[PATCH v7 10/11] virt: arm-cca-guest: TSM_REPORT support for realms

Catalin Marinas catalin.marinas at arm.com
Tue Oct 22 04:06:49 PDT 2024


On Thu, Oct 17, 2024 at 02:14:33PM +0100, Steven Price wrote:
> From: Sami Mujawar <sami.mujawar at arm.com>
> 
> Introduce an arm-cca-guest driver that registers with
> the configfs-tsm module to provide user interfaces for
> retrieving an attestation token.
> 
> When a new report is requested the arm-cca-guest driver
> invokes the appropriate RSI interfaces to query an
> attestation token.
> 
> The steps to retrieve an attestation token are as follows:
>   1. Mount the configfs filesystem if not already mounted
>      mount -t configfs none /sys/kernel/config
>   2. Generate an attestation token
>      report=/sys/kernel/config/tsm/report/report0
>      mkdir $report
>      dd if=/dev/urandom bs=64 count=1 > $report/inblob
>      hexdump -C $report/outblob
>      rmdir $report
> 
> Signed-off-by: Sami Mujawar <sami.mujawar at arm.com>
> Signed-off-by: Suzuki K Poulose <suzuki.poulose at arm.com>
> Signed-off-by: Steven Price <steven.price at arm.com>
> ---
> Changes since v6:
>  * Avoid get_cpu() and instead make the init attestation call using
>    smp_call_function_single(). Improve comments to explain the logic.
>  * Minor code reorgnisation and comment cleanup following Gavin's review
>    (thanks!)

Gavin, since most changes in v7 are based on your feedback, do you have
any more comments on this patch? I plan to push this series into -next
fairly soon.

Thanks.

-- 
Catalin



More information about the linux-arm-kernel mailing list