From nobody Sat Jul 25 01:34:42 2026 Received: from mail-pg1-f177.google.com (mail-pg1-f177.google.com [209.85.215.177]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 4311638B14C for ; Tue, 21 Jul 2026 05:45:35 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.215.177 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784612737; cv=none; b=VCww09q9PHaeuhGm79Dr8579n7SOTjMFpeI0t+yjyWU/EG2GXhpWn9AJuUp+G+p+3zpsPlt0unW/HE+xOyL49icNuOgoYn2Z6xX/DEJT9SkbvUoIbmgtfSGaWwdDo4aJzWXug3fCV7FFLIXrizKHS4noctnSU36KPwLgedl0NHk= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784612737; c=relaxed/simple; bh=lr26kXFL1hHfgp2b30tVNsktdYjyhepmuSF83pAOJs4=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=K+Zhl66SO+dwRfmXirMwiFMswVl1J+rApVtFuTJq31T43M9ca66y0X5r9yuxtuR0LIsAeo7Fx7P99gO9xWzyw0UPSHTxGL+iIwEF2F42jqauK2f6zwDTCDN/oDUeSH4otBz7x0eXbPUZmiQCrUP74BLMVzKgvJ4Mx9ToHLTxbMY= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=rL6hZrDG; arc=none smtp.client-ip=209.85.215.177 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="rL6hZrDG" Received: by mail-pg1-f177.google.com with SMTP id 41be03b00d2f7-ca913a601fbso7352226a12.3 for ; Mon, 20 Jul 2026 22:45:35 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1784612734; x=1785217534; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=jKhFN9zG5GWfS1y9kxMxjS3nA8FNjbgYmSAyZRA2lkM=; b=rL6hZrDG4vWzOMGEnOt8fSiyJQhnIHfcE2/kIPQB7uoBZwFxrkylTZo8e5yH1/53OF 0qPy4TlB9YB+R9KSSMap5kQ3tbJXAQUiXjnVSbhbt71gkzjCO+yCLH+G8WGf1KkNhaBE KVQ1ScWAmnFQ1rwHztpRsUUtaLs+eZi11JJf0jhTEals7Ke2eXgMr4aj5wVP0RHfOMqL cE8BghKMN/rCY/eEhCZMN1F/vCAPT6rSPGq644RQLSvr4a4+QRKr/koMBUvBPjkSCXMt kCHvqWxOJAMxX8RZ2AnYU3bTVbYSh6unAFcHfxo7427eFrfkUO5xOo2yObK+oNgPmxiO +hwQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784612734; x=1785217534; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=jKhFN9zG5GWfS1y9kxMxjS3nA8FNjbgYmSAyZRA2lkM=; b=JDU1QxZ1Y7+/yhRdIBf21xIRTNzA99oFJ5D27LZyIp+8EX9BBbmR+hAanCJ8f5Cs2o K8wLBqGHJe+W/X88NIklJ/UAriGAkuFnNwiMKTcAum4aH4naN3xAwLO5xR3i3J/WAwR9 TSyR8ZaCHC6dxIyf0PGZXL5QNVr3K0L84DPI5ibUlwpB3OvHo0DDzb5Ru1TdIRjB4kQg 6v0A1wJ7+ZUKmb7/HV5bG2mfxmLD2zVns0WQVCvCmVvrU14yqrSdySzAzyMPwYnOL+VZ xT57pzl1OuN+CZ9fAd6qBVkVAbKADBDYIHwStAaV6l0HCDCeewTEo7ZkIy04zf3Zq3Zk 31oA== X-Forwarded-Encrypted: i=1; AHgh+RrJaq6WU66LHpZDh0cZgkwJRSQE90GcpaofNNydK7sPaxVOmhOvnlLEftv9JUWIzRlAjmJjZ/A8USkNZfc=@vger.kernel.org X-Gm-Message-State: AOJu0YzBoiDooLQ7n7zMgBnsrSVlzkv1+H45fyGlLE7y6zKAMgP18yQV 0o8UjgFZf9boqRp8Vgpr1YV0xEA+5DHwXJMw+Eef6QOw+MZNKWSJCBs= X-Gm-Gg: AfdE7clGX/iA+tMyia3et47l9EXOt54Z5LKoCKrwFeE5GWxu/6pQeIFYbxxNzppBEea uuVGlPegnS7tkcClJsfdno8jrQlX//3P+q4dy06hngNtIgFBOkzBOpINq6OoYBO0meD0R8TDwku dCwCtKbit006OL2zVMqXFmRmvEj8eQIQeZ8+iJStdyjkG7G7ngZq6PT+Y73/iJ/GkyGiuCW3cF4 Y6cwdt9BJ4UeA1ubwrPpPGCinmhYS8ye44dx6FB0KuNBYDI9CD7e7ssuV7CySbAlRk3japFLXGc NurZfmLdhVxZas2YmEOsBGEvLiFWWbzc2hvqBUG2aIDea/e+Yxd1zCZMLzn95F5bCJGfSYnfxvZ VQ8NxJ8fJnD1csMOCWitvRH/IJVpDIKr3tqyTAbWu1VhNmiVjPJTkyCsBie5sFPhWleLr/Z1zb9 C4bN/4NpGdN18y4eFjAfUD2QNsa1cKkJZbNhmJ5cBAzyG2tWzO X-Received: by 2002:a05:6a21:485:b0:3bf:6acf:2940 with SMTP id adf61e73a8af0-3c3ad5d51e8mr18203546637.11.1784612734470; Mon, 20 Jul 2026 22:45:34 -0700 (PDT) Received: from at-Standard-PC-Q35-ICH9-2009.. ([27.60.20.188]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-3142a1bb770sm46620876eec.16.2026.07.20.22.45.24 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 20 Jul 2026 22:45:33 -0700 (PDT) From: Atharva Tiwari To: Cc: Atharva Tiwari , Bjorn Helgaas , Thomas Gleixner , Ingo Molnar , Borislav Petkov , Dave Hansen , x86@kernel.org, "H. Peter Anvin" , Andreas Noever , Mika Westerberg , Yehezkel Bernat , Hans de Goede , =?UTF-8?q?Ilpo=20J=C3=A4rvinen?= , Jarkko Sakkinen , Mimi Zohar , Roberto Sassu , Dmitry Kasatkin , Eric Snowberg , Paul Moore , James Morris , "Serge E. Hallyn" , linux-pci@vger.kernel.org, linux-kernel@vger.kernel.org, linux-usb@vger.kernel.org, platform-driver-x86@vger.kernel.org, linux-integrity@vger.kernel.org, keyrings@vger.kernel.org, linux-security-module@vger.kernel.org Subject: [PATCH v2 1/2] treewide: Add a flag to detect the Apple T2 chip Date: Tue, 21 Jul 2026 01:45:01 -0400 Message-ID: <20260721054506.11871-2-atharvatiwarilinuxdev@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260721054506.11871-1-atharvatiwarilinuxdev@gmail.com> References: <20260721054506.11871-1-atharvatiwarilinuxdev@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Add a flag to detect Apple T2 chips on Intel Macs. Cache the result to avoid repeated checks. That will be used in upcoming patches. Signed-off-by: Atharva Tiwari Reviewed-by: Jarkko Sakkinen --- arch/x86/kernel/quirks.c | 105 ++++++++++++++++++ include/linux/platform_data/x86/apple.h | 5 + security/integrity/platform_certs/load_uefi.c | 38 ++----- 3 files changed, 118 insertions(+), 30 deletions(-) diff --git a/arch/x86/kernel/quirks.c b/arch/x86/kernel/quirks.c index a92f18db9610..74b29738d404 100644 --- a/arch/x86/kernel/quirks.c +++ b/arch/x86/kernel/quirks.c @@ -664,8 +664,113 @@ DECLARE_PCI_FIXUP_EARLY(PCI_VENDOR_ID_INTEL, 0x2083, = quirk_intel_purley_xeon_ras bool x86_apple_machine; EXPORT_SYMBOL(x86_apple_machine); =20 +bool has_apple_t2_chip; +EXPORT_SYMBOL(has_apple_t2_chip); + +static const struct dmi_system_id apple_t2_devices[] =3D { + { + .matches =3D { + DMI_MATCH(DMI_SYS_VENDOR, "Apple Inc."), + DMI_MATCH(DMI_PRODUCT_NAME, "MacBookPro15,1"), + }, + }, + { + .matches =3D { + DMI_MATCH(DMI_SYS_VENDOR, "Apple Inc."), + DMI_MATCH(DMI_PRODUCT_NAME, "MacBookPro15,2"), + }, + }, + { + .matches =3D { + DMI_MATCH(DMI_SYS_VENDOR, "Apple Inc."), + DMI_MATCH(DMI_PRODUCT_NAME, "MacBookPro15,3"), + }, + }, + { + .matches =3D { + DMI_MATCH(DMI_SYS_VENDOR, "Apple