From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mx0b-0031df01.pphosted.com (mx0b-0031df01.pphosted.com [205.220.180.131]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 8886735F170 for ; Wed, 25 Mar 2026 06:55:31 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=205.220.180.131 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1774421732; cv=none; b=WGCIj2fFyfFWRwBv7vBKGkDgBK4xxP+gcVLH5owYaYdGAKpJw+2xomPljtex1U49pAPDBnrO9f4KceW6HsKISlN9m55Avb6DWr6QYIlObYD7SgV+amz2lRALuy4yL7Y0lvc55cH5egMSDvbVcnfoqAV051rWm+qCnimFbMuwrG4= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1774421732; c=relaxed/simple; bh=A9Bw7A93QwyB/11G0f5DcWqXROOckyJZYM3CCOgkNCk=; h=Message-ID:Date:MIME-Version:Subject:To:Cc:References:From: In-Reply-To:Content-Type; b=lscKsUDsLTnEs5Z++Lph3St8151IJAyIoh/TqSwF+BiEW0I9iwSEzkf973nnoGu+XMbdAN5Qza2t6AH5cglwXReknrpNuXX63qKLcE+YlOgB7JuxO5806kOoZHP3Yk2Kew9Y75LL8OfhqhOIF56KOUojpmSjelWjeTmGFG0Z/yE= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=oss.qualcomm.com; spf=pass smtp.mailfrom=oss.qualcomm.com; dkim=pass (2048-bit key) header.d=qualcomm.com header.i=@qualcomm.com header.b=ci3z0clO; dkim=pass (2048-bit key) header.d=oss.qualcomm.com header.i=@oss.qualcomm.com header.b=dfJU92A/; arc=none smtp.client-ip=205.220.180.131 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=oss.qualcomm.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=oss.qualcomm.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=qualcomm.com header.i=@qualcomm.com header.b="ci3z0clO"; dkim=pass (2048-bit key) header.d=oss.qualcomm.com header.i=@oss.qualcomm.com header.b="dfJU92A/" Received: from pps.filterd (m0279869.ppops.net [127.0.0.1]) by mx0a-0031df01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 62P3oCid1208841 for ; Wed, 25 Mar 2026 06:55:30 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=qualcomm.com; h= cc:content-transfer-encoding:content-type:date:from:in-reply-to :message-id:mime-version:references:subject:to; s=qcppdkim1; bh= /OyRLeF1qiRXWOZLHBDozmhB2d8QM8xWWW+aAnLORUI=; b=ci3z0clOgC8UHxX9 ynM7JYqI7e71SxHgKyxjQsM0LgoUdR0M+Ch0zQDKMAN/w7HWOb+s3t7K6SRdnO/9 Gt5S8TbUkQV/fLKNN4x9g7398akOBzlnlH8E53kGYdUk/wvWvyDHwNahgeyX1Aim dWQ2z4Qg1ev8c6KzrmR5dzfg7fakeVamWqmYUVfcwlzrLrFDUJr08zEkk6lZsA6G IdmRJrDzUzaemRNRuuUrOW63i6jMxxPBoEUeb+qWOjBP5TzXuxFTWyi7ouC8oMkv 86VaGqZJtnj+lsNi2NSHlp6P0lBFSTrchdOYmEWjlvcHcrBVJM2qFzUuJaH8mMV7 NdhYUg== Received: from mail-dl1-f70.google.com (mail-dl1-f70.google.com [74.125.82.70]) by mx0a-0031df01.pphosted.com (PPS) with ESMTPS id 4d48598grq-1 (version=TLSv1.3 cipher=TLS_AES_128_GCM_SHA256 bits=128 verify=NOT) for ; Wed, 25 Mar 2026 06:55:30 +0000 (GMT) Received: by mail-dl1-f70.google.com with SMTP id a92af1059eb24-1275c6fc58aso4258997c88.0 for ; Tue, 24 Mar 2026 23:55:30 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=oss.qualcomm.com; s=google; t=1774421729; x=1775026529; darn=vger.kernel.org; h=content-transfer-encoding:in-reply-to:from:content-language :references:cc:to:subject:user-agent:mime-version:date:message-id :from:to:cc:subject:date:message-id:reply-to; bh=/OyRLeF1qiRXWOZLHBDozmhB2d8QM8xWWW+aAnLORUI=; b=dfJU92A/UmW4e38htyYsiBk+ID4O9R33gMuR7wPNNx9DWpJfeFbdVTJhl86/JYgPJG K8zSxxhFRpEwDj96nt7OrQatDSTSTHM5bj2i6ir/3OYj5wWbPzN+7Cy/x7IYTL0xeqWz ZUfPW3QNveiUjx/ILMcVKzhC6DebhTwpAIPgqlIEBw8+RBf2fz+7Sh6273wLrS0ruu0k Srj0gp6uhxrkXEAB5xyfwu/Fy6oJXdgKSKtk7pvBQTer+SyKPIkJTXuFyW/yML3REV1a qbAs58uIsjHn+6SLKPfYe3FyAFc4v8ZQiDye2dRy5mZhArOzWqE16WuDBMDsx6wsBhHQ Vqtg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1774421729; x=1775026529; h=content-transfer-encoding:in-reply-to:from:content-language :references:cc:to:subject:user-agent:mime-version:date:message-id :x-gm-gg:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=/OyRLeF1qiRXWOZLHBDozmhB2d8QM8xWWW+aAnLORUI=; b=NFT2fvBHw49MXID4+SO3rD0a7892irSFZ6SGUQ0xyKpD/zqbOzw71DFLC7mRZ4u4TB 9DuDGYuCKebKo/JtYQ56opT7MobBX7HE9tHDK0ZPnVTQmzlcbkY4AQi5eN2/wSDF+2q9 M3eO4yHb9l6h4kLLcMwji/XOb7VuM2UpuoFfCacrNTDT6mqbiXicejxSLiGOWpIDK2/K ooHJqO6aLKb3TYgTl/KTyjIp8y8wPRoolFGahByV0IdiZ7LFyU/kPPAVxvb37XR+Bib/ GqDYkBU6AIVvABicy8DN/jgvnIU8uY6mp2HU0UfLU3TeTdmE/T3U1afycxcrqBcOqjwR mRcw== X-Forwarded-Encrypted: i=1; AJvYcCUXKCudU+gAjE+WOksJmdiMO3D/Ew+1mT4yLJPMss8j5uKqXIrK9+w325efChn5U54B+j3bHU7FaKwcNyg=@vger.kernel.org X-Gm-Message-State: AOJu0YxAOEsSi43jafQsdsrRTKxl7DVsaoVxUt4HNszVB1jt9UeuVPVj WynqwsCX6rH+qKaOaDf7QvUbwEb5QMVdR6RRZ+MyMrBiIRVniKQ6OKQBVOB+EH25Tl09p8gkp2y W+tiGYaweTMqzQ2cmQ0itbG2j7i8xJpzW3YG1RkmLO6TbvqHc8l8EOaydTb7LoLoyl/E= X-Gm-Gg: ATEYQzzzyJP+5441iHRKcqAL1UJ5q3LcfFoCsD1CQEkFGbK99r7bwlojy0sole6TTgJ c+4tbWVaPCuJY5ms6gKJ2NahQ6Zwy0ARORgVVdVDm1b3eGQviliN33vlFXhW1rXYxrx0U+SnrSp qBYrcg88PrnXR0qaAYJDu4ZgplvoAIRM8h5tLORfa/onP52Chzjx96JDDx0xfAePXvlivWSyFRJ E1e2jn8hHr3i6F88Tl6cfCG/JZ1nbiYV5zMhNlrzZ7/tE3G/0tvAYFkEQ3oApQxNlGFOwQC2n3O QsvTShTLeHkSwV4AqxG4Cv7OpLkAvLGkjL+hhc8Mo9u9YVY5i2/h3YCHbx8kWRS/2pbFMmRdYFn mms1ZDgWIoBn/gjNJSwggijwqHM68oaqmDMLRq0C+ugKeONRsiys4DsD4M2lC8W6yaqmw0Cswy5 Mts1Q= X-Received: by 2002:a05:7022:6713:b0:128:d17b:e7ab with SMTP id a92af1059eb24-12a96ef7ce1mr1124998c88.36.1774421729159; Tue, 24 Mar 2026 23:55:29 -0700 (PDT) X-Received: by 2002:a05:7022:6713:b0:128:d17b:e7ab with SMTP id a92af1059eb24-12a96ef7ce1mr1124976c88.36.1774421727992; Tue, 24 Mar 2026 23:55:27 -0700 (PDT) Received: from [10.110.19.183] (i-global254.qualcomm.com. [199.106.103.254]) by smtp.gmail.com with ESMTPSA id a92af1059eb24-12a733b4a99sm12883815c88.1.2026.03.24.23.55.25 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Tue, 24 Mar 2026 23:55:27 -0700 (PDT) Message-ID: Date: Wed, 25 Mar 2026 14:55:23 +0800 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: Re: [PATCH v1 2/3] dm-inlinecrypt: add target for inline block device encryption To: Eric Biggers Cc: linux-block@vger.kernel.org, linux-kernel@vger.kernel.org, adrianvovk@gmail.com, dm-devel@lists.linux.dev, quic_mdalam@quicinc.com, gmazyland@gmail.com, israelr@nvidia.com, mpatocka@redhat.com References: <20260304121729.1532469-1-linlin.zhang@oss.qualcomm.com> <20260304121729.1532469-3-linlin.zhang@oss.qualcomm.com> <20260312070110.GD2359@sol> Content-Language: en-US From: Linlin Zhang In-Reply-To: <20260312070110.GD2359@sol> Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwMzI1MDA0NyBTYWx0ZWRfXw1hcRriKUmmH UnqceATl78wZMdcOgFOpKdrkNv3VOXmwO3sq1Cfov1+s+0B1kBVhEUYeDLpeR+vPW9IqiOlG45M CeBm0475qykPEXcmGM4mc0aW7kUByk+Hl0Fhv2cmibr628SCvRgdRpdMloNAe2trt0CScw6aS5E BtRn0wIEpI5Pksxl2gwGJE13bWLfvK36/6IOnviulkXuKJ2YytOouGrl+lTRSbdHiBXBaLk7cB8 iJrsGtG6Ou2X0Phh1fn9ahMBi7e/6mLDq48OE4S63Rufv0gapSIz6KmyFgh7stmnt05RlxsDp7l 2zac1pLeLBNqPRShiRS6vW4Ja5rYsogbtcphOS25V7Lsk0pyenHh7ekY/uKwNxPQB8b7XaZ2j6z bCpcZ1gMKdXPXRbVfixPsyxlrHc3EvtYYL56rk0PjjMjXe78d3X9CyZLBVK3jbUhAZWQIfBIBNb VeaVhXLg0q3eK4m89BA== X-Authority-Analysis: v=2.4 cv=VODQXtPX c=1 sm=1 tr=0 ts=69c386e2 cx=c_pps a=SvEPeNj+VMjHSW//kvnxuw==:117 a=JYp8KDb2vCoCEuGobkYCKw==:17 a=IkcTkHD0fZMA:10 a=Yq5XynenixoA:10 a=s4-Qcg_JpJYA:10 a=VkNPw1HP01LnGYTKEx00:22 a=u7WPNUs3qKkmUXheDGA7:22 a=_glEPmIy2e8OvE2BGh3C:22 a=VwQbUJbxAAAA:8 a=Oh2cFVv5AAAA:8 a=1XWaLZrsAAAA:8 a=EUspDBNiAAAA:8 a=p8t-2gd-wzcZwGZBdWsA:9 a=QEXdDO2ut3YA:10 a=Kq8ClHjjuc5pcCNDwlU0:22 a=7KeoIwV6GZqOttXkcoxL:22 X-Proofpoint-GUID: Tjl-NN92h1TAzz9GwYbtvvZ6WMradcPO X-Proofpoint-ORIG-GUID: Tjl-NN92h1TAzz9GwYbtvvZ6WMradcPO X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1143,Hydra:6.1.51,FMLib:17.12.100.49 definitions=2026-03-25_02,2026-03-24_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 suspectscore=0 lowpriorityscore=0 malwarescore=0 phishscore=0 priorityscore=1501 spamscore=0 impostorscore=0 clxscore=1015 adultscore=0 bulkscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2603050001 definitions=main-2603250047 On 3/12/2026 3:01 PM, Eric Biggers wrote: > On Wed, Mar 04, 2026 at 04:17:27AM -0800, Linlin Zhang wrote: >> From: Eric Biggers >> >> Add a new device-mapper target "dm-inlinecrypt" that is similar to >> dm-crypt but uses the blk-crypto API instead of the regular crypto API. >> This allows it to take advantage of inline encryption hardware such as >> that commonly built into UFS host