1 // SPDX-License-Identifier: GPL-2.0
3 * Copyright 2020 Google Inc.
5 * Based on Infineon TPM driver by Peter Huewe.
7 * cr50 is a firmware for H1 secure modules that requires special
8 * handling for the I2C interface.
10 * - Use an interrupt for transaction status instead of hardcoded delays.
11 * - Must use write+wait+read read protocol.
12 * - All 4 bytes of status register must be read/written at once.
13 * - Burst count max is 63 bytes, and burst count behaves slightly differently
14 * than other I2C TPMs.
15 * - When reading from FIFO the full burstcnt must be read instead of just
16 * reading header and determining the remainder.
19 #include <linux/acpi.h>
20 #include <linux/completion.h>
21 #include <linux/i2c.h>
22 #include <linux/interrupt.h>
23 #include <linux/module.h>
25 #include <linux/slab.h>
26 #include <linux/wait.h>
28 #include "tpm_tis_core.h"
30 #define TPM_CR50_MAX_BUFSIZE 64
31 #define TPM_CR50_TIMEOUT_SHORT_MS 2 /* Short timeout during transactions */
32 #define TPM_CR50_TIMEOUT_NOIRQ_MS 20 /* Timeout for TPM ready without IRQ */
33 #define TPM_CR50_I2C_DID_VID 0x00281ae0L /* Device and vendor ID reg value */
34 #define TPM_CR50_I2C_MAX_RETRIES 3 /* Max retries due to I2C errors */
35 #define TPM_CR50_I2C_RETRY_DELAY_LO 55 /* Min usecs between retries on I2C */
36 #define TPM_CR50_I2C_RETRY_DELAY_HI 65 /* Max usecs between retries on I2C */
38 #define TPM_I2C_ACCESS(l) (0x0000 | ((l) << 4))
39 #define TPM_I2C_STS(l) (0x0001 | ((l) << 4))
40 #define TPM_I2C_DATA_FIFO(l) (0x0005 | ((l) << 4))
41 #define TPM_I2C_DID_VID(l) (0x0006 | ((l) << 4))
44 * struct tpm_i2c_cr50_priv_data - Driver private data.
45 * @irq: Irq number used for this chip.
46 * If irq <= 0, then a fixed timeout is used instead of waiting for irq.
47 * @tpm_ready: Struct used by irq handler to signal R/W readiness.
48 * @buf: Buffer used for i2c writes, with i2c address prepended to content.
50 * Private driver struct used by kernel threads and interrupt context.
52 struct tpm_i2c_cr50_priv_data {
54 struct completion tpm_ready;
55 u8 buf[TPM_CR50_MAX_BUFSIZE];
59 * tpm_cr50_i2c_int_handler() - cr50 interrupt handler.
60 * @dummy: Unused parameter.
61 * @tpm_info: TPM chip information.
63 * The cr50 interrupt handler signals waiting threads that the
64 * interrupt has been asserted. It does not do any interrupt triggered
65 * processing but is instead used to avoid fixed delays.
68 * IRQ_HANDLED signifies irq was handled by this device.
70 static irqreturn_t tpm_cr50_i2c_int_handler(int dummy, void *tpm_info)
72 struct tpm_chip *chip = tpm_info;
73 struct tpm_i2c_cr50_priv_data *priv = dev_get_drvdata(&chip->dev);
75 complete(&priv->tpm_ready);
81 * tpm_cr50_i2c_wait_tpm_ready() - Wait for tpm to signal ready.
84 * Wait for completion interrupt if available, otherwise use a fixed
85 * delay for the TPM to be ready.
89 * - -errno: A POSIX error code.
