From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-qk1-f181.google.com (mail-qk1-f181.google.com [209.85.222.181]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id E3F023C3BF3 for ; Mon, 13 Apr 2026 12:59:27 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.222.181 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1776085169; cv=none; b=rqFac6VV4qhDO5QyGzRU9WjxTBlQvDrp5pCZ1HiZyowlCgMoXJRMwSAuLbONMRS8Im1NdJi7quNGMIJFRYWcYeUgyQBGoWCWxIM26sA5fJuf++WIk2UQMOPx6lxK/+THOekw8GTsiAqU0F+SoUzLxQXbdzrDzOW5OXGfO8TzktI= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1776085169; c=relaxed/simple; bh=1hNMMlVpcGS+O/sj7nlgPcyx0Xt12bMLRLtqOSbamjg=; h=Date:From:To:Cc:Subject:Message-ID:References:MIME-Version: Content-Type:Content-Disposition:In-Reply-To; b=Hy1Bue32GNn17po1s06kWpXPkujx+n/uFnsoDHLmwKcg//QTEysrp2Hj8uDozSFJcY/LPG5+R1/fSMufk4fui9v5koY6JWK7z9M9ijZJevXTS0OfsWHe8bFbtF6eGi5u+MFtm1IEPijFf30QfCNkZTt1OUWpmoVQpzjybNPbVf8= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=ziepe.ca; spf=pass smtp.mailfrom=ziepe.ca; dkim=pass (2048-bit key) header.d=ziepe.ca header.i=@ziepe.ca header.b=NQ/yJETE; arc=none smtp.client-ip=209.85.222.181 Authentication-Results: smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=ziepe.ca Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=ziepe.ca Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=ziepe.ca header.i=@ziepe.ca header.b="NQ/yJETE" Received: by mail-qk1-f181.google.com with SMTP id af79cd13be357-8cb4136d865so526768685a.1 for ; Mon, 13 Apr 2026 05:59:27 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ziepe.ca; s=google; t=1776085167; x=1776689967; darn=vger.kernel.org; h=in-reply-to:content-disposition:mime-version:references:message-id :subject:cc:to:from:date:from:to:cc:subject:date:message-id:reply-to; bh=GtewcD3NlQ9T2rz4r/4NzvXWwz+tL/DhJnSJQl16Rzg=; b=NQ/yJETEshLeqFUYO2DS5IiOfry2MRFTCOmVsrsDiUAtcwdwRIOuAgHYt4FVCqLcPt xDaj6oJBXtFqxKgchNPeG5pL3w+dv5BEZrNkKClPsi5g54hiBDEfbSyhQFOY4e4SeyGm 2tmsraj+2jlrfHzYtVtTSh7B09cb4yyVsJ324wY7bhxhzXgnZDil5y0qGk2s3hjtke+w 0i8AQg1HXyi6SCJ3jK6iQS4NsSQ4sC6AqqZhA/9tYDYowPlRWNkyftiDGLPrKSK6Zazq rqHlu9tnfG1OpX2PqTk9OceMi/ZZorPig1/KHvA+AlUQl8+rQlpqApUBvRKUjv+0C5Vy BXmQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1776085167; x=1776689967; h=in-reply-to:content-disposition:mime-version:references:message-id :subject:cc:to:from:date:x-gm-gg:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to; bh=GtewcD3NlQ9T2rz4r/4NzvXWwz+tL/DhJnSJQl16Rzg=; b=Z9T7xjQDhCbsNhFOsr5+j2fPE4q9g9e2bWwwbFtV9pxwfLmT+SzFtSO9WSNA0TPT9L V0RNZrXaFR/U9DCDn7s7ArAl3ipVjC5ZgDZK5BkBYK6Doc0Sn/ycMeqxOuoicQLa+3+M R8IMgR1zAwI8oEDwzJ4qcWbjI5QX0hZlD+7v/omH3w9tjoxlPhidqWiAly+UzlWtjxTW 85ouHMmQLF8m0cLHO0ruaZcCQTwjCHyGRpXfEzDRnsCiqgXNvjNBq/cqIU96ruCMpfoA jx7gPAIwOWHItkjLTSTjoyUTxQ29j2aqj5uTMFNnu2jWsZpO89l/FDNQlT2+x0ZHiPZ5 /A2w== X-Forwarded-Encrypted: i=1; AFNElJ+1kZA6qZTDjttdX7gpddOR9rN1uPTvnoDE5Attt1MWnVe/GsjhaJ/H5scB9WFGT6jJ9WuYxSmnFF6yrIo=@vger.kernel.org X-Gm-Message-State: AOJu0Yz/lWpCk0Y7yIEURw6CWvKbI87GbdYbI0HG+XD08Q8anIWzJKKK x2FUoMkS2B8xqbp1I4woEr168sAl6s1wEhGjGDIBPy8KLk37FkhwyFc/OGsHLyA/j1s= X-Gm-Gg: AeBDievsuIG0hB4kJUOzKcOwwvf7WtKDsjgLIVOTFgvmJyf4gJmy7THtAvol4++JKRv mXDbs4jGqjIy3kniLKZraDgYzNsO0FqDXwZGVY92k3cCnWSbnIwXZU3TFaG3AlLMYVLdLOvVm1T 95o6s007TNEuU7JK0UIQQRg+8oPKM9wAiPZIwxa/EEj151lKJYBS3wxh5qVvPRkLLt+NOFxlnEF tf7xDVuy723aIIO9GLzeX5hvFHhSZ/lR7DHeBw3reoll6qMUW8Pm+WoAbEd8zajyV43gEHUX5u/ ozK14KmoV3vgpni2PyLYBSMzSs6nRqEEzDAbsURLfjVx/7I0Sc3I78bWM9K5/PLrfYvBa8JNxY1 