Inc."), + DMI_MATCH(DMI_PRODUCT_NAME, "MacBookPro15,4"), + }, + }, + { + .matches =3D { + DMI_MATCH(DMI_SYS_VENDOR, "Apple Inc."), + DMI_MATCH(DMI_PRODUCT_NAME, "MacBookPro16,1"), + }, + }, + { + .matches =3D { + DMI_MATCH(DMI_SYS_VENDOR, "Apple Inc."), + DMI_MATCH(DMI_PRODUCT_NAME, "MacBookPro16,2"), + }, + }, + { + .matches =3D { + DMI_MATCH(DMI_SYS_VENDOR, "Apple Inc."), + DMI_MATCH(DMI_PRODUCT_NAME, "MacBookPro16,3"), + }, + }, + { + .matches =3D { + DMI_MATCH(DMI_SYS_VENDOR, "Apple Inc."), + DMI_MATCH(DMI_PRODUCT_NAME, "MacBookPro16,4"), + }, + }, + { + .matches =3D { + DMI_MATCH(DMI_SYS_VENDOR, "Apple Inc."), + DMI_MATCH(DMI_PRODUCT_NAME, "MacBookAir8,1"), + }, + }, + { + .matches =3D { + DMI_MATCH(DMI_SYS_VENDOR, "Apple Inc."), + DMI_MATCH(DMI_PRODUCT_NAME, "MacBookAir8,2"), + }, + }, + { + .matches =3D { + DMI_MATCH(DMI_SYS_VENDOR, "Apple Inc."), + DMI_MATCH(DMI_PRODUCT_NAME, "MacBookAir9,1"), + }, + }, + { + .matches =3D { + DMI_MATCH(DMI_SYS_VENDOR, "Apple Inc."), + DMI_MATCH(DMI_PRODUCT_NAME, "Macmini8,1"), + }, + }, + { + .matches =3D { + DMI_MATCH(DMI_SYS_VENDOR, "Apple Inc."), + DMI_MATCH(DMI_PRODUCT_NAME, "MacPro7,1"), + }, + }, + { + .matches =3D { + DMI_MATCH(DMI_SYS_VENDOR, "Apple Inc."), + DMI_MATCH(DMI_PRODUCT_NAME, "iMac20,1"), + }, + }, + { + .matches =3D { + DMI_MATCH(DMI_SYS_VENDOR, "Apple Inc."), + DMI_MATCH(DMI_PRODUCT_NAME, "iMac20,2"), + }, + }, + { + .matches =3D { + DMI_MATCH(DMI_SYS_VENDOR, "Apple Inc."), + DMI_MATCH(DMI_PRODUCT_NAME, "iMacPro1,1"), + }, + }, + { } +}; + void __init early_platform_quirks(void) { x86_apple_machine =3D dmi_match(DMI_SYS_VENDOR, "Apple Inc.") || dmi_match(DMI_SYS_VENDOR, "Apple Computer, Inc."); + + has_apple_t2_chip =3D dmi_check_system(apple_t2_devices); } diff --git a/include/linux/platform_data/x86/apple.h b/include/linux/platfo= rm_data/x86/apple.h index 079e816c3c21..50bbcc5134fc 100644 --- a/include/linux/platform_data/x86/apple.h +++ b/include/linux/platform_data/x86/apple.h @@ -6,8 +6,13 @@ * x86_apple_machine - whether the machine is an x86 Apple Macintosh */ extern bool x86_apple_machine; +/** + * has_apple_t2_chip - whether the machine has the Apple T2 chip + */ +extern bool has_apple_t2_chip; #else #define x86_apple_machine false +#define has_t2_chip false #endif =20 #endif diff --git a/security/integrity/platform_certs/load_uefi.c b/security/integ= rity/platform_certs/load_uefi.c index c0d6948446c3..b4096d4c828d 100644 --- a/security/integrity/platform_certs/load_uefi.c +++ b/security/integrity/platform_certs/load_uefi.c @@ -3,42 +3,16 @@ #include #include #include -#include #include #include #include #include +#include #include #include #include "../integrity.h" #include "keyring_handler.h" =20 -/* - * On T2 Macs reading the db and dbx efi variables to load UEFI Secure Boot - * certificates causes occurrence of a page fault in Apple's firmware and - * a crash disabling EFI runtime services. The following quirk skips readi= ng - * these variables. - */ -static const struct dmi_system_id uefi_skip_cert[] =3D { - { UEFI_QUIRK_SKIP_CERT("Apple Inc.", "MacBookPro15,1") }, - { UEFI_QUIRK_SKIP_CERT("Apple Inc.", "MacBookPro15,2") }, - { UEFI_QUIRK_SKIP_CERT("Apple Inc.", "MacBookPro15,3") }, - { UEFI_QUIRK_SKIP_CERT("Apple Inc.", "MacBookPro15,4") }, - { UEFI_QUIRK_SKIP_CERT("Apple Inc.", "MacBookPro16,1") }, - { UEFI_QUIRK_SKIP_CERT("Apple Inc.", "MacBookPro16,2") }, - { UEFI_QUIRK_SKIP_CERT("Apple Inc.", "MacBookPro16,3") }, - { UEFI_QUIRK_SKIP_CERT("Apple Inc.", "MacBookPro16,4") }, - { UEFI_QUIRK_SKIP_CERT("Apple Inc.", "MacBookAir8,1") }, - { UEFI_QUIRK_SKIP_CERT("Apple Inc.", "MacBookAir8,2") }, - { UEFI_QUIRK_SKIP_CERT("Apple Inc.", "MacBookAir9,1") }, - { UEFI_QUIRK_SKIP_CERT("Apple Inc.", "Macmini8,1") }, - { UEFI_QUIRK_SKIP_CERT("Apple Inc.", "MacPro7,1") }, - { UEFI_QUIRK_SKIP_CERT("Apple Inc.", "iMac20,1") }, - { UEFI_QUIRK_SKIP_CERT("Apple Inc.", "iMac20,2") }, - { UEFI_QUIRK_SKIP_CERT("Apple Inc.", "iMacPro1,1") }, - { } -}; - /* * Look to see if a UEFI variable called MokIgnoreDB exists and return tru= e if * it does. @@ -165,10 +139,14 @@ static int __init load_uefi_certs(void) unsigned long dbsize =3D 0, dbxsize =3D 0, mokxsize =3D 0; efi_status_t status; int rc =3D 0; - const struct dmi_system_id *dmi_id; =20 - dmi_id =3D dmi_first_match(uefi_skip_cert); - if (dmi_id) { + /* + * On T2 Macs reading the db and dbx efi variables to load UEFI Secure Bo= ot + * certificates causes occurrence of a page fault in Apple's firmware and + * a crash disabling EFI runtime services. The following quirk skips read= ing + * these variables. + */ + if (has_apple_t2_chip) { pr_err("Reading UEFI Secure Boot Certs is not supported on T2 Macs.\n"); return false; } --=20 2.43.0 From nobody Sat Jul 25 01:34:42 2026 Received: from mail-pg1-f173.google.com (mail-pg1-f173.google.com [209.85.215.173]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id AA20E3B47F5 for ; Tue, 21 Jul 2026 05:45:46 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.215.173 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784612748; cv=none; b=jPchAsqG9dkNKa8oPqHRt6ZfwBP+4dGGHqrUF4KgKDK1bcHW82Q+MLTEx6Ftl7/phT+FHU8Cs0ZEXwzczYq3uVsTGesIqNB7W0SwJRpsUcQIC8SnDbxQ0L7qBoD7j6maZcDXETV7XY6UN9AtHq6EmWksvqhl+0sLeYYlN7KKcvk= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784612748; c=relaxed/simple; bh=DNpHQBMjU1wP0f8jQ4t452JbWb0XX8oIoHdLdwtqCfM=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=JnQp3MPsKN+91WgQ1UxEkJovFnPhHVNd5F2mIPNJk8aSGdaFnyC2YGEYsnrh5EUtF9i8UBscQ+NISkLrExNY+qjMIH9LCZkF0NrIhUJbidM8GYEsTmsc9FsvmHGgmQ+QBieBnu21DTAAZ1y/w28rFvor4n7jidJS8s/k/kRxRZs= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=pzcULYBV; arc=none smtp.client-ip=209.85.215.173 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="pzcULYBV" Received: by mail-pg1-f173.google.com with SMTP id 41be03b00d2f7-cb5a6aa8760so1739844a12.1 for ; Mon, 20 Jul 2026 22:45:46 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1784612746; x=1785217546; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=UgojYRWP1WvUNsyVTZf0JAe0a0XGAFDjQiUak8O6rqY=; b=pzcULYBVnMcH42hzqIwsULuQFNtipObN+NiIpKsIBH47VbCr+NjIbq1VyfD3kgfITX 9iZ+vh2egG2QQqzTX4YetuldKVvXBrwrHq7f4pq/61AFFQl32a79Q8T6Z+GgGxN8wjn2 sbxzSNeGJ+5CIQcQsa2hpxEQh/d/g7Ffnf4FxIdqlPQ9fWAio6izmjG0UuW0EtFf00tt 8mYD/9k81Y4hP/adpqahHlMp7QnBd0/tNL+EpdzqKHUian1XgxcMEIfT24bIq3kw8Ame opVCC38Meewn8qrYWIBNcEjIt7+tjvYOo/TDgF9le0C+ZwWSMrLyJ+lCY7u+HDY258Wa tPLw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784612746; x=1785217546; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=UgojYRWP1WvUNsyVTZf0JAe0a0XGAFDjQiUak8O6rqY=; b=mlcMi93zdwyBuaVMX4rOspWI2wGoIvGcZ5xye3Yc08Lt6j8fQZMF2g45ONPkoedQCn BS4ySbnz5cbOVtBRaXCyVx/Do5f3xL6Pv83++byAGNREjuOWdus5VJzyFcSLgjo0RrID u65YJqQ4OoCT17AynsvJvpyVNde3MZekQu8if38bjk6OJsaV+HnP8AZSuf9tfM9e3ha0 LZPv+cRJ7FudqpFrstW1Bzv76pimwexjlYK2CozPd6OrdAoZSeJrqTa6FMwoUIFkN4pb IbsEPMojFsk/HRL2spb0ApFkd/mn42dHIUjcGLIUGixctge0lskj1qeOFDlVe+BIzkId /TgA== X-Forwarded-Encrypted: i=1; AHgh+Rovou9xGDJe+QUUwa9Rkfmkw9Fi9i4quGOmWxwi5CVyEvWqUdcPfnND88kRp9h0R6AfIZUsOMi419ODyhU=@vger.kernel.org X-Gm-Message-State: AOJu0Yxc/bWjkC+dXgH+ogG4gEnXS2xSn4mIrN3sF+nwv/OoefTTHDMv Rh57WMiIJ6stozPm9H6VCKLBCJLzp69KgXFbAVg+DzSP0/Z8DJaIqQ4= X-Gm-Gg: AfdE7cm5Z3CsbEV7KBN3dRotuLlnarQYkJAyNt7YmsnyVoFB2/Ed1B4gwLr/52uJwG8 uVVNpnkBehKQnljPcQk9XMClc3PzOnJ9Bi4Ao/om7gRM+Cp34kw18VgSrKGzNjjSnRtEYJjGyzw x15qwHWs9NxLnbGdkgLKjUe3BkcPAqUDFuWqCcTLCU6jnKIAzTrnxfue+P0A4mDIr85fbGuVKi/ zMaihKKUAndvpGbCVB9IJEJrQINPMUzljc8ZTDHfGP2zYuAnv+jF58tympqzTw2rBweiM9JTYlB B50CLBGn/O/S4/SRVO9PRg2T24MpBHR292wQu15BkHVITNGACzUdYx1xXYImFIqRaDjG7PttJe/ P9APIXFypqg1/AmE/RASt9gwzAZPgFKwOinX9fe3OWN0s4HUOD/Evq8OW9ConzMfr/rsyHx12n/ g1j8/Qr2gLOOluUL+oTESVvPwU1nseFxa/EEVmPQ== X-Received: by 2002:a05:6a21:7111:b0:3c3:a41f:ce83 with SMTP id adf61e73a8af0-3c3ada9e0bbmr18607951637.61.1784612745975; Mon, 20 Jul 2026 22:45:45 -0700 (PDT) Received: from at-Standard-PC-Q35-ICH9-2009.. ([27.60.20.188]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-3142a1bb770sm46620876eec.16.2026.07.20.22.45.35 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 20 Jul 2026 22:45:44 -0700 (PDT) From: Atharva Tiwari To: Cc: Atharva Tiwari , Andre Eikmeyer , Bjorn Helgaas , Thomas Gleixner , Ingo Molnar , Borislav Petkov , Dave Hansen , x86@kernel.org, "H. Peter Anvin" , Andreas Noever , Mika Westerberg , Yehezkel Bernat , Hans de Goede , =?UTF-8?q?Ilpo=20J=C3=A4rvinen?= , Jarkko Sakkinen , Mimi Zohar , Roberto Sassu , Dmitry Kasatkin , Eric Snowberg , Paul Moore , James Morris , "Serge E. Hallyn" , linux-pci@vger.kernel.org, linux-kernel@vger.kernel.org, linux-usb@vger.kernel.org, platform-driver-x86@vger.kernel.org, linux-integrity@vger.kernel.org, keyrings@vger.kernel.org, linux-security-module@vger.kernel.org Subject: [PATCH v2 2/2] thunderbolt: Add device links for Apple T2 NHI Date: Tue, 21 Jul 2026 01:45:02 -0400 Message-ID: <20260721054506.11871-3-atharvatiwarilinuxdev@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260721054506.11871-1-atharvatiwarilinuxdev@gmail.com> References: <20260721054506.11871-1-atharvatiwarilinuxdev@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" From: Andre Eikmeyer Thunderbolt NHI on T2 Macs (2018-2020). The NHI and its associated PCIe root ports all sit directly on the root complex with no upstream port. Apple's ACPI tables name Thunderbolt root ports as TRP0, TRP1, etc. Find them and create device links back to the NHI so that PCIe tunnels can be re-established after sleep. Co-developed-by: Atharva Tiwari Signed-off-by: Atharva Tiwari Signed-off-by: Andre Eikmeyer --- drivers/thunderbolt/tb.c | 51 +++++++++++++++++++++++++++++++++++++++- 1 file changed, 50 insertions(+), 1 deletion(-) diff --git a/drivers/thunderbolt/tb.c b/drivers/thunderbolt/tb.c index c69c323e6952..ca47bfbcefdf 100644 --- a/drivers/thunderbolt/tb.c +++ b/drivers/thunderbolt/tb.c @@ -6,6 +6,7 @@ * Copyright (C) 2019, Intel Corporation */ =20 +#include #include #include #include @@ -3305,11 +3306,59 @@ static const struct tb_cm_ops tb_cm_ops =3D { static bool tb_apple_add_links(struct tb_nhi *nhi) { struct pci_dev *upstream, *pdev; - bool ret; + bool ret =3D false; =20 if (!x86_apple_machine) return false; =20 + /* On T2 Macs. the root ports are stored in ACPI as TRP0, + * TRP1, etc. Find them and create device links + * so that PCIe tunnels can be re-established after + * sleep. + */ + if (has_apple_t2_chip) { + struct acpi_device *adev; + unsigned int slot, func; + const struct device_link *link; + const char *bid; + + for (slot =3D 0; slot < 32; slot++) { + for (func =3D 0; func < 8; func++) { + pdev =3D pci_get_slot(nhi->pdev->bus, PCI_DEVFN(slot, func)); + if (!pdev) + continue; + + if (!pci_is_pcie(pdev) || pci_pcie_type(pdev) !=3D + PCI_EXP_TYPE_ROOT_PORT) + goto put_pdev; + + adev =3D ACPI_COMPANION(&pdev->dev); + if (!adev) + goto put_pdev; + + bid =3D acpi_device_bid(adev); + if (!bid || strncmp(bid, "TRP", 3) !=3D 0) + goto put_pdev; + + link =3D device_link_add(&pdev->dev, &nhi->pdev->dev, + DL_FLAG_AUTOREMOVE_SUPPLIER | + DL_FLAG_PM_RUNTIME); + if (link) { + dev_dbg(&nhi->pdev->dev, "created link from %s\n", + dev_name(&pdev->dev)); + ret =3D true; + } else + dev_warn(&nhi->pdev->dev, + "device link creation from %s failed\n", + dev_name(&pdev->dev)); + +put_pdev: + pci_dev_put(pdev); + } + } + return ret; + } + switch (nhi->pdev->device) { case PCI_DEVICE_ID_INTEL_LIGHT_RIDGE: case PCI_DEVICE_ID_INTEL_CACTUS_RIDGE_4C: --=20 2.43.0