qemu-devel.nongnu.org archive mirror
 help / color / mirror / Atom feed
From: Stefan Berger <stefanb@linux.vnet.ibm.com>
To: "Michael S. Tsirkin" <mst@redhat.com>,
	Igor Mammedov <imammedo@redhat.com>
Cc: safford@watson.ibm.com, qemu-devel@nongnu.org, quan.xu@intel.com
Subject: Re: [Qemu-devel] [PATCH 0/5] Extend TPM support with a QEMU-external TPM
Date: Thu, 16 Apr 2015 15:21:18 -0400	[thread overview]
Message-ID: <55300BAE.5050800@linux.vnet.ibm.com> (raw)
In-Reply-To: <20150416205335-mutt-send-email-mst@redhat.com>

On 04/16/2015 02:55 PM, Michael S. Tsirkin wrote:
> On Thu, Apr 16, 2015 at 03:35:06PM +0200, Igor Mammedov wrote:
>> On Wed, 15 Apr 2015 18:38:43 -0400
>> Stefan Berger <stefanb@linux.vnet.ibm.com> wrote:
>>
>>> The following series of patches extends TPM support with an
>>> external TPM that offers a Linux CUSE (character device in userspace)
>>> interface. This TPM lets each VM access its own private vTPM.
>>> The CUSE TPM supports suspend/resume and migration. Much
>>> out-of-band functionality necessary to control the CUSE TPM is
>>> implemented using ioctl's.
>>>
>>> The series extends the TPM support so far that most functionality of
>>> TPM support on a physical platform is now available to each x86 VM,
>>> this includes the Physical Presence Interface support that has
>>> its counter-part in the SeaBIOS and is implemented using ACPI.
>>>
>>> http://www.seabios.org/pipermail/seabios/2015-March/008978.html
>> is it already merged?
>>
>> Is it possible to use MMIO region instead of allocating tpm_ppi_anchor
>> and tpm_ppi in BIOS memory?
>> That would simplify BIOS part a bit and significantly simplify ACPI code
>> as most of it is dealing with figuring out address of tpm_ppi.
> Which (if it works) I guess brings us back to the idea of using
> a pci device with a bar where we can stick tpm+vm id+whatever?

Well, at least the current implementation works with these patches + 
CUSE TPM + patched SeaBIOS .

So the PCI bar does not get reset during a machine reboot and thus 
preserves values? I did not model the TPM TIS as a PCI device, since it 
typically is not such a device, but a LPC devices (close to ISA type of 
device).

If we wanted to achieve that this method also works on real hardware, 
with SeaBIOS running piggy-backed on coreboot, then we shouldn't assume 
a PCI device, since it won't be. Otherwise, what are we trying to 
achieve? Is the ACPI code the problem?

     Stefan

      reply	other threads:[~2015-04-16 19:21 UTC|newest]

Thread overview: 21+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2015-04-15 22:38 [Qemu-devel] [PATCH 0/5] Extend TPM support with a QEMU-external TPM Stefan Berger
2015-04-15 22:38 ` [Qemu-devel] [PATCH 1/5] Provide support for the CUSE TPM Stefan Berger
2015-04-15 22:38 ` [Qemu-devel] [PATCH 2/5] Support Physical Presence Interface Spec Stefan Berger
2015-04-15 22:38 ` [Qemu-devel] [PATCH 3/5] Introduce condition to notifiy waiters of completed command Stefan Berger
2015-04-15 22:38 ` [Qemu-devel] [PATCH 4/5] Introduce condition in TPM backend for notification Stefan Berger
2015-04-15 22:38 ` [Qemu-devel] [PATCH 5/5] Add support for VM suspend/resume for TPM TIS Stefan Berger
2015-04-16 13:35 ` [Qemu-devel] [PATCH 0/5] Extend TPM support with a QEMU-external TPM Igor Mammedov
2015-04-16 14:05   ` Stefan Berger
2015-04-22  7:00     ` Igor Mammedov
2015-04-22 18:18       ` Stefan Berger
2015-04-29  9:06         ` Igor Mammedov
2015-04-29 16:42           ` Stefan Berger
2015-05-04  9:16             ` Igor Mammedov
2015-05-04 15:22               ` Stefan Berger
2015-05-04 16:16                 ` Kevin O'Connor
2015-05-04 18:39                   ` Stefan Berger
2015-05-04 21:41                     ` Igor Mammedov
2015-05-05  2:50                       ` Kevin O'Connor
2015-05-05 17:42                         ` Stefan Berger
2015-04-16 18:55   ` Michael S. Tsirkin
2015-04-16 19:21     ` Stefan Berger [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=55300BAE.5050800@linux.vnet.ibm.com \
    --to=stefanb@linux.vnet.ibm.com \
    --cc=imammedo@redhat.com \
    --cc=mst@redhat.com \
    --cc=qemu-devel@nongnu.org \
    --cc=quan.xu@intel.com \
    --cc=safford@watson.ibm.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).