From: Krzysztof Kozlowski <krzk@kernel.org>
To: Linlin Zhang <linlin.zhang@oss.qualcomm.com>,
ebiggers@kernel.org, axboe@kernel.dk, mst@redhat.com,
jasowangio@gmail.com, James.Bottomley@HansenPartnership.com,
martin.petersen@oracle.com, robh@kernel.org, krzk+dt@kernel.org,
conor+dt@kernel.org, linux-block@vger.kernel.org,
linux-crypto@vger.kernel.org, linux-scsi@vger.kernel.org,
virtualization@lists.linux.dev, devicetree@vger.kernel.org,
linux-arm-msm@vger.kernel.org
Cc: neeraj.soni@oss.qualcomm.com, gaurav.kashyap@oss.qualcomm.com,
mani@kernel.org, andersson@kernel.org, konradybcio@kernel.org,
bvanassche@acm.org, alim.akhtar@samsung.com,
avri.altman@sandisk.com, stefanha@redhat.com,
pbonzini@redhat.com, eperezma@redhat.com,
xuanzhuo@linux.alibaba.com, linux-kernel@vger.kernel.org
Subject: Re: [PATCH v1 09/11] soc: qcom: add ICE keyslot partitioning driver for guest VMs
Date: Mon, 31 Aug 2026 09:02:58 +0200 [thread overview]
Message-ID: <e23142e8-41b3-40f5-9d63-53c9c38fba38@kernel.org> (raw)
In-Reply-To: <20260827160806.1295313-10-linlin.zhang@oss.qualcomm.com>
On 27/08/2026 18:07, Linlin Zhang wrote:
> From: linlzhan <linlin.zhang@oss.qualcomm.com>
>
> On Qualcomm platforms the ICE hardware has a fixed number of physical
> keyslots shared across the host and all guest VMs. A userspace
> virtio-blk backend handling VIRTIO_BLK_T_CRYPTO_IN/OUT requests needs
> to translate a guest's virtual keyslot index to the corresponding
> physical ICE keyslot without letting one VM access another VM's slots.
>
> Add QCOM_ICE_SLOTS, a platform driver that implements bcp_slot_virt_ops
> for the /dev/blk-crypto-proxy device. It parses a
> qcom,ice-keyslot-map device-tree node describing the per-VM keyslot
> allocation table, where each child entry maps a guest_id to a
> contiguous physical slot range [slot_offset .. slot_offset +
> max_ice_slots). Entry 0 is reserved for the host; guest entries start
> at index 1 and are excluded from the guest-facing translation so that
> blk-crypto-proxy cannot accidentally route a guest request into the
> host's physical keyslots.
>
> The driver exposes two callbacks:
>
> get_guest_slots() — return the number of ICE keyslots allocated to
> a given guest_id; used by BCP_GET_CRYPTO_CAPS to
> populate the max_slots field in the virtio config
> space.
> vslot_to_pslot() — translate a (guest_id, virtual-slot) pair to the
> corresponding physical ICE keyslot index; used by
> BCP_SUBMIT_IO_BY_VSLOT before calling
> bio_crypt_set_ctx_by_slot().
>
> The singleton pointer to the parsed table is RCU-protected; the hot
> path reads it lock-free. Probe validates that no two VM entries share
> a guest_id or overlapping physical slot ranges.
>
> Note: This patch is submitted for visibility. The keyslot partitioning
> is based on the current DT-based keyslot allocation with vm_id known.
> We are aware this may be revised to use a TZ SCM query interface in a
> future version of this series, submit it RFC for design discussion.
>
> Signed-off-by: linlzhan <linlin.zhang@oss.qualcomm.com>
> ---
> drivers/soc/qcom/Kconfig | 18 +++
> drivers/soc/qcom/Makefile | 1 +
> drivers/soc/qcom/qcom_ice_slots.c | 232 ++++++++++++++++++++++++++++++
> 3 files changed, 251 insertions(+)
> create mode 100644 drivers/soc/qcom/qcom_ice_slots.c
>
> diff --git a/drivers/soc/qcom/Kconfig b/drivers/soc/qcom/Kconfig
> index 6c632d114d45..e1f383b4dc63 100644
> --- a/drivers/soc/qcom/Kconfig
> +++ b/drivers/soc/qcom/Kconfig
> @@ -294,6 +294,24 @@ endif
> # Options selected by other drivers from different subsystems must be outside
> # of the menuconfig if-block:
>
> +config QCOM_ICE_SLOTS
> + tristate "Qualcomm ICE keyslot partitioning for VM guests"
> + depends on ARCH_QCOM || COMPILE_TEST
> + depends on BLK_CRYPTO_PROXY
> + depends on BLK_INLINE_ENCRYPTION
> + help
> + Parses the qcom,ice-keyslot-map device-tree node and provides
> + per-VM ICE keyslot accounting and virtual-to-physical slot
> + translation for guest VMs sharing ICE hardware on Qualcomm
> + platforms.
