From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pl1-f171.google.com (mail-pl1-f171.google.com [209.85.214.171]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 706E73E835E for ; Tue, 4 Aug 2026 08:25:37 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.171 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785831940; cv=none; b=onz/M/k7tBJc6VnQER4xrc1G4S4fahuRpeXZz85SAROP1Y5FAeff1/RAFv/qPV/ui3JXWX1XVxFLtY+hSlGdjjhK6A9AaiXz+/AskCc6kzYs6MsF0HXHEynBWHcYwruq6WmmDjAqvhP0+zpxxFXzLGqELKUZfc14oATj8JVXxQc= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785831940; c=relaxed/simple; bh=JFLe89ORv6CtpTIOWlPLJ4jMWK/w3jKTnLrwTPVsSmQ=; h=Date:From:To:Cc:Subject:Message-ID:References:MIME-Version: Content-Type:Content-Disposition:In-Reply-To; b=PxCALQ0VXNjHdYxcRTY7yeSv6kmXQhJOJHnf/Tso4qLWp81UO46VDj5QfgUAXilFP67WYdkFGc8UxCvfGhEzku5prz/+pFZtwYqEqBrwtk8E9KTveqgoBGvkkoLmmCLKoU7iL4N6GGVoyx68q8pjfNc4XFfGPtJUhk96hL6D+U4= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=sifive.com; spf=pass smtp.mailfrom=sifive.com; dkim=pass (2048-bit key) header.d=sifive.com header.i=@sifive.com header.b=EkoxFlBV; arc=none smtp.client-ip=209.85.214.171 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=sifive.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=sifive.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=sifive.com header.i=@sifive.com header.b="EkoxFlBV" Received: by mail-pl1-f171.google.com with SMTP id d9443c01a7336-2cf6d65d8a7so60186915ad.0 for ; Tue, 04 Aug 2026 01:25:36 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=sifive.com; s=google; t=1785831936; x=1786436736; darn=vger.kernel.org; h=in-reply-to:content-disposition:content-type:mime-version :references:message-id:subject:cc:to:from:date:from:to:cc:subject :date:message-id:reply-to:content-type; bh=5pIRJZIZuQtpYpVv500fQ7C7fCRBLkrhOWthKpIbWoU=; b=EkoxFlBV7wRAigeq34KveuCoyQo+eF3JY8RKb2gQ1r10BDRyB0zjUdyx3d6xCMjyY+ vEhIt/ZoSQpp01vlVV5nw3un1g4jR+Lf/mUtign0HADX2pOdUvlEOHd/BbEDOFnxlKJr N9hyLy5BbZ0HQeeXzvzOzPfOCmRpP4Sh3aZYAg7qpweC5K6xEqSlZIgo8CCYlgfsxoT1 82pqi/I6fQhrnBu/TCJa2ZuQWrw0xuWKkhOr59/NCTDLr5akxAFTIgU/wx3zh0SK2iCK LdLZSCLzCjeXa6pIKK9wJtXeIr5p1AJdlaygFrpq+lAmcVwO81Z97WRKTK31C7uRNdRz cnGg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785831936; x=1786436736; h=in-reply-to:content-disposition:content-type:mime-version :references:message-id:subject:cc:to:from:date:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=5pIRJZIZuQtpYpVv500fQ7C7fCRBLkrhOWthKpIbWoU=; b=F0frhjoNkXM44QCBcchTVLs4po4u0OdtSmnXPVBAYmueIONL9Xb401JgBLS+zcHweE 2u+aKw1aqXRkRWmoeuck63pZC6lid2no3DTyT2pWWyqM/DJeiVVzjZCpQK5jQ+VhKLyB 0f9CWSznb11h3xWdaly7sCLXHWYTYLG+t1KD9KfJTQyjRhkNrg8PGe1jMApdgSraQcb9 G6OjmnCeMkRA3bVZKglfWvndP95jUOJc++tPxO7XRXX7WYLdm9PvWDEnN1lDUv13Q3T5 Sanl4KHVZGdee0PyJhacTYXtRxyFmtavifrZsSah0Zr1vV/EbJXNTXUlxZC+eFBAMTLD BBHQ== X-Forwarded-Encrypted: i=1; AHgh+RoMiBMmfwi7nZX4sqOtTd1SxxIV/utmLiCsNG8yvE3mg81eELk6IdmKFGSUAJSAF5P83OonuqYpn51J/SM=@vger.kernel.org X-Gm-Message-State: AOJu0Yz7fax4LSqknc0FjPDcoMGUUpiq1dGnq4P7w7oHLtHrGhNd42CU ewWElISi+2VXPt+cU/voWm1fMREBGwEnDvKmlsvE5L0+s44GhZMJj9cPNLnMAR3GEG0= X-Gm-Gg: AR+sD10c+uVSW4coGI37Q+x8pgcTXroMcnN8PUAlAMnSq2qvtOEiE3RS/2bBYdaZgW1 8FqRDuVbOH+Kpc4yH2ySTLUrCD1bffYcFip0dbO2RxvY3zgNRlwJYUc9yCTkRTa6yzLpBI69CHy mMZE11Wxtx1MbAdpd6PYdVRTaowCzZYAgHHFyUgW/grufN8OsXQCL8nTEV9sdb3sxwS0gWQ8+80 LPFIzoVEhtLK+SF3uz8fpXW4qhYKyzw1tlGumjNV1kQMY5cOdsjDYOKyCN3zCNqJyXByGfW+F/x