blob: b903b757246c7f4956408a4c293ef12e267cae14 [file] [log] [blame]
Roberto Pereira24261972018-07-30 14:54:58 -07001/*
2 * Copyright 2018 The Android Open Source Project
3 *
4 * Licensed under the Apache License, Version 2.0 (the "License");
5 * you may not use this file except in compliance with the License.
6 * You may obtain a copy of the License at
7 *
8 * http://www.apache.org/licenses/LICENSE-2.0
9 *
10 * Unless required by applicable law or agreed to in writing, software
11 * distributed under the License is distributed on an "AS IS" BASIS,
12 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13 * See the License for the specific language governing permissions and
14 * limitations under the License.
15 */
16
Shawn Willdenfed81d82021-04-22 13:32:56 -060017#define LOG_TAG "trusty_keymaster_hal"
18#include <android-base/logging.h>
19
Roberto Pereira24261972018-07-30 14:54:58 -070020#include <keymaster/android_keymaster_messages.h>
21#include <keymaster/keymaster_configuration.h>
22#include <trusty_keymaster/TrustyKeymaster.h>
23#include <trusty_keymaster/ipc/trusty_keymaster_ipc.h>
24
25namespace keymaster {
26
Shawn Willdenfed81d82021-04-22 13:32:56 -060027int TrustyKeymaster::Initialize(KmVersion version) {
Roberto Pereira24261972018-07-30 14:54:58 -070028 int err;
29
Shawn Willdenfed81d82021-04-22 13:32:56 -060030 LOG(INFO) << "Initializing TrustyKeymaster as KmVersion: " << (int)version;
31
Roberto Pereira24261972018-07-30 14:54:58 -070032 err = trusty_keymaster_connect();
33 if (err) {
Shawn Willdenfed81d82021-04-22 13:32:56 -060034 LOG(ERROR) << "Failed to connect to trusty keymaster (1st try)" << err;
Roberto Pereira24261972018-07-30 14:54:58 -070035 return err;
36 }
37
Shawn Willden9323f412021-01-06 19:15:29 +000038 // Try GetVersion2 first.
39 GetVersion2Request versionReq;
Shawn Willdenfed81d82021-04-22 13:32:56 -060040 versionReq.max_message_version = MessageVersion(version);
Shawn Willden9323f412021-01-06 19:15:29 +000041 GetVersion2Response versionRsp = GetVersion2(versionReq);
42 if (versionRsp.error != KM_ERROR_OK) {
Shawn Willdenfed81d82021-04-22 13:32:56 -060043 LOG(WARNING) << "TA appears not to support GetVersion2, falling back (err = "
44 << versionRsp.error << ")";
Shawn Willden9323f412021-01-06 19:15:29 +000045
Matthew Maurerc4abbe62021-01-20 13:19:13 -080046 err = trusty_keymaster_connect();
47 if (err) {
Shawn Willdenfed81d82021-04-22 13:32:56 -060048 LOG(FATAL) << "Failed to connect to trusty keymaster (2nd try) " << err;
Matthew Maurerc4abbe62021-01-20 13:19:13 -080049 return err;
50 }
51
Shawn Willden9323f412021-01-06 19:15:29 +000052 GetVersionRequest versionReq;
53 GetVersionResponse versionRsp;
54 GetVersion(versionReq, &versionRsp);
55 if (versionRsp.error != KM_ERROR_OK) {
Shawn Willdenfed81d82021-04-22 13:32:56 -060056 LOG(FATAL) << "Failed to get TA version " << versionRsp.error;
Shawn Willden9323f412021-01-06 19:15:29 +000057 return -1;
58 } else {
59 keymaster_error_t error;
60 message_version_ = NegotiateMessageVersion(versionRsp, &error);
61 if (error != KM_ERROR_OK) {
Shawn Willdenfed81d82021-04-22 13:32:56 -060062 LOG(FATAL) << "Failed to negotiate message version " << error;
Shawn Willden9323f412021-01-06 19:15:29 +000063 return -1;
64 }
65 }
66 } else {
67 message_version_ = NegotiateMessageVersion(versionReq, versionRsp);
68 }
69
70 ConfigureRequest req(message_version());
Roberto Pereira24261972018-07-30 14:54:58 -070071 req.os_version = GetOsVersion();
72 req.os_patchlevel = GetOsPatchlevel();
73
Shawn Willden9323f412021-01-06 19:15:29 +000074 ConfigureResponse rsp(message_version());
Roberto Pereira24261972018-07-30 14:54:58 -070075 Configure(req, &rsp);
76
77 if (rsp.error != KM_ERROR_OK) {
Shawn Willdenfed81d82021-04-22 13:32:56 -060078 LOG(FATAL) << "Failed to configure keymaster " << rsp.error;
Roberto Pereira24261972018-07-30 14:54:58 -070079 return -1;
80 }
81
David Drysdalee7697d72021-07-13 12:17:17 +010082 // Set the vendor patchlevel to value retrieved from system property (which
83 // requires SELinux permission).
84 ConfigureVendorPatchlevelRequest vendor_req(message_version());
85 vendor_req.vendor_patchlevel = GetVendorPatchlevel();
86 ConfigureVendorPatchlevelResponse vendor_rsp = ConfigureVendorPatchlevel(vendor_req);
87 if (vendor_rsp.error != KM_ERROR_OK) {
88 LOG(ERROR) << "Failed to configure keymaster vendor patchlevel: " << vendor_rsp.error;
89 // Don't fail if this message isn't understood.
90 }
91
Roberto Pereira24261972018-07-30 14:54:58 -070092 return 0;
93}
94
95TrustyKeymaster::TrustyKeymaster() {}
96
97TrustyKeymaster::~TrustyKeymaster() {
98 trusty_keymaster_disconnect();
99}
100
Shawn Willden9323f412021-01-06 19:15:29 +0000101static void ForwardCommand(enum keymaster_command command, const KeymasterMessage& req,
Roberto Pereira24261972018-07-30 14:54:58 -0700102 KeymasterResponse* rsp) {
103 keymaster_error_t err;
104 err = trusty_keymaster_send(command, req, rsp);
105 if (err != KM_ERROR_OK) {
Shawn Willdenfed81d82021-04-22 13:32:56 -0600106 LOG(ERROR) << "Cmd " << command << " returned error: " << err;
Roberto Pereira24261972018-07-30 14:54:58 -0700107 rsp->error = err;
108 }
109}
110
111void TrustyKeymaster::GetVersion(const GetVersionRequest& request, GetVersionResponse* response) {
112 ForwardCommand(KM_GET_VERSION, request, response);
113}
114
Roberto Pereira24261972018-07-30 14:54:58 -0700115void TrustyKeymaster::AddRngEntropy(const AddEntropyRequest& request,
116 AddEntropyResponse* response) {
117 ForwardCommand(KM_ADD_RNG_ENTROPY, request, response);
118}
119
120void TrustyKeymaster::Configure(const ConfigureRequest& request, ConfigureResponse* response) {
121 ForwardCommand(KM_CONFIGURE, request, response);
122}
123
124void TrustyKeymaster::GenerateKey(const GenerateKeyRequest& request,
125 GenerateKeyResponse* response) {
Shawn Willdenfed81d82021-04-22 13:32:56 -0600126 if (message_version_ < 4) {
127 // Pre-KeyMint we need to add TAG_CREATION_DATETIME if not provided by the caller.
128 GenerateKeyRequest datedRequest(request.message_version);
129 datedRequest.key_description = request.key_description;
Roberto Pereira24261972018-07-30 14:54:58 -0700130
Shawn Willdenfed81d82021-04-22 13:32:56 -0600131 if (!request.key_description.Contains(TAG_CREATION_DATETIME)) {
132 datedRequest.key_description.push_back(TAG_CREATION_DATETIME, java_time(time(NULL)));
133 }
134
135 ForwardCommand(KM_GENERATE_KEY, datedRequest, response);
136 } else {
137 ForwardCommand(KM_GENERATE_KEY, request, response);
Roberto Pereira24261972018-07-30 14:54:58 -0700138 }
Roberto Pereira24261972018-07-30 14:54:58 -0700139}
140
Max Bires95b5b042021-06-09 17:40:54 -0700141void TrustyKeymaster::GenerateRkpKey(const GenerateRkpKeyRequest& request,
142 GenerateRkpKeyResponse* response) {
143 ForwardCommand(KM_GENERATE_RKP_KEY, request, response);
144}
145
146void TrustyKeymaster::GenerateCsr(const GenerateCsrRequest& request,
147 GenerateCsrResponse* response) {
148 ForwardCommand(KM_GENERATE_CSR, request, response);
149}
150
Roberto Pereira24261972018-07-30 14:54:58 -0700151void TrustyKeymaster::GetKeyCharacteristics(const GetKeyCharacteristicsRequest& request,
152 GetKeyCharacteristicsResponse* response) {
153 ForwardCommand(KM_GET_KEY_CHARACTERISTICS, request, response);
154}
155
156void TrustyKeymaster::ImportKey(const ImportKeyRequest& request, ImportKeyResponse* response) {
157 ForwardCommand(KM_IMPORT_KEY, request, response);
158}
159
160void TrustyKeymaster::ImportWrappedKey(const ImportWrappedKeyRequest& request,
161 ImportWrappedKeyResponse* response) {
162 ForwardCommand(KM_IMPORT_WRAPPED_KEY, request, response);
163}
164
165void TrustyKeymaster::ExportKey(const ExportKeyRequest& request, ExportKeyResponse* response) {
166 ForwardCommand(KM_EXPORT_KEY, request, response);
167}
168
169void TrustyKeymaster::AttestKey(const AttestKeyRequest& request, AttestKeyResponse* response) {
170 ForwardCommand(KM_ATTEST_KEY, request, response);
171}
172
173void TrustyKeymaster::UpgradeKey(const UpgradeKeyRequest& request, UpgradeKeyResponse* response) {
174 ForwardCommand(KM_UPGRADE_KEY, request, response);
175}
176
177void TrustyKeymaster::DeleteKey(const DeleteKeyRequest& request, DeleteKeyResponse* response) {
178 ForwardCommand(KM_DELETE_KEY, request, response);
179}
180
181void TrustyKeymaster::DeleteAllKeys(const DeleteAllKeysRequest& request,
182 DeleteAllKeysResponse* response) {
183 ForwardCommand(KM_DELETE_ALL_KEYS, request, response);
184}
185
186void TrustyKeymaster::BeginOperation(const BeginOperationRequest& request,
187 BeginOperationResponse* response) {
188 ForwardCommand(KM_BEGIN_OPERATION, request, response);
189}
190
191void TrustyKeymaster::UpdateOperation(const UpdateOperationRequest& request,
192 UpdateOperationResponse* response) {
193 ForwardCommand(KM_UPDATE_OPERATION, request, response);
194}
195
196void TrustyKeymaster::FinishOperation(const FinishOperationRequest& request,
197 FinishOperationResponse* response) {
198 ForwardCommand(KM_FINISH_OPERATION, request, response);
199}
200
201void TrustyKeymaster::AbortOperation(const AbortOperationRequest& request,
202 AbortOperationResponse* response) {
203 ForwardCommand(KM_ABORT_OPERATION, request, response);
204}
205
Roberto Pereira24261972018-07-30 14:54:58 -0700206GetHmacSharingParametersResponse TrustyKeymaster::GetHmacSharingParameters() {
Shawn Willden9323f412021-01-06 19:15:29 +0000207 GetHmacSharingParametersRequest request(message_version());
208 GetHmacSharingParametersResponse response(message_version());
Matthew Maurerb321b412019-03-18 13:59:28 -0700209 ForwardCommand(KM_GET_HMAC_SHARING_PARAMETERS, request, &response);
Roberto Pereira24261972018-07-30 14:54:58 -0700210 return response;
211}
212
213ComputeSharedHmacResponse TrustyKeymaster::ComputeSharedHmac(
Matthew Maurerb321b412019-03-18 13:59:28 -0700214 const ComputeSharedHmacRequest& request) {
Shawn Willden9323f412021-01-06 19:15:29 +0000215 ComputeSharedHmacResponse response(message_version());
Matthew Maurerb321b412019-03-18 13:59:28 -0700216 ForwardCommand(KM_COMPUTE_SHARED_HMAC, request, &response);
Roberto Pereira24261972018-07-30 14:54:58 -0700217 return response;
218}
219
220VerifyAuthorizationResponse TrustyKeymaster::VerifyAuthorization(
Matthew Maurerb321b412019-03-18 13:59:28 -0700221 const VerifyAuthorizationRequest& request) {
Shawn Willden9323f412021-01-06 19:15:29 +0000222 VerifyAuthorizationResponse response(message_version());
Matthew Maurerb321b412019-03-18 13:59:28 -0700223 ForwardCommand(KM_VERIFY_AUTHORIZATION, request, &response);
Roberto Pereira24261972018-07-30 14:54:58 -0700224 return response;
225}
226
Shawn Willden9323f412021-01-06 19:15:29 +0000227GetVersion2Response TrustyKeymaster::GetVersion2(const GetVersion2Request& request) {
228 GetVersion2Response response(message_version());
229 ForwardCommand(KM_GET_VERSION_2, request, &response);
230 return response;
231}
232
Shawn Willdenfed81d82021-04-22 13:32:56 -0600233EarlyBootEndedResponse TrustyKeymaster::EarlyBootEnded() {
234 EarlyBootEndedResponse response(message_version());
235 ForwardCommand(KM_EARLY_BOOT_ENDED, EarlyBootEndedRequest(message_version()), &response);
236 return response;
237}
238
239DeviceLockedResponse TrustyKeymaster::DeviceLocked(const DeviceLockedRequest& request) {
240 DeviceLockedResponse response(message_version());
241 ForwardCommand(KM_DEVICE_LOCKED, request, &response);
242 return response;
243}
244
David Drysdalee7697d72021-07-13 12:17:17 +0100245ConfigureVendorPatchlevelResponse TrustyKeymaster::ConfigureVendorPatchlevel(
246 const ConfigureVendorPatchlevelRequest& request) {
247 ConfigureVendorPatchlevelResponse response(message_version());
248 ForwardCommand(KM_CONFIGURE_VENDOR_PATCHLEVEL, request, &response);
249 return response;
250}
251
Roberto Pereira24261972018-07-30 14:54:58 -0700252} // namespace keymaster