From: "Quigley, David" <david.quigley@intel.com>
To: Jiri Pirko <jiri@resnulli.us>
Cc: <linux-coco@lists.linux.dev>, <linux-pci@vger.kernel.org>,
<driver-core@lists.linux.dev>
Subject: Re: [PATCH 00/15] Device Evidence and Trust for PCI Security Protocol (TDISP)
Date: Wed, 30 Sep 2026 08:14:00 -0600 [thread overview]
Message-ID: <b32438d2-4470-44b6-aa62-b691f93a2b9c@intel.com> (raw)
In-Reply-To: <arzr32ZDComnfmny@FV6GYCPJ69>
Is there a way for this to be posted as its own patch set so we can
provide feedback inline? Also do we have any other potential uses for
your proposed ctlv mechanism or is attestation the only user at the moment?
On 9/30/2026 5:22 AM, Jiri Pirko wrote:
> Fri, Sep 04, 2026 at 11:52:12AM +0200, jiri@resnulli.us wrote:
>> Thu, Sep 03, 2026 at 03:36:54PM +0200, lukas@wunner.de wrote:
>>> [+cc Jonathan, start of thread is here:
>>> https://lore.kernel.org/all/20260902150125.GD2890729@ziepe.ca/
>>> ]
>>>
>>> On Wed, Sep 02, 2026 at 12:01:25PM -0300, Jason Gunthorpe wrote:
>>
>> [..]
>>
>>
>>>> I've asked Jiri Pirko to work on
>>>> the PCI evidence uAPI based on his deep netlink experience
>>> netlink isn't well suited to transport large blobs because the nlattr
>>> len is u16. (The len of the enclosing nlmsg is u32, which is sufficient.)
>>>
>>> Previous approaches, including the one proposed by Dan in this series,
>>> work around the problem by splitting the blob into a sequence of nlattrs.
>>> I think we should instead extend the netlink protocol with 32-bit "jumbo"
>>> attributes.
>>>
>>> I suggest we reserve bit 13 of nla_type as NLA_F_JUMBO and use the
>>> the first 4 bytes after the struct nlattr header as length (if the
>>> jumbo flag is set).
>>>
>>>
>>> A second problem is that the size of a socket buffer's linear data
>>> is limited. Also, copying the blob into the nlmsg is a bit wasteful
>>> and we'd want zero copy instead. The solution I've come up with is
>>> to attach the pages backing the blob as fragments to the skb.
>>> It's very simple, overcomes the skb size limitation and allows for
>>> zero-copy:
>>>
>>> https://github.com/l1k/linux/commit/6e73bb999128
>>>
>>> That commit is from January and the time I've been able to devote
>>> to this has since been limited as my employer prioritized various
>>> AER feature gaps and fixes.
>>>
>>> I worked on this for native PCI device authentication, which faces
>>> the same netlink blob issue as TSM-mediated authentication.
>>> Both should use the same uABI for evidence exposure. Additionally,
>>> native device authentication may be used by non-PCI buses such as
>>> ATA or SCSI. The uABI should work for those use cases as well.
>> Not sure if netlink as actually the best fit for this purpose,
>> for large blob transfers ioctl-based iface is probably much more
>> convenient. I'm working on a uapi framework that make the best of
>> netlink and takes it over to a fd-based ioctl. I call it CTLV, here's
>> a link to an early pre-RFC draft:
>>
>> https://github.com/jpirko/linux_mlxsw/commits/wip_ctlv_pre_rfc_draft1/
>>
> [..]
>
> Following up on this, I have a very early draft of an attestation
> framework here:
>
> https://github.com/jpirko/linux_mlxsw/commits/wip_attestation_pre_rfc_draft1/
>
> It introduces a provider-neutral, fd-based interface for evidence
> retrieval, userspace verdicts tied to exact device/evidence generations,
> measurement registers and their journal, events, and device-security
> state transitions. Large evidence is written directly to referenced
> buffers instead of being split across Netlink messages.
>
> For this series, the intent is to replace the device-evidence
> Generic Netlink UAPI and the draft PCI/TSM evidence-accept UAPI.
> It does not replace PCI/TSM connect/disconnect or lock/unlock,
> nor the underlying device-trust, SPDM/IDE/TDISP, MMIO, or
> DMA machinery.
>
> The branch currently contains the core, a simulation provider with
> tests, and a TDX provider demonstrating the provider boundary.
> The PCI/TSM provider is not implemented yet.
next prev parent reply other threads:[~2026-09-30 14:14 UTC|newest]
Thread overview: 73+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-05 22:08 [PATCH 00/15] Device Evidence and Trust for PCI Security Protocol (TDISP) Dan Williams
2026-07-05 22:08 ` [PATCH 01/15] netlink: specs: Introduce multi-message blobs for SPDM Dan Williams
2026-07-08 11:13 ` Donald Hunter
2026-07-11 1:43 ` Dan Williams (nvidia)
2026-07-08 13:23 ` Donald Hunter
2026-07-22 1:20 ` Jakub Kicinski
2026-08-02 17:58 ` Ankit Agrawal
2026-08-03 16:35 ` Jakub Kicinski
2026-07-05 22:08 ` [PATCH 02/15] tools: ynl: Teach pyynl to handle blobs Dan Williams
2026-07-08 13:48 ` Donald Hunter
2026-07-05 22:08 ` [PATCH 03/15] tools: ynl: Teach ynl_gen_c to validate and dump 'blob' attributes Dan Williams
2026-07-05 22:08 ` [PATCH 04/15] device core: Introduce "device evidence" over netlink Dan Williams
2026-07-08 13:22 ` Donald Hunter
2026-07-05 22:08 ` [PATCH 05/15] device core: Add "device evidence" 'validate' command Dan Williams
2026-07-05 22:08 ` [PATCH 06/15] PCI/TSM: Add device evidence support Dan Williams
2026-07-08 5:00 ` Alexey Kardashevskiy
2026-07-08 18:25 ` Dan Williams (nvidia)
2026-07-05 22:08 ` [PATCH 07/15] modules: Document the global async_probe parameter Dan Williams
2026-07-17 13:44 ` Nikolay Borisov
2026-07-05 22:08 ` [PATCH 08/15] device core: Initial device trust infrastructure Dan Williams
2026-07-06 13:45 ` Jason Gunthorpe
2026-07-05 22:08 ` [PATCH 09/15] PCI, device core: Move "untrusted" concept to DEVICE_TRUST_ADVERSARY Dan Williams
2026-07-06 13:49 ` Jason Gunthorpe
2026-07-07 13:04 ` Robin Murphy
2026-07-05 22:08 ` [PATCH 10/15] PCI/TSM: Add device interface security LOCKED support Dan Williams
2026-07-05 22:08 ` [PATCH 11/15] PCI/TSM: Add device interface security RUN support Dan Williams
2026-07-05 22:08 ` [PATCH 12/15] PCI/TSM: Add device interface security DMA enable/disable Dan Williams
2026-07-05 22:08 ` [PATCH 13/15] PCI, device core: Add private memory access for DEVICE_TRUST_TCB Dan Williams
2026-07-06 12:42 ` Aneesh Kumar K.V
2026-07-08 18:06 ` Dan Williams (nvidia)
2026-07-08 18:10 ` Aneesh Kumar K.V
2026-07-09 6:32 ` Alexey Kardashevskiy
2026-07-09 7:38 ` Alexey Kardashevskiy
2026-07-05 22:08 ` [PATCH 14/15] PCI/TSM: Create MMIO descriptors via TDISP Report Dan Williams
2026-07-08 9:49 ` Alexey Kardashevskiy
2026-07-05 22:08 ` [PATCH 15/15] PCI/TSM: Add relative MMIO offset support? Dan Williams
2026-07-08 2:25 ` Alexey Kardashevskiy
2026-07-08 18:05 ` Dan Williams (nvidia)
2026-07-06 12:51 ` [PATCH 00/15] Device Evidence and Trust for PCI Security Protocol (TDISP) Jason Gunthorpe
2026-07-06 20:55 ` Dan Williams (nvidia)
2026-07-07 12:43 ` Jason Gunthorpe
2026-07-08 0:12 ` Dan Williams (nvidia)
2026-07-08 14:31 ` Jason Gunthorpe
2026-07-09 2:45 ` Dan Williams (nvidia)
2026-07-09 13:36 ` Jason Gunthorpe
2026-07-15 9:04 ` Alexey Kardashevskiy
2026-07-16 18:51 ` Jason Gunthorpe
2026-07-28 8:20 ` Alexey Kardashevskiy
2026-07-28 23:29 ` Jason Gunthorpe
2026-08-04 1:48 ` Xu Yilun
2026-08-04 20:33 ` Ankit Agrawal
2026-08-05 17:43 ` Xu Yilun
2026-08-05 0:55 ` Jason Gunthorpe
2026-09-02 2:12 ` Xu Yilun
2026-09-02 2:20 ` Alexey Kardashevskiy
2026-09-02 7:28 ` Leon Romanovsky
2026-09-02 9:30 ` Xu Yilun
2026-09-02 15:01 ` Jason Gunthorpe
2026-09-03 2:21 ` Alexey Kardashevskiy
2026-09-03 5:59 ` Aneesh Kumar K.V
2026-09-03 6:51 ` Leon Romanovsky
2026-09-03 8:11 ` Ankit Agrawal
2026-09-03 11:04 ` Ankit Agrawal
2026-09-03 13:36 ` Lukas Wunner
2026-09-03 15:05 ` Dave Hansen
2026-09-03 17:53 ` Jason Gunthorpe
2026-09-03 20:02 ` Jonathan Cameron
2026-09-04 9:52 ` Jiri Pirko
2026-09-30 11:22 ` Jiri Pirko
2026-09-30 14:14 ` Quigley, David [this message]
2026-09-30 14:47 ` Jiri Pirko
2026-07-29 1:57 ` Ankit Agrawal
2026-08-02 18:12 ` Ankit Agrawal
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=b32438d2-4470-44b6-aa62-b691f93a2b9c@intel.com \
--to=david.quigley@intel.com \
--cc=driver-core@lists.linux.dev \
--cc=jiri@resnulli.us \
--cc=linux-coco@lists.linux.dev \
--cc=linux-pci@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox