From: Yu-Chien Peter Lin <peter.lin@sifive.com>
To: devicetree@vger.kernel.org, linux-riscv@lists.infradead.org,
linux-kernel@vger.kernel.org
Cc: robh@kernel.org, krzk+dt@kernel.org, conor+dt@kernel.org,
pjw@kernel.org, palmer@dabbelt.com, aou@eecs.berkeley.edu,
alex@ghiti.fr, samuel.holland@sifive.com, dlan@kernel.org,
guodong@riscstar.com, dfustini@oss.tenstorrent.com,
michal.simek@amd.com, junhui.liu@pigmoral.tech,
darshan.prajapati@einfochips.com, akpm@linux-foundation.org,
zhangchunyan@iscas.ac.cn, luxu.kernel@bytedance.com,
pincheng.plct@isrc.iscas.ac.cn, nick.hu@sifive.com,
jim.shu@sifive.com, zong.li@sifive.com, greentime.hu@sifive.com,
robin.randhawa@sifive.com, scott@riscstar.com,
dave.patel@riscstar.com, raymond.mao@riscstar.com,
anup@brainfault.org, pawandeep.oza@oss.qualcomm.com,
Yu-Chien Peter Lin <peter.lin@sifive.com>
Subject: [PATCH v2 3/3] dt-bindings: sifive: Add WorldGuard Checker
Date: Thu, 30 Jul 2026 00:39:08 +0800 [thread overview]
Message-ID: <20260729163908.249838-4-peter.lin@sifive.com> (raw)
In-Reply-To: <20260729163908.249838-1-peter.lin@sifive.com>
Add YAML binding schema for the SiFive wgChecker, a programmable
access controller integrated in the interconnect fabric of RISC-V
Worlds-capable SoCs.
wgChecker enforces World ID (WID) based access control on downstream
bus transactions. Each checker slot encodes a 2-bit permission field
per WID (read/write), enabling fine-grained memory partitioning and
device isolation between execution contexts. Violations are reported
via bus errors, interrupts, or both, selectable and lockable per slot.
The binding registers wgChecker as an access-controllers provider.
Consumers (i.e. its protected device) reference it via the standard
access-controllers phandle to declare their access requirements.
Also document the sifive,trustedwid property for the /cpus node,
identifying the privileged WID authorized to configure all checkers
on the platform.
Link: https://github.com/riscvarchive/security/blob/main/papers/worldguard%20proposal.pdf
Signed-off-by: Yu-Chien Peter Lin <peter.lin@sifive.com>
Reviewed-by: Zong Li <zong.li@sifive.com>
Reviewed-by: Jim Shu <jim.shu@sifive.com>
---
.../devicetree/bindings/riscv/worlds.yaml | 9 +
.../bindings/sifive/sifive,wgchecker2.yaml | 356 ++++++++++++++++++
2 files changed, 365 insertions(+)
create mode 100644 Documentation/devicetree/bindings/sifive/sifive,wgchecker2.yaml
diff --git a/Documentation/devicetree/bindings/riscv/worlds.yaml b/Documentation/devicetree/bindings/riscv/worlds.yaml
index cc8b3747591e..c39a06c2dd8d 100644
--- a/Documentation/devicetree/bindings/riscv/worlds.yaml
+++ b/Documentation/devicetree/bindings/riscv/worlds.yaml
@@ -34,6 +34,14 @@ properties:
minimum: 2
maximum: 64
+ sifive,trustedwid:
+ $ref: /schemas/types.yaml#/definitions/uint32
+ maximum: 31
+ description: |
+ The World ID (WID) designated as the trusted WID for this platform.
+ Transactions tagged with this WID are authorized to access and configure
+ WorldGuard blocks, including wgCheckers and wgMarkers.
