OP-TEE Archive on lore.kernel.org
 help / color / mirror / Atom feed
* [v2,0/4] rpmb subsystem, uapi and virtio-rpmb driver
@ 2023-05-29 23:23 Shyam Saini
  0 siblings, 0 replies; only message in thread
From: Shyam Saini @ 2023-05-29 23:23 UTC (permalink / raw)
  To: op-tee

[-- Attachment #1: Type: text/plain, Size: 880 bytes --]

Hi Alex,


Are you still working on it or planning to resubmit it ?

[1] The current optee tee kernel driver implementation doesn't work when
IMA is used with optee implemented ftpm.

The ftpm has dependency on tee-supplicant which comes once the user-space
is up and running and IMA attestation happens at boot time and it requires
to extend ftpm PCRs.

But IMA can't use PCRs if ftpm use secure emmc RPMB partition. As optee
can only access RPMB via tee-supplicant(user space). So, there should
be a fast path to allow optee os to access the RPMB parititon without
waiting for user-space the tee supplicant.

To achieve this fast path linux optee driver and mmc driver needs
some work and finally it will need RPMB driver which you posted.

Please let me know what's your plan on this.

[1] https://optee.readthedocs.io/en/latest/architecture/secure_storage.html

Thanks,
Shyam

^ permalink raw reply	[flat|nested] only message in thread

only message in thread, other threads:[~2023-05-29 23:23 UTC | newest]

Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2023-05-29 23:23 [v2,0/4] rpmb subsystem, uapi and virtio-rpmb driver Shyam Saini

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox