1 /* SPDX-License-Identifier: GPL-2.0 WITH Linux-syscall-note */
2 /*
3  * Copyright © 2016 Intel Corporation
4  *
5  * Authors:
6  *    Rafael Antognolli <rafael.antognolli@intel.com>
7  *    Scott  Bauer      <scott.bauer@intel.com>
8  */
9 
10 #ifndef _UAPI_SED_OPAL_H
11 #define _UAPI_SED_OPAL_H
12 
13 #include <linux/types.h>
14 
15 #define OPAL_KEY_MAX 256
16 #define OPAL_MAX_LRS 9
17 
18 enum opal_mbr {
19 	OPAL_MBR_ENABLE = 0x0,
20 	OPAL_MBR_DISABLE = 0x01,
21 };
22 
23 enum opal_mbr_done_flag {
24 	OPAL_MBR_NOT_DONE = 0x0,
25 	OPAL_MBR_DONE = 0x01
26 };
27 
28 enum opal_user {
29 	OPAL_ADMIN1 = 0x0,
30 	OPAL_USER1 = 0x01,
31 	OPAL_USER2 = 0x02,
32 	OPAL_USER3 = 0x03,
33 	OPAL_USER4 = 0x04,
34 	OPAL_USER5 = 0x05,
35 	OPAL_USER6 = 0x06,
36 	OPAL_USER7 = 0x07,
37 	OPAL_USER8 = 0x08,
38 	OPAL_USER9 = 0x09,
39 };
40 
41 enum opal_lock_state {
42 	OPAL_RO = 0x01, /* 0001 */
43 	OPAL_RW = 0x02, /* 0010 */
44 	OPAL_LK = 0x04, /* 0100 */
45 };
46 
47 enum opal_lock_flags {
48 	/* IOC_OPAL_SAVE will also store the provided key for locking */
49 	OPAL_SAVE_FOR_LOCK = 0x01,
50 };
51 
52 struct opal_key {
53 	__u8 lr;
54 	__u8 key_len;
55 	__u8 __align[6];
56 	__u8 key[OPAL_KEY_MAX];
57 };
58 
59 struct opal_lr_act {
60 	struct opal_key key;
61 	__u32 sum;
62 	__u8 num_lrs;
63 	__u8 lr[OPAL_MAX_LRS];
64 	__u8 align[2]; /* Align to 8 byte boundary */
65 };
66 
67 struct opal_session_info {
68 	__u32 sum;
69 	__u32 who;
70 	struct opal_key opal_key;
71 };
72 
73 struct opal_user_lr_setup {
74 	__u64 range_start;
75 	__u64 range_length;
76 	__u32 RLE; /* Read Lock enabled */
77 	__u32 WLE; /* Write Lock Enabled */
78 	struct opal_session_info session;
79 };
80 
81 struct opal_lock_unlock {
82 	struct opal_session_info session;
83 	__u32 l_state;
84 	__u16 flags;
85 	__u8 __align[2];
86 };
87 
88 struct opal_new_pw {
89 	struct opal_session_info session;
90 
91 	/* When we're not operating in sum, and we first set
92 	 * passwords we need to set them via ADMIN authority.
93 	 * After passwords are changed, we can set them via,
94 	 * User authorities.
95 	 * Because of this restriction we need to know about
96 	 * Two different users. One in 'session' which we will use
97 	 * to start the session and new_userr_pw as the user we're
98 	 * chaning the pw for.
99 	 */
100 	struct opal_session_info new_user_pw;
101 };
102 
103 struct opal_mbr_data {
104 	struct opal_key key;
105 	__u8 enable_disable;
106 	__u8 __align[7];
107 };
108 
109 struct opal_mbr_done {
110 	struct opal_key key;
111 	__u8 done_flag;
112 	__u8 __align[7];
113 };
114 
115 struct opal_shadow_mbr {
116 	struct opal_key key;
117 	const __u64 data;
118 	__u64 offset;
119 	__u64 size;
120 };
121 
122 /* Opal table operations */
123 enum opal_table_ops {
124 	OPAL_READ_TABLE,
125 	OPAL_WRITE_TABLE,
126 };
127 
128 #define OPAL_UID_LENGTH 8
129 struct opal_read_write_table {
130 	struct opal_key key;
131 	const __u64 data;
132 	const __u8 table_uid[OPAL_UID_LENGTH];
133 	__u64 offset;
134 	__u64 size;
135 #define OPAL_TABLE_READ (1 << OPAL_READ_TABLE)
136 #define OPAL_TABLE_WRITE (1 << OPAL_WRITE_TABLE)
137 	__u64 flags;
138 	__u64 priv;
139 };
140 
141 #define OPAL_FL_SUPPORTED		0x00000001
142 #define OPAL_FL_LOCKING_SUPPORTED	0x00000002
143 #define OPAL_FL_LOCKING_ENABLED		0x00000004
144 #define OPAL_FL_LOCKED			0x00000008
145 #define OPAL_FL_MBR_ENABLED		0x00000010
146 #define OPAL_FL_MBR_DONE		0x00000020
147 #define OPAL_FL_SUM_SUPPORTED		0x00000040
148 
149 struct opal_status {
150 	__u32 flags;
151 	__u32 reserved;
152 };
153 
154 #define IOC_OPAL_SAVE		    _IOW('p', 220, struct opal_lock_unlock)
155 #define IOC_OPAL_LOCK_UNLOCK	    _IOW('p', 221, struct opal_lock_unlock)
156 #define IOC_OPAL_TAKE_OWNERSHIP	    _IOW('p', 222, struct opal_key)
157 #define IOC_OPAL_ACTIVATE_LSP       _IOW('p', 223, struct opal_lr_act)
158 #define IOC_OPAL_SET_PW             _IOW('p', 224, struct opal_new_pw)
159 #define IOC_OPAL_ACTIVATE_USR       _IOW('p', 225, struct opal_session_info)
160 #define IOC_OPAL_REVERT_TPR         _IOW('p', 226, struct opal_key)
161 #define IOC_OPAL_LR_SETUP           _IOW('p', 227, struct opal_user_lr_setup)
162 #define IOC_OPAL_ADD_USR_TO_LR      _IOW('p', 228, struct opal_lock_unlock)
163 #define IOC_OPAL_ENABLE_DISABLE_MBR _IOW('p', 229, struct opal_mbr_data)
164 #define IOC_OPAL_ERASE_LR           _IOW('p', 230, struct opal_session_info)
165 #define IOC_OPAL_SECURE_ERASE_LR    _IOW('p', 231, struct opal_session_info)
166 #define IOC_OPAL_PSID_REVERT_TPR    _IOW('p', 232, struct opal_key)
167 #define IOC_OPAL_MBR_DONE           _IOW('p', 233, struct opal_mbr_done)
168 #define IOC_OPAL_WRITE_SHADOW_MBR   _IOW('p', 234, struct opal_shadow_mbr)
169 #define IOC_OPAL_GENERIC_TABLE_RW   _IOW('p', 235, struct opal_read_write_table)
170 #define IOC_OPAL_GET_STATUS         _IOR('p', 236, struct opal_status)
171 
172 #endif /* _UAPI_SED_OPAL_H */
173