From patchwork Tue Oct 15 09:00:59 2024 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Pankaj Gupta X-Patchwork-Id: 13835938 Received: from EUR02-DB5-obe.outbound.protection.outlook.com (mail-db5eur02on2064.outbound.protection.outlook.com [40.107.249.64]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 72CF11D9A79 for ; Tue, 15 Oct 2024 09:05:39 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=fail smtp.client-ip=40.107.249.64 ARC-Seal: i=2; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1728983141; cv=fail; b=BVcrFc75nv1FdjM2CmiMHvzenKezBgP93OtQu5OIyFYKiVSq+2gLLg3uYe2FflBkWJnjiZNP1p9L5JFflJMP0Eq4NxfB1I9hRBKzFyYqhEBUnPYXEdWOtyR6u9l6cf0pgI+PwagA74+P0Dk/00kINnfKsh3mFrLRXV2sHf4tiKs= ARC-Message-Signature: i=2; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1728983141; c=relaxed/simple; bh=FwHu8HOgjdeesS4jBLvkey7Y+WnnBYkcgUp1hGR75ZU=; h=From:Date:Subject:Content-Type:Message-Id:References:In-Reply-To: To:Cc:MIME-Version; b=ReSH6E8mYq9xDQRdeTAIaMgoP27ZBrDeEqvj6S8GuIIq4YmyGek2Z68JGtbWWCKsZtU/bDJMLX15aV/vsrtCZkUPW1TYZRzdcVbA3HNVWIc9N7LSRkyNxK3CuStc329b+8CoUYaAJoaLzxhIV7Lnypwmm/koSbso9oUcyO0lHK8= ARC-Authentication-Results: i=2; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=nxp.com; spf=pass smtp.mailfrom=nxp.com; dkim=pass (2048-bit key) header.d=nxp.com header.i=@nxp.com header.b=RDONsXzq; arc=fail smtp.client-ip=40.107.249.64 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=nxp.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=nxp.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=nxp.com header.i=@nxp.com header.b="RDONsXzq" ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=oiY9/AUirsKO+93dkEnntxkWC1IPm6/L73J2f3Y7W00/R65CZq0FOEUnKiLnFmXkI0H+spL4dPod3YrBbywsk53Xt9TshLH5+zG14ItA74Y/9RgEwzTDfPRPJkHkfWJeqJnVvJbztTHcB2f8+2S2DrB9mMpjt6PcFt0dAgjWq48UMuTmUfLrDCoGxtOFsTAj3pgafkS2E3Mt/K8+iItHU0hWqOgocPYMxUTXZvbuQPGl11bvuInu9EiWdgQkDCNmx12boV3I51CSdgXrSm0FtnGiGKPHdPD2BCBkF4ZokFNLwZJhyjmvFPGiFvqZlaMMxe5kSR//FcUDx6jopK9Dwg== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=rydjPSyjFpE1b+KVUJhSPw9jPLhoKfIzwxtGoWGJhg4=; b=ydUG20sT669wdhh+FCQZ/SUVmCl92pc4EE2g6OuTK+Y7TsSsH2e4O3zHR6NPx5XPIqz/nb2gei9UFNZMquiD01Ss52gtE1uGgyLGgJ1bQUAQN4+hJ01RZWrRT/ok4DsqiOAI6J4UfqZq87b9CFtVV7I8j5G3tOPj3ffItsJGQPPPKJSPvlLSzniz0LVTSAkZtXXEZMFd7etOw99GXWJiurXRP1AaVbgE8JrNbuuQiHsqSnZWs6cPIiuPUNmas6o834M0e9VhVtLm4+/QyBMjDP96nB9uaCdctINZy9hLcIaNjxb121H1gmnkWt7wJ3TR3ci0J+EfROUF4nj2oSJPBw== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=nxp.com; dmarc=pass action=none header.from=nxp.com; dkim=pass header.d=nxp.com; arc=none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=nxp.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=rydjPSyjFpE1b+KVUJhSPw9jPLhoKfIzwxtGoWGJhg4=; b=RDONsXzqJvvNc/Uk0gKM7+zJ4SDleFdu4ShB1Hhen6MahSsspACnQIsdh6c2Z87Oqzf40J57hnbiGPy0+2/J69p4YUP8M3yqnXf00r7N1uYqiorJ75Pq4VbSor8+P+ZjrekSMI6d5TEj1waVnKweCB9N9rWrhOLNsWzpCHQBbNDq/DUP0CH81K89aJ3/O4kbDE8LGzEGW9DcP9zu53+oU6rLYBspDa0lphSw2MhXNIfov+pWkBWEnltXV48NLf1cPemv3tt5+B0J7AH2/Ft6u0X3FXw+TV0Cl3eD/n8Yp9o578t+QCK4Apw5FJ4BPj7EqxvoEu3dGf6/fkhaFzKhYQ== Authentication-Results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=nxp.com; Received: from AM9PR04MB8604.eurprd04.prod.outlook.com (2603:10a6:20b:43b::21) by PA4PR04MB9223.eurprd04.prod.outlook.com (2603:10a6:102:2a2::15) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.8069.17; Tue, 15 Oct 2024 09:05:35 +0000 Received: from AM9PR04MB8604.eurprd04.prod.outlook.com ([fe80::e751:223e:aa3d:5827]) by AM9PR04MB8604.eurprd04.prod.outlook.com ([fe80::e751:223e:aa3d:5827%5]) with mapi id 15.20.8048.020; Tue, 15 Oct 2024 09:05:35 +0000 From: Pankaj Gupta Date: Tue, 15 Oct 2024 14:30:59 +0530 Subject: [PATCH v8 1/5] Documentation/firmware: add imx/se to other_interfaces Message-Id: <20241015-imx-se-if-v8-1-915438e267d3@nxp.com> References: <20241015-imx-se-if-v8-0-915438e267d3@nxp.com> In-Reply-To: <20241015-imx-se-if-v8-0-915438e267d3@nxp.com> To: Jonathan Corbet , Rob Herring , Krzysztof Kozlowski , Conor Dooley , Shawn Guo , Sascha Hauer , Pengutronix Kernel Team , Fabio Estevam , Pankaj Gupta , Rob Herring Cc: linux-doc@vger.kernel.org, linux-kernel@vger.kernel.org, devicetree@vger.kernel.org, imx@lists.linux.dev, linux-arm-kernel@lists.infradead.org X-Mailer: b4 0.13.0 X-Developer-Signature: v=1; a=ed25519-sha256; t=1728982877; l=6679; i=pankaj.gupta@nxp.com; s=20240523; h=from:subject:message-id; bh=FwHu8HOgjdeesS4jBLvkey7Y+WnnBYkcgUp1hGR75ZU=; b=u+8NDXlnVE7athGjzhrM5LJk6qkb4yx+XAWXSln9eLk47fEqSzrKRUSryd+r0oIYZQTInMVVD Mvjrch8YcckAboplriwhB928jikXwawOuqMH0cKafkiAvWRLYpGtCXq X-Developer-Key: i=pankaj.gupta@nxp.com; a=ed25519; pk=OA0pBQoupy5lV0XfKzD8B0OOBVB6tpAoIf+0x1bYGRg= X-ClientProxiedBy: SG2P153CA0019.APCP153.PROD.OUTLOOK.COM (2603:1096:4:c7::6) To AM9PR04MB8604.eurprd04.prod.outlook.com (2603:10a6:20b:43b::21) Precedence: bulk X-Mailing-List: imx@lists.linux.dev List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-MS-PublicTrafficType: Email X-MS-TrafficTypeDiagnostic: AM9PR04MB8604:EE_|PA4PR04MB9223:EE_ X-MS-Office365-Filtering-Correlation-Id: 614c56a8-9794-4446-cfa3-08dcecf88784 X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam: BCL:0;ARA:13230040|1800799024|376014|52116014|366016|7416014|921020|38350700014; X-Microsoft-Antispam-Message-Info: =?utf-8?q?FALXWATTvWfZnW85gcyaSfpE0ft3AVd?= =?utf-8?q?yFnSImz6UioIJKSdyoX+HxOqPG779usFR5t7wW6TfwBUO6OqGlWtt/sNKtJOqZ2nq?= =?utf-8?q?3i2Z/hJy31nQDWqT9ZPsv+SKcdKy0U+DUKnwM9BdxIA+CQXzm/2SOQFMscEMUvXC5?= =?utf-8?q?HSY2KOucM+5x1yZiry/qU+gE3k9uZH52wJZ+GKwIDfcfD1AHYUMHY50ns+qfX7hH8?= =?utf-8?q?7d76kv0DWO8ETusdDLyiEETqLoRGrXkEHDqcc0I7rqOwyBdzbsBMaeZQCVUW7S3Sm?= =?utf-8?q?dxOk1kQWySKUTXgX396m2bfCLIlbWtz6YJmtGmoRmVLZd8PdRa5anirAPHSefsNYx?= =?utf-8?q?tZqLyIsDxWfpehLOXWhqyD5ECAuK6aXRJDLOLPSFy4vw2V957Zu1xw4CZqE1jQF6D?= =?utf-8?q?mKNAlQ1BhH6DMvR9EL7S1oDT/2TAlKAg0ZmFhcB2ofClmGxdp5l3Ue3d7mgkmBxXm?= =?utf-8?q?6p74ZMi7O1uw/RUwIhqb8l+qiL7S/WUQHd6u8e8GgtDbM6AOuZceuGuUprJEeyHBp?= =?utf-8?q?lfOyekusW6Gozk4+r6sEnXV0JP3f4sXEJlHibUbA4ojSMy6S4qShXOg3ZXKgdqihn?= =?utf-8?q?wsqcShgBjog8pAnrq51NocimpWbWu3maYIalA7CIQ2/BrOg8xRoJA8yF3/S37G62o?= =?utf-8?q?5dpKW4yREpG5VsEGQzKh5BxcaUep56MDaPcTNsKuL9E/FhqyDQO+ymSJPzy1tZu2t?= =?utf-8?q?nN4iOC8Y57aaXFLesqAYsdlGpp9/v4N69Q7xpSNcjbAUvDpd18QvIuD7upi0CjdYv?= =?utf-8?q?Zi3PCZ24DS/dL4ZULYG6F4UMTzxPUYA05BisB+3NmBk63dGObGU+yifvfwylhLreV?= =?utf-8?q?xDIOi+6Ul+j8mXtwPY0Jhp5o89sXwauWj+3P6F+oFsvBttuVmuuCYE4e3QVUSySzS?= =?utf-8?q?sMgnpMgBkGR2z3d3xL2poGAr/5vY+VZp+tXrCjrtjkMiskYDntSvsYtTUnIC2ZIUi?= =?utf-8?q?XR2HAS5paxdPx38AvYqKRWjgQG+MZZ6Xb5cKszPetPL8qWCaro1mWq4ArTUj5AQ5P?= =?utf-8?q?1Z3GMd1spOXlwOtCFFrAba1oVKOXE6DMbXKY/Lj9p4oiw5NmCVmTjuAw1CbzyNsH7?= =?utf-8?q?nEpLJsTKP0xykvDZkceDSjbNFrz8pceIpkklXPByqzz6MX6pd+ZKI5nubX3lVDbQE?= =?utf-8?q?vlah9BQHOk5JNSKF8lU7Je2hjA6NHZD+MQXa5WEyMHa/hLWuQNcMemdasXjmfMGRw?= =?utf-8?q?t+y/auHluXeh8I4jt7Q36fNyV/ZIAa0DWDwu8pPmon4k5uiNI1IWucCNTYmOhZKCW?= =?utf-8?q?Bqs+VpJnJwptbAHJ6CnE5el2IzNA4de+ajw=3D=3D?= X-Forefront-Antispam-Report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:AM9PR04MB8604.eurprd04.prod.outlook.com;PTR:;CAT:NONE;SFS:(13230040)(1800799024)(376014)(52116014)(366016)(7416014)(921020)(38350700014);DIR:OUT;SFP:1101; X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1 X-MS-Exchange-AntiSpam-MessageData-0: =?utf-8?q?RUzJ31M/C2CsdoES7g0JjyQhKDmX?= =?utf-8?q?nWkGtyy36Od6PlzWkU7eBGx/KRXkcYtiozU3hI7CUmEuy1zdGRVXvtGWEpQYwe4k6?= =?utf-8?q?OXwkS4wNjOCSbcmbRx54N8CHH5RYumZbJrwSrQRzVhNIR2uqPHVuy1tjfHBJ70Kkt?= =?utf-8?q?MJPqfUnriq6naPjIou4tulY1j8IYQtIGwhp89VenveuMdQYa2sUVf/y6OZ138GbCL?= =?utf-8?q?OzbXxNElbo3FqibGfUR5KeC6YFVfLPYm/udywJewxl/FJwBXl0JDMDWtpKN5xZ0Lk?= =?utf-8?q?D2KkWb2DrBBbz9LwGRTkd+eU0/2WVwShn943hTaaqqh1Geom5gb8VM1jmhlCaq+Vs?= =?utf-8?q?SRpjSixGEaC3TXAIC5nCaqTR6tpB5yrjctQxAw9LNMcvQPZHqMcYR/JYlGrTZrCId?= =?utf-8?q?jtRSFRJNCzq9YpHX2mjOme+5rBQBoILgLsH08eBFM9GEfR37FDhoEf89wsr5VnPQr?= =?utf-8?q?InwGPm9Gum8fIuuFWap3Yp+1FhpWxDxIt4qvw/Kskf8r686Tq4zWsCcecLRqtfH/t?= =?utf-8?q?FghhYB3haW6K53SOFCFuo3bzNhVxDdFQSXt92TxlN3U3HGD17QsA3+Cu8vbIJjTxL?= =?utf-8?q?IVUN1Zz/RDpoxyouuKKCH7Qu4XLzE/m4AWmdCc1Xnmjwsr3s1FArcNGpBK1VI15FB?= =?utf-8?q?7YFwmBfVkZOFqsNwpgzl+kdIcOpYGDW34FHfA6x6U/+geu+HFMjpwi/I0WNZoh15G?= =?utf-8?q?VE5DCDM0+283ACRMrQz8LEX/PQsjsHqd0V4VH80pYuTrRJ6szkYuuLotakjpdB4RT?= =?utf-8?q?rz9xvRirlTLlkUzuxaTzCHrIWJDjQBgifYYAFujRHWbjjpQophtdLkfwgkNEggnf9?= =?utf-8?q?okY4lwEIkkkKgOsMg3mR24qMmDmP8R0B19lRJA6+QPfG2OfR01pLeNfAhx0Mq5+xW?= =?utf-8?q?lfp8IvLLgVbwgJfCMghyWrXk4zKyVtWckPnS/TdcFoIqHtqftundC/YWgT+uLL5qG?= =?utf-8?q?1TD7sKqolbmNV0+zm6A32e0xQDJKmq7L1MYUCyTlnSfuRHY2YxBflM4e6UDvOxnT3?= =?utf-8?q?13q99BFt+PEOzV0IgS/yPNKdTcd5hMSMV1OAszekdhjCjvSCE+cQKX/NjlZslXp+J?= =?utf-8?q?hU9p7gkTCqO0RcUV4wI3/DGCVdwRcB6UrLSJHm6p1QPHIdSJPPn1BsZt9T4K9yXNP?= =?utf-8?q?7+onqbTvahJqqg8CNGXJN6RXh69m/DblVewMZ7CfuCbzesrfnjX3K0Y0FlhoJ5GOA?= =?utf-8?q?DLh+ABcQ1y+CVelIjO1Bl1opiYJ2WabdOef6mYMJLH1z1aRUQcNECk9tAiNm3ZBrH?= =?utf-8?q?g0LAa9ukIjin3Uqcqw7oR06zNPo9avWH7+JBwh8kOVmn0wNwsRsiE7ElxaKJS6XIb?= =?utf-8?q?Fka8Z9vkzUR800xr9rO66YeArqlkJEBur4xhd5tAUQzTJm2jawC8dKeNOn5O7zWgZ?= =?utf-8?q?qjsweWK9P+t5IGCPO8DFLxkE5UrtQQMINCs75CNujiXIwuUxkgGlC+evC+pM/tW3o?= =?utf-8?q?WdGsttqfrzyQ3b4sPWT4XupFxyV08d2A0bb8NlVQfmjKiNdX5uxtjz9yya//CVLvG?= =?utf-8?q?IEVotn8w4WZo?= X-OriginatorOrg: nxp.com X-MS-Exchange-CrossTenant-Network-Message-Id: 614c56a8-9794-4446-cfa3-08dcecf88784 X-MS-Exchange-CrossTenant-AuthSource: AM9PR04MB8604.eurprd04.prod.outlook.com X-MS-Exchange-CrossTenant-AuthAs: Internal X-MS-Exchange-CrossTenant-OriginalArrivalTime: 15 Oct 2024 09:05:35.0436 (UTC) X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted X-MS-Exchange-CrossTenant-Id: 686ea1d3-bc2b-4c6f-a92c-d99c5c301635 X-MS-Exchange-CrossTenant-MailboxType: HOSTED X-MS-Exchange-CrossTenant-UserPrincipalName: 1jEapWi1WoUKkP2X2xqJ5EPbdcglHNyxdgStp0avvXtQTj+5SzGvvAK66XmNiqY/b8mKk8kI+nA2LCKxh03lMQ== X-MS-Exchange-Transport-CrossTenantHeadersStamped: PA4PR04MB9223 Documents i.MX SoC's Service layer and C_DEV driver for selected SoC(s) that contains the NXP hardware IP(s) for Secure Enclaves(se) like: - NXP EdgeLock Enclave on i.MX93 & i.MX8ULP Signed-off-by: Pankaj Gupta --- .../driver-api/firmware/other_interfaces.rst | 121 +++++++++++++++++++++ 1 file changed, 121 insertions(+) diff --git a/Documentation/driver-api/firmware/other_interfaces.rst b/Documentation/driver-api/firmware/other_interfaces.rst index 06ac89adaafb..a3a95b54a174 100644 --- a/Documentation/driver-api/firmware/other_interfaces.rst +++ b/Documentation/driver-api/firmware/other_interfaces.rst @@ -49,3 +49,124 @@ of the requests on to a secure monitor (EL3). .. kernel-doc:: drivers/firmware/stratix10-svc.c :export: + +NXP Secure Enclave Firmware Interface +===================================== + +Introduction +------------ +The NXP's i.MX HW IP like EdgeLock Enclave, V2X etc., creates an embedded secure +enclave within the SoC boundary to enable features like + - Hardware Security Module (HSM) + - Security Hardware Extension (SHE) + - Vehicular to Anything (V2X) + +Each of the above feature is enabled through dedicated NXP H/W IP on the SoC. +On a single SoC, multiple hardware IP (or can say more than one secure enclave) +can exist. + +NXP SoCs enabled with the such secure enclaves(SEs) IPs are: +i.MX93, i.MX8ULP + +To communicate with one or more co-existing SE(s) on SoC, there is/are dedicated +messaging units(MU) per SE. Each co-existing SE can have one or multiple exclusive +MUs, dedicated to itself. None of the MU is shared between two SEs. +Communication of the MU is realized using the Linux mailbox driver. + +NXP Secure Enclave(SE) Interface +-------------------------------- +Although MU(s) is/are not shared between