Skip to content

arch/arm64/imx9: add an ELE-backed /dev/random driver - #20191

Merged
acassis merged 3 commits into
apache:masterfrom
royzah:imx9-rng
Sep 27, 2026
Merged

acassis merged 3 commits into
apache:masterfrom
royzah:imx9-rng

Conversation

@royzah

@royzah royzah commented Sep 19, 2026 •

Copy link
Copy Markdown
Contributor

Why

imx9_ele_get_random() exists, but nothing registers a device for it, so the i.MX9 entropy pool is never seeded from hardware. stm32h7, nrf52, lpc54xx and rp23xx all ship this driver; imx9 does not.

Modelled on https://github.com/apache/nuttx/blob/master/arch/arm/src/stm32h7/stm32_rng.c

How

Point
imx9_ele.c built only for CONFIG_IMX9_BOOTLOADER the enclave was out of reach of the application core. It moves behind a new CONFIG_IMX9_ELE that the bootloader selects, so existing configs are unchanged
a transfer that never lands is silent the buffer is prefilled, and a block still holding the pattern is refused, as is an all-zero block and, by the FIPS 140-2 continuous test, a repeat

Zero alone could not tell "the write never arrived" from "the ELE answered with zeros".

Depends on

#20196

Tested

Compiles for imx93-evk:nsh with CONFIG_IMX9_RNG=y, tools/nxstyle clean.

That build is what caught the first version gating IMX9_ELE on IMX9_HAVE_MU, which only ARCH_CHIP_IMX95 selects, so the driver was unselectable on the chip it is for.

@github-actions github-actions Bot added Arch: arm64 Issues related to ARM64 (64-bit) architecture Area: OS Components OS Components issues Size: M The size of the change in this PR is medium labels Sep 19, 2026
Comment thread arch/arm64/src/imx9/Kconfig
Comment thread arch/arm64/src/imx9/Make.defs
@github-actions

github-actions Bot commented Sep 19, 2026 •

Copy link
Copy Markdown

MemBrowse Memory Report

No memory changes detected for:

@github-actions github-actions Bot removed the Area: OS Components OS Components issues label Sep 19, 2026
@royzah
royzah force-pushed the imx9-rng branch 5 times, most recently from d7ba53b to 0e7024c Compare September 20, 2026 04:00
@github-actions github-actions Bot added Size: L The size of the change in this PR is large and removed Size: M The size of the change in this PR is medium labels Sep 20, 2026
…ual one.

The ELE addresses memory physically; cache maintenance takes a virtual
address. Both buffer calls supply one and use it for both, in opposite
directions: get_random() runs up_flush_dcache() on a physical address,
get_key() hands the enclave a virtual one. Both fail silently, and both
are correct only while the two are equal.

Take the virtual address in both, maintain the cache on it, and translate
for the message. get_random() also gains the alignment check get_key()
already has.

Signed-off-by: Royyan Zahir <royzah@gmail.com>
@github-actions github-actions Bot added Size: M The size of the change in this PR is medium and removed Size: L The size of the change in this PR is large labels Sep 21, 2026

@acassis acassis left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@royzah please add Documentation to this new driver on iMX9x page

@royzah

royzah commented Sep 23, 2026 •

Copy link
Copy Markdown
Contributor Author

Run on hardware: i.MX93 Cortex-A55, PX4 kernel build, NuttX 12.11.0. Shell over MAVLink SERIAL_CONTROL.

uname -a
NuttX 12.11.0 1ace719ff0 Sep 23 2026 12:02:35 arm64 px4

hexdump /dev/random -c 32
/dev/random at 00000000:
0000: 7c 9a f9 b0 fb 89 be 9d 23 bf 17 28 88 43 67 10
0010: c5 79 10 9e d7 be ca 42 2f 51 00 bd bc ce 77 54

hexdump /dev/random -c 32
/dev/random at 00004800:
0000: e4 82 74 40 86 7a 73 87 de a7 40 ea 5d 65 89 2a
0010: 34 f5 fb 9a c1 8d 95 c5 2f cf ad 91 b0 d7 ba 6b

Both reads distinct, /dev/urandom likewise, and /dev lists random and urandom.

Tested with this branch applied onto a downstream i.MX93 board tree: imx9_rng.c and imx9_ele.h are byte-identical to it, imx9_ele.c differs only by #include <debug.h> in place of <nuttx/debug.h>. The shell prompt is elided from the log, nothing else changed.

@royzah
royzah requested a review from pussuw as a code owner September 23, 2026 12:32
@royzah

royzah commented Sep 23, 2026

Copy link
Copy Markdown
Contributor Author

@acassis added the driver docs you asked for, on the i.MX9x page rather than the board page since it is a chip peripheral. Covers the Kconfig chain and the health checks, with the hardware log.

@xiaoxiang781216 the IMX9_ELE prompt is gone as you suggested, and the stray .ddx files are out.

Out of draft now, ready for another look.

@github-actions github-actions Bot added the Area: Documentation Improvements or additions to documentation label Sep 23, 2026
@royzah
royzah requested a review from acassis September 23, 2026 14:44
acassis
acassis previously approved these changes Sep 23, 2026
Comment thread arch/arm64/src/imx9/imx9_rng.c
The i.MX9 has a true random number generator behind the EdgeLock Enclave
and imx9_ele_get_random() to reach it, but nothing registers a character
device for it, so the entropy pool is never seeded from hardware. stm32h7,
nrf52, lpc54xx and rp23xx all provide one; imx9 does not.

imx9_ele.c was built only for CONFIG_IMX9_BOOTLOADER, putting the enclave
out of reach of the application core. It moves behind a new CONFIG_IMX9_ELE
that the bootloader selects, so existing configurations build as before.

A transfer that never lands is silent, so the buffer is prefilled with a
pattern and a block still holding it is refused, as is an all-zero block
and, by the FIPS 140-2 continuous test, a repeat of the one before.

Compiles for imx93-evk:nsh with CONFIG_IMX9_RNG=y.

Signed-off-by: Royyan Zahir <royzah@gmail.com>
The i.MX9x platform page carried only a board toctree, so there was nowhere
describing what the chip supports.

Add a peripheral table and a section on the random number generator: the
Kconfig chain, which of DEV_RANDOM and DEV_URANDOM come on by themselves,
and the health checks a block must pass before a read returns it.

Signed-off-by: Royyan Zahir <royzah@gmail.com>
@royzah

royzah commented Sep 24, 2026

Copy link
Copy Markdown
Contributor Author

Hi @acassis
Can you give this PR another look ? 👍

@royzah

royzah commented Sep 27, 2026

Copy link
Copy Markdown
Contributor Author

@acassis gentle bump: the docs you asked for are in and xiaoxiang's approved. Anything else you'd like changed?

@acassis
acassis merged commit 40783f8 into apache:master Sep 27, 2026
26 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Arch: arm64 Issues related to ARM64 (64-bit) architecture Area: Documentation Improvements or additions to documentation Size: M The size of the change in this PR is medium

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants