From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from fout-b6-smtp.messagingengine.com (fout-b6-smtp.messagingengine.com [202.12.124.149]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id E231F2E764D for ; Tue, 7 Jul 2026 10:04:28 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=202.12.124.149 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783418670; cv=none; b=IZrKGwRmgjjH07toUKR79s17+c2NmhB293BjM70bOlXYewg2JmA2z1Q5N0bHHevCngPqxZutVMzlN01/KjlCU3KMdjhSOQK9lngbwMP+xFm2kNM45COg/8sP0tB19EfD/KU9/xbmhZc/q8OGn1MJU1h2ItmchBGZzW+aj/wJPAU= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783418670; c=relaxed/simple; bh=Ngslog0LYlMoBvOcImCW/Cakaw3SNZmAcw5aYcmvhPQ=; h=MIME-Version:Date:From:To:Message-Id:In-Reply-To:References: Subject:Content-Type; b=aXbm+4TSWZPAURI9w7IqUDlilvY8u9un6dnQyLrgjADDV64/WUB5tyUQEMPUXIvA7J46Q3U/LxeZY1tPTokhUd6X9Uefhfz6QBE37UolGsP3F1fDYkbX1HlCgDhrU6NcjeuWBX888Uvg7IYXvK9Kw80oA9lifUGS3w7F/Coho90= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=arndb.de; spf=pass smtp.mailfrom=arndb.de; dkim=pass (2048-bit key) header.d=arndb.de header.i=@arndb.de header.b=C9Te1uIw; dkim=pass (2048-bit key) header.d=messagingengine.com header.i=@messagingengine.com header.b=mqEcWGid; arc=none smtp.client-ip=202.12.124.149 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=arndb.de Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=arndb.de Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=arndb.de header.i=@arndb.de header.b="C9Te1uIw"; dkim=pass (2048-bit key) header.d=messagingengine.com header.i=@messagingengine.com header.b="mqEcWGid" Received: from phl-compute-04.internal (phl-compute-04.internal [10.202.2.44]) by mailfout.stl.internal (Postfix) with ESMTP id 03FD91D00139; Tue, 7 Jul 2026 06:04:27 -0400 (EDT) Received: from phl-imap-05 ([10.202.2.95]) by phl-compute-04.internal (MEProxy); Tue, 07 Jul 2026 06:04:28 -0400 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=arndb.de; h=cc :content-transfer-encoding:content-type:content-type:date:date :from:from:in-reply-to:in-reply-to:message-id:mime-version :references:reply-to:subject:subject:to:to; s=fm1; t=1783418667; x=1783505067; bh=Py3+QhcKs5OW/olQ1FkhyXVB4mmjsUO4a+hCb9tut0s=; b= C9Te1uIwRWMzeUCmDTuVussVejUqZx/K9ZOF3KPrcdSgylco0/Qb0OD1Sh2qm0vJ p50disR4kLWtfv6CITdApo7sktW8FOHZkYCcS6Es2BAJtUFc/+nystAb7mJPMLIq AHDR1pVD+wp7nF2sgr0S9qhQr96KjBbaq/4o9+KUgqVHApzHFAEVX44uwL8obvNT 8DtOxbgCkWvqOo4pOx2dTYgtD2vqywz2wlG1VxX5W+bfnzl0q7rBVBj0w8CVB+6M D7Wazn5ffzgwU0Nn2uEu3F3dnLuJcpkrrx1ISH425iuTNobBun3QbRiriSs7NEJ8 DiMxHegr0XMIee5sZViNmg== DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=cc:content-transfer-encoding:content-type :content-type:date:date:feedback-id:feedback-id:from:from :in-reply-to:in-reply-to:message-id:mime-version:references :reply-to:subject:subject:to:to:x-me-proxy:x-me-sender :x-me-sender:x-sasl-enc; s=fm2; t=1783418667; x=1783505067; bh=P y3+QhcKs5OW/olQ1FkhyXVB4mmjsUO4a+hCb9tut0s=; b=mqEcWGidXCK0mo7VE DzdiJ8XN8fsRLXY11JFuxpIrKOsXDN11Z1T6Sq7VbC7brZtYJEiy4mBhK+hTcJSx 2OmH0VR4CqcL+XbDaQHhmPvgfhI/0zKDLJU71yj8JO3vI41dkffi6HPLlPcbAJzN 1B8BGlza8GF5XpoJ4kqGSlRHZ6spipPRS4Im94UmruhT1DR+XvelOgXAXJ+naA66 mi6rKLYJvc6oYZ8Ej2uAHP6afdJcwyNgrOd0xrv8gZmOeTtFzX/I8zri8Esu8lN1 DgZD6sS8JGmZUGZjEKo/saRLKnn08S8+4SSSLac+K96jf3tPGAvhxnmQEcXGKAeZ /l89w== X-ME-Sender: X-ME-Proxy-Cause: dmFkZTE9j0ZAq3juDUwMJggKTQxJ84hrYNrhVsMbfPFMlFSI6iGmolQ9BsGKhJpGs4bw3f GtyvdgjQxZNepvTVShvMEFspHyIQEiYR0cebZJHlJm36A1Iylv2zJtsq5E6ENB6lHTWf1b FGXc8xjqpbqylr4GXGYVN005HQs4/Z50SM95kiubeyc13ambV07TkKgqY0tnq+a7b3MDUq /dhXs0rpr/A3r0A8u+bOOW5L3H50bbR4fWV57iwlMNYr1x5YNsx26Hcej0K9IbO3FNXuBN efRhU1SaDkscoHr494u//eMExtfZu2vlawrelx3bHvjQzZgODK/TbeNjOPAW/SJM/HQxRQ 2yOJ0ekuyPW1uy9ASs3LU1kyo34GFbVyBjQwI+kehO4VTMdS7iMak6YPj0xsu7DntU/S4O VYsg29dIG7ewb5AV7o2Ov8ruFYqmekHgwcJAcp04haaA11TofCBkmPnwKHA+FLbRrfDz9q ox7ld18g3/eIjgNKT+qBoxf7LteD0hLMoA6u9Stj4Vc6sS5lsd5IzA8DYRgCzAHDp3FfUq lGSbrX0158w4DC9HLkmqDzYpH5xOdSru35hhn4jf+HaU0YHER6h96OLaYdU6YHvLqEMsVb FKDLATUwmAZGpE6cPXR5KYbnGfXU6qHye9tiEeDOmZJDTs4ltrnKlnopNFYA X-ME-Proxy: Feedback-ID: i56a14606:Fastmail Received: by mailuser.phl.internal (Postfix, from userid 501) id 87381182007E; Tue, 7 Jul 2026 06:04:27 -0400 (EDT) X-Mailer: MessagingEngine.com Webmail Interface Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-ThreadId: AoRJ6HJh7ZXF Date: Tue, 07 Jul 2026 12:04:07 +0200 From: "Arnd Bergmann" To: "Harsh Jain" , "Greg Kroah-Hartman" , "Michal Simek" , linux-kernel@vger.kernel.org, sarat.chand.savitala@amd.com, nkowlaku@amd.com Message-Id: In-Reply-To: <20260707095620.2795456-3-h.jain@amd.com> References: <20260707095620.2795456-1-h.jain@amd.com> <20260707095620.2795456-3-h.jain@amd.com> Subject: Re: [PATCH 2/2] misc: Add Xilinx PUF driver Content-Type: text/plain Content-Transfer-Encoding: 7bit On Tue, Jul 7, 2026, at 11:56, Harsh Jain wrote: > Versal devices contain a physically unclonable function (PUF) block > that derives device-unique secrets from intrinsic silicon > characteristics. The PUF generates a Key Encryption Key (KEK) used > internally by the AES engine for secure key storage, which is not > externally accessible. In addition, the PUF provides a readable > device-unique identifier derived from the same entropy source. > > Add a misc character driver to support PUF registration and regeneration. > Registration generates a unique secret and outputs binary helper data > that can later be used during regeneration to reproduce the same > secrets. > > The driver also implements PUF_CLEAR_ID and PUF_CLEAR_KEY ioctls to clear > the PUF ID and PUF-derived AES key via firmware. They are disabled by default > unless puf_clear is set. > > Signed-off-by: Harsh Jain Hi Harsh, This description sounds like it should be integrated into the existing crypto infrastructure of the kernel. I'm not sure what the exact feature set in your hardware is like, but please work with the crypto and keyctl maintainers to either use that infrastructure, or extend it to your requirements instead of adding a custom ioctl interface. My guess would be that you can have a driver similar to drivers/platform/cznic/turris-omnia-mcu-keyctl.c for managing private keys in the hardware and managing it through the keyctl(2) infrastructure. Have you looked at this already? Arnd