Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1588000

Re: [tpmdd-devel] [PATCH v2 6/7] tpm: expose spaces via a device link /dev/tpms<n>

From Jason Gunthorpe <jgunthorpe@obsidianresearch.com>
Newsgroups linux.kernel
Subject Re: [tpmdd-devel] [PATCH v2 6/7] tpm: expose spaces via a device link /dev/tpms<n>
Date 2017-02-25 00:30 +0100
Message-ID <textf-7sW-7@gated-at.bofh.it> (permalink)
References (4 earlier) <tes0y-3rI-27@gated-at.bofh.it> <tesDg-3VB-5@gated-at.bofh.it> <teuF4-5q2-19@gated-at.bofh.it> <tev85-5AX-3@gated-at.bofh.it> <tex9T-7mc-7@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


On Fri, Feb 24, 2017 at 06:01:00PM -0500, James Bottomley wrote:

> Well, as a glib answer, I'd say the TPM is a device, so the thing which
> restricts device access to containers is the device cgroup ... that's
> what we should be plugging into.  I'd have to look, but I suspect the
> device cgroup basically operates on device node appearance, so it
> should "just work"(tm).  I can explore when I'm back home.

Seems reasonable..

It just seems confusing to call something a namespace that isn't also
a CLONE_NEW* option..

FWIW more background on the topic:

Stefan was concerned about information leakage via sysfs of TPM data,
eg that a container could still touch the host's TPM. I wonder if
device cgroup could be extended to block access to the sysfs
directories containing a disallowed 'dev' ?

I was also wondering about kernel use from within the container -
all kernel consumers are locked to physical tpm0.. But maybe the
kernel can consult the right device cgroup to find an allowed TPM?

Jason

Back to linux.kernel | Previous | NextPrevious in thread | Next in thread | Find similar | Unroll thread


