From: Stefan Berger <stefanb@linux.vnet.ibm.com>
To: "Michael S. Tsirkin" <mst@redhat.com>,
Igor Mammedov <imammedo@redhat.com>
Cc: safford@watson.ibm.com, qemu-devel@nongnu.org, quan.xu@intel.com
Subject: Re: [Qemu-devel] [PATCH 0/5] Extend TPM support with a QEMU-external TPM
Date: Thu, 16 Apr 2015 15:21:18 -0400 [thread overview]
Message-ID: <55300BAE.5050800@linux.vnet.ibm.com> (raw)
In-Reply-To: <20150416205335-mutt-send-email-mst@redhat.com>
On 04/16/2015 02:55 PM, Michael S. Tsirkin wrote:
> On Thu, Apr 16, 2015 at 03:35:06PM +0200, Igor Mammedov wrote:
>> On Wed, 15 Apr 2015 18:38:43 -0400
>> Stefan Berger <stefanb@linux.vnet.ibm.com> wrote:
>>
>>> The following series of patches extends TPM support with an
>>> external TPM that offers a Linux CUSE (character device in userspace)
>>> interface. This TPM lets each VM access its own private vTPM.
>>> The CUSE TPM supports suspend/resume and migration. Much
>>> out-of-band functionality necessary to control the CUSE TPM is
>>> implemented using ioctl's.
>>>
>>> The series extends the TPM support so far that most functionality of
>>> TPM support on a physical platform is now available to each x86 VM,
>>> this includes the Physical Presence Interface support that has
>>> its counter-part in the SeaBIOS and is implemented using ACPI.
>>>
>>> http://www.seabios.org/pipermail/seabios/2015-March/008978.html
>> is it already merged?
>>
>> Is it possible to use MMIO region instead of allocating tpm_ppi_anchor
>> and tpm_ppi in BIOS memory?
>> That would simplify BIOS part a bit and significantly simplify ACPI code
>> as most of it is dealing with figuring out address of tpm_ppi.
> Which (if it works) I guess brings us back to the idea of using
> a pci device with a bar where we can stick tpm+vm id+whatever?
Well, at least the current implementation works with these patches +
CUSE TPM + patched SeaBIOS .
So the PCI bar does not get reset during a machine reboot and thus
preserves values? I did not model the TPM TIS as a PCI device, since it
typically is not such a device, but a LPC devices (close to ISA type of
device).
If we wanted to achieve that this method also works on real hardware,
with SeaBIOS running piggy-backed on coreboot, then we shouldn't assume
a PCI device, since it won't be. Otherwise, what are we trying to
achieve? Is the ACPI code the problem?
Stefan
prev parent reply other threads:[~2015-04-16 19:21 UTC|newest]
Thread overview: 21+ messages / expand[flat|nested] mbox.gz Atom feed top
2015-04-15 22:38 [Qemu-devel] [PATCH 0/5] Extend TPM support with a QEMU-external TPM Stefan Berger
2015-04-15 22:38 ` [Qemu-devel] [PATCH 1/5] Provide support for the CUSE TPM Stefan Berger
2015-04-15 22:38 ` [Qemu-devel] [PATCH 2/5] Support Physical Presence Interface Spec Stefan Berger
2015-04-15 22:38 ` [Qemu-devel] [PATCH 3/5] Introduce condition to notifiy waiters of completed command Stefan Berger
2015-04-15 22:38 ` [Qemu-devel] [PATCH 4/5] Introduce condition in TPM backend for notification Stefan Berger
2015-04-15 22:38 ` [Qemu-devel] [PATCH 5/5] Add support for VM suspend/resume for TPM TIS Stefan Berger
2015-04-16 13:35 ` [Qemu-devel] [PATCH 0/5] Extend TPM support with a QEMU-external TPM Igor Mammedov
2015-04-16 14:05 ` Stefan Berger
2015-04-22 7:00 ` Igor Mammedov
2015-04-22 18:18 ` Stefan Berger
2015-04-29 9:06 ` Igor Mammedov
2015-04-29 16:42 ` Stefan Berger
2015-05-04 9:16 ` Igor Mammedov
2015-05-04 15:22 ` Stefan Berger
2015-05-04 16:16 ` Kevin O'Connor
2015-05-04 18:39 ` Stefan Berger
2015-05-04 21:41 ` Igor Mammedov
2015-05-05 2:50 ` Kevin O'Connor
2015-05-05 17:42 ` Stefan Berger
2015-04-16 18:55 ` Michael S. Tsirkin
2015-04-16 19:21 ` Stefan Berger [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=55300BAE.5050800@linux.vnet.ibm.com \
--to=stefanb@linux.vnet.ibm.com \
--cc=imammedo@redhat.com \
--cc=mst@redhat.com \
--cc=qemu-devel@nongnu.org \
--cc=quan.xu@intel.com \
--cc=safford@watson.ibm.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.