diff options
| author | Pankaj Gupta <pankaj.gupta@nxp.com> | 2026-09-15 01:10:00 +0530 |
|---|---|---|
| committer | Frank Li <Frank.Li@nxp.com> | 2026-09-23 17:16:40 -0400 |
| commit | dfc0183f20c3b21d67a3e4e6dd34b833a83c19fc (patch) | |
| tree | ff1e02976bd9d42a17534be3e0aee333dd8fb99c /drivers/firmware/imx/se_ctrl.h | |
| parent | 1af212aacb3f6a33106cfd86a50acda47c65b034 (diff) | |
| download | linux-next-dfc0183f20c3b21d67a3e4e6dd34b833a83c19fc.tar.gz linux-next-dfc0183f20c3b21d67a3e4e6dd34b833a83c19fc.zip | |
firmware: imx: add driver for NXP EdgeLock Enclave
Add MU-based communication interface for secure enclave.
NXP hardware IP(s) for secure-enclaves like Edgelock Enclave(ELE), are
embedded in the SoC to support the features like HSM, SHE & V2X, using
message based communication interface.
The secure enclave FW communicates with Linux over single or multiple
dedicated messaging unit(MU) based interface(s).
Exists on i.MX SoC(s) like i.MX8ULP, i.MX93, i.MX95 etc.
For i.MX9x SoC(s) there is at least one dedicated ELE MU(s) for each
world - Linux(one or more) and OPTEE-OS (one or more).
Other dependent kernel drivers will be:
- NVMEM: that supports non-volatile devices like EFUSES,
managed by NXP's secure-enclave.
Signed-off-by: Pankaj Gupta <pankaj.gupta@nxp.com>
Reviewed-by: Frank Li <Frank.Li@nxp.com>
Signed-off-by: Frank Li <Frank.Li@nxp.com>
Diffstat (limited to 'drivers/firmware/imx/se_ctrl.h')
| -rw-r--r-- | drivers/firmware/imx/se_ctrl.h | 112 |
1 files changed, 112 insertions, 0 deletions
diff --git a/drivers/firmware/imx/se_ctrl.h b/drivers/firmware/imx/se_ctrl.h new file mode 100644 index 000000000000..54b2a262a2c3 --- /dev/null +++ b/drivers/firmware/imx/se_ctrl.h @@ -0,0 +1,112 @@ +/* SPDX-License-Identifier: GPL-2.0+ */ +/* + * Copyright 2026 NXP + */ + +#ifndef SE_CTRL_H +#define SE_CTRL_H + +#include <linux/bitfield.h> +#include <linux/miscdevice.h> +#include <linux/mailbox_client.h> +#include <linux/semaphore.h> + +#define MAX_FW_LOAD_RETRIES 50 +#define SE_MSG_WORD_SZ 0x4 + +#define RES_STATUS(x) FIELD_GET(0x000000ff, x) +#define MAX_NVM_MSG_LEN (256) +#define MESSAGING_VERSION_6 0x6 +#define MESSAGING_VERSION_7 0x7 + +struct se_clbk_handle { + struct completion done; + bool signal_rcvd; + u32 rx_msg_sz; + /* + * Assignment of the rx_msg buffer to held till the + * received content as part callback function, is copied. + */ + struct se_api_msg *rx_msg; + /* + * Serialise the timeout path in ele_msg_rcv() against + * se_if_rx_callback() so that the callback can never + * memcpy into a buffer that the timeout path has already + * freed. + */ + spinlock_t clbk_rx_lock; +}; + +struct se_imem_buf { + u8 *buf; + dma_addr_t daddr; + u32 size; + u32 state; +}; + +/* Header of the messages exchange with the EdgeLock Enclave */ +struct se_msg_hdr { + u8 ver; + u8 size; + u8 command; + u8 tag; +} __packed; + +#define SE_MU_HDR_SZ 4 +#define SE_MU_HDR_WORD_SZ 1 + +struct se_api_msg { + struct se_msg_hdr header; + u32 data[]; +}; + +struct se_if_defines { + const u8 se_if_type; + u8 cmd_tag; + u8 rsp_tag; + u8 success_tag; + u8 base_api_ver; + u8 fw_api_ver; +}; + +struct se_fw_img_name { + const char *prim_fw_nm_in_rfs; + const char *seco_fw_nm_in_rfs; +}; + +struct se_fw_load_info { + const struct se_fw_img_name *se_fw_img_nm; + bool is_fw_tobe_loaded; + bool imem_mgmt; + struct se_imem_buf imem; + /* to serialize the fw load state */ + struct mutex load_fw_lock; +}; + +struct se_if_priv { + struct device *dev; + + struct se_clbk_handle cmd_receiver_clbk_hdl; + /* + * Update to the waiting_rsp_dev, to be protected + * under se_if_cmd_lock. + */ + struct se_clbk_handle waiting_rsp_clbk_hdl; + /* + * prevent new command to be sent on the se interface while previous + * command is still processing. (response is awaited) + */ + struct mutex se_if_cmd_lock; + + struct mbox_client se_mb_cl; + struct mbox_chan *tx_chan, *rx_chan; + + struct gen_pool *mem_pool; + const struct se_if_defines *if_defs; + struct se_fw_load_info load_fw; + + atomic_t fw_busy; +}; + +char *get_se_if_name(u8 se_if_id); +#endif |
