Re: [PATCH v3 6/6] firmware: qcom: Add support for TEE based EFI-var client driver

From: Harshal Dev

Date: Mon Oct 05 2026 - 00:44:02 EST


Hi Krzysztof,

On 02-10-2026 11:16 am, Krzysztof Kozlowski wrote:
> On 01/10/2026 13:02, Harshal Dev wrote:
>> On Qualcomm SoC based platforms, UEFI stores EFI variables within the
>> Replay Protected Memory Block (RPMB) located within either the UFS,
>> eMMC or SPI-NOR storage. The RPMB key which is one-time programmed into
>> the storage controller to allow authentication of the RPMB frames is
>> generated by and only available to the Qualcomm Trusted Execution
>> Environment (QTEE).
>>
>> The legacy QSEECOM protocol used for communicating with the QTEE is
>> deprecated and replaced with the use-case agnostic SMCInvoke protocol
>> starting with the Qualcomm SM8x50 series. On platforms where the QSEECOM
>> still driver probes, it does not support a listener interface with QTEE
>> to enable writing of non-volatile EFI variables to the RPMB for UFS and
>> eMMC storage.
>> Therefore on such platforms, a TEE client driver which communicates with
>> QTEE via the SMCInvoke protocol implemented by the QCOMTEE driver (and
>> registered with the TEE subsystem) must be used to update such EFI
>> variables.
>>
>> Add support for a TEE based uefisecapp client driver which installs efivar
>> operations after obtaining an object reference to the uefisecapp service.
>> This enables the kernel/user-space to access or modify both volatile EFI
>> variables stored by the Secure Application (in-memory) and non-volatile
>> ones stored within RPMB.
>>
>> Signed-off-by: Harshal Dev <harshal.dev@xxxxxxxxxxxxxxxx>
>> ---
>> MAINTAINERS | 6 +
>> arch/arm64/configs/defconfig | 1 +
>> drivers/firmware/qcom/Kconfig | 31 ++
>> drivers/firmware/qcom/Makefile | 1 +
>> drivers/firmware/qcom/qcom_tee_uefisecapp.c | 636 ++++++++++++++++++++++++++++
>> 5 files changed, 675 insertions(+)
>>
>> diff --git a/MAINTAINERS b/MAINTAINERS
>> index 30c1cdd0fb38..7ccedad8d388 100644
>> --- a/MAINTAINERS
>> +++ b/MAINTAINERS
>> @@ -22981,6 +22981,12 @@ L: linux-arm-msm@xxxxxxxxxxxxxxx
>> S: Maintained
>> F: drivers/firmware/qcom/qcom_qseecom_uefisecapp.c
>>
>> +QUALCOMM TEE UEFISECAPP DRIVER
>> +M: Harshal Dev <harshal.dev@xxxxxxxxxxxxxxxx>
>> +L: linux-arm-msm@xxxxxxxxxxxxxxx
>> +S: Maintained
>> +F: drivers/firmware/qcom/qcom_tee_uefisecapp.c
>> +
>> QUALCOMM PINCTRL DRIVERS
>> M: Bartosz Golaszewski <brgl@xxxxxxxxxx>
>> L: linux-arm-msm@xxxxxxxxxxxxxxx
>> diff --git a/arch/arm64/configs/defconfig b/arch/arm64/configs/defconfig
>> index fce418fe6ff6..a8525878c679 100644
>> --- a/arch/arm64/configs/defconfig
>> +++ b/arch/arm64/configs/defconfig
>> @@ -277,6 +277,7 @@ CONFIG_IMX_SCU=y
>> CONFIG_QCOM_TZMEM_MODE_SHMBRIDGE=y
>> CONFIG_QCOM_QSEECOM=y
>> CONFIG_QCOM_QSEECOM_UEFISECAPP=y
>> +CONFIG_QCOM_TEE_UEFISECAPP=m
>
> I do not see how this change is relevant here. Adding a driver has
> nothing to do with defconfig. Drop or split.
>
> Not mentioning that nowhere is explained why you actually need it.

Ack, I will split this into a separate commit and provide a brief explanation
for this config.

Regards,
Harshal

>
>
> Best regards,
> Krzysztof