All of lore.kernel.org
 help / color / mirror / Atom feed
From: Jorge Ramirez <jorge.ramirez@oss.qualcomm.com>
To: Neil Armstrong <neil.armstrong@linaro.org>
Cc: Jorge Ramirez <jorge.ramirez@oss.qualcomm.com>,
	Neha Malcom Francis <n-francis@ti.com>,
	trini@konsulko.com, jens.wiklander@linaro.org,
	ilias.apalodimas@linaro.org, peng.fan@nxp.com,
	jh80.chung@samsung.com, bhupesh.linux@gmail.com,
	xypron.glpk@gmx.de, marek.vasut+renesas@mailbox.org,
	igor.belwon@mentallysanemainliners.org, shawn.lin@rock-chips.com,
	tuyen.dang.xa@renesas.com, yoshihiro.shimoda.uh@renesas.com,
	padmarao.begari@amd.com, macpaul.lin@mediatek.com,
	jstephan@baylibre.com, hayashi.kunihiko@socionext.com,
	j-mcarthur@ti.com, venkyada@qti.qualcomm.com,
	dlechner@baylibre.com, u-boot@lists.denx.de,
	u-boot@lists.u-boot-project.org
Subject: Re: [PATCH v4 0/5] ufs: rpmb: route OP-TEE RPMB secure storage over UFS
Date: Tue, 8 Sep 2026 11:47:39 +0200	[thread overview]
Message-ID: <ap_Zuydj9tCPc2w8@trex> (raw)
In-Reply-To: <d191ab8c-3c5f-46c4-8278-9644a508470b@linaro.org>

