Received: by 2002:a05:6602:2086:0:0:0:0 with SMTP id a6csp4619605ioa; Wed, 27 Apr 2022 07:37:17 -0700 (PDT) X-Google-Smtp-Source: ABdhPJzNA4WfQaLYw3SMW76Y/DLwiSWWhJIjkey9ZTLOX/NL9XCPr8S6gE1kJcEgmj2XyL2h38fS X-Received: by 2002:a17:90b:4c04:b0:1d9:3749:415 with SMTP id na4-20020a17090b4c0400b001d937490415mr25122428pjb.3.1651070237362; Wed, 27 Apr 2022 07:37:17 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1651070237; cv=none; d=google.com; s=arc-20160816; b=lg7h4szCM07WJ8TNm6odpVBlxcwQrjgLO1iJPXdeUgH1yNR5zvJkGBQTFKurjT4JaK macxP1JXydV3nnLI1psmF+nLbFg2g6hs9b+g2cW1D8NH/3GLhQ2QCjrx772TJSZ/qHs0 vycQUaGehUodWuWUBkYhAomeZ9tjtsHnZeVKa4gtACGDwmKMhanl9PpiH99A083aJnUT qTQEGv+tZTDdPop/dwCTV5iNrpo9T2lMxwX9SAVSgJZfGnRu2NiaR4STE41L/DN4alzs v8KjjVVuywHjj4b6UsERzuy+sODgpq6lQk+0BeCQjzc8/YFJZz91Cpkjo4C39C+JZlRm bggg== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:content-transfer-encoding:in-reply-to:from :references:cc:to:content-language:subject:user-agent:mime-version :date:message-id:dkim-signature; bh=QBUP5W2GFl3IRF9AusRlIHlfCvXzC9GpPKikOtywUDI=; b=BTtPfxk3YZBnfr7iqnUAUh6kE+K16vEPyGhKspU3uOR3ulAbzkxXs1CGax6KWvR9w2 aC8g4O5Ocdj+fkxOYrk4aU4ydSPcpAtHl64iOQYgvnpE/EAvcQbQAYn4qXV5B97lRDtO LNRe2KwSq3W/UzDE6tayoM/+t5n+qdHEdQr5VpQgrnyXgUiYsTUiq5+bw05sHfrBNAMu 1W7DYTl3dzAGBSy8Hyw0NYmePSIojRXtwek70BDuZzGwuMmVwixncsXGr5tCHeqNUnul an0XLKj2WVYRn6i1xNxxoBgHUCURCbQs6WCTON4lIOaiBPoMZ2/u8lyGo+d+in2B57uz sSZQ== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@intel.com header.s=Intel header.b=EQNwsmU5; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:18 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=intel.com Return-Path: Received: from lindbergh.monkeyblade.net (lindbergh.monkeyblade.net. [2620:137:e000::1:18]) by mx.google.com with ESMTPS id f20-20020a63e314000000b003ab8129839asi2155155pgh.325.2022.04.27.07.37.16 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 27 Apr 2022 07:37:17 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:18 as permitted sender) client-ip=2620:137:e000::1:18; Authentication-Results: mx.google.com; dkim=pass header.i=@intel.com header.s=Intel header.b=EQNwsmU5; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:18 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=intel.com Received: from vger.kernel.org (vger.kernel.org [23.128.96.18]) by lindbergh.monkeyblade.net (Postfix) with ESMTP id 8BFE44EF44; Wed, 27 Apr 2022 07:09:25 -0700 (PDT) Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S237271AbiD0OM0 (ORCPT + 99 others); Wed, 27 Apr 2022 10:12:26 -0400 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:54812 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S237151AbiD0OMY (ORCPT ); Wed, 27 Apr 2022 10:12:24 -0400 Received: from mga03.intel.com (mga03.intel.com [134.134.136.65]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id 0039E4EDF1 for ; Wed, 27 Apr 2022 07:09:12 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=intel.com; i=@intel.com; q=dns/txt; s=Intel; t=1651068553; x=1682604553; h=message-id:date:mime-version:subject:to:cc:references: from:in-reply-to:content-transfer-encoding; bh=KWtSzk6XLIEmgrFCdr2CVRtw4pCvRrQiE+rGfmmtx2M=; b=EQNwsmU5M5hP1SY3UDt7P2OOimYfS7NwqP5A2+HSp8rqxoA3cd2I0L5I b2ffhwVfK3YV3cYFdHl3WI+xsXsUCW/asQ58ILghrEZyG0xVdS5vY8SBL BJCVjd1It1+ptXbtGNIkXIe2RAMxpe79HrgQkY2Le7W/Q7/J/ZCxTvh+m 3G2tNrzk2KXuEMDJzGYNjMFsSvJVOKRrJOe6jxcV4i9V3/SzphjUBeFCd undCKDgx8cuQ0RnXoUoChQPVhkj3XWuTHWJT/5EpwLpKyHaKXZXJLQvbv 2iq+Z5oZ41LHzoFYI11/fZR1lAoSHL242Weam1uKtb5skz5/wwdq9Jzsj w==; X-IronPort-AV: E=McAfee;i="6400,9594,10329"; a="265748382" X-IronPort-AV: E=Sophos;i="5.90,293,1643702400"; d="scan'208";a="265748382" Received: from orsmga005.jf.intel.com ([10.7.209.41]) by orsmga103.jf.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 27 Apr 2022 07:09:12 -0700 X-IronPort-AV: E=Sophos;i="5.90,293,1643702400"; d="scan'208";a="730815345" Received: from jsaetton-mobl1.amr.corp.intel.com (HELO [10.209.41.167]) ([10.209.41.167]) by orsmga005-auth.jf.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 27 Apr 2022 07:09:11 -0700 Message-ID: <505b210f-1a4e-4cda-e1ba-920969326461@linux.intel.com> Date: Wed, 27 Apr 2022 07:09:11 -0700 MIME-Version: 1.0 User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:91.0) Gecko/20100101 Firefox/91.0 Thunderbird/91.7.0 Subject: Re: [PATCH v4 1/3] x86/tdx: Add TDX Guest attestation interface driver Content-Language: en-US To: Kai Huang , Thomas Gleixner , Ingo Molnar , Borislav Petkov , Dave Hansen , x86@kernel.org Cc: "H . Peter Anvin" , "Kirill A . Shutemov" , Tony Luck , Andi Kleen , linux-kernel@vger.kernel.org References: <20220422233418.1203092-1-sathyanarayanan.kuppuswamy@linux.intel.com> <20220422233418.1203092-2-sathyanarayanan.kuppuswamy@linux.intel.com> <0457ce8e78ddd1d6c7832176368e095adae1bc18.camel@intel.com> <405a4f3c-3d49-f3c2-441b-8d8b9d5eec23@linux.intel.com> From: Sathyanarayanan Kuppuswamy In-Reply-To: Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 7bit X-Spam-Status: No, score=-4.3 required=5.0 tests=BAYES_00,DKIMWL_WL_HIGH, DKIM_SIGNED,DKIM_VALID,HEADER_FROM_DIFFERENT_DOMAINS, MAILING_LIST_MULTI,NICE_REPLY_A,RDNS_NONE,SPF_HELO_NONE autolearn=unavailable autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on lindbergh.monkeyblade.net Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On 4/26/22 9:28 PM, Kai Huang wrote: > >> >> How about the following summary? It includes important notes mentioned >> by you and some more driver info. > > Yes fine to me, except minor comments below: > >> >> x86/tdx: Add TDX Guest attestation interface driver >> >> In TDX guest, attestation is used to verify the trustworthiness of a TD >> to other entities before provisioning secrets to the TD. >> >> One usage example is, when a TD guest uses encrypted drive and if the >> decryption keys required to access the drive are stored in a secure 3rd >> party key server, the key server can use attestation to verify TD's >> trustworthiness and release the decryption keys to the TD. >> >> The attestation process consists of two steps: TDREPORT generation and >> Quote generation. >> >> TDREPORT (TDREPORT_STRUCT) is a fixed-size data structure generated by >> the TDX module which contains TD-specific information (such as TD >> measurements), platform security version, and the MAC to protect the >> integrity of the TDREPORT. The TD kernel uses TDCALL[TDG.MR.REPORT] to >> get the TDREPORT from the TDX module. A user-provided 64-Byte >> REPORTDATA is used as input and included in the TDREPORT. Typically it >> can be some nonce provided by attestation service so the TDREPORT can >> be verified uniquely. More details about TDREPORT can be found in >> Intel TDX Module specification, section titled "TDG.MR.REPORT Leaf". >> >> After getting the TDREPORT, the second step of the attestation process >> is to send the TDREPORT to Quoting Enclave (QE) or Quote Generation >> Service (QGS) to generate the Quote. However, the method of sending the >> TDREPORT to QE/QGS, communication channel used and data format used is >> specific to the implementation of QE/QGS. >> >> A typical implementation is, TD userspace attestation software gets the >> TDREPORT from TD kernel, sends it to QE/QGS, and QE/QGS returns the >> Quote. TD attestation software can use any available communication >> channel to talk to QE/QGS, such as using vsock and tcp/ip. >> >> To support the case that those communication channels are not directly >> available to the TD, TDX also defines TDVMCALL >> (TDG.VP.VMCALL) to allow TD to ask VMM to help with sending >> the TDREPORT and receiving the Quote. This support is documented in the >> GHCI spec section titled "5.4 TD attestation". > > I intentionally omitted to mention TDG.VP.VMCALL as I personally > believe there are still couple issues around GetQuote that we haven't discussed > thoroughly (timeout, etc). I am still considering whether we should change GHCI > to use TDG.VP.VMCALL defined in GHCI 1.5 for attestation. And the name > of TDVMCALL doesn't actually matter here, so I think we don't need to mention > GetQuote here but just say we have TDVMCALLs for that. Ok. > >> >> Implement a basic attestation driver to allow TD userspace to get the >> TDREPORT, which is sent to QE by the attestation software to generate >> a Quote for remote verification. Add a wrapper function >> (tdx_mcall_tdreport()) to get the TDREPORT from the TDX Module. This >> API will be used by the interface driver to request for TDREPORT. > > I don't think you need to mention tdx_mcall_tdreport(). Ok. Will remove it. > >> >> Also note that explicit access permissions are not enforced in this >> driver because the quote and measurements are not a secret. However >> the access permissions of the device node can be used to set any >> desired access policy. The udev default is usually root access >> only. >> >> >> >> > -- Sathyanarayanan Kuppuswamy Linux Kernel Developer