All of lore.kernel.org
 help / color / mirror / Atom feed
From: Yeoreum Yun <yeoreum.yun@arm.com>
To: Kohei Enju <enju.kohei@fujitsu.com>
Cc: Yeoreum Yun <yeoreum.yun@arm.com>,
	linux-arm-kernel@lists.infradead.org,
	linux-kernel@vger.kernel.org,
	Catalin Marinas <catalin.marinas@arm.com>,
	Will Deacon <will@kernel.org>, Jason Gunthorpe <jgg@ziepe.ca>,
	Suzuki Poulose <suzuki.poulose@arm.com>,
	Steven Price <steven.price@arm.com>,
	Sami Mujawar <sami.mujawar@arm.com>,
	thuth@redhat.com
Subject: Re: [PATCH v2 1/3] arm64: rsi: Add helpers for Arm CCA measurement register operations
Date: Wed, 30 Sep 2026 06:13:35 +0100	[thread overview]
Message-ID: <aryafzI-M06aZ4bZ@e129823.arm.com> (raw)
In-Reply-To: <arxrOt1HEYeG6GJx@FCCLS0092175.localdomain>

> On 09/29 17:57, Yeoreum Yun wrote:
> > From: Sami Mujawar <sami.mujawar@arm.com>
> > 
> > Add static inline helper functions to support reading the Realm
> > Initial Measurement (RIM) and reading/extending the Realm
> > Extensible Measurement (REM) registers.
> > 
> > The indices of the Arm CCA measurement registers, as defined by
> > the Realm Management Monitor specification, are as follows:
> >     Index    Register
> >     0        RIM
> >     1 - 4    REM[0 - 3]
> > 
> > The rsi_measurement_extend() function allows extending REM[0–3]
> > registers with a caller-provided digest (up to 64 bytes).
> > Index 0 (RIM) is read-only and cannot be extended.
> > 
> > The rsi_measurement_read() function allows reading measurement
> > values from RIM (index 0) or REM[0–3] (indices 1–4). The returned
> > digest is expected to be 64 bytes.
> > 
> > Signed-off-by: Sami Mujawar <sami.mujawar@arm.com>
> > ---
> >  include/linux/arm-rsi-cmds.h | 105 ++++++++++++++++++++++++++++++++++++++++++-
> >  1 file changed, 104 insertions(+), 1 deletion(-)
> > 
> > diff --git a/include/linux/arm-rsi-cmds.h b/include/linux/arm-rsi-cmds.h
> > index 3f7a6a833993..608343266d81 100644
> > --- a/include/linux/arm-rsi-cmds.h
> > +++ b/include/linux/arm-rsi-cmds.h
> > @@ -1,6 +1,6 @@
> >  /* SPDX-License-Identifier: GPL-2.0-only */
> >  /*
> > - * Copyright (C) 2023 ARM Ltd.
> > + * Copyright (C) 2023 - 2025 ARM Ltd.
> >   */
> >  
> >  #ifndef __LINUX_ARM_RSI_CMDS_H_
> > @@ -36,6 +36,26 @@ static inline bool is_realm_world(void) { return false; }
> >  #define RSI_GRANULE_SHIFT		12
> >  #define RSI_GRANULE_SIZE		(_AC(1, UL) << RSI_GRANULE_SHIFT)
> >  
> > +/*
> > + * Maximum measurement data size in bytes.
> > + * According to the RMM Specification, the width of the RmmRealmMeasurement type
> > + * is 512 bits.
> > + */
> > +#define RSI_MAX_MEASUREMENT_DATA_SIZE_BYTES  64
> > +
> > +/*
> > + * Indices for the Realm Initial Measurement register (RIM) and the Realm
> > + * Extensible Measurement registers (REMs).
> > + * According to the RMM Specification, Realm attributes of a Realm include
> > + * an array of measurement values. The first entry in this array is a RIM.
> > + * The remaining entries in this array are REMs.
> > + */
> > +#define RSI_INDEX_RIM		0
> > +#define RSI_INDEX_REM0		1
> > +#define RSI_INDEX_REM1		2
> > +#define RSI_INDEX_REM2		3
> > +#define RSI_INDEX_REM3		4
> > +
> >  enum ripas {
> >  	RSI_RIPAS_EMPTY = 0,
> >  	RSI_RIPAS_RAM = 1,
> > @@ -236,4 +256,87 @@ static inline unsigned long rsi_attestation_token_continue(phys_addr_t granule,
> >  	return res.a0;
> >  }
> >  
> > +/**
> > + * rsi_measurement_extend - Extend the measurement value to the Realm Extensible
> > + * Measurement (REM).
> > + *
> > + * @idx:		Index of the REM register.
> > + *				Where:
> > + *				Index	Register
> > + *				1 - 4	REM[0-3]
> > + * @digest:		The digest data to be extended.
> > + * @digest_size:	Size of the digest data in bytes.
> > + *
> > + * Returns:
> > + *  On success, returns RSI_SUCCESS.
> > + *  Otherwise, -EINVAL
> > + */
> > +static inline unsigned long rsi_measurement_extend(u32 idx,
> > +						   const u8 *digest,
> > +						   unsigned long digest_size)
> > +{
> > +	struct arm_smccc_1_2_regs regs = { 0 };
> > +
> > +	/*
> > +	 * Index 0 is for RIM (which is Read Only), while
> > +	 * REM[0-3] are indexed from 1 - 4.
> > +	 * The digest size can be at the most 64 bytes.
> > +	 */
> > +	if (!digest || idx < RSI_INDEX_REM0 || idx > RSI_INDEX_REM3 ||
> > +	    digest_size == 0 || digest_size > RSI_MAX_MEASUREMENT_DATA_SIZE_BYTES)
> > +		return -EINVAL;
> > +
> > +	regs.a0 = SMC_RSI_MEASUREMENT_EXTEND;
> > +	regs.a1 = idx;
> > +	regs.a2 = digest_size;
> > +	memcpy(&regs.a3, digest, digest_size);
> 
> With CONFIG_FORTIFY_SOURCE=y, FORTIFY reports the following warning for
> this memcpy:
> 
>   [  899.918673] ------------[ cut here ]------------
>   [  899.918806] memcpy: detected field-spanning write (size 32) of single field "&regs.a3" at ./include/linux/arm-rsi-cmds.h:292 (size 8)
>   [  899.919277] WARNING: ./include/linux/arm-rsi-cmds.h:292 at rsi_measurement_extend+0x104/0x118, CPU#0: dd/123
>   [  900.672180] Modules linked in:
>   [  900.769378] CPU: 0 UID: 0 PID: 123 Comm: dd Not tainted 7.3.0-rc4+ #6 PREEMPT(full)
>   [  901.034515] Hardware name: linux,dummy-virt (DT)
>   [  901.194939] pstate: 61402005 (nZCv daif +PAN -UAO -TCO +DIT -SSBS BTYPE=--)
>   [  901.390491] pc : rsi_measurement_extend+0x104/0x118
>   [  901.530657] lr : rsi_measurement_extend+0x104/0x118
>   [...]
>   [  903.770326] Call trace:
>   [  903.893102]  rsi_measurement_extend+0x104/0x118 (P)
>   [  904.056234]  arm_cca_mr_extend+0x40/0x58
>   [  904.270991]  tm_digest_write+0x90/0x1d8
>   [  904.439429]  sysfs_kf_bin_write+0x98/0xc8
>   [  904.596599]  kernfs_fop_write_iter+0x150/0x1e8
>   [  904.779881]  vfs_write+0x29c/0x450
>   [...]
> 
> Would it make sense to use a union to overlay the struct
> arm_smccc_1_2_regs with an RSI-specific argument layout and copy the
> digest into an explicit 64-byte array, as in commit 221049874b6a
> ("arm64: RSI: fix field-spanning write warning in attestation token
> init")?

