Received: by 2002:a05:6a10:7420:0:0:0:0 with SMTP id hk32csp4657257pxb; Tue, 22 Feb 2022 03:40:24 -0800 (PST) X-Google-Smtp-Source: ABdhPJzsIGqleq65STS44r90LRKEOK8EkjIhULgdww3pXNJMcZ3p6PYx2Bp34e1jFkDvQtYTRuiI X-Received: by 2002:a17:907:58e:b0:6ce:375a:4b8d with SMTP id vw14-20020a170907058e00b006ce375a4b8dmr18728333ejb.107.1645530023976; Tue, 22 Feb 2022 03:40:23 -0800 (PST) ARC-Seal: i=1; a=rsa-sha256; t=1645530023; cv=none; d=google.com; s=arc-20160816; b=FGUINtg4Q8fI8n2Qya9HvXOMk+EKOBj9uhYjS8pt4vRWLPEY5OC7IzF0XJU+WjgFtF WOOe0spibIOYaBYVMiOszjHdpFNN2fPzDqgtodWZiws+BdM53ZgSWDQtMR/jENKw3IJv /tw2xvNp+agzGlg53R1wtCcyA6KJNXzLOlhQbp7tf5vhjcJGOq0YK+W/RAxPmCCV0dRj 0sp7QSvBmmyeXprChOAyINWrSyKsso8jCAfV52sHCwFsxVzu+wcb2rC4bfu4/hmnGJuT 88Jg4kK2jXRLovlFK7nIVIK/qXuMTqlxJuwkbht4fCo7R6VtKh54cbHR7dBLOGhVGas+ YVQg== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:content-transfer-encoding:in-reply-to :content-language:references:cc:to:subject:from:user-agent :mime-version:date:message-id; bh=6bv158uIV2xT8RZjFmiuOJ2D7BoKQ804qu/PB8TfbMg=; b=QG2zOPVqUCAYVLVvUZzTWvabNyejG552ffWjEAD2e5lt8WpZmRreq6MTj+Phi7DJFt GHbovOI07+RD6zJOhCe1rt4l9HZRqmc/6U0RGYAcZz6JA7sIkun/nOqvQ6KQ/n/iI8aw mcylZ/GY4Pt8DxNB4zxpgPaFxlDiiPHbt/6iGYRkcNkso24f//n2zSr15U19qxpovUe3 KBXdT6SdVvIkAD03Sn2MO+uJcbjkJGTTSnHIzBbP4qVRAGhbDcM5uSQ9fhC0IbTWk59f 6j/11TdEIUFztQhl70Ezsxakex+yfwDLMzS+4imFMJAWX/WhvtMQ5DPbpuLSkTtsNL5e +PSQ== ARC-Authentication-Results: i=1; mx.google.com; spf=pass (google.com: domain of linux-crypto-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-crypto-owner@vger.kernel.org Return-Path: Received: from out1.vger.email (out1.vger.email. [2620:137:e000::1:20]) by mx.google.com with ESMTP id j19si12563747eds.373.2022.02.22.03.39.50; Tue, 22 Feb 2022 03:40:23 -0800 (PST) Received-SPF: pass (google.com: domain of linux-crypto-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) client-ip=2620:137:e000::1:20; Authentication-Results: mx.google.com; spf=pass (google.com: domain of linux-crypto-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-crypto-owner@vger.kernel.org Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S231709AbiBVLZu (ORCPT + 99 others); Tue, 22 Feb 2022 06:25:50 -0500 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:50946 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S230268AbiBVLZn (ORCPT ); Tue, 22 Feb 2022 06:25:43 -0500 Received: from metis.ext.pengutronix.de (metis.ext.pengutronix.de [IPv6:2001:67c:670:201:290:27ff:fe1d:cc33]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id 830E9131942 for ; Tue, 22 Feb 2022 03:25:18 -0800 (PST) Received: from gallifrey.ext.pengutronix.de ([2001:67c:670:201:5054:ff:fe8d:eefb] helo=[127.0.0.1]) by metis.ext.pengutronix.de with esmtp (Exim 4.92) (envelope-from ) id 1nMTHb-0000ST-9t; Tue, 22 Feb 2022 12:24:39 +0100 Message-ID: Date: Tue, 22 Feb 2022 12:24:33 +0100 MIME-Version: 1.0 User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:91.0) Gecko/20100101 