From: Aubrey Li <aubrey.li@linux.intel.com>
To: Kuppuswamy Sathyanarayanan
<sathyanarayanan.kuppuswamy@linux.intel.com>,
Thomas Gleixner <tglx@linutronix.de>,
Ingo Molnar <mingo@redhat.com>, Borislav Petkov <bp@alien8.de>,
x86@kernel.org, Hans de Goede <hdegoede@redhat.com>,
Mark Gross <mgross@linux.intel.com>,
Alexei Starovoitov <ast@kernel.org>,
Daniel Borkmann <daniel@iogearbox.net>,
Andrii Nakryiko <andrii@kernel.org>
Cc: "H . Peter Anvin" <hpa@zytor.com>,
Kuppuswamy Sathyanarayanan <knsathya@kernel.org>,
"Kirill A . Shutemov" <kirill.shutemov@linux.intel.com>,
Andy Shevchenko <andriy.shevchenko@linux.intel.com>,
Tony Luck <tony.luck@intel.com>,
linux-kernel@vger.kernel.org,
platform-driver-x86@vger.kernel.org, netdev@vger.kernel.org,
bpf@vger.kernel.org
Subject: Re: [PATCH v1 0/6] Add TDX Guest Attestation support
Date: Thu, 10 Mar 2022 22:45:40 +0800 [thread overview]
Message-ID: <93767fe9-9edd-8e31-c3ca-155bfa807915@linux.intel.com> (raw)
In-Reply-To: <20220222231735.268919-1-sathyanarayanan.kuppuswamy@linux.intel.com>
On 2022/2/23 上午7:17, Kuppuswamy Sathyanarayanan wrote:
> Hi All,
>
> Intel's Trust Domain Extensions (TDX) protect guest VMs from malicious
> hosts and some physical attacks. VM guest with TDX support is called
> as TD Guest.
>
> In TD Guest, the attestation process is used to verify the
> trustworthiness of TD guest to the 3rd party servers. Such attestation
> process is required by 3rd party servers before sending sensitive
> information to TD guests. One usage example is to get encryption keys
> from the key server for mounting the encrypted rootfs or secondary drive.
>
> Following patches add the attestation support to TDX guest which
> includes attestation user interface driver, user agent example, and
> related hypercall support.
>
> In this series, only following patches are in arch/x86 and are
> intended for x86 maintainers review.
>
> * x86/tdx: Add TDREPORT TDX Module call support
> * x86/tdx: Add GetQuote TDX hypercall support
> * x86/tdx: Add SetupEventNotifyInterrupt TDX hypercall support
> * x86/tdx: Add TDX Guest event notify interrupt vector support
>
> Patch titled "platform/x86: intel_tdx_attest: Add TDX Guest attestation
> interface driver" adds the attestation driver support. This is supposed
> to be reviewed by platform-x86 maintainers.
>
> Also, patch titled "tools/tdx: Add a sample attestation user app" adds
> a testing app for attestation feature which needs review from
> bpf@vger.kernel.org.
>
> Dependencies:
> --------------
>
> This feature has dependency on TDX guest core patch set series.
>
> https://lore.kernel.org/all/20220218161718.67148-1-kirill.shutemov@linux.intel.com/T/
Does this feature also have dependency on QEMU tdx support?
>
> History:
> ----------
>
> Previously this patch set was sent under title "Add TDX Guest
> Support (Attestation support)". In the previous version, only the
> attestation driver patch was reviewed and got acked. Rest of the
> patches need to be reviewed freshly.
>
> https://lore.kernel.org/bpf/20210806000946.2951441-1-sathyanarayanan.kuppuswamy@linux.intel.com/
>
> Changes since previous submission:
> * Updated commit log and error handling in TDREPORT, GetQuote and
> SetupEventNotifyInterrupt support patches.
> * Added locking support in attestation driver.
>
> Kuppuswamy Sathyanarayanan (6):
> x86/tdx: Add tdx_mcall_tdreport() API support
> x86/tdx: Add tdx_hcall_get_quote() API support
> x86/tdx: Add SetupEventNotifyInterrupt TDX hypercall support
> platform/x86: intel_tdx_attest: Add TDX Guest attestation interface
> driver
> x86/tdx: Add TDX Guest event notify interrupt vector support
> tools/tdx: Add a sample attestation user app
>
> arch/x86/coco/tdx.c | 170 ++++++++++++
> arch/x86/include/asm/hardirq.h | 4 +
> arch/x86/include/asm/idtentry.h | 4 +
> arch/x86/include/asm/irq_vectors.h | 7 +-
> arch/x86/include/asm/tdx.h | 5 +
> arch/x86/kernel/irq.c | 7 +
> drivers/platform/x86/intel/Kconfig | 1 +
> drivers/platform/x86/intel/Makefile | 1 +
> drivers/platform/x86/intel/tdx/Kconfig | 13 +
> drivers/platform/x86/intel/tdx/Makefile | 3 +
> .../platform/x86/intel/tdx/intel_tdx_attest.c | 241 ++++++++++++++++++
> include/uapi/misc/tdx.h | 37 +++
> tools/Makefile | 13 +-
> tools/tdx/Makefile | 19 ++
> tools/tdx/attest/.gitignore | 2 +
> tools/tdx/attest/Makefile | 24 ++
> tools/tdx/attest/tdx-attest-test.c | 240 +++++++++++++++++
> 17 files changed, 784 insertions(+), 7 deletions(-)
> create mode 100644 drivers/platform/x86/intel/tdx/Kconfig
> create mode 100644 drivers/platform/x86/intel/tdx/Makefile
> create mode 100644 drivers/platform/x86/intel/tdx/intel_tdx_attest.c
> create mode 100644 include/uapi/misc/tdx.h
> create mode 100644 tools/tdx/Makefile
> create mode 100644 tools/tdx/attest/.gitignore
> create mode 100644 tools/tdx/attest/Makefile
> create mode 100644 tools/tdx/attest/tdx-attest-test.c
>
next prev parent reply other threads:[~2022-03-10 14:53 UTC|newest]
Thread overview: 13+ messages / expand[flat|nested] mbox.gz Atom feed top
2022-02-22 23:17 [PATCH v1 0/6] Add TDX Guest Attestation support Kuppuswamy Sathyanarayanan
2022-02-22 23:17 ` [PATCH v1 1/6] x86/tdx: Add tdx_mcall_tdreport() API support Kuppuswamy Sathyanarayanan
2022-02-22 23:17 ` [PATCH v1 2/6] x86/tdx: Add tdx_hcall_get_quote() " Kuppuswamy Sathyanarayanan
2022-02-22 23:17 ` [PATCH v1 3/6] x86/tdx: Add SetupEventNotifyInterrupt TDX hypercall support Kuppuswamy Sathyanarayanan
2022-02-22 23:17 ` [PATCH v1 4/6] platform/x86: intel_tdx_attest: Add TDX Guest attestation interface driver Kuppuswamy Sathyanarayanan
2022-03-10 14:55 ` Aubrey Li
2022-03-10 14:57 ` Sathyanarayanan Kuppuswamy
2022-02-22 23:17 ` [PATCH v1 5/6] x86/tdx: Add TDX Guest event notify interrupt vector support Kuppuswamy Sathyanarayanan
2022-02-22 23:17 ` [PATCH v1 6/6] tools/tdx: Add a sample attestation user app Kuppuswamy Sathyanarayanan
2022-02-24 15:32 ` [PATCH v1 0/6] Add TDX Guest Attestation support Hans de Goede
2022-02-24 15:48 ` Sathyanarayanan Kuppuswamy
2022-03-10 14:45 ` Aubrey Li [this message]
2022-03-10 14:54 ` Sathyanarayanan Kuppuswamy
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=93767fe9-9edd-8e31-c3ca-155bfa807915@linux.intel.com \
--to=aubrey.li@linux.intel.com \
--cc=andrii@kernel.org \
--cc=andriy.shevchenko@linux.intel.com \
--cc=ast@kernel.org \
--cc=bp@alien8.de \
--cc=bpf@vger.kernel.org \
--cc=daniel@iogearbox.net \
--cc=hdegoede@redhat.com \
--cc=hpa@zytor.com \
--cc=kirill.shutemov@linux.intel.com \
--cc=knsathya@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=mgross@linux.intel.com \
--cc=mingo@redhat.com \
--cc=netdev@vger.kernel.org \
--cc=platform-driver-x86@vger.kernel.org \
--cc=sathyanarayanan.kuppuswamy@linux.intel.com \
--cc=tglx@linutronix.de \
--cc=tony.luck@intel.com \
--cc=x86@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.