Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1473642 > unrolled thread

[PATCH 0/5] Atmel sama5d2 security module support

Started byAlexandre Belloni <alexandre.belloni@free-electrons.com>
First post2016-08-31 18:20 +0200
Last post2016-08-31 18:20 +0200
Articles 9 — 3 participants

Back to article view | Back to linux.kernel


Contents

  [PATCH 0/5] Atmel sama5d2 security module support Alexandre Belloni <alexandre.belloni@free-electrons.com> - 2016-08-31 18:20 +0200
    [PATCH 1/5] Documentation: dt: atmel-at91: Document secumod bindings Alexandre Belloni <alexandre.belloni@free-electrons.com> - 2016-08-31 18:20 +0200
      Re: [PATCH 1/5] Documentation: dt: atmel-at91: Document secumod  bindings Rob Herring <robh@kernel.org> - 2016-09-06 23:50 +0200
    [PATCH 5/5] misc: sram: add Atmel securam support Alexandre Belloni <alexandre.belloni@free-electrons.com> - 2016-08-31 18:20 +0200
      Re: [PATCH 5/5] misc: sram: add Atmel securam support Philipp Zabel <p.zabel@pengutronix.de> - 2016-08-31 18:50 +0200
        Re: [PATCH 5/5] misc: sram: add Atmel securam support Alexandre Belloni <alexandre.belloni@free-electrons.com> - 2016-08-31 19:10 +0200
    [PATCH 4/5] misc: sram: document new compatible Alexandre Belloni <alexandre.belloni@free-electrons.com> - 2016-08-31 18:20 +0200
      Re: [PATCH 4/5] misc: sram: document new compatible Rob Herring <robh@kernel.org> - 2016-09-06 23:50 +0200
    [PATCH 2/5] ARM: dts: at91: sama5d2: Add secumod node Alexandre Belloni <alexandre.belloni@free-electrons.com> - 2016-08-31 18:20 +0200

#1473642 — [PATCH 0/5] Atmel sama5d2 security module support

FromAlexandre Belloni <alexandre.belloni@free-electrons.com>
Date2016-08-31 18:20 +0200
Subject[PATCH 0/5] Atmel sama5d2 security module support
Message-ID<scgp4-4D4-11@gated-at.bofh.it>
Hi,

There has already been multiple tentatives trying to add support for the
Sama5d2 security module and in particular, access to its SRAM.
After multiple discussions, I believe adding support in the sram
driver/framework is probably the best because it allows exporting the
SRAM to the kernel, to userspace and also to run code from it.

As the support for the sama5d2 securam is fairly small, I've included it
directly in the mmio-sram driver.

Regards,

Cc: Rob Herring <robh+dt@kernel.org>
Cc: devicetree@vger.kernel.org
Cc: Arnd Bergmann <arnd@arndb.de>
Cc: Philipp Zabel <p.zabel@pengutronix.de>
Cc: Vladimir Zapolskiy <vladimir_zapolskiy@mentor.com>

Alexandre Belloni (5):
  Documentation: dt: atmel-at91: Document secumod bindings
  ARM: dts: at91: sama5d2: Add secumod node
  ARM: at91: add secumod register definitions
  misc: sram: document new compatible
  misc: sram: add Atmel securam support

 .../devicetree/bindings/arm/atmel-at91.txt         | 17 +++++++
 Documentation/devicetree/bindings/sram/sram.txt    |  2 +-
 arch/arm/boot/dts/sama5d2.dtsi                     | 19 ++++++++
 drivers/misc/sram.c                                | 52 +++++++++++++++++++---
 include/soc/at91/atmel-secumod.h                   | 46 +++++++++++++++++++
 5 files changed, 128 insertions(+), 8 deletions(-)
 create mode 100644 include/soc/at91/atmel-secumod.h

-- 
2.9.3

[toc] | [next] | [standalone]


#1473647 — [PATCH 1/5] Documentation: dt: atmel-at91: Document secumod bindings

FromAlexandre Belloni <alexandre.belloni@free-electrons.com>
Date2016-08-31 18:20 +0200
Subject[PATCH 1/5] Documentation: dt: atmel-at91: Document secumod bindings
Message-ID<scgp4-4D4-19@gated-at.bofh.it>
In reply to#1473642
A security module is available starting with sama5d2, add its bindings.

Signed-off-by: Alexandre Belloni <alexandre.belloni@free-electrons.com>
---
Cc: Rob Herring <robh+dt@kernel.org>
Cc: devicetree@vger.kernel.org
 Documentation/devicetree/bindings/arm/atmel-at91.txt | 17 +++++++++++++++++
 1 file changed, 17 insertions(+)

diff --git a/Documentation/devicetree/bindings/arm/atmel-at91.txt b/Documentation/devicetree/bindings/arm/atmel-at91.txt
index e1f5ad855f14..eea1f44d5666 100644
--- a/Documentation/devicetree/bindings/arm/atmel-at91.txt
+++ b/Documentation/devicetree/bindings/arm/atmel-at91.txt
@@ -225,3 +225,20 @@ required properties:
 		compatible = "atmel,sama5d3-sfr", "syscon";
 		reg = <0xf0038000 0x60>;
 	};
+
+Security Module (SECUMOD)
+
+The Security Module macrocell provides all necessary secure functions to avoid
+voltage, temperature, frequency and mechanical attacks on the chip. It also
+embeds secure memories that can be scrambled
+
+required properties:
+- compatible: Should be "atmel,<chip>-secumod", "syscon".
+  <chip> can be "sama5d2".
+- reg: Should contain registers location and length
+
+	secumod@fc040000 {
+		compatible = "atmel,sama5d2-secumod", "syscon";
+		reg = <0xfc040000 0x100>;
+	};
+
-- 
2.9.3

[toc] | [prev] | [next] | [standalone]


#1477836 — Re: [PATCH 1/5] Documentation: dt: atmel-at91: Document secumod bindings

FromRob Herring <robh@kernel.org>
Date2016-09-06 23:50 +0200
SubjectRe: [PATCH 1/5] Documentation: dt: atmel-at91: Document secumod bindings
Message-ID<sewpH-7zd-15@gated-at.bofh.it>
In reply to#1473647
On Wed, Aug 31, 2016 at 06:11:04PM +0200, Alexandre Belloni wrote:
> A security module is available starting with sama5d2, add its bindings.
> 
> Signed-off-by: Alexandre Belloni <alexandre.belloni@free-electrons.com>
> ---
> Cc: Rob Herring <robh+dt@kernel.org>
> Cc: devicetree@vger.kernel.org
>  Documentation/devicetree/bindings/arm/atmel-at91.txt | 17 +++++++++++++++++
>  1 file changed, 17 insertions(+)

Acked-by: Rob Herring <robh@kernel.org>

[toc] | [prev] | [next] | [standalone]


#1473649 — [PATCH 5/5] misc: sram: add Atmel securam support

FromAlexandre Belloni <alexandre.belloni@free-electrons.com>
Date2016-08-31 18:20 +0200
Subject[PATCH 5/5] misc: sram: add Atmel securam support
Message-ID<scgp5-4D4-33@gated-at.bofh.it>
In reply to#1473642
The Atmel secure SRAM is connected to a security module and may be erased
automatically under certain conditions. For that reason, it is necessary to
wait for the security module to flag that SRAM accesses are allowed before
accessing it.

