Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1632859 > unrolled thread

[PATCH v2 0/3] Extend the vTPM proxy driver to pass locality to emulator

Started byStefan Berger <stefanb@linux.vnet.ibm.com>
First post2017-04-28 15:10 +0200
Last post2017-05-04 11:20 +0200
Articles 8 — 2 participants

Back to article view | Back to linux.kernel


Contents

  [PATCH v2 0/3]  Extend the vTPM proxy driver to pass locality to emulator Stefan Berger <stefanb@linux.vnet.ibm.com> - 2017-04-28 15:10 +0200
    [PATCH v2 2/3] tpm: vtpm_proxy: Implement request_locality Stefan Berger <stefanb@linux.vnet.ibm.com> - 2017-04-28 15:10 +0200
    [PATCH v2 1/3] tpm: vtpm_proxy: Add ioctl to get supported flags Stefan Berger <stefanb@linux.vnet.ibm.com> - 2017-04-28 15:10 +0200
      Re: [PATCH v2 1/3] tpm: vtpm_proxy: Add ioctl to get supported flags Jarkko Sakkinen <jarkko.sakkinen@linux.intel.com> - 2017-05-04 00:40 +0200
    Re: [PATCH v2 0/3]  Extend the vTPM proxy driver to pass locality to  emulator Jarkko Sakkinen <jarkko.sakkinen@linux.intel.com> - 2017-04-29 14:00 +0200
    Re: [PATCH v2 0/3]  Extend the vTPM proxy driver to pass locality to  emulator Jarkko Sakkinen <jarkko.sakkinen@linux.intel.com> - 2017-05-04 00:40 +0200
      Re: [PATCH v2 0/3] Extend the vTPM proxy driver to pass locality to  emulator Stefan Berger <stefanb@linux.vnet.ibm.com> - 2017-05-04 01:50 +0200
        Re: [PATCH v2 0/3] Extend the vTPM proxy driver to pass locality to  emulator Jarkko Sakkinen <jarkko.sakkinen@linux.intel.com> - 2017-05-04 11:20 +0200

#1632859 — [PATCH v2 0/3] Extend the vTPM proxy driver to pass locality to emulator

FromStefan Berger <stefanb@linux.vnet.ibm.com>
Date2017-04-28 15:10 +0200
Subject[PATCH v2 0/3] Extend the vTPM proxy driver to pass locality to emulator
Message-ID<tBdON-7J4-7@gated-at.bofh.it>
The purpose of this series of patches is to enable the passing of the locality
a command is executing in to a TPM emulator. To enable this we introduce a new
flag for the device creation ioctl that requests that the locality be prepended
to every command. For applications to check which flags the driver supports, we
add a new ioctl that returns a bitmask of supported flags.

v1->v2:
  - fixed return value from function in patch 3/3


Stefan Berger (3):
  tpm: vtpm_proxy: Add ioctl to get supported flags
  tpm: vtpm_proxy: Implement request_locality
  tpm: vtpm_proxy: Add ioctl to request locality prepended to command

 drivers/char/tpm/tpm_vtpm_proxy.c | 53 +++++++++++++++++++++++++++++++++++----
 include/uapi/linux/vtpm_proxy.h   | 15 ++++++++++-
 2 files changed, 62 insertions(+), 6 deletions(-)

-- 
2.4.3

[toc] | [next] | [standalone]


#1632864 — [PATCH v2 2/3] tpm: vtpm_proxy: Implement request_locality

FromStefan Berger <stefanb@linux.vnet.ibm.com>
Date2017-04-28 15:10 +0200
Subject[PATCH v2 2/3] tpm: vtpm_proxy: Implement request_locality
Message-ID<tBdOO-7J4-21@gated-at.bofh.it>
In reply to#1632859
Implement the request_locality function. Accept all localities assuming
that the emulator handling the localities will check for a valid locality.

Signed-off-by: Stefan Berger <stefanb@linux.vnet.ibm.com>
---
 drivers/char/tpm/tpm_vtpm_proxy.c | 6 ++++++
 1 file changed, 6 insertions(+)

diff --git a/drivers/char/tpm/tpm_vtpm_proxy.c b/drivers/char/tpm/tpm_vtpm_proxy.c
index fb4d207..48b9818 100644
--- a/drivers/char/tpm/tpm_vtpm_proxy.c
+++ b/drivers/char/tpm/tpm_vtpm_proxy.c
@@ -371,6 +371,11 @@ static bool vtpm_proxy_tpm_req_canceled(struct tpm_chip  *chip, u8 status)
 	return ret;
 }
 
+static int vtpm_proxy_request_locality(struct tpm_chip *chip, int locality)
+{
+	return locality;
+}
+
 static const struct tpm_class_ops vtpm_proxy_tpm_ops = {
 	.flags = TPM_OPS_AUTO_STARTUP,
 	.recv = vtpm_proxy_tpm_op_recv,
@@ -380,6 +385,7 @@ static const struct tpm_class_ops vtpm_proxy_tpm_ops = {
 	.req_complete_mask = VTPM_PROXY_REQ_COMPLETE_FLAG,
 	.req_complete_val = VTPM_PROXY_REQ_COMPLETE_FLAG,
 	.req_canceled = vtpm_proxy_tpm_req_canceled,
+	.request_locality = vtpm_proxy_request_locality,
 };
 
 /*
-- 
2.4.3

[toc] | [prev] | [next] | [standalone]


#1632865 — [PATCH v2 1/3] tpm: vtpm_proxy: Add ioctl to get supported flags

FromStefan Berger <stefanb@linux.vnet.ibm.com>
Date2017-04-28 15:10 +0200
Subject[PATCH v2 1/3] tpm: vtpm_proxy: Add ioctl to get supported flags
Message-ID<tBdOO-7J4-25@gated-at.bofh.it>
In reply to#1632859
Add an ioctl to get the supported flags.

Signed-off-by: Stefan Berger <stefanb@linux.vnet.ibm.com>
---
 drivers/char/tpm/tpm_vtpm_proxy.c | 29 +++++++++++++++++++++++++++++
 include/uapi/linux/vtpm_proxy.h   | 11 +++++++++++
 2 files changed, 40 insertions(+)

diff --git a/drivers/char/tpm/tpm_vtpm_proxy.c b/drivers/char/tpm/tpm_vtpm_proxy.c
index 751059d..fb4d207 100644
--- a/drivers/char/tpm/tpm_vtpm_proxy.c
+++ b/drivers/char/tpm/tpm_vtpm_proxy.c
@@ -592,6 +592,33 @@ static long vtpmx_ioc_new_dev(struct file *file, unsigned int ioctl,
 	return 0;
 }
 
+/**
+ * vtpmx_ioc_get_supt_flags - handler for the %VTPM_PROXY_IOC_GET_SUPT_FLAGS
+ *                            ioctl
+ * @file:	/dev/vtpmx
+ * @ioctl:	the ioctl number
+ * @arg:	pointer to the struct vtpmx_proxy_get_supt_flags
+ *
+ * Return the bitfield of supported flags
+ */
+static long vtpmx_ioc_get_supt_flags(struct file *file, unsigned int ioctl,
+				     unsigned long arg)
+{
+	void __user *argp = (void __user *)arg;
+	struct vtpm_proxy_supt_flags __user *vtpm_supt_flags_p = argp;
+	struct vtpm_proxy_supt_flags flags = {
+		.flags = VTPM_PROXY_FLAGS_ALL,
+	};
+
+	if (!capable(CAP_SYS_ADMIN))
+		return -EPERM;
+
+	if (copy_to_user(vtpm_supt_flags_p, &flags, sizeof(flags)))
+		return -EFAULT;
+
+	return 0;
+}
+
 /*
  * vtpmx_fops_ioctl: ioctl on /dev/vtpmx
  *
@@ -604,6 +631,8 @@ static long vtpmx_fops_ioctl(struct file *f, unsigned int ioctl,
 	switch (ioctl) {
 	case VTPM_PROXY_IOC_NEW_DEV:
 		return vtpmx_ioc_new_dev(f, ioctl, arg);
+	case VTPM_PROXY_IOC_GET_SUPT_FLAGS:
+		return vtpmx_ioc_get_supt_flags(f, ioctl, arg);
 	default:
 		return -ENOIOCTLCMD;
 	}
diff --git a/include/uapi/linux/vtpm_proxy.h b/include/uapi/linux/vtpm_proxy.h
index a69e991..83e64e7 100644
--- a/include/uapi/linux/vtpm_proxy.h
+++ b/include/uapi/linux/vtpm_proxy.h
@@ -44,6 +44,17 @@ struct vtpm_proxy_new_dev {
 	__u32 minor;         /* output */
 };
 
+/**
+ * struct vtpm_proxy_supt_flags - parameter structure for the
+ *                                %VTPM_PROXY_IOC_GET_SUPT_FLAGS ioctl
+ * @flags: flags supported by the vtpm proxy driver
+ */
+struct vtpm_proxy_supt_flags {
+	__u32 flags;         /* output */
+};
+
 #define VTPM_PROXY_IOC_NEW_DEV	_IOWR(0xa1, 0x00, struct vtpm_proxy_new_dev)
+#define VTPM_PROXY_IOC_GET_SUPT_FLAGS \
+				_IOR(0xa1, 0x01, struct vtpm_proxy_supt_flags)
 
 #endif /* _UAPI_LINUX_VTPM_PROXY_H */
-- 
2.4.3

[toc] | [prev] | [next] | [standalone]


#1635325 — Re: [PATCH v2 1/3] tpm: vtpm_proxy: Add ioctl to get supported flags

FromJarkko Sakkinen <jarkko.sakkinen@linux.intel.com>
Date2017-05-04 00:40 +0200
SubjectRe: [PATCH v2 1/3] tpm: vtpm_proxy: Add ioctl to get supported flags
Message-ID<tDb69-381-17@gated-at.bofh.it>
In reply to#1632865
On Fri, Apr 28, 2017 at 09:02:16AM -0400, Stefan Berger wrote:
> Add an ioctl to get the supported flags.
> 
> Signed-off-by: Stefan Berger <stefanb@linux.vnet.ibm.com>

The commit message is a bit lacking on explaining things like why we
need it.

> ---
>  drivers/char/tpm/tpm_vtpm_proxy.c | 29 +++++++++++++++++++++++++++++
>  include/uapi/linux/vtpm_proxy.h   | 11 +++++++++++
>  2 files changed, 40 insertions(+)
> 
> diff --git a/drivers/char/tpm/tpm_vtpm_proxy.c b/drivers/char/tpm/tpm_vtpm_proxy.c
> index 751059d..fb4d207 100644
> --- a/drivers/char/tpm/tpm_vtpm_proxy.c
> +++ b/drivers/char/tpm/tpm_vtpm_proxy.c
> @@ -592,6 +592,33 @@ static long vtpmx_ioc_new_dev(struct file *file, unsigned int ioctl,
>  	return 0;
>  }
>  
> +/**
> + * vtpmx_ioc_get_supt_flags - handler for the %VTPM_PROXY_IOC_GET_SUPT_FLAGS
> + *                            ioctl
> + * @file:	/dev/vtpmx
> + * @ioctl:	the ioctl number
> + * @arg:	pointer to the struct vtpmx_proxy_get_supt_flags
> + *
> + * Return the bitfield of supported flags
> + */
> +static long vtpmx_ioc_get_supt_flags(struct file *file, unsigned int ioctl,
> +				     unsigned long arg)
> +{
> +	void __user *argp = (void __user *)arg;
> +	struct vtpm_proxy_supt_flags __user *vtpm_supt_flags_p = argp;
> +	struct vtpm_proxy_supt_flags flags = {
> +		.flags = VTPM_PROXY_FLAGS_ALL,
> +	};
> +
> +	if (!capable(CAP_SYS_ADMIN))
> +		return -EPERM;
> +
> +	if (copy_to_user(vtpm_supt_flags_p, &flags, sizeof(flags)))
> +		return -EFAULT;
> +
> +	return 0;
> +}
> +
>  /*
>   * vtpmx_fops_ioctl: ioctl on /dev/vtpmx
>   *
> @@ -604,6 +631,8 @@ static long vtpmx_fops_ioctl(struct file *f, unsigned int ioctl,
>  	switch (ioctl) {
>  	case VTPM_PROXY_IOC_NEW_DEV:
>  		return vtpmx_ioc_new_dev(f, ioctl, arg);
> +	case VTPM_PROXY_IOC_GET_SUPT_FLAGS:
> +		return vtpmx_ioc_get_supt_flags(f, ioctl, arg);
>  	default:
>  		return -ENOIOCTLCMD;
>  	}
> diff --git a/include/uapi/linux/vtpm_proxy.h b/include/uapi/linux/vtpm_proxy.h
> index a69e991..83e64e7 100644
> --- a/include/uapi/linux/vtpm_proxy.h
> +++ b/include/uapi/linux/vtpm_proxy.h
> @@ -44,6 +44,17 @@ struct vtpm_proxy_new_dev {
>  	__u32 minor;         /* output */
>  };
>  
> +/**
> + * struct vtpm_proxy_supt_flags - parameter structure for the
> + *                                %VTPM_PROXY_IOC_GET_SUPT_FLAGS ioctl
> + * @flags: flags supported by the vtpm proxy driver
> + */
> +struct vtpm_proxy_supt_flags {
> +	__u32 flags;         /* output */
> +};
> +
>  #define VTPM_PROXY_IOC_NEW_DEV	_IOWR(0xa1, 0x00, struct vtpm_proxy_new_dev)
> +#define VTPM_PROXY_IOC_GET_SUPT_FLAGS \
> +				_IOR(0xa1, 0x01, struct vtpm_proxy_supt_flags)
>  
>  #endif /* _UAPI_LINUX_VTPM_PROXY_H */
> -- 
> 2.4.3
> 

