Linux Power Management development
 help / color / mirror / Atom feed
* [RFC] Make hibernation work with lockdown
@ 2026-10-08 13:20 Matthew Garrett
  2026-10-08 13:20 ` [PATCH 01/17] tpm: Define a kernel-owned TPM NV index that can't be modified by userland Matthew Garrett
                   ` (17 more replies)
  0 siblings, 18 replies; 31+ messages in thread
From: Matthew Garrett @ 2026-10-08 13:20 UTC (permalink / raw)
  To: mjg59
  Cc: keyrings, James.Bottomley, linux-integrity, rafael, linux-pm,
	linux-efi

Hibernation writes out the full system state to disk in an unencrypted 
and unauthenticated manner. Resuming from hibernate reads that data and 
throws it directly into RAM, then jumps into it. This is effectively an 
entirely unauthenticated mechanism for putting whatever you want into 
kernel space. This violates the assumptions around lockdown (root can 
write whatever they want to the swap partition and then trigger a 
resume), and as such lockdown blocks hibernate.

This has made many people unhappy.

This patchset seeks to solve this problem. In order for hibernation to 
be trustworthy we need to be able to prove that the image was generated 
by the kernel and not modified after that. This is not an easy task, and 
requires some infrastructural framework. To that end, this patchset does 
the following:

1) Co-opts a TPM NV index for the kernel's sole use. This is currently a 
placeholder and we should register one explicitly from an appropriate 
range in order to ensure that we don't conflict with userland.

2) Does something horrifying with PCR 5 in order to prove that a given 
kernel supports (1). We need to extend and cap a PCR before userland is 
running in order to prove that the kernel has support for this feature, 
but since we don't currently cap any PCRs there's nothing stopping 
userland from doing the same and so achieving the same state. The way 
around this is to rely on a feature of PCR 5 - it is extended as a 
result of ExitBootServices being called, and since the boot stub can 
execute code before that happens we can perform the proof extension 
there and then have it implicitly capped by the firmware's extension.

3) Adds support for audited TPM sessions in the kernel, allowing us to 
generate signed digests of the commands that were executed in that 
session and their results

4) Adds support for generating a predictable AK that can be used to sign 
digests from those audit sessions

5) Adds support for generating a TPM signing key in such a session, and 
using the signed digest to prove that the session took place in the 
kernel

6) Signs the hibernation image with such a key

An old kernel that doesn't implement (1) won't be able to mimic the same 
PCR 5 value. Userland won't be able to mimic the NV index value because 
the kernel will block it. This means that the only way that key could 
have been created is by the kernel, and so we can trust that the image 
was generated by the kernel.

QUESTIONS:

1) I haven't tried to make the key management generic, since this isn't 
intended to ever be exposed to userland in any way. Should it be 
integrated into the trusted keys layer anyway?

2) Filtering TPM commands from userland isn't ideal - anyone able to 
poke commands into the TPM directly is in a position to violate the 
assumptions here. Is there any way we can get a secret into the kernel 
that can be used as an auth value? It would need to be impossible to 
obtain from userland and it would need to be consistent over platform 
reboots.


^ permalink raw reply	[flat|nested] 31+ messages in thread

end of thread, other threads:[~2026-10-09  8:33 UTC | newest]

Thread overview: 31+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-10-08 13:20 [RFC] Make hibernation work with lockdown Matthew Garrett
2026-10-08 13:20 ` [PATCH 01/17] tpm: Define a kernel-owned TPM NV index that can't be modified by userland Matthew Garrett
2026-10-08 13:41   ` Matthew Garrett
2026-10-08 16:24     ` Jarkko Sakkinen
2026-10-08 16:23   ` Jarkko Sakkinen
2026-10-09  8:33     ` Matthew Garrett
2026-10-08 17:06   ` Ilias Apalodimas
2026-10-08 13:20 ` [PATCH 02/17] efi: Add a mechanism to modify TPM state depending on kernel security features Matthew Garrett
2026-10-08 16:38   ` Jarkko Sakkinen
2026-10-08 13:20 ` [PATCH 03/17] tpm: Allow tpm2_start_auth_session() to start an audit session Matthew Garrett
2026-10-08 13:20 ` [PATCH 04/17] tpm: Log commands executed in " Matthew Garrett
2026-10-08 13:20 ` [PATCH 05/17] tpm: Add a kernel attestation key and signed audit digest retrieval Matthew Garrett
2026-10-08 16:45   ` James Bottomley
2026-10-09  8:29     ` Matthew Garrett
2026-10-08 13:20 ` [PATCH 06/17] tpm: Use TPM2_NV_ReadPublic to read NV index names Matthew Garrett
2026-10-08 13:20 ` [PATCH 07/17] tpm: Add in-kernel support for reading NV indices Matthew Garrett
2026-10-08 13:20 ` [PATCH 08/17] tpm: Add NV define, undefine and write helpers Matthew Garrett
2026-10-08 13:20 ` [PATCH 09/17] tpm: Provision the kernel NV index at registration Matthew Garrett
2026-10-08 13:20 ` [PATCH 10/17] tpm: Move the bounds-checked response reader to a header Matthew Garrett
2026-10-08 13:20 ` [PATCH 11/17] tpm: Add kernel signing key creation with audited provenance Matthew Garrett
2026-10-08 17:00   ` James Bottomley
2026-10-09  8:31     ` Matthew Garrett
2026-10-08 13:20 ` [PATCH 12/17] tpm: Add signing with the kernel signing key Matthew Garrett
2026-10-08 13:20 ` [PATCH 13/17] tpm: Add verification of kernel signing key provenance Matthew Garrett
2026-10-08 13:20 ` [PATCH 14/17] PM: hibernate: Add image digest and signature page infrastructure Matthew Garrett
2026-10-08 13:20 ` [PATCH 15/17] PM: hibernate: Sign and verify images with a kernel-generated TPM key Matthew Garrett
2026-10-08 13:20 ` [PATCH 16/17] PM: hibernate: Refuse to verify images with a virtual TPM Matthew Garrett
2026-10-08 13:20 ` [PATCH 17/17] PM: hibernate: Allow hibernation under lockdown with signed images Matthew Garrett
2026-10-08 16:53   ` Jarkko Sakkinen
2026-10-09  8:31     ` Matthew Garrett
2026-10-08 15:56 ` [RFC] Make hibernation work with lockdown Jarkko Sakkinen

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox