From: Yu-Chien Peter Lin <peter.lin@sifive.com>
To: Pawandeep Oza <pawandeep.oza@oss.qualcomm.com>
Cc: opensbi@lists.infradead.org, zong.li@sifive.com,
greentime.hu@sifive.com, anup@brainfault.org, scott@riscstar.com,
conor@kernel.org, dave.patel@riscstar.com,
raymond.mao@riscstar.com, robin.randhawa@sifive.com,
samuel.holland@sifive.com
Subject: Re: [RFC PATCH 04/12] lib: sbi_hart: lock mwid CSR for RoT immutability
Date: Mon, 20 Jul 2026 15:36:51 +0800 [thread overview]
Message-ID: <al3QE++JPwPBB9KJ@plin-1878> (raw)
In-Reply-To: <CAAVgOkK0ccb2L2SGtx-LFRhjt83t9jN-e7AmCH0S_do-=yX-0Q@mail.gmail.com>
On Mon, Jul 13, 2026 at 02:28:50PM -0700, Pawandeep Oza wrote:
> On Fri, Jun 26, 2026 at 3:16 AM Yu-Chien Peter Lin <peter.lin@sifive.com> wrote:
> >
> > Lock the M-mode World ID (mwid) CSR during hart re-initialization to
> > enforce immutability of the WID established by the root-of-trust.
> >
> > OpenSBI does not assign the WID value itself; it only sets MWID_LOCK
> > to freeze the value established by prior RoT stage. The MWID_LOCK bit
> > at XLEN-1 is sticky and makes the CSR read-only until reset, enforcing
> > a temporal security boundary per the RISC-V Worlds specification.
> >
> > Signed-off-by: Yu-Chien Peter Lin <peter.lin@sifive.com>
> > ---
> > lib/sbi/sbi_hart.c | 7 +++++++
> > 1 file changed, 7 insertions(+)
> >
> > diff --git a/lib/sbi/sbi_hart.c b/lib/sbi/sbi_hart.c
> > index cb0c66ea..4fbe46d7 100644
> > --- a/lib/sbi/sbi_hart.c
> > +++ b/lib/sbi/sbi_hart.c
> > @@ -804,6 +804,13 @@ int sbi_hart_reinit(struct sbi_scratch *scratch)
> > if (rc)
> > return rc;
> >
> > + /*
> > + * Assume MWID is restored by root-of-trust M-mode in previous
> > + * stage. Lock mwid so RoT-defined WID remains immutable.
> > + */
> > + if (sbi_hart_has_extension(scratch, SBI_HART_EXT_SMWID))
> > + csr_set(CSR_MWID, MWID_LOCK);
> At minimum, before locking, read back CSR_MWID & ~MWID_LOCK and verify
> it matches hf->pmwid. If they don't match, this is a fatal security
> error and sbi_panic() is appropriate
In this patchset, OpenSBI trusts that RoT M-mode has set mwid correctly
in the previous boot stage. The early-boot M-mode may set mwid to any
value (within pmwidlist if exists) when unlocked on reset, independent
of DT's riscv,pmwid (which describes the reset default, not a mandatory
final value). Adding a panic would incorrectly treat RoT's legitimate
WID selection as a security error. Am I missing something?
Thanks,
Peter Lin
> > +
> > return 0;
> > }
> >
> > --
> > 2.43.7
> >
> >
> > --
> > opensbi mailing list
> > opensbi@lists.infradead.org
> > http://lists.infradead.org/mailman/listinfo/opensbi
--
opensbi mailing list
opensbi@lists.infradead.org
http://lists.infradead.org/mailman/listinfo/opensbi
next prev parent reply other threads:[~2026-07-20 7:37 UTC|newest]
Thread overview: 36+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-06-26 10:14 [RFC PATCH 00/12] Add RISC-V Worlds ISA support to OpenSBI Yu-Chien Peter Lin
2026-06-26 10:14 ` [RFC PATCH 01/12] lib: sbi_hart: detect RISC-V Worlds ISA extensions Yu-Chien Peter Lin
2026-07-13 20:58 ` Pawandeep Oza
2026-07-20 3:14 ` Yu-Chien Peter Lin
2026-06-26 10:14 ` [RFC PATCH 02/12] lib: utils: fdt_helper: parse RISC-V Worlds DT properties Yu-Chien Peter Lin
2026-07-09 0:36 ` Pawandeep Oza
2026-07-09 0:42 ` Pawandeep Oza
2026-07-13 21:13 ` Pawandeep Oza
2026-07-20 6:41 ` Yu-Chien Peter Lin
2026-07-20 5:55 ` Yu-Chien Peter Lin
2026-07-20 3:29 ` Yu-Chien Peter Lin
2026-06-26 10:14 ` [RFC PATCH 03/12] lib: sbi_hart: enforce riscv,pmwid for Worlds ISA Yu-Chien Peter Lin
2026-07-13 21:26 ` Pawandeep Oza
2026-07-20 7:01 ` Yu-Chien Peter Lin
2026-06-26 10:14 ` [RFC PATCH 04/12] lib: sbi_hart: lock mwid CSR for RoT immutability Yu-Chien Peter Lin
2026-07-13 21:28 ` Pawandeep Oza
2026-07-20 7:36 ` Yu-Chien Peter Lin [this message]
2026-06-26 10:14 ` [RFC PATCH 05/12] include: sbi_domain: add Worlds WID fields Yu-Chien Peter Lin
2026-07-13 21:52 ` Pawandeep Oza
2026-07-20 7:55 ` Yu-Chien Peter Lin
2026-06-26 10:14 ` [RFC PATCH 06/12] include: sbi_types: add PRIx64 format macro Yu-Chien Peter Lin
2026-06-26 10:14 ` [RFC PATCH 07/12] lib: sbi_domain: print World ID config at boot Yu-Chien Peter Lin
2026-07-13 23:48 ` Pawandeep Oza
2026-07-20 8:24 ` Yu-Chien Peter Lin
2026-06-26 10:14 ` [RFC PATCH 08/12] lib: sbi_init: print M-mode World ID " Yu-Chien Peter Lin
2026-06-26 10:14 ` [RFC PATCH 09/12] platform: generic: parse root domain WID config from DT Yu-Chien Peter Lin
2026-07-09 0:39 ` Pawandeep Oza
2026-07-20 8:54 ` Yu-Chien Peter Lin
2026-07-20 10:39 ` Anup Patel
2026-07-20 21:14 ` Pawandeep Oza
2026-07-21 6:24 ` Yu-Chien Peter Lin
2026-06-26 10:14 ` [RFC PATCH 10/12] lib: utils: fdt_domain: parse per-domain WID properties Yu-Chien Peter Lin
2026-06-26 10:14 ` [RFC PATCH 11/12] lib: sbi_domain: add Worlds CSR config on domain entry Yu-Chien Peter Lin
2026-06-26 10:14 ` [RFC PATCH 12/12] docs: add RISC-V Worlds next-wid/next-widlist DT properties Yu-Chien Peter Lin
2026-07-09 0:44 ` [RFC PATCH 00/12] Add RISC-V Worlds ISA support to OpenSBI Pawandeep Oza
2026-07-14 0:33 ` Pawandeep Oza
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=al3QE++JPwPBB9KJ@plin-1878 \
--to=peter.lin@sifive.com \
--cc=anup@brainfault.org \
--cc=conor@kernel.org \
--cc=dave.patel@riscstar.com \
--cc=greentime.hu@sifive.com \
--cc=opensbi@lists.infradead.org \
--cc=pawandeep.oza@oss.qualcomm.com \
--cc=raymond.mao@riscstar.com \
--cc=robin.randhawa@sifive.com \
--cc=samuel.holland@sifive.com \
--cc=scott@riscstar.com \
--cc=zong.li@sifive.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox