From: Yeoreum Yun <yeoreum.yun@arm.com>
To: Jason Gunthorpe <jgg@ziepe.ca>
Cc: Roberto Sassu <roberto.sassu@huaweicloud.com>,
Yeoreum Yun <yeoreum.yun@arm.com>,
linux-coco@lists.linux.dev, linux-kernel@vger.kernel.org,
linux-arm-kernel@lists.infradead.org,
Eric Snowberg <eric.snowberg@oracle.com>,
linux-integrity@vger.kernel.org,
linux-security-module@vger.kernel.org,
Mimi Zohar <zohar@linux.ibm.com>,
Roberto Sassu <roberto.sassu@huawei.com>,
Dmitry Kasatkin <dmitry.kasatkin@gmail.com>,
Paul Moore <paul@paul-moore.com>,
James Morris <jmorris@namei.org>,
"Serge E. Hallyn" <serge@hallyn.com>,
Catalin Marinas <catalin.marinas@arm.com>,
Suzuki Poulose <suzuki.poulose@arm.com>,
Steven Price <steven.price@arm.com>,
Sami Mujawar <sami.mujawar@arm.com>,
"Aneesh Kumar K.V" <aneesh.kumar@kernel.org>,
Jiri Pirko <jiri@resnulli.us>,
gongruiqi1@huawei.com
Subject: Re: [PATCH RFC 0/3] security: ima: support TSM measurement registers
Date: Thu, 1 Oct 2026 17:39:20 +0100 [thread overview]
Message-ID: <ar6MuKSDQc9J8o-6@e129823.arm.com> (raw)
In-Reply-To: <20261001151801.GC3019323@ziepe.ca>
Hi Jason,
> On Thu, Oct 01, 2026 at 01:45:26PM +0200, Roberto Sassu wrote:
> > On Thu, 2026-10-01 at 13:27 +0200, Roberto Sassu wrote:
> > > On Wed, 2026-09-30 at 14:43 +0100, Yeoreum Yun wrote:
> > > > Confidential computing guests without a TPM can use TSM measurement
> > > > registers to record IMA measurement digests instead of TPM PCRs.
> >
> > + Gong Ruiqi, of course.
>
> We are working very seriously on this same problem too.
>
> For some time we did investigate extending tsm_mr to do more things,
> have a better uAPI, but that eventually evolved into the realization
> that tsm_mr is simply too narrowly focused. It looks like James got to
> this idea before we did. I agree with his remarks in the 2025 thread
> with Gong.
>
> So we've started work on a new comprehensive "Attestation subsytem"
> that will pull in all forms of ROTs, TPM, CC stuff and SPDM use cases
> to give a consistent user API to work with this class of HW. In many
> ways I view this as a rename of tsm_mr (it will eventually fully
> absorb it), but the name evokes the broader goal and encourages
> everyone to come in, not just CC world.
>
> Our overall goal would be for something like systemd to have a single
> uniform kernel API that allows it interwork with any ROT someone may
> have. A uAPI to do "Extend", "Quote", "Get Log" operations so that the
> existing TPM support in systemd can be improved to work on any ROT
> flexibly without having to hard code specific ROT behaviors into
> systemd.
>
> I've felt the ultimate end goal would be to make all the in-kernel tpm
> users go through the proposed attestation subsystem so they can have
> ROT and "PCR profile" agility. Certainly I've heard enough people
> asking for this.
>
> This is a broader topic than just IMA. For example DRTM also has to
> use the TPM, and other ROTs. It also brings in a global shift of how
> the system wide "PCR Profile" should work as post-DRTM has a different
> TPM locality and access to the protected DRTM-only PCRs that are
> normally blocked.
>
> Jiri posted his current state here:
> https://lore.kernel.org/r/arzr32ZDComnfmny@FV6GYCPJ69
Thanks to let me know. I'll take a look for this.
--
Sincerely,
Yeoreum Yun
prev parent reply other threads:[~2026-10-01 16:39 UTC|newest]
Thread overview: 13+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-30 13:43 [PATCH RFC 0/3] security: ima: support TSM measurement registers Yeoreum Yun
2026-09-30 13:43 ` [PATCH RFC 1/3] virt: coco: introduce tsm_default_tm() and tsm_mr_read()/write() Yeoreum Yun
2026-09-30 13:55 ` sashiko-bot
2026-09-30 13:44 ` [PATCH RFC 2/3] security: IMA: introduce ima_mr structure Yeoreum Yun
2026-09-30 13:55 ` sashiko-bot
2026-09-30 13:44 ` [PATCH RFC 3/3] security: IMA: use TSM measurement registers Yeoreum Yun
2026-09-30 13:59 ` sashiko-bot
2026-10-01 11:27 ` [PATCH RFC 0/3] security: ima: support " Roberto Sassu
2026-10-01 11:45 ` Roberto Sassu
2026-10-01 14:24 ` Yeoreum Yun
2026-10-08 11:10 ` GONG Ruiqi
2026-10-01 15:18 ` Jason Gunthorpe
2026-10-01 16:39 ` Yeoreum Yun [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=ar6MuKSDQc9J8o-6@e129823.arm.com \
--to=yeoreum.yun@arm.com \
--cc=aneesh.kumar@kernel.org \
--cc=catalin.marinas@arm.com \
--cc=dmitry.kasatkin@gmail.com \
--cc=eric.snowberg@oracle.com \
--cc=gongruiqi1@huawei.com \
--cc=jgg@ziepe.ca \
--cc=jiri@resnulli.us \
--cc=jmorris@namei.org \
--cc=linux-arm-kernel@lists.infradead.org \
--cc=linux-coco@lists.linux.dev \
--cc=linux-integrity@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-security-module@vger.kernel.org \
--cc=paul@paul-moore.com \
--cc=roberto.sassu@huawei.com \
--cc=roberto.sassu@huaweicloud.com \
--cc=sami.mujawar@arm.com \
--cc=serge@hallyn.com \
--cc=steven.price@arm.com \
--cc=suzuki.poulose@arm.com \
--cc=zohar@linux.ibm.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.