Subject: Re: [PATCH v3] virtio-tee: Reserve device ID 46 for TEE device

Fixes: https://github.com/oasis-tcs/virtio-spec/issues/175

Request for votes.



On 28-Sep-23 11:42 AM, jeshwank wrote:
In a virtual environment, an application running in guest VM may want
to delegate security sensitive tasks to a Trusted Application (TA)
running within a Trusted Execution Environment (TEE). A TEE is a trusted
OS running in some secure environment, for example, TrustZone on ARM
CPUs, or a separate secure co-processor etc.

A virtual TEE device emulates a TEE within a guest VM. Such a virtual
TEE device supports multiple operations such as:

VIRTIO_TEE_CMD_OPEN_DEVICE â Open a communication channel with virtio
                              TEE device.
VIRTIO_TEE_CMD_CLOSE_DEVICE â Close communication channel with virtio
                               TEE device.
VIRTIO_TEE_CMD_GET_VERSION â Get version of virtio TEE.
VIRTIO_TEE_CMD_OPEN_SESSION â Open a session to communicate with
                               trusted application running in TEE.
VIRTIO_TEE_CMD_CLOSE_SESSION â Close a session to end communication
                                with trusted application running in TEE.
VIRTIO_TEE_CMD_INVOKE_FUNC â Invoke a command or function in trusted
                              application running in TEE.
VIRTIO_TEE_CMD_CANCEL_REQ â Cancel an ongoing command within TEE.
VIRTIO_TEE_CMD_REGISTER_MEM - Register shared memory with TEE.
VIRTIO_TEE_CMD_UNREGISTER_MEM - Unregister shared memory from TEE.

We would like to reserve device ID 46 for Virtio-TEE device.

Signed-off-by: Jeshwanth Kumar <jeshwanthkumar.nk@amd.com>
Reviewed-by: Rijo Thomas <Rijo-john.Thomas@amd.com>
Reviewed-by: Parav Pandit <parav@nvidia.com>
Acked-by: Sumit Garg <sumit.garg@linaro.org>
  content.tex | 2 ++
  1 file changed, 2 insertions(+)

diff --git a/content.tex b/content.tex
index 0a62dce..644aa4a 100644
--- a/content.tex
+++ b/content.tex
@@ -739,6 +739,8 @@ \chapter{Device Types}\label{sec:Device Types}
  45         &   SPI master \\
+46         &   TEE device \\
Some of the devices above are unspecified by this document,

