Received: by 2002:a05:7412:d1aa:b0:fc:a2b0:25d7 with SMTP id ba42csp1540554rdb; Wed, 31 Jan 2024 01:30:48 -0800 (PST) X-Google-Smtp-Source: AGHT+IFDz4HzIw5c1bz7fvqqhVmmdGZ6WW3b56ZkLrJIgqW/k8ExIvq+kjAqliGmyxgEhQHrvsMl X-Received: by 2002:a05:622a:1cb:b0:42b:ee98:c1e1 with SMTP id t11-20020a05622a01cb00b0042bee98c1e1mr34829qtw.18.1706693448767; Wed, 31 Jan 2024 01:30:48 -0800 (PST) X-Forwarded-Encrypted: i=1; AJvYcCWyTlO93kNV8E/9RYmYRbszPQfkIuS607C5JCBhd2YP+PoqQkbntiyOeIq8+OwEy/MBA2MCS6tYuBhNSJU0LG/Mw6drc561gSwD7QZ9MA== Return-Path: Received: from ny.mirrors.kernel.org (ny.mirrors.kernel.org. [2604:1380:45d1:ec00::1]) by mx.google.com with ESMTPS id y10-20020a05622a120a00b0042aabcc7d6csi5311512qtx.745.2024.01.31.01.30.48 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 31 Jan 2024 01:30:48 -0800 (PST) Received-SPF: pass (google.com: domain of linux-kernel+bounces-46139-linux.lists.archive=gmail.com@vger.kernel.org designates 2604:1380:45d1:ec00::1 as permitted sender) client-ip=2604:1380:45d1:ec00::1; Authentication-Results: mx.google.com; dkim=neutral (body hash did not verify) header.i=@alien8.de header.s=alien8 header.b=BI+GR4Bj; arc=fail (body hash mismatch); spf=pass (google.com: domain of linux-kernel+bounces-46139-linux.lists.archive=gmail.com@vger.kernel.org designates 2604:1380:45d1:ec00::1 as permitted sender) smtp.mailfrom="linux-kernel+bounces-46139-linux.lists.archive=gmail.com@vger.kernel.org"; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=alien8.de Received: from smtp.subspace.kernel.org (wormhole.subspace.kernel.org [52.25.139.140]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ny.mirrors.kernel.org (Postfix) with ESMTPS id 9C1571C24DDE for ; Wed, 31 Jan 2024 09:30:30 +0000 (UTC) Received: from localhost.localdomain (localhost.localdomain [127.0.0.1]) by smtp.subspace.kernel.org (Postfix) with ESMTP id 22F0067C51; Wed, 31 Jan 2024 09:30:24 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; dkim=fail reason="signature verification failed" (4096-bit key) header.d=alien8.de header.i=@alien8.de header.b="BI+GR4Bj" Received: from mail.alien8.de (mail.alien8.de [65.109.113.108]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 9D69560DCC; Wed, 31 Jan 2024 09:30:20 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=65.109.113.108 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1706693423; cv=none; b=DUGZK0bGR9ACpZyjpFr5dI5kV4aFKoKyuP4EV6DuNBQDHHLQzKlaVOo9es3f0kEWaaZQKUIpANLSF7gUf/Yy9xp/0Rwjkpgb2i7EfEPuzgYAkY7gkIwq6ibCWYs1mp9sPSftBAcZsHP6Juav7z6ffV3Kb1nxXR/CXtQjtuxzvrM= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1706693423; c=relaxed/simple; bh=Gez7VbeF659gZEkC8FCMwPC1tU8GUsrN0yYCZ4bjcxA=; h=Date:From:To:Cc:Subject:Message-ID:References:MIME-Version: Content-Type:Content-Disposition:In-Reply-To; b=iMZBC/bjujBI8weztxN/LFT3NOqnOH6EO/8pmmfmfLnqYrEIgWGbOtrj7pWAvaZmbH1EUyL11zmluAn0q/yZdnd+56d4ju62KkzMkHvDoOCyUdERICz7sG425PofPHxiyviHyf750fj7CrWCn4WKEjPXIqW8MeRjEC5RBZMfyGo= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=alien8.de; spf=pass smtp.mailfrom=alien8.de; dkim=pass (4096-bit key) header.d=alien8.de header.i=@alien8.de header.b=BI+GR4Bj; arc=none smtp.client-ip=65.109.113.108 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=alien8.de Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=alien8.de Received: from localhost (localhost.localdomain [127.0.0.1]) by mail.alien8.de (SuperMail on ZX Spectrum 128k) with ESMTP id 0327840E00C5; Wed, 31 Jan 2024 09:30:18 +0000 (UTC) X-Virus-Scanned: Debian amavisd-new at mail.alien8.de Authentication-Results: mail.alien8.de (amavisd-new); dkim=pass (4096-bit key) header.d=alien8.de Received: from mail.alien8.de ([127.0.0.1]) by localhost (mail.alien8.de [127.0.0.1]) (amavisd-new, port 10026) with ESMTP id s-UgUl8KYLm8; Wed, 31 Jan 2024 09:30:16 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=alien8.de; s=alien8; t=1706693415; bh=r2DcM4ro+qsysihnxyBJGhyOPymf2yk6oBbpEdllaa0=; h=Date:From:To:Cc:Subject:References:In-Reply-To:From; b=BI+GR4Bj7fdTu0/S9ol+YgYAt0RK7PFx2iM963t17eHrJTwzJQCfzG7UXy9CXuZf1 PwldErDu3oKQaLUtO82oAVq6+jOBblBG7D5fjcDzInWveqnSzcIo1xAkANVGeGS1ki +JxvVZZuxZ4RF+ltMamgsePeF+bgrJmYCY4gUc2iCxSGiXLjLN7RaTmMEZSfuXijB9 BV/6lHgclTJQ6cNbBD8uBOcp+bzY4QCnxvQGLOSntcb481/NKa4Mmh90zw7foaokgd lcdeOr/Beo8y77zxhNKhnwGsZFt/hVOZuiomjBnxWnBuwU2XfxC/Fa/dmFFTahXmGH M+0WvEQYfX8zlt+/XT298P3pulbY6es94YHCRqxUO+6qvYHVvn6pxJhfuBjhsnnVyS +VlY+fauYYaORevg6fv6VjF0zBaKEzToTiiSNQW13FBfKFrUXaxOmgOHLEiY/tPmMY /rAtd030CkTitXwLmqQ99EbVESF4JHRDlKbEaIkCy7msta5Kn9gwcoXrI7MFiX/tnz r0BCazYpItueZWMsw/KdjrpNgjl/4MSWq+aLktLSvbOV8S1jKEFyWXVnAC68fH6vnA fIdjt9v5ntQoWKUphjQ6qzOuSUgEtrX4d2iWt0NxiTZnzUmtMgFGdYnRf0x5NN1EjY M+MBm8Sb2v4q5KVIonf7FVO4= Received: from zn.tnic (pd953033e.dip0.t-ipconnect.de [217.83.3.62]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange ECDHE (P-256) server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail.alien8.de (SuperMail on ZX Spectrum 128k) with ESMTPSA id AA30140E0177; Wed, 31 Jan 2024 09:29:57 +0000 (UTC) Date: Wed, 31 Jan 2024 10:29:52 +0100 From: Borislav Petkov To: Ard Biesheuvel Cc: Ard Biesheuvel , linux-kernel@vger.kernel.org, Kevin Loughlin , Tom Lendacky , Dionna Glaze , Thomas Gleixner , Ingo Molnar , Dave Hansen , Andy Lutomirski , Arnd Bergmann , Nathan Chancellor , Nick Desaulniers , Justin Stitt , Kees Cook , Brian Gerst , linux-arch@vger.kernel.org, llvm@lists.linux.dev Subject: Re: [PATCH v3 02/19] x86/boot: Move mem_encrypt= parsing to the decompressor Message-ID: <20240131092952.GCZboTECip8DbWtYtz@fat_crate.local> References: <20240129180502.4069817-21-ardb+git@google.com> <20240129180502.4069817-23-ardb+git@google.com> <20240131083511.GIZboGP8jPIrUZA8DF@fat_crate.local> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Disposition: inline In-Reply-To: On Wed, Jan 31, 2024 at 10:12:13AM +0100, Ard Biesheuvel wrote: > The reason we need two flags is because there is no default value to > use when the command line param is absent. I think absent means memory encryption disabled like with every other option which is not present... > There is CONFIG_AMD_MEM_ENCRYPT_ACTIVE_BY_DEFAULT but that one is AMD .. yes, and I'm thinking that it is time we kill this. I don't think anything uses it. It was meant well at the time. Let's wait for Tom to wake up first, though, as he might have some objections... Thx. -- Regards/Gruss, Boris. https://people.kernel.org/tglx/notes-about-netiquette