From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mx0b-0031df01.pphosted.com (mx0b-0031df01.pphosted.com [205.220.180.131]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 1176B1C84BC for ; Wed, 8 Jul 2026 06:01:52 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=205.220.180.131 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783490514; cv=none; b=TU0aRV+rh6AEdLcjoWg/4fg1dJMUn8RXnsMha0rr438pL8QuSK7ltvRMJhgQBlvGKFqoGO6iGDq0nBfPKqPLrlr8iG5BBFHVeetRcTEyajhljmkC6ZUOzhwg0GSdfrS00vgfse/KCi9N+tM4EYoeXhQ0Pf/sVHDBWBz1Ycz/eiE= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783490514; c=relaxed/simple; bh=WRcaoMH+g/SoWUtKRqzbRYwUKYcUQ2XK7GrXG21fTJI=; h=Message-ID:Date:MIME-Version:Subject:To:Cc:References:From: In-Reply-To:Content-Type; b=KQuyofDPHV5HvQMxa+E+ZaxxVxCGgfWTEIYyGLDAbdiqKq7i+6ScSmHdg/+M+x34ADsDYdfaRIORQ3Bx959dsb73cy+0cqwYkromW9mJLb5XCP5p3AA4jTSgqx+bxr6G6vCXPWwWdihr6KkM1aBqU9/o9BCGglkejVMTbmRN0XE= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=oss.qualcomm.com; spf=pass smtp.mailfrom=oss.qualcomm.com; dkim=pass (2048-bit key) header.d=qualcomm.com header.i=@qualcomm.com header.b=Fjdbr4gN; dkim=pass (2048-bit key) header.d=oss.qualcomm.com header.i=@oss.qualcomm.com header.b=BhLcDB+/; arc=none smtp.client-ip=205.220.180.131 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=oss.qualcomm.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=oss.qualcomm.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=qualcomm.com header.i=@qualcomm.com header.b="Fjdbr4gN"; dkim=pass (2048-bit key) header.d=oss.qualcomm.com header.i=@oss.qualcomm.com header.b="BhLcDB+/" Received: from pps.filterd (m0279868.ppops.net [127.0.0.1]) by mx0a-0031df01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 66842Wvq1638173 for ; Wed, 8 Jul 2026 06:01:52 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=qualcomm.com; h= cc:content-transfer-encoding:content-type:date:from:in-reply-to :message-id:mime-version:references:subject:to; s=qcppdkim1; bh= 7z8OET7rO6M3TRuXlj9b3aCKb7Zgt+kWJI0H9Bb/fuw=; b=Fjdbr4gNWBSM8/F0 0tZHbKfgy1SYKpIq59hJGEZYeCBQtwX7vVFGQUX7uVcvAu8aISWrnF4KILKeotMR eFOt2iq6GOZwDdzKL6UtARsDBBj1sB/ySNYzLcCHfDJEr/GjuUyfIsxpx8LP6taU kEqfMrPcg6satyig8DGtXxDLSG17sGuf4C7y57zyzIuos8RNd+q1aml4+8xTeKTt Iah4yuLAPIE1KbZNFepnFDSzMmFT2TbNo3p277pZ1xqD1rFy3T5FO4Q40ZE5mscY bPKQk6g1R2FI0rsI2iqlTLdxm0cELW2/xIPm/GDEqs2XWQ2jSGVJIyZHKhDnZPg1 cx6bOg== Received: from mail-pl1-f197.google.com (mail-pl1-f197.google.com [209.85.214.197]) by mx0a-0031df01.pphosted.com (PPS) with ESMTPS id 4f9c6a91wk-1 (version=TLSv1.3 cipher=TLS_AES_128_GCM_SHA256 bits=128 verify=NOT) for ; Wed, 08 Jul 2026 06:01:51 +0000 (GMT) Received: by mail-pl1-f197.google.com with SMTP id d9443c01a7336-2c354050c34so5973455ad.3 for ; Tue, 07 Jul 2026 23:01:51 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=oss.qualcomm.com; s=google; t=1783490511; x=1784095311; darn=vger.kernel.org; h=content-transfer-encoding:in-reply-to:from:content-language :references:cc:to:subject:user-agent:mime-version:date:message-id :from:to:cc:subject:date:message-id:reply-to; bh=7z8OET7rO6M3TRuXlj9b3aCKb7Zgt+kWJI0H9Bb/fuw=; b=BhLcDB+/nUMQxwCUnyzLEuPs7FSflmsBSsoM9jW3HozWpW0Xjtc98/cZzBFf8V4JK7 Jg0BUwmopPGm/PGjvqEuYk/s3tQUbOD0dEQncl/UutZKBY/PSTQWQH+fsa5oGMOrZhop EFPgmp1ErRKfiwRRseIe3Db+jD0UDF1F+lka/xVvto5aSEmGrCvOGtNWfCTukl1sO9E0 2XnsCumOxpdCC9BOuU4mCFY2meajAL39QTwU1cgCjRx4pR2C1IPe9Bspr9phWpeMqlwB oKTJsc5NuIKBbbJYktfCcN5vjqKY/nN0AjjaTWFqGjpdfY6lRYtlrNvmcsD37rK15pGX RI8w== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1783490511; x=1784095311; h=content-transfer-encoding:in-reply-to:from:content-language :references:cc:to:subject:user-agent:mime-version:date:message-id :x-gm-gg:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=7z8OET7rO6M3TRuXlj9b3aCKb7Zgt+kWJI0H9Bb/fuw=; b=mQEP9mnVTC/05lka+gojPt8qzdT3MOQPK6PDSJ6ip6ekYNTTVsxZ+oQpu/vbxL/MSX gY5IIxHqAK+PuYCc5aXbYNj2N3I0Lzd1b5Q/uWUqmNNgBpUPcQyy+yGQR+XxtKIapoBZ Tb3dWSIr9WsiOkiAjynPJxjVzgdRO4eQxPlVi01WnO1+G8jwM0Q+h0FqFTz5DONSdw+c F0FHv8mRaJXFKleZYXSoN70x7VQp080f/QiJGr/sgMYRqHK/7b/18WwpVJz/3p8+3sD1 GyGEywzUc94WKPVeUsZSgSY2t3WN8oT7dX9xouXvixKZVOOxkstXQUuJ/4OFoJt9HgFe bkfw== X-Forwarded-Encrypted: i=1; AHgh+RpkUPa36KykKOE36GQvU2b9n7ajrYCTLxZdW1366fLKD25uB92NDS+MV54H6LiXGySw6puwEiEPbzQDaqI=@vger.kernel.org X-Gm-Message-State: AOJu0Yz72hd5wj13Uj5ZKYJpjAociHc96VfJw8zRltEwBvfCuBAukDa9 wQuVUoyjQXXqnZRYy35oCd6iCBJ8XGNTgR+OInR5i50Ky0cH2aUWf91u0XSepyx21rJ8GZc1m3W hS/sqeEDcKkxbAnWQI3PC3xpl/ZnCQtjelY/NYxBewKvBubuBxaQkbohhoIhrsqit6sc5EqWXHQ == X-Gm-Gg: AfdE7cm6Q5n0CZJzL4fzSFJQKpAuLK6MDOuVqjEY4ipXmNzV/v8QR51f277g3aMBhx8 D1bcCEDRj9cXy38HHTfAB8rTisI2aBFmpUIYiNXbNtr+HINfkVkfFJkUnAQGK6JKOU4K/qCqxEq 7xe8BkL82nwzkQJ4kNMMx4KfNTF92VjOaNujLTIb15OGfM5nWREA6RLHlIa66rXQPhmKZQlYfmd xvnTOUvHVY7Ql/LPy5E90FCFA6/xy2xkVRliq2aBpjku8BpZbxY3nWaS0V5dzvDaAl5d5WCaplf sYsysQNt+0ctt4K9pvFZ5IplJ9a1Ma/3a/r3Sx3esv9lBD4TUYehtASLJgtaXY4HK5FX9mzWv+U NeVR6Nmy3pmLmKLV/v6A+WOU6ZV9YLbX8cUK+2hqWpJmg X-Received: by 2002:a17:902:f686:b0:2cc:741a:ff33 with SMTP id d9443c01a7336-2ccea5a4c8emr12224045ad.43.1783490510830; Tue, 07 Jul 2026 23:01:50 -0700 (PDT) X-Received: by 2002:a17:902:f686:b0:2cc:741a:ff33 with SMTP id d9443c01a7336-2ccea5a4c8emr12223645ad.43.1783490510210; Tue, 07 Jul 2026 23:01:50 -0700 (PDT) Received: from [192.168.1.86] ([206.83.113.14]) by smtp.gmail.com with ESMTPSA id d9443c01a7336-2ccc9d1ea74sm22247685ad.41.2026.07.07.23.01.46 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Tue, 07 Jul 2026 