,
378 .cmd = QCOM_SCM_INFO_IS_CALL_AVAIL,
379 .owner = ARM_SMCCC_OWNER_SIP,
380 };
381 struct qcom_scm_res res;
382
383 desc.arginfo = QCOM_SCM_ARGS(1);
384 switch (__get_convention()) {
385 case SMC_CONVENTION_ARM_32:
386 case SMC_CONVENTION_ARM_64:
387 desc.args[0] = SCM_SMC_FNID(svc_id, cmd_id) |
388 (ARM_SMCCC_OWNER_SIP << ARM_SMCCC_OWNER_SHIFT);
389 break;
390 case SMC_CONVENTION_LEGACY:
391 desc.args[0] = SCM_LEGACY_FNID(svc_id, cmd_id);
392 break;
393 default:
394 pr_err("Unknown SMC convention being used\n");
395 return false;
396 }
397
398 ret = qcom_scm_call(dev, &desc, &res);
399
400 return ret ? false : !!res.result[0];
401 }
402
qcom_scm_set_boot_addr(void * entry,const u8 * cpu_bits)403 static int qcom_scm_set_boot_addr(void *entry, const u8 *cpu_bits)
404 {
405 int cpu;
406 unsigned int flags = 0;
407 struct qcom_scm_desc desc = {
408 .svc = QCOM_SCM_SVC_BOOT,
409 .cmd = QCOM_SCM_BOOT_SET_ADDR,
410 .arginfo = QCOM_SCM_ARGS(2),
411 .owner = ARM_SMCCC_OWNER_SIP,
412 };
413
414 for_each_present_cpu(cpu) {
415 if (cpu >= QCOM_SCM_BOOT_MAX_CPUS)
416 return -EINVAL;
417 flags |= cpu_bits[cpu];
418 }
419
420 desc.args[0] = flags;
421 desc.args[1] = virt_to_phys(entry);
422
423 return qcom_scm_call_atomic(__scm ? __scm->dev : NULL, &desc, NULL);
424 }
425
qcom_scm_set_boot_addr_mc(void * entry,unsigned int flags)426 static int qcom_scm_set_boot_addr_mc(void *entry, unsigned int flags)
427 {
428 struct qcom_scm_desc desc = {
429 .svc = QCOM_SCM_SVC_BOOT,
430 .cmd = QCOM_SCM_BOOT_SET_ADDR_MC,
431 .owner = ARM_SMCCC_OWNER_SIP,
432 .arginfo = QCOM_SCM_ARGS(6),
433 .args = {
434 virt_to_phys(entry),
435 /* Apply to all CPUs in all affinity levels */
436 ~0ULL, ~0ULL, ~0ULL, ~0ULL,
437 flags,
438 },
439 };
440
441 /* Need a device for DMA of the additional arguments */
442 if (!__scm || __get_convention() == SMC_CONVENTION_LEGACY)
443 return -EOPNOTSUPP;
444
445 return qcom_scm_call(__scm->dev, &desc, NULL);
446 }
447
448 /**
449 * qcom_scm_set_warm_boot_addr() - Set the warm boot address for all cpus
450 * @entry: Entry point function for the cpus
451 *
452 * Set the Linux entry point for the SCM to transfer control to when coming
453 * out of a power down. CPU power down may be executed on cpuidle or hotplug.
454 */
qcom_scm_set_warm_boot_addr(void * entry)455 int qcom_scm_set_warm_boot_addr(void *entry)
456 {
457 if (qcom_scm_set_boot_addr_mc(entry, QCOM_SCM_BOOT_MC_FLAG_WARMBOOT))
458 /* Fallback to old SCM call */
459 return qcom_scm_set_boot_addr(entry, qcom_scm_cpu_warm_bits);
460 return 0;
461 }
462 EXPORT_SYMBOL_GPL(qcom_scm_set_warm_boot_addr);
463
464 /**
465 * qcom_scm_set_cold_boot_addr() - Set the cold boot address for all cpus
466 * @entry: Entry point function for the cpus
467 */
qcom_scm_set_cold_boot_addr(void * entry)468 int qcom_scm_set_cold_boot_addr(void *entry)
469 {
470 if (qcom_scm_set_boot_addr_mc(entry, QCOM_SCM_BOOT_MC_FLAG_COLDBOOT))
471 /* Fallback to old SCM call */
472 return qcom_scm_set_boot_addr(entry, qcom_scm_cpu_cold_bits);
473 return 0;
474 }
475 EXPORT_SYMBOL_GPL(qcom_scm_set_cold_boot_addr);
476
477 /**
478 * qcom_scm_cpu_power_down() - Power down the cpu
479 * @flags: Flags to flush cache
480 *
481 * This is an end point to power down cpu. If there was a pending interrupt,
482 * the control would return from this function, otherwise, the cpu jumps to the
483 * warm boot entry point set for this cpu upon reset.
484 */
qcom_scm_cpu_power_down(u32 flags)485 void qcom_scm_cpu_power_down(u32 flags)
486 {
487 struct qcom_scm_desc desc = {
488 .svc = QCOM_SCM_SVC_BOOT,
489 .cmd = QCOM_SCM_BOOT_TERMINATE_PC,
490 .args[0] = flags & QCOM_SCM_FLUSH_FLAG_MASK,
491 .arginfo = QCOM_SCM_ARGS(1),
492 .owner = ARM_SMCCC_OWNER_SIP,
493 };
494
495 qcom_scm_call_atomic(__scm ? __scm->dev : NULL, &desc, NULL);
496 }
497 EXPORT_SYMBOL_GPL(qcom_scm_cpu_power_down);
498
qcom_scm_disable_sdi(void)499 static int qcom_scm_disable_sdi(void)
500 {
501 int ret;
502 struct qcom_scm_desc desc = {
503 .svc = QCOM_SCM_SVC_BOOT,
504 .cmd = QCOM_SCM_BOOT_SDI_CONFIG,
505 .args[0] = 1, /* Disable watchdog debug */
506 .args[1] = 0, /* Disable SDI */
507 .arginfo = QCOM_SCM_ARGS(2),
508 .owner = ARM_SMCCC_OWNER_SIP,
509 };
510 struct qcom_scm_res res;
511
512 ret = qcom_scm_clk_enable();
513 if (ret)
514 return ret;
515 ret = qcom_scm_call(__scm->dev, &desc, &res);
516
517 qcom_scm_clk_disable();
518
519 return ret ? : res.result[0];
520 }
521
__qcom_scm_set_dload_mode(struct device * dev,bool enable)522 static int __qcom_scm_set_dload_mode(struct device *dev, bool enable)
523 {
524 struct qcom_scm_desc desc = {
525 .svc = QCOM_SCM_SVC_BOOT,
526 .cmd = QCOM_SCM_BOOT_SET_DLOAD_MODE,
527 .arginfo = QCOM_SCM_ARGS(2),
528 .args[0] = QCOM_SCM_BOOT_SET_DLOAD_MODE,
529 .owner = ARM_SMCCC_OWNER_SIP,
530 };
531
532 desc.args[1] = enable ? QCOM_SCM_BOOT_SET_DLOAD_MODE : 0;
533
534 return qcom_scm_call_atomic(__scm->dev, &desc, NULL);
535 }
536
qcom_scm_io_rmw(phys_addr_t addr,unsigned int mask,unsigned int val)537 static int qcom_scm_io_rmw(phys_addr_t addr, unsigned int mask, unsigned int val)
538 {
539 unsigned int old;
540 unsigned int new;
541 int ret;
542
543 ret = qcom_scm_io_readl(addr, &old);
544 if (ret)
545 return ret;
546
547 new = (old & ~mask) | (val & mask);
548
549 return qcom_scm_io_writel(addr, new);
550 }
551
qcom_scm_set_download_mode(struct qcom_scm * scm,u32 dload_mode)552 static void qcom_scm_set_download_mode(struct qcom_scm *scm, u32 dload_mode)
553 {
554 int ret = 0;
555
556 if (scm->dload_mode_addr) {
557 ret = qcom_scm_io_rmw(scm->dload_mode_addr, QCOM_DLOAD_MASK,
558 FIELD_PREP(QCOM_DLOAD_MASK, dload_mode));
559 } else if (__qcom_scm_is_call_available(scm->dev, QCOM_SCM_SVC_BOOT,
560 QCOM_SCM_BOOT_SET_DLOAD_MODE)) {
561 ret = __qcom_scm_set_dload_mode(scm->dev, !!dload_mode);
562 } else if (dload_mode) {
563 dev_err(scm->dev,
564 "No available mechanism for setting download mode\n");
565 }
566
567 if (ret)
568 dev_err(scm->dev, "failed to set download mode: %d\n", ret);
569
570 /*
571 * Write the destination into the always-on SRAM so boot firmware
572 * can read it before DDR is initialised on the next warm reset.
573 * Only written when minidump is active;
574 */
575 if (scm->minidump_sram && (dload_mode & QCOM_DLOAD_MINIDUMP))
576 writel_relaxed(minidump_dest, scm->minidump_sram);
577 }
578
devm_qcom_scm_pas_context_alloc(struct device * dev,u32 pas_id,phys_addr_t mem_phys,size_t mem_size)579 struct qcom_scm_pas_context *devm_qcom_scm_pas_context_alloc(struct device *dev,
580 u32 pas_id,
581 phys_addr_t mem_phys,
582 size_t mem_size)
583 {
584 struct qcom_pas_context *ctx;
585
586 ctx = devm_kzalloc(dev, sizeof(*ctx), GFP_KERNEL);
587 if (!ctx)
588 return ERR_PTR(-ENOMEM);
589
590 ctx->dev = dev;
591 ctx->pas_id = pas_id;
592 ctx->mem_phys = mem_phys;
593 ctx->mem_size = mem_size;
594
595 return (struct qcom_scm_pas_context *)ctx;
596 }
597 EXPORT_SYMBOL_GPL(devm_qcom_scm_pas_context_alloc);
598
__qcom_scm_pas_init_image(struct device * dev,u32 pas_id,dma_addr_t mdata_phys,struct qcom_scm_res * res)599 static int __qcom_scm_pas_init_image(struct device *dev, u32 pas_id,
600 dma_addr_t mdata_phys,
601 struct qcom_scm_res *res)
602 {
603 struct qcom_scm_desc desc = {
604 .svc = QCOM_SCM_SVC_PIL,
605 .cmd = QCOM_SCM_PIL_PAS_INIT_IMAGE,
606 .arginfo = QCOM_SCM_ARGS(2, QCOM_SCM_VAL, QCOM_SCM_RW),
607 .args[0] = pas_id,
608 .owner = ARM_SMCCC_OWNER_SIP,
609 };
610 int ret;
611
612 ret = qcom_scm_clk_enable();
613 if (ret)
614 return ret;
615
616 ret = qcom_scm_bw_enable();
617 if (ret)
618 goto disable_clk;
619
620 desc.args[1] = mdata_phys;
621
622 ret = qcom_scm_call(dev, &desc, res);
623 qcom_scm_bw_disable();
624
625 disable_clk:
626 qcom_scm_clk_disable();
627
628 return ret;
629 }
630
qcom_scm_pas_prep_and_init_image(struct device * dev,struct qcom_pas_context * ctx,const void * metadata,size_t size)631 static int qcom_scm_pas_prep_and_init_image(struct device *dev,
632 struct qcom_pas_context *ctx,
633 const void *metadata, size_t size)
634 {
635 struct qcom_scm_res res;
636 phys_addr_t mdata_phys;
637 void *mdata_buf;
638 int ret;
639
640 mdata_buf = qcom_tzmem_alloc(__scm->mempool, size, GFP_KERNEL);
641 if (!mdata_buf)
642 return -ENOMEM;
643
644 memcpy(mdata_buf, metadata, size);
645 mdata_phys = qcom_tzmem_to_phys(mdata_buf);
646
647 ret = __qcom_scm_pas_init_image(dev, ctx->pas_id, mdata_phys, &res);
648 if (ret < 0)
649 qcom_tzmem_free(mdata_buf);
650 else
651 ctx->ptr = mdata_buf;
652
653 return ret ? : res.result[0];
654 }
655
__qcom_scm_pas_init_image2(struct device * dev,u32 pas_id,const void * metadata,size_t size,struct qcom_pas_context * ctx)656 static int __qcom_scm_pas_init_image2(struct device *dev, u32 pas_id,
657 const void *metadata, size_t size,
658 struct qcom_pas_context *ctx)
659 {
660 struct qcom_scm_res res;
661 dma_addr_t mdata_phys;
662 void *mdata_buf;
663 int ret;
664
665 if (ctx && ctx->use_tzmem)
666 return qcom_scm_pas_prep_and_init_image(dev, ctx, metadata, size);
667
668 /*
669 * During the scm call memory protection will be enabled for the meta
670 * data blob, so make sure it's physically contiguous, 4K aligned and
671 * non-cachable to avoid XPU violations.
672 *
673 * For PIL calls the hypervisor creates SHM Bridges for the blob
674 * buffers on behalf of Linux so we must not do it ourselves hence
675 * not using the TZMem allocator here.
676 *
677 * If we pass a buffer that is already part of an SHM Bridge to this
678 * call, it will fail.
679 */
680 mdata_buf = dma_alloc_coherent(dev, size, &mdata_phys, GFP_KERNEL);
681 if (!mdata_buf)
682 return -ENOMEM;
683
684 memcpy(mdata_buf, metadata, size);
685
686 ret = __qcom_scm_pas_init_image(dev, pas_id, mdata_phys, &res);
687 if (ret < 0 || !ctx) {
688 dma_free_coherent(dev, size, mdata_buf, mdata_phys);
689 } else if (ctx) {
690 ctx->ptr = mdata_buf;
691 ctx->phys = mdata_phys;
692 ctx->size = size;
693 }
694
695 return ret ? : res.result[0];
696 }
697
qcom_scm_pas_init_image(u32 pas_id,const void * metadata,size_t size,struct qcom_scm_pas_context * ctx)698 int qcom_scm_pas_init_image(u32 pas_id, const void *metadata, size_t size,
699 struct qcom_scm_pas_context *ctx)
700 {
701 return __qcom_scm_pas_init_image2(__scm->dev, pas_id, metadata, size,
702 (struct qcom_pas_context *)ctx);
703 }
704 EXPORT_SYMBOL_GPL(qcom_scm_pas_init_image);
705
__qcom_scm_pas_metadata_release(struct device * dev,struct qcom_pas_context * ctx)706 static void __qcom_scm_pas_metadata_release(struct device *dev,
707 struct qcom_pas_context *ctx)
708 {
709 if (ctx->use_tzmem)
710 qcom_tzmem_free(ctx->ptr);
711 else
712 dma_free_coherent(dev, ctx->size, ctx->ptr, ctx->phys);
713
714 ctx->ptr = NULL;
715 }
716
qcom_scm_pas_metadata_release(struct qcom_scm_pas_context * ctx)717 void qcom_scm_pas_metadata_release(struct qcom_scm_pas_context *ctx)
718 {
719 __qcom_scm_pas_metadata_release(__scm->dev,
720 (struct qcom_pas_context *)ctx);
721 }
722 EXPORT_SYMBOL_GPL(qcom_scm_pas_metadata_release);
723
__qcom_scm_pas_mem_setup(struct device * dev,u32 pas_id,phys_addr_t addr,phys_addr_t size)724 static int __qcom_scm_pas_mem_setup(struct device *dev, u32 pas_id,
725 phys_addr_t addr, phys_addr_t size)
726 {
727 int ret;
728 struct qcom_scm_desc desc = {
729 .svc = QCOM_SCM_SVC_PIL,
730 .cmd = QCOM_SCM_PIL_PAS_MEM_SETUP,
731 .arginfo = QCOM_SCM_ARGS(3),
732 .args[0] = pas_id,
733 .args[1] = addr,
734 .args[2] = size,
735 .owner = ARM_SMCCC_OWNER_SIP,
736 };
737 struct qcom_scm_res res;
738
739 ret = qcom_scm_clk_enable();
740 if (ret)
741 return ret;
742
743 ret = qcom_scm_bw_enable();
744 if (ret)
745 goto disable_clk;
746
747 ret = qcom_scm_call(dev, &desc, &res);
748 qcom_scm_bw_disable();
749
750 disable_clk:
751 qcom_scm_clk_disable();
752
753 return ret ? : res.result[0];
754 }
755
qcom_scm_pas_mem_setup(u32 pas_id,phys_addr_t addr,phys_addr_t size)756 int qcom_scm_pas_mem_setup(u32 pas_id, phys_addr_t addr, phys_addr_t size)
757 {
758 return __qcom_scm_pas_mem_setup(__scm->dev, pas_id, addr, size);
759 }
760 EXPORT_SYMBOL_GPL(qcom_scm_pas_mem_setup);
761
__qcom_scm_pas_get_rsc_table(struct device * dev,u32 pas_id,void * input_rt_tzm,size_t input_rt_size,size_t * output_rt_size)762 static void *__qcom_scm_pas_get_rsc_table(struct device *dev, u32 pas_id,
763 void *input_rt_tzm,
764 size_t input_rt_size,
765 size_t *output_rt_size)
766 {
767 struct qcom_scm_desc desc = {
768 .svc = QCOM_SCM_SVC_PIL,
769 .cmd = QCOM_SCM_PIL_PAS_GET_RSCTABLE,
770 .arginfo = QCOM_SCM_ARGS(5, QCOM_SCM_VAL, QCOM_SCM_RO, QCOM_SCM_VAL,
771 QCOM_SCM_RW, QCOM_SCM_VAL),
772 .args[0] = pas_id,
773 .owner = ARM_SMCCC_OWNER_SIP,
774 };
775 struct qcom_scm_res res;
776 void *output_rt_tzm;
777 int ret;
778
779 output_rt_tzm = qcom_tzmem_alloc(__scm->mempool, *output_rt_size, GFP_KERNEL);
780 if (!output_rt_tzm)
781 return ERR_PTR(-ENOMEM);
782
783 desc.args[1] = qcom_tzmem_to_phys(input_rt_tzm);
784 desc.args[2] = input_rt_size;
785 desc.args[3] = qcom_tzmem_to_phys(output_rt_tzm);
786 desc.args[4] = *output_rt_size;
787
788 /*
789 * Whether SMC fail or pass, res.result[2] will hold actual resource table
790 * size.
791 *
792 * If passed 'output_rt_size' buffer size is not sufficient to hold the
793 * resource table TrustZone sends, response code in res.result[1] as
794 * RSCTABLE_BUFFER_NOT_SUFFICIENT so that caller can retry this SMC call
795 * with output_rt_tzm buffer with res.result[2] size however, It should not
796 * be of unresonable size.
797 */
798 ret = qcom_scm_call(dev, &desc, &res);
799 if (!ret && res.result[2] > SZ_1G) {
800 ret = -E2BIG;
801 goto free_output_rt;
802 }
803
804 *output_rt_size = res.result[2];
805 if (ret && res.result[1] == RSCTABLE_BUFFER_NOT_SUFFICIENT)
806 ret = -EOVERFLOW;
807
808 free_output_rt:
809 if (ret)
810 qcom_tzmem_free(output_rt_tzm);
811
812 return ret ? ERR_PTR(ret) : output_rt_tzm;
813 }
814
__qcom_scm_pas_get_rsc_table2(struct device * dev,struct qcom_pas_context * ctx,void * input_rt,size_t input_rt_size,size_t * output_rt_size)815 static void *__qcom_scm_pas_get_rsc_table2(struct device *dev,
816 struct qcom_pas_context *ctx,
817 void *input_rt,
818 size_t input_rt_size,
819 size_t *output_rt_size)
820 {
821 struct resource_table empty_rsc = {};
822 size_t size = SZ_16K;
823 void *output_rt_tzm;
824 void *input_rt_tzm;
825 void *tbl_ptr;
826 int ret;
827
828 ret = qcom_scm_clk_enable();
829 if (ret)
830 return ERR_PTR(ret);
831
832 ret = qcom_scm_bw_enable();
833 if (ret)
834 goto disable_clk;
835
836 /*
837 * TrustZone can not accept buffer as NULL value as argument hence,
838 * we need to pass a input buffer indicating that subsystem firmware
839 * does not have resource table by filling resource table structure.
840 */
841 if (!input_rt) {
842 input_rt = &empty_rsc;
843 input_rt_size = sizeof(empty_rsc);
844 }
845
846 input_rt_tzm = qcom_tzmem_alloc(__scm->mempool, input_rt_size, GFP_KERNEL);
847 if (!input_rt_tzm) {
848 ret = -ENOMEM;
849 goto disable_scm_bw;
850 }
851
852 memcpy(input_rt_tzm, input_rt, input_rt_size);
853
854 output_rt_tzm = __qcom_scm_pas_get_rsc_table(dev, ctx->pas_id,
855 input_rt_tzm,
856 input_rt_size, &size);
857 if (PTR_ERR(output_rt_tzm) == -EOVERFLOW)
858 /* Try again with the size requested by the TZ */
859 output_rt_tzm = __qcom_scm_pas_get_rsc_table(dev, ctx->pas_id,
860 input_rt_tzm,
861 input_rt_size,
862 &size);
863 if (IS_ERR(output_rt_tzm)) {
864 ret = PTR_ERR(output_rt_tzm);
865 goto free_input_rt;
866 }
867
868 tbl_ptr = kmemdup(output_rt_tzm, size, GFP_KERNEL);
869 if (!tbl_ptr) {
870 qcom_tzmem_free(output_rt_tzm);
871 ret = -ENOMEM;
872 goto free_input_rt;
873 }
874
875 *output_rt_size = size;
876 qcom_tzmem_free(output_rt_tzm);
877
878 free_input_rt:
879 qcom_tzmem_free(input_rt_tzm);
880
881 disable_scm_bw:
882 qcom_scm_bw_disable();
883
884 disable_clk:
885 qcom_scm_clk_disable();
886
887 return ret ? ERR_PTR(ret) : tbl_ptr;
888 }
889
qcom_scm_pas_get_rsc_table(struct qcom_scm_pas_context * ctx,void * input_rt,size_t input_rt_size,size_t * output_rt_size)890 struct resource_table *qcom_scm_pas_get_rsc_table(struct qcom_scm_pas_context *ctx,
891 void *input_rt,
892 size_t input_rt_size,
893 size_t *output_rt_size)
894 {
895 return __qcom_scm_pas_get_rsc_table2(__scm->dev,
896 (struct qcom_pas_context *)ctx,
897 input_rt, input_rt_size,
898 output_rt_size);
899 }
900 EXPORT_SYMBOL_GPL(qcom_scm_pas_get_rsc_table);
901
__qcom_scm_pas_auth_and_reset(struct device * dev,u32 pas_id)902 static int __qcom_scm_pas_auth_and_reset(struct device *dev, u32 pas_id)
903 {
904 int ret;
905 struct qcom_scm_desc desc = {
906 .svc = QCOM_SCM_SVC_PIL,
907 .cmd = QCOM_SCM_PIL_PAS_AUTH_AND_RESET,
908 .arginfo = QCOM_SCM_ARGS(1),
909 .args[0] = pas_id,
910 .owner = ARM_SMCCC_OWNER_SIP,
911 };
912 struct qcom_scm_res res;
913
914 ret = qcom_scm_clk_enable();
915 if (ret)
916 return ret;
917
918 ret = qcom_scm_bw_enable();
919 if (ret)
920 goto disable_clk;
921
922 ret = qcom_scm_call(dev, &desc, &res);
923 qcom_scm_bw_disable();
924
925 disable_clk:
926 qcom_scm_clk_disable();
927
928 return ret ? : res.result[0];
929 }
930
qcom_scm_pas_auth_and_reset(u32 pas_id)931 int qcom_scm_pas_auth_and_reset(u32 pas_id)
932 {
933 return __qcom_scm_pas_auth_and_reset(__scm->dev, pas_id);
934 }
935 EXPORT_SYMBOL_GPL(qcom_scm_pas_auth_and_reset);
936
__qcom_scm_pas_prepare_and_auth_reset(struct device * dev,struct qcom_pas_context * ctx)937 static int __qcom_scm_pas_prepare_and_auth_reset(struct device *dev,
938 struct qcom_pas_context *ctx)
939 {
940 u64 handle;
941 int ret;
942
943 /*
944 * When Linux running @ EL1, Gunyah hypervisor running @ EL2 traps the
945 * auth_and_reset call and create an shmbridge on the remote subsystem
946 * memory region and then invokes a call to TrustZone to authenticate.
947 */
948 if (!ctx->use_tzmem)
949 return __qcom_scm_pas_auth_and_reset(dev, ctx->pas_id);
950
951 /*
952 * When Linux runs @ EL2 Linux must create the shmbridge itself and then
953 * subsequently call TrustZone for authenticate and reset.
954 */
955 ret = qcom_tzmem_shm_bridge_create(ctx->mem_phys, ctx->mem_size, &handle);
956 if (ret)
957 return ret;
958
959 ret = __qcom_scm_pas_auth_and_reset(dev, ctx->pas_id);
960 qcom_tzmem_shm_bridge_delete(handle);
961
962 return ret;
963 }
964
qcom_scm_pas_prepare_and_auth_reset(struct qcom_scm_pas_context * ctx)965 int qcom_scm_pas_prepare_and_auth_reset(struct qcom_scm_pas_context *ctx)
966 {
967 return __qcom_scm_pas_prepare_and_auth_reset(__scm->dev,
968 (struct qcom_pas_context *)ctx);
969 }
970 EXPORT_SYMBOL_GPL(qcom_scm_pas_prepare_and_auth_reset);
971
__qcom_scm_pas_set_remote_state(struct device * dev,u32 state,u32 pas_id)972 static int __qcom_scm_pas_set_remote_state(struct device *dev, u32 state,
973 u32 pas_id)
974 {
975 struct qcom_scm_desc desc = {
976 .svc = QCOM_SCM_SVC_BOOT,
977 .cmd = QCOM_SCM_BOOT_SET_REMOTE_STATE,
978 .arginfo = QCOM_SCM_ARGS(2),
979 .args[0] = state,
980 .args[1] = pas_id,
981 .owner = ARM_SMCCC_OWNER_SIP,
982 };
983 struct qcom_scm_res res;
984 int ret;
985
986 ret = qcom_scm_call(dev, &desc, &res);
987
988 return ret ? : res.result[0];
989 }
990
qcom_scm_set_remote_state(u32 state,u32 id)991 int qcom_scm_set_remote_state(u32 state, u32 id)
992 {
993 return __qcom_scm_pas_set_remote_state(__scm->dev, state, id);
994 }
995 EXPORT_SYMBOL_GPL(qcom_scm_set_remote_state);
996
__qcom_scm_pas_shutdown(struct device * dev,u32 pas_id)997 static int __qcom_scm_pas_shutdown(struct device *dev, u32 pas_id)
998 {
999 int ret;
1000 struct qcom_scm_desc desc = {
1001 .svc = QCOM_SCM_SVC_PIL,
1002 .cmd = QCOM_SCM_PIL_PAS_SHUTDOWN,
1003 .arginfo = QCOM_SCM_ARGS(1),
1004 .args[0] = pas_id,
1005 .owner = ARM_SMCCC_OWNER_SIP,
1006 };
1007 struct qcom_scm_res res;
1008
1009 ret = qcom_scm_clk_enable();
1010 if (ret)
1011 return ret;
1012
1013 ret = qcom_scm_bw_enable();
1014 if (ret)
1015 goto disable_clk;
1016
1017 ret = qcom_scm_call(dev, &desc, &res);
1018 qcom_scm_bw_disable();
1019
1020 disable_clk:
1021 qcom_scm_clk_disable();
1022
1023 return ret ? : res.result[0];
1024 }
1025
qcom_scm_pas_shutdown(u32 pas_id)1026 int qcom_scm_pas_shutdown(u32 pas_id)
1027 {
1028 return __qcom_scm_pas_shutdown(__scm->dev, pas_id);
1029 }
1030 EXPORT_SYMBOL_GPL(qcom_scm_pas_shutdown);
1031
__qcom_scm_pas_supported(struct device * dev,u32 pas_id)1032 static bool __qcom_scm_pas_supported(struct device *dev, u32 pas_id)
1033 {
1034 int ret;
1035 struct qcom_scm_desc desc = {
1036 .svc = QCOM_SCM_SVC_PIL,
1037 .cmd = QCOM_SCM_PIL_PAS_IS_SUPPORTED,
1038 .arginfo = QCOM_SCM_ARGS(1),
1039 .args[0] = pas_id,
1040 .owner = ARM_SMCCC_OWNER_SIP,
1041 };
1042 struct qcom_scm_res res;
1043
1044 if (!__qcom_scm_is_call_available(dev, QCOM_SCM_SVC_PIL,
1045 QCOM_SCM_PIL_PAS_IS_SUPPORTED))
1046 return false;
1047
1048 ret = qcom_scm_call(dev, &desc, &res);
1049
1050 return ret ? false : !!res.result[0];
1051 }
1052
qcom_scm_pas_supported(u32 pas_id)1053 bool qcom_scm_pas_supported(u32 pas_id)
1054 {
1055 return __qcom_scm_pas_supported(__scm->dev, pas_id);
1056 }
1057 EXPORT_SYMBOL_GPL(qcom_scm_pas_supported);
1058
1059 static struct qcom_pas_ops qcom_pas_ops_scm = {
1060 .drv_name = "qcom_scm",
1061 .supported = __qcom_scm_pas_supported,
1062 .init_image = __qcom_scm_pas_init_image2,
1063 .mem_setup = __qcom_scm_pas_mem_setup,
1064 .get_rsc_table = __qcom_scm_pas_get_rsc_table2,
1065 .auth_and_reset = __qcom_scm_pas_auth_and_reset,
1066 .prepare_and_auth_reset = __qcom_scm_pas_prepare_and_auth_reset,
1067 .set_remote_state = __qcom_scm_pas_set_remote_state,
1068 .shutdown = __qcom_scm_pas_shutdown,
1069 .metadata_release = __qcom_scm_pas_metadata_release,
1070 };
1071
1072 /**
1073 * qcom_scm_is_pas_available() - Check if the peripheral authentication service
1074 * is available via SCM or not
1075 *
1076 * Returns true if PAS is available, otherwise false.
1077 */
qcom_scm_is_pas_available(void)1078 static bool qcom_scm_is_pas_available(void)
1079 {
1080 if (!__qcom_scm_is_call_available(__scm->dev, QCOM_SCM_SVC_PIL,
1081 QCOM_SCM_PIL_PAS_AUTH_AND_RESET))
1082 return false;
1083
1084 return true;
1085 }
1086
__qcom_scm_pas_mss_reset(struct device * dev,bool reset)1087 static int __qcom_scm_pas_mss_reset(struct device *dev, bool reset)
1088 {
1089 struct qcom_scm_desc desc = {
1090 .svc = QCOM_SCM_SVC_PIL,
1091 .cmd = QCOM_SCM_PIL_PAS_MSS_RESET,
1092 .arginfo = QCOM_SCM_ARGS(2),
1093 .args[0] = reset,
1094 .args[1] = 0,
1095 .owner = ARM_SMCCC_OWNER_SIP,
1096 };
1097 struct qcom_scm_res res;
1098 int ret;
1099
1100 ret = qcom_scm_call(__scm->dev, &desc, &res);
1101
1102 return ret ? : res.result[0];
1103 }
1104
qcom_scm_pas_reset_assert(struct reset_controller_dev * rcdev,unsigned long idx)1105 static int qcom_scm_pas_reset_assert(struct reset_controller_dev *rcdev,
1106 unsigned long idx)
1107 {
1108 if (idx != 0)
1109 return -EINVAL;
1110
1111 return __qcom_scm_pas_mss_reset(__scm->dev, 1);
1112 }
1113
qcom_scm_pas_reset_deassert(struct reset_controller_dev * rcdev,unsigned long idx)1114 static int qcom_scm_pas_reset_deassert(struct reset_controller_dev *rcdev,
1115 unsigned long idx)
1116 {
1117 if (idx != 0)
1118 return -EINVAL;
1119
1120 return __qcom_scm_pas_mss_reset(__scm->dev, 0);
1121 }
1122
1123 static const struct reset_control_ops qcom_scm_pas_reset_ops = {
1124 .assert = qcom_scm_pas_reset_assert,
1125 .deassert = qcom_scm_pas_reset_deassert,
1126 };
1127
qcom_scm_io_readl(phys_addr_t addr,unsigned int * val)1128 int qcom_scm_io_readl(phys_addr_t addr, unsigned int *val)
1129 {
1130 struct qcom_scm_desc desc = {
1131 .svc = QCOM_SCM_SVC_IO,
1132 .cmd = QCOM_SCM_IO_READ,
1133 .arginfo = QCOM_SCM_ARGS(1),
1134 .args[0] = addr,
1135 .owner = ARM_SMCCC_OWNER_SIP,
1136 };
1137 struct qcom_scm_res res;
1138 int ret;
1139
1140
1141 ret = qcom_scm_call_atomic(__scm->dev, &desc, &res);
1142 if (ret >= 0)
1143 *val = res.result[0];
1144
1145 return ret < 0 ? ret : 0;
1146 }
1147 EXPORT_SYMBOL_GPL(qcom_scm_io_readl);
1148
qcom_scm_io_writel(phys_addr_t addr,unsigned int val)1149 int qcom_scm_io_writel(phys_addr_t addr, unsigned int val)
1150 {
1151 struct qcom_scm_desc desc = {
1152 .svc = QCOM_SCM_SVC_IO,
1153 .cmd = QCOM_SCM_IO_WRITE,
1154 .arginfo = QCOM_SCM_ARGS(2),
1155 .args[0] = addr,
1156 .args[1] = val,
1157 .owner = ARM_SMCCC_OWNER_SIP,
1158 };
1159
1160 return qcom_scm_call_atomic(__scm->dev, &desc, NULL);
1161 }
1162 EXPORT_SYMBOL_GPL(qcom_scm_io_writel);
1163
1164 /**
1165 * qcom_scm_restore_sec_cfg_available() - Check if secure environment
1166 * supports restore security config interface.
1167 *
1168 * Return true if restore-cfg interface is supported, false if not.
1169 */
qcom_scm_restore_sec_cfg_available(void)1170 bool qcom_scm_restore_sec_cfg_available(void)
1171 {
1172 return __qcom_scm_is_call_available(__scm->dev, QCOM_SCM_SVC_MP,
1173 QCOM_SCM_MP_RESTORE_SEC_CFG);
1174 }
1175 EXPORT_SYMBOL_GPL(qcom_scm_restore_sec_cfg_available);
1176
qcom_scm_restore_sec_cfg(u32 device_id,u32 spare)1177 int qcom_scm_restore_sec_cfg(u32 device_id, u32 spare)
1178 {
1179 struct qcom_scm_desc desc = {
1180 .svc = QCOM_SCM_SVC_MP,
1181 .cmd = QCOM_SCM_MP_RESTORE_SEC_CFG,
1182 .arginfo = QCOM_SCM_ARGS(2),
1183 .args[0] = device_id,
1184 .args[1] = spare,
1185 .owner = ARM_SMCCC_OWNER_SIP,
1186 };
1187 struct qcom_scm_res res;
1188 int ret;
1189
1190 ret = qcom_scm_call(__scm->dev, &desc, &res);
1191
1192 return ret ? : res.result[0];
1193 }
1194 EXPORT_SYMBOL_GPL(qcom_scm_restore_sec_cfg);
1195
1196 #define QCOM_SCM_CP_APERTURE_CONTEXT_MASK GENMASK(7, 0)
1197
qcom_scm_set_gpu_smmu_aperture_is_available(void)1198 bool qcom_scm_set_gpu_smmu_aperture_is_available(void)
1199 {
1200 return __qcom_scm_is_call_available(__scm->dev, QCOM_SCM_SVC_MP,
1201 QCOM_SCM_MP_CP_SMMU_APERTURE_ID);
1202 }
1203 EXPORT_SYMBOL_GPL(qcom_scm_set_gpu_smmu_aperture_is_available);
1204
qcom_scm_set_gpu_smmu_aperture(unsigned int context_bank)1205 int qcom_scm_set_gpu_smmu_aperture(unsigned int context_bank)
1206 {
1207 struct qcom_scm_desc desc = {
1208 .svc = QCOM_SCM_SVC_MP,
1209 .cmd = QCOM_SCM_MP_CP_SMMU_APERTURE_ID,
1210 .arginfo = QCOM_SCM_ARGS(4),
1211 .args[0] = 0xffff0000 | FIELD_PREP(QCOM_SCM_CP_APERTURE_CONTEXT_MASK, context_bank),
1212 .args[1] = 0xffffffff,
1213 .args[2] = 0xffffffff,
1214 .args[3] = 0xffffffff,
1215 .owner = ARM_SMCCC_OWNER_SIP
1216 };
1217
1218 return qcom_scm_call(__scm->dev, &desc, NULL);
1219 }
1220 EXPORT_SYMBOL_GPL(qcom_scm_set_gpu_smmu_aperture);
1221
qcom_scm_iommu_secure_ptbl_size(u32 spare,size_t * size)1222 int qcom_scm_iommu_secure_ptbl_size(u32 spare, size_t *size)
1223 {
1224 struct qcom_scm_desc desc = {
1225 .svc = QCOM_SCM_SVC_MP,
1226 .cmd = QCOM_SCM_MP_IOMMU_SECURE_PTBL_SIZE,
1227 .arginfo = QCOM_SCM_ARGS(1),
1228 .args[0] = spare,
1229 .owner = ARM_SMCCC_OWNER_SIP,
1230 };
1231 struct qcom_scm_res res;
1232 int ret;
1233
1234 ret = qcom_scm_call(__scm->dev, &desc, &res);
1235
1236 if (size)
1237 *size = res.result[0];
1238
1239 return ret ? : res.result[1];
1240 }
1241 EXPORT_SYMBOL_GPL(qcom_scm_iommu_secure_ptbl_size);
1242
qcom_scm_iommu_secure_ptbl_init(u64 addr,u32 size,u32 spare)1243 int qcom_scm_iommu_secure_ptbl_init(u64 addr, u32 size, u32 spare)
1244 {
1245 struct qcom_scm_desc desc = {
1246 .svc = QCOM_SCM_SVC_MP,
1247 .cmd = QCOM_SCM_MP_IOMMU_SECURE_PTBL_INIT,
1248 .arginfo = QCOM_SCM_ARGS(3, QCOM_SCM_RW, QCOM_SCM_VAL,
1249 QCOM_SCM_VAL),
1250 .args[0] = addr,
1251 .args[1] = size,
1252 .args[2] = spare,
1253 .owner = ARM_SMCCC_OWNER_SIP,
1254 };
1255 int ret;
1256
1257 ret = qcom_scm_call(__scm->dev, &desc, NULL);
1258
1259 /* the pg table has been initialized already, ignore the error */
1260 if (ret == -EPERM)
1261 ret = 0;
1262
1263 return ret;
1264 }
1265 EXPORT_SYMBOL_GPL(qcom_scm_iommu_secure_ptbl_init);
1266
qcom_scm_iommu_set_cp_pool_size(u32 spare,u32 size)1267 int qcom_scm_iommu_set_cp_pool_size(u32 spare, u32 size)
1268 {
1269 struct qcom_scm_desc desc = {
1270 .svc = QCOM_SCM_SVC_MP,
1271 .cmd = QCOM_SCM_MP_IOMMU_SET_CP_POOL_SIZE,
1272 .arginfo = QCOM_SCM_ARGS(2),
1273 .args[0] = size,
1274 .args[1] = spare,
1275 .owner = ARM_SMCCC_OWNER_SIP,
1276 };
1277
1278 return qcom_scm_call(__scm->dev, &desc, NULL);
1279 }
1280 EXPORT_SYMBOL_GPL(qcom_scm_iommu_set_cp_pool_size);
1281
qcom_scm_mem_protect_video_var(u32 cp_start,u32 cp_size,u32 cp_nonpixel_start,u32 cp_nonpixel_size)1282 int qcom_scm_mem_protect_video_var(u32 cp_start, u32 cp_size,
1283 u32 cp_nonpixel_start,
1284 u32 cp_nonpixel_size)
1285 {
1286 int ret;
1287 struct qcom_scm_desc desc = {
1288 .svc = QCOM_SCM_SVC_MP,
1289 .cmd = QCOM_SCM_MP_VIDEO_VAR,
1290 .arginfo = QCOM_SCM_ARGS(4, QCOM_SCM_VAL, QCOM_SCM_VAL,
1291 QCOM_SCM_VAL, QCOM_SCM_VAL),
1292 .args[0] = cp_start,
1293 .args[1] = cp_size,
1294 .args[2] = cp_nonpixel_start,
1295 .args[3] = cp_nonpixel_size,
1296 .owner = ARM_SMCCC_OWNER_SIP,
1297 };
1298 struct qcom_scm_res res;
1299
1300 ret = qcom_scm_call(__scm->dev, &desc, &res);
1301
1302 return ret ? : res.result[0];
1303 }
1304 EXPORT_SYMBOL_GPL(qcom_scm_mem_protect_video_var);
1305
__qcom_scm_assign_mem(struct device * dev,phys_addr_t mem_region,size_t mem_sz,phys_addr_t src,size_t src_sz,phys_addr_t dest,size_t dest_sz)1306 static int __qcom_scm_assign_mem(struct device *dev, phys_addr_t mem_region,
1307 size_t mem_sz, phys_addr_t src, size_t src_sz,
1308 phys_addr_t dest, size_t dest_sz)
1309 {
1310 int ret;
1311 struct qcom_scm_desc desc = {
1312 .svc = QCOM_SCM_SVC_MP,
1313 .cmd = QCOM_SCM_MP_ASSIGN,
1314 .arginfo = QCOM_SCM_ARGS(7, QCOM_SCM_RO, QCOM_SCM_VAL,
1315 QCOM_SCM_RO, QCOM_SCM_VAL, QCOM_SCM_RO,
1316 QCOM_SCM_VAL, QCOM_SCM_VAL),
1317 .args[0] = mem_region,
1318 .args[1] = mem_sz,
1319 .args[2] = src,
1320 .args[3] = src_sz,
1321 .args[4] = dest,
1322 .args[5] = dest_sz,
1323 .args[6] = 0,
1324 .owner = ARM_SMCCC_OWNER_SIP,
1325 };
1326 struct qcom_scm_res res;
1327
1328 ret = qcom_scm_call(dev, &desc, &res);
1329
1330 return ret ? : res.result[0];
1331 }
1332
1333 /**
1334 * qcom_scm_assign_mem() - Make a secure call to reassign memory ownership
1335 * @mem_addr: mem region whose ownership need to be reassigned
1336 * @mem_sz: size of the region.
1337 * @srcvm: vmid for current set of owners, each set bit in
1338 * flag indicate a unique owner
1339 * @newvm: array having new owners and corresponding permission
1340 * flags
1341 * @dest_cnt: number of owners in next set.
1342 *
1343 * Return negative errno on failure or 0 on success with @srcvm updated.
