From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from foss.arm.com (foss.arm.com [217.140.110.172]) by mx.groups.io with SMTP id smtpd.web08.3237.1663615341061423925 for ; Mon, 19 Sep 2022 12:22:21 -0700 Authentication-Results: mx.groups.io; dkim=missing; spf=pass (domain: arm.com, ip: 217.140.110.172, mailfrom: pierre.gondois@arm.com) Received: from usa-sjc-imap-foss1.foss.arm.com (unknown [10.121.207.14]) by usa-sjc-mx-foss1.foss.arm.com (Postfix) with ESMTP id 267981424; Mon, 19 Sep 2022 12:22:27 -0700 (PDT) Received: from pierre123.arm.com (unknown [172.31.20.19]) by usa-sjc-imap-foss1.foss.arm.com (Postfix) with ESMTPA id 81AB03F73B; Mon, 19 Sep 2022 12:22:18 -0700 (PDT) From: "PierreGondois" To: devel@edk2.groups.io Cc: Sami Mujawar , Leif Lindholm , Ard Biesheuvel , Rebecca Cran , Michael D Kinney , Liming Gao , Jiewen Yao , Jian J Wang Subject: [PATCH v5 00/21] Add Raw algorithm support using Arm FW-TRNG interface Date: Mon, 19 Sep 2022 21:21:46 +0200 Message-Id: <20220919192207.637786-1-Pierre.Gondois@arm.com> X-Mailer: git-send-email 2.25.1 MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable From: Pierre Gondois Bugzilla: Bug 3668 (https://bugzilla.tianocore.org/show_bug.cgi?id=3D3668= ) The Arm True Random Number Generator Firmware, Interface 1.0, specificati= on defines an interface between an Operating System (OS) executing at EL1 an= d Firmware (FW) exposing a conditioned entropy source that is provided by a TRNG back end. This patch-set: - defines a TRNG library class that provides an interface to access the entropy source on a platform. - implements a TRNG library instance that uses the Arm FW-TRNG interface. - Adds RawAlgorithm support to RngDxe for Arm architecture using the Arm FW-TRNG interface. - Enables RNG support using FW-TRNG interface for Kvmtool Guest/Virtual firmware. This patch-set is based on the v2 from Sami Mujawar: [PATCH v2 0/8] Add Raw algorithm support using Arm FW-TRNG interface=20 v2: https://edk2.groups.io/g/devel/message/83775 v3: https://edk2.groups.io/g/devel/message/90845 https://github.com/PierreARM/edk2/tree/Arm_Trng_v3 v4: https://github.com/PierreARM/edk2/tree/Arm_Trng_v4 v5: https://github.com/PierreARM/edk2/tree/Arm_Trng_v V5: - Removed references in Trnglib.h to 'Special Publication' 800-90A and 800-90C, and only reference 'Arm True Random Number Generator Firmware, Interface 1.0' in the Arm implementation of the TrngLib. [Jiewen] V4: - Removed dependencies on ArmPkg and dropped patch: [PATCH v3 12/22] SecurityPkg: Update Securitypkg.ci.yaml [Jiewen] - Use a dynamically allocated array to hold available algorithms. The array is freed in a new UNLOAD_IMAGE function and allocated in arch specific implementations of GetAvailableAlgorithms(), available in AArch64/AArch64Algo.c and Arm/ArmAlgo.c. - Correctly reference gEfiRngAlgorithmSp80090Ctr256Guid Guid by copying its address (add missing '&'). [Jiewen] V3: - Address Leif's comment (moving definitions, optimizations, ...) - Add ArmMonitorLib to choose Hvc/Smc conduit depending on a Pcd. - Re-factor some parts of SecurityPkg/RngDxe/ to ease the addition of new algorithms. - Add ArmHasRngExt() function to check Arm's FEAT_RNG extension. V2: - Updates TrngLib definitions to use RETURN_STATUS as the return type from the interface functions as TrngLib is base type library. - Drops the patch "MdePkg: Add definition for NULL GUID" as there is already an equivalent definition provided by gZeroGuid. Thus, the use of gNullGuid has been replaced with gZeroGuid. Pierre Gondois (13): ArmPkg/ArmMonitorLib: Definition for ArmMonitorLib library class ArmPkg/ArmMonitorLib: Add ArmMonitorLib ArmPkg/ArmHvcNullLib: Add NULL instance of ArmHvcLib MdePkg/BaseRngLib: Rename ArmReadIdIsar0() to ArmGetFeatRng() ArmPkg/ArmLib: Add ArmReadIdIsar0() helper ArmPkg/ArmLib: Add ArmHasRngExt() SecurityPkg/RngDxe: Replace Pcd with Sp80090Ctr256Guid SecurityPkg/RngDxe: Remove ArchGetSupportedRngAlgorithms() SecurityPkg/RngDxe: Documentation/include/parameter cleanup SecurityPkg/RngDxe: Check before advertising Cpu Rng algo SecurityPkg/RngDxe: Add debug warning for NULL PcdCpuRngSupportedAlgorithm SecurityPkg/RngDxe: Rename AArch64/RngDxe.c SecurityPkg/RngDxe: Add Arm support of RngDxe Sami Mujawar (8): ArmPkg: PCD to select conduit for monitor calls MdePkg/TrngLib: Definition for TRNG library class interface MdePkg/TrngLib: Add NULL instance of TRNG Library ArmPkg: Add FID definitions for Firmware TRNG ArmPkg/TrngLib: Add Arm Firmware TRNG library SecurityPkg/RngDxe: Rename RdRandGenerateEntropy to generic name SecurityPkg/RngDxe: Add AArch64 RawAlgorithm support through TrngLib ArmVirtPkg: Kvmtool: Add RNG support using FW-TRNG interface ArmPkg/ArmPkg.dec | 12 +- ArmPkg/ArmPkg.dsc | 3 + ArmPkg/Include/IndustryStandard/ArmStdSmc.h | 109 ++++- ArmPkg/Include/Library/ArmLib.h | 12 +- ArmPkg/Include/Library/ArmMonitorLib.h | 42 ++ ArmPkg/Library/ArmFwTrngLib/ArmFwTrngDefs.h | 50 +++ ArmPkg/Library/ArmFwTrngLib/ArmFwTrngLib.c | 388 ++++++++++++++++++ ArmPkg/Library/ArmFwTrngLib/ArmFwTrngLib.inf | 29 ++ ArmPkg/Library/ArmHvcNullLib/ArmHvcNullLib.c | 29 ++ .../Library/ArmHvcNullLib/ArmHvcNullLib.inf | 22 + ArmPkg/Library/ArmLib/AArch64/AArch64Lib.c | 15 +- ArmPkg/Library/ArmLib/AArch64/AArch64Lib.h | 14 +- .../Library/ArmLib/AArch64/AArch64Support.S | 7 +- ArmPkg/Library/ArmLib/Arm/ArmV7Lib.c | 16 +- ArmPkg/Library/ArmMonitorLib/ArmMonitorLib.c | 34 ++ .../Library/ArmMonitorLib/ArmMonitorLib.inf | 29 ++ ArmVirtPkg/ArmVirtKvmTool.dsc | 10 + ArmVirtPkg/ArmVirtKvmTool.fdf | 5 + MdePkg/Include/Library/TrngLib.h | 103 +++++ .../{ArmReadIdIsar0.S =3D> ArmGetFeatRng.S} | 8 +- .../{ArmReadIdIsar0.asm =3D> ArmGetFeatRng.asm} | 8 +- MdePkg/Library/BaseRngLib/AArch64/ArmRng.h | 2 +- MdePkg/Library/BaseRngLib/AArch64/Rndr.c | 2 +- MdePkg/Library/BaseRngLib/BaseRngLib.inf | 4 +- .../Library/BaseTrngLibNull/BaseTrngLibNull.c | 117 ++++++ .../BaseTrngLibNull/BaseTrngLibNull.inf | 30 ++ .../BaseTrngLibNull/BaseTrngLibNull.uni | 12 + MdePkg/MdePkg.dec | 5 + MdePkg/MdePkg.dsc | 1 + .../RngDxe/AArch64/AArch64Algo.c | 72 ++++ .../RngDxe/Arm/ArmAlgo.c | 51 +++ .../RngDxe/{AArch64/RngDxe.c =3D> ArmRngDxe.c} | 81 +++- .../RandomNumberGenerator/RngDxe/ArmTrng.c | 71 ++++ .../RngDxe/Rand/RdRand.c | 14 +- .../RngDxe/Rand/RdRand.h | 43 -- .../RngDxe/Rand/RngDxe.c | 62 ++- .../RandomNumberGenerator/RngDxe/RngDxe.c | 90 ++-- .../RandomNumberGenerator/RngDxe/RngDxe.inf | 18 +- .../RngDxe/RngDxeInternals.h | 71 ++-- SecurityPkg/SecurityPkg.dsc | 5 +- 40 files changed, 1524 insertions(+), 172 deletions(-) create mode 100644 ArmPkg/Include/Library/ArmMonitorLib.h create mode 100644 ArmPkg/Library/ArmFwTrngLib/ArmFwTrngDefs.h create mode 100644 ArmPkg/Library/ArmFwTrngLib/ArmFwTrngLib.c create mode 100644 ArmPkg/Library/ArmFwTrngLib/ArmFwTrngLib.inf create mode 100644 ArmPkg/Library/ArmHvcNullLib/ArmHvcNullLib.c create mode 100644 ArmPkg/Library/ArmHvcNullLib/ArmHvcNullLib.inf create mode 100644 ArmPkg/Library/ArmMonitorLib/ArmMonitorLib.c create mode 100644 ArmPkg/Library/ArmMonitorLib/ArmMonitorLib.inf create mode 100644 MdePkg/Include/Library/TrngLib.h rename MdePkg/Library/BaseRngLib/AArch64/{ArmReadIdIsar0.S =3D> ArmGetFe= atRng.S} (78%) rename MdePkg/Library/BaseRngLib/AArch64/{ArmReadIdIsar0.asm =3D> ArmGet= FeatRng.asm} (81%) create mode 100644 MdePkg/Library/BaseTrngLibNull/BaseTrngLibNull.c create mode 100644 MdePkg/Library/BaseTrngLibNull/BaseTrngLibNull.inf create mode 100644 MdePkg/Library/BaseTrngLibNull/BaseTrngLibNull.uni create mode 100644 SecurityPkg/RandomNumberGenerator/RngDxe/AArch64/AArc= h64Algo.c create mode 100644 SecurityPkg/RandomNumberGenerator/RngDxe/Arm/ArmAlgo.= c rename SecurityPkg/RandomNumberGenerator/RngDxe/{AArch64/RngDxe.c =3D> A= rmRngDxe.c} (64%) create mode 100644 SecurityPkg/RandomNumberGenerator/RngDxe/ArmTrng.c delete mode 100644 SecurityPkg/RandomNumberGenerator/RngDxe/Rand/RdRand.= h --=20 2.25.1