Re: [PATCH v2 0/3] dt-bindings: riscv: Add RISC-V Worlds and SiFive WorldGuard DT bindings

Yu-Chien Peter Lin <[email protected]> Tue, 4 Aug 2026 16:25:29 +0800
Newsgroups org.infradead.lists.linux-riscv,org.kernel.vger.linux-devicetree,org.kernel.vger.linux-kernel
Message-ID <anGh+dr/5dCX/cHd@plin-1878>
Hi Nick,

Thanks for the questions.

On Fri, Jul 31, 2026 at 04:43:56AM +0300, Nick Kossifidis wrote:
> Hello Peter,
> 
> On 7/29/26 19:39, Yu-Chien Peter Lin wrote:
> > Add device tree bindings for RISC-V Worlds, a standard extension that tags
> > every transaction with a World ID for fine-grained isolation. SiFive's
> > WorldGuard Checker is a hardware firewall in the system interconnect that
> > inspects transaction WIDs and enforces per-World access policies on memory
> > and MMIO devices.
> > 
> > wgChecker specification reference:
> > https://github.com/riscvarchive/security/blob/main/papers/worldguard%20proposal.pdf
> > 
> > Yu-Chien Peter Lin (3):
> >    dt-bindings: riscv: Add Worlds ISA extensions
> >    dt-bindings: riscv: Add Worlds per-hart properties
> >    dt-bindings: sifive: Add WorldGuard Checker
> > 
> >   .../devicetree/bindings/riscv/cpus.yaml       |  61 +++
> >   .../devicetree/bindings/riscv/extensions.yaml |  53 +++
> >   .../devicetree/bindings/riscv/worlds.yaml     |  86 +++++
> >   .../bindings/sifive/sifive,wgchecker2.yaml    | 356 ++++++++++++++++++
> >   4 files changed, 556 insertions(+)
> >   create mode 100644 Documentation/devicetree/bindings/riscv/worlds.yaml
> >   create mode 100644 Documentation/devicetree/bindings/sifive/sifive,wgchecker2.yaml
> > 
> 
> What's the plan for this and why do we need Linux-specific dt bindings ?
> This looks more like a set of firmware specific bindings, like OpenSBI
> domains for example (https://github.com/riscv-software-src/opensbi/blob/master/docs/domain_support.md).
> I understand adding the ISA extensions in the list (although the fast track
> is still underway, it's not ratified yet), but the rest don't make sense,
> not yet at least. How do you plan to use pmlwidlist on Linux to associate
> processes to wids ? Do you plan on adding a driver for the wg checker (and
> the markers that you mention) on Linux ? Do you ever expect Linux to run
> under trustedwid ?

We do not currently plan to implement a wgChecker driver in
the Linux kernel which holds the untrusted WID; wgChecker slot
configuration is handled by OpenSBI only at boot-time.

The intention here is providing a standardized device-tree format
for describing wgChecker hardware and protection policy, usable
consistently across Linux ecosystem (OpenSBI and possibly OP-TEE).

Thanks,
Peter Lin

> 
> Regards,
> Nick

_______________________________________________
linux-riscv mailing list
[email protected]
http://lists.infradead.org/mailman/listinfo/linux-riscv