All of lore.kernel.org
 help / color / mirror / Atom feed
From: Eddie James <eajames@linux.ibm.com>
To: u-boot@lists.denx.de
Cc: ilias.apalodimas@linaro.org, sjg@chromium.org,
	xypron.glpk@gmx.de, joel@jms.id.au, eajames@linux.ibm.com
Subject: [PATCH v11 6/8] doc: Add measured boot documentation
Date: Mon,  7 Aug 2023 14:25:40 -0500	[thread overview]
Message-ID: <20230807192542.90526-7-eajames@linux.ibm.com> (raw)
In-Reply-To: <20230807192542.90526-1-eajames@linux.ibm.com>

Briefly describe the feature and specify the requirements.

Signed-off-by: Eddie James <eajames@linux.ibm.com>
Reviewed-by: Simon Glass <sjg@chromium.org>
---
 doc/usage/index.rst         |  1 +
 doc/usage/measured_boot.rst | 23 +++++++++++++++++++++++
 2 files changed, 24 insertions(+)
 create mode 100644 doc/usage/measured_boot.rst

diff --git a/doc/usage/index.rst b/doc/usage/index.rst
index 388e59f173..64eb362aef 100644
--- a/doc/usage/index.rst
+++ b/doc/usage/index.rst
@@ -13,6 +13,7 @@ Use U-Boot
    partitions
    cmdline
    semihosting
+   measured_boot
 
 Shell commands
 --------------
diff --git a/doc/usage/measured_boot.rst b/doc/usage/measured_boot.rst
new file mode 100644
index 0000000000..8357b1f480
--- /dev/null
+++ b/doc/usage/measured_boot.rst
@@ -0,0 +1,23 @@
+.. SPDX-License-Identifier: GPL-2.0+
+
+Measured Boot
+=====================
+
+U-Boot can perform a measured boot, the process of hashing various components
+of the boot process, extending the results in the TPM and logging the
+component's measurement in memory for the operating system to consume.
+
+Requirements
+---------------------
+
+* A hardware TPM 2.0 supported by the U-Boot drivers
+* CONFIG_TPM=y
+* CONFIG_MEASURED_BOOT=y
+* Device-tree configuration of the TPM device to specify the memory area
+  for event logging. The TPM device node must either contain a phandle to
+  a reserved memory region or "linux,sml-base" and "linux,sml-size"
+  indicating the address and size of the memory region. An example can be
+  found in arch/sandbox/dts/test.dts
+* The operating system must also be configured to use the memory regions
+  specified in the U-Boot device-tree in order to make use of the event
+  log.
-- 
2.39.3


  parent reply	other threads:[~2023-08-07 19:26 UTC|newest]

Thread overview: 15+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2023-08-07 19:25 [PATCH v11 0/8] tpm: Support boot measurements Eddie James
2023-08-07 19:25 ` [PATCH v11 1/8] tpm: Fix spelling for tpmu_ha union Eddie James
2023-08-07 19:25 ` [PATCH v11 2/8] tpm: sandbox: Update for needed TPM2 capabilities Eddie James
2023-08-07 19:25 ` [PATCH v11 3/8] tpm: Support boot measurements Eddie James
2023-08-09  8:34   ` Ilias Apalodimas
2023-08-09 10:37     ` Heinrich Schuchardt
2023-08-09 10:43       ` Ilias Apalodimas
2023-08-09 14:01         ` Eddie James
2023-08-10  7:44           ` Ilias Apalodimas
2023-08-10 13:45             ` Eddie James
2023-08-07 19:25 ` [PATCH v11 4/8] bootm: Support boot measurement Eddie James
2023-08-07 19:25 ` [PATCH v11 5/8] test: Add sandbox TPM " Eddie James
2023-08-07 19:25 ` Eddie James [this message]
2023-08-07 19:25 ` [PATCH v11 7/8] efi_loader: fix EFI_ENTRY point on get_active_pcr_banks Eddie James
2023-08-07 19:25 ` [PATCH v11 8/8] test: use a non system PCR for testing PCR extend Eddie James

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20230807192542.90526-7-eajames@linux.ibm.com \
    --to=eajames@linux.ibm.com \
    --cc=ilias.apalodimas@linaro.org \
    --cc=joel@jms.id.au \
    --cc=sjg@chromium.org \
    --cc=u-boot@lists.denx.de \
    --cc=xypron.glpk@gmx.de \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.