All of lore.kernel.org
 help / color / mirror / Atom feed
From: Eddie James <eajames@linux.ibm.com>
To: u-boot@lists.denx.de
Cc: ilias.apalodimas@linaro.org, sjg@chromium.org,
	xypron.glpk@gmx.de, eajames@linux.ibm.com
Subject: [PATCH v14 6/8] doc: Add measured boot documentation
Date: Tue, 24 Oct 2023 10:43:52 -0500	[thread overview]
Message-ID: <20231024154354.197524-7-eajames@linux.ibm.com> (raw)
In-Reply-To: <20231024154354.197524-1-eajames@linux.ibm.com>

Briefly describe the feature and specify the requirements.

Signed-off-by: Eddie James <eajames@linux.ibm.com>
Reviewed-by: Simon Glass <sjg@chromium.org>
---
Changes since v12:
 - Add a bit of detail about OS usage and what pieces are measured

 doc/usage/index.rst         |  1 +
 doc/usage/measured_boot.rst | 31 +++++++++++++++++++++++++++++++
 2 files changed, 32 insertions(+)
 create mode 100644 doc/usage/measured_boot.rst

diff --git a/doc/usage/index.rst b/doc/usage/index.rst
index 98b4719c40..bf53bb6bda 100644
--- a/doc/usage/index.rst
+++ b/doc/usage/index.rst
@@ -14,6 +14,7 @@ Use U-Boot
    partitions
    cmdline
    semihosting
+   measured_boot
 
 Shell commands
 --------------
diff --git a/doc/usage/measured_boot.rst b/doc/usage/measured_boot.rst
new file mode 100644
index 0000000000..0aad590859
--- /dev/null
+++ b/doc/usage/measured_boot.rst
@@ -0,0 +1,31 @@
+.. SPDX-License-Identifier: GPL-2.0+
+
+Measured Boot
+=====================
+
+U-Boot can perform a measured boot, the process of hashing various components
+of the boot process, extending the results in the TPM and logging the
+component's measurement in memory for the operating system to consume.
+
+By default, U-Boot will measure the operating system (linux) image, the
+initrd image, and the "bootargs" environment variable. By enabling
+CONFIG_MEASURE_DEVICETREE, U-Boot will also measure the devicetree image.
+
+The operating system typically would verify that the hashes found in the
+TPM PCRs match the contents of the event log. This can further be checked
+against the hash results of previous boots.
+
+Requirements
+---------------------
+
+* A hardware TPM 2.0 supported by the U-Boot drivers
+* CONFIG_TPM=y
+* CONFIG_MEASURED_BOOT=y
+* Device-tree configuration of the TPM device to specify the memory area
+  for event logging. The TPM device node must either contain a phandle to
+  a reserved memory region or "linux,sml-base" and "linux,sml-size"
+  indicating the address and size of the memory region. An example can be
+  found in arch/sandbox/dts/test.dts
+* The operating system must also be configured to use the memory regions
+  specified in the U-Boot device-tree in order to make use of the event
+  log.
-- 
2.39.3


  parent reply	other threads:[~2023-10-24 15:45 UTC|newest]

Thread overview: 17+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2023-10-24 15:43 [PATCH v14 0/8] tpm: Support boot measurements Eddie James
2023-10-24 15:43 ` [PATCH v14 1/8] tpm: Fix spelling for tpmu_ha union Eddie James
2023-10-24 15:43 ` [PATCH v14 2/8] tpm: sandbox: Update for needed TPM2 capabilities Eddie James
2023-10-24 15:43 ` [PATCH v14 3/8] tpm: Support boot measurements Eddie James
2023-10-24 15:43 ` [PATCH v14 4/8] bootm: Support boot measurement Eddie James
2023-10-25 12:41   ` Ilias Apalodimas
2023-10-25 13:53     ` Eddie James
2023-10-25 13:03   ` Heinrich Schuchardt
2023-10-25 13:21     ` Ilias Apalodimas
2023-10-25 13:58       ` Heinrich Schuchardt
2023-10-25 14:27         ` Ilias Apalodimas
2023-10-24 15:43 ` [PATCH v14 5/8] test: Add sandbox TPM " Eddie James
2023-10-24 15:43 ` Eddie James [this message]
2023-10-25 12:37   ` [PATCH v14 6/8] doc: Add measured boot documentation Ilias Apalodimas
2023-10-24 15:43 ` [PATCH v14 7/8] efi_loader: fix EFI_ENTRY point on get_active_pcr_banks Eddie James
2023-10-24 15:43 ` [PATCH v14 8/8] test: use a non system PCR for testing PCR extend Eddie James
2023-10-25 12:38 ` [PATCH v14 0/8] tpm: Support boot measurements Ilias Apalodimas

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20231024154354.197524-7-eajames@linux.ibm.com \
    --to=eajames@linux.ibm.com \
    --cc=ilias.apalodimas@linaro.org \
    --cc=sjg@chromium.org \
    --cc=u-boot@lists.denx.de \
    --cc=xypron.glpk@gmx.de \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.