From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mx0a-0031df01.pphosted.com (mx0a-0031df01.pphosted.com [205.220.168.131]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 483DF289E13 for ; Wed, 2 Sep 2026 05:58:27 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=205.220.168.131 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788328708; cv=none; b=DbONd6AiShk7ao7QNnjJRZUzZaB1B87Z/xmyFTqee68LZXM9Cy/AYiv4MwP5u1ug4/KdMDh7DpYSLQdILEMZn5wJ5AIhdbQVxRToOTjaJXFd+2OYIVCI1v/Nl3W/xLOo9f1SNQZlfCiJ/n+hnCvvN61Z65Ie47OLHARBK5DiPWY= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788328708; c=relaxed/simple; bh=YU8UPMKZ/ySiuNk1+MpS6FNLDJVxn5Pnh3Srux/+E3g=; h=Message-ID:Date:MIME-Version:Subject:To:Cc:References:From: In-Reply-To:Content-Type; b=DRhp0QZN3Hn6xh5V4FuOWC5gDKuoOIjXZOVDx2I9f78+oLXKGDjnPFJHE3dCF/lsZaH0/ckaeiDJKeEhHBBm1JBgry25nx0ys4bJMR3gli8vloyLAX/ug/qZEo82psawLfxH90fv3C8ojPXQUzFhkzRqzn5feh3K2KwyeMh5V/E= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=oss.qualcomm.com; spf=pass smtp.mailfrom=oss.qualcomm.com; dkim=pass (2048-bit key) header.d=qualcomm.com header.i=@qualcomm.com header.b=Z3Cupj4x; dkim=pass (2048-bit key) header.d=oss.qualcomm.com header.i=@oss.qualcomm.com header.b=VvGu/Hbs; arc=none smtp.client-ip=205.220.168.131 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=oss.qualcomm.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=oss.qualcomm.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=qualcomm.com header.i=@qualcomm.com header.b="Z3Cupj4x"; dkim=pass (2048-bit key) header.d=oss.qualcomm.com header.i=@oss.qualcomm.com header.b="VvGu/Hbs" Received: from pps.filterd (m0279864.ppops.net [127.0.0.1]) by mx0a-0031df01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 6825YHbW3630617 for ; Wed, 2 Sep 2026 05:58:26 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=qualcomm.com; h= cc:content-transfer-encoding:content-type:date:from:in-reply-to :message-id:mime-version:references:subject:to; s=qcppdkim1; bh= 1OvAK2FF1tp6tcmLzdukvxlL1CZuIQ6FiGRnYYPcWf4=; b=Z3Cupj4xK0M8m9+n HjPNoKTjeyNo+c+jG+BW7b81ZBszWFE9bGKqqv8VtmKwpjwQmAyzR9DQy6XOEOTn JIik4SxlBmNoATDKXWCRQOhT1fTMHvT+qwulbIt7juSNHHiX/sfhKDwfUPiA/vMp Rb1Lz+1LQuMZlkDq/BmEUf/fRmTSsKks3w9dcB9pHDaM5AZYj6bxXdUhl5/JO6r1 qTgIw7Qh7P9izcq01KhGO8WPbBSMNT4QlAB8p2HTuw8skaSvhoN7q0g9q+j71Yfi 8nMskBlrvZH0VVkD4Fejfvz5RHKCV/nQCnOGHuDmB3DZXWw5NCwZAfxoUbguo3IS cLMX2g== Received: from mail-pj1-f71.google.com (mail-pj1-f71.google.com [209.85.216.71]) by mx0a-0031df01.pphosted.com (PPS) with ESMTPS id 4ge39cjagm-1 (version=TLSv1.3 cipher=TLS_AES_128_GCM_SHA256 bits=128 verify=NOT) for ; Wed, 02 Sep 2026 05:58:26 +0000 (GMT) Received: by mail-pj1-f71.google.com with SMTP id 98e67ed59e1d1-399311947f6so1313722a91.0 for ; Tue, 01 Sep 2026 22:58:26 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=oss.qualcomm.com; s=google; t=1788328706; x=1788933506; darn=vger.kernel.org; h=content-transfer-encoding:content-type:in-reply-to:from :content-language:references:cc:to:subject:user-agent:mime-version :date:message-id:from:to:cc:subject:date:message-id:reply-to :content-type; bh=1OvAK2FF1tp6tcmLzdukvxlL1CZuIQ6FiGRnYYPcWf4=; b=VvGu/HbsQTDRB/ELpMwv5hYLbnia3iQxcd+R0H6MWLsbUYg+8sZW9KzB+VNB+8ay+5 c2H6lU/rEFspuzoxYak5vrp5XqtI7dEiT/BNAgX9IDO2YsFSfcqOgR6pFq3fQcsQ7j3V Zp1clPfH3sQ5kAUaZwKCNiCtUbWt9ASnNsAPsAqzDx54ols1X9AzsNnQONorAmrB3oXH VjJGsDm+Q/sorQw3cMA94OjHS2exuguMQTJCT3wl5nJMq93sI8BgM68nJ1HuFEOxkABK /RCNorTM2Hknmm5/1RK0VtQys/jIl6unKerOLfqtATwpsxqOKjrW9JzA9DbzO5TBPuOF +9ow== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788328706; x=1788933506; h=content-transfer-encoding:content-type:in-reply-to:from :content-language:references:cc:to:subject:user-agent:mime-version :date:message-id:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=1OvAK2FF1tp6tcmLzdukvxlL1CZuIQ6FiGRnYYPcWf4=; b=Dms5avF7dxIh+hz3lWusDSkRokwxs4zTrd5FWEbhzsf5hESWuzyzKItKD9vYCqNJYU fCNKGelBbHmQB1qG6xHRK3jEF2Lq3Vldvceinwf/EE54qmsQvQYrV/XVteg7kD14ZDFt gBe7I0I9XcQo5TujaJqABAYj1veUkJuIQCu+3dmdvQkkrzUzq0VFMMinXhu7Ntg42MkY KSs+Bu2ZGLb8WUww4SM1xoE6vwIIqRFTbKml4Z/JY0ZBPiqL7sSxGa9f8Lz2WhWL/o8V 4GPsbyZ33jbJuReAJ3BD5YY+Z91nCoKh7fVZHFZoKKuWu2OF+kW43h7Za5WrAd7AqO+x ECDQ== X-Forwarded-Encrypted: i=1; AKwUvBxfDPXbDZl5Nw/uzBqUA+ylaEn+47kM9lur0nIHPJEP7T8hn+hQSaR299HIdJARDY1f3Zk2PjZzInQBcg==@vger.kernel.org X-Gm-Message-State: AFuF++n7vbvqmnDCKD8BDdwj4RuHiSY8POQuCCblN8RkUjFbq2//sqsN hxe1Q2+MfJBPvln2DT8KLpbizf/OGPFCmDUPZiCMF8jtdCn3APjptnknW9OIA74fqljnWCjQSIk Ax88i7U2ghe9rvA8R1q04cxbTC7gIKAI5ewd7YV92wAd+Dnxn3LEVjBRLctgqDSUv4A== X-Gm-Gg: AYBFou2nuWWWyFtzl/x/HsqD+8goIZteJXnAFvwlW58IoGpa+0ZZromyo9Y/KXfGcGY i/i7qW8LEkIko9070v5DuWzjgsR6X74s8S9Caa/z3XC9wW5850hln+QwaMPaVzVmjWZ1mPasTkQ WiWYJ2OeOt1Xkzs+IbI7EmI8VBEvpso5hPZW01KNHh9hAajHMvqrt+hJKv0uT0pO2r0Ku8ZTRrl kd+LU12Cf3fmwiE2YEgnBeAf4eUjWW0+vHAdvkEJIXDOqQ1c/stGYtN3VUTWXX00s47fB6tODqu PURQEdMqE8c2FgpYKtODeHWhYxSpeVGtWsjwihG/E7pCU9QFvrqqIZHivuM+q5GNg46Fq8GEVd/ JdrZ6O+X+XkO9513QjI+PfPt6weFRQWZzpd26vhTf+msMXdvbkOLxBIRy X-Received: by 2002:a17:90b:4ac9:b0:398:9bd5:490c with SMTP id 98e67ed59e1d1-39aee0b498dmr2783812a91.19.1788328705731; Tue, 01 Sep 2026 22:58:25 -0700 (PDT) X-Received: by 2002:a17:90b:4ac9:b0:398:9bd5:490c with SMTP id 98e67ed59e1d1-39aee0b498dmr2783746a91.19.1788328705240; Tue, 01 Sep 2026 22:58:25 -0700 (PDT) Received: from [10.110.50.50] (i-global254.qualcomm.com. [199.106.103.254]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-32f07b79898sm3792600eec.15.2026.09.01.22.58.19 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Tue, 01 Sep 2026 22:58:24 -0700 (PDT) Message-ID: Date: Wed, 2 Sep 2026 13:58:17 +0800 Precedence: bulk X-Mailing-List: linux-block@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: Re: [PATCH v1 01/11] virtio_blk: add inline encryption support To: Stefan Hajnoczi Cc: ebiggers@kernel.org, axboe@kernel.dk, mst@redhat.com, jasowangio@gmail.com, James.Bottomley@hansenpartnership.com, martin.petersen@oracle.com, robh@kernel.org, krzk+dt@kernel.org, conor+dt@kernel.org, linux-block@vger.kernel.org, linux-crypto@vger.kernel.org, linux-scsi@vger.kernel.org, virtualization@lists.linux.dev, devicetree@vger.kernel.org, linux-arm-msm@vger.kernel.org, neeraj.soni@oss.qualcomm.com, gaurav.kashyap@oss.qualcomm.com, mani@kernel.org, andersson@kernel.org, konradybcio@kernel.org, bvanassche@acm.org, alim.akhtar@samsung.com, avri.altman@sandisk.com, pbonzini@redhat.com, eperezma@redhat.com, xuanzhuo@linux.alibaba.com, linux-kernel@vger.kernel.org References: <20260827160806.1295313-1-linlin.zhang@oss.qualcomm.com> <20260827160806.1295313-2-linlin.zhang@oss.qualcomm.com> <20260901194817.GE729142@fedora> Content-Language: en-US From: Linlin Zhang In-Reply-To: <20260901194817.GE729142@fedora> Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit X-Authority-Analysis: v=2.4 cv=T968ifKQ c=1 sm=1 tr=0 ts=6a97bb02 cx=c_pps a=UNFcQwm+pnOIJct1K4W+Mw==:117 a=JYp8KDb2vCoCEuGobkYCKw==:17 a=IkcTkHD0fZMA:10 a=VdqzKS8jKosA:10 a=s4-Qcg_JpJYA:10 a=VkNPw1HP01LnGYTKEx00:22 a=u7WPNUs3qKkmUXheDGA7:22 a=DJpcGTmdVt4CTyJn9g5Z:22 a=EUspDBNiAAAA:8 a=dlkBk7sggpSz48gVZtEA:9 a=QEXdDO2ut3YA:10 a=uKXjsCUrEbL0IQVhDsJ9:22 X-Proofpoint-ORIG-GUID: PWayBEfBwCm6AS2wDfwV5ELL6JKM023B X-Proofpoint-Spam-Info: AW1haW4tMjYwOTAyMDA1MSBTYWx0ZWRfXy8LkRHKV1tox XNe9hOUXrGOFVzPuFbczmJta35UYp6riwiZ2RBRu0gd66CwNC+sx5hxm+WacRbEl75dLbNHqRdt T6D4FKLf6vog8cl83Y/GRLH2YRAiW3Y= X-Proofpoint-GUID: PWayBEfBwCm6AS2wDfwV5ELL6JKM023B X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwOTAyMDA1MSBTYWx0ZWRfX0KEuY42CMWpR lJLeb8dcEi2Z0w25SYVOhC3mn88bmSAyUOCiqO6cnSMwMAvMsTI/n/+xPRJi7pvAn3mfzZdzaHO bcJIRzCq7acxE7+8AZ1rPona4PuAeCpBwe76Vvbf3aXujT3RwNPRANh+bjMZ8iupvhb0GHWTKmU g0iGkUhAa5XZs7Ic4sms0XLnDu8tzTyM3Tij8Nx8ENBdvQkmUy/GVG0CKk2og0lPfizPB9TXKZd KzOsO3hEyKPBtVdZTIMQ6qBYZxiX4/9ceGcfHXwDa/CyGTR3rO6ULSpC9BYcR3Re0HRAL9EGLSG AMMH12MGBpA5lbK/r0XPsyToKMXCcR6/6r6Pg8F+u5Z8DuEPiOJQMSLNUxw4aFhJBbY3cF7gaP9 mlobWILzyTMK2rSbEKpzxqymKoOq9mL86PZbvWvTwJctKSfdQvNoCmsLvD+OfBei6JenJwPHko4 05C0cg37zCy1AcV7Qzg== X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1176,Hydra:6.1.134,FMLib:17.12.100.49 definitions=2026-09-01_06,2026-09-01_03,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 