mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH 0/3] arm64: realm: Add support for encrypted data from firmware
@ 2025-06-13 11:11 Suzuki K Poulose
  2025-06-13 11:11 ` [PATCH 1/3] arm64: realm: ioremap: Allow mapping memory as encrypted Suzuki K Poulose
                   ` (4 more replies)
  0 siblings, 5 replies; 15+ messages in thread
From: Suzuki K Poulose @ 2025-06-13 11:11 UTC (permalink / raw)
  To: linux-arm-kernel
  Cc: will, catalin.marinas, sami.mujawar, aneesh.kumar, steven.price,
	linux-kernel, sudeep.holla, Suzuki K Poulose

Confidential compute firmware may provide secret data via reserved memory regions
(e.g., ACPI CCEL, EFI Coco secret area). These must be ioremap'ed() as encrypted.
As of now, realm only maps "trusted devices" (RIPAS = RSI_RIPAS_DEV) as encrypted.
This series adds support for mapping areas that are protected
(i.e., RIPAS = RSI_RIPAS_RAM) as encrypted. Also, extrapolating that, we can map
anything that is not RIPAS_EMPTY as protected, as it is guaranteed to be "protected".

With this in place, we can naturally map any firmware provided area based on the
RIPAS value. If the firmware provides a shared region (not trusted), it must have
set the RIPAS accordingly, before placing the data, as the transition is always
destructive.

Also enables the EFI Coco secret area support and Confidential Compute Event
Log (CCEL) for arm64.


Suzuki K Poulose (3):
  arm64: realm: ioremap: Allow mapping memory as encrypted
  arm64: Enable EFI secret area Securityfs support
  arm64: acpi: Enable ACPI CCEL support

 arch/arm64/include/asm/io.h          |  6 +++++-
 arch/arm64/include/asm/rsi.h         |  2 +-
 arch/arm64/kernel/acpi.c             |  5 +++++
 arch/arm64/kernel/rsi.c              | 26 ++++++++++++++++++++++----
 drivers/virt/coco/efi_secret/Kconfig |  2 +-
 5 files changed, 34 insertions(+), 7 deletions(-)

-- 
2.43.0


^ permalink raw reply	[flat|nested] 15+ messages in thread

end of thread, other threads:[~2025-07-25 11:09 UTC | newest]

Thread overview: 15+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2025-06-13 11:11 [PATCH 0/3] arm64: realm: Add support for encrypted data from firmware Suzuki K Poulose
2025-06-13 11:11 ` [PATCH 1/3] arm64: realm: ioremap: Allow mapping memory as encrypted Suzuki K Poulose
2025-06-18 15:02   ` Steven Price
2025-06-30  1:33   ` Gavin Shan
2025-06-13 11:11 ` [PATCH 2/3] arm64: Enable EFI secret area Securityfs support Suzuki K Poulose
2025-06-30  1:34   ` Gavin Shan
2025-06-13 11:11 ` [PATCH 3/3] arm64: acpi: Enable ACPI CCEL support Suzuki K Poulose
2025-06-30  1:34   ` Gavin Shan
2025-07-15 13:56   ` Will Deacon
2025-07-15 14:38     ` Suzuki K Poulose
2025-07-15 14:58       ` Will Deacon
2025-07-25 11:09         ` Suzuki K Poulose
2025-06-16 11:15 ` [PATCH 0/3] arm64: realm: Add support for encrypted data from firmware Suzuki K Poulose
2025-06-17  9:20   ` Sami Mujawar
2025-07-09 12:53 ` Suzuki K Poulose

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®