diff options
| author | Mark Brown <broonie@kernel.org> | 2026-09-30 12:47:29 +0100 |
|---|---|---|
| committer | Mark Brown <broonie@kernel.org> | 2026-09-30 12:47:29 +0100 |
| commit | d5ffed5a8e3daecdeecc2e18bfa04a2253d84f60 (patch) | |
| tree | 40df117b456007261f68c826e833963e84278cbf /Documentation | |
| parent | 4d80b22865cc3e453aab4777948408c32f150483 (diff) | |
| parent | 5d034f17b24642b2a764c0e3a68b4c6937c9ba75 (diff) | |
| download | linux-next-d5ffed5a8e3daecdeecc2e18bfa04a2253d84f60.tar.gz linux-next-d5ffed5a8e3daecdeecc2e18bfa04a2253d84f60.zip | |
Merge branch 'for-next' of https://git.kernel.org/pub/scm/linux/kernel/git/frank.li/linux.git
Diffstat (limited to 'Documentation')
8 files changed, 517 insertions, 13 deletions
diff --git a/Documentation/ABI/testing/se-cdev b/Documentation/ABI/testing/se-cdev new file mode 100644 index 000000000000..0a353caeaab2 --- /dev/null +++ b/Documentation/ABI/testing/se-cdev @@ -0,0 +1,45 @@ +What: /dev/<se>_mu[0-9]+_ch[0-9]+ +Date: Mar 2025 +KernelVersion: 6.8 +Contact: linux-imx@nxp.com, pankaj.gupta@nxp.com +Description: + NXP offers multiple hardware IP(s) for secure enclaves like EdgeLock- + Enclave(ELE), SECO. The character device file descriptors + /dev/<se>_mu*_ch* are the interface between userspace NXP's secure- + enclave shared library and the kernel driver. + + The ioctl(2)-based ABI is defined and documented in + [include]<uapi/linux/se_ioctl.h> + ioctl(s) are used primarily for: + + - shared memory management + - allocation of I/O buffers + - getting mu info + - setting a dev-ctx as receiver to receive all the commands from FW + - getting SoC info + - send command and receive command response + + The following file operations are supported: + + open(2) + Currently the only useful flags are O_RDWR. + + read(2) + Every read() from the opened character device context is waiting on + wait_for_completion_interruptible_timeout, that gets set by the + registered mailbox callback function, indicating a message received + from the firmware on message-unit. + + write(2) + Every write() to the opened character device context needs to acquire + `fops_lock` + `se_if_cmd_lock` lock before sending message on to the + message unit. + + close(2) + Stops and frees up the I/O contexts that were associated + with the file descriptor. + +Users: https://github.com/nxp-imx/imx-secure-enclave.git, + https://github.com/nxp-imx/imx-smw.git, + crypto/skcipher, + drivers/nvmem/imx-ocotp-ele.c diff --git a/Documentation/devicetree/bindings/arm/fsl.yaml b/Documentation/devicetree/bindings/arm/fsl.yaml index 656f2596e1d5..e563d96e4ff7 100644 --- a/Documentation/devicetree/bindings/arm/fsl.yaml +++ b/Documentation/devicetree/bindings/arm/fsl.yaml @@ -950,6 +950,23 @@ properties: - const: toradex,colibri-imx7d-emmc - const: fsl,imx7d + - description: i.MX7D Variscite Boards based on VAR-SOM-MX7 Module + oneOf: + - items: + - enum: + - variscite,var-som-imx7d-emmc-mx7customboard + - variscite,var-som-imx7d-emmc-wm8731-mx7customboard + - variscite,var-som-imx7d-nand-mx7customboard + - variscite,var-som-imx7d-nand-wm8731-mx7customboard + - const: variscite,var-som-imx7d + - const: fsl,imx7d + - items: + - enum: + - variscite,var-som-imx7d-v2-emmc-mx7customboard + - variscite,var-som-imx7d-v2-nand-mx7customboard + - const: variscite,var-som-imx7d-v2 + - const: fsl,imx7d + - description: i.MX7ULP based Boards items: - enum: @@ -1511,6 +1528,21 @@ properties: - fsl,imx91-11x11-frdm-s # FRDM i.MX91S Development Board - const: fsl,imx91 + - description: i.MX91 boards with Toradex Lino Modules and Verdin Adapter + items: + - enum: + - toradex,lino-imx91-verdin-dahlia # Lino iMX91 Module on Verdin Dahlia Board + - toradex,lino-imx91-verdin-dev # Lino iMX91 Module on Verdin Dev Board + - const: toradex,lino-imx91-verdin # Lino iMX91 Module on Verdin Adapter + - const: toradex,lino-imx91 + - const: fsl,imx91 + + - description: i.MX91 boards with Toradex OSM Modules + items: + - const: toradex,osm-imx91-dev # OSM iMX91 Module on OSM Dev Board + - const: toradex,osm-imx91 + - const: fsl,imx91 + - description: i.MX93 based Boards items: - enum: @@ -1519,6 +1551,22 @@ properties: - fsl,imx93-11x11-frdm # i.MX93 11x11 FRDM Board - fsl,imx93-14x14-evk # i.MX93 14x14 EVK Board - fsl,imx93-wireless-evk # i.MX93 and IW610G WLCSP (Wi-Fi + BLE + 802.15.4) SiP EVK Board + - fsl,imx93-wireless-frdm # i.MX93 and IW610G WLCSP (Wi-Fi + BLE + 802.15.4) SiP FRDM Board + - const: fsl,imx93 + + - description: i.MX93 boards with Toradex Lino Modules and Verdin Adapter + items: + - enum: + - toradex,lino-imx93-verdin-dahlia # Lino iMX93 Module on Verdin Dahlia Board + - toradex,lino-imx93-verdin-dev # Lino iMX93 Module on Verdin Dev Board + - const: toradex,lino-imx93-verdin # Lino iMX93 Module on Verdin Adapter + - const: toradex,lino-imx93 + - const: fsl,imx93 + + - description: i.MX93 boards with Toradex OSM Modules + items: + - const: toradex,osm-imx93-dev # OSM iMX93 Module on OSM Dev Board + - const: toradex,osm-imx93 - const: fsl,imx93 - description: i.MX94 based Boards @@ -1542,6 +1590,7 @@ properties: items: - enum: - fsl,imx952-evk # i.MX952 EVK Board + - fsl,imx952-frdm # i.MX952 FRDM Board - const: fsl,imx952 - description: PHYTEC i.MX 95 FPSC based Boards @@ -1559,6 +1608,12 @@ properties: - const: toradex,aquila-imx95 # Aquila iMX95 Module - const: fsl,imx95 + - description: Toradex Boards with OSM iMX95 Modules + items: + - const: toradex,osm-imx95-dev # Toradex OSM iMX95 Module on Toradex OSM Development Board + - const: toradex,osm-imx95 # Toradex OSM iMX95 Module + - const: fsl,imx95 + - description: Toradex Boards with SMARC iMX95 Modules items: - const: toradex,smarc-imx95-dev # Toradex SMARC iMX95 on Toradex SMARC Development Board @@ -1737,9 +1792,11 @@ properties: - fsl,vf610 - fsl,vf610m4 - - description: Toradex Colibri VF50 Module on Colibri Evaluation Board + - description: Toradex Colibri VF50 Module on a carrier board items: - - const: toradex,vf500-colibri_vf50-on-eval + - enum: + - toradex,vf500-colibri_vf50-on-eval + - toradex,vf500-colibri-vf50-on-iris - const: toradex,vf500-colibri_vf50 - const: fsl,vf500 @@ -1751,9 +1808,11 @@ properties: - phytec,vf610-cosmic # PHYTEC Cosmic/Cosmic+ Board - const: fsl,vf610 - - description: Toradex Colibri VF61 Module on Colibri Evaluation Board + - description: Toradex Colibri VF61 Module on a carrier board items: - - const: toradex,vf610-colibri_vf61-on-eval + - enum: + - toradex,vf610-colibri_vf61-on-eval + - toradex,vf610-colibri-vf61-on-iris - const: toradex,vf610-colibri_vf61 - const: fsl,vf610 @@ -1930,6 +1989,7 @@ properties: - description: LX2160A based Boards items: - enum: + - freemobile,nbxv3 - fsl,lx2160a-bluebox3 - fsl,lx2160a-bluebox3-rev-a - fsl,lx2160a-qds diff --git a/Documentation/devicetree/bindings/display/bridge/fsl,ldb.yaml b/Documentation/devicetree/bindings/display/bridge/fsl,ldb.yaml index 7f380879fffd..e5a8870bb76a 100644 --- a/Documentation/devicetree/bindings/display/bridge/fsl,ldb.yaml +++ b/Documentation/devicetree/bindings/display/bridge/fsl,ldb.yaml @@ -28,9 +28,11 @@ properties: const: ldb reg: + minItems: 1 maxItems: 2 reg-names: + minItems: 1 items: - const: ldb - const: lvds @@ -83,15 +85,6 @@ allOf: ports: properties: port@2: false - - if: - not: - properties: - compatible: - contains: - const: fsl,imx6sx-ldb - then: - required: - - reg-names - if: properties: @@ -100,7 +93,19 @@ allOf: const: fsl,imx6sx-ldb then: properties: + reg: + maxItems: 1 + reg-names: + maxItems: 1 nxp,enable-termination-resistor: false + else: + required: + - reg-names + properties: + reg: + minItems: 2 + reg-names: + minItems: 2 additionalProperties: false diff --git a/Documentation/devicetree/bindings/display/fsl,lcdif.yaml b/Documentation/devicetree/bindings/display/fsl,lcdif.yaml index 2dd0411ec651..2b123ddf0684 100644 --- a/Documentation/devicetree/bindings/display/fsl,lcdif.yaml +++ b/Documentation/devicetree/bindings/display/fsl,lcdif.yaml @@ -182,6 +182,7 @@ allOf: contains: enum: - fsl,imx28-lcdif + - fsl,imx6ul-lcdif then: properties: dmas: false diff --git a/Documentation/devicetree/bindings/firmware/fsl,imx-se.yaml b/Documentation/devicetree/bindings/firmware/fsl,imx-se.yaml new file mode 100644 index 000000000000..fa81adbf9b80 --- /dev/null +++ b/Documentation/devicetree/bindings/firmware/fsl,imx-se.yaml @@ -0,0 +1,91 @@ +# SPDX-License-Identifier: (GPL-2.0-only OR BSD-2-Clause) +%YAML 1.2 +--- +$id: http://devicetree.org/schemas/firmware/fsl,imx-se.yaml# +$schema: http://devicetree.org/meta-schemas/core.yaml# + +title: NXP i.MX HW Secure Enclave(s) EdgeLock Enclave + +maintainers: + - Pankaj Gupta <pankaj.gupta@nxp.com> + +description: | + NXP's SoC may contain one or multiple embedded secure-enclave HW + IP(s) like i.MX EdgeLock Enclave, V2X etc. These NXP's HW IP(s) + enables features like + - Hardware Security Module (HSM), + - Security Hardware Extension (SHE), and + - Vehicular to Anything (V2X) + + Communication interface to the secure-enclaves(se) is based on the + messaging unit(s). + +properties: + compatible: + enum: + - fsl,imx8ulp-se-ele-hsm + - fsl,imx93-se-ele-hsm + - fsl,imx95-se-ele-hsm + + mboxes: + items: + - description: mailbox phandle to send message to se firmware + - description: mailbox phandle to receive message from se firmware + + mbox-names: + items: + - const: tx + - const: rx + + memory-region: + maxItems: 1 + + sram: + maxItems: 1 + +required: + - compatible + - mboxes + - mbox-names + +allOf: + # memory-region + - if: + properties: + compatible: + contains: + enum: + - fsl,imx8ulp-se-ele-hsm + - fsl,imx93-se-ele-hsm + then: + required: + - memory-region + else: + properties: + memory-region: false + + # sram + - if: + properties: + compatible: + contains: + enum: + - fsl,imx8ulp-se-ele-hsm + then: + required: + - sram + + else: + properties: + sram: false + +additionalProperties: false + +examples: + - | + secure-enclave { + compatible = "fsl,imx95-se-ele-hsm"; + mboxes = <&ele_mu0 0 0>, <&ele_mu0 1 0>; + mbox-names = "tx", "rx"; + }; +... diff --git a/Documentation/devicetree/bindings/soc/imx/fsl,imx-iomuxc-gpr.yaml b/Documentation/devicetree/bindings/soc/imx/fsl,imx-iomuxc-gpr.yaml index 721a67e84c13..49813adce71c 100644 --- a/Documentation/devicetree/bindings/soc/imx/fsl,imx-iomuxc-gpr.yaml +++ b/Documentation/devicetree/bindings/soc/imx/fsl,imx-iomuxc-gpr.yaml @@ -47,10 +47,23 @@ properties: reg: maxItems: 1 + '#address-cells': + const: 1 + + '#size-cells': + const: 1 + + ranges: true + mux-controller: type: object $ref: /schemas/mux/reg-mux.yaml + bridge@18: + type: object + $ref: /schemas/display/bridge/fsl,ldb.yaml# + unevaluatedProperties: false + patternProperties: "^ipu[12]_csi[01]_mux$": type: object @@ -67,6 +80,19 @@ allOf: patternProperties: '^ipu[12]_csi[01]_mux$': false + - if: + properties: + compatible: + not: + contains: + const: fsl,imx6sx-iomuxc-gpr + then: + properties: + bridge@18: false + '#address-cells': false + '#size-cells': false + ranges: false + additionalProperties: false required: @@ -87,4 +113,40 @@ examples: }; }; + - | + #include <dt-bindings/clock/imx6sx-clock.h> + + syscon@20e4000 { + compatible = "fsl,imx6sx-iomuxc-gpr", "fsl,imx6q-iomuxc-gpr", "syscon", "simple-mfd"; + reg = <0x020e4000 0x4000>; + #address-cells = <1>; + #size-cells = <1>; + ranges; + + bridge@18 { + compatible = "fsl,imx6sx-ldb"; + reg = <0x18 0x4>; + clocks = <&clks IMX6SX_CLK_LDB_DI0>; + clock-names = "ldb"; + + ports { + #address-cells = <1>; + #size-cells = <0>; + + port@0 { + reg = <0>; + + endpoint { + }; + }; + + port@1 { + reg = <1>; + + endpoint { + }; + }; + }; + }; + }; ... diff --git a/Documentation/devicetree/bindings/vendor-prefixes.yaml b/Documentation/devicetree/bindings/vendor-prefixes.yaml index ba2002969373..e467da45cd7a 100644 --- a/Documentation/devicetree/bindings/vendor-prefixes.yaml +++ b/Documentation/devicetree/bindings/vendor-prefixes.yaml @@ -626,6 +626,8 @@ patternProperties: description: Freebox SAS "^freecom,.*": description: Freecom Gmbh + "^freemobile,.*": + description: Free Mobile "^frida,.*": description: Shenzhen Frida LCD Co., Ltd. "^friendlyarm,.*": diff --git a/Documentation/driver-api/firmware/other_interfaces.rst b/Documentation/driver-api/firmware/other_interfaces.rst index 06ac89adaafb..984ee3ecc8dc 100644 --- a/Documentation/driver-api/firmware/other_interfaces.rst +++ b/Documentation/driver-api/firmware/other_interfaces.rst @@ -49,3 +49,241 @@ of the requests on to a secure monitor (EL3). .. kernel-doc:: drivers/firmware/stratix10-svc.c :export: + +NXP Secure Enclave Firmware Interface +-------------------------------------- + +Introduction +~~~~~~~~~~~~ +NXP i.MX hardware IPs such as EdgeLock Enclave (ELE) and V2X create an +embedded secure enclave within the SoC boundary to enable features like: + +- Hardware Security Module (HSM) +- Security Hardware Extension (SHE) +- Vehicular to Anything (V2X) + +Each of the above features is enabled through a dedicated NXP hardware IP +on the SoC. A single SoC may contain more than one such hardware IP, that +is, more than one secure enclave can coexist. + +NXP SoCs with such secure enclave (SE) IPs are: +i.MX93, i.MX8ULP + +To communicate with one or more coexisting SEs on the SoC, there are +dedicated messaging units (MU) per SE. Each coexisting SE can have one or +more exclusive MUs dedicated to itself. No MU is shared between two SEs. +MU communication is realized using the mailbox driver. Each secure enclave +can serve multiple clients by virtue of these exclusive MUs, and can +distinguish transactions from different clients based on the MU used and +the core security state. The communication between clients and secure +enclaves uses a command/response mechanism. Each client can expose a +specific set of secure enclave features to higher layers, based on the +commands it supports. For example, a secure enclave can simultaneously +serve an OP-TEE TA and a Linux middleware client. Each client exposes a +specific set of secure enclave features based on its supported command set. + +NXP Secure Enclave (SE) Interface +~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ +MUs are not shared between SEs. For an SoC like i.MX95, which has multiple +SEs such as HSM, V2X-HSM, and V2X-SHE, all SEs and their ``se-if`` +interfaces dedicated to a particular SE are enumerated and provisioned +using the single compatible node ``fsl,imx95-se``. + +Each ``se-if`` comprises two layers: + +- (C_DEV Layer) User-space software-access interface. +- (Service Layer) OS-level software-access interface. + +:: + + +--------------------------------------------+ + | Character Device(C_DEV) | + | | + | +---------+ +---------+ +---------+ | + | | misc #1 | | misc #2 | ... | misc #n | | + | | dev | | dev | | dev | | + | +---------+ +---------+ +---------+ | + | +-------------------------+ | + | | Misc. Dev Sync Logic | | + | +-------------------------+ | + | | + +--------------------------------------------+ + +:: + + +--------------------------------------------+ + | Service Layer | + | | + | +-----------------------------+ | + | | Message Serialization Logic | | + | +-----------------------------+ | + | +---------------+ | + | | imx-mailbox | | + | | mailbox.c | | + | +---------------+ | + | | + +--------------------------------------------+ + +- service layer: + This layer ensures the communication protocol defined for interaction + with firmware. + + The firmware communication protocol provides two guarantees: + + - Serializing the messages to be sent over an MU. + - Firmware can handle one command message at a time. + +- c_dev: + This layer offers character device contexts, created as + ``/dev/<se>_mux_chx``. Using multiple device contexts multiplexed over + a single MU, userspace applications can use file operations (fops) such + as ``write`` and ``read`` to send a command message and read back the + response to/from firmware. These fops use the service layer API to + communicate with firmware. + + Misc-device (``/dev/<se>_mux_chn``) synchronization protocol:: + + Non-Secure + Secure + | + | + +-----------+ +-------------+ | + | se_ctrl.c +<---->+imx-mailbox.c| | + | | | mailbox.c +<-->+------+ +------+ + +-----+-----+ +-------------+ | MU X +<-->+ ELE | + | +------+ +------+ + +----------------+ | + | | | + v v | + logical logical | + receiver waiter | + + + | + | | | + | | | + | +----+------+ | + | | | | + | | | | + device_ctx device_ctx device_ctx | + | + User 0 User 1 User Y | + +------+ +------+ +------+ | + |misc.c| |misc.c| |misc.c| | + kernel space +------+ +------+ +------+ | + | + +---------------------------------------------------- | + | | | | + userspace /dev/ele_muXch0 | | | + /dev/ele_muXch1 | | + /dev/ele_muXchY | + | + +When a user sends a command to the firmware, it registers its +``device_ctx`` as a waiter of a response from firmware. + +The secure enclave firmware manages storage over a Linux filesystem. +For this, ``c_dev`` provisions a dedicated device context called the +command-receiver. + + +ELE_STORAGE_OPEN_REQ concurrency and command-receiver exclusivity +~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ + +A userspace-created ``dev_ctx`` becomes the storage subordinate to FW by +being registered as the command-receiver via +``set_dev_ctx_as_command_receiver()``. FW sends NVM callback commands to +this ``dev_ctx`` via that priv's MU, on which the ``dev_ctx`` was created. +Once a userspace ``dev_ctx`` on one priv is registered as the +command-receiver, after opening the storage handle with FW, FW enforces a +global one-storage-instance limit: a concurrent ELE_STORAGE_OPEN_REQ +arriving over this or any other priv's MU is rejected by FW itself, before +any storage handle is allocated. The driver uses three layers of +protection; the sequence below shows how a concurrent race is handled +safely:: + + Userspace A Kernel (se_ctrl) FW (ELE) Userspace B + | | | | + |--ioctl(SEND_RCV)-->| | | + | [advisory check under | | + | modify_lock: no receiver] | | + | [acquire se_if_cmd_lock] |--ioctl(SEND_RCV)-> + | | | [advisory check | + | | | passes: TOCTOU] | + | | | [blocks on | + | | | se_if_cmd_lock] | + | ele_msg_send_rcv() | | + | |--STORAGE_OPEN_REQ--->| | + | |<--STORAGE_OPEN_RSP---| | + | fw_api_specific_ops(): | | + | set_dev_ctx_as_command_receiver| | + | [re-check under modify_lock] | | + | [release se_if_cmd_lock] | | + |<--ioctl 0----------| | | + | | | [B gets lock] | + | | |--STORAGE_OPEN_REQ-> + | | | [FW rejects: | + | | | one storage | + | | | at a time] | + | | |<--ERROR_RSP------| + | | se_val_rsp_hdr_n_status: -EPERM | + | | fw_api_specific_ops not called | + | |<--ioctl -EPERM-to B------------------->| + +The three protection layers are: + +1. Advisory early check (under modify_lock, before send): fast-path + rejection if a receiver is already registered. Not the final gate + because modify_lock is released before the MU send (TOCTOU window). + +2. ``se_if_cmd_lock``: held for the entire send+receive cycle, so only + one ioctl command is in flight on a given MU at a time. + +3. ``set_dev_ctx_as_command_receiver()`` re-checks under modify_lock + after the response arrives. If two callers race past layer 1, FW + itself rejects the second ELE_STORAGE_OPEN_REQ before any handle is + allocated. + +Signal handling after a completed hardware operation +~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ + +A signal may arrive after the firmware has already executed the command +and delivered its response into the MU receive buffer. The driver detects +this case and preserves state before returning ``-EINTR``:: + + Userspace Kernel (se_ctrl) FW (ELE) + | | | + |--ioctl(SEND_RCV)-->| | + | ele_msg_send_rcv() | + | |--CMD_REQ------------>| + | [signal arrives] | | (FW executes, + | | | allocates handle, + | | | writes response) + | |<--CMD_RSP------------| + | wait_for_completion_interruptible() | + | wakes: signal seen -> -ERESTARTSYS | + | | | + | [response is in rx_msg: | + | validate with | + | se_val_rsp_hdr_n_status()] | + | [fw_api_specific_ops() | + | (is_cmd_interrupted=true): | + | for SESSION_OPEN: record | + | handle, close session via | + | se_close_session(), clear; | + | for STORAGE_OPEN: record | + | handle, close storage via | + | se_close_storage(), return 0] | + | err = -EINTR | + | (not -ERESTARTSYS: | + | prevents VFS auto-restart) | + |<--ioctl -EINTR-----| | + | | | + | [signal handler runs; userspace decides | + | whether to re-issue; FW handle tracked | + | or cleaned up; no firmware resource leak]| + +Returning ``-EINTR`` instead of ``-ERESTARTSYS`` is intentional: the VFS +would transparently restart an ioctl on ``-ERESTARTSYS``, re-running the +command with already-zeroed shared input buffers. ``-EINTR`` lets userspace +enter its signal handler and decide whether to reissue the command. + +.. kernel-doc:: drivers/firmware/imx/se_ctrl.c + :export: |