+
additionalProperties: true
examples:
@@ -44,6 +52,7 @@ examples:
#size-cells = <0>;
timebase-frequency = <1000000>;
riscv,nworlds = <4>;
+ sifive,trustedwid = <3>;
cpu@0 {
device_type = "cpu";
diff --git a/Documentation/devicetree/bindings/sifive/sifive,wgchecker2.yaml b/Documentation/devicetree/bindings/sifive/sifive,wgchecker2.yaml
new file mode 100644
index 000000000000..c025a4765cb3
--- /dev/null
+++ b/Documentation/devicetree/bindings/sifive/sifive,wgchecker2.yaml
@@ -0,0 +1,356 @@
+# SPDX-License-Identifier: (GPL-2.0-only OR BSD-2-Clause)
+# Copyright (C) 2026 SiFive, Inc.
+%YAML 1.2
+---
+$id: http://devicetree.org/schemas/sifive/sifive,wgchecker2.yaml#
+$schema: http://devicetree.org/meta-schemas/core.yaml#
+
+title: SiFive WorldGuard Checker
+
+maintainers:
+ - Yu-Chien Peter Lin <peter.lin@sifive.com>
+
+description: |
+ The RISC-V Worlds ISA extension defines World IDs (WIDs) as architectural
+ identifiers that tag each system transaction with its originating context.
+ System integrators assign WIDs to execution contexts such as privilege modes,
+ trusted execution environments, or other isolation boundaries.
+
+ The SiFive WorldGuard Checker is a hardware firewall positioned in the
+ system interconnect fabric. It inspects every transaction, evaluating the
+ WID against access control policies encoded in checker slots for each
+ protected resource. Transactions from unauthorized WIDs are blocked and
+ reported as bus errors, interrupts, or both.
+
+ This enables spatial partitioning of memory regions and memory-mapped devices
+ across execution contexts. Different address ranges can enforce distinct
+ policies, allowing isolated workloads to coexist with hardware-enforced
+ protection.
+
+ The wgChecker acts as an access-controller provider as defined in the
+ access-controllers framework. Protected devices are consumers that declare
+ their access policy via the access-controllers property. The hardware
+ supports up to 32 World IDs.
+
+ The World ID authorized to configure WorldGuard blocks is specified by the
+ sifive,trustedwid property in the /cpus node.
+
+allOf:
+ - $ref: /schemas/access-controllers/access-controllers.yaml#
+
+properties:
+ compatible:
+ oneOf:
+ - items:
+ - const: qemu,wgchecker2
+ - const: sifive,wgchecker2
+ - const: sifive,wgchecker2
+
+ reg:
+ maxItems: 1
+ description:
+ Base address and size of the wgChecker memory-mapped I/O registers.
+
+ interrupts:
+ maxItems: 1
+ description:
+ Interrupt line asserted when a WID access violation is detected and
+ interrupt reporting is enabled in the slot configuration (IR or IW
+ bits set).
+
+ '#access-controller-cells':
+ const: 1
+ description: |
+ Specifies the partition identifier to reference a partition child
+ node that defines the access control region, WID permissions, and
+ access failure configuration. The special ID 0xFFFFFFFF indicates
+ unprotected mode, granting unrestricted access to the device.
+
+ '#address-cells':
+ const: 1
+
+ '#size-cells':
+ const: 0
+
+patternProperties:
+ "^partition@[0-9a-f]+$":
+ type: object
+ additionalProperties: false
+
+ properties:
+ reg:
+ maximum: 0xFFFFFFFE
+ description:
+ Partition identifier. Must be unique within the wgChecker node.
+ The value 0xFFFFFFFF is reserved for unprotected mode and must
+ not be used.
+
+ sifive,protected-region:
+ $ref: /schemas/types.yaml#/definitions/uint32-array
+ description:
+ Protected memory region encoded as a base address and size.
