From: Stefan Hajnoczi <stefanha@redhat.com>
To: Linlin Zhang <linlin.zhang@oss.qualcomm.com>
Cc: ebiggers@kernel.org, axboe@kernel.dk, mst@redhat.com,
jasowangio@gmail.com, James.Bottomley@hansenpartnership.com,
martin.petersen@oracle.com, robh@kernel.org, krzk+dt@kernel.org,
conor+dt@kernel.org, linux-block@vger.kernel.org,
linux-crypto@vger.kernel.org, linux-scsi@vger.kernel.org,
virtualization@lists.linux.dev, devicetree@vger.kernel.org,
linux-arm-msm@vger.kernel.org, neeraj.soni@oss.qualcomm.com,
gaurav.kashyap@oss.qualcomm.com, mani@kernel.org,
andersson@kernel.org, konradybcio@kernel.org, bvanassche@acm.org,
alim.akhtar@samsung.com, avri.altman@sandisk.com,
pbonzini@redhat.com, eperezma@redhat.com,
xuanzhuo@linux.alibaba.com, linux-kernel@vger.kernel.org
Subject: Re: [PATCH v1 01/11] virtio_blk: add inline encryption support
Date: Tue, 1 Sep 2026 15:48:17 -0400 [thread overview]
Message-ID: <20260901194817.GE729142@fedora> (raw)
In-Reply-To: <20260827160806.1295313-2-linlin.zhang@oss.qualcomm.com>
[-- Attachment #1: Type: text/plain, Size: 2487 bytes --]
On Thu, Aug 27, 2026 at 09:07:10AM -0700, Linlin Zhang wrote:
> From: linlzhan <linlzhan@qti.qualcomm.com>
>
> Negotiate VIRTIO_BLK_F_INLINE_ENCRYPTION with the host and wire it into
> the block layer's inline-crypto framework to enable inline encryption
> on virtio block device.
>
> When the feature is present, the driver reads crypto characteristics from
> virtio config space (key-slot count, DUN size, supported key types) and
> issues VIRTIO_BLK_T_GET_CRYPTO_MODES to discover supported cipher and
> data-unit-size combinations. Encrypted requests use new request types
> VIRTIO_BLK_T_CRYPTO_IN/OUT, which append a virtio_blk_crypto_msg
> (keyslot index, DUN, data-unit-size-bits) to the standard outhdr.
>
> A new virtio block crypto extension driver (virtio_blk_crypto_ext),
> owns the blk_crypto_profile singleton and the blk_crypto_ll_ops dispatch
> table. Actual key operations are forwarded to a platform-specific
> backend registered via virtblk_set_crypto_ops(); without one,
> VIRTIO_BLK_F_INLINE_ENCRYPTION is still negotiated and the
> profile is registered, but every keyslot operation returns -EOPNOTSUPP.
>
> The shared profile is a singleton as per blk_crypto_profile is
> corresponding to one ICE hardware: the first device to negotiate the
> feature initializes it; subsequent devices reuse it only when their
> negotiated capabilities (slot count, DUN size, key types) match exactly.
>
> Signed-off-by: linlzhan <linlin.zhang@oss.qualcomm.com>
> ---
> drivers/block/Kconfig | 13 ++
> drivers/block/Makefile | 2 +
> drivers/block/virtio_blk.c | 199 ++++++++++++++++--
> drivers/block/virtio_blk_crypto_ext.c | 283 ++++++++++++++++++++++++++
> include/linux/virtio_blk_crypto_ext.h | 78 +++++++
> include/uapi/linux/virtio_blk.h | 62 ++++++
> 6 files changed, 623 insertions(+), 14 deletions(-)
> create mode 100644 drivers/block/virtio_blk_crypto_ext.c
> create mode 100644 include/linux/virtio_blk_crypto_ext.h
Thanks for sending this as we discuss the VIRTIO spec changes.
Although it's nice to have all the Linux patches together, there are two
separate parts: 1. the virtio_blk.ko guest driver changes and 2. the
hypervisor blk-crypto uapi. I suggest splitting this into two patch
series to avoid confusion between these parts. It may also make review
and merging easier if we stay focussed on just the guest or just the
host parts.
Stefan
[-- Attachment #2: signature.asc --]
[-- Type: application/pgp-signature, Size: 488 bytes --]
next prev parent reply other threads:[~2026-09-01 19:48 UTC|newest]
Thread overview: 54+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-27 16:07 [PATCH v1 00/11] FBE virtualization: inline encryption for virtio-blk guests Linlin Zhang
2026-08-27 16:07 ` [PATCH v1 01/11] virtio_blk: add inline encryption support Linlin Zhang
2026-08-27 16:23 ` sashiko-bot
2026-09-01 19:48 ` Stefan Hajnoczi [this message]
2026-09-02 5:58 ` Linlin Zhang
2026-08-27 16:07 ` [PATCH v1 02/11] soc: qcom: add crypto_virt backend for virtio-blk inline crypto Linlin Zhang
2026-08-27 16:24 ` sashiko-bot
2026-08-31 6:56 ` Krzysztof Kozlowski
2026-09-01 9:39 ` Linlin Zhang
2026-09-01 13:58 ` Krzysztof Kozlowski
2026-08-27 16:07 ` [PATCH v1 03/11] soc: qcom: crypto_virt: add support for create, prepare and import keys Linlin Zhang
2026-08-27 16:19 ` sashiko-bot
2026-08-31 6:58 ` Krzysztof Kozlowski
2026-09-01 10:31 ` Linlin Zhang
2026-09-01 14:01 ` Krzysztof Kozlowski
2026-08-27 16:07 ` [PATCH v1 04/11] dt-bindings: soc: qcom: add binding for qcom,crypto-virt Linlin Zhang
2026-08-27 16:14 ` sashiko-bot
2026-08-31 7:01 ` Krzysztof Kozlowski
2026-09-01 10:40 ` Linlin Zhang
2026-08-27 16:07 ` [PATCH v1 05/11] blk-crypto: add slot-based inline encryption path Linlin Zhang
2026-08-27 16:26 ` sashiko-bot
2026-09-01 19:06 ` Stefan Hajnoczi
2026-08-27 16:07 ` [PATCH v1 06/11] scsi: ufs: core: add slot path to ufshcd_prepare_lrbp_crypto Linlin Zhang
2026-08-27 16:20 ` sashiko-bot
2026-09-01 19:08 ` Stefan Hajnoczi
2026-08-27 16:07 ` [PATCH v1 07/11] blk-crypto: move bio_crypt_dun_increment() to the public header Linlin Zhang
2026-08-27 16:18 ` sashiko-bot
2026-09-01 19:13 ` Stefan Hajnoczi
2026-09-02 6:02 ` Linlin Zhang
2026-08-27 16:07 ` [PATCH v1 08/11] block: add /dev/blk-crypto-proxy for host-side virtio-blk inline encryption Linlin Zhang
2026-08-27 16:24 ` sashiko-bot
2026-09-01 19:43 ` Stefan Hajnoczi
2026-08-27 16:07 ` [PATCH v1 09/11] soc: qcom: add ICE keyslot partitioning driver for guest VMs Linlin Zhang
2026-08-27 16:17 ` sashiko-bot
2026-08-31 7:02 ` Krzysztof Kozlowski
2026-09-01 10:48 ` Linlin Zhang
2026-08-27 16:07 ` [PATCH v1 10/11] blk-crypto: add slot_offset to blk_crypto_profile Linlin Zhang
2026-08-27 16:23 ` sashiko-bot
2026-08-27 16:07 ` [PATCH v1 11/11] scsi: ufs: ufs-qcom: support ICE keyslot partitioning for guest VMs Linlin Zhang
2026-08-27 16:26 ` sashiko-bot
2026-08-31 7:03 ` Krzysztof Kozlowski
2026-09-01 10:54 ` Linlin Zhang
2026-09-01 14:02 ` Krzysztof Kozlowski
[not found] ` <20260827184219.GB2137493@google.com>
2026-08-28 15:37 ` [PATCH v1 00/11] FBE virtualization: inline encryption for virtio-blk guests Linlin Zhang
2026-08-28 15:56 ` Linlin Zhang
2026-08-31 6:21 ` Linlin Zhang
2026-08-31 20:41 ` Stefan Hajnoczi
2026-09-01 9:21 ` Linlin Zhang
2026-09-01 18:47 ` Stefan Hajnoczi
2026-08-31 21:07 ` Eric Biggers
2026-09-01 8:22 ` Linlin Zhang
2026-09-01 8:45 ` Linlin Zhang
2026-09-01 19:44 ` Stefan Hajnoczi
2026-09-01 21:28 ` Eric Biggers
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260901194817.GE729142@fedora \
--to=stefanha@redhat.com \
--cc=James.Bottomley@hansenpartnership.com \
--cc=alim.akhtar@samsung.com \
--cc=andersson@kernel.org \
--cc=avri.altman@sandisk.com \
--cc=axboe@kernel.dk \
--cc=bvanassche@acm.org \
--cc=conor+dt@kernel.org \
--cc=devicetree@vger.kernel.org \
--cc=ebiggers@kernel.org \
--cc=eperezma@redhat.com \
--cc=gaurav.kashyap@oss.qualcomm.com \
--cc=jasowangio@gmail.com \
--cc=konradybcio@kernel.org \
--cc=krzk+dt@kernel.org \
--cc=linlin.zhang@oss.qualcomm.com \
--cc=linux-arm-msm@vger.kernel.org \
--cc=linux-block@vger.kernel.org \
--cc=linux-crypto@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-scsi@vger.kernel.org \
--cc=mani@kernel.org \
--cc=martin.petersen@oracle.com \
--cc=mst@redhat.com \
--cc=neeraj.soni@oss.qualcomm.com \
--cc=pbonzini@redhat.com \
--cc=robh@kernel.org \
--cc=virtualization@lists.linux.dev \
--cc=xuanzhuo@linux.alibaba.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox