Linux-mediatek Archive on lore.kernel.org
 help / color / mirror / Atom feed
From: Yunfei Dong <yunfei.dong@mediatek.com>
To: "Jeffrey Kardatzke" <jkardatzke@google.com>,
	"Nícolas F . R . A . Prado" <nfraprado@collabora.com>,
	"Nathan Hebert" <nhebert@chromium.org>,
	"Nicolas Dufresne" <nicolas.dufresne@collabora.com>,
	"Hans Verkuil" <hverkuil-cisco@xs4all.nl>,
	"AngeloGioacchino Del Regno"
	<angelogioacchino.delregno@collabora.com>,
	"Benjamin Gaignard" <benjamin.gaignard@collabora.com>,
	"Sebastian Fricke" <sebastian.fricke@collabora.com>,
	"Tomasz Figa" <tfiga@chromium.org>,
	"Mauro Carvalho Chehab" <mchehab@kernel.org>,
	"Marek Szyprowski" <m.szyprowski@samsung.com>
Cc: "Chen-Yu Tsai" <wenst@chromium.org>,
	"Yong Wu" <yong.wu@mediatek.com>,
	"Hsin-Yi Wang" <hsinyi@chromium.org>,
	"Fritz Koenig" <frkoenig@chromium.org>,
	"Daniel Vetter" <daniel@ffwll.ch>,
	"Steve Cho" <stevecho@chromium.org>,
	"Yunfei Dong" <yunfei.dong@mediatek.com>,
	"Sumit Semwal" <sumit.semwal@linaro.org>,
	"Brian Starkey" <Brian.Starkey@arm.com>,
	"John Stultz" <jstultz@google.com>,
	"T . J . Mercier" <tjmercier@google.com>,
	"Christian König" <christian.koenig@amd.com>,
	"Matthias Brugger" <matthias.bgg@gmail.com>,
	linux-media@vger.kernel.org, dri-devel@lists.freedesktop.org,
	linux-kernel@vger.kernel.org,
	linux-arm-kernel@lists.infradead.org,
	linux-mediatek@lists.infradead.org,
	Project_Global_Chrome_Upstream_Group@mediatek.com
Subject: [PATCH v7 00/28] media: mediatek: add driver to support secure video decoder
Date: Sat, 20 Jul 2024 15:15:38 +0800	[thread overview]
Message-ID: <20240720071606.27930-1-yunfei.dong@mediatek.com> (raw)

The patch series used to enable secure video playback (SVP) on MediaTek
hardware in the Linux kernel.

Memory Definitions:
secure memory - Memory allocated in the TEE (Trusted Execution
Environment) which is inaccessible in the REE (Rich Execution
Environment, i.e. linux kernel/user space).
secure handle - Integer value which acts as reference to 'secure
memory'. Used in communication between TEE and REE to reference
'secure memory'.
secure buffer - 'secure memory' that is used to store decrypted,
compressed video or for other general purposes in the TEE.
secure surface - 'secure memory' that is used to store graphic buffers.

Memory Usage in SVP:
The overall flow of SVP starts with encrypted video coming in from an
outside source into the REE. The REE will then allocate a 'secure
buffer' and send the corresponding 'secure handle' along with the
encrypted, compressed video data to the TEE. The TEE will then decrypt
the video and store the result in the 'secure buffer'. The REE will
then allocate a 'secure surface'. The REE will pass the 'secure
handles' for both the 'secure buffer' and 'secure surface' into the
TEE for video decoding. The video decoder HW will then decode the
contents of the 'secure buffer' and place the result in the 'secure
surface'. The REE will then attach the 'secure surface' to the overlay
plane for rendering of the video.

Everything relating to ensuring security of the actual contents of the
'secure buffer' and 'secure surface' is out of scope for the REE and
is the responsibility of the TEE.

This patch series is consists of four parts. The first is from Jeffrey,
adding secure memory flag in v4l2 framework to support request secure
buffer.

The second and third parts are from John and T.J, adding some heap
interfaces, then our kernel users could allocate buffer from special
heap. The patch v1 is inside below dmabuf link.
https://lore.kernel.org/linux-mediatek/20230911023038.30649-1-yong.wu@mediatek.com/
To avoid confusing, move them into vcodec patch set since we use the
new interfaces directly.

The last part is mediatek video decoder driver, adding tee interface and
decoder driver to support secure video playback.

This patch set depends on "dma-buf: heaps: Add restricted heap"[1]

[1] https://patchwork.kernel.org/project/linux-mediatek/list/?series=853380
---
Changed in v7:
- fix many reviewer's comments
- build optee driver to ko
- support h264 svp and non svp vsi

Changed in v6:
- fix unreasonable logic for patch 2/3/23
- add to support vp9 for patch 24

Changed in v5:
- fix merge conflict when rebase to latest media stage for patch 1/2
- change allocate memory type to cma for patch 12
- add to support av1 for patch 23

Changed in v4:
- change the driver according to maintainer advice for patch 1/2/3/4
- replace secure with restricted for patch 1/2/3/4
- fix svp decoder error for patch 21
- add to support hevc for patch 22

Changed in v3:
- rewrite the cover-letter of this patch series
- disable irq for svp mode
- rebase the driver based on the latest media stage

Changed in v2:
- remove setting decoder mode and getting secure handle from decode
- add Jeffrey's patch
- add John and T.J's patch
- getting secure flag with request buffer
- fix some comments from patch v1
---
Jeffrey Kardatzke (2):
  v4l2: add restricted memory flags
  v4l2: handle restricted memory flags in queue setup

John Stultz (2):
  dma-heap: Add proper kref handling on dma-buf heaps
  dma-heap: Provide accessors so that in-kernel drivers can allocate
    dmabufs from specific heaps

T.J. Mercier (1):
  dma-buf: heaps: Deduplicate docs and adopt common format

Xiaoyong Lu (1):
  media: mediatek: vcodec: support av1 svp decoder for mt8188

Yilong Zhou (1):
  media: mediatek: vcodec: support vp9 svp decoder for mt8188

Yunfei Dong (21):
  media: videobuf2: calculate restricted memory size
  media: mediatek: vcodec: add tee client interface to communiate with
    optee-os
  media: mediatek: vcodec: build decoder OPTEE driver as module
  media: mediatek: vcodec: allocate tee share memory
  media: mediatek: vcodec: send share memory data to optee
  media: mediatek: vcodec: initialize msg and vsi information
  media: mediatek: vcodec: add interface to allocate/free secure memory
  media: mediatek: vcodec: using shared memory as vsi address
  media: mediatek: vcodec: add single allocation format
  media: mediatek: vcodec: support single allocation format
  media: mediatek: vcodec: support single allocation buffer
  media: mediatek: vcodec: re-construct h264 driver to support svp mode
  media: mediatek: vcodec: remove parse nal_info in kernel
  media: mediatek: vcodec: disable wait interrupt for svp mode
  media: mediatek: vcodec: support tee decoder
  media: mediatek: vcodec: move vdec init interface to setup callback
  media: mediatek: vcodec: support hevc svp for mt8188
  media: mediatek: vcodec: remove vsi data from common interface
  media: mediatek: vcodec: rename vsi to extend vsi
  media: mediatek: vcodec: adding non extend struct
  media: mediatek: vcodec: support extend h264 driver

