From: jarkko.sakkinen@linux.intel.com (Jarkko Sakkinen)
To: linux-security-module@vger.kernel.org
Subject: [tpmdd-devel] [PATCH RESEND 3/3] tpm-chip: Export TPM device to user space even when startup failed
Date: Wed, 30 Aug 2017 14:07:48 +0300 [thread overview]
Message-ID: <20170830110721.edidi46sx2qgovzu@linux.intel.com> (raw)
In-Reply-To: <20170830123416.29117269@kitsune.suse.cz>
On Wed, Aug 30, 2017 at 12:34:16PM +0200, Michal Such?nek wrote:
> On Wed, 30 Aug 2017 13:20:02 +0300
> Jarkko Sakkinen <jarkko.sakkinen@linux.intel.com> wrote:
>
> > On Wed, Aug 30, 2017 at 01:15:10PM +0300, Jarkko Sakkinen wrote:
> > > On Tue, Aug 29, 2017 at 03:17:39PM +0200, Michal Such?nek wrote:
> > > > Hello,
> > > >
> > > > On Tue, 29 Aug 2017 15:55:09 +0300
> > > > Jarkko Sakkinen <jarkko.sakkinen@linux.intel.com> wrote:
> > > >
> > > > > On Mon, Aug 28, 2017 at 05:15:58PM +0000,
> > > > > Alexander.Steffen at infineon.com wrote:
> > > > > > But is that just because nobody bothered to implement the
> > > > > > necessary logic or for some other reason?
> > > > >
> > > > > We do not want user space to access broken hardware. It's a
> > > > > huge risk for system stability and potentially could be used
> > > > > for evil purposes.
> > > > >
> > > > > This is not going to mainline as it is not suitable for general
> > > > > consumption. You must use a patched kernel if you want this.
> > > > >
> > > > > /Jarkko
> > > > >
> > > >
> > > > It has been pointed out that userspace applications that use
> > > > direct IO access exist for the purpose. So using a kernel driver
> > > > is an improvement over that if the interface is otherwise sane.
> > > >
> > > > What do you expect is the potential for instability or evil use?
> > >
> > > By definition the use of broken hardware can have unpredictable
> > > effects. Use a patched kernel if you want to do it.
> > >
> > > /Jarkko
> >
> > I.e. too many unknown unknowns for mainline.
> >
> > I could consider a solution for the TPM error case on self-test that
> > allows only restricted subset of commands.
> >
> > The patch description did not go to *any* detail on how it is used so
> > practically it's unreviewable at this point. There's a big burder of
> > proof and now there's only hand waving.
> >
> Hello,
>
> there was a bug patched recently in which Linux was not sending the
> shutdown command on system shutdown. Presumably with this bug some TPMs
> consider being under attack and stop performing most functions.
> However, you should be able to read the log if this is implemented
> sanely. For that the TPM needs to be accessible.
>
> There are probably other cases when the TPM might be useless for system
> use but it might be useful to access it. For example, does Linux handle
> uninitialized TPMs?
>
> Thanks
>
> Michal
Agreed. I still think it would make sense to start with a limited subset
of TPM commands, not with all-command-allowed.
I guess Alexander should be able to propose such subset.
/Jarkko
--
To unsubscribe from this list: send the line "unsubscribe linux-security-module" in
the body of a message to majordomo at vger.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html
WARNING: multiple messages have this Message-ID (diff)
From: Jarkko Sakkinen <jarkko.sakkinen@linux.intel.com>
To: "Michal Suchánek" <msuchanek@suse.de>
Cc: Alexander.Steffen@infineon.com,
linux-security-module@vger.kernel.org,
tpmdd-devel@lists.sourceforge.net
Subject: Re: [tpmdd-devel] [PATCH RESEND 3/3] tpm-chip: Export TPM device to user space even when startup failed
Date: Wed, 30 Aug 2017 14:07:48 +0300 [thread overview]
Message-ID: <20170830110721.edidi46sx2qgovzu@linux.intel.com> (raw)
In-Reply-To: <20170830123416.29117269@kitsune.suse.cz>
On Wed, Aug 30, 2017 at 12:34:16PM +0200, Michal Suchánek wrote:
> On Wed, 30 Aug 2017 13:20:02 +0300
> Jarkko Sakkinen <jarkko.sakkinen@linux.intel.com> wrote:
>
> > On Wed, Aug 30, 2017 at 01:15:10PM +0300, Jarkko Sakkinen wrote:
> > > On Tue, Aug 29, 2017 at 03:17:39PM +0200, Michal Suchánek wrote:
> > > > Hello,
> > > >
> > > > On Tue, 29 Aug 2017 15:55:09 +0300
> > > > Jarkko Sakkinen <jarkko.sakkinen@linux.intel.com> wrote:
> > > >
> > > > > On Mon, Aug 28, 2017 at 05:15:58PM +0000,
> > > > > Alexander.Steffen@infineon.com wrote:
> > > > > > But is that just because nobody bothered to implement the
> > > > > > necessary logic or for some other reason?
> > > > >
> > > > > We do not want user space to access broken hardware. It's a
> > > > > huge risk for system stability and potentially could be used
> > > > > for evil purposes.
> > > > >
> > > > > This is not going to mainline as it is not suitable for general
> > > > > consumption. You must use a patched kernel if you want this.
> > > > >
> > > > > /Jarkko
> > > > >
> > > >
> > > > It has been pointed out that userspace applications that use
> > > > direct IO access exist for the purpose. So using a kernel driver
> > > > is an improvement over that if the interface is otherwise sane.
> > > >
> > > > What do you expect is the potential for instability or evil use?
> > >
> > > By definition the use of broken hardware can have unpredictable
> > > effects. Use a patched kernel if you want to do it.
> > >
> > > /Jarkko
> >
> > I.e. too many unknown unknowns for mainline.
> >
> > I could consider a solution for the TPM error case on self-test that
> > allows only restricted subset of commands.
> >
> > The patch description did not go to *any* detail on how it is used so
> > practically it's unreviewable at this point. There's a big burder of
> > proof and now there's only hand waving.
> >
> Hello,
>
> there was a bug patched recently in which Linux was not sending the
> shutdown command on system shutdown. Presumably with this bug some TPMs
> consider being under attack and stop performing most functions.
> However, you should be able to read the log if this is implemented
> sanely. For that the TPM needs to be accessible.
>
> There are probably other cases when the TPM might be useless for system
> use but it might be useful to access it. For example, does Linux handle
> uninitialized TPMs?
>
> Thanks
>
> Michal
Agreed. I still think it would make sense to start with a limited subset
of TPM commands, not with all-command-allowed.
I guess Alexander should be able to propose such subset.
/Jarkko
next prev parent reply other threads:[~2017-08-30 11:07 UTC|newest]
Thread overview: 42+ messages / expand[flat|nested] mbox.gz Atom feed top
2017-08-24 8:37 [PATCH RESEND 0/3] Export broken TPMs to user space Alexander Steffen
[not found] ` <20170824083714.10016-1-Alexander.Steffen-d0qZbvYSIPpWk0Htik3J/w@public.gmane.org>
2017-08-24 8:37 ` [PATCH RESEND 1/3] tpm-chip: Move idr_replace calls to appropriate places Alexander Steffen
2017-08-25 17:25 ` Jarkko Sakkinen
2017-08-25 17:25 ` Jarkko Sakkinen
2017-08-28 17:18 ` Alexander.Steffen at infineon.com
2017-08-28 17:18 ` Alexander.Steffen-d0qZbvYSIPpWk0Htik3J/w
2017-08-24 8:37 ` [PATCH RESEND 2/3] tpm-chip: Return TPM error codes from auto_startup functions Alexander Steffen
[not found] ` <20170824083714.10016-3-Alexander.Steffen-d0qZbvYSIPpWk0Htik3J/w@public.gmane.org>
2017-08-25 17:06 ` Jarkko Sakkinen
[not found] ` <20170825170607.wfnr5y5zres2n42r-VuQAYsv1563Yd54FQh9/CA@public.gmane.org>
2017-08-29 12:11 ` Alexander.Steffen-d0qZbvYSIPpWk0Htik3J/w
2017-08-24 8:37 ` [PATCH RESEND 3/3] tpm-chip: Export TPM device to user space even when startup failed Alexander Steffen
2017-08-25 17:20 ` Jarkko Sakkinen
2017-08-25 17:20 ` Jarkko Sakkinen
2017-08-28 17:15 ` Alexander.Steffen at infineon.com
2017-08-28 17:15 ` Alexander.Steffen-d0qZbvYSIPpWk0Htik3J/w
2017-08-29 12:55 ` Jarkko Sakkinen
2017-08-29 12:55 ` Jarkko Sakkinen
2017-08-29 13:17 ` [tpmdd-devel] " Michal Suchánek
2017-08-29 13:17 ` Michal Suchánek
2017-08-29 13:53 ` Peter Huewe
2017-08-29 13:53 ` Peter Huewe
2017-08-30 10:26 ` [tpmdd-devel] " Jarkko Sakkinen
2017-08-30 10:26 ` Jarkko Sakkinen
2017-08-30 10:15 ` Jarkko Sakkinen
2017-08-30 10:15 ` Jarkko Sakkinen
2017-08-30 10:20 ` [tpmdd-devel] " Jarkko Sakkinen
2017-08-30 10:20 ` Jarkko Sakkinen
2017-08-30 10:34 ` Michal Suchánek
2017-08-30 10:34 ` Michal Suchánek
2017-08-30 11:07 ` Jarkko Sakkinen [this message]
2017-08-30 11:07 ` Jarkko Sakkinen
2017-08-31 16:18 ` Alexander.Steffen at infineon.com
2017-08-31 16:18 ` Alexander.Steffen
2017-09-02 10:20 ` Jarkko Sakkinen
2017-09-02 10:20 ` Jarkko Sakkinen
2017-08-30 10:41 ` Peter Huewe
2017-08-30 10:41 ` Peter Huewe
2017-08-30 11:10 ` [tpmdd-devel] " Jarkko Sakkinen
2017-08-30 11:10 ` Jarkko Sakkinen
2017-08-31 16:26 ` Alexander.Steffen at infineon.com
2017-08-31 16:26 ` Alexander.Steffen
2017-09-02 10:24 ` Jarkko Sakkinen
2017-09-02 10:24 ` Jarkko Sakkinen
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20170830110721.edidi46sx2qgovzu@linux.intel.com \
--to=jarkko.sakkinen@linux.intel.com \
--cc=linux-security-module@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.