Discussion of the implementations of VIRTIO specification
 help / color / mirror / Atom feed
From: Stefan Hajnoczi <stefanha@redhat.com>
To: Linlin Zhang <linlin.zhang@oss.qualcomm.com>
Cc: virtio-dev@lists.linux.dev, ebiggers@kernel.org,
	neeraj.soni@oss.qualcomm.com
Subject: Re: [PATCH v3 0/2] virtio-blk: Add inline encryption support
Date: Thu, 17 Sep 2026 17:08:41 -0400	[thread overview]
Message-ID: <20260917210841.GD331587@fedora> (raw)
In-Reply-To: <20260913161628.368484-1-linlin.zhang@oss.qualcomm.com>

[-- Attachment #1: Type: text/plain, Size: 1778 bytes --]

On Sun, Sep 13, 2026 at 09:16:13AM -0700, Linlin Zhang wrote:
> From: linlzhan <linlin.zhang@oss.qualcomm.com>
> 
> This series adds virtio-blk inline encryption support for devices backed
> by storage hardware with an inline crypto engine.
> 
> The protocol exposes device capabilities such as keyslot count, maximum
> DUN size, and supported key types. Encrypted requests identify a
> provisioned keyslot and carry a 256-bit DUN. Key management and crypto
> capability discovery use the block device control virtqueue.
> 
> The control virtqueue is defined as a generic framework so that its
> buffer layout and queue placement are independent of any particular
> control command. Inline encryption then builds on this framework with
> explicit crypto command formats, capability validation, and keyslot
> state semantics.
> 
> All key related operatios are handled in the control virtqueue, and
> the crypto I/O request is handled in the request queue.
> 
> For background on inline encryption in UFS and eMMC storage, see:
> https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/tree/Documentation/block/inline-encryption.rst
> 
> changes in v3:
>  - Add a control virtqueue
>  - Move key program/evict/derive_sw_secret/generate/prepare/import to
>    the control virtqueue

Thank you. This was a big change, especially if you already have an
implementation. I appreciate it!

My main feedback is that the new control virtqueue commands are not yet
documented in enough detail so that implementors could implement them.
Once you've decided on the precise semantics, error codes, etc and added
them to the spec, then this will round off the inline encryption
feature. I look forward to reviewing that in the future.

Stefan

[-- Attachment #2: signature.asc --]
[-- Type: application/pgp-signature, Size: 488 bytes --]

  parent reply	other threads:[~2026-09-21 13:37 UTC|newest]

Thread overview: 16+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-13 16:16 [PATCH v3 0/2] virtio-blk: Add inline encryption support Linlin Zhang
2026-09-13 16:16 ` [PATCH v3 1/2] virtio-blk: Add the control virtqueue Linlin Zhang
2026-09-17 20:16   ` Stefan Hajnoczi
2026-09-22 11:10     ` Linlin Zhang
2026-09-13 16:16 ` [PATCH v3 2/2] virtio-blk: Add inline encryption support Linlin Zhang
2026-09-17 21:05   ` Stefan Hajnoczi
2026-09-24  9:32     ` Linlin Zhang
2026-09-17 21:08 ` Stefan Hajnoczi [this message]
2026-09-22  4:29   ` [PATCH v3 0/2] " Linlin Zhang
2026-09-22 13:14     ` Stefan Hajnoczi
2026-09-24  9:35       ` Linlin Zhang
2026-09-29 22:46         ` Max Gurtovoy
2026-10-08  9:17           ` Linlin Zhang
2026-10-08 10:15             ` Michael S. Tsirkin
2026-10-09 11:21               ` Linlin Zhang
2026-10-09 12:25                 ` Michael S. Tsirkin

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260917210841.GD331587@fedora \
    --to=stefanha@redhat.com \
    --cc=ebiggers@kernel.org \
    --cc=linlin.zhang@oss.qualcomm.com \
    --cc=neeraj.soni@oss.qualcomm.com \
    --cc=virtio-dev@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox