From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1753864AbdBJTHf (ORCPT ); Fri, 10 Feb 2017 14:07:35 -0500 Received: from mga07.intel.com ([134.134.136.100]:52841 "EHLO mga07.intel.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1753625AbdBJTHd (ORCPT ); Fri, 10 Feb 2017 14:07:33 -0500 X-ExtLoop1: 1 X-IronPort-AV: E=Sophos;i="5.35,142,1484035200"; d="scan'208";a="42670165" Date: Fri, 10 Feb 2017 21:07:27 +0200 From: Jarkko Sakkinen To: James Bottomley Cc: tpmdd-devel@lists.sourceforge.net, linux-security-module@vger.kernel.org, Peter Huewe , Marcel Selhorst , Jason Gunthorpe , open list Subject: Re: [PATCH 6/6] tpm2: add session handle context saving and restoring to the space code' Message-ID: <20170210190727.abaxbbpqq45kb2mm@intel.com> References: <20170208110713.14070-1-jarkko.sakkinen@linux.intel.com> <20170208110713.14070-7-jarkko.sakkinen@linux.intel.com> <20170210085256.eqhnrmdug2fcz4ql@intel.com> <1486743078.2502.4.camel@HansenPartnership.com> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <1486743078.2502.4.camel@HansenPartnership.com> Organization: Intel Finland Oy - BIC 0357606-4 - Westendinkatu 7, 02160 Espoo User-Agent: Mutt/1.6.2-neo (2016-08-21) Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On Fri, Feb 10, 2017 at 08:11:18AM -0800, James Bottomley wrote: > On Fri, 2017-02-10 at 10:52 +0200, Jarkko Sakkinen wrote: > > On Wed, Feb 08, 2017 at 01:07:08PM +0200, Jarkko Sakkinen wrote: > > > + rc = tpm2_load_context(chip, space->session_buf, > > > + &offset, &handle); > > > + if (rc == -ENOENT) { > > > + /* load failed, just forget session */ > > > + space->session_tbl[i] = 0; > > > > This is my only concern in this commit. Should we also in this case > > just flush the space or not? > > I elected not to. If the handle is flushed by an external resource > manager, we get this event. If the RM and the app agreed to release > the session handle, then flushing the space would be overkill because > it would destroy the client session, so simply removing the handle > works. If the client tries to use the session again, it gets an error > and if it doesn't everything just works, which seems to be optimal. > > James Makes sense. Just wanted the check the logic you had in this decision. /Jarkko