170-sunxi-sid-initial.patch 9.4 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290
  1. From 1d4b3ab562fa87e2c7f05cf92af1ff4b6cd42581 Mon Sep 17 00:00:00 2001
  2. From: Oliver Schinagl <[email protected]>
  3. Date: Tue, 3 Sep 2013 12:33:27 +0200
  4. Subject: [PATCH] ARM: sunxi: Initial support for Allwinner's Security ID fuses
  5. Allwinner has electric fuses (efuse) on their line of chips. This driver
  6. reads those fuses, seeds the kernel entropy and exports them as a sysfs
  7. node.
  8. These fuses are most likely to be programmed at the factory, encoding
  9. things like Chip ID, some sort of serial number, etc. and appear to be
  10. reasonably unique.
  11. While in theory, these should be writeable by the user, it will probably
  12. be inconvenient to do so. Allwinner recommends that a certain input pin,
  13. labeled 'efuse_vddq', be connected to GND. To write these fuses however,
  14. a 2.5 V programming voltage needs to be applied to this pin.
  15. Even so, they can still be used to generate a board-unique mac from,
  16. board unique RSA key and seed the kernel RNG.
  17. On sun7i additional storage is available, this is initially used for an
  18. UEFI BOOT key, Secure JTAG key, HDMI-HDCP key and vendor specific keys.
  19. Currently supported are the following known chips:
  20. Allwinner sun4i (A10)
  21. Allwinner sun5i (A10s, A13)
  22. Allwinner sun7i (A20)
  23. Signed-off-by: Oliver Schinagl <[email protected]>
  24. ---
  25. Documentation/ABI/testing/sysfs-driver-sunxi-sid | 22 +++
  26. .../bindings/misc/allwinner,sunxi-sid.txt | 17 +++
  27. drivers/misc/eeprom/Kconfig | 13 ++
  28. drivers/misc/eeprom/Makefile | 1 +
  29. drivers/misc/eeprom/sunxi_sid.c | 158 +++++++++++++++++++++
  30. 5 files changed, 211 insertions(+)
  31. create mode 100644 Documentation/ABI/testing/sysfs-driver-sunxi-sid
  32. create mode 100644 Documentation/devicetree/bindings/misc/allwinner,sunxi-sid.txt
  33. create mode 100644 drivers/misc/eeprom/sunxi_sid.c
  34. diff --git a/Documentation/ABI/testing/sysfs-driver-sunxi-sid b/Documentation/ABI/testing/sysfs-driver-sunxi-sid
  35. new file mode 100644
  36. index 0000000..ffb9536
  37. --- /dev/null
  38. +++ b/Documentation/ABI/testing/sysfs-driver-sunxi-sid
  39. @@ -0,0 +1,22 @@
  40. +What: /sys/devices/*/<our-device>/eeprom
  41. +Date: August 2013
  42. +Contact: Oliver Schinagl <[email protected]>
  43. +Description: read-only access to the SID (Security-ID) on current
  44. + A-series SoC's from Allwinner. Currently supports A10, A10s, A13
  45. + and A20 CPU's. The earlier A1x series of SoCs exports 16 bytes,
  46. + whereas the newer A20 SoC exposes 512 bytes split into sections.
  47. + Besides the 16 bytes of SID, there's also an SJTAG area,
  48. + HDMI-HDCP key and some custom keys. Below a quick overview, for
  49. + details see the user manual:
  50. + 0x000 128 bit root-key (sun[457]i)
  51. + 0x010 128 bit boot-key (sun7i)
  52. + 0x020 64 bit security-jtag-key (sun7i)
  53. + 0x028 16 bit key configuration (sun7i)
  54. + 0x02b 16 bit custom-vendor-key (sun7i)
  55. + 0x02c 320 bit low general key (sun7i)
  56. + 0x040 32 bit read-control access (sun7i)
  57. + 0x064 224 bit low general key (sun7i)
  58. + 0x080 2304 bit HDCP-key (sun7i)
  59. + 0x1a0 768 bit high general key (sun7i)
  60. +Users: any user space application which wants to read the SID on
  61. + Allwinner's A-series of CPU's.
  62. diff --git a/Documentation/devicetree/bindings/misc/allwinner,sunxi-sid.txt b/Documentation/devicetree/bindings/misc/allwinner,sunxi-sid.txt
  63. new file mode 100644
  64. index 0000000..68ba372
  65. --- /dev/null
  66. +++ b/Documentation/devicetree/bindings/misc/allwinner,sunxi-sid.txt
  67. @@ -0,0 +1,17 @@
  68. +Allwinner sunxi-sid
  69. +
  70. +Required properties:
  71. +- compatible: "allwinner,sun4i-sid" or "allwinner,sun7i-a20-sid".
