From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mx0a-0031df01.pphosted.com (mx0a-0031df01.pphosted.com [205.220.168.131]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 11181379C5B for ; Fri, 22 May 2026 05:56:26 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=205.220.168.131 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1779429388; cv=none; b=a/moXKOybWq4iHjGISRF/C6nHA6IjRcf/fooAXMIaTcuizii/08JJCZzyNxqkWTSikZKGbtwA2S2BSe4oQ6+nabCi+mTTsGkRh0ooBiPPLtZd5XA5hZDseOaEZkr+oTzqhuE3pUO9I685mcIks/CjpG2CuHkB1D3nLSzSmyePYY= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1779429388; c=relaxed/simple; bh=Qt1n0KdM0wIAqdbqxxW54xRT+G2unHl8FzyI1UydKlc=; h=Message-ID:Date:MIME-Version:Subject:To:Cc:References:From: In-Reply-To:Content-Type; b=mx6YbngtezuwBAHa3EjANLWHNYRkfIgdjtiuZYVvAyVG2UAwWisXmsx0/eSb4AUEIMJAfsTmtJi5U92sYaqbGFnKt/3ixmTxdCblxMM2zxtJ6ufMFhEAk+9DZpDtFdNtvAgCzz62IsftEGduvlsR49MY+qViSOZDyKbyJXKjqEs= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=oss.qualcomm.com; spf=pass smtp.mailfrom=oss.qualcomm.com; dkim=pass (2048-bit key) header.d=qualcomm.com header.i=@qualcomm.com header.b=NqeIfyCV; dkim=pass (2048-bit key) header.d=oss.qualcomm.com header.i=@oss.qualcomm.com header.b=VJBfYsMX; arc=none smtp.client-ip=205.220.168.131 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=oss.qualcomm.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=oss.qualcomm.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=qualcomm.com header.i=@qualcomm.com header.b="NqeIfyCV"; dkim=pass (2048-bit key) header.d=oss.qualcomm.com header.i=@oss.qualcomm.com header.b="VJBfYsMX" Received: from pps.filterd (m0279862.ppops.net [127.0.0.1]) by mx0a-0031df01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 64M41lK03005120 for ; Fri, 22 May 2026 05:56:26 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=qualcomm.com; h= cc:content-transfer-encoding:content-type:date:from:in-reply-to :message-id:mime-version:references:subject:to; s=qcppdkim1; bh= LLUYimo4jYypFis8+6QYWL4/jJ4CGaTBz0co1X0lX4A=; b=NqeIfyCVxt8eVAxQ DKHom7HdAi6uhoaPXqY+sVBQS+fSAIjZYa8pKy6tNJxFPH7llUMxlKz4j5KggeP+ A1Li842oc5d7NUfTEStDXAJ1sKjLyeICL4+QB0bnwfOhVM3GDNebBnhK3j3qNmO8 4IEXMl5Qzudmh8Tt+Wt7FqnAYVhNTXH0uxmIK+yogQ/PPpMrskm+m8YpGjquCwWX U4KDxOTq2USO6kOhpL6A2YUEVWZYAuMbxcY/CztSM6eHEg3dKNHmF11IIMjzD2A4 pta1yi56EbSpHnOX3938trwfyDO1n7WGVYJPMD/afwfhN5AqvbcEUVMHBQFf4lGM wRTu2g== Received: from mail-dy1-f199.google.com (mail-dy1-f199.google.com [74.125.82.199]) by mx0a-0031df01.pphosted.com (PPS) with ESMTPS id 4eafrt8a7m-1 (version=TLSv1.3 cipher=TLS_AES_128_GCM_SHA256 bits=128 verify=NOT) for ; Fri, 22 May 2026 05:56:26 +0000 (GMT) Received: by mail-dy1-f199.google.com with SMTP id 5a478bee46e88-2f2d983d109so1439072eec.0 for ; Thu, 21 May 2026 22:56:26 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=oss.qualcomm.com; s=google; t=1779429385; x=1780034185; darn=vger.kernel.org; h=content-transfer-encoding:in-reply-to:from:content-language :references:cc:to:subject:user-agent:mime-version:date:message-id :from:to:cc:subject:date:message-id:reply-to; bh=LLUYimo4jYypFis8+6QYWL4/jJ4CGaTBz0co1X0lX4A=; b=VJBfYsMX6s3URSEyva++TbNL5BXjw9uJNwEJybpJNTwXKySpy1J+9tWmQtTXOCm43I MS/2R1fYm4bKU6i7KVIn4nVPlyze0mmdvYQKLcxvQyXaZwTV9VhPdToCgut0HF4ozH9P z41hFQaG3N/3D4bccKxr31nELwycyWLlRoYU5xpTBxYUS+zaKGVM+fld8wJtGl66MDvO pL8D2qvf87ZAn6OB/Y6+dP1lkJrDItODEkbOIgL5BVLtE37ho37djNazvPhbCkx9rxOM t+x92MQGICDu/Jv4ZlVel7CcBF0i30F40kg029AblbPjIP5q290c+OkJSbizRUvXko8R AqwA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1779429385; x=1780034185; h=content-transfer-encoding:in-reply-to:from:content-language :references:cc:to:subject:user-agent:mime-version:date:message-id :x-gm-gg:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=LLUYimo4jYypFis8+6QYWL4/jJ4CGaTBz0co1X0lX4A=; b=G3VOJsqT4wRTEptOk2kC7beDOB/FFpj2NyJWrCMvSq0hPuCIEpEJZidSPrtubZqdax ldrHtUyCTZjSpT5dTqNs4fBM6vabE9hxaw4HNV38DzRW51dUxJcT0cyzIR5NN1BaaX5t WczmjdaBH6BTj21q8eeUlwSlFFiRqbPh0LsPlpttAS4cEowuSZsY9Kqfvt7HOyq4W8Dn LLspTnr3TxAGmfBLVgI1ribJx1A7noE1zmuRJuQg/KEPDsdbgXALTcdpRTGlS/so9Dwg 4y9iMkVYSAr6oS1BWC8W2XwJUKr/Hp6TH/vfgWY+IraSymH6PLjiq+e739fxaxg4MgRC avEA== X-Forwarded-Encrypted: i=1; AFNElJ8wO2A8+OjIuxX/IC+pLXmi+qMXJQS8yQ0kdwqoL02NwPv22rx9GBltSiS++WAZ3hFVG/Jqyuy6X3/hvME=@vger.kernel.org X-Gm-Message-State: AOJu0YwVpMUbC4CaujMFPLoNkPm3cFwC3SBVlR1bkDi6ojR4uoRc7jI6 e9LUDOwSFsqz7Raxb+gfETuKZeQVO9ChIj5S8p6PSVNdwGKWD//EL6BRUkJGguE3IVYfO54PuCV szW5FdCm+1I/t9WnyIGwIjSv1k+Y9ZxMixI+QrXr242VFHhF5PYeg84KefRfLhFWMQz4= X-Gm-Gg: Acq92OHf0u3swce3VubeKcI4BHEhxA86WXuwKd+IV4U/mDpfxC2fmIGoBOWSyU9SWk4 DIxUdRawwQNu5joA9B5hfZ1mSCurtQjdRzB9L002QSpFpjnCndqvrD71JZZ+RepyIo7ptWZqVkO 4TGe5EbmEK0uEGcnhELdlgplFkmL8vGxpVTyhqcxO0PrO4tUL5738r+zXEFIRrDK+pPmg/I5qqL sBhLm6kLp8zSOqyjhxlZOMWxMCsFFbNDuAgFiUecd3MTaMmknL94UpHlvMDeSEK8XWWPqF4CpDc YFKzjLdmoZAye1fB7qbHy8jK0WhxnXDTkVy6UUFd0G/TmG5q8NgUu+1GmclILDdo7FuuVbqm+7W E3AQhj/ahzlmrJWEvZFW9/i8V9pDryuPRHgTEC9et9gocAdB46FZpuAPsx4wc3Vh8kleOwdVTWv gFMbSY X-Received: by 2002:a05:7300:434a:b0:2c0:c5e4:605f with SMTP id 5a478bee46e88-30449186bb7mr1185096eec.24.1779429385391; Thu, 21 May 2026 22:56:25 -0700 (PDT) X-Received: by 2002:a05:7300:434a:b0:2c0:c5e4:605f with SMTP id 5a478bee46e88-30449186bb7mr1185073eec.24.1779429384859; Thu, 21 May 2026 22:56:24 -0700 (PDT) Received: from [10.110.121.192] (i-global254.qualcomm.com. [199.106.103.254]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-304522314a4sm243736eec.18.2026.05.21.22.56.22 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Thu, 21 May 2026 22:56:24 -0700 (PDT) Message-ID: <16f929d6-2494-4ca2-b36a-880dce8bb019@oss.qualcomm.com> Date: Fri, 22 May 2026 13:56:20 +0800 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: Re: [PATCH v2 1/1] dm-inlinecrypt: add support for hardware-wrapped keys To: Mikulas Patocka Cc: Milan Broz , Eric Biggers , Alasdair Kergon , Mike Snitzer , Benjamin Marzinski , Neeraj Soni , dm-devel@lists.linux.dev, linux-kernel@vger.kernel.org References: <20260516115045.3958326-1-linlin.zhang@oss.qualcomm.com> <20260516115045.3958326-2-linlin.zhang@oss.qualcomm.com> <3b57685a-09b4-473a-8810-bbb46769ab42@gmail.com> <2712f864-0f68-4428-9ba5-55fbf35de6e8@oss.qualcomm.com> Content-Language: en-US From: Linlin Zhang In-Reply-To: Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit X-Authority-Analysis: v=2.4 cv=JN0LdcKb c=1 sm=1 tr=0 ts=6a0ff00a cx=c_pps a=cFYjgdjTJScbgFmBucgdfQ==:117 a=JYp8KDb2vCoCEuGobkYCKw==:17 a=IkcTkHD0fZMA:10 a=NGcC8JguVDcA:10 a=s4-Qcg_JpJYA:10 a=VkNPw1HP01LnGYTKEx00:22 a=u7WPNUs3qKkmUXheDGA7:22 a=_K5XuSEh1TEqbUxoQ0s3:22 a=VwQbUJbxAAAA:8 a=p0WdMEafAAAA:8 a=EUspDBNiAAAA:8 a=4AoxfBD4PrQTERy5mSIA:9 a=3ZKOabzyN94A:10 a=QEXdDO2ut3YA:10 a=scEy_gLbYbu1JhEsrz4S:22 X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwNTIyMDA1NiBTYWx0ZWRfX0KQ/pWk0oJmi qOelE2WEYamA5OKbqtsIBoPI0lZREoBBgY0DVXImEIVh+7nefzNKFYNN1dDLjVboBJlgujDW28g QMed7ivOY89bUZLWUP4LP704hkAgnmZfs9rC5wvYk8C+be5NYT+oMJgCi9oFXBdTyHLdeOPCpKl rSkZ2jjZzZtYyMgroAXvlO1sTqUu2yb4+VoHNK56ztr4GmtBUEJoNsrwnC/X4LYrK8nVkjb/DnB yoH1pT9azp915BEU0hA808QUzh2s5v5idlGlWHJzzvkIdt5jCQ54rCViNJXqGa9yu/Otm0r/mVE HiOBQoTlDSyP91ju/iWl22UBud+LvT+9hNa/QNC2i3KooLJSRcigLKCEesQ5Ov4b8EjmRCiDUD0 wZwffmvcfrRHXZlc0i3w3gRDZuRH7ymPhJ/ZTPImGi9bhd9bg7XPK+45hn+qgIske3hNh7ddjx1 r/kBv7AE/jeRvRvcOWg== X-Proofpoint-GUID: xw6TF48Z1JB-dlmR4o4qkoiTEXgI1kEu X-Proofpoint-ORIG-GUID: xw6TF48Z1JB-dlmR4o4qkoiTEXgI1kEu X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1143,Hydra:6.1.51,FMLib:17.12.100.49 definitions=2026-05-22_01,2026-05-18_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 adultscore=0 lowpriorityscore=0 suspectscore=0 malwarescore=0 impostorscore=0 phishscore=0 bulkscore=0 clxscore=1015 spamscore=0 priorityscore=1501 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2605130000 definitions=main-2605220056 On 5/18/2026 8:37 PM, Mikulas Patocka wrote: > > > On Mon, 18 May 2026, Linlin Zhang wrote: > >> >> >> On 5/16/2026 8:17 PM, Milan Broz wrote: >>> On 5/16/26 1:50 PM, Linlin Zhang wrote: >>>> Add support for hardware-wrapped encryption keys to the >>>> dm-inlinecrypt target. >>>> >>>> Introduce a new parameter to indicate whether >>>> the provided key is a raw key or a hardware-wrapped key. Based >>>> on this flag, the appropriate blk-crypto key type is selected >>>> when initializing the key. >>>> >>>> This allows dm-inlinecrypt to work with hardware that requires >>>> keys to be wrapped and managed by the underlying inline >>>> encryption engine. >>>> >>>> Update the target argument parsing accordingly and pass the >>>> key type to blk_crypto_init_key(). Documentation is also >>>> updated to reflect the new parameter and usage. >>>> >>>> Signed-off-by: Linlin Zhang >>>> --- >>>>   .../device-mapper/dm-inlinecrypt.rst          | 10 ++- >>>>   drivers/md/dm-inlinecrypt.c                   | 71 +++++++++++-------- >>>>   2 files changed, 50 insertions(+), 31 deletions(-) >>>> >>>> diff --git a/Documentation/admin-guide/device-mapper/dm-inlinecrypt.rst b/Documentation/admin-guide/device-mapper/dm-inlinecrypt.rst >>>> index c71e600efb76..3a4ce2c5f228 100644 >>>> --- a/Documentation/admin-guide/device-mapper/dm-inlinecrypt.rst >>>> +++ b/Documentation/admin-guide/device-mapper/dm-inlinecrypt.rst >>>> @@ -10,7 +10,7 @@ https://docs.kernel.org/block/inline-encryption.html >>>>     Parameters:: >>>>   -          \ >>>> +          \ >>>>             [<#opt_params> ] >>> >>> Please use optional parameter. >>> Adding mandatory field will introduce unnecessary incompatibility with dm-crypt mappings. >>> (The idea was that you can simply switch "crypt" to "inlinecrypt" for raw keys.) >>> >>> I would probably just add "hw-wrapped" or "keytype=raw|hw-wrapped" optional argument >>> (with raw as default, so no need so specify it). >>> >>> IOW the mapping will look like this (1 is number of optional parameters): >>> >>>    1 hw-wrapped >>> or >>>    1 keytype=hw-wrapped >> >> >> Thanks for your suggestion! >> >> I agree that keeping "hw-wrapped" or "keytype=raw|hw-wrapped" as an optional >> argument helps preserve compatibility when switching from "crypt" to >> "inlinecrypt" >> >> My concern is that, in practice, this optional argument may effectively become >> mandatory for certain configurations. For instance, "hw-wrapped" or >> "keytype=raw|hw-wrapped" must be set for a wrapped key. This slightly blurs the >> original intent of "optional arguments", which are typically expected to be >> truly optional for correct operation. >> >> Would this be acceptable? which one is more acceptable for upstream? >> incompatibility semantics mappings b/w dm-crypt and dm-inlinecrypt or blur >> the original intent of "optional arguments"? >> >> Any additional thoughts or feedback from others would be much appreciated. Thanks! > > Hi > > I would prefer an optional argument "keytype:raw" or "keytype:hw-wrapped". > Device mapper targets use colon to separate arguments from values, so I > would use it here too. Thanks for the comment! ACK. I'll send a new patch with such modification. > > I removed the patch that always sets BLK_CRYPTO_KEY_TYPE_HW_WRAPPED from > the linux-dm repository and I will accept a patch that introduces > "keytype:hw-wrapped" when you send it. > > Mikulas > >>> >>> The second option will allow to add new key type much easier. >> >> Regarding the second option ("keytype=..."), I agree it is more extensible. >> Could you please clarify what other key types you envision supporting in the >> future? >> >>> >>> Please check how other targets implement it, some dm-crypt examples >>> https://gitlab.com/cryptsetup/cryptsetup/-/wikis/DMCrypt >>> >>> Thanks, >>> Milan >>> >>