All of lore.kernel.org
 help / color / mirror / Atom feed
From: Matthew Fioravante <matthew.fioravante@jhuapl.edu>
To: George Dunlap <George.Dunlap@eu.citrix.com>
Cc: "xen-devel@lists.xensource.com" <xen-devel@lists.xensource.com>,
	Ian Campbell <Ian.Campbell@citrix.com>
Subject: Re: [PATCH] Upgrade vtpmd to berlios version 0.7.4
Date: Wed, 26 Sep 2012 10:39:57 -0400	[thread overview]
Message-ID: <506313BD.7020600@jhuapl.edu> (raw)
In-Reply-To: <CAFLBxZYh69025_LHq2qWfQMotincb_pvDtCtiAa7sXCg-RQL6A@mail.gmail.com>


[-- Attachment #1.1: Type: text/plain, Size: 2193 bytes --]

On 09/26/2012 07:46 AM, George Dunlap wrote:
> On Tue, Sep 25, 2012 at 4:50 PM, Matthew Fioravante
> <matthew.fioravante@jhuapl.edu> wrote:
>> I don't know if there is anyone who would want to still use vtpms as
>> processes when the stub domains are now available. Security research
>> people like the domain model because it guarantees a better separation
>> of components guaranteed by the hypervisor and doesn't have to trust the
>> dom0 OS.
>>
>> If we got rid of the process and hybrid model, then the
>> tools/vtpm_manager code that is still used could be moved into the
>> vtpmmgrdom stubdom codebase. tools/vtpm could be completely removed
>> along with the --enable-vtpm stuff in the configure script and the cmake
>> dependency.
> I haven't had a chance to look at your patches in detail (because the
> few I've looked at have whitespace damage that Ian mentioned before),
> but I as long as the user interface (via xl, config files, &c) is the
> same, or comparable, I don't see any reason not to move entirely over
> the stubdom model; especially if the process or hybrid models are not
> being tested or maintained.
It would also simplify the whole system quite a bit. If I am to maintain
vtpm I'd like to not have to deal with bugs in the old code.

So how should we proceed with this then? Do you all want to remove the
vtpm process/hybrid model entirely now or just deprecate it for a while?
If we deprecate it do you still want my updates for it?

Let me know and I'll provide patches to make it happen either way.

The last piece of this puzzle that I haven't figured out is the linux
tpm frontend driver. Its not in the main linux tree. Its from the old
2006 vtpm code but it still works. I believe it shipped with the old xen
2.6.18 kernel but now I don't know whats happened to it. I still have a
copy we have been porting to newer kernels internally.

Should we try to get it in mainline linux? Or maybe provide it in the
xen tree as an externally compilable kernel module?

There also exists a linux tpm backend driver, but if were only going to
support the domain model that is no longer needed and can go away.
>  -George



[-- Attachment #1.2: S/MIME Cryptographic Signature --]
[-- Type: application/pkcs7-signature, Size: 1459 bytes --]

[-- Attachment #2: Type: text/plain, Size: 126 bytes --]

_______________________________________________
Xen-devel mailing list
Xen-devel@lists.xen.org
http://lists.xen.org/xen-devel

  reply	other threads:[~2012-09-26 14:39 UTC|newest]

Thread overview: 10+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2012-09-17 17:52 [PATCH] Upgrade vtpmd to berlios version 0.7.4 Matthew Fioravante
2012-09-18  7:38 ` Ian Campbell
2012-09-18 17:33   ` Matthew Fioravante
2012-09-25  9:53     ` Ian Campbell
2012-09-25 15:50       ` Matthew Fioravante
2012-09-26 11:46         ` George Dunlap
2012-09-26 14:39           ` Matthew Fioravante [this message]
2012-09-26 15:09             ` George Dunlap
2012-09-26 15:21             ` Ian Campbell
2012-09-26 15:58               ` Matthew Fioravante

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=506313BD.7020600@jhuapl.edu \
    --to=matthew.fioravante@jhuapl.edu \
    --cc=George.Dunlap@eu.citrix.com \
    --cc=Ian.Campbell@citrix.com \
    --cc=xen-devel@lists.xensource.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.