Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1588008

Re: [tpmdd-devel] [PATCH v2 6/7] tpm: expose spaces via a device link /dev/tpms<n>

From James Bottomley <James.Bottomley@HansenPartnership.com>
Newsgroups linux.kernel
Subject Re: [tpmdd-devel] [PATCH v2 6/7] tpm: expose spaces via a device link /dev/tpms<n>
Date 2017-02-25 00:50 +0100
Message-ID <texMC-7D1-5@gated-at.bofh.it> (permalink)
References (5 earlier) <tesDg-3VB-5@gated-at.bofh.it> <teuF4-5q2-19@gated-at.bofh.it> <tev85-5AX-3@gated-at.bofh.it> <tex9T-7mc-7@gated-at.bofh.it> <textf-7sW-7@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


On Fri, 2017-02-24 at 16:23 -0700, Jason Gunthorpe wrote:
> On Fri, Feb 24, 2017 at 06:01:00PM -0500, James Bottomley wrote:
> 
> > Well, as a glib answer, I'd say the TPM is a device, so the thing 
> > which restricts device access to containers is the device cgroup 
> > ... that's what we should be plugging into.  I'd have to look, but 
> > I suspect the device cgroup basically operates on device node 
> > appearance, so it should "just work"(tm).  I can explore when I'm
> > back home.
> 
> Seems reasonable..
> 
> It just seems confusing to call something a namespace that isn't also
> a CLONE_NEW* option..

Well, there's namespace behaviour and then there's how you enter them. 
 We have namespace behaviour with the /dev/tpms<n> but the namespace is
entered on opening the device, even if the same process opens the
device more than once.  So we have namespace behaviour with a non clone
entry mechanism.  Since we're namespaceing a device, that seems to me
to be the correct semantic.

> FWIW more background on the topic:
> 
> Stefan was concerned about information leakage via sysfs of TPM data,
> eg that a container could still touch the host's TPM. I wonder if
> device cgroup could be extended to block access to the sysfs
> directories containing a disallowed 'dev' ?

It doesn't need to.  The sysfs entries (those that ask the TPM
something) are surrounded by chip->tpm_mutex, so when it asks, we know
all the spaces are context saved (i.e. the only TPM visible state is
global not anything space local).

> I was also wondering about kernel use from within the container -
> all kernel consumers are locked to physical tpm0.. But maybe the
> kernel can consult the right device cgroup to find an allowed TPM?

I'd use the device cgroup to determine what's allowable per container
(i.e. what tpm you can see) then within the container I'd open the
tpms<n> device ... because the TPM volatile storage is so tiny its not
inconceivable that multiple processes, even within a single container,
need access ... and they'd each need their own "namespace" (which they
get with the current model).  However, this is opinion ... we should
try it out and see what works best.

James

Back to linux.kernel | Previous | NextPrevious in thread | Next in thread | Find similar | Unroll thread


Thread

[PATCH v2 0/7] in-kernel resource manager Jarkko Sakkinen <jarkko.sakkinen@linux.intel.com> - 2017-02-16 20:30 +0100
  [PATCH v2 1/7] tpm: move length validation to tpm_transmit() Jarkko Sakkinen <jarkko.sakkinen@linux.intel.com> - 2017-02-16 20:30 +0100
  [PATCH v2 7/7] tpm2: add session handle context saving and restoring to the space code Jarkko Sakkinen <jarkko.sakkinen@linux.intel.com> - 2017-02-16 20:30 +0100
    Re: [PATCH v2 7/7] tpm2: add session handle context saving and  restoring to the space code Jarkko Sakkinen <jarkko.sakkinen@linux.intel.com> - 2017-02-23 10:10 +0100
  [PATCH v2 6/7] tpm: expose spaces via a device link /dev/tpms<n> Jarkko Sakkinen <jarkko.sakkinen@linux.intel.com> - 2017-02-16 20:30 +0100
    Re: [PATCH v2 6/7] tpm: expose spaces via a device link /dev/tpms<n> Jarkko Sakkinen <jarkko.sakkinen@linux.intel.com> - 2017-02-23 10:10 +0100
      Re: [PATCH v2 6/7] tpm: expose spaces via a device link /dev/tpms<n> James Bottomley <James.Bottomley@HansenPartnership.com> - 2017-02-24 14:10 +0100
        Re: [PATCH v2 6/7] tpm: expose spaces via a device link /dev/tpms<n> Jarkko Sakkinen <jarkko.sakkinen@linux.intel.com> - 2017-02-24 18:40 +0100
          Re: [PATCH v2 6/7] tpm: expose spaces via a device link /dev/tpms<n> Jason Gunthorpe <jgunthorpe@obsidianresearch.com> - 2017-02-24 19:20 +0100
            Re: [PATCH v2 6/7] tpm: expose spaces via a device link /dev/tpms<n> James Bottomley <James.Bottomley@HansenPartnership.com> - 2017-02-24 21:30 +0100
              Re: [PATCH v2 6/7] tpm: expose spaces via a device link /dev/tpms<n> Jason Gunthorpe <jgunthorpe@obsidianresearch.com> - 2017-02-24 22:00 +0100
                Re: [tpmdd-devel] [PATCH v2 6/7] tpm: expose spaces via a device  link /dev/tpms<n> James Bottomley <James.Bottomley@HansenPartnership.com> - 2017-02-25 00:10 +0100
                Re: [tpmdd-devel] [PATCH v2 6/7] tpm: expose spaces via a device  link /dev/tpms<n> Jason Gunthorpe <jgunthorpe@obsidianresearch.com> - 2017-02-25 00:30 +0100
                Re: [tpmdd-devel] [PATCH v2 6/7] tpm: expose spaces via a device  link /dev/tpms<n> James Bottomley <James.Bottomley@HansenPartnership.com> - 2017-02-25 00:50 +0100
                Re: [tpmdd-devel] [PATCH v2 6/7] tpm: expose spaces via a device  link /dev/tpms<n> Jason Gunthorpe <jgunthorpe@obsidianresearch.com> - 2017-02-25 01:30 +0100
                Re: [tpmdd-devel] [PATCH v2 6/7] tpm: expose spaces via a device  link /dev/tpms<n> James Bottomley <James.Bottomley@HansenPartnership.com> - 2017-02-25 18:10 +0100
                Re: [tpmdd-devel] [PATCH v2 6/7] tpm: expose spaces via a device  link /dev/tpms<n> Jason Gunthorpe <jgunthorpe@obsidianresearch.com> - 2017-02-27 18:40 +0100
        Re: [PATCH v2 6/7] tpm: expose spaces via a device link /dev/tpms<n> Jarkko Sakkinen <jarkko.sakkinen@linux.intel.com> - 2017-02-26 12:50 +0100
          Re: [PATCH v2 6/7] tpm: expose spaces via a device link /dev/tpms<n> "Dr. Greg Wettstein" <greg@enjellic.com> - 2017-02-26 19:40 +0100
            Re: [PATCH v2 6/7] tpm: expose spaces via a device link /dev/tpms<n> Ken Goldman <kgold@linux.vnet.ibm.com> - 2017-02-28 20:00 +0100
          Re: [PATCH v2 6/7] tpm: expose spaces via a device link /dev/tpms<n> Jason Gunthorpe <jgunthorpe@obsidianresearch.com> - 2017-02-27 18:40 +0100
    Re: [tpmdd-devel] [PATCH v2 6/7] tpm: expose spaces via a device link  /dev/tpms<n> Nayna <nayna@linux.vnet.ibm.com> - 2017-02-24 08:10 +0100
      Re: [tpmdd-devel] [PATCH v2 6/7] tpm: expose spaces via a device  link /dev/tpms<n> James Bottomley <James.Bottomley@HansenPartnership.com> - 2017-02-24 14:00 +0100
        Re: [tpmdd-devel] [PATCH v2 6/7] tpm: expose spaces via a device link  /dev/tpms<n> Nayna <nayna@linux.vnet.ibm.com> - 2017-02-27 12:50 +0100
          Re: [tpmdd-devel] [PATCH v2 6/7] tpm: expose spaces via a device  link /dev/tpms<n> James Bottomley <James.Bottomley@HansenPartnership.com> - 2017-02-27 16:10 +0100
  [PATCH v2 4/7] tpm: infrastructure for TPM spaces Jarkko Sakkinen <jarkko.sakkinen@linux.intel.com> - 2017-02-16 20:30 +0100
    Re: [tpmdd-devel] [PATCH v2 4/7] tpm: infrastructure for TPM spaces Nayna <nayna@linux.vnet.ibm.com> - 2017-02-21 19:30 +0100
      Re: [tpmdd-devel] [PATCH v2 4/7] tpm: infrastructure for TPM spaces James Bottomley <James.Bottomley@HansenPartnership.com> - 2017-02-22 18:40 +0100
        Re: [tpmdd-devel] [PATCH v2 4/7] tpm: infrastructure for TPM spaces Ken Goldman <kgold@linux.vnet.ibm.com> - 2017-02-22 22:00 +0100
      Re: [tpmdd-devel] [PATCH v2 4/7] tpm: infrastructure for TPM spaces Jarkko Sakkinen <jarkko.sakkinen@linux.intel.com> - 2017-02-22 22:20 +0100
      Re: [tpmdd-devel] [PATCH v2 4/7] tpm: infrastructure for TPM spaces Ken Goldman <kgold@linux.vnet.ibm.com> - 2017-02-22 22:30 +0100
    Re: [PATCH v2 4/7] tpm: infrastructure for TPM spaces James Bottomley <James.Bottomley@HansenPartnership.com> - 2017-02-24 14:00 +0100
      Re: [PATCH v2 4/7] tpm: infrastructure for TPM spaces Jarkko Sakkinen <jarkko.sakkinen@linux.intel.com> - 2017-02-24 18:10 +0100

csiph-web