Hi Jason, > On Thu, Oct 01, 2026 at 01:45:26PM +0200, Roberto Sassu wrote: > > On Thu, 2026-10-01 at 13:27 +0200, Roberto Sassu wrote: > > > On Wed, 2026-09-30 at 14:43 +0100, Yeoreum Yun wrote: > > > > Confidential computing guests without a TPM can use TSM measurement > > > > registers to record IMA measurement digests instead of TPM PCRs. > > > > + Gong Ruiqi, of course. > > We are working very seriously on this same problem too. > > For some time we did investigate extending tsm_mr to do more things, > have a better uAPI, but that eventually evolved into the realization > that tsm_mr is simply too narrowly focused. It looks like James got to > this idea before we did. I agree with his remarks in the 2025 thread > with Gong. > > So we've started work on a new comprehensive "Attestation subsytem" > that will pull in all forms of ROTs, TPM, CC stuff and SPDM use cases > to give a consistent user API to work with this class of HW. In many > ways I view this as a rename of tsm_mr (it will eventually fully > absorb it), but the name evokes the broader goal and encourages > everyone to come in, not just CC world. > > Our overall goal would be for something like systemd to have a single > uniform kernel API that allows it interwork with any ROT someone may > have. A uAPI to do "Extend", "Quote", "Get Log" operations so that the > existing TPM support in systemd can be improved to work on any ROT > flexibly without having to hard code specific ROT behaviors into > systemd. > > I've felt the ultimate end goal would be to make all the in-kernel tpm > users go through the proposed attestation subsystem so they can have > ROT and "PCR profile" agility. Certainly I've heard enough people > asking for this. > > This is a broader topic than just IMA. For example DRTM also has to > use the TPM, and other ROTs. It also brings in a global shift of how > the system wide "PCR Profile" should work as post-DRTM has a different > TPM locality and access to the protected DRTM-only PCRs that are > normally blocked. > > Jiri posted his current state here: > https://lore.kernel.org/r/arzr32ZDComnfmny@FV6GYCPJ69
Thanks to let me know. I'll take a look for this. -- Sincerely, Yeoreum Yun

