From: Jiri Pirko <jiri@resnulli.us>
To: "Quigley, David" <david.quigley@intel.com>
Cc: linux-coco@lists.linux.dev, linux-pci@vger.kernel.org,
driver-core@lists.linux.dev
Subject: Re: [PATCH 00/15] Device Evidence and Trust for PCI Security Protocol (TDISP)
Date: Wed, 30 Sep 2026 16:47:21 +0200 [thread overview]
Message-ID: <ar0gagYLbCbxT2Ay@FV6GYCPJ69> (raw)
In-Reply-To: <b32438d2-4470-44b6-aa62-b691f93a2b9c@intel.com>
Wed, Sep 30, 2026 at 04:14:00PM +0200, david.quigley@intel.com wrote:
>Is there a way for this to be posted as its own patch set so we can provide
>feedback inline? Also do we have any other potential uses for your proposed
>ctlv mechanism or is attestation the only user at the moment?
Will do that, still need to do some work on it before though.
So far I focus on attestation with ctlv, as that is my immediate target.
But the mechanism is quite generic, easy to be used by anyone.
>
>On 9/30/2026 5:22 AM, Jiri Pirko wrote:
>> Fri, Sep 04, 2026 at 11:52:12AM +0200, jiri@resnulli.us wrote:
>> > Thu, Sep 03, 2026 at 03:36:54PM +0200, lukas@wunner.de wrote:
>> > > [+cc Jonathan, start of thread is here:
>> > > https://lore.kernel.org/all/20260902150125.GD2890729@ziepe.ca/
>> > > ]
>> > >
>> > > On Wed, Sep 02, 2026 at 12:01:25PM -0300, Jason Gunthorpe wrote:
>> >
>> > [..]
>> >
>> >
>> > > > I've asked Jiri Pirko to work on
>> > > > the PCI evidence uAPI based on his deep netlink experience
>> > > netlink isn't well suited to transport large blobs because the nlattr
>> > > len is u16. (The len of the enclosing nlmsg is u32, which is sufficient.)
>> > >
>> > > Previous approaches, including the one proposed by Dan in this series,
>> > > work around the problem by splitting the blob into a sequence of nlattrs.
>> > > I think we should instead extend the netlink protocol with 32-bit "jumbo"
>> > > attributes.
>> > >
>> > > I suggest we reserve bit 13 of nla_type as NLA_F_JUMBO and use the
>> > > the first 4 bytes after the struct nlattr header as length (if the
>> > > jumbo flag is set).
>> > >
>> > >
>> > > A second problem is that the size of a socket buffer's linear data
>> > > is limited. Also, copying the blob into the nlmsg is a bit wasteful
>> > > and we'd want zero copy instead. The solution I've come up with is
>> > > to attach the pages backing the blob as fragments to the skb.
>> > > It's very simple, overcomes the skb size limitation and allows for
>> > > zero-copy:
>> > >
>> > > https://github.com/l1k/linux/commit/6e73bb999128
>> > >
>> > > That commit is from January and the time I've been able to devote
>> > > to this has since been limited as my employer prioritized various
>> > > AER feature gaps and fixes.
>> > >
>> > > I worked on this for native PCI device authentication, which faces
>> > > the same netlink blob issue as TSM-mediated authentication.
>> > > Both should use the same uABI for evidence exposure. Additionally,
>> > > native device authentication may be used by non-PCI buses such as
>> > > ATA or SCSI. The uABI should work for those use cases as well.
>> > Not sure if netlink as actually the best fit for this purpose,
>> > for large blob transfers ioctl-based iface is probably much more
>> > convenient. I'm working on a uapi framework that make the best of
>> > netlink and takes it over to a fd-based ioctl. I call it CTLV, here's
>> > a link to an early pre-RFC draft:
>> >
>> > https://github.com/jpirko/linux_mlxsw/commits/wip_ctlv_pre_rfc_draft1/
>> >
>> [..]
>>
>> Following up on this, I have a very early draft of an attestation
>> framework here:
>>
>> https://github.com/jpirko/linux_mlxsw/commits/wip_attestation_pre_rfc_draft1/
>>
>> It introduces a provider-neutral, fd-based interface for evidence
>> retrieval, userspace verdicts tied to exact device/evidence generations,
>> measurement registers and their journal, events, and device-security
>> state transitions. Large evidence is written directly to referenced
>> buffers instead of being split across Netlink messages.
>>
>> For this series, the intent is to replace the device-evidence
>> Generic Netlink UAPI and the draft PCI/TSM evidence-accept UAPI.
>> It does not replace PCI/TSM connect/disconnect or lock/unlock,
>> nor the underlying device-trust, SPDM/IDE/TDISP, MMIO, or
>> DMA machinery.
>>
>> The branch currently contains the core, a simulation provider with
>> tests, and a TDX provider demonstrating the provider boundary.
>> The PCI/TSM provider is not implemented yet.
next prev parent reply other threads:[~2026-09-30 14:47 UTC|newest]
Thread overview: 76+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-05 22:08 [PATCH 00/15] Device Evidence and Trust for PCI Security Protocol (TDISP) Dan Williams
2026-07-05 22:08 ` [PATCH 01/15] netlink: specs: Introduce multi-message blobs for SPDM Dan Williams
2026-07-08 11:13 ` Donald Hunter
2026-07-11 1:43 ` Dan Williams (nvidia)
2026-07-08 13:23 ` Donald Hunter
2026-07-22 1:20 ` Jakub Kicinski
2026-08-02 17:58 ` Ankit Agrawal
2026-08-03 16:35 ` Jakub Kicinski
2026-07-05 22:08 ` [PATCH 02/15] tools: ynl: Teach pyynl to handle blobs Dan Williams
2026-07-08 13:48 ` Donald Hunter
2026-07-05 22:08 ` [PATCH 03/15] tools: ynl: Teach ynl_gen_c to validate and dump 'blob' attributes Dan Williams
2026-07-05 22:08 ` [PATCH 04/15] device core: Introduce "device evidence" over netlink Dan Williams
2026-07-08 13:22 ` Donald Hunter
2026-07-05 22:08 ` [PATCH 05/15] device core: Add "device evidence" 'validate' command Dan Williams
2026-07-05 22:08 ` [PATCH 06/15] PCI/TSM: Add device evidence support Dan Williams
2026-07-08 5:00 ` Alexey Kardashevskiy
2026-07-08 18:25 ` Dan Williams (nvidia)
2026-07-05 22:08 ` [PATCH 07/15] modules: Document the global async_probe parameter Dan Williams
2026-07-17 13:44 ` Nikolay Borisov
2026-07-05 22:08 ` [PATCH 08/15] device core: Initial device trust infrastructure Dan Williams
2026-07-06 13:45 ` Jason Gunthorpe
2026-07-05 22:08 ` [PATCH 09/15] PCI, device core: Move "untrusted" concept to DEVICE_TRUST_ADVERSARY Dan Williams
2026-07-06 13:49 ` Jason Gunthorpe
2026-07-07 13:04 ` Robin Murphy
2026-07-05 22:08 ` [PATCH 10/15] PCI/TSM: Add device interface security LOCKED support Dan Williams
2026-07-05 22:08 ` [PATCH 11/15] PCI/TSM: Add device interface security RUN support Dan Williams
2026-07-05 22:08 ` [PATCH 12/15] PCI/TSM: Add device interface security DMA enable/disable Dan Williams
2026-07-05 22:08 ` [PATCH 13/15] PCI, device core: Add private memory access for DEVICE_TRUST_TCB Dan Williams
2026-07-06 12:42 ` Aneesh Kumar K.V
2026-07-08 18:06 ` Dan Williams (nvidia)
2026-07-08 18:10 ` Aneesh Kumar K.V
2026-07-09 6:32 ` Alexey Kardashevskiy
2026-07-09 7:38 ` Alexey Kardashevskiy
2026-07-05 22:08 ` [PATCH 14/15] PCI/TSM: Create MMIO descriptors via TDISP Report Dan Williams
2026-07-08 9:49 ` Alexey Kardashevskiy
2026-07-05 22:08 ` [PATCH 15/15] PCI/TSM: Add relative MMIO offset support? Dan Williams
2026-07-08 2:25 ` Alexey Kardashevskiy
2026-07-08 18:05 ` Dan Williams (nvidia)
2026-07-06 12:51 ` [PATCH 00/15] Device Evidence and Trust for PCI Security Protocol (TDISP) Jason Gunthorpe
2026-07-06 20:55 ` Dan Williams (nvidia)
2026-07-07 12:43 ` Jason Gunthorpe
2026-07-08 0:12 ` Dan Williams (nvidia)
2026-07-08 14:31 ` Jason Gunthorpe
2026-07-09 2:45 ` Dan Williams (nvidia)
2026-07-09 13:36 ` Jason Gunthorpe
2026-07-15 9:04 ` Alexey Kardashevskiy
2026-07-16 18:51 ` Jason Gunthorpe
2026-07-28 8:20 ` Alexey Kardashevskiy
2026-07-28 23:29 ` Jason Gunthorpe
2026-08-04 1:48 ` Xu Yilun
2026-08-04 20:33 ` Ankit Agrawal
2026-08-05 17:43 ` Xu Yilun
2026-08-05 0:55 ` Jason Gunthorpe
2026-09-02 2:12 ` Xu Yilun
2026-09-02 2:20 ` Alexey Kardashevskiy
2026-09-02 7:28 ` Leon Romanovsky
2026-09-02 9:30 ` Xu Yilun
2026-09-02 15:01 ` Jason Gunthorpe
2026-09-03 2:21 ` Alexey Kardashevskiy
2026-09-03 5:59 ` Aneesh Kumar K.V
2026-09-03 6:51 ` Leon Romanovsky
2026-09-03 8:11 ` Ankit Agrawal
2026-09-03 11:04 ` Ankit Agrawal
2026-09-03 13:36 ` Lukas Wunner
2026-09-03 15:05 ` Dave Hansen
2026-09-03 17:53 ` Jason Gunthorpe
2026-09-03 20:02 ` Jonathan Cameron
2026-09-04 9:52 ` Jiri Pirko
2026-09-30 11:22 ` Jiri Pirko
2026-09-30 14:14 ` Quigley, David
2026-09-30 14:47 ` Jiri Pirko [this message]
2026-09-14 19:29 ` Quigley, David
2026-09-15 2:07 ` Alexey Kardashevskiy
2026-10-07 12:21 ` Alexey Kardashevskiy
2026-07-29 1:57 ` Ankit Agrawal
2026-08-02 18:12 ` Ankit Agrawal
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=ar0gagYLbCbxT2Ay@FV6GYCPJ69 \
--to=jiri@resnulli.us \
--cc=david.quigley@intel.com \
--cc=driver-core@lists.linux.dev \
--cc=linux-coco@lists.linux.dev \
--cc=linux-pci@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox