From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-qk1-f169.google.com (mail-qk1-f169.google.com [209.85.222.169]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id BA1C33AE1A3 for ; Thu, 11 Jun 2026 11:49:57 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.222.169 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1781178599; cv=none; b=nqNrR8WklA3iGw7Hsof3PV7nbtWguc2b2OMoEqzApj388GazH8lvxzYfzqHA3iuXs+681ag8YpHAnLqR51A5ZH9erAINJX+J7jT4fj6hYQMCurUyPEA09U6UQWo/rFgIh8ok/PUZtSbTHvz0C4dYEA1lFh72nWH4whT2dUDFJZk= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1781178599; c=relaxed/simple; bh=lecRcnS3vUJjK0l9Kw8UQNPdJUmzKu/EO7NFXV7ojG8=; h=Date:From:To:Cc:Subject:Message-ID:References:MIME-Version: Content-Type:Content-Disposition:In-Reply-To; b=ZnXZjrxS0h4rvv7JzwWCpF3oPLHcyrXSbUKRGSNtHkNW6TP06WVtP2S7Fs8m8bBwTUP70QBadSqmefOL5vXSY4kRoFNZfOn3JF9II2+Vqm3Yh0bTiKxgSlYloA5C7mILEVhyU5DOfaNy9SKMZU0PJPWjLdmDMu3/DMNyfGR1IbE= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=ziepe.ca; spf=pass smtp.mailfrom=ziepe.ca; dkim=pass (2048-bit key) header.d=ziepe.ca header.i=@ziepe.ca header.b=HEQojTk0; arc=none smtp.client-ip=209.85.222.169 Authentication-Results: smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=ziepe.ca Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=ziepe.ca Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=ziepe.ca header.i=@ziepe.ca header.b="HEQojTk0" Received: by mail-qk1-f169.google.com with SMTP id af79cd13be357-91588056619so556757885a.2 for ; Thu, 11 Jun 2026 04:49:57 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ziepe.ca; s=google; t=1781178597; x=1781783397; darn=vger.kernel.org; h=in-reply-to:content-disposition:mime-version:references:message-id :subject:cc:to:from:date:from:to:cc:subject:date:message-id:reply-to; bh=dNgsH2tvtJn5m59hVAt9rmEgOo4VHkNi7fOm5lsoIhI=; b=HEQojTk0l2+0GoeOEKWvXU2pAEQbqfqj5+ETWftSgYPJDYGZhQTZXKHcjdLjmEf/R+ qnlE3V+8i7F0+9NljEo/Zs9H4SFjV7BcjJ5uuOJvY5LUKQWEHWQunX7Atpduwd9Ov2pe wAMa/oAAubhSxo1F/Fl5t+qphh95fhbalIx0CQSeZFozqpwXXnc7sYh19NCb9122Ivdd Qmabm3H39uXP5S++D0o9WtwRTrkZhQ8d2bPSXfb0qss8gMW2jTRGhMaP5ti0c7xeITtq ehDA1NUXIAP0kxTSAgzMB1I2+1cROoy4plkhZ6JZ+ZLPdlwPVil1M828zEm4wKRs1evU 05lQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1781178597; x=1781783397; h=in-reply-to:content-disposition:mime-version:references:message-id :subject:cc:to:from:date:x-gm-gg:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to; bh=dNgsH2tvtJn5m59hVAt9rmEgOo4VHkNi7fOm5lsoIhI=; b=WSwboFSB5xVOow0gI21KV8n0fBaYY/z6kC0+XWQwuDJnDwKUpqQpVQeNogr+BYa5GY 27hNtI+AAGlIeUNXdmz5oP7bYKIhHRkYNQsf6H9muXxNa+9xOMXS5NPRrAXcwn9PTWca lAuRzE151V/r14b9httwhV/Z28HC0C+zDMBYCSbWKlIstsa4nB2jJt2Y6zaNdg/V/Lyz kksMBld2hVuKhNbNyLmXKLOo+1NROBfgsvXPUVR4COsH2sfikJ7UKnf3Lks0VL5nt4l/ 4TgYIq+SWGNa4umOPSBJDWvjwPgyxUPASS2puLnmOrtTagIz/pFUPXmK+qOD/kVJ+XvM NETg== X-Forwarded-Encrypted: i=1; AFNElJ9ZrLqQhPMFpzNn+XENJak3nMbAzmW9q37MsH+HPLRRmfXeeKMeQJS3F4RqSnhguEppCYEZYhZ8HeIENxQ=@vger.kernel.org X-Gm-Message-State: AOJu0YwES4bM58Iu4qbs+6LNicOQ5H3TaR7fa+LWfL4fTJ91nydVRzOj T4adkkXPqtq2FXLuoKVdTIFJ7K6thbzefj/ZhqlaQoJCiLuIX6oi/1V+vLN844TQiaByXfvmzph O1SlG X-Gm-Gg: Acq92OF/ZppaAneAr6zW3CjsIivmhmUbPRXZpXDc8GNOGwrOvv8XCSQxXQZ439hymAY /T2wT92BVz6ktJKDMSQQW0aplPyjyuQNRW46sXKdzKyK16bAsElArIF1TVpl6QiQ0MbOHBJRpXG FAm1BIGZlgAuJoF70x5mBNaFKI3Yrs1gFoTcBKxYG9rZQOvXUb91ooV+XfQywKJQEYg5Zr8GEOJ VzO7k/Tyd4q4Dbl5qaWZb6i1GDBTOVa0M/PvcdhyWgw7exLDkE24Ofqxg2q72eIzSE6gVbwqxkg mZhQbYYSixoI0AGawzCZxhRS3mMQmOIwCiLkHD7D2MbOqg01wjov79GIo2Q7TTojve0Jv/jahZU vVA0WvcNQvhY3uZA6n07t0tdJ4XnnQBOs+F4rHF1deOTjPzsAV3g7hQ3oHHKDG/8m2DNJ9/6OdB xD1ziaGe3y1mnk+gh9mIFIx/IM+xqPbzozQMnDiMdb0Fi/BvzHFg/SpaOsiQqGNnKeidKEfL1Wf 5zEHKLtyUHz6ZxR5tinMLTruXE= X-Received: by 2002:a05:620a:1a12:b0:915:87ad:d5b1 with SMTP id af79cd13be357-9160ab34661mr372192085a.15.1781178596642; Thu, 11 Jun 2026 04:49:56 -0700 (PDT) Received: from ziepe.ca (crbknf0213w-47-54-130-67.pppoe-dynamic.high-speed.nl.bellaliant.net. [47.54.130.67]) by smtp.gmail.com with ESMTPSA id af79cd13be357-9160acab48csm167602085a.16.2026.06.11.04.49.55 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 11 Jun 2026 04:49:55 -0700 (PDT) Received: from jgg by wakko with local (Exim 4.97) (envelope-from ) id 1wXdv0-00000005gTA-3lYL; Thu, 11 Jun 2026 08:49:54 -0300 Date: Thu, 11 Jun 2026 08:49:54 -0300 From: Jason Gunthorpe To: Catalin Marinas Cc: Kameron Carr , akpm@linux-foundation.org, urezki@gmail.com, linux-mm@kvack.org, linux-kernel@vger.kernel.org, rppt@kernel.org, mhklinux@outlook.com, linux-coco@lists.linux.dev, Suzuki K Poulose Subject: Re: [RFC PATCH] mm/vmalloc: add vmalloc_decrypted() and vzalloc_decrypted() Message-ID: <20260611114954.GC1066031@ziepe.ca> References: <20260521205834.1012925-1-kameroncarr@linux.microsoft.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: On Mon, Jun 08, 2026 at 04:37:02PM +0100, Catalin Marinas wrote: > > +/** > > + * vzalloc_decrypted - allocate zeroed virtually contiguous decrypted memory > > + * @size: allocation size > > + * > > + * Like vmalloc_decrypted(), but the memory is set to zero. > > + * > > + * Return: pointer to the allocated memory or %NULL on error > > + */ > > +void *vzalloc_decrypted_noprof(unsigned long size) > > +{ > > + void *addr; > > + > > + addr = __vmalloc_node_range_noprof(size, 1, VMALLOC_START, VMALLOC_END, > > + GFP_KERNEL, > > + pgprot_decrypted(PAGE_KERNEL), > > + VM_DECRYPTED, NUMA_NO_NODE, > > + __builtin_return_address(0)); > > + if (addr) > > + memset(addr, 0, size); > > Talking to Suzuki, the small window between set_memory_decrypted() and > memset() potentially exposing stale data is safe, at least for Arm CCA > as the memory would be scrubbed (there are other places in the kernel > where we do something similar). I assume that's also the case for other > architectures, although not sure what pKVM does. It seems like a poor practice though, this should probably be re-organized to use __GFP_ZERO so things are ordered sensibly. But what is the purpose of this? I guess some hyperv thing - but shouldn't we have a more structured way to "DMA map" things for the hypervisor instead of stuff like this? Why can't you use dma_alloc_coherent() which actually gives you an address that is sensible to pass to the hypervisor? Jason