dxnRv0FDiiHQKT7MuMVqN+zJ8ozbr2mfLaWRor05GoOnYAbhwJYoR+DmbhABbo/nan8RZAhnnVn c8CR7yYW7pUdJqJ1qgLjRgl+now+JX/N2hs/KzmminOE1B4eM0BXV/Ma4fZGQKwS2yAX8f9JCaq X7f0g== X-Received: by 2002:a05:620a:2589:b0:8cf:e015:afe2 with SMTP id af79cd13be357-8ddcf6b5c97mr1946023485a.48.1776085166749; Mon, 13 Apr 2026 05:59:26 -0700 (PDT) Received: from ziepe.ca (crbknf0213w-47-54-130-67.pppoe-dynamic.high-speed.nl.bellaliant.net. [47.54.130.67]) by smtp.gmail.com with ESMTPSA id af79cd13be357-8ddb646d715sm826322485a.15.2026.04.13.05.59.26 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 13 Apr 2026 05:59:26 -0700 (PDT) Received: from jgg by wakko with local (Exim 4.97) (envelope-from ) id 1wCGsv-00000005Aom-2whV; Mon, 13 Apr 2026 09:59:25 -0300 Date: Mon, 13 Apr 2026 09:59:25 -0300 From: Jason Gunthorpe To: Sami Mujawar , Dan Williams Cc: linux-arm-kernel@lists.infradead.org, linux-kernel@vger.kernel.org, catalin.marinas@arm.com, will@kernel.org, thuth@redhat.com, Suzuki.Poulose@arm.com, steven.price@arm.com, gshan@redhat.com, YeoReum.Yun@arm.com Subject: Re: [PATCH 0/3] arm64/virt: Add Arm CCA measurement register support Message-ID: <20260413125925.GK3694781@ziepe.ca> References: <20260413084957.327661-1-sami.mujawar@arm.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <20260413084957.327661-1-sami.mujawar@arm.com> On Mon, Apr 13, 2026 at 09:49:54AM +0100, Sami Mujawar wrote: > This series adds support for Arm Confidential Compute Architecture (CCA) > measurement registers in the Linux kernel, enabling guest Realms to > access, extend, and expose measurement values for attestation and runtime > integrity tracking. > > The Realm Management Monitor (RMM) defines a set of measurement registers > consisting of a Realm Initial Measurement (RIM) and a number of Realm > Extensible Measurements (REMs). This series introduces the necessary > infrastructure to interact with these registers via the RSI interface > and exposes them to userspace through the TSM measurement framework. > > At a high level, the series includes: > - Helper interfaces for reading and extending measurement > registers via RSI > - Definitions for Realm hash algorithms as defined by the > RMM specification > - Integration with the TSM measurement subsystem and sysfs > exposure for userspace visibility and interaction > > After applying this series, measurement registers are exposed under: > /sys/devices/virtual/misc/arm_cca_guest/measurements/ I'm surprised we get some random sysfs files? How does some more generic userspace figure out to use this vs a TPM or some other platform's version of it? I also think exposing PCRs as was done for TPM in sysfs was something of a mistake.. Allowing extension without logging is too low level and is very hard to build an entire attestation system around. I really think we are missing a subsystem here, TPM has sort of been filling this role in a non-generic way, but we should have a common uAPI for platform measurement & attestation: - Discover available measurements - Report signed measurements, with ingesting a nonce - Report measurement logs - Extend measurements and udpate logs - Report certificates used in signing - General reporting of various kinds of attestation evidence And it would be nice for the PCI devices and others to plug into the general framework as well instead of building a parallel TSM framework for handling evidence. Isn't this also sort of incomplete? Doesn't anything serious need signed measurements? Isnt't there alot more data that comes out of RMM than just a few measurement registers? Jason