OP-TEE secure storage (CFG_RPMB_FS) relies on an RPMB partition, but U-Boot's OP-TEE RPMB supplicant only speaks the legacy single-command interface, which is bound to eMMC. SoCs that are UFS-only and have no eMMC (for example the Qualcomm SA8775P) therefore cannot back OP-TEE secure storage from U-Boot today. This series adds that support.
It introduces the transport-agnostic OP-TEE RPMB "subsystem" interface (PROBE_RESET / PROBE_NEXT / FRAMES), where the normal world enumerates the RPMB device and reports its kind, size and CID, then carries the signed frames. The legacy eMMC supplicant is preserved unchanged, only renamed to rpmb_emmc.c, with the new UFS backend added as a separate rpmb_ufs.c; the two are mutually exclusive via Kconfig (SUPPORT_UFS_RPMB depends on !SUPPORT_EMMC_RPMB) because the OP-TEE supplicant handles a single RPMB transport. The subsystem interface is UFS-only for now; eMMC can be migrated onto it later as the legacy path is retired. On top of that it adds a UFS RPMB transport that moves JEDEC RPMB frames to and from the RPMB Well-Known LUN using SCSI SECURITY PROTOCOL IN/OUT. The per-region 16-byte CID is derived by BLAKE2b-hashing the exact device-id string the Linux kernel builds (ufshcd_create_device_id() plus a "-R<region>" suffix), so OP-TEE derives an RPMB key that matches the one Linux would use. The first patch is a standalone UFS descriptor fix the RPMB path depends on (UTF-16BE string decoding); the transport patches also include a power-on UNIT ATTENTION retry and a DMA-alignment bounce for the RPMB WLUN. Note: reading UFS descriptors reliably also requires the descriptor data-segment cache-invalidation fix, which has already been posted and merged separately, so this series is based on top of it. Tested on the Qualcomm IQ-9075-EVK (SA8775P): OP-TEE with CFG_RPMB_FS programs the RPMB key through U-Boot and reads/writes secure-storage objects, with the derived CID matching the Linux UFS device_id ABI. Dependencies: Linux kernel: https://lore.kernel.org/linux-scsi/[email protected]/ Op-tee https://github.com/OP-TEE/optee_os/pull/7881 v4: - ufs: decode string descriptors: dropped the in-place ufshcd_str_desc_to_cpu() byte-swap helper; instead added an endian argument to utf16_to_utf8() (UTF16_HOST/LITTLE/BIG_ENDIAN) and decode with UTF16_BIG_ENDIAN, mirroring the kernel's utf16s_to_utf8s(). Existing EFI callers pass UTF16_HOST_ENDIAN. - ufs: RPMB transport: build the SECURITY PROTOCOL CDB with put_unaligned_be16()/put_unaligned_be32(); drop the rpmb_frame_request() helper in favour of get_unaligned_be16(); move ufs_rpmb_read_geometry() to the patch that first uses it so it is not an unused static function during git bisect. - ufs: per-region CID/size: reject an out-of-range device-reported logical block size before shifting and split the size computation into separate statements for readability; order <u-boot/...> after <linux/...>; note that the serial hex encoding matches the kernel device-id ABI. v3: - Renamed the legacy eMMC supplicant to rpmb_emmc.c (was rpmb_legacy.c) and kept it as a pure 100% rename: the UFS RPMB subsystem backend now lives in its own rpmb_ufs.c instead of being folded into rpmb.c, so the eMMC path is left byte-for-byte unchanged. - Added CONFIG_UFS_RPMB_CONTROLLER to select the RPMB-owning UFS controller on boards with more than one UFS controller. - Reworked the commit messages to lead with the motivation rather than the implementation detail. v2: - Squashed the standalone "retry SECURITY PROTOCOL on power-on UNIT ATTENTION" and "bounce unaligned frames through a DMA-aligned buffer" patches into the UFS RPMB transport patch; the series is now 5 patches. - Reused the existing ufshcd_read_desc_param() (now exported) for all descriptor reads instead of adding a new ufshcd_read_descriptor() wrapper. - Moved the SECURITY PROTOCOL IN/OUT opcodes to the generic SCSI header as SCSI_SECURITY_PROTOCOL_IN/OUT instead of private UFS defines. - Factored the UTF-16BE string-descriptor byte-swap into a ufshcd_str_desc_to_cpu() helper. - Dropped the ufs_rpmb_get_scsi_dev() wrapper; callers now use uclass_get_device(UCLASS_SCSI, ...) directly. Jorge Ramirez-Ortiz (5): ufs: decode string descriptors as UTF-16 big-endian ufs: add RPMB transport over SCSI SECURITY PROTOCOL ufs: derive the per-region RPMB CID and size for OP-TEE optee: rename rpmb.c to rpmb_emmc.c optee: implement the RPMB subsystem interface for UFS drivers/tee/optee/Makefile | 3 +- drivers/tee/optee/optee_msg_supplicant.h | 8 + drivers/tee/optee/optee_private.h | 41 +++ drivers/tee/optee/{rpmb.c => rpmb_emmc.c} | 0 drivers/tee/optee/rpmb_ufs.c | 141 ++++++++++ drivers/tee/optee/supplicant.c | 9 + drivers/ufs/Kconfig | 21 ++ drivers/ufs/Makefile | 1 + drivers/ufs/ufs-rpmb.c | 324 ++++++++++++++++++++++ drivers/ufs/ufs-uclass.c | 13 +- drivers/ufs/ufs.h | 7 + include/charset.h | 17 +- include/scsi.h | 2 + include/ufs.h | 10 + lib/charset.c | 15 +- lib/efi_loader/efi_file.c | 4 +- 16 files changed, 605 insertions(+), 11 deletions(-) rename drivers/tee/optee/{rpmb.c => rpmb_emmc.c} (100%) create mode 100644 drivers/tee/optee/rpmb_ufs.c create mode 100644 drivers/ufs/ufs-rpmb.c base-commit: ece349ade2973e220f524ce59e59711cc919263f -- 2.54.0
