From: "Jarkko Sakkinen" <jarkko@kernel.org>
To: "Jarkko Sakkinen" <jarkko@kernel.org>,
"Jonathan Corbet" <corbet@lwn.net>,
"Peter Huewe" <peterhuewe@gmx.de>,
"Jason Gunthorpe" <jgg@ziepe.ca>
Cc: <James.Bottomley@hansenpartnership.com>,
<andrew.cooper3@citrix.com>, <ardb@kernel.org>,
<baolu.lu@linux.intel.com>, <bp@alien8.de>,
<dave.hansen@linux.intel.com>, <davem@davemloft.net>,
<dpsmith@apertussolutions.com>, <dwmw2@infradead.org>,
<ebiederm@xmission.com>, <herbert@gondor.apana.org.au>,
<hpa@zytor.com>, <iommu@lists.linux-foundation.org>,
<kanth.ghatraju@oracle.com>, <kexec@lists.infradead.org>,
<linux-crypto@vger.kernel.org>, <linux-doc@vger.kernel.org>,
<linux-efi@vger.kernel.org>, <linux-integrity@vger.kernel.org>,
<linux-kernel@vger.kernel.org>, <luto@amacapital.net>,
<mingo@redhat.com>, <mjg59@srcf.ucam.org>,
<nivedita@alum.mit.edu>, <ross.philipson@oracle.com>,
<tglx@linutronix.de>, <trenchboot-devel@googlegroups.com>,
<x86@kernel.org>
Subject: Re: [RFC PATCH v2 1/2] tpm, tpm_tis: Introduce TPM_IOC_SET_LOCALITY
Date: Sat, 02 Nov 2024 08:29:52 +0200 [thread overview]
Message-ID: <D5BHBW3NUS5C.293GUI03HMTCF@kernel.org> (raw)
In-Reply-To: <20241102062259.2521361-1-jarkko@kernel.org>
On Sat Nov 2, 2024 at 8:22 AM EET, Jarkko Sakkinen wrote:
> DRTM needs to be able to set the locality used by kernel. Provide
> TPM_IOC_SET_LOCALITY operation for this purpose. It is enabled only if
> the kernel command-line has 'tpm.set_locality_enabled=1'. The operation
> is one-shot allowed only for tpm_tis for the moment.
>
> Signed-off-by: Jarkko Sakkinen <jarkko@kernel.org>
> ---
> v2:
> - Do not ignore the return value of tpm_ioc_set_locality().
> - if (!(chip->flags & TPM_CHIP_FLAG_SET_LOCALITY_ENABLED))
> - Refined kernel-parameters.txt description.
> - Use __u8 instead of u8 in the uapi.
> - Tested with https://codeberg.org/jarkko/tpm-set-locality-test/src/branch/main/src/main.rs
This version has been also tested (and encountered bugs fixed). I wrote
a small test program to verify that it works linked above.
After the boot, the new ioctl can reset exactly once the locality. Other
benefit is that the feature can be selected per driver (at this point
tpm_tis drivers) and protection of the access with DAC, SELinux etc.
And thanks to the kernel command-line parameter, it is an opt-in
feature like it should because vast majority of users will probably
never use trenchboot. I.e. set 'tpm.set_locality_enable=1' to have
the ioctl available.
I think this is a solution that at least I could live with. It has
somewhat rigid commmon-sense constraints.
BR, Jarkko
next prev parent reply other threads:[~2024-11-02 6:29 UTC|newest]
Thread overview: 58+ messages / expand[flat|nested] mbox.gz Atom feed top
2024-09-13 20:04 [PATCH v11 00/20] x86: Trenchboot secure dynamic launch Linux kernel support Ross Philipson
2024-09-13 20:04 ` [PATCH v11 01/20] Documentation/x86: Secure Launch kernel documentation Ross Philipson
2024-11-01 19:31 ` Elliott, Robert (Servers)
2024-09-13 20:04 ` [PATCH v11 02/20] x86: Secure Launch Kconfig Ross Philipson
2024-09-13 20:05 ` [PATCH v11 03/20] x86: Secure Launch Resource Table header file Ross Philipson
2024-09-13 20:05 ` [PATCH v11 04/20] x86: Secure Launch main " Ross Philipson
2024-09-13 20:05 ` [PATCH v11 05/20] x86: Add early SHA-1 support for Secure Launch early measurements Ross Philipson
2024-09-13 20:05 ` [PATCH v11 06/20] x86: Add early SHA-256 " Ross Philipson
2024-09-13 20:05 ` [PATCH v11 07/20] x86/msr: Add variable MTRR base/mask and x2apic ID registers Ross Philipson
2024-09-13 20:05 ` [PATCH v11 08/20] x86/boot: Place TXT MLE header in the kernel_info section Ross Philipson
2024-09-13 20:05 ` [PATCH v11 09/20] x86: Secure Launch kernel early boot stub Ross Philipson
