From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp-out2.suse.de (smtp-out2.suse.de [195.135.223.131]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 17225266568 for ; Tue, 2 Dec 2025 15:30:38 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=195.135.223.131 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1764689441; cv=none; b=reUorqEfehnxIuYtvD+X/EFWRrEb+HpeLr+g0a2wuzypg0dbR6n1xroZNkRH6d2LXnvf+XT1dA2BJ2hJ9ieNoTUrwZO24F4gftltKIEQdZJwAkR7zFsrKygzN0Fv1FwFrkYAP7c9WHQyyJ41IdZ421yo7xG5muZcP7iZw+Ou/mQ= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1764689441; c=relaxed/simple; bh=BI2W/7n0jk1tWeEmF60gc9M30OJn0LNfgAkcyfqzOeQ=; h=Message-ID:Date:MIME-Version:Subject:To:Cc:References:From: In-Reply-To:Content-Type; b=f4Nu38aRTUAx+aUWC1qhSmb+pnF5mF/A7B6iRdRI4roai3gT6b8oqHzD35aJWrpjWhZXefZ3R6KUyr3FuUEKLa4PkgNHEaGveff+hSDPRjhOdGVc12/FBcY1KUWsOxPiMPygXc0VXGEnozckinfxTjcFPmd0OlDWu65RPYI3FMs= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=suse.de; spf=pass smtp.mailfrom=suse.de; dkim=pass (1024-bit key) header.d=suse.de header.i=@suse.de header.b=tQeX+UhJ; dkim=permerror (0-bit key) header.d=suse.de header.i=@suse.de header.b=esgK5jMt; dkim=pass (1024-bit key) header.d=suse.de header.i=@suse.de header.b=hPmLkwIn; dkim=permerror (0-bit key) header.d=suse.de header.i=@suse.de header.b=dGJPRmBB; arc=none smtp.client-ip=195.135.223.131 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=suse.de Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=suse.de Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=suse.de header.i=@suse.de header.b="tQeX+UhJ"; dkim=permerror (0-bit key) header.d=suse.de header.i=@suse.de header.b="esgK5jMt"; dkim=pass (1024-bit key) header.d=suse.de header.i=@suse.de header.b="hPmLkwIn"; dkim=permerror (0-bit key) header.d=suse.de header.i=@suse.de header.b="dGJPRmBB" Received: from imap1.dmz-prg2.suse.org (unknown [10.150.64.97]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by smtp-out2.suse.de (Postfix) with ESMTPS id DE7C25BCCB; Tue, 2 Dec 2025 15:30:34 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=suse.de; s=susede2_rsa; t=1764689437; h=from:from:reply-to:date:date:message-id:message-id:to:to:cc:cc: mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=h6kQNbPeKf4oy5KKXviez7TCTV6nNtW3S9FWe5RYWv0=; b=tQeX+UhJmvqREkSx0DCWXLQX+wysKl+Kf51g+lFn2N7Bx2eYNiesuo3hW8resS6LsIF0o4 vbnd8T2RE4RTNhowB5laTglyG5OUFE5BFS2TsqvmuctVq745BpnO8qZznIulm21bhsiqUB N2rhlUlyepkoBtoeh7Jciw7PdSCs9DY= DKIM-Signature: v=1; a=ed25519-sha256; c=relaxed/relaxed; d=suse.de; s=susede2_ed25519; t=1764689437; h=from:from:reply-to:date:date:message-id:message-id:to:to:cc:cc: mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=h6kQNbPeKf4oy5KKXviez7TCTV6nNtW3S9FWe5RYWv0=; b=esgK5jMtmfwzt0xfB4agcZcUEOJtaaOdfoV4QNRYxnyr/sL+C3B+soXpPgESRoVt4B05vY x7g6dEN5yj9M+1Bg== Authentication-Results: smtp-out2.suse.de; none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=suse.de; s=susede2_rsa; t=1764689434; h=from:from:reply-to:date:date:message-id:message-id:to:to:cc:cc: mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=h6kQNbPeKf4oy5KKXviez7TCTV6nNtW3S9FWe5RYWv0=; b=hPmLkwIn+fNuETiEUjbdC/BOMxZCVMCHbh3G+7Cu57lDAyspdcUmjckI6gEL02EgUayWEg njJC2mqmh6OE2Sjyr5l8T7wyuomPFpuBNhZN2u9mjKfAO4E69kZ0MfGXSlZd40xOjB/LSH xVcW3njqINsRtcZIOoydkElvu1xXswk= DKIM-Signature: v=1; a=ed25519-sha256; c=relaxed/relaxed; d=suse.de; s=susede2_ed25519; t=1764689434; h=from:from:reply-to:date:date:message-id:message-id:to:to:cc:cc: mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=h6kQNbPeKf4oy5KKXviez7TCTV6nNtW3S9FWe5RYWv0=; b=dGJPRmBBoGCT3VIjC3UNM8nC9ay7sLELZb67tg7EkigyC2O/ZZyfU+1yTPc4gEP8Q7uwWM UGrs9eOItWKcQkCw== Received: from imap1.dmz-prg2.suse.org (localhost [127.0.0.1]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by imap1.dmz-prg2.suse.org (Postfix) with ESMTPS id 5D5E13EA63; Tue, 2 Dec 2025 15:30:34 +0000 (UTC) Received: from dovecot-director2.suse.de ([2a07:de40:b281:106:10:150:64:167]) by imap1.dmz-prg2.suse.org with ESMTPSA id 9NiYFRoGL2nKLwAAD6G6ig (envelope-from ); Tue, 02 Dec 2025 15:30:34 +0000 Message-ID: <6ee5d2e8-71c3-4aae-be63-759c8e56a742@suse.de> Date: Tue, 2 Dec 2025 16:30:33 +0100 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: Re: [PATCH v4 4/4] nvme: Allow reauth from sysfs To: alistair23@gmail.com, kbusch@kernel.org, axboe@kernel.dk, hch@lst.de, sagi@grimberg.me, kch@nvidia.com, linux-nvme@lists.infradead.org Cc: linux-kernel@vger.kernel.org, Alistair Francis References: <20251202051755.1312158-1-alistair.francis@wdc.com> <20251202051755.1312158-5-alistair.francis@wdc.com> Content-Language: en-US From: Hannes Reinecke In-Reply-To: <20251202051755.1312158-5-alistair.francis@wdc.com> Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 8bit X-Spam-Flag: NO X-Spam-Score: -4.29 X-Spam-Level: X-Spamd-Result: default: False [-4.29 / 50.00]; BAYES_HAM(-3.00)[100.00%]; NEURAL_HAM_LONG(-1.00)[-1.000]; NEURAL_HAM_SHORT(-0.19)[-0.965]; MIME_GOOD(-0.10)[text/plain]; RCVD_VIA_SMTP_AUTH(0.00)[]; FREEMAIL_TO(0.00)[gmail.com,kernel.org,kernel.dk,lst.de,grimberg.me,nvidia.com,lists.infradead.org]; ARC_NA(0.00)[]; MIME_TRACE(0.00)[0:+]; RCPT_COUNT_SEVEN(0.00)[9]; FUZZY_RATELIMITED(0.00)[rspamd.com]; MID_RHS_MATCH_FROM(0.00)[]; FREEMAIL_ENVRCPT(0.00)[gmail.com]; DKIM_SIGNED(0.00)[suse.de:s=susede2_rsa,suse.de:s=susede2_ed25519]; FROM_EQ_ENVFROM(0.00)[]; FROM_HAS_DN(0.00)[]; TO_DN_SOME(0.00)[]; RCVD_TLS_ALL(0.00)[]; TO_MATCH_ENVRCPT_ALL(0.00)[]; RCVD_COUNT_TWO(0.00)[2]; DBL_BLOCKED_OPENRESOLVER(0.00)[suse.de:email,suse.de:mid,infradead.org:email,wdc.com:email,imap1.dmz-prg2.suse.org:helo] On 12/2/25 06:17, alistair23@gmail.com wrote: > From: Alistair Francis > > Allow userspace to trigger a reauth (REPLACETLSPSK) from sysfs. > This can be done by writing a zero to the sysfs file. > > echo 0 > /sys/devices/virtual/nvme-fabrics/ctl/nvme0/tls_configured_key > > In order to use the new keys for the admin queue we call controller > reset. This isn't ideal, but I can't find a simpler way to reset the > admin queue TLS connection. > > Signed-off-by: Alistair Francis > --- > v4: > - Forcefully reset the connection > v3: > - Only trigger if a 0 is written to `tls_configured_key` > - Add documentation > v2: > - Trigger on any value written to `tls_configured_key` > > Documentation/ABI/testing/sysfs-nvme | 13 ++++++++ > drivers/nvme/host/sysfs.c | 44 +++++++++++++++++++++++++++- > 2 files changed, 56 insertions(+), 1 deletion(-) > create mode 100644 Documentation/ABI/testing/sysfs-nvme > > diff --git a/Documentation/ABI/testing/sysfs-nvme b/Documentation/ABI/testing/sysfs-nvme > new file mode 100644 > index 000000000000..16aaf0dca9e2 > --- /dev/null > +++ b/Documentation/ABI/testing/sysfs-nvme > @@ -0,0 +1,13 @@ > +What: /sys/devices/virtual/nvme-fabrics/ctl/.../tls_configured_key > +Date: November 2025 > +KernelVersion: 6.19 > +Contact: Linux NVMe mailing list > +Description: > + The file is avaliable when using a secure concatanation > + connection to a NVMe taget. Reading the file will return > + the serial of the currently negotiated key. > + > + Writing 0 to the file will trigger a PSK reauthentication > + (REPLACETLSPSK) with the target. After a reauthentication > + the value returned by tls_configured_key will be the new > + serial. > diff --git a/drivers/nvme/host/sysfs.c b/drivers/nvme/host/sysfs.c > index 6d10e12136d0..caf853a0da33 100644 > --- a/drivers/nvme/host/sysfs.c > +++ b/drivers/nvme/host/sysfs.c > @@ -806,7 +806,49 @@ static ssize_t tls_configured_key_show(struct device *dev, > > return sysfs_emit(buf, "%08x\n", key_serial(key)); > } > -static DEVICE_ATTR_RO(tls_configured_key); > + > +static ssize_t tls_configured_key_store(struct device *dev, > + struct device_attribute *attr, > + const char *buf, size_t count) > +{ > + struct nvme_ctrl *ctrl = dev_get_drvdata(dev); > + int error, qid; > + > + error = kstrtoint(buf, 10, &qid); > + if (error) > + return error; > + > + /* > + * We currently only allow userspace to write a `0` indicating > + * generate a new key. 'indicating generate a new key' is a bit awkward; maybe 'indicating that a new key should be generated'? Otherwise looks good. Reviewed-by: Hannes Reinecke Cheers, Hannes -- Dr. Hannes Reinecke Kernel Storage Architect hare@suse.de +49 911 74053 688 SUSE Software Solutions GmbH, Frankenstr. 146, 90461 Nürnberg HRB 36809 (AG Nürnberg), GF: I. Totev, A. McDonald, W. Knoblich