On 22/08/2018 22:11, Brijesh Singh wrote: > > Yes, this is one of approach I have in mind. It will avoid splitting > the larger pages; I am thinking that early in boot code we can lookup > for this special section and decrypt it in-place and probably maps with > C=0. Only downside, it will increase data section footprint a bit > because we need to align this section to PM_SIZE. If you can ensure it doesn't span a PMD, maybe it does not need to be aligned; you could establish a C=0 mapping of the whole 2M around it. Paolo