U-Boot Archive on lore.kernel.org
 help / color / mirror / Atom feed
From: Jens Wiklander <jens.wiklander@linaro.org>
To: u-boot@lists.denx.de
Subject: [U-Boot] [PATCH v2 14/15] tee: optee: support AVB trusted application
Date: Thu, 23 Aug 2018 12:43:33 +0200	[thread overview]
Message-ID: <20180823104334.16083-15-jens.wiklander@linaro.org> (raw)
In-Reply-To: <20180823104334.16083-1-jens.wiklander@linaro.org>

Adds configuration option OPTEE_TA_AVB and a header file describing the
interface to the AVB trusted application provided by OP-TEE.

Tested-by: Igor Opaniuk <igor.opaniuk@linaro.org>
Reviewed-by: Igor Opaniuk <igor.opaniuk@linaro.org>
Signed-off-by: Jens Wiklander <jens.wiklander@linaro.org>
---
 MAINTAINERS                |  1 +
 drivers/tee/optee/Kconfig  | 16 +++++++++++++
 include/tee.h              |  7 ++++++
 include/tee/optee_ta_avb.h | 48 ++++++++++++++++++++++++++++++++++++++
 4 files changed, 72 insertions(+)
 create mode 100644 include/tee/optee_ta_avb.h

diff --git a/MAINTAINERS b/MAINTAINERS
index 7458c606ee92..cb36c45d74ea 100644
--- a/MAINTAINERS
+++ b/MAINTAINERS
@@ -576,6 +576,7 @@ M:	Jens Wiklander <jens.wiklander@linaro.org>
 S:	Maintained
 F:	drivers/tee/
 F:	include/tee.h
+F:	include/tee/
 
 UBI
 M:	Kyungmin Park <kmpark@infradead.org>
diff --git a/drivers/tee/optee/Kconfig b/drivers/tee/optee/Kconfig
index 8f7ebe161111..a5dc08439629 100644
--- a/drivers/tee/optee/Kconfig
+++ b/drivers/tee/optee/Kconfig
@@ -5,3 +5,19 @@ config OPTEE
 	help
 	  This implements the OP-TEE Trusted Execution Environment (TEE)
 	  driver.
+
+if OPTEE
+
+menu "OP-TEE options"
+
+config OPTEE_TA_AVB
+	bool "Support AVB TA"
+	default y
+	help
+	  Enables support for the AVB Trusted Application (TA) in OP-TEE.
+	  The TA can support the "avb" subcommands "read_rb", "write"rb"
+	  and "is_unlocked".
+
+endmenu
+
+endif
diff --git a/include/tee.h b/include/tee.h
index 3e6771123ef0..b851d718d32f 100644
--- a/include/tee.h
+++ b/include/tee.h
@@ -48,6 +48,13 @@
 
 #define TEE_ORIGIN_COMMS		0x00000002
 
+struct tee_optee_ta_uuid {
+	u32 time_low;
+	u16 time_mid;
+	u16 time_hi_and_version;
+	u8 clock_seq_and_node[8];
+};
+
 /**
  * struct tee_shm - memory shared with the TEE
  * @dev:	The TEE device
diff --git a/include/tee/optee_ta_avb.h b/include/tee/optee_ta_avb.h
new file mode 100644
index 000000000000..0e1da084e09d
--- /dev/null
+++ b/include/tee/optee_ta_avb.h
@@ -0,0 +1,48 @@
+/* SPDX-License-Identifier: BSD-2-Clause */
+/* Copyright (c) 2018, Linaro Limited */
+
+#ifndef __TA_AVB_H
+#define __TA_AVB_H
+
+#define TA_AVB_UUID { 0x023f8f1a, 0x292a, 0x432b, \
+		      { 0x8f, 0xc4, 0xde, 0x84, 0x71, 0x35, 0x80, 0x67 } }
+
+#define TA_AVB_MAX_ROLLBACK_LOCATIONS	256
+
+/*
+ * Gets the rollback index corresponding to the given rollback index slot.
+ *
+ * in	params[0].value.a:	rollback index slot
+ * out	params[1].value.a:	upper 32 bits of rollback index
+ * out	params[1].value.b:	lower 32 bits of rollback index
+ */
+#define TA_AVB_CMD_READ_ROLLBACK_INDEX	0
+
+/*
+ * Updates the rollback index corresponding to the given rollback index slot.
+ *
+ * Will refuse to update a slot with a lower value.
+ *
+ * in	params[0].value.a:	rollback index slot
+ * in	params[1].value.a:	upper 32 bits of rollback index
+ * in	params[1].value.b:	lower 32 bits of rollback index
+ */
+#define TA_AVB_CMD_WRITE_ROLLBACK_INDEX	1
+
+/*
+ * Gets the lock state of the device.
+ *
+ * out	params[0].value.a:	lock state
+ */
+#define TA_AVB_CMD_READ_LOCK_STATE	2
+
+/*
+ * Sets the lock state of the device.
+ *
+ * If the lock state is changed all rollback slots will be reset to 0
+ *
+ * in	params[0].value.a:	lock state
+ */
+#define TA_AVB_CMD_WRITE_LOCK_STATE	3
+
+#endif /*__TA_AVB_H*/
-- 
2.17.1

