Link: https://lore.kernel.org/r/20260217200002.683975158@linuxfoundation.org Tested-by: Florian Fainelli <florian.fainelli@broadcom.com> Tested-by: Takeshi Ogasawara <takeshi.ogasawara@futuring-girl.com> Tested-by: Peter Schneider <pschneider1968@googlemail.com> Tested-by: Jon Hunter <jonathanh@nvidia.com> Tested-by: Salvatore Bonaccorso <carnil@debian.org> Tested-by: Brett A C Sheffield <bacs@librecast.net> Tested-by: Mark Brown <broonie@kernel.org> Tested-by: Luna Jernberg <droidbittin@gmail.com> Tested-by: Ronald Warsow <rwarsow@gmx.de> Tested-by: Justin M. Forbes <jforbes@fedoraproject.org> Tested-by: Ron Economos <re@w6rz.net> Tested-by: Miguel Ojeda <ojeda@kernel.org> Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
33 lines
1.1 KiB
Plaintext
33 lines
1.1 KiB
Plaintext
# SPDX-License-Identifier: GPL-2.0-only
|
|
# OP-TEE Trusted Execution Environment Configuration
|
|
config OPTEE
|
|
tristate "OP-TEE"
|
|
depends on HAVE_ARM_SMCCC
|
|
depends on MMU
|
|
depends on RPMB || !RPMB
|
|
help
|
|
This implements the OP-TEE Trusted Execution Environment (TEE)
|
|
driver.
|
|
|
|
config OPTEE_INSECURE_LOAD_IMAGE
|
|
bool "Load OP-TEE image as firmware"
|
|
default n
|
|
depends on OPTEE && ARM64
|
|
help
|
|
This loads the BL32 image for OP-TEE as firmware when the driver is
|
|
probed. This returns -EPROBE_DEFER until the firmware is loadable from
|
|
the filesystem which is determined by checking the system_state until
|
|
it is in SYSTEM_RUNNING. This also requires enabling the corresponding
|
|
option in Trusted Firmware for Arm. The documentation there explains
|
|
the security threat associated with enabling this as well as
|
|
mitigations at the firmware and platform level.
|
|
https://trustedfirmware-a.readthedocs.io/en/latest/threat_model/threat_model.html
|
|
|
|
Additional documentation on kernel security risks are at
|
|
Documentation/tee/op-tee.rst.
|
|
|
|
config OPTEE_STATIC_PROTMEM_POOL
|
|
bool
|
|
depends on HAS_IOMEM && TEE_DMABUF_HEAPS
|
|
default y
|