On Thu, Oct 01, 2026 at 01:45:26PM +0200, Roberto Sassu wrote:
> On Thu, 2026-10-01 at 13:27 +0200, Roberto Sassu wrote:
> > On Wed, 2026-09-30 at 14:43 +0100, Yeoreum Yun wrote:
> > > Confidential computing guests without a TPM can use TSM measurement
> > > registers to record IMA measurement digests instead of TPM PCRs.
> 
> + Gong Ruiqi, of course.

We are working very seriously on this same problem too.

For some time we did investigate extending tsm_mr to do more things,
have a better uAPI, but that eventually evolved into the realization
that tsm_mr is simply too narrowly focused. It looks like James got to
this idea before we did. I agree with his remarks in the 2025 thread
with Gong.

So we've started work on a new comprehensive "Attestation subsytem"
that will pull in all forms of ROTs, TPM, CC stuff and SPDM use cases
to give a consistent user API to work with this class of HW. In many
ways I view this as a rename of tsm_mr (it will eventually fully
absorb it), but the name evokes the broader goal and encourages
everyone to come in, not just CC world.

Our overall goal would be for something like systemd to have a single
uniform kernel API that allows it interwork with any ROT someone may
have. A uAPI to do "Extend", "Quote", "Get Log" operations so that the
existing TPM support in systemd can be improved to work on any ROT
flexibly without having to hard code specific ROT behaviors into
systemd.

I've felt the ultimate end goal would be to make all the in-kernel tpm
users go through the proposed attestation subsystem so they can have
ROT and "PCR profile" agility. Certainly I've heard enough people
asking for this.

This is a broader topic than just IMA. For example DRTM also has to
use the TPM, and other ROTs. It also brings in a global shift of how
the system wide "PCR Profile" should work as post-DRTM has a different
TPM locality and access to the protected DRTM-only PCRs that are
normally blocked.

Jiri posted his current state here:
  https://lore.kernel.org/r/arzr32ZDComnfmny@FV6GYCPJ69

While we plan to start with SPDM and CC topics as the initial launch
Jiri has enough detailed plans now for all the main use cases, PCI
SPDM, TPM, "CC PCRS", CC attestation, and Caliptra that I'm feeling
confident something like this is the right way forward.

Jason

Reply via email to