Received: by 10.213.65.68 with SMTP id h4csp26092imn; Mon, 12 Mar 2018 16:06:18 -0700 (PDT) X-Google-Smtp-Source: AG47ELt0hUcG9UzwEV0Lxo4OVg+FmiO6eGRGPaRQbZDtCRAeakSm5/EkbLtjNDXeezg8vT1+cobu X-Received: by 10.101.77.142 with SMTP id p14mr8134877pgq.106.1520895978052; Mon, 12 Mar 2018 16:06:18 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1520895978; cv=none; d=google.com; s=arc-20160816; b=oWTYfJVY9xRSM5upzYI6zW3ju8sekYdYXW6yI4I34W0aLHoe4bHy85ZB7ak6d00L2A ydmXxYwfW/mtUCIxtJB8z3kbd28nt4dKgzbQIh84VisNHpr1W7rczjPubmcP/nRFAVeF Ku4b+dJZED1IFpiLUfGbiZOhILipwVqVGufHT1+AhKgP+v4PQYnCzd1h5N2NaTZjtRdq N28t19xUK+I8gIsVDm0B/KlnnhAJIZSuZ7RaOhTl3NgADHNAckRUK4kCqQmIT9JdtLSU ID1QprLh9+G61kb0ixqz4TJBshQaufYzEtRbgEPBQbY5w++4IvAFdhZOG3TD0Md5abw9 iZNA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:sender:user-agent:in-reply-to :content-transfer-encoding:content-disposition:mime-version :references:message-id:subject:cc:to:from:date:dkim-signature :arc-authentication-results; bh=J23ZZmh2UBQHAEyR/Y4vcKkxqADuciiofo/zW0+7BZ0=; b=WDHr4mlpFpARVHzAlZLMaCmHDNrNqFS79Coa/jzREfa6VXOo4LYLrkq5C43UbyRyVE pPl4aYE//QD+/M1V2ReivP5Wt3frFLZG+/YSlGXYAnOtGJAm9STWQBotiWM4yomqbYW6 Nm6Xk9wtdTVEyOKeblqWpz3cTvwyucQIf+Whtwsf4a1l7FIFMAShiMDZVvuVrmKcpvx1 da8gQJbpgdP4GJN4PaIq6M+D7y96UvjqvPprXKCIdL4SaC4WkM55KFACMRaA7nVm32Nw jAoSg4xvEgY5ZCjTbtVfTP6lWYEUk7GvxqWXYXtm05upnbrQV6ALXgeY8z+se8fIEPTZ dSYQ== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@ziepe.ca header.s=google header.b=lZUIQkFs; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Return-Path: Received: from vger.kernel.org (vger.kernel.org. [209.132.180.67]) by mx.google.com with ESMTP id r8si5588777pgv.414.2018.03.12.16.06.03; Mon, 12 Mar 2018 16:06:18 -0700 (PDT) Received-SPF: pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) client-ip=209.132.180.67; Authentication-Results: mx.google.com; dkim=pass header.i=@ziepe.ca header.s=google header.b=lZUIQkFs; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1751572AbeCLXFK (ORCPT + 99 others); Mon, 12 Mar 2018 19:05:10 -0400 Received: from mail-wr0-f195.google.com ([209.85.128.195]:37803 "EHLO mail-wr0-f195.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1751484AbeCLXFI (ORCPT ); Mon, 12 Mar 2018 19:05:08 -0400 Received: by mail-wr0-f195.google.com with SMTP id z12so17401674wrg.4 for ; Mon, 12 Mar 2018 16:05:08 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ziepe.ca; s=google; h=date:from:to:cc:subject:message-id:references:mime-version :content-disposition:content-transfer-encoding:in-reply-to :user-agent; bh=J23ZZmh2UBQHAEyR/Y4vcKkxqADuciiofo/zW0+7BZ0=; b=lZUIQkFslVxHeki+c6z4wGCbb4S+iOM1u5yreEvIfN+NdNQ1Yy+GvAJXttmsQikNyf aRfn480WDWADkg4uR1qGkbNTjXH3Y/weianiEqHilwSJvumTZBpDIZDauC85nLY2NzU1 fT1KHkAnUNNr61SbGgaheQ42PaOXlVRlkqgLSkb23Mk8gwV1Tzj+Mz7AuVy7+sPi0O/+ dmqTE48nGSrGl0Nemg2e5dUlPE/ciR1R1d3JNvA83+sJeHVU6iBlWxahqf+StzNMfir2 yJwkF1MGMPGR13ZdmFu3FlWkkXCIKedMsnKIsW+Pv/f5fazH4mKbNQZhR286xG8t0Esy 3bNA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:date:from:to:cc:subject:message-id:references :mime-version:content-disposition:content-transfer-encoding :in-reply-to:user-agent; bh=J23ZZmh2UBQHAEyR/Y4vcKkxqADuciiofo/zW0+7BZ0=; b=XUh7qgSae1yHnoumc/TFQAZXoN83IYMlapks9pixYozznmRUvPprs2MieJ9kxebuk+ zmKzMOHaLJuXCXD121x8E582dMT9kVncOIL/6aKKVCJxazDOz1OEpIRXKQ1q6AZ0ffoz q4sI9Xr8txuHPPxA8RIpmJ6x/mpvz1DgEV/T4Uqv6agdzJvlBQb1RbzXMzMZNiOO1JIU gVzewsarux5UGlzfPknOkTb3nL+JttKG3vx8ctT0SQFjLA+fkE3RCMASkOrv6R4yT5zb OYvJjFAYcaVxA8k6ML8W5/gC5qJbL39If2Z2MrZaF1O45CCStZVZCB5vZ6uDb6sf6cCP UZHg== X-Gm-Message-State: AElRT7HfSSWZ+VWh0uz/xG7JzesTdabzX3Tcp1gHhSV5nXwSOG3Jf3LY fuJu4w3CwNrXiCCK8mEA58BGRw== X-Received: by 10.28.197.205 with SMTP id v196mr6469730wmf.141.1520895907299; Mon, 12 Mar 2018 16:05:07 -0700 (PDT) Received: from ziepe.ca (S010614cc2056d97f.ed.shawcable.net. [174.3.196.123]) by smtp.gmail.com with ESMTPSA id o47sm2846181wrc.7.2018.03.12.16.05.06 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Mon, 12 Mar 2018 16:05:06 -0700 (PDT) Received: from jgg by mlx.ziepe.ca with local (Exim 4.86_2) (envelope-from ) id 1evWV3-0003iM-VW; Mon, 12 Mar 2018 17:05:01 -0600 Date: Mon, 12 Mar 2018 17:05:01 -0600 From: Jason Gunthorpe To: Mimi Zohar Cc: James Bottomley , Jiandi An , dmitry.kasatkin@gmail.com, jmorris@namei.org, serge@hallyn.com, linux-integrity@vger.kernel.org, linux-ima-devel@lists.sourceforge.net, linux-ima-user@lists.sourceforge.net, linux-security-module@vger.kernel.org, linux-kernel@vger.kernel.org, David Safford Subject: Re: [PATCH] security: Fix IMA Kconfig for dependencies on ARM64 Message-ID: <20180312230501.GJ24717@ziepe.ca> References: <1520448953.10396.565.camel@linux.vnet.ibm.com> <1520449719.5558.28.camel@HansenPartnership.com> <1520450495.10396.587.camel@linux.vnet.ibm.com> <1520451662.24314.5.camel@HansenPartnership.com> <1520461156.10396.654.camel@linux.vnet.ibm.com> <191cfd49-0c66-a5ef-3d2b-b6c4132aa294@codeaurora.org> <1520615461.12216.6.camel@HansenPartnership.com> <1520891598.3547.190.camel@linux.vnet.ibm.com> <20180312215957.GI24717@ziepe.ca> <1520895525.3547.226.camel@linux.vnet.ibm.com> MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Disposition: inline Content-Transfer-Encoding: 8bit In-Reply-To: <1520895525.3547.226.camel@linux.vnet.ibm.com> User-Agent: Mutt/1.5.24 (2015-08-30) Sender: linux-kernel-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On Mon, Mar 12, 2018 at 06:58:45PM -0400, Mimi Zohar wrote: > On Mon, 2018-03-12 at 15:59 -0600, Jason Gunthorpe wrote: > > On Mon, Mar 12, 2018 at 05:53:18PM -0400, Mimi Zohar wrote: > > > > > Using Kconfig to force the TPM to be builtin is not required, but > > > helpful.  Users interested in IMA-measurement could configure the TPM > > > as builtin themselves.  Without the TPM builtin, IMA goes into TPM- > > > bypass mode. > > > > This issues, broadly speaking, we have lots of TPM drivers, selecting > > only some to actually support IMA shows we have some kind of problem > > here. > > True, IMA is not selecting the older TPM vendor specific modules, but > only the newer TPM_TIS and now TPM_CRB modules.  That doesn't imply > that IMA only supports some TPMs.  It means that by default, these > TPMs are builtin.  Anyone building a kernel, can select the vendor > specific TPM to be builtin. That doesn't help distros, which is the main point of the complaint with this scheme :) Jaason