* [PATCH v2 0/3] arm64/virt: Add Arm CCA measurement register support
@ 2026-09-29 16:57 Yeoreum Yun
2026-09-29 16:57 ` [PATCH v2 1/3] arm64: rsi: Add helpers for Arm CCA measurement register operations Yeoreum Yun
` (3 more replies)
0 siblings, 4 replies; 17+ messages in thread
From: Yeoreum Yun @ 2026-09-29 16:57 UTC (permalink / raw)
To: linux-arm-kernel, linux-kernel
Cc: Catalin Marinas, Will Deacon, Jason Gunthorpe, Suzuki Poulose,
Steven Price, Sami Mujawar, thuth
This series adds support for Arm Confidential Compute Architecture (CCA)
measurement registers in the Linux kernel, enabling guest Realms to
access, extend, and expose measurement values for attestation and runtime
integrity tracking.
The Realm Management Monitor (RMM) defines a set of measurement registers
consisting of a Realm Initial Measurement (RIM) and a number of Realm
Extensible Measurements (REMs). This series introduces the necessary
infrastructure to interact with these registers via the RSI interface
and exposes them to userspace through the TSM measurement framework.
At a high level, the series includes:
- Helper interfaces for reading and extending measurement
registers via RSI
- Definitions for Realm hash algorithms as defined by the
RMM specification
- Integration with the TSM measurement subsystem and sysfs
exposure for userspace visibility and interaction
After applying this series, measurement registers are exposed under:
/sys/devices/virtual/misc/arm_cca_guest/measurements/
Where:
- rim is read-only (initial measurement)
- rem[0-3] are read/write (extensible measurements)
- The hash algorithm reflects the Realm configuration
Patch summary:
1. arm64: rsi: Add helpers for Arm CCA measurement registers
- Introduces RSI helper APIs to read and extend RIM/REM registers
2. arm64: rsi: Add realm hash algorithm defines
- Adds definitions for SHA-256 and SHA-512 identifiers returned
by the RMM
3. virt: arm-cca-guest: Add support for measurement registers
- Integrates with TSM measurement framework
- Implements measurement register refresh and extend operations
- Exposes registers via sysfs using a misc device
- Dynamically configures hash algorithm and digest size per Realm
This enables a consistent mechanism for attestation-related measurements
in Arm CCA guests and aligns with the kernel TSM measurement abstraction.
This patch based on arm64 tree's for-next/smccc-bus
---
Changes in v2:
- rebase to arm64 tree's for-next/smccc-bus
- Link to v1: https://lore.kernel.org/all/20260413084957.327661-1-sami.mujawar@arm.com/
---
---
Sami Mujawar (3):
arm64: rsi: Add helpers for Arm CCA measurement register operations
arm64: rsi: Add realm hash algorithm defines
virt: arm-cca-guest: Add support for measurement registers
.../sysfs-devices-virtual-misc-arm_cca_guest | 38 +++
drivers/virt/coco/arm-cca-guest/Kconfig | 1 +
drivers/virt/coco/arm-cca-guest/main.c | 282 ++++++++++++++++++++-
include/linux/arm-rsi-cmds.h | 105 +++++++-
include/linux/arm-smccc-rsi.h | 7 +
5 files changed, 430 insertions(+), 3 deletions(-)
---
base-commit: bce57945f5e7207960b2bd567a6e880f90258ffb
change-id: 20260929-arm_cca_mr-a194b2e92c17
Best regards,
--
Sincerely,
Yeoreum Yun
^ permalink raw reply [flat|nested] 17+ messages in thread* [PATCH v2 1/3] arm64: rsi: Add helpers for Arm CCA measurement register operations 2026-09-29 16:57 [PATCH v2 0/3] arm64/virt: Add Arm CCA measurement register support Yeoreum Yun @ 2026-09-29 16:57 ` Yeoreum Yun 2026-09-30 2:04 ` Kohei Enju 2026-09-29 16:57 ` [PATCH v2 2/3] arm64: rsi: Add realm hash algorithm defines Yeoreum Yun ` (2 subsequent siblings) 3 siblings, 1 reply; 17+ messages in thread From: Yeoreum Yun @ 2026-09-29 16:57 UTC (permalink / raw) To: linux-arm-kernel, linux-kernel Cc: Catalin Marinas, Will Deacon, Jason Gunthorpe, Suzuki Poulose, Steven Price, Sami Mujawar, thuth From: Sami Mujawar <sami.mujawar@arm.com> Add static inline helper functions to support reading the Realm Initial Measurement (RIM) and reading/extending the Realm Extensible Measurement (REM) registers. The indices of the Arm CCA measurement registers, as defined by the Realm Management Monitor specification, are as follows: Index Register 0 RIM 1 - 4 REM[0 - 3] The rsi_measurement_extend() function allows extending REM[0–3] registers with a caller-provided digest (up to 64 bytes). Index 0 (RIM) is read-only and cannot be extended. The rsi_measurement_read() function allows reading measurement values from RIM (index 0) or REM[0–3] (indices 1–4). The returned digest is expected to be 64 bytes. Signed-off-by: Sami Mujawar <sami.mujawar@arm.com> --- include/linux/arm-rsi-cmds.h | 105 ++++++++++++++++++++++++++++++++++++++++++- 1 file changed, 104 insertions(+), 1 deletion(-) diff --git a/include/linux/arm-rsi-cmds.h b/include/linux/arm-rsi-cmds.h index 3f7a6a833993..608343266d81 100644 --- a/include/linux/arm-rsi-cmds.h +++ b/include/linux/arm-rsi-cmds.h @@ -1,6 +1,6 @@ /* SPDX-License-Identifier: GPL-2.0-only */ /* - * Copyright (C) 2023 ARM Ltd. + * Copyright (C) 2023 - 2025 ARM Ltd. */ #ifndef __LINUX_ARM_RSI_CMDS_H_ @@ -36,6 +36,26 @@ static inline bool is_realm_world(void) { return false; } #define RSI_GRANULE_SHIFT 12 #define RSI_GRANULE_SIZE (_AC(1, UL) << RSI_GRANULE_SHIFT) +/* + * Maximum measurement data size in bytes. + * According to the RMM Specification, the width of the RmmRealmMeasurement type + * is 512 bits. + */ +#define RSI_MAX_MEASUREMENT_DATA_SIZE_BYTES 64 + +/* + * Indices for the Realm Initial Measurement register (RIM) and the Realm + * Extensible Measurement registers (REMs). + * According to the RMM Specification, Realm attributes of a Realm include + * an array of measurement values. The first entry in this array is a RIM. + * The remaining entries in this array are REMs. + */ +#define RSI_INDEX_RIM 0 +#define RSI_INDEX_REM0 1 +#define RSI_INDEX_REM1 2 +#define RSI_INDEX_REM2 3 +#define RSI_INDEX_REM3 4 + enum ripas { RSI_RIPAS_EMPTY = 0, RSI_RIPAS_RAM = 1, @@ -236,4 +256,87 @@ static inline unsigned long rsi_attestation_token_continue(phys_addr_t granule, return res.a0; } +/** + * rsi_measurement_extend - Extend the measurement value to the Realm Extensible + * Measurement (REM). + * + * @idx: Index of the REM register. + * Where: + * Index Register + * 1 - 4 REM[0-3] + * @digest: The digest data to be extended. + * @digest_size: Size of the digest data in bytes. + * + * Returns: + * On success, returns RSI_SUCCESS. + * Otherwise, -EINVAL + */ +static inline unsigned long rsi_measurement_extend(u32 idx, + const u8 *digest, + unsigned long digest_size) +{ + struct arm_smccc_1_2_regs regs = { 0 }; + + /* + * Index 0 is for RIM (which is Read Only), while + * REM[0-3] are indexed from 1 - 4. + * The digest size can be at the most 64 bytes. + */ + if (!digest || idx < RSI_INDEX_REM0 || idx > RSI_INDEX_REM3 || + digest_size == 0 || digest_size > RSI_MAX_MEASUREMENT_DATA_SIZE_BYTES) + return -EINVAL; + + regs.a0 = SMC_RSI_MEASUREMENT_EXTEND; + regs.a1 = idx; + regs.a2 = digest_size; + memcpy(®s.a3, digest, digest_size); + arm_smccc_1_2_smc(®s, ®s); + + if (regs.a0 != RSI_SUCCESS) + return -EINVAL; + + return regs.a0; +} + +/** + * rsi_measurement_read - Read the measurement value from the Realm Initial + * Measurement (RIM) or the Realm Extensible Measurement (REM) register. + * + * @idx: Index of the RIM or REM register. + * Where: + * Index Register + * 0 RIM + * 1 - 4 REM[0-3] + * @digest: The digest data to be returned. + * @digest_size: Size of the digest data buffer in bytes. + * + * Returns: + * On success, returns RSI_SUCCESS. + * Otherwise, -EINVAL + */ +static inline unsigned long rsi_measurement_read(u32 idx, + u8 *digest, + unsigned long digest_size) +{ + struct arm_smccc_1_2_regs regs = { 0 }; + + /* + * The digest size can be at the most 64 bytes, if less then 64 bytes + * it is zero padded. + */ + if (!digest || idx > RSI_INDEX_REM3 || + digest_size == 0 || digest_size > RSI_MAX_MEASUREMENT_DATA_SIZE_BYTES) + return -EINVAL; + + regs.a0 = SMC_RSI_MEASUREMENT_READ; + regs.a1 = idx; + arm_smccc_1_2_smc(®s, ®s); + + if (regs.a0 != RSI_SUCCESS) + return -EINVAL; + + memcpy(digest, ®s.a1, digest_size); + return regs.a0; +} + #endif /* __LINUX_ARM_RSI_CMDS_H_ */ -- 2.43.0 ^ permalink raw reply [flat|nested] 17+ messages in thread
* Re: [PATCH v2 1/3] arm64: rsi: Add helpers for Arm CCA measurement register operations 2026-09-29 16:57 ` [PATCH v2 1/3] arm64: rsi: Add helpers for Arm CCA measurement register operations Yeoreum Yun @ 2026-09-30 2:04 ` Kohei Enju 2026-09-30 5:13 ` Yeoreum Yun 0 siblings, 1 reply; 17+ messages in thread From: Kohei Enju @ 2026-09-30 2:04 UTC (permalink / raw) To: Yeoreum Yun Cc: linux-arm-kernel, linux-kernel, Catalin Marinas, Will Deacon, Jason Gunthorpe, Suzuki Poulose, Steven Price, Sami Mujawar, thuth On 09/29 17:57, Yeoreum Yun wrote: > From: Sami Mujawar <sami.mujawar@arm.com> > > Add static inline helper functions to support reading the Realm > Initial Measurement (RIM) and reading/extending the Realm > Extensible Measurement (REM) registers. > > The indices of the Arm CCA measurement registers, as defined by > the Realm Management Monitor specification, are as follows: > Index Register > 0 RIM > 1 - 4 REM[0 - 3] > > The rsi_measurement_extend() function allows extending REM[0–3] > registers with a caller-provided digest (up to 64 bytes). > Index 0 (RIM) is read-only and cannot be extended. > > The rsi_measurement_read() function allows reading measurement > values from RIM (index 0) or REM[0–3] (indices 1–4). The returned > digest is expected to be 64 bytes. > > Signed-off-by: Sami Mujawar <sami.mujawar@arm.com> > --- > include/linux/arm-rsi-cmds.h | 105 ++++++++++++++++++++++++++++++++++++++++++- > 1 file changed, 104 insertions(+), 1 deletion(-) > > diff --git a/include/linux/arm-rsi-cmds.h b/include/linux/arm-rsi-cmds.h > index 3f7a6a833993..608343266d81 100644 > --- a/include/linux/arm-rsi-cmds.h > +++ b/include/linux/arm-rsi-cmds.h > @@ -1,6 +1,6 @@ > /* SPDX-License-Identifier: GPL-2.0-only */ > /* > - * Copyright (C) 2023 ARM Ltd. > + * Copyright (C) 2023 - 2025 ARM Ltd. > */ > > #ifndef __LINUX_ARM_RSI_CMDS_H_ > @@ -36,6 +36,26 @@ static inline bool is_realm_world(void) { return false; } > #define RSI_GRANULE_SHIFT 12 > #define RSI_GRANULE_SIZE (_AC(1, UL) << RSI_GRANULE_SHIFT) > > +/* > + * Maximum measurement data size in bytes. > + * According to the RMM Specification, the width of the RmmRealmMeasurement type > + * is 512 bits. > + */ > +#define RSI_MAX_MEASUREMENT_DATA_SIZE_BYTES 64 > + > +/* > + * Indices for the Realm Initial Measurement register (RIM) and the Realm > + * Extensible Measurement registers (REMs). > + * According to the RMM Specification, Realm attributes of a Realm include > + * an array of measurement values. The first entry in this array is a RIM. > + * The remaining entries in this array are REMs. > + */ > +#define RSI_INDEX_RIM 0 > +#define RSI_INDEX_REM0 1 > +#define RSI_INDEX_REM1 2 > +#define RSI_INDEX_REM2 3 > +#define RSI_INDEX_REM3 4 > + > enum ripas { > RSI_RIPAS_EMPTY = 0, > RSI_RIPAS_RAM = 1, > @@ -236,4 +256,87 @@ static inline unsigned long rsi_attestation_token_continue(phys_addr_t granule, > return res.a0; > } > > +/** > + * rsi_measurement_extend - Extend the measurement value to the Realm Extensible > + * Measurement (REM). > + * > + * @idx: Index of the REM register. > + * Where: > + * Index Register > + * 1 - 4 REM[0-3] > + * @digest: The digest data to be extended. > + * @digest_size: Size of the digest data in bytes. > + * > + * Returns: > + * On success, returns RSI_SUCCESS. > + * Otherwise, -EINVAL > + */ > +static inline unsigned long rsi_measurement_extend(u32 idx, > + const u8 *digest, > + unsigned long digest_size) > +{ > + struct arm_smccc_1_2_regs regs = { 0 }; > + > + /* > + * Index 0 is for RIM (which is Read Only), while > + * REM[0-3] are indexed from 1 - 4. > + * The digest size can be at the most 64 bytes. > + */ > + if (!digest || idx < RSI_INDEX_REM0 || idx > RSI_INDEX_REM3 || > + digest_size == 0 || digest_size > RSI_MAX_MEASUREMENT_DATA_SIZE_BYTES) > + return -EINVAL; > + > + regs.a0 = SMC_RSI_MEASUREMENT_EXTEND; > + regs.a1 = idx; > + regs.a2 = digest_size; > + memcpy(®s.a3, digest, digest_size); With CONFIG_FORTIFY_SOURCE=y, FORTIFY reports the following warning for this memcpy: [ 899.918673] ------------[ cut here ]------------ [ 899.918806] memcpy: detected field-spanning write (size 32) of single field "®s.a3" at ./include/linux/arm-rsi-cmds.h:292 (size 8) [ 899.919277] WARNING: ./include/linux/arm-rsi-cmds.h:292 at rsi_measurement_extend+0x104/0x118, CPU#0: dd/123 [ 900.672180] Modules linked in: [ 900.769378] CPU: 0 UID: 0 PID: 123 Comm: dd Not tainted 7.3.0-rc4+ #6 PREEMPT(full) [ 901.034515] Hardware name: linux,dummy-virt (DT) [ 901.194939] pstate: 61402005 (nZCv daif +PAN -UAO -TCO +DIT -SSBS BTYPE=--) [ 901.390491] pc : rsi_measurement_extend+0x104/0x118 [ 901.530657] lr : rsi_measurement_extend+0x104/0x118 [...] [ 903.770326] Call trace: [ 903.893102] rsi_measurement_extend+0x104/0x118 (P) [ 904.056234] arm_cca_mr_extend+0x40/0x58 [ 904.270991] tm_digest_write+0x90/0x1d8 [ 904.439429] sysfs_kf_bin_write+0x98/0xc8 [ 904.596599] kernfs_fop_write_iter+0x150/0x1e8 [ 904.779881] vfs_write+0x29c/0x450 [...] Would it make sense to use a union to overlay the struct arm_smccc_1_2_regs with an RSI-specific argument layout and copy the digest into an explicit 64-byte array, as in commit 221049874b6a ("arm64: RSI: fix field-spanning write warning in attestation token init")? Thanks, Kohei > + arm_smccc_1_2_smc(®s, ®s); > + > + if (regs.a0 != RSI_SUCCESS) > + return -EINVAL; > + > + return regs.a0; > +} > + ^ permalink raw reply [flat|nested] 17+ messages in thread
* Re: [PATCH v2 1/3] arm64: rsi: Add helpers for Arm CCA measurement register operations 2026-09-30 2:04 ` Kohei Enju @ 2026-09-30 5:13 ` Yeoreum Yun 0 siblings, 0 replies; 17+ messages in thread From: Yeoreum Yun @ 2026-09-30 5:13 UTC (permalink / raw) To: Kohei Enju Cc: Yeoreum Yun, linux-arm-kernel, linux-kernel, Catalin Marinas, Will Deacon, Jason Gunthorpe, Suzuki Poulose, Steven Price, Sami Mujawar, thuth > On 09/29 17:57, Yeoreum Yun wrote: > > From: Sami Mujawar <sami.mujawar@arm.com> > > > > Add static inline helper functions to support reading the Realm > > Initial Measurement (RIM) and reading/extending the Realm > > Extensible Measurement (REM) registers. > > > > The indices of the Arm CCA measurement registers, as defined by > > the Realm Management Monitor specification, are as follows: > > Index Register > > 0 RIM > > 1 - 4 REM[0 - 3] > > > > The rsi_measurement_extend() function allows extending REM[0–3] > > registers with a caller-provided digest (up to 64 bytes). > > Index 0 (RIM) is read-only and cannot be extended. > > > > The rsi_measurement_read() function allows reading measurement > > values from RIM (index 0) or REM[0–3] (indices 1–4). The returned > > digest is expected to be 64 bytes. > > > > Signed-off-by: Sami Mujawar <sami.mujawar@arm.com> > > --- > > include/linux/arm-rsi-cmds.h | 105 ++++++++++++++++++++++++++++++++++++++++++- > > 1 file changed, 104 insertions(+), 1 deletion(-) > > > > diff --git a/include/linux/arm-rsi-cmds.h b/include/linux/arm-rsi-cmds.h > > index 3f7a6a833993..608343266d81 100644 > > --- a/include/linux/arm-rsi-cmds.h > > +++ b/include/linux/arm-rsi-cmds.h > > @@ -1,6 +1,6 @@ > > /* SPDX-License-Identifier: GPL-2.0-only */ > > /* > > - * Copyright (C) 2023 ARM Ltd. > > + * Copyright (C) 2023 - 2025 ARM Ltd. > > */ > > > > #ifndef __LINUX_ARM_RSI_CMDS_H_ > > @@ -36,6 +36,26 @@ static inline bool is_realm_world(void) { return false; } > > #define RSI_GRANULE_SHIFT 12 > > #define RSI_GRANULE_SIZE (_AC(1, UL) << RSI_GRANULE_SHIFT) > > > > +/* > > + * Maximum measurement data size in bytes. > > + * According to the RMM Specification, the width of the RmmRealmMeasurement type > > + * is 512 bits. > > + */ > > +#define RSI_MAX_MEASUREMENT_DATA_SIZE_BYTES 64 > > + > > +/* > > + * Indices for the Realm Initial Measurement register (RIM) and the Realm > > + * Extensible Measurement registers (REMs). > > + * According to the RMM Specification, Realm attributes of a Realm include > > + * an array of measurement values. The first entry in this array is a RIM. > > + * The remaining entries in this array are REMs. > > + */ > > +#define RSI_INDEX_RIM 0 > > +#define RSI_INDEX_REM0 1 > > +#define RSI_INDEX_REM1 2 > > +#define RSI_INDEX_REM2 3 > > +#define RSI_INDEX_REM3 4 > > + > > enum ripas { > > RSI_RIPAS_EMPTY = 0, > > RSI_RIPAS_RAM = 1, > > @@ -236,4 +256,87 @@ static inline unsigned long rsi_attestation_token_continue(phys_addr_t granule, > > return res.a0; > > } > > > > +/** > > + * rsi_measurement_extend - Extend the measurement value to the Realm Extensible > > + * Measurement (REM). > > + * > > + * @idx: Index of the REM register. > > + * Where: > > + * Index Register > > + * 1 - 4 REM[0-3] > > + * @digest: The digest data to be extended. > > + * @digest_size: Size of the digest data in bytes. > > + * > > + * Returns: > > + * On success, returns RSI_SUCCESS. > > + * Otherwise, -EINVAL > > + */ > > +static inline unsigned long rsi_measurement_extend(u32 idx, > > + const u8 *digest, > > + unsigned long digest_size) > > +{ > > + struct arm_smccc_1_2_regs regs = { 0 }; > > + > > + /* > > + * Index 0 is for RIM (which is Read Only), while > > + * REM[0-3] are indexed from 1 - 4. > > + * The digest size can be at the most 64 bytes. > > + */ > > + if (!digest || idx < RSI_INDEX_REM0 || idx > RSI_INDEX_REM3 || > > + digest_size == 0 || digest_size > RSI_MAX_MEASUREMENT_DATA_SIZE_BYTES) > > + return -EINVAL; > > + > > + regs.a0 = SMC_RSI_MEASUREMENT_EXTEND; > > + regs.a1 = idx; > > + regs.a2 = digest_size; > > + memcpy(®s.a3, digest, digest_size); > > With CONFIG_FORTIFY_SOURCE=y, FORTIFY reports the following warning for > this memcpy: > > [ 899.918673] ------------[ cut here ]------------ > [ 899.918806] memcpy: detected field-spanning write (size 32) of single field "®s.a3" at ./include/linux/arm-rsi-cmds.h:292 (size 8) > [ 899.919277] WARNING: ./include/linux/arm-rsi-cmds.h:292 at rsi_measurement_extend+0x104/0x118, CPU#0: dd/123 > [ 900.672180] Modules linked in: > [ 900.769378] CPU: 0 UID: 0 PID: 123 Comm: dd Not tainted 7.3.0-rc4+ #6 PREEMPT(full) > [ 901.034515] Hardware name: linux,dummy-virt (DT) > [ 901.194939] pstate: 61402005 (nZCv daif +PAN -UAO -TCO +DIT -SSBS BTYPE=--) > [ 901.390491] pc : rsi_measurement_extend+0x104/0x118 > [ 901.530657] lr : rsi_measurement_extend+0x104/0x118 > [...] > [ 903.770326] Call trace: > [ 903.893102] rsi_measurement_extend+0x104/0x118 (P) > [ 904.056234] arm_cca_mr_extend+0x40/0x58 > [ 904.270991] tm_digest_write+0x90/0x1d8 > [ 904.439429] sysfs_kf_bin_write+0x98/0xc8 > [ 904.596599] kernfs_fop_write_iter+0x150/0x1e8 > [ 904.779881] vfs_write+0x29c/0x450 > [...] > > Would it make sense to use a union to overlay the struct > arm_smccc_1_2_regs with an RSI-specific argument layout and copy the > digest into an explicit 64-byte array, as in commit 221049874b6a > ("arm64: RSI: fix field-spanning write warning in attestation token > init")? Thanks for reporting and suggestion. I'll fix at next-spin. -- Sincerely, Yeoreum Yun ^ permalink raw reply [flat|nested] 17+ messages in thread
* [PATCH v2 2/3] arm64: rsi: Add realm hash algorithm defines 2026-09-29 16:57 [PATCH v2 0/3] arm64/virt: Add Arm CCA measurement register support Yeoreum Yun 2026-09-29 16:57 ` [PATCH v2 1/3] arm64: rsi: Add helpers for Arm CCA measurement register operations Yeoreum Yun @ 2026-09-29 16:57 ` Yeoreum Yun 2026-09-30 2:39 ` Kohei Enju 2026-09-29 16:57 ` [PATCH v2 3/3] virt: arm-cca-guest: Add support for measurement registers Yeoreum Yun 2026-09-29 19:20 ` [PATCH v2 0/3] arm64/virt: Add Arm CCA measurement register support Jason Gunthorpe 3 siblings, 1 reply; 17+ messages in thread From: Yeoreum Yun @ 2026-09-29 16:57 UTC (permalink / raw) To: linux-arm-kernel, linux-kernel Cc: Catalin Marinas, Will Deacon, Jason Gunthorpe, Suzuki Poulose, Steven Price, Sami Mujawar, thuth From: Sami Mujawar <sami.mujawar@arm.com> Add macro definitions for the hash algorithm identifiers, as specified in the Realm Management Monitor (RMM) specification. Signed-off-by: Sami Mujawar <sami.mujawar@arm.com> --- include/linux/arm-smccc-rsi.h | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/include/linux/arm-smccc-rsi.h b/include/linux/arm-smccc-rsi.h index fddb77986f70..a83df2655808 100644 --- a/include/linux/arm-smccc-rsi.h +++ b/include/linux/arm-smccc-rsi.h @@ -144,6 +144,13 @@ struct realm_config { #endif /* __ASSEMBLER__ */ +/* + * The RSI definition of the Hash Algorithm (as specified by the Secure + * Hash Standard) returned in the realm_config data structure. + */ +#define RSI_HASH_SHA_256 0 +#define RSI_HASH_SHA_512 1 + /* * Read configuration for the current Realm. * -- 2.43.0 ^ permalink raw reply [flat|nested] 17+ messages in thread
* Re: [PATCH v2 2/3] arm64: rsi: Add realm hash algorithm defines 2026-09-29 16:57 ` [PATCH v2 2/3] arm64: rsi: Add realm hash algorithm defines Yeoreum Yun @ 2026-09-30 2:39 ` Kohei Enju 2026-09-30 5:10 ` Yeoreum Yun 0 siblings, 1 reply; 17+ messages in thread From: Kohei Enju @ 2026-09-30 2:39 UTC (permalink / raw) To: Yeoreum Yun Cc: linux-arm-kernel, linux-kernel, Catalin Marinas, Will Deacon, Jason Gunthorpe, Suzuki Poulose, Steven Price, Sami Mujawar, thuth On 09/29 17:57, Yeoreum Yun wrote: > From: Sami Mujawar <sami.mujawar@arm.com> > > Add macro definitions for the hash algorithm identifiers, as > specified in the Realm Management Monitor (RMM) specification. > > Signed-off-by: Sami Mujawar <sami.mujawar@arm.com> > --- > include/linux/arm-smccc-rsi.h | 7 +++++++ > 1 file changed, 7 insertions(+) > > diff --git a/include/linux/arm-smccc-rsi.h b/include/linux/arm-smccc-rsi.h > index fddb77986f70..a83df2655808 100644 > --- a/include/linux/arm-smccc-rsi.h > +++ b/include/linux/arm-smccc-rsi.h > @@ -144,6 +144,13 @@ struct realm_config { > > #endif /* __ASSEMBLER__ */ > > +/* > + * The RSI definition of the Hash Algorithm (as specified by the Secure > + * Hash Standard) returned in the realm_config data structure. > + */ > +#define RSI_HASH_SHA_256 0 > +#define RSI_HASH_SHA_512 1 Is it intentional to omit RSI_HASH_SHA_384 here? I realize it might not be implemented in RMM yet, but would it be worth adding the constant now for future support? Thanks, Kohei > + > /* > * Read configuration for the current Realm. > * > > -- > 2.43.0 > ^ permalink raw reply [flat|nested] 17+ messages in thread
* Re: [PATCH v2 2/3] arm64: rsi: Add realm hash algorithm defines 2026-09-30 2:39 ` Kohei Enju @ 2026-09-30 5:10 ` Yeoreum Yun 0 siblings, 0 replies; 17+ messages in thread From: Yeoreum Yun @ 2026-09-30 5:10 UTC (permalink / raw) To: Kohei Enju Cc: Yeoreum Yun, linux-arm-kernel, linux-kernel, Catalin Marinas, Will Deacon, Jason Gunthorpe, Suzuki Poulose, Steven Price, Sami Mujawar, thuth On Wed, Sep 30, 2026 at 11:39:36AM +0900, Kohei Enju wrote: > On 09/29 17:57, Yeoreum Yun wrote: > > From: Sami Mujawar <sami.mujawar@arm.com> > > > > Add macro definitions for the hash algorithm identifiers, as > > specified in the Realm Management Monitor (RMM) specification. > > > > Signed-off-by: Sami Mujawar <sami.mujawar@arm.com> > > --- > > include/linux/arm-smccc-rsi.h | 7 +++++++ > > 1 file changed, 7 insertions(+) > > > > diff --git a/include/linux/arm-smccc-rsi.h b/include/linux/arm-smccc-rsi.h > > index fddb77986f70..a83df2655808 100644 > > --- a/include/linux/arm-smccc-rsi.h > > +++ b/include/linux/arm-smccc-rsi.h > > @@ -144,6 +144,13 @@ struct realm_config { > > > > #endif /* __ASSEMBLER__ */ > > > > +/* > > + * The RSI definition of the Hash Algorithm (as specified by the Secure > > + * Hash Standard) returned in the realm_config data structure. > > + */ > > +#define RSI_HASH_SHA_256 0 > > +#define RSI_HASH_SHA_512 1 > > Is it intentional to omit RSI_HASH_SHA_384 here? I realize it might not > be implemented in RMM yet, but would it be worth adding the constant now > for future support? Acked. Thanks! [...] -- Sincerely, Yeoreum Yun ^ permalink raw reply [flat|nested] 17+ messages in thread
* [PATCH v2 3/3] virt: arm-cca-guest: Add support for measurement registers 2026-09-29 16:57 [PATCH v2 0/3] arm64/virt: Add Arm CCA measurement register support Yeoreum Yun 2026-09-29 16:57 ` [PATCH v2 1/3] arm64: rsi: Add helpers for Arm CCA measurement register operations Yeoreum Yun 2026-09-29 16:57 ` [PATCH v2 2/3] arm64: rsi: Add realm hash algorithm defines Yeoreum Yun @ 2026-09-29 16:57 ` Yeoreum Yun 2026-09-30 3:24 ` Kohei Enju 2026-09-29 19:20 ` [PATCH v2 0/3] arm64/virt: Add Arm CCA measurement register support Jason Gunthorpe 3 siblings, 1 reply; 17+ messages in thread From: Yeoreum Yun @ 2026-09-29 16:57 UTC (permalink / raw) To: linux-arm-kernel, linux-kernel Cc: Catalin Marinas, Will Deacon, Jason Gunthorpe, Suzuki Poulose, Steven Price, Sami Mujawar, thuth From: Sami Mujawar <sami.mujawar@arm.com> Add support for Arm CCA measurement registers (MRs), enabling attestation and runtime integrity tracking from guest Realms. This implementation registers a measurement configuration with the TSM framework and exposes measurement register values via sysfs using a misc device. The supported registers include the Realm Initial Measurement (RIM) and four Runtime Extensible Measurement Registers (REM0–REM3), each using SHA-256 or SHA-512 depending on Realm configuration. The measurement registers are located under the following sysfs node: /sys/devices/virtual/misc/arm_cca_guest/measurements/ -rw-r--r-- 1 0 0 64 Jul 21 11:46 rem0:sha512 -rw-r--r-- 1 0 0 64 Jul 21 11:46 rem1:sha512 -rw-r--r-- 1 0 0 64 Jul 21 11:46 rem2:sha512 -rw-r--r-- 1 0 0 64 Jul 21 11:46 rem3:sha512 -r--r--r-- 1 0 0 64 Jul 21 11:46 rim:sha512 As seen above the attributes for the REMs are 'rw' indicating they can be read or extended. While the attributes for RIM is 'r' indicating that it can only be read and not extended. The sysfs node suffix for the measurement register (i.e. ':sha512') indicates the hash algorithm used is sha512. This also reflects that the Realm was launched with SHA512 as the measurement algorithm. Signed-off-by: Sami Mujawar <sami.mujawar@arm.com> --- .../sysfs-devices-virtual-misc-arm_cca_guest | 38 +++ drivers/virt/coco/arm-cca-guest/Kconfig | 1 + drivers/virt/coco/arm-cca-guest/main.c | 282 ++++++++++++++++++++- 3 files changed, 319 insertions(+), 2 deletions(-) diff --git a/Documentation/ABI/testing/sysfs-devices-virtual-misc-arm_cca_guest b/Documentation/ABI/testing/sysfs-devices-virtual-misc-arm_cca_guest new file mode 100644 index 000000000000..878dc54e48f8 --- /dev/null +++ b/Documentation/ABI/testing/sysfs-devices-virtual-misc-arm_cca_guest @@ -0,0 +1,38 @@ +What: /sys/devices/virtual/misc/arm_cca_guest/measurements/MRNAME[:HASH] +Date: July, 2025 +KernelVersion: v6.16 +Contact: linux-coco@lists.linux.dev +Description: + Value of a Arm CCA Realm measurement register (MR). The optional + suffix :HASH is to represent the hash algorithms associated with + the MRs. See below for a complete list of Arm CCA Realm MRs exposed + via sysfs. Refer to the Arm Realm Management Monitor (RMM) + Specification for more information on the Realm Measurement registers. + + The Arm Realm Management Monitor Specification can be found at: + https://developer.arm.com/documentation/den0137/latest/ + + See also: + https://docs.kernel.org/driver-api/coco/measurement-registers.html + +What: /sys/devices/virtual/misc/arm_cca_guest/measurements/rim:[sha256|sha512] +Date: July, 2025 +KernelVersion: v6.16 +Contact: linux-coco@lists.linux.dev +Description: + (RO) RIM - [32|64]-byte immutable storage typically used to represent + the Realm Initial Measurement (RIM) which is the measurement of + the configuration and contents of a Realm at the time of activation. + +What: /sys/devices/virtual/misc/arm_cca_guest/measurements/rem[0123]:[sha256|sha512] +Date: July, 2025 +KernelVersion: v6.16 +Contact: linux-coco@lists.linux.dev +Description: + (RW) REM[0123] - 4 Run-Time extendable Measurement Registers that + represent the Realm Extensible Measurement (REM) registers which + can be extended during the lifetime of a Realm. + Read from any of these returns the current value of the corresponding + REM. Write extends the written buffer to the REM. All writes must start + at offset 0 and be maximum 64 bytes in size. Attempting to write more + than 64 bytes will result in EINVAL returned by the write() syscall. diff --git a/drivers/virt/coco/arm-cca-guest/Kconfig b/drivers/virt/coco/arm-cca-guest/Kconfig index 0d4ce72e2d86..3693d3bc90c6 100644 --- a/drivers/virt/coco/arm-cca-guest/Kconfig +++ b/drivers/virt/coco/arm-cca-guest/Kconfig @@ -3,6 +3,7 @@ config ARM_CCA_GUEST depends on ARM_RMM_RSI depends on HAVE_ARM_SMCCC_DISCOVERY select TSM_REPORTS + select TSM_MEASUREMENTS help The driver provides userspace interface to request and attestation report from the Realm Management Monitor(RMM). diff --git a/drivers/virt/coco/arm-cca-guest/main.c b/drivers/virt/coco/arm-cca-guest/main.c index f97f593da6e3..9bbad43c4669 100644 --- a/drivers/virt/coco/arm-cca-guest/main.c +++ b/drivers/virt/coco/arm-cca-guest/main.c @@ -1,6 +1,6 @@ // SPDX-License-Identifier: GPL-2.0-only /* - * Copyright (C) 2023 ARM Ltd. + * Copyright (C) 2023 - 2025 ARM Ltd. */ #include <linux/arm-rsi-cmds.h> @@ -9,11 +9,280 @@ #include <linux/cc_platform.h> #include <linux/kernel.h> #include <linux/device-id/platform.h> +#include <linux/miscdevice.h> #include <linux/module.h> #include <linux/smp.h> #include <linux/tsm.h> +#include <linux/tsm-mr.h> #include <linux/types.h> +#include <crypto/hash.h> + +/* MR buffer */ +static u8 *arm_cca_mr_buf; + +/** + * arm_cca_mrs - ARM CCA measurement register set. + * + * Defines a static array of measurement registers used by the ARM + * Confidential Compute Architecture (CCA). These registers are used + * for attestation and runtime integrity tracking. + * + * Register types: + * - rim: Realm initial measurement register (RIM) + * - rem0–rem3: Runtime extensible measurement registers (REMs) + */ +static struct tsm_measurement_register arm_cca_mrs[] = { + { TSM_MR_(rim, SHA256) | TSM_MR_F_READABLE }, + { TSM_MR_(rem0, SHA256) | TSM_MR_F_RTMR }, + { TSM_MR_(rem1, SHA256) | TSM_MR_F_RTMR }, + { TSM_MR_(rem2, SHA256) | TSM_MR_F_RTMR }, + { TSM_MR_(rem3, SHA256) | TSM_MR_F_RTMR } +}; + +/** + * arm_cca_mr_refresh - Refresh measurement registers for ARM CCA. + * + * @tm: Pointer to a struct tsm_measurements containing measurement registers. + * + * Iterates through all measurement registers in @tm and refreshes those + * marked with TSM_MR_F_LIVE or TSM_MR_F_READABLE by invoking + * rsi_measurement_read() for each. + * + * Return: 0 on success, or -EINVAL if @tm is NULL or a read operation fails. + */ +static int arm_cca_mr_refresh(const struct tsm_measurements *tm) +{ + int retval; + int index = 0; + const struct tsm_measurement_register *mr; + + if (!tm) + return -EINVAL; + + while (index < tm->nr_mrs) { + mr = &tm->mrs[index]; + + /* Skip if the MR is not Live or Readable. */ + if ((mr->mr_flags & (TSM_MR_F_LIVE | TSM_MR_F_READABLE)) != 0) { + retval = rsi_measurement_read(index, + mr->mr_value, + mr->mr_size); + if (retval != 0) + return -EINVAL; + } + + index++; + } + + return 0; +} + +/** + * arm_cca_mr_extend - Extend a measurement register with new data. + * + * @tm: Pointer to the tsm_measurements structure containing measurement + * registers. + * @mr: Pointer to the specific measurement register to extend. + * @data: Pointer to the data to be used for extension. + * + * This function extends a measurement register with new input data. + * + * Return: 0 on success, or a negative error code (e.g., -EINVAL for invalid + * arguments). + */ +static int arm_cca_mr_extend(const struct tsm_measurements *tm, + const struct tsm_measurement_register *mr, + const u8 *data) +{ + if (!tm || !mr || !data) + return -EINVAL; + + return rsi_measurement_extend((mr - tm->mrs), data, mr->mr_size); +} + +/** + * arm_cca_measurements - ARM CCA measurement configuration instance. + * + * This defines the measurement set and behavior for the ARM + * Confidential Compute Architecture, enabling measurements + * for attestation and runtime validation. + */ +static struct tsm_measurements arm_cca_measurements = { + .mrs = arm_cca_mrs, + .nr_mrs = ARRAY_SIZE(arm_cca_mrs), + .refresh = arm_cca_mr_refresh, + .write = arm_cca_mr_extend, +}; + +/** + * arm_cca_attr_groups - Attribute groups for the arm_cca_misc_dev miscellaneous + * device. + * + */ +static const struct attribute_group *arm_cca_attr_groups[] = { + NULL, /* measurements */ + NULL +}; + +/** + * arm_cca_misc_dev - Miscellaneous device for ARM CCA functionality. + * + */ +static struct miscdevice arm_cca_misc_dev = { + .name = KBUILD_MODNAME, + .minor = MISC_DYNAMIC_MINOR, + .groups = arm_cca_attr_groups, +}; + +/** + * arm_cca_get_hash_algorithm - Get the hash algorithm and digest size for + * a Realm. + * + * @hash_algo: Pointer to an int to receive the internal hash algorithm ID + * (e.g., HASH_ALGO_SHA256 or HASH_ALGO_SHA512). + * @digest_size: Pointer to an int to receive the digest size in bytes + * (e.g., SHA256_DIGEST_SIZE or SHA512_DIGEST_SIZE). + * + * This function retrieves the hash algorithm used in a Realm's configuration + * by invoking the `rsi_get_realm_config()` interface. + * + * Return: + * * %0 - Success. The hash algorithm and digest size are returned. + * * %-ENOMEM - Memory allocation failed. + * * %-EINVAL - Configuration fetch failed or algorithm is unsupported. + * + */ +static int arm_cca_get_hash_algorithm(int *hash_algo, int *digest_size) +{ + int ret = 0; + unsigned long result; + struct realm_config *cfg = NULL; + + cfg = alloc_pages_exact(sizeof(*cfg), GFP_KERNEL); + if (!cfg) + return -ENOMEM; + + result = rsi_get_realm_config(cfg); + if (result != RSI_SUCCESS) { + ret = -EINVAL; + goto exit_free_realm_config; + } + + switch (cfg->hash_algo) { + case RSI_HASH_SHA_512: + *hash_algo = HASH_ALGO_SHA512; + *digest_size = SHA512_DIGEST_SIZE; + break; + case RSI_HASH_SHA_256: + *hash_algo = HASH_ALGO_SHA256; + *digest_size = SHA256_DIGEST_SIZE; + break; + default: + /* Unknown/unsupported algorithm. */ + ret = -EINVAL; + break; + } + +exit_free_realm_config: + free_pages_exact(cfg, RSI_GRANULE_SIZE); + return ret; +} + +/** + * arm_cca_mr_init - Initialize ARM CCA measurement register infrastructure. + * + * This function sets up the internal data structures for handling ARM CCA + * measurement registers (MRs) and creates a sysfs attribute group. It also + * registers a miscelaneous device for exposing the Arm CCA measurement + * registers to userspace. + * + * Return: + * * %0 - On success. + * * %-ENOMEM - if memory allocation fails. + * * %-EINVAL - On hash algorithm retrieval or attribute group creation + * failure. + */ +static int arm_cca_mr_init(void) +{ + const struct attribute_group *g; + int ret; + int hash_algo; + int digest_size; + int digest_buf_size; + + /* Retrieve the hash algorithm and digest size. */ + ret = arm_cca_get_hash_algorithm(&hash_algo, &digest_size); + if (ret) + return ret; + + /* + * Allocate a single contiguous buffer to hold the digest values + * for all MRs. + */ + digest_buf_size = ARRAY_SIZE(arm_cca_mrs) * digest_size; + u8 *digest_buf __free(kfree) = kzalloc(digest_buf_size, GFP_KERNEL); + if (!digest_buf) + return -ENOMEM; + + arm_cca_mr_buf = digest_buf; + + /* Initialise the mr_value storage and the mr_size. */ + for (size_t i = 0; i < ARRAY_SIZE(arm_cca_mrs); ++i) { + arm_cca_mrs[i].mr_value = digest_buf + (digest_size * i); + arm_cca_mrs[i].mr_size = digest_size; + arm_cca_mrs[i].mr_hash = hash_algo; + } + + /* Read the measurement registers. */ + ret = arm_cca_mr_refresh(&arm_cca_measurements); + if (ret) + return ret; + + /* + * Create a sysfs attribute group to expose the measurements + * to userspace. + */ + g = tsm_mr_create_attribute_group(&arm_cca_measurements); + if (IS_ERR_OR_NULL(g)) + return PTR_ERR(g); + + /* Initialise the attribute group before registering the misc device. */ + arm_cca_attr_groups[0] = g; + + /* + * Register a miscelaneous device for exposing + * the Arm CCA measurement registers to userspace. + */ + ret = misc_register(&arm_cca_misc_dev); + if (ret < 0) { + tsm_mr_free_attribute_group(g); + return ret; + } + + arm_cca_mr_buf = no_free_ptr(digest_buf); + + return 0; +} + +/** + * arm_cca_mr_cleanup - Unregister sysfs attribute group and free the + * measurement digest buffer region. + * + * @mr_grp: Pointer to the sysfs attribute group. + * + * This function performs cleanup for the Arm CCA memory registers (MR). + * + * The function should be called during the teardown or cleanup phase + * to ensure proper resource deallocation. + */ +static void arm_cca_mr_cleanup(const struct attribute_group *mr_grp) +{ + misc_deregister(&arm_cca_misc_dev); + tsm_mr_free_attribute_group(mr_grp); + kfree(arm_cca_mr_buf); +} + /** * struct arm_cca_token_info - a descriptor for the token buffer. * @granule: PA of the granule to which the token will be written @@ -169,10 +438,18 @@ static int cca_tsm_probe(struct arm_smccc_device *sdev) if (!is_realm_world()) return -ENODEV; + ret = arm_cca_mr_init(); + if (ret < 0) { + pr_err("Error %d initialising MRs\n", ret); + return ret; + } + ret = tsm_report_register(&arm_cca_tsm_report_ops, NULL); - if (ret < 0) + if (ret < 0) { + arm_cca_mr_cleanup(arm_cca_attr_groups[0]); return dev_err_probe(&sdev->dev, ret, "Error registering with TSM\n"); + } return 0; } @@ -180,6 +457,7 @@ static int cca_tsm_probe(struct arm_smccc_device *sdev) static void cca_tsm_remove(struct arm_smccc_device *sdev) { tsm_report_unregister(&arm_cca_tsm_report_ops); + arm_cca_mr_cleanup(arm_cca_attr_groups[0]); } static const struct arm_smccc_device_id cca_tsm_id_table[] = { -- 2.43.0 ^ permalink raw reply [flat|nested] 17+ messages in thread
* Re: [PATCH v2 3/3] virt: arm-cca-guest: Add support for measurement registers 2026-09-29 16:57 ` [PATCH v2 3/3] virt: arm-cca-guest: Add support for measurement registers Yeoreum Yun @ 2026-09-30 3:24 ` Kohei Enju 2026-09-30 4:45 ` Kohei Enju 2026-09-30 5:09 ` Yeoreum Yun 0 siblings, 2 replies; 17+ messages in thread From: Kohei Enju @ 2026-09-30 3:24 UTC (permalink / raw) To: Yeoreum Yun Cc: linux-arm-kernel, linux-kernel, Catalin Marinas, Will Deacon, Jason Gunthorpe, Suzuki Poulose, Steven Price, Sami Mujawar, thuth Hi Yeoreum, Sami, On 09/29 17:57, Yeoreum Yun wrote: > From: Sami Mujawar <sami.mujawar@arm.com> > > Add support for Arm CCA measurement registers (MRs), enabling attestation > and runtime integrity tracking from guest Realms. > > This implementation registers a measurement configuration with the TSM > framework and exposes measurement register values via sysfs using a > misc device. The supported registers include the Realm Initial > Measurement (RIM) and four Runtime Extensible Measurement Registers > (REM0–REM3), each using SHA-256 or SHA-512 depending on Realm Is SHA-384 intentionally out of scope for this series? Although TF-RMM does not support it yet, the RMM specification defines RSI_HASH_SHA_384. A platform using a custom RMM implementation could therefore launch a Realm configured to use SHA-384. I think the Realm guest driver should support it rather than fail initialization. > configuration. > > The measurement registers are located under the following sysfs node: > /sys/devices/virtual/misc/arm_cca_guest/measurements/ > -rw-r--r-- 1 0 0 64 Jul 21 11:46 rem0:sha512 > -rw-r--r-- 1 0 0 64 Jul 21 11:46 rem1:sha512 > -rw-r--r-- 1 0 0 64 Jul 21 11:46 rem2:sha512 > -rw-r--r-- 1 0 0 64 Jul 21 11:46 rem3:sha512 > -r--r--r-- 1 0 0 64 Jul 21 11:46 rim:sha512 > > As seen above the attributes for the REMs are 'rw' indicating they can > be read or extended. While the attributes for RIM is 'r' indicating > that it can only be read and not extended. > > The sysfs node suffix for the measurement register (i.e. ':sha512') > indicates the hash algorithm used is sha512. This also reflects > that the Realm was launched with SHA512 as the measurement algorithm. > > Signed-off-by: Sami Mujawar <sami.mujawar@arm.com> > --- > .../sysfs-devices-virtual-misc-arm_cca_guest | 38 +++ > drivers/virt/coco/arm-cca-guest/Kconfig | 1 + > drivers/virt/coco/arm-cca-guest/main.c | 282 ++++++++++++++++++++- > 3 files changed, 319 insertions(+), 2 deletions(-) > > diff --git a/Documentation/ABI/testing/sysfs-devices-virtual-misc-arm_cca_guest b/Documentation/ABI/testing/sysfs-devices-virtual-misc-arm_cca_guest > new file mode 100644 > index 000000000000..878dc54e48f8 > --- /dev/null > +++ b/Documentation/ABI/testing/sysfs-devices-virtual-misc-arm_cca_guest > @@ -0,0 +1,38 @@ > +What: /sys/devices/virtual/misc/arm_cca_guest/measurements/MRNAME[:HASH] > +Date: July, 2025 > +KernelVersion: v6.16 I think this Date and KernelVersion are stale and they should be updated. > +Contact: linux-coco@lists.linux.dev > +Description: > + Value of a Arm CCA Realm measurement register (MR). The optional If the :HASH suffix actually optional for Arm CCA? It appears that the driver always associates a hash algorithm with each register. > + suffix :HASH is to represent the hash algorithms associated with > + the MRs. See below for a complete list of Arm CCA Realm MRs exposed > + via sysfs. Refer to the Arm Realm Management Monitor (RMM) > + Specification for more information on the Realm Measurement registers. > + > + The Arm Realm Management Monitor Specification can be found at: > + https://developer.arm.com/documentation/den0137/latest/ > + > + See also: > + https://docs.kernel.org/driver-api/coco/measurement-registers.html > + > +What: /sys/devices/virtual/misc/arm_cca_guest/measurements/rim:[sha256|sha512] > +Date: July, 2025 > +KernelVersion: v6.16 > +Contact: linux-coco@lists.linux.dev > +Description: > + (RO) RIM - [32|64]-byte immutable storage typically used to represent > + the Realm Initial Measurement (RIM) which is the measurement of > + the configuration and contents of a Realm at the time of activation. > + > +What: /sys/devices/virtual/misc/arm_cca_guest/measurements/rem[0123]:[sha256|sha512] > +Date: July, 2025 > +KernelVersion: v6.16 > +Contact: linux-coco@lists.linux.dev > +Description: > + (RW) REM[0123] - 4 Run-Time extendable Measurement Registers that > + represent the Realm Extensible Measurement (REM) registers which > + can be extended during the lifetime of a Realm. > + Read from any of these returns the current value of the corresponding > + REM. Write extends the written buffer to the REM. All writes must start > + at offset 0 and be maximum 64 bytes in size. Attempting to write more > + than 64 bytes will result in EINVAL returned by the write() syscall. > diff --git a/drivers/virt/coco/arm-cca-guest/Kconfig b/drivers/virt/coco/arm-cca-guest/Kconfig > index 0d4ce72e2d86..3693d3bc90c6 100644 > --- a/drivers/virt/coco/arm-cca-guest/Kconfig > +++ b/drivers/virt/coco/arm-cca-guest/Kconfig > @@ -3,6 +3,7 @@ config ARM_CCA_GUEST > depends on ARM_RMM_RSI > depends on HAVE_ARM_SMCCC_DISCOVERY > select TSM_REPORTS > + select TSM_MEASUREMENTS > help > The driver provides userspace interface to request and > attestation report from the Realm Management Monitor(RMM). > diff --git a/drivers/virt/coco/arm-cca-guest/main.c b/drivers/virt/coco/arm-cca-guest/main.c > index f97f593da6e3..9bbad43c4669 100644 > --- a/drivers/virt/coco/arm-cca-guest/main.c > +++ b/drivers/virt/coco/arm-cca-guest/main.c > @@ -1,6 +1,6 @@ > // SPDX-License-Identifier: GPL-2.0-only > /* > - * Copyright (C) 2023 ARM Ltd. > + * Copyright (C) 2023 - 2025 ARM Ltd. > */ > > #include <linux/arm-rsi-cmds.h> > @@ -9,11 +9,280 @@ > #include <linux/cc_platform.h> > #include <linux/kernel.h> > #include <linux/device-id/platform.h> > +#include <linux/miscdevice.h> > #include <linux/module.h> > #include <linux/smp.h> > #include <linux/tsm.h> > +#include <linux/tsm-mr.h> > #include <linux/types.h> > > +#include <crypto/hash.h> > + > +/* MR buffer */ > +static u8 *arm_cca_mr_buf; > + > +/** > + * arm_cca_mrs - ARM CCA measurement register set. > + * > + * Defines a static array of measurement registers used by the ARM > + * Confidential Compute Architecture (CCA). These registers are used > + * for attestation and runtime integrity tracking. > + * > + * Register types: > + * - rim: Realm initial measurement register (RIM) > + * - rem0–rem3: Runtime extensible measurement registers (REMs) > + */ > +static struct tsm_measurement_register arm_cca_mrs[] = { > + { TSM_MR_(rim, SHA256) | TSM_MR_F_READABLE }, > + { TSM_MR_(rem0, SHA256) | TSM_MR_F_RTMR }, > + { TSM_MR_(rem1, SHA256) | TSM_MR_F_RTMR }, > + { TSM_MR_(rem2, SHA256) | TSM_MR_F_RTMR }, > + { TSM_MR_(rem3, SHA256) | TSM_MR_F_RTMR } > +}; > + > +/** > + * arm_cca_mr_refresh - Refresh measurement registers for ARM CCA. > + * > + * @tm: Pointer to a struct tsm_measurements containing measurement registers. > + * > + * Iterates through all measurement registers in @tm and refreshes those > + * marked with TSM_MR_F_LIVE or TSM_MR_F_READABLE by invoking > + * rsi_measurement_read() for each. > + * > + * Return: 0 on success, or -EINVAL if @tm is NULL or a read operation fails. > + */ > +static int arm_cca_mr_refresh(const struct tsm_measurements *tm) > +{ > + int retval; > + int index = 0; > + const struct tsm_measurement_register *mr; > + > + if (!tm) > + return -EINVAL; > + > + while (index < tm->nr_mrs) { > + mr = &tm->mrs[index]; > + > + /* Skip if the MR is not Live or Readable. */ > + if ((mr->mr_flags & (TSM_MR_F_LIVE | TSM_MR_F_READABLE)) != 0) { > + retval = rsi_measurement_read(index, > + mr->mr_value, > + mr->mr_size); > + if (retval != 0) > + return -EINVAL; > + } > + > + index++; > + } > + > + return 0; > +} > + > +/** > + * arm_cca_mr_extend - Extend a measurement register with new data. > + * > + * @tm: Pointer to the tsm_measurements structure containing measurement > + * registers. > + * @mr: Pointer to the specific measurement register to extend. > + * @data: Pointer to the data to be used for extension. > + * > + * This function extends a measurement register with new input data. > + * > + * Return: 0 on success, or a negative error code (e.g., -EINVAL for invalid > + * arguments). > + */ > +static int arm_cca_mr_extend(const struct tsm_measurements *tm, > + const struct tsm_measurement_register *mr, > + const u8 *data) > +{ > + if (!tm || !mr || !data) > + return -EINVAL; > + > + return rsi_measurement_extend((mr - tm->mrs), data, mr->mr_size); > +} > + > +/** > + * arm_cca_measurements - ARM CCA measurement configuration instance. > + * > + * This defines the measurement set and behavior for the ARM > + * Confidential Compute Architecture, enabling measurements > + * for attestation and runtime validation. > + */ > +static struct tsm_measurements arm_cca_measurements = { > + .mrs = arm_cca_mrs, > + .nr_mrs = ARRAY_SIZE(arm_cca_mrs), > + .refresh = arm_cca_mr_refresh, > + .write = arm_cca_mr_extend, From the RMM specification and the commit message, I understand that a REM can be extended with a measurement value of up to 64 bytes, regardless of the selected hash algorithm (for example, SHA-256 or SHA-512). However, when SHA-256 is selected, this interface does not allow a REM to be extended with a 64-byte value. The write partially succeeds: the REM is extended with the first 32 bytes, and then the write of the remaining 32 bytes fails with -EFBIG. As far as I can tell, the write is truncated to the sysfs binary attribute size, which is set to the SHA-256 digest size (32 bytes). The subsequent write at offset 32 is then rejected by sysfs_kf_bin_write() with -EFBIG. I do not see a straightforward fix because the TSM measurement register interface currently uses mr_size both as the readable digest size and as the required write size. [Realm VM] ~ # export REM3=/sys/devices/virtual/misc/arm_cca_guest/measurements/rem3:sha256 ~ # dd if=/dev/urandom bs=64 count=1 of=$REM3 dd: error writing '/sys/devices/virtual/misc/arm_cca_guest/measurements/rem3:sha256': File too large 1+0 records in 0+0 records out [RMM] SMC_RSI_MEASUREMENT_EXTEND 4 20 3cfcaa635bca042d c148121346b6e1b5 7342800b438d20d7 3dc7a25048cbbad8 0 0 0 0 > RSI_SUCCESS Do you have any thoughts on how the TSM interface should represent the maximum extend input size separately from the digest size? > +}; > + > +/** > + * arm_cca_attr_groups - Attribute groups for the arm_cca_misc_dev miscellaneous > + * device. > + * > + */ > +static const struct attribute_group *arm_cca_attr_groups[] = { > + NULL, /* measurements */ > + NULL > +}; > + > +/** > + * arm_cca_misc_dev - Miscellaneous device for ARM CCA functionality. > + * > + */ > +static struct miscdevice arm_cca_misc_dev = { > + .name = KBUILD_MODNAME, > + .minor = MISC_DYNAMIC_MINOR, > + .groups = arm_cca_attr_groups, > +}; > + > +/** > + * arm_cca_get_hash_algorithm - Get the hash algorithm and digest size for > + * a Realm. > + * > + * @hash_algo: Pointer to an int to receive the internal hash algorithm ID > + * (e.g., HASH_ALGO_SHA256 or HASH_ALGO_SHA512). > + * @digest_size: Pointer to an int to receive the digest size in bytes > + * (e.g., SHA256_DIGEST_SIZE or SHA512_DIGEST_SIZE). > + * > + * This function retrieves the hash algorithm used in a Realm's configuration > + * by invoking the `rsi_get_realm_config()` interface. > + * > + * Return: > + * * %0 - Success. The hash algorithm and digest size are returned. > + * * %-ENOMEM - Memory allocation failed. > + * * %-EINVAL - Configuration fetch failed or algorithm is unsupported. > + * > + */ > +static int arm_cca_get_hash_algorithm(int *hash_algo, int *digest_size) > +{ > + int ret = 0; > + unsigned long result; > + struct realm_config *cfg = NULL; > + > + cfg = alloc_pages_exact(sizeof(*cfg), GFP_KERNEL); > + if (!cfg) > + return -ENOMEM; > + > + result = rsi_get_realm_config(cfg); > + if (result != RSI_SUCCESS) { > + ret = -EINVAL; > + goto exit_free_realm_config; > + } > + > + switch (cfg->hash_algo) { > + case RSI_HASH_SHA_512: > + *hash_algo = HASH_ALGO_SHA512; > + *digest_size = SHA512_DIGEST_SIZE; > + break; > + case RSI_HASH_SHA_256: > + *hash_algo = HASH_ALGO_SHA256; > + *digest_size = SHA256_DIGEST_SIZE; > + break; > + default: > + /* Unknown/unsupported algorithm. */ > + ret = -EINVAL; Would it make sense to add an error message here? For example: pr_err("Unknown/unsupported Realm hash algorithm: %u\n", cfg->hash_algo); For context, I tested your v1 series in the past and found that this function sometimes failed due to wrong definition of realm_config::hash_algo [0]. Therefore, I think a diagnostic message including the returned value would be useful. [0] https://lore.kernel.org/all/20260929-cca-b4-rsi-fix-hash_algo-type-rebase-v1-1-6932cf0aa605@fujitsu.com/ Thanks, Kohei ^ permalink raw reply [flat|nested] 17+ messages in thread
* Re: [PATCH v2 3/3] virt: arm-cca-guest: Add support for measurement registers 2026-09-30 3:24 ` Kohei Enju @ 2026-09-30 4:45 ` Kohei Enju 2026-09-30 5:09 ` Yeoreum Yun 1 sibling, 0 replies; 17+ messages in thread From: Kohei Enju @ 2026-09-30 4:45 UTC (permalink / raw) To: Yeoreum Yun, Suzuki Poulose Cc: linux-arm-kernel, linux-kernel, Catalin Marinas, Will Deacon, Jason Gunthorpe, Suzuki Poulose, Steven Price, Sami Mujawar, thuth Hi Yeoreum, Suzuki On 09/30 12:24, Kohei Enju wrote: > Hi Yeoreum, Sami, > > On 09/29 17:57, Yeoreum Yun wrote: > > From: Sami Mujawar <sami.mujawar@arm.com> > > > > Add support for Arm CCA measurement registers (MRs), enabling attestation > > and runtime integrity tracking from guest Realms. > > > > This implementation registers a measurement configuration with the TSM > > framework and exposes measurement register values via sysfs using a > > misc device. The supported registers include the Realm Initial > > Measurement (RIM) and four Runtime Extensible Measurement Registers > > (REM0–REM3), each using SHA-256 or SHA-512 depending on Realm > > Is SHA-384 intentionally out of scope for this series? > > Although TF-RMM does not support it yet, the RMM specification defines > RSI_HASH_SHA_384. A platform using a custom RMM implementation could > therefore launch a Realm configured to use SHA-384. I think the Realm > guest driver should support it rather than fail initialization. Separately from this driver implementation, I noticed that "B5.4.9.3 Success conditions" in the RMM specification 2.0-bet3 lacks a success condition for sha_384. Could you please report this to the specification team, or let me know the appropriate contact for reporting specification issues? Thanks, Kohei ^ permalink raw reply [flat|nested] 17+ messages in thread
* Re: [PATCH v2 3/3] virt: arm-cca-guest: Add support for measurement registers 2026-09-30 3:24 ` Kohei Enju 2026-09-30 4:45 ` Kohei Enju @ 2026-09-30 5:09 ` Yeoreum Yun 2026-09-30 5:59 ` Kohei Enju 1 sibling, 1 reply; 17+ messages in thread From: Yeoreum Yun @ 2026-09-30 5:09 UTC (permalink / raw) To: Kohei Enju Cc: Yeoreum Yun, linux-arm-kernel, linux-kernel, Catalin Marinas, Will Deacon, Jason Gunthorpe, Suzuki Poulose, Steven Price, Sami Mujawar, thuth On Wed, Sep 30, 2026 at 12:24:08PM +0900, Kohei Enju wrote: > Hi Yeoreum, Sami, > > On 09/29 17:57, Yeoreum Yun wrote: > > From: Sami Mujawar <sami.mujawar@arm.com> > > > > Add support for Arm CCA measurement registers (MRs), enabling attestation > > and runtime integrity tracking from guest Realms. > > > > This implementation registers a measurement configuration with the TSM > > framework and exposes measurement register values via sysfs using a > > misc device. The supported registers include the Realm Initial > > Measurement (RIM) and four Runtime Extensible Measurement Registers > > (REM0–REM3), each using SHA-256 or SHA-512 depending on Realm > > Is SHA-384 intentionally out of scope for this series? > > Although TF-RMM does not support it yet, the RMM specification defines > RSI_HASH_SHA_384. A platform using a custom RMM implementation could > therefore launch a Realm configured to use SHA-384. I think the Realm > guest driver should support it rather than fail initialization. Fair enough. Let's change in next-spin. > > > configuration. > > > > The measurement registers are located under the following sysfs node: > > /sys/devices/virtual/misc/arm_cca_guest/measurements/ > > -rw-r--r-- 1 0 0 64 Jul 21 11:46 rem0:sha512 > > -rw-r--r-- 1 0 0 64 Jul 21 11:46 rem1:sha512 > > -rw-r--r-- 1 0 0 64 Jul 21 11:46 rem2:sha512 > > -rw-r--r-- 1 0 0 64 Jul 21 11:46 rem3:sha512 > > -r--r--r-- 1 0 0 64 Jul 21 11:46 rim:sha512 > > > > As seen above the attributes for the REMs are 'rw' indicating they can > > be read or extended. While the attributes for RIM is 'r' indicating > > that it can only be read and not extended. > > > > The sysfs node suffix for the measurement register (i.e. ':sha512') > > indicates the hash algorithm used is sha512. This also reflects > > that the Realm was launched with SHA512 as the measurement algorithm. > > > > Signed-off-by: Sami Mujawar <sami.mujawar@arm.com> > > --- > > .../sysfs-devices-virtual-misc-arm_cca_guest | 38 +++ > > drivers/virt/coco/arm-cca-guest/Kconfig | 1 + > > drivers/virt/coco/arm-cca-guest/main.c | 282 ++++++++++++++++++++- > > 3 files changed, 319 insertions(+), 2 deletions(-) > > > > diff --git a/Documentation/ABI/testing/sysfs-devices-virtual-misc-arm_cca_guest b/Documentation/ABI/testing/sysfs-devices-virtual-misc-arm_cca_guest > > new file mode 100644 > > index 000000000000..878dc54e48f8 > > --- /dev/null > > +++ b/Documentation/ABI/testing/sysfs-devices-virtual-misc-arm_cca_guest > > @@ -0,0 +1,38 @@ > > +What: /sys/devices/virtual/misc/arm_cca_guest/measurements/MRNAME[:HASH] > > +Date: July, 2025 > > +KernelVersion: v6.16 > > I think this Date and KernelVersion are stale and they should be > updated. Oh. I missed it. I'll update in next-spin. > > > +Contact: linux-coco@lists.linux.dev > > +Description: > > + Value of a Arm CCA Realm measurement register (MR). The optional > > If the :HASH suffix actually optional for Arm CCA? > It appears that the driver always associates a hash algorithm with each > register. > > > + suffix :HASH is to represent the hash algorithms associated with > > + the MRs. See below for a complete list of Arm CCA Realm MRs exposed > > + via sysfs. Refer to the Arm Realm Management Monitor (RMM) > > + Specification for more information on the Realm Measurement registers. > > + > > + The Arm Realm Management Monitor Specification can be found at: > > + https://developer.arm.com/documentation/den0137/latest/ > > + > > + See also: > > + https://docs.kernel.org/driver-api/coco/measurement-registers.html > > + > > +What: /sys/devices/virtual/misc/arm_cca_guest/measurements/rim:[sha256|sha512] > > +Date: July, 2025 > > +KernelVersion: v6.16 > > +Contact: linux-coco@lists.linux.dev > > +Description: > > + (RO) RIM - [32|64]-byte immutable storage typically used to represent > > + the Realm Initial Measurement (RIM) which is the measurement of > > + the configuration and contents of a Realm at the time of activation. > > + > > +What: /sys/devices/virtual/misc/arm_cca_guest/measurements/rem[0123]:[sha256|sha512] > > +Date: July, 2025 > > +KernelVersion: v6.16 > > +Contact: linux-coco@lists.linux.dev > > +Description: > > + (RW) REM[0123] - 4 Run-Time extendable Measurement Registers that > > + represent the Realm Extensible Measurement (REM) registers which > > + can be extended during the lifetime of a Realm. > > + Read from any of these returns the current value of the corresponding > > + REM. Write extends the written buffer to the REM. All writes must start > > + at offset 0 and be maximum 64 bytes in size. Attempting to write more > > + than 64 bytes will result in EINVAL returned by the write() syscall. > > diff --git a/drivers/virt/coco/arm-cca-guest/Kconfig b/drivers/virt/coco/arm-cca-guest/Kconfig > > index 0d4ce72e2d86..3693d3bc90c6 100644 > > --- a/drivers/virt/coco/arm-cca-guest/Kconfig > > +++ b/drivers/virt/coco/arm-cca-guest/Kconfig > > @@ -3,6 +3,7 @@ config ARM_CCA_GUEST > > depends on ARM_RMM_RSI > > depends on HAVE_ARM_SMCCC_DISCOVERY > > select TSM_REPORTS > > + select TSM_MEASUREMENTS > > help > > The driver provides userspace interface to request and > > attestation report from the Realm Management Monitor(RMM). > > diff --git a/drivers/virt/coco/arm-cca-guest/main.c b/drivers/virt/coco/arm-cca-guest/main.c > > index f97f593da6e3..9bbad43c4669 100644 > > --- a/drivers/virt/coco/arm-cca-guest/main.c > > +++ b/drivers/virt/coco/arm-cca-guest/main.c > > @@ -1,6 +1,6 @@ > > // SPDX-License-Identifier: GPL-2.0-only > > /* > > - * Copyright (C) 2023 ARM Ltd. > > + * Copyright (C) 2023 - 2025 ARM Ltd. > > */ > > > > #include <linux/arm-rsi-cmds.h> > > @@ -9,11 +9,280 @@ > > #include <linux/cc_platform.h> > > #include <linux/kernel.h> > > #include <linux/device-id/platform.h> > > +#include <linux/miscdevice.h> > > #include <linux/module.h> > > #include <linux/smp.h> > > #include <linux/tsm.h> > > +#include <linux/tsm-mr.h> > > #include <linux/types.h> > > > > +#include <crypto/hash.h> > > + > > +/* MR buffer */ > > +static u8 *arm_cca_mr_buf; > > + > > +/** > > + * arm_cca_mrs - ARM CCA measurement register set. > > + * > > + * Defines a static array of measurement registers used by the ARM > > + * Confidential Compute Architecture (CCA). These registers are used > > + * for attestation and runtime integrity tracking. > > + * > > + * Register types: > > + * - rim: Realm initial measurement register (RIM) > > + * - rem0–rem3: Runtime extensible measurement registers (REMs) > > + */ > > +static struct tsm_measurement_register arm_cca_mrs[] = { > > + { TSM_MR_(rim, SHA256) | TSM_MR_F_READABLE }, > > + { TSM_MR_(rem0, SHA256) | TSM_MR_F_RTMR }, > > + { TSM_MR_(rem1, SHA256) | TSM_MR_F_RTMR }, > > + { TSM_MR_(rem2, SHA256) | TSM_MR_F_RTMR }, > > + { TSM_MR_(rem3, SHA256) | TSM_MR_F_RTMR } > > +}; > > + > > +/** > > + * arm_cca_mr_refresh - Refresh measurement registers for ARM CCA. > > + * > > + * @tm: Pointer to a struct tsm_measurements containing measurement registers. > > + * > > + * Iterates through all measurement registers in @tm and refreshes those > > + * marked with TSM_MR_F_LIVE or TSM_MR_F_READABLE by invoking > > + * rsi_measurement_read() for each. > > + * > > + * Return: 0 on success, or -EINVAL if @tm is NULL or a read operation fails. > > + */ > > +static int arm_cca_mr_refresh(const struct tsm_measurements *tm) > > +{ > > + int retval; > > + int index = 0; > > + const struct tsm_measurement_register *mr; > > + > > + if (!tm) > > + return -EINVAL; > > + > > + while (index < tm->nr_mrs) { > > + mr = &tm->mrs[index]; > > + > > + /* Skip if the MR is not Live or Readable. */ > > + if ((mr->mr_flags & (TSM_MR_F_LIVE | TSM_MR_F_READABLE)) != 0) { > > + retval = rsi_measurement_read(index, > > + mr->mr_value, > > + mr->mr_size); > > + if (retval != 0) > > + return -EINVAL; > > + } > > + > > + index++; > > + } > > + > > + return 0; > > +} > > + > > +/** > > + * arm_cca_mr_extend - Extend a measurement register with new data. > > + * > > + * @tm: Pointer to the tsm_measurements structure containing measurement > > + * registers. > > + * @mr: Pointer to the specific measurement register to extend. > > + * @data: Pointer to the data to be used for extension. > > + * > > + * This function extends a measurement register with new input data. > > + * > > + * Return: 0 on success, or a negative error code (e.g., -EINVAL for invalid > > + * arguments). > > + */ > > +static int arm_cca_mr_extend(const struct tsm_measurements *tm, > > + const struct tsm_measurement_register *mr, > > + const u8 *data) > > +{ > > + if (!tm || !mr || !data) > > + return -EINVAL; > > + > > + return rsi_measurement_extend((mr - tm->mrs), data, mr->mr_size); > > +} > > + > > +/** > > + * arm_cca_measurements - ARM CCA measurement configuration instance. > > + * > > + * This defines the measurement set and behavior for the ARM > > + * Confidential Compute Architecture, enabling measurements > > + * for attestation and runtime validation. > > + */ > > +static struct tsm_measurements arm_cca_measurements = { > > + .mrs = arm_cca_mrs, > > + .nr_mrs = ARRAY_SIZE(arm_cca_mrs), > > + .refresh = arm_cca_mr_refresh, > > + .write = arm_cca_mr_extend, > > From the RMM specification and the commit message, I understand that a > REM can be extended with a measurement value of up to 64 bytes, > regardless of the selected hash algorithm (for example, SHA-256 or > SHA-512). > > However, when SHA-256 is selected, this interface does not allow a REM > to be extended with a 64-byte value. The write partially succeeds: the > REM is extended with the first 32 bytes, and then the write of the > remaining 32 bytes fails with -EFBIG. > > As far as I can tell, the write is truncated to the sysfs binary > attribute size, which is set to the SHA-256 digest size (32 bytes). The > subsequent write at offset 32 is then rejected by sysfs_kf_bin_write() > with -EFBIG. > > I do not see a straightforward fix because the TSM measurement register > interface currently uses mr_size both as the readable digest size and as > the required write size. > > [Realm VM] > ~ # export REM3=/sys/devices/virtual/misc/arm_cca_guest/measurements/rem3:sha256 > ~ # dd if=/dev/urandom bs=64 count=1 of=$REM3 > dd: error writing '/sys/devices/virtual/misc/arm_cca_guest/measurements/rem3:sha256': File too large > 1+0 records in > 0+0 records out > > [RMM] > SMC_RSI_MEASUREMENT_EXTEND 4 20 3cfcaa635bca042d c148121346b6e1b5 7342800b438d20d7 3dc7a25048cbbad8 0 0 0 0 > RSI_SUCCESS > > Do you have any thoughts on how the TSM interface should represent the > maximum extend input size separately from the digest size? I don't think we need to represent the maximum extend input size separately. The TSM measurement register interface is intended to expose PCR-like semantics, where the value being extended is a measurement digest whose size is determined by the selected hash algorithm. In other words, the extend operation is conceptually: new_digest = Hash(old_digest || measurement_digest) Therefore, for a SHA-256 measurement register, the extend value should be 32 bytes, and rejecting a value larger than 32 bytes with -EFBIG seems correct to me and intended. A 64-byte extend value would only be valid for a register using a 64-byte digest, such as SHA-512. Although the RMM interface may allow a measurement value of up to 64 bytes independently of the REM hash algorithm, I don't think that capability needs to be exposed through the generic TSM measurement register interface in point of viewt to preserve PCR-like semantics. > > > +}; > > + > > +/** > > + * arm_cca_attr_groups - Attribute groups for the arm_cca_misc_dev miscellaneous > > + * device. > > + * > > + */ > > +static const struct attribute_group *arm_cca_attr_groups[] = { > > + NULL, /* measurements */ > > + NULL > > +}; > > + > > +/** > > + * arm_cca_misc_dev - Miscellaneous device for ARM CCA functionality. > > + * > > + */ > > +static struct miscdevice arm_cca_misc_dev = { > > + .name = KBUILD_MODNAME, > > + .minor = MISC_DYNAMIC_MINOR, > > + .groups = arm_cca_attr_groups, > > +}; > > + > > +/** > > + * arm_cca_get_hash_algorithm - Get the hash algorithm and digest size for > > + * a Realm. > > + * > > + * @hash_algo: Pointer to an int to receive the internal hash algorithm ID > > + * (e.g., HASH_ALGO_SHA256 or HASH_ALGO_SHA512). > > + * @digest_size: Pointer to an int to receive the digest size in bytes > > + * (e.g., SHA256_DIGEST_SIZE or SHA512_DIGEST_SIZE). > > + * > > + * This function retrieves the hash algorithm used in a Realm's configuration > > + * by invoking the `rsi_get_realm_config()` interface. > > + * > > + * Return: > > + * * %0 - Success. The hash algorithm and digest size are returned. > > + * * %-ENOMEM - Memory allocation failed. > > + * * %-EINVAL - Configuration fetch failed or algorithm is unsupported. > > + * > > + */ > > +static int arm_cca_get_hash_algorithm(int *hash_algo, int *digest_size) > > +{ > > + int ret = 0; > > + unsigned long result; > > + struct realm_config *cfg = NULL; > > + > > + cfg = alloc_pages_exact(sizeof(*cfg), GFP_KERNEL); > > + if (!cfg) > > + return -ENOMEM; > > + > > + result = rsi_get_realm_config(cfg); > > + if (result != RSI_SUCCESS) { > > + ret = -EINVAL; > > + goto exit_free_realm_config; > > + } > > + > > + switch (cfg->hash_algo) { > > + case RSI_HASH_SHA_512: > > + *hash_algo = HASH_ALGO_SHA512; > > + *digest_size = SHA512_DIGEST_SIZE; > > + break; > > + case RSI_HASH_SHA_256: > > + *hash_algo = HASH_ALGO_SHA256; > > + *digest_size = SHA256_DIGEST_SIZE; > > + break; > > + default: > > + /* Unknown/unsupported algorithm. */ > > + ret = -EINVAL; > > Would it make sense to add an error message here? For example: > pr_err("Unknown/unsupported Realm hash algorithm: %u\n", cfg->hash_algo); > > For context, I tested your v1 series in the past and found that this function > sometimes failed due to wrong definition of realm_config::hash_algo [0]. > Therefore, I think a diagnostic message including the returned value > would be useful. > > [0] https://lore.kernel.org/all/20260929-cca-b4-rsi-fix-hash_algo-type-rebase-v1-1-6932cf0aa605@fujitsu.com/ Fair enough. I'll add the error log. Thanks! -- Sincerely, Yeoreum Yun ^ permalink raw reply [flat|nested] 17+ messages in thread
* Re: [PATCH v2 3/3] virt: arm-cca-guest: Add support for measurement registers 2026-09-30 5:09 ` Yeoreum Yun @ 2026-09-30 5:59 ` Kohei Enju 2026-09-30 6:40 ` Yeoreum Yun 0 siblings, 1 reply; 17+ messages in thread From: Kohei Enju @ 2026-09-30 5:59 UTC (permalink / raw) To: Yeoreum Yun Cc: linux-arm-kernel, linux-kernel, Catalin Marinas, Will Deacon, Jason Gunthorpe, Suzuki Poulose, Steven Price, Sami Mujawar, thuth On 09/30 06:09, Yeoreum Yun wrote: > On Wed, Sep 30, 2026 at 12:24:08PM +0900, Kohei Enju wrote: > > Hi Yeoreum, Sami, > > > > On 09/29 17:57, Yeoreum Yun wrote: > > > From: Sami Mujawar <sami.mujawar@arm.com> > > > > > > Add support for Arm CCA measurement registers (MRs), enabling attestation > > > and runtime integrity tracking from guest Realms. > > > > > > This implementation registers a measurement configuration with the TSM > > > framework and exposes measurement register values via sysfs using a > > > misc device. The supported registers include the Realm Initial > > > Measurement (RIM) and four Runtime Extensible Measurement Registers > > > (REM0–REM3), each using SHA-256 or SHA-512 depending on Realm > > > > Is SHA-384 intentionally out of scope for this series? > > > > Although TF-RMM does not support it yet, the RMM specification defines > > RSI_HASH_SHA_384. A platform using a custom RMM implementation could > > therefore launch a Realm configured to use SHA-384. I think the Realm > > guest driver should support it rather than fail initialization. > > Fair enough. Let's change in next-spin. > > > > > > configuration. > > > > > > The measurement registers are located under the following sysfs node: > > > /sys/devices/virtual/misc/arm_cca_guest/measurements/ > > > -rw-r--r-- 1 0 0 64 Jul 21 11:46 rem0:sha512 > > > -rw-r--r-- 1 0 0 64 Jul 21 11:46 rem1:sha512 > > > -rw-r--r-- 1 0 0 64 Jul 21 11:46 rem2:sha512 > > > -rw-r--r-- 1 0 0 64 Jul 21 11:46 rem3:sha512 > > > -r--r--r-- 1 0 0 64 Jul 21 11:46 rim:sha512 > > > > > > As seen above the attributes for the REMs are 'rw' indicating they can > > > be read or extended. While the attributes for RIM is 'r' indicating > > > that it can only be read and not extended. > > > > > > The sysfs node suffix for the measurement register (i.e. ':sha512') > > > indicates the hash algorithm used is sha512. This also reflects > > > that the Realm was launched with SHA512 as the measurement algorithm. > > > > > > Signed-off-by: Sami Mujawar <sami.mujawar@arm.com> > > > --- > > > .../sysfs-devices-virtual-misc-arm_cca_guest | 38 +++ > > > drivers/virt/coco/arm-cca-guest/Kconfig | 1 + > > > drivers/virt/coco/arm-cca-guest/main.c | 282 ++++++++++++++++++++- > > > 3 files changed, 319 insertions(+), 2 deletions(-) > > > > > > diff --git a/Documentation/ABI/testing/sysfs-devices-virtual-misc-arm_cca_guest b/Documentation/ABI/testing/sysfs-devices-virtual-misc-arm_cca_guest > > > new file mode 100644 > > > index 000000000000..878dc54e48f8 > > > --- /dev/null > > > +++ b/Documentation/ABI/testing/sysfs-devices-virtual-misc-arm_cca_guest > > > @@ -0,0 +1,38 @@ > > > +What: /sys/devices/virtual/misc/arm_cca_guest/measurements/MRNAME[:HASH] > > > +Date: July, 2025 > > > +KernelVersion: v6.16 > > > > I think this Date and KernelVersion are stale and they should be > > updated. > > Oh. I missed it. I'll update in next-spin. > > > > > > +Contact: linux-coco@lists.linux.dev > > > +Description: > > > + Value of a Arm CCA Realm measurement register (MR). The optional > > > > If the :HASH suffix actually optional for Arm CCA? > > It appears that the driver always associates a hash algorithm with each > > register. > > > > > + suffix :HASH is to represent the hash algorithms associated with > > > + the MRs. See below for a complete list of Arm CCA Realm MRs exposed > > > + via sysfs. Refer to the Arm Realm Management Monitor (RMM) > > > + Specification for more information on the Realm Measurement registers. > > > + > > > + The Arm Realm Management Monitor Specification can be found at: > > > + https://developer.arm.com/documentation/den0137/latest/ > > > + > > > + See also: > > > + https://docs.kernel.org/driver-api/coco/measurement-registers.html > > > + > > > +What: /sys/devices/virtual/misc/arm_cca_guest/measurements/rim:[sha256|sha512] > > > +Date: July, 2025 > > > +KernelVersion: v6.16 > > > +Contact: linux-coco@lists.linux.dev > > > +Description: > > > + (RO) RIM - [32|64]-byte immutable storage typically used to represent > > > + the Realm Initial Measurement (RIM) which is the measurement of > > > + the configuration and contents of a Realm at the time of activation. > > > + > > > +What: /sys/devices/virtual/misc/arm_cca_guest/measurements/rem[0123]:[sha256|sha512] > > > +Date: July, 2025 > > > +KernelVersion: v6.16 > > > +Contact: linux-coco@lists.linux.dev > > > +Description: > > > + (RW) REM[0123] - 4 Run-Time extendable Measurement Registers that > > > + represent the Realm Extensible Measurement (REM) registers which > > > + can be extended during the lifetime of a Realm. > > > + Read from any of these returns the current value of the corresponding > > > + REM. Write