From: Dave Hansen <dave.hansen@intel.com>
To: Rich Persaud <persaur@gmail.com>
Cc: Ross Philipson <ross.philipson@oracle.com>,
linux-kernel@vger.kernel.org, x86@kernel.org,
linux-integrity@vger.kernel.org, linux-doc@vger.kernel.org,
linux-crypto@vger.kernel.org, kexec@lists.infradead.org,
linux-efi@vger.kernel.org, iommu@lists.linux.dev,
dpsmith@apertussolutions.com, tglx@linutronix.de,
mingo@redhat.com, bp@alien8.de, hpa@zytor.com,
dave.hansen@linux.intel.com, ardb@kernel.org,
mjg59@srcf.ucam.org, James.Bottomley@hansenpartnership.com,
peterhuewe@gmx.de, jarkko@kernel.org, jgg@ziepe.ca,
luto@amacapital.net, nivedita@alum.mit.edu,
herbert@gondor.apana.org.au, davem@davemloft.net, corbet@lwn.net,
ebiederm@xmission.com, dwmw2@infradead.org,
baolu.lu@linux.intel.com, kanth.ghatraju@oracle.com,
andrew.cooper3@citrix.com, trenchboot-devel@googlegroups.com,
Sergii Dmytruk <sergii.dmytruk@3mdeb.com>,
openxt@googlegroups.com, "Mowka,
Mateusz" <mateusz.mowka@intel.com>, Ning Sun <ning.sun@intel.com>,
tboot-devel@lists.sourceforge.net
Subject: Re: [PATCH v14 00/19] x86: Trenchboot secure dynamic launch Linux kernel support
Date: Fri, 25 Apr 2025 07:12:51 -0700 [thread overview]
Message-ID: <9b18e8e3-f3e2-48d4-839a-56e1d8f62657@intel.com> (raw)
In-Reply-To: <18F9BD47-282D-4225-AB6B-FDA4AD52D7AE@gmail.com>
On 4/25/25 03:12, Rich Persaud wrote:
> On Apr 24, 2025, at 2:45 PM, Dave Hansen <dave.hansen@intel.com>
> wrote:
>> On 4/21/25 09:26, Ross Philipson wrote:
>>> This patchset provides detailed documentation of DRTM, the
>>> approach used for adding the capbility, and relevant API/ABI
>>> documentation. In addition to the documentation the patch set
>>> introduces Intel TXT support as the first platform for Linux
>>> Secure Launch.
>>
>> So, I know some of the story here thanks to Andy Cooper. But the
>> elephant in the room is:
>>
>>> INTEL(R) TRUSTED EXECUTION TECHNOLOGY (TXT) M: Ning Sun
>>> <ning.sun@intel.com> L: tboot-devel@lists.sourceforge.net
>>> S: Supported W: http://tboot.sourceforge.net T: hg
>>> http://tboot.hg.sourceforge.net:8000/hgroot/tboot/tboot F:
>>> Documentation/arch/x86/intel_txt.rst F: arch/x86/ kernel/
>>> tboot.c F: include/linux/tboot.h
>>
>> Linux already supports TXT. Why do we need TrenchBoot?
>
> One reason is to generalize DRTM support to other platforms.
OK, but why do this in Linux as opposed to tboot? Right now, much of the
TXT magic is done outside of the kernel. Why do it *IN* the kernel?
>> Also, honestly, what do you think we should do with the Linux
>> tboot code? Is everyone going to be moving over to Trenchboot>
> OpenXT will migrate development of measured launch from tboot to
> TrenchBoot Secure Launch, after upstream Linux and Xen have support
> for both Intel and AMD DRTM. Previously-deployed Intel devices using
> tboot, derived from OpenXT, will need support until users upgrade
> their hardware.
Say we axed tboot support from 6.16, but merged Trenchboot. A user on
old hardware upgrades their kernel. What happens to them?
>> so that Linux support for TXT/tboot can just go away?
You didn't _really_ answer the question.
Summarizing, I think you're saying that TXT/tboot Linux support can just
go away, but it will be help if its maintainers help its users transition.
Does anybody disagree with that?
> In that perfect world, Intel ACM and tboot developers would review
> the TrenchBoot Linux series
So, I was looking on the cc list and I didn't see them on there.
Shouldn't they be cc'd if you want them to review the series? A little
poking at lore makes me think that they were *NEVER* cc'd.
Is that right, or is my lore-foo weak?
next prev parent reply other threads:[~2025-04-25 15:37 UTC|newest]
Thread overview: 13+ messages / expand[flat|nested] mbox.gz Atom feed top
2025-04-25 10:12 [PATCH v14 00/19] x86: Trenchboot secure dynamic launch Linux kernel support Rich Persaud
2025-04-25 14:12 ` Dave Hansen [this message]
2025-04-29 0:04 ` Daniel P. Smith
2025-04-29 0:56 ` Dave Hansen
2025-05-18 14:42 ` Mike
-- strict thread matches above, loose matches on Subject: below --
2025-04-21 16:26 Ross Philipson
2025-04-21 20:52 ` Dave Hansen
2025-04-21 21:00 ` Andrew Cooper
2025-04-22 18:17 ` Andrew Cooper
2025-04-22 19:16 ` Dave Hansen
2025-04-22 21:26 ` Ard Biesheuvel
2025-04-22 23:21 ` Dave Hansen
2025-04-24 18:45 ` Dave Hansen
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=9b18e8e3-f3e2-48d4-839a-56e1d8f62657@intel.com \
--to=dave.hansen@intel.com \
--cc=James.Bottomley@hansenpartnership.com \
--cc=andrew.cooper3@citrix.com \
--cc=ardb@kernel.org \
--cc=baolu.lu@linux.intel.com \
--cc=bp@alien8.de \
--cc=corbet@lwn.net \
--cc=dave.hansen@linux.intel.com \
--cc=davem@davemloft.net \
--cc=dpsmith@apertussolutions.com \
--cc=dwmw2@infradead.org \
--cc=ebiederm@xmission.com \
--cc=herbert@gondor.apana.org.au \
--cc=hpa@zytor.com \
--cc=iommu@lists.linux.dev \
--cc=jarkko@kernel.org \
--cc=jgg@ziepe.ca \
--cc=kanth.ghatraju@oracle.com \
--cc=kexec@lists.infradead.org \
--cc=linux-crypto@vger.kernel.org \
--cc=linux-doc@vger.kernel.org \
--cc=linux-efi@vger.kernel.org \
--cc=linux-integrity@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=luto@amacapital.net \
--cc=mateusz.mowka@intel.com \
--cc=mingo@redhat.com \
--cc=mjg59@srcf.ucam.org \
--cc=ning.sun@intel.com \
--cc=nivedita@alum.mit.edu \
--cc=openxt@googlegroups.com \
--cc=persaur@gmail.com \
--cc=peterhuewe@gmx.de \
--cc=ross.philipson@oracle.com \
--cc=sergii.dmytruk@3mdeb.com \
--cc=tboot-devel@lists.sourceforge.net \
--cc=tglx@linutronix.de \
--cc=trenchboot-devel@googlegroups.com \
--cc=x86@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.