1344 */
qcom_scm_assign_mem(phys_addr_t mem_addr,size_t mem_sz,u64 * srcvm,const struct qcom_scm_vmperm * newvm,unsigned int dest_cnt)1345 int qcom_scm_assign_mem(phys_addr_t mem_addr, size_t mem_sz,
1346 u64 *srcvm,
1347 const struct qcom_scm_vmperm *newvm,
1348 unsigned int dest_cnt)
1349 {
1350 struct qcom_scm_current_perm_info *destvm;
1351 struct qcom_scm_mem_map_info *mem_to_map;
1352 phys_addr_t mem_to_map_phys;
1353 phys_addr_t dest_phys;
1354 phys_addr_t ptr_phys;
1355 size_t mem_to_map_sz;
1356 size_t dest_sz;
1357 size_t src_sz;
1358 size_t ptr_sz;
1359 int next_vm;
1360 __le32 *src;
1361 int ret, i, b;
1362 u64 srcvm_bits = *srcvm;
1363
1364 src_sz = hweight64(srcvm_bits) * sizeof(*src);
1365 mem_to_map_sz = sizeof(*mem_to_map);
1366 dest_sz = dest_cnt * sizeof(*destvm);
1367 ptr_sz = ALIGN(src_sz, SZ_64) + ALIGN(mem_to_map_sz, SZ_64) +
1368 ALIGN(dest_sz, SZ_64);
1369
1370 void *ptr __free(qcom_tzmem) = qcom_tzmem_alloc(__scm->mempool,
1371 ptr_sz, GFP_KERNEL);
1372 if (!ptr)
1373 return -ENOMEM;
1374
1375 ptr_phys = qcom_tzmem_to_phys(ptr);
1376
1377 /* Fill source vmid detail */
1378 src = ptr;
1379 i = 0;
1380 for (b = 0; b < BITS_PER_TYPE(u64); b++) {
1381 if (srcvm_bits & BIT(b))
1382 src[i++] = cpu_to_le32(b);
1383 }
1384
1385 /* Fill details of mem buff to map */
1386 mem_to_map = ptr + ALIGN(src_sz, SZ_64);
1387 mem_to_map_phys = ptr_phys + ALIGN(src_sz, SZ_64);
1388 mem_to_map->mem_addr = cpu_to_le64(mem_addr);
1389 mem_to_map->mem_size = cpu_to_le64(mem_sz);
1390
1391 next_vm = 0;
1392 /* Fill details of next vmid detail */
1393 destvm = ptr + ALIGN(mem_to_map_sz, SZ_64) + ALIGN(src_sz, SZ_64);
1394 dest_phys = ptr_phys + ALIGN(mem_to_map_sz, SZ_64) + ALIGN(src_sz, SZ_64);
1395 for (i = 0; i < dest_cnt; i++, destvm++, newvm++) {
1396 destvm->vmid = cpu_to_le32(newvm->vmid);
1397 destvm->perm = cpu_to_le32(newvm->perm);
1398 destvm->ctx = 0;
1399 destvm->ctx_size = 0;
1400 next_vm |= BIT(newvm->vmid);
1401 }
1402
1403 ret = __qcom_scm_assign_mem(__scm->dev, mem_to_map_phys, mem_to_map_sz,
1404 ptr_phys, src_sz, dest_phys, dest_sz);
1405 if (ret) {
1406 dev_err(__scm->dev,
1407 "Assign memory protection call failed %d\n", ret);
1408 return ret;
1409 }
1410
1411 *srcvm = next_vm;
1412 return 0;
1413 }
1414 EXPORT_SYMBOL_GPL(qcom_scm_assign_mem);
1415
1416 /**
1417 * qcom_scm_ocmem_lock_available() - is OCMEM lock/unlock interface available
1418 */
qcom_scm_ocmem_lock_available(void)1419 bool qcom_scm_ocmem_lock_available(void)
1420 {
1421 return __qcom_scm_is_call_available(__scm->dev, QCOM_SCM_SVC_OCMEM,
1422 QCOM_SCM_OCMEM_LOCK_CMD);
1423 }
1424 EXPORT_SYMBOL_GPL(qcom_scm_ocmem_lock_available);
1425
1426 /**
1427 * qcom_scm_ocmem_lock() - call OCMEM lock interface to assign an OCMEM
1428 * region to the specified initiator
1429 *
1430 * @id: tz initiator id
1431 * @offset: OCMEM offset
1432 * @size: OCMEM size
1433 * @mode: access mode (WIDE/NARROW)
1434 */
qcom_scm_ocmem_lock(enum qcom_scm_ocmem_client id,u32 offset,u32 size,u32 mode)1435 int qcom_scm_ocmem_lock(enum qcom_scm_ocmem_client id, u32 offset, u32 size,
1436 u32 mode)
1437 {
1438 struct qcom_scm_desc desc = {
1439 .svc = QCOM_SCM_SVC_OCMEM,
1440 .cmd = QCOM_SCM_OCMEM_LOCK_CMD,
1441 .args[0] = id,
1442 .args[1] = offset,
1443 .args[2] = size,
1444 .args[3] = mode,
1445 .arginfo = QCOM_SCM_ARGS(4),
1446 };
1447
1448 return qcom_scm_call(__scm->dev, &desc, NULL);
1449 }
1450 EXPORT_SYMBOL_GPL(qcom_scm_ocmem_lock);
1451
1452 /**
1453 * qcom_scm_ocmem_unlock() - call OCMEM unlock interface to release an OCMEM
1454 * region from the specified initiator
1455 *
1456 * @id: tz initiator id
1457 * @offset: OCMEM offset
1458 * @size: OCMEM size
1459 */
qcom_scm_ocmem_unlock(enum qcom_scm_ocmem_client id,u32 offset,u32 size)1460 int qcom_scm_ocmem_unlock(enum qcom_scm_ocmem_client id, u32 offset, u32 size)
1461 {
1462 struct qcom_scm_desc desc = {
1463 .svc = QCOM_SCM_SVC_OCMEM,
1464 .cmd = QCOM_SCM_OCMEM_UNLOCK_CMD,
1465 .args[0] = id,
1466 .args[1] = offset,
1467 .args[2] = size,
1468 .arginfo = QCOM_SCM_ARGS(3),
1469 };
1470
1471 return qcom_scm_call(__scm->dev, &desc, NULL);
1472 }
1473 EXPORT_SYMBOL_GPL(qcom_scm_ocmem_unlock);
1474
1475 /**
1476 * qcom_scm_ice_available() - Is the ICE key programming interface available?
1477 *
1478 * Return: true iff the SCM calls wrapped by qcom_scm_ice_invalidate_key() and
1479 * qcom_scm_ice_set_key() are available.
1480 */
qcom_scm_ice_available(void)1481 bool qcom_scm_ice_available(void)
1482 {
1483 return __qcom_scm_is_call_available(__scm->dev, QCOM_SCM_SVC_ES,
1484 QCOM_SCM_ES_INVALIDATE_ICE_KEY) &&
1485 __qcom_scm_is_call_available(__scm->dev, QCOM_SCM_SVC_ES,
1486 QCOM_SCM_ES_CONFIG_SET_ICE_KEY);
1487 }
1488 EXPORT_SYMBOL_GPL(qcom_scm_ice_available);
1489
1490 /**
1491 * qcom_scm_ice_invalidate_key() - Invalidate an inline encryption key
1492 * @index: the keyslot to invalidate
1493 *
1494 * The UFSHCI and eMMC standards define a standard way to do this, but it
1495 * doesn't work on these SoCs; only this SCM call does.
1496 *
1497 * It is assumed that the SoC has only one ICE instance being used, as this SCM
1498 * call doesn't specify which ICE instance the keyslot belongs to.
1499 *
1500 * Return: 0 on success; -errno on failure.
1501 */
qcom_scm_ice_invalidate_key(u32 index)1502 int qcom_scm_ice_invalidate_key(u32 index)
1503 {
1504 struct qcom_scm_desc desc = {
1505 .svc = QCOM_SCM_SVC_ES,
1506 .cmd = QCOM_SCM_ES_INVALIDATE_ICE_KEY,
1507 .arginfo = QCOM_SCM_ARGS(1),
1508 .args[0] = index,
1509 .owner = ARM_SMCCC_OWNER_SIP,
1510 };
1511
1512 return qcom_scm_call(__scm->dev, &desc, NULL);
1513 }
1514 EXPORT_SYMBOL_GPL(qcom_scm_ice_invalidate_key);
1515
1516 /**
1517 * qcom_scm_ice_set_key() - Set an inline encryption key
1518 * @index: the keyslot into which to set the key
1519 * @key: the key to program
1520 * @key_size: the size of the key in bytes
1521 * @cipher: the encryption algorithm the key is for
1522 * @data_unit_size: the encryption data unit size, i.e. the size of each
1523 * individual plaintext and ciphertext. Given in 512-byte
1524 * units, e.g. 1 = 512 bytes, 8 = 4096 bytes, etc.
1525 *
1526 * Program a key into a keyslot of Qualcomm ICE (Inline Crypto Engine), where it
1527 * can then be used to encrypt/decrypt UFS or eMMC I/O requests inline.
1528 *
1529 * The UFSHCI and eMMC standards define a standard way to do this, but it
1530 * doesn't work on these SoCs; only this SCM call does.
1531 *
1532 * It is assumed that the SoC has only one ICE instance being used, as this SCM
1533 * call doesn't specify which ICE instance the keyslot belongs to.
1534 *
1535 * Return: 0 on success; -errno on failure.
1536 */
qcom_scm_ice_set_key(u32 index,const u8 * key,u32 key_size,enum qcom_scm_ice_cipher cipher,u32 data_unit_size)1537 int qcom_scm_ice_set_key(u32 index, const u8 *key, u32 key_size,
1538 enum qcom_scm_ice_cipher cipher, u32 data_unit_size)
1539 {
1540 struct qcom_scm_desc desc = {
1541 .svc = QCOM_SCM_SVC_ES,
1542 .cmd = QCOM_SCM_ES_CONFIG_SET_ICE_KEY,
1543 .arginfo = QCOM_SCM_ARGS(5, QCOM_SCM_VAL, QCOM_SCM_RW,
1544 QCOM_SCM_VAL, QCOM_SCM_VAL,
1545 QCOM_SCM_VAL),
1546 .args[0] = index,
1547 .args[2] = key_size,
1548 .args[3] = cipher,
1549 .args[4] = data_unit_size,
1550 .owner = ARM_SMCCC_OWNER_SIP,
1551 };
1552
1553 int ret;
1554
1555 void *keybuf __free(qcom_tzmem) = qcom_tzmem_alloc(__scm->mempool,
1556 key_size,
1557 GFP_KERNEL);
1558 if (!keybuf)
1559 return -ENOMEM;
1560 memcpy(keybuf, key, key_size);
1561 desc.args[1] = qcom_tzmem_to_phys(keybuf);
1562
1563 ret = qcom_scm_call(__scm->dev, &desc, NULL);
1564
1565 memzero_explicit(keybuf, key_size);
1566
1567 return ret;
1568 }
1569 EXPORT_SYMBOL_GPL(qcom_scm_ice_set_key);
1570
qcom_scm_has_wrapped_key_support(void)1571 bool qcom_scm_has_wrapped_key_support(void)
1572 {
1573 return __qcom_scm_is_call_available(__scm->dev, QCOM_SCM_SVC_ES,
1574 QCOM_SCM_ES_DERIVE_SW_SECRET) &&
1575 __qcom_scm_is_call_available(__scm->dev, QCOM_SCM_SVC_ES,
1576 QCOM_SCM_ES_GENERATE_ICE_KEY) &&
1577 __qcom_scm_is_call_available(__scm->dev, QCOM_SCM_SVC_ES,
1578 QCOM_SCM_ES_PREPARE_ICE_KEY) &&
1579 __qcom_scm_is_call_available(__scm->dev, QCOM_SCM_SVC_ES,
1580 QCOM_SCM_ES_IMPORT_ICE_KEY);
1581 }
1582 EXPORT_SYMBOL_GPL(qcom_scm_has_wrapped_key_support);
1583
1584 /**
1585 * qcom_scm_derive_sw_secret() - Derive software secret from wrapped key
1586 * @eph_key: an ephemerally-wrapped key
1587 * @eph_key_size: size of @eph_key in bytes
1588 * @sw_secret: output buffer for the software secret
1589 * @sw_secret_size: size of the software secret to derive in bytes
1590 *
1591 * Derive a software secret from an ephemerally-wrapped key for software crypto
1592 * operations. This is done by calling into the secure execution environment,
1593 * which then calls into the hardware to unwrap and derive the secret.
1594 *
1595 * For more information on sw_secret, see the "Hardware-wrapped keys" section of
1596 * Documentation/block/inline-encryption.rst.
1597 *
1598 * Return: 0 on success; -errno on failure.
1599 */
qcom_scm_derive_sw_secret(const u8 * eph_key,size_t eph_key_size,u8 * sw_secret,size_t sw_secret_size)1600 int qcom_scm_derive_sw_secret(const u8 *eph_key, size_t eph_key_size,
1601 u8 *sw_secret, size_t sw_secret_size)
1602 {
1603 struct qcom_scm_desc desc = {
1604 .svc = QCOM_SCM_SVC_ES,
1605 .cmd = QCOM_SCM_ES_DERIVE_SW_SECRET,
1606 .arginfo = QCOM_SCM_ARGS(4, QCOM_SCM_RW, QCOM_SCM_VAL,
1607 QCOM_SCM_RW, QCOM_SCM_VAL),
1608 .owner = ARM_SMCCC_OWNER_SIP,
1609 };
1610 int ret;
1611
1612 void *eph_key_buf __free(qcom_tzmem) = qcom_tzmem_alloc(__scm->mempool,
1613 eph_key_size,
1614 GFP_KERNEL);
1615 if (!eph_key_buf)
1616 return -ENOMEM;
1617
1618 void *sw_secret_buf __free(qcom_tzmem) = qcom_tzmem_alloc(__scm->mempool,
1619 sw_secret_size,
1620 GFP_KERNEL);
1621 if (!sw_secret_buf)
1622 return -ENOMEM;
1623
1624 memcpy(eph_key_buf, eph_key, eph_key_size);
1625 desc.args[0] = qcom_tzmem_to_phys(eph_key_buf);
1626 desc.args[1] = eph_key_size;
1627 desc.args[2] = qcom_tzmem_to_phys(sw_secret_buf);
1628 desc.args[3] = sw_secret_size;
1629
1630 ret = qcom_scm_call(__scm->dev, &desc, NULL);
1631 if (!ret)
1632 memcpy(sw_secret, sw_secret_buf, sw_secret_size);
1633
1634 memzero_explicit(eph_key_buf, eph_key_size);
1635 memzero_explicit(sw_secret_buf, sw_secret_size);
1636 return ret;
1637 }
1638 EXPORT_SYMBOL_GPL(qcom_scm_derive_sw_secret);
1639
1640 /**
1641 * qcom_scm_generate_ice_key() - Generate a wrapped key for storage encryption
1642 * @lt_key: output buffer for the long-term wrapped key
1643 * @lt_key_size: size of @lt_key in bytes. Must be the exact wrapped key size
1644 * used by the SoC.
1645 *
1646 * Generate a key using the built-in HW module in the SoC. The resulting key is
1647 * returned wrapped with the platform-specific Key Encryption Key.
1648 *
1649 * Return: 0 on success; -errno on failure.
1650 */
qcom_scm_generate_ice_key(u8 * lt_key,size_t lt_key_size)1651 int qcom_scm_generate_ice_key(u8 *lt_key, size_t lt_key_size)
1652 {
1653 struct qcom_scm_desc desc = {
1654 .svc = QCOM_SCM_SVC_ES,
1655 .cmd = QCOM_SCM_ES_GENERATE_ICE_KEY,
1656 .arginfo = QCOM_SCM_ARGS(2, QCOM_SCM_RW, QCOM_SCM_VAL),
1657 .owner = ARM_SMCCC_OWNER_SIP,
1658 };
1659 int ret;
1660
1661 void *lt_key_buf __free(qcom_tzmem) = qcom_tzmem_alloc(__scm->mempool,
1662 lt_key_size,
1663 GFP_KERNEL);
1664 if (!lt_key_buf)
1665 return -ENOMEM;
1666
1667 desc.args[0] = qcom_tzmem_to_phys(lt_key_buf);
1668 desc.args[1] = lt_key_size;
1669
1670 ret = qcom_scm_call(__scm->dev, &desc, NULL);
1671 if (!ret)
1672 memcpy(lt_key, lt_key_buf, lt_key_size);
1673
1674 memzero_explicit(lt_key_buf, lt_key_size);
1675 return ret;
1676 }
1677 EXPORT_SYMBOL_GPL(qcom_scm_generate_ice_key);
1678
1679 /**
1680 * qcom_scm_prepare_ice_key() - Re-wrap a key with the per-boot ephemeral key
1681 * @lt_key: a long-term wrapped key
1682 * @lt_key_size: size of @lt_key in bytes
1683 * @eph_key: output buffer for the ephemerally-wrapped key
1684 * @eph_key_size: size of @eph_key in bytes. Must be the exact wrapped key size
1685 * used by the SoC.
1686 *
1687 * Given a long-term wrapped key, re-wrap it with the per-boot ephemeral key for
1688 * added protection. The resulting key will only be valid for the current boot.
1689 *
1690 * Return: 0 on success; -errno on failure.
1691 */
qcom_scm_prepare_ice_key(const u8 * lt_key,size_t lt_key_size,u8 * eph_key,size_t eph_key_size)1692 int qcom_scm_prepare_ice_key(const u8 *lt_key, size_t lt_key_size,
1693 u8 *eph_key, size_t eph_key_size)
1694 {
1695 struct qcom_scm_desc desc = {
1696 .svc = QCOM_SCM_SVC_ES,
1697 .cmd = QCOM_SCM_ES_PREPARE_ICE_KEY,
1698 .arginfo = QCOM_SCM_ARGS(4, QCOM_SCM_RO, QCOM_SCM_VAL,
1699 QCOM_SCM_RW, QCOM_SCM_VAL),
1700 .owner = ARM_SMCCC_OWNER_SIP,
1701 };
1702 int ret;
1703
1704 void *lt_key_buf __free(qcom_tzmem) = qcom_tzmem_alloc(__scm->mempool,
1705 lt_key_size,
1706 GFP_KERNEL);
1707 if (!lt_key_buf)
1708 return -ENOMEM;
1709
1710 void *eph_key_buf __free(qcom_tzmem) = qcom_tzmem_alloc(__scm->mempool,
1711 eph_key_size,
1712 GFP_KERNEL);
1713 if (!eph_key_buf)
1714 return -ENOMEM;
1715
1716 memcpy(lt_key_buf, lt_key, lt_key_size);
1717 desc.args[0] = qcom_tzmem_to_phys(lt_key_buf);
1718 desc.args[1] = lt_key_size;
1719 desc.args[2] = qcom_tzmem_to_phys(eph_key_buf);
1720 desc.args[3] = eph_key_size;
1721
1722 ret = qcom_scm_call(__scm->dev, &desc, NULL);
1723 if (!ret)
1724 memcpy(eph_key, eph_key_buf, eph_key_size);
1725
1726 memzero_explicit(lt_key_buf, lt_key_size);
1727 memzero_explicit(eph_key_buf, eph_key_size);
1728 return ret;
1729 }
1730 EXPORT_SYMBOL_GPL(qcom_scm_prepare_ice_key);
1731
1732 /**
1733 * qcom_scm_import_ice_key() - Import key for storage encryption
1734 * @raw_key: the raw key to import
1735 * @raw_key_size: size of @raw_key in bytes
1736 * @lt_key: output buffer for the long-term wrapped key
1737 * @lt_key_size: size of @lt_key in bytes. Must be the exact wrapped key size
1738 * used by the SoC.
1739 *
1740 * Import a raw key and return a long-term wrapped key. Uses the SoC's HWKM to
1741 * wrap the raw key using the platform-specific Key Encryption Key.
1742 *
1743 * Return: 0 on success; -errno on failure.
1744 */
qcom_scm_import_ice_key(const u8 * raw_key,size_t raw_key_size,u8 * lt_key,size_t lt_key_size)1745 int qcom_scm_import_ice_key(const u8 *raw_key, size_t raw_key_size,
1746 u8 *lt_key, size_t lt_key_size)
1747 {
1748 struct qcom_scm_desc desc = {
1749 .svc = QCOM_SCM_SVC_ES,
1750 .cmd = QCOM_SCM_ES_IMPORT_ICE_KEY,
1751 .arginfo = QCOM_SCM_ARGS(4, QCOM_SCM_RO, QCOM_SCM_VAL,
1752 QCOM_SCM_RW, QCOM_SCM_VAL),
1753 .owner = ARM_SMCCC_OWNER_SIP,
1754 };
1755 int ret;
1756
1757 void *raw_key_buf __free(qcom_tzmem) = qcom_tzmem_alloc(__scm->mempool,
1758 raw_key_size,
1759 GFP_KERNEL);
1760 if (!raw_key_buf)
1761 return -ENOMEM;
1762
1763 void *lt_key_buf __free(qcom_tzmem) = qcom_tzmem_alloc(__scm->mempool,
1764 lt_key_size,
1765 GFP_KERNEL);
1766 if (!lt_key_buf)
1767 return -ENOMEM;
1768
1769 memcpy(raw_key_buf, raw_key, raw_key_size);
1770 desc.args[0] = qcom_tzmem_to_phys(raw_key_buf);
1771 desc.args[1] = raw_key_size;
1772 desc.args[2] = qcom_tzmem_to_phys(lt_key_buf);
1773 desc.args[3] = lt_key_size;
1774
1775 ret = qcom_scm_call(__scm->dev, &desc, NULL);
1776 if (!ret)
1777 memcpy(lt_key, lt_key_buf, lt_key_size);
1778
1779 memzero_explicit(raw_key_buf, raw_key_size);
1780 memzero_explicit(lt_key_buf, lt_key_size);
1781 return ret;
1782 }
1783 EXPORT_SYMBOL_GPL(qcom_scm_import_ice_key);
1784
1785 /**
1786 * qcom_scm_hdcp_available() - Check if secure environment supports HDCP.
1787 *
1788 * Return true if HDCP is supported, false if not.
1789 */
qcom_scm_hdcp_available(void)1790 bool qcom_scm_hdcp_available(void)
1791 {
1792 bool avail;
1793 int ret = qcom_scm_clk_enable();
1794
1795 if (ret)
1796 return ret;
1797
1798 avail = __qcom_scm_is_call_available(__scm->dev, QCOM_SCM_SVC_HDCP,
1799 QCOM_SCM_HDCP_INVOKE);
1800
1801 qcom_scm_clk_disable();
1802
1803 return avail;
1804 }
1805 EXPORT_SYMBOL_GPL(qcom_scm_hdcp_available);
1806
1807 /**
1808 * qcom_scm_hdcp_req() - Send HDCP request.
1809 * @req: HDCP request array
1810 * @req_cnt: HDCP request array count
1811 * @resp: response buffer passed to SCM
1812 *
1813 * Write HDCP register(s) through SCM.
1814 */
qcom_scm_hdcp_req(struct qcom_scm_hdcp_req * req,u32 req_cnt,u32 * resp)1815 int qcom_scm_hdcp_req(struct qcom_scm_hdcp_req *req, u32 req_cnt, u32 *resp)
1816 {
1817 int ret;
1818 struct qcom_scm_desc desc = {
1819 .svc = QCOM_SCM_SVC_HDCP,
1820 .cmd = QCOM_SCM_HDCP_INVOKE,
1821 .arginfo = QCOM_SCM_ARGS(10),
1822 .args = {
1823 req[0].addr,
1824 req[0].val,
1825 req[1].addr,
1826 req[1].val,
1827 req[2].addr,
1828 req[2].val,
1829 req[3].addr,
1830 req[3].val,
1831 req[4].addr,
1832 req[4].val
1833 },
1834 .owner = ARM_SMCCC_OWNER_SIP,
1835 };
1836 struct qcom_scm_res res;
1837
1838 if (req_cnt > QCOM_SCM_HDCP_MAX_REQ_CNT)
1839 return -ERANGE;
1840
1841 ret = qcom_scm_clk_enable();
1842 if (ret)
1843 return ret;
1844
1845 ret = qcom_scm_call(__scm->dev, &desc, &res);
1846 *resp = res.result[0];
1847
1848 qcom_scm_clk_disable();
1849
1850 return ret;
1851 }
1852 EXPORT_SYMBOL_GPL(qcom_scm_hdcp_req);
1853
qcom_scm_iommu_set_pt_format(u32 sec_id,u32 ctx_num,u32 pt_fmt)1854 int qcom_scm_iommu_set_pt_format(u32 sec_id, u32 ctx_num, u32 pt_fmt)
1855 {
1856 struct qcom_scm_desc desc = {
1857 .svc = QCOM_SCM_SVC_SMMU_PROGRAM,
1858 .cmd = QCOM_SCM_SMMU_PT_FORMAT,
1859 .arginfo = QCOM_SCM_ARGS(3),
1860 .args[0] = sec_id,
1861 .args[1] = ctx_num,
1862 .args[2] = pt_fmt, /* 0: LPAE AArch32 - 1: AArch64 */
1863 .owner = ARM_SMCCC_OWNER_SIP,
1864 };
1865
1866 return qcom_scm_call(__scm->dev, &desc, NULL);
1867 }
1868 EXPORT_SYMBOL_GPL(qcom_scm_iommu_set_pt_format);
1869
qcom_scm_qsmmu500_wait_safe_toggle(bool en)1870 int qcom_scm_qsmmu500_wait_safe_toggle(bool en)
1871 {
1872 struct qcom_scm_desc desc = {
1873 .svc = QCOM_SCM_SVC_SMMU_PROGRAM,
1874 .cmd = QCOM_SCM_SMMU_CONFIG_ERRATA1,
1875 .arginfo = QCOM_SCM_ARGS(2),
1876 .args[0] = QCOM_SCM_SMMU_CONFIG_ERRATA1_CLIENT_ALL,
1877 .args[1] = en,
1878 .owner = ARM_SMCCC_OWNER_SIP,
1879 };
1880
1881
1882 return qcom_scm_call_atomic(__scm->dev, &desc, NULL);
1883 }
1884 EXPORT_SYMBOL_GPL(qcom_scm_qsmmu500_wait_safe_toggle);
1885
qcom_scm_lmh_dcvsh_available(void)1886 bool qcom_scm_lmh_dcvsh_available(void)
1887 {
1888 return __qcom_scm_is_call_available(__scm->dev, QCOM_SCM_SVC_LMH, QCOM_SCM_LMH_LIMIT_DCVSH);
1889 }
1890 EXPORT_SYMBOL_GPL(qcom_scm_lmh_dcvsh_available);
1891
1892 /*
1893 * This is only supposed to be called once by the TZMem module. It takes the
1894 * SCM struct device as argument and uses it to pass the call as at the time
1895 * the SHM Bridge is enabled, the SCM is not yet fully set up and doesn't
1896 * accept global user calls. Don't try to use the __scm pointer here.
1897 */
qcom_scm_shm_bridge_enable(struct device * scm_dev)1898 int qcom_scm_shm_bridge_enable(struct device *scm_dev)
1899 {
1900 int ret;
1901
1902 struct qcom_scm_desc desc = {
1903 .svc = QCOM_SCM_SVC_MP,
1904 .cmd = QCOM_SCM_MP_SHM_BRIDGE_ENABLE,
1905 .owner = ARM_SMCCC_OWNER_SIP
1906 };
1907
1908 struct qcom_scm_res res;
1909
1910 if (!__qcom_scm_is_call_available(scm_dev, QCOM_SCM_SVC_MP,
1911 QCOM_SCM_MP_SHM_BRIDGE_ENABLE))
1912 return -EOPNOTSUPP;
1913
1914 ret = qcom_scm_call(scm_dev, &desc, &res);
1915
1916 if (ret)
1917 return ret;
1918
1919 if (res.result[0] == SHMBRIDGE_RESULT_NOTSUPP)
1920 return -EOPNOTSUPP;
1921
1922 return res.result[0];
1923 }
1924 EXPORT_SYMBOL_GPL(qcom_scm_shm_bridge_enable);
1925
qcom_scm_shm_bridge_create(u64 pfn_and_ns_perm_flags,u64 ipfn_and_s_perm_flags,u64 size_and_flags,u64 ns_vmids,u64 * handle)1926 int qcom_scm_shm_bridge_create(u64 pfn_and_ns_perm_flags,
1927 u64 ipfn_and_s_perm_flags, u64 size_and_flags,
1928 u64 ns_vmids, u64 *handle)
1929 {
1930 struct qcom_scm_desc desc = {
1931 .svc = QCOM_SCM_SVC_MP,
1932 .cmd = QCOM_SCM_MP_SHM_BRIDGE_CREATE,
1933 .owner = ARM_SMCCC_OWNER_SIP,
1934 .args[0] = pfn_and_ns_perm_flags,
1935 .args[1] = ipfn_and_s_perm_flags,
1936 .args[2] = size_and_flags,
1937 .args[3] = ns_vmids,
1938 .arginfo = QCOM_SCM_ARGS(4, QCOM_SCM_VAL, QCOM_SCM_VAL,
1939 QCOM_SCM_VAL, QCOM_SCM_VAL),
1940 };
1941
1942 struct qcom_scm_res res;
1943 int ret;
1944
1945 ret = qcom_scm_call(__scm->dev, &desc, &res);
1946
1947 if (handle && !ret)
1948 *handle = res.result[1];
1949
1950 return ret ?: res.result[0];
1951 }
1952 EXPORT_SYMBOL_GPL(qcom_scm_shm_bridge_create);
1953
qcom_scm_shm_bridge_delete(u64 handle)1954 int qcom_scm_shm_bridge_delete(u64 handle)
1955 {
1956 struct qcom_scm_desc desc = {
1957 .svc = QCOM_SCM_SVC_MP,
1958 .cmd = QCOM_SCM_MP_SHM_BRIDGE_DELETE,
1959 .owner = ARM_SMCCC_OWNER_SIP,
1960 .args[0] = handle,
1961 .arginfo = QCOM_SCM_ARGS(1, QCOM_SCM_VAL),
1962 };
1963
1964 return qcom_scm_call(__scm->dev, &desc, NULL);
1965 }
1966 EXPORT_SYMBOL_GPL(qcom_scm_shm_bridge_delete);
1967
qcom_scm_lmh_profile_change(u32 profile_id)1968 int qcom_scm_lmh_profile_change(u32 profile_id)
1969 {
1970 struct qcom_scm_desc desc = {
1971 .svc = QCOM_SCM_SVC_LMH,
1972 .cmd = QCOM_SCM_LMH_LIMIT_PROFILE_CHANGE,
1973 .arginfo = QCOM_SCM_ARGS(1, QCOM_SCM_VAL),
1974 .args[0] = profile_id,
1975 .owner = ARM_SMCCC_OWNER_SIP,
1976 };
1977
1978 return qcom_scm_call(__scm->dev, &desc, NULL);
1979 }
1980 EXPORT_SYMBOL_GPL(qcom_scm_lmh_profile_change);
1981
qcom_scm_lmh_dcvsh(u32 payload_fn,u32 payload_reg,u32 payload_val,u64 limit_node,u32 node_id,u64 version)1982 int qcom_scm_lmh_dcvsh(u32 payload_fn, u32 payload_reg, u32 payload_val,
1983 u64 limit_node, u32 node_id, u64 version)
1984 {
1985 int ret, payload_size = 5 * sizeof(u32);
1986
1987 struct qcom_scm_desc desc = {
1988 .svc = QCOM_SCM_SVC_LMH,
1989 .cmd = QCOM_SCM_LMH_LIMIT_DCVSH,
1990 .arginfo = QCOM_SCM_ARGS(5, QCOM_SCM_RO, QCOM_SCM_VAL, QCOM_SCM_VAL,
1991 QCOM_SCM_VAL, QCOM_SCM_VAL),
1992 .args[1] = payload_size,
1993 .args[2] = limit_node,
1994 .args[3] = node_id,
1995 .args[4] = version,
1996 .owner = ARM_SMCCC_OWNER_SIP,
1997 };
1998
1999 u32 *payload_buf __free(qcom_tzmem) = qcom_tzmem_alloc(__scm->mempool,
2000 payload_size,
2001 GFP_KERNEL);
2002 if (!payload_buf)
2003 return -ENOMEM;
2004
2005 payload_buf[0] = payload_fn;
2006 payload_buf[1] = 0;
2007 payload_buf[2] = payload_reg;
2008 payload_buf[3] = 1;
2009 payload_buf[4] = payload_val;
2010
2011 desc.args[0] = qcom_tzmem_to_phys(payload_buf);
2012
2013 ret = qcom_scm_call(__scm->dev, &desc, NULL);
2014
2015 return ret;
2016 }
2017 EXPORT_SYMBOL_GPL(qcom_scm_lmh_dcvsh);
2018
qcom_scm_gpu_init_regs(u32 gpu_req)2019 int qcom_scm_gpu_init_regs(u32 gpu_req)
2020 {
2021 struct qcom_scm_desc desc = {
2022 .svc = QCOM_SCM_SVC_GPU,
2023 .cmd = QCOM_SCM_SVC_GPU_INIT_REGS,
2024 .arginfo = QCOM_SCM_ARGS(1),
2025 .args[0] = gpu_req,
2026 .owner = ARM_SMCCC_OWNER_SIP,
2027 };
2028
2029 return qcom_scm_call(__scm->dev, &desc, NULL);
2030 }
2031 EXPORT_SYMBOL_GPL(qcom_scm_gpu_init_regs);
2032
qcom_scm_map_minidump_sram(struct device * dev,void __iomem ** out)2033 static int qcom_scm_map_minidump_sram(struct device *dev, void __iomem **out)
2034 {
2035 struct device_node *np = dev->of_node;
2036 struct device_node *sram_np;
2037 struct resource res;
2038 int ret;
2039
2040 sram_np = of_parse_phandle(np, "sram", 0);
2041 if (!sram_np)
2042 return 0;
2043
2044 ret = of_address_to_resource(sram_np, 0, &res);
2045 of_node_put(sram_np);
2046 if (ret)
2047 return ret;
2048
2049 *out = devm_ioremap(dev, res.start, resource_size(&res));
2050 if (!*out)
2051 return -ENOMEM;
2052
2053 return 0;
2054 }
2055
qcom_scm_find_dload_address(struct device * dev,u64 * addr)2056 static int qcom_scm_find_dload_address(struct device *dev, u64 *addr)
2057 {
2058 struct device_node *tcsr;
2059 struct device_node *np = dev->of_node;
2060 struct resource res;
2061 u32 offset;
2062 int ret;
2063
2064 tcsr = of_parse_phandle(np, "qcom,dload-mode", 0);
2065 if (!tcsr)
2066 return 0;
2067
2068 ret = of_address_to_resource(tcsr, 0, &res);
2069 of_node_put(tcsr);
2070 if (ret)
2071 return ret;
2072
2073 ret = of_property_read_u32_index(np, "qcom,dload-mode", 1, &offset);
2074 if (ret < 0)
2075 return ret;
2076
2077 *addr = res.start + offset;
2078
2079 return 0;
2080 }
2081
2082 #ifdef CONFIG_QCOM_QSEECOM
2083
2084 /* Lock for QSEECOM SCM call executions */
2085 static DEFINE_MUTEX(qcom_scm_qseecom_call_lock);
2086
__qcom_scm_qseecom_call(const struct qcom_scm_desc * desc,struct qcom_scm_qseecom_resp * res)2087 static int __qcom_scm_qseecom_call(const struct qcom_scm_desc *desc,
2088 struct qcom_scm_qseecom_resp *res)
2089 {
2090 struct qcom_scm_res scm_res = {};
2091 int status;
2092
2093 /*
2094 * QSEECOM SCM calls should not be executed concurrently. Therefore, we
2095 * require the respective call lock to be held.
2096 */
2097 lockdep_assert_held(&qcom_scm_qseecom_call_lock);
2098
2099 status = qcom_scm_call(__scm->dev, desc, &scm_res);
2100
2101 res->result = scm_res.result[0];
2102 res->resp_type = scm_res.result[1];
2103 res->data = scm_res.result[2];
2104
2105 if (status)
2106 return status;
2107
2108 return 0;
2109 }
2110
2111 /**
2112 * qcom_scm_qseecom_call() - Perform a QSEECOM SCM call.
2113 * @desc: SCM call descriptor.
2114 * @res: SCM call response (output).
2115 *
2116 * Performs the QSEECOM SCM call described by @desc, returning the response in
2117 * @rsp.
2118 *
2119 * Return: Zero on success, nonzero on failure.
2120 */
qcom_scm_qseecom_call(const struct qcom_scm_desc * desc,struct qcom_scm_qseecom_resp * res)2121 static int qcom_scm_qseecom_call(const struct qcom_scm_desc *desc,
2122 struct qcom_scm_qseecom_resp *res)
2123 {
2124 int status;
2125
2126 /*
2127 * Note: Multiple QSEECOM SCM calls should not be executed same time,
2128 * so lock things here. This needs to be extended to callback/listener
2129 * handling when support for that is implemented.
2130 */
2131
2132 mutex_lock(&qcom_scm_qseecom_call_lock);
2133 status = __qcom_scm_qseecom_call(desc, res);
2134 mutex_unlock(&qcom_scm_qseecom_call_lock);
2135
2136 dev_dbg(__scm->dev, "%s: owner=%x, svc=%x, cmd=%x, result=%lld, type=%llx, data=%llx\n",
2137 __func__, desc->owner, desc->svc, desc->cmd, res->result,
2138 res->resp_type, res->data);
2139
2140 if (status) {
2141 dev_err(__scm->dev, "qseecom: scm call failed with error %d\n", status);
2142 return status;
2143 }
2144
2145 /*
2146 * TODO: Handle incomplete and blocked calls:
2147 *
2148 * Incomplete and blocked calls are not supported yet. Some devices
2149 * and/or commands require those, some don't. Let's warn about them
2150 * prominently in case someone attempts to try these commands with a
2151 * device/command combination that isn't supported yet.
2152 */
2153 WARN_ON(res->result == QSEECOM_RESULT_INCOMPLETE);
2154 WARN_ON(res->result == QSEECOM_RESULT_BLOCKED_ON_LISTENER);
2155
2156 return 0;
2157 }
2158
2159 /**
2160 * qcom_scm_qseecom_get_version() - Query the QSEECOM version.
2161 * @version: Pointer where the QSEECOM version will be stored.
2162 *
2163 * Performs the QSEECOM SCM querying the QSEECOM version currently running in
2164 * the TrustZone.
2165 *
2166 * Return: Zero on success, nonzero on failure.
2167 */
qcom_scm_qseecom_get_version(u32 * version)2168 static int qcom_scm_qseecom_get_version(u32 *version)
2169 {
2170 struct qcom_scm_desc desc = {};
2171 struct qcom_scm_qseecom_resp res = {};
2172 u32 feature = 10;
2173 int ret;
2174
2175 desc.owner = QSEECOM_TZ_OWNER_SIP;
2176 desc.svc = QSEECOM_TZ_SVC_INFO;
2177 desc.cmd = QSEECOM_TZ_CMD_INFO_VERSION;
2178 desc.arginfo = QCOM_SCM_ARGS(1, QCOM_SCM_VAL);
2179 desc.args[0] = feature;
2180
2181 ret = qcom_scm_qseecom_call(&desc, &res);
2182 if (ret)
2183 return ret;
2184
2185 *version = res.result;
2186 return 0;
2187 }
2188
2189 /**
2190 * qcom_scm_qseecom_app_get_id() - Query the app ID for a given QSEE app name.
2191 * @app_name: The name of the app.
2192 * @app_id: The returned app ID.
2193 *
2194 * Query and return the application ID of the SEE app identified by the given
2195 * name. This returned ID is the unique identifier of the app required for
2196 * subsequent communication.
2197 *
2198 * Return: Zero on success, nonzero on failure, -ENOENT if the app has not been
2199 * loaded or could not be found.
2200 */
qcom_scm_qseecom_app_get_id(const char * app_name,u32 * app_id)2201 int qcom_scm_qseecom_app_get_id(const char *app_name, u32 *app_id)
2202 {
2203 unsigned long name_buf_size = QSEECOM_MAX_APP_NAME_SIZE;
2204 unsigned long app_name_len = strlen(app_name);
2205 struct qcom_scm_desc desc = {};
2206 struct qcom_scm_qseecom_resp res = {};
2207 int status;
2208
2209 if (app_name_len >= name_buf_size)
2210 return -EINVAL;
2211
2212 char *name_buf __free(qcom_tzmem) = qcom_tzmem_alloc(__scm->mempool,
2213 name_buf_size,
2214 GFP_KERNEL);
2215 if (!name_buf)
2216 return -ENOMEM;
2217
2218 memcpy(name_buf, app_name, app_name_len);
2219
2220 desc.owner = QSEECOM_TZ_OWNER_QSEE_OS;
2221 desc.svc = QSEECOM_TZ_SVC_APP_MGR;
2222 desc.cmd = QSEECOM_TZ_CMD_APP_LOOKUP;
2223 desc.arginfo = QCOM_SCM_ARGS(2, QCOM_SCM_RW, QCOM_SCM_VAL);
2224 desc.args[0] = qcom_tzmem_to_phys(name_buf);
2225 desc.args[1] = app_name_len;
2226
2227 status = qcom_scm_qseecom_call(&desc, &res);
2228
2229 if (status)
2230 return status;
2231
2232 if (res.result == QSEECOM_RESULT_FAILURE)
2233 return -ENOENT;
2234
2235 if (res.result != QSEECOM_RESULT_SUCCESS)
2236 return -EINVAL;
2237
2238 if (res.resp_type != QSEECOM_SCM_RES_APP_ID)
2239 return -EINVAL;
2240
2241 *app_id = res.data;
2242 return 0;
2243 }
2244 EXPORT_SYMBOL_GPL(qcom_scm_qseecom_app_get_id);
2245
2246 /**
2247 * qcom_scm_qseecom_app_send() - Send to and receive data from a given QSEE app.
2248 * @app_id: The ID of the target app.
2249 * @req: Request buffer sent to the app (must be TZ memory)
2250 * @req_size: Size of the request buffer.
2251 * @rsp: Response buffer, written to by the app (must be TZ memory)
2252 * @rsp_size: Size of the response buffer.
2253 *
2254 * Sends a request to the QSEE app associated with the given ID and read back
2255 * its response. The caller must provide two DMA memory regions, one for the
2256 * request and one for the response, and fill out the @req region with the
2257 * respective (app-specific) request data. The QSEE app reads this and returns
2258 * its response in the @rsp region.
2259 *
2260 * Return: Zero on success, nonzero on failure.
2261 */
qcom_scm_qseecom_app_send(u32 app_id,void * req,size_t req_size,void * rsp,size_t rsp_size)2262 int qcom_scm_qseecom_app_send(u32 app_id, void *req, size_t req_size,
2263 void *rsp, size_t rsp_size)
2264 {
2265 struct qcom_scm_qseecom_resp res = {};
2266 struct qcom_scm_desc desc = {};
2267 phys_addr_t req_phys;
2268 phys_addr_t rsp_phys;
2269 int status;
2270
2271 req_phys = qcom_tzmem_to_phys(req);
2272 rsp_phys = qcom_tzmem_to_phys(rsp);
2273
2274 desc.owner = QSEECOM_TZ_OWNER_TZ_APPS;
2275 desc.svc = QSEECOM_TZ_SVC_APP_ID_PLACEHOLDER;
2276 desc.cmd = QSEECOM_TZ_CMD_APP_SEND;
2277 desc.arginfo = QCOM_SCM_ARGS(5, QCOM_SCM_VAL,
2278 QCOM_SCM_RW, QCOM_SCM_VAL,
2279 QCOM_SCM_RW, QCOM_SCM_VAL);
2280 desc.args[0] = app_id;
2281 desc.args[1] = req_phys;
2282 desc.args[2] = req_size;
2283 desc.args[3] = rsp_phys;
2284 desc.args[4] = rsp_size;
2285
2286 status = qcom_scm_qseecom_call(&desc, &res);
2287
2288 if (status)
2289 return status;
2290
2291 if (res.result != QSEECOM_RESULT_SUCCESS)
2292 return -EIO;
2293
2294 return 0;
2295 }
2296 EXPORT_SYMBOL_GPL(qcom_scm_qseecom_app_send);
2297
2298 /*
2299 * We do not yet support re-entrant calls via the qseecom interface. To prevent
2300 + any potential issues with this, only allow validated machines for now.