91 static int tpm_cr50_i2c_wait_tpm_ready(struct tpm_chip *chip)
93 struct tpm_i2c_cr50_priv_data *priv = dev_get_drvdata(&chip->dev);
95 /* Use a safe fixed delay if interrupt is not supported */
97 msleep(TPM_CR50_TIMEOUT_NOIRQ_MS);
101 /* Wait for interrupt to indicate TPM is ready to respond */
102 if (!wait_for_completion_timeout(&priv->tpm_ready,
103 msecs_to_jiffies(chip->timeout_a))) {
104 dev_warn(&chip->dev, "Timeout waiting for TPM ready\n");
112 * tpm_cr50_i2c_enable_tpm_irq() - Enable TPM irq.
115 static void tpm_cr50_i2c_enable_tpm_irq(struct tpm_chip *chip)
117 struct tpm_i2c_cr50_priv_data *priv = dev_get_drvdata(&chip->dev);
120 reinit_completion(&priv->tpm_ready);
121 enable_irq(priv->irq);
126 * tpm_cr50_i2c_disable_tpm_irq() - Disable TPM irq.
129 static void tpm_cr50_i2c_disable_tpm_irq(struct tpm_chip *chip)
131 struct tpm_i2c_cr50_priv_data *priv = dev_get_drvdata(&chip->dev);
134 disable_irq(priv->irq);
138 * tpm_cr50_i2c_transfer_message() - Transfer a message over i2c.
139 * @dev: Device information.
140 * @adapter: I2C adapter.
141 * @msg: Message to transfer.
143 * Call unlocked i2c transfer routine with the provided parameters and
144 * retry in case of bus errors.
148 * - -errno: A POSIX error code.
150 static int tpm_cr50_i2c_transfer_message(struct device *dev,
151 struct i2c_adapter *adapter,
157 for (try = 0; try < TPM_CR50_I2C_MAX_RETRIES; try++) {
158 rc = __i2c_transfer(adapter, msg, 1);
160 return 0; /* Successfully transferred the message */
162 dev_warn(dev, "i2c transfer failed (attempt %d/%d): %d\n",
163 try + 1, TPM_CR50_I2C_MAX_RETRIES, rc);
164 usleep_range(TPM_CR50_I2C_RETRY_DELAY_LO, TPM_CR50_I2C_RETRY_DELAY_HI);
167 /* No i2c message transferred */
172 * tpm_cr50_i2c_read() - Read from TPM register.
174 * @addr: Register address to read from.
175 * @buffer: Read destination, provided by caller.
176 * @len: Number of bytes to read.
178 * Sends the register address byte to the TPM, then waits until TPM
179 * is ready via interrupt signal or timeout expiration, then 'len'
180 * bytes are read from TPM response into the provided 'buffer'.
184 * - -errno: A POSIX error code.
186 static int tpm_cr50_i2c_read(struct tpm_chip *chip, u8 addr, u8 *buffer, size_t len)
188 struct i2c_client *client = to_i2c_client(chip->dev.parent);
189 struct i2c_msg msg_reg_addr = {
190 .addr = client->addr,
194 struct i2c_msg msg_response = {
195 .addr = client->addr,
202 i2c_lock_bus(client->adapter, I2C_LOCK_SEGMENT);
204 /* Prepare for completion interrupt */
205 tpm_cr50_i2c_enable_tpm_irq(chip);
207 /* Send the register address byte to the TPM */
208 rc = tpm_cr50_i2c_transfer_message(&chip->dev, client->adapter, &msg_reg_addr);
212 /* Wait for TPM to be ready with response data */
213 rc = tpm_cr50_i2c_wait_tpm_ready(chip);
217 /* Read response data from the TPM */
218 rc = tpm_cr50_i2c_transfer_message(&chip->dev, client->adapter, &msg_response);
221 tpm_cr50_i2c_disable_tpm_irq(chip);
222 i2c_unlock_bus(client->adapter, I2C_LOCK_SEGMENT);
231 * tpm_cr50_i2c_write()- Write to TPM register.
233 * @addr: Register address to write to.
234 * @buffer: Data to write.
235 * @len: Number of bytes to write.
237 * The provided address is prepended to the data in 'buffer', the
238 * cobined address+data is sent to the TPM, then wait for TPM to
239 * indicate it is done writing.
243 * - -errno: A POSIX error code.
245 static int tpm_cr50_i2c_write(struct tpm_chip *chip, u8 addr, u8 *buffer,
248 struct tpm_i2c_cr50_priv_data *priv = dev_get_drvdata(&chip->dev);
249 struct i2c_client *client = to_i2c_client(chip->dev.parent);
250 struct i2c_msg msg = {
251 .addr = client->addr,
257 if (len > TPM_CR50_MAX_BUFSIZE - 1)
260 /* Prepend the 'register address' to the buffer */
262 memcpy(priv->buf + 1, buffer, len);
264 i2c_lock_bus(client->adapter, I2C_LOCK_SEGMENT);
266 /* Prepare for completion interrupt */
267 tpm_cr50_i2c_enable_tpm_irq(chip);
269 /* Send write request buffer with address */
270 rc = tpm_cr50_i2c_transfer_message(&chip->dev, client->adapter, &msg);
274 /* Wait for TPM to be ready, ignore timeout */
275 tpm_cr50_i2c_wait_tpm_ready(chip);
278 tpm_cr50_i2c_disable_tpm_irq(chip);
279 i2c_unlock_bus(client->adapter, I2C_LOCK_SEGMENT);
288 * tpm_cr50_check_locality() - Verify TPM locality 0 is active.
293 * - -errno: A POSIX error code.
295 static int tpm_cr50_check_locality(struct tpm_chip *chip)
297 u8 mask = TPM_ACCESS_VALID | TPM_ACCESS_ACTIVE_LOCALITY;
301 rc = tpm_cr50_i2c_read(chip, TPM_I2C_ACCESS(0), &buf, sizeof(buf));
305 if ((buf & mask) == mask)
312 * tpm_cr50_release_locality() - Release TPM locality.
314 * @force: Flag to force release if set.
316 static void tpm_cr50_release_locality(struct tpm_chip *chip, bool force)
318 u8 mask = TPM_ACCESS_VALID | TPM_ACCESS_REQUEST_PENDING;
319 u8 addr = TPM_I2C_ACCESS(0);
322 if (tpm_cr50_i2c_read(chip, addr, &buf, sizeof(buf)) < 0)
325 if (force || (buf & mask) == mask) {
326 buf = TPM_ACCESS_ACTIVE_LOCALITY;
327 tpm_cr50_i2c_write(chip, addr, &buf, sizeof(buf));
332 * tpm_cr50_request_locality() - Request TPM locality 0.
337 * - -errno: A POSIX error code.
339 static int tpm_cr50_request_locality(struct tpm_chip *chip)
341 u8 buf = TPM_ACCESS_REQUEST_USE;
345 if (!tpm_cr50_check_locality(chip))
348 rc = tpm_cr50_i2c_write(chip, TPM_I2C_ACCESS(0), &buf, sizeof(buf));
352 stop = jiffies + chip->timeout_a;
354 if (!tpm_cr50_check_locality(chip))
357 msleep(TPM_CR50_TIMEOUT_SHORT_MS);
358 } while (time_before(jiffies, stop));
364 * tpm_cr50_i2c_tis_status() - Read cr50 tis status.
367 * cr50 requires all 4 bytes of status register to be read.
372 static u8 tpm_cr50_i2c_tis_status(struct tpm_chip *chip)
376 if (tpm_cr50_i2c_read(chip, TPM_I2C_STS(0), buf, sizeof(buf)) < 0)
383 * tpm_cr50_i2c_tis_set_ready() - Set status register to ready.
386 * cr50 requires all 4 bytes of status register to be written.
