1*91f16700Schasinglulu /* 2*91f16700Schasinglulu * Copyright (c) 2020-2022, Arm Limited. All rights reserved. 3*91f16700Schasinglulu * 4*91f16700Schasinglulu * SPDX-License-Identifier: BSD-3-Clause 5*91f16700Schasinglulu */ 6*91f16700Schasinglulu 7*91f16700Schasinglulu #ifndef EVENT_LOG_H 8*91f16700Schasinglulu #define EVENT_LOG_H 9*91f16700Schasinglulu 10*91f16700Schasinglulu #include <stdint.h> 11*91f16700Schasinglulu 12*91f16700Schasinglulu #include <common/debug.h> 13*91f16700Schasinglulu #include <common/tbbr/tbbr_img_def.h> 14*91f16700Schasinglulu #include <drivers/auth/crypto_mod.h> 15*91f16700Schasinglulu #include <drivers/measured_boot/event_log/tcg.h> 16*91f16700Schasinglulu 17*91f16700Schasinglulu /* 18*91f16700Schasinglulu * Set Event Log debug level to one of: 19*91f16700Schasinglulu * 20*91f16700Schasinglulu * LOG_LEVEL_ERROR 21*91f16700Schasinglulu * LOG_LEVEL_INFO 22*91f16700Schasinglulu * LOG_LEVEL_WARNING 23*91f16700Schasinglulu * LOG_LEVEL_VERBOSE 24*91f16700Schasinglulu */ 25*91f16700Schasinglulu #if EVENT_LOG_LEVEL == LOG_LEVEL_ERROR 26*91f16700Schasinglulu #define LOG_EVENT ERROR 27*91f16700Schasinglulu #elif EVENT_LOG_LEVEL == LOG_LEVEL_NOTICE 28*91f16700Schasinglulu #define LOG_EVENT NOTICE 29*91f16700Schasinglulu #elif EVENT_LOG_LEVEL == LOG_LEVEL_WARNING 30*91f16700Schasinglulu #define LOG_EVENT WARN 31*91f16700Schasinglulu #elif EVENT_LOG_LEVEL == LOG_LEVEL_INFO 32*91f16700Schasinglulu #define LOG_EVENT INFO 33*91f16700Schasinglulu #elif EVENT_LOG_LEVEL == LOG_LEVEL_VERBOSE 34*91f16700Schasinglulu #define LOG_EVENT VERBOSE 35*91f16700Schasinglulu #else 36*91f16700Schasinglulu #error "Not supported EVENT_LOG_LEVEL" 37*91f16700Schasinglulu #endif 38*91f16700Schasinglulu 39*91f16700Schasinglulu /* Number of hashing algorithms supported */ 40*91f16700Schasinglulu #define HASH_ALG_COUNT 1U 41*91f16700Schasinglulu 42*91f16700Schasinglulu #define EVLOG_INVALID_ID UINT32_MAX 43*91f16700Schasinglulu 44*91f16700Schasinglulu #define MEMBER_SIZE(type, member) sizeof(((type *)0)->member) 45*91f16700Schasinglulu 46*91f16700Schasinglulu /* 47*91f16700Schasinglulu * Each event log entry has some metadata (i.e. a string) that identifies 48*91f16700Schasinglulu * what is measured.These macros define these strings. 49*91f16700Schasinglulu * Note that these strings follow the standardization recommendations 50*91f16700Schasinglulu * defined in the Arm Server Base Security Guide (a.k.a. SBSG, Arm DEN 0086), 51*91f16700Schasinglulu * where applicable. They should not be changed in the code. 52*91f16700Schasinglulu * Where the SBSG does not make recommendations, we are free to choose any 53*91f16700Schasinglulu * naming convention. 54*91f16700Schasinglulu * The key thing is to choose meaningful strings so that when the TPM event 55*91f16700Schasinglulu * log is used in attestation, the different components can be identified. 56*91f16700Schasinglulu */ 57*91f16700Schasinglulu #define EVLOG_BL2_STRING "BL_2" 58*91f16700Schasinglulu #define EVLOG_BL31_STRING "SECURE_RT_EL3" 59*91f16700Schasinglulu #if defined(SPD_opteed) 60*91f16700Schasinglulu #define EVLOG_BL32_STRING "SECURE_RT_EL1_OPTEE" 61*91f16700Schasinglulu #elif defined(SPD_tspd) 62*91f16700Schasinglulu #define EVLOG_BL32_STRING "SECURE_RT_EL1_TSPD" 63*91f16700Schasinglulu #elif defined(SPD_tlkd) 64*91f16700Schasinglulu #define EVLOG_BL32_STRING "SECURE_RT_EL1_TLKD" 65*91f16700Schasinglulu #elif defined(SPD_trusty) 66*91f16700Schasinglulu #define EVLOG_BL32_STRING "SECURE_RT_EL1_TRUSTY" 67*91f16700Schasinglulu #else 68*91f16700Schasinglulu #define EVLOG_BL32_STRING "SECURE_RT_EL1_UNKNOWN" 69*91f16700Schasinglulu #endif 70*91f16700Schasinglulu #define EVLOG_BL32_EXTRA1_STRING "SECURE_RT_EL1_OPTEE_EXTRA1" 71*91f16700Schasinglulu #define EVLOG_BL32_EXTRA2_STRING "SECURE_RT_EL1_OPTEE_EXTRA2" 72*91f16700Schasinglulu #define EVLOG_BL33_STRING "BL_33" 73*91f16700Schasinglulu #define EVLOG_FW_CONFIG_STRING "FW_CONFIG" 74*91f16700Schasinglulu #define EVLOG_HW_CONFIG_STRING "HW_CONFIG" 75*91f16700Schasinglulu #define EVLOG_NT_FW_CONFIG_STRING "NT_FW_CONFIG" 76*91f16700Schasinglulu #define EVLOG_SCP_BL2_STRING "SYS_CTRL_2" 77*91f16700Schasinglulu #define EVLOG_SOC_FW_CONFIG_STRING "SOC_FW_CONFIG" 78*91f16700Schasinglulu #define EVLOG_STM32_STRING "STM32" 79*91f16700Schasinglulu #define EVLOG_TB_FW_CONFIG_STRING "TB_FW_CONFIG" 80*91f16700Schasinglulu #define EVLOG_TOS_FW_CONFIG_STRING "TOS_FW_CONFIG" 81*91f16700Schasinglulu #define EVLOG_RMM_STRING "RMM" 82*91f16700Schasinglulu #define EVLOG_SP1_STRING "SP1" 83*91f16700Schasinglulu #define EVLOG_SP2_STRING "SP2" 84*91f16700Schasinglulu #define EVLOG_SP3_STRING "SP3" 85*91f16700Schasinglulu #define EVLOG_SP4_STRING "SP4" 86*91f16700Schasinglulu #define EVLOG_SP5_STRING "SP5" 87*91f16700Schasinglulu #define EVLOG_SP6_STRING "SP6" 88*91f16700Schasinglulu #define EVLOG_SP7_STRING "SP7" 89*91f16700Schasinglulu #define EVLOG_SP8_STRING "SP8" 90*91f16700Schasinglulu 91*91f16700Schasinglulu typedef struct { 92*91f16700Schasinglulu unsigned int id; 93*91f16700Schasinglulu const char *name; 94*91f16700Schasinglulu unsigned int pcr; 95*91f16700Schasinglulu } event_log_metadata_t; 96*91f16700Schasinglulu 97*91f16700Schasinglulu #define ID_EVENT_SIZE (sizeof(id_event_headers_t) + \ 98*91f16700Schasinglulu (sizeof(id_event_algorithm_size_t) * HASH_ALG_COUNT) + \ 99*91f16700Schasinglulu sizeof(id_event_struct_data_t)) 100*91f16700Schasinglulu 101*91f16700Schasinglulu #define LOC_EVENT_SIZE (sizeof(event2_header_t) + \ 102*91f16700Schasinglulu sizeof(tpmt_ha) + TCG_DIGEST_SIZE + \ 103*91f16700Schasinglulu sizeof(event2_data_t) + \ 104*91f16700Schasinglulu sizeof(startup_locality_event_t)) 105*91f16700Schasinglulu 106*91f16700Schasinglulu #define LOG_MIN_SIZE (ID_EVENT_SIZE + LOC_EVENT_SIZE) 107*91f16700Schasinglulu 108*91f16700Schasinglulu #define EVENT2_HDR_SIZE (sizeof(event2_header_t) + \ 109*91f16700Schasinglulu sizeof(tpmt_ha) + TCG_DIGEST_SIZE + \ 110*91f16700Schasinglulu sizeof(event2_data_t)) 111*91f16700Schasinglulu 112*91f16700Schasinglulu /* Functions' declarations */ 113*91f16700Schasinglulu void event_log_buf_init(uint8_t *event_log_start, uint8_t *event_log_finish); 114*91f16700Schasinglulu void event_log_init(uint8_t *event_log_start, uint8_t *event_log_finish); 115*91f16700Schasinglulu void event_log_write_specid_event(void); 116*91f16700Schasinglulu void event_log_write_header(void); 117*91f16700Schasinglulu void dump_event_log(uint8_t *log_addr, size_t log_size); 118*91f16700Schasinglulu int event_log_measure(uintptr_t data_base, uint32_t data_size, 119*91f16700Schasinglulu unsigned char hash_data[CRYPTO_MD_MAX_SIZE]); 120*91f16700Schasinglulu void event_log_record(const uint8_t *hash, uint32_t event_type, 121*91f16700Schasinglulu const event_log_metadata_t *metadata_ptr); 122*91f16700Schasinglulu int event_log_measure_and_record(uintptr_t data_base, uint32_t data_size, 123*91f16700Schasinglulu uint32_t data_id, 124*91f16700Schasinglulu const event_log_metadata_t *metadata_ptr); 125*91f16700Schasinglulu size_t event_log_get_cur_size(uint8_t *event_log_start); 126*91f16700Schasinglulu 127*91f16700Schasinglulu #endif /* EVENT_LOG_H */ 128