From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-7.7 required=3.0 tests=BAYES_00,DKIM_SIGNED, DKIM_VALID,DKIM_VALID_AU,FREEMAIL_FORGED_FROMDOMAIN,FREEMAIL_FROM, HEADER_FROM_DIFFERENT_DOMAINS,MAILING_LIST_MULTI,MENTIONS_GIT_HOSTING, SPF_HELO_NONE,SPF_PASS,URIBL_BLOCKED autolearn=no autolearn_force=no version=3.4.0 Received: from mail.kernel.org (mail.kernel.org [198.145.29.99]) by smtp.lore.kernel.org (Postfix) with ESMTP id E81E2C433E0 for ; Tue, 30 Mar 2021 21:51:49 +0000 (UTC) Received: from vger.kernel.org (vger.kernel.org [23.128.96.18]) by mail.kernel.org (Postfix) with ESMTP id B3761619CA for ; Tue, 30 Mar 2021 21:51:49 +0000 (UTC) Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S232495AbhC3VvQ (ORCPT ); Tue, 30 Mar 2021 17:51:16 -0400 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:56610 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S230125AbhC3VvE (ORCPT ); Tue, 30 Mar 2021 17:51:04 -0400 Received: from mail-qv1-xf36.google.com (mail-qv1-xf36.google.com [IPv6:2607:f8b0:4864:20::f36]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id 67095C061574; Tue, 30 Mar 2021 14:51:04 -0700 (PDT) Received: by mail-qv1-xf36.google.com with SMTP id cx5so8961070qvb.10; Tue, 30 Mar 2021 14:51:04 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=+K4nfDlNqS+buaOaVq0AwqLIJ0qhfMJqcEYS+OVTapc=; b=NDqsZVY+29ySsRg/3HK1AA9ORV4ajVk3u617yrGmsZWxFWcoaAYGq23GczTy0umqTH zbXaf9OVWiu4k1LhyQJVkrAiM/MoA0COtEgwl/dMRGUTGnDkmq6gwsdcB771g4tFCljH kQ3GH6/35vFXENrtuus3SAZ08usNE50+792tG7PfsyK7dvTRmdQeq9MXS0tcx9T0WgYy Zsv1nC2/iKlh50dieaiECdA/DZTmSORJRjmK8233DGdyXd7o4kiI9iiTfuxcf38Rpxtt Q9Txi/rmBlh5W9mSla1tJWDeLLfKG0USMfQlMXWS74O2US11V9sk26jcukF5Q7gPj5kD 1IfQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=+K4nfDlNqS+buaOaVq0AwqLIJ0qhfMJqcEYS+OVTapc=; b=KSTZi/AMVFLr18G1q7C23TRYLo3xSiucZ7YkjnaK7etCb4N+R68cWroTmr6LEKUBki 10YY4A5ov7927g35oPJK+oUP17yMV74y647l52jZJCPWkiQpx7x9jKEAdzrw6JpsduOP weSVxTXOBWLR8/ivgCXtbBjrjZY2aOhQrbskWrac3OhGS1lS6g4lNjwAyt4Ad+8se5EW P5hsAv2meKfkyRn4RlcmhHUwAiDI/U+qzT2zbg2Y6oNrmr+VUV9B6y4fCEk/3ic/9dji AkUCg2KfBwMCYXmZztnh1flpY6fHZXWvwR9MDbBPkkGd7jsWFkwUcmLELAfqJWGerDq7 33Qw== X-Gm-Message-State: AOAM5304/aDWEgAG4NKcTpgHTzfusD5x7erYtevhwRcd2WIy/xm5OQYW F79lg9EOhly25ZkXcfIN3bX8FAkP6xX0uVSseME= X-Google-Smtp-Source: ABdhPJyslbdbjpfFB3Lq8Z40X1hr6APZEGUsaFpYs3kEAQ437pGTOonhltLSjPHd1MsDmKhxXgHtxg3plK2vT4EC3XE= X-Received: by 2002:ad4:57a5:: with SMTP id g5mr215200qvx.60.1617141063684; Tue, 30 Mar 2021 14:51:03 -0700 (PDT) MIME-Version: 1.0 References: In-Reply-To: From: Richard Weinberger Date: Tue, 30 Mar 2021 23:50:52 +0200 Message-ID: Subject: Re: [PATCH v1 0/3] KEYS: trusted: Introduce support for NXP CAAM-based trusted keys To: Ahmad Fatoum Cc: Jarkko Sakkinen , =?UTF-8?Q?Horia_Geant=C4=83?= , Mimi Zohar , Aymen Sghaier , Herbert Xu , "David S. Miller" , James Bottomley , kernel@pengutronix.de, David Howells , James Morris , "Serge E. Hallyn" , Steffen Trumtrar , Udit Agarwal , Jan Luebbe , David Gstir , Franck LENORMAND , Sumit Garg , linux-integrity@vger.kernel.org, keyrings@vger.kernel.org, Linux Crypto Mailing List , LKML , LSM Content-Type: text/plain; charset="UTF-8" Precedence: bulk List-ID: Ahmad, On Wed, Mar 17, 2021 at 3:08 PM Ahmad Fatoum wrote: > TABLE="0 $BLOCKS crypt $ALGO :32:trusted:$KEYNAME 0 $DEV 0 1 allow_discards" > echo $TABLE | dmsetup create mydev > echo $TABLE | dmsetup load mydev Do you also plan to add support for this to cryptsetup? David and I have added (rough) support for our CAAM/DCP based keyrings to cryptsetup: https://github.com/sigma-star/cryptsetup/tree/rw/plain I'm pretty sure with minimal changes it will work with your recent approach too. -- Thanks, //richard