[PATCH RFC v2 00/10] firmware: riscv: add RPMI TEE service group transport

From: Amirreza Zarrabi

Date: Wed Oct 07 2026 - 23:34:16 EST


This RFC series adds the RISC-V RPMI TEE service group transport [1],
which provides RISC-V systems a mechanism for Linux to communicate
with TEE endpoints. Linux and a TEE act as endpoints of the RPMI TEE
service group, while the RPMI framework in machine-mode firmware
mediates communication between them over an SBI MPXY [2] mailbox
channel.

The series is layered as follows:

- Two mailbox patches add a direct synchronous send mode
(mbox_send_message_sync()) and its implementation for RPMI MPXY
channels, needed because RPMI TEE requests must complete
synchronously in the calling context.

- The RPMI TEE bus registers one device per discovered TEE endpoint
and service UUID pair, following the device-per-service model,
so individual service drivers can bind independently.

- The RPMI TEE transport core binds to the mailbox channel and
validates the RPMI and TEE service-group versions before any
discovery or service traffic is attempted.

- Discovery uses PROBE_SYSTEM, PROBE_DOMAIN and PROBE_ENDPOINT to
obtain the local endpoint identity and enumerate physical TEE
endpoints and their services.

- Memory parcel operations (lend, share, reclaim) let a consumer
driver share memory with a TEE endpoint. Linux creates a parcel and
the parcel identifier is then used by the consumer's own protocol to
refer to that memory.

- Signal buses let a consumer driver exchange asynchronous
notifications with its TEE endpoint in both directions.

This series only establishes the transport, bus, and discovery layer.
An OP-TEE backend using these interfaces has been posted as a separate
series [3].

Feedback on the overall architecture, the bus/device model, and the
memory-parcel and signal-bus abstractions is especially welcome at
this stage in this RFC series.

[1] https://github.com/riscv-non-isa/riscv-rpmi/commits/main/src/srvgrp-tee.adoc
[2] https://github.com/riscv-non-isa/riscv-sbi-doc/releases
[3] https://lore.kernel.org/op-tee/20261005-rpmi-tee-service-grp-dev-v2-0-72f222e23ec1@xxxxxxxxxxxxxxxx

Signed-off-by: Amirreza Zarrabi <amirreza.zarrabi@xxxxxxxxxxxxxxxx>
---
Changes in v2:
- Fix memory-block address encoding to preserve the full physical address.
- Report the blocks included in the initial segmented CREATE request,
rather than the total parcel block count.
- Correct the CREATE block-count documentation and remove an unused
include.
- Stop signal retrieval during shutdown so continuously arriving signals
cannot prevent the notification workqueue from draining.
- Drain notification callbacks before unregistering child devices, including
on partial registration failure. Keep the mailbox and signal buses
available until client removal completes.
- Allocate signal-bus state before firmware setup and use automatic
cleanup on setup failure.
- Skip disabled System-MSI nodes when locating the notification IRQ
controller.
- Add rpmi_tee_info_ops.msg_limits_get() to expose maximum TEE_CALL
request and response payload sizes, excluding transport headers.
- Cache TEE_CALL payload limits during transport initialization and reuse
them for capability reporting and call bounds checking.
- Include missing <linux/idr.h> for the RPMI TEE bus's IDA APIs.
- Replace SYSINFO descriptor-table discovery with PROBE_SYSTEM,
PROBE_DOMAIN and PROBE_ENDPOINT, and update service and feature
identifiers to match the revised RPMI TEE specification.
- Move discovery into discovery.c and shared internal declarations into
rpmi_tee_private.h.
- Store discovered endpoints and their service UUIDs in per-endpoint list
entries, avoiding array reallocations.
- Link to v1: https://lore.kernel.org/r/20260928-riscv-rpmi-tee-abi-v1-0-04908b81d885@xxxxxxxxxxxxxxxx

---
Amirreza Zarrabi (10):
mailbox: add direct synchronous send support
mailbox: mpxy: add direct synchronous send
firmware: add RPMI TEE bus support
dt-bindings: firmware: add RISC-V RPMI TEE transport
firmware: add RPMI TEE transport core
firmware: riscv: rpmi-tee: discover TEE endpoints
firmware: riscv: rpmi-tee: register TEE services and support calls
firmware: riscv: rpmi-tee: cache TEE capabilities
firmware: riscv: rpmi-tee: add memory parcel operations
firmware: riscv: rpmi-tee: add signal bus support

.../bindings/firmware/riscv,rpmi-tee.yaml | 35 +
drivers/firmware/Kconfig | 2 +
drivers/firmware/Makefile | 1 +
drivers/firmware/riscv_rpmi_tee/Kconfig | 8 +
drivers/firmware/riscv_rpmi_tee/Makefile | 8 +
drivers/firmware/riscv_rpmi_tee/bus.c | 202 +++
drivers/firmware/riscv_rpmi_tee/discovery.c | 383 +++++
drivers/firmware/riscv_rpmi_tee/driver.c | 1583 ++++++++++++++++++++
drivers/firmware/riscv_rpmi_tee/rpmi_tee_private.h | 128 ++
drivers/mailbox/mailbox.c | 72 +-
drivers/mailbox/riscv-sbi-mpxy-mbox.c | 196 ++-
include/linux/mailbox/riscv-rpmi-message.h | 13 +
include/linux/mailbox_client.h | 3 +
include/linux/mailbox_controller.h | 10 +
include/linux/rpmi_tee.h | 200 +++
15 files changed, 2772 insertions(+), 72 deletions(-)
---
base-commit: 6375e61c01e93e35ee7acd336a689ac1fae4b509
change-id: 20260928-riscv-rpmi-tee-abi-603e9a3b4399

Best regards,
--
Amirreza Zarrabi <amirreza.zarrabi@xxxxxxxxxxxxxxxx>