23:01:49 -0700 (PDT) Message-ID: Date: Wed, 8 Jul 2026 16:01:43 +1000 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: Re: [PATCH 1/6] tee: qcomtee: Track the object invocation context To: Harshal Dev , Jens Wiklander , Sumit Garg , Bjorn Andersson , Konrad Dybcio Cc: Basant Kumar , Apurupa Pattapu , Arun Kumar Neelakantam , op-tee@lists.trustedfirmware.org, linux-kernel@vger.kernel.org, linux-arm-msm@vger.kernel.org References: <20260707-qcom_uefisecapp_migrate_qcomtee-v1-0-f659cbd5d04c@oss.qualcomm.com> <20260707-qcom_uefisecapp_migrate_qcomtee-v1-1-f659cbd5d04c@oss.qualcomm.com> Content-Language: en-US From: Amirreza Zarrabi In-Reply-To: <20260707-qcom_uefisecapp_migrate_qcomtee-v1-1-f659cbd5d04c@oss.qualcomm.com> Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwNzA4MDA1NSBTYWx0ZWRfX6ngIzJQncOBI kskmTzS+qj2q/wc8TKrfkdNlGC46BvADlTuso5fW6QTYshUe3voYrJFSl7g78mU9VXx3YSOqRFA kNkvhYMHZztQF9l29xfH0MiaqxiNKpXdAjl5gmwy2I2kj8CE+eZ5IQrlwrH3QoYlFFAaO1CN2FV 25OayuRXyxzuVKfLc/1BuberrYQM7Quya1S7NY+K+IfjdhRg5+dB/Z0geKpyBT0SPaXIPGv94js EBGHpjxBKjl7kc6qf6MnaXR058otPxEVyLKhlgEwkvBXFZvG9WaBxQTEerCmKbRehS0tdzFmxqH 9oTvRG6azxWhAS+iBgmL6SJa0t0rMY4EPowNEq/gPE9JJZcbSK2PEbMqHD1ChqSZ7e9+h7ijnAg 7hkR0tIPBzW4Fn51RMV6qVwDwhnkE4huCU1E8y5UChpsV0uMWO0c5tRMjxwDgFTn5QG6nYNh/vh PI8P/rwuce0LBixszlw== X-Proofpoint-ORIG-GUID: 78DJl8NzF-SnCJwoT-2Iitmss6YJxY1e X-Proofpoint-Spam-Info: AW1haW4tMjYwNzA4MDA1NSBTYWx0ZWRfX7TKTMngiFYi0 zy7PKj5BVOwxUILKUktbv1oiQ9rHfVHuksRIWmN5xTzLnj04OvasHqSCjRWcvd1Z4I1KA2JGZIp Rw+E1SzgPFEGnQZfKA7LpUjjDPPU3Cw= X-Authority-Analysis: v=2.4 cv=UehhjqSN c=1 sm=1 tr=0 ts=6a4de7cf cx=c_pps a=cmESyDAEBpBGqyK7t0alAg==:117 a=+r7WnWcjNhrw7ahDJtTqLQ==:17 a=IkcTkHD0fZMA:10 a=RAioF0-LDSMA:10 a=s4-Qcg_JpJYA:10 a=VkNPw1HP01LnGYTKEx00:22 a=u7WPNUs3qKkmUXheDGA7:22 a=ZpdpYltYx_vBUK5n70dp:22 a=EUspDBNiAAAA:8 a=Xpymrd_i7WOtP7wGS5kA:9 a=QEXdDO2ut3YA:10 a=1OuFwYUASf3TG4hYMiVC:22 X-Proofpoint-GUID: 78DJl8NzF-SnCJwoT-2Iitmss6YJxY1e X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1143,Hydra:6.1.134,FMLib:17.12.100.49 definitions=2026-07-07_06,2026-07-06_02,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 malwarescore=0 suspectscore=0 spamscore=0 phishscore=0 adultscore=0 lowpriorityscore=0 clxscore=1015 priorityscore=1501 bulkscore=0 impostorscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2607080055 Hi Harshal, On 7/7/2026 4:11 PM, Harshal Dev wrote: > QCOMTEE needs to distinguish between object invocations arriving from > kernel clients and user-space clients in order to correctly marshal > UBUF parameters and decide whether certain operations should be permitted. > > Add a kernel_ctx flag to struct qcomtee_object_invoke_context to track > the context of object invocation. Objects invoked from the kernel-space > are expected to have the MSB of their 64-bit object-id set to indicate a > kernel context, whereas objects invoked from user-space should not set it. > To ensure this, we restrict the object-id space of user-space invoked > objects to 32-bits. This is in-line with QTEE expectation of 32-bit object > ids. > > Signed-off-by: Amirreza Zarrabi > Signed-off-by: Harshal Dev > --- > drivers/tee/qcomtee/call.c | 24 ++++++++++++++++++++++-- > drivers/tee/qcomtee/qcomtee.h | 6 ++++++ > drivers/tee/qcomtee/qcomtee_object.h | 8 ++++++-- > drivers/tee/tee_core.c | 4 ++++ > 4 files changed, 38 insertions(+), 4 deletions(-) > > diff --git a/drivers/tee/qcomtee/call.c b/drivers/tee/qcomtee/call.c > index 0efc5646242a..a74a54d67b06 100644 > --- a/drivers/tee/qcomtee/call.c > +++ b/drivers/tee/qcomtee/call.c > @@ -397,11 +397,31 @@ static int qcomtee_object_invoke(struct tee_context *ctx, > { > struct qcomtee_context_data *ctxdata = ctx->data; > struct qcomtee_object *object; > + bool kernel_ctx = false; > int i, ret, result; > > if (qcomtee_params_check(params, arg->num_params)) > return -EINVAL; > > + /* Obtain the invocation context information from the MSB of the object > + * `id` field. > + */ > + kernel_ctx = QCOMTEE_GET_CLIENT_CTX(arg->id); > + /* User-space identifies a NULL object via a 32-bit TEE_OBJREF_NULL id, whereas > + * the kernel uses as 64-bit object-id. Hence, we check for a NULL object by > + * sign-extending the object-id to 64 bits. If user-space is indeed invoking a > + * NULL object we must extend the object-id to 64-bits from here on so that > + * QCOMTEE can recognize it. > + */ > + if (!kernel_ctx && ((s64)(s32)arg->id) == TEE_OBJREF_NULL) > + arg->id = TEE_OBJREF_NULL; Does it need to be MSB -- why bit 63? the object ID supported by QTEE is 32-bit anyway. Let's mask the upper 32-bit and do something like kernel_ctx = !!upper_32_bits(id). What do you think? > + > + /* If the object being invoked is not NULL, drop the MSB from the `id` field to > + * obtain the actual object-id. > + */ > + if (arg->id != TEE_OBJREF_NULL) > + arg->id = QCOMTEE_SANITIZE_OBJ_ID(arg->id); > + > /* First, handle reserved operations: */ > if (arg->op == QCOMTEE_MSG_OBJECT_OP_RELEASE) { > del_qtee_object(arg->id, ctxdata); > @@ -411,7 +431,7 @@ static int qcomtee_object_invoke(struct tee_context *ctx, > > /* Otherwise, invoke a QTEE object: */ > struct qcomtee_object_invoke_ctx *oic __free(kfree) = > - qcomtee_object_invoke_ctx_alloc(ctx); > + qcomtee_object_invoke_ctx_alloc(ctx, kernel_ctx); > if (!oic) > return -ENOMEM; > > @@ -648,7 +668,7 @@ static void qcomtee_get_qtee_feature_list(struct tee_context *ctx, u32 id, > int result; > > struct qcomtee_object_invoke_ctx *oic __free(kfree) = > - qcomtee_object_invoke_ctx_alloc(ctx); > + qcomtee_object_invoke_ctx_alloc(ctx, true); > if (!oic) > return; > > diff --git a/drivers/tee/qcomtee/qcomtee.h b/drivers/tee/qcomtee/qcomtee.h > index f39bf63fd1c2..5d292a2ff83d 100644 > --- a/drivers/tee/qcomtee/qcomtee.h > +++ b/drivers/tee/qcomtee/qcomtee.h > @@ -17,6 +17,12 @@ > #define QCOMTEE_OBJREF_FLAG_USER BIT(1) > #define QCOMTEE_OBJREF_FLAG_MEM BIT(2) > > +/* The MSB of the object_id field indicates whether the client is invoking the > + * object from user context or kernel context. > + */ > +#define QCOMTEE_GET_CLIENT_CTX(x) (((x) >> 63) & 1U) > +#define QCOMTEE_SANITIZE_OBJ_ID(x) ((x) & (BIT(63) - 1)) > + > /** > * struct qcomtee - Main service struct. > * @teedev: client device. > diff --git a/drivers/tee/qcomtee/qcomtee_object.h b/drivers/tee/qcomtee/qcomtee_object.h > index 8b4401ecad48..2528d07e4576 100644 > --- a/drivers/tee/qcomtee/qcomtee_object.h > +++ b/drivers/tee/qcomtee/qcomtee_object.h > @@ -146,6 +146,7 @@ static inline int qcomtee_args_len(struct qcomtee_arg *args) > * struct qcomtee_object_invoke_ctx - QTEE context for object invocation. > * @ctx: TEE context for this invocation. > * @flags: flags for the invocation context. > + * @kernel_ctx: flag that indicates this context is owned by a kernel client. > * @errno: error code for the invocation. > * @object: current object invoked in this callback context. > * @u: array of arguments for the current invocation (+1 for ending arg). > @@ -158,6 +159,7 @@ static inline int qcomtee_args_len(struct qcomtee_arg *args) > struct qcomtee_object_invoke_ctx { > struct tee_context *ctx; > unsigned long flags; > + bool kernel_ctx; > int errno; > > struct qcomtee_object *object; > @@ -172,13 +174,15 @@ struct qcomtee_object_invoke_ctx { > }; > > static inline struct qcomtee_object_invoke_ctx * > -qcomtee_object_invoke_ctx_alloc(struct tee_context *ctx) > +qcomtee_object_invoke_ctx_alloc(struct tee_context *ctx, bool kernel_ctx) > { > struct qcomtee_object_invoke_ctx *oic; > > oic = kzalloc_obj(*oic); > - if (oic) > + if (oic) { > oic->ctx = ctx; > + oic->kernel_ctx = kernel_ctx; > + } > return oic; > } > > diff --git a/drivers/tee/tee_core.c b/drivers/tee/tee_core.c > index ef9642d72672..7f986d7fb47f 100644 > --- a/drivers/tee/tee_core.c > +++ b/drivers/tee/tee_core.c > @@ -706,6 +706,10 @@ static int tee_ioctl_object_invoke(struct tee_context *ctx, > goto out; > } > > + /* Userspace object-ids are restricted to 32-bits. */ > + if (arg.id > U32_MAX) > + return -EINVAL; > + This change belongs to tee SS, move it to a separate commit with appropriate message. > rc = ctx->teedev->desc->ops->object_invoke_func(ctx, &arg, params); > if (rc) > goto out; > Regards, Amir