Re: [PATCH] fuse: mark DAX VMA page protections as decrypted

"Gupta, Pankaj" <[email protected]>
Newsgroups dev.linux.lists.linux-coco,org.kernel.vger.linux-fsdevel,org.kernel.vger.linux-kernel
Message-ID <[email protected]>
>>> In confidential computing guest environments (such as AMD SEV-SNP or
>>> Intel TDX), direct memory access (DAX) mappings between the guest kernel
>>> and host-backed FUSE/virtiofs shared memory regions must be accessed
>>> using shared (decrypted) page protections.
>>>
>>> Modify fuse_dax_mmap() to apply pgprot_decrypted() to vma->vm_page_prot
>>> when establishing FUSE DAX memory mappings. This ensures guest page
>>> table entries for shared DAX buffers are explicitly marked as decrypted,
>>> preventing memory encryption faults when accessing host-shared DAX memory.
>>>
>>> Signed-off-by: Punit Salian <[email protected]>
>>> ---
>>>   fs/fuse/dax.c | 1 +
>>>   1 file changed, 1 insertion(+)
>>>
>>> diff --git a/fs/fuse/dax.c b/fs/fuse/dax.c
>>> index a15c464c8d19..00e316a7f805 100644
>>> --- a/fs/fuse/dax.c
>>> +++ b/fs/fuse/dax.c
>>> @@ -826,6 +826,7 @@ int fuse_dax_mmap(struct file *file, struct vm_area_struct *vma)
>>>          file_accessed(file);
>>>          vma->vm_ops = &fuse_dax_vm_ops;
>>>          vm_flags_set(vma, VM_MIXEDMAP | VM_HUGEPAGE);
>>> +       vma->vm_page_prot = pgprot_decrypted(vma->vm_page_prot);

For virtio-pmem on host with SEV support we addressed similar issue by 
marking FS DAX device memory decrypted in memremap_pages()

(commit 867400af90f1, "mm/memremap.c: map FS_DAX device memory as 
decrypted"), since the device memory

is mapped though the kernel address space there. For virtio-fs DAX we 
don't seem to have such a central location so

VMA level handling seems reasonable fix to me.

That said, I'm not entirely certain about all of the security 
implications in a CoCo environment, given that the host is generally 
considered untrusted

and virtio-fs involves sharing host-backed memory with the guest. Till 
we get some mechanism to access this memory as encrypted, we can have 
this support

with existing security practices for virtio-fs:

Acked-by: Pankaj Gupta <[email protected]>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.