Expensive and permanently fractures the direct map.
I'm struggling to figure out why the direct map is even touched here.
I think Sathya did it this way because the TD interface requires a
physical address.
Why not just use a vmalloc area mapping? You really just need *a*
decrypted mapping to the page. You don't need to make *every* mapping
to the page decrypted.
Yes it would be possible to use vmap() on the page and only set the vmap
encrypted by passing the right flags directly.
That would avoid breaking up the direct mapping.
-Andi