+ items:
+ - description: Upper 32 bits of the base address
+ - description: Lower 32 bits of the base address
+ - description: Upper 32 bits of the region size
+ - description: Lower 32 bits of the region size
+
+ sifive,slot-permissions:
+ $ref: /schemas/types.yaml#/definitions/uint64
+ description: |
+ 64-bit WID permission bitmap. Each WID N uses two consecutive bits:
+ - bit[2*N] : Read permission for WID N
+ - bit[2*N+1]: Write permission for WID N
+ Set bits grant access.
+
+ sifive,slot-config:
+ $ref: /schemas/types.yaml#/definitions/uint32
+ maximum: 0x1F
+ description: |
+ Access failure configuration flags for this slot:
+ bit[0] (ER): report read violations as bus errors
+ bit[1] (EW): report write violations as bus errors
+ bit[2] (IR): report read violations via interrupt
+ bit[3] (IW): report write violations via interrupt
+ bit[4] (L) : lock this slot against further modification
+ Bits[5:31] are reserved and must be zero.
+
+ required:
+ - reg
+ - sifive,protected-region
+ - sifive,slot-permissions
+ - sifive,slot-config
+
+required:
+ - compatible
+ - reg
+ - '#address-cells'
+ - '#size-cells'
+ - '#access-controller-cells'
+
+additionalProperties: false
+
+examples:
+ - |
+ #include <dt-bindings/interrupt-controller/irq.h>
+
+ // Example 1: Peripheral device protection
+
+ cpus {
+ #address-cells = <1>;
+ #size-cells = <0>;
+ timebase-frequency = <1000000>;
+ riscv,nworlds = <4>;
+ sifive,trustedwid = <3>;
+
+ cpu@0 {
+ device_type = "cpu";
+ reg = <0>;
+ compatible = "riscv";
+ riscv,isa-base = "rv64i";
+ riscv,isa-extensions = "i", "m", "a", "c", "smlwid";
+ riscv,pmwid = <3>;
+
+ cpu_intc0: interrupt-controller {
+ #interrupt-cells = <1>;
+ compatible = "riscv,cpu-intc";
+ interrupt-controller;
+ };
+ };
+ };
+
+ soc {
+ #address-cells = <2>;
+ #size-cells = <2>;
+
+ uart: uart@1c1000 {
+ compatible = "ns16550a";
+ reg = <0x0 0x001c1000 0x0 0x1000>;
+ reg-names = "control";
+ interrupts = <10 IRQ_TYPE_LEVEL_HIGH>;
+ access-controllers = <&wgchecker0 0>;
+ };
+
+ wgchecker0: access-controller@1c2000 {
+ compatible = "qemu,wgchecker2", "sifive,wgchecker2";
+ reg = <0x0 0x001c2000 0x0 0x1000>;
+ #access-controller-cells = <1>;
+ #address-cells = <1>;
+ #size-cells = <0>;
+ interrupts = <80 IRQ_TYPE_LEVEL_HIGH>;
+ interrupt-parent = <&aplic0_m>;
+
+ partition@0 {
+ reg = <0>;
+ sifive,protected-region = <0x0 0x001c1000 0x0 0x00001000>;
+ sifive,slot-permissions = <0x0 0x000000c3>;
+ sifive,slot-config = <0x0f>;
+ };
+ };
+
+ aplic0_m: interrupt-controller@c000000 {
+ compatible = "qemu,aplic", "riscv,aplic";
+ reg = <0x0 0xc000000 0x0 0x4000>;
+ interrupt-controller;
+ #interrupt-cells = <2>;
+ riscv,num-sources = <96>;
+ interrupts-extended = <&cpu_intc0 11>;
+ };
+ };
+
+ - |
+ #include <dt-bindings/interrupt-controller/irq.h>
+
