[PATCH 0/3] crypto: ccp - two PSP init fixes, and the AMD BC-250
From: Mattia Tadini
Date: Sat Sep 19 2026 - 14:45:58 EST
The AMD BC-250 is a Zen 2 APU board (Cyan Skillfish) sold as surplus mining
hardware and now used as a small desktop by a fair number of people. It carries
an AMD Secure Processor at PCI 1022:143e that sp_pci_table[] does not match, so
the device has always been left unbound with its memory windows disabled.
Adding the ID turned out to need two fixes first, both of the same shape: the
driver decides what to bring up from the hardware capability register alone,
and then uses the psp_vdata pointers for those features without checking that
this device has them. On this board the two disagree, because the firmware
advertises a TEE whose ring never comes up.
Patch 1 is a NULL pointer dereference in the sysfs is_visible callback. It
oopses during probe. It needs no new hardware to be reachable in principle:
any device whose firmware sets the TEE capability bit while its psp_vdata
carries no tee data hits it, which today means pspv1 and pspv2 parts. I have
only observed it on the BC-250, so I have not added a stable tag - please add
one if you think it deserves it.
Patch 2 stops a failed optional sub-device from taking down the rest of the
PSP. Without it, a psp_vdata that deliberately omits TEE gets nothing at all,
platform access included.
Patch 3 adds the board. The register layout was read off the device rather
than assumed, and the numbers are in the commit message.
Tested on a BC-250 running 7.2.6. Before:
01:00.2 Encryption controller: AMD Device 143e
Memory at fe700000 [disabled] [size=1M]
Memory at fe884000 [disabled] [size=8K]
(no driver)
After:
ccp 0000:01:00.2: enabling device (0000 -> 0002)
ccp 0000:01:00.2: platform access enabled
ccp 0000:01:00.2: psp enabled
# cat /sys/bus/pci/devices/0000:01:00.2/bootloader_version
00.1c.01.02
with the platform mailbox answering commands. Dynamic boost control is probed
and cleanly rejected by this firmware, and HSTI reports nothing because the
security reporting capability bit is clear. There is no CCP crypto engine
behind this function: the version register at 0x100 reads back all ones.
The series is against v7.2.6 and touches only drivers/crypto/ccp/.
Mattia Tadini (3):
crypto: ccp - fix NULL dereference in psp_firmware_is_visible()
crypto: ccp - do not start PSP sub-devices without their vdata
crypto: ccp - add support for the AMD BC-250 secure processor
drivers/crypto/ccp/psp-dev.c | 8 ++++++--
drivers/crypto/ccp/sp-pci.c | 24 +++++++++++++++++++++++-
2 files changed, 29 insertions(+), 3 deletions(-)
--
2.55.0