1 // SPDX-License-Identifier: GPL-2.0
2 /*
3 * chaoskey - driver for ChaosKey device from Altus Metrum.
4 *
5 * This device provides true random numbers using a noise source based
6 * on a reverse-biased p-n junction in avalanche breakdown. More
7 * details can be found at http://chaoskey.org
8 *
9 * The driver connects to the kernel hardware RNG interface to provide
10 * entropy for /dev/random and other kernel activities. It also offers
11 * a separate /dev/ entry to allow for direct access to the random
12 * bit stream.
13 *
14 * Copyright © 2015 Keith Packard <keithp@keithp.com>
15 */
16
17 #include <linux/module.h>
18 #include <linux/slab.h>
19 #include <linux/usb.h>
20 #include <linux/wait.h>
21 #include <linux/hw_random.h>
22 #include <linux/mutex.h>
23 #include <linux/uaccess.h>
24
25 static struct usb_driver chaoskey_driver;
26 static struct usb_class_driver chaoskey_class;
27 static int chaoskey_rng_read(struct hwrng *rng, void *data,
28 size_t max, bool wait);
29
30 #define usb_dbg(usb_if, format, arg...) \
31 dev_dbg(&(usb_if)->dev, format, ## arg)
32
33 #define usb_err(usb_if, format, arg...) \
34 dev_err(&(usb_if)->dev, format, ## arg)
35
36 /* Version Information */
37 #define DRIVER_AUTHOR "Keith Packard, keithp@keithp.com"
38 #define DRIVER_DESC "Altus Metrum ChaosKey driver"
39 #define DRIVER_SHORT "chaoskey"
40
41 MODULE_AUTHOR(DRIVER_AUTHOR);
42 MODULE_DESCRIPTION(DRIVER_DESC);
43 MODULE_LICENSE("GPL");
44
45 #define CHAOSKEY_VENDOR_ID 0x1d50 /* OpenMoko */
46 #define CHAOSKEY_PRODUCT_ID 0x60c6 /* ChaosKey */
47
48 #define ALEA_VENDOR_ID 0x12d8 /* Araneus */
49 #define ALEA_PRODUCT_ID 0x0001 /* Alea I */
50
51 #define CHAOSKEY_BUF_LEN 64 /* max size of USB full speed packet */
52
53 #define NAK_TIMEOUT (HZ) /* normal stall/wait timeout */
54 #define ALEA_FIRST_TIMEOUT (HZ*3) /* first stall/wait timeout for Alea */
55
56 #ifdef CONFIG_USB_DYNAMIC_MINORS
57 #define USB_CHAOSKEY_MINOR_BASE 0
58 #else
59
60 /* IOWARRIOR_MINOR_BASE + 16, not official yet */
61 #define USB_CHAOSKEY_MINOR_BASE 224
62 #endif
63
64 static const struct usb_device_id chaoskey_table[] = {
65 { USB_DEVICE(CHAOSKEY_VENDOR_ID, CHAOSKEY_PRODUCT_ID) },
66 { USB_DEVICE(ALEA_VENDOR_ID, ALEA_PRODUCT_ID) },
67 { },
68 };
69 MODULE_DEVICE_TABLE(usb, chaoskey_table);
70
71 static void chaos_read_callback(struct urb *urb);
72
73 /* Driver-local specific stuff */
74 struct chaoskey {
75 struct usb_interface *interface;
76 char in_ep;
77 struct mutex lock;
78 struct mutex rng_lock;
79 int open; /* open count */
80 bool present; /* device not disconnected */
81 bool reading; /* ongoing IO */
82 bool reads_started; /* track first read for Alea */
83 int size; /* size of buf */
84 int valid; /* bytes of buf read */
85 int used; /* bytes of buf consumed */
86 char *name; /* product + serial */
87 struct hwrng hwrng; /* Embedded struct for hwrng */
88 int hwrng_registered; /* registered with hwrng API */
89 wait_queue_head_t wait_q; /* for timeouts */
90 struct urb *urb; /* for performing IO */
91 char *buf;
92 };
93
chaoskey_free(struct chaoskey * dev)94 static void chaoskey_free(struct chaoskey *dev)
95 {
96 if (dev) {
97 usb_dbg(dev->interface, "free");
98 usb_free_urb(dev->urb);
99 kfree(dev->name);
100 kfree(dev->buf);
101 usb_put_intf(dev->interface);
102 kfree(dev);
103 }
104 }
105
chaoskey_probe(struct usb_interface * interface,const struct usb_device_id * id)106 static int chaoskey_probe(struct usb_interface *interface,
