Received: by 2002:a05:7412:d1aa:b0:fc:a2b0:25d7 with SMTP id ba42csp502013rdb; Mon, 29 Jan 2024 08:41:57 -0800 (PST) X-Google-Smtp-Source: AGHT+IEcD1UR5y6jCKpbpp6DImeLBZV4OxY0dekrLnI54DOsZ3XZmuYLy0t8rLBDn7WM2UaKwaaR X-Received: by 2002:a17:907:d50f:b0:a2f:163c:5d54 with SMTP id wb15-20020a170907d50f00b00a2f163c5d54mr10051838ejc.1.1706546517079; Mon, 29 Jan 2024 08:41:57 -0800 (PST) ARC-Seal: i=2; a=rsa-sha256; t=1706546517; cv=pass; d=google.com; s=arc-20160816; b=RxlCgRpIM2NeFSxd4MTB/Cd3DC6QV8LpacHIuwEk3PLlkzCXrBUdIPkXxTB8j1rtkI fW/8gs3+2K9Osc2yeINEOt1QyW9lgq6mGIFpIHNt7qXrwbXyL95l/UDsYllZQqMUqlDK YJsDZYFSSSAM2jf4S6nQD6oK4NnXoqovn2SyySvZZqyforZBfWFOkQJ5rA4VaUWC0xpR +oSU/yQ6HGz9cup1UrKSf6CpKDNIDcwBoflYfjfFtGLdYLEtJ2ODEggfgnFwdcLzHELu kMorDMXAomd8Xn4NUhX2hXuQnnnPiaMivqD1ZRBP3M1E1IpyWPWZwaeTocLKI/kFqkS8 EVFg== ARC-Message-Signature: i=2; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=content-transfer-encoding:mime-version:list-unsubscribe :list-subscribe:list-id:precedence:message-id:references:in-reply-to :user-agent:subject:cc:to:from:date:dkim-signature:dkim-filter; bh=jnhiHc2vJcf7shopPtxezoFGdpgQ4x3ykCkhtXB1nVg=; fh=eU9Ysf2m9almCuBnT+Q8FIxaYJY/AW7A+weLzX0BiLc=; b=bkwAdS76pwjUEG4hpfHJ1jrxPfWAYDUeCAFgBMHevT7uL1JZPdgi4iIj2QXlm4LEJA +rEJbGoFt74lVzf3UWdaTd9kWy3HTln8S8ab4HajqooWe4J6xrPrIyoK21CdHznCxwrR DG1s6d962yyIdIlAyU6I7EgTmYILM5JxmcVe7NHcZ6QzncazZPQPM/uOLDm/h/xcj1sH eKzujaDOhpaNN410E8iMARgXMXh8tw8oAj4dgDmAoRUSmHh09SRtV1hmWxah6Jq7uJQ0 2vqjZI4MCLrF1I+gamv/9S6JQXwN2TsN2xijEkZHsMAmP25DcDhf8BqyxSx+ij3HrGpZ 9W/g== ARC-Authentication-Results: i=2; mx.google.com; dkim=temperror (no key for signature) header.i=@zytor.com header.s=2024011201 header.b=lnbTimrl; arc=pass (i=1 spf=pass spfdomain=zytor.com dmarc=pass fromdomain=zytor.com); spf=pass (google.com: domain of linux-kernel+bounces-43129-linux.lists.archive=gmail.com@vger.kernel.org designates 2604:1380:4601:e00::3 as permitted sender) smtp.mailfrom="linux-kernel+bounces-43129-linux.lists.archive=gmail.com@vger.kernel.org"; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=zytor.com Return-Path: Received: from am.mirrors.kernel.org (am.mirrors.kernel.org. [2604:1380:4601:e00::3]) by mx.google.com with ESMTPS id lh12-20020a170906f8cc00b00a3498eb636asi3605106ejb.682.2024.01.29.08.41.57 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 29 Jan 2024 08:41:57 -0800 (PST) Received-SPF: pass (google.com: domain of linux-kernel+bounces-43129-linux.lists.archive=gmail.com@vger.kernel.org designates 2604:1380:4601:e00::3 as permitted sender) client-ip=2604:1380:4601:e00::3; Authentication-Results: mx.google.com; dkim=temperror (no key for signature) header.i=@zytor.com header.s=2024011201 header.b=lnbTimrl; arc=pass (i=1 spf=pass spfdomain=zytor.com dmarc=pass fromdomain=zytor.com); spf=pass (google.com: domain of linux-kernel+bounces-43129-linux.lists.archive=gmail.com@vger.kernel.org designates 2604:1380:4601:e00::3 as permitted sender) smtp.mailfrom="linux-kernel+bounces-43129-linux.lists.archive=gmail.com@vger.kernel.org"; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=zytor.com Received: from smtp.subspace.kernel.org (wormhole.subspace.kernel.org [52.25.139.140]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by am.mirrors.kernel.org (Postfix) with ESMTPS id D11C01F212B5 for ; Mon, 29 Jan 2024 16:41:56 +0000 (UTC) Received: from localhost.localdomain (localhost.localdomain [127.0.0.1]) by smtp.subspace.kernel.org (Postfix) with ESMTP id 46C7515AAD4; Mon, 29 Jan 2024 16:37:59 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; dkim=fail reason="signature verification failed" (2048-bit key) header.d=zytor.com header.i=@zytor.com header.b="lnbTimrl" Received: from mail.zytor.com (terminus.zytor.com [198.137.202.136]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id C740A155A59 for ; Mon, 29 Jan 2024 16:37:56 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=198.137.202.136 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1706546278; cv=none; b=rB0YGAokvAiJUb6NVGk7GY8gvoBAmdwaxA4POV7Ni/cvKof3+pNKHclJahfzdyAArZb7EQwPRotn/+qzMsIdg7iqchTrkHSeV2bHiNP29U3rvmO9Uk3nzUDBxh8dGZ7SR5hMZ1nQNIFVeArHMD1yEJOdQtPkqi9RYy6i98vFrd0= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1706546278; c=relaxed/simple; bh=Vv0bghzWikF0hRqV3J+Zqtj67Ynj9bVIOzXQeSr1MR0=; h=Date:From:To:CC:Subject:In-Reply-To:References:Message-ID: MIME-Version:Content-Type; b=UemR8676G9kF3yCUDUIzw8SgM5bo7kk3FK1HsxJodFNGq2IWbaQltKQN9snbmMULe9GkyW3G36iG559AttP0/UWXji3zj+rrV0/qElPKJ894t/w9dpb6eKtjYpp9Y6Nj6fQNc8Pk/8qtobN8x1ZGqTGtbzYeqTpfrWi2gSy2C/A= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=zytor.com; spf=pass smtp.mailfrom=zytor.com; dkim=fail (2048-bit key) header.d=zytor.com header.i=@zytor.com header.b=lnbTimrl reason="signature verification failed"; arc=none smtp.client-ip=198.137.202.136 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=zytor.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=zytor.com Received: from [127.0.0.1] ([76.133.66.138]) (authenticated bits=0) by mail.zytor.com (8.17.2/8.17.1) with ESMTPSA id 40TGbI5I2234742 (version=TLSv1.3 cipher=TLS_AES_128_GCM_SHA256 bits=128 verify=NO); Mon, 29 Jan 2024 08:37:18 -0800 DKIM-Filter: OpenDKIM Filter v2.11.0 mail.zytor.com 40TGbI5I2234742 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=zytor.com; s=2024011201; t=1706546240; bh=jnhiHc2vJcf7shopPtxezoFGdpgQ4x3ykCkhtXB1nVg=; h=Date:From:To:CC:Subject:In-Reply-To:References:From; b=lnbTimrlMHWAIptNbJLJlsWk/ZzejlJYo7i0NhbqKX9pzTjQwc1sC18gGk04/K1Vx ZQoNUJVCAsPQDcfuiVOMC+hHMvmcHNR4gV30x3Reh/GArk3M0GuqP9J7HFMXw8ROrW WDJIE4tPLzANlznjDrUZzesM7aG8dCKOk0avC3eQJesc3AZesr8FOoh+aWpeuRcF1R 1uwPPJQbs0aMUuaROMcO1xBvlD4dWvMjvHjWxiUQFBzRZem/0i5tZSs2ZZbjC2jfzw ksMDFTp1rRWnnYhS0c3AA3Q408uLhT9kulckKPMW65ZJZefIQtXt37V/3hxCR9c/fw pHH7xjAennTcw== Date: Mon, 29 Jan 2024 08:37:15 -0800 From: "H. Peter Anvin" To: Dave Hansen , "Kirill A. Shutemov" , Thomas Gleixner , Ingo Molnar , Borislav Petkov , Dave Hansen , x86@kernel.org, "Theodore Ts'o" , "Jason A. Donenfeld" CC: Kuppuswamy Sathyanarayanan , Elena Reshetova , Jun Nakajima , Tom Lendacky , "Kalra, Ashish" , Sean Christopherson , linux-coco@lists.linux.dev, linux-kernel@vger.kernel.org Subject: Re: [RFC] Randomness on confidential computing platforms User-Agent: K-9 Mail for Android In-Reply-To: <276aaeee-cb01-47d3-a3bf-f8fa2e59016c@intel.com> References: <20240126134230.1166943-1-kirill.shutemov@linux.intel.com> <276aaeee-cb01-47d3-a3bf-f8fa2e59016c@intel.com> Message-ID: <82842879-FD34-4652-9714-AEE1F237EFF4@zytor.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable On January 29, 2024 8:30:11 AM PST, Dave Hansen = wrote: >On 1/26/24 05:42, Kirill A=2E Shutemov wrote: >> 3=2E Panic after enough re-tries of RDRAND/RDSEED instructions fail=2E >> Another DoS variant against the Guest=2E > >I think Sean was going down the same path, but I really dislike the idea >of having TDX-specific (or CoCo-specific) policy here=2E > >How about we WARN_ON() RDRAND/RDSEED going bonkers? The paranoid folks >can turn on panic_on_warn, if they haven't already=2E That would be good anyway=2E