[...] > > > >> For the QEMU/RPMB/OP-TEE question: QEMU RPMB would cover the storage > >> backend, but the FF-A runtime transport also needs the secure world to > >> expose the MM variable service through an FF-A secure partition. OP-TEE > >> alone would exercise the existing CONFIG_EFI_MM_COMM_TEE transport, not > >> the FF-A runtime transport, unless OP-TEE/SPMC is hosting an FF-A SP > >> that implements the same MM variable communication protocol. > > > > OP-TEE can also be configured to run in SPMC mode and load SPs. The > > question is what is the backing storage of your SP > > > >> > >> For Corstone-1000 we are already using the Trusted Services SMM Gateway > >> SP. That SP implements the MM variable service and exposes the MM > >> Communicate endpoint over FF-A direct messages, which is the path used > >> by this series. > >> > >> I agree that QEMU would be better for wider review and CI. I will have > >> to investigate the QEMU setup using the same SMM Gateway SP along with > >> OP-TEE/SPMC and RPMB, so we can reproduce the FF-A runtime variable path > >> without access to Corstone-1000. > > > > I can help, I just need a bit more info on that SP. I'll have a look > > at the public docs as well > > > >> > >> Do you suggest that I investigate this QEMU setup for the > >> next revision? > > > > I'd like to at least see the gap, but I suspect it's going to be small > > if it even exists. > > > > Thanks Ilias. > > The SP we use on Corstone-1000 is the Trusted Services SMM Gateway SP. > It is built from the Trusted Services smm-gateway deployment and exposes > the MM Communicate endpoint over FF-A direct messages. The generated SP > manifest uses the SMM Gateway UUID. > > The main gap I found so far is on the QEMU/TF-A side. Trusted Services > already provides the SMM Gateway SP, and QEMU has RPMB support, but I > could not find a QEMU-specific OP-TEE SPMC manifest in TF-A. The FVP > platform has fvp_spmc_el1_optee_manifest.dts, but there does not appear > to be an equivalent QEMU manifest in the TF-A tree. > > So I think the QEMU work is likely to be: > - add a QEMU OP-TEE SPMC manifest for TF-A > - package the SMM Gateway SP with OP-TEE SPMC > - wire QEMU RPMB into the secure storage backend > > Do you suggest that I continue investigating this QEMU setup for the > next revision?
The QEMU setup will be a convenient way to integrate this into CI, but I don't mind if we address it later. If you have time to spend on it, by all means; otherwise, I am ok with the FVP setup Cheers /Ilias > > Regards > Harsimran Singh Tungal > > >> > >> The setup I am currently testing is Corstone-1000 FVP with the MM > >> variable service exposed through FF-A. The FF-A runtime path is tested > >> in two phases as follows: > >> > >> The first phase (setup phase) creates the non-volatile runtime variable > >> before reset. On U-Boot prompt: > >> > >> corstone1000# setenv efi_selftest 'variables at runtime setup' > >> corstone1000# bootefi selftest > >> > >> > >> Then reset the Corstone-1000 FVP and run the second phase. > >> The second phase verifies that the variable is available after reset, > >> then exercises runtime get/set/append/delete paths. > >> On U-Boot prompt after reset, execute the following commands: > >> > >> corstone1000# setenv efi_selftest 'variables at runtime verify' > >> corstone1000# bootefi selftest > >> > >> The testing steps are documented in the bootefi documentation commit: > >> doc: bootefi: note two-phase runtime variables selftest > >> > >> For v5, I can add these tested steps to the cover letter. > > > > There's no need for a v5 yet, I'll take some time and reprod with the > > FVP. Just keep in mind I'll be off for the next ~20 days so this is > > going to take a while, apologies. > > > > Cheers > > /Ilias > >> > >> Thanks > >> Harsimran Singh Tungal > >> > >>>>> latest version of QEMU do support emulating an RPMB device. Would the > >>>>> changes above work with with an SP, QEMU RPMB and OP-TEE? > >>>>> > >>>>> Thanks > >>>>> /Ilias > >>>>> > >>>>> On Wed, 29 Jul 2026 at 11:51, Harsimran Singh Tungal > >>>>> <[email protected]> wrote: > >>>>>> > >>>>>> Hi all, > >>>>>> > >>>>>> This series adds FF-A runtime transport support so EFI variable runtime > >>>>>> services can communicate with the secure world after > >>>>>> ExitBootServices(). > >>>>>> It also extends tests, documentation, and Corstone-1000 configuration > >>>>>> to > >>>>>> validate the runtime path and keep boot-time behavior aligned with the > >>>>>> runtime flow. > >>>>>> > >>>>>> Changes in this series: > >>>>>> - Add EFI runtime-safe memset helper and FF-A runtime transport > >>>>>> support. > >>>>>> - Add runtime-safe FF-A direct-message handling and ExitBootServices > >>>>>> setup. > >>>>>> - Implement FF-A runtime communication in the EFI variable TEE backend. > >>>>>> - Enable EFI runtime SetVariable(), GetVariable(), > >>>>>> GetNextVariableName(), > >>>>>> and QueryVariableInfo() over the FF-A transport. > >>>>>> - Add sandbox FF-A runtime transport tests. > >>>>>> - Extend EFI selftests for runtime variables and enable bootefi > >>>>>> selftest > >>>>>> on Corstone-1000. > >>>>>> - Document the FF-A runtime transport and runtime-variable selftest > >>>>>> flow. > >>>>>> > >>>>>> Changes in v4: > >>>>>> > >>>>>> Address Ilias Apalodimas's review comments: > >>>>>> - Split FF-A bus runtime support into smaller patches covering runtime > >>>>>> private data, SMC invocation, direct-message helpers, boot-time > >>>>>> reuse, > >>>>>> and ExitBootServices setup. > >>>>>> - Split the ARMv8 cache range-maintenance runtime annotations into a > >>>>>> separate patch. > >>>>>> - Split the EFI variable TEE runtime SetVariable(), GetVariable(), > >>>>>> GetNextVariableName(), and QueryVariableInfo() support into separate > >>>>>> patches. > >>>>>> - Replace MM SP status macros with an enum. > >>>>>> - Keep OP-TEE as the runtime fallback when FF-A runtime mode is not > >>>>>> enabled. > >>>>>> > >>>>>> Other changes: > >>>>>> - Rebased the series onto current U-Boot master. > >>>>>> > >>>>>> Changes in v3: > >>>>>> > >>>>>> Address Simon Glass's review comments: > >>>>>> - Move FF-A ExitBootServices event registration to the end of probe and > >>>>>> clean up RX/TX buffer handling on failure. > >>>>>> - Rename FF-A runtime-context helpers to the ffa_runtime_context_* > >>>>>> form. > >>>>>> - Rework FF-A/MM cache maintenance to cover only rounded request and > >>>>>> response ranges. > >>>>>> - Add SetVirtualAddressMap handling for the FF-A shared buffer. > >>>>>> - Document FF-A shared-buffer ownership and alignment assumptions. > >>>>>> - Add EFIAPI to the TEE runtime GetVariable and GetNextVariableName > >>>>>> entry points. > >>>>>> - Tighten sandbox FF-A runtime tests and reset runtime state between > >>>>>> test cases. > >>>>>> - Update FF-A and bootefi documentation for the runtime transport and > >>>>>> split runtime-variable selftests. > >>>>>> - Rework commit messages to drop redundant information. > >>>>>> > >>>>>> Address Ilias Apalodimas's review comments: > >>>>>> - Keep efi_var_common.c unchanged and drop commit 6 from v2 patchset. > >>>>>> - Rename the TEE/FF-A runtime handlers to the *_int_runtime form. > >>>>>> - Remove log_*() calls from __efi_runtime FF-A/MM communication paths. > >>>>>> > >>>>>> Other: > >>>>>> - Fix FF-A memory-share sender_id to use the runtime private endpoint > >>>>>> ID after rebasing. > >>>>>> - Fix the expected QueryVariableInfo() return status for the > >>>>>> TEE-backed runtime selftest path. > >>>>>> > >>>>>> > >>>>>> Changes in v2: > >>>>>> > >>>>>> Address Simon Glass's review comments: > >>>>>> - Fix efi_memset_runtime() style, declaration, and byte cast > >>>>>> - Tighten the FF-A runtime context failure path, clean up > >>>>>> arm-ffa-runtime.c > >>>>>> style issues, and move ExitBootServices event registration earlier > >>>>>> in probe > >>>>>> - Add shared-buffer bounds/alignment checks, and tightening > >>>>>> comments/kernel-doc > >>>>>> - Document the FF-A shared buffer cacheline-alignment requirement and > >>>>>> add > >>>>>> BUILD_BUG_ON() checks for the address > >>>>>> - Cache attributes before the shared buffer is reused, moving the > >>>>>> read-only > >>>>>> check earlier, and split the u16_strsize() related change in > >>>>>> separate patch > >>>>>> - Reword commit messages for the runtime helper relocation > >>>>>> - Rework the non-volatile runtime variable selftest into setup/verify > >>>>>> phases > >>>>>> - Extend the sandbox FF-A runtime tests with no-context coverage, > >>>>>> runtime-context reset, and separate errno-mapping coverage > >>>>>> - Refresh the FF-A runtime transport and bootefi documentation > >>>>>> - Drop patch 12 in v1, as ffa_mm_communicate handles both runtime and > >>>>>> boottime capabilities in v2 > >>>>>> - Squash patch 8 and patch 9 from v1 > >>>>>> > >>>>>> Address Ilias Apalodimas's review comments: > >>>>>> - Reuse common MM SP error mapping for boot and runtime paths > >>>>>> - Rename runtime-phase tracking to reflect the ExitBootServices > >>>>>> transition > >>>>>> - Collapse duplicated boot-time and runtime MM communication helpers > >>>>>> into common > >>>>>> implementations > >>>>>> - Keep the arm64 cache-maintenance path runtime-safe > >>>>>> - Move FF-A shared-buffer runtime memory-map registration to the end of > >>>>>> variable-service initialization > >>>>>> > >>>>>> Link to v3: > >>>>>> https://lore.kernel.org/u-boot/[email protected]/ > >>>>>> Link to v2: > >>>>>> https://lore.kernel.org/u-boot/[email protected]/ > >>>>>> Link to v1: > >>>>>> https://lore.kernel.org/u-boot/[email protected]/ > >>>>>> > >>>>>> Harsimran Singh Tungal (22): > >>>>>> efi_loader: add runtime memset helper > >>>>>> arm-ffa: store boot-discovered runtime data separately > >>>>>> arm-ffa: add runtime-safe FF-A SMC wrapper > >>>>>> arm-ffa: add runtime direct-message support > >>>>>> arm-ffa: reuse direct-message helper at boot time > >>>>>> arm-ffa: enable runtime context at ExitBootServices > >>>>>> arm: cache: keep range maintenance available at EFI runtime > >>>>>> efi_loader: add MM SP status mapping for FF-A variables > >>>>>> efi_loader: make MM transport selection runtime-safe > >>>>>> efi_loader: make FF-A MM SP notification runtime-safe > >>>>>> efi_loader: make FF-A MM communication runtime-safe > >>>>>> efi_loader: reserve FF-A shared buffer for runtime variables > >>>>>> efi_loader: enable TEE runtime SetVariable() over FF-A > >>>>>> efi_loader: enable TEE runtime GetVariable() over FF-A > >>>>>> efi_loader: enable TEE runtime GetNextVariableName() over FF-A > >>>>>> efi_loader: enable TEE runtime QueryVariableInfo() over FF-A > >>>>>> charset: mark u16_strsize() as __efi_runtime > >>>>>> corstone1000: enable bootefi selftest > >>>>>> efi: selftest: add runtime variable tests with non-volatile storage > >>>>>> test: dm: add sandbox FF-A runtime transport tests > >>>>>> doc: arm64: document FF-A runtime path for EFI variables > >>>>>> doc: bootefi: note two-phase runtime variables selftest > >>>>>> > >>>>>> arch/arm/cpu/armv8/cache.S | 8 + > >>>>>> arch/arm/cpu/armv8/cache_v8.c | 13 +- > >>>>>> arch/sandbox/include/asm/sandbox_arm_ffa.h | 16 +- > >>>>>> configs/corstone1000_defconfig | 3 + > >>>>>> doc/arch/arm64.ffa.rst | 88 ++- > >>>>>> doc/usage/cmd/armffa.rst | 11 + > >>>>>> doc/usage/cmd/bootefi.rst | 31 + > >>>>>> drivers/firmware/arm-ffa/Kconfig | 11 + > >>>>>> drivers/firmware/arm-ffa/Makefile | 4 +- > >>>>>> drivers/firmware/arm-ffa/arm-ffa-runtime.c | 294 +++++++ > >>>>>> drivers/firmware/arm-ffa/arm-ffa-uclass.c | 114 +-- > >>>>>> drivers/firmware/arm-ffa/arm-ffa.c | 16 +- > >>>>>> drivers/firmware/arm-ffa/ffa-emul-uclass.c | 49 +- > >>>>>> include/arm_ffa.h | 16 +- > >>>>>> include/arm_ffa_priv.h | 22 +- > >>>>>> include/arm_ffa_runtime.h | 191 +++++ > >>>>>> include/efi_loader.h | 3 + > >>>>>> lib/charset.c | 2 +- > >>>>>> lib/efi_loader/Kconfig | 4 + > >>>>>> lib/efi_loader/efi_runtime.c | 20 + > >>>>>> lib/efi_loader/efi_variable_tee.c | 739 > >>>>>> +++++++++++++++--- > >>>>>> .../efi_selftest_variables_runtime.c | 715 +++++++++++------ > >>>>>> test/dm/Makefile | 3 +- > >>>>>> test/dm/ffa.c | 6 +- > >>>>>> test/dm/ffa_runtime.c | 123 +++ > >>>>>> 25 files changed, 2004 insertions(+), 498 deletions(-) > >>>>>> create mode 100644 drivers/firmware/arm-ffa/arm-ffa-runtime.c > >>>>>> create mode 100644 include/arm_ffa_runtime.h > >>>>>> create mode 100644 test/dm/ffa_runtime.c > >>>>>> > >>>>>> -- > >>>>>> 2.34.1 > >>>>>> > >> > >> IMPORTANT NOTICE: The contents of this email and any attachments are > >> confidential and may also be privileged. If you are not the intended > >> recipient, please notify the sender immediately and do not disclose the > >> contents to any other person, use it for any purpose, or store or copy the > >> information in any medium. Thank you. > > IMPORTANT NOTICE: The contents of this email and any attachments are > confidential and may also be privileged. If you are not the intended > recipient, please notify the sender immediately and do not disclose the > contents to any other person, use it for any purpose, or store or copy the > information in any medium. Thank you.
