From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mx0b-0031df01.pphosted.com (mx0b-0031df01.pphosted.com [205.220.180.131]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 9D2D1331EAC for ; Fri, 17 Jul 2026 10:28:40 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=205.220.180.131 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784284122; cv=none; b=qxHfzyZ1e62erfNpQs61V+vW8TCULZTnynWCGHDeu5MMY/Rtm7NmoZoWvYurXHREN5Io7zA7Bq2MyyhB2XZMSWgU+RD/r5gxNmbb1ZoFJ0TP8ZnlIR84NAzcxZ25SFM75RqJ76uMJjf71UsflRCEaE+E5w9iF0/ymah78Svst5c= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784284122; c=relaxed/simple; bh=9bNI51YMtAF7tCIzavxuP+Bw10YD+bsCUTTTQ43Ue9w=; h=From:Date:To:Cc:Subject:Message-ID:References:MIME-Version: Content-Type:Content-Disposition:In-Reply-To; b=bgQVCJFjbWVWD/A7jXkxCwI5/nn0IrF9lKpon1lALLkpklysbZrGObWoNNgmrL0Q2WdYuo7UwmfIplBlf1CRKS1BzeqvEE6/VWWUBIii0APyVaJOPSwNbXOQiJVOgkJfu2NUzFDQu22d0ruDHabsYCWWJrBb+xe+PDOi6nQnls0= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=oss.qualcomm.com; spf=pass smtp.mailfrom=oss.qualcomm.com; dkim=pass (2048-bit key) header.d=qualcomm.com header.i=@qualcomm.com header.b=lWMM+cx8; dkim=pass (2048-bit key) header.d=oss.qualcomm.com header.i=@oss.qualcomm.com header.b=WIzBGu/4; arc=none smtp.client-ip=205.220.180.131 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=oss.qualcomm.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=oss.qualcomm.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=qualcomm.com header.i=@qualcomm.com header.b="lWMM+cx8"; dkim=pass (2048-bit key) header.d=oss.qualcomm.com header.i=@oss.qualcomm.com header.b="WIzBGu/4" Received: from pps.filterd (m0279872.ppops.net [127.0.0.1]) by mx0a-0031df01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 66H6cTwh851707 for ; Fri, 17 Jul 2026 10:28:39 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=qualcomm.com; h= cc:content-transfer-encoding:content-type:date:from:in-reply-to :message-id:mime-version:references:subject:to; s=qcppdkim1; bh= GJCYGiRTawctkNCl84JlSf9o1HOO8bimM+ytWBDPjmM=; b=lWMM+cx8feBhLbB2 RcU69sEZ19EFRyEhb9A1VlQL2OUkZVo0zr4NEVHWXcWmLjf27vyWPqvPIact2Msw UDwA1jROHqthGHeU5NDvInGMXMVrIhNhQU16pVHxzDhT2t9TEyou1FZfnxC58mjA vbXQasGZKE8BdB73UcxL1DYH2WDua+oxEAbonDLS2LvmLtoJBVUTpeKFe5UU/zpQ C8lhuWYMg+Mmp53VPnVDFBAfghi/ZuGv3OPNVGNv4sMrNaQTMo2LPIxroj+oJjkM GfJYhP6YC2EpoEpz0g3y+CTA1nlwwKQP8kNEsy+3sMfFVSYjurYDHtXFEP1iE8/y fsfRMA== Received: from mail-qt1-f199.google.com (mail-qt1-f199.google.com [209.85.160.199]) by mx0a-0031df01.pphosted.com (PPS) with ESMTPS id 4fff9p8v3p-1 (version=TLSv1.3 cipher=TLS_AES_128_GCM_SHA256 bits=128 verify=NOT) for ; Fri, 17 Jul 2026 10:28:39 +0000 (GMT) Received: by mail-qt1-f199.google.com with SMTP id d75a77b69052e-51c1a97644aso188564981cf.2 for ; Fri, 17 Jul 2026 03:28:39 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=oss.qualcomm.com; s=google; t=1784284118; x=1784888918; darn=vger.kernel.org; h=in-reply-to:content-transfer-encoding:content-disposition :content-type:mime-version:references:message-id:subject:cc:to:date :from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=GJCYGiRTawctkNCl84JlSf9o1HOO8bimM+ytWBDPjmM=; b=WIzBGu/4On+lVkpidoyrEhYSla3kkmY9wUAZHlyTkZZqOCAUjSVoIBptD1/EqN5q15 MK0dTCN/G5ovkvXj9+MGM2F88CGFC+egdWgpHgclNiEWIOwF+ryfoTQwaQNJY6caYE4/ 1ifpI/sFBIg0L7WzzXEJJ3e5se+adXUP5a6XoyRwLBwieEDjiCSAArQT1dPpeP5bGqXz 2f7BymM/dV+8ORL7DXMWvC50d2T1fpsy1SE2YSGqXhH62qMQVih4N+Z4cnZl9WkVCkVx 34VgQ0E1OLP2vabTJN+gamq2VDutVDz80X+dq0EyBxuXNrj+sCp/SZXXlrVN7ApSRssR qjtg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784284118; x=1784888918; h=in-reply-to:content-transfer-encoding:content-disposition :content-type:mime-version:references:message-id:subject:cc:to:date :from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to:content-type; bh=GJCYGiRTawctkNCl84JlSf9o1HOO8bimM+ytWBDPjmM=; b=Cz3ZFwGsWlrWu+ZIgQYlkIuUd3r7/+3jdVh81oCzN/3cP3r4YoXJMXokej44B8eYh5 PTBrZ7r7IGZqu8Q5yds0L0czU2EQ4j7ZoBL+LcDJjIAin/hKqO25MON+BbWRiukskrFV Ftw5a4bZUmQUD9s3LxY2ETdMtkKU2flM0NJQT7QqSGjEZdfxhekKlVUED7F2ih/I3dS9 BBoiDPpWCRc/yBStobES+W3vj1yezM4aHP9juioxndtmsGAYLLy5W0a1XGBlk83YVjYj H4G10wE+2A34BUt1gFNmBTv2qz1u4oGSAd7/D6ZR8ivYxYqt1PLluFO26TFMLUHtIQ0i AByQ== X-Forwarded-Encrypted: i=1; AHgh+Rqp6HGHXlKn7S1M1ic/r92TD9lINeJfKciIUfnpfZU1NP89cU8E6Jy8bI7gnIhwLPUwWYMVQjViSF1VyCk=@vger.kernel.org X-Gm-Message-State: AOJu0YxYp2PxgzZCGp9oJtFQVxIE3IuxzZ3RCDtb34ZaeqlskmGJDrVO mNNNz6MElh8IeS9DCnOxLMhzqdENoaQUpQVnDzdkHWVGGvHfHu11/nf+3+rXIOM8ulxwhRNmPfk 8wsR2+NE95+ADLAizyUAr1ywLbkqTkskkkslq86DeTnHvco1DbjygSwd9vGPinxPZTcMBw3IhiV Q= X-Gm-Gg: AfdE7cl2nvpKUNYoGkPyag/RFBm2hlmsg4cpCD9roLcDQ0861anuBpAzWLwwOTiFyhF 4tXz9ay4ob78346JyM6qLtWDCziPgze3Nn4Ut9ELZYmSOq5VWFYr/qqttLSVNfIYlKXhbTcJM3w PbgTDMt4ehatbDIQGsootHYKntnFs7DLneTJlh18UJdFmIYlw0wH+xQsPm8aE4fEHZzQEESuAZW NjzXaC9fwW94u5+EKPxy4LkWBY3c5LFzw6hn7UbvFd18PfrHrZeMQvibWcZotQcjCcCkMtP2LUr qcfEFWmuvwOE2D5qdWhvExa9L1qkh79tJEvB0PkB6RwJwKxmLhgrmg+7Q60Wa7vhL34Wh+W56/R VsytXT7e+z5lhOENRMBjs+Kih1iN6cSea4mE= X-Received: by 2002:a05:622a:228a:b0:51c:667:7e30 with SMTP id d75a77b69052e-5213e28e24emr15579921cf.47.1784284118505; Fri, 17 Jul 2026 03:28:38 -0700 (PDT) X-Received: by 2002:a05:622a:228a:b0:51c:667:7e30 with SMTP id d75a77b69052e-5213e28e24emr15579581cf.47.1784284117985; Fri, 17 Jul 2026 03:28:37 -0700 (PDT) Received: from trex (182.red-79-144-196.dynamicip.rima-tde.net. [79.144.196.182]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-4954a2eddb8sm76488975e9.14.2026.07.17.03.28.36 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 17 Jul 2026 03:28:37 -0700 (PDT) From: Jorge Ramirez X-Google-Original-From: Jorge Ramirez Date: Fri, 17 Jul 2026 12:28:35 +0200 To: Jens Wiklander Cc: Jorge Ramirez-Ortiz , alim.akhtar@samsung.com, avri.altman@wdc.com, bvanassche@acm.org, James.Bottomley@hansenpartnership.com, martin.petersen@oracle.com, beanhuo@micron.com, can.guo@oss.qualcomm.com, linux-scsi@vger.kernel.org, linux-kernel@vger.kernel.org, op-tee@lists.trustedfirmware.org, jenswi@kernel.org, sumit.garg@oss.qualcomm.com Subject: Re: [PATCH v1 2/2] ufs: rpmb: use a fixed-length RPMB dev_id Message-ID: References: <20260716083728.2226422-1-jorge.ramirez@oss.qualcomm.com> <20260716083728.2226422-3-jorge.ramirez@oss.qualcomm.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Disposition: inline Content-Transfer-Encoding: 8bit In-Reply-To: X-Proofpoint-GUID: YlVD57iN_V0qLmyCkdHeotlnvx5-yijr X-Proofpoint-ORIG-GUID: YlVD57iN_V0qLmyCkdHeotlnvx5-yijr X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwNzE3MDEwNSBTYWx0ZWRfX+Ac0Avh2KX1T ac0u9m31olJ0YSMxUkC+NnTIZUv/S6DggCcXAq7EWoyBvBaXq7C1we1SbK3kksLZsSFFTVc1hHD CAHGBvx3hROH8qEEXEaZJtKkFgFH8YnOQL1doqdEmwYYR2UIKIk/vTPGVTD1IakPYv0HtcpvQe3 P/y5otmaodyM9ZvcJxXyTNRPuxuSebbNDTlJycrt6HC+B/GZzEfWS4WiqWtxWRwpW9N0nBL+oC1 p8PvwK1irvpjhhHTSmkwP7zoik+NmEoUCTWuoL6EmMO032GiVuaDSGqdETwzKBYxRKNiKn4X90F LbZaGRHVcqgWKC+HhRGwWc/o5P8o5pX9cn74rD+visnqTdT1v8VpSsRdPb7b8wpX1jeyl3nCZjz 50y5U5oTCvtJONYcFg82k96B0302ZdiY/ssdVNYKI9USEz0GWepXOyrIM8dHmVsbIvXkUCQUuiN Nm2BJaT1+A11H+DSRBA== X-Authority-Analysis: v=2.4 cv=TaqmcxQh c=1 sm=1 tr=0 ts=6a5a03d7 cx=c_pps a=WeENfcodrlLV9YRTxbY/uA==:117 a=2lELrtOEK2EaG96G7mOeag==:17 a=IkcTkHD0fZMA:10 a=RAioF0-LDSMA:10 a=s4-Qcg_JpJYA:10 a=VkNPw1HP01LnGYTKEx00:22 a=u7WPNUs3qKkmUXheDGA7:22 a=yx91gb_oNiZeI1HMLzn7:22 a=NEAV23lmAAAA:8 a=voM4FWlXAAAA:8 a=EUspDBNiAAAA:8 a=AhAad4elxc9sd5kYIg8A:9 a=3ZKOabzyN94A:10 a=QEXdDO2ut3YA:10 a=kacYvNCVWA4VmyqE58fU:22 a=IC2XNlieTeVoXbcui8wp:22 X-Proofpoint-Spam-Info: AW1haW4tMjYwNzE3MDEwNSBTYWx0ZWRfXy0W+0uUY8AnD SYKRZUpDUl7qpSDgd//60QvFGXlbAni0pfMAmrQ48+xjVtwAf0uIdAwm3hTFoVaZhB77escVUrl G79Q0I+7LY5KF5yWj8ZcGIj4Iq1/17o= X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1143,Hydra:6.1.134,FMLib:17.12.100.49 definitions=2026-07-17_02,2026-07-15_02,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 clxscore=1015 impostorscore=0 suspectscore=0 lowpriorityscore=0 phishscore=0 adultscore=0 spamscore=0 bulkscore=0 priorityscore=1501 malwarescore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2607170105 On 17/07/26 11:38:31, Jens Wiklander wrote: > Hi Jorge, > > On Thu, Jul 16, 2026 at 10:37 AM Jorge Ramirez-Ortiz > wrote: > > > > The RPMB authentication key is derived from the dev_id handed to the > > RPMB subsystem. OP-TEE implements the eMMC RPMB flow, where the dev_id > > is the eMMC CID, a fixed 16-byte value, and it derives the key on that > > assumption. > > > > The UFS RPMB id built here is "-R", which is variable > > length and longer than 16 bytes. Passing it verbatim would tie the > > derived key to a length OP-TEE does not expect and diverge from the > > fixed-CID eMMC ABI, requiring OP-TEE to be taught about variable-length > > UFS ids. > > Yes, if it's possible, It's nice to avoid that. > > > > > Hash the UFS id into a fixed 16-byte dev_id with blake2s instead. This > > keeps the derived key stable and unique per region while matching the > > eMMC CID layout OP-TEE relies on, so the key-derivation ABI stays > > identical and no OP-TEE change is