mirror of
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
synced 2026-09-18 23:09:29 +02:00
pKVM does support memory encryption, expose that to the rest of the kernel through cc_platform_has() At the moment, all devices inside the guest are emulated which requires its memory to be shared back to the host (decrypted), so set force_dma_unencrypted() to always return true. Although, typically pKVM guests rely on restricted-dma-pools to bounce traffic, with this change, it is possible to solely rely on the default SWIOTLB for that (assuming the appropriate size is set from the command line) Signed-off-by: Mostafa Saleh <smostafa@google.com> Reviewed-by: Catalin Marinas <catalin.marinas@arm.com> Tested-by: Aneesh Kumar K.V (Arm) <aneesh.kumar@kernel.org> Signed-off-by: Will Deacon <will@kernel.org>
39 lines
1.0 KiB
C
39 lines
1.0 KiB
C
/* SPDX-License-Identifier: GPL-2.0-only */
|
|
#ifndef __ASM_MEM_ENCRYPT_H
|
|
#define __ASM_MEM_ENCRYPT_H
|
|
|
|
#include <asm/hypervisor.h>
|
|
#include <asm/rsi.h>
|
|
|
|
struct device;
|
|
|
|
struct arm64_mem_crypt_ops {
|
|
int (*encrypt)(unsigned long addr, int numpages);
|
|
int (*decrypt)(unsigned long addr, int numpages);
|
|
};
|
|
|
|
int arm64_mem_crypt_ops_register(const struct arm64_mem_crypt_ops *ops);
|
|
|
|
int set_memory_encrypted(unsigned long addr, int numpages);
|
|
int set_memory_decrypted(unsigned long addr, int numpages);
|
|
|
|
int realm_register_memory_enc_ops(void);
|
|
|
|
static inline bool force_dma_unencrypted(struct device *dev)
|
|
{
|
|
return is_realm_world() || is_protected_kvm_guest();
|
|
}
|
|
|
|
/*
|
|
* For Arm CCA guests, canonical addresses are "encrypted", so no changes
|
|
* required for dma_addr_encrypted().
|
|
* The unencrypted DMA buffers must be accessed via the unprotected IPA,
|
|
* "top IPA bit" set.
|
|
*/
|
|
#define dma_addr_unencrypted(x) ((x) | PROT_NS_SHARED)
|
|
|
|
/* Clear the "top" IPA bit while converting back */
|
|
#define dma_addr_canonical(x) ((x) & ~PROT_NS_SHARED)
|
|
|
|
#endif /* __ASM_MEM_ENCRYPT_H */
|