Conversation
| bool "Bootloader" | ||
| select ARM64_DECODEFIQ if ARCH_ARM64_EXCEPTION_LEVEL = 3 | ||
| select IMX9_DDR_TRAINING if ARCH_ARM64_EXCEPTION_LEVEL = 3 | ||
| select IMX9_ELE |
Contributor
There was a problem hiding this comment.
why select IMX9_ELE
Author
There was a problem hiding this comment.
imx9_trdc.c calls imx9_ele_init() and builds under IMX9_BOOTLOADER, so it won't link without this:
https://github.com/apache/nuttx/blob/master/arch/arm64/src/imx9/imx9_trdc.c#L760
Same pattern as IMX9_AHAB_BOOT a few lines down:
https://github.com/apache/nuttx/blob/master/arch/arm64/src/imx9/Kconfig#L116
Contributor
There was a problem hiding this comment.
if so, let's remove the prompt string from option
royzah
force-pushed
the
imx9-rng
branch
3 times, most recently
from
September 19, 2026 16:39
e9abe14 to
6f61329
Compare
up_addrenv_va_to_pa() is declared in include/nuttx/arch.h but implemented only by armv7-a, so no arm64 port can map a virtual address to a physical one. A driver whose device addresses memory physically has nothing to call. The translation is asked of the MMU with AT S1E1R rather than walked in software, so it answers for whatever is actually mapped: any granule size, block or page, at any level, and it cannot drift from the tables in use. PAR_EL1 is one register per CPU, so nothing may run between the translation and reading the result. Interrupts are banked with it, so masking them locally is sufficient and SMP needs nothing further. Returns zero for an address that is not mapped for a privileged read, which is what the declaration in arch.h specifies. Note this differs from the armv7-a implementation, which returns the virtual address unchanged. Signed-off-by: Royyan Zahir <royzah@gmail.com>
…ual one. The ELE addresses memory physically; cache maintenance takes a virtual address. Both buffer calls supply one and use it for both, in opposite directions: get_random() runs up_flush_dcache() on a physical address, get_key() hands the enclave a virtual one. Both fail silently, and both are correct only while the two are equal. Take the virtual address in both, maintain the cache on it, and translate for the message. get_random() also gains the alignment check get_key() already has. Signed-off-by: Royyan Zahir <royzah@gmail.com>
The i.MX9 has a true random number generator behind the EdgeLock Enclave and imx9_ele_get_random() to reach it, but nothing registers a character device for it, so the entropy pool is never seeded from hardware. stm32h7, nrf52, lpc54xx and rp23xx all provide one; imx9 does not. imx9_ele.c was built only for CONFIG_IMX9_BOOTLOADER, putting the enclave out of reach of the application core. It moves behind a new CONFIG_IMX9_ELE that the bootloader selects, so existing configurations build as before. A transfer that never lands is silent, so the buffer is prefilled with a pattern and a block still holding it is refused, as is an all-zero block and, by the FIPS 140-2 continuous test, a repeat of the one before. Compiles for imx93-evk:nsh with CONFIG_IMX9_RNG=y. Signed-off-by: Royyan Zahir <royzah@gmail.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
imx9_ele_get_random()exists, but nothing registers a device for it, so the i.MX9 entropy pool is never seeded from hardware.stm32h7,nrf52,lpc54xxandrp23xxall ship this driver;imx9does not.Modelled on https://github.com/apache/nuttx/blob/master/arch/arm/src/stm32h7/stm32_rng.c
Two points for review:
imx9_ele.cbuilt only forCONFIG_IMX9_BOOTLOADER, putting the enclave out of reach of the application core. It moves behind a newCONFIG_IMX9_ELEthat the bootloader selects, so existing configs are unchanged.Impact
CONFIG_IMX9_RNG, off by default, registers/dev/randomand/dev/urandom. i.MX9 only, no existing defconfig changes behaviour.Depends on
The address-space fix in #20196, so the buffer reaches the enclave correctly under an MMU.
Testing
Compiles for
imx93-evk:nshwithCONFIG_IMX9_RNG=y,tools/nxstyleclean.That build is what caught the first version gating
IMX9_ELEonIMX9_HAVE_MU, which onlyARCH_CHIP_IMX95selects, so the driver was unselectable on the chip it is for.