mirror of
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
synced 2024-11-01 17:08:10 +00:00
7e0438f83d
The following sequence of operations results in a refcount warning: 1. Open device /dev/tpmrm. 2. Remove module tpm_tis_spi. 3. Write a TPM command to the file descriptor opened at step 1. ------------[ cut here ]------------ WARNING: CPU: 3 PID: 1161 at lib/refcount.c:25 kobject_get+0xa0/0xa4 refcount_t: addition on 0; use-after-free. Modules linked in: tpm_tis_spi tpm_tis_core tpm mdio_bcm_unimac brcmfmac sha256_generic libsha256 sha256_arm hci_uart btbcm bluetooth cfg80211 vc4 brcmutil ecdh_generic ecc snd_soc_core crc32_arm_ce libaes raspberrypi_hwmon ac97_bus snd_pcm_dmaengine bcm2711_thermal snd_pcm snd_timer genet snd phy_generic soundcore [last unloaded: spi_bcm2835] CPU: 3 PID: 1161 Comm: hold_open Not tainted 5.10.0ls-main-dirty #2 Hardware name: BCM2711 [<c0410c3c>] (unwind_backtrace) from [<c040b580>] (show_stack+0x10/0x14) [<c040b580>] (show_stack) from [<c1092174>] (dump_stack+0xc4/0xd8) [<c1092174>] (dump_stack) from [<c0445a30>] (__warn+0x104/0x108) [<c0445a30>] (__warn) from [<c0445aa8>] (warn_slowpath_fmt+0x74/0xb8) [<c0445aa8>] (warn_slowpath_fmt) from [<c08435d0>] (kobject_get+0xa0/0xa4) [<c08435d0>] (kobject_get) from [<bf0a715c>] (tpm_try_get_ops+0x14/0x54 [tpm]) [<bf0a715c>] (tpm_try_get_ops [tpm]) from [<bf0a7d6c>] (tpm_common_write+0x38/0x60 [tpm]) [<bf0a7d6c>] (tpm_common_write [tpm]) from [<c05a7ac0>] (vfs_write+0xc4/0x3c0) [<c05a7ac0>] (vfs_write) from [<c05a7ee4>] (ksys_write+0x58/0xcc) [<c05a7ee4>] (ksys_write) from [<c04001a0>] (ret_fast_syscall+0x0/0x4c) Exception stack(0xc226bfa8 to 0xc226bff0) bfa0: 00000000 000105b4 00000003beafe664
00000014 00000000 bfc0: 00000000 000105b4 000103f8 00000004 00000000 00000000 b6f9c000 beafe684 bfe0: 0000006c beafe648 0001056c b6eb6944 ---[ end trace d4b8409def9b8b1f ]--- The reason for this warning is the attempt to get the chip->dev reference in tpm_common_write() although the reference counter is already zero. Since commit8979b02aaf
("tpm: Fix reference count to main device") the extra reference used to prevent a premature zero counter is never taken, because the required TPM_CHIP_FLAG_TPM2 flag is never set. Fix this by moving the TPM 2 character device handling from tpm_chip_alloc() to tpm_add_char_device() which is called at a later point in time when the flag has been set in case of TPM2. Commitfdc915f7f7
("tpm: expose spaces via a device link /dev/tpmrm<n>") already introduced function tpm_devs_release() to release the extra reference but did not implement the required put on chip->devs that results in the call of this function. Fix this by putting chip->devs in tpm_chip_unregister(). Finally move the new implementation for the TPM 2 handling into a new function to avoid multiple checks for the TPM_CHIP_FLAG_TPM2 flag in the good case and error cases. Cc: stable@vger.kernel.org Fixes:fdc915f7f7
("tpm: expose spaces via a device link /dev/tpmrm<n>") Fixes:8979b02aaf
("tpm: Fix reference count to main device") Co-developed-by: Jason Gunthorpe <jgg@ziepe.ca> Signed-off-by: Jason Gunthorpe <jgg@ziepe.ca> Signed-off-by: Lino Sanfilippo <LinoSanfilippo@gmx.de> Tested-by: Stefan Berger <stefanb@linux.ibm.com> Reviewed-by: Jason Gunthorpe <jgg@nvidia.com> Reviewed-by: Jarkko Sakkinen <jarkko@kernel.org> Signed-off-by: Jarkko Sakkinen <jarkko@kernel.org>
244 lines
6.7 KiB
C
244 lines
6.7 KiB
C
/* SPDX-License-Identifier: GPL-2.0-only */
|
|
/*
|
|
* Copyright (C) 2004 IBM Corporation
|
|
* Copyright (C) 2015 Intel Corporation
|
|
*
|
|
* Authors:
|
|
* Leendert van Doorn <leendert@watson.ibm.com>
|
|
* Dave Safford <safford@watson.ibm.com>
|
|
* Reiner Sailer <sailer@watson.ibm.com>
|
|
* Kylene Hall <kjhall@us.ibm.com>
|
|
*
|
|
* Maintained by: <tpmdd-devel@lists.sourceforge.net>
|
|
*
|
|
* Device driver for TCG/TCPA TPM (trusted platform module).