> +
> + When enabled, guest virtual keyslot indices are mapped to the
> + physical ICE keyslot range allocated to each VM, preventing one
> + VM from accessing another VM's keyslots.
> +
> + Say M here when multiple VMs share ICE keyslots on a Qualcomm
> + platform. If unsure, say N.
> +
> config QCOM_INLINE_CRYPTO_ENGINE
> tristate
> select QCOM_SCM
> diff --git a/drivers/soc/qcom/Makefile b/drivers/soc/qcom/Makefile
> index 6d4b7546d1fb..952a57554f9d 100644
> --- a/drivers/soc/qcom/Makefile
> +++ b/drivers/soc/qcom/Makefile
> @@ -38,6 +38,7 @@ obj-$(CONFIG_QCOM_LLCC) += llcc-qcom.o
> obj-$(CONFIG_QCOM_KRYO_L2_ACCESSORS) += kryo-l2-accessors.o
> obj-$(CONFIG_QCOM_ICC_BWMON) += icc-bwmon.o
> qcom_ice-objs += ice.o
> +obj-$(CONFIG_QCOM_ICE_SLOTS) += qcom_ice_slots.o
> obj-$(CONFIG_QCOM_INLINE_CRYPTO_ENGINE) += qcom_ice.o
> obj-$(CONFIG_QCOM_CRYPTO_VIRT) += crypto_virt.o
> obj-$(CONFIG_QCOM_PBS) += qcom-pbs.o
> diff --git a/drivers/soc/qcom/qcom_ice_slots.c b/drivers/soc/qcom/qcom_ice_slots.c
> new file mode 100644
> index 000000000000..364ac93077c1
> --- /dev/null
> +++ b/drivers/soc/qcom/qcom_ice_slots.c
> @@ -0,0 +1,232 @@
> +// SPDX-License-Identifier: GPL-2.0-only
> +/*
> + * qcom_ice_slots.c - Qualcomm ICE keyslot partitioning for guest VMs
> + *
> + * Implements bcp_slot_virt_ops: translates a (guest_id, virtual-slot) pair to
> + * a physical ICE keyslot index using a per-VM allocation table parsed from
> + * the device-tree node with compatible = "qcom,ice-keyslot-map".
> + *
> + * Device-tree layout:
> + *
> + * ice_keyslot_map: ice-keyslot-map {
> + * compatible = "qcom,ice-keyslot-map";
NAK, there is no such stuff.
Drivers for undocumented downstream DTS are not allowed.
...
> +
> + dev_info(dev, "registered: %u VMs, %u total ICE slots\n",
> + idx, total_slots);
This does not look like useful printk message. Drivers should be silent
on success:
https://elixir.bootlin.com/linux/v6.15-rc7/source/Documentation/process/coding-style.rst#L913
https://elixir.bootlin.com/linux/v6.15-rc7/source/Documentation/process/debugging/driver_development_debugging_guide.rst#L79
Best regards,
Krzysztof
next prev parent reply other threads:[~2026-08-31 7:03 UTC|newest]
Thread overview: 62+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-27 16:07 [PATCH v1 00/11] FBE virtualization: inline encryption for virtio-blk guests Linlin Zhang
2026-08-27 16:07 ` [PATCH v1 01/11] virtio_blk: add inline encryption support Linlin Zhang
2026-08-27 16:23 ` sashiko-bot
2026-09-01 19:48 ` Stefan Hajnoczi
2026-09-02 5:58 ` Linlin Zhang
2026-08-27 16:07 ` [PATCH v1 02/11] soc: qcom: add crypto_virt backend for virtio-blk inline crypto Linlin Zhang
2026-08-27 16:24 ` sashiko-bot
2026-08-31 6:56 ` Krzysztof Kozlowski
2026-09-01 9:39 ` Linlin Zhang
2026-09-01 13:58 ` Krzysztof Kozlowski
2026-09-02 15:01 ` Linlin Zhang
2026-09-03 8:16 ` Krzysztof Kozlowski
2026-08-27 16:07 ` [PATCH v1 03/11] soc: qcom: crypto_virt: add support for create, prepare and import keys Linlin Zhang
2026-08-27 16:19 ` sashiko-bot
2026-08-31 6:58 ` Krzysztof Kozlowski
2026-09-01 10:31 ` Linlin Zhang
2026-09-01 14:01 ` Krzysztof Kozlowski
2026-09-02 15:33 ` Linlin Zhang
2026-08-27 16:07 ` [PATCH v1 04/11] dt-bindings: soc: qcom: add binding for qcom,crypto-virt Linlin Zhang
2026-08-27 16:14 ` sashiko-bot
2026-08-31 7:01 ` Krzysztof Kozlowski
2026-09-01 10:40 ` Linlin Zhang
2026-08-27 16:07 ` [PATCH v1 05/11] blk-crypto: add slot-based inline encryption path Linlin Zhang
2026-08-27 16:26 ` sashiko-bot
2026-09-01 19:06 ` Stefan Hajnoczi
2026-08-27 16:07 ` [PATCH v1 06/11] scsi: ufs: core: add slot path to ufshcd_prepare_lrbp_crypto Linlin Zhang
2026-08-27 16:20 ` sashiko-bot
2026-09-01 19:08 ` Stefan Hajnoczi
2026-08-27 16:07 ` [PATCH v1 07/11] blk-crypto: move bio_crypt_dun_increment() to the public header Linlin Zhang
2026-08-27 16:18 ` sashiko-bot
2026-09-01 19:13 ` Stefan Hajnoczi
2026-09-02 6:02 ` Linlin Zhang
2026-08-27 16:07 ` [PATCH v1 08/11] block: add /dev/blk-crypto-proxy for host-side virtio-blk inline encryption Linlin Zhang
2026-08-27 16:24 ` sashiko-bot
2026-09-01 19:43 ` Stefan Hajnoczi
2026-09-02 13:14 ` Linlin Zhang
2026-08-27 16:07 ` [PATCH v1 09/11] soc: qcom: add ICE keyslot partitioning driver for guest VMs Linlin Zhang
2026-08-27 16:17 ` sashiko-bot
2026-08-31 7:02 ` Krzysztof Kozlowski [this message]
2026-09-01 10:48 ` Linlin Zhang
2026-08-27 16:07 ` [PATCH v1 10/11] blk-crypto: add slot_offset to blk_crypto_profile Linlin Zhang
2026-08-27 16:23 ` sashiko-bot
2026-08-27 16:07 ` [PATCH v1 11/11] scsi: ufs: ufs-qcom: support ICE keyslot partitioning for guest VMs Linlin Zhang
2026-08-27 16:26 ` sashiko-bot
2026-08-31 7:03 ` Krzysztof Kozlowski
2026-09-01 10:54 ` Linlin Zhang
2026-09-01 14:02 ` Krzysztof Kozlowski
2026-09-02 15:03 ` Linlin Zhang
2026-08-27 18:42 ` [PATCH v1 00/11] FBE virtualization: inline encryption for virtio-blk guests Eric Biggers
2026-08-28 15:37 ` Linlin Zhang
2026-08-28 15:56 ` Linlin Zhang
2026-08-31 6:21 ` Linlin Zhang
2026-08-31 20:41 ` Stefan Hajnoczi
2026-09-01 9:21 ` Linlin Zhang
2026-09-01 18:47 ` Stefan Hajnoczi
2026-08-31 21:07 ` Eric Biggers
2026-09-01 8:22 ` Linlin Zhang
2026-09-01 8:45 ` Linlin Zhang
2026-09-01 19:44 ` Stefan Hajnoczi
2026-09-02 8:15 ` Linlin Zhang
2026-09-01 21:28 ` Eric Biggers
2026-09-02 14:33 ` Linlin Zhang
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=e23142e8-41b3-40f5-9d63-53c9c38fba38@kernel.org \
--to=krzk@kernel.org \
--cc=James.Bottomley@HansenPartnership.com \
--cc=alim.akhtar@samsung.com \
--cc=andersson@kernel.org \
--cc=avri.altman@sandisk.com \
--cc=axboe@kernel.dk \
--cc=bvanassche@acm.org \
--cc=conor+dt@kernel.org \
--cc=devicetree@vger.kernel.org \
--cc=ebiggers@kernel.org \
--cc=eperezma@redhat.com \
--cc=gaurav.kashyap@oss.qualcomm.com \
--cc=jasowangio@gmail.com \
--cc=konradybcio@kernel.org \
--cc=krzk+dt@kernel.org \
--cc=linlin.zhang@oss.qualcomm.com \
--cc=linux-arm-msm@vger.kernel.org \
--cc=linux-block@vger.kernel.org \
--cc=linux-crypto@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-scsi@vger.kernel.org \
--cc=mani@kernel.org \
--cc=martin.petersen@oracle.com \
--cc=mst@redhat.com \
--cc=neeraj.soni@oss.qualcomm.com \
--cc=pbonzini@redhat.com \
--cc=robh@kernel.org \
--cc=stefanha@redhat.com \
--cc=virtualization@lists.linux.dev \
--cc=xuanzhuo@linux.alibaba.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.