From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from CH1PR05CU001.outbound.protection.outlook.com (mail-northcentralusazon11010012.outbound.protection.outlook.com [52.101.193.12]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id DD61738F95B for ; Thu, 23 Jul 2026 05:28:03 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=fail smtp.client-ip=52.101.193.12 ARC-Seal:i=2; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784784486; cv=fail; b=ST1J+hm2Gx/C8T0rvZS06M8oXjI0U+zCfrMEXW5br8/LTbJeL4Y6MI7VEV+rZs0fATOcAtuty1VA+C50NLMzXS+prgfOsBVXny1CPfZ3t8OTzTW7fwGO2Il2j/9lrdiSMObEnI7aWYZF6X9dOaViMEI9L99GyWzVkkjdCCeadUM= ARC-Message-Signature:i=2; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784784486; c=relaxed/simple; bh=/JMc7d7Uwe2X4K3LctNWPVyJnN1S6fBV0b2PbpJgaH0=; h=Message-ID:Date:Cc:Subject:From:To:References:In-Reply-To: Content-Type:MIME-Version; b=GHTLQxdMJpqFZ96asGzSiSwmXTatue0P8P3QSc3/VfKrp2up4/jLP6x4TrwZLjFBjBkl8HFUSHmbr0W47SH9ws0viWxIREPgM4WV315T4w8IZ19s+0ibHtvk0TYtkyq0kqFEDNOs/WYBEhYu9gCRZRC1Lzgp61oDkTmNX2m3qw4= ARC-Authentication-Results:i=2; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=altera.com; spf=pass smtp.mailfrom=altera.com; dkim=pass (2048-bit key) header.d=altera.com header.i=@altera.com header.b=wQghcNpY; arc=fail smtp.client-ip=52.101.193.12 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=altera.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=altera.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=altera.com header.i=@altera.com header.b="wQghcNpY" ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=aapo9cphKzK4+SB58vbEoE3h6TLcVrC8l9JRTQuDU7hvnMJIgaCOxq0v+24H0ui/bAeA6SsClgcb2nKPzhZZuXnegmvE4yaWSZOBooL78iV7odIdHfjSEVDtX2+pCjIu5KBDYh6lYqulmB31jqUDN8FqR40CE9LQcrj5Sn9QxXY6AKmHyYrdpG2BLGDH/R8exYbp9WYOT2N+XlVY09kW0XcGYFsrk97fqiYOHCQHB7Ffu1cAide74jBoKkw9fD2+LimQOgSLBa33XN8m14dkRBaMIDSh3pOyIy8OTDFobFidftNeCKvV+pOdYXDUy7ZETBpkI9wzQibMcLHZmGKsBQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=6JnEP5UR9lEW3WDbDhHELLMZMnubc9M6fg6M/ii+Ai0=; b=XWmmNJqva9vfr+7lqyjyHgu6rqOAVUaU5YwYiZMUGrQ+ku0N0GvuDMxZhH+94A+xpHyXCOVMvFae3wqPgahmVMJp1HLmeOpeh0jRlrijQh9y6Ane692JyN7z9jcoPjQfeVHH/IlnivpJ6cFr/PwmTaATUpLUwWnGDHnW2hA8etvPA68PrGJZK7ptyTV30cQPFGhx1/VMsFvX/buapMo9/nMyrocKA9wsSCDi0+y4nFMQoEPOrfrJPAOaHxnGKbBjwslpb39Och4nDeC2Yq6qe/CvBmMJTq50b9ilo8dKe6X2hvSpy7N6L7Di26wnEDLWqOpfeIA+NoDFwMZKa+v5Bw== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=altera.com; dmarc=pass action=none header.from=altera.com; dkim=pass header.d=altera.com; arc=none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=altera.com; s=selector2; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=6JnEP5UR9lEW3WDbDhHELLMZMnubc9M6fg6M/ii+Ai0=; b=wQghcNpYxaDKwBAToGOraK0GIjvkTLAMFSd36oJEK/7Mo6WRSPuEaag3t0AKuT0nUChkGswf9jM5pR5Tzfj/q9L/GY896TimL92aFXINh2GSo45gFC9kCcKsju0OGCM6IOfcWUI42nAnqInCF1/JQFjKzf0sg+nVN+6fAJml0eLl1J2AnbOnvPUp6i/IM+ApglLhxk4v2aSEab+vAMqe4yFuoUVFA1dpcfK/Jg22L710bgHVfHM1YuswqE3XLfHEEt1cPxh9JCn0OLt7ihJsrocDk1M/J5iHSdlWTGYIx3B0QMzSmg0ISb0do7rDBfayxv5rYF6BnctvPiZY77OCWg== Authentication-Results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=altera.com; Received: from MW4PR03MB6555.namprd03.prod.outlook.com (2603:10b6:303:126::12) by IA6PR03MB846654.namprd03.prod.outlook.com (2603:10b6:208:5e8::15) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.245.10; Thu, 23 Jul 2026 05:28:01 +0000 Received: from MW4PR03MB6555.namprd03.prod.outlook.com ([fe80::c8e9:5e5d:afad:5eaa]) by MW4PR03MB6555.namprd03.prod.outlook.com ([fe80::c8e9:5e5d:afad:5eaa%3]) with mapi id 15.21.0245.010; Thu, 23 Jul 2026 05:28:01 +0000 Message-ID: <02ac2b9c-25af-4910-8eab-63d328844fb1@altera.com> Date: Thu, 23 Jul 2026 13:27:52 +0800 User-Agent: Mozilla Thunderbird Cc: muhammad.nazim.amirul.nazle.asmade@altera.com, tze.yee.ng@altera.com, chee.nouk.phoon@altera.com, genevieve.chan@altera.com, adrian.ho.yin.ng@altera.com Subject: Re: [PATCH v2 1/2] firmware: stratix10-svc: add FCS crypto-service commands for Agilex 5 From: Hang Suan Wang To: Greg Kroah-Hartman , Dinh Nguyen , linux-kernel@vger.kernel.org, "Michael S . Tsirkin" , Huacai Chen , Florian Fainelli , Chen-Yu Tsai References: <185cdbe74f2c66e0e73e5907d1a2f1d7859d0960.1783966717.git.hang.suan.wang@altera.com> Content-Language: en-US In-Reply-To: <185cdbe74f2c66e0e73e5907d1a2f1d7859d0960.1783966717.git.hang.suan.wang@altera.com> Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit X-ClientProxiedBy: SI2PR01CA0045.apcprd01.prod.exchangelabs.com (2603:1096:4:193::19) To MW4PR03MB6555.namprd03.prod.outlook.com (2603:10b6:303:126::12) Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-MS-PublicTrafficType: Email X-MS-TrafficTypeDiagnostic: MW4PR03MB6555:EE_|IA6PR03MB846654:EE_ X-MS-Office365-Filtering-Correlation-Id: 92de8d2a-40b4-42bf-6746-08dee87b293d X-MS-Exchange-AtpMessageProperties: SA X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam: BCL:0;ARA:13230040|1800799024|376014|23010399003|366016|6133799003|22082099003|18002099003|55112099003|3023799007|11063799006|56012099006|4143699003|5023799004|10067099003; X-Microsoft-Antispam-Message-Info: Lb7AOlLVk5kZhcI7RcqL/huvQcjwJPO7E7IJZ8r4jYYT+GdlrQtYpkhHqNiv9JfdPg7DULY8hsPVBx7+BANmX7af9+DOdNNE8sIAnuSSYdEF0SMZbBIIHVlJtHR9TW1JZCNFIbdyXyWBMhsajVVXjCQfZSSk69yRtbGnnNsAb6VZMauuGvH7dx5mCGDZlMO+s7jPa/SeD46k3fT0HxQh9hhJS3VbfodH5vaY8/ePqQmiE90pVO+8YobfWnzFpUOutzvPvNlESxdvi7X/vZhSSM5YLjGwO+iwaffLhCCq7Idna09C0uTZ/AZ7+rKBH0Mh6IxftqWo1qmHcbo7BMvR2TaaKR/jYWqOnTOUlwSAMMY03YCJqhEgezRHrAPsk5SZP5qYFV33zmmH0LhLAEhkpMhwXlIwNU70hhdD6cmKsVesRrIPc68sDjRKuKJFrqIaB7Ck4Le1FjU+CMnFnqMs0yBkCbolk15j2D+fNOh8FuR57PtD+RTjwRYZ4ylxnqzRPPJ/nVLNW4pGo2SjWXYUXnnwkJyE363ymGcrEYPvRd3XG2A5b5Lfx1RpRrVw3sMlkNB5hoiM2ttocvCBvUf5wo1edgV0w80Tv9xWz9imIq8= X-Forefront-Antispam-Report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:MW4PR03MB6555.namprd03.prod.outlook.com;PTR:;CAT:NONE;SFS:(13230040)(1800799024)(376014)(23010399003)(366016)(6133799003)(22082099003)(18002099003)(55112099003)(3023799007)(11063799006)(56012099006)(4143699003)(5023799004)(10067099003);DIR:OUT;SFP:1101; X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1 X-MS-Exchange-AntiSpam-MessageData-0: =?utf-8?B?Qll0dnZER0NCS2pkYTRRcWNaOXVOWlF1WjBHdmcvaVh4ZHNJWmxTQ1BVZ0pC?