drivers/misc/open-dice.c | 51 +++++++++++++++++++++++++++++----------- 1 file changed, 37 insertions(+), 14 deletions(-)
OpenDICE can also used on x86 platforms for attestation, one of the
usecase is Android's protected VM.
The OpenDICE device driver only supports device tree, adding ACPI
support so it can also be used on x86 environments easily.
The patch is verified using crosvm, with the following ACPI table passed
using --acpi-table, with --file-backed-mapping for the corresponding
memory region.
DefinitionBlock (
"opendice.aml", "SSDT", 2, "GOOGLE", "OpenDICE", 0x00000001
)
{
Scope (\_SB)
{
Device (DICE)
{
Name (_HID, "PRP0001")
Name (_DSD, Package () {
ToUUID ("daffd814-6eba-4d8c-8a91-bc9bbf4aa301"),
Package () {
Package () {
"compatible",
Package () { "google,open-dice" }
}
}
})
Name (_CRS, ResourceTemplate () {
Memory32Fixed (ReadOnly, 0x9D1C3000, 0x00001000)
})
}
}
}
Signed-off-by: Song Guo <songguo@google.com>
---
drivers/misc/open-dice.c | 51 +++++++++++++++++++++++++++++-----------
1 file changed, 37 insertions(+), 14 deletions(-)
diff --git a/drivers/misc/open-dice.c b/drivers/misc/open-dice.c
index 45060fb4ea27..303b35b03cb4 100644
--- a/drivers/misc/open-dice.c
+++ b/drivers/misc/open-dice.c
@@ -2,6 +2,7 @@
/*
* Copyright (C) 2021 - Google LLC
* Author: David Brazdil <dbrazdil@google.com>
+ * Author: Song Guo <songguo@google.com>
*
* Driver for Open Profile for DICE.
*
@@ -19,6 +20,7 @@
* close(fd);
*/
+#include <linux/acpi.h>
#include <linux/io.h>
#include <linux/miscdevice.h>
#include <linux/mm.h>
@@ -31,7 +33,8 @@
struct open_dice_drvdata {
struct mutex lock;
char name[16];
- struct reserved_mem *rmem;
+ phys_addr_t mem_base;
+ resource_size_t mem_size;
struct miscdevice misc;
};
@@ -45,14 +48,14 @@ static int open_dice_wipe(struct open_dice_drvdata *drvdata)
void *kaddr;
mutex_lock(&drvdata->lock);
- kaddr = devm_memremap(drvdata->misc.this_device, drvdata->rmem->base,
- drvdata->rmem->size, MEMREMAP_WC);
+ kaddr = devm_memremap(drvdata->misc.this_device, drvdata->mem_base,
+ drvdata->mem_size, MEMREMAP_WC);
if (IS_ERR(kaddr)) {
mutex_unlock(&drvdata->lock);
return PTR_ERR(kaddr);
}
- memset(kaddr, 0, drvdata->rmem->size);
+ memset(kaddr, 0, drvdata->mem_size);
devm_memunmap(drvdata->misc.this_device, kaddr);
mutex_unlock(&drvdata->lock);
return 0;
@@ -64,7 +67,7 @@ static int open_dice_wipe(struct open_dice_drvdata *drvdata)
static ssize_t open_dice_read(struct file *filp, char __user *ptr, size_t len,
loff_t *off)
{
- unsigned long val = to_open_dice_drvdata(filp)->rmem->size;
+ unsigned long val = to_open_dice_drvdata(filp)->mem_size;
return simple_read_from_buffer(ptr, len, off, &val, sizeof(val));
}
@@ -102,8 +105,8 @@ static int open_dice_mmap_prepare(struct vm_area_desc *desc)
/* Create write-combine mapping so all clients observe a wipe. */
desc->page_prot = pgprot_writecombine(desc->page_prot);
vma_desc_set_flags(desc, VMA_DONTCOPY_BIT, VMA_DONTDUMP_BIT);
- mmap_action_simple_ioremap(desc, drvdata->rmem->base,
- drvdata->rmem->size);
+ mmap_action_simple_ioremap(desc, drvdata->mem_base,
+ drvdata->mem_size);
return 0;
}
@@ -118,22 +121,40 @@ static int __init open_dice_probe(struct platform_device *pdev)
{
static unsigned int dev_idx;
struct device *dev = &pdev->dev;
- struct reserved_mem *rmem;
struct open_dice_drvdata *drvdata;
+ phys_addr_t mem_base;
+ resource_size_t mem_size;
int ret;
- rmem = of_reserved_mem_lookup(dev->of_node);
- if (!rmem) {
- dev_err(dev, "failed to lookup reserved memory\n");
+ if (dev->of_node) {
+ struct reserved_mem *rmem = of_reserved_mem_lookup(dev->of_node);
+
+ if (!rmem) {
+ dev_err(dev, "failed to lookup reserved memory\n");
+ return -EINVAL;
+ }
+ mem_base = rmem->base;
+ mem_size = rmem->size;
+ } else if (is_acpi_node(dev->fwnode)) {
+ struct resource *res = platform_get_resource(pdev, IORESOURCE_MEM, 0);
+
+ if (!res) {
+ dev_err(dev, "failed to get MMIO resource\n");
+ return -EINVAL;
+ }
+ mem_base = res->start;
+ mem_size = resource_size(res);
+ } else {
+ dev_err(dev, "device not supported (no DT or ACPI node)\n");
return -EINVAL;
}
- if (!rmem->size || (rmem->size > ULONG_MAX)) {
+ if (!mem_size || (mem_size > ULONG_MAX)) {
dev_err(dev, "invalid memory region size\n");
return -EINVAL;
}
- if (!PAGE_ALIGNED(rmem->base) || !PAGE_ALIGNED(rmem->size)) {
+ if (!PAGE_ALIGNED(mem_base) || !PAGE_ALIGNED(mem_size)) {
dev_err(dev, "memory region must be page-aligned\n");
return -EINVAL;
}
@@ -143,7 +164,8 @@ static int __init open_dice_probe(struct platform_device *pdev)
return -ENOMEM;
*drvdata = (struct open_dice_drvdata){
- .rmem = rmem,
+ .mem_base = mem_base,
+ .mem_size = mem_size,
.misc = (struct miscdevice){
.parent = dev,
.name = drvdata->name,
@@ -207,3 +229,4 @@ module_exit(open_dice_exit);
MODULE_DESCRIPTION("Driver for Open Profile for DICE.");
MODULE_LICENSE("GPL v2");
MODULE_AUTHOR("David Brazdil <dbrazdil@google.com>");
+MODULE_AUTHOR("Song Guo <songguo@google.com>");
--
2.55.0.141.g00534a21ce-goog
On Wed, Jul 15, 2026 at 08:18:20AM +0000, Song Guo wrote:
> OpenDICE can also used on x86 platforms for attestation, one of the
> usecase is Android's protected VM.
>
> The OpenDICE device driver only supports device tree, adding ACPI
> support so it can also be used on x86 environments easily.
>
> The patch is verified using crosvm, with the following ACPI table passed
> using --acpi-table, with --file-backed-mapping for the corresponding
> memory region.
>
> DefinitionBlock (
> "opendice.aml", "SSDT", 2, "GOOGLE", "OpenDICE", 0x00000001
> )
> {
> Scope (\_SB)
> {
> Device (DICE)
> {
> Name (_HID, "PRP0001")
>
> Name (_DSD, Package () {
> ToUUID ("daffd814-6eba-4d8c-8a91-bc9bbf4aa301"),
> Package () {
> Package () {
> "compatible",
> Package () { "google,open-dice" }
> }
> }
> })
>
> Name (_CRS, ResourceTemplate () {
> Memory32Fixed (ReadOnly, 0x9D1C3000, 0x00001000)
> })
> }
> }
> }
>
> Signed-off-by: Song Guo <songguo@google.com>
> ---
> drivers/misc/open-dice.c | 51 +++++++++++++++++++++++++++++-----------
> 1 file changed, 37 insertions(+), 14 deletions(-)
>
> diff --git a/drivers/misc/open-dice.c b/drivers/misc/open-dice.c
> index 45060fb4ea27..303b35b03cb4 100644
> --- a/drivers/misc/open-dice.c
> +++ b/drivers/misc/open-dice.c
> @@ -2,6 +2,7 @@
> /*
> * Copyright (C) 2021 - Google LLC
> * Author: David Brazdil <dbrazdil@google.com>
> + * Author: Song Guo <songguo@google.com>
> *
> * Driver for Open Profile for DICE.
> *
> @@ -19,6 +20,7 @@
> * close(fd);
> */
>
> +#include <linux/acpi.h>
> #include <linux/io.h>
> #include <linux/miscdevice.h>
> #include <linux/mm.h>
> @@ -31,7 +33,8 @@
> struct open_dice_drvdata {
> struct mutex lock;
> char name[16];
> - struct reserved_mem *rmem;
> + phys_addr_t mem_base;
> + resource_size_t mem_size;
Shouldn't this be a 2 patch series, the first converting to use these
two variables instead of reserved_mem, and the second adding ACPI
support? Otherwise you are mixing the two different things here and
it's a bit hard to follow.
thanks,
greg k-h
On Wed, Jul 15, 2026 at 12:07 PM Greg Kroah-Hartman
<gregkh@linuxfoundation.org> wrote:
>
> On Wed, Jul 15, 2026 at 08:18:20AM +0000, Song Guo wrote:
> > OpenDICE can also used on x86 platforms for attestation, one of the
> > usecase is Android's protected VM.
> >
> > The OpenDICE device driver only supports device tree, adding ACPI
> > support so it can also be used on x86 environments easily.
> >
> > The patch is verified using crosvm, with the following ACPI table passed
> > using --acpi-table, with --file-backed-mapping for the corresponding
> > memory region.
> >
> > DefinitionBlock (
> > "opendice.aml", "SSDT", 2, "GOOGLE", "OpenDICE", 0x00000001
> > )
> > {
> > Scope (\_SB)
> > {
> > Device (DICE)
> > {
> > Name (_HID, "PRP0001")
> >
> > Name (_DSD, Package () {
> > ToUUID ("daffd814-6eba-4d8c-8a91-bc9bbf4aa301"),
> > Package () {
> > Package () {
> > "compatible",
> > Package () { "google,open-dice" }
> > }
> > }
> > })
> >
> > Name (_CRS, ResourceTemplate () {
> > Memory32Fixed (ReadOnly, 0x9D1C3000, 0x00001000)
> > })
> > }
> > }
> > }
> >
> > Signed-off-by: Song Guo <songguo@google.com>
> > ---
> > drivers/misc/open-dice.c | 51 +++++++++++++++++++++++++++++-----------
> > 1 file changed, 37 insertions(+), 14 deletions(-)
> >
> > diff --git a/drivers/misc/open-dice.c b/drivers/misc/open-dice.c
> > index 45060fb4ea27..303b35b03cb4 100644
> > --- a/drivers/misc/open-dice.c
> > +++ b/drivers/misc/open-dice.c
> > @@ -2,6 +2,7 @@
> > /*
> > * Copyright (C) 2021 - Google LLC
> > * Author: David Brazdil <dbrazdil@google.com>
> > + * Author: Song Guo <songguo@google.com>
> > *
> > * Driver for Open Profile for DICE.
> > *
> > @@ -19,6 +20,7 @@
> > * close(fd);
> > */
> >
> > +#include <linux/acpi.h>
> > #include <linux/io.h>
> > #include <linux/miscdevice.h>
> > #include <linux/mm.h>
> > @@ -31,7 +33,8 @@
> > struct open_dice_drvdata {
> > struct mutex lock;
> > char name[16];
> > - struct reserved_mem *rmem;
> > + phys_addr_t mem_base;
> > + resource_size_t mem_size;
>
> Shouldn't this be a 2 patch series, the first converting to use these
> two variables instead of reserved_mem, and the second adding ACPI
> support? Otherwise you are mixing the two different things here and
> it's a bit hard to follow.
Thanks for the quick comment!
After reviewing the changes, I feel it's better to have three instead
of two. To make the changes atomic, and have clearer commit messages
for each commit.
I'm splitting it into:
- check nullness of of_node
- use two variables instead of reserved_mem
- add ACPI support
I'm updating it and will send the updated changes.
>
> thanks,
>
> greg k-h
Regards,
Song
© 2016 - 2026 Red Hat, Inc.