Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1751284AbcKZM72 (ORCPT ); Sat, 26 Nov 2016 07:59:28 -0500 Received: from mga01.intel.com ([192.55.52.88]:57234 "EHLO mga01.intel.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1750745AbcKZM7S (ORCPT ); Sat, 26 Nov 2016 07:59:18 -0500 X-ExtLoop1: 1 X-IronPort-AV: E=Sophos;i="5.31,552,1473145200"; d="scan'208";a="35758760" Date: Sat, 26 Nov 2016 14:59:13 +0200 From: Jarkko Sakkinen To: Jason Gunthorpe Cc: Nayna Jain , tpmdd-devel@lists.sourceforge.net, peterhuewe@gmx.de, tpmdd@selhorst.net, linux-security-module@vger.kernel.org, linux-kernel@vger.kernel.org Subject: Re: [PATCH v5 3/3] tpm: add securityfs support for TPM 2.0 firmware event log Message-ID: <20161126125913.kavkmocx7ixzs3tp@intel.com> References: <1479922057-8752-1-git-send-email-nayna@linux.vnet.ibm.com> <1479922057-8752-4-git-send-email-nayna@linux.vnet.ibm.com> <20161124211057.xynmfteky5r7uc27@intel.com> <20161125194317.GG16504@obsidianresearch.com> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <20161125194317.GG16504@obsidianresearch.com> Organization: Intel Finland Oy - BIC 0357606-4 - Westendinkatu 7, 02160 Espoo User-Agent: Mutt/1.6.2-neo (2016-08-21) Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Content-Length: 1639 Lines: 37 On Fri, Nov 25, 2016 at 12:43:17PM -0700, Jason Gunthorpe wrote: > On Thu, Nov 24, 2016 at 11:10:57PM +0200, Jarkko Sakkinen wrote: > > On Wed, Nov 23, 2016 at 12:27:37PM -0500, Nayna Jain wrote: > > > Unlike the device driver support for TPM 1.2, the TPM 2.0 does > > > not support the securityfs pseudo files for displaying the > > > firmware event log. > > > > > > This patch enables support for providing the TPM 2.0 event log in > > > binary form. TPM 2.0 event log supports a crypto agile format that > > > records multiple digests, which is different from TPM 1.2. This > > > patch enables the tpm_bios_log_setup for TPM 2.0 and adds the > > > event log parser which understand the TPM 2.0 crypto agile format. > > > > > > Signed-off-by: Nayna Jain > > > > I don't want to say much about this before I've tested it. I wonder > > what cheap hardware I could use to test this. Any advice is on this > > from anyone is much appreciated. > > If you found a small ARM system with TPM you could customize the uboot > to build an event log and pass it in via DT. > > Not sure how much work that would be, does uboot have tpm code > already? I have BeagleBoard Rev C (omap3530 arm board) and it has GPIOs but at the moment I do not possess a spare dTPM module. I'll ask my employer for one. It's quite old (2009), which is a good thing because of range of support I would presume... If I get the spare dTPM I can do I2C/SPI through GPIOs as long as I find a way to inject stuff to DT. Hmm.. that said I've never done this before. I guess you can ask I2C/SPI driver somehow to use GPIOs? > Jason /Jarkko