Signed-off-by: Alexandre Belloni <alexandre.belloni@free-electrons.com>
---
Cc: Arnd Bergmann <arnd@arndb.de>
Cc: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Cc: Philipp Zabel <p.zabel@pengutronix.de>
Cc: Vladimir Zapolskiy <vladimir_zapolskiy@mentor.com>
 drivers/misc/sram.c | 52 +++++++++++++++++++++++++++++++++++++++++++++-------
 1 file changed, 45 insertions(+), 7 deletions(-)

diff --git a/drivers/misc/sram.c b/drivers/misc/sram.c
index f84b53d6ce50..8d411c64d07f 100644
--- a/drivers/misc/sram.c
+++ b/drivers/misc/sram.c
@@ -19,12 +19,16 @@
  */
 
 #include <linux/clk.h>
+#include <linux/delay.h>
 #include <linux/genalloc.h>
 #include <linux/io.h>
 #include <linux/list_sort.h>
 #include <linux/of_address.h>
 #include <linux/platform_device.h>
+#include <linux/regmap.h>
 #include <linux/slab.h>
+#include <linux/mfd/syscon.h>
+#include <soc/at91/atmel-secumod.h>
 
 #define SRAM_GRANULARITY	32
 
@@ -334,12 +338,43 @@ static int sram_reserve_regions(struct sram_dev *sram, struct resource *res)
 	return ret;
 }
 
+static int atmel_securam_wait(void)
+{
+	struct regmap *regmap;
+	unsigned long timeout = jiffies + HZ;
+	u32 val;
+
+	regmap = syscon_regmap_lookup_by_compatible("atmel,sama5d2-secumod");
+	if (IS_ERR(regmap))
+		return -ENODEV;
+
+	regmap_read(regmap, AT91_SECUMOD_RAMRDY, &val);
+	while (!(val & AT91_SECUMOD_RAMRDY_READY) &&
+	       time_before(jiffies, timeout)) {
+		mdelay(10);
+		regmap_read(regmap, AT91_SECUMOD_RAMRDY, &val);
+	}
+	if (!time_before(jiffies, timeout))
+		return -ETIMEDOUT;
+
+	return 0;
+}
+
+#ifdef CONFIG_OF
+static const struct of_device_id sram_dt_ids[] = {
+	{ .compatible = "mmio-sram" },
+	{ .compatible = "atmel,sama5d2-securam", .data = atmel_securam_wait },
+	{}
+};
+#endif
+
 static int sram_probe(struct platform_device *pdev)
 {
 	struct sram_dev *sram;
 	struct resource *res;
 	size_t size;
 	int ret;
+	const struct of_device_id *match;
 
 	sram = devm_kzalloc(&pdev->dev, sizeof(*sram), GFP_KERNEL);
 	if (!sram)
@@ -384,6 +419,16 @@ static int sram_probe(struct platform_device *pdev)
 
 	platform_set_drvdata(pdev, sram);
 
+	match = of_match_node(sram_dt_ids, pdev->dev.of_node);
+	if (match->data) {
+		int (*init_func)(void);
+
+		init_func = match->data;
+		ret = init_func();
+		if (ret)
+			return ret;
+	}
+
 	dev_dbg(sram->dev, "SRAM pool: %zu KiB @ 0x%p\n",
 		gen_pool_size(sram->pool) / 1024, sram->virt_base);
 
@@ -405,13 +450,6 @@ static int sram_remove(struct platform_device *pdev)
 	return 0;
 }
 
-#ifdef CONFIG_OF
-static const struct of_device_id sram_dt_ids[] = {
-	{ .compatible = "mmio-sram" },
-	{}
-};
-#endif
-
 static struct platform_driver sram_driver = {
 	.driver = {
 		.name = "sram",
-- 
2.9.3

[toc] | [prev] | [next] | [standalone]


#1473689 — Re: [PATCH 5/5] misc: sram: add Atmel securam support

FromPhilipp Zabel <p.zabel@pengutronix.de>
Date2016-08-31 18:50 +0200
SubjectRe: [PATCH 5/5] misc: sram: add Atmel securam support
Message-ID<scgS5-4O7-9@gated-at.bofh.it>
In reply to#1473649
Hi Alexandre,