|
|
* Specifications at www.trustedcomputinggroup.org
|
|
*/
|
|
|
|
#ifndef __TPM_H__
|
|
#define __TPM_H__
|
|
|
|
#include <linux/module.h>
|
|
#include <linux/delay.h>
|
|
#include <linux/mutex.h>
|
|
#include <linux/sched.h>
|
|
#include <linux/platform_device.h>
|
|
#include <linux/io.h>
|
|
#include <linux/tpm.h>
|
|
#include <linux/tpm_eventlog.h>
|
|
|
|
#ifdef CONFIG_X86
|
|
#include <asm/intel-family.h>
|
|
#endif
|
|
|
|
#define TPM_MINOR 224 /* officially assigned */
|
|
#define TPM_BUFSIZE 4096
|
|
#define TPM_NUM_DEVICES 65536
|
|
#define TPM_RETRY 50
|
|
|
|
enum tpm_timeout {
|
|
TPM_TIMEOUT = 5, /* msecs */
|
|
TPM_TIMEOUT_RETRY = 100, /* msecs */
|
|
TPM_TIMEOUT_RANGE_US = 300, /* usecs */
|
|
TPM_TIMEOUT_POLL = 1, /* msecs */
|
|
TPM_TIMEOUT_USECS_MIN = 100, /* usecs */
|
|
TPM_TIMEOUT_USECS_MAX = 500 /* usecs */
|
|
};
|
|
|
|
/* TPM addresses */
|
|
enum tpm_addr {
|
|
TPM_SUPERIO_ADDR = 0x2E,
|
|
TPM_ADDR = 0x4E,
|
|
};
|
|
|
|
#define TPM_WARN_RETRY 0x800
|
|
#define TPM_WARN_DOING_SELFTEST 0x802
|
|
#define TPM_ERR_DEACTIVATED 0x6
|
|
#define TPM_ERR_DISABLED 0x7
|
|
#define TPM_ERR_INVALID_POSTINIT 38
|
|
|
|
#define TPM_TAG_RQU_COMMAND 193
|
|
|
|
/* TPM2 specific constants. */
|
|
#define TPM2_SPACE_BUFFER_SIZE 16384 /* 16 kB */
|
|
|
|
struct stclear_flags_t {
|
|
__be16 tag;
|
|
u8 deactivated;
|
|
u8 disableForceClear;
|
|
u8 physicalPresence;
|
|
u8 physicalPresenceLock;
|
|
u8 bGlobalLock;
|
|
} __packed;
|
|
|
|
struct tpm1_version {
|
|
u8 major;
|
|
u8 minor;
|
|
u8 rev_major;
|
|
u8 rev_minor;
|
|
} __packed;
|
|
|
|
struct tpm1_version2 {
|
|
__be16 tag;
|
|
struct tpm1_version version;
|
|
} __packed;
|
|
|
|
struct timeout_t {
|
|
__be32 a;
|
|
__be32 b;
|
|
__be32 c;
|
|
__be32 d;
|
|
} __packed;
|
|
|
|
struct duration_t {
|
|
__be32 tpm_short;
|
|
__be32 tpm_medium;
|
|
__be32 tpm_long;
|
|
} __packed;
|
|
|
|
struct permanent_flags_t {
|
|
__be16 tag;
|
|
u8 disable;
|
|
u8 ownership;
|
|
u8 deactivated;
|
|
u8 readPubek;
|
|
u8 disableOwnerClear;
|
|
u8 allowMaintenance;
|
|
u8 physicalPresenceLifetimeLock;
|
|
u8 physicalPresenceHWEnable;
|
|
u8 physicalPresenceCMDEnable;
|
|
u8 CEKPUsed;
|
|
u8 TPMpost;
|
|
u8 TPMpostLock;
|
|
u8 FIPS;
|
|
u8 operator;
|
|
u8 enableRevokeEK;
|
|
u8 nvLocked;
|
|
u8 readSRKPub;
|
|
u8 tpmEstablished;
|
|
u8 maintenanceDone;
|
|
u8 disableFullDALogicInfo;
|
|
} __packed;
|
|
|
|
typedef union {
|
|
struct permanent_flags_t perm_flags;
|
|
struct stclear_flags_t stclear_flags;
|
|
__u8 owned;
|
|
__be32 num_pcrs;
|
|
struct tpm1_version version1;
|
|
struct tpm1_version2 version2;
|
|
__be32 manufacturer_id;
|
|
struct timeout_t timeout;
|
|
struct duration_t duration;
|
|
} cap_t;
|
|
|
|
enum tpm_capabilities {
|
|
TPM_CAP_FLAG = 4,
|
|
TPM_CAP_PROP = 5,
|
|
TPM_CAP_VERSION_1_1 = 0x06,
|
|
TPM_CAP_VERSION_1_2 = 0x1A,
|
|
};
|
|
|
|
enum tpm_sub_capabilities {
|
|
TPM_CAP_PROP_PCR = 0x101,
|
|
TPM_CAP_PROP_MANUFACTURER = 0x103,
|
|
TPM_CAP_FLAG_PERM = 0x108,
|
|
TPM_CAP_FLAG_VOL = 0x109,
|
|
TPM_CAP_PROP_OWNER = 0x111,
|
|
TPM_CAP_PROP_TIS_TIMEOUT = 0x115,
|
|
TPM_CAP_PROP_TIS_DURATION = 0x120,
|
|
};
|
|
|
|
|
|
/* 128 bytes is an arbitrary cap. This could be as large as TPM_BUFSIZE - 18
|
|
* bytes, but 128 is still a relatively large number of random bytes and
|
|
* anything much bigger causes users of struct tpm_cmd_t to start getting
|
|
* compiler warnings about stack frame size. */
|
|
#define TPM_MAX_RNG_DATA 128
|
|
|
|
extern struct class *tpm_class;
|
|
extern struct class *tpmrm_class;
|
|
extern dev_t tpm_devt;
|
|
extern const struct file_operations tpm_fops;
|
|
extern const struct file_operations tpmrm_fops;
|
|
extern struct idr dev_nums_idr;
|
|
|
|
ssize_t tpm_transmit(struct tpm_chip *chip, u8 *buf, size_t bufsiz);
|
|
int tpm_get_timeouts(struct tpm_chip *);
|
|
int tpm_auto_startup(struct tpm_chip *chip);
|
|
|
|
int tpm1_pm_suspend(struct tpm_chip *chip, u32 tpm_suspend_pcr);
|
|
int tpm1_auto_startup(struct tpm_chip *chip);
|
|
int tpm1_do_selftest(struct tpm_chip *chip);
|
|
int tpm1_get_timeouts(struct tpm_chip *chip);
|
|
unsigned long tpm1_calc_ordinal_duration(struct tpm_chip *chip, u32 ordinal);
|
|
int tpm1_pcr_extend(struct tpm_chip *chip, u32 pcr_idx, const u8 *hash,
|
|
const char *log_msg);
|
|
int tpm1_pcr_read(struct tpm_chip *chip, u32 pcr_idx, u8 *res_buf);
|
|
ssize_t tpm1_getcap(struct tpm_chip *chip, u32 subcap_id, cap_t *cap,
|
|
const char *desc, size_t min_cap_length);
|
|
int tpm1_get_random(struct tpm_chip *chip, u8 *out, size_t max);
|
|
int tpm1_get_pcr_allocation(struct tpm_chip *chip);
|
|
unsigned long tpm_calc_ordinal_duration(struct tpm_chip *chip, u32 ordinal);
|
|
int tpm_pm_suspend(struct device *dev);
|
|
int tpm_pm_resume(struct device *dev);
|
|
|
|
static inline void tpm_msleep(unsigned int delay_msec)
|
|
{
|
|
usleep_range((delay_msec * 1000) - TPM_TIMEOUT_RANGE_US,
|
|
delay_msec * 1000);
|
|
};
|
|
|
|
int tpm_chip_start(struct tpm_chip *chip);
|
|
void tpm_chip_stop(struct tpm_chip *chip);
|
|
struct tpm_chip *tpm_find_get_ops(struct tpm_chip *chip);
|
|
|
|
struct tpm_chip *tpm_chip_alloc(struct device *dev,
|
|
const struct tpm_class_ops *ops);
|
|
struct tpm_chip *tpmm_chip_alloc(struct device *pdev,
|
|
const struct tpm_class_ops *ops);
|
|
int tpm_chip_register(struct tpm_chip *chip);
|
|
void tpm_chip_unregister(struct tpm_chip *chip);
|
|
|
|
void tpm_sysfs_add_device(struct tpm_chip *chip);
|
|
|
|
|
|
#ifdef CONFIG_ACPI
|
|
extern void tpm_add_ppi(struct tpm_chip *chip);
|
|
#else
|
|
static inline void tpm_add_ppi(struct tpm_chip *chip)
|
|
{
|
|
}
|
|
#endif
|
|
|
|
int tpm2_get_timeouts(struct tpm_chip *chip);
|
|
int tpm2_pcr_read(struct tpm_chip *chip, u32 pcr_idx,
|
|
struct tpm_digest *digest, u16 *digest_size_ptr);
|
|
int tpm2_pcr_extend(struct tpm_chip *chip, u32 pcr_idx,
|
|
struct tpm_digest *digests);
|
|
int tpm2_get_random(struct tpm_chip *chip, u8 *dest, size_t max);
|
|
ssize_t tpm2_get_tpm_pt(struct tpm_chip *chip, u32 property_id,
|
|
u32 *value, const char *desc);
|
|
|
|
ssize_t tpm2_get_pcr_allocation(struct tpm_chip *chip);
|
|
int tpm2_auto_startup(struct tpm_chip *chip);
|
|
void tpm2_shutdown(struct tpm_chip *chip, u16 shutdown_type);
|
|
unsigned long tpm2_calc_ordinal_duration(struct tpm_chip *chip, u32 ordinal);
|
|
int tpm2_probe(struct tpm_chip *chip);
|
|
int tpm2_get_cc_attrs_tbl(struct tpm_chip *chip);
|
|
int tpm2_find_cc(struct tpm_chip *chip, u32 cc);
|
|
int tpm2_init_space(struct tpm_space *space, unsigned int buf_size);
|
|
void tpm2_del_space(struct tpm_chip *chip, struct tpm_space *space);
|
|
void tpm2_flush_space(struct tpm_chip *chip);
|
|
int tpm2_prepare_space(struct tpm_chip *chip, struct tpm_space *space, u8 *cmd,
|
|
size_t cmdsiz);
|
|
int tpm2_commit_space(struct tpm_chip *chip, struct tpm_space *space, void *buf,
|
|
size_t *bufsiz);
|
|
int tpm_devs_add(struct tpm_chip *chip);
|
|
void tpm_devs_remove(struct tpm_chip *chip);
|
|
|
|
void tpm_bios_log_setup(struct tpm_chip *chip);
|
|
void tpm_bios_log_teardown(struct tpm_chip *chip);
|
|
int tpm_dev_common_init(void);
|
|
void tpm_dev_common_exit(void);
|
|
#endif
|