extends the written buffer to the REM. All writes must start > > > + at offset 0 and be maximum 64 bytes in size. Attempting to write more > > > + than 64 bytes will result in EINVAL returned by the write() syscall. > > > diff --git a/drivers/virt/coco/arm-cca-guest/Kconfig b/drivers/virt/coco/arm-cca-guest/Kconfig > > > index 0d4ce72e2d86..3693d3bc90c6 100644 > > > --- a/drivers/virt/coco/arm-cca-guest/Kconfig > > > +++ b/drivers/virt/coco/arm-cca-guest/Kconfig > > > @@ -3,6 +3,7 @@ config ARM_CCA_GUEST > > > depends on ARM_RMM_RSI > > > depends on HAVE_ARM_SMCCC_DISCOVERY > > > select TSM_REPORTS > > > + select TSM_MEASUREMENTS > > > help > > > The driver provides userspace interface to request and > > > attestation report from the Realm Management Monitor(RMM). > > > diff --git a/drivers/virt/coco/arm-cca-guest/main.c b/drivers/virt/coco/arm-cca-guest/main.c > > > index f97f593da6e3..9bbad43c4669 100644 > > > --- a/drivers/virt/coco/arm-cca-guest/main.c > > > +++ b/drivers/virt/coco/arm-cca-guest/main.c > > > @@ -1,6 +1,6 @@ > > > // SPDX-License-Identifier: GPL-2.0-only > > > /* > > > - * Copyright (C) 2023 ARM Ltd. > > > + * Copyright (C) 2023 - 2025 ARM Ltd. > > > */ > > > > > > #include <linux/arm-rsi-cmds.h> > > > @@ -9,11 +9,280 @@ > > > #include <linux/cc_platform.h> > > > #include <linux/kernel.h> > > > #include <linux/device-id/platform.h> > > > +#include <linux/miscdevice.h> > > > #include <linux/module.h> > > > #include <linux/smp.h> > > > #include <linux/tsm.h> > > > +#include <linux/tsm-mr.h> > > > #include <linux/types.h> > > > > > > +#include <crypto/hash.h> > > > + > > > +/* MR buffer */ > > > +static u8 *arm_cca_mr_buf; > > > + > > > +/** > > > + * arm_cca_mrs - ARM CCA measurement register set. > > > + * > > > + * Defines a static array of measurement registers used by the ARM > > > + * Confidential Compute Architecture (CCA). These registers are used > > > + * for attestation and runtime integrity tracking. > > > + * > > > + * Register types: > > > + * - rim: Realm initial measurement register (RIM) > > > + * - rem0–rem3: Runtime extensible measurement registers (REMs) > > > + */ > > > +static struct tsm_measurement_register arm_cca_mrs[] = { > > > + { TSM_MR_(rim, SHA256) | TSM_MR_F_READABLE }, > > > + { TSM_MR_(rem0, SHA256) | TSM_MR_F_RTMR }, > > > + { TSM_MR_(rem1, SHA256) | TSM_MR_F_RTMR }, > > > + { TSM_MR_(rem2, SHA256) | TSM_MR_F_RTMR }, > > > + { TSM_MR_(rem3, SHA256) | TSM_MR_F_RTMR } > > > +}; > > > + > > > +/** > > > + * arm_cca_mr_refresh - Refresh measurement registers for ARM CCA. > > > + * > > > + * @tm: Pointer to a struct tsm_measurements containing measurement registers. > > > + * > > > + * Iterates through all measurement registers in @tm and refreshes those > > > + * marked with TSM_MR_F_LIVE or TSM_MR_F_READABLE by invoking > > > + * rsi_measurement_read() for each. > > > + * > > > + * Return: 0 on success, or -EINVAL if @tm is NULL or a read operation fails. > > > + */ > > > +static int arm_cca_mr_refresh(const struct tsm_measurements *tm) > > > +{ > > > + int retval; > > > + int index = 0; > > > + const struct tsm_measurement_register *mr; > > > + > > > + if (!tm) > > > + return -EINVAL; > > > + > > > + while (index < tm->nr_mrs) { > > > + mr = &tm->mrs[index]; > > > + > > > + /* Skip if the MR is not Live or Readable. */ > > > + if ((mr->mr_flags & (TSM_MR_F_LIVE | TSM_MR_F_READABLE)) != 0) { > > > + retval = rsi_measurement_read(index, > > > + mr->mr_value, > > > + mr->mr_size); > > > + if (retval != 0) > > > + return -EINVAL; > > > + } > > > + > > > + index++; > > > + } > > > + > > > + return 0; > > > +} > > > + > > > +/** > > > + * arm_cca_mr_extend - Extend a measurement register with new data. > > > + * > > > + * @tm: Pointer to the tsm_measurements structure containing measurement > > > + * registers. > > > + * @mr: Pointer to the specific measurement register to extend. > > > + * @data: Pointer to the data to be used for extension. > > > + * > > > + * This function extends a measurement register with new input data. > > > + * > > > + * Return: 0 on success, or a negative error code (e.g., -EINVAL for invalid > > > + * arguments). > > > + */ > > > +static int arm_cca_mr_extend(const struct tsm_measurements *tm, > > > + const struct tsm_measurement_register *mr, > > > + const u8 *data) > > > +{ > > > + if (!tm || !mr || !data) > > > + return -EINVAL; > > > + > > > + return rsi_measurement_extend((mr - tm->mrs), data, mr->mr_size); > > > +} > > > + > > > +/** > > > + * arm_cca_measurements - ARM CCA measurement configuration instance. > > > + * > > > + * This defines the measurement set and behavior for the ARM > > > + * Confidential Compute Architecture, enabling measurements > > > + * for attestation and runtime validation. > > > + */ > > > +static struct tsm_measurements arm_cca_measurements = { > > > + .mrs = arm_cca_mrs, > > > + .nr_mrs = ARRAY_SIZE(arm_cca_mrs), > > > + .refresh = arm_cca_mr_refresh, > > > + .write = arm_cca_mr_extend, > > > > From the RMM specification and the commit message, I understand that a > > REM can be extended with a measurement value of up to 64 bytes, > > regardless of the selected hash algorithm (for example, SHA-256 or > > SHA-512). > > > > However, when SHA-256 is selected, this interface does not allow a REM > > to be extended with a 64-byte value. The write partially succeeds: the > > REM is extended with the first 32 bytes, and then the write of the > > remaining 32 bytes fails with -EFBIG. > > > > As far as I can tell, the write is truncated to the sysfs binary > > attribute size, which is set to the SHA-256 digest size (32 bytes). The > > subsequent write at offset 32 is then rejected by sysfs_kf_bin_write() > > with -EFBIG. > > > > I do not see a straightforward fix because the TSM measurement register > > interface currently uses mr_size both as the readable digest size and as > > the required write size. > > > > [Realm VM] > > ~ # export REM3=/sys/devices/virtual/misc/arm_cca_guest/measurements/rem3:sha256 > > ~ # dd if=/dev/urandom bs=64 count=1 of=$REM3 > > dd: error writing '/sys/devices/virtual/misc/arm_cca_guest/measurements/rem3:sha256': File too large > > 1+0 records in > > 0+0 records out > > > > [RMM] > > SMC_RSI_MEASUREMENT_EXTEND 4 20 3cfcaa635bca042d c148121346b6e1b5 7342800b438d20d7 3dc7a25048cbbad8 0 0 0 0 > RSI_SUCCESS > > > > Do you have any thoughts on how the TSM interface should represent the > > maximum extend input size separately from the digest size? > > I don't think we need to represent the maximum extend input size separately. > > The TSM measurement register interface is intended to expose PCR-like > semantics, where the value being extended is a measurement digest whose size > is determined by the selected hash algorithm. > > In other words, the extend operation is conceptually: > > new_digest = Hash(old_digest || measurement_digest) > > Therefore, for a SHA-256 measurement register, the extend value should be > 32 bytes, and rejecting a value larger than 32 bytes with -EFBIG seems > correct to me and intended. A 64-byte extend value would only be valid for > a register using a 64-byte digest, such as SHA-512. > > Although the RMM interface may allow a measurement value of up to 64 bytes > independently of the REM hash algorithm, I don't think that capability > needs to be exposed through the generic TSM measurement register interface > in point of viewt to preserve PCR-like semantics. Thanks for the clarification. That makes sense to me. In that case, could the ABI documentation be updated? It currently states: All writes must start at offset 0 and be maximum 64 bytes in size. Attempting to write more than 64 bytes will result in EINVAL returned by the write() syscall. However, the TSM interface requires the write size to exactly match mr_size. Therefore, this would be 32 bytes for SHA-256, 48 bytes for SHA-384, and 64 bytes for SHA-512. My remaining concern is that since sysfs_kf_bin_write() truncates oversized writes to the binary attribute size before invoking the callback, tm_digest_write() sees an exact-sized write and extends the MR. The following validation is useless in this case. static ssize_t tm_digest_write(struct file *filp, struct kobject *kobj, const struct bin_attribute *attr, char *buffer, loff_t off, size_t count) { [...] /* partial writes are not supported */ if (off != 0 || count != attr->size) return -EINVAL; IMO this is not specific to Arm CCA, but do you have any thoughts on this? > > > > > > +}; > > > + > > > +/** > > > + * arm_cca_attr_groups - Attribute groups for the arm_cca_misc_dev miscellaneous > > > + * device. > > > + * > > > + */ > > > +static const struct attribute_group *arm_cca_attr_groups[] = { > > > + NULL, /* measurements */ > > > + NULL > > > +}; > > > + > > > +/** > > > + * arm_cca_misc_dev - Miscellaneous device for ARM CCA functionality. > > > + * > > > + */ > > > +static struct miscdevice arm_cca_misc_dev = { > > > + .name = KBUILD_MODNAME, > > > + .minor = MISC_DYNAMIC_MINOR, > > > + .groups = arm_cca_attr_groups, > > > +}; > > > + > > > +/** > > > + * arm_cca_get_hash_algorithm - Get the hash algorithm and digest size for > > > + * a Realm. > > > + * > > > + * @hash_algo: Pointer to an int to receive the internal hash algorithm ID > > > + * (e.g., HASH_ALGO_SHA256 or HASH_ALGO_SHA512). > > > + * @digest_size: Pointer to an int to receive the digest size in bytes > > > + * (e.g., SHA256_DIGEST_SIZE or SHA512_DIGEST_SIZE). > > > + * > > > + * This function retrieves the hash algorithm used in a Realm's configuration > > > + * by invoking the `rsi_get_realm_config()` interface. > > > + * > > > + * Return: > > > + * * %0 - Success. The hash algorithm and digest size are returned. > > > + * * %-ENOMEM - Memory allocation failed. > > > + * * %-EINVAL - Configuration fetch failed or algorithm is unsupported. > > > + * > > > + */ > > > +static int arm_cca_get_hash_algorithm(int *hash_algo, int *digest_size) > > > +{ > > > + int ret = 0; > > > + unsigned long result; > > > + struct realm_config *cfg = NULL; > > > + > > > + cfg = alloc_pages_exact(sizeof(*cfg), GFP_KERNEL); > > > + if (!cfg) > > > + return -ENOMEM; > > > + > > > + result = rsi_get_realm_config(cfg); > > > + if (result != RSI_SUCCESS) { > > > + ret = -EINVAL; > > > + goto exit_free_realm_config; > > > + } > > > + > > > + switch (cfg->hash_algo) { > > > + case RSI_HASH_SHA_512: > > > + *hash_algo = HASH_ALGO_SHA512; > > > + *digest_size = SHA512_DIGEST_SIZE; > > > + break; > > > + case RSI_HASH_SHA_256: > > > + *hash_algo = HASH_ALGO_SHA256; > > > + *digest_size = SHA256_DIGEST_SIZE; > > > + break; > > > + default: > > > + /* Unknown/unsupported algorithm. */ > > > + ret = -EINVAL; > > > > Would it make sense to add an error message here? For example: > > pr_err("Unknown/unsupported Realm hash algorithm: %u\n", cfg->hash_algo); > > > > For context, I tested your v1 series in the past and found that this function > > sometimes failed due to wrong definition of realm_config::hash_algo [0]. > > Therefore, I think a diagnostic message including the returned value > > would be useful. > > > > [0] https://lore.kernel.org/all/20260929-cca-b4-rsi-fix-hash_algo-type-rebase-v1-1-6932cf0aa605@fujitsu.com/ > > Fair enough. I'll add the error log. > > Thanks! > > -- > Sincerely, > Yeoreum Yun ^ permalink raw reply [flat|nested] 17+ messages in thread
* Re: [PATCH v2 3/3] virt: arm-cca-guest: Add support for measurement registers 2026-09-30 5:59 ` Kohei Enju @ 2026-09-30 6:40 ` Yeoreum Yun 2026-09-30 7:04 ` Kohei Enju 0 siblings, 1 reply; 17+ messages in thread From: Yeoreum Yun @ 2026-09-30 6:40 UTC (permalink / raw) To: Kohei Enju Cc: Yeoreum Yun, linux-arm-kernel, linux-kernel, Catalin Marinas, Will Deacon, Jason Gunthorpe, Suzuki Poulose, Steven Price, Sami Mujawar, thuth > On 09/30 06:09, Yeoreum Yun wrote: > > On Wed, Sep 30, 2026 at 12:24:08PM +0900, Kohei Enju wrote: > > > Hi Yeoreum, Sami, > > > > > > On 09/29 17:57, Yeoreum Yun wrote: > > > > From: Sami Mujawar <sami.mujawar@arm.com> > > > > > > > > Add support for Arm CCA measurement registers (MRs), enabling attestation > > > > and runtime integrity tracking from guest Realms. > > > > > > > > This implementation registers a measurement configuration with the TSM > > > > framework and exposes measurement register values via sysfs using a > > > > misc device. The supported registers include the Realm Initial > > > > Measurement (RIM) and four Runtime Extensible Measurement Registers > > > > (REM0–REM3), each using SHA-256 or SHA-512 depending on Realm > > > > > > Is SHA-384 intentionally out of scope for this series? > > > > > > Although TF-RMM does not support it yet, the RMM specification defines > > > RSI_HASH_SHA_384. A platform using a custom RMM implementation could > > > therefore launch a Realm configured to use SHA-384. I think the Realm > > > guest driver should support it rather than fail initialization. > > > > Fair enough. Let's change in next-spin. > > > > > > > > > configuration. > > > > > > > > The measurement registers are located under the following sysfs node: > > > > /sys/devices/virtual/misc/arm_cca_guest/measurements/ > > > > -rw-r--r-- 1 0 0 64 Jul 21 11:46 rem0:sha512 > > > > -rw-r--r-- 1 0 0 64 Jul 21 11:46 rem1:sha512 > > > > -rw-r--r-- 1 0 0 64 Jul 21 11:46 rem2:sha512 > > > > -rw-r--r-- 1 0 0 64 Jul 21 11:46 rem3:sha512 > > > > -r--r--r-- 1 0 0 64 Jul 21 11:46 rim:sha512 > > > > > > > > As seen above the attributes for the REMs are 'rw' indicating they can > > > > be read or extended. While the attributes for RIM is 'r' indicating > > > > that it can only be read and not extended. > > > > > > > > The sysfs node suffix for the measurement register (i.e. ':sha512') > > > > indicates the hash algorithm used is sha512. This also reflects > > > > that the Realm was launched with SHA512 as the measurement algorithm. > > > > > > > > Signed-off-by: Sami Mujawar <sami.mujawar@arm.com> > > > > --- > > > > .../sysfs-devices-virtual-misc-arm_cca_guest | 38 +++ > > > > drivers/virt/coco/arm-cca-guest/Kconfig | 1 + > > > > drivers/virt/coco/arm-cca-guest/main.c | 282 ++++++++++++++++++++- > > > > 3 files changed, 319 insertions(+), 2 deletions(-) > > > > > > > > diff --git a/Documentation/ABI/testing/sysfs-devices-virtual-misc-arm_cca_guest b/Documentation/ABI/testing/sysfs-devices-virtual-misc-arm_cca_guest > > > > new file mode 100644 > > > > index 000000000000..878dc54e48f8 > > > > --- /dev/null > > > > +++ b/Documentation/ABI/testing/sysfs-devices-virtual-misc-arm_cca_guest > > > > @@ -0,0 +1,38 @@ > > > > +What: /sys/devices/virtual/misc/arm_cca_guest/measurements/MRNAME[:HASH] > > > > +Date: July, 2025 > > > > +KernelVersion: v6.16 > > > > > > I think this Date and KernelVersion are stale and they should be > > > updated. > > > > Oh. I missed it. I'll update in next-spin. > > > > > > > > > +Contact: linux-coco@lists.linux.dev > > > > +Description: > > > > + Value of a Arm CCA Realm measurement register (MR). The optional > > > > > > If the :HASH suffix actually optional for Arm CCA? > > > It appears that the driver always associates a hash algorithm with each > > > register. > > > > > > > + suffix :HASH is to represent the hash algorithms associated with > > > > + the MRs. See below for a complete list of Arm CCA Realm MRs exposed > > > > + via sysfs. Refer to the Arm Realm Management Monitor (RMM) > > > > + Specification for more information on the Realm Measurement registers. > > > > + > > > > + The Arm Realm Management Monitor Specification can be found at: > > > > + https://developer.arm.com/documentation/den0137/latest/ > > > > + > > > > + See also: > > > > + https://docs.kernel.org/driver-api/coco/measurement-registers.html > > > > + > > > > +What: /sys/devices/virtual/misc/arm_cca_guest/measurements/rim:[sha256|sha512] > > > > +Date: July, 2025 > > > > +KernelVersion: v6.16 > > > > +Contact: linux-coco@lists.linux.dev > > > > +Description: > > > > + (RO) RIM - [32|64]-byte immutable storage typically used to represent > > > > + the Realm Initial Measurement (RIM) which is the measurement of > > > > + the configuration and contents of a Realm at the time of activation. > > > > + > > > > +What: /sys/devices/virtual/misc/arm_cca_guest/measurements/rem[0123]:[sha256|sha512] > > > > +Date: July, 2025 > > > > +KernelVersion: v6.16 > > > > +Contact: linux-coco@lists.linux.dev > > > > +Description: > > > > + (RW) REM[0123] - 4 Run-Time extendable Measurement Registers that > > > > + represent the Realm Extensible Measurement (REM) registers which > > > > + can be extended during the lifetime of a Realm. > > > > + Read from any of these returns the current value of the corresponding > > > > + REM. Write extends the written buffer to the REM. All writes must start > > > > + at offset 0 and be maximum 64 bytes in size. Attempting to write more > > > > + than 64 bytes will result in EINVAL returned by the write() syscall. > > > > diff --git a/drivers/virt/coco/arm-cca-guest/Kconfig b/drivers/virt/coco/arm-cca-guest/Kconfig > > > > index 0d4ce72e2d86..3693d3bc90c6 100644 > > > > --- a/drivers/virt/coco/arm-cca-guest/Kconfig > > > > +++ b/drivers/virt/coco/arm-cca-guest/Kconfig > > > > @@ -3,6 +3,7 @@ config ARM_CCA_GUEST > > > > depends on ARM_RMM_RSI > > > > depends on HAVE_ARM_SMCCC_DISCOVERY > > > > select TSM_REPORTS > > > > + select TSM_MEASUREMENTS > > > > help > > > > The driver provides userspace interface to request and > > > > attestation report from the Realm Management Monitor(RMM). > > > > diff --git a/drivers/virt/coco/arm-cca-guest/main.c b/drivers/virt/coco/arm-cca-guest/main.c > > > > index f97f593da6e3..9bbad43c4669 100644 > > > > --- a/drivers/virt/coco/arm-cca-guest/main.c > > > > +++ b/drivers/virt/coco/arm-cca-guest/main.c > > > > @@ -1,6 +1,6 @@ > > > > // SPDX-License-Identifier: GPL-2.0-only > > > > /* > > > > - * Copyright (C) 2023 ARM Ltd. > > > > + * Copyright (C) 2023 - 2025 ARM Ltd. > > > > */ > > > > > > > > #include <linux/arm-rsi-cmds.h> > > > > @@ -9,11 +9,280 @@ > > > > #include <linux/cc_platform.h> > > > > #include <linux/kernel.h> > > > > #include <linux/device-id/platform.h> > > > > +#include <linux/miscdevice.h> > > > > #include <linux/module.h> > > > > #include <linux/smp.h> > > > > #include <linux/tsm.h> > > > > +#include <linux/tsm-mr.h> > > > > #include <linux/types.h> > > > > > > > > +#include <crypto/hash.h> > > > > + > > > > +/* MR buffer */ > > > > +static u8 *arm_cca_mr_buf; > > > > + > > > > +/** > > > > + * arm_cca_mrs - ARM CCA measurement register set. > > > > + * > > > > + * Defines a static array of measurement registers used by the ARM > > > > + * Confidential Compute Architecture (CCA). These registers are used > > > > + * for attestation and runtime integrity tracking. > > > > + * > > > > + * Register types: > > > > + * - rim: Realm initial measurement register (RIM) > > > > + * - rem0–rem3: Runtime extensible measurement registers (REMs) > > > > + */ > > > > +static struct tsm_measurement_register arm_cca_mrs[] = { > > > > + { TSM_MR_(rim, SHA256) | TSM_MR_F_READABLE }, > > > > + { TSM_MR_(rem0, SHA256) | TSM_MR_F_RTMR }, > > > > + { TSM_MR_(rem1, SHA256) | TSM_MR_F_RTMR }, > > > > + { TSM_MR_(rem2, SHA256) | TSM_MR_F_RTMR }, > > > > + { TSM_MR_(rem3, SHA256) | TSM_MR_F_RTMR } > > > > +}; > > > > + > > > > +/** > > > > + * arm_cca_mr_refresh - Refresh measurement registers for ARM CCA. > > > > + * > > > > + * @tm: Pointer to a struct tsm_measurements containing measurement registers. > > > > + * > > > > + * Iterates through all measurement registers in @tm and refreshes those > > > > + * marked with TSM_MR_F_LIVE or TSM_MR_F_READABLE by invoking > > > > + * rsi_measurement_read() for each. > > > > + * > > > > + * Return: 0 on success, or -EINVAL if @tm is NULL or a read operation fails. > > > > + */ > > > > +static int arm_cca_mr_refresh(const struct tsm_measurements *tm) > > > > +{ > > > > + int retval; > > > > + int index = 0; > > > > + const struct tsm_measurement_register *mr; > > > > + > > > > + if (!tm) > > > > + return -EINVAL; > > > > + > > > > + while (index < tm->nr_mrs) { > > > > + mr = &tm->mrs[index]; > > > > + > > > > + /* Skip if the MR is not Live or Readable. */ > > > > + if ((mr->mr_flags & (TSM_MR_F_LIVE | TSM_MR_F_READABLE)) != 0) { > > > > + retval = rsi_measurement_read(index, > > > > + mr->mr_value, > > > > + mr->mr_size); > > > > + if (retval != 0) > > > > + return -EINVAL; > > > > + } > > > > + > > > > + index++; > > > > + } > > > > + > > > > + return 0; > > > > +} > > > > + > > > > +/** > > > > + * arm_cca_mr_extend - Extend a measurement register with new data. > > > > + * > > > > + * @tm: Pointer to the tsm_measurements structure containing measurement > > > > + * registers. > > > > + * @mr: Pointer to the specific measurement register to extend. > > > > + * @data: Pointer to the data to be used for extension. > > > > + * > > > > + * This function extends a measurement register with new input data. > > > > + * > > > > + * Return: 0 on success, or a negative error code (e.g., -EINVAL for invalid > > > > + * arguments). > > > > + */ > > > > +static int arm_cca_mr_extend(const struct tsm_measurements *tm, > > > > + const struct tsm_measurement_register *mr, > > > > + const u8 *data) > > > > +{ > > > > + if (!tm || !mr || !data) > > > > + return -EINVAL; > > > > + > > > > + return rsi_measurement_extend((mr - tm->mrs), data, mr->mr_size); > > > > +} > > > > + > > > > +/** > > > > + * arm_cca_measurements - ARM CCA measurement configuration instance. > > > > + * > > > > + * This defines the measurement set and behavior for the ARM > > > > + * Confidential Compute Architecture, enabling measurements > > > > + * for attestation and runtime validation. > > > > + */ > > > > +static struct tsm_measurements arm_cca_measurements = { > > > > + .mrs = arm_cca_mrs, > > > > + .nr_mrs = ARRAY_SIZE(arm_cca_mrs), > > > > + .refresh = arm_cca_mr_refresh, > > > > + .write = arm_cca_mr_extend, > > > > > > From the RMM specification and the commit message, I understand that a > > > REM can be extended with a measurement value of up to 64 bytes, > > > regardless of the selected hash algorithm (for example, SHA-256 or > > > SHA-512). > > > > > > However, when SHA-256 is selected, this interface does not allow a REM > > > to be extended with a 64-byte value. The write partially succeeds: the > > > REM is extended with the first 32 bytes, and then the write of the > > > remaining 32 bytes fails with -EFBIG. > > > > > > As far as I can tell, the write is truncated to the sysfs binary > > > attribute size, which is set to the SHA-256 digest size (32 bytes). The > > > subsequent write at offset 32 is then rejected by sysfs_kf_bin_write() > > > with -EFBIG. > > > > > > I do not see a straightforward fix because the TSM measurement register > > > interface currently uses mr_size both as the readable digest size and as > > > the required write size. > > > > > > [Realm VM] > > > ~ # export REM3=/sys/devices/virtual/misc/arm_cca_guest/measurements/rem3:sha256 > > > ~ # dd if=/dev/urandom bs=64 count=1 of=$REM3 > > > dd: error writing '/sys/devices/virtual/misc/arm_cca_guest/measurements/rem3:sha256': File too large > > > 1+0 records in > > > 0+0 records out > > > > > > [RMM] > > > SMC_RSI_MEASUREMENT_EXTEND 4 20 3cfcaa635bca042d c148121346b6e1b5 7342800b438d20d7 3dc7a25048cbbad8 0 0 0 0 > RSI_SUCCESS > > > > > > Do you have any thoughts on how the TSM interface should represent the > > > maximum extend input size separately from the digest size? > > > > I don't think we need to represent the maximum extend input size separately. > > > > The TSM measurement register interface is intended to expose PCR-like > > semantics, where the value being extended is a measurement digest whose size > > is determined by the selected hash algorithm. > > > > In other words, the extend operation is conceptually: > > > > new_digest = Hash(old_digest || measurement_digest) > > > > Therefore, for a SHA-256 measurement register, the extend value should be > > 32 bytes, and rejecting a value larger than 32 bytes with -EFBIG seems > > correct to me and intended. A 64-byte extend value would only be valid for > > a register using a 64-byte digest, such as SHA-512. > > > > Although the RMM interface may allow a measurement value of up to 64 bytes > > independently of the REM hash algorithm, I don't think that capability > > needs to be exposed through the generic TSM measurement register interface > > in point of viewt to preserve PCR-like semantics. > > Thanks for the clarification. That makes sense to me. > > In that case, could the ABI documentation be updated? It currently > states: > All writes must start at offset 0 and be maximum 64 bytes in size. > Attempting to write more than 64 bytes will result in EINVAL returned > by the write() syscall. Yeap. I'll update accordingly. Thanks. > > However, the TSM interface requires the write size to exactly match > mr_size. Therefore, this would be 32 bytes for SHA-256, 48 bytes for > SHA-384, and 64 bytes for SHA-512. > > My remaining concern is that since sysfs_kf_bin_write() truncates > oversized writes to the binary attribute size before invoking the > callback, tm_digest_write() sees an exact-sized write and extends the > MR. The following validation is useless in this case. > > static ssize_t tm_digest_write(struct file *filp, struct kobject *kobj, > const struct bin_attribute *attr, char *buffer, > loff_t off, size_t count) > { > [...] > /* partial writes are not supported */ > if (off != 0 || count != attr->size) > return -EINVAL; > > IMO this is not specific to Arm CCA, but do you have any thoughts on > this? I think this is ultimately a limitation of sysfs. At this layer, simply knowing that userspace supplied a larger buffer does not allow us to determine whether all of the data in that buffer is valid. For example, a userspace program could allocate a 64-byte buffer, place only a 32-byte SHA-256 digest in it, and still pass the full buffer size to write(). From the kernel's point of view, there is no reliable way to distinguish that from a valid 64-byte input. Therefore, I think userspace needs to check the size of the binary attribute, e.g. remX256 in this case, and write exactly that amount of valid data. Given the current sysfs interface, I think requiring userspace to check the bin_attr size and provide valid data of exactly that size is the best we can do. IOW, above sanity check is to catch-up what you worried about as comment say, Its purpose to prohibit the *partial write*. > > > > > > > > > > > +}; > > > > + > > > > +/** > > > > + * arm_cca_attr_groups - Attribute groups for the arm_cca_misc_dev miscellaneous > > > > + * device. > > > > + * > > > > + */ > > > > +static const struct attribute_group *arm_cca_attr_groups[] = { > > > > + NULL, /* measurements */ > > > > + NULL > > > > +}; > > > > + > > > > +/** > > > > + * arm_cca_misc_dev - Miscellaneous device for ARM CCA functionality. > > > > + * > > > > + */ > > > > +static struct miscdevice arm_cca_misc_dev = { > > > > + .name = KBUILD_MODNAME, > > > > + .minor = MISC_DYNAMIC_MINOR, > > > > + .groups = arm_cca_attr_groups, > > > > +}; > > > > + > > > > +/** > > > > + * arm_cca_get_hash_algorithm - Get the hash algorithm and digest size for > > > > + * a Realm. > > > > + * > > > > + * @hash_algo: Pointer to an int to receive the internal hash algorithm ID > > > > + * (e.g., HASH_ALGO_SHA256 or HASH_ALGO_SHA512). > > > > + * @digest_size: Pointer to an int to receive the digest size in bytes > > > > + * (e.g., SHA256_DIGEST_SIZE or SHA512_DIGEST_SIZE). > > > > + * > > > > + * This function retrieves the hash algorithm used in a Realm's configuration > > > > + * by invoking the `rsi_get_realm_config()` interface. > > > > + * > > > > + * Return: > > > > + * * %0 - Success. The hash algorithm and digest size are returned. > > > > + * * %-ENOMEM - Memory allocation failed. > > > > + * * %-EINVAL - Configuration fetch failed or algorithm is unsupported. > > > > + * > > > > + */ > > > > +static int arm_cca_get_hash_algorithm(int *hash_algo, int *digest_size) > > > > +{ > > > > + int ret = 0; > > > > + unsigned long result; > > > > + struct realm_config *cfg = NULL; > > > > + > > > > + cfg = alloc_pages_exact(sizeof(*cfg), GFP_KERNEL); > > > > + if (!cfg) > > > > + return -ENOMEM; > > > > + > > > > + result = rsi_get_realm_config(cfg); > > > > + if (result != RSI_SUCCESS) { > > > > + ret = -EINVAL; > > > > + goto exit_free_realm_config; > > > > + } > > > > + > > > > + switch (cfg->hash_algo) { > > > > + case RSI_HASH_SHA_512: > > > > + *hash_algo = HASH_ALGO_SHA512; > > > > + *digest_size = SHA512_DIGEST_SIZE; > > > > + break; > > > > + case RSI_HASH_SHA_256: > > > > + *hash_algo = HASH_ALGO_SHA256; > > > > + *digest_size = SHA256_DIGEST_SIZE; > > > > + break; > > > > + default: > > > > + /* Unknown/unsupported algorithm. */ > > > > + ret = -EINVAL; > > > > > > Would it make sense to add an error message here? For example: > > > pr_err("Unknown/unsupported Realm hash algorithm: %u\n", cfg->hash_algo); > > > > > > For context, I tested your v1 series in the past and found that this function > > > sometimes failed due to wrong definition of realm_config::hash_algo [0]. > > > Therefore, I think a diagnostic message including the returned value > > > would be useful. > > > > > > [0] https://lore.kernel.org/all/20260929-cca-b4-rsi-fix-hash_algo-type-rebase-v1-1-6932cf0aa605@fujitsu.com/ > > > > Fair enough. I'll add the error log. > > > > Thanks! > > > > -- > > Sincerely, > > Yeoreum Yun -- Sincerely, Yeoreum Yun ^ permalink raw reply [flat|nested] 17+ messages in thread
* Re: [PATCH v2 3/3] virt: arm-cca-guest: Add support for measurement registers 2026-09-30 6:40 ` Yeoreum Yun @ 2026-09-30 7:04 ` Kohei Enju 0 siblings, 0 replies; 17+ messages in thread From: Kohei Enju @ 2026-09-30 7:04 UTC (permalink / raw) To: Yeoreum Yun Cc: linux-arm-kernel, linux-kernel, Catalin Marinas, Will Deacon, Jason Gunthorpe, Suzuki Poulose, Steven Price, Sami Mujawar, thuth On 09/30 07:40, Yeoreum Yun wrote: > > > > > +/** > > > > > + * arm_cca_measurements - ARM CCA measurement configuration instance. > > > > > + * > > > > > + * This defines the measurement set and behavior for the ARM > > > > > + * Confidential Compute Architecture, enabling measurements > > > > > + * for attestation and runtime validation. > > > > > + */ > > > > > +static struct tsm_measurements arm_cca_measurements = { > > > > > + .mrs = arm_cca_mrs, > > > > > + .nr_mrs = ARRAY_SIZE(arm_cca_mrs), > > > > > + .refresh = arm_cca_mr_refresh, > > > > > + .write = arm_cca_mr_extend, > > > > > > > > From the RMM specification and the commit message, I understand that a > > > > REM can be extended with a measurement value of up to 64 bytes, > > > > regardless of the selected hash algorithm (for example, SHA-256 or > > > > SHA-512). > > > > > > > > However, when SHA-256 is selected, this interface does not allow a REM > > > > to be extended with a 64-byte value. The write partially succeeds: the > > > > REM is extended with the first 32 bytes, and then the write of the > > > > remaining 32 bytes fails with -EFBIG. > > > > > > > > As far as I can tell, the write is truncated to the sysfs binary > > > > attribute size, which is set to the SHA-256 digest size (32 bytes). The > > > > subsequent write at offset 32 is then rejected by sysfs_kf_bin_write() > > > > with -EFBIG. > > > > > > > > I do not see a straightforward fix because the TSM measurement register > > > > interface currently uses mr_size both as the readable digest size and as > > > > the required write size. > > > > > > > > [Realm VM] > > > > ~ # export REM3=/sys/devices/virtual/misc/arm_cca_guest/measurements/rem3:sha256 > > > > ~ # dd if=/dev/urandom bs=64 count=1 of=$REM3 > > > > dd: error writing '/sys/devices/virtual/misc/arm_cca_guest/measurements/rem3:sha256': File too large > > > > 1+0 records in > > > > 0+0 records out > > > > > > > > [RMM] > > > > SMC_RSI_MEASUREMENT_EXTEND 4 20 3cfcaa635bca042d c148121346b6e1b5 7342800b438d20d7 3dc7a25048cbbad8 0 0 0 0 > RSI_SUCCESS > > > > > > > > Do you have any thoughts on how the TSM interface should represent the > > > > maximum extend input size separately from the digest size? > > > > > > I don't think we need to represent the maximum extend input size separately. > > > > > > The TSM measurement register interface is intended to expose PCR-like > > > semantics, where the value being extended is a measurement digest whose size > > > is determined by the selected hash algorithm. > > > > > > In other words, the extend operation is conceptually: > > > > > > new_digest = Hash(old_digest || measurement_digest) > > > > > > Therefore, for a SHA-256 measurement register, the extend value should be > > > 32 bytes, and rejecting a value larger than 32 bytes with -EFBIG seems > > > correct to me and intended. A 64-byte extend value would only be valid for > > > a register using a 64-byte digest, such as SHA-512. > > > > > > Although the RMM interface may allow a measurement value of up to 64 bytes > > > independently of the REM hash algorithm, I don't think that capability > > > needs to be exposed through the generic TSM measurement register interface > > > in point of viewt to preserve PCR-like semantics. > > > > Thanks for the clarification. That makes sense to me. > > > > In that case, could the ABI documentation be updated? It currently > > states: > > All writes must start at offset 0 and be maximum 64 bytes in size. > > Attempting to write more than 64 bytes will result in EINVAL returned > > by the write() syscall. > > Yeap. I'll update accordingly. Thanks. > > > > > However, the TSM interface requires the write size to exactly match > > mr_size. Therefore, this would be 32 bytes for SHA-256, 48 bytes for > > SHA-384, and 64 bytes for SHA-512. > > > > My remaining concern is that since sysfs_kf_bin_write() truncates > > oversized writes to the binary attribute size before invoking the > > callback, tm_digest_write() sees an exact-sized write and extends the > > MR. The following validation is useless in this case. > > > > static ssize_t tm_digest_write(struct file *filp, struct kobject *kobj, > > const struct bin_attribute *attr, char *buffer, > > loff_t off, size_t count) > > { > > [...] > > /* partial writes are not supported */ > > if (off != 0 || count != attr->size) > > return -EINVAL; > > > > IMO this is not specific to Arm CCA, but do you have any thoughts on > > this? > > I think this is ultimately a limitation of sysfs. At this layer, > simply knowing that userspace supplied a larger buffer does not allow us to > determine whether all of the data in that buffer is valid. I agree that this is a common sysfs/TSM issue rather than something that needs to be addressed in this series. > > For example, a userspace program could allocate a 64-byte buffer, > place only a 32-byte SHA-256 digest in it, and still pass the full buffer > size to write(). From the kernel's point of view, there is no reliable way > to distinguish that from a valid 64-byte input. > > Therefore, I think userspace needs to check the size of the binary attribute, > e.g. remX256 in this case, and write exactly that amount of valid data. Agreed. Userspace should normally inspect the attribute size and write exactly that mount. > > Given the current sysfs interface, I think requiring userspace to check > the bin_attr size and provide valid data of exactly that size is the best > we can do. > > IOW, above sanity check is to catch-up what you worried about as comment > say, Its purpose to prohibit the *partial write*. Right, but my concern is that this check cannot detect an oversized write, since sysfs_kf_bin_write() truncates it before invoking tm_digest_write(). Consequently, the check passes and the MR is extended, even though userspace observes a short write. I think this could be handled by adding an opt-in option that prevents sysfs from truncating writes. I did a basic test with the prototype patch below and confirmed that an oversized digest was rejected with -EFBIG before the MR was extended. Anyway, I will look into addressing this separately through the common TSM/sysfs code. Thanks for the clarification, Yeoreum. ---8<--- diff --git a/drivers/virt/coco/guest/tsm-mr.c b/drivers/virt/coco/guest/tsm-mr.c index 657b9c5739d0..5880b12e1f55 100644 --- a/drivers/virt/coco/guest/tsm-mr.c +++ b/drivers/virt/coco/guest/tsm-mr.c @@ -215,6 +215,7 @@ tsm_mr_create_attribute_group(const struct tsm_measurements *tm) if (tm->mrs[i].mr_flags & TSM_MR_F_WRITABLE) { bap->attr.mode |= 0200; bap->write = tm_digest_write; + bap->no_write_truncate = true; } bap->size = tm->mrs[i].mr_size; diff --git a/fs/sysfs/file.c b/fs/sysfs/file.c index cd5bb0f9fee6..1d6a0bf8109e 100644 --- a/fs/sysfs/file.c +++ b/fs/sysfs/file.c @@ -156,6 +156,8 @@ static ssize_t sysfs_kf_bin_write(struct kernfs_open_file *of, char *buf, if (size) { if (size <= pos) return -EFBIG; + if (battr->no_write_truncate && count > size - pos) + return -EFBIG; count = min_t(ssize_t, count, size - pos); } if (!count) diff --git a/include/linux/sysfs.h b/include/linux/sysfs.h index b1a3a1e6ad09..31a4c3cf5d51 100644 --- a/include/linux/sysfs.h +++ b/include/linux/sysfs.h @@ -312,6 +312,7 @@ struct bin_attribute { struct attribute attr; size_t size; void *private; + bool no_write_truncate; struct address_space *(*f_mapping)(void); ssize_t (*read)(struct file *, struct kobject *, const struct bin_attribute *, char *, loff_t, size_t); Thanks, Kohei ^ permalink raw reply [flat|nested] 17+ messages in thread
* Re: [PATCH v2 0/3] arm64/virt: Add Arm CCA measurement register support 2026-09-29 16:57 [PATCH v2 0/3] arm64/virt: Add Arm CCA measurement register support Yeoreum Yun ` (2 preceding siblings ...) 2026-09-29 16:57 ` [PATCH v2 3/3] virt: arm-cca-guest: Add support for measurement registers Yeoreum Yun @ 2026-09-29 19:20 ` Jason Gunthorpe 2026-09-29 19:42 ` Yeoreum Yun 3 siblings, 1 reply; 17+ messages in thread From: Jason Gunthorpe @ 2026-09-29 19:20 UTC (permalink / raw) To: Yeoreum Yun Cc: linux-arm-kernel, linux-kernel, Catalin Marinas, Will Deacon, Suzuki Poulose, Steven Price, Sami Mujawar, thuth, Jiri Pirko On Tue, Sep 29, 2026 at 05:57:46PM +0100, Yeoreum Yun wrote: > This series adds support for Arm Confidential Compute Architecture (CCA) > measurement registers in the Linux kernel, enabling guest Realms to > access, extend, and expose measurement values for attestation and runtime > integrity tracking. I'd prefer not to add any more tsm_measurements users until we bottom out on the attestation subsystem.. Mainly because it establishes uAPI that doesn't really do everything people need from this stuff.. The actual code seemed reasonble from a quick glance. Jason ^ permalink raw reply [flat|nested] 17+ messages in thread
* Re: [PATCH v2 0/3] arm64/virt: Add Arm CCA measurement register support 2026-09-29 19:20 ` [PATCH v2 0/3] arm64/virt: Add Arm CCA measurement register support Jason Gunthorpe @ 2026-09-29 19:42 ` Yeoreum Yun 2026-09-29 19:45 ` Jason Gunthorpe 0 siblings, 1 reply; 17+ messages in thread From: Yeoreum Yun @ 2026-09-29 19:42 UTC (permalink / raw) To: Jason Gunthorpe Cc: Yeoreum Yun, linux-arm-kernel, linux-kernel, Catalin Marinas, Will Deacon, Suzuki Poulose, Steven Price, Sami Mujawar, thuth, Jiri Pirko On Tue, Sep 29, 2026 at 04:20:51PM -0300, Jason Gunthorpe wrote: > On Tue, Sep 29, 2026 at 05:57:46PM +0100, Yeoreum Yun wrote: > > This series adds support for Arm Confidential Compute Architecture (CCA) > > measurement registers in the Linux kernel, enabling guest Realms to > > access, extend, and expose measurement values for attestation and runtime > > integrity tracking. > > I'd prefer not to add any more tsm_measurements users until we bottom > out on the attestation subsystem.. Mainly because it establishes uAPI > that doesn't really do everything people need from this stuff.. Tend to agree. However, I think this seems like an integration with the attestation subsystem. IOW, although the functionality and interface are currently scattered, the functionality of the TSM MR doesn't change — showing the current measurement register status and generating a token with a challenge. Therefore, even if the subsystem is refactored, I don't think this would be a burden for it, and personally, I'd like to see this patch series emancipated from almost six months of waiting ;) > > The actual code seemed reasonble from a quick glance. Thanks! -- Sincerely, Yeoreum Yun ^ permalink raw reply [flat|nested] 17+ messages in thread
* Re: [PATCH v2 0/3] arm64/virt: Add Arm CCA measurement register support 2026-09-29 19:42 ` Yeoreum Yun @ 2026-09-29 19:45 ` Jason Gunthorpe 0 siblings, 0 replies; 17+ messages in thread From: Jason Gunthorpe @ 2026-09-29 19:45 UTC (permalink / raw) To: Yeoreum Yun Cc: linux-arm-kernel, linux-kernel, Catalin Marinas, Will Deacon, Suzuki Poulose, Steven Price, Sami Mujawar, thuth, Jiri Pirko On Tue, Sep 29, 2026 at 08:42:36PM +0100, Yeoreum Yun wrote: > On Tue, Sep 29, 2026 at 04:20:51PM -0300, Jason Gunthorpe wrote: > > On Tue, Sep 29, 2026 at 05:57:46PM +0100, Yeoreum Yun wrote: > > > This series adds support for Arm Confidential Compute Architecture (CCA) > > > measurement registers in the Linux kernel, enabling guest Realms to > > > access, extend, and expose measurement values for attestation and runtime > > > integrity tracking. > > > > I'd prefer not to add any more tsm_measurements users until we bottom > > out on the attestation subsystem.. Mainly because it establishes uAPI > > that doesn't really do everything people need from this stuff.. > > Tend to agree. However, I think this seems like an integration with > the attestation subsystem. > IOW, although the functionality and interface are currently scattered, > the functionality of the TSM MR doesn't change — > showing the current measurement register status and generating > a token with a challenge. Therefore, even if the subsystem is refactored, > I don't think this would be a burden for it, and personally, > I'd like to see this patch series emancipated from almost six months of waiting ;) Yeah, but it immediately establishes a sysfs uAPI that we don't want anyone to implement :( That's my main issue.. Jason ^ permalink raw reply [flat|nested] 17+ messages in thread
end of thread, other threads:[~2026-09-30 7:06 UTC | newest] Thread overview: 17+ messages (download: mbox.gz / follow: Atom feed) -- links below jump to the message on this page -- 2026-09-29 16:57 [PATCH v2 0/3] arm64/virt: Add Arm CCA measurement register support Yeoreum Yun 2026-09-29 16:57 ` [PATCH v2 1/3] arm64: rsi: Add helpers for Arm CCA measurement register operations Yeoreum Yun 2026-09-30 2:04 ` Kohei Enju 2026-09-30 5:13 ` Yeoreum Yun 2026-09-29 16:57 ` [PATCH v2 2/3] arm64: rsi: Add realm hash algorithm defines Yeoreum Yun 2026-09-30 2:39 ` Kohei Enju 2026-09-30 5:10 ` Yeoreum Yun 2026-09-29 16:57 ` [PATCH v2 3/3] virt: arm-cca-guest: Add support for measurement registers Yeoreum Yun 2026-09-30 3:24 ` Kohei Enju 2026-09-30 4:45 ` Kohei Enju 2026-09-30 5:09 ` Yeoreum Yun 2026-09-30 5:59 ` Kohei Enju 2026-09-30 6:40 ` Yeoreum Yun 2026-09-30 7:04 ` Kohei Enju 2026-09-29 19:20 ` [PATCH v2 0/3] arm64/virt: Add Arm CCA measurement register support Jason Gunthorpe 2026-09-29 19:42 ` Yeoreum Yun 2026-09-29 19:45 ` Jason Gunthorpe
This is a public inbox, see mirroring instructions for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®