From: Dave Hansen <dave.hansen@intel.com>
To: Andy Lutomirski <luto@amacapital.net>
Cc: Borislav Petkov <bp@alien8.de>,
Daniel Gutson <daniel@eclypsium.com>,
"Kirill A. Shutemov" <kirill.shutemov@linux.intel.com>,
Thomas Gleixner <tglx@linutronix.de>,
Ingo Molnar <mingo@redhat.com>, X86 ML <x86@kernel.org>,
"H. Peter Anvin" <hpa@zytor.com>, Arnd Bergmann <arnd@arndb.de>,
Greg Kroah-Hartman <gregkh@linuxfoundation.org>,
Peter Zijlstra <peterz@infradead.org>,
"David S. Miller" <davem@davemloft.net>,
Rob Herring <robh@kernel.org>, Tony Luck <tony.luck@intel.com>,
Rahul Tanwar <rahul.tanwar@linux.intel.com>,
Xiaoyao Li <xiaoyao.li@intel.com>,
Sean Christopherson <sean.j.christopherson@intel.com>,
Dave Hansen <dave.hansen@linux.intel.com>,
LKML <linux-kernel@vger.kernel.org>,
Richard Hughes <hughsient@gmail.com>
Subject: Re: [PATCH] Ability to read the MKTME status from userspace (patch v2)
Date: Thu, 25 Jun 2020 14:43:42 -0700 [thread overview]
Message-ID: <b3ea365a-816c-b712-29c6-9f49df1bd41f@intel.com> (raw)
In-Reply-To: <CALCETrWLqdmFpGn8r7phKnZOondNRLhKHfe0bmEO=uX1S+xVcQ@mail.gmail.com>
On 6/25/20 2:39 PM, Andy Lutomirski wrote:
> What about MKTME platforms that (using hypothetical future kernel
> support) have encryption enabled for a node but have disabled it for
> specific pages using madvise()? Or that have any other nontrivial
> policy like that?
I think it's fine if the magic new bit means "normal allocations get
hardware encryption". If we have a way for users to opt out of that,
that's fine with me because the default is to provide it and a user must
have gone through _some_ hoop to undo the protection.
BTW, although the MKTME hardware and architecture support disabling
encryption, we don't have any plans to expose that to applications.
next prev parent reply other threads:[~2020-06-25 21:43 UTC|newest]
Thread overview: 8+ messages / expand[flat|nested] mbox.gz Atom feed top
2020-06-25 21:10 Daniel Gutson
2020-06-25 21:14 ` Borislav Petkov
[not found] ` <CAFmMkTGy5vOiPUpWw6HfQv-JM90JqLBcsKwMpbWdsjaLBw730Q@mail.gmail.com>
2020-06-25 21:27 ` Borislav Petkov
2020-06-25 21:37 ` Dave Hansen
2020-06-25 21:39 ` Andy Lutomirski
2020-06-25 21:43 ` Dave Hansen [this message]
2020-06-25 21:29 ` Dave Hansen
2020-06-26 1:55 ` Alison Schofield
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=b3ea365a-816c-b712-29c6-9f49df1bd41f@intel.com \
--to=dave.hansen@intel.com \
--cc=arnd@arndb.de \
--cc=bp@alien8.de \
--cc=daniel@eclypsium.com \
--cc=dave.hansen@linux.intel.com \
--cc=davem@davemloft.net \
--cc=gregkh@linuxfoundation.org \
--cc=hpa@zytor.com \
--cc=hughsient@gmail.com \
--cc=kirill.shutemov@linux.intel.com \
--cc=linux-kernel@vger.kernel.org \
--cc=luto@amacapital.net \
--cc=mingo@redhat.com \
--cc=peterz@infradead.org \
--cc=rahul.tanwar@linux.intel.com \
--cc=robh@kernel.org \
--cc=sean.j.christopherson@intel.com \
--cc=tglx@linutronix.de \
--cc=tony.luck@intel.com \
--cc=x86@kernel.org \
--cc=xiaoyao.li@intel.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®