/Jarkko

[toc] | [prev] | [next] | [standalone]


#1633295 — Re: [PATCH v2 0/3] Extend the vTPM proxy driver to pass locality to emulator

FromJarkko Sakkinen <jarkko.sakkinen@linux.intel.com>
Date2017-04-29 14:00 +0200
SubjectRe: [PATCH v2 0/3] Extend the vTPM proxy driver to pass locality to emulator
Message-ID<tBzcB-5Mb-9@gated-at.bofh.it>
In reply to#1632859
I will get into this with detail after 4.12-rc1.

/Jarkko

On Fri, Apr 28, 2017 at 09:02:15AM -0400, Stefan Berger wrote:
> The purpose of this series of patches is to enable the passing of the locality
> a command is executing in to a TPM emulator. To enable this we introduce a new
> flag for the device creation ioctl that requests that the locality be prepended
> to every command. For applications to check which flags the driver supports, we
> add a new ioctl that returns a bitmask of supported flags.
> 
> v1->v2:
>   - fixed return value from function in patch 3/3
> 
> 
> Stefan Berger (3):
>   tpm: vtpm_proxy: Add ioctl to get supported flags
>   tpm: vtpm_proxy: Implement request_locality
>   tpm: vtpm_proxy: Add ioctl to request locality prepended to command
> 
>  drivers/char/tpm/tpm_vtpm_proxy.c | 53 +++++++++++++++++++++++++++++++++++----
>  include/uapi/linux/vtpm_proxy.h   | 15 ++++++++++-
>  2 files changed, 62 insertions(+), 6 deletions(-)
> 
> -- 
> 2.4.3
> 

[toc] | [prev] | [next] | [standalone]


#1635321 — Re: [PATCH v2 0/3] Extend the vTPM proxy driver to pass locality to emulator

FromJarkko Sakkinen <jarkko.sakkinen@linux.intel.com>
Date2017-05-04 00:40 +0200
SubjectRe: [PATCH v2 0/3] Extend the vTPM proxy driver to pass locality to emulator
Message-ID<tDb69-381-5@gated-at.bofh.it>
In reply to#1632859
On Fri, Apr 28, 2017 at 09:02:15AM -0400, Stefan Berger wrote:
> The purpose of this series of patches is to enable the passing of the locality
> a command is executing in to a TPM emulator. To enable this we introduce a new
> flag for the device creation ioctl that requests that the locality be prepended
> to every command. For applications to check which flags the driver supports, we
> add a new ioctl that returns a bitmask of supported flags.

This is a weird change proposal as you could use tpm_vtpm_proxy for
other than some TPM emulator.

> 
> v1->v2:
>   - fixed return value from function in patch 3/3
> 
> 
> Stefan Berger (3):
>   tpm: vtpm_proxy: Add ioctl to get supported flags
>   tpm: vtpm_proxy: Implement request_locality
>   tpm: vtpm_proxy: Add ioctl to request locality prepended to command
> 
>  drivers/char/tpm/tpm_vtpm_proxy.c | 53 +++++++++++++++++++++++++++++++++++----
>  include/uapi/linux/vtpm_proxy.h   | 15 ++++++++++-
>  2 files changed, 62 insertions(+), 6 deletions(-)
> 
> -- 
> 2.4.3
> 

/Jarkko

[toc] | [prev] | [next] | [standalone]


#1635341 — Re: [PATCH v2 0/3] Extend the vTPM proxy driver to pass locality to emulator

FromStefan Berger <stefanb@linux.vnet.ibm.com>
Date2017-05-04 01:50 +0200
SubjectRe: [PATCH v2 0/3] Extend the vTPM proxy driver to pass locality to emulator
Message-ID<tDcbT-3QP-5@gated-at.bofh.it>
In reply to#1635321
On 05/03/2017 06:38 PM, Jarkko Sakkinen wrote:
> On Fri, Apr 28, 2017 at 09:02:15AM -0400, Stefan Berger wrote:
>> The purpose of this series of patches is to enable the passing of the locality
>> a command is executing in to a TPM emulator. To enable this we introduce a new
>> flag for the device creation ioctl that requests that the locality be prepended
>> to every command. For applications to check which flags the driver supports, we
>> add a new ioctl that returns a bitmask of supported flags.
> This is a weird change proposal as you could use tpm_vtpm_proxy for
> other than some TPM emulator.

I think in most cases the recipient of the TPM commands from the 
vtpm_proxy driver will be a TPM emulator. What do you have in mind?

>
>> v1->v2:
>>    - fixed return value from function in patch 3/3
>>
>>
>> Stefan Berger (3):
>>    tpm: vtpm_proxy: Add ioctl to get supported flags
>>    tpm: vtpm_proxy: Implement request_locality
>>    tpm: vtpm_proxy: Add ioctl to request locality prepended to command
>>
>>   drivers/char/tpm/tpm_vtpm_proxy.c | 53 +++++++++++++++++++++++++++++++++++----
>>   include/uapi/linux/vtpm_proxy.h   | 15 ++++++++++-
>>   2 files changed, 62 insertions(+), 6 deletions(-)
>>
>> -- 
>> 2.4.3
>>
> /Jarkko
> --
> To unsubscribe from this list: send the line "unsubscribe linux-security-module" in
> the body of a message to majordomo@vger.kernel.org
> More majordomo info at  http://vger.kernel.org/majordomo-info.html
>

[toc] | [prev] | [next] | [standalone]


#1635543 — Re: [PATCH v2 0/3] Extend the vTPM proxy driver to pass locality to emulator

FromJarkko Sakkinen <jarkko.sakkinen@linux.intel.com>
Date2017-05-04 11:20 +0200
SubjectRe: [PATCH v2 0/3] Extend the vTPM proxy driver to pass locality to emulator
Message-ID<tDl5x-1sT-53@gated-at.bofh.it>
In reply to#1635341
On Wed, May 03, 2017 at 07:42:06PM -0400, Stefan Berger wrote:
> On 05/03/2017 06:38 PM, Jarkko Sakkinen wrote:
> > On Fri, Apr 28, 2017 at 09:02:15AM -0400, Stefan Berger wrote:
> > > The purpose of this series of patches is to enable the passing of the locality
> > > a command is executing in to a TPM emulator. To enable this we introduce a new
> > > flag for the device creation ioctl that requests that the locality be prepended
> > > to every command. For applications to check which flags the driver supports, we
> > > add a new ioctl that returns a bitmask of supported flags.
> > This is a weird change proposal as you could use tpm_vtpm_proxy for
> > other than some TPM emulator.
> 
> I think in most cases the recipient of the TPM commands from the vtpm_proxy
> driver will be a TPM emulator. What do you have in mind?

Like using Intel SGX to implement TPM in ring-3. I've thought
vtpm_tpm_proxy as generic proxy that you can also use for emulators.

/Jarkko

[toc] | [prev] | [standalone]


Back to top | Article view | linux.kernel


csiph-web