mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Roberto Sassu <roberto.sassu@huaweicloud.com>
To: Yeoreum Yun <yeoreum.yun@arm.com>,
	linux-coco@lists.linux.dev,  linux-kernel@vger.kernel.org,
	linux-arm-kernel@lists.infradead.org,
	Eric Snowberg <eric.snowberg@oracle.com>,
	linux-integrity@vger.kernel.org,
	 linux-security-module@vger.kernel.org
Cc: Dan Williams <djbw@kernel.org>, Mimi Zohar <zohar@linux.ibm.com>,
	 Roberto Sassu <roberto.sassu@huawei.com>,
	Dmitry Kasatkin <dmitry.kasatkin@gmail.com>,
	Paul Moore <paul@paul-moore.com>,
	James Morris <jmorris@namei.org>,
	"Serge E. Hallyn" <serge@hallyn.com>,
	Catalin Marinas <catalin.marinas@arm.com>,
	Jason Gunthorpe <jgg@ziepe.ca>,
	Suzuki Poulose <suzuki.poulose@arm.com>,
	Steven Price <steven.price@arm.com>,
	Sami Mujawar <sami.mujawar@arm.com>,
	"Aneesh Kumar K.V" <aneesh.kumar@kernel.org>,
	Jiri Pirko <jiri@resnulli.us>,
	gongruiqi1@huawei.com
Subject: Re: [PATCH RFC 0/3] security: ima: support TSM measurement registers
Date: Thu, 01 Oct 2026 13:45:26 +0200	[thread overview]
Message-ID: <c4fe5315d70fc162f1e5648e3fccb1676710d5e6.camel@huaweicloud.com> (raw)
In-Reply-To: <ebe68f6463f8ece8a5cd8ce70bba292ec4f64a41.camel@huaweicloud.com>

On Thu, 2026-10-01 at 13:27 +0200, Roberto Sassu wrote:
> On Wed, 2026-09-30 at 14:43 +0100, Yeoreum Yun wrote:
> > Confidential computing guests without a TPM can use TSM measurement
> > registers to record IMA measurement digests instead of TPM PCRs.

+ Gong Ruiqi, of course.

Roberto

> Hi Yeoreum
> 
> a similar patch set has been sent to the linux-integrity mailing list:
> 
> https://lore.kernel.org/linux-integrity/20250630125928.765285-1-gongruiqi1@huawei.com/
> 
> Could you please work with Gong Ruiqi to have a unified proposal?
> 
> Thanks
> 
> Roberto
> 
> > This series introduces in-kernel interfaces for accessing TSM
> > measurement registers, abstracts IMA's measurement-register operations,
> > and adds a TSM backend for Intel TDX and Arm CCA.
> > 
> > The following mappings between TPM PCR indices and TSM measurement
> > registers are defined for Intel TDX [0] and proposed for Arm CCA [1]:
> > 
> >   TPM PCR index | Intel TDX register | Arm CCA register
> >   --------------+--------------------+-----------------
> >   0             | MRTD               | RIM
> >   1, 7          | RTMR[0]            | REM[0]
> >   2-6           | RTMR[1]            | REM[1]
> >   8-15          | RTMR[2]            | REM[2]
> > 
> > These mappings allow IMA to translate PCR indices into the corresponding
> > TSM measurement registers.
> > 
> > The TPM backend remains preferred when it is available at IMA
> > initialization. Otherwise, IMA falls back to a supported TSM backend.
> > Only one backend is selected; IMA measurements are not extended to both
> > TPM PCRs and TSM measurement registers.
> > 
> > The attestation proccess for guest with TSM measurement register will
> > be done with Confidential Compute Event Log (CCEL) which is exported by
> > /sys/firmware/acpi/tables/data/CCEL. Here is brief process in arm64:
> > 
> >   Verifier                 Realm guest              RMM / Platform
> >      |                         |                           |
> >      |--- Challenge (nonce) -->|                           |
> >      |                         |--- Request token -------->|
> >      |                         |    with challenge         |
> >      |                         |                           |
> >      |                         |<-- CCA token T -----------|
> >      |<-- CCA token T ---------|                           |
> >      |<-- CCEL event log ------|                           |
> >      |<-- IMA measurement log -|                           |
> >      |                         |                           |
> >  Verify token T:               |                           |
> >   - signatures                 |                           |
> >   - Platform/Realm             |                           |
> >     token binding              |                           |
> >   - challenge freshness        |                           |
> >   - platform/RIM policy        |                           |
> >   - verify measurement logs    |                           |
> >      |                         |                           |
> >      | ----ACCEPT / REJECT---->|                           |
> > 
> > This patch based on arm-cca-mr series [3].
> > 
> > Link: [0] https://uefi.org/specs/UEFI/2.11/38_Confidential_Computing.html#intel-trust-domain-extension
> > Link: [1] https://github.com/tianocore/edk2/issues/11383
> > Link: [2] https://github.com/tianocore/edk2/issues/11384
> > Link: [3] https://lore.kernel.org/all/20260929-arm_cca_mr-v2-0-1d98bba187fd@arm.com/
> > 
> > ---
> > Yeoreum Yun (3):
> >       virt: coco: introduce tsm_default_tm() and tsm_mr_read()/write()
> >       security: IMA: introduce ima_mr structure
> >       security: IMA: use TSM measurement registers
> > 
> >  drivers/virt/coco/guest/tsm-mr.c          | 159 +++++++++++++---
> >  include/linux/tsm-mr.h                    |  26 +++
> >  security/integrity/ima/Makefile           |   3 +-
> >  security/integrity/ima/ima.h              |   7 +-
> >  security/integrity/ima/ima_api.c          |   4 +-
> >  security/integrity/ima/ima_crypto.c       | 137 +++++---------
> >  security/integrity/ima/ima_fs.c           |  16 +-
> >  security/integrity/ima/ima_init.c         |   7 +-
> >  security/integrity/ima/ima_mr.c           |  48 +++++
> >  security/integrity/ima/ima_mr.h           |  76 ++++++++
> >  security/integrity/ima/ima_mr_tpm.c       | 155 ++++++++++++++++
> >  security/integrity/ima/ima_mr_tsm.c       | 290 ++++++++++++++++++++++++++++++
> >  security/integrity/ima/ima_queue.c        |  39 ++--
> >  security/integrity/ima/ima_template.c     |   4 +-
> >  security/integrity/ima/ima_template_lib.c |   2 +-
> >  15 files changed, 819 insertions(+), 154 deletions(-)
> > ---
> > base-commit: b561246f45174b7472c24b75358ea95bae72b7b8
> > change-id: 20260929-ima_tgx_integration_v2-1c54aeeaeaee
> > 
> > Best regards,


  reply	other threads:[~2026-10-01 11:45 UTC|newest]

Thread overview: 9+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-30 13:43 Yeoreum Yun
2026-09-30 13:43 ` [PATCH RFC 1/3] virt: coco: introduce tsm_default_tm() and tsm_mr_read()/write() Yeoreum Yun
2026-09-30 13:44 ` [PATCH RFC 2/3] security: IMA: introduce ima_mr structure Yeoreum Yun
2026-09-30 13:44 ` [PATCH RFC 3/3] security: IMA: use TSM measurement registers Yeoreum Yun
2026-10-01 11:27 ` [PATCH RFC 0/3] security: ima: support " Roberto Sassu
2026-10-01 11:45   ` Roberto Sassu [this message]
2026-10-01 14:24     ` Yeoreum Yun
2026-10-01 15:18     ` Jason Gunthorpe
2026-10-01 16:39       ` Yeoreum Yun

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=c4fe5315d70fc162f1e5648e3fccb1676710d5e6.camel@huaweicloud.com \
    --to=roberto.sassu@huaweicloud.com \
    --cc=aneesh.kumar@kernel.org \
    --cc=catalin.marinas@arm.com \
    --cc=djbw@kernel.org \
    --cc=dmitry.kasatkin@gmail.com \
    --cc=eric.snowberg@oracle.com \
    --cc=gongruiqi1@huawei.com \
    --cc=jgg@ziepe.ca \
    --cc=jiri@resnulli.us \
    --cc=jmorris@namei.org \
    --cc=linux-arm-kernel@lists.infradead.org \
    --cc=linux-coco@lists.linux.dev \
    --cc=linux-integrity@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-security-module@vger.kernel.org \
    --cc=paul@paul-moore.com \
    --cc=roberto.sassu@huawei.com \
    --cc=sami.mujawar@arm.com \
    --cc=serge@hallyn.com \
    --cc=steven.price@arm.com \
    --cc=suzuki.poulose@arm.com \
    --cc=yeoreum.yun@arm.com \
    --cc=zohar@linux.ibm.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®