From: James Bottomley <James.Bottomley-d9PhHud1JfjCXq6kfMZ53/egYHeGw8Jk@public.gmane.org>
To: Jason Gunthorpe
<jgunthorpe-ePGOBjL8dl3ta4EC/59zMFaTQe2KTcn/@public.gmane.org>
Cc: tpmdd-devel-5NWGOfrQmneRv+LV9MX5uipxlwaOVQ5f@public.gmane.org
Subject: Re: [PATCH] tpm-emulator: add a TPM emulator pass through
Date: Mon, 09 Jan 2017 09:04:05 -0800 [thread overview]
Message-ID: <1483981445.2398.4.camel@HansenPartnership.com> (raw)
In-Reply-To: <20170109165416.GA13960-ePGOBjL8dl3ta4EC/59zMFaTQe2KTcn/@public.gmane.org>
On Mon, 2017-01-09 at 09:54 -0700, Jason Gunthorpe wrote:
> On Mon, Jan 09, 2017 at 08:23:02AM -0800, James Bottomley wrote:
> > On Mon, 2017-01-09 at 08:49 -0700, Jason Gunthorpe wrote:
> > > On Sun, Jan 08, 2017 at 04:58:33PM -0800, James Bottomley wrote:
> > > > I noticed, while playing around with the kernel based resource
> > > > manager, that it's very advantageous to have an emulated TPM
> > > > device to test now that I'm playing with startup sequences and
> > > > TPM ownership.
> > > >
> > > > This is an emulator pass through. It connects an existing
> > > > emulator running on the platform (expected to be the MS
> > > > Simulator available from
> > > > https://sourceforge.net/projects/ibmswtpm2/) and adds it
> > > > as an in-kernel device, meaning you can exercise the kernel TPM
> > > > interface from either inside the kernel or using the device
> > > > node.
> > > >
> > > > The tpm-emulator simply connects to the command socket of the
> > > > MS simulator (on localhost:2321) and proxies TPM commands. The
> > > > destination and port are settable as module parameters meaning
> > > > that the TPM emulator doesn't have to be running locally.
> > >
> > > What is wrong with using drivers/char/tpm/tpm_vtpm_proxy.c and
> > > doing the socket connection in userspace?
> >
> > Simplicity, mostly. It's a tiny driver to proxy the network
> > protocol directly, meaning it's much easier to set up.
>
> Not sure I see it, surely running a program in userspace is simpler
> than patching the kernel?
Heh, is that a serious question to a kernel developer? If the program
actually existed, sure, but does it?
> > Plus if you're running smoke tests in a VM you can actually run the
> > emulator in the host without any additional code in the guest.
>
> I haven't tried it, but qemu has TPM passthrough support, so it
> should be able to pass /dev/tpm1, created by vtpm through to the
> guest. AFAIK this should support all existing guests without a custom
> kernel or messing with module options.
>
> Honestly, I'd rather see the emulator community get behind vtpm..
OK, so work out how to do it and post the instructions and we can see
what's easier for users. Opinions can always change. I didn't really
see a need to use an emulated TPM in the kernel until Jarkko's smoke
tests caused a DA lockout on my physical TPM at which point not
impacting all my other TPM based stuff while playing with the kernel
suddenly seemed important.
James
------------------------------------------------------------------------------
Developer Access Program for Intel Xeon Phi Processors
Access to Intel Xeon Phi processor-based developer platforms.
With one year of Intel Parallel Studio XE.
Training and support from Colfax.
Order your platform today. http://sdm.link/xeonphi
next prev parent reply other threads:[~2017-01-09 17:04 UTC|newest]
Thread overview: 20+ messages / expand[flat|nested] mbox.gz Atom feed top
2017-01-09 0:58 [PATCH] tpm-emulator: add a TPM emulator pass through James Bottomley
[not found] ` <1483923513.2644.1.camel-d9PhHud1JfjCXq6kfMZ53/egYHeGw8Jk@public.gmane.org>
2017-01-09 15:49 ` Jason Gunthorpe
[not found] ` <20170109154945.GA28023-ePGOBjL8dl3ta4EC/59zMFaTQe2KTcn/@public.gmane.org>
2017-01-09 16:23 ` James Bottomley
[not found] ` <1483978982.2448.7.camel-d9PhHud1JfjCXq6kfMZ53/egYHeGw8Jk@public.gmane.org>
2017-01-09 16:54 ` Jason Gunthorpe
[not found] ` <20170109165416.GA13960-ePGOBjL8dl3ta4EC/59zMFaTQe2KTcn/@public.gmane.org>
2017-01-09 17:04 ` James Bottomley [this message]
[not found] ` <1483981445.2398.4.camel-d9PhHud1JfjCXq6kfMZ53/egYHeGw8Jk@public.gmane.org>
2017-01-09 17:14 ` Jason Gunthorpe
[not found] ` <20170109171430.GA18648-ePGOBjL8dl3ta4EC/59zMFaTQe2KTcn/@public.gmane.org>
2017-01-09 18:03 ` Stefan Berger
[not found] ` <7bef4616-cd69-2798-fc1f-f7eee2fb8c98-23VcF4HTsmIX0ybBhKVfKdBPR1lH4CV8@public.gmane.org>
2017-01-09 18:24 ` James Bottomley
[not found] ` <1483986287.2398.5.camel-d9PhHud1JfjCXq6kfMZ53/egYHeGw8Jk@public.gmane.org>
2017-01-09 18:41 ` Stefan Berger
[not found] ` <1e9d8540-63b9-e6fe-d643-30705030d49c-23VcF4HTsmIX0ybBhKVfKdBPR1lH4CV8@public.gmane.org>
2017-01-09 18:51 ` James Bottomley
[not found] ` <1483987877.2398.9.camel-d9PhHud1JfjCXq6kfMZ53/egYHeGw8Jk@public.gmane.org>
2017-01-09 18:52 ` Stefan Berger
[not found] ` <fdbd3976-e457-f17e-faed-e40e749f5a21-23VcF4HTsmIX0ybBhKVfKdBPR1lH4CV8@public.gmane.org>
2017-01-09 19:18 ` James Bottomley
[not found] ` <1483989503.2398.13.camel-d9PhHud1JfjCXq6kfMZ53/egYHeGw8Jk@public.gmane.org>
2017-01-09 19:37 ` Stefan Berger
[not found] ` <c59ebdec-d1e1-b8d6-53b2-81973ea3e64f-23VcF4HTsmIX0ybBhKVfKdBPR1lH4CV8@public.gmane.org>
2017-01-09 20:06 ` James Bottomley
[not found] ` <1483992413.2398.16.camel-d9PhHud1JfjCXq6kfMZ53/egYHeGw8Jk@public.gmane.org>
2017-01-15 19:18 ` Stefan Berger
[not found] ` <7fa906c5-081f-f095-6730-dfcb35cda661-23VcF4HTsmIX0ybBhKVfKdBPR1lH4CV8@public.gmane.org>
2017-01-15 19:40 ` James Bottomley
[not found] ` <1484509202.2405.18.camel-d9PhHud1JfjCXq6kfMZ53/egYHeGw8Jk@public.gmane.org>
2017-01-16 2:25 ` Stefan Berger
[not found] ` <2b98d20d-3321-a986-f4f5-a0bd9add6244-23VcF4HTsmIX0ybBhKVfKdBPR1lH4CV8@public.gmane.org>
2017-01-16 6:37 ` James Bottomley
2017-01-10 19:24 ` [PATCH] tpm-emulator: add a TPM emulator pass through -> DA lockout Ken Goldman
2017-01-09 23:10 ` [PATCH] tpm-emulator: add a TPM emulator pass through Jarkko Sakkinen
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=1483981445.2398.4.camel@HansenPartnership.com \
--to=james.bottomley-d9phhud1jfjcxq6kfmz53/egyhegw8jk@public.gmane.org \
--cc=jgunthorpe-ePGOBjL8dl3ta4EC/59zMFaTQe2KTcn/@public.gmane.org \
--cc=tpmdd-devel-5NWGOfrQmneRv+LV9MX5uipxlwaOVQ5f@public.gmane.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.