From: Linlin Zhang <linlin.zhang@oss.qualcomm.com>
To: ebiggers@kernel.org, axboe@kernel.dk, mst@redhat.com,
jasowangio@gmail.com, James.Bottomley@HansenPartnership.com,
martin.petersen@oracle.com, robh@kernel.org, krzk+dt@kernel.org,
conor+dt@kernel.org, linux-block@vger.kernel.org,
linux-crypto@vger.kernel.org, linux-scsi@vger.kernel.org,
virtualization@lists.linux.dev, devicetree@vger.kernel.org,
linux-arm-msm@vger.kernel.org
Cc: neeraj.soni@oss.qualcomm.com, gaurav.kashyap@oss.qualcomm.com,
mani@kernel.org, andersson@kernel.org, konradybcio@kernel.org,
bvanassche@acm.org, alim.akhtar@samsung.com,
avri.altman@sandisk.com, stefanha@redhat.com,
pbonzini@redhat.com, eperezma@redhat.com,
xuanzhuo@linux.alibaba.com, linux-kernel@vger.kernel.org
Subject: [PATCH v1 03/11] soc: qcom: crypto_virt: add support for create, prepare and import keys
Date: Thu, 27 Aug 2026 09:07:12 -0700 [thread overview]
Message-ID: <20260827160806.1295313-4-linlin.zhang@oss.qualcomm.com> (raw)
In-Reply-To: <20260827160806.1295313-1-linlin.zhang@oss.qualcomm.com>
From: linlzhan <linlin.zhang@oss.qualcomm.com>
The SCM interfaces used to generate, prepare and import hardware
wrapped keys require the exact wrapped key size as input. The size
is ICE hardware specific and cannot be derived by the guest.
Since the guest does not have direct access to the ICE hardware and
the information is not exposed through virtio, obtain the wrapped
key size from the "wrapped-key-size" DT property.
Convert the driver to a platform_driver matching
"qcom,crypto-virt" and initialize the wrapped-key operations during
probe. When a valid wrapped key size is provided, enable the SCM
based wrapped-key helpers:
generate_key -> qcom_scm_generate_ice_key()
prepare_key -> qcom_scm_prepare_ice_key()
import_key -> qcom_scm_import_ice_key()
If the property is missing or invalid, the driver still probes
successfully. In that case, only wrapped-key generation,
preparation and import are unavailable, while key programming and
eviction continue to work for keys provisioned through other
mechanisms.
Signed-off-by: linlzhan <linlin.zhang@oss.qualcomm.com>
---
drivers/soc/qcom/crypto_virt.c | 114 ++++++++++++++++++++++++++++++++-
1 file changed, 111 insertions(+), 3 deletions(-)
diff --git a/drivers/soc/qcom/crypto_virt.c b/drivers/soc/qcom/crypto_virt.c
index 4ee2a36af6c1..93c7993fb4a5 100644
--- a/drivers/soc/qcom/crypto_virt.c
+++ b/drivers/soc/qcom/crypto_virt.c
@@ -1,11 +1,15 @@
// SPDX-License-Identifier: GPL-2.0-only
#include <linux/module.h>
+#include <linux/of.h>
+#include <linux/platform_device.h>
#include <linux/types.h>
#include <linux/blk-crypto.h>
#include <linux/virtio_blk_crypto_ext.h>
#include <linux/firmware/qcom/qcom_scm.h>
+static unsigned int g_wrapped_key_size;
+
static int crypto_virt_program_key(const struct blk_crypto_key *key,
unsigned int slot)
{
@@ -17,7 +21,7 @@ static int crypto_virt_program_key(const struct blk_crypto_key *key,
return -EINVAL;
}
- /* Only AES-256-XTS has been tested so far. */
+ /* Only AES-256-XTS is supported so far. */
if (key->crypto_cfg.crypto_mode !=
BLK_ENCRYPTION_MODE_AES_256_XTS) {
pr_err_ratelimited("Unsupported crypto mode: %d\n",
@@ -63,24 +67,128 @@ static int crypto_virt_derive_sw_secret_key(const u8 *eph_key, size_t eph_key_si
return ret;
}
+static int crypto_virt_generate_key(u8 lt_key[BLK_CRYPTO_MAX_HW_WRAPPED_KEY_SIZE])
+{
+ int ret;
+
+ if (!g_wrapped_key_size) {
+ pr_err("%s: no expected wrapped key size\n", __func__);
+ return -EINVAL;
+ }
+
+ ret = qcom_scm_generate_ice_key(lt_key, g_wrapped_key_size);
+ if (ret) {
+ pr_err("%s: generate hardware wrapped key failed: %d\n", __func__, ret);
+ return ret;
+ }
+
+ return g_wrapped_key_size;
+}
+
+static int crypto_virt_prepare_key(const u8 *lt_key, size_t lt_key_size,
+ u8 eph_key[BLK_CRYPTO_MAX_HW_WRAPPED_KEY_SIZE])
+{
+ int ret;
+
+ if (!g_wrapped_key_size) {
+ pr_err("%s: no expected wrapped key size\n", __func__);
+ return -EINVAL;
+ }
+
+ ret = qcom_scm_prepare_ice_key(lt_key, lt_key_size,
+ eph_key, g_wrapped_key_size);
+ if (ret == -EIO || ret == -EINVAL)
+ ret = -EBADMSG; /* probably invalid key */
+
+ if (ret) {
+ pr_err("%s: prepare hardware wrapped key failed: %d\n", __func__, ret);
+ return ret;
+ }
+
+ return g_wrapped_key_size;
+}
+
+static int crypto_virt_import_key(const u8 *raw_key, size_t raw_key_size,
+ u8 lt_key[BLK_CRYPTO_MAX_HW_WRAPPED_KEY_SIZE])
+{
+ int ret;
+
+ if (!g_wrapped_key_size) {
+ pr_err("%s: no expected wrapped key size\n", __func__);
+ return -EINVAL;
+ }
+
+ ret = qcom_scm_import_ice_key(raw_key, raw_key_size,
+ lt_key, g_wrapped_key_size);
+ if (ret) {
+ pr_err("%s: import hardware wrapped key failed: %d\n", __func__, ret);
+ return ret;
+ }
+
+ return g_wrapped_key_size;
+}
+
static struct virtblk_crypto_variant_ops virtblk_crypto_qcom_vops = {
.owner = THIS_MODULE,
.program_key = crypto_virt_program_key,
.evict_key = crypto_virt_invalidate_key,
.derive_sw_secret_key = crypto_virt_derive_sw_secret_key,
+ .generate_key = crypto_virt_generate_key,
+ .prepare_key = crypto_virt_prepare_key,
+ .import_key = crypto_virt_import_key,
};
-static int __init crypto_virt_init(void)
+static int crypto_virt_probe(struct platform_device *pdev)
{
+ int ret;
+
+ ret = of_property_read_u32(pdev->dev.of_node, "qcom,wrapped-key-size",
+ &g_wrapped_key_size);
+ if (ret)
+ dev_warn(&pdev->dev, "qcom,wrapped-key-size not found\n");
+
+ if (!g_wrapped_key_size ||
+ g_wrapped_key_size > BLK_CRYPTO_MAX_HW_WRAPPED_KEY_SIZE) {
+ dev_err(&pdev->dev,
+ "invalid qcom,wrapped-key-size %u, won't support generate/import/prepare hardware wrapped key\n",
+ g_wrapped_key_size);
+ g_wrapped_key_size = 0;
+ }
+
virtblk_set_crypto_ops(&virtblk_crypto_qcom_vops);
return 0;
}
+
+static void crypto_virt_remove(struct platform_device *pdev)
+{
+ virtblk_set_crypto_ops(NULL);
+}
+
+static const struct of_device_id crypto_virt_of_match[] = {
+ { .compatible = "qcom,crypto-virt" },
+ { }
+};
+MODULE_DEVICE_TABLE(of, crypto_virt_of_match);
+
+static struct platform_driver crypto_virt_driver = {
+ .probe = crypto_virt_probe,
+ .remove = crypto_virt_remove,
+ .driver = {
+ .name = "crypto_virt",
+ .of_match_table = crypto_virt_of_match,
+ },
+};
+
+static int __init crypto_virt_init(void)
+{
+ return platform_driver_register(&crypto_virt_driver);
+}
module_init(crypto_virt_init);
#if IS_MODULE(CONFIG_QCOM_CRYPTO_VIRT)
static void __exit crypto_virt_exit(void)
{
- virtblk_set_crypto_ops(NULL);
+ platform_driver_unregister(&crypto_virt_driver);
}
module_exit(crypto_virt_exit);
#endif
--
2.34.1
next prev parent reply other threads:[~2026-08-27 16:08 UTC|newest]
Thread overview: 26+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-27 16:07 [PATCH v1 00/11] FBE virtualization: inline encryption for virtio-blk guests Linlin Zhang
2026-08-27 16:07 ` [PATCH v1 01/11] virtio_blk: add inline encryption support Linlin Zhang
2026-08-27 16:23 ` sashiko-bot
2026-08-27 16:07 ` [PATCH v1 02/11] soc: qcom: add crypto_virt backend for virtio-blk inline crypto Linlin Zhang
2026-08-27 16:24 ` sashiko-bot
2026-08-27 16:07 ` Linlin Zhang [this message]
2026-08-27 16:19 ` [PATCH v1 03/11] soc: qcom: crypto_virt: add support for create, prepare and import keys sashiko-bot
2026-08-27 16:07 ` [PATCH v1 04/11] dt-bindings: soc: qcom: add binding for qcom,crypto-virt Linlin Zhang
2026-08-27 16:14 ` sashiko-bot
2026-08-27 16:07 ` [PATCH v1 05/11] blk-crypto: add slot-based inline encryption path Linlin Zhang
2026-08-27 16:26 ` sashiko-bot
2026-08-27 16:07 ` [PATCH v1 06/11] scsi: ufs: core: add slot path to ufshcd_prepare_lrbp_crypto Linlin Zhang
2026-08-27 16:20 ` sashiko-bot
2026-08-27 16:07 ` [PATCH v1 07/11] blk-crypto: move bio_crypt_dun_increment() to the public header Linlin Zhang
2026-08-27 16:18 ` sashiko-bot
2026-08-27 16:07 ` [PATCH v1 08/11] block: add /dev/blk-crypto-proxy for host-side virtio-blk inline encryption Linlin Zhang
2026-08-27 16:24 ` sashiko-bot
2026-08-27 16:07 ` [PATCH v1 09/11] soc: qcom: add ICE keyslot partitioning driver for guest VMs Linlin Zhang
2026-08-27 16:17 ` sashiko-bot
2026-08-27 16:07 ` [PATCH v1 10/11] blk-crypto: add slot_offset to blk_crypto_profile Linlin Zhang
2026-08-27 16:23 ` sashiko-bot
2026-08-27 16:07 ` [PATCH v1 11/11] scsi: ufs: ufs-qcom: support ICE keyslot partitioning for guest VMs Linlin Zhang
2026-08-27 16:26 ` sashiko-bot
2026-08-27 18:42 ` [PATCH v1 00/11] FBE virtualization: inline encryption for virtio-blk guests Eric Biggers
2026-08-28 15:37 ` Linlin Zhang
2026-08-28 15:56 ` Linlin Zhang
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260827160806.1295313-4-linlin.zhang@oss.qualcomm.com \
--to=linlin.zhang@oss.qualcomm.com \
--cc=James.Bottomley@HansenPartnership.com \
--cc=alim.akhtar@samsung.com \
--cc=andersson@kernel.org \
--cc=avri.altman@sandisk.com \
--cc=axboe@kernel.dk \
--cc=bvanassche@acm.org \
--cc=conor+dt@kernel.org \
--cc=devicetree@vger.kernel.org \
--cc=ebiggers@kernel.org \
--cc=eperezma@redhat.com \
--cc=gaurav.kashyap@oss.qualcomm.com \
--cc=jasowangio@gmail.com \
--cc=konradybcio@kernel.org \
--cc=krzk+dt@kernel.org \
--cc=linux-arm-msm@vger.kernel.org \
--cc=linux-block@vger.kernel.org \
--cc=linux-crypto@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-scsi@vger.kernel.org \
--cc=mani@kernel.org \
--cc=martin.petersen@oracle.com \
--cc=mst@redhat.com \
--cc=neeraj.soni@oss.qualcomm.com \
--cc=pbonzini@redhat.com \
--cc=robh@kernel.org \
--cc=stefanha@redhat.com \
--cc=virtualization@lists.linux.dev \
--cc=xuanzhuo@linux.alibaba.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox