1*91f16700Schasinglulu /* 2*91f16700Schasinglulu * Copyright (c) 2020-2022, Arm Limited. All rights reserved. 3*91f16700Schasinglulu * 4*91f16700Schasinglulu * SPDX-License-Identifier: BSD-3-Clause 5*91f16700Schasinglulu */ 6*91f16700Schasinglulu 7*91f16700Schasinglulu #include <assert.h> 8*91f16700Schasinglulu #include <errno.h> 9*91f16700Schasinglulu #include <string.h> 10*91f16700Schasinglulu #include <arch_helpers.h> 11*91f16700Schasinglulu 12*91f16700Schasinglulu #include <common/bl_common.h> 13*91f16700Schasinglulu #include <common/debug.h> 14*91f16700Schasinglulu #include <drivers/auth/crypto_mod.h> 15*91f16700Schasinglulu #include <drivers/measured_boot/event_log/event_log.h> 16*91f16700Schasinglulu 17*91f16700Schasinglulu #if TPM_ALG_ID == TPM_ALG_SHA512 18*91f16700Schasinglulu #define CRYPTO_MD_ID CRYPTO_MD_SHA512 19*91f16700Schasinglulu #elif TPM_ALG_ID == TPM_ALG_SHA384 20*91f16700Schasinglulu #define CRYPTO_MD_ID CRYPTO_MD_SHA384 21*91f16700Schasinglulu #elif TPM_ALG_ID == TPM_ALG_SHA256 22*91f16700Schasinglulu #define CRYPTO_MD_ID CRYPTO_MD_SHA256 23*91f16700Schasinglulu #else 24*91f16700Schasinglulu # error Invalid TPM algorithm. 25*91f16700Schasinglulu #endif /* TPM_ALG_ID */ 26*91f16700Schasinglulu 27*91f16700Schasinglulu /* Running Event Log Pointer */ 28*91f16700Schasinglulu static uint8_t *log_ptr; 29*91f16700Schasinglulu 30*91f16700Schasinglulu /* Pointer to the first byte past end of the Event Log buffer */ 31*91f16700Schasinglulu static uintptr_t log_end; 32*91f16700Schasinglulu 33*91f16700Schasinglulu /* TCG_EfiSpecIdEvent */ 34*91f16700Schasinglulu static const id_event_headers_t id_event_header = { 35*91f16700Schasinglulu .header = { 36*91f16700Schasinglulu .pcr_index = PCR_0, 37*91f16700Schasinglulu .event_type = EV_NO_ACTION, 38*91f16700Schasinglulu .digest = {0}, 39*91f16700Schasinglulu .event_size = (uint32_t)(sizeof(id_event_struct_t) + 40*91f16700Schasinglulu (sizeof(id_event_algorithm_size_t) * 41*91f16700Schasinglulu HASH_ALG_COUNT)) 42*91f16700Schasinglulu }, 43*91f16700Schasinglulu 44*91f16700Schasinglulu .struct_header = { 45*91f16700Schasinglulu .signature = TCG_ID_EVENT_SIGNATURE_03, 46*91f16700Schasinglulu .platform_class = PLATFORM_CLASS_CLIENT, 47*91f16700Schasinglulu .spec_version_minor = TCG_SPEC_VERSION_MINOR_TPM2, 48*91f16700Schasinglulu .spec_version_major = TCG_SPEC_VERSION_MAJOR_TPM2, 49*91f16700Schasinglulu .spec_errata = TCG_SPEC_ERRATA_TPM2, 50*91f16700Schasinglulu .uintn_size = (uint8_t)(sizeof(unsigned int) / 51*91f16700Schasinglulu sizeof(uint32_t)), 52*91f16700Schasinglulu .number_of_algorithms = HASH_ALG_COUNT 53*91f16700Schasinglulu } 54*91f16700Schasinglulu }; 55*91f16700Schasinglulu 56*91f16700Schasinglulu static const event2_header_t locality_event_header = { 57*91f16700Schasinglulu /* 58*91f16700Schasinglulu * All EV_NO_ACTION events SHALL set 59*91f16700Schasinglulu * TCG_PCR_EVENT2.pcrIndex = 0, unless otherwise specified 60*91f16700Schasinglulu */ 61*91f16700Schasinglulu .pcr_index = PCR_0, 62*91f16700Schasinglulu 63*91f16700Schasinglulu /* 64*91f16700Schasinglulu * All EV_NO_ACTION events SHALL set 65*91f16700Schasinglulu * TCG_PCR_EVENT2.eventType = 03h 66*91f16700Schasinglulu */ 67*91f16700Schasinglulu .event_type = EV_NO_ACTION, 68*91f16700Schasinglulu 69*91f16700Schasinglulu /* 70*91f16700Schasinglulu * All EV_NO_ACTION events SHALL set TCG_PCR_EVENT2.digests to all 71*91f16700Schasinglulu * 0x00's for each allocated Hash algorithm 72*91f16700Schasinglulu */ 73*91f16700Schasinglulu .digests = { 74*91f16700Schasinglulu .count = HASH_ALG_COUNT 75*91f16700Schasinglulu } 76*91f16700Schasinglulu }; 77*91f16700Schasinglulu 78*91f16700Schasinglulu /* 79*91f16700Schasinglulu * Record a measurement as a TCG_PCR_EVENT2 event 80*91f16700Schasinglulu * 81*91f16700Schasinglulu * @param[in] hash Pointer to hash data of TCG_DIGEST_SIZE bytes 82*91f16700Schasinglulu * @param[in] event_type Type of Event, Various Event Types are 83*91f16700Schasinglulu * mentioned in tcg.h header 84*91f16700Schasinglulu * @param[in] metadata_ptr Pointer to event_log_metadata_t structure 85*91f16700Schasinglulu * 86*91f16700Schasinglulu * There must be room for storing this new event into the event log buffer. 87*91f16700Schasinglulu */ 88*91f16700Schasinglulu void event_log_record(const uint8_t *hash, uint32_t event_type, 89*91f16700Schasinglulu const event_log_metadata_t *metadata_ptr) 90*91f16700Schasinglulu { 91*91f16700Schasinglulu void *ptr = log_ptr; 92*91f16700Schasinglulu uint32_t name_len = 0U; 93*91f16700Schasinglulu 94*91f16700Schasinglulu assert(hash != NULL); 95*91f16700Schasinglulu assert(metadata_ptr != NULL); 96*91f16700Schasinglulu /* event_log_buf_init() must have been called prior to this. */ 97*91f16700Schasinglulu assert(log_ptr != NULL); 98*91f16700Schasinglulu 99*91f16700Schasinglulu if (metadata_ptr->name != NULL) { 100*91f16700Schasinglulu name_len = (uint32_t)strlen(metadata_ptr->name) + 1U; 101*91f16700Schasinglulu } 102*91f16700Schasinglulu 103*91f16700Schasinglulu /* Check for space in Event Log buffer */ 104*91f16700Schasinglulu assert(((uintptr_t)ptr + (uint32_t)EVENT2_HDR_SIZE + name_len) < 105*91f16700Schasinglulu log_end); 106*91f16700Schasinglulu 107*91f16700Schasinglulu /* 108*91f16700Schasinglulu * As per TCG specifications, firmware components that are measured 109*91f16700Schasinglulu * into PCR[0] must be logged in the event log using the event type 110*91f16700Schasinglulu * EV_POST_CODE. 111*91f16700Schasinglulu */ 112*91f16700Schasinglulu /* TCG_PCR_EVENT2.PCRIndex */ 113*91f16700Schasinglulu ((event2_header_t *)ptr)->pcr_index = metadata_ptr->pcr; 114*91f16700Schasinglulu 115*91f16700Schasinglulu /* TCG_PCR_EVENT2.EventType */ 116*91f16700Schasinglulu ((event2_header_t *)ptr)->event_type = event_type; 117*91f16700Schasinglulu 118*91f16700Schasinglulu /* TCG_PCR_EVENT2.Digests.Count */ 119*91f16700Schasinglulu ptr = (uint8_t *)ptr + offsetof(event2_header_t, digests); 120*91f16700Schasinglulu ((tpml_digest_values *)ptr)->count = HASH_ALG_COUNT; 121*91f16700Schasinglulu 122*91f16700Schasinglulu /* TCG_PCR_EVENT2.Digests[] */ 123*91f16700Schasinglulu ptr = (uint8_t *)((uintptr_t)ptr + 124*91f16700Schasinglulu offsetof(tpml_digest_values, digests)); 125*91f16700Schasinglulu 126*91f16700Schasinglulu /* TCG_PCR_EVENT2.Digests[].AlgorithmId */ 127*91f16700Schasinglulu ((tpmt_ha *)ptr)->algorithm_id = TPM_ALG_ID; 128*91f16700Schasinglulu 129*91f16700Schasinglulu /* TCG_PCR_EVENT2.Digests[].Digest[] */ 130*91f16700Schasinglulu ptr = (uint8_t *)((uintptr_t)ptr + offsetof(tpmt_ha, digest)); 131*91f16700Schasinglulu 132*91f16700Schasinglulu /* Copy digest */ 133*91f16700Schasinglulu (void)memcpy(ptr, (const void *)hash, TCG_DIGEST_SIZE); 134*91f16700Schasinglulu 135*91f16700Schasinglulu /* TCG_PCR_EVENT2.EventSize */ 136*91f16700Schasinglulu ptr = (uint8_t *)((uintptr_t)ptr + TCG_DIGEST_SIZE); 137*91f16700Schasinglulu ((event2_data_t *)ptr)->event_size = name_len; 138*91f16700Schasinglulu 139*91f16700Schasinglulu /* Copy event data to TCG_PCR_EVENT2.Event */ 140*91f16700Schasinglulu if (metadata_ptr->name != NULL) { 141*91f16700Schasinglulu (void)memcpy((void *)(((event2_data_t *)ptr)->event), 142*91f16700Schasinglulu (const void *)metadata_ptr->name, name_len); 143*91f16700Schasinglulu } 144*91f16700Schasinglulu 145*91f16700Schasinglulu /* End of event data */ 146*91f16700Schasinglulu log_ptr = (uint8_t *)((uintptr_t)ptr + 147*91f16700Schasinglulu offsetof(event2_data_t, event) + name_len); 148*91f16700Schasinglulu } 149*91f16700Schasinglulu 150*91f16700Schasinglulu void event_log_buf_init(uint8_t *event_log_start, uint8_t *event_log_finish) 151*91f16700Schasinglulu { 152*91f16700Schasinglulu assert(event_log_start != NULL); 153*91f16700Schasinglulu assert(event_log_finish > event_log_start); 154*91f16700Schasinglulu 155*91f16700Schasinglulu log_ptr = event_log_start; 156*91f16700Schasinglulu log_end = (uintptr_t)event_log_finish; 157*91f16700Schasinglulu } 158*91f16700Schasinglulu 159*91f16700Schasinglulu /* 160*91f16700Schasinglulu * Initialise Event Log global variables, used during the recording 161*91f16700Schasinglulu * of various payload measurements into the Event Log buffer 162*91f16700Schasinglulu * 163*91f16700Schasinglulu * @param[in] event_log_start Base address of Event Log buffer 164*91f16700Schasinglulu * @param[in] event_log_finish End address of Event Log buffer, 165*91f16700Schasinglulu * it is a first byte past end of the 166*91f16700Schasinglulu * buffer 167*91f16700Schasinglulu */ 168*91f16700Schasinglulu void event_log_init(uint8_t *event_log_start, uint8_t *event_log_finish) 169*91f16700Schasinglulu { 170*91f16700Schasinglulu event_log_buf_init(event_log_start, event_log_finish); 171*91f16700Schasinglulu } 172*91f16700Schasinglulu 173*91f16700Schasinglulu void event_log_write_specid_event(void) 174*91f16700Schasinglulu { 175*91f16700Schasinglulu void *ptr = log_ptr; 176*91f16700Schasinglulu 177*91f16700Schasinglulu /* event_log_buf_init() must have been called prior to this. */ 178*91f16700Schasinglulu assert(log_ptr != NULL); 179*91f16700Schasinglulu assert(((uintptr_t)log_ptr + ID_EVENT_SIZE) < log_end); 180*91f16700Schasinglulu 181*91f16700Schasinglulu /* 182*91f16700Schasinglulu * Add Specification ID Event first 183*91f16700Schasinglulu * 184*91f16700Schasinglulu * Copy TCG_EfiSpecIDEventStruct structure header 185*91f16700Schasinglulu */ 186*91f16700Schasinglulu (void)memcpy(ptr, (const void *)&id_event_header, 187*91f16700Schasinglulu sizeof(id_event_header)); 188*91f16700Schasinglulu ptr = (uint8_t *)((uintptr_t)ptr + sizeof(id_event_header)); 189*91f16700Schasinglulu 190*91f16700Schasinglulu /* TCG_EfiSpecIdEventAlgorithmSize structure */ 191*91f16700Schasinglulu ((id_event_algorithm_size_t *)ptr)->algorithm_id = TPM_ALG_ID; 192*91f16700Schasinglulu ((id_event_algorithm_size_t *)ptr)->digest_size = TCG_DIGEST_SIZE; 193*91f16700Schasinglulu ptr = (uint8_t *)((uintptr_t)ptr + sizeof(id_event_algorithm_size_t)); 194*91f16700Schasinglulu 195*91f16700Schasinglulu /* 196*91f16700Schasinglulu * TCG_EfiSpecIDEventStruct.vendorInfoSize 197*91f16700Schasinglulu * No vendor data 198*91f16700Schasinglulu */ 199*91f16700Schasinglulu ((id_event_struct_data_t *)ptr)->vendor_info_size = 0; 200*91f16700Schasinglulu log_ptr = (uint8_t *)((uintptr_t)ptr + 201*91f16700Schasinglulu offsetof(id_event_struct_data_t, vendor_info)); 202*91f16700Schasinglulu } 203*91f16700Schasinglulu 204*91f16700Schasinglulu /* 205*91f16700Schasinglulu * Initialises Event Log by writing Specification ID and 206*91f16700Schasinglulu * Startup Locality events 207*91f16700Schasinglulu */ 208*91f16700Schasinglulu void event_log_write_header(void) 209*91f16700Schasinglulu { 210*91f16700Schasinglulu const char locality_signature[] = TCG_STARTUP_LOCALITY_SIGNATURE; 211*91f16700Schasinglulu void *ptr; 212*91f16700Schasinglulu 213*91f16700Schasinglulu event_log_write_specid_event(); 214*91f16700Schasinglulu 215*91f16700Schasinglulu ptr = log_ptr; 216*91f16700Schasinglulu assert(((uintptr_t)log_ptr + LOC_EVENT_SIZE) < log_end); 217*91f16700Schasinglulu 218*91f16700Schasinglulu /* 219*91f16700Schasinglulu * The Startup Locality event should be placed in the log before 220*91f16700Schasinglulu * any event which extends PCR[0]. 221*91f16700Schasinglulu * 222*91f16700Schasinglulu * Ref. TCG PC Client Platform Firmware Profile 9.4.5.3 223*91f16700Schasinglulu */ 224*91f16700Schasinglulu 225*91f16700Schasinglulu /* Copy Startup Locality Event Header */ 226*91f16700Schasinglulu (void)memcpy(ptr, (const void *)&locality_event_header, 227*91f16700Schasinglulu sizeof(locality_event_header)); 228*91f16700Schasinglulu ptr = (uint8_t *)((uintptr_t)ptr + sizeof(locality_event_header)); 229*91f16700Schasinglulu 230*91f16700Schasinglulu /* TCG_PCR_EVENT2.Digests[].AlgorithmId */ 231*91f16700Schasinglulu ((tpmt_ha *)ptr)->algorithm_id = TPM_ALG_ID; 232*91f16700Schasinglulu 233*91f16700Schasinglulu /* TCG_PCR_EVENT2.Digests[].Digest[] */ 234*91f16700Schasinglulu (void)memset(&((tpmt_ha *)ptr)->digest, 0, TCG_DIGEST_SIZE); 235*91f16700Schasinglulu ptr = (uint8_t *)((uintptr_t)ptr + 236*91f16700Schasinglulu offsetof(tpmt_ha, digest) + TCG_DIGEST_SIZE); 237*91f16700Schasinglulu 238*91f16700Schasinglulu /* TCG_PCR_EVENT2.EventSize */ 239*91f16700Schasinglulu ((event2_data_t *)ptr)->event_size = 240*91f16700Schasinglulu (uint32_t)sizeof(startup_locality_event_t); 241*91f16700Schasinglulu ptr = (uint8_t *)((uintptr_t)ptr + offsetof(event2_data_t, event)); 242*91f16700Schasinglulu 243*91f16700Schasinglulu /* TCG_EfiStartupLocalityEvent.Signature */ 244*91f16700Schasinglulu (void)memcpy(ptr, (const void *)locality_signature, 245*91f16700Schasinglulu sizeof(TCG_STARTUP_LOCALITY_SIGNATURE)); 246*91f16700Schasinglulu 247*91f16700Schasinglulu /* 248*91f16700Schasinglulu * TCG_EfiStartupLocalityEvent.StartupLocality = 0: 249*91f16700Schasinglulu * the platform's boot firmware 250*91f16700Schasinglulu */ 251*91f16700Schasinglulu ((startup_locality_event_t *)ptr)->startup_locality = 0U; 252*91f16700Schasinglulu log_ptr = (uint8_t *)((uintptr_t)ptr + sizeof(startup_locality_event_t)); 253*91f16700Schasinglulu } 254*91f16700Schasinglulu 255*91f16700Schasinglulu int event_log_measure(uintptr_t data_base, uint32_t data_size, 256*91f16700Schasinglulu unsigned char hash_data[CRYPTO_MD_MAX_SIZE]) 257*91f16700Schasinglulu { 258*91f16700Schasinglulu /* Calculate hash */ 259*91f16700Schasinglulu return crypto_mod_calc_hash(CRYPTO_MD_ID, 260*91f16700Schasinglulu (void *)data_base, data_size, hash_data); 261*91f16700Schasinglulu } 262*91f16700Schasinglulu 263*91f16700Schasinglulu /* 264*91f16700Schasinglulu * Calculate and write hash of image, configuration data, etc. 265*91f16700Schasinglulu * to Event Log. 266*91f16700Schasinglulu * 267*91f16700Schasinglulu * @param[in] data_base Address of data 268*91f16700Schasinglulu * @param[in] data_size Size of data 269*91f16700Schasinglulu * @param[in] data_id Data ID 270*91f16700Schasinglulu * @param[in] metadata_ptr Event Log metadata 271*91f16700Schasinglulu * @return: 272*91f16700Schasinglulu * 0 = success 273*91f16700Schasinglulu * < 0 = error 274*91f16700Schasinglulu */ 275*91f16700Schasinglulu int event_log_measure_and_record(uintptr_t data_base, uint32_t data_size, 276*91f16700Schasinglulu uint32_t data_id, 277*91f16700Schasinglulu const event_log_metadata_t *metadata_ptr) 278*91f16700Schasinglulu { 279*91f16700Schasinglulu unsigned char hash_data[CRYPTO_MD_MAX_SIZE]; 280*91f16700Schasinglulu int rc; 281*91f16700Schasinglulu 282*91f16700Schasinglulu assert(metadata_ptr != NULL); 283*91f16700Schasinglulu 284*91f16700Schasinglulu /* Get the metadata associated with this image. */ 285*91f16700Schasinglulu while ((metadata_ptr->id != EVLOG_INVALID_ID) && 286*91f16700Schasinglulu (metadata_ptr->id != data_id)) { 287*91f16700Schasinglulu metadata_ptr++; 288*91f16700Schasinglulu } 289*91f16700Schasinglulu assert(metadata_ptr->id != EVLOG_INVALID_ID); 290*91f16700Schasinglulu 291*91f16700Schasinglulu /* Measure the payload with algorithm selected by EventLog driver */ 292*91f16700Schasinglulu rc = event_log_measure(data_base, data_size, hash_data); 293*91f16700Schasinglulu if (rc != 0) { 294*91f16700Schasinglulu return rc; 295*91f16700Schasinglulu } 296*91f16700Schasinglulu 297*91f16700Schasinglulu event_log_record(hash_data, EV_POST_CODE, metadata_ptr); 298*91f16700Schasinglulu 299*91f16700Schasinglulu return 0; 300*91f16700Schasinglulu } 301*91f16700Schasinglulu 302*91f16700Schasinglulu /* 303*91f16700Schasinglulu * Get current Event Log buffer size i.e. used space of Event Log buffer 304*91f16700Schasinglulu * 305*91f16700Schasinglulu * @param[in] event_log_start Base Pointer to Event Log buffer 306*91f16700Schasinglulu * 307*91f16700Schasinglulu * @return: current Size of Event Log buffer 308*91f16700Schasinglulu */ 309*91f16700Schasinglulu size_t event_log_get_cur_size(uint8_t *event_log_start) 310*91f16700Schasinglulu { 311*91f16700Schasinglulu assert(event_log_start != NULL); 312*91f16700Schasinglulu assert(log_ptr >= event_log_start); 313*91f16700Schasinglulu 314*91f16700Schasinglulu return (size_t)((uintptr_t)log_ptr - (uintptr_t)event_log_start); 315*91f16700Schasinglulu } 316