From: Srish Srinivasan <ssrish@linux.ibm.com>
To: linux-integrity@vger.kernel.org, keyrings@vger.kernel.org,
linuxppc-dev@lists.ozlabs.org
Cc: maddy@linux.ibm.com, mpe@ellerman.id.au, npiggin@gmail.com,
christophe.leroy@csgroup.eu,
James.Bottomley@HansenPartnership.com, jarkko@kernel.org,
zohar@linux.ibm.com, linux-kernel@vger.kernel.org,
linux-security-module@vger.kernel.org, nayna@linux.ibm.com,
rnsastry@linux.ibm.com, ssrish@linux.ibm.com
Subject: [PATCH 0/8] Extend PKWM to support user-created wrapping keys
Date: Thu, 27 Aug 2026 11:53:00 +0530 [thread overview]
Message-ID: <20260827062309.724808-1-ssrish@linux.ibm.com> (raw)
The PKWM trusted source currently uses a single default wrapping key per
LPAR. This key is created during trusted source initialization, and all
trusted keys backed by PKWM are sealed and unsealed using it.
Recent versions of PKWM allow users to create and manage their own wrapping
keys through a set of lifecycle operations. This patch series brings these
PKWM capabilities into the kernel, allowing users to create, manage, and
select wrapping keys for sealing and unsealing their trusted keys, rather
than requiring all trusted keys to use the default wrapping key.
In addition to implementing user-created wrapping key support, this series
includes five prerequisite cleanup patches for the PLPKS and PKWM code.
These patches improve error handling and type consistency, rename a macro
for clarity, prevent unsupported capabilities from being exposed through
the sysfs, and make minor documentation and MAINTAINERS updates.
Srish Srinivasan (8):
pseries/plpks: update PKS documentation and maintainer entry
pseries/plpks: fix error handling in plpks_read_var()
pseries/plpks: improve type consistency and parameter validation
pseries/plpks: rename the default wrapping key macro
pseries/plpks: hide wrapping_features when unsupported
pseries/plpks: add HCALLs for PKWM wrapping key life cycle management
keys/trusted_keys: enable PKWM wrapping key selection by label
pseries/plpks/wrapkey: expose PKWM wrapping key management to
userspace via sysfs
.../ABI/testing/sysfs-firmware-plpks | 106 ++++
Documentation/arch/powerpc/papr_hcalls.rst | 49 +-
.../security/keys/trusted-encrypted.rst | 4 +-
MAINTAINERS | 2 +-
arch/powerpc/include/asm/hvcall.h | 5 +-
arch/powerpc/include/asm/plpks.h | 40 +-
arch/powerpc/platforms/pseries/Kconfig | 13 +
arch/powerpc/platforms/pseries/Makefile | 1 +
arch/powerpc/platforms/pseries/plpks-sysfs.c | 31 +-
.../platforms/pseries/plpks-wrapkey-sysfs.c | 407 +++++++++++++
arch/powerpc/platforms/pseries/plpks.c | 557 ++++++++++++++++--
include/keys/trusted_pkwm.h | 3 +
security/keys/trusted-keys/trusted_pkwm.c | 40 +-
13 files changed, 1188 insertions(+), 70 deletions(-)
create mode 100644 arch/powerpc/platforms/pseries/plpks-wrapkey-sysfs.c
--
2.52.0
next reply other threads:[~2026-08-27 6:23 UTC|newest]
Thread overview: 9+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-27 6:23 Srish Srinivasan [this message]
2026-08-27 6:23 ` [PATCH 1/8] pseries/plpks: update PKS documentation and maintainer entry Srish Srinivasan
2026-08-27 6:23 ` [PATCH 2/8] pseries/plpks: fix error handling in plpks_read_var() Srish Srinivasan
2026-08-27 6:23 ` [PATCH 3/8] pseries/plpks: improve type consistency and parameter validation Srish Srinivasan
2026-08-27 6:23 ` [PATCH 4/8] pseries/plpks: rename the default wrapping key macro Srish Srinivasan
2026-08-27 6:23 ` [PATCH 5/8] pseries/plpks: hide wrapping_features when unsupported Srish Srinivasan
2026-08-27 6:23 ` [PATCH 6/8] pseries/plpks: add HCALLs for PKWM wrapping key life cycle management Srish Srinivasan
2026-08-27 6:23 ` [PATCH 7/8] keys/trusted_keys: enable PKWM wrapping key selection by label Srish Srinivasan
2026-08-27 6:23 ` [PATCH 8/8] pseries/plpks/wrapkey: expose PKWM wrapping key management to userspace via sysfs Srish Srinivasan
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260827062309.724808-1-ssrish@linux.ibm.com \
--to=ssrish@linux.ibm.com \
--cc=James.Bottomley@HansenPartnership.com \
--cc=christophe.leroy@csgroup.eu \
--cc=jarkko@kernel.org \
--cc=keyrings@vger.kernel.org \
--cc=linux-integrity@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-security-module@vger.kernel.org \
--cc=linuxppc-dev@lists.ozlabs.org \
--cc=maddy@linux.ibm.com \
--cc=mpe@ellerman.id.au \
--cc=nayna@linux.ibm.com \
--cc=npiggin@gmail.com \
--cc=rnsastry@linux.ibm.com \
--cc=zohar@linux.ibm.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®