From: Sumit Garg <sumit.garg@kernel.org>
To: Mathieu Poirier <mathieu.poirier@linaro.org>
Cc: andersson@kernel.org, konradybcio@kernel.org,
linux-arm-msm@vger.kernel.org, devicetree@vger.kernel.org,
dri-devel@lists.freedesktop.org, freedreno@lists.freedesktop.org,
linux-media@vger.kernel.org, netdev@vger.kernel.org,
linux-wireless@vger.kernel.org, ath12k@lists.infradead.org,
linux-remoteproc@vger.kernel.org, robh@kernel.org,
krzk+dt@kernel.org, conor+dt@kernel.org,
robin.clark@oss.qualcomm.com, sean@poorly.run,
akhilpo@oss.qualcomm.com, lumag@kernel.org,
abhinav.kumar@linux.dev, jesszhan0024@gmail.com,
marijn.suijten@somainline.org, airlied@gmail.com,
simona@ffwll.ch, vikash.garodia@oss.qualcomm.com, bod@kernel.org,
mchehab@kernel.org, elder@kernel.org, andrew+netdev@lunn.ch,
davem@davemloft.net, edumazet@google.com, kuba@kernel.org,
pabeni@redhat.com, jjohnson@kernel.org,
trilokkumar.soni@oss.qualcomm.com, mukesh.ojha@oss.qualcomm.com,
pavan.kondeti@oss.qualcomm.com, jorge.ramirez@oss.qualcomm.com,
tonyh@qti.qualcomm.com, vignesh.viswanathan@oss.qualcomm.com,
srinivas.kandagatla@oss.qualcomm.com,
amirreza.zarrabi@oss.qualcomm.com, jenswi@kernel.org,
op-tee@lists.trustedfirmware.org, apurupa@qti.qualcomm.com,
skare@qti.qualcomm.com, linux-kernel@vger.kernel.org,
Sumit Garg <sumit.garg@oss.qualcomm.com>
Subject: Re: [PATCH v9 00/14] firmware: qcom: Add OP-TEE PAS service support
Date: Fri, 3 Jul 2026 09:43:19 +0530 [thread overview]
Message-ID: <akc23w16MeSu8ODb@sumit-xelite> (raw)
In-Reply-To: <CANLsYkyFJ+CbUJpwWAy28KHvmNz6rJRtM5KrEzHjyAha-7grTQ@mail.gmail.com>
Hey Mathieu,
On Thu, Jul 02, 2026 at 01:14:03PM -0600, Mathieu Poirier wrote:
> Hey Sumit - nice hearing from you...
>
Good to hear from you too.
> Is there some kind of overarching design harminisation between what
> you are proposing here and what Arnaud posted back in April [1] ?
The design here for remoteproc bringup on Qcom platforms for OP-TEE is
carried forward from whatever existed earlier with QTEE. This patch-set
just adds OP-TEE backend and replicate the same co-processor bringup
design as QTEE.
Co-processor bringup using a TEE is very different on Qcom platforms as
compared to what ST did. The image formats for Qcom are custom ones
using MBN format over ELF for which the MDT loader exists in the kernel
only. Similarly the firmware image authentication is very tightly
coupled with Qcom secure boot chain.
The ST framework rather uses an ELF loader in OP-TEE for image loading
and have an authentication mechanism similar to TAs. Also, the OP-TEE
ABI is altogether different from the PAS ABI that Qcom has for the TEE.
-Sumit
>
> [1]. https://lists.trustedfirmware.org/archives/list/op-tee@lists.trustedfirmware.org/thread/VMKTRATYUFWL2TP7NHN5KJ37MSVZZMPK/
>
> On Thu, 2 Jul 2026 at 05:59, Sumit Garg <sumit.garg@kernel.org> wrote:
> >
> > From: Sumit Garg <sumit.garg@oss.qualcomm.com>
> >
> > Qcom platforms has the legacy of using non-standard SCM calls
> > splintered over the various kernel drivers. These SCM calls aren't
> > compliant with the standard SMC calling conventions which is a
> > prerequisite to enable migration to the FF-A specifications from Arm.
> >
> > OP-TEE as an alternative trusted OS to Qualcomm TEE (QTEE) can't
> > support these non-standard SCM calls. And even for newer architectures
> > using S-EL2 with Hafnium support, QTEE won't be able to support SCM
> > calls either with FF-A requirements coming in. And with both OP-TEE
> > and QTEE drivers well integrated in the TEE subsystem, it makes further
> > sense to reuse the TEE bus client drivers infrastructure.