 .../userspace-api/media/v4l/buffer.rst        |  10 +-
 .../media/v4l/pixfmt-reserved.rst             |   7 +
 .../media/v4l/vidioc-reqbufs.rst              |   6 +
 drivers/dma-buf/dma-heap.c                    | 139 ++++-
 .../media/common/videobuf2/videobuf2-core.c   |  29 +
 .../common/videobuf2/videobuf2-dma-contig.c   |  34 +-
 .../media/common/videobuf2/videobuf2-v4l2.c   |   4 +-
 .../media/platform/mediatek/vcodec/Kconfig    |  13 +
 .../mediatek/vcodec/common/mtk_vcodec_util.c  | 117 +++-
 .../mediatek/vcodec/common/mtk_vcodec_util.h  |   8 +-
 .../platform/mediatek/vcodec/decoder/Makefile |   4 +
 .../mediatek/vcodec/decoder/mtk_vcodec_dec.c  | 152 +++--
 .../vcodec/decoder/mtk_vcodec_dec_drv.c       |   8 +
 .../vcodec/decoder/mtk_vcodec_dec_drv.h       |  11 +
 .../vcodec/decoder/mtk_vcodec_dec_hw.c        |  34 +-
 .../vcodec/decoder/mtk_vcodec_dec_optee.c     | 391 +++++++++++++
 .../vcodec/decoder/mtk_vcodec_dec_optee.h     | 198 +++++++
 .../vcodec/decoder/mtk_vcodec_dec_pm.c        |   6 +-
 .../vcodec/decoder/mtk_vcodec_dec_stateless.c |  35 +-
 .../vcodec/decoder/vdec/vdec_av1_req_lat_if.c | 104 ++--
 .../decoder/vdec/vdec_h264_req_common.c       |  18 +-
 .../decoder/vdec/vdec_h264_req_multi_if.c     | 536 +++++++++++++++++-
 .../decoder/vdec/vdec_hevc_req_multi_if.c     |  88 +--
 .../vcodec/decoder/vdec/vdec_vp9_req_lat_if.c | 101 ++--
 .../mediatek/vcodec/decoder/vdec_drv_if.c     |   4 +-
 .../mediatek/vcodec/decoder/vdec_msg_queue.c  |   9 +-
 .../mediatek/vcodec/decoder/vdec_vpu_if.c     |  51 +-
 .../mediatek/vcodec/decoder/vdec_vpu_if.h     |   4 +
 drivers/media/v4l2-core/v4l2-common.c         |   2 +
 drivers/media/v4l2-core/v4l2-ioctl.c          |   1 +
 include/linux/dma-heap.h                      |  29 +-
 include/media/videobuf2-core.h                |   8 +-
 include/uapi/linux/videodev2.h                |   3 +
 33 files changed, 1868 insertions(+), 296 deletions(-)
 create mode 100644 drivers/media/platform/mediatek/vcodec/decoder/mtk_vcodec_dec_optee.c
 create mode 100644 drivers/media/platform/mediatek/vcodec/decoder/mtk_vcodec_dec_optee.h

-- 
2.18.0



             reply	other threads:[~2024-07-20  7:36 UTC|newest]

Thread overview: 39+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2024-07-20  7:15 Yunfei Dong [this message]
2024-07-20  7:15 ` [PATCH v7 01/28] v4l2: add restricted memory flags Yunfei Dong
2024-07-20  9:13   ` Hans Verkuil
2024-07-20  7:15 ` [PATCH v7 02/28] v4l2: handle restricted memory flags in queue setup Yunfei Dong
2024-07-20  9:20   ` Hans Verkuil
2024-07-20  9:53   ` Hans Verkuil
2024-07-20  7:15 ` [PATCH v7 03/28] media: videobuf2: calculate restricted memory size Yunfei Dong
2024-07-20  9:29   ` Hans Verkuil
2024-07-20  7:15 ` [PATCH v7 04/28] dma-buf: heaps: Deduplicate docs and adopt common format Yunfei Dong
2024-07-25 11:52   ` Christian König
2024-07-25 18:28     ` T.J. Mercier
2024-07-20  7:15 ` [PATCH v7 05/28] dma-heap: Add proper kref handling on dma-buf heaps Yunfei Dong
2024-07-20 15:13   ` Markus Elfring
2024-07-22 18:06     ` John Stultz
2024-07-22 18:38       ` Markus Elfring
2024-07-20  7:15 ` [PATCH v7 06/28] dma-heap: Provide accessors so that in-kernel drivers can allocate dmabufs from specific heaps Yunfei Dong
2024-07-20  7:15 ` [PATCH v7 07/28] media: mediatek: vcodec: add tee client interface to communiate with optee-os Yunfei Dong
2024-07-20  7:15 ` [PATCH v7 08/28] media: mediatek: vcodec: build decoder OPTEE driver as module Yunfei Dong
2024-07-20  7:15 ` [PATCH v7 09/28] media: mediatek: vcodec: allocate tee share memory Yunfei Dong
2024-07-20  7:15 ` [PATCH v7 10/28] media: mediatek: vcodec: send share memory data to optee Yunfei Dong
2024-07-20  7:15 ` [PATCH v7 11/28] media: mediatek: vcodec: initialize msg and vsi information Yunfei Dong
2024-07-20  7:15 ` [PATCH v7 12/28] media: mediatek: vcodec: add interface to allocate/free secure memory Yunfei Dong
2024-07-20  7:15 ` [PATCH v7 13/28] media: mediatek: vcodec: using shared memory as vsi address Yunfei Dong
2024-07-20  7:15 ` [PATCH v7 14/28] media: mediatek: vcodec: add single allocation format Yunfei Dong
2024-07-20  7:15 ` [PATCH v7 15/28] media: mediatek: vcodec: support " Yunfei Dong
2024-07-20  7:15 ` [PATCH v7 16/28] media: mediatek: vcodec: support single allocation buffer Yunfei Dong
2024-07-20  7:15 ` [PATCH v7 17/28] media: mediatek: vcodec: re-construct h264 driver to support svp mode Yunfei Dong
2024-07-20  7:15 ` [PATCH v7 18/28] media: mediatek: vcodec: remove parse nal_info in kernel Yunfei Dong
2024-07-20  7:15 ` [PATCH v7 19/28] media: mediatek: vcodec: disable wait interrupt for svp mode Yunfei Dong
2024-07-20  7:15 ` [PATCH v7 20/28] media: mediatek: vcodec: support tee decoder Yunfei Dong
2024-07-20  7:15 ` [PATCH v7 21/28] media: mediatek: vcodec: move vdec init interface to setup callback Yunfei Dong
2024-07-20  7:16 ` [PATCH v7 22/28] media: mediatek: vcodec: support hevc svp for mt8188 Yunfei Dong
2024-07-20  7:16 ` [PATCH v7 23/28] media: mediatek: vcodec: support av1 svp decoder " Yunfei Dong
2024-07-20  7:16 ` [PATCH v7 24/28] media: mediatek: vcodec: support vp9 " Yunfei Dong
2024-07-20  7:16 ` [PATCH v7 25/28] media: mediatek: vcodec: remove vsi data from common interface Yunfei Dong
2024-07-20  7:16 ` [PATCH v7 26/28] media: mediatek: vcodec: rename vsi to extend vsi Yunfei Dong
2024-07-20  7:16 ` [PATCH v7 27/28] media: mediatek: vcodec: adding non extend struct Yunfei Dong
2024-07-20  7:16 ` [PATCH v7 28/28] media: mediatek: vcodec: support extend h264 driver Yunfei Dong
2024-11-13 12:20 ` [PATCH v7 00/28] media: mediatek: add driver to support secure video decoder Sebastian Fricke

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20240720071606.27930-1-yunfei.dong@mediatek.com \
    --to=yunfei.dong@mediatek.com \
    --cc=Brian.Starkey@arm.com \
    --cc=Project_Global_Chrome_Upstream_Group@mediatek.com \
    --cc=angelogioacchino.delregno@collabora.com \
    --cc=benjamin.gaignard@collabora.com \
    --cc=christian.koenig@amd.com \
    --cc=daniel@ffwll.ch \
    --cc=dri-devel@lists.freedesktop.org \
    --cc=frkoenig@chromium.org \
    --cc=hsinyi@chromium.org \
    --cc=hverkuil-cisco@xs4all.nl \
    --cc=jkardatzke@google.com \
    --cc=jstultz@google.com \
    --cc=linux-arm-kernel@lists.infradead.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-media@vger.kernel.org \
    --cc=linux-mediatek@lists.infradead.org \
    --cc=m.szyprowski@samsung.com \
    --cc=matthias.bgg@gmail.com \
    --cc=mchehab@kernel.org \
    --cc=nfraprado@collabora.com \
    --cc=nhebert@chromium.org \
    --cc=nicolas.dufresne@collabora.com \
    --cc=sebastian.fricke@collabora.com \
    --cc=stevecho@chromium.org \
    --cc=sumit.semwal@linaro.org \
    --cc=tfiga@chromium.org \
    --cc=tjmercier@google.com \
    --cc=wenst@chromium.org \
    --cc=yong.wu@mediatek.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox