Skip to content

Pil: nord, shikra and cacao - #45

Draft
pawarai123 wants to merge 51 commits into
qualcomm-linux:qcom-nextfrom
pawarai123:pil-cacao-shikra
Draft

pawarai123 wants to merge 51 commits into
qualcomm-linux:qcom-nextfrom
pawarai123:pil-cacao-shikra

Conversation

@pawarai123

Copy link
Copy Markdown
Contributor

No description provided.

Organizes PAS clock support under platform/$(PLATFORM_FLAVOR)/ so
future platforms can provide their own PAS clock implementation.

Signed-off-by: Jorge Ramirez-Ortiz <jorge.ramirez@oss.qualcomm.com>
Reviewed-by: Sumit Garg <sumit.garg@oss.qualcomm.com>
Move all Kodiak-specific logic and the PTA command handlers into
platform/kodiak/, and model each subsystem with a descriptor/ops
abstraction: every platform exposes a table via
qcom_pas_platform_subsys() that the generic pas_core.c drives.
Pure structural refactor.

Signed-off-by: Jorge Ramirez-Ortiz <jorge.ramirez@oss.qualcomm.com>
Reviewed-by: Sumit Garg <sumit.garg@oss.qualcomm.com>
Add qcom_clock_lucidevo_pll_enable(), a self-contained helper that
configures, locks and enables the main output of a Lucid-EVO PLL given its
register block base and a struct qcom_lucidevo_pll_config.

No caller yet; this provides the building block for per-processor PLL
bring-up.

Signed-off-by: Jorge Ramirez-Ortiz <jorge.ramirez@oss.qualcomm.com>
Reviewed-by: Sumit Garg <sumit.garg@oss.qualcomm.com>
Bring up the Compute DSP (CDSP0/1) via the PAS peripheral
authentication path on the Lemans platform.

Signed-off-by: Jorge Ramirez-Ortiz <jorge.ramirez@oss.qualcomm.com>
Reviewed-by: Sumit Garg <sumit.garg@oss.qualcomm.com>
Each PAS subsystem maps its controller window at runtime via
core_mmu_add_mapping(); these late mappings come from
CFG_RESERVED_VASPACE_SIZE and are never released. The six DSP windows
total ~146.5 MB but the previous 60 MB default fits only one, so
reserve 256 MB to cover them with headroom.

Signed-off-by: Jorge Ramirez-Ortiz <jorge.ramirez@oss.qualcomm.com>
Reviewed-by: Sumit Garg <sumit.garg@oss.qualcomm.com>
Add LPASS / ADSP (QDSP6 v68/v69) PAS bring-up for the Lemans platform
(IQ-9075-EVK), following the existing Lemans CDSP0/1 PAS + clock-driver
pattern and the Kodiak LPASS PTA layout.

Signed-off-by: Jorge Ramirez-Ortiz <jorge.ramirez@oss.qualcomm.com>
Reviewed-by: Sumit Garg <sumit.garg@oss.qualcomm.com>
After boot the static memory map is frozen at count + 5 entries, so
core_mmu_add_mapping() failed once those spare slots were exhausted.

Grow the map through the same realloc hook as every other add path,
re-resolving RES_VASPACE afterwards.

Signed-off-by: Jorge Ramirez-Ortiz <jorge.ramirez@oss.qualcomm.com>
Reviewed-by: Sumit Garg <sumit.garg@oss.qualcomm.com>
Add the IRIS video-codec PAS driver for lemans, mirroring the kodiak
venus driver (which already targets IRIS hardware). The lemans IRIS
register layout is identical: WRAPPER_TZ at IRIS+0xc0000 with the same
XTSS_SW_RESET / FW / CPA / NONPIX offsets.

Signed-off-by: Jorge Ramirez-Ortiz <jorge.ramirez@oss.qualcomm.com>
Reviewed-by: Sumit Garg <sumit.garg@oss.qualcomm.com>
Add PAS bring-up for the two general-purpose Hexagon DSPs on Lemans
(SA8775P): GP-DSP0 (TURINGGDSP, image id 39) and GP-DSP1 (TURINGGDSP1,
image id 40). This follows the same architecture as the existing
CDSP0/1, LPASS and IRIS subsystems.

Signed-off-by: Jorge Ramirez-Ortiz <jorge.ramirez@oss.qualcomm.com>
Reviewed-by: Sumit Garg <sumit.garg@oss.qualcomm.com>
The subsystem manages the Iris video core, so name the file and its
symbols accordingly to match the hardware it drives.

Signed-off-by: Jorge Ramirez-Ortiz <jorge.ramirez@oss.qualcomm.com>
Reviewed-by: Sumit Garg <sumit.garg@oss.qualcomm.com>
Move the PAS_ID_* definitions out of the per-platform target_config.h
files into the PTA's pas_data.h so they live in one place.

These IDs are really part of the PTA contract with the client rather
than a platform definition; centralizing them in the PTA is a first
step towards that abstraction.

Signed-off-by: Jorge Ramirez-Ortiz <jorge.ramirez@oss.qualcomm.com>
Reviewed-by: Sumit Garg <sumit.garg@oss.qualcomm.com>
Add io_read32_off()/io_write32_off() for reading/writing a 32-bit MMIO
register at a base address plus byte offset, and
io_read32_off_field()/io_write32_off_field() for getting/setting a
masked, shifted field within such a register.

Signed-off-by: Amirreza Zarrabi <amirreza.zarrabi@oss.qualcomm.com>
Add a driver for the Qualcomm Hardware Key Manager (HWKM), a hardware
IP block present on Qualcomm SoCs that manages cryptographic key slots
in a tamper-resistant key table. Keys stored in HWKM slots are never
exposed in plaintext to software above the security level they were
provisioned at; the hardware enforces per-slot access-control and
usage policies.

The driver exposes the following functionality to OP-TEE:

  - Hardware Unique Key (HUK): implements tee_otp_get_hw_unique_key()
    by performing a three-level key derivation using the SYSTEM_KDF
    command. A stable SKDK L3 mixing key is first derived from
    TZ_SKDK_L2 into the dedicated mixing key slot; the UKDK L3 KDK
    and the final L4 HUK are then derived with the mixing key folded
    in via BSVE.MKS_EN. Two Kconfig options control this behaviour:
    CFG_HWKM_HUK_MIX_SKDK (default y) enables the SKDK mixing step,
    and CFG_HWKM_HUK_FUSE_REGION_DIGEST (default 0x0) selects fuse
    regions whose SHA256 digest is bound into the KDF input.

  - Full command set: NIST_KEYGEN, SYSTEM_KDF, KEY_WRAP_EXPORT,
    KEY_UNWRAP_IMPORT, KEY_SLOT_CLEAR, KEY_SLOT_RDWR, and SET_TPKEY
    are all implemented and exposed through a transaction queue API.

Signed-off-by: Amirreza Zarrabi <amirreza.zarrabi@oss.qualcomm.com>
Acked-by: Sumit Garg <sumit.garg@oss.qualcomm.com>
Reviewed-by: Jorge Ramirez-Ortiz <jorge.ramirez@oss.qualcomm.com>
Add a MAINTAINERS entry for the new Qualcomm Hardware Key Manager
(HWKM) driver.

Signed-off-by: Amirreza Zarrabi <amirreza.zarrabi@oss.qualcomm.com>
Acked-by: Sumit Garg <sumit.garg@oss.qualcomm.com>
Reviewed-by: Jorge Ramirez-Ortiz <jorge.ramirez@oss.qualcomm.com>
Add the HWKM master register region base and size to the shared Hoya
architecture config so all Hoya-family targets can reference them, and
enable CFG_QCOM_HWKM by default for the lemans target.

Signed-off-by: Amirreza Zarrabi <amirreza.zarrabi@oss.qualcomm.com>
Acked-by: Sumit Garg <sumit.garg@oss.qualcomm.com>
Reviewed-by: Jorge Ramirez-Ortiz <jorge.ramirez@oss.qualcomm.com>
Standardize RNG driver naming and configuration across
QCOM platforms.Rename prng.c to qcom-csrng.c and consolidate
driver inclusion in the parent qcom/sub.mk with the
unified CFG_QCOM_CSRNG flag.This change simplifies the
driver structure and aligns with platform-agnostic
naming conventions.

The QCOM RNG IPs are confirmed by the hardware team to be
cryptographically secure (CSRNG), so the driver is named
qcom-csrng.c and enabled via CFG_QCOM_CSRNG to explicitly
reflect that the source is safe for key generation.

Update hoya chipset configurations to use the new
CFG_QCOM_CSRNG flag and configure QCOM_RNG_REG_BASE
for PRNG variant support, ensuring backward compatibility
while establishing consistent naming standards across
the codebase.

Force enable CFG_QCOM_CSRNG to use the hardware QRNG driver, and
disable CFG_WITH_SOFTWARE_PRNG whenever CFG_QCOM_CSRNG is enabled to
prevent fallback to the software PRNG.

Signed-off-by: Harikrishna <hart@qti.qualcomm.com>
Reviewed-by: Selvam Sathappan Periakaruppan <speriaka@qti.qualcomm.com>
Reviewed-by: Sumit Garg <sumit.garg@oss.qualcomm.com>
Configure QCOM_RNG_REG_BASE and enable the consolidated RNG driver
for the Bobcat family (ipq52xx).

Force enable CFG_QCOM_CSRNG to use the hardware QRNG driver, and
disable CFG_WITH_SOFTWARE_PRNG whenever CFG_QCOM_CSRNG is enabled to
prevent fallback to the software PRNG.

When HWRNG_PTA is enabled:
   - Configure HWRNG quality to 1024 bits entropy
   - Set HWRNG rate to 0 (unlimited)

Signed-off-by: Harikrishna <hart@qti.qualcomm.com>
Reviewed-by: Selvam Sathappan Periakaruppan <speriaka@qti.qualcomm.com>
Reviewed-by: Sumit Garg <sumit.garg@oss.qualcomm.com>
QCOM platforms manage secure watchdog via driver_init() without
framework registration. This is sufficient as QCOM currently
does not require HLOS control over the secure watchdog. The
implementation maintains separation between secure and
non-secure world watchdog management.

The implementation maps the watchdog base (QCOM_WDT_TMR_BASE)
into secure I/O memory, configures bark and bite timeouts
using a 32 KHz clock, registers a bark interrupt handler, and
services the watchdog by writing to the reset register.

Signed-off-by: Harikrishna <hart@qti.qualcomm.com>
Reviewed-by: Selvam Sathappan Periakaruppan <speriaka@qti.qualcomm.com>
Reviewed-by: Sumit Garg <sumit.garg@oss.qualcomm.com>
CFG_QCOM_SEC_WDOG is enabled in bobcat/arch.mk for
all Bobcat targets, with platform-specific watchdog
base addresses, interrupt IDs, and reset offsets
defined in the respective target_config.h files
(e.g., ipq96xx/ipq54xx and ipq52xx variants).

Signed-off-by: Harikrishna <hart@qti.qualcomm.com>
Reviewed-by: Selvam Sathappan Periakaruppan <speriaka@qti.qualcomm.com>
Reviewed-by: Sumit Garg <sumit.garg@oss.qualcomm.com>
The Camera ICP (Imaging Control Processor, PAS ID 33) firmware must be
loaded and authenticated by OP-TEE before CAMX can use the camera
subsystem on SA8775P / Lemans EVK. Without this support the kernel
camera driver fails to bring up the ICP and camera preview is
unavailable.

Add PAS reset ops for the ICP, register the subsystem in the PAS table.

Tested: camera preview use case exercised on Lemans EVK; ICP firmware
loads, authenticates and executes correctly with camera preview
confirmed functional end-to-end.

Signed-off-by: Ignatius Michael Jihan <mignatiu@qti.qualcomm.com>
TZDRAM and the DIAG log are currently protected by TF-A's static XPU
policy, duplicating values OP-TEE already owns. Move ownership to
OP-TEE for a single source of truth.

Add an XPU4 driver: xpu_protect_region() takes a region and access
policy, and resolves the XPU instance and a free resource group
itself. It has no external callers, so it stays static.

Both regions are protected from one service_init() call. DIAG log
protection is skipped when CFG_QCOM_DIAG_LOG is disabled, so an unused
buffer doesn't consume a resource group.

Compiles only when CFG_QCOM_XPUV4 is enabled.

Testing:
XPU resource-group registers matched the expected TZDRAM/DIAG log
ranges and permissions. Non-secure accesses raised XPU violations.

Tested-on: Hermosa (IPQ52xx)
Tested-on: Juhu (IPQ96xx)
Signed-off-by: Harikrishna <hart@qti.qualcomm.com>
Enable OP-TEE-owned XPU protection for TZDRAM and the DIAG log on the
Bobcat family (IPQ52xx, IPQ96xx), replacing TF-A's static policy for
these regions.

Tested-on: Hermosa (IPQ52xx)
Tested-on: Juhu (IPQ96xx)
Signed-off-by: Harikrishna <hart@qti.qualcomm.com>
A stale carveout could be reused across peripheral loads: shutdown
did not clear the cached MEM_SETUP coordinates, so a subsystem that
was stopped and reloaded without a fresh MEM_SETUP call would pass
the resulting VERIFY_IMAGE cross-check against physical memory it no
longer owns. qcom_pas_capabilities() also passed the wrong parameter
to pas_platform_capabilities(), reading the output flags field instead
of the caller-supplied pas_id.

Fix both ahead of the authentication work that builds on this code,
along with unrelated include and logging cleanup, so the feature
commits that follow stay focused on the feature. pas_lookup() is
exported for the same reason: later commits need it directly.

Signed-off-by: Selvam Sathappan Periakaruppan <speriaka@qti.qualcomm.com>
Assisted-by: Claude:sonnet-5
Reviewed-by: Jorge Ramirez-Ortiz <jorge.ramirez@oss.qualcomm.com>
PIL firmware images carry a Qualcomm MBN hash segment holding the
per-segment digest table, signature and certificate material the
PAS TA needs to authenticate an image before releasing the
peripheral from reset.

Introduce a parser for this segment so the authentication phases
that follow can consume a single, structured view of it rather than
each phase re-parsing the raw metadata buffer independently and
risking disagreement about region boundaries.

Signed-off-by: Selvam Sathappan Periakaruppan <speriaka@qti.qualcomm.com>
Assisted-by: Claude:sonnet-5
Reviewed-by: Jorge Ramirez-Ortiz <jorge.ramirez@oss.qualcomm.com>
A compromised REE could substitute firmware in the peripheral's
carveout between the point image metadata is accepted and the point
the peripheral is released from reset. Add a verification step that
re-hashes each loaded segment against the image's own digest table
and fails closed on any mismatch, so the peripheral only runs code
whose bytes match what was authenticated.

Provide it as a standalone capability so hash verification can be
enabled and reviewed independently of signature authentication.

Signed-off-by: Selvam Sathappan Periakaruppan <speriaka@qti.qualcomm.com>
Assisted-by: Claude:sonnet-5
Reviewed-by: Jorge Ramirez-Ortiz <jorge.ramirez@oss.qualcomm.com>
Segment-hash verification lives in the PTA but nothing invokes it
today, so a peripheral can be released from reset without any
TEE-side check that the firmware in its carveout is what was
authenticated. Bridge that gap: the TA captures a TEE-private copy
of the REE-supplied metadata at image-init time and drives the
verifier with it at reset time, so the REE cannot mutate the
metadata the check runs against between the two events.

Per-peripheral state is keyed by ID so concurrent bring-ups on the
same session do not clobber each other. Signature authentication is
left as a placeholder so segment-hash verification can land and be
reviewed without waiting on it.

Release the captured metadata when a peripheral is shut down, so it
does not remain allocated for the life of the session after the
peripheral it authenticated is torn down. The per-ID slot itself is
retained because slots are provisioned one per peripheral;
reclaiming it would break the capacity model when the same
peripheral is reloaded later.

Signed-off-by: Selvam Sathappan Periakaruppan <speriaka@qti.qualcomm.com>
Assisted-by: Claude:sonnet-5
Reviewed-by: Jorge Ramirez-Ortiz <jorge.ramirez@oss.qualcomm.com>
Enable CFG_QCOM_PAS_AUTH on Lemans so PIL images are authenticated
before the peripheral leaves reset. Segment-hash verification takes
effect immediately; signature authentication is a runtime step that
only engages once secure-boot fuses are blown, and is filled in
later in this series.

