* [PATCH v35 1/7] Documentation/firmware: add imx/se to other_interfaces
2026-08-06 11:51 [PATCH v35 0/7] firmware: imx: driver for NXP secure-enclave pankaj.gupta
@ 2026-08-06 11:51 ` pankaj.gupta
2026-08-06 11:08 ` sashiko-bot
2026-08-06 11:51 ` [PATCH v35 2/7] dt-bindings: arm: fsl: add imx-se-fw binding doc pankaj.gupta
` (5 subsequent siblings)
6 siblings, 1 reply; 15+ messages in thread
From: pankaj.gupta @ 2026-08-06 11:51 UTC (permalink / raw)
To: Jonathan Corbet, Shuah Khan, Rob Herring, Krzysztof Kozlowski,
Conor Dooley, Frank Li, Sascha Hauer, Pengutronix Kernel Team,
Fabio Estevam, Pankaj Gupta
Cc: linux-doc, linux-kernel, devicetree, imx, linux-arm-kernel
From: Pankaj Gupta <pankaj.gupta@nxp.com>
Documents i.MX SoC's Service layer and C_DEV driver for selected SoC(s)
that contains the NXP hardware IP(s) for Secure Enclaves(se) like:
- NXP EdgeLock Enclave on i.MX93 & i.MX8ULP
Signed-off-by: Pankaj Gupta <pankaj.gupta@nxp.com>
Signed-off-by: Frank Li <Frank.Li@nxp.com>
---
.../driver-api/firmware/other_interfaces.rst | 133 +++++++++++++++++++++
1 file changed, 133 insertions(+)
diff --git a/Documentation/driver-api/firmware/other_interfaces.rst b/Documentation/driver-api/firmware/other_interfaces.rst
index 06ac89adaafb..6c6fa9a0ba1d 100644
--- a/Documentation/driver-api/firmware/other_interfaces.rst
+++ b/Documentation/driver-api/firmware/other_interfaces.rst
@@ -49,3 +49,136 @@ of the requests on to a secure monitor (EL3).
.. kernel-doc:: drivers/firmware/stratix10-svc.c
:export:
+
+NXP Secure Enclave Firmware Interface
+=====================================
+
+Introduction
+------------
+The NXP's i.MX HW IP like EdgeLock Enclave, V2X etc., creates an embedded secure
+enclave within the SoC boundary to enable features like:
+
+- Hardware Security Module (HSM)
+- Security Hardware Extension (SHE)
+- Vehicular to Anything (V2X)
+
+Each of the above features is enabled through dedicated NXP H/W IP on the SoC.
+On a single SoC, multiple hardware IP (or can say more than one secure enclave)
+can exist.
+
+NXP SoCs enabled with the such secure enclaves(SEs) IPs are:
+i.MX93, i.MX8ULP
+
+To communicate with one or more co-existing SE(s) on SoC, there is/are dedicated
+messaging units(MU) per SE. Each co-existing SE can have one or multiple exclusive
+MUs, dedicated to itself. None of the MU is shared between two SEs. Communication
+of the MU is realized using the mailbox driver. Each secure enclave can cater to
+multiple clients by virtue of these exclusive MUs. Also, they can distinguish
+transactions originating from these clients based on the MU used and core security
+state. The communication between the clients and secure enclaves is in the form of
+a command/response mechanism. Each client could expose a specific set of secure enclave
+features to the higher layers, based on the commands supported by that client. For
+example, the secure enclave could simultaneously support an OPTEE TA and Linux
+middleware as clients. Each of these clients can expose a specific set of secure
+enclave features based on the command set supported by them.
+
+NXP Secure Enclave(SE) Interface
+--------------------------------
+MU(s) is/are not shared between SE(s). But for an SoC like i.MX95 which has
+multiple SE(s) like HSM, V2X-HSM, V2X-SHE, all the SE(s) and their interfaces 'se-if'
+that is/are dedicated to a particular SE will be enumerated and provisioned using the
+single compatible node("fsl,imx95-se").
+
+Each 'se-if' comprises two layers:
+
+- (C_DEV Layer) User-Space software-access interface.
+- (Service Layer) OS-level software-access interface.
+
+::
+
+ +--------------------------------------------+
+ | Character Device(C_DEV) |
+ | |
+ | +---------+ +---------+ +---------+ |
+ | | misc #1 | | misc #2 | ... | misc #n | |
+ | | dev | | dev | | dev | |
+ | +---------+ +---------+ +---------+ |
+ | +-------------------------+ |
+ | | Misc. Dev Synchr. Logic | |
+ | +-------------------------+ |
+ | |
+ +--------------------------------------------+
+
+ +--------------------------------------------+
+ | Service Layer |
+ | |
+ | +-----------------------------+ |
+ | | Message Serialization Logic | |
+ | +-----------------------------+ |
+ | +---------------+ |
+ | | imx-mailbox | |
+ | | mailbox.c | |
+ | +---------------+ |
+ | |
+ +--------------------------------------------+
+
+- service layer:
+ This layer is responsible for ensuring the communication protocol that is defined
+ for communication with firmware.
+
+ FW Communication protocol ensures two things:
+
+ - Serializing the messages to be sent over an MU.
+ - FW can handle one command message at a time.
+
+- c_dev:
+ This layer offers character device contexts, created as '/dev/<se>_mux_chx'.
+ Using these multiple device contexts that are multiplexed over a single MU,
+ userspace application(s) can call fops like write/read to send the command message,
+ and read back the command response message to/from Firmware.
+ fops like read & write use the above defined service layer API(s) to communicate with
+ Firmware.
+
+ Misc-device(/dev/<se>_mux_chn) synchronization protocol::
+
+ Non-Secure + Secure
+ |
+ |
+ +-----------+ +-------------+ |
+ | se_ctrl.c +<---->+imx-mailbox.c| |
+ | | | mailbox.c +<-->+------+ +------+
+ +-----+-----+ +-------------+ | MU X +<-->+ ELE |
+ | +------+ +------+
+ +----------------+ |
+ | | |
+ v v |
+ logical logical |
+ receiver waiter |
+ + + |
+ | | |
+ | | |
+ | +----+------+ |
+ | | | |
+ | | | |
+ device_ctx device_ctx device_ctx |
+ |
+ User 0 User 1 User Y |
+ +------+ +------+ +------+ |
+ |misc.c| |misc.c| |misc.c| |
+ kernel space +------+ +------+ +------+ |
+ |
+ +---------------------------------------------------- |
+ | | | |
+ userspace /dev/ele_muXch0 | | |
+ /dev/ele_muXch1 | |
+ /dev/ele_muXchY |
+ |
+
+When a user sends a command to the firmware, it registers its device_ctx
+as waiter of a response from firmware.
+
+Enclave's Firmware owns the storage management over a Linux filesystem.
+For this c_dev provisions a dedicated slave device called "receiver".
+
+.. kernel-doc:: drivers/firmware/imx/se_ctrl.c
+ :export:
--
2.43.0
^ permalink raw reply related [flat|nested] 15+ messages in thread* Re: [PATCH v35 1/7] Documentation/firmware: add imx/se to other_interfaces
2026-08-06 11:51 ` [PATCH v35 1/7] Documentation/firmware: add imx/se to other_interfaces pankaj.gupta
@ 2026-08-06 11:08 ` sashiko-bot
0 siblings, 0 replies; 15+ messages in thread
From: sashiko-bot @ 2026-08-06 11:08 UTC (permalink / raw)
To: pankaj.gupta; +Cc: robh, Frank.Li, conor+dt, devicetree, imx
Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
- [Low] The `kernel-doc` directive references a non-existent file `drivers/firmware/imx/se_ctrl.c`, which will cause Sphinx build warnings or errors during documentation generation.
- [Low] Grammatical issues and awkward phrasing in the newly added documentation.
--
--- Patch [1]: [PATCH v35 1/7] Documentation/firmware: add imx/se to other_interfaces ---
commit 5b71a12dcba08cd85c4d04d9b33297065e03bb54
Author: Pankaj Gupta <pankaj.gupta@nxp.com>
Documentation/firmware: add imx/se to other_interfaces
Documents i.MX SoC's Service layer and C_DEV driver for selected SoC(s)
that contains the NXP hardware IP(s) for Secure Enclaves(se).
> diff --git a/Documentation/driver-api/firmware/other_interfaces.rst b/Documentation/driver-api/firmware/other_interfaces.rst
> index 06ac89adaafba..6c6fa9a0ba1df 100644
> --- a/Documentation/driver-api/firmware/other_interfaces.rst
> +++ b/Documentation/driver-api/firmware/other_interfaces.rst
[ ... ]
> +Each of the above features is enabled through dedicated NXP H/W IP on the SoC.
> +On a single SoC, multiple hardware IP (or can say more than one secure enclave)
> +can exist.
> +
> +NXP SoCs enabled with the such secure enclaves(SEs) IPs are:
> +i.MX93, i.MX8ULP
[Severity: Low]
This isn't a bug, but the phrasing "with the such secure enclaves(SEs) IPs"
reads a bit awkwardly. Should this perhaps be "with such secure enclave (SE)
IPs" instead?
There are a couple of other similar grammatical structures in this section
(like "The NXP's i.MX HW IP" and "multiple hardware IP") that might also
benefit from being smoothed out.
[ ... ]
> +When a user sends a command to the firmware, it registers its device_ctx
> +as waiter of a response from firmware.
> +
> +Enclave's Firmware owns the storage management over a Linux filesystem.
> +For this c_dev provisions a dedicated slave device called "receiver".
> +
> +.. kernel-doc:: drivers/firmware/imx/se_ctrl.c
> + :export:
[Severity: Low]
Will this kernel-doc directive trigger Sphinx build warnings during make
htmldocs?
It looks like drivers/firmware/imx/se_ctrl.c is not included in this patch.
Does the file exist in the current tree, or should this documentation patch
be combined with the patch that actually introduces se_ctrl.c to prevent
documentation build errors?
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260806-imx-se-if-v35-0-11b25bb308ef@nxp.com?part=1
^ permalink raw reply [flat|nested] 15+ messages in thread
* [PATCH v35 2/7] dt-bindings: arm: fsl: add imx-se-fw binding doc
2026-08-06 11:51 [PATCH v35 0/7] firmware: imx: driver for NXP secure-enclave pankaj.gupta
2026-08-06 11:51 ` [PATCH v35 1/7] Documentation/firmware: add imx/se to other_interfaces pankaj.gupta
@ 2026-08-06 11:51 ` pankaj.gupta
2026-08-06 11:51 ` [PATCH v35 3/7] firmware: imx: add driver for NXP EdgeLock Enclave pankaj.gupta
` (4 subsequent siblings)
6 siblings, 0 replies; 15+ messages in thread
From: pankaj.gupta @ 2026-08-06 11:51 UTC (permalink / raw)
To: Jonathan Corbet, Shuah Khan, Rob Herring, Krzysztof Kozlowski,
Conor Dooley, Frank Li, Sascha Hauer, Pengutronix Kernel Team,
Fabio Estevam, Pankaj Gupta
Cc: linux-doc, linux-kernel, devicetree, imx, linux-arm-kernel
From: Pankaj Gupta <pankaj.gupta@nxp.com>
The NXP security hardware IP(s) like: i.MX EdgeLock Enclave, V2X etc.,
creates an embedded secure enclave within the SoC boundary to enable
features like:
- HSM
- SHE
- V2X
Secure-Enclave(s) communication interface are typically via message
unit, i.e., based on mailbox linux kernel driver. This driver enables
communication ensuring well defined message sequence protocol between
Application Core and enclave's firmware.
Driver configures multiple misc-device on the MU, for multiple
user-space applications, to be able to communicate over single MU.
It exists on some i.MX processors. e.g. i.MX8ULP, i.MX93 etc.
Signed-off-by: Pankaj Gupta <pankaj.gupta@nxp.com>
Reviewed-by: Rob Herring (Arm) <robh@kernel.org>
Signed-off-by: Frank Li <Frank.Li@nxp.com>
---
.../devicetree/bindings/firmware/fsl,imx-se.yaml | 91 ++++++++++++++++++++++
1 file changed, 91 insertions(+)
diff --git a/Documentation/devicetree/bindings/firmware/fsl,imx-se.yaml b/Documentation/devicetree/bindings/firmware/fsl,imx-se.yaml
new file mode 100644
index 000000000000..fa81adbf9b80
--- /dev/null
+++ b/Documentation/devicetree/bindings/firmware/fsl,imx-se.yaml
@@ -0,0 +1,91 @@
+# SPDX-License-Identifier: (GPL-2.0-only OR BSD-2-Clause)
+%YAML 1.2
+---
+$id: http://devicetree.org/schemas/firmware/fsl,imx-se.yaml#
+$schema: http://devicetree.org/meta-schemas/core.yaml#
+
+title: NXP i.MX HW Secure Enclave(s) EdgeLock Enclave
+
+maintainers:
+ - Pankaj Gupta <pankaj.gupta@nxp.com>
+
+description: |
+ NXP's SoC may contain one or multiple embedded secure-enclave HW
+ IP(s) like i.MX EdgeLock Enclave, V2X etc. These NXP's HW IP(s)
+ enables features like
+ - Hardware Security Module (HSM),
+ - Security Hardware Extension (SHE), and
+ - Vehicular to Anything (V2X)
+
+ Communication interface to the secure-enclaves(se) is based on the
+ messaging unit(s).
+
+properties:
+ compatible:
+ enum:
+ - fsl,imx8ulp-se-ele-hsm
+ - fsl,imx93-se-ele-hsm
+ - fsl,imx95-se-ele-hsm
+
+ mboxes:
+ items:
+ - description: mailbox phandle to send message to se firmware
+ - description: mailbox phandle to receive message from se firmware
+
+ mbox-names:
+ items:
+ - const: tx
+ - const: rx
+
+ memory-region:
+ maxItems: 1
+
+ sram:
+ maxItems: 1
+
+required:
+ - compatible
+ - mboxes
+ - mbox-names
+
+allOf:
+ # memory-region
+ - if:
+ properties:
+ compatible:
+ contains:
+ enum:
+ - fsl,imx8ulp-se-ele-hsm
+ - fsl,imx93-se-ele-hsm
+ then:
+ required:
+ - memory-region
+ else:
+ properties:
+ memory-region: false
+
+ # sram
+ - if:
+ properties:
+ compatible:
+ contains:
+ enum:
+ - fsl,imx8ulp-se-ele-hsm
+ then:
+ required:
+ - sram
+
+ else:
+ properties:
+ sram: false
+
+additionalProperties: false
+
+examples:
+ - |
+ secure-enclave {
+ compatible = "fsl,imx95-se-ele-hsm";
+ mboxes = <&ele_mu0 0 0>, <&ele_mu0 1 0>;
+ mbox-names = "tx", "rx";
+ };
+...
--
2.43.0
^ permalink raw reply related [flat|nested] 15+ messages in thread* [PATCH v35 3/7] firmware: imx: add driver for NXP EdgeLock Enclave
2026-08-06 11:51 [PATCH v35 0/7] firmware: imx: driver for NXP secure-enclave pankaj.gupta
2026-08-06 11:51 ` [PATCH v35 1/7] Documentation/firmware: add imx/se to other_interfaces pankaj.gupta
2026-08-06 11:51 ` [PATCH v35 2/7] dt-bindings: arm: fsl: add imx-se-fw binding doc pankaj.gupta
@ 2026-08-06 11:51 ` pankaj.gupta
2026-08-06 11:17 ` sashiko-bot
2026-08-06 11:51 ` [PATCH v35 4/7] firmware: imx: device context dedicated to priv pankaj.gupta
` (3 subsequent siblings)
6 siblings, 1 reply; 15+ messages in thread
From: pankaj.gupta @ 2026-08-06 11:51 UTC (permalink / raw)
To: Jonathan Corbet, Shuah Khan, Rob Herring, Krzysztof Kozlowski,
Conor Dooley, Frank Li, Sascha Hauer, Pengutronix Kernel Team,
Fabio Estevam, Pankaj Gupta
Cc: linux-doc, linux-kernel, devicetree, imx, linux-arm-kernel,
Frieder Schrempf, sashiko-bot
From: Pankaj Gupta <pankaj.gupta@nxp.com>
Add MU-based communication interface for secure enclave.
NXP hardware IP(s) for secure-enclaves like Edgelock Enclave(ELE), are
embedded in the SoC to support the features like HSM, SHE & V2X, using
message based communication interface.
The secure enclave FW communicates with Linux over single or multiple
dedicated messaging unit(MU) based interface(s).
Exists on i.MX SoC(s) like i.MX8ULP, i.MX93, i.MX95 etc.
For i.MX9x SoC(s) there is at least one dedicated ELE MU(s) for each
world - Linux(one or more) and OPTEE-OS (one or more).
Other dependent kernel drivers will be:
- NVMEM: that supports non-volatile devices like EFUSES,
managed by NXP's secure-enclave.
Signed-off-by: Pankaj Gupta <pankaj.gupta@nxp.com>
Reviewed-by: Frank Li <Frank.Li@nxp.com>
Tested-by: Frieder Schrempf <frieder.schrempf@kontron.de>
Reviewed-by: Frieder Schrempf <frieder.schrempf@kontron.de>
---
Changes from v32 to v33
- Sample jiffies once. jiffies is volatile, so reading
it separately for the deadline check and for the
remaining-time subtraction would be a TOCTOU: a timer
tick (or a NO_HZ/virtualized tick catch-up that jumps
jiffies by several ticks) landing between the two
reads could push jiffies past the deadline and make
deadline_jiffies - jiffies underflow to a near
ULONG_MAX timeout, hanging the wait. One snapshot
keeps both uses consistent, so now < deadline_jiffies
guarantees a strictly positive remainder.
Reported-by: sashiko-bot <sashiko-bot@kernel.org>
Closes: https://sashiko.dev/#/patchset/20260121-imx-se-if-v32-0-c5222df51cc2@nxp.com?part=3
---
drivers/firmware/imx/Kconfig | 12 +
drivers/firmware/imx/Makefile | 2 +
drivers/firmware/imx/ele_base_msg.c | 282 ++++++++++++++++++++
drivers/firmware/imx/ele_base_msg.h | 100 +++++++
drivers/firmware/imx/ele_common.c | 492 ++++++++++++++++++++++++++++++++++
drivers/firmware/imx/ele_common.h | 45 ++++
drivers/firmware/imx/se_ctrl.c | 507 ++++++++++++++++++++++++++++++++++++
drivers/firmware/imx/se_ctrl.h | 112 ++++++++
include/linux/firmware/imx/se_api.h | 14 +
9 files changed, 1566 insertions(+)
diff --git a/drivers/firmware/imx/Kconfig b/drivers/firmware/imx/Kconfig
index 127ad752acf8..93ac339800e2 100644
--- a/drivers/firmware/imx/Kconfig
+++ b/drivers/firmware/imx/Kconfig
@@ -55,3 +55,15 @@ config IMX_SCMI_MISC_DRV
core that could provide misc functions such as board control.
This driver can also be built as a module.
+
+config IMX_SEC_ENCLAVE
+ tristate "i.MX Embedded Secure Enclave - EdgeLock Enclave Firmware driver."
+ depends on MAILBOX && ((IMX_MBOX && ARCH_MXC && ARM64) || COMPILE_TEST)
+ select FW_LOADER
+ default m if ARCH_MXC
+
+ help
+ Exposes APIs supported by the iMX Secure Enclave HW IP called:
+ - EdgeLock Enclave Firmware (for i.MX8ULP, i.MX93),
+ like base, HSM, V2X & SHE using the SAB protocol via the shared Messaging
+ Unit.
diff --git a/drivers/firmware/imx/Makefile b/drivers/firmware/imx/Makefile
index 3bbaffa6e347..4412b15846b1 100644
--- a/drivers/firmware/imx/Makefile
+++ b/drivers/firmware/imx/Makefile
@@ -4,3 +4,5 @@ obj-$(CONFIG_IMX_SCU) += imx-scu.o misc.o imx-scu-irq.o rm.o imx-scu-soc.o
obj-${CONFIG_IMX_SCMI_CPU_DRV} += sm-cpu.o
obj-${CONFIG_IMX_SCMI_MISC_DRV} += sm-misc.o
obj-${CONFIG_IMX_SCMI_LMM_DRV} += sm-lmm.o
+sec_enclave-objs = se_ctrl.o ele_common.o ele_base_msg.o
+obj-${CONFIG_IMX_SEC_ENCLAVE} += sec_enclave.o
diff --git a/drivers/firmware/imx/ele_base_msg.c b/drivers/firmware/imx/ele_base_msg.c
new file mode 100644
index 000000000000..724f6e913ce7
--- /dev/null
+++ b/drivers/firmware/imx/ele_base_msg.c
@@ -0,0 +1,282 @@
+// SPDX-License-Identifier: GPL-2.0+
+/*
+ * Copyright 2025 NXP
+ */
+
+#include <linux/types.h>
+
+#include <linux/cleanup.h>
+#include <linux/completion.h>
+#include <linux/dma-mapping.h>
+#include <linux/genalloc.h>
+
+#include "ele_base_msg.h"
+#include "ele_common.h"
+
+#define FW_DBG_DUMP_FIXED_STR "ELE"
+
+static void ele_get_info_cleanup(struct se_if_priv *priv, u32 *buf, dma_addr_t d_addr,
+ size_t size)
+{
+ if (priv->mem_pool)
+ gen_pool_free(priv->mem_pool, (unsigned long)buf, size);
+ else
+ dma_free_coherent(priv->dev, size, buf, d_addr);
+}
+
+int ele_get_info(struct se_if_priv *priv, struct ele_dev_info *s_info)
+{
+ dma_addr_t get_info_addr = 0;
+ void *get_info_data = NULL;
+ u32 get_info_len;
+ int ret = 0;
+
+ if (!priv)
+ return -EINVAL;
+
+ memset(s_info, 0x0, sizeof(*s_info));
+
+ struct se_api_msg *tx_msg __free(kfree) =
+ kzalloc(ELE_GET_INFO_REQ_MSG_SZ, GFP_KERNEL);
+ if (!tx_msg)
+ return -ENOMEM;
+
+ struct se_api_msg *rx_msg __free(kfree) =
+ kzalloc(ELE_GET_INFO_RSP_MSG_SZ, GFP_KERNEL);
+ if (!rx_msg)
+ return -ENOMEM;
+
+ get_info_len = ELE_GET_INFO_BUFF_SZ;
+ if (priv->mem_pool)
+ get_info_data = gen_pool_dma_alloc(priv->mem_pool,
+ get_info_len,
+ &get_info_addr);
+ else
+ get_info_data = dma_alloc_coherent(priv->dev,
+ get_info_len,
+ &get_info_addr,
+ GFP_KERNEL);
+ if (!get_info_data) {
+ dev_err(priv->dev,
+ "%s: Failed to allocate get_info_addr.", __func__);
+ return -ENOMEM;
+ }
+
+ /* gen_pool_dma_alloc() does not zero the buffer. */
+ memset(get_info_data, 0, get_info_len);
+
+ se_fill_cmd_msg_hdr(priv, (struct se_msg_hdr *)&tx_msg->header,
+ ELE_GET_INFO_REQ, ELE_GET_INFO_REQ_MSG_SZ, true);
+
+ tx_msg->data[0] = upper_32_bits(get_info_addr);
+ tx_msg->data[1] = lower_32_bits(get_info_addr);
+ tx_msg->data[2] = sizeof(*s_info);
+ ret = ele_msg_send_rcv(priv, tx_msg, ELE_GET_INFO_REQ_MSG_SZ, rx_msg,
+ ELE_GET_INFO_RSP_MSG_SZ);
+ if (ret < 0) {
+ ele_get_info_cleanup(priv, get_info_data, get_info_addr, get_info_len);
+ return ret;
+ }
+
+ ret = se_val_rsp_hdr_n_status(priv, rx_msg, ELE_GET_INFO_REQ,
+ ELE_GET_INFO_RSP_MSG_SZ, true);
+ if (ret < 0) {
+ ele_get_info_cleanup(priv, get_info_data, get_info_addr, get_info_len);
+ return ret;
+ }
+
+ memcpy(s_info, get_info_data, sizeof(*s_info));
+
+ ele_get_info_cleanup(priv, get_info_data, get_info_addr, get_info_len);
+
+ return ret;
+}
+
+int ele_fetch_soc_info(struct se_if_priv *priv, void *data)
+{
+ return ele_get_info(priv, (struct ele_dev_info *)data);
+}
+
+int ele_ping(struct se_if_priv *priv)
+{
+ int ret = 0;
+
+ if (!priv)
+ return -EINVAL;
+
+ struct se_api_msg *tx_msg __free(kfree) = kzalloc(ELE_PING_REQ_SZ,
+ GFP_KERNEL);
+ if (!tx_msg)
+ return -ENOMEM;
+
+ struct se_api_msg *rx_msg __free(kfree) = kzalloc(ELE_PING_RSP_SZ,
+ GFP_KERNEL);
+ if (!rx_msg)
+ return -ENOMEM;
+
+ se_fill_cmd_msg_hdr(priv, (struct se_msg_hdr *)&tx_msg->header,
+ ELE_PING_REQ, ELE_PING_REQ_SZ, true);
+
+ ret = ele_msg_send_rcv(priv, tx_msg, ELE_PING_REQ_SZ, rx_msg,
+ ELE_PING_RSP_SZ);
+ if (ret < 0)
+ return ret;
+
+ ret = se_val_rsp_hdr_n_status(priv, rx_msg, ELE_PING_REQ,
+ ELE_PING_RSP_SZ, true);
+
+ return ret;
+}
+
+int ele_service_swap(struct se_if_priv *priv,
+ dma_addr_t addr,
+ u32 addr_size, u16 flag)
+{
+ int ret = 0;
+
+ if (!priv)
+ return -EINVAL;
+
+ if (upper_32_bits(addr)) {
+ dev_err(priv->dev,
+ "ELE service-swap address exceeds 32-bit range: %pad\n",
+ &addr);
+ return -ERANGE;
+ }
+
+ struct se_api_msg *tx_msg __free(kfree) =
+ kzalloc(ELE_SERVICE_SWAP_REQ_MSG_SZ, GFP_KERNEL);
+ if (!tx_msg)
+ return -ENOMEM;
+
+ struct se_api_msg *rx_msg __free(kfree) =
+ kzalloc(ELE_SERVICE_SWAP_RSP_MSG_SZ, GFP_KERNEL);
+ if (!rx_msg)
+ return -ENOMEM;
+
+ se_fill_cmd_msg_hdr(priv, (struct se_msg_hdr *)&tx_msg->header,
+ ELE_SERVICE_SWAP_REQ, ELE_SERVICE_SWAP_REQ_MSG_SZ, true);
+
+ tx_msg->data[0] = flag;
+ tx_msg->data[1] = addr_size;
+ tx_msg->data[2] = ELE_NONE_VAL;
+ tx_msg->data[3] = lower_32_bits(addr);
+ ret = se_update_msg_chksum((u32 *)&tx_msg[0], ELE_SERVICE_SWAP_REQ_MSG_SZ);
+ if (ret)
+ return -EINVAL;
+
+ ret = ele_msg_send_rcv(priv, tx_msg, ELE_SERVICE_SWAP_REQ_MSG_SZ,
+ rx_msg, ELE_SERVICE_SWAP_RSP_MSG_SZ);
+ if (ret < 0)
+ return ret;
+
+ ret = se_val_rsp_hdr_n_status(priv, rx_msg, ELE_SERVICE_SWAP_REQ,
+ ELE_SERVICE_SWAP_RSP_MSG_SZ, true);
+ if (ret)
+ return ret;
+
+ if (flag == ELE_IMEM_EXPORT)
+ ret = rx_msg->data[1];
+ else
+ ret = 0;
+
+ return ret;
+}
+
+int ele_fw_authenticate(struct se_if_priv *priv, dma_addr_t contnr_addr,
+ dma_addr_t img_addr)
+{
+ int ret = 0;
+
+ if (!priv)
+ return -EINVAL;
+
+ if (upper_32_bits(contnr_addr) || upper_32_bits(img_addr)) {
+ dev_err(priv->dev, "Wrong address: %pap %pap\n", &contnr_addr, &img_addr);
+ return -EINVAL;
+ }
+
+ struct se_api_msg *tx_msg __free(kfree) =
+ kzalloc(ELE_FW_AUTH_REQ_SZ, GFP_KERNEL);
+ if (!tx_msg)
+ return -ENOMEM;
+
+ struct se_api_msg *rx_msg __free(kfree) =
+ kzalloc(ELE_FW_AUTH_RSP_MSG_SZ, GFP_KERNEL);
+ if (!rx_msg)
+ return -ENOMEM;
+
+ se_fill_cmd_msg_hdr(priv, (struct se_msg_hdr *)&tx_msg->header,
+ ELE_FW_AUTH_REQ, ELE_FW_AUTH_REQ_SZ, true);
+
+ tx_msg->data[0] = lower_32_bits(contnr_addr);
+ tx_msg->data[1] = 0;
+ tx_msg->data[2] = lower_32_bits(img_addr);
+
+ ret = ele_msg_send_rcv(priv, tx_msg, ELE_FW_AUTH_REQ_SZ, rx_msg,
+ ELE_FW_AUTH_RSP_MSG_SZ);
+ if (ret < 0)
+ return ret;
+
+ ret = se_val_rsp_hdr_n_status(priv, rx_msg, ELE_FW_AUTH_REQ,
+ ELE_FW_AUTH_RSP_MSG_SZ, true);
+
+ return ret;
+}
+
+int ele_debug_dump(struct se_if_priv *priv)
+{
+ bool keep_logging;
+ int msg_ex_cnt;
+ int ret = 0;
+ int i;
+
+ if (!priv)
+ return -EINVAL;
+
+ struct se_api_msg *tx_msg __free(kfree) = kzalloc(ELE_DEBUG_DUMP_REQ_SZ,
+ GFP_KERNEL);
+ if (!tx_msg)
+ return -ENOMEM;
+
+ struct se_api_msg *rx_msg __free(kfree) = kzalloc(ELE_DEBUG_DUMP_RSP_SZ,
+ GFP_KERNEL);
+ if (!rx_msg)
+ return -ENOMEM;
+
+ se_fill_cmd_msg_hdr(priv, &tx_msg->header, ELE_DEBUG_DUMP_REQ,
+ ELE_DEBUG_DUMP_REQ_SZ, true);
+
+ msg_ex_cnt = 0;
+ do {
+ memset(rx_msg, 0x0, ELE_DEBUG_DUMP_RSP_SZ);
+
+ ret = ele_msg_send_rcv(priv, tx_msg, ELE_DEBUG_DUMP_REQ_SZ,
+ rx_msg, ELE_DEBUG_DUMP_RSP_SZ);
+ if (ret < 0)
+ return ret;
+
+ ret = se_val_rsp_hdr_n_status(priv, rx_msg, ELE_DEBUG_DUMP_REQ,
+ ELE_DEBUG_DUMP_RSP_SZ, true);
+ if (ret) {
+ dev_err(priv->dev, "Dump_Debug_Buffer Error: %x.", ret);
+ break;
+ }
+ keep_logging = (rx_msg->header.size >= (ELE_DEBUG_DUMP_RSP_SZ >> 2) &&
+ msg_ex_cnt < ELE_MAX_DBG_DMP_PKT);
+
+ rx_msg->header.size -= 2;
+
+ if (rx_msg->header.size > 2)
+ rx_msg->header.size--;
+
+ for (i = 0; i < rx_msg->header.size; i += 2)
+ dev_info(priv->dev, "%s%02x_%02x: 0x%08x 0x%08x",
+ FW_DBG_DUMP_FIXED_STR, msg_ex_cnt, i,
+ rx_msg->data[i + 1], rx_msg->data[i + 2]);
+
+ msg_ex_cnt++;
+ } while (keep_logging);
+
+ return ret;
+}
diff --git a/drivers/firmware/imx/ele_base_msg.h b/drivers/firmware/imx/ele_base_msg.h
new file mode 100644
index 000000000000..d532c3f49449
--- /dev/null
+++ b/drivers/firmware/imx/ele_base_msg.h
@@ -0,0 +1,100 @@
+/* SPDX-License-Identifier: GPL-2.0+ */
+/*
+ * Copyright 2025 NXP
+ *
+ * Header file for the EdgeLock Enclave Base API(s).