> >
> > The added benefit of TEE bus infrastructure is that there is support
> > for discoverable/enumerable services. With that client drivers don't
> > have to manually invoke a special SCM call to know the service status.
> >
> > So enable the generic Peripheral Authentication Service (PAS) provided
> > by the firmware. It acts as the common layer with different TZ
> > backends plugged in whether it's an SCM implementation or a proper
> > TEE bus based PAS service implementation.
> >
> > The TEE PAS service ABI is designed to be extensible with additional API
> > as PTA_QCOM_PAS_CAPABILITIES. This allows to accommodate any future
> > extensions of the PAS service needed while still maintaining backwards
> > compatibility.
> >
> > Currently OP-TEE support is being added to provide the backend PAS
> > service implementation which can be found as part of this PR [1].
> > This implementation has been tested on Kodiak/RB3Gen2 and lemans
> > EVK boards. In addition to that WIN/IPQ targets tested OP-TEE with
> > this service too. Surely the backwards compatibility is maintained and
> > tested for SCM backend.
> >
> > Note that kernel PAS service support while running in EL2 is at parity
> > among OP-TEE vs QTEE. Especially the media (venus/iris) support depends
> > on proper IOMMU support being worked out on the PAS client end.
> >
> > Patch summary:
> > - Patch #1: adds generic PAS service.
> > - Patch #2: migrates SCM backend to generic PAS service.
> > - Patch #3: adds TEE/OP-TEE backend for generic PAS service.
> > - Patch #4-#12: migrates all client drivers to generic PAS service.
> > - Patch #13: drops legacy PAS SCM exported APIs.
> >
> > The patch-set is based on v7.2-rc1 and can be found in git tree
> > here [2].
> >
> > Merge strategy:
> >
> > It is expected due to APIs dependency, the entire patch-set to go via
> > the Qcom tree. All other subsystem maintainers, it will be great if I
> > can get acks for the corresponding subsystem patches.
> >
> > [1] https://github.com/OP-TEE/optee_os/pull/7721 (already merged)
> > [2] https://git.kernel.org/pub/scm/linux/kernel/git/sumit.garg/linux.git/log/?h=qcom-pas-v9
> >
> > ---
> > Changes in v9:
> > - Rebased to 7.2-rc1.
> > - Enable SCM backend similar to TEE if ARCH_QCOM is set.
> > - Address misc. comments from Konrad.
> > - Add checks for corner cases (although not reachable as per OP-TEE ABI)
> > reported by Shashiko on patch #3.
> > - Picked up review tags from Konrad.
> >
> > Changes in v8:
> > - Rebased on mainline tip (no functional changes).
> > - Now Lemans EVK is also tested to support OP-TEE PAS here:
> > https://github.com/OP-TEE/optee_os/pull/7845
> > - Drop Kodiak DT patch as it is carried independently by Mukesh here:
> > https://lore.kernel.org/lkml/20260624063952.2242702-1-mukesh.ojha@oss.qualcomm.com/
> > - Regarding Sashiko comments, I have already replied in v6 the ones that
> > don't apply but in v7 I got the same comments again. Specific context
> > reasoning which Shashiko ignores:
> > - ABI contract between Linux and TZ
> > - No support for multiple concurrent backends
> > - The TZ backend doesn’t detach during the entire boot cycle
> >
> > Changes in v7:
> > - Rebased to qcom tree (for-next branch) tip.
> > - Merged patch #5 and #7 due to build dependency.
> > - Disabled modem for kodiak EL2 as it isn't tested yet.
> > - Fix an issue found out by sashiko-bot for patch #4.
> >
> > Changes in v6:
> > - Rebased to v7.1-rc4 tag.
> > - Patch #14: fixed ret error print.
> > - Add Kconfig descriptions for PAS symbols such that they are visible
> > in menuconfig to update.
> >
> > Changes in v5:
> > - Incorporated misc. comments from Mukesh.
> > - Split up patch #11 into 2 to add an independent commit for passing
> > proper PAS ID to set_remote_state API.
> > - Picked up tags.
> >
> > Changes in v4:
> > - Incorporate misc. comments on patch #4.
> > - Picked up an ack for patch #10.
> > - Clarify in cover letter about state of media support.
> >
> > Changes in v3:
> > - Incorporated some style and misc. comments for patch #2, #3 and #4.
> > - Add QCOM_PAS Kconfig dependency for various subsystems.
> > - Switch from pseudo TA to proper TA invoke commands.
> >
> > Changes in v2:
> > - Fixed kernel doc warnings.
> > - Polish commit message and comments for patch #2.
> > - Pass proper PAS ID in set_remote_state API for media firmware drivers.
> > - Added Maintainer entry and dropped MODULE_AUTHOR.
> >
> > Sumit Garg (14):
> > firmware: qcom: Add a generic PAS service
> > firmware: qcom_scm: Migrate to generic PAS service
> > firmware: qcom: Add a PAS TEE service
> > remoteproc: qcom_q6v5_pas: Switch over to generic PAS TZ APIs
> > remoteproc: qcom_q6v5_mss: Switch to generic PAS TZ APIs
> > remoteproc: qcom_wcnss: Switch to generic PAS TZ APIs
> > remoteproc: qcom: Select QCOM_PAS generic service
> > drm/msm: Switch to generic PAS TZ APIs
> > media: qcom: Switch to generic PAS TZ APIs
> > media: qcom: Pass proper PAS ID to set_remote_state API
> > net: ipa: Switch to generic PAS TZ APIs
> > wifi: ath12k: Switch to generic PAS TZ APIs
> > firmware: qcom_scm: Remove SCM PAS wrappers
> > MAINTAINERS: Add maintainer entry for Qualcomm PAS TZ service
> >
> > MAINTAINERS | 9 +
> > drivers/firmware/qcom/Kconfig | 22 +-
> > drivers/firmware/qcom/Makefile | 2 +
> > drivers/firmware/qcom/qcom_pas.c | 299 +++++++++++
> > drivers/firmware/qcom/qcom_pas.h | 50 ++
> > drivers/firmware/qcom/qcom_pas_tee.c | 479 ++++++++++++++++++
> > drivers/firmware/qcom/qcom_scm.c | 302 ++++-------
> > drivers/gpu/drm/msm/Kconfig | 1 +
> > drivers/gpu/drm/msm/adreno/a5xx_gpu.c | 4 +-
> > drivers/gpu/drm/msm/adreno/adreno_gpu.c | 11 +-
> > drivers/media/platform/qcom/iris/Kconfig | 27 +-
> > .../media/platform/qcom/iris/iris_firmware.c | 9 +-
> > drivers/media/platform/qcom/venus/Kconfig | 1 +
> > drivers/media/platform/qcom/venus/firmware.c | 11 +-
> > drivers/net/ipa/Kconfig | 2 +-
> > drivers/net/ipa/ipa_main.c | 13 +-
> > drivers/net/wireless/ath/ath12k/Kconfig | 2 +-
> > drivers/net/wireless/ath/ath12k/ahb.c | 10 +-
> > drivers/remoteproc/Kconfig | 4 +-
> > drivers/remoteproc/qcom_q6v5_mss.c | 5 +-
> > drivers/remoteproc/qcom_q6v5_pas.c | 51 +-
> > drivers/remoteproc/qcom_wcnss.c | 12 +-
> > drivers/soc/qcom/mdt_loader.c | 12 +-
> > include/linux/firmware/qcom/qcom_pas.h | 43 ++
> > include/linux/firmware/qcom/qcom_scm.h | 29 --
> > include/linux/soc/qcom/mdt_loader.h | 6 +-
> > 26 files changed, 1095 insertions(+), 321 deletions(-)
> > create mode 100644 drivers/firmware/qcom/qcom_pas.c
> > create mode 100644 drivers/firmware/qcom/qcom_pas.h
> > create mode 100644 drivers/firmware/qcom/qcom_pas_tee.c
> > create mode 100644 include/linux/firmware/qcom/qcom_pas.h
> >
> > --
> > 2.53.0
> >
>
prev parent reply other threads:[~2026-07-03 4:13 UTC|newest]
Thread overview: 20+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-02 11:58 [PATCH v9 00/14] firmware: qcom: Add OP-TEE PAS service support Sumit Garg
2026-07-02 11:58 ` [PATCH v9 01/14] firmware: qcom: Add a generic PAS service Sumit Garg
