From nobody Fri Jul 24 23:31:27 2026 Received: from mx0a-0031df01.pphosted.com (mx0a-0031df01.pphosted.com [205.220.168.131]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 8EB4A3BCD05 for ; Wed, 22 Jul 2026 06:59:41 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=205.220.168.131 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784703582; cv=none; b=ITwTroRY+xSt+ZFa3X4EguX0eIh6W97DaRLqdgdCCG+rwiZq9WvniejiAlzcQpEwTAvviTHYL3ZhPFGFEV0tF+U4BuLS+fqz51y5i2g9paUiiCZ+59FvQbjCS79+e8OD6iBcRhEOQdmCzH+XD497+/bNOe77Am6aZrhGeHf+hR8= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784703582; c=relaxed/simple; bh=Uq74hKAscOJpoTlWbeJLC+5TbwItuETl2mqfiOIyB/o=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=pFv7lbKbDl2G0wdmSzGn7Ms46xEuNAMmw0fv8Xngo0d1IrPNMVRqSrH1PPzzCJFwjkLTgZrkU7J+tVjo2BWG3L3P4eIye/CFYzsF6p8wRsfGUI659io1pTfIrBxG2wSEi53FuZYTN6fmB0g/CKayK/15nRjRkxaxi0yA8xLJXl0= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=oss.qualcomm.com; spf=pass smtp.mailfrom=oss.qualcomm.com; dkim=pass (2048-bit key) header.d=qualcomm.com header.i=@qualcomm.com header.b=K+M0kxUY; dkim=pass (2048-bit key) header.d=oss.qualcomm.com header.i=@oss.qualcomm.com header.b=WGMbCRn6; arc=none smtp.client-ip=205.220.168.131 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=oss.qualcomm.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=oss.qualcomm.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=qualcomm.com header.i=@qualcomm.com header.b="K+M0kxUY"; dkim=pass (2048-bit key) header.d=oss.qualcomm.com header.i=@oss.qualcomm.com header.b="WGMbCRn6" Received: from pps.filterd (m0279862.ppops.net [127.0.0.1]) by mx0a-0031df01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 66M53X3c3767503 for ; Wed, 22 Jul 2026 06:59:41 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=qualcomm.com; h= cc:content-transfer-encoding:content-type:date:from:in-reply-to :message-id:mime-version:references:subject:to; s=qcppdkim1; bh= saoDSDdEuqFBR3Jg2F/u3iejFckYCh1dzz5cbtTO9NU=; b=K+M0kxUYU0m3W+AF bXsV/ySbeQfAVDHn9IzibpPhNyrPlopAQnguasY9QOag13ySP129KQMX0UKv2iF4 hY+u+mgDsH1b2OxubxfRjtOatCAjfdofM/0ceqQ4ZfmLLjTEaltQc9ayhZwb+hOo oI9BwqCLAXXuPC2ul5+v4JrWNkfbJoCnBMOGzzW0RJtlpru7t6Egn1dkRLZl9iAZ 1Mwfk4qqrWmhy/Xw20u4JU6rGZRveZSbJU3DLcW+xHRlORt+nSDt8Axw5mCh8YBC GVSenSiUh93Si/ZroftHKkTGkAWh5N8hRDBD6rIpK8IvSgRZKo+s/Twin2TmN0td Ix9cmg== Received: from mail-pj1-f71.google.com (mail-pj1-f71.google.com [209.85.216.71]) by mx0a-0031df01.pphosted.com (PPS) with ESMTPS id 4fjnu4rr7h-1 (version=TLSv1.3 cipher=TLS_AES_128_GCM_SHA256 bits=128 verify=NOT) for ; Wed, 22 Jul 2026 06:59:40 +0000 (GMT) Received: by mail-pj1-f71.google.com with SMTP id 98e67ed59e1d1-38ea32e57e2so1240072a91.1 for ; Tue, 21 Jul 2026 23:59:40 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=oss.qualcomm.com; s=google; t=1784703580; x=1785308380; darn=vger.kernel.org; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=saoDSDdEuqFBR3Jg2F/u3iejFckYCh1dzz5cbtTO9NU=; b=WGMbCRn6mJ92t83t/NjIy8auHk8URQlLIwoihke8FNmR9p/4p9Oortlli6gYcs3I4k uQFNZsenixyVua4HOzgjeOItA9lz0sB1q8rBRoARuz4hvYdLNVmca3iGHRey6dXAfroo HPvmD9jwnA5rc73Acl2dnM3/jcO2dB10y6Hq2VeLXU3vQKFiENU6mmZn1p1b0X5Rl3MK FG4OT2lHgdFWbTkAosUTJrrDIn9SWBMPYVGJKeHTMhBgCk+eyJCsqnML15+UqDG2ibCm thVqeItQoegHVa9BU0Mkv/T46IbvzqbPCtR86A01iKVvr4Q0SeI47/3IrbsTBbi0Y1Bd JObg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784703580; x=1785308380; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=saoDSDdEuqFBR3Jg2F/u3iejFckYCh1dzz5cbtTO9NU=; b=nF+MW/LBbTsKtr/5U6L8dp+QH5J2JgU1DnaHN6k+oVFps/VaB8xVjVgdnvHGZaePPh qnXdm/IFDNGN34G9PzB81V9jXW0OYClJEtfIW88xHi5TUV1KoUCw1gbSuflLN7jG/Hrv 2rODOxKlhUJ1p3geGqmRqYKbOUYsWAJ5lQQnm0EibHp7/nt8MPSkcNj+dgGLzoU5ks2B ZdGOLB8G1yFylEdcAemJ4wxjcUkvKUZrFcHa3hZvbHyuLr/stH/XhLzOqfm9OpgKKJuX 9vjWVlgrIA/SmNaCfdftM44qwe16Ou+KO8Qead33YyuhrbMiaJUXzFi4i8QLCTffzfwa kS5w== X-Forwarded-Encrypted: i=1; AHgh+RoGQKe6kuV5Dg9L6AfgBCPuOr6yVoxiukbNqeviBTZ1L9IMWEoIB/3olbN8NkHhf9Z/7WZ+AjmP9gGwMmw=@vger.kernel.org X-Gm-Message-State: AOJu0YxS35VV3J2LpXrP5xzywW0bzO4psdi1NRLzx7McLtEhUlPSDxac g14AKgspX1kkiahXDG361NFOSW6tgJHqyz0PRACPR3dk3cSZu34Qc9RXuJTHCZuvMkjQmHVgaQ6 Y3ntPwldFR+fCyIo6X6WK8+WW8O13ftWQOV4KeKUg3ALcksY4cTN4fxCC8m979CYXp2A= X-Gm-Gg: AR+sD13eypBjUrreveOR8oHd7vYUsTvqv2lRV0WLDx49FwUeHFd8uUTRQxbYXiwaAFH jLmovYNv8EXm+HMMQxGmU4PxXkpFo29JqkSYEjt57qgn7UPevJB1qC8+WyAwfxMMFSjRYagAVzv WVjo8Ta7jZfMrwlCJq0O0GXCbMEzYbWJ6FCpLSQIA+87DahKs1KDJr3a5FUHpU7kQPezVyaJLm6 wv7HQKDPnnEkmPrioZObNmS0AX6Fpq+QhUe4Rt9lM5hY3wywtkkVAPKkYThjG0+/xoc2Jd7m3DT YN4FNuxN3qdasuP6IAtBlc3IWSEfkPOpJDCq0HFYTvHJ+1qySAV0fiR/iKua2IxnpjQD7m/9X0h hCt7HX2+IHU0NdhJD2Wy2EOT+6A== X-Received: by 2002:a17:903:189:b0:2cf:906c:7d1 with SMTP id d9443c01a7336-2cf906c0d37mr21989975ad.20.1784703580064; Tue, 21 Jul 2026 23:59:40 -0700 (PDT) X-Received: by 2002:a17:903:189:b0:2cf:906c:7d1 with SMTP id d9443c01a7336-2cf906c0d37mr21989805ad.20.1784703579605; Tue, 21 Jul 2026 23:59:39 -0700 (PDT) Received: from hu-hdev-hyd.qualcomm.com ([202.46.22.19]) by smtp.gmail.com with ESMTPSA id d9443c01a7336-2cf8efd88f7sm9428935ad.22.2026.07.21.23.59.34 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 21 Jul 2026 23:59:38 -0700 (PDT) From: Harshal Dev Date: Wed, 22 Jul 2026 12:29:12 +0530 Subject: [PATCH v2 1/6] tee: qcomtee: Track the object invocation context Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260722-qcom_uefisecapp_migrate_qcomtee-v2-1-b8a8fcbe4211@oss.qualcomm.com> References: <20260722-qcom_uefisecapp_migrate_qcomtee-v2-0-b8a8fcbe4211@oss.qualcomm.com> In-Reply-To: <20260722-qcom_uefisecapp_migrate_qcomtee-v2-0-b8a8fcbe4211@oss.qualcomm.com> To: Jens Wiklander , Jens Wiklander , Sumit Garg , Amirreza Zarrabi , Bjorn Andersson , Konrad Dybcio Cc: Basant Kumar , Apurupa Pattapu , Arun Kumar Neelakantam , op-tee@lists.trustedfirmware.org, linux-kernel@vger.kernel.org, linux-arm-msm@vger.kernel.org, Harshal Dev X-Mailer: b4 0.14.3 X-Developer-Signature: v=1; a=ed25519-sha256; t=1784703569; l=5105; i=harshal.dev@oss.qualcomm.com; s=20251124; h=from:subject:message-id; bh=Uq74hKAscOJpoTlWbeJLC+5TbwItuETl2mqfiOIyB/o=; b=PFbHpdPKr5cwtQn4xbDEDLIt+rmsnl3yHQmhSVoVCCSwjBpvEBP9mTv+rpaNItkG5Hw5+zCoE Kp/MK/SYd3OAc8PcuRfoqqf3LBCqe1xO5x+mDvRJUQRIS5Gxw6Kvm8P X-Developer-Key: i=harshal.dev@oss.qualcomm.com; a=ed25519; pk=SHJ8K4SglF5t7KmfMKXl6Mby40WczSeLs4Qus7yFO7c= X-Proofpoint-GUID: YR3G6R8D4yVzujeJjSsO0gU_8rwJc13H X-Authority-Analysis: v=2.4 cv=KLhqylFo c=1 sm=1 tr=0 ts=6a606a5c cx=c_pps a=UNFcQwm+pnOIJct1K4W+Mw==:117 a=fChuTYTh2wq5r3m49p7fHw==:17 a=IkcTkHD0fZMA:10 a=RAioF0-LDSMA:10 a=s4-Qcg_JpJYA:10 a=VkNPw1HP01LnGYTKEx00:22 a=u7WPNUs3qKkmUXheDGA7:22 a=_K5XuSEh1TEqbUxoQ0s3:22 a=EUspDBNiAAAA:8 a=bFqmgcYAq-yHHMqQ97oA:9 a=QEXdDO2ut3YA:10 a=uKXjsCUrEbL0IQVhDsJ9:22 X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwNzIyMDA2MyBTYWx0ZWRfX98LlHh8ZqJBE gEEXf86NPg7a4MAB4oUjPqmhVE2zJ8Je+Oqx9103l8AotV2DB+yPoA39Y6Oe3WP6RSC1TLtUW6k I4vslI23AxPZJtbJGURHxnmlf5pB8QGoZWPBwBuaVblfM2w/rIZpfFS6B8ifEUs7d3dcCrZ8lRM r0lzT/uKWE/K/q5ZBdr0lsns2759+YTcBuaL/WITE4K9RiU3+7pCBkDdEjDA+9C1/uss5qIBUQX R/nLDemMxnsZAyIXhExLD1iHAleevuwb1o20zaVUzk/obGlidZ0YPVBLd7L/YKzxUVhNAnXG3dm nFCL8lgesRAbInFH/HaT72DBYGjaQ8QramE4LXXIfXFrGCQG12KwSq5QV0RuzD4F4BPTH1/mkHC uSgCMPhn2L4WbHsjasbFjg5VAunVZsy9b245uNWb/8WswhjlANzX96utSx51HOwK1LJAmC+uDHw WRiXHzEdCcbTRKsFi+g== X-Proofpoint-ORIG-GUID: YR3G6R8D4yVzujeJjSsO0gU_8rwJc13H X-Proofpoint-Spam-Info: AW1haW4tMjYwNzIyMDA2MyBTYWx0ZWRfXxyxQlnzVzs89 sHiaLa8tzDLvWZPVeqVklGQ/G96boXrTKrbLCqzfrja7svcc4JB6T/x8LA9twUHuqpDwK7Runbh LuSPIs7+66RRwqXyRv46cGRj9d0q27Q= X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1143,Hydra:6.1.134,FMLib:17.12.100.49 definitions=2026-07-22_02,2026-07-21_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 bulkscore=0 spamscore=0 clxscore=1015 impostorscore=0 lowpriorityscore=0 priorityscore=1501 malwarescore=0 phishscore=0 adultscore=0 suspectscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2607220063 QCOMTEE needs to distinguish between object invocations arriving from kernel clients and user-space clients in order to correctly marshal UBUF parameters and decide whether certain operations should be permitted. Introduce an enum tee_object_invoke_origin to allow clients to indicate the context of the TEE object invocation, and add a kernel_ctx flag to the QCOMTEE context so the TEE back-end can track it. Signed-off-by: Harshal Dev --- drivers/tee/qcomtee/call.c | 11 ++++++++--- drivers/tee/qcomtee/qcomtee_object.h | 8 ++++++-- drivers/tee/tee_core.c | 3 ++- include/linux/tee_core.h | 8 +++++++- 4 files changed, 23 insertions(+), 7 deletions(-) diff --git a/drivers/tee/qcomtee/call.c b/drivers/tee/qcomtee/call.c index 0efc5646242a..03d33b118f6d 100644 --- a/drivers/tee/qcomtee/call.c +++ b/drivers/tee/qcomtee/call.c @@ -393,15 +393,20 @@ static int qcomtee_root_object_check(u32 op, struct t= ee_param *params, */ static int qcomtee_object_invoke(struct tee_context *ctx, struct tee_ioctl_object_invoke_arg *arg, - struct tee_param *params) + struct tee_param *params, + enum tee_object_invoke_origin origin) { struct qcomtee_context_data *ctxdata =3D ctx->data; struct qcomtee_object *object; + bool kernel_ctx =3D false; int i, ret, result; =20 if (qcomtee_params_check(params, arg->num_params)) return -EINVAL; =20 + if (origin =3D=3D TEE_OBJECT_INVOKE_KERNEL) + kernel_ctx =3D true; + /* First, handle reserved operations: */ if (arg->op =3D=3D QCOMTEE_MSG_OBJECT_OP_RELEASE) { del_qtee_object(arg->id, ctxdata); @@ -411,7 +416,7 @@ static int qcomtee_object_invoke(struct tee_context *ct= x, =20 /* Otherwise, invoke a QTEE object: */ struct qcomtee_object_invoke_ctx *oic __free(kfree) =3D - qcomtee_object_invoke_ctx_alloc(ctx); + qcomtee_object_invoke_ctx_alloc(ctx, kernel_ctx); if (!oic) return -ENOMEM; =20 @@ -648,7 +653,7 @@ static void qcomtee_get_qtee_feature_list(struct tee_co= ntext *ctx, u32 id, int result; =20 struct qcomtee_object_invoke_ctx *oic __free(kfree) =3D - qcomtee_object_invoke_ctx_alloc(ctx); + qcomtee_object_invoke_ctx_alloc(ctx, true); if (!oic) return; =20 diff --git a/drivers/tee/qcomtee/qcomtee_object.h b/drivers/tee/qcomtee/qco= mtee_object.h index 8b4401ecad48..2528d07e4576 100644 --- a/drivers/tee/qcomtee/qcomtee_object.h +++ b/drivers/tee/qcomtee/qcomtee_object.h @@ -146,6 +146,7 @@ static inline int qcomtee_args_len(struct qcomtee_arg *= args) * struct qcomtee_object_invoke_ctx - QTEE context for object invocation. * @ctx: TEE context for this invocation. * @flags: flags for the invocation context. + * @kernel_ctx: flag that indicates this context is owned by a kernel clie= nt. * @errno: error code for the invocation. * @object: current object invoked in this callback context. * @u: array of arguments for the current invocation (+1 for ending arg). @@ -158,6 +159,7 @@ static inline int qcomtee_args_len(struct qcomtee_arg *= args) struct qcomtee_object_invoke_ctx { struct tee_context *ctx; unsigned long flags; + bool kernel_ctx; int errno; =20 struct qcomtee_object *object; @@ -172,13 +174,15 @@ struct qcomtee_object_invoke_ctx { }; =20 static inline struct qcomtee_object_invoke_ctx * -qcomtee_object_invoke_ctx_alloc(struct tee_context *ctx) +qcomtee_object_invoke_ctx_alloc(struct tee_context *ctx, bool kernel_ctx) { struct qcomtee_object_invoke_ctx *oic; =20 oic =3D kzalloc_obj(*oic); - if (oic) + if (oic) { oic->ctx =3D ctx; + oic->kernel_ctx =3D kernel_ctx; + } return oic; } =20 diff --git a/drivers/tee/tee_core.c b/drivers/tee/tee_core.c index ef9642d72672..dba5d4d2d47e 100644 --- a/drivers/tee/tee_core.c +++ b/drivers/tee/tee_core.c @@ -706,7 +706,8 @@ static int tee_ioctl_object_invoke(struct tee_context *= ctx, goto out; } =20 - rc =3D ctx->teedev->desc->ops->object_invoke_func(ctx, &arg, params); + rc =3D ctx->teedev->desc->ops->object_invoke_func(ctx, &arg, params, + TEE_OBJECT_INVOKE_USERSPACE); if (rc) goto out; =20 diff --git a/include/linux/tee_core.h b/include/linux/tee_core.h index f993d5118edd..bcb5418d6fdc 100644 --- a/include/linux/tee_core.h +++ b/include/linux/tee_core.h @@ -73,6 +73,11 @@ struct tee_device { struct tee_shm_pool *pool; }; =20 +enum tee_object_invoke_origin { + TEE_OBJECT_INVOKE_USERSPACE, + TEE_OBJECT_INVOKE_KERNEL, +}; + /** * struct tee_driver_ops - driver operations vtable * @get_version: returns version of driver @@ -117,7 +122,8 @@ struct tee_driver_ops { struct tee_param *param); int (*object_invoke_func)(struct tee_context *ctx, struct tee_ioctl_object_invoke_arg *arg, - struct tee_param *param); + struct tee_param *param, + enum tee_object_invoke_origin origin); int (*cancel_req)(struct tee_context *ctx, u32 cancel_id, u32 session); int (*supp_recv)(struct tee_context *ctx, u32 *func, u32 *num_params, struct tee_param *param); --=20 2.34.1 From nobody Fri Jul 24 23:31:27 2026 Received: from mx0a-0031df01.pphosted.com (mx0a-0031df01.pphosted.com [205.220.168.131]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id D39923C1961 for ; Wed, 22 Jul 2026 06:59:46 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=205.220.168.131 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784703588; cv=none; b=tYAjbItDSi7Iu19U5fCf8AlMZZaG/X1pUQR1lb0l8oRzqRwas115BFY5VHxV6ZAIozf0kZx8Kqt7Wya/BQevZoqqvGVxm//T7Z2PjmIZ4SvH8fy3ONODnWLqV5eJHuMbf/OLXLcxNIoH1TE1hLxjai9rDlU/1EhRj7Hhyvt/3Zw= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784703588; c=relaxed/simple; bh=25WePboOUIh0OM10e66E31TxP7xc6qwFaDOGM2WjvkA=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=W+fJobV7DT1zkXx5tCKQ2rfzpHdlIKa+fmyLmb7xgqIQvrFcRQ3dc2LD/X70n6s+6PX2LDePj71fWYMH10rD1EI4Co6d6wYY1V7udiE6NMHLNf9Ui8swP+L3yDOoVzJ+AP3SKnktyMPrO1HuP9DSF9nf+gqSBM9kyBlGK0+cqQk= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=oss.qualcomm.com; spf=pass smtp.mailfrom=oss.qualcomm.com; dkim=pass (2048-bit key) header.d=qualcomm.com header.i=@qualcomm.com header.b=MDjA985F; dkim=pass (2048-bit key) header.d=oss.qualcomm.com header.i=@oss.qualcomm.com header.b=fzeQbItp; arc=none smtp.client-ip=205.220.168.131 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=oss.qualcomm.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=oss.qualcomm.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=qualcomm.com header.i=@qualcomm.com header.b="MDjA985F"; dkim=pass (2048-bit key) header.d=oss.qualcomm.com header.i=@oss.qualcomm.com header.b="fzeQbItp" Received: from pps.filterd (m0279865.ppops.net [127.0.0.1]) by mx0a-0031df01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 66M6fuNT200496 for ; Wed, 22 Jul 2026 06:59:46 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=qualcomm.com; h= cc:content-transfer-encoding:content-type:date:from:in-reply-to :message-id:mime-version:references:subject:to; s=qcppdkim1; bh= 31qc/02ryLxVGZE3W44tXTDK/BxZ/hQGixj6FDcU8hw=; b=MDjA985FTEihcs3X 2wdY/g4MKqtNbHKn/0l7btgtoFPyOsqvr8b6MCDfonA+ut2Flz/loSIvW7Lou1IR 2PHskQaiWFW9MZTt312VyXPBuwzunDZd6sdNWj9yRGz0y84QDfzLRfrZ4oZ3qATq ek8hXIO0pAHOsUZeL6fm2LxkpfINR0A4h5s5WIZ8gsoswy2KYlff1heenxfQUNLd z7U+vQbcMNI9T0d8ceVpnnUXEOlgEL78Nc6uxknaJGHROZ/eFKHepsq0z6aGQ1+s 4lyAO2VVUNevv79cLlzvGEZeJ+/5nPguQgHO7QwFL8lrOMyVKutGxODVaDFG94u5 SIZDfw== Received: from mail-pj1-f71.google.com (mail-pj1-f71.google.com [209.85.216.71]) by mx0a-0031df01.pphosted.com (PPS) with ESMTPS id 4fjrtt02fh-1 (version=TLSv1.3 cipher=TLS_AES_128_GCM_SHA256 bits=128 verify=NOT) for ; Wed, 22 Jul 2026 06:59:46 +0000 (GMT) Received: by mail-pj1-f71.google.com with SMTP id 98e67ed59e1d1-38e22137fb3so11153346a91.0 for ; Tue, 21 Jul 2026 23:59:45 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=oss.qualcomm.com; s=google; t=1784703585; x=1785308385; darn=vger.kernel.org; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=31qc/02ryLxVGZE3W44tXTDK/BxZ/hQGixj6FDcU8hw=; b=fzeQbItpq2dxE7CNIiJ9G0bu0ocWYRScq8OrbDiJ4IcZMaYE/aUvXr9dNTViK36dyy hycUJcxtPGhQ3XW1rIeoRzBvboxpIuSLjiHsNM2bJ1DkwuzujiBoMX7U+rP4Bg+VfrWd E+ldQztGYjG8rxe6ffSMD47kGG00BBvpwNjSw7CZRZetvAB72Jmktr6isWgivNzVdVCU lY8+rrIAHvp5Ze1oymvcAYIbl0YYEbMNpg7mnSgjXjta0u+vM0YcvOWYu1gXdUSnoPgx 43/oZ+iSG/S5QrxSG2NmqF+5NwjeWnvcDpdPO3Nimo7AKxD5QD8/LVkWEC1D3WPpgBY+ jrog== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784703585; x=1785308385; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=31qc/02ryLxVGZE3W44tXTDK/BxZ/hQGixj6FDcU8hw=; b=Az3xJadQBoGBLQA4YksbK/32xzKS+XjqNzkv1Jef+Z+g6yX6c4l8A1362vHyG5+9+o LrXcwZ6HmQM0hx/eCeu6tGAeO2W+sMKYuecrgkTOROF4fFvcD2CKI7GMkqZLsvK/6bqH BEctJjm6y68UwDKI48W71hEkYIRu7erR4guV6NUhkQUN74aUsqDSD3zRP7t283SuMd6g jkA2pW1Xnl4+kSkIRaCaU1XZ6KPTmWnx+zSDVKb4KygS9HnIm/bEtVlbRTuUeJ6SgLuF KEKdYtXD/m88Mnbq7K5fcT8UFMh/fiBmWakwaWpsAaBc06QiwmF/+xM0c6TvBqu6nOr3 1hTg== X-Forwarded-Encrypted: i=1; AHgh+RrVDrOX60cljtci30/FRLjULHfTVhGdJGzdrNZMDlPwutZLQOz8cckt1zp8KfW4q7ZqxMH9HcHHU6OGsbg=@vger.kernel.org X-Gm-Message-State: AOJu0YzpDD/OFAdlsxQAX35jr4O1nIPiTBHio+64EAf6ItWDZPY2Zrhv Pwhdo83M+cXJDSEg6aIw1u+F4Xy0m3mo8ilGGJnK/1qCpMoTbAyfkqqvCDh+5/6/fI8aUfjtfTU ce5bgLKfr+P6HxnM11fW2vNGjbKukT/IU1kPAdJoXnhQ4u5ecWjA7+NF003IxiReR4Hs= X-Gm-Gg: AR+sD120NJQptGAN0zEU4u6H08wDXDJT/+yyr43ys3C/08Z2wbcr566UqM65MRRQZqq suVsS5G8R+yPvStlwdrVllHcv57NUBh2gerq/KigkfqoiQkeVURBGoStQRlMc/LD7phNJTrnnaj CcyAnvAjuRjm1tNau9RY9MpGZJSU42kV6teTsTtGJiRlSWbupCvGoY26ptdyR1FBDB1B7qJxyBd 2/GTZtmzqnzoCgcLv53tIgKu3rJP8hcrXzWPXwj7pRvZ/Cl89xxNn/SLes4NQPRMuCwhRlqKBxf EaGFlkwx6gA3moWD3oKdMOroYtd9YeJAPX8QLneVEEg//2CSawYCLbJ94ykIiXPklZ0J+c3quTn L5qumEayoNz+aJfjcJt8hHOjIyQ== X-Received: by 2002:a17:902:fc4b:b0:2ba:6518:a6d4 with SMTP id d9443c01a7336-2cf34906386mr240005795ad.20.1784703585375; Tue, 21 Jul 2026 23:59:45 -0700 (PDT) X-Received: by 2002:a17:902:fc4b:b0:2ba:6518:a6d4 with SMTP id d9443c01a7336-2cf34906386mr240005515ad.20.1784703584781; Tue, 21 Jul 2026 23:59:44 -0700 (PDT) Received: from hu-hdev-hyd.qualcomm.com ([202.46.22.19]) by smtp.gmail.com with ESMTPSA id d9443c01a7336-2cf8efd88f7sm9428935ad.22.2026.07.21.23.59.39 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 21 Jul 2026 23:59:43 -0700 (PDT) From: Harshal Dev Date: Wed, 22 Jul 2026 12:29:13 +0530 Subject: [PATCH v2 2/6] tee: Add kernel client object invoke helper Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260722-qcom_uefisecapp_migrate_qcomtee-v2-2-b8a8fcbe4211@oss.qualcomm.com> References: <20260722-qcom_uefisecapp_migrate_qcomtee-v2-0-b8a8fcbe4211@oss.qualcomm.com> In-Reply-To: <20260722-qcom_uefisecapp_migrate_qcomtee-v2-0-b8a8fcbe4211@oss.qualcomm.com> To: Jens Wiklander , Jens Wiklander , Sumit Garg , Amirreza Zarrabi , Bjorn Andersson , Konrad Dybcio Cc: Basant Kumar , Apurupa Pattapu , Arun Kumar Neelakantam , op-tee@lists.trustedfirmware.org, linux-kernel@vger.kernel.org, linux-arm-msm@vger.kernel.org, Harshal Dev X-Mailer: b4 0.14.3 X-Developer-Signature: v=1; a=ed25519-sha256; t=1784703569; l=2583; i=harshal.dev@oss.qualcomm.com; s=20251124; h=from:subject:message-id; bh=CXt0mSkOb6Fv+NT3vb9BCSp9EdXlKG5hU1H1pxd/wnc=; b=Y2LJQzDplsNqP3q2YuickHd4qkJhiO33TsIfTfT4UR7bl6qIwggPUpi31T5kjH5TerPc+qXX1 D/kUoMsA64yAkN1RPu42L90ss/hWblwUp9b7FmCCOHQllGUqNLRVmN7 X-Developer-Key: i=harshal.dev@oss.qualcomm.com; a=ed25519; pk=SHJ8K4SglF5t7KmfMKXl6Mby40WczSeLs4Qus7yFO7c= X-Proofpoint-ORIG-GUID: 5z_NVRd57iqPZJnrCO_xrUJwS7IgLeLr X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwNzIyMDA2MiBTYWx0ZWRfX/V6UOsIwwRe7 BTrYB0IKGhGUhobUCMpwfql3MtBnaqyzF/16Vhhtx14CHnm8GfUVC1QxqMvgSY7mtr1CQUABFq5 KHv72EhiNw3xTtUYYMGOCmVKzu6Wb/C6rynWma7mngN59WMllZo5P/NdUWpsruD2fNDSdhft1Is HBiWrKeElDOHWmldVcTGKM8CcOwZyS61EvQlnh72fjD+6zcjhwOv88qXV4aiiA7X18IaAwQ3BF1 m7hPS91ZlDDljxEYjgNoHmLK1kgOOpHM2wfhrt+EyGtjIHmkcIbl+r4vcKR+AOrtd131jBTTL5l 76iZ1FGVUPF6/hEMyZBMyZYCo4N3/aiO01JgDyhWKHjm/9jKZ5qDMco03AUZwg0dwLMgDPAcGAd Coahm6qR4etn8JfwTh0UOFhUu+gWFHRR1rbrnprcAyi8sHgS9ZP219uTkWUCsW+E0dtniAS9SZG TKXL2wLou/nlu9GnP0w== X-Proofpoint-Spam-Info: AW1haW4tMjYwNzIyMDA2MiBTYWx0ZWRfX1oRM59VpXC8L B0BxkkSS23nS/FOXC8jqmlkaKVHVWbEzg2sCtsMxX0TWH0UyHTf54XROdDfmlbOunWahgm2/3O9 yHLCYTm77iQMQgXeWvrvXXTN7cTwJRs= X-Proofpoint-GUID: 5z_NVRd57iqPZJnrCO_xrUJwS7IgLeLr X-Authority-Analysis: v=2.4 cv=V8lNF+ni c=1 sm=1 tr=0 ts=6a606a62 cx=c_pps a=UNFcQwm+pnOIJct1K4W+Mw==:117 a=fChuTYTh2wq5r3m49p7fHw==:17 a=IkcTkHD0fZMA:10 a=RAioF0-LDSMA:10 a=s4-Qcg_JpJYA:10 a=VkNPw1HP01LnGYTKEx00:22 a=u7WPNUs3qKkmUXheDGA7:22 a=Um2Pa8k9VHT-vaBCBUpS:22 a=EUspDBNiAAAA:8 a=kr-ihz5DC76VLKRVsLUA:9 a=QEXdDO2ut3YA:10 a=uKXjsCUrEbL0IQVhDsJ9:22 X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1143,Hydra:6.1.134,FMLib:17.12.100.49 definitions=2026-07-22_02,2026-07-21_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 spamscore=0 phishscore=0 lowpriorityscore=0 bulkscore=0 impostorscore=0 adultscore=0 priorityscore=1501 malwarescore=0 clxscore=1015 suspectscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2607220062 From: Amirreza Zarrabi Kernel clients can open a TEE context and invoke regular TA commands through tee_client_invoke_func(). However, there is currently no equivalent helper for invoking TEE objects. Add tee_client_object_invoke_func() as a kernel client API for issuing object invocation requests. The helper checks that the backend provides object_invoke_func() before forwarding the request by setting the origin as TEE_OBJECT_INVOKE_KERNEL. This allows TEE backends to support privileged object-based calls from the kernel-space. Co-developed-by: Harshal Dev Signed-off-by: Harshal Dev Signed-off-by: Amirreza Zarrabi --- drivers/tee/tee_core.c | 12 ++++++++++++ include/linux/tee_drv.h | 13 +++++++++++++ 2 files changed, 25 insertions(+) diff --git a/drivers/tee/tee_core.c b/drivers/tee/tee_core.c index dba5d4d2d47e..bb418490f3af 100644 --- a/drivers/tee/tee_core.c +++ b/drivers/tee/tee_core.c @@ -1410,6 +1410,18 @@ int tee_client_invoke_func(struct tee_context *ctx, } EXPORT_SYMBOL_GPL(tee_client_invoke_func); =20 +int tee_client_object_invoke_func(struct tee_context *ctx, + struct tee_ioctl_object_invoke_arg *arg, + struct tee_param *param) +{ + if (!ctx->teedev->desc->ops->object_invoke_func) + return -EINVAL; + + return ctx->teedev->desc->ops->object_invoke_func(ctx, arg, param, + TEE_OBJECT_INVOKE_KERNEL); +} +EXPORT_SYMBOL_GPL(tee_client_object_invoke_func); + int tee_client_cancel_req(struct tee_context *ctx, struct tee_ioctl_cancel_arg *arg) { diff --git a/include/linux/tee_drv.h b/include/linux/tee_drv.h index e561a26f537a..ca99c6b747a8 100644 --- a/include/linux/tee_drv.h +++ b/include/linux/tee_drv.h @@ -283,6 +283,19 @@ int tee_client_invoke_func(struct tee_context *ctx, struct tee_ioctl_invoke_arg *arg, struct tee_param *param); =20 +/** + * tee_client_object_invoke_func() - Invoke a TEE object from kernel space + * @ctx: TEE Context + * @arg: Invoke arguments, see description of + * struct tee_ioctl_object_invoke_arg + * @param: Parameters for the object invocation + * + * Return: On success, returns 0; on failure, returns < 0. + */ +int tee_client_object_invoke_func(struct tee_context *ctx, + struct tee_ioctl_object_invoke_arg *arg, + struct tee_param *param); + /** * tee_client_cancel_req() - Request cancellation of the previous open-ses= sion * or invoke-command operations in a Trusted Application --=20 2.34.1 From nobody Fri Jul 24 23:31:27 2026 Received: from mx0b-0031df01.pphosted.com (mx0b-0031df01.pphosted.com [205.220.180.131]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 0752D3B9D97 for ; Wed, 22 Jul 2026 06:59:52 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=205.220.180.131 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784703594; cv=none; b=iybgaYqN+7nD8fN8Tt1yIMbET2Bv52FN5NXUj7BBzg2NOy45aGGljhqY5Qut+OyiuxfMvbKUYmH6fqSlZICz7wB7tqMmPCM+lGD0gOE5pnriuoBuaCQX6IwT1BirfsxJ4+9uIL5L72UiUTWjm6cHQHWy3DYiUldj7WnySppyUAA= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784703594; c=relaxed/simple; bh=G6VnwaO1IVScbnDaolrmIYtJTI0uR93I+XZ8UW66RtY=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=LdmciLFWC7+3dH31lRqZCWLTaculpnKdetWCNlHZvNwd0mfMrOBBeDHrF5TAAWhaFo1EglZSrayPy1JZ8WUaYSkBYyTHFV50n78VsFc8xqXzQb9hUzef2b+nE2xqnwpD/pEXnZW6DCECbwd8h3/vQeqCi1f+PjlHGnK3ECe+J4Y= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=oss.qualcomm.com; spf=pass smtp.mailfrom=oss.qualcomm.com; dkim=pass (2048-bit key) header.d=qualcomm.com header.i=@qualcomm.com header.b=bUaXQhtc; dkim=pass (2048-bit key) header.d=oss.qualcomm.com header.i=@oss.qualcomm.com header.b=K5kb5dO4; arc=none smtp.client-ip=205.220.180.131 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=oss.qualcomm.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=oss.qualcomm.