Received: by 2002:ab2:3141:0:b0:1ed:23cc:44d1 with SMTP id i1csp495837lqg; Fri, 1 Mar 2024 11:17:39 -0800 (PST) X-Forwarded-Encrypted: i=3; AJvYcCUb79B91QTqYxAKX5LjuAavv0/01Z0Xr76j77skHGw2N0yfrKWpuJEyoI+0mqWlcTY1VtMJEuJqJKxGAqCr1YAl6XgQfQMc8gfTOxnbmA== X-Google-Smtp-Source: AGHT+IGksuJTIGIshtOx3OwI/KADF8Hs/PuZSz+E0nw/rih6WLCh+XyFRgkH9EJgVHKaQ2335129 X-Received: by 2002:a17:90a:d344:b0:29a:8398:b0d6 with SMTP id i4-20020a17090ad34400b0029a8398b0d6mr2703963pjx.9.1709320658710; Fri, 01 Mar 2024 11:17:38 -0800 (PST) ARC-Seal: i=2; a=rsa-sha256; t=1709320658; cv=pass; d=google.com; s=arc-20160816; b=0CjtPtv/lqZmLp40dzAaklefjWA/O7uY4BYQVEPlajoAWMEJlmh29FCAjJ1p91oMbr oH0Bl+w3FXQq7uk1RwQvMzDC/qmM+lpdYjm0LTbKvz/fsyIJfPEFRdrFzMOyDw6QJDBk tPp5n320Yxb7Se4b/CNGErGcnQ9okEP6vsbCq2sWIHJimQ5S+9Wx5DjGPuS4Xmv4dTbs XG2RZ0Sq/qow+5PlY6sa4D2U/bTooEOHj3+2F0xkr2+JzbFnej2hWzFI4kRuaSODjgd2 Fn5cm/sm2z+vaZZ53CyYKulI6xUL0XYy6J2sGG2kuIcikx32oq4KsRE8uNoubkEOk7Ox 6a5g== ARC-Message-Signature: i=2; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=in-reply-to:content-disposition:mime-version:list-unsubscribe :list-subscribe:list-id:precedence:references:message-id:subject:cc :to:from:date:dkim-signature; bh=sd/nD7Yx33s4fZwmlkzXtyIVaIXVfPoDtiJXjkBlQOM=; fh=P9FZDZWaQO629a0BbHAoZYKMhxyRaUt1DysaRvvGFuE=; b=rd9WbFK2YExuR/5DOcXyDDLzKy1/Q7F8XpJ51DSxsHmBHSCRBo1NgJMPRiyblDCI0i BvYCJ49KHvHP5MSJ8Z9ozGlAYMRBdKeNK+WhLITjCIA2xx6l9o9vijAh5wneIUJDFKq1 Gv4RVGOdHDHp2satfRAOmhCj10cvrrLgEx/aH5kVwvjjSzOFZhSX47GorzhwnE58h74a BRyI4YyeZw1uZicztxluP6vasFjmP3kgintvMsFCqoTtwBm6FYSi8TcBfIBUyZs2057n yQjf+eAMmCpuvX/v4if1a6DG0bcn/27efngtKrR2nJzHUHt92/197OAMMQwIIez92xbc mf+w==; dara=google.com ARC-Authentication-Results: i=2; mx.google.com; dkim=pass header.i=@alien8.de header.s=alien8 header.b="VO1Lo/Y1"; arc=pass (i=1 spf=pass spfdomain=alien8.de dkim=pass dkdomain=alien8.de dmarc=pass fromdomain=alien8.de); spf=pass (google.com: domain of linux-kernel+bounces-89005-linux.lists.archive=gmail.com@vger.kernel.org designates 2604:1380:45e3:2400::1 as permitted sender) smtp.mailfrom="linux-kernel+bounces-89005-linux.lists.archive=gmail.com@vger.kernel.org"; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=alien8.de Return-Path: Received: from sv.mirrors.kernel.org (sv.mirrors.kernel.org. [2604:1380:45e3:2400::1]) by mx.google.com with ESMTPS id qd6-20020a17090b3cc600b0029acb1fa197si4301311pjb.151.2024.03.01.11.17.38 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 01 Mar 2024 11:17:38 -0800 (PST) Received-SPF: pass (google.com: domain of linux-kernel+bounces-89005-linux.lists.archive=gmail.com@vger.kernel.org designates 2604:1380:45e3:2400::1 as permitted sender) client-ip=2604:1380:45e3:2400::1; Authentication-Results: mx.google.com; dkim=pass header.i=@alien8.de header.s=alien8 header.b="VO1Lo/Y1"; arc=pass (i=1 spf=pass spfdomain=alien8.de dkim=pass dkdomain=alien8.de dmarc=pass fromdomain=alien8.de); spf=pass (google.com: domain of linux-kernel+bounces-89005-linux.lists.archive=gmail.com@vger.kernel.org designates 2604:1380:45e3:2400::1 as permitted sender) smtp.mailfrom="linux-kernel+bounces-89005-linux.lists.archive=gmail.com@vger.kernel.org"; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=alien8.de Received: from smtp.subspace.kernel.org (wormhole.subspace.kernel.org [52.25.139.140]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by sv.mirrors.kernel.org (Postfix) with ESMTPS id 3CFD828ABEC for ; Fri, 1 Mar 2024 19:17:11 +0000 (UTC) Received: from localhost.localdomain (localhost.localdomain [127.0.0.1]) by smtp.subspace.kernel.org (Postfix) with ESMTP id B8B333A1B0; Fri, 1 Mar 2024 19:17:06 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; dkim=pass (4096-bit key) header.d=alien8.de header.i=@alien8.de header.b="VO1Lo/Y1" Received: from mail.alien8.de (mail.alien8.de [65.109.113.108]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id E093039AEA for ; Fri, 1 Mar 2024 19:17:03 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=65.109.113.108 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1709320625; cv=none; b=axOaMCdFNfOBRUVKrxu7pe57IquoCbwIcg/IvXLuFHNlLUQit2U8fCwaihui/EBTGbVE3ewAQ97A4O7L5pgCpN3zbpfMslDIc/2uyPCLZkr/3nNCcznXyzBjseadwJTogD4QKsLrF98L8RKUNe8mtg0B2vw6H0kJq60SLZjIZz8= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1709320625; c=relaxed/simple; bh=dEmjzPDrT+npTyMci1PwxN3F1Q+kk+yxzW8fa60q1AU=; h=Date:From:To:Cc:Subject:Message-ID:References:MIME-Version: Content-Type:Content-Disposition:In-Reply-To; b=WWiAu+Kb67OWGQX+HzzkbuG/XZrkcbW8JWehxFLTy59X2ACNCvPlGNSpBuMqPQD4OX9dzszDgIJxDDFdu0KGnHSbOkp+g7reMU7FufJ/9A6v6yDLpN5tOCzLkL9P8jRIAm953KdSK0T0DvGzvKpSwTg8Y1b4cUQzh9HaIr2stT8= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=alien8.de; spf=pass smtp.mailfrom=alien8.de; dkim=pass (4096-bit key) header.d=alien8.de header.i=@alien8.de header.b=VO1Lo/Y1; arc=none smtp.client-ip=65.109.113.108 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=alien8.de Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=alien8.de Received: from localhost (localhost.localdomain [127.0.0.1]) by mail.alien8.de (SuperMail on ZX Spectrum 128k) with ESMTP id 6CA6A40E0196; Fri, 1 Mar 2024 19:17:01 +0000 (UTC) X-Virus-Scanned: Debian amavisd-new at mail.alien8.de Authentication-Results: mail.alien8.de (amavisd-new); dkim=pass (4096-bit key) header.d=alien8.de Received: from mail.alien8.de ([127.0.0.1]) by localhost (mail.alien8.de [127.0.0.1]) (amavisd-new, port 10026) with ESMTP id 5jYA0sa8vCA5; Fri, 1 Mar 2024 19:16:59 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=alien8.de; s=alien8; t=1709320619; bh=sd/nD7Yx33s4fZwmlkzXtyIVaIXVfPoDtiJXjkBlQOM=; h=Date:From:To:Cc:Subject:References:In-Reply-To:From; b=VO1Lo/Y1GhJsKcSv6cC5FTu5R1YH02Ll27aXZ2PMSU6OFOWh9TJsU7z5Zh8ylBqKc C0vZOh/IDM1NWm7M7F/7lS3WNom7WiGQHz0BEB1UPjhLAlJ9s5Ao5uRfsH2O38duS8 a3MusfPakfDxTCku6NUy66pOvGm0TQZi5Glw6CGgKa3dF8grfZh+3InDS/6G8Qrc7h l2CT5qPekiCSwJKa+Bzr72jnEZchbNb7+lJIXSlTxzH9q4uQSLzSR+bpYDYfX3sKDf 7DrQcxXOwhBS2ypNkXZRij+I+llThaeIqfdedDNRP3bGI1mR5P5fpzJ2PKSd3T/QIT CCfpZGswpW9YsTTzNQYQemAzgmIT8Hxy1GuhHs5Vppnian1fkNQq5N0OnDVitHZR54 HpqOWCGveg1yS0IMLA8FnJFKffnfUh65B5lysexEm0VKECdoGCj+u9tXEYCKb7BAqi /u0MHsEWzEDiFoN9tCNZzl6uc2W0pw7ypw5Wv7D5Rzkm/rQCV+b1LWqi9Csf33pBRq fvGwbq58w4lpRtQ/Nxk7HxibyHHdMcKQ5D1joAQa6Mc4qQMiokDbb88mFRu+BiijSO 5KJ2dgPXJ2oym4vP2uofOLtdgfo8ihgWTzEr7reGsFsk0wEPACEWCL2zWlMCpOJd8o DKJjXwXg78j2X5x0Tsf+DKa8= Received: from zn.tnic (pd953021b.dip0.t-ipconnect.de [217.83.2.27]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange ECDHE (P-256) server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail.alien8.de (SuperMail on ZX Spectrum 128k) with ESMTPSA id DDEAD40E00B2; Fri, 1 Mar 2024 19:16:47 +0000 (UTC) Date: Fri, 1 Mar 2024 20:16:40 +0100 From: Borislav Petkov To: Ard Biesheuvel Cc: linux-kernel@vger.kernel.org, Ard Biesheuvel , Kevin Loughlin , Tom Lendacky , Dionna Glaze , Thomas Gleixner , Ingo Molnar , Dave Hansen , Andy Lutomirski , Brian Gerst Subject: Re: [PATCH v7 6/9] x86/boot: Move mem_encrypt= parsing to the decompressor Message-ID: <20240301191640.GNZeIpmAU3iM1EIg4S@fat_crate.local> References: <20240227151907.387873-11-ardb+git@google.com> <20240227151907.387873-17-ardb+git@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Disposition: inline In-Reply-To: <20240227151907.387873-17-ardb+git@google.com> On Tue, Feb 27, 2024 at 04:19:14PM +0100, Ard Biesheuvel wrote: > diff --git a/arch/x86/include/uapi/asm/bootparam.h b/arch/x86/include/uapi/asm/bootparam.h > index 01d19fc22346..eeea058cf602 100644 > --- a/arch/x86/include/uapi/asm/bootparam.h > +++ b/arch/x86/include/uapi/asm/bootparam.h > @@ -38,6 +38,7 @@ > #define XLF_EFI_KEXEC (1<<4) > #define XLF_5LEVEL (1<<5) > #define XLF_5LEVEL_ENABLED (1<<6) > +#define XLF_MEM_ENCRYPTION (1<<7) Needs documenting in Documentation/arch/x86/boot.rst. And yes, those 5LEVEL things are not documented either but I'm even questioning the justification for their existence. We'll see... Thx. -- Regards/Gruss, Boris. https://people.kernel.org/tglx/notes-about-netiquette