From: zeroknots <zeroknots@protonmail.com>
To: kuldeep.singh@oss.qualcomm.com
Cc: amirreza.zarrabi@oss.qualcomm.com, jarkko@kernel.org,
jenswi@kernel.org, jgg@ziepe.ca, linux-arm-msm@vger.kernel.org,
linux-integrity@vger.kernel.org, linux-kernel@vger.kernel.org,
op-tee@lists.trustedfirmware.org, peterhuewe@gmx.de,
sumit.garg@kernel.org
Subject: Re: [PATCH v2 0/3] Add TPM support via Qualcomm TEE TPM TA
Date: Thu, 01 Oct 2026 05:50:34 +0000 [thread overview]
Message-ID: <20261001055029.1960743-1-zeroknots@protonmail.com> (raw)
Hi Kuldeep,
A data point from retail hardware, in case it is useful for this
series: on an ASUS Zenbook A14 UX3407NA (Glymur, X2E-88-100, BIOS
UX3407NA.315) the TPM TA is not reachable as QTEE service 81, but it
is present as the QSEECOM application "qcom.tz.tpm".
With the qcomtee driver on a 7.3-rc3 based kernel, QTEE reports
version 5.2.0, and service discovery finds neither 81 (TPM) nor 413
(UEFI secure app). On the same boot, qseecom (version 0x1402000) works
and backs efivars through "qcom.tz.uefisecapp" (app id 7). An app-id
lookup for "qcom.tz.tpm" returns app id 1; a made-up name returns
-ENOENT.
The Windows driver for this machine agrees: QcTrEE8480.inf configures
the TPM service with AppName="qcom.tz.tpm", SecureApp=1, LoadApp=0
(preloaded by firmware). The EFI configuration table carries the
TPMEventLog and TPMFinalLog entries, so the firmware TPM is active.
Through that app, using a QSEECOM transport (based on Xilin Wu's
out-of-tree SC8280XP driver: QUERY_INFO_2 / SEND_COMMAND with a
CRB-style control area, here at 0x81d10000), /dev/tpm0 works: TPM 2.0,
manufacturer QCOM, vendor string "xCG fTPM", firmware 0x40000, real
PCR 0-7 values, GetRandom, ECC and RSA-2048 primaries, sign and
verify, and a sealed object that persists across reboots.
So, as far as I can tell, retail Glymur laptops may ship firmware on
which this driver finds no TPM, while the same TA is available over
QSEECOM.
The same applies to the prerequisite series that moves uefisecapp to
QCOMTEE [1]: on this firmware service 413 is absent and EFI variables
work only through the QSEECOM uefisecapp. If the QSEECOM path were
dropped for Glymur, efivars would stop working on this machine, so it
would be good to keep it as a fallback when the QTEE service is not
found.
Two questions:
- Is service 81 expected to appear on retail firmware through an
update, or is it specific to the CRD firmware?
- Would you consider a QSEECOM-based path for such firmware? I am
happy to test this series, or any other service UID you would like
checked, on this machine, and to share the transport code.
[1] https://lore.kernel.org/lkml/20260722-qcom_uefisecapp_migrate_qcomtee-v2-0-b8a8fcbe4211@oss.qualcomm.com/
Thanks,
zeroknots
Assisted-by: LLM (analysis and drafting; the measurements were made on
the hardware and reviewed by me)
next reply other threads:[~2026-10-01 5:50 UTC|newest]
Thread overview: 10+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-01 5:50 zeroknots [this message]
2026-10-05 6:57 ` Kuldeep Singh
2026-10-05 7:24 ` Dmitry Baryshkov
2026-10-05 12:00 ` Kuldeep Singh
-- strict thread matches above, loose matches on Subject: below --
2026-09-07 9:28 Kuldeep Singh
2026-09-16 9:02 ` Kuldeep Singh
2026-09-18 1:53 ` Jarkko Sakkinen
2026-09-21 8:36 ` Kuldeep Singh
2026-09-25 14:46 ` Jarkko Sakkinen
2026-09-28 9:34 ` Kuldeep Singh
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261001055029.1960743-1-zeroknots@protonmail.com \
--to=zeroknots@protonmail.com \
--cc=amirreza.zarrabi@oss.qualcomm.com \
--cc=jarkko@kernel.org \
--cc=jenswi@kernel.org \
--cc=jgg@ziepe.ca \
--cc=kuldeep.singh@oss.qualcomm.com \
--cc=linux-arm-msm@vger.kernel.org \
--cc=linux-integrity@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=op-tee@lists.trustedfirmware.org \
--cc=peterhuewe@gmx.de \
--cc=sumit.garg@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®