+ // Example 2: Device with multiple address regions and per-region access rules
+
+ cpus {
+ #address-cells = <1>;
+ #size-cells = <0>;
+ timebase-frequency = <1000000>;
+ riscv,nworlds = <16>;
+ sifive,trustedwid = <3>;
+
+ cpu@0 {
+ device_type = "cpu";
+ reg = <0>;
+ compatible = "riscv";
+ riscv,isa-base = "rv64i";
+ riscv,isa-extensions = "i", "m", "a", "c", "smlwid";
+ riscv,pmwid = <3>;
+
+ cpu_intc1: interrupt-controller {
+ #interrupt-cells = <1>;
+ compatible = "riscv,cpu-intc";
+ interrupt-controller;
+ };
+ };
+ };
+
+ soc {
+ #address-cells = <2>;
+ #size-cells = <2>;
+
+ device: device@10000 {
+ compatible = "vendor,soc1-ip";
+ reg = <0x0 0x00010000 0x0 0x8000>,
+ <0x0 0x00a00000 0x0 0x4000>;
+ reg-names = "m_mode", "s_mode";
+ // m_mode: WID 3 only; s_mode: WID 0,3 RW
+ access-controllers = <&wgchecker1 0>,
+ <&wgchecker1 1>;
+ };
+
+ wgchecker1: access-controller@35000 {
+ compatible = "qemu,wgchecker2", "sifive,wgchecker2";
+ reg = <0x0 0x00035000 0x0 0x1000>;
+ #access-controller-cells = <1>;
+ #address-cells = <1>;
+ #size-cells = <0>;
+ interrupts = <81 IRQ_TYPE_LEVEL_HIGH>;
+ interrupt-parent = <&aplic1_m>;
+
+ partition@0 {
+ reg = <0>;
+ sifive,protected-region = <0x0 0x00010000 0x0 0x00008000>;
+ sifive,slot-permissions = <0x0 0x000000c0>;
+ sifive,slot-config = <0x0f>;
+ };
+
+ partition@1 {
+ reg = <1>;
+ sifive,protected-region = <0x0 0x00a00000 0x0 0x00004000>;
+ sifive,slot-permissions = <0x0 0x000000c3>;
+ sifive,slot-config = <0x0f>;
+ };
+ };
+
+ aplic1_m: interrupt-controller@c000000 {
+ compatible = "qemu,aplic", "riscv,aplic";
+ reg = <0x0 0xc000000 0x0 0x4000>;
+ interrupt-controller;
+ #interrupt-cells = <2>;
+ riscv,num-sources = <96>;
+ interrupts-extended = <&cpu_intc1 11>;
+ };
+ };
+
+ - |
+ #include <dt-bindings/interrupt-controller/irq.h>
+
+ // Example 3: DRAM partitioning with a secure enclave
+
+ cpus {
+ #address-cells = <1>;
+ #size-cells = <0>;
+ timebase-frequency = <1000000>;
+ riscv,nworlds = <4>;
+ sifive,trustedwid = <3>;
+
+ cpu@0 {
+ device_type = "cpu";
+ reg = <0>;
+ compatible = "riscv";
+ riscv,isa-base = "rv64i";
+ riscv,isa-extensions = "i", "m", "a", "c", "smlwid", "smwiddeleg", "sswid";
+ riscv,pmwid = <3>;
+
+ cpu_intc2: interrupt-controller {
+ #interrupt-cells = <1>;
+ compatible = "riscv,cpu-intc";
+ interrupt-controller;
+ };
+ };
+ };
+
+ soc {
+ #address-cells = <2>;
+ #size-cells = <2>;
+
+ memory@80000000 {
+ device_type = "memory";
+ reg = <0x0 0x80000000 0x0 0x80000000>;
+ access-controllers = <&wgchecker2 0>,
+ <&wgchecker2 1>,
+ <&wgchecker2 2>;
+ };
+
+ wgchecker2: access-controller@40000000 {
+ compatible = "qemu,wgchecker2", "sifive,wgchecker2";
+ reg = <0x0 0x40000000 0x0 0x1000>;
+ #access-controller-cells = <1>;
+ #address-cells = <1>;
+ #size-cells = <0>;
+ interrupts = <82 IRQ_TYPE_LEVEL_HIGH>;
+ interrupt-parent = <&aplic2_m>;
+
+ partition@0 {
+ reg = <0>;
+ sifive,protected-region = <0x0 0x80000000 0x0 0x40000000>;
+ sifive,slot-permissions = <0x0 0x000000cf>;
+ sifive,slot-config = <0x0f>;
+ };
+
+ partition@1 {
+ reg = <1>;
+ sifive,protected-region = <0x0 0xc0000000 0x0 0x01000000>;
+ sifive,slot-permissions = <0x0 0x000000cc>;
+ sifive,slot-config = <0x0f>;
+ };
+
+ partition@2 {
+ reg = <2>;
+ sifive,protected-region = <0x0 0xc1000000 0x0 0x3f000000>;
+ sifive,slot-permissions = <0x0 0x000000cf>;
+ sifive,slot-config = <0x0f>;
+ };
+ };
+
+ aplic2_m: interrupt-controller@c000000 {
+ compatible = "qemu,aplic", "riscv,aplic";
+ reg = <0x0 0xc000000 0x0 0x4000>;
+ interrupt-controller;
+ #interrupt-cells = <2>;
+ riscv,num-sources = <96>;
+ interrupts-extended = <&cpu_intc2 11>;
+ };
+ };
--
2.43.7
_______________________________________________
linux-riscv mailing list
linux-riscv@lists.infradead.org
http://lists.infradead.org/mailman/listinfo/linux-riscv
next prev parent reply other threads:[~2026-07-29 16:40 UTC|newest]
Thread overview: 9+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-29 16:39 [PATCH v2 0/3] dt-bindings: riscv: Add RISC-V Worlds and SiFive WorldGuard DT bindings Yu-Chien Peter Lin
2026-07-29 16:39 ` [PATCH v2 1/3] dt-bindings: riscv: Add Worlds ISA extensions Yu-Chien Peter Lin
2026-07-29 16:39 ` [PATCH v2 2/3] dt-bindings: riscv: Add Worlds per-hart properties Yu-Chien Peter Lin
2026-07-29 18:06 ` Rob Herring (Arm)
2026-07-30 7:30 ` Krzysztof Kozlowski
2026-07-29 16:39 ` Yu-Chien Peter Lin [this message]
2026-07-29 18:07 ` [PATCH v2 3/3] dt-bindings: sifive: Add WorldGuard Checker Rob Herring (Arm)
2026-07-30 7:35 ` Krzysztof Kozlowski
2026-07-30 7:37 ` Krzysztof Kozlowski
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260729163908.249838-4-peter.lin@sifive.com \
--to=peter.lin@sifive.com \
--cc=akpm@linux-foundation.org \
--cc=alex@ghiti.fr \
--cc=anup@brainfault.org \
--cc=aou@eecs.berkeley.edu \
--cc=conor+dt@kernel.org \
--cc=darshan.prajapati@einfochips.com \
--cc=dave.patel@riscstar.com \
--cc=devicetree@vger.kernel.org \
--cc=dfustini@oss.tenstorrent.com \
--cc=dlan@kernel.org \
--cc=greentime.hu@sifive.com \
--cc=guodong@riscstar.com \
--cc=jim.shu@sifive.com \
--cc=junhui.liu@pigmoral.tech \
--cc=krzk+dt@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-riscv@lists.infradead.org \
--cc=luxu.kernel@bytedance.com \
--cc=michal.simek@amd.com \
--cc=nick.hu@sifive.com \
--cc=palmer@dabbelt.com \
--cc=pawandeep.oza@oss.qualcomm.com \
--cc=pincheng.plct@isrc.iscas.ac.cn \
--cc=pjw@kernel.org \
--cc=raymond.mao@riscstar.com \
--cc=robh@kernel.org \
--cc=robin.randhawa@sifive.com \
--cc=samuel.holland@sifive.com \
--cc=scott@riscstar.com \
--cc=zhangchunyan@iscas.ac.cn \
--cc=zong.li@sifive.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox