From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mx0a-0031df01.pphosted.com (mx0a-0031df01.pphosted.com [205.220.168.131]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 0D764370ADA for ; Tue, 14 Jul 2026 23:48:08 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=205.220.168.131 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784072890; cv=none; b=s9FVZ44gDRFUhrMQcs4MmvPChM3WfUNorkeN7C2ukegy4KNGsRGxU3ElxQdElUTfSOuHrA8aSsVBI4IaTDiMnWuN319dnxzvvW6TbB7DdVm8aa8HYHsW+jcKCzZQkRXb+FpyDgAnm1WcZmWeqbhIxfd991PbF/VJnfUUw/Cr6vQ= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784072890; c=relaxed/simple; bh=n9AjW65p0a7D6KQPmbrkol4qR1Xm8c7052xAtW+SOos=; h=Message-ID:Date:MIME-Version:Subject:To:Cc:References:From: In-Reply-To:Content-Type; b=KkNvjEsmmu7ViibiN5eCTatmHWkhxxOeowrIzmYjLnSbZvLnsvWuhq7GgY0Zs/FdNAJ9Z9csC3eActT8PJFHnvKkecPGT0xwbh2tjp5smIuVYlgfgkltAbw4fIBaiPdz9llEgoXshChta8QC5LPze1Jow5sLXK4Uit3bWZudVaI= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=oss.qualcomm.com; spf=pass smtp.mailfrom=oss.qualcomm.com; dkim=pass (2048-bit key) header.d=qualcomm.com header.i=@qualcomm.com header.b=lRLVL0wv; dkim=pass (2048-bit key) header.d=oss.qualcomm.com header.i=@oss.qualcomm.com header.b=gkUCE2nc; arc=none smtp.client-ip=205.220.168.131 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=oss.qualcomm.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=oss.qualcomm.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=qualcomm.com header.i=@qualcomm.com header.b="lRLVL0wv"; dkim=pass (2048-bit key) header.d=oss.qualcomm.com header.i=@oss.qualcomm.com header.b="gkUCE2nc" Received: from pps.filterd (m0279864.ppops.net [127.0.0.1]) by mx0a-0031df01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 66EIw9ps1136462 for ; Tue, 14 Jul 2026 23:48:08 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=qualcomm.com; h= cc:content-transfer-encoding:content-type:date:from:in-reply-to :message-id:mime-version:references:subject:to; s=qcppdkim1; bh= vn4MUzHPyhlagDYIvwca+AzfFmNytjBwvjVc71GBUkU=; b=lRLVL0wvMySyzkx2 bm/jqLTqSS3Uj5xno85m35cdJWvZQEdt6WFdfcD6vx01lyPfb5hYagFpz/Rc4ogC NM7ivzc0wRoSWg6hgoc+veM8eSeFwsvGDQ1hFWNiB0oSTNaG7/WHUcGKhjytr0am eaV5BHEOqHbem4dT0lg64sdIoXJw0/xZZ36taoWAUinC5u/ZlI3eyqNWwI6uVmai X4KbXpITyZLnkWFr4AFpfeKtJcCkSsGPyctlwGs+SCCuhEXiEsh3tDBewEWA+Nws BvhdoWOHymprYISolLXQK7NYqyLyEGYGQSPPcY/3si82nPpdmrzUbFA07RGzMlf+ 0ydbSw== Received: from mail-pj1-f71.google.com (mail-pj1-f71.google.com [209.85.216.71]) by mx0a-0031df01.pphosted.com (PPS) with ESMTPS id 4fds9mh5jh-1 (version=TLSv1.3 cipher=TLS_AES_128_GCM_SHA256 bits=128 verify=NOT) for ; Tue, 14 Jul 2026 23:48:08 +0000 (GMT) Received: by mail-pj1-f71.google.com with SMTP id 98e67ed59e1d1-38e22137fb3so419964a91.0 for ; Tue, 14 Jul 2026 16:48:07 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=oss.qualcomm.com; s=google; t=1784072887; x=1784677687; darn=vger.kernel.org; h=content-transfer-encoding:content-type:in-reply-to:from :content-language:references:cc:to:subject:user-agent:mime-version :date:message-id:from:to:cc:subject:date:message-id:reply-to :content-type; bh=vn4MUzHPyhlagDYIvwca+AzfFmNytjBwvjVc71GBUkU=; b=gkUCE2ncHQhryLBubB3gWiz7GxMA+xyIcHxbokynL/Yze+xjH69oGdFTJ/KLbl/+GV zvt4LE5BZVCU0ek2ZquHSWUh+0k/W+XPZlQgtrgwKzAlou2GTaCYwEa/V2OZsSy5uXW3 P54uWwNhSuACrrA/N04LIJeaNvSgF6Ufra5V8oo3UYbUpWgt2PodN5A20nE3KvVI1V6w Gs6wnUMiz9aO9ObFysyce+FW5DfLxSN8k1+G4Haov/1ZrwOciLVxwpZioy0hBr7Ze/Y4 gsbvfQG9RULgXDwsA4YkijAW4bewI8zYzQzVt/vXtviR1ir4UDworF/9PDx9tfxoWDuN SJmw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784072887; x=1784677687; h=content-transfer-encoding:content-type:in-reply-to:from :content-language:references:cc:to:subject:user-agent:mime-version :date:message-id:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=vn4MUzHPyhlagDYIvwca+AzfFmNytjBwvjVc71GBUkU=; b=R13cSpNe/Jh7pahU0glG0Pn583BLLjm63Mj9ryt8DBPyzv8Kh+JNQSXN3qdCA3BtPo PDsI0ZFm0Ifakbp1F0jXAfHtM7xhTp51O4xJBhgcej1ZXrvAl/Sub9fXqkaedAHbedgd a9+Jl8XK6uIzDvWhYh4zQA+pMfjS0UIeCOjTYfjii0ojx1AZK24/Y4ImhRva/Pyb+3Ld z3frABnaSmOSU0oERIq/j9MFqh6yKCgQOlu2gTYWgm+5TN62Jpspx0OD4ymqqPr7Vayo aFAPhi/bppGo6mkvTKidwiaJHVMOHlDWoQ6FnqCLAzxHu5hQ4o2YxJ9sOOmS85MLoYDE s7+Q== X-Forwarded-Encrypted: i=1; AHgh+RpfUEi9lffeTkvGcLt8dCSC/CWf3iyo5NhaqGhPCq/PESGr7PeBYwEaDExj3mIqGsvQ+CV1bsMtEht2Cjs=@vger.kernel.org X-Gm-Message-State: AOJu0YzwbrhM95DLvh6ISAv6KG7m+/isTo0bS2pPKRuzQ7++zUOGsayf hOwxxfCGVl6EDZzQ1pTXl0B2DWXcCQfHccfZr3UaYoTMXCeVPhSNKko5LhzsMchoLRN2of+bbo0 qqjUvC0/aCTlNdpUmNxTLNwzS7PsRkBIdZ9UFDS1iw17+OgsRNgReVpr/IZrhA5m/Dw== X-Gm-Gg: AfdE7cmAbg9yI+WWySbzl74E3JX20Hc2VQMXJbKp0lqMi5Y4z4/lciIOvy7YkeD2gBr rKrbJbsDLh96VH+KrChGFuh0PPiIfOnM8njj4sCJMFBvPkRUZKxzAMCUFpzxysPaeVLkcMxEPEm wvC7l+UL7AD70MTDsX8BBsGgRXiQhKahK/3aikG0Ox8cu68ZXdbhUqWYUu4YyuzF8/avfNmq2yO 9iSS0xkIDLsox6c7OihdjJAYWo8bhCIGFzfowIyytgQYgFl82Wi0GslcpVLH++NIgRCLBT+5fWq V3n33JGSS2OGU88LWzD53XH8AV0UuFZe+OwISQkTjTFhbagoilrD3pjNvGlm4cTrcoARA8ZqWMS HdwB/+EcNr2SKQMMvnKm98P7nNHj/uYX2BJ8UQXR68Z8= X-Received: by 2002:a05:6a20:6f04:b0:3c0:9c19:6592 with SMTP id adf61e73a8af0-3c3576c5a50mr5232426637.76.1784072887398; Tue, 14 Jul 2026 16:48:07 -0700 (PDT) X-Received: by 2002:a05:6a20:6f04:b0:3c0:9c19:6592 with SMTP id adf61e73a8af0-3c3576c5a50mr5232398637.76.1784072886848; Tue, 14 Jul 2026 16:48:06 -0700 (PDT) Received: from [192.168.1.86] ([65.181.14.20]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-31198cb2b99sm58087377eec.26.2026.07.14.16.48.02 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Tue, 14 Jul 2026 16:48:06 -0700 (PDT) Message-ID: Date: Wed, 15 Jul 2026 09:47:59 +1000 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: Re: [PATCH 1/6] tee: qcomtee: Track the object invocation context To: Harshal Dev Cc: Basant Kumar , Apurupa Pattapu , Arun Kumar Neelakantam , op-tee@lists.trustedfirmware.org, linux-kernel@vger.kernel.org, linux-arm-msm@vger.kernel.org, Konrad Dybcio , Bjorn Andersson , Sumit Garg , jenswi@kernel.org References: <20260707-qcom_uefisecapp_migrate_qcomtee-v1-0-f659cbd5d04c@oss.qualcomm.com> <20260707-qcom_uefisecapp_migrate_qcomtee-v1-1-f659cbd5d04c@oss.qualcomm.com> Content-Language: en-US From: Amirreza Zarrabi In-Reply-To: Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwNzE0MDI0NiBTYWx0ZWRfXwSxCO2ZeCSaG yI+E/vuzVCks1GSlfQ0BAImpO54TYZ/FzwGnQ990NXaQ/yEUdU4z9iCLf5TK4pNbBF9nOGTBs6C qmcPzwieEMlAJ/CV2KSaxUwIBT1+K2F48+zU3Zi6Aen6/Dg6RLtyw2wAp/ReDc/CGs0ywcUxMzk 6ixy8C33bbRkCGThRCYZwd1BAYg7agD3mvSdAtRK8ZTaUWDfNU7GJcS6kH2J1XKF2DY+o95m+0U SNIHpVB9nYNcDtXkx7bEAeJhEog65pl3WoXtMuiJG5ClLzhwC+3xgHe/hAy2PjkLQA6PSMtDnl7 X04XpSnA0GeQhe6q1d4FyDeS18LWqGjJyxkSHt+CozB6SbDRnR6tA7H7pLps0mFbW9XSojD7QO/ IeAHdENDytv9ELh4PUx5GxfxUOPLt5ucwEVmwprXnq7tQgjAlLo9xFmGsFzYiflEXps3OSh9q/j fUaqTEbsHcTAEfxp11A== X-Proofpoint-ORIG-GUID: 1NS7-lzn2HzB1z6hIPHnipii5ttE6SHq X-Proofpoint-GUID: 1NS7-lzn2HzB1z6hIPHnipii5ttE6SHq X-Authority-Analysis: v=2.4 cv=E+79Y6dl c=1 sm=1 tr=0 ts=6a56cab8 cx=c_pps a=UNFcQwm+pnOIJct1K4W+Mw==:117 a=1ihhdXzpPjkKEZVMewh6kw==:17 a=IkcTkHD0fZMA:10 a=RAioF0-LDSMA:10 a=s4-Qcg_JpJYA:10 a=VkNPw1HP01LnGYTKEx00:22 a=u7WPNUs3qKkmUXheDGA7:22 a=DJpcGTmdVt4CTyJn9g5Z:22 a=NEAV23lmAAAA:8 a=EUspDBNiAAAA:8 a=j_0Qh49M8Pi7-mX27roA:9 a=QEXdDO2ut3YA:10 a=uKXjsCUrEbL0IQVhDsJ9:22 X-Proofpoint-Spam-Info: AW1haW4tMjYwNzE0MDI0NiBTYWx0ZWRfX52sVsCSVdaIi wmuzJKYdGbex3HGHG3hrPIXyEeiGJwLkYPZyko8ZL0l3BBoL1hdjYtSMYFFW56dhgGDx2gJlTdV TVgCJass5VWDgE0nVgnHuE/IXNTR0uo= X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1143,Hydra:6.1.134,FMLib:17.12.100.49 definitions=2026-07-14_05,2026-07-14_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 malwarescore=0 suspectscore=0 phishscore=0 bulkscore=0 clxscore=1015 lowpriorityscore=0 spamscore=0 impostorscore=0 adultscore=0 priorityscore=1501 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2607140246 Hi Harshal, On 7/10/2026 4:37 PM, Harshal Dev wrote: > Hi Amir, > > On 7/8/2026 11:31 AM, Amirreza Zarrabi wrote: >> Hi Harshal, >> >> On 7/7/2026 4:11 PM, Harshal Dev wrote: >>> QCOMTEE needs to distinguish between object invocations arriving from >>> kernel clients and user-space clients in order to correctly marshal >>> UBUF parameters and decide whether certain operations should be permitted. >>> >>> Add a kernel_ctx flag to struct qcomtee_object_invoke_context to track >>> the context of object invocation. Objects invoked from the kernel-space >>> are expected to have the MSB of their 64-bit object-id set to indicate a >>> kernel context, whereas objects invoked from user-space should not set it. >>> To ensure this, we restrict the object-id space of user-space invoked >>> objects to 32-bits. This is in-line with QTEE expectation of 32-bit object >>> ids. >>> >>> Signed-off-by: Amirreza Zarrabi >>> Signed-off-by: Harshal Dev >>> --- >>> drivers/tee/qcomtee/call.c | 24 ++++++++++++++++++++++-- >>> drivers/tee/qcomtee/qcomtee.h | 6 ++++++ >>> drivers/tee/qcomtee/qcomtee_object.h | 8 ++++++-- >>> drivers/tee/tee_core.c | 4 ++++ >>> 4 files changed, 38 insertions(+), 4 deletions(-) >>> >>> diff --git a/drivers/tee/qcomtee/call.c b/drivers/tee/qcomtee/call.c >>> index 0efc5646242a..a74a54d67b06 100644 >>> --- a/drivers/tee/qcomtee/call.c >>> +++ b/drivers/tee/qcomtee/call.c >>> @@ -397,11 +397,31 @@ static int qcomtee_object_invoke(struct tee_context *ctx, >>> { >>> struct qcomtee_context_data *ctxdata = ctx->data; >>> struct qcomtee_object *object; >>> + bool kernel_ctx = false; >>> int i, ret, result; >>> >>> if (qcomtee_params_check(params, arg->num_params)) >>> return -EINVAL; >>> >>> + /* Obtain the invocation context information from the MSB of the object >>> + * `id` field. >>> + */ >>> + kernel_ctx = QCOMTEE_GET_CLIENT_CTX(arg->id); >>> + /* User-space identifies a NULL object via a 32-bit TEE_OBJREF_NULL id, whereas >>> + * the kernel uses as 64-bit object-id. Hence, we check for a NULL object by >>> + * sign-extending the object-id to 64 bits. If user-space is indeed invoking a >>> + * NULL object we must extend the object-id to 64-bits from here on so that >>> + * QCOMTEE can recognize it. >>> + */ >>> + if (!kernel_ctx && ((s64)(s32)arg->id) == TEE_OBJREF_NULL) >>> + arg->id = TEE_OBJREF_NULL; >> >> Does it need to be MSB -- why bit 63? the object ID supported by QTEE is 32-bit anyway. >> Let's mask the upper 32-bit and do something like kernel_ctx = !!upper_32_bits(id). >> What do you think? > > I agree. Instead of checking for kernel-ctx by right shifting, I can use this approach. > QTEE objects invoked from user-space (including NULL object) will always have their > object-id constrained to lower 32 bits anyway as per PR: https://github.com/quic/quic-teec/pull/27 > > And for kernel-space invoked QTEE objects, upper 32-bits would be set for NULL object, > and 63rd bit expected to be set as well. > Re-thinking this, I'm a bit concerned about overloading id while keeping it as a u64, and then filtering its upper 32 bits in tee_ioctl_object_invoke(). It feels unintuitive, as it naturally raises the question: if only the lower 32 bits are meaningful, why is id a `u64` in the first place? What if we make the caller origin explicit instead, for example: enum tee_object_invoke_origin { TEE_OBJECT_INVOKE_USERSPACE, TEE_OBJECT_INVOKE_KERNEL, }; and then pass it through the backend op: int (*object_invoke_func)(struct tee_context *ctx, struct tee_ioctl_object_invoke_arg *arg, struct tee_param *param, enum tee_object_invoke_origin origin); It seems more straightforward and avoids encoding caller-origin metadata into id. If you are OK, let's do this. - Amir >> >>> + >>> + /* If the object being invoked is not NULL, drop the MSB from the `id` field to >>> + * obtain the actual object-id. >>> + */ >>> + if (arg->id != TEE_OBJREF_NULL) >>> + arg->id = QCOMTEE_SANITIZE_OBJ_ID(arg->id); >>> + >>> /* First, handle reserved operations: */ >>> if (arg->op == QCOMTEE_MSG_OBJECT_OP_RELEASE) { >>> del_qtee_object(arg->id, ctxdata); >>> @@ -411,7 +431,7 @@ static int qcomtee_object_invoke(struct tee_context *ctx, >>> >>> /* Otherwise, invoke a QTEE object: */ >>> struct qcomtee_object_invoke_ctx *oic __free(kfree) = >>> - qcomtee_object_invoke_ctx_alloc(ctx); >>> + qcomtee_object_invoke_ctx_alloc(ctx, kernel_ctx); >>> if (!oic) >>> return -ENOMEM; >>> >>> @@ -648,7 +668,7 @@ static void qcomtee_get_qtee_feature_list(struct tee_context *ctx, u32 id, >>> int result; >>> >>> struct qcomtee_object_invoke_ctx *oic __free(kfree) = >>> - qcomtee_object_invoke_ctx_alloc(ctx); >>> + qcomtee_object_invoke_ctx_alloc(ctx, true); >>> if (!oic) >>> return; >>> >>> diff --git a/drivers/tee/qcomtee/qcomtee.h b/drivers/tee/qcomtee/qcomtee.h >>> index f39bf63fd1c2..5d292a2ff83d 100644 >>> --- a/drivers/tee/qcomtee/qcomtee.h >>> +++ b/drivers/tee/qcomtee/qcomtee.h >>> @@ -17,6 +17,12 @@ >>> #define QCOMTEE_OBJREF_FLAG_USER BIT(1) >>> #define QCOMTEE_OBJREF_FLAG_MEM BIT(2) >>> >>> +/* The MSB of the object_id field indicates whether the client is invoking the >>> + * object from user context or kernel context. >>> + */ >>> +#define QCOMTEE_GET_CLIENT_CTX(x) (((x) >> 63) & 1U) >>> +#define QCOMTEE_SANITIZE_OBJ_ID(x) ((x) & (BIT(63) - 1)) >>> + >>> /** >>> * struct qcomtee - Main service struct. >>> * @teedev: client device. >>> diff --git a/drivers/tee/qcomtee/qcomtee_object.h b/drivers/tee/qcomtee/qcomtee_object.h >>> index 8b4401ecad48..2528d07e4576 100644 >>> --- a/drivers/tee/qcomtee/qcomtee_object.h >>> +++ b/drivers/tee/qcomtee/qcomtee_object.h >>> @@ -146,6 +146,7 @@ static inline int qcomtee_args_len(struct qcomtee_arg *args) >>> * struct qcomtee_object_invoke_ctx - QTEE context for object invocation. >>> * @ctx: TEE context for this invocation. >>> * @flags: flags for the invocation context. >>> + * @kernel_ctx: flag that indicates this context is owned by a kernel client. >>> * @errno: error code for the invocation. >>> * @object: current object invoked in this callback context. >>> * @u: array of arguments for the current invocation (+1 for ending arg). >>> @@ -158,6 +159,7 @@ static inline int qcomtee_args_len(struct qcomtee_arg *args) >>> struct qcomtee_object_invoke_ctx { >>> struct tee_context *ctx; >>> unsigned long flags; >>> + bool kernel_ctx; >>> int errno; >>> >>> struct qcomtee_object *object; >>> @@ -172,13 +174,15 @@ struct qcomtee_object_invoke_ctx { >>> }; >>> >>> static inline struct qcomtee_object_invoke_ctx * >>> -qcomtee_object_invoke_ctx_alloc(struct tee_context *ctx) >>> +qcomtee_object_invoke_ctx_alloc(struct tee_context *ctx, bool kernel_ctx) >>> { >>> struct qcomtee_object_invoke_ctx *oic; >>> >>> oic = kzalloc_obj(*oic); >>> - if (oic) >>> + if (oic) { >>> oic->ctx = ctx; >>> + oic->kernel_ctx = kernel_ctx; >>> + } >>> return oic; >>> } >>> >>> diff --git a/drivers/tee/tee_core.c b/drivers/tee/tee_core.c >>> index ef9642d72672..7f986d7fb47f 100644 >>> --- a/drivers/tee/tee_core.c >>> +++ b/drivers/tee/tee_core.c >>> @@ -706,6 +706,10 @@ static int tee_ioctl_object_invoke(struct tee_context *ctx, >>> goto out; >>> } >>> >>> + /* Userspace object-ids are restricted to 32-bits. */ >>> + if (arg.id > U32_MAX) >>> + return -EINVAL; >>> + >> >> This change belongs to tee SS, move it to a separate commit with appropriate message. > > Ack. > > Regards, > Harshal >> >>> rc = ctx->teedev->desc->ops->object_invoke_func(ctx, &arg, params); >>> if (rc) >>> goto out; >>> >> >> Regards, >> Amir >> >