Am Mittwoch, den 31.08.2016, 18:11 +0200 schrieb Alexandre Belloni:
> The Atmel secure SRAM is connected to a security module and may be erased
> automatically under certain conditions. For that reason, it is necessary to
> wait for the security module to flag that SRAM accesses are allowed before
> accessing it.
> 
> Signed-off-by: Alexandre Belloni <alexandre.belloni@free-electrons.com>
> ---
> Cc: Arnd Bergmann <arnd@arndb.de>
> Cc: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
> Cc: Philipp Zabel <p.zabel@pengutronix.de>
> Cc: Vladimir Zapolskiy <vladimir_zapolskiy@mentor.com>
>  drivers/misc/sram.c | 52 +++++++++++++++++++++++++++++++++++++++++++++-------
>  1 file changed, 45 insertions(+), 7 deletions(-)
> 
> diff --git a/drivers/misc/sram.c b/drivers/misc/sram.c
> index f84b53d6ce50..8d411c64d07f 100644
> --- a/drivers/misc/sram.c
> +++ b/drivers/misc/sram.c
> @@ -19,12 +19,16 @@
>   */
>  
>  #include <linux/clk.h>
> +#include <linux/delay.h>
>  #include <linux/genalloc.h>
>  #include <linux/io.h>
>  #include <linux/list_sort.h>
>  #include <linux/of_address.h>
>  #include <linux/platform_device.h>
> +#include <linux/regmap.h>
>  #include <linux/slab.h>
> +#include <linux/mfd/syscon.h>
> +#include <soc/at91/atmel-secumod.h>
>  
>  #define SRAM_GRANULARITY	32
>  
> @@ -334,12 +338,43 @@ static int sram_reserve_regions(struct sram_dev *sram, struct resource *res)
>  	return ret;
>  }
>  
> +static int atmel_securam_wait(void)
> +{
> +	struct regmap *regmap;
> +	unsigned long timeout = jiffies + HZ;

Can this really take up to a second?

> +	u32 val;
> +
> +	regmap = syscon_regmap_lookup_by_compatible("atmel,sama5d2-secumod");
> +	if (IS_ERR(regmap))
> +		return -ENODEV;
> +
> +	regmap_read(regmap, AT91_SECUMOD_RAMRDY, &val);
> +	while (!(val & AT91_SECUMOD_RAMRDY_READY) &&
> +	       time_before(jiffies, timeout)) {
> +		mdelay(10);
> +		regmap_read(regmap, AT91_SECUMOD_RAMRDY, &val);
> +	}
> +	if (!time_before(jiffies, timeout))
> +		return -ETIMEDOUT;
> +
> +	return 0;

Could you use regmap_read_poll_timeout here?

> +}
> +
> +#ifdef CONFIG_OF
> +static const struct of_device_id sram_dt_ids[] = {
> +	{ .compatible = "mmio-sram" },
> +	{ .compatible = "atmel,sama5d2-securam", .data = atmel_securam_wait },
> +	{}
> +};
> +#endif
> +
>  static int sram_probe(struct platform_device *pdev)
>  {
>  	struct sram_dev *sram;
>  	struct resource *res;
>  	size_t size;
>  	int ret;
> +	const struct of_device_id *match;
>  
>  	sram = devm_kzalloc(&pdev->dev, sizeof(*sram), GFP_KERNEL);
>  	if (!sram)
> @@ -384,6 +419,16 @@ static int sram_probe(struct platform_device *pdev)
>  
>  	platform_set_drvdata(pdev, sram);
>  
> +	match = of_match_node(sram_dt_ids, pdev->dev.of_node);
> +	if (match->data) {

And of_device_get_match_data here?

> +		int (*init_func)(void);
> +
> +		init_func = match->data;
> +		ret = init_func();
> +		if (ret)
> +			return ret;
> +	}
> +
>  	dev_dbg(sram->dev, "SRAM pool: %zu KiB @ 0x%p\n",
>  		gen_pool_size(sram->pool) / 1024, sram->virt_base);
>  
> @@ -405,13 +450,6 @@ static int sram_remove(struct platform_device *pdev)
>  	return 0;
>  }
>  
> -#ifdef CONFIG_OF
> -static const struct of_device_id sram_dt_ids[] = {
> -	{ .compatible = "mmio-sram" },
> -	{}
> -};
> -#endif
> -
>  static struct platform_driver sram_driver = {
>  	.driver = {
>  		.name = "sram",

regards
Philipp

[toc] | [prev] | [next] | [standalone]


#1473722 — Re: [PATCH 5/5] misc: sram: add Atmel securam support

FromAlexandre Belloni <alexandre.belloni@free-electrons.com>
Date2016-08-31 19:10 +0200
SubjectRe: [PATCH 5/5] misc: sram: add Atmel securam support
Message-ID<schbs-59T-53@gated-at.bofh.it>
In reply to#1473689
On 31/08/2016 at 18:45:37 +0200, Philipp Zabel wrote :
> Hi Alexandre,
> 
> Am Mittwoch, den 31.08.2016, 18:11 +0200 schrieb Alexandre Belloni:
> > The Atmel secure SRAM is connected to a security module and may be erased
> > automatically under certain conditions. For that reason, it is necessary to
> > wait for the security module to flag that SRAM accesses are allowed before
> > accessing it.
> > 
> > Signed-off-by: Alexandre Belloni <alexandre.belloni@free-electrons.com>
> > ---
> > Cc: Arnd Bergmann <arnd@arndb.de>
> > Cc: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
> > Cc: Philipp Zabel <p.zabel@pengutronix.de>
> > Cc: Vladimir Zapolskiy <vladimir_zapolskiy@mentor.com>
> >  drivers/misc/sram.c | 52 +++++++++++++++++++++++++++++++++++++++++++++-------
> >  1 file changed, 45 insertions(+), 7 deletions(-)
> > 
> > diff --git a/drivers/misc/sram.c b/drivers/misc/sram.c
> > index f84b53d6ce50..8d411c64d07f 100644
> > --- a/drivers/misc/sram.c
> > +++ b/drivers/misc/sram.c
> > @@ -19,12 +19,16 @@
> >   */
> >  
> >  #include <linux/clk.h>
> > +#include <linux/delay.h>
> >  #include <linux/genalloc.h>
> >  #include <linux/io.h>
> >  #include <linux/list_sort.h>
> >  #include <linux/of_address.h>
> >  #include <linux/platform_device.h>
> > +#include <linux/regmap.h>
> >  #include <linux/slab.h>
> > +#include <linux/mfd/syscon.h>
> > +#include <soc/at91/atmel-secumod.h>
> >  
> >  #define SRAM_GRANULARITY	32
> >  
> > @@ -334,12 +338,43 @@ static int sram_reserve_regions(struct sram_dev *sram, struct resource *res)
> >  	return ret;
> >  }
> >  
> > +static int atmel_securam_wait(void)
> > +{
> > +	struct regmap *regmap;
> > +	unsigned long timeout = jiffies + HZ;
> 
> Can this really take up to a second?
> 

Well, probably not but it can take some time. My understanding is that
it can take up to almost half a second (4096 bytes at 8kHz). But quite
frankly, by the time linux is starting, the delay has probably already
expired so the while loop is unlikely to run.

-- 
Alexandre Belloni, Free Electrons
Embedded Linux and Kernel engineering
http://free-electrons.com

[toc] | [prev] | [next] | [standalone]


#1473651 — [PATCH 4/5] misc: sram: document new compatible

FromAlexandre Belloni <alexandre.belloni@free-electrons.com>
Date2016-08-31 18:20 +0200
Subject[PATCH 4/5] misc: sram: document new compatible
Message-ID<scgp5-4D4-31@gated-at.bofh.it>
In reply to#1473642
Add atmel,sama5d2-securam to the compatible list.

Signed-off-by: Alexandre Belloni <alexandre.belloni@free-electrons.com>
---
Cc: Rob Herring <robh+dt@kernel.org>
Cc: devicetree@vger.kernel.org
 Documentation/devicetree/bindings/sram/sram.txt | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/Documentation/devicetree/bindings/sram/sram.txt b/Documentation/devicetree/bindings/sram/sram.txt
index add48f09015e..068c2c03c38f 100644
--- a/Documentation/devicetree/bindings/sram/sram.txt
+++ b/Documentation/devicetree/bindings/sram/sram.txt
@@ -4,7 +4,7 @@ Simple IO memory regions to be managed by the genalloc API.
 
 Required properties:
 
-- compatible : mmio-sram
+- compatible : mmio-sram or atmel,sama5d2-securam
 
 - reg : SRAM iomem address range
 
-- 
2.9.3

[toc] | [prev] | [next] | [standalone]


#1477837 — Re: [PATCH 4/5] misc: sram: document new compatible

FromRob Herring <robh@kernel.org>
Date2016-09-06 23:50 +0200
SubjectRe: [PATCH 4/5] misc: sram: document new compatible
Message-ID<sewpI-7zd-23@gated-at.bofh.it>
In reply to#1473651
On Wed, Aug 31, 2016 at 06:11:07PM +0200, Alexandre Belloni wrote:
> Add atmel,sama5d2-securam to the compatible list.
> 
> Signed-off-by: Alexandre Belloni <alexandre.belloni@free-electrons.com>
> ---
> Cc: Rob Herring <robh+dt@kernel.org>
> Cc: devicetree@vger.kernel.org
>  Documentation/devicetree/bindings/sram/sram.txt | 2 +-
>  1 file changed, 1 insertion(+), 1 deletion(-)

Acked-by: Rob Herring <robh@kernel.org>

[toc] | [prev] | [next] | [standalone]


#1473655 — [PATCH 2/5] ARM: dts: at91: sama5d2: Add secumod node

FromAlexandre Belloni <alexandre.belloni@free-electrons.com>
Date2016-08-31 18:20 +0200
Subject[PATCH 2/5] ARM: dts: at91: sama5d2: Add secumod node
Message-ID<scgp5-4D4-43@gated-at.bofh.it>
In reply to#1473642
The sama5d2 has a security module, add its node.

Signed-off-by: Alexandre Belloni <alexandre.belloni@free-electrons.com>
---
 arch/arm/boot/dts/sama5d2.dtsi | 19 +++++++++++++++++++
 1 file changed, 19 insertions(+)

diff --git a/arch/arm/boot/dts/sama5d2.dtsi b/arch/arm/boot/dts/sama5d2.dtsi
index 353d0e5ec83b..b027e96e40ef 100644
--- a/arch/arm/boot/dts/sama5d2.dtsi
+++ b/arch/arm/boot/dts/sama5d2.dtsi
@@ -706,6 +706,11 @@
 						atmel,clk-output-range = <0 83000000>;
 					};
 
+					securam_clk: securam_clk {
+						#clock-cells = <0>;
+						reg = <51>;
+					};
+
 					i2s0_clk: i2s0_clk {
 						#clock-cells = <0>;
 						reg = <54>;
@@ -1029,6 +1034,15 @@
 				status = "disabled";
 			};
 
+			securam: sram@f8044000 {
+				compatible = "atmel,sama5d2-securam", "mmio-sram";
+				reg = <0xf8044000 0x40000>;
+				clocks = <&securam_clk>;
+				#address-cells = <1>;
+				#size-cells = <1>;
+				ranges = <0 0xf8044000 0x1420>;
+			};
+
 			rstc@f8048000 {
 				compatible = "atmel,sama5d3-rstc";
 				reg = <0xf8048000 0x10>;
@@ -1231,6 +1245,11 @@
 				clocks = <&pioA_clk>;
 			};
 
+			secumod@fc040000 {
+				compatible = "atmel,sama5d2-secumod", "syscon";
+				reg = <0xfc040000 0x100>;
+			};
+
 			tdes@fc044000 {
 				compatible = "atmel,at91sam9g46-tdes";
 				reg = <0xfc044000 0x100>;
-- 
2.9.3

[toc] | [prev] | [standalone]


Back to top | Article view | linux.kernel


csiph-web