qemu/linux-headers/linux/psp-sev.h
<<
>>
Prefs
   1/*
   2 * Userspace interface for AMD Secure Encrypted Virtualization (SEV)
   3 * platform management commands.
   4 *
   5 * Copyright (C) 2016-2017 Advanced Micro Devices, Inc.
   6 *
   7 * Author: Brijesh Singh <brijesh.singh@amd.com>
   8 *
   9 * SEV spec 0.14 is available at:
  10 * http://support.amd.com/TechDocs/55766_SEV-KM%20API_Specification.pdf
  11 *
  12 * This program is free software; you can redistribute it and/or modify
  13 * it under the terms of the GNU General Public License version 2 as
  14 * published by the Free Software Foundation.
  15 */
  16
  17#ifndef __PSP_SEV_USER_H__
  18#define __PSP_SEV_USER_H__
  19
  20#include <linux/types.h>
  21
  22/**
  23 * SEV platform commands
  24 */
  25enum {
  26        SEV_FACTORY_RESET = 0,
  27        SEV_PLATFORM_STATUS,
  28        SEV_PEK_GEN,
  29        SEV_PEK_CSR,
  30        SEV_PDH_GEN,
  31        SEV_PDH_CERT_EXPORT,
  32        SEV_PEK_CERT_IMPORT,
  33        SEV_GET_ID,
  34
  35        SEV_MAX,
  36};
  37
  38/**
  39 * SEV Firmware status code
  40 */
  41typedef enum {
  42        SEV_RET_SUCCESS = 0,
  43        SEV_RET_INVALID_PLATFORM_STATE,
  44        SEV_RET_INVALID_GUEST_STATE,
  45        SEV_RET_INAVLID_CONFIG,
  46        SEV_RET_INVALID_LEN,
  47        SEV_RET_ALREADY_OWNED,
  48        SEV_RET_INVALID_CERTIFICATE,
  49        SEV_RET_POLICY_FAILURE,
  50        SEV_RET_INACTIVE,
  51        SEV_RET_INVALID_ADDRESS,
  52        SEV_RET_BAD_SIGNATURE,
  53        SEV_RET_BAD_MEASUREMENT,
  54        SEV_RET_ASID_OWNED,
  55        SEV_RET_INVALID_ASID,
  56        SEV_RET_WBINVD_REQUIRED,
  57        SEV_RET_DFFLUSH_REQUIRED,
  58        SEV_RET_INVALID_GUEST,
  59        SEV_RET_INVALID_COMMAND,
  60        SEV_RET_ACTIVE,
  61        SEV_RET_HWSEV_RET_PLATFORM,
  62        SEV_RET_HWSEV_RET_UNSAFE,
  63        SEV_RET_UNSUPPORTED,
  64        SEV_RET_MAX,
  65} sev_ret_code;
  66
  67/**
  68 * struct sev_user_data_status - PLATFORM_STATUS command parameters
  69 *
  70 * @major: major API version
  71 * @minor: minor API version
  72 * @state: platform state
  73 * @flags: platform config flags
  74 * @build: firmware build id for API version
  75 * @guest_count: number of active guests
  76 */
  77struct sev_user_data_status {
  78        __u8 api_major;                         /* Out */
  79        __u8 api_minor;                         /* Out */
  80        __u8 state;                             /* Out */
  81        __u32 flags;                            /* Out */
  82        __u8 build;                             /* Out */
  83        __u32 guest_count;                      /* Out */
  84} __attribute__((packed));
  85
  86/**
  87 * struct sev_user_data_pek_csr - PEK_CSR command parameters
  88 *
  89 * @address: PEK certificate chain
  90 * @length: length of certificate
  91 */
  92struct sev_user_data_pek_csr {
  93        __u64 address;                          /* In */
  94        __u32 length;                           /* In/Out */
  95} __attribute__((packed));
  96
  97/**
  98 * struct sev_user_data_cert_import - PEK_CERT_IMPORT command parameters
  99 *
 100 * @pek_address: PEK certificate chain
 101 * @pek_len: length of PEK certificate
 102 * @oca_address: OCA certificate chain
 103 * @oca_len: length of OCA certificate
 104 */
 105struct sev_user_data_pek_cert_import {
 106        __u64 pek_cert_address;                 /* In */
 107        __u32 pek_cert_len;                     /* In */
 108        __u64 oca_cert_address;                 /* In */
 109        __u32 oca_cert_len;                     /* In */
 110} __attribute__((packed));
 111
 112/**
 113 * struct sev_user_data_pdh_cert_export - PDH_CERT_EXPORT command parameters
 114 *
 115 * @pdh_address: PDH certificate address
 116 * @pdh_len: length of PDH certificate
 117 * @cert_chain_address: PDH certificate chain
 118 * @cert_chain_len: length of PDH certificate chain
 119 */
 120struct sev_user_data_pdh_cert_export {
 121        __u64 pdh_cert_address;                 /* In */
 122        __u32 pdh_cert_len;                     /* In/Out */
 123        __u64 cert_chain_address;               /* In */
 124        __u32 cert_chain_len;                   /* In/Out */
 125} __attribute__((packed));
 126
 127/**
 128 * struct sev_user_data_get_id - GET_ID command parameters
 129 *
 130 * @socket1: Buffer to pass unique ID of first socket
 131 * @socket2: Buffer to pass unique ID of second socket
 132 */
 133struct sev_user_data_get_id {
 134        __u8 socket1[64];                       /* Out */
 135        __u8 socket2[64];                       /* Out */
 136} __attribute__((packed));
 137
 138/**
 139 * struct sev_issue_cmd - SEV ioctl parameters
 140 *
 141 * @cmd: SEV commands to execute
 142 * @opaque: pointer to the command structure
 143 * @error: SEV FW return code on failure
 144 */
 145struct sev_issue_cmd {
 146        __u32 cmd;                              /* In */
 147        __u64 data;                             /* In */
 148        __u32 error;                            /* Out */
 149} __attribute__((packed));
 150
 151#define SEV_IOC_TYPE            'S'
 152#define SEV_ISSUE_CMD   _IOWR(SEV_IOC_TYPE, 0x0, struct sev_issue_cmd)
 153
 154#endif /* __PSP_USER_SEV_H */
 155