[PATCH v5 00/15] coco/TSM: Host-side Arm CCA IDE setup via connect/disconnect callbacks
From: "Aneesh Kumar K.V (Arm)" <aneesh.kumar@kernel.org>
Date: 2026-09-10 14:05:19
Also in:
kvmarm, linux-coco, lkml
This patch series implements the TSM ->connect() and ->disconnect() callbacks required for the Arm CCA IDE setup as per the RMM 2.0bet3 specification [1]. This patchset includes the host-side flow needed by connect/disconnect, including: - DA feature detection helpers - host TSM callback wiring and IDE stream allocation support - creation/registration of RMM pdev descriptors - RMM pdev communication helpers - pdev stop and teardown helpers for disconnect - pdev instantiation from the connect path - public key registration with RMM To support public-key handling from the device certificate chain, the series also includes the required X.509 parser updates. Testing / Usage To initiate the IDE setup: echo tsm0 > /sys/bus/pci/devices/$DEVICE/tsm/connect To disconnect: echo tsm0 > /sys/bus/pci/devices/$DEVICE/tsm/disconnect The series is based on: - https://lore.kernel.org/all/20260904095000.1184861-1-aneesh.kumar@kernel.org (local) - https://lore.kernel.org/all/20260907095942.1140734-1-suzuki.poulose@arm.com (local) Changes from v4: https://lore.kernel.org/all/20260427065121.916615-1-aneesh.kumar@kernel.org (local) * Update rmi_set_pub_key() based on the latest specification. * Rename structure members to match the specification. * Rebase on top of the latest dependent series. Changes from v3: https://lore.kernel.org/all/20260312080129.3483585-1-aneesh.kumar@kernel.org (local) * updated the patches to follow the RMM 2.0bet1 specification * reworked the host-side pdev lifecycle to better match the RMM 2.0bet1 flow, including common pdev state, root-port pdev support, and non-coherent stream setup and teardown * split PF0 setup into identity collection and conditional public-key installation, and gate DA enablement on RMI_FEATURE_REGISTER_2_DA * added coordinated handling for RMI_DEV_COMM_EXIT_STREAM_WAIT, along with stream connect/disconnect and stream key refresh/purge support during vdev teardown Changes from v2: rfc-v2 https://lore.kernel.org/all/20251027095602.1154418-1-aneesh.kumar@kernel.org (local) * rebase to latest kernel and core TSM changes * Address review feedback. v1: rfc-v1 https://lore.kernel.org/all/20250728135216.48084-1-aneesh.kumar@kernel.org (local) [1] https://developer.arm.com/documentation/den0137/2-0bet3/ [2] https://lore.kernel.org/all/20260303000207.1836586-1-dan.j.williams@intel.com (local) [3] https://lore.kernel.org/all/20260318155413.793430-1-steven.price@arm.com (local) [4] https://gitlab.arm.com/linux-arm/linux-cca.git cca/topics/cca-tdisp-upstream-rfc-v4 Cc: Alexey Kardashevskiy <redacted> Cc: Catalin Marinas <catalin.marinas@arm.com> Cc: Dan Williams <redacted> Cc: Jason Gunthorpe <jgg@ziepe.ca> Cc: Jonathan Cameron <jic23@kernel.org> Cc: Marc Zyngier <maz@kernel.org> Cc: Samuel Ortiz <redacted> Cc: Steven Price <steven.price@arm.com> Cc: Suzuki K Poulose <Suzuki.Poulose@arm.com> Cc: Will Deacon <will@kernel.org> Cc: Xu Yilun <redacted> Aneesh Kumar K.V (Arm) (12): coco: host: arm64: Prepare host TSM plumbing for IDE streams coco: host: arm64: Create RMM pdev objects for PCI endpoints coco: host: arm64: Add RMM pdev communication plumbing coco: host: arm64: Add RMM pdev stop and destroy helper coco: host: arm64: Register device public key with RMM coco: host: arm64: Initialize RMM pdev state for TDISP IDE connect coco: host: arm64: Coordinate peer stream waits during pdev communication coco: host: arm64: Connect RMM pdev streams for IDE devices coco: host: arm64: Refcount root-port pdevs used by IDE streams PCI/TSM: Move CMA DOE mailbox discovery out of pci_tsm_pf0_constructor() coco: host: arm64: Add NCOH_SYS stream support for RC endpoints coco: host: arm64: Enable PCI TSM connect callbacks Lukas Wunner (3): X.509: Make certificate parser public X.509: Parse Subject Alternative Name in certificates X.509: Move certificate length retrieval into new helper crypto/asymmetric_keys/x509_cert_parser.c | 9 + crypto/asymmetric_keys/x509_loader.c | 38 +- crypto/asymmetric_keys/x509_parser.h | 42 +- drivers/crypto/ccp/sev-dev-tsm.c | 13 + drivers/firmware/arm_rmm/rmi.c | 4 +- drivers/firmware/smccc/smccc.c | 6 + drivers/pci/tsm.c | 13 +- drivers/virt/coco/Kconfig | 2 + drivers/virt/coco/Makefile | 1 + drivers/virt/coco/arm-cca-host/Kconfig | 26 + drivers/virt/coco/arm-cca-host/Makefile | 5 + drivers/virt/coco/arm-cca-host/main.c | 461 ++++++++++++ drivers/virt/coco/arm-cca-host/rmi-da.c | 859 ++++++++++++++++++++++ drivers/virt/coco/arm-cca-host/rmi-da.h | 217 ++++++ include/keys/asymmetric-type.h | 2 + include/keys/x509-parser.h | 57 ++ include/linux/arm-rmi-cmds.h | 85 +++ include/linux/arm-smccc-rmi.h | 161 ++++ 18 files changed, 1940 insertions(+), 61 deletions(-) create mode 100644 drivers/virt/coco/arm-cca-host/Kconfig create mode 100644 drivers/virt/coco/arm-cca-host/Makefile create mode 100644 drivers/virt/coco/arm-cca-host/main.c create mode 100644 drivers/virt/coco/arm-cca-host/rmi-da.c create mode 100644 drivers/virt/coco/arm-cca-host/rmi-da.h create mode 100644 include/keys/x509-parser.h -- 2.43.0