From: Stefan Berger <stefanb@linux.ibm.com>
To: Jarkko Sakkinen <jarkko@kernel.org>, linux-integrity@vger.kernel.org
Cc: Jonathan Corbet <corbet@lwn.net>,
"Daniel P . Smith" <dpsmith@apertussolutions.com>,
Lino Sanfilippo <l.sanfilippo@kunbus.com>,
Jason Gunthorpe <jgg@ziepe.ca>, Peter Huewe <peterhuewe@gmx.de>,
James Bottomley <James.Bottomley@HansenPartnership.com>,
Alexander Steffen <Alexander.Steffen@infineon.com>,
keyrings@vger.kernel.org, linux-doc@vger.kernel.org,
linux-kernel@vger.kernel.org,
Randy Dunlap <rdunlap@infradead.org>
Subject: Re: [PATCH v2] Documentation: tpm_tis
Date: Wed, 20 Mar 2024 12:15:56 -0400 [thread overview]
Message-ID: <afc9471c-1c28-4384-82c1-29464ca1fb1f@linux.ibm.com> (raw)
In-Reply-To: <20240320085601.40450-1-jarkko@kernel.org>
On 3/20/24 04:56, Jarkko Sakkinen wrote:
> Based recent discussions on LKML, provide preliminary bits of tpm_tis_core
> dependent drivers. Includes only bare essentials but can be extended later
> on case by case. This way some people may even want to read it later on.
>
> Cc: Jonathan Corbet <corbet@lwn.net>
> CC: Daniel P. Smith <dpsmith@apertussolutions.com>
> Cc: Lino Sanfilippo <l.sanfilippo@kunbus.com>
> Cc: Jason Gunthorpe <jgg@ziepe.ca>
> Cc: Peter Huewe <peterhuewe@gmx.de>
> Cc: James Bottomley <James.Bottomley@HansenPartnership.com>
> Cc: Alexander Steffen <Alexander.Steffen@infineon.com>
> Cc: keyrings@vger.kernel.org
> Cc: linux-doc@vger.kernel.org
> Cc: linux-kernel@vger.kernel.org
> Cc: linux-integrity@vger.kernel.org
> Cc: Randy Dunlap <rdunlap@infradead.org>
> Signed-off-by: Jarkko Sakkinen <jarkko@kernel.org>
> ---
> v2:
> - Fixed errors reported by Randy:
> https://lore.kernel.org/all/aed28265-d677-491a-a045-24b351854b24@infradead.org/
> - Improved the text a bit to have a better presentation.
> ---
> Documentation/security/tpm/index.rst | 1 +
> Documentation/security/tpm/tpm_tis.rst | 30 ++++++++++++++++++++++++++
> 2 files changed, 31 insertions(+)
> create mode 100644 Documentation/security/tpm/tpm_tis.rst
>
> diff --git a/Documentation/security/tpm/index.rst b/Documentation/security/tpm/index.rst
> index fc40e9f23c85..f27a17f60a96 100644
> --- a/Documentation/security/tpm/index.rst
> +++ b/Documentation/security/tpm/index.rst
> @@ -5,6 +5,7 @@ Trusted Platform Module documentation
> .. toctree::
>
> tpm_event_log
> + tpm_tis
> tpm_vtpm_proxy
> xen-tpmfront
> tpm_ftpm_tee
> diff --git a/Documentation/security/tpm/tpm_tis.rst b/Documentation/security/tpm/tpm_tis.rst
> new file mode 100644
> index 000000000000..b331813b3c45
> --- /dev/null
> +++ b/Documentation/security/tpm/tpm_tis.rst
> @@ -0,0 +1,30 @@
> +.. SPDX-License-Identifier: GPL-2.0
> +
> +=========================
> +TPM FIFO interface Driver
> +=========================
> +
> +FIFO (First-In-First-Out) is the name of the hardware interface used by the
FIFO is the type. I am surprised you call it a 'name'. I would say TIS
is the 'name'.
> +tpm_tis_core dependent drivers. The prefix "tis" comes from the TPM Interface
tis is a tla -- a three letter *acronym*. You aren't using it as a 'prefix'.
> +Specification, which is the hardware interface specification for TPM 1.x chips.
It's also available for TPM2.
> +
> +Communication is based on a 5 KiB buffer shared by the TPM chip through a
I thought it was typically 4 KiB.
> +hardware bus or memory map, depending on the physical wiring. The buffer is
> +further split into five equal-size buffers, which provide equivalent sets of
equal-sized MMIO regions?
> +registers for communication between the CPU and TPM. These communication
> +endpoints are called localities in the TCG terminology.
> +
> +When the kernel wants to send commands to the TPM chip, it first reserves
> +locality 0 by setting the requestUse bit in the TPM_ACCESS register. The bit is
> +cleared by the chip when the access is granted. Once it completes its
> +communication, the kernel writes the TPM_ACCESS.activeLocality bit. This
> +informs the chip that the locality has been relinquished.
> +
> +Pending localities are served in order by the chip in descending order, one at
> +a time:
I think I know what pending localities are because I have worked with
this device but I am not sure whether the user can deduce this from the
paragraph above. Also, why this particular detail when the driver only
uses locality 0 and nobody is competing about access to localities?
> +
> +- Locality 0 has the lowest priority.
> +- Locality 5 has the highest priority.
> +
> +Further information on the purpose and meaning of the localities can be found
> +in section 3.2 of the TCG PC Client Platform TPM Profile Specification.
next prev parent reply other threads:[~2024-03-20 16:16 UTC|newest]
Thread overview: 9+ messages / expand[flat|nested] mbox.gz Atom feed top
2024-03-20 8:56 Jarkko Sakkinen
2024-03-20 14:27 ` Randy Dunlap
2024-03-21 15:55 ` Jarkko Sakkinen
2024-03-20 16:15 ` Stefan Berger [this message]
2024-03-21 15:51 ` Jarkko Sakkinen
2024-03-21 16:09 ` Stefan Berger
2024-03-21 16:24 ` Jarkko Sakkinen
2024-03-21 16:32 ` Jarkko Sakkinen
2024-03-21 16:35 ` Jarkko Sakkinen
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=afc9471c-1c28-4384-82c1-29464ca1fb1f@linux.ibm.com \
--to=stefanb@linux.ibm.com \
--cc=Alexander.Steffen@infineon.com \
--cc=James.Bottomley@HansenPartnership.com \
--cc=corbet@lwn.net \
--cc=dpsmith@apertussolutions.com \
--cc=jarkko@kernel.org \
--cc=jgg@ziepe.ca \
--cc=keyrings@vger.kernel.org \
--cc=l.sanfilippo@kunbus.com \
--cc=linux-doc@vger.kernel.org \
--cc=linux-integrity@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=peterhuewe@gmx.de \
--cc=rdunlap@infradead.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®