From: Srish Srinivasan <ssrish@linux.ibm.com>
To: nayna <nayna@imap.linux.ibm.com>
Cc: linux-integrity@vger.kernel.org, keyrings@vger.kernel.org,
linuxppc-dev@lists.ozlabs.org, maddy@linux.ibm.com,
mpe@ellerman.id.au, npiggin@gmail.com,
christophe.leroy@csgroup.eu,
James.Bottomley@hansenpartnership.com, jarkko@kernel.org,
zohar@linux.ibm.com, linux-kernel@vger.kernel.org,
linux-security-module@vger.kernel.org, nayna@linux.ibm.com,
rnsastry@linux.ibm.com
Subject: Re: [PATCH v2 00/10] Extend PKWM to support user-created wrapping keys
Date: Tue, 22 Sep 2026 00:56:29 +0530 [thread overview]
Message-ID: <bcd5e2e9-5000-44a8-9e7d-ebb4cc3e02d9@linux.ibm.com> (raw)
In-Reply-To: <b133937fab3f5cd7203d8b48824a6e0e@imap.linux.ibm.com>
Hi Nayna,
On 9/21/26 7:09 PM, nayna wrote:
> On 2026-08-31 07:17, Srish Srinivasan wrote:
>> The PKWM trusted source currently uses a single default wrapping key per
>> LPAR. This key is created during trusted source initialization, and all
>> trusted keys backed by PKWM are sealed and unsealed using it.
>>
>> Recent versions of PKWM allow users to create and manage their own
>> wrapping
>> keys through a set of lifecycle operations. This patch series brings
>> these
>> PKWM capabilities into the kernel, allowing users to create, manage, and
>> select wrapping keys for sealing and unsealing their trusted keys,
>> rather
>> than requiring all trusted keys to use the default wrapping key.
>>
>> This series adds support for user-created wrapping keys to PLPKS and
>> PKWM.
>> It begins with seven preparatory cleanup and bug-fix patches that
>> improve
>> error handling and type consistency, clarify macro naming, prevent
>> unsupported capabilities from being exposed through sysfs, and update
>> the
>> documentation and MAINTAINERS entry.
>>
>> The final three patches add the required hcalls, enable wrapping key
>> selection by label for PKWM-backed trusted keys, and provide a sysfs
>> interface for managing wrapping keys from userspace.
>
> Thanks Srish for your work.
>
> It would be cleaner to split these into two separate series: one for
> the cleanups and one for the user-created wrapping keys management
> feature. This makes each series easier to review and test. Also, this
> allows cleanup patches to be accepted even if the wrapping key
> management feature is still under review.
Sure, that makes sense.
Will split them up into two separate series.
>
> Thanks & Regards,
> - Nayna
Thanks,
Srish.
prev parent reply other threads:[~2026-09-21 19:26 UTC|newest]
Thread overview: 22+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-31 11:17 Srish Srinivasan
2026-08-31 11:17 ` [PATCH v2 01/10] pseries/plpks: update PKS documentation and maintainer entry Srish Srinivasan
2026-09-04 6:10 ` R Nageswara Sastry
2026-08-31 11:17 ` [PATCH v2 02/10] pseries/plpks: fix error handling in plpks_read_var() Srish Srinivasan
2026-09-04 6:10 ` R Nageswara Sastry
2026-08-31 11:17 ` [PATCH v2 03/10] pseries/plpks: improve type consistency and parameter validation Srish Srinivasan
2026-09-04 6:11 ` R Nageswara Sastry
2026-08-31 11:17 ` [PATCH v2 04/10] keys/trusted_keys: propagate wrapping key generation errors Srish Srinivasan
2026-09-04 6:12 ` R Nageswara Sastry
2026-08-31 11:17 ` [PATCH v2 05/10] pseries/plpks: rename the default wrapping key macro Srish Srinivasan
2026-09-04 6:13 ` R Nageswara Sastry
2026-08-31 11:17 ` [PATCH v2 06/10] pseries/plpks: fix self-reference in plpks_var initializer Srish Srinivasan
2026-09-04 6:14 ` R Nageswara Sastry
2026-08-31 11:17 ` [PATCH v2 07/10] pseries/plpks: hide wrapping_features when unsupported Srish Srinivasan
2026-09-04 6:16 ` R Nageswara Sastry
2026-08-31 11:17 ` [PATCH v2 08/10] pseries/plpks: add HCALLs for PKWM wrapping key life cycle management Srish Srinivasan
2026-09-04 6:16 ` R Nageswara Sastry
2026-08-31 11:17 ` [PATCH v2 09/10] keys/trusted_keys: enable PKWM wrapping key selection by label Srish Srinivasan
2026-09-04 6:17 ` R Nageswara Sastry
2026-08-31 11:17 ` [PATCH v2 10/10] pseries/plpks/wrapkey: expose PKWM wrapping key management to userspace via sysfs Srish Srinivasan
2026-09-04 6:19 ` R Nageswara Sastry
[not found] ` <b133937fab3f5cd7203d8b48824a6e0e@imap.linux.ibm.com>
2026-09-21 19:26 ` Srish Srinivasan [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=bcd5e2e9-5000-44a8-9e7d-ebb4cc3e02d9@linux.ibm.com \
--to=ssrish@linux.ibm.com \
--cc=James.Bottomley@hansenpartnership.com \
--cc=christophe.leroy@csgroup.eu \
--cc=jarkko@kernel.org \
--cc=keyrings@vger.kernel.org \
--cc=linux-integrity@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-security-module@vger.kernel.org \
--cc=linuxppc-dev@lists.ozlabs.org \
--cc=maddy@linux.ibm.com \
--cc=mpe@ellerman.id.au \
--cc=nayna@imap.linux.ibm.com \
--cc=nayna@linux.ibm.com \
--cc=npiggin@gmail.com \
--cc=rnsastry@linux.ibm.com \
--cc=zohar@linux.ibm.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®