+ */
+
+#ifndef ELE_BASE_MSG_H
+#define ELE_BASE_MSG_H
+
+#include <linux/unaligned.h>
+#include <linux/device.h>
+#include <linux/types.h>
+
+#include "se_ctrl.h"
+
+#define ELE_NONE_VAL 0x0
+
+#define ELE_GET_INFO_REQ 0xda
+#define ELE_GET_INFO_REQ_MSG_SZ 0x10
+#define ELE_GET_INFO_RSP_MSG_SZ 0x08
+
+#define MAX_UID_SIZE (16)
+#define DEV_GETINFO_ROM_PATCH_SHA_SZ (32)
+#define DEV_GETINFO_FW_SHA_SZ (32)
+#define DEV_GETINFO_OEM_SRKH_SZ (64)
+#define DEV_GETINFO_MIN_VER_MASK 0xff
+#define DEV_GETINFO_MAJ_VER_MASK 0xff00
+#define ELE_DEV_INFO_EXTRA_SZ 0x60
+
+struct dev_info {
+ u8 cmd;
+ u8 ver;
+ u16 length;
+ u16 soc_id;
+ u16 soc_rev;
+ u16 lmda_val;
+ u8 ssm_state;
+ u8 dev_atts_api_ver;
+ u8 uid[MAX_UID_SIZE];
+ u8 sha_rom_patch[DEV_GETINFO_ROM_PATCH_SHA_SZ];
+ u8 sha_fw[DEV_GETINFO_FW_SHA_SZ];
+};
+
+struct dev_addn_info {
+ u8 oem_srkh[DEV_GETINFO_OEM_SRKH_SZ];
+ u8 trng_state;
+ u8 csal_state;
+ u8 imem_state;
+ u8 reserved2;
+};
+
+struct ele_dev_info {
+ struct dev_info d_info;
+ struct dev_addn_info d_addn_info;
+};
+
+#define ELE_GET_INFO_BUFF_SZ (sizeof(struct ele_dev_info) \
+ + ELE_DEV_INFO_EXTRA_SZ)
+
+#define GET_SERIAL_NUM_FROM_UID(x, uid_word_sz) ({\
+ const u8 *__x = (const u8 *)(x); \
+ size_t __sz = (uid_word_sz); \
+ ((u64)get_unaligned_le32(__x + (__sz - 1) * sizeof(u32)) << 32) | \
+ get_unaligned_le32(__x); \
+ })
+
+#define ELE_MAX_DBG_DMP_PKT 50
+#define ELE_DEBUG_DUMP_REQ 0x21
+#define ELE_DEBUG_DUMP_REQ_SZ 0x4
+#define ELE_DEBUG_DUMP_RSP_SZ 0x5c
+
+#define ELE_PING_REQ 0x01
+#define ELE_PING_REQ_SZ 0x04
+#define ELE_PING_RSP_SZ 0x08
+
+#define ELE_SERVICE_SWAP_REQ 0xdf
+#define ELE_SERVICE_SWAP_REQ_MSG_SZ 0x18
+#define ELE_SERVICE_SWAP_RSP_MSG_SZ 0x0c
+#define ELE_IMEM_SIZE 0x10000
+#define ELE_IMEM_STATE_OK 0xca
+#define ELE_IMEM_STATE_BAD 0xfe
+#define ELE_IMEM_STATE_WORD 0x27
+#define ELE_IMEM_STATE_MASK 0x00ff0000
+#define ELE_IMEM_EXPORT 0x1
+#define ELE_IMEM_IMPORT 0x2
+
+#define ELE_FW_AUTH_REQ 0x02
+#define ELE_FW_AUTH_REQ_SZ 0x10
+#define ELE_FW_AUTH_RSP_MSG_SZ 0x08
+
+int ele_get_info(struct se_if_priv *priv, struct ele_dev_info *s_info);
+int ele_fetch_soc_info(struct se_if_priv *priv, void *data);
+int ele_ping(struct se_if_priv *priv);
+int ele_service_swap(struct se_if_priv *priv, dma_addr_t addr,
+ u32 addr_size, u16 flag);
+int ele_fw_authenticate(struct se_if_priv *priv, dma_addr_t contnr_addr,
+ dma_addr_t img_addr);
+int ele_debug_dump(struct se_if_priv *priv);
+#endif
diff --git a/drivers/firmware/imx/ele_common.c b/drivers/firmware/imx/ele_common.c
new file mode 100644
index 000000000000..bc08ea2dcd87
--- /dev/null
+++ b/drivers/firmware/imx/ele_common.c
@@ -0,0 +1,492 @@
+// SPDX-License-Identifier: GPL-2.0+
+/*
+ * Copyright 2025 NXP
+ */
+
+#include "ele_base_msg.h"
+#include "ele_common.h"
+
+/*
+ * se_update_msg_chksum() - calculate and update message checksum word.
+ * @msg: message buffer.
+ * @msg_len: message length in bytes.
+ *
+ * The message length must be 4-byte aligned. The last word is treated as the
+ * checksum field and is not included in the checksum calculation.
+ *
+ * Return:
+ * 0 on success, negative errno on failure.
+ */
+int se_update_msg_chksum(u32 *msg, u32 msg_len)
+{
+ u32 nb_words;
+ u32 chksum = 0;
+ u32 i;
+
+ if (!msg)
+ return -EINVAL;
+
+ if (msg_len % SE_MSG_WORD_SZ) {
+ pr_err("Msg-len is not 4-byte aligned.\n");
+ return -EINVAL;
+ }
+
+ nb_words = msg_len / sizeof(*msg);
+ if (nb_words < 5)
+ return -EINVAL;
+
+ /* Last word is the checksum word, so skip it. */
+ nb_words--;
+
+ for (i = 0; i < nb_words; i++)
+ chksum ^= msg[i];
+
+ msg[nb_words] = chksum;
+
+ return 0;
+}
+
+int ele_msg_rcv(struct se_if_priv *priv, struct se_clbk_handle *se_clbk_hdl)
+{
+ bool is_rsp_wait_with_timeout = false;
+ bool wait_uninterruptible = false;
+ unsigned long remaining_jiffies;
+ unsigned long deadline_jiffies;
+ unsigned long flags;
+ int ret;
+
+ remaining_jiffies = msecs_to_jiffies(SE_RCV_MSG_DEFAULT_TIMEOUT_MS);
+ if (se_clbk_hdl == &priv->waiting_rsp_clbk_hdl) {
+ is_rsp_wait_with_timeout = true;
+ deadline_jiffies = jiffies + remaining_jiffies;
+ }
+
+ do {
+ if (is_rsp_wait_with_timeout) {
+ unsigned long now = jiffies;
+
+ if (time_after_eq(now, deadline_jiffies)) {
+ /* Deadline hit: fence hung FW, like the ret==0 path. */
+ spin_lock_irqsave(&se_clbk_hdl->clbk_rx_lock, flags);
+ se_clbk_hdl->rx_msg = NULL;
+ if (!completion_done(&se_clbk_hdl->done))
+ atomic_set(&priv->fw_busy, 1);
+ spin_unlock_irqrestore(&se_clbk_hdl->clbk_rx_lock, flags);
+ ret = -ETIMEDOUT;
+ break;
+ }
+ remaining_jiffies = deadline_jiffies - now;
+ }
+
+ if (wait_uninterruptible)
+ ret = wait_for_completion_timeout(&se_clbk_hdl->done,
+ remaining_jiffies);
+ else
+ ret = wait_for_completion_interruptible_timeout(&se_clbk_hdl->done,
+ remaining_jiffies);
+ if (ret == -ERESTARTSYS) {
+ /*
+ * Record that a signal was observed, then continue waiting non-
+ * interruptibly until the response arrives or the timeout
+ * expires. The caller can surface the interruption to userspace
+ * after the protocol transaction is brought back to a
+ * synchronized state.
+ */
+ if (is_rsp_wait_with_timeout &&
+ READ_ONCE(se_clbk_hdl->rx_msg)) {
+ WRITE_ONCE(se_clbk_hdl->signal_rcvd, true);
+ wait_uninterruptible = true;
+ continue;
+ }
+ break;
+ }
+
+ if (ret == 0) {
+ /*
+ * The response buffer belongs to the caller of ele_msg_send_rcv()
+ * and may be freed as soon as this function returns. Clear rx_msg
+ * under clbk_rx_lock so that a late se_if_rx_callback() can
+ * observe that the waiter has timed out and must not copy into
+ * the stale buffer.
+ *
+ * If the completion has not yet been signaled, mark the firmware
+ * path busy. This acts as a circuit breaker: reject new
+ * command/response transactions until the delayed response
+ * arrives and the callback closes the breaker.
+ */
+
+ spin_lock_irqsave(&se_clbk_hdl->clbk_rx_lock, flags);
+ se_clbk_hdl->rx_msg = NULL;
+ if (!completion_done(&se_clbk_hdl->done))
+ atomic_set(&priv->fw_busy, 1);
+
+ spin_unlock_irqrestore(&se_clbk_hdl->clbk_rx_lock, flags);
+ ret = -ETIMEDOUT;
+ dev_err(priv->dev,
+ "Fatal Error: SE interface %s0, hangs indefinitely.\n",
+ get_se_if_name(priv->if_defs->se_if_type));
+ break;
+ }
+ ret = se_clbk_hdl->rx_msg_sz;
+ break;
+ } while (ret < 0);
+
+ return ret;
+}
+
+int ele_msg_send(struct se_if_priv *priv,
+ void *tx_msg,
+ int tx_msg_sz)
+{
+ struct se_msg_hdr *header = tx_msg;
+ int err;
+
+ /*
+ * Check that the size passed as argument matches the size
+ * carried in the message.
+ */
+ if (header->size << 2 != tx_msg_sz) {
+ dev_err(priv->dev,
+ "User buf hdr: 0x%x, sz mismatced with input-sz (%d != %d).",
+ *(u32 *)header, header->size << 2, tx_msg_sz);
+ return -EINVAL;
+ }
+
+ /*
+ * The i.MX MU mailbox controller copies the payload words into MU
+ * registers synchronously from its send path. It does not retain the
+ * caller-provided tx_msg pointer after mbox_send_message() returns, so
+ * the caller-owned buffer may be released after a successful send.
+ */
+ err = mbox_send_message(priv->tx_chan, tx_msg);
+ if (err < 0) {
+ dev_err(priv->dev, "Error: mbox_send_message failure.\n");
+ return err;
+ }
+
+ return tx_msg_sz;
+}
+
+static void ele_msg_send_rcv_cleanup(struct se_if_priv *priv)
+{
+ unsigned long flags;
+
+ spin_lock_irqsave(&priv->waiting_rsp_clbk_hdl.clbk_rx_lock, flags);
+ priv->waiting_rsp_clbk_hdl.rx_msg = NULL;
+ priv->waiting_rsp_clbk_hdl.rx_msg_sz = 0;
+ spin_unlock_irqrestore(&priv->waiting_rsp_clbk_hdl.clbk_rx_lock, flags);
+}
+
+/* API used for send/receive blocking call. */
+int ele_msg_send_rcv(struct se_if_priv *priv, void *tx_msg, int tx_msg_sz,
+ void *rx_msg, int exp_rx_msg_sz)
+{
+ unsigned long flags;
+ int err;
+
+ guard(mutex)(&priv->se_if_cmd_lock);
+
+ if (atomic_read(&priv->fw_busy)) {
+ dev_dbg(priv->dev, "ELE became unresponsive.\n");
+ return -EBUSY;
+ }
+ reinit_completion(&priv->waiting_rsp_clbk_hdl.done);
+ /* Publish rx_msg/rx_msg_sz under the lock read by se_if_rx_callback(). */
+ spin_lock_irqsave(&priv->waiting_rsp_clbk_hdl.clbk_rx_lock, flags);
+ priv->waiting_rsp_clbk_hdl.rx_msg_sz = exp_rx_msg_sz;
+ priv->waiting_rsp_clbk_hdl.rx_msg = rx_msg;
+ spin_unlock_irqrestore(&priv->waiting_rsp_clbk_hdl.clbk_rx_lock, flags);
+
+ err = ele_msg_send(priv, tx_msg, tx_msg_sz);
+ if (err < 0) {
+ ele_msg_send_rcv_cleanup(priv);
+ return err;
+ }
+
+ err = ele_msg_rcv(priv, &priv->waiting_rsp_clbk_hdl);
+
+ if (priv->waiting_rsp_clbk_hdl.signal_rcvd) {
+ /*
+ * Signal was deferred until the FW/kernel protocol resynchronized.
+ * On success report -ERESTARTSYS for the interrupted wait; the
+ * command is not re-sent. Keep real errors like -ETIMEDOUT.
+ */
+ if (err > 0)
+ err = -ERESTARTSYS;
+ priv->waiting_rsp_clbk_hdl.signal_rcvd = false;
+ dev_dbg(priv->dev, "Err[0x%x]:Interrupted by signal.", err);
+ }
+
+ ele_msg_send_rcv_cleanup(priv);
+
+ return err;
+}
+
+static bool check_hdr_exception_for_sz(struct se_if_priv *priv,
+ struct se_msg_hdr *header)
+{
+ /*
+ * List of API headers that can accept a variable length response buffer.
+ */
+ if (header->command == ELE_DEBUG_DUMP_REQ &&
+ header->ver == priv->if_defs->base_api_ver &&
+ header->size >= 2 && header->size <= (ELE_DEBUG_DUMP_RSP_SZ / 4))
+ return true;
+
+ return false;
+}
+
+/*
+ * Callback called by mailbox FW, when data is received.
+ */
+void se_if_rx_callback(struct mbox_client *mbox_cl, void *msg)
+{
+ struct se_clbk_handle *se_clbk_hdl;
+ struct device *dev = mbox_cl->dev;
+ struct se_msg_hdr *header;
+ bool sz_mismatch = false;
+ struct se_if_priv *priv;
+ unsigned long flags;
+ u32 rx_msg_sz;
+
+ priv = dev_get_drvdata(dev);
+ if (!priv)
+ return;
+
+ /* The function can be called with NULL msg */
+ if (IS_ERR_OR_NULL(msg)) {
+ dev_err(dev, "Message is invalid\n");
+ return;
+ }
+
+ header = msg;
+ rx_msg_sz = header->size << 2;
+
+ /* Incoming command: wake up the receiver if any. */
+ if (header->tag == priv->if_defs->cmd_tag) {
+ se_clbk_hdl = &priv->cmd_receiver_clbk_hdl;
+ spin_lock_irqsave(&se_clbk_hdl->clbk_rx_lock, flags);
+ if (!se_clbk_hdl->rx_msg) {
+ spin_unlock_irqrestore(&se_clbk_hdl->clbk_rx_lock, flags);
+ dev_warn(dev, "No command receiver registered for message: %.8x\n",
+ *((u32 *)header));
+ return;
+ }
+
+ /*
+ * cmd_tag messages are delivered only to the explicitly registered
+ * command receiver. Unlike the synchronous response waiter path, the
+ * command receiver uses a dedicated long-lived buffer installed by
+ * SE_IOCTL_ENABLE_CMD_RCV and is not subject to the timeout/circuit-
+ * breaker handling used for rsp_tag messages.
+ */
+ dev_dbg(dev, "Selecting cmd receiver: for mesg header:0x%x.",
+ *(u32 *)header);
+
+ /*
+ * Pre-allocated buffer of MAX_NVM_MSG_LEN
+ * as the NVM command are initiated by FW.
+ * Size is revealed as part of this call function.
+ */
+
+ if (rx_msg_sz > MAX_NVM_MSG_LEN)
+ sz_mismatch = true;
+
+ /*
+ * Clamp the copy length to the pre-allocated receiver buffer (MAX_NVM_MSG_LEN).
+ */
+ se_clbk_hdl->rx_msg_sz = min_t(u32, rx_msg_sz, MAX_NVM_MSG_LEN);
+ memcpy(se_clbk_hdl->rx_msg, msg, se_clbk_hdl->rx_msg_sz);
+ complete(&se_clbk_hdl->done);
+ spin_unlock_irqrestore(&se_clbk_hdl->clbk_rx_lock, flags);
+ if (sz_mismatch)
+ dev_err(dev,
+ "CMD-RCVER NVM: hdr(0x%x) with different sz(%d != %d).\n",
+ *(u32 *)header,
+ (header->size << 2), rx_msg_sz);
+ } else if (header->tag == priv->if_defs->rsp_tag) {
+ bool exception_for_sz_mismatch = check_hdr_exception_for_sz(priv, header);
+ u32 exp_rx_msg_sz = 0;
+
+ /*
+ * rx_msg and rx_msg_sz are owned by the sender under clbk_rx_lock.
+ * Read both under the lock: drop a late response instead of copying
+ * into freed memory, and avoid a stale size. A late response also
+ * closes the firmware-busy circuit breaker.
+ */
+ se_clbk_hdl = &priv->waiting_rsp_clbk_hdl;
+ spin_lock_irqsave(&se_clbk_hdl->clbk_rx_lock, flags);
+ if (!se_clbk_hdl->rx_msg) {
+ /* Close circuit breaker on spinlock race */
+ atomic_set(&priv->fw_busy, 0);
+ spin_unlock_irqrestore(&se_clbk_hdl->clbk_rx_lock, flags);
+ dev_info(dev, "ELE responded (late), recovery FW available.");
+ return;
+ }
+ exp_rx_msg_sz = se_clbk_hdl->rx_msg_sz;
+ dev_dbg(dev, "Selecting resp waiter: for mesg header:0x%x.",
+ *(u32 *)header);
+
+ /*
+ * For rsp_tag traffic, the sender provides the expected response
+ * buffer size. If firmware returns a different size, clamp the copy
+ * length to the caller's buffer capacity before memcpy() and report the
+ * mismatch after dropping the spinlock.
+ */
+ if (rx_msg_sz != exp_rx_msg_sz && !exception_for_sz_mismatch)
+ sz_mismatch = true;
+
+ se_clbk_hdl->rx_msg_sz = min(rx_msg_sz, exp_rx_msg_sz);
+ memcpy(se_clbk_hdl->rx_msg, msg, se_clbk_hdl->rx_msg_sz);
+ complete(&se_clbk_hdl->done);
+ spin_unlock_irqrestore(&se_clbk_hdl->clbk_rx_lock, flags);
+
+ if (sz_mismatch)
+ dev_err(dev,
+ "Rsp to CMD: hdr(0x%x) with different sz(%d != %d).\n",
+ *(u32 *)header,
+ (header->size << 2), exp_rx_msg_sz);
+ } else {
+ dev_err(dev, "Failed to select a device for message: %.8x\n",
+ *((u32 *)header));
+ }
+}
+
+int se_val_rsp_hdr_n_status(struct se_if_priv *priv, struct se_api_msg *msg,
+ u8 msg_id, u8 sz, bool is_base_api)
+{
+ struct se_msg_hdr *header = &msg->header;
+ u32 status;
+
+ if (header->tag != priv->if_defs->rsp_tag) {
+ dev_dbg(priv->dev, "MSG[0x%x] Hdr: Resp tag mismatch. (0x%x != 0x%x)",
+ msg_id, header->tag, priv->if_defs->rsp_tag);
+ return -EINVAL;
+ }
+
+ if (header->command != msg_id) {
+ dev_dbg(priv->dev, "MSG Header: Cmd id mismatch. (0x%x != 0x%x)",
+ header->command, msg_id);
+ return -EINVAL;
+ }
+
+ if ((sz % 4) || (header->size != (sz >> 2) &&
+ !check_hdr_exception_for_sz(priv, header))) {
+ dev_dbg(priv->dev, "MSG[0x%x] Hdr: Cmd size mismatch. (0x%x != 0x%x)",
+ msg_id, header->size, (sz >> 2));
+ return -EINVAL;
+ }
+
+ if (is_base_api && header->ver != priv->if_defs->base_api_ver) {
+ dev_dbg(priv->dev,
+ "MSG[0x%x] Hdr: Base API Vers mismatch. (0x%x != 0x%x)",
+ msg_id, header->ver, priv->if_defs->base_api_ver);
+ return -EINVAL;
+ } else if (!is_base_api && header->ver != priv->if_defs->fw_api_ver) {
+ dev_dbg(priv->dev,
+ "MSG[0x%x] Hdr: FW API Vers mismatch. (0x%x != 0x%x)",
+ msg_id, header->ver, priv->if_defs->fw_api_ver);
+ return -EINVAL;
+ }
+
+ if (header->size > SE_MU_HDR_WORD_SZ) {
+ status = RES_STATUS(msg->data[0]);
+ if (status != priv->if_defs->success_tag) {
+ dev_dbg(priv->dev, "Command Id[%x], Response Failure = 0x%x",
+ header->command, status);
+ return -EPERM;
+ }
+ }
+
+ return 0;
+}
+
+int se_save_imem_state(struct se_if_priv *priv, struct se_imem_buf *imem)
+{
+ struct ele_dev_info s_info = {0};
+ int ret;
+
+ ret = ele_get_info(priv, &s_info);
+ if (ret) {
+ dev_err(priv->dev, "Failed to get info from ELE.\n");
+ return ret;
+ }
+
+ /* Check for the imem-state before continue to save imem state. */
+ if (s_info.d_addn_info.imem_state == ELE_IMEM_STATE_BAD)
+ return 0;
+
+ /*
+ * EXPORT command will save encrypted IMEM to given address,
+ * so later in resume, IMEM can be restored from the given
+ * address.
+ *
+ * Size must be at least 64 kB.
+ */
+ ret = ele_service_swap(priv, imem->daddr, ELE_IMEM_SIZE, ELE_IMEM_EXPORT);
+ if (ret < 0) {
+ dev_err(priv->dev, "Failed to export IMEM.");
+ imem->size = 0;
+ } else if (ret > ELE_IMEM_SIZE) {
+ dev_err(priv->dev, "Invalid exported IMEM size %d.", ret);
+ imem->size = 0;
+ ret = -EIO;
+ } else {
+ dev_dbg(priv->dev,
+ "Exported %d bytes of encrypted IMEM.",
+ ret);
+ imem->size = ret;
+ }
+
+ return ret > 0 ? 0 : ret;
+}
+
+int se_restore_imem_state(struct se_if_priv *priv, struct se_imem_buf *imem)
+{
+ struct ele_dev_info s_info;
+ int ret;
+
+ /* get info from ELE */
+ ret = ele_get_info(priv, &s_info);
+ if (ret) {
+ dev_err(priv->dev, "Failed to get info from ELE.");
+ return ret;
+ }
+ imem->state = s_info.d_addn_info.imem_state;
+
+ /* Check for the imem-state and imem-size before continue to
+ * restore imem state.
+ */
+ if (s_info.d_addn_info.imem_state != ELE_IMEM_STATE_BAD || !imem->size)
+ return 0;
+
+ /*
+ * IMPORT command will restore IMEM from the given
+ * address, here size is the actual size returned by ELE
+ * during the export operation
+ */
+ ret = ele_service_swap(priv, imem->daddr, imem->size, ELE_IMEM_IMPORT);
+ if (ret) {
+ dev_err(priv->dev, "Failed to import IMEM");
+ return ret;
+ }
+
+ /*
+ * After importing IMEM, check if IMEM state is equal to 0xCA
+ * to ensure IMEM is fully loaded and
+ * ELE functionality can be used.
+ */
+ ret = ele_get_info(priv, &s_info);
+ if (ret) {
+ dev_err(priv->dev, "Failed to get info from ELE.");
+ return ret;
+ }
+ imem->state = s_info.d_addn_info.imem_state;
+
+ if (s_info.d_addn_info.imem_state == ELE_IMEM_STATE_OK)
+ dev_dbg(priv->dev, "Successfully restored IMEM.");
+ else
+ dev_err(priv->dev, "Failed to restore IMEM.");
+
+ return ret;
+}
diff --git a/drivers/firmware/imx/ele_common.h b/drivers/firmware/imx/ele_common.h
new file mode 100644
index 000000000000..7bf2febefc45
--- /dev/null
+++ b/drivers/firmware/imx/ele_common.h
@@ -0,0 +1,45 @@
+/* SPDX-License-Identifier: GPL-2.0+ */
+/*
+ * Copyright 2025 NXP
+ */
+
+#ifndef __ELE_COMMON_H__
+#define __ELE_COMMON_H__
+
+#include "se_ctrl.h"
+
+#define SE_RCV_MSG_DEFAULT_TIMEOUT_MS 3000
+
+#define ELE_SUCCESS_IND 0xD6
+
+#define IMX_ELE_FW_DIR "imx/ele/"
+
+int se_update_msg_chksum(u32 *msg, u32 msg_len);
+
+int ele_msg_rcv(struct se_if_priv *priv, struct se_clbk_handle *se_clbk_hdl);
+
+int ele_msg_send(struct se_if_priv *priv, void *tx_msg, int tx_msg_sz);
+
+int ele_msg_send_rcv(struct se_if_priv *priv, void *tx_msg, int tx_msg_sz,
+ void *rx_msg, int exp_rx_msg_sz);
+
+void se_if_rx_callback(struct mbox_client *mbox_cl, void *msg);
+
+int se_val_rsp_hdr_n_status(struct se_if_priv *priv, struct se_api_msg *msg,
+ u8 msg_id, u8 sz, bool is_base_api);
+
+/* Fill a command message header with a given command ID and length in bytes. */
+static inline void se_fill_cmd_msg_hdr(struct se_if_priv *priv, struct se_msg_hdr *hdr,
+ u8 cmd, u32 len, bool is_base_api)
+{
+ hdr->tag = priv->if_defs->cmd_tag;
+ hdr->ver = (is_base_api) ? priv->if_defs->base_api_ver : priv->if_defs->fw_api_ver;
+ hdr->command = cmd;
+ hdr->size = len >> 2;
+}
+
+int se_save_imem_state(struct se_if_priv *priv, struct se_imem_buf *imem);
+
+int se_restore_imem_state(struct se_if_priv *priv, struct se_imem_buf *imem);
+
+#endif /*__ELE_COMMON_H__ */
diff --git a/drivers/firmware/imx/se_ctrl.c b/drivers/firmware/imx/se_ctrl.c
new file mode 100644
index 000000000000..53091cc37e7e
--- /dev/null
+++ b/drivers/firmware/imx/se_ctrl.c
@@ -0,0 +1,507 @@
+// SPDX-License-Identifier: GPL-2.0+
+/*
+ * Copyright 2026 NXP
+ */
+
+#include <linux/bitfield.h>
+#include <linux/completion.h>
+#include <linux/delay.h>
+#include <linux/dev_printk.h>
+#include <linux/dma-mapping.h>
+#include <linux/errno.h>
+#include <linux/export.h>
+#include <linux/firmware.h>
+#include <linux/firmware/imx/se_api.h>
+#include <linux/genalloc.h>
+#include <linux/init.h>
+#include <linux/io.h>
+#include <linux/miscdevice.h>
+#include <linux/module.h>
+#include <linux/of_platform.h>
+#include <linux/of_reserved_mem.h>
+#include <linux/platform_device.h>
+#include <linux/slab.h>
+#include <linux/string.h>
+#include <linux/sys_soc.h>
+
+#include "ele_base_msg.h"
+#include "ele_common.h"
+#include "se_ctrl.h"
+
+#define MAX_SOC_INFO_DATA_SZ 256
+#define MBOX_TX_NAME "tx"
+#define MBOX_RX_NAME "rx"
+
+#define SE_TYPE_STR_DBG "dbg"
+#define SE_TYPE_STR_HSM "hsm"
+
+#define SE_TYPE_ID_DBG 0x1
+
+#define SE_TYPE_ID_HSM 0x2
+
+struct se_soc_dev_regn {
+ bool soc_dev_registered;
+ struct soc_device *soc_dev;
+ struct soc_device_attribute *soc_dev_attr;
+};
+
+struct se_var_info {
+ u16 soc_rev;
+ struct se_soc_dev_regn soc_dev_regn;
+ /* To serialize populating common SoC level info. */
+ struct mutex se_var_info_lock;
+};
+
+/* contains fixed information */
+struct se_soc_info {
+ const u16 soc_id;
+ const char *soc_name;
+ const struct se_fw_img_name se_fw_img_nm;
+ bool imem_state_mgmt;
+};
+
+struct se_if_node {
+ struct se_soc_info *se_info;
+ u8 *pool_name;
+ bool reserved_dma_ranges;
+ struct se_if_defines if_defs;
+};
+
+/* common for all the SoC. */
+static struct se_var_info var_se_info = {
+ .soc_rev = 0,
+ .se_var_info_lock = __MUTEX_INITIALIZER(var_se_info.se_var_info_lock)
+};
+
+static struct se_soc_info se_imx8ulp_info = {
+ .soc_id = SOC_ID_OF_IMX8ULP,
+ .soc_name = "i.MX8ULP",
+ .se_fw_img_nm = {
+ .prim_fw_nm_in_rfs = IMX_ELE_FW_DIR
+ "mx8ulpa2-ahab-container.img",
+ .seco_fw_nm_in_rfs = IMX_ELE_FW_DIR
+ "mx8ulpa2ext-ahab-container.img",
+ },
+ .imem_state_mgmt = true,
+};
+
+static struct se_if_node imx8ulp_se_ele_hsm = {
+ .se_info = &se_imx8ulp_info,
+ .pool_name = "sram",
+ .reserved_dma_ranges = true,
+ .if_defs = {
+ .se_if_type = SE_TYPE_ID_HSM,
+ .cmd_tag = 0x17,
+ .rsp_tag = 0xe1,
+ .success_tag = ELE_SUCCESS_IND,
+ .base_api_ver = MESSAGING_VERSION_6,
+ .fw_api_ver = MESSAGING_VERSION_7,
+ },
+};
+
+static struct se_soc_info se_imx93_info = {
+ .soc_id = SOC_ID_OF_IMX93,
+};
+
+static struct se_if_node imx93_se_ele_hsm = {
+ .se_info = &se_imx93_info,
+ .reserved_dma_ranges = true,
+ .if_defs = {
+ .se_if_type = SE_TYPE_ID_HSM,
+ .cmd_tag = 0x17,
+ .rsp_tag = 0xe1,
+ .success_tag = ELE_SUCCESS_IND,
+ .base_api_ver = MESSAGING_VERSION_6,
+ .fw_api_ver = MESSAGING_VERSION_7,
+ },
+};
+
+static const struct of_device_id se_match[] = {
+ { .compatible = "fsl,imx8ulp-se-ele-hsm", .data = &imx8ulp_se_ele_hsm },
+ { .compatible = "fsl,imx93-se-ele-hsm", .data = &imx93_se_ele_hsm },
+ { }
+};
+MODULE_DEVICE_TABLE(of, se_match);
+
+char *get_se_if_name(u8 se_if_id)
+{
+ switch (se_if_id) {
+ case SE_TYPE_ID_DBG: return SE_TYPE_STR_DBG;
+ case SE_TYPE_ID_HSM: return SE_TYPE_STR_HSM;
+ }
+
+ return "unknown";
+}
+
+static struct se_fw_load_info *get_load_fw_instance(struct se_if_priv *priv)
+{
+ return &priv->load_fw;
+}
+
+static void se_soc_device_unregister(struct se_soc_dev_regn *soc_dev_regn)
+{
+ guard(mutex)(&var_se_info.se_var_info_lock);
+
+ if (soc_dev_regn->soc_dev) {
+ soc_device_unregister(soc_dev_regn->soc_dev);
+ soc_dev_regn->soc_dev = NULL;
+ }
+
+ if (soc_dev_regn->soc_dev_attr) {
+ /*
+ * revision and serial_number are the only kasprintf()-allocated
+ * strings. machine points into the DT, and soc_id/family are
+ * constants, so they must not be freed.
+ */
+ kfree(soc_dev_regn->soc_dev_attr->revision);
+ kfree(soc_dev_regn->soc_dev_attr->serial_number);
+ kfree(soc_dev_regn->soc_dev_attr);
+ soc_dev_regn->soc_dev_attr = NULL;
+ }
+
+ soc_dev_regn->soc_dev_registered = false;
+}
+
+/*
+ * Build and register a soc_device entry for this SoC. Separated from
+ * get_se_soc_info() so that the firmware-fetch path and the sysfs
+ * registration path can be reasoned about independently.
+ */
+static int se_soc_dev_register(struct se_if_priv *priv, u16 soc_rev,
+ const char *soc_name, const u8 *uid)
+{
+ struct soc_device_attribute *attr;
+ struct soc_device *sdev;
+ int err;
+
+ if (!soc_rev || !soc_name || !uid)
+ return -EINVAL;
+
+ attr = kzalloc_obj(*attr, GFP_KERNEL);
+ if (!attr)
+ return -ENOMEM;
+
+ if (FIELD_GET(DEV_GETINFO_MIN_VER_MASK, soc_rev))
+ attr->revision = kasprintf(GFP_KERNEL, "%x.%x",
+ FIELD_GET(DEV_GETINFO_MAJ_VER_MASK, soc_rev),
+ FIELD_GET(DEV_GETINFO_MIN_VER_MASK, soc_rev));
+ else
+ attr->revision = kasprintf(GFP_KERNEL, "%x",
+ FIELD_GET(DEV_GETINFO_MAJ_VER_MASK, soc_rev));
+
+ if (!attr->revision) {
+ err = -ENOMEM;
+ goto err_free_attr;
+ }
+
+ attr->soc_id = soc_name;
+
+ err = of_property_read_string(of_root, "model", &attr->machine);
+ if (err) {
+ err = -EINVAL;
+ goto err_free_rev;
+ }
+
+ attr->family = "Freescale i.MX";
+
+ attr->serial_number = kasprintf(GFP_KERNEL, "%016llX",
+ GET_SERIAL_NUM_FROM_UID(uid, MAX_UID_SIZE >> 2));
+ if (!attr->serial_number) {
+ err = -ENOMEM;
+ goto err_free_rev;
+ }
+
+ sdev = soc_device_register(attr);
+ if (IS_ERR(sdev)) {
+ err = PTR_ERR(sdev);
+ goto err_free_serial;
+ }
+
+ /*
+ * Publish the singleton. Freed once, at module unload, by
+ * se_soc_device_unregister(). Caller holds se_var_info_lock.
+ */
+ var_se_info.soc_dev_regn.soc_dev = sdev;
+ var_se_info.soc_dev_regn.soc_dev_attr = attr;
+
+ /* Mark registration complete so get_se_soc_info() skips this path on retry. */
+ var_se_info.soc_dev_regn.soc_dev_registered = true;
+
+ return 0;
+
+err_free_serial:
+ kfree(attr->serial_number);
+err_free_rev:
+ kfree(attr->revision);
+err_free_attr:
+ kfree(attr);
+
+ return err;
+}
+
+static int get_se_soc_info(struct se_if_priv *priv, const struct se_soc_info *se_info)
+{
+ struct se_fw_load_info *load_fw = get_load_fw_instance(priv);
+ u8 data[MAX_SOC_INFO_DATA_SZ];
+ struct ele_dev_info *s_info;
+ int err;
+
+ guard(mutex)(&var_se_info.se_var_info_lock);
+
+ /*
+ * Early exit: both objectives already complete, nothing to do.
+ */
+ if (var_se_info.soc_rev &&
+ (!se_info->soc_name || var_se_info.soc_dev_regn.soc_dev_registered))
+ return 0;
+
+ err = ele_fetch_soc_info(priv, &data);
+ if (err < 0)
+ return dev_err_probe(priv->dev, err, "Failed to fetch SoC Info.");
+
+ s_info = (struct ele_dev_info *)data;
+
+ if (!var_se_info.soc_rev) {
+ var_se_info.soc_rev = s_info->d_info.soc_rev;
+
+ /*
+ * Only update IMEM state when the load_fw path is active;
+ * on SoCs without IMEM management (e.g. i.MX93) the field
+ * is not meaningful.
+ */
+ if (load_fw->imem_mgmt)
+ load_fw->imem.state = s_info->d_addn_info.imem_state;
+ }
+
+ if (se_info->soc_name && !var_se_info.soc_dev_regn.soc_dev_registered) {
+ err = se_soc_dev_register(priv, var_se_info.soc_rev,
+ se_info->soc_name, s_info->d_info.uid);
+ if (err < 0)
+ return dev_err_probe(priv->dev, err,
+ "Failed to register SE SoC device.");
+ }
+
+ return 0;
+}
+
+static int se_if_request_channel(struct device *dev, struct mbox_chan **chan,
+ struct mbox_client *cl, const char *name)
+{
+ struct mbox_chan *t_chan;
+
+ t_chan = mbox_request_channel_byname(cl, name);
+ if (IS_ERR(t_chan))
+ return dev_err_probe(dev, PTR_ERR(t_chan),
+ "Failed to request %s channel.", name);
+
+ *chan = t_chan;
+
+ return 0;
+}
+
+static void se_if_probe_cleanup(void *plat_dev)
+{
+ struct platform_device *pdev = plat_dev;
+ struct device *dev = &pdev->dev;
+ struct se_if_priv *priv;
+
+ priv = dev_get_drvdata(dev);
+ if (!priv)
+ return;
+
+ if (priv->rx_chan)
+ mbox_free_channel(priv->rx_chan);
+ if (priv->tx_chan)
+ mbox_free_channel(priv->tx_chan);
+
+ /*
+ * Being device managed buffer, no need to free the buffer allocated
+ * in se probe to store encrypted IMEM.
+ */
+
+ /*
+ * No need to check, if reserved memory is allocated
+ * before calling for its release. Or clearing the
+ * un-set bit.
+ */
+ of_reserved_mem_device_release(dev);
+
+ dev_set_drvdata(dev, NULL);
+
+ kfree(priv);
+}
+
+static int se_if_probe(struct platform_device *pdev)
+{
+ const struct se_soc_info *se_info;
+ const struct se_if_node *if_node;
+ struct se_fw_load_info *load_fw;
+ struct device *dev = &pdev->dev;
+ struct se_if_priv *priv;
+ int ret;
+
+ if_node = device_get_match_data(dev);
+ if (!if_node)
+ return -EINVAL;
+
+ se_info = if_node->se_info;
+
+ priv = kzalloc_obj(*priv, GFP_KERNEL);
+ if (!priv)
+ return -ENOMEM;
+
+ priv->dev = dev;
+ priv->if_defs = &if_node->if_defs;
+ dev_set_drvdata(dev, priv);
+
+ mutex_init(&priv->se_if_cmd_lock);
+ spin_lock_init(&priv->cmd_receiver_clbk_hdl.clbk_rx_lock);
+ spin_lock_init(&priv->waiting_rsp_clbk_hdl.clbk_rx_lock);
+ atomic_set(&priv->fw_busy, 0);
+ init_completion(&priv->waiting_rsp_clbk_hdl.done);
+ init_completion(&priv->cmd_receiver_clbk_hdl.done);
+
+ ret = devm_add_action_or_reset(dev, se_if_probe_cleanup, pdev);
+ if (ret)
+ return ret;
+
+ /* Mailbox client configuration */
+ priv->se_mb_cl.dev = dev;
+ priv->se_mb_cl.tx_block = false;
+ priv->se_mb_cl.knows_txdone = false;
+ priv->se_mb_cl.rx_callback = se_if_rx_callback;
+
+ ret = se_if_request_channel(dev, &priv->tx_chan, &priv->se_mb_cl, MBOX_TX_NAME);
+ if (ret)
+ return ret;
+
+ ret = se_if_request_channel(dev, &priv->rx_chan, &priv->se_mb_cl, MBOX_RX_NAME);
+ if (ret)
+ return ret;
+
+ if (if_node->pool_name) {
+ priv->mem_pool = of_gen_pool_get(dev->of_node, if_node->pool_name, 0);
+ if (!priv->mem_pool)
+ return dev_err_probe(dev, -ENOMEM,
+ "Unable to get sram pool = %s.",
+ if_node->pool_name);
+ }
+
+ if (if_node->reserved_dma_ranges) {
+ ret = of_reserved_mem_device_init(dev);
+ if (ret)
+ return dev_err_probe(dev, ret,
+ "Failed to init reserved memory region.");
+ }
+
+ ret = dma_set_mask_and_coherent(dev, DMA_BIT_MASK(32));
+ if (ret)
+ return dev_err_probe(dev, ret, "Failed to set 32-bit coherent DMA mask.");
+
+ /*
+ * Initialize load_fw_lock before registering the misc device.
+ * A userspace process could open the device and trigger se_load_firmware()
+ * via IOCTL immediately after misc_register(), so the mutex must be ready
+ * before the device becomes visible.
+ */
+ if (se_info->se_fw_img_nm.seco_fw_nm_in_rfs) {
+ load_fw = get_load_fw_instance(priv);
+ mutex_init(&load_fw->load_fw_lock);
+ load_fw->se_fw_img_nm = &se_info->se_fw_img_nm;
+ load_fw->is_fw_tobe_loaded = true;
+ }
+
+ /* By default, there is no pending FW to be loaded.*/
+ if (se_info->imem_state_mgmt) {
+ load_fw = get_load_fw_instance(priv);
+
+ /* allocate buffer where SE store encrypted IMEM */
+ load_fw->imem.buf = dmam_alloc_coherent(priv->dev, ELE_IMEM_SIZE,
+ &load_fw->imem.daddr,
+ GFP_KERNEL);
+ if (!load_fw->imem.buf)
+ return dev_err_probe(dev, -ENOMEM,
+ "dmam-alloc-failed: To store encr-IMEM.");
+ load_fw->imem_mgmt = true;
+ }
+
+ if (if_node->if_defs.se_if_type == SE_TYPE_ID_HSM) {
+ ret = get_se_soc_info(priv, se_info);
+ if (ret)
+ return dev_err_probe(dev, ret, "Failed to fetch SoC Info.");
+ }
+
+ dev_info(dev, "i.MX secure-enclave: %s0 interface to firmware, configured.",
+ get_se_if_name(priv->if_defs->se_if_type));
+
+ return ret;
+}
+
+static int se_suspend(struct device *dev)
+{
+ struct se_if_priv *priv = dev_get_drvdata(dev);
+ struct se_fw_load_info *load_fw;
+ int ret = 0;
+
+ load_fw = get_load_fw_instance(priv);
+
+ if (load_fw->imem_mgmt) {
+ ret = se_save_imem_state(priv, &load_fw->imem);
+ if (ret)
+ dev_warn(dev, "Failure saving IMEM state[0x%x]", ret);
+ }
+
+ return 0;
+}
+
+static int se_resume(struct device *dev)
+{
+ struct se_if_priv *priv = dev_get_drvdata(dev);
+ struct se_fw_load_info *load_fw;
+ int ret = 0;
+
+ load_fw = get_load_fw_instance(priv);
+
+ if (load_fw->imem_mgmt) {
+ ret = se_restore_imem_state(priv, &load_fw->imem);
+ if (ret)
+ dev_warn(dev, "Failure restoring IMEM state[0x%x]", ret);
+ }
+
+ return 0;
+}
+
+DEFINE_SIMPLE_DEV_PM_OPS(se_pm, se_suspend, se_resume);
+
+static struct platform_driver se_driver = {
+ .driver = {
+ .name = "fsl-se",
+ .of_match_table = se_match,
+ .pm = pm_sleep_ptr(&se_pm),
+ },
+ .probe = se_if_probe,
+};
+
+static int __init se_init(void)
+{
+ return platform_driver_register(&se_driver);
+}
+module_init(se_init);
+
+static void __exit se_exit(void)
+{
+ platform_driver_unregister(&se_driver);
+
+ /*
+ * The soc_device is a module-scoped singleton that outlives any single
+ * MU interface bind/unbind. Release it here, once, after every interface
+ * has been unbound, so its lifetime is tied to the module rather than to
+ * the first-probed interface.
+ */
+ se_soc_device_unregister(&var_se_info.soc_dev_regn);
+}
+module_exit(se_exit);
+
+MODULE_AUTHOR("Pankaj Gupta <pankaj.gupta@nxp.com>");
+MODULE_DESCRIPTION("iMX Secure Enclave Driver.");
+MODULE_LICENSE("GPL");
diff --git a/drivers/firmware/imx/se_ctrl.h b/drivers/firmware/imx/se_ctrl.h
new file mode 100644
index 000000000000..54b2a262a2c3
--- /dev/null
+++ b/drivers/firmware/imx/se_ctrl.h
@@ -0,0 +1,112 @@
+/* SPDX-License-Identifier: GPL-2.0+ */
+/*
+ * Copyright 2026 NXP
+ */
+
+#ifndef SE_CTRL_H
+#define SE_CTRL_H
+
+#include <linux/bitfield.h>
+#include <linux/miscdevice.h>
+#include <linux/mailbox_client.h>
+#include <linux/semaphore.h>
+
+#define MAX_FW_LOAD_RETRIES 50
+#define SE_MSG_WORD_SZ 0x4
+
+#define RES_STATUS(x) FIELD_GET(0x000000ff, x)
+#define MAX_NVM_MSG_LEN (256)
+#define MESSAGING_VERSION_6 0x6
+#define MESSAGING_VERSION_7 0x7
+
+struct se_clbk_handle {
+ struct completion done;
+ bool signal_rcvd;
+ u32 rx_msg_sz;
+ /*
+ * Assignment of the rx_msg buffer to held till the
+ * received content as part callback function, is copied.
+ */
+ struct se_api_msg *rx_msg;
+ /*
+ * Serialise the timeout path in ele_msg_rcv() against
+ * se_if_rx_callback() so that the callback can never
+ * memcpy into a buffer that the timeout path has already
+ * freed.
+ */
+ spinlock_t clbk_rx_lock;
+};
+
+struct se_imem_buf {
+ u8 *buf;
+ dma_addr_t daddr;
+ u32 size;
+ u32 state;
+};
+
+/* Header of the messages exchange with the EdgeLock Enclave */
+struct se_msg_hdr {
+ u8 ver;
+ u8 size;
+ u8 command;
+ u8 tag;
+} __packed;
+
+#define SE_MU_HDR_SZ 4
+#define SE_MU_HDR_WORD_SZ 1
+
+struct se_api_msg {
+ struct se_msg_hdr header;
+ u32 data[];
+};
+
+struct se_if_defines {
+ const u8 se_if_type;
+ u8 cmd_tag;
+ u8 rsp_tag;
+ u8 success_tag;
+ u8 base_api_ver;
+ u8 fw_api_ver;
+};
+
+struct se_fw_img_name {
+ const char *prim_fw_nm_in_rfs;
+ const char *seco_fw_nm_in_rfs;
+};
+
+struct se_fw_load_info {
+ const struct se_fw_img_name *se_fw_img_nm;
+ bool is_fw_tobe_loaded;
+ bool imem_mgmt;
+ struct se_imem_buf imem;
+ /* to serialize the fw load state */
+ struct mutex load_fw_lock;
+};
+
+struct se_if_priv {
+ struct device *dev;
+
+ struct se_clbk_handle cmd_receiver_clbk_hdl;
+ /*
+ * Update to the waiting_rsp_dev, to be protected
+ * under se_if_cmd_lock.
+ */
+ struct se_clbk_handle waiting_rsp_clbk_hdl;
+ /*
+ * prevent new command to be sent on the se interface while previous
+ * command is still processing. (response is awaited)
+ */
+ struct mutex se_if_cmd_lock;
+
+ struct mbox_client se_mb_cl;
+ struct mbox_chan *tx_chan, *rx_chan;
+
+ struct gen_pool *mem_pool;
+ const struct se_if_defines *if_defs;
+ struct se_fw_load_info load_fw;
+
+ atomic_t fw_busy;
+};
+
+char *get_se_if_name(u8 se_if_id);
+#endif
diff --git a/include/linux/firmware/imx/se_api.h b/include/linux/firmware/imx/se_api.h
new file mode 100644
index 000000000000..b1c4c9115d7b
--- /dev/null
+++ b/include/linux/firmware/imx/se_api.h
@@ -0,0 +1,14 @@
+/* SPDX-License-Identifier: GPL-2.0+ */
+/*
+ * Copyright 2025 NXP
+ */
+
+#ifndef __SE_API_H__
+#define __SE_API_H__
+
+#include <linux/types.h>
+
+#define SOC_ID_OF_IMX8ULP 0x084d
+#define SOC_ID_OF_IMX93 0x9300
+
+#endif /* __SE_API_H__ */
--
2.43.0
^ permalink raw reply related [flat|nested] 15+ messages in thread* Re: [PATCH v35 3/7] firmware: imx: add driver for NXP EdgeLock Enclave
2026-08-06 11:51 ` [PATCH v35 3/7] firmware: imx: add driver for NXP EdgeLock Enclave pankaj.gupta
@ 2026-08-06 11:17 ` sashiko-bot
2026-08-06 16:08 ` Frank Li
0 siblings, 1 reply; 15+ messages in thread
From: sashiko-bot @ 2026-08-06 11:17 UTC (permalink / raw)
To: pankaj.gupta; +Cc: Frank.Li, conor+dt, robh, devicetree, imx
Thank you for your contribution! Sashiko AI review found 5 potential issue(s) to consider:
- [High] The DMA buffer used for get_info is freed prematurely upon a timeout, allowing the enclave firmware to corrupt memory when it completes the transaction.
- [High] Allocating memory with GFP_KERNEL during the PM suspend/resume phases can cause system deadlocks.
- [Medium] A successfully completed firmware command is incorrectly reported as interrupted (-ERESTARTSYS), introducing a replay vulnerability.
- [Medium] se_restore_imem_state() ignores validation failure and returns success even if the IMEM state is bad.
- [Medium] Multi-byte fields in struct dev_info are populated via DMA by little-endian hardware but are accessed as native integers by the driver.
--
--- Patch [3]: [PATCH v35 3/7] firmware: imx: add driver for NXP EdgeLock Enclave ---
commit 357109d983ad738d0dc813242f9d555c6b2d561c
Author: Pankaj Gupta <pankaj.gupta@nxp.com>
firmware: imx: add driver for NXP EdgeLock Enclave
This commit adds the MU-based communication interface for the NXP EdgeLock
secure enclave, enabling messaging between the Linux kernel and the enclave
firmware on i.MX SoC platforms.
Link: https://sashiko.dev/#/patchset/20260121-imx-se-if-v32-0-c5222df51cc2@nxp.com?part=3
> --- /dev/null
> +++ b/drivers/firmware/imx/ele_base_msg.c
[ ... ]
> +static void ele_get_info_cleanup(struct se_if_priv *priv, u32 *buf, dma_addr_t d_addr,
> + size_t size)
> +{
> + if (priv->mem_pool)
> + gen_pool_free(priv->mem_pool, (unsigned long)buf, size);
> + else
> + dma_free_coherent(priv->dev, size, buf, d_addr);
> +}
[Severity: High]
If the ele_msg_send_rcv() transaction times out, the hardware might still
process the command and DMA the response payload later. Since this cleanup
function unconditionally frees the DMA buffer back to the pool or system,
could a delayed hardware response silently corrupt whatever kernel data is
subsequently allocated at this physical address?
[ ... ]
> +int ele_get_info(struct se_if_priv *priv, struct ele_dev_info *s_info)
> +{
> + dma_addr_t get_info_addr = 0;
> + void *get_info_data = NULL;
> + u32 get_info_len;
> + int ret = 0;
> +
> + if (!priv)
> + return -EINVAL;
> +
> + memset(s_info, 0x0, sizeof(*s_info));
> +
> + struct se_api_msg *tx_msg __free(kfree) =
> + kzalloc(ELE_GET_INFO_REQ_MSG_SZ, GFP_KERNEL);
[Severity: High]
Can this allocation cause a deadlock during system suspend?
During system suspend, se_suspend() calls se_save_imem_state(), which invokes
ele_get_info(). Using GFP_KERNEL here and for the DMA buffer below can trigger
direct memory reclaim. If the reclaim process waits on I/O or swapping while
underlying storage devices are already suspended, will the system hang?
[ ... ]
> --- /dev/null
> +++ b/drivers/firmware/imx/ele_base_msg.h
[ ... ]
> +struct dev_info {
> + u8 cmd;
> + u8 ver;
> + u16 length;
> + u16 soc_id;
> + u16 soc_rev;
> + u16 lmda_val;
> + u8 ssm_state;
> + u8 dev_atts_api_ver;
> + u8 uid[MAX_UID_SIZE];
> + u8 sha_rom_patch[DEV_GETINFO_ROM_PATCH_SHA_SZ];
> + u8 sha_fw[DEV_GETINFO_FW_SHA_SZ];
> +};
[Severity: Medium]
Since these multi-byte fields are populated directly via DMA from the NXP
enclave firmware (which uses little-endian format), will they be read
incorrectly on big-endian architectures?
For instance, get_se_soc_info() directly accesses s_info->d_info.soc_rev
without any byte-swapping, which might yield an invalid version number on
big-endian systems. Should these be defined as __le16 instead?
[ ... ]
> --- /dev/null
> +++ b/drivers/firmware/imx/ele_common.c
[ ... ]
> +int ele_msg_send_rcv(struct se_if_priv *priv, void *tx_msg, int tx_msg_sz,
> + void *rx_msg, int exp_rx_msg_sz)
> +{
[ ... ]
> + err = ele_msg_rcv(priv, &priv->waiting_rsp_clbk_hdl);
> +
> + if (priv->waiting_rsp_clbk_hdl.signal_rcvd) {
> + /*
> + * Signal was deferred until the FW/kernel protocol resynchronized.
> + * On success report -ERESTARTSYS for the interrupted wait; the
> + * command is not re-sent. Keep real errors like -ETIMEDOUT.
> + */
> + if (err > 0)
> + err = -ERESTARTSYS;
[Severity: Medium]
Does this unintentionally convert a successful firmware transaction into an
error?
When a wait is interrupted by a signal, ele_msg_rcv() continues waiting
uninterruptibly. When the firmware finally responds successfully, err will
be positive. By overwriting this success with -ERESTARTSYS, won't this
cause the kernel to silently replay the syscall from userspace? For
non-idempotent operations, executing the command twice could corrupt enclave
state.
[ ... ]
> +int se_restore_imem_state(struct se_if_priv *priv, struct se_imem_buf *imem)
> +{
[ ... ]
> + /*
> + * After importing IMEM, check if IMEM state is equal to 0xCA
> + * to ensure IMEM is fully loaded and
> + * ELE functionality can be used.
> + */
> + ret = ele_get_info(priv, &s_info);
> + if (ret) {
> + dev_err(priv->dev, "Failed to get info from ELE.");
> + return ret;
> + }
> + imem->state = s_info.d_addn_info.imem_state;
> +
> + if (s_info.d_addn_info.imem_state == ELE_IMEM_STATE_OK)
> + dev_dbg(priv->dev, "Successfully restored IMEM.");
> + else
> + dev_err(priv->dev, "Failed to restore IMEM.");
> +
> + return ret;
> +}
[Severity: Medium]
If the IMEM state is bad (not ELE_IMEM_STATE_OK), the code logs an error
but still returns the success code (ret = 0) from the preceding ele_get_info()
call. Does this hide the hardware failure from the power management subsystem
and leave the enclave in a non-functional state after a system resume?
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260806-imx-se-if-v35-0-11b25bb308ef@nxp.com?part=3
^ permalink raw reply [flat|nested] 15+ messages in thread* Re: [PATCH v35 3/7] firmware: imx: add driver for NXP EdgeLock Enclave
2026-08-06 11:17 ` sashiko-bot
@ 2026-08-06 16:08 ` Frank Li
0 siblings, 0 replies; 15+ messages in thread
From: Frank Li @ 2026-08-06 16:08 UTC (permalink / raw)
To: sashiko-reviews; +Cc: pankaj.gupta, Frank.Li, conor+dt, robh, devicetree, imx
On Thu, Aug 06, 2026 at 11:17:23AM +0000, sashiko-bot@kernel.org wrote:
> Thank you for your contribution! Sashiko AI review found 5 potential issue(s) to consider:
> - [High] The DMA buffer used for get_info is freed prematurely upon a timeout, allowing the enclave firmware to corrupt memory when it completes the transaction.
> - [High] Allocating memory with GFP_KERNEL during the PM suspend/resume phases can cause system deadlocks.
> - [Medium] A successfully completed firmware command is incorrectly reported as interrupted (-ERESTARTSYS), introducing a replay vulnerability.
> - [Medium] se_restore_imem_state() ignores validation failure and returns success even if the IMEM state is bad.
> - [Medium] Multi-byte fields in struct dev_info are populated via DMA by little-endian hardware but are accessed as native integers by the driver.
> --
>
> --- Patch [3]: [PATCH v35 3/7] firmware: imx: add driver for NXP EdgeLock Enclave ---
> commit 357109d983ad738d0dc813242f9d555c6b2d561c
> Author: Pankaj Gupta <pankaj.gupta@nxp.com>
>
> firmware: imx: add driver for NXP EdgeLock Enclave
>
> This commit adds the MU-based communication interface for the NXP EdgeLock
> secure enclave, enabling messaging between the Linux kernel and the enclave
> firmware on i.MX SoC platforms.
>
> Link: https://sashiko.dev/#/patchset/20260121-imx-se-if-v32-0-c5222df51cc2@nxp.com?part=3
>
> > --- /dev/null
> > +++ b/drivers/firmware/imx/ele_base_msg.c
> [ ... ]
> > +static void ele_get_info_cleanup(struct se_if_priv *priv, u32 *buf, dma_addr_t d_addr,
> > + size_t size)
> > +{
> > + if (priv->mem_pool)
> > + gen_pool_free(priv->mem_pool, (unsigned long)buf, size);
> > + else
> > + dma_free_coherent(priv->dev, size, buf, d_addr);
> > +}
>
> [Severity: High]
> If the ele_msg_send_rcv() transaction times out, the hardware might still
> process the command and DMA the response payload later. Since this cleanup
> function unconditionally frees the DMA buffer back to the pool or system,
> could a delayed hardware response silently corrupt whatever kernel data is
> subsequently allocated at this physical address?
>
> [ ... ]
> > +int ele_get_info(struct se_if_priv *priv, struct ele_dev_info *s_info)
> > +{
> > + dma_addr_t get_info_addr = 0;
> > + void *get_info_data = NULL;
> > + u32 get_info_len;
> > + int ret = 0;
> > +
> > + if (!priv)
> > + return -EINVAL;
> > +
> > + memset(s_info, 0x0, sizeof(*s_info));
> > +
> > + struct se_api_msg *tx_msg __free(kfree) =
> > + kzalloc(ELE_GET_INFO_REQ_MSG_SZ, GFP_KERNEL);
>
> [Severity: High]
> Can this allocation cause a deadlock during system suspend?
>
> During system suspend, se_suspend() calls se_save_imem_state(), which invokes
> ele_get_info(). Using GFP_KERNEL here and for the DMA buffer below can trigger
> direct memory reclaim. If the reclaim process waits on I/O or swapping while
> underlying storage devices are already suspended, will the system hang?
>
> [ ... ]
> > --- /dev/null
> > +++ b/drivers/firmware/imx/ele_base_msg.h
> [ ... ]
> > +struct dev_info {
> > + u8 cmd;
> > + u8 ver;
> > + u16 length;
> > + u16 soc_id;
> > + u16 soc_rev;
> > + u16 lmda_val;
> > + u8 ssm_state;
> > + u8 dev_atts_api_ver;
> > + u8 uid[MAX_UID_SIZE];
> > + u8 sha_rom_patch[DEV_GETINFO_ROM_PATCH_SHA_SZ];
> > + u8 sha_fw[DEV_GETINFO_FW_SHA_SZ];
> > +};
>
> [Severity: Medium]
> Since these multi-byte fields are populated directly via DMA from the NXP
> enclave firmware (which uses little-endian format), will they be read
> incorrectly on big-endian architectures?
>
> For instance, get_se_soc_info() directly accesses s_info->d_info.soc_rev
> without any byte-swapping, which might yield an invalid version number on
> big-endian systems. Should these be defined as __le16 instead?
>
> [ ... ]
> > --- /dev/null
> > +++ b/drivers/firmware/imx/ele_common.c
> [ ... ]
> > +int ele_msg_send_rcv(struct se_if_priv *priv, void *tx_msg, int tx_msg_sz,
> > + void *rx_msg, int exp_rx_msg_sz)
> > +{
> [ ... ]
> > + err = ele_msg_rcv(priv, &priv->waiting_rsp_clbk_hdl);
> > +
> > + if (priv->waiting_rsp_clbk_hdl.signal_rcvd) {
> > + /*
> > + * Signal was deferred until the FW/kernel protocol resynchronized.
> > + * On success report -ERESTARTSYS for the interrupted wait; the
> > + * command is not re-sent. Keep real errors like -ETIMEDOUT.
> > + */
> > + if (err > 0)
> > + err = -ERESTARTSYS;
>
> [Severity: Medium]
> Does this unintentionally convert a successful firmware transaction into an
> error?
>
> When a wait is interrupted by a signal, ele_msg_rcv() continues waiting
> uninterruptibly. When the firmware finally responds successfully, err will
> be positive. By overwriting this success with -ERESTARTSYS, won't this
> cause the kernel to silently replay the syscall from userspace? For
> non-idempotent operations, executing the command twice could corrupt enclave
> state.
>
> [ ... ]
> > +int se_restore_imem_state(struct se_if_priv *priv, struct se_imem_buf *imem)
> > +{
> [ ... ]
> > + /*
> > + * After importing IMEM, check if IMEM state is equal to 0xCA
> > + * to ensure IMEM is fully loaded and
> > + * ELE functionality can be used.
> > + */
> > + ret = ele_get_info(priv, &s_info);
> > + if (ret) {
> > + dev_err(priv->dev, "Failed to get info from ELE.");
> > + return ret;
> > + }
> > + imem->state = s_info.d_addn_info.imem_state;
> > +
> > + if (s_info.d_addn_info.imem_state == ELE_IMEM_STATE_OK)
> > + dev_dbg(priv->dev, "Successfully restored IMEM.");
> > + else
> > + dev_err(priv->dev, "Failed to restore IMEM.");
> > +
> > + return ret;
> > +}
>
> [Severity: Medium]
> If the IMEM state is bad (not ELE_IMEM_STATE_OK), the code logs an error
> but still returns the success code (ret = 0) from the preceding ele_get_info()
> call. Does this hide the hardware failure from the power management subsystem
> and leave the enclave in a non-functional state after a system resume?
This one make sense, should return failure.
Frank
>
> --
> Sashiko AI review · https://sashiko.dev/#/patchset/20260806-imx-se-if-v35-0-11b25bb308ef@nxp.com?part=3
^ permalink raw reply [flat|nested] 15+ messages in thread
* [PATCH v35 4/7] firmware: imx: device context dedicated to priv
2026-08-06 11:51 [PATCH v35 0/7] firmware: imx: driver for NXP secure-enclave pankaj.gupta
` (2 preceding siblings ...)
2026-08-06 11:51 ` [PATCH v35 3/7] firmware: imx: add driver for NXP EdgeLock Enclave pankaj.gupta
@ 2026-08-06 11:51 ` pankaj.gupta
2026-08-06 11:15 ` sashiko-bot
2026-08-06 11:51 ` [PATCH v35 5/7] firmware: imx: adds miscdev pankaj.gupta
` (2 subsequent siblings)
6 siblings, 1 reply; 15+ messages in thread
From: pankaj.gupta @ 2026-08-06 11:51 UTC (permalink / raw)
To: Jonathan Corbet, Shuah Khan, Rob Herring, Krzysztof Kozlowski,
Conor Dooley, Frank Li, Sascha Hauer, Pengutronix Kernel Team,
Fabio Estevam, Pankaj Gupta
Cc: linux-doc, linux-kernel, devicetree, imx, linux-arm-kernel
From: Pankaj Gupta <pankaj.gupta@nxp.com>
Add priv_dev_ctx to prepare enabling misc-device context based send-receive
path, to communicate with FW.
No functionality change.
Signed-off-by: Pankaj Gupta <pankaj.gupta@nxp.com>
Reviewed-by: Frank Li <Frank.Li@nxp.com>
Signed-off-by: Frank Li <Frank.Li@nxp.com>
---
drivers/firmware/imx/ele_base_msg.c | 15 +++++-----
drivers/firmware/imx/ele_common.c | 55 +++++++++++++++++++++----------------
drivers/firmware/imx/ele_common.h | 8 +++---
drivers/firmware/imx/se_ctrl.c | 41 +++++++++++++++++++++++++++
drivers/firmware/imx/se_ctrl.h | 9 ++++++
5 files changed, 94 insertions(+), 34 deletions(-)
diff --git a/drivers/firmware/imx/ele_base_msg.c b/drivers/firmware/imx/ele_base_msg.c
index 724f6e913ce7..b70e3ef88a16 100644
--- a/drivers/firmware/imx/ele_base_msg.c
+++ b/drivers/firmware/imx/ele_base_msg.c
@@ -71,8 +71,9 @@ int ele_get_info(struct se_if_priv *priv, struct ele_dev_info *s_info)
tx_msg->data[0] = upper_32_bits(get_info_addr);
tx_msg->data[1] = lower_32_bits(get_info_addr);
tx_msg->data[2] = sizeof(*s_info);
- ret = ele_msg_send_rcv(priv, tx_msg, ELE_GET_INFO_REQ_MSG_SZ, rx_msg,
- ELE_GET_INFO_RSP_MSG_SZ);
+
+ ret = ele_msg_send_rcv(priv->priv_dev_ctx, tx_msg, ELE_GET_INFO_REQ_MSG_SZ,
+ rx_msg, ELE_GET_INFO_RSP_MSG_SZ);
if (ret < 0) {
ele_get_info_cleanup(priv, get_info_data, get_info_addr, get_info_len);
return ret;
@@ -117,8 +118,8 @@ int ele_ping(struct se_if_priv *priv)
se_fill_cmd_msg_hdr(priv, (struct se_msg_hdr *)&tx_msg->header,
ELE_PING_REQ, ELE_PING_REQ_SZ, true);
- ret = ele_msg_send_rcv(priv, tx_msg, ELE_PING_REQ_SZ, rx_msg,
- ELE_PING_RSP_SZ);
+ ret = ele_msg_send_rcv(priv->priv_dev_ctx, tx_msg, ELE_PING_REQ_SZ,
+ rx_msg, ELE_PING_RSP_SZ);
if (ret < 0)
return ret;
@@ -165,7 +166,7 @@ int ele_service_swap(struct se_if_priv *priv,
if (ret)
return -EINVAL;
- ret = ele_msg_send_rcv(priv, tx_msg, ELE_SERVICE_SWAP_REQ_MSG_SZ,
+ ret = ele_msg_send_rcv(priv->priv_dev_ctx, tx_msg, ELE_SERVICE_SWAP_REQ_MSG_SZ,
rx_msg, ELE_SERVICE_SWAP_RSP_MSG_SZ);
if (ret < 0)
return ret;
@@ -213,7 +214,7 @@ int ele_fw_authenticate(struct se_if_priv *priv, dma_addr_t contnr_addr,
tx_msg->data[1] = 0;
tx_msg->data[2] = lower_32_bits(img_addr);
- ret = ele_msg_send_rcv(priv, tx_msg, ELE_FW_AUTH_REQ_SZ, rx_msg,
+ ret = ele_msg_send_rcv(priv->priv_dev_ctx, tx_msg, ELE_FW_AUTH_REQ_SZ, rx_msg,
ELE_FW_AUTH_RSP_MSG_SZ);
if (ret < 0)
return ret;
@@ -251,7 +252,7 @@ int ele_debug_dump(struct se_if_priv *priv)
do {
memset(rx_msg, 0x0, ELE_DEBUG_DUMP_RSP_SZ);
- ret = ele_msg_send_rcv(priv, tx_msg, ELE_DEBUG_DUMP_REQ_SZ,
+ ret = ele_msg_send_rcv(priv->priv_dev_ctx, tx_msg, ELE_DEBUG_DUMP_REQ_SZ,
rx_msg, ELE_DEBUG_DUMP_RSP_SZ);
if (ret < 0)
return ret;
diff --git a/drivers/firmware/imx/ele_common.c b/drivers/firmware/imx/ele_common.c
index bc08ea2dcd87..707fb69431ba 100644
--- a/drivers/firmware/imx/ele_common.c
+++ b/drivers/firmware/imx/ele_common.c
@@ -46,8 +46,9 @@ int se_update_msg_chksum(u32 *msg, u32 msg_len)
return 0;
}
-int ele_msg_rcv(struct se_if_priv *priv, struct se_clbk_handle *se_clbk_hdl)
+int ele_msg_rcv(struct se_if_device_ctx *dev_ctx, struct se_clbk_handle *se_clbk_hdl)
{
+ struct se_if_priv *priv = dev_ctx->priv;
bool is_rsp_wait_with_timeout = false;
bool wait_uninterruptible = false;
unsigned long remaining_jiffies;
@@ -134,7 +135,7 @@ int ele_msg_rcv(struct se_if_priv *priv, struct se_clbk_handle *se_clbk_hdl)
return ret;
}
-int ele_msg_send(struct se_if_priv *priv,
+int ele_msg_send(struct se_if_device_ctx *dev_ctx,
void *tx_msg,
int tx_msg_sz)
{
@@ -146,9 +147,9 @@ int ele_msg_send(struct se_if_priv *priv,
* carried in the message.
*/
if (header->size << 2 != tx_msg_sz) {
- dev_err(priv->dev,
- "User buf hdr: 0x%x, sz mismatced with input-sz (%d != %d).",
- *(u32 *)header, header->size << 2, tx_msg_sz);
+ dev_err(dev_ctx->priv->dev,
+ "%s: User buf hdr: 0x%x, sz mismatched with input-sz (%d != %d).",
+ dev_ctx->devname, *(u32 *)header, header->size << 2, tx_msg_sz);
return -EINVAL;
}
@@ -158,9 +159,10 @@ int ele_msg_send(struct se_if_priv *priv,
* caller-provided tx_msg pointer after mbox_send_message() returns, so
* the caller-owned buffer may be released after a successful send.
*/
- err = mbox_send_message(priv->tx_chan, tx_msg);
+ err = mbox_send_message(dev_ctx->priv->tx_chan, tx_msg);
if (err < 0) {
- dev_err(priv->dev, "Error: mbox_send_message failure.\n");
+ dev_err(dev_ctx->priv->dev,
+ "%s: Error: mbox_send_message failure.", dev_ctx->devname);
return err;
}
@@ -172,38 +174,41 @@ static void ele_msg_send_rcv_cleanup(struct se_if_priv *priv)
unsigned long flags;
spin_lock_irqsave(&priv->waiting_rsp_clbk_hdl.clbk_rx_lock, flags);
+ priv->waiting_rsp_clbk_hdl.dev_ctx = NULL;
priv->waiting_rsp_clbk_hdl.rx_msg = NULL;
priv->waiting_rsp_clbk_hdl.rx_msg_sz = 0;
spin_unlock_irqrestore(&priv->waiting_rsp_clbk_hdl.clbk_rx_lock, flags);
}
-/* API used for send/receive blocking call. */
-int ele_msg_send_rcv(struct se_if_priv *priv, void *tx_msg, int tx_msg_sz,
- void *rx_msg, int exp_rx_msg_sz)
+/* API used for send/receive blocking calls. */
+int ele_msg_send_rcv(struct se_if_device_ctx *dev_ctx, void *tx_msg,
+ int tx_msg_sz, void *rx_msg, int exp_rx_msg_sz)
{
+ struct se_if_priv *priv = dev_ctx->priv;
unsigned long flags;
int err;
guard(mutex)(&priv->se_if_cmd_lock);
if (atomic_read(&priv->fw_busy)) {
- dev_dbg(priv->dev, "ELE became unresponsive.\n");
+ dev_dbg(priv->dev, "%s: ELE became unresponsive.\n", dev_ctx->devname);
return -EBUSY;
}
reinit_completion(&priv->waiting_rsp_clbk_hdl.done);
/* Publish rx_msg/rx_msg_sz under the lock read by se_if_rx_callback(). */
spin_lock_irqsave(&priv->waiting_rsp_clbk_hdl.clbk_rx_lock, flags);
+ priv->waiting_rsp_clbk_hdl.dev_ctx = dev_ctx;
priv->waiting_rsp_clbk_hdl.rx_msg_sz = exp_rx_msg_sz;
priv->waiting_rsp_clbk_hdl.rx_msg = rx_msg;
spin_unlock_irqrestore(&priv->waiting_rsp_clbk_hdl.clbk_rx_lock, flags);
- err = ele_msg_send(priv, tx_msg, tx_msg_sz);
+ err = ele_msg_send(dev_ctx, tx_msg, tx_msg_sz);
if (err < 0) {
ele_msg_send_rcv_cleanup(priv);
return err;
}
- err = ele_msg_rcv(priv, &priv->waiting_rsp_clbk_hdl);
+ err = ele_msg_rcv(dev_ctx, &priv->waiting_rsp_clbk_hdl);
if (priv->waiting_rsp_clbk_hdl.signal_rcvd) {
/*
@@ -214,7 +219,8 @@ int ele_msg_send_rcv(struct se_if_priv *priv, void *tx_msg, int tx_msg_sz,
if (err > 0)
err = -ERESTARTSYS;
priv->waiting_rsp_clbk_hdl.signal_rcvd = false;
- dev_dbg(priv->dev, "Err[0x%x]:Interrupted by signal.", err);
+ dev_dbg(priv->dev, "%s: Err[0x%x]:Interrupted by signal.",
+ dev_ctx->devname, err);
}
ele_msg_send_rcv_cleanup(priv);
@@ -243,6 +249,7 @@ void se_if_rx_callback(struct mbox_client *mbox_cl, void *msg)
{
struct se_clbk_handle *se_clbk_hdl;
struct device *dev = mbox_cl->dev;
+ const char *devname = NULL;
struct se_msg_hdr *header;
bool sz_mismatch = false;
struct se_if_priv *priv;
@@ -266,7 +273,7 @@ void se_if_rx_callback(struct mbox_client *mbox_cl, void *msg)
if (header->tag == priv->if_defs->cmd_tag) {
se_clbk_hdl = &priv->cmd_receiver_clbk_hdl;
spin_lock_irqsave(&se_clbk_hdl->clbk_rx_lock, flags);
- if (!se_clbk_hdl->rx_msg) {
+ if (!se_clbk_hdl->dev_ctx || !se_clbk_hdl->rx_msg) {
spin_unlock_irqrestore(&se_clbk_hdl->clbk_rx_lock, flags);
dev_warn(dev, "No command receiver registered for message: %.8x\n",
*((u32 *)header));
@@ -280,8 +287,8 @@ void se_if_rx_callback(struct mbox_client *mbox_cl, void *msg)
* SE_IOCTL_ENABLE_CMD_RCV and is not subject to the timeout/circuit-
* breaker handling used for rsp_tag messages.
*/
- dev_dbg(dev, "Selecting cmd receiver: for mesg header:0x%x.",
- *(u32 *)header);
+ dev_dbg(dev, "Selecting cmd receiver:%s for mesg header:0x%x.",
+ se_clbk_hdl->dev_ctx->devname, *(u32 *)header);
/*
* Pre-allocated buffer of MAX_NVM_MSG_LEN
@@ -296,13 +303,14 @@ void se_if_rx_callback(struct mbox_client *mbox_cl, void *msg)
* Clamp the copy length to the pre-allocated receiver buffer (MAX_NVM_MSG_LEN).
*/
se_clbk_hdl->rx_msg_sz = min_t(u32, rx_msg_sz, MAX_NVM_MSG_LEN);
+ devname = se_clbk_hdl->dev_ctx->devname;
memcpy(se_clbk_hdl->rx_msg, msg, se_clbk_hdl->rx_msg_sz);
complete(&se_clbk_hdl->done);
spin_unlock_irqrestore(&se_clbk_hdl->clbk_rx_lock, flags);
if (sz_mismatch)
dev_err(dev,
- "CMD-RCVER NVM: hdr(0x%x) with different sz(%d != %d).\n",
- *(u32 *)header,
+ "%s: CMD-RCVER NVM: hdr(0x%x) with different sz(%d != %d).\n",
+ devname, *(u32 *)header,
(header->size << 2), rx_msg_sz);
} else if (header->tag == priv->if_defs->rsp_tag) {
bool exception_for_sz_mismatch = check_hdr_exception_for_sz(priv, header);
@@ -324,8 +332,8 @@ void se_if_rx_callback(struct mbox_client *mbox_cl, void *msg)
return;
}
exp_rx_msg_sz = se_clbk_hdl->rx_msg_sz;
- dev_dbg(dev, "Selecting resp waiter: for mesg header:0x%x.",
- *(u32 *)header);
+ dev_dbg(dev, "Selecting resp waiter:%s for mesg header:0x%x.",
+ se_clbk_hdl->dev_ctx->devname, *(u32 *)header);
/*
* For rsp_tag traffic, the sender provides the expected response
@@ -337,14 +345,15 @@ void se_if_rx_callback(struct mbox_client *mbox_cl, void *msg)
sz_mismatch = true;
se_clbk_hdl->rx_msg_sz = min(rx_msg_sz, exp_rx_msg_sz);
+ devname = se_clbk_hdl->dev_ctx->devname;
memcpy(se_clbk_hdl->rx_msg, msg, se_clbk_hdl->rx_msg_sz);
complete(&se_clbk_hdl->done);
spin_unlock_irqrestore(&se_clbk_hdl->clbk_rx_lock, flags);
if (sz_mismatch)
dev_err(dev,
- "Rsp to CMD: hdr(0x%x) with different sz(%d != %d).\n",
- *(u32 *)header,
+ "%s: Rsp to CMD: hdr(0x%x) with different sz(%d != %d).\n",
+ devname, *(u32 *)header,
(header->size << 2), exp_rx_msg_sz);
} else {
dev_err(dev, "Failed to select a device for message: %.8x\n",
diff --git a/drivers/firmware/imx/ele_common.h b/drivers/firmware/imx/ele_common.h
index 7bf2febefc45..07e6b6a1bafa 100644
--- a/drivers/firmware/imx/ele_common.h
+++ b/drivers/firmware/imx/ele_common.h
@@ -16,12 +16,12 @@
int se_update_msg_chksum(u32 *msg, u32 msg_len);
-int ele_msg_rcv(struct se_if_priv *priv, struct se_clbk_handle *se_clbk_hdl);
+int ele_msg_rcv(struct se_if_device_ctx *dev_ctx, struct se_clbk_handle *se_clbk_hdl);
-int ele_msg_send(struct se_if_priv *priv, void *tx_msg, int tx_msg_sz);
+int ele_msg_send(struct se_if_device_ctx *dev_ctx, void *tx_msg, int tx_msg_sz);
-int ele_msg_send_rcv(struct se_if_priv *priv, void *tx_msg, int tx_msg_sz,
- void *rx_msg, int exp_rx_msg_sz);
+int ele_msg_send_rcv(struct se_if_device_ctx *dev_ctx, void *tx_msg,
+ int tx_msg_sz, void *rx_msg, int exp_rx_msg_sz);
void se_if_rx_callback(struct mbox_client *mbox_cl, void *msg);
diff --git a/drivers/firmware/imx/se_ctrl.c b/drivers/firmware/imx/se_ctrl.c
index 53091cc37e7e..a8974eef190b 100644
--- a/drivers/firmware/imx/se_ctrl.c
+++ b/drivers/firmware/imx/se_ctrl.c
@@ -284,6 +284,36 @@ static int get_se_soc_info(struct se_if_priv *priv, const struct se_soc_info *se
return 0;
}
+static int init_misc_device_context(struct se_if_priv *priv, int ch_id,
+ struct se_if_device_ctx **new_dev_ctx)
+{
+ const char *err_str = "Failed to allocate memory";
+ struct se_if_device_ctx *dev_ctx;
+ int ret = -ENOMEM;
+
+ dev_ctx = kzalloc_obj(*dev_ctx, GFP_KERNEL);
+
+ if (!dev_ctx)
+ return ret;
+
+ dev_ctx->devname = kasprintf(GFP_KERNEL, "%s0_ch%d",
+ get_se_if_name(priv->if_defs->se_if_type),
+ ch_id);
+ if (!dev_ctx->devname)
+ goto exit;
+
+ dev_ctx->priv = priv;
+ *new_dev_ctx = dev_ctx;
+
+ return 0;
+exit:
+ *new_dev_ctx = NULL;
+
+ kfree(dev_ctx->devname);
+ kfree(dev_ctx);
+ return dev_err_probe(priv->dev, ret, "%s", err_str);
+}
+
static int se_if_request_channel(struct device *dev, struct mbox_chan **chan,
struct mbox_client *cl, const char *name)
{
@@ -328,6 +358,11 @@ static void se_if_probe_cleanup(void *plat_dev)
dev_set_drvdata(dev, NULL);
+ if (priv->priv_dev_ctx) {
+ kfree(priv->priv_dev_ctx->devname);
+ kfree(priv->priv_dev_ctx);
+ }
+
kfree(priv);
}
@@ -425,6 +460,12 @@ static int se_if_probe(struct platform_device *pdev)
load_fw->imem_mgmt = true;
}
+ ret = init_misc_device_context(priv, 0, &priv->priv_dev_ctx);
+ if (ret)
+ return dev_err_probe(dev, ret,
+ "Failed[0x%x] to create device contexts.",
+ ret);
+
if (if_node->if_defs.se_if_type == SE_TYPE_ID_HSM) {
ret = get_se_soc_info(priv, se_info);
if (ret)
diff --git a/drivers/firmware/imx/se_ctrl.h b/drivers/firmware/imx/se_ctrl.h
index 54b2a262a2c3..dd4a1ea7e35a 100644
--- a/drivers/firmware/imx/se_ctrl.h
+++ b/drivers/firmware/imx/se_ctrl.h
@@ -20,6 +20,7 @@
#define MESSAGING_VERSION_7 0x7
struct se_clbk_handle {
+ struct se_if_device_ctx *dev_ctx;
struct completion done;
bool signal_rcvd;
u32 rx_msg_sz;
@@ -44,6 +45,12 @@ struct se_imem_buf {
u32 state;
};
+/* Private struct for each char device instance. */
+struct se_if_device_ctx {
+ struct se_if_priv *priv;
+ const char *devname;
+};
+
/* Header of the messages exchange with the EdgeLock Enclave */
struct se_msg_hdr {
u8 ver;
@@ -106,6 +113,8 @@ struct se_if_priv {
struct se_fw_load_info load_fw;
atomic_t fw_busy;
+
+ struct se_if_device_ctx *priv_dev_ctx;
};
char *get_se_if_name(u8 se_if_id);
--
2.43.0
^ permalink raw reply related [flat|nested] 15+ messages in thread* Re: [PATCH v35 4/7] firmware: imx: device context dedicated to priv
2026-08-06 11:51 ` [PATCH v35 4/7] firmware: imx: device context dedicated to priv pankaj.gupta
@ 2026-08-06 11:15 ` sashiko-bot
0 siblings, 0 replies; 15+ messages in thread
From: sashiko-bot @ 2026-08-06 11:15 UTC (permalink / raw)
To: pankaj.gupta; +Cc: Frank.Li, conor+dt, devicetree, imx, robh
Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
New issues:
- [Medium] The `devname` string pointer is cached inside `clbk_rx_lock` but dereferenced after the lock is released and the completion is signaled, leading to a potential Use-After-Free.
Pre-existing issues:
- [High] Returning `-ERESTARTSYS` after a successful firmware transaction causes the VFS to silently retry the ioctl, leading to duplicate execution of non-idempotent firmware commands.
--
--- Patch [4]: [PATCH v35 4/7] firmware: imx: device context dedicated to priv ---
commit df99e6bab818347c619050f003cdaa34c153bd90
Author: Pankaj Gupta <pankaj.gupta@nxp.com>
firmware: imx: device context dedicated to priv
Add priv_dev_ctx to prepare enabling misc-device context based send-receive
path, to communicate with FW. No functionality change.
> diff --git a/drivers/firmware/imx/ele_common.c b/drivers/firmware/imx/ele_common.c
> index bc08ea2dcd87d..707fb69431baa 100644
> --- a/drivers/firmware/imx/ele_common.c
> +++ b/drivers/firmware/imx/ele_common.c
[ ... ]
> @@ -214,7 +219,8 @@ int ele_msg_send_rcv(struct se_if_priv *priv, void *tx_msg, int tx_msg_sz,
> if (err > 0)
> err = -ERESTARTSYS;
[Severity: High]
This is a pre-existing issue, but does returning -ERESTARTSYS after a
successful firmware transaction cause problems with the VFS layer?
If a signal is delivered to the process while waiting, ele_msg_rcv() catches
it but waits uninterruptibly because the command is already in flight. Once
the firmware successfully responds, ele_msg_rcv() returns the positive
response size.
However, in ele_msg_send_rcv(), seeing signal_rcvd is true causes the
positive return value to be explicitly replaced with -ERESTARTSYS:
if (err > 0)
err = -ERESTARTSYS;
Would this cause the VFS layer to automatically restart the syscall,
leading to the same firmware command being issued a second time, which
might be unsafe for non-idempotent operations like key generation?
> priv->waiting_rsp_clbk_hdl.signal_rcvd = false;
> - dev_dbg(priv->dev, "Err[0x%x]:Interrupted by signal.", err);
> + dev_dbg(priv->dev, "%s: Err[0x%x]:Interrupted by signal.",
> + dev_ctx->devname, err);
> }
[ ... ]
> @@ -296,13 +303,14 @@ void se_if_rx_callback(struct mbox_client *mbox_cl, void *msg)
> * Clamp the copy length to the pre-allocated receiver buffer (MAX_NVM_MSG_LEN).
> */
> se_clbk_hdl->rx_msg_sz = min_t(u32, rx_msg_sz, MAX_NVM_MSG_LEN);
> + devname = se_clbk_hdl->dev_ctx->devname;
> memcpy(se_clbk_hdl->rx_msg, msg, se_clbk_hdl->rx_msg_sz);
> complete(&se_clbk_hdl->done);
> spin_unlock_irqrestore(&se_clbk_hdl->clbk_rx_lock, flags);
> if (sz_mismatch)
> dev_err(dev,
> - "CMD-RCVER NVM: hdr(0x%x) with different sz(%d != %d).\n",
> - *(u32 *)header,
> + "%s: CMD-RCVER NVM: hdr(0x%x) with different sz(%d != %d).\n",
> + devname, *(u32 *)header,
> (header->size << 2), rx_msg_sz);
[Severity: Medium]
Could this code trigger a use-after-free of the devname string when dynamic
file descriptor lifetimes are fully implemented?
In se_if_rx_callback(), the devname pointer is cached locally, but the lock
is then dropped and complete() is called. This can wake up a waiting thread.
If the waking thread immediately closes the file descriptor, could dev_ctx
and its dynamically allocated devname string be freed before the dev_err()
statement above finishes executing?
[ ... ]
> @@ -337,14 +345,15 @@ void se_if_rx_callback(struct mbox_client *mbox_cl, void *msg)
> sz_mismatch = true;
>
> se_clbk_hdl->rx_msg_sz = min(rx_msg_sz, exp_rx_msg_sz);
> + devname = se_clbk_hdl->dev_ctx->devname;
> memcpy(se_clbk_hdl->rx_msg, msg, se_clbk_hdl->rx_msg_sz);
> complete(&se_clbk_hdl->done);
> spin_unlock_irqrestore(&se_clbk_hdl->clbk_rx_lock, flags);
>
> if (sz_mismatch)
> dev_err(dev,
> - "Rsp to CMD: hdr(0x%x) with different sz(%d != %d).\n",
> - *(u32 *)header,
> + "%s: Rsp to CMD: hdr(0x%x) with different sz(%d != %d).\n",
> + devname, *(u32 *)header,
> (header->size << 2), exp_rx_msg_sz);
[Severity: Medium]
Does this branch also share the same potential use-after-free pattern as the
cmd_tag handling branch above, if the waking thread frees dev_ctx before
dev_err() completes?
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260806-imx-se-if-v35-0-11b25bb308ef@nxp.com?part=4
^ permalink raw reply [flat|nested] 15+ messages in thread
* [PATCH v35 5/7] firmware: imx: adds miscdev
2026-08-06 11:51 [PATCH v35 0/7] firmware: imx: driver for NXP secure-enclave pankaj.gupta
` (3 preceding siblings ...)
2026-08-06 11:51 ` [PATCH v35 4/7] firmware: imx: device context dedicated to priv pankaj.gupta
@ 2026-08-06 11:51 ` pankaj.gupta
2026-08-06 11:27 ` sashiko-bot
2026-08-06 11:51 ` [PATCH v35 6/7] arm64: dts: imx8ulp: add secure enclave node pankaj.gupta
2026-08-06 11:51 ` [PATCH v35 7/7] arm64: dts: imx8ulp: add reserved memory for EdgeLock Enclave pankaj.gupta
6 siblings, 1 reply; 15+ messages in thread
From: pankaj.gupta @ 2026-08-06 11:51 UTC (permalink / raw)
To: Jonathan Corbet, Shuah Khan, Rob Herring, Krzysztof Kozlowski,
Conor Dooley, Frank Li, Sascha Hauer, Pengutronix Kernel Team,
Fabio Estevam, Pankaj Gupta
Cc: linux-doc, linux-kernel, devicetree, imx, linux-arm-kernel,
sashiko-bot
From: Pankaj Gupta <pankaj.gupta@nxp.com>
Adds the driver for communication interface to secure-enclave, that
enables exchanging messages with NXP secure enclave HW IP(s)
like EdgeLock Enclave, from:
- User-Space Applications via character driver.
ABI documentation for the NXP secure-enclave driver.
User-space library using this driver:
- i.MX Secure Enclave library:
-- URL: https://github.com/nxp-imx/imx-secure-enclave.git,
- i.MX Secure Middle-Ware:
-- URL: https://github.com/nxp-imx/imx-smw.git
Following checks are performed on the incoming msg-header,
to block exchanging invalid arbitrary commands:
- maximum allowed words,
- check if command-tag & response-tag are valid
- version,
- command id validation check, to allow limited base-line API(s)
and restrict following:
- exchanging power management commands.
- reset requests.
- BBSM configuration requests.
- re-initializing the FW.
- RNG init
- CAAM resource release management
- SE's internal memory management.
from user-space.
Signed-off-by: Pankaj Gupta <pankaj.gupta@nxp.com>
---
Changes from v34 to v35:
1. [High] Close request built with base API version but validated with
FW API version.
se_close_session()/se_close_storage() formatted the request header
with se_fill_cmd_msg_hdr(..., is_base_api=true) yet validated the
response with se_val_rsp_hdr_n_status(..., is_base_api=false). The
version mismatch made validation fail with -EINVAL, so teardown
closes always reported failure and the FW session/storage handle was
leaked. Format the close requests with the FW API version to match
the response validation.
2. [High] Storage handle recorded only after receiver registration.
In fw_api_specific_ops() ELE_STORAGE_OPEN_REQ, dev_ctx->strg_hdl was
assigned only after a successful set_dev_ctx_as_command_receiver().
A failing registration (e.g. -EBUSY) left strg_hdl at 0 while the
ioctl still returned success, so cleanup_dev_ctx() never closed the
handle and it leaked in FW. Record the handle first, then register.
3. [High] Close request did not verify the payload handle belongs to the
caller.
ele_uapi_allowed_fw_cmd() only checked that the calling context had
some session/storage open, not that the handle carried in the payload
(data[0]) matched. A process could submit a close for another
process's handle. Thread the tx buffer size through
se_chk_tx_msg_hdr()/ele_uapi_allowed_fw_cmd() and, for the session
and storage close requests, reject a buffer too short to hold data[0]
or a data[0] that does not match this context's own handle. Checking
the size first also keeps the data[0] read in bounds.
4. [High] Concurrent close() racing driver unbind could transmit on a
freed mailbox channel.
se_close_session()/se_close_storage() hardcoded priv->priv_dev_ctx as
the transport, bypassing the going_away teardown safeguard in
ele_msg_send_rcv(). A userspace close() racing unbind could send on a
freed priv->tx_chan (use-after-free in mbox_send_message()). Pass the
transport context explicitly: cleanup_dev_ctx() sends userspace-close
(is_fclose) traffic on the caller's own dev_ctx so the going_away
check rejects it with -ENODEV, while the teardown path keeps using
priv_dev_ctx, the only context let through going_away for
teardown-close messages while tx_chan is still live.
5. [Medium] Interrupted wait discarded an already-delivered FW response
and leaked the handle.
On an interrupted wait ele_msg_send_rcv() converts a successful
(err > 0) result to -ERESTARTSYS. The ioctl handler returned early on
err < 0 without recording the session/storage handle, so a handle the
FW had already allocated (and returned in the delivered response) was
never tracked and leaked. Keep returning -EINTR to userspace so it can
run its signal handler and the syscall is not auto-restarted, but
before returning, validate the already-delivered response and, if it
is well formed, copy out data and run fw_api_specific_ops() so the
handle is recorded and closed on teardown. No memory is leaked: the
err < 0 path still calls se_ioctl_cmd_snd_rcv_cleanup() and the tx/rx
buffers are freed via __free(kfree).
Reported-by: sashiko-bot <sashiko-bot@kernel.org>
Closes: https://sashiko.dev/#/patchset/20260805-imx-se-if-v34-0-7e4713d14e0a@nxp.com?part=5
---
Documentation/ABI/testing/se-cdev | 44 +
drivers/firmware/imx/Makefile | 2 +-
drivers/firmware/imx/ele_base_msg.c | 84 +-
drivers/firmware/imx/ele_base_msg.h | 19 +
drivers/firmware/imx/ele_common.c | 131 ++-
drivers/firmware/imx/ele_common.h | 7 +
drivers/firmware/imx/ele_fw_api.c | 241 +++++
drivers/firmware/imx/ele_fw_api.h | 31 +
drivers/firmware/imx/se_ctrl.c | 1645 ++++++++++++++++++++++++++++++++++-
drivers/firmware/imx/se_ctrl.h | 90 ++
include/uapi/linux/se_ioctl.h | 97 +++
11 files changed, 2340 insertions(+), 51 deletions(-)
diff --git a/Documentation/ABI/testing/se-cdev b/Documentation/ABI/testing/se-cdev
new file mode 100644
index 000000000000..c6b8e16bda78
--- /dev/null
+++ b/Documentation/ABI/testing/se-cdev
@@ -0,0 +1,44 @@
+What: /dev/<se>_mu[0-9]+_ch[0-9]+
+Date: Mar 2025
+KernelVersion: 6.8
+Contact: linux-imx@nxp.com, pankaj.gupta@nxp.com
+Description:
+ NXP offers multiple hardware IP(s) for secure enclaves like EdgeLock-
+ Enclave(ELE), SECO. The character device file descriptors
+ /dev/<se>_mu*_ch* are the interface between userspace NXP's secure-
+ enclave shared library and the kernel driver.
+
+ The ioctl(2)-based ABI is defined and documented in
+ [include]<linux/firmware/imx/ele_mu_ioctl.h>.
+ ioctl(s) are used primarily for:
+
+ - shared memory management
+ - allocation of I/O buffers
+ - getting mu info
+ - setting a dev-ctx as receiver to receive all the commands from FW
+ - getting SoC info
+ - send command and receive command response
+
+ The following file operations are supported:
+
+ open(2)
+ Currently the only useful flags are O_RDWR.
+
+ read(2)
+ Every read() from the opened character device context is waiting on
+ wait_event_interruptible, that gets set by the registered mailbox callback
+ function, indicating a message received from the firmware on message-
+ unit.
+
+ write(2)
+ Every write() to the opened character device context needs to acquire
+ mailbox_lock before sending message on to the message unit.
+
+ close(2)
+ Stops and frees up the I/O contexts that were associated
+ with the file descriptor.
+
+Users: https://github.com/nxp-imx/imx-secure-enclave.git,
+ https://github.com/nxp-imx/imx-smw.git,
+ crypto/skcipher,
+ drivers/nvmem/imx-ocotp-ele.c
diff --git a/drivers/firmware/imx/Makefile b/drivers/firmware/imx/Makefile
index 4412b15846b1..3f41131a0fdc 100644
--- a/drivers/firmware/imx/Makefile
+++ b/drivers/firmware/imx/Makefile
@@ -4,5 +4,5 @@ obj-$(CONFIG_IMX_SCU) += imx-scu.o misc.o imx-scu-irq.o rm.o imx-scu-soc.o
obj-${CONFIG_IMX_SCMI_CPU_DRV} += sm-cpu.o
obj-${CONFIG_IMX_SCMI_MISC_DRV} += sm-misc.o
obj-${CONFIG_IMX_SCMI_LMM_DRV} += sm-lmm.o
-sec_enclave-objs = se_ctrl.o ele_common.o ele_base_msg.o
+sec_enclave-objs = se_ctrl.o ele_common.o ele_base_msg.o ele_fw_api.o
obj-${CONFIG_IMX_SEC_ENCLAVE} += sec_enclave.o
diff --git a/drivers/firmware/imx/ele_base_msg.c b/drivers/firmware/imx/ele_base_msg.c
index b70e3ef88a16..2da8817af092 100644
--- a/drivers/firmware/imx/ele_base_msg.c
+++ b/drivers/firmware/imx/ele_base_msg.c
@@ -15,13 +15,57 @@
#define FW_DBG_DUMP_FIXED_STR "ELE"
+int ele_uapi_allowed_base_cmd(struct se_if_priv *priv,
+ struct se_msg_hdr *header)
+{
+ switch (header->command) {
+ case ELE_PING_REQ: return 0;
+ case ELE_DEBUG_DUMP_REQ: return 0;
+ case ELE_OEM_AUTH_CONTAINER_REQ: return 0;
+ case ELE_OEM_VERIFY_IMAGE_REQ: return 0;
+ case ELE_OEM_REL_CONTAINER_REQ: return 0;
+ case ELE_FW_LIFE_CYCLE_REQ: return 0;
+ case ELE_READ_FUSE_REQ: return 0;
+ case ELE_GET_FW_VERS_REQ: return 0;
+ case ELE_RETURN_LIFE_CYCLE_REQ: return 0;
+ case ELE_GET_EVENT_REQ: return 0;
+ case ELE_COMMIT_REQ: return 0;
+ case ELE_GEN_KEY_BLOB_REQ: return 0;
+ case ELE_GET_FW_STATUS_REQ: return 0;
+ case ELE_XIP_DECRYPT_REQ: return 0;
+ case ELE_WRITE_FUSE: return 0;
+ case ELE_GET_INFO_REQ: return 0;
+ case ELE_DEV_ATTEST_REQ: return 0;
+ case ELE_WRITE_SHADOW_FUSE_REQ: return 0;
+ case ELE_READ_SHADOW_FUSE_REQ: return 0;
+ default:
+ return -EACCES;
+ }
+}
+
static void ele_get_info_cleanup(struct se_if_priv *priv, u32 *buf, dma_addr_t d_addr,
size_t size)
{
- if (priv->mem_pool)
- gen_pool_free(priv->mem_pool, (unsigned long)buf, size);
- else
- dma_free_coherent(priv->dev, size, buf, d_addr);
+ /* For the case when priv->mem_pool != NULL:
+ *
+ * If this probe-time transaction timed out, the firmware may
+ * still write into the SRAM buffer after this function returns.
+ * Do not release it back to the pool while the firmware-busy
+ * circuit breaker still marks this context as owning an
+ * outstanding transaction. The buffer is reclaimed with the
+ * device on unbind; leaking this fixed-size probe buffer is
+ * preferable to letting the firmware corrupt reused pool memory.
+ * This mirrors the guard already applied on the shared-memory
+ * cleanup path below.
+ */
+
+ if (priv->mem_pool) {
+ if (se_is_fw_busy_ctx(priv->priv_dev_ctx))
+ return;
+ se_cleanup_mem_pool_buf(priv->priv_dev_ctx, true);
+ } else {
+ se_dev_ctx_shared_mem_cleanup(priv->priv_dev_ctx);
+ }
}
int ele_get_info(struct se_if_priv *priv, struct ele_dev_info *s_info)
@@ -34,6 +78,7 @@ int ele_get_info(struct se_if_priv *priv, struct ele_dev_info *s_info)
if (!priv)
return -EINVAL;
+ guard(mutex)(&priv->priv_dev_ctx->fops_lock);
memset(s_info, 0x0, sizeof(*s_info));
struct se_api_msg *tx_msg __free(kfree) =
@@ -47,24 +92,23 @@ int ele_get_info(struct se_if_priv *priv, struct ele_dev_info *s_info)
return -ENOMEM;
get_info_len = ELE_GET_INFO_BUFF_SZ;
- if (priv->mem_pool)
- get_info_data = gen_pool_dma_alloc(priv->mem_pool,
- get_info_len,
- &get_info_addr);
- else
- get_info_data = dma_alloc_coherent(priv->dev,
- get_info_len,
- &get_info_addr,
- GFP_KERNEL);
- if (!get_info_data) {
- dev_err(priv->dev,
- "%s: Failed to allocate get_info_addr.", __func__);
- return -ENOMEM;
+ if (priv->mem_pool) {
+ ret = se_get_mem_pool_buf(priv->priv_dev_ctx, &get_info_data,
+ &get_info_addr, get_info_len);
+ if (ret) {
+ dev_err(priv->dev, "Failed[0x%x] to alloc from gen_pool.\n", ret);
+ return -ENOMEM;
+ }
+ } else {
+ ret = get_shared_mem_slot(priv->priv_dev_ctx,
+ &get_info_len, &get_info_addr,
+ &get_info_data);
+ if (ret) {
+ dev_err(priv->dev, "Failed to allocate buffer.\n");
+ return -ENOMEM;
+ }
}
- /* gen_pool_dma_alloc() does not zero the buffer. */
- memset(get_info_data, 0, get_info_len);
-
se_fill_cmd_msg_hdr(priv, (struct se_msg_hdr *)&tx_msg->header,
ELE_GET_INFO_REQ, ELE_GET_INFO_REQ_MSG_SZ, true);
diff --git a/drivers/firmware/imx/ele_base_msg.h b/drivers/firmware/imx/ele_base_msg.h
index d532c3f49449..475074580dd7 100644
--- a/drivers/firmware/imx/ele_base_msg.h
+++ b/drivers/firmware/imx/ele_base_msg.h
@@ -16,6 +16,23 @@
#define ELE_NONE_VAL 0x0
+#define ELE_OEM_AUTH_CONTAINER_REQ 0x87
+#define ELE_OEM_VERIFY_IMAGE_REQ 0x88
+#define ELE_OEM_REL_CONTAINER_REQ 0x89
+#define ELE_FW_LIFE_CYCLE_REQ 0x95
+#define ELE_READ_FUSE_REQ 0x97
+#define ELE_GET_FW_VERS_REQ 0x9d
+#define ELE_RETURN_LIFE_CYCLE_REQ 0xa0
+#define ELE_GET_EVENT_REQ 0xa2
+#define ELE_COMMIT_REQ 0xa8
+#define ELE_GEN_KEY_BLOB_REQ 0xaf
+#define ELE_GET_FW_STATUS_REQ 0xc5
+#define ELE_XIP_DECRYPT_REQ 0xc6
+#define ELE_WRITE_FUSE 0xd6
+#define ELE_DEV_ATTEST_REQ 0xdb
+#define ELE_WRITE_SHADOW_FUSE_REQ 0xf2
+#define ELE_READ_SHADOW_FUSE_REQ 0xf3
+
#define ELE_GET_INFO_REQ 0xda
#define ELE_GET_INFO_REQ_MSG_SZ 0x10
#define ELE_GET_INFO_RSP_MSG_SZ 0x08
@@ -97,4 +114,6 @@ int ele_service_swap(struct se_if_priv *priv, dma_addr_t addr,
int ele_fw_authenticate(struct se_if_priv *priv, dma_addr_t contnr_addr,
dma_addr_t img_addr);
int ele_debug_dump(struct se_if_priv *priv);
+int ele_uapi_allowed_base_cmd(struct se_if_priv *priv,
+ struct se_msg_hdr *header);
#endif
diff --git a/drivers/firmware/imx/ele_common.c b/drivers/firmware/imx/ele_common.c
index 707fb69431ba..3cf5c0b332f6 100644
--- a/drivers/firmware/imx/ele_common.c
+++ b/drivers/firmware/imx/ele_common.c
@@ -5,6 +5,28 @@
#include "ele_base_msg.h"
#include "ele_common.h"
+#include "ele_fw_api.h"
+#include "se_ctrl.h"
+
+int se_chk_tx_msg_hdr(struct se_if_device_ctx *dev_ctx, struct se_msg_hdr *header,
+ u32 tx_msg_sz)
+{
+ struct se_if_priv *priv = dev_ctx->priv;
+
+ if (!header->size || header->size > MAX_WORD_SIZE)
+ return -EINVAL;
+
+ if (header->tag != priv->if_defs->cmd_tag &&
+ header->tag != priv->if_defs->rsp_tag)
+ return -EINVAL;
+
+ if (header->ver == priv->if_defs->base_api_ver)
+ return ele_uapi_allowed_base_cmd(priv, header);
+ else if (header->ver == priv->if_defs->fw_api_ver)
+ return ele_uapi_allowed_fw_cmd(dev_ctx, header, tx_msg_sz);
+
+ return -EINVAL;
+}
/*
* se_update_msg_chksum() - calculate and update message checksum word.
@@ -46,6 +68,25 @@ int se_update_msg_chksum(u32 *msg, u32 msg_len)
return 0;
}
+static void se_mark_fw_busy(struct se_if_device_ctx *dev_ctx)
+{
+ struct se_if_priv *priv = dev_ctx->priv;
+ unsigned long flags;
+
+ spin_lock_irqsave(&priv->fw_busy_lock, flags);
+ if (!priv->fw_busy_dev_ctx) {
+ kref_get(&dev_ctx->refcount);
+ priv->fw_busy_dev_ctx = dev_ctx;
+ atomic_set(&priv->fw_busy, 1);
+ }
+ spin_unlock_irqrestore(&priv->fw_busy_lock, flags);
+}
+
+void set_se_rcv_msg_timeout(struct se_if_device_ctx *dev_ctx, u32 timeout_ms)
+{
+ dev_ctx->rcv_msg_timeout_jiffies = msecs_to_jiffies(timeout_ms);
+}
+
int ele_msg_rcv(struct se_if_device_ctx *dev_ctx, struct se_clbk_handle *se_clbk_hdl)
{
struct se_if_priv *priv = dev_ctx->priv;
@@ -56,10 +97,20 @@ int ele_msg_rcv(struct se_if_device_ctx *dev_ctx, struct se_clbk_handle *se_clbk
unsigned long flags;
int ret;
- remaining_jiffies = msecs_to_jiffies(SE_RCV_MSG_DEFAULT_TIMEOUT_MS);
+ remaining_jiffies = dev_ctx->rcv_msg_timeout_jiffies;
if (se_clbk_hdl == &priv->waiting_rsp_clbk_hdl) {
is_rsp_wait_with_timeout = true;
deadline_jiffies = jiffies + remaining_jiffies;
+
+ /*
+ * Internal kernel transactions run on priv_dev_ctx (probe
+ * get_info/ping, FW auth, PM IMEM swap). They are not tied to a
+ * restartable syscall, so wait uninterruptibly: PM freezer fake
+ * signals must not abort them with -ERESTARTSYS. Userspace
+ * waiters stay interruptible via the deferred-signal path below.
+ */
+ if (se_clbk_hdl->dev_ctx == priv->priv_dev_ctx)
+ wait_uninterruptible = true;
}
do {
@@ -71,7 +122,7 @@ int ele_msg_rcv(struct se_if_device_ctx *dev_ctx, struct se_clbk_handle *se_clbk
spin_lock_irqsave(&se_clbk_hdl->clbk_rx_lock, flags);
se_clbk_hdl->rx_msg = NULL;
if (!completion_done(&se_clbk_hdl->done))
- atomic_set(&priv->fw_busy, 1);
+ se_mark_fw_busy(dev_ctx);
spin_unlock_irqrestore(&se_clbk_hdl->clbk_rx_lock, flags);
ret = -ETIMEDOUT;
break;
@@ -119,7 +170,7 @@ int ele_msg_rcv(struct se_if_device_ctx *dev_ctx, struct se_clbk_handle *se_clbk
spin_lock_irqsave(&se_clbk_hdl->clbk_rx_lock, flags);
se_clbk_hdl->rx_msg = NULL;
if (!completion_done(&se_clbk_hdl->done))
- atomic_set(&priv->fw_busy, 1);
+ se_mark_fw_busy(dev_ctx);
spin_unlock_irqrestore(&se_clbk_hdl->clbk_rx_lock, flags);
ret = -ETIMEDOUT;
@@ -128,8 +179,35 @@ int ele_msg_rcv(struct se_if_device_ctx *dev_ctx, struct se_clbk_handle *se_clbk
get_se_if_name(priv->if_defs->se_if_type));
break;
}
+
+ /*
+ * A positive wait return normally means a real response. During
+ * teardown, se_if_probe_cleanup() forces this wait to return via
+ * complete_all() with no response, while the enclave may still
+ * DMA into the shared buffer. Treat that as a failed transaction
+ * and arm the circuit breaker so the buffer is quarantined, not
+ * freed.
+ *
+ * rx_delivered tells the two apart: se_if_rx_callback() sets it
+ * under clbk_rx_lock only after copying a real response. This
+ * keeps teardown-time session/storage close responses from being
+ * mistaken for the forced abort, which would fail the close and
+ * leak its DMA buffer.
+ */
+ spin_lock_irqsave(&se_clbk_hdl->clbk_rx_lock, flags);
+ if (is_rsp_wait_with_timeout && atomic_read(&priv->going_away) &&
+ !se_clbk_hdl->rx_delivered) {
+ se_clbk_hdl->rx_msg = NULL;
+ se_mark_fw_busy(dev_ctx);
+ spin_unlock_irqrestore(&se_clbk_hdl->clbk_rx_lock, flags);
+ ret = -ENODEV;
+ break;
+ }
+ spin_unlock_irqrestore(&se_clbk_hdl->clbk_rx_lock, flags);
+
ret = se_clbk_hdl->rx_msg_sz;
break;
+
} while (ret < 0);
return ret;
@@ -190,16 +268,42 @@ int ele_msg_send_rcv(struct se_if_device_ctx *dev_ctx, void *tx_msg,
guard(mutex)(&priv->se_if_cmd_lock);
+ /*
+ * Arm the transaction under clbk_rx_lock. se_if_probe_cleanup() sets
+ * going_away under this same lock, then complete_all()s, so checking
+ * going_away and arming (reinit_completion() + publish) together makes
+ * teardown and arming mutually exclusive and closes the lost-wakeup
+ * window. priv_dev_ctx teardown-close commands are still let through.
+ *
+ * Check going_away before fw_busy so a caller racing unbind gets
+ * -ENODEV, not a misleading retryable -EBUSY. fw_busy is only
+ * atomic_read() here, so no fw_busy_lock is taken and there is no
+ * deadlock.
+ */
+ spin_lock_irqsave(&priv->waiting_rsp_clbk_hdl.clbk_rx_lock, flags);
+ if (atomic_read(&priv->going_away) &&
+ (dev_ctx != priv->priv_dev_ctx ||
+ !is_msg_xchng_for_tdown(tx_msg))) {
+ spin_unlock_irqrestore(&priv->waiting_rsp_clbk_hdl.clbk_rx_lock, flags);
+ return -ENODEV;
+ }
+
if (atomic_read(&priv->fw_busy)) {
+ spin_unlock_irqrestore(&priv->waiting_rsp_clbk_hdl.clbk_rx_lock, flags);
dev_dbg(priv->dev, "%s: ELE became unresponsive.\n", dev_ctx->devname);
return -EBUSY;
}
+
reinit_completion(&priv->waiting_rsp_clbk_hdl.done);
- /* Publish rx_msg/rx_msg_sz under the lock read by se_if_rx_callback(). */
- spin_lock_irqsave(&priv->waiting_rsp_clbk_hdl.clbk_rx_lock, flags);
priv->waiting_rsp_clbk_hdl.dev_ctx = dev_ctx;
priv->waiting_rsp_clbk_hdl.rx_msg_sz = exp_rx_msg_sz;
priv->waiting_rsp_clbk_hdl.rx_msg = rx_msg;
+ /*
+ * Arm a fresh transaction: clear the delivered flag so a stale value
+ * from a previous response cannot make ele_msg_rcv() mistake a
+ * teardown-forced complete_all() for a genuine firmware response.
+ */
+ priv->waiting_rsp_clbk_hdl.rx_delivered = false;
spin_unlock_irqrestore(&priv->waiting_rsp_clbk_hdl.clbk_rx_lock, flags);
err = ele_msg_send(dev_ctx, tx_msg, tx_msg_sz);
@@ -248,6 +352,7 @@ static bool check_hdr_exception_for_sz(struct se_if_priv *priv,
void se_if_rx_callback(struct mbox_client *mbox_cl, void *msg)
{
struct se_clbk_handle *se_clbk_hdl;
+ bool schedule_fw_busy_work = false;
struct device *dev = mbox_cl->dev;
const char *devname = NULL;
struct se_msg_hdr *header;
@@ -325,9 +430,13 @@ void se_if_rx_callback(struct mbox_client *mbox_cl, void *msg)
se_clbk_hdl = &priv->waiting_rsp_clbk_hdl;
spin_lock_irqsave(&se_clbk_hdl->clbk_rx_lock, flags);
if (!se_clbk_hdl->rx_msg) {
- /* Close circuit breaker on spinlock race */
- atomic_set(&priv->fw_busy, 0);
+ if (atomic_read(&priv->fw_busy))
+ schedule_fw_busy_work = true;
spin_unlock_irqrestore(&se_clbk_hdl->clbk_rx_lock, flags);
+
+ if (schedule_fw_busy_work)
+ schedule_work(&priv->fw_busy_work);
+
dev_info(dev, "ELE responded (late), recovery FW available.");
return;
}
@@ -347,6 +456,12 @@ void se_if_rx_callback(struct mbox_client *mbox_cl, void *msg)
se_clbk_hdl->rx_msg_sz = min(rx_msg_sz, exp_rx_msg_sz);
devname = se_clbk_hdl->dev_ctx->devname;
memcpy(se_clbk_hdl->rx_msg, msg, se_clbk_hdl->rx_msg_sz);
+ /*
+ * Mark that a genuine firmware response was delivered. ele_msg_rcv()
+ * reads this under clbk_rx_lock to avoid mistaking this response for
+ * a teardown-forced complete_all() wakeup.
+ */
+ se_clbk_hdl->rx_delivered = true;
complete(&se_clbk_hdl->done);
spin_unlock_irqrestore(&se_clbk_hdl->clbk_rx_lock, flags);
@@ -398,7 +513,7 @@ int se_val_rsp_hdr_n_status(struct se_if_priv *priv, struct se_api_msg *msg,
return -EINVAL;
}
- if (header->size > SE_MU_HDR_WORD_SZ) {
+ if (header->size > SE_MU_HDR_WORD_SZ && (sz >> 2) > SE_MU_HDR_WORD_SZ) {
status = RES_STATUS(msg->data[0]);
if (status != priv->if_defs->success_tag) {
dev_dbg(priv->dev, "Command Id[%x], Response Failure = 0x%x",
diff --git a/drivers/firmware/imx/ele_common.h b/drivers/firmware/imx/ele_common.h
index 07e6b6a1bafa..33bd00d45b8d 100644
--- a/drivers/firmware/imx/ele_common.h
+++ b/drivers/firmware/imx/ele_common.h
@@ -9,11 +9,15 @@
#include "se_ctrl.h"
#define SE_RCV_MSG_DEFAULT_TIMEOUT_MS 3000
+#define SE_RCV_MSG_LONG_TIMEOUT_MS 5000000
#define ELE_SUCCESS_IND 0xD6
#define IMX_ELE_FW_DIR "imx/ele/"
+#define MAX_WORD_SIZE 0x20
+
+void set_se_rcv_msg_timeout(struct se_if_device_ctx *dev_ctx, u32 val);
int se_update_msg_chksum(u32 *msg, u32 msg_len);
int ele_msg_rcv(struct se_if_device_ctx *dev_ctx, struct se_clbk_handle *se_clbk_hdl);
@@ -42,4 +46,7 @@ int se_save_imem_state(struct se_if_priv *priv, struct se_imem_buf *imem);
int se_restore_imem_state(struct se_if_priv *priv, struct se_imem_buf *imem);
+int se_chk_tx_msg_hdr(struct se_if_device_ctx *dev_ctx, struct se_msg_hdr *header,
+ u32 tx_msg_sz);
+
#endif /*__ELE_COMMON_H__ */
diff --git a/drivers/firmware/imx/ele_fw_api.c b/drivers/firmware/imx/ele_fw_api.c
new file mode 100644
index 000000000000..dd783932d835
--- /dev/null
+++ b/drivers/firmware/imx/ele_fw_api.c
@@ -0,0 +1,241 @@
+// SPDX-License-Identifier: GPL-2.0+
+/*
+ * Copyright 2026 NXP
+ */
+
+#include "se_ctrl.h"
+#include "ele_common.h"
+#include "ele_fw_api.h"
+
+static bool se_cmd_receiver_allowed_cmd(u8 cmd)
+{
+ switch (cmd) {
+ case ELE_SESSION_CLOSE_REQ:
+ case ELE_STORAGE_CLOSE_REQ:
+ case ELE_STORAGE_MASTER_IMPORT_REQ:
+ return true;
+ default:
+ return false;
+ }
+}
+
+int ele_uapi_allowed_fw_cmd(struct se_if_device_ctx *dev_ctx, struct se_msg_hdr *header,
+ u32 tx_msg_sz)
+{
+ struct se_api_msg *msg = container_of(header, struct se_api_msg, header);
+ struct se_if_priv *priv = dev_ctx->priv;
+ bool is_cmd_receiver = false;
+ int ret = 0;
+
+ scoped_guard(mutex, &priv->modify_lock)
+ if (dev_ctx == priv->cmd_receiver_clbk_hdl.dev_ctx)
+ is_cmd_receiver = true;
+
+ if (header->tag == priv->if_defs->cmd_tag) {
+ if (is_cmd_receiver && !se_cmd_receiver_allowed_cmd(header->command))
+ return -EOPNOTSUPP;
+ }
+
+ if (header->tag == priv->if_defs->rsp_tag && !is_cmd_receiver)
+ return -EOPNOTSUPP;
+
+ switch (header->command) {
+ case ELE_SESSION_OPEN_REQ:
+ /* Might be cleared as part of tear down. */
+ ret = dev_ctx->sess_hdl ? -EEXIST : 0;
+ break;
+ case ELE_SESSION_CLOSE_REQ:
+ /* Might be cleared as part of tear down. */
+ if (!dev_ctx->sess_hdl) {
+ ret = -ENXIO;
+ break;
+ }
+ /*
+ * A close request must target this context's own session. The
+ * handle to close is carried in the payload (data[0]); reject a
+ * request whose buffer is too short to hold it, or whose handle
+ * does not match this context. Checking the buffer size first
+ * also keeps the data[0] read in bounds. This stops one process
+ * from closing - and leaking - another process's session with a
+ * spoofed handle.
+ */
+ if (tx_msg_sz < ELE_SESSION_CLOSE_REQ_SZ ||
+ msg->data[0] != dev_ctx->sess_hdl)
+ ret = -EINVAL;
+ break;
+ case ELE_STORAGE_OPEN_REQ:
+ /* Might be cleared as part of tear down. */
+ ret = dev_ctx->strg_hdl ? -EEXIST : 0;
+ break;
+ case ELE_STORAGE_CLOSE_REQ:
+ /* Might be cleared as part of tear down. */
+ if (!dev_ctx->strg_hdl) {
+ ret = -ENXIO;
+ break;
+ }
+ /* Same self-ownership check as the session close above. */
+ if (tx_msg_sz < ELE_STORAGE_CLOSE_REQ_SZ ||
+ msg->data[0] != dev_ctx->strg_hdl)
+ ret = -EINVAL;
+ break;
+ }
+
+ return ret;
+}
+
+void fw_api_specific_ops(struct se_if_device_ctx *dev_ctx, struct se_api_msg *rx_msg)
+{
+ struct se_msg_hdr *header = &rx_msg->header;
+ struct se_if_priv *priv = dev_ctx->priv;
+
+ switch (header->command) {
+ case ELE_SESSION_OPEN_REQ:
+ dev_ctx->sess_hdl = rx_msg->data[1];
+ break;
+ case ELE_SESSION_CLOSE_REQ:
+ dev_ctx->sess_hdl = 0;
+ break;
+ case ELE_STORAGE_CLOSE_REQ:
+ scoped_guard(mutex, &priv->modify_lock)
+ unset_dev_ctx_as_command_receiver(dev_ctx);
+ dev_ctx->strg_hdl = 0;
+ break;
+ case ELE_STORAGE_OPEN_REQ: {
+ int rc = 0;
+
+ /*
+ * Record the storage handle before registering as command
+ * receiver. FW has already allocated the handle; if we assigned
+ * it only after a successful registration, a failing
+ * set_dev_ctx_as_command_receiver() (e.g. -EBUSY) would leave
+ * strg_hdl at 0 while the ioctl still returns success to
+ * userspace. The kernel would then never close the handle on
+ * teardown, leaking it in FW. Storing it first guarantees
+ * cleanup_dev_ctx() closes it regardless of registration.
+ */
+ dev_ctx->strg_hdl = rx_msg->data[1];
+
+ rc = set_dev_ctx_as_command_receiver(dev_ctx);
+ if (rc)
+ dev_err(priv->dev,
+ "Failed to register %s as CMD-Receiver: %d\n",
+ dev_ctx->devname, rc);
+ break;
+ }
+ default:
+ dev_dbg(priv->dev, "%s: Unknown command = 0x%x.",
+ dev_ctx->devname, header->command);
+ }
+}
+
+/*
+ * Return true when tx_msg is one of the close requests the driver issues
+ * from its own teardown path (session/storage close). ele_msg_send_rcv()
+ * uses this to let those close messages through even after going_away is
+ * set, so the kernel can still resynchronise session/storage state with FW.
+ */
+bool is_msg_xchng_for_tdown(void *tx_msg)
+{
+ struct se_msg_hdr *header = &((struct se_api_msg *)tx_msg)->header;
+
+ return (header->command == ELE_SESSION_CLOSE_REQ ||
+ header->command == ELE_STORAGE_CLOSE_REQ);
+}
+
+int se_close_session(struct se_if_device_ctx *dev_ctx, u32 session_hdl)
+{
+ struct se_api_msg *tx_msg __free(kfree) = NULL;
+ struct se_api_msg *rx_msg __free(kfree) = NULL;
+ struct se_if_priv *priv;
+ int ret;
+
+ if (!dev_ctx || !dev_ctx->priv)
+ return -EINVAL;
+
+ priv = dev_ctx->priv;
+
+ tx_msg = kzalloc(ELE_SESSION_CLOSE_REQ_SZ, GFP_KERNEL);
+ if (!tx_msg)
+ return -ENOMEM;
+
+ rx_msg = kzalloc(ELE_SESSION_CLOSE_RSP_SZ, GFP_KERNEL);
+ if (!rx_msg)
+ return -ENOMEM;
+
+ /*
+ * Session close is a FW-API command; format it with the FW API version
+ * so se_val_rsp_hdr_n_status() below (called with is_base_api = false,
+ * i.e. expecting fw_api_ver) does not reject the matching response and
+ * wrongly report the close as failed, which would leak the handle.
+ */
+ se_fill_cmd_msg_hdr(priv, (struct se_msg_hdr *)&tx_msg->header,
+ ELE_SESSION_CLOSE_REQ, ELE_SESSION_CLOSE_REQ_SZ, false);
+
+ tx_msg->data[0] = session_hdl;
+
+ /*
+ * Transmit on the caller's own context. Using dev_ctx (rather than
+ * hardcoding priv->priv_dev_ctx) keeps a userspace close() subject to
+ * the going_away check in ele_msg_send_rcv(): if unbind has begun and
+ * freed priv->tx_chan, the send is rejected with -ENODEV instead of
+ * touching the freed mailbox channel. The teardown path passes
+ * priv_dev_ctx so its resync closes are still let through.
+ */
+ ret = ele_msg_send_rcv(dev_ctx,
+ tx_msg,
+ ELE_SESSION_CLOSE_REQ_SZ,
+ rx_msg,
+ ELE_SESSION_CLOSE_RSP_SZ);
+ if (ret < 0)
+ return ret;
+
+ ret = se_val_rsp_hdr_n_status(priv,
+ rx_msg,
+ ELE_SESSION_CLOSE_REQ,
+ ELE_SESSION_CLOSE_RSP_SZ,
+ false);
+ return ret;
+}
+
+int se_close_storage(struct se_if_device_ctx *dev_ctx, u32 storage_hdl)
+{
+ struct se_api_msg *tx_msg __free(kfree) = NULL;
+ struct se_api_msg *rx_msg __free(kfree) = NULL;
+ struct se_if_priv *priv;
+ int ret;
+
+ if (!dev_ctx || !dev_ctx->priv)
+ return -EINVAL;
+
+ priv = dev_ctx->priv;
+
+ tx_msg = kzalloc(ELE_STORAGE_CLOSE_REQ_SZ, GFP_KERNEL);
+ if (!tx_msg)
+ return -ENOMEM;
+
+ rx_msg = kzalloc(ELE_STORAGE_CLOSE_RSP_SZ, GFP_KERNEL);
+ if (!rx_msg)
+ return -ENOMEM;
+
+ /* Same FW-API version handling as se_close_session() above. */
+ se_fill_cmd_msg_hdr(priv, (struct se_msg_hdr *)&tx_msg->header,
+ ELE_STORAGE_CLOSE_REQ, ELE_STORAGE_CLOSE_REQ_SZ, false);
+
+ tx_msg->data[0] = storage_hdl;
+
+ /* Transmit on the caller's own context; see se_close_session(). */
+ ret = ele_msg_send_rcv(dev_ctx,
+ tx_msg,
+ ELE_STORAGE_CLOSE_REQ_SZ,
+ rx_msg,
+ ELE_STORAGE_CLOSE_RSP_SZ);
+ if (ret < 0)
+ return ret;
+
+ ret = se_val_rsp_hdr_n_status(priv,
+ rx_msg,
+ ELE_STORAGE_CLOSE_REQ,
+ ELE_STORAGE_CLOSE_RSP_SZ,
+ false);
+ return ret;
+}
diff --git a/drivers/firmware/imx/ele_fw_api.h b/drivers/firmware/imx/ele_fw_api.h
new file mode 100644
index 000000000000..afd8a148ff1d
--- /dev/null
+++ b/drivers/firmware/imx/ele_fw_api.h
@@ -0,0 +1,31 @@
+/* SPDX-License-Identifier: GPL-2.0+ */
+/*
+ * Copyright 2026 NXP
+ */
+
+#ifndef ELE_FW_API_H
+#define ELE_FW_API_H
+#include "se_ctrl.h"
+
+#define ELE_SESSION_OPEN_REQ 0x10u
+
+#define ELE_SESSION_CLOSE_REQ_SZ 0x08u
+#define ELE_SESSION_CLOSE_RSP_SZ 0x08u
+#define ELE_SESSION_CLOSE_REQ 0x11u
+
+#define ELE_STORAGE_OPEN_REQ 0xE0u
+
+#define ELE_STORAGE_CLOSE_REQ_SZ 0x08u
+#define ELE_STORAGE_CLOSE_RSP_SZ 0x08u
+#define ELE_STORAGE_CLOSE_REQ 0xE1u
+
+#define ELE_STORAGE_MASTER_IMPORT_REQ 0xE2u
+
+int ele_uapi_allowed_fw_cmd(struct se_if_device_ctx *dev_ctx, struct se_msg_hdr *header,
+ u32 tx_msg_sz);
+void fw_api_specific_ops(struct se_if_device_ctx *dev_ctx, struct se_api_msg *rx_msg);
+bool is_msg_xchng_for_tdown(void *tx_msg);
+int se_close_session(struct se_if_device_ctx *dev_ctx, u32 session_hdl);
+int se_close_storage(struct se_if_device_ctx *dev_ctx, u32 storage_hdl);
+
+#endif /* ELE_FW_API_H */
diff --git a/drivers/firmware/imx/se_ctrl.c b/drivers/firmware/imx/se_ctrl.c
index a8974eef190b..626983155517 100644
--- a/drivers/firmware/imx/se_ctrl.c
+++ b/drivers/firmware/imx/se_ctrl.c
@@ -4,6 +4,7 @@
*/
#include <linux/bitfield.h>
+#include <linux/cleanup.h>
#include <linux/completion.h>
#include <linux/delay.h>
#include <linux/dev_printk.h>
@@ -15,6 +16,7 @@
#include <linux/genalloc.h>
#include <linux/init.h>
#include <linux/io.h>
+#include <linux/kref.h>
#include <linux/miscdevice.h>
#include <linux/module.h>
#include <linux/of_platform.h>
@@ -23,22 +25,21 @@
#include <linux/slab.h>
#include <linux/string.h>
#include <linux/sys_soc.h>
+#include <uapi/linux/se_ioctl.h>
#include "ele_base_msg.h"
#include "ele_common.h"
+#include "ele_fw_api.h"
#include "se_ctrl.h"
+/* Maximum response buffer size in bytes for debug-dump replies. */
+#define MAX_ALLOWED_RX_MSG_SZ ELE_DEBUG_DUMP_RSP_SZ
+#define MAX_ALLOWED_TX_MSG_SZ SZ_4K
+
#define MAX_SOC_INFO_DATA_SZ 256
#define MBOX_TX_NAME "tx"
#define MBOX_RX_NAME "rx"
-#define SE_TYPE_STR_DBG "dbg"
-#define SE_TYPE_STR_HSM "hsm"
-
-#define SE_TYPE_ID_DBG 0x1
-
-#define SE_TYPE_ID_HSM 0x2
-
struct se_soc_dev_regn {
bool soc_dev_registered;
struct soc_device *soc_dev;
@@ -133,6 +134,13 @@ char *get_se_if_name(u8 se_if_id)
return "unknown";
}
+static u32 get_se_soc_id(struct se_if_priv *priv)
+{
+ const struct se_if_node *if_node = device_get_match_data(priv->dev);
+
+ return if_node->se_info->soc_id;
+}
+
static struct se_fw_load_info *get_load_fw_instance(struct se_if_priv *priv)
{
return &priv->load_fw;
@@ -284,11 +292,319 @@ static int get_se_soc_info(struct se_if_priv *priv, const struct se_soc_info *se
return 0;
}
+static int load_firmware(struct se_if_priv *priv, const u8 *se_img_file_to_load)
+{
+ const struct firmware *fw = NULL;
+ dma_addr_t se_fw_dma_addr;
+ u32 se_fw_buf_len;
+ void *se_fw_buf;
+ int ret;
+
+ if (!se_img_file_to_load) {
+ dev_err(priv->dev, "FW image is not provided.");
+ return -EINVAL;
+ }
+ ret = request_firmware(&fw, se_img_file_to_load, priv->dev);
+ if (ret)
+ return ret;
+
+ if (fw->size > U32_MAX) {
+ ret = -EFBIG;
+ release_firmware(fw);
+ return ret;
+ }
+ dev_info(priv->dev, "loading firmware %s.", se_img_file_to_load);
+
+ /*
+ * Serialize access to priv_dev_ctx shared memory to prevent pos
+ * corruption if two driver-internal callers run concurrently (e.g.
+ * ele_get_info() racing with load_firmware()).
+ */
+ scoped_guard(mutex, &priv->priv_dev_ctx->fops_lock) {
+ se_fw_buf_len = fw->size;
+ ret = get_shared_mem_slot(priv->priv_dev_ctx,
+ &se_fw_buf_len, &se_fw_dma_addr,
+ &se_fw_buf);
+ if (ret) {
+ dev_err(priv->dev, "Failed to allocate firmware shared buffer: %d\n",
+ ret);
+ release_firmware(fw);
+ return ret;
+ }
+
+ memcpy(se_fw_buf, fw->data, fw->size);
+ ret = ele_fw_authenticate(priv, se_fw_dma_addr, se_fw_dma_addr);
+ if (ret < 0) {
+ dev_err(priv->dev,
+ "Error %pe: Authenticate & load SE firmware %s.",
+ ERR_PTR(ret), se_img_file_to_load);
+ ret = -EPERM;
+ }
+ if (!se_is_fw_busy_ctx(priv->priv_dev_ctx))
+ se_dev_ctx_shared_mem_cleanup(priv->priv_dev_ctx);
+ }
+
+ release_firmware(fw);
+
+ return ret;
+}
+
+static int se_load_firmware(struct se_if_priv *priv)
+{
+ struct se_fw_load_info *load_fw = get_load_fw_instance(priv);
+ int ret = 0;
+
+ guard(mutex)(&load_fw->load_fw_lock);
+ if (!load_fw->is_fw_tobe_loaded)
+ return 0;
+
+ if (load_fw->imem.state == ELE_IMEM_STATE_BAD) {
+ ret = load_firmware(priv, load_fw->se_fw_img_nm->prim_fw_nm_in_rfs);
+ if (ret) {
+ dev_err(priv->dev, "Failed to load boot firmware.");
+ return -EPERM;
+ }
+ }
+
+ ret = load_firmware(priv, load_fw->se_fw_img_nm->seco_fw_nm_in_rfs);
+ if (ret) {
+ dev_err(priv->dev, "Failed to load runtime firmware.");
+ return -EPERM;
+ }
+
+ load_fw->is_fw_tobe_loaded = false;
+
+ return ret;
+}
+
+static int init_se_shared_mem(struct se_if_device_ctx *dev_ctx)
+{
+ struct se_shared_mem_mgmt_info *se_shared_mem_mgmt = &dev_ctx->se_shared_mem_mgmt;
+ struct se_if_priv *priv = dev_ctx->priv;
+
+ INIT_LIST_HEAD(&se_shared_mem_mgmt->pending_out);
+ INIT_LIST_HEAD(&se_shared_mem_mgmt->pending_in);
+
+ if (priv->mem_pool)
+ INIT_LIST_HEAD(&se_shared_mem_mgmt->mem_pool_buf_list);
+
+ se_shared_mem_mgmt->non_secure_mem.ptr =
+ dma_alloc_coherent(priv->dev, MAX_DATA_SIZE_PER_USER,
+ &se_shared_mem_mgmt->non_secure_mem.dma_addr,
+ GFP_KERNEL);
+ if (!se_shared_mem_mgmt->non_secure_mem.ptr)
+ return -ENOMEM;
+
+ se_shared_mem_mgmt->non_secure_mem.size = MAX_DATA_SIZE_PER_USER;
+ se_shared_mem_mgmt->non_secure_mem.pos = 0;
+
+ return 0;
+}
+
+static void cleanup_se_shared_mem(struct se_if_device_ctx *dev_ctx, bool reclaim)
+{
+ struct se_shared_mem_mgmt_info *se_shared_mem_mgmt = &dev_ctx->se_shared_mem_mgmt;
+ struct se_if_priv *priv = dev_ctx->priv;
+ bool free_dma_buf;
+
+ /*
+ * mem_pool_buf_list is only initialised for interfaces that own a
+ * gen_pool (priv->mem_pool != NULL). On interfaces without a pool
+ * (e.g. imx93, which has no pool_name) the list head is left
+ * zero-filled, so se_cleanup_mem_pool_buf() must not walk it here or
+ * list_for_each_entry_safe() would dereference a NULL head and panic
+ * the kernel on close/teardown. Skip the pool cleanup entirely when
+ * there is no pool; there is nothing to reclaim in that case.
+ */
+ if (priv->mem_pool)
+ se_cleanup_mem_pool_buf(dev_ctx, reclaim);
+
+ /* Guard against being called before shared memory was ever allocated
+ * (e.g. probe failure before dma_alloc_coherent succeeded).
+ */
+ if (!se_shared_mem_mgmt->non_secure_mem.ptr)
+ return;
+
+ /*
+ * Decide whether the DMA buffer can be released before touching the
+ * pending lists. se_dev_ctx_shared_mem_cleanup() resets
+ * non_secure_mem.pos, so the "nothing staged" test must be sampled
+ * here first. When reclaim is false the buffer is released only if no
+ * data is still staged for the firmware; otherwise the enclave may
+ * still be DMA-ing into it and the buffer is deliberately leaked to
+ * avoid a DMA-after-free.
+ */
+ free_dma_buf = reclaim || !se_shared_mem_mgmt->non_secure_mem.pos;
+
+ /*
+ * Free any se_buf_desc items that were never consumed (e.g. when the
+ * fd is closed while pending I/O buffers are still listed). This must
+ * happen before the DMA backing memory is released to avoid a leak.
+ */
+ se_dev_ctx_shared_mem_cleanup(dev_ctx);
+
+ if (free_dma_buf) {
+ dma_free_coherent(priv->dev, MAX_DATA_SIZE_PER_USER,
+ se_shared_mem_mgmt->non_secure_mem.ptr,
+ se_shared_mem_mgmt->non_secure_mem.dma_addr);
+ }
+
+ /*
+ * Drop the host-side tracking unconditionally. On the reclaim path the
+ * buffer has been freed. On the deliberate-leak path the buffer is
+ * abandoned on purpose, so clearing the pointer here guarantees a later
+ * cleanup pass (e.g. se_if_priv_release()) cannot double-free it.
+ */
+ se_shared_mem_mgmt->non_secure_mem.ptr = NULL;
+ se_shared_mem_mgmt->non_secure_mem.dma_addr = 0;
+ se_shared_mem_mgmt->non_secure_mem.size = 0;
+ se_shared_mem_mgmt->non_secure_mem.pos = 0;
+}
+
+static int se_dev_ctx_cpy_out_data(struct se_if_device_ctx *dev_ctx)
+{
+ struct se_shared_mem_mgmt_info *se_shared_mem_mgmt = &dev_ctx->se_shared_mem_mgmt;
+ struct se_if_priv *priv = dev_ctx->priv;
+ struct se_buf_desc *b_desc, *temp;
+ bool do_cpy = true;
+
+ list_for_each_entry_safe(b_desc, temp, &se_shared_mem_mgmt->pending_out, link) {
+ if (b_desc->usr_buf_ptr && b_desc->shared_buf_ptr && do_cpy) {
+ dev_dbg(priv->dev, "Copying output data to user.");
+ if (do_cpy && copy_to_user(b_desc->usr_buf_ptr,
+ b_desc->shared_buf_ptr,
+ b_desc->size)) {
+ dev_err(priv->dev, "Failure copying output data to user.");
+ do_cpy = false;
+ }
+ }
+
+ if (b_desc->shared_buf_ptr)
+ memset(b_desc->shared_buf_ptr, 0, b_desc->size);
+
+ list_del(&b_desc->link);
+ kfree(b_desc);
+ }
+
+ return do_cpy ? 0 : -EFAULT;
+}
+
+/*
+ * Clean the used Shared Memory space,
+ * whether its Input Data copied from user buffers, or
+ * Data received from FW.
+ */
+void se_dev_ctx_shared_mem_cleanup(struct se_if_device_ctx *dev_ctx)
+{
+ struct se_shared_mem_mgmt_info *se_shared_mem_mgmt = &dev_ctx->se_shared_mem_mgmt;
+ struct list_head *pending_lists[] = {&se_shared_mem_mgmt->pending_in,
+ &se_shared_mem_mgmt->pending_out};
+ struct se_buf_desc *b_desc, *temp;
+ bool is_fw_busy_dev_ctx;
+ int i;
+
+ /*
+ * If this context is the one that caused a firmware timeout the shared
+ * DMA buffers may still be actively read/written by the firmware.
+ */
+ is_fw_busy_dev_ctx = se_is_fw_busy_ctx(dev_ctx);
+
+ for (i = 0; i < ARRAY_SIZE(pending_lists); i++) {
+ list_for_each_entry_safe(b_desc, temp, pending_lists[i], link) {
+ if (!is_fw_busy_dev_ctx && b_desc->shared_buf_ptr)
+ memset(b_desc->shared_buf_ptr, 0, b_desc->size);
+
+ list_del(&b_desc->link);
+ kfree(b_desc);
+ }
+ }
+
+ /*
+ * Keep non_secure_mem.pos non-zero while this context still owns an
+ * outstanding firmware transaction. A non-zero pos is the marker that
+ * data is still staged for the enclave, which cleanup_se_shared_mem()
+ * uses to decide the buffer must be leaked rather than freed. Resetting
+ * it here would let a later teardown pass free a buffer the enclave may
+ * still be DMA-ing into.
+ */
+ if (!is_fw_busy_dev_ctx)
+ se_shared_mem_mgmt->non_secure_mem.pos = 0;
+}
+
+static struct se_buf_desc *add_b_desc_to_pending_list(void *shared_ptr_with_pos,
+ struct se_ioctl_setup_iobuf *io,
+ struct se_if_device_ctx *dev_ctx)
+{
+ struct se_shared_mem_mgmt_info *se_shared_mem_mgmt = &dev_ctx->se_shared_mem_mgmt;
+ struct se_buf_desc *b_desc = NULL;
+
+ b_desc = kzalloc_obj(*b_desc, GFP_KERNEL);
+ if (!b_desc)
+ return ERR_PTR(-ENOMEM);
+
+ b_desc->shared_buf_ptr = shared_ptr_with_pos;
+ b_desc->usr_buf_ptr = u64_to_user_ptr(io->user_buf);
+ b_desc->size = io->length;
+
+ if (io->flags & SE_IO_BUF_FLAGS_IS_INPUT) {
+ /*
+ * buffer is input:
+ * add an entry in the "pending input buffers" list so
+ * that copied data can be cleaned from shared memory
+ * later.
+ */
+ list_add_tail(&b_desc->link, &se_shared_mem_mgmt->pending_in);
+ } else {
+ /*
+ * buffer is output:
+ * add an entry in the "pending out buffers" list so data
+ * can be copied to user space when receiving Secure-Enclave
+ * response.
+ */
+ list_add_tail(&b_desc->link, &se_shared_mem_mgmt->pending_out);
+ }
+
+ return b_desc;
+}
+
+static void se_if_open_gate_release(struct kref *kref)
+{
+ struct se_if_open_gate *gate =
+ container_of(kref, struct se_if_open_gate, refcount);
+
+ kfree(gate);
+}
+
+static bool se_if_open_gate_get(struct se_if_open_gate *gate)
+{
+ if (!gate)
+ return false;
+
+ return kref_get_unless_zero(&gate->refcount);
+}
+
+static void se_if_open_gate_put(struct se_if_open_gate *gate)
+{
+ if (gate)
+ kref_put(&gate->refcount, se_if_open_gate_release);
+}
+
+/*
+ * Distinct lockdep class for the internal priv_dev_ctx fops_lock. Taking it
+ * while an open context's fops_lock is held (for example a firmware load
+ * triggered from an ioctl) is valid hierarchical locking, but shares the same
+ * class as the per-open fops_lock and would otherwise be misreported as
+ * recursive locking by lockdep.
+ */
+static struct lock_class_key se_priv_ctx_fops_key;
+
static int init_misc_device_context(struct se_if_priv *priv, int ch_id,
- struct se_if_device_ctx **new_dev_ctx)
+ struct se_if_device_ctx **new_dev_ctx,
+ const struct file_operations *se_if_fops)
{
const char *err_str = "Failed to allocate memory";
struct se_if_device_ctx *dev_ctx;
+ struct se_if_open_gate *gate = NULL;
int ret = -ENOMEM;
dev_ctx = kzalloc_obj(*dev_ctx, GFP_KERNEL);
@@ -296,19 +612,57 @@ static int init_misc_device_context(struct se_if_priv *priv, int ch_id,
if (!dev_ctx)
return ret;
+ dev_ctx->priv = priv;
dev_ctx->devname = kasprintf(GFP_KERNEL, "%s0_ch%d",
get_se_if_name(priv->if_defs->se_if_type),
ch_id);
if (!dev_ctx->devname)
goto exit;
- dev_ctx->priv = priv;
+ mutex_init(&dev_ctx->fops_lock);
+ lockdep_set_class(&dev_ctx->fops_lock, &se_priv_ctx_fops_key);
+
+ kref_init(&dev_ctx->refcount);
+ dev_ctx->cleanup_done = false;
*new_dev_ctx = dev_ctx;
+ set_se_rcv_msg_timeout(dev_ctx, SE_RCV_MSG_DEFAULT_TIMEOUT_MS);
+
+ ret = init_se_shared_mem(dev_ctx);
+ if (ret < 0)
+ goto exit;
+
+ gate = kzalloc_obj(*gate, GFP_KERNEL);
+ if (!gate) {
+ ret = -ENOMEM;
+ goto exit;
+ }
+
+ mutex_init(&gate->lock);
+ kref_init(&gate->refcount); /* device-owned reference */
+ gate->priv = priv;
+ gate->dying = false;
+ priv->open_gate = gate;
+
+ /*
+ * The miscdevice storage is now owned by the open gate object.
+ * priv->priv_dev_ctx still keeps a pointer to that miscdevice.
+ */
+ dev_ctx->miscdev = &gate->miscdev;
+
+ dev_ctx->miscdev->name = dev_ctx->devname;
+ dev_ctx->miscdev->minor = MISC_DYNAMIC_MINOR;
+ dev_ctx->miscdev->fops = se_if_fops;
+ dev_ctx->miscdev->parent = priv->dev;
return 0;
exit:
*new_dev_ctx = NULL;
+ if (gate) {
+ priv->open_gate = NULL;
+ se_if_open_gate_put(gate);
+ }
+ cleanup_se_shared_mem(dev_ctx, true);
kfree(dev_ctx->devname);
kfree(dev_ctx);
return dev_err_probe(priv->dev, ret, "%s", err_str);
@@ -329,9 +683,25 @@ static int se_if_request_channel(struct device *dev, struct mbox_chan **chan,
return 0;
}
+/*
+ * Forward declarations. se_if_probe_cleanup() and se_if_probe() are kept
+ * together as the teardown/probe pair, but several helpers, the file
+ * operations table and the firmware-busy work handler they reference are
+ * defined further down in this file.
+ */
+static void dlink_dev_ctx(struct se_if_device_ctx *dev_ctx);
+static void cleanup_dev_ctx(struct se_if_device_ctx *dev_ctx, bool is_fclose);
+static void se_clear_fw_busy(struct se_if_priv *priv);
+static void se_if_dev_ctx_release(struct kref *kref);
+static void se_if_priv_release(struct kref *kref);
+static int se_if_misc_register(struct se_if_priv *priv);
+static void se_fw_busy_work(struct work_struct *work);
+static const struct file_operations se_if_fops;
+
static void se_if_probe_cleanup(void *plat_dev)
{
struct platform_device *pdev = plat_dev;
+ struct se_if_device_ctx *dev_ctx;
struct device *dev = &pdev->dev;
struct se_if_priv *priv;
@@ -339,31 +709,122 @@ static void se_if_probe_cleanup(void *plat_dev)
if (!priv)
return;
+ /*
+ * Announce teardown, then wake any in-flight waiter. going_away makes
+ * ele_msg_send_rcv() bail out instead of arming a new transaction and
+ * lets ele_msg_rcv() tell a teardown-forced completion apart from a
+ * real response; it must be set before complete_all().
+ *
+ * Set it under clbk_rx_lock, not se_if_cmd_lock: se_if_cmd_lock is held
+ * across the whole blocking transaction, so taking it here would stall
+ * unbind for a full receive-timeout. clbk_rx_lock is the short spinlock
+ * ele_msg_send_rcv() holds while arming, so this closes the lost-wakeup
+ * window - the sender either sees going_away and bails before arming, or
+ * armed first and this store (and complete_all()) is ordered after its
+ * reinit_completion() - and supplies the ordering the relaxed atomics do
+ * not.
+ */
+ scoped_guard(spinlock_irqsave, &priv->waiting_rsp_clbk_hdl.clbk_rx_lock)
+ atomic_set(&priv->going_away, 1);
+ /*
+ * Wake the waiter before iterating the device-context list. It sleeps on
+ * this completion holding dev_ctx->fops_lock, which cleanup_dev_ctx()
+ * below also takes, so completing first avoids an unbind hang. Runs
+ * outside clbk_rx_lock; the going_away store above already orders it
+ * against the arming path.
+ */
+ complete_all(&priv->waiting_rsp_clbk_hdl.done);
+
+ /*
+ * Mark the private device context as cleanup_done first.
+ * This prevents new device contexts from being created in open().
+ */
+ if (priv->priv_dev_ctx) {
+ /*
+ * Mark cleanup_done under fops_lock so that se_if_fops_open(),
+ * which checks cleanup_done while holding fops_lock, cannot
+ * race past this and add a new device context after teardown.
+ */
+ scoped_guard(mutex, &priv->priv_dev_ctx->fops_lock)
+ priv->priv_dev_ctx->cleanup_done = true;
+
+ if (priv->open_gate) {
+ scoped_guard(mutex, &priv->open_gate->lock) {
+ priv->open_gate->dying = true;
+ priv->open_gate->priv = NULL;
+ }
+ }
+
+ /*
+ * misc_register() is deferred to the end of probe, so the
+ * device may have a miscdev set up but never registered if
+ * probe failed before se_if_misc_register(). Only deregister
+ * when registration actually succeeded.
+ */
+ if (priv->open_gate && priv->open_gate->registered &&
+ priv->priv_dev_ctx->miscdev)
+ misc_deregister(priv->priv_dev_ctx->miscdev);
+ }
+
+ while (true) {
+ dev_ctx = NULL;
+
+ scoped_guard(mutex, &priv->modify_lock) {
+ if (list_empty(&priv->dev_ctx_list))
+ goto out_done;
+
+ dev_ctx = list_first_entry(&priv->dev_ctx_list,
+ struct se_if_device_ctx, link);
+
+ /* pin this context so close() cannot free it under us */
+ kref_get(&dev_ctx->refcount);
+ dlink_dev_ctx(dev_ctx);
+ }
+
+ /*
+ * Local cleanup outside the global lock avoids ABBA deadlock
+ * with paths that already take dev_ctx->fops_lock first.
+ */
+ cleanup_dev_ctx(dev_ctx, false);
+ kref_put(&dev_ctx->refcount, se_if_dev_ctx_release);
+ }
+out_done:
+
+ /*
+ * Free the rx mailbox channel before cancelling fw_busy_work.
+ * se_if_rx_callback() runs from the rx channel and can schedule
+ * fw_busy_work when a late response arrives. If the channel were still
+ * live after cancel_work_sync(), a callback could re-arm the work and
+ * later dereference priv after it has been freed. Releasing the rx
+ * channel first guarantees no further callbacks, so the subsequent
+ * cancel_work_sync() is final.
+ */
if (priv->rx_chan)
mbox_free_channel(priv->rx_chan);
if (priv->tx_chan)
mbox_free_channel(priv->tx_chan);
/*
- * Being device managed buffer, no need to free the buffer allocated
- * in se probe to store encrypted IMEM.
+ * A timed-out synchronous command may have retained a dev_ctx through
+ * priv->fw_busy_dev_ctx even after the fd was closed and the context was
+ * removed from dev_ctx_list. If no late response arrived, release that
+ * retained context during driver teardown.
+ *
+ * se_clear_fw_busy() is idempotent and internally checks
+ * priv->fw_busy_dev_ctx under fw_busy_lock.
*/
+ se_clear_fw_busy(priv);
+ cancel_work_sync(&priv->fw_busy_work);
/*
- * No need to check, if reserved memory is allocated
- * before calling for its release. Or clearing the
- * un-set bit.
+ * Being device managed buffer, no need to free the buffer allocated
+ * in se probe to store encrypted IMEM.
*/
- of_reserved_mem_device_release(dev);
dev_set_drvdata(dev, NULL);
- if (priv->priv_dev_ctx) {
- kfree(priv->priv_dev_ctx->devname);
- kfree(priv->priv_dev_ctx);
- }
-
- kfree(priv);
+ /* Drop the initial reference - priv will be freed when last fd closes */
+ kref_put(&priv->refcount, se_if_priv_release);
}
static int se_if_probe(struct platform_device *pdev)
@@ -386,15 +847,30 @@ static int se_if_probe(struct platform_device *pdev)
return -ENOMEM;
priv->dev = dev;
+ /*
+ * Pin the parent device for the lifetime of priv. A file descriptor may
+ * stay open after the device is unbound; close() then still passes
+ * priv->dev to dma_free_coherent()/dev_warn(). Without this reference
+ * the struct device could be freed while priv->dev still points at it,
+ * so the reference is dropped in se_if_priv_release() via put_device().
+ */
+ get_device(priv->dev);
+ kref_init(&priv->refcount);
priv->if_defs = &if_node->if_defs;
dev_set_drvdata(dev, priv);
mutex_init(&priv->se_if_cmd_lock);
+ mutex_init(&priv->modify_lock);
spin_lock_init(&priv->cmd_receiver_clbk_hdl.clbk_rx_lock);
spin_lock_init(&priv->waiting_rsp_clbk_hdl.clbk_rx_lock);
atomic_set(&priv->fw_busy, 0);
+ spin_lock_init(&priv->fw_busy_lock);
+ priv->fw_busy_dev_ctx = NULL;
+ INIT_WORK(&priv->fw_busy_work, se_fw_busy_work);
+
init_completion(&priv->waiting_rsp_clbk_hdl.done);
init_completion(&priv->cmd_receiver_clbk_hdl.done);
+ INIT_LIST_HEAD(&priv->dev_ctx_list);
ret = devm_add_action_or_reset(dev, se_if_probe_cleanup, pdev);
if (ret)
@@ -460,7 +936,7 @@ static int se_if_probe(struct platform_device *pdev)
load_fw->imem_mgmt = true;
}
- ret = init_misc_device_context(priv, 0, &priv->priv_dev_ctx);
+ ret = init_misc_device_context(priv, 0, &priv->priv_dev_ctx, &se_if_fops);
if (ret)
return dev_err_probe(dev, ret,
"Failed[0x%x] to create device contexts.",
@@ -472,12 +948,1137 @@ static int se_if_probe(struct platform_device *pdev)
return dev_err_probe(dev, ret, "Failed to fetch SoC Info.");
}
+ /*
+ * All probe-time initialization is complete; expose the
+ * interface to userspace last so that an open()/ioctl cannot
+ * race against a not-yet-initialized device.
+ */
+ ret = se_if_misc_register(priv);
+ if (ret)
+ return ret;
+
dev_info(dev, "i.MX secure-enclave: %s0 interface to firmware, configured.",
get_se_if_name(priv->if_defs->se_if_type));
return ret;
}
+/*
+ * Expose the interface to userspace. Deferred until the end of probe so
+ * the device node only becomes openable after SoC info has been fetched
+ * and, on SoCs with IMEM management, the encrypted-IMEM buffer has been
+ * allocated. This prevents userspace from opening the node and issuing
+ * commands against a partially initialized interface.
+ */
+static int se_if_misc_register(struct se_if_priv *priv)
+{
+ int ret;
+
+ ret = misc_register(priv->priv_dev_ctx->miscdev);
+ if (ret)
+ return dev_err_probe(priv->dev, ret,
+ "Failed to register misc device.");
+
+ priv->open_gate->registered = true;
+
+ return 0;
+}
+
+static void se_if_priv_release(struct kref *kref)
+{
+ struct se_if_priv *priv = container_of(kref, struct se_if_priv, refcount);
+
+ /* Free priv_dev_ctx if it exists */
+ if (priv->priv_dev_ctx) {
+ /*
+ * miscdev storage belongs to open_gate, not directly to
+ * priv_dev_ctx. The gate should already have been detached
+ * from priv during teardown.
+ *
+ * Reclaim the internal context's shared memory directly here
+ * instead of through cleanup_dev_ctx(). Teardown already set
+ * cleanup_done on priv_dev_ctx, so cleanup_dev_ctx() would
+ * short-circuit and leak the host descriptors and the coherent
+ * buffer. By this point the device is fully unbound; if this
+ * context ever armed the firmware-busy breaker, se_clear_fw_busy()
+ * has already run with reclaim=false and freed the host
+ * descriptors, emptied the pool list and cleared
+ * non_secure_mem.ptr. A reclaim=true pass here is therefore both
+ * safe and idempotent: it releases the buffers for a normal
+ * context and is a no-op for the abandoned firmware-busy one.
+ */
+ scoped_guard(mutex, &priv->priv_dev_ctx->fops_lock)
+ cleanup_se_shared_mem(priv->priv_dev_ctx, true);
+
+ kfree(priv->priv_dev_ctx->devname);
+ kfree(priv->priv_dev_ctx);
+ priv->priv_dev_ctx = NULL;
+ }
+ /*
+ * No need to check, if reserved memory is allocated
+ * before calling for its release. Or clearing the
+ * un-set bit.
+ */
+ of_reserved_mem_device_release(priv->dev);
+
+ /*
+ * Be defensive: if teardown did not already drop the device-owned
+ * gate reference for some reason, release it here.
+ */
+ if (priv->open_gate) {
+ se_if_open_gate_put(priv->open_gate);
+ priv->open_gate = NULL;
+ }
+
+ /*
+ * Drop the reference on priv->dev taken in se_if_probe(). The device was
+ * pinned so that a file descriptor closed after device unbind can still
+ * safely pass priv->dev to dma_free_coherent()/dev_warn().
+ */
+ put_device(priv->dev);
+
+ /* Free any remaining resources that weren't devm-managed */
+ kfree(priv);
+}
+
+static void se_if_dev_ctx_release(struct kref *kref)
+{
+ struct se_if_device_ctx *dev_ctx =
+ container_of(kref, struct se_if_device_ctx, refcount);
+ struct se_if_priv *priv = dev_ctx->priv;
+
+ kfree(dev_ctx);
+
+ /* drop the priv reference owned by this device context */
+ kref_put(&priv->refcount, se_if_priv_release);
+}
+
+static void se_clear_fw_busy(struct se_if_priv *priv)
+{
+ struct se_if_device_ctx *dev_ctx = NULL;
+ unsigned long flags;
+
+ spin_lock_irqsave(&priv->fw_busy_lock, flags);
+ dev_ctx = priv->fw_busy_dev_ctx;
+ priv->fw_busy_dev_ctx = NULL;
+ atomic_set(&priv->fw_busy, 0);
+ spin_unlock_irqrestore(&priv->fw_busy_lock, flags);
+
+ if (!dev_ctx)
+ return;
+
+ /*
+ * The circuit breaker is cleared from two places, which need opposite
+ * memory-reclaim policies:
+ *
+ * 1. se_fw_busy_work(): a late firmware response actually arrived.
+ * going_away is not set and the enclave has finished with the
+ * buffer, so a full reclaim (reclaim=true) is safe. Only do this
+ * once the owning fd has been closed (cleanup_done); while the fd
+ * is still open the buffer belongs to that context and is released
+ * on its normal close path.
+ *
+ * 2. se_if_probe_cleanup(): teardown. going_away is set and no
+ * response has been confirmed, so the enclave may still be
+ * DMA-writing into the shared buffer. Freeing it here would be a
+ * DMA-after-free. Pass reclaim=false so cleanup_se_shared_mem()
+ * frees only the host-side descriptors and deliberately leaks the
+ * DMA buffer that the enclave might still touch.
+ */
+ scoped_guard(mutex, &dev_ctx->fops_lock) {
+ if (atomic_read(&priv->going_away)) {
+ /*
+ * Fatal, but deliberately non-panic: the enclave is
+ * unresponsive at unbind with a transaction still in
+ * flight. Both the coherent staging buffer and any
+ * gen_pool buffers this context owns are abandoned
+ * (host descriptors freed, DMA-visible memory leaked)
+ * to avoid a DMA-after-free while the enclave may still
+ * be writing. Emit one headline error here rather than
+ * per-buffer so the count of faulted contexts is clear.
+ * Do not use WARN/BUG: this path is recoverable and
+ * panic_on_warn kernels must not be brought down by it.
+ */
+ dev_err(priv->dev,
+ "%s: FATAL: enclave stuck at unbind, DMA leaked.\n",
+ dev_ctx->devname);
+ cleanup_se_shared_mem(dev_ctx, false);
+ } else if (dev_ctx->cleanup_done) {
+ cleanup_se_shared_mem(dev_ctx, true);
+ }
+ }
+
+ kref_put(&dev_ctx->refcount, se_if_dev_ctx_release);
+}
+
+void unset_dev_ctx_as_command_receiver(struct se_if_device_ctx *dev_ctx)
+{
+ struct se_if_priv *priv = dev_ctx->priv;
+ struct se_api_msg *old_rx_msg = NULL;
+ struct se_clbk_handle *se_clbk_hdl;
+ unsigned long flags;
+
+ lockdep_assert_held(&priv->modify_lock);
+
+ se_clbk_hdl = &priv->cmd_receiver_clbk_hdl;
+
+ if (se_clbk_hdl->dev_ctx == dev_ctx) {
+ spin_lock_irqsave(&se_clbk_hdl->clbk_rx_lock, flags);
+ old_rx_msg = se_clbk_hdl->rx_msg;
+ se_clbk_hdl->dev_ctx = NULL;
+ se_clbk_hdl->rx_msg = NULL;
+ se_clbk_hdl->rx_msg_sz = 0;
+ spin_unlock_irqrestore(&se_clbk_hdl->clbk_rx_lock, flags);
+
+ kfree(old_rx_msg);
+ complete_all(&se_clbk_hdl->done);
+ }
+}
+
+int set_dev_ctx_as_command_receiver(struct se_if_device_ctx *dev_ctx)
+{
+ struct se_if_priv *priv = dev_ctx->priv;
+ struct se_api_msg *new_rx_msg = NULL;
+ struct se_clbk_handle *se_clbk_hdl;
+ unsigned long flags;
+
+ se_clbk_hdl = &priv->cmd_receiver_clbk_hdl;
+ guard(mutex)(&priv->modify_lock);
+ if (se_clbk_hdl->dev_ctx == dev_ctx)
+ return 0;
+
+ if (se_clbk_hdl->dev_ctx)
+ return -EBUSY;
+
+ if (!se_clbk_hdl->rx_msg) {
+ new_rx_msg = kzalloc(MAX_NVM_MSG_LEN, GFP_KERNEL);
+ if (!new_rx_msg)
+ return -ENOMEM;
+ }
+ spin_lock_irqsave(&se_clbk_hdl->clbk_rx_lock, flags);
+ if (new_rx_msg)
+ se_clbk_hdl->rx_msg = new_rx_msg;
+ reinit_completion(&se_clbk_hdl->done);
+ se_clbk_hdl->rx_msg_sz = MAX_NVM_MSG_LEN;
+ se_clbk_hdl->dev_ctx = dev_ctx;
+ dev_ctx->rcv_msg_timeout_jiffies = MAX_SCHEDULE_TIMEOUT;
+ spin_unlock_irqrestore(&se_clbk_hdl->clbk_rx_lock, flags);
+
+ return 0;
+}
+
+static void dlink_dev_ctx(struct se_if_device_ctx *dev_ctx)
+{
+ struct se_if_priv *priv = dev_ctx->priv;
+
+ unset_dev_ctx_as_command_receiver(dev_ctx);
+
+ if (!list_empty(&dev_ctx->link)) {
+ list_del_init(&dev_ctx->link);
+ priv->active_devctx_count--;
+ }
+}
+
+bool se_is_fw_busy_ctx(struct se_if_device_ctx *dev_ctx)
+{
+ struct se_if_priv *priv = dev_ctx->priv;
+ unsigned long flags;
+ bool match;
+
+ spin_lock_irqsave(&priv->fw_busy_lock, flags);
+ match = priv->fw_busy_dev_ctx == dev_ctx;
+ spin_unlock_irqrestore(&priv->fw_busy_lock, flags);
+
+ return match;
+}
+
+static void cleanup_dev_ctx(struct se_if_device_ctx *dev_ctx, bool is_fclose)
+{
+ bool already_done;
+
+ scoped_guard(mutex, &dev_ctx->fops_lock) {
+ already_done = dev_ctx->cleanup_done;
+ if (!already_done) {
+ /*
+ * Ask FW to drop this context's session and storage so
+ * the kernel and FW stay in sync. Done here, under this
+ * context's fops_lock only (not the global modify_lock),
+ * because both close requests block on a firmware
+ * round-trip; issuing them while modify_lock was held
+ * would stall every other context for the FW timeout.
+ *
+ * Skip the round-trips once the FW path is marked busy.
+ * fw_busy is armed when a synchronous transaction times
+ * out; while it is set ele_msg_send_rcv() rejects further
+ * commands with -EBUSY without waiting. It is only cleared
+ * by se_clear_fw_busy(), which during unbind runs once
+ * after this loop (or earlier from fw_busy_work only if a
+ * genuine late FW response arrives). On a hung FW no late
+ * response comes, so the breaker stays set for the rest of
+ * the loop and the remaining closes would just return
+ * -EBUSY and log spurious "failed to close" errors. Skip
+ * them and emit a single warning instead.
+ */
+ if (atomic_read(&dev_ctx->priv->fw_busy)) {
+ if (dev_ctx->strg_hdl || dev_ctx->sess_hdl)
+ dev_warn(dev_ctx->priv->dev,
+ "%s: skipping session/storage close, FW is busy\n",
+ dev_ctx->devname);
+ } else {
+ /*
+ * Pick the context that carries the close messages.
+ *
+ * fclose (is_fclose): a userspace close() may race
+ * driver unbind. Send on the caller's own dev_ctx so
+ * ele_msg_send_rcv()'s going_away check rejects the
+ * transmission with -ENODEV if unbind has begun (and
+ * may have freed priv->tx_chan), instead of touching a
+ * freed mailbox channel.
+ *
+ * Teardown (!is_fclose): going_away is already set, but
+ * priv->tx_chan is still live at this point in
+ * se_if_probe_cleanup(). Send on priv_dev_ctx, the only
+ * context ele_msg_send_rcv() lets through going_away for
+ * teardown-close messages, so the kernel can still
+ * resynchronise session/storage state with FW.
+ */
+ struct se_if_device_ctx *tx_ctx = is_fclose ? dev_ctx :
+ dev_ctx->priv->priv_dev_ctx;
+
+ if (dev_ctx->strg_hdl && se_close_storage(tx_ctx,
+ dev_ctx->strg_hdl))
+ dev_err(dev_ctx->priv->dev, "failed to close storage.\n");
+ if (dev_ctx->sess_hdl && se_close_session(tx_ctx,
+ dev_ctx->sess_hdl))
+ dev_err(dev_ctx->priv->dev, "failed to close session.\n");
+ }
+ /*
+ * fw_busy is caused by one timed-out synchronous transaction.
+ * Only that transaction's dev_ctx may still have coherent
+ * memory referenced by FW. Do not skip cleanup for unrelated
+ * contexts while fw_busy is set.
+ */
+ if (se_is_fw_busy_ctx(dev_ctx))
+ dev_warn(dev_ctx->priv->dev,
+ "%s: deferring shared memory cleanup while FW is busy\n",
+ dev_ctx->devname);
+ else
+ cleanup_se_shared_mem(dev_ctx, true);
+
+ kfree(dev_ctx->devname);
+ dev_ctx->devname = NULL;
+ dev_ctx->cleanup_done = true;
+ }
+ }
+
+ if (is_fclose)
+ kref_put(&dev_ctx->refcount, se_if_dev_ctx_release);
+}
+
+static void dlink_n_cleanup_dev_ctx(struct se_if_device_ctx *dev_ctx, bool is_fclose)
+{
+ struct se_if_priv *priv = dev_ctx->priv;
+
+ if (is_fclose) {
+ scoped_guard(mutex, &priv->modify_lock)
+ dlink_dev_ctx(dev_ctx);
+ }
+
+ cleanup_dev_ctx(dev_ctx, is_fclose);
+}
+
+static int init_device_context(struct se_if_priv *priv, int ch_id,
+ struct se_if_device_ctx **new_dev_ctx)
+{
+ struct se_if_device_ctx *dev_ctx;
+ int ret = 0;
+
+ dev_ctx = kzalloc_obj(*dev_ctx, GFP_KERNEL);
+
+ if (!dev_ctx)
+ return -ENOMEM;
+
+ dev_ctx->devname = kasprintf(GFP_KERNEL, "%s0_ch%d",
+ get_se_if_name(priv->if_defs->se_if_type),
+ ch_id);
+ if (!dev_ctx->devname) {
+ kfree(dev_ctx);
+ return -ENOMEM;
+ }
+
+ mutex_init(&dev_ctx->fops_lock);
+ kref_init(&dev_ctx->refcount);
+ dev_ctx->priv = priv;
+ dev_ctx->cleanup_done = false;
+ INIT_LIST_HEAD(&dev_ctx->link);
+ set_se_rcv_msg_timeout(dev_ctx, SE_RCV_MSG_LONG_TIMEOUT_MS);
+ *new_dev_ctx = dev_ctx;
+
+ ret = init_se_shared_mem(dev_ctx);
+ if (ret < 0) {
+ kfree(dev_ctx->devname);
+ kfree(dev_ctx);
+ *new_dev_ctx = NULL;
+
+ return ret;
+ }
+
+ /* Take a reference to priv for this device context */
+ kref_get(&priv->refcount);
+
+ scoped_guard(mutex, &priv->modify_lock) {
+ list_add_tail(&dev_ctx->link, &priv->dev_ctx_list);
+ priv->active_devctx_count++;
+ }
+
+ return ret;
+}
+
+static int se_ioctl_cmd_snd_rcv_cleanup(struct se_if_device_ctx *dev_ctx, void __user *uarg,
+ struct se_ioctl_cmd_snd_rcv_rsp_info *cmd_snd_rcv_rsp_info)
+{
+ /* shared memory is allocated before this IOCTL */
+ se_dev_ctx_shared_mem_cleanup(dev_ctx);
+
+ if (cmd_snd_rcv_rsp_info->rx_buf_sz &&
+ copy_to_user(uarg, cmd_snd_rcv_rsp_info, sizeof(*cmd_snd_rcv_rsp_info))) {
+ dev_err(dev_ctx->priv->dev, "%s: Failed to copy cmd_snd_rcv_rsp_info to user.",
+ dev_ctx->devname);
+ return -EFAULT;
+ }
+
+ return 0;
+}
+
+static int se_ioctl_cmd_snd_rcv_rsp_handler(struct se_if_device_ctx *dev_ctx,
+ void __user *uarg)
+{
+ struct se_ioctl_cmd_snd_rcv_rsp_info cmd_snd_rcv_rsp_info = {0};
+ struct se_if_priv *priv = dev_ctx->priv;
+ int rsp_status_err = 0;
+ int cleanup_err = 0;
+ int err = 0;
+
+ if (copy_from_user(&cmd_snd_rcv_rsp_info, uarg,
+ sizeof(cmd_snd_rcv_rsp_info))) {
+ dev_err(priv->dev,
+ "%s: Failed to copy cmd_snd_rcv_rsp_info from user.",
+ dev_ctx->devname);
+ se_ioctl_cmd_snd_rcv_cleanup(dev_ctx, uarg, &cmd_snd_rcv_rsp_info);
+ return -EFAULT;
+ }
+
+ if (cmd_snd_rcv_rsp_info.tx_buf_sz < SE_MU_HDR_SZ ||
+ cmd_snd_rcv_rsp_info.tx_buf_sz > MAX_ALLOWED_TX_MSG_SZ) {
+ dev_err(priv->dev, "%s: User buffer too small/large(%d < %d)",
+ dev_ctx->devname, cmd_snd_rcv_rsp_info.tx_buf_sz,
+ cmd_snd_rcv_rsp_info.tx_buf_sz < SE_MU_HDR_SZ ? SE_MU_HDR_SZ :
+ MAX_ALLOWED_TX_MSG_SZ);
+ se_ioctl_cmd_snd_rcv_cleanup(dev_ctx, uarg, &cmd_snd_rcv_rsp_info);
+ return -ENOSPC;
+ }
+
+ struct se_api_msg *tx_msg __free(kfree) =
+ memdup_user(u64_to_user_ptr(cmd_snd_rcv_rsp_info.tx_buf),
+ cmd_snd_rcv_rsp_info.tx_buf_sz);
+ if (IS_ERR(tx_msg)) {
+ err = PTR_ERR(tx_msg);
+ se_ioctl_cmd_snd_rcv_cleanup(dev_ctx, uarg, &cmd_snd_rcv_rsp_info);
+ return err;
+ }
+
+ err = se_chk_tx_msg_hdr(dev_ctx, &tx_msg->header,
+ cmd_snd_rcv_rsp_info.tx_buf_sz);
+ if (err) {
+ se_ioctl_cmd_snd_rcv_cleanup(dev_ctx, uarg, &cmd_snd_rcv_rsp_info);
+ return err;
+ }
+
+ if (cmd_snd_rcv_rsp_info.rx_buf_sz < SE_MU_HDR_SZ ||
+ cmd_snd_rcv_rsp_info.rx_buf_sz > MAX_ALLOWED_RX_MSG_SZ) {
+ se_ioctl_cmd_snd_rcv_cleanup(dev_ctx, uarg, &cmd_snd_rcv_rsp_info);
+ return -EINVAL;
+ }
+
+ if (tx_msg->header.tag != priv->if_defs->cmd_tag) {
+ se_ioctl_cmd_snd_rcv_cleanup(dev_ctx, uarg, &cmd_snd_rcv_rsp_info);
+ return -EINVAL;
+ }
+
+ if (tx_msg->header.ver == priv->if_defs->fw_api_ver &&
+ get_load_fw_instance(priv)->is_fw_tobe_loaded) {
+ err = se_load_firmware(priv);
+ if (err) {
+ dev_err(priv->dev, "Could not send msg as FW is not loaded.");
+ se_ioctl_cmd_snd_rcv_cleanup(dev_ctx, uarg, &cmd_snd_rcv_rsp_info);
+ return -EPERM;
+ }
+ }
+
+ struct se_api_msg *rx_msg __free(kfree) =
+ kzalloc(cmd_snd_rcv_rsp_info.rx_buf_sz, GFP_KERNEL);
+ if (!rx_msg) {
+ se_ioctl_cmd_snd_rcv_cleanup(dev_ctx, uarg, &cmd_snd_rcv_rsp_info);
+ return -ENOMEM;
+ }
+
+ err = ele_msg_send_rcv(dev_ctx, tx_msg, cmd_snd_rcv_rsp_info.tx_buf_sz,
+ rx_msg, cmd_snd_rcv_rsp_info.rx_buf_sz);
+ if (err < 0) {
+ /*
+ * -ERESTARTSYS here means the wait was interrupted by a signal
+ * after the command had already been handed to - and executed
+ * by - the firmware, with its response delivered into rx_msg
+ * (ele_msg_send_rcv() converts only a positive, i.e. successfully
+ * received, result to -ERESTARTSYS). If that response carried a
+ * freshly allocated session/storage handle, record it now via
+ * fw_api_specific_ops(): the handle is already live in firmware,
+ * so leaving it untracked would stop cleanup_dev_ctx() from ever
+ * closing it and leak the firmware resource. Validate the
+ * delivered response first, using its own declared length bounded
+ * by the caller's buffer, so a truncated or malformed reply is
+ * not acted upon.
+ */
+ if (err == -ERESTARTSYS) {
+ u32 rsp_sz = rx_msg->header.size << 2;
+
+ if (rsp_sz && rsp_sz <= cmd_snd_rcv_rsp_info.rx_buf_sz &&
+ !se_val_rsp_hdr_n_status(priv, rx_msg,
+ tx_msg->header.command, rsp_sz,
+ tx_msg->header.ver ==
+ priv->if_defs->base_api_ver)) {
+ se_dev_ctx_cpy_out_data(dev_ctx);
+ fw_api_specific_ops(dev_ctx, rx_msg);
+ }
+ /*
+ * Returning -ERESTARTSYS would let the VFS transparently restart
+ * the ioctl, which would re-run the command with the just
+ * cleaned-up (zeroed) shared input buffers. Report -EINTR instead
+ * so the syscall is not auto-restarted; userspace enters its
+ * signal handler and can decide whether to reissue the command.
+ */
+ err = -EINTR;
+ }
+
+ se_ioctl_cmd_snd_rcv_cleanup(dev_ctx, uarg, &cmd_snd_rcv_rsp_info);
+
+ return err;
+ }
+
+ /*
+ * ele_msg_send_rcv() returns a positive received-message size on
+ * success. Returning that raw size as the ioctl result would make a
+ * successful transaction look like a positive (non-zero) return value
+ * to userspace. Record the actual received size in rx_buf_sz for the
+ * response copied back to userspace, then normalise err to 0 so the
+ * ioctl reports plain success; the firmware status is conveyed to
+ * userspace inside the response buffer itself.
+ */
+ cmd_snd_rcv_rsp_info.rx_buf_sz = err;
+ err = 0;
+
+ dev_dbg(priv->dev, "%s: %s %s.", dev_ctx->devname, __func__,
+ "message received, start transmit to user");
+
+ rsp_status_err =
+ se_val_rsp_hdr_n_status(priv, rx_msg, tx_msg->header.command,
+ cmd_snd_rcv_rsp_info.rx_buf_sz,
+ tx_msg->header.ver == priv->if_defs->base_api_ver);
+
+ if (!rsp_status_err) {
+ err = se_dev_ctx_cpy_out_data(dev_ctx);
+ if (err < 0) {
+ se_ioctl_cmd_snd_rcv_cleanup(dev_ctx, uarg, &cmd_snd_rcv_rsp_info);
+ return err;
+ }
+ }
+
+ /* Copy data from the buffer */
+ print_hex_dump_debug("to user ", DUMP_PREFIX_OFFSET, 4, 4, rx_msg,
+ cmd_snd_rcv_rsp_info.rx_buf_sz, false);
+
+ if (copy_to_user(u64_to_user_ptr(cmd_snd_rcv_rsp_info.rx_buf), rx_msg,
+ cmd_snd_rcv_rsp_info.rx_buf_sz)) {
+ dev_err(priv->dev, "%s: Failed to copy to user.", dev_ctx->devname);
+ err = -EFAULT;
+ }
+
+ cleanup_err = se_ioctl_cmd_snd_rcv_cleanup(dev_ctx, uarg, &cmd_snd_rcv_rsp_info);
+
+ if (cleanup_err && !err)
+ err = cleanup_err;
+
+ if (!err && !rsp_status_err)
+ fw_api_specific_ops(dev_ctx, rx_msg);
+
+ return err;
+}
+
+static int se_ioctl_get_mu_info(struct se_if_device_ctx *dev_ctx,
+ void __user *uarg)
+{
+ struct se_if_priv *priv = dev_ctx->priv;
+ struct se_ioctl_get_if_info if_info;
+ struct se_if_node *if_node;
+ int err = 0;
+
+ if_node = container_of(priv->if_defs, typeof(*if_node), if_defs);
+
+ if_info.se_if_id = 0;
+ if_info.interrupt_idx = 0;
+ if_info.tz = 0;
+ if_info.did = 0;
+ if_info.cmd_tag = priv->if_defs->cmd_tag;
+ if_info.rsp_tag = priv->if_defs->rsp_tag;
+ if_info.success_tag = priv->if_defs->success_tag;
+ if_info.base_api_ver = priv->if_defs->base_api_ver;
+ if_info.fw_api_ver = priv->if_defs->fw_api_ver;
+
+ dev_dbg(priv->dev, "%s: info [se_if_id: %d, irq_idx: %d, tz: 0x%x, did: 0x%x].",
+ dev_ctx->devname, if_info.se_if_id, if_info.interrupt_idx, if_info.tz,
+ if_info.did);
+
+ if (copy_to_user(uarg, &if_info, sizeof(if_info))) {
+ dev_err(priv->dev, "%s: Failed to copy mu info to user.",
+ dev_ctx->devname);
+ err = -EFAULT;
+ }
+
+ return err;
+}
+
+static void rollback_shared_mem_pos(struct se_if_device_ctx *dev_ctx, u32 length)
+{
+ struct se_shared_mem *shared_mem = NULL;
+
+ shared_mem = &dev_ctx->se_shared_mem_mgmt.non_secure_mem;
+
+ if (WARN_ON_ONCE(length > shared_mem->pos)) {
+ shared_mem->pos = 0;
+ return;
+ }
+
+ shared_mem->pos -= length;
+}
+
+int get_shared_mem_slot(struct se_if_device_ctx *dev_ctx,
+ u32 *length, dma_addr_t *ele_dma_addr, void **ptr)
+{
+ struct se_shared_mem *shared_mem = NULL;
+ bool is_fw_busy_dev_ctx;
+ size_t aligned_len = 0;
+ u32 pos;
+
+ /*
+ * If this context is the one that caused a firmware timeout the shared
+ * DMA buffers may still be actively read/written by the firmware.
+ */
+ is_fw_busy_dev_ctx = se_is_fw_busy_ctx(dev_ctx);
+ if (is_fw_busy_dev_ctx)
+ return -EBUSY;
+
+ aligned_len = round_up((size_t)*length, 8);
+ if (aligned_len < *length) {
+ dev_err(dev_ctx->priv->dev, "%s: Invalid buffer length.",
+ dev_ctx->devname);
+ return -EINVAL;
+ }
+
+ /* No specific requirement for this buffer. */
+ shared_mem = &dev_ctx->se_shared_mem_mgmt.non_secure_mem;
+
+ /* Check there is enough space in the shared memory. */
+ dev_dbg(dev_ctx->priv->dev, "%s: req_size = %zd, max_size= %d, curr_pos = %d",
+ dev_ctx->devname, aligned_len, shared_mem->size,
+ shared_mem->pos);
+
+ if (shared_mem->size < shared_mem->pos ||
+ aligned_len > (shared_mem->size - shared_mem->pos)) {
+ dev_err(dev_ctx->priv->dev, "%s: Not enough space in shared memory.",
+ dev_ctx->devname);
+ return -ENOMEM;
+ }
+
+ /* Allocate space in shared memory. 8 bytes aligned. */
+ pos = shared_mem->pos;
+ shared_mem->pos += aligned_len;
+ *ele_dma_addr = (u64)shared_mem->dma_addr + pos;
+ *ptr = shared_mem->ptr + pos;
+ *length = aligned_len;
+
+ memset(shared_mem->ptr + pos, 0, aligned_len);
+
+ return 0;
+}
+
+/*
+ * Copy a buffer of data to/from the user and return the address to use in
+ * messages
+ */
+static int se_ioctl_setup_iobuf_handler(struct se_if_device_ctx *dev_ctx,
+ void __user *uarg)
+{
+ struct se_ioctl_setup_iobuf io = {0};
+ struct se_buf_desc *b_desc = NULL;
+ void *dma_buf_ptr = NULL;
+ dma_addr_t ele_dma_addr;
+ u32 aligned_len = 0;
+ int err = 0;
+
+ if (copy_from_user(&io, uarg, sizeof(io))) {
+ dev_err(dev_ctx->priv->dev, "%s: Failed copy iobuf config from user.",
+ dev_ctx->devname);
+ return -EFAULT;
+ }
+
+ dev_dbg(dev_ctx->priv->dev, "%s: io [buf: %p(%d) flag: %x].", dev_ctx->devname,
+ u64_to_user_ptr(io.user_buf), io.length, io.flags);
+
+ if (io.length == 0 || !io.user_buf) {
+ /*
+ * Accept NULL pointers since some buffers are optional
+ * in FW commands. In this case we should return 0 as
+ * pointer to be embedded into the message.
+ * Skip all data copy part of code below.
+ */
+ io.ele_addr = 0;
+ goto copy;
+ }
+
+ aligned_len = io.length;
+ err = get_shared_mem_slot(dev_ctx, &aligned_len, &ele_dma_addr, &dma_buf_ptr);
+ if (err)
+ return err;
+
+ io.ele_addr = ele_dma_addr;
+ if ((io.flags & SE_IO_BUF_FLAGS_IS_INPUT) ||
+ (io.flags & SE_IO_BUF_FLAGS_IS_IN_OUT)) {
+ /*
+ * buffer is input:
+ * copy data from user space to this allocated buffer.
+ */
+ if (copy_from_user(dma_buf_ptr, u64_to_user_ptr(io.user_buf),
+ io.length)) {
+ dev_err(dev_ctx->priv->dev,
+ "%s: Failed copy data to shared memory.",
+ dev_ctx->devname);
+ err = -EFAULT;
+ goto rollback;
+ }
+ }
+
+ b_desc = add_b_desc_to_pending_list(dma_buf_ptr, &io, dev_ctx);
+ if (IS_ERR(b_desc)) {
+ err = PTR_ERR(b_desc);
+ dev_err(dev_ctx->priv->dev, "%s: Failed to allocate/link b_desc.",
+ dev_ctx->devname);
+ goto rollback;
+ }
+
+copy:
+ /* Provide the EdgeLock Enclave address to user space only if success.*/
+ if (copy_to_user(uarg, &io, sizeof(io))) {
+ dev_err(dev_ctx->priv->dev, "%s: Failed to copy iobuff setup to user.",
+ dev_ctx->devname);
+ err = -EFAULT;
+ goto rollback;
+ }
+ return err;
+
+rollback:
+ if (!IS_ERR_OR_NULL(b_desc)) {
+ list_del(&b_desc->link);
+ kfree(b_desc);
+ }
+
+ if (dma_buf_ptr && aligned_len) {
+ memset(dma_buf_ptr, 0, aligned_len);
+ rollback_shared_mem_pos(dev_ctx, aligned_len);
+ }
+
+ return err;
+}
+
+/* IOCTL to provide SoC information */
+static int se_ioctl_get_se_soc_info_handler(struct se_if_device_ctx *dev_ctx,
+ void __user *uarg)
+{
+ struct se_ioctl_get_soc_info soc_info;
+ int err = -EINVAL;
+
+ soc_info.soc_id = get_se_soc_id(dev_ctx->priv);
+ soc_info.soc_rev = var_se_info.soc_rev;
+
+ err = copy_to_user(uarg, (u8 *)(&soc_info), sizeof(soc_info));
+ if (err) {
+ dev_err(dev_ctx->priv->dev, "%s: Failed to copy soc info to user.",
+ dev_ctx->devname);
+ err = -EFAULT;
+ }
+
+ return err;
+}
+
+/*
+ * File operations for user-space
+ */
+
+/* Write a message to the MU. */
+static ssize_t se_if_fops_write(struct file *fp, const char __user *buf,
+ size_t size, loff_t *ppos)
+{
+ struct se_if_device_ctx *dev_ctx = fp->private_data;
+ struct se_if_priv *priv;
+ int err;
+
+ scoped_cond_guard(mutex_intr, return -ERESTARTSYS, &dev_ctx->fops_lock) {
+ if (dev_ctx->cleanup_done)
+ return -ENODEV;
+
+ priv = dev_ctx->priv;
+
+ dev_dbg(priv->dev, "%s: write from buf (%p)%zu, ppos=%lld.", dev_ctx->devname,
+ buf, size, ((ppos) ? *ppos : 0));
+
+ if (dev_ctx != priv->cmd_receiver_clbk_hdl.dev_ctx) {
+ se_dev_ctx_shared_mem_cleanup(dev_ctx);
+ return -EINVAL;
+ }
+
+ if (size < SE_MU_HDR_SZ || size > MAX_ALLOWED_TX_MSG_SZ) {
+ dev_err(priv->dev, "%s: User buffer too small/large(%zu < %d)",
+ dev_ctx->devname, size,
+ size < SE_MU_HDR_SZ ? SE_MU_HDR_SZ :
+ MAX_ALLOWED_TX_MSG_SZ);
+ return -ENOSPC;
+ }
+
+ struct se_api_msg *tx_msg __free(kfree) = memdup_user(buf, size);
+ if (IS_ERR(tx_msg))
+ return PTR_ERR(tx_msg);
+
+ err = se_chk_tx_msg_hdr(dev_ctx, &tx_msg->header, size);
+ if (err)
+ return err;
+
+ print_hex_dump_debug("from user ", DUMP_PREFIX_OFFSET, 4, 4,
+ tx_msg, size, false);
+
+ err = ele_msg_send(dev_ctx, tx_msg, size);
+
+ return err;
+ }
+}
+
+/*
+ * Read a message from the MU.
+ * Blocking until a message is available.
+ */
+static ssize_t se_if_fops_read(struct file *fp, char __user *buf, size_t size,
+ loff_t *ppos)
+{
+ struct se_if_device_ctx *dev_ctx = fp->private_data;
+ u8 rx_msg_snap[MAX_NVM_MSG_LEN];
+ struct se_if_priv *priv;
+ unsigned long flags;
+ size_t copy_len;
+ int err;
+
+ scoped_cond_guard(mutex_intr, return -ERESTARTSYS, &dev_ctx->fops_lock) {
+ priv = dev_ctx->priv;
+
+ if (dev_ctx->cleanup_done)
+ return -ENODEV;
+
+ dev_dbg(priv->dev, "%s: read to buf %p(%zu), ppos=%lld.", dev_ctx->devname,
+ buf, size, ((ppos) ? *ppos : 0));
+
+ mutex_lock(&priv->modify_lock);
+ if (dev_ctx != priv->cmd_receiver_clbk_hdl.dev_ctx) {
+ mutex_unlock(&priv->modify_lock);
+ se_dev_ctx_shared_mem_cleanup(dev_ctx);
+ return -EINVAL;
+ }
+ mutex_unlock(&priv->modify_lock);
+ }
+
+ err = ele_msg_rcv(dev_ctx, &priv->cmd_receiver_clbk_hdl);
+ if (err < 0) {
+ if (err != -ERESTARTSYS)
+ dev_err(priv->dev,
+ "%s: Er[0x%x]: Signal Interrupted. Current act-dev-ctx count: %d.",
+ dev_ctx->devname, err, dev_ctx->priv->active_devctx_count);
+ return err;
+ }
+
+ /*
+ * Reacquire fops_lock before touching any dev_ctx state (pending lists,
+ * rx_msg) after the blocking wait. fops_lock was dropped before calling
+ * ele_msg_rcv(). If cleanup_dev_ctx() ran concurrently it could have
+ * freed the DMA buffers and the pending lists, leading to UAF and list
+ * corruption. Re-checking cleanup_done under fops_lock prevents that.
+ */
+ mutex_lock(&dev_ctx->fops_lock);
+
+ if (dev_ctx->cleanup_done) {
+ mutex_unlock(&dev_ctx->fops_lock);
+ return -ENODEV;
+ }
+
+ /*
+ * Snapshot rx_msg pointer under clbk_rx_lock before releasing it.
+ * unset_dev_ctx_as_command_receiver() can acquire the lock, NULL out
+ * rx_msg, and free the buffer at any time after the unlock; using a
+ * stale pointer from the shared field after the unlock is a UAF.
+ */
+ scoped_guard(mutex, &priv->modify_lock) {
+ spin_lock_irqsave(&priv->cmd_receiver_clbk_hdl.clbk_rx_lock, flags);
+ if (priv->cmd_receiver_clbk_hdl.dev_ctx != dev_ctx ||
+ !priv->cmd_receiver_clbk_hdl.rx_msg ||
+ !priv->cmd_receiver_clbk_hdl.rx_msg_sz) {
+ spin_unlock_irqrestore(&priv->cmd_receiver_clbk_hdl.clbk_rx_lock, flags);
+ mutex_unlock(&dev_ctx->fops_lock);
+ return -ENODEV;
+ }
+ /* Taking snapshot is enough for the one common pre-allocated buffer. */
+ copy_len = min(size, priv->cmd_receiver_clbk_hdl.rx_msg_sz);
+ memcpy(rx_msg_snap, priv->cmd_receiver_clbk_hdl.rx_msg, copy_len);
+ priv->cmd_receiver_clbk_hdl.rx_msg_sz = 0;
+ spin_unlock_irqrestore(&priv->cmd_receiver_clbk_hdl.clbk_rx_lock, flags);
+
+ /* We may need to copy the output data to user before
+ * delivering the completion message.
+ */
+ err = se_dev_ctx_cpy_out_data(dev_ctx);
+ if (err < 0) {
+ se_dev_ctx_shared_mem_cleanup(dev_ctx);
+ mutex_unlock(&dev_ctx->fops_lock);
+ return err;
+ }
+ /* Copy data from the buffer using the snapshot taken under the lock. */
+ print_hex_dump_debug("to user ", DUMP_PREFIX_OFFSET, 4, 4,
+ rx_msg_snap, copy_len, false);
+
+ err = copy_len;
+ if (copy_to_user(buf, rx_msg_snap, copy_len))
+ err = -EFAULT;
+
+ se_dev_ctx_shared_mem_cleanup(dev_ctx);
+ mutex_unlock(&dev_ctx->fops_lock);
+ }
+
+ return err;
+}
+
+/* Open a character device. */
+static int se_if_fops_open(struct inode *nd, struct file *fp)
+{
+ struct miscdevice *miscdev = fp->private_data;
+ struct se_if_open_gate *gate;
+ struct se_if_device_ctx *misc_dev_ctx;
+ struct se_if_device_ctx *dev_ctx;
+ struct se_if_priv *priv;
+ int err = 0;
+
+ gate = container_of(miscdev, struct se_if_open_gate, miscdev);
+
+ if (!se_if_open_gate_get(gate))
+ return -ENODEV;
+
+ if (mutex_lock_interruptible(&gate->lock)) {
+ se_if_open_gate_put(gate);
+ return -ERESTARTSYS;
+ }
+
+ if (gate->dying || !gate->priv ||
+ !kref_get_unless_zero(&gate->priv->refcount)) {
+ err = -ENODEV;
+ goto out_unlock_gate;
+ }
+
+ priv = gate->priv;
+ mutex_unlock(&gate->lock);
+
+ misc_dev_ctx = priv->priv_dev_ctx;
+
+ if (mutex_lock_interruptible(&misc_dev_ctx->fops_lock)) {
+ err = -ERESTARTSYS;
+ goto out_put_priv;
+ }
+
+ if (misc_dev_ctx->cleanup_done) {
+ err = -ENODEV;
+ goto out_unlock_misc;
+ }
+
+ priv->dev_ctx_mono_count++;
+ err = init_device_context(priv, priv->dev_ctx_mono_count, &dev_ctx);
+ if (err) {
+ dev_err(priv->dev, "Failed[0x%x] to create dev-ctx.", err);
+ goto out_unlock_misc;
+ }
+
+ fp->private_data = dev_ctx;
+
+out_unlock_misc:
+ mutex_unlock(&misc_dev_ctx->fops_lock);
+out_put_priv:
+ kref_put(&priv->refcount, se_if_priv_release);
+ se_if_open_gate_put(gate);
+ return err;
+out_unlock_gate:
+ mutex_unlock(&gate->lock);
+ se_if_open_gate_put(gate);
+ return err;
+}
+
+/* Close a character device. */
+static int se_if_fops_close(struct inode *nd, struct file *fp)
+{
+ struct se_if_device_ctx *dev_ctx = fp->private_data;
+
+ dlink_n_cleanup_dev_ctx(dev_ctx, true);
+
+ return 0;
+}
+
+/* IOCTL entry point of a character device */
+static long se_ioctl(struct file *fp, unsigned int cmd, unsigned long arg)
+{
+ struct se_if_device_ctx *dev_ctx = fp->private_data;
+ struct se_if_priv *priv;
+ void __user *uarg = (void __user *)arg;
+ long err;
+
+ /* Prevent race during change of device context */
+ scoped_cond_guard(mutex_intr, return -ERESTARTSYS, &dev_ctx->fops_lock) {
+ if (dev_ctx->cleanup_done)
+ return -ENODEV;
+
+ priv = dev_ctx->priv;
+
+ switch (cmd) {
+ case SE_IOCTL_ENABLE_CMD_RCV: {
+ err = set_dev_ctx_as_command_receiver(dev_ctx);
+ if (err)
+ dev_err(priv->dev, "Failed to register %s as CMD-Receiver: %ld\n",
+ dev_ctx->devname, err);
+ break;
+ }
+ case SE_IOCTL_GET_MU_INFO:
+ err = se_ioctl_get_mu_info(dev_ctx, uarg);
+ break;
+ case SE_IOCTL_SETUP_IOBUF:
+ err = se_ioctl_setup_iobuf_handler(dev_ctx, uarg);
+ break;
+ case SE_IOCTL_GET_SOC_INFO:
+ err = se_ioctl_get_se_soc_info_handler(dev_ctx, uarg);
+ break;
+ case SE_IOCTL_CMD_SEND_RCV_RSP:
+ err = se_ioctl_cmd_snd_rcv_rsp_handler(dev_ctx, uarg);
+ break;
+ default:
+ err = -ENOTTY;
+ dev_dbg(priv->dev, "%s: IOCTL %.8x not supported.",
+ dev_ctx->devname, cmd);
+ }
+ }
+
+ return err;
+}
+
+/* Char driver setup */
+static const struct file_operations se_if_fops = {
+ .open = se_if_fops_open,
+ .owner = THIS_MODULE,
+ .release = se_if_fops_close,
+ .unlocked_ioctl = se_ioctl,
+ .compat_ioctl = compat_ptr_ioctl,
+ .read = se_if_fops_read,
+ .write = se_if_fops_write,
+};
+
+int se_get_mem_pool_buf(struct se_if_device_ctx *dev_ctx, void **buf,
+ dma_addr_t *daddr, u32 len)
+{
+ struct se_shared_mem_mgmt_info *se_shared_mem_mgmt = &dev_ctx->se_shared_mem_mgmt;
+ struct se_if_priv *priv = dev_ctx->priv;
+ struct se_buf_desc *b_desc = NULL;
+
+ lockdep_assert_held(&dev_ctx->fops_lock);
+
+ if (se_is_fw_busy_ctx(dev_ctx))
+ return -EBUSY;
+
+ b_desc = kzalloc_obj(*b_desc, GFP_KERNEL);
+ if (!b_desc)
+ return -ENOMEM;
+
+ /*
+ * gen_pool is internally thread-safe, so contexts may allocate
+ * concurrently. The buffer is tracked on this context's own
+ * mem_pool_buf_list and released on its cleanup path.
+ */
+ *buf = gen_pool_dma_alloc(priv->mem_pool, len, daddr);
+ if (!*buf) {
+ dev_err(priv->dev, "Failed to alloc from gen_pool.\n");
+ kfree(b_desc);
+ return -ENOMEM;
+ }
+
+ /* gen_pool_dma_alloc() does not zero the buffer. */
+ memset(*buf, 0, len);
+ b_desc->shared_buf_ptr = *buf;
+ b_desc->size = len;
+
+ list_add_tail(&b_desc->link, &se_shared_mem_mgmt->mem_pool_buf_list);
+
+ return 0;
+}
+
+void se_cleanup_mem_pool_buf(struct se_if_device_ctx *dev_ctx, bool reclaim)
+{
+ struct se_shared_mem_mgmt_info *se_shared_mem_mgmt = &dev_ctx->se_shared_mem_mgmt;
+ struct se_if_priv *priv = dev_ctx->priv;
+ struct se_buf_desc *b_desc, *temp;
+
+ /*
+ * Free only the buffers this context allocated. A context that never
+ * used the pool has an empty list, so this is a no-op for it.
+ *
+ * Unlike the coherent staging buffer, the pool path needs no
+ * "nothing staged" (pos) gate on the reclaim=false leg. Pool buffers
+ * are ephemeral, per-transaction allocations: se_get_mem_pool_buf()
+ * refuses to allocate once the context is fw_busy, ele_msg_send_rcv()
+ * refuses to start a new command while fw_busy, and the success path
+ * frees the whole list via se_cleanup_mem_pool_buf(reclaim=true)
+ * before returning. se_if_cmd_lock serialises synchronous commands, so
+ * at most one transaction is outstanding. The only way to reach here
+ * with reclaim=false and a non-empty list is the single fw_busy
+ * context still owning the buffer(s) from the one timed-out
+ * transaction. Those buffers are exactly the in-flight ones the
+ * enclave may still be DMA-ing into, so leaving them on the list (no
+ * gen_pool_free) deliberately leaks them to avoid a DMA-after-free -
+ * there are no already-consumed pool buffers to reclaim on this leg.
+ */
+ list_for_each_entry_safe(b_desc, temp, &se_shared_mem_mgmt->mem_pool_buf_list, link) {
+ if (reclaim)
+ gen_pool_free(priv->mem_pool,
+ (unsigned long)b_desc->shared_buf_ptr,
+ b_desc->size);
+ list_del(&b_desc->link);
+ kfree(b_desc);
+ }
+}
+
+static void se_fw_busy_work(struct work_struct *work)
+{
+ struct se_if_priv *priv =
+ container_of(work, struct se_if_priv, fw_busy_work);
+
+ se_clear_fw_busy(priv);
+}
+
static int se_suspend(struct device *dev)
{
struct se_if_priv *priv = dev_get_drvdata(dev);
diff --git a/drivers/firmware/imx/se_ctrl.h b/drivers/firmware/imx/se_ctrl.h
index dd4a1ea7e35a..35389095ed1c 100644
--- a/drivers/firmware/imx/se_ctrl.h
+++ b/drivers/firmware/imx/se_ctrl.h
@@ -10,20 +10,40 @@
#include <linux/miscdevice.h>
#include <linux/mailbox_client.h>
#include <linux/semaphore.h>
+#include <linux/workqueue.h>
#define MAX_FW_LOAD_RETRIES 50
#define SE_MSG_WORD_SZ 0x4
#define RES_STATUS(x) FIELD_GET(0x000000ff, x)
+#define MAX_DATA_SIZE_PER_USER (128 * 1024)
#define MAX_NVM_MSG_LEN (256)
#define MESSAGING_VERSION_6 0x6
#define MESSAGING_VERSION_7 0x7
+struct se_if_open_gate {
+ struct miscdevice miscdev;
+ struct se_if_priv *priv;
+ /* to lock to update the structure */
+ struct mutex lock;
+ struct kref refcount;
+ bool dying;
+ /* set once misc_register() has succeeded (deferred to probe end) */
+ bool registered;
+};
+
struct se_clbk_handle {
struct se_if_device_ctx *dev_ctx;
struct completion done;
bool signal_rcvd;
+ /*
+ * Set under clbk_rx_lock once a real response is copied into rx_msg,
+ * cleared when a new transaction is armed. Lets ele_msg_rcv() tell a
+ * genuine response from a teardown-forced complete_all() with no data.
+ */
+ bool rx_delivered;
u32 rx_msg_sz;
+
/*
* Assignment of the rx_msg buffer to held till the
* received content as part callback function, is copied.
@@ -45,10 +65,46 @@ struct se_imem_buf {
u32 state;
};
+struct se_buf_desc {
+ u8 *shared_buf_ptr;
+ void __user *usr_buf_ptr;
+ u32 size;
+ struct list_head link;
+};
+
+struct se_shared_mem {
+ dma_addr_t dma_addr;
+ u32 size;
+ u32 pos;
+ u8 *ptr;
+};
+
+struct se_shared_mem_mgmt_info {
+ struct list_head mem_pool_buf_list;
+ struct list_head pending_in;
+ struct list_head pending_out;
+
+ struct se_shared_mem non_secure_mem;
+};
+
/* Private struct for each char device instance. */
struct se_if_device_ctx {
struct se_if_priv *priv;
+ struct miscdevice *miscdev;
const char *devname;
+ u32 sess_hdl;
+ u32 strg_hdl;
+ bool cleanup_done;
+ unsigned long rcv_msg_timeout_jiffies;
+
+ /* process one file operation at a time. */
+ struct mutex fops_lock;
+
+ struct se_shared_mem_mgmt_info se_shared_mem_mgmt;
+ struct list_head link;
+
+ /* Add reference counting */
+ struct kref refcount;
};
/* Header of the messages exchange with the EdgeLock Enclave */
@@ -113,9 +169,43 @@ struct se_if_priv {
struct se_fw_load_info load_fw;
atomic_t fw_busy;
+ /*
+ * Set once teardown begins. New synchronous transactions are rejected
+ * and a teardown-forced completion is not mistaken for a real firmware
+ * response.
+ */
+ atomic_t going_away;
+ /*
+ * Serialise the fw_busy_dev_ctx and fw_busy state updates between the
+ * timeout path, late-response callback/work, and teardown.
