DM-Crypt usage on i.MX Platforms without CAAM hardware IP

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

DM-Crypt usage on i.MX Platforms without CAAM hardware IP

460 Views
wooosaiiii
Contributor IV

Hi,

I am following a "DM-Crypt usage on i.MX Platforms without CAAM hardware IP" guide from NXP on i.MX93 board.

I am using the following steps:

modprobe dm-crypt
modprobe tee_crypto
modprobe trusted

export DEV=/dev/loop0
dd if=/dev/zero of=/data/encrypted.img bs=1M count=512
losetup -P $DEV /data/encrypted.img

export KEYNAME=dm_trustedkey
export KEY="$(keyctl add trusted $KEYNAME 'new 32' @s)"
keyctl pipe $KEY >/data/$KEYNAME.blob
keyctl list @s

export ALGO="capi:cbc-aes-tee-plain"
export BLOCKS=$(blockdev --getsz /dev/loop0)
export SECTOR_SIZE=4096
export TABLE="0 $BLOCKS crypt $ALGO :32:trusted:$KEYNAME 0 $DEV 0 1 sector_size:$SECTOR_SIZE"

dmsetup -v create encrypted --table "$TABLE"


However, my kernel crashes with the following OOPS:

[  713.174934] Unable to handle kernel paging request at virtual address ffff8000a1fca858
[  713.182908] Mem abort info:
[  713.185716]   ESR = 0x0000000096000006
[  713.189477]   EC = 0x25: DABT (current EL), IL = 32 bits
[  713.194786]   SET = 0, FnV = 0
[  713.197848]   EA = 0, S1PTW = 0
[  713.200993]   FSC = 0x06: level 2 translation fault
[  713.205873] Data abort info:
[  713.208762]   ISV = 0, ISS = 0x00000006, ISS2 = 0x00000000
[  713.214246]   CM = 0, WnR = 0, TnD = 0, TagAccess = 0
[  713.219296]   GCS = 0, Overlay = 0, DirtyBit = 0, Xs = 0
[  713.224611] swapper pgtable: 4k pages, 48-bit VAs, pgdp=0000000089bcd000
[  713.231309] [ffff8000a1fca858] pgd=10000000fffff003, p4d=10000000fffff003, pud=10000000ffffe003, pmd=0000000000000000
[  713.241943] Internal error: Oops: 0000000096000006 [#1] PREEMPT SMP
[  713.248199] Modules linked in: tee_crypto dm_crypt crct10dif_ce polyval_ce polyval_generic layerscape_edac_mod rtc_rv8803 at24 btnxpuart flexcan can_dev cfg80211 fuse overlay trusted
[  713.264459] CPU: 0 PID: 532 Comm: dmsetup Not tainted 6.6.52-lts-next-07235-gfdd32c7240b4 #1
[  713.272880] Hardware name: EVVA i.MX93 Gateway (DT)
[  713.277743] pstate: a0400009 (NzCv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)
[  713.284694] pc : osq_lock+0x5c/0x134
[  713.288270] lr : __mutex_lock.constprop.0+0x1f0/0x540
[  713.293317] sp : ffff800083543750
[  713.296616] x29: ffff800083543750 x28: ffff000001e3417a x27: 0000000000000001
[  713.303743] x26: ffff000000a43e00 x25: ffff000005b7dbf0 x24: 00000000ffffffff
[  713.310864] x23: 0000000000000002 x22: fffffc000002e4c0 x21: fffffc000002e884
[  713.317988] x20: ffff800083543768 x19: fffffc000002e878 x18: 0000000000000001
[  713.325112] x17: 0000000000000000 x16: 0000000000000000 x15: 0000000000000000
[  713.332239] x14: 0000000000000000 x13: 01485ce3a37a7a58 x12: ed352f5eedb722c0
[  713.339360] x11: 0101010101010101 x10: fffffffffa67a3b3 x9 : 0000000000000000
[  713.346484] x8 : ffff800083543920 x7 : 0000000000000000 x6 : 000000000000003f
[  713.353608] x5 : 0000000000000040 x4 : 0000000003fffbff x3 : ffff800081fcc860
[  713.360732] x2 : ffff800081cf0d00 x1 : ffff00007fb98d00 x0 : fffffc000002e884
[  713.367859] Call trace:
[  713.370294]  osq_lock+0x5c/0x134
[  713.373518]  __mutex_lock.constprop.0+0x1f0/0x540
[  713.378215]  __mutex_lock_slowpath+0x14/0x20
[  713.382479]  mutex_lock+0x48/0x54
[  713.385787]  tee_device_get+0x20/0x6c
[  713.389444]  register_shm_helper+0x3c/0x2e8
[  713.393624]  tee_shm_register_kernel_buf+0x18/0x24
[  713.398408]  skcipher_setkey+0xe8/0x21c [tee_crypto]
[  713.403374]  cbc_skcipher_setkey+0x38/0x7c [tee_crypto]
[  713.408589]  crypto_skcipher_setkey+0x6c/0x124
[  713.413029]  crypt_setkey+0x104/0x22c [dm_crypt]
[  713.417658]  crypt_set_key+0x248/0x360 [dm_crypt]
[  713.422354]  crypt_ctr+0x634/0xfb8 [dm_crypt]
[  713.426705]  dm_table_add_target+0x218/0x380
[  713.430969]  table_load+0x140/0x3f0
[  713.434453]  ctl_ioctl+0x378/0x648
[  713.437851]  dm_ctl_ioctl+0x10/0x20
[  713.441334]  __arm64_sys_ioctl+0xac/0xf0
[  713.445252]  invoke_syscall+0x48/0x114
[  713.448996]  el0_svc_common.constprop.0+0xc0/0xe0
[  713.453693]  do_el0_svc+0x1c/0x28
[  713.457001]  el0_svc+0x40/0xe4
[  713.460055]  el0t_64_sync_handler+0x120/0x12c
[  713.464402]  el0t_64_sync+0x190/0x194
[  713.468066] Code: 340005c4 51000484 d000f723 91218063 (f864d863) 
[  713.474147] ---[ end trace 0000000000000000 ]---
[  713.478800] note: dmsetup[532] exited with preempt_count 1


I am using 6.6.52_2.2.2 scarthgap release.

I think the problematic driver is drivers/tee/crypto/tee_skcipher.c.

Here is the output when loading the kernel module:

[  665.731673] tee_client_open_session failed, err: ffff0008
[  665.737206] tee_crypt algorithms registered in /proc/crypto
[  665.742835] driver 1.0 loaded.

 

The prerequisites from the document have been fulfilled in our BSP:

Prerequisites:
Ensure that a region of OCRAM is reserved to be accessed by Secure World only. This region is used to save cryptographic keys. Current OCRAM reserved regions:

For i.MX 93: 0x20518000 - 0x2051C000
For i.MX 95: 0x204BC000 - 0x204C0000
For i.MX 91: 0x204A0000 - 0x204A4000
For i.MX 943: 0x204BC000 - 0x204C0000

Make sure the following configurations are enabled in the kernel:
CONFIG_TEE_CRYPTO = m
CONFIG_DM_CRYPT = m
CONFIG_TRUSTED_KEYS = m
CONFIG_TRUSTED_KEYS_CAAM = n
CONFIG_TRUSTED_KEYS_TEE = y

In OP-TEE, check whether the following flags in the core/arch/arm/plat-imx/conf.mk platform specific section for which DM-crypt are enabled or not:
CFG_IMX_TRUSTED_ARM_CE = y
CFG_IN_TREE_EARLY_TAS += trusted_keys/f04a0fe7-1f5d-4b9b-abf7-619b85b4ce8c

Any ideas what might be an issue here?

Tags (4)
0 Kudos
Reply
1 Reply

442 Views
wooosaiiii
Contributor IV

Fixed it. I forgot to update optee blob when rebuilding with CFG_IMX_TRUSTED_ARM_CE = y.

Can be closed.

0 Kudos
Reply
%3CLINGO-SUB%20id%3D%22lingo-sub-2366863%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3EDM-Crypt%20usage%20on%20i.MX%20Platforms%20without%20CAAM%20hardware%20IP%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2366863%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CP%3EHi%2C%3C%2FP%3E%3CP%3EI%20am%20following%20a%20%22DM-Crypt%20usage%20on%20i.MX%20Platforms%20without%20CAAM%20hardware%20IP%22%20guide%20from%20NXP%20on%20i.MX93%20board.%3C%2FP%3E%3CP%3EI%20am%20using%20the%20following%20steps%3A%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FP%3E%3CPRE%20class%3D%22lia-code-sample%20language-c%22%3E%3CCODE%3Emodprobe%20dm-crypt%0Amodprobe%20tee_crypto%0Amodprobe%20trusted%0A%0Aexport%20DEV%3D%2Fdev%2Floop0%0Add%20if%3D%2Fdev%2Fzero%20of%3D%2Fdata%2Fencrypted.img%20bs%3D1M%20count%3D512%0Alosetup%20-P%20%24DEV%20%2Fdata%2Fencrypted.img%0A%0Aexport%20KEYNAME%3Ddm_trustedkey%0Aexport%20KEY%3D%22%24(keyctl%20add%20trusted%20%24KEYNAME%20'new%2032'%20%40s)%22%0Akeyctl%20pipe%20%24KEY%20%26gt%3B%2Fdata%2F%24KEYNAME.blob%0Akeyctl%20list%20%40s%0A%0Aexport%20ALGO%3D%22capi%3Acbc-aes-tee-plain%22%0Aexport%20BLOCKS%3D%24(blockdev%20--getsz%20%2Fdev%2Floop0)%0Aexport%20SECTOR_SIZE%3D4096%0Aexport%20TABLE%3D%220%20%24BLOCKS%20crypt%20%24ALGO%20%3A32%3Atrusted%3A%24KEYNAME%200%20%24DEV%200%201%20sector_size%3A%24SECTOR_SIZE%22%0A%0Admsetup%20-v%20create%20encrypted%20--table%20%22%24TABLE%22%3C%2FCODE%3E%3C%2FPRE%3E%3CP%3E%3CBR%20%2F%3EHowever%2C%20my%20kernel%20crashes%20with%20the%20following%20OOPS%3A%3C%2FP%3E%3CPRE%20class%3D%22lia-code-sample%20language-markup%22%3E%3CCODE%3E%5B%20%20713.174934%5D%20Unable%20to%20handle%20kernel%20paging%20request%20at%20virtual%20address%20ffff8000a1fca858%0A%5B%20%20713.182908%5D%20Mem%20abort%20info%3A%0A%5B%20%20713.185716%5D%20%20%20ESR%20%3D%200x0000000096000006%0A%5B%20%20713.189477%5D%20%20%20EC%20%3D%200x25%3A%20DABT%20(current%20EL)%2C%20IL%20%3D%2032%20bits%0A%5B%20%20713.194786%5D%20%20%20SET%20%3D%200%2C%20FnV%20%3D%200%0A%5B%20%20713.197848%5D%20%20%20EA%20%3D%200%2C%20S1PTW%20%3D%200%0A%5B%20%20713.200993%5D%20%20%20FSC%20%3D%200x06%3A%20level%202%20translation%20fault%0A%5B%20%20713.205873%5D%20Data%20abort%20info%3A%0A%5B%20%20713.208762%5D%20%20%20ISV%20%3D%200%2C%20ISS%20%3D%200x00000006%2C%20ISS2%20%3D%200x00000000%0A%5B%20%20713.214246%5D%20%20%20CM%20%3D%200%2C%20WnR%20%3D%200%2C%20TnD%20%3D%200%2C%20TagAccess%20%3D%200%0A%5B%20%20713.219296%5D%20%20%20GCS%20%3D%200%2C%20Overlay%20%3D%200%2C%20DirtyBit%20%3D%200%2C%20Xs%20%3D%200%0A%5B%20%20713.224611%5D%20swapper%20pgtable%3A%204k%20pages%2C%2048-bit%20VAs%2C%20pgdp%3D0000000089bcd000%0A%5B%20%20713.231309%5D%20%5Bffff8000a1fca858%5D%20pgd%3D10000000fffff003%2C%20p4d%3D10000000fffff003%2C%20pud%3D10000000ffffe003%2C%20pmd%3D0000000000000000%0A%5B%20%20713.241943%5D%20Internal%20error%3A%20Oops%3A%200000000096000006%20%5B%231%5D%20PREEMPT%20SMP%0A%5B%20%20713.248199%5D%20Modules%20linked%20in%3A%20tee_crypto%20dm_crypt%20crct10dif_ce%20polyval_ce%20polyval_generic%20layerscape_edac_mod%20rtc_rv8803%20at24%20btnxpuart%20flexcan%20can_dev%20cfg80211%20fuse%20overlay%20trusted%0A%5B%20%20713.264459%5D%20CPU%3A%200%20PID%3A%20532%20Comm%3A%20dmsetup%20Not%20tainted%206.6.52-lts-next-07235-gfdd32c7240b4%20%231%0A%5B%20%20713.272880%5D%20Hardware%20name%3A%20EVVA%20i.MX93%20Gateway%20(DT)%0A%5B%20%20713.277743%5D%20pstate%3A%20a0400009%20(NzCv%20daif%20%2BPAN%20-UAO%20-TCO%20-DIT%20-SSBS%20BTYPE%3D--)%0A%5B%20%20713.284694%5D%20pc%20%3A%20osq_lock%2B0x5c%2F0x134%0A%5B%20%20713.288270%5D%20lr%20%3A%20__mutex_lock.constprop.0%2B0x1f0%2F0x540%0A%5B%20%20713.293317%5D%20sp%20%3A%20ffff800083543750%0A%5B%20%20713.296616%5D%20x29%3A%20ffff800083543750%20x28%3A%20ffff000001e3417a%20x27%3A%200000000000000001%0A%5B%20%20713.303743%5D%20x26%3A%20ffff000000a43e00%20x25%3A%20ffff000005b7dbf0%20x24%3A%2000000000ffffffff%0A%5B%20%20713.310864%5D%20x23%3A%200000000000000002%20x22%3A%20fffffc000002e4c0%20x21%3A%20fffffc000002e884%0A%5B%20%20713.317988%5D%20x20%3A%20ffff800083543768%20x19%3A%20fffffc000002e878%20x18%3A%200000000000000001%0A%5B%20%20713.325112%5D%20x17%3A%200000000000000000%20x16%3A%200000000000000000%20x15%3A%200000000000000000%0A%5B%20%20713.332239%5D%20x14%3A%200000000000000000%20x13%3A%2001485ce3a37a7a58%20x12%3A%20ed352f5eedb722c0%0A%5B%20%20713.339360%5D%20x11%3A%200101010101010101%20x10%3A%20fffffffffa67a3b3%20x9%20%3A%200000000000000000%0A%5B%20%20713.346484%5D%20x8%20%3A%20ffff800083543920%20x7%20%3A%200000000000000000%20x6%20%3A%20000000000000003f%0A%5B%20%20713.353608%5D%20x5%20%3A%200000000000000040%20x4%20%3A%200000000003fffbff%20x3%20%3A%20ffff800081fcc860%0A%5B%20%20713.360732%5D%20x2%20%3A%20ffff800081cf0d00%20x1%20%3A%20ffff00007fb98d00%20x0%20%3A%20fffffc000002e884%0A%5B%20%20713.367859%5D%20Call%20trace%3A%0A%5B%20%20713.370294%5D%20%20osq_lock%2B0x5c%2F0x134%0A%5B%20%20713.373518%5D%20%20__mutex_lock.constprop.0%2B0x1f0%2F0x540%0A%5B%20%20713.378215%5D%20%20__mutex_lock_slowpath%2B0x14%2F0x20%0A%5B%20%20713.382479%5D%20%20mutex_lock%2B0x48%2F0x54%0A%5B%20%20713.385787%5D%20%20tee_device_get%2B0x20%2F0x6c%0A%5B%20%20713.389444%5D%20%20register_shm_helper%2B0x3c%2F0x2e8%0A%5B%20%20713.393624%5D%20%20tee_shm_register_kernel_buf%2B0x18%2F0x24%0A%5B%20%20713.398408%5D%20%20skcipher_setkey%2B0xe8%2F0x21c%20%5Btee_crypto%5D%0A%5B%20%20713.403374%5D%20%20cbc_skcipher_setkey%2B0x38%2F0x7c%20%5Btee_crypto%5D%0A%5B%20%20713.408589%5D%20%20crypto_skcipher_setkey%2B0x6c%2F0x124%0A%5B%20%20713.413029%5D%20%20crypt_setkey%2B0x104%2F0x22c%20%5Bdm_crypt%5D%0A%5B%20%20713.417658%5D%20%20crypt_set_key%2B0x248%2F0x360%20%5Bdm_crypt%5D%0A%5B%20%20713.422354%5D%20%20crypt_ctr%2B0x634%2F0xfb8%20%5Bdm_crypt%5D%0A%5B%20%20713.426705%5D%20%20dm_table_add_target%2B0x218%2F0x380%0A%5B%20%20713.430969%5D%20%20table_load%2B0x140%2F0x3f0%0A%5B%20%20713.434453%5D%20%20ctl_ioctl%2B0x378%2F0x648%0A%5B%20%20713.437851%5D%20%20dm_ctl_ioctl%2B0x10%2F0x20%0A%5B%20%20713.441334%5D%20%20__arm64_sys_ioctl%2B0xac%2F0xf0%0A%5B%20%20713.445252%5D%20%20invoke_syscall%2B0x48%2F0x114%0A%5B%20%20713.448996%5D%20%20el0_svc_common.constprop.0%2B0xc0%2F0xe0%0A%5B%20%20713.453693%5D%20%20do_el0_svc%2B0x1c%2F0x28%0A%5B%20%20713.457001%5D%20%20el0_svc%2B0x40%2F0xe4%0A%5B%20%20713.460055%5D%20%20el0t_64_sync_handler%2B0x120%2F0x12c%0A%5B%20%20713.464402%5D%20%20el0t_64_sync%2B0x190%2F0x194%0A%5B%20%20713.468066%5D%20Code%3A%20340005c4%2051000484%20d000f723%2091218063%20(f864d863)%20%0A%5B%20%20713.474147%5D%20---%5B%20end%20trace%200000000000000000%20%5D---%0A%5B%20%20713.478800%5D%20note%3A%20dmsetup%5B532%5D%20exited%20with%20preempt_count%201%3C%2FCODE%3E%3C%2FPRE%3E%3CP%3E%3CBR%20%2F%3EI%20am%20using%206.6.52_2.2.2%20scarthgap%20release.%3C%2FP%3E%3CP%3EI%20think%20the%20problematic%20driver%20is%26nbsp%3Bdrivers%2Ftee%2Fcrypto%2Ftee_skcipher.c.%3C%2FP%3E%3CP%3EHere%20is%20the%20output%20when%20loading%20the%20kernel%20module%3A%3C%2FP%3E%3CPRE%20class%3D%22lia-code-sample%20language-c%22%3E%3CCODE%3E%5B%20%20665.731673%5D%20tee_client_open_session%20failed%2C%20err%3A%20ffff0008%0A%5B%20%20665.737206%5D%20tee_crypt%20algorithms%20registered%20in%20%2Fproc%2Fcrypto%0A%5B%20%20665.742835%5D%20driver%201.0%20loaded.%3C%2FCODE%3E%3C%2FPRE%3E%3CBR%20%2F%3E%3CP%3EThe%20prerequisites%20from%20the%20document%20have%20been%20fulfilled%20in%20our%20BSP%3A%3C%2FP%3E%3CP%3EPrerequisites%3A%3CBR%20%2F%3EEnsure%20that%20a%20region%20of%20OCRAM%20is%20reserved%20to%20be%20accessed%20by%20Secure%20World%20only.%20This%20region%20is%20used%20to%20save%20cryptographic%20keys.%20Current%20OCRAM%20reserved%20regions%3A%3C%2FP%3E%3CP%3EFor%20i.MX%2093%3A%200x20518000%20-%200x2051C000%3CBR%20%2F%3EFor%20i.MX%2095%3A%200x204BC000%20-%200x204C0000%3CBR%20%2F%3EFor%20i.MX%2091%3A%200x204A0000%20-%200x204A4000%3CBR%20%2F%3EFor%20i.MX%20943%3A%200x204BC000%20-%200x204C0000%3C%2FP%3E%3CP%3EMake%20sure%20the%20following%20configurations%20are%20enabled%20in%20the%20kernel%3A%3CBR%20%2F%3ECONFIG_TEE_CRYPTO%20%3D%20m%3CBR%20%2F%3ECONFIG_DM_CRYPT%20%3D%20m%3CBR%20%2F%3ECONFIG_TRUSTED_KEYS%20%3D%20m%3CBR%20%2F%3ECONFIG_TRUSTED_KEYS_CAAM%20%3D%20n%3CBR%20%2F%3ECONFIG_TRUSTED_KEYS_TEE%20%3D%20y%3C%2FP%3E%3CP%3EIn%20OP-TEE%2C%20check%20whether%20the%20following%20flags%20in%20the%20core%2Farch%2Farm%2Fplat-imx%2Fconf.mk%20platform%20specific%20section%20for%20which%20DM-crypt%20are%20enabled%20or%20not%3A%3CBR%20%2F%3ECFG_IMX_TRUSTED_ARM_CE%20%3D%20y%3CBR%20%2F%3ECFG_IN_TREE_EARLY_TAS%20%2B%3D%20trusted_keys%2Ff04a0fe7-1f5d-4b9b-abf7-619b85b4ce8c%3CBR%20%2F%3E%3CBR%20%2F%3EAny%20ideas%20what%20might%20be%20an%20issue%20here%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2366958%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%20translate%3D%22no%22%3ERe%3A%20DM-Crypt%20usage%20on%20i.MX%20Platforms%20without%20CAAM%20hardware%20IP%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2366958%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CP%3EFixed%20it.%20I%20forgot%20to%20update%20optee%20blob%20when%20rebuilding%20with%26nbsp%3B%3CSPAN%3ECFG_IMX_TRUSTED_ARM_CE%20%3D%20y.%3CBR%20%2F%3E%3CBR%20%2F%3ECan%20be%20closed.%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E