SE(s). But for SoC like i.MX95 which has +multiple SE(s) like HSM, V2X-HSM, V2X-SHE; all the SE(s) and their interfaces 'se-if' +that is/are dedicated to a particular SE will be enumerated and provisioned using the +single compatible node("fsl,imx95-se"). + +Each 'se-if' comprise of twp layers: +- (C_DEV Layer) User-Space software-access interface. +- (Service Layer) OS-level software-access interface. + + +--------------------------------------------+ + | Character Device(C_DEV) | + | | + | +---------+ +---------+ +---------+ | + | | misc #1 | | misc #2 | ... | misc #n | | + | | dev | | dev | | dev | | + | +---------+ +---------+ +---------+ | + | +-------------------------+ | + | | Misc. Dev Synchr. Logic | | + | +-------------------------+ | + | | + +--------------------------------------------+ + + +--------------------------------------------+ + | Service Layer | + | | + | +-----------------------------+ | + | | Message Serialization Logic | | + | +-----------------------------+ | + | +---------------+ | + | | imx-mailbox | | + | | mailbox.c | | + | +---------------+ | + | | + +--------------------------------------------+ + +- service layer: + This layer is responsible for ensuring the communication protocol that is defined + for communication with firmware. + + FW Communication protocol ensures two things: + - Serializing the messages to be sent over an MU. + + - FW can handle one command message at a time. + +- c_dev: + This layer offers character device contexts, created as '/dev/_mux_chx'. + Using these multiple device contexts that are getting multiplexed over a single MU, + userspace application(s) can call fops like write/read to send the command message, + and read back the command response message to/from Firmware. + fops like read & write use the above defined service layer API(s) to communicate with + Firmware. + + Misc-device(/dev/_mux_chn) synchronization protocol: + + Non-Secure + Secure + | + | + +---------+ +-------------+ | + | se_fw.c +<---->+imx-mailbox.c| | + | | | mailbox.c +<-->+------+ +------+ + +---+-----+ +-------------+ | MU X +<-->+ ELE | + | +------+ +------+ + +----------------+ | + | | | + v v | + logical logical | + receiver waiter | + + + | + | | | + | | | + | +----+------+ | + | | | | + | | | | + device_ctx device_ctx device_ctx | + | + User 0 User 1 User Y | + +------+ +------+ +------+ | + |misc.c| |misc.c| |misc.c| | + kernel space +------+ +------+ +------+ | + | + +------------------------------------------------------ | + | | | | + userspace /dev/ele_muXch0 | | | + /dev/ele_muXch1 | | + /dev/ele_muXchY | + | + +When a user sends a command to the firmware, it registers its device_ctx +as waiter of a response from firmware. + +Enclave's Firmware owns the storage management, over Linux filesystem. +For this c_dev provisions a dedicated slave device called "receiver". + +.. kernel-doc:: drivers/firmware/imx/se_fw.c + :export: