From: Jason Gunthorpe <jgunthorpe@obsidianresearch.com>
To: Jarkko Sakkinen <jarkko.sakkinen@linux.intel.com>
Cc: tpmdd-devel@lists.sourceforge.net,
linux-security-module@vger.kernel.org,
Peter Huewe <peterhuewe@gmx.de>,
Marcel Selhorst <tpmdd@selhorst.net>,
open list <linux-kernel@vger.kernel.org>
Subject: Re: [PATCH RFC 4/4] tpm: add the infrastructure for TPM space for TPM 2.0
Date: Tue, 3 Jan 2017 11:46:27 -0700 [thread overview]
Message-ID: <20170103184627.GA26706@obsidianresearch.com> (raw)
In-Reply-To: <20170103003730.he32vl55kkta2q64@intel.com>
On Tue, Jan 03, 2017 at 02:37:30AM +0200, Jarkko Sakkinen wrote:
> On Mon, Jan 02, 2017 at 02:09:53PM -0700, Jason Gunthorpe wrote:
> > On Mon, Jan 02, 2017 at 03:22:10PM +0200, Jarkko Sakkinen wrote:
> > > Added a ioctl for creating a TPM space. The space is isolated from the
> > > other users of the TPM. Only a process holding the file with the handle
> > > can access the objects and only objects that are created through that
> > > file handle can be accessed.
> >
> > I don't understand this comment. /dev/tpmX is forced to be
> > single-process-open, so how can there ever be more than 1 FD for it?
> >
> > Since the space is tied to that single fd these patches just create a
> > way for the single user-space process to auto-cleanup if it crashes?
> >
> > Is that the entire intent of this design? I guess it is OK as a
> > stepping point..
>
> is_open is cleared in tpm_ioc_new_space.
That is no good, it is racy if the intention is to use multiple
clients, and any single client that doesn't support the new API blocks
all access.
Jason
next prev parent reply other threads:[~2017-01-03 18:47 UTC|newest]
Thread overview: 67+ messages / expand[flat|nested] mbox.gz Atom feed top
2017-01-02 13:22 [PATCH RFC 0/4] RFC: in-kernel resource manager Jarkko Sakkinen
2017-01-02 13:22 ` [PATCH RFC 1/4] tpm: migrate struct tpm_buf to struct tpm_chip Jarkko Sakkinen
2017-01-02 21:01 ` Jason Gunthorpe
2017-01-03 0:57 ` Jarkko Sakkinen
2017-01-03 19:13 ` Jason Gunthorpe
2017-01-04 12:29 ` Jarkko Sakkinen
2017-01-02 13:22 ` [PATCH RFC 2/4] tpm: validate TPM 2.0 commands Jarkko Sakkinen
[not found] ` <OF8D508BD2.EAB22BFD-ON0025809E.0062B40C-8525809E.006356C3@notes.na.collabserv.com>
2017-01-04 18:19 ` [tpmdd-devel] " James Bottomley
2017-01-04 18:44 ` Jason Gunthorpe
2017-01-02 13:22 ` [PATCH RFC 3/4] tpm: export tpm2_flush_context_cmd Jarkko Sakkinen
2017-01-02 13:22 ` [PATCH RFC 4/4] tpm: add the infrastructure for TPM space for TPM 2.0 Jarkko Sakkinen
2017-01-02 21:09 ` Jason Gunthorpe
2017-01-03 0:37 ` Jarkko Sakkinen
2017-01-03 18:46 ` Jason Gunthorpe [this message]
2017-01-04 12:43 ` Jarkko Sakkinen
2017-01-03 19:16 ` Jason Gunthorpe
2017-01-04 12:45 ` Jarkko Sakkinen
[not found] ` <OF9C3EE9AE.65978870-ON0025809E.0061E7AF-8525809E.0061FFDA@notes.na.collabserv.com>
2017-01-09 22:11 ` [tpmdd-devel] " Jarkko Sakkinen
2017-01-02 16:36 ` [tpmdd-devel] [PATCH RFC 0/4] RFC: in-kernel resource manager James Bottomley
2017-01-02 19:33 ` Jarkko Sakkinen
2017-01-02 21:40 ` James Bottomley
2017-01-03 5:26 ` James Bottomley
2017-01-03 13:41 ` Jarkko Sakkinen
2017-01-03 16:14 ` James Bottomley
2017-01-03 18:36 ` Jarkko Sakkinen
2017-01-03 19:14 ` Jarkko Sakkinen
2017-01-03 19:34 ` James Bottomley
2017-01-03 21:54 ` Jason Gunthorpe
2017-01-04 12:58 ` Jarkko Sakkinen
2017-01-04 16:55 ` Jason Gunthorpe
2017-01-04 5:47 ` Andy Lutomirski
2017-01-04 13:00 ` Jarkko Sakkinen
2017-01-03 13:51 ` Jarkko Sakkinen
2017-01-03 16:36 ` James Bottomley
2017-01-03 18:40 ` Jarkko Sakkinen
2017-01-03 21:47 ` Jason Gunthorpe
2017-01-03 22:21 ` Ken Goldman
2017-01-03 23:20 ` Jason Gunthorpe
2017-01-03 22:39 ` James Bottomley
2017-01-04 0:17 ` Jason Gunthorpe
2017-01-04 0:29 ` James Bottomley
2017-01-04 0:56 ` Jason Gunthorpe
2017-01-04 12:50 ` Jarkko Sakkinen
2017-01-04 14:53 ` James Bottomley
2017-01-04 18:31 ` Jason Gunthorpe
2017-01-04 18:57 ` James Bottomley
2017-01-04 19:24 ` Jason Gunthorpe
2017-01-04 12:48 ` Jarkko Sakkinen
2017-01-03 21:32 ` Jason Gunthorpe
2017-01-03 22:03 ` James Bottomley
2017-01-05 15:52 ` Fuchs, Andreas
2017-01-05 17:27 ` Jason Gunthorpe
2017-01-05 18:06 ` James Bottomley
2017-01-06 8:43 ` Andreas Fuchs
2017-01-05 18:33 ` James Bottomley
2017-01-05 19:20 ` Jason Gunthorpe
2017-01-05 19:55 ` James Bottomley
2017-01-05 22:21 ` Jason Gunthorpe
2017-01-05 22:58 ` James Bottomley
2017-01-05 23:50 ` Jason Gunthorpe
2017-01-06 0:36 ` James Bottomley
2017-01-06 8:59 ` Andreas Fuchs
2017-01-06 19:10 ` Jason Gunthorpe
2017-01-06 19:02 ` Jason Gunthorpe
2017-01-10 19:03 ` Ken Goldman
2017-01-09 22:39 ` [tpmdd-devel] " Jarkko Sakkinen
2017-01-11 10:03 ` Andreas Fuchs
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20170103184627.GA26706@obsidianresearch.com \
--to=jgunthorpe@obsidianresearch.com \
--cc=jarkko.sakkinen@linux.intel.com \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-security-module@vger.kernel.org \
--cc=peterhuewe@gmx.de \
--cc=tpmdd-devel@lists.sourceforge.net \
--cc=tpmdd@selhorst.net \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
Powered by JetHome