388 static void tpm_cr50_i2c_tis_set_ready(struct tpm_chip *chip)
390 u8 buf[4] = { TPM_STS_COMMAND_READY };
392 tpm_cr50_i2c_write(chip, TPM_I2C_STS(0), buf, sizeof(buf));
393 msleep(TPM_CR50_TIMEOUT_SHORT_MS);
397 * tpm_cr50_i2c_get_burst_and_status() - Get burst count and status.
399 * @mask: Status mask.
400 * @burst: Return value for burst.
401 * @status: Return value for status.
403 * cr50 uses bytes 3:2 of status register for burst count and
404 * all 4 bytes must be read.
408 * - -errno: A POSIX error code.
410 static int tpm_cr50_i2c_get_burst_and_status(struct tpm_chip *chip, u8 mask,
411 size_t *burst, u32 *status)
418 /* wait for burstcount */
419 stop = jiffies + chip->timeout_b;
422 if (tpm_cr50_i2c_read(chip, TPM_I2C_STS(0), buf, sizeof(buf)) < 0) {
423 msleep(TPM_CR50_TIMEOUT_SHORT_MS);
428 *burst = le16_to_cpup((__le16 *)(buf + 1));
430 if ((*status & mask) == mask &&
431 *burst > 0 && *burst <= TPM_CR50_MAX_BUFSIZE - 1)
434 msleep(TPM_CR50_TIMEOUT_SHORT_MS);
435 } while (time_before(jiffies, stop));
437 dev_err(&chip->dev, "Timeout reading burst and status\n");
442 * tpm_cr50_i2c_tis_recv() - TPM reception callback.
444 * @buf: Reception buffer.
445 * @buf_len: Buffer length to read.
448 * - >= 0: Number of read bytes.
449 * - -errno: A POSIX error code.
451 static int tpm_cr50_i2c_tis_recv(struct tpm_chip *chip, u8 *buf, size_t buf_len)
454 u8 mask = TPM_STS_VALID | TPM_STS_DATA_AVAIL;
455 size_t burstcnt, cur, len, expected;
456 u8 addr = TPM_I2C_DATA_FIFO(0);
460 if (buf_len < TPM_HEADER_SIZE)
463 rc = tpm_cr50_i2c_get_burst_and_status(chip, mask, &burstcnt, &status);
467 if (burstcnt > buf_len || burstcnt < TPM_HEADER_SIZE) {
469 "Unexpected burstcnt: %zu (max=%zu, min=%d)\n",
470 burstcnt, buf_len, TPM_HEADER_SIZE);
475 /* Read first chunk of burstcnt bytes */
476 rc = tpm_cr50_i2c_read(chip, addr, buf, burstcnt);
478 dev_err(&chip->dev, "Read of first chunk failed\n");
482 /* Determine expected data in the return buffer */
483 expected = be32_to_cpup((__be32 *)(buf + 2));
484 if (expected > buf_len) {
485 dev_err(&chip->dev, "Buffer too small to receive i2c data\n");
490 /* Now read the rest of the data */
492 while (cur < expected) {
493 /* Read updated burst count and check status */
494 rc = tpm_cr50_i2c_get_burst_and_status(chip, mask, &burstcnt, &status);
498 len = min_t(size_t, burstcnt, expected - cur);
499 rc = tpm_cr50_i2c_read(chip, addr, buf + cur, len);
501 dev_err(&chip->dev, "Read failed\n");
508 /* Ensure TPM is done reading data */
509 rc = tpm_cr50_i2c_get_burst_and_status(chip, TPM_STS_VALID, &burstcnt, &status);
512 if (status & TPM_STS_DATA_AVAIL) {
513 dev_err(&chip->dev, "Data still available\n");
518 tpm_cr50_release_locality(chip, false);
522 /* Abort current transaction if still pending */
523 if (tpm_cr50_i2c_tis_status(chip) & TPM_STS_COMMAND_READY)
524 tpm_cr50_i2c_tis_set_ready(chip);
526 tpm_cr50_release_locality(chip, false);
531 * tpm_cr50_i2c_tis_send() - TPM transmission callback.
