Re: [PATCH v3 3/4] tpm: add SNP SVSM vTPM driver

2025-03-18 Thread Tom Lendacky
On 3/18/25 05:38, Stefano Garzarella wrote: > On Mon, Mar 17, 2025 at 03:43:18PM +0200, Jarkko Sakkinen wrote: >> On Fri, Mar 14, 2025 at 11:48:11AM -0500, Tom Lendacky wrote: >>> On 3/11/25 04:42, Stefano Garzarella wrote: Add driver for the vTPM defined by the AMD SVSM spec [1]. Th

Re: [PATCH v3 3/4] tpm: add SNP SVSM vTPM driver

2025-03-18 Thread Stefano Garzarella
On Tue, Mar 18, 2025 at 09:54:31AM -0500, Tom Lendacky wrote: On 3/18/25 05:38, Stefano Garzarella wrote: On Mon, Mar 17, 2025 at 03:43:18PM +0200, Jarkko Sakkinen wrote: On Fri, Mar 14, 2025 at 11:48:11AM -0500, Tom Lendacky wrote: On 3/11/25 04:42, Stefano Garzarella wrote: Add driver for t

Re: [RFC PATCH v1 0/7] ima: get rid of hard dependency on SHA-1

2025-03-18 Thread Roberto Sassu
On Thu, 2025-03-13 at 18:33 +0100, Nicolai Stange wrote: > Hi all, > > if no SHA-1 implementation was available to the kernel, IMA init would > currently fail, rendering the whole subsystem unusable. > > This patch series is an attempt to make SHA-1 availability non-mandatory > for IMA. The main

Re: [PATCH v3 4/4] x86/sev: register tpm-svsm platform device

2025-03-18 Thread Stefano Garzarella
On Mon, Mar 17, 2025 at 03:34:10PM +0200, Jarkko Sakkinen wrote: On Fri, Mar 14, 2025 at 11:56:31AM -0500, Tom Lendacky wrote: On 3/11/25 04:42, Stefano Garzarella wrote: > SNP platform can provide a vTPM device emulated by SVSM. > > The "tpm-svsm" device can be handled by the platform driver ad

Re: [RFC PATCH v1 6/7] ima: invalidate unsupported PCR banks once at first use

2025-03-18 Thread Nicolai Stange
Mimi Zohar writes: > On Tue, 2025-03-18 at 11:26 +0100, Nicolai Stange wrote: >> Mimi Zohar writes: >> >> > On Thu, 2025-03-13 at 18:33 +0100, Nicolai Stange wrote: >> > > Normally IMA would extend a template hash of each bank's associated >> > > algorithm into a PCR. However, if a bank's hash

Re: [RFC PATCH 2/3] tpm/tpm_ftpm_tee: use send_recv() op

2025-03-18 Thread Stefano Garzarella
Hi Sumit, Jens, On Thu, Mar 13, 2025 at 01:59:19PM +0100, Jens Wiklander wrote: On Thu, Mar 13, 2025 at 10:13 AM Sumit Garg wrote: + Jens Hi Stefano, On Tue, Mar 11, 2025 at 11:01:29AM +0100, Stefano Garzarella wrote: > This driver does not support interrupts, and receiving the response is

Re: [RFC PATCH v1 0/7] ima: get rid of hard dependency on SHA-1

2025-03-18 Thread Nicolai Stange
Roberto Sassu writes: > On Thu, 2025-03-13 at 18:33 +0100, Nicolai Stange wrote: >> Hi all, >> >> if no SHA-1 implementation was available to the kernel, IMA init would >> currently fail, rendering the whole subsystem unusable. >> >> This patch series is an attempt to make SHA-1 availability no

Re: [PATCH v3 1/4] x86/sev: add SVSM vTPM probe/send_command functions

2025-03-18 Thread Stefano Garzarella
On Mon, Mar 17, 2025 at 03:36:26PM +0200, Jarkko Sakkinen wrote: On Fri, Mar 14, 2025 at 10:27:07AM -0500, Tom Lendacky wrote: On 3/11/25 04:42, Stefano Garzarella wrote: > Add two new functions to probe and send commands to the SVSM vTPM. > They leverage the two calls defined by the AMD SVSM sp

Re: [RFC PATCH v1 6/7] ima: invalidate unsupported PCR banks once at first use

2025-03-18 Thread Mimi Zohar
On Tue, 2025-03-18 at 11:26 +0100, Nicolai Stange wrote: > Mimi Zohar writes: > > > On Thu, 2025-03-13 at 18:33 +0100, Nicolai Stange wrote: > > > Normally IMA would extend a template hash of each bank's associated > > > algorithm into a PCR. However, if a bank's hash algorithm is unavailable > >

Re: [RFC PATCH v1 6/7] ima: invalidate unsupported PCR banks once at first use

2025-03-18 Thread Mimi Zohar
On Tue, 2025-03-18 at 16:55 +0100, Nicolai Stange wrote: > Mimi Zohar writes: > > > On Tue, 2025-03-18 at 11:26 +0100, Nicolai Stange wrote: > > > Mimi Zohar writes: > > > > > > > On Thu, 2025-03-13 at 18:33 +0100, Nicolai Stange wrote: > > > > > Normally IMA would extend a template hash of eac

Re: [PATCH v3 3/4] tpm: add SNP SVSM vTPM driver

2025-03-18 Thread Stefano Garzarella
On Mon, Mar 17, 2025 at 03:43:18PM +0200, Jarkko Sakkinen wrote: >On Fri, Mar 14, 2025 at 11:48:11AM -0500, Tom Lendacky wrote: >> On 3/11/25 04:42, Stefano Garzarella wrote: >> > Add driver for the vTPM defined by the AMD SVSM spec [1]. >> > >> > The specification defines a protocol that a SEV-SNP

Re: [RFC PATCH v1 6/7] ima: invalidate unsupported PCR banks once at first use

2025-03-18 Thread Nicolai Stange
Mimi Zohar writes: > On Thu, 2025-03-13 at 18:33 +0100, Nicolai Stange wrote: >> Normally IMA would extend a template hash of each bank's associated >> algorithm into a PCR. However, if a bank's hash algorithm is unavailable >> to the kernel at IMA init time, it would fallback to extending padded