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=qualcomm.com header.i=@qualcomm.com header.b="bUaXQhtc"; dkim=pass (2048-bit key) header.d=oss.qualcomm.com header.i=@oss.qualcomm.com header.b="K5kb5dO4" Received: from pps.filterd (m0279872.ppops.net [127.0.0.1]) by mx0a-0031df01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 66M53p0o3787369 for ; Wed, 22 Jul 2026 06:59:51 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=qualcomm.com; h= cc:content-transfer-encoding:content-type:date:from:in-reply-to :message-id:mime-version:references:subject:to; s=qcppdkim1; bh= QcGMG8S4sHvnkwBvz/VTr4JXUXb6aBnJmGIPnGyQ4as=; b=bUaXQhtcPF303SZr oy87bIYzvB4UQDcPgMNnp/1BjlNzsc0SgYPOUNkWdvJozIBidArbnlgMJiyf2vx8 X5z/OFMTIDYx8VmfVleBHh0FmhXmbKqhdAF4YK8Q3ugXluCiKFimfmmFeRe/gmrW TYQArpLq4tcYMrtyO6wFz6KeOpBsqA6dXtbBTlzyBk7S106wRoEPI3AeCPm5cg6s Tz9576/sQyCcL/sLtT7fsFv38j5RFd+7ThLpsAR8GMstNiasns9mIfFJ3trzYV+5 J05rRJPNa8QcyjfYi9jEhx6D86iD0FSmoU0lIvxIdxxUzd3wEcCs8ZH0mJ05K8cq PQ3kdw== Received: from mail-pg1-f197.google.com (mail-pg1-f197.google.com [209.85.215.197]) by mx0a-0031df01.pphosted.com (PPS) with ESMTPS id 4fj9aec32k-1 (version=TLSv1.3 cipher=TLS_AES_128_GCM_SHA256 bits=128 verify=NOT) for ; Wed, 22 Jul 2026 06:59:51 +0000 (GMT) Received: by mail-pg1-f197.google.com with SMTP id 41be03b00d2f7-cbb92868263so186976a12.2 for ; Tue, 21 Jul 2026 23:59:51 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=oss.qualcomm.com; s=google; t=1784703590; x=1785308390; darn=vger.kernel.org; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=QcGMG8S4sHvnkwBvz/VTr4JXUXb6aBnJmGIPnGyQ4as=; b=K5kb5dO4nc42GQmZCQ0r8Q9aDUWM8I9AKiMr8IEWi/Hn3nbtnmG6vuzDX1lDomi8q/ pV6OEwh7uRB/Nyf4mCSiwuxvJWkEqIL2krR1foScWs0+uFzPZwVIQXf1IXa1vbtJDQ0n XgErxwjGwohMHctLXNBeXzEIHSndtJqrSDnBFdqCPuQU4b49GusI1adrn8fBlflUKy0+ WjrI1OGcUg2hfIFyQiTzZ6slVZLTAvFXvf+VM8UZU/9U/plAY77HeAtolmin8KC/Gt7d UdE6zrwDPDdXKW4i4dX4k71k21nLrjcbcP99Wb157G4mge24/l1EvAY6SGQMVqnqjTI/ A5yg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784703590; x=1785308390; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=QcGMG8S4sHvnkwBvz/VTr4JXUXb6aBnJmGIPnGyQ4as=; b=X085Xx4M18cPXPkkeo+I6bLV/Gk6iwOMqDZi//SvwbxrPyusmYftWV2G1oGSzqndQi 4WLi1hPY4F1rfJJEslCB5ABhPsZvI7zbv7h+2aX3FCekkJADXfa1jvFpbo03ml1ZeYi5 Pjh+X0EB0AkLQrIcdT3woaAehxWndaLbt2JwXAtOyLREBesZdeWxfRbGNJBEMc8Y5HA5 H6wOeOSoMFQ0bNPWcBh0zqGQpXFwFaTH/BG1VkdEKZ9mGTNkCdn1phYa3QAopFjtBp5E 1sxHucOYlPi7btxGFnhQ2mGlkUgcC4SdlZaloyj+AwpwM3/3aV7s5OMbSDulhAFkQL0z 7CbQ== X-Forwarded-Encrypted: i=1; AHgh+Rqtq/wd/6E4wSLwP08Zi+A+vnIRAp1zfU7z7kYkoqPR54OFCrSDsEX0lcaQjeIK4SBIn5RDoUdKyion3vo=@vger.kernel.org X-Gm-Message-State: AOJu0YwWU9glmreJr8HKfEL7muHeGD1pYosXnBrGii3Kdc0a0BtQ/vOe VMOxZ/kMgRF/F+UGWxv1/YpqIM1u8KNx/DEq1E4MzIdJe3QVokO2zfXfzQcJSsq8Y7eYRIzLTh9 LruDGA51YAFmoj1jTX6r5HIeo+CDJCRU3RxmZi9AXp0b60wgUi6+DaBTtMi9m9AWnImE= X-Gm-Gg: AR+sD13cExqOV7bOV2J/lmcz/z0fbGHruAZxdpEu02RTP+Qxtl3PQXc7JY1AyELFdNH 3UjJamePebMRRnncAI72vuBBvfs3yg5HS4E+/ZFxHO2tLJTiqC5DSg1xOoUWP9sltHfP/zBXjse Cy7UBIz8XIc/AUlOp4mPY5/QmmAvZqxuJD/aicG5DfBc4PbMMM3G6G/UucgiOZEXsoeDBXw3n6j K+70iIedno4RleU3f4Syen+R34tnqlnjfxXLdlhLub1bA+QRaA6NQNH+XJAT97fji9KVltebYK9 iBj9SAeqVtEeEyujYvEZ6PNkxuhcuhKDMIyJqDer9jv8s1YvAUbGOxFP03X9Qi6lGdwT4/B0A4g TKPrMHNBztH8TfdyGUMjyhudWQg== X-Received: by 2002:a17:903:1a87:b0:2c8:25c8:85a6 with SMTP id d9443c01a7336-2cf3481b77fmr231364105ad.2.1784703590451; Tue, 21 Jul 2026 23:59:50 -0700 (PDT) X-Received: by 2002:a17:903:1a87:b0:2c8:25c8:85a6 with SMTP id d9443c01a7336-2cf3481b77fmr231363795ad.2.1784703589966; Tue, 21 Jul 2026 23:59:49 -0700 (PDT) Received: from hu-hdev-hyd.qualcomm.com ([202.46.22.19]) by smtp.gmail.com with ESMTPSA id d9443c01a7336-2cf8efd88f7sm9428935ad.22.2026.07.21.23.59.45 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 21 Jul 2026 23:59:49 -0700 (PDT) From: Harshal Dev Date: Wed, 22 Jul 2026 12:29:14 +0530 Subject: [PATCH v2 3/6] tee: qcomtee: Allow object invokes from kernel clients Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260722-qcom_uefisecapp_migrate_qcomtee-v2-3-b8a8fcbe4211@oss.qualcomm.com> References: <20260722-qcom_uefisecapp_migrate_qcomtee-v2-0-b8a8fcbe4211@oss.qualcomm.com> In-Reply-To: <20260722-qcom_uefisecapp_migrate_qcomtee-v2-0-b8a8fcbe4211@oss.qualcomm.com> To: Jens Wiklander , Jens Wiklander , Sumit Garg , Amirreza Zarrabi , Bjorn Andersson , Konrad Dybcio Cc: Basant Kumar , Apurupa Pattapu , Arun Kumar Neelakantam , op-tee@lists.trustedfirmware.org, linux-kernel@vger.kernel.org, linux-arm-msm@vger.kernel.org, Harshal Dev X-Mailer: b4 0.14.3 X-Developer-Signature: v=1; a=ed25519-sha256; t=1784703569; l=6532; i=harshal.dev@oss.qualcomm.com; s=20251124; h=from:subject:message-id; bh=ZmUkuPpOF1W6pfjx6a8SqHj69RiLqeBYMsNl5lK852Q=; b=qYiW8DMUyPHo2m/kD+h7brMbuBtdk9j4aOvafDtQ9+Ij8V6+NkUH2Ec4Z1mzHUvDALnv295M5 p73dmDh1H9hB8ql7hxwfvh+wRBxvlBPPXBhhRev+voj9faF6edqc6jM X-Developer-Key: i=harshal.dev@oss.qualcomm.com; a=ed25519; pk=SHJ8K4SglF5t7KmfMKXl6Mby40WczSeLs4Qus7yFO7c= X-Proofpoint-ORIG-GUID: 7TP2I_PUhD4es2XgckXSm5EYrCyk_7OE X-Proofpoint-Spam-Info: AW1haW4tMjYwNzIyMDA2MyBTYWx0ZWRfX36d0/jlqnPYJ T0Z/+th5bRHQzL+nr5iQqptXZOvY+xJsecpBBB6szfZTO1I7q2DtnwZWxngxt07gUQYvukbiPE6 iHnOX7/S4Id/rGDBd6HDRN/8Eubnc/0= X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwNzIyMDA2MyBTYWx0ZWRfXwztLESrmDchf jlznDZislagaXR0/tR07H7iBWEgqSGw2aixAtkyMIhZHUrhSIP/5tlWpta6zJCSGB+oUhaVjchy q0yTcXK9Xf82Nc2BdFGR4wwyXEzbQ/TCTxHrL/eySQNYfuJJL+CHfPHunsZzZjK3Y2hlccX5091 LQpoFgaEb32niyfl89buwHRgUzoyWfiqctB5mG0Ie3166ZgGxexA08tt/iQX9JYs8ssPfDx44dr SWbKYARjROsnx6/gGS1vCLfKFqIIIFPnjU58KIHpNc0QfEjPjwhZycYjjbp3oTUVvoaNgLJVi/+ zkBiGvbaTINp1eANgBDh5G6FcRr3qUotPaw+dKXEsW8g5N5pOH+qcq3V8+FvHpJUTasOqccfmMc o/vDttA5Q+TVeUmKqteIQ2Sqx/xBLNLSqDVaDlSLPqxy55g0FtUwYLN5GY0I0lQ6jM7jwnkLwKh WdmLFiuQ5s4Yn8KADFw== X-Proofpoint-GUID: 7TP2I_PUhD4es2XgckXSm5EYrCyk_7OE X-Authority-Analysis: v=2.4 cv=Cr6PtH4D c=1 sm=1 tr=0 ts=6a606a67 cx=c_pps a=rz3CxIlbcmazkYymdCej/Q==:117 a=fChuTYTh2wq5r3m49p7fHw==:17 a=IkcTkHD0fZMA:10 a=RAioF0-LDSMA:10 a=s4-Qcg_JpJYA:10 a=VkNPw1HP01LnGYTKEx00:22 a=u7WPNUs3qKkmUXheDGA7:22 a=yx91gb_oNiZeI1HMLzn7:22 a=EUspDBNiAAAA:8 a=XyePUiwmHbEyLJ1dZiEA:9 a=QEXdDO2ut3YA:10 a=bFCP_H2QrGi7Okbo017w:22 X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1143,Hydra:6.1.134,FMLib:17.12.100.49 definitions=2026-07-22_02,2026-07-21_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 priorityscore=1501 malwarescore=0 adultscore=0 impostorscore=0 lowpriorityscore=0 spamscore=0 phishscore=0 clxscore=1015 suspectscore=0 bulkscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2607220063 From: Amirreza Zarrabi QCOMTEE currently treats UBUF parameters as userspace addresses and applies userspace restrictions when invoking the root object. This is not suitable for object invocation requests issued by kernel clients. Use the kernel_ctx flag to distinguish kernel client requests from userspace requests. For kernel contexts, do not mark UBUF parameters as user addresses, and allow permitted root-object operations to proceed without applying the userspace-only checks. This allows in-kernel users of tee_client_object_invoke_func() to issue object invocation requests through the qcomtee backend. Co-developed-by: Harshal Dev Signed-off-by: Harshal Dev Signed-off-by: Amirreza Zarrabi --- drivers/tee/qcomtee/call.c | 34 +++++++++++++++++++++++---------= -- drivers/tee/qcomtee/qcomtee_object.h | 5 +++-- include/linux/tee_drv.h | 5 ++++- 3 files changed, 30 insertions(+), 14 deletions(-) diff --git a/drivers/tee/qcomtee/call.c b/drivers/tee/qcomtee/call.c index 03d33b118f6d..c1bba5fbfa3e 100644 --- a/drivers/tee/qcomtee/call.c +++ b/drivers/tee/qcomtee/call.c @@ -202,7 +202,7 @@ int qcomtee_objref_from_arg(struct tee_param *param, st= ruct qcomtee_arg *arg, */ static int qcomtee_params_to_args(struct qcomtee_arg *u, struct tee_param *params, int num_params, - struct tee_context *ctx) + struct qcomtee_object_invoke_ctx *oic) { int i; =20 @@ -210,8 +210,14 @@ static int qcomtee_params_to_args(struct qcomtee_arg *= u, switch (params[i].attr) { case TEE_IOCTL_PARAM_ATTR_TYPE_UBUF_INPUT: case TEE_IOCTL_PARAM_ATTR_TYPE_UBUF_OUTPUT: - u[i].flags =3D QCOMTEE_ARG_FLAGS_UADDR; - u[i].b.uaddr =3D params[i].u.ubuf.uaddr; + u[i].flags =3D oic->kernel_ctx ? 0 : + QCOMTEE_ARG_FLAGS_UADDR; + + if (u[i].flags && QCOMTEE_ARG_FLAGS_UADDR) + u[i].b.uaddr =3D params[i].u.ubuf.uaddr; + else + u[i].b.addr =3D params[i].u.ubuf.addr; + u[i].b.size =3D params[i].u.ubuf.size; =20 if (params[i].attr =3D=3D @@ -223,7 +229,7 @@ static int qcomtee_params_to_args(struct qcomtee_arg *u, break; case TEE_IOCTL_PARAM_ATTR_TYPE_OBJREF_INPUT: u[i].type =3D QCOMTEE_ARG_TYPE_IO; - if (qcomtee_objref_to_arg(&u[i], ¶ms[i], ctx)) + if (qcomtee_objref_to_arg(&u[i], ¶ms[i], oic->ctx)) goto out_failed; =20 break; @@ -270,7 +276,7 @@ static int qcomtee_params_to_args(struct qcomtee_arg *u, */ static int qcomtee_params_from_args(struct tee_param *params, struct qcomtee_arg *u, int num_params, - struct tee_context *ctx) + struct qcomtee_object_invoke_ctx *oic) { int i, np; =20 @@ -288,7 +294,8 @@ static int qcomtee_params_from_args(struct tee_param *p= arams, break; case QCOMTEE_ARG_TYPE_OO: /* TEE_IOCTL_PARAM_ATTR_TYPE_OBJREF_OUTPUT */ - if (qcomtee_objref_from_arg(¶ms[np], &u[np], ctx)) + if (qcomtee_objref_from_arg(¶ms[np], &u[np], + oic->ctx)) goto out_failed; =20 break; @@ -304,7 +311,7 @@ static int qcomtee_params_from_args(struct tee_param *p= arams, /* Undo qcomtee_objref_from_arg(). */ for (i =3D 0; i < np; i++) { if (params[i].attr =3D=3D TEE_IOCTL_PARAM_ATTR_TYPE_OBJREF_OUTPUT) - qcomtee_context_del_qtee_object(¶ms[i], ctx); + qcomtee_context_del_qtee_object(¶ms[i], oic->ctx); } =20 /* Release any IO and OO objects not processed. */ @@ -357,7 +364,8 @@ static int qcomtee_params_check(struct tee_param *param= s, int num_params) } =20 /* Check if an operation on ROOT_QCOMTEE_OBJECT from userspace is permitte= d. */ -static int qcomtee_root_object_check(u32 op, struct tee_param *params, +static int qcomtee_root_object_check(struct qcomtee_object_invoke_ctx *oic, + u32 op, struct tee_param *params, int num_params) { /* Some privileged operations recognized by QTEE. */ @@ -366,6 +374,9 @@ static int qcomtee_root_object_check(u32 op, struct tee= _param *params, op =3D=3D QCOMTEE_ROOT_OP_ADCI_SHUTDOWN) return -EINVAL; =20 + if (oic->kernel_ctx) + return 0; + /* * QCOMTEE_ROOT_OP_REG_WITH_CREDENTIALS is to register with QTEE * by passing a credential object as input OBJREF. TEE_OBJREF_NULL as a @@ -429,7 +440,8 @@ static int qcomtee_object_invoke(struct tee_context *ct= x, /* Get an object to invoke. */ if (arg->id =3D=3D TEE_OBJREF_NULL) { /* Use ROOT if TEE_OBJREF_NULL is invoked. */ - if (qcomtee_root_object_check(arg->op, params, arg->num_params)) + if (qcomtee_root_object_check(oic, arg->op, params, + arg->num_params)) return -EINVAL; =20 object =3D ROOT_QCOMTEE_OBJECT; @@ -437,7 +449,7 @@ static int qcomtee_object_invoke(struct tee_context *ct= x, return -EINVAL; } =20 - ret =3D qcomtee_params_to_args(u, params, arg->num_params, ctx); + ret =3D qcomtee_params_to_args(u, params, arg->num_params, oic); if (ret) goto out; =20 @@ -455,7 +467,7 @@ static int qcomtee_object_invoke(struct tee_context *ct= x, =20 if (!result) { /* Assume service is UNAVAIL if unable to process the result. */ - if (qcomtee_params_from_args(params, u, arg->num_params, ctx)) + if (qcomtee_params_from_args(params, u, arg->num_params, oic)) result =3D QCOMTEE_MSG_ERROR_UNAVAIL; } else { /* diff --git a/drivers/tee/qcomtee/qcomtee_object.h b/drivers/tee/qcomtee/qco= mtee_object.h index 2528d07e4576..7bd6e23b038c 100644 --- a/drivers/tee/qcomtee/qcomtee_object.h +++ b/drivers/tee/qcomtee/qcomtee_object.h @@ -112,8 +112,9 @@ struct qcomtee_buffer { * @b: address and size if the type of argument is a buffer. * @o: object instance if the type of argument is an object. * - * &qcomtee_arg.flags only accepts %QCOMTEE_ARG_FLAGS_UADDR for now, which - * states that &qcomtee_arg.b contains a userspace address in uaddr. ++ * If %QCOMTEE_ARG_FLAGS_UADDR is set in &qcomtee_arg.flags then it impli= es ++ * that &qcomtee_arg.b contains a userspace address in uaddr. ++ * Otherwise, &qcomtee_arg.b contains a kernel address in addr. */ struct qcomtee_arg { enum qcomtee_arg_type type; diff --git a/include/linux/tee_drv.h b/include/linux/tee_drv.h index ca99c6b747a8..71d0536db60e 100644 --- a/include/linux/tee_drv.h +++ b/include/linux/tee_drv.h @@ -83,7 +83,10 @@ struct tee_param_memref { }; =20 struct tee_param_ubuf { - void __user *uaddr; + union { + void *addr; + void __user *uaddr; + }; size_t size; }; =20 --=20 2.34.1 From nobody Fri Jul 24 23:31:27 2026 Received: from mx0a-0031df01.pphosted.com (mx0a-0031df01.pphosted.com [205.220.168.131]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 6C2F43B8D40 for ; Wed, 22 Jul 2026 06:59:57 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=205.220.168.131 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784703598; cv=none; b=jvGsyNFsP7asnlXoddUWSbDrsA1Tg6cB7FMD8kV8E8dFk53akbK2f6MtmHnmqP53nVKqGeOFD2vfGWGNjFmOU+uBUDGWKxLptA4rj5/DVjAFCoxi6Aj+RnxIuTog5hoSs/MwwxsjplYXI9EprWacCK2tb+Y4GcaZHzZH59WoEuY= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784703598; c=relaxed/simple; bh=UutwisPxLmXUS8raj8VcKR5HsTjTxGdmVUYtVk2b150=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=jSKDKhwH6BEPJjcO1J5l+FSAs2SatDCHMOSSzT0A1l0alTPn3p8Ieu1RgBGiOapTVcxet9KrRDBtefiyRhhxGZDiKlxnY7I0iCyTZmLA2EyhAkbe8Mb7RkfY2TRwy73s47C7Yxih6KgrQ8O9Lz8TBsqSSIJWZUp5jD+DppNoxaQ= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=oss.qualcomm.com; spf=pass smtp.mailfrom=oss.qualcomm.com; dkim=pass (2048-bit key) header.d=qualcomm.com header.i=@qualcomm.com header.b=nUbNWyQu; dkim=pass (2048-bit key) header.d=oss.qualcomm.com header.i=@oss.qualcomm.com header.b=OzBK9sif; arc=none smtp.client-ip=205.220.168.131 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=oss.qualcomm.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=oss.qualcomm.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=qualcomm.com header.i=@qualcomm.com header.b="nUbNWyQu"; dkim=pass (2048-bit key) header.d=oss.qualcomm.com header.i=@oss.qualcomm.com header.b="OzBK9sif" Received: from pps.filterd (m0279862.ppops.net [127.0.0.1]) by mx0a-0031df01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 66M53bHL3767556 for ; Wed, 22 Jul 2026 06:59:56 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=qualcomm.com; h= cc:content-transfer-encoding:content-type:date:from:in-reply-to :message-id:mime-version:references:subject:to; s=qcppdkim1; bh= DN7n/bdfkW6wuLU+Ox37xcY8Be/ZEVNLsXfifpOhL+0=; b=nUbNWyQumK/DBmof ASV/5Cgecfp7vw6pRDIrtK0EYgydzKrCfa0aRoZF+9toVz4+GSPKwov0nLunkk8i /XTTrfT2uz9/qogFAy11SXiDSmmp8b5e8zhJXvGhFrxDPCL6JB8hlSw08bfKi3vJ jLiaf4iAFe82/RU0aQ4pWZxhctj3hgY8mxPp5QDvp9NZbrVq0y32j5ORByL2Ph18 8uaQNy/5KllxXFiFkeL9J2pR4lFFowwcE32Kympw/QztfusgTZmkwPwNQqAoyUXw k2o7DwWbkLqW0VcwSIAv+a/c/HBTDcb8s//vIcsIV1LbJfgOcqoa7nqbIMJ9vQnt eGdrhw== Received: from mail-pl1-f197.google.com (mail-pl1-f197.google.com [209.85.214.197]) by mx0a-0031df01.pphosted.com (PPS) with ESMTPS id 4fjnu4rrak-1 (version=TLSv1.3 cipher=TLS_AES_128_GCM_SHA256 bits=128 verify=NOT) for ; Wed, 22 Jul 2026 06:59:56 +0000 (GMT) Received: by mail-pl1-f197.google.com with SMTP id d9443c01a7336-2ccd1958e8fso123695405ad.2 for ; Tue, 21 Jul 2026 23:59:56 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=oss.qualcomm.com; s=google; t=1784703596; x=1785308396; darn=vger.kernel.org; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=DN7n/bdfkW6wuLU+Ox37xcY8Be/ZEVNLsXfifpOhL+0=; b=OzBK9sifXP63963fzL0qExpeb3uOAYEEitEn3oXr59FQoKjsFTqzNKRs6cGCEqwFel aYJtNCyF56FjCnOd2qLOayjRi0Vh7Rub2I9PeqslFF24kPWfeMeItDVX2zW62fUn/R7B LRP4Tv06sE4s9xnmdU0wuiGL0GqGet1DI520LwLCB5O1XWatXBB8n6MuAZOry0tG3lvb JQnoiMuofMqO78tqbSqIIzd6D4/eW3kTWoO7ca1i7kSEWe3imEAfiUQxBZ126X8a+G6l ylB+60YcSLokyHccQLdgGIO2sGJD/X6uM+EO/JoFYEn3kIyRpwQI+kNRPTBvXAqWjCE9 j1MA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784703596; x=1785308396; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=DN7n/bdfkW6wuLU+Ox37xcY8Be/ZEVNLsXfifpOhL+0=; b=qz5zNxHHZhWLndflf0qEVCt85kwz5pZOqsDthr/I/B7WbINc2ODmJC25+HQWR5oaof zZUy3J5pNn1dGBV+PMHN80EWtEYLXmUQ3RKeGgkeU7csqNhO9e0xo1A5mxBxCiwWR2mN yi3TmUVOnIDcVnxKkQVhu02OoU8UOcy7X+Hv3Ds3rzkkcZ6BqCUOwTO5Kl9RBclrKSeO NNdWPk5G6GUDZonIMcFkwvHKLv9Fx95AAzZOw+ICqkqS4GEamo/y5QT33znPdTnaIVna mkcuNyzaQHSBqBhdxqKHUFl+XX4VwKvQwC4mI6VU4Sn9kCyBmYP0jkMOst30Z0I81ZSQ T9ag== X-Forwarded-Encrypted: i=1; AHgh+RoERsm9ltCQyhNhsW1gvkUkh3TspwXT8Azk1JtHbvszbUNbrxU7RGmLfcaOEh8SGfnkrUInm63mMb8bLb0=@vger.kernel.org X-Gm-Message-State: AOJu0Yw7Rbtm/iUpmwcfzARYlm/sz28NzelYgMf+DgbAJY0e2hPKx/vh WX4v0SXKog/FZ3csNv0v34Lnc/ed1pHvFrWKKNe6U52+mruxjCAsJ7jaOsOEGCEBbR4EMZ+tgRV lQni1jJUZOxvaPOrYG/8IruIdsLOhrFUys7t05XGxljfVuAaPVZJmjs5xDqMsRU4IFzo= X-Gm-Gg: AR+sD10Q9LTDxY2pVYyIw1p1GtvuoW8rVARMeEzpdnAgdyTSmAZu7hGxbYZdXq57xJA ex+j1jO6kd3CoZ52Pg65eysSf8Q1iMv8dKH34pKAKfC9exABvu8++7yjiZMQLRuJKOa978vdbk8 quWpL6oNWQv+77SukXNz9dPLL+Kb3o5otCZYOdd3J/KmQmPbQ3gVKd1zBe0QYEy+g27MC4PaDD+ +NR5Pn2z8ASKGj3u/u9mfLFlcZzrVmDi1tEpLOVxsetLDpxUrXuqA/93yJfaag9h6Fsd5FKLB6o l6teu122Qy/KVUf+Qu8uFV6e5pw+S97+WVNr1/3BCh2QjKbp16xVRP/X2Ffult8zQfIID1nUlWK wPMIA8rOXh9J98YYFpjSl150Wpw== X-Received: by 2002:a17:902:d48a:b0:2ca:b8fd:f31 with SMTP id d9443c01a7336-2cf34889935mr241887125ad.15.1784703595872; Tue, 21 Jul 2026 23:59:55 -0700 (PDT) X-Received: by 2002:a17:902:d48a:b0:2ca:b8fd:f31 with SMTP id d9443c01a7336-2cf34889935mr241886725ad.15.1784703595269; Tue, 21 Jul 2026 23:59:55 -0700 (PDT) Received: from hu-hdev-hyd.qualcomm.com ([202.46.22.19]) by smtp.gmail.com with ESMTPSA id d9443c01a7336-2cf8efd88f7sm9428935ad.22.2026.07.21.23.59.50 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 21 Jul 2026 23:59:54 -0700 (PDT) From: Harshal Dev Date: Wed, 22 Jul 2026 12:29:15 +0530 Subject: [PATCH v2 4/6] tee: Export uuidv5 generation for TEE backends Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260722-qcom_uefisecapp_migrate_qcomtee-v2-4-b8a8fcbe4211@oss.qualcomm.com> References: <20260722-qcom_uefisecapp_migrate_qcomtee-v2-0-b8a8fcbe4211@oss.qualcomm.com> In-Reply-To: <20260722-qcom_uefisecapp_migrate_qcomtee-v2-0-b8a8fcbe4211@oss.qualcomm.com> To: Jens Wiklander , Jens Wiklander , Sumit Garg , Amirreza Zarrabi , Bjorn Andersson , Konrad Dybcio Cc: Basant Kumar , Apurupa Pattapu , Arun Kumar Neelakantam , op-tee@lists.trustedfirmware.org, linux-kernel@vger.kernel.org, linux-arm-msm@vger.kernel.org, Harshal Dev X-Mailer: b4 0.14.3 X-Developer-Signature: v=1; a=ed25519-sha256; t=1784703569; l=2841; i=harshal.dev@oss.qualcomm.com; s=20251124; h=from:subject:message-id; bh=UutwisPxLmXUS8raj8VcKR5HsTjTxGdmVUYtVk2b150=; b=e3840ElqGSsbHCB/vLaMQ0i5nkwNtX7qIXk4AQ5l3SYykOH+T0ZsgFDH5wsLcBe09Pbg1b0lV ojALYmxiZ/7DcaLepple6Z8D1EJcn3Wc9nlMRylWSvsb0nWaz2EIMLn X-Developer-Key: i=harshal.dev@oss.qualcomm.com; a=ed25519; pk=SHJ8K4SglF5t7KmfMKXl6Mby40WczSeLs4Qus7yFO7c= X-Proofpoint-GUID: -oyRb4NHvDFS0FzaCo4DqHrnBc4x1ikx X-Authority-Analysis: v=2.4 cv=KLhqylFo c=1 sm=1 tr=0 ts=6a606a6c cx=c_pps a=cmESyDAEBpBGqyK7t0alAg==:117 a=fChuTYTh2wq5r3m49p7fHw==:17 a=IkcTkHD0fZMA:10 a=RAioF0-LDSMA:10 a=s4-Qcg_JpJYA:10 a=VkNPw1HP01LnGYTKEx00:22 a=u7WPNUs3qKkmUXheDGA7:22 a=_K5XuSEh1TEqbUxoQ0s3:22 a=EUspDBNiAAAA:8 a=_y_UpZ8dDEjReVSEE2UA:9 a=+jEqtf1s3R9VXZ0wqowq2kgwd+I=:19 a=QEXdDO2ut3YA:10 a=1OuFwYUASf3TG4hYMiVC:22 X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwNzIyMDA2MyBTYWx0ZWRfX1BqHeqGyr2CC A4XcQeNxxfhSdGpd8kXkl6lK9/ku6+RxZNbh8R5YPvz0RaEU0UX5o/v8VENUqtTjTW7+6eUjF01 hmtakwIhbAVxLYahFgfNRaFI5slLN1lZuIMzNLOecdEsETr1I2t/R5OdAL//IEzcYQY/7rpQapV CIHV9rjsUa0HTV1Cm8ctmU9g0IeSwAeTQ3/FQX+mGZ11oNdKtKbiGX5EZDCzxVXV0S7LovVTG7M 1hcZI0SjIT3mTXIHvRvsSA1kNvYHd9XYOOpyeEN4dmDdq3j3S3waZC3i1441xGoO5Qp9qrdEX3z nqdhLEmdUomc2khKLWxJiNK2erp9Bg7oqxZW0EsDJDT0dFrBKOLpZCKc4WnCyx6u/gOjZOARSpg RNWcZPpzJ0zS5WvLIZ/MnZsucIZL+n57XgX+s5OfugWlsehTazQGQxJB1shgYKPj9oViIXPqyJA qQaOYKu9IfVZjvcXccQ== X-Proofpoint-ORIG-GUID: -oyRb4NHvDFS0FzaCo4DqHrnBc4x1ikx X-Proofpoint-Spam-Info: AW1haW4tMjYwNzIyMDA2MyBTYWx0ZWRfX5FAvVGGNlcLv A+yC6ROxAmyQeqdUnGKwN/+Gn9wTSe0kDAB3GZ5tqwbC7yA5Va07ahvAv7i/OvFmkPGfT9QQfcW v6e2voUiP43qXnyLfONlQeeC0/zHZKo= X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1143,Hydra:6.1.134,FMLib:17.12.100.49 definitions=2026-07-22_02,2026-07-21_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 bulkscore=0 spamscore=0 clxscore=1015 impostorscore=0 lowpriorityscore=0 priorityscore=1501 malwarescore=0 phishscore=0 adultscore=0 suspectscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2607220063 Export the uuidv5() function defined in the TEE core to all TEE backends. This enables the TEE backend drivers to generate a UUID for identifying and registering their secure services on the TEE bus. Signed-off-by: Harshal Dev --- drivers/tee/tee_core.c | 9 +++++---- include/linux/tee_core.h | 15 +++++++++++++++ 2 files changed, 20 insertions(+), 4 deletions(-) diff --git a/drivers/tee/tee_core.c b/drivers/tee/tee_core.c index bb418490f3af..df88727b3680 100644 --- a/drivers/tee/tee_core.c +++ b/drivers/tee/tee_core.c @@ -135,7 +135,7 @@ static int tee_release(struct inode *inode, struct file= *filp) } =20 /** - * uuid_v5() - Calculate UUIDv5 + * tee_generate_uuid_v5() - Calculate UUIDv5 * @uuid: Resulting UUID * @ns: Name space ID for UUIDv5 function * @name: Name for UUIDv5 function @@ -146,8 +146,8 @@ static int tee_release(struct inode *inode, struct file= *filp) * This implements section (for SHA-1): * 4.3. Algorithm for Creating a Name-Based UUID */ -static void uuid_v5(uuid_t *uuid, const uuid_t *ns, const void *name, - size_t size) +void tee_generate_uuid_v5(uuid_t *uuid, const uuid_t *ns, const void *name, + size_t size) { unsigned char hash[SHA1_DIGEST_SIZE]; struct sha1_ctx ctx; @@ -163,6 +163,7 @@ static void uuid_v5(uuid_t *uuid, const uuid_t *ns, con= st void *name, uuid->b[6] =3D (hash[6] & 0x0F) | 0x50; uuid->b[8] =3D (hash[8] & 0x3F) | 0x80; } +EXPORT_SYMBOL_GPL(tee_generate_uuid_v5); =20 int tee_session_calc_client_uuid(uuid_t *uuid, u32 connection_method, const u8 connection_data[TEE_IOCTL_UUID_LEN]) @@ -228,7 +229,7 @@ int tee_session_calc_client_uuid(uuid_t *uuid, u32 conn= ection_method, goto out_free_name; } =20 - uuid_v5(uuid, &tee_client_uuid_ns, name, name_len); + tee_generate_uuid_v5(uuid, &tee_client_uuid_ns, name, name_len); out_free_name: kfree(name); =20 diff --git a/include/linux/tee_core.h b/include/linux/tee_core.h index bcb5418d6fdc..a3f4f88b8423 100644 --- a/include/linux/tee_core.h +++ b/include/linux/tee_core.h @@ -272,6 +272,21 @@ void tee_device_set_dev_groups(struct tee_device *teed= ev, int tee_session_calc_client_uuid(uuid_t *uuid, u32 connection_method, const u8 connection_data[TEE_IOCTL_UUID_LEN]); =20 +/** + * tee_generate_uuid_v5() - Calculate UUIDv5 + * @uuid: Resulting UUID + * @ns: Name space ID for UUIDv5 function + * @name: Name for UUIDv5 function + * @size: Size of name + * + * UUIDv5 is specific in RFC 4122. + * + * This implements section (for SHA-1): + * 4.3. Algorithm for Creating a Name-Based UUID + */ +void tee_generate_uuid_v5(uuid_t *uuid, const uuid_t *ns, const void *name, + size_t size); + /** * struct tee_shm_pool - shared memory pool * @ops: operations --=20 2.34.1 From nobody Fri Jul 24 23:31:27 2026 Received: from mx0b-0031df01.pphosted.com (mx0b-0031df01.pphosted.com [205.220.180.131]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 87CC23B8D40 for ; Wed, 22 Jul 2026 07:00:03 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=205.220.180.131 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784703614; cv=none; b=AQK6hYqlwhfh9JN2N6A7prEwgnCKuTVsAhW7SAr/IPCqRfIlxWIXAO5MPACnTE0PNTINiv6lWxCikgDhtyMw4CH9kzU2SgFpGhXXXqpo7+NSUvyjZE/H2bq0fnZKXtbFQXROuj5nusZIoARkDoR9fHVdLjqYPORhAFtISxp2+HI= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784703614; c=relaxed/simple; bh=ltTUr4ZNz1WK8n1xoNtPuphhExPvrUNLbuEMZg8+YzA=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=Te1dUDuUZGaOY75HFVpJp1EvgFk25brWjpadL2eSUzUFFSVjjmMRJEgbFWdSSI733jx26T7+thP7eYKUstxTqdzBHAY0YNMt/VvHIKuttHxb4MLCm5tccWU82a97kUrfMHn9uEaOjpzF3/DX8xvp+sBB7BLYqWr6WCEfhcZMk7E= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=oss.qualcomm.com; spf=pass smtp.mailfrom=oss.qualcomm.com; dkim=pass (2048-bit key) header.d=qualcomm.com header.i=@qualcomm.com header.b=k6Cwq5Pf; dkim=pass (2048-bit key) header.d=oss.qualcomm.com header.i=@oss.qualcomm.com header.b=f2uz4/JC; arc=none smtp.client-ip=205.220.180.131 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=oss.qualcomm.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=oss.qualcomm.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=qualcomm.com header.i=@qualcomm.com header.b="k6Cwq5Pf"; dkim=pass (2048-bit key) header.d=oss.qualcomm.com header.i=@oss.qualcomm.com header.b="f2uz4/JC" Received: from pps.filterd (m0279872.ppops.net [127.0.0.1]) by mx0a-0031df01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 66M53jJE3787196 for ; Wed, 22 Jul 2026 07:00:02 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=qualcomm.com; h= cc:content-transfer-encoding:content-type:date:from:in-reply-to :message-id:mime-version:references:subject:to; s=qcppdkim1; bh= Z7g91lbv5RV9lZPR9a6UTHIBqV9Y4ZqcpArgNql62cA=; b=k6Cwq5PfeE6QB+Hx EYJhzHCY3i0gmOedVUIhpY3D0eyGv2i1svyuPpqqJiwBF7TPq87wLlLcWhFk+1B8 0aTfRaItVY9Qki/npFrecIViW5EcgK8tDQBrUW1D+olpOEU7AN5bD932DLNwuUMb iLQpkCnEQ8XoiTwQ+zwU3D594sQwaDyggCFJS6BJPbp6au9n1UOtklA3zaJeu9gh yp9cghMG1rGHAqAmcHJgEkdo2BuzMtCcl+x5ysqq1ygFwfGHnwJnYzjhaHqhsvQH YfoTHylGCK1n/5Vknw0yCeoVufYp+WuhDawxqRqZV5uklOlxhYSDANfJcBalOY20 HuUURA== Received: from mail-pl1-f197.google.com (mail-pl1-f197.google.com [209.85.214.197]) by mx0a-0031df01.pphosted.com (PPS) with ESMTPS id 4fj9aec33e-1 (version=TLSv1.3 cipher=TLS_AES_128_GCM_SHA256 bits=128 verify=NOT) for ; Wed, 22 Jul 2026 07:00:02 +0000 (GMT) Received: by mail-pl1-f197.google.com with SMTP id d9443c01a7336-2cc640dfde3so103915435ad.1 for ; Wed, 22 Jul 2026 00:00:02 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=oss.qualcomm.com; s=google; t=1784703601; x=1785308401; darn=vger.kernel.org; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=Z7g91lbv5RV9lZPR9a6UTHIBqV9Y4ZqcpArgNql62cA=; b=f2uz4/JCl/bnfPxAMs+Gf1GVbrqo8ayfsRCqh8HBZYgl70m+xWWQfNP6CXEz4H3o2C e7g/aSRxC5lg+n43vLceLNPHrDRla0Kq0Qr5/NCYnHTGdiCjsyReZkLnorvpHiItCUQd EZ4SxDoLzS4wwiclPOGU50dSUHOn5FNzaW3NrMG1aNihO/8Zi7hcduDSi1thD/nVjYUf FolShHGJ2fOIL0oMGFJkin7FtdA+uFa+bOJpaHBGvSjaCZ1Q9V2R40FXaaXTt4E199a4 vl1N+bbbF4RhAAgDurCrKbQMhmunngiOLr/7pHxBdR+mBKHfuzDHWbgnLDjftQJKi/Cv Hs4g== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784703601; x=1785308401; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=Z7g91lbv5RV9lZPR9a6UTHIBqV9Y4ZqcpArgNql62cA=; b=Yk/YISWKd/rew6x4ap+iBydbyPl/YvaSSd4sSDvy1xsQbheBu76LLK9b4SLSMFk0ht YzHiDega4n3/AvRDFQr10k/wzToYw7BIYzdR4oZg17KKSGNtj7fab9V9xgjKWn59ppyV GNDo5FfEdX5KGZgYWJ7ZEJwigGibIHkLd9aOqcR1uAW3ymTDCwfjgP4ZSftUCLp9UYaO hLZWUQO2h49oIzGDi5rcP56aLUBXQx+iNLeDJvbIJEwrEMydjrJUl0EaF07onCGsdxea fNPnusLM3uVIGb9yqixpQn4YGKoZKt8rx2ext5HDQg9tb6nNS01phyBvFj00ubKm8KHH LcwQ== X-Forwarded-Encrypted: i=1; AHgh+RodYzyCojjZSPai6+VhanaV8HfG4PpjeAKrF/YChKAtEieHfr26IjiAcxl3SyGTWiXAL3KRwlHBP8hymKQ=@vger.kernel.org X-Gm-Message-State: AOJu0YwK1aSdEbhzeA1fx17baJrqXCWBuqM9Xn7Coq0FRL8aOh3Gn1tT JhtXt2/xtyLaKJd8YZBK9W+8aTRE7QazLhTcv/JlaUqWYudtboNDX1i/TZxaXKS/MEB1FsVjagZ FF9UBB5E91mctRZUl/bQdXpwjTVh1HIm076fOGMuTIYOCtO3XigG4xotK/yraAgMOl5w= X-Gm-Gg: AR+sD11U1Wdxm62gH4/MLjn1yrvZ5fYv23jIC1kZZhS78dVLrDG2aknzvng8b2NXmrs j5sNK/gKaEaV3iVYc4vxRCs1u+zxcbz9V4hFnn0JcS9W4lQRe5n7Ys5kxFeCN19rK0hNP3TSRYh /XOh4T2a7m/rk64YIrgZ65m8zwblaNe4/XyKblQdimsnoSaFZgZY32a9Cn2zihYSzhS2JbYMLr/ k9yZtBtpEFLjeZnJtej7DPLvE6KC3R1e920F2af3Y2cQcG96i1/1t/KSzJ1OIcjUmrxxr1MWojk XvYvwqenI/jgH69B8k/NLk5rzmZT/Swu0gCo/1Gom/J8ctIKFcn88TYm0UX8IPmUYEP2JSnpG/Y fZ9CmPGkzcyMsy/hlSmVHmwavfg== X-Received: by 2002:a17:903:40cf:b0:2ca:2079:91cc with SMTP id d9443c01a7336-2cf34836a55mr231116785ad.5.1784703600895; Wed, 22 Jul 2026 00:00:00 -0700 (PDT) X-Received: by 2002:a17:903:40cf:b0:2ca:2079:91cc with SMTP id d9443c01a7336-2cf34836a55mr231116565ad.5.1784703600419; Wed, 22 Jul 2026 00:00:00 -0700 (PDT) Received: from hu-hdev-hyd.qualcomm.com ([202.46.22.19]) by smtp.gmail.com with ESMTPSA id d9443c01a7336-2cf8efd88f7sm9428935ad.22.2026.07.21.23.59.55 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 21 Jul 2026 23:59:59 -0700 (PDT) From: Harshal Dev Date: Wed, 22 Jul 2026 12:29:16 +0530 Subject: [PATCH v2 5/6] tee: qcomtee: Add support for registering QTEE services on TEE bus Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260722-qcom_uefisecapp_migrate_qcomtee-v2-5-b8a8fcbe4211@oss.qualcomm.com> References: <20260722-qcom_uefisecapp_migrate_qcomtee-v2-0-b8a8fcbe4211@oss.qualcomm.com> In-Reply-To: <20260722-qcom_uefisecapp_migrate_qcomtee-v2-0-b8a8fcbe4211@oss.qualcomm.com> To: Jens Wiklander , Jens Wiklander , Sumit Garg , Amirreza Zarrabi , Bjorn Andersson , Konrad Dybcio Cc: Basant Kumar , Apurupa Pattapu , Arun Kumar Neelakantam , op-tee@lists.trustedfirmware.org, linux-kernel@vger.kernel.org, linux-arm-msm@vger.kernel.org, Harshal Dev X-Mailer: b4 0.14.3 X-Developer-Signature: v=1; a=ed25519-sha256; t=1784703569; l=10257; i=harshal.dev@oss.qualcomm.com; s=20251124; h=from:subject:message-id; bh=ltTUr4ZNz1WK8n1xoNtPuphhExPvrUNLbuEMZg8+YzA=; b=ZecvUzCUTBtloCfVPCAS/ldUdsIlbuSrcJ/nDKElROmdw8SbaiDBPwu9WIYAg+BLvCKma1y8d Bz159LXYGYpCDrQc28w96S/YciUdkMeLcrxQbzRBkY+tO/zwb+nYBOu X-Developer-Key: i=harshal.dev@oss.qualcomm.com; a=ed25519; pk=SHJ8K4SglF5t7KmfMKXl6Mby40WczSeLs4Qus7yFO7c= X-Proofpoint-ORIG-GUID: HdfLGbAVPvhZ8_8scYiAkswnxzrmdO8x X-Proofpoint-Spam-Info: AW1haW4tMjYwNzIyMDA2MyBTYWx0ZWRfXxoriBffPPc6c DuONdKaJ8AyGEg8sYUIGlDXOtMb+8022kx/IUWgqXth8OShxnT2k6NbO1Rcz2KVyDMtebqDIkFI oVFTQqQ+hO120nHaMy2O3GrkOvy9om4= X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwNzIyMDA2MyBTYWx0ZWRfXwsCbVtcJN2ud vUqgBxCf42whKxKkhSBhJSftfLCfpHI1NE2dJ5TJ1nT7Vhnw6Nolhv5n4tfgMiJJOpCqYcG0cpH bjKuJLTkL0dpVz0hzGJx2Rsmmw6nnfUOJi3y1MAFJ3SbW5x+zkHwnlrx4DWj/avEG8m6hM92Y7c VMndX4k4YigBB+1A01co9dWamdCmbWexco/COr0p3lRDCSQuRBut0btqfj+C/w8N84WarSJpVzN +qWf93g7IoqMrVfsBGU5eB9iFdvwll/SW812LWhbEBBuY7/d/hrhKkMMh87guVSFrv0buW61G0w 3g+dHCmFKXN7jvkO2+ggMMb9dg1ON8W2krnVBU7yeoVwnH4dSCiDNIPhitEVbvvHD5q8D5dGYCW dz5P+7QtjHyMl1npGLhbydzjvA4JMKzQplAmWXSEtdpDABF8oz6Jjtnx7GDrF+WiZCVXCCjzA8J tJsygRrxB6zqdU+OytQ== X-Proofpoint-GUID: HdfLGbAVPvhZ8_8scYiAkswnxzrmdO8x X-Authority-Analysis: v=2.4 cv=Cr6PtH4D c=1 sm=1 tr=0 ts=6a606a72 cx=c_pps a=cmESyDAEBpBGqyK7t0alAg==:117 a=fChuTYTh2wq5r3m49p7fHw==:17 a=IkcTkHD0fZMA:10 a=RAioF0-LDSMA:10 a=s4-Qcg_JpJYA:10 a=VkNPw1HP01LnGYTKEx00:22 a=u7WPNUs3qKkmUXheDGA7:22 a=yx91gb_oNiZeI1HMLzn7:22 a=EUspDBNiAAAA:8 a=nsqFTM80TsG4aMfu2G4A:9 a=QEXdDO2ut3YA:10 a=1OuFwYUASf3TG4hYMiVC:22 X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1143,Hydra:6.1.134,FMLib:17.12.100.49 definitions=2026-07-22_02,2026-07-21_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 priorityscore=1501 malwarescore=0 adultscore=0 impostorscore=0 lowpriorityscore=0 spamscore=0 phishscore=0 clxscore=1015 suspectscore=0 bulkscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2607220063 QTEE exposes certain secure services implemented either within the QTEE kernel or via pre-loaded Trusted Applications (TAs). Such always-available services can be readily accessed by TEE client drivers via QTEE's object-IPC protocol if the service is registered as a device on the TEE bus. One such service is the EFI-variables service, implemented by the uefisecapp TA which enables kernel clients to access EFI variables at runtime. Maintain a static list of such always-available secure services and add support for the QCOMTEE driver to register these services as devices on the TEE bus during probe. Signed-off-by: Harshal Dev --- drivers/tee/qcomtee/call.c | 160 +++++++++++++++++++++++++++++++= +++- drivers/tee/qcomtee/core.c | 9 +- drivers/tee/qcomtee/qcomtee.h | 12 +++ drivers/tee/qcomtee/qcomtee_msg.h | 1 + drivers/tee/qcomtee/qcomtee_object.h | 3 +- 5 files changed, 177 insertions(+), 8 deletions(-) diff --git a/drivers/tee/qcomtee/call.c b/drivers/tee/qcomtee/call.c index c1bba5fbfa3e..e909955e6b21 100644 --- a/drivers/tee/qcomtee/call.c +++ b/drivers/tee/qcomtee/call.c @@ -662,7 +662,7 @@ static void qcomtee_get_qtee_feature_list(struct tee_co= ntext *ctx, u32 id, { struct qcomtee_object *client_env, *service; struct qcomtee_arg u[3] =3D { 0 }; - int result; + int result, error =3D 0; =20 struct qcomtee_object_invoke_ctx *oic __free(kfree) =3D qcomtee_object_invoke_ctx_alloc(ctx, true); @@ -675,9 +675,13 @@ static void qcomtee_get_qtee_feature_list(struct tee_c= ontext *ctx, u32 id, =20 /* Get ''FeatureVersions Service'' object. */ service =3D qcomtee_object_get_service(oic, client_env, - QCOMTEE_FEATURE_VER_UID); - if (service =3D=3D NULL_QCOMTEE_OBJECT) + QCOMTEE_FEATURE_VER_UID, + &error); + if (service =3D=3D NULL_QCOMTEE_OBJECT) { + if (error) + pr_err("Failed to get service! error: %d\n", error); goto out_failed; + } =20 /* IB: Feature to query. */ u[0].b.addr =3D &id; @@ -697,6 +701,153 @@ static void qcomtee_get_qtee_feature_list(struct tee_= context *ctx, u32 id, qcomtee_object_put(client_env); } =20 +/** + * is_qcomtee_service_available() - Check if the QTEE service identified b= y the UID + * is available + * @ctx: TEE context. + * @uid: 32-bit UID of the service. + * + * Returns true if the service exists and is available. + * Returns false if a service is not exposed by QTEE. + */ +static bool is_qcomtee_service_available(struct tee_context *ctx, u32 uid) +{ + struct qcomtee_object *client_env; + struct qcomtee_object *service; + int error =3D 0; + bool ret =3D false; + + struct qcomtee_object_invoke_ctx *oic __free(kfree) =3D + qcomtee_object_invoke_ctx_alloc(ctx, true); + if (!oic) + return ret; + + client_env =3D qcomtee_object_get_client_env(oic); + if (client_env =3D=3D NULL_QCOMTEE_OBJECT) + return ret; + + /* Get service object corresponding to the uid. */ + service =3D qcomtee_object_get_service(oic, client_env, uid, &error); + if (service !=3D NULL_QCOMTEE_OBJECT) { + qcomtee_object_put(service); + ret =3D true; + } + + /* When we fail to get the service, QTEE provides the reason. */ + if (error) + pr_err("Failed to get service! error: %d\n", error); + + qcomtee_object_put(client_env); + return ret; +} + +/* + * QTEE Service UUID name space identifier + * + * A random UUID that is allocated as a name space identifier for forming = UUID's + * representing secure services exposed by QTEE. + */ +static const uuid_t qtee_service_uuid_ns =3D UUID_INIT(0xe1b48857, 0x6154,= 0x49f9, + 0x93, 0x4e, 0xa2, 0xf2, + 0x0a, 0xba, 0x98, 0x42); + +static const struct qtee_service qtee_services[] =3D { + { "qcom.tz.uefisecapp", + QCOMTEE_UEFI_SEC_UID } +}; + +static void qtee_release_service(struct device *dev) +{ + struct tee_client_device *qtee_service =3D to_tee_client_device(dev); + + kfree(qtee_service); +} + +/** + * qtee_enumerate_service() - Enumerate a given QTEE service and register + * it on the TEE bus as a TEE client device + * @ctx: TEE context. + * @service_uuid: UUID of the service to be registered on the TEE bus. + * @uid: 32-bit UID used by QTEE to identify the service. + * + * Returns 0 on success and < 0 on failure. + */ +static int qtee_enumerate_service(struct tee_context *ctx, const char *ser= vice_name, + const u32 uid) +{ + struct tee_client_device *qtee_service; + uuid_t service_uuid; + int rc; + + if (!is_qcomtee_service_available(ctx, uid)) + return -ENXIO; + + tee_generate_uuid_v5(&service_uuid, &qtee_service_uuid_ns, service_name, + strlen(service_name)); + + qtee_service =3D kzalloc_obj(*qtee_service); + if (!qtee_service) + return -ENOMEM; + + qtee_service->dev.bus =3D &tee_bus_type; + qtee_service->dev.release =3D qtee_release_service; + if (dev_set_name(&qtee_service->dev, "qtee-svc-%pUb", &service_uuid)) { + kfree(qtee_service); + return -ENOMEM; + } + uuid_copy(&qtee_service->id.uuid, &service_uuid); + + rc =3D device_register(&qtee_service->dev); + if (rc) { + pr_err("QTEE service registration failed, err: %d\n", rc); + put_device(&qtee_service->dev); + kfree(qtee_service); + return rc; + } + + return 0; +} + +/** + * qtee_enumerate_services() - Enumerate all the secure services exposed b= y QTEE + * from the static 'qtee_services' list and register them on the TEE bus as + * TEE client devices. + * + * Not all versions of QTEE support a given service. Hence, we try to + * enumerate as many services from the 'qtee_services' list as possible. + * Not being able to enumerate a service shouldn't cause the driver probe + * to fail since none of the services in the list are mandatory for + * establishing communication with QTEE. + * @ctx: TEE context. + */ +static void qtee_enumerate_services(struct tee_context *ctx) +{ + int rc; + u32 idx; + + for (idx =3D 0; idx < ARRAY_SIZE(qtee_services); idx++) { + rc =3D qtee_enumerate_service(ctx, qtee_services[idx].name, + qtee_services[idx].uid); + if (rc =3D=3D -ENXIO) + pr_err("QTEE does not implement service %d.\n", + qtee_services[idx].uid); + } +} + +static int qtee_unregister_service(struct device *dev, void *data) +{ + if (!strncmp(dev_name(dev), "qtee-svc", strlen("qtee-svc"))) + device_unregister(dev); + + return 0; +} + +static void qtee_unregister_services(void) +{ + bus_for_each_dev(&tee_bus_type, NULL, NULL, + qtee_unregister_service); +} + static const struct tee_driver_ops qcomtee_ops =3D { .get_version =3D qcomtee_get_version, .open =3D qcomtee_open, @@ -778,6 +929,8 @@ static int qcomtee_probe(struct platform_device *pdev) QTEE_VERSION_GET_MINOR(qcomtee->qtee_version), QTEE_VERSION_GET_PATCH(qcomtee->qtee_version)); =20 + qtee_enumerate_services(qcomtee->ctx); + return 0; =20 err_dest_wq: @@ -807,6 +960,7 @@ static void qcomtee_remove(struct platform_device *pdev) { struct qcomtee *qcomtee =3D platform_get_drvdata(pdev); =20 + qtee_unregister_services(); teedev_close_context(qcomtee->ctx); /* Wait for RELEASE operations to be processed for QTEE objects. */ tee_device_unregister(qcomtee->teedev); diff --git a/drivers/tee/qcomtee/core.c b/drivers/tee/qcomtee/core.c index b1cb50e434f0..4e39e867c3e9 100644 --- a/drivers/tee/qcomtee/core.c +++ b/drivers/tee/qcomtee/core.c @@ -896,19 +896,20 @@ qcomtee_object_get_client_env(struct qcomtee_object_i= nvoke_ctx *oic) =20 struct qcomtee_object * qcomtee_object_get_service(struct qcomtee_object_invoke_ctx *oic, - struct qcomtee_object *client_env, u32 uid) + struct qcomtee_object *client_env, u32 uid, + int *result) { struct qcomtee_arg u[3] =3D { 0 }; - int ret, result; + int ret; =20 u[0].b.addr =3D &uid; u[0].b.size =3D sizeof(uid); u[0].type =3D QCOMTEE_ARG_TYPE_IB; u[1].type =3D QCOMTEE_ARG_TYPE_OO; ret =3D qcomtee_object_do_invoke(oic, client_env, QCOMTEE_CLIENT_ENV_OPEN, - u, &result); + u, result); =20 - if (ret || result) + if (ret || *result) return NULL_QCOMTEE_OBJECT; =20 return u[1].o; diff --git a/drivers/tee/qcomtee/qcomtee.h b/drivers/tee/qcomtee/qcomtee.h index f39bf63fd1c2..66d305a46c0a 100644 --- a/drivers/tee/qcomtee/qcomtee.h +++ b/drivers/tee/qcomtee/qcomtee.h @@ -17,6 +17,8 @@ #define QCOMTEE_OBJREF_FLAG_USER BIT(1) #define QCOMTEE_OBJREF_FLAG_MEM BIT(2) =20 +#define QTEE_UUID_NS_NAME_SIZE 128 + /** * struct qcomtee - Main service struct. * @teedev: client device. @@ -39,6 +41,16 @@ struct qcomtee { u32 qtee_version; }; =20 +/** + * struct qtee_service - A secure service exposed by QTEE identified by a = 32-bit UID. + * @name: Name of the QTEE service. + * @uid: 32-bit UID used by QTEE to identify the service. + */ +struct qtee_service { + const char *name; + const u32 uid; +}; + void qcomtee_fetch_async_reqs(struct qcomtee_object_invoke_ctx *oic); struct qcomtee_object *qcomtee_idx_erase(struct qcomtee_object_invoke_ctx = *oic, u32 idx); diff --git a/drivers/tee/qcomtee/qcomtee_msg.h b/drivers/tee/qcomtee/qcomte= e_msg.h index 878f70178a5b..ecaf8db67d45 100644 --- a/drivers/tee/qcomtee/qcomtee_msg.h +++ b/drivers/tee/qcomtee/qcomtee_msg.h @@ -105,6 +105,7 @@ union qcomtee_msg_arg { #define QTEE_VERSION_GET_MINOR(x) (((x) >> 12) & 0xffU) #define QTEE_VERSION_GET_PATCH(x) ((x) >> 0 & 0xfffU) =20 +#define QCOMTEE_UEFI_SEC_UID 413 /* Response types as returned from qcomtee_object_invoke_ctx_invoke(). */ =20 /* The message contains a callback request. */ diff --git a/drivers/tee/qcomtee/qcomtee_object.h b/drivers/tee/qcomtee/qco= mtee_object.h index 7bd6e23b038c..f4cb9b8fcbd4 100644 --- a/drivers/tee/qcomtee/qcomtee_object.h +++ b/drivers/tee/qcomtee/qcomtee_object.h @@ -316,6 +316,7 @@ qcomtee_object_get_client_env(struct qcomtee_object_inv= oke_ctx *oic); =20 struct qcomtee_object * qcomtee_object_get_service(struct qcomtee_object_invoke_ctx *oic, - struct qcomtee_object *client_env, u32 uid); + struct qcomtee_object *client_env, u32 uid, + int *result); =20 #endif /* QCOMTEE_OBJECT_H */ --=20 2.34.1 From nobody Fri Jul 24 23:31:27 2026 Received: from mx0a-0031df01.pphosted.com (mx0a-0031df01.pphosted.com [205.220.168.131]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 9EEC93AEF49 for ; Wed, 22 Jul 2026 07:00:08 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=205.220.168.131 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784703619; cv=none; b=Xvf8XfPJOWQX8TuLFtHQ90R4lVo6Nnqw1ULU/IoOMFDeoJYAvqvq5m5CddSyCndaicalhS6Hbw84xG/4LN6rCtQRtCg/Ruah0f5aqxknANWA6VebAD4JzfqhJFpj9l2KJyPFi8rscYG8aQ8G1FIgVFk834tn3Hfttrz5e7tq7Ck= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784703619; c=relaxed/simple; bh=LosjvZDIaSYjB3Gq/q9l/AWJ3RurWA5UZWsVfICp0jM=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=tIp/0aUStYXKo4xV4Bf8iV5Gh1N7KsCpJeU+Qf+iQSvqajRSJS5fSRc/IlLmSbHpDOXoyzXDNIHAGY2dg8+LNdnZYgsjIBEdRSBYthTB5OkuvP5SsycP6AyqU6XsTmRw1oXRsNxZPi4QGl0coRXLzZBC1mbAT21/N90RPncmDMQ= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=oss.qualcomm.com; spf=pass smtp.mailfrom=oss.qualcomm.com; dkim=pass (2048-bit key) header.d=qualcomm.com header.i=@qualcomm.com header.b=F7dEPz1m; dkim=pass (2048-bit key) header.d=oss.qualcomm.com header.i=@oss.qualcomm.com header.b=GFmtVcje; arc=none smtp.client-ip=205.220.168.131 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=oss.qualcomm.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=oss.qualcomm.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=qualcomm.com header.i=@qualcomm.com header.b="F7dEPz1m"; dkim=pass (2048-bit key) header.d=oss.qualcomm.com header.i=@oss.qualcomm.com header.b="GFmtVcje" Received: from pps.filterd (m0279867.ppops.net [127.0.0.1]) by mx0a-0031df01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 66M61ua5984493 for ; Wed, 22 Jul 2026 07:00:08 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=qualcomm.com; h= cc:content-transfer-encoding:content-type:date:from:in-reply-to :message-id:mime-version:references:subject:to; s=qcppdkim1; bh= 9PuxTn6tqXxb1UzBUrLi98bIB+U0tB5y7IeqUgq/+Zo=; b=F7dEPz1m5gjDttwk pJbhI7KpMPUUrvIHLIyrKr3fGKVUvkJHJC/Vcw7ZILPm85sk6OmU/6MZ1PYkyn7G jX9NaW2P7KxqlfWnsFE3sYmjJWkbOyncPuSbQUY744zokQg7/jrr+bCdg5A1WvfC SrqMphAcEthUsD+gdknhVUNnr5cMk5OEKAESxcgJemY1lz2dA9sQfMpOUXMlWePn zGXd7HZnw6pHvM0jh+OQdH7twcEek1a2SnThgnNsmrr6Kq9dchF6KTuvMJRGXKMa s6vXAvacWatqROEwGEDXEIhk3WjRHCmAWimY0fTl2UM12iAr6b0I5IG8gtx6XkcJ R25Wqg== Received: from mail-pl1-f197.google.com (mail-pl1-f197.google.com [209.85.214.197]) by mx0a-0031df01.pphosted.com (PPS) with ESMTPS id 4fjr83875c-1 (version=TLSv1.3 cipher=TLS_AES_128_GCM_SHA256 bits=128 verify=NOT) for ; Wed, 22 Jul 2026 07:00:07 +0000 (GMT) Received: by mail-pl1-f197.google.com with SMTP id d9443c01a7336-2cacf17c7e0so124878625ad.0 for ; Wed, 22 Jul 2026 00:00:07 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=oss.qualcomm.com; s=google; t=1784703607; x=1785308407; darn=vger.kernel.org; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=9PuxTn6tqXxb1UzBUrLi98bIB+U0tB5y7IeqUgq/+Zo=; b=GFmtVcjet+jMHv6BsitaccEbeH87Uz9dq685ehTvWQhyaVUkLBS302s6PMDuvIXZlv dV83P/5jlAExChh6pFKsRXliFInGA7PI/6LCIFBtOFgG+kr9mC/MRDw0/vQpvrXL9Skh eTeq3RkBBIteG+aU8wpaxPtuk6pSDYcwc+vb2pLev0zM20QWFj09Mp+CPfX0Ocu3r36E XBGK5gcqa6RF2K+uV1Su3EDnA41ZrT/u33phrjAKr26QKKcjyQlFxBEnPln9bqL0SUjs jCz/F6uBJ6Y+Ol8mhaWQMGmY2rLLUNbh9Dm124wWnN72ine/eXA8bCr5vRMEAPQ1ytch VDMQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784703607; x=1785308407; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=9PuxTn6tqXxb1UzBUrLi98bIB+U0tB5y7IeqUgq/+Zo=; b=DXbjG9WisBt52gJ5YLZV/GiQ0gMv+lP5DPbWn4iFv2CiKjV9+9RbnFc0E8p0ZVGms5 LoN8FwZcg1ojXXrcsqR8QifYjXeUvp1GwAidkr9SahLX3Gr2cUSP7j2zq0WsbKsNbq06 +s6avcbVAP2AyoDRp4Dxjz+w8Vbs6eA2cT1PqYj5WuxBO1qb/v8z6STthYegfhZoSeMN PwTrHvY5PqbfIOzZmuIL10FzxjmRzbdVm9dboJ4fu9sNyJGkxB9XcjQMnbjd28i6rBQP nbhtyB1STUJCwd2hW0DCXFFO0DTcfieDXk6I+oXq4lVA30xyLBcLMepUaMiQpFF8eOU/ ra5Q== X-Forwarded-Encrypted: i=1; AHgh+RqY5vAep5Rd7VPrBfNO6YlE9dCuqM1XAiIjwfmKWyMIHH4VL8JWu6Y45cktNjh8CiYLlJqzKidz7EcpNFw=@vger.kernel.org X-Gm-Message-State: AOJu0YxNSB2O6Agm8LFrGqNBwLYOWJTZrQ/FFbbIJcSs1aS+u1tQUX0p zdYQ0/8PatJZm2HgNaA9FvjeB25tkRDblRFykqR9/pMtbRpgom2Mp1HpTaUS/el5USrq4wSMWP7 9V3j+KWA1hBk+mAZbXTItCe1NUMBHzE/bVNuj5JkdVIwRgXrBOOl/+A4+rYtiNvWqWtc= X-Gm-Gg: AR+sD12oHoUiS95iXT7bhAA6wuwOMEh2nNPksm3+J9HsWO5RHmxIx9Oce9fMP0FOQyS d3wuWAn3SVJB/4aVnXnbEswAsoXZg5HWAWCC3spOqwUVU/BcHYUF2AtTlrOk4r+v53IRT77xZna /646OqVdquexKuXQHY5k+nn/eVqR0YDtVyemypiYGUfNnRivzv2SNzYI2xw3hW/MfoMxRo4KUTz QCqKQQzz7MbvxmrGceAnSkXUMrgmEd0N4QLFpQ+a3dF0N4YRR3rnuvenuuFcswHXExbn+NXi+9d ljWZiKSmyqwvbndGEOobnljX9D31YOvUibK8IHxloI8Fa9JX0TdSu/djYE2hh/J4hyXhy3iDQdS q7bcKjcTgXZ+jXFqNCJ1Aa/W40A== X-Received: by 2002:a17:902:d2ce:b0:2c9:e2c1:4fb5 with SMTP id d9443c01a7336-2cf34997962mr232058495ad.22.1784703606360; Wed, 22 Jul 2026 00:00:06 -0700 (PDT) X-Received: by 2002:a17:902:d2ce:b0:2c9:e2c1:4fb5 with SMTP id d9443c01a7336-2cf34997962mr232057865ad.22.1784703605648; Wed, 22 Jul 2026 00:00:05 -0700 (PDT) Received: from hu-hdev-hyd.qualcomm.com ([202.46.22.19]) by smtp.gmail.com with ESMTPSA id d9443c01a7336-2cf8efd88f7sm9428935ad.22.2026.07.22.00.00.00 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 22 Jul 2026 00:00:04 -0700 (PDT) From: Harshal Dev Date: Wed, 22 Jul 2026 12:29:17 +0530 Subject: [PATCH v2 6/6] firmware: qcom: Add support for TEE based EFI-var client driver Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260722-qcom_uefisecapp_migrate_qcomtee-v2-6-b8a8fcbe4211@oss.qualcomm.com> References: <20260722-qcom_uefisecapp_migrate_qcomtee-v2-0-b8a8fcbe4211@oss.qualcomm.com> In-Reply-To: <20260722-qcom_uefisecapp_migrate_qcomtee-v2-0-b8a8fcbe4211@oss.qualcomm.com> To: Jens Wiklander , Jens Wiklander , Sumit Garg , Amirreza Zarrabi , Bjorn Andersson , Konrad Dybcio Cc: Basant Kumar , Apurupa Pattapu , Arun Kumar Neelakantam , op-tee@lists.trustedfirmware.org, linux-kernel@vger.kernel.org, linux-arm-msm@vger.kernel.org, Harshal Dev X-Mailer: b4 0.14.3 X-Developer-Signature: v=1; a=ed25519-sha256; t=1784703569; l=26036; i=harshal.dev@oss.qualcomm.com; s=20251124; h=from:subject:message-id; bh=LosjvZDIaSYjB3Gq/q9l/AWJ3RurWA5UZWsVfICp0jM=; b=GL8Pd5NDBHbqi734JZA1eYHtk7R6u5+4cDNw052g8mCFumrKvTjv4P5BRtatR9Q3bq2pfmgrY /kVUyTjbnv7Ad7dvuoyuGMboF5fFMByZtbiiQmo45Qz8CIvDL/Mu5Y1 X-Developer-Key: i=harshal.dev@oss.qualcomm.com; a=ed25519; pk=SHJ8K4SglF5t7KmfMKXl6Mby40WczSeLs4Qus7yFO7c= X-Proofpoint-ORIG-GUID: I7Qro4iU2ND_P5XUtVm1I1D4j7DBIuxc X-Authority-Analysis: v=2.4 cv=VfrH+lp9 c=1 sm=1 tr=0 ts=6a606a77 cx=c_pps a=cmESyDAEBpBGqyK7t0alAg==:117 a=fChuTYTh2wq5r3m49p7fHw==:17 a=IkcTkHD0fZMA:10 a=RAioF0-LDSMA:10 a=s4-Qcg_JpJYA:10 a=VkNPw1HP01LnGYTKEx00:22 a=u7WPNUs3qKkmUXheDGA7:22 a=eoimf2acIAo5FJnRuUoq:22 a=EUspDBNiAAAA:8 a=VwQbUJbxAAAA:8 a=NEAV23lmAAAA:8 a=lX1A334Kam2MR8cuwK8A:9 a=ZP9I4r549iL3ZUHD:21 a=QEXdDO2ut3YA:10 a=1OuFwYUASf3TG4hYMiVC:22 X-Proofpoint-GUID: I7Qro4iU2ND_P5XUtVm1I1D4j7DBIuxc X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwNzIyMDA2MyBTYWx0ZWRfX2xq6OR17EIwg RvhJ/fV1/IIcb2bmvMLrFPKxE9nCUSPv4xhKRb0m1YK7SdlyK4m8ZxN5fqV9B4KzOMcCRMOJijH lhm/xdNlpmU0uyI3eP2/L0p7mCbCKgdiG/lmt6pbyBtvWRoBkCa+CvgdQzUeYHbkM4VpqDjNW3X 1KxckaW1g6yMQtB28fSe1kdCjW6f6//muxuaUJ1fhnPyP2hboILhwynaAzlPqn1g8Scsuj9jcKQ E7t4HqshlV+1Ep0YmO2qD2UtO+KYqzebCOK790ac5A5GbkY/AgVgqs6O8Zd+RztU3tIRhLTnMi4 vN8CmmfexRWIE5EFBjHvZ6huWJZEAh7XQ6b3J6uYSP/hebMGBLryRTsqyWmkfUROGPwt1bGeSAg QgFgGPFb0VhvJ/LXcC1YrXKyfNWiLndFHfS39iO84hEP/lfYQ6580m/lOfpD61j5qaCZul6tL6c Jh8xgX8oW3e1qF+CItQ== X-Proofpoint-Spam-Info: AW1haW4tMjYwNzIyMDA2MyBTYWx0ZWRfXwZYSl3zwrL8C KORuEKNpL14/YrMFnJbyTgaGiCaHtAn4GIXNWEhbj5V3a8nXJq0mZvQ1u3PlSzUpApmuHl+WGec PAPp+W8hfX9IkGlulMmu4CON/c1PQTo= X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1143,Hydra:6.1.134,FMLib:17.12.100.49 definitions=2026-07-22_02,2026-07-21_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 phishscore=0 suspectscore=0 malwarescore=0 lowpriorityscore=0 clxscore=1015 priorityscore=1501 spamscore=0 bulkscore=0 impostorscore=0 adultscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2607220063 On Qualcomm SoC based platforms, UEFI stores EFI variables within the Replay Protected Memory Block (RPMB) which is only accessible by the Qualcomm Trusted Execution Environment (QTEE). For Qualcomm platforms without emulated RPMB support, specifically platforms where RPMB is not located within SPI-NOR storage and instead located on UFS/EMMC storage, non-volatile EFI variables can only be set via a callback request from the UEFI Trusted Application (TA) to the RPMB service running in user-space (within the QTEE supplicant). Unlike the QCOMTEE driver, the QSEECOM driver (used by the current uefisecapp client driver) does not support callback requests. And on certain Qualcomm platforms such as the RB3Gen2, attempts to access the QSEECOM interface fail due to lack of support within QTEE. On all such platforms, a TEE based uefisecapp client driver must be used to access cached/volatile EFI variables within the uefisecapp TA and ensure persistence of writes to non-volatile EFI variables through the RPMB service hosted in the QTEE supplicant. Add support for a TEE based uefisecapp client driver which installs efivar operations after obtaining an object reference to the uefisecapp service. This enables the kernel/user-space to access/modify both volatile EFI vars stored by the Secure Application (in-memory) and non-volatile ones stored within RPMB. Signed-off-by: Harshal Dev --- MAINTAINERS | 7 + drivers/firmware/qcom/Kconfig | 24 ++ drivers/firmware/qcom/Makefile | 1 + drivers/firmware/qcom/qcom_tee_uefisecapp.c | 525 ++++++++++++++++++++++++= ++++ drivers/firmware/qcom/qcom_tee_uefisecapp.h | 120 +++++++ 5 files changed, 677 insertions(+) diff --git a/MAINTAINERS b/MAINTAINERS index 10d12b51b1f6..e8316007370f 100644 --- a/MAINTAINERS +++ b/MAINTAINERS @@ -22018,6 +22018,13 @@ L: linux-arm-msm@vger.kernel.org S: Maintained F: drivers/firmware/qcom/qcom_qseecom_uefisecapp.c =20 +QUALCOMM TEE UEFISECAPP DRIVER +M: Harshal Dev +L: linux-arm-msm@vger.kernel.org +S: Maintained +F: drivers/firmware/qcom/qcom_tee_uefisecapp.c +F: drivers/firmware/qcom/qcom_tee_uefisecapp.h + QUALCOMM RMNET DRIVER M: Subash Abhinov Kasiviswanathan M: Sean Tranchetti diff --git a/drivers/firmware/qcom/Kconfig b/drivers/firmware/qcom/Kconfig index b477d54b495a..20ce8b58e490 100644 --- a/drivers/firmware/qcom/Kconfig +++ b/drivers/firmware/qcom/Kconfig @@ -74,4 +74,28 @@ config QCOM_QSEECOM_UEFISECAPP Select Y here to provide access to EFI variables on the aforementioned platforms. =20 +config QCOM_TEE_UEFISECAPP + tristate "Qualcomm TEE UEFI Secure App client driver" + depends on QCOMTEE + depends on EFI + depends on !QCOM_QSEECOM_UEFISECAPP + help + On Qualcomm SoC based platforms without emulated RPMB support, + specifically platforms where RPMB is not present within SPI-NOR storage + and instead located on UFS/EMMC storage, non-volatile EFI variables can + only be set via a callback request from the UEFI Secure Application to + the RPMB service running in user-space (within the QTEE supplicant: + github.com/qualcomm/minkipc). Unlike the QCOMTEE driver, the QSEECOM + driver used by the QSEECOM based uefisecapp does not support callback + requests. And so on these platforms, the TEE based uefisecapp client + driver must be used to ensure persistence of non-volatile EFI variables + via writes through the RPMB service hosted in the QTEE supplicant. + + This module provides a TEE client driver for uefisecapp, installing efi= var + operations to allow the kernel and user-space access to EFI variables. + + Select m here to provide access to EFI variables on the aforementioned + platforms if your Linux distribution has QTEE supplicant installed and + running. + endmenu diff --git a/drivers/firmware/qcom/Makefile b/drivers/firmware/qcom/Makefile index 0be40a1abc13..d780490b2865 100644 --- a/drivers/firmware/qcom/Makefile +++ b/drivers/firmware/qcom/Makefile @@ -8,3 +8,4 @@ qcom-scm-objs +=3D qcom_scm.o qcom_scm-smc.o qcom_scm-legac= y.o obj-$(CONFIG_QCOM_TZMEM) +=3D qcom_tzmem.o obj-$(CONFIG_QCOM_QSEECOM) +=3D qcom_qseecom.o obj-$(CONFIG_QCOM_QSEECOM_UEFISECAPP) +=3D qcom_qseecom_uefisecapp.o +obj-$(CONFIG_QCOM_TEE_UEFISECAPP) +=3D qcom_tee_uefisecapp.o diff --git a/drivers/firmware/qcom/qcom_tee_uefisecapp.c b/drivers/firmware= /qcom/qcom_tee_uefisecapp.c new file mode 100644 index 000000000000..9a5a6f145a9f --- /dev/null +++ b/drivers/firmware/qcom/qcom_tee_uefisecapp.c @@ -0,0 +1,525 @@ +// SPDX-License-Identifier: GPL-2.0-only +/* + * Copyright (c) Qualcomm Technologies, Inc. and/or its subsidiaries. + */ + +#include +#include +#include +#include +#include "qcom_tee_uefisecapp.h" + +static struct qcomtee_uefisec_app uefisec_app; + +static int qcuefi_get_variable(struct tee_param_ubuf in_variable, efi_guid= _t *guid, + struct tee_param_ubuf in_attributes, + struct tee_param_ubuf *data, + u32 *out_attributes, u32 *out_errno) +{ + int ret; + struct tee_ioctl_object_invoke_arg inv_arg; + u64 obj_id =3D uefisec_app.uefisec_svc_obj.id; + u32 nparams =3D 5; + struct tee_param param[nparams]; + + struct { + efi_guid_t guid; + u32 in_data_size; + } in_cong =3D { 0 }; + + struct { + u32 out_data_size; + u32 attributes; + u32 errno; + } out_cong =3D { 0 }; + + in_cong.guid =3D *guid; + in_cong.in_data_size =3D data->size; + + memset(&inv_arg, 0, sizeof(inv_arg)); + memset(¶m, 0, sizeof(param)); + + SET_INVOKE_ARG(inv_arg, obj_id, QCOMTEE_UEFI_SEC_OP_GET_VAR, nparams); + SET_TEE_PARAM_UBUF(param[0], UBUF_INPUT, TEE_PARAM_UBUF(in_cong)); + SET_TEE_PARAM_UBUF(param[1], UBUF_INPUT, in_variable); + SET_TEE_PARAM_UBUF(param[2], UBUF_INPUT, in_attributes); + SET_TEE_PARAM_UBUF(param[3], UBUF_OUTPUT, TEE_PARAM_UBUF(out_cong)); + SET_TEE_PARAM_UBUF(param[4], UBUF_OUTPUT, *data); + + ret =3D tee_client_object_invoke_func(uefisec_app.ctx, &inv_arg, param); + if (ret < 0 || inv_arg.ret !=3D 0) { + dev_err(uefisec_app.dev, "QCOMTEE_UEFI_SEC_OP_GET_VAR invoke ret: %d, er= r: 0x%x\n", + ret, inv_arg.ret); + return ret ?: inv_arg.ret; + } + + data->size =3D out_cong.out_data_size; + *out_attributes =3D out_cong.attributes; + *out_errno =3D out_cong.errno; + + return ret; +} + +static efi_status_t qcomtee_uefi_get_variable(efi_char16_t *name, efi_guid= _t *guid, + u32 *attr, unsigned long *data_size, + void *data) +{ + int ret; + u32 in_attr, out_attributes, out_errno; + struct tee_param_ubuf in_data, in_var, in_attributes; + + if (!name || !guid) + return EFI_INVALID_PARAMETER; + + /* 'attr' can be NULL, however an input attribute is always expected + * by UefiSecApp TA + */ + in_attr =3D 0; + if (attr) + in_attr =3D *attr; + + in_data =3D (struct tee_param_ubuf){ .addr =3D data, *data_size }; + in_var =3D (struct tee_param_ubuf){ .addr =3D name, + (ucs2_strlen(name) + 1) * sizeof(*name) }; + in_attributes =3D (struct tee_param_ubuf){ .addr =3D &in_attr, sizeof(u32= ) }; + + /* On SUCCESS, 'data' member of 'in_data' has already been updated. */ + ret =3D qcuefi_get_variable(in_var, guid, in_attributes, &in_data, + &out_attributes, &out_errno); + + if (ret) + return EFI_DEVICE_ERROR; + + if (!out_errno || out_errno =3D=3D QCOMTEE_UEFI_SEC_ERROR_SIZE_OUT) { + /* If 'attr' is NULL 'out_attributes' is not updated. */ + if (attr) + *attr =3D out_attributes; + + *data_size =3D in_data.size; + } + + return uefisecapp_err_to_efi_status(out_errno); +} + +static int qcuefi_set_variable(struct tee_param_ubuf in_variable, efi_guid= _t *guid, + u32 attributes, struct tee_param_ubuf data, + u32 *out_errno) +{ + int ret; + struct tee_ioctl_object_invoke_arg inv_arg; + u64 obj_id =3D uefisec_app.uefisec_svc_obj.id; + u32 nparams =3D 4; + struct tee_param param[nparams]; + + struct { + efi_guid_t guid; + u32 attributes; + u32 in_data_size; + } in_cong =3D { 0 }; + + in_cong.guid =3D *guid; + in_cong.attributes =3D attributes; + in_cong.in_data_size =3D data.size; + + memset(&inv_arg, 0, sizeof(inv_arg)); + memset(¶m, 0, sizeof(param)); + + SET_INVOKE_ARG(inv_arg, obj_id, QCOMTEE_UEFI_SEC_OP_SET_VAR, nparams); + SET_TEE_PARAM_UBUF(param[0], UBUF_INPUT, TEE_PARAM_UBUF(in_cong)); + SET_TEE_PARAM_UBUF(param[1], UBUF_INPUT, in_variable); + SET_TEE_PARAM_UBUF(param[2], UBUF_INPUT, data); + SET_TEE_PARAM_UBUF(param[3], UBUF_OUTPUT, TEE_PARAM_UBUF(*out_errno)); + + ret =3D tee_client_object_invoke_func(uefisec_app.ctx, &inv_arg, param); + if (ret < 0 || inv_arg.ret !=3D 0) { + dev_err(uefisec_app.dev, "QCOMTEE_UEFI_SEC_OP_SET_VAR invoke ret: %d, er= r: 0x%x\n", + ret, inv_arg.ret); + return ret ?: inv_arg.ret; + } + + return ret; +} + +static efi_status_t qcomtee_uefi_set_variable(efi_char16_t *name, efi_guid= _t *guid, + u32 attr, unsigned long data_size, + void *data) +{ + int ret; + u32 out_errno; + struct tee_param_ubuf in_data, in_var; + + if (!name || !guid) + return EFI_INVALID_PARAMETER; + + in_data =3D (struct tee_param_ubuf){ .addr =3D data, data_size }; + in_var =3D (struct tee_param_ubuf){ .addr =3D name, + (ucs2_strlen(name) + 1) * sizeof(*name) }; + + ret =3D qcuefi_set_variable(in_var, guid, attr, in_data, &out_errno); + if (ret) + return EFI_DEVICE_ERROR; + + return uefisecapp_err_to_efi_status(out_errno); +} + +static int qcuefi_get_next_variable(struct tee_param_ubuf in_variable, efi= _guid_t *guid, + struct tee_param_ubuf *out_variable, + efi_guid_t *out_vendor_guid, u32 *out_errno) +{ + int ret; + struct tee_ioctl_object_invoke_arg inv_arg; + u64 obj_id =3D uefisec_app.uefisec_svc_obj.id; + u32 nparams =3D 4; + struct tee_param param[nparams]; + + struct { + efi_guid_t guid; + u32 in_data_size; + } in_cong =3D { 0 }; + + struct { + efi_guid_t guid; + u32 out_data_size; + u32 errno; + } out_cong =3D { 0 }; + + /* Pass size of available buffer */ + in_cong.in_data_size =3D out_variable->size; + in_cong.guid =3D *guid; + + memset(&inv_arg, 0, sizeof(inv_arg)); + memset(¶m, 0, sizeof(param)); + + SET_INVOKE_ARG(inv_arg, obj_id, QCOMTEE_UEFI_SEC_OP_GET_NEXT_VAR_NAME, np= arams); + SET_TEE_PARAM_UBUF(param[0], UBUF_INPUT, TEE_PARAM_UBUF(in_cong)); + SET_TEE_PARAM_UBUF(param[1], UBUF_INPUT, in_variable); + SET_TEE_PARAM_UBUF(param[2], UBUF_OUTPUT, TEE_PARAM_UBUF(out_cong)); + SET_TEE_PARAM_UBUF(param[3], UBUF_OUTPUT, *out_variable); + + ret =3D tee_client_object_invoke_func(uefisec_app.ctx, &inv_arg, param); + if (ret < 0 || inv_arg.ret !=3D 0) { + dev_err(uefisec_app.dev, "QCOMTEE_UEFI_SEC_OP_GET_NEXT_VAR_NAME invoke r= et: %d, err: 0x%x\n", + ret, inv_arg.ret); + return ret ?: inv_arg.ret; + } + + /* UefiSecApp TA does not touch 'out_variable.size'. Update it here. + * On SUCCESS (!out_errno), 'out_data_size' is length of name in 'out_var= iable.addr'. + * On failure (out_errno =3D=3D QCOMTEE_UEFI_SEC_ERROR_SIZE_OUT), 'out_da= ta_size' is + * actual name length. + * Otherwise, it's undefined. + */ + out_variable->size =3D out_cong.out_data_size; + *out_vendor_guid =3D out_cong.guid; + *out_errno =3D out_cong.errno; + + return ret; +} + +static efi_status_t qcomtee_uefi_get_next_variable(unsigned long *name_siz= e, + efi_char16_t *name, + efi_guid_t *guid) +{ + int ret; + u32 out_errno; + efi_guid_t out_guid; + struct tee_param_ubuf in_var, out_var; + + if (!name_size || !name || !guid) + return EFI_INVALID_PARAMETER; + + if (*name_size =3D=3D 0) + return EFI_INVALID_PARAMETER; + + /* For 'in_var', 'name_size' is not necessarily size of 'name'; + * could be size of buffer where 'name' has been stored. TA expects a + * NULL-terminated string in 'name' and ignores the size. + * For 'out_var', 'name_size' is size of buffer pointed by 'name'. + */ + in_var =3D (struct tee_param_ubuf){ .addr =3D name, *name_size }; + out_var =3D (struct tee_param_ubuf){ .addr =3D name, *name_size }; + + ret =3D qcuefi_get_next_variable(in_var, guid, &out_var, &out_guid, + &out_errno); + if (ret) + return EFI_DEVICE_ERROR; + + if (!out_errno) + *guid =3D out_guid; + + if (!out_errno || out_errno =3D=3D QCOMTEE_UEFI_SEC_ERROR_SIZE_OUT) + *name_size =3D out_var.size; + + /* On SUCCESS, 'name' stores the next variable name. */ + return uefisecapp_err_to_efi_status(out_errno); +} + +static int qcuefi_query_variable_info(u32 attributes, + u64 *maximum_variable_storage_size, + u64 *remaining_variable_storage_size, + u64 *maximum_variable_size, u32 *out_errno) +{ + int ret; + struct tee_ioctl_object_invoke_arg inv_arg; + u64 obj_id =3D uefisec_app.uefisec_svc_obj.id; + u32 nparams =3D 2; + struct tee_param param[nparams]; + + struct { + u64 max_var_storage_size; + u64 remaining_var_storage_size; + u64 maximum_var_size; + u32 errno; + } out_cong =3D { 0 }; + + memset(&inv_arg, 0, sizeof(inv_arg)); + memset(¶m, 0, sizeof(param)); + + SET_INVOKE_ARG(inv_arg, obj_id, QCOMTEE_UEFI_SEC_OP_QUERY_VAR_INFO, npara= ms); + SET_TEE_PARAM_UBUF(param[0], UBUF_INPUT, TEE_PARAM_UBUF(attributes)); + SET_TEE_PARAM_UBUF(param[1], UBUF_OUTPUT, TEE_PARAM_UBUF(out_cong)); + + ret =3D tee_client_object_invoke_func(uefisec_app.ctx, &inv_arg, param); + if (ret < 0 || inv_arg.ret !=3D 0) { + dev_err(uefisec_app.dev, "QCOMTEE_UEFI_SEC_OP_QUERY_VAR_INFO invoke ret:= %d, err: 0x%x\n", + ret, inv_arg.ret); + return ret ?: inv_arg.ret; + } + + *maximum_variable_storage_size =3D out_cong.max_var_storage_size; + *remaining_variable_storage_size =3D out_cong.remaining_var_storage_size; + *maximum_variable_size =3D out_cong.maximum_var_size; + *out_errno =3D out_cong.errno; + + return ret; +} + +static efi_status_t qcomtee_uefi_query_variable_info(u32 attr, u64 *storag= e_space, + u64 *remaining_space, + u64 *max_variable_size) +{ + int ret; + u32 out_errno; + u64 maximum_variable_storage_size; + u64 remaining_variable_storage_size; + u64 maximum_variable_size; + + if (!storage_space || !remaining_space || !max_variable_size) + return EFI_INVALID_PARAMETER; + + ret =3D qcuefi_query_variable_info(attr, + &maximum_variable_storage_size, + &remaining_variable_storage_size, + &maximum_variable_size, + &out_errno); + + if (ret) + return EFI_DEVICE_ERROR; + + if (!out_errno) { + *storage_space =3D maximum_variable_storage_size; + *remaining_space =3D remaining_variable_storage_size; + *max_variable_size =3D maximum_variable_size; + } + + return uefisecapp_err_to_efi_status(out_errno); +} + +/** + * qcomtee_release_object() - Release an object returned by QTEE. + * + * Each object returned by QTEE repesents a secure service exposed to the + * client. Whenever an secure service is opened, QTEE may allocate resourc= es + * on the client's behalf. Therefore, once the client is done accessing the + * secure service, the object representing it should be explicitly released + * so that QTEE can release the associated resources as well. + * + * @ctx: TEE context. + * @object: The object to release. + */ +static void qcomtee_release_object(struct tee_context *ctx, + struct tee_param_objref object) +{ + struct tee_ioctl_object_invoke_arg inv_arg; + + memset(&inv_arg, 0, sizeof(inv_arg)); + SET_INVOKE_ARG(inv_arg, object.id, QCOMTEE_MSG_OBJECT_OP_RELEASE, 0); + tee_client_object_invoke_func(ctx, &inv_arg, NULL); +} + +/** + * qcomtee_get_uefisec_svc_obj() - Get a UEFI Secure App service object to + * begin communication with the service. + * @ctx: TEE context. + * @client_env_obj: The client environment object returned earlier by QTEE. + * @uefisec_svc_obj: The UEFI Secure App service object. + * + * Returns 0 on success. + * Returns < 0 if client environment object invocation failed. + * Returns > 0 if client environment invocation was success but UEFI Secur= e App + * service object could not be returned for some other reason (represented= by the + * returned value) + */ +static int qcomtee_get_uefisec_svc_obj(struct tee_context *ctx, + struct tee_param_objref client_env_obj, + struct tee_param_objref *uefisec_svc_obj) +{ + int ret; + struct tee_ioctl_object_invoke_arg inv_arg; + u64 obj_id =3D client_env_obj.id; + u32 nparams =3D 2; + struct tee_param param[nparams]; + u32 uefisec_uid =3D QCOMTEE_UEFI_SEC_UID; + + memset(&inv_arg, 0, sizeof(inv_arg)); + memset(¶m, 0, sizeof(param)); + + SET_INVOKE_ARG(inv_arg, obj_id, QCOMTEE_OP_CLIENT_ENV_OPEN, nparams); + SET_TEE_PARAM_UBUF(param[0], UBUF_INPUT, TEE_PARAM_UBUF(uefisec_uid)); + SET_TEE_PARAM_OBJREF(param[1], OBJREF_OUTPUT, 0, 0); + + ret =3D tee_client_object_invoke_func(ctx, &inv_arg, param); + if (ret < 0 || inv_arg.ret !=3D 0) { + dev_err(uefisec_app.dev, "QCOMTEE_CLIENT_ENV_OPEN invoke ret: %d, err: 0= x%x\n", + ret, inv_arg.ret); + return ret ?: inv_arg.ret; + } + + *uefisec_svc_obj =3D param[1].u.objref; + return ret; +} + +/** + * qcomtee_get_client_env_obj() - Get a client environment object to begin + * object exchange with QTEE. + * @ctx: TEE context. + * @client_env_obj: The client environment object returned by QTEE. + * + * Returns 0 on success. + * Returns < 0 if root object invocation failed. + * Returns > 0 if root object invocation was success but client environment + * object could not be returned for some other reason (represented by the + * returned value) + */ +static int qcomtee_get_client_env_obj(struct tee_context *ctx, + struct tee_param_objref *client_env_obj) +{ + int ret; + struct tee_ioctl_object_invoke_arg inv_arg; + u32 nparams =3D 2; + struct tee_param param[nparams]; + + memset(&inv_arg, 0, sizeof(inv_arg)); + memset(¶m, 0, sizeof(param)); + + SET_INVOKE_ARG(inv_arg, TEE_OBJREF_NULL, + QCOMTEE_ROOT_OP_REG_WITH_CREDENTIALS, nparams); + SET_TEE_PARAM_OBJREF(param[0], OBJREF_INPUT, TEE_OBJREF_NULL, 0); + SET_TEE_PARAM_OBJREF(param[1], OBJREF_OUTPUT, 0, 0); + + ret =3D tee_client_object_invoke_func(ctx, &inv_arg, param); + if (ret < 0 || inv_arg.ret !=3D 0) { + dev_err(uefisec_app.dev, "QCOMTEE_ROOT_OP_REG_WITH_CREDENTIALS invoke re= t: %d, err: 0x%x\n", + ret, inv_arg.ret); + return ret ?: inv_arg.ret; + } + + *client_env_obj =3D param[1].u.objref; + return ret; +} + +static const struct efivar_operations qcom_efivar_ops =3D { + .get_variable =3D qcomtee_uefi_get_variable, + .set_variable =3D qcomtee_uefi_set_variable, + .get_next_variable =3D qcomtee_uefi_get_next_variable, + .query_variable_info =3D qcomtee_uefi_query_variable_info, +}; + +static int qcomtee_ctx_match(struct tee_ioctl_version_data *ver, + const void *data) +{ + return (ver->impl_id =3D=3D TEE_IMPL_ID_QTEE); +} + +static int qcomtee_uefisecapp_probe(struct tee_client_device *tee_dev) +{ + int ret, err; + struct tee_param_objref client_env_obj; + struct tee_param_objref uefisec_svc_obj; + + uefisec_app.dev =3D &tee_dev->dev; + /* Open context with QCOMTEE driver */ + uefisec_app.ctx =3D tee_client_open_context(NULL, qcomtee_ctx_match, NULL, + NULL); + if (IS_ERR(uefisec_app.ctx)) + return -ENODEV; + + /* Obtain a reference to client_env object to begin object exchange + * with QTEE + */ + ret =3D qcomtee_get_client_env_obj(uefisec_app.ctx, &client_env_obj); + if (ret) { + err =3D -EINVAL; + goto err_get_client_env; + } + + /* Obtain a reference to the uefisec_svc object which provides access to + * the EFI var storage. + */ + ret =3D qcomtee_get_uefisec_svc_obj(uefisec_app.ctx, client_env_obj, + &uefisec_svc_obj); + if (ret) { + err =3D -EINVAL; + goto err_get_uefisec_svc; + } + uefisec_app.uefisec_svc_obj =3D uefisec_svc_obj; + + ret =3D efivars_register(&uefisec_app.efivars, &qcom_efivar_ops); + if (ret) { + err =3D ret; + goto err_efi_vars_reg; + } + + /* We don't need to keep a reference to this object anymore, we only + * needed it to obtain the uefisec_svc object. + */ + qcomtee_release_object(uefisec_app.ctx, client_env_obj); + return 0; + +err_efi_vars_reg: + qcomtee_release_object(uefisec_app.ctx, uefisec_svc_obj); +err_get_uefisec_svc: + qcomtee_release_object(uefisec_app.ctx, client_env_obj); +err_get_client_env: + tee_client_close_context(uefisec_app.ctx); + + return err; +} + +static void qcomtee_uefisecapp_remove(struct tee_client_device *tee_dev) +{ + efivars_unregister(&uefisec_app.efivars); + qcomtee_release_object(uefisec_app.ctx, uefisec_app.uefisec_svc_obj); + tee_client_close_context(uefisec_app.ctx); +} + +static const struct tee_client_device_id qcomtee_uefisecapp_id_table[] =3D= { + {UEFISECAPP_UUID}, + {} +}; +MODULE_DEVICE_TABLE(tee, qcomtee_uefisecapp_id_table); + +static struct tee_client_driver qcomtee_uefisecapp_driver =3D { + .id_table =3D qcomtee_uefisecapp_id_table, + .probe =3D qcomtee_uefisecapp_probe, + .remove =3D qcomtee_uefisecapp_remove, + .driver =3D { + .name =3D "qcom-tee-uefisecapp", + }, +}; + +module_tee_client_driver(qcomtee_uefisecapp_driver); + +MODULE_AUTHOR("Qualcomm"); +MODULE_DESCRIPTION("TEE client driver for Qualcomm TEE UEFI Secure App"); +MODULE_LICENSE("GPL"); diff --git a/drivers/firmware/qcom/qcom_tee_uefisecapp.h b/drivers/firmware= /qcom/qcom_tee_uefisecapp.h new file mode 100644 index 000000000000..a014c18cfed0 --- /dev/null +++ b/drivers/firmware/qcom/qcom_tee_uefisecapp.h @@ -0,0 +1,120 @@ +/* SPDX-License-Identifier: GPL-2.0-only */ +/* + * Copyright (c) Qualcomm Technologies, Inc. and/or its subsidiaries. + */ + +#ifndef QCOM_TEE_UEFISECAPP_H +#define QCOM_TEE_UEFISECAPP_H + +#define QCOMTEE_OP_CLIENT_ENV_OPEN 0 +#define QCOMTEE_ROOT_OP_REG_WITH_CREDENTIALS 5 + +/* Each service exposed by QTEE is identified by a 32-bit UID */ +#define QCOMTEE_UEFI_SEC_UID 413 + +/* Operations supported by the UEFI Sec App service */ +#define QCOMTEE_UEFI_SEC_OP_GET_VAR 0 +#define QCOMTEE_UEFI_SEC_OP_SET_VAR 1 +#define QCOMTEE_UEFI_SEC_OP_QUERY_VAR_INFO 2 +#define QCOMTEE_UEFI_SEC_OP_GET_NEXT_VAR_NAME 3 + +/* Error codes returned by the UEFI Sec App service */ +#define QCOMTEE_UEFI_SEC_SUCCESS 0 +#define QCOMTEE_UEFI_SEC_ERROR_INVALID_PARAMETER 10 +#define QCOMTEE_UEFI_SEC_ERROR_UNSUPPORTED 11 +#define QCOMTEE_UEFI_SEC_ERROR_WRITE_PROTECTED 12 +#define QCOMTEE_UEFI_SEC_ERROR_SECURITY_VIOLATION 13 +#define QCOMTEE_UEFI_SEC_ERROR_DEVICE_ERROR 14 +#define QCOMTEE_UEFI_SEC_ERROR_OUT_OF_RESOURCES 15 +#define QCOMTEE_UEFI_SEC_ERROR_VOLUME_CORRUPTED 16 +#define QCOMTEE_UEFI_SEC_ERROR_SIZE_OUT 17 +#define QCOMTEE_UEFI_SEC_ERROR_NOT_FOUND 18 +#define QCOMTEE_UEFI_SEC_ERROR_ALREADY_STARTED 19 + +/* Operations for objects are 32-bit. QCOMTEE transport uses the upper 16 = bits. */ +#define QCOMTEE_MSG_OBJECT_OP_MASK GENMASK(15, 0) +#define QCOMTEE_MSG_OBJECT_OP_RELEASE (QCOMTEE_MSG_OBJECT_OP_MASK - 0) + +/** + * struct qcomtee_uefisec_app - An instance of UEFI Secure Application. + * @dev: TEE client device on the TEE bus which represents uefisecapp. + * @ctx: The context opened with the TEE subsystem by the uefisecapp clien= t. + * @uefisec_svc_obj: A TEE object representing the uefisecapp service. + * @efivars: EFI variables registered with the EFI subsystem. + */ +struct qcomtee_uefisec_app { + struct device *dev; + struct tee_context *ctx; + struct tee_param_objref uefisec_svc_obj; + struct efivars efivars; +}; + +#define UEFISECAPP_UUID \ + UUID_INIT(0x01f95dcd, 0x2d7e, 0x58be, \ + 0xa1, 0x43, 0x81, 0x32, 0xa1, 0x72, 0xdb, 0x7d) + +/* Short-hands for these long attribute names */ +#define UBUF_INPUT TEE_IOCTL_PARAM_ATTR_TYPE_UBUF_INPUT +#define UBUF_OUTPUT TEE_IOCTL_PARAM_ATTR_TYPE_UBUF_OUTPUT +#define OBJREF_INPUT TEE_IOCTL_PARAM_ATTR_TYPE_OBJREF_INPUT +#define OBJREF_OUTPUT TEE_IOCTL_PARAM_ATTR_TYPE_OBJREF_OUTPUT + +/* Init instance of 'struct tee_param_objref'. */ +#define SET_TEE_PARAM_OBJREF(param, attri, obj_id, obj_flag) do { \ + (param).attr =3D (attri); \ + (param).u.objref.id =3D (obj_id); \ + (param).u.objref.flags =3D (obj_flag); \ + } while (0) + +/* Init instance of 'struct tee_param_ubuf'. */ +#define SET_TEE_PARAM_UBUF(param, attri, ubuff) do { \ + (param).attr =3D (attri); \ + (param).u.ubuf =3D (ubuff); \ + } while (0) + +#define TEE_PARAM_UBUF(x) ((struct tee_param_ubuf){ .addr =3D &(x), sizeof= (x) }) + +#define SET_INVOKE_ARG(arg, object_id, opp, nparam) do { \ + (arg).id =3D (object_id); \ + (arg).op =3D (opp); \ + (arg).num_params =3D (nparam); \ + } while (0) + +static inline efi_status_t uefisecapp_err_to_efi_status(u32 err) +{ + switch (err) { + case QCOMTEE_UEFI_SEC_SUCCESS: + return EFI_SUCCESS; + + case QCOMTEE_UEFI_SEC_ERROR_INVALID_PARAMETER: + return EFI_INVALID_PARAMETER; + + case QCOMTEE_UEFI_SEC_ERROR_UNSUPPORTED: + return EFI_UNSUPPORTED; + + case QCOMTEE_UEFI_SEC_ERROR_WRITE_PROTECTED: + return EFI_WRITE_PROTECTED; + + case QCOMTEE_UEFI_SEC_ERROR_SECURITY_VIOLATION: + return EFI_SECURITY_VIOLATION; + + case QCOMTEE_UEFI_SEC_ERROR_DEVICE_ERROR: + return EFI_DEVICE_ERROR; + + case QCOMTEE_UEFI_SEC_ERROR_OUT_OF_RESOURCES: + return EFI_OUT_OF_RESOURCES; + + case QCOMTEE_UEFI_SEC_ERROR_SIZE_OUT: + return EFI_BUFFER_TOO_SMALL; + + case QCOMTEE_UEFI_SEC_ERROR_NOT_FOUND: + return EFI_NOT_FOUND; + + /* No matching on EFI_* list. */ + case QCOMTEE_UEFI_SEC_ERROR_ALREADY_STARTED: /* EFI_ALREADY_STARTED. */ + case QCOMTEE_UEFI_SEC_ERROR_VOLUME_CORRUPTED: /* EFI_VOLUME_CORRUPTED. */ + default: + return EFI_DEVICE_ERROR; + } +} +#endif /* QCOM_TEE_UEFISECAPP_H */ --=20 2.34.1