From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mx0a-0031df01.pphosted.com (mx0a-0031df01.pphosted.com [205.220.168.131]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 1B6682F6931 for ; Fri, 24 Apr 2026 13:53:31 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=205.220.168.131 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1777038813; cv=none; b=UxRu3OvJKCDoA6FpEgbudHJ/WVbJ5mWU47RhK5cUHGxiR++ORYM/FPmwRaqqJHHNY4Oa5tCFpfHSe0WT8hC/VfSyh86viH/39aPzwaO5CXAi3DwGmRiK8H2heEGuRdw6pj6Cp4xgvYnz4piwbijSHEdWkYzjv+/o1mzHbOpQHNc= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1777038813; c=relaxed/simple; bh=Ew/WV0PUTr0b3usbEk/Lg6XKBeQ1rjvblixshSrvBb4=; h=Message-ID:Date:MIME-Version:Subject:To:Cc:References:From: In-Reply-To:Content-Type; b=FRAAA8pJe+XsKL2xnU9gyasO4V1oftQckvVAj9q7WjISHajubzru1SFY5rXJA2jhzsJj+BKUcN1uUQrjVfayAbebjn05OZJeL0fj0laoQNGZPtPgmdOIS+h7Q4PJq6BBRSRqxcEYg6ViWrbgFimC9sY+flQBUeQg9cm9RYoL/hc= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=oss.qualcomm.com; spf=pass smtp.mailfrom=oss.qualcomm.com; dkim=pass (2048-bit key) header.d=qualcomm.com header.i=@qualcomm.com header.b=D6Zvbauf; dkim=pass (2048-bit key) header.d=oss.qualcomm.com header.i=@oss.qualcomm.com header.b=exNDjcp/; arc=none smtp.client-ip=205.220.168.131 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=oss.qualcomm.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=oss.qualcomm.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=qualcomm.com header.i=@qualcomm.com header.b="D6Zvbauf"; dkim=pass (2048-bit key) header.d=oss.qualcomm.com header.i=@oss.qualcomm.com header.b="exNDjcp/" Received: from pps.filterd (m0279864.ppops.net [127.0.0.1]) by mx0a-0031df01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 63OCgkeK1822923 for ; Fri, 24 Apr 2026 13:53:31 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=qualcomm.com; h= cc:content-transfer-encoding:content-type:date:from:in-reply-to :message-id:mime-version:references:subject:to; s=qcppdkim1; bh= F8PoJPEsRbQRU9RB6wNnJ9EpTGXTP8HI8ZOx3/+rwVA=; b=D6Zvbaufpi1byZhs x1fHDUi3wN4G/kJT1JMgu4Oc4XtfHQmkNuMPGg7GG+qXMeLXiCfoB1s/Ecj5QsBL MfmlhkrcBP/9/3N2DGulHpYSNQVC/BtGggdBIffc7IY8JkSk/CmCQP/0WarBqVyF J/0P7XvGWfqCO9EmCoPvhnTe4LQH+osWDmuM7HOHtOv4eJdsim2pTyCz+gZkaw3T 5g3yh1xkj9Ks9Yu2nqZf7T3T1LmKYyYjX9+kfLEM014W+5EJYOcTLV2fY//bcDEE Nisztc9D/K/EJMWmhEfaoQh0oB+6iAye9iOq4LLuisGIp+Gr/EQ16JSwk2vVxDoT 8ro3ow== Received: from mail-dy1-f198.google.com (mail-dy1-f198.google.com [74.125.82.198]) by mx0a-0031df01.pphosted.com (PPS) with ESMTPS id 4dqv5ru98h-1 (version=TLSv1.3 cipher=TLS_AES_128_GCM_SHA256 bits=128 verify=NOT) for ; Fri, 24 Apr 2026 13:53:31 +0000 (GMT) Received: by mail-dy1-f198.google.com with SMTP id 5a478bee46e88-2dd1c74508cso12656720eec.0 for ; Fri, 24 Apr 2026 06:53:31 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=oss.qualcomm.com; s=google; t=1777038811; x=1777643611; darn=vger.kernel.org; h=content-transfer-encoding:in-reply-to:from:content-language :references:cc:to:subject:user-agent:mime-version:date:message-id :from:to:cc:subject:date:message-id:reply-to; bh=F8PoJPEsRbQRU9RB6wNnJ9EpTGXTP8HI8ZOx3/+rwVA=; b=exNDjcp/JTBhGy1Qv0aqQdBxy7DBa+GRzjJC2lziaFSv7Mguuc2Q3fd4hLwaMAZUkD ffBvUH9b8+QJudGOCCfROtQhj1ojP55tzvxad0Pjdr+libvdLesOecTcKUFhUVZ198tK 2Ow5JMq1Y8czze2LWXhmauNROZH7HFytIpYvvcVmD5czBwRhzq6upoaBvt6yre63ctDb H8PnkWk6dFQepQctdhbu7Q82ddSGNOhHoeV3T29qDKd+W40yqi+2LwEbA+pn5G98tQNW nZOBFA4UXq2nZTkHvxAMTtO8L1SZdAveKCamgI1rMYGKXKyzPr71iiDN+E7Mhv7TL56/ LhBw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1777038811; x=1777643611; h=content-transfer-encoding:in-reply-to:from:content-language :references:cc:to:subject:user-agent:mime-version:date:message-id :x-gm-gg:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=F8PoJPEsRbQRU9RB6wNnJ9EpTGXTP8HI8ZOx3/+rwVA=; b=V4eXkELOiA+MyE68xXg35z6G4eQrS3QBb9g/LcjHiPwjWR+2RK1IAUAWxkf5NTEhfz wkBOPMSe0HmPsYYS1/x5ZTVw/UXfWG+q1Ri8ZmSmp00ET23zYJSSX/e7OVbC8fYwt6Gq TQvAMR4KopD4Ya4Ty2Tan/CbU/wKYSWGce1EFN9SsxtOqpBQebUnjW0XqqoL64eLigCl jv7aWfWz77hOcPvO2+Al81s6KzFPCj48ralPmuU93iO7Q6pACL1RtSyVEBzL9f7ahoCu cR8ddXwmi1rtKOJNmOiCY6bPXNLZwqpJvr/0RHYebTqz3jAh2MIiWFjp0uDqDwoli18a rDKw== X-Gm-Message-State: AOJu0YzmZK6ny5zHjT+fodHgTEqjKLg/cXDKOH1HMZ2XV1N2j2zn8GpI YFaqWS1YZFsELaUEVVhky0l3Un07pfYF1fBUW0UB5VbbxbtGV8bwdlFp675pebHCo+wfomhdxwc 8eYD+KbIxGNyAidVVdGuUsn7EDVb1siMCtQON1GTrEA23EcoosaXm8KEkCWoXqBUCsic= X-Gm-Gg: AeBDietiLw6061jeZgMMnWWATa5XU6j/CgTi4cLrtxAg5MfOs00EsmEHMTyb1sra6Uj dDrKAbMqukpQktVLJoE/HNWz1BkOmggL76Qd60nT/Gyq8AhV2qv/sW/qJ8WKTx/dMhvi5qinVza cRwpBGe6S1X2szab/FMBR3l3+hHCqaYayGsI6wdmQGEtn29nHUA+ot9l2xEUybq6JfgEtE2KLEI nEarlcYyiBdkvQDPT/xUu1ZY0LhVImMGT4hZstmq9sfbKnd0yvlHJRk9vmyLZAVoiiy2kgZZaZi Z1TDblRzT/wgL3tpemZM0LzrzIR8ed1N18LFubYNgnP3Hd+RQ8VnGgmQj2rxIQIb6aS1kolH1bU 7HTvo3G6PkeKUxsc45VyiAn6DtY3Z2edTnLoQRWcLEnv/p74uOTMeNSm9jOHI8itDkjJ1a3yJsP ZMmIh9Gx0gDKBoiA== X-Received: by 2002:a05:693c:8005:b0:2dd:144b:6c2 with SMTP id 5a478bee46e88-2e478e28c50mr12950268eec.27.1777038810399; Fri, 24 Apr 2026 06:53:30 -0700 (PDT) X-Received: by 2002:a05:693c:8005:b0:2dd:144b:6c2 with SMTP id 5a478bee46e88-2e478e28c50mr12950239eec.27.1777038809634; Fri, 24 Apr 2026 06:53:29 -0700 (PDT) Received: from [10.110.109.54] (i-global254.qualcomm.com. [199.106.103.254]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-2e79c2954f6sm34425608eec.30.2026.04.24.06.53.26 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Fri, 24 Apr 2026 06:53:29 -0700 (PDT) Message-ID: Date: Fri, 24 Apr 2026 21:53:24 +0800 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: Re: [PATCH v2 3/3] dm: add documentation for dm-inlinecrypt target To: Milan Broz , linux-block@vger.kernel.org, ebiggers@kernel.org, mpatocka@redhat.com Cc: linux-kernel@vger.kernel.org, adrianvovk@gmail.com, dm-devel@lists.linux.dev, quic_mdalam@quicinc.com, israelr@nvidia.com, hch@infradead.org, axboe@kernel.dk References: <20260410134031.2880675-1-linlin.zhang@oss.qualcomm.com> <20260410134031.2880675-4-linlin.zhang@oss.qualcomm.com> <1a36c5e7-5fd6-4923-926e-65bb04c33b04@gmail.com> Content-Language: en-US From: Linlin Zhang In-Reply-To: <1a36c5e7-5fd6-4923-926e-65bb04c33b04@gmail.com> Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit X-Authority-Analysis: v=2.4 cv=LqiiDHdc c=1 sm=1 tr=0 ts=69eb75db cx=c_pps a=wEP8DlPgTf/vqF+yE6f9lg==:117 a=JYp8KDb2vCoCEuGobkYCKw==:17 a=IkcTkHD0fZMA:10 a=A5OVakUREuEA:10 a=s4-Qcg_JpJYA:10 a=VkNPw1HP01LnGYTKEx00:22 a=u7WPNUs3qKkmUXheDGA7:22 a=DJpcGTmdVt4CTyJn9g5Z:22 a=p0WdMEafAAAA:8 a=EUspDBNiAAAA:8 a=9XuA7vtyGULosQ0LkOoA:9 a=3ZKOabzyN94A:10 a=QEXdDO2ut3YA:10 a=bBxd6f-gb0O0v-kibOvt:22 X-Proofpoint-ORIG-GUID: safMpoJH-hozRyDVZsf2wN1vgi1s40YY X-Proofpoint-GUID: safMpoJH-hozRyDVZsf2wN1vgi1s40YY X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwNDI0MDEzMyBTYWx0ZWRfX8WBcAmTQr9Ya PmU9FFOccSQngrQrDUOgsAp9Qr+JP/0TO3aAiPBGVU6nSJWJ9wHEdJfA680hHrlzs00P5B66cM1 A/PCXnUKVvBNrzKySFf0f0OxpXEo4u8ea1UXVMakdNMa+bQ1NqqA6ac+1odF/Tq0tjA/mvoZ/MX sml/ZA9604suwLIokno7Y6mn/Ir9/eSIJlbtlfgexGY5vynt0BD3ZTf3DwPUHI/Lrulz+SXbL77 LeJp+nUgJUKZmq+HMy7+DUUx5NZi0bEA83CbxbQbA3enD6QbpQwJayCDYf41uvgIMazj9CNUa9o STABJcuAprAAKhn1sUjlI5bR+Fnb9KahyJQZCdWe96lVnHUNsBHxopIzDctwpvNKp9fjyMu+DMe +UF/z+XLE0YZ68tw6uZOw3td6HoeNs0NBJqRHT6cjy763eHojc44n6oQ+oKgmD0b+kV2CDRRmMc pGVlmtdLyWvdkO3NG8A== X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1143,Hydra:6.1.51,FMLib:17.12.100.49 definitions=2026-04-24_01,2026-04-21_02,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 spamscore=0 bulkscore=0 clxscore=1015 impostorscore=0 lowpriorityscore=0 malwarescore=0 suspectscore=0 adultscore=0 phishscore=0 priorityscore=1501 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2604200000 definitions=main-2604240133 On 4/11/2026 1:07 AM, Milan Broz wrote: > On 4/10/26 3:40 PM, Linlin Zhang wrote: >> This adds the admin-guide documentation for dm-inlinecrypt. >> >> dm-inlinecrypt.rst is the guide to using dm-inlinecrypt. >> >> Signed-off-by: Linlin Zhang >> --- > > ... > >> + >> + >> +    Encryption cipher type. >> + >> +    The cipher specifications format is:: >> + >> +       cipher >> + >> +    Examples:: >> + >> +       aes-xts-plain64 >> + >> +    The cipher type is correspond one-to-one with encryption modes. For > > ... with encryption modes supported for inline crypto in block layer? > > In your patch only BLK_ENCRYPTION_MODE_AES_256_XTS. Thanks for your insights! Yes, here the encryption modes refer to the inline crypto modessupported by the block layer. Currently, this patch only supports BLK_ENCRYPTION_MODE_AES_256_XTS. I will reword it as: The cipher type corresponds to the encryption modes supported by inline crypto in the block layer. Currently, only BLK_ENCRYPTION_MODE_AES_256_XTS (i.e. aes-xts-plain64) is supported. Could you please let me know if you expect more than that? > >> +    instance, the corresponding crypto mode of aes-xts-plain64 is >> +    BLK_ENCRYPTION_MODE_AES_256_XTS. > > ... > >> +iv_large_sectors >> +   IV generators will use sector number counted in units >> +   instead of default 512 bytes sectors. >> + >> +   For example, if is 4096 bytes, plain64 IV for the second >> +   sector will be 8 (without flag) and 1 if iv_large_sectors is present. >> +   The must be multiple of (in 512 bytes units) >> +   if this flag is specified. > > Is it true? I see this comment in the code: > > /* dm-inlinecrypt doesn't implement iv_large_sectors=false. */ Thanks for your comment! The example is describing the general IV generation semantics of iv_large_sectors versus the legacy behavior, i.e. how plain64 IVs would be computed conceptually with and without the flag. However, for dm-inlinecrypt, the comment you quoted is correct: iv_large_sectors=false is not implemented. When a sector size larger than 512 bytes is used, iv_large_sectors is mandatory, and the legacy 512-byte-based IV behavior is intentionally unsupported. In the code this is enforced by rejecting configurations where sector_size != 512 and iv_large_sectors is not specified, so in practice the “without flag” case is not usable for dm-inlinecrypt. I reword it as: iv_large_sectors Use -based sector numbers for IV generation instead of 512-byte sectors. For dm-inlinecrypt, this flag must be specified when is larger than 512 bytes. The legacy 512-byte-based IV behavior is not supported. When specified, if is 4096 bytes, plain64 IV for the second sector will be 1, and must be a multiple of (in 512-byte units). Do think it's enough? > > ... > >> +Example scripts >> +=============== >> +LUKS (Linux Unified Key Setup) is now the preferred way to set up disk >> +encryption with dm-inlinecrypt using the 'cryptsetup' utility, see >> +https://gitlab.com/cryptsetup/cryptsetup > > Cryptsetup has no support for inlinecrypt and it is question if it should have. > It would require additional options and maybe LUKS2 metadata flag to make it persistent. > > How did you test it? Please remove this cryptsetup example. > It can be added later when userspace get this functionality. You are right. cryptsetup currently has no support for dm-inlinecrypt, and the example would indeed create a dm-crypt device instead. Supporting dm-inlinecrypt in cryptsetup would require explicit userspace changes and possibly extensions to LUKS2 metadata to make it persistent. I did the testing using dmsetup directly, not via cryptsetup/LUKS. And I'll remove the LUKS/cryptsetup references and examples from the documentation and leave LUKS integration to be documented once userspace support exists. I reword it as: Currently, dm-inlinecrypt devices must be set up directly using dmsetup. There is no userspace support yet to integrate dm-inlinecrypt with LUKS or cryptsetup. In particular, cryptsetup currently only supports dm-crypt, and cannot be used to create dm-inlinecrypt mappings. The following examples demonstrate how to create dm-inlinecrypt devices using dmsetup. > > ...> + >> +    #!/bin/sh >> +    # Create a inlinecrypt device using cryptsetup and LUKS header with default cipher >> +    cryptsetup luksFormat $1 >> +    cryptsetup luksOpen $1 inlinecrypt1 > > ditto. This example will use dm-crypt, not dm-inlinecrypt. ACK > > Milan >