= =?utf-8?B?NTJVdHVMWHdhNVJpeWFnSlNkZEdpNVlxTVhYNytESldkMVZtNDgxTXh0UmFm?= =?utf-8?B?bHV5VEh0YkFMRTNpdUJvQ1c2b0lLdE53SGI0SjRYbm80dFNGclN5V2hTYW5O?= =?utf-8?B?UForYXFEdWViZExDRzJWd3kvKzFweUV0d0lPaHZwdGQ0Mk4yZm56SFh6c3Nz?= =?utf-8?B?TUpVWFd1UWpvUkJhbXNKbktoTnRUdTRweXhzd2piQ0dXUzFkbU9xZ1dQSzN5?= =?utf-8?B?MXZpeTZOcVkrMjVqODV0OHJ4VDk5Wmd3UmhReW1UVkJuYmVTaHdIcDhhcWQ4?= =?utf-8?B?TjZaUkhYb1gwa3graloraGRsUWkweTBJWUdXanVTdjljOFZVTWljV3lNNEpD?= =?utf-8?B?ZDhJbVVqV0w1NW9vdnhLNnlIYmVVVmN0d1RodzJUZmRlczV1NzI0em8xNnBm?= =?utf-8?B?ckdWaFovdDFMV0Jpa1Qwd29YTWdnc1htUnR4Y3cvWThvVEJISGhrZ3c0dWRO?= =?utf-8?B?TndBZ0dsbFF2MUMxZVdEYjJxc1E1T1JzOFcrTWxveFJIYUoza0dtd0dtYlE4?= =?utf-8?B?cXJYSzB0SEw5UnN6RFgveHVnQllma0pLdzhsSzBNUUROOWY3T2xLUU5BT29o?= =?utf-8?B?Q3NmQlJLaEZjemo3TnpCdnpqWkwzb0l4THIxdlNJbEtKd0FaaldlNUNUTFMx?= =?utf-8?B?RXlXeE1maTdtYTR3Wmd3WjB3ZWpiREJEVi9xL2hsYmxQak5qOGVFelUrRkJQ?= =?utf-8?B?U3JlaVFQcks0S2JtNCs4TElGQmhHOGRYSlJKQnNsTFI1ZGtrdzRBNGIxYzJy?= =?utf-8?B?Ni9pZnQ0RnNSMGJhSTQyNWt3Rk9WWDdQOWFjWDNoQjJFZ045MC83YlZ6cFhi?= =?utf-8?B?OUxmSSt0VDc4Rkg2T2tYMW42SDVpVU85M2dueWxDa0FLNm9xNDFkRkYvTjdi?= =?utf-8?B?S2tZZWFJcGFTQlJSclJSR0R5TDlBSjNEZm5zMTl2dU9OTytxRHlXdEROWHFL?= =?utf-8?B?LzZNZWlKU2dwVDJzbjZmbDcxZGlaR3drR1hlcEVEMGJSM042RnpORFNPRmpF?= =?utf-8?B?eEU1d1lCRnd2UFNLcHgvQ0RCcGNuYnpLbnRYcTA0eXlOa1BiTG5LaFdGKzNw?= =?utf-8?B?a3R6UCtwRG5JL1BwWThCY2RpTVNLRklEWjZGdElPcmYzRlZ6Y0RRa3ZQMXhR?= =?utf-8?B?Tnp1OU9LeGNtc2o1ZVJENk1CSmd0Y1I2aEo1aWd2UFBnWklBYzhLYWhpaUo1?= =?utf-8?B?bS9wYTE3YU52MmtMeXhtcEcwcHRGVmVlcWRMdXN4VUtpVjRaeHBGU0hHcXZ5?= =?utf-8?B?TXhYRG1haEdiSFpENEtYV0R6SFEwTGFFVTNBVk5Xa2FkTU1NQzlKaUNNVU8w?= =?utf-8?B?d3JNUnc2aktJeGFraHV4S2h2Q0E5VUhISWVVN2hJdk1GaVlQeGFSZ0svZnlX?= =?utf-8?B?S2hJbnFuK2R3MnFDQnZGc2U5MVZoWjhEOW8rRiszUnl1M1BwaXQyVnA1SEF5?= =?utf-8?B?UmNPeTRjSERwSGRWM3o2REQ1dGhiVWJrSzJCelBuVURlNklsVTN3YUIvZ3cy?= =?utf-8?B?eFppZExBeTEyZmVWcC8rU0NWVHpkTmZVV2tqd2dQdE13K2ZaK2hMd04vV1RX?= =?utf-8?B?Y3YreWNWSng0RFBoVHdmZTNzNDFaYjZtK21Mdmt5NHhZZDJERllXSDR0YlJ3?= =?utf-8?B?V0VUQmJvVFV1OEkwVmdKOHY0YStqQUV1V25KM2pJMmIvYkZDd1kxSjN0SnpI?= =?utf-8?B?TmlKQXF0cVNXUFVLTWdsclVBbEZIT0NrSGNLZkxPRXpFMGNjMFhCTHhuZUJ5?= =?utf-8?B?NklYQzdiV2g4cm12MEN6cWxqYzZwYXZSUXI3T1FKR3lqUFBMU0lKSDMxSnNl?= =?utf-8?B?Wmc2Ym1IK1lqc0tiQlZlUEx0K3c0SjcvRzRtL0pPUDdHa1VnejZqNXVaREt4?= =?utf-8?B?dHJGRUtsNmp2akZqMmNzQXp1aytFSCtxbXRoY1gyclV0T2taR1RRT1hGYlQx?= =?utf-8?B?QytKWkpwVkNWem9qSEUvekZXaVhOYnJjcS9aYVhBZnNzbUpreU0zTjJZdm1j?= =?utf-8?B?dFdVK1RJS0Y4Y2IvNHhHaWllbjBiWnAxRDVOS3BmMzRmNjNNa1BoUXhEL2VN?= =?utf-8?B?cWQ2bHQ0aGgvcnhUKzV6K1pLbWlsNjVoTkJNNnFENUJ4T0hZOW4wRTZKTnVx?= =?utf-8?B?akRvWXE5MVhXZFBsK3Q5N1l4M1BXTkkxZ3VYdkVZdU04WnVMV1lMZmVQQkZO?= =?utf-8?B?ZVYzTmlzbThZVUQwT1VsTERnclNLM3Rya2RTNFlvNFNXNUR5SlVpWWgwSEt2?= =?utf-8?B?bDRFTG5GQWRVSlVid3dkUUlrMmZIdVEweWs3ZFg5UVc0Wm9TQVJ1TlRSVlc0?= =?utf-8?Q?FTAGoJSuucTVbd64=3D?= X-OriginatorOrg: altera.com X-MS-Exchange-CrossTenant-Network-Message-Id: 92de8d2a-40b4-42bf-6746-08dee87b293d X-MS-Exchange-CrossTenant-AuthSource: MW4PR03MB6555.namprd03.prod.outlook.com X-MS-Exchange-CrossTenant-AuthAs: Internal X-MS-Exchange-CrossTenant-OriginalArrivalTime: 23 Jul 2026 05:28:01.0169 (UTC) X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted X-MS-Exchange-CrossTenant-Id: fbd72e03-d4a5-4110-adce-614d51f2077a X-MS-Exchange-CrossTenant-MailboxType: HOSTED X-MS-Exchange-CrossTenant-UserPrincipalName: eU5nyvtcsbmrPPVvZXEplS3pKlsbqfERyF63Y/aWRaja6HXk3pGtAMp5zv0aoXOH68z5lxpxlIwI7X6NSSjrN9mXBzsqAeZR2r2G2EExAKs= X-MS-Exchange-Transport-CrossTenantHeadersStamped: IA6PR03MB846654 Response based on Sashiko review: https://sashiko.dev/#/patchset/cover.1783966717.git.hang.suan.wang%40altera.com On 14/7/2026 2:35 am, hang.suan.wang@altera.com wrote: > From: Hang Suan Wang > > The Agilex 5 Secure Device Manager (SDM 1.5) exposes an FPGA Crypto > Service (FCS) over the existing SIP SMC mailbox: a session-based > interface for crypto primitives such as SDOS (Secure Data Object > Service) encrypt/decrypt. The service layer has no command to drive it > yet. > > Teach stratix10-svc about this interface so an in-kernel FCS client can > use it: > > - add the client command codes COMMAND_FCS_CRYPTO_OPEN_SESSION, > COMMAND_FCS_CRYPTO_CLOSE_SESSION and COMMAND_FCS_SDOS_DATA_EXT (all > asynchronous), and grow stratix10_svc_client_msg::arg[] from three > to four entries so the SDOS command can carry its session, context, > mode and owner arguments; > > - add the matching asynchronous SIP SMC function IDs > (INTEL_SIP_SMC_ASYNC_FCS_OPEN_CS_SESSION, > INTEL_SIP_SMC_ASYNC_FCS_CLOSE_CS_SESSION and > INTEL_SIP_SMC_ASYNC_FCS_CRYPTION_EXT) with their register-usage > documentation; > > - match "intel,agilex5-svc" and register a "stratix10-fcs" child > platform device, mirroring the existing RSU child, so an FCS client > driver can bind without a dedicated device-tree node; > > - dispatch the new commands in the asynchronous send and response > paths; for the SDOS data command, translate the source and > destination buffers (allocated from the service-layer gen_pool) to > physical addresses and pass them, together with the session/context > IDs and owner ID, to the SDM. > > The transport is unchanged: Agilex 5 reuses the SIP SMC calling > convention and async mailbox ABI the driver already implements, so no > new transport mechanism is required. > > The SDOS SMMU-remapped address slots currently carry the buffer > physical addresses; SMMU remapping support is added in a follow-up > series. > > This is a prerequisite for the SoCFPGA FCS driver, the first in-tree > consumer of these commands. > > Signed-off-by: Hang Suan Wang > Reviewed-by: Dinh Nguyen > --- > drivers/firmware/stratix10-svc.c | 58 +++++++++++++++-- > include/linux/firmware/intel/stratix10-smc.h | 64 +++++++++++++++++++ > .../firmware/intel/stratix10-svc-client.h | 18 +++++- > 3 files changed, 135 insertions(+), 5 deletions(-) > > diff --git a/drivers/firmware/stratix10-svc.c b/drivers/firmware/stratix10-svc.c > index c24ca5823078..09f709a2f28e 100644 > --- a/drivers/firmware/stratix10-svc.c > +++ b/drivers/firmware/stratix10-svc.c > @@ -45,6 +45,7 @@ > > /* stratix10 service layer clients */ > #define STRATIX10_RSU "stratix10-rsu" > +#define STRATIX10_FCS "stratix10-fcs" > > /* Maximum number of SDM client IDs. */ > #define MAX_SDM_CLIENT_IDS 16 > @@ -104,9 +105,11 @@ struct stratix10_svc_chan; > /** > * struct stratix10_svc - svc private data > * @stratix10_svc_rsu: pointer to stratix10 RSU device > + * @stratix10_svc_fcs: pointer to stratix10 FCS device > */ > struct stratix10_svc { > struct platform_device *stratix10_svc_rsu; > + struct platform_device *stratix10_svc_fcs; > }; > > /** > @@ -1319,6 +1322,30 @@ int stratix10_svc_async_send(struct stratix10_svc_chan *chan, void *msg, > STRATIX10_SIP_SMC_SET_TRANSACTIONID_X1(handle->transaction_id); > > switch (p_msg->command) { > + case COMMAND_FCS_CRYPTO_OPEN_SESSION: > + args.a0 = INTEL_SIP_SMC_ASYNC_FCS_OPEN_CS_SESSION; > + break; > + case COMMAND_FCS_CRYPTO_CLOSE_SESSION: > + args.a0 = INTEL_SIP_SMC_ASYNC_FCS_CLOSE_CS_SESSION; > + args.a2 = p_msg->arg[0]; > + break; > + case COMMAND_FCS_SDOS_DATA_EXT: > + args.a0 = INTEL_SIP_SMC_ASYNC_FCS_CRYPTION_EXT; > + args.a2 = p_msg->arg[0]; > + args.a3 = p_msg->arg[1]; > + args.a4 = p_msg->arg[2]; > + /* payloads are allocated from the svc gen_pool; pass phys addr */ > + args.a5 = gen_pool_virt_to_phys(ctrl->genpool, > + (unsigned long)p_msg->payload); > If a client driver passes a NULL or invalid buffer (for example, if a > decryption operation only requires an output buffer or an encryption > operation has no payload yet), gen_pool_virt_to_phys() will return -1. > Since this is cast to unsigned long and passed directly into the SMC > arguments args.a5, args.a7, args.a10, and args.a11, could this cause > secure-world crashes or undefined behavior in the firmware? > Should the driver explicitly check for valid buffer addresses or sizes > and handle absent buffers gracefully by passing 0? > This isn't a bug introduced by this patch, but does stratix10_svc_async_send() > need a memory barrier before invoking the SMC call? > The memory pool used for SMC payloads is mapped as Write-Combine (MEMREMAP_WC). > On ARM64, writes to WC memory are placed in write-combine buffers. > Since context synchronization events like an SMC instruction do not guarantee > the visibility of memory accesses to other observers, is it possible for the > EL3 firmware to read stale or partial data from the payload buffer? > Should there be a dma_wmb() or wmb() issued before actrl->invoke_fn() is > called later in this function? The buffer-validity concern does not actually apply because by the time stratix10_svc_async_send() runs, the payload is already fully populated and both pointers are guaranteed valid. The missing-barrier gap is confirmed pre-existing, I think I shall not introduced in this patch. > + args.a6 = p_msg->payload_length; > + args.a7 = gen_pool_virt_to_phys(ctrl->genpool, > + (unsigned long)p_msg->payload_output); > + args.a8 = p_msg->payload_length_output; > + args.a9 = p_msg->arg[3]; > + /* SMMU remapping is added later; pass phys addr for now */ > + args.a10 = args.a5; > + args.a11 = args.a7; > + break; > case COMMAND_RSU_GET_SPT_TABLE: > args.a0 = INTEL_SIP_SMC_ASYNC_RSU_GET_SPT; > break; > @@ -1408,8 +1435,13 @@ static int stratix10_svc_async_prepare_response(struct stratix10_svc_chan *chan, > data->status = STRATIX10_GET_SDM_STATUS_CODE(handle->res.a1); > > switch (p_msg->command) { > + case COMMAND_FCS_CRYPTO_CLOSE_SESSION: > case COMMAND_RSU_NOTIFY: > break; > + case COMMAND_FCS_CRYPTO_OPEN_SESSION: > + case COMMAND_FCS_SDOS_DATA_EXT: > + data->kaddr1 = (void *)&handle->res.a2; > + break; > case COMMAND_RSU_GET_SPT_TABLE: > data->kaddr1 = (void *)&handle->res.a2; > data->kaddr2 = (void *)&handle->res.a3; > @@ -1908,6 +1940,7 @@ EXPORT_SYMBOL_GPL(stratix10_svc_free_memory); > static const struct of_device_id stratix10_svc_drv_match[] = { > {.compatible = "intel,stratix10-svc"}, > {.compatible = "intel,agilex-svc"}, > + {.compatible = "intel,agilex5-svc"}, > {}, > }; > > @@ -2011,20 +2044,36 @@ static int stratix10_svc_drv_probe(struct platform_device *pdev) > > ret = platform_device_add(svc->stratix10_svc_rsu); > if (ret) > - goto err_put_device; > + goto err_put_rsu; > + > + svc->stratix10_svc_fcs = platform_device_alloc(STRATIX10_FCS, 0); > + if (!svc->stratix10_svc_fcs) { > + dev_err(dev, "failed to allocate %s device\n", STRATIX10_FCS); > + ret = -ENOMEM; > + goto err_unregister_rsu; > + } > + > + ret = platform_device_add(svc->stratix10_svc_fcs); > + if (ret) > + goto err_put_fcs; > > ret = of_platform_default_populate(dev_of_node(dev), NULL, dev); > if (ret) > - goto err_unregister_rsu_dev; > + goto err_unregister_fcs; > > pr_info("Intel Service Layer Driver Initialized\n"); > > return 0; > > -err_unregister_rsu_dev: > +err_unregister_fcs: > + platform_device_unregister(svc->stratix10_svc_fcs); > + goto err_unregister_rsu; > +err_put_fcs: > + platform_device_put(svc->stratix10_svc_fcs); > +err_unregister_rsu: > platform_device_unregister(svc->stratix10_svc_rsu); > goto err_free_fifos; > -err_put_device: > +err_put_rsu: > platform_device_put(svc->stratix10_svc_rsu); > err_free_fifos: > /* only remove from list if list_add_tail() was reached */ > This isn't a bug introduced by this patch, but in the probe error path for > stratix10_svc_drv_probe(), if adding the fcs child device fails, the code > jumps to err_unregister_rsu. > This triggers the RSU driver's remove callback, which drops a reference but > does not stop the service channel's svc_smc_hvc_thread kthread. Execution > then continues to err_free_fifos, where the parent driver frees all channel > FIFOs using kfifo_free(). > Could the still-running kthread continue to access the freed FIFO memory via > kfifo_out_spinlocked() and cause a use-after-free? > Does the parent probe error path need to explicitly stop any active channel > tasks before freeing the FIFOs, similar to how it is handled in > stratix10_svc_drv_remove()? This is not a real concern, by the time stratix10_rsu_probe() returns, chan->task is already NULL. When the FCS allocation then fails and we jump err_unregister_rsu → stratix10_rsu_remove() → stratix10_svc_free_channel() and on into err_free_fifos's kfifo_free(), there's no live kthread left to race with the FIFO teardown. > @@ -2051,6 +2100,7 @@ static void stratix10_svc_drv_remove(struct platform_device *pdev) > of_platform_depopulate(ctrl->dev); > > platform_device_unregister(svc->stratix10_svc_rsu); > + platform_device_unregister(svc->stratix10_svc_fcs); > > for (i = 0; i < SVC_NUM_CHANNEL; i++) { > if (ctrl->chans[i].task) { > This isn't a bug introduced by this patch, but looking at > stratix10_svc_drv_remove(), the parent driver calls stratix10_svc_async_exit() > before unregistering the child devices via platform_device_unregister(). > stratix10_svc_async_exit() clears the hash table and frees all active > transaction handlers. > If a child driver concurrently polls a transaction via stratix10_svc_async_poll() > during teardown, could it access the freed handle pointer and cause a > use-after-free? > Should the parent driver fully unregister child devices (ensuring their remove > callbacks have finished executing) before tearing down the asynchronous > infrastructure? this might be true when timeout expires and becomes NULL. will exit gracefully after unregister. will fix in v3. > diff --git a/include/linux/firmware/intel/stratix10-smc.h b/include/linux/firmware/intel/stratix10-smc.h > index 9116512169dc..d7ad6bd6f669 100644 > --- a/include/linux/firmware/intel/stratix10-smc.h > +++ b/include/linux/firmware/intel/stratix10-smc.h > @@ -640,6 +640,70 @@ INTEL_SIP_SMC_FAST_CALL_VAL(INTEL_SIP_SMC_FUNCID_FPGA_CONFIG_COMPLETED_WRITE) > #define INTEL_SIP_SMC_FCS_GET_PROVISION_DATA \ > INTEL_SIP_SMC_STD_CALL_VAL(INTEL_SIP_SMC_FUNCID_FCS_GET_PROVISION_DATA) > > +/** > + * Request INTEL_SIP_SMC_ASYNC_FCS_CRYPTION_EXT > + * Async call to perform encryption/decryption > + * > + * Call register usage: > + * a0 INTEL_SIP_SMC_ASYNC_FCS_CRYPTION_EXT > + * a1 transaction job id > + * a2 session ID > + * a3 context ID > + * a4 cryption operating mode (1 for encryption and 0 for decryption) > + * a5 physical address of source > + * a6 size of source > + * a7 physical address of destination > + * a8 size of destination > + * a9 sdos ownership > + * a10 smmu remapped address of source > + * a11 smmu remapped address of destination > + * a12-a17 not used > + * > + * Return status: > + * a0 INTEL_SIP_SMC_STATUS_OK or INTEL_SIP_SMC_STATUS_ERROR > + * a1-a17 not used > + */ > +#define INTEL_SIP_SMC_ASYNC_FUNC_ID_FCS_CRYPTION_EXT (0x12F) > +#define INTEL_SIP_SMC_ASYNC_FCS_CRYPTION_EXT \ > + INTEL_SIP_SMC_ASYNC_VAL(INTEL_SIP_SMC_ASYNC_FUNC_ID_FCS_CRYPTION_EXT) > + > +/** > + * Request INTEL_SIP_SMC_ASYNC_FCS_OPEN_CS_SESSION > + * Async call to open and establish a crypto service session with firmware > + * > + * Call register usage: > + * a0 INTEL_SIP_SMC_FCS_OPEN_CRYPTO_SERVICE_SESSION > + * a1 transaction job id > + * a2-a17 not used > + * > + * Return status: > + * a0 INTEL_SIP_SMC_STATUS_OK ,INTEL_SIP_SMC_STATUS_REJECTED > + * or INTEL_SIP_SMC_STATUS_BUSY > + * a1-a17 not used > + */ > +#define INTEL_SIP_SMC_ASYNC_FUNC_ID_FCS_OPEN_CS_SESSION (0x13A) > +#define INTEL_SIP_SMC_ASYNC_FCS_OPEN_CS_SESSION \ > + INTEL_SIP_SMC_ASYNC_VAL(INTEL_SIP_SMC_ASYNC_FUNC_ID_FCS_OPEN_CS_SESSION) > + > +/** > + * Request INTEL_SIP_SMC_ASYNC_FCS_CLOSE_CS_SESSION > + * Async call to close a service session > + * > + * Call register usage: > + * a0 INTEL_SIP_SMC_ASYNC_FCS_CLOSE_CS_SESSION > + * a1 transaction job id > + * a2 session ID > + * a3-a17 not used > + * > + * Return status: > + * a0 INTEL_SIP_SMC_STATUS_OK ,INTEL_SIP_SMC_STATUS_REJECTED > + * or INTEL_SIP_SMC_STATUS_BUSY > + * a1-a17 not used > + */ > +#define INTEL_SIP_SMC_ASYNC_FUNC_ID_FCS_CLOSE_CS_SESSION (0x13B) > +#define INTEL_SIP_SMC_ASYNC_FCS_CLOSE_CS_SESSION \ > + INTEL_SIP_SMC_ASYNC_VAL(INTEL_SIP_SMC_ASYNC_FUNC_ID_FCS_CLOSE_CS_SESSION) > + > /** > * Request INTEL_SIP_SMC_HWMON_READTEMP > * Sync call to request temperature > diff --git a/include/linux/firmware/intel/stratix10-svc-client.h b/include/linux/firmware/intel/stratix10-svc-client.h > index 3edd93502bf8..285fddafeacb 100644 > --- a/include/linux/firmware/intel/stratix10-svc-client.h > +++ b/include/linux/firmware/intel/stratix10-svc-client.h > @@ -7,6 +7,8 @@ > #ifndef __STRATIX10_SVC_CLIENT_H > #define __STRATIX10_SVC_CLIENT_H > > +#include > + > /* > * Service layer driver supports client names > * > @@ -122,6 +124,15 @@ struct stratix10_svc_chan; > * @COMMAND_SMC_SVC_VERSION: Non-mailbox SMC SVC API Version, > * return status is SVC_STATUS_OK > * > + * @COMMAND_FCS_CRYPTO_OPEN_SESSION: open the crypto service session(s), > + * return status is SVC_STATUS_OK or SVC_STATUS_ERROR > + * > + * @COMMAND_FCS_CRYPTO_CLOSE_SESSION: close the crypto service session(s), > + * return status is SVC_STATUS_OK or SVC_STATUS_ERROR > + * > + * @COMMAND_FCS_SDOS_DATA_EXT: extend SDOS data encryption & decryption, > + * return status is SVC_STATUS_OK or SVC_STATUS_ERROR > + * > * @COMMAND_MBOX_SEND_CMD: send generic mailbox command, return status is > * SVC_STATUS_OK or SVC_STATUS_ERROR > * > @@ -185,6 +196,11 @@ enum stratix10_svc_command_code { > COMMAND_FCS_RANDOM_NUMBER_GEN, > /* for general status poll */ > COMMAND_POLL_SERVICE_STATUS = 40, > + /* for crypto service */ > + COMMAND_FCS_CRYPTO_OPEN_SESSION = 50, > + COMMAND_FCS_CRYPTO_CLOSE_SESSION, > + /* for extended SDOS encrypt/decrypt */ > + COMMAND_FCS_SDOS_DATA_EXT = 82, > /* for generic mailbox send command */ > COMMAND_MBOX_SEND_CMD = 100, > /* Non-mailbox SMC Call */ > @@ -210,7 +226,7 @@ struct stratix10_svc_client_msg { > void *payload_output; > size_t payload_length_output; > enum stratix10_svc_command_code command; > - u64 arg[3]; > + u64 arg[4]; > }; > > /**