Re: [PATCH v2] tee: optee: ffa: support shared memory offsets on large-page kernels

From: Jens Wiklander

Date: Fri Oct 02 2026 - 09:27:50 EST


On Mon, Sep 21, 2026 at 2:25 PM Sumit Garg <sumit.garg@xxxxxxxxxx> wrote:
>
> On Thu, 10 Sep 2026 at 16:11:24 +0000, Mahantesh Salimath wrote:
> >OP-TEE FF-A memory objects use 4 KiB pages, while the kernel page
> >size may be larger. Consequently, tee_shm->offset can be greater than
> >or equal to FFA_PAGE_SIZE, but OP-TEE rejects such a value in
> >internal_offs.
> >
> >Do not encode the excess page offset in offs_low/offs_high. Those
> >fields describe the logical memref offset and are copied back into
> >tee_param->shm_offs on return. Folding the page offset into them breaks
> >parameter round trips when a memref is reused. They are also ignored by
> >the OPTEE_RPC_CMD_SHM_ALLOC response path, which uses only global_id and
> >internal_offs to construct the shared-memory mobj.
> >
> >Instead, start the FF-A descriptor at the 4 KiB page containing the
> >shared buffer, the same approach as optee_fill_pages_list() in the SMC
> >ABI. Store the remaining in-page offset in internal_offs and preserve
> >shm_offs in offs_low/offs_high. This keeps internal_offs within the
> >FF-A page size, maps RPC allocations at the correct address, and
> >preserves normal memref offsets across repeated invocations.
> >
> >Tested on ARMv8-A with 64 KiB PAGE_SIZE. OP-TEE OS ran as a secure
> >partition under Hafnium (SPMC) over FF-A. Verified registered shared
> >memory with tee_shm->offset >= 4 KiB, memref reuse on the same
> >TEEC_Operation, and RPC OPTEE_RPC_CMD_SHM_ALLOC (xtest regression
> >6007-6009). optee_hello_world, optee_aes, and xtest regression 1005,
> >1007, 1008, 4001-4003 and 6001-6003 also passed.
> >
> >Fixes: 4615e5a34b95 ("optee: add FF-A support")
> >Acked-by: Liming Sun <limings@xxxxxxxxxx>
> >Acked-by: James Hurley <jahurley@xxxxxxxxxx>
> >Acked-by: Dave Thompson <davthompson@xxxxxxxxxx>
> >Signed-off-by: Mahantesh Salimath <mahantesh@xxxxxxxxxx>
> >---
> >v2:
> >- Drop helper indirection; mask internal_offs inline (Sumit Garg)
> >- Keep a single ffa_offs local in optee_ffa_shm_register()
> >
> >Link: https://lore.kernel.org/lkml/20260904134732.1072541-1-mahantesh@xxxxxxxxxx/
> >
> > drivers/tee/optee/ffa_abi.c | 22 ++++++++++++++++++----
> > drivers/tee/optee/optee_msg.h | 4 ++--
> > 2 files changed, 20 insertions(+), 6 deletions(-)
>
> Reviewed-by: Sumit Garg <sumit.garg@xxxxxxxxxxxxxxxx>

Looks good. I'm picking this up.

Thanks,
Jens