2026-07-03 15:06 ` Konrad Dybcio
2026-07-02 11:58 ` [PATCH v9 02/14] firmware: qcom_scm: Migrate to " Sumit Garg
2026-07-02 11:58 ` [PATCH v9 03/14] firmware: qcom: Add a PAS TEE service Sumit Garg
2026-07-02 11:58 ` [PATCH v9 04/14] remoteproc: qcom_q6v5_pas: Switch over to generic PAS TZ APIs Sumit Garg
2026-07-02 11:58 ` [PATCH v9 05/14] remoteproc: qcom_q6v5_mss: Switch " Sumit Garg
2026-07-02 11:58 ` [PATCH v9 06/14] remoteproc: qcom_wcnss: " Sumit Garg
2026-07-02 11:58 ` [PATCH v9 07/14] remoteproc: qcom: Select QCOM_PAS generic service Sumit Garg
2026-07-02 11:58 ` [PATCH v9 08/14] drm/msm: Switch to generic PAS TZ APIs Sumit Garg
2026-07-02 11:58 ` [PATCH v9 09/14] media: qcom: " Sumit Garg
2026-07-02 11:58 ` [PATCH v9 10/14] media: qcom: Pass proper PAS ID to set_remote_state API Sumit Garg
2026-07-02 12:23 ` Konrad Dybcio
2026-07-02 11:58 ` [PATCH v9 11/14] net: ipa: Switch to generic PAS TZ APIs Sumit Garg
2026-07-02 11:58 ` [PATCH v9 12/14] wifi: ath12k: " Sumit Garg
2026-07-02 12:34 ` Konrad Dybcio
2026-07-02 11:58 ` [PATCH v9 13/14] firmware: qcom_scm: Remove SCM PAS wrappers Sumit Garg
2026-07-02 11:58 ` [PATCH v9 14/14] MAINTAINERS: Add maintainer entry for Qualcomm PAS TZ service Sumit Garg
2026-07-02 19:14 ` [PATCH v9 00/14] firmware: qcom: Add OP-TEE PAS service support Mathieu Poirier
2026-07-03 4:13 ` Sumit Garg [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=akc23w16MeSu8ODb@sumit-xelite \
--to=sumit.garg@kernel.org \
--cc=abhinav.kumar@linux.dev \
--cc=airlied@gmail.com \
--cc=akhilpo@oss.qualcomm.com \
--cc=amirreza.zarrabi@oss.qualcomm.com \
--cc=andersson@kernel.org \
--cc=andrew+netdev@lunn.ch \
--cc=apurupa@qti.qualcomm.com \
--cc=ath12k@lists.infradead.org \
--cc=bod@kernel.org \
--cc=conor+dt@kernel.org \
--cc=davem@davemloft.net \
--cc=devicetree@vger.kernel.org \
--cc=dri-devel@lists.freedesktop.org \
--cc=edumazet@google.com \
--cc=elder@kernel.org \
--cc=freedreno@lists.freedesktop.org \
--cc=jenswi@kernel.org \
--cc=jesszhan0024@gmail.com \
--cc=jjohnson@kernel.org \
--cc=jorge.ramirez@oss.qualcomm.com \
--cc=konradybcio@kernel.org \
--cc=krzk+dt@kernel.org \
--cc=kuba@kernel.org \
--cc=linux-arm-msm@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-media@vger.kernel.org \
--cc=linux-remoteproc@vger.kernel.org \
--cc=linux-wireless@vger.kernel.org \
--cc=lumag@kernel.org \
--cc=marijn.suijten@somainline.org \
--cc=mathieu.poirier@linaro.org \
--cc=mchehab@kernel.org \
--cc=mukesh.ojha@oss.qualcomm.com \
--cc=netdev@vger.kernel.org \
--cc=op-tee@lists.trustedfirmware.org \
--cc=pabeni@redhat.com \
--cc=pavan.kondeti@oss.qualcomm.com \
--cc=robh@kernel.org \
--cc=robin.clark@oss.qualcomm.com \
--cc=sean@poorly.run \
--cc=simona@ffwll.ch \
--cc=skare@qti.qualcomm.com \
--cc=srinivas.kandagatla@oss.qualcomm.com \
--cc=sumit.garg@oss.qualcomm.com \
--cc=tonyh@qti.qualcomm.com \
--cc=trilokkumar.soni@oss.qualcomm.com \
--cc=vignesh.viswanathan@oss.qualcomm.com \
--cc=vikash.garodia@oss.qualcomm.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox