Re: [PATCH v2 5/6] platform/x86: intel_tdx_attest: Add TDX Guest attestation interface driver

From: Andi Kleen
Date: Thu Jul 08 2021 - 20:38:47 EST



Expensive and permanently fractures the direct map.

I'm struggling to figure out why the direct map is even touched here.
I think Sathya did it this way because the TD interface requires a physical address.
Why not just use a vmalloc area mapping? You really just need *a*
decrypted mapping to the page. You don't need to make *every* mapping
to the page decrypted.

Yes it would be possible to use vmap() on the page and only set the vmap encrypted by passing the right flags directly.

That would avoid breaking up the direct mapping.


-Andi