Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1632859 > unrolled thread
| Started by | Stefan Berger <stefanb@linux.vnet.ibm.com> |
|---|---|
| First post | 2017-04-28 15:10 +0200 |
| Last post | 2017-05-04 11:20 +0200 |
| Articles | 8 — 2 participants |
Back to article view | Back to linux.kernel
[PATCH v2 0/3] Extend the vTPM proxy driver to pass locality to emulator Stefan Berger <stefanb@linux.vnet.ibm.com> - 2017-04-28 15:10 +0200
[PATCH v2 2/3] tpm: vtpm_proxy: Implement request_locality Stefan Berger <stefanb@linux.vnet.ibm.com> - 2017-04-28 15:10 +0200
[PATCH v2 1/3] tpm: vtpm_proxy: Add ioctl to get supported flags Stefan Berger <stefanb@linux.vnet.ibm.com> - 2017-04-28 15:10 +0200
Re: [PATCH v2 1/3] tpm: vtpm_proxy: Add ioctl to get supported flags Jarkko Sakkinen <jarkko.sakkinen@linux.intel.com> - 2017-05-04 00:40 +0200
Re: [PATCH v2 0/3] Extend the vTPM proxy driver to pass locality to emulator Jarkko Sakkinen <jarkko.sakkinen@linux.intel.com> - 2017-04-29 14:00 +0200
Re: [PATCH v2 0/3] Extend the vTPM proxy driver to pass locality to emulator Jarkko Sakkinen <jarkko.sakkinen@linux.intel.com> - 2017-05-04 00:40 +0200
Re: [PATCH v2 0/3] Extend the vTPM proxy driver to pass locality to emulator Stefan Berger <stefanb@linux.vnet.ibm.com> - 2017-05-04 01:50 +0200
Re: [PATCH v2 0/3] Extend the vTPM proxy driver to pass locality to emulator Jarkko Sakkinen <jarkko.sakkinen@linux.intel.com> - 2017-05-04 11:20 +0200
| From | Stefan Berger <stefanb@linux.vnet.ibm.com> |
|---|---|
| Date | 2017-04-28 15:10 +0200 |
| Subject | [PATCH v2 0/3] Extend the vTPM proxy driver to pass locality to emulator |
| Message-ID | <tBdON-7J4-7@gated-at.bofh.it> |
The purpose of this series of patches is to enable the passing of the locality a command is executing in to a TPM emulator. To enable this we introduce a new flag for the device creation ioctl that requests that the locality be prepended to every command. For applications to check which flags the driver supports, we add a new ioctl that returns a bitmask of supported flags. v1->v2: - fixed return value from function in patch 3/3 Stefan Berger (3): tpm: vtpm_proxy: Add ioctl to get supported flags tpm: vtpm_proxy: Implement request_locality tpm: vtpm_proxy: Add ioctl to request locality prepended to command drivers/char/tpm/tpm_vtpm_proxy.c | 53 +++++++++++++++++++++++++++++++++++---- include/uapi/linux/vtpm_proxy.h | 15 ++++++++++- 2 files changed, 62 insertions(+), 6 deletions(-) -- 2.4.3
[toc] | [next] | [standalone]
| From | Stefan Berger <stefanb@linux.vnet.ibm.com> |
|---|---|
| Date | 2017-04-28 15:10 +0200 |
| Subject | [PATCH v2 2/3] tpm: vtpm_proxy: Implement request_locality |
| Message-ID | <tBdOO-7J4-21@gated-at.bofh.it> |
| In reply to | #1632859 |
Implement the request_locality function. Accept all localities assuming
that the emulator handling the localities will check for a valid locality.