Thread

[PATCH v2 0/7] in-kernel resource manager Jarkko Sakkinen <jarkko.sakkinen@linux.intel.com> - 2017-02-16 20:30 +0100
  [PATCH v2 1/7] tpm: move length validation to tpm_transmit() Jarkko Sakkinen <jarkko.sakkinen@linux.intel.com> - 2017-02-16 20:30 +0100
  [PATCH v2 7/7] tpm2: add session handle context saving and restoring to the space code Jarkko Sakkinen <jarkko.sakkinen@linux.intel.com> - 2017-02-16 20:30 +0100
    Re: [PATCH v2 7/7] tpm2: add session handle context saving and  restoring to the space code Jarkko Sakkinen <jarkko.sakkinen@linux.intel.com> - 2017-02-23 10:10 +0100
  [PATCH v2 6/7] tpm: expose spaces via a device link /dev/tpms<n> Jarkko Sakkinen <jarkko.sakkinen@linux.intel.com> - 2017-02-16 20:30 +0100
    Re: [PATCH v2 6/7] tpm: expose spaces via a device link /dev/tpms<n> Jarkko Sakkinen <jarkko.sakkinen@linux.intel.com> - 2017-02-23 10:10 +0100
      Re: [PATCH v2 6/7] tpm: expose spaces via a device link /dev/tpms<n> James Bottomley <James.Bottomley@HansenPartnership.com> - 2017-02-24 14:10 +0100
        Re: [PATCH v2 6/7] tpm: expose spaces via a device link /dev/tpms<n> Jarkko Sakkinen <jarkko.sakkinen@linux.intel.com> - 2017-02-24 18:40 +0100
          Re: [PATCH v2 6/7] tpm: expose spaces via a device link /dev/tpms<n> Jason Gunthorpe <jgunthorpe@obsidianresearch.com> - 2017-02-24 19:20 +0100
            Re: [PATCH v2 6/7] tpm: expose spaces via a device link /dev/tpms<n> James Bottomley <James.Bottomley@HansenPartnership.com> - 2017-02-24 21:30 +0100
              Re: [PATCH v2 6/7] tpm: expose spaces via a device link /dev/tpms<n> Jason Gunthorpe <jgunthorpe@obsidianresearch.com> - 2017-02-24 22:00 +0100
                Re: [tpmdd-devel] [PATCH v2 6/7] tpm: expose spaces via a device  link /dev/tpms<n> James Bottomley <James.Bottomley@HansenPartnership.com> - 2017-02-25 00:10 +0100
                Re: [tpmdd-devel] [PATCH v2 6/7] tpm: expose spaces via a device  link /dev/tpms<n> Jason Gunthorpe <jgunthorpe@obsidianresearch.com> - 2017-02-25 00:30 +0100
                Re: [tpmdd-devel] [PATCH v2 6/7] tpm: expose spaces via a device  link /dev/tpms<n> James Bottomley <James.Bottomley@HansenPartnership.com> - 2017-02-25 00:50 +0100
                Re: [tpmdd-devel] [PATCH v2 6/7] tpm: expose spaces via a device  link /dev/tpms<n> Jason Gunthorpe <jgunthorpe@obsidianresearch.com> - 2017-02-25 01:30 +0100
                Re: [tpmdd-devel] [PATCH v2 6/7] tpm: expose spaces via a device  link /dev/tpms<n> James Bottomley <James.Bottomley@HansenPartnership.com> - 2017-02-25 18:10 +0100
                Re: [tpmdd-devel] [PATCH v2 6/7] tpm: expose spaces via a device  link /dev/tpms<n> Jason Gunthorpe <jgunthorpe@obsidianresearch.com> - 2017-02-27 18:40 +0100
        Re: [PATCH v2 6/7] tpm: expose spaces via a device link /dev/tpms<n> Jarkko Sakkinen <jarkko.sakkinen@linux.intel.com> - 2017-02-26 12:50 +0100
          Re: [PATCH v2 6/7] tpm: expose spaces via a device link /dev/tpms<n> "Dr. Greg Wettstein" <greg@enjellic.com> - 2017-02-26 19:40 +0100
            Re: [PATCH v2 6/7] tpm: expose spaces via a device link /dev/tpms<n> Ken Goldman <kgold@linux.vnet.ibm.com> - 2017-02-28 20:00 +0100
          Re: [PATCH v2 6/7] tpm: expose spaces via a device link /dev/tpms<n> Jason Gunthorpe <jgunthorpe@obsidianresearch.com> - 2017-02-27 18:40 +0100
    Re: [tpmdd-devel] [PATCH v2 6/7] tpm: expose spaces via a device link  /dev/tpms<n> Nayna <nayna@linux.vnet.ibm.com> - 2017-02-24 08:10 +0100
      Re: [tpmdd-devel] [PATCH v2 6/7] tpm: expose spaces via a device  link /dev/tpms<n> James Bottomley <James.Bottomley@HansenPartnership.com> - 2017-02-24 14:00 +0100
        Re: [tpmdd-devel] [PATCH v2 6/7] tpm: expose spaces via a device link  /dev/tpms<n> Nayna <nayna@linux.vnet.ibm.com> - 2017-02-27 12:50 +0100
          Re: [tpmdd-devel] [PATCH v2 6/7] tpm: expose spaces via a device  link /dev/tpms<n> James Bottomley <James.Bottomley@HansenPartnership.com> - 2017-02-27 16:10 +0100
  [PATCH v2 4/7] tpm: infrastructure for TPM spaces Jarkko Sakkinen <jarkko.sakkinen@linux.intel.com> - 2017-02-16 20:30 +0100
    Re: [tpmdd-devel] [PATCH v2 4/7] tpm: infrastructure for TPM spaces Nayna <nayna@linux.vnet.ibm.com> - 2017-02-21 19:30 +0100
      Re: [tpmdd-devel] [PATCH v2 4/7] tpm: infrastructure for TPM spaces James Bottomley <James.Bottomley@HansenPartnership.com> - 2017-02-22 18:40 +0100
        Re: [tpmdd-devel] [PATCH v2 4/7] tpm: infrastructure for TPM spaces Ken Goldman <kgold@linux.vnet.ibm.com> - 2017-02-22 22:00 +0100
      Re: [tpmdd-devel] [PATCH v2 4/7] tpm: infrastructure for TPM spaces Jarkko Sakkinen <jarkko.sakkinen@linux.intel.com> - 2017-02-22 22:20 +0100
      Re: [tpmdd-devel] [PATCH v2 4/7] tpm: infrastructure for TPM spaces Ken Goldman <kgold@linux.vnet.ibm.com> - 2017-02-22 22:30 +0100
    Re: [PATCH v2 4/7] tpm: infrastructure for TPM spaces James Bottomley <James.Bottomley@HansenPartnership.com> - 2017-02-24 14:00 +0100
      Re: [PATCH v2 4/7] tpm: infrastructure for TPM spaces Jarkko Sakkinen <jarkko.sakkinen@linux.intel.com> - 2017-02-24 18:10 +0100

csiph-web