From patchwork Thu Dec 19 18:57:22 2024 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Pankaj Gupta X-Patchwork-Id: 13915089 Received: from EUR05-DB8-obe.outbound.protection.outlook.com (mail-db8eur05on2051.outbound.protection.outlook.com [40.107.20.51]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 7B44BF9E8 for ; Thu, 19 Dec 2024 13:33:27 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=fail smtp.client-ip=40.107.20.51 ARC-Seal: i=2; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1734615209; cv=fail; b=VS/3tlwcXuGfXi2/dHOb40D1zZ5OZDs50+bFdk9aMlaLmb10gB4h+uLlY8BegPaSGc6/puiayNVEXAgbGeNHkGufNZjsZrziylH/Sf74nyWdjhy/SFbeEXmo4XLQa1OQcfRPeOv5Iv9WSYdOom2stMGLEKaLFSiBhiriq3KfZyg= ARC-Message-Signature: i=2; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1734615209; c=relaxed/simple; bh=FwHu8HOgjdeesS4jBLvkey7Y+WnnBYkcgUp1hGR75ZU=; h=From:Date:Subject:Content-Type:Message-Id:References:In-Reply-To: To:Cc:MIME-Version; b=dlAmRVCE2Nbq7ZYJ47LcgSjglZcw1d3hN0/CZEDgy3jN9UVoKD1EptYFwFd48Q31CS8gml8bBysZcT94kP4F7IgoicySzQv76XutdrE3rY+C2mLwtj+318Xxp3HmLDNxtjEUuE1qL0sGKfFmpnD2XoET99QQVH+R/4Wwe44aNKs= ARC-Authentication-Results: i=2; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=nxp.com; spf=pass smtp.mailfrom=nxp.com; dkim=pass (2048-bit key) header.d=nxp.com header.i=@nxp.com header.b=hWimqy5P; arc=fail smtp.client-ip=40.107.20.51 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=nxp.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=nxp.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=nxp.com header.i=@nxp.com header.b="hWimqy5P" ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=n6yaFlaSOH80c5bQcMygDWRL5iOEaCcA5ORqtuCIAhzognZWar83lDprz10p0Xpr9Y29jhK/ntVZwZ/gYnkOsECLEx2eSoolKDSQLFcMrPxbpqxVEf9bhrVxyP/GzTXSbFFGYzlIlTaIHGl6gXKtBTcBXn6CKfBmOBfOQQJt5U3A5JqX2COaeWmtOkHaeSNBKNgcVyENP414fCvU9x7k3J3XM2WcExIebwFa49Cj0iY0apkbOls4kec7UcoiqRPmwoUSw+MvWt14WSXfmfWSmf4+lh/CTLMP+oaurUFvOHztBPpj2Yb7A7xoasqtw6ERmrg8+p7+KOMFcunh0dde4w== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=rydjPSyjFpE1b+KVUJhSPw9jPLhoKfIzwxtGoWGJhg4=; b=d6oMa3B47XRxFPp+Eo67qPPlDitzpzdMRLZXUvY7PBPK/335HP0ORxXxQY57camsNilhMrJld0jrnsBzupn5yt5+9gma8Jk2gA6/Ky0AAvdhDNGztUn3fe5ncWm6qZ9nDHM00LQh1iKs25/n5kZQYbSjjf+YpnPVrFVrza+WXf1i/KxTFYf2Jd3yXESqU4eVP5nWry0Q9I2sUUjdpw48N6FUxF+Ck85OLoV9o91KQlapE7Pxs/LPqefgljuyyNHrvt/7i8Wuj2anQUpHQIKaWuy03rZ65QmkVBS5JsDNXDd4VThtP0M5vXjKYbr2JiHk5fz9yjB9LOqiwydNFEwsJQ== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=nxp.com; dmarc=pass action=none header.from=nxp.com; dkim=pass header.d=nxp.com; arc=none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=nxp.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=rydjPSyjFpE1b+KVUJhSPw9jPLhoKfIzwxtGoWGJhg4=; b=hWimqy5PWINeC/BUscdkGW71x1E5m0q1s3NDk//cGUMCT0qeA+tbBzOIdUbw5At2pjfIv1swe2fQtadabgxL40r4iU2AxfJi4UxzF61A7DoeXY3rLy1ZRDqAeNwCC+j5XqWyKoB204W3IQQkj2PY+ODt/XDb7z304qAC8vJiuuaFD5aKQw8Q5AYaU7pQC3QNLZHauTpJZDJnPUIN9OvlX5J6ys3r3QY/UU4CapKM0rQgmU6J1jM6b93gAdzOJdcjfIDULWaNB1dVJdymm5BjI6DUGGgsSzbm2dIDhOJx95arTUx4G9290MvNLFiyBjAvuiOULaCjUCWbw2rI+iByZQ== Authentication-Results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=nxp.com; Received: from AM9PR04MB8604.eurprd04.prod.outlook.com (2603:10a6:20b:43b::21) by DUZPR04MB9919.eurprd04.prod.outlook.com (2603:10a6:10:4d9::11) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.8272.13; Thu, 19 Dec 2024 13:33:25 +0000 Received: from AM9PR04MB8604.eurprd04.prod.outlook.com ([fe80::e751:223e:aa3d:5827]) by AM9PR04MB8604.eurprd04.prod.outlook.com ([fe80::e751:223e:aa3d:5827%4]) with mapi id 15.20.8272.013; Thu, 19 Dec 2024 13:33:25 +0000 From: Pankaj Gupta Date: Fri, 20 Dec 2024 00:27:22 +0530 Subject: [PATCH v11 1/5] Documentation/firmware: add imx/se to other_interfaces Message-Id: <20241220-imx-se-if-v11-1-0c7e65d7ae7b@nxp.com> References: <20241220-imx-se-if-v11-0-0c7e65d7ae7b@nxp.com> In-Reply-To: <20241220-imx-se-if-v11-0-0c7e65d7ae7b@nxp.com> To: Jonathan Corbet , Rob Herring , Krzysztof Kozlowski , Conor Dooley , Shawn Guo , Sascha Hauer , Pengutronix Kernel Team , Fabio Estevam , Pankaj Gupta Cc: linux-doc@vger.kernel.org, linux-kernel@vger.kernel.org, devicetree@vger.kernel.org, imx@lists.linux.dev, linux-arm-kernel@lists.infradead.org X-Mailer: b4 0.13.0 X-Developer-Signature: v=1; a=ed25519-sha256; t=1734634652; l=6679; i=pankaj.gupta@nxp.com; s=20240523; h=from:subject:message-id; bh=FwHu8HOgjdeesS4jBLvkey7Y+WnnBYkcgUp1hGR75ZU=; b=uOfJCs2uqohNFlKFXi5wpmFQWkW1t+bdDE8E7GgpDJMclASvmVndXPz4YplsCo2mH5msuQuPd d0WHmpUya04Dlg8UJRvcWTL3zeFs9Nc2GKZEeVjFlTlgkoNpkCcFexv X-Developer-Key: i=pankaj.gupta@nxp.com; a=ed25519; pk=OA0pBQoupy5lV0XfKzD8B0OOBVB6tpAoIf+0x1bYGRg= X-ClientProxiedBy: SG2P153CA0012.APCP153.PROD.OUTLOOK.COM (2603:1096::22) To AM9PR04MB8604.eurprd04.prod.outlook.com (2603:10a6:20b:43b::21) Precedence: bulk X-Mailing-List: imx@lists.linux.dev List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-MS-PublicTrafficType: Email X-MS-TrafficTypeDiagnostic: AM9PR04MB8604:EE_|DUZPR04MB9919:EE_ X-MS-Office365-Filtering-Correlation-Id: 4ab33ec8-a56d-4d0f-7953-08dd2031afcb X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam: BCL:0;ARA:13230040|1800799024|52116014|7416014|376014|366016|38350700014; X-Microsoft-Antispam-Message-Info: =?utf-8?q?KHZkVYcYl0WmjBFOg8jUAv2emdEYqdP?= =?utf-8?q?gOoUNOXNO07+aHlvxHgF8rXdSD5b+cCV39cPuSgQRQZbCwW5SokYVtGFywTJdp6yv?= =?utf-8?q?Z3uUDq+L5OCwdH2P6f0s7av/Qsy+vkTHkD3QGvrwsbtlGngWOHb0J3DngdSlIPaWM?= =?utf-8?q?IB43XTPrmbcXjCy6aMbKuSFiZJQRjUT3TSLJFHRDwKWvtRkoXSNFqVhklpHegTcVG?= =?utf-8?q?i/998USj0eFYEr0mSNduC19lAUgZ0b46IVSpRLGrEIGlP8zDPNt7mUY4JbqKgOR/f?= =?utf-8?q?9qUs4XSHd8nH7tuV2eL3TBBhOj5ETutKO4xJw/a2K+DirQO+GD2mwqqNdaP07xLtv?= =?utf-8?q?HlVmCEqCh5Z2QHFWRXVhePUPXL2bZHNaEgju5PVxk1ipLQ/6oQQjqj2L6fkXiQoEW?= =?utf-8?q?eZvi5EztuW48UwuQ2MLf7kfUz1LGPAJIPnxABwgNoOiRddqHA0606lmAY/txhLfGl?= =?utf-8?q?GATEE5vYNRZQkBoGyibeB759y0oHTBCc9OhhCA8hlME2tf0jkjub1LsOqmefA6kph?= =?utf-8?q?dYaTf5Ybl//lioSNlwzaykPk7Wj/lhez0CUJ5IxwtdhHdswkelE/xvhAQp9KZ09uv?= =?utf-8?q?meogciTMsqp5TwIfBhd59lc96GGpl4QFIScJs18kK9uGQXLGcDmSUM7sa5GN97snP?= =?utf-8?q?PGQHW0ah/pAszJEeWw3kc9wIzdK4eo1/qNDYK3IsjsEFhwQDrXQjEculIlbPLe4DZ?= =?utf-8?q?tzmjYIIpbLraX4+/TWPrAbe+rdDO2zqzUa7Ggjh/vbFUdVu5ptpHVfqy3yoBokvX8?= =?utf-8?q?oTUyprsKunjuP1UJVZDhfDj8R5AHorKoMCgkC6YxbbOby+7ocoLTG+otfsmntwaq5?= =?utf-8?q?wifIPq7uPl/hLoON4RmWMretjxJw63sSSG20v8Wuc81nlzR6ycjTCbPgwmS1YOxGq?= =?utf-8?q?V0CBL3Bdnu1fOn8zAf+mGrTkWM58rPPKhtLE4wcE7F1Gi4IgKAQzLG7D/pVjPSpk2?= =?utf-8?q?t2RjbeEJT0UUUbKCO95MUThAzV2PylDuhTOmqnmkAmzas/yeY05YT8DMzoAaSEO1h?= =?utf-8?q?U0wrud3huzMgxzXqsz4lMan9NW0ZCmOsXqf+ucrdDBoRTUtbodSh8gTaL+3QRpUE7?= =?utf-8?q?f2KbLImcoi4n9N3/zPlnLfeg7QsCh/r5E/fcUFjoShSdcKn6PtSloIgEeQDM7h4Ky?= =?utf-8?q?qK7CqoQurqGp2HWU1Lcub2mSAMNk6kqNx115ECR+fQhm9GWR2XF7xJ13h8Ndy0IbK?= =?utf-8?q?N0pGXbSdDWrgzp48/+x04s1+EoRacegfJ3DeB9FUcECzR0pJIZD6pTYUiNp1Mvjyz?= =?utf-8?q?AFN07TO+yPkStlQQbBUq8VIuZgUpK7NEN4xpnyGsZV9EA3spDGkQ5crVSLtCETmoj?= =?utf-8?q?SKb1Wrh3LkgWwUJY6sbcgs0Hc2DeGHpQPBbhCEWGt/atIAQoDmfZPXQ=3D?= X-Forefront-Antispam-Report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:AM9PR04MB8604.eurprd04.prod.outlook.com;PTR:;CAT:NONE;SFS:(13230040)(1800799024)(52116014)(7416014)(376014)(366016)(38350700014);DIR:OUT;SFP:1101; X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1 X-MS-Exchange-AntiSpam-MessageData-0: =?utf-8?q?GeF+evIxYk2XNFlGRYm9mqGtIgO1?= =?utf-8?q?SDNQf355SUL1jMNY7N+Dkh0JehvVbhGholBGgX1CWs3v7I5uHJ2j7JVEblJkmMwci?= =?utf-8?q?rKeQiOIOc50yB81RZueXm4EnuM7xjw8QitOoGRCFwwkVUfEUp5otS2mjJAo6mqYd8?= =?utf-8?q?DZVCqL4WQjsC9ExXZn2RWmH/zmPoHzBrPeJVI8GvC5XJSzzrpt8jO3/xC4mWuzElE?= =?utf-8?q?66mCQ7ukj/YUgsYzie3AaN85Hqd0uEiD4zhyhNcjIGBOF8gjontWp8eaIgoDme8GW?= =?utf-8?q?YjwtDvS59oqgBYrT0bu5Bb4DF8mRaTb8yxJ1YdNtzK1oaYxBSaphFxwVjgayS1VX1?= =?utf-8?q?+L3+VB8jpdR+YS4wsNXw+zww1OuQXP1aZaIhqvluUwi8cHnUeM7VUac21cx8LuNW6?= =?utf-8?q?yAKzhlm2ORQiWqFhUPCWv8VTS0tzFTWkfhT17Vc7sIcHKbBANKcpV3Pci7SM2lssq?= =?utf-8?q?5PDwsUbwOqpn5DkHvqH2+q+1bXJN92gauzc99LTcEucJH67ah1g4261IemIQPb3jX?= =?utf-8?q?oa5GyVJevBq6BLlWzHyvMwYxRngJmQL/BTHArhd5L/oIjir/rwMHO3RnyW4I5liGC?= =?utf-8?q?lfKQrtyQKQB9LDHxKMm1fvXWRbSO+aq8Q/IOmzHiMkOgaLelLGPLZlsMpAMDsZ9a+?= =?utf-8?q?uyGBPxNXcm0pNjVEoItLrNraMTZ837r57L1nyxZ+4RVNUysp1qtAcYKE2SyEqpbc3?= =?utf-8?q?jtoQWEp7V8TfViAoPqNo+fJK9ZzRXy1NVwvEdjFBVaMAIYIwbgUbCRXhJR8G97Wa1?= =?utf-8?q?bLWI5SzGX96eWhtIDeVcbAizr7iIlghEz7rQac9ZbNO66LVpmw+tiHAVSFNg5AWDm?= =?utf-8?q?LaHN/PbN0eOTPJgsn5E83Mq871mJ3XaDPtefoqoePpD6cSK1VLXwvHDXlAPUBaD18?= =?utf-8?q?iyoAjE56sUI3fJhsOfS2QTY4Gk36v/zlI7KAWQv/9hVVDeXeFVDKOx+B3b63qvNiT?= =?utf-8?q?YNkjRX+NBOcLOaaaAM/NO6z7fwGC/HOqLL/lLb+emIA6SKfZPbk7HfyWoV8gBRKdz?= =?utf-8?q?qnygCni2BzFKil0B4wuLmW8zZy4cBJuvU9Z+DsrNUv/a1PqT/V9UuP1ANE4jcSXTk?= =?utf-8?q?cirsVqNjtUQ7flrQHnSsCTSfF59iesnNGCZXKXQ2vH5CzggGgdff69nmNtpvfhd+2?= =?utf-8?q?MzfGZE/4b1ZT1PEqAwvkaIGxk7bIVfCaq5wQk5MYESl+46OD2VqCbmRJ54APEax+r?= =?utf-8?q?SekgNR6+qH9PaA0RITenJbJlaBJOBp1ucfBWCwTqZnQYPir7kzQhzD4t8WnyNfRK/?= =?utf-8?q?FkiADxdKNVFN2S8luZ2rD3olYgAZXcnPUr4VuY057ewK2NLc3YdKD+BsSFaZXnDGV?= =?utf-8?q?mkZc2JtpKCQBGPjD1CKCnIddvwGOqhUJSdrFqKR2ywK5mEKdgyGSNeNUkXsyt+KV2?= =?utf-8?q?CK0L1xn877iVKe8QAxbNmd3OqxiwDRmfwLKj/atQlCWlYshGjE1KCnX+f/brXXi2Q?= =?utf-8?q?Q56WnB4yUdd55VQzKDON2KezTcwakH4/C8lJkXnuOXMEE33VyMe1gV6bLLxONSE9j?= =?utf-8?q?WeGX8rc7qtrC?= X-OriginatorOrg: nxp.com X-MS-Exchange-CrossTenant-Network-Message-Id: 4ab33ec8-a56d-4d0f-7953-08dd2031afcb X-MS-Exchange-CrossTenant-AuthSource: AM9PR04MB8604.eurprd04.prod.outlook.com X-MS-Exchange-CrossTenant-AuthAs: Internal X-MS-Exchange-CrossTenant-OriginalArrivalTime: 19 Dec 2024 13:33:21.7287 (UTC) X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted X-MS-Exchange-CrossTenant-Id: 686ea1d3-bc2b-4c6f-a92c-d99c5c301635 X-MS-Exchange-CrossTenant-MailboxType: HOSTED X-MS-Exchange-CrossTenant-UserPrincipalName: Pgy4w0txBD3/3XwSRUl0nBov9kiHTxTtKXQPS3vu92nM+whezLOe5MydyE8yJZ/4OL5t9h7+o/c9PdF9Hyosyg== X-MS-Exchange-Transport-CrossTenantHeadersStamped: DUZPR04MB9919 Documents i.MX SoC's Service layer and C_DEV driver for selected SoC(s) that contains the NXP hardware IP(s) for Secure Enclaves(se) like: - NXP EdgeLock Enclave on i.MX93 & i.MX8ULP Signed-off-by: Pankaj Gupta --- .../driver-api/firmware/other_interfaces.rst | 121 +++++++++++++++++++++ 1 file changed, 121 insertions(+) diff --git a/Documentation/driver-api/firmware/other_interfaces.rst b/Documentation/driver-api/firmware/other_interfaces.rst index 06ac89adaafb..a3a95b54a174 100644 --- a/Documentation/driver-api/firmware/other_interfaces.rst +++ b/Documentation/driver-api/firmware/other_interfaces.rst @@ -49,3 +49,124 @@ of the requests on to a secure monitor (EL3). .. kernel-doc:: drivers/firmware/stratix10-svc.c :export: + +NXP Secure Enclave Firmware Interface +===================================== + +Introduction +------------ +The NXP's i.MX HW IP like EdgeLock Enclave, V2X etc., creates an embedded secure +enclave within the SoC boundary to enable features like + - Hardware Security Module (HSM) + - Security Hardware Extension (SHE) + - Vehicular to Anything (V2X) + +Each of the above feature is enabled through dedicated NXP H/W IP on the SoC. +On a single SoC, multiple hardware IP (or can say more than one secure enclave) +can exist. + +NXP SoCs enabled with the such secure enclaves(SEs) IPs are: +i.MX93, i.MX8ULP + +To communicate with one or more co-existing SE(s) on SoC, there is/are dedicated +messaging units(MU) per SE. Each co-existing SE can have one or multiple exclusive +MUs, dedicated to itself. None of the MU is shared between two SEs. +Communication of the MU is realized using the Linux mailbox driver. + +NXP Secure Enclave(SE) Interface +-------------------------------- +Although MU(s) is/are not shared between SE(s). But for SoC like i.MX95 which has +multiple SE(s) like HSM, V2X-HSM, V2X-SHE; all the SE(s) and their interfaces 'se-if' +that is/are dedicated to a particular SE will be enumerated and provisioned using the +single compatible node("fsl,imx95-se"). + +Each 'se-if' comprise of twp layers: +- (C_DEV Layer) User-Space software-access interface. +- (Service Layer) OS-level software-access interface. + + +--------------------------------------------+ + | Character Device(C_DEV) | + | | + | +---------+ +---------+ +---------+ | + | | misc #1 | | misc #2 | ... | misc #n | | + | | dev | | dev | | dev | | + | +---------+ +---------+ +---------+ | + | +-------------------------+ | + | | Misc. Dev Synchr. Logic | | + | +-------------------------+ | + | | + +--------------------------------------------+ + + +--------------------------------------------+ + | Service Layer | + | | + | +-----------------------------+ | + | | Message Serialization Logic | | + | +-----------------------------+ | + | +---------------+ | + | | imx-mailbox | | + | | mailbox.c | | + | +---------------+ | + | | + +--------------------------------------------+ + +- service layer: + This layer is responsible for ensuring the communication protocol that is defined + for communication with firmware. + + FW Communication protocol ensures two things: + - Serializing the messages to be sent over an MU. + + - FW can handle one command message at a time. + +- c_dev: + This layer offers character device contexts, created as '/dev/_mux_chx'. + Using these multiple device contexts that are getting multiplexed over a single MU, + userspace application(s) can call fops like write/read to send the command message, + and read back the command response message to/from Firmware. + fops like read & write use the above defined service layer API(s) to communicate with + Firmware. + + Misc-device(/dev/_mux_chn) synchronization protocol: + + Non-Secure + Secure + | + | + +---------+ +-------------+ | + | se_fw.c +<---->+imx-mailbox.c| | + | | | mailbox.c +<-->+------+ +------+ + +---+-----+ +-------------+ | MU X +<-->+ ELE | + | +------+ +------+ + +----------------+ | + | | | + v v | + logical logical | + receiver waiter | + + + | + | | | + | | | + | +----+------+ | + | | | | + | | | | + device_ctx device_ctx device_ctx | + | + User 0 User 1 User Y | + +------+ +------+ +------+ | + |misc.c| |misc.c| |misc.c| | + kernel space +------+ +------+ +------+ | + | + +------------------------------------------------------ | + | | | | + userspace /dev/ele_muXch0 | | | + /dev/ele_muXch1 | | + /dev/ele_muXchY | + | + +When a user sends a command to the firmware, it registers its device_ctx +as waiter of a response from firmware. + +Enclave's Firmware owns the storage management, over Linux filesystem. +For this c_dev provisions a dedicated slave device called "receiver". + +.. kernel-doc:: drivers/firmware/imx/se_fw.c + :export: