summaryrefslogtreecommitdiff
path: root/Documentation/ABI/testing/se-cdev
blob: 0a353caeaab2b9b1bcf6a376119c2ea426c0a559 (plain) (blame)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
What:		/dev/<se>_mu[0-9]+_ch[0-9]+
Date:		Mar 2025
KernelVersion:	6.8
Contact:	linux-imx@nxp.com, pankaj.gupta@nxp.com
Description:
		NXP offers multiple hardware IP(s) for secure enclaves like EdgeLock-
		Enclave(ELE), SECO. The character device file descriptors
		/dev/<se>_mu*_ch* are the interface between userspace NXP's secure-
		enclave shared library and the kernel driver.

		The ioctl(2)-based ABI is defined and documented in
		[include]<uapi/linux/se_ioctl.h>
		ioctl(s) are used primarily for:

			- shared memory management
			- allocation of I/O buffers
			- getting mu info
			- setting a dev-ctx as receiver to receive all the commands from FW
			- getting SoC info
			- send command and receive command response

		The following file operations are supported:

		open(2)
		  Currently the only useful flags are O_RDWR.

		read(2)
		  Every read() from the opened character device context is waiting on
		  wait_for_completion_interruptible_timeout, that gets set by the
		  registered mailbox callback function, indicating a message received
		  from the firmware on message-unit.

		write(2)
		  Every write() to the opened character device context needs to acquire
		  `fops_lock` + `se_if_cmd_lock` lock before sending message on to the
		  message unit.

		close(2)
		  Stops and frees up the I/O contexts that were associated
		  with the file descriptor.

Users:		https://github.com/nxp-imx/imx-secure-enclave.git,
		https://github.com/nxp-imx/imx-smw.git,
		crypto/skcipher,
		drivers/nvmem/imx-ocotp-ele.c