tee: add private login method for kernel clients
authorSumit Garg <sumit.garg@linaro.org>
Fri, 27 Mar 2020 05:29:48 +0000 (10:59 +0530)
committerJens Wiklander <jens.wiklander@linaro.org>
Mon, 20 Apr 2020 14:18:14 +0000 (16:18 +0200)
There are use-cases where user-space shouldn't be allowed to communicate
directly with a TEE device which is dedicated to provide a specific
service for a kernel client. So add a private login method for kernel
clients and disallow user-space to open-session using GP implementation
defined login method range: (0x80000000 - 0xBFFFFFFF).

Reviewed-by: Jerome Forissier <jerome@forissier.org>
Signed-off-by: Sumit Garg <sumit.garg@linaro.org>
Signed-off-by: Jens Wiklander <jens.wiklander@linaro.org>
drivers/tee/tee_core.c
include/uapi/linux/tee.h

index 6aec502c495cd91354fe486ba24a320418430564..fb907bf437084fe108ab2dda6f400de5e58b890f 100644 (file)
@@ -333,6 +333,13 @@ static int tee_ioctl_open_session(struct tee_context *ctx,
                        goto out;
        }
 
+       if (arg.clnt_login >= TEE_IOCTL_LOGIN_REE_KERNEL_MIN &&
+           arg.clnt_login <= TEE_IOCTL_LOGIN_REE_KERNEL_MAX) {
+               pr_debug("login method not allowed for user-space client\n");
+               rc = -EPERM;
+               goto out;
+       }
+
        rc = ctx->teedev->desc->ops->open_session(ctx, &arg, params);
        if (rc)
                goto out;
index 6596f3a09e543b3ba9b748308a67ba8b124f408c..b619f37ee03e5376b8452e92d7821d395a8107d3 100644 (file)
@@ -173,6 +173,15 @@ struct tee_ioctl_buf_data {
 #define TEE_IOCTL_LOGIN_APPLICATION            4
 #define TEE_IOCTL_LOGIN_USER_APPLICATION       5
 #define TEE_IOCTL_LOGIN_GROUP_APPLICATION      6
+/*
+ * Disallow user-space to use GP implementation specific login
+ * method range (0x80000000 - 0xBFFFFFFF). This range is rather
+ * being reserved for REE kernel clients or TEE implementation.
+ */
+#define TEE_IOCTL_LOGIN_REE_KERNEL_MIN         0x80000000
+#define TEE_IOCTL_LOGIN_REE_KERNEL_MAX         0xBFFFFFFF
+/* Private login method for REE kernel clients */
+#define TEE_IOCTL_LOGIN_REE_KERNEL             0x80000000
 
 /**
  * struct tee_ioctl_param - parameter