controllers. >> >> The table syntax matches dm-crypt's, but for now only a stripped-down >> set of parameters is supported. For example, for now AES-256-XTS is the >> only supported cipher. >> >> dm-inlinecrypt is based on Android's dm-default-key with the >> controversial passthrough support removed. Note that due to the removal >> of passthrough support, use of dm-inlinecrypt in combination with >> fscrypt causes double encryption of file contents (similar to dm-crypt + >> fscrypt), with the fscrypt layer not being able to use the inline >> encryption hardware. This makes dm-inlinecrypt unusable on systems such >> as Android that use fscrypt and where a more optimized approach is >> needed. It is however suitable as a replacement for dm-crypt. >> >> Signed-off-by: Eric Biggers >> Signed-off-by: Linlin Zhang > > I don't think it's plausible that this new patch was actually tested. > The version I sent in 2024 was tested at the time > (https://lore.kernel.org/r/20241016232748.134211-3-ebiggers@kernel.org/), > but I see at least two things that would make this new patch not work. > > First, the call to blk_crypto_init_key() will always fail, since it's > being passed BLK_CRYPTO_KEY_TYPE_HW_WRAPPED but using a 64-byte raw key. > > It needs to be BLK_CRYPTO_KEY_TYPE_RAW. (BLK_CRYPTO_KEY_TYPE_HW_WRAPPED > support would make sense to add as an extra feature, once the basic raw > key support is working. Note that when I sent the first version of this > patch, support for wrapped keys was not yet upstream at all.) Thanks for the review! Yes, a mini change about key size validation is absent in this patch, which leads to the failure of dm-table loading with dm-inlinecrypt target. Similar to dm-default-key in Android, next patch updates ctr function to ensure the key size not larger than BLK_CRYPTO_MAX_ANY_KEY_SIZE, and pass this key size to blk_crypto_init_key(). > > Second, since v7.0-rc1, submitters of bios don't automatically get > blk-crypto-fallback support; they need to request it explicitly. So, > this patch will not work with blk-crypto-fallback anymore. > > If you'd like to continue work on this patch, it might be helpful to > check the latest version of dm-default-key.c in "android-mainline" > (https://android.googlesource.com/kernel/common/+/android-mainline/drivers/md/dm-default-key.c) > and resynchronize this patch with it. It already has the code to > correctly support both key types and blk-crypto-fallback, for example. ACK > > Either way, this patch also needs to be re-tested with the latest > upstream kernel, which doesn't seem to have happened unfortunately. I'll share the test result on top of the latest upstream kernel in next patch. > > - Eric