mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Srish Srinivasan <ssrish@linux.ibm.com>
To: nayna <nayna@imap.linux.ibm.com>
Cc: linux-integrity@vger.kernel.org, keyrings@vger.kernel.org,
	linuxppc-dev@lists.ozlabs.org, maddy@linux.ibm.com,
	mpe@ellerman.id.au, npiggin@gmail.com,
	christophe.leroy@csgroup.eu,
	James.Bottomley@hansenpartnership.com, jarkko@kernel.org,
	zohar@linux.ibm.com, linux-kernel@vger.kernel.org,
	linux-security-module@vger.kernel.org, nayna@linux.ibm.com,
	rnsastry@linux.ibm.com
Subject: Re: [PATCH v2 00/10] Extend PKWM to support user-created wrapping keys
Date: Tue, 22 Sep 2026 00:56:29 +0530	[thread overview]
Message-ID: <bcd5e2e9-5000-44a8-9e7d-ebb4cc3e02d9@linux.ibm.com> (raw)
In-Reply-To: <b133937fab3f5cd7203d8b48824a6e0e@imap.linux.ibm.com>

Hi Nayna,

On 9/21/26 7:09 PM, nayna wrote:
> On 2026-08-31 07:17, Srish Srinivasan wrote:
>> The PKWM trusted source currently uses a single default wrapping key per
>> LPAR. This key is created during trusted source initialization, and all
>> trusted keys backed by PKWM are sealed and unsealed using it.
>>
>> Recent versions of PKWM allow users to create and manage their own 
>> wrapping
>> keys through a set of lifecycle operations. This patch series brings 
>> these
>> PKWM capabilities into the kernel, allowing users to create, manage, and
>> select wrapping keys for sealing and unsealing their trusted keys, 
>> rather
>> than requiring all trusted keys to use the default wrapping key.
>>
>> This series adds support for user-created wrapping keys to PLPKS and 
>> PKWM.
>> It begins with seven preparatory cleanup and bug-fix patches that 
>> improve
>> error handling and type consistency, clarify macro naming, prevent
>> unsupported capabilities from being exposed through sysfs, and update 
>> the
>> documentation and MAINTAINERS entry.
>>
>> The final three patches add the required hcalls, enable wrapping key
>> selection by label for PKWM-backed trusted keys, and provide a sysfs
>> interface for managing wrapping keys from userspace.
>
> Thanks Srish for your work.
>
> It would be cleaner to split these into two separate series: one for 
> the cleanups and one for the user-created wrapping keys management 
> feature. This makes each series easier to review and test. Also, this 
> allows cleanup patches to be accepted even if the wrapping key 
> management feature is still under review.


Sure, that makes sense.
Will split them up into two separate series.


>
> Thanks & Regards,
>    - Nayna

Thanks,
Srish.

      parent reply	other threads:[~2026-09-21 19:26 UTC|newest]

Thread overview: 22+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-31 11:17 Srish Srinivasan
2026-08-31 11:17 ` [PATCH v2 01/10] pseries/plpks: update PKS documentation and maintainer entry Srish Srinivasan
2026-09-04  6:10   ` R Nageswara Sastry
2026-08-31 11:17 ` [PATCH v2 02/10] pseries/plpks: fix error handling in plpks_read_var() Srish Srinivasan
2026-09-04  6:10   ` R Nageswara Sastry
2026-08-31 11:17 ` [PATCH v2 03/10] pseries/plpks: improve type consistency and parameter validation Srish Srinivasan
2026-09-04  6:11   ` R Nageswara Sastry
2026-08-31 11:17 ` [PATCH v2 04/10] keys/trusted_keys: propagate wrapping key generation errors Srish Srinivasan
2026-09-04  6:12   ` R Nageswara Sastry
2026-08-31 11:17 ` [PATCH v2 05/10] pseries/plpks: rename the default wrapping key macro Srish Srinivasan
2026-09-04  6:13   ` R Nageswara Sastry
2026-08-31 11:17 ` [PATCH v2 06/10] pseries/plpks: fix self-reference in plpks_var initializer Srish Srinivasan
2026-09-04  6:14   ` R Nageswara Sastry
2026-08-31 11:17 ` [PATCH v2 07/10] pseries/plpks: hide wrapping_features when unsupported Srish Srinivasan
2026-09-04  6:16   ` R Nageswara Sastry
2026-08-31 11:17 ` [PATCH v2 08/10] pseries/plpks: add HCALLs for PKWM wrapping key life cycle management Srish Srinivasan
2026-09-04  6:16   ` R Nageswara Sastry
2026-08-31 11:17 ` [PATCH v2 09/10] keys/trusted_keys: enable PKWM wrapping key selection by label Srish Srinivasan
2026-09-04  6:17   ` R Nageswara Sastry
2026-08-31 11:17 ` [PATCH v2 10/10] pseries/plpks/wrapkey: expose PKWM wrapping key management to userspace via sysfs Srish Srinivasan
2026-09-04  6:19   ` R Nageswara Sastry
     [not found] ` <b133937fab3f5cd7203d8b48824a6e0e@imap.linux.ibm.com>
2026-09-21 19:26   ` Srish Srinivasan [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=bcd5e2e9-5000-44a8-9e7d-ebb4cc3e02d9@linux.ibm.com \
    --to=ssrish@linux.ibm.com \
    --cc=James.Bottomley@hansenpartnership.com \
    --cc=christophe.leroy@csgroup.eu \
    --cc=jarkko@kernel.org \
    --cc=keyrings@vger.kernel.org \
    --cc=linux-integrity@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-security-module@vger.kernel.org \
    --cc=linuxppc-dev@lists.ozlabs.org \
    --cc=maddy@linux.ibm.com \
    --cc=mpe@ellerman.id.au \
    --cc=nayna@imap.linux.ibm.com \
    --cc=nayna@linux.ibm.com \
    --cc=npiggin@gmail.com \
    --cc=rnsastry@linux.ibm.com \
    --cc=zohar@linux.ibm.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®