+ */
+ spinlock_t fw_busy_lock;
+ struct se_if_device_ctx *fw_busy_dev_ctx;
+ struct work_struct fw_busy_work;
struct se_if_device_ctx *priv_dev_ctx;
+ struct list_head dev_ctx_list;
+
+ /* prevent modifying priv member variable in parallel. */
+ struct mutex modify_lock;
+ u32 active_devctx_count;
+ u32 dev_ctx_mono_count;
+
+ /* Add reference counting */
+ struct kref refcount;
+
+ /* stable gate used by .open() */
+ struct se_if_open_gate *open_gate;
};
char *get_se_if_name(u8 se_if_id);
+void unset_dev_ctx_as_command_receiver(struct se_if_device_ctx *dev_ctx);
+int set_dev_ctx_as_command_receiver(struct se_if_device_ctx *dev_ctx);
+bool se_is_fw_busy_ctx(struct se_if_device_ctx *dev_ctx);
+void se_dev_ctx_shared_mem_cleanup(struct se_if_device_ctx *dev_ctx);
+int get_shared_mem_slot(struct se_if_device_ctx *dev_ctx,
+ u32 *length, dma_addr_t *ele_dma_addr, void **ptr);
+int se_get_mem_pool_buf(struct se_if_device_ctx *dev_ctx, void **buf,
+ dma_addr_t *daddr, u32 len);
+void se_cleanup_mem_pool_buf(struct se_if_device_ctx *dev_ctx, bool reclaim);
#endif
diff --git a/include/uapi/linux/se_ioctl.h b/include/uapi/linux/se_ioctl.h
new file mode 100644
index 000000000000..6302ff66034f
--- /dev/null
+++ b/include/uapi/linux/se_ioctl.h
@@ -0,0 +1,97 @@
+/* SPDX-License-Identifier: (GPL-2.0 WITH Linux-syscall-note) OR BSD-3-Clause*/
+/*
+ * Copyright 2025 NXP
+ */
+
+#ifndef SE_IOCTL_H
+#define SE_IOCTL_H
+
+#include <linux/types.h>
+
+#define SE_TYPE_STR_DBG "dbg"
+#define SE_TYPE_STR_HSM "hsm"
+#define SE_TYPE_ID_UNKWN 0x0
+#define SE_TYPE_ID_DBG 0x1
+#define SE_TYPE_ID_HSM 0x2
+/* IOCTL definitions. */
+
+struct se_ioctl_setup_iobuf {
+ __u64 user_buf;
+ __u32 length;
+ __u32 flags;
+ __u64 ele_addr;
+};
+
+struct se_ioctl_shared_mem_cfg {
+ __u32 base_offset;
+ __u32 size;
+};
+
+struct se_ioctl_get_if_info {
+ __u8 se_if_id;
+ __u8 interrupt_idx;
+ __u8 tz;
+ __u8 did;
+ __u8 cmd_tag;
+ __u8 rsp_tag;
+ __u8 success_tag;
+ __u8 base_api_ver;
+ __u8 fw_api_ver;
+};
+
+struct se_ioctl_cmd_snd_rcv_rsp_info {
+ __u64 tx_buf;
+ __u64 rx_buf;
+ __u32 tx_buf_sz;
+ __u32 rx_buf_sz;
+};
+
+struct se_ioctl_get_soc_info {
+ __u16 soc_id;
+ __u16 soc_rev;
+};
+
+/* IO Buffer Flags */
+#define SE_IO_BUF_FLAGS_IS_OUTPUT (0x00u)
+#define SE_IO_BUF_FLAGS_IS_INPUT (0x01u)
+#define SE_IO_BUF_FLAGS_USE_SEC_MEM (0x02u)
+#define SE_IO_BUF_FLAGS_USE_SHORT_ADDR (0x04u)
+#define SE_IO_BUF_FLAGS_IS_IN_OUT (0x10u)
+
+/* IOCTLS */
+#define SE_IOCTL 0x0A /* like MISC_MAJOR. */
+
+/*
+ * ioctl to designated the current fd as logical-reciever.
+ * This is ioctl is send when the nvm-daemon, a slave to the
+ * firmware is started by the user.
+ */
+#define SE_IOCTL_ENABLE_CMD_RCV _IO(SE_IOCTL, 0x01)
+
+/*
+ * ioctl to get the buffer allocated from the memory, which is shared
+ * between kernel and FW.
+ * Post allocation, the kernel tagged the allocated memory with:
+ * Output
+ * Input
+ * Input-Output
+ * Short address
+ * Secure-memory
+ */
+#define SE_IOCTL_SETUP_IOBUF _IOWR(SE_IOCTL, 0x03, struct se_ioctl_setup_iobuf)
+
+/*
+ * ioctl to get the mu information, that is used to exchange message
+ * with FW, from user-spaced.
+ */
+#define SE_IOCTL_GET_MU_INFO _IOR(SE_IOCTL, 0x04, struct se_ioctl_get_if_info)
+/*
+ * ioctl to get SoC Info from user-space.
+ */
+#define SE_IOCTL_GET_SOC_INFO _IOR(SE_IOCTL, 0x06, struct se_ioctl_get_soc_info)
+
+/*
+ * ioctl to send command and receive response from user-space.
+ */
+#define SE_IOCTL_CMD_SEND_RCV_RSP _IOWR(SE_IOCTL, 0x07, struct se_ioctl_cmd_snd_rcv_rsp_info)
+#endif
--
2.43.0
^ permalink raw reply related [flat|nested] 15+ messages in thread* Re: [PATCH v35 5/7] firmware: imx: adds miscdev
2026-08-06 11:51 ` [PATCH v35 5/7] firmware: imx: adds miscdev pankaj.gupta
@ 2026-08-06 11:27 ` sashiko-bot
2026-08-06 16:31 ` Frank Li
0 siblings, 1 reply; 15+ messages in thread
From: sashiko-bot @ 2026-08-06 11:27 UTC (permalink / raw)
To: pankaj.gupta; +Cc: Frank.Li, imx, robh, devicetree, conor+dt
Thank you for your contribution! Sashiko AI review found 5 potential issue(s) to consider:
- [Critical] The driver allows userspace to embed arbitrary DMA addresses in permitted firmware commands, enabling arbitrary physical memory overwrite.
- [High] The `se_if_open_gate` structure can be accessed after it is freed if an `open()` system call races with driver unbind.
- [High] A concurrent `close()` racing with driver unbind causes a Use-After-Free on the mailbox channel `priv->tx_chan` due to premature unlinking.
- [High] Firmware session and storage handles can be permanently leaked if response validation or userspace memory copies fail, bypassing the tracking of allocated handles.
- [High] Signal interruption converts an interruptible wait into an unkillable uninterruptible wait for up to 5000 seconds.
--
--- Patch [5]: [PATCH v35 5/7] firmware: imx: adds miscdev ---
commit a678d58783e842f1a853a0ba674864702cf30910
Author: Pankaj Gupta <pankaj.gupta@nxp.com>
Subject: firmware: imx: adds miscdev
This commit adds a character driver to communicate with the NXP secure
enclave hardware. It provides an ioctl interface for userspace applications
to send commands, manage shared memory, and restricts invalid or disallowed
firmware commands.
Closes: https://sashiko.dev/#/patchset/20260805-imx-se-if-v34-0-7e4713d14e0a@nxp.com?part=5
> diff --git a/drivers/firmware/imx/ele_base_msg.c b/drivers/firmware/imx/ele_base_msg.c
> --- a/drivers/firmware/imx/ele_base_msg.c
> +++ b/drivers/firmware/imx/ele_base_msg.c
> @@ -15,13 +15,57 @@
>
> #define FW_DBG_DUMP_FIXED_STR "ELE"
>
> +int ele_uapi_allowed_base_cmd(struct se_if_priv *priv,
> + struct se_msg_hdr *header)
> +{
> + switch (header->command) {
> + case ELE_PING_REQ: return 0;
> + case ELE_DEBUG_DUMP_REQ: return 0;
> + case ELE_OEM_AUTH_CONTAINER_REQ: return 0;
> + case ELE_OEM_VERIFY_IMAGE_REQ: return 0;
> + case ELE_OEM_REL_CONTAINER_REQ: return 0;
> + case ELE_FW_LIFE_CYCLE_REQ: return 0;
> + case ELE_READ_FUSE_REQ: return 0;
> + case ELE_GET_FW_VERS_REQ: return 0;
> + case ELE_RETURN_LIFE_CYCLE_REQ: return 0;
> + case ELE_GET_EVENT_REQ: return 0;
> + case ELE_COMMIT_REQ: return 0;
> + case ELE_GEN_KEY_BLOB_REQ: return 0;
> + case ELE_GET_FW_STATUS_REQ: return 0;
> + case ELE_XIP_DECRYPT_REQ: return 0;
> + case ELE_WRITE_FUSE: return 0;
> + case ELE_GET_INFO_REQ: return 0;
> + case ELE_DEV_ATTEST_REQ: return 0;
> + case ELE_WRITE_SHADOW_FUSE_REQ: return 0;
> + case ELE_READ_SHADOW_FUSE_REQ: return 0;
> + default:
> + return -EACCES;
> + }
> +}
[Severity: Critical]
Does this allowlist permit userspace to embed arbitrary DMA addresses without
kernel validation?
Commands like ELE_GET_INFO_REQ accept physical DMA addresses directly in
their payloads. Because se_chk_tx_msg_hdr() only validates the command header
against this list and performs no payload sanitization, could an unprivileged
user embed arbitrary physical addresses (e.g., kernel text) leading to the
hardware enclave overwriting arbitrary memory?
> diff --git a/drivers/firmware/imx/ele_common.c b/drivers/firmware/imx/ele_common.c
> --- a/drivers/firmware/imx/ele_common.c
> +++ b/drivers/firmware/imx/ele_common.c
[ ... ]
> @@ -71,7 +122,7 @@ int ele_msg_rcv(struct se_if_device_ctx *dev_ctx, struct se_clbk_handle *se_clbk
> + if (ret == -ERESTARTSYS) {
> + /*
> + * Record that a signal was observed, then continue waiting non-
> + * interruptibly until the response arrives or the timeout
> + * expires. The caller can surface the interruption to userspace
> + * after the protocol transaction is brought back to a
> + * synchronized state.
> + */
> + if (is_rsp_wait_with_timeout &&
> + READ_ONCE(se_clbk_hdl->rx_msg)) {
> + WRITE_ONCE(se_clbk_hdl->signal_rcvd, true);
> + wait_uninterruptible = true;
> + continue;
> + }
> + break;
> + }
[Severity: High]
Can this loop trap a process in an unkillable state for a very long time?
If a process is interrupted by a signal while waiting in ele_msg_rcv(), the
code converts the interruptible wait into an uninterruptible one by setting
wait_uninterruptible = true. Given that SE_RCV_MSG_LONG_TIMEOUT_MS is 5000
seconds, this could leave the task unkillable for over an hour, potentially
triggering the kernel's hung task watchdog.
> diff --git a/drivers/firmware/imx/se_ctrl.c b/drivers/firmware/imx/se_ctrl.c
> --- a/drivers/firmware/imx/se_ctrl.c
> +++ b/drivers/firmware/imx/se_ctrl.c
[ ... ]
> +static void dlink_n_cleanup_dev_ctx(struct se_if_device_ctx *dev_ctx, bool is_fclose)
> +{
> + struct se_if_priv *priv = dev_ctx->priv;
> +
> + if (is_fclose) {
> + scoped_guard(mutex, &priv->modify_lock)
> + dlink_dev_ctx(dev_ctx);
> + }
> +
> + cleanup_dev_ctx(dev_ctx, is_fclose);
> +}
[Severity: High]
Does unlinking dev_ctx before executing cleanup_dev_ctx() open a race
condition during driver unbind?
In se_if_probe_cleanup(), the unbind thread iterates over priv->dev_ctx_list
to gracefully close contexts. By unlinking the context here before the
cleanup completes, the unbind thread won't see it, won't block on fops_lock,
and might call mbox_free_channel(priv->tx_chan) prematurely. This could cause
the concurrent close thread to send on a freed channel in ele_msg_send().
[ ... ]
> + rsp_status_err =
> + se_val_rsp_hdr_n_status(priv, rx_msg, tx_msg->header.command,
> + cmd_snd_rcv_rsp_info.rx_buf_sz,
> + tx_msg->header.ver == priv->if_defs->base_api_ver);
> +
> + if (!rsp_status_err) {
> + err = se_dev_ctx_cpy_out_data(dev_ctx);
> + if (err < 0) {
> + se_ioctl_cmd_snd_rcv_cleanup(dev_ctx, uarg, &cmd_snd_rcv_rsp_info);
> + return err;
> + }
> + }
> +
> + /* Copy data from the buffer */
> + print_hex_dump_debug("to user ", DUMP_PREFIX_OFFSET, 4, 4, rx_msg,
> + cmd_snd_rcv_rsp_info.rx_buf_sz, false);
> +
> + if (copy_to_user(u64_to_user_ptr(cmd_snd_rcv_rsp_info.rx_buf), rx_msg,
> + cmd_snd_rcv_rsp_info.rx_buf_sz)) {
> + dev_err(priv->dev, "%s: Failed to copy to user.", dev_ctx->devname);
> + err = -EFAULT;
> + }
> +
> + cleanup_err = se_ioctl_cmd_snd_rcv_cleanup(dev_ctx, uarg, &cmd_snd_rcv_rsp_info);
> +
> + if (cleanup_err && !err)
> + err = cleanup_err;
> +
> + if (!err && !rsp_status_err)
> + fw_api_specific_ops(dev_ctx, rx_msg);
[Severity: High]
Could this error handling sequence leak firmware session or storage handles?
If the firmware successfully executes an ELE_SESSION_OPEN_REQ, it allocates a
handle. However, if a user submits an intentionally truncated rx_buf_sz
(causing se_val_rsp_hdr_n_status() to fail) or a bad user pointer (causing
copy_to_user() to fail), the function skips calling fw_api_specific_ops().
This leaves the handle untracked by the kernel, preventing cleanup and
leaking hardware resources.
[ ... ]
> +/* Open a character device. */
> +static int se_if_fops_open(struct inode *nd, struct file *fp)
> +{
> + struct miscdevice *miscdev = fp->private_data;
> + struct se_if_open_gate *gate;
> + struct se_if_device_ctx *misc_dev_ctx;
> + struct se_if_device_ctx *dev_ctx;
> + struct se_if_priv *priv;
> + int err = 0;
> +
> + gate = container_of(miscdev, struct se_if_open_gate, miscdev);
> +
> + if (!se_if_open_gate_get(gate))
> + return -ENODEV;
[Severity: High]
Is there a use-after-free risk if open() races with driver unbind?
When the module unbinds, se_if_probe_cleanup() calls misc_deregister(),
which does not fully synchronize with active open() calls. If the unbind
thread drops the final reference to priv in se_if_priv_release(),
se_if_open_gate_put() frees the gate object. A concurrent se_if_fops_open()
might then attempt to access the refcount of this already freed gate pointer.
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260806-imx-se-if-v35-0-11b25bb308ef@nxp.com?part=5
^ permalink raw reply [flat|nested] 15+ messages in thread* Re: [PATCH v35 5/7] firmware: imx: adds miscdev
2026-08-06 11:27 ` sashiko-bot
@ 2026-08-06 16:31 ` Frank Li
0 siblings, 0 replies; 15+ messages in thread
From: Frank Li @ 2026-08-06 16:31 UTC (permalink / raw)
To: sashiko-reviews; +Cc: pankaj.gupta, Frank.Li, imx, robh, devicetree, conor+dt
On Thu, Aug 06, 2026 at 11:27:24AM +0000, sashiko-bot@kernel.org wrote:
> Thank you for your contribution! Sashiko AI review found 5 potential issue(s) to consider:
> - [Critical] The driver allows userspace to embed arbitrary DMA addresses in permitted firmware commands, enabling arbitrary physical memory overwrite.
> - [High] The `se_if_open_gate` structure can be accessed after it is freed if an `open()` system call races with driver unbind.
> - [High] A concurrent `close()` racing with driver unbind causes a Use-After-Free on the mailbox channel `priv->tx_chan` due to premature unlinking.
> - [High] Firmware session and storage handles can be permanently leaked if response validation or userspace memory copies fail, bypassing the tracking of allocated handles.
> - [High] Signal interruption converts an interruptible wait into an unkillable uninterruptible wait for up to 5000 seconds.
> --
>
> --- Patch [5]: [PATCH v35 5/7] firmware: imx: adds miscdev ---
> commit a678d58783e842f1a853a0ba674864702cf30910
> Author: Pankaj Gupta <pankaj.gupta@nxp.com>
> Subject: firmware: imx: adds miscdev
>
> This commit adds a character driver to communicate with the NXP secure
> enclave hardware. It provides an ioctl interface for userspace applications
> to send commands, manage shared memory, and restricts invalid or disallowed
> firmware commands.
>
> Closes: https://sashiko.dev/#/patchset/20260805-imx-se-if-v34-0-7e4713d14e0a@nxp.com?part=5
>
> > diff --git a/drivers/firmware/imx/ele_base_msg.c b/drivers/firmware/imx/ele_base_msg.c
> > --- a/drivers/firmware/imx/ele_base_msg.c
> > +++ b/drivers/firmware/imx/ele_base_msg.c
> > @@ -15,13 +15,57 @@
> >
> > #define FW_DBG_DUMP_FIXED_STR "ELE"
> >
> > +int ele_uapi_allowed_base_cmd(struct se_if_priv *priv,
> > + struct se_msg_hdr *header)
> > +{
> > + switch (header->command) {
> > + case ELE_PING_REQ: return 0;
> > + case ELE_DEBUG_DUMP_REQ: return 0;
> > + case ELE_OEM_AUTH_CONTAINER_REQ: return 0;
> > + case ELE_OEM_VERIFY_IMAGE_REQ: return 0;
> > + case ELE_OEM_REL_CONTAINER_REQ: return 0;
> > + case ELE_FW_LIFE_CYCLE_REQ: return 0;
> > + case ELE_READ_FUSE_REQ: return 0;
> > + case ELE_GET_FW_VERS_REQ: return 0;
> > + case ELE_RETURN_LIFE_CYCLE_REQ: return 0;
> > + case ELE_GET_EVENT_REQ: return 0;
> > + case ELE_COMMIT_REQ: return 0;
> > + case ELE_GEN_KEY_BLOB_REQ: return 0;
> > + case ELE_GET_FW_STATUS_REQ: return 0;
> > + case ELE_XIP_DECRYPT_REQ: return 0;
> > + case ELE_WRITE_FUSE: return 0;
> > + case ELE_GET_INFO_REQ: return 0;
> > + case ELE_DEV_ATTEST_REQ: return 0;
> > + case ELE_WRITE_SHADOW_FUSE_REQ: return 0;
> > + case ELE_READ_SHADOW_FUSE_REQ: return 0;
> > + default:
> > + return -EACCES;
> > + }
> > +}
>
> [Severity: Critical]
> Does this allowlist permit userspace to embed arbitrary DMA addresses without
> kernel validation?
>
> Commands like ELE_GET_INFO_REQ accept physical DMA addresses directly in
> their payloads. Because se_chk_tx_msg_hdr() only validates the command header
> against this list and performs no payload sanitization, could an unprivileged
> user embed arbitrary physical addresses (e.g., kernel text) leading to the
> hardware enclave overwriting arbitrary memory?
This one may security hole, you need check payload to make sure DMA
address is in ranges.
>
> > diff --git a/drivers/firmware/imx/ele_common.c b/drivers/firmware/imx/ele_common.c
> > --- a/drivers/firmware/imx/ele_common.c
> > +++ b/drivers/firmware/imx/ele_common.c
> [ ... ]
> > @@ -71,7 +122,7 @@ int ele_msg_rcv(struct se_if_device_ctx *dev_ctx, struct se_clbk_handle *se_clbk
> > + if (ret == -ERESTARTSYS) {
> > + /*
> > + * Record that a signal was observed, then continue waiting non-
> > + * interruptibly until the response arrives or the timeout
> > + * expires. The caller can surface the interruption to userspace
> > + * after the protocol transaction is brought back to a
> > + * synchronized state.
> > + */
> > + if (is_rsp_wait_with_timeout &&
> > + READ_ONCE(se_clbk_hdl->rx_msg)) {
> > + WRITE_ONCE(se_clbk_hdl->signal_rcvd, true);
> > + wait_uninterruptible = true;
> > + continue;
> > + }
> > + break;
> > + }
>
> [Severity: High]
> Can this loop trap a process in an unkillable state for a very long time?
>
> If a process is interrupted by a signal while waiting in ele_msg_rcv(), the
> code converts the interruptible wait into an uninterruptible one by setting
> wait_uninterruptible = true. Given that SE_RCV_MSG_LONG_TIMEOUT_MS is 5000
> seconds, this could leave the task unkillable for over an hour, potentially
> triggering the kernel's hung task watchdog.
This one need double check.
Other high problem need your judgement.
Frank
>
> > diff --git a/drivers/firmware/imx/se_ctrl.c b/drivers/firmware/imx/se_ctrl.c
> > --- a/drivers/firmware/imx/se_ctrl.c
> > +++ b/drivers/firmware/imx/se_ctrl.c
> [ ... ]
> > +static void dlink_n_cleanup_dev_ctx(struct se_if_device_ctx *dev_ctx, bool is_fclose)
> > +{
> > + struct se_if_priv *priv = dev_ctx->priv;
> > +
> > + if (is_fclose) {
> > + scoped_guard(mutex, &priv->modify_lock)
> > + dlink_dev_ctx(dev_ctx);
> > + }
> > +
> > + cleanup_dev_ctx(dev_ctx, is_fclose);
> > +}
>
> [Severity: High]
> Does unlinking dev_ctx before executing cleanup_dev_ctx() open a race
> condition during driver unbind?
>
> In se_if_probe_cleanup(), the unbind thread iterates over priv->dev_ctx_list
> to gracefully close contexts. By unlinking the context here before the
> cleanup completes, the unbind thread won't see it, won't block on fops_lock,
> and might call mbox_free_channel(priv->tx_chan) prematurely. This could cause
> the concurrent close thread to send on a freed channel in ele_msg_send().
>
> [ ... ]
> > + rsp_status_err =
> > + se_val_rsp_hdr_n_status(priv, rx_msg, tx_msg->header.command,
> > + cmd_snd_rcv_rsp_info.rx_buf_sz,
> > + tx_msg->header.ver == priv->if_defs->base_api_ver);
> > +
> > + if (!rsp_status_err) {
> > + err = se_dev_ctx_cpy_out_data(dev_ctx);
> > + if (err < 0) {
> > + se_ioctl_cmd_snd_rcv_cleanup(dev_ctx, uarg, &cmd_snd_rcv_rsp_info);
> > + return err;
> > + }
> > + }
> > +
> > + /* Copy data from the buffer */
> > + print_hex_dump_debug("to user ", DUMP_PREFIX_OFFSET, 4, 4, rx_msg,
> > + cmd_snd_rcv_rsp_info.rx_buf_sz, false);
> > +
> > + if (copy_to_user(u64_to_user_ptr(cmd_snd_rcv_rsp_info.rx_buf), rx_msg,
> > + cmd_snd_rcv_rsp_info.rx_buf_sz)) {
> > + dev_err(priv->dev, "%s: Failed to copy to user.", dev_ctx->devname);
> > + err = -EFAULT;
> > + }
> > +
> > + cleanup_err = se_ioctl_cmd_snd_rcv_cleanup(dev_ctx, uarg, &cmd_snd_rcv_rsp_info);
> > +
> > + if (cleanup_err && !err)
> > + err = cleanup_err;
> > +
> > + if (!err && !rsp_status_err)
> > + fw_api_specific_ops(dev_ctx, rx_msg);
>
> [Severity: High]
> Could this error handling sequence leak firmware session or storage handles?
>
> If the firmware successfully executes an ELE_SESSION_OPEN_REQ, it allocates a
> handle. However, if a user submits an intentionally truncated rx_buf_sz
> (causing se_val_rsp_hdr_n_status() to fail) or a bad user pointer (causing
> copy_to_user() to fail), the function skips calling fw_api_specific_ops().
> This leaves the handle untracked by the kernel, preventing cleanup and
> leaking hardware resources.
>
> [ ... ]
> > +/* Open a character device. */
> > +static int se_if_fops_open(struct inode *nd, struct file *fp)
> > +{
> > + struct miscdevice *miscdev = fp->private_data;
> > + struct se_if_open_gate *gate;
> > + struct se_if_device_ctx *misc_dev_ctx;
> > + struct se_if_device_ctx *dev_ctx;
> > + struct se_if_priv *priv;
> > + int err = 0;
> > +
> > + gate = container_of(miscdev, struct se_if_open_gate, miscdev);
> > +
> > + if (!se_if_open_gate_get(gate))
> > + return -ENODEV;
>
> [Severity: High]
> Is there a use-after-free risk if open() races with driver unbind?
>
> When the module unbinds, se_if_probe_cleanup() calls misc_deregister(),
> which does not fully synchronize with active open() calls. If the unbind
> thread drops the final reference to priv in se_if_priv_release(),
> se_if_open_gate_put() frees the gate object. A concurrent se_if_fops_open()
> might then attempt to access the refcount of this already freed gate pointer.
>
> --
> Sashiko AI review · https://sashiko.dev/#/patchset/20260806-imx-se-if-v35-0-11b25bb308ef@nxp.com?part=5
^ permalink raw reply [flat|nested] 15+ messages in thread
* [PATCH v35 6/7] arm64: dts: imx8ulp: add secure enclave node
2026-08-06 11:51 [PATCH v35 0/7] firmware: imx: driver for NXP secure-enclave pankaj.gupta
` (4 preceding siblings ...)
2026-08-06 11:51 ` [PATCH v35 5/7] firmware: imx: adds miscdev pankaj.gupta
@ 2026-08-06 11:51 ` pankaj.gupta
2026-08-06 11:13 ` sashiko-bot
2026-08-06 11:51 ` [PATCH v35 7/7] arm64: dts: imx8ulp: add reserved memory for EdgeLock Enclave pankaj.gupta
6 siblings, 1 reply; 15+ messages in thread
From: pankaj.gupta @ 2026-08-06 11:51 UTC (permalink / raw)
To: Jonathan Corbet, Shuah Khan, Rob Herring, Krzysztof Kozlowski,
Conor Dooley, Frank Li, Sascha Hauer, Pengutronix Kernel Team,
Fabio Estevam, Pankaj Gupta
Cc: linux-doc, linux-kernel, devicetree, imx, linux-arm-kernel
From: Pankaj Gupta <pankaj.gupta@nxp.com>
Add the EdgeLock Enclave (ELE) secure-enclave node to the i.MX8ULP SoC
dtsi, together with a label for sram@2201f000 that the node references.
Keep the node disabled in the SoC dtsi so it does not impose a
reserved-memory requirement on every board. Boards enable the enclave and
provide its memory-region by including imx8ulp-firmware.dtsi.
Signed-off-by: Pankaj Gupta <pankaj.gupta@nxp.com>
Reviewed-by: Frank Li <Frank.Li@nxp.com>
---
arch/arm64/boot/dts/freescale/imx8ulp.dtsi | 12 ++++++++++--
1 file changed, 10 insertions(+), 2 deletions(-)
diff --git a/arch/arm64/boot/dts/freescale/imx8ulp.dtsi b/arch/arm64/boot/dts/freescale/imx8ulp.dtsi
index c6d1bb9edf38..38233dd74ee3 100644
--- a/arch/arm64/boot/dts/freescale/imx8ulp.dtsi
+++ b/arch/arm64/boot/dts/freescale/imx8ulp.dtsi
@@ -1,6 +1,6 @@
// SPDX-License-Identifier: (GPL-2.0+ OR MIT)
/*
- * Copyright 2021 NXP
+ * Copyright 2021, 2025 NXP
*/
#include <dt-bindings/clock/imx8ulp-clock.h>
@@ -153,7 +153,7 @@ sosc: clock-sosc {
#clock-cells = <0>;
};
- sram@2201f000 {
+ sram0: sram@2201f000 {
compatible = "mmio-sram";
reg = <0x0 0x2201f000 0x0 0x1000>;
@@ -185,6 +185,14 @@ scmi_sensor: protocol@15 {
#thermal-sensor-cells = <1>;
};
};
+
+ hsm0: secure-enclave {
+ compatible = "fsl,imx8ulp-se-ele-hsm";
+ mbox-names = "tx", "rx";
+ mboxes = <&s4muap 0 0>, <&s4muap 1 0>;
+ sram = <&sram0>;
+ status = "disabled";
+ };
};
cm33: remoteproc-cm33 {
--
2.43.0
^ permalink raw reply related [flat|nested] 15+ messages in thread* Re: [PATCH v35 6/7] arm64: dts: imx8ulp: add secure enclave node
2026-08-06 11:51 ` [PATCH v35 6/7] arm64: dts: imx8ulp: add secure enclave node pankaj.gupta
@ 2026-08-06 11:13 ` sashiko-bot
0 siblings, 0 replies; 15+ messages in thread
From: sashiko-bot @ 2026-08-06 11:13 UTC (permalink / raw)
To: pankaj.gupta; +Cc: devicetree, robh, imx, Frank.Li, conor+dt
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Medium] The newly added `hsm0` node lacks the mandatory `memory-region` property, causing a `dtbs_check` validation failure. Additionally, the file `imx8ulp-firmware.dtsi` referenced in the commit message is missing from the patch series.
--
--- Patch [6]: [PATCH v35 6/7] arm64: dts: imx8ulp: add secure enclave node ---
commit c890c3315c7900443e29c20509319084f32b21c7
Author: Pankaj Gupta <pankaj.gupta@nxp.com>
arm64: dts: imx8ulp: add secure enclave node
Add the EdgeLock Enclave (ELE) secure-enclave node to the i.MX8ULP SoC
dtsi. The node is kept disabled so it does not impose a reserved-memory
requirement on every board, and the commit message notes that boards can
provide the memory-region by including imx8ulp-firmware.dtsi.
> diff --git a/arch/arm64/boot/dts/freescale/imx8ulp.dtsi b/arch/arm64/boot/dts/freescale/imx8ulp.dtsi
> index c6d1bb9edf388..38233dd74ee33 100644
> --- a/arch/arm64/boot/dts/freescale/imx8ulp.dtsi
> +++ b/arch/arm64/boot/dts/freescale/imx8ulp.dtsi
[ ... ]
> @@ -185,6 +185,14 @@ scmi_sensor: protocol@15 {
> #thermal-sensor-cells = <1>;
> };
> };
> +
> + hsm0: secure-enclave {
> + compatible = "fsl,imx8ulp-se-ele-hsm";
> + mbox-names = "tx", "rx";
> + mboxes = <&s4muap 0 0>, <&s4muap 1 0>;
> + sram = <&sram0>;
> + status = "disabled";
> + };
[Severity: Medium]
Will adding this node without a memory-region property cause a dtbs_check
validation failure?
According to Documentation/devicetree/bindings/firmware/fsl,imx-se.yaml, the
schema unconditionally enforces the memory-region requirement for this
compatible string:
- if:
properties:
compatible:
contains:
enum:
- fsl,imx8ulp-se-ele-hsm
- fsl,imx93-se-ele-hsm
then:
required:
- memory-region
Even though the node is disabled, it seems any board including this dtsi
will fail device tree schema validation due to the missing required property.
Additionally, the commit message states:
> Boards enable the enclave and provide its memory-region by including
> imx8ulp-firmware.dtsi.
Is there a missing patch in this series? The imx8ulp-firmware.dtsi file
mentioned in the commit message does not appear to be included in this patch
or currently present in the tree.
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260806-imx-se-if-v35-0-11b25bb308ef@nxp.com?part=6
^ permalink raw reply [flat|nested] 15+ messages in thread
* [PATCH v35 7/7] arm64: dts: imx8ulp: add reserved memory for EdgeLock Enclave
2026-08-06 11:51 [PATCH v35 0/7] firmware: imx: driver for NXP secure-enclave pankaj.gupta
` (5 preceding siblings ...)
2026-08-06 11:51 ` [PATCH v35 6/7] arm64: dts: imx8ulp: add secure enclave node pankaj.gupta
@ 2026-08-06 11:51 ` pankaj.gupta
6 siblings, 0 replies; 15+ messages in thread
From: pankaj.gupta @ 2026-08-06 11:51 UTC (permalink / raw)
To: Jonathan Corbet, Shuah Khan, Rob Herring, Krzysztof Kozlowski,
Conor Dooley, Frank Li, Sascha Hauer, Pengutronix Kernel Team,
Fabio Estevam, Pankaj Gupta
Cc: linux-doc, linux-kernel, devicetree, imx, linux-arm-kernel
From: Pankaj Gupta <pankaj.gupta@nxp.com>
Reserve 1MB of DDR for the EdgeLock Enclave. The enclave hardware can only
access DDR in the 0x80000000 - 0xafffffff window, so constrain the pool to
that range with alloc-ranges and let the kernel choose the placement rather
than hardcoding an address.
Provide this as a shared imx8ulp-firmware.dtsi that also enables the hsm0
node and wires up its memory-region, so every i.MX8ULP board can bring up
the enclave with a single include instead of duplicating the reserved
memory node. Include it from imx8ulp-evk.
Signed-off-by: Pankaj Gupta <pankaj.gupta@nxp.com>
Reviewed-by: Frank Li <Frank.Li@nxp.com>
---
arch/arm64/boot/dts/freescale/imx8ulp-evk.dts | 3 ++-
.../arm64/boot/dts/freescale/imx8ulp-firmware.dtsi | 31 ++++++++++++++++++++++
2 files changed, 33 insertions(+), 1 deletion(-)
diff --git a/arch/arm64/boot/dts/freescale/imx8ulp-evk.dts b/arch/arm64/boot/dts/freescale/imx8ulp-evk.dts
index 5dea66c1e7aa..885242fd07ce 100644
--- a/arch/arm64/boot/dts/freescale/imx8ulp-evk.dts
+++ b/arch/arm64/boot/dts/freescale/imx8ulp-evk.dts
@@ -1,11 +1,12 @@
// SPDX-License-Identifier: (GPL-2.0+ OR MIT)
/*
- * Copyright 2021 NXP
+ * Copyright 2021, 2025 NXP
*/
/dts-v1/;
#include "imx8ulp.dtsi"
+#include "imx8ulp-firmware.dtsi"
/ {
model = "NXP i.MX8ULP EVK";
diff --git a/arch/arm64/boot/dts/freescale/imx8ulp-firmware.dtsi b/arch/arm64/boot/dts/freescale/imx8ulp-firmware.dtsi
new file mode 100644
index 000000000000..e4bc352f68af
--- /dev/null
+++ b/arch/arm64/boot/dts/freescale/imx8ulp-firmware.dtsi
@@ -0,0 +1,31 @@
+// SPDX-License-Identifier: (GPL-2.0+ OR MIT)
+/*
+ * Copyright 2025 NXP
+ *
+ * Default reserved memory and EdgeLock Enclave (ELE) enablement shared by
+ * i.MX8ULP boards. Include this from a board dts to bring up the secure
+ * enclave without having to duplicate the reserved-memory node. The ELE
+ * hardware can only access DDR in the 0x80000000 - 0xafffffff window, so the
+ * pool is constrained to that range with alloc-ranges and the kernel is left
+ * to place the 1 MiB region.
+ */
+
+/ {
+ reserved-memory {
+ #address-cells = <2>;
+ #size-cells = <2>;
+ ranges;
+
+ ele_reserved: ele-reserved {
+ compatible = "shared-dma-pool";
+ alloc-ranges = <0 0x80000000 0 0x30000000>;
+ size = <0 0x100000>;
+ no-map;
+ };
+ };
+};
+
+&hsm0 {
+ memory-region = <&ele_reserved>;
+ status = "okay";
+};
--
2.43.0
^ permalink raw reply related [flat|nested] 15+ messages in thread