  parent reply	other threads:[~2018-08-23 10:43 UTC|newest]

Thread overview: 38+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2018-08-23 10:43 [U-Boot] [PATCH v2 00/15] AVB using OP-TEE Jens Wiklander
2018-08-23 10:43 ` [U-Boot] [PATCH v2 01/15] dm: fdt: scan for devices under /firmware too Jens Wiklander
2018-08-30  0:28   ` Simon Glass
2020-01-07  8:49   ` Michal Simek
2020-01-08  9:44     ` Jens Wiklander
2018-08-23 10:43 ` [U-Boot] [PATCH v2 02/15] cmd: avb read_rb: print rb_idx in hexadecimal Jens Wiklander
2018-08-30  0:28   ` Simon Glass
2018-08-23 10:43 ` [U-Boot] [PATCH v2 03/15] cmd: avb: print error message if command fails Jens Wiklander
2018-08-30  0:28   ` Simon Glass
2018-08-23 10:43 ` [U-Boot] [PATCH v2 04/15] mmc: rpmb: add mmc_rpmb_route_frames() Jens Wiklander
2018-08-23 10:43 ` [U-Boot] [PATCH v2 05/15] Add UCLASS_TEE for Trusted Execution Environment Jens Wiklander
2018-08-30  0:28   ` Simon Glass
2018-08-30 13:16     ` Jens Wiklander
2018-08-23 10:43 ` [U-Boot] [PATCH v2 06/15] dt/bindings: add bindings for optee Jens Wiklander
2018-08-23 10:43 ` [U-Boot] [PATCH v2 07/15] tee: add OP-TEE driver Jens Wiklander
2018-08-30  0:28   ` Simon Glass
2018-08-31  7:02     ` Jens Wiklander
2018-08-23 10:43 ` [U-Boot] [PATCH v2 08/15] Documentation: tee uclass and op-tee driver Jens Wiklander
2018-08-30  0:28   ` Simon Glass
2018-08-31  8:04     ` Jens Wiklander
2018-08-23 10:43 ` [U-Boot] [PATCH v2 09/15] test: tee: test TEE uclass Jens Wiklander
2018-08-30  0:28   ` Simon Glass
2018-08-23 10:43 ` [U-Boot] [PATCH v2 10/15] sandbox: dt: add sandbox_tee node Jens Wiklander
2018-08-30  0:28   ` Simon Glass
2018-08-31  8:06     ` Jens Wiklander
2018-08-23 10:43 ` [U-Boot] [PATCH v2 11/15] configs: sandbox: enable CONFIG_TEE (TEE uclass) Jens Wiklander
2018-08-30  0:29   ` Simon Glass
2018-08-31  8:08     ` Jens Wiklander
2018-08-23 10:43 ` [U-Boot] [PATCH v2 12/15] arm: dt: hikey: Add optee node Jens Wiklander
2018-08-30  0:29   ` Simon Glass
2018-08-23 10:43 ` [U-Boot] [PATCH v2 13/15] optee: support routing of rpmb data frames to mmc Jens Wiklander
2018-08-30  0:29   ` Simon Glass
2018-08-30 14:41     ` Jens Wiklander
2018-08-23 10:43 ` Jens Wiklander [this message]
2018-08-30  0:29   ` [U-Boot] [PATCH v2 14/15] tee: optee: support AVB trusted application Simon Glass
2018-08-31 12:10     ` Jens Wiklander
2018-09-26  5:41       ` Simon Glass
2018-08-23 10:43 ` [U-Boot] [PATCH v2 15/15] avb_verify: support using OP-TEE TA AVB Jens Wiklander

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20180823104334.16083-15-jens.wiklander@linaro.org \
    --to=jens.wiklander@linaro.org \
    --cc=u-boot@lists.denx.de \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox