* [PATCH v3 0/2] Add Apple T2 NHI device links @ 2026-07-21 6:34 Atharva Tiwari 2026-07-21 6:34 ` [PATCH v3 1/2] treewide: Add a flag to detect the Apple T2 chip Atharva Tiwari 2026-07-21 6:34 ` [PATCH v3 2/2] thunderbolt: Add device links for Apple T2 NHI Atharva Tiwari 0 siblings, 2 replies; 6+ messages in thread From: Atharva Tiwari @ 2026-07-21 6:34 UTC (permalink / raw) Cc: Atharva Tiwari, Bjorn Helgaas, Thomas Gleixner, Ingo Molnar, Borislav Petkov, Dave Hansen, x86, H. Peter Anvin, Andreas Noever, Mika Westerberg, Yehezkel Bernat, Hans de Goede, Ilpo Järvinen, Jarkko Sakkinen, Mimi Zohar, Roberto Sassu, Dmitry Kasatkin, Eric Snowberg, Paul Moore, James Morris, Serge E. Hallyn, linux-pci, linux-kernel, linux-usb, platform-driver-x86, linux-integrity, keyrings, linux-security-module This series adds a cached flag to detect Apple T2 systems, then uses it to create device links for the Thunderbolt NHI. Changes in v3: - Fix build errors with non-x86 machines - Used __initconst for apple_t2_devices - Removed UEFI_QUIRK_SKIP_CERT as its unused now - Used IS_ENABLED(CONFIG_ACPI) in tb_apple_add_links for the T2 part - Removed !bid check to remove warning with -Waddress Changes in v2: - Used a less generic name for has_t2_chip - Used DMI instead of PCI for has_apple_t2_chip to avoid PCI problems - Initialized ret in tb_apple_add_links Link to v2: https://lore.kernel.org/all/20260721054506.11871-1-atharvatiwarilinuxdev@gmail.com/ Link to v1: https://lore.kernel.org/all/20260719180308.1398-1-atharvatiwarilinuxdev@gmail.com/ Atharva Tiwari (2): treewide: Add a flag to detect the Apple T2 chip thunderbolt: Add device links for Apple T2 NHI arch/x86/kernel/quirks.c | 105 ++++++++++++++++++ drivers/thunderbolt/tb.c | 51 ++++++++- include/linux/platform_data/x86/apple.h | 5 + .../platform_certs/keyring_handler.h | 8 -- security/integrity/platform_certs/load_uefi.c | 38 ++----- 5 files changed, 168 insertions(+), 39 deletions(-) -- 2.43.0 ^ permalink raw reply [flat|nested] 6+ messages in thread
* [PATCH v3 1/2] treewide: Add a flag to detect the Apple T2 chip 2026-07-21 6:34 [PATCH v3 0/2] Add Apple T2 NHI device links Atharva Tiwari @ 2026-07-21 6:34 ` Atharva Tiwari 2026-07-21 10:57 ` Jarkko Sakkinen 2026-07-21 15:29 ` Hans de Goede 2026-07-21 6:34 ` [PATCH v3 2/2] thunderbolt: Add device links for Apple T2 NHI Atharva Tiwari 1 sibling, 2 replies; 6+ messages in thread From: Atharva Tiwari @ 2026-07-21 6:34 UTC (permalink / raw) Cc: Atharva Tiwari, Bjorn Helgaas, Thomas Gleixner, Ingo Molnar, Borislav Petkov, Dave Hansen, x86, H. Peter Anvin, Andreas Noever, Mika Westerberg, Yehezkel Bernat, Hans de Goede, Ilpo Järvinen, Jarkko Sakkinen, Mimi Zohar, Roberto Sassu, Dmitry Kasatkin, Eric Snowberg, Paul Moore, James Morris, Serge E. Hallyn, linux-pci, linux-kernel, linux-usb, platform-driver-x86, linux-integrity, keyrings, linux-security-module Add a flag to detect Apple T2 chips on Intel Macs. Cache the result to avoid repeated checks. That will be used in upcoming patches. Signed-off-by: Atharva Tiwari <atharvatiwarilinuxdev@gmail.com> --- arch/x86/kernel/quirks.c | 105 ++++++++++++++++++ include/linux/platform_data/x86/apple.h | 5 + .../platform_certs/keyring_handler.h | 8 -- security/integrity/platform_certs/load_uefi.c | 38 ++----- 4 files changed, 118 insertions(+), 38 deletions(-) diff --git a/arch/x86/kernel/quirks.c b/arch/x86/kernel/quirks.c index a92f18db9610..300d6436060d 100644 --- a/arch/x86/kernel/quirks.c +++ b/arch/x86/kernel/quirks.c @@ -664,8 +664,113 @@ DECLARE_PCI_FIXUP_EARLY(PCI_VENDOR_ID_INTEL, 0x2083, quirk_intel_purley_xeon_ras bool x86_apple_machine; EXPORT_SYMBOL(x86_apple_machine); +bool has_apple_t2_chip; +EXPORT_SYMBOL(has_apple_t2_chip); + +static const struct dmi_system_id apple_t2_devices[] __initconst = { + { + .matches = { + DMI_MATCH(DMI_SYS_VENDOR, "Apple Inc."), + DMI_MATCH(DMI_PRODUCT_NAME, "MacBookPro15,1"), + }, + }, + { + .matches = { + DMI_MATCH(DMI_SYS_VENDOR, "Apple Inc."), + DMI_MATCH(DMI_PRODUCT_NAME, "MacBookPro15,2"), + }, + }, + { + .matches = { + DMI_MATCH(DMI_SYS_VENDOR, "Apple Inc."), + DMI_MATCH(DMI_PRODUCT_NAME, "MacBookPro15,3"), + }, + }, + { + .matches = { + DMI_MATCH(DMI_SYS_VENDOR, "Apple Inc."), + DMI_MATCH(DMI_PRODUCT_NAME, "MacBookPro15,4"), + }, + }, + { + .matches = { + DMI_MATCH(DMI_SYS_VENDOR, "Apple Inc."), + DMI_MATCH(DMI_PRODUCT_NAME, "MacBookPro16,1"), + }, + }, + { + .matches = { + DMI_MATCH(DMI_SYS_VENDOR, "Apple Inc."), + DMI_MATCH(DMI_PRODUCT_NAME, "MacBookPro16,2"), + }, + }, + { + .matches = { + DMI_MATCH(DMI_SYS_VENDOR, "Apple Inc."), + DMI_MATCH(DMI_PRODUCT_NAME, "MacBookPro16,3"), + }, + }, + { + .matches = { + DMI_MATCH(DMI_SYS_VENDOR, "Apple Inc."), + DMI_MATCH(DMI_PRODUCT_NAME, "MacBookPro16,4"), + }, + }, + { + .matches = { + DMI_MATCH(DMI_SYS_VENDOR, "Apple Inc."), + DMI_MATCH(DMI_PRODUCT_NAME, "MacBookAir8,1"), + }, + }, + { + .matches = { + DMI_MATCH(DMI_SYS_VENDOR, "Apple Inc."), + DMI_MATCH(DMI_PRODUCT_NAME, "MacBookAir8,2"), + }, + }, + { + .matches = { + DMI_MATCH(DMI_SYS_VENDOR, "Apple Inc."), + DMI_MATCH(DMI_PRODUCT_NAME, "MacBookAir9,1"), + }, + }, + { + .matches = { + DMI_MATCH(DMI_SYS_VENDOR, "Apple Inc."), + DMI_MATCH(DMI_PRODUCT_NAME, "Macmini8,1"), + }, + }, + { + .matches = { + DMI_MATCH(DMI_SYS_VENDOR, "Apple Inc."), + DMI_MATCH(DMI_PRODUCT_NAME, "MacPro7,1"), + }, + }, + { + .matches = { + DMI_MATCH(DMI_SYS_VENDOR, "Apple Inc."), + DMI_MATCH(DMI_PRODUCT_NAME, "iMac20,1"), + }, + }, + { + .matches = { + DMI_MATCH(DMI_SYS_VENDOR, "Apple Inc."), + DMI_MATCH(DMI_PRODUCT_NAME, "iMac20,2"), + }, + }, + { + .matches = { + DMI_MATCH(DMI_SYS_VENDOR, "Apple Inc."), + DMI_MATCH(DMI_PRODUCT_NAME, "iMacPro1,1"), + }, + }, + { } +}; + void __init early_platform_quirks(void) { x86_apple_machine = dmi_match(DMI_SYS_VENDOR, "Apple Inc.") || dmi_match(DMI_SYS_VENDOR, "Apple Computer, Inc."); + + has_apple_t2_chip = dmi_check_system(apple_t2_devices); } diff --git a/include/linux/platform_data/x86/apple.h b/include/linux/platform_data/x86/apple.h index 079e816c3c21..47b27dceab18 100644 --- a/include/linux/platform_data/x86/apple.h +++ b/include/linux/platform_data/x86/apple.h @@ -6,8 +6,13 @@ * x86_apple_machine - whether the machine is an x86 Apple Macintosh */ extern bool x86_apple_machine; +/** + * has_apple_t2_chip - whether the machine has the Apple T2 chip + */ +extern bool has_apple_t2_chip; #else #define x86_apple_machine false +#define has_apple_t2_chip false #endif #endif diff --git a/security/integrity/platform_certs/keyring_handler.h b/security/integrity/platform_certs/keyring_handler.h index f92895cc50f6..a355f4400179 100644 --- a/security/integrity/platform_certs/keyring_handler.h +++ b/security/integrity/platform_certs/keyring_handler.h @@ -45,11 +45,3 @@ efi_element_handler_t get_handler_for_code_signing_keys(const efi_guid_t *sig_ty efi_element_handler_t get_handler_for_dbx(const efi_guid_t *sig_type); #endif - -#ifndef UEFI_QUIRK_SKIP_CERT -#define UEFI_QUIRK_SKIP_CERT(vendor, product) \ - .matches = { \ - DMI_MATCH(DMI_BOARD_VENDOR, vendor), \ - DMI_MATCH(DMI_PRODUCT_NAME, product), \ - }, -#endif diff --git a/security/integrity/platform_certs/load_uefi.c b/security/integrity/platform_certs/load_uefi.c index c0d6948446c3..b4096d4c828d 100644 --- a/security/integrity/platform_certs/load_uefi.c +++ b/security/integrity/platform_certs/load_uefi.c @@ -3,42 +3,16 @@ #include <linux/kernel.h> #include <linux/sched.h> #include <linux/cred.h> -#include <linux/dmi.h> #include <linux/err.h> #include <linux/efi.h> #include <linux/slab.h> #include <linux/ima.h> +#include <linux/platform_data/x86/apple.h> #include <keys/asymmetric-type.h> #include <keys/system_keyring.h> #include "../integrity.h" #include "keyring_handler.h" -/* - * On T2 Macs reading the db and dbx efi variables to load UEFI Secure Boot - * certificates causes occurrence of a page fault in Apple's firmware and - * a crash disabling EFI runtime services. The following quirk skips reading - * these variables. - */ -static const struct dmi_system_id uefi_skip_cert[] = { - { UEFI_QUIRK_SKIP_CERT("Apple Inc.", "MacBookPro15,1") }, - { UEFI_QUIRK_SKIP_CERT("Apple Inc.", "MacBookPro15,2") }, - { UEFI_QUIRK_SKIP_CERT("Apple Inc.", "MacBookPro15,3") }, - { UEFI_QUIRK_SKIP_CERT("Apple Inc.", "MacBookPro15,4") }, - { UEFI_QUIRK_SKIP_CERT("Apple Inc.", "MacBookPro16,1") }, - { UEFI_QUIRK_SKIP_CERT("Apple Inc.", "MacBookPro16,2") }, - { UEFI_QUIRK_SKIP_CERT("Apple Inc.", "MacBookPro16,3") }, - { UEFI_QUIRK_SKIP_CERT("Apple Inc.", "MacBookPro16,4") }, - { UEFI_QUIRK_SKIP_CERT("Apple Inc.", "MacBookAir8,1") }, - { UEFI_QUIRK_SKIP_CERT("Apple