From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from bombadil.infradead.org (bombadil.infradead.org [198.137.202.133]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.lore.kernel.org (Postfix) with ESMTPS id 46D92CD4F4C for ; Mon, 9 Sep 2024 04:14:34 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.infradead.org; s=bombadil.20210309; h=Sender:List-Subscribe:List-Help :List-Post:List-Archive:List-Unsubscribe:List-Id:Content-Transfer-Encoding: Content-Type:In-Reply-To:From:References:Cc:To:Subject:MIME-Version:Date: Message-ID:Reply-To:Content-ID:Content-Description:Resent-Date:Resent-From: Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Owner; bh=qWJH4JtiF+rIHPnRLC4WN/TNvZ/uRdMkrGB+YOGo0Hs=; b=X1WaXuJ2eezw56lX3Md8X2KpJa LNaZaj+8EVNoycPyAus+2L8c5pXDC8/GLwLJrywsLQq+Btx/qIG/5KHPYpJWXB1XktZmwVw2f4hic gKtILO8PJICDcD7qR3ekHB61Xuwl0pFq0NHzZ0kIp/cXktI9m4p1VsjnolYeadQqwNo6zxQXM82X7 zFebnG5FFPPE0x2YyU2XEODbUNDVWhmV3uzH3+N0luFciVUM2m54WD6zbUCiISBXdmu4Gim2i/xTK at2fYGdLcmKusIo8o465kHo6Wd70BhowPp1/dHSMXX935RYNvr6gpndrF8y2seBCuRF+Z2zYkxbVP ersZ6xWA==; Received: from localhost ([::1] helo=bombadil.infradead.org) by bombadil.infradead.org with esmtp (Exim 4.97.1 #2 (Red Hat Linux)) id 1snVnF-00000000QI7-1Qer; Mon, 09 Sep 2024 04:14:25 +0000 Received: from us-smtp-delivery-124.mimecast.com ([170.10.133.124]) by bombadil.infradead.org with esmtps (Exim 4.97.1 #2 (Red Hat Linux)) id 1snVmE-00000000QBA-4At3 for linux-arm-kernel@lists.infradead.org; Mon, 09 Sep 2024 04:13:24 +0000 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1725855200; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=qWJH4JtiF+rIHPnRLC4WN/TNvZ/uRdMkrGB+YOGo0Hs=; b=RfUHfWtFdOb8BmcU3S7O8oLy1sRvSqZHXUZLhTATyAlrxn27KBN5Arh/ef/W03tT4uud7Y l9Ag/PCibvQdsODAmOrXNepltUz6C+D2Htk5zg0IW5uf6iqNQhawhvZLclV9yaKIykBXDN /X9Hi2QEp/a6p0BkMkldt7P9gNHxy9c= Received: from mail-pf1-f199.google.com (mail-pf1-f199.google.com [209.85.210.199]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-690-EOI9iHv0Oc2VxLgWQFY3Ng-1; Mon, 09 Sep 2024 00:13:18 -0400 X-MC-Unique: EOI9iHv0Oc2VxLgWQFY3Ng-1 Received: by mail-pf1-f199.google.com with SMTP id d2e1a72fcca58-718f200ae10so1643394b3a.2 for ; Sun, 08 Sep 2024 21:13:18 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1725855198; x=1726459998; h=content-transfer-encoding:in-reply-to:from:content-language :references:cc:to:subject:user-agent:mime-version:date:message-id :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to; bh=qWJH4JtiF+rIHPnRLC4WN/TNvZ/uRdMkrGB+YOGo0Hs=; b=LivOp5h1AuwhAaAhjHwdVResdpuxulweSELizVHJwuydYZM2UGUcvG7scD2FuVRev2 Ba6W1vjefygOzg6w2wkiFOYXCHvNAvAWtsZdL+uS8X8Mg99K8sTp2QFGXss+8Ot1YMjT +Os0CCQqb/M/Wt12XO6R6ATMZ8ByjTE7+bDGlyu7XEjWCMxJvy2HJpatbS70bCXt4TMf fRoQqJY7YhZ7WCyfBN8IMz3d/5ff0qnUhGbVKlfgmX9xhp2p86ryIKsvFYN1SdOFAOjS 3DQVUaoll6xveyRbeYh29mH/hw3e7V+rPq24z6n3v6gxGqO1QJtJD27WUg7bpZSRWhtz FvdQ== X-Forwarded-Encrypted: i=1; AJvYcCXaef62cBYO+rFvzkmr+92S6BfqQGdrsuhdLc4OlJ4IkzQj9DiSl0mxdrUL34kg487dxszMz1U0nf6SSlBNOY4O@lists.infradead.org X-Gm-Message-State: AOJu0Ywd19EM06izuk3WDZInKV4Mj9o9XCdWwwPVvPRXpkkgzbblIxDu vaM0ULW4G2IArf4BaRTrLzlsJ7Uo0YvLbUFYvdhXp9BCSI4stdm+k1IrWGkhYPBgPM+rBab0dO/ mRYGKITfcvG3OnEJwzOy7E1fxBFuBFw1INya7n+FDupwlEEDPjpNDzmBdDFgYH/iz/yk6BTfV X-Received: by 2002:a05:6a20:d49b:b0:1cf:3b22:feca with SMTP id adf61e73a8af0-1cf3b230136mr3918236637.15.1725855197879; Sun, 08 Sep 2024 21:13:17 -0700 (PDT) X-Google-Smtp-Source: AGHT+IEnUKDaM2E6KNKbxP6Avir+4/JCbohvZZf9a+5rUYwTHzqD3kkO8haVPQRh64vM65/fXpKKbA== X-Received: by 2002:a05:6a20:d49b:b0:1cf:3b22:feca with SMTP id adf61e73a8af0-1cf3b230136mr3918188637.15.1725855197215; Sun, 08 Sep 2024 21:13:17 -0700 (PDT) Received: from [192.168.68.54] ([103.210.27.31]) by smtp.gmail.com with ESMTPSA id 41be03b00d2f7-7d823cf3b1fsm2543061a12.33.2024.09.08.21.13.09 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Sun, 08 Sep 2024 21:13:16 -0700 (PDT) Message-ID: <3aea7984-6e84-4bc5-9cd6-55b2a45d71c0@redhat.com> Date: Mon, 9 Sep 2024 14:13:06 +1000 MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: Re: [PATCH v5 19/19] virt: arm-cca-guest: TSM_REPORT support for realms To: Steven Price , kvm@vger.kernel.org, kvmarm@lists.linux.dev Cc: Catalin Marinas , Marc Zyngier , Will Deacon , James Morse , Oliver Upton , Suzuki K Poulose , Zenghui Yu , linux-arm-kernel@lists.infradead.org, linux-kernel@vger.kernel.org, Joey Gouly , Alexandru Elisei , Christoffer Dall , Fuad Tabba , linux-coco@lists.linux.dev, Ganapatrao Kulkarni , Shanker Donthineni , Alper Gun , Sami Mujawar References: <20240819131924.372366-1-steven.price@arm.com> <20240819131924.372366-20-steven.price@arm.com> From: Gavin Shan In-Reply-To: <20240819131924.372366-20-steven.price@arm.com> X-Mimecast-Spam-Score: 0 X-Mimecast-Originator: redhat.com Content-Language: en-US Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 7bit X-CRM114-Version: 20100106-BlameMichelson ( TRE 0.8.0 (BSD) ) MR-646709E3 X-CRM114-CacheID: sfid-20240908_211323_144713_A75CF595 X-CRM114-Status: GOOD ( 20.91 ) X-BeenThere: linux-arm-kernel@lists.infradead.org X-Mailman-Version: 2.1.34 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: "linux-arm-kernel" Errors-To: linux-arm-kernel-bounces+linux-arm-kernel=archiver.kernel.org@lists.infradead.org On 8/19/24 11:19 PM, Steven Price wrote: > From: Sami Mujawar > > Introduce an arm-cca-guest driver that registers with > the configfs-tsm module to provide user interfaces for > retrieving an attestation token. > > When a new report is requested the arm-cca-guest driver > invokes the appropriate RSI interfaces to query an > attestation token. > > The steps to retrieve an attestation token are as follows: > 1. Mount the configfs filesystem if not already mounted > mount -t configfs none /sys/kernel/config > 2. Generate an attestation token > report=/sys/kernel/config/tsm/report/report0 > mkdir $report > dd if=/dev/urandom bs=64 count=1 > $report/inblob > hexdump -C $report/outblob > rmdir $report > > Signed-off-by: Sami Mujawar > Signed-off-by: Suzuki K Poulose > Signed-off-by: Steven Price > --- > v3: Minor improvements to comments and adapt to the renaming of > GRANULE_SIZE to RSI_GRANULE_SIZE. > --- > drivers/virt/coco/Kconfig | 2 + > drivers/virt/coco/Makefile | 1 + > drivers/virt/coco/arm-cca-guest/Kconfig | 11 + > drivers/virt/coco/arm-cca-guest/Makefile | 2 + > .../virt/coco/arm-cca-guest/arm-cca-guest.c | 211 ++++++++++++++++++ > 5 files changed, 227 insertions(+) > create mode 100644 drivers/virt/coco/arm-cca-guest/Kconfig > create mode 100644 drivers/virt/coco/arm-cca-guest/Makefile > create mode 100644 drivers/virt/coco/arm-cca-guest/arm-cca-guest.c > [...] > + > +/** > + * arm_cca_report_new - Generate a new attestation token. > + * > + * @report: pointer to the TSM report context information. > + * @data: pointer to the context specific data for this module. > + * > + * Initialise the attestation token generation using the challenge data > + * passed in the TSM decriptor. Allocate memory for the attestation token ^^^^^^^^^ Typo. s/decriptor/descriptor as reported by './scripts/checkpatch.pl --codespell' > + * and schedule calls to retrieve the attestation token on the same CPU > + * on which the attestation token generation was initialised. > + * > + * The challenge data must be at least 32 bytes and no more than 64 bytes. If > + * less than 64 bytes are provided it will be zero padded to 64 bytes. > + * > + * Return: > + * * %0 - Attestation token generated successfully. > + * * %-EINVAL - A parameter was not valid. > + * * %-ENOMEM - Out of memory. > + * * %-EFAULT - Failed to get IPA for memory page(s). > + * * A negative status code as returned by smp_call_function_single(). > + */ Thanks, Gavin