Bug 2525507

Summary: Review Request: minkipc - Capability based security framework
Product: [Fedora] Fedora Reporter: Ali Erdinc Koroglu <ali.koroglu>
Component: Package ReviewAssignee: Hans de Goede <hans>
Status: NEW --- QA Contact: Fedora Extras Quality Assurance <extras-qa>
Severity: medium Docs Contact:
Priority: unspecified    
Version: rawhideCC: hans, package-review
Target Milestone: ---Flags: hans: fedora-review?
Target Release: ---   
Hardware: Unspecified   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Ali Erdinc Koroglu 2026-08-28 08:35:26 UTC
SPEC Url: https://download.copr.fedorainfracloud.org/results/aekoroglu/fedora/fedora-rawhide-aarch64/10909154-minkipc/minkipc.spec
SRPM Url: https://download.copr.fedorainfracloud.org/results/aekoroglu/fedora/fedora-rawhide-aarch64/10909154-minkipc/minkipc-1.2.9-1.fc46.src.rpm

Description
Mink (Mink is Not a Kernel) is Qualcomm's lightweight capability based
inter-process communication (IPC) framework. It enables secure synchronous
message passing across different security domains—like Linux user space to
Trusted Execution Environment using unforgeable object references and transport
mechanisms such as SMC, sockets, or TEE IOCTL.

Reproducible: Always

Comment 1 Hans de Goede 2026-09-10 11:04:49 UTC
I'm going to review this, assigning to myself.

Comment 2 Hans de Goede 2026-09-10 11:45:11 UTC
There are a number of issues with this package:

1. You have the same %changelog instead of %autochangelog as in a couple of your previous packages, please fix this for the next version.

2. its -devel install a /usr/include/object.h header which is a much much too generic header name

3. The udev-rules start the service based on quite generic device names / classes like /dev/tee* and mmc_rpmb, causing the services to also hw-activate on non Qualcomm hw when installed. I think it might be best to install this as a udev-rule example in %docs instead. That or fix the udev-rules to be more specific / selective.

4. A bigger problem is that the upstream sources seem to contain binary only firmware files, looking at:

https://download.copr.fedorainfracloud.org/results/aekoroglu/fedora/fedora-rawhide-aarch64/10909154-minkipc/fedora-review/licensecheck.txt

and then specifically at the "Unknown or generated" at the end it has:

minkipc-1.2.9-build/minkipc-1.2.9/mink_platform/mink_test/qtvm_test/prebuilt_qtee_ta/credtestapp64.mbn
...
minkipc-1.2.9-build/minkipc-1.2.9/ta/NO.LOGIN.BINARY.LICENSE.QTI.pdf
minkipc-1.2.9-build/minkipc-1.2.9/ta/glymur/FD02C9DA-306C-48C7-A49C-BBD827AE86EE.mbn
minkipc-1.2.9-build/minkipc-1.2.9/ta/glymur/tzecotestapp.mbn
minkipc-1.2.9-build/minkipc-1.2.9/ta/kaanapali/FD02C9DA-306C-48C7-A49C-BBD827AE86EE.mbn
minkipc-1.2.9-build/minkipc-1.2.9/ta/kaanapali/tzecotestapp.mbn
minkipc-1.2.9-build/minkipc-1.2.9/ta/mahua/FD02C9DA-306C-48C7-A49C-BBD827AE86EE.mbn
minkipc-1.2.9-build/minkipc-1.2.9/ta/mahua/tzecotestapp.mbn
minkipc-1.2.9-build/minkipc-1.2.9/ta/qcm2290/FD02C9DA-306C-48C7-A49C-BBD827AE86EE.mbn
minkipc-1.2.9-build/minkipc-1.2.9/ta/qcm2290/tzecotestapp.mbn
minkipc-1.2.9-build/minkipc-1.2.9/ta/qcm6490/FD02C9DA-306C-48C7-A49C-BBD827AE86EE.mbn
minkipc-1.2.9-build/minkipc-1.2.9/ta/qcm6490/tzecotestapp.mbn
minkipc-1.2.9-build/minkipc-1.2.9/ta/qcs615/FD02C9DA-306C-48C7-A49C-BBD827AE86EE.mbn
minkipc-1.2.9-build/minkipc-1.2.9/ta/qcs8300/FD02C9DA-306C-48C7-A49C-BBD827AE86EE.mbn
minkipc-1.2.9-build/minkipc-1.2.9/ta/qcs8300/tzecotestapp.mbn
minkipc-1.2.9-build/minkipc-1.2.9/ta/qcs9100/FD02C9DA-306C-48C7-A49C-BBD827AE86EE.mbn
minkipc-1.2.9-build/minkipc-1.2.9/ta/qcs9100/tzecotestapp.mbn
minkipc-1.2.9-build/minkipc-1.2.9/ta/shikra/FD02C9DA-306C-48C7-A49C-BBD827AE86EE.mbn
minkipc-1.2.9-build/minkipc-1.2.9/ta/shikra/tzecotestapp.mbn
minkipc-1.2.9-build/minkipc-1.2.9/ta/sm8750/FD02C9DA-306C-48C7-A49C-BBD827AE86EE.mbn
minkipc-1.2.9-build/minkipc-1.2.9/ta/sm8750/tzecotestapp.mbn
minkipc-1.2.9-build/minkipc-1.2.9/ta/x1e80100/FD02C9DA-306C-48C7-A49C-BBD827AE86EE.mbn
minkipc-1.2.9-build/minkipc-1.2.9/ta/x1e80100/tzecotestapp.mbn
minkipc-1.2.9-build/minkipc-1.2.9/ta/x1p42100/FD02C9DA-306C-48C7-A49C-BBD827AE86EE.mbn
minkipc-1.2.9-build/minkipc-1.2.9/ta/x1p42100/tzecotestapp.mbn

The files under the 'ta/' dir are presumably licensed under:

minkipc-1.2.9-build/minkipc-1.2.9/ta/NO.LOGIN.BINARY.LICENSE.QTI.pdf

Which when converted to text appears to be the same license as under which Qualcomm linux-firmware files are shipped. Which would make them fall under the firmware-license exception:

https://docs.fedoraproject.org/en-US/legal/license-approval/#_licenses_allowed_for_firmware

But the minkipc-1.2.9-build/minkipc-1.2.9/mink_platform/mink_test/qtvm_test/prebuilt_qtee_ta/credtestapp64.mbn file does not seem to have any license specified at all!

And even with the other firmware files being under an ok firmware license, none end up in the actual build rpms and the firmware-license extension starts with: "Some applications, drivers, and hardware require binary firmware images to boot Fedora Linux or function properly." which is clearly not the case here since we end up not packaging these at all.

So I think it is just best to use a cleaned tarbal with *all* firmware files removed, see:

https://fedorapeople.org/~tmz/guidelines/packaging-guidelines/SourceURL/#when-upstream-uses-prohibited-code