2301 */
2302 static const struct of_device_id qcom_scm_qseecom_allowlist[] __maybe_unused = {
2303 { .compatible = "asus,vivobook-s15" },
2304 { .compatible = "asus,vivobook-s15-x1p4" },
2305 { .compatible = "asus,zenbook-a14-ux3407qa" },
2306 { .compatible = "asus,zenbook-a14-ux3407ra" },
2307 { .compatible = "asus,zenbook-a16-ux3607oa" },
2308 { .compatible = "dell,inspiron-14-plus-7441" },
2309 { .compatible = "dell,latitude-7455" },
2310 { .compatible = "dell,xps13-9345" },
2311 { .compatible = "ecs,liva-qc710" },
2312 { .compatible = "honor,magicbook-art-14-snapdragon" },
2313 { .compatible = "hp,elitebook-ultra-g1q" },
2314 { .compatible = "hp,omnibook-x14" },
2315 { .compatible = "huawei,gaokun3" },
2316 { .compatible = "lenovo,flex-5g" },
2317 { .compatible = "lenovo,ideacentre-mini-01q8x10" },
2318 { .compatible = "lenovo,thinkbook-16" },
2319 { .compatible = "lenovo,thinkpad-t14s" },
2320 { .compatible = "lenovo,thinkpad-x13s", },
2321 { .compatible = "lenovo,yoga-slim7x" },
2322 { .compatible = "medion,sprchrgd14s1" },
2323 { .compatible = "microsoft,arcata", },
2324 { .compatible = "microsoft,surface-pro-12in", },
2325 { .compatible = "microsoft,blackrock" },
2326 { .compatible = "microsoft,denali", },
2327 { .compatible = "microsoft,romulus13", },
2328 { .compatible = "microsoft,romulus15", },
2329 { .compatible = "qcom,glymur-crd" },
2330 { .compatible = "qcom,hamoa-iot-evk" },
2331 { .compatible = "qcom,mahua-crd" },
2332 { .compatible = "qcom,purwa-iot-evk" },
2333 { .compatible = "qcom,sc8180x-primus" },
2334 { .compatible = "qcom,x1e001de-devkit" },
2335 { .compatible = "qcom,x1e80100-crd" },
2336 { .compatible = "qcom,x1e80100-qcp" },
2337 { .compatible = "qcom,x1p42100-crd" },
2338 { }
2339 };
2340
qcom_scm_qseecom_free(void * data)2341 static void qcom_scm_qseecom_free(void *data)
2342 {
2343 struct platform_device *qseecom_dev = data;
2344
2345 platform_device_del(qseecom_dev);
2346 platform_device_put(qseecom_dev);
2347 }
2348
qcom_scm_qseecom_init(struct qcom_scm * scm)2349 static int qcom_scm_qseecom_init(struct qcom_scm *scm)
2350 {
2351 struct platform_device *qseecom_dev;
2352 u32 version;
2353 int ret;
2354
2355 /*
2356 * Note: We do two steps of validation here: First, we try to query the
2357 * QSEECOM version as a check to see if the interface exists on this
2358 * device. Second, we check against known good devices due to current
2359 * driver limitations (see comment in qcom_scm_qseecom_allowlist).
2360 *
2361 * Note that we deliberately do the machine check after the version
2362 * check so that we can log potentially supported devices. This should
2363 * be safe as downstream sources indicate that the version query is
2364 * neither blocking nor reentrant.
2365 */
2366 ret = qcom_scm_qseecom_get_version(&version);
2367 if (ret)
2368 return 0;
2369
2370 dev_info(scm->dev, "qseecom: found qseecom with version 0x%x\n", version);
2371
2372 if (!of_machine_device_match(qcom_scm_qseecom_allowlist)) {
2373 dev_info(scm->dev, "qseecom: untested machine, skipping\n");
2374 return 0;
2375 }
2376
2377 /*
2378 * Set up QSEECOM interface device. All application clients will be
2379 * set up and managed by the corresponding driver for it.
2380 */
2381 qseecom_dev = platform_device_alloc("qcom_qseecom", -1);
2382 if (!qseecom_dev)
2383 return -ENOMEM;
2384
2385 qseecom_dev->dev.parent = scm->dev;
2386
2387 ret = platform_device_add(qseecom_dev);
2388 if (ret) {
2389 platform_device_put(qseecom_dev);
2390 return ret;
2391 }
2392
2393 return devm_add_action_or_reset(scm->dev, qcom_scm_qseecom_free, qseecom_dev);
2394 }
2395
2396 #else /* CONFIG_QCOM_QSEECOM */
2397
qcom_scm_qseecom_init(struct qcom_scm * scm)2398 static int qcom_scm_qseecom_init(struct qcom_scm *scm)
2399 {
2400 return 0;
2401 }
2402
2403 #endif /* CONFIG_QCOM_QSEECOM */
2404
2405 /**
2406 * qcom_scm_qtee_invoke_smc() - Invoke a QTEE object.
2407 * @inbuf: start address of memory area used for inbound buffer.
2408 * @inbuf_size: size of the memory area used for inbound buffer.
2409 * @outbuf: start address of memory area used for outbound buffer.
2410 * @outbuf_size: size of the memory area used for outbound buffer.
2411 * @result: result of QTEE object invocation.
2412 * @response_type: response type returned by QTEE.
2413 *
2414 * @response_type determines how the contents of @inbuf and @outbuf
2415 * should be processed.
2416 *
2417 * Return: On success, return 0 or <0 on failure.
2418 */
qcom_scm_qtee_invoke_smc(phys_addr_t inbuf,size_t inbuf_size,phys_addr_t outbuf,size_t outbuf_size,u64 * result,u64 * response_type)2419 int qcom_scm_qtee_invoke_smc(phys_addr_t inbuf, size_t inbuf_size,
2420 phys_addr_t outbuf, size_t outbuf_size,
2421 u64 *result, u64 *response_type)
2422 {
2423 struct qcom_scm_desc desc = {
2424 .svc = QCOM_SCM_SVC_SMCINVOKE,
2425 .cmd = QCOM_SCM_SMCINVOKE_INVOKE,
2426 .owner = ARM_SMCCC_OWNER_TRUSTED_OS,
2427 .args[0] = inbuf,
2428 .args[1] = inbuf_size,
2429 .args[2] = outbuf,
2430 .args[3] = outbuf_size,
2431 .arginfo = QCOM_SCM_ARGS(4, QCOM_SCM_RW, QCOM_SCM_VAL,
2432 QCOM_SCM_RW, QCOM_SCM_VAL),
2433 };
2434 struct qcom_scm_res res;
2435 int ret;
2436
2437 ret = qcom_scm_call(__scm->dev, &desc, &res);
2438 if (ret)
2439 return ret;
2440
2441 if (response_type)
2442 *response_type = res.result[0];
2443
2444 if (result)
2445 *result = res.result[1];
2446
2447 return 0;
2448 }
2449 EXPORT_SYMBOL(qcom_scm_qtee_invoke_smc);
2450
2451 /**
2452 * qcom_scm_qtee_callback_response() - Submit response for callback request.
2453 * @buf: start address of memory area used for outbound buffer.
2454 * @buf_size: size of the memory area used for outbound buffer.
2455 * @result: Result of QTEE object invocation.
2456 * @response_type: Response type returned by QTEE.
2457 *
2458 * @response_type determines how the contents of @buf should be processed.
2459 *
2460 * Return: On success, return 0 or <0 on failure.
2461 */
qcom_scm_qtee_callback_response(phys_addr_t buf,size_t buf_size,u64 * result,u64 * response_type)2462 int qcom_scm_qtee_callback_response(phys_addr_t buf, size_t buf_size,
2463 u64 *result, u64 *response_type)
2464 {
2465 struct qcom_scm_desc desc = {
2466 .svc = QCOM_SCM_SVC_SMCINVOKE,
2467 .cmd = QCOM_SCM_SMCINVOKE_CB_RSP,
2468 .owner = ARM_SMCCC_OWNER_TRUSTED_OS,
2469 .args[0] = buf,
2470 .args[1] = buf_size,
2471 .arginfo = QCOM_SCM_ARGS(2, QCOM_SCM_RW, QCOM_SCM_VAL),
2472 };
2473 struct qcom_scm_res res;
2474 int ret;
2475
2476 ret = qcom_scm_call(__scm->dev, &desc, &res);
2477 if (ret)
2478 return ret;
2479
2480 if (response_type)
2481 *response_type = res.result[0];
2482
2483 if (result)
2484 *result = res.result[1];
2485
2486 return 0;
2487 }
2488 EXPORT_SYMBOL(qcom_scm_qtee_callback_response);
2489
qcom_scm_gunyah_wdt_free(void * data)2490 static void qcom_scm_gunyah_wdt_free(void *data)
2491 {
2492 struct platform_device *gunyah_wdt_dev = data;
2493
2494 platform_device_unregister(gunyah_wdt_dev);
2495 }
2496
qcom_scm_gunyah_wdt_init(struct qcom_scm * scm)2497 static void qcom_scm_gunyah_wdt_init(struct qcom_scm *scm)
2498 {
2499 struct platform_device *gunyah_wdt_dev;
2500 struct device_node *np;
2501 bool of_wdt_available;
2502 int i;
2503 static const uuid_t gunyah_uuid = UUID_INIT(0xc1d58fcd, 0xa453, 0x5fdb,
2504 0x92, 0x65, 0xce, 0x36,
2505 0x67, 0x3d, 0x5f, 0x14);
2506 static const char * const of_wdt_compatible[] = {
2507 "qcom,kpss-wdt",
2508 "arm,sbsa-gwdt",
2509 };
2510
2511 /* Bail out if we are not running under Gunyah */
2512 if (!IS_ENABLED(CONFIG_HAVE_ARM_SMCCC_DISCOVERY) ||
2513 !arm_smccc_hypervisor_has_uuid(&gunyah_uuid))
2514 return;
2515
2516 /*
2517 * Gunyah emulates either of Qualcomm watchdog or ARM SBSA watchdog on
2518 * newer platforms. Bail out if we find them in the devicetree.
2519 */
2520 for (i = 0; i < ARRAY_SIZE(of_wdt_compatible); i++) {
2521 np = of_find_compatible_node(NULL, NULL, of_wdt_compatible[i]);
2522 of_wdt_available = of_device_is_available(np);
2523 of_node_put(np);
2524 if (of_wdt_available)
2525 return;
2526 }
2527
2528 gunyah_wdt_dev = platform_device_register_simple("gunyah-wdt", -1,
2529 NULL, 0);
2530 if (IS_ERR(gunyah_wdt_dev)) {
2531 dev_err(scm->dev, "Failed to register Gunyah watchdog device: %ld\n",
2532 PTR_ERR(gunyah_wdt_dev));
2533 return;
2534 }
2535
2536 devm_add_action_or_reset(scm->dev, qcom_scm_gunyah_wdt_free,
2537 gunyah_wdt_dev);
2538 }
2539
qcom_scm_qtee_free(void * data)2540 static void qcom_scm_qtee_free(void *data)
2541 {
2542 struct platform_device *qtee_dev = data;
2543
2544 platform_device_unregister(qtee_dev);
2545 }
2546
qcom_scm_qtee_init(struct qcom_scm * scm)2547 static void qcom_scm_qtee_init(struct qcom_scm *scm)
2548 {
2549 struct platform_device *qtee_dev;
2550 u64 result, response_type;
2551 int ret;
2552
2553 /*
2554 * Probe for smcinvoke support. This will fail due to invalid buffers,
2555 * but first, it checks whether the call is supported in QTEE syscall
2556 * handler. If it is not supported, -EIO is returned.
2557 */
2558 ret = qcom_scm_qtee_invoke_smc(0, 0, 0, 0, &result, &response_type);
2559 if (ret == -EIO)
2560 return;
2561
2562 /* Setup QTEE interface device. */
2563 qtee_dev = platform_device_register_data(scm->dev, "qcomtee",
2564 PLATFORM_DEVID_NONE, NULL, 0);
2565 if (IS_ERR(qtee_dev))
2566 return;
2567
2568 devm_add_action_or_reset(scm->dev, qcom_scm_qtee_free, qtee_dev);
2569 }
2570
2571 /**
2572 * qcom_scm_is_available() - Checks if SCM is available
2573 */
qcom_scm_is_available(void)2574 bool qcom_scm_is_available(void)
2575 {
2576 /* Paired with smp_store_release() in qcom_scm_probe */
2577 return !!smp_load_acquire(&__scm);
2578 }
2579 EXPORT_SYMBOL_GPL(qcom_scm_is_available);
2580
qcom_scm_fill_irq_fwspec_params(struct irq_fwspec * fwspec,u32 hwirq)2581 static int qcom_scm_fill_irq_fwspec_params(struct irq_fwspec *fwspec, u32 hwirq)
2582 {
2583 if (hwirq >= GIC_SPI_BASE && hwirq <= GIC_MAX_SPI) {
2584 fwspec->param[0] = GIC_SPI;
2585 fwspec->param[1] = hwirq - GIC_SPI_BASE;
2586 } else if (hwirq >= GIC_ESPI_BASE && hwirq <= GIC_MAX_ESPI) {
2587 fwspec->param[0] = GIC_ESPI;
2588 fwspec->param[1] = hwirq - GIC_ESPI_BASE;
2589 } else {
2590 WARN(1, "Unexpected hwirq: %d\n", hwirq);
2591 return -ENXIO;
2592 }
2593
2594 fwspec->param[2] = IRQ_TYPE_EDGE_RISING;
2595 fwspec->param_count = 3;
2596
2597 return 0;
2598 }
2599
qcom_scm_query_waitq_count(struct qcom_scm * scm)2600 static int qcom_scm_query_waitq_count(struct qcom_scm *scm)
2601 {
2602 struct qcom_scm_desc desc = {
2603 .svc = QCOM_SCM_SVC_WAITQ,
2604 .cmd = QCOM_SCM_WAITQ_GET_INFO,
2605 .owner = ARM_SMCCC_OWNER_SIP
2606 };
2607 struct qcom_scm_res res;
2608 int ret;
2609
2610 ret = qcom_scm_call_atomic(scm->dev, &desc, &res);
2611 if (ret)
2612 return ret;
2613
2614 return res.result[0] & GENMASK(7, 0);
2615 }
2616
qcom_scm_get_waitq_irq(struct qcom_scm * scm)2617 static int qcom_scm_get_waitq_irq(struct qcom_scm *scm)
2618 {
2619 struct qcom_scm_desc desc = {
2620 .svc = QCOM_SCM_SVC_WAITQ,
2621 .cmd = QCOM_SCM_WAITQ_GET_INFO,
2622 .owner = ARM_SMCCC_OWNER_SIP
2623 };
2624 struct device_node *parent_irq_node;
2625 struct irq_fwspec fwspec;
2626 struct qcom_scm_res res;
2627 u32 hwirq;
2628 int ret;
2629
2630 ret = qcom_scm_call_atomic(scm->dev, &desc, &res);
2631 if (ret)
2632 return ret;
2633
2634 hwirq = res.result[1] & GENMASK(15, 0);
2635 ret = qcom_scm_fill_irq_fwspec_params(&fwspec, hwirq);
2636 if (ret)
2637 return ret;
2638
2639 parent_irq_node = of_irq_find_parent(scm->dev->of_node);
2640 if (!parent_irq_node)
2641 return -ENODEV;
2642
2643 fwspec.fwnode = of_fwnode_handle(parent_irq_node);
2644
2645 return irq_create_fwspec_mapping(&fwspec);
2646 }
2647
qcom_scm_get_completion(struct qcom_scm * scm,u32 wq_ctx)2648 static struct completion *qcom_scm_get_completion(struct qcom_scm *scm, u32 wq_ctx)
2649 {
2650 if (WARN_ON_ONCE(wq_ctx >= scm->wq_cnt))
2651 return ERR_PTR(-EINVAL);
2652
2653 return &scm->waitq_comps[wq_ctx];
2654 }
2655
qcom_scm_wait_for_wq_completion(struct device * dev,u32 wq_ctx)2656 int qcom_scm_wait_for_wq_completion(struct device *dev, u32 wq_ctx)
2657 {
2658 struct qcom_scm *scm = dev_get_drvdata(dev);
2659 struct completion *wq;
2660
2661 wq = qcom_scm_get_completion(scm, wq_ctx);
2662 if (IS_ERR(wq))
2663 return PTR_ERR(wq);
2664
2665 wait_for_completion_state(wq, TASK_IDLE);
2666
2667 return 0;
2668 }
2669
qcom_scm_waitq_wakeup(struct qcom_scm * scm,unsigned int wq_ctx)2670 static int qcom_scm_waitq_wakeup(struct qcom_scm *scm, unsigned int wq_ctx)
2671 {
2672 struct completion *wq;
2673
2674 wq = qcom_scm_get_completion(scm, wq_ctx);
2675 if (IS_ERR(wq))
2676 return PTR_ERR(wq);
2677
2678 complete(wq);
2679
2680 return 0;
2681 }
2682
qcom_scm_irq_handler(int irq,void * data)2683 static irqreturn_t qcom_scm_irq_handler(int irq, void *data)
2684 {
2685 int ret;
2686 struct qcom_scm *scm = data;
2687 u32 wq_ctx, flags, more_pending = 0;
2688
2689 do {
2690 ret = scm_get_wq_ctx(&wq_ctx, &flags, &more_pending);
2691 if (ret) {
2692 dev_err(scm->dev, "GET_WQ_CTX SMC call failed: %d\n", ret);
2693 goto out;
2694 }
2695
2696 if (flags != QCOM_SMC_WAITQ_FLAG_WAKE_ONE) {
2697 dev_err(scm->dev, "Invalid flags received for wq_ctx: %u\n", flags);
2698 goto out;
2699 }
2700
2701 ret = qcom_scm_waitq_wakeup(scm, wq_ctx);
2702 if (ret)
2703 goto out;
2704 } while (more_pending);
2705
2706 out:
2707 return IRQ_HANDLED;
2708 }
2709
get_download_mode(char * buffer,const struct kernel_param * kp)2710 static int get_download_mode(char *buffer, const struct kernel_param *kp)
2711 {
2712 if (download_mode >= ARRAY_SIZE(download_mode_name))
2713 return sysfs_emit(buffer, "unknown mode\n");
2714
2715 return sysfs_emit(buffer, "%s\n", download_mode_name[download_mode]);
2716 }
2717
set_download_mode(const char * val,const struct kernel_param * kp)2718 static int set_download_mode(const char *val, const struct kernel_param *kp)
2719 {
2720 struct qcom_scm *scm;
2721 bool tmp;
2722 int ret;
2723
2724 ret = sysfs_match_string(download_mode_name, val);
2725 if (ret < 0) {
2726 ret = kstrtobool(val, &tmp);
2727 if (ret < 0) {
2728 pr_err("qcom_scm: err: %d\n", ret);
2729 return ret;
2730 }
2731
2732 ret = tmp ? 1 : 0;
2733 }
2734
2735 download_mode = ret;
2736 /* Pairs with smp_store_release() in qcom_scm_probe(). */
2737 scm = smp_load_acquire(&__scm);
2738 if (scm)
2739 qcom_scm_set_download_mode(scm, download_mode);
2740
2741 return 0;
2742 }
2743
2744 static const struct kernel_param_ops download_mode_param_ops = {
2745 .get = get_download_mode,
2746 .set = set_download_mode,
2747 };
2748
2749 module_param_cb(download_mode, &download_mode_param_ops, NULL, 0644);
2750 MODULE_PARM_DESC(download_mode, "download mode: off/0/N for no dump mode, full/on/1/Y for full dump mode, mini for minidump mode and full,mini for both full and minidump mode together are acceptable values");
2751
get_minidump_dest(char * buffer,const struct kernel_param * kp)2752 static int get_minidump_dest(char *buffer, const struct kernel_param *kp)
2753 {
2754 int i;
2755
2756 for (i = 0; i < ARRAY_SIZE(minidump_dest_map); i++)
2757 if (minidump_dest == minidump_dest_map[i].val)
2758 return sysfs_emit(buffer, "%s\n", minidump_dest_map[i].name);
2759
2760 return sysfs_emit(buffer, "unknown\n");
2761 }
2762
set_minidump_dest(const char * val,const struct kernel_param * kp)2763 static int set_minidump_dest(const char *val, const struct kernel_param *kp)
2764 {
2765 struct qcom_scm *scm;
2766 int i;
2767
2768 for (i = 0; i < ARRAY_SIZE(minidump_dest_map); i++)
2769 if (sysfs_streq(val, minidump_dest_map[i].name))
2770 break;
2771
2772 if (i >= ARRAY_SIZE(minidump_dest_map))
2773 return -EINVAL;
2774
2775 minidump_dest = minidump_dest_map[i].val;
2776
2777 /* Pairs with smp_store_release() in qcom_scm_probe(). */
2778 scm = smp_load_acquire(&__scm);
2779 if (scm && scm->minidump_sram && (download_mode & QCOM_DLOAD_MINIDUMP))
2780 writel_relaxed(minidump_dest, scm->minidump_sram);
2781
2782 return 0;
2783 }
2784
2785 static const struct kernel_param_ops minidump_dest_param_ops = {
2786 .get = get_minidump_dest,
2787 .set = set_minidump_dest,
2788 };
2789
2790 module_param_cb(minidump_dest, &minidump_dest_param_ops, NULL, 0644);
2791 MODULE_PARM_DESC(minidump_dest, "Minidump SRAM destination: usb (default) or storage");
2792
qcom_scm_probe(struct platform_device * pdev)2793 static int qcom_scm_probe(struct platform_device *pdev)
2794 {
2795 struct qcom_tzmem_pool_config pool_config;
2796 struct qcom_scm *scm;
2797 int irq, ret;
2798 int i;
2799
2800 scm = devm_kzalloc(&pdev->dev, sizeof(*scm), GFP_KERNEL);
2801 if (!scm)
2802 return -ENOMEM;
2803
2804 scm->dev = &pdev->dev;
2805 platform_set_drvdata(pdev, scm);
2806 ret = qcom_scm_find_dload_address(&pdev->dev, &scm->dload_mode_addr);
2807 if (ret < 0)
2808 return dev_err_probe(&pdev->dev, ret,
2809 "Failed to get download mode address\n");
2810
2811 ret = qcom_scm_map_minidump_sram(&pdev->dev, &scm->minidump_sram);
2812 if (ret < 0)
2813 return dev_err_probe(&pdev->dev, ret,
2814 "Failed to map minidump SRAM\n");
2815
2816 mutex_init(&scm->scm_bw_lock);
2817
2818 scm->path = devm_of_icc_get(&pdev->dev, NULL);
2819 if (IS_ERR(scm->path))
2820 return dev_err_probe(&pdev->dev, PTR_ERR(scm->path),
2821 "failed to acquire interconnect path\n");
2822
2823 scm->core_clk = devm_clk_get_optional(&pdev->dev, "core");
2824 if (IS_ERR(scm->core_clk))
2825 return PTR_ERR(scm->core_clk);
2826
2827 scm->iface_clk = devm_clk_get_optional(&pdev->dev, "iface");
2828 if (IS_ERR(scm->iface_clk))
2829 return PTR_ERR(scm->iface_clk);
2830
2831 scm->bus_clk = devm_clk_get_optional(&pdev->dev, "bus");
2832 if (IS_ERR(scm->bus_clk))
2833 return PTR_ERR(scm->bus_clk);
2834
2835 scm->reset.ops = &qcom_scm_pas_reset_ops;
2836 scm->reset.nr_resets = 1;
2837 scm->reset.of_node = pdev->dev.of_node;
2838 ret = devm_reset_controller_register(&pdev->dev, &scm->reset);
2839 if (ret)
2840 return ret;
2841
2842 /* vote for max clk rate for highest performance */
2843 ret = clk_set_rate(scm->core_clk, INT_MAX);
2844 if (ret)
2845 return ret;
2846
2847 ret = of_reserved_mem_device_init(scm->dev);
2848 if (ret && ret != -ENODEV)
2849 return dev_err_probe(scm->dev, ret,
2850 "Failed to setup the reserved memory region for TZ mem\n");
2851
2852 ret = qcom_tzmem_enable(scm->dev);
2853 if (ret) {
2854 ret = dev_err_probe(scm->dev, ret,
2855 "Failed to enable the TrustZone memory allocator\n");
2856 goto err_rmem;
2857 }
2858
2859 memset(&pool_config, 0, sizeof(pool_config));
2860 pool_config.initial_size = 0;
2861 pool_config.policy = QCOM_TZMEM_POLICY_ON_DEMAND;
2862 pool_config.max_size = SZ_256K;
2863
2864 scm->mempool = devm_qcom_tzmem_pool_new(scm->dev, &pool_config);
2865 if (IS_ERR(scm->mempool)) {
2866 ret = dev_err_probe(scm->dev, PTR_ERR(scm->mempool),
2867 "Failed to create the SCM memory pool\n");
2868 goto err_rmem;
2869 }
2870
2871 ret = qcom_scm_query_waitq_count(scm);
2872 scm->wq_cnt = ret < 0 ? QCOM_SCM_DEFAULT_WAITQ_COUNT : ret;
2873 scm->waitq_comps = devm_kcalloc(&pdev->dev, scm->wq_cnt, sizeof(*scm->waitq_comps),
2874 GFP_KERNEL);
2875 if (!scm->waitq_comps)
2876 return -ENOMEM;
2877
2878 for (i = 0; i < scm->wq_cnt; i++)
2879 init_completion(&scm->waitq_comps[i]);
2880
2881 irq = qcom_scm_get_waitq_irq(scm);
2882 if (irq < 0)
2883 irq = platform_get_irq_optional(pdev, 0);
2884
2885 if (irq < 0) {
2886 if (irq != -ENXIO)
2887 return irq;
2888 } else {
2889 ret = devm_request_threaded_irq(scm->dev, irq, NULL, qcom_scm_irq_handler,
2890 IRQF_ONESHOT, "qcom-scm", scm);
2891 if (ret < 0)
2892 return dev_err_probe(scm->dev, ret,
2893 "Failed to request qcom-scm irq\n");
2894 }
2895
2896 /*
2897 * Paired with smp_load_acquire() in qcom_scm_is_available().
2898 *
2899 * This marks the SCM API as ready to accept user calls and can only
2900 * be called after the TrustZone memory pool is initialized and the
2901 * waitqueue interrupt requested.
2902 */
2903 smp_store_release(&__scm, scm);
2904
2905 __get_convention();
2906
2907 if (qcom_scm_is_pas_available()) {
2908 qcom_pas_ops_scm.dev = scm->dev;
2909 qcom_pas_ops_register(&qcom_pas_ops_scm);
2910 }
2911
2912 /*
2913 * If "download mode" is requested, from this point on warmboot
2914 * will cause the boot stages to enter download mode, unless
2915 * disabled below by a clean shutdown/reboot.
2916 */
2917 qcom_scm_set_download_mode(scm, download_mode);
2918
2919 /*
2920 * Disable SDI if indicated by DT that it is enabled by default.
2921 */
2922 if (of_property_read_bool(pdev->dev.of_node, "qcom,sdi-enabled") || !download_mode)
2923 qcom_scm_disable_sdi();
2924
2925 /*
2926 * Initialize the QSEECOM interface.
2927 *
2928 * Note: QSEECOM is fairly self-contained and this only adds the
2929 * interface device (the driver of which does most of the heavy
2930 * lifting). So any errors returned here should be either -ENOMEM or
2931 * -EINVAL (with the latter only in case there's a bug in our code).
2932 * This means that there is no need to bring down the whole SCM driver.
2933 * Just log the error instead and let SCM live.
2934 */
2935 ret = qcom_scm_qseecom_init(scm);
2936 WARN(ret < 0, "failed to initialize qseecom: %d\n", ret);
2937
2938 /* Initialize the QTEE object interface. */
2939 qcom_scm_qtee_init(scm);
2940
2941 /* Initialize the Gunyah watchdog platform device. */
2942 qcom_scm_gunyah_wdt_init(scm);
2943
2944 return 0;
2945
2946 err_rmem:
2947 of_reserved_mem_device_release(scm->dev);
2948 return ret;
2949 }
2950
qcom_scm_shutdown(struct platform_device * pdev)2951 static void qcom_scm_shutdown(struct platform_device *pdev)
2952 {
2953 /* Clean shutdown, disable download mode to allow normal restart */
2954 qcom_scm_set_download_mode(__scm, QCOM_DLOAD_NODUMP);
2955 qcom_pas_ops_unregister();
2956 }
2957
2958 static const struct of_device_id qcom_scm_dt_match[] = {
2959 { .compatible = "qcom,scm" },
2960
2961 /* Legacy entries kept for backwards compatibility */
2962 { .compatible = "qcom,scm-apq8064" },
2963 { .compatible = "qcom,scm-apq8084" },
2964 { .compatible = "qcom,scm-ipq4019" },
2965 { .compatible = "qcom,scm-msm8953" },
2966 { .compatible = "qcom,scm-msm8974" },
2967 { .compatible = "qcom,scm-msm8996" },
2968 {}
2969 };
2970 MODULE_DEVICE_TABLE(of, qcom_scm_dt_match);
2971
2972 static struct platform_driver qcom_scm_driver = {
2973 .driver = {
2974 .name = "qcom_scm",
2975 .of_match_table = qcom_scm_dt_match,
2976 .suppress_bind_attrs = true,
2977 },
2978 .probe = qcom_scm_probe,
2979 .shutdown = qcom_scm_shutdown,
2980 };
2981
qcom_scm_init(void)2982 static int __init qcom_scm_init(void)
2983 {
2984 return platform_driver_register(&qcom_scm_driver);
2985 }
2986 subsys_initcall(qcom_scm_init);
2987
2988 MODULE_DESCRIPTION("Qualcomm Technologies, Inc. SCM driver");
2989 MODULE_LICENSE("GPL v2");
2990