  72. +- reg: Should contain registers location and length
  73. +
  74. +Example for sun4i:
  75. + sid@01c23800 {
  76. + compatible = "allwinner,sun4i-sid";
  77. + reg = <0x01c23800 0x10>
  78. + };
  79. +
  80. +Example for sun7i:
  81. + sid@01c23800 {
  82. + compatible = "allwinner,sun7i-a20-sid";
  83. + reg = <0x01c23800 0x200>
  84. + };
  85. diff --git a/drivers/misc/eeprom/Kconfig b/drivers/misc/eeprom/Kconfig
  86. index 04f2e1f..9536852f 100644
  87. --- a/drivers/misc/eeprom/Kconfig
  88. +++ b/drivers/misc/eeprom/Kconfig
  89. @@ -96,4 +96,17 @@ config EEPROM_DIGSY_MTC_CFG
  90. If unsure, say N.
  91. +config EEPROM_SUNXI_SID
  92. + tristate "Allwinner sunxi security ID support"
  93. + depends on ARCH_SUNXI && SYSFS
  94. + help
  95. + This is a driver for the 'security ID' available on various Allwinner
  96. + devices.
  97. +
  98. + Due to the potential risks involved with changing e-fuses,
  99. + this driver is read-only.
  100. +
  101. + This driver can also be built as a module. If so, the module
  102. + will be called sunxi_sid.
  103. +
  104. endmenu
  105. diff --git a/drivers/misc/eeprom/Makefile b/drivers/misc/eeprom/Makefile
  106. index fc1e81d..9507aec 100644
  107. --- a/drivers/misc/eeprom/Makefile
  108. +++ b/drivers/misc/eeprom/Makefile
  109. @@ -4,4 +4,5 @@ obj-$(CONFIG_EEPROM_LEGACY) += eeprom.o
  110. obj-$(CONFIG_EEPROM_MAX6875) += max6875.o
  111. obj-$(CONFIG_EEPROM_93CX6) += eeprom_93cx6.o
  112. obj-$(CONFIG_EEPROM_93XX46) += eeprom_93xx46.o
  113. +obj-$(CONFIG_EEPROM_SUNXI_SID) += sunxi_sid.o
  114. obj-$(CONFIG_EEPROM_DIGSY_MTC_CFG) += digsy_mtc_eeprom.o
  115. diff --git a/drivers/misc/eeprom/sunxi_sid.c b/drivers/misc/eeprom/sunxi_sid.c
  116. new file mode 100644
  117. index 0000000..9c34e57
  118. --- /dev/null
  119. +++ b/drivers/misc/eeprom/sunxi_sid.c
  120. @@ -0,0 +1,158 @@
  121. +/*
  122. + * Copyright (c) 2013 Oliver Schinagl <[email protected]>
  123. + * http://www.linux-sunxi.org
  124. + *
  125. + * This program is free software; you can redistribute it and/or modify
  126. + * it under the terms of the GNU General Public License as published by
  127. + * the Free Software Foundation; either version 2 of the License, or
  128. + * (at your option) any later version.
  129. + *
  130. + * This program is distributed in the hope that it will be useful,
  131. + * but WITHOUT ANY WARRANTY; without even the implied warranty of
  132. + * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
  133. + * GNU General Public License for more details.
  134. + *
  135. + * This driver exposes the Allwinner security ID, efuses exported in byte-
  136. + * sized chunks.
  137. + */
  138. +
  139. +#include <linux/compiler.h>
  140. +#include <linux/device.h>
  141. +#include <linux/err.h>
  142. +#include <linux/export.h>
  143. +#include <linux/fs.h>
  144. +#include <linux/init.h>
  145. +#include <linux/io.h>
  146. +#include <linux/kernel.h>
  147. +#include <linux/kobject.h>
  148. +#include <linux/module.h>
  149. +#include <linux/of_device.h>
  150. +#include <linux/platform_device.h>
  151. +#include <linux/random.h>
  152. +#include <linux/slab.h>
  153. +#include <linux/stat.h>
  154. +#include <linux/sysfs.h>
  155. +#include <linux/types.h>
  156. +
  157. +#define DRV_NAME "sunxi-sid"
  158. +
  159. +struct sunxi_sid_data {
  160. + void __iomem *reg_base;
  161. + unsigned int keysize;
  162. +};
  163. +
  164. +/* We read the entire key, due to a 32 bit read alignment requirement. Since we
  165. + * want to return the requested byte, this results in somewhat slower code and
  166. + * uses 4 times more reads as needed but keeps code simpler. Since the SID is
  167. + * only very rarely probed, this is not really an issue.
  168. + */
  169. +static u8 sunxi_sid_read_byte(const struct sunxi_sid_data *sid_data,
  170. + const unsigned int offset)
  171. +{
  172. + u32 sid_key;
  173. +
  174. + if (offset >= sid_data->keysize)
  175. + return 0;
  176. +
  177. + sid_key = ioread32be(sid_data->reg_base + round_down(offset, 4));
  178. + sid_key >>= (offset % 4) * 8;
  179. +
  180. + return sid_key; /* Only return the last byte */
  181. +}
  182. +
  183. +static ssize_t sid_read(struct file *fd, struct kobject *kobj,
  184. + struct bin_attribute *attr, char *buf,
  185. + loff_t pos, size_t size)
  186. +{
  187. + struct platform_device *pdev;
  188. + struct sunxi_sid_data *sid_data;
  189. + int i;
  190. +
  191. + pdev = to_platform_device(kobj_to_dev(kobj));
  192. + sid_data = platform_get_drvdata(pdev);
  193. +
  194. + if (pos < 0 || pos >= sid_data->keysize)
  195. + return 0;
  196. + if (size > sid_data->keysize - pos)
  197. + size = sid_data->keysize - pos;
  198. +
  199. + for (i = 0; i < size; i++)
  200. + buf[i] = sunxi_sid_read_byte(sid_data, pos + i);
  201. +
  202. + return i;
  203. +}
  204. +
  205. +static struct bin_attribute sid_bin_attr = {
  206. + .attr = { .name = "eeprom", .mode = S_IRUGO, },
  207. + .read = sid_read,
  208. +};
  209. +
  210. +static int sunxi_sid_remove(struct platform_device *pdev)
  211. +{
  212. + device_remove_bin_file(&pdev->dev, &sid_bin_attr);
  213. + dev_dbg(&pdev->dev, "driver unloaded\n");
  214. +
  215. + return 0;
  216. +}
  217. +
  218. +static const struct of_device_id sunxi_sid_of_match[] = {
  219. + { .compatible = "allwinner,sun4i-sid", .data = (void *)16},
  220. + { .compatible = "allwinner,sun7i-a20-sid", .data = (void *)512},
  221. + {/* sentinel */},
  222. +};
  223. +MODULE_DEVICE_TABLE(of, sunxi_sid_of_match);
  224. +
  225. +static int sunxi_sid_probe(struct platform_device *pdev)
  226. +{
  227. + struct sunxi_sid_data *sid_data;
  228. + struct resource *res;
  229. + const struct of_device_id *of_dev_id;
  230. + u8 *entropy;
  231. + unsigned int i;
  232. +
  233. + sid_data = devm_kzalloc(&pdev->dev, sizeof(struct sunxi_sid_data),
  234. + GFP_KERNEL);
  235. + if (!sid_data)
  236. + return -ENOMEM;
  237. +
  238. + res = platform_get_resource(pdev, IORESOURCE_MEM, 0);
  239. + sid_data->reg_base = devm_ioremap_resource(&pdev->dev, res);
  240. + if (IS_ERR(sid_data->reg_base))
  241. + return PTR_ERR(sid_data->reg_base);
  242. +
  243. + of_dev_id = of_match_device(sunxi_sid_of_match, &pdev->dev);
  244. + if (!of_dev_id)
  245. + return -ENODEV;
  246. + sid_data->keysize = (int)of_dev_id->data;
  247. +
  248. + platform_set_drvdata(pdev, sid_data);
  249. +
  250. + sid_bin_attr.size = sid_data->keysize;
  251. + if (device_create_bin_file(&pdev->dev, &sid_bin_attr))
  252. + return -ENODEV;
  253. +
  254. + entropy = kzalloc(sizeof(u8) * sid_data->keysize, GFP_KERNEL);
  255. + for (i = 0; i < sid_data->keysize; i++)
  256. + entropy[i] = sunxi_sid_read_byte(sid_data, i);
  257. + add_device_randomness(entropy, sid_data->keysize);
  258. + kfree(entropy);
  259. +
  260. + dev_dbg(&pdev->dev, "loaded\n");
  261. +
  262. + return 0;
  263. +}
  264. +
  265. +static struct platform_driver sunxi_sid_driver = {
  266. + .probe = sunxi_sid_probe,
  267. + .remove = sunxi_sid_remove,
  268. + .driver = {
  269. + .name = DRV_NAME,
  270. + .owner = THIS_MODULE,
  271. + .of_match_table = sunxi_sid_of_match,
  272. + },
  273. +};
  274. +module_platform_driver(sunxi_sid_driver);
  275. +
  276. +MODULE_AUTHOR("Oliver Schinagl <[email protected]>");
  277. +MODULE_DESCRIPTION("Allwinner sunxi security id driver");
  278. +MODULE_LICENSE("GPL");
  279. --
  280. 1.8.4