Thunderbird/91.5.0 From: Ahmad Fatoum Subject: Re: [EXT] Re: [PATCH v4 5/5] KEYS: trusted: Introduce support for NXP CAAM-based trusted keys To: Pankaj Gupta , Matthias Schiffer Cc: David Gstir , Aymen Sghaier , "linux-doc@vger.kernel.org" , Mimi Zohar , Jan Luebbe , "keyrings@vger.kernel.org" , Udit Agarwal , Herbert Xu , Horia Geanta , Jonathan Corbet , Richard Weinberger , James Morris , Eric Biggers , Jarkko Sakkinen , James Bottomley , "Serge E. Hallyn" , "tharvey@gateworks.com" , Franck Lenormand , Sumit Garg , David Howells , "linux-kernel@vger.kernel.org" , "linux-security-module@vger.kernel.org" , "linux-crypto@vger.kernel.org" , "kernel@pengutronix.de" , "linux-integrity@vger.kernel.org" , "David S. Miller" References: <59f1f3e6-fcf1-794d-610c-674b826822bf@pengutronix.de> <4decdfb7d4395e967e1bf6c65212616400c8064a.camel@ew.tq-group.com> Content-Language: en-US In-Reply-To: Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit X-SA-Exim-Connect-IP: 2001:67c:670:201:5054:ff:fe8d:eefb X-SA-Exim-Mail-From: a.fatoum@pengutronix.de X-SA-Exim-Scanned: No (on metis.ext.pengutronix.de); SAEximRunCond expanded to false X-PTX-Original-Recipient: linux-crypto@vger.kernel.org X-Spam-Status: No, score=-4.2 required=5.0 tests=BAYES_00,NICE_REPLY_A, RCVD_IN_DNSWL_MED,SPF_HELO_NONE,SPF_PASS,T_SCC_BODY_TEXT_LINE autolearn=unavailable autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on lindbergh.monkeyblade.net Precedence: bulk List-ID: X-Mailing-List: linux-crypto@vger.kernel.org Hello Pankaj, On 22.02.22 05:30, Pankaj Gupta wrote: > Hi Ahmad, > > >> -----Original Message----- >> From: Matthias Schiffer >> Sent: Monday, December 13, 2021 7:11 PM >> To: Ahmad Fatoum >> >>> For now, this is pointed out in the documentation. If you have a >>> suggestion on a specific condition we should check and issue a >>> diagnostic on, I can incorporate it. An exhaustive if >>> WARN_ON(!secure()) is impossible, but having some warning for >>> unsuspecting users would indeed be nice. >> >> I don't know of any condition that doesn't involve looking at SoC- specific OTP >> registers - that's what U-Boot does to determine whether HAB is enabled... >> > > Check the value fetched from the SEC Status Register (SSTA) (Offset 0xFD4h, bit 8,9 => 00b - Non-Secure, 01b - Secure, 10b - Trusted, 11b - Fail), for MOO (Mode of Operation). > And the warning can be issued accordingly. > > It is to be noted that this register is part of CAAM page0, which might not be accessible to Linux, for all the iMX SoC(s). > > For other SoC(s), this can be added. Thanks for the pointer. I am only testing this with i.MX, so I'd prefer this be left as a future exercise for a Layerscape user. Thanks for your reviews. I collected them on Patches 2/5 and 4/5 for v5. Cheers, Ahmad -- Pengutronix e.K. | | Steuerwalder Str. 21 | http://www.pengutronix.de/ | 31137 Hildesheim, Germany | Phone: +49-5121-206917-0 | Amtsgericht Hildesheim, HRA 2686 | Fax: +49-5121-206917-5555 |