suspectscore=0 adultscore=0 clxscore=1015 phishscore=0 priorityscore=1501 impostorscore=0 bulkscore=0 spamscore=0 malwarescore=0 lowpriorityscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2609020051 On 9/2/2026 3:48 AM, Stefan Hajnoczi wrote: > On Thu, Aug 27, 2026 at 09:07:10AM -0700, Linlin Zhang wrote: >> From: linlzhan >> >> Negotiate VIRTIO_BLK_F_INLINE_ENCRYPTION with the host and wire it into >> the block layer's inline-crypto framework to enable inline encryption >> on virtio block device. >> >> When the feature is present, the driver reads crypto characteristics from >> virtio config space (key-slot count, DUN size, supported key types) and >> issues VIRTIO_BLK_T_GET_CRYPTO_MODES to discover supported cipher and >> data-unit-size combinations. Encrypted requests use new request types >> VIRTIO_BLK_T_CRYPTO_IN/OUT, which append a virtio_blk_crypto_msg >> (keyslot index, DUN, data-unit-size-bits) to the standard outhdr. >> >> A new virtio block crypto extension driver (virtio_blk_crypto_ext), >> owns the blk_crypto_profile singleton and the blk_crypto_ll_ops dispatch >> table. Actual key operations are forwarded to a platform-specific >> backend registered via virtblk_set_crypto_ops(); without one, >> VIRTIO_BLK_F_INLINE_ENCRYPTION is still negotiated and the >> profile is registered, but every keyslot operation returns -EOPNOTSUPP. >> >> The shared profile is a singleton as per blk_crypto_profile is >> corresponding to one ICE hardware: the first device to negotiate the >> feature initializes it; subsequent devices reuse it only when their >> negotiated capabilities (slot count, DUN size, key types) match exactly. >> >> Signed-off-by: linlzhan >> --- >> drivers/block/Kconfig | 13 ++ >> drivers/block/Makefile | 2 + >> drivers/block/virtio_blk.c | 199 ++++++++++++++++-- >> drivers/block/virtio_blk_crypto_ext.c | 283 ++++++++++++++++++++++++++ >> include/linux/virtio_blk_crypto_ext.h | 78 +++++++ >> include/uapi/linux/virtio_blk.h | 62 ++++++ >> 6 files changed, 623 insertions(+), 14 deletions(-) >> create mode 100644 drivers/block/virtio_blk_crypto_ext.c >> create mode 100644 include/linux/virtio_blk_crypto_ext.h > > Thanks for sending this as we discuss the VIRTIO spec changes. > > Although it's nice to have all the Linux patches together, there are two > separate parts: 1. the virtio_blk.ko guest driver changes and 2. the > hypervisor blk-crypto uapi. I suggest splitting this into two patch > series to avoid confusion between these parts. It may also make review > and merging easier if we stay focussed on just the guest or just the > host parts. Thanks for the comments! I can separate them as 2 patch series in next patch. > > Stefan