Inc.", "MacBookAir8,2") }, - { UEFI_QUIRK_SKIP_CERT("Apple Inc.", "MacBookAir9,1") }, - { UEFI_QUIRK_SKIP_CERT("Apple Inc.", "Macmini8,1") }, - { UEFI_QUIRK_SKIP_CERT("Apple Inc.", "MacPro7,1") }, - { UEFI_QUIRK_SKIP_CERT("Apple Inc.", "iMac20,1") }, - { UEFI_QUIRK_SKIP_CERT("Apple Inc.", "iMac20,2") }, - { UEFI_QUIRK_SKIP_CERT("Apple Inc.", "iMacPro1,1") }, - { } -}; - /* * Look to see if a UEFI variable called MokIgnoreDB exists and return true if * it does. @@ -165,10 +139,14 @@ static int __init load_uefi_certs(void) unsigned long dbsize = 0, dbxsize = 0, mokxsize = 0; efi_status_t status; int rc = 0; - const struct dmi_system_id *dmi_id; - dmi_id = dmi_first_match(uefi_skip_cert); - if (dmi_id) { + /* + * On T2 Macs reading the db and dbx efi variables to load UEFI Secure Boot + * certificates causes occurrence of a page fault in Apple's firmware and + * a crash disabling EFI runtime services. The following quirk skips reading + * these variables. + */ + if (has_apple_t2_chip) { pr_err("Reading UEFI Secure Boot Certs is not supported on T2 Macs.\n"); return false; } -- 2.43.0 ^ permalink raw reply related [flat|nested] 6+ messages in thread
* Re: [PATCH v3 1/2] treewide: Add a flag to detect the Apple T2 chip 2026-07-21 6:34 ` [PATCH v3 1/2] treewide: Add a flag to detect the Apple T2 chip Atharva Tiwari @ 2026-07-21 10:57 ` Jarkko Sakkinen 2026-07-21 15:29 ` Hans de Goede 1 sibling, 0 replies; 6+ messages in thread From: Jarkko Sakkinen @ 2026-07-21 10:57 UTC (permalink / raw) To: Atharva Tiwari Cc: Bjorn Helgaas, Thomas Gleixner, Ingo Molnar, Borislav Petkov, Dave Hansen, x86, H. Peter Anvin, Andreas Noever, Mika Westerberg, Yehezkel Bernat, Hans de Goede, Ilpo Järvinen, Mimi Zohar, Roberto Sassu, Dmitry Kasatkin, Eric Snowberg, Paul Moore, James Morris, Serge E. Hallyn, linux-pci, linux-kernel, linux-usb, platform-driver-x86, linux-integrity, keyrings, linux-security-module On Tue, Jul 21, 2026 at 02:34:06AM -0400, Atharva Tiwari wrote: > Add a flag to detect Apple T2 chips on Intel Macs. > Cache the result to avoid repeated checks. That will > be used in upcoming patches. > > Signed-off-by: Atharva Tiwari <atharvatiwarilinuxdev@gmail.com> > --- > arch/x86/kernel/quirks.c | 105 ++++++++++++++++++ > include/linux/platform_data/x86/apple.h | 5 + > .../platform_certs/keyring_handler.h | 8 -- > security/integrity/platform_certs/load_uefi.c | 38 ++----- > 4 files changed, 118 insertions(+), 38 deletions(-) > > diff --git a/arch/x86/kernel/quirks.c b/arch/x86/kernel/quirks.c > index a92f18db9610..300d6436060d 100644 > --- a/arch/x86/kernel/quirks.c > +++ b/arch/x86/kernel/quirks.c > @@ -664,8 +664,113 @@ DECLARE_PCI_FIXUP_EARLY(PCI_VENDOR_ID_INTEL, 0x2083, quirk_intel_purley_xeon_ras > bool x86_apple_machine; > EXPORT_SYMBOL(x86_apple_machine); > > +bool has_apple_t2_chip; > +EXPORT_SYMBOL(has_apple_t2_chip); > + > +static const struct dmi_system_id apple_t2_devices[] __initconst = { > + { > + .matches = { > + DMI_MATCH(DMI_SYS_VENDOR, "Apple Inc."), > + DMI_MATCH(DMI_PRODUCT_NAME, "MacBookPro15,1"), > + }, > + }, > + { > + .matches = { > + DMI_MATCH(DMI_SYS_VENDOR, "Apple Inc."), > + DMI_MATCH(DMI_PRODUCT_NAME, "MacBookPro15,2"), > + }, > + }, > + { > + .matches = { > + DMI_MATCH(DMI_SYS_VENDOR, "Apple Inc."), > + DMI_MATCH(DMI_PRODUCT_NAME, "MacBookPro15,3"), > + }, > + }, > + { > + .matches = { > + DMI_MATCH(DMI_SYS_VENDOR, "Apple Inc."), > + DMI_MATCH(DMI_PRODUCT_NAME, "MacBookPro15,4"), > + }, > + }, > + { > + .matches = { > + DMI_MATCH(DMI_SYS_VENDOR, "Apple Inc."), > + DMI_MATCH(DMI_PRODUCT_NAME, "MacBookPro16,1"), > + }, > + }, > + { > + .matches = { > + DMI_MATCH(DMI_SYS_VENDOR, "Apple Inc."), > + DMI_MATCH(DMI_PRODUCT_NAME, "MacBookPro16,2"), > + }, > + }, > + { > + .matches = { > + DMI_MATCH(DMI_SYS_VENDOR, "Apple Inc."), > + DMI_MATCH(DMI_PRODUCT_NAME, "MacBookPro16,3"), > + }, > + }, > + { > + .matches = { > + DMI_MATCH(DMI_SYS_VENDOR, "Apple Inc."), > + DMI_MATCH(DMI_PRODUCT_NAME, "MacBookPro16,4"), > + }, > + }, > + { > + .matches = { > + DMI_MATCH(DMI_SYS_VENDOR, "Apple Inc."), > + DMI_MATCH(DMI_PRODUCT_NAME, "MacBookAir8,1"), > + }, > + }, > + { > + .matches = { > + DMI_MATCH(DMI_SYS_VENDOR, "Apple Inc."), > + DMI_MATCH(DMI_PRODUCT_NAME, "MacBookAir8,2"), > + }, > + }, > + { > + .matches = { > + DMI_MATCH(DMI_SYS_VENDOR, "Apple Inc."), > + DMI_MATCH(DMI_PRODUCT_NAME, "MacBookAir9,1"), > + }, > + }, > + { > + .matches = { > + DMI_MATCH(DMI_SYS_VENDOR, "Apple Inc."), > + DMI_MATCH(DMI_PRODUCT_NAME, "Macmini8,1"), > + }, > + }, > + { > + .matches = { > + DMI_MATCH(DMI_SYS_VENDOR, "Apple Inc."), > + DMI_MATCH(DMI_PRODUCT_NAME, "MacPro7,1"), > + }, > + }, > + { > + .matches = { > + DMI_MATCH(DMI_SYS_VENDOR, "Apple Inc."), > + DMI_MATCH(DMI_PRODUCT_NAME, "iMac20,1"), > + }, > + }, > + { > + .matches = { > + DMI_MATCH(DMI_SYS_VENDOR, "Apple Inc."), > + DMI_MATCH(DMI_PRODUCT_NAME, "iMac20,2"), > + }, > + }, > + { > + .matches = { > + DMI_MATCH(DMI_SYS_VENDOR, "Apple Inc."), > + DMI_MATCH(DMI_PRODUCT_NAME, "iMacPro1,1"), > + }, > + }, > + { } > +}; > + > void __init early_platform_quirks(void) > { > x86_apple_machine = dmi_match(DMI_SYS_VENDOR, "Apple Inc.") || > dmi_match(DMI_SYS_VENDOR, "Apple Computer, Inc."); > + > + has_apple_t2_chip = dmi_check_system(apple_t2_devices); > } > diff --git a/include/linux/platform_data/x86/apple.h b/include/linux/platform_data/x86/apple.h > index 079e816c3c21..47b27dceab18 100644 > --- a/include/linux/platform_data/x86/apple.h > +++ b/include/linux/platform_data/x86/apple.h > @@ -6,8 +6,13 @@ > * x86_apple_machine - whether the machine is an x86 Apple Macintosh > */ > extern bool x86_apple_machine; > +/** > + * has_apple_t2_chip - whether the machine has the Apple T2 chip > + */ > +extern bool has_apple_t2_chip; > #else > #define x86_apple_machine false > +#define has_apple_t2_chip false > #endif > > #endif > diff --git a/security/integrity/platform_certs/keyring_handler.h b/security/integrity/platform_certs/keyring_handler.h > index f92895cc50f6..a355f4400179 100644 > --- a/security/integrity/platform_certs/keyring_handler.h > +++ b/security/integrity/platform_certs/keyring_handler.h > @@ -45,11 +45,3 @@ efi_element_handler_t get_handler_for_code_signing_keys(const efi_guid_t *sig_ty > efi_element_handler_t get_handler_for_dbx(const efi_guid_t *sig_type); > > #endif > - > -#ifndef UEFI_QUIRK_SKIP_CERT > -#define UEFI_QUIRK_SKIP_CERT(vendor, product) \ > - .matches = { \ > - DMI_MATCH(DMI_BOARD_VENDOR, vendor), \ > - DMI_MATCH(DMI_PRODUCT_NAME, product), \ > - }, > -#endif > diff --git a/security/integrity/platform_certs/load_uefi.c b/security/integrity/platform_certs/load_uefi.c > index c0d6948446c3..b4096d4c828d 100644 > --- a/security/integrity/platform_certs/load_uefi.c > +++ b/security/integrity/platform_certs/load_uefi.c > @@ -3,42 +3,16 @@ > #include <linux/kernel.h> > #include <linux/sched.h> > #include <linux/cred.h> > -#include <linux/dmi.h> > #include <linux/err.h> > #include <linux/efi.h> > #include <linux/slab.h> > #include <linux/ima.h> > +#include <linux/platform_data/x86/apple.h> > #include <keys/asymmetric-type.h> > #include <keys/system_keyring.h> > #include "../integrity.h" > #include "keyring_handler.h" > > -/* > - * On T2 Macs reading the db and dbx efi variables to load UEFI Secure Boot > - * certificates causes occurrence of a page fault in Apple's firmware and > - * a crash disabling EFI runtime services. The following quirk skips reading > - * these variables. > - */ > -static const struct dmi_system_id uefi_skip_cert[] = { > - { UEFI_QUIRK_SKIP_CERT("Apple Inc.", "MacBookPro15,1") }, > - { UEFI_QUIRK_SKIP_CERT("Apple Inc.", "MacBookPro15,2") }, > - { UEFI_QUIRK_SKIP_CERT("Apple Inc.", "MacBookPro15,3") }, > - { UEFI_QUIRK_SKIP_CERT("Apple Inc.", "MacBookPro15,4") }, > - { UEFI_QUIRK_SKIP_CERT("Apple Inc.", "MacBookPro16,1") }, > - { UEFI_QUIRK_SKIP_CERT("Apple Inc.", "MacBookPro16,2") }, > - { UEFI_QUIRK_SKIP_CERT("Apple Inc.", "MacBookPro16,3") }, > - { UEFI_QUIRK_SKIP_CERT("Apple Inc.", "MacBookPro16,4") }, > - { UEFI_QUIRK_SKIP_CERT("Apple Inc.", "MacBookAir8,1") }, > - { UEFI_QUIRK_SKIP_CERT("Apple Inc.", "MacBookAir8,2") }, > - { UEFI_QUIRK_SKIP_CERT("Apple Inc.", "MacBookAir9,1") }, > - { UEFI_QUIRK_SKIP_CERT("Apple Inc.", "Macmini8,1") }, > - { UEFI_QUIRK_SKIP_CERT("Apple Inc.", "MacPro7,1") }, > - { UEFI_QUIRK_SKIP_CERT("Apple Inc.", "iMac20,1") }, > - { UEFI_QUIRK_SKIP_CERT("Apple Inc.", "iMac20,2") }, > - { UEFI_QUIRK_SKIP_CERT("Apple Inc.", "iMacPro1,1") }, > - { } > -}; > - > /* > * Look to see if a UEFI variable called MokIgnoreDB exists and return true if > * it does. > @@ -165,10 +139,14 @@ static int __init load_uefi_certs(void) > unsigned long dbsize = 0, dbxsize = 0, mokxsize = 0; > efi_status_t status; > int rc = 0; > - const struct dmi_system_id *dmi_id; > > - dmi_id = dmi_first_match(uefi_skip_cert); > - if (dmi_id) { > + /* > + * On T2 Macs reading the db and dbx efi variables to load UEFI Secure Boot > + * certificates causes occurrence of a page fault in Apple's firmware and > + * a crash disabling EFI runtime services. The following quirk skips reading > + * these variables. > + */ > + if (has_apple_t2_chip) { > pr_err("Reading UEFI Secure Boot Certs is not supported on T2 Macs.\n"); > return false; > } > -- > 2.43.0 > Acked-by: Jarkko Sakkinen <jarkko@kernel.org> BR, Jarkko ^ permalink raw reply [flat|nested] 6+ messages in thread
* Re: [PATCH v3 1/2] treewide: Add a flag to detect the Apple T2 chip 2026-07-21 6:34 ` [PATCH v3 1/2] treewide: Add a flag to detect the Apple T2 chip Atharva Tiwari 2026-07-21 10:57 ` Jarkko Sakkinen @ 2026-07-21 15:29 ` Hans de Goede 1 sibling, 0 replies; 6+ messages in thread From: Hans de Goede @ 2026-07-21 15:29 UTC (permalink / raw) To: Atharva Tiwari Cc: Bjorn Helgaas, Thomas Gleixner, Ingo Molnar, Borislav Petkov, Dave Hansen, x86, H. Peter Anvin, Andreas Noever, Mika Westerberg, Yehezkel Bernat, Ilpo Järvinen, Jarkko Sakkinen, Mimi Zohar, Roberto Sassu, Dmitry Kasatkin, Eric Snowberg, Paul Moore, James Morris, Serge E. Hallyn, linux-pci, linux-kernel, linux-usb, platform-driver-x86, linux-integrity, keyrings, linux-security-module Hi, On 21-Jul-26 08:34, Atharva Tiwari wrote: > Add a flag to detect Apple T2 chips on Intel Macs. > Cache the result to avoid repeated checks. That will > be used in upcoming patches. > > Signed-off-by: Atharva Tiwari <atharvatiwarilinuxdev@gmail.com> > --- > arch/x86/kernel/quirks.c | 105 ++++++++++++++++++ > include/linux/platform_data/x86/apple.h | 5 + > .../platform_certs/keyring_handler.h | 8 -- > security/integrity/platform_certs/load_uefi.c | 38 ++----- > 4 files changed, 118 insertions(+), 38 deletions(-) > > diff --git a/arch/x86/kernel/quirks.c b/arch/x86/kernel/quirks.c > index a92f18db9610..300d6436060d 100644 > --- a/arch/x86/kernel/quirks.c > +++ b/arch/x86/kernel/quirks.c > @@ -664,8 +664,113 @@ DECLARE_PCI_FIXUP_EARLY(PCI_VENDOR_ID_INTEL, 0x2083, quirk_intel_purley_xeon_ras > bool x86_apple_machine; > EXPORT_SYMBOL(x86_apple_machine); > > +bool has_apple_t2_chip; > +EXPORT_SYMBOL(has_apple_t2_chip); > + > +static const struct dmi_system_id apple_t2_devices[] __initconst = { > + { > + .matches = { > + DMI_MATCH(DMI_SYS_VENDOR, "Apple Inc."), > + DMI_MATCH(DMI_PRODUCT_NAME, "MacBookPro15,1"), > + }, > + }, > + { > + .matches = { > + DMI_MATCH(DMI_SYS_VENDOR, "Apple Inc."), > + DMI_MATCH(DMI_PRODUCT_NAME, "MacBookPro15,2"), > + }, > + }, > + { > + .matches = { > + DMI_MATCH(DMI_SYS_VENDOR, "Apple Inc."), > + DMI_MATCH(DMI_PRODUCT_NAME, "MacBookPro15,3"), > + }, > + }, > + { > + .matches = { > + DMI_MATCH(DMI_SYS_VENDOR, "Apple Inc."), > + DMI_MATCH(DMI_PRODUCT_NAME, "MacBookPro15,4"), > + }, > + }, > + { > + .matches = { > + DMI_MATCH(DMI_SYS_VENDOR, "Apple Inc."), > + DMI_MATCH(DMI_PRODUCT_NAME, "MacBookPro16,1"), > + }, > + }, > + { > + .matches = { > + DMI_MATCH(DMI_SYS_VENDOR, "Apple Inc."), > + DMI_MATCH(DMI_PRODUCT_NAME, "MacBookPro16,2"), > + }, > + }, > + { > + .matches = { > + DMI_MATCH(DMI_SYS_VENDOR, "Apple Inc."), > + DMI_MATCH(DMI_PRODUCT_NAME, "MacBookPro16,3"), > + }, > + }, > + { > + .matches = { > + DMI_MATCH(DMI_SYS_VENDOR, "Apple Inc."), > + DMI_MATCH(DMI_PRODUCT_NAME, "MacBookPro16,4"), > + }, > + }, > + { > + .matches = { > + DMI_MATCH(DMI_SYS_VENDOR, "Apple Inc."), > + DMI_MATCH(DMI_PRODUCT_NAME, "MacBookAir8,1"), > + }, > + }, > + { > + .matches = { > + DMI_MATCH(DMI_SYS_VENDOR, "Apple Inc."), > + DMI_MATCH(DMI_PRODUCT_NAME, "MacBookAir8,2"), > + }, > + }, > + { > + .matches = { > + DMI_MATCH(DMI_SYS_VENDOR, "Apple Inc."), > + DMI_MATCH(DMI_PRODUCT_NAME, "MacBookAir9,1"), > + }, > + }, > + { > + .matches = { > + DMI_MATCH(DMI_SYS_VENDOR, "Apple Inc."), > + DMI_MATCH(DMI_PRODUCT_NAME, "Macmini8,1"), > + }, > + }, > + { > + .matches = { > + DMI_MATCH(DMI_SYS_VENDOR, "Apple Inc."), > + DMI_MATCH(DMI_PRODUCT_NAME, "MacPro7,1"), > + }, > + }, > + { > + .matches = { > + DMI_MATCH(DMI_SYS_VENDOR, "Apple Inc."), > + DMI_MATCH(DMI_PRODUCT_NAME, "iMac20,1"), > + }, > + }, > + { > + .matches = { > + DMI_MATCH(DMI_SYS_VENDOR, "Apple Inc."), > + DMI_MATCH(DMI_PRODUCT_NAME, "iMac20,2"), > + }, > + }, > + { > + .matches = { > + DMI_MATCH(DMI_SYS_VENDOR, "Apple Inc."), > + DMI_MATCH(DMI_PRODUCT_NAME, "iMacPro1,1"), > + }, > + }, > + { } > +}; > + This takes quite a bit of storage, struct dmi_system_id is not very efficient. How about making this a NULL terminated array of strings: const char *apple_t2_devices[] __initconst = { "MacBookPro15,1", ... "iMacPro1,1", NULL }; > void __init early_platform_quirks(void) > { > x86_apple_machine = dmi_match(DMI_SYS_VENDOR, "Apple Inc.") || > dmi_match(DMI_SYS_VENDOR, "Apple Computer, Inc."); > + > + has_apple_t2_chip = dmi_check_system(apple_t2_devices); and then here: for (int i = 0; x86_apple_machine && apple_t2_devices[i]; i++) if (dmi_match(DMI_PRODUCT_NAME, apple_t2_devices[i])) { has_apple_t2_chip = true; break; } This should save some space and IMHO just having a compact list of product-names is more readable too. Regards, Hans > } > diff --git a/include/linux/platform_data/x86/apple.h b/include/linux/platform_data/x86/apple.h > index 079e816c3c21..47b27dceab18 100644 > --- a/include/linux/platform_data/x86/apple.h > +++ b/include/linux/platform_data/x86/apple.h > @@ -6,8 +6,13 @@ > * x86_apple_machine - whether the machine is an x86 Apple Macintosh > */ > extern bool x86_apple_machine; > +/** > + * has_apple_t2_chip - whether the machine has the Apple T2 chip > + */ > +extern bool has_apple_t2_chip; > #else > #define x86_apple_machine false > +#define has_apple_t2_chip false > #endif > > #endif > diff --git a/security/integrity/platform_certs/keyring_handler.h b/security/integrity/platform_certs/keyring_handler.h > index f92895cc50f6..a355f4400179 100644 > --- a/security/integrity/platform_certs/keyring_handler.h > +++ b/security/integrity/platform_certs/keyring_handler.h > @@ -45,11 +45,3 @@ efi_element_handler_t get_handler_for_code_signing_keys(const efi_guid_t *sig_ty > efi_element_handler_t get_handler_for_dbx(const efi_guid_t *sig_type); > > #endif > - > -#ifndef UEFI_QUIRK_SKIP_CERT > -#define UEFI_QUIRK_SKIP_CERT(vendor, product) \ > - .matches = { \ > - DMI_MATCH(DMI_BOARD_VENDOR, vendor), \ > - DMI_MATCH(DMI_PRODUCT_NAME, product), \ > - }, > -#endif > diff --git a/security/integrity/platform_certs/load_uefi.c b/security/integrity/platform_certs/load_uefi.c > index c0d6948446c3..b4096d4c828d 100644 > --- a/security/integrity/platform_certs/load_uefi.c > +++ b/security/integrity/platform_certs/load_uefi.c > @@ -3,42 +3,16 @@ > #include <linux/kernel.h> > #include <linux/sched.h> > #include <linux/cred.h> > -#include <linux/dmi.h> > #include <linux/err.h> > #include <linux/efi.h> > #include <linux/slab.h> > #include <linux/ima.h> > +#include <linux/platform_data/x86/apple.h> > #include <keys/asymmetric-type.h> > #include <keys/system_keyring.h> > #include "../integrity.h" > #include "keyring_handler.h" > > -/* > - * On T2 Macs reading the db and dbx efi variables to load UEFI Secure Boot > - * certificates causes occurrence of a page fault in Apple's firmware and > - * a crash disabling EFI runtime services. The following quirk skips reading > - * these variables. > - */ > -static const struct dmi_system_id uefi_skip_cert[] = { > - { UEFI_QUIRK_SKIP_CERT("Apple Inc.", "MacBookPro15,1") }, > - { UEFI_QUIRK_SKIP_CERT("Apple Inc.", "MacBookPro15,2") }, > - { UEFI_QUIRK_SKIP_CERT("Apple Inc.", "MacBookPro15,3") }, > - { UEFI_QUIRK_SKIP_CERT("Apple Inc.", "MacBookPro15,4") }, > - { UEFI_QUIRK_SKIP_CERT("Apple Inc.", "MacBookPro16,1") }, > - { UEFI_QUIRK_SKIP_CERT("Apple Inc.", "MacBookPro16,2") }, > - { UEFI_QUIRK_SKIP_CERT("Apple Inc.", "MacBookPro16,3") }, > - { UEFI_QUIRK_SKIP_CERT("Apple Inc.", "MacBookPro16,4") }, > - { UEFI_QUIRK_SKIP_CERT("Apple Inc.", "MacBookAir8,1") }, > - { UEFI_QUIRK_SKIP_CERT("Apple Inc.", "MacBookAir8,2") }, > - { UEFI_QUIRK_SKIP_CERT("Apple Inc.", "MacBookAir9,1") }, > - { UEFI_QUIRK_SKIP_CERT("Apple Inc.", "Macmini8,1") }, > - { UEFI_QUIRK_SKIP_CERT("Apple Inc.", "MacPro7,1") }, > - { UEFI_QUIRK_SKIP_CERT("Apple Inc.", "iMac20,1") }, > - { UEFI_QUIRK_SKIP_CERT("Apple Inc.", "iMac20,2") }, > - { UEFI_QUIRK_SKIP_CERT("Apple Inc.", "iMacPro1,1") }, > - { } > -}; > - > /* > * Look to see if a UEFI variable called MokIgnoreDB exists and return true if > * it does. > @@ -165,10 +139,14 @@ static int __init load_uefi_certs(void) > unsigned long dbsize = 0, dbxsize = 0, mokxsize = 0; > efi_status_t status; > int rc = 0; > - const struct dmi_system_id *dmi_id; > > - dmi_id = dmi_first_match(uefi_skip_cert); > - if (dmi_id) { > + /* > + * On T2 Macs reading the db and dbx efi variables to load UEFI Secure Boot > + * certificates causes occurrence of a page fault in Apple's firmware and > + * a crash disabling EFI runtime services. The following quirk skips reading > + * these variables. > + */ > + if (has_apple_t2_chip) { > pr_err("Reading UEFI Secure Boot Certs is not supported on T2 Macs.\n"); > return false; > } ^ permalink raw reply [flat|nested] 6+ messages in thread
* [PATCH v3 2/2] thunderbolt: Add device links for Apple T2 NHI 2026-07-21 6:34 [PATCH v3 0/2] Add Apple T2 NHI device links Atharva Tiwari 2026-07-21 6:34 ` [PATCH v3 1/2] treewide: Add a flag to detect the Apple T2 chip Atharva Tiwari @ 2026-07-21 6:34 ` Atharva Tiwari 2026-07-21 9:03 ` Ilpo Järvinen 1 sibling, 1 reply; 6+ messages in thread From: Atharva Tiwari @ 2026-07-21 6:34 UTC (permalink / raw) Cc: Atharva Tiwari, Andre Eikmeyer, Bjorn Helgaas, Thomas Gleixner, Ingo Molnar, Borislav Petkov, Dave Hansen, x86, H. Peter Anvin, Andreas Noever, Mika Westerberg, Yehezkel Bernat, Hans de Goede, Ilpo Järvinen, Jarkko Sakkinen, Mimi Zohar, Roberto Sassu, Dmitry Kasatkin, Eric Snowberg, Paul Moore, James Morris, Serge E. Hallyn, linux-pci, linux-kernel, linux-usb, platform-driver-x86, linux-integrity, keyrings, linux-security-module From: Andre Eikmeyer <andre@negmaster.com> Thunderbolt NHI on T2 Macs (2018-2020). The NHI and its associated PCIe root ports all sit directly on the root complex with no upstream port. Apple's ACPI tables name Thunderbolt root ports as TRP0, TRP1, etc. Find them and create device links back to the NHI so that PCIe tunnels can be re-established after sleep. Co-developed-by: Atharva Tiwari <atharvatiwarilinuxdev@gmail.com> Signed-off-by: Atharva Tiwari <atharvatiwarilinuxdev@gmail.com> Signed-off-by: Andre Eikmeyer <andre@negmaster.com> --- drivers/thunderbolt/tb.c | 51 +++++++++++++++++++++++++++++++++++++++- 1 file changed, 50 insertions(+), 1 deletion(-) diff --git a/drivers/thunderbolt/tb.c b/drivers/thunderbolt/tb.c index c69c323e6952..0cdffcf577cd 100644 --- a/drivers/thunderbolt/tb.c +++ b/drivers/thunderbolt/tb.c @@ -6,6 +6,7 @@ * Copyright (C) 2019, Intel Corporation */ +#include <linux/acpi.h> #include <linux/slab.h> #include <linux/errno.h> #include <linux/delay.h> @@ -3305,11 +3306,59 @@ static const struct tb_cm_ops tb_cm_ops = { static bool tb_apple_add_links(struct tb_nhi *nhi) { struct pci_dev *upstream, *pdev; - bool ret; + bool ret = false; if (!x86_apple_machine) return false; + /* On T2 Macs. the root ports are stored in ACPI as TRP0, + * TRP1, etc. Find them and create device links + * so that PCIe tunnels can be re-established after + * sleep. + */ + if (has_apple_t2_chip && IS_ENABLED(CONFIG_ACPI)) { + struct acpi_device *adev; + unsigned int slot, func; + const struct device_link *link; + const char *bid; + + for (slot = 0; slot < 32; slot++) { + for (func = 0; func < 8; func++) { + pdev = pci_get_slot(nhi->pdev->bus, PCI_DEVFN(slot, func)); + if (!pdev) + continue; + + if (!pci_is_pcie(pdev) || pci_pcie_type(pdev) != + PCI_EXP_TYPE_ROOT_PORT) + goto put_pdev; + + adev = ACPI_COMPANION(&pdev->dev); + if (!adev) + goto put_pdev; + + bid = acpi_device_bid(adev); + if (strncmp(bid, "TRP", 3) != 0) + goto put_pdev; + + link = device_link_add(&pdev->dev, &nhi->pdev->dev, + DL_FLAG_AUTOREMOVE_SUPPLIER | + DL_FLAG_PM_RUNTIME); + if (link) { + dev_dbg(&nhi->pdev->dev, "created link from %s\n", + dev_name(&pdev->dev)); + ret = true; + } else + dev_warn(&nhi->pdev->dev, + "device link creation from %s failed\n", + dev_name(&pdev->dev)); + +put_pdev: + pci_dev_put(pdev); + } + } + return ret; + } + switch (nhi->pdev->device) { case PCI_DEVICE_ID_INTEL_LIGHT_RIDGE: case PCI_DEVICE_ID_INTEL_CACTUS_RIDGE_4C: -- 2.43.0 ^ permalink raw reply related [flat|nested] 6+ messages in thread
* Re: [PATCH v3 2/2] thunderbolt: Add device links for Apple T2 NHI 2026-07-21 6:34 ` [PATCH v3 2/2] thunderbolt: Add device links for Apple T2 NHI Atharva Tiwari @ 2026-07-21 9:03 ` Ilpo Järvinen 0 siblings, 0 replies; 6+ messages in thread From: Ilpo Järvinen @ 2026-07-21 9:03 UTC (permalink / raw) To: Atharva Tiwari Cc: Andre Eikmeyer, Bjorn Helgaas, Thomas Gleixner, Ingo Molnar, Borislav Petkov, Dave Hansen, x86, H. Peter Anvin, Andreas Noever, Mika Westerberg, Yehezkel Bernat, Hans de Goede, Jarkko Sakkinen, Mimi Zohar, Roberto Sassu, Dmitry Kasatkin, Eric Snowberg, Paul Moore, James Morris, Serge E. Hallyn, linux-pci, LKML, linux-usb, platform-driver-x86, linux-integrity, keyrings, linux-security-module On Tue, 21 Jul 2026, Atharva Tiwari wrote: > From: Andre Eikmeyer <andre@negmaster.com> > > Thunderbolt NHI on T2 Macs (2018-2020). The NHI and its > associated PCIe root ports all sit directly on the root complex > with no upstream port. Apple's ACPI tables name Thunderbolt root > ports as TRP0, TRP1, etc. Find them and create device links back > to the NHI so that PCIe tunnels can be re-established after sleep. > > Co-developed-by: Atharva Tiwari <atharvatiwarilinuxdev@gmail.com> > Signed-off-by: Atharva Tiwari <atharvatiwarilinuxdev@gmail.com> > > Signed-off-by: Andre Eikmeyer <andre@negmaster.com> > --- > drivers/thunderbolt/tb.c | 51 +++++++++++++++++++++++++++++++++++++++- > 1 file changed, 50 insertions(+), 1 deletion(-) > > diff --git a/drivers/thunderbolt/tb.c b/drivers/thunderbolt/tb.c > index c69c323e6952..0cdffcf577cd 100644 > --- a/drivers/thunderbolt/tb.c > +++ b/drivers/thunderbolt/tb.c > @@ -6,6 +6,7 @@ > * Copyright (C) 2019, Intel Corporation > */ > > +#include <linux/acpi.h> > #include <linux/slab.h> > #include <linux/errno.h> > #include <linux/delay.h> > @@ -3305,11 +3306,59 @@ static const struct tb_cm_ops tb_cm_ops = { > static bool tb_apple_add_links(struct tb_nhi *nhi) > { > struct pci_dev *upstream, *pdev; This file seems to have a pre-existing lack of pci.h include, please add it now when doing pci related code. > - bool ret; > + bool ret = false; > > if (!x86_apple_machine) > return false; > > + /* On T2 Macs. the root ports are stored in ACPI as TRP0, > + * TRP1, etc. Find them and create device links > + * so that PCIe tunnels can be re-established after > + * sleep. > + */ > + if (has_apple_t2_chip && IS_ENABLED(CONFIG_ACPI)) { > + struct acpi_device *adev; > + unsigned int slot, func; > + const struct device_link *link; > + const char *bid; > + > + for (slot = 0; slot < 32; slot++) { > + for (func = 0; func < 8; func++) { > + pdev = pci_get_slot(nhi->pdev->bus, PCI_DEVFN(slot, func)); > + if (!pdev) > + continue; > + > + if (!pci_is_pcie(pdev) || pci_pcie_type(pdev) != > + PCI_EXP_TYPE_ROOT_PORT) > + goto put_pdev; > + > + adev = ACPI_COMPANION(&pdev->dev); > + if (!adev) > + goto put_pdev; > + > + bid = acpi_device_bid(adev); > + if (strncmp(bid, "TRP", 3) != 0) > + goto put_pdev; > + > + link = device_link_add(&pdev->dev, &nhi->pdev->dev, > + DL_FLAG_AUTOREMOVE_SUPPLIER | > + DL_FLAG_PM_RUNTIME); > + if (link) { > + dev_dbg(&nhi->pdev->dev, "created link from %s\n", > + dev_name(&pdev->dev)); > + ret = true; > + } else > + dev_warn(&nhi->pdev->dev, > + "device link creation from %s failed\n", > + dev_name(&pdev->dev)); Please only use balanced braces. > + > +put_pdev: > + pci_dev_put(pdev); I think you can use __free() with it and avoid the label. You cannot then reuse the existing pdev variable for it but declare it in this block while you assign to it. This line would be misaligned anyway but better get rid of goto logic anyway. > + } > + } > + return ret; > + } > + > switch (nhi->pdev->device) { > case PCI_DEVICE_ID_INTEL_LIGHT_RIDGE: > case PCI_DEVICE_ID_INTEL_CACTUS_RIDGE_4C: > -- i. ^ permalink raw reply [flat|nested] 6+ messages in thread
end of thread, other threads:[~2026-07-21 15:29 UTC | newest] Thread overview: 6+ messages (download: mbox.gz follow: Atom feed -- links below jump to the message on this page -- 2026-07-21 6:34 [PATCH v3 0/2] Add Apple T2 NHI device links Atharva Tiwari 2026-07-21 6:34 ` [PATCH v3 1/2] treewide: Add a flag to detect the Apple T2 chip Atharva Tiwari 2026-07-21 10:57 ` Jarkko Sakkinen 2026-07-21 15:29 ` Hans de Goede 2026-07-21 6:34 ` [PATCH v3 2/2] thunderbolt: Add device links for Apple T2 NHI Atharva Tiwari 2026-07-21 9:03 ` Ilpo Järvinen
This is a public inbox, see mirroring instructions for how to clone and mirror all data and code used for this inbox