tree 799cfca566ddd871b3e646f9008f6968da53eebb
parent da085276f033b5e90e2e7add09ea8a73fddc79af
author David Brazdil <dbrazdil@google.com> 1636553804 +0000
committer David Brazdil <dbrazdil@google.com> 1638879087 +0000

misc: dice: Add driver to forward secrets to userspace

Open Profile for DICE is a protocol for deriving unique secrets at boot,
used by some Android devices. The firmware/bootloader hands over secrets
in a reserved memory region, this driver takes ownership of the memory
region and exposes it to userspace via a character device that
lets userspace mmap the memory region into its process.

The character device can only be opened once at any given time.

Userspace can issue an ioctl requesting that the memory be wiped after
the current FD is released. In that case, the driver will clear
the buffer and refuse to open any new FDs.

Signed-off-by: David Brazdil <dbrazdil@google.com>
