lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date:   Tue, 3 May 2022 04:27:21 +0300
From:   "Kirill A. Shutemov" <kirill@...temov.name>
To:     Kai Huang <kai.huang@...el.com>
Cc:     Kuppuswamy Sathyanarayanan 
        <sathyanarayanan.kuppuswamy@...ux.intel.com>,
        Thomas Gleixner <tglx@...utronix.de>,
        Ingo Molnar <mingo@...hat.com>, Borislav Petkov <bp@...en8.de>,
        Dave Hansen <dave.hansen@...ux.intel.com>, x86@...nel.org,
        "H . Peter Anvin" <hpa@...or.com>,
        "Kirill A . Shutemov" <kirill.shutemov@...ux.intel.com>,
        Tony Luck <tony.luck@...el.com>,
        Andi Kleen <ak@...ux.intel.com>,
        Wander Lairson Costa <wander@...hat.com>,
        Isaku Yamahata <isaku.yamahata@...il.com>,
        marcelo.cerri@...onical.com, tim.gardner@...onical.com,
        khalid.elmously@...onical.com, philip.cox@...onical.com,
        linux-kernel@...r.kernel.org
Subject: Re: [PATCH v5 3/3] x86/tdx: Add Quote generation support

On Mon, May 02, 2022 at 02:40:26PM +1200, Kai Huang wrote:
> 
> > +
> > +	/* Get order for Quote buffer page allocation */
> > +	order = get_order(quote_req.len);
> > +
> > +	/*
> > +	 * Allocate buffer to get TD Quote from the VMM.
> > +	 * Size needs to be 4KB aligned (which is already
> > +	 * met in page allocation).
> > +	 */
> > +	tdquote = (void *)__get_free_pages(GFP_KERNEL | __GFP_ZERO, order);
> > +	if (!tdquote) {
> > +		ret = -ENOMEM;
> > +		goto quote_failed;
> > +	}
> 
> You can use alloc_pages_exact().
> 
> > +
> > +	/*
> > +	 * Since this buffer will be shared with the VMM via GetQuote
> > +	 * hypercall, decrypt it.
> > +	 */
> > +	ret = set_memory_decrypted((unsigned long)tdquote, 1UL << order);
> > +	if (ret)
> > +		goto quote_failed;
> 
> 
> Again, Dave and Andi already commented you should use vmap() to avoid breaking
> up the direct-mapping.  Please use vmap() instead.
> 
> https://lore.kernel.org/all/ce0feeec-a949-35f8-3010-b0d69acbbc2e@linux.intel.com/
> 
> Will review the rest later.

I would rather convert it to use DMA API for memory allocation. It will
tap into swiotlb buffer that already converted and there's no need to
touch direct mapping. Both allocation and freeing such memory is cheaper
because of that.

-- 
 Kirill A. Shutemov

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