From: Jorge Ramirez-Ortiz <jorge.ramirez@oss.qualcomm.com>
To: jorge.ramirez@oss.qualcomm.com, stanleyjhu@google.com,
beanhuo@micron.com, beanhuo@iokpp.de,
James.Bottomley@hansenpartnership.com,
martin.petersen@oracle.com, alim.akhtar@samsung.com,
avri.altman@wdc.com, bvanassche@acm.org,
can.guo@oss.qualcomm.com, sumit.garg@oss.qualcomm.com,
jenswi@kernel.org
Cc: linux-scsi@vger.kernel.org, linux-kernel@vger.kernel.org,
op-tee@lists.trustedfirmware.org
Subject: [PATCH v5 2/2] ufs: rpmb: use a fixed-length RPMB dev_id
Date: Mon, 31 Aug 2026 17:48:01 +0200 [thread overview]
Message-ID: <20260831154804.719528-3-jorge.ramirez@oss.qualcomm.com> (raw)
In-Reply-To: <20260831154804.719528-1-jorge.ramirez@oss.qualcomm.com>
The RPMB authentication key is derived from the dev_id handed to the
RPMB subsystem. OP-TEE implements the eMMC RPMB flow, where the dev_id
is the eMMC CID: a fixed 16-byte value the key derivation depends on.
The UFS RPMB id is "<device_id>-R<region>", which is variable length
and longer than 16 bytes. Handing it to the RPMB subsystem as-is would
tie the derived key to a length OP-TEE does not expect and diverge from
the fixed-CID eMMC ABI, forcing OP-TEE to be taught about
variable-length UFS ids.
A fixed 16-byte dev_id is needed so the derived key stays stable and
unique per region while matching the eMMC CID layout OP-TEE relies on,
keeping the key-derivation ABI identical with no OP-TEE change. The
reduction to a fixed 16 bytes must also be reproducible by the
bootloaders (such as U-Boot) that derive the same dev_id.
Signed-off-by: Jorge Ramirez-Ortiz <jorge.ramirez@oss.qualcomm.com>
Reviewed-by: Bean Huo <beanhuo@micron.com>
Reviewed-by: Stanley Jhu <stanleyjhu@google.com>
---
drivers/ufs/Kconfig | 1 +
drivers/ufs/core/ufs-rpmb.c | 9 +++++++--
2 files changed, 8 insertions(+), 2 deletions(-)
diff --git a/drivers/ufs/Kconfig b/drivers/ufs/Kconfig
index f662e7ce71f1..b62c00e7ff06 100644
--- a/drivers/ufs/Kconfig
+++ b/drivers/ufs/Kconfig
@@ -7,6 +7,7 @@ menuconfig SCSI_UFSHCD
tristate "Universal Flash Storage Controller"
depends on SCSI && SCSI_DMA
depends on RPMB || !RPMB
+ select CRYPTO_LIB_BLAKE2B if RPMB
select PM_DEVFREQ
select DEVFREQ_GOV_SIMPLE_ONDEMAND
select NLS
diff --git a/drivers/ufs/core/ufs-rpmb.c b/drivers/ufs/core/ufs-rpmb.c
index 79e6cd2b20a0..cb3ac23fa01a 100644
--- a/drivers/ufs/core/ufs-rpmb.c
+++ b/drivers/ufs/core/ufs-rpmb.c
@@ -10,6 +10,7 @@
* Can Guo <can.guo@oss.qualcomm.com>
*/
+#include <crypto/blake2b.h>
#include <linux/module.h>
#include <linux/device.h>
#include <linux/kernel.h>
@@ -21,6 +22,7 @@
#include <linux/unaligned.h>
#include "ufshcd-priv.h"
+#define UFS_RPMB_ID_LEN 16 /* Match eMMC CID Length */
#define UFS_RPMB_UA_RETRIES 3 /* Retries for the power-on UNIT ATTENTION */
#define UFS_RPMB_SEC_PROTOCOL 0xEC /* JEDEC UFS application */
#define UFS_RPMB_SEC_PROTOCOL_ID 0x01 /* JEDEC UFS RPMB protocol ID, CDB byte3 */
@@ -153,6 +155,7 @@ static void ufs_rpmb_device_release(struct device *dev)
int ufs_rpmb_probe(struct ufs_hba *hba)
{
struct ufs_rpmb_dev *ufs_rpmb, *it, *tmp;
+ u8 dev_id[UFS_RPMB_ID_LEN];
struct rpmb_dev *rdev;
char *cid = NULL;
int region;
@@ -213,8 +216,10 @@ int ufs_rpmb_probe(struct ufs_hba *hba)
goto err_out;
}
- descr.dev_id = cid;
- descr.dev_id_len = strlen(cid);
+ blake2b(NULL, 0, cid, strlen(cid), dev_id, UFS_RPMB_ID_LEN);
+
+ descr.dev_id = dev_id;
+ descr.dev_id_len = UFS_RPMB_ID_LEN;
descr.capacity = cap;
/* Register RPMB device */
--
2.54.0
WARNING: multiple messages have this Message-ID (diff)
From: Jorge Ramirez-Ortiz via OP-TEE <op-tee@lists.trustedfirmware.org>
To: jorge.ramirez@oss.qualcomm.com, stanleyjhu@google.com,
beanhuo@micron.com, beanhuo@iokpp.de,
James.Bottomley@hansenpartnership.com,
martin.petersen@oracle.com, alim.akhtar@samsung.com,
avri.altman@wdc.com, bvanassche@acm.org,
can.guo@oss.qualcomm.com, sumit.garg@oss.qualcomm.com,
jenswi@kernel.org
Cc: linux-scsi@vger.kernel.org, linux-kernel@vger.kernel.org,
op-tee@lists.trustedfirmware.org
Subject: [PATCH v5 2/2] ufs: rpmb: use a fixed-length RPMB dev_id
Date: Mon, 31 Aug 2026 17:48:01 +0200 [thread overview]
Message-ID: <20260831154804.719528-3-jorge.ramirez@oss.qualcomm.com> (raw)
In-Reply-To: <20260831154804.719528-1-jorge.ramirez@oss.qualcomm.com>
The RPMB authentication key is derived from the dev_id handed to the
RPMB subsystem. OP-TEE implements the eMMC RPMB flow, where the dev_id
is the eMMC CID: a fixed 16-byte value the key derivation depends on.
The UFS RPMB id is "<device_id>-R<region>", which is variable length
and longer than 16 bytes. Handing it to the RPMB subsystem as-is would
tie the derived key to a length OP-TEE does not expect and diverge from
the fixed-CID eMMC ABI, forcing OP-TEE to be taught about
variable-length UFS ids.
A fixed 16-byte dev_id is needed so the derived key stays stable and
unique per region while matching the eMMC CID layout OP-TEE relies on,
keeping the key-derivation ABI identical with no OP-TEE change. The
reduction to a fixed 16 bytes must also be reproducible by the
bootloaders (such as U-Boot) that derive the same dev_id.
Signed-off-by: Jorge Ramirez-Ortiz <jorge.ramirez@oss.qualcomm.com>
Reviewed-by: Bean Huo <beanhuo@micron.com>
Reviewed-by: Stanley Jhu <stanleyjhu@google.com>
---
drivers/ufs/Kconfig | 1 +
drivers/ufs/core/ufs-rpmb.c | 9 +++++++--
2 files changed, 8 insertions(+), 2 deletions(-)
diff --git a/drivers/ufs/Kconfig b/drivers/ufs/Kconfig
index f662e7ce71f1..b62c00e7ff06 100644
--- a/drivers/ufs/Kconfig
+++ b/drivers/ufs/Kconfig
@@ -7,6 +7,7 @@ menuconfig SCSI_UFSHCD
tristate "Universal Flash Storage Controller"
depends on SCSI && SCSI_DMA
depends on RPMB || !RPMB
+ select CRYPTO_LIB_BLAKE2B if RPMB
select PM_DEVFREQ
select DEVFREQ_GOV_SIMPLE_ONDEMAND
select NLS
diff --git a/drivers/ufs/core/ufs-rpmb.c b/drivers/ufs/core/ufs-rpmb.c
index 79e6cd2b20a0..cb3ac23fa01a 100644
--- a/drivers/ufs/core/ufs-rpmb.c
+++ b/drivers/ufs/core/ufs-rpmb.c
@@ -10,6 +10,7 @@
* Can Guo <can.guo@oss.qualcomm.com>
*/
+#include <crypto/blake2b.h>
#include <linux/module.h>
#include <linux/device.h>
#include <linux/kernel.h>
@@ -21,6 +22,7 @@
#include <linux/unaligned.h>
#include "ufshcd-priv.h"
+#define UFS_RPMB_ID_LEN 16 /* Match eMMC CID Length */
#define UFS_RPMB_UA_RETRIES 3 /* Retries for the power-on UNIT ATTENTION */
#define UFS_RPMB_SEC_PROTOCOL 0xEC /* JEDEC UFS application */
#define UFS_RPMB_SEC_PROTOCOL_ID 0x01 /* JEDEC UFS RPMB protocol ID, CDB byte3 */
@@ -153,6 +155,7 @@ static void ufs_rpmb_device_release(struct device *dev)
int ufs_rpmb_probe(struct ufs_hba *hba)
{
struct ufs_rpmb_dev *ufs_rpmb, *it, *tmp;
+ u8 dev_id[UFS_RPMB_ID_LEN];
struct rpmb_dev *rdev;
char *cid = NULL;
int region;
@@ -213,8 +216,10 @@ int ufs_rpmb_probe(struct ufs_hba *hba)
goto err_out;
}
- descr.dev_id = cid;
- descr.dev_id_len = strlen(cid);
+ blake2b(NULL, 0, cid, strlen(cid), dev_id, UFS_RPMB_ID_LEN);
+
+ descr.dev_id = dev_id;
+ descr.dev_id_len = UFS_RPMB_ID_LEN;
descr.capacity = cap;
/* Register RPMB device */
--
2.54.0
next prev parent reply other threads:[~2026-08-31 15:48 UTC|newest]
Thread overview: 9+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-31 15:47 [PATCH v5 0/2] ufs: rpmb: make RPMB usable with OP-TEE key derivation Jorge Ramirez-Ortiz
2026-08-31 15:47 ` Jorge Ramirez-Ortiz via OP-TEE
2026-08-31 15:48 ` [PATCH v5 1/2] ufs: rpmb: retry power-on UNIT ATTENTION on the RPMB WLUN Jorge Ramirez-Ortiz
2026-08-31 15:48 ` Jorge Ramirez-Ortiz via OP-TEE
2026-08-31 15:48 ` Jorge Ramirez-Ortiz [this message]
2026-08-31 15:48 ` [PATCH v5 2/2] ufs: rpmb: use a fixed-length RPMB dev_id Jorge Ramirez-Ortiz via OP-TEE
2026-08-31 18:58 ` sashiko-bot
2026-09-10 1:55 ` [PATCH v5 0/2] ufs: rpmb: make RPMB usable with OP-TEE key derivation Martin K. Petersen (Oracle) via OP-TEE
2026-09-10 1:55 ` Martin K. Petersen (Oracle)
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260831154804.719528-3-jorge.ramirez@oss.qualcomm.com \
--to=jorge.ramirez@oss.qualcomm.com \
--cc=James.Bottomley@hansenpartnership.com \
--cc=alim.akhtar@samsung.com \
--cc=avri.altman@wdc.com \
--cc=beanhuo@iokpp.de \
--cc=beanhuo@micron.com \
--cc=bvanassche@acm.org \
--cc=can.guo@oss.qualcomm.com \
--cc=jenswi@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-scsi@vger.kernel.org \
--cc=martin.petersen@oracle.com \
--cc=op-tee@lists.trustedfirmware.org \
--cc=stanleyjhu@google.com \
--cc=sumit.garg@oss.qualcomm.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.