Bug 2525507 - Review Request: minkipc - Capability based security framework
Summary: Review Request: minkipc - Capability based security framework
Keywords:
Status: NEW
Alias: None
Product: Fedora
Classification: Fedora
Component: Package Review
Version: rawhide
Hardware: Unspecified
OS: Linux
unspecified
medium
Target Milestone: ---
Assignee: Hans de Goede
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-08-28 08:35 UTC by Ali Erdinc Koroglu
Modified: 2026-09-10 11:45 UTC (History)
2 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Type: ---
Embargoed:
hans: fedora-review?


Attachments (Terms of Use)

Description Ali Erdinc Koroglu 2026-08-28 08:35:26 UTC
SPEC Url: https://download.copr.fedorainfracloud.org/results/aekoroglu/fedora/fedora-rawhide-aarch64/10909154-minkipc/minkipc.spec
SRPM Url: https://download.copr.fedorainfracloud.org/results/aekoroglu/fedora/fedora-rawhide-aarch64/10909154-minkipc/minkipc-1.2.9-1.fc46.src.rpm

Description
Mink (Mink is Not a Kernel) is Qualcomm's lightweight capability based
inter-process communication (IPC) framework. It enables secure synchronous
message passing across different security domains—like Linux user space to
Trusted Execution Environment using unforgeable object references and transport
mechanisms such as SMC, sockets, or TEE IOCTL.

Reproducible: Always

Comment 1 Hans de Goede 2026-09-10 11:04:49 UTC
I'm going to review this, assigning to myself.

Comment 2 Hans de Goede 2026-09-10 11:45:11 UTC
There are a number of issues with this package:

1. You have the same %changelog instead of %autochangelog as in a couple of your previous packages, please fix this for the next version.

2. its -devel install a /usr/include/object.h header which is a much much too generic header name

3. The udev-rules start the service based on quite generic device names / classes like /dev/tee* and mmc_rpmb, causing the services to also hw-activate on non Qualcomm hw when installed. I think it might be best to install this as a udev-rule example in %docs instead. That or fix the udev-rules to be more specific / selective.

4. A bigger problem is that the upstream sources seem to contain binary only firmware files, looking at:

https://download.copr.fedorainfracloud.org/results/aekoroglu/fedora/fedora-rawhide-aarch64/10909154-minkipc/fedora-review/licensecheck.txt

and then specifically at the "Unknown or generated" at the end it has:

minkipc-1.2.9-build/minkipc-1.2.9/mink_platform/mink_test/qtvm_test/prebuilt_qtee_ta/credtestapp64.mbn
...
minkipc-1.2.9-build/minkipc-1.2.9/ta/NO.LOGIN.BINARY.LICENSE.QTI.pdf
minkipc-1.2.9-build/minkipc-1.2.9/ta/glymur/FD02C9DA-306C-48C7-A49C-BBD827AE86EE.mbn
minkipc-1.2.9-build/minkipc-1.2.9/ta/glymur/tzecotestapp.mbn
minkipc-1.2.9-build/minkipc-1.2.9/ta/kaanapali/FD02C9DA-306C-48C7-A49C-BBD827AE86EE.mbn
minkipc-1.2.9-build/minkipc-1.2.9/ta/kaanapali/tzecotestapp.mbn
minkipc-1.2.9-build/minkipc-1.2.9/ta/mahua/FD02C9DA-306C-48C7-A49C-BBD827AE86EE.mbn
minkipc-1.2.9-build/minkipc-1.2.9/ta/mahua/tzecotestapp.mbn
minkipc-1.2.9-build/minkipc-1.2.9/ta/qcm2290/FD02C9DA-306C-48C7-A49C-BBD827AE86EE.mbn
minkipc-1.2.9-build/minkipc-1.2.9/ta/qcm2290/tzecotestapp.mbn
minkipc-1.2.9-build/minkipc-1.2.9/ta/qcm6490/FD02C9DA-306C-48C7-A49C-BBD827AE86EE.mbn
minkipc-1.2.9-build/minkipc-1.2.9/ta/qcm6490/tzecotestapp.mbn
minkipc-1.2.9-build/minkipc-1.2.9/ta/qcs615/FD02C9DA-306C-48C7-A49C-BBD827AE86EE.mbn
minkipc-1.2.9-build/minkipc-1.2.9/ta/qcs8300/FD02C9DA-306C-48C7-A49C-BBD827AE86EE.mbn
minkipc-1.2.9-build/minkipc-1.2.9/ta/qcs8300/tzecotestapp.mbn
minkipc-1.2.9-build/minkipc-1.2.9/ta/qcs9100/FD02C9DA-306C-48C7-A49C-BBD827AE86EE.mbn
minkipc-1.2.9-build/minkipc-1.2.9/ta/qcs9100/tzecotestapp.mbn
minkipc-1.2.9-build/minkipc-1.2.9/ta/shikra/FD02C9DA-306C-48C7-A49C-BBD827AE86EE.mbn
minkipc-1.2.9-build/minkipc-1.2.9/ta/shikra/tzecotestapp.mbn
minkipc-1.2.9-build/minkipc-1.2.9/ta/sm8750/FD02C9DA-306C-48C7-A49C-BBD827AE86EE.mbn
minkipc-1.2.9-build/minkipc-1.2.9/ta/sm8750/tzecotestapp.mbn
minkipc-1.2.9-build/minkipc-1.2.9/ta/x1e80100/FD02C9DA-306C-48C7-A49C-BBD827AE86EE.mbn
minkipc-1.2.9-build/minkipc-1.2.9/ta/x1e80100/tzecotestapp.mbn
minkipc-1.2.9-build/minkipc-1.2.9/ta/x1p42100/FD02C9DA-306C-48C7-A49C-BBD827AE86EE.mbn
minkipc-1.2.9-build/minkipc-1.2.9/ta/x1p42100/tzecotestapp.mbn

The files under the 'ta/' dir are presumably licensed under:

minkipc-1.2.9-build/minkipc-1.2.9/ta/NO.LOGIN.BINARY.LICENSE.QTI.pdf

Which when converted to text appears to be the same license as under which Qualcomm linux-firmware files are shipped. Which would make them fall under the firmware-license exception:

https://docs.fedoraproject.org/en-US/legal/license-approval/#_licenses_allowed_for_firmware

But the minkipc-1.2.9-build/minkipc-1.2.9/mink_platform/mink_test/qtvm_test/prebuilt_qtee_ta/credtestapp64.mbn file does not seem to have any license specified at all!

And even with the other firmware files being under an ok firmware license, none end up in the actual build rpms and the firmware-license extension starts with: "Some applications, drivers, and hardware require binary firmware images to boot Fedora Linux or function properly." which is clearly not the case here since we end up not packaging these at all.

So I think it is just best to use a cleaned tarbal with *all* firmware files removed, see:

https://fedorapeople.org/~tmz/guidelines/packaging-guidelines/SourceURL/#when-upstream-uses-prohibited-code


Note You need to log in before you can comment on or make changes to this bug.