533 * @buf: Buffer to send.
534 * @len: Buffer length.
538 * - -errno: A POSIX error code.
540 static int tpm_cr50_i2c_tis_send(struct tpm_chip *chip, u8 *buf, size_t len)
542 size_t burstcnt, limit, sent = 0;
543 u8 tpm_go[4] = { TPM_STS_GO };
548 rc = tpm_cr50_request_locality(chip);
552 /* Wait until TPM is ready for a command */
553 stop = jiffies + chip->timeout_b;
554 while (!(tpm_cr50_i2c_tis_status(chip) & TPM_STS_COMMAND_READY)) {
555 if (time_after(jiffies, stop)) {
560 tpm_cr50_i2c_tis_set_ready(chip);
564 u8 mask = TPM_STS_VALID;
566 /* Wait for data if this is not the first chunk */
568 mask |= TPM_STS_DATA_EXPECT;
570 /* Read burst count and check status */
571 rc = tpm_cr50_i2c_get_burst_and_status(chip, mask, &burstcnt, &status);
576 * Use burstcnt - 1 to account for the address byte
577 * that is inserted by tpm_cr50_i2c_write()
579 limit = min_t(size_t, burstcnt - 1, len);
580 rc = tpm_cr50_i2c_write(chip, TPM_I2C_DATA_FIFO(0), &buf[sent], limit);
582 dev_err(&chip->dev, "Write failed\n");
590 /* Ensure TPM is not expecting more data */
591 rc = tpm_cr50_i2c_get_burst_and_status(chip, TPM_STS_VALID, &burstcnt, &status);
594 if (status & TPM_STS_DATA_EXPECT) {
595 dev_err(&chip->dev, "Data still expected\n");
600 /* Start the TPM command */
601 rc = tpm_cr50_i2c_write(chip, TPM_I2C_STS(0), tpm_go,
604 dev_err(&chip->dev, "Start command failed\n");
610 /* Abort current transaction if still pending */
611 if (tpm_cr50_i2c_tis_status(chip) & TPM_STS_COMMAND_READY)
612 tpm_cr50_i2c_tis_set_ready(chip);
614 tpm_cr50_release_locality(chip, false);
619 * tpm_cr50_i2c_req_canceled() - Callback to notify a request cancel.
621 * @status: Status given by the cancel callback.
624 * True if command is ready, False otherwise.
626 static bool tpm_cr50_i2c_req_canceled(struct tpm_chip *chip, u8 status)
628 return status == TPM_STS_COMMAND_READY;
631 static const struct tpm_class_ops cr50_i2c = {
632 .flags = TPM_OPS_AUTO_STARTUP,
633 .status = &tpm_cr50_i2c_tis_status,
634 .recv = &tpm_cr50_i2c_tis_recv,
635 .send = &tpm_cr50_i2c_tis_send,
636 .cancel = &tpm_cr50_i2c_tis_set_ready,
637 .req_complete_mask = TPM_STS_DATA_AVAIL | TPM_STS_VALID,
638 .req_complete_val = TPM_STS_DATA_AVAIL | TPM_STS_VALID,
639 .req_canceled = &tpm_cr50_i2c_req_canceled,
642 static const struct i2c_device_id cr50_i2c_table[] = {
646 MODULE_DEVICE_TABLE(i2c, cr50_i2c_table);
649 static const struct acpi_device_id cr50_i2c_acpi_id[] = {
653 MODULE_DEVICE_TABLE(acpi, cr50_i2c_acpi_id);
657 static const struct of_device_id of_cr50_i2c_match[] = {
658 { .compatible = "google,cr50", },
661 MODULE_DEVICE_TABLE(of, of_cr50_i2c_match);
665 * tpm_cr50_i2c_probe() - Driver probe function.
666 * @client: I2C client information.
667 * @id: I2C device id.
671 * - -errno: A POSIX error code.