Signed-off-by: Stefan Berger <stefanb@linux.vnet.ibm.com>
---
drivers/char/tpm/tpm_vtpm_proxy.c | 6 ++++++
1 file changed, 6 insertions(+)
diff --git a/drivers/char/tpm/tpm_vtpm_proxy.c b/drivers/char/tpm/tpm_vtpm_proxy.c
index fb4d207..48b9818 100644
--- a/drivers/char/tpm/tpm_vtpm_proxy.c
+++ b/drivers/char/tpm/tpm_vtpm_proxy.c
@@ -371,6 +371,11 @@ static bool vtpm_proxy_tpm_req_canceled(struct tpm_chip *chip, u8 status)
return ret;
}
+static int vtpm_proxy_request_locality(struct tpm_chip *chip, int locality)
+{
+ return locality;
+}
+
static const struct tpm_class_ops vtpm_proxy_tpm_ops = {
.flags = TPM_OPS_AUTO_STARTUP,
.recv = vtpm_proxy_tpm_op_recv,
@@ -380,6 +385,7 @@ static const struct tpm_class_ops vtpm_proxy_tpm_ops = {
.req_complete_mask = VTPM_PROXY_REQ_COMPLETE_FLAG,
.req_complete_val = VTPM_PROXY_REQ_COMPLETE_FLAG,
.req_canceled = vtpm_proxy_tpm_req_canceled,
+ .request_locality = vtpm_proxy_request_locality,
};
/*
--
2.4.3
[toc] | [prev] | [next] | [standalone]
| From | Stefan Berger <stefanb@linux.vnet.ibm.com> |
|---|---|
| Date | 2017-04-28 15:10 +0200 |
| Subject | [PATCH v2 1/3] tpm: vtpm_proxy: Add ioctl to get supported flags |
| Message-ID | <tBdOO-7J4-25@gated-at.bofh.it> |
| In reply to | #1632859 |
Add an ioctl to get the supported flags.
Signed-off-by: Stefan Berger <stefanb@linux.vnet.ibm.com>
---
drivers/char/tpm/tpm_vtpm_proxy.c | 29 +++++++++++++++++++++++++++++
include/uapi/linux/vtpm_proxy.h | 11 +++++++++++
2 files changed, 40 insertions(+)
diff --git a/drivers/char/tpm/tpm_vtpm_proxy.c b/drivers/char/tpm/tpm_vtpm_proxy.c
index 751059d..fb4d207 100644
--- a/drivers/char/tpm/tpm_vtpm_proxy.c
+++ b/drivers/char/tpm/tpm_vtpm_proxy.c
@@ -592,6 +592,33 @@ static long vtpmx_ioc_new_dev(struct file *file, unsigned int ioctl,
return 0;
}
+/**
+ * vtpmx_ioc_get_supt_flags - handler for the %VTPM_PROXY_IOC_GET_SUPT_FLAGS
+ * ioctl
+ * @file: /dev/vtpmx
+ * @ioctl: the ioctl number
+ * @arg: pointer to the struct vtpmx_proxy_get_supt_flags
+ *
+ * Return the bitfield of supported flags
+ */
+static long vtpmx_ioc_get_supt_flags(struct file *file, unsigned int ioctl,
+ unsigned long arg)
+{
+ void __user *argp = (void __user *)arg;
+ struct vtpm_proxy_supt_flags __user *vtpm_supt_flags_p = argp;
+ struct vtpm_proxy_supt_flags flags = {
+ .flags = VTPM_PROXY_FLAGS_ALL,
+ };
+
+ if (!capable(CAP_SYS_ADMIN))
+ return -EPERM;
+
+ if (copy_to_user(vtpm_supt_flags_p, &flags, sizeof(flags)))
+ return -EFAULT;
+
+ return 0;
+}
+
/*
* vtpmx_fops_ioctl: ioctl on /dev/vtpmx
*
@@ -604,6 +631,8 @@ static long vtpmx_fops_ioctl(struct file *f, unsigned int ioctl,
switch (ioctl) {
case VTPM_PROXY_IOC_NEW_DEV:
return vtpmx_ioc_new_dev(f, ioctl, arg);
+ case VTPM_PROXY_IOC_GET_SUPT_FLAGS:
+ return vtpmx_ioc_get_supt_flags(f, ioctl, arg);
default:
return -ENOIOCTLCMD;
}
diff --git a/include/uapi/linux/vtpm_proxy.h b/include/uapi/linux/vtpm_proxy.h
index a69e991..83e64e7 100644
--- a/include/uapi/linux/vtpm_proxy.h
+++ b/include/uapi/linux/vtpm_proxy.h
@@ -44,6 +44,17 @@ struct vtpm_proxy_new_dev {
__u32 minor; /* output */
};
+/**
+ * struct vtpm_proxy_supt_flags - parameter structure for the
+ * %VTPM_PROXY_IOC_GET_SUPT_FLAGS ioctl
+ * @flags: flags supported by the vtpm proxy driver
+ */
+struct vtpm_proxy_supt_flags {
+ __u32 flags; /* output */
+};
+
#define VTPM_PROXY_IOC_NEW_DEV _IOWR(0xa1, 0x00, struct vtpm_proxy_new_dev)
+#define VTPM_PROXY_IOC_GET_SUPT_FLAGS \
+ _IOR(0xa1, 0x01, struct vtpm_proxy_supt_flags)
#endif /* _UAPI_LINUX_VTPM_PROXY_H */
--
2.4.3
[toc] | [prev] | [next] | [standalone]
| From | Jarkko Sakkinen <jarkko.sakkinen@linux.intel.com> |
|---|---|
| Date | 2017-05-04 00:40 +0200 |
| Subject | Re: [PATCH v2 1/3] tpm: vtpm_proxy: Add ioctl to get supported flags |
| Message-ID | <tDb69-381-17@gated-at.bofh.it> |
| In reply to | #1632865 |
On Fri, Apr 28, 2017 at 09:02:16AM -0400, Stefan Berger wrote:
> Add an ioctl to get the supported flags.
>
> Signed-off-by: Stefan Berger <stefanb@linux.vnet.ibm.com>
The commit message is a bit lacking on explaining things like why we
need it.
> ---
> drivers/char/tpm/tpm_vtpm_proxy.c | 29 +++++++++++++++++++++++++++++
> include/uapi/linux/vtpm_proxy.h | 11 +++++++++++
> 2 files changed, 40 insertions(+)
>
> diff --git a/drivers/char/tpm/tpm_vtpm_proxy.c b/drivers/char/tpm/tpm_vtpm_proxy.c
> index 751059d..fb4d207 100644
> --- a/drivers/char/tpm/tpm_vtpm_proxy.c
> +++ b/drivers/char/tpm/tpm_vtpm_proxy.c
> @@ -592,6 +592,33 @@ static long vtpmx_ioc_new_dev(struct file *file, unsigned int ioctl,
> return 0;
> }
>
> +/**
> + * vtpmx_ioc_get_supt_flags - handler for the %VTPM_PROXY_IOC_GET_SUPT_FLAGS
> + * ioctl
> + * @file: /dev/vtpmx
> + * @ioctl: the ioctl number
> + * @arg: pointer to the struct vtpmx_proxy_get_supt_flags
> + *
> + * Return the bitfield of supported flags
> + */
> +static long vtpmx_ioc_get_supt_flags(struct file *file, unsigned int ioctl,
> + unsigned long arg)
> +{
> + void __user *argp = (void __user *)arg;
> + struct vtpm_proxy_supt_flags __user *vtpm_supt_flags_p = argp;
> + struct vtpm_proxy_supt_flags flags = {
> + .flags = VTPM_PROXY_FLAGS_ALL,
> + };
> +
> + if (!capable(CAP_SYS_ADMIN))
> + return -EPERM;
> +
> + if (copy_to_user(vtpm_supt_flags_p, &flags, sizeof(flags)))
> + return -EFAULT;
> +
> + return 0;
> +}
> +
> /*
> * vtpmx_fops_ioctl: ioctl on /dev/vtpmx
> *
> @@ -604,6 +631,8 @@ static long vtpmx_fops_ioctl(struct file *f, unsigned int ioctl,
> switch (ioctl) {
> case VTPM_PROXY_IOC_NEW_DEV:
> return vtpmx_ioc_new_dev(f, ioctl, arg);
> + case VTPM_PROXY_IOC_GET_SUPT_FLAGS:
> + return vtpmx_ioc_get_supt_flags(f, ioctl, arg);
> default:
> return -ENOIOCTLCMD;
> }
> diff --git a/include/uapi/linux/vtpm_proxy.h b/include/uapi/linux/vtpm_proxy.h
> index a69e991..83e64e7 100644
> --- a/include/uapi/linux/vtpm_proxy.h
> +++ b/include/uapi/linux/vtpm_proxy.h
> @@ -44,6 +44,17 @@ struct vtpm_proxy_new_dev {
> __u32 minor; /* output */
> };
>
> +/**
> + * struct vtpm_proxy_supt_flags - parameter structure for the
> + * %VTPM_PROXY_IOC_GET_SUPT_FLAGS ioctl
> + * @flags: flags supported by the vtpm proxy driver
> + */
> +struct vtpm_proxy_supt_flags {
> + __u32 flags; /* output */
> +};
> +
> #define VTPM_PROXY_IOC_NEW_DEV _IOWR(0xa1, 0x00, struct vtpm_proxy_new_dev)
> +#define VTPM_PROXY_IOC_GET_SUPT_FLAGS \
> + _IOR(0xa1, 0x01, struct vtpm_proxy_supt_flags)
>
> #endif /* _UAPI_LINUX_VTPM_PROXY_H */
> --
> 2.4.3
>
/Jarkko
[toc] | [prev] | [next] | [standalone]
| From | Jarkko Sakkinen <jarkko.sakkinen@linux.intel.com> |
|---|---|
| Date | 2017-04-29 14:00 +0200 |
| Subject | Re: [PATCH v2 0/3] Extend the vTPM proxy driver to pass locality to emulator |
| Message-ID | <tBzcB-5Mb-9@gated-at.bofh.it> |
| In reply to | #1632859 |
I will get into this with detail after 4.12-rc1. /Jarkko On Fri, Apr 28, 2017 at 09:02:15AM -0400, Stefan Berger wrote: > The purpose of this series of patches is to enable the passing of the locality > a command is executing in to a TPM emulator. To enable this we introduce a new > flag for the device creation ioctl that requests that the locality be prepended > to every command. For applications to check which flags the driver supports, we > add a new ioctl that returns a bitmask of supported flags. > > v1->v2: > - fixed return value from function in patch 3/3 > > > Stefan Berger (3): > tpm: vtpm_proxy: Add ioctl to get supported flags > tpm: vtpm_proxy: Implement request_locality > tpm: vtpm_proxy: Add ioctl to request locality prepended to command > > drivers/char/tpm/tpm_vtpm_proxy.c | 53 +++++++++++++++++++++++++++++++++++---- > include/uapi/linux/vtpm_proxy.h | 15 ++++++++++- > 2 files changed, 62 insertions(+), 6 deletions(-) > > -- > 2.4.3 >
[toc] | [prev] | [next] | [standalone]
| From | Jarkko Sakkinen <jarkko.sakkinen@linux.intel.com> |
|---|---|
| Date | 2017-05-04 00:40 +0200 |
| Subject | Re: [PATCH v2 0/3] Extend the vTPM proxy driver to pass locality to emulator |
| Message-ID | <tDb69-381-5@gated-at.bofh.it> |
| In reply to | #1632859 |
On Fri, Apr 28, 2017 at 09:02:15AM -0400, Stefan Berger wrote: > The purpose of this series of patches is to enable the passing of the locality > a command is executing in to a TPM emulator. To enable this we introduce a new > flag for the device creation ioctl that requests that the locality be prepended > to every command. For applications to check which flags the driver supports, we > add a new ioctl that returns a bitmask of supported flags. This is a weird change proposal as you could use tpm_vtpm_proxy for other than some TPM emulator. > > v1->v2: > - fixed return value from function in patch 3/3 > > > Stefan Berger (3): > tpm: vtpm_proxy: Add ioctl to get supported flags > tpm: vtpm_proxy: Implement request_locality > tpm: vtpm_proxy: Add ioctl to request locality prepended to command > > drivers/char/tpm/tpm_vtpm_proxy.c | 53 +++++++++++++++++++++++++++++++++++---- > include/uapi/linux/vtpm_proxy.h | 15 ++++++++++- > 2 files changed, 62 insertions(+), 6 deletions(-) > > -- > 2.4.3 > /Jarkko
[toc] | [prev] | [next] | [standalone]
| From | Stefan Berger <stefanb@linux.vnet.ibm.com> |