YUOrOaQqd0YpNQ8DMc2CXiEFKP20cAEHYyF9zinLRcaEeqUzI6slRbyDfFPynU7iwQbBwtB5Qi1 WeKg6ZjO6ROvmjNrANhGOTCa7LXE6Naz39Jv9MSUSO7kpSCqNv4AJhWCMRYNUsgRGYiiqtBIv8+ AVlO4qBZ+GerkU3YfSTMhYNOK+kXQmuzLAEDTYEFQfIXRV1j4AO31ADVU4CE8= X-Received: by 2002:a17:903:124c:b0:2ca:5d9a:ecc6 with SMTP id d9443c01a7336-2d0523b7dbamr119193075ad.28.1785831935707; Tue, 04 Aug 2026 01:25:35 -0700 (PDT) Received: from plin-1878 ([136.226.240.191]) by smtp.gmail.com with ESMTPSA id d9443c01a7336-2d0aa4930e1sm2426415ad.41.2026.08.04.01.25.32 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 04 Aug 2026 01:25:35 -0700 (PDT) Date: Tue, 4 Aug 2026 16:25:29 +0800 From: Yu-Chien Peter Lin To: Nick Kossifidis Cc: devicetree@vger.kernel.org, linux-riscv@lists.infradead.org, linux-kernel@vger.kernel.org, robh@kernel.org, krzk+dt@kernel.org, conor+dt@kernel.org, pjw@kernel.org, palmer@dabbelt.com, aou@eecs.berkeley.edu, alex@ghiti.fr Subject: Re: [PATCH v2 0/3] dt-bindings: riscv: Add RISC-V Worlds and SiFive WorldGuard DT bindings Message-ID: References: <20260729163908.249838-1-peter.lin@sifive.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: Hi Nick, Thanks for the questions. On Fri, Jul 31, 2026 at 04:43:56AM +0300, Nick Kossifidis wrote: > Hello Peter, > > On 7/29/26 19:39, Yu-Chien Peter Lin wrote: > > Add device tree bindings for RISC-V Worlds, a standard extension that tags > > every transaction with a World ID for fine-grained isolation. SiFive's > > WorldGuard Checker is a hardware firewall in the system interconnect that > > inspects transaction WIDs and enforces per-World access policies on memory > > and MMIO devices. > > > > wgChecker specification reference: > > https://github.com/riscvarchive/security/blob/main/papers/worldguard%20proposal.pdf > > > > Yu-Chien Peter Lin (3): > > dt-bindings: riscv: Add Worlds ISA extensions > > dt-bindings: riscv: Add Worlds per-hart properties > > dt-bindings: sifive: Add WorldGuard Checker > > > > .../devicetree/bindings/riscv/cpus.yaml | 61 +++ > > .../devicetree/bindings/riscv/extensions.yaml | 53 +++ > > .../devicetree/bindings/riscv/worlds.yaml | 86 +++++ > > .../bindings/sifive/sifive,wgchecker2.yaml | 356 ++++++++++++++++++ > > 4 files changed, 556 insertions(+) > > create mode 100644 Documentation/devicetree/bindings/riscv/worlds.yaml > > create mode 100644 Documentation/devicetree/bindings/sifive/sifive,wgchecker2.yaml > > > > What's the plan for this and why do we need Linux-specific dt bindings ? > This looks more like a set of firmware specific bindings, like OpenSBI > domains for example (https://github.com/riscv-software-src/opensbi/blob/master/docs/domain_support.md). > I understand adding the ISA extensions in the list (although the fast track > is still underway, it's not ratified yet), but the rest don't make sense, > not yet at least. How do you plan to use pmlwidlist on Linux to associate > processes to wids ? Do you plan on adding a driver for the wg checker (and > the markers that you mention) on Linux ? Do you ever expect Linux to run > under trustedwid ? We do not currently plan to implement a wgChecker driver in the Linux kernel which holds the untrusted WID; wgChecker slot configuration is handled by OpenSBI only at boot-time. The intention here is providing a standardized device-tree format for describing wgChecker hardware and protection policy, usable consistently across Linux ecosystem (OpenSBI and possibly OP-TEE). Thanks, Peter Lin > > Regards, > Nick