2024-09-13 20:05 ` [PATCH v11 10/20] x86: Secure Launch kernel late " Ross Philipson
2024-09-13 20:05 ` [PATCH v11 11/20] x86: Secure Launch SMP bringup support Ross Philipson
2024-09-13 20:05 ` [PATCH v11 12/20] kexec: Secure Launch kexec SEXIT support Ross Philipson
2024-09-13 20:05 ` [PATCH v11 13/20] x86/reboot: Secure Launch SEXIT support on reboot paths Ross Philipson
2024-09-13 20:05 ` [PATCH v11 14/20] tpm: Protect against locality counter underflow Ross Philipson
2024-11-01 9:33 ` Jarkko Sakkinen
2024-09-13 20:05 ` [PATCH v11 15/20] tpm: Ensure tpm is in known state at startup Ross Philipson
2024-11-01 9:37 ` Jarkko Sakkinen
2024-11-02 14:02 ` Jarkko Sakkinen
2024-09-13 20:05 ` [PATCH v11 16/20] tpm: Make locality requests return consistent values Ross Philipson
2024-11-01 10:04 ` Jarkko Sakkinen
2024-11-02 14:26 ` Jarkko Sakkinen
2024-09-13 20:05 ` [PATCH v11 17/20] tpm: Add ability to set the default locality the TPM chip uses Ross Philipson
2024-11-01 10:05 ` Jarkko Sakkinen
2024-11-02 1:37 ` [RFC PATCH] tpm, tpm_tis: Introduce TPM_IOC_SET_LOCALITY Jarkko Sakkinen
2024-11-02 1:39 ` Jarkko Sakkinen
2024-11-02 6:22 ` [RFC PATCH v2 1/2] " Jarkko Sakkinen
2024-11-02 6:22 ` [RFC PATCH v2 2/2] tpm: show the default locality in sysfs Jarkko Sakkinen
2024-11-02 6:29 ` Jarkko Sakkinen [this message]
2024-11-02 9:02 ` [RFC PATCH v2 1/2] tpm, tpm_tis: Introduce TPM_IOC_SET_LOCALITY Ard Biesheuvel
2024-11-02 10:38 ` Jarkko Sakkinen
2024-11-02 10:40 ` Jarkko Sakkinen
2024-11-02 10:52 ` Ard Biesheuvel
2024-11-02 13:39 ` Jarkko Sakkinen
2024-11-02 14:07 ` Jarkko Sakkinen
2024-09-13 20:05 ` [PATCH v11 18/20] tpm: Add sysfs interface to allow setting and querying the default locality Ross Philipson
2024-11-01 3:17 ` James Bottomley
2024-11-01 10:06 ` Jarkko Sakkinen
2024-11-01 21:50 ` Jarkko Sakkinen
2024-11-01 21:56 ` Jarkko Sakkinen
2024-09-13 20:05 ` [PATCH v11 19/20] x86: Secure Launch late initcall platform module Ross Philipson
2024-09-13 20:05 ` [PATCH v11 20/20] x86/efi: EFI stub DRTM launch support for Secure Launch Ross Philipson
2024-10-31 19:25 ` [PATCH v11 00/20] x86: Trenchboot secure dynamic launch Linux kernel support Thomas Gleixner
2024-10-31 22:37 ` Jarkko Sakkinen
2024-10-31 23:08 ` Thomas Gleixner
2024-11-01 0:33 ` Jarkko Sakkinen
2024-11-01 0:40 ` Jarkko Sakkinen
2024-11-01 8:50 ` Ard Biesheuvel
2024-11-01 9:18 ` Jarkko Sakkinen
2024-11-01 9:30 ` Jarkko Sakkinen
2024-11-01 14:51 ` Jarkko Sakkinen
2024-11-01 10:28 ` Jarkko Sakkinen
2024-11-01 20:34 ` Thomas Gleixner
2024-11-01 21:13 ` Jarkko Sakkinen
2024-11-01 21:19 ` Jarkko Sakkinen
2024-11-01 22:04 ` Thomas Gleixner
2024-11-01 22:18 ` Jarkko Sakkinen
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=D5BHBW3NUS5C.293GUI03HMTCF@kernel.org \
--to=jarkko@kernel.org \
--cc=James.Bottomley@hansenpartnership.com \
--cc=andrew.cooper3@citrix.com \
--cc=ardb@kernel.org \
--cc=baolu.lu@linux.intel.com \
--cc=bp@alien8.de \
--cc=corbet@lwn.net \
--cc=dave.hansen@linux.intel.com \
--cc=davem@davemloft.net \
--cc=dpsmith@apertussolutions.com \
--cc=dwmw2@infradead.org \
--cc=ebiederm@xmission.com \
--cc=herbert@gondor.apana.org.au \
--cc=hpa@zytor.com \
--cc=iommu@lists.linux-foundation.org \
--cc=jgg@ziepe.ca \
--cc=kanth.ghatraju@oracle.com \
--cc=kexec@lists.infradead.org \
--cc=linux-crypto@vger.kernel.org \
--cc=linux-doc@vger.kernel.org \
--cc=linux-efi@vger.kernel.org \
--cc=linux-integrity@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=luto@amacapital.net \
--cc=mingo@redhat.com \
--cc=mjg59@srcf.ucam.org \
--cc=nivedita@alum.mit.edu \
--cc=peterhuewe@gmx.de \
--cc=ross.philipson@oracle.com \
--cc=tglx@linutronix.de \
--cc=trenchboot-devel@googlegroups.com \
--cc=x86@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).