|---|---|
| Date | 2017-05-04 01:50 +0200 |
| Subject | Re: [PATCH v2 0/3] Extend the vTPM proxy driver to pass locality to emulator |
| Message-ID | <tDcbT-3QP-5@gated-at.bofh.it> |
| In reply to | #1635321 |
On 05/03/2017 06:38 PM, Jarkko Sakkinen wrote: > On Fri, Apr 28, 2017 at 09:02:15AM -0400, Stefan Berger wrote: >> The purpose of this series of patches is to enable the passing of the locality >> a command is executing in to a TPM emulator. To enable this we introduce a new >> flag for the device creation ioctl that requests that the locality be prepended >> to every command. For applications to check which flags the driver supports, we >> add a new ioctl that returns a bitmask of supported flags. > This is a weird change proposal as you could use tpm_vtpm_proxy for > other than some TPM emulator. I think in most cases the recipient of the TPM commands from the vtpm_proxy driver will be a TPM emulator. What do you have in mind? > >> v1->v2: >> - fixed return value from function in patch 3/3 >> >> >> Stefan Berger (3): >> tpm: vtpm_proxy: Add ioctl to get supported flags >> tpm: vtpm_proxy: Implement request_locality >> tpm: vtpm_proxy: Add ioctl to request locality prepended to command >> >> drivers/char/tpm/tpm_vtpm_proxy.c | 53 +++++++++++++++++++++++++++++++++++---- >> include/uapi/linux/vtpm_proxy.h | 15 ++++++++++- >> 2 files changed, 62 insertions(+), 6 deletions(-) >> >> -- >> 2.4.3 >> > /Jarkko > -- > To unsubscribe from this list: send the line "unsubscribe linux-security-module" in > the body of a message to majordomo@vger.kernel.org > More majordomo info at http://vger.kernel.org/majordomo-info.html >
[toc] | [prev] | [next] | [standalone]
| From | Jarkko Sakkinen <jarkko.sakkinen@linux.intel.com> |
|---|---|
| Date | 2017-05-04 11:20 +0200 |
| Subject | Re: [PATCH v2 0/3] Extend the vTPM proxy driver to pass locality to emulator |
| Message-ID | <tDl5x-1sT-53@gated-at.bofh.it> |
| In reply to | #1635341 |
On Wed, May 03, 2017 at 07:42:06PM -0400, Stefan Berger wrote: > On 05/03/2017 06:38 PM, Jarkko Sakkinen wrote: > > On Fri, Apr 28, 2017 at 09:02:15AM -0400, Stefan Berger wrote: > > > The purpose of this series of patches is to enable the passing of the locality > > > a command is executing in to a TPM emulator. To enable this we introduce a new > > > flag for the device creation ioctl that requests that the locality be prepended > > > to every command. For applications to check which flags the driver supports, we > > > add a new ioctl that returns a bitmask of supported flags. > > This is a weird change proposal as you could use tpm_vtpm_proxy for > > other than some TPM emulator. > > I think in most cases the recipient of the TPM commands from the vtpm_proxy > driver will be a TPM emulator. What do you have in mind? Like using Intel SGX to implement TPM in ring-3. I've thought vtpm_tpm_proxy as generic proxy that you can also use for emulators. /Jarkko
[toc] | [prev] | [standalone]
Back to top | Article view | linux.kernel
csiph-web