Signed-off-by: Selvam Sathappan Periakaruppan <speriaka@qti.qualcomm.com>
Assisted-by: Claude:sonnet-5
Reviewed-by: Jorge Ramirez-Ortiz <jorge.ramirez@oss.qualcomm.com>
…files

Nord was the only Wildcat chip in the tree, so its GIC base addresses
and DARE-TZ TZDRAM region settings were placed in the shared Wildcat
architecture layer.  Adding a second Wildcat chip with different
addresses makes the architecture layer the wrong home for them.

Move GICD_BASE and GICR_BASE from arch_config.h to
nord/target_config.h, and move the DARE-TZ TZDRAM region configuration
from qcom-arch.mk to nord/target.mk, so the shared Wildcat layer stays
chip-agnostic.  Add SPDX licence identifier to qcom-arch.mk while there.

Signed-off-by: Pawan Rai <pawarai@qti.qualcomm.com>
Reviewed-by: Harshal Dev <harshal.dev@oss.qualcomm.com>
Tested-by: Harshal Dev <harshal.dev@oss.qualcomm.com>
Reviewed-by: Jorge Ramirez-Ortiz <jorge.ramirez@oss.qualcomm.com>
Cacao is a Qualcomm XR chipset in the Wildcat architecture family,
featuring an octa-core Oryon CPU, a GICv4 interrupt controller, and
DARE-TZ in-line memory encryption managed by the TME root-of-trust.
OP-TEE runs in a DARE-TZ protected DRAM region and does not need a
separate DARE driver.

Testing: Tested on Rumi.

Signed-off-by: Pawan Rai <pawarai@qti.qualcomm.com>
Reviewed-by: Harshal Dev <harshal.dev@oss.qualcomm.com>
Tested-by: Harshal Dev <harshal.dev@oss.qualcomm.com>
Reviewed-by: Jorge Ramirez-Ortiz <jorge.ramirez@oss.qualcomm.com>
Add PLATFORM=qcom-cacao build to the CI.

Reviewed-by: Jorge Ramirez-Ortiz <jorge.ramirez@oss.qualcomm.com>
Signed-off-by: Pawan Rai <pawarai@qti.qualcomm.com>
Selvam (zelvam95) and others added 7 commits August 20, 2026 21:51
Shikra is a Qualcomm IoT chipset in the Bruin architecture family,
featuring a quad-core Cortex-A55 CPU and a GICv3 interrupt controller.

Tested optee boot-up on Shikra board.

Signed-off-by: Pawan Rai <pawarai@qti.qualcomm.com>
Reviewed-by: Jorge Ramirez-Ortiz <jorge.ramirez@oss.qualcomm.com>
Reviewed-by: Harshal Dev <harshal.dev@oss.qualcomm.com>
Tested-by: Harshal Dev <harshal.dev@oss.qualcomm.com>
Add PLATFORM=qcom-shikra build to the CI.

Signed-off-by: Pawan Rai <pawarai@qti.qualcomm.com>
Reviewed-by: Jorge Ramirez-Ortiz <jorge.ramirez@oss.qualcomm.com>
@pawarai123 pawarai123 changed the title Pil cacao shikra Pil cacao shikra and nord Aug 25, 2026
@pawarai123
pawarai123 force-pushed the pil-cacao-shikra branch 2 times, most recently from 0d4bb34 to e00b6e5 Compare August 27, 2026 13:49
@pawarai123 pawarai123 changed the title Pil cacao shikra and nord Pil: nord, shikra and cacao Aug 27, 2026
Taniya Das (taniyadas20) and others added 14 commits August 27, 2026 19:48
Add the clock and PAS bring-up support required to load the additional
DSP images on the Nord platform:

 - clock-qcom: add a Lucid-OLE PLL enable helper. Lucid-OLE reuses the
   Lucid-EVO register layout but packs PLL_L_VAL as an 8-bit L value plus
   separate 8-bit process-cal and ring-osc-cal fields, and requires the
   PLL_TEST_CTL* trim registers to be programmed, so it gets its own
   config struct and enable path.
 - clk_qcom: add QCOM_CLKS_{SOCCP,HPASS0,HPASS1,HPASS2,TURING2,TURING3}
   clock groups and route them through the PAS enable path.
 - pas_data: add PAS IDs for TURING2/3, HPASS0-2 and SOCCP.
 - nord: add the per-platform clock-qcom-pas.c and clock_group_qcom.h
   describing the PLL and clock-group configuration for these subsystems.
 - arch/target config: add the register base/size definitions needed by
   the new bring-up code.