Thanks for reporting and suggestion. I'll fix at next-spin.


-- 
Sincerely,
Yeoreum Yun


  reply	other threads:[~2026-09-30  5:13 UTC|newest]

Thread overview: 23+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-29 16:57 [PATCH v2 0/3] arm64/virt: Add Arm CCA measurement register support Yeoreum Yun
2026-09-29 16:57 ` [PATCH v2 1/3] arm64: rsi: Add helpers for Arm CCA measurement register operations Yeoreum Yun
2026-09-30  2:04   ` Kohei Enju
2026-09-30  5:13     ` Yeoreum Yun [this message]
2026-09-29 16:57 ` [PATCH v2 2/3] arm64: rsi: Add realm hash algorithm defines Yeoreum Yun
2026-09-30  2:39   ` Kohei Enju
2026-09-30  5:10     ` Yeoreum Yun
2026-09-29 16:57 ` [PATCH v2 3/3] virt: arm-cca-guest: Add support for measurement registers Yeoreum Yun
2026-09-30  3:24   ` Kohei Enju
2026-09-30  4:45     ` Kohei Enju
2026-09-30  5:09     ` Yeoreum Yun
2026-09-30  5:59       ` Kohei Enju
2026-09-30  6:40         ` Yeoreum Yun
2026-09-30  7:04           ` Kohei Enju
2026-09-30  7:54             ` Yeoreum Yun
2026-09-30 13:54           ` Jason Gunthorpe
2026-09-30 14:12             ` Yeoreum Yun
2026-09-30 14:17               ` Jason Gunthorpe
2026-09-30 14:28                 ` Yeoreum Yun
2026-10-01  1:33               ` Kohei Enju
2026-09-29 19:20 ` [PATCH v2 0/3] arm64/virt: Add Arm CCA measurement register support Jason Gunthorpe
2026-09-29 19:42   ` Yeoreum Yun
2026-09-29 19:45     ` Jason Gunthorpe

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=aryafzI-M06aZ4bZ@e129823.arm.com \
    --to=yeoreum.yun@arm.com \
    --cc=catalin.marinas@arm.com \
    --cc=enju.kohei@fujitsu.com \
    --cc=jgg@ziepe.ca \
    --cc=linux-arm-kernel@lists.infradead.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=sami.mujawar@arm.com \
    --cc=steven.price@arm.com \
    --cc=suzuki.poulose@arm.com \
    --cc=thuth@redhat.com \
    --cc=will@kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.