673 static int tpm_cr50_i2c_probe(struct i2c_client *client,
674 const struct i2c_device_id *id)
676 struct tpm_i2c_cr50_priv_data *priv;
677 struct device *dev = &client->dev;
678 struct tpm_chip *chip;
683 if (!i2c_check_functionality(client->adapter, I2C_FUNC_I2C))
686 chip = tpmm_chip_alloc(dev, &cr50_i2c);
688 return PTR_ERR(chip);
690 priv = devm_kzalloc(dev, sizeof(*priv), GFP_KERNEL);
694 /* cr50 is a TPM 2.0 chip */
695 chip->flags |= TPM_CHIP_FLAG_TPM2;
696 chip->flags |= TPM_CHIP_FLAG_FIRMWARE_POWER_MANAGED;
698 /* Default timeouts */
699 chip->timeout_a = msecs_to_jiffies(TIS_SHORT_TIMEOUT);
700 chip->timeout_b = msecs_to_jiffies(TIS_LONG_TIMEOUT);
701 chip->timeout_c = msecs_to_jiffies(TIS_SHORT_TIMEOUT);
702 chip->timeout_d = msecs_to_jiffies(TIS_SHORT_TIMEOUT);
704 dev_set_drvdata(&chip->dev, priv);
705 init_completion(&priv->tpm_ready);
707 if (client->irq > 0) {
708 rc = devm_request_irq(dev, client->irq, tpm_cr50_i2c_int_handler,
709 IRQF_TRIGGER_FALLING | IRQF_ONESHOT |
711 dev->driver->name, chip);
713 dev_err(dev, "Failed to probe IRQ %d\n", client->irq);
717 priv->irq = client->irq;
719 dev_warn(dev, "No IRQ, will use %ums delay for TPM ready\n",
720 TPM_CR50_TIMEOUT_NOIRQ_MS);
723 rc = tpm_cr50_request_locality(chip);
725 dev_err(dev, "Could not request locality\n");
729 /* Read four bytes from DID_VID register */
730 rc = tpm_cr50_i2c_read(chip, TPM_I2C_DID_VID(0), buf, sizeof(buf));
732 dev_err(dev, "Could not read vendor id\n");
733 tpm_cr50_release_locality(chip, true);
737 vendor = le32_to_cpup((__le32 *)buf);
738 if (vendor != TPM_CR50_I2C_DID_VID) {
739 dev_err(dev, "Vendor ID did not match! ID was %08x\n", vendor);
740 tpm_cr50_release_locality(chip, true);
744 dev_info(dev, "cr50 TPM 2.0 (i2c 0x%02x irq %d id 0x%x)\n",
745 client->addr, client->irq, vendor >> 16);
747 return tpm_chip_register(chip);
751 * tpm_cr50_i2c_remove() - Driver remove function.
752 * @client: I2C client information.
756 * - -errno: A POSIX error code.
758 static int tpm_cr50_i2c_remove(struct i2c_client *client)
760 struct tpm_chip *chip = i2c_get_clientdata(client);
761 struct device *dev = &client->dev;
764 dev_err(dev, "Could not get client data at remove\n");
768 tpm_chip_unregister(chip);
769 tpm_cr50_release_locality(chip, true);
774 static SIMPLE_DEV_PM_OPS(cr50_i2c_pm, tpm_pm_suspend, tpm_pm_resume);
776 static struct i2c_driver cr50_i2c_driver = {
777 .id_table = cr50_i2c_table,
778 .probe = tpm_cr50_i2c_probe,
779 .remove = tpm_cr50_i2c_remove,
783 .acpi_match_table = ACPI_PTR(cr50_i2c_acpi_id),
784 .of_match_table = of_match_ptr(of_cr50_i2c_match),
788 module_i2c_driver(cr50_i2c_driver);
790 MODULE_DESCRIPTION("cr50 TPM I2C Driver");
791 MODULE_LICENSE("GPL");