Change-Id: I50499c920aa97c792fe5d2856946a0dae8285ab0
Signed-off-by: Taniya Das <taniya.das@oss.qualcomm.com>
Enable the full PAS (Peripheral Authentication Service) framework for
the Nord platform to support PIL firmware authentication:

 - CFG_DRIVERS_CLK / CFG_DRIVERS_QCOM_CLK: enable the clock driver
   framework needed for PAS peripheral bring-up sequences
 - CFG_QCOM_QFPROM_FUSEPROV / CMD_DB / RPMH_CLIENT / QFPROM: enable
   fuse provisioning support (gated on !CFG_INSECURE) for future
   secure-boot fuse checks during signature authentication
 - CFG_QCOM_PAS_PTA: enables the PAS Pseudo-TA (S-EL1) which owns
   carveout mapping, segment hash verification, and clock/reset
   sequencing
 - CFG_QCOM_PAS_AUTH: enables per-segment SHA-256/384 hash verification
   at AUTH_AND_RESET time; a tampered firmware segment triggers
   TEE_ERROR_SECURITY and the DSP is never released from reset
 - CFG_PAS_MD_SLOTS=8: allows up to 8 concurrent per-peripheral
   metadata slots within one shared TEE session
 - CFG_IN_TREE_EARLY_TAS: registers the qcom_pas user TA
   (UUID cff7d191-7ca0-4784-af13-48223b9a4fbe) so Linux remoteproc
   can open a TEE session for PIL bring-up

Change-Id: I1181df76124b120dee1ec4705d0333400e07e76f
Signed-off-by: Pawan Rai <pawarai@qti.qualcomm.com>
Add the IRIS video-codec PAS platform for the Nord (SA8797P/Oryon)
chipset. This includes:
 - platform/nord/iris.c: firmware start/shutdown/set_state ops with
   SID table programming, memory region protection, and SCIBCMDARG3
   trigger ported from TZ nord/video_arch.c
 - platform/nord/subsys.c: single IRIS subsystem (PAS_ID 9),
   QCOM_PAS_RESET_NONE as clocks are owned by HLOS
 - wildcat/nord/target_config.h: IRIS_BASE/SIZE register window
 - wildcat/nord/target.mk: enable CFG_QCOM_PAS_PTA and register
   qcom_pas as an early TA

Change-Id: Ic36b047cb6dfcbcad03ba1fbde4f87be1b62b866
Signed-off-by: Priyanka Gujjula <pgujjula@qti.qualcomm.com>
Enable the PIL firmware authentication framework for the Shikra platform:

 - CFG_QCOM_QFPROM_FUSEPROV / CMD_DB / RPMH_CLIENT / QFPROM: enable
   fuse provisioning support (gated on !CFG_INSECURE)
 - CFG_QCOM_PAS_PTA: enables the PAS Pseudo-TA (S-EL1) which owns
   carveout mapping, segment hash verification, and bring-up sequencing
 - CFG_QCOM_PAS_AUTH: enables per-segment SHA-256/384 hash verification
   at AUTH_AND_RESET time
 - CFG_PAS_MD_SLOTS=8: allows up to 8 concurrent per-peripheral
   metadata slots within one shared TEE session
 - CFG_IN_TREE_EARLY_TAS: registers the qcom_pas user TA
   (UUID cff7d191-7ca0-4784-af13-48223b9a4fbe) so Linux remoteproc
   can open a TEE session for PIL bring-up
 - platform/shikra/subsys.c: subsystem infrastructure with empty table;
   individual subsystems to be added by respective subsystem teams

Clock enablement (CFG_DRIVERS_CLK) is left disabled pending clock
driver support.

Change-Id: I74ab23235d43fcae900e5447741d2aef327016c7
Signed-off-by: Pawan Rai <pawarai@qti.qualcomm.com>
Enable the PIL firmware authentication framework for the Cacao platform:

 - CFG_QCOM_QFPROM_FUSEPROV / CMD_DB / RPMH_CLIENT / QFPROM: enable
   fuse provisioning support (gated on !CFG_INSECURE)
 - CFG_QCOM_PAS_PTA: enables the PAS Pseudo-TA (S-EL1) which owns
   carveout mapping, segment hash verification, and bring-up sequencing
 - CFG_QCOM_PAS_AUTH: enables per-segment SHA-256/384 hash verification
   at AUTH_AND_RESET time
 - CFG_PAS_MD_SLOTS=8: allows up to 8 concurrent per-peripheral
   metadata slots within one shared TEE session
 - CFG_IN_TREE_EARLY_TAS: registers the qcom_pas user TA
   (UUID cff7d191-7ca0-4784-af13-48223b9a4fbe) so Linux remoteproc
   can open a TEE session for PIL bring-up
 - platform/cacao/subsys.c: subsystem infrastructure with empty table;
   individual subsystems to be added by respective subsystem teams

Clock enablement (CFG_DRIVERS_CLK) is left disabled pending clock
driver support.

Change-Id: Iaa41c560b8245a31f9ed47f27ea3c80460896075
Signed-off-by: Pawan Rai <pawarai@qti.qualcomm.com>
Register the PAS bring-up for Nord's subsystems HPASS & NSPSS.
- hpass0-2: program the HPASS reset-EVB and TCSR EVB-select
  registers for each HPASS instance from its own base offset and
  TCSR stride index.
- nspss0-3: program the NSPSS reset-EVB register for each
  CDSP instance.
- subsys.c: register all subsystems (HPASS0-2, NSPSS0-3)
  with their PAS IDs, base/size and clock groups.

Change-Id: Ib222088c33e4c9ea0ca2dd66c640e7f2f7af15b5
Signed-off-by: “Deepak <kudee@qti.qualcomm.com>
Align the Qualcomm clock driver filenames with the clk-<vendor> naming
used by the rest of the clk subsystem, and with the clk_qcom.h header
they implement. No functional change.

Update sub.mk in the same commit so the tree still builds; renaming the
sources alone leaves srcs-y pointing at the old paths.

Signed-off-by: Naresh Nunna <nnunna@qti.qualcomm.com>
Assisted-by: Claude:claude-opus-5
Add an API to copy a resource's auxiliary data blob by resource ID.
For ARC resources this is the list of corner levels the rail
supports, which RPMh commands index into rather than accepting a raw
voltage. This is a prerequisite for the QUP SE clock driver's CX/MX
voltage vote, which resolves a rail's supported-corner ordinal list
via this API before voting a corner over RPMh.

copy_aux_data() previously clamped the copy to the caller's buffer and
returned success, so a caller with an undersized buffer received a
silently truncated blob it had no way to detect. Return
TEE_ERROR_SHORT_BUFFER with the required size instead, and copy
nothing. Both existing callers query metadata only (NULL data buffer,
zero length) and never reach this path.

Also fix cmd_db_get_entry_by_res_id() to clear result->len on the
zero-length-entry path, which cmd_db_get_aux() exercises.

Signed-off-by: Naresh Nunna <nnunna@qti.qualcomm.com>
Assisted-by: Claude:claude-opus-5
Register each QUPv3 serial-engine RCG on lemans as a standard struct
clk with no parent (clk_ops: enable/disable/set_rate/get_rate),
consumed on demand by a future TEE-side SPI/I2C driver via
qcom_clk_get_by_name() (this platform has no secure DT, so DT-based
acquire isn't available).

set_rate walks a per-domain frequency-config table (mux/divider/MND/
DFS-index), and votes a CX/MX voltage corner via RPMh around the rate
change -- raise before programming, lower after -- using an aggregate
reference-counted vote model. The voltage vote requires
cmd_db_get_addr()/cmd_db_get_aux() to resolve the rail's RPMh resource
address and its supported-corner ordinal list, so CFG_QCOM_CMD_DB/
CFG_QCOM_RPMH_CLIENT are now force-enabled whenever CFG_QCOM_CLK_BSP=y
(default y).

CX and MX are voted as a pair, so a failure between the two would
leave the rails disagreeing with the cached corner while the
no-change shortcut suppressed the corrective re-vote. Track that
mismatch and re-vote both rails on the next call.

The rail-vote backend lives in clk-qcom-vreg.c behind the
qcom_clk_vreg_vote() contract, so a non-RPMh target can supply its own
without touching the RCG walker. The per-target domain table and
frequency plans live in platform/<flavor>/clk-qcom-bsp.c, keeping the
filename flavor-generic so enabling CFG_QCOM_CLK_BSP on another target
needs no sub.mk change.

Known gap, documented but not blocking: the voltage vote is bypassed
on a hardware-driven DFS switch (it only covers explicit set_rate).

Change-Id: Ia7fa577837dbef2a078a8f8d676b0876b8c606f1
Signed-off-by: Naresh Nunna <nnunna@qti.qualcomm.com>
Assisted-by: Claude:claude-opus-5
The CBCR-to-CMD_RCGR distance used to derive one register's location
from another is not architectural: it is 8 bytes on lemans but not
constant across chipsets (nord's QUP SEs sit 0x10 apart, and nord's
QUPv3 wrapper 3 keeps no fixed relation at all). Deriving offsets that
way silently breaks on any target where the assumption doesn't hold.

Give struct qcom_clk_domain and struct qcom_clk_src_vote a full
physical address per register (cmd_rcgr_addr/cbcr_addr/vote_reg_addr)
instead of one GCC-relative offset each, matching how the reference
clock driver's own HWIO_<reg>_ADDR macros are built. Add struct
qcom_clk_window so a domain names the register window its addresses
fall inside rather than assuming a single global GCC base -- needed
because some targets split their QUP SEs across more than one clock
controller. The walker resolves each address against its domain's
window and bounds-checks it before use.

Convert lemans' header macros from GCC-relative offsets to
(GCC_BASE + offset) form to match, and update its BSP table to the
renamed struct fields. No functional change on lemans: GCC_BASE is
still the only window, and every resolved address is identical to the
previous offset-based one.

Signed-off-by: Naresh Nunna <nnunna@qti.qualcomm.com>
Assisted-by: Claude:claude-opus-5
Add Nord (wildcat) platform support for the QUPv3 serial-engine clock
walker: quadrant-controller GCC bases/windows, cmd_db AOP message-RAM
window and RPMh base, and the SOCCP PAS clock group needed by the
walker's RPMh/cmd_db client path.

Unlike lemans, Nord's cmd_db blob address is not fixed at build time --
AOP publishes it as a pointer word in AOP message RAM, so cmd_db_init()
reads that pointer and maps the blob on the fly via
core_mmu_add_mapping() instead of the static register_phys_mem()/
phys_to_virt() path lemans uses.

Change-Id: Ic2932695974d256a89c6ba6f795eaf3f08f6373f
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
The RPMh command MSGID encodes a MSG_LENGTH field describing the
payload length, in bytes, of the command. This field was hardcoded
to 1 which is leading to unpredictable behavior on the
AOP side (including the command never being acknowledged, causing timeouts).

Changing it to 8 (the correct length for the single 32-bit data
word every RPMh command carries), introducing macros MSGID_MSG_LENGTH_VALUE,
MSGID_WRITE, MSGID_READ so the expected encoding is explicit.

Using MSGID_WRITE since it's a write command.

Signed-off-by: Shivam Sanjay <shivsanj@qti.qualcomm.com>
Nord has two independent Camera ICP (Imaging Control Processor)
instances (PAS ID 33/50) that must be loaded and authenticated by
OP-TEE before CAMX can use the camera subsystem, unlike lemans's
single Titan SS block. Without this support the kernel camera driver
fails to bring up the ICPs.

Add PAS reset ops for both ICPs and register them in the PAS table,
building on optee_os#43's nord PIL/PAS bring-up.

Validation: pending - not yet tested on hardware.

Change-Id: Iccb7451a05ba6092fe8815926ef9cc55ee97239b
Signed-off-by: Ignatius Michael Jihan <mignatiu@qti.qualcomm.com>
@zelvam95

Selvam (zelvam95) commented Aug 30, 2026

Copy link
Copy Markdown
Contributor

What is the goal of this PR pawarai123? Can we please split it per target? Separate PR for Nord/Shikra & Cacao? This PR currently has ~7000 lines of code.

Also, If this PR is still not tested, could you please consider moving it to draft? (Only if its not tested/not yet ready for review)

@b49020
Sumit Garg (b49020) force-pushed the qcom-next branch 2 times, most recently from 1a117cb to dab3efd Compare September 7, 2026 07:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.