107 const struct usb_device_id *id)
108 {
109 struct usb_device *udev = interface_to_usbdev(interface);
110 struct usb_host_interface *altsetting = interface->cur_altsetting;
111 struct usb_endpoint_descriptor *epd;
112 int in_ep;
113 struct chaoskey *dev;
114 int result = -ENOMEM;
115 int size;
116 int res;
117
118 usb_dbg(interface, "probe %s-%s", udev->product, udev->serial);
119
120 /* Find the first bulk IN endpoint and its packet size */
121 res = usb_find_bulk_in_endpoint(altsetting, &epd);
122 if (res) {
123 usb_dbg(interface, "no IN endpoint found");
124 return res;
125 }
126
127 in_ep = usb_endpoint_num(epd);
128 size = usb_endpoint_maxp(epd);
129
130 /* Validate endpoint and size */
131 if (size <= 0) {
132 usb_dbg(interface, "invalid size (%d)", size);
133 return -ENODEV;
134 }
135
136 if (size > CHAOSKEY_BUF_LEN) {
137 usb_dbg(interface, "size reduced from %d to %d\n",
138 size, CHAOSKEY_BUF_LEN);
139 size = CHAOSKEY_BUF_LEN;
140 }
141
142 /* Looks good, allocate and initialize */
143
144 dev = kzalloc(sizeof(struct chaoskey), GFP_KERNEL);
145
146 if (dev == NULL)
147 goto out;
148
149 dev->interface = usb_get_intf(interface);
150
151 dev->buf = kmalloc(size, GFP_KERNEL);
152
153 if (dev->buf == NULL)
154 goto out;
155
156 dev->urb = usb_alloc_urb(0, GFP_KERNEL);
157
158 if (!dev->urb)
159 goto out;
160
161 usb_fill_bulk_urb(dev->urb,
162 udev,
163 usb_rcvbulkpipe(udev, in_ep),
164 dev->buf,
165 size,
166 chaos_read_callback,
167 dev);
168
169 /* Construct a name using the product and serial values. Each
170 * device needs a unique name for the hwrng code
171 */
172
173 if (udev->product && udev->serial) {
174 dev->name = kasprintf(GFP_KERNEL, "%s-%s", udev->product,
175 udev->serial);
176 if (dev->name == NULL)
177 goto out;
178 }
179
180 dev->in_ep = in_ep;
181
182 if (le16_to_cpu(udev->descriptor.idVendor) != ALEA_VENDOR_ID)
183 dev->reads_started = true;
184
185 dev->size = size;
186 dev->present = true;
187
188 init_waitqueue_head(&dev->wait_q);
189
190 mutex_init(&dev->lock);
191 mutex_init(&dev->rng_lock);
192
193 usb_set_intfdata(interface, dev);
194
195 result = usb_register_dev(interface, &chaoskey_class);
196 if (result) {
197 usb_err(interface, "Unable to allocate minor number.");
198 goto out;
199 }
200
201 dev->hwrng.name = dev->name ? dev->name : chaoskey_driver.name;
202 dev->hwrng.read = chaoskey_rng_read;
203 dev->hwrng.quality = 1024;
204
205 dev->hwrng_registered = (hwrng_register(&dev->hwrng) == 0);
206 if (!dev->hwrng_registered)
207 usb_err(interface, "Unable to register with hwrng");
208
209 usb_enable_autosuspend(udev);
210
211 usb_dbg(interface, "chaoskey probe success, size %d", dev->size);
212 return 0;
213
214 out:
215 usb_set_intfdata(interface, NULL);
216 chaoskey_free(dev);
217 return result;
218 }
219
chaoskey_disconnect(struct usb_interface * interface)220 static void chaoskey_disconnect(struct usb_interface *interface)
221 {
222 struct chaoskey *dev;
223
224 usb_dbg(interface, "disconnect");
225 dev = usb_get_intfdata(interface);
226 if (!dev) {
227 usb_dbg(interface, "disconnect failed - no dev");
228 return;
229 }
230
231 if (dev->hwrng_registered)
232 hwrng_unregister(&dev->hwrng);
233
234 usb_deregister_dev(interface, &chaoskey_class);
235
236 usb_set_intfdata(interface, NULL);
237 mutex_lock(&dev->lock);
238
239 dev->present = false;
240 usb_poison_urb(dev->urb);
241
242 if (!dev->open) {
243 mutex_unlock(&dev->lock);
244 chaoskey_free(dev);
245 } else
246 mutex_unlock(&dev->lock);
247
248 usb_dbg(interface, "disconnect done");
249 }
250
chaoskey_open(struct inode * inode,struct file * file)251 static int chaoskey_open(struct inode *inode, struct file *file)
252 {
253 struct chaoskey *dev;
254 struct usb_interface *interface;
255
256 /* get the interface from minor number and driver information */
257 interface = usb_find_interface(&chaoskey_driver, iminor(inode));
258 if (!interface)
259 return -ENODEV;
260
261 usb_dbg(interface, "open");
262
263 dev = usb_get_intfdata(interface);
264 if (!dev) {
265 usb_dbg(interface, "open (dev)");
266 return -ENODEV;
267 }
268
269 file->private_data = dev;
270 mutex_lock(&dev->lock);
271 ++dev->open;
272 mutex_unlock(&dev->lock);
273
274 usb_dbg(interface, "open success");
275 return 0;
276 }
277
chaoskey_release(struct inode * inode,struct file * file)278 static int chaoskey_release(struct inode *inode, struct file *file)
279 {
280 struct chaoskey *dev = file->private_data;
281 struct usb_interface *interface;
282
283 if (dev == NULL)
284 return -ENODEV;
285
286 interface = dev->interface;
287
288 usb_dbg(interface, "release");
289
290 mutex_lock(&dev->lock);
291
292 usb_dbg(interface, "open count at release is %d", dev->open);
293
294 if (dev->open <= 0) {
295 usb_dbg(interface, "invalid open count (%d)", dev->open);
296 mutex_unlock(&dev->lock);
297 return -ENODEV;
298 }
299
300 --dev->open;
301
302 if (!dev->present) {
303 if (dev->open == 0) {
304 mutex_unlock(&dev->lock);
305 chaoskey_free(dev);
306 } else
307 mutex_unlock(&dev->lock);
308 } else
309 mutex_unlock(&dev->lock);
310
311 usb_dbg(interface, "release success");
312 return 0;
313 }
314
chaos_read_callback(struct urb * urb)315 static void chaos_read_callback(struct urb *urb)
316 {
317 struct chaoskey *dev = urb->context;
318 int status = urb->status;
319
320 usb_dbg(dev->interface, "callback status (%d)", status);
321
322 if (status == 0)
323 dev->valid = urb->actual_length;
324 else
325 dev->valid = 0;
326
327 dev->used = 0;
328
329 /* must be seen first before validity is announced */
330 smp_wmb();
331
332 dev->reading = false;
333 wake_up(&dev->wait_q);
334 }
335
336 /* Fill the buffer. Called with dev->lock held
337 */
_chaoskey_fill(struct chaoskey * dev)338 static int _chaoskey_fill(struct chaoskey *dev)
339 {
340 DEFINE_WAIT(wait);
341 int result;
342 bool started;
343
344 usb_dbg(dev->interface, "fill");
345
346 /* Return immediately if someone called before the buffer was
347 * empty */
348 if (dev->valid != dev->used) {
349 usb_dbg(dev->interface, "not empty yet (valid %d used %d)",
350 dev->valid, dev->used);
351 return 0;
352 }
353
354 /* Bail if the device has been removed */
355 if (!dev->present) {
356 usb_dbg(dev->interface, "device not present");
357 return -ENODEV;
358 }
359
360 /* Make sure the device is awake */
361 result = usb_autopm_get_interface(dev->interface);
362 if (result) {
363 usb_dbg(dev->interface, "wakeup failed (result %d)", result);
364 return result;
365 }
366
367 dev->reading = true;
368 result = usb_submit_urb(dev->urb, GFP_KERNEL);
369 if (result < 0) {
370 result = usb_translate_errors(result);
371 dev->reading = false;
372 goto out;
373 }
374
375 /* The first read on the Alea takes a little under 2 seconds.
376 * Reads after the first read take only a few microseconds
377 * though. Presumably the entropy-generating circuit needs
378 * time to ramp up. So, we wait longer on the first read.
379 */
380 started = dev->reads_started;
381 dev->reads_started = true;
382 result = wait_event_interruptible_timeout(
383 dev->wait_q,
384 !dev->reading,
385 (started ? NAK_TIMEOUT : ALEA_FIRST_TIMEOUT) );
386
387 if (result < 0)
388 goto out;
389
390 if (result == 0)
391 result = -ETIMEDOUT;
392 else
393 result = dev->valid;
394 out:
395 /* Let the device go back to sleep eventually */
396 usb_autopm_put_interface(dev->interface);
397
398 usb_dbg(dev->interface, "read %d bytes", dev->valid);
399
400 return result;
401 }
402
chaoskey_read(struct file * file,char __user * buffer,size_t count,loff_t * ppos)403 static ssize_t chaoskey_read(struct file *file,
404 char __user *buffer,
405 size_t count,
406 loff_t *ppos)
407 {
408 struct chaoskey *dev;
409 ssize_t read_count = 0;
410 int this_time;
411 int result = 0;
412 unsigned long remain;
413
414 dev = file->private_data;
415
416 if (dev == NULL || !dev->present)
417 return -ENODEV;
418
419 usb_dbg(dev->interface, "read %zu", count);
420
421 while (count > 0) {
422
423 /* Grab the rng_lock briefly to ensure that the hwrng interface
424 * gets priority over other user access
425 */
426 result = mutex_lock_interruptible(&dev->rng_lock);
427 if (result)
428 goto bail;
429 mutex_unlock(&dev->rng_lock);
430
431 result = mutex_lock_interruptible(&dev->lock);
432 if (result)
433 goto bail;
434 if (dev->valid == dev->used) {
435 result = _chaoskey_fill(dev);
436 if (result < 0) {
437 mutex_unlock(&dev->lock);
438 goto bail;
439 }
440 }
441
442 this_time = dev->valid - dev->used;
443 if (this_time > count)
444 this_time = count;
445
446 remain = copy_to_user(buffer, dev->buf + dev->used, this_time);
447 if (remain) {
448 result = -EFAULT;
449
450 /* Consume the bytes that were copied so we don't leak
451 * data to user space
452 */
453 dev->used += this_time - remain;
454 mutex_unlock(&dev->lock);
455 goto bail;
456 }
457
458 count -= this_time;
459 read_count += this_time;
460 buffer += this_time;
461 dev->used += this_time;
462 mutex_unlock(&dev->lock);
463 }
464 bail:
465 if (read_count) {
466 usb_dbg(dev->interface, "read %zu bytes", read_count);
467 return read_count;
468 }
469 usb_dbg(dev->interface, "empty read, result %d", result);
470 if (result == -ETIMEDOUT)
471 result = -EAGAIN;
472 return result;
473 }
474
chaoskey_rng_read(struct hwrng * rng,void * data,size_t max,bool wait)475 static int chaoskey_rng_read(struct hwrng *rng, void *data,
476 size_t max, bool wait)
477 {
478 struct chaoskey *dev = container_of(rng, struct chaoskey, hwrng);
479 int this_time;
480
481 usb_dbg(dev->interface, "rng_read max %zu wait %d", max, wait);
482
483 if (!dev->present) {
484 usb_dbg(dev->interface, "device not present");
485 return 0;
486 }
487
488 /* Hold the rng_lock until we acquire the device lock so that
489 * this operation gets priority over other user access to the
490 * device
491 */
492 mutex_lock(&dev->rng_lock);
493
494 mutex_lock(&dev->lock);
495
496 mutex_unlock(&dev->rng_lock);
497
498 /* Try to fill the buffer if empty. It doesn't actually matter
499 * if _chaoskey_fill works; we'll just return zero bytes as
500 * the buffer will still be empty
501 */
502 if (dev->valid == dev->used)
503 (void) _chaoskey_fill(dev);
504
505 this_time = dev->valid - dev->used;
506 if (this_time > max)
507 this_time = max;
508
509 memcpy(data, dev->buf + dev->used, this_time);
510
511 dev->used += this_time;
512
513 mutex_unlock(&dev->lock);
514
515 usb_dbg(dev->interface, "rng_read this_time %d\n", this_time);
516 return this_time;
517 }
518
519 #ifdef CONFIG_PM
chaoskey_suspend(struct usb_interface * interface,pm_message_t message)520 static int chaoskey_suspend(struct usb_interface *interface,
521 pm_message_t message)
522 {
523 usb_dbg(interface, "suspend");
524 return 0;
525 }
526
chaoskey_resume(struct usb_interface * interface)527 static int chaoskey_resume(struct usb_interface *interface)
528 {
529 usb_dbg(interface, "resume");
530 return 0;
531 }
532 #else
533 #define chaoskey_suspend NULL
534 #define chaoskey_resume NULL
535 #endif
536
537 /* file operation pointers */
538 static const struct file_operations chaoskey_fops = {
539 .owner = THIS_MODULE,
540 .read = chaoskey_read,
541 .open = chaoskey_open,
542 .release = chaoskey_release,
543 .llseek = default_llseek,
544 };
545
546 /* class driver information */
547 static struct usb_class_driver chaoskey_class = {
548 .name = "chaoskey%d",
549 .fops = &chaoskey_fops,
550 .minor_base = USB_CHAOSKEY_MINOR_BASE,
551 };
552
553 /* usb specific object needed to register this driver with the usb subsystem */
554 static struct usb_driver chaoskey_driver = {
555 .name = DRIVER_SHORT,
556 .probe = chaoskey_probe,
557 .disconnect = chaoskey_disconnect,
558 .suspend = chaoskey_suspend,
559 .resume = chaoskey_resume,
560 .reset_resume = chaoskey_resume,
561 .id_table = chaoskey_table,
562 .supports_autosuspend = 1,
563 };
564
565 module_usb_driver(chaoskey_driver);
566
567