2 * Copyright (C) 2005, 2006 IBM Corporation
5 * Leendert van Doorn <leendert@watson.ibm.com>
6 * Kylene Hall <kjhall@us.ibm.com>
8 * Device driver for TCG/TCPA TPM (trusted platform module).
9 * Specifications at www.trustedcomputinggroup.org
11 * This device driver implements the TPM interface as defined in
12 * the TCG TPM Interface Spec version 1.2, revision 1.0.
14 * This program is free software; you can redistribute it and/or
15 * modify it under the terms of the GNU General Public License as
16 * published by the Free Software Foundation, version 2 of the
19 #include <linux/init.h>
20 #include <linux/module.h>
21 #include <linux/moduleparam.h>
22 #include <linux/pnp.h>
23 #include <linux/interrupt.h>
24 #include <linux/wait.h>
27 #define TPM_HEADER_SIZE 10
30 TPM_ACCESS_VALID = 0x80,
31 TPM_ACCESS_ACTIVE_LOCALITY = 0x20,
32 TPM_ACCESS_REQUEST_PENDING = 0x04,
33 TPM_ACCESS_REQUEST_USE = 0x02,
38 TPM_STS_COMMAND_READY = 0x40,
40 TPM_STS_DATA_AVAIL = 0x10,
41 TPM_STS_DATA_EXPECT = 0x08,
45 TPM_GLOBAL_INT_ENABLE = 0x80000000,
46 TPM_INTF_BURST_COUNT_STATIC = 0x100,
47 TPM_INTF_CMD_READY_INT = 0x080,
48 TPM_INTF_INT_EDGE_FALLING = 0x040,
49 TPM_INTF_INT_EDGE_RISING = 0x020,
50 TPM_INTF_INT_LEVEL_LOW = 0x010,
51 TPM_INTF_INT_LEVEL_HIGH = 0x008,
52 TPM_INTF_LOCALITY_CHANGE_INT = 0x004,
53 TPM_INTF_STS_VALID_INT = 0x002,
54 TPM_INTF_DATA_AVAIL_INT = 0x001,
58 TIS_MEM_BASE = 0xFED40000,
60 TIS_SHORT_TIMEOUT = 750, /* ms */
61 TIS_LONG_TIMEOUT = 2000, /* 2 sec */
64 #define TPM_ACCESS(l) (0x0000 | ((l) << 12))
65 #define TPM_INT_ENABLE(l) (0x0008 | ((l) << 12))
66 #define TPM_INT_VECTOR(l) (0x000C | ((l) << 12))
67 #define TPM_INT_STATUS(l) (0x0010 | ((l) << 12))
68 #define TPM_INTF_CAPS(l) (0x0014 | ((l) << 12))
69 #define TPM_STS(l) (0x0018 | ((l) << 12))
70 #define TPM_DATA_FIFO(l) (0x0024 | ((l) << 12))
72 #define TPM_DID_VID(l) (0x0F00 | ((l) << 12))
73 #define TPM_RID(l) (0x0F04 | ((l) << 12))
75 static LIST_HEAD(tis_chips);
76 static DEFINE_SPINLOCK(tis_lock);
78 static int check_locality(struct tpm_chip *chip, int l)
80 if ((ioread8(chip->vendor.iobase + TPM_ACCESS(l)) &
81 (TPM_ACCESS_ACTIVE_LOCALITY | TPM_ACCESS_VALID)) ==
82 (TPM_ACCESS_ACTIVE_LOCALITY | TPM_ACCESS_VALID))
83 return chip->vendor.locality = l;
88 static void release_locality(struct tpm_chip *chip, int l, int force)
90 if (force || (ioread8(chip->vendor.iobase + TPM_ACCESS(l)) &
91 (TPM_ACCESS_REQUEST_PENDING | TPM_ACCESS_VALID)) ==
92 (TPM_ACCESS_REQUEST_PENDING | TPM_ACCESS_VALID))
93 iowrite8(TPM_ACCESS_ACTIVE_LOCALITY,
94 chip->vendor.iobase + TPM_ACCESS(l));
97 static int request_locality(struct tpm_chip *chip, int l)
102 if (check_locality(chip, l) >= 0)
105 iowrite8(TPM_ACCESS_REQUEST_USE,
106 chip->vendor.iobase + TPM_ACCESS(l));
108 if (chip->vendor.irq) {
109 rc = wait_event_interruptible_timeout(chip->vendor.int_queue,
112 chip->vendor.timeout_a);
117 /* wait for burstcount */
118 stop = jiffies + chip->vendor.timeout_a;
120 if (check_locality(chip, l) >= 0)
124 while (time_before(jiffies, stop));
129 static u8 tpm_tis_status(struct tpm_chip *chip)
131 return ioread8(chip->vendor.iobase +
132 TPM_STS(chip->vendor.locality));
135 static void tpm_tis_ready(struct tpm_chip *chip)
137 /* this causes the current command to be aborted */
138 iowrite8(TPM_STS_COMMAND_READY,
139 chip->vendor.iobase + TPM_STS(chip->vendor.locality));
142 static int get_burstcount(struct tpm_chip *chip)
147 /* wait for burstcount */
148 /* which timeout value, spec has 2 answers (c & d) */
149 stop = jiffies + chip->vendor.timeout_d;
151 burstcnt = ioread8(chip->vendor.iobase +
152 TPM_STS(chip->vendor.locality) + 1);
153 burstcnt += ioread8(chip->vendor.iobase +
154 TPM_STS(chip->vendor.locality) +
159 } while (time_before(jiffies, stop));
163 static int wait_for_stat(struct tpm_chip *chip, u8 mask, unsigned long timeout,
164 wait_queue_head_t *queue)
170 /* check current status */
171 status = tpm_tis_status(chip);
172 if ((status & mask) == mask)
175 if (chip->vendor.irq) {
176 rc = wait_event_interruptible_timeout(*queue,
183 stop = jiffies + timeout;
186 status = tpm_tis_status(chip);
187 if ((status & mask) == mask)
189 } while (time_before(jiffies, stop));
194 static int recv_data(struct tpm_chip *chip, u8 *buf, size_t count)
196 int size = 0, burstcnt;
197 while (size < count &&
199 TPM_STS_DATA_AVAIL | TPM_STS_VALID,
200 chip->vendor.timeout_c,
201 &chip->vendor.read_queue)
203 burstcnt = get_burstcount(chip);
204 for (; burstcnt > 0 && size < count; burstcnt--)
205 buf[size++] = ioread8(chip->vendor.iobase +
206 TPM_DATA_FIFO(chip->vendor.
212 static int tpm_tis_recv(struct tpm_chip *chip, u8 *buf, size_t count)
215 int expected, status;
217 if (count < TPM_HEADER_SIZE) {
222 /* read first 10 bytes, including tag, paramsize, and result */
224 recv_data(chip, buf, TPM_HEADER_SIZE)) < TPM_HEADER_SIZE) {
225 dev_err(chip->dev, "Unable to read header\n");
229 expected = be32_to_cpu(*(__be32 *) (buf + 2));
230 if (expected > count) {
236 recv_data(chip, &buf[TPM_HEADER_SIZE],
237 expected - TPM_HEADER_SIZE)) < expected) {
238 dev_err(chip->dev, "Unable to read remainder of result\n");
243 wait_for_stat(chip, TPM_STS_VALID, chip->vendor.timeout_c,
244 &chip->vendor.int_queue);
245 status = tpm_tis_status(chip);
246 if (status & TPM_STS_DATA_AVAIL) { /* retry? */
247 dev_err(chip->dev, "Error left over data\n");
254 release_locality(chip, chip->vendor.locality, 0);
259 * If interrupts are used (signaled by an irq set in the vendor structure)
260 * tpm.c can skip polling for the data to be available as the interrupt is
263 static int tpm_tis_send(struct tpm_chip *chip, u8 *buf, size_t len)
265 int rc, status, burstcnt;
269 if (request_locality(chip, 0) < 0)
272 status = tpm_tis_status(chip);
273 if ((status & TPM_STS_COMMAND_READY) == 0) {
276 (chip, TPM_STS_COMMAND_READY, chip->vendor.timeout_b,
277 &chip->vendor.int_queue) < 0) {
283 while (count < len - 1) {
284 burstcnt = get_burstcount(chip);
285 for (; burstcnt > 0 && count < len - 1; burstcnt--) {
286 iowrite8(buf[count], chip->vendor.iobase +
287 TPM_DATA_FIFO(chip->vendor.locality));
291 wait_for_stat(chip, TPM_STS_VALID, chip->vendor.timeout_c,
292 &chip->vendor.int_queue);
293 status = tpm_tis_status(chip);
294 if ((status & TPM_STS_DATA_EXPECT) == 0) {
300 /* write last byte */
302 chip->vendor.iobase +
303 TPM_DATA_FIFO(chip->vendor.locality));
304 wait_for_stat(chip, TPM_STS_VALID, chip->vendor.timeout_c,
305 &chip->vendor.int_queue);
306 status = tpm_tis_status(chip);
307 if ((status & TPM_STS_DATA_EXPECT) != 0) {
314 chip->vendor.iobase + TPM_STS(chip->vendor.locality));
316 if (chip->vendor.irq) {
317 ordinal = be32_to_cpu(*((__be32 *) (buf + 6)));
319 (chip, TPM_STS_DATA_AVAIL | TPM_STS_VALID,
320 tpm_calc_ordinal_duration(chip, ordinal),
321 &chip->vendor.read_queue) < 0) {
329 release_locality(chip, chip->vendor.locality, 0);
333 static struct file_operations tis_ops = {
334 .owner = THIS_MODULE,
339 .release = tpm_release,
342 static DEVICE_ATTR(pubek, S_IRUGO, tpm_show_pubek, NULL);
343 static DEVICE_ATTR(pcrs, S_IRUGO, tpm_show_pcrs, NULL);
344 static DEVICE_ATTR(enabled, S_IRUGO, tpm_show_enabled, NULL);
345 static DEVICE_ATTR(active, S_IRUGO, tpm_show_active, NULL);
346 static DEVICE_ATTR(owned, S_IRUGO, tpm_show_owned, NULL);
347 static DEVICE_ATTR(temp_deactivated, S_IRUGO, tpm_show_temp_deactivated,
349 static DEVICE_ATTR(caps, S_IRUGO, tpm_show_caps_1_2, NULL);
350 static DEVICE_ATTR(cancel, S_IWUSR | S_IWGRP, NULL, tpm_store_cancel);
352 static struct attribute *tis_attrs[] = {
353 &dev_attr_pubek.attr,
355 &dev_attr_enabled.attr,
356 &dev_attr_active.attr,
357 &dev_attr_owned.attr,
358 &dev_attr_temp_deactivated.attr,
360 &dev_attr_cancel.attr, NULL,
363 static struct attribute_group tis_attr_grp = {
367 static struct tpm_vendor_specific tpm_tis = {
368 .status = tpm_tis_status,
369 .recv = tpm_tis_recv,
370 .send = tpm_tis_send,
371 .cancel = tpm_tis_ready,
372 .req_complete_mask = TPM_STS_DATA_AVAIL | TPM_STS_VALID,
373 .req_complete_val = TPM_STS_DATA_AVAIL | TPM_STS_VALID,
374 .req_canceled = TPM_STS_COMMAND_READY,
375 .attr_group = &tis_attr_grp,
380 static irqreturn_t tis_int_probe(int irq, void *dev_id, struct pt_regs *regs)
382 struct tpm_chip *chip = (struct tpm_chip *) dev_id;
385 interrupt = ioread32(chip->vendor.iobase +
386 TPM_INT_STATUS(chip->vendor.locality));
391 chip->vendor.irq = irq;
393 /* Clear interrupts handled with TPM_EOI */
395 chip->vendor.iobase +
396 TPM_INT_STATUS(chip->vendor.locality));
400 static irqreturn_t tis_int_handler(int irq, void *dev_id, struct pt_regs *regs)
402 struct tpm_chip *chip = (struct tpm_chip *) dev_id;
406 interrupt = ioread32(chip->vendor.iobase +
407 TPM_INT_STATUS(chip->vendor.locality));
412 if (interrupt & TPM_INTF_DATA_AVAIL_INT)
413 wake_up_interruptible(&chip->vendor.read_queue);
414 if (interrupt & TPM_INTF_LOCALITY_CHANGE_INT)
415 for (i = 0; i < 5; i++)
416 if (check_locality(chip, i) >= 0)
419 (TPM_INTF_LOCALITY_CHANGE_INT | TPM_INTF_STS_VALID_INT |
420 TPM_INTF_CMD_READY_INT))
421 wake_up_interruptible(&chip->vendor.int_queue);
423 /* Clear interrupts handled with TPM_EOI */
425 chip->vendor.iobase +
426 TPM_INT_STATUS(chip->vendor.locality));
430 static int interrupts = 1;
431 module_param(interrupts, bool, 0444);
432 MODULE_PARM_DESC(interrupts, "Enable interrupts");
434 static int __devinit tpm_tis_pnp_init(struct pnp_dev *pnp_dev,
435 const struct pnp_device_id *pnp_id)
437 u32 vendor, intfcaps, intmask;
439 unsigned long start, len;
440 struct tpm_chip *chip;
442 start = pnp_mem_start(pnp_dev, 0);
443 len = pnp_mem_len(pnp_dev, 0);
446 start = TIS_MEM_BASE;
450 if (!(chip = tpm_register_hardware(&pnp_dev->dev, &tpm_tis)))
453 chip->vendor.iobase = ioremap(start, len);
454 if (!chip->vendor.iobase) {
459 vendor = ioread32(chip->vendor.iobase + TPM_DID_VID(0));
461 /* Default timeouts */
462 chip->vendor.timeout_a = msecs_to_jiffies(TIS_SHORT_TIMEOUT);
463 chip->vendor.timeout_b = msecs_to_jiffies(TIS_LONG_TIMEOUT);
464 chip->vendor.timeout_c = msecs_to_jiffies(TIS_SHORT_TIMEOUT);
465 chip->vendor.timeout_d = msecs_to_jiffies(TIS_SHORT_TIMEOUT);
467 dev_info(&pnp_dev->dev,
468 "1.2 TPM (device-id 0x%X, rev-id %d)\n",
469 vendor >> 16, ioread8(chip->vendor.iobase + TPM_RID(0)));
471 /* Figure out the capabilities */
473 ioread32(chip->vendor.iobase +
474 TPM_INTF_CAPS(chip->vendor.locality));
475 dev_dbg(&pnp_dev->dev, "TPM interface capabilities (0x%x):\n",
477 if (intfcaps & TPM_INTF_BURST_COUNT_STATIC)
478 dev_dbg(&pnp_dev->dev, "\tBurst Count Static\n");
479 if (intfcaps & TPM_INTF_CMD_READY_INT)
480 dev_dbg(&pnp_dev->dev, "\tCommand Ready Int Support\n");
481 if (intfcaps & TPM_INTF_INT_EDGE_FALLING)
482 dev_dbg(&pnp_dev->dev, "\tInterrupt Edge Falling\n");
483 if (intfcaps & TPM_INTF_INT_EDGE_RISING)
484 dev_dbg(&pnp_dev->dev, "\tInterrupt Edge Rising\n");
485 if (intfcaps & TPM_INTF_INT_LEVEL_LOW)
486 dev_dbg(&pnp_dev->dev, "\tInterrupt Level Low\n");
487 if (intfcaps & TPM_INTF_INT_LEVEL_HIGH)
488 dev_dbg(&pnp_dev->dev, "\tInterrupt Level High\n");
489 if (intfcaps & TPM_INTF_LOCALITY_CHANGE_INT)
490 dev_dbg(&pnp_dev->dev, "\tLocality Change Int Support\n");
491 if (intfcaps & TPM_INTF_STS_VALID_INT)
492 dev_dbg(&pnp_dev->dev, "\tSts Valid Int Support\n");
493 if (intfcaps & TPM_INTF_DATA_AVAIL_INT)
494 dev_dbg(&pnp_dev->dev, "\tData Avail Int Support\n");
496 if (request_locality(chip, 0) != 0) {
501 /* INTERRUPT Setup */
502 init_waitqueue_head(&chip->vendor.read_queue);
503 init_waitqueue_head(&chip->vendor.int_queue);
506 ioread32(chip->vendor.iobase +
507 TPM_INT_ENABLE(chip->vendor.locality));
509 intmask |= TPM_INTF_CMD_READY_INT
510 | TPM_INTF_LOCALITY_CHANGE_INT | TPM_INTF_DATA_AVAIL_INT
511 | TPM_INTF_STS_VALID_INT;
514 chip->vendor.iobase +
515 TPM_INT_ENABLE(chip->vendor.locality));
518 ioread8(chip->vendor.iobase +
519 TPM_INT_VECTOR(chip->vendor.locality));
521 for (i = 3; i < 16 && chip->vendor.irq == 0; i++) {
522 iowrite8(i, chip->vendor.iobase +
523 TPM_INT_VECTOR(chip->vendor.locality));
525 (i, tis_int_probe, SA_SHIRQ,
526 chip->vendor.miscdev.name, chip) != 0) {
528 "Unable to request irq: %d for probe\n",
533 /* Clear all existing */
535 (chip->vendor.iobase +
536 TPM_INT_STATUS(chip->vendor.locality)),
537 chip->vendor.iobase +
538 TPM_INT_STATUS(chip->vendor.locality));
541 iowrite32(intmask | TPM_GLOBAL_INT_ENABLE,
542 chip->vendor.iobase +
543 TPM_INT_ENABLE(chip->vendor.locality));
545 /* Generate Interrupts */
546 tpm_gen_interrupt(chip);
550 chip->vendor.iobase +
551 TPM_INT_ENABLE(chip->vendor.locality));
555 if (chip->vendor.irq) {
556 iowrite8(chip->vendor.irq,
557 chip->vendor.iobase +
558 TPM_INT_VECTOR(chip->vendor.locality));
560 (chip->vendor.irq, tis_int_handler, SA_SHIRQ,
561 chip->vendor.miscdev.name, chip) != 0) {
563 "Unable to request irq: %d for use\n",
565 chip->vendor.irq = 0;
567 /* Clear all existing */
569 (chip->vendor.iobase +
570 TPM_INT_STATUS(chip->vendor.locality)),
571 chip->vendor.iobase +
572 TPM_INT_STATUS(chip->vendor.locality));
575 iowrite32(intmask | TPM_GLOBAL_INT_ENABLE,
576 chip->vendor.iobase +
577 TPM_INT_ENABLE(chip->vendor.locality));
581 INIT_LIST_HEAD(&chip->vendor.list);
582 spin_lock(&tis_lock);
583 list_add(&chip->vendor.list, &tis_chips);
584 spin_unlock(&tis_lock);
586 tpm_get_timeouts(chip);
587 tpm_continue_selftest(chip);
591 if (chip->vendor.iobase)
592 iounmap(chip->vendor.iobase);
593 tpm_remove_hardware(chip->dev);
597 static int tpm_tis_pnp_suspend(struct pnp_dev *dev, pm_message_t msg)
599 return tpm_pm_suspend(&dev->dev, msg);
602 static int tpm_tis_pnp_resume(struct pnp_dev *dev)
604 return tpm_pm_resume(&dev->dev);
607 static struct pnp_device_id tpm_pnp_tbl[] __devinitdata = {
608 {"PNP0C31", 0}, /* TPM */
609 {"ATM1200", 0}, /* Atmel */
610 {"IFX0102", 0}, /* Infineon */
611 {"BCM0101", 0}, /* Broadcom */
612 {"NSC1200", 0}, /* National */
614 {"", 0}, /* User Specified */
615 {"", 0} /* Terminator */
618 static struct pnp_driver tis_pnp_driver = {
620 .id_table = tpm_pnp_tbl,
621 .probe = tpm_tis_pnp_init,
622 .suspend = tpm_tis_pnp_suspend,
623 .resume = tpm_tis_pnp_resume,
626 #define TIS_HID_USR_IDX sizeof(tpm_pnp_tbl)/sizeof(struct pnp_device_id) -2
627 module_param_string(hid, tpm_pnp_tbl[TIS_HID_USR_IDX].id,
628 sizeof(tpm_pnp_tbl[TIS_HID_USR_IDX].id), 0444);
629 MODULE_PARM_DESC(hid, "Set additional specific HID for this driver to probe");
631 static int __init init_tis(void)
633 return pnp_register_driver(&tis_pnp_driver);
636 static void __exit cleanup_tis(void)
638 struct tpm_vendor_specific *i, *j;
639 struct tpm_chip *chip;
640 spin_lock(&tis_lock);
641 list_for_each_entry_safe(i, j, &tis_chips, list) {
642 chip = to_tpm_chip(i);
643 iowrite32(~TPM_GLOBAL_INT_ENABLE &
644 ioread32(chip->vendor.iobase +
645 TPM_INT_ENABLE(chip->vendor.
647 chip->vendor.iobase +
648 TPM_INT_ENABLE(chip->vendor.locality));
649 release_locality(chip, chip->vendor.locality, 1);
650 if (chip->vendor.irq)
651 free_irq(chip->vendor.irq, chip);
654 tpm_remove_hardware(chip->dev);
656 spin_unlock(&tis_lock);
657 pnp_unregister_driver(&tis_pnp_driver);
660 module_init(init_tis);
661 module_exit(cleanup_tis);
662 MODULE_AUTHOR("Leendert van Doorn (leendert@watson.ibm.com)");
663 MODULE_DESCRIPTION("TPM Driver");
664 MODULE_VERSION("2.0");
665 MODULE_LICENSE("GPL");