needed. > > > > Signed-off-by: Jorge Ramirez-Ortiz > > --- > > drivers/ufs/core/ufs-rpmb.c | 19 +++++++++++++++++-- > > 1 file changed, 17 insertions(+), 2 deletions(-) > > > > diff --git a/drivers/ufs/core/ufs-rpmb.c b/drivers/ufs/core/ufs-rpmb.c > > index d0c7ea7a36f4..b800871269bb 100644 > > --- a/drivers/ufs/core/ufs-rpmb.c > > +++ b/drivers/ufs/core/ufs-rpmb.c > > @@ -10,6 +10,7 @@ > > * Can Guo > > */ > > > > +#include > > #include > > #include > > #include > > @@ -21,6 +22,7 @@ > > #include > > #include "ufshcd-priv.h" > > > > +#define UFS_RPMB_ID_LEN 16 /* Match eMMC CID Length */ > > #define UFS_RPMB_SEC_PROTOCOL 0xEC /* JEDEC UFS application */ > > #define UFS_RPMB_SEC_PROTOCOL_ID 0x01 /* JEDEC UFS RPMB protocol ID, CDB byte3 */ > > > > @@ -154,6 +156,7 @@ int ufs_rpmb_probe(struct ufs_hba *hba) > > { > > struct ufs_rpmb_dev *ufs_rpmb, *it, *tmp; > > struct rpmb_dev *rdev; > > + char *dev_id = NULL; > > char *cid = NULL; > > int region; > > u32 cap; > > @@ -213,8 +216,17 @@ int ufs_rpmb_probe(struct ufs_hba *hba) > > goto err_out; > > } > > > > - descr.dev_id = cid; > > - descr.dev_id_len = strlen(cid); > > + dev_id = kzalloc(UFS_RPMB_ID_LEN, GFP_KERNEL); > > + if (!dev_id) { > > + device_unregister(&ufs_rpmb->dev); > > + ret = -ENOMEM; > > + goto err_out; > > + } > > + > > + blake2s(NULL, 0, cid, strlen(cid), dev_id, UFS_RPMB_ID_LEN); > > + > > + descr.dev_id = dev_id; > > + descr.dev_id_len = UFS_RPMB_ID_LEN; > > This change will break current users of this interface, if there are > any. There are currently no upstream users in OP-TEE since you're > adding that with https://github.com/OP-TEE/optee_os/pull/7881, but I > suppose that's not the only use case. I was wondering too - but since this is an OP-TEE driver (at least that is what the module directive says at the bottom of the file) - I chose to do it here (cleaner). But we could take care of this on the rpc.c instead A similar sort of change will need to go to U-boot but since the current CID is broken anyway, I believe we will be able to go that route as well. See: https://patchwork.ozlabs.org/project/uboot/patch/20260717093013.3253643-1-jorge.ramirez@oss.qualcomm.com/ BTW I need to send another revision of this set (we need to use blake2b (there is no support for blake2s in U-boot). But I'll wait for comments if this is the right way to go instead of using full-size srings (ie, 88 characters on this particular case which seems desproportionate IMO) > > Cheers, > Jens > > > > descr.capacity = cap; > > > > /* Register RPMB device */ > > @@ -228,6 +240,8 @@ int ufs_rpmb_probe(struct ufs_hba *hba) > > > > kfree(cid); > > cid = NULL; > > + kfree(dev_id); > > + dev_id = NULL; > > > > ufs_rpmb->rdev = rdev; > > ufs_rpmb->region_id = region; > > @@ -240,6 +254,7 @@ int ufs_rpmb_probe(struct ufs_hba *hba) > > return 0; > > err_out: > > kfree(cid); > > + kfree(dev_id); > > list_for_each_entry_safe(it, tmp, &hba->rpmbs, node) { > > list_del(&it->node); > > device_unregister(&it->dev); > > -- > > 2.54.0 > >