From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pg1-f174.google.com (mail-pg1-f174.google.com [209.85.215.174]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 90F8733F8AE for ; Thu, 8 Jan 2026 06:45:30 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.215.174 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1767854734; cv=none; b=mW2ZvrOXlYmnTB0tVAKWD/3gRh36v3ZUUAaMyaQ3nJ5QYm2NQgSo+/pUFecWzi1rdI+kFV1zkL0RIVJPjSxkxe7wGK0go/B4UGLCZyfJLR4KangKEkjAlQf7gfmfWt82TYDUGH4swjvftBCSulYI5x+cif8Z+ETSfEGoF9xv/No= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1767854734; c=relaxed/simple; bh=RFHmz5TQHKHs2Vp+TjRAkZnnq8URvJSA+vTP5gc8K/Q=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=XIBStaR7Hss9XVbstWcnDSmiAuhg9RfbrU6d9t3qaPebbBawCPt1mYLG+Sx0nxa9Chew0qNmXKLt2ryf1z7bwWkB//h0EnrZsiatsjfEX77vPbrGUvszyH4wWl9++VJggDoqHvOoYKThTmG4pXp8B7jefa7e3qXWKfrMuL4Se9w= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=euQ2l+Wf; arc=none smtp.client-ip=209.85.215.174 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="euQ2l+Wf" Received: by mail-pg1-f174.google.com with SMTP id 41be03b00d2f7-b98983bae80so1523857a12.0 for ; Wed, 07 Jan 2026 22:45:29 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20230601; t=1767854728; x=1768459528; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to; bh=4AgHaSdzGFhpjrKWJPhfx+okgTbgrInnDnJ59Awpc9s=; b=euQ2l+WfFdPNsE/KImpNs+hKtOD/GAxi4RnvzjAbhtp7gCJ2c/X3oCAI1Zy3CZo/sa SVDSDgZ7jSrbiPG0gdHTsW+tBmp1ONS7C9OizmJzCUmhysgm8RuwDXVQs6u629dKPcOt /pR6gV+zciIVsUHD9aknG+YrQw4xf6wl8coel8w0IaUQeJnMqiwyYEo9r+Ca83dZRGOR 23fLrsMNIRMvnjMlzoYHHHdKJ0yLfVwr5YLXAJ4O9FVsdaRsI8u0lYlhw0sTjpZ0yuMX vfTTa1zgDWseqXtN142be571OaXpXimfaykbZB9Iz3A6IZN1rGsvXMjPdfRABqkEZkaX 0UXg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1767854728; x=1768459528; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to; bh=4AgHaSdzGFhpjrKWJPhfx+okgTbgrInnDnJ59Awpc9s=; b=pI2NySCl2gakFZd39b189aHym49xaFv+Y9jHlf+4SHGWDJl8XCIfDxv9NGUlOIx5XY WPeVEr5tV/jTMG8KfewvHISnQvRjR90w+B6XyUSFIk4V8Vf5vrfHpqlz7f6YpaDVgel9 BabFeSkXlQYGNRH4QZ80hLbTA3+eEFwoUBpzbsMQtSks09C0qBC50Zk1ZkFF6Zx7BWZc X1w4zjCQ46Do9pvyMp+4r0QFzw44qy7nNJb7pqj+LpL4ZpokxlXkmBI/5GYimfrqkMJ4 IM2EYtBbW9/C+oguyhorn2/VCS47U0OZ8TRUY8m4J6RYbHso+b2KvYenUTvnjZKSGW0j 0wMA== X-Gm-Message-State: AOJu0YwY1Luz6EzbC5RnL5KXuVU/BHgXrbMbVfQdpVhrsUDcOJPI3WQ4 svspf5ZQr3KPsTjfdVhxC4h5MgX4CIwc4xdto89Aj84DoGbOYDiRZP+zJX5OKQ== X-Gm-Gg: AY/fxX7Q0mL6t48N08aOmjqhWeHh00u5APNrVP6gYGMgH4n4PO7EeJNB8sBmR/8/Sid rH4pzHmzdYndCFDIjWPN1W0yvm5VyDYSA4M3xey8ecj3mLxk2mrjiQ2xsYtyXEQ7ce97gDIvOiV EKr2I9u/f1AapZ447hueCXIR/id1jKvOq5amuA1BJkOSsQ9N25S/MtOIBZFKOU+doFWhySpwC9O Y7xmv2Z/2k50a2ifwwhMzASb1qGZowqm4sFDY0sdaCZWN0dBtAfzUajT0QI462O8ybQO7w4c7fk wiJGKzo2FubKYXTS3oHvT5B8rMusr2KVpL9QaNXGN9sa7e1CHfql96UNvGnlk+ykUmn+sLIjpg2 jVX4lr0HjnUlSe2RI6g6tALqvuqbIpfGlp/G/SqEv8ODnaryXUduw/HWm1ooGb1UBFQ/jTI2U04 yFV04wQe2WuSCZrLkl+ilM9hXoBPNoOqdR2D2Xx8VbWcs2kjOvtte5mE7d3YjcZdGwSPfQsNqPA 47rVdKdzpfJZ6hb X-Google-Smtp-Source: AGHT+IE8cpwFdvEfxjiXZpXnLEiZi3TaeibsbE5/TP+xSDkwdtKd3mRg89Yp35x66sqUklLvxXsGKw== X-Received: by 2002:a05:6a20:939f:b0:366:14ac:8c76 with SMTP id adf61e73a8af0-3898f9e2dcfmr4896869637.76.1767854728408; Wed, 07 Jan 2026 22:45:28 -0800 (PST) Received: from aristo-PC.tail872496.ts.net (124-218-37-86.cm.dynamic.apol.com.tw. [124.218.37.86]) by smtp.gmail.com with ESMTPSA id 41be03b00d2f7-c4cc95d5dbfsm6813334a12.27.2026.01.07.22.45.26 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 07 Jan 2026 22:45:28 -0800 (PST) From: Aristo Chen X-Google-Original-From: Aristo Chen To: linux-kernel@vger.kernel.org Cc: jens.wiklander@linaro.org, sumit.garg@kernel.org, op-tee@lists.trustedfirmware.org, harshal.dev@oss.qualcomm.com, mario.limonciello@amd.com, Rijo-john.Thomas@amd.com, amirreza.zarrabi@oss.qualcomm.com, Aristo Chen Subject: [PATCH v6 2/2] tee: optee: store OS revision for TEE core Date: Thu, 8 Jan 2026 14:45:09 +0800 Message-ID: <20260108064517.13854-2-aristo.chen@canonical.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260108064517.13854-1-aristo.chen@canonical.com> References: <20260107152607.902735-1-aristo.chen@canonical.com> <20260108064517.13854-1-aristo.chen@canonical.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit Collect OP-TEE OS revision from secure world for both SMC and FF-A ABIs, store it in the OP-TEE driver, and expose it through the generic get_tee_revision() callback. Signed-off-by: Aristo Chen --- drivers/tee/optee/core.c | 23 +++++++++++++ drivers/tee/optee/ffa_abi.c | 57 ++++++++++++++++++++++++------- drivers/tee/optee/optee_private.h | 19 +++++++++++ drivers/tee/optee/smc_abi.c | 15 ++++++-- 4 files changed, 99 insertions(+), 15 deletions(-) diff --git a/drivers/tee/optee/core.c b/drivers/tee/optee/core.c index 5b62139714ce..2d807bc748bc 100644 --- a/drivers/tee/optee/core.c +++ b/drivers/tee/optee/core.c @@ -63,6 +63,29 @@ int optee_set_dma_mask(struct optee *optee, u_int pa_width) return dma_coerce_mask_and_coherent(&optee->teedev->dev, mask); } +int optee_get_revision(struct tee_device *teedev, char *buf, size_t len) +{ + struct optee *optee = tee_get_drvdata(teedev); + u64 build_id; + + if (!optee) + return -ENODEV; + if (!buf || !len) + return -EINVAL; + + build_id = optee->revision.os_build_id; + if (build_id) + scnprintf(buf, len, "%u.%u (%016llx)", + optee->revision.os_major, + optee->revision.os_minor, + (unsigned long long)build_id); + else + scnprintf(buf, len, "%u.%u", optee->revision.os_major, + optee->revision.os_minor); + + return 0; +} + static void optee_bus_scan(struct work_struct *work) { WARN_ON(optee_enumerate_devices(PTA_CMD_GET_DEVICES_SUPP)); diff --git a/drivers/tee/optee/ffa_abi.c b/drivers/tee/optee/ffa_abi.c index bf8390789ecf..82dbed1c87e5 100644 --- a/drivers/tee/optee/ffa_abi.c +++ b/drivers/tee/optee/ffa_abi.c @@ -775,6 +775,42 @@ static int optee_ffa_reclaim_protmem(struct optee *optee, * with a matching configuration. */ +static bool optee_ffa_get_os_revision(struct ffa_device *ffa_dev, + const struct ffa_ops *ops, + struct optee_revision *revision, + bool log) +{ + const struct ffa_msg_ops *msg_ops = ops->msg_ops; + struct ffa_send_direct_data data = { + .data0 = OPTEE_FFA_GET_OS_VERSION, + }; + int rc; + + msg_ops->mode_32bit_set(ffa_dev); + + rc = msg_ops->sync_send_receive(ffa_dev, &data); + if (rc) { + pr_err("Unexpected error %d\n", rc); + return false; + } + + if (revision) { + revision->os_major = data.data0; + revision->os_minor = data.data1; + revision->os_build_id = data.data2; + } + + if (log) { + if (data.data2) + pr_info("revision %lu.%lu (%08lx)", + data.data0, data.data1, data.data2); + else + pr_info("revision %lu.%lu", data.data0, data.data1); + } + + return true; +} + static bool optee_ffa_api_is_compatible(struct ffa_device *ffa_dev, const struct ffa_ops *ops) { @@ -798,19 +834,8 @@ static bool optee_ffa_api_is_compatible(struct ffa_device *ffa_dev, return false; } - data = (struct ffa_send_direct_data){ - .data0 = OPTEE_FFA_GET_OS_VERSION, - }; - rc = msg_ops->sync_send_receive(ffa_dev, &data); - if (rc) { - pr_err("Unexpected error %d\n", rc); + if (!optee_ffa_get_os_revision(ffa_dev, ops, NULL, true)) return false; - } - if (data.data2) - pr_info("revision %lu.%lu (%08lx)", - data.data0, data.data1, data.data2); - else - pr_info("revision %lu.%lu", data.data0, data.data1); return true; } @@ -900,6 +925,7 @@ static int optee_ffa_open(struct tee_context *ctx) static const struct tee_driver_ops optee_ffa_clnt_ops = { .get_version = optee_ffa_get_version, + .get_tee_revision = optee_get_revision, .open = optee_ffa_open, .release = optee_release, .open_session = optee_open_session, @@ -918,6 +944,7 @@ static const struct tee_desc optee_ffa_clnt_desc = { static const struct tee_driver_ops optee_ffa_supp_ops = { .get_version = optee_ffa_get_version, + .get_tee_revision = optee_get_revision, .open = optee_ffa_open, .release = optee_release_supp, .supp_recv = optee_supp_recv, @@ -1060,6 +1087,12 @@ static int optee_ffa_probe(struct ffa_device *ffa_dev) if (!optee) return -ENOMEM; + if (!optee_ffa_get_os_revision(ffa_dev, ffa_ops, &optee->revision, + false)) { + rc = -EINVAL; + goto err_free_optee; + } + pool = optee_ffa_shm_pool_alloc_pages(); if (IS_ERR(pool)) { rc = PTR_ERR(pool); diff --git a/drivers/tee/optee/optee_private.h b/drivers/tee/optee/optee_private.h index db9ea673fbca..acd3051c4879 100644 --- a/drivers/tee/optee/optee_private.h +++ b/drivers/tee/optee/optee_private.h @@ -171,6 +171,24 @@ struct optee_ffa { struct optee; +/** + * struct optee_revision - OP-TEE OS revision reported by secure world + * @os_major: OP-TEE OS major version + * @os_minor: OP-TEE OS minor version + * @os_build_id: OP-TEE OS build identifier (0 if unspecified) + * + * Values come from OPTEE_SMC_CALL_GET_OS_REVISION (SMC ABI) or + * OPTEE_FFA_GET_OS_VERSION (FF-A ABI); this is the trusted OS revision, not an + * FF-A ABI version. + */ +struct optee_revision { + u32 os_major; + u32 os_minor; + u64 os_build_id; +}; + +int optee_get_revision(struct tee_device *teedev, char *buf, size_t len); + /** * struct optee_ops - OP-TEE driver internal operations * @do_call_with_arg: enters OP-TEE in secure world @@ -249,6 +267,7 @@ struct optee { bool in_kernel_rpmb_routing; struct work_struct scan_bus_work; struct work_struct rpmb_scan_bus_work; + struct optee_revision revision; }; struct optee_session { diff --git a/drivers/tee/optee/smc_abi.c b/drivers/tee/optee/smc_abi.c index 0be663fcd52b..51fae1ab8ef8 100644 --- a/drivers/tee/optee/smc_abi.c +++ b/drivers/tee/optee/smc_abi.c @@ -1242,6 +1242,7 @@ static int optee_smc_open(struct tee_context *ctx) static const struct tee_driver_ops optee_clnt_ops = { .get_version = optee_get_version, + .get_tee_revision = optee_get_revision, .open = optee_smc_open, .release = optee_release, .open_session = optee_open_session, @@ -1261,6 +1262,7 @@ static const struct tee_desc optee_clnt_desc = { static const struct tee_driver_ops optee_supp_ops = { .get_version = optee_get_version, + .get_tee_revision = optee_get_revision, .open = optee_smc_open, .release = optee_release_supp, .supp_recv = optee_supp_recv, @@ -1323,7 +1325,8 @@ static bool optee_msg_api_uid_is_optee_image_load(optee_invoke_fn *invoke_fn) } #endif -static void optee_msg_get_os_revision(optee_invoke_fn *invoke_fn) +static void optee_msg_get_os_revision(optee_invoke_fn *invoke_fn, + struct optee_revision *revision) { union { struct arm_smccc_res smccc; @@ -1337,6 +1340,12 @@ static void optee_msg_get_os_revision(optee_invoke_fn *invoke_fn) invoke_fn(OPTEE_SMC_CALL_GET_OS_REVISION, 0, 0, 0, 0, 0, 0, 0, &res.smccc); + if (revision) { + revision->os_major = res.result.major; + revision->os_minor = res.result.minor; + revision->os_build_id = res.result.build_id; + } + if (res.result.build_id) pr_info("revision %lu.%lu (%0*lx)", res.result.major, res.result.minor, (int)sizeof(res.result.build_id) * 2, @@ -1745,8 +1754,6 @@ static int optee_probe(struct platform_device *pdev) return -EINVAL; } - optee_msg_get_os_revision(invoke_fn); - if (!optee_msg_api_revision_is_compatible(invoke_fn)) { pr_warn("api revision mismatch\n"); return -EINVAL; @@ -1815,6 +1822,8 @@ static int optee_probe(struct platform_device *pdev) goto err_free_shm_pool; } + optee_msg_get_os_revision(invoke_fn, &optee->revision); + optee->ops = &optee_ops; optee->smc.invoke_fn = invoke_fn; optee->smc.sec_caps = sec_caps; -- 2.43.0