From: Jan Kiszka <jan.kiszka@siemens.com>
To: Ilias Apalodimas <ilias.apalodimas@linaro.org>,
Masahisa Kojima <masahisa.kojima@linaro.org>
Cc: Ard Biesheuvel <ardb@kernel.org>,
Jens Wiklander <jens.wiklander@linaro.org>,
Sumit Garg <sumit.garg@linaro.org>,
linux-kernel@vger.kernel.org, op-tee@lists.trustedfirmware.org,
Johan Hovold <johan+linaro@kernel.org>,
Randy Dunlap <rdunlap@infradead.org>,
Heinrich Schuchardt <heinrich.schuchardt@canonical.com>,
Jonathan Cameron <Jonathan.Cameron@huawei.com>
Subject: Re: [PATCH v8 0/5] introduce tee-based EFI Runtime Variable Service
Date: Mon, 14 Aug 2023 19:23:26 +0200 [thread overview]
Message-ID: <660cec45-d0d1-433f-b58e-a22a07a289fb@siemens.com> (raw)
In-Reply-To: <CAC_iWjLU+mVtG4uGVoEJSJwuE0=GVcfJgi=h3QX54=fh2P4EAg@mail.gmail.com>
On 14.08.23 11:24, Ilias Apalodimas wrote:
> Hi Jan,
>
> On Mon, 7 Aug 2023 at 05:53, Masahisa Kojima <masahisa.kojima@linaro.org> wrote:
>>
>> This series introduces the tee based EFI Runtime Variable Service.
>>
>> The eMMC device is typically owned by the non-secure world(linux in
>> this case). There is an existing solution utilizing eMMC RPMB partition
>> for EFI Variables, it is implemented by interacting with
>> OP-TEE, StandaloneMM(as EFI Variable Service Pseudo TA), eMMC driver
>> and tee-supplicant. The last piece is the tee-based variable access
>> driver to interact with OP-TEE and StandaloneMM.
>>
>> Changelog:
>> v7 -> v8
>> Only patch #3 "efi: Add tee-based EFI variable driver" is updated.
>> - fix typos
>> - refactor error handling, direct return if applicable
>> - use devm_add_action_or_reset() for closing of tee context/session
>> - remove obvious comment
>
> Any chance you can run this and see if it solves your issues?
>
I also need [1], and I still need a cleanup script before terminating
the tee-supplicant, right? And if need some service in the initrd
already, I still need to start the supplicant there and transfer its
ownership to systemd later on? These patches here only make life easier
if the supplicant is started by systemd, after efivarfs has been
mounted, correct?
Jan
[1] https://lkml.org/lkml/2023/7/28/853
--
Siemens AG, Technology
Linux Expert Center
next prev parent reply other threads:[~2023-08-14 17:24 UTC|newest]
Thread overview: 19+ messages / expand[flat|nested] mbox.gz Atom feed top
2023-08-07 2:53 Masahisa Kojima
2023-08-07 2:53 ` [PATCH v8 1/5] efi: expose efivar generic ops register function Masahisa Kojima
2023-08-07 2:53 ` [PATCH v8 2/5] efi: Add EFI_ACCESS_DENIED status code Masahisa Kojima
2023-08-07 2:53 ` [PATCH v8 3/5] efi: Add tee-based EFI variable driver Masahisa Kojima
2023-08-08 9:43 ` Jonathan Cameron
2023-08-07 2:53 ` [PATCH v8 4/5] efivarfs: automatically update super block flag Masahisa Kojima
2023-10-11 17:00 ` Ilias Apalodimas
2023-10-13 6:20 ` Masahisa Kojima
2023-10-13 7:53 ` Sumit Garg
2023-10-13 15:25 ` Ilias Apalodimas
2023-10-17 10:58 ` Sumit Garg
2023-10-17 12:55 ` Ilias Apalodimas
2023-08-07 2:53 ` [PATCH v8 5/5] efivarfs: force RO when remounting if SetVariable is not supported Masahisa Kojima
2023-08-14 9:24 ` [PATCH v8 0/5] introduce tee-based EFI Runtime Variable Service Ilias Apalodimas
2023-08-14 17:23 ` Jan Kiszka [this message]
[not found] ` <CADQ0-X_dJag7EuEEEgCZrnJNNH9Va77mxmGYA9vPFw9DkoB-AA@mail.gmail.com>
2023-08-16 11:58 ` Ilias Apalodimas
2023-08-16 14:07 ` Jan Kiszka
2023-08-17 9:22 ` Sumit Garg
2023-08-17 9:33 ` Ilias Apalodimas
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=660cec45-d0d1-433f-b58e-a22a07a289fb@siemens.com \
--to=jan.kiszka@siemens.com \
--cc=Jonathan.Cameron@huawei.com \
--cc=ardb@kernel.org \
--cc=heinrich.schuchardt@canonical.com \
--cc=ilias.apalodimas@linaro.org \
--cc=jens.wiklander@linaro.org \
--cc=johan+linaro@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=masahisa.kojima@linaro.org \
--cc=op-tee@lists.trustedfirmware.org \
--cc=rdunlap@infradead.org \
--cc=sumit.garg@linaro.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®