[PATCH 0/3] media: qcom: Skip SCM secure memory protection with OP-TEE PAS backend

From: Sumit Garg

Date: Fri Sep 11 2026 - 08:47:18 EST


The Qualcomm peripheral authentication service (PAS) can be serviced by
either the SCM (TrustZone) backend or, on OP-TEE based platforms, by the
OP-TEE backend. qcom_scm_mem_protect_video_var() is only implemented by
the SCM backend; with OP-TEE the TEE itself owns secure memory
protection and does not service this call. Issuing it unconditionally on
an OP-TEE backend fails firmware bring-up for the venus and iris video
codecs.

To let consumers make this distinction, patch 1 exposes the name of the
active PAS backend via a new qcom_pas_get_backend() helper and adds
QCOM_PAS_BACKEND_SCM/QCOM_PAS_BACKEND_TEE identifiers for them to match
against.

Patches 2 and 3 use this helper in the iris and venus drivers to skip
the SCM-only qcom_scm_mem_protect_video_var() call when a non-SCM
backend (e.g. OP-TEE) is active, leaving the SCM path unchanged.

No functional change is intended for the SCM backend.

Signed-off-by: Sumit Garg <sumit.garg@xxxxxxxxxxxxxxxx>
---
Jorge Ramirez-Ortiz (2):
firmware: qcom: pas: Expose the active PAS backend name
media: iris: Skip SCM call for non-SCM PAS backend

Sumit Garg (1):
media: venus: Skip SCM call for non-SCM PAS backend

drivers/firmware/qcom/qcom_pas.c | 8 ++++++++
drivers/firmware/qcom/qcom_pas_tee.c | 2 +-
drivers/firmware/qcom/qcom_scm.c | 2 +-
drivers/media/platform/qcom/iris/iris_firmware.c | 11 +++++++++++
drivers/media/platform/qcom/venus/firmware.c | 10 ++++++++++
include/linux/firmware/qcom/qcom_pas.h | 5 +++++
6 files changed, 36 insertions(+), 2 deletions(-)
---
base-commit: 08df884136f1c1197bab2a27814404fd329d9aac
change-id: 20260911-video-optee-pas-v1-c69298e840ca

Best regards,
--
Sumit Garg <sumit.garg@xxxxxxxxxx>