On 08/09/26 09:43:14, neil.armstrong@linaro.org wrote:
> On 9/7/26 10:40, Jorge Ramirez wrote:
> > On 07/09/26 12:47:39, Neha Malcom Francis wrote:
> > > Hi Jorge
> > > 
> > > On 07/09/26 12:38, Jorge Ramirez wrote:
> > > > On 27/08/26 11:01:41, Jorge Ramirez wrote:
> > > > > On 21/08/26 16:02:18, Jorge Ramirez wrote:
> > > > > > On 17/08/26 16:38:40, Jorge Ramirez wrote:
> > > > > > > On 07/08/26 16:01:05, Jorge Ramirez-Ortiz wrote:
> > > > > > > > OP-TEE secure storage (CFG_RPMB_FS) relies on an RPMB partition, but
> > > > > > > > U-Boot's OP-TEE RPMB supplicant only speaks the legacy single-command
> > > > > > > > interface, which is bound to eMMC. SoCs that are UFS-only and have no
> > > > > > > > eMMC (for example the Qualcomm SA8775P) therefore cannot back OP-TEE
> > > > > > > > secure storage from U-Boot today. This series adds that support.
> > > > > > > > 
> > > > > > > > It introduces the transport-agnostic OP-TEE RPMB "subsystem" interface
> > > > > > > > (PROBE_RESET / PROBE_NEXT / FRAMES), where the normal world enumerates
> > > > > > > > the RPMB device and reports its kind, size and CID, then carries the
> > > > > > > > signed frames. The legacy eMMC supplicant is preserved unchanged, only
> > > > > > > > renamed to rpmb_emmc.c, with the new UFS backend added as a separate
> > > > > > > > rpmb_ufs.c; the two are mutually exclusive via Kconfig (SUPPORT_UFS_RPMB
> > > > > > > > depends on !SUPPORT_EMMC_RPMB) because the OP-TEE supplicant handles a
> > > > > > > > single RPMB transport. The subsystem interface is UFS-only for now; eMMC
> > > > > > > > can be migrated onto it later as the legacy path is retired.
> > > > > > > > 
> > > > > > > > On top of that it adds a UFS RPMB transport that moves JEDEC RPMB frames
> > > > > > > > to and from the RPMB Well-Known LUN using SCSI SECURITY PROTOCOL IN/OUT.
> > > > > > > > The per-region 16-byte CID is derived by BLAKE2b-hashing the exact
> > > > > > > > device-id string the Linux kernel builds (ufshcd_create_device_id()
> > > > > > > > plus a "-R<region>" suffix), so OP-TEE derives an RPMB key that matches
> > > > > > > > the one Linux would use.
> > > > > > > > 
> > > > > > > > The first patch is a standalone UFS descriptor fix the RPMB path depends
> > > > > > > > on (UTF-16BE string decoding); the transport patches also include a
> > > > > > > > power-on UNIT ATTENTION retry and a DMA-alignment bounce for the RPMB
> > > > > > > > WLUN.
> > > > > > > > 
> > > > > > > > Note: reading UFS descriptors reliably also requires the descriptor
> > > > > > > > data-segment cache-invalidation fix, which has already been posted and
> > > > > > > > merged separately, so this series is based on top of it.
> > > > > > > > 
> > > > > > > > Tested on the Qualcomm IQ-9075-EVK (SA8775P): OP-TEE with CFG_RPMB_FS
> > > > > > > > programs the RPMB key through U-Boot and reads/writes secure-storage
> > > > > > > > objects, with the derived CID matching the Linux UFS device_id ABI.
> > > > > > > > 
> > > > > > > > Dependencies:
> > > > > > > > Linux kernel:
> > > > > > > >   https://lore.kernel.org/linux-scsi/20260716083728.2226422-1-jorge.ramirez@oss.qualcomm.com/
> > > > > > > > Op-tee
> > > > > > > >   https://github.com/OP-TEE/optee_os/pull/7881
> > > > > > > > 
> > > > > > > > v4:
> > > > > > > >   - ufs: decode string descriptors: dropped the in-place
> > > > > > > >     ufshcd_str_desc_to_cpu() byte-swap helper; instead added an endian
> > > > > > > >     argument to utf16_to_utf8() (UTF16_HOST/LITTLE/BIG_ENDIAN) and decode
> > > > > > > >     with UTF16_BIG_ENDIAN, mirroring the kernel's utf16s_to_utf8s().
> > > > > > > >     Existing EFI callers pass UTF16_HOST_ENDIAN.
> > > > > > > >   - ufs: RPMB transport: build the SECURITY PROTOCOL CDB with
> > > > > > > >     put_unaligned_be16()/put_unaligned_be32(); drop the
> > > > > > > >     rpmb_frame_request() helper in favour of get_unaligned_be16(); move
> > > > > > > >     ufs_rpmb_read_geometry() to the patch that first uses it so it is not
> > > > > > > >     an unused static function during git bisect.
> > > > > > > >   - ufs: per-region CID/size: reject an out-of-range device-reported
> > > > > > > >     logical block size before shifting and split the size computation into
> > > > > > > >     separate statements for readability; order <u-boot/...> after
> > > > > > > >     <linux/...>; note that the serial hex encoding matches the kernel
> > > > > > > >     device-id ABI.
> > > > > > > > 
> > > > > > > 
> > > > > > > any further comments, is it ok to merge?
> > > > > > > 
> > > > > > 
> > > > > > EOW reminder - this has been pending for a long while
> > > > > 
> > > > > 
> > > > > anyone care to comment please?
> > > > 
> > > > 
> > > > kernel changes accepted and op-tee changes merged.
> > > > Just this one pending with no comments for nearly a month.
> > > > 
> > > > maybe we can merge?
> > > > 
> > > > thanks
> > > > Jorge
> > > > 
> > > > 
> > > > 
> > > 
> > > Looks like you're sending to the old mailing list instead of
> > > u-boot@lists.u-boot-project.org
> > > 
> > 
> > hi Neah,
> > 
> > ah interesting, maybe that explains it depending on people'w workflows: I see it hasnt landed on u-boot lore's.
> > 
> > I just run get_maintainers.pl and the recommended list is
> > 
> > jramirez@trex:u-boot (ufs-rpmb.v4 $) $ ./scripts/get_maintainer.pl drivers/tee/optee/Makefile
> > Jens Wiklander <jens.wiklander@linaro.org> (maintainer:TEE)
> > Ilias Apalodimas <ilias.apalodimas@linaro.org> (maintainer:TEE,commit_signer:2/3=67%)
> > Tom Rini <trini@konsulko.com> (maintainer:THE REST,authored:1/3=33%,added_lines:1/3=33%,removed_lines:1/2=50%)
> > Jorge Ramirez-Ortiz <jorge.ramirez@oss.qualcomm.com> (commit_signer:2/3=67%,authored:2/3=67%,added_lines:2/3=67%,removed_lines:1/2=50%)
> > u-boot@lists.denx.de (open list)...
> > 
> > still I can see it on patchworks with Neil being the gatekeeper.
> > 
> > I hope he can work from there without me having to resend
> 
> I'd like some review on the optee side before picking the UFS changes, which are fine.
> 
> I'm worried about the clash with Jan's changeset on the optee side.
> 
> Neil


adding the correct mailing list now

> 
> > 
> > thanks for the heads up though!
> > Jorge
> > 
> > 
> > > --
> > > Thanking You
> > > Neha Malcom Francis
> > > 
> 

  parent reply	other threads:[~2026-09-08  9:47 UTC|newest]

Thread overview: 8+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
     [not found] <20260807140119.324858-1-jorge.ramirez@oss.qualcomm.com>
     [not found] ` <aoMc8FDcE0bYGZch@trex>
     [not found]   ` <aohaajBy5e6A4gFL@trex>
     [not found]     ` <ao_89VbNNE1QTX6a@trex>
     [not found]       ` <ap5i9edBJ7sNVmax@trex>
     [not found]         ` <61fd743d-c722-42b8-a754-175715a4bcbe@ti.com>
     [not found]           ` <ap54m53aTMXhIso3@trux>
2026-09-07 16:13             ` [PATCH v4 0/5] ufs: rpmb: route OP-TEE RPMB secure storage over UFS Tom Rini
2026-09-07 19:16               ` Jorge Ramirez
2026-09-07 19:36                 ` Tom Rini
2026-09-07 21:28                   ` Jorge Ramirez
2026-09-08  7:30                 ` Peter Robinson
     [not found]             ` <d191ab8c-3c5f-46c4-8278-9644a508470b@linaro.org>
2026-09-08  9:47               ` Jorge Ramirez [this message]
     [not found] ` <20260807140119.324858-2-jorge.ramirez@oss.qualcomm.com>
2026-09-09 16:11   ` [PATCH v4 1/5] ufs: decode string descriptors as UTF-16 big-endian David Lechner
2026-09-09 16:13     ` David Lechner

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=ap_Zuydj9tCPc2w8@trex \
    --to=jorge.ramirez@oss.qualcomm.com \
    --cc=bhupesh.linux@gmail.com \
    --cc=dlechner@baylibre.com \
    --cc=hayashi.kunihiko@socionext.com \
    --cc=igor.belwon@mentallysanemainliners.org \
    --cc=ilias.apalodimas@linaro.org \
    --cc=j-mcarthur@ti.com \
    --cc=jens.wiklander@linaro.org \
    --cc=jh80.chung@samsung.com \
    --cc=jstephan@baylibre.com \
    --cc=macpaul.lin@mediatek.com \
    --cc=marek.vasut+renesas@mailbox.org \
    --cc=n-francis@ti.com \
    --cc=neil.armstrong@linaro.org \
    --cc=padmarao.begari@amd.com \
    --cc=peng.fan@nxp.com \
    --cc=shawn.lin@rock-chips.com \
    --cc=trini@konsulko.com \
    --cc=tuyen.dang.xa@renesas.com \
    --cc=u-boot@lists.denx.de \
    --cc=u-boot@lists.u-boot-project.org \
    --cc=venkyada@qti.qualcomm.com \
    --cc=xypron.glpk@gmx.de \
    --cc=yoshihiro.shimoda.uh@renesas.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.