From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from kanga.kvack.org (kanga.kvack.org [205.233.56.17]) by smtp.lore.kernel.org (Postfix) with ESMTP id 87FB3C433FE for ; Tue, 7 Dec 2021 19:46:19 +0000 (UTC) Received: by kanga.kvack.org (Postfix) id 1B3CD6B0072; Tue, 7 Dec 2021 14:46:09 -0500 (EST) Received: by kanga.kvack.org (Postfix, from userid 40) id 162916B0073; Tue, 7 Dec 2021 14:46:09 -0500 (EST) X-Delivered-To: int-list-linux-mm@kvack.org Received: by kanga.kvack.org (Postfix, from userid 63042) id 029EF6B0074; Tue, 7 Dec 2021 14:46:08 -0500 (EST) X-Delivered-To: linux-mm@kvack.org Received: from forelay.hostedemail.com (smtprelay0120.hostedemail.com [216.40.44.120]) by kanga.kvack.org (Postfix) with ESMTP id EA96B6B0072 for ; Tue, 7 Dec 2021 14:46:08 -0500 (EST) Received: from smtpin14.hostedemail.com (10.5.19.251.rfc1918.com [10.5.19.251]) by forelay05.hostedemail.com (Postfix) with ESMTP id B5DCE1854A7FC for ; Tue, 7 Dec 2021 19:45:58 +0000 (UTC) X-FDA: 78892028796.14.91936C3 Received: from mail-yb1-f170.google.com (mail-yb1-f170.google.com [209.85.219.170]) by imf16.hostedemail.com (Postfix) with ESMTP id 4084BF00008F for ; Tue, 7 Dec 2021 19:45:58 +0000 (UTC) Received: by mail-yb1-f170.google.com with SMTP id v203so406119ybe.6 for ; Tue, 07 Dec 2021 11:45:58 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=eclypsium.com; s=google; h=mime-version:in-reply-to:references:from:date:message-id:subject:to :cc; bh=2MSneKG+T5ZjFsWvdBHkKcc61yLnH/4zmInamMFTcOc=; b=XRkVTCiWO1xz/EgHSVzeCjqGeOiyHM0C+EN8gqsD/GqXB68KIB5RbhVg6sQb4LCb3u MRNmBwVVRaoAZ/Q8jvhNx0e/VxiN53KcjnypA1l69bDxHGLdgaPSd2GEhJowXsz53FKl I+zyjV3nz4SgF+4McKTXS6Nj32UMfk04IS1TsLBkMasy3mRiOg+KHMPOh4QpyZJIwsRq 0ZyNf2090Jdx/gL/0XHDt5WWeVpPXHocZB1Ad8FOBYIdcEGqn1l6V2KsGrvXH2ApiBjs ArsNfqlOy7/hXZXncjsZCbJHFeVHPFLaUAE6TNcwsPZ45P3l49H/Dp4cQZHVTqKb8Mfa avhg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to:cc; bh=2MSneKG+T5ZjFsWvdBHkKcc61yLnH/4zmInamMFTcOc=; b=vzJShVwNwe+x6DGB7nM9nQR4QBjLb1usG4s3Tx1nYyvTpTzGeH9eXLokMt7dBkorRc ANC0B0+Shb/XKSUhFn3F3yYpRfGup6oKLkB7zbeIe1ZGOktIBbTLjNlhINtU6EAkyHnT WlX0E0hxlDfuybH2Y+qvu9Nq7hCvszSLD7SgL/tz/1x/TDifE0Ogb8Y73l3upjU9abP6 WaGjD9M0HE5yUXJX8TB8Lz81bmyjawnmdn7Ps5YAIf7bohuwiH3kIepGGfE5LazeXYXL J5MVgK9yShlZ7dVftzQnnezxXV18SUd6Pkclpf/4F5v3uu9HQr/9isks1F97gO9p/Tem 4IRw== X-Gm-Message-State: AOAM533TN9z2bJq7JVZc3K80ZZEvtrqiU2sAkC94VsAcMPwf6lR04rNs de2z5ylCGSLHdFDUgX9MWta08OWTpvwHd/FUVkrgnA== X-Google-Smtp-Source: ABdhPJyMqHWSV5GGCftCDu/HHVqZSiWmTiUYcfhsLUySuKeO9UuAqLyCDwSql+GLxl0eiomj1NdDabqRlTah2chxdy8= X-Received: by 2002:a25:c8c3:: with SMTP id y186mr53620558ybf.20.1638906357546; Tue, 07 Dec 2021 11:45:57 -0800 (PST) MIME-Version: 1.0 Received: by 2002:a0d:c906:0:0:0:0:0 with HTTP; Tue, 7 Dec 2021 11:45:56 -0800 (PST) In-Reply-To: References: <20211203192148.585399-1-martin.fernandez@eclypsium.com> From: Martin Fernandez Date: Tue, 7 Dec 2021 16:45:56 -0300 Message-ID: Subject: Re: [PATCH v3 0/5] x86: Show in sysfs if a memory node is able to do encryption To: Mike Rapoport Cc: Richard Hughes , linux-kernel@vger.kernel.org, linux-efi@vger.kernel.org, platform-driver-x86@vger.kernel.org, linux-mm@kvack.org, tglx@linutronix.de, mingo@redhat.com, bp@alien8.de, dave.hansen@linux.intel.com, x86@kernel.org, hpa@zytor.com, ardb@kernel.org, dvhart@infradead.org, andy@infradead.org, gregkh@linuxfoundation.org, rafael@kernel.org, akpm@linux-foundation.org, daniel.gutson@eclypsium.com, alex.bazhaniuk@eclypsium.com, alison.schofield@intel.com Content-Type: text/plain; charset="UTF-8" X-Rspamd-Server: rspam10 X-Rspamd-Queue-Id: 4084BF00008F X-Stat-Signature: s7tn84imrw7sq4f9p58rntzqsnz9ffaw Authentication-Results: imf16.hostedemail.com; dkim=pass header.d=eclypsium.com header.s=google header.b=XRkVTCiW; dmarc=pass (policy=quarantine) header.from=eclypsium.com; spf=pass (imf16.hostedemail.com: domain of martin.fernandez@eclypsium.com designates 209.85.219.170 as permitted sender) smtp.mailfrom=martin.fernandez@eclypsium.com X-HE-Tag: 1638906358-168803 X-Bogosity: Ham, tests=bogofilter, spamicity=0.000000, version=1.2.4 Sender: owner-linux-mm@kvack.org Precedence: bulk X-Loop: owner-majordomo@kvack.org List-ID: On 12/7/21, Mike Rapoport wrote: > Hi Richard, > > On Mon, Dec 06, 2021 at 07:58:10PM +0000, Richard Hughes wrote: >> On Sun, 5 Dec 2021 at 06:04, Mike Rapoport wrote: >> > On Fri, Dec 03, 2021 at 04:21:43PM -0300, Martin Fernandez wrote: >> > > fwupd project plans to use it as part of a check to see if the users >> > > have properly configured memory hardware encryption capabilities. >> > I'm missing a description about *how* the new APIs/ABIs are going to be >> > used. >> >> We're planning to use this feature in the Host Security ID checks done >> at every boot. Please see >> https://fwupd.github.io/libfwupdplugin/hsi.html for details. I'm happy >> to answer questions or concerns. Thanks! > > Can you please describe the actual check for the memory encryption and how > it would impact the HSI rating? > > I wonder, for example, why did you choose per-node reporting rather than > per-region as described in UEFI spec. Some time ago we discussed about this and concluded with Dave Hansen that it was better to do it in this per-node way. This is the archive of the relevant discussion: http://lkml.iu.edu/hypermail/linux/kernel/2006.2/06753.html