From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pz2-f9.google.com (mail-pz2-f9.google.com [74.125.228.9]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id F051F420898 for ; Wed, 19 Aug 2026 08:36:45 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=74.125.228.9 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787128607; cv=none; b=PYYDgYAxp4SPb+dvRM00Oe/6lNebAX/AjE4NZ9OCl6x10Z1gK0KzIpXi3FRosK3Xe0LMlVeH6f7t5DzyIEHhGdYkzt54rP4zK9frlE0r3rp3PHMArcXg489WP/rlGaNhva3tfxiu2eAT17QVK3gsTRCaF0qe5lWrTXOxfwZfOSc= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787128607; c=relaxed/simple; bh=P8ZslpnwpzWSGlubFgJm518h1JGOYuAU34Vm5b4g3LA=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=dU7kq7v/SmOAdNbsbxfY1XAFy4xLMIyWli13XTyO03QYmkXYdcbJwsW6kHsRBao2ZHxz5ylS1tCq3WOGgwo8za6FbxZFlqrNM6QnfwCyPuEc8lSJtbOv3cObj3PgKVtOMcAOFaUNt/bheYxHwQUFc3zSWfBNEnfB+x0LgEwqJKQ= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=fIsrl8MF; arc=none smtp.client-ip=74.125.228.9 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="fIsrl8MF" Received: by mail-pz2-f9.google.com with SMTP id 41be03b00d2f7-cbec619cd2cso175440a12.0 for ; Wed, 19 Aug 2026 01:36:45 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1787128605; x=1787733405; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=c/nqPj16def9ZnxDQwFpTtIBuj8LfIQAUc8OONxlNco=; b=fIsrl8MFRSa3fHYBxoXOEB/hfEcO3T0kp9IwlIuPtnRw51ylszUHp1mBSVxQua2Ts0 jitkwfSaENl0kyRaTan5gcdTexVkZZVLZLfFp/y5d/y895h1BFJrNz2zkv1l9SwtnKVc 0iJ/un5F1CW0QhbU5YTWOYhNwNCZ1ImJMs2MuVg+iR2SOKy8cPsoqzfkZTwqqrIhJAtP +MSyVczRHY76KHXZxvT6qOkP/6gTvpgQgXt/0sL1X7e+U4CtWURDfYFa0V6doQFM+pZu ZW9hWhKmJfuvNYrxgpnSRhUrMr+zNOUK/oAd+u/K8Ntg99+1XNzLQLfV83PFnRT8Oo/S 4jRg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787128605; x=1787733405; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=c/nqPj16def9ZnxDQwFpTtIBuj8LfIQAUc8OONxlNco=; b=XTB60peGfH4cGY6qnXmpthysJ7gNi5Jk6YFgFF50iooLZD4xbc0R9clPW1/boYlugD jSivUSgg2pTvLBmfdOW0JB6OiKYNhGtSqF95x7osyJenD24koJEkePJjommG+dXtNHjd eCwMIPVIM6P1rhXzwWCFUmAdfQGSbWi6GgFwGY7JBnU/oDO5t7znJVGVG8QcDWIvIgx3 rJmEFgT0DDQR6W6E11l4Gv673JA3iFf9Q7M/3VHajfAIi1Q4d/dJ99cb33EixUgUYdBu 7wcoGV9H82Rw2REzS/ecqvh+ZbFfKhU/KqoY9uVye/GXI4SXjAM19jKeHV1BPK9sUa7f aGEg== X-Forwarded-Encrypted: i=1; AHgh+RoYtigb0mVH3zA/krdfqguD28IadE0btf0434ErvWqcqsCl8XUDL72GDQF7dYqn5c8R3ZFcskcXLOcVnSI=@vger.kernel.org X-Gm-Message-State: AOJu0YxsW7Eh5sSW9iZGc5BTUBDjH5MthIoXU0PZD2xWM8x09668yHp/ b1MfAals7cLb1TPzAJCd3/jtwwk3om1fHzb4GuGRf4hvbnffXo4+nvd0 X-Gm-Gg: AR+sD13TeigktyeFktF14g8H+7YL6Sd01hJYO+3AASjwt0vX1L9cQO0ENG3P2JAZ6ZJ fkME2d1K15wooWkC15UlA5jjZbA+RPdB8Ef+oXBtre8BH3cEXSCiW2Q61Kx6LRrJoD1HorEhKX7 TdZDIJ3zIWa5qI8FbaJCo2OSJmcwkX+E4oN/Z8fLpwzi6F4lW0JL39N2WV0KzmE2mna0fDXpTfF YeTcJAooSYsJBlhcbMNWI6/ILODM6ldOz35hRbMX9UA5k7q1E2WvU6yh6/Gx6tlMuNrlDnAEMYw xQfHH+56ZC17/M/AvuAsA/yBDIaPJLxuH19UtDO7IPbFolGLLD8I/qwwZ7qNT8Jx6/ZIiveBcQY 8jde3TGJyiyQ9jn/BQKwaMfyJKgJbiVcZWx5Rt7MIxVs1DH07NS5vJb069y8dYiOFsi8cmjp/sC JWlva63O+ozYd+q+qWBjO6S1mrP9UlVqpd0qgOCH6MDvPYN2l/U9JsklV4cNLK8h8= X-Received: by 2002:a05:6300:2284:b0:3b4:5ff3:45cb with SMTP id adf61e73a8af0-3cd00e24fb6mr6745037637.8.1787128605149; Wed, 19 Aug 2026 01:36:45 -0700 (PDT) Received: from ubuntu24.. ([85.149.220.152]) by smtp.gmail.com with ESMTPSA id 41be03b00d2f7-cc155464a0asm332268a12.14.2026.08.19.01.36.40 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 19 Aug 2026 01:36:43 -0700 (PDT) From: Xing Loong To: Jens Wiklander Cc: Krzysztof Kozlowski , Conor Dooley , Rob Herring , Sumit Garg , op-tee@lists.trustedfirmware.org, devicetree@vger.kernel.org, linux-riscv@lists.infradead.org, linux-kernel@vger.kernel.org, Xing Loong Subject: [PATCH v4 2/3] dt-bindings: firmware: add mbedtee,tee binding Date: Wed, 19 Aug 2026 16:35:58 +0800 Message-ID: <20260819083559.1303348-3-xing.xl.loong@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260819083559.1303348-1-xing.xl.loong@gmail.com> References: <20260819083559.1303348-1-xing.xl.loong@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit MbedTEE is a Trusted Execution Environment for embedded systems (https://github.com/mbedtee). It communicates with the REE via shared-memory ring buffers using a fixed RPC protocol. Two platform configurations are supported: - ARM/AArch64 (TrustZone, SMC): two reserved-memory regions (t2r-ring and t2r-shm) plus a GIC SPI edge interrupt for TEE-to-REE notifications. - RISC-V (IMSIC): three reserved-memory regions, adding r2t-ring for REE-to-TEE command submissions; no interrupts property (T2R notifications use IMSIC MSI allocated at runtime). Signed-off-by: Xing Loong --- Changes in v4: - Move reserved-memory region descriptions into memory-region-names property (Rob) - Define memory-region-names item order at top level; keep per-branch name count constraints (maxItems: 2 / minItems: 3) (Rob) Changes in v3: - Drop all phandle stub nodes from examples. - Remove redundant required: - interrupts from then branch. - Simplify title and description. Changes in v2: - Fix DT binding review comments from Krzysztof Kozlowski: - Drop $nodename, "YAML devicetree binding" wording, property descriptions - Rename compatible string to mbedtee,tee - Rename memory regions: rpc-t2r-ring -> t2r-ring, rpc-t2r-shm -> t2r-shm, rpc-r2t-ring -> r2t-ring - Add memory-region / memory-region-names to required - Simplify allOf constraints (drop redundant else-branch items) - Rewrite description to describe hardware/firmware, not the binding or driver - Drop all irrelevant platform nodes (gic, cpus, reserved-memory) - Add maxItems: 1 constraint to interrupts property (Sashiko AI review) --- .../bindings/firmware/mbedtee,tee.yaml | 102 ++++++++++++++++++ 1 file changed, 102 insertions(+) create mode 100644 Documentation/devicetree/bindings/firmware/mbedtee,tee.yaml diff --git a/Documentation/devicetree/bindings/firmware/mbedtee,tee.yaml b/Documentation/devicetree/bindings/firmware/mbedtee,tee.yaml new file mode 100644 index 0000000..a67ac43 --- /dev/null +++ b/Documentation/devicetree/bindings/firmware/mbedtee,tee.yaml @@ -0,0 +1,102 @@ +# SPDX-License-Identifier: (GPL-2.0-only OR BSD-2-Clause) +%YAML 1.2 +--- +$id: http://devicetree.org/schemas/firmware/mbedtee,tee.yaml# +$schema: http://devicetree.org/meta-schemas/core.yaml# + +title: MbedTEE + +maintainers: + - Xing Loong + +description: | + MbedTEE is a Trusted Execution Environment for embedded systems. + It communicates with the REE (Linux) via shared-memory ring + buffers using a fixed RPC protocol. + + We're using "mbedtee" as the vendor prefix for the open-source TEE + project at https://github.com/mbedtee. + + The REE and TEE CPUs sharing the RPC memory must be in a + hardware-coherent domain. + + Two or three reserved-memory regions are required. On ARM the + transport uses SMC and a GIC SPI interrupt. On RISC-V the + transport uses shared-memory rings and IMSIC MSI; the TEE polls + r2t-ring for commands from the REE. + +properties: + compatible: + const: mbedtee,tee + + interrupts: + maxItems: 1 + + msi-parent: + maxItems: 1 + + memory-region: + minItems: 2 + maxItems: 3 + + memory-region-names: + description: | + t2r-ring: ring buffer for TEE-to-REE notifications + t2r-shm: shared memory for TEE-to-REE RPC payloads + r2t-ring: ring buffer for REE-to-TEE command submissions (RISC-V) + minItems: 2 + items: + - const: t2r-ring + - const: t2r-shm + - const: r2t-ring + +required: + - compatible + - memory-region + - memory-region-names + +allOf: + - if: + required: + - interrupts + then: + properties: + msi-parent: false + memory-region: + maxItems: 2 + memory-region-names: + maxItems: 2 + else: + required: + - msi-parent + properties: + interrupts: false + memory-region: + minItems: 3 + memory-region-names: + minItems: 3 + +additionalProperties: false + +examples: + - | + #include + + firmware { + mbedtee { + compatible = "mbedtee,tee"; + interrupts = ; + memory-region = <&t2r_ring>, <&t2r_shm>; + memory-region-names = "t2r-ring", "t2r-shm"; + }; + }; + + - | + firmware { + mbedtee { + compatible = "mbedtee,tee"; + msi-parent = <&imsic>; + memory-region = <&t2r_ring>, <&t2r_shm>, <&r2t_ring>; + memory-region-names = "t2r-ring